Cisco ISEãšã¯äœã§ããïŒ
Cisco Identity Services EngineïŒISEïŒã¯ãã¢ã¯ã»ã¹ã³ã³ããã¹ãã«åºã¥ããŠäŒæ¥ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããããã®ãœãªã¥ãŒã·ã§ã³ã§ãã ãã®ãœãªã¥ãŒã·ã§ã³ã¯ãèªèšŒãæ¿èªãã€ãã³ãã¢ã«ãŠã³ãã£ã³ã°ïŒAAAïŒãã¹ããŒã¿ã¹è©äŸ¡ããããã¡ã€ãªã³ã°ãã²ã¹ãã¢ã¯ã»ã¹ç®¡çãµãŒãã¹ãåäžã®ãã©ãããã©ãŒã ã«çµ±åããŸãã Cisco ISEã¯ããšã³ããã€ã³ãããã€ã¹ãèªåçã«èå¥ããã³åé¡ãããŠãŒã¶ãŒãšããã€ã¹ã®äž¡æ¹ãèªèšŒããããšã«ããé©åãªã¬ãã«ã®ã¢ã¯ã»ã¹ãæäŸããŸãããŸããäŒæ¥ITã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®ã¢ã¯ã»ã¹ãæäŸããåã«ã»ãã¥ãªãã£ã¹ããŒã¿ã¹ãè©äŸ¡ããããšã«ããããšã³ããã€ã³ããäŒæ¥æ å ±ã»ãã¥ãªãã£ããªã·ãŒã«æºæ ããããã«ããŸãã ãã©ãããã©ãŒã ã¯ãã»ãã¥ãªãã£ã°ã«ãŒãïŒSGïŒãã»ãã¥ãªãã£ã°ã«ãŒãã©ãã«ïŒSGTïŒãã»ãã¥ãªãã£ã°ã«ãŒãã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒSGACLïŒãªã©ã®æè»ãªã¢ã¯ã»ã¹å¶åŸ¡ã¡ã«ããºã ããµããŒãããŸãã ããã«ã€ããŠã¯ä»¥äžã§èª¬æããŸãã
å°ãã®çµ±èš
å±éã®90ïŒ ã«ã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ä¿è·ãå«ãŸããŠããŸãã ã客æ§ã¯éåžžã«ç°ãªã£ãŠããŸãã äºç®ãéãããŠããããã誰ããæ°ããããããšã³ãã®ã·ã¹ã³æ©åšãè³Œå ¥ãã誰ããããã䜿çšããŠããŸãã ããããå®å šãªæç·ã¢ã¯ã»ã¹ã®ããã«ã¯ãæãåçŽãªã¢ãã«ã¯é©åã§ã¯ãªããç¹å®ã®ã¹ã€ãããå¿ èŠã§ãã ãããã誰ããæã£ãŠããããã§ã¯ãããŸããã ã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ã³ã³ãããŒã©ãŒãã·ã¹ã³ãœãªã¥ãŒã·ã§ã³äžã«æ§ç¯ãããŠããå Žåãéåžžã¯Cisco ISEããµããŒãããããã®æŽæ°ã®ã¿ãå¿ èŠã§ãã
ã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ã§ã¯ãéåžžãåäžã®ã³ã³ãããŒã©ãŒãšå€æ°ã®ãããã䜿çšãããŸãã ãŸããã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ãå©çšããããããŠãŒã¶ãŒã¢ã¯ã»ã¹ãšã²ã¹ãã¢ã¯ã»ã¹ã®äž¡æ¹ã«åãã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšãããšäŸ¿å©ãªãããã»ãšãã©ã®é¡§å®¢ïŒçŽ80ïŒ ïŒãã²ã¹ãã¢ã¯ã»ã¹ãå®è£ ããããšèããŠããŸãã
æ¥çã¯ä»®æ³åã«åãã£ãŠããŸãããä»®æ³åç°å¢ãšãªãœãŒã¹å²ãåœãŠã«äŸåããªãããã«ãã客æ§ã®åæ°ãããŒããŠã§ã¢ãœãªã¥ãŒã·ã§ã³ãéžæããŠããŸãã ããã€ã¹ã¯ãã§ã«ãã©ã³ã¹ãåããŠãããé©åãªéã®RAMãšããã»ããµãåããŠããŸãã 顧客ã¯ä»®æ³ãªãœãŒã¹ã®å²ãåœãŠãå¿é ããããšã¯ã§ããŸãããå€ãã®å Žåãã©ãã¯å ã§ã®é 眮ãåžæããŠããŸããããœãªã¥ãŒã·ã§ã³ããã®ããŒããŠã§ã¢å®è£ å°çšã«æé©åãããŠããããšãèœã¡çããŠãã ããã
ãµã³ãã«ãããžã§ã¯ã
ã¢ãã«ãããžã§ã¯ããšã¯äœã§ããïŒ ããã«ã¯ãç¡ç·ã¢ã¯ã»ã¹ä¿è·ãšã²ã¹ãã¢ã¯ã»ã¹ãå«ãŸããå¯èœæ§ãé«ãã§ãã ç§ãã¡ã¯çãèªåã®ããã€ã¹ãä»äºã«æã£ãŠè¡ããããããšäžç·ã«ãªã³ã©ã€ã³ã«ããã®ã倧奜ãã§ãã ããããä»æ¥ã§ãããã¹ãŠã®ã¬ãžã§ããã«GSMã¢ãžã¥ãŒã«ãããããã§ã¯ãããŸããã ããŒãœãã«ããã€ã¹ãäŒæ¥ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã«ã»ãã¥ãªãã£ãäœäžããªãããã«ãBYODã€ã³ãã©ã¹ãã©ã¯ãã£ã匷調衚瀺ãããŸããããã«ãããããŒãœãã«ããã€ã¹ãèªåãŸãã¯åèªåã§ç»é²ã§ããŸãã ã·ã¹ãã ã¯ããããäŒæ¥ã§ã¯ãªãã¬ãžã§ããã§ããããšãç解ããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã®ã¿ãæäŸããŸãã
ããã¯ç§ãã¡ãšã©ãã§ããïŒ æºåž¯é»è©±ãæã£ãŠWi-Fiçµç±ã§æ¥ç¶ãããšãã€ã³ã¿ãŒãããäžã§ã®ã¿è§£æŸãããŸãã Wi-Fiçµç±ã§ã©ããããããæ¥ç¶ãããšããªãã£ã¹ãããã¯ãŒã¯ãšãã¹ãŠã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ãããŸãã ããã¯BYODãã¯ãããžãŒã§ãã
å€ãã®å Žåãæã¡èŸŒãŸããããã€ã¹ããä¿è·ããããã«ããŠãŒã¶ãŒã ãã§ãªãã¯ãŒã¯ã¹ããŒã·ã§ã³ã®èªèšŒãå¯èœã«ããEAPãã§ãŒã³ãã¯ãããžãŒãå®è£ ããŠããŸãã ã€ãŸãããã¡ã€ã³ã©ããããããŸãã¯å人ã®ã©ãããããããããã¯ãŒã¯ã«æ¥ç¶ãããŠãããã©ãããå€æããããã«å¿ããŠããã€ãã®ããªã·ãŒãé©çšã§ããŸãã
ã€ãŸãããèªèšŒæžã¿/æªèªèšŒãã«å ããŠãããã¡ã€ã³/éãã¡ã€ã³ããšããåºæºã衚瀺ãããŸãã 4ã€ã®åºæºã®å ±ééšåã«åºã¥ããŠãç°ãªãããªã·ãŒãå®çŸ©ã§ããŸãã ããšãã°ããã¡ã€ã³ãŠãŒã¶ãŒã§ã¯ãªããã¡ã€ã³ãã·ã³ïŒããã¯ã管çè ãããŒã«ã«ã§äœããæ§æããããã«ãªã£ãããšãæå³ããŸãã ã»ãšãã©ã®å Žåã圌ã¯ãããã¯ãŒã¯äžã®ç¹å¥ãªæš©éãå¿ èŠãšããŸãã ãã¡ã€ã³ãã·ã³ããã³ãã¡ã€ã³ãŠãŒã¶ãŒã®å Žåãæš©éã«åŸã£ãŠæšæºã¢ã¯ã»ã¹ãæäŸããŸãã ãŸãããã¡ã€ã³ãã·ã³ã§ã¯ãªããã¡ã€ã³ãŠãŒã¶ãŒã®å Žåããã®ãŠãŒã¶ãŒã¯å人ã®ã©ããããããæã¡èŸŒã¿ãã¢ã¯ã»ã¹æš©ãå¶éããå¿ èŠããããŸãã
ãŸããå šå¡ãIPé»è©±ãšããªã³ã¿ãŒã®ãããã¡ã€ãªã³ã°ã䜿çšããããšããå§ãããŸãã ãããã¡ã€ãªã³ã°ã¯ãéæ¥çãªæšèããããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã€ã¹ã®çš®é¡ã«ãã決å®ã§ãã ãªããããéèŠãªã®ã§ããïŒ ããªã³ã¿ãŒãåããŸãã éåžžã圌ã¯å»äžã«ç«ã£ãŠããŸããã€ãŸããè¿ãã«ãœã±ããããããç£èŠã«ã¡ã©ã§èŠãããªãããšããããããŸãã ãã³ãã¹ã¿ãŒãšãµã€ããŒç¯çœªè ã¯ãã°ãã°ããã䜿çšããŸãã圌ãã¯ããã€ãã®ããŒããåããå°ããªããã€ã¹ãã³ã³ã»ã³ãã«æ¥ç¶ããããªã³ã¿ãŒã®åŸãã«çœ®ããŸããããã€ã¹ã¯1ãæéãããã¯ãŒã¯ãæ©ãåããããŒã¿ãåéããã¢ã¯ã»ã¹ãååŸããŸãã ããã«ãããªã³ã¿ã¯åžžã«æš©éãå¶éããããã§ã¯ãªããããããå¥ã®VLANã«ããããããŸãã ããã¯å€ãã®å Žåãã»ãã¥ãªãã£ãªã¹ã¯ã«ã€ãªãããŸãã ãããã¡ã€ãªã³ã°ãèšå®ãããšããã®ããã€ã¹ããããã¯ãŒã¯ã«å ¥ããšããã«ãããã«ã€ããŠèª¿ã¹ãæ¥ãŠããœã±ããããåãåºããŠã誰ãããã«æ®ããããå€æããŸãã
æåŸã«ãå®æçã«ãã¹ãã£ã䜿çšããŸããæ å ±ã»ãã¥ãªãã£èŠä»¶ãžã®æºæ ããŠãŒã¶ãŒã«ç¢ºèªããŸãã éåžžãããã¯ãªã¢ãŒããŠãŒã¶ãŒã«é©çšãããŸãã ããšãã°ã誰ããèªå® ãåºåŒµããVPNãä»ããŠæ¥ç¶ããŸãã å€ãã®å Žåã圌ã¯éèŠãªã¢ã¯ã»ã¹ãå¿ èŠãšããŸãã ãããã圌ãå人ãŸãã¯ã¢ãã€ã«ããã€ã¹ã®æ å ±ã»ãã¥ãªãã£ã«åªããŠãããã©ãããç解ããããšã¯éåžžã«å°é£ã§ãã ãŸãããã¹ãã£ã䜿çšãããšãããšãã°ããŠãŒã¶ãŒã«ææ°ã®ãŠã€ã«ã¹å¯Ÿçããã°ã©ã ããããã©ãããå®è¡äžãã©ãããæŽæ°ããã°ã©ã ããããã©ããã確èªã§ããŸãã ãã®ãããé€å€ããªãå Žåã§ããå°ãªããšããªã¹ã¯ãæžããããšãã§ããŸãã
ããªãããŒãªã¿ã¹ã¯
ããã§ã¯ã奜å¥å¿ã®åŒ·ããããžã§ã¯ãã«ã€ããŠè©±ããŸãããã 顧客ã®1人ãäœå¹Žãåã«Cisco ISEãè³Œå ¥ããŸããã äŒç€Ÿã®æ å ±ã»ãã¥ãªãã£ããªã·ãŒã¯éåžžã«å³æ Œã§ããå¯èœãªãã¹ãŠãèŠå¶ãããŠãããä»ã®äººã®ããã€ã¹ããããã¯ãŒã¯ã«æ¥ç¶ããããšã¯èš±å¯ãããŠããŸãããã€ãŸããBYODã¯ãããŸããã ãŠãŒã¶ãŒã1ã€ã®ã³ã³ã»ã³ãããã³ã³ãã¥ãŒã¿ãŒã®ãã©ã°ãæããé£ã®ã³ã³ã»ã³ãã«å·®ã蟌ãã å Žåãããã¯ãã§ã«æ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã§ãã æ倧ã¬ãã«ã®ãã¥ãŒãªã¹ãã£ãã¯ãåããã¢ã³ããŠã€ã«ã¹ãããŒã«ã«ãã¡ã€ã¢ãŠã©ãŒã«ã¯çä¿¡æ¥ç¶ãçŠæ¢ããŸãã
ã客æ§ã¯ãã©ã®äŒæ¥ããã€ã¹ããããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã©ã®OSããŒãžã§ã³ãååšããããªã©ã«é¢ããæ å ±ãæ¬åœã«åãåããããšæã£ãŠããŸããã ããã«åºã¥ããŠã圌ã¯ã»ãã¥ãªãã£ããªã·ãŒãäœæããŸããã ç§ãã¡ã®ã·ã¹ãã ã§ã¯ãããã€ã¹ãèå¥ããããã«ããŸããŸãªéæ¥ããŒã¿ãå¿ èŠã§ããã æé©ãªãªãã·ã§ã³ã¯DHCPãããŒãã§ãããã®ããã«ãDHCPãã©ãã£ãã¯ã®ã³ããŒãŸãã¯DNSãã©ãã£ãã¯ã®ã³ããŒãåä¿¡ããå¿ èŠããããŸãã ãããã顧客ã¯ãããã¯ãŒã¯ããã®ãã©ãã£ãã¯ã®éä¿¡ãæåºãšããŠæåŠããŸããã ãŸããã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¯ä»ã«å¹æçãªãµã³ãã«ã¯ãããŸããã§ããã 圌ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ã眮ãããŠããã¯ãŒã¯ã¹ããŒã·ã§ã³ãã©ã®ããã«å€æã§ããããèãå§ããŸããã å€ã§ã¹ãã£ã³ããããšã¯ã§ããŸããã
æçµçã«ã圌ãã¯Cisco CDPãããã³ã«ã«é¡äŒŒããLLDPãããã³ã«ã䜿çšããããšã決å®ããŸãããããã«ããããããã¯ãŒã¯ããã€ã¹ã¯èªèº«ã«é¢ããæ å ±ã亀æããŸãã ããšãã°ãã¹ã€ããã¯å¥ã®ã¹ã€ããã«ã¡ãã»ãŒãžãéä¿¡ããŸãïŒãç§ã¯ã¹ã€ããã§ãã24ã®ããŒããããããã®ãããªVLANããããŸãããããã¯èšå®ã§ããã
é©åãªãšãŒãžã§ã³ããèŠã€ããŠã¯ãŒã¯ã¹ããŒã·ã§ã³ã«çœ®ããæ¥ç¶ãããã³ã³ãã¥ãŒã¿ãŒããã®OSãããã³æ©åšã«é¢ããããŒã¿ãã¹ã€ããã«éä¿¡ããŸããã åæã«ãåãåã£ãããŒã¿ã«åºã¥ããŠISEã§ã«ã¹ã¿ã ãããã¡ã€ãªã³ã°ããªã·ãŒãäœæã§ããããšã¯éåžžã«å¹žéã§ããã
åã顧客ã§æãå¿«é©ãªã±ãŒã¹ãåºãããã§ã¯ãããŸããã äŒç€Ÿã«ã¯Polycomã³ã³ãã¡ã¬ã³ã¹ã¹ããŒã·ã§ã³ããããéåžžã¯äº€æžäžã§ãã ã·ã¹ã³ã¯ãæ°å¹Žåã«Polycomæ©åšã®ãµããŒããçºè¡šããŸããããããã£ãŠãã¹ããŒã·ã§ã³ã¯ããã«ãããã¡ã€ã«ããå¿ èŠããããå¿ èŠãªçµã¿èŸŒã¿ããªã·ãŒã¯Cisco ISEã«å«ãŸããŠããŸããã ISEã¯ãããèŠãŠãµããŒãããŸããããã«ã¹ã¿ããŒã¹ããŒã·ã§ã³ã¯é©åã«ãããã¡ã€ãªã³ã°ããŸããã§ãããç¹å®ã®ã¢ãã«ãæå®ããã«IPé»è©±ãšããŠå®çŸ©ãããŸããã ãŸãã顧客ã¯ã©ã®äŒè°å®€ã§ã©ã®ã¢ãã«ãç«ã£ãŠããããå€æããããšèããŸããã
ç§ãã¡ã¯èŠã€ãå§ããŸããã ãã©ã€ããªããã€ã¹ã®ãããã¡ã€ãªã³ã°ã¯ãMACã¢ãã¬ã¹ã«åºã¥ããŠããŸãã ãåãã®ãšãããMACã®æåã®6æ¡ã¯äŒç€Ÿããšã«äžæã§ããããããã¯ã§äºçŽãããŠããŸãã ãã®Conference Stationã®ãããã¡ã€ãªã³ã°äžã«ããããã°ã¢ãŒãããªã³ã«ããŠããã°ã«éåžžã«åçŽãªã€ãã³ãããããŸãããISEã¯MACãååŸããCiscoã§ã¯ãªãPolycomã§ãããšèšã£ããããCDPããã³LLDPããŒãªã³ã°ã¯è¡ããŸããã
ãã³ããŒã«æçŽãæžããŸããã ãã®Conference Stationã®å¥ã®ã€ã³ã¹ã¿ã³ã¹ããã圌ãã¯MACã¢ãã¬ã¹ãååŸããŸãããããã¯ãç§ãã¡ã®ãã®ãšã¯ã»ãã®æ°æ¡ç°ãªããæ£ãããããã¡ã€ã«ãããŠããŸããã ãã®ç¹å®ã®ã¹ããŒã·ã§ã³ã®ã¢ãã¬ã¹ãäžéã ã£ãããšãå€æãããã®çµæãCiscoã¯ãã®ããã®ããããã»ãŒãªãªãŒã¹ãããã®åŸã¯ã©ã€ã¢ã³ããæ£ãããããã¡ã€ã«ãéå§ããŸããã
SGT
æåŸã«ãæè¿ã®æãèå³æ·±ããããžã§ã¯ãã®1ã€ã«ã€ããŠã話ããããšæããŸãã ãã ããæåã«SGTïŒã»ãã¥ãªãã£ã°ã«ãŒãã¿ã°ïŒãšåŒã°ããæè¡ãæãåºãå¿ èŠããããŸãã
ã»ãã¥ãªãã£ã°ã«ãŒãã¿ã°ãã¯ãããžãŒ
ãããã¯ãŒã¯ã·ãŒã«ãã®å€å
žçãªæ¹æ³ã¯ãããŒããšãã®ããŒãã®éä¿¡å
ããã³å®å
IPã¢ãã¬ã¹ã«åºã¥ããŠããŸãã ãã ãããã®æ
å ±ã¯å°ããããŸãããåæã«VLANã«å³å¯ã«ä»å ãããŠããŸãã ã·ã¹ã³ã¯éåžžã«ã·ã³ãã«ãªã¢ã€ãã¢ãæãã€ããŸããïŒSGTã¿ã°ãæ©åšã®ãã¹ãŠã®éä¿¡è
ãšåä¿¡è
ã«å²ãåœãŠãã¿ã°AãšBãšCãã¿ã°11ãš10ã®éã11ãš20ã®éã§äº€æã§ãããããã³ã«ããã€ã¹ã«ããªã·ãŒãé©çšããŸããããããŠ10ãš20ã®é-ããã¯äžå¯èœã§ãã ã€ãŸããèš±å¯ããã³çŠæ¢ãããããŒã¿äº€æãã¹ã®ãããªãã¯ã¹ãååŸãããŸãã ããã«ããã®ãããªãã¯ã¹ã§ã¯ãåçŽãªã¢ã¯ã»ã¹ãªã¹ãã䜿çšã§ããŸãã IPã¢ãã¬ã¹ã¯ãªããããŒãã®ã¿ããããŸãã ããã«ãããããã¢ãããã¯ã§è©³çŽ°ãªããªã·ãŒãå¯èœã«ãªããŸãã
SGTã¢ãŒããã¯ãã£ã¯4ã€ã®ã³ã³ããŒãã³ãã§æ§æãããŠããŸãã
SGTã¢ãŒããã¯ãã£ã¯4ã€ã®ã³ã³ããŒãã³ãã§æ§æãããŠããŸãã
- ã¿ã° ãŸããSGTã¿ã°ãå²ãåœãŠãå¿
èŠããããŸãã ãããè¡ãã«ã¯4ã€ã®æ¹æ³ããããŸãã
- IPã¢ãã¬ã¹ã«åºã¥ããŸã ã ãã®ãããªãããã¯ãŒã¯ã¯å
éšçãªãã®ã§ãããç¹å®ã®IPã¢ãã¬ã¹ã«åºã¥ããŠæå®ã§ããŸããããšãã°ããããã¯ãŒã¯10.31.10.0/24ã¯ãµãŒããŒã»ã°ã¡ã³ãã§ãããåãã«ãŒã«ãé©çšããŸãã ãã®ãµãŒããŒã»ã°ã¡ã³ãå
ã«ã¯ãPCI DSSãæ
åœãããµãŒããŒããããŸããããå³ããã«ãŒã«ãé©çšããŸãã ãã®å ŽåããµãŒããŒãã»ã°ã¡ã³ããã移åããå¿
èŠã¯ãããŸããã
ãªãããã䟿å©ãªã®ã§ããïŒ ãã¡ã€ã¢ãŠã©ãŒã«ãã©ããã«å®è£ ããããå³æ Œãªã«ãŒã«ãäœæããå Žåã¯ããµãŒããŒã顧客ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«é 眮ããå¿ èŠããããŸããããã¯ãå€ãã®å Žåã管çãé£ãããã®ã§ãã ãµãŒããŒãé£æ¥ãµãŒããŒãšéä¿¡ããã¹ãã§ã¯ãªããå¥ã®ã»ã°ã¡ã³ãã§éžæããæ¹ãè¯ããšèãã人ã¯ããŸããã§ããã ãŸãããã¡ã€ã¢ãŠã©ãŒã«ãå®è£ ããå Žåã1ã€ã®ã»ã°ã¡ã³ãããå¥ã®ã»ã°ã¡ã³ããžã®æšå¥šäºé ã«åŸã£ãŠãµãŒããŒã移è¡ããã®ã«æãæéãããããŸãã SGTã®å Žåãããã¯å¿ èŠãããŸããã - VLANã«åºã¥ããŸã ã VLAN1ãã©ãã«1ãVLAN10ãã©ãã«10ãªã©ã®ããã«æå®ã§ããŸãã
- ã¹ã€ããããŒãã«åºã¥ããŸã ã ããŒãã«é¢ããŠãåãããšãã§ããŸããããšãã°ãã¹ã€ããã®ããŒã24ããã®ãã¹ãŠã®ããŒã¿ã«10ã®ã©ãã«ãä»ããŸãã
- æåŸã®æãèå³æ·±ãæ¹æ³-ISEã䜿çšããåçãªã©ãã«ä»ã ã ã€ãŸããCisco ISEã¯ACLã®å²ãåœãŠããªãã€ã¬ã¯ããžã®éä¿¡ãªã©ã ãã§ãªããSGTã¿ã°ãå²ãåœãŠãããšãã§ããŸãã ãã®çµæãåçã«æ±ºå®ããããšãã§ããŸãããã®ãŠãŒã¶ãŒã¯ãã®ã»ã°ã¡ã³ãããæ¥ãŸããããã®ãããªãšãã«ã圌ã¯ãã®ãããªãã¡ã€ã³ã¢ã«ãŠã³ããIPã¢ãã¬ã¹ãæã£ãŠããŸãã ãããŠããã§ã«ãã®ããŒã¿ã«åºã¥ããŠã©ãã«ãå²ãåœãŠãŠããŸãã
- IPã¢ãã¬ã¹ã«åºã¥ããŸã ã ãã®ãããªãããã¯ãŒã¯ã¯å
éšçãªãã®ã§ãããç¹å®ã®IPã¢ãã¬ã¹ã«åºã¥ããŠæå®ã§ããŸããããšãã°ããããã¯ãŒã¯10.31.10.0/24ã¯ãµãŒããŒã»ã°ã¡ã³ãã§ãããåãã«ãŒã«ãé©çšããŸãã ãã®ãµãŒããŒã»ã°ã¡ã³ãå
ã«ã¯ãPCI DSSãæ
åœãããµãŒããŒããããŸããããå³ããã«ãŒã«ãé©çšããŸãã ãã®å ŽåããµãŒããŒãã»ã°ã¡ã³ããã移åããå¿
èŠã¯ãããŸããã
- ã¿ã°å ±æ ã å²ãåœãŠãããã©ãã«ãé©çšå ã«è»¢éããå¿ èŠããããŸãã ãã®ããã«ãSXPãããã³ã«ã䜿çšãããŸãã
- SGTããªã·ãŒ ã ããã¯äžèšã§èª¬æãããããªãã¯ã¹ã§ãããã©ã®ã€ã³ã¿ã©ã¯ã·ã§ã³ã䜿çšã§ããã©ã®ã€ã³ã¿ã©ã¯ã·ã§ã³ã䜿çšã§ããªããã瀺ããŠããŸãã
- SGTã®åŒ·å¶äœ¿çš ã ãããã¹ã€ããã®æ©èœã§ãã
SGTã«åºã¥ãèå³æ·±ããããžã§ã¯ã
çŸåšã顧客ã®1人ã§IPãšSGTã®ãããã³ã°ãæ§æãã13ã®ã»ã°ã¡ã³ããåºå¥ã§ããããã«ãªããŸããã ãããã¯å€ãã®ç¹ã§éè€ããŠããŸãããç¹å®ã®ãã¹ããŸã§åžžã«æäžäœã®ãšã³ããªãéžæãããç²åºŠã®ãããã§ãããããã¹ãŠãã»ã°ã¡ã³ãåããããšãã§ããŸããã ISEã¯ãã©ãã«ãããªã·ãŒãIPããã³SGTã³ã³ãã©ã€ã¢ã³ã¹æ å ±ã®åäžã®ãªããžããªãšããŠäœ¿çšãããŸãã ãŸããã©ãã«ãå®çŸ©ããŸããïŒ12-éçºã13-æ¬çªã11-ãã¹ãã ããã«ã12ãã13ã®éã¯HTTPSãããã³ã«ãä»ããŠã®ã¿éä¿¡å¯èœã§ããã12ãã11ã®éã¯çžäºäœçšããªãããã«ãããªã©ã®æ±ºå®ããªãããŸããã çµæã¯ããããã¯ãŒã¯ãšãã¹ããšããã«å¯Ÿå¿ããã©ãã«ã®ãªã¹ãã§ãã ãŸããã·ã¹ãã å šäœãã客æ§ã®ããŒã¿ã»ã³ã¿ãŒã®4ã€ã®Nexus 7000ã«å®è£ ãããŠããŸãã
ã客æ§ã«ã¯ã©ã®ãããªã¡ãªããããããŸãããïŒ
çŸåšãååæ¿æ²»å®¶ã¯åœŒã«å©çšå¯èœã§ãã ãããããã¯ãŒã¯ã§ã管çè ã誀ã£ãŠå¥ã®ãããã¯ãŒã¯ãããµãŒããŒãå±éããããšããããŸãã ããšãã°ãå®çšŒåç°å¢ã®ãã¹ããéçºãããã¯ãŒã¯ã§å€±ãããŸããã ãã®çµæããµãŒããŒã転éããIPãå€æŽããé£æ¥ãµãŒããŒãšã®æ¥ç¶ãåæãããŠããªãã確èªããå¿ èŠããããŸãã ããããä»ã§ã¯ããå€éšããµãŒããŒãåã«ãã€ã¯ãã»ã°ã¡ã³ãåã§ããŸããããã¯ãä»ã®ãããã¯ãŒã¯ã®åå è ãšã¯ç°ãªããå®çšŒåã®äžéšãšããŠå®£èšããä»ã®ã«ãŒã«ãé©çšããŸãã ãããŠåæã«ããã¹ããä¿è·ãããŸãã
ããã«ã顧客ã¯ããªã·ãŒãäžå çãã€èé害çã«ä¿åããã³ç®¡çã§ããããã«ãªããŸããã
ããããISEã䜿çšããŠãŠãŒã¶ãŒã«ã©ãã«ãåçã«å²ãåœãŠãã®ã¯æ¬åœã«ã¯ãŒã«ã§ãã ããã¯ãIPã¢ãã¬ã¹ã ãã§ãªããæéããŠãŒã¶ãŒã®å ŽæããŠãŒã¶ãŒã®ãã¡ã€ã³ããã³ã¢ã«ãŠã³ãã«åºã¥ããŠè¡ãããšãã§ããŸãã ãã®ãŠãŒã¶ãŒãæ¬ç€Ÿã«åº§ã£ãŠããå Žåãç¹æš©ãšæš©å©ã®ã¿ãæã¡ããã©ã³ãã«æ¥ãå Žåã圌ã¯ãã§ã«åºåŒµäžã§ãå¶éãããæš©å©ãæã£ãŠãããšèŠå®ã§ããŸãã
ISEèªäœã®ãã°ã確èªããããšæããŸãã çŸåšã4ã€ã®NexusãšISEãäžå€®ã¹ãã¬ãŒãžãšããŠäœ¿çšããå Žåãã¹ã€ããèªäœã«ã¢ã¯ã»ã¹ããŠãã°ã衚瀺ããã³ã³ãœãŒã«ã«ã¯ãšãªãéããå¿çããã£ã«ã¿ãªã³ã°ããå¿ èŠããããŸãã ãã€ãããã¯ãããã³ã°ã䜿çšãããšãISEããã°ã®åéãéå§ããç¹å®ã®æ§é ã«ã¢ã¯ã»ã¹ã§ããªãã£ããŠãŒã¶ãŒãããçç±ãäžå çã«ç¢ºèªã§ããŸãã
ãããã顧客ãããŒã¿ã»ã³ã¿ãŒã®ã¿ãä¿è·ããããšã決å®ããããããããŸã§ã®ãšããããããã®æ©èœã¯å®çŸãããŠããŸããã ãããã£ãŠããŠãŒã¶ãŒã¯å€éšããæ¥ãŠãããISEã«æ¥ç¶ãããŠããŸããã
Cisco ISEã®æŽå²
èªèšŒå±
ãã®éèŠãªé©æ°ã¯ã2013幎10æã«ããŒãžã§ã³1.3ã§ç»å ŽããŸããã ããšãã°ãã¯ã©ã€ã¢ã³ãã®1ã€ã«ã蚌ææžã®ã¿ã§æ©èœããããªã³ã¿ãŒããããŸãããã€ãŸãããã¹ã¯ãŒãã§ã¯ãªãããããã¯ãŒã¯äžã®èšŒææžã®ã¿ã§èªèšŒããæ¹æ³ãç¥ã£ãŠããŸããã ã¯ã©ã€ã¢ã³ãã¯ãCAããªãããã«ããã€ã¹ã«æ¥ç¶ã§ããã5å°ã®ããªã³ã¿ãŒã®ããã«ããã€ã¹ãå±éããããªãã£ãããšã«è ¹ãç«ãŠãŸããã ãã®åŸãçµã¿èŸŒã¿ã®APIã䜿çšããŠã蚌ææžãçºè¡ããããªã³ã¿ãŒãéåžžã®æ¹æ³ã§æ¥ç¶ã§ããŸããã
Cisco ASAèªå¯å€æŽïŒCoAïŒã®ãµããŒã
Cisco ASAã§ã®CoAãµããŒãã®åºçŸä»¥æ¥ããªãã£ã¹ã«æ¥ãŠãããã¯ãŒã¯ã«æ¥ç¶ãããŠãŒã¶ãŒã ãã§ãªãããªã¢ãŒããŠãŒã¶ãŒãå¶åŸ¡ã§ããŸãã ãã¡ããã以åã¯ãããå®è¡ã§ããŸãããããã®ããã«ã¯ããã©ãã£ãã¯ããããã·ããæ¿èªããªã·ãŒãé©çšããããã«å¥ã®IPNããŒãããã€ã¹ãå¿ èŠã§ããã ã€ãŸããVPNãçµäºãããã¡ã€ã¢ãŠã©ãŒã«ããããšããäºå®ã«å ããŠãCisco ISEã§ã«ãŒã«ãé©çšããããã ãã«å¥ã®ããã€ã¹ã䜿çšããå¿ èŠããããŸããã ããã¯é«äŸ¡ã§äžå¿«ã§ããã
ããŒãžã§ã³9.2.1ã§ã¯ã2014幎12æã«ããã³ããŒã¯æçµçã«Cisco ASAã«èš±å¯ã®å€æŽã®ãµããŒããè¿œå ãããã®çµæããã¹ãŠã®Cisco ISEæ©èœããµããŒããããŸããã 顧客ã®äœäººãã¯åãã§ããæ¯ãã€ããVPNãã©ãã£ãã¯ãçµäºããã ãã§ãªãã解æŸãããIPNããŒãã䜿çšããããšãã§ããŸããã
TACACS +
ç§ãã¡ã¯çããã®ãããã³ã«ã®å®è£ ãéåžžã«é·ãéåŸ ã£ãŠããŸããã TACACS +ã䜿çšãããšã管çè ãèªèšŒãããã®ã¢ã¯ãã£ããã£ãèšé²ã§ããŸãã ãããã®æ©èœã¯ã管çå¶åŸ¡çšã®PCI DSSãããžã§ã¯ãã§é »ç¹ã«éèŠããããŸãã 以åã¯ãCisco ISEãæçµçã«æ©èœã䜿çšãããŸã§ããã®ããã®å¥ã®Cisco ACS補åããããŸãããããã£ãããšæ¶æ» ããŠããŸããã
AnyConnectãã¹ãã£
AnyConnectã§ã®ãã®æ©èœã®å€èŠ³ã¯ãCisco ISEã®ç»æçãªæ©èœã®1ã€ã«ãªããŸããã 次ã®å³ã«ã©ã®æ©èœã衚瀺ãããŠããŸããã ãã¹ãã£ããã»ã¹ã¯æ¬¡ã®ããã«ãªããŸãããŠãŒã¶ãŒã¯ïŒãã°ã€ã³ããã¹ã¯ãŒãã蚌ææžããŸãã¯MACã«ãã£ãŠïŒèªèšŒãããCisco ISEããã®å¿çã§ã¢ã¯ã»ã¹ã«ãŒã«ãå«ãããªã·ãŒãå°çããŸãã
ãŠãŒã¶ãŒã®ã³ã³ãã©ã€ã¢ã³ã¹ã確èªããå¿ èŠãããå Žåããªãã€ã¬ã¯ãããŠãŒã¶ãŒã«éä¿¡ãããŸããããã¯ããŠãŒã¶ãŒã®ãã©ãã£ãã¯ã®ãã¹ãŠãŸãã¯äžéšãç¹å®ã®ã¢ãã¬ã¹ã«ãªãã€ã¬ã¯ãããç¹å¥ãªãªã³ã¯ã§ãã ãã®æç¹ã§ã®ã¯ã©ã€ã¢ã³ãã«ã¯ããã¹ãã£çšã®ç¹å¥ãªãšãŒãžã§ã³ããããŠãããã¯æã ãªã³ã©ã€ã³ã«ãªã£ãŠåŸ æ©ããŸãã ISEãµãŒããŒã«ãªãã€ã¬ã¯ããããå Žåãããããããªã·ãŒãååŸããããã䜿çšããŠã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ã³ã³ãã©ã€ã¢ã³ã¹ã確èªããããã€ãã®çµè«ãå°ãåºããŸãã
ãšãŒãžã§ã³ãã¯ã5åããšã«1åãã€URLã確èªããŠããŸããã ããã¯é·ããäžäŸ¿ã§ãããåæã«ç©ºã®ãã©ãã£ãã¯ã§ãããã¯ãŒã¯ãæ··ä¹±ãããŸããã æåŸã«ããã®ã¡ã«ããºã ã¯AnyConnectã«å«ãŸããŠããŸãã ãããã¯ãŒã¯ã¬ãã«ã®åœŒã¯ãäœãã圌女ã«èµ·ãã£ãããšãç解ããŠããŸãã ãããã¯ãŒã¯ã«æ¥ç¶ãŸãã¯åæ¥ç¶ããããWi-Fiã«æ¥ç¶ããããVPNãæ§ç¯ãããšä»®å®ããŸããAnyConnectã¯ããããã¹ãŠã®ã€ãã³ãã«ã€ããŠåŠç¿ãããšãŒãžã§ã³ãã®ããªã¬ãŒãšããŠæ©èœããŸãã ããã«ããããã¹ãã£ã®éå§ãŸã§ã®åŸ æ©æéã4ã5åãã15ç§ã«å€æŽãããŸããã
æ©èœã®æ¶å€±
ããããã®ããŒãžã§ã³ã§æåã«å§¿ãæ¶ããæ©èœã®èå³æ·±ãã±ãŒã¹ãããããã°ãããããšãããè¿ãããŸããã
Cisco ISEã«ã¯ã²ã¹ãã¢ã¯ã»ã¹ã¢ã«ãŠã³ãããããŸããç§æžã§ãããã¹ã¯ãŒããçºè¡ã§ãããããã¯ãŒã¯ã§ãã ãŸããã·ã¹ãã 管çè ãå€æ°ã®ã²ã¹ãã¢ã«ãŠã³ããäœæããå°çã«å°å°ããŠè²¬ä»»è ã«æž¡ãããšãã§ããå Žåãéåžžã«äŸ¿å©ãªæ©èœããããŸãã ãããã®ã¢ã«ãŠã³ãã¯ç¹å®ã®æéæå¹ã§ãã ããšãã°ãåœç€Ÿã§ã¯ãããã¯æåã®ãšã³ããªããã®é±ã§ãã ãŠãŒã¶ãŒã¯å°çãåãåãããããå°å·ããŠå ¥åããã«ãŠã³ã¿ãŒãå»ã¿å§ããŸãã 䟿å©ã§å®çšçã
åœåããã®æ©èœã¯Cisco ISEã®å°å ¥ä»¥æ¥ã§ããããããŒãžã§ã³1.4ã§ã¯å§¿ãæ¶ããŸããã ãããŠæ°å¹ŽåŸãããŒãžã§ã³2.1ã§åœŒå¥³ãè¿ãããŸããã ã²ã¹ãã¢ã¯ã»ã¹ãäžè¶³ããŠããããã2幎以äžãã®éãããžãã¹ããã»ã¹ãåæ§ç¯ããæºåãã§ããŠããªãã£ãããã瀟å ã®Cisco ISEããŒãžã§ã³ãæŽæ°ããŠããŸããã
* * *
é¢çœããã°
å¥ãã§ãé¢çœã話ãæãåºãããŸããã èŠããŠãããŠãç§ãã¡ã¯éåžžã«å³ããã»ãã¥ãªãã£ããªã·ãŒãæã€ã¯ã©ã€ã¢ã³ãã«ã€ããŠè©±ããŸãããïŒ æ¥µæ±ã«ãããããã«ã¿ã€ã ãŸãŒã³ãå€æŽããããšãGMT + 10ã§ã¯ãªãGMT + 11ã«ãªããŸããã ãããŠã顧客ã¯ãã¢ãžã¢/ãµããªã³ããèšå®ããã ããªã®ã§ãæ£ç¢ºãªæé衚瀺ãå®çŸããããã«åœŒã¯ç§ãã¡ã«é ŒããŸããã
ã·ã¹ã³ã«é£çµ¡ããŸããããè¿ããã¡ã«æéããããããããããã¿ã€ã ãŸãŒã³ãæŽæ°ããªããšåçããŸããã 圌ãã¯æšæºã®GMT + 11ãŸãŒã³ã®äœ¿çšãææ¡ããŸããã ç§ãã¡ã¯ãããã»ããã¢ããããŸããããã·ã¹ã³ã¯è£œåãååã«ãã¹ãããŠããªãããšãããããŸããããã«ãã¯GMT-11ã«ãªããŸããã ã€ãŸããã¯ã©ã€ã¢ã³ãã®æéã¯12æéé²ã¿ãŸããã é¢çœãããšã«ãã«ã ãã£ãã«ãšãµããªã³ã¯GMT + 11ã«ããã2ã€ã®ã¢ã¡ãªã«ã®å³¶ã¯GMT-11ã«ãããŸãã ã€ãŸããã·ã¹ã³ã¯ããããã®ã¿ã€ã ãŸãŒã³ããã ããã補åãè³Œå ¥ããããšãæ³å®ããŠãããããã¹ããå®æœããŸããã§ããã 圌ãã¯ãã®ãã°ãããªãé·ãéä¿®æ£ããè¬çœªããŸããã
Jet Infosystemsã®ãšã³ãžãã¢ãªã³ã°ãµããŒãããã³æ å ±ã»ãã¥ãªãã£ãµãŒãã¹éšéã®å°é家ã§ããStanislav Kalabin