
ãã®èšäºã§ã¯ãCheck Pointã䜿çšããŠåæ£ãããã¯ãŒã¯ãæ§ç¯ããããã®ãªãã·ã§ã³ãæ€èšããŸãã Check Pointã®ãµã€ãéVPNã®äž»ãªæ©èœã説æããããã€ãã®å žåçãªã·ããªãªãæ€èšããããããã®é·æãšçæã説æããåæ£VPNãããã¯ãŒã¯ãèšç»ããéã«ãéãç¯çŽã§ããæ¹æ³ã説æããããšããŸãã
ãã§ãã¯ãã€ã³ãã¯æšæºIPSecã䜿çš
ããã¯ããã§ãã¯ãã€ã³ãã®ãµã€ãéVPNã«ã€ããŠæåã«ç¥ã£ãŠããã¹ãããšã§ãã ãã®è«æã¯ãCheck Point VPNã«é¢ããæãäžè¬çãªè³ªåã®1ã€ã«çããŸãã
-ä»ã®ããã€ã¹ãšãåéãäœããããšã¯å¯èœã§ããïŒ
-ã¯ããã§ããŸãïŒ
ãããããµãŒãããŒãã£VPNã æšæºã®IPSecã䜿çšãããŠãããããVPNã¯IPSecããµããŒãããããã€ã¹ã§æ§ç¯ã§ããŸãã å人çã«ã¯ãCisco ASAãCiscoã«ãŒã¿ãŒãD-LinkãMikrotikãStoneGateã§VPNãæ§ç¯ããããšããŸããã ããã€ãã®æ©èœããããŸããããã¹ãŠãæ©èœããŸãã äž»ãªããšã¯ã第1ãã§ãŒãºãšç¬¬2ãã§ãŒãºã®ãã¹ãŠã®ãã©ã¡ãŒã¿ãŒãæ£ããèšå®ããããšã§ãã IPSecæ¥ç¶ã§ãµããŒãããããã©ã¡ãŒã¿ãŒïŒ
æå·åæ¹åŒïŒIKEv1ãIKEv2
IKE Security AssociationïŒãã§ãŒãº1ïŒ
-æå·åã¢ã«ãŽãªãºã ïŒAES-128ãAES-256ãDESã3DESãCAST
-ããŒã¿ã®æŽåæ§ïŒSHA1ãSHA256ãSHA384ãMD5ãAES-XCBC
-Diffie-Hellmanã°ã«ãŒãïŒã°ã«ãŒã1ãã°ã«ãŒã2ãã°ã«ãŒã5ãã°ã«ãŒã14ãã°ã«ãŒã19ãã°ã«ãŒã20
IKEã»ãã¥ãªãã£ã¢ãœã·ãšãŒã·ã§ã³ïŒãã§ãŒãº2ïŒ
-æå·åã¢ã«ãŽãªãºã ïŒAES-128ãAES-256ãAES-GCM-128ãAES-GCM-256ãDESã3DESãDES-40CPãCASTãCAST-40ãNULL
-ããŒã¿ã®æŽåæ§ïŒSHA1ãSHA256ãSHA384ãMD5ãAES-XCBC
è¿œå ãªãã·ã§ã³ïŒ
-ã¢ã°ã¬ãã·ãã¢ãŒãã䜿çšããïŒãã§ãŒãº1ïŒ
-Perfect Forward Secrecyã䜿çšããïŒãã§ãŒãº2ïŒ
-IPå§çž®ã®ãµããŒãïŒãã§ãŒãº2ïŒ
ãªããªã Check Pointã ãã§ãªããVPNãæ§ç¯ããããšãã§ããŸãããã®å Žåãããã«åé¡ãçºçããŸãããã©ã³ãã«ãã€ã³ã¹ããŒã«ããããã®ã¯äœã§ããïŒ
æ¯åºã«äœ¿çšããæ©åšã¯äœã§ããïŒ
éžæè¢ã¯2ã€ã ãã§ãã ããããèæ ®ããããããã®é·æãšçæã説æããŠã¿ãŠãã ããã
1.ãã©ã³ãã®ãã§ãã¯ãã€ã³ã
ãããæãç°¡åãªãªãã·ã§ã³ã§ãã Check Pointã¯ãã»ã³ãã©ã«ãªãã£ã¹ïŒHQïŒãšãã©ã³ãïŒãã©ã³ãïŒã«ã€ã³ã¹ããŒã«ãããŠããŸãã
é·æ ã äž»ãªãã©ã¹ã¯äœ¿ããããã§ãã ã»ãã¥ãªãã£ããªã·ãŒã¯1ãæãã管çããŸãïŒã»ãã¥ãªãã£ç®¡çãµãŒããŒïŒã ãã¹ãŠã®ãã°ã¯1ãæã«ä¿åãããŸãã ã¬ããŒããçæããå šäœåãèŠãããšãã§ããŸãã åæ£ãããã¯ãŒã¯ç®¡çãå€§å¹ ã«ç°¡çŽ åãããŸãã ç£èŠã·ã¹ãã ããå¿ èŠãªããããããŸãã;æ©èœã®ããã€ãã¯äžå€®ç®¡çãµãŒããŒã«ãã£ãŠããã©ã«ãã§å®è¡ãããŸãã VPNèšå®ãé«éåãããã¢ã¯ã»ã¹ãªã¹ããç¡éã«ç·šéããå¿ èŠããªããªããŸããã 倧ãŸããªæŠç®ã§ã¯ããããCisco DMVPNãšæ¯èŒã§ããŸãïŒè©³çŽ°ã¯åŸè¿°ïŒã
çæ å¯äžã®ãã€ãã¹ã¯ã財åã³ã¹ãã§ãã ãã¡ããããé«äŸ¡ãŸãã¯å®äŸ¡ããšãã質åã¯å°ãå²åŠçã§ããããã®ãããã¯ã«ã€ããŠã¯èª¬æããŸããã ãã ããæå°ã®ãã©ã³ãïŒATMã§ããïŒã§ãCheck Pointã²ãŒããŠã§ã€ãã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã å°ãåŸã§ããã®ãããªã¿ã¹ã¯ã®ç¹å®ã®ã¢ãã«ã«ã€ããŠèª¬æããŸãã
ãã®ãªãã·ã§ã³ã䜿çšããã®ã¯èª°ã§ããïŒãã©ã³ãã®ãã§ãã¯ãã€ã³ãïŒïŒ å®éãã»ãšãã©ãã¹ãŠã®ããžãã¹ã»ã°ã¡ã³ãïŒéè¡ãå°å£²ãç£æ¥ããã«ã¹ã±ã¢ãç³æ²¹ããã³ã¬ã¹äŒç€Ÿã

å³ 1.ãã¹ãŠã®ãã©ã³ãã²ãŒããŠã§ã€ã衚瀺ãããCheck Point SmartConsole
2.ãã©ã³ãã§ãã€ã³ãããã§ãã¯ããªãã§ãã ãã
ãŸããããªãäžè¬çãªãªãã·ã§ã³ã§ãã ã»ã³ã¿ãŒïŒHQïŒã«ã¯ãã§ãã¯ãã€ã³ããèšå®ããããã©ã³ãïŒãã©ã³ãïŒã«ã¯IPSec VPNããµããŒãããä»ã®ããã€ã¹ãèšå®ãããŠããŸãã
é·æ ã ããããå¯äžã®ãã©ã¹ã¯ãæå°éã®è²¡åã³ã¹ãã§ãã æãå®äŸ¡ãªMikrotikãŸãã¯D-Linkãé 眮ã§ããŸããã»ã³ãã©ã«ãªãã£ã¹ãžã®VPNã¯æ£åžžã«æ©èœããŸãã
çæ çæã¯ãã£ãšå€§ããã§ãã å®éã以åã®ããŒãžã§ã³ã§èª¬æãããã¹ãŠã®å©ç¹ã倱ãããŸãã åãã©ã³ãã®èšå®ããç·šéãããå¿ èŠããããŸãã 2ãã3ã®å Žåãããã¯ããã»ã©å€§ããªåé¡ã§ã¯ãªãã§ãããã ãããããããã®æ°ã5ã10ãè¶ ããå Žåããããªãã¹ã±ãŒãªã³ã°ã®æ·±å»ãªåé¡ãçºçããŸãã æ§æ管çãã¢ã¯ã»ã¹ããªã·ãŒãç£èŠãããããã¹ãŠã¯ããµãŒãããŒãã£ãœãªã¥ãŒã·ã§ã³ïŒãªãŒãã³ãœãŒã¹ã®å¯èœæ§ããããŸãïŒã«åºã¥ããŠæŽçããå¿ èŠããããŸãã å¥ã®å€§ããªãã€ãã¹-VPNãã£ãã«ã®äºçŽãæŽçããããšã¯äžå¯èœã§ãã
ãã®ãªãã·ã§ã³ã䜿çšããã®ã¯èª°ã§ããïŒãã©ã³ãã®ãã§ãã¯ãã€ã³ãã§ã¯ãããŸããïŒïŒ éåžžãããã¯å°æ°ã®æ¯åºãæã€å°èŠæš¡äŒæ¥ã§ãã
ã¢ãã£ãªãšã€ãã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã®çš®é¡ã ç¬ç«ãŸãã¯äžå åïŒ
ãã©ã³ãã®ããã€ã¹ã®éžæã¯ãã€ã³ã¿ãŒãããæ¥ç¶ã®ã¿ã€ãã«ãã£ãŠç°ãªããŸãã ãŸãã2ã€ã®ãªãã·ã§ã³ããããããããã«é·æãšçæããããŸãã
1.ç¬ç«ããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹
æãé »ç¹ã«äœ¿çšãããŸãã VPNãã£ãã«ã¯ãã»ã³ãã©ã«ãªãã£ã¹ïŒCheck Pointãç«ã€å ŽæïŒã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹å°çšã«äœ¿çšãããŸãã
é·æ ã ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã¯ãVPNãªãã£ã¹ãšã»ã³ãã©ã«ãªãã£ã¹ã®æ©åšã«äŸåããŸããã ã€ãŸã ã»ã³ãã©ã«ãªãã£ã¹ã®ãã¹ãŠããèœã¡ããå Žåãæ¯åºã¯ã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ãä¿æããäžéšã®äŒæ¥ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã倱ããŸãã
çæ ã»ãã¥ãªãã£ããªã·ãŒã®ç®¡çãå€§å¹ ã«è€éã«ããŸãã å®éããã©ã³ããä¿è·ããã¿ã¹ã¯ãããå Žåã¯ãIPSãã¹ããªãŒãã³ã°ãŠã€ã«ã¹å¯ŸçãURLãã£ã«ã¿ãªã³ã°ãªã©ã®ä¿è·å¯Ÿçãé©çšããå¿ èŠããããŸãã ããã¯ãæ å ±ã»ãã¥ãªãã£ã®ç®¡çãšç£èŠã«é¢ããå€ãã®åé¡ã«ã€ãªãããŸãã
æšå¥šäºé ãã¡ããããã®ãªãã·ã§ã³ã§ã¯ããã©ã³ãã§ãã§ãã¯ãã€ã³ãã䜿çšããããšããå§ãããŸãã ãã®ãã¹ãŠã®ãçµæžããäžå 管çã§ããŸãã 1ã€ã®æšæºã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ããªã·ãŒãäœæããããããã¹ãŠã®ãã©ã³ãã«å±éã§ããŸãã ç£èŠãå€§å¹ ã«ç°¡çŽ åãããŸãã ãã¹ãŠã®IBã€ã³ã·ãã³ãã1ãæã«è¡šç€ºãããã€ãã³ãã®çžé¢ã®å¯èœæ§ããããŸãã
2.äžå åãããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹
ãã®ãªãã·ã§ã³ã¯ããŸãé »ç¹ã«äœ¿çšãããŸããã äžå€®ãªãã£ã¹ïŒCheck Pointãååšããå ŽæïŒã«å¯ŸããŠVPNãæ§ç¯ãããŠããããã¹ãŠã®ãã©ã³ããã©ãã£ãã¯ãããã«ã©ãããããŠããŸãã ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã¯ãã»ã³ãã©ã«ãªãã£ã¹çµç±ã§ã®ã¿å¯èœã§ãã
é·æ ã ãã®å Žåãåºæ¬çã«ãã©ã³ãã«äœããããã¯æ°ã«ããŸãããäž»ãªããšã¯ãã»ã³ã¿ãŒãžã®VPNãæ§ç¯ããããšã§ãã configã«ã¯å€§ããªåé¡ã¯ãªãã¯ãã§ãã å®éããVPNå ã®ãã¹ãŠã®ãã©ãã£ãã¯ããšããã«ãŒã«ã1ã€ã ããããŸãã ãã¹ãŠã®ã»ãã¥ãªãã£ããªã·ãŒãšã¢ã¯ã»ã¹ãªã¹ãã¯ãã»ã³ãã©ã«ãªãã£ã¹ã§ã®ã¿èšå®ããŸãã ãåç¥ã®ããã«ããã®ãªãã·ã§ã³ã䜿çšãããšãCheck Pointã®è³Œå ¥ãå€§å¹ ã«ç¯çŽã§ããŸãã
çæ ã¹ã±ãŒã©ããªãã£ã管çãããã³ç£èŠã«ã¯äŸç¶ãšããŠåé¡ããããŸãïŒãã ããã€ã³ã¿ãŒããããžã®ç¬ç«ããã¢ã¯ã»ã¹ã»ã©éèŠã§ã¯ãããŸããïŒã ããã«ãæ¯åºã®æ¥åã¯äžå€®ãªãã£ã¹ã«å®å šã«äŸåããŠããŸãã ç·æ¥ã®å Žåããããã¯ãŒã¯å šäœããèœã¡ããŸãã ã¢ãã£ãªãšã€ãã¯ã€ã³ã¿ãŒããããªãã§æŸçœ®ãããŸãã
æšå¥šäºé ãã®ãªãã·ã§ã³ã¯ãå°æ°ã®ãã©ã³ãïŒ2ã4ïŒã«æé©ã§ãã ãã¡ãããè¡šæããããªã¹ã¯ã«æºè¶³ããŠããå ŽåïŒã»ã³ã¿ãŒãžã®äŸåïŒã ã»ã³ãã©ã«ãªãã£ã¹ã«Check Pointããã€ã¹ãéžæããå Žåããã©ã³ããã©ãã£ãã¯ãèæ ®ããå¿ èŠãªããã©ãŒãã³ã¹ãæ éã«èšç®ãã䟡å€ããããŸãã åºæ¬çã«ãæå°éã®è²¡åã³ã¹ãã§ãã©ã³ãã®ãã©ãã£ãã¯ç®¡çãéäžåã§ããŸãã ãã ããå€æ°ã®ãã©ã³ãïŒããã³ãæ·±å»ãªããã©ãã£ãã¯ïŒãããå Žåããã®ãããªã¹ããŒã ã¯åŒ·ãæšå¥šãããŸããã 倱æããå Žåã®çµæã¯å€§ããããŸãã ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã¯è€éã«ãªããäžå€®ãªãã£ã¹ã«ã¯éåžžã«åŒ·åãªããŒããŠã§ã¢ãå¿ èŠã«ãªãããã©ã³ãã«ç¬èªã®Check Pointã²ãŒããŠã§ã€ãããå Žåãããæçµçã«é«äŸ¡ã«ãªãå¯èœæ§ããããŸãã
ã©ã€ã»ã³ã¹ã®ç¯çŽã®å¯èœæ§
ãã©ã³ãã§Check Pointã䜿çšããããšã決å®ããVPNã®ã¿ãå¿ èŠãªå ŽåïŒããšãã°ãéäžåã€ã³ã¿ãŒãããæ¥ç¶ïŒãã©ã€ã»ã³ã¹ãå€§å¹ ã«ç¯çŽã§ããŸãã ãã¬ãŒãIPSec VPNã¯ãããªãæ¹æ³ã§ãã©ã€ã»ã³ã¹ãããŠããŸããã ããã€ã¹ãè³Œå ¥ãããšãåžžã«ãã¡ã€ã¢ãŠã©ãŒã«ãšVPNæ©èœãå©çšã§ããŸãã ãã®ããã«ãµãŒãã¹ã®æ¡åŒµæ©èœãè³Œå ¥ããå¿ èŠã¯ãããŸããããã¹ãŠããšã«ããåäœããŸãã
è³Œå ¥ããªããã°ãªããªãã®ã¯ãã¯ãã«ã«ãµããŒããµãŒãã¹ã®ã¿ã§ãæ éããå Žåã«ãµããŒãã«é£çµ¡ããŠããã€ã¹ã亀æã§ããŸãã ãã ãã ãéãç¯çŽãããªãã·ã§ã³ããããŸã ïŒãã ãããå§ãããŸããïŒã ç¥èã«èªä¿¡ãããããµããŒãã«é£çµ¡ããå¿ èŠããªãå Žåã¯ããã¯ãã«ã«ãµããŒãã®å»¶é·ãè³Œå ¥ããããšã¯ã§ããŸããã
ã¹ãã¢ããŒãã§1ã€ãŸãã¯2ã€ã®ããã€ã¹ãè³Œå ¥ã§ããŸãããã©ã³ãã®1ã€ãæ éããå Žåã¯ããã®ããã€ã¹ãå€æŽããã ãã§ãã å€æ°ã®æ¯ç€Ÿãããå Žåãä»ã®ãã¹ãŠã®ããã€ã¹ã®ãµããŒããè³Œå ¥ããããããäºåã®ããã€ã¹ãè³Œå ¥ããæ¹ãçµæžçã«æå©ã§ãã ç¹°ãè¿ããŸããããã®ãªãã·ã§ã³ã¯ãå§ãããŸããã
ãã©ã³ããã€ã³ããã§ãã¯ãã€ã³ãïŒSMBïŒã¢ãã«
Check Pointã¯å€§äŒæ¥å°çšã®ãã³ããŒã§ãããšããæèŠããããŸãã ãã ããã©ã€ã³ãããã«ã¯ãSMBã»ã¯ã¿ãŒçšã®ããã€ã¹ãªãã·ã§ã³ãããªããããŸãã ç¹ã«ããã®ãéçããæ¯åºã«äœ¿çšãããæ¬ç€Ÿã®äžå€®ç®¡çãµãŒããŒã«ãã£ãŠç®¡çãããå Žåã

å³ 2.ãã§ãã¯ãã€ã³ãã®ã©ã€ã³ããã
SMBãœãªã¥ãŒã·ã§ã³ã«é¢ããå¥ã®èšäºãæ¢ã«å ¬éããŠããããããã©ã³ãã§æãé »ç¹ã«äœ¿çšãããã¢ãã«ããªã¹ãããŸãã
- 倧èŠæš¡æ¯åºïŒ150ã200人ïŒåãã®5000ã·ãªãŒãºïŒ5100ã5200ïŒã
- äžèŠæš¡ãã©ã³ãïŒ100ã150人ïŒçšã®3000çªç®ã®ã·ãªãŒãºïŒ3100ã3200ïŒã
- å°æïŒ100人æªæºïŒçšã®1400çªç®ã®ã·ãªãŒãºïŒ1430ã1450ã1470ã1490ïŒã
人æ°ã«é¢ããããŒã¿ã¯ãçµéšã«åºã¥ã䞻芳çãªæèŠã®ã¿ã§ãã ARMããã»ããµãããŒã¹ã«ããæ¯èŒçæ°ããã¢ãã«ã§ãã1400ã·ãªãŒãºã«æ³šæããããšã匷ããå§ãããŸãã å€ãã¢ãã«ãšæ¯èŒããŠæè¡çãªå¶éããããŸãïŒç°ãªãOS-Gaia Embeddedã䜿çšããŠããããïŒãã管çãµãŒããŒã§ã¯ãç¹ã«ãã©ã³ããããã¯ãŒã¯ã®å Žåããããã®å¶éã¯éèŠã§ã¯ãããŸããã
VPNããããžïŒéå§ãã¡ãã·ã¥ïŒ
ããã«ãæè¡çãªãããšã«ã€ããŠè©±ããVPNããããžïŒãã§ãã¯ãã€ã³ãã®çšèªã§ã®VPNã³ãã¥ããã£ïŒããå§ããŸãããã ä»ã®ãã³ããŒãšåæ§ã«ãCheck Pointã«ã¯2ã€ã®ã¿ã€ãããããŸãã
- æ ååã¯ããèªäœãç©èªã£ãŠããŸãã ãã¹ãŠã®ãã©ã³ãããã®VPNãã£ãã«ã¯ã»ã³ã¿ãŒã«åæããŸãã ãã®ãããªããããžã§ã¯ããã©ã³ããçžäºã«éä¿¡ããå¿ èŠãããå Žåã§ãããã©ãã£ãã¯ã¯ã»ã³ã¿ãŒãééããŸãã æã«ã¯éåžžã«äŸ¿å©ã§å®çšçã§ã¯ãããŸããã å®éã«ã¯ããã®ããããžãæããã䜿çšãããŸããã
- ã¡ãã·ã¥ ããããžãŒã¯ãããããã«ãã ãã¯ãã»ã³ã¿ãŒã¯ãããŸããã 1ã€ã®ã¡ãã·ã¥VPNã³ãã¥ããã£ã«é 眮ããããã¹ãŠã®ã²ãŒããŠã§ã€ã¯ãäºãã«ãã³ãã«ãæ§ç¯ã§ããŸãã

ãããã®2ã€ã®ããããžãçµã¿åãããããšãæ°ã«ãã人ã¯ããªãããšã«æ³šæããŠãã ããã ããšãã°ã1ã€ã®ã¡ãã·ã¥ãä»ããŠ2ã€ã®éå§ã³ãã¥ããã£ããªã³ã¯ããŸãã

å³ 3.ã¹ã¿ãŒ+ã¡ãã·ã¥
2çš®é¡ã®ãã³ãã«
æåŸã«ããã©ã³ãã«ãCheck Pointããããšããæ¡ä»¶ã§ãCheck Point VPNãæ¬åœã«äŸ¿å©ãªçç±ã説æã§ããããã«ãªããŸããã VPNãã³ãã«ãæ§ç¯ããå Žåã2ã€ã®ã¿ã€ãã®éžæè¢ããããŸãã
1.ãã¡ã€ã³ããŒã¹ã®VPN
æå³ã¯éåžžã«ç°¡åã§ãã ãã©ã³ãã²ãŒããŠã§ã€ïŒããã³äžå€®ïŒã®ããããã£ã§ããã§ãã¯ãã€ã³ãã®èåŸã«ãããããã¯ãŒã¯ãæå®ããŸãã æ¯åºã®ããŒã«ã«ãããã¯ãŒã¯ã

å³ 4. VPNãã¡ã€ã³ã®å®çŸ©
ãã¹ãŠã®ã²ãŒããŠã§ã€ã1ã€ã®ç®¡çãµãŒããŒã®å¶åŸ¡äžã«ããããããã®æ å ±ã¯ãVPNã³ãã¥ããã£ã®ãã¹ãŠã®åå è éã§ïŒãã¹ã¿ãŒããŸãã¯ãã¡ãã·ã¥ãã§ããããåããïŒãæ··ä¹±ãããŠããŸãã ãããã£ãŠãåã²ãŒããŠã§ã€ã®VPNèšå®ãç·šéããå¿ èŠã¯ãããŸããããããã¯ãVPNãæ§ç¯ããããã®å Žæããããã¯ãŒã¯ãããã³IPSecãã©ã¡ãŒã¿ãŒãæ¢ã«ç¥ã£ãŠããŸãã åŠæ¹ãã¢ãã¢ã¯ã»ã¹ãªã¹ãã¯ãããŸããã ã»ããã¢ããã¯è¿ éãã€ç°¡åã§ãã ç§ã®æèŠã§ã¯ãDMVPNãããããã«äŸ¿å©ã§ãã ãã¡ã€ã³ããŒã¹ã®VPNã¯ãå®éã«æããã䜿çšãããŸãã
2.ã«ãŒãããŒã¹
ãã®ã¿ã€ãã®VPNã¯ãCiscoã®ãã¡ã³ã«ã¯éåžžã«éŠŽæã¿ã®ãããã®ã§ãã VTIïŒä»®æ³ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ïŒãã²ãŒããŠã§ã€äžã«äœæããããã³ãã«ã¢ãã¬ã¹ãæã€VPNãã£ãã«ãçºçããŸãã ãã³ãã«ã«ã©ãããããŠã«ãŒãã£ã³ã°ãããæå·åããããã©ãã£ãã¯ã ããã«ãã«ãŒãã¯éçãŸãã¯åçã®ããããã§ãã ããšãã°ããã¹ãŠã®ãã©ã³ãã§ãã®ãããªVPNãäžããOSPFãå®è¡ã§ããŸãã ãããã£ãŠããã¹ãŠã®ã²ãŒããŠã§ã€ã¯ã䜿çšå¯èœãªãã¹ãŠã®ãããã¯ãŒã¯ãèªèããå¿ èŠãªãã©ãã£ãã¯ãç®çã®ãã³ãã«ã«èªåçã«ãã©ãããããŸãã GREãã³ãã«ãšæ¯èŒã§ãããšæããŸãã
æšå¥šäºé
ã«ãŒãããŒã¹ã®VPNã¯ã ã»ãšãã©ã®å Žåããã¡ã€ã³ããŒã¹ã®VPNã§ååã§ãããç解ãããããã»ããã¢ãããé«éã§ãã åæã«ããã©ã³ãå ã®ãµãŒãããŒãã£è£œæ©åšïŒãã§ãã¯ãã€ã³ãã§ã¯ãªãïŒã®å Žåããã¡ã€ã³ããŒã¹ã®VPNã䜿çšã§ããŸãã ç¹°ãè¿ããŸãããå人çãªçµéšã«åºã¥ããŠããã¡ã€ã³ããŒã¹ã®VPNã®äœ¿çšããå§ãããŸãã åé¡ã¯ãã£ãšå°ãªããªããŸãã ã«ãŒãããŒã¹ã¯ãŸã£ãã䜿çšããªãæ¹ãããïŒå€ãã®å¶éãããã©ãŒãã³ã¹ã®äœäžïŒã ãã¡ããããã¯ãã¹ãŠããªãã®ã¿ã¹ã¯ã«äŸåããŸãããããããã®ã±ãŒã¹ã¯å¥ã ã«èæ ®ããå¿ èŠããããŸãã
蚌ææžãŸãã¯äºåå ±æããŒã®VPN
ä»ã®IPSec察å¿ããã€ã¹ãšåæ§ã«ãCheck Pointã¯äºåå ±æããŒãšèšŒææžã«åºã¥ããŠVPNãæ§ç¯ã§ããŸãã 蚌ææžã§ã®VPNãã£ãã«ã®å©ç¹ã«ã€ããŠã¯èª¬æããŸããã Check Pointãœãªã¥ãŒã·ã§ã³ã§åæ£ãããã¯ãŒã¯ãæ§ç¯ãããã1ã€ã®å©ç¹ã¯ãçµ±åããã蚌ææ©é¢ïŒCAïŒãååšããããšã§ãã ãã®CAã¯ã管çãµãŒããŒäžã«åžžã«ããã©ã«ãã§ååšãããã®å¶åŸ¡äžã«ãããã¹ãŠã®Check Pointã²ãŒããŠã§ã€ã®èšŒææžãèªåçã«çæããŸãã ãµãŒãããŒãã£ã®èªèšŒå±ã«ãèŠãããå¿ èŠã¯ãããŸããïŒãã§ãã¯ãã€ã³ãã«ããã蟌ããããšãã§ããŸãïŒã
VPNãã§ã€ã«ãªãŒããŒ
å€ãã®å Žåã圌ãã¯ãã®æ©äŒãå¿ããŠããŸãã ãããã圌女ã¯ããã§ãã ãã©ã³ããªãã£ã¹ãšã»ã³ãã©ã«ãªãã£ã¹ã«ã¯ã2ã€ã®ã€ã³ã¿ãŒããããã£ãã«ããããŸãã ãã©ã³ãã«ãã§ãã¯ãã€ã³ããããå Žåã¯ããã§ã€ã«ã»ãŒãVPNïŒãã¡ã€ã³ããŒã¹ïŒãæ§æã§ããŸãã ç¹ã«æ°åã®ã¯ãªãã¯ã§æåéãèšå®ãããã®ã§ããã®ãã§ãã¯ãã€ã³ãã®æ©èœãç¡èŠããªãã§ãã ããã
管çãµãŒããŒã®ã©ã€ã»ã³ã¹
åæ£ãããã¯ãŒã¯ãèšç»ãããšãã«å¿ãããããã1ã€ã®éèŠãªãã€ã³ãã Security Management Serverã¯ã管çã§ããã²ãŒããŠã§ã€ã®æ°ããšã«ã©ã€ã»ã³ã¹ãä»äžãããŸãã 5ã€ã®ã²ãŒããŠã§ã€ã10ã25ã50ã150ãªã©ã管çããããã®ã©ã€ã»ã³ã¹ããããŸãã åæã«ãäŸ¡æ Œã¯å€§ããç°ãªããŸãã ã¯ã©ã¹ã¿ãŒã¯2ã€ã®ã²ãŒããŠã§ã€ãšããŠã«ãŠã³ããããŸãïŒ äºç®ãèšç»ãããšãã¯æ³šæããŠãã ããã
Check Point VPNã®ãã®ä»ã®å©ç¹
æè¡çãªèŠ³ç¹ããèŠããšãCheck Point VPNã«ã¯ããã«å€ãã®å©ç¹ããããŸãã æç·ã¢ãŒãããã©ãã£ãã¯ããªããŠããã³ãã«ãç¶ç¶çã«ç¶æããæ©èœãæå·åããããã©ãã£ãã¯ãšéåžžã®ãã©ãã£ãã¯ã«ç°ãªãã«ãŒã«ãäœæããæ©èœããã³ãã«ããç¹å®ã®ã¿ã€ãã®ãã©ãã£ãã¯ãé€å€ããæ©èœãªã©ãããããŸãã ããããç§ã¯èª°ãç²ããªãããã«ãã®ãããªæè¡çãªè©³çŽ°ã«è¡ããããªãã§ãããã ç¹å®ã®äœãã«èå³ãããå Žåã¯ãã³ã¡ã³ãã§è³ªåããŠãã ããã ã¢ãŒããã¯ãã£ã®æ©èœã«ã€ããŠè©³ãã調ã¹ãŠã¿ãŸããã
PSè³æã®æºåã«ååããŠãããã€ãªã€ã»ãŽã¬ã«ãã³ ïŒãã§ãã¯ã»ãã€ã³ãã®äŒç€ŸïŒã«æè¬ããŸãã