å 責äºé
ãã®èšäºã§ã¯ãå žåçãªNGFWå®è£ ã·ããªãªã®äŸã玹ä»ããŸãã å®æãããã³ãã¬ãŒãã«å¯ŸããŠææ¡ãããã¹ããŒã ã䜿çšããªãã§ãã ããã å®ç掻ã§ã¯ãã»ãŒãã¹ãŠã®å®è£ ã¯äžæã§ãã ãããã¯ãŒã¯ããããžãèšç»ããåã«æ³šæãã¹ãå€ãã®èœãšãç©ŽããããŸãã ãããäžè¬çã«ããã¹ãŠã®ãªãã·ã§ã³ã¯ããã€ãã®æŠå¿µãäžå¿ã«ãå±éãããŸãã ãããã«ã€ããŠè°è«ããããšããŸãã
æ å ±ã»ãã¥ãªãã£ã«é¢ããå žåçãªãããã¯ãŒã¯ã¢ãŒããã¯ãã£
NGFWã®å®è£ ãªãã·ã§ã³ã«ã€ããŠèª¬æããåã«ããã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããããã®ããã€ãã®å žåçãªã·ããªãªã«ã€ããŠèª¬æããŸãã ã»ãšãã©ãã¹ãŠã®äŒæ¥ã§å©çšå¯èœãªæãäžè¬çãªããŒã«ãæ€èšããŸãïŒãã¡ãããã§ããã ãåçŽåãããè¡šé¢çãªãã®ã§ãã å®éã«ã¯ã»ãšãã©ã®å Žåãæãäžè¬çãª3ã€ã®ãªãã·ã§ã³ããããŸãã
1ïŒäžçŽ
ããªãå žåçãªã¹ããŒã ã ãããã¯ãŒã¯ã®å¢çã§ã¯ãå°ãªããšã3ã€ã®ã»ã°ã¡ã³ãïŒã€ã³ã¿ãŒããããDMZãããã³ããŒã«ã«ãšãªã¢ãããã¯ãŒã¯ïŒãæã€ã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšãããŸãã åãMEã§ããµã€ãéVPNãšRA VPNãç·šæã§ããŸãã DMZã§ã¯ãéåžžãå ¬å ±ãµãŒãã¹ãé 眮ãããŸãã ã»ãšãã©ã®å Žåãã¢ã³ããŠã€ã«ã¹æ©èœãåããäœããã®ã¹ãã 察çãœãªã¥ãŒã·ã§ã³ããããŸãã
ã³ã¢ã¹ã€ããïŒL3ïŒã«ã¯ãå°ãªããšã2ã€ã®ã»ã°ã¡ã³ãïŒãŠãŒã¶ãŒã»ã°ã¡ã³ããšãµãŒããŒã»ã°ã¡ã³ãïŒããããããŒã«ã«ãã©ãã£ãã¯ã®ã«ãŒãã£ã³ã°ãæ åœããŸãã ãµãŒããŒã»ã°ã¡ã³ãã«ã¯ããŠã€ã«ã¹å¯Ÿçæ©èœãåãããããã·ãµãŒããŒãšäŒæ¥ã¡ãŒã«ãµãŒããŒããããŸãã å€ãã®å ŽåããµãŒããŒã»ã°ã¡ã³ãã¯è¿œå ã®MEïŒä»®æ³ãŸãã¯ãéãïŒã«ãã£ãŠä¿è·ãããŸãã
è¿œå ã®ä¿è·å¯ŸçãšããŠããã©ãã£ãã¯ã®ã³ããŒãç£èŠããIPSãé©çšã§ããŸãïŒSPANããŒãã«æ¥ç¶ïŒã å®éã«ã¯ãIPSãã€ã³ã©ã€ã³ã¢ãŒãã«ããããšãæ¢ããŠããŸããã
å€ãã®äººããã®ã¹ããŒã ã§åœŒãã®ãããã¯ãŒã¯ãæšæž¬ãããšç¢ºä¿¡ããŠããŸãã
2ïŒç°¡ç¥å
ãã®ãªãã·ã§ã³ãéåžžã«äžè¬çã§ãã ã»ãšãã©ãã¹ãŠã®ã»ãã¥ãªãã£æ©èœã¯ãåäžã®UTMãœãªã¥ãŒã·ã§ã³ïŒãã¡ã€ã¢ãŠã©ãŒã«ããããã·ãAVãã¢ã³ãã¹ãã ãIPSïŒå ã«å±éãããŸãã ããŒã«ã«ãã©ãã£ãã¯ãã«ãŒãã£ã³ã°ããã«ã¯ãã«ãŒãã«ã¹ã€ããïŒCore SW L3ïŒã䜿çšãããŸãã äŒç€Ÿã®ã¡ãŒã«ãµãŒããŒããã³ãã®ä»ã®ãµãŒãã¹ãå«ããµãŒããŒã»ã°ã¡ã³ãã匷調衚瀺ãããŸãã
3ïŒSMB
æãç°¡åãªãªãã·ã§ã³ã åã®ãã®ãšã¯ãã«ãŒãã«ã¹ã€ããããªãããç°ãªããŸãã ã€ãŸã ããŒã«ã«ã»ã°ã¡ã³ããšã€ã³ã¿ãŒãããéã®ãã©ãã£ãã¯ã¯ãåäžã®UTMããã€ã¹ãä»ããŠã«ãŒãã£ã³ã°ãããŸãã ãã®ãªãã·ã§ã³ã¯ããã©ãã£ãã¯ã®å°ãªãå°èŠæš¡äŒæ¥ã§ããèŠãããŸãã
äžã§æžããããã«ãããã¯æãäžè¬çãªãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããããã®3ã€ã®å žåçãªã·ããªãªã®éåžžã«è¡šé¢çãªèª¬æã§ãã
NGFW
次äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ã¯ã次äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ã§ãã ç§ãã¡ã¯ããããäœã§ãããããããUTMãšã©ã® ããã«ç°ãªã ããåžå ŽãªãŒããŒãšã¯äœããéžæããéã«æ³šæãæãå¿ èŠããããã®ã«ã€ããŠç¹°ãè¿ãè°è«ããŠããŸããã åœåãNGFWãå°å ¥ãããäž»ãªãã®ã¯ãã¢ããªã±ãŒã·ã§ã³å¶åŸ¡ãšè©³çŽ°ãªãã±ããæ€æ»ã§ããïŒå®éãåè ã¯åŸè ãªãã§ã¯äžå¯èœã§ãïŒã ã¢ããªã±ãŒã·ã§ã³ã¯ãå€å žçãªãåããã¢ããªã±ãŒã·ã§ã³ãšããŠã ãã§ãªããWebããŒã¹ã®ãã€ã¯ãã¢ããªã±ãŒã·ã§ã³ãšããŠãç解ãããŸãã äŸãšããŠã¯ããœãŒã·ã£ã«ãããã¯ãŒã¯ã§ã®æçš¿ããããªããã£ããããããŸãã
ãã ããæè¿ã®ã»ãšãã©ãã¹ãŠã®NGFWã«ã¯ãããã«å€ãã®æ©èœãçµã¿èŸŒãŸããŠããŸãã
- ã¢ããªã±ãŒã·ã§ã³å¶åŸ¡
- URLãã£ã«ã¿ãªã³ã°
- VPN
- IPS
- ã¢ã³ããŠã€ã«ã¹
- ã¹ãã 察ç
äžéšã®ãœãªã¥ãŒã·ã§ã³ã«ã¯è¿œå æ©èœããããŸãã
- DLP
- ãµã³ãããã¯ã¹
- ãã°åæããã³çžé¢ãŠããã
ãã®ãããªæ©èœã®å€§èŠæš¡ãªå¯çšæ§ã«ãããå®è£ äžã«çåãçããŸãã ãããã·ãµãŒããŒïŒããšãã°ãironportïŒãè³Œå ¥ããå Žåãã¢ããªã±ãŒã·ã§ã³ã·ããªãªã¯ã¯ããã«å°ãªããªããŸãã åãããšã¯ãé«åºŠã«ã¿ãŒã²ãããçµã£ãã¹ãã 察çãœãªã¥ãŒã·ã§ã³ã«ãåœãŠã¯ãŸããŸãã ããããçŸä»£ã®NGFWã®ãããªãåç©«è ããšã¯ã©ãããã°ããã®ã§ããããïŒ ã©ãã«çœ®ããã©ã®ããã«äœ¿çšããŸããïŒ ããã€ãã®å žåçãªã·ããªãªãèŠãŠãæé©ãªå®è£ æ¹æ³ã説æããŸãããã ãã®åŸã®çµè«ã¯ãã¹ãŠéåžžã«äž»èŠ³çã§ãããå人çãªçµéšã®ã¿ã«åºã¥ããŠãããããã¹ããã©ã¯ãã£ã¹ãã«åŸã£ãŠããŸãã
1ïŒå¢çããã€ã¹ãšããŠã®NGFW
æãåçŽã§æãæ£ããå®è£ ãªãã·ã§ã³ã ãã®ãããNGFWã¯ãããã¯ãŒã¯ã®ç«¯ã«ç«ã€ããšãèããŸããã
å©ç¹ã¯äœã§ããïŒ
- å°çšã®ãããã·ã䜿çšããå¿ èŠã¯ãããŸããã ã»ãšãã©ã®NGFWã¯ãããã·ã¢ãŒãã§åäœã§ããŸãããå¿ èŠãªæ©èœã¯ãã¹ãŠããã¹ãŠã®ããŒã«ã«ãããã¯ãŒã¯ã®ãããã©ã«ãã«ãŒããã¢ãŒãã§ãæ©èœããŸãã ããã©ã«ãã²ãŒããŠã§ã€ãèšå®ããŠãå¿ããŠãã ããã ãŠãŒã¶ãŒãã©ãŠã¶ãŒã«ã¯æ瀺çãªãããã·ã¯ãããŸããã
- ããã©ã«ãã§ã¯ãIPSã¯ååšããããã«ã€ã³ã©ã€ã³ã¢ãŒãã«ãªããŸãã åé¡ãæããŠããå Žåã¯ã[æ€åº]ãèšå®ã§ããŸãã å°çšã®IPSããã€ã¹ãä»ããŠãã©ãã£ãã¯ãã©ããããæ¹æ³ããåé¡ãçºçããå Žåã«ãã©ãã£ãã¯ãè¿ éã«æ»ãæ¹æ³ã«ã€ããŠèããå¿ èŠã¯ãããŸããã
- HTTPSãã©ãã£ãã¯ïŒSSLã€ã³ã¹ãã¯ã·ã§ã³ãæå¹ïŒãå«ããWebãã©ãã£ãã¯ã®ãŠã€ã«ã¹å¯Ÿçã
- ã¡ãŒã«ãã©ãã£ãã¯çšã®ãŠã€ã«ã¹å¯Ÿçã ãªã³ã¯ãšæ·»ä»ãã¡ã€ã«ã確èªããŠãã ããã
- ã¹ãã 察çæ©èœã
- ããµã³ãããã¯ã¹ãïŒãµã³ãããã¯ã¹ïŒã®æ©èœãè¿ éã«å®è£ ããæ©èœã ã»ãŒãã¹ãŠã®ææ°ã®NGFWã«ã¯ããµã³ãããã¯ã¹ïŒã¯ã©ãŠããŸãã¯ããŒã«ã«ïŒãã¢ã¯ãã£ãåããæ©èœããããŸãã
- ãã¹ãŠã®æ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®çµã¿èŸŒã¿ã¬ããŒãã
ã芧ã®ãšãããã¹ããŒã ã¯å€§å¹ ã«ç°¡çŽ åãããŠããŸãã ããã€ãã®åŸæ¥ã®ãã¡ã€ã¢ãŠã©ãŒã«ãåé€ããŸãã äžæ¹ã§ã¯ãããã¯ãã©ã¹ïŒç®¡çãç°¡çŽ åãããŸãïŒãä»æ¹ã§ã¯ãã€ãã¹ïŒåäžé害ç¹ïŒã§ãã ã©ã¡ããè¯ããã«ã€ããŠã¯ãããã§ã¯èª¬æããŸããã ã³ã³ã»ãããè°è«ããŠããã ãã§ãã
ãããã¯ãŒã¯ã®å¢çäžã«ããNGFWãéžæãããšãã«æ¢ãã¹ããã®ïŒ
- ããã§æã泚æãæãå¿ èŠãããã®ã¯ãã¡ãŒã«ãã§ãã¯æ©èœã§ãïŒãã¡ãããçŸåšã®ã¹ãã 察çãœãªã¥ãŒã·ã§ã³ãåé€ããå ŽåïŒã ã¡ãŒã«ãå®å šã«åŠçããã«ã¯ãNGFWã«MTAïŒã¡ãŒã«è»¢éãšãŒãžã§ã³ãïŒãæèŒãããŠããå¿ èŠããããŸãã å®éããã®ã¢ãŒãã§ã¯ãNGFWãSMTPãªã¬ãŒã眮ãæããŸããããã«ãããã¡ãŒã«ãã©ãã£ãã¯ã®ãã£ãŒãã¹ãã£ã³ãå®è¡ã§ããŸãã ãµã³ãããã¯ã¹ã«æ·»ä»ãã¡ã€ã«ã®æ€èšŒãå«ããã MTAããªãå Žåã¯ãå°ãªããšãSMTPãªã¬ãŒãé¢ããå¿ èŠããããŸãã
- NGFWã«MTAãååšããå Žåã§ããã¡ãŒã«ãã£ã«ã¿ãªã³ã°ãªãã·ã§ã³ã泚ææ·±ãèªãã§ãã ããã æãéèŠãªåºæºã®1ã€ã¯ãæ€ç«ïŒãŸãã¯ãããæŽçããæ¹æ³ïŒã®ååšã§ãã
- åœç¶ãHTTPSæ€æ»ããµããŒãããå¿ èŠããããŸãã ãã®æ©èœããªããšãNGFWã®ååã1ã€æ®ããŸãã
- NGFWãåºå¥ã§ããã¢ããªã±ãŒã·ã§ã³ã®æ°ã éžæãããœãªã¥ãŒã·ã§ã³ãå¿ èŠãªã¢ããªã±ãŒã·ã§ã³ïŒWebã¢ããªã±ãŒã·ã§ã³ãå«ãïŒã決å®ãããã©ãããå¿ ã確èªããŠãã ããã
èããããå¶éãŸãã¯åé¡
å€ãã®å ŽåãMEã§ã¯ãªãã«ãŒã¿ãŒããšããžããã€ã¹ãšããŠäœ¿çšãããŸãã åæã«ãNGFWã®çŽç²ãªåœ¢åŒã§ã¯å©çšã§ããªãæ©èœïŒããŸããŸãªWANãã¯ãããžãã«ãŒãã£ã³ã°ãããã³ã«ãªã©ïŒãçŸåšã®ã¹ããŒã ã§äœ¿çšã§ããŸãã ãããå®è£ ããåã«èæ ®ããæ éã«èšç»ããå¿ èŠããããŸãã ã«ãŒã¿ãŒãé¢ããŠäžŠè¡ããŠäœ¿çšããïŒããšãã°ãWANãããã¯ãŒã¯ãç·šæããïŒã®ã¯è«ççãããããŸããã äŸïŒ
ãŸãšã
äžã§æžããããã«ããªãã·ã§ã³ããããã¯ãŒã¯ã®å¢çäžã®NGFWãã¯ããã®èœåãæ倧éã«åŒãåºãçæ³çãªãªãã·ã§ã³ã§ãã ãã ããNGFWã¯ã«ãŒã¿ãŒã§ã¯ãªãããšãå¿ããªãã§ãã ããã éåžžã®æ©èœïŒbgpãgreãip slaãªã©ïŒã¯ååšããªãããéåžžã«åãæšãŠãããæ©èœã«ååšããå ŽåããããŸãã
2ïŒãããã·ãµãŒããŒãšããŠã®NGFW
å¥åŠãªããšã«ããããããªãäžè¬çãªãªãã·ã§ã³ã§ãã NGFWã¯ãããã·ãšããŠéçºãããŠããŸãããã å žåçãªã¹ããŒã ïŒ
ãã®ãªãã·ã§ã³ã®å©ç¹ïŒ
- å®è£ ã®é床ã å€ããããã·ã眮ãæãããšå®äºã§ãã
- çŸåšã®ã¹ããŒã ãŸãã¯ã«ãŒãã£ã³ã°ãå€æŽããå¿ èŠã¯ãããŸããã
ããã§ãããã¯ããããçµäºããŸãã çºè¡šãããå©ç¹ã¯å€ãã®äŒæ¥ã«ãšã£ãŠéåžžã«é »ç¹ã«æ±ºå®çã«ãªããŸããã
ãããã·ãšããŠæ©èœããNGFWãéžæããéã«æ¢ãã¹ããã®ïŒ
- ããã§æãéèŠãªç¹ã¯ããŠãŒã¶ãŒèªèšŒã®æ¹æ³ïŒNTLMãKerberosããã£ããã£ãããŒã¿ã«ãªã©ïŒã§ãã éžæãããœãªã¥ãŒã·ã§ã³ãçŸåšã®èªèšŒæ¹æ³ããµããŒãããŠããããšããŸãã¯é©åãªãã®ã«çœ®ãæããããšãã§ããããšã確èªããŠãã ããã
- ãŠãŒã¶ãŒã«é¢ããçµã¿èŸŒã¿NGFWã¬ããŒãïŒæ¶è²»ãã©ãã£ãã¯ã蚪åãªãœãŒã¹ãªã©ïŒã«æºè¶³ããŠããããšã確èªããŸãã
- ãã©ãã£ãã¯ãå¶éããæ©äŒ-QoSãé床ã®å¶éïŒã·ã§ãŒãã³ã°ïŒãããŠã³ããŒãããããã©ãã£ãã¯ã®éïŒå¶éïŒã
èããããå¶éãŸãã¯åé¡ïŒ
- æåã«èŠããŠããã¹ãããšã¯ããããã·ã¢ãŒãã®NGFWã¯ã»ãšãã©ã®å Žåãæ©èœãåãæšãŠãããŠããããšã§ãã 100ããŒã»ã³ã䜿çšããããšã¯ã§ããŸããã ç¹ã«ãé»åã¡ãŒã«ãã©ãã£ãã¯ã®ãã§ãã¯ã«é¢ããŠã¯ã
- ããäœã垯åå¹ ã ãããã·ã¢ãŒãã®ã»ãšãã©ãã¹ãŠã®NGFWãœãªã¥ãŒã·ã§ã³ã¯ããŠãŒã¶ãŒãããã®é床ãé ãããšãå®èšŒããŠããŸãã
- ããã§ãIPSã䜿çšããå¿ èŠããããŸãã ãªããªã ãã©ãã£ãã¯ã®äžéšã¯ãããã·çµç±ã§ã€ã³ã¿ãŒãããã«éãããŸãã
ãŸãšã
å人çãªã¢ããã€ã¹-ããããã·ãšããŠã®NGFWããåé¿ã§ããå Žåã¯ãåé¿ããŠãã ããã å®éã«ã¯ãææžåãããŠããªãæ©èœãçªç¶ãäžæãããå§ããŸãã ãããŠæ倧ã®ãã€ãã¹ç¹ã¯ãã¡ãŒã«ãå®å šã«ãã§ãã¯ã§ããªãããšã§ãïŒæè¡çã«ã¯ãã¡ããããããè¡ãããšãã§ããŸããããæŸèæãã«ãªããŸãïŒã
3ïŒã³ã¢ãšããŠã®NGFW
å°èŠæš¡ãããã¯ãŒã¯ã®äžè¬çãªãªãã·ã§ã³ã ãã¹ãŠã®ãã©ãã£ãã¯ïŒã€ã³ã¿ãŒããããããŒã«ã«ããµãŒããŒïŒã®ã«ãŒãã£ã³ã°ã¯ãNGFWã§ããã³ã°ãããŠããŸãã L3ã¹ã€ãããååšããªãããåã«ã«ãŒãã£ã³ã°ã«äœ¿çšãããŠããŸããã
ãã®ãªãã·ã§ã³ã®å©ç¹ïŒ
- 管çã®ããããã ãã¹ãŠã®ã¢ã¯ã»ã¹ãªã¹ãã1ãæã«ã
- å±éé床ã ååãšããŠãNGFWã¯ããã®åã«MEããããã¯ãŒã¯ã³ã¢ã®åœ¹å²ãå®è¡ããããããžã§ãã®ããã«èšå®ãããŸãã
- ãªãã·ã§ã³ããããã¯ãŒã¯ã®å¢çäžã®NGFWãã®ãã¹ãŠã®å©ç¹ã
ã«ãŒãã«ã¢ãŒãã§NGFWãéžæããéã®æ³šæäºé
ã»ãšãã©ãã¹ãŠã¯ãããããã¯ãŒã¯ã®å¢çäžã®NGFWããšåãã§ãã ãã ãããã®å ŽåãMTAé¢æ°ã®ååšã«ç¹å¥ãªæ³šæãæã䟡å€ããããŸãã ãã®ãããªå°ããªãããã¯ãŒã¯ã§ã¯ãSMTPãªã¬ãŒã®åœ¢åŒã§è¿œå ã®ããã€ã¹ã䜿çšããã«è¡ãããšããå§ãããŸãã ãã®æ©èœãNGFWã«ååšããæ¹ãè¯ãã§ãã
èããããå¶éãŸãã¯åé¡ïŒ
- ãããããäž»ãªåé¡ã¯åäžç¹é害ã§ãã ããã€ã¹ãéžæãããšãã¯ãéžæããNGFWã¢ãã«ãè² è·ãåŠçã§ããããã«ãããŒã«ã«ãã©ãã£ãã¯ãå¿ ãèæ ®ããŠãã ããã
- ãããã¯ãŒã¯ã¯ãå€æŽã«é¢ããŠæè»æ§ãäœããªããŸãã ããå°ãªãã«ãŒãã£ã³ã°ããã€ã¹-ããå°ãªããã©ãã£ãã¯ç®¡çæ©èœã
ãŸãšã
ããããããã¯äžå°äŒæ¥ã«æé©ã§ãã ãã¡ãããåäžé害ç¹ã®ãªã¹ã¯ãæ³å®ããŠããå Žåã
4ïŒããªããžã¢ãŒãã®NGFW
ããŸã人æ°ã®ãªããªãã·ã§ã³ã§ãããç§ãã¡ãæããããäžè¬çã§ãã ãã®å ŽåãçŸåšã®ãããã¯ãŒã¯ããžãã¯ã¯ãŸã£ããå€æŽãããã第2ã¬ãã«ã®ãã©ãã£ãã¯ã¯NGFWãééããŸããããã¯ããªããžã¢ãŒãã§åäœããŸãã
ãã®å ŽåããµãŒãããŒãã£ã®IPSãæ®ãããšã¯æå³ããããŸããïŒç¹ã«ãã©ãã£ãã¯ã®ç£èŠã®ããïŒã NGFWã¯ãã®æ©èœã«å¯ŸåŠããŸãã ãã®ãªãã·ã§ã³ã¯ãäœããã®çç±ã§ããããžã®å€æŽãäžå¯èœãŸãã¯éåžžã«æãŸãããªããããé«åºŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ã§æããã䜿çšãããŸãã
ãã®ãªãã·ã§ã³ã®å©ç¹ïŒ
- å®è£ ã®é床ã ãããã¯ãŒã¯ããžãã¯ãå€æŽããå¿ èŠã¯ãããŸãããæ倧ã§ã±ãŒãã«ãæ¥ç¶ããããVLANããã©ãããããå¿ èŠããããŸãã
- ããå°ãªãããã-ããåçŽãªãããã¯ãŒã¯ããžãã¯ã
ããããããã ãã§ãã
ãããªããžãã¢ãŒãã§NGFWãéžæããéã®æ³šæäºé ïŒ
- ãããªããžãã¢ãŒãã®å¶éã«ã€ããŠïŒ 泚ææ·±ãèªãã§ãã ããã
- ãªãã«ãªã£ãŠããå Žåã§ãããã©ãã£ãã¯ãããã€ã¹ãæµããããã«ãã€ãã¹ã¢ãžã¥ãŒã«ã䜿çšããããšããå§ãããŸãã
èããããå¶éãŸãã¯åé¡
ãããŠãããã«ã¯å€ãã®èœãšãç©ŽããããŸãã ããªããžã¢ãŒãã§é©åã«æ©èœããåäžã®NGFWãœãªã¥ãŒã·ã§ã³ã«ã¯ãŸã ééããŠããŸããã ãã¶ãç§ã¯äžéã ã£ãã ãããããã®èšäºã§ã¯ç§ã®çµéšã®ã¿ãå ±æããŸãã æ©èœã«é¢ããå ¬åŒã®ïŒææžåãããïŒå¶éã«å ããŠããã°ã®åœ¢ã®ãéå ¬åŒãªãå¶éãå€ãã®åé¡ãåžžã«çºçããŸãã ãã¡ãããããã¯ãã¹ãŠãããªããžã¢ãŒãã§äœ¿çšããæ©èœã«äŸåããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã®ã¿ãæ§æããå Žåãå®è³ªçã«åé¡ã¯ãããŸããã ãã ããIPSãã¢ããªã±ãŒã·ã§ã³å¶åŸ¡ãHTTPSæ€æ»ããŸãã¯ãµã³ãããã¯ã¹åãªã©ã®æ©èœãæå¹ã«ããå Žåã¯ãé©ãã«åããŠãã ããã
ãŸãšã
ãããã·ãšåæ§ã«ãããªããžã¢ãŒããåé¿ããããšããå§ãããŸãã ãããäžå¯èœãªå Žåã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã§ãã®ã¢ãŒãããã¹ãããããšã匷ããå§ãããŸãã ãã®åŸã決å®ãäžããŸãã
èé害æ§
ç§ã¯ãã®ç¹ã«è§Šããã«ã¯ããããŸããã§ããã ã»ãŒãã¹ãŠã®NGFWãœãªã¥ãŒã·ã§ã³ã¯ã2ã€ã®ã¯ã©ã¹ã¿ãªã³ã°ã¢ãŒãããµããŒãããŠããŸãã
- é«å¯çšæ§ 1ã€ã®ã¯ã©ã¹ã¿ãŒããŒãã¯ã¢ã¯ãã£ãã§ãã©ãã£ãã¯ãã«ãŒãã£ã³ã°ãã2çªç®ã®ããŒãã¯ããã·ãã§ãããã¹ã¿ã³ãã€ã«ãããæåã®ããŒãã§åé¡ãçºçããå Žåã«ã¢ã¯ãã£ãã«ãªãæºåãã§ããŠããŸãã
- è² è·åæ£ äž¡æ¹ã®ããŒããã¢ã¯ãã£ãã§ããããã©ãã£ãã¯ã¯ããŒãéã§ãåå²ããããŸãã
NGFWãèšç»ããã³å®è£ ãããšãã«ãè² è·å ±æã¢ãŒãã«å€§ããäŸåããŠãã人ãå€ãããŸãã
-ããã€ã¹éã§ãã©ãã£ãã¯ãå ±æããå Žåãããã€ã¹ã®è² è·ã¯ååã«ãªããŸããã€ãŸããããã€ã¹ããã匱ããããå®ãæ·èšã§ããŸããïŒ
-ããïŒ
å€ãã®ãã¹ãã瀺ãããã«ãé©åãªãã©ãã£ãã¯ãã©ã³ã·ã³ã°ãéæããããšã¯äžå¯èœã§ãã ãŸããè² è·å ±æãæäŸããæ倧ã®å¹æã¯ãããã€ã¹ã®è² è·ã15ïŒ ä»¥äžåæžããããšã§ãã ããã«ããã®ã¢ãŒãã«ã¯ãã»ãšãã©ã®å Žåãé«å¯çšæ§ã«ã¯ãªãããã€ãã®å¶éããããŸãã å¿ ããã§ãã¯ããŠãã ããã ãŸããããã€ã¹ãéžæãããšãã¯ãåžžã«1ã€ã®ããŒããŠã§ã¢ã«äŸåããŠãã¹ãŠã®ãã©ãã£ãã¯ãåŠçããŸãã
ãŸãšã
é«å¯çšæ§ã¢ãŒãã䜿çšããŸãã
ä»®æ³NGFWãŸãã¯ããŒããŠã§ã¢
NGFWãèšç»ãããšãã®ãã1ã€ã®éåžžã«äžè¬çãªè³ªåã ä»®æ³ãœãªã¥ãŒã·ã§ã³ãŸãã¯ã¢ãã©ã€ã¢ã³ã¹ãéžæããŸãã åäžã®çãã¯ãããŸããã ããã¯ãã¹ãŠãçŸåšã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãäºç®ãããã³ãããã¯ãŒã¯ããžãã¯ã®å€æŽãªãã·ã§ã³ã«äŸåããŸãã ãã ããããŸããŸãªå®è£ ãªãã·ã§ã³ã«é¢ããäžè¬çãªæšå¥šäºé ã¯ãŸã ãããŸãã
- ãããã¯ãŒã¯ã®å¢çäžã®NGFWã ããã§ãæè¯ã®ãªãã·ã§ã³ã¯ã¢ãã©ã€ã¢ã³ã¹ã§ãã ããã¯è«ççã§ãããªããªã ãããã¯ãŒã¯ã®å¢çã¯ç©ççã«åºå¥ããå¿ èŠããããŸãã ããã§ãä»®æ³ãœãªã¥ãŒã·ã§ã³ãå¿ èŠãªå Žåã¯ãNGFWãããŒã«ã«ãããã¯ãŒã¯ãšã¯ç©ççã«åºå¥ãããå°çšãµãŒããŒã«å±éããããšã匷ããå§ãããŸãã å®éããã³ããŒã®ããŒããŠã§ã¢ã®ä»£ããã«ãåãã¢ãã©ã€ã¢ã³ã¹ãååŸãããµãŒããŒããã€ããŒãã€ã¶ãŒãšãšãã«äœ¿çšããŸãã ãŸãããã€ããŒãã€ã¶ãŒèªäœã®èšå®ã«æ éã«ã¢ãããŒãããŠãå€éšãããã¯ãŒã¯ããã¢ã¯ã»ã¹ãããªãããã«ããå¿ èŠããããŸãã
- ãããã·ãšããŠã®NGFWã äœãéžæãããã¯ããã»ã©éãã¯ãããŸããã ç§ã®æèŠã§ã¯ãä»®æ³ãœãªã¥ãŒã·ã§ã³ã®æ¹ããã䟿å©ã§äŸ¿å©ãªãªãã·ã§ã³ã§ãã
- ãããã¯ãŒã¯ã®ã³ã¢ãšããŠã®NGFWã æåã®æ®µèœã®ãããªåºæ¬çãªèŠä»¶ã ãªããªã NGFWãã€ã³ã¿ãŒãããã«çŽæ¥æ¥ç¶ãããŠããå Žåããœãªã¥ãŒã·ã§ã³ã¯äŒç€Ÿã®ãµãŒããŒïŒå°çšãµãŒããŒäžã®ã¢ãã©ã€ã¢ã³ã¹ãŸãã¯ä»®æ³ãã·ã³ïŒããç©ççã«åé¢ããå¿ èŠããããŸãã ãªããªã ãã®å Žåã®NGFWã¯ã«ãŒãã«ã®åœ¹å²ãæãããŸããå¿ èŠãªç©çããŒãã®æ°ãšãã©ã®ããŒãïŒ1gã10gããªããã£ã¯ã¹ïŒãç解ããå¿ èŠããããŸãã ãŸããéžæã«ã倧ãã圱é¿ããŸãã
- ããªããžã¢ãŒãã®NGFWã ãã®ãªãã·ã§ã³ã§ã¯ãããŒããŠã§ã¢ããã€ã¹ã匷ããå§ãããŸãã ãã€ãã¹ã¢ãžã¥ãŒã«ã®ååšãæãŸããã§ãïŒããã€ã¹ã®é»æºããªãã®å Žåã§ããã©ãã£ãã¯ã¯ééããŸãïŒã
ä»®æ³ãœãªã¥ãŒã·ã§ã³ã®é·æãšçæãèŠãŠã¿ãŸãããã
ä»®æ³ãœãªã¥ãŒã·ã§ã³ã®å©ç¹ïŒ
- ä»®æ³ãœãªã¥ãŒã·ã§ã³ã®äž»ãªå©ç¹ã¯ã管çã®å®¹æãïŒããã¯ã¢ãããã¹ãããã·ã§ããïŒãšå±éã®é床ã§ãã
- ãŸããéåžžã«é »ç¹ã«å®äŸ¡ã§æ¡åŒµæ§ãåªããŠããŸãã ååãšããŠãã©ã€ã»ã³ã¹ã¯äœ¿çšãããã³ã¢ã®æ°ã«åºã¥ããŠããŸãã å¿ èŠã«å¿ããŠãããã€ãã®ã³ã¢ãç°¡åã«è³Œå ¥ã§ããŸãã
ä»®æ³ãœãªã¥ãŒã·ã§ã³ã®çæïŒ
- ããŒããŠã§ã¢ã«ä¿èšŒã¯ãããŸããã ãµãŒããŒãæ éããå Žåã¯ãèªåã§å¯ŸåŠããå¿ èŠããããŸãã
- ã»ãã¥ãªãã£ã®å°é家ã§ããã°ãITéšéãšããåãããå¿ èŠããããŸãã å¥åŠãªããšã«ãå€ãã®äŒæ¥ã§ã¯ããã¯éåžžã«å€§ããªåé¡ã§ãã
ã¢ãã©ã€ã¢ã³ã¹ã®å Žåãéã®ããšãåœãŠã¯ãŸããŸãã ããã«ãè¿œå ã®ç©çããŒããããã«äœ¿çšã§ããŸãã
ãããã«
ãã®èšäºãéå±ã§è¡šé¢çãªãã®ã§ã¯ãªãããšãé¡ã£ãŠããŸãã ç§ã¯èŠç¹ã匷調ããæ°æéã®èªæžã®ããã«ãè¬çŸ©ããåºããããããŸããã§ããã ãã®èšäºã誰ãã«æ¬åœã«åœ¹ç«ã€ãšããããã§ãã ã質åããæèŠããããŸããããã³ã¡ã³ããŸãã¯ãã©ã€ããŒãã¡ãã»ãŒãžã§ãçžè«ãã ããã
PSè©Šçšçã©ã€ã»ã³ã¹ãååŸããŠãèå³ã®ãããœãªã¥ãŒã·ã§ã³ãããã§ãã¹ãããŠãã ãã