
ã»ãã¥ãªãã£ãªã¹ã¯ãå®å šã«æé€ããããšã«ã€ããŠè©±ãã®ã¯æå³ããããŸããã ååãšããŠããããããŒãã«æžããããšã¯ã§ããŸããã ãŸãããããã¯ãŒã¯ãããå®å šã«ããããã«åªåããã«ã€ããŠããœãªã¥ãŒã·ã§ã³ããŸããŸãé«äŸ¡ã«ãªãããšãç解ããå¿ èŠããããŸãã äŸ¡æ Œãè€éããã»ãã¥ãªãã£ã®éã§ãããã¯ãŒã¯ã®åççãªåŠ¥åç¹ãèŠã€ããå¿ èŠããããŸãã
ãã¡ãããã»ãã¥ãªãã£èšèšã¯å šäœçãªã¢ãŒããã¯ãã£ã«ææ©çã«çµ±åãããŠããã䜿çšãããã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã¯ã¹ã±ãŒã©ããªãã£ãä¿¡é Œæ§ã管çæ§ã...ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã圱é¿ããŸãããããèæ ®ããå¿ èŠããããŸãã
ããããä»ã¯ãããã¯ãŒã¯ã®äœæã«ã€ããŠè©±ããŠããªãããšãæãåºãããŠãã ããã åææ¡ä»¶ã«åŸã£ãŠãèšèšãéžæããæ©åšãéžæããã€ã³ãã©ã¹ãã©ã¯ãã£ãäœæããŸããããã®æ®µéã§ãå¯èœã§ããã°ã以åã«éžæããã¢ãããŒãã®ã³ã³ããã¹ãã§ãœãªã¥ãŒã·ã§ã³ããå®è¡ãããèŠã€ããå¿ èŠããããŸãã
ããã§ã®ã¿ã¹ã¯ã¯ããããã¯ãŒã¯ã¬ãã«ã§ã»ãã¥ãªãã£ã«é¢é£ãããªã¹ã¯ãç¹å®ãããããã劥åœãªå€ã«æžããããšã§ãã
ãããã¯ãŒã¯ã»ãã¥ãªãã£ç£æ»
çµç¹ãISO 27kããã»ã¹ãå®è£ ããŠããå Žåããã®ã¢ãããŒãã®äžéšãšããŠãã»ãã¥ãªãã£ç£æ»ãšãããã¯ãŒã¯ã®å€æŽãããã»ã¹å šäœã«ææ©çã«çµ±åããå¿ èŠããããŸãã ãããããããã®æšæºã¯ç¹å®ã®ãœãªã¥ãŒã·ã§ã³ã«é¢ãããã®ã§ã¯ãªããæ§æã«é¢ãããã®ã§ã¯ãªããèšèšã«é¢ãããã®ã§ã¯ãããŸãã...æ確ãªãã³ãã¯ãããŸããããããã¯ãŒã¯ã®è©³çŽ°ãèŠå®ããæšæºã¯ãããŸãããããããã®ã¿ã¹ã¯ã®è€éããšçŸããã§ãã
ããã€ãã®ãããã¯ãŒã¯ã»ãã¥ãªãã£ç£æ»ã®å¯èœæ§ã匷調ããŸãã
- æ©åšæ§æç£æ»ïŒåŒ·åïŒ
- ã»ãã¥ãªãã£ç£æ»èšèš
- ã¢ã¯ã»ã¹ç£æ»
- ããã»ã¹ç£æ»
ããŒããŠã§ã¢æ§æç£æ»ïŒåŒ·åïŒ
ã»ãšãã©ã®å Žåãããã¯ãããã¯ãŒã¯ã®ç£æ»ãšã»ãã¥ãªãã£åäžã®ããã®æé©ãªåºçºç¹ãšæãããŸãã ç§èŠãããã¯ãã¬ãŒãã®æ³åã®è¯ããã¢ã³ã¹ãã¬ãŒã·ã§ã³ã§ãïŒåªåã®20ïŒ ã¯çµæã®80ïŒ ãäžããåªåã®æ®ãã®80ïŒ ã¯çµæã®ããã20ïŒ ã§ãïŒã
çµè«ãšããŠã¯ãéåžžãæ©åšãæ§æããéã®å®å šæ§ã«é¢ããããã¹ããã©ã¯ãã£ã¹ãã«é¢ãããã³ããŒããã®æšå¥šäºé ããããŸãã ããã¯åŒ·åãšåŒã°ããŸãã
ãŸãããããã®æšå¥šäºé ã«åºã¥ããŠã¢ã³ã±ãŒããèŠã€ããïŒãŸãã¯èªåã§äœæããïŒããšãã§ããŸããããã¯ãããŒããŠã§ã¢æ§æããããã®ããã¹ããã©ã¯ãã£ã¹ãã«ã©ã®ããã«äžèŽããããå€æããçµæã«å¿ããŠãããã¯ãŒã¯ãå€æŽããã®ã«åœ¹ç«ã¡ãŸãã ããã«ãããéåžžã«ç°¡åã«ãäºå®äžç¡æã§ãã»ãã¥ãªãã£ãªã¹ã¯ãå€§å¹ ã«åæžã§ããŸãã
äžéšã®ã·ã¹ã³ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããã€ãã®äŸã
Cisco IOSèšå®ã®åŒ·å
Cisco IOS-XRèšå®ã®åŒ·å
Cisco NX-OSæ§æã®åŒ·å
CiscoããŒã¹ã©ã€ã³ã»ãã¥ãªãã£ãã§ãã¯ãªã¹ã
ãããã®ããã¥ã¡ã³ãã«åºã¥ããŠãåã¿ã€ãã®æ©åšã®æ§æèŠä»¶ã®ãªã¹ããäœæã§ããŸãã ããšãã°ãCisco N7K VDCã®å Žåããããã®èŠä»¶ã¯æ¬¡ã®ããã«ãªããŸã ã
ãããã£ãŠããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ããŸããŸãªçš®é¡ã®ã¢ã¯ãã£ããªæ©åšã®æ§æãã¡ã€ã«ãäœæã§ããŸãã ããã«ãæåãŸãã¯èªååã䜿çšããŠããããã®æ§æãã¡ã€ã«ããã¢ããããŒããã§ããŸãã ãã®ããã»ã¹ãèªååããæ¹æ³ã«ã€ããŠã¯ããªãŒã±ã¹ãã¬ãŒã·ã§ã³ãšèªååã«é¢ããå¥ã®äžé£ã®èšäºã§è©³ãã説æããŸãã
ã»ãã¥ãªãã£ç£æ»èšèš
éåžžãäœããã®åœ¢ã®ãšã³ã¿ãŒãã©ã€ãºãããã¯ãŒã¯ã«ã¯ã次ã®ã»ã°ã¡ã³ããå«ãŸããŸãã
- DCïŒå ¬å ±ãµãŒãã¹DMZããã³ã€ã³ãã©ãããããŒã¿ã»ã³ã¿ãŒïŒ
- ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹
- ãªã¢ãŒãã¢ã¯ã»ã¹VPN
- ã¯ã³ãšããž
- æ¯åº
- ãã£ã³ãã¹ïŒãªãã£ã¹ïŒ
- ã³ã¢
ååã¯Cisco SAFEã¢ãã«ããååŸãããŸããããã¡ããããããã®ååãšãã®ã¢ãã«ã«ãã€ã³ãããå¿ èŠã¯ãããŸããã ããã§ããç§ã¯æ¬è³ªã«ã€ããŠè©±ããããã®ã§ãããæç¶ãã«ã¯é¢äžããŸããã
ãããã®ã»ã°ã¡ã³ãããšã«ãã»ãã¥ãªãã£ã®ã¬ãã«ããªã¹ã¯ãããã³ããã«å¿ããææ決å®ã®èŠä»¶ãç°ãªããŸãã
ã»ãã¥ãªãã£èšèšã®é¢ã§çºçããå¯èœæ§ã®ããåé¡ã«ã€ããŠããããããåå¥ã«æ€èšããŸãã ãã¡ãããç¹°ãè¿ããŸããããã®èšäºãå®å šã§ãããšäž»åŒµããããšã¯æ±ºããŠãããŸããããã®æ·±ããŠå€é¢çãªãããã¯ã§éæããã®ã¯ç°¡åã§ã¯ãããŸãããïŒå¯èœãªå ŽåïŒãå人çãªçµéšãåæ ããŠããŸãã
å®ç§ãªè§£æ±ºçã¯ãããŸããïŒå°ãªããšãä»ã®ãšããïŒã ããã¯åžžã«åŠ¥åã§ãã ãããããã®ã¢ãããŒããŸãã¯ãã®ã¢ãããŒããé©çšãã決å®ã¯ããã®é·æãšçæã®äž¡æ¹ãç解ããŠãæèçã«è¡ãããããšãéèŠã§ãã
ããŒã¿ã»ã³ã¿ãŒ
æãéèŠãªã»ãã¥ãªãã£ã»ã°ã¡ã³ãã
ãããŠããã€ãã®ããã«ãæ®éçãªè§£æ±ºçããããŸããã ããã¯ãã¹ãŠãããã¯ãŒã¯èŠä»¶ã«äŸåããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ã¯å¿ èŠã§ããïŒ
çãã¯æçœãªããã«æããŸããããã¹ãŠãèŠãç®ã»ã©æ確ã§ã¯ãããŸããã ãããŠãããªãã®éžæã¯äŸ¡æ Œã ãã§ãªã圱é¿ãåãããããããŸããã
äŸ1. é 延ã
ãããã¯ãŒã¯ã®äžéšã®ã»ã°ã¡ã³ãéã§äœé 延ãäžå¯æ¬ ãªèŠä»¶ã§ããå ŽåïŒããšãã°ã亀æã®å Žåã«è©²åœããå ŽåïŒããããã®ã»ã°ã¡ã³ãéã§ã¯ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšã§ããŸããã ãã¡ã€ã¢ãŠã©ãŒã«ã®é 延ã«é¢ããç 究ãèŠã€ããããšã¯å°é£ã§ãããããå°æ°ã®ã¹ã€ããã¢ãã«ã®ã¿ã1ããªç§ä»¥äžã®é 延ãæäŸã§ããããããã€ã¯ãç§ãéèŠãªå Žåããã¡ã€ã¢ãŠã©ãŒã«ã¯é©åã§ã¯ãªããšæããŸãã
äŸ2. ããã©ãŒãã³ã¹ã
æäžäœã®L3ã¹ã€ããã®åž¯åå¹ ã¯ãéåžžãæãçç£æ§ã®é«ããã¡ã€ã¢ãŠã©ãŒã«ã®åž¯åå¹ ããã1æ¡é«ãã§ãã ãããã£ãŠãé«åŒ·åºŠã®ãã©ãã£ãã¯ã®å Žåããã®ãã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ããã€ãã¹ã§ããããã«ããå¿ èŠããããŸãã
äŸ3. ä¿¡é Œæ§ãäžèšã®äŸã®å Žåãã»ãšãã©ã®å ŽåïŒéåžžã©ããïŒåŠ¥åç¹ãèŠã€ããå¿ èŠããããŸãã 次ã®è§£æ±ºçãæ€èšããŠãã ããã
ãã¡ã€ã¢ãŠã©ãŒã«ãç¹ã«ææ°ã®NGFWïŒæ¬¡äžä»£FWïŒã¯è€éãªããã€ã¹ã§ãã L3 / L2ã¹ã€ãããããã¯ããã«è€éã§ãã å€æ°ã®ãµãŒãã¹ãšèšå®ãªãã·ã§ã³ãæäŸãããããä¿¡é Œæ§ãã¯ããã«äœãããšã¯é©ãããšã§ã¯ãããŸããã ãããã¯ãŒã¯ã«ãšã£ãŠãµãŒãã¹ã®ç¶ç¶æ§ãéèŠãªå Žåããã¡ã€ã¢ãŠã©ãŒã«ã®ã»ãã¥ãªãã£ããéåžžã®ACLã䜿çšããã¹ã€ããïŒãŸãã¯ããŸããŸãªå·¥å ŽïŒã§æ§ç¯ããããããã¯ãŒã¯ã®ã·ã³ãã«ããªã©ãå¯çšæ§ãé«ãããã®ãéžæããå¿ èŠããããŸãã
- ããŒã¿ã»ã³ã¿ãŒå ã§ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããªãããšã«æ±ºããå Žåã¯ãå¢çãžã®ã¢ã¯ã»ã¹ãå¯èœãªéãå¶éããæ¹æ³ãæ€èšããå¿ èŠããããŸãã ããšãã°ãã€ã³ã¿ãŒãããïŒã¯ã©ã€ã¢ã³ããã©ãã£ãã¯çšïŒããå¿ èŠãªããŒãã®ã¿ãéãããžã£ã³ããã¹ãããã®ã¿ããŒã¿ã»ã³ã¿ãŒãžã®ç®¡çã¢ã¯ã»ã¹ãéãããšãã§ããŸãã ãžã£ã³ããã¹ãã§ãå¿ èŠãªãã¹ãŠã®ãã§ãã¯ãå®è¡ããŸãïŒèªèšŒ/æ¿èªããŠã€ã«ã¹å¯Ÿçããã°èšé²ãªã©ïŒã
- PSEFABRICã®äŸp002ã§èª¬æãããŠããã¹ããŒã ãšåæ§ã«ãããŒã¿ã»ã³ã¿ãŒãããã¯ãŒã¯ã®ã»ã°ã¡ã³ããžã®è«çããŒãã£ã·ã§ã³ã䜿çšã§ããŸãã ãã®å Žåãé 延ãŸãã¯é«åŒ·åºŠã®ãã©ãã£ãã¯ã«ææãªãã©ãã£ãã¯ã1ã€ã®ã»ã°ã¡ã³ãïŒp002ãVRF-aã®å ŽåïŒã«ãå ¥ããããã¡ã€ã¢ãŠã©ãŒã«ãééããªãããã«ã«ãŒãã£ã³ã°ãæ§æããå¿ èŠããããŸãã ç°ãªãã»ã°ã¡ã³ãéã®ãã©ãã£ãã¯ã¯åŒãç¶ããã¡ã€ã¢ãŠã©ãŒã«ãééããŸãã VRFéã®ã«ãŒããªãŒã¯ã䜿çšããŠããã¡ã€ã¢ãŠã©ãŒã«ãééãããã©ãã£ãã¯ã®ãªãã€ã¬ã¯ããåé¿ããããšãã§ããŸãã
- ãŸãããããã®èŠå ïŒé 延/ããã©ãŒãã³ã¹ïŒãéèŠã§ãªãVLANã«å¯ŸããŠã®ã¿ãééã¢ãŒãã§ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšã§ããŸãã ãã ãããã³ããŒããšã«ãã®modã®äœ¿çšã«é¢é£ããå¶éãæ éã«æ€èšããå¿ èŠããããŸãã
- ãµãŒãã¹ãã§ãŒã³ã¢ãŒããã¯ãã£ã®é©çšãæ€èšããŠãã ããã ããã«ãããå¿ èŠãªãã©ãã£ãã¯ã®ã¿ããã¡ã€ã¢ãŠã©ãŒã«çµç±ã§éä¿¡ã§ããŸãã çè«çã«ã¯çŸããããã«èŠããŸããããã®ãœãªã¥ãŒã·ã§ã³ãå®éã«èŠãããšã¯ãããŸããã çŽ3幎åã«Cisco ACI / Juniper SRX / F5 LTMã®ãµãŒãã¹ãã§ãŒã³ããã¹ãããŸãããããã®æç¹ã§ã¯ãã®ãœãªã¥ãŒã·ã§ã³ã¯ãçãã®ããã§ãã
ä¿è·ã¬ãã«
ããã§ããã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã°ã«äœ¿çšããããŒã«ã®è³ªåã«çããå¿ èŠããããŸãã NGFWã«éåžžååšããæ©èœã®äžéšã次ã«ç€ºããŸãïŒããšãã°ã ãã¡ã ïŒã
- ã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ïŒããã©ã«ãïŒ
- ã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«
- è åšã®é²æ¢ïŒãŠã€ã«ã¹å¯Ÿçãã¹ãã€ãŠã§ã¢å¯Ÿçãè匱æ§ïŒ
- URLãã£ã«ã¿ãªã³ã°
- ããŒã¿ãã£ã«ã¿ãªã³ã°ïŒã³ã³ãã³ããã£ã«ã¿ãªã³ã°ïŒ
- ãã¡ã€ã«ã®ãããã¯ïŒãã¡ã€ã«ã®çš®é¡ã®ãããã¯ïŒ
- ãã¹ä¿è·
ãŸãããã¹ãŠãæ確ã§ã¯ãããŸããã ä¿è·ã®ã¬ãã«ãé«ãã»ã©è¯ãããã«æãããŸãã ããããããªãããããèæ ®ããå¿ èŠããããŸã
- äžèšã®ãã¡ã€ã¢ãŠã©ãŒã«æ©èœã䜿çšããã°ããã»ã©ãåœç¶ããé«äŸ¡ã«ãªããŸãïŒã©ã€ã»ã³ã¹ãè¿œå ã¢ãžã¥ãŒã«ïŒ
- ç¹å®ã®ã¢ã«ãŽãªãºã ã䜿çšãããšããã¡ã€ã¢ãŠã©ãŒã«ã®ã¹ã«ãŒããããå€§å¹ ã«äœäžããé 延ãå¢å ããå¯èœæ§ããããŸããããšãã°ã ãã¡ããåç §ããŠãã ãã
- è€éãªãœãªã¥ãŒã·ã§ã³ãšåæ§ã«ãè€éãªä¿è·æ¹æ³ã䜿çšãããšããœãªã¥ãŒã·ã§ã³ã®ä¿¡é Œæ§ãäœäžããå¯èœæ§ããããŸããããšãã°ãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŠããå Žåãéåžžã«æšæºçãªåäœäžã®ã¢ããªã±ãŒã·ã§ã³ïŒdnsãsmbïŒ
éåžžããããã¯ãŒã¯ã«æé©ãªãœãªã¥ãŒã·ã§ã³ãèŠã€ããå¿ èŠããããŸãã
ã©ã®ä¿è·æ©èœãå¿ èŠããšãã質åã«æ確ã«çããããšã¯äžå¯èœã§ãã ãŸãã転éãŸãã¯ä¿åããä¿è·ããããšããŠããããŒã¿ã«äŸåããããã§ãã 第äºã«ãå®éã«ã¯ãææžçã®éžæã¯ãã³ããŒã«å¯Ÿããä¿¡é Œãšä¿¡é Œã®åé¡ã§ããããšãå€ãã ã¢ã«ãŽãªãºã ãããããªããã¢ã«ãŽãªãºã ã®å¹æãããããªããå®å šã«ãã¹ãããããšã¯ã§ããŸããã
ãããã£ãŠãéèŠãªã»ã°ã¡ã³ãã§ã¯ãããŸããŸãªäŒæ¥ããã®ãªãã¡ãŒã䜿çšããã®ãè¯ã解決çãããããŸããã ããšãã°ããã¡ã€ã¢ãŠã©ãŒã«ã§ãŠã€ã«ã¹å¯Ÿçãæå¹ã«ã§ããŸããããã¹ãã§ããŒã«ã«ã«ãŠã€ã«ã¹å¯Ÿçä¿è·ïŒå¥ã®è£œé å ããïŒã䜿çšããããšãã§ããŸãã
ã»ã°ã¡ã³ããŒã·ã§ã³
ããã¯ãããŒã¿ã»ã³ã¿ãŒãããã¯ãŒã¯ã®è«ççãªåºåã§ãã ããšãã°ãVLANãšãµããããã«åå²ããããšãè«ççãªã»ã°ã¡ã³ããŒã·ã§ã³ã§ããããã®èªææ§ã®ããèæ ®ããŸããã FWã»ãã¥ãªãã£ãŸãŒã³ãVRFïŒããã³ããŸããŸãªãã³ããŒã«é¢é£ããé¡äŒŒç©ïŒãè«çããã€ã¹ïŒPA VSYSãCisco N7K VDCãCisco ACIããã³ããªã©ïŒãªã©ã®ãšã³ãã£ãã£ãèæ ®ãããšãã»ã°ã¡ã³ããŒã·ã§ã³ã¯èå³æ·±ããã®ã§ã...
ãã®ãããªè«ççãªã»ã°ã¡ã³ããŒã·ã§ã³ãšçŸåšå¿ èŠãªããŒã¿ã»ã³ã¿ãŒãã¶ã€ã³ã®äŸã¯PSEFABRICãããžã§ã¯ãã®p002ã§äžããããŸãããããã¯ãŒã¯ã®è«çéšåãå®çŸ©ãããããã©ãã£ãã¯ãç°ãªãã»ã°ã¡ã³ãéã§ã©ã®ããã«æµããããã©ã®ããã€ã¹ã§ã©ã®ãããªæ段ã§ãã£ã«ã¿ãªã³ã°ãå®è¡ãããããããã«èª¬æã§ããŸãã
ãããã¯ãŒã¯ã«æ確ãªè«çããŒãã£ã·ã§ã³ããªããç°ãªãããŒã¿ãããŒã«ã»ãã¥ãªãã£ããªã·ãŒãé©çšããããã®ã«ãŒã«ãæ£åŒåãããŠããªãå Žåãããã¯ããã®ã¢ã¯ã»ã¹ãŸãã¯ãã®ã¢ã¯ã»ã¹ãéããšããã®åé¡ã匷å¶çã«è§£æ±ºããããšãæå³ããé«ã確çã§æ¯å解決ããŸãããŸããŸãªæ¹æ³ã§ã
å€ãã®å Žåãã»ã°ã¡ã³ããŒã·ã§ã³ã¯FWã»ãã¥ãªãã£ãŸãŒã³ã®ã¿ã«åºã¥ããŠããŸãã 次ã«ã次ã®è³ªåã«çããå¿ èŠããããŸãã
- ã©ã®ã»ãã¥ãªãã£ãŸãŒã³ãå¿ èŠã§ãã
- ãããã®åãŸãŒã³ã«ã©ã®ã¬ãã«ã®ä¿è·ãé©çšããŸãã
- ãŸãŒã³å ãã©ãã£ãã¯ãããã©ã«ãã§èš±å¯ããããã©ãã
- ããã§ãªãå ŽåãåãŸãŒã³å ã§é©çšããããã©ãã£ãã¯ãã£ã«ã¿ãªã³ã°ããªã·ãŒ
- ãŸãŒã³ã®åãã¢ïŒãœãŒã¹/å®å ïŒã«é©çšããããã©ãã£ãã¯ãã£ã«ã¿ãªã³ã°ããªã·ãŒ
TCAM
å€ãã®å Žåãã«ãŒãã£ã³ã°ãšã¢ã¯ã»ã¹ã®äž¡æ¹ã§TCAMïŒTernary Content Addressable MemoryïŒãäžååã§ãããšããåé¡ããããŸãã ç§èŠãããã¯æ©åšãéžæããéã®æãéèŠãªåé¡ã®1ã€ãªã®ã§ããã®åé¡ãé©åãªç²ŸåºŠã§åŠçããå¿ èŠããããŸãã
äŸ1.転éããŒãã«TCAMã
Palo Alto 7kãã¡ã€ã¢ãŠã©ãŒã«ãèŠãŠã¿ãŸãããã
IPv4転éããŒãã«ãµã€ãº* = 32KãããããŸã
åæã«ããã®ã«ãŒãæ°ã¯ãã¹ãŠã®VSYSã«å ±éã§ãã
èšèšã«å¿ããŠ4ã€ã®VSYSã䜿çšãããšæ±ºãããšããŸãã
ãããã®åBGPS VSYSã¯ãBBãšããŠäœ¿çšãã2ã€ã®MPLSã¯ã©ãŠãPEã«æ¥ç¶ãããŠããŸãã ãããã£ãŠã4ã€ã®VSYSã¯ãã¹ãŠã®ç¹å®ã®ã«ãŒããçžäºã«äº€æããã»ãŒåãã«ãŒãã»ããïŒãã ããç°ãªãNHïŒãæã€è»¢éããŒãã«ãæã£ãŠããŸãã ãªããªã åVSYSã«ã¯2ã€ã®BGPã»ãã·ã§ã³ïŒåãèšå®ïŒããããMPLSãä»ããŠåä¿¡ããåã«ãŒãã«ã¯2ã€ã®NHããããããã«å¿ããŠè»¢éããŒãã«ã«2ã€ã®FIBãšã³ããªããããŸãã ãããããŒã¿ã»ã³ã¿ãŒå ã®å¯äžã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ããããã¹ãŠã®ã«ãŒãã«ã€ããŠç¥ã£ãŠããå¿ èŠããããšä»®å®ããå Žåãããã¯ããŒã¿ã»ã³ã¿ãŒå ã®ã«ãŒãã®ç·æ°ã32K /ïŒ4 * 2ïŒ= 4Kãè¶ ããŠã¯ãªããªãããšãæå³ããŸãã
ããã§ã2ã€ã®ããŒã¿ã»ã³ã¿ãŒïŒåããã¶ã€ã³ïŒããããããŒã¿ã»ã³ã¿ãŒéã§ãã¹ãã¬ããããããVLANã䜿çšããå ŽåïŒvMotionãªã©ïŒãã«ãŒãã£ã³ã°ã®åé¡ã解決ããã«ã¯ã次ã䜿çšããå¿ èŠããããŸãããã¹ãã«ãŒãã§ãããããã¯2ã€ã®ããŒã¿ã»ã³ã¿ãŒã«äœ¿çšã§ãããã¹ãã4096以äžã§ããããšãæå³ãããã¡ããããã§ã¯ååã§ã¯ãããŸããã
äŸ2. ACL TCAMãTCAMãäžååã§ãããšããåé¡ãçºçããå Žåã¯ããŸãæåã«ãæé©åã®å¯èœæ§ãèæ ®ããå¿ èŠããããŸãã ãã®ããããã©ã¯ãŒãã£ã³ã°ããŒãã«ã®ãµã€ãºã«åé¡ãããå Žåã¯ãã«ãŒããéçŽããå¯èœæ§ãèæ ®ããå¿ èŠããããŸãã ã¢ã¯ã»ã¹ã®TCAMãµã€ãºã«åé¡ãããå Žå-ã¢ã¯ã»ã¹ã®ç£æ»ãå€ãã¬ã³ãŒããšéè€ããã¬ã³ãŒãã®åé€ãããã³ããããã¢ã¯ã»ã¹ãéãããã®æé ã®æ¹èšïŒã¢ã¯ã»ã¹ç£æ»ã®ç« ã§è©³çŽ°ã«èª¬æããŸãïŒã
L3ã¹ã€ããïŒãŸãã¯Cisco ACIãªã©ã®L3ã¹ã€ããã䜿çšããä»ã®ãœãªã¥ãŒã·ã§ã³ïŒã§ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããå Žåã¯ãæ©åšãéžæãããšãã«TCAM ACLã«æ³šæããå¿ èŠããããŸãã
Cisco Catalyst 4500 SVIã€ã³ã¿ãŒãã§ã€ã¹ã§ã¢ã¯ã»ã¹ãå¶åŸ¡ããå Žåã ãã®èšäºãããããããã«ãTCAMã®4096è¡ã®ã¿ã䜿çšããŠãã€ã³ã¿ãŒãã§ã€ã¹äžã®çºä¿¡ïŒããã³çä¿¡ïŒãã©ãã£ãã¯ãå¶åŸ¡ã§ããŸãã TCAM3ã䜿çšãããšãçŽ4000äžACEïŒåç·ACLïŒãåŸãããŸãã
é«å¯çšæ§
åé¡ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«HAã䜿çšãããã2ã€ã®ç¬ç«ããããã¯ã¹ãã䞊åãã«é 眮ããããã©ã¡ãããã¯ã©ãã·ã¥ããå Žåã«ãã©ãã£ãã¯ã2çªç®ã«ã«ãŒãã£ã³ã°ãããã©ããã§ãã
çãã¯æããã ãšæãããŸã-HAã䜿çšããŸãã ããã«ãããããããã®åé¡ãçºçããçç±ã¯ãæ®å¿µãªãããçè«äžããã³åºå99ããã³å®éã®ã¢ã¯ã»ã·ããªãã£ã®ããŒã»ã³ãã®å°æ°ç¹ä»¥äžã®æ°9ã¯ãã¯ããã«ãã©è²ãå°ãªãããšãå€æããããã§ãã HAã¯è«ççã«éåžžã«è€éãªãã®ã§ãããç°ãªãæ©åšãç°ãªããã³ããŒïŒäŸå€ã¯ãããŸããã§ããïŒã§ãåé¡ããã°ãèŠã€ããŠãµãŒãã¹ãåæ¢ããŸããã
HAã䜿çšããå Žåãåã ã®ããŒãããªãã«ãããµãŒãã¹ãåæ¢ããã«ããŒãéãåãæ¿ããããšãã§ããŸããããã¯ãããšãã°ã¢ããã°ã¬ãŒãã®éã«éèŠã§ãããäž¡æ¹ã®ããŒããåæã«å£ããå¯èœæ§ã¯æ±ºããŠãããŸããããã³ããŒãçŽæããã»ã©ã¢ããã°ã¬ãŒãã¯ã¹ã ãŒãºã«é²ã¿ãŸããïŒå®éšè£ 眮ã§ã¢ããã°ã¬ãŒãããã¹ãããæ©äŒãããã°ããã®åé¡ã¯åé¿ã§ããŸãïŒã
HAã䜿çšããªãå Žåãäºéã®æå·ã®èŠ³ç¹ããããªã¹ã¯ã¯ã¯ããã«äœããªããŸãïŒ2ã€ã®ç¬ç«ãããã¡ã€ã¢ãŠã©ãŒã«ãããããïŒã ã»ãã·ã§ã³ã¯åæãããªãããããããã®ãã¡ã€ã¢ãŠã©ãŒã«éã®åãæ¿ããçºçãããã³ã«ããã©ãã£ãã¯ã倱ãããŸãã ãã¡ãããã¹ããŒãã¬ã¹ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšã§ããŸããããã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããæå³ã¯ã»ãšãã©å€±ãããŸãã
ãããã£ãŠãç£æ»ã®çµæãå€ç¬ãªãã¡ã€ã¢ãŠã©ãŒã«ãèŠã€ããããããã¯ãŒã¯ã®ä¿¡é Œæ§ãé«ããããšãèããŠããå ŽåãHAã¯ãã¡ããæšå¥šããããœãªã¥ãŒã·ã§ã³ã®1ã€ã§ããããã®ã¢ãããŒãã«é¢é£ããæ¬ ç¹ãèæ ®ããå¿ èŠããããŸããå¥ã®ãœãªã¥ãŒã·ã§ã³ãããé©åã§ãã
管çã®å©äŸ¿æ§ïŒç®¡çæ§ïŒ
ååãšããŠãHAã¯ç®¡çæ§ã«ãé¢ä¿ããŠããŸãã 2ã€ã®ããã¯ã¹ãåå¥ã«æ§æããŠæ§æã®åæã®åé¡ã解決ãã代ããã«ã1ã€ã®ããã€ã¹ããããã®ããã«å€ãã®æ¹æ³ã§ãããã管çããŸãã
ããããããããããªãã¯å€ãã®ããŒã¿ã»ã³ã¿ãŒãšå€ãã®ãã¡ã€ã¢ãŠã©ãŒã«ãæã£ãŠããã§ãããããããŠãã®è³ªåã¯æ°ããã¬ãã«ã«äžãããŸãã ãããŠè³ªåã¯èšå®ã ãã§ãªãã
- ããã¯ã¢ããæ§æ
- æŽæ°
- ã¢ããã°ã¬ãŒã
- ç£èŠ
- ãã®ã³ã°
ãããŠããããã¯ãã¹ãŠéäžç®¡çã·ã¹ãã ã«ãã£ãŠè§£æ±ºã§ããŸãã
ããšãã°ãPalo Altoãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŠããå Žåã Panoramaã¯ãã®ãããªãœãªã¥ãŒã·ã§ã³ã§ãã
ç¶ç¶ããã