
Palo Alto Networksãã¡ã€ã¢ãŠã©ãŒã«ã®ãã¹ãŠã®å©ç¹ã«ãããããããRuNetã§ãããã®ããã€ã¹ãæ§æããæ¹æ³ã«é¢ããè³æãããã®å®è£ ã®çµéšã説æããããã¹ãã¯ããŸããããŸããã ãã®ãã³ããŒã®æ©åšãšã®äœæ¥äžã«èç©ããè³æãèŠçŽããããŸããŸãªãããžã§ã¯ãã®å®è£ äžã«ééããæ©èœã«ã€ããŠè©±ãããšã«ããŸããã
ãã®èšäºã§ã¯ãPalo Alto Networksã«ç²Ÿéããããã«ãæãäžè¬çãªãã¡ã€ã¢ãŠã©ãŒã«ã¿ã¹ã¯ã®1ã€ã§ãããªã¢ãŒãã¢ã¯ã»ã¹çšã®SSL VPNã解決ããããã«å¿ èŠãªèšå®ã«ã€ããŠèª¬æããŸãã ãŸãããã¡ã€ã¢ãŠã©ãŒã«ã®äžè¬çãªæ§æããŠãŒã¶ãŒã®èå¥ãã¢ããªã±ãŒã·ã§ã³ãããã³ã»ãã¥ãªãã£ããªã·ãŒã®è£å©æ©èœã«ã€ããŠã説æããŸãã ãã®ãããã¯ãèªè ã®é¢å¿ãåŒããã®ã§ããå Žåãä»åŸããµã€ãéVPNãåçã«ãŒãã£ã³ã°ãããã³ããã©ãã䜿çšããéäžç®¡çã®åæãå«ãè³æããªãªãŒã¹ããŸãã
ããã¢ã«ããããã¯ãŒã¯ã¹ã®ãã¡ã€ã¢ãŠã©ãŒã«ã¯ãApp-IDãUser-IDãContent-IDãªã©ã®å€ãã®é©æ°çãªãã¯ãããžãŒã䜿çšããŠããŸãã ãã®æ©èœã䜿çšãããšãé«åºŠãªã»ãã¥ãªãã£ãå®çŸããŸãã ããšãã°ãApp-IDã䜿çšãããšã䜿çšãããŠããããŒãããããã³ã«ïŒSSLãã³ãã«å ãå«ãïŒã«é¢ä¿ãªãã眲åããã³ãŒããããã³ãã¥ãŒãªã¹ãã£ãã¯ã«åºã¥ããŠã¢ããªã±ãŒã·ã§ã³ãã©ãã£ãã¯ãèå¥ã§ããŸãã ãŠãŒã¶ãŒIDã䜿çšãããšãLDAPãšã®çµ±åã«ãããããã¯ãŒã¯ãŠãŒã¶ãŒãèå¥ã§ããŸãã Content-IDã䜿çšãããšããã©ãã£ãã¯ãã¹ãã£ã³ãã転éããããã¡ã€ã«ãšãã®ã³ã³ãã³ããèå¥ã§ããŸãã ãã®ä»ã®ãã¡ã€ã¢ãŠã©ãŒã«æ©èœã«ã¯ãäŸµå ¥ä¿è·ãè匱æ§ããã³DoSæ»æã«å¯Ÿããä¿è·ãçµã¿èŸŒã¿ã®ã¹ãã€ãŠã§ã¢å¯ŸçãURLãã£ã«ã¿ãªã³ã°ãã¯ã©ã¹ã¿ãªã³ã°ãããã³éäžç®¡çãå«ãŸããŸãã
ãã¢ã³ã¹ãã¬ãŒã·ã§ã³ã®ããã«ãããã€ã¹åãADãã¡ã€ã³åãããã³IPã¢ãã¬ã¹ãé€ããŠãå®éã®æ§æãšåãæ§æã®åé¢ãããã¹ã¿ã³ãã䜿çšããŸãã å®éã«ã¯ããã¹ãŠãããè€éã§ã-å€ãã®ãã©ã³ããããå ŽåããããŸãã ãã®å Žåãåäžã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãªããäžå€®ãµã€ãã®å¢çã«ã¯ã©ã¹ã¿ãŒãã€ã³ã¹ããŒã«ãããåçã«ãŒãã£ã³ã°ãå¿ èŠã«ãªãå ŽåããããŸãã
ã¹ã¿ã³ãã¯PAN-OS 7.1.9ã䜿çšããŸãã å žåçãªæ§æãšããŠãå¢çã«Palo Alto Networksãã¡ã€ã¢ãŠã©ãŒã«ããããããã¯ãŒã¯ãèããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã¯ãæ¬ç€Ÿãžã®ãªã¢ãŒãSSL VPNã¢ã¯ã»ã¹ãæäŸããŸãã Active Directoryãã¡ã€ã³ã¯ãŠãŒã¶ãŒããŒã¿ããŒã¹ãšããŠäœ¿çšãããŸãïŒå³1ïŒã

å³1-ãããã¯ãŒã¯ãããã¯å³
èšå®æé ïŒ
- ããã€ã¹ã®ããªã»ããã ååã管çIPã¢ãã¬ã¹ãéçã«ãŒãã管çè ã¢ã«ãŠã³ãã管çãããã¡ã€ã«ã®èšå®
- ã©ã€ã»ã³ã¹ãã€ã³ã¹ããŒã«ããã¢ããããŒããèšå®ããã³ã€ã³ã¹ããŒã«ããŸã
- ã»ãã¥ãªãã£ãŸãŒã³ããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ããã©ãã£ãã¯ããªã·ãŒãã¢ãã¬ã¹å€æã®æ§æ
- LDAPèªèšŒãããã¡ã€ã«ãšãŠãŒã¶ãŒIDãæ§æãã
- SSL VPNãæ§æãã
1.ããªã»ãã
Palo Alto Networksãã¡ã€ã¢ãŠã©ãŒã«ãæ§æããããã®äž»èŠãªããŒã«ã¯Webã€ã³ã¿ãŒãã§ãŒã¹ã§ãããCLIãä»ããå¶åŸ¡ãå¯èœã§ãã ããã©ã«ãã§ã¯ã管çã€ã³ã¿ãŒãã§ãŒã¹ã®IPã¢ãã¬ã¹ã¯192.168.1.1/24ããã°ã€ã³ïŒadminããã¹ã¯ãŒãïŒadminã§ãã
ã¢ãã¬ã¹ãå€æŽããã«ã¯ãåããããã¯ãŒã¯ããWebã€ã³ã¿ãŒãã§ã€ã¹ã«æ¥ç¶ãããã set deviceconfig system ip-address <> netmask <>ã³ãã³ãã䜿çšããŸãã æ§æã¢ãŒãã§å®è¡ãããŸãã configureã³ãã³ãã䜿çšããŠãæ§æã¢ãŒãã«åãæ¿ããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã®ãã¹ãŠã®å€æŽã¯ãã³ãã³ãã©ã€ã³ã¢ãŒããšWebã€ã³ã¿ãŒãã§ã€ã¹ã®äž¡æ¹ã§ã commitã³ãã³ãã§èšå®ã確èªããåŸã«ã®ã¿çºçããŸãã
Webã€ã³ã¿ãŒãã§ãŒã¹ã®èšå®ãå€æŽããã«ã¯ã ãããã€ã¹->äžè¬èšå®ãããã³ãããã€ã¹->管çã€ã³ã¿ãŒãã§ãŒã¹èšå®ãã»ã¯ã·ã§ã³ã䜿çšããŸãã ååããããŒãã¿ã€ã ãŸãŒã³ããã®ä»ã®èšå®ã¯ãäžè¬èšå®ã»ã¯ã·ã§ã³ã§èšå®ã§ããŸãïŒå³2ïŒã

å³2-管çã€ã³ã¿ãŒãã§ã€ã¹ã®ãã©ã¡ãŒã¿ãŒ
ESXiç°å¢ã§ä»®æ³ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšãããŠããå ŽåãïŒäžè¬èšå®ïŒã»ã¯ã·ã§ã³ã§ããã€ããŒãã€ã¶ãŒã«ãã£ãŠå²ãåœãŠãããMACã¢ãã¬ã¹ã®äœ¿çšãæå¹ã«ãããããã¡ã€ã¢ãŠã©ãŒã«ã€ã³ã¿ãŒãã§ã€ã¹ã§æå®ããããã€ããŒãã€ã¶ãŒã§MACã¢ãã¬ã¹ãæ§æããããä»®æ³ã¹ã€ããã®èšå®ãå€æŽããŠMACã®å€æŽãèš±å¯ããå¿ èŠããããŸãã¢ãã¬ã¹ã ããããªããšããã©ãã£ãã¯ã¯ééããŸããã
管çã€ã³ã¿ãŒãã§ã€ã¹ã¯åå¥ã«æ§æããããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®ãªã¹ãã«ã¯è¡šç€ºãããŸããã [ 管çã€ã³ã¿ãŒãã§ã€ã¹ã®èšå®]ã»ã¯ã·ã§ã³ã§ã¯ã管çã€ã³ã¿ãŒãã§ã€ã¹ã®ããã©ã«ãã²ãŒããŠã§ã€ãæå®ããŸãã ä»ã®éçã«ãŒãã¯ãä»®æ³ã«ãŒã¿ãŒã»ã¯ã·ã§ã³ã§æ§æãããŸããããã«ã€ããŠã¯åŸã§èª¬æããŸãã
ä»ã®ã€ã³ã¿ãŒãã§ãŒã¹ãä»ããããã€ã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããã«ã¯ã [ãããã¯ãŒã¯]-> [ãããã¯ãŒã¯ãããã¡ã€ã«]-> [ã€ã³ã¿ãŒãã§ãŒã¹ç®¡ç]ã»ã¯ã·ã§ã³ã§ç®¡çãããã¡ã€ã«ãäœæããé©åãªã€ã³ã¿ãŒãã§ãŒã¹ã«å²ãåœãŠãå¿ èŠããããŸãã
次ã«ãæŽæ°ãåä¿¡ããæå»ãæ£ãã衚瀺ããããã«ã[ ããã€ã¹]-> [ãµãŒãã¹]ã»ã¯ã·ã§ã³ã§DNSãšNTPãæ§æããå¿ èŠããããŸãïŒå³3ïŒã ããã©ã«ãã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠçæããããã¹ãŠã®ãã©ãã£ãã¯ã¯ã管çã€ã³ã¿ãŒãã§ã€ã¹ã®IPã¢ãã¬ã¹ããœãŒã¹IPã¢ãã¬ã¹ãšããŠäœ¿çšããŸãã Service Route Configurationã»ã¯ã·ã§ã³ã§ãç¹å®ã®åãµãŒãã¹ã«ç°ãªãã€ã³ã¿ãŒãã§ã€ã¹ãå²ãåœãŠãããšãã§ããŸãã

å³3-DNSãNTPãããã³ã·ã¹ãã ã«ãŒãèšå®
2.ã©ã€ã»ã³ã¹ãã€ã³ã¹ããŒã«ããã¢ããããŒããèšå®ããã³ã€ã³ã¹ããŒã«ããŸã
ãã¡ã€ã¢ãŠã©ãŒã«ã®ãã¹ãŠã®æ©èœãå®å šã«åäœãããã«ã¯ãã©ã€ã»ã³ã¹ãã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã ãã©ã€ã¢ã«ã©ã€ã»ã³ã¹ã¯ãããã¢ã«ããããã¯ãŒã¯ããŒãããŒã«ãªã¯ãšã¹ãããããšã§äœ¿çšã§ããŸãã æå¹æéã¯30æ¥ã§ãã ã©ã€ã»ã³ã¹ã¯ããã¡ã€ã«ãŸãã¯èªèšŒã³ãŒãã䜿çšããŠã¢ã¯ãã£ãåãããŸãã ã©ã€ã»ã³ã¹ã¯ã[ ããã€ã¹]-> [ã©ã€ã»ã³ã¹]ã»ã¯ã·ã§ã³ã§æ§æãããŸãïŒå³4ïŒã
ã©ã€ã»ã³ã¹ãã€ã³ã¹ããŒã«ãããã[ ããã€ã¹]-> [åçæŽæ°]ã»ã¯ã·ã§ã³ã§æŽæ°ããã°ã©ã ã®ã€ã³ã¹ããŒã«ãæ§æããå¿ èŠããããŸãã
[ããã€ã¹]-> [ãœãããŠã§ã¢]ã»ã¯ã·ã§ã³ã§ãPAN-OSã®æ°ããããŒãžã§ã³ãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ã§ããŸãã

å³4-ã©ã€ã»ã³ã¹ã³ã³ãããŒã«ããã«
3.ã»ãã¥ãªãã£ãŸãŒã³ããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ããã©ãã£ãã¯ããªã·ãŒãã¢ãã¬ã¹å€æã®æ§æ
Palo Alto Networksãã¡ã€ã¢ãŠã©ãŒã«ã¯ããããã¯ãŒã¯ã«ãŒã«ãæ§æãããšãã«ãŸãŒã³ããžãã¯ãé©çšããŸãã ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã¯ç¹å®ã®ãŸãŒã³ã«å²ãåœãŠããããã©ãã£ãã¯ã«ãŒã«ã§äœ¿çšãããŸãã ãã®ã¢ãããŒãã«ãããå°æ¥ãã€ã³ã¿ãŒãã§ãŒã¹èšå®ãå€æŽãããšãã«ããã©ãã£ãã¯ã«ãŒã«ãå€æŽããã®ã§ã¯ãªããå¿ èŠãªã€ã³ã¿ãŒãã§ãŒã¹ã察å¿ãããŸãŒã³ã«åå²ãåœãŠããããšãã§ããŸãã ããã©ã«ãã§ã¯ããŸãŒã³å ã®ãã©ãã£ãã¯ã¯èš±å¯ããããŸãŒã³éã®ãã©ãã£ãã¯ã¯çŠæ¢ãããŸããããã«ã¯ã intrazone-defaultããã³interzone-defaultã®äºåå®çŸ©ã«ãŒã«ã責任ãè² ããŸã ã

å³5-ã»ãã¥ãªãã£ãŸãŒã³
ãã®äŸã§ã¯ãå éšãããã¯ãŒã¯ã®ã€ã³ã¿ãŒãã§ã€ã¹ã¯å éšãŸãŒã³ã«å²ãåœãŠãããã€ã³ã¿ãŒãããã«åããããã€ã³ã¿ãŒãã§ã€ã¹ã¯å€éšãŸãŒã³ã«å²ãåœãŠãããŸãã vpnãŸãŒã³ã«å²ãåœãŠãããSSL VPNçšã®ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ãäœæãããŸããïŒå³5ïŒã
Palo Alto Networksãã¡ã€ã¢ãŠã©ãŒã«ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã¯ã5ã€ã®ç°ãªãã¢ãŒãã§åäœã§ããŸãã
- ã¿ãã -ç£èŠããã³åæã®ããã«ãã©ãã£ãã¯ãåéããããã«äœ¿çšãããŸãã
- HA-ã¯ã©ã¹ã¿ãŒæäœã«äœ¿çš
- ä»®æ³ã¯ã€ã€ -ãã®ã¢ãŒãã§ã¯ãPalo Alto Networksã¯2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ãçµã¿åãããMACã¢ãã¬ã¹ãšIPã¢ãã¬ã¹ãå€æŽããã«ããããã®éã§ééçã«ãã©ãã£ãã¯ãæž¡ããŸã
- Layer2-ã¹ã€ããã¢ãŒã
- ã¬ã€ã€ãŒ3-ã«ãŒã¿ãŒã¢ãŒã

å³6-ã€ã³ã¿ãŒãã§ãŒã¹ã®åäœã¢ãŒãã®èšå®
ãã®äŸã§ã¯ãLayer3ã¢ãŒãã䜿çšãããŸãïŒå³6ïŒã ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®ãã©ã¡ãŒã¿ãŒã¯ãIPã¢ãã¬ã¹ãåäœã¢ãŒããããã³å¯Ÿå¿ããã»ãã¥ãªãã£ãŸãŒã³ã瀺ããŸãã ã€ã³ã¿ãŒãã§ãŒã¹ã®åäœã¢ãŒãã«å ããŠãä»®æ³ã«ãŒã¿ãŒã«å²ãåœãŠãå¿ èŠããããŸããããã¯ãPalo Alto Networksã®VRFã€ã³ã¹ã¿ã³ã¹ã«é¡äŒŒããŠããŸãã ä»®æ³ã«ãŒã¿ãŒã¯çžäºã«åé¢ãããŠãããç¬èªã®ã«ãŒãã£ã³ã°ããŒãã«ãšãããã¯ãŒã¯ãããã³ã«èšå®ããããŸãã
ä»®æ³ã«ãŒã¿ãŒã®èšå®ã¯ãéçã«ãŒããšã«ãŒãã£ã³ã°ãããã³ã«ã®èšå®ã瀺ããŸãã ãã®äŸã§ã¯ãå€éšãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹çšã«ããã©ã«ãã«ãŒãã®ã¿ãäœæãããŸããïŒå³7ïŒã

å³7-ä»®æ³ã«ãŒã¿ãŒã®æ§æ
次ã®èšå®æé ã¯ããã©ãã£ãã¯ããªã·ãŒã®ã»ã¯ã·ã§ã³ããªã·ãŒ->ã»ãã¥ãªãã£ã§ãã æ§æã®äŸãå³8ã«ç€ºããŸããã«ãŒã«ã®ããžãã¯ã¯ããã¹ãŠã®ãã¡ã€ã¢ãŠã©ãŒã«ãšåãã§ãã æåã«äžèŽãããŸã§ãã«ãŒã«ã¯äžããäžã«ãã§ãã¯ãããŸãã ã«ãŒã«ã®ç°¡åãªèª¬æïŒ
1. WebããŒã¿ã«ãžã®SSL VPNã¢ã¯ã»ã¹ã ãªã¢ãŒãæ¥ç¶ãèªèšŒããããã®WebããŒã¿ã«ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸã
2. VPNãã©ãã£ãã¯-ãªã¢ãŒãæ¥ç¶ãšæ¬ç€Ÿéã®ãã©ãã£ãã¯ãèš±å¯ããŸã
3.åºæ¬çãªã€ã³ã¿ãŒããã-dnsãpingãtracerouteãntpã¢ããªã±ãŒã·ã§ã³ã®èš±å¯ã ãã¡ã€ã¢ãŠã©ãŒã«ã¯ãããŒãçªå·ãšãããã³ã«çªå·ã§ã¯ãªãã眲åããã³ãŒããããã³ãã¥ãŒãªã¹ãã£ãã¯ã«åºã¥ããã¢ããªã±ãŒã·ã§ã³ãèš±å¯ãããããapplication-defaultã¯Serviceã»ã¯ã·ã§ã³ã§æå®ãããŸãã ãã®ã¢ããªã±ãŒã·ã§ã³ã®ããã©ã«ãã®ããŒã/ãããã³ã«
4. Webã¢ã¯ã»ã¹-ã¢ããªã±ãŒã·ã§ã³å¶åŸ¡ãªãã§HTTPããã³HTTPSçµç±ã§ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããèš±å¯
5,6ã ä»ã®ãã©ãã£ãã¯ã®ããã©ã«ãã«ãŒã«ã

å³8-ãããã¯ãŒã¯ã«ãŒã«ã®èšå®äŸ
NATãèšå®ããã«ã¯ã[ ããªã·ãŒ]-> [NAT]ã»ã¯ã·ã§ã³ã䜿çšããŸã ã NATæ§æã®äŸãå³9ã«ç€ºããŸãã

å³9-NATèšå®ã®äŸ
å éšããå€éšãžã®ãã©ãã£ãã¯ã«ã€ããŠã¯ãéä¿¡å ã¢ãã¬ã¹ããã¡ã€ã¢ãŠã©ãŒã«ã®å€éšIPã¢ãã¬ã¹ã«å€æŽããåçããŒãã¢ãã¬ã¹ïŒPATïŒã䜿çšã§ããŸãã
4. LDAPèªèšŒãããã¡ã€ã«ãšãŠãŒã¶ãŒèå¥æ©èœãæ§æãã
ãŠãŒã¶ãŒãSSL-VPNçµç±ã§æ¥ç¶ããåã«ãèªèšŒã¡ã«ããºã ãæ§æããå¿ èŠããããŸãã ãã®äŸã§ã¯ãPalo Alto Networks Webã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠActive Directoryãã¡ã€ã³ã³ã³ãããŒã©ãŒã§èªèšŒãè¡ãããŸãã

å³10-LDAPãããã¡ã€ã«
èªèšŒãæ©èœãããã«ã¯ã LDAPãããã¡ã€ã«ãšèªèšŒãããã¡ã€ã«ãæ§æããå¿ èŠããããŸãã [ããã€ã¹]-> [ãµãŒããŒãããã¡ã€ã«]-> [LDAP]ã»ã¯ã·ã§ã³ïŒå³10ïŒã§ã¯ã ãµãŒããŒãªãã¬ãŒã¿ãŒ ã ã€ãã³ããã°ãªãŒã㌠ã åæ£COMãŠãŒã¶ãŒã°ã«ãŒãã«å«ãŸãããã¡ã€ã³ã³ã³ãããŒã©ãŒã®IPã¢ãã¬ã¹ãšããŒããLDAPã¿ã€ããšãŠãŒã¶ãŒã¢ã«ãŠã³ããæå®ããå¿ èŠããããŸãã 次ã«ã [ããã€ã¹]-> [èªèšŒãããã¡ã€ã«]ã»ã¯ã·ã§ã³ã§èªèšŒãããã¡ã€ã«ãäœæãïŒå³11ïŒã以åã«äœæããLDAPãããã¡ã€ã«ãããŒã¯ãã[詳现èšå®]ã¿ãã§ãªã¢ãŒãã¢ã¯ã»ã¹ãèš±å¯ãããŠãŒã¶ãŒã®ã°ã«ãŒãïŒå³12ïŒãæå®ããŸãã ãããã¡ã€ã«ã®User Domainãã©ã¡ãŒã¿ã«æ³šæããããšãéèŠã§ããããããªããšãã°ã«ãŒãããŒã¹ã®èªèšŒãæ©èœããŸããã ãã®ãã£ãŒã«ãã«ã¯ãNetBIOSãã¡ã€ã³åãå«ãŸããŠããå¿ èŠããããŸãã

å³11-èªèšŒãããã¡ã€ã«

å³12-ADã°ã«ãŒãã®éžæ
次ã®ã¹ãããã¯ã ããã€ã¹->ãŠãŒã¶ãŒèå¥ãæ§æããããšã§ãã ããã§ã¯ããã¡ã€ã³ã³ã³ãããŒã©ãŒã®IPã¢ãã¬ã¹ãæ¥ç¶ã®è³æ Œæ å ±ãæå®ãã ã»ãã¥ãªãã£ãã°ã® æå¹åãã»ãã·ã§ã³ã® æå¹åããããŒãã® æå¹åã®èšå®ãæ§æããå¿ èŠããããŸãïŒå³13ïŒã [ ã°ã«ãŒããããã³ã°]ã»ã¯ã·ã§ã³ïŒå³14ïŒã§ã¯ãLDAPã®ãªããžã§ã¯ããèå¥ããããã®ãã©ã¡ãŒã¿ãŒãšãæ¿èªã«äœ¿çšãããã°ã«ãŒãã®ãªã¹ãã«æ³šæããå¿ èŠããããŸãã èªèšŒãããã¡ã€ã«ãšåãããã«ãããã§ã¯ãŠãŒã¶ãŒãã¡ã€ã³ãã©ã¡ãŒã¿ãŒãèšå®ããå¿ èŠããããŸãã

å³13-ãŠãŒã¶ãŒãããã³ã°ãã©ã¡ãŒã¿ãŒ

å³14-ã°ã«ãŒããããã³ã°ãã©ã¡ãŒã¿ãŒ
ãã®æé ã®æåŸã®æé ã¯ãVPNãŸãŒã³ãšãã®ãŸãŒã³ã®ã€ã³ã¿ãŒãã§ã€ã¹ãäœæããããšã§ãã ã€ã³ã¿ãŒãã§ã€ã¹ã§ã [ãŠãŒã¶ãŒèå¥ãæå¹ã«ãã]ãã©ã¡ãŒã¿ãŒãæå¹ã«ããŸãïŒå³15ïŒã

å³15-VPNãŸãŒã³ã®æ§æ
5. SSL VPNãæ§æãã
SSL VPNã«æ¥ç¶ããåã«ããªã¢ãŒããŠãŒã¶ãŒã¯WebããŒã¿ã«ã«ã¢ã¯ã»ã¹ããŠãGlobal Protectã¯ã©ã€ã¢ã³ããèªèšŒããã³ããŠã³ããŒãããå¿ èŠããããŸãã 次ã«ããã®ã¯ã©ã€ã¢ã³ãã¯è³æ Œæ å ±ãèŠæ±ããäŒæ¥ãããã¯ãŒã¯ã«æ¥ç¶ããŸãã WebããŒã¿ã«ã¯httpsã¢ãŒãã§åäœããããããã®ããã®èšŒææžãã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã å¯èœã§ããã°ãå ¬é蚌ææžã䜿çšããŠãã ããã ãã®å ŽåããŠãŒã¶ãŒã«ã¯ããµã€ãã§èšŒææžãç¡å¹ã§ããããšã«é¢ããèŠåã¯è¡šç€ºãããŸããã ãããªãã¯èšŒææžã䜿çšã§ããªãå Žåã¯ãç¬èªã®èšŒææžãçºè¡ããå¿ èŠããããŸããããã¯ãhttpsã®WebããŒãžã§äœ¿çšãããŸãã èªå·±çœ²åããããšããããŒã«ã«ã®èšŒææ©é¢ãéããŠçºè¡ããããšãã§ããŸãã ãŠãŒã¶ãŒãWebããŒã¿ã«ã«æ¥ç¶ãããšãã«ãšã©ãŒãåãåããªãããã«ããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã®ä¿¡é Œãããã«ãŒãã»ã³ã¿ãŒã®ãªã¹ãã«ã«ãŒã蚌ææžãŸãã¯èªå·±çœ²å蚌ææžãå¿ èŠã§ãã ãã®äŸã§ã¯ãActive Directory蚌ææžãµãŒãã¹ã®èšŒææ©é¢ãéããŠçºè¡ããã蚌ææžã䜿çšãããŸãã
蚌ææžãçºè¡ããã«ã¯ãã»ã¯ã·ã§ã³ããã€ã¹->蚌ææžç®¡ç->蚌ææž->çæââã§èšŒææžãªã¯ãšã¹ããäœæããå¿ èŠããããŸãã ãªã¯ãšã¹ãã§ã蚌ææžã®ååãšWebããŒã¿ã«ã®IPã¢ãã¬ã¹ãŸãã¯FQDNãæå®ããŸãïŒå³16ïŒã èŠæ±ãçââæããåŸã .csrãã¡ã€ã«ãããŠã³ããŒããããã®ã³ã³ãã³ããAD CS Webç»é²Webãã©ãŒã ã®èšŒææžèŠæ±ãã£ãŒã«ãã«ã³ããŒããŸãã 蚌ææ©é¢ã®èšå®ã«å¿ããŠã蚌ææžèŠæ±ãæ¿èªããçºè¡ããã蚌ææžãBase64ãšã³ã³ãŒã蚌ææžåœ¢åŒã§ããŠã³ããŒãããå¿ èŠããããŸãã ããã«ã蚌ææ©é¢ã®ã«ãŒã蚌ææžãããŠã³ããŒãããå¿ èŠããããŸãã 次ã«ãäž¡æ¹ã®èšŒææžããã¡ã€ã¢ãŠã©ãŒã«ã«ã€ã³ããŒãããå¿ èŠããããŸãã WebããŒã¿ã«ã®èšŒææžãã€ã³ããŒãããå Žåãä¿çã¹ããŒã¿ã¹ã®ãªã¯ãšã¹ããéžæããã€ã³ããŒããã¯ãªãã¯ããŸãã 蚌ææžã®ååã¯ããªã¯ãšã¹ãã§ä»¥åã«æå®ãããååãšäžèŽããå¿ èŠããããŸãã ã«ãŒã蚌ææžã®ååã¯ä»»æã«æå®ã§ããŸãã 蚌ææžãã€ã³ããŒãããåŸã ããã€ã¹->蚌ææžç®¡çã»ã¯ã·ã§ã³ã§SSL / TLSãµãŒãã¹ãããã¡ã€ã«ãäœæããå¿ èŠããããŸãã ãããã¡ã€ã«ã§ã以åã«ã€ã³ããŒããã蚌ææžãæå®ããŸãã

å³16-蚌ææžãªã¯ãšã¹ã
次ã®æé ã¯ã ãããã¯ãŒã¯->ã°ããŒãã«ä¿è·ã»ã¯ã·ã§ã³ã§ã°ããŒãã«ä¿è·ã²ãŒããŠã§ã€ãšã°ããŒãã«ä¿è·ããŒã¿ã«ãªããžã§ã¯ããæ§æããããšã§ãã Global Protect Gatewayèšå®ã§ã¯ ããã¡ã€ã¢ãŠã©ãŒã«ã®å€éšIPã¢ãã¬ã¹ãããã³ä»¥åã«äœæãããSSLãããã¡ã€ã« ã èªèšŒãããã¡ã€ã« ããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ãããã³ã¯ã©ã€ã¢ã³ãIPèšå®ãæå®ããŸãã ã¯ã©ã€ã¢ã³ãã«ã¢ãã¬ã¹ãå²ãåœãŠãããIPã¢ãã¬ã¹ã®ããŒã«ãæå®ããå¿ èŠããããŸããã¢ã¯ã»ã¹ã«ãŒãã¯ãã¯ã©ã€ã¢ã³ããã«ãŒããæã€ãµããããã§ãã ã¿ã¹ã¯ããã¹ãŠã®ãŠãŒã¶ãŒãã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ã§ã©ããããå Žåããµãããã0.0.0.0/0ãæå®ããå¿ èŠããããŸãïŒå³17ïŒã

å³17-IPã¢ãã¬ã¹ãšã«ãŒãã®ããŒã«ã®æ§æ
次ã«ã ã°ããŒãã«ä¿è·ããŒã¿ã«ãæ§æããå¿ èŠããããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã®IPã¢ãã¬ã¹ã SSLãããã¡ã€ã«ãšèªèšŒãããã¡ã€ã« ãããã³ã¯ã©ã€ã¢ã³ããæ¥ç¶ãããã¡ã€ã¢ãŠã©ãŒã«ã®å€éšIPã¢ãã¬ã¹ã®ãªã¹ããæå®ããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ãè€æ°ããå Žåãæ¥ç¶ãããã¡ã€ã¢ãŠã©ãŒã«ãéžæãããŠãŒã¶ãŒã«å¿ããŠãããããã«åªå é äœãèšå®ã§ããŸãã
[ããã€ã¹]-> [GlobalProtectã¯ã©ã€ã¢ã³ã]ã»ã¯ã·ã§ã³ã§ã Palo Alto NetworksãµãŒããŒããVPNã¯ã©ã€ã¢ã³ãé åžããã±ãŒãžãããŠã³ããŒãããŠã¢ã¯ãã£ãåããå¿ èŠããããŸãã æ¥ç¶ããã«ã¯ããŠãŒã¶ãŒã¯ããŒã¿ã«ã®WebããŒãžã«ç§»åããŠã GlobalProtectã¯ã©ã€ã¢ã³ããããŠã³ããŒãããããã«æ±ããããŸãã ããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããåŸãè³æ Œæ å ±ãå ¥åããSSL VPNçµç±ã§äŒæ¥ãããã¯ãŒã¯ã«æ¥ç¶ã§ããŸãã
ãããã«
Palo Alto Networksã®ã»ããã¢ããã®ãã®éšåã¯çµäºããŸããã æ å ±ãæçšã§ãããèªè ãããã¢ã«ããããã¯ãŒã¯ã¹ã§äœ¿çšãããŠãããã¯ãããžãŒã®ã¢ã€ãã¢ãåŸãããšãé¡ã£ãŠããŸãã ã«ã¹ã¿ãã€ãºã«é¢ãã質åãä»åŸã®èšäºã®ãããã¯ã«é¢ããææ¡ãããå Žåã¯ãã³ã¡ã³ãã«æžããŠãã ãããåãã§ãçãããŸãã