ã¯ãŒã«ãªåºåã«å±ããŠãèªçºçã«äœããè³Œå ¥ããé »åºŠã¯ã©ããããã§ããïŒããããããã®æåã«æãŸãããã®ã¯ã次ã®äžè¬çãªæé€ãŸãã¯ç§»åãŸã§ãã¯ããŒãŒããããã³ããªãŒããŸãã¯ã¬ã¬ãŒãžã«ã»ãããéããŸããïŒ çµæãšããŠãäžåœãªæåŸ ãšç¡é§ãªãéã«ãã倱æã ãããããžãã¹ã«èµ·ãããšãããã«æªåããŸãã å€ãã®å ŽåãããŒã±ãã£ã³ã°ã®ã³ãã¯éåžžã«åªããŠãããããäŒæ¥ã¯ã¢ããªã±ãŒã·ã§ã³ã®å šäœåãèŠãã«é«äŸ¡ãªãœãªã¥ãŒã·ã§ã³ãååŸããŸãã äžæ¹ãã·ã¹ãã ã®è©Šçšãã¹ãã¯ãçµ±åã®ããã«ã€ã³ãã©ã¹ãã©ã¯ãã£ãæºåããæ¹æ³ãã©ã®æ©èœãã©ã®çšåºŠå®è£ ããå¿ èŠãããããç解ããã®ã«åœ¹ç«ã¡ãŸãã ãã®ããã補åããç²ç®çã«ãéžæããããšã«ããèšå€§ãªæ°ã®åé¡ãåé¿ã§ããŸãã ããã«ãæèœãªããã€ããããã®åŸã®å°å ¥ã«ããããšã³ãžãã¢ã¯ç¥çµçŽ°èãçœé«ªã®æå·ãã¯ããã«å°ãªããªããŸãã äŒæ¥ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããäžè¬çãªããŒã«ã®äŸã§ããCisco ISEã䜿çšããŠããã€ããããã¹ãããããžã§ã¯ãã®æåã«ãšã£ãŠéåžžã«éèŠã§ããçç±ãèŠãŠã¿ãŸãããã ç§ãã¡ã®å®è·µã§ééãããœãªã¥ãŒã·ã§ã³ãé©çšããããã®æšæºãªãã·ã§ã³ãšå®å šã«éæšæºã®ãªãã·ã§ã³ã®äž¡æ¹ãèããŠã¿ãŸãããã
Cisco ISE-ãã¹ããã€ãäžã®ååŸãµãŒããŒã
Cisco Identity Services EngineïŒISEïŒã¯ãçµç¹ã®ããŒã«ã«ãšãªã¢ãããã¯ãŒã¯çšã®ã¢ã¯ã»ã¹å¶åŸ¡ã·ã¹ãã ãäœæããããã®ãã©ãããã©ãŒã ã§ãã å°é家ã³ãã¥ããã£ã§ã¯ããã®ããããã£ã®è£œåã¯ãRadius server on steroidsããšåŒã°ããŠããŸããã ãªããã æ¬è³ªçã«ããœãªã¥ãŒã·ã§ã³ã¯RadiusãµãŒããŒã§ãããèšå€§ãªæ°ã®è¿œå ãµãŒãã¹ãšãããããããã蟌ãŸãã倧éã®ã³ã³ããã¹ãæ å ±ãåãåããçµæã®ããŒã¿ã»ãããã¢ã¯ã»ã¹ããªã·ãŒã«é©çšã§ããŸãã
ä»ã®RadiusãµãŒããŒãšåæ§ã«ãCisco ISEã¯ã¢ã¯ã»ã¹ã¬ãã«ã®ãããã¯ãŒã¯æ©åšãšããåãããäŒæ¥ãããã¯ãŒã¯ãžã®ãã¹ãŠã®æ¥ç¶è©Šè¡ã«é¢ããæ å ±ãåéããèªèšŒããã³èš±å¯ããªã·ãŒã«åºã¥ããŠãLANãžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ãèš±å¯ãŸãã¯æåŠããŸãã ãã ãããããã¡ã€ãªã³ã°ãã¹ã±ãžã¥ãŒãªã³ã°ãä»ã®æ å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšã®çµ±åã®å¯èœæ§ã«ãããèš±å¯ããªã·ãŒã®ããžãã¯ãå€§å¹ ã«è€éåããå¯èœæ§ããããããã«ããããªãå°é£ã§èå³æ·±ãã¿ã¹ã¯ã解決ãããŸãã
å®è£
ã¯ãã€ãããã§ããŸãã ïŒãªããã¹ããå¿
èŠãªã®ã§ããïŒ
ãã€ããããã¹ãã®äŸ¡å€ã¯ãç¹å®ã®çµç¹ã®ç¹å®ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã·ã¹ãã ã®ãã¹ãŠã®æ©èœãå®èšŒããããšã«ãããŸãã å±éåã«Cisco ISEãè©Šéšéçšããããšã¯ããã¹ãŠã®ãããžã§ã¯ãåå è ã«åœ¹ç«ã€ãšç¢ºä¿¡ããŠããŸãããã®ããã§ãã
ã€ã³ãã°ã¬ãŒã¿ãŒã«ãšã£ãŠãããã¯é¡§å®¢ã®æåŸ ã®æ確ãªã¢ã€ãã¢ãæäŸããããã¹ãŠã倧äžå€«ã«ããããšããäžè¬çãªãã¬ãŒãºãããã¯ããã«å€ãã®è©³çŽ°ãå«ãæ£ããæè¡ã¿ã¹ã¯ãçå®ããã®ã«åœ¹ç«ã¡ãŸãã ããã€ããããã«ããã顧客ã®ãã¹ãŠã®çã¿ãæããã©ã®ã¿ã¹ã¯ã圌ã«ãšã£ãŠåªå çã§ãããã©ã®ã¿ã¹ã¯ãäºæ¬¡çã§ããããç解ã§ããŸãã ç§ãã¡ã«ãšã£ãŠãããã¯çµç¹ã§äœ¿çšãããŠããæ©åšãå®è£ æ¹æ³ããµã€ããå Žæãªã©ãäºåã«ææ¡ãã絶奜ã®æ©äŒã§ãã
ãã€ããããã¹ãäžã«ã顧客ã¯å®éã®ã·ã¹ãã ã®åäœã確èªããã€ã³ã¿ãŒãã§ã€ã¹ã«ç²ŸéããããŒããŠã§ã¢ãšäºææ§ããããã©ããã確èªããå®å šãªå®è£ åŸã®ãœãªã¥ãŒã·ã§ã³ã®åäœã®å šäœåãææ¡ã§ããŸãã ããã€ãããããšã¯ãçµ±åäžã«çºçããå¯èœæ§ã®ãããã¹ãŠã®ãèœãšãç©Žãã確èªããè³Œå ¥ããå¿ èŠãããã©ã€ã»ã³ã¹æ°ã決å®ã§ããç¬éã§ãã
ããã€ããããäžã«ãåºçŸãã§ãããã®
ããã§ã¯ãCisco ISEã®å®è£ ã«ã©ã®ããã«æºåããŸããïŒ ç§ãã¡ã®çµéšãããã·ã¹ãã ã®ãã€ããããã¹ãã®ããã»ã¹ã§èæ ®ããå¿ èŠããã4ã€ã®äž»èŠãªãã€ã³ããã«ãŠã³ãããŸããã
ãã©ãŒã ãã¡ã¯ã¿ãŒ
æåã«ãã·ã¹ãã ãå®è£ ãããã©ãŒã ãã¡ã¯ã¿ãŒïŒç©çãŸãã¯ä»®æ³ïŒã決å®ããå¿ èŠããããŸãã åãªãã·ã§ã³ã«ã¯é·æãšçæããããŸãã ããšãã°ãç©ççãªã¢ããã©ã€ãã³ã°ã®åŒ·ãã¯äºæž¬ãããããã©ãŒãã³ã¹ã§ããããã®ãããªããã€ã¹ãæéãšãšãã«å»æ¢ãããããšãå¿ããŠã¯ãªããŸããã ä»®æ³ã®éèµ·ã¯ããŸãäºæž¬ã§ããªã ãããã¯ãä»®æ³åç°å¢ãå±éãããŠããæ©åšã«äŸåããŸãããåæã«æ·±å»ãªãã©ã¹ããããŸãããµããŒããããã°ããã€ã§ãææ°ããŒãžã§ã³ã«æŽæ°ã§ããŸãã
ãããã¯ãŒã¯æ©åšã¯Cisco ISEãšäºææ§ããããŸããïŒ
ãã¡ãããçæ³çãªã·ããªãªã¯ããã¹ãŠã®æ©åšãäžåºŠã«ã·ã¹ãã ã«æ¥ç¶ããããšã§ãã ãã ããå€ãã®çµç¹ã§ã¯ç®¡çãããŠããªãã¹ã€ãããŸãã¯Cisco ISEãå®è¡ãããŠããäžéšã®ãã¯ãããžãŒããµããŒãããŠããªãã¹ã€ããã䜿çšããŠãããããããã¯åžžã«å¯èœãšã¯éããŸããã ã¡ãªã¿ã«ãããã¯ã¹ã€ããã ãã§ãªããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã³ã³ãããŒã©ãŒãVPNã³ã³ã»ã³ãã¬ãŒã¿ãŒãããã³ãŠãŒã¶ãŒãæ¥ç¶ãããã®ä»ã®æ©åšã§ããããŸãã ç§ã®å®åã§ã¯ãã·ã¹ãã ãå®å šã«å®è£ ããããã®ãã¢ãè¡ã£ãåŸã顧客ãææ°ã®ã·ã¹ã³æ©åšã®ã¢ã¯ã»ã¹ã¬ãã«ã¹ã€ããã®ã»ãŒå šäœãæŽæ°ããå ŽåããããŸããã äžå¿«ãªé©ããé¿ããããã«ããµããŒããããŠããªãæ©åšã®å²åãäºåã«æ±ºå®ããããšã¯äŸ¡å€ããããŸãã
ãã¹ãŠã®ããã€ã¹ã¯å žåçã§ããïŒ
ã©ã®ãããã¯ãŒã¯ã«ããã¯ãŒã¯ã¹ããŒã·ã§ã³ãIPé»è©±ãWi-Fiã¢ã¯ã»ã¹ãã€ã³ãããããªã«ã¡ã©ãªã©ãæ¥ç¶ããã®ãé£ãããªãå žåçãªããã€ã¹ããããŸãã ããããããšãã°RS232 /ã€ãŒãµããããã¹ä¿¡å·ã³ã³ããŒã¿ãŒãç¡åé»é»æºè£ 眮ã€ã³ã¿ãŒãã§ãŒã¹ãããŸããŸãªåŠçè£ çœ®ãªã©ã®éæšæºããã€ã¹ãLANã«æ¥ç¶ããå¿ èŠãããããšããããŸãããã®ãããªããã€ã¹ã®ãªã¹ããäºåã«æ±ºå®ããŠãå®è£ 段éã§ç解ããŠããããšãéèŠã§ããã©ã®ããã«æè¡çã«Cisco ISEãšé£æºãããã
ITå°é家ãšã®å»ºèšçãªå¯Ÿè©±
å€ãã®å ŽåãCisco ISEã®ã客æ§ã¯ã»ãã¥ãªãã£éšéã§ãããéåžžãITéšéã¯ã¢ã¯ã»ã¹ã¬ãã«ã¹ã€ãããšActive Directoryã®æ§æãæ åœããŸãã ãããã£ãŠãã»ãã¥ãªãã£ãšITã®å°é家ã®çç£çãªããåãã¯ãçã¿ã®ãªãã·ã¹ãã å®è£ ã®éèŠãªæ¡ä»¶ã®1ã€ã§ãã åŸè ããæµæã䌎ããçµ±åãèªèããå ŽåãITéšéã«ãšã£ãŠãœãªã¥ãŒã·ã§ã³ãã©ã®ããã«åœ¹ç«ã€ãã説æãã䟡å€ããããŸãã
äžäœ5ã€ã®Cisco ISEãŠãŒã¶ãŒã±ãŒã¹
ç§ãã¡ã®çµéšã§ã¯ããã€ããããã¹ã段éã§å¿ èŠãªã·ã¹ãã æ©èœãæ€åºãããŸãã 以äžã¯ããã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããæãäžè¬çã§ããŸãäžè¬çã§ãªãã±ãŒã¹ã®äžéšã§ãã
EAP-TLSã«ããå®å šãªLANã¢ã¯ã»ã¹
ãã³ãã¹ã¿ãŒã®èª¿æ»çµæã瀺ãããã«ãå€ãã®å Žåãæ»æè ã¯éåžžã®ãœã±ããã䜿çšããŠãããªã³ã¿ãŒãé»è©±ãIPã«ã¡ã©ãWi-Fiãã€ã³ãããã®ä»ã®éå人çãªãããã¯ãŒã¯ããã€ã¹ãæ¥ç¶ãããŠããäŒç€Ÿã®ãããã¯ãŒã¯ã«äŸµå ¥ããŸãã ãããã£ãŠããããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãdot1xãã¯ãããžãŒã«åºã¥ããŠããŠãããŠãŒã¶ãŒèªèšŒèšŒææžã䜿çšããã«ä»£æ¿ãããã³ã«ã䜿çšãããå Žåã§ããã»ãã·ã§ã³ã€ã³ã¿ãŒã»ãããšãã¹ã¯ãŒãã®ãã«ãŒããã©ãŒã¹ã«ããæ»æãæåããå¯èœæ§ãé«ããªããŸãã Cisco ISEã®å Žåã蚌ææžãååŸããããšã¯ã¯ããã«å°é£ã«ãªããŸãããã®ãããããã«ãŒã¯ããå€ãã®ã³ã³ãã¥ãŒãã£ã³ã°ãã¯ãŒãå¿ èŠãšããããããã®ã±ãŒã¹ã¯éåžžã«å¹æçã§ãã
ãã¥ã¢ã«SSIDã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹
ãã®ã·ããªãªã®æ¬è³ªã¯ã2ã€ã®ãããã¯ãŒã¯èå¥åïŒSSIDïŒã䜿çšããããšã§ãã ãããã®1ã€ã¯æ¡ä»¶ä»ãã§ãã²ã¹ãããšåŒã°ããŸãã ããã«ãããã²ã¹ããšäŒç€Ÿã®åŸæ¥å¡ã®äž¡æ¹ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã«å ¥ãããšãã§ããŸãã æ¥ç¶ããããšãããšãåŸè ã¯ç¹å¥ãªããŒã¿ã«ã«ãªãã€ã¬ã¯ããããããã§ããããžã§ãã³ã°ãè¡ãããŸãã ã€ãŸãã蚌ææžããŠãŒã¶ãŒã«çºè¡ããããŠãŒã¶ãŒã®å人çšããã€ã¹ã¯2çªç®ã®SSIDã«èªåçã«åæ¥ç¶ããããã«æ§æãããŸããSSIDã¯ãæåã®ã±ãŒã¹ã®ãã¹ãŠã®å©ç¹ãåããEAP-TLSãæ¢ã«äœ¿çšããŸãã
MACèªèšŒã®ãã€ãã¹ãšãããã¡ã€ãªã³ã°
å¥ã®äžè¬çãªã±ãŒã¹ã¯ãæ¥ç¶ããããã€ã¹ã®ã¿ã€ããèªåçã«æ±ºå®ããããã«é©åãªå¶éãé©çšããããšã§ãã 圌ã¯ã©ã®ããã«é¢çœãã§ããïŒ å®éã802.1Xãããã³ã«ã§ã®èªèšŒããµããŒãããŠããªãããã€ã¹ã¯ãŸã ããªããããŸãã ãããã£ãŠããã®ãããªããã€ã¹ãMACã¢ãã¬ã¹ã§èµ·åããå¿ èŠããããŸãããããã¯éåžžã«ç°¡åã«åœé ã§ããŸãã ããã§ãCisco ISEãå©ãã«ãªããŸããã·ã¹ãã ã®å©ããåããŠããããã¯ãŒã¯å ã§ã®ããã€ã¹ã®åäœã確èªãããããã¡ã€ã«ãã³ã³ãã€ã«ããŠãIPé»è©±ãã¯ãŒã¯ã¹ããŒã·ã§ã³ãªã©ã®ä»ã®ããã€ã¹ã®ã°ã«ãŒããšäžèŽãããããšãã§ããŸãã æ»æè ãMACã¢ãã¬ã¹ãã¹ããŒãã£ã³ã°ããŠãããã¯ãŒã¯ã«æ¥ç¶ããããšãããšãã·ã¹ãã ã¯ããã€ã¹ãããã¡ã€ã«ãå€æŽãããããšã確èªããçãããåäœãéç¥ããçããããŠãŒã¶ãŒããããã¯ãŒã¯ã«å ¥ããŸããã
Eapãã§ãŒã³
EAP-Chainingãã¯ãããžãŒã¯ãåäœäžã®PCãšãŠãŒã¶ãŒã¢ã«ãŠã³ãã®é 次èªèšŒãæå³ããŸãã ãã®ã±ãŒã¹ã¯åºãŸã£ãŠããŸã å€ãã®äŒæ¥ã¯ãå人ã®åŸæ¥å¡ã®ã¬ãžã§ãããäŒæ¥LANã«æ¥ç¶ããããšããŸã æè¿ããŠããŸããã ãã®ã¢ãããŒããèªèšŒã«äœ¿çšãããšãç¹å®ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ããã¡ã€ã³ã®ã¡ã³ããŒã§ãããã©ããã確èªã§ããŸããçµæãåŠå®çã§ããå ŽåããŠãŒã¶ãŒã¯ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããããã°ã€ã³ãããããŸããããç¹å®ã®å¶éããããŸãã
姿å¢
ãã®å Žåã¯ãã¯ãŒã¯ã¹ããŒã·ã§ã³ãœãããŠã§ã¢ãæ å ±ã»ãã¥ãªãã£ã®èŠä»¶ã«æºæ ããŠãããã©ãããè©äŸ¡ããããšã§ãã ãã®ãã¯ãããžã䜿çšãããšãã¯ãŒã¯ã¹ããŒã·ã§ã³äžã®ãœãããŠã§ã¢ãæŽæ°ãããŠããããã»ãã¥ãªãã£æ©èœãã€ã³ã¹ããŒã«ãããŠãããããã¹ããã¡ã€ã¢ãŠã©ãŒã«ãæ§æãããŠããããªã©ã確èªã§ããŸãã èå³æ·±ãããšã«ããã®æè¡ã䜿çšãããšãããšãã°ãå¿ èŠãªãã¡ã€ã«ã®ååšã®ç¢ºèªãã·ã¹ãã å šäœã®ãœãããŠã§ã¢ã®ã€ã³ã¹ããŒã«ãªã©ãã»ãã¥ãªãã£ã«é¢é£ããªãä»ã®ã¿ã¹ã¯ã解決ããããšãã§ããŸãã
ãã¹ã¹ã«ãŒãã¡ã€ã³èªèšŒïŒããã·ãIDïŒãSGTããŒã¹ã®ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãšãã£ã«ã¿ãªã³ã°ãã¢ãã€ã«ããã€ã¹ç®¡çã·ã¹ãã ïŒMDMïŒããã³è匱æ§ã¹ãã£ããŒïŒè匱æ§ã¹ãã£ããŒïŒãšã®çµ±åãªã©ã®Cisco ISE䜿çšã·ããªãªãããŸãäžè¬çã§ã¯ãããŸããã
éæšæºãããžã§ã¯ãïŒä»ã«Cisco ISEãå¿ èŠãªçç±ããŸãã¯ç§ãã¡ã®å®è·µããã®3ã€ã®ãŸããªã±ãŒã¹
LinuxãµãŒããŒã®ã¢ã¯ã»ã¹å¶åŸ¡
ãã§ã«Cisco ISEã·ã¹ãã ãå®è£ ããŠãã顧客ã®1人ã®ããªãéèŠãªã±ãŒã¹ã解決ããããLinuxãå®è¡ããŠãããµãŒããŒã§ãŠãŒã¶ãŒã¢ã¯ã·ã§ã³ïŒäž»ã«ç®¡çè ïŒãå¶åŸ¡ããæ¹æ³ãèŠã€ããå¿ èŠããããŸããã çããæ¢ããŠãç¡æã®PAM Radius ModuleãœãããŠã§ã¢ã䜿çšãããšããã¢ã€ãã¢ãåŸãŸãããããã«ãããå€éšã®RADIUSãµãŒããŒã§èªèšŒãããLinuxããŒã¹ã®ãµãŒããŒã«ãã°ãªã³ã§ããŸãã ãã®ç¹ã«é¢ããŠã¯ããã¹ãŠãé©åã§ãããèªèšŒèŠæ±ã«å¿çãéä¿¡ããRADIUSãµãŒããŒã¯ãã¢ã«ãŠã³ãåã®ã¿ãè¿ããçµæã¯è©äŸ¡ãããè©äŸ¡ãããŸãã äžæ¹ãLinuxã§ã®æ¿èªã«ã¯ãå°ãªããšã1ã€ä»¥äžã®ãã©ã¡ãŒã¿ãŒïŒããŒã ãã£ã¬ã¯ããªïŒãå²ãåœãŠãå¿ èŠããããŸããããã«ããããŠãŒã¶ãŒãå°ãªããšãã©ããã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã ãããååŸå±æ§ãšããŠæå®ããæ¹æ³ãèŠã€ãããªãã£ããããåèªåã¢ãŒãã§ãã¹ãã«ã¢ã«ãŠã³ãããªã¢ãŒãã§äœæããç¹å¥ãªã¹ã¯ãªãããäœæããŸããã 管çè ã¢ã«ãŠã³ããæ±ã£ãŠããã®ã§ããã®ã¿ã¹ã¯ã¯ããªãå®è¡å¯èœã§ããããã®æ°ã¯ããã»ã©å€ããããŸããã§ããã ãã®åŸããŠãŒã¶ãŒã¯å¿ èŠãªããã€ã¹ã«ã¢ã¯ã»ã¹ãããã®åŸãå¿ èŠãªã¢ã¯ã»ã¹ãå²ãåœãŠãããŸããã åççãªçåãçããŸãããã®ãããªå Žåã«Cisco ISEã䜿çšããããšã¯å¿ é ã§ããïŒ å®éãããã-ã©ããªååŸã®ãµãŒããŒã§ãã§ããŸããã顧客ã¯ãã§ã«ãã®ã·ã¹ãã ãæã£ãŠããã®ã§ãæ°ããæ©èœãè¿œå ããŸããã
LANå ã®ããŒããŠã§ã¢ãšãœãããŠã§ã¢ã®ã€ã³ãã³ããª
ãã€ãŠããã€ãããããªãã§1人ã®é¡§å®¢ã«Cisco ISEãæäŸãããããžã§ã¯ãã«åãçµãã§ããŸããã ãœãªã¥ãŒã·ã§ã³ã«å¯Ÿããæ確ãªèŠä»¶ã¯ãªãããã©ããã§ã»ã°ã¡ã³ãåãããŠããªããããã¯ãŒã¯ãæ±ã£ãŠãããã¹ãŠã®ãã®ããã£ããããã¿ã¹ã¯ãè€éã«ãªããŸããã ãããžã§ã¯ãäžã«ããããã¯ãŒã¯ããµããŒãããå¯èœãªãã¹ãŠã®ãããã¡ã€ãªã³ã°æ¹æ³ãæ§æããŸããïŒNetFlowãDHCPãSNMPãADçµ±åãªã©ã ãã®çµæãMARã¢ã¯ã»ã¹ã¯ãèªèšŒã倱æããå Žåã«ãããã¯ãŒã¯ã«å ¥ãæ©èœã§æ§æãããŸããã ã€ãŸããèªèšŒãæåããªãã£ãå Žåã§ããã·ã¹ãã ã¯ãŠãŒã¶ãŒããããã¯ãŒã¯ã«å ¥ãããŠãŒã¶ãŒã«é¢ããæ å ±ãåéãããããISEããŒã¿ããŒã¹ã«æžã蟌ã¿ãŸãã ãã®ãããªæ°é±éã«ããããããã¯ãŒã¯ã®ç£èŠã¯ããã©ã°ã€ã³ã·ã¹ãã ãšéå人çãªããã€ã¹ãèå¥ãããããã®ã»ã°ã¡ã³ããŒã·ã§ã³ãžã®ã¢ãããŒããéçºããã®ã«åœ¹ç«ã¡ãŸããã ãã®åŸãã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ã€ã³ã¹ããŒã«ããããœãããŠã§ã¢ã«é¢ããæ å ±ãåéããããã«ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããããã®ã¹ã±ãžã¥ãŒãªã³ã°ãè¿œå ã§æ§æããŸããã çµæã¯äœã§ããïŒ ãããã¯ãŒã¯ãåå²ããã¯ãŒã¯ã¹ããŒã·ã§ã³ããåé€ããå¿ èŠã®ãããœãããŠã§ã¢ã®ãªã¹ãã決å®ããŸããã ãŠãŒã¶ãŒããã¡ã€ã³ã°ã«ãŒãã«å²ãåœãŠãã¢ã¯ã»ã¹æš©ãåºåããšãããããªãã¿ã¹ã¯ã«ã¯ããªãã®æéãããããŸãããããã®æ¹æ³ã§ã顧客ããããã¯ãŒã¯äžã«ã©ã®ãããªããŒããŠã§ã¢ãæã£ãŠããããå®å šã«ææ¡ã§ããŸããã ã¡ãªã¿ã«ãããã¯ããã«äœ¿ãããããã¡ã€ãªã³ã°äœæ¥ã®ãããé£ãããããŸããã§ããã ããŠããããã¡ã€ãªã³ã°ã圹ã«ç«ããªãã£ãã®ã§ãç§ãã¡ã¯ãããèªåèªèº«ã§èŠãŠãæ©åšãæ¥ç¶ãããã¹ã€ããããŒãã匷調ããŸããã
ã¯ãŒã¯ã¹ããŒã·ã§ã³ãžã®ãªã¢ãŒããœãããŠã§ã¢ã€ã³ã¹ããŒã«
ãã®ã±ãŒã¹ã¯ç§ã®ç·Žç¿ã®äžã§æãå¥åŠãªãã®ã®äžã€ã§ãã 顧客ãç§ãã¡ã®ãšããã«æ¥ãŠå©ããå«ã³ãŸãã-Cisco ISEã®å®è£ äžã«äœãããããããªãããã¹ãŠãæ éããä»ã®èª°ããããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ã§ããªããªããŸããã ç§ãã¡ã¯æ¬¡ã®ããšãç解ãå§ããŸããã å瀟ã«ã¯2,000å°ã®ã³ã³ãã¥ãŒã¿ãŒãããããã¡ã€ã³ã³ã³ãããŒã©ãŒããªããããã¡ã€ã³ç®¡çè ãã管çãããŠããŸããã ã¹ã±ãžã¥ãŒãªã³ã°ã®ç®çã§ãçµç¹ã«Cisco ISEãå°å ¥ãããŸããã ãŠã€ã«ã¹å¯Ÿçãæ¢åã®PCã«ã€ã³ã¹ããŒã«ãããŠãããã©ããããœãããŠã§ã¢ç°å¢ãæŽæ°ãããŠãããã©ãããªã©ãäœããã®æ¹æ³ã§ç解ããå¿ èŠããããŸããã ãŸãããããã¯ãŒã¯æ©åšã¯IT管çè ã«ãã£ãŠã·ã¹ãã ã«æã¡èŸŒãŸããããã圌ããã¢ã¯ã»ã¹ã§ããã®ã¯åœç¶ã§ãã ãããã©ã®ããã«æ©èœããããèŠãŠãPCãã¹ã±ãžã¥ãŒã«ããåŸã管çè ã¯åŸæ¥å¡ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã«å人çãªèšªåãªãã§ãœãããŠã§ã¢ããªã¢ãŒãã§ã€ã³ã¹ããŒã«ãããšããã¢ã€ãã¢ãæãã€ããŸããã 1æ¥ã§äœæ©ç¯çŽã§ãããæ³åããŠã¿ãŠãã ããïŒ ç®¡çè ã¯ãCïŒ\ Program Filesãã£ã¬ã¯ããªã«ç¹å®ã®ãã¡ã€ã«ãååšãããã©ããã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ããã€ãã®ãã§ãã¯ãè¡ãããã®äžåšã§ã¯ã.exeã€ã³ã¹ããŒã«ãã¡ã€ã«ã®ãã¡ã€ã«ã¹ãã¬ãŒãžãžã®ãªã³ã¯ã§èªå修埩ãéå§ãããŸããã ããã«ãããäžè¬ãŠãŒã¶ãŒã¯ãã¡ã€ã«å ±æã«å ¥ããããããå¿ èŠãªãœãããŠã§ã¢ãããŠã³ããŒãã§ããŸãã æ®å¿µãªããã管çè ã¯ISEã·ã¹ãã ãååã«ç¥ãããå ±æåŸã®ã¡ã«ããºã ãç ŽæããŸãããããªã·ãŒã誀ã£ãŠèšè¿°ããããããœãªã¥ãŒã·ã§ã³ã«é¢é£ããåé¡ãçºçããŸããã å人çã«ã¯ããã¡ã€ã³ã³ã³ãããŒã©ãŒãäœæããæ¹ãã¯ããã«å®äŸ¡ã§æéãããããªãããããã®ãããªåµé çãªã¢ãããŒãã«å¿ããé©ããŸããã ããããæŠå¿µå®èšŒãã©ã®ããã«æ©èœããã®ãã
Cisco ISEãå®è£ ãããšãã«çããæè¡çãªãã¥ã¢ã³ã¹ã®è©³çŽ°ã«ã€ããŠã¯ãååã®èšäºãImplementing Cisco ISEã ãšã³ãžãã¢ã®å€èŠ³ ã "
Artem Bobrikovããã¶ã€ã³ãšã³ãžãã¢ãæ å ±ã»ãã¥ãªãã£ã»ã³ã¿ãŒãJet Infosystems
ããšãã ïŒ
ãã®æçš¿ã§ã¯Cisco ISEã·ã¹ãã ã«ã€ããŠèª¬æããŠããŸããã説æãããŠããåé¡ã¯NACãœãªã¥ãŒã·ã§ã³ã®ã¯ã©ã¹å šäœã«é¢é£ããŠããŸãã ã©ã®ãã³ããŒã®æ±ºå®ãå®è£ ã®ããã«èšç»ãããŠãããã¯ããã»ã©éèŠã§ã¯ãããŸãã-äžèšã®ã»ãšãã©ã¯åŒãç¶ãé©çšãããŸãã