ãã®ããŒãã¯ããã£ã³ãã¹ïŒãªãã£ã¹ïŒã»ãã¥ãªãã£èšèšãšãªã¢ãŒãã¢ã¯ã»ã¹VPNã»ã°ã¡ã³ãã®ç£æ»ã«å°å¿µããŸãã
ãªãã£ã¹ãããã¯ãŒã¯ã®èšèšã¯åçŽã«èŠãããããããŸããã
å®éãL2 / L3ã¹ã€ããã䜿çšããããããæ¥ç¶ããŸãã 次ã«ããã©ã³ãããã©ã«ãã²ãŒããŠã§ã€ã®åºæ¬æ§æãã·ã³ãã«ã«ãŒãã£ã³ã°ã®åŒãäžããWiFiã³ã³ãããŒã©ãŒãã¢ã¯ã»ã¹ãã€ã³ãã®æ¥ç¶ãASAã®ã€ã³ã¹ããŒã«ãšãªã¢ãŒãã¢ã¯ã»ã¹çšã®æ§æãè¡ãããã¹ãŠãæ©èœããããšãå¬ããæããŸãã ååãšããŠããã®ã·ãªãŒãºã®ä»¥åã®èšäºã®ããããã§ãã§ã«æžããããã«ããã¬ãã®ã³ãŒã¹ã®2åŠæãèããïŒãããŠåŠãã ïŒã»ãŒãã¹ãŠã®åŠçã¯ããäœããã®åœ¢ã§æ©èœããããªãã£ã¹ãããã¯ãŒã¯ãèšèšããã³æ§æã§ããŸãã
ããããåŠã¹ã°åŠã¶ã»ã©ããã®ã¿ã¹ã¯ã¯åæ©çã«èŠããªããªããŸãã å人çã«ã¯ããªãã£ã¹ãããã¯ãŒã¯èšèšã®ããŒãã§ãããã®ãããã¯ã¯ãŸã£ããåçŽã§ã¯ãªãããã§ãããã®èšäºã§ã¯ããã®çç±ã説æããŸãã
èŠããã«ãããªãå€ãã®èŠå ãèæ ®ããå¿ èŠããããŸãã å€ãã®å Žåããããã®èŠå ã¯äºãã«å¯Ÿç«ããŠãããåççãªåŠ¥åã暡玢ããå¿ èŠããããŸãã
ãã®äžç¢ºå®æ§ãäž»ãªå°é£ã§ãã ãããã£ãŠãã»ãã¥ãªãã£ã«ã€ããŠèšãã°ãã»ãã¥ãªãã£ãåŸæ¥å¡ã®å©äŸ¿æ§ããœãªã¥ãŒã·ã§ã³ã®äŸ¡æ Œãšãã3ã€ã®é ç¹ãæã€äžè§åœ¢ããããŸãã
ãããŠã3ã€ã®éã®åŠ¥åç¹ãèŠã€ããå¿ èŠããããŸãã
建ç¯
ããã2ã€ã®ã»ã°ã¡ã³ãã®ã¢ãŒããã¯ãã£ã®äŸãšããŠã以åã®èšäºãšåæ§ã«ã Cisco SAFEã¢ãã«ãæšå¥šããŸããEnterpriseCampus ã Enterprise Internet Edgeã§ãã
ãããã¯ããæ代é ãã®ææžã§ãã ååãšããŠã¹ããŒã ãšã¢ãããŒãã¯å€æŽãããŠããªãã®ã§ãããã«ããããæã¡èŸŒã¿ãŸãããåæã«æ°ããããã¥ã¡ã³ãããããã¬ãŒã³ããŒã·ã§ã³ã奜ãã§ãã
ã·ã¹ã³ã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããããã«ä¿ãããšãªãããã®èšèšãæ éã«æ€èšããããšã¯äŸç¶ãšããŠæçšã ãšæããŸãã
ãã®èšäºã¯ããã€ãã®ããã«ãäœããã®ãµããããããšãªãããã®æ å ±ãžã®è¿œå ã§ãã
èšäºã®æåŸã§ãããã§æŠèª¬ããæŠå¿µã®èŠ³ç¹ããããªãã£ã¹åãã®Cisco SAFEã®èšèšãåæããŸãã
äžè¬åå
ãã¡ããããªãã£ã¹ãããã¯ãŒã¯ã®èšèšã¯ããèšèšå質è©äŸ¡åºæºãã®ç« ã§èª¬æãããŠããäžè¬çãªèŠä»¶ãæºããå¿ èŠããããŸãã ãã®èšäºã§èª¬æããäŸ¡æ Œãšã»ãã¥ãªãã£ã«å ããŠãèšèšæïŒãŸãã¯å€æŽæïŒã«èæ ®ããªããã°ãªããªãåºæºã3ã€ãããŸãã
- æ¡åŒµæ§
- 管çã®å©äŸ¿æ§ïŒç®¡çæ§ïŒ
- å©çšå¯èœ
ããŒã¿ã»ã³ã¿ãŒã§è°è«ããããã®ã®å€ãã¯ããªãã£ã¹ã«ãåœãŠã¯ãŸããŸãã
ããããããã«ããããããããªãã£ã¹ã»ã°ã¡ã³ãã«ã¯ç¬èªã®ç¹ç°æ§ããããããã¯ã»ãã¥ãªãã£ã®èŠ³ç¹ããéèŠã§ãã ãã®ç¹ç°æ§ã®æ¬è³ªã¯ããã®ã»ã°ã¡ã³ããäŒç€Ÿã®åŸæ¥å¡ïŒããã³ããŒãããŒãšã²ã¹ãïŒã«ãããã¯ãŒã¯ãµãŒãã¹ãæäŸããããã«äœæããããã®çµæãåé¡ã®æé«ã¬ãã«ã®èæ ®äºé ã«2ã€ã®ã¿ã¹ã¯ãããããšã§ãã
- åŸæ¥å¡ïŒã²ã¹ããããŒãããŒïŒããã³åœŒãã䜿çšãããœãããŠã§ã¢ããçããå¯èœæ§ã®ããæªæã®ãã掻åããäŒç€Ÿã®ãªãœãŒã¹ãä¿è·ããŸãã ããã«ã¯ãäžæ£ãªãããã¯ãŒã¯æ¥ç¶ã«å¯Ÿããä¿è·ãå«ãŸããŸãã
- ã·ã¹ãã ãšãŠãŒã¶ãŒããŒã¿ãä¿è·ãã
ãããŠãããã¯åé¡ã®çåŽã«ãããŸããïŒããããäžè§åœ¢ã®1ã€ã®é ç¹ïŒã äžæ¹ããŠãŒã¶ãŒã®å©äŸ¿æ§ãšé©çšããããœãªã¥ãŒã·ã§ã³ã®äŸ¡æ Œã§ãã
ãŸãããŠãŒã¶ãŒãææ°ã®ãªãã£ã¹ãããã¯ãŒã¯ã«æåŸ ãããã®ãèŠãŠã¿ãŸãããã
ã¢ã¡ããã£
ç§ã®æèŠã§ã¯ããªãã£ã¹ãŠãŒã¶ãŒã«ãšã£ãŠããããã¯ãŒã¯ã®å©äŸ¿æ§ãã¯æ¬¡ã®ããã«ãªããŸãã
- æ©åæ§
- 䜿ãæ £ãããã¹ãŠã®ããã€ã¹ãšãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšããæ©èœ
- å¿ èŠãªãã¹ãŠã®äŒæ¥ãªãœãŒã¹ãžã®ç°¡åãªã¢ã¯ã»ã¹
- ããŸããŸãªã¯ã©ãŠããµãŒãã¹ãå«ãã€ã³ã¿ãŒããããªãœãŒã¹ã®å¯çšæ§
- ãé«éäœæ¥ããããã¯ãŒã¯
ããã¯ãã¹ãŠãåŸæ¥å¡ãšã²ã¹ãïŒãŸãã¯ããŒãããŒïŒã®äž¡æ¹ã«é©çšãããŸããããã¯ãããŸããŸãªãŠãŒã¶ãŒã°ã«ãŒãã®ã¢ã¯ã»ã¹ãåºå¥ããããã®æ¿èªã«åºã¥ãäŒç€Ÿã®ãšã³ãžãã¢ã®ã¿ã¹ã¯ã§ãã
ãããã®ååŽé¢ã詳ããèŠãŠã¿ãŸãããã
æ©åæ§
ããã¯ãäžçäžã®ã©ãããã§ãïŒãã¡ãããã€ã³ã¿ãŒããããå©çšå¯èœã§ããã°ïŒäŒç€Ÿã®ãã¹ãŠã®å¿ èŠãªãªãœãŒã¹ã䜿çšããŠäœ¿çšããæ©äŒã«ã€ããŠã§ãã
ããã¯å®å šã«ãªãã£ã¹ã«é©çšãããŸãã ããã¯ããªãã£ã¹ã®ã©ãããã§ãä»äºãç¶ããæ©äŒãããå Žåã«äŸ¿å©ã§ããããšãã°ãã¡ãŒã«ã®åä¿¡ãäŒæ¥ã®ã¡ãã»ã³ãžã£ãŒã§ã®ã³ãã¥ãã±ãŒã·ã§ã³ããããªã³ãŒã«ãžã®å¿å¯Ÿãªã©ã§ããããã«ãããäžæ¹ã§ããã©ã€ãããéããŠããã€ãã®åé¡ã解決ã§ããŸããã³ãã¥ãã±ãŒã·ã§ã³ïŒããšãã°ãéäŒã«åå ããããïŒãããã³ãã®ä»-åžžã«ãªã³ã©ã€ã³ã§ãåžžã«ææ°ã®ç¶æ ã«ä¿ã¡ãåªå 床ã®é«ãç·æ¥ã¿ã¹ã¯ããã°ãã解決ããŸãã ããã¯éåžžã«äŸ¿å©ã§ãããå®éãéä¿¡ã®å質ãåäžãããŸãã
ããã¯ãWiFiãããã¯ãŒã¯ã®æ£ããèšèšã«ãã£ãŠå®çŸãããŸãã
çºèš
ããã¯éåžžãçåãæèµ·ããŸããWiFiã®ã¿ã䜿çšããã ãã§ååã§ããïŒ ããã¯ããªãã£ã¹ã§ã€ãŒãµãããããŒãã®äœ¿çšãæåŠã§ãããšããããšã§ããïŒ éåžžã®ã€ãŒãµãããããŒãã«æ¥ç¶ããã®ãè³¢æãªãµãŒããŒã«ã€ããŠã§ã¯ãªãããŠãŒã¶ãŒã ãã«ã€ããŠè©±ããŠããå Žåãäžè¬çã«çãã¯æ¬¡ã®ãšããã§ããã¯ããWiFiã®ã¿ã«å¶éã§ããŸãã ãããã埮åŠãªéãããããŸãã
å¥ã®ã¢ãããŒããå¿ èŠãšããéèŠãªãŠãŒã¶ãŒã°ã«ãŒãããããŸãã ãã¡ããããããã¯ç®¡çè ã§ãã ååãšããŠãWiFiæ¥ç¶ã¯éåžžã®ã€ãŒãµãããããŒããããä¿¡é Œæ§ãäœãïŒãã©ãã£ãã¯æ倱ã®ç¹ã§ïŒãé床ãé ããªããŸãã ããã¯ç®¡çè ã«ãšã£ãŠéèŠã§ãã ããã«ãããšãã°ããããã¯ãŒã¯ç®¡çè ã¯ãåºæ¬çã«åž¯åå€æ¥ç¶çšã«ç¬èªã®å°çšã€ãŒãµããããããã¯ãŒã¯ãæã€ããšãã§ããŸãã
ããªãã®äŒç€Ÿã«ã¯ããããã®èŠå ãéèŠãªä»ã®ã°ã«ãŒã/éšéããããããããŸããã
å¥ã®éèŠãªãã€ã³ãããããŸã-é»è©±ã ããããäœããã®çç±ã§ãã¯ã€ã€ã¬ã¹VoIPã䜿çšãããéåžžã®ã€ãŒãµãããæ¥ç¶ã§IPé»è©±ã䜿çšãããå ŽåããããŸãã
äžè¬ã«ãç§ãåããŠããäŒæ¥ã§ã¯ãéåžžãWiFiæ¥ç¶ãšã€ãŒãµãããããŒãã®äž¡æ¹ãååšããå¯èœæ§ããããŸããã
ã¢ããªãã£ããªãã£ã¹ã ãã«éãããŠããªãããšãé¡ã£ãŠããŸãã
èªå® ïŒãŸãã¯ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããä»ã®å ŽæïŒããäœæ¥ã§ããããã«ãVPNæ¥ç¶ã䜿çšãããŸãã åæã«ãåŸæ¥å¡ãåšå® å€åãšé éå€åã®éããæããªãããšãæãŸãããããã¯ãåãã¢ã¯ã»ã¹ã®ååšãæå³ããŸãã ãããæŽçããæ¹æ³ã«ã€ããŠã¯ããçµ±åãããéäžèªèšŒããã³æ¿èªã·ã¹ãã ãã®ç« ã§å°ã説æããŸãã
çºèš
ã»ãšãã©ã®å Žåãããªãããªãã£ã¹ã«ãããªã¢ãŒãã¯ãŒã¯ãšåãå質ã®ãµãŒãã¹ãå®å šã«æäŸããããšã¯ã§ããŸããã Cisco ASA 5520ãVPNã²ãŒããŠã§ã€ãšããŠäœ¿çšããŠãããšä»®å®ãããšã ããŒã¿ã·ãŒãã«ãããšããã®ããã€ã¹ã¯225 Mbpsã®VPNãã©ãã£ãã¯ã®ã¿ãããã€ãžã§ã¹ããã§ããŸãã ããã¯ãã¡ããã垯åå¹ ã®ç¹ã§ã¯ãVPNæ¥ç¶ã¯ãªãã£ã¹ã§åãããšãšã¯éåžžã«ç°ãªããŸãã ãŸããäœããã®çç±ã§ããããã¯ãŒã¯ãµãŒãã¹ã®é 延ãæ倱ããžãã¿ãŒïŒããšãã°ããªãã£ã¹ã®IPãã¬ãã©ããŒã䜿çšãããïŒãéèŠãªå Žåããªãã£ã¹ã«ãããšããšåãå質ãåŸãããšãã§ããŸããã ãããã£ãŠãã¢ããªãã£ã«ã€ããŠè©±ããšãã¯ãèããããå¶éã«çæããå¿ èŠããããŸãã
ãã¹ãŠã®äŒæ¥ãªãœãŒã¹ãžã®ç°¡åãªã¢ã¯ã»ã¹
ãã®ã¿ã¹ã¯ã¯ãä»ã®æè¡éšéãšé£æºããŠå¯ŸåŠããå¿ èŠããããŸãã
çæ³çãªç¶æ³ã¯ããŠãŒã¶ãŒãäžåºŠã ãèªèšŒããå¿ èŠãããããã®åŸãå¿ èŠãªãã¹ãŠã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããå Žåã§ãã
ã»ãã¥ãªãã£ãæãªãããšãªãç°¡åã«ã¢ã¯ã»ã¹ã§ããããã«ãããšãäœæ¥å¹çãå€§å¹ ã«åäžããååã®ã¹ãã¬ã¹ã¬ãã«ã軜æžãããŸãã
åè1
ã¢ã¯ã»ã¹ã®ããããã¯ããã¹ã¯ãŒããå ¥åããªããã°ãªããªãåæ°ã ãã§ã¯ãããŸããã ããšãã°ãã»ãã¥ãªãã£ããªã·ãŒã«åŸã£ãŠããªãã£ã¹ããããŒã¿ã»ã³ã¿ãŒã«æ¥ç¶ããå Žåãæåã«VPNã²ãŒããŠã§ã€ã«æ¥ç¶ããå¿ èŠããããåæã«ãªãã£ã¹ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã倱ãå¿ èŠãããå Žåããããéåžžã«äžäŸ¿ã§ãã
åè2
éåžžãå°çšã®AAAãµãŒããŒãçšæãããŠãããµãŒãã¹ïŒãããã¯ãŒã¯æ©åšãžã®ã¢ã¯ã»ã¹ãªã©ïŒããããŸãããã®å Žåãéåžžã¯æ°åèªèšŒããå¿ èŠããããŸãã
ã€ã³ã¿ãŒããããªãœãŒã¹ã®å¯çšæ§
ã€ã³ã¿ãŒãããã¯ãšã³ã¿ãŒãã€ã¡ã³ãã ãã§ãªããä»äºã«éåžžã«åœ¹ç«ã€ãµãŒãã¹ã®ã»ããã§ããããŸãã çŽç²ã«å¿ççãªèŠå ããããŸãã ã€ã³ã¿ãŒããããä»ããŠä»ã®äººãšæ¥ç¶ãããå€ãã®ä»®æ³ã¹ã¬ãããä»ããŠçŸä»£äººã¯ãç§ã®æèŠã§ã¯ã圌ãä»äºäžã§ãã£ãŠããã®æ¥ç¶ãæãç¶ããã°äœãæªãããšã¯ãããŸããã
æéã浪費ãããšãã芳ç¹ããã¯ãããšãã°åŸæ¥å¡ãã¹ã«ã€ããå®è¡ããŠããŠãåé¡ãããŸãããå¿ èŠã«å¿ããŠãæãã人ãš5åé話ãããŸãã
ããã¯ãã€ã³ã¿ãŒããããåžžã«å©çšå¯èœã§ããããšãæå³ããŸããïŒããã¯ãåŸæ¥å¡ããã¹ãŠã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ããªãŒãã³ã§ããããããå¶åŸ¡ã§ããªãããšãæå³ããŸããïŒ
ãããããã¡ãããããŸããã ã€ã³ã¿ãŒãããã®éæŸæ§ã®ã¬ãã«ã¯ãå®å šãªééããå®å šãªéæŸæ§ãŸã§ãäŒæ¥ã«ãã£ãŠç°ãªãå ŽåããããŸãã ãã©ãã£ãã¯ãå¶åŸ¡ããæ¹æ³ã«ã€ããŠã¯ãã»ãã¥ãªãã£æ©èœã®ã»ã¯ã·ã§ã³ã§åŸã»ã©èª¬æããŸãã
䜿ãæ £ãããã¹ãŠã®ããã€ã¹ã䜿çšããæ©èœ
ããšãã°ãè·å Žã§ã®éåžžã®ã³ãã¥ãã±ãŒã·ã§ã³æ段ããã¹ãŠäœ¿ãç¶ããæ©äŒãããå Žåã«äŸ¿å©ã§ãã ãããæè¡çã«å®è£ ããã®ã«å°é£ã¯ãããŸããã ãããè¡ãã«ã¯ãWiFiãšã²ã¹ãvilanãå¿ èŠã§ãã
æ £ããŠãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšã§ããå Žåã«ãé©ããŠããŸãã ããããç§ã®èŠ³å¯ã§ã¯ãéåžžãããã¯ãããŒãžã£ãŒã管çè ãããã³éçºè ã«ã®ã¿èš±å¯ãããŠããŸãã
äŸ
ãã¡ããããã§ãã¯ãã€ã³ãã§æºåž¯é»è©±ãšã¬ãžã§ãããåé€ããããšãªããçŠæ¢ã®ãã¹ããã©ãããªã¢ãŒãã¢ã¯ã»ã¹ãçŠæ¢ããã¢ãã€ã«ããã€ã¹ããã®æ¥ç¶ãçŠæ¢ãããã¹ãŠã®éçã€ãŒãµãããæ¥ç¶ãå¶éããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãå¶éããããšãã§ããŸã...ã»ãã¥ãªãã£èŠä»¶ããããŠå Žåã«ãã£ãŠã¯ãããã¯æ£åœåããããããããŸãããã...åäžã®çµç¹ã®é²æ©ãæ¢ããè©Šã¿ã®ããã«èŠããããšã«åæããŸãã ãã¡ãããææ°ã®ãã¯ãããžãŒãæäŸããæ©äŒãšé©åãªã¬ãã«ã®ã»ãã¥ãªãã£ãçµã¿åãããããšæããŸãã
ãé«éäœæ¥ããããã¯ãŒã¯
ããŒã¿è»¢éé床ã¯ãæè¡çã«å€ãã®èŠçŽ ã§æ§æãããŠããŸãã éåžžãæ¥ç¶ããŒãã®é床ã¯æãéèŠã§ã¯ãããŸããã åžžã«ã¢ããªã±ãŒã·ã§ã³ã®é ãåäœããããã¯ãŒã¯ã®åé¡ã«é¢é£ããŠããããã§ã¯ãããŸããããä»ã¯ãããã¯ãŒã¯ã®éšåã«ã®ã¿é¢å¿ããããŸãã ããŒã«ã«ãããã¯ãŒã¯ã®ãé床äœäžãã®æãäžè¬çãªåé¡ã¯ããã±ããæ倱ã«é¢é£ããŠããŸãã ããã¯éåžžãããã«ããã¯å¹æãŸãã¯L1ïŒOSIïŒã®åé¡ã§çºçããŸãã ããŸãäžè¬çã§ã¯ãããŸããããäžéšã®èšèšã§ã¯ïŒããšãã°ããã¡ã€ã¢ãŠã©ãŒã«ããµããããã®ããã©ã«ãã²ãŒããŠã§ã€ãšããŠæ©èœããããããã¹ãŠã®ãã©ãã£ãã¯ãééããå ŽåïŒãããŒããŠã§ã¢ã®ããã©ãŒãã³ã¹ãäœäžããå ŽåããããŸãã
ãããã£ãŠãæ©åšãšã¢ãŒããã¯ãã£ãéžæãããšãã¯ããšã³ãããŒãããã©ã³ã¯ã®é床ãããã³æ©åšã®ããã©ãŒãã³ã¹ãçžé¢ãããå¿ èŠããããŸãã
äŸ
ã¢ã¯ã»ã¹ã¬ãã«ã¹ã€ãããšããŠ1ã®ã¬ãããããŒãã®ã¹ã€ããã䜿çšãããšããŸãã ãããã¯ãEtherchannel 2 x 10ã®ã¬ãããã§çžäºæ¥ç¶ãããŸãã ããã©ã«ãã²ãŒããŠã§ã€ãšããŠãã®ã¬ãããããŒããåãããã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããEtherchannelã«çµ±åããã2ã€ã®ã®ã¬ãããããŒãã䜿çšãããªãã£ã¹ã®L2ãããã¯ãŒã¯ã«æ¥ç¶ããŸãã
ãã®ã¢ãŒããã¯ãã£ã¯ãæ©èœçã«éåžžã«äŸ¿å©ã§ãããªããªãã ãã¹ãŠã®ãã©ãã£ãã¯ã¯ãã¡ã€ã¢ãŠã©ãŒã«ãééããã¢ã¯ã»ã¹ããªã·ãŒãå¿«é©ã«ç®¡çããè€éãªã¢ã«ãŽãªãºã ãé©çšããŠãã©ãã£ãã¯ãå¶åŸ¡ããæ»æã®å¯èœæ§ãé²ãããšãã§ããŸãïŒä»¥äžãåç §ïŒãã垯åå¹ ãšããã©ãŒãã³ã¹ã®èŠ³ç¹ããããã®èšèšã«ã¯æœåšçãªåé¡ããããŸã ãããã£ãŠãããšãã°ãããŒã¿ãããŠã³ããŒããã2ã€ã®ãã¹ãïŒããŒãé床ã1ã®ã¬ãããïŒã¯ã2ã®ã¬ãããæ¥ç¶ããã¡ã€ã¢ãŠã©ãŒã«ã«å®å šã«ããŒãã§ããããããªãã£ã¹ã»ã°ã¡ã³ãå šäœã®ãµãŒãã¹ã®äœäžã«ã€ãªãããŸãã
äžè§åœ¢ã®1ã€ã®é ç¹ãèŠãŸããã次ã«ãã»ãã¥ãªãã£ãæäŸããæ¹æ³ãèŠãŠã¿ãŸãããã
ææž
ãããã£ãŠããã¡ãããéåžžãç§ãã¡ã®æ¬²æ±ïŒãŸãã¯ãããããç§ãã¡ã®ãªãŒããŒã·ããã®æ¬²æ±ïŒã¯ãäžå¯èœãéæããããšãã€ãŸããæ倧éã®å©äŸ¿æ§ãšæ倧éã®ã»ãã¥ãªãã£ãšæå°éã®äŸ¡æ ŒãæäŸããããšã§ãã
ä¿è·ãæäŸããå¿ èŠãããæ¹æ³ãèŠãŠã¿ãŸãããã
ãªãã£ã¹ã§ã¯ã次ã®ããšãéžã³ãŸãã
- ãŒããã©ã¹ãèšèšã¢ãããŒã
- é«ã¬ãã«ã®ä¿è·
- ãããã¯ãŒã¯ã®å¯èŠæ§
- åäžã®éäžèªèšŒããã³èªå¯ã·ã¹ãã
- ãã¹ããã§ãã¯
次ã«ããããã®ååŽé¢ã«ã€ããŠè©³ãã説æããŸãã
ãŒããã©ã¹ã
ITã®äžçã¯æ¥éã«å€åããŠããŸãã æåéããéå»10幎éãæ°ããæè¡ãšè£œåã®åºçŸã«ãããã»ãã¥ãªãã£ã®æŠå¿µãå€§å¹ ã«æ¹èšãããŸããã 10幎åãã»ãã¥ãªãã£ã®èŠ³ç¹ããããããã¯ãŒã¯ãä¿¡é ŒãŸãŒã³ãdmzãŸãŒã³ãuntrustãŸãŒã³ã«åå²ãããå¢çé²åŸ¡ããšåŒã°ãããã®ã䜿çšããŸãããuntrust-> dmzããã³dmz-> trustã ãŸããä¿è·ã¯éåžžãL3 / L4ïŒOSIïŒããããŒïŒIPãTCP / UDPããŒããTCPãã©ã°ïŒã«åºã¥ãã¢ã¯ã»ã¹ãªã¹ãã«éå®ãããŠããŸããã L7ãå«ããããé«ãã¬ãã«ã«é¢é£ãããã®ã¯ãã¹ãŠããšã³ããã¹ãã«ã€ã³ã¹ããŒã«ãããOSããã³ä¿è·è£œåã«ä»»ãããŠããŸããã
çŸåšãç¶æ³ã¯åçã«å€åããŠããŸãã ãŒããã©ã¹ãã®çŸä»£ã®æŠå¿µã¯ãå éšãã€ãŸãå¢çå ã®ã·ã¹ãã ãä¿¡é Œããããšã¯ãã¯ãäžå¯èœã§ãããå¢çã®æŠå¿µãã®ãã®ãææ§ã«ãªã£ããšããäºå®ã«åºã¥ããŠããŸãã
ã€ã³ã¿ãŒãããæ¥ç¶ã«å ããŠãæã ãæã£ãŠããŸã
- ãªã¢ãŒãã¢ã¯ã»ã¹VPNãŠãŒã¶ãŒ
- ããŸããŸãªããŒãœãã«ã¬ãžã§ããã«ããããªãã£ã¹ã®WiFiãä»ããŠã©ããããããæ¥ç¶ãããŸãã
- ä»ã®ïŒæ¯åºïŒãªãã£ã¹
- ã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ãšã®çµ±å
ãŒããã©ã¹ãã®ã¢ãããŒãã¯å®éã«ã¯ã©ã®ããã«èŠããŸããïŒ
çæ³çã«ã¯ãå¿ èŠãªãã©ãã£ãã¯ã®ã¿ãèš±å¯ããçæ³ã«ã€ããŠè©±ããŠããå Žåã¯ãL3 / L4ã¬ãã«ã ãã§ãªããã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§ãå¶åŸ¡ããå¿ èŠããããŸãã
ããšãã°ããã¹ãŠã®ãã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ãééãããæ©äŒãããã°ãçæ³ã«è¿ã¥ããããšãã§ããŸãã ãã ãããã®ã¢ãããŒãã¯ãããã¯ãŒã¯ã®ç·åž¯åå¹ ãå€§å¹ ã«åæžã§ããŸãããŸããã¢ããªã±ãŒã·ã§ã³ã«ãããã£ã«ã¿ãªã³ã°ãåžžã«é©åã«æ©èœãããšã¯éããŸããã
ïŒæšæºACLã䜿çšããŠïŒã«ãŒã¿ãŒãŸãã¯L3ã¹ã€ããäžã®ãã©ãã£ãã¯ãç£èŠããå Žåãä»ã®åé¡ãçºçããŸãã
- ããã¯ãL3 / L4ãã£ã«ã¿ãªã³ã°ã®ã¿ã§ãã æ»æè ãã¢ããªã±ãŒã·ã§ã³ïŒhttpã§ã¯ãªãïŒã«èš±å¯ãããããŒãïŒTCP 80ãªã©ïŒã䜿çšããããšã劚ãããã®ã¯äœããããŸãã
- è€éãªACL管çïŒACLã®åæãå°é£ïŒ
- ããã¯ã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãããŸãããã€ãŸããæ瀺çã«éãã©ãã£ãã¯ãèš±å¯ããå¿ èŠããããŸãã
- ã¹ã€ããã®å ŽåãéåžžãTCAMã®ãµã€ãºã«ãã£ãŠéåžžã«å³ããå¶éãããŸãããå¿ èŠãªãã®ã ããèš±å¯ãããã¢ãããŒãã䜿çšãããšãããã«åé¡ã«ãªããŸãã
çºèš
éãã©ãã£ãã¯ãšããã°ã次ã®æ©äŒãããããšãèŠããŠããå¿ èŠããããŸãïŒCiscoïŒ
ä»»æã®ç¢ºç«ãããtcpãèš±å¯ããŸã
ãã ãããã®è¡ã¯2è¡ã«çžåœããããšãç解ããå¿ èŠããããŸãã
tcp any any ackãèš±å¯ããŸã
tcp any any rstãèš±å¯ããŸã
ã€ãŸããSYNãã©ã°ãæã€å ã®TCPã»ã°ã¡ã³ãããªãã£ãå ŽåïŒã€ãŸããTCPã»ãã·ã§ã³ã確ç«ãããªãã£ãå Žåã§ãïŒããã®ACLã¯ACKãã©ã°ãæã€ãã±ãããã¹ãããããæ»æè ã¯ããã䜿çšããŠããŒã¿ãéä¿¡ã§ããŸãã
ã€ãŸãããã®è¡ã¯ãã«ãŒã¿ãŒãŸãã¯L3ã¹ã€ãããã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ã«æ±ºããŠå€ããŸããã
é«ã¬ãã«ã®ä¿è·
ããŒã¿ã»ã³ã¿ãŒã«ç¹åããã»ã¯ã·ã§ã³ã®èšäºã§ã¯ã次ã®ä¿è·æ¹æ³ãæ€èšããŸããã
- ã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ïŒããã©ã«ãïŒ
- ddos / dosä¿è·
- ã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«
- è åšã®é²æ¢ïŒãŠã€ã«ã¹å¯Ÿçãã¹ãã€ãŠã§ã¢å¯Ÿçãè匱æ§ïŒ
- URLãã£ã«ã¿ãªã³ã°
- ããŒã¿ãã£ã«ã¿ãªã³ã°ïŒã³ã³ãã³ããã£ã«ã¿ãªã³ã°ïŒ
- ãã¡ã€ã«ã®ãããã¯ïŒãã¡ã€ã«ã®çš®é¡ã®ãããã¯ïŒ
ãªãã£ã¹ã®å Žåãç¶æ³ã¯äŒŒãŠããŸãããåªå é äœã¯ãããã«ç°ãªããŸãã éåžžãOfficeã®ã¢ã¯ã»ã·ããªãã£ïŒå¯çšæ§ïŒã¯ããŒã¿ã»ã³ã¿ãŒã®å Žåã»ã©éèŠã§ã¯ãããŸãããããå éšãã®æªæã®ãããã©ãã£ãã¯ã®å¯èœæ§ã¯æ¡éãã«é«ããªããŸãã
ãããã£ãŠããã®ã»ã°ã¡ã³ãã®æ¬¡ã®ä¿è·æ¹æ³ãéèŠã«ãªããŸãã
- ã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«
- è åšã®é²æ¢ïŒãŠã€ã«ã¹å¯Ÿçãã¹ãã€ãŠã§ã¢å¯Ÿçãè匱æ§ïŒ
- URLãã£ã«ã¿ãªã³ã°
- ããŒã¿ãã£ã«ã¿ãªã³ã°ïŒã³ã³ãã³ããã£ã«ã¿ãªã³ã°ïŒ
- ãã¡ã€ã«ã®ãããã¯ïŒãã¡ã€ã«ã®çš®é¡ã®ãããã¯ïŒ
ãããã®ãã¹ãŠã®ä¿è·æ¹æ³ã¯ãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ãé€ããäŒçµ±çã«è§£æ±ºãããŠããããšã³ããã¹ãã§ïŒããšãã°ããŠã€ã«ã¹å¯Ÿçããã°ã©ã ãã€ã³ã¹ããŒã«ããããšã«ãã£ãŠïŒãããã·ã䜿çšããŠè§£æ±ºããç¶ããŠããŸãããææ°ã®NGFWã¯ãããã®ãµãŒãã¹ãæäŸããŸãã
ã»ãã¥ãªãã£æ©åšãã³ããŒã¯å æ¬çãªä¿è·ã®äœæã«åªããŠãããããŒã«ã«ããã¯ã¹ã§ã®ä¿è·ãšãšãã«ããã¹ãçšã®ããŸããŸãªã¯ã©ãŠããã¯ãããžãŒãšã¯ã©ã€ã¢ã³ããœãããŠã§ã¢ïŒãšã³ããã€ã³ãä¿è·/ EPPïŒãæäŸãããŠããŸãã ããšãã°ã2018幎ã®Gartner Magic Quadrantã§ã¯ã Palo AltoãšCiscoã«ã¯ç¬èªã®EPPïŒPAïŒãã©ãããCiscoïŒAMPïŒããããŸããããªãŒããŒããã¯ã»ã©é ãããšãããããŸãã
ãã¡ããããããã®ä¿è·ãïŒéåžžã¯ã©ã€ã»ã³ã¹ã®è³Œå ¥ãéããŠïŒãã¡ã€ã¢ãŠã©ãŒã«ã«å«ããããšã¯å¿ é ã§ã¯ãããŸããïŒåŸæ¥ã®æ¹æ³ã䜿çšã§ããŸãïŒããããã€ãã®å©ç¹ããããŸãã
- ãã®å Žåãä¿è·æ¹æ³ã®åäžã®é©çšãã€ã³ãã衚瀺ãããå¯èŠæ§ãåäžããŸãïŒæ¬¡ã®ãããã¯ãåç §ïŒã
- ãããã¯ãŒã¯ã«ä¿è·ãããŠããªãããã€ã¹ãããå Žåããã¡ã€ã¢ãŠã©ãŒã«ä¿è·ã®ãåãã®å¯Ÿè±¡ãšãªããŸã
- ãã¡ã€ã¢ãŠã©ãŒã«ã®ä¿è·ãšãšã³ããã¹ãã®ä¿è·ã䜵çšãããšãæªæã®ãããã©ãã£ãã¯ãæ€åºããå¯èœæ§ãé«ãŸããŸãã ããšãã°ãããŒã«ã«ãã¹ãããã³ãã¡ã€ã¢ãŠã©ãŒã«ã§è åšé²æ¢ã䜿çšãããšãæ€åºã®å¯èœæ§ãé«ããªããŸãïŒãã¡ããããããã®ãœãªã¥ãŒã·ã§ã³ãç°ãªããœãããŠã§ã¢è£œåã«åºã¥ããŠããå ŽåïŒ
çºèš
ããšãã°ããã¡ã€ã¢ãŠã©ãŒã«ãšãšã³ããã¹ãã®äž¡æ¹ã§KasperskyããŠã€ã«ã¹å¯ŸçãšããŠäœ¿çšããå Žåãããã¯ãã¡ããããããã¯ãŒã¯ã§ã®ãŠã€ã«ã¹æ»æãé²æ¢ããå¯èœæ§ãå€§å¹ ã«é«ããããšã¯ãããŸããã
ãããã¯ãŒã¯ã®å¯èŠæ§
åºæ¬çãªèãæ¹ã¯ç°¡åã§ãããªã¢ã«ã¿ã€ã ããŒã¿ãšå±¥æŽããŒã¿ã®äž¡æ¹ã§ããããã¯ãŒã¯ã§äœãèµ·ãã£ãŠãããããèŠããããšãã§ããŸãã
ãã®ãããžã§ã³ãã2ã€ã®ã°ã«ãŒãã«åããŸãã
ã°ã«ãŒã1ïŒç£èŠã·ã¹ãã ãéåžžæäŸãããã®ã
- æ©åšã®ããŒãã£ã³ã°
- ããŒãã£ã³ã°ãã£ã³ãã«
- ã¡ã¢ãªäœ¿çšé
- ãã£ã¹ã¯äœ¿çšé
- ã«ãŒãã£ã³ã°ããŒãã«ãå€æŽãã
- ãªã³ã¯ç¶æ
- æ©åšïŒãŸãã¯ãã¹ãïŒã®å¯çšæ§
- ...
ã°ã«ãŒã2ïŒã»ãã¥ãªãã£é¢é£æ å ±ã
- ããŸããŸãªçš®é¡ã®çµ±èšïŒã¢ããªã±ãŒã·ã§ã³ããšããã©ãã£ãã¯URLããšãããŠã³ããŒããããããŒã¿ã®çš®é¡ããŠãŒã¶ãŒããšã®ããŒã¿ãªã©ïŒ
- ã»ãã¥ãªãã£ããªã·ãŒã«ãã£ãŠãããã¯ããããã®ãšãã®çç±
- çŠæ¢ç³è«
- IP /ãããã³ã«/ããŒã/ãã©ã°/ãŸãŒã³ã«åºã¥ããŠçŠæ¢
- è åšé²æ¢
- URLãã£ã«ã¿ãªã³ã°
- ããŒã¿ãã£ã«ã¿ãªã³ã°
- ãã¡ã€ã«ã®ãããã¯
- ...
- DOS / DDOSæ»æã«é¢ããçµ±èš
- 倱æããèªèšŒããã³èš±å¯ã®è©Šè¡
- äžèšã®ãã¹ãŠã®ã»ãã¥ãªãã£ããªã·ãŒéåã«é¢ããçµ±èš
- ...
ã»ãã¥ãªãã£ã«é¢ãããã®ç« ã§ã¯ãæ£ç¢ºã«ç¬¬2éšã«èå³ããããŸãã
äžéšã®ææ°ã®ãã¡ã€ã¢ãŠã©ãŒã«ïŒç§ã®Palo Altoã®å®è·µã«ããïŒã¯ãè¯å¥œãªã¬ãã«ã®å¯èŠæ§ãæäŸããŸãã ãã ãããã¡ãããé¢å¿ã®ãããã©ãã£ãã¯ã¯ãã®ãã¡ã€ã¢ãŠã©ãŒã«ãééããå¿ èŠãããïŒãã®å Žåããã©ãã£ãã¯ããããã¯ã§ããŸãïŒããŸãã¯ãã¡ã€ã¢ãŠã©ãŒã«ã«ãã©ãŒãªã³ã°ããïŒç£èŠãšåæã®ã¿ã«äœ¿çšïŒããããã®ãµãŒãã¹ããã¹ãŠæå¹ã«ããããã®ã©ã€ã»ã³ã¹ãå¿ èŠã§ãã
ãã¡ããã代æ¿ãã¹ããããŸãããããšãã°ãåŸæ¥ã®ãã¹ããããŸãã
- ã»ãã·ã§ã³ã«é¢ããçµ±èšã¯ãnetflowãä»ããŠåéã§ãããã®åŸãç¹å¥ãªãŠãŒãã£ãªãã£ã䜿çšããŠæ å ±ãåæããããŒã¿ãèŠèŠåã§ããŸãã
- è åšã®é²æ¢-ãšã³ããã¹ãäžã®ç¹å¥ãªããã°ã©ã ïŒãŠã€ã«ã¹å¯Ÿçãã¹ãã€ãŠã§ã¢å¯Ÿçããã¡ã€ã¢ãŠã©ãŒã«ïŒ
- URLãã£ã«ã¿ãªã³ã°ãããŒã¿ãã£ã«ã¿ãªã³ã°ããã¡ã€ã«ããããã³ã°-ãããã·äž
- ãŸãã snort㧠tcpdumpã解æããããšãã§ããŸã
ãããã®2ã€ã®ã¢ãããŒããçµã¿åãããŠãæ¬ èœããŠããæ©èœãè£å®ãããè€è£œããŠãæ»æãæ€åºããå¯èœæ§ãé«ããããšãã§ããŸãã
ã©ã®ã¢ãããŒããéžæããŸããïŒ
ããã¯ããªãã®ããŒã ã®è³æ Œãšå¥œã¿ã«äŸåããŸãã
é·æãšçæããããŸãã
çµ±åãããéäžèªèšŒããã³èªå¯ã·ã¹ãã
åªããèšèšã«ããããã®èšäºã§èª¬æããã¢ããªãã£ã¯ããªãã£ã¹ãèªå® ã空枯ãã«ãã§ããŸãã¯ãã®ä»ã®å Žæããäœæ¥ãããšãã«åãã¢ã¯ã»ã¹æš©ãæã£ãŠããããšãåæãšããŠããŸãïŒäžèšã§èª¬æããå¶éããããŸãïŒã åé¡ã¯äœã§ããïŒ
ãã®ã¿ã¹ã¯ã®è€éããããããç解ããããã«ãå žåçãªãã¶ã€ã³ãèŠãŠã¿ãŸãããã
äŸ
- ãã¹ãŠã®åŸæ¥å¡ãã°ã«ãŒãã«åå²ããŸããã ã°ã«ãŒãã¢ã¯ã»ã¹ãèš±å¯ããããšã«ããŸãã
- ãªãã£ã¹å ã§ã¯ããªãã£ã¹ã®ãã¡ã€ã¢ãŠã©ãŒã«ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããŸã
- ããŒã¿ã»ã³ã¿ãŒã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ããªãã£ã¹ããããŒã¿ã»ã³ã¿ãŒãžã®ãã©ãã£ãã¯ãå¶åŸ¡ããŸã
- VPNã²ãŒããŠã§ã€ãšããŠãCisco ASAã䜿çšããå²ãåœãŠãããã¯ã©ã€ã¢ã³ããããããã¯ãŒã¯ã«å ¥ããã©ãã£ãã¯ãå¶åŸ¡ããã«ã¯ãããŒã«ã«ïŒASAäžïŒACLã䜿çšããŸã
ããã§ãç¹å®ã®åŸæ¥å¡ã«ã¢ã¯ã»ã¹ãè¿œå ããããã«æ±ãããããšããŸãã åæã«ãããªãã¯åœŒã ãã«ã¢ã¯ã»ã¹æš©ãè¿œå ããããã«æ±ãããã圌ã®ã°ã«ãŒãããã¯èª°ãè¿œå ããŸããã
ãããè¡ãã«ã¯ããã®åŸæ¥å¡çšã«å¥ã®ã°ã«ãŒããäœæããå¿ èŠããããŸãã
- ASAã§ããã®åŸæ¥å¡çšã«åå¥ã®IPããŒã«ãäœæããŸã
- ASAã«æ°ããACLãè¿œå ãããã®ãªã¢ãŒãã¯ã©ã€ã¢ã³ãã«ãã€ã³ãããŸã
- ãªãã£ã¹ããã³ããŒã¿ã»ã³ã¿ãŒã®ãã¡ã€ã¢ãŠã©ãŒã«ã«æ°ããã»ãã¥ãªãã£ããªã·ãŒãäœæãã
ãŸãããã®ã€ãã³ãããŸããªå Žåã ããããç§ã®å®è·µã§ã¯ãåŸæ¥å¡ãããŸããŸãªãããžã§ã¯ãã«åå ããç¶æ³ããããäžéšã®åŸæ¥å¡ã®ãã®ãããžã§ã¯ãã»ããã¯é »ç¹ã«å€æŽãããããã¯1ã2人ã§ã¯ãªãæ°å人ã§ããã ãã¡ãããããã§äœããå€æŽããå¿ èŠããããŸããã
ããã¯æ¬¡ã®æ¹æ³ã§è§£æ±ºãããŸããã
ãã¹ãŠã®åŸæ¥å¡ã¢ã¯ã»ã¹ã決å®ããå¯äžã®çå®ã®ãœãŒã¹ã¯LDAPã§ãããšå€æããŸããã ã¢ã¯ã»ã¹ã®ã»ãããå®çŸ©ãããã¹ãŠã®çš®é¡ã®ã°ã«ãŒããäœæããåãŠãŒã¶ãŒã1ã€ãŸãã¯è€æ°ã®ã°ã«ãŒãã«ãªã³ã¯ããŸããã
ãããã£ãŠãããšãã°ãã°ã«ãŒãããã£ããšããŸã
- ã²ã¹ãïŒã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ïŒ
- å ±éã¢ã¯ã»ã¹ïŒå ±æãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ïŒã¡ãŒã«ãç¥èããŒã¹ã...ïŒ
- çµç
- ãããžã§ã¯ã1
- ãããžã§ã¯ã2
- ããŒã¿ããŒã¹ç®¡çè
- Linux管çè
- ...
ãŸããåŸæ¥å¡ã®1人ããããžã§ã¯ã1ãšãããžã§ã¯ã2ã®äž¡æ¹ã«é¢äžããŠããããããã®ãããžã§ã¯ãã§äœæ¥ããããã«å¿ èŠãªã¢ã¯ã»ã¹ãå¿ èŠãªå Žåããã®åŸæ¥å¡ã¯ãããã次ã®ã°ã«ãŒãã«æå±ããŠããŸããã
- ã²ã¹ã
- å ±éã¢ã¯ã»ã¹
- ãããžã§ã¯ã1
- ãããžã§ã¯ã2
ãã®æ å ±ããããã¯ãŒã¯æ©åšäžã®ã¢ã¯ã»ã¹ã«å€æããæ¹æ³ã¯ïŒ
Cisco ASAãã€ãããã¯ã¢ã¯ã»ã¹ããªã·ãŒïŒDAPïŒïŒ www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/108000-dap-deploy-guideãåç §.html ïŒãœãªã¥ãŒã·ã§ã³ã¯ããã®ã¿ã¹ã¯ã«æé©ã§ãã
å®è£ ã«ã€ããŠç°¡åã«èª¬æãããšãèå¥/æ¿èªããã»ã¹äžã«ãASAã¯LDAPãããã®ãŠãŒã¶ãŒã«å¯Ÿå¿ããã°ã«ãŒãã®ã»ãããåãåããããã€ãã®ããŒã«ã«ACLïŒãããããã°ã«ãŒãã«å¯Ÿå¿ïŒããå¿ èŠãªãã¹ãŠã®ã¢ã¯ã»ã¹ãæã€åçACLããåéãããŸãã
ãã ããããã¯VPNæ¥ç¶å°çšã§ãã VPNãä»ããŠæ¥ç¶ãããåŸæ¥å¡ãšãªãã£ã¹ã®åŸæ¥å¡ã®äž¡æ¹ã§ç¶æ³ãåãã«ããããã«ã次ã®ã¹ããããåãããŸããã
ãªãã£ã¹ããæ¥ç¶ããå Žåã802.1xãããã³ã«ã䜿çšãããŠãŒã¶ãŒã¯ãã²ã¹ãvilanïŒã²ã¹ãçšïŒãŸãã¯å ±æã¢ã¯ã»ã¹ã®ããvilanïŒäŒç€Ÿã®åŸæ¥å¡çšïŒã§çµäºããŸããã ããã«ãç¹å®ã®ã¢ã¯ã»ã¹ïŒããŒã¿ã»ã³ã¿ãŒå ã®ãããžã§ã¯ããªã©ïŒãååŸããããã«ãåŸæ¥å¡ã¯VPNçµç±ã§æ¥ç¶ããå¿ èŠããããŸããã
ãªãã£ã¹ãšèªå® ããæ¥ç¶ããããã«ãASAã®ç°ãªããã³ãã«ã°ã«ãŒãã䜿çšãããŸããã ããã¯ããªãã£ã¹ããå ±æãªãœãŒã¹ïŒã¡ãŒã«ããã¡ã€ã«ãµãŒããŒããã±ããã·ã¹ãã ãDNSãªã©ã®ãã¹ãŠã®åŸæ¥å¡ã䜿çšïŒã«æ¥ç¶ãããã©ãã£ãã¯ã®å ŽåãASAã§ã¯ãªãããŒã«ã«ãããã¯ãŒã¯ãçµç±ããããã«å¿ èŠã§ãã ãããã£ãŠãé«åŒ·åºŠã®ãã©ãã£ãã¯ãå«ãéå°ãªãã©ãã£ãã¯ã§ASAãããŒãããŸããã§ããã
ãããã£ãŠãåé¡ã¯è§£æ±ºãããŸããã
ã§ãã
- ãªãã£ã¹ããã®æ¥ç¶ãšãªã¢ãŒãæ¥ç¶ã®äž¡æ¹ã«åãã¢ã¯ã»ã¹ã»ãã
- ASAãä»ããé«åŒ·åºŠãã©ãã£ãã¯ã®éä¿¡ã«é¢é£ãããªãã£ã¹ã§ã®äœæ¥æã®ãµãŒãã¹äœäžã®æ¬ åŠ
ãã®ã¢ãããŒãã®å©ç¹ã¯äœã§ããïŒ
ã¢ã¯ã»ã¹ç®¡çã ã¢ã¯ã»ã¹ã¯1ãæã§ç°¡åã«å€æŽã§ããŸãã
ããšãã°ãåŸæ¥å¡ãéè·ããå ŽåãLDAPããåé€ããã ãã§ããã®åŸæ¥å¡ã¯ãã¹ãŠã®ã¢ã¯ã»ã¹ãèªåçã«å€±ããŸãã
ãã¹ããã§ãã¯
ãªã¢ãŒãæ¥ç¶ãå¯èœãªå ŽåãäŒç€Ÿã®åŸæ¥å¡ã ãã§ãªãã圌ã®ã³ã³ãã¥ãŒã¿ãŒïŒèªå® ãªã©ïŒã«ååšããå¯èœæ§ã®ãããã¹ãŠã®æªæã®ãããœãããŠã§ã¢ããããã¯ãŒã¯ã«èš±å¯ãããªã¹ã¯ããããŸããããã«ããã®ãœãããŠã§ã¢ãéããŠããã®ãã¹ãããããã·ãšããŠäœ¿çšããæ»æè ãžã®ãããã¯ãŒã¯ã
ãªã¢ãŒããã¹ãããªãã£ã¹ãã¹ããšåãã»ãã¥ãªãã£èŠä»¶ãé©çšããããšã¯çã«ããªã£ãŠããŸãã
ããã«ã¯ãOSã®ãæ£ãããããŒãžã§ã³ããŠã€ã«ã¹å¯Ÿçãã¹ãã€ãŠã§ã¢å¯Ÿçãããã³ãã¡ã€ã¢ãŠã©ãŒã«ãœãããŠã§ã¢ãšæŽæ°ãå«ãŸããŸããéåžžããã®æ©èœã¯VPNã²ãŒããŠã§ã€ã«ååšããŸãïŒASAã«ã€ããŠã¯ãããšãã°ããã¡ããåç §ããŠãã ããïŒã
ãŸããã»ãã¥ãªãã£ããªã·ãŒã«åŸã£ãŠãªãã£ã¹ãã©ãã£ãã¯ã«é©çšããããã©ãã£ãã¯åæããã³ãããã¯ã®åãæ¹æ³ïŒãé«ã¬ãã«ã®ä¿è·ããåç §ïŒãé©çšããããšãåççã§ãã
ãªãã£ã¹ãããã¯ãŒã¯ããªãã£ã¹ãã«ãšãã®äžã«ãããã¹ãã«éå®ãããªããªã£ããšä»®å®ããã®ã¯åççã§ãã
äŸ
ãªã¢ãŒãã¢ã¯ã»ã¹ãå¿ èŠãšãããã¹ãŠã®åŸæ¥å¡ã«ã䟿å©ã§äŸ¿å©ãªã©ããããããè£ åãããªãã£ã¹ãšèªå® ã®äž¡æ¹ã§ä»äºãããããšã ããèŠæ±ããããšãæè¿ããŸãã
ããã«ããããããã¯ãŒã¯ã®ã»ãã¥ãªãã£ã¬ãã«ãåäžããã ãã§ãªããéåžžã«äŸ¿å©ã§ãããéåžžã¯åŸæ¥å¡ãç©æ¥µçã«èªèããŸãïŒæ¬åœã«äŸ¿å©ã§äŸ¿å©ãªã©ãããããã®å ŽåïŒã
ãã©ã³ã¹æèŠãšãã©ã³ã¹ã«ã€ããŠ
ååãšããŠãããã¯äžè§åœ¢ã®3çªç®ã®ããŒã¯ãã€ãŸãäŸ¡æ Œã«é¢ããäŒè©±ã§ãã
æ¶ç©ºã®äŸãèŠãŠã¿ãŸãããã
äŸ
200 . .
. security , (anti-virus, anti-spyware, and firewall software), .
( ) 10- , â NGFW , , Palo Alto 7K (c 40 ), , , High Availability .
, , security .
, .
, 10 , ( ) .
, 200 âŠ
䟿å©ã§ããïŒ , .
âŠ
, - , . â , , , .
ãã®äŸã¯èªåŒµãããŠããŸããïŒæ¬¡ã®ç« ã§ãã®è³ªåã«çããŸãã
ãããã¯ãŒã¯äžã§ããã®èšäºã§æ€èšããå 容ã衚瀺ãããªãå Žåã¯ããããæšæºã§ãã
ç¹å®ã®ã±ãŒã¹ããšã«ãå©äŸ¿æ§ãäŸ¡æ Œãã»ãã¥ãªãã£ã®éã®åççãªåŠ¥åç¹ãèŠã€ããå¿ èŠããããŸããå€ãã®å Žåããªãã£ã¹ã§NGFWããå¿ èŠãšããªãããããã¡ã€ã¢ãŠã©ãŒã«ã§ã®L7ä¿è·ã¯å¿ èŠãããŸãããé©åãªã¬ãã«ã®å¯èŠæ§ãšã¢ã©ãŒããæäŸããã ãã§ååã§ããããã¯ãããšãã°ãªãŒãã³ãœãŒã¹è£œåã䜿çšããŠå®è¡ã§ããŸããã¯ããæ»æã«å¯Ÿããããªãã®åå¿ã¯ç¬æã§ã¯ãããŸããããäž»ãªããšã¯ãããèŠããšããããšã§ãããããªãã®éšéã«é©åãªããã»ã¹ãããã°ãããªãã¯ãããè¿ éã«ç¡ååããããšãã§ããŸãã
ãããŠããããã®äžé£ã®èšäºã®ã¢ã€ãã¢ã«ããã°ãããªãã¯ãããã¯ãŒã¯èšèšã«é¢äžããŠããããããªããåŸããã®ãæ¹åããããšããŠããã ãã§ããããšãæãåºãããŠãã ããã
ãªãã£ã¹ã¢ãŒããã¯ãã£ã®å®å šåæ
ããã§èª¬æãããSAFE Secure Campus Architecture Guideã®å³äžã§å Žæãå²ãåœãŠããã®èµ€ãåè§ã«æ³šæããŠãã ããã
ããã¯ã建ç¯ã®éèŠãªå Žæã®1ã€ã§ãããæãéèŠãªäžç¢ºå®æ§ã®1ã€ã§ãã
泚ïŒ
FirePowerãèšå®ããããšã¯ãªãïŒCiscoãã¡ã€ã¢ãŠã©ãŒã«ã©ã€ã³ãã-ASAã®ã¿ïŒãåãæ©èœãåããŠãããšä»®å®ããŠãããšãã°Juniper SRXãPalo Altoãªã©ã®ä»ã®ãã¡ã€ã¢ãŠã©ãŒã«ãšåæ§ã«æ€èšããŸãã
éåžžã®æ§é ããããã®æ¥ç¶ã§ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããããã®4ã€ã®å¯èœãªãªãã·ã§ã³ã®ã¿ã衚瀺ãããŸãã
- åãµããããã®ããã©ã«ãã²ãŒããŠã§ã€ã¯ã¹ã€ããã§ããããã¡ã€ã¢ãŠã©ãŒã«ã¯ééã¢ãŒãã§ãïŒã€ãŸãããã¹ãŠã®ãã©ãã£ãã¯ã¯ééããŸãããL3ãããã圢æããŸããïŒã
- - ( SVI ), L2
- VRF, VRF , VRF ACL
- ,
1
, .
2
PBR ( service chain), , , , .
ããã¥ã¡ã³ãã®ãããŒã®èª¬æããããã¹ãŠã®åããã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ãééããããšãããããŸããã€ãŸããCiscoã®èšèšã«åŸã£ãŠã4çªç®ã®ãªãã·ã§ã³ã¯è¡šç€ºãããªããªããŸãã
æåã®2ã€ã®ãªãã·ã§ã³ãèŠãŠã¿ãŸãããã
ãããã®ãªãã·ã§ã³ã䜿çšãããšããã¹ãŠã®ãã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ãééããŸãã
次ã«ãããŒã¿ã·ãŒããšCisco GPLãèŠãŠããªãã£ã¹ã®åèšåž¯åå¹ ãå°ãªããšã10ã20ã®ã¬ãããã®é åã«ãããå Žåã¯ã4KããŒãžã§ã³ãè³Œå ¥ããå¿ èŠãããããšã確èªããŸãã
泚
åèšåž¯åå¹ ã«ã€ããŠè©±ããšãããµããããéã®ãã©ãã£ãã¯ãæå³ããŸãïŒ1ã€ã®wilanå ã§ã¯ãããŸããïŒã
GPLãããThreat DefenseãåããHAãã³ãã«ã®äŸ¡æ Œã¯ãã¢ãã«ïŒ4110ã4150ïŒã«å¿ããŠãçŽ50ã250äžãã«ãšç°ãªãããšãããããŸãã
ã€ãŸããèšèšã¯åã®äŸã®ããã«ãªãå§ããŸãã
ããã¯ããã®èšèšãééã£ãŠããããšãæå³ããŸããïŒ
ããããããã§ã¯ãããŸãããã·ã¹ã³ã¯ãææãã補åã©ã€ã³ã«åºã¥ããŠå¯èœãªéãæé«ã®ä¿è·ãæäŸããŸããããããããã¯ãããããªãã«ãšã£ãŠããã¹ããã¥ãã§ããããšãæå³ãããã®ã§ã¯ãããŸããã
ååãšããŠãããã¯ãªãã£ã¹ãŸãã¯ããŒã¿ã»ã³ã¿ãŒã®èšèšã§çºçããäžè¬çãªè³ªåã§ãããããã¯åŠ¥åç¹ãæ¢ããªããã°ãªããªãããšãæå³ããŸãã
ããšãã°ããã¹ãŠã®ãã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ãééã§ããããã§ã¯ãããŸããããã®å Žåã3çªç®ã®ãªãã·ã§ã³ã¯éåžžã«è¯ãããã«æããŸãïŒåã®ã»ã¯ã·ã§ã³ãåç §ïŒãããããããã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãã«Threat Defenseã¯å¿ èŠãªããããã¡ã€ã¢ãŠã©ãŒã«ã¯äžèŠå¿ èŠãªã®ã¯ãææïŒé«äŸ¡ã§ã¯ãªãïŒãŸãã¯ãªãŒãã³ãœãŒã¹ã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããããã·ãã¢ãã¿ãªã³ã°ããŸãã¯ãã¡ã€ã¢ãŠã©ãŒã«ãå¿ èŠã§ãããå¥ã®ãã³ããŒãå¿ èŠã§ãã
éåžžããã®äžç¢ºå®æ§ã¯åžžã«ååšããã©ã®ãœãªã¥ãŒã·ã§ã³ãæé©ã§ãããã«ã€ããŠåäžã®çãã¯ãããŸããã
ããããã®ã¿ã¹ã¯ã®è€éããšçŸããã§ãã