ã€ã³ã¿ãŒãã§ãŒã¹èšå®
Cisco ASAã¯ãã¹ããŒããã«ã€ã³ã¹ãã¯ã·ã§ã³ã»ãã·ã§ã³ãåããã¹ããŒããã«ã€ã³ã¹ãã¯ã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ã§ãã ASAã¯ãã«ãŒãããïŒããã©ã«ãã§ã¯ã«ãŒã¿ãŒã¢ãŒãïŒãšééïŒASAããã£ã«ã¿ãªã³ã°ããªããžãšããŠæ©èœããå Žåã¯ééãã¡ã€ã¢ãŠã©ãŒã«ïŒã®2ã€ã®ã¢ãŒãã§åäœã§ããŸãã æåã®ã¢ãŒãã§äœæ¥ãç¥ãããã«ãªãã以éãç¹ã«æå®ããªãéããã©ãã§ããããæå³ããŸãã
ã«ãŒãããã¢ãŒãã§ã¯ãåASAã€ã³ã¿ãŒãã§ã€ã¹ã¯IPã¢ãã¬ã¹ããã¹ã¯ãã»ãã¥ãªãã£ã¬ãã«ãã€ã³ã¿ãŒãã§ã€ã¹åã§èšå®ãããããã©ã«ãã§ã¯ãã¹ãŠã®ã€ã³ã¿ãŒãã§ã€ã¹ãã管çè ã«ããç¡å¹åãç¶æ ã«ãããããã€ã³ã¿ãŒãã§ã€ã¹ã匷å¶çã«äžããå¿ èŠããããŸãã ïŒäŸå€ããããŸããASAã¯äºåã«æ§æãããŠããå ŽåããããŸããããã¯5505ã¢ãã«ã®å žåã§ãããã®å ŽåãååãšããŠãå éšã®ååãæã€å éšã€ã³ã¿ãŒãã§ã€ã¹ã¯æ¢ã«æãå®å šã§äžããããDHCPãµãŒããŒãå®è¡ããããããã¯ãŒã¯192.168.1.0ããã®éçã¢ãã¬ã¹ãèšå®ãããŠããŸã/ 24ãoutsideãšããååã®å€éšã€ã³ã¿ãŒãã§ã€ã¹ãçºçããããèªäœãDHCPçµç±ã§ã¢ãã¬ã¹ãåä¿¡ããå éšã€ã³ã¿ãŒãã§ã€ã¹ã®èåŸã®ãããã¯ãŒã¯ããå€éšã€ã³ã¿ãŒãã§ã€ã¹ã¢ãã¬ã¹ãžã®ã¢ãã¬ã¹å€æãèšå®ãããŸãããã®ãããªãã©ã°ã¢ã³ããã¬ã€ãå€æããŸãã
int g0 / 0 IPã¢ãã¬ã¹{ã¢ãã¬ã¹} {ãã¹ã¯} ã»ãã¥ãªãã£ã¬ãã«{æ°å€} nameif {name} ã·ã£ããããŠã³ãªã
ãã»ãã¥ãªãã£ã¬ãã«ããã©ã¡ãŒã¿ã¯0ã100ã®æ°å€ã§ã2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ãæ¯èŒããã©ã¡ãããããå®å šãããå€æã§ããŸãã ãã©ã¡ãŒã¿ã¯ãå®éçã§ã¯ãªãå®æ§çã«äœ¿çšãããŸãã ããå°ãªãé¢ä¿ã®ã¿ãéèŠã§ãã ããã©ã«ãã§ã¯ããã©ãã£ãã¯ã¯ãå€éšãã«åãã£ãŠããŸãã ã»ãã¥ãªãã£ã¬ãã«ã®é«ãã€ã³ã¿ãŒãã§ã€ã¹ããã»ãã¥ãªãã£ã¬ãã«ã®äœãã€ã³ã¿ãŒãã§ã€ã¹ãŸã§ãã¹ããããããã»ãã·ã§ã³ã¯èšæ¶ããããããã®ã»ãã·ã§ã³ããã®å¿çã®ã¿ãã¹ããããããŸãã ãå éšããžã®ãã©ãã£ãã¯ã¯ããã©ã«ãã§ã¯çŠæ¢ãããŠããŸãã
å°æ¥ããã©ã¡ãŒã¿ãŒãã€ã³ã¿ãŒãã§ãŒã¹åãïŒnameifïŒã䜿çšãããšãèšå®ã§ã€ã³ã¿ãŒãã§ãŒã¹ã®ç©çåã§ã¯ãªããã話ãããšããŠéžæã§ããååïŒå éšãå€éšãdmzãããŒãããŒãªã©ïŒã䜿çšã§ããŸãã çè«çã«ã¯ãã·ã¹ã³èªäœã«ãããšãååã¯å€§æåãšå°æåãåºå¥ããïŒå€§æåãšå°æåãåºå¥ããŸããïŒãå®éã«ã¯ãå€ãã®ã³ãã³ãã§å€§æåãšå°æåãåºå¥ããå¿ èŠããããããã¯ããªãäžäŸ¿ã§ãã å žåçãªäŸïŒã€ã³ã¿ãŒãã§ã€ã¹ã«æå·ããããé©çšããã«ã¯ãã€ã³ã¿ãŒãã§ã€ã¹åã®æ£ç¢ºãªã¹ãã«ãå¿ èŠã§ãã ã€ã³ã¿ãŒãã§ã€ã¹ã®ååãç¶ããã«ã¯ãTABãã¿ã³ãæŒããŸãã å ¥åããå é ãã€ã³ã¿ãŒãã§ã€ã¹ãäžæã«èå¥ããå Žåãååã®å é ãå ¥åããã¿ãã¥ã¬ãŒã¿ãŒã§æåŸãŸã§ç¶è¡ã§ããŸãã
ãã®ã€ã³ã¿ãŒãã§ã€ã¹èšå®ã¯ãASA 5505ãé€ããã¹ãŠã®ASAã¢ãã«ã«å ±éã§ãã5505ã«ã¯ãçµã¿èŸŒã¿ã®8ããŒãL2 / L3ã¹ã€ããããããŸãã ã¢ãã«5505ã®IPã¢ãã¬ã¹ã¯è«çã€ã³ã¿ãŒãã§ã€ã¹ã«èšå®ãããŸã
ã€ã³ã¿ãŒãã§ã€ã¹VLAN {ïŒ} IPã¢ãã¬ã¹{ã¢ãã¬ã¹} {ãã¹ã¯} ã»ãã¥ãªãã£ã¬ãã«{æ°å€} nameif {name} ã·ã£ããããŠã³ãªã
ç©çL2ã€ã³ã¿ãŒãã§ã€ã¹èªäœã¯VLANã«ãããã³ã°ãããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹f0 / 0 ã¹ã€ããããŒãã¢ã¯ã»ã¹VLAN {ïŒ}
ãããã£ãŠããã¡ã€ã¢ãŠã©ãŒã«ã¯è«çã€ã³ã¿ãŒãã§ã€ã¹VLANã®éã§çºçããŸãã
ååãšããŠãã€ã³ã¿ãŒãã§ã€ã¹ã®ã»ãã¥ãªãã£ã¬ãã«ã¯ããããã¯ãŒã¯ã®è«çããããžã«æââé©ãªæ¹æ³ã§éžæãããŸãã ããããžèªäœã¯ã»ãã¥ãªãã£ãŸãŒã³ã§ããããããã®éã®çžäºäœçšã®ã«ãŒã«ã§ãã å€å žçãªã¹ããŒã ã¯ãããŸããŸãªã»ãã¥ãªãã£ã¬ãã«ãããŸããŸãªã€ã³ã¿ãŒãã§ã€ã¹ã«å²ãåœãŠãããšã§ãã
ç°ãªãã€ã³ã¿ãŒãã§ã€ã¹ã®ã»ãã¥ãªãã£ã¬ãã«ãåãã«ããããšãçŠæ¢ãã人ã¯ããŸããããããã©ã«ãã§ã¯ããã®ãããªã€ã³ã¿ãŒãã§ã€ã¹éã®ãã©ãã£ãã¯äº€æã¯çŠæ¢ãããŠããŸãã ãã®ãããªãã©ãã£ãã¯ã¯ãã³ãã³ããäžããããšã§æå³çã«èš±å¯ããããšãã§ããŸã
åäžã»ãã¥ãªãã£ãã©ãã£ãã¯èš±å¯ã€ã³ã¿ãŒãã§ã€ã¹é
ãã ããåãã¬ãã«ã®ã»ãã¥ãªãã£ãåããã€ã³ã¿ãŒãã§ã€ã¹éã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãªãã«ãŒãã£ã³ã°ã®ã¿ãè¡ãããããšãç解ããå¿ èŠããããŸãã ãããã£ãŠããã®ã¢ãããŒãã¯ãåãè«çã»ãã¥ãªãã£ãŸãŒã³ã«é¢é£ããã€ã³ã¿ãŒãã§ã€ã¹ã«äœ¿çšãããŸãïŒããšãã°ãASAã«ãã£ãŠçµåããããŠãŒã¶ãŒã®2ã€ã®ããŒã«ã«ãšãªã¢ãããã¯ãŒã¯ïŒ
ã«ãŒãã£ã³ã°
ããŠããããªãã§ã©ãã«ïŒ ã«ãŒã¿ãŒãšåæ§ã«ïŒASAã¯ã«ãŒãã£ã³ã°ããŒãã«ã䜿çšããŠãã±ãããéä¿¡ãããããASAã«ããããŸãïŒãã€ã³ã¿ãŒãã§ã€ã¹ã«èšå®ããããããã¯ãŒã¯ã¯ããæ¥ç¶æžã¿ããšããŒã¯ãããã«ãŒãã£ã³ã°ããŒãã«ã«èªåçã«åé¡ãããŸããã¢ããç¶æ ã ãããã®ãããã¯ãŒã¯éã®ãã±ããã«ãŒãã£ã³ã°ã¯èªåã§ãã
ASAèªäœãèšè¿°ããå¿ èŠã®ãªããããã¯ãŒã¯ã ããã¯ãã³ãã³ãã䜿çšããŠæåã§å®è¡ã§ããŸã
ã«ãŒã{ã€ã³ã¿ãŒãã§ãŒã¹} {ãããã¯ãŒã¯} {ãã¹ã¯} {ãã¯ã¹ãããã} [{管çè·é¢}] [ãã©ãã¯{ïŒ}]
ãã¯ã¹ãããããæ¢ãã€ã³ã¿ãŒãã§ã€ã¹ãæå®ããŸãã ASAèªäœã¯ãã®ãããªæ€çŽ¢ãè¡ããŸããïŒéåžžã®Ciscoã«ãŒã¿ãŒãšã¯ç°ãªããŸãïŒã æ倧16ã®äžŠåãã¹ã䜿çšã§ããåŸæ¥ã®ã«ãŒã¿ãŒãšã¯ç°ãªããã«ãŒãã£ã³ã°ããŒãã«å ã®å®å ãããã¯ãŒã¯ã«å°éããã«ãŒãã¯1ã€ã ãã§ãã
ããã©ã«ãã«ãŒãã¯åãæ¹æ³ã§èšå®ãããŸãã
route {interface} 0.0.0.0 0.0.0.0 {next-hop}
ASAãã«ãŒãã£ã³ã°ããŒãã«ã«ãã±ããå®å ãããã¯ãŒã¯ã«é¢ãããšã³ããªããªãå Žåããã±ãããå»æ£ããŸãã
ã¡ã€ã³ã®ã«ãŒããæ¶ãããšãã«ã®ã¿æ©èœããããã¯ã¢ããéçã«ãŒããäœæãããšããã¿ã¹ã¯ãçºçããå Žåãããã¯ããããã«ãŒãã®ç®¡çè·é¢ã瀺ãããšã§è§£æ±ºãããŸãã ããã¯ã0ã255ã®æ°å€ã§ãããã«ãŒãéžææ¹æ³ã®æå¹æ§ã瀺ããŸãã ããšãã°ãéçã«ãŒãã¯ããã©ã«ãã§AD 1ãEIGRP-90ãOSPF-110ãRIP-120ã«ããããããŸããã¡ã€ã³ADãããå€ãã®ãã©ãŒã«ããã¯ã«ãŒãã«ADãæ瀺çã«æå®ã§ããŸãã äŸïŒ
0.0.0.0 0.0.0.0ã®å€åŽã®ã«ãŒã{next-hop} 1 ã«ãŒãããã¯ã¢ãã0.0.0.0 0.0.0.0 {next-hop_backup} 210
ãããããã®ç¶æ³ã§ã¯ã1ã€ã®éèŠãªè³ªåããããŸããã¡ã€ã³ã«ãŒãããæ¶å€±ããããæ¹æ³ã§ããã ã€ã³ã¿ãŒãã§ã€ã¹ãç©ççã«èœã¡ãå Žåããã¹ãŠãæããã§ã-ããã¯ããèªäœã§åäœããŸãããã€ã³ã¿ãŒãã§ã€ã¹ãã¢ããããŠããããããã€ããŒãæ»ãã§ããå Žåã¯ã©ããªããŸããïŒ ããã¯ãASAã«ç©ççãªã€ãŒãµããããéåžžã«ãŸãã«ããååšããªããããéåžžã«äžè¬çãªç¶æ³ã§ãã
ãã®åé¡ã解決ããããã«ãSLAãã¯ãããžãŒã䜿çšãããŸãã ããã¯ãã¯ã©ã·ãã¯ã«ãŒã¿ãŒã§é«åºŠã«éçºãããŠãããããŒãžã§ã³7.2以éã®ASAã§ã¯ãæãåçŽãªã¡ã«ããºã ïŒicmpãããã³ã«çµç±ã®ãã¹ãã®å¯çšæ§ïŒã®ã¿ãå®è£ ããŠããŸããã ãããè¡ãã«ã¯ããã®ãããªãpingovalkaãïŒsla monitorïŒãäœæããŸã
sla monitor {ïŒ} ã¿ã€ãecho protocol ipIcmpEcho {ip address} interface {interface}
ããã«ãéå§æéïŒãä»ããéå§ããããšãå¯èœïŒãšäœæ¥ã®çµäºïŒäœæ¥ãç¡éã«èšå®ã§ããŸãïŒãæå®ããŠéå§ããå¿ èŠããããŸãã
SLAã¢ãã¿ãŒã¹ã±ãžã¥ãŒã«{ïŒ}人çãæ°žé ã«éå§
ããããããã ãã§ã¯ãããŸããã ãpingovalkaãã®ã¹ããŒã¿ã¹ã远跡ãããã¹ã€ãããïŒãã©ãã¯ïŒãäœæããå¿ èŠããããŸãã
ãã©ãã¯{ãã©ãã¯ïŒ} rtr {slaïŒ}å°éå¯èœæ§
pingovalkaãã€ã³ãã£ã³ã°ãrtrããŒã¯ãŒãã䜿çšããŠå®è¡ãããçç±ãå°ããªãã§ãã ãããããã¯ãCiscoã«ãŒã¿ãŒã§ã®äžè²«æ§ã®ãªãèšå®ã®ãã³ã»ã³ã¹ã§ãã ã¡ãªã¿ã«ããã®ãããªäžäžèŽã¯ã«ãŒã¿ãŒèªäœã§æ¢ã«ä¿®æ£ãããŠããŸãããASAã§ã¯ãŸã ä¿®æ£ãããŠããŸããã
ããã§ããã®æ§æãéçã«ãŒãã£ã³ã°ã«é©çšããæºåããã¹ãŠæŽããŸããã
0å€ã®ã«ãŒã{next-hop_outside}ãã©ãã¯{ïŒ} ã«ãŒãããã¯ã¢ãã0 0 {next-hop_backup} 210
ããã§ãpingå¯èœãªãã¹ãã«ã¢ã¯ã»ã¹ã§ããéããã©ãã¯ã¯èµ·åãïŒã»ãšãã©ãupãã«æžã蟌ãŸããŸãïŒãã¡ã€ã³ã«ãŒãã¯ã«ãŒãã£ã³ã°ããŒãã«ã«ãããŸãããæ¥ç¶ã倱ããããšããã«ãæå®ãããæ°ã®ãã±ããã倱ãããŸãïŒããã©ã«ãã§ã¯ã10åããšã«ãã±ãããéä¿¡ãããŸãïŒç§ã3ãã±ããã®æ倱ãåŸ ã€ïŒãã©ãã¯ãåæ¢ãããã¡ã€ã³ã«ãŒããã«ãŒãã£ã³ã°ããŒãã«ããæ¶ãããã±ããã代æ¿ãã¹ãä»ããŠéä¿¡ãããŸãã
ã¡ã€ã³ãããã€ããŒã®å¯çšæ§ã確èªããªãããç°ãªããããã€ããŒãéã2ã€ã®ããã©ã«ãã«ãŒãã®èšå®äŸã瀺ããŸãã
SLAã¢ãã¿ãŒ1 ã¿ã€ãecho protocol ipIcmpEcho 1.1.1.1å€éšã€ã³ã¿ãŒãã§ã€ã¹ SLAã¢ãã¿ãŒã¹ã±ãžã¥ãŒã«1ä»ããéå§ ãã©ãã¯11 RTR 1å°éå¯èœæ§ 0 0 1.1.1.1ãã©ãã¯11å€ã®ã«ãŒã ã«ãŒãããã¯ã¢ãã0 0 2.2.2.1 210
ãããã³ã«RIPv1ã2ãOSPFãEIGRPã䜿çšããŠãASAã§ã®åçã«ãŒãã£ã³ã°ãå¯èœã§ãã ASAã§ãããã®ãããã³ã«ãèšå®ããããšã¯ãCiscoã«ãŒã¿ãŒãèšå®ããããšã«éåžžã«äŒŒãŠããŸãã ä»ã®ãšããããããã®åºçç©ã®åçã«ãŒãã£ã³ã°ã«ã€ããŠã¯è§ŠããŸããããæãå±ãèå³ãããå Žåã¯ãå¥ã®ç« ãæžããŸãã
ãªã¢ã³ã³
ããŒã¿ãããã¯ãŒã¯ã®çŸåšã®éçºã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã®ãªã¢ãŒãå¶åŸ¡ãå°å ¥ããªãã®ã¯äžåçã§ããããšã¯æããã§ãã ãããã£ãŠãASAã¯ãã»ãšãã©ã®ã·ã¹ã³ããã€ã¹ãšåæ§ã«ãããã€ãã®ãªã¢ãŒã管çæ¹æ³ãæäŸããŸãã
æãåçŽã§æãå±éºãªã®ã¯telnetã§ãã telnetçµç±ã§ASAã«ã¢ã¯ã»ã¹ã§ããããã«ããã«ã¯ãã©ã®ãã¹ããšãããã¯ãŒã¯ãããã³ã©ã®ã€ã³ã¿ãŒãã§ã€ã¹ã¢ã¯ã»ã¹ãèš±å¯ããããæ瀺çã«æå®ããå¿ èŠããããŸãããŸããpasswdã³ãã³ãã§telnetã®ãã¹ã¯ãŒããæå®ããå¿ èŠããããŸãã
telnet 192.168.1.128 255.255.255.128å éš telnet 192.168.1.254 255.255.255.255å éš passwd {ãã¹ã¯ãŒã}
ã»ãã¥ãªãã£äžã®çç±ãããæãå®å šã§ã¯ãªãïŒãã®ASAå ã§æãã»ãã¥ãªãã£ã¬ãã«ãäœãïŒã€ã³ã¿ãŒãã§ã€ã¹ã§ã®telnetæäœã¯ãããã¯ããããã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ã®telnetæäœã¯ãIPSecãã³ãã«ãä»ããŠå°çããå Žåã«ã®ã¿å¯èœã§ãã
sshãããã³ã«ã«ãããããå®å šãªã³ãã³ãã©ã€ã³ã¢ã¯ã»ã¹ãæäŸãããŸãã ãã ããsshãä»ããŠã¢ã¯ã»ã¹ãæäŸããã«ã¯ã管çã®ããã«ã¢ã¯ã»ã¹ã§ãããã¹ããæ瀺çã«æå®ããããšã«å ããŠããŠãŒã¶ãŒããŒã¿ã®æå·åã«å¿ èŠãªRSAããŒãæå®ããå¿ èŠããããŸãã ããã©ã«ãã§ã¯ãpixãŠãŒã¶ãŒã¯sshæ¥ç¶ã«äœ¿çšãããpasswdã³ãã³ãã§æå®ããããã¹ã¯ãŒãïŒtelnetãã¹ã¯ãŒãïŒã䜿çšãããŸãã
ïŒ ãã¡ã€ã³åãèšå®ãã ãã¡ã€ã³å{name} ïŒ ïŒ ããã©ã«ã以å€ã®ãã¹ãåãæå®ããããšããå§ãããŸã ãã¹ãå{åå} ïŒ ïŒ ãã®åŸãããŒãçæã§ããŸã æå·éµã¯RSAãçæããŸã ïŒ ïŒ sshãèš±å¯ãã ssh 192.168.1.128 255.255.255.128å éš ssh 1.2.3.4 255.255.255.255å€éš passwd {ãã¹ã¯ãŒã}
ååãšããŠãããŒãžã§ã³7.2以éã®ASAã§ã¯ããã¡ã€ã³åããã§ã«èšå®ãããŠããïŒdomain.invalidïŒãããã©ã«ãããŒãçæãããŸãããå°ãªããšãããã確èªããå¿ èŠããããŸã
æå·éµmypubkey rsaã衚瀺
å°ãªããšãããã€ãã®RSAããŒã®ååšã«ããããã§ã«sshã§äœæ¥ã§ããŸãã ãã ããããã©ã«ã以å€ã®ããŒãã¢ãè¿œå ã§äœæããããšãã§ããŸãã ãããè¡ãã«ã¯ãããŒãã¢ã®ååãæ瀺çã«æå®ããå¿ èŠããããŸã
æå·éµã¯ãRSAã©ãã«ãçæããŸã{ãã¢å}
ããŒãã¢ïŒãŸãã¯ãã¹ãŠã®ãã¢ïŒãåé€ããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸã
æå·éµãŒãårsa [ã©ãã«{ãã¢å}]
ãã³ãïŒããŒãã¢ã䜿çšããã¢ã¯ã·ã§ã³ïŒäœæãåé€ïŒã®åŸãå¿ ãä¿åããŠãã ããã ããã«ã¯ãæšæºã®ciscoã³ãã³ãã䜿çšã§ããŸãã
å®è¡æ§æã®èµ·åæ§æã®ã³ã㌠æžã蟌ã¿ã¡ã¢ãª
ãŸãã¯æåŸã®ã³ãã³ãã®çãããŒãžã§ã³
wr
ASAã¯ãWebãã©ãŠã¶ã䜿çšããéåžžã«äžè¬çãªèšå®æ¹æ³ãæäŸããŸãã ãã®æ¹æ³ã¯ASDMïŒAdaptive Security Device ManagerïŒãšåŒã°ããŸãã å®å šãªãããã³ã«httpsãã¢ã¯ã»ã¹ã«äœ¿çšãããŸãã ã¢ã¯ã»ã¹å¶åŸ¡ã¯ãsshãšéåžžã«ãã䌌ãæ§æã«ãªã£ãŠããŸããããã©ã«ãã®RSAããŒãããããšã確èªããããæ¥ç¶ã§ããå Žæã瀺ãå¿ èŠããããŸãã
ãã¡ã€ã³å{name} ãã¹ãå{åå} æå·éµã¯RSAãçæããŸã ïŒ httpsãµãŒããŒèªäœããªã³ã«ããŸããå€ãã®å Žåãããã©ã«ãã§ãªã³ã«ãªã£ãŠããŸãã ãªã³ã«ãããšã ïŒ èªå·±çœ²å蚌ææžãçæããŸãã HTTPãµãŒããŒã®æå¹å ïŒ httpsãèš±å¯ãã http 192.168.1.128 255.255.255.128å éš http 1.2.3.4 255.255.255.255å€éš
ä»ã«äœãèšå®ããªãå ŽåããŠãŒã¶ãŒãæå®ããã«ã¢ã¯ã»ã¹ãæäŸãããŸãã ç¹æš©ã¢ãŒãã®ãã¹ã¯ãŒããæå®ãããå Žå
ã€ããŒãã«ãã¹ã¯ãŒã{password}
次ã«ãæ¥ç¶æã«ããŠãŒã¶ãŒãæå®ããã«ãã¹ã¯ãŒããšããŠæå®ããå¿ èŠããããŸãã
ASDMãã©ãã·ã¥ã«ã䜿çšãããŠããOSã«å¯Ÿå¿ããASDMãã¡ã€ã«ãå«ãŸããŠããããšã確èªããå¿ èŠããããŸãã
dir flashïŒ ã·ã§ãŒãã©ãã·ã¥
ASDMã䜿çšããå Žåãjavaã䜿çšããã次ã®ããšãåœãŠã¯ãŸããŸããOSããŒãžã§ã³7.Xã䜿çšããŠããå ŽåãASDMã¯ããŒãžã§ã³5.Xããã³java 1.5ãå¿ èŠãšããŸãã OS 8.Xã䜿çšããå ŽåãããŒãžã§ã³6.Xããã³JavaããŒãžã§ã³1.6ã«ã¯ASDMãå¿ èŠã§ãã éçºè ã®å瞟ãšãã¥ãŒããŒã®åã³ã®ããã«ãASDMããŒãžã§ã³6ã¯ããŒãžã§ã³5.Xãããåªããé«éã§åäœããŸãã 誰ã®ã¡ãªãããããïŒJavaãŸãã¯CiscoãŸãã¯ãã®äž¡æ¹-ç§ã¯ç¥ããŸããã
åççãªçåãçããŸããããã©ã«ãã®ã¢ã¯ã»ã¹ã«ãŒã«ã§ã¯ãªããã©ãã§ãŠãŒã¶ãŒãååŸããããæ瀺çã«æå®ãããå Žåã¯ã©ãã§ããããã ããã«ã¯ã³ãã³ãã䜿çšãããŸãïŒã³ã³ãœãŒã«-ããŒã¯ãŒãïŒ
aaaèªèšŒtelnetã³ã³ãœãŒã«{AAAãµãŒããŒå} [ããŒã«ã«] aaaèªèšŒsshã³ã³ãœãŒã«{AAAãµãŒããŒå} [ããŒã«ã«] aaaèªèšŒhttpã³ã³ãœãŒã«{AAAãµãŒããŒå} [ããŒã«ã«]
ããŒã«ã«ãŠãŒã¶ãŒããŒã¿ããŒã¹ã®ã¿ã䜿çšããå Žåã¯ãèªèšŒã«ãŒã«ã§LOCALã®ã¿ãæå®ã§ããŸãïŒå°ãªããšã1人ã®ãŠãŒã¶ãŒãäœæãããŠããããšã確èªããŸããããã§ãªãå Žåã¯ãèªåãžã®ã¢ã¯ã»ã¹ããããã¯ã§ããŸãïŒããã®ãããªãµãŒããŒã¯äºåã«æ§æããå¿ èŠããããŸã
aaa-server {AAAãµãŒããŒå}ãããã³ã«{tacacs | radius | ldap} aaa-server {AAAãµãŒããŒå}ïŒ{ã€ã³ã¿ãŒãã§ã€ã¹}ïŒãã¹ã{ip} ããŒ{key} ïŒ ãã®ã¿ã€ãã®ãµãŒããŒã«åºæã®ãã®ä»ã®ã³ãã³ã
ããŒã«ã«ãŠãŒã¶ãŒããŒã¹ã¯ããŒã ã«ãã£ãŠèšå®ãããŸã
ãŠãŒã¶ãŒ{ãŠãŒã¶ãŒ}ãã¹ã¯ãŒã{ãã¹ã¯ãŒã} [ç¹æš©ïŒ]
ASDMçµç±ã®ã¢ã¯ã»ã¹ã¯ãç¹æš©ã¬ãã«15ã®ãŠãŒã¶ãŒã«ä»£ãã£ãŠã®ã¿å¯èœã§ãïŒæ倧ãšã¯ããŠãŒã¶ãŒãæ§æã§ããããšãæå³ããŸãïŒ
次ã®ã³ãã³ãã䜿çšããŠãããŒã«ã«ãŠãŒã¶ãŒã«ããã€ãã®å±æ§ãèšå®ããããšãã§ããŸãã
ãŠãŒã¶ãŒ{user}å±æ§ ïŒ ããŸããŸãªãŠãŒã¶ãŒå±æ§
ãã®ããŒããçµããŠãèšå®ã®äžéšãæäŸããŸãã æ§æããã2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ïŒãã®å Žåã¯gigabitethernet 0/0ããã³0/1ã§ãããç°ãªããã©ãããã©ãŒã ã§ã¯ä»ã®ç©çã€ã³ã¿ãŒãã§ã€ã¹ã§ãããŸããŸããïŒãå éšããã³å€éšãããã©ã«ãã«ãŒããsshããã³httpsçµç±ã®ãªã¢ãŒãã¢ã¯ã»ã¹ã¯ã©ãããã§ãèš±å¯ãããŸãããã
èªèšŒã¯ããŒã«ã«ãŠãŒã¶ãŒããŒã¿ããŒã¹ã䜿çšããŸãã
ãã¹ãåmyAsa ïŒ ãã¡ã€ã³åanticisco.ru ïŒ ã€ã³ã¿ãŒãã§ãŒã¹g0 / 0 å€ã®åå ã»ãã¥ãªãã£ã¬ãã«0 IPã¢ãã¬ã¹1.1.1.2 255.255.255.252 éãŸããªã ïŒ int g0 / 1 äžã®åå ã»ãã¥ãªãã£ã¬ãã«100 IPã¢ãã¬ã¹10.1.1.1 255.255.255.0 éãŸããªã ïŒ ïŒ ASAã¬ã³ãŒãã§ã¯0.0.0.0ã0ã«æžããããšãã§ããŸã ïŒ 0 0 1.1.1.1å€ã®ã«ãŒã ïŒ ãŠãŒã¶ãŒåadminãã¹ã¯ãŒãciscoç¹æš©15 ïŒ ssh 0 0å éš ssh 0 0å€ ïŒ http 0 0å éš http 0 0å€ ïŒ aaaèªèšŒsshã³ã³ãœãŒã«ããŒã«ã« AAAèªèšŒHTTPã³ã³ãœãŒã«LOCAL
ãããã®èšå®ã䜿çšãããšãå éšã€ã³ã¿ãŒãã§ã€ã¹ã®èåŸã«ããçŽæ¥æ¥ç¶ããããããã¯ãŒã¯ããå€éšãžã®ãã±ããéä¿¡ãèš±å¯ã§ããŸãã å€éšã§ã¯ãã»ãã·ã§ã³ïŒtcpããã³udpïŒã®å¿çã®ã¿ãåä¿¡ãããå éšããéãããŸãã ããã©ã«ãã§ã¯ããå éšããžã®ãã©ãã£ãã¯ã¯å®å šã«çŠæ¢ãããŠããŸãã 解決æ¹æ³ã«ã€ããŠã¯ã次ã®ããŒãã§èª¬æããŸãã
ã¢ã¯ã»ã¹ãªã¹ãïŒç¶ãïŒ