ãŸããçšèªãå®çŸ©ããŸãããã ãã§ã«ãåç¥ã®ããã«ãASAã§ã¯ãéä¿¡å ã€ã³ã¿ãŒãã§ã€ã¹ãšå®å ã€ã³ã¿ãŒãã§ã€ã¹ã®ã»ãã¥ãªãã£ã¬ãã«ãæ¯èŒããããšã«ããããã¡ã€ã¢ãŠã©ãŒã«ã®ãå€åŽããšãå åŽãã®æ¹åãç°¡åã«å€æã§ããŸãïŒåãã»ãã¥ãªãã£ã¬ãã«ã®ç¶æ³ãåå¥ã«æ€èšããŸãïŒã
éåžžã å éš ïŒå éšïŒãããŒããã£ã¹ããšå€éš ïŒå€éšïŒãããŒããã£ã¹ããåé¢ããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ããå€åŽãã«åºããšãå éšãããŒããã£ã¹ãããœãŒã¹ã¢ãã¬ã¹ã眮ãæããMEãééãããšãã«å€éšãããŒããã£ã¹ãããœãŒã¹ã¢ãã¬ã¹ã眮ãæããŸãã
ååãšããŠãå éšå€æã䜿çšããŠããã©ã€ããŒãã§ã«ãŒãã£ã³ã°ã§ããªãã€ã³ã¿ãŒãããã¢ãã¬ã¹ïŒRFC1918ïŒããããã€ããŒãçºè¡ããã°ããŒãã«ã¢ãã¬ã¹ã«çœ®ãæããã ãã§ååã§ãã
ãŸãã ã¢ãã¬ã¹ããã¢ãã¬ã¹ãžã®å€æïŒNATãOSIã¢ãã«ã¬ãã«3ã§å®è¡ããã1ã€ã®ã¢ãã¬ã¹ãå¥ã®ã¢ãã¬ã¹ã«çœ®ãæããããŸãïŒãããã³ããŒãããŒã¹ã®å€æ ïŒããŒãã¢ãã¬ã¹å€æãPATãOSIã¢ãã«ã¬ãã«4ã§å®è¡ãããã¢ãã¬ã¹ã ãã§ãªããããŒãïŒã PATãããŒããã£ã¹ãã¯ãããŒãïŒTCPãUDPïŒãæã€ãããã³ã«ã«å¯ŸããŠã®ã¿å®è¡ã§ããããšã¯æããã§ãã ãã ããPATã䜿çšãããšãè€æ°ã®ããŒã«ã«ã¢ãã¬ã¹ã1ã€ã®ã°ããŒãã«ã«å€æã§ããŸãã倿ãã£ãã·ã¥ã¯ããœãŒã¹ã¢ãã¬ã¹ãšããŒããããã³å€æã®çµæãšããŠåä¿¡ããã¢ãã¬ã¹ãšããŒãã®å¯Ÿå¿ãæžã蟌ã¿ãŸãã
äŸïŒã¢ãã¬ã¹10.1.1.100ããã³10.1.1.200ã®2人ã®ããŒã«ã«ãŠãŒã¶ãŒãåããµã€ãwww.anticisco.ruã«ã¢ã¯ã»ã¹ããããšã決å®ã§ããããã«ããŸãã NATã䜿çšããå Žåããã®å ŽåãISPPoolïŒïŒãããã€ããŒããŒã«ããã®ã°ããŒãã«ã¢ãã¬ã¹ã§åå éšãŠãŒã¶ãŒãäžããå¿ èŠããããŸãã
10.1.1.100-> ISPPoolïŒ1ïŒ 10.1.1.200-> ISPPoolïŒ2ïŒ
PATã䜿çšããå Žåã1ã€ã®ã°ããŒãã«ã¢ãã¬ã¹ãç°ãªããã©ã€ããŒãã¢ãã¬ã¹ã«ãããã³ã°ã§ããŸããããœãŒã¹ããŒããæžãçããŸãã
10.1.1.100:29010-> ISPPoolïŒ1ïŒïŒ1024 10.1.1.200:18932-> ISPPoolïŒ1ïŒïŒ1025
ãããŠããµãŒããŒããå¿çãæ¥ããšãASAã¯å€æãã£ãã·ã¥ãããã®ããŒãã«å¿çãæ¥ããã®ãéžæããŸãã
æåŸã«ãèªè ã®çãããæåŸã«ãæŸéã¯éçãšåçã«åãããããšèšããŸãã éçãªã¢ãã¬ã¹ã¯ãããã¢ãã¬ã¹ãå¥ã®ã¢ãã¬ã¹ïŒNATã®å ŽåïŒãŸãã¯ã¢ãã¬ã¹ãšããŒãã®ãã¢ïŒPATã®å ŽåïŒã«å³å¯ã«ãã€ã³ãããŸãã çä¿¡ããã±ãŒãžã翻蚳ã«ãŒã«ã®éžæåºæºãæºãããŠããå Žåãå¿ èŠã«å¿ããŠåçãªããã±ãŒãžãäœæãããŸãã
èšèããã«ã¹ã¿ãã€ãºãŸã§ã
ãããŒããã£ã¹ããã©ã®ããã«å®è¡ãããããçè§£ããã«ã¯ãã€ã³ã¿ãŒãã§ã€ã¹ã«æåã«å°çããã®ã¯ã«ãŒãã£ã³ã°ããŒãã«ã«ãã£ãŠãã±ããããã§ãã¯ãããããšãæãåºããŠãã ããã ãã®åŸãå®å ãããã¯ãŒã¯ãžã®ã«ãŒããèŠã€ãããªãå Žåãçºä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ã決å®ããããããã±ãããç Žæ£ãããŸãã å®å ãããã¯ãŒã¯ãMEã®ãå€éšãã«ããå ŽåïŒçä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ãšæ¯èŒããŠã»ãã¥ãªãã£ã¬ãã«ãäœãã€ã³ã¿ãŒãã§ã€ã¹ã®èåŸïŒãå éšãããŒããã£ã¹ãã®ã«ãŒã«ããã§ãã¯ããããå éšãã®å Žå-å€éšïŒå€éšïŒ
Ciscoã«ãŒã¿ãŒãšã¯ç°ãªããASA倿ã«ãŒã«ã¯ããã±ããã®éåä¿¡ã«é¢ä¿ããã€ã³ã¿ãŒãã§ã€ã¹ãšå¯æ¥ã«ãªã³ã¯ãããŠããŸãã ããã«ãããã«ãŒã«ãç°¡åã«èšè¿°ã§ããŸãã
ã«ãŒã¿ãŒãšã®å¥ã®éãïŒASAã§ã¯ã倿èŠåã®ãªããã±ããã®ééãå³å¯ã«çŠæ¢ã§ããŸãã ããŒã ã«ããèŠå¶
nat-control
ããã©ã«ãã§ã¯ããã®ã³ãã³ãã¯ç¡å¹ã«ãªã£ãŠããŸãã 倿èŠåããªãå Žåããã±ããã¯åã«ã«ãŒãã£ã³ã°ã«åŸã£ãŠé²ã¿ãèŠåãããå Žåã倿ãå®è¡ãããŸãã ãã®ã³ãã³ããæå¹ã«ãããšãæããã«ç¿»èš³ã«ãŒã«ã«è©²åœããªãã£ãããã±ãŒãžã¯æ®é ·ã«ç Žå£ãããŸãã
ãã€ãããã¯ãããŒããã£ã¹ã
ãè峿·±ããããã±ãŒãžãåä¿¡ã€ã³ã¿ãŒãã§ãŒã¹ã«å°çãããšãå¿ èŠãªãšãã«åçãªãããŒããã£ã¹ããäœæãããããšãæãåºãããŠãã ããã ã©ã®ããã±ãŒãžã翻蚳ããå¿ èŠãããããèšè¿°ããã«ãŒã«ã¯ãnatã³ãã³ãã«ãã£ãŠèšè¿°ãããããã±ãŒãžã®ãœãŒã¹ã¢ãã¬ã¹ãèšå®ãããŸãã
natïŒ{ã€ã³ã¿ãŒãã§ã€ã¹}ïŒïŒ{ãããã¯ãŒã¯} {ãã¹ã¯}
interface-ãã±ããã®éä¿¡å ã®ã€ã³ã¿ãŒãã§ãŒã¹ã®åå
ïŒã¯ãããŒããã£ã¹ãçªå·ã§ãã ã¢ãã¬ã¹ãäœã«å€æãããã®é©åãªæç€ºãæ€çŽ¢ããå¿ èŠããããŸãã
äŸïŒ
natïŒinsïŒ1 10.1.1.0 255.255.255.0 natïŒinsïŒ1 10.2.2.2 255.255.255.255
ã芧ã®ãšãããåãçªå·ã®ã«ãŒã«ã倿°ååšããå¯èœæ§ããããŸã
ãããŒããã£ã¹ãããå 容ã瀺ã1ã€ã®æç€ºã ãã§ã¯ååã§ã¯ãªãããšã¯æããã§ãã ãŸããäœããããŒããã£ã¹ãããããèšè¿°ããå¿ èŠããããŸãã ããã¯globalã³ãã³ãã䜿çšããŠè¡ãããŸãã
ã°ããŒãã«ïŒ{ã€ã³ã¿ãŒãã§ãŒã¹}ïŒïŒ{ããŒã«|ã¢ãã¬ã¹}
interface-ããã±ãŒãžãåºãŠè¡ãã€ã³ã¿ãŒãã§ãŒã¹ã®åå
ïŒ-ãããŒããã£ã¹ãçªå·ã ããã¯ç§ãã¡ãèå³ãæã£ãŠããç¶æ natãšåãã§ãªããã°ãªããŸãã
ããŒã«-倿ããip_start-ip_end圢åŒã§ã¢ãã¬ã¹ã®ç¯å²ãæç€ºçã«èšå®ããŸãã ãã®å Žåããã€ãããã¯NAT倿ãååŸããŸãã
ã¢ãã¬ã¹-ã¢ãã¬ã¹ã®ããŒã«ã§ã¯ãªã1ã€ã®ã¢ãã¬ã¹ãæå®ãããšããã¹ãŠã®å€æããã®äžã§å®è¡ãããŸããã€ãŸããPATããããŒããã£ã¹ããããŸãã
äŸïŒ
ã°ããŒãã«ïŒã¢ãŠãïŒ1 81.1.1.10-81.1.1.20 ã°ããŒãã«ïŒã¢ãŠãïŒ1 81.1.1.21
çºä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ã®ã¢ãã¬ã¹ã«å€æããå Žåã¯ãããŒã¯ãŒãã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠæç€ºçã«æå®ããå¿ èŠããããŸã
ã°ããŒãã«ïŒåºåïŒ1ã€ã³ã¿ãŒãã§ã€ã¹
åãçªå·ã®ã°ããŒãã«ã«ãŒã«ãè€æ°ããå Žåã¯ãNATãæåã«ïŒã¢ãã¬ã¹ããŒã«ã«ïŒå€æãããæ¬¡ã«PATãå¥ã®ã¢ãã¬ã¹ã«å€æãããæ¬¡ã«PATãã€ã³ã¿ãŒãã§ã€ã¹ã¢ãã¬ã¹ã«å€æãããŸãã åççãªçåãçããå¯èœæ§ããããŸãïŒããã¯ãã€ããã€ãæ¥ãã®ã§ããããïŒ ã¢ãã¬ã¹ããŒã«ã«ã€ããŠã¯ãæç¢ºã§ããããšãé¡ã£ãŠããŸããããŒã«å ã®ã¢ãã¬ã¹ã¯ãã€ãRATãããŒããã£ã¹ãå ã®ã¢ãã¬ã¹éã§äœ¿ãæããããŸããïŒ ããã§ããã®è³ªåã¯æ¬åœã«èµ·ãããŸãããïŒ ããŠãããäžåºŠèããŠãã ãã:)
ãã¹ãŠããŸãšããŠç¹°ãè¿ããŸããPATãããŒããã£ã¹ãã§äœ¿çšãããã¢ãã¬ã¹ãšäžè¬çãªã¢ãã¬ã¹ã«åãæ¿ããããå Žåããããã®å€ããååšããå¯èœæ§ããããŸããïŒ
ãããã®äž¡æ¹ã®è³ªåã«å¯Ÿããçãã¯1ã€ã ãã§ããRATã®åãã¢ãã¬ã¹ãžã®å€æã¯ãASAã§çŽ4,000ä»¶ããäºçŽãããŠããŸããã ãã®åŸãæ°ãããããŒããã£ã¹ãã¯äœæãããŸããã ã©ãããïŒ PATã«ã¯è€æ°ã®ã¢ãã¬ã¹ã䜿çšããŸãã ã€ãŸã åãæ°ã®ã°ããŒãã«ã®è€æ°è¡ã
åç¬ã§ç«ã€ã®ã¯ãçªå·0ã®natã«ãŒã«ã§ãããã®ã«ãŒã«ã¯ãå€åºãããšãã«ãããŒããã£ã¹ãããå¿ èŠããªããã®ãèšè¿°ããŸãã ãã®ã«ãŒã«ã¯ãå³å¯ãªNATå¶åŸ¡ã¢ãŒããæå¹ã«ãªã£ãŠããå Žåã«ç¹ã«å¿ èŠã§ãã ãã®ã«ãŒã«ã§ã¯ãã°ããŒãã«ãšããèšèã¯æ©èœããŸããã å®éããããã®ãã±ããã«ã€ããŠã¯ãã¢ãã¬ã¹ãããèªäœã«å€æããã«ãŒã«ãæå¹ã§ãããšæ³åã§ããŸãã
ãããã£ãŠãå éšåç倿ïŒNATããã³PATïŒã®ã«ãŒã«ã«ã€ããŠèª¬æããŸããã ã€ãŸã ãã±ããããå€éšãã«ç§»åãããšãçä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ã®natã«ãŒã«ã®ååšããã§ãã¯ãããããã«ã«ãŒã«ãããããã±ããããã®äžã«ããå Žåãçºä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ã§å¯Ÿå¿ããã°ããŒãã«ã«ãŒã«ãæ¢ããŸãã åæã«ãçºä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ã®ã»ãã¥ãªãã£ã¬ãã«ã¯çä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ã®ã»ãã¥ãªãã£ã¬ãã«ãããäœã
ASAã®ãå éšãã«å ¥ããã±ããã®éä¿¡å ã¢ãã¬ã¹ãåçã«å€æŽããå¿ èŠãããå Žåãã»ãã¥ãªãã£ã®é«ãã€ã³ã¿ãŒãã§ã€ã¹ã§ã°ããŒãã«ã«ãŒã«ãæ€çŽ¢ããå¿ èŠãããããšãæç€ºçã«ç€ºãå¿ èŠããããŸãã ããã¯ãnatã³ãã³ãã®outsideããŒã¯ãŒãã䜿çšããŠè¡ãããŸãïŒnat 0ã«ãŒã«ã«ãé©çšå¯èœïŒã
natïŒ{ã€ã³ã¿ãŒãã§ã€ã¹}ïŒïŒ{ãããã¯ãŒã¯} {ãã¹ã¯}å€
äŸïŒã€ã³ã¿ãŒãããããã®åŒã³åºãå ã®ãã¹ãŠã®å®éã®ã¢ãã¬ã¹ããé衚瀺ãã«ããŠãããããå éšã€ã³ã¿ãŒãã§ã€ã¹ã®ã¢ãã¬ã¹ã«çœ®ãæããããšããŸã
natïŒoutïŒ10 0 0å€ ã°ããŒãã«ïŒinsïŒ10ã€ã³ã¿ãŒãã§ã€ã¹
ã芧ã®ãšãããã³ãã³ã圢åŒã¯éåžžã«äŒŒãŠããŸãã ãšããã§ãäŸã«ç€ºãããŠãã倿ã¿ã€ãã¯ãæ®å¿µãªãããCiscoã«ãŒã¿ãŒïŒPATå€ïŒã§ã¯ãµããŒããããŠããŸãã
ã¢ãã¬ã¹å€æã®è¿œå ã®å¯èœæ§ã¯ããªãŒãã³TCPã»ãã·ã§ã³ã®æå€§æ°ãUDPã»ãã·ã§ã³ã®æå€§æ°ãããã³ããŒããªãŒãã³TCPã»ãã·ã§ã³ïŒèïŒã®æ°ãå¶éããèœåã§ãããã®åŸãDoSæ»æïŒèšå€§ãªæ°ã®ã»ãã·ã§ã³ãªãŒããã³ã°ãªã¯ãšã¹ãïŒã«å¯ŸããSYNãã©ããä¿è·æè¡ããªã³ã«ãªããŸãã ãã®æè¡ã¯SYN CookieãšåŒã°ããŸãã
natïŒ{interface}ïŒïŒ{network} {mask} tcp {max} {embryonic} udp {max}
0ãæå®ãããšãããã®ãã©ã¡ãŒã¿ãŒã远跡ããªããããšãæå³ããŸãã
ãããŠãããã¯ãã£ã«ã®è³ªåïŒ1ã€ã®ãããã¯ãŒã¯ã«ç§»åããå¥ã®ãããã¯ãŒã¯ã«ç§»åããå Žåãã©ã®ããã«1ã€ã®ããŒã«ã«å€æããŸããïŒ ãããŸã§ã®ãšãããå®å ãããã¯ãŒã¯ãåºæºãšããŠå ¥åãããå¯èœæ§ãããããšã¯ç¢ºèªããŠããŸããã
ãã®åé¡ã解決ããã«ã¯ãäžèšã®ã³ãã³ãã§ã¯äžååã§ãã ãããè¡ãã«ã¯ãããªã·ãŒNATã䜿çšããŸãïŒåè¿°ã®ãéåžžã®ãNATã¯ã¬ã®ã¥ã©ãŒãšåŒã°ããŸãïŒ
ãã ããäºåã«æãããªãã§ãã ãããããªã·ãŒNATã«ã¯è€éãªããšã¯ãããŸããããœãŒã¹ãããã¯ãŒã¯ãåºæºãšããŠæå®ããã ãã§ãªãããããŒããã£ã¹ããããã®ã ãã§ãªããèš±å¯ãšããåèªã§ç€ºãã¢ã¯ã»ã¹ãªã¹ããæå®ããå¿ èŠããããŸãã
ããšãã°ãPARTNERãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ãããšãã«ãLANãIPSPoolïŒ1ïŒã¢ãã¬ã¹ã«å€æããŸãã
ã¢ã¯ã»ã¹ãªã¹ãNATèš±å¯ip LANããŒãã㌠natïŒinsïŒ1ã¢ã¯ã»ã¹ãªã¹ãNAT ã°ããŒãã«ïŒåºåïŒ1 ISPPoolïŒ1ïŒ
ããªã·ãŒNATã§äœ¿çšãããã¢ã¯ã»ã¹ãªã¹ãã«ã¯å¶éããããŸãããã®äžã§æåŠè¡ã䜿çšããããšã¯ã§ããŸããã ã€ãŸã 翻蚳ãããã®ã¯ãã¹ãŠãèš±å¯è¡ã§æç€ºçã«èšè¿°ããå¿ èŠããããŸãã nat 0ã®ã¢ã¯ã»ã¹ãªã¹ãã«å¯ŸããŠã®ã¿äŸå€ãäœæãããŸããæåŠãªã¹ãã«ã¯ãæåŠæååãå«ãŸããå ŽåããããŸãã ãããŠããããã®è¡ã¯ãä»ã®å€æã«ãŒã«ãèŠãå¿ èŠãããããšãæå³ããŸã-çªç¶ã¢ãã¬ã¹ã¯çœ®æãå¿ èŠã§ãã
ããªã·ãŒNATã¯ãéåžžã®NATãããç¹æš©ããããŸãã
NATã«ãŒã«ãåŠçããé åºã¯è€éã§ãããç¥ã£ãŠããå¿ èŠããããŸãã ãããã£ãŠãéçãªãããŒããã£ã¹ãã«é¢ããéšåãåŸ ããã«ããããã®ã«ãŒã«ãåçåããããšããŸã
æåã®ã«ãŒã«ã¯åžžã«ããªã·ãŒNAT 0ã§ã
natïŒ{interface}ïŒ0ã¢ã¯ã»ã¹ãªã¹ã{NONAT}
次ã«ãéçãããŒããã£ã¹ãã®ãããã¯ããããŸãããããã«ã€ããŠã¯åŸã§æ±ããŸãã èŠããŠããã¹ãäž»ãªããšã¯ãéçãªãããŒããã£ã¹ãã¯åçãªãããŒããã£ã¹ããããç¹æš©ãããããšã§ã
ãã®åŸã«ããªã·ãŒNATã®å€æãç¶ããŸã
natïŒ{interface}ïŒïŒã¢ã¯ã»ã¹ãªã¹ã{ACL}
åæã«ãASAã¯ãããã®ã¢ã¯ã»ã¹ãªã¹ããéè€ããªãããã«ããŸãã
次ã«ãæé·äžèŽã«ãŒã«ãé©çšãããéåžžã®NATã«ãŒã«ããããŸãã ããã«ãNAT 0ã«ãŒã«ã®å Žåãåæ§ã§ãã
ããšãã°ããããã¯ãŒã¯10..1.1.0 / 24ããããŒããã£ã¹ãããã«ãã¢ãã¬ã¹10.1.1.1ã倿ããä»ã®ãã¹ãŠãä»ã®äœãã«å€æã§ããŸãã
natïŒinsïŒ0 10.1.1.0 255.255.255.0 natïŒinsïŒ1 10.1.1.1 255.255.255.255 natïŒinsïŒ2 0 0
ãã®éšåãä¿®æ£ããã«ã¯2ã€ã®å°ããªæŒç¿ïŒ
1.å€éšããASAã«ã¢ã¯ã»ã¹ã§ããŸãããã®èåŸã«ã¯ãããã©ã«ãã²ãŒããŠã§ã€ãæ£ããæ§æãããŠããªãïŒæ¬ èœããŠããïŒã³ã³ãã¥ãŒã¿ãŒãå éšã€ã³ã¿ãŒãã§ã€ã¹ã®èåŸã«æ¥ç¶ãããŠããŸãã ããã«å°éããå¿ èŠããããŸãïŒããšãã°ãããã«RDPãå«ãŸããŠããŸãïŒ
2.å®è¡ãããé åºã§å€æã«ãŒã«ãé 眮ããŸã
access-list NAT1 permit ip any host 198.133.219.25 ã¢ã¯ã»ã¹ãªã¹ãNAT1ã¯ããã¹ã216.255.83.40ãæåŠããŸãã ã°ããŒãã«ïŒåºåïŒ2 int ã°ããŒãã«ïŒåºåïŒ2 1.1.1.1-1.1.1.100 natïŒinsïŒ0 10.1.1.1 255.255.255.255 natïŒinsïŒ2 10.1.1.0 255.255.255.0 ã°ããŒãã«ïŒã¢ãŠãïŒ1 1.1.1.254 ã°ããŒãã«ïŒåºåïŒ1 1.1.1.101-1.1.1.110 natïŒinsïŒ1ã¢ã¯ã»ã¹ãªã¹ãNAT1
éçãªãããŒããã£ã¹ã ïŒç§ã責ããªãã§ãã ããïŒç¶ç¶ã®ã¿ãç¶ããŸãïŒ
Threat Friendsã¯ã転èŒã翻蚳ãåŸæ¥å¡ãšã®å ±åäœæ¥ã«äœ¿çšããéã«ãç§ãšwww.anticisco.ruãåç §ããŠãã ããïŒ ããããããäºæ¿ãã ãã:)
ã»ã«ã²ã€ã»ãã§ããããã€ã³ã¹ãã©ã¯ã¿ãŒ