ã¿ãªããããã«ã¡ã¯ïŒ
CISCOããŒã¿ã»ã³ã¿ãŒæ©åšãã¡ããª-CISCO ACEïŒApplication Control EngineïŒã«ã€ããŠå°ãã話ãããããšæããŸãã ãã®èšäºã§ã¯ãããã€ã¹ã®ç®çãã¢ãŒããã¯ãã£ãŒæ©èœãã¢ããªã±ãŒã·ã§ã³ã®å¯èœæ§ãåºæ¬æ©èœã®ã»ããã¢ãããªã©ã®åé¡ã«å¯ŸåŠããŸãã ãã®è³æã¯ããã现ããäœæ¥ãæäŸãããã®ã§ã¯ãããŸããããããããã®ãããªããã€ã¹ã®å®è£
ãæ€èšããéžæãè©Šã¿ããã®ãããªæ©åšããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æé©åã«åœ¹ç«ã¡ããµãŒãã¹ã®å®è£
ã®å¯çšæ§ãšæéãå¢ããæ¹æ³ãç解ããã人ã®ããã«èšèšãããŠããŸãã
人ã
ã¯ãããã®ããã€ã¹ãããã©ã³ãµãŒããã€ãŸãç¹å®ã®æ¡ä»¶ã«å¿ããŠè€æ°ã®ãµãŒããŒã«è² è·ãåæ£ã§ããããã€ã¹ãšåŒã³ãŸãã ã¹ã€ããã³ã°ã¯L4-L7ã¬ãã«ã§è¡ããããšèšããŸãã ããããããã¯ã³ã€ã³ã®çåŽã«ãããã補é æ¥è
èªèº«ãããŒã¿ã»ã³ã¿ãŒã§CISCO ACEã䜿çšãããšæ¬¡ã®ããšãã§ãããšè¿°ã¹ãŠããŸãã
â¢çç£æ§ã®åäžã
â¢ã¹ã±ãŒã©ããªãã£ã
â¢ãªãœãŒã¹ãæè»ã«åå²ãåœãŠãã
â¢æ°ããã¢ããªã±ãŒã·ã§ã³ãå°å
¥ããããã»ã¹ãç°¡çŽ åãã
â¢ã¢ããªã±ãŒã·ã§ã³ã®ããã©ãŒãã³ã¹ãæé©åãã
â¢å¯çšæ§ã確ä¿ãã
â¢ãªãœãŒã¹ãçµ±åãã
â¢ç®¡çæ§ãšç£èŠãæäŸããŸãã
ãããã®ããã€ã¹ã¯ãã¹ã¿ã³ãã¢ãã³æ©åšïŒCISCO ACE 4710ãªã©ïŒãšCISCO 6500/7600ã·ã£ãŒã·å
ã®ã¢ãžã¥ãŒã«ïŒCISCO ACE-20 / 30ã¢ãžã¥ãŒã«ïŒã®2ã€ã®ãã©ãŒã ãã¡ã¯ã¿ãŒã®åœ¢åŒã§è¡šç€ºãããŸãã ã¹ã¿ã³ãã¢ãã³æ©åšã¯ãä»»æã®ãã³ããŒã«åºã¥ããŠæ§ç¯ããããããã¯ãŒã¯ã«çµ±åã§ããåå¥ã®ããã€ã¹ã§ãããµãŒãã¹ã¢ãžã¥ãŒã«ã¯ããããã¯ãŒã¯å
ã®æ¢åã®6500/7600ã·ã£ãŒã·ãžã®ã€ã³ã¹ããŒã«ã«é©ããé«æ§èœããã€ã¹ã§ãããçç£æ§ã®åäžãéäžå¶åŸ¡ãã±ãŒãã«æ¥ç¶æ°ã®åæžãé«éåãå¯èœã«ããŸããµãŒãã¹ã®å°å
¥ã
ä»æ§ïŒ
CISCO ACE 4710ç¹åŸŽ | æ倧ã®ããã©ãŒãã³ã¹ãŸãã¯æ§æ |
ã¹ã«ãŒããã | 0.5ã1ã2ããŸãã¯4 Gbps |
å§çž® | 0.5ã1ããŸãã¯2 GbpsïŒGZIPãŸãã¯Deflateã䜿çšïŒ |
ä»®æ³ã³ã³ããã¹ã | 20 |
SSLã¹ã«ãŒããã | 1 gbps |
SSL TPS | 1024ãããããŒã䜿çšãã7500 SSL TPS |
SSL TPS | 1024ãããããŒã䜿çšãã7500 SSL TPS |
1ç§ãããã®æ倧L4æ¥ç¶ | 100,000ã®å®å
šãªãã©ã³ã¶ã¯ã·ã§ã³æç¶ç |
1ç§ãããã®æ倧L7æ¥ç¶ | 30,000å®å
šãã©ã³ã¶ã¯ã·ã§ã³æç¶ã¬ãŒã |
åææ¥ç¶ | 100äž |
ç®±ã®äžèº«ïŒIntel Pentium 4 3.4 Ghz CPUã4x1GEã8Gb RAMïŒå¢èšäžå¯ïŒã1Gb FlashïŒå¢èšäžå¯ïŒãã³ã³ãœãŒã«ããŒããã¢ãã¿ãŒæ¥ç¶çšããŒããããŒããŒãã CLIãSNMPãWEBã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠå¶åŸ¡ããæ©èœã ãã©ãŒã ãã¡ã¯ã¿ãŒ-1Uã
CISCO ACE-20 / 30ã¢ãžã¥ãŒã«ç¹åŸŽ | æ倧ã®ããã©ãŒãã³ã¹ãŸãã¯æ§æ |
ã¹ã«ãŒããã | 16 Gbps *ã8 Gbps *ãããã³4 Gbps |
åèšVLANïŒã¯ã©ã€ã¢ã³ããšãµãŒããŒïŒ | 4000 |
ãããŒã | ICMPãTCPãUDPããšã³ãŒããã£ã³ã¬ãŒãDNSãTelnetãFTPãHTTPãHTTPSãSMTPãPOP3ãIMAPãRTSPãRADIUSãSIPãSNMPãKAL-APãããã³TCLã¹ã¯ãªãã |
NATãšã³ã㪠| 100äž |
ä»®æ³ããŒãã£ã·ã§ã³ | æ倧250 *; åºæ¬äŸ¡æ Œã«å«ãŸãã5ã€ã®ä»®æ³ããŒãã£ã·ã§ã³ïŒããã€ã¹ïŒ |
SSLã¹ã«ãŒããã | 3.3 / 6 Gbps |
SSL TPS | åºæ¬äŸ¡æ Œã«å«ãŸãã1000 TPSãããã³ã©ã€ã»ã³ã¹äº€ä»ã§5000ã10,000ããŸãã¯15,000 TPSïŒ1024ãããããŒã§æ倧30,000ïŒ |
1ç§ãããã®æ倧L4æ¥ç¶ | 325,000 / 500,000å®å
šãã©ã³ã¶ã¯ã·ã§ã³æç¶ã¬ãŒã |
1ç§ãããã®æ倧L7æ¥ç¶ | 130,000 / 200,000å®å
šãã©ã³ã¶ã¯ã·ã§ã³æç¶ã¬ãŒã |
åææ¥ç¶ | 400äž |
ã¹ãã£ããããŒãã«ãšã³ã㪠| 400äž |
å
éšïŒ1Gbãã©ãã·ã¥ïŒå¢å äžå¯ïŒã3Gb RAMããŒã¿ãã¬ãŒã³ã1Gb RAMã³ã³ãããŒã«ãã¬ãŒã³ã
CISCO 6500/7600ã·ã£ãŒã·ã«æ倧4ã€ã®ã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããããšãã§ããããã«ãããã·ã£ãŒã·ãããæ倧64 Gbã®ããã©ãŒãã³ã¹ãåŸãããŸãã 4ã€ã®ã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããŠãã宣èšãããããã©ãŒãã³ã¹ãåãã1ã€ã®ãã©ã³ãµãŒãã·ã¹ãã ã«ååšããããšãæå³ããããã§ã¯ãªãããšã«æ³šæããŠãã ããã ããŒã±ãã£ã³ã°æ
åœè
ã¯ãã®ãããªæ°åãåŒçšããã®ã倧奜ãã§ãããåæ§ã«ã1ããŒã¹ã®CISCO ACE 4710ãåããäºãã®äžã«æšªããããçŽ æŽãããããã©ãŒãã³ã¹ãåŸãããšãã§ããŸãã ãšããã§ãããã€ã¹ã®äŸ¡æ Œã¯æ¬¡ã®ãšããã§ãã
æ§æ | äŸ¡æ Œ$ GPL |
ACE 4710 0.5 Gbps | 15.995 |
ACE 4710 1 Gbps | 29.995 |
ACE 4710 2 Gbps | 39.995 |
ACE 4710 4 Gbps | 49.995 |
4Gã1G Compã1K SSL TPSããã³5VCãåããACE30ã¢ãžã¥ãŒã« | 39.995 |
16Gã6G Compã30K SSL TPSããã³250VCãåããACE30ã¢ãžã¥ãŒã« | 109.995 |
äŸ¡æ Œãªã¹ãã«ã¯ãªãã¡ãŒãã»ãšãã©ãªããäŸ¡æ Œã¯å¿
èŠãªã³ã³ããã¹ãã®æ°ïŒããã«ã€ããŠã¯åŸã§èª¬æããŸãïŒãSSLã»ãã·ã§ã³ãªã©ã«ãã£ãŠå€§ããç°ãªããããããããã®äŸ¡æ ŒãäžããããŸãã
ç¹åŸŽããã§ã¯ããããã®ããªãå®äŸ¡ãªããã€ã¹ã§ã§ããããšã«ã€ããŠå°ã説æããŸãïŒãªã¹ãã¯å®å
šã§ã¯ãªããäž»ãªãã®ã ãã§ãïŒã
1.ã¢ããªã±ãŒã·ã§ã³ã®åãæ¿ããCISCO ACEã¯ãL4ããL7ã®æ
å ±ã«åºã¥ããŠãµãŒããŒã®è² è·åæ£ãæäŸããã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ã¹ã€ããã§ãã HTTPãFTPãDNSãã€ã³ã¿ãŒãããå¶åŸ¡ã¡ãã»ãŒãžãããã³ã«ïŒICMPïŒãã»ãã·ã§ã³éå§ãããã³ã«ïŒSIPïŒããªã¢ã«ã¿ã€ã ã¹ããªãŒãã³ã°ãããã³ã«ïŒRTSPïŒãæ¡åŒµRTSPãRADIUSãMicrosoftãªã¢ãŒããã¹ã¯ããããããã³ã«ã®çµã¿èŸŒã¿ãã€ãã£ããã£ãŒããµããŒãïŒæ±çšãããã³ã«è§£æïŒ ïŒRDPïŒã ã€ãŸãããããã®ãããã³ã«ã䜿çšããå Žåããã€ããŒãã®æ
å ±ã«åºã¥ããŠïŒå®éã«ïŒãã©ãã£ãã¯ã®ãã©ã³ã¹ãåãããšãã§ããŸãã
HTTPããããŒã®æäœïŒè¿œå ãåé€ãå€æŽãªã©ïŒãšåæ§ã«ãæ£èŠè¡šçŸã®ããã®æè»ãªã¡ã«ããºã ããããŸãã
2.ãã©ãã£ãã¯åŠçããã§ã«æããã«ãªã£ãŠããããã«ãACEã¯è©³çŽ°ãªãã±ããæ€æ»ãå®è¡ã§ããŸãããtcpdumpãããããã©ãã«ã·ã¥ãŒãã£ã³ã°ã«ç¹ã«åœ¹ç«ã¡ãŸãã
3.ã¢ãã¬ã¹å€æããœãŒã¹NATãå®å
NATãããã³éçNATãå®è£
ã§ããŸãïŒãã ããããã¯ãµãŒããŒãã¡ãŒã ã«1ã€ã®ãµãŒããŒãããå Žåã®åã®2ã€ã®ã¿ã€ãã®å¯äœçšã§ãããããã«ã€ããŠã¯åŸã§è©³ãã説æããŸãïŒã
4.ãã©ã³ã¹ãåãæ¹æ³ããµãŒããŒãã¡ãŒã å
ã®ãµãŒããŒãžã®ãã©ãã£ãã¯ã®ãã©ã³ã¹ããšãããã«ãã¢ããªã±ãŒã·ã§ã³/ãµãŒãã¹ã®å¯çšæ§ãå€æããããã®äžé£ã®ãã¹ããå®è¡ãããŸãã ãããã£ãŠã次ã®ãµãŒããŒã§ãã©ã³ã¹ãåãããšãã§ããŸãã ãã©ã¡ãŒã¿ãŒïŒæå°è² è·ïŒæ¥ç¶æ°ãŸãã¯ãµãŒããŒãžã®ãã©ãã£ãã¯éïŒãã©ã³ãã ïŒããã§ã¯ããµãŒããŒãã¡ãŒã å
ã®åãµãŒããŒã«ä¿æ°-éã¿ãå²ãåœãŠãããŸããç¹å®ã®ãµãŒããŒã«ãªã¯ãšã¹ããéä¿¡ãã確çã¯ãéã¿ã®åèšã«å¯Ÿããèªèº«ã®éã¿ã®æ¯çãšããŠå®çŸ©ãããŸãïŒãããã£ãŠããã¹ãŠã®ãµãŒããŒã®éã¿ïŒçžå¯Ÿå€ïŒãåãå Žåããã©ã³ã¹ã¯åäžã«ãªããŸãïŒãã¢ãã¬ã¹ããã®ããã·ã¥ãCookieããã®ããã·ã¥ããããã³ã«ããããŒããã®ããã·ã¥ãURLãå«ãããã·ã¥ãå®çŸ©ããŸãã CookieãŸãã¯SSLã䜿çšããå Žåãããã€ã¹ã¯ç¹å®ã®ãŠãŒã¶ãŒãç¹å®ã®ãµãŒããŒã«ãã€ã³ãããŠãã»ãã·ã§ã³ã®ç¶ç¶æ§ã確ä¿ããŸãã
5.ãµãŒãã¹/ã¢ããªã±ãŒã·ã§ã³ã®å¯çšæ§ã決å®ãã ïŒãããã©ã®ããã«æ§æãããŠããããåŸã§äŸã瀺ããŸãïŒïŒICMPãTCPãUDPãECHO {tcp | udp}ããã£ã³ã¬ãŒãHTTPãHTTPSãFTPãTelnetãDNSãSMTPãIMAPãPOPãRADIUSãã¹ã¯ãªãããããŒãã¢ã©ã€ãã¢ãã©ã€ã¢ã³ã¹ãããã³ã«ïŒKAL-APïŒãRTSPãSIPãHTTPãªã¿ãŒã³ã³ãŒã解æãSNMPã ãŸããïŒããšãã°ïŒHTTPãããŒãã䜿çšãããšãå¿çãåä¿¡ããããšã§ã¢ã¯ã»ã·ããªãã£ã決å®ãããã ãã§ãªããå¿
èŠãªå¿çã³ãŒãïŒãŸãã¯ãã®ç¯å²ïŒãHTTPå¿çã®ããããŒã®å¿
èŠãªå€ãå¿çæéãªã©ãæå®ããããšãã§ããŸãã ãµã³ãã«ãäœæãããšãããªã¯ãšã¹ããããããŒãžãããããŒå€ãªã©ã決å®ããŸãã ã¡ã«ããºã ã¯éåžžã«æè»ã§ãã
6.ãã©ãŒã«ããã¬ã©ã³ã¹ã ãã©ãŒã«ããã¬ã©ã³ã¹ã¯ãåãã·ã£ãŒã·å
ã§è¿œå ã®ã¢ãžã¥ãŒã«/ããã€ã¹ã䜿çšããããã¢ã¯ãã£ã/ã¢ã¯ãã£ããã¢ã¯ãã£ã/ã¹ã¿ã³ãã€ã¢ãŒãã§å°ççã«åé¢ããããšã§å®çŸãããŸãã CISCO VSSã䜿çšãããšãã·ã£ãŒã·å
ã®äž¡æ¹ã®ã¢ãžã¥ãŒã«ã1ã€ã®ä»®æ³ããã€ã¹ã«ä»®æ³åã§ããŸãã
7.ã¢ããªã±ãŒã·ã§ã³ã®é«éåã ããã€ã¹ã¯ãããã¯ãŒã¯ããã©ãŒãã³ã¹ãæ¹åããããã«TCP / UDPã»ãã·ã§ã³ãå€éåããŸãã
8. SSLã¢ã¯ã»ã©ã¬ãŒã·ã§ã³ã ACEã«ã¯ããŒããŠã§ã¢SSLã¢ã¯ã»ã©ã¬ãŒã¿ãçµã¿èŸŒãŸããŠãããããã€ã¹äžã®ã»ãã·ã§ã³ãçµäºã§ããããããµãŒããŒã®è² è·ã軜æžãããŸãã æäœã«ã¯ãSSLçµäºãSSLéå§ããšã³ãããŒãšã³ãSSLïŒçµäº+éå§ïŒã®3ã€ã®ã¢ãŒãããããŸãã SSLçµäº-ã»ãã·ã§ã³ã¯CISCO ACEã§çµäºãããã©ã³ãµãŒãããµãŒããŒãžã®ãã©ãã£ãã¯ã¯ã¯ãªã¢ã«ãªããŸãã ãµãŒããŒã¯ãã©ã³ãµãŒã«å¿çãããã©ã³ãµãŒã¯ããŒã¿ãæå·åããŠã¯ã©ã€ã¢ã³ãã«éãè¿ããŸãã 1ã€ã®èå³æ·±ãæ©èœã«æ³šæããå¿
èŠããããŸãããã©ã³ãµãŒã¯ãã©ãã£ãã¯ã解èªããŸãããå®å
ããŒãïŒTCPïŒã¯å€æŽããŸãããã€ãŸãããµãŒããŒäžã®WEBãµãŒããŒã¯80ã®ä»£ããã«ããŒã443ããªãã¹ã³ããå¿
èŠããããŸãã
SSLéå§-ã¯ã©ã€ã¢ã³ããããã©ã³ãµãŒãžã®ãã©ãã£ãã¯ã¯ã¯ãªã¢ã«ãªãããã©ã³ãµãŒã¯ãµãŒããŒãšã®SSLã»ãã·ã§ã³ã確ç«ããSSLã䜿çšããŠãµãŒããŒãšéä¿¡ããŸãã ã¯ã©ã€ã¢ã³ããžã®éå£éšã¯ãæå·åãããŠããªã圢åŒã§éä¿¡ãããŸãã
3çªç®ã®ã¢ãŒãã§ã¯ãã¯ã©ã€ã¢ã³ãã¯ãã©ã³ãµãŒãšã®1ã€ã®ã»ãã·ã§ã³ã確ç«ããããªã¥ãŒã ã¯ãµãŒããŒãšã®å¥ã®ã»ãã·ã§ã³ã確ç«ããŸãã äºéæå·åãçºçããŸãïŒæå·åãããæå·åã§ã¯ãªãã以åã«åŸ©å·åãããæå·åã®åæå·åãæå³ããŸãïŒã
9.ã»ãã¥ãªãã£æ©èœ
ïŒ ACLïŒL3-L7ïŒãåæ¹åNATããã³PATïŒ+ããªã·ãŒNATïŒãTCPæ¥ç¶ç¶æ
远跡ãUDPã®ä»®æ³æ¥ç¶ç¶æ
ãã·ãŒã±ã³ã¹çªå·ã®ã©ã³ãã åãTCPããããŒæ€èšŒãTCPãŠã£ã³ããŠãµã€ãºãã§ãã¯ããŠããã£ã¹ããªããŒã¹ãã§ãã¯ã»ãã·ã§ã³ã®ç¢ºç«æã®ãã¹è»¢éïŒURPFïŒãã¬ãŒãå¶éã
10.ä»®æ³åæ©èœãããã€ã¹ã¯å¯äžã®ããã€ã¹ãšããŠæ©èœããŸãããåžžã«æè»ã§ãããšã¯éããŸããã ãŸãã¯ã1ã€ã®ç©çããã€ã¹ããæ倧250ã®ä»®æ³ãã©ã³ãµãŒãäœæã§ããŸãã ãã®ãããªåãã©ã³ãµãŒã«ã¯ãç¬èªã®ç®¡çè
ãç¬èªã®æ§æãç¬èªã®ã«ãŒã«ãããã³äœ¿çšããããªãœãŒã¹ïŒCPUãæ¥ç¶ã垯åå¹
ïŒã®å¶éããããŸãã èªåã®ããŒãºã«éåžžã«é©ããŠããã ãã§ãªããå°çšã®ACEãµãŒãã¹ã顧客ã«æäŸããããšãã§ããŸããããã§ã¯ãããã€ã¹å
ã§äœã§ãããããããšãã§ããŸãã
11.åäœã¢ãŒã ïŒã«ãŒãããã¢ãŒããããªããžã¢ãŒããé察称ãµãŒããŒæ£èŠåïŒASNïŒã ã«ãŒã¿ãŒã¢ãŒãã§ã¯ãã€ã³ã©ã€ã³ãšãªã³ã¹ãã£ãã¯ïŒãŸãã¯ã¯ã³ã¢ãŒã ã¢ãŒãïŒã®2ã€ã®ãµãã¢ãŒããåºå¥ã§ããŸãã
ããªããžã¢ãŒãããã€ã¹ã¯ããµãŒããŒãšãµãŒããŒã®ããã©ã«ãã²ãŒããŠã§ã€ã®éã®ãã®ã£ãããã«ãããŸãã L2ïŒããªããžïŒã¢ãŒãã®åããµããããäžã®äž¡æ¹ã®ããã€ã¹ã€ã³ã¿ãŒãã§ã€ã¹ã åææ¡ä»¶ã¯ãCISCO ACEãçµç±ããªããµãŒããŒãšã«ãŒã¿ãŒéã®ãã©ãã£ãã¯ã®äžè¶³ã§ãã ãããã£ãŠãã¯ã©ã€ã¢ã³ãã¯VIP 172.16.3.100ïŒä»®æ³IP-ãã©ã³ãµãŒã®ä»®æ³ã¢ãã¬ã¹ãããã«å°çãããã©ãã£ãã¯ïŒVIPïŒã¯ãµãŒããŒéã§åæ£ãããŸãïŒã«ã¢ã¯ã»ã¹ããããã€ã¹ã¯ãªã¯ãšã¹ãããµãŒããŒã«ãªãã€ã¬ã¯ãããå®å
ã¢ãã¬ã¹ãå€æŽããŸãã ãµãŒããŒã¯172.16.3.1ã«å¿çãéä¿¡ããŸããããã©ãã£ãã¯ãACEãééãããšïŒãããŠããããå¿
é ã§ãããšèšããŸããïŒããœãŒã¹ã¢ãã¬ã¹ã¯172.15.3.100ã«æ»ããŸãã
ãã®ãœãªã¥ãŒã·ã§ã³ã¯ãæ¢åã®ãããã¯ãŒã¯ã§ã®CISCO ACEã®å®è£
ã«é©ããŠããŸããã¢ãã¬ã¹æå®ã¯å€æŽãããããµãŒããŒã®åæ§æã¯å®è¡ãããŸããã
ã«ãŒãããã€ã³ã©ã€ã³ã¢ãŒããã®ã¢ãŒãã§ã¯ãCISCO ACEã¯ãã©ãã£ãã¯ãæž¡ãããã®ããããå®è¡ããŸãã ãã®ã¢ãŒãã¯ãæ°èŠã€ã³ã¹ããŒã«ã«é©ããŠããŸãã ãã©ã³ãµãŒã¯ãµãŒããŒã®ããã©ã«ãã²ãŒããŠã§ã€ã§ãã ãã®ã¢ãŒãã§ã¯ãããã«è©³ãã説æãããã©ã³ã¹ãåãããã®äžè¬çãªæ§æã瀺ããŸãã
ã«ãŒãããã¢ãŒãOn-a-stickïŒã¯ã³ã¢ãŒã ã¢ãŒãïŒãŠãŒã¶ãŒããã®ãã©ãã£ãã¯ã¯ãã©ã³ãµãŒïŒVIPïŒã«å°éããŸãã ã¯ã©ã€ã¢ã³ãã¢ãã¬ã¹ã¯ãç¬èªã®ãã©ã³ãµãŒã¢ãã¬ã¹ãå®å
ã¢ãã¬ã¹ã¯å®éã®ãµãŒããŒã¢ãã¬ã¹ïŒãŸãã¯å®éã®ãµãŒããŒã¢ãã¬ã¹ã®1ã€ïŒã«çœ®ãæããããŸãã ãã®å ŽåããµãŒããŒã¯ãã©ã³ãµãŒã«çŽæ¥å¿çããæé ã¯éã®é åºã§ç¹°ãè¿ãããŸãããœãŒã¹ã¢ãã¬ã¹ãVIPã«å€æŽãããå®å
ã¢ãã¬ã¹ãã¯ã©ã€ã¢ã³ãã¢ãã¬ã¹ã«å€æŽãããŸãã ã¯ã©ã€ã¢ã³ãã¯ã¢ãã¬ã¹ïŒVIPïŒã䜿çšããŠãµãŒããŒãšéä¿¡ããå°è±¡ãæã£ãŠããŸãããå®éã«ã¯ãµãŒããŒã¯äžçäžã«é
眮ã§ããŸãã
ã¯ã©ã€ã¢ã³ãããã©ã³ã¹ãµãŒãã¹ãååŸãããå Žåã«é©ãããªãã·ã§ã³ã§ãã ããšãã°ãã¯ã©ã€ã¢ã³ãã«ã¯ãç°ãªãDCã«3ã€ã®WEBãµãŒããŒããããŸãã ç§ãã¡ããã圌ã¯ãã©ã³ãµãŒã®å®éã®IPã¢ãã¬ã¹âVIPãåãåããŸãã èšå®ã§ã¯ãDNSã¯ãã®ãã¡ã€ã³ãå°çšã®VIPã«ãã€ã³ãããŸãã ããã§ãã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒããã·ã£ã€ãã³ã°ãããããµãŒããŒãè¿œå ãŸãã¯åé€ããã ãã§ãªããã¯ã©ã€ã¢ã³ãã¯åŒãç¶ããµãŒãã¹ãåããŸãã
ã«ãŒãããã¢ãŒãã®é察称ãµãŒããŒã®æ£èŠåã¢ãŒãã¯ä»¥åã®ã¢ãŒããšéåžžã«äŒŒãŠããŸãããã®å ŽåããµãŒããŒã¯ã¯ã©ã€ã¢ã³ãã«çŽæ¥å¿çããCISCO ACEããã€ãã¹ããŸãã
èšå®äŸãæ€èšããŠãã ããå€ãã®ãªãã·ã§ã³ã説æããã«åºæ¬çãªäŸãæ€èšããããšæããŸããããã¯ç·æ¥ã®å¿
èŠããªãããïŒè¯ãè³æãžã®ãªã³ã¯ãæäŸããŸãïŒãå¿
èŠã«å¿ããŠãäžæãªç¹ãã³ã¡ã³ããŸãã¯èª¬æããæ¹ãè¯ãã§ãã
ããããžãŒãšããŠãç§ãã¡ã¯ã飯ãåããŸãã ã«ãŒãããã€ã³ã©ã€ã³ã¢ãŒãã
管çã€ã³ã¿ãŒãã§ã€ã¹172.16.1.5ã
å¶åŸ¡ããªã·ãŒã®ã«ãŒã«ãæžããŸãããã
class-map type management match-any L4_REMOTE-ACCESS_CLASS
description Enabling remote access traffic to the ACE and the Cisco ACE Module
2 match protocol ssh source-address 172.16.1.0 255.255.255.0
3 match protocol icmp source-address 172.16.1.0 255.255.255.0
4 match protocol https source-address 172.16.1.0 255.255.255.0
5 match protocol snmp source-address 172.16.1.0 255.255.255.0
policy-map type management first-match L4_REMOTE-ACCESS_MATCH
class L4_REMOTE-ACCESS_CLASS
permit
interface vlan 20
ip address 172.16.1.5 255.255.255.0
service-policy input L4_REMOTE-ACCESS_MATCH
ãããã¯ãŒã¯172.16.1.0/24ãããSSHãSNMPãHTTPSãICMPãããã³ã«ã䜿çšããŠããã€ã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã
ãµãŒããŒãã¡ãŒã ã«3å°ã®ãµãŒããŒãããããã®äžã§è² è·ãåæ£ããŸãã ãµãŒããŒã宣èšããŸãã
rserver host SERVER-1
description SERVER-1
ip address 192.168.1.11
inservice
rserver host SERVER-2
description SERVER-2
ip address 192.168.1.12
inservice
rserver host SERVER-3
description SERVER-3
ip address 192.168.1.13
inservice
ãµãŒããŒããã¡ãŒã ã«çµ±åããŸãïŒãµã³ãã«ã§ã¯ãââHTTPãšICMPã䜿çšããŸãïŒã
serverfarm host FARM
probe HTTP_PROBE
probe ICMP_PROBE
rserver SERVER-1
inservice
rserver SERVER-2
inservice
rserver SERVER-3
inservice
ãµã³ãã«ã®èª¬æïŒ
probe http HTTP_PROBE
interval 5
passdetect interval 10
passdetect count 2
request method head url /index.html
expect status 200 210
header User-Agent header-value "LoadBalance"
probe icmp ICMP_PROBE
interval 10
passdetect interval 60
passdetect count 4
receive 1
interval-ãµã³ãã«éã®éé
receive-å¿çã¿ã€ã ã¢ãŠã
passdetectã«ãŠã³ã-ããŸãå€ãã®åçãåãåããªãå ŽåããµãŒããŒã¯å©çšäžå¯ãšèŠãªãããŸã
passdetect interval-䜿çšã§ããªããµãŒããŒã®ãµã³ãã«éé
ãã©ã³ã¹ããªã·ãŒã«ã€ããŠèª¬æããŸãã
ä»®æ³IPã¢ãã¬ã¹ïŒããŒã80ã§ã®ã¿ãªã¯ãšã¹ããåãä»ããŸãïŒïŒ
class-map match-all FARM-VIP
2 match virtual-address 172.16.1.100 any eq www
ãã¡ãŒã ãžã®ãã©ãã£ãã¯ã®ãã©ã³ã¹ãåããŸããã€ãŸãããã©ã³ã¹ããªã·ãŒã説æããŸãã
policy-map type loadbalance http first-match FARM_POLICY
class class-default
serverfarm FARM
HTTPãã©ã³ã·ã³ã°ã®ã¿ã€ããèšå®ããªãå ŽåïŒããã¯å¿
èŠãããŸããïŒãHTTPãããã³ã«ã䜿çšãããšãããšãã°Cookieã§åé¡ãçºçããå¯èœæ§ããããŸãã ãã®ãã©ã¡ãŒã¿ã¯ãå°æ¥ã®ãã©ãã£ãã¯ãšåŠçæ©èœã®ã¿ã€ãã決å®ããŸãã ããã¹ã±ãããã®åé¡ïŒ
ããã¯ãFARM_POLICYããªã·ãŒãå²ãåœãŠãããHTTPãã©ãã£ãã¯ãFARMãã¡ãŒã ã«ã«ãŒãã£ã³ã°ãããããšãæå³ããŸãã
次ã«ãäžèšãçµã¿åãããããªã·ãŒãäœæããŸãã
policy-map multi-match WWW-PM
class FARM-VIP
loadbalance vip inservice
loadbalance policy FARM_POLICY
loadbalance vip icmp-reply active
ãã®ããªã·ãŒã¯ãå
¥åïŒå€éšïŒã€ã³ã¿ãŒãã§ãŒã¹ã«é©çšã§ããŸãã
interface vlan 20
service-policy input WWW-PM
ããã¯ããŸããã¢ãã¬ã¹172.16.1.100ãèŠæ±ãããšãã«ãã©ã³ãµãŒãMACãæäŸããããšãæå³ããŸãã ããã«ããã©ãã£ãã¯ãã¢ãã¬ã¹172.16.1.100ïŒclass-map match-all FARM-VIPïŒã®ããŒã80ã«åããå Žåãèšè¿°ããããã©ã³ã·ã³ã°ã«ãŒã«ïŒloadbalance policy FARM_POLICYïŒãã€ãŸããã¹ãŠïŒclass class-default ïŒFARMãã¡ãŒã ïŒserverfarm FARMïŒã«éä¿¡ããŸãã CISCO ACEã¯ããã®ã¢ãã¬ã¹ãžã®pingã«ãå¿çããŸãïŒloadbalance vip icmp-reply activeïŒã
ãµãŒããŒã®å¿çãäžè¬ã«æ£ããã¢ãã¬ã¹ã§ã¯ã©ã€ã¢ã³ãã«å±ãããã«ããã«ã¯ãå
éšãµãŒããŒã¢ãã¬ã¹ããå€éšVIPã¢ãã¬ã¹ãžã®å€æãäœæããå¿
èŠããããŸãã
ãŸãããã¹ãŠã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ããã¹ãŠãèš±å¯ããACLãè¿œå ããŸãã ä»ã®å Žæã§ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããŠããããšãæå³ããŸãã CISCO ACEã¯ããã©ã«ãã§ãã¹ãŠã®ãã©ãã£ãã¯ããããã¯ããŸãã
access-list PERMIT-ANY line 8 extended permit ip any any
access-list NAT line 1 extended permit ip host 192.168.1.11 any
access-list NAT line 2 extended permit ip host 192.168.1.12 any
access-list NAT line 3 extended permit ip host 192.168.1.13 any
class-map match-any PAT-ClassMap
2 match access-list NAT
policy-map multi-match NAT-PM
class PAT-ClassMap
nat dynamic 1 vlan 20
interface vlan 20
access-group input PERMIT-ANY
nat-pool 1 172.16.1.100 172.16.1.100 netmask 255.255.255.255 pat
interface vlan 40
ip address 192.168.1.1 255.255.255.0
access-group input PERMIT-ANY
service-policy input NAT-PM
FWSMïŒASAãPIXïŒã§ã¯ãNATã¯æ°åç°¡åã«æ§æãããŸãã
å°ããªã¿ããïŒããã©ã«ãã«ãŒããSNMPïŒïŒ
ip route 0.0.0.0 0.0.0.0 172.16.1.1
snmp-server community xxx group Network-Monitor
snmp-server user user_name Network-Monitor auth sha p@ssword localizedkey
snmp-server host 172.16.1.2 traps version 2 xxx
ãªã³ã¯ïŒhttp://pastebin.com/DV4QM2YaïŒãã¯ãªãã¯ããŠãå®å
šãªæ§æãèŠã€ããŸãã æ©èœãå®èšŒããããã«ãCISCO ACEã«ã¯ãŠãŒã¶ãŒãããã¯ãŒã¯ãžã®ã€ã³ã¿ãŒãã§ã€ã¹ããããŸãã ãŠãŒã¶ãŒã«å¯ŸããŠã¯ãPATã®æ©èœãå®è¡ããFTPãããã³ã«ãæ€æ»ããŠããã®ãããã³ã«ã«åé¡ããªãããã«ããŸãïŒã¢ã¯ãã£ã/ããã·ãã¢ãŒãïŒãåãåã£ããã®ã®ç£èŠïŒããŒã¹ïŒïŒ
ACE # show serverfarm FARM
serverfarm : FARM, type: HOST
total rservers : 2
---------------------------------
----------connections-----------
real weight state current total failures
---+---------------------+------+------------+----------+----------+---------
rserver: SERVER-1
192.168.1.11:0 8 OPERATIONAL 44 52841950 12274606
rserver: SERVER-2
192.168.1.11:0 8 OPERATIONAL 49 51043947 13091531
ACE-MEL/Admin# show serverfarm FARM detail
serverfarm : FARM, type: HOST
total rservers : 2
active rservers: 2
description : -
state : ACTIVE
predictor : ROUNDROBIN
failaction : -
back-inservice : 0
partial-threshold : 0
num times failover : 0
num times back inservice : 0
total conn-dropcount : 44
Probe(s) :
HTTP_PROBE, type = HTTP
ICMP_PROBE, type = ICMP
---------------------------------
----------connections-----------
real weight state current total failures
---+---------------------+------+------------+----------+----------+---------
rserver: SERVER-1
192.168.1.11:0 8 OPERATIONAL 44 52841981 12274606
description : -
max-conns : - , out-of-rotation count : -
min-conns : -
conn-rate-limit : - , out-of-rotation count : -
bandwidth-rate-limit : - , out-of-rotation count : -
retcode out-of-rotation count : -
load value : 0
rserver: SERVER-1
192.168.1.11:0 8 OPERATIONAL 49 51043976 13091532
description : -
max-conns : - , out-of-rotation count : -
min-conns : -
conn-rate-limit : - , out-of-rotation count : -
bandwidth-rate-limit : - , out-of-rotation count : -
retcode out-of-rotation count : -
load value : 0
ACE # show rserver SERVER-1
rserver : SERVER-1, type: HOST
state : OPERATIONAL (verified by arp response)
---------------------------------
----------connections-----------
real weight state current total
---+---------------------+------+------------+----------+--------------------
serverfarm: FARM
192.168.1.11:0 8 OPERATIONAL 13 1288706
ãããŠãããã«å€ãã®ããŒã ã
ãŸãšãããšãã®èšäºã§ã¯ãCISCOããã ãã§ãªããäžè¬çã«ããŒã¿ã»ã³ã¿ãŒã€ã³ãã©ã¹ãã©ã¯ãã£ã®ããªãéèŠãªéšåãšããŠãã©ã³ãµãŒã䜿çšããŠãèªè
ã«ãã®æ©åšãå°ã玹ä»ãããã£ãã®ã§ãã ç§ã®é ã®äžã§å€ãã®æ
å ±ãåã£ãŠããŸããããã®æçš¿ã¯ããã»ã©å°ããã¯ãªãããã§ãã
ãã®ããããã®ãããªããã€ã¹ã®äž»ãªç®çã¯ããµãŒãã¹éã®è² è·åæ£ïŒå¯çšæ§ã®åäžãããã©ãŒãã³ã¹ã®åäžããªãœãŒã¹ã®çµ±åïŒããµãŒããŒããããŒããŠã§ã¢ã¢ã¯ã»ã©ã¬ãŒã¿ãžã®SSLçµäºæ©èœã®è»¢éãã»ãã¥ãªãã£ã®æ¹åïŒæ£èŠåããã³ãã®ä»ã®ç¬èªæè¡ã®ãããïŒãTCP /ã¢ã¯ã»ã©ã¬ãŒã·ã§ã³ã§ãUDPïŒå€éåãå§çž®ã«ããïŒã
ãŸãã1ã€ã®ããŒã¿ã»ã³ã¿ãŒã®éè·¯ã ãã§ãªããå°ççã«é¢ãããµãŒãã¹éã§ãã©ã³ã¹ãåãå¯èœæ§ã泚ç®ã«å€ããŸãã
ACE20-MOD-K9 4Gbpsã¢ãžã¥ãŒã«ã䜿çšããŸãã ãã¡ããããã¹ãŠã®4Gbpsã§ããŒããããããã§ã¯ãããŸããããã¿ã¹ã¯ãå®è¡ããŸãã æäœäžãåé¡ã¯ãããŸããã§ãã;ããã¯éåžžã«ãã確ç«ãããŠããŸãã ãªãç§ã¯ããã«ã€ããŠæžãå§ããã®ã§ããã å®éãç¹ã«ãªãœãŒã¹etherealmind.comã§ãCISCO ACEã«å¯Ÿããè¯å®çãªã¬ãã¥ãŒãèããããšã¯ãããŸããã ãŸãã¯ãäœãæžããªãã§ãã ããã ã»ãšãã©ã®å ŽåãããªãŒãºãIOSãã®ãŒãäžå®å®æ§ã«ã€ããŠäžå¹³ãèšããŸãã ACEãåããCISCOã¯ãä»ã®è£œåãããå
ãè¡ã£ãŠããããã§ã¯ãããŸããã ãšã³ãžãã¢ã¯F5ã®è£œåãéåžžã«åŒ·ãè³è³ããåæã«åäŸã®äŸ¡æ Œããã¯ã»ã©é ãããšã«æ³šç®ããŠããŸãã ç§ã¯ãã®æ©åšã«ééããããšã¯ãããŸããããäžè¬çã«ãç§ãã¡ã®å°åã§ã¯çãããã®ã§ããããã®ãããªæ©åšãèŠãããšã¯ãããŸããã
èªè
ãäœãããã£ãšè©³ããç¥ããããšããé¡æãæã£ãŠãããªããç§ã¯å©ããããšããããå¥ã®ã¡ã¢ãæžããŸãã
ç§ã¯ãåæ§ã®æ©åšã§åãã/åããŠãã人ã
ã®ã³ã¡ã³ããšæèŠãæ¬åœã«æ¥œãã¿ã«ããŠããŸãã å®éããã®ãããã¯ã¯å®éã«ã¯Habréã«ã¯è§ŠããŠããŸããã§ããã
CIS ACEã ããŒã2ïŒãªã¢ãŒããµãŒããŒãšã¢ããªã±ãŒã·ã§ã³ã®ãã©ã³ã¹ããšããœãŒã¹ïŒ1. CISCOããã¥ã¡ã³ããcisco.comã
2. vivekganapathi.blogspot.com/2010/07/cisco-ace-4710-load-balancer.html3.www.packetslave.com/2010/01/24/cisco-ace-basic-http-load-balancing4. docwiki.cisco.com/wiki/Cisco_Application_Control_Engine_ïŒACEïŒ_Configuration_Examples
5.
etherealmind.com/cisco-ace-load-balance-stick-source-nat-part-16.
etherealmind.com/cisco-ace-load-balance-stick-source-nat-part-27.
etherealmind.com/cisco-ace-load-balance-stick-source-nat-part-38.
etherealmind.com/cisco-ace-fwsm-resource-allocation-for-virtualization9.
www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809c3041.shtml