ã¯ããã«ããŸãã¯ãªãWCCPã«é¢ããå¥ã®èšäºãå¿
èŠãªã®ã§ããïŒ
ããã«é¢ããåªããèšäºãå«ããWCCPãããã³ã«ã䜿çšããWebãã©ãã£ãã¯ã®ééçãªãã£ãã·ã³ã°ã®çµç¹ã«ã€ããŠå€ãã®ããšãæžãããŠããŸãã éåžžããããã®èšäºã§ã¯ãå·Šã®å³ã«ç€ºãããŠãããã®ãšåæ§ã®ã¹ããŒã ãèæ
®ãããŸãã

äžèŠãããšããããã®ãœãªã¥ãŒã·ã§ã³ã«ã¯ç¢ºããªå©ç¹ããããŸããå®è£
ã¯ç°¡åã§ããã£ãã·ã¥ã¯ãŠãŒã¶ãŒã«å¯ŸããŠå®å
šã«ééçã§ãããããã·ãµãŒããŒã«é害ãçºçãããšããªã¯ãšã¹ãã¯èªåçã«çŽæ¥ãªãã€ã¬ã¯ããããŸãã
ããããWCCPã¯åžžã«ã¹ã ãŒãºã«é²ãã§ããŸããïŒ ããã§ãªãå Žåãæ°ããªåé¡ã«å¯ŸåŠããæ¹æ³ã¯ïŒ
ããšãã°ãã»ãšãã©ãã¹ãŠã®èšäºã§ããã£ãã·ã¥ãµãŒããŒã¯ãŠãŒã¶ãŒãšåãã»ã°ã¡ã³ãã«ååšããå¿
èŠããããšèšèŒãããŠããŸããããã®çç±ã¯æèšãããŠããŸããã ããããã»ãã¥ãªãã£ããªã·ãŒã§ããã¹ãŠã®ãµãŒããŒãå¢çãããã¯ãŒã¯å
ã«ããããã¡ã€ã¢ãŠã©ãŒã«ã§ä¿è·ãããŠããå¿
èŠãããå Žåã¯ã©ãã§ããããã
æè¿ãéä¿¡äºæ¥è
ã®ãããã¯ãŒã¯ã«ãã£ãã·ã³ã°ãµãŒããŒãã€ã³ã¹ããŒã«ãããšãã«ãåæ§ã®èŠä»¶ã«å¯ŸåŠããå¿
èŠããããŸããããã®ç°¡ç¥å³ãå³åŽã®ã¿ã€ãã«ç»åã«ç€ºãããŠããŸãã
èªè
ããã®ãããªã¹ããŒã ãå®è£
ãããšãã«ééããåé¡ãããã³å¶éãåé¿ããæ¹æ³ã«èå³ãããå Žåã¯ãæè¿ããŸãã
çè«-æšæºããã³å®è£
æ©èœ
ãŸããå°ãã®çè«ã
WCCPãããã³ã«ã¯ãïŒWebã ãã§ãªãïŒãã©ãã£ãã¯ããªã¢ã«ã¿ã€ã ã§ãªãã€ã¬ã¯ãããããã«èšèšãããŠããŸãã ãããã³ã«ã¯ããšããšã·ã¹ã³ã«ãã£ãŠéçºããããã®åŸã»ãšãã©ã®ãã³ããŒã䜿çšãããªãŒãã³ã¹ã¿ã³ããŒãã«ãªããŸããã
çŸåšãInternet-Draftã®ã¹ããŒã¿ã¹ã«ããã
draft-mclaggan-wccp-v2rev1-00ã§èšè¿°ãããŠããããŒãžã§ã³2
ãé¢é£ããŠããŸãã
ãã®ãããã³ã«ã®åäœã«ãããããã€ãã®éèŠãªç¹ã«ã€ããŠèª¬æããŸãïŒå³ãåç
§ïŒã

ãã¹ãŠã®WCCPã¡ãã»ãŒãžã¯ãå®å
ããŒãçªå·ã2048ã®UDPãã±ããã§ããã¡ãã»ãŒãžã³ã°ã®é åºã¯æ¬¡ã®ãšããã§ãã
- ãµãŒããŒããã©ãã£ãã¯ãã£ãã·ã³ã°èŠæ±ãåŠçããæºåãã§ããŠããå ŽåãWCCP2_HERE_I_AMã¡ãã»ãŒãžãéä¿¡ããŸãã
- ã«ãŒã¿ã¯ãèšå®ã«é¢ããæ
å ±ãç¹ã«ãReceive IDããã£ãŒã«ããå«ãWCCP2_I_SEE_YOUã¡ãã»ãŒãžããµãŒããŒã«éä¿¡ããŸãã
- å¿çãããµãŒããŒã¯ãå¥ã®ã¡ãã»ãŒãžWCCP2_HERE_I_AMãéä¿¡ããŸãããã®ã¡ãã»ãŒãžã«ã¯ãåã®ã¹ããããšåãå€ãæã€ãReceive IDããã£ãŒã«ããå«ãŸããã«ãŒã¿ãŒã§åäœããæºåãã§ããŠããããšã確èªããŸãã
- ãã®ãããªã¡ãã»ãŒãžãåãåã£ãã«ãŒã¿ãŒã¯ããã®æç¹ããWebãµã€ããžã®ãŠãŒã¶ãŒãªã¯ãšã¹ãããã£ãã·ã¥ãµãŒããŒã«ãªãã€ã¬ã¯ãããå¿
èŠãããããšãç解ããŠããŸãã
ã·ã¹ãã ã®æºåãæŽããŸããã WCCP2_HERE_I_AMããã³WCCP2_I_SEE_YOUã¡ãã»ãŒãžã³ã°ããã»ã¹ã¯å®æçã«ç¹°ãè¿ããïŒããã©ã«ãã§ã¯10ç§ããšã«1åïŒãã«ãŒã¿ãŒããã£ãã·ã¥ãµãŒããŒããå¿çãåä¿¡ããªãå ŽåãåŸè
ã¯ããã»ã¹ããé€å€ãããŸãã
å®éã«ã¯ããããã³ã«ã¯ããè€éã§ãèªèšŒãããŸããŸãªãªãã€ã¬ã¯ãã¢ã«ãŽãªãºã ãªã©ãæäŸããŸãããç解ãæ·±ããããã«éèŠã§ã¯ãªã詳现ã¯æèçã«çç¥ããŸãã èå³ã®ããèªè
ã¯ã察å¿ãããã©ããã§ããããèŠã€ããããšãã§ããŸãããªã³ã¯ã¯äžèšã«ãããŸãã
ãã®å®è£
ã¯ããœãªã¥ãŒã·ã§ã³ã®ãã©ãŒã«ããã¬ã©ã³ã¹ã«è²¢ç®ããŸãããã£ãã·ã³ã°ãµãŒããŒã«é害ãçºçããWCCP2_HERE_I_AMã¡ãã»ãŒãžã®éä¿¡ãåæ¢ãããšãã«ãŒã¿ãŒã¯ãã±ããã®è»¢éã®è©Šè¡ãåæ¢ããã€ã³ã¿ãŒããããžã®çŽæ¥éä¿¡ãéå§ããŸãã ãµãŒãã¹ã埩å
ããããšãWCCP2_HERE_I_AM / WCCP2_I_SEE_YOUã¡ãã»ãŒãžã³ã°ããã»ã¹ãç¹°ãè¿ããããã£ãã·ã³ã°ã¹ããŒã ãåã³æ©èœãå§ããŸãã
ãŠãŒã¶ãŒã«ãšã£ãŠããã®ãããªæåŠã¯å®å
šã«èŠããªããããã©ãŠã¶ã«ããŒãžããªããŒãããããšæ¶ãããæ¥ç¶ã§ããŸããããšããäžæçãªã¡ãã»ãŒãžã®ããã«èŠããŸãã
Wiresharkã§ã¯ã次ã®å³ã«ç€ºãããã«ãWCCPã¡ãã»ãŒãžã³ã°ããã»ã¹ã衚瀺ãããŸãã [æé]åã«æ³šæããŠãã ããã ãã©ãã£ãã¯ã€ã¡ãŒãžã¯å®éã®ã·ã¹ãã ããååŸããããããIPã¢ãã¬ã¹ã¯ã»ãã¥ãªãã£ã®ããã«åãæšãŠãããŸãã

ã¯ã©ã€ã¢ã³ããWebãµãŒããŒããããŒã¿ãååŸããããšãããšãã«äœãèµ·ãããèŠãŠã¿ãŸãããã ãããããã
ããããã«ãäŸã§
䜿çšããããã«å²ãåœãŠãããç¹å¥ãªç¯å²
ã䜿çšããŠç¹å®ã®IPã¢ãã¬ã¹ããã¹ãã«
å²ãåœãŠãŸããç°¡åã«ããããã«ãäžèŠãªæ©èœïŒNATããã¡ã€ã¢ãŠã©ãŒã«ãªã©ïŒããã¹ãŠèæ
®ããé€å€ããŸãã

- ãŠãŒã¶ãŒãã©ãŠã¶ãŒã¯ãSRC IP 198.51.100.150ãDST IP 192.0.2.20ãDST TCPããŒã80ãTCP SYNãã©ã°ã䜿çšããŠãã±ãããéä¿¡ããããšã«ãããTCPã»ãã·ã§ã³ãéå§ããŸãã
- ãã®ãããªãã±ãããåä¿¡ãããšãã«ãŒã¿ãŒã¯ãããããã«ã€ã³ã¿ãŒãããã«éä¿¡ãããGREãã±ããã«å®å
šã«ããã¯ããŠãã£ãã·ã¥ãµãŒããŒã«éä¿¡ããŸãã GREãã±ããã«ã¯ãããããSRC IP 192.51.100.1ãšDST IP 198.51.100.100ããããŸãã Wiresharkã§ã¯ã次ã®å³ã®ããã«ãªããŸãã

- ãã®ãããªãã±ãããåä¿¡ãããšããã£ãã·ã¥ãµãŒããŒã¯ãŸããã®ãã±ãããåŠçãããã©ããã決å®ããŸãã ããã§ãªãå Žåããã±ããã¯åãGREãã³ãã«ãä»ããéåžžã®è»¢éã®ããã«ã«ãŒã¿ãŒã«éãè¿ãããã¢ã«ãŽãªãºã ã¯çµäºããŸãã ã¯ãã®å ŽåããµãŒããŒã¯æ¬¡ã®ã¹ãããã«é²ã¿ãŸãã
- ãã£ãã·ã³ã°ãµãŒããŒã¯ãWebãµãŒããŒãšã®æ¥ç¶ã確ç«ãããã®ããã«SRC IP 198.51.100.100ãDST IP 192.0.2.20ãDST TCPããŒã80ãTCP SYNãã©ã°ãæã€ãã±ãããéä¿¡ããŸãã
- ããã«å¿ããŠãWebãµãŒããŒã¯ãSRC IP 192.0.2.20ãSRC TCPããŒã80ãDST IP 198.51.100.100ãTCP SYN / ACKãã©ã°ã䜿çšããŠãã€ãŸããæ¹æ³æ¡æã
- WebãµãŒããŒããå¿çãåä¿¡ãããã£ãã·ã³ã°ãµãŒããŒã¯ã次ã®2ã€ã®ããšãè¡ããŸãã
- SRC IP 198.51.100.100ãDST IP 192.0.2.20ãDST TCPããŒã80ãACKãã©ã°ã䜿çšããŠWebãµãŒããŒã«ãã±ãããéä¿¡ããŸããã€ãŸããéåžžã®TCPã»ãã·ã§ã³ãç¶ç¶ããŸãã IPã¢ãã¬ã¹ã198.51.100.100ã®ã¯ã©ã€ã¢ã³ãã
- SRC IP 192.0.2.20ãSRC TCPããŒã80ãDST IP 198.51.100.150ãTCP SYN / ACKãã©ã°ã䜿çšããŠWebã¯ã©ã€ã¢ã³ãã«ãã±ãããéä¿¡ããŸããã€ãŸããã¯ã©ã€ã¢ã³ãã«å¯ŸããŠã¯ãWebãµãŒããŒãçŽæ¥å¿çããããã«èŠããŸãã ãã®ç¬éãèŠããŠãããŠãã ãããããã¯ãããªãç解ã®éµã§ãã
- ãããã£ãŠã2ã€ã®TCPã»ãã·ã§ã³ã確ç«ãããŠããŸãã1ã€ã¯ã¯ã©ã€ã¢ã³ããšãã£ãã·ã¥ãµãŒããŒã®éããã1ã€ã¯ãã£ãã·ã¥ãµãŒããŒãšWebãµãŒããŒã®éã§ãã ãã£ãã·ã¥ãµãŒããŒã¯ãéåžžã®æ¹æ³ã§WebãµãŒããŒããã³ã³ãã³ããåä¿¡ããã¯ã©ã€ã¢ã³ãã«ãããŒããã£ã¹ãããåæã«ã¡ã¢ãªãŸãã¯ïŒããã³ïŒãã£ã¹ã¯ã«ä¿åããŸãã
ãã®åŸåãã³ã³ãã³ãã«ã¢ã¯ã»ã¹ãããšããã£ãã·ã¥ãµãŒããŒã¯ãç¹å®ã®æ¡ä»¶ã«åŸã£ãŠããã®WebãµãŒããŒãå床ãã³ãã§ãã¿åºãããšã¯ã§ããŸããããããèªäœã§Webã¯ã©ã€ã¢ã³ãã«æäŸããããšãã§ããŸãã
説æããã¢ã«ãŽãªãºã ãå³ã«æŠç¥çã«ç€ºããŸãã

ããã€ãã®éèŠãªç¹ã«æ³šæããŠãã ããã
- GREãã³ãã«å
ã®ãã±ããã¯ãäž»ã«ã«ãŒã¿ãŒãããã£ãã·ã¥ãµãŒããŒã«éä¿¡ãããŸãïŒãã£ãã·ã¥ãµãŒããŒããã±ãããåŠçã§ãããéåžžã®è»¢éã®ããã«ã«ãŒã¿ãŒã«éãè¿ãå Žåãé€ãïŒã
- éæ¹åãã€ãŸããã£ãã·ã¥ãµãŒããŒããWebã¯ã©ã€ã¢ã³ããžã¯ãäžè¬çã«ã«ãŒã¿ãŒããã€ãã¹ããŠãã±ãããçŽæ¥éä¿¡ãããŸãã
- ãã£ãã·ã³ã°ãµãŒããŒã¯ãWebã¯ã©ã€ã¢ã³ãã®ãã±ããã®ã¢ãã¬ã¹ãèšå®ããã®ã§ã¯ãªãããªã¯ãšã¹ããè¡ãããWebãµã€ãã®ã¢ãã¬ã¹ãèšå®ããŸãã
ãã®ãããªãããã³ã«ã®å®è£
ã«ããããã©ãã£ãã¯ãWebã¯ã©ã€ã¢ã³ãããWebãµãŒããŒã«ãªãã€ã¬ã¯ããããã ãã§ãããéåžžã¯ãã®éãå°ãªããããã«ãŒã¿ãŒã®è² è·ã倧å¹
ã«åæžãããŸãã é垞倧éã®WebãµãŒããŒããã®ãã©ãã£ãã¯ã¯ãè€éãªåŠçãåããŸãã-åã«ã«ãŒãã£ã³ã°ãããŸãã
ãã ãããã®ãããªå®è£
ã§ã¯é察称ãã©ãã£ãã¯ãäœæããã次ã®ã»ã¯ã·ã§ã³ã§èª¬æããè€éããçºçããŸãã
ç·Žç¿-ã«ãŒã¿ãŒãšãã¡ã€ã¢ãŠã©ãŒã«ãšã®æŠã
åã®ã¹ããŒã ãå€æŽããŸã-ãã¡ã€ã¢ãŠã©ãŒã«ã®èåŸã«ãã£ãã·ã¥ãµãŒããŒãé
眮ããŸãã

Cisco IOSãœãããŠã§ã¢ããŒãžã§ã³12.3以éãæèŒããCiscoã«ãŒã¿ãŒããœãããŠã§ã¢ããŒãžã§ã³8.2以éãæèŒããCisco ASAãã¡ã€ã¢ãŠã©ãŒã«ãLinuxããŒã¹ã®ãã£ãã·ã¥ãµãŒããŒïŒRHELãŸãã¯CentOSãã£ã¹ããªãã¥ãŒã·ã§ã³ïŒãããã³Squidãã£ãã·ã³ã°ãœãããŠã§ã¢ã䜿çšããããšãæ³å®ããŸãã
ãã®å Žåããã¹ãŠãæ§æããæ¹æ³ã¯ïŒ åºæ¬æ©èœããã§ã«æ§æãããŠãããšä»®å®ããŸããã€ãŸããWebã¯ã©ã€ã¢ã³ããšãã£ãã·ã¥ãµãŒããŒãã€ã³ã¿ãŒãããäžã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ãããšããŸãã ã·ã¹ã³ã§WCCPãã»ããã¢ããããããšããå§ããŸãããã
次ã®2ã€ã®ã¢ã¯ã»ã¹ãªã¹ããäœæããæºåäœæ¥ãå®è¡ããŸãã
ip access-list standard l_wccp_service permit 203.0.113.100 ip access-list extended l_wccp_redirect permit tcp host 198.51.100.150 any eq www
æåã¯ãWCCP2_HERE_I_AMã¡ãã»ãŒãžãåä¿¡ã§ãããã£ãã·ã³ã°ãµãŒããŒã決å®ããŸãã
2çªç®ã¯ããã£ãã·ã¥ãµãŒããŒã«ã©ããããå¿
èŠããããã©ãã£ãã¯ã決å®ããŸãã
WCCPãæ§æããå
éšãŠãŒã¶ãŒãã€ãŸãã¢ãã¬ã¹198.51.100.1ã察象ãšããã€ã³ã¿ãŒãã§ã€ã¹ã§WCCPãæå¹ã«ããŸãã æ確ã«ããããã«ãFastEthernet0 / 0ãšããŸãïŒïŒ
ip wccp web-cache redirect-list l_wccp_redirect group-list l_wccp_service interface FastEthernet0/0 ip wccp web-cache redirect in
ãã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãã«ãŒã¿ãŒãšãã£ãã·ã¥ãµãŒããŒéã§WCCPããã³GREãã±ããã亀æã§ããŸãã
access-list l_wccp extended permit gre host 198.51.100.1 host 203.0.113.100 access-list l_wccp extended permit udp host 198.51.100.1 host 203.0.113.100 access-group l_wccp in interface outside
ãã£ãã·ã¥ãµãŒããŒãæ§æããŸãã ãŸããsquidãã€ã³ã¹ããŒã«ããŠèšå®ããŸããããã«ã¯ããæ°ã«å
¥ãã®ããã¹ããšãã£ã¿ãŒã䜿çšããŠ/etc/squid/squid.confãã¡ã€ã«ãéãã次ã®è¡ãå«ãŸããŠããããšã確èªããŸãã
# /etc/squid/squid.conf http_port 3128 transparent wccp2_router 198.51.100.1 wccp2_forwarding_method 1 wccp2_return_method 1 wccp2_assignment_method hash wccp2_service standard 0
ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ãäœæããŠã¿ãŸãããããã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ãããæ°ã«å
¥ãã®ãšãã£ã¿ãŒã§ã次ã®å
容ã®ãã¡ã€ã«/ etc / sysconfig / network-scripts / ifcfg-tun0ãäœæããŸãã
# /etc/sysconfig/network-scripts/ifcfg-tun0 DEVICE=tun0 BOOTPROTO=none ONBOOT=yes TYPE=GRE PEER_OUTER_IPADDR=198.51.100.1 PEER_INNER_IPADDR=192.168.168.1 MY_INNER_IPADDR=192.168.168.2
IPã¢ãã¬ã¹PEER_INNER_IPADDRããã³MY_INNER_IPADDRã¯çµ¶å¯Ÿã«ä»»æã§ããéåžžã®æ¹æ³ã§ã¯ããã®ãã³ãã«ãä»ããŠäœãã«ãŒãã£ã³ã°ãããŸããã 代ããã«ãDSTããŒã80ã§çä¿¡ãããã¹ãŠã®TCPãã©ãã£ãã¯ã¯ãiptablesã䜿çšããŠsquidã§ã©ãããããŸãã squidãããŒã3128ã§å¿çããŠãããšä»®å®ããŠããã³ãã«ã€ã³ã¿ãŒãã§ãŒã¹ãäžããsquidã§å¿
èŠãªãã©ãã£ãã¯ãã©ããããŸãã
/etc/sysconfig/network-scripts/ifup tun0 iptables -t nat -A PREROUTING -i tun0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 203.0.113.100:3128 /etc/init.d/iptables save
ãã£ãã·ã¥ãµãŒããŒãã«ãŒã¿ãŒã«ç»é²ãããŠããããšã確èªããŸãã
cisco# show ip wccp Global WCCP information: Router information: Router Identifier: 198.51.100.1 Protocol Version: 2.0 Service Identifier: web-cache Number of Service Group Clients: 1 Number of Service Group Routers: 1 Total Packets s/w Redirected: 175623 Process: 0 Fast: 0 CEF: 175623 Redirect access-list: l_wccp_redirect Total Packets Denied Redirect: 113892411 Total Packets Unassigned: 20590 Group access-list: l_wccp_service Total Messages Denied to Group: 26558 Total Authentication failures: 0 Total Bypassed Packets Received: 0
ããã§ã¯ãäžå¿«ãªåŸ
ã¡äŒããäºæ³ãããŸããéåžžãã«ãŒã¿ãŒã«ã¯ãç°ãªãIPã¢ãã¬ã¹ãæã€è€æ°ã®ã€ã³ã¿ãŒãã§ã€ã¹ããããŸãã ãããŠãããã€ã³ã¿ãŒãã§ã€ã¹ã®SRC IPããWCCP2_I_SEE_YOUãã±ãããéä¿¡ããå¥ã®ã€ã³ã¿ãŒãã§ã€ã¹ã®SRC IPããGREãã±ãããéä¿¡ããããšã劚ãããã®ã¯äœããããŸããã
Cisco IOSã«ãŒã¿ãŒã®ãã¡ãŒã ãŠã§ã¢ã®ãã¹ãŠã®ããŒãžã§ã³ã§ã¯ãããŸããããã³ãã³ããip wccp source-interfaceããæäŸãããŸããããã«ãããIPã¢ãã¬ã¹ãWCCPãµãã·ã¹ãã ã«é¢é£ãããã¹ãŠã®ãã±ããã®SRC IPãšããŠäœ¿çšãããã€ã³ã¿ãŒãã§ã€ã¹ãããŒãã»ããã§ããŸãã
ã«ãŒã¿ãŒããã®ã³ãã³ãããµããŒãããŠããå Žåã幞éã§ãã å®è¡ããŠãã ããïŒ
ip wccp source-interface FastEthernet 0/0
ãã®ãããªã³ãã³ãã«å¿ããŠãã«ãŒã¿ãŒããæ§æãšã©ãŒãã®ãããªãã®ãçæããå Žåã次ã®ããã«é²ã¿ãŸã-MEãããã³ãã£ãã·ã¥ãµãŒããŒã§ãããã¯ãŒã¯ã¢ãã©ã€ã¶ãŒïŒå°ãªããšãtcpdumpïŒã§èšºæãå®è¡ããã©ã®IPã¢ãã¬ã¹ããæ¥ããã調ã¹ãŸãWCCPããã±ãŒãžãããã³GREããã±ãŒãžã
次ã«ãsquidã®èšå®ã§ããã³ãã«ã€ã³ã¿ãŒãã§ãŒã¹ãšiptablesã®èšå®ã§2çªç®ã®IPã¢ãã¬ã¹ãæå®ããŸãã ããã«å¿ããŠãMEã®ã¢ã¯ã»ã¹ãªã¹ããå€æŽããŸãã
ã«ãŒã¿ã®åŸç¶ã®åèšå®äžã«ãã€ã³ã¿ãŒãã§ã€ã¹éã§WCCPãã±ãããå°çããIPã¢ãã¬ã¹ãé²ãããã«ãæåŸã®ã€ã³ã¿ãŒãã§ã€ã¹ã«ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ãäœæã§ããŸãã ãã®å ŽåãWCCPã¯ãã¹ãŠã®ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®äžã§æ倧ã®IPã¢ãã¬ã¹ã䜿çšããŠãã±ãããéä¿¡ããŸãã
interface lo0 ip address 198.51.100.20 255.255.255.255
ãªãã€ã¬ã¯ããæ©èœããããšã確èªããŸãã æåã«ã以åã«äœæããã¢ã¯ã»ã¹ãªã¹ãã®ãã±ããæ°ãå¢å ããããšã確èªããŸãã
cisco# show access-list l_wccp_redirect Extended IP access list l_wccp_redirect 10 permit tcp host 198.51.100.150 any eq www (2399 matches)
次ã«ãã¯ã©ã€ã¢ã³ããã·ã³ã®ãã©ãŠã¶ã§ä»»æã®WebããŒãžãéããŸãã ãããŠã確ãã«äœãããŸããããªãã§ãããã ãããç解ããããšãããšããã¡ã€ã¢ãŠã©ãŒã«ã®ãã°ã§ãã®ã¿ã€ãã«é¢ããã¡ãã»ãŒãžãèŠã€ããã§ãããã
%ASA-4-313004: Denied ICMP type=0, from 192.0.2.20 on interface dmz to 198.51.100.150: no matching session
Googleã§æ€çŽ¢ããããšãããšãæåã®ãªã³ã¯ããé察称ã«ãŒãã£ã³ã°ã«é¢ããæ
å ±ãåŸãããŸãã ãããäœãæå³ããããç解ããŸãããã
Cisco ASAãã¡ã€ã¢ãŠã©ãŒã«ã¯
ã¹ããŒããã«ã€ã³ã¹ãã¯ã·ã§ã³ããã€ã¹ã§ããã€ãŸããTCP SYN / ACKãã©ã°ä»ãã®ãã±ããããã£ãã·ã¥ãµãŒããŒããã¯ã©ã€ã¢ã³ãã«æž¡ãã«ã¯ããŸãã¯ã©ã€ã¢ã³ãããã®TCP SYNãã©ã°ä»ãã®å¯Ÿå¿ãããã±ãããå¿
èŠã§ãããŠã§ããµã€ãã«åãMEãé²ããŸããã
ãã®å ŽåãMEã¯ã¯ã©ã€ã¢ã³ããTCPã»ãã·ã§ã³ãéå§ããããšãç解ããé©åãªå
éšæ§é ãäœæãããã®TCPã»ãã·ã§ã³ã®ç¶æ
ãæ£ããç£èŠãå§ããŸãã
ãã®ã¹ããŒã ã§ã¯ãéå§SYNãã±ããã¯MEãééããŸãaïŒGREãã³ãã«å
ãšbïŒãééã£ãæ¹åã«ãããã®ããã«ãã
ãããã£ãŠãMEã¯æ¥ç¶ããŒãã«ã§TCPã»ãã·ã§ã³ãéå§ãããã»ãã·ã§ã³ãéå§ããããšãç解ã§ããããã±ãããã¹ãããããå¿
èŠããããŸãã
ãã®ãããªç¶æ³ã§äœããã¹ããïŒ MEããã€ãã¹ããŠãã£ãã·ã¥ãµãŒããŒã«æ¥ç¶ã§ããªãå ŽåãDMZåŽããå°çãããã±ããã®ãªãŒãã³TCPã»ãã·ã§ã³ã®ãã§ãã¯ãç¡å¹ã«ããã ãã§ãã
Cisco ASAã§ã¯ãæ€èšŒã®ç¡å¹åæ©èœã¯
TCPãã€ãã¹ãšåŒã°ã
ãŸã ã ãã®æ©èœã«ã¯å¶éããããŸãã
- ãœãããŠã§ã¢ããŒãžã§ã³8.2以åã®Cisco ASAã§ã¯æ©èœããŸããã
- åãCisco ASAã¢ãã«MEã§ã¯ã©ã€ã¢ã³ããŸãŒã³ãšDMZã®äž¡æ¹ãç·šæããæ¹æ³ã¯ïŒå°ãªããšãèŠã€ãããŸããã§ããïŒç¥ãããŠããªã-IPã¢ãã¬ã¹å€æã¯äºæž¬ã©ããã«æ©èœããŸããã
ãããã£ãŠãTCPãã€ãã¹æ©èœãæå¹ã«ããŸãã
access-list l_bypass extended permit tcp any eq www host 198.51.100.150 class-map c_bypass match access-list l_bypass policy-map p_bypass class c_bypass set connection advanced-options tcp-state-bypass service-policy p_bypass interface dmz
l_bypassã¢ã¯ã»ã¹ãªã¹ãã«ã¯ãã¯ã©ã€ã¢ã³ãIPã¢ãã¬ã¹ã®ç¯å²ãå¿
èŠã§ãã
ããã§ãã¹ãŠãæ©èœããã¯ãã§ãã å°ãªããšãããã¯ç§ãã¡ã®ããã«åããã
ãããã«
ãã®èšäºã¯ãå°èŠæš¡ãªéä¿¡äºæ¥è
ã®ãããã¯ãŒã¯ã«Webãã©ãã£ãã¯ããã£ãã·ã¥ããæ©èœãå®è£
ããçµéšã«åºã¥ããŠããããããã¯ãŒã¯ãšã³ãžãã¢ã®ä»äºã«ããã2ã€ã®å€ãååãããäžåºŠèª¬æããŠããŸãã
- ãããã³ã«ã®æšæºãšèª¬æãç¡èŠããªãã§ãã ããã
- äœãèµ·ãã£ãŠããã®ãããããªãå Žåã¯ãæ ããã«ãããã¯ãŒã¯ã¢ãã©ã€ã¶ãŒãæ¥ç¶ããŠãã ããã
ãã¹ããšå®è£
ã«æåããŸããïŒ ãããŠãä»ãåžžã«ããªãã®ãã£ã³ãã«ãå¯èœãªéãå°ãªããã©ãã£ãã¯ã転éããããã«ããŸãã