å Žåã«ãã£ãŠã¯ãéä¿¡è
ã«åºã¥ããŠã¡ãŒã«ã«ãŒãã£ã³ã°ãè¡ãå¿
èŠããããŸãã ãã®ã¿ã¹ã¯ã®è±èªã®çšèªã¯ãéä¿¡è
ããŒã¹ã®ã«ãŒãã£ã³ã°ã§ãã ãã®åé¡ã¯ããŸããŸãªæ¹æ³ã§è§£æ±ºã§ããŸããã¡ãŒã«ãµãŒããŒã®ããŸããŸãªå€éšãªã¬ãŒãMS Exchangeã䜿çšããå Žåã®ç¹å¥ãªãšãŒãžã§ã³ãïŒããšãã°ãExchange Serverã®Sender Based Routing AgentïŒãªã©ã ãã®ã¡ã¢ã§ã¯ãCisco Email Security ApplianceïŒä»¥éãESAïŒã䜿çšããåé¡ã®è§£æ±ºçïŒä»¥åã®IronPort ESAïŒãå
±æãããã£ãã®ã§ãã
éä¿¡è
ããŒã¹ã®ã«ãŒãã£ã³ã°ã¿ã¹ã¯ã¯ãåãã¡ãŒã«ãµãŒããŒã§è€æ°ã®éä¿¡è
/åä¿¡è
ãã¡ã€ã³ã䜿çšããå¿
èŠãããå Žåã«é¢é£ããŸãã ãããŠãããã¯æ¬¡ã®çç±ã«é¢é£ããŠããŸãã ã¹ãã 察çã·ã¹ãã ã®å€§éšåã¯ãéä¿¡è
ã®IPã¢ãã¬ã¹ã®PTRã¬ã³ãŒãããã§ãã¯ããŸãã 1ã€ã®IPã¢ãã¬ã¹ã«å¯ŸããŠãè€æ°ã®PTRã¬ã³ãŒããäœæããããšã¯åŒ·ãæšå¥šãããŸããã ãããã£ãŠãã¡ãŒã«ãµãŒããŒã®åãã¡ã€ã³ããã®æçŽã¯ãåäžã®PTRã¬ã³ãŒããããç¬èªã®IPã¢ãã¬ã¹ããéä¿¡ããå¿
èŠããããŸãã ããããªããšãåä¿¡è
åŽã®ã¹ãã 察çã·ã¹ãã ãã¡ãã»ãŒãžãããããããå¯èœæ§ããããŸãã ããã§åé¡ãçºçããŸãããéä¿¡è
ã®ãã¡ã€ã³ã«åºã¥ããŠã1ã€ã®ã¡ãŒã«ãµãŒããŒããå¥ã®IPã¢ãã¬ã¹ã«ïŒç¹ã«ãç°ãªãã€ã³ã¿ãŒããããããã€ããŒãä»ããŠéä¿¡ããïŒæçŽãã©ã®ããã«åæ£ã§ããŸããïŒ
ç§ã®ç¹å®ã®äŸã§ã¯ãã¿ã¹ã¯ã¯æ¬¡ã®ããã«èšå®ãããŸããããµãŒãããŒãã£ãããã€ããŒã®IPã¢ãã¬ã¹ããç¹å®ã®MS Exchangeãã¡ã€ã³ã«ã¬ã¿ãŒãéä¿¡ããå¿
èŠããããŸãã èšãæãããšãMS ExchangeãµãŒããŒäžã®éä¿¡è
/åä¿¡è
ã®æ°ããè¿œå ãã¡ã€ã³ã䜿çšããããšã«ãªã£ãŠããããã®éä¿¡å
ã¯å¥ã®åœã«ãããªã¢ãŒããªãã£ã¹ã®IPã¢ãã¬ã¹ããéä¿¡ãããå¿
èŠããããŸãã
MS ExchangeãµãŒããŒãé
眮ãããŠããã»ã³ãã©ã«ãªãã£ã¹ã§ã¯ãCisco ASA ITUã䜿çšããŠã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããŸãã ãªã¢ãŒããªãã£ã¹ã«ã¯ãCisco ASAããããŸãã VPNãµã€ãéãã¯ãããžãŒIPsecãæ§æãããªãã£ã¹éã
æçŽãéãããããã®ã¹ããŒã ã以äžã«ç€ºããŸãã
@ abc.ruãã¡ã€ã³ããã®æçŽã¯ã1.1.1.1ããããŒã«ã«ISPã¡ã€ã³ISPãä»ããŠéä¿¡ããã@ xyz.ruãã¡ã€ã³ããã®æçŽã¯ãVPNãä»ããŠãªã¢ãŒããªãã£ã¹ã«éä¿¡ãããã¢ãã¬ã¹9.9.9.9ã®ããŒã«ã«ãªã¢ãŒãISPãããã€ããŒãä»ããŠã€ã³ã¿ãŒãããã«éä¿¡ãããŸãã ãã®èšäºã§ã¯ãCisco ASAã§ã®VPN Site-to-Siteã®æ§ç¯ããã³ãªã¢ãŒããããã€ããŒãä»ããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã®çµç¹ã«ã€ããŠã¯èª¬æããŸããããã®ãããã¯ã«ã€ããŠã¯ãcisco.comã®å
¬åŒããã¥ã¡ã³ããšå€æ°ã®ãã©ãŒã©ã ã®äž¡æ¹ã§è©³ãã説æããŠããŸãã
åœåãCisco ESAã¯ãã®é¡§å®¢ã®ãããã¯ãŒã¯ã§ã¹ãã 察çãœãªã¥ãŒã·ã§ã³ãšããŠã®ã¿äœ¿çšãããŠããŸããã çä¿¡ã¡ãŒã«ã®ã¿ãCisco ESAãééããŸããã ã¡ãã»ãŒãžã¯ãCisco ESAããã€ãã¹ããŠéä¿¡ãããŸããMSExchangeãµãŒããŒã¯ãããã©ã«ãã²ãŒããŠã§ã€ã«çŽæ¥ã¡ãã»ãŒãžãéä¿¡ããŸããã ãã®å ŽåãCisco ASAã§ã
@ abcããã³@ xyzãã¡ã€ã³ã®åä¿¡ã¡ãŒã«ãæŽçããã®ã«ããªãã¯ã¯ãããŸããã @ abcã®MXã¬ã³ãŒããã¡ã€ã³ãããã€ããŒïŒã¡ã€ã³ISPïŒã®ã¢ãã¬ã¹ã§å
¬éãã@ xyzã®MXã¬ã³ãŒãããªã¢ãŒããããã€ããŒïŒãªã¢ãŒãISPïŒã®ã¢ãã¬ã¹ã§å
¬éããCisco ESAã®ã«ãŒãã£ã³ã°ãšå
¬éãæ£ããæ§æããã ãã§ååã§ãã
説æããäŸã§ã¯ãCisco ESAããã§ã«é¡§å®¢ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«å±éãããŠãããéä¿¡ã¡ãŒã«ã®å€éšãªã¬ãŒãšããŠäœ¿çšã§ããŸãã ãããã£ãŠããŸããéä¿¡è
ããŒã¹ã®ã«ãŒãã£ã³ã°ã®åé¡ã解決ããã®ã«åœ¹ç«ã€ãã©ããçåã«æããŸããã çµå±ã®ãšãããã¯ãã ãã®åé¡ã¯ESAã®çºä¿¡ãã£ã«ã¿ã䜿çšããŠè§£æ±ºããããšãã§ããŸã-çºä¿¡ã³ã³ãã³ããã£ã«ã¿ïŒ
Cisco ESAã䜿çšãããšãç¹å®ã®é»åã¡ãŒã«ãç°ãªãIPã¢ãã¬ã¹ããéä¿¡ãããããã«ãã£ã«ã¿ãŒãèšå®ã§ããŸãã 以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ãçºä¿¡ã³ã³ãã³ããã£ã«ã¿ãŒã®èšå®ã瀺ããŠããŸãã
ãæ¡ä»¶ã®è¿œå ãã®æåã®ã¹ã¯ãªãŒã³ã·ã§ãããããããããã«ãCisco ESAã¯ãå¿
èŠãªã¢ã¯ã·ã§ã³ãé©çšããæåãéžæããååãªæ©äŒãæäŸããŸãïŒãã¢ã¯ã·ã§ã³ã®è¿œå ãããïŒã ããã«ãæ¡ä»¶ã®ã»ãããäœæãããããã«è«çANDãŸãã¯ORãé©çšã§ããŸãã ãã®åé¡ã解決ããã«ã¯ãã¬ã¿ãŒã®MAIL FROMãã£ãŒã«ãã«@ xyzãšãããã¬ãŒãºãå«ãŸããŠããã°ãæå®ããã ãã§ååã§ãã ã¢ã¯ã·ã§ã³ïŒãã¢ã¯ã·ã§ã³ã®è¿œå ãïŒãšããŠãDeliver from IP Interfaceãæå®ããç°ãªãIPã¢ãã¬ã¹ãæã€2çªç®ã®ïŒãŸã 䜿çšãããŠããªãïŒCisco ESAã€ã³ã¿ãŒãã§ã€ã¹ãéžæããå¿
èŠããããŸãã ãã®ã€ã³ã¿ãŒãã§ã€ã¹ã¯ããŒã¿2ãšåŒã°ããŸããäœæããããã£ã«ã¿ãŒãRedirect-Filterãªã©ã®ååã§ä¿åããäœæããããã£ã«ã¿ãŒã[éä¿¡ã¡ãŒã«ããªã·ãŒ]ã»ã¯ã·ã§ã³ã®éä¿¡ã¡ãŒã«ã®æ¢å®ã®ããªã·ãŒã«é©çšããã ãã§ãã
ãããã£ãŠããã¡ã€ã³@ xyzãã¡ã€ã³ããã®æåãããŒã¿2ã€ã³ã¿ãŒãã§ã€ã¹ã®IPã¢ãã¬ã¹ããéä¿¡ããã@ abcãã¡ã€ã³ããã®æåãæåã®ã€ã³ã¿ãŒãã§ã€ã¹-ããŒã¿1ã®IPã¢ãã¬ã¹ã«éä¿¡ãããããã«ãCisco ESAãèšå®ã§ããŸããã Cisco ESAçµç±ã§ã¬ã¿ãŒãéä¿¡ããå¿
èŠããã£ãå ŽåãHATããŒãã«ïŒãã¹ãã¢ã¯ã»ã¹ããŒãã«ïŒã®RELAYLISTã§MS Exchangeã®IPã¢ãã¬ã¹ãæå®ããããšãå¿ããªãã§ãã ããã
ãã¹ãŠã®ã¡ãã»ãŒãžãCisco ESAçµç±ã§éä¿¡ããããã«MS Exchangeãæ§æãïŒã¹ããŒããã¹ããšããŠCisco ESAãæå®ïŒããªãã£ã¹éã®VPNãæ§æããŠãCisco ESA Data 2ã€ã³ã¿ãŒãã§ã€ã¹ïŒ@ xyzãã¡ã€ã³ã¡ãã»ãŒãžã®éä¿¡å
ïŒã®IPã¢ãã¬ã¹ãšã€ã³ã¿ãŒãããéã®ãã©ãã£ãã¯ãæå·åããããšã¯æ®ããŸãã å®éãCisco ASAã®èšå®ã§ã¯ãData 2ã€ã³ã¿ãŒãã§ã€ã¹ã®IPã¢ãã¬ã¹ã察å¿ããæå·åã¢ã¯ã»ã¹ãªã¹ãã«è¿œå ããå¿
èŠã«å¿ããŠNATã«ãŒã«ãä¿®æ£ããå¿
èŠããããŸãã
ãããã£ãŠããã®ããŒãã§ã¯ãCisco ESAã䜿çšããŠéä¿¡è
ããŒã¹ã®ã«ãŒãã£ã³ã°ã¿ã¹ã¯ã解決ããæ¹æ³ã®å
·äœäŸãæ€èšããŸããã ææ¡ããããœãªã¥ãŒã·ã§ã³ã®äž»ãªã¢ã€ãã¢ã¯ãæåã®ãã¡ã€ã³ã®æåãCisco ESA Data 1ã€ã³ã¿ãŒãã§ã€ã¹ã®IPã¢ãã¬ã¹ããéä¿¡ãã2çªç®ã®ãã¡ã€ã³ã®æåãData 2ã€ã³ã¿ãŒãã§ã€ã¹ã®IPã¢ãã¬ã¹ããéä¿¡ããããšã§ããç°ãªãIPã¢ãã¬ã¹ã«æåãå²ãåœãŠãåŸã䟿å©ã§æé ãªäŸ¡æ Œã§ãã®ãããªæåããããã¯ãŒã¯æ©åšã«ã«ãŒãã£ã³ã°ããããšãå¯èœã«ãªããŸãæ¹æ³ã èšèŒãããŠããã±ãŒã¹ã§ã¯ããã©ãã£ãã¯ã¯æå·åã¢ã¯ã»ã¹ãªã¹ãã䜿çšããŠCisco ASAã«ã«ãŒãã£ã³ã°ããããã±ããã¯VPNãã³ãã«ã§ã©ãããããŸããã ã«ãŒã¿ãŒã§ã¯ããããã®ç®çã§ããªã·ãŒããŒã¹ã«ãŒãã£ã³ã°ãŸãã¯VRFã䜿çšã§ããŸãã
çµè«ãšããŠã説æããæ©èœãCisco ESAã«å®è£
ããããã«è¿œå ã®ã©ã€ã»ã³ã¹ã¯å¿
èŠãããŸããã å¿
èŠãªã®ã¯ãã¹ãã 察çæ©èœãæäŸããããã«å¿
èŠãªæãäžè¬çãªCisco Email Security Inboundã©ã€ã»ã³ã¹ã ãã§ãã
Cisco ESAã©ã€ã»ã³ã¹æ¹åŒã®è©³çŽ°ã¯ã次ã®ãšããã§ããCisco ESAã©ã€ã»ã³ã¹æ¹åŒã§ã¯ãã€ã³ããŠã³ããã¢ãŠãããŠã³ãããã¬ãã¢ã ïŒã€ã³ããŠã³ã+ã¢ãŠãããŠã³ãïŒã®3çš®é¡ã®ã©ã€ã»ã³ã¹ãšãè¿œå æ©èœïŒImage Analyzerãè¿œå ã®McAfeeã¢ã³ããŠã€ã«ã¹ãSoureFIRE-AMPããã®è¿œå ãã¡ã€ã«ã¢ã³ããŠã€ã«ã¹ïŒãéãããã®A-la-Carteã©ã€ã»ã³ã¹ã®ã»ãããæäŸãããŸããªã©ïŒã ã¹ãã 察çæ©èœãæäŸããã«ã¯ãã€ã³ããŠã³ãã©ã€ã»ã³ã¹ãå¿
èŠã§ãã ããæ£ç¢ºã«ã¯ããã®ã©ã€ã»ã³ã¹ã¯ãã¹ãã 察çããŠã€ã«ã¹å¯ŸçïŒSophosïŒãããã³ãŒããã€è
åšãã£ã«ã¿ãŒïŒOutbreak FiltersïŒã®æ©èœãéããŸãã ã©ã€ã»ã³ã¹ã®ååããå€æãããšãCisco ESAãä»ããŠã¬ã¿ãŒãéä¿¡ããã«ã¯ã¢ãŠãããŠã³ãã©ã€ã»ã³ã¹ãå¿
èŠã§ãããšèãããããããŸããã ããããããã¯ããã§ã¯ãããŸããã Cisco ESAãä»ããŠã¬ã¿ãŒãéä¿¡ããéä¿¡ã¡ãŒã«ã®ãã£ã«ã¿ãŒïŒã¢ãŠãããŠã³ãã³ã³ãã³ããã£ã«ã¿ãŒïŒã䜿çšããã«ã¯ãã€ã³ããŠã³ãã©ã€ã»ã³ã¹ãããã°ååã§ãã ã¢ãŠãããŠã³ãã©ã€ã»ã³ã¹ã¯ãã¬ã¿ãŒã®æå·åæ©èœãéããæ
å ±æŒæŽ©ããä¿è·ããããã«ã®ã¿å¿
èŠã§ãïŒæå·åãšããŒã¿æ倱é²æ¢ïŒã ããã«ããããã®ã©ã€ã»ã³ã¹ã«ã¯åŒ·åãªæå·åãå«ãŸããŠãããããã¢ãŠãããŠã³ãã©ã€ã»ã³ã¹ããããã£ãŠãã¬ãã¢ã ã©ã€ã»ã³ã¹ã¯ã«ããŽãªC3ã«åé¡ãããŸãã ãã®ãããªè£œåããã·ã¢é£éŠã«èŒžå
¥ããã«ã¯ãFSBããèš±å¯ãååŸããå¿
èŠããããŸãããããã£ãŠãååãšããŠããã®ãããªã©ã€ã»ã³ã¹ã®çŽæã¯é·ããªããŸãã