ããã«ã¡ã¯ãHabrïŒ æšç§ãCisco ASAãã¡ã€ã¢ãŠã©ãŒã«ã«
FirePOWERãµãŒãã¹ãå®è£
ãã
çµéšãå
±æããŸããã
æ°å¹Žã®ãã©ãã·ã¥ããã¯ã§ã¯ã FirePOWERããŒãžã§ã³6.0ã«ã€ããŠèšåããŸããããã®ããŒãžã§ã³ã§ã¯ãäž»ãªé©æ°ã®1ã€ãASDMã䜿çšãããã¹ãŠã®ãµãŒãã¹ã®ç®¡çã§ããã ã·ã¹ã³ã®é²æ©ã¯ãŸã æ¢ãŸã£ãŠãããããã®æ¥ã
Cisco Firepower 4100ããã³9300ã®æ°ããã©ã€ã³ã¢ãããçºè¡šãããŸããã å®éããããã¯5585-Xã«äŒŒãåãã¢ãžã¥ã©ãŒASAã§ãããæ°ããååïŒããŒã±ãã£ã³ã°éšéïŒãããæŽç·Žããããããå¹ççãªæ°ããéäžç®¡çãœãããŠã§ã¢Firepower Threat DefenseïŒFTDïŒãåããŠããŸãã FTDã¯ãæ°ããã¢ãã«ç¯å²ã®ããã€ã¹ã ãã§ãªãã5585-Xãé€ããã¹ãŠã®ASA 5500-Xã¢ãã«ã§ãïŒå°ãªããšãçŸæç¹ã§ã¯ïŒèµ·åã§ããŸãã ãã®èšäºã§ã¯ãã·ã¹ã³ã®ãã®æ°ãããœãããŠã§ã¢ã«ã€ããŠèª¬æããŸãã
èæ¯ã®ãããã FirePOWERããŒãžã§ã³5.4ã§ã¯ããã¹ãŠããã·ã³ãã«ãã§ãããASASSDïŒãŸãã¯å¥ã®ããŒããŠã§ã¢ããŸãã¯ä»®æ³ãã·ã³ïŒã«ã»ã³ãµãŒããããFireSIGHT Management CenterïŒå¥åDefense CenterïŒã管çãããœãããŠã§ã¢ããããŸããã ASAã«ã¯ãCLI / ASDMã«ããå¶åŸ¡ãåããç¬èªã®æšæºIOSã€ã¡ãŒãžããããŸããã ã»ã³ãµãŒã«ã¯ãåãCLI ASAïŒãŸãã¯mgmtããŒããžã®SSHïŒãä»ããŠã¢ã¯ã»ã¹ãããç¬èªã®ã€ã¡ãŒãžãå¿
èŠã§ããã ããŠãFireSIGHTãžã®ã¢ã¯ã»ã¹ã¯ãã©ãŠã¶ãä»ããŠè¡ãããŸããã ããã«ã¯ãASAã®åå¥ã®ã©ã€ã»ã³ã¹+ã¹ããŒãããããFireSIGHTã®ã»ã³ãµãŒãšã¹ããŒããããã®åå¥ã®ãµãã¹ã¯ãªãã·ã§ã³ãè¿œå ããå¿
èŠããããŸãã èšããŸã§ããªãããã¹ãŠã®ãµãŒãã¹ã管çããããã®ãã®ãããªåæ£ã¢ãããŒãã¯ãå€ãã®äººã«é©ããŠããªãã FirePOWERããŒãžã§ã³6.0ã®ãªãªãŒã¹ã«ãããASDMã䜿çšããŠãã¹ãŠã®ãµãŒãã¹ã管çã§ããããã«ãªããŸããã ASDMèªäœã«ãã£ãŠèª²ããããå€ãã®å¶éãç°ãªãã»ã³ãµãŒã«ãããããªã·ãŒã®äžå
åãããé
åžã®æ¬ åŠãããã³ä»ã®ããã€ãã®æ©èœã¯èª°ãã奜ããã®ã§ã¯ãªãã£ããããå€ãã¯ãŸã ãã¹ãŠãäžå
管çããå®å
šãªãœãªã¥ãŒã·ã§ã³ãåŸ
ããªããã°ãªããŸããã
ãããã ãŽã·ããTsiskaã«ãããšãCisco ASAåãã®æ°ããASDMã®éçºã¯æ¬æ Œçã§ãããHTML 5ã§èšè¿°ãããäºå®ã§ãã ããããšã
FTDã®ãªãªãŒã¹ã«ãããã»ã³ãµãŒãœãããŠã§ã¢ãšCisco ASAãœãããŠã§ã¢ãå転ãã1ã€ã®ã€ã¡ãŒãžãéäžç®¡çãããŸããã ã©ã¡ããFirepower Management Centerã§ç®¡çãããŸãïŒFMCã¯FireSIGHTãåãååã®3çªç®ã®ååã§ããä»ããåæ¢ããŠãã ããïŒã ãããŠããã¹ãŠã¯åé¡ãããŸããããASDMã®å Žåã«FPãµãŒãã¹ã®å¶éãåããå ŽåãASAã®æ©èœãšèšå®ã«å¶éãããããŸãã äž»ãªå¶éã¯ããæ©èœããªããVPNã§ãã ãããŠããããæ©èœããªãããã§ã¯ãªããéåžžã®æ段ã䜿çšããŠèšå®ããããšã¯ã§ããŸããã çŸåšããµã€ãéVPNããªã¢ãŒãã¢ã¯ã»ã¹VPNãæ§æã§ããŸããã
ãµã€ãéVPNã«ã€ããŠãµã€ãéVPNã®å Žåããã¹ãŠãããªãææ§ã§ãïŒ
ããŒãžã§ã³6.0.1ã®ãªãªãŒã¹ããŒãã§ã¯ãçœé»ã§èšè¿°ãããŠããŸãïŒãFirepower Threat Defenseãå®è¡ããŠããããã€ã¹ã¯ãããŒãžã§ã³6.0.1ã§ã¯
VPNæ©èœã
ãµããŒãããŸããããã¹ã€ããã³ã°ããã³ã«ãŒãã£ã³ã°æ©èœããµããŒãããŸãã ãããããåæã«
ãFMC 6.0.1ã®æ§æã¬ã€ã ïŒpdf圢åŒïŒã¯åãããã«èªã¿ãŸãã
Firepower Threat Defenseã¢ãã©ã€ã¢ã³ã¹ã¯ãçµ±åããã次äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ãšæ¬¡äžä»£IPSããã€ã¹ãæäŸããŸãã ãFirepowerãœãããŠã§ã¢ã¢ãã«ã§å©çšå¯èœãªIPSæ©èœã«å ããŠããã¡ã€ã¢ãŠã©ãŒã«ããã³ãã©ãããã©ãŒã æ©èœã«
ã¯ããµã€ãéVPN ãå
ç¢ãªã«ãŒãã£ã³ã°ãNATãã¯ã©ã¹ã¿ãªã³ã°ïŒFirepower 9300çšïŒãããã³ã¢ããªã±ãŒã·ã§ã³æ€æ»ãšã¢ã¯ã»ã¹å¶åŸ¡ã«ããããã®ä»ã®æé©åãå«ãŸããŸããã FMCãããµã€ãéVPNãæ§æããè©Šã¿ã倱æããããããªãªãŒã¹ããŒãã®ããŒãžã§ã³ã«åŸåããŠããŸãã
FTDã®ã€ã³ã¹ããŒã«FTDã€ã¡ãŒãžã¯ããã¹ãŠã®ASA 5500-Xããã³FP 4100/9300ãã©ãããã©ãŒã ã«ã€ã³ã¹ããŒã«ã§ããŸãã ä»®æ³å®è¡ãªãã§ã¯ãªã-vFTDãããã«åºã¥ããŠãäž»ã«ããããªããã¬ãŒã·ã§ã³ãæ§ç¯ãããŸãã
æåã®FTDã€ã¡ãŒãžã¯ããŒãžã§ã³6.0.1ãåãåããŸããã FTDãFMCã«æ¥ç¶ã§ããããã«ããã«ã¯ãFireSIGHTãããŒãžã§ã³6.0.1ã«æŽæ°ããå¿
èŠããããŸãïŒFMCã®èŠä»¶ã¯ã補åã®ä»¥åã®ããŒãžã§ã³ã®èŠä»¶ãšåãã§ãïŒã FTDã€ã¡ãŒãžã®ã€ã³ã¹ããŒã«ãšFMCãžã®æ¥ç¶ã䜿çšããŠä»®æ³ç°å¢ãŸãã¯Cisco ASAãæºåããããã»ã¹ã¯ãã¯ã€ãã¯ã¹ã¿ãŒãã¬ã€ãïŒ
VMware ã
Cisco ASAããã³
Firepower 4100 ã
Firepower 9300ã®å ŽåïŒã§è©³çŽ°ã«èª¬æãããŠãããããããã§ã¯è©³ãã説æããŸããã ããã«ãASAãšVMwareã®ãã®ããã»ã¹ã¯ããããã®ãã©ãããã©ãŒã ã«å¥åã®FPã»ã³ãµãŒãã€ã³ã¹ããŒã«ããããšãšå€§å·®ãããŸããã æçµçã«ãæ¥ç¶ãããFTDïŒãã®å Žåã¯vFTDïŒã®ç»åã¯æ¬¡ã®ããã«ãªããŸãã
å³1-FMCã³ã³ãœãŒã«ã§ã®vFTDã®è¡šç€ºããã§æ³šæãã¹ãããšïŒ
1.ã©ã€ã»ã³ã¹ã©ã€ã»ã³ã¹ã¯ãã¹ããŒãã©ã€ã»ã³ã¹ããã°ã©ã ãçµç±ããããã«ãªããŸãããããã¯ãã·ã¹ã³ããã®æ°ããã©ã€ã»ã³ã¹ã¹ããŒã ã§ãã
ãããã ãŽã·ããTsiskaã¯ã é ãå°æ¥ããã®ã¹ããŒã ã¯ãæè¿å°å
¥ãããCisco ONEã¹ããŒã ãå«ãããã¹ãŠã®åŸæ¥ã®ã©ã€ã»ã³ã¹ã¹ããŒã ã眮ãæãããšèšããŸãã
ãã®ã¹ããŒã ã®äž»ãªã¡ãã»ãŒãžã¯ãããã€ã¹ã«ãããµãã¹ã¯ãªãã·ã§ã³/ã©ã€ã»ã³ã¹ã®é¢é£æ§ã®èªåç£èŠïŒããã€ã¹ã¯ãã€ã³ã¹ããŒã«ãããã©ã€ã»ã³ã¹ãé¢é£ãããã©ãããããã³ã«ã¹ã¿ã æ©èœããµãã¹ã¯ãªãã·ã§ã³æ¡ä»¶ã«äžèŽãããã©ãããã·ã¹ã³ã«å®æçã«ç¢ºèªããŸãïŒãããã³ãã®ããã«äœæãããSmart Software ManagerããŒã¿ã«ãéããŠãã¹ãŠã®ãµãã¹ã¯ãªãã·ã§ã³/ã©ã€ã»ã³ã¹ãéäžç®¡çããæ©èœã§ã
å³2-vFTDã®ã¹ããŒãã©ã€ã»ã³ã¹2.ä»®æ³FTDã®ã«ãŒãããã¢ãŒãä»®æ³FPã»ã³ãµãŒãšã¯ç°ãªããvFTDã¯ã«ãŒãã£ã³ã°ã¢ãŒãã§åäœã§ããŸãã ããã¯ãFTDå
ã«ASAãœãããŠã§ã¢ã€ã¡ãŒãžãããããã§ãã ãŸããä»®æ³åã®å Žåã¯ãäœãã§å®è¡ããå¿
èŠããããŸããããã¯ãã¡ãããASAvãããå
·äœçã«ã¯ASAv30ã§ãã vFTDãããŒãããããã»ã¹ã§ã¯ãã³ã³ãœãŒã«ã«ASAvã®èµ·åã«é¢ããã¡ãã»ãŒãžãåžžã«è¡šç€ºãããŸãããŸãã¯ãã©ã®ã€ã¡ãŒãžãããŒãããããå°ããŸãã
å³3-vFTDã®ããŠã³ããŒãã ASAvã®ã€ã¡ãŒãžã®éžæãšããã§ãvFTDã®ããŒãæã®ã³ã³ãœãŒã«ã¯ãASAvèªäœã®çŸåšã®ã©ã€ã»ã³ã¹ãèŠãããšãã§ããå¯äžã®å Žæã§ãã
å³4-ã¢ã¯ãã£ãåããã3des-aesãšAnyconnectãªãã®ã©ã€ã»ã³ã¹ãVPN Premiumãããã¯vFTDãåããASAv30ã§ããããããã³ããŒã®ããŒã¿ã·ãŒãã®æ°å€ïŒ
ASA 5500-X ã
ASAv pdfïŒããå€æãããšãéASA 5525-Xã«å¹æµããããã©ãŒãã³ã¹ãåŸãããŸãã ãã¡ãããFPã®æ©èœãèæ
®ããŠã©ã®ãããªããã©ãŒãã³ã¹ãããã®ãââã¯ãŸã æ確ã§ã¯ãããŸããããããã§ããªãçŽ æŽãããã§ãã
ã«ãŒãããã¢ãŒããšãã©ã³ã¹ãã¢ã¬ã³ãã¢ãŒãã«ã€ããŠããã¥ã¡ã³ãã«ãããšãééã¢ãŒãã¯FTDã§ã䜿çšã§ããŸãããvFTDã®å Žåãã«ãŒãã£ã³ã°ã¢ãŒãã®ã¿ã䜿çšå¯èœã§ãã
FTDã»ããã¢ããFTDã»ããã¢ããã¯ã3ã€ã®ãã€ã³ãã«åããããšãã§ããŸãã
- ã·ã¹ãã èšå®
- ã«ãŒãã£ã³ã°èšå®ã
- ãµãã¹ã¯ãªãã·ã§ã³ïŒNGFWãNGIPSãAMPïŒã«ããæ©èœã®ã«ã¹ã¿ãã€ãºã
ã·ã¹ãã èšå®ãããã®èšå®ã¯ã[ããã€ã¹]-> [ãã©ãããã©ãŒã èšå®]ã¿ãã§æ§æ/ç·šéãããŸãã 次ã®ããã«ãªããŸãã
å³5-vFTDã®ãã©ãããã©ãŒã èšå®ååãšããŠãååããäœãåå ã§ããããæ確ã§ãããããããã§ã¯ãå€éšèªèšŒ+ã»ãã¥ã¢ã·ã§ã«/ HTTPã®1ã€ã ããåãäžããŸãã
ãã®ãããªãã³ãã«ã¯ãASAvã³ã³ãœãŒã«ã«çŽæ¥ã¢ã¯ã»ã¹ã§ããããã«ããããã«å¿
èŠã§ãã ããŒã«ã«ã¢ã«ãŠã³ãã¯äœæã§ããªããããèªèšŒã«ã¯LDAPãŸãã¯RADIUSïŒå€éšèªèšŒïŒã䜿çšããå¿
èŠããããŸãã ãã¹ãŠããã€ãã®ããã«èŠããŸããæåã«èªèšŒæ¹æ³ãèšå®ãã次ã«ã©ã®ã¢ãã¬ã¹ãããã©ã®ã€ã³ã¿ãŒãã§ãŒã¹ãšãããã³ã«ã«ã¢ã¯ã»ã¹ã§ããããèšå®ããŸãã ãããŠããã¹ãŠãSSHã§ããŸãããã°ãHTTPã¯æããã«ãæªæ¥ã®ããã«ãäœãããŸãã Cisco ASAäžã®HTTPã¯éåžžãASDMçµç±ã§ã¢ã¯ã»ã¹ããããã«èšå®ãããŠããŸããããã®å ŽåãASDMã€ã¡ãŒãžã¯ASAvã§å©çšã§ãããFMCã§ããŠã³ããŒãããã³èšå®ãããªãã·ã§ã³ããªãããããã©ãŠã¶ããã¢ã¯ã»ã¹ãããšããããã³ASDMçµç±ã§æ¥ç¶ãããšãã«404ãšã©ãŒãçºçããŸããããã€ã¹ãããŒãžã£ãŒãèµ·åã§ããŸãããïŒ
å³6-HTTPãä»ããFTDãžã®æ¥ç¶SSHçµç±ã§ã³ã³ãœãŒã«ã«ã¢ã¯ã»ã¹ãããšãæåã«èŠãã®ã¯show versionã§ãã
å³7-SSHçµç±ã§ããŒãžã§ã³ã衚瀺ããã¯ãvFTDããŒãžã§ã³ãšASAvã®ãœãããŠã§ã¢/ããŒããŠã§ã¢ã«é¢ããæ
å ±ã§ãã CLIã«ã€ããŠå°ã調ã¹ããšãããç£èŠãšãã©ãã«ã·ã¥ãŒãã£ã³ã°ã®ç®çã ãã®ããã«äœæããããšããçµè«ã«éããŸããã
showã«ããŽãªã®ã»ãšãã©ã®æšæºã³ãã³ãã¯ãããã«ãASAv / ASAã®åãã³ãã³ããšéãã¯ãããŸããã
ãã£ããã£ããã±ãããã¬ãŒãµãŒããããã°ããã¹ããªã©ã®ã³ãã³ãããããŸãã æ§æã¢ãŒãïŒ
conf t ïŒã¯ãããŸããã
ã€ããŒãã«ã¢ãŒãããèšå®ã§ããå¯äžã®ãã®ã¯ãåãCLIã«å¯ŸããŠãŠãŒã¶ãèªèšŒãã
aaa-serverã§ãã ãŸãã2ã€ã®ãªãã·ã§ã³ããããŸãããããã¯ã¢ã«ãŠã³ãã¢ã¯ã»ã¹å¶éããŸãã¯ãã®ãããªASAvã€ã¡ãŒãžã®ããããã§ãããååã¯éåžžã«æšæºçã§ãïŒ
asa961-smp-k8.bin ïŒã ããã§ãã衚瀺ãããæ§æãæ
éã«æ€èšãããšã2çªç®ã®ãªãã·ã§ã³ã®åŸåãçŸããŸãããæåã®ãªãã·ã§ã³ãé¢äžããªãããã§ã¯ãããŸããã
ã«ãŒãã£ã³ã°èšå®å®éãããã¯FMCãä»ããASAæ©èœã®ãŸãã«èšå®ã§ãã ãã¹ãŠã®èšå®ã¯ã[ããã€ã¹]-> [ããã€ã¹ç®¡ç]ãš[ãªããžã§ã¯ã]ã¿ãã®2ã€ã®ã¿ãã§å®è¡ãããŸãã [ãªããžã§ã¯ã]ã¿ãã§ãBGPã®SLAãã«ãŒãããããACLããã³[ASãã¹ãã³ãã¥ããã£ãªã¹ããããªã·ãŒãªã¹ã]ã®æšæºã®ASAèšå®ã確èªã§ããŸãã
å³8-ASAã¯ã©ã·ãã¯èšå®ã®ã³ã³ããŒãã³ã[ãªããžã§ã¯ã]ã¿ãã®ãã¹ãŠã®ã«ã¹ã¿ã ããªããžã§ã¯ããã¯ãããŸããŸãªããªã·ãŒãç¹ã«[ããã€ã¹ç®¡ç]ã¿ãã§ããã€ã¹ã«é©çšãããããªã·ãŒã§ããã«äœ¿çšããããã«äœæãããŸãã
CLIã®ãªããžã§ã¯ãFMCã«1ã€ãŸãã¯å¥ã®ããªããžã§ã¯ããã®èšå®ãååšããã©ã®ããªã·ãŒã§ã䜿çšãããŠããªãå Žåã§ãããã®ãããªããªããžã§ã¯ããã¯CLIã«è¡šç€ºãããªããšããäºå®ãèæ
®ãã䟡å€ããããŸãã
[ããã€ã¹ç®¡ç]ã¿ãã®ããªã·ãŒèšå®ã«ã¯æ¬¡ã®ãã®ãå«ãŸããŸãã
1.ã»ã¯ã·ã§ã³ããã€ã¹ãå¥ã®FPã»ã³ãµãŒãã»ããã¢ããããå Žåãåæ§ã§ãã
å³9-ããã€ã¹ã»ã¯ã·ã§ã³2.ã«ãŒãã£ã³ã°ãéçããã³åçïŒ
EIGRP ãOSPFãRIPãBGPã
ãã«ããã£ã¹ã ïŒã æããã«ãBGPãèšå®ããæ©èœã«ã€ããŠã¯ãä»®æ³ASAã®ããŒãžã§ã³9.6ïŒ1ïŒã«æè¬ããå¿
èŠããããŸãã
å³10-ã«ãŒãã£ã³ã°ã®ã»ããã¢ãããŸããSLAããªããžã§ã¯ãããéçã«ãŒãã«é©çšããCLIã§è¡šç€ºããäŸã次ã«ç€ºããŸãã
å³11-SLAã»ããã¢ããã®äŸ3. NATãããã§ã¯ããã¥ã¢ã³ã¹ãšå¶éãªãã§ãNATã«ãŒã«ã®ãã¹ãŠã®ããªã¢ã³ãã䜿çšã§ããŸãã
å³12-å€æã«ãŒã«ã®èšå®4.ã€ã³ã¿ãŒãã§ã€ã¹ã®æ§æãå³13-ã€ã³ã¿ãŒãã§ã€ã¹ã®æ§æã€ã³ã¿ãŒãã§ãŒã¹ã§ã¯ã1ç¹ãé€ããŠãã¹ãŠãéåžžã«æšæºçã§ããéåžžã®ã»ãã¥ãªãã£ã¬ãã«ã¯èšå®ã§ããããã¹ãŠã®ã€ã³ã¿ãŒãã§ãŒã¹ã«ã¯ãŒãã»ãã¥ãªãã£ã¬ãã«ãèšå®ãããŠããŸãã ãã ããæ§æã«åãã¬ãã«ã®ã»ãã¥ãªãã£ïŒ
åãã»ãã¥ãªãã£ãã©ãã£ãã¯èš±å¯ã€ã³ã¿ãŒã€ã³ã¿ãŒãã§ã€ã¹ ïŒã®ã€ã³ã¿ãŒãã§ã€ã¹éã§ãã©ãã£ãã¯ãæž¡ãèš±å¯ããªããšããäºå®ã«ããããããããã¹ãŠãæ£åžžã«æ©èœããŸãã
åãã»ãã¥ãªãã£ãã©ãã£ãã¯ã®ã€ã³ã¿ãŒãã§ã€ã¹éã¢ã¯ã»ã¹èš±å¯ 5.ã€ã³ã©ã€ã³ã»ããã®ã»ããã¢ãããã¿ããã¢ãŒã -ãã¹ãŠã®ãã©ãã£ãã¯ãã»ã³ãµãŒã«æž¡ãã®ã§ã¯ãªãããã©ãã£ãã¯ã®ã³ããŒã®ã¿ãã»ã³ãµãŒã«å°éãããããã¢ã¯ãã£ããªã¢ã¯ã·ã§ã³ã¯ãã©ãã£ãã¯ã«é©çšãããŸããã ãã ããåæã«ã€ãã³ãïŒIPSã€ãã³ããªã©ïŒãçæãããŸãã éžæãããã€ã³ã¿ãŒãã§ã€ã¹ãã¢ã®ãã©ãã£ãã¯ã®äžçš®ã®ç£èŠã¢ãŒãïŒåå¥ã®FPã»ã³ãµãŒãšæ¯èŒããå Žåã®ãã¹ãã³ã¢ãŒããïŒã
ãªã³ã¯ç¶æ
ã®äŒæ -ãã€ãã¹ã¢ãŒãããã§ãã¯ããã«ãã¹ãŠã®ãã©ãã£ãã¯ãã¹ããããããã¢ã®ã€ã³ã¿ãŒãã§ã€ã¹ã®1ã€ãããŠã³ç¶æ
ã§éä¿¡ãããå Žåã2çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ãåãããšãèµ·ãããŸãïŒåé¡ã®ããã€ã³ã¿ãŒãã§ã€ã¹ãã¢ããç¶æ
ã«æ»ããšããã«ã2çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ãèªåçã«ç«ã¡äžãããŸãïŒã
å³å¯ãªTCPåŒ·å¶ -TCPã»ãã·ã§ã³ã®ããªãã«ãã³ãã·ã§ã€ã¯å¶åŸ¡ãæå¹ã«ããŸãã Tapã¢ãŒããšStrict TCP Enforcementãåæã«æå¹ã«ããããšã¯ã§ããŸããã
å³14-ã€ã³ã©ã€ã³ã»ããã®æ§æ6. DHCPãµãŒãã¹ãæ§æããŸãã3ã€ã®ãªãã·ã§ã³ïŒDHCPãµãŒããŒãDHCPãªã¬ãŒãããã³DDNSã
å³15-DHCPèšå®ããããããã ãã§ãã åŸæ¥ã®ãã©ãã£ãã¯æ€æ»ã®ãã©ã¡ãŒã¿ã«é¢ããŠã¯ãå€æŽããããšã¯ã§ããŸããããCLIã§ã¯ipãªãã·ã§ã³ããã³tcpã®è¿œå ãªãã·ã§ã³ãšãã圢ã§è¥å¹²ã®è¿œå ãå ããããŠãããããéåžžã«æšæºçã«èŠããŸãã
ãµãã¹ã¯ãªãã·ã§ã³ããªã·ãŒã®æ§æïŒNGFWãNGIPSãAMPïŒãã¹ãŠã®ããªã·ãŒã¯ã以åãšåãæ¹æ³ã§æ§æãããŸãã äž»ãªããšã¯ãããããå±éãããšãã«å¿
èŠãªããã€ã¹ãéžæããããšãå¿ããªãããšã§ãã èå³æ·±ãç¹ã¯ãã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒïŒNGFWïŒã§ããèšå®ããã³é©çšããããã¹ãŠã®ã«ãŒã«ã¯ãCLIã§è¡šç€ºã§ããŸãã CLIã§ã¯ãç¹å®ã®ååãæã¡ãããå
·äœçãªæ§æãæã€ACLãšããŠè¡šç€ºãããŸãã
å³16-ã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒã«ãŒã«ããããŠããã§ã®äž»ãªããšã¯ããã®ãããªACLãã°ããŒãã«ã«é©çšããïŒ
ã¢ã¯ã»ã¹ã°ã«ãŒãCSM_FW_ACL_ global ïŒãããã«ãACLã®æåŸã«ã«ãŒã«ã
æåŠããã¯ã©ã·ãã¯ãååšããªããšããããšã¯ãå®éã«ååšããªãããšãæå³ããŸãã äœæãããã«ãŒã«ïŒå€åŽããå
åŽãžã®æ¹åãå«ãïŒã«è©²åœããªããã¹ãŠã®ãã©ãã£ãã¯ã¯ããããã©ã«ãã¢ã¯ã·ã§ã³ãïŒããã©ã«ãã¢ã¯ã·ã§ã³ãå³16ïŒã«ãã£ãŠåŠçãããŸãã ãããã£ãŠããã¹ãŠã®çä¿¡ãã©ãã£ãã¯ãèš±å¯ãããç¶æ³ãåé¿ããããã«ãã«ãŒã«ã®æºåã«ç¹å¥ãªæ³šæãæã䟡å€ããããŸãã ãã¡ã€ã«ããªã·ãŒãŸãã¯IPSããªã·ãŒã®æ§æã«åŸ®åŠãªéãã¯ãããŸããã§ããã
ãããã«äžèŠãããŒãžã§ã³6.0.1 FTDã¯
éåžžã« ãçãã®ããã«èŠããŸããããããã¯æåã®ããŒãžã§ã³ã§ããããã¢ããããŒãã¯ããããã«ãããŸãïŒå·çæç¹ã§ãããŒãžã§ã³6.0.1.1ãžã®ã¢ããã°ã¬ãŒãããªãªãŒã¹ãããããã«ã¯å€æ°ã®ãã°ä¿®æ£ãå«ãŸããŠããŸãïŒã çŸæç¹ã§ã¯ãã¯ã©ã·ãã¯ASAã®ãã¹ãŠã®æ©èœãæ°ãããã©ãããã©ãŒã ã«ç§»è¡ããããšã¯ã§ããŸããããã¡ãããVPNã®æ¬ åŠã¯ç¹ã«æ¥ããããããšã§ãã ãããã«ãããASA FTDã«åºã¥ããœãªã¥ãŒã·ã§ã³ã¯ãFirePOWERæ©èœã®ã¿ãå¿
èŠãªç¶æ³ã«é©ããŠããŸãã ãã®ä»ã®ç¶æ³ã§ã¯ãFirePOWERãµãŒãã¹ã§Cisco ASAã®ãã¹ããªãããããŒãžã§ã³ã䜿çšããå¿
èŠããããŸãã ãããŠãæåŸãŸã§èªãã§ïŒãŸãã¯æåŸããå§ããŠïŒãã®ãããªãœãªã¥ãŒã·ã§ã³ã䜿çšããããšãçå£ã«èããïŒãŸãã¯æ¢ã«äœ¿çšããŠããïŒäººã«ãšã£ãŠã¯ãå°ããªãã©ã€ãããã¯ãã¯ã«ããã®äžã«ãããŸãã
ãµã€ãéVPNã®æ»ç¥ãµã€ãéVPN
æŸèæãèšå®ã§ããŸãã SSHçµç±ã§ã¢ã¯ã»ã¹ã§ããŸããã¯ããæ§æãç·šéããããšã¯ã§ããŸããã ãããããããããŒãããããšãã§ããŸã-
ã³ããŒã³ãã³ãã¯å®å
šã«å©çšå¯èœã§ãã å¿
èŠãªããšã¯ãå®è¡ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ãããšãã°tftpãµãŒããŒã«ã¢ããããŒãããŠç·šéããããŒããçŽãããšã ãã§ãã VPNã«å¿
èŠãªãã¹ãŠã®è¡ã¯ãæ§æãã¡ã€ã«ã®æåŸãã2çªç®ã®è¡ãšæåŸã®è¡ïŒCryptochecksumããã³endïŒã®éã®ã®ã£ããã«è¿œå ã§ããŸãã
Cryptochecksum:073c34a024b2cff7f7303a5c888c2c61 crypto ikev1 policy 10 authentication pre-share encryption 3des hash sha group 2 lifetime 86400 crypto ikev1 enable outside crypto ipsec ikev1 transform-set ESP-AES-SHA esp-aes-256 esp-sha-hmac access-list crypto-acl extended permit ip host 192.168.20.5 host 172.25.25.20 crypto map CMAP 10 match address crypto-acl crypto map CMAP 10 set peer 192.168.200.252 crypto map CMAP 10 set ikev1 transform-set ESP-AES-SHA crypto map CMAP interface outside tunnel-group 192.168.200.252 type ipsec-l2l tunnel-group 192.168.200.252 ipsec-attributes ikev1 pre-shared-key 123456 : end
FTDäžã®èšå®ãã¡ã€ã«ã®å Žæãæ確ã«ç€ºããã³ãã³ãã䜿çšããŠãæºåãããèšå®ãèªã¿èŸŒãå¿
èŠããããŸãã
copy tftp system:running-config
ãã¡ã€ã«ãã³ããŒãããåŸãSSHæ¥ç¶ãåæããããããåæ¥ç¶ããŠæ§æãä¿åããå¿
èŠããããŸãïŒ
ã¡ã¢ãªã®æžã蟌㿠ïŒã å察åŽã§é©åãªæ§æãå®äºãããšãæ¬æ Œçãªåäœãããµã€ãéVPNãåŸãããŸãã
ãããŠããã¹ãŠã¯äœããããŸãããã1ã€ã®ãã¥ã¢ã³ã¹ã§ãªããã°ããæŸèæãã§ã¯ãããŸããããã®æ¹æ³ã§äœæ
ããããã®æå·ã«ãŒãçšã«
äœæããã
ã¢ã¯ã»ã¹ãªã¹ãã¯ãFMCã³ã³ãœãŒã«ã§å€æŽãé©çšãããã³ã«FTDèšå®ããåé€ãããŸãïŒDeployãå®è¡ããŸãïŒ ã ãã®ç¶æ³ã§ã¯ãããŒãžã§ã³9.2ïŒ1ïŒããASAã«è¿œå ãããEmbedded Event ManagerïŒEEMïŒã圹ç«ã¡ãŸãã VPNèšå®ãšåãæ¹æ³ã§ãEEMèšå®ã«è¿œå ããŸãã
event manager applet cryptoACL event timer watchdog time 5 action 0 cli command "access-list crypto-acl extended permit ip host 192.168.20.5 host 172.25.25.20" action 1 cli command "crypto map CMAP 10 match address crypto-acl" output none
ãã®ãããªEEMã¯ãå¿
èŠãªACLã5ç§ããšã«æ§æã«è¿œå ããŸãã ãŸããæ§æããACLãåé€ãããšãã€ã³ãã£ã³ã°ãåé€ããããããACLãã€ã³ãã£ã³ã°ã³ãã³ããæå·ã«ãŒãã«è¿œå ããå¿
èŠããããŸãã ãããã£ãŠãå®å
šã«æ©èœããVPNãååŸããŸãã
ãã®ãããªå®è£
ã§ã¯ãFMCããFTDãžã®ããªã·ãŒã®å±éã®ç¬éã«ãã±ããæ倱ãäºæ³ãããŸãã
EEMã®
ã€ãã³ãã¿ã€ããŒã®å¯èœãªä»£æ¿æ¹æ³ã¯ãç¹å®ã®IDïŒ
ã€ãã³ãsyslog id ïŒãæã€ãã°ã«ã¡ãã»ãŒãžã衚瀺ããããšãã«ã¢ã¯ã·ã§ã³ãå®è¡ããããšã§ãã ãã®ãªãã·ã§ã³ã¯ãã¹ããããŠããªãããããã®æåã«ã€ããŠã¯äœãèšããŸããïŒIDãæ£ããéžæãããŠããå Žåã§ãïŒã
UPDïŒ2016幎9æ2æ¥ïŒïŒ8æ29æ¥ãTsiskaã¯ããŒãžã§ã³6.1ã®ã¢ããããŒãããªãªãŒã¹ããŸããã å
¬åŒWebãµã€ãã®
ãªãªãŒã¹ããŒãã«èšèŒãããŠããã¢ããããŒãã®å®å
šãªãªã¹ãã
ããããã®ã¢ããããŒããããããããã¯ãã¹ãŠ
ãããããŠæ¥œããã§ãã ãããã®ããã€ãã次ã«ç€ºããŸãã
- ã¿ãŒããã«ãµãŒããŒçšã®TSãšãŒãžã§ã³ãïŒVDI IDãµããŒãïŒã
ããã§ã端æ«ã®èåŸã«ãããŠãŒã¶ãŒãèªèã§ããããã«ãªããŸããã åäœã®åçã¯ãCheck Pointã§ã®åäœã«äŒŒãŠããŸã-åãŠãŒã¶ãŒãžã®ããŒãç¯å²ã®å²ãåœãŠã ç§ã¯äœãã»ã®ããããŸãããã ãªãåã«ãããªãã®ã§ããïŒ ãšã«ãããããã£ãã - KerberosèªèšŒã
ã·ã³ã°ã«ãµã€ã³ãªã³ãæ¯æŽã§ããŸãã 圌ããåŸ
ã£ãŠããŸãããããããšãã - ã¬ãŒãå¶éã
ããã§ããããã¯ãŒã¯ããŸãŒã³ããŠãŒã¶ãŒ/ã°ã«ãŒããã¢ããªã±ãŒã·ã§ã³ãããŒããããã³ISEããåä¿¡ãããã©ã¡ãŒã¿ãŒã§åž¯åå¹
ãåæžã§ããŸãã - ãµã€ãéVPNã
ããã§ããŒããªãã§åäœããã¯ãã§ãã - ä»®æ³åãµããŒãã®åŒ·åã
KVMãåŸ
ã¡ãŸããHyper-VãåŸ
ã¡ãŸãã
ãã¹ãŠãã¯ãŒã«ã«èŠããŸãããå®éã«ã¯ãã¹ããããŠããªããããå®éã®ç¶æ³ã«ã€ããŠã¯äœãèšããŸããã å°ãªããšãä»ã®ãšããã