å
éšãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãååŸããããšã«ãããæ»æè
ã¯æ¯èŒçç°¡åã«é£æ¥ããŒããæ¢çŽ¢ããéä¿¡ãããæ
å ±ãåéã§ããäžè¬ã«ãã¹ãŠããã§ã«å€±ãããŠããããã«èŠããŸãã
ããã«ãããããããã¢ã¯ã»ã¹ã¬ãã«ãå¶åŸ¡ããæ£ããã¢ãããŒãã§ã¯ãåè¿°ã®æé ã¯éåžžã«è€éã«ãªãå¯èœæ§ããããŸãã åæã«ãæªæã®ããç°åžžã«æ°ä»ããååã«æºåããããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ããããã¿ã€ã ãªãŒã«éç¥ããæ害ã®è»œæžã«åœ¹ç«ã¡ãŸãã
ã«ããã®äžã«ã¯ããã®æ©èœãå®çŸããã®ã«åœ¹ç«ã€ã¡ã«ããºã ã®ãªã¹ãããããŸãã
Wikiãäžå¿
èŠã«æ£åœåããããšãªãäžè¬çãªçµã蟌ã¿ãè¡ããããšæããŸãããããã§ãæ§æã®ããªãšãŒã·ã§ã³ã®èª¬æããããŸãããããã§ãèšäºãå€éšã®èªè
ã«ãšã£ãŠãã芪ãã¿ãããããã«æè²ããã°ã©ã ã«éåŽããããšããããŸãã
èšäºã¯èšå€§ã§ãããç§ã®æèŠã§ã¯ã倧ããããèšäºã¯èªãŸããŸããããããªããšãªããã¹ã¿ãŒããšããèãã§é·ãç®±ã«ç©ã¿äžããããŸãã ãã®ãããçŽ æãåå²ããå¿
èŠããããŸããããæåããã®ã§ãããŸãäžè¬çã§ã¯ãªãïŒå°ãªããšãç§ãã¡ã«ãšã£ãŠã¯ïŒæè¡ã§2çªç®ã®éšåãæ§æããŸãã
å
容ïŒ
ãã¯ãããžãŒã¯ã·ã¹ã³ã¹ã€ããã«åºã¥ããŠèª¬æãããŠããŸããå
·äœçã«ã¯ããã¹ãã¢ãã«ãšãã¹ãããŒãžã§ã³ã¯æ¬¡ã®ãšããã§ãã
ç§ã¯ããã®ãã³ããŒãæãåºãæ®åããæãæ
å ±éãå€ãããã®ãããªãããã¯ãç 究ããåå¿è
ã®é¢å¿ãé«ããŠãããšæããŸãã
ããã§ããtsiskaã§ç¹å®ã®åæè¡ãç¿åŸããåŸã30åããã°ä»ã®ãã³ããŒãæ£ããæ§æããããšã¯é£ãããªããšç¢ºä¿¡ããŠããŸãã éåžžã®ãŠãŒã¶ãŒã¬ã€ãã
åæ§ã®ããšã
ãããš
ããã§æºãã
ããããšãã§ããŸãããæ
å ±ã¯ãã§ã«ããã«ååšãããã®ãšéè€ããªããšæã
ãŸã ã
ããŒãã»ãã¥ãªãã£
説æ
ãã®æè¡ã¯ãã¹ã€ããã«æ¥ç¶ãããããã€ã¹ãå¶åŸ¡ããMACã¢ãã¬ã¹ããŒãã«ã®ãªãŒããŒãããŒãç®çãšããç°åžžãŸãã¯æ»æïŒCAMããŒãã«ãªãŒããŒãããŒïŒãé²ãããã«èšèšãããŠããŸãã
ããŒãã»ãã¥ãªãã£ã䜿çšãããšãç¹å®ã®ã¹ã€ããããŒãïŒOSIã®ç¬¬2ã¬ãã«ã§åäœãããããã¯ãŒã¯ããŒãïŒãŸãã¯VLANããšã®MACã¢ãã¬ã¹ã®æ倧æ°ã確ç«ãããæå®ãããMACã¢ãã¬ã¹ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ãããŸãã
MACã¢ãã¬ã¹ã䜿çšããæ¹æ³ïŒ
- åç -èš±å¯ãããæ倧å€ã«éãããŸã§ãMACã¢ãã¬ã¹ãã¹ãããããŠïŒäžå®æéïŒèšæ¶ããŸãã
- éç -äºåã«æåã§å
¥åãããMACã¢ãã¬ã¹ã®ã¿ãèš±å¯ããŸãïŒåçã¿ã€ããšäžç·ã«äœ¿çšã§ããŸãïŒã
- ã¹ãã£ãã㌠-æ°ããMACã¢ãã¬ã¹ãæ§æã«æžã蟌ãããšã§æããŸãã
æš©éã®æ¿«çšã®å Žåã®æªçœ®ïŒ
- Potect-è¿œå ãŸãã¯æªæå®ã® MACã¢ãã¬ã¹ã®å Žåãæ°ããMACã¢ãã¬ã¹ãéå§ãããsyslogãŸãã¯SNMPãã©ãããçæãããã€ã³ã¿ãŒãã§ãŒã¹ãããããããŸããã
- å¶éã¯ä¿è·ãšåãã§ããããã°ããã³/ãŸãã¯SNMPãã©ãããè¿œå ãããŸãã ãŸãã
show port-security interface <name>
äžã®ã«ãŠã³ã¿ãŒã«å ±åãshow port-security interface <name>
ã
- ã·ã£ããããŠã³ ïŒããã©ã«ãã§éžæïŒ-åã®ã¢ã¯ã·ã§ã³ããã ãããã©ã¹ã€ã³ã¿ãŒãã§ã€ã¹ã¯errdisableã¹ããŒã¿ã¹ã«ãªãããã©ãã£ãã¯ã®éä¿¡ãåæ¢ããŸãã
- VLANã®ã·ã£ããããŠã³ -åã®äŸãšåæ§ã«ããã®VLANã®ãã¹ãŠã®ã€ã³ã¿ãŒãã§ãŒã¹ã¯errdisableã§ã®ã¿åäœããŸãã
æ§æ
ããŒãã»ãã¥ãªãã£ã¯ãã¹ã€ããããŒãã¿ã€ããæ瀺çã«èšå®ãããŠããå ŽåïŒã€ãŸããã¢ã¯ã»ã¹ãŸãã¯ãã©ã³ã¯ïŒã«ã®ã¿ã¢ã¯ãã£ãã«ã§ããŸãã ããŒããåçãªå ŽåïŒæ¢ã«ééã£ãŠããŸãïŒãPort-Securityãæå¹ã«ããããšã¯ã§ããŸããã
ã¢ã¯ã»ã¹ããŒã
ãã®ãã¯ãããžãŒã¯ãç¹å®ã®ã€ã³ã¿ãŒãã§ã€ã¹ã®èšå®ã¢ãŒãã§
switchport port-security ...ã³ãã³ãã䜿çšããŠèšå®ãããŸãã䜿çšå¯èœãªãªãã·ã§ã³ã¯æ¬¡ã®ãšããã§ãã
- ãšãŒãžã³ã° -åçMACã¢ãã¬ã¹ãæžãæãããããŸã§ã®æéééãèšå®ããŸãã
- mac-address-次ã®ãã©ã³ããžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸãã
ã€ãŸã èš±å¯/çŠæ¢ã¢ãã¬ã¹ãèšå®ããããéçã«ããããåŠç¿ããããã«äŒããŸãã
- æ倧 -èš±å¯ãããã¢ãã¬ã¹ã®å¶éã瀺ããŸãã
- éå -äžèšã®ã¢ã¯ã·ã§ã³ãèšå®ããŸãã
å¿
èŠãªãã®ãå¿
èŠã§ãªããã®ãèšå®ããŸãã æåŸã«ããªãã·ã§ã³ãªãã§
switchport port-security
ã³ãã³ãã䜿çšããŠãã¯ãããžãŒãã¢ã¯ãã£ãã«ããŸãã
ãã®çµæããã¹ãŠã次ã®ããã«ãªããŸãã
-解決ãããå Žåã¯ãã©ã®ãããŒãäžæã§ããã®æ°ã5çªç®ã«å¶éããæ倧å€ã5ã«èšå®ããéçã«èšå®ããªãã§ãã ããã ãªãã·ã§ã³ã§ãã©ã€ãã¿ã€ã ã瀺ããŸãã
-ããã€ã¹ãã¯ã€ã€ã®2çªç®ã®ç«¯ã«ããããšãããã£ãŠããŠãä»ã«äœãååšãããååšããªãå Žåã¯ãæ倧= 1ãã¢ãã¬ã¹ãéçã«æžã蟌ã¿ãŸãã
-æ°ããåŸæ¥å¡ãæ°ããPCãæã£ãŠããããŸãã¯MACã¢ãã¬ã¹ãèŠã€ããã®ãé¢åãªå Žåã¯ãStickyãå
¥ããŸããåæ¥ç¶åŸã«ç¢ºèªããŸãã
ãã©ã³ã¯ããŒã
åæ§ã«ãåäœãæå®ã§ããã®ã¯ç©çã€ã³ã¿ãŒãã§ã€ã¹ã«çžå¯Ÿçã§ã¯ãªããç¹å®ã®VLAN'aã§ãã ãããè¡ãã«ã¯ãæåŸã«vlanãåã®åã³ãã³ãã«è¿œå ããŸãã
確èªãã
show runã«é Œããã«ãPort-Securityã«é¢ããæ
å ±ãèŠã€ããããšãã§ããŸãã
show port-security
ã€ã³ã¿ãŒãã§ã€ã¹ããããã®ã¹ããŒã¿ã¹ãã¢ãã¬ã¹æ°ã«é¢ããåèšæ
å ±ã衚瀺ããŸããshow interface <name> switchport
ãã詳现ãªæ
å ±ïŒã«ãŠã³ã¿ãŒãåã
ã®ãªãã·ã§ã³ïŒ;show mac address-table ..
ãã©ã¹ãªãã·ã§ã³ã以äžã®ãªã¹ãã衚瀺ããŸãã
ããŒã ã¯ãMACã¢ãã¬ã¹ããŒãã«ã«é¢ããçŸåšã®æ
å ±ã確èªããŸãã ããšãã°ãç¹å®ã®VLANã®ããŒãã«å
ã®çŸåšã®ãšã³ããªæ°ãšäœ¿çšå¯èœãªãšã³ããªã®éã¯ã show mac address-table count vlan <id>
ã䜿çšããŠç¢ºèªãããŸãã
DHCPã¹ããŒãã³ã°
説æ
ãã®ãã¯ãããžãŒã¯ããããã¯ãŒã¯äžã§èš±å¯ãããŠããªãDHCPãµãŒããŒã®äœ¿çšãé²ããããšãã°äžéè
ïŒMITMïŒæ»æãå®è¡ããããšãå¯èœã«ããŸãã ãŸããDHCPæ¯æžæ»æïŒDHCP飢v /ãªãŒã¯ã·ã§ã³ïŒãããããã¯ãŒã¯ãä¿è·ããŸãããããã¯ç¹ã«é¢ä¿ãããŸããã
ãã®ãã¯ãããžãŒã¯ããããã¯ãŒã¯äžã®DHCPéä¿¡ãç£èŠããŸãããããã¯ãŒã¯ã¯ïŒäž»ã«ïŒ4ã€ã®ãã±ããã§æ§æãããŠããŸãã
- DHCPçºèŠ-ã¯ã©ã€ã¢ã³ããIP over DHCPã®èŠæ±ã®ã¿ãéä¿¡ããŸãã
- DHCPãªãã¡ãŒ-ãµãŒããŒãDHCPãµãŒããŒããã®æ§æææ¡ã®ã¿ãéä¿¡ããŸãã
- DHCPèŠæ±-ã¯ã©ã€ã¢ã³ããç¹å®ã®æ§æããã³ãµãŒããŒã®éžæã®ã¿ãéä¿¡ããŸãã
- DHCP ACK-ãµãŒããŒãæçµç¢ºèªã®ã¿ãéä¿¡ããŸãã
DHCPã¹ããŒãã³ã°ãã¢ã¯ãã£ãã«ããåã«ãDHCPãµãŒããŒãé
眮ãããŠãããä¿¡é Œã§ãããããŒããæå®ããå¿
èŠããããŸãã ä¿¡é Œã§ããããŒãã®ã¿ãDHCP OfferãšDHCP ACKïŒãµãŒããŒããã®ãã±ããïŒãéä¿¡ããŸãã ãã®æ¥ç¶ã§ã¯ããã®ã¹ã€ããã®ä»ã®ã€ã³ã¿ãŒãã§ã€ã¹ã®èåŸã«ããåäžã®ããã€ã¹ã¯DHCPãµãŒããŒãæäœã§ãããç¬èªã®ãããã¯ãŒã¯æ§æãªãã·ã§ã³ãæäŸããŸãã
DHCPã¹ããŒãã³ã°ãã¢ã¯ãã£ãã«ããåŸãã¹ã€ããã¯ãããã¯ãŒã¯äžã®DHCPéä¿¡ã®ç£èŠãéå§ããèŠæ±ãããããã€ã¹ã®MACã¢ãã¬ã¹ã§çºè¡ãããIPã¢ãã¬ã¹ãèå¥ãããã®æ
å ±ãDHCPã¹ããŒãã³ã°ãã€ã³ãã£ã³ã°ããŒãã«ã«ä¿åããããšãéåžžã«éèŠã§ãã
æ§æ
ip dhcp snooping trust
ã³ãã³ãã¯ãä¿¡é Œã§ããã€ã³ã¿ãŒãã§ã€ã¹ã®äžã§å
¥åãããŸãã
DHCPã®æ¯æžãé²ãããã«ãä¿¡é ŒãããŠããªãã€ã³ã¿ãŒãã§ã€ã¹ã¯ã
ip dhcp snooping limit rate <nr>
ã䜿çšããŠãåä¿¡ããã¯ã©ã€ã¢ã³ãèŠæ±ã®é »åºŠãæå®ããŸãã
æå¹ãªãã©ãã£ãã¯ãé®æããªãããã«ããã®ç¹æ§ãéå°è©äŸ¡ããªãããšãéèŠã§ãã Tsiskaã¯ãæ°åã10ãã®äœ¿çšãæšå¥šããŠããŸãã
ãã®åŸãDHCPã¹ããŒãã³ã°çšã®ç¹å®ã®VLANãæå®ãããªãã·ã§ã³ãªãã®ã³ãã³ãã§ãã¯ãããžãŒèªäœãçŽæ¥æå¹ã«ããŸãã
(config)# ip dhcp snooping vlan <id> (config)# ip dhcp snooping
確èªãã
- show ip dhcp snooping -DHCPã¹ããŒãã³ã°ãæå¹ã«ãªã£ãŠããä¿¡é Œã§ããããŒããšVLANã衚瀺ããŸãã
- show ip dhcp snooping binding -DHCPã¹ããŒãã³ã°ãæå¹ã«ãªã£ãŠããVLANå
ã§IP-MACãã€ã³ãã£ã³ã°ã衚瀺ãããããŒãã«ã衚瀺ããŸãã
ãã€ãããã¯ARPã€ã³ã¹ãã¯ã·ã§ã³
説æ
ãã®æè¡ã¯ãARPã¹ããŒãã£ã³ã°/ãã€ãºãã³ã°æ»æãé²ãããã«èšèšãããŠããŸããããã¯ããã©ãã£ãã¯ã€ã³ã¿ãŒã»ããïŒåã³ãäžéè
æ»æ/ MITMïŒãçµç¹ããåºæ¬çãªæ¹æ³ã§ããã被害è
ãšåããããŒããã£ã¹ããã¡ã€ã³ã«ååšããŸãã
æ§æ
ARPã¹ããŒãã£ã³ã°ãå¹æçã«é²æ¢ããã«ã¯ãã¹ã€ããã«MACã¢ãã¬ã¹/ IPã¢ãã¬ã¹æ
å ±ãå¿
èŠã§ãã åè¿°ã®ããã«ããã®æ
å ±ã¯DHCPã¹ããŒãã³ã°ããŒãã«ã«ä¿åãããŸãã ãããã£ãŠãããã2ã€ã®ãã¯ãããžãŒã¯ãã»ãŒåžžã«æ£ããæ§æãäžç·ã«äœ¿çšããŸãã
DHCPã¹ããŒãã³ã°ã§äœ¿çšããå Žåããã®ãã¯ãããžãŒã¯æ¬¡ã®ã³ãã³ãã§ã°ããŒãã«ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã¢ãŒãã§ã¢ã¯ãã£ãã«ãªããŸãã
(config)# ip arp inspection vlan <id>
ãã®åŸããã®VLANã§ã¯ãDHCPã¹ããŒãã³ã°ããŒãã«ã«è¡šç€ºãããããã€ã¹ã«å¯ŸããŠã®ã¿ãã©ãã£ãã¯ãèš±å¯ãããŸãã
ããã€ã¹ãDHCPã䜿çšã
ãªãå Žåãè¿œå ã®å¯Ÿçãè¬ããå¿
èŠããããŸãã ARPã€ã³ã¹ãã¯ã·ã§ã³ã§ã¯ãéçã¬ã³ãŒãã䜿çšã§ããŸãã ãã®ããã«ãARPã¢ã¯ã»ã¹ãªã¹ããäœæãããŸããããã¯ã次ã®ã³ãã³ãã䜿çšããŠã°ããŒãã«ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã¢ãŒãããäœæãããŸãã
(config)# arp access-list <name>
åäžã®ãšã³ããªã®æ§æã¯æ¬¡ã®ãšããã§ãã
ãããŠãŸã..åäžã®MACã¢ãã¬ã¹ãæå®ããããšã«å ããŠãarpã¢ã¯ã»ã¹ãªã¹ãã§ç¯å²ãæå®ã§ããŸãã ãããŠãããã¯å®äº
ã§ãïŒ éARP ãã¹ã¯ïŒ
ç§ã®æèŠã§ã¯ãããã¯ã²ã©ãæŸèæã§ãããäžçã¯çã£ãŠããŸãããä»ã®æ¹æ³ã§ã¯ãªãå Žå..
ãã®arpã¢ã¯ã»ã¹ãªã¹ãã®äžã«ãå¿
èŠãªãã¹ãŠã®éçãšã³ããªã瀺ãããŸãã ããã«ããã¯ãããžãŒã¯ä»¥åãšã¯
ç°ãªã ã
ãã£ã«ã¿ãŒãªãã·ã§ã³ã䜿çšããŠã¢ã¯ãã£ãã«ãªããŸãã
åå¥ã®ã€ã³ã¿ãŒãã§ã€ã¹ãä¿¡é Œæžã¿ãšããŠããŒã¯ã§ããŸãã ARPæ€æ»ã¯ããããã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ã¯å®è¡ãããŸããã
ã»ãšãã©ã®å Žåãä¿¡é Œã§ãããã©ã³ã¯ããŒããã€ã³ã¹ããŒã«ãããŸãïŒã¡ã«ããºã å
šäœãã¢ã¯ãã£ãã«ãã
åã« ããã®ããšãå¿ããªãã§ãã ããïŒã ãã ãããã®å Žåãããã©ã«ãã®ARPã¡ãã»ãŒãžå¶éãäžããããšãéèŠã§ããããã¯15ã§ãããç¹ã«ãã©ã³ã¯ã§ã¯çãããå¯èœæ§ããããŸãã 100ãå
¥ããããšããå§ãããŸãã
ãªãã·ã§ã³ã§ãARPããã³ã€ãŒãµãããããããŒã«MACã¢ãã¬ã¹ã®ãã§ãã¯ãè¿œå ã§ããŸãã ããã¯ã
ip arp inspection validate <option>
ã³ãã³ãã䜿çšããŠå®è¡ãããŸãã
åãªãã·ã§ã³ã®æ©èœã¯ã
ããã§åå¥ã«èªãããšãã§ã
ãŸã ã
確èªãã
ãã¯ãããžãŒã®ã¹ããŒã¿ã¹ãæå¹ã«ãªã£ãŠããããã¢ã¯ã»ã¹ãªã¹ãã䜿çšããŠããããè¿œå ãªãã·ã§ã³ã®æ€èšŒã¹ããŒã¿ã¹ãªã©ã確èªããŸãã æ
å ±ïŒ
show ip arp inspection vlan <id>
åã®ã³ãã³ãïŒè¡æ«ã«è¿œå ïŒã®äŸ¿å©ãªãªãã·ã§ã³ã¯ã
çµ±èš ïŒããããã«ãŠã³ã¿ãŒãªã©ã衚瀺ïŒãš
ã€ã³ã¿ãŒãã§ã€ã¹ ïŒä¿¡é Œã§ããã€ã³ã¿ãŒãã§ã€ã¹ãARPã¡ãã»ãŒãžã®å¶éïŒã§ãã
ãœãŒã¹ã¬ãŒã
説æ
ARPæ€æ»ã®ããã«ãµããããå
šäœããã§ãã¯ããå¿
èŠã¯ãªããããã®ãããªè
åšããããã€ãã®ããŒããä¿è·ãããå Žåã¯ããœãŒã¹ã¬ãŒãã䜿çšã§ããŸãã å®éã«ã¯ã埮åŠãªéãã¯ãããŸããããããã®æ©èœã¯äºãã«éè€ããŠããŸãã
ãã®ãã¯ãããžãŒã¯ãæå®ãããIP-MACãç¹å®ã®ç©çã€ã³ã¿ãŒãã§ãŒã¹ã«ãã€ã³ãããŸãã ãã®çµæãARPã¹ããŒãã£ã³ã°ãé²æ¢ããã1ã€ã®ãããã¯ãŒã¯ããŒããå¥ã®ãããã¯ãŒã¯ããŒãã«ä»£ãã£ãŠãã©ãã£ãã¯ãéä¿¡ã§ããªããªããIPããã³MACã®éä¿¡å
ã¢ãã¬ã¹ãå€æŽãããŸãïŒARPæ€æ»ã®å Žåãããã¯éèŠã§ã¯ãããŸãããå¯èœã§ãïŒã
æ§æ
ãœãŒã¹ã¬ãŒãã¯DHCPã¹ããŒãã³ã°ããŒãã«ã䜿çšããŸãã IP-MACãã³ãã«ã ãã§ãªããèåŸã«ç¹å®ã®ããŒããé
眮ãããŠããã€ã³ã¿ãŒãã§ã€ã¹ãå«ãŸããŠããŸãã
ããŒããåã³DHCPã䜿çšããªãå Žåãã°ããŒãã«æ§æã¢ãŒãã§æåãšã³ããªãäœæãããŸãã
(config)# ip source binding <mac.add.ress> vlan <id> <IP.add.re.ss> interface <name>
ãœãŒã¹ã¬ãŒãã¯ãã€ã³ã¿ãŒãã§ã€ã¹äžã§çŽæ¥ã¢ã¯ãã£ãã«ãªããŸãã
(config-if)# ip verify source port-security
確èªãã
ãã¯ãããžãŒã䜿çšããã¬ã³ãŒãã®ç¢ºèªã¯ã次ã®ã³ãã³ãã«ãã£ãŠå®è¡ãããŸãã
IPãœãŒã¹ãã€ã³ãã£ã³ã°ã瀺ããŠäžãã䟿å©ãªã®ã¯ããã®ã³ãã³ããDHCPããŒãã«ããååŸããæåèšé²ãšã¹ããŒãã³ã°ã®äž¡æ¹ã衚瀺ããããšã§ãã
Source Guardãã¢ã¯ãã£ãã«ãªã£ãŠããã€ã³ã¿ãŒãã§ã€ã¹ã®ãªã¹ãã¯ã次ã®ã³ãã³ãã§è¡šç€ºãããŸãã
show ip verify sourceä»ã¯ããã§ååã ãšæã
次åã¯ãã¹ã€ããã«ããä»ã®ã¢ã¯ã»ã¹ãªã¹ããšããããå¿
èŠãªçç±ã瀺ããŸãã åããµããããå
ã®éä¿¡ãå¶åŸ¡ããæ¹æ³ã ã€ã³ã¿ãŒãã§ã€ã¹ã®
errdisableã¹ããŒã¿ã¹ãžã®ç§»è¡ã®åŸ®åŠãªç¹ã匷調ããMACsecãå¿
èŠãã©ãããç解ããããšãã§ããŸãã