ãã®èšäºãæžããšããã¢ã€ãã¢ã¯ãã€ã³ã¿ãŒãããäžã§Huaweiãããã¡ã€ã¢ãŠã©ãŒã«ãã»ããã¢ããããããšã«é¢ããå°ãªããšãããã€ãã®æ
å ±ãèŠã€ããããšããåŸã«çãŸããŸããã ãã·ã¢èªã®ã»ã°ã¡ã³ãã§ã¯äœãèŠã€ãããŸããã§ãããè±èªåã®ã»ã°ã¡ã³ãã§ã¯ãã»ãšãã©ã以åã®ã¢ãã«ã®å€ãããŒã¿ãšããã¥ã¡ã³ããžã®ãªã³ã¯ã§ãïŒã¡ãªã¿ã«ãããã¯ãããªãã¯ãã¡ã€ã³ã®è£œé å
ã®Webãµã€ãã«ãããéåžžã«è©³çŽ°ã§ãïŒã
ä»ã®ã¡ãŒã«ãŒã®ãã¡ã€ã¢ãŠã©ãŒã«ã®äœ¿çšçµéšãããå Žåãããã¥ã¡ã³ãã¯Huawei USGãèµ·åããŠäœ¿çšããã®ã«ååãªã¯ãã§ãããçµéšããããã¹ãŠã®ãªãã·ã§ã³ãæ¢ã«è©ŠãããŠãããšãã«ããã¥ã¢ã«ã«ã¢ã¯ã»ã¹ã§ããããšãç¥ã£ãŠããŸãã ãããã£ãŠããã®èšäºã®ç®æšã®1ã€ã¯ããã®æ¯èŒçæ°ããæ©åšã®åæè©Šé転äžã®æéãç¯çŽããããšã§ãã ãã¡ããã1ã€ã®èšäºã§ã¯ãã¹ãŠã®æ©èœãã«ããŒããããšã¯ã§ããŸããããããã§èšå®ããäž»ãªåæã±ãŒã¹ãèæ
®ãããŸãã ããã§èª¬æããåºæ¬èšå®ã¯ååãšããŠãã¹ãŠã®ã€ã³ã¹ããŒã«ã§è¡ãå¿
èŠãããããããšã³ãžãã¢ã¯ãã®èšäºããããã¯ãŒã¯æ©åšã®ã€ã³ã¹ããŒã«ã®ããŒãã·ãŒããšããŠäœ¿çšã§ããŸãã
åºæãã®èšäºã¯ç«¶åä»ç€Ÿãšæ¯èŒããããšã¯ãªããäžè¬çã«æäœéã®ããŒã±ãã£ã³ã°ã§ã¯ãªãã管çã«é¢ãã話ã«ãªããŸãã Huawei USGã®äž»ãªç«¶åçžæã¯Cisco ASAãCheckPointãFortiNetãªã©ã§ãããããããæè¿ã®äžåœã®æ©åšãç¹ã«æ
å ±ä¿è·æ©åšãžã®é¢å¿ã®é«ãŸãã¯ãäžèšã®ã¢ã¡ãªã«ã®ãã³ããŒã®ã茞å
¥ä»£æ¿ãã®ãããã¯ã«é¢é£ããŠããŸãã
Huawei USGå®èŠãšç°¡åãªä»æ§
Huawei USGã¯ãæ°äžä»£ã®æ
å ±ä¿è·ããã€ã¹ããŸãã¯ããããNGFWïŒæ¬¡äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ïŒã§ãã NGFWã¯ãåäžä»£ã®ä¿è·ããŒã«ãšã¯ç°ãªãã詳现ãªãã±ããåæïŒL7ãŸã§ïŒãå®è¡ããã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§ãã©ãã£ãã¯ãæ€æ»ããIPSãçµ±åããä»ã®åæ§ã®ããã€ã¹ãšçžäºäœçšããæ¹åããã®æœåšçãªæ»æã«é¢ããæ
å ±ãåä¿¡ã§ããŸãã ãŸããã·ã³ãã«ãªDLPïŒæ
å ±æŒããæ€åºïŒã¡ã«ããºã ãåããŠããŸãã
USG 6300ã·ãªãŒãºã¯ãäžå°äŒæ¥ã察象ãšããææ°ã®ããã€ã¹ã·ãªãŒãºã§ãã 以äžã®è¡šã«ç°¡åãªä»æ§ã瀺ããŸãã
è¡šã«ãªã¹ããããŠãã6300ã·ãªãŒãºããã€ã¹ã¯ã19ã€ã³ãã©ãã¯ããŠã³ãçšã«èšèšãããŠããŸãã ãã®èšäºãæžããŠãããšããããã€ã¹ã¯ãã¹ã¯ãããããŒãžã§ã³ã§äœæãããHuawei USG 6320ã䜿çšããŠããŸããã
ãã®ç°¡åãªç¹åŸŽã¯æ¬¡ã®ãšããã§ãã
ã€ã³ã¿ãŒãã§ãŒã¹ïŒ8GE
é»æºïŒACã¢ããã¿ãŒ
ãã¡ã€ã¢ãŠã©ãŒã«ã¹ã«ãŒãããïŒ2ã®ã¬ããã/ç§
IPSã¹ã«ãŒãããïŒ700 Mbit / s
IPS + AVã¹ã«ãŒãããïŒ700 Mbit / s
åæã»ãã·ã§ã³ïŒ500,000
VPNã¹ã«ãŒãããïŒIPSecïŒïŒ400Mbit / s
Huawei USG6320ãšãã®ã·ãªãŒãºã®ã©ãã¯ããŒãžã§ã³ã®äž»ãªéãã¯ãããŒããã©ã€ãããã®äžã«é
眮ã§ããªãããšã§ããããã¯ãäž»ã«WEBã€ã³ã¿ãŒãã§ã€ã¹ããã®ããã€ã¹ã«åºã¥ãããã°ã®èšé²ãšçæã«äœ¿çšãããŸãã ãã以å€ã®å Žåãã·ãªãŒãºïŒããã³å€ã6600ã·ãªãŒãºãïŒã®ãã¹ãŠã®ããã€ã¹ã¯åãVRPãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§åäœããŸãã ã€ãŸããå°ãªããšãå·çæç¹ã§ã¯ã6300ã·ãªãŒãºãš6600ã·ãªãŒãºã®ããã¡ãŒã ãŠã§ã¢ããã¡ã€ã«ã¯åãã§ãã
ããã€ã¹ãåããŠãªã³ã«ãã
ã³ã³ãœãŒã«ããŒããä»ããŠæšæºãã©ã¡ãŒã¿ãŒïŒããªãã£ãªãã®9600ããŒïŒã§æ¥ç¶ããé»æºããªã³ã«ããŠããŠã³ããŒããéå§ãããŸãã
*********************************************************** * * * NGFW * * * *********************************************************** Base Bootrom Ver : 060 Dec 4 2015 06:55:42 Extended Bootrom Ver : 060 Dec 4 2015 07:00:34 CPLD BigVer : 02 CPLD SmlVer : 00 2015-03-19 PCB Ver : SUE1MPUB REV A BOM Ver : 000 CPU L2 Cache : 2048 KB CPU Core Frequency : 1000 MHz BUS Frequency : 600 MHz Mem Size : 2048 MB Press Ctrl+B to enter main menu...
ããŠã³ããŒãã®æåã«ã念ã®ãããããã€ã¹ãå·¥å Žåºè·æã®èšå®ã«ãªã»ããããŸãã ãŸãããã®æé ã¯ãæ¢ã«æ§æãããŠããæ°ããããã€ã¹ä»¥å€ãæ±ã£ãŠãããã³ã³ãœãŒã«ã®ãã¹ã¯ãŒããããããªãå Žåã«åœ¹ç«ã¡ãŸãã
BootRomã¡ãã¥ãŒã«å
¥ãã«ã¯ãããŒãã®åæ段éã§Ctrl + BãæŒãå¿
èŠããããŸãã ã»ãšãã©ã®Huaweiãããã¯ãŒã¯ããã€ã¹ã§BootRomã«ãã°ã€ã³ããããã®ããã©ã«ãã®ãã¹ã¯ãŒãã¯OïŒm15213ã§ãïŒæåã®æåã¯0ã§ã¯ãªãOã§ãïŒã ãããã¡ã€ã³ã®BootRomã¡ãã¥ãŒã®å€èŠ³ã§ãã
====================< Extend Main Menu >==================== | <1> Boot System | | <2> Set Startup Application Software and Configuration | | <3> File Management Menu... | | <4> Load and Upgrade Menu... | | <5> Modify Bootrom Password | | <6> Reset Factory Configuration | | <0> Reboot | | ---------------------------------------------------------| | Press Ctrl+T to Enter Manufacture Test Menu... | | Press Ctrl+Z to Enter Diagnose Menu... | ============================================================ Enter your choice(0-6):
ã¡ãã¥ãŒé
ç®6ãéžæããŠå·¥å Žåºè·æèšå®ã«ãªã»ããããã¡ãã¥ãŒé
ç®0ãéžæããŠãªã»ããããŸãã
ããŠã³ããŒããå®äºãããšãããã€ã¹ã¯ã³ã³ãœãŒã«ããŒããä»ããŠç®¡ççšã®ãã°ã€ã³ãšãã¹ã¯ãŒããå
¥åããããã«æ±ããŸãã å·¥å Žåºè·æã®èšå®ã«æ»ã£ããããã³ã³ãœãŒã«ãžã®ããã©ã«ãã®ãã°ã€ã³ãšãã¹ã¯ãŒãã¯æ¬¡ã®ããã«ãªããŸãã
Login: admin Password: Admin@123
Huawei USGã³ãã³ãã©ã€ã³
Huawei USGã³ãã³ãã©ã€ã³ã¯ãããããªãã¥ã¢ã³ã¹ãé€ããCiscoã³ãã³ãã©ã€ã³ã«éåžžã«äŒŒãŠããŸãã ã·ã¹ã³ã«ã¯3ã€ã®CLIã³ãã³ãã¢ãŒãããããŸãã
- ãŠãŒã¶ãŒã¢ãŒãïŒã¢ã€ã³ã³>ïŒ;
- ç¹æš©ã¢ãŒãïŒã¢ã€ã³ã³ïŒãenableã³ãã³ãã«ããå
¥åïŒ;
- ã°ããŒãã«ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã¢ãŒãïŒç¹æš©ã¢ãŒãããconfigure terminalã³ãã³ãããå
¥åïŒã
ã·ã¹ã³ãšã¯ç°ãªããHuaweiãããã¯ãŒã¯æ©åšã®ã³ãã³ãã©ã€ã³ïŒUSGã ãã§ãªããã¹ã€ãããšã«ãŒã¿ãŒïŒã¯2ã€ã®ã¢ãŒãã§æ§æãããŠããŸãã
- ãŠãŒã¶ãŒã¢ãŒãïŒã¢ã€ã³ã³>ïŒ;
- ã·ã¹ãã ãã¥ãŒã¢ãŒãïŒã¢ã€ã³ã³ïŒããŠãŒã¶ãŒã¢ãŒãããã®system-viewã³ãã³ãã«ããå
¥åïŒã
ã·ã¹ãã ãã¥ãŒã¯ãç¹æš©ã¢ãŒããšã°ããŒãã«ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã¢ãŒããçµã¿åããããã®ã§ãã
ããã«ããã€ãã®éãïŒ
- Ciscoã®showã³ãã³ãã¯ãHuaweiã®VRP衚瀺ã³ãã³ãã«äŒŒãŠããŸãã
- Ciscoã®noã³ãã³ãã¯ãHuaweiã®ã¢ã³ãã¥ã«äŒŒãŠããŸãã
ãããã£ãŠãHuaweiã§ã®çŸåšã®äœæ¥æ§æïŒCiscoã®å Žåã¯show runnïŒã®è¡šç€ºã¯æ¬¡ã®ããã«ãªããŸãã
display current-configuration
CLIãšåãããã«ãã·ã¹ã³ã¯ã³ãã³ãå
šäœãå
¥åããå¿
èŠã¯ãããŸããã ã³ãã³ãã®äžéšãèªèã«ååã§ããå Žåãã³ãã³ãã¯åãå
¥ããããããTABã䜿çšããŠè¿œå ã§ããŸãã
ãŸããããã€ã¹ãçŸåšå¶åŸ¡ããŠããVRP OSã®ããŒãžã§ã³ã確èªããå¿
èŠããããŸãããããææ°ããŒãžã§ã³ã§ãªãå Žåã¯ãææ°ããŒãžã§ã³ãã€ã³ã¹ããŒã«ããå¿
èŠããããŸãã 次ã®ã³ãã³ãã§VRP OSããŒãžã§ã³ã確èªã§ããŸã
display version
ã·ã¹ã³ã§ã¯ãåæ§ã®ã³ãã³ããèŠããŸã
show version
ç§ãã¡ã¯ãã§ãã¯ããŸãïŒ
<USG6300>display version 17:02:50 2017/03/27 Huawei Versatile Security Platform Software Software Version: USG6300 V100R001C30SPC600PWE (VRP (R) Software, Version 5.30) Copyright (C) 2014-2016 Huawei Technologies Co., Ltd.. USG6320 uptime is 0 week, 0 day, 0 hour, 2 minutes Engine Version : V200R001C10 AV Signature Database Version : IPS Signature Database Version : IPS Engine Version : V200R001C10SPC352 SA Signature Database Version : 2015121601 Location Signature Database Version : 2015020515 RPU's Version Information: 2048M bytes SDRAM 16M bytes FLASH 1024M bytes CFCARD 1024K bytes SRAM PCB Version : VER.A CPLD Version : 200 Base Bootrom Version : 060 Dec 4 2015 06:55:42 Extended Bootrom Version : 060 Dec 4 2015 07:00:34
ãã®å ŽåãVRP OSããŒãžã§ã³ïŒV100R001C30SPC600PWEã ã€ãŸããããŒãžã§ã³100ããªãªãŒã¹001ããµããªãªãŒã¹30ããµãŒãã¹ããã¯600ã§ããPWEãµãã£ãã¯ã¹ã«ã泚æãæã䟡å€ããããŸããããã¯ãæå·åãªãã®ãã€ããŒããã€ãŸã ç§ãã¡ã®ããŒãžã§ã³ã®ãœãããŠã§ã¢ã¯ãéåžžã«å€ãããšã«å ããŠããŸã 匷åãªæå·åããµããŒãããŠããŸããã
ããã€ã¹ãœãããŠã§ã¢ã®æŽæ°
çŸåšã®ãœãããŠã§ã¢ããŒãžã§ã³ïŒ2017幎3æçŸåšïŒã¯v500r001c30spc100ã§ãã
å€ãããŒãžã§ã³ã®ãœãããŠã§ã¢ã§ãã®ããã€ã¹ã®æ§æãéå§ããŠãæå³ããããŸããã ãŸããçŸåšã®V500ã®CLIéšåãå€æŽãããŠããã»ãã¥ãªãã£ããªã·ãŒã«é¢é£ããã³ãã³ããå«ãããã€ãã®ã³ãã³ãã®æ§æãå€æŽãããŠããŸãã
第äºã«ã匷åãªæå·åã®æ¬ åŠïŒã€ãŸãããã®ãããªããŒãžã§ã³ã®ãœãããŠã§ã¢ã§ã¯ã茞å
¥ãç°¡åã«ããããã«ããã€ã¹ããã·ã¢ã«å±ããããŸãïŒã¯ãå€ãã®äººã«ã¯åããªããšæããŸãã
ãã®ããããŸããHuawei USG VRPãœãããŠã§ã¢ãçŸåšã®ææ°ããŒãžã§ã³ã«æŽæ°ããå¿
èŠããããŸãã ãã°ã€ã³ã«é©åãªæš©éãããå Žåã¯ãã¡ãŒã«ãŒã®Webãµã€ãããããŠã³ããŒãã§ããŸãïŒååãšããŠãHuaweiããŒãããŒã«ä»äžãããŸãïŒã ãœãããŠã§ã¢ã®ææ°ããŒãžã§ã³ãå©çšã§ããªãå ŽåïŒãããã«ããŠãWebãµã€ãã«è¡šç€ºãããŸãããããŠã³ããŒãããããšã¯ã§ããŸããïŒãæ©åšã®çŽå
¥å
ã®äŒç€ŸãŸãã¯Huaweiã®ãã·ã¢èªãµããŒãã«é£çµ¡ããå¿
èŠããããŸãã
ãµã€ããããã¡ã€ã«USG6000V500R001C30SPC100.bin VRPãœãããŠã§ã¢ãããŠã³ããŒãããã¢ãã¬ã¹172.31.31.250ã®TFTPãµãŒããŒã®ãã©ã«ããŒã«é
眮ããŸããã
Huawei USGã®ãžã¥ãã¢ããŒããããŒã«ã«ãããã¯ãŒã¯172.31.31.0 / 24ã«æ¥ç¶ããŠãTFTPãããã³ã«çµç±ã§æ°ãããã¡ã€ã«ãããŠã³ããŒãããŸããã ãã ãããã®ããã«ã¯ããããã¯ãŒã¯ããIPã¢ãã¬ã¹ãç»é²ããå¿
èŠããããŸãã 次ã®ããã«ãã£ãŠã¿ãŸãããïŒ
<USG6300>system-view [USG6300]interface GigabitEthernet0/0/0 [USG6300-GigabitEthernet0/0/0] ip address 172.31.31.86 255.255.255.0 [USG6300-GigabitEthernet0/0/0]quit [USG6300]
ã¢ãã¬ã¹ã綎ãããŠããŸãã ããããtftpãµãŒããŒã¯USGã§å¿çããªãããšãããããŸããã ããã¯ãã¹ãŠãããã©ã«ãã§USGã»ãã¥ãªãã£ããªã·ãŒãæå¹ã«ãªã£ãŠãããããã©ã«ãã¢ã¯ã·ã§ã³ãæåŠãããŠããããã§ãã çŠæ¢ããã åæèšå®ãé«éåããããã«ãããã©ã«ãã®ã«ãŒã«ãèš±å¯ããããšãææ¡ããŸããããã€ã¹ãã€ã³ã¿ãŒãããã§ãªãªãŒã¹ããããŸã§ãããã¯è
åšã«ãªããŸããã åæã«ãåæã»ããã¢ããã倧å¹
ã«ç°¡çŽ åãããŸãã
[USG6300] security-policy [USG6300-policy-security] default action permit Warning:Setting the default packet filtering to permit poses security risks. You are advised to configure the security policy based on the actual data flows. Are you sure you want to continue?[Y/N]Y [USG6300-policy-security] quit [USG6300]Ctrl+Z
TFTPãµãŒããŒã®å°éå¯èœæ§ã確èªããŸãã
<USG6300>ping 172.31.31.250 17:46:58 2017/03/27 PING 172.31.31.250: 56 data bytes, press CTRL_C to break Reply from 172.31.31.250: bytes=56 Sequence=1 ttl=128 time=1 ms Reply from 172.31.31.250: bytes=56 Sequence=2 ttl=128 time=1 ms
次ã«ã次ã®ã³ãã³ãã䜿çšããŠãTFTPãµãŒããŒãããã©ãã·ã¥ã¡ã¢ãªã«ãœãããŠã§ã¢ã®æ°ããããŒãžã§ã³ãããŒãããŸãã
<USG6300>tftp 172.31.31.250 get USG6000V500R001C30SPC100.bin
次ã«ãããŒãããŒããŒã«ãåèµ·ååŸã«ãçŸåšããŒããããã®ããã§ã¯ãªãããã®ã€ã¡ãŒãžãããœãããŠã§ã¢ãããŠã³ããŒãããå¿
èŠãããããšãäŒããå¿
èŠããããŸãã
<USG6300>startup system-software USG6000V500R001C30SPC100.bin Info:System software for the next startup:hda1:/usg6000v500r001c30spc100.bin, start read file.... Succeeded in setting the software for booting system. <USG6300>
次ã«ããã€ã¹ãèµ·åãããšãã«ãå¿
èŠãªãœãããŠã§ã¢ã®ããŒãžã§ã³ã§èµ·åããããšã確èªããŸãã
<USG6300>display startup 17:50:53 2017/03/27 MainBoard: Configed startup system software: hda1:/suempua15v1r1c30spc600pwe.bin Startup system software: hda1:/suempua15v1r1c30spc600pwe.bin Next startup system software: hda1:/usg6000v500r001c30spc100.bin Startup saved-configuration file: NULL Next startup saved-configuration file: NULL
次ã«ãæ§æãä¿åããŠããã€ã¹ãåèµ·åããŸãã
<USG6300>save all <USG6300>reboot 17:52:31 2017/03/27 System will reboot! Do you want to save the running configuration? [Y/N]:Y 2017-03-27 17:52:33 USG6300 %%01CFM/4/SAVE(l): When deciding whether to save configuration to the device, the user admin chose Y. Next config file name is NULL,set to Default... Next config file is hda1:/vrpcfg.zip Now saving the current configuration to the device.... Info:The current configuration was saved to the device successfully.. System will reboot! Continue? [Y/N]:Y
åèµ·ååŸããœãããŠã§ã¢ã®çŸåšã®ããŒãžã§ã³ã確èªããŸãã
<USG6300>display version 2017-03-27 18:37:42.590 Huawei Versatile Routing Platform Software VRP (R) Software, Version 5.160 (USG6300 V500R001C30SPC100) Copyright (C) 2014-2016 Huawei Technologies Co., Ltd USG6320 uptime is 0 week, 0 day, 0 hour, 37 minutes
ã芧ã®ãšãããç§ãã¡ã®ããŒãžã§ã³ã¯çŸåšææ°ã§ãã ãã®ç¬éãããæ©åšã®æ§æãéå§ã§ããŸãã
ãªã¢ãŒã管ççšã®ã€ã³ã¿ãŒãã§ã€ã¹ãšSSHã®æ§æ
次ã«ããªã¢ãŒã管ççšã«SSHãæ§æããŸãã HTTPSã®ã¿ãããã©ã«ãã§æå¹ã«ãªã£ãŠããŸãã
åå ãããã¹ãŠã®ã€ã³ã¿ãŒãã§ã€ã¹ã§sshãµãŒãã¹ãä»ããŠç®¡çã§ããããã«ããŸãã GigabitEthernet0 / 0/7ããããªãã¯IPã®WANã€ã³ã¿ãŒãã§ã€ã¹ãšããGigabitEthernet0 / 0/1ããããã¯ãŒã¯192.168.200.0 / 24ã®LANã€ã³ã¿ãŒãã§ã€ã¹ãšããŸãã
<USG6300> system-view [USG6300] interface GigabitEthernet 0/0/7 [USG6300-GigabitEthernet0/0/7] service-manage enable [USG6300-GigabitEthernet0/0/7] service-manage ssh permit [USG6300-GigabitEthernet0/0/7] ip address 195.26.xxx.xxx 255.255.255.224 [USG6300-GigabitEthernet0/0/7] service-manage http permit [USG6300-GigabitEthernet0/0/7] service-manage https permit [USG6300-GigabitEthernet0/0/7] service-manage ping permit [USG6300-GigabitEthernet0/0/7] quit [USG6300] interface GigabitEthernet0/0/1 [USG6300-GigabitEthernet0/0/1] undo shutdown [USG6300-GigabitEthernet0/0/1] ip address 192.168.200.100 255.255.255.0 [USG6300-GigabitEthernet0/0/1] service-manage http permit [USG6300-GigabitEthernet0/0/1] service-manage https permit [USG6300-GigabitEthernet0/0/1] service-manage ping permit [USG6300-GigabitEthernet0/0/1] service-manage ssh permit
ããã©ã«ãã§ãHuawei USGã«ã¯ãå²ãåœãŠãããåªå
床ïŒæ¬åŒ§å
ïŒãæã€4ã€ã®ãã¡ã€ã¢ãŠã©ãŒã«ãŸãŒã³ããããŸãïŒããŒã«ã«ïŒ100ïŒãdmzïŒ50ïŒãä¿¡é ŒïŒ85ïŒãéä¿¡é ŒïŒ5ïŒã ãã¹ãŠãCisco ASAã§è¡ãããæ¹æ³ãšéåžžã«ãã䌌ãŠããŸããåããŸãŒã³ã®ãŠãŒã¶ãŒã¯åãã»ãã¥ãªãã£å±æ§ãæã£ãŠããŸãã ã»ãã¥ãªãã£ãŸãŒã³ã®åäœã¡ã«ããºã ã«ã€ããŠã¯ã以äžã§è©³ãã説æããŸãããããã§ã¯ã察å¿ãããŸãŒã³ã§æ§æãããã°ããã®ã€ã³ã¿ãŒãã§ã€ã¹ãå®çŸ©ããã ãã§ãã
[USG6300] firewall zone trust [USG6300-zone-trust] add interface GigabitEthernet0/0/1 [USG6300-zone-trust] quit [USG6300] firewall zone untrust [USG6300-zone-untrust] add interface GigabitEthernet0/0/7 [USG6300-zone-untrust] quit
次ã«ãããã©ã«ãã²ãŒããŠã§ã€ãæ§æããŸãã
[USG6300] ip route-static 0.0.0.0 0.0.0.0 195.26.xxx.1
AAAããµããŒãããããã«VTYã€ã³ã¿ãŒãã§ã€ã¹ãæ§æããŸãã
[USG6300] user-interface vty 0 4 [USG6300-vty0-4] authentication-mode aaa [USG6300-vty0-4] protocol inbound ssh [USG6300-vty0-4] user privilege level 15 [USG6300-vty0-4] quit
SSHçµç±ã§ããã€ã¹ãå¶åŸ¡ã§ããusersshãŠãŒã¶ãŒãäœæããŸãã
[USG6300] aaa [USG6300-aaa] manager-user userssh [USG6300-aaa-manager-user-userssh] password Enter Password: Confirm Password: [USG6300-aaa-manager-user-userssh] service-type ssh [USG6300-aaa-manager-user-userssh] quit [USG6300-aaa] bind manager-user userssh role system-admin [USG6300-aaa] quit
ããŒã«ã«ã®rsaããŒãã¢ãçæããŸãã
[USG6300] rsa local-key-pair create
Secure TelnetïŒSSHïŒãµãŒãã¹ãæå¹ã«ããŸãã
[USG6300] stelnet server enable
usersshãSSH管çè
ãšããŠæ§æããŸãã
[USG6300] ssh user userssh [USG6300] ssh user userssh authentication-type password [USG6300] ssh user userssh service-type stelnet
ããã§ãåæèšå®ãå®äºãããšã¿ãªããå€éšã€ã³ã¿ãŒããããšããŒã«ã«ãããã¯ãŒã¯ã®ã±ãŒãã«ã察å¿ããèšå®æžã¿ã€ã³ã¿ãŒãã§ãŒã¹ã«æ¥ç¶ã§ããŸãã
WEBã€ã³ã¿ãŒãã§ãŒã¹ã䜿çšããã»ããã¢ãã
ä»ã®ã»ãšãã©ã®æ§æãšåæ§ã«ãåºæ¬çãªèšå®ãè¡ããã³ãã³ãã©ã€ã³ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã¢ããã°ã¬ãŒãããããšã奜ã¿ãŸãã ããã§ããWebã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠå€ãã®ïŒãã¹ãŠã§ã¯ãªãïŒãè¡ãããšãã§ããŸããWebã€ã³ã¿ãŒãã§ã€ã¹ã¯ãJavaãŸãã¯ã¯ã©ã€ã¢ã³ãããã°ã©ã ïŒCisco ASAã®ASDMãªã©ïŒãå¿
èŠãšããªããéåžžã«é©åã«å®è£
ãããŠããŸãã ã¯ããã»ãã¥ãªãã£ããªã·ãŒã¯ãWebã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠäœæããæ¹ãã¯ããã«èŠèŠçã§ç°¡åã§ãã
ããã©ã«ãã§ã¯ãããã€ã¹ã®Webã€ã³ã¿ãŒãã§ãŒã¹ã¯ç®¡çããŒãã§æå¹åããã³æå¹åãããŸããã©ãã¯ããã€ã¹ã§ã¯ããã®ããŒãã¯å¥åã§ããUSG6320ã®å Žåãããã©ã«ãã§ã¯ããã®ããŒãã¯ããŒãäžã§æãè¥ãããœãããŠã§ã¢ã®æŽæ°ã«äœ¿çšããããŒãã§ãã ããã©ã«ãã§ã¯ãIP 192.168.0.1 / 24ã管çããŒãã«ç»é²ããããã¹ãŠã®çš®é¡ã®ãµãŒãã¹ãèš±å¯ãããDHCPãæå¹ã«ãªã£ãŠããŸãããããã£ãŠãã³ãã³ãã©ã€ã³ã®çžæã«å¯ŸããŠã¯ãããã©ã«ãã§ãããã®ãã©ã¡ãŒã¿ãŒãç¥ã£ãŠããæåããWEBã€ã³ã¿ãŒãã§ãŒã¹ã䜿çšã§ããŸãã 次ã®ããã«ãªããŸãã
interface GigabitEthernet0/0/0 undo shutdown ip address 192.168.0.1 255.255.255.0 anti-ddos flow-statistic enable anti-ddos syn-flood source-detect alert-rate 100 service-manage http permit service-manage https permit service-manage ping permit service-manage ssh permit service-manage snmp permit service-manage telnet permit dhcp select interface dhcp server ip-range 192.168.0.1 192.168.0.254
httpsã®å¶åŸ¡ããŒãã¯8443ã§ããããŒãã®ã¢ãã¬ã¹ãå°ãåã«172.31.31.86ã«å€æŽããããã次ã®ããã«ä»»æã®ãã©ãŠã¶ãŒããããã€ã¹ã«ã¢ã¯ã»ã¹ããŸãã
https:
Huawei USGããã·ã¥ããŒãã¿ããŸããã·ã¹ãã ->ã©ã€ã»ã³ã¹ç®¡çã»ã¯ã·ã§ã³ã§è³Œå
¥ããã©ã€ã»ã³ã¹ãããŠã³ããŒãããå¿
èŠããããŸãã
次ã®å¶éä»ãã§é©åãªãªãã·ã§ã³ãéžæããããšã«ãããè©Šçšçã©ã€ã»ã³ã¹ã䜿çšããããšãã§ããŸãã
ãã©ã€ã¢ã«ãŠã€ã«ã¹å¯Ÿçããã³IPSãµãã¹ã¯ãªãã·ã§ã³ã®æå¹æéã¯2ãæã§ãã
ãŸãã¯ãããŒã«ã«ã®æåã¢ã¯ãã£ããŒã·ã§ã³ãéžæãããšãçæããããã¡ã€ã«ãdatæ¡åŒµåã§ã©ã€ã»ã³ã¹ã«çœ®ãæãã賌å
¥ããã©ã€ã»ã³ã¹ãã¢ã¯ãã£ããŒããããŸãã
ã»ãã¥ãªãã£ããªã·ãŒãšçœ²åã®æŽæ°ãæ§æãã
次ã«ãããã€ã¹ã®ã€ã³ã¿ãŒãããæ¥ç¶ãšçœ²åã®æŽæ°ãã€ã³ã¿ãŒãããçµç±ã§æ§æããããšãææ¡ããŸãã èšå®ãé²ããåã«ãHuawei USGã®ã»ãã¥ãªãã£ãŸãŒã³ã®åäœã¡ã«ããºã ã«ã€ããŠç°¡åã«èª¬æããŸãã
äžèšã®ããã«ãããã©ã«ãã§4ã€ã®ã»ãã¥ãªãã£ãŸãŒã³ãæ§æãããŠããŸãã
- ä¿¡é ŒããªãïŒ5ïŒã ã€ã³ã¿ãŒããããªã©ãã»ãã¥ãªãã£ã¬ãã«ãæãäœããããã¯ãŒã¯ã»ã°ã¡ã³ããèå¥ããŸã5ã
- DMZïŒ50ïŒã ååãšããŠãå€éšããã®ã¢ã¯ã»ã¹ãæäŸããå¿
èŠããããµãŒããŒãé
眮ãããŠããã»ã°ã¡ã³ããå®çŸ©ããŸãã ããããåæã«ãããå®å
šãªãããã¯ãŒã¯ã»ã°ã¡ã³ããžã®ã¢ã¯ã»ã¹ã¯ãã®ãŸãŒã³ããçŠæ¢ãããŠããŸãã
- ä¿¡é ŒïŒ85ïŒã ååãšããŠããŠãŒã¶ãŒã¯ãŒã¯ã¹ããŒã·ã§ã³ãé
眮ãããŠããå®å
šãªãããã¯ãŒã¯ã»ã°ã¡ã³ããå®çŸ©ããŸãã
- ããŒã«ã«ïŒ100ïŒã ã€ã³ã¿ãŒãã§ã€ã¹ãå«ããUSGããã€ã¹èªäœã®é åã
ãŸãŒã³ã®åªå
é äœãå€æŽããããå¿
èŠã«å¿ããŠæ°ãããŸãŒã³ãè¿œå ãããã§ããŸãã ããã¯ãããŒã«ã«ãé€ããã¹ãŠã®ãŸãŒã³ã«é©çšãããŸã-åªå
床ãå€æŽããããã€ã³ã¿ãŒãã§ãŒã¹ãè¿œå ãããããããšã¯ã§ããŸããã
åãã»ãã¥ãªãã£ãŸãŒã³å
ã®ããŒã¿ã¹ããªãŒã ã¯ä¿¡é Œãããã»ãã¥ãªãã£ããªã·ãŒã®èšå®ã¯äžèŠã§ãã ãããŸãŒã³ããå¥ã®ãŸãŒã³ãžã®ããŒã¿ã®æµããæ§æããå¿
èŠãããå Žåã¯ã次ã®èŠåã«åŸã£ãŠãã©ãã£ãã¯ã®æ¹åãèæ
®ããŠãã»ãã¥ãªãã£ããªã·ãŒãæ§æããå¿
èŠããããŸãã
- ã€ã³ããŠã³ãïŒåªå
床ã®äœããŸãŒã³ããåªå
床ã®é«ããŸãŒã³ãžã®ãã©ãã£ãã¯ã
- ã¢ãŠãããŠã³ãïŒåªå
床ã®é«ããŸãŒã³ããåªå
床ã®äœããŸãŒã³ãžã®ãã©ãã£ãã¯ã転éãããŸãã
ãã©ãã£ãã¯ã®æ¹åã¯ãæåã®ãã±ããã®æ¹åã«ãã£ãŠæ±ºãŸããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹ãæ¢ã«æ§æãããããã€ããŒããã®ã±ãŒãã«ãGigabitEhternet0 / 0/7ã«æ¥ç¶ããããŒã«ã«ãããã¯ãŒã¯ããã®ã±ãŒãã«ãGigabitEthernet0 / 0/1ã«æ¥ç¶ããŠããããšãæãåºãããŠãã ããã ããã€ã¹ïŒããŒã«ã«ãŸãŒã³ïŒããå€éšïŒuntrustãŸãŒã³ïŒã«çŽæ¥pingãè©Šã¿ããšã次ã®å³ã衚瀺ãããŸãã
[USG6300]ping 8.8.8.8 PING 8.8.8.8: 56 data bytes, press CTRL_C to break Request time out Request time out Request time out Request time out Request time out
ããã©ã«ãã«ãŒããèšå®ãããããã€ã¹ããããã€ããŒã«æ¥ç¶ãããŠããã«ããããããããã¹ãŠã®ãã±ããã倱ãããŸãã ãã®ãããªç¶æ³ã§ã¯ãéåžžã®ã«ãŒã¿ãŒã¯ICMPå¿çãåä¿¡ããç¶æ³ã¯ç°ãªããŸãã ãã ãããã®å Žåãäžèšã®ã»ãã¥ãªãã£ãŸãŒã³æäœã¡ã«ããºã ãæ©èœããåªå
床100ïŒããŒã«ã«ïŒã®ãŸãŒã³ããåªå
床5ïŒã¢ã³ãã©ã¹ãïŒã®ãŸãŒã³ãžã®ããŒã¿ãããŒã®éå§ããããããã»ãã¥ãªãã£ããªã·ãŒïŒéä¿¡ã»ãã¥ãªãã£ããªã·ãŒïŒãæ§æããŠãäž¡æ¹åã®ããã±ãŒãžãæ©ãã LOCALâUNTRUSTã®æ¹åã®ãã©ãã£ãã¯ã«é¢ããçºä¿¡ããªã·ãŒã®å Žåããã®æ¹åã§æ°ããã»ãã·ã§ã³ãéå§ããããã³ã«ãããã€ã¹ã¯ã»ãã·ã§ã³ããŒãã«ã«æ°ããã¬ã³ãŒããäœæããŸãã ã¬ã³ãŒãã«ã¯ãéä¿¡å
ããã³å®å
IPã¢ãã¬ã¹ã察å¿ããããŒãçªå·ãããã³ãããã³ã«ã¿ã€ããå«ãŸããŸãã
ã¯ã©ã€ã¢ã³ããLOCALãŸãŒã³ãšUntrustãŸãŒã³ã®ãµãŒããŒãã亀æãããã±ãããã»ãã·ã§ã³ããŒãã«ã®ãšã³ããªã«å¯Ÿå¿ããå Žåããã¡ã€ã¢ãŠã©ãŒã«ã¯ãã±ãã転éã®æ¹åãå床確èªããããšãªããçºä¿¡ã»ãã¥ãªãã£ããªã·ãŒã«åºã¥ããŠãã±ãããåŠçããŸãã ã€ãŸãããã®å Žåãã¢ãã¬ã¹8.8.8.8ããICMP ECHOãåä¿¡ããå¿
èŠããããŸãã
policy_to_Inetãšããååã®[è¿œå ]ãã¿ã³ãã¯ãªãã¯ããŠã[ããªã·ãŒ]ã»ã¯ã·ã§ã³ã§ããªã·ãŒãæ§æããŸãã
ããªã·ãŒãé©çšããåŸãããã€ã¹ã®ã¢ãã¬ã¹8.8.8.8ã§pingãå®è¡ããŠãæäœæ§ã確èªããŸãã
[USG6300]ping 8.8.8.8 PING 8.8.8.8: 56 data bytes, press CTRL_C to break Reply from 8.8.8.8: bytes=56 Sequence=1 ttl=47 time=19 ms Reply from 8.8.8.8: bytes=56 Sequence=2 ttl=47 time=21 ms Reply from 8.8.8.8: bytes=56 Sequence=3 ttl=47 time=19 ms Reply from 8.8.8.8: bytes=56 Sequence=4 ttl=47 time=20 ms Reply from 8.8.8.8: bytes=56 Sequence=5 ttl=47 time=20 ms
[ã·ã¹ãã ]â[ã¢ããããŒãã»ã³ã¿ãŒ]ã»ã¯ã·ã§ã³ã§ãããå察åŽã«ãã[ãŠã€ã«ã¹å¯Ÿçã·ã°ããã£ããŒã¿ããŒã¹]ãªã©ã®[æŽæ°]ãã¯ãªãã¯ããŠãIPSããã³ãŠã€ã«ã¹å¯Ÿçã·ã°ããã£ã®æŽæ°ãè©Šã¿ãŸãã
ãã°ãããããšã[ã¹ããŒã¿ã¹]åã§ãæŽæ°ãµãŒããŒã®ãã¡ã€ã³åïŒsec.huawei.comïŒã解決ã§ããªãã£ããããããŒã¿ããŒã¹ã®ããŠã³ããŒãã倱æããããšãããããŸãã å®éãååã解決ããã«ã¯ã[è¿œå ]ãã¿ã³ãã¯ãªãã¯ããŠã[ãããã¯ãŒã¯]-> [DNS]ã»ã¯ã·ã§ã³ã«DNSãµãŒããŒãç»é²ããå¿
èŠããããŸãã
DNSãµãŒããŒãç»é²ããåŸããã¹ãŠãå€æããŸããã
ãã®åŸããã¹ãŠã®çœ²åã¯ãã¹ã±ãžã¥ãŒã«ãããæŽæ°æéã»ã¯ã·ã§ã³ã®æéã«åŸã£ãŠæŽæ°ãããŸãããã®å Žåãæ¯æ¥åå6æ38åã§ãã
ã€ã³ã¿ãŒããããžã®LANã¢ã¯ã»ã¹ã®ããã®NAT / PATã®æ§æ
PATçµç±ã§ããŒã«ã«ãããã¯ãŒã¯192.168.200.0 / 24ïŒãŸãŒã³ã®ä¿¡é ŒïŒã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãæ§æããŸãã ãã®å Žåããã©ãã£ãã¯ã®æ¹åã¯é«åªå
床ïŒä¿¡é ŒïŒã®ãŸãŒã³ããäœåªå
床ïŒéä¿¡é ŒïŒã®ãŸãŒã³ã«åãããããéä¿¡ããªã·ãŒã»ãã¥ãªãã£ãæ§æããå¿
èŠããããŸãã ããã§ã®ã«ãŒã«ã¯ãããŒã«ã«ãŸãŒã³ã§ãã§ã«è¡ã£ãã«ãŒã«ãšãŸã£ããåãã§ãã æ°ããã«ãŒã«ãèšå®ã§ããŸãããŸãã¯ãä»ã®ãã¹ãŠã®ãã©ã¡ãŒã¿ãŒãåãå Žåãæ¢ã«äœæãããŠããpolicy_to_Inetã«å¥ã®ãœãŒã¹ãŸãŒã³ãè¿œå ã§ããŸãïŒãã®å Žåã¯trustïŒã
[ã³ã³ãã³ãã»ãã¥ãªãã£]ã»ã¯ã·ã§ã³ã§ãæ¢å®ã®å®çŸ©æžã¿ãããã¡ã€ã«ããŠã€ã«ã¹å¯ŸçãµãããŒã«è¿œå ããå³å¯ãªãããã¡ã€ã«ã䟵å
¥é²æ¢ãµãããŒã«è¿œå ããŸãã
ãã®åŸãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããããã«ãã©ã¹ããŸãŒã³ã®NATããªã·ãŒãäœæããå€éšIPã¢ãã¬ã¹ãããã¹ãã³ã°ãããŸãã
ãã®åŸããããã¯ãŒã¯192.168.200.0 / 24ã®ãŠãŒã¶ãŒã¯ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã
Huawei USGã®åºæ¬æ§æã¯å®å
šã§ãããšèããããšãã§ããŸãã VRPããã€ã¹ãœãããŠã§ã¢ã¯ææ°ããŒãžã§ã³ã«ã¢ããã°ã¬ãŒããããSSHã¯ã³ãã³ãã©ã€ã³ãä»ãããªã¢ãŒãã³ã³ãããŒã«çšã«èšå®ãããã€ã³ã¿ãŒããããšä¿¡é ŒãŸãŒã³ããã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒãä»ããŠçœ²åã®æŽæ°ãèšå®ããŸããã
ç¹°ãè¿ããŸãããéåžžã«åªããã»ããã¢ããã¬ã€ãã«èšåãã䟡å€ããããŸãïŒãã®èšäºã§ã¯ãHUAWEI USG6000ããã³USG9500 V500R001C30SPC200ããã³NGFW Module V500R002C00SPC200補åããã¥ã¡ã³ãã䜿çšããŸããïŒã 説æããæ©èœã«å ããŠãIPsecãµã€ãéãã³ãã«ããªã¢ãŒããŠãŒã¶ãŒãæ¥ç¶ããããã®SSL VPNããªã¢ãŒãSSL-VPNãŠãŒã¶ãŒãèš±å¯ããããã®Microsoft Active Directoryãšã®çµ±åãããã³ãã¡ã€ã³ãŠãŒã¶ãŒã®ããã®ã·ã³ã°ã«ãµã€ã³ãªã³ïŒè¿œå ã®èš±å¯ãªãã§ãã¡ã€ã³ãŠãŒã¶ãŒã®ããã«ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããïŒãæ§æããŸãããããŠããäžã€ã
ãã®èšäºããæåãªã¢ã¡ãªã«ã®ãã³ããŒã®åæ§ã®ããã€ã¹ã眮ãæããããã«UTM / NGFW /ãã¡ã€ã¢ãŠã©ãŒã«ããã€ã¹ãæ€èšããŠãã人ã
ã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã