
以åã¯ãäœããåºå¥ããå¿
èŠãããå ŽåïŒããšãã°ãæ¯æãåŠçãè¡ããµãŒããŒãšãªãã£ã¹ãŠãŒã¶ãŒã®ç«¯æ«ïŒãäžå€®ã«ãã¡ã€ã¢ãŠã©ãŒã«ããªããžãåãã2ã€ã®ç¬ç«ãããããã¯ãŒã¯ãæ§ç¯ããŠããŸããã ã·ã³ãã«ã§ä¿¡é Œæ§ããããŸãããé«äŸ¡ã§ãããå¿
ããã䟿å©ã§ã¯ãããŸããã
åŸã«ãä»ã®ã¿ã€ãã®ã»ã°ã¡ã³ããŒã·ã§ã³ãç¹ã«ãã©ã³ã¶ã¯ã·ã§ã³ã«ãŒãã«åºã¥ãæš©å©ãç»å ŽããŸããã 䞊è¡ããŠãç¹å®ã®æš©éããã·ã³ã人ããŸãã¯ãµãŒãã¹ã«å²ãåœãŠãããããŒã«ã¹ããŒã ãéçºãããŸããã æ¬¡ã®è«çã©ãŠã³ãã¯ãDMZãåãã·ã³ã®åšãã«é
眮ããããšãã®ä»®æ³ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã§ãã
ãã·ã¢ã§ã¯ããã®ãããªé²åŸ¡æ§é ã®å®è£
ã¯ãŸã ã»ãšãã©ãããŸãããããŸããªããããã®å®è£
ãå¢ããã§ãããã ãããŠããããããç§ãã¡ã¯ããããªãã§çããããšãã©ã®ããã«å¯èœã§ãã£ããããçè§£ããªãã§ãããã ãã®ãããªãããã¯ãŒã¯ã®æ»æã·ããªãªãšãããã«å¯Ÿããåå¿ãèŠãŠã¿ãŸãããã
ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãšã¯
ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã¯ãã¯ãŒã¯ããŒãã®ã¬ãã«ãŸã§ããŒã¿ã»ã³ã¿ãŒã¢ããªã±ãŒã·ã§ã³ã«ã»ãã¥ãªãã£ããªã·ãŒãå²ãåœãŠãããšãã§ããã»ãã¥ãªãã£æ¹åŒã§ãã ããé©çšãããã¢ããªã±ãŒã·ã§ã³ã§ã¯ãããŒã¿ã»ã³ã¿ãŒã®ã»ãã¥ãªãã£ã¢ãã«ã§ãã ãããã¯ãŒã¯ã»ãã¥ãªãã£ããªã·ãŒã¯ãããŒã¿ã»ã³ã¿ãŒã«ãã§ã«ååšãããã€ããŒãã€ã¶ãŒã«çµ±åããããã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠå®æœãããŸãã ããã«ããããŠããã¿ã¹ä¿è·ãæäŸãããŸãã ããã«ãã¯ãŒã¯ããŒãã®å€åã«åãããŠèªåçãã€åçã«é©å¿ããããªã©ãã»ãã¥ãªãã£ããªã·ãŒã䟿å©ã«å€æŽã§ããŸãã
以åã®ããã«
以äžã¯ãææ°ã®ãããã¯ãŒã¯ã®ãç³åšæä»£ãã§ã-管çãããŠããªããããã¯ãŒã¯ïŒ

ããæ£ç¢ºã«ã¯ããªã³ã¯ãååšããªãããã«ãããã¯ãŒã¯ãäžè¬çã«ç©ççã«åé¢ãããŠããå Žåãããã¯ç³åšæä»£ã«ãªããŸãã ãã ããããã§ã¯ã«ãŒã¿ãŒã§æ¥ç¶ããã亀差ç¹ã®ããŒããŠã§ã¢ãã¡ã€ã¢ãŠã©ãŒã«ã§ä¿è·ãããŠããŸãã ããã¯ãçŸå®ã®äžçã«å
¥ããªãéããè¯ãéžæè¢ã§ãã
é²è¡ã®é²åã®æ¬¡ã®ã©ãŠã³ãã¯æ¬¡ã®ãšããã§ãã

仿¥ãã»ãšãã©ã®äŒæ¥ã¯ãµãŒããŒã¯ã©ã¹ã¿ã䜿çšããŠãã€ã³ãã©ã¹ãã©ã¯ãã£å
šäœãã²ãããŸãã
Aeroexpressã®äŸã次ã«ç€ºããŸããå®éã1ã€ã®ã¯ã©ã¹ã¿ãŒãš2ã€ã®ä»®æ³ãµããããããããå¶æ¥æïŒéåžžã®ãŠãŒã¶ãŒïŒãšéè¡æ¥åãã€ãŸãçºåžçšã§ãã å°å
¥åã¯ããããã¯ãŒã¯ã¯1ã€ãããããŸããã§ããããçè«çã«ã¯ãã¬ãžä¿ã¯ãã±ããçºè¡ããµãŒããŒã«æäŸããããšãã§ããŸããã ãã®åé¢åŸã®æ¬¡ã®è«çã¹ãããã¯ãä»®æ³åãšãã€ã¯ãã»ã°ã¡ã³ãã®æ§ç¯ãããã«åŒ·åããããšã§ãããéã®ã¬ãã«ã§ã¯ãªããæè»ãªãµãŒãã¹æš©ã®ã¬ãã«ã§ãã ããã«ããã2ã3å°ã®ãã·ã³ããã现ããåé¢ããåŸæ¥ã®ã¿ã¹ã¯ã«æ¯ã¹ãŠç®¡çã倧å¹
ã«ç°¡çŽ åãããã¯ã©ã¹ã¿ãŒå
ã®ä¿è·ã®ä¿¡é Œæ§ã®é¢ã§å¯¿åœã倧å¹
ã«ç°¡çŽ åãããŸãã åãã€ã¯ãã»ã°ã¡ã³ãã¯ãæå³çã«ä¿¡é Œããããã®ã§ã¯ãªãã飿¥ãããã®ãå€ã®äžçãšèŠãªããŸãã
ããã¯ãã¿ã¹ã¯ã«å¿ããŠãç°ãªãå¢çã®äº€å·®ç¹ã䜿çšãããæãåçŽãªã¹ããŒã ã®1ã€ã§ãã ããã¯æ¬¡ã®å³ã®ããã«ãªããŸãã

ãã®å³ã§ã¯ããããã¯ãŒã¯ã³ã³ããŒãã³ãã®ã¹ã±ãŒãªã³ã°ã®åé¡ïŒæ°ããVMã®å±éã«ãã£ãŠå®è¡ãããïŒã®è§£æ±ºæžã¿ã®åé¡ãèŠãããšãã§ããŸããä»»æã®ãããã¯ãŒã¯æ©åšã䜿çšã§ããVMãã©ãã£ãã¯ã®æ°Žå¹³åæ£ãå¶åŸ¡ã§ããŸããVLANã¯VxLANã«çœ®ãæããããŸãã ããã«ããã€ã¢ã«ãŠã³ã-1ã®äŸã䜿çšããŠã¹ããŒã ã®ã«ã©ãŒã¹ããŒã ãèŠããšã次ã®ã·ããªãªãèŠãããšãã§ããŸãã
- ç°ãªãç©çãµã€ãã«ããã¢ããªã±ãŒã·ã§ã³ãµãŒããŒã¯ãåãè«çãããã¯ãŒã¯P6ïŒãªã¬ã³ãžã®æ¥åïŒã«ãããŸãã
- åæã«ãåãå人ã¢ã«ãŠã³ã-1ã®WebãµãŒããŒã¯æ¢ã«ç°ãªãè«çãããã¯ãŒã¯ïŒç·è²ã®æ¥åP4ãšP5ïŒã«ãããŸãã
- å人ã¢ã«ãŠã³ããå®è£
ãããã¹ãŠã®ãµãŒããŒ-1ã¯ã1ã€ã®è«çãããã¯ãŒã¯P10ïŒç Žç·ã§ããŒã¯ããããŸãŒã³ïŒã«é
眮ãããŸãã
ããããããªãã¯ãã§ã«ãã¹ãŠãçè§£ããŠããŠãä»ã§ã¯ãããç¶æããããšãã©ãã»ã©é£ããããç¥ããããšæãã§ãããã ãã®ããããã€ããŒãã€ã¶ãŒã®æ°ããããŒãžã§ã³ã§ã¯ããã®ãããªæ§é ã¯ããã®ãŸãŸããµããŒããããŠããŸãã
ãã®ãããªãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã®å®è£
ã®äž»ãªããŒãã¯ãã¯ã©ã¹ã¿ãŒããã³ããŒãœãã«ã¯ã©ãŠããã¯ãããžãŒã®ã³ã³ããã¹ãã«ãããéèŠãªãµãŒãã¹ã®ä¿è·ã§ãã
äŸ ïŒäŒèšå£«ã®äœæ¥ãã·ã³ããããéåžžã®æ¯æ¥ã®äœæ¥äžã«ããäŒèšã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ããªã©ã®ããªã·ãŒãé©çšãããã€ã³ã¿ãŒããããäžè¬çãªã€ã³ãã©ã¹ãã©ã¯ãã£ãµãŒãã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã ã¯ã©ã€ã¢ã³ããã³ã¯ãéå§ããããšãæ¿æ²»å®¶ã¯çŽã¡ã«éè¡ã¯ã©ã€ã¢ã³ãã®ãã©ãã£ãã¯ã«é¢é£ä»ããããã«ãŒã«ãåŠçãããã®ãã©ãã£ãã¯ã¯éè¡ã®IP / DNSãµãŒããŒã«ã®ã¿éä¿¡ããã远å ã®æ
å ±ä¿è·ææ®µãä»ããŠãã®ãããªãã©ãã£ãã¯ãæž¡ãããšãå¿
é ã§ãã ïŒããšãã°ãDPIãµãŒããŒïŒã ã¯ã©ã€ã¢ã³ãéè¡ã¯ééãããŠããŸã-åã³ãAWP Accountingãã«ãªããŸãã
NSXãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãã©ãããã©ãŒã ã®1ã€ã¯äœããæ§æãããŠããŸããïŒ
äž»ãªã³ã³ããŒãã³ãã¯æ¬¡ã®ãšããã§ãã
æŽæµ
|
ã¬ã€ã€ãŒ2è«çãªãŒããŒã¬ã€ã¯ãããŒã¿ã»ã³ã¿ãŒã®å
å€ã®ã¬ã€ã€ãŒ3ã¹ã€ããããããªãã¯ã¹å
šäœã«æäŸãããŸãã VXLANã«åºã¥ããªãŒããŒã¬ã€ãããã¯ãŒã¯ã®ãµããŒãã
|
ã«ãŒãã£ã³ã°
|
ä»®æ³ãããã¯ãŒã¯éã®åçã«ãŒãã£ã³ã°ã¯ããã€ããŒãã€ã¶ãŒã®ã«ãŒãã«ã«ãã£ãŠåæ£æ¹åŒã§å®è¡ãããç©çã«ãŒã¿ãŒãžã®ã¢ã¯ãã£ã/ã¢ã¯ãã£ãã¿ã€ãã®ãã§ãŒã«ãªãŒããŒã«ããæ°Žå¹³ã¹ã±ãŒãªã³ã°ããµããŒããããŸãã éçããã³åçã«ãŒãã£ã³ã°ãããã³ã«ïŒOSPFãBGPïŒããµããŒããããŠããŸãã
|
忣ãã¡ã€ã¢ãŠã©ãŒã«
|
ãã€ããŒãã€ã¶ãŒãµãŒããŒãžã®æå€§20 Gb / sã®ã¹ã«ãŒãããã§ããã€ããŒãã€ã¶ãŒã®ã³ã¢ã«çµã¿èŸŒãŸããã¹ããŒããã«ãªåæ£ãã¡ã€ã¢ãŠã©ãŒã«ãµãŒãã¹ã Active Directoryã®ãµããŒããšã¢ã¯ã·ã§ã³ã®ç£èŠã ããã«ãNSXã¯NSX Edgeã«åçŽãã¡ã€ã¢ãŠã©ãŒã«ãæäŸããŸãã
|
è² è·åæ£
|
SSLè² è·è»¢éãšãšã³ãããŒãšã³ãéä¿¡ããµãŒããŒãã«ã¹ãã§ãã¯ãã¢ããªã±ãŒã·ã§ã³ã«ãŒã«ã«ããã¬ãã«4ã7ã®è² è·åæ£ã«ãããããã°ã©ãã³ã°ãšãã©ãã£ãã¯æäœæ©èœãæäŸãããŸãã
|
VPN
|
VPNããã³ç°å¢ããåªäœãžã®VPNæ¥ç¶ãã¯ã©ãŠãã²ãŒããŠã§ã€ãµãŒãã¹çšã®ç®¡çãããŠããªãVPNãä»ãããªã¢ãŒãã¢ã¯ã»ã¹ã
|
NSXã²ãŒããŠã§ã€
|
VXLANãšVLANéã®ããªããžã³ã°ã¯ãç©ççãªã¯ãŒã¯ããŒããžã®æé©ãªæ¥ç¶ãæäŸããŸãã ãã®ã³ã³ããŒãã³ãã¯NSXãã©ãããã©ãŒã ã«çµã¿èŸŒãŸããŠããããšã³ã·ã¹ãã ããŒãããŒãæäŸããã©ãã¯ã¹ã€ããã§ããµããŒããããŠããŸãã
|
NSX API
|
RESTããŒã¹ã®APIã¯ãã¯ã©ãŠã管çãŸãã¯ãŠãŒã¶ãŒãã©ãããã©ãŒã ãšã®çµ±åã®ããã«ãµããŒããããŠããŸã
|
ãããŠä»ãç§ãã¡ã¯ããŸããŸãªè
åšã€ãã³ãã®ã·ããªãªãæ€èšãããããå®å
šã«æããã«ãªãããã«ããŸãã
ã·ããªãª1ïŒãã«ã¯ã©
å€§äŒæ¥ã§ã®äŸµå
¥ãšææã®çµè·¯ã¯ã»ãŒåãã§ãããã£ãã·ã³ã°ãæšçåæ»æããã©ãã·ã¥ãã©ã€ãã®åœ¢ã®ãæ
è¡ãªã³ãŽãã§ãã ååãšããŠããã«ãŠã§ã¢ã¯èªååãããã¯ãŒã¯ã¹ããŒã·ã§ã³ã®1ã€ã«ææãïŒããšãã°ãæçŽãå±ããå ŽåïŒãå¢çå
ã§ã¯æ€åºããããŸã§äœã§ãã§ããŸãã ç§ã¯æè¿ãéè¡ã®ç¶æ³ãèŠãŸããã æ·±å»ãªäººã
ãšæ·±å»ãªã»ãã¥ãªãã£ãæã£ãŠãããšèšããªããã°ãªããŸãããããããã¯ãŒã¯å
ã®ç¶æ³ã¯ãå±éããããã¹ããã«ãŠã§ã¢ïŒãã€ããŒããªãïŒããã¹ãç°å¢ããçªç Žãããä¿è·ã·ã¹ãã ã«èŠãããŸã§ããã€ãã®ãã©ã³ãã«ææãããããªç¶æ³ã§ããã äžéšã®ãŠãŒã¶ãŒã«ãšã£ãŠããŠãŒã¶ãŒã»ã°ã¡ã³ãã¯ã¯ãªãã£ã«ã«ãããŸã£ããåé¢ãããŠãããããŠãŒã¶ãŒã¯1CãµãŒããŒãéèååŒã®ãããã·ã³ãWebãµãŒããŒãæŽæ°ãµãŒããŒãªã©ã«ãã«ãŠã§ã¢ãåãã§æããŠããŸãã
ç§ãã¡ã®ãã©ãã€ã ã§ã¯ãä¿è·ã¯æ¬¡ã®ãšããã§ãããµãŒããŒããµãŒãã¹ãããã³ãŠãŒã¶ãŒã®ã¬ãã«ã§ã®ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã åã°ã«ãŒããå¢çç·ã§åºåããŸãïŒäžã®å³ã®ããã«ïŒã ååãšããŠã1å°ã®ä»®æ³ãã·ã³ãææããŸããããã¯ããã€ããŒãã€ã¶ãŒã®é«ãããå®è¡ãããŠããã¢ã³ããŠã€ã«ã¹ã«ãã£ãŠæ€åºãããŸãã éå®åã®ã¢ã¯ãã£ããã£ãçºçãããã·ã³ã¯ãããã«èªåçã«éé¢ãããŸããããã¯ãæ®éã§ã¯ãªãããšããããã¹ãŠã®äººãé¥ãç¹å¥ãªã»ã°ã¡ã³ãã§ãã
ããã«æšæºçãªå¯Ÿçãããšãã°å
žåçãªãµã³ãããã¯ã¹ãåºå®ã§ããŸãã
ææ°ã®ãã«ãŠã§ã¢ã¯ãåäžã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§èœã¡çããéåžžã«å°ããªä¿¡å·ã管çãµãŒããŒã«éä¿¡ãããããã§ã«ãæçšãªãè² è·ãéã¶2çªç®ã®ãããã¯ãå±éããŸãã ãã®å Žåãæ€åºãããã®ã¯ãã«ãŠã§ã¢ã®ç¬¬2äžä»£ã§ããæåã®ããµã€ã¬ã³ããã¯ã·ã¹ãã ã«æ®ããŸãã 幞éãªå Žåãã¢ã³ããŠã€ã«ã¹ã¯äž¡æ¹ã®ãããã¯ãæ€åºããŠæ®ºãå¯èœæ§ããããŸããããããã¯ãŒã¯ã®ç«¯ã§çºçããå¯èœæ§ãé«ãããã®åŸãæå®³ã远跡ããããã«å€ãã®äœæ¥ãè¡ãå¿
èŠããããŸãã ãŸãããã€ããŒãã€ã¶ãŒã¬ãã«ã䜿çšããªããŠã€ã«ã¹å¯Ÿçèªäœã®çµ±åã¯ãããè€éã§ãã
2017幎3æ17æ¥ã«ãKasperskyã¯NSXã®Agentless ProtectionãæŽæ°ããŸããã
ã·ããªãª2ïŒéèŠãªãµãŒãã¹ã«å¯Ÿããæšçåæ»æ
ç¹ã«éèŠãªã³ã³ãã¥ãŒã¿ãŒããã³ãµãŒããŒïŒç°¿èšãSWIFTãžã®ã¢ã¯ã»ã¹æš©ãæã€ãã·ã³ãåŠçãµãŒããŒïŒã«å¯Ÿããæ»æã¯ãã»ãšãã©ã®å ŽåDDoSãšããŠå§ãŸãããã«ãŠã§ã¢ãå®è¡ãç¶ããŸãã ããã¯ç°¡åã«è§£æ±ºãããŸãïŒå®å
šãªã«ãããªãã®ããã«ããã1ã€ïŒå¿
èŠã«å¿ããŠ2ã€ã3ã€ïŒDMZããµãŒããŒã°ã«ãŒãå
ã«äœæãããŸãã ãã¡ãããããã«ã€ããŠåãã£ãŠèããªããã°ãªããŸããã
ãã¡ãããéåžžã®ç®¡çè
ã¯å¥ã®ãããã¯ãŒã¯ãæã£ãŠãããããé·å¹Žã«ããã£ãŠç©Žãéããã«åçŽã«ç¶æããããšã¯ããå°é£ã§ãã ãŸããéäžåãªãã ãŸãããããã¯ãŒã¯ãŸãã¯ä»®æ³ãã·ã³ã転éãããšãããŒã«ãçºçããå¯èœæ§ãããããã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã®å Žåã確çã¯ã¯ããã«äœããªããŸãã
ã·ããªãª3ïŒã©ã³ãã ãªèª€ã£ãç§»è¡ãŸãã¯åçŽåããããããã¯ãŒã¯åæå
ããŒã¿æå€±ã®3åã®1ã®ã¿ãæ»æè
ã®ã¢ã¯ã·ã§ã³ã«é¢é£ããŠããŸãã æ®ãã¯ããããµããèŠèœãšããŸãã¯åãªãæããã§ãã é®®æãªäŸã¯ããããã¯ãŒã¯ã§éåžžã«é »ç¹ã«çºçãã倿Žã§ããããšãã°ããããµããããããå¥ã®ãµãããããžã®ãã·ã³ãŸãã¯ãã·ã³ã®ã°ã«ãŒãã®ç§»è¡ïŒããå®å
šãªãã®ããå®å
šæ§ã®äœããã®ãžã®ç§»è¡ã§ããããã«ãããç§»è¡ããããã·ã³ã¯è
åšã®åã§ã裞ãã«ãªããŸãïŒã
ãœãªã¥ãŒã·ã§ã³ã¯ããã·ã³ãŸãã¯ãã·ã³ã®ã°ã«ãŒããžã®ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãšãããã¡ã€ã«å²ãåœãŠã§ãã ãããã£ãŠãã»ãã¥ãªãã£èšå®ããã³å¿
èŠãªãã¹ãŠã®ãã¡ã€ã¢ãŠã©ãŒã«ïŒãã€ããŒãã€ã¶ãŒã«ãã£ãŠå®è£
ïŒã¯ãç§»è¡ã®æ¹æ³ãšå Žæã«é¢ä¿ãªãVMã«æ®ããŸãã
ç§ã®ãæ°ã«å
¥ãã®äŸã¯ãããå°å£²ãã§ãŒã³ã§ãªã¹ã¯ã誀ã£ãŠè©äŸ¡ãããããšã§ãã ãã±ãããªãã£ã¹ã¯ãŠãŒã¶ãŒãŸãŒã³ã«ç§»è¡ããŸããïŒããæ£ç¢ºã«ã¯ã6ãæåŸã«ãŠãŒã¶ãŒæš©éã倿ŽãããŸããïŒã 誰ããæ¬¡ã®ãããã§äœããå¿ããŠããŸã£ã-ãããŠã圌ãã¯è£žã®ããŒã¿ããŒã¹ãå€ã«åºããŸããã
ã·ããªãª4ïŒç¹ã«æåãããã³ãã¹ã
ããã¯æ¬åœã«å¥ã®ã·ããªãªã§ãããã®ãããªåŠšå®³ã®ããã«ãæãæã€ããšã¯éåžžã«èŠçã ããã§ãã ç¹ã«éèéšéã§ã ç§ã¯éåžžã«ç°¡åãªè©±ãèŠãŸããïŒéè¡ãïŒãã¹ãç°å¢ã§ïŒç¹å®ã®VMã°ã«ãŒãã®äŸµå
¥ãåœããŸããã ãã³ãã¹ã¿ãŒã¯æãæã«ãããããã¹ãç°å¢ãæãäžããã¡ã€ã³ã»ã°ã¡ã³ãã«è¡ããABSãµãŒããŒã1æ¥é眮ããŠãå°ã倢äžã«ãªã£ãã ããã¯åãªã段èœã§ãïŒ
äžè¬ã«ããã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã¯ããããã¯ãŒã¯ããŸã£ããæ¥ç¶ãããŠããªããã®ããã«ããããã¯ãŒã¯ãäºãã«ãç©ççã«ãèŠããªãããã«ããã®ã«åœ¹ç«ã¡ãŸãã 圌ãã¯ãŸã ãã€ããŒãã€ã¶ãŒã®ã¬ãã«ã«ã¯éããŸããïŒå°ãªããšããäžçã¯ã©ã¹ã®0ãã€ããªããã°ïŒã çªç¶äœãã管çè
æš©éãååŸããŠæ¡æ£ããå Žåããã€ããŒãã€ã¶ãŒã¯ããããã£ããããŸãã ãŸããä»®æ³ãã·ã³ã®ããŒã«ããã¯ã¯ã¯ããã«ç°¡åã§ãã
ã·ããªãª5ïŒå€åãã®ãµãŒãã¹ãæ»æããŠãå
éšãããã¯ãŒã¯ã®åé¡ãåŒãèµ·ãã
å°å£²åºã«WebãµãŒããŒããããŸãã åé¢ãšãŠã§ãã®éã«åé¢ãšéããããŒãããããŸãã
圌ãã¯åœŒãæã«å
¥ãããšåæã«ããã§ãã¯ã¢ãŠãã©ã€ã³ãããŠã³ããŸããã 管çè
ã¯æ¬¡ã®æ¥ã«æ°ããä»äºãæ¢ããŠããŸãã äžè¬ã«ãæ»æã®æ¬è³ªã¯ãæ»æè
ãã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹å¯èœãªã¢ããªã±ãŒã·ã§ã³ãµãŒããŒãŸãã¯WebãµãŒããŒã®è匱æ§ãæªçšããäŒæ¥ã€ã³ãã©ã¹ãã©ã¯ãã£å
ã®éèŠãªãµãŒããŒããã³ããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ããããšã§ãã ãŸãããŸãã¯åã«ãã£ããœãŒã ã®äžã«ãã¹ãŠãå
¥ããŸãã
ãã®ãã©ãã€ã ã¯ã圹å²ãå®è¡ãããµãŒããŒããšã«ç¹å®ã®ã»ãã¥ãªãã£èšå®ãããããã«ãåãµãŒãã¹ãµãŒããŒã®ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãæ³å®ããŠããŸãã ãããã¡ã€ã«ã䜿çšããŠæ§æå¯èœã
ãã®ä»ã®ã·ããªãª
äžè¬ã«ãä»ã®ã·ããªãªã¯ã»ãŒåãæ¹æ³ã§è§£æ±ºãããŠããŸãã ããšãã°ãç§ãã¡ã®èгç¹ãããããšãã€ã³ãµã€ããŒã¯ææããAWPã«ãããŸããã ãããŠã圌ãè¡åããããã¢ã«ãŠã³ããååŸãããã¯é¢ä¿ãããŸããã éå®åã¢ã¯ãã£ããã£-éé¢-圱é¿ãåããVMã®é²è¡ãšãã®ââåŸã®ããŒã«ããã¯ã
è¡ãæ¹
å®çšçãªã±ãŒã¹ã®1ã€ã«ã€ããŠè©±ããŸãããã
- 調æ»ã宿œããŸããã ãã®èª¿æ»ã§ã¯ããããã¯ãŒã¯ããããžãä»®æ³ã€ã³ãã©ã¹ãã©ã¯ãã£ã¢ãŒããã¯ãã£ãå±éãããã·ã¹ãã ãšãµãŒãã¹ã®çš®é¡ãèšé²ããŸããã ãã®æ®µéã§ããã¹ãŠã®æ
å ±ãããŒïŒãŠãŒã¶ãŒããµãŒãã¹ã管çãã©ãã£ãã¯ãç£èŠããã³æŽæ°ãã©ãã£ãã¯ïŒã決å®ãããèšé²ãããŸãã
- ãããã¯ãŒã¯ãå«ãä»®æ³ã€ã³ãã©ã¹ãã©ã¯ãã£ã®å€æŽã®åæãšèšèšã¯ã調æ»ã®æ®µéã§ç¹å®ãããéèŠåºŠã°ã«ãŒããšæäŸæ©èœãèæ
®ããŠå®è¡ãããŸãã
- VMãã¹ãã°ã«ãŒãã®ãããã¡ã€ã«ïŒVMã°ã«ãŒããããŒã«ãã»ãã¥ãªãã£èšå®ãITUèšå®ããŠãŒã¶ãŒã°ã«ãŒãã¢ã¯ã»ã¹èšå®ïŒã®åææ§æãå®è¡ãããŸãã
- çæããããããã¡ã€ã«ãé©çšãããäœæ¥ãç£èŠãããŸãã å¿
èŠã«å¿ããŠã調æŽãè¡ãããŸãã ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãå®è£
ããå ŽåãããŒããã©ã¹ããã¢ãã«ã䜿çšãããŸãã ãã®ã¢ãã«ã§ã¯ãæåã¯äœãä¿¡é Œãããæ€èšŒæžã¿ã®ä¿¡é Œã§ããçžäºäœçšã®ã¿ãèš±å¯ããŸãã
- ãã®ãœãªã¥ãŒã·ã§ã³ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£å
šäœã«å¯Ÿå¿ããŸãã
ããã«ãã€ã³ãã©ã¹ãã©ã¯ãã£å
šäœããæå°éã®äººå¡ã§åäžã®ã³ã³ãœãŒã«ããäžå
çã«ç¶æããã³ç®¡çãããŸãã ã°ã«ãŒããšãããã¡ã€ã«ã圢æããããã®ç®çã¯ååã«é«éã§ãã å²ãåœãŠããããããã¡ã€ã«ã¯ãåãä»®æ³ã€ã³ãã©ã¹ãã©ã¯ãã£å
ã®ã©ãã§ãæ©èœããŸãã ITUããã³ã»ãã¥ãªãã£èšå®ã®ç®¡çã«å ããŠããµãŒããŒããã³ãµãŒãã¹ã®ç§»è¡ãæŽæ°ã詊é転ãããã³å»æ£ã®ããã»ã¹ãéäžç®¡çãããŸãã
ç¹ã«èšåããNSXãœãªã¥ãŒã·ã§ã³ã®éèŠãªãã€ã³ãïŒ
- Cisco ASA 5520ãã¡ã€ã¢ãŠã©ãŒã«ã亀æããå¿
èŠããããŸãã
- ãµãããããšVLANã«é¢ä¿ãªããããŒã¿ã»ã³ã¿ãŒãåå¥ã®ã»ã°ã¡ã³ãã«åå²ããæ©èœã
- OSããã³ãã®ååã«å¿ããVMãžã®ããªã·ãŒã®é©çšã
- ãªã¢ãŒããã©ã³ããšã®éä¿¡ã®ããã®IPsecãœãªã¥ãŒã·ã§ã³ã®ãµããŒãã
ãã®ãããªãããã¯ãŒã¯ããããŸããïŒ

å®è£
ã®åã«ãVMware vRealize Network InsightãŠãŒãã£ãªãã£ã䜿çšããŠãä»®æ³ããŒã¿ã»ã³ã¿ãŒã§ãã©ãã£ãã¯ããæµãããæ¹æ³ãçè§£ããããã«ç£æ»ã宿œããŸããã ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã«ãŒã«ãèšå®ããã®ã«åœ¹ç«ã¡ãŸãã æ¬¡ã®ããã«ãªããŸãã
åºæãããŠãã客æ§ãé¢å¿ã®ãããã©ã¡ãŒã¿ãŒãæ¯èŒããŸããïŒããšãã°ãã¿ã¹ã¯ã®1ã€ãVPNã®çœ®ãæãã§ããïŒã
|
Cisco ASA 5520
|
Cisco ASA 5515-X
|
Cisco ASA 1000V
|
Cisco ASA 5555-X
|
VMware NSX Edge ïŒXã©ãŒãžïŒ
|
çš®é¡
|
ç©çããã€ã¹
|
ç©çããã€ã¹
|
ä»®æ³ãã·ã³
|
ç©çããã€ã¹
|
ä»®æ³ãã·ã³
|
æå€§ãã¡ã€ã¢ãŠã©ãŒã«ã¹ã«ãŒãããïŒæå€§ïŒ
|
0.4 Gbps
|
1.2 Gbps
|
1.2 Gbps
|
4 Gbps
|
9 Gbps
|
æå€§åæã»ãã·ã§ã³
|
280,000
|
245,000
|
200,000
|
1,000,000
|
1,000,000
|
1ç§ãããã®æå€§æ¥ç¶æ°
|
N / a
|
6000
|
10,000
|
50,000
|
131,000
|
VPN垯åå¹
|
250 Mbps
|
250 Mbps
|
200 Mbps
|
700 Mbps
|
2 gbps
|
æå€§IPsecãã³ãã«
|
750
|
250
|
750
|
5,000
|
6,000
|
æå€§SSLãã³ãã«
|
750
|
250
|
750
|
5,000
|
6,000
|
䞊è¡ããŠãç©çæ©åšã®ãããã¯ãŒã¯å³ãäœæããŸããã ç§ãã¡ã«ãšã£ãŠéèŠãªããšã¯ãããŒã¿ã»ã³ã¿ãŒå
ã®ãã©ãã£ãã¯ã®åããçè§£ããŠããªã·ãŒãæ§æããããšã§ãã åé€ãããããã«é©çšãããŸããã äœããã«ãããããå Žå-åŸã§è¿œå ããŸãã é©åãªããããäœæããŠãã¹ãŠã®ãµãŒãã¹ã決å®ããã«ã¯ã1ã2é±éã§ååã§ãã
èšçœ®ã¯ããªãç°¡åã§ã2ã€ã®ãã¬ãŒãã«èšçœ®ããŸããã è²»çšïŒ
æå
|
æ°é
|
â RAMïŒGBïŒ
|
âvCPU
|
âHDDïŒGBïŒ
|
NSX Manager
|
1
|
16
|
4
|
60
|
NSX Controller
|
3
|
12
|
12
|
60
|
NSX DLR
|
2
|
4
|
8
|
3
|
NSX EDGE
|
1
|
2
|
4
|
2
|
ã客æ§ã¯ãã§ã«VMware vSphereä»®æ³åç°å¢ã䜿çšããŠãããããNSXã®ã©ã€ã»ã³ã¹ã賌å
¥ããŸããã åœæãNSXãšãã£ã·ã§ã³ã¯ãªããã©ã€ã»ã³ã¹ã®è³Œå
¥ããã»ãŒ1ãæåŸã«ç»å ŽããŸããã 補åèªäœã¯ãœã±ããã§ã©ã€ã»ã³ã¹ãããŠããŸãã
ãã·ã³ãã°ã«ãŒãã«åå²ããŠã¿ã°ãå²ãåœãŠãASAãã忣ãã¡ã€ã¢ãŠã©ãŒã«ã«ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã転éããvRealize Network Insightãå床確èªããŠããã©ãã£ãã¯ãããŒãæ£ãã瀺ããäœãå¿ããŠããªãããšã確èªããŸããã
å©çïŒ
åç
§è³æ