
Palo Alto Networksãã¡ã€ã¢ãŠã©ãŒã«ã®ãã¹ãŠã®å©ç¹ã«ãããããããRuNetã§ãããã®ããã€ã¹ãæ§æããæ¹æ³ã«é¢ããè³æãããã®å®è£
ã®çµéšã説æããããã¹ãã¯ããŸããããŸããã ãã®ãã³ããŒã®æ©åšãšã®äœæ¥äžã«èç©ããè³æãèŠçŽããããŸããŸãªãããžã§ã¯ãã®å®è£
äžã«ééããæ©èœã«ã€ããŠè©±ãããšã«ããŸããã
ãã®èšäºã§ã¯ãPalo Alto Networksã«ç²Ÿéããããã«ãæãäžè¬çãªãã¡ã€ã¢ãŠã©ãŒã«ã¿ã¹ã¯ã®1ã€ã§ãããªã¢ãŒãã¢ã¯ã»ã¹çšã®SSL VPNã解決ããããã«å¿
èŠãªèšå®ã«ã€ããŠèª¬æããŸãã ãŸãããã¡ã€ã¢ãŠã©ãŒã«ã®äžè¬çãªæ§æããŠãŒã¶ãŒã®èå¥ãã¢ããªã±ãŒã·ã§ã³ãããã³ã»ãã¥ãªãã£ããªã·ãŒã®è£å©æ©èœã«ã€ããŠã説æããŸãã ãã®ãããã¯ãèªè
ã®é¢å¿ãåŒããã®ã§ããå Žåãä»åŸããµã€ãéVPNãåçã«ãŒãã£ã³ã°ãããã³ããã©ãã䜿çšããéäžç®¡çã®åæãå«ãè³æããªãªãŒã¹ããŸãã
ããã¢ã«ããããã¯ãŒã¯ã¹ã®ãã¡ã€ã¢ãŠã©ãŒã«ã¯ãApp-IDãUser-IDãContent-IDãªã©ã®å€ãã®é©æ°çãªãã¯ãããžãŒã䜿çšããŠããŸãã ãã®æ©èœã䜿çšãããšãé«åºŠãªã»ãã¥ãªãã£ãå®çŸããŸãã ããšãã°ãApp-IDã䜿çšãããšã䜿çšãããŠããããŒãããããã³ã«ïŒSSLãã³ãã«å
ãå«ãïŒã«é¢ä¿ãªãã眲åããã³ãŒããããã³ãã¥ãŒãªã¹ãã£ãã¯ã«åºã¥ããŠã¢ããªã±ãŒã·ã§ã³ãã©ãã£ãã¯ãèå¥ã§ããŸãã ãŠãŒã¶ãŒIDã䜿çšãããšãLDAPãšã®çµ±åã«ãããããã¯ãŒã¯ãŠãŒã¶ãŒãèå¥ã§ããŸãã Content-IDã䜿çšãããšããã©ãã£ãã¯ãã¹ãã£ã³ãã転éããããã¡ã€ã«ãšãã®ã³ã³ãã³ããèå¥ã§ããŸãã ãã®ä»ã®ãã¡ã€ã¢ãŠã©ãŒã«æ©èœã«ã¯ã䟵å
¥ä¿è·ãè匱æ§ããã³DoSæ»æã«å¯Ÿããä¿è·ãçµã¿èŸŒã¿ã®ã¹ãã€ãŠã§ã¢å¯ŸçãURLãã£ã«ã¿ãªã³ã°ãã¯ã©ã¹ã¿ãªã³ã°ãããã³éäžç®¡çãå«ãŸããŸãã
ãã¢ã³ã¹ãã¬ãŒã·ã§ã³ã®ããã«ãããã€ã¹åãADãã¡ã€ã³åãããã³IPã¢ãã¬ã¹ãé€ããŠãå®éã®æ§æãšåãæ§æã®åé¢ãããã¹ã¿ã³ãã䜿çšããŸãã å®éã«ã¯ããã¹ãŠãããè€éã§ã-å€ãã®ãã©ã³ããããå ŽåããããŸãã ãã®å Žåãåäžã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãªããäžå€®ãµã€ãã®å¢çã«ã¯ã©ã¹ã¿ãŒãã€ã³ã¹ããŒã«ãããåçã«ãŒãã£ã³ã°ãå¿
èŠã«ãªãå ŽåããããŸãã
ã¹ã¿ã³ãã¯
PAN-OS 7.1.9ã䜿çšããŸãã å
žåçãªæ§æãšããŠãå¢çã«Palo Alto Networksãã¡ã€ã¢ãŠã©ãŒã«ããããããã¯ãŒã¯ãèããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã¯ãæ¬ç€Ÿãžã®ãªã¢ãŒãSSL VPNã¢ã¯ã»ã¹ãæäŸããŸãã Active Directoryãã¡ã€ã³ã¯ãŠãŒã¶ãŒããŒã¿ããŒã¹ãšããŠäœ¿çšãããŸãïŒå³1ïŒã
å³1-ãããã¯ãŒã¯ãããã¯å³èšå®æé ïŒ
- ããã€ã¹ã®ããªã»ããã ååã管çIPã¢ãã¬ã¹ãéçã«ãŒãã管çè
ã¢ã«ãŠã³ãã管çãããã¡ã€ã«ã®èšå®
- ã©ã€ã»ã³ã¹ãã€ã³ã¹ããŒã«ããã¢ããããŒããèšå®ããã³ã€ã³ã¹ããŒã«ããŸã
- ã»ãã¥ãªãã£ãŸãŒã³ããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ããã©ãã£ãã¯ããªã·ãŒãã¢ãã¬ã¹å€æã®æ§æ
- LDAPèªèšŒãããã¡ã€ã«ãšãŠãŒã¶ãŒIDãæ§æãã
- SSL VPNãæ§æãã
1.ããªã»ãã
Palo Alto Networksãã¡ã€ã¢ãŠã©ãŒã«ãæ§æããããã®äž»èŠãªããŒã«ã¯Webã€ã³ã¿ãŒãã§ãŒã¹ã§ãããCLIãä»ããå¶åŸ¡ãå¯èœã§ãã ããã©ã«ãã§ã¯ã管çã€ã³ã¿ãŒãã§ãŒã¹ã®IPã¢ãã¬ã¹ã¯192.168.1.1/24ããã°ã€ã³ïŒadminããã¹ã¯ãŒãïŒadminã§ãã
ã¢ãã¬ã¹ã倿Žããã«ã¯ãåããããã¯ãŒã¯ããWebã€ã³ã¿ãŒãã§ã€ã¹ã«æ¥ç¶ãããã
set deviceconfig system ip-address <> netmask <>ã³ãã³ãã䜿çšããŸãã æ§æã¢ãŒãã§å®è¡ãããŸãã configureã³ãã³ãã䜿çšããŠãæ§æã¢ãŒãã«åãæ¿ããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã®ãã¹ãŠã®å€æŽã¯ãã³ãã³ãã©ã€ã³ã¢ãŒããšWebã€ã³ã¿ãŒãã§ã€ã¹ã®äž¡æ¹ã§ã
commitã³ãã³ãã§èšå®ã確èªããåŸã«ã®ã¿çºçããŸãã
Webã€ã³ã¿ãŒãã§ãŒã¹ã®èšå®ã倿Žããã«ã¯ã
ãããã€ã¹->äžè¬èšå®ãããã³ãããã€ã¹->管çã€ã³ã¿ãŒãã§ãŒã¹èšå®ãã»ã¯ã·ã§ã³ã䜿çšããŸã
ã ååããããŒãã¿ã€ã ãŸãŒã³ããã®ä»ã®èšå®ã¯ãäžè¬èšå®ã»ã¯ã·ã§ã³ã§èšå®ã§ããŸãïŒå³2ïŒã
å³2-管çã€ã³ã¿ãŒãã§ã€ã¹ã®ãã©ã¡ãŒã¿ãŒESXiç°å¢ã§ä»®æ³ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšãããŠããå ŽåãïŒäžè¬èšå®ïŒã»ã¯ã·ã§ã³ã§ããã€ããŒãã€ã¶ãŒã«ãã£ãŠå²ãåœãŠãããMACã¢ãã¬ã¹ã®äœ¿çšãæå¹ã«ãããããã¡ã€ã¢ãŠã©ãŒã«ã€ã³ã¿ãŒãã§ã€ã¹ã§æå®ããããã€ããŒãã€ã¶ãŒã§MACã¢ãã¬ã¹ãæ§æããããä»®æ³ã¹ã€ããã®èšå®ã倿ŽããŠMACã®å€æŽãèš±å¯ããå¿
èŠããããŸãã¢ãã¬ã¹ã ããããªããšããã©ãã£ãã¯ã¯ééããŸããã
管çã€ã³ã¿ãŒãã§ã€ã¹ã¯åå¥ã«æ§æããããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®ãªã¹ãã«ã¯è¡šç€ºãããŸããã [
管çã€ã³ã¿ãŒãã§ã€ã¹ã®èšå®]ã»ã¯ã·ã§ã³ã§ã¯ã管çã€ã³ã¿ãŒãã§ã€ã¹ã®ããã©ã«ãã²ãŒããŠã§ã€ãæå®ããŸãã ä»ã®éçã«ãŒãã¯ãä»®æ³ã«ãŒã¿ãŒã»ã¯ã·ã§ã³ã§æ§æãããŸããããã«ã€ããŠã¯åŸã§èª¬æããŸãã
ä»ã®ã€ã³ã¿ãŒãã§ãŒã¹ãä»ããããã€ã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããã«ã¯ã
[ãããã¯ãŒã¯]-> [ãããã¯ãŒã¯ãããã¡ã€ã«]-> [ã€ã³ã¿ãŒãã§ãŒã¹ç®¡ç]ã»ã¯ã·ã§ã³ã§
管çãããã¡ã€ã«ãäœæããé©åãªã€ã³ã¿ãŒãã§ãŒã¹ã«å²ãåœãŠãå¿
èŠããããŸãã
次ã«ãæŽæ°ãåä¿¡ããæå»ãæ£ãã衚瀺ããããã«ã[
ããã€ã¹]-> [ãµãŒãã¹]ã»ã¯ã·ã§ã³ã§DNSãšNTPãæ§æããå¿
èŠããããŸãïŒå³3ïŒã ããã©ã«ãã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠçæããããã¹ãŠã®ãã©ãã£ãã¯ã¯ã管çã€ã³ã¿ãŒãã§ã€ã¹ã®IPã¢ãã¬ã¹ããœãŒã¹IPã¢ãã¬ã¹ãšããŠäœ¿çšããŸãã
Service Route Configurationã»ã¯ã·ã§ã³ã§ãç¹å®ã®åãµãŒãã¹ã«ç°ãªãã€ã³ã¿ãŒãã§ã€ã¹ãå²ãåœãŠãããšãã§ããŸãã
å³3-DNSãNTPãããã³ã·ã¹ãã ã«ãŒãèšå®2.ã©ã€ã»ã³ã¹ãã€ã³ã¹ããŒã«ããã¢ããããŒããèšå®ããã³ã€ã³ã¹ããŒã«ããŸã
ãã¡ã€ã¢ãŠã©ãŒã«ã®ãã¹ãŠã®æ©èœãå®å
šã«åäœãããã«ã¯ãã©ã€ã»ã³ã¹ãã€ã³ã¹ããŒã«ããå¿
èŠããããŸãã ãã©ã€ã¢ã«ã©ã€ã»ã³ã¹ã¯ãããã¢ã«ããããã¯ãŒã¯ããŒãããŒã«ãªã¯ãšã¹ãããããšã§äœ¿çšã§ããŸãã æå¹æéã¯30æ¥ã§ãã ã©ã€ã»ã³ã¹ã¯ããã¡ã€ã«ãŸãã¯èªèšŒã³ãŒãã䜿çšããŠã¢ã¯ãã£ãåãããŸãã ã©ã€ã»ã³ã¹ã¯ã[
ããã€ã¹]-> [ã©ã€ã»ã³ã¹]ã»ã¯ã·ã§ã³ã§æ§æãããŸãïŒå³4ïŒã
ã©ã€ã»ã³ã¹ãã€ã³ã¹ããŒã«ãããã[
ããã€ã¹]-> [åçæŽæ°]ã»ã¯ã·ã§ã³ã§æŽæ°ããã°ã©ã ã®ã€ã³ã¹ããŒã«ãæ§æããå¿
èŠããããŸãã
[ããã€ã¹]-> [ãœãããŠã§ã¢]ã»ã¯ã·ã§ã³ã§ãPAN-OSã®æ°ããããŒãžã§ã³ãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ã§ããŸãã
å³4-ã©ã€ã»ã³ã¹ã³ã³ãããŒã«ããã«3.ã»ãã¥ãªãã£ãŸãŒã³ããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ããã©ãã£ãã¯ããªã·ãŒãã¢ãã¬ã¹å€æã®æ§æ
Palo Alto Networksãã¡ã€ã¢ãŠã©ãŒã«ã¯ããããã¯ãŒã¯ã«ãŒã«ãæ§æãããšãã«ãŸãŒã³ããžãã¯ãé©çšããŸãã ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã¯ç¹å®ã®ãŸãŒã³ã«å²ãåœãŠããããã©ãã£ãã¯ã«ãŒã«ã§äœ¿çšãããŸãã ãã®ã¢ãããŒãã«ãããå°æ¥ãã€ã³ã¿ãŒãã§ãŒã¹èšå®ã倿Žãããšãã«ããã©ãã£ãã¯ã«ãŒã«ã倿Žããã®ã§ã¯ãªããå¿
èŠãªã€ã³ã¿ãŒãã§ãŒã¹ã察å¿ãããŸãŒã³ã«åå²ãåœãŠããããšãã§ããŸãã ããã©ã«ãã§ã¯ããŸãŒã³å
ã®ãã©ãã£ãã¯ã¯èš±å¯ããããŸãŒã³éã®ãã©ãã£ãã¯ã¯çŠæ¢ãããŸããããã«ã¯ã
intrazone-defaultããã³
interzone-defaultã®äºåå®çŸ©ã«ãŒã«ã責任ãè² ã
ãŸã ã
å³5-ã»ãã¥ãªãã£ãŸãŒã³ãã®äŸã§ã¯ãå
éšãããã¯ãŒã¯ã®ã€ã³ã¿ãŒãã§ã€ã¹ã¯
å
éšãŸãŒã³ã«å²ãåœãŠãããã€ã³ã¿ãŒãããã«åããããã€ã³ã¿ãŒãã§ã€ã¹ã¯
å€éšãŸãŒã³ã«å²ãåœãŠãããŸãã
vpnãŸãŒã³ã«å²ãåœãŠãããSSL VPNçšã®ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ãäœæãããŸããïŒå³5ïŒã
Palo Alto Networksãã¡ã€ã¢ãŠã©ãŒã«ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã¯ã5ã€ã®ç°ãªãã¢ãŒãã§åäœã§ããŸãã
- ã¿ãã -ç£èŠããã³åæã®ããã«ãã©ãã£ãã¯ãåéããããã«äœ¿çšãããŸãã
- HA-ã¯ã©ã¹ã¿ãŒæäœã«äœ¿çš
- ä»®æ³ã¯ã€ã€ -ãã®ã¢ãŒãã§ã¯ãPalo Alto Networksã¯2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ãçµã¿åãããMACã¢ãã¬ã¹ãšIPã¢ãã¬ã¹ã倿Žããã«ããããã®éã§ééçã«ãã©ãã£ãã¯ãæž¡ããŸã
- Layer2-ã¹ã€ããã¢ãŒã
- ã¬ã€ã€ãŒ3-ã«ãŒã¿ãŒã¢ãŒã
å³6-ã€ã³ã¿ãŒãã§ãŒã¹ã®åäœã¢ãŒãã®èšå®ãã®äŸã§ã¯ãLayer3ã¢ãŒãã䜿çšãããŸãïŒå³6ïŒã ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®ãã©ã¡ãŒã¿ãŒã¯ãIPã¢ãã¬ã¹ãåäœã¢ãŒããããã³å¯Ÿå¿ããã»ãã¥ãªãã£ãŸãŒã³ã瀺ããŸãã ã€ã³ã¿ãŒãã§ãŒã¹ã®åäœã¢ãŒãã«å ããŠãä»®æ³ã«ãŒã¿ãŒã«å²ãåœãŠãå¿
èŠããããŸããããã¯ãPalo Alto Networksã®VRFã€ã³ã¹ã¿ã³ã¹ã«é¡äŒŒããŠããŸãã ä»®æ³ã«ãŒã¿ãŒã¯çžäºã«åé¢ãããŠãããç¬èªã®ã«ãŒãã£ã³ã°ããŒãã«ãšãããã¯ãŒã¯ãããã³ã«èšå®ããããŸãã
ä»®æ³ã«ãŒã¿ãŒã®èšå®ã¯ãéçã«ãŒããšã«ãŒãã£ã³ã°ãããã³ã«ã®èšå®ã瀺ããŸãã ãã®äŸã§ã¯ãå€éšãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹çšã«ããã©ã«ãã«ãŒãã®ã¿ãäœæãããŸããïŒå³7ïŒã
å³7-ä»®æ³ã«ãŒã¿ãŒã®æ§ææ¬¡ã®èšå®æé ã¯ããã©ãã£ãã¯ããªã·ãŒã®ã»ã¯ã·ã§ã³
ããªã·ãŒ->ã»ãã¥ãªãã£ã§ãã æ§æã®äŸãå³8ã«ç€ºããŸããã«ãŒã«ã®ããžãã¯ã¯ããã¹ãŠã®ãã¡ã€ã¢ãŠã©ãŒã«ãšåãã§ãã æåã«äžèŽãããŸã§ãã«ãŒã«ã¯äžããäžã«ãã§ãã¯ãããŸãã ã«ãŒã«ã®ç°¡åãªèª¬æïŒ
1. WebããŒã¿ã«ãžã®SSL VPNã¢ã¯ã»ã¹ã ãªã¢ãŒãæ¥ç¶ãèªèšŒããããã®WebããŒã¿ã«ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸã
2. VPNãã©ãã£ãã¯-ãªã¢ãŒãæ¥ç¶ãšæ¬ç€Ÿéã®ãã©ãã£ãã¯ãèš±å¯ããŸã
3.åºæ¬çãªã€ã³ã¿ãŒããã-dnsãpingãtracerouteãntpã¢ããªã±ãŒã·ã§ã³ã®èš±å¯ã ãã¡ã€ã¢ãŠã©ãŒã«ã¯ãããŒãçªå·ãšãããã³ã«çªå·ã§ã¯ãªãã眲åããã³ãŒããããã³ãã¥ãŒãªã¹ãã£ãã¯ã«åºã¥ããã¢ããªã±ãŒã·ã§ã³ãèš±å¯ãããããapplication-defaultã¯Serviceã»ã¯ã·ã§ã³ã§æå®ãããŸãã ãã®ã¢ããªã±ãŒã·ã§ã³ã®ããã©ã«ãã®ããŒã/ãããã³ã«
4. Webã¢ã¯ã»ã¹-ã¢ããªã±ãŒã·ã§ã³å¶åŸ¡ãªãã§HTTPããã³HTTPSçµç±ã§ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããèš±å¯
5,6ã ä»ã®ãã©ãã£ãã¯ã®ããã©ã«ãã«ãŒã«ã
å³8-ãããã¯ãŒã¯ã«ãŒã«ã®èšå®äŸNATãèšå®ããã«ã¯ã[
ããªã·ãŒ]-> [NAT]ã»ã¯ã·ã§ã³ã䜿çšã
ãŸã ã NATæ§æã®äŸãå³9ã«ç€ºããŸãã
å³9-NATèšå®ã®äŸå
éšããå€éšãžã®ãã©ãã£ãã¯ã«ã€ããŠã¯ãéä¿¡å
ã¢ãã¬ã¹ããã¡ã€ã¢ãŠã©ãŒã«ã®å€éšIPã¢ãã¬ã¹ã«å€æŽããåçããŒãã¢ãã¬ã¹ïŒPATïŒã䜿çšã§ããŸãã
4. LDAPèªèšŒãããã¡ã€ã«ãšãŠãŒã¶ãŒè奿©èœãæ§æãããŠãŒã¶ãŒãSSL-VPNçµç±ã§æ¥ç¶ããåã«ãèªèšŒã¡ã«ããºã ãæ§æããå¿
èŠããããŸãã ãã®äŸã§ã¯ãPalo Alto Networks Webã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠActive Directoryãã¡ã€ã³ã³ã³ãããŒã©ãŒã§èªèšŒãè¡ãããŸãã
å³10-LDAPãããã¡ã€ã«èªèšŒãæ©èœãããã«ã¯ã
LDAPãããã¡ã€ã«ãš
èªèšŒãããã¡ã€ã«ãæ§æããå¿
èŠããããŸãã
[ããã€ã¹]-> [ãµãŒããŒãããã¡ã€ã«]-> [LDAP]ã»ã¯ã·ã§ã³ïŒå³10ïŒã§ã¯ã
ãµãŒããŒãªãã¬ãŒã¿ãŒ ã
ã€ãã³ããã°ãªãŒã㌠ã
忣COMãŠãŒã¶ãŒã°ã«ãŒãã«å«ãŸãããã¡ã€ã³ã³ã³ãããŒã©ãŒã®IPã¢ãã¬ã¹ãšããŒããLDAPã¿ã€ããšãŠãŒã¶ãŒã¢ã«ãŠã³ããæå®ããå¿
èŠããããŸãã æ¬¡ã«ã
[ããã€ã¹]-> [èªèšŒãããã¡ã€ã«]ã»ã¯ã·ã§ã³ã§èªèšŒãããã¡ã€ã«ãäœæãïŒå³11ïŒã以åã«äœæãã
LDAPãããã¡ã€ã«ãããŒã¯ãã[詳现èšå®]ã¿ãã§ãªã¢ãŒãã¢ã¯ã»ã¹ãèš±å¯ãããŠãŒã¶ãŒã®ã°ã«ãŒãïŒå³12ïŒãæå®ããŸãã ãããã¡ã€ã«ã®
User Domainãã©ã¡ãŒã¿ã«æ³šæããããšãéèŠã§ããããããªããšãã°ã«ãŒãããŒã¹ã®èªèšŒãæ©èœããŸããã ãã®ãã£ãŒã«ãã«ã¯ãNetBIOSãã¡ã€ã³åãå«ãŸããŠããå¿
èŠããããŸãã
å³11-èªèšŒãããã¡ã€ã«
å³12-ADã°ã«ãŒãã®éžææ¬¡ã®ã¹ãããã¯ã
ããã€ã¹->ãŠãŒã¶ãŒèå¥ãæ§æããããšã§ãã ããã§ã¯ããã¡ã€ã³ã³ã³ãããŒã©ãŒã®IPã¢ãã¬ã¹ãæ¥ç¶ã®è³æ Œæ
å ±ãæå®ãã
ã»ãã¥ãªãã£ãã°ã® æå¹åãã»ãã·ã§ã³ã® æå¹åããããŒãã® æå¹åã®èšå®ãæ§æããå¿
èŠããããŸãïŒå³13ïŒã [
ã°ã«ãŒããããã³ã°]ã»ã¯ã·ã§ã³ïŒå³14ïŒã§ã¯ãLDAPã®ãªããžã§ã¯ããèå¥ããããã®ãã©ã¡ãŒã¿ãŒãšãæ¿èªã«äœ¿çšãããã°ã«ãŒãã®ãªã¹ãã«æ³šæããå¿
èŠããããŸãã èªèšŒãããã¡ã€ã«ãšåãããã«ãããã§ã¯ãŠãŒã¶ãŒãã¡ã€ã³ãã©ã¡ãŒã¿ãŒãèšå®ããå¿
èŠããããŸãã
å³13-ãŠãŒã¶ãŒãããã³ã°ãã©ã¡ãŒã¿ãŒ
å³14-ã°ã«ãŒããããã³ã°ãã©ã¡ãŒã¿ãŒãã®æé ã®æåŸã®æé ã¯ãVPNãŸãŒã³ãšãã®ãŸãŒã³ã®ã€ã³ã¿ãŒãã§ã€ã¹ãäœæããããšã§ãã ã€ã³ã¿ãŒãã§ã€ã¹ã§ã
[ãŠãŒã¶ãŒèå¥ãæå¹ã«ãã]ãã©ã¡ãŒã¿ãŒã
æå¹ã«ããŸãïŒå³15ïŒã
å³15-VPNãŸãŒã³ã®æ§æ5. SSL VPNãæ§æãã
SSL VPNã«æ¥ç¶ããåã«ããªã¢ãŒããŠãŒã¶ãŒã¯WebããŒã¿ã«ã«ã¢ã¯ã»ã¹ããŠãGlobal Protectã¯ã©ã€ã¢ã³ããèªèšŒããã³ããŠã³ããŒãããå¿
èŠããããŸãã æ¬¡ã«ããã®ã¯ã©ã€ã¢ã³ãã¯è³æ Œæ
å ±ãèŠæ±ããäŒæ¥ãããã¯ãŒã¯ã«æ¥ç¶ããŸãã WebããŒã¿ã«ã¯httpsã¢ãŒãã§åäœããããããã®ããã®èšŒææžãã€ã³ã¹ããŒã«ããå¿
èŠããããŸãã å¯èœã§ããã°ãå
¬éèšŒææžã䜿çšããŠãã ããã ãã®å ŽåããŠãŒã¶ãŒã«ã¯ããµã€ãã§èšŒææžãç¡å¹ã§ããããšã«é¢ããèŠåã¯è¡šç€ºãããŸããã ãããªãã¯èšŒææžã䜿çšã§ããªãå Žåã¯ãç¬èªã®èšŒææžãçºè¡ããå¿
èŠããããŸããããã¯ãhttpsã®WebããŒãžã§äœ¿çšãããŸãã èªå·±çœ²åããããšããããŒã«ã«ã®èšŒææ©é¢ãéããŠçºè¡ããããšãã§ããŸãã ãŠãŒã¶ãŒãWebããŒã¿ã«ã«æ¥ç¶ãããšãã«ãšã©ãŒãåãåããªãããã«ããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã®ä¿¡é Œãããã«ãŒãã»ã³ã¿ãŒã®ãªã¹ãã«ã«ãŒãèšŒææžãŸãã¯èªå·±çœ²åèšŒææžãå¿
èŠã§ãã ãã®äŸã§ã¯ãActive DirectoryèšŒææžãµãŒãã¹ã®èšŒææ©é¢ãéããŠçºè¡ãããèšŒææžã䜿çšãããŸãã
èšŒææžãçºè¡ããã«ã¯ãã»ã¯ã·ã§ã³
ããã€ã¹->èšŒææžç®¡ç->èšŒææž->çæââã§èšŒææžãªã¯ãšã¹ããäœæããå¿
èŠããããŸãã ãªã¯ãšã¹ãã§ãèšŒææžã®ååãšWebããŒã¿ã«ã®IPã¢ãã¬ã¹ãŸãã¯FQDNãæå®ããŸãïŒå³16ïŒã èŠæ±ãçââæããåŸã
.csrãã¡ã€ã«ãããŠã³ããŒããããã®ã³ã³ãã³ããAD CS Webç»é²Webãã©ãŒã ã®èšŒææžèŠæ±ãã£ãŒã«ãã«ã³ããŒããŸãã èšŒææ©é¢ã®èšå®ã«å¿ããŠãèšŒææžèŠæ±ãæ¿èªããçºè¡ãããèšŒææžã
Base64ãšã³ã³ãŒãèšŒææžåœ¢åŒã§ããŠã³ããŒãããå¿
èŠããããŸãã ããã«ãèšŒææ©é¢ã®ã«ãŒãèšŒææžãããŠã³ããŒãããå¿
èŠããããŸãã æ¬¡ã«ãäž¡æ¹ã®èšŒææžããã¡ã€ã¢ãŠã©ãŒã«ã«ã€ã³ããŒãããå¿
èŠããããŸãã WebããŒã¿ã«ã®èšŒææžãã€ã³ããŒãããå Žåãä¿çã¹ããŒã¿ã¹ã®ãªã¯ãšã¹ããéžæããã€ã³ããŒããã¯ãªãã¯ããŸãã èšŒææžã®ååã¯ããªã¯ãšã¹ãã§ä»¥åã«æå®ãããååãšäžèŽããå¿
èŠããããŸãã ã«ãŒãèšŒææžã®ååã¯ä»»æã«æå®ã§ããŸãã èšŒææžãã€ã³ããŒãããåŸã
ããã€ã¹->èšŒææžç®¡çã»ã¯ã·ã§ã³ã§
SSL / TLSãµãŒãã¹ãããã¡ã€ã«ãäœæããå¿
èŠããããŸãã ãããã¡ã€ã«ã§ã以åã«ã€ã³ããŒãããèšŒææžãæå®ããŸãã
å³16-èšŒææžãªã¯ãšã¹ãæ¬¡ã®æé ã¯ã
ãããã¯ãŒã¯->ã°ããŒãã«ä¿è·ã»ã¯ã·ã§ã³ã§
ã°ããŒãã«ä¿è·ã²ãŒããŠã§ã€ãš
ã°ããŒãã«ä¿è·ããŒã¿ã«ãªããžã§ã¯ããæ§æããããšã§ãã
Global Protect Gatewayèšå®ã§
㯠ããã¡ã€ã¢ãŠã©ãŒã«ã®å€éšIPã¢ãã¬ã¹ãããã³ä»¥åã«äœæããã
SSLãããã¡ã€ã« ã
èªèšŒãããã¡ã€ã« ããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ãããã³ã¯ã©ã€ã¢ã³ãIPèšå®ãæå®ããŸãã ã¯ã©ã€ã¢ã³ãã«ã¢ãã¬ã¹ãå²ãåœãŠãããIPã¢ãã¬ã¹ã®ããŒã«ãæå®ããå¿
èŠããããŸããã¢ã¯ã»ã¹ã«ãŒãã¯ãã¯ã©ã€ã¢ã³ããã«ãŒããæã€ãµããããã§ãã ã¿ã¹ã¯ããã¹ãŠã®ãŠãŒã¶ãŒãã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ã§ã©ããããå Žåããµãããã0.0.0.0/0ãæå®ããå¿
èŠããããŸãïŒå³17ïŒã
å³17-IPã¢ãã¬ã¹ãšã«ãŒãã®ããŒã«ã®æ§ææ¬¡ã«ã
ã°ããŒãã«ä¿è·ããŒã¿ã«ãæ§æããå¿
èŠããããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã®IPã¢ãã¬ã¹ã
SSLãããã¡ã€ã«ãš
èªèšŒãããã¡ã€ã« ãããã³ã¯ã©ã€ã¢ã³ããæ¥ç¶ãããã¡ã€ã¢ãŠã©ãŒã«ã®å€éšIPã¢ãã¬ã¹ã®ãªã¹ããæå®ããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ãè€æ°ããå Žåãæ¥ç¶ãããã¡ã€ã¢ãŠã©ãŒã«ãéžæãããŠãŒã¶ãŒã«å¿ããŠãããããã«åªå
é äœãèšå®ã§ããŸãã
[ããã€ã¹]-> [GlobalProtectã¯ã©ã€ã¢ã³ã]ã»ã¯ã·ã§ã³ã§ã Palo Alto NetworksãµãŒããŒããVPNã¯ã©ã€ã¢ã³ãé
åž
ããã±ãŒãžãããŠã³ããŒãããŠã¢ã¯ãã£ãåããå¿
èŠããããŸãã æ¥ç¶ããã«ã¯ããŠãŒã¶ãŒã¯ããŒã¿ã«ã®WebããŒãžã«ç§»åããŠã
GlobalProtectã¯ã©ã€ã¢ã³ããããŠã³ããŒãããããã«æ±ããããŸãã ããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããåŸãè³æ Œæ
å ±ãå
¥åããSSL VPNçµç±ã§äŒæ¥ãããã¯ãŒã¯ã«æ¥ç¶ã§ããŸãã
ãããã«
Palo Alto Networksã®ã»ããã¢ããã®ãã®éšåã¯çµäºããŸããã æ
å ±ãæçšã§ãããèªè
ãããã¢ã«ããããã¯ãŒã¯ã¹ã§äœ¿çšãããŠãããã¯ãããžãŒã®ã¢ã€ãã¢ãåŸãããšãé¡ã£ãŠããŸãã ã«ã¹ã¿ãã€ãºã«é¢ãã質åãä»åŸã®èšäºã®ãããã¯ã«é¢ããææ¡ãããå Žåã¯ãã³ã¡ã³ãã«æžããŠãã ãããåãã§ãçãããŸãã