ãã®èšäºã¯ãããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã管çããæ¹æ³ããšããã¿ã€ãã«ã®äžé£ã®èšäºã®5çªç®ã§ãã ã·ãªãŒãºã®ãã¹ãŠã®èšäºã®å
容ãšãªã³ã¯ã¯ããã§èŠã€ããããšãã§ããŸã ã
ãã®ããŒãã¯ããã£ã³ãã¹ïŒãªãã£ã¹ïŒã»ãã¥ãªãã£èšèšãšãªã¢ãŒãã¢ã¯ã»ã¹VPNã»ã°ã¡ã³ãã®ç£æ»ã«å°å¿µããŸãã

ãªãã£ã¹ãããã¯ãŒã¯ã®èšèšã¯åçŽã«èŠãããããããŸããã
å®éãL2 / L3ã¹ã€ããã䜿çšããããããæ¥ç¶ããŸãã æ¬¡ã«ããã©ã³ãããã©ã«ãã²ãŒããŠã§ã€ã®åºæ¬æ§æãã·ã³ãã«ã«ãŒãã£ã³ã°ã®åŒãäžããWiFiã³ã³ãããŒã©ãŒãã¢ã¯ã»ã¹ãã€ã³ãã®æ¥ç¶ãASAã®ã€ã³ã¹ããŒã«ãšãªã¢ãŒãã¢ã¯ã»ã¹çšã®æ§æãè¡ãããã¹ãŠãæ©èœããããšãå¬ããæããŸãã ååãšããŠ
ããã®ã·ãªãŒãºã®ä»¥åã®
èšäºã®ããããã§ãã§ã«æžããããã«ããã¬ãã®ã³ãŒã¹ã®2åŠæãèããïŒãããŠåŠãã ïŒã»ãŒãã¹ãŠã®åŠçã¯ããäœããã®åœ¢ã§æ©èœããããªãã£ã¹ãããã¯ãŒã¯ãèšèšããã³æ§æã§ããŸãã
ããããåŠã¹ã°åŠã¶ã»ã©ããã®ã¿ã¹ã¯ã¯åæ©çã«èŠããªããªããŸãã å人çã«ã¯ããªãã£ã¹ãããã¯ãŒã¯èšèšã®ããŒãã§ãããã®ãããã¯ã¯ãŸã£ããåçŽã§ã¯ãªãããã§ãããã®èšäºã§ã¯ããã®çç±ã説æããŸãã
èŠããã«ãããªãå€ãã®èŠå ãèæ
®ããå¿
èŠããããŸãã å€ãã®å Žåããããã®èŠå ã¯äºãã«å¯Ÿç«ããŠãããåççãªåŠ¥åãæš¡çŽ¢ããå¿
èŠããããŸãã
ãã®äžç¢ºå®æ§ãäž»ãªå°é£ã§ãã ãããã£ãŠãã»ãã¥ãªãã£ã«ã€ããŠèšãã°ãã»ãã¥ãªãã£ãåŸæ¥å¡ã®å©äŸ¿æ§ããœãªã¥ãŒã·ã§ã³ã®äŸ¡æ Œãšãã3ã€ã®é ç¹ãæã€äžè§åœ¢ããããŸãã
ãããŠã3ã€ã®éã®åŠ¥åç¹ãèŠã€ããå¿
èŠããããŸãã
建ç¯
ããã2ã€ã®ã»ã°ã¡ã³ãã®ã¢ãŒããã¯ãã£ã®äŸãšããŠã以åã®èšäºãšåæ§ã«ã
Cisco SAFEã¢ãã«ãæšå¥šããŸã
ãEnterpriseCampus ã
Enterprise Internet Edgeã§ãã
ãããã¯ããæä»£é
ãã®ææžã§ãã ååãšããŠã¹ããŒã ãšã¢ãããŒãã¯å€æŽãããŠããªãã®ã§ãããã«ããããæã¡èŸŒã¿ãŸãããåæã«
æ°ããããã¥ã¡ã³ãããããã¬ãŒã³ããŒã·ã§ã³ã奜ãã§ãã
ã·ã¹ã³ã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããããã«ä¿ãããšãªãããã®èšèšãæ
éã«æ€èšããããšã¯äŸç¶ãšããŠæçšã ãšæããŸãã
ãã®èšäºã¯ããã€ãã®ããã«ãäœããã®ãµããããããšãªãããã®æ
å ±ãžã®è¿œå ã§ãã
èšäºã®æåŸã§ãããã§æŠèª¬ããæŠå¿µã®èгç¹ããããªãã£ã¹åãã®Cisco SAFEã®èšèšãåæããŸãã
äžè¬åå
ãã¡ããããªãã£ã¹ãããã¯ãŒã¯ã®èšèšã¯ããèšèšå質è©äŸ¡åºæºãã®ç« ã§èª¬æã
ããŠããäžè¬çãªèŠä»¶ãæºããå¿
èŠããããŸãã ãã®èšäºã§èª¬æããäŸ¡æ Œãšã»ãã¥ãªãã£ã«å ããŠãèšèšæïŒãŸãã¯å€æŽæïŒã«èæ
®ããªããã°ãªããªãåºæºã3ã€ãããŸãã
- æ¡åŒµæ§
- 管çã®å©äŸ¿æ§ïŒç®¡çæ§ïŒ
- å©çšå¯èœ
ããŒã¿ã»ã³ã¿ãŒã§è°è«ããããã®ã®å€ãã¯ããªãã£ã¹ã«ãåœãŠã¯ãŸããŸãã
ããããããã«ããããããããªãã£ã¹ã»ã°ã¡ã³ãã«ã¯ç¬èªã®ç¹ç°æ§ããããããã¯ã»ãã¥ãªãã£ã®èгç¹ããéèŠã§ãã ãã®ç¹ç°æ§ã®æ¬è³ªã¯ããã®ã»ã°ã¡ã³ããäŒç€Ÿã®åŸæ¥å¡ïŒããã³ããŒãããŒãšã²ã¹ãïŒã«ãããã¯ãŒã¯ãµãŒãã¹ãæäŸããããã«äœæããããã®çµæãåé¡ã®æé«ã¬ãã«ã®èæ
®äºé
ã«2ã€ã®ã¿ã¹ã¯ãããããšã§ãã
- åŸæ¥å¡ïŒã²ã¹ããããŒãããŒïŒããã³åœŒãã䜿çšãããœãããŠã§ã¢ããçããå¯èœæ§ã®ããæªæã®ããæŽ»åããäŒç€Ÿã®ãªãœãŒã¹ãä¿è·ããŸãã ããã«ã¯ãäžæ£ãªãããã¯ãŒã¯æ¥ç¶ã«å¯Ÿããä¿è·ãå«ãŸããŸãã
- ã·ã¹ãã ãšãŠãŒã¶ãŒããŒã¿ãä¿è·ãã
ãããŠãããã¯åé¡ã®çåŽã«ãããŸããïŒããããäžè§åœ¢ã®1ã€ã®é ç¹ïŒã äžæ¹ããŠãŒã¶ãŒã®å©äŸ¿æ§ãšé©çšããããœãªã¥ãŒã·ã§ã³ã®äŸ¡æ Œã§ãã
ãŸãããŠãŒã¶ãŒãææ°ã®ãªãã£ã¹ãããã¯ãŒã¯ã«æåŸ
ãããã®ãèŠãŠã¿ãŸãããã
ã¢ã¡ããã£
ç§ã®æèŠã§ã¯ããªãã£ã¹ãŠãŒã¶ãŒã«ãšã£ãŠããããã¯ãŒã¯ã®å©äŸ¿æ§ãã¯æ¬¡ã®ããã«ãªããŸãã
- æ©åæ§
- 䜿ãæ
£ãããã¹ãŠã®ããã€ã¹ãšãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšããæ©èœ
- å¿
èŠãªãã¹ãŠã®äŒæ¥ãªãœãŒã¹ãžã®ç°¡åãªã¢ã¯ã»ã¹
- ããŸããŸãªã¯ã©ãŠããµãŒãã¹ãå«ãã€ã³ã¿ãŒããããªãœãŒã¹ã®å¯çšæ§
- ãé«éäœæ¥ããããã¯ãŒã¯
ããã¯ãã¹ãŠãåŸæ¥å¡ãšã²ã¹ãïŒãŸãã¯ããŒãããŒïŒã®äž¡æ¹ã«é©çšãããŸããããã¯ãããŸããŸãªãŠãŒã¶ãŒã°ã«ãŒãã®ã¢ã¯ã»ã¹ãåºå¥ããããã®æ¿èªã«åºã¥ãäŒç€Ÿã®ãšã³ãžãã¢ã®ã¿ã¹ã¯ã§ãã
ãããã®ååŽé¢ã詳ããèŠãŠã¿ãŸãããã
æ©åæ§
ããã¯ãäžçäžã®ã©ãããã§ãïŒãã¡ãããã€ã³ã¿ãŒããããå©çšå¯èœã§ããã°ïŒäŒç€Ÿã®ãã¹ãŠã®å¿
èŠãªãªãœãŒã¹ã䜿çšããŠäœ¿çšããæ©äŒã«ã€ããŠã§ãã
ããã¯å®å
šã«ãªãã£ã¹ã«é©çšãããŸãã ããã¯ããªãã£ã¹ã®ã©ãããã§ãä»äºãç¶ããæ©äŒãããå Žåã«äŸ¿å©ã§ããããšãã°ãã¡ãŒã«ã®åä¿¡ãäŒæ¥ã®ã¡ãã»ã³ãžã£ãŒã§ã®ã³ãã¥ãã±ãŒã·ã§ã³ããããªã³ãŒã«ãžã®å¿å¯Ÿãªã©ã§ããããã«ãããäžæ¹ã§ããã©ã€ãããéããŠããã€ãã®åé¡ã解決ã§ããŸããã³ãã¥ãã±ãŒã·ã§ã³ïŒããšãã°ãéäŒã«åå ããããïŒãããã³ãã®ä»-åžžã«ãªã³ã©ã€ã³ã§ãåžžã«ææ°ã®ç¶æ
ã«ä¿ã¡ãåªå
床ã®é«ãç·æ¥ã¿ã¹ã¯ããã°ãã解決ããŸãã ããã¯éåžžã«äŸ¿å©ã§ãããå®éãéä¿¡ã®å質ãåäžãããŸãã
ããã¯ãWiFiãããã¯ãŒã¯ã®æ£ããèšèšã«ãã£ãŠå®çŸãããŸãã
çºèš
ããã¯éåžžãçåãæèµ·ããŸããWiFiã®ã¿ã䜿çšããã ãã§ååã§ããïŒ ããã¯ããªãã£ã¹ã§ã€ãŒãµãããããŒãã®äœ¿çšãæåŠã§ãããšããããšã§ããïŒ éåžžã®ã€ãŒãµãããããŒãã«æ¥ç¶ããã®ãè³¢æãªãµãŒããŒã«ã€ããŠã§ã¯ãªãããŠãŒã¶ãŒã ãã«ã€ããŠè©±ããŠããå Žåãäžè¬çã«çãã¯æ¬¡ã®ãšããã§ããã¯ããWiFiã®ã¿ã«å¶éã§ããŸãã ãããã埮åŠãªéãããããŸãã
å¥ã®ã¢ãããŒããå¿
èŠãšããéèŠãªãŠãŒã¶ãŒã°ã«ãŒãããããŸãã ãã¡ããããããã¯ç®¡çè
ã§ãã ååãšããŠãWiFiæ¥ç¶ã¯éåžžã®ã€ãŒãµãããããŒããããä¿¡é Œæ§ãäœãïŒãã©ãã£ãã¯æå€±ã®ç¹ã§ïŒãé床ãé
ããªããŸãã ããã¯ç®¡çè
ã«ãšã£ãŠéèŠã§ãã ããã«ãããšãã°ããããã¯ãŒã¯ç®¡çè
ã¯ãåºæ¬çã«åž¯å倿¥ç¶çšã«ç¬èªã®å°çšã€ãŒãµããããããã¯ãŒã¯ãæã€ããšãã§ããŸãã
ããªãã®äŒç€Ÿã«ã¯ããããã®èŠå ãéèŠãªä»ã®ã°ã«ãŒã/éšéããããããããŸããã
å¥ã®éèŠãªãã€ã³ãããããŸã-é»è©±ã ããããäœããã®çç±ã§ãã¯ã€ã€ã¬ã¹VoIPã䜿çšãããéåžžã®ã€ãŒãµãããæ¥ç¶ã§IPé»è©±ã䜿çšãããå ŽåããããŸãã
äžè¬ã«ãç§ãåããŠããäŒæ¥ã§ã¯ãéåžžãWiFiæ¥ç¶ãšã€ãŒãµãããããŒãã®äž¡æ¹ãååšããå¯èœæ§ããããŸããã
ã¢ããªãã£ããªãã£ã¹ã ãã«éãããŠããªãããšãé¡ã£ãŠããŸãã
èªå®
ïŒãŸãã¯ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããä»ã®å ŽæïŒããäœæ¥ã§ããããã«ãVPNæ¥ç¶ã䜿çšãããŸãã åæã«ãåŸæ¥å¡ãåšå®
å€åãšé éå€åã®éããæããªãããšãæãŸãããããã¯ãåãã¢ã¯ã»ã¹ã®ååšãæå³ããŸãã ãããæŽçããæ¹æ³ã«ã€ããŠã¯ããçµ±åãããéäžèªèšŒããã³æ¿èªã·ã¹ãã ãã®ç« ã§å°ã説æããŸãã
çºèš
ã»ãšãã©ã®å Žåãããªãããªãã£ã¹ã«ãããªã¢ãŒãã¯ãŒã¯ãšåãå質ã®ãµãŒãã¹ãå®å
šã«æäŸããããšã¯ã§ããŸããã Cisco ASA 5520ãVPNã²ãŒããŠã§ã€ãšããŠäœ¿çšããŠãããšä»®å®ãããšã ããŒã¿ã·ãŒãã«ãããšããã®ããã€ã¹ã¯225 Mbpsã®VPNãã©ãã£ãã¯ã®ã¿ãããã€ãžã§ã¹ããã§ããŸãã ããã¯ãã¡ããã垯åå¹
ã®ç¹ã§ã¯ãVPNæ¥ç¶ã¯ãªãã£ã¹ã§åãããšãšã¯éåžžã«ç°ãªããŸãã ãŸããäœããã®çç±ã§ããããã¯ãŒã¯ãµãŒãã¹ã®é
å»¶ãæå€±ããžãã¿ãŒïŒããšãã°ããªãã£ã¹ã®IPãã¬ãã©ããŒã䜿çšãããïŒãéèŠãªå Žåããªãã£ã¹ã«ãããšããšåãå質ãåŸãããšãã§ããŸããã ãããã£ãŠãã¢ããªãã£ã«ã€ããŠè©±ããšãã¯ãèããããå¶éã«çæããå¿
èŠããããŸãã
ãã¹ãŠã®äŒæ¥ãªãœãŒã¹ãžã®ç°¡åãªã¢ã¯ã»ã¹
ãã®ã¿ã¹ã¯ã¯ãä»ã®æè¡éšéãšé£æºããŠå¯ŸåŠããå¿
èŠããããŸãã
çæ³çãªç¶æ³ã¯ããŠãŒã¶ãŒãäžåºŠã ãèªèšŒããå¿
èŠãããããã®åŸãå¿
èŠãªãã¹ãŠã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããå Žåã§ãã
ã»ãã¥ãªãã£ãæãªãããšãªãç°¡åã«ã¢ã¯ã»ã¹ã§ããããã«ãããšãäœæ¥å¹çã倧å¹
ã«åäžããååã®ã¹ãã¬ã¹ã¬ãã«ã軜æžãããŸãã
åè1
ã¢ã¯ã»ã¹ã®ããããã¯ããã¹ã¯ãŒããå
¥åããªããã°ãªããªãåæ°ã ãã§ã¯ãããŸããã ããšãã°ãã»ãã¥ãªãã£ããªã·ãŒã«åŸã£ãŠããªãã£ã¹ããããŒã¿ã»ã³ã¿ãŒã«æ¥ç¶ããå Žåãæåã«VPNã²ãŒããŠã§ã€ã«æ¥ç¶ããå¿
èŠããããåæã«ãªãã£ã¹ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã倱ãå¿
èŠãããå Žåããããéåžžã«äžäŸ¿ã§ãã
åè2
éåžžãå°çšã®AAAãµãŒããŒãçšæãããŠãããµãŒãã¹ïŒãããã¯ãŒã¯æ©åšãžã®ã¢ã¯ã»ã¹ãªã©ïŒããããŸãããã®å Žåãéåžžã¯æ°åèªèšŒããå¿
èŠããããŸãã
ã€ã³ã¿ãŒããããªãœãŒã¹ã®å¯çšæ§
ã€ã³ã¿ãŒãããã¯ãšã³ã¿ãŒãã€ã¡ã³ãã ãã§ãªããä»äºã«éåžžã«åœ¹ç«ã€ãµãŒãã¹ã®ã»ããã§ããããŸãã çŽç²ã«å¿ççãªèŠå ããããŸãã ã€ã³ã¿ãŒããããä»ããŠä»ã®äººãšæ¥ç¶ãããå€ãã®ä»®æ³ã¹ã¬ãããä»ããŠçŸä»£äººã¯ãç§ã®æèŠã§ã¯ã圌ãä»äºäžã§ãã£ãŠããã®æ¥ç¶ãæãç¶ããã°äœãæªãããšã¯ãããŸããã
æéãæµªè²»ãããšãã芳ç¹ããã¯ãããšãã°åŸæ¥å¡ãã¹ã«ã€ããå®è¡ããŠããŠãåé¡ãããŸãããå¿
èŠã«å¿ããŠãæãã人ãš5åé話ãããŸãã
ããã¯ãã€ã³ã¿ãŒããããåžžã«å©çšå¯èœã§ããããšãæå³ããŸããïŒããã¯ãåŸæ¥å¡ããã¹ãŠã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ããªãŒãã³ã§ããããããå¶åŸ¡ã§ããªãããšãæå³ããŸããïŒ
ãããããã¡ãããããŸããã ã€ã³ã¿ãŒãããã®éæŸæ§ã®ã¬ãã«ã¯ãå®å
šãªééããå®å
šãªéæŸæ§ãŸã§ãäŒæ¥ã«ãã£ãŠç°ãªãå ŽåããããŸãã ãã©ãã£ãã¯ãå¶åŸ¡ããæ¹æ³ã«ã€ããŠã¯ãã»ãã¥ãªãã£æ©èœã®ã»ã¯ã·ã§ã³ã§åŸã»ã©èª¬æããŸãã
䜿ãæ
£ãããã¹ãŠã®ããã€ã¹ã䜿çšããæ©èœ
ããšãã°ãè·å Žã§ã®éåžžã®ã³ãã¥ãã±ãŒã·ã§ã³ææ®µããã¹ãŠäœ¿ãç¶ããæ©äŒãããå Žåã«äŸ¿å©ã§ãã ãããæè¡çã«å®è£
ããã®ã«å°é£ã¯ãããŸããã ãããè¡ãã«ã¯ãWiFiãšã²ã¹ãvilanãå¿
èŠã§ãã
æ
£ããŠãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšã§ããå Žåã«ãé©ããŠããŸãã ããããç§ã®èгå¯ã§ã¯ãéåžžãããã¯ãããŒãžã£ãŒã管çè
ãããã³éçºè
ã«ã®ã¿èš±å¯ãããŠããŸãã
äŸ
ãã¡ããããã§ãã¯ãã€ã³ãã§æºåž¯é»è©±ãšã¬ãžã§ãããåé€ããããšãªããçŠæ¢ã®ãã¹ããã©ãããªã¢ãŒãã¢ã¯ã»ã¹ãçŠæ¢ããã¢ãã€ã«ããã€ã¹ããã®æ¥ç¶ãçŠæ¢ãããã¹ãŠã®éçã€ãŒãµãããæ¥ç¶ãå¶éããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãå¶éããããšãã§ããŸã...ã»ãã¥ãªãã£èŠä»¶ããããŠå Žåã«ãã£ãŠã¯ãããã¯æ£åœåããããããããŸãããã...åäžã®çµç¹ã®é²æ©ãæ¢ãã詊ã¿ã®ããã«èŠããããšã«åæããŸãã ãã¡ãããææ°ã®ãã¯ãããžãŒãæäŸããæ©äŒãšé©åãªã¬ãã«ã®ã»ãã¥ãªãã£ãçµã¿åãããããšæããŸãã
ãé«éäœæ¥ããããã¯ãŒã¯
ããŒã¿è»¢éé床ã¯ãæè¡çã«å€ãã®èŠçŽ ã§æ§æãããŠããŸãã éåžžãæ¥ç¶ããŒãã®éåºŠã¯æãéèŠã§ã¯ãããŸããã åžžã«ã¢ããªã±ãŒã·ã§ã³ã®é
ãåäœããããã¯ãŒã¯ã®åé¡ã«é¢é£ããŠããããã§ã¯ãããŸããããä»ã¯ãããã¯ãŒã¯ã®éšåã«ã®ã¿é¢å¿ããããŸãã ããŒã«ã«ãããã¯ãŒã¯ã®ãé床äœäžãã®æãäžè¬çãªåé¡ã¯ããã±ããæå€±ã«é¢é£ããŠããŸãã ããã¯éåžžãããã«ããã¯å¹æãŸãã¯L1ïŒOSIïŒã®åé¡ã§çºçããŸãã ããŸãäžè¬çã§ã¯ãããŸããããäžéšã®èšèšã§ã¯ïŒããšãã°ããã¡ã€ã¢ãŠã©ãŒã«ããµããããã®ããã©ã«ãã²ãŒããŠã§ã€ãšããŠæ©èœããããããã¹ãŠã®ãã©ãã£ãã¯ãééããå ŽåïŒãããŒããŠã§ã¢ã®ããã©ãŒãã³ã¹ãäœäžããå ŽåããããŸãã
ãããã£ãŠãæ©åšãšã¢ãŒããã¯ãã£ãéžæãããšãã¯ããšã³ãããŒãããã©ã³ã¯ã®é床ãããã³æ©åšã®ããã©ãŒãã³ã¹ãçžé¢ãããå¿
èŠããããŸãã
äŸ
ã¢ã¯ã»ã¹ã¬ãã«ã¹ã€ãããšããŠ1ã®ã¬ãããããŒãã®ã¹ã€ããã䜿çšãããšããŸãã ãããã¯ãEtherchannel 2 x 10ã®ã¬ãããã§çžäºæ¥ç¶ãããŸãã ããã©ã«ãã²ãŒããŠã§ã€ãšããŠãã®ã¬ãããããŒããåãããã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããEtherchannelã«çµ±åããã2ã€ã®ã®ã¬ãããããŒãã䜿çšãããªãã£ã¹ã®L2ãããã¯ãŒã¯ã«æ¥ç¶ããŸãã
ãã®ã¢ãŒããã¯ãã£ã¯ãæ©èœçã«éåžžã«äŸ¿å©ã§ãããªããªãã ãã¹ãŠã®ãã©ãã£ãã¯ã¯ãã¡ã€ã¢ãŠã©ãŒã«ãééããã¢ã¯ã»ã¹ããªã·ãŒãå¿«é©ã«ç®¡çããè€éãªã¢ã«ãŽãªãºã ãé©çšããŠãã©ãã£ãã¯ãå¶åŸ¡ããæ»æã®å¯èœæ§ãé²ãããšãã§ããŸãïŒä»¥äžãåç
§ïŒãã垯åå¹
ãšããã©ãŒãã³ã¹ã®èгç¹ããããã®èšèšã«ã¯æœåšçãªåé¡ããããŸã ãããã£ãŠãããšãã°ãããŒã¿ãããŠã³ããŒããã2ã€ã®ãã¹ãïŒããŒãé床ã1ã®ã¬ãããïŒã¯ã2ã®ã¬ãããæ¥ç¶ããã¡ã€ã¢ãŠã©ãŒã«ã«å®å
šã«ããŒãã§ããããããªãã£ã¹ã»ã°ã¡ã³ãå
šäœã®ãµãŒãã¹ã®äœäžã«ã€ãªãããŸãã
äžè§åœ¢ã®1ã€ã®é ç¹ãèŠãŸãããæ¬¡ã«ãã»ãã¥ãªãã£ãæäŸããæ¹æ³ãèŠãŠã¿ãŸãããã
ææž
ãããã£ãŠããã¡ãããéåžžãç§ãã¡ã®æ¬²æ±ïŒãŸãã¯ãããããç§ãã¡ã®ãªãŒããŒã·ããã®æ¬²æ±ïŒã¯ãäžå¯èœãéæããããšãã€ãŸããæå€§éã®å©äŸ¿æ§ãšæå€§éã®ã»ãã¥ãªãã£ãšæå°éã®äŸ¡æ ŒãæäŸããããšã§ãã
ä¿è·ãæäŸããå¿
èŠãããæ¹æ³ãèŠãŠã¿ãŸãããã
ãªãã£ã¹ã§ã¯ã次ã®ããšãéžã³ãŸãã
- ãŒããã©ã¹ãèšèšã¢ãããŒã
- é«ã¬ãã«ã®ä¿è·
- ãããã¯ãŒã¯ã®å¯èŠæ§
- åäžã®éäžèªèšŒããã³èªå¯ã·ã¹ãã
- ãã¹ããã§ãã¯
次ã«ããããã®ååŽé¢ã«ã€ããŠè©³ãã説æããŸãã
ãŒããã©ã¹ã
ITã®äžçã¯æ¥éã«å€åããŠããŸãã æåéããéå»10幎éãæ°ããæè¡ãšè£œåã®åºçŸã«ãããã»ãã¥ãªãã£ã®æŠå¿µã倧å¹
ã«æ¹èšãããŸããã 10幎åãã»ãã¥ãªãã£ã®èгç¹ããããããã¯ãŒã¯ãä¿¡é ŒãŸãŒã³ãdmzãŸãŒã³ãuntrustãŸãŒã³ã«åå²ãããå¢çé²åŸ¡ããšåŒã°ãããã®ã䜿çšããŸãããuntrust-> dmzããã³dmz-> trustã ãŸããä¿è·ã¯éåžžãL3 / L4ïŒOSIïŒããããŒïŒIPãTCP / UDPããŒããTCPãã©ã°ïŒã«åºã¥ãã¢ã¯ã»ã¹ãªã¹ãã«éå®ãããŠããŸããã L7ãå«ããããé«ãã¬ãã«ã«é¢é£ãããã®ã¯ãã¹ãŠããšã³ããã¹ãã«ã€ã³ã¹ããŒã«ãããOSããã³ä¿è·è£œåã«ä»»ãããŠããŸããã
çŸåšãç¶æ³ã¯åçã«å€åããŠããŸãã
ãŒããã©ã¹ãã®çŸä»£ã®æŠå¿µã¯ãå
éšãã€ãŸãå¢çå
ã®ã·ã¹ãã ã
ä¿¡é Œããããšã¯ãã¯ãäžå¯èœã§ãããå¢çã®æŠå¿µãã®ãã®ãææ§ã«ãªã£ããšããäºå®ã«åºã¥ããŠããŸãã
ã€ã³ã¿ãŒãããæ¥ç¶ã«å ããŠãæã
ãæã£ãŠããŸã
- ãªã¢ãŒãã¢ã¯ã»ã¹VPNãŠãŒã¶ãŒ
- ããŸããŸãªããŒãœãã«ã¬ãžã§ããã«ããããªãã£ã¹ã®WiFiãä»ããŠã©ããããããæ¥ç¶ãããŸãã
- ä»ã®ïŒæ¯åºïŒãªãã£ã¹
- ã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ãšã®çµ±å
ãŒããã©ã¹ãã®ã¢ãããŒãã¯å®éã«ã¯ã©ã®ããã«èŠããŸããïŒ
çæ³çã«ã¯ãå¿
èŠãªãã©ãã£ãã¯ã®ã¿ãèš±å¯ããçæ³ã«ã€ããŠè©±ããŠããå Žåã¯ãL3 / L4ã¬ãã«ã ãã§ãªããã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§ãå¶åŸ¡ããå¿
èŠããããŸãã
ããšãã°ããã¹ãŠã®ãã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ãééãããæ©äŒãããã°ãçæ³ã«è¿ã¥ããããšãã§ããŸãã ãã ãããã®ã¢ãããŒãã¯ãããã¯ãŒã¯ã®ç·åž¯åå¹
ã倧å¹
ã«åæžã§ããŸãããŸããã¢ããªã±ãŒã·ã§ã³ã«ãããã£ã«ã¿ãªã³ã°ãåžžã«é©åã«æ©èœãããšã¯éããŸããã
ïŒæšæºACLã䜿çšããŠïŒã«ãŒã¿ãŒãŸãã¯L3ã¹ã€ããäžã®ãã©ãã£ãã¯ãç£èŠããå Žåãä»ã®åé¡ãçºçããŸãã
- ããã¯ãL3 / L4ãã£ã«ã¿ãªã³ã°ã®ã¿ã§ãã æ»æè
ãã¢ããªã±ãŒã·ã§ã³ïŒhttpã§ã¯ãªãïŒã«èš±å¯ãããããŒãïŒTCP 80ãªã©ïŒã䜿çšããããšã劚ãããã®ã¯äœããããŸãã
- è€éãªACL管çïŒACLã®åæãå°é£ïŒ
- ããã¯ã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãããŸãããã€ãŸããæç€ºçã«éãã©ãã£ãã¯ãèš±å¯ããå¿
èŠããããŸãã
- ã¹ã€ããã®å ŽåãéåžžãTCAMã®ãµã€ãºã«ãã£ãŠéåžžã«å³ããå¶éãããŸãããå¿
èŠãªãã®ã ããèš±å¯ãããã¢ãããŒãã䜿çšãããšãããã«åé¡ã«ãªããŸãã
çºèš
éãã©ãã£ãã¯ãšããã°ãæ¬¡ã®æ©äŒãããããšãèŠããŠããå¿
èŠããããŸãïŒCiscoïŒ
ä»»æã®ç¢ºç«ãããtcpãèš±å¯ããŸã
ãã ãããã®è¡ã¯2è¡ã«çžåœããããšãçè§£ããå¿
èŠããããŸãã
tcp any any ackãèš±å¯ããŸã
tcp any any rstãèš±å¯ããŸã
ã€ãŸããSYNãã©ã°ãæã€å
ã®TCPã»ã°ã¡ã³ãããªãã£ãå ŽåïŒã€ãŸããTCPã»ãã·ã§ã³ã確ç«ãããªãã£ãå Žåã§ãïŒããã®ACLã¯ACKãã©ã°ãæã€ãã±ãããã¹ãããããæ»æè
ã¯ããã䜿çšããŠããŒã¿ãéä¿¡ã§ããŸãã
ã€ãŸãããã®è¡ã¯ãã«ãŒã¿ãŒãŸãã¯L3ã¹ã€ãããã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ã«æ±ºããŠå€ããŸããã
é«ã¬ãã«ã®ä¿è·
ããŒã¿ã»ã³ã¿ãŒã«ç¹åããã»ã¯ã·ã§ã³ã®
èšäºã§ã¯ã次ã®ä¿è·æ¹æ³ãæ€èšããŸããã
- ã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ïŒããã©ã«ãïŒ
- ddos / dosä¿è·
- ã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«
- è
åšã®é²æ¢ïŒãŠã€ã«ã¹å¯Ÿçãã¹ãã€ãŠã§ã¢å¯Ÿçãè匱æ§ïŒ
- URLãã£ã«ã¿ãªã³ã°
- ããŒã¿ãã£ã«ã¿ãªã³ã°ïŒã³ã³ãã³ããã£ã«ã¿ãªã³ã°ïŒ
- ãã¡ã€ã«ã®ãããã¯ïŒãã¡ã€ã«ã®çš®é¡ã®ãããã¯ïŒ
ãªãã£ã¹ã®å Žåãç¶æ³ã¯äŒŒãŠããŸãããåªå
é äœã¯ãããã«ç°ãªããŸãã éåžžãOfficeã®ã¢ã¯ã»ã·ããªãã£ïŒå¯çšæ§ïŒã¯ããŒã¿ã»ã³ã¿ãŒã®å Žåã»ã©éèŠã§ã¯ãããŸãããããå
éšãã®æªæã®ãããã©ãã£ãã¯ã®å¯èœæ§ã¯æ¡éãã«é«ããªããŸãã
ãããã£ãŠããã®ã»ã°ã¡ã³ãã®æ¬¡ã®ä¿è·æ¹æ³ãéèŠã«ãªããŸãã
- ã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«
- è
åšã®é²æ¢ïŒãŠã€ã«ã¹å¯Ÿçãã¹ãã€ãŠã§ã¢å¯Ÿçãè匱æ§ïŒ
- URLãã£ã«ã¿ãªã³ã°
- ããŒã¿ãã£ã«ã¿ãªã³ã°ïŒã³ã³ãã³ããã£ã«ã¿ãªã³ã°ïŒ
- ãã¡ã€ã«ã®ãããã¯ïŒãã¡ã€ã«ã®çš®é¡ã®ãããã¯ïŒ
ãããã®ãã¹ãŠã®ä¿è·æ¹æ³ã¯ãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ãé€ããäŒçµ±çã«è§£æ±ºãããŠããããšã³ããã¹ãã§ïŒããšãã°ããŠã€ã«ã¹å¯Ÿçããã°ã©ã ãã€ã³ã¹ããŒã«ããããšã«ãã£ãŠïŒãããã·ã䜿çšããŠè§£æ±ºããç¶ããŠããŸãããææ°ã®NGFWã¯ãããã®ãµãŒãã¹ãæäŸããŸãã
ã»ãã¥ãªãã£æ©åšãã³ããŒã¯å
æ¬çãªä¿è·ã®äœæã«åªããŠãããããŒã«ã«ããã¯ã¹ã§ã®ä¿è·ãšãšãã«ããã¹ãçšã®ããŸããŸãªã¯ã©ãŠããã¯ãããžãŒãšã¯ã©ã€ã¢ã³ããœãããŠã§ã¢ïŒãšã³ããã€ã³ãä¿è·/ EPPïŒãæäŸãããŠããŸãã ããšãã°
ã2018幎ã®Gartner Magic Quadrantã§ã¯ã Palo AltoãšCiscoã«ã¯ç¬èªã®EPPïŒPAïŒãã©ãããCiscoïŒAMPïŒããããŸããããªãŒããŒããã¯ã»ã©é ãããšãããããŸãã
ãã¡ããããããã®ä¿è·ãïŒéåžžã¯ã©ã€ã»ã³ã¹ã®è³Œå
¥ãéããŠïŒãã¡ã€ã¢ãŠã©ãŒã«ã«å«ããããšã¯å¿
é ã§ã¯ãããŸããïŒåŸæ¥ã®æ¹æ³ã䜿çšã§ããŸãïŒããããã€ãã®å©ç¹ããããŸãã
- ãã®å Žåãä¿è·æ¹æ³ã®åäžã®é©çšãã€ã³ãã衚瀺ãããå¯èŠæ§ãåäžããŸãïŒæ¬¡ã®ãããã¯ãåç
§ïŒã
- ãããã¯ãŒã¯ã«ä¿è·ãããŠããªãããã€ã¹ãããå Žåããã¡ã€ã¢ãŠã©ãŒã«ä¿è·ã®ãåãã®å¯Ÿè±¡ãšãªããŸã
- ãã¡ã€ã¢ãŠã©ãŒã«ã®ä¿è·ãšãšã³ããã¹ãã®ä¿è·ã䜵çšãããšãæªæã®ãããã©ãã£ãã¯ãæ€åºããå¯èœæ§ãé«ãŸããŸãã ããšãã°ãããŒã«ã«ãã¹ãããã³ãã¡ã€ã¢ãŠã©ãŒã«ã§è
åšé²æ¢ã䜿çšãããšãæ€åºã®å¯èœæ§ãé«ããªããŸãïŒãã¡ããããããã®ãœãªã¥ãŒã·ã§ã³ãç°ãªããœãããŠã§ã¢è£œåã«åºã¥ããŠããå ŽåïŒ
çºèš
ããšãã°ããã¡ã€ã¢ãŠã©ãŒã«ãšãšã³ããã¹ãã®äž¡æ¹ã§KasperskyããŠã€ã«ã¹å¯ŸçãšããŠäœ¿çšããå Žåãããã¯ãã¡ããããããã¯ãŒã¯ã§ã®ãŠã€ã«ã¹æ»æã鲿¢ããå¯èœæ§ã倧å¹
ã«é«ããããšã¯ãããŸããã
ãããã¯ãŒã¯ã®å¯èŠæ§
åºæ¬çãªèãæ¹ã¯ç°¡åã§ãããªã¢ã«ã¿ã€ã ããŒã¿ãšå±¥æŽããŒã¿ã®äž¡æ¹ã§ããããã¯ãŒã¯ã§äœãèµ·ãã£ãŠãããããèŠããããšãã§ããŸãã
ãã®ãããžã§ã³ãã2ã€ã®ã°ã«ãŒãã«åããŸãã
ã°ã«ãŒã1ïŒç£èŠã·ã¹ãã ãéåžžæäŸãããã®ã
- æ©åšã®ããŒãã£ã³ã°
- ããŒãã£ã³ã°ãã£ã³ãã«
- ã¡ã¢ãªäœ¿çšé
- ãã£ã¹ã¯äœ¿çšé
- ã«ãŒãã£ã³ã°ããŒãã«ã倿Žãã
- ãªã³ã¯ç¶æ
- æ©åšïŒãŸãã¯ãã¹ãïŒã®å¯çšæ§
- ...
ã°ã«ãŒã2ïŒã»ãã¥ãªãã£é¢é£æ
å ±ã
- ããŸããŸãªçš®é¡ã®çµ±èšïŒã¢ããªã±ãŒã·ã§ã³ããšããã©ãã£ãã¯URLããšãããŠã³ããŒããããããŒã¿ã®çš®é¡ããŠãŒã¶ãŒããšã®ããŒã¿ãªã©ïŒ
- ã»ãã¥ãªãã£ããªã·ãŒã«ãã£ãŠãããã¯ããããã®ãšãã®çç±
- çŠæ¢ç³è«
- IP /ãããã³ã«/ããŒã/ãã©ã°/ãŸãŒã³ã«åºã¥ããŠçŠæ¢
- è
åšé²æ¢
- URLãã£ã«ã¿ãªã³ã°
- ããŒã¿ãã£ã«ã¿ãªã³ã°
- ãã¡ã€ã«ã®ãããã¯
- ...
- DOS / DDOSæ»æã«é¢ããçµ±èš
- 倱æããèªèšŒããã³èš±å¯ã®è©Šè¡
- äžèšã®ãã¹ãŠã®ã»ãã¥ãªãã£ããªã·ãŒéåã«é¢ããçµ±èš
- ...
ã»ãã¥ãªãã£ã«é¢ãããã®ç« ã§ã¯ãæ£ç¢ºã«ç¬¬2éšã«èå³ããããŸãã
äžéšã®ææ°ã®ãã¡ã€ã¢ãŠã©ãŒã«ïŒç§ã®Palo Altoã®å®è·µã«ããïŒã¯ãè¯å¥œãªã¬ãã«ã®å¯èŠæ§ãæäŸããŸãã ãã ãããã¡ãããé¢å¿ã®ãããã©ãã£ãã¯ã¯ãã®ãã¡ã€ã¢ãŠã©ãŒã«ãééããå¿
èŠãããïŒãã®å Žåããã©ãã£ãã¯ããããã¯ã§ããŸãïŒããŸãã¯ãã¡ã€ã¢ãŠã©ãŒã«ã«ãã©ãŒãªã³ã°ããïŒç£èŠãšåæã®ã¿ã«äœ¿çšïŒããããã®ãµãŒãã¹ããã¹ãŠæå¹ã«ããããã®ã©ã€ã»ã³ã¹ãå¿
èŠã§ãã
ãã¡ããã代æ¿ãã¹ããããŸãããããšãã°ãåŸæ¥ã®ãã¹ããããŸãã
- ã»ãã·ã§ã³ã«é¢ããçµ±èšã¯ãnetflowãä»ããŠåéã§ãããã®åŸãç¹å¥ãªãŠãŒãã£ãªãã£ã䜿çšããŠæ
å ±ãåæããããŒã¿ãèŠèŠåã§ããŸãã
- è
åšã®é²æ¢-ãšã³ããã¹ãäžã®ç¹å¥ãªããã°ã©ã ïŒãŠã€ã«ã¹å¯Ÿçãã¹ãã€ãŠã§ã¢å¯Ÿçããã¡ã€ã¢ãŠã©ãŒã«ïŒ
- URLãã£ã«ã¿ãªã³ã°ãããŒã¿ãã£ã«ã¿ãªã³ã°ããã¡ã€ã«ããããã³ã°-ãããã·äž
- ãŸãã snortã§ tcpdumpãè§£æããããšãã§ããŸã
ãããã®2ã€ã®ã¢ãããŒããçµã¿åãããŠãæ¬ èœããŠããæ©èœãè£å®ãããè€è£œããŠãæ»æãæ€åºããå¯èœæ§ãé«ããããšãã§ããŸãã
ã©ã®ã¢ãããŒããéžæããŸããïŒ
ããã¯ããªãã®ããŒã ã®è³æ Œãšå¥œã¿ã«äŸåããŸãã
é·æãšçæããããŸãã
çµ±åãããéäžèªèšŒããã³èªå¯ã·ã¹ãã
åªããèšèšã«ããããã®èšäºã§èª¬æããã¢ããªãã£ã¯ããªãã£ã¹ãèªå®
ã空枯ãã«ãã§ããŸãã¯ãã®ä»ã®å Žæããäœæ¥ãããšãã«åãã¢ã¯ã»ã¹æš©ãæã£ãŠããããšãåæãšããŠããŸãïŒäžèšã§èª¬æããå¶éããããŸãïŒã åé¡ã¯äœã§ããïŒ
ãã®ã¿ã¹ã¯ã®è€éããããããçè§£ããããã«ãå
žåçãªãã¶ã€ã³ãèŠãŠã¿ãŸãããã
äŸ
- ãã¹ãŠã®åŸæ¥å¡ãã°ã«ãŒãã«åå²ããŸããã ã°ã«ãŒãã¢ã¯ã»ã¹ãèš±å¯ããããšã«ããŸãã
- ãªãã£ã¹å
ã§ã¯ããªãã£ã¹ã®ãã¡ã€ã¢ãŠã©ãŒã«ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããŸã
- ããŒã¿ã»ã³ã¿ãŒã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ããªãã£ã¹ããããŒã¿ã»ã³ã¿ãŒãžã®ãã©ãã£ãã¯ãå¶åŸ¡ããŸã
- VPNã²ãŒããŠã§ã€ãšããŠãCisco ASAã䜿çšããå²ãåœãŠãããã¯ã©ã€ã¢ã³ããããããã¯ãŒã¯ã«å
¥ããã©ãã£ãã¯ãå¶åŸ¡ããã«ã¯ãããŒã«ã«ïŒASAäžïŒACLã䜿çšããŸã
ããã§ãç¹å®ã®åŸæ¥å¡ã«ã¢ã¯ã»ã¹ã远å ããããã«æ±ãããããšããŸãã åæã«ãããªãã¯åœŒã ãã«ã¢ã¯ã»ã¹æš©ã远å ããããã«æ±ãããã圌ã®ã°ã«ãŒãããã¯èª°ã远å ããŸããã
ãããè¡ãã«ã¯ããã®åŸæ¥å¡çšã«å¥ã®ã°ã«ãŒããäœæããå¿
èŠããããŸãã
- ASAã§ããã®åŸæ¥å¡çšã«åå¥ã®IPããŒã«ãäœæããŸã
- ASAã«æ°ããACLã远å ãããã®ãªã¢ãŒãã¯ã©ã€ã¢ã³ãã«ãã€ã³ãããŸã
- ãªãã£ã¹ããã³ããŒã¿ã»ã³ã¿ãŒã®ãã¡ã€ã¢ãŠã©ãŒã«ã«æ°ããã»ãã¥ãªãã£ããªã·ãŒãäœæãã
ãŸãããã®ã€ãã³ãããŸããªå Žåã ããããç§ã®å®è·µã§ã¯ãåŸæ¥å¡ãããŸããŸãªãããžã§ã¯ãã«åå ããç¶æ³ããããäžéšã®åŸæ¥å¡ã®ãã®ãããžã§ã¯ãã»ããã¯é »ç¹ã«å€æŽãããããã¯1ã2人ã§ã¯ãªãæ°å人ã§ããã ãã¡ãããããã§äœãã倿Žããå¿
èŠããããŸããã
ããã¯æ¬¡ã®æ¹æ³ã§è§£æ±ºãããŸããã
ãã¹ãŠã®åŸæ¥å¡ã¢ã¯ã»ã¹ã決å®ããå¯äžã®çå®ã®ãœãŒã¹ã¯LDAPã§ãããšå€æããŸããã ã¢ã¯ã»ã¹ã®ã»ãããå®çŸ©ãããã¹ãŠã®çš®é¡ã®ã°ã«ãŒããäœæããåãŠãŒã¶ãŒã1ã€ãŸãã¯è€æ°ã®ã°ã«ãŒãã«ãªã³ã¯ããŸããã
ãããã£ãŠãããšãã°ãã°ã«ãŒãããã£ããšããŸã
- ã²ã¹ãïŒã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ïŒ
- å
±éã¢ã¯ã»ã¹ïŒå
±æãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ïŒã¡ãŒã«ãç¥èããŒã¹ã...ïŒ
- çµç
- ãããžã§ã¯ã1
- ãããžã§ã¯ã2
- ããŒã¿ããŒã¹ç®¡çè
- Linux管çè
- ...
ãŸããåŸæ¥å¡ã®1人ããããžã§ã¯ã1ãšãããžã§ã¯ã2ã®äž¡æ¹ã«é¢äžããŠããããããã®ãããžã§ã¯ãã§äœæ¥ããããã«å¿
èŠãªã¢ã¯ã»ã¹ãå¿
èŠãªå Žåããã®åŸæ¥å¡ã¯ããããæ¬¡ã®ã°ã«ãŒãã«æå±ããŠããŸããã
- ã²ã¹ã
- å
±éã¢ã¯ã»ã¹
- ãããžã§ã¯ã1
- ãããžã§ã¯ã2
ãã®æ
å ±ããããã¯ãŒã¯æ©åšäžã®ã¢ã¯ã»ã¹ã«å€æããæ¹æ³ã¯ïŒ
Cisco ASAãã€ãããã¯ã¢ã¯ã»ã¹ããªã·ãŒïŒDAPïŒïŒ www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/108000-dap-deploy-guideãåç
§.html ïŒãœãªã¥ãŒã·ã§ã³ã¯ããã®ã¿ã¹ã¯ã«æé©ã§ãã
å®è£
ã«ã€ããŠç°¡åã«èª¬æãããšãèå¥/æ¿èªããã»ã¹äžã«ãASAã¯LDAPãããã®ãŠãŒã¶ãŒã«å¯Ÿå¿ããã°ã«ãŒãã®ã»ãããåãåããããã€ãã®ããŒã«ã«ACLïŒãããããã°ã«ãŒãã«å¯Ÿå¿ïŒããå¿
èŠãªãã¹ãŠã®ã¢ã¯ã»ã¹ãæã€åçACLããåéãããŸãã
ãã ããããã¯VPNæ¥ç¶å°çšã§ãã VPNãä»ããŠæ¥ç¶ãããåŸæ¥å¡ãšãªãã£ã¹ã®åŸæ¥å¡ã®äž¡æ¹ã§ç¶æ³ãåãã«ããããã«ã次ã®ã¹ããããåãããŸããã
ãªãã£ã¹ããæ¥ç¶ããå Žåã802.1xãããã³ã«ã䜿çšãããŠãŒã¶ãŒã¯ãã²ã¹ãvilanïŒã²ã¹ãçšïŒãŸãã¯å
±æã¢ã¯ã»ã¹ã®ããvilanïŒäŒç€Ÿã®åŸæ¥å¡çšïŒã§çµäºããŸããã ããã«ãç¹å®ã®ã¢ã¯ã»ã¹ïŒããŒã¿ã»ã³ã¿ãŒå
ã®ãããžã§ã¯ããªã©ïŒãååŸããããã«ãåŸæ¥å¡ã¯VPNçµç±ã§æ¥ç¶ããå¿
èŠããããŸããã
ãªãã£ã¹ãšèªå®
ããæ¥ç¶ããããã«ãASAã®ç°ãªããã³ãã«ã°ã«ãŒãã䜿çšãããŸããã ããã¯ããªãã£ã¹ããå
±æãªãœãŒã¹ïŒã¡ãŒã«ããã¡ã€ã«ãµãŒããŒããã±ããã·ã¹ãã ãDNSãªã©ã®ãã¹ãŠã®åŸæ¥å¡ã䜿çšïŒã«æ¥ç¶ãããã©ãã£ãã¯ã®å ŽåãASAã§ã¯ãªãããŒã«ã«ãããã¯ãŒã¯ãçµç±ããããã«å¿
èŠã§ãã ãããã£ãŠãé«åŒ·åºŠã®ãã©ãã£ãã¯ãå«ãéå°ãªãã©ãã£ãã¯ã§ASAãããŒãããŸããã§ããã
ãããã£ãŠãåé¡ã¯è§£æ±ºãããŸããã
ã§ãã
- ãªãã£ã¹ããã®æ¥ç¶ãšãªã¢ãŒãæ¥ç¶ã®äž¡æ¹ã«åãã¢ã¯ã»ã¹ã»ãã
- ASAãä»ããé«åŒ·åºŠãã©ãã£ãã¯ã®éä¿¡ã«é¢é£ãããªãã£ã¹ã§ã®äœæ¥æã®ãµãŒãã¹äœäžã®æ¬ åŠ
ãã®ã¢ãããŒãã®å©ç¹ã¯äœã§ããïŒ
ã¢ã¯ã»ã¹ç®¡çã ã¢ã¯ã»ã¹ã¯1ãæã§ç°¡åã«å€æŽã§ããŸãã
ããšãã°ãåŸæ¥å¡ãéè·ããå ŽåãLDAPããåé€ããã ãã§ããã®åŸæ¥å¡ã¯ãã¹ãŠã®ã¢ã¯ã»ã¹ãèªåçã«å€±ããŸãã
ãã¹ããã§ãã¯
ãªã¢ãŒãæ¥ç¶ãå¯èœãªå ŽåãäŒç€Ÿã®åŸæ¥å¡ã ãã§ãªãã圌ã®ã³ã³ãã¥ãŒã¿ãŒïŒèªå®
ãªã©ïŒã«ååšããå¯èœæ§ã®ãããã¹ãŠã®æªæã®ãããœãããŠã§ã¢ããããã¯ãŒã¯ã«èš±å¯ãããªã¹ã¯ããããŸããããã«ããã®ãœãããŠã§ã¢ãéããŠããã®ãã¹ãããããã·ãšããŠäœ¿çšããæ»æè
ãžã®ãããã¯ãŒã¯ã
ãªã¢ãŒããã¹ãããªãã£ã¹ãã¹ããšåãã»ãã¥ãªãã£èŠä»¶ãé©çšããããšã¯çã«ããªã£ãŠããŸãã
ããã«ã¯ãOSã®ãæ£ãããããŒãžã§ã³ããŠã€ã«ã¹å¯Ÿçãã¹ãã€ãŠã§ã¢å¯Ÿçãããã³ãã¡ã€ã¢ãŠã©ãŒã«ãœãããŠã§ã¢ãšæŽæ°ãå«ãŸããŸãã
éåžžããã®æ©èœã¯VPNã²ãŒããŠã§ã€ã«ååšããŸãïŒASAã«ã€ããŠã¯ãããšãã°ããã¡ããåç
§ããŠãã ããïŒããŸããã»ãã¥ãªãã£ããªã·ãŒã«åŸã£ãŠãªãã£ã¹ãã©ãã£ãã¯ã«é©çšããããã©ãã£ãã¯åæããã³ãããã¯ã®åãæ¹æ³ïŒãé«ã¬ãã«ã®ä¿è·ããåç
§ïŒãé©çšããããšãåççã§ãããªãã£ã¹ãããã¯ãŒã¯ããªãã£ã¹ãã«ãšãã®äžã«ãããã¹ãã«éå®ãããªããªã£ããšä»®å®ããã®ã¯åççã§ããäŸ
ãªã¢ãŒãã¢ã¯ã»ã¹ãå¿
èŠãšãããã¹ãŠã®åŸæ¥å¡ã«ã䟿å©ã§äŸ¿å©ãªã©ããããããè£
åãããªãã£ã¹ãšèªå®
ã®äž¡æ¹ã§ä»äºãããããšã ããèŠæ±ããããšãæè¿ããŸãã
ããã«ããããããã¯ãŒã¯ã®ã»ãã¥ãªãã£ã¬ãã«ãåäžããã ãã§ãªããéåžžã«äŸ¿å©ã§ãããéåžžã¯åŸæ¥å¡ãç©æ¥µçã«èªèããŸãïŒæ¬åœã«äŸ¿å©ã§äŸ¿å©ãªã©ãããããã®å ŽåïŒã
ãã©ã³ã¹æèŠãšãã©ã³ã¹ã«ã€ããŠ
ååãšããŠãããã¯äžè§åœ¢ã®3çªç®ã®ããŒã¯ãã€ãŸãäŸ¡æ Œã«é¢ããäŒè©±ã§ããæ¶ç©ºã®äŸãèŠãŠã¿ãŸããããäŸ
200 . .
. security , (anti-virus, anti-spyware, and firewall software), .
( ) 10- , â NGFW , , Palo Alto 7K (c 40 ), , , High Availability .
, , security .
, .
, 10 , ( ) .
, 200 âŠ
䟿å©ã§ããïŒ , .
âŠ
, - , . â , , , .
ãã®äŸã¯èªåŒµãããŠããŸããïŒæ¬¡ã®ç« ã§ãã®è³ªåã«çããŸãããããã¯ãŒã¯äžã§ããã®èšäºã§æ€èšããå
容ã衚瀺ãããªãå Žåã¯ããããæšæºã§ããç¹å®ã®ã±ãŒã¹ããšã«ãå©äŸ¿æ§ãäŸ¡æ Œãã»ãã¥ãªãã£ã®éã®åççãªåŠ¥åç¹ãèŠã€ããå¿
èŠããããŸããå€ãã®å Žåããªãã£ã¹ã§NGFWããå¿
èŠãšããªãããããã¡ã€ã¢ãŠã©ãŒã«ã§ã®L7ä¿è·ã¯å¿
èŠãããŸãããé©åãªã¬ãã«ã®å¯èŠæ§ãšã¢ã©ãŒããæäŸããã ãã§ååã§ããããã¯ãããšãã°ãªãŒãã³ãœãŒã¹è£œåã䜿çšããŠå®è¡ã§ããŸããã¯ããæ»æã«å¯Ÿããããªãã®åå¿ã¯ç¬æã§ã¯ãããŸããããäž»ãªããšã¯ãããèŠããšããããšã§ãããããªãã®éšéã«é©åãªããã»ã¹ãããã°ãããªãã¯ãããè¿
éã«ç¡ååããããšãã§ããŸãããããŠããããã®äžé£ã®èšäºã®ã¢ã€ãã¢ã«ããã°ãããªãã¯ãããã¯ãŒã¯èšèšã«é¢äžããŠããããããªããåŸããã®ãæ¹åããããšããŠããã ãã§ããããšãæãåºãããŠãã ããããªãã£ã¹ã¢ãŒããã¯ãã£ã®å®å
šåæ
ããã§èª¬æãããSAFE Secure Campus Architecture Guideã®å³äžã§å Žæãå²ãåœãŠããã®èµ€ãåè§ã«æ³šæããŠãã ããã
ããã¯ã建ç¯ã®éèŠãªå Žæã®1ã€ã§ãããæãéèŠãªäžç¢ºå®æ§ã®1ã€ã§ããæ³šïŒ
FirePowerãèšå®ããããšã¯ãªãïŒCiscoãã¡ã€ã¢ãŠã©ãŒã«ã©ã€ã³ãã-ASAã®ã¿ïŒãåãæ©èœãåããŠãããšä»®å®ããŠãããšãã°Juniper SRXãPalo Altoãªã©ã®ä»ã®ãã¡ã€ã¢ãŠã©ãŒã«ãšåæ§ã«æ€èšããŸãã
éåžžã®æ§é ããããã®æ¥ç¶ã§ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããããã®4ã€ã®å¯èœãªãªãã·ã§ã³ã®ã¿ã衚瀺ãããŸãã- åãµããããã®ããã©ã«ãã²ãŒããŠã§ã€ã¯ã¹ã€ããã§ããããã¡ã€ã¢ãŠã©ãŒã«ã¯ééã¢ãŒãã§ãïŒã€ãŸãããã¹ãŠã®ãã©ãã£ãã¯ã¯ééããŸãããL3ãããã圢æããŸããïŒã
- - ( SVI ), L2
- VRF, VRF , VRF ACL
- ,
1
, .
2
PBR ( service chain), , , , .
ããã¥ã¡ã³ãã®ãããŒã®èª¬æããããã¹ãŠã®åããã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ãééããããšãããããŸããã€ãŸããCiscoã®èšèšã«åŸã£ãŠã4çªç®ã®ãªãã·ã§ã³ã¯è¡šç€ºãããªããªããŸããæåã®2ã€ã®ãªãã·ã§ã³ãèŠãŠã¿ãŸãããããããã®ãªãã·ã§ã³ã䜿çšãããšããã¹ãŠã®ãã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ãééããŸããæ¬¡ã«ãããŒã¿ã·ãŒããšCisco GPLãèŠãŠããªãã£ã¹ã®åèšåž¯åå¹
ãå°ãªããšã10ã20ã®ã¬ãããã®é åã«ãããå Žåã¯ã4KããŒãžã§ã³ã賌å
¥ããå¿
èŠãããããšã確èªããŸããæ³š
åèšåž¯åå¹
ã«ã€ããŠè©±ããšãããµããããéã®ãã©ãã£ãã¯ãæå³ããŸãïŒ1ã€ã®wilanå
ã§ã¯ãããŸããïŒã
GPLãããThreat DefenseãåããHAãã³ãã«ã®äŸ¡æ Œã¯ãã¢ãã«ïŒ4110ã4150ïŒã«å¿ããŠãçŽ50ã250äžãã«ãšç°ãªãããšãããããŸããã€ãŸããèšèšã¯åã®äŸã®ããã«ãªãå§ããŸããããã¯ããã®èšèšãééã£ãŠããããšãæå³ããŸããïŒããããããã§ã¯ãããŸãããã·ã¹ã³ã¯ãææãã補åã©ã€ã³ã«åºã¥ããŠå¯èœãªéãæé«ã®ä¿è·ãæäŸããŸããããããããã¯ãããããªãã«ãšã£ãŠããã¹ããã¥ãã§ããããšãæå³ãããã®ã§ã¯ãããŸãããååãšããŠãããã¯ãªãã£ã¹ãŸãã¯ããŒã¿ã»ã³ã¿ãŒã®èšèšã§çºçããäžè¬çãªè³ªåã§ãããããã¯åŠ¥åç¹ãæ¢ããªããã°ãªããªãããšãæå³ããŸããããšãã°ããã¹ãŠã®ãã©ãã£ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ãééã§ããããã§ã¯ãããŸããããã®å Žåã3çªç®ã®ãªãã·ã§ã³ã¯éåžžã«è¯ãããã«æããŸãïŒåã®ã»ã¯ã·ã§ã³ãåç
§ïŒãããããããã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãã«Threat Defenseã¯å¿
èŠãªããããã¡ã€ã¢ãŠã©ãŒã«ã¯äžèŠå¿
èŠãªã®ã¯ãææïŒé«äŸ¡ã§ã¯ãªãïŒãŸãã¯ãªãŒãã³ãœãŒã¹ã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããããã·ãã¢ãã¿ãªã³ã°ããŸãã¯ãã¡ã€ã¢ãŠã©ãŒã«ãå¿
èŠã§ãããå¥ã®ãã³ããŒãå¿
èŠã§ããéåžžããã®äžç¢ºå®æ§ã¯åžžã«ååšããã©ã®ãœãªã¥ãŒã·ã§ã³ãæé©ã§ãããã«ã€ããŠåäžã®çãã¯ãããŸãããããããã®ã¿ã¹ã¯ã®è€éããšçŸããã§ãã