åºæ¬çãªã€ã³ã¿ãŒãã§ã€ã¹ãšã«ãŒãã£ã³ã°èšå®ãããã³ãªã¢ãŒã管çã®æ¥ç¶èšå®ããå§ããŸããã
ã€ã³ã¿ãŒãã§ãŒã¹èšå®Cisco ASAã¯ãã¹ããŒããã«ã€ã³ã¹ãã¯ã·ã§ã³ã»ãã·ã§ã³ãåããã¹ããŒããã«ã€ã³ã¹ãã¯ã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ã§ãã ASAã¯ãã«ãŒãããïŒããã©ã«ãã§ã¯ã«ãŒã¿ãŒã¢ãŒãïŒãšééïŒASAããã£ã«ã¿ãªã³ã°ããªããžãšããŠæ©èœããå Žåã¯ééãã¡ã€ã¢ãŠã©ãŒã«ïŒã®2ã€ã®ã¢ãŒãã§åäœã§ããŸãã æåã®ã¢ãŒãã§äœæ¥ãç¥ãããã«ãªãã以éãç¹ã«æå®ããªãéããã©ãã§ããããæå³ããŸãã
ã«ãŒãããã¢ãŒãã§ã¯ãåASAã€ã³ã¿ãŒãã§ã€ã¹ã¯IPã¢ãã¬ã¹ããã¹ã¯ãã»ãã¥ãªãã£ã¬ãã«ãã€ã³ã¿ãŒãã§ã€ã¹åã§èšå®ãããããã©ã«ãã§ã¯ãã¹ãŠã®ã€ã³ã¿ãŒãã§ã€ã¹ãã管çè
ã«ããç¡å¹åãç¶æ
ã«ãããããã€ã³ã¿ãŒãã§ã€ã¹ã匷å¶çã«äžããå¿
èŠããããŸãã ïŒäŸå€ããããŸããASAã¯äºåã«æ§æãããŠããå ŽåããããŸããããã¯5505ã¢ãã«ã®å
žåã§ãããã®å ŽåãååãšããŠãå
éšã®ååãæã€å
éšã€ã³ã¿ãŒãã§ã€ã¹ã¯æ¢ã«æãå®å
šã§äžããããDHCPãµãŒããŒãå®è¡ããããããã¯ãŒã¯192.168.1.0ããã®éçã¢ãã¬ã¹ãèšå®ãããŠããŸã/ 24ãoutsideãšããååã®å€éšã€ã³ã¿ãŒãã§ã€ã¹ãçºçããããèªäœãDHCPçµç±ã§ã¢ãã¬ã¹ãåä¿¡ããå
éšã€ã³ã¿ãŒãã§ã€ã¹ã®èåŸã®ãããã¯ãŒã¯ããå€éšã€ã³ã¿ãŒãã§ã€ã¹ã¢ãã¬ã¹ãžã®ã¢ãã¬ã¹å€æãèšå®ãããŸãããã®ãããªãã©ã°ã¢ã³ããã¬ã€ã倿ããŸãã
int g0 / 0
IPã¢ãã¬ã¹{ã¢ãã¬ã¹} {ãã¹ã¯}
ã»ãã¥ãªãã£ã¬ãã«{æ°å€}
nameif {name}
ã·ã£ããããŠã³ãªã
ãã»ãã¥ãªãã£ã¬ãã«ããã©ã¡ãŒã¿ã¯0ã100ã®æ°å€ã§ã2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ãæ¯èŒããã©ã¡ãããããå®å
šããã倿ã§ããŸãã ãã©ã¡ãŒã¿ã¯ãå®éçã§ã¯ãªã宿§çã«äœ¿çšãããŸãã ããå°ãªãé¢ä¿ã®ã¿ãéèŠã§ãã ããã©ã«ãã§ã¯ããã©ãã£ãã¯ã¯ãå€éšãã«åãã£ãŠããŸãã ã»ãã¥ãªãã£ã¬ãã«ã®é«ãã€ã³ã¿ãŒãã§ã€ã¹ããã»ãã¥ãªãã£ã¬ãã«ã®äœãã€ã³ã¿ãŒãã§ã€ã¹ãŸã§ãã¹ããããããã»ãã·ã§ã³ã¯èšæ¶ããããããã®ã»ãã·ã§ã³ããã®å¿çã®ã¿ãã¹ããããããŸãã ãå
éšããžã®ãã©ãã£ãã¯ã¯ããã©ã«ãã§ã¯çŠæ¢ãããŠããŸãã
å°æ¥ããã©ã¡ãŒã¿ãŒãã€ã³ã¿ãŒãã§ãŒã¹åãïŒnameifïŒã䜿çšãããšãèšå®ã§ã€ã³ã¿ãŒãã§ãŒã¹ã®ç©çåã§ã¯ãªããã話ãããšããŠéžæã§ããååïŒå
éšãå€éšãdmzãããŒãããŒãªã©ïŒã䜿çšã§ããŸãã çè«çã«ã¯ãã·ã¹ã³èªäœã«ãããšãååã¯å€§æåãšå°æåãåºå¥ããïŒå€§æåãšå°æåãåºå¥ããŸããïŒãå®éã«ã¯ãå€ãã®ã³ãã³ãã§å€§æåãšå°æåãåºå¥ããå¿
èŠããããããã¯ããªãäžäŸ¿ã§ãã å
žåçãªäŸïŒã€ã³ã¿ãŒãã§ã€ã¹ã«æå·ããããé©çšããã«ã¯ãã€ã³ã¿ãŒãã§ã€ã¹åã®æ£ç¢ºãªã¹ãã«ãå¿
èŠã§ãã ã€ã³ã¿ãŒãã§ã€ã¹ã®ååãç¶ããã«ã¯ãTABãã¿ã³ãæŒããŸãã å
¥åããå
é ãã€ã³ã¿ãŒãã§ã€ã¹ãäžæã«èå¥ããå Žåãååã®å
é ãå
¥åããã¿ãã¥ã¬ãŒã¿ãŒã§æåŸãŸã§ç¶è¡ã§ããŸãã
ãã®ã€ã³ã¿ãŒãã§ã€ã¹èšå®ã¯ãASA 5505ãé€ããã¹ãŠã®ASAã¢ãã«ã«å
±éã§ãã5505ã«ã¯ãçµã¿èŸŒã¿ã®8ããŒãL2 / L3ã¹ã€ããããããŸãã ã¢ãã«5505ã®IPã¢ãã¬ã¹ã¯è«çã€ã³ã¿ãŒãã§ã€ã¹ã«èšå®ãããŸã
ã€ã³ã¿ãŒãã§ã€ã¹VLAN {ïŒ}
IPã¢ãã¬ã¹{ã¢ãã¬ã¹} {ãã¹ã¯}
ã»ãã¥ãªãã£ã¬ãã«{æ°å€}
nameif {name}
ã·ã£ããããŠã³ãªã
ç©çL2ã€ã³ã¿ãŒãã§ã€ã¹èªäœã¯VLANã«ãããã³ã°ãããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹f0 / 0
ã¹ã€ããããŒãã¢ã¯ã»ã¹VLAN {ïŒ}
ãããã£ãŠããã¡ã€ã¢ãŠã©ãŒã«ã¯è«çã€ã³ã¿ãŒãã§ã€ã¹VLANã®éã§çºçããŸãã
ååãšããŠãã€ã³ã¿ãŒãã§ã€ã¹ã®ã»ãã¥ãªãã£ã¬ãã«ã¯ããããã¯ãŒã¯ã®è«çããããžã«æââé©ãªæ¹æ³ã§éžæãããŸãã ããããžèªäœã¯ã»ãã¥ãªãã£ãŸãŒã³ã§ããããããã®éã®çžäºäœçšã®ã«ãŒã«ã§ãã å€å
žçãªã¹ããŒã ã¯ãããŸããŸãªã»ãã¥ãªãã£ã¬ãã«ãããŸããŸãªã€ã³ã¿ãŒãã§ã€ã¹ã«å²ãåœãŠãããšã§ãã
ç°ãªãã€ã³ã¿ãŒãã§ã€ã¹ã®ã»ãã¥ãªãã£ã¬ãã«ãåãã«ããããšãçŠæ¢ãã人ã¯ããŸããããããã©ã«ãã§ã¯ããã®ãããªã€ã³ã¿ãŒãã§ã€ã¹éã®ãã©ãã£ãã¯äº€æã¯çŠæ¢ãããŠããŸãã ãã®ãããªãã©ãã£ãã¯ã¯ãã³ãã³ããäžããããšã§æå³çã«èš±å¯ããããšãã§ããŸã
åäžã»ãã¥ãªãã£ãã©ãã£ãã¯èš±å¯ã€ã³ã¿ãŒãã§ã€ã¹é
ãã ããåãã¬ãã«ã®ã»ãã¥ãªãã£ãåããã€ã³ã¿ãŒãã§ã€ã¹éã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãªãã«ãŒãã£ã³ã°ã®ã¿ãè¡ãããããšãçè§£ããå¿
èŠããããŸãã ãããã£ãŠããã®ã¢ãããŒãã¯ãåãè«çã»ãã¥ãªãã£ãŸãŒã³ã«é¢é£ããã€ã³ã¿ãŒãã§ã€ã¹ã«äœ¿çšãããŸãïŒããšãã°ãASAã«ãã£ãŠçµåããããŠãŒã¶ãŒã®2ã€ã®ããŒã«ã«ãšãªã¢ãããã¯ãŒã¯ïŒ
ã«ãŒãã£ã³ã°ããŠããããªãã§ã©ãã«ïŒ ã«ãŒã¿ãŒãšåæ§ã«ïŒASAã¯ã«ãŒãã£ã³ã°ããŒãã«ã䜿çšããŠãã±ãããéä¿¡ãããããASAã«ããããŸãïŒãã€ã³ã¿ãŒãã§ã€ã¹ã«èšå®ããããããã¯ãŒã¯ã¯ããæ¥ç¶æžã¿ããšããŒã¯ãããã«ãŒãã£ã³ã°ããŒãã«ã«èªåçã«åé¡ãããŸããã¢ããç¶æ
ã ãããã®ãããã¯ãŒã¯éã®ãã±ããã«ãŒãã£ã³ã°ã¯èªåã§ãã
ASAèªäœãèšè¿°ããå¿
èŠã®ãªããããã¯ãŒã¯ã ããã¯ãã³ãã³ãã䜿çšããŠæåã§å®è¡ã§ããŸã
ã«ãŒã{ã€ã³ã¿ãŒãã§ãŒã¹} {ãããã¯ãŒã¯} {ãã¹ã¯} {ãã¯ã¹ãããã} [{管çè·é¢}] [ãã©ãã¯{ïŒ}]
ãã¯ã¹ãããããæ¢ãã€ã³ã¿ãŒãã§ã€ã¹ãæå®ããŸãã ASAèªäœã¯ãã®ãããªæ€çŽ¢ãè¡ããŸããïŒéåžžã®Ciscoã«ãŒã¿ãŒãšã¯ç°ãªããŸãïŒã æå€§16ã®äžŠåãã¹ã䜿çšã§ããåŸæ¥ã®ã«ãŒã¿ãŒãšã¯ç°ãªããã«ãŒãã£ã³ã°ããŒãã«å
ã®å®å
ãããã¯ãŒã¯ã«å°éããã«ãŒãã¯1ã€ã ãã§ãã
ããã©ã«ãã«ãŒãã¯åãæ¹æ³ã§èšå®ãããŸãã
route {interface} 0.0.0.0 0.0.0.0 {next-hop}
ASAãã«ãŒãã£ã³ã°ããŒãã«ã«ãã±ããå®å
ãããã¯ãŒã¯ã«é¢ãããšã³ããªããªãå Žåããã±ããã廿£ããŸãã
ã¡ã€ã³ã®ã«ãŒããæ¶ãããšãã«ã®ã¿æ©èœããããã¯ã¢ããéçã«ãŒããäœæãããšããã¿ã¹ã¯ãçºçããå Žåãããã¯ããããã«ãŒãã®ç®¡çè·é¢ã瀺ãããšã§è§£æ±ºãããŸãã ããã¯ã0ã255ã®æ°å€ã§ãããã«ãŒãéžææ¹æ³ã®æå¹æ§ã瀺ããŸãã ããšãã°ãéçã«ãŒãã¯ããã©ã«ãã§AD 1ãEIGRP-90ãOSPF-110ãRIP-120ã«ããããããŸããã¡ã€ã³ADãããå€ãã®ãã©ãŒã«ããã¯ã«ãŒãã«ADãæç€ºçã«æå®ã§ããŸãã äŸïŒ
0.0.0.0 0.0.0.0ã®å€åŽã®ã«ãŒã{next-hop} 1
ã«ãŒãããã¯ã¢ãã0.0.0.0 0.0.0.0 {next-hop_backup} 210
ãããããã®ç¶æ³ã§ã¯ã1ã€ã®éèŠãªè³ªåããããŸããã¡ã€ã³ã«ãŒãããæ¶å€±ããããæ¹æ³ã§ããã ã€ã³ã¿ãŒãã§ã€ã¹ãç©ççã«èœã¡ãå Žåããã¹ãŠãæããã§ã-ããã¯ããèªäœã§åäœããŸãããã€ã³ã¿ãŒãã§ã€ã¹ãã¢ããããŠããããããã€ããŒãæ»ãã§ããå Žåã¯ã©ããªããŸããïŒ ããã¯ãASAã«ç©ççãªã€ãŒãµããããéåžžã«ãŸãã«ããååšããªããããéåžžã«äžè¬çãªç¶æ³ã§ãã
ãã®åé¡ã解決ããããã«ãSLAãã¯ãããžãŒã䜿çšãããŸãã ããã¯ãã¯ã©ã·ãã¯ã«ãŒã¿ãŒã§é«åºŠã«éçºãããŠãããããŒãžã§ã³7.2以éã®ASAã§ã¯ãæãåçŽãªã¡ã«ããºã ïŒicmpãããã³ã«çµç±ã®ãã¹ãã®å¯çšæ§ïŒã®ã¿ãå®è£
ããŠããŸããã ãããè¡ãã«ã¯ããã®ãããªãpingovalkaãïŒsla monitorïŒãäœæããŸã
sla monitor {ïŒ}
ã¿ã€ãecho protocol ipIcmpEcho {ip address} interface {interface}
ããã«ãéå§æéïŒãä»ããéå§ããããšãå¯èœïŒãšäœæ¥ã®çµäºïŒäœæ¥ãç¡éã«èšå®ã§ããŸãïŒãæå®ããŠéå§ããå¿
èŠããããŸãã
SLAã¢ãã¿ãŒã¹ã±ãžã¥ãŒã«{ïŒ}人çãæ°žé ã«éå§
ããããããã ãã§ã¯ãããŸããã ãpingovalkaãã®ã¹ããŒã¿ã¹ã远跡ãããã¹ã€ãããïŒãã©ãã¯ïŒãäœæããå¿
èŠããããŸãã
ãã©ãã¯{ãã©ãã¯ïŒ} rtr {slaïŒ}å°éå¯èœæ§
pingovalkaãã€ã³ãã£ã³ã°ãrtrããŒã¯ãŒãã䜿çšããŠå®è¡ãããçç±ãå°ããªãã§ãã ãããããã¯ãCiscoã«ãŒã¿ãŒã§ã®äžè²«æ§ã®ãªãèšå®ã®ãã³ã»ã³ã¹ã§ãã ã¡ãªã¿ã«ããã®ãããªäžäžèŽã¯ã«ãŒã¿ãŒèªäœã§æ¢ã«ä¿®æ£ãããŠããŸãããASAã§ã¯ãŸã ä¿®æ£ãããŠããŸããã
ããã§ããã®æ§æãéçã«ãŒãã£ã³ã°ã«é©çšããæºåããã¹ãŠæŽããŸããã
0å€ã®ã«ãŒã{next-hop_outside}ãã©ãã¯{ïŒ}
ã«ãŒãããã¯ã¢ãã0 0 {next-hop_backup} 210
ããã§ãpingå¯èœãªãã¹ãã«ã¢ã¯ã»ã¹ã§ããéããã©ãã¯ã¯èµ·åãïŒã»ãšãã©ãupãã«æžã蟌ãŸããŸãïŒãã¡ã€ã³ã«ãŒãã¯ã«ãŒãã£ã³ã°ããŒãã«ã«ãããŸãããæ¥ç¶ã倱ããããšããã«ãæå®ãããæ°ã®ãã±ããã倱ãããŸãïŒããã©ã«ãã§ã¯ã10åããšã«ãã±ãããéä¿¡ãããŸãïŒç§ã3ãã±ããã®æå€±ãåŸ
ã€ïŒãã©ãã¯ã忢ãããã¡ã€ã³ã«ãŒããã«ãŒãã£ã³ã°ããŒãã«ããæ¶ãããã±ããã代æ¿ãã¹ãä»ããŠéä¿¡ãããŸãã
ã¡ã€ã³ãããã€ããŒã®å¯çšæ§ã確èªããªãããç°ãªããããã€ããŒãéã2ã€ã®ããã©ã«ãã«ãŒãã®èšå®äŸã瀺ããŸãã
SLAã¢ãã¿ãŒ1
ã¿ã€ãecho protocol ipIcmpEcho 1.1.1.1å€éšã€ã³ã¿ãŒãã§ã€ã¹
SLAã¢ãã¿ãŒã¹ã±ãžã¥ãŒã«1ä»ããéå§
ãã©ãã¯11 RTR 1å°éå¯èœæ§
0 0 1.1.1.1ãã©ãã¯11å€ã®ã«ãŒã
ã«ãŒãããã¯ã¢ãã0 0 2.2.2.1 210
ãããã³ã«RIPv1ã2ãOSPFãEIGRPã䜿çšããŠãASAã§ã®åçã«ãŒãã£ã³ã°ãå¯èœã§ãã ASAã§ãããã®ãããã³ã«ãèšå®ããããšã¯ãCiscoã«ãŒã¿ãŒãèšå®ããããšã«éåžžã«äŒŒãŠããŸãã ä»ã®ãšããããããã®åºçç©ã®åçã«ãŒãã£ã³ã°ã«ã€ããŠã¯è§ŠããŸããããæãå±ãèå³ãããå Žåã¯ãå¥ã®ç« ãæžããŸãã
ãªã¢ã³ã³ããŒã¿ãããã¯ãŒã¯ã®çŸåšã®éçºã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã®ãªã¢ãŒãå¶åŸ¡ãå°å
¥ããªãã®ã¯äžåçã§ããããšã¯æããã§ãã ãããã£ãŠãASAã¯ãã»ãšãã©ã®ã·ã¹ã³ããã€ã¹ãšåæ§ã«ãããã€ãã®ãªã¢ãŒãç®¡çæ¹æ³ãæäŸããŸãã
æãåçŽã§æãå±éºãªã®ã¯telnetã§ãã telnetçµç±ã§ASAã«ã¢ã¯ã»ã¹ã§ããããã«ããã«ã¯ãã©ã®ãã¹ããšãããã¯ãŒã¯ãããã³ã©ã®ã€ã³ã¿ãŒãã§ã€ã¹ã¢ã¯ã»ã¹ãèš±å¯ããããæç€ºçã«æå®ããå¿
èŠããããŸãããŸããpasswdã³ãã³ãã§telnetã®ãã¹ã¯ãŒããæå®ããå¿
èŠããããŸãã
telnet 192.168.1.128 255.255.255.128å
éš
telnet 192.168.1.254 255.255.255.255å
éš
passwd {ãã¹ã¯ãŒã}
ã»ãã¥ãªãã£äžã®çç±ãããæãå®å
šã§ã¯ãªãïŒãã®ASAå
ã§æãã»ãã¥ãªãã£ã¬ãã«ãäœãïŒã€ã³ã¿ãŒãã§ã€ã¹ã§ã®telnetæäœã¯ãããã¯ããããã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ã®telnetæäœã¯ãIPSecãã³ãã«ãä»ããŠå°çããå Žåã«ã®ã¿å¯èœã§ãã
sshãããã³ã«ã«ãããããå®å
šãªã³ãã³ãã©ã€ã³ã¢ã¯ã»ã¹ãæäŸãããŸãã ãã ããsshãä»ããŠã¢ã¯ã»ã¹ãæäŸããã«ã¯ã管çã®ããã«ã¢ã¯ã»ã¹ã§ãããã¹ããæç€ºçã«æå®ããããšã«å ããŠããŠãŒã¶ãŒããŒã¿ã®æå·åã«å¿
èŠãªRSAããŒãæå®ããå¿
èŠããããŸãã ããã©ã«ãã§ã¯ãpixãŠãŒã¶ãŒã¯sshæ¥ç¶ã«äœ¿çšãããpasswdã³ãã³ãã§æå®ããããã¹ã¯ãŒãïŒtelnetãã¹ã¯ãŒãïŒã䜿çšãããŸãã
ïŒ ãã¡ã€ã³åãèšå®ãã
ãã¡ã€ã³å{name}
ïŒ
ïŒ ããã©ã«ã以å€ã®ãã¹ãåãæå®ããããšããå§ãããŸã
ãã¹ãå{åå}
ïŒ
ïŒ ãã®åŸãããŒãçæã§ããŸã
æå·éµã¯RSAãçæããŸã
ïŒ
ïŒ sshãèš±å¯ãã
ssh 192.168.1.128 255.255.255.128å
éš
ssh 1.2.3.4 255.255.255.255å€éš
passwd {ãã¹ã¯ãŒã}
ååãšããŠãããŒãžã§ã³7.2以éã®ASAã§ã¯ããã¡ã€ã³åããã§ã«èšå®ãããŠããïŒdomain.invalidïŒãããã©ã«ãããŒãçæãããŸãããå°ãªããšãããã確èªããå¿
èŠããããŸã
æå·éµmypubkey rsaã衚瀺
å°ãªããšãããã€ãã®RSAããŒã®ååšã«ããããã§ã«sshã§äœæ¥ã§ããŸãã ãã ããããã©ã«ã以å€ã®ããŒãã¢ã远å ã§äœæããããšãã§ããŸãã ãããè¡ãã«ã¯ãããŒãã¢ã®ååãæç€ºçã«æå®ããå¿
èŠããããŸã
æå·éµã¯ãRSAã©ãã«ãçæããŸã{ãã¢å}
ããŒãã¢ïŒãŸãã¯ãã¹ãŠã®ãã¢ïŒãåé€ããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸã
æå·éµãŒãårsa [ã©ãã«{ãã¢å}]
ãã³ãïŒããŒãã¢ã䜿çšããã¢ã¯ã·ã§ã³ïŒäœæãåé€ïŒã®åŸãå¿
ãä¿åããŠãã ããã ããã«ã¯ãæšæºã®ciscoã³ãã³ãã䜿çšã§ããŸãã
å®è¡æ§æã®èµ·åæ§æã®ã³ããŒ
æžã蟌ã¿ã¡ã¢ãª
ãŸãã¯æåŸã®ã³ãã³ãã®çãããŒãžã§ã³
wr
ASAã¯ãWebãã©ãŠã¶ã䜿çšããéåžžã«äžè¬çãªèšå®æ¹æ³ãæäŸããŸãã ãã®æ¹æ³ã¯ASDMïŒAdaptive Security Device ManagerïŒãšåŒã°ããŸãã å®å
šãªãããã³ã«httpsãã¢ã¯ã»ã¹ã«äœ¿çšãããŸãã ã¢ã¯ã»ã¹å¶åŸ¡ã¯ãsshãšéåžžã«ããäŒŒãæ§æã«ãªã£ãŠããŸããããã©ã«ãã®RSAããŒãããããšã確èªããããæ¥ç¶ã§ããå Žæã瀺ãå¿
èŠããããŸãã
ãã¡ã€ã³å{name}
ãã¹ãå{åå}
æå·éµã¯RSAãçæããŸã
ïŒ httpsãµãŒããŒèªäœããªã³ã«ããŸããå€ãã®å Žåãããã©ã«ãã§ãªã³ã«ãªã£ãŠããŸãã ãªã³ã«ãããšã
ïŒ èªå·±çœ²åèšŒææžãçæããŸãã
HTTPãµãŒããŒã®æå¹å
ïŒ httpsãèš±å¯ãã
http 192.168.1.128 255.255.255.128å
éš
http 1.2.3.4 255.255.255.255å€éš
ä»ã«äœãèšå®ããªãå ŽåããŠãŒã¶ãŒãæå®ããã«ã¢ã¯ã»ã¹ãæäŸãããŸãã ç¹æš©ã¢ãŒãã®ãã¹ã¯ãŒããæå®ãããå Žå
ã€ããŒãã«ãã¹ã¯ãŒã{password}
次ã«ãæ¥ç¶æã«ããŠãŒã¶ãŒãæå®ããã«ãã¹ã¯ãŒããšããŠæå®ããå¿
èŠããããŸãã
ASDMãã©ãã·ã¥ã«ã䜿çšãããŠããOSã«å¯Ÿå¿ããASDMãã¡ã€ã«ãå«ãŸããŠããããšã確èªããå¿
èŠããããŸãã
dir flashïŒ
ã·ã§ãŒãã©ãã·ã¥
ASDMã䜿çšããå Žåãjavaã䜿çšãããæ¬¡ã®ããšãåœãŠã¯ãŸããŸããOSããŒãžã§ã³7.Xã䜿çšããŠããå ŽåãASDMã¯ããŒãžã§ã³5.Xããã³java 1.5ãå¿
èŠãšããŸãã OS 8.Xã䜿çšããå ŽåãããŒãžã§ã³6.Xããã³JavaããŒãžã§ã³1.6ã«ã¯ASDMãå¿
èŠã§ãã éçºè
ã®å瞟ãšãã¥ãŒããŒã®åã³ã®ããã«ãASDMããŒãžã§ã³6ã¯ããŒãžã§ã³5.Xãããåªããé«éã§åäœããŸãã 誰ã®ã¡ãªãããããïŒJavaãŸãã¯CiscoãŸãã¯ãã®äž¡æ¹-ç§ã¯ç¥ããŸããã
åççãªçåãçããŸããããã©ã«ãã®ã¢ã¯ã»ã¹ã«ãŒã«ã§ã¯ãªããã©ãã§ãŠãŒã¶ãŒãååŸããããæç€ºçã«æå®ãããå Žåã¯ã©ãã§ããããã ããã«ã¯ã³ãã³ãã䜿çšãããŸãïŒã³ã³ãœãŒã«-ããŒã¯ãŒãïŒ
aaaèªèšŒtelnetã³ã³ãœãŒã«{AAAãµãŒããŒå} [ããŒã«ã«]
aaaèªèšŒsshã³ã³ãœãŒã«{AAAãµãŒããŒå} [ããŒã«ã«]
aaaèªèšŒhttpã³ã³ãœãŒã«{AAAãµãŒããŒå} [ããŒã«ã«]
ããŒã«ã«ãŠãŒã¶ãŒããŒã¿ããŒã¹ã®ã¿ã䜿çšããå Žåã¯ãèªèšŒã«ãŒã«ã§LOCALã®ã¿ãæå®ã§ããŸãïŒå°ãªããšã1人ã®ãŠãŒã¶ãŒãäœæãããŠããããšã確èªããŸããããã§ãªãå Žåã¯ãèªåãžã®ã¢ã¯ã»ã¹ããããã¯ã§ããŸãïŒããã®ãããªãµãŒããŒã¯äºåã«æ§æããå¿
èŠããããŸã
aaa-server {AAAãµãŒããŒå}ãããã³ã«{tacacs | radius | ldap}
aaa-server {AAAãµãŒããŒå}ïŒ{ã€ã³ã¿ãŒãã§ã€ã¹}ïŒãã¹ã{ip}
ããŒ{key}
ïŒ ãã®ã¿ã€ãã®ãµãŒããŒã«åºæã®ãã®ä»ã®ã³ãã³ã
ããŒã«ã«ãŠãŒã¶ãŒããŒã¹ã¯ããŒã ã«ãã£ãŠèšå®ãããŸã
ãŠãŒã¶ãŒ{ãŠãŒã¶ãŒ}ãã¹ã¯ãŒã{ãã¹ã¯ãŒã} [ç¹æš©ïŒ]
ASDMçµç±ã®ã¢ã¯ã»ã¹ã¯ãç¹æš©ã¬ãã«15ã®ãŠãŒã¶ãŒã«ä»£ãã£ãŠã®ã¿å¯èœã§ãïŒæå€§ãšã¯ããŠãŒã¶ãŒãæ§æã§ããããšãæå³ããŸãïŒ
次ã®ã³ãã³ãã䜿çšããŠãããŒã«ã«ãŠãŒã¶ãŒã«ããã€ãã®å±æ§ãèšå®ããããšãã§ããŸãã
ãŠãŒã¶ãŒ{user}屿§
ïŒ ããŸããŸãªãŠãŒã¶ãŒå±æ§
ãã®ããŒããçµããŠãèšå®ã®äžéšãæäŸããŸãã æ§æããã2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ïŒãã®å Žåã¯gigabitethernet 0/0ããã³0/1ã§ãããç°ãªããã©ãããã©ãŒã ã§ã¯ä»ã®ç©çã€ã³ã¿ãŒãã§ã€ã¹ã§ãããŸããŸããïŒãå
éšããã³å€éšãããã©ã«ãã«ãŒããsshããã³httpsçµç±ã®ãªã¢ãŒãã¢ã¯ã»ã¹ã¯ã©ãããã§ãèš±å¯ãããŸãããã
èªèšŒã¯ããŒã«ã«ãŠãŒã¶ãŒããŒã¿ããŒã¹ã䜿çšããŸãã
ãã¹ãåmyAsa
ïŒ
ãã¡ã€ã³åanticisco.ru
ïŒ
ã€ã³ã¿ãŒãã§ãŒã¹g0 / 0
å€ã®åå
ã»ãã¥ãªãã£ã¬ãã«0
IPã¢ãã¬ã¹1.1.1.2 255.255.255.252
éãŸããªã
ïŒ
int g0 / 1
äžã®åå
ã»ãã¥ãªãã£ã¬ãã«100
IPã¢ãã¬ã¹10.1.1.1 255.255.255.0
éãŸããªã
ïŒ
ïŒ ASAã¬ã³ãŒãã§ã¯0.0.0.0ã0ã«æžããããšãã§ããŸã
ïŒ
0 0 1.1.1.1å€ã®ã«ãŒã
ïŒ
ãŠãŒã¶ãŒåadminãã¹ã¯ãŒãciscoç¹æš©15
ïŒ
ssh 0 0å
éš
ssh 0 0å€
ïŒ
http 0 0å
éš
http 0 0å€
ïŒ
aaaèªèšŒsshã³ã³ãœãŒã«ããŒã«ã«
AAAèªèšŒHTTPã³ã³ãœãŒã«LOCAL
ãããã®èšå®ã䜿çšãããšãå
éšã€ã³ã¿ãŒãã§ã€ã¹ã®èåŸã«ããçŽæ¥æ¥ç¶ããããããã¯ãŒã¯ããå€éšãžã®ãã±ããéä¿¡ãèš±å¯ã§ããŸãã å€éšã§ã¯ãã»ãã·ã§ã³ïŒtcpããã³udpïŒã®å¿çã®ã¿ãåä¿¡ãããå
éšããéãããŸãã ããã©ã«ãã§ã¯ããå
éšããžã®ãã©ãã£ãã¯ã¯å®å
šã«çŠæ¢ãããŠããŸãã è§£æ±ºæ¹æ³ã«ã€ããŠã¯ã次ã®ããŒãã§èª¬æããŸãã
ã¢ã¯ã»ã¹ãªã¹ãïŒç¶ãïŒ