ื›ื™ืฆื“ ืœื”ืฉืชืœื˜ ืขืœ ืชืฉืชื™ืช ื”ืจืฉืช ืฉืœืš. ืคืจืง ืฉืœื™ืฉื™. ืื‘ื˜ื—ืช ืจืฉืช. ื—ืœืง ืฉืœื™ืฉื™

ืžืืžืจ ื–ื” ื”ื•ื ื”ื—ืžื™ืฉื™ ื‘ืกื“ืจื” "ื›ื™ืฆื“ ืœื”ืฉืชืœื˜ ืขืœ ืชืฉืชื™ืช ื”ืจืฉืช ืฉืœืš". ื ื™ืชืŸ ืœืžืฆื•ื ืืช ื”ืชื•ื›ืŸ ืฉืœ ื›ืœ ื”ืžืืžืจื™ื ื‘ืกื“ืจื” ื•ื”ืงื™ืฉื•ืจื™ื ื›ืืŸ.

ื—ืœืง ื–ื” ื™ื•ืงื“ืฉ ืœืžืงื˜ืขื™ VPN ืฉืœ ืงืžืคื•ืก (ืžืฉืจื“) ื•ื’ื™ืฉื” ืžืจื—ื•ืง.

ื›ื™ืฆื“ ืœื”ืฉืชืœื˜ ืขืœ ืชืฉืชื™ืช ื”ืจืฉืช ืฉืœืš. ืคืจืง ืฉืœื™ืฉื™. ืื‘ื˜ื—ืช ืจืฉืช. ื—ืœืง ืฉืœื™ืฉื™

ืขื™ืฆื•ื‘ ืจืฉืช ืžืฉืจื“ื™ืช ืขืฉื•ื™ ืœื”ื™ืจืื•ืช ืงืœ.

ื•ืื›ืŸ, ืื ื—ื ื• ืœื•ืงื—ื™ื ืžืชื’ื™ L2/L3 ื•ืžื—ื‘ืจื™ื ืื•ืชื ื–ื” ืœื–ื”. ืœืื—ืจ ืžื›ืŸ, ืื ื• ืžื‘ืฆืขื™ื ืืช ื”ื”ื’ื“ืจื” ื”ื‘ืกื™ืกื™ืช ืฉืœ Vilans ื•ืฉืขืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ, ืžื’ื“ื™ืจื™ื ื ื™ืชื•ื‘ ืคืฉื•ื˜, ืžื—ื‘ืจื™ื ื‘ืงืจื™ WiFi, ื ืงื•ื“ื•ืช ื’ื™ืฉื”, ืžืชืงื™ืŸ ื•ืžื’ื“ื™ืจ ASA ืœื’ื™ืฉื” ืžืจื—ื•ืง, ืื ื• ืฉืžื—ื™ื ืฉื”ื›ืœ ืขื‘ื“. ื‘ืขืฆื, ื›ืคื™ ืฉื›ื‘ืจ ื›ืชื‘ืชื™ ื‘ืื—ื“ ื”ืงื•ื“ืžื™ื ืžืืžืจื™ื ื‘ืžื—ื–ื•ืจ ื”ื–ื”, ื›ืžืขื˜ ื›ืœ ืกื˜ื•ื“ื ื˜ ืฉืœืžื“ (ื•ืœืžื“) ืฉื ื™ ืกืžืกื˜ืจื™ื ืฉืœ ืงื•ืจืก ื˜ืœืงื•ื ื™ื›ื•ืœ ืœืขืฆื‘ ื•ืœื”ื’ื“ื™ืจ ืจืฉืช ืžืฉืจื“ื™ืช ื›ืš ืฉื”ื™ื "ืื™ื›ืฉื”ื• ืขื•ื‘ื“ืช".

ืื‘ืœ ื›ื›ืœ ืฉืœื•ืžื“ื™ื ื™ื•ืชืจ, ื”ืžืฉื™ืžื” ื”ื–ื• ืžืชื—ื™ืœื” ืœื”ื™ืจืื•ืช ืคื—ื•ืช ืคืฉื•ื˜ื”. ืœื™ ืื™ืฉื™ืช ื”ื ื•ืฉื ื”ื–ื”, ื ื•ืฉื ืขื™ืฆื•ื‘ ืจืฉืชื•ืช ืžืฉืจื“ื™ื•ืช, ื ืจืื” ืœื ืคืฉื•ื˜ ื‘ื›ืœืœ ื•ื‘ืžืืžืจ ื–ื” ืื ืกื” ืœื”ืกื‘ื™ืจ ืžื“ื•ืข.

ื‘ืงื™ืฆื•ืจ, ื™ืฉ ืœื ืžืขื˜ ื’ื•ืจืžื™ื ืฉืฆืจื™ืš ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ. ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื’ื•ืจืžื™ื ืืœื• ืžืชื ื’ืฉื™ื ื–ื” ืขื ื–ื” ื•ื™ืฉ ืœื—ืคืฉ ืคืฉืจื” ืกื‘ื™ืจื”.
ื—ื•ืกืจ ื”ื•ื•ื“ืื•ืช ื”ื–ื” ื”ื•ื ื”ืงื•ืฉื™ ื”ืขื™ืงืจื™. ืื– ืื ื›ื‘ืจ ืžื“ื‘ืจื™ื ืขืœ ืื‘ื˜ื—ื”, ื™ืฉ ืœื ื• ืžืฉื•ืœืฉ ืขื ืฉืœื•ืฉื” ืงื•ื“ืงื•ื“ื™ื: ืื‘ื˜ื—ื”, ื ื•ื—ื•ืช ืœืขื•ื‘ื“ื™ื, ืžื—ื™ืจ ื”ืคืชืจื•ืŸ.
ื•ื‘ื›ืœ ืคืขื ืฆืจื™ืš ืœื—ืคืฉ ืคืฉืจื” ื‘ื™ืŸ ืฉืœื•ืฉืช ืืœื•.

ืื“ืจื™ื›ืœื•ืช

ื›ื“ื•ื’ืžื” ืœืืจื›ื™ื˜ืงื˜ื•ืจื” ืœืฉื ื™ ื”ืงื˜ืขื™ื ื”ืœืœื•, ื›ืžื• ื‘ืžืืžืจื™ื ืงื•ื“ืžื™ื, ืื ื™ ืžืžืœื™ืฅ ืกื™ืกืงื• SAFE ื“ึถื’ึถื: ืงืžืคื•ืก ืืจื’ื•ื ื™, Enterprise Internet Edge.

ืžื“ื•ื‘ืจ ื‘ืžืกืžื›ื™ื ืžืขื˜ ืžื™ื•ืฉื ื™ื. ืื ื™ ืžืฆื™ื’ ืื•ืชื ื›ืืŸ ืžื›ื™ื•ื•ืŸ ืฉื”ืกื›ืžื•ืช ื•ื”ื’ื™ืฉื” ื”ื‘ืกื™ืกื™ื•ืช ืœื ื”ืฉืชื ื•, ืื‘ืœ ื™ื—ื“ ืขื ื–ืืช ืื ื™ ืื•ื”ื‘ ืืช ื”ืžืฆื’ืช ื™ื•ืชืจ ืžืืฉืจ ื‘ื” ืชื™ืขื•ื“ ื—ื“ืฉ.

ืžื‘ืœื™ ืœืขื•ื“ื“ ืื•ืชืš ืœื”ืฉืชืžืฉ ื‘ืคืชืจื•ื ื•ืช ืฉืœ ืกื™ืกืงื•, ืื ื™ ืขื“ื™ื™ืŸ ื—ื•ืฉื‘ ืฉืžื•ืขื™ืœ ืœืœืžื•ื“ ื”ื™ื˜ื‘ ืืช ื”ืขื™ืฆื•ื‘ ื”ื–ื”.

ืžืืžืจ ื–ื”, ื›ืจื’ื™ืœ, ืื™ื ื• ืžืชื™ื™ืžืจ ื‘ืฉื•ื ืื•ืคืŸ ืœื”ื™ื•ืช ืฉืœื, ืืœื ืžื”ื•ื•ื” ืชื•ืกืคืช ืœืžื™ื“ืข ื–ื”.

ื‘ืกื•ืฃ ื”ืžืืžืจ, ื ื ืชื— ืืช ืขื™ืฆื•ื‘ ื”ืžืฉืจื“ ืฉืœ Cisco SAFE ื‘ืžื•ื ื—ื™ื ืฉืœ ื”ืžื•ืฉื’ื™ื ื”ืžืคื•ืจื˜ื™ื ื›ืืŸ.

ืขืงืจื•ื ื•ืช ื›ืœืœื™ื™ื

ืขื™ืฆื•ื‘ ืจืฉืช ื”ืžืฉืจื“ื™ื ื—ื™ื™ื‘ ื›ืžื•ื‘ืŸ ืœืขืžื•ื“ ื‘ื“ืจื™ืฉื•ืช ื”ื›ืœืœื™ื•ืช ืฉื ื“ื•ื ื• ื›ืืŸ ื‘ืคืจืง "ืงืจื™ื˜ืจื™ื•ื ื™ื ืœื”ืขืจื›ืช ืื™ื›ื•ืช ื”ืชื›ื ื•ืŸ". ืžืœื‘ื“ ื”ืžื—ื™ืจ ื•ื”ื‘ื˜ื™ื—ื•ืช, ืขืœื™ื”ื ืื ื• ืžืชื›ื•ื•ื ื™ื ืœื“ื•ืŸ ื‘ืžืืžืจ ื–ื”, ื™ืฉื ื ืขื“ื™ื™ืŸ ืฉืœื•ืฉื” ืงืจื™ื˜ืจื™ื•ื ื™ื ืฉืขืœื™ื ื• ืœืฉืงื•ืœ ื‘ืขืช ืชื›ื ื•ืŸ (ืื• ื‘ื™ืฆื•ืข ืฉื™ื ื•ื™ื™ื):

  • ืžื“ืจื’ื™ื•ืช
  • ืงืœื•ืช ืฉื™ืžื•ืฉ (ื ื™ืชื ื•ืช ืœื ื™ื”ื•ืœ)
  • ื–ืžื™ื ื•ืช

ื”ืจื‘ื” ืžืžื” ืฉื“ื ื• ื‘ืขื‘ื•ืจื• ืžืจื›ื–ื™ ื ืชื•ื ื™ื ื–ื” ื ื›ื•ืŸ ื’ื ืœื’ื‘ื™ ื”ืžืฉืจื“.

ืื‘ืœ ืขื“ื™ื™ืŸ, ืœืžื’ื–ืจ ื”ืžืฉืจื“ื™ื ื™ืฉ ืืช ื”ืคืจื˜ื™ื ืฉืœื•, ืฉื”ื ืงืจื™ื˜ื™ื™ื ืžื ืงื•ื“ืช ืžื‘ื˜ ืื‘ื˜ื—ื”. ื”ืžื”ื•ืช ืฉืœ ื”ืกืคืฆื™ืคื™ื•ืช ื”ื–ื• ื”ื™ื ืฉื”ืžื’ื–ืจ ื”ื–ื” ื ื•ืฆืจ ื›ื“ื™ ืœืกืคืง ืฉื™ืจื•ืชื™ ืจืฉืช ืœืขื•ื‘ื“ื™ื (ื›ืžื• ื’ื ืœืฉื•ืชืคื™ื ื•ืื•ืจื—ื™ื) ืฉืœ ื”ื—ื‘ืจื”, ื•ื›ืชื•ืฆืื” ืžื›ืš, ื‘ืจืžืช ื”ื”ืชื—ืฉื‘ื•ืช ื”ื’ื‘ื•ื”ื” ื‘ื™ื•ืชืจ ืฉืœ ื”ื‘ืขื™ื” ื™ืฉ ืœื ื• ืฉืชื™ ืžืฉื™ืžื•ืช:

  • ืœื”ื’ืŸ ืขืœ ืžืฉืื‘ื™ ื”ื—ื‘ืจื” ืžืคื ื™ ืคืขื•ืœื•ืช ื–ื“ื•ื ื™ื•ืช ืฉืขืœื•ืœื•ืช ืœื”ื’ื™ืข ืžืขื•ื‘ื“ื™ื (ืื•ืจื—ื™ื, ืฉื•ืชืคื™ื) ื•ืžื”ืชื•ื›ื ื” ืฉื‘ื” ื”ื ืžืฉืชืžืฉื™ื. ื–ื” ื›ื•ืœืœ ื’ื ื”ื’ื ื” ืžืคื ื™ ื—ื™ื‘ื•ืจ ืœื ืžื•ืจืฉื” ืœืจืฉืช.
  • ืœื”ื’ืŸ ืขืœ ืžืขืจื›ื•ืช ื•ื ืชื•ื ื™ ืžืฉืชืžืฉ

ื•ื–ื” ืจืง ืฆื“ ืื—ื“ ืฉืœ ื”ื‘ืขื™ื” (ืื• ืœื™ืชืจ ื“ื™ื•ืง, ืงื•ื“ืงื•ื“ ืื—ื“ ืฉืœ ื”ืžืฉื•ืœืฉ). ืžื”ืฆื“ ื”ืฉื ื™ ืขื•ืžื“ืช ื ื•ื—ื•ืช ื”ืžืฉืชืžืฉ ื•ืžื—ื™ืจ ื”ืคืชืจื•ื ื•ืช ื‘ื”ื ื ืขืฉื” ืฉื™ืžื•ืฉ.

ื ืชื—ื™ืœ ื‘ื‘ื—ื™ื ื” ืœืžื” ื”ืžืฉืชืžืฉ ืžืฆืคื” ืžืจืฉืช ืžืฉืจื“ื™ื ืžื•ื“ืจื ื™ืช.

ืฆื™ื•ื“

ื›ืš ื ืจืื™ื "ืฉื™ืจื•ืชื™ ืจืฉืช" ืขื‘ื•ืจ ืžืฉืชืžืฉ ืžืฉืจื“ื™ ืœื“ืขืชื™:

  • ื ื™ื™ื“ื•ืช
  • ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ื›ืœ ืžื’ื•ื•ืŸ ื”ืžื›ืฉื™ืจื™ื ื•ืžืขืจื›ื•ืช ื”ื”ืคืขืœื” ื”ืžื•ื›ืจื•ืช
  • ื’ื™ืฉื” ื ื•ื—ื” ืœื›ืœ ืžืฉืื‘ื™ ื”ื—ื‘ืจื” ื”ื“ืจื•ืฉื™ื
  • ื–ืžื™ื ื•ืช ืžืฉืื‘ื™ ืื™ื ื˜ืจื ื˜, ืœืจื‘ื•ืช ืฉื™ืจื•ืชื™ ืขื ืŸ ืฉื•ื ื™ื
  • "ื”ืคืขืœื” ืžื”ื™ืจื”" ืฉืœ ื”ืจืฉืช

ื›ืœ ื–ื” ืชืงืฃ ื”ืŸ ืœืขื•ื‘ื“ื™ื ื•ื”ืŸ ืœืื•ืจื—ื™ื (ืื• ืฉื•ืชืคื™ื), ื•ืžืฉื™ืžืชื ืฉืœ ืžื”ื ื“ืกื™ ื”ื—ื‘ืจื” ืœื”ื‘ื“ื™ืœ ื‘ื™ืŸ ื’ื™ืฉื” ืœืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื ืฉื•ื ื•ืช ืขืœ ื‘ืกื™ืก ื”ืจืฉืื”.

ื”ื‘ื” ื ืกืชื›ืœ ืขืœ ื›ืœ ืื—ื“ ืžื”ื”ื™ื‘ื˜ื™ื ื”ืœืœื• ื‘ืคื™ืจื•ื˜ ืงื˜ืŸ ื™ื•ืชืจ.

ื ื™ื™ื“ื•ืช

ืื ื—ื ื• ืžื“ื‘ืจื™ื ืขืœ ื”ื”ื–ื“ืžื ื•ืช ืœืขื‘ื•ื“ ื•ืœื”ืฉืชืžืฉ ื‘ื›ืœ ืžืฉืื‘ื™ ื”ื—ื‘ืจื” ื”ื“ืจื•ืฉื™ื ืžื›ืœ ืžืงื•ื ื‘ืขื•ืœื (ื›ืžื•ื‘ืŸ, ื”ื™ื›ืŸ ืฉื”ืื™ื ื˜ืจื ื˜ ื–ืžื™ืŸ).

ื–ื” ื—ืœ ื‘ืžืœื•ืื• ืขืœ ื”ืžืฉืจื“. ื–ื” ื ื•ื— ื›ืืฉืจ ื™ืฉ ืœืš ืืคืฉืจื•ืช ืœื”ืžืฉื™ืš ืœืขื‘ื•ื“ ืžื›ืœ ืžืงื•ื ื‘ืžืฉืจื“, ืœืžืฉืœ, ืœืงื‘ืœ ื“ื•ืืจ, ืœืชืงืฉืจ ื‘ืžืกื ื’'ืจ ืืจื’ื•ื ื™, ืœื”ื™ื•ืช ื–ืžื™ืŸ ืœืฉื™ื—ืช ื•ื™ื“ืื•,... ื›ืš, ื–ื” ืžืืคืฉืจ ืœืš, ืžืฆื“ ืื—ื“, ืœืคืชื•ืจ ื›ืžื” ื‘ืขื™ื•ืช ื‘ืชืงืฉื•ืจืช "ื—ื™ื”" (ืœืžืฉืœ, ืœื”ืฉืชืชืฃ ื‘ืขืฆืจื•ืช), ื•ืžืฆื“ ืฉื ื™, ืœื”ื™ื•ืช ืชืžื™ื“ ืžืงื•ื•ืŸ, ืœื”ื—ื–ื™ืง ืืช ื”ืืฆื‘ืข ืขืœ ื”ื“ื•ืคืง ื•ืœืคืชื•ืจ ื‘ืžื”ื™ืจื•ืช ื›ืžื” ืžืฉื™ืžื•ืช ื“ื—ื•ืคื•ืช ื‘ืขื“ื™ืคื•ืช ื’ื‘ื•ื”ื”. ื–ื” ืžืื•ื“ ื ื•ื— ื•ื‘ืืžืช ืžืฉืคืจ ืืช ืื™ื›ื•ืช ื”ืชืงืฉื•ืจืช.

ื–ื” ืžื•ืฉื’ ืขืœ ื™ื“ื™ ืขื™ืฆื•ื‘ ื ื›ื•ืŸ ืฉืœ ืจืฉืช WiFi.

ื”ืขืจื”:

ื›ืืŸ ื‘ื“ืจืš ื›ืœืœ ืขื•ืœื” ื”ืฉืืœื”: ื”ืื ืžืกืคื™ืง ืœื”ืฉืชืžืฉ ืจืง ื‘-WiFi? ื”ืื ื–ื” ืื•ืžืจ ืฉืืชื” ื™ื›ื•ืœ ืœื”ืคืกื™ืง ืœื”ืฉืชืžืฉ ื‘ื™ืฆื™ืื•ืช Ethernet ื‘ืžืฉืจื“? ืื ืื ื—ื ื• ืžื“ื‘ืจื™ื ืจืง ืขืœ ืžืฉืชืžืฉื™ื, ื•ืœื ืขืœ ืฉืจืชื™ื, ืฉืขื“ื™ื™ืŸ ืกื‘ื™ืจ ืœื”ืชื—ื‘ืจ ืขื ื™ืฆื™ืืช Ethernet ืจื’ื™ืœื”, ืื– ื‘ืื•ืคืŸ ื›ืœืœื™ ื”ืชืฉื•ื‘ื” ื”ื™ื: ื›ืŸ, ืืชื” ื™ื›ื•ืœ ืœื”ื’ื‘ื™ืœ ืืช ืขืฆืžืš ืœ-WiFi ื‘ืœื‘ื“. ืื‘ืœ ื™ืฉ ื ื™ื•ืื ืกื™ื.

ื™ืฉื ืŸ ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื ื—ืฉื•ื‘ื•ืช ื”ื“ื•ืจืฉื•ืช ื’ื™ืฉื” ื ืคืจื“ืช. ืืœื• ื”ื, ื›ืžื•ื‘ืŸ, ืžื ื”ืœื™ื. ื‘ืื•ืคืŸ ืขืงืจื•ื ื™, ื—ื™ื‘ื•ืจ WiFi ืคื—ื•ืช ืืžื™ืŸ (ืžื‘ื—ื™ื ืช ืื•ื‘ื“ืŸ ืชืขื‘ื•ืจื”) ื•ืื™ื˜ื™ ื™ื•ืชืจ ืžื™ืฆื™ืืช Ethernet ืจื’ื™ืœื”. ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžืฉืžืขื•ืชื™ ืขื‘ื•ืจ ืžื ื”ืœื™ ืžืขืจื›ืช. ื‘ื ื•ืกืฃ, ืžื ื”ืœื™ ืจืฉืช, ืœืžืฉืœ, ื™ื›ื•ืœื™ื, ื‘ืื•ืคืŸ ืขืงืจื•ื ื™, ืœื”ื—ื–ื™ืง ื‘ืจืฉืช Ethernet ื™ื™ืขื•ื“ื™ืช ืžืฉืœื”ื ืœื—ื™ื‘ื•ืจื™ื ืžื—ื•ืฅ ืœืคืก.

ื™ื™ืชื›ื ื• ืงื‘ื•ืฆื•ืช/ืžื—ืœืงื•ืช ื ื•ืกืคื•ืช ื‘ื—ื‘ืจื” ืฉืœืš ืฉื’ื ื”ื’ื•ืจืžื™ื ื”ืœืœื• ื—ืฉื•ื‘ื™ื ืœื”ืŸ.

ื™ืฉ ืขื•ื“ ื ืงื•ื“ื” ื—ืฉื•ื‘ื” - ื˜ืœืคื•ื ื™ื”. ืื•ืœื™ ืžืกื™ื‘ื” ื›ืœืฉื”ื™ ืื™ื ืš ืจื•ืฆื” ืœื”ืฉืชืžืฉ ื‘-VoIP ืืœื—ื•ื˜ื™ ื•ืจื•ืฆื” ืœื”ืฉืชืžืฉ ื‘ื˜ืœืคื•ื ื™ื IP ืขื ื—ื™ื‘ื•ืจ Ethernet ืจื’ื™ืœ.

ื‘ืื•ืคืŸ ื›ืœืœื™, ืœื—ื‘ืจื•ืช ืฉืขื‘ื“ืชื™ ื‘ื”ืŸ ื”ื™ื• ื‘ื“ืจืš ื›ืœืœ ื’ื ืงื™ืฉื•ืจื™ื•ืช WiFi ื•ื’ื ื™ืฆื™ืืช Ethernet.

ื”ื™ื™ืชื™ ืจื•ืฆื” ืฉื”ื ื™ื™ื“ื•ืช ืœื ืชื•ื’ื‘ืœ ืจืง ืœืžืฉืจื“.

ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืืช ื”ื™ื›ื•ืœืช ืœืขื‘ื•ื“ ืžื”ื‘ื™ืช (ืื• ื›ืœ ืžืงื•ื ืื—ืจ ืขื ืื™ื ื˜ืจื ื˜ ื ื’ื™ืฉ), ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื—ื™ื‘ื•ืจ VPN. ื™ื—ื“ ืขื ื–ืืช, ืจืฆื•ื™ ืฉื”ืขื•ื‘ื“ื™ื ืœื ื™ืจื’ื™ืฉื• ื‘ื”ื‘ื“ืœ ื‘ื™ืŸ ืขื‘ื•ื“ื” ืžื”ื‘ื™ืช ืœืขื‘ื•ื“ื” ืžืจื—ื•ืง, ื”ืžื ื™ื—ื” ืืช ืื•ืชื” ื’ื™ืฉื”. ื ื“ื•ืŸ ื›ื™ืฆื“ ืœืืจื’ืŸ ื–ืืช ืžืขื˜ ืžืื•ื—ืจ ื™ื•ืชืจ ื‘ืคืจืง "ืžืขืจื›ืช ืื™ืžื•ืช ื•ื”ืจืฉืื” ืžืื•ื—ื“ืช ืžืื•ื—ื“ืช."

ื”ืขืจื”:

ืกื‘ื™ืจ ืœื”ื ื™ื— ืฉืœื ืชื•ื›ืœ ืœืกืคืง ื‘ืื•ืคืŸ ืžืœื ืืช ืื•ืชื” ืื™ื›ื•ืช ืฉื™ืจื•ืชื™ื ืœืขื‘ื•ื“ื” ืžืจื—ื•ืง ืฉื™ืฉ ืœืš ื‘ืžืฉืจื“. ื‘ื•ื ื ื ื™ื— ืฉืืชื” ืžืฉืชืžืฉ ื‘-Cisco ASA 5520 ื›ืฉืขืจ ื”-VPN ืฉืœืš. ื˜ื•ืคืก ืžื™ื“ืข ื”ืžื›ืฉื™ืจ ื”ื–ื” ืžืกื•ื’ืœ "ืœืขื›ืœ" ืจืง 225 Mbit ืฉืœ ืชืขื‘ื•ืจืช VPN. ื›ืœื•ืžืจ, ื›ืžื•ื‘ืŸ, ืžื‘ื—ื™ื ืช ืจื•ื—ื‘ ืคืก, ื—ื™ื‘ื•ืจ ื“ืจืš VPN ืฉื•ื ื” ืžืื•ื“ ืžืขื‘ื•ื“ื” ืžื”ืžืฉืจื“. ื›ืžื• ื›ืŸ, ืื, ืžืกื™ื‘ื” ื›ืœืฉื”ื™, ื—ื‘ื™ื•ืŸ, ืื•ื‘ื“ืŸ, ืจื™ืฆื•ื“ (ืœืžืฉืœ, ืืชื” ืจื•ืฆื” ืœื”ืฉืชืžืฉ ื‘ื˜ืœืคื•ื ื™ื” IP ืžืฉืจื“ื™ืช) ืขื‘ื•ืจ ืฉื™ืจื•ืชื™ ื”ืจืฉืช ืฉืœืš ื”ื ืžืฉืžืขื•ืชื™ื™ื, ืืชื” ื’ื ืœื ืชืงื‘ืœ ืืช ืื•ืชื” ืื™ื›ื•ืช ื›ืื™ืœื• ื”ื™ื™ืช ื‘ืžืฉืจื“. ืœื›ืŸ, ื›ืฉืžื“ื‘ืจื™ื ืขืœ ื ื™ื™ื“ื•ืช, ืขืœื™ื ื• ืœื”ื™ื•ืช ืžื•ื“ืขื™ื ืœืžื’ื‘ืœื•ืช ืืคืฉืจื™ื•ืช.

ื’ื™ืฉื” ื ื•ื—ื” ืœื›ืœ ืžืฉืื‘ื™ ื”ื—ื‘ืจื”

ืžืฉื™ืžื” ื–ื• ืฆืจื™ื›ื” ืœื”ื™ืคืชืจ ื‘ืžืฉื•ืชืฃ ืขื ืžื—ืœืงื•ืช ื˜ื›ื ื™ื•ืช ืื—ืจื•ืช.
ื”ืžืฆื‘ ื”ืื™ื“ื™ืืœื™ ื”ื•ื ื›ืืฉืจ ื”ืžืฉืชืžืฉ ืฆืจื™ืš ืœื‘ืฆืข ืื™ืžื•ืช ืคืขื ืื—ืช ื‘ืœื‘ื“, ื•ืœืื—ืจ ืžื›ืŸ ื™ืฉ ืœื• ื’ื™ืฉื” ืœื›ืœ ื”ืžืฉืื‘ื™ื ื”ื“ืจื•ืฉื™ื.
ืžืชืŸ ื’ื™ืฉื” ืงืœื” ืžื‘ืœื™ ืœื”ืงืจื™ื‘ ืืช ื”ืื‘ื˜ื—ื” ื™ื›ื•ืœ ืœืฉืคืจ ืžืฉืžืขื•ืชื™ืช ืืช ื”ืคืจื•ื“ื•ืงื˜ื™ื‘ื™ื•ืช ื•ืœื”ืคื—ื™ืช ืืช ื”ืœื—ืฅ ื‘ืงืจื‘ ืขืžื™ืชื™ืš.

ื”ืขืจื” 1

ืงืœื•ืช ื”ื’ื™ืฉื” ื”ื™ื ืœื ืจืง ื›ืžื” ืคืขืžื™ื ืืชื” ืฆืจื™ืš ืœื”ื–ื™ืŸ ืกื™ืกืžื”. ืื, ืœืžืฉืœ, ื‘ื”ืชืื ืœืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื” ืฉืœืš, ื›ื“ื™ ืœื”ืชื—ื‘ืจ ืžื”ืžืฉืจื“ ืœืžืจื›ื– ื”ื ืชื•ื ื™ื, ืขืœื™ืš ืœื”ืชื—ื‘ืจ ืชื—ื™ืœื” ืœืฉืขืจ ื”-VPN, ื•ื‘ืžืงื‘ื™ืœ ืชืื‘ื“ ืืช ื”ื’ื™ืฉื” ืœืžืฉืื‘ื™ ื”ืžืฉืจื“, ืื– ื–ื” ื’ื ืžืื•ื“ , ืžืื•ื“ ืœื ื ื•ื—.

ื”ืขืจื” 2

ื™ืฉื ื ืฉื™ืจื•ืชื™ื (ืœืžืฉืœ, ื’ื™ืฉื” ืœืฆื™ื•ื“ ืจืฉืช) ื‘ื”ื ื™ืฉ ืœื ื• ืœืจื•ื‘ ืฉืจืชื™ AAA ื™ื™ืขื•ื“ื™ื™ื ืžืฉืœื ื• ื•ื–ื• ื”ื ื•ืจืžื” ื›ืืฉืจ ื‘ืžืงืจื” ื–ื” ืขืœื™ื ื• ืœื‘ืฆืข ืื™ืžื•ืช ืžืกืคืจ ืคืขืžื™ื.

ื–ืžื™ื ื•ืช ืžืฉืื‘ื™ ืื™ื ื˜ืจื ื˜

ื”ืื™ื ื˜ืจื ื˜ ื”ื•ื ืœื ืจืง ื‘ื™ื“ื•ืจ, ืืœื ื’ื ืื•ืกืฃ ืฉืœ ืฉื™ืจื•ืชื™ื ืฉื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ื™ื ืžืื•ื“ ืœืขื‘ื•ื“ื”. ื™ืฉ ื’ื ื’ื•ืจืžื™ื ืคืกื™ื›ื•ืœื•ื’ื™ื™ื ื’ืจื™ื“ื. ืื“ื ืžื•ื“ืจื ื™ ืžื—ื•ื‘ืจ ืขื ืื ืฉื™ื ืื—ืจื™ื ื“ืจืš ื”ืื™ื ื˜ืจื ื˜ ื“ืจืš ืฉืจืฉื•ืจื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื ืจื‘ื™ื, ื•ืœื“ืขืชื™ ืื™ืŸ ืฉื•ื ื“ื‘ืจ ืจืข ืื ื”ื•ื ื™ืžืฉื™ืš ืœื”ืจื’ื™ืฉ ืืช ื”ืงืฉืจ ื”ื–ื” ื’ื ื‘ื–ืžืŸ ื”ืขื‘ื•ื“ื”.

ืžื ืงื•ื“ืช ืžื‘ื˜ ืฉืœ ื‘ื–ื‘ื•ื– ื–ืžืŸ, ืื™ืŸ ืฉื•ื ื“ื‘ืจ ืจืข ืื ืœืขื•ื‘ื“, ืœืžืฉืœ, ื™ืฉ ืกืงื™ื™ืค ืคื•ืขืœ ื•ืžืงื“ื™ืฉ 5 ื“ืงื•ืช ืœืชืงืฉื•ืจืช ืขื ืื“ื ืื”ื•ื‘ ื‘ืžื™ื“ืช ื”ืฆื•ืจืš.

ื”ืื ื–ื” ืื•ืžืจ ืฉื”ืื™ื ื˜ืจื ื˜ ืฆืจื™ืš ืœื”ื™ื•ืช ื–ืžื™ืŸ ืชืžื™ื“, ื”ืื ื–ื” ืื•ืžืจ ืฉื”ืขื•ื‘ื“ื™ื ื™ื›ื•ืœื™ื ืœืงื‘ืœ ื’ื™ืฉื” ืœื›ืœ ื”ืžืฉืื‘ื™ื ื•ืœื ืœืฉืœื•ื˜ ื‘ื”ื ื‘ืฉื•ื ืฆื•ืจื”?

ืœื ืœื ืื•ืžืจ ืืช ื–ื”, ื›ืžื•ื‘ืŸ. ืจืžืช ื”ืคืชื™ื—ื•ืช ืฉืœ ื”ืื™ื ื˜ืจื ื˜ ื™ื›ื•ืœื” ืœื”ืฉืชื ื•ืช ืขื‘ื•ืจ ื—ื‘ืจื•ืช ืฉื•ื ื•ืช โ€“ ืžืกื’ื™ืจื” ืžื•ื—ืœื˜ืช ื•ืขื“ ืœืคืชื™ื—ื•ืช ืžื•ื—ืœื˜ืช. ื ื“ื•ืŸ ื‘ื“ืจื›ื™ื ืœืฉืœื™ื˜ื” ื‘ืชื ื•ืขื” ื‘ื”ืžืฉืš ื”ืกืขื™ืคื™ื ืขืœ ืืžืฆืขื™ ืื‘ื˜ื—ื”.

ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ื›ืœ ืžื’ื•ื•ืŸ ื”ืžื›ืฉื™ืจื™ื ื”ืžื•ื›ืจื™ื

ื–ื” ื ื•ื— ื›ืืฉืจ, ืœืžืฉืœ, ื™ืฉ ืœืš ื”ื–ื“ืžื ื•ืช ืœื”ืžืฉื™ืš ืœื”ืฉืชืžืฉ ื‘ื›ืœ ืืžืฆืขื™ ื”ืชืงืฉื•ืจืช ืฉืืชื” ืจื’ื™ืœ ืืœื™ื”ื ื‘ืขื‘ื•ื“ื”. ืื™ืŸ ืงื•ืฉื™ ืœื™ื™ืฉื ืืช ื–ื” ื˜ื›ื ื™ืช. ื‘ืฉื‘ื™ืœ ื–ื” ืืชื” ืฆืจื™ืš WiFi ื•ื•ื•ื™ืœืืŸ ืื•ืจื—.

ื–ื” ื’ื ื˜ื•ื‘ ืื ื™ืฉ ืœืš ื”ื–ื“ืžื ื•ืช ืœื”ืฉืชืžืฉ ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื” ืฉืืชื” ืจื’ื™ืœ ืืœื™ื”. ืื‘ืœ, ืœื”ืขืจื›ืชื™, ื–ื” ื‘ื“ืจืš ื›ืœืœ ืžื•ืชืจ ืจืง ืœืžื ื”ืœื™ื, ืœืžื ื”ืœื™ื ื•ืœืžืคืชื—ื™ื.

ื“ื•ื’ืžื”

ืืคืฉืจ ื›ืžื•ื‘ืŸ ืœืœื›ืช ื‘ื“ืจืš ื”ืื™ืกื•ืจื™ื, ืœืืกื•ืจ ื’ื™ืฉื” ืžืจื—ื•ืง, ืœืืกื•ืจ ื—ื™ื‘ื•ืจ ืžืžื›ืฉื™ืจื™ื ื ื™ื™ื“ื™ื, ืœื”ื’ื‘ื™ืœ ื”ื›ืœ ืœื—ื™ื‘ื•ืจื™ ืืชืจื ื˜ ืกื˜ื˜ื™ื™ื, ืœื”ื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜, ืœื”ื—ืจื™ื ื‘ื—ื•ื‘ื” ื˜ืœืคื•ื ื™ื ืกืœื•ืœืจื™ื™ื ื•ื’ืื“ื’'ื˜ื™ื ื‘ืžื—ืกื•ื... ื•ื”ื ืชื™ื‘ ื”ื–ื” ืœืžืขืฉื” ืขื•ืงื‘ื™ื ืื—ืจื™ ื›ืžื” ืืจื’ื•ื ื™ื ืขื ื“ืจื™ืฉื•ืช ืื‘ื˜ื—ื” ืžื•ื’ื‘ืจื•ืช, ื•ืื•ืœื™ ื‘ืžืงืจื™ื ืžืกื•ื™ืžื™ื ื–ื” ืขืฉื•ื™ ืœื”ื™ื•ืช ืžื•ืฆื“ืง, ืื‘ืœ... ืืชื ื—ื™ื™ื‘ื™ื ืœื”ืกื›ื™ื ืฉื–ื” ื ืจืื” ื›ืžื• ื ื™ืกื™ื•ืŸ ืœืขืฆื•ืจ ื”ืชืงื“ืžื•ืช ื‘ืืจื’ื•ืŸ ื‘ื•ื“ื“. ื›ืžื•ื‘ืŸ, ืื ื™ ืจื•ืฆื” ืœืฉืœื‘ ืืช ื”ื”ื–ื“ืžื ื•ื™ื•ืช ืฉื”ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื”ืžื•ื“ืจื ื™ื•ืช ืžืกืคืงื•ืช ืขื ืจืžืช ืื‘ื˜ื—ื” ืžืกืคืงืช.

"ื”ืคืขืœื” ืžื”ื™ืจื”" ืฉืœ ื”ืจืฉืช

ืžื”ื™ืจื•ืช ื”ืขื‘ืจืช ื”ื ืชื•ื ื™ื ืžื•ืจื›ื‘ืช ืžื‘ื—ื™ื ื” ื˜ื›ื ื™ืช ืžื’ื•ืจืžื™ื ืจื‘ื™ื. ื•ืžื”ื™ืจื•ืช ื™ืฆื™ืืช ื”ื—ื™ื‘ื•ืจ ืฉืœืš ื”ื™ื ื‘ื“ืจืš ื›ืœืœ ืœื ื”ื—ืฉื•ื‘ื” ื‘ื™ื•ืชืจ. ืคืขื•ืœื” ืื™ื˜ื™ืช ืฉืœ ืืคืœื™ืงืฆื™ื” ืœื ืชืžื™ื“ ืงืฉื•ืจื” ืœื‘ืขื™ื•ืช ืจืฉืช, ืื‘ืœ ื‘ื™ื ืชื™ื™ื ืื ื—ื ื• ืžืชืขื ื™ื™ื ื™ื ืจืง ื‘ื—ืœืง ื”ืจืฉืช. ื”ื‘ืขื™ื” ื”ื ืคื•ืฆื” ื‘ื™ื•ืชืจ ืขื "ื”ืื˜ื”" ื‘ืจืฉืช ืžืงื•ืžื™ืช ืงืฉื•ืจื” ืœืื•ื‘ื“ืŸ ืžื ื•ืช. ื–ื” ืžืชืจื—ืฉ ื‘ื“ืจืš ื›ืœืœ ื›ืืฉืจ ื™ืฉ ืฆื•ื•ืืจ ื‘ืงื‘ื•ืง ืื• ื‘ืขื™ื•ืช L1 (OSI). ืœืขืชื™ื ืจื—ื•ืงื•ืช ื™ื•ืชืจ, ืขื ืขื™ืฆื•ื‘ื™ื ืžืกื•ื™ืžื™ื (ืœื“ื•ื’ืžื”, ื›ืืฉืจ ืœืจืฉืชื•ืช ื”ืžืฉื ื” ืฉืœืš ื™ืฉ ื—ื•ืžืช ืืฉ ื›ืฉืขืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื•ืœื›ืŸ ื›ืœ ื”ืชืขื‘ื•ืจื” ืขื•ื‘ืจืช ื“ืจื›ื•), ื™ืชื›ืŸ ืฉื‘ื™ืฆื•ืขื™ ื”ื—ื•ืžืจื” ื—ืกืจื™ื.

ืœื›ืŸ, ื‘ืขืช ื‘ื—ื™ืจืช ืฆื™ื•ื“ ื•ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืขืœื™ืš ืœืชืื ืืช ื”ืžื”ื™ืจื•ื™ื•ืช ืฉืœ ื™ืฆื™ืื•ืช ื”ืงืฆื”, ืชื ื”ืžื˜ืขืŸ ื•ื‘ื™ืฆื•ืขื™ ื”ืฆื™ื•ื“.

ื“ื•ื’ืžื”

ื ื ื™ื— ืฉืืชื” ืžืฉืชืžืฉ ื‘ืžืชื’ื™ื ืขื ื™ืฆื™ืื•ืช ืฉืœ 1 ื’'ื™ื’ื”-ื‘ื™ื˜ ื›ืžืชื’ื™ ืฉื›ื‘ืช ื’ื™ืฉื”. ื”ื ืžื—ื•ื‘ืจื™ื ื–ื” ืœื–ื” ื‘ืืžืฆืขื•ืช Etherchannel 2 x 10 ื’ื™ื’ื”-ื‘ื™ื˜. ื›ืฉืขืจ ื‘ืจื™ืจืช ืžื—ื“ืœ, ืืชื” ืžืฉืชืžืฉ ื‘ื—ื•ืžืช ืืฉ ืขื ื™ืฆื™ืื•ืช ื’ื™ื’ื”-ื‘ื™ื˜, ื›ื“ื™ ืœื—ื‘ืจ ืื•ืชื” ืœืจืฉืช ื”ืžืฉืจื“ื™ืช L2 ืืชื” ืžืฉืชืžืฉ ื‘-2 ื™ืฆื™ืื•ืช ื’'ื™ื’ื”-ื‘ื™ื˜ ืžืฉื•ืœื‘ื•ืช ื‘-Etherchannel.

ืืจื›ื™ื˜ืงื˜ื•ืจื” ื–ื• ื ื•ื—ื” ืœืžื“ื™ ืžื ืงื•ื“ืช ืžื‘ื˜ ืคื•ื ืงืฆื™ื•ื ืœื™ืช, ื›ื™... ื›ืœ ื”ืชืขื‘ื•ืจื” ืขื•ื‘ืจืช ื“ืจืš ื—ื•ืžืช ื”ืืฉ, ื•ืืชื” ื™ื›ื•ืœ ืœื ื”ืœ ื‘ื ื•ื—ื•ืช ืžื“ื™ื ื™ื•ืช ื’ื™ืฉื”, ื•ืœื™ื™ืฉื ืืœื’ื•ืจื™ืชืžื™ื ืžื•ืจื›ื‘ื™ื ื›ื“ื™ ืœืฉืœื•ื˜ ื‘ืชืขื‘ื•ืจื” ื•ืœืžื ื•ืข ื”ืชืงืคื•ืช ืืคืฉืจื™ื•ืช (ืจืื” ืœื”ืœืŸ), ืื‘ืœ ืžื ืงื•ื“ืช ืžื‘ื˜ ืฉืœ ืชืคื•ืงื” ื•ื‘ื™ืฆื•ืขื™ื ืœืชื›ื ื•ืŸ ื”ื–ื”, ื›ืžื•ื‘ืŸ, ื™ืฉ ื‘ืขื™ื•ืช ืคื•ื˜ื ืฆื™ืืœื™ื•ืช. ื›ืš, ืœืžืฉืœ, 2 ืžืืจื—ื™ื ืžื•ืจื™ื“ื™ื ื ืชื•ื ื™ื (ืขื ืžื”ื™ืจื•ืช ื™ืฆื™ืื” ืฉืœ 1 ื’ื™ื’ื”-ื‘ื™ื˜) ื™ื›ื•ืœื™ื ืœื˜ืขื•ืŸ ืœื—ืœื•ื˜ื™ืŸ ื—ื™ื‘ื•ืจ ืฉืœ 2 ื’ื™ื’ื”-ื‘ื™ื˜ ืœื—ื•ืžืช ื”ืืฉ, ื•ื‘ื›ืš ืœื”ื•ื‘ื™ืœ ืœืคื’ื™ืขื” ื‘ืฉื™ืจื•ืช ืขื‘ื•ืจ ื›ืœ ืžืงื˜ืข ื”ืžืฉืจื“ื™ื.

ื”ืกืชื›ืœื ื• ืขืœ ืงื•ื“ืงื•ื“ ืื—ื“ ืฉืœ ื”ืžืฉื•ืœืฉ, ืขื›ืฉื™ื• ื‘ื•ืื• ื ืกืชื›ืœ ื›ื™ืฆื“ ื ื•ื›ืœ ืœื”ื‘ื˜ื™ื— ืื‘ื˜ื—ื”.

ืกืขื“ื™ื

ืื–, ื›ืžื•ื‘ืŸ, ื‘ื“ืจืš ื›ืœืœ ื”ืจืฆื•ืŸ ืฉืœื ื• (ืื• ื™ื•ืชืจ ื ื›ื•ืŸ, ื”ืจืฆื•ืŸ ืฉืœ ื”ื”ื ื”ืœื” ืฉืœื ื•) ื”ื•ื ืœื”ืฉื™ื’ ืืช ื”ื‘ืœืชื™ ืืคืฉืจื™, ื›ืœื•ืžืจ ืœืกืคืง ื ื•ื—ื•ืช ืžืงืกื™ืžืœื™ืช ืขื ืžืงืกื™ืžื•ื ืื‘ื˜ื—ื” ื•ืžื™ื ื™ืžื•ื ืขืœื•ืช.

ื”ื‘ื” ื ื‘ื—ืŸ ืื™ืœื• ืฉื™ื˜ื•ืช ื™ืฉ ืœื ื• ืœืกืคืง ื”ื’ื ื”.

ืขื‘ื•ืจ ื”ืžืฉืจื“, ืืฆื™ื™ืŸ ืืช ื”ื“ื‘ืจื™ื ื”ื‘ืื™ื:

  • ื’ื™ืฉืช ืืคืก ืืžื•ืŸ ืœืขื™ืฆื•ื‘
  • ืจืžืช ื”ื’ื ื” ื’ื‘ื•ื”ื”
  • ื ืจืื•ืช ืจืฉืช
  • ืžืขืจื›ืช ืื™ืžื•ืช ื•ื”ืจืฉืื” ืžืจื›ื–ื™ืช ืžืื•ื—ื“ืช
  • ื‘ื“ื™ืงืช ืžืืจื—

ืœืื—ืจ ืžื›ืŸ, ื ืชืขื›ื‘ ืžืขื˜ ื™ื•ืชืจ ืขืœ ื›ืœ ืื—ื“ ืžื”ื”ื™ื‘ื˜ื™ื ื”ืœืœื•.

ืืคืก ืืžื•ืŸ

ืขื•ืœื ื”-IT ืžืฉืชื ื” ืžื”ืจ ืžืื•ื“. ืจืง ื‘ืžื”ืœืš 10 ื”ืฉื ื™ื ื”ืื—ืจื•ื ื•ืช, ื”ื•ืคืขืชืŸ ืฉืœ ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื•ืžื•ืฆืจื™ื ื—ื“ืฉื™ื ื”ื•ื‘ื™ืœื” ืœืฉื™ื ื•ื™ ืžืฉืžืขื•ืชื™ ืฉืœ ืชืคื™ืกื•ืช ื”ืื‘ื˜ื—ื”. ืœืคื ื™ ืขืฉืจ ืฉื ื™ื, ืžื ืงื•ื“ืช ืžื‘ื˜ ืื‘ื˜ื—ื”, ืคื™ืœื—ื ื• ืืช ื”ืจืฉืช ืœืื–ื•ืจื™ ืืžื•ืŸ, dmz ื•ื—ื•ืกืจ ืืžื•ืŸ, ื•ื”ืฉืชืžืฉื ื• ื‘ืžื” ืฉื ืงืจื "ื”ื’ื ื” ื”ื™ืงืคื™ืช", ืฉื‘ื” ื”ื™ื• 2 ืงื•ื•ื™ ื”ื’ื ื”: ืื™ ืืžื•ืŸ -> dmz ื•-dmz -> ืืžื•ืŸ. ื›ืžื• ื›ืŸ, ื”ื”ื’ื ื” ื”ื™ื™ืชื” ืžื•ื’ื‘ืœืช ื‘ื“ืจืš ื›ืœืœ ืœืจืฉื™ืžื•ืช ื’ื™ืฉื” ื”ืžื‘ื•ืกืกื•ืช ืขืœ ื›ื•ืชืจื•ืช L3/L4 (OSI) (ื™ืฆื™ืื•ืช IP, TCP/UDP, ื“ื’ืœื™ TCP). ื›ืœ ืžื” ืฉืงืฉื•ืจ ืœืจืžื•ืช ื’ื‘ื•ื”ื•ืช ื™ื•ืชืจ, ื›ื•ืœืœ L7, ื”ื•ืฉืืจ ืœืžืขืจื›ืช ื”ื”ืคืขืœื” ื•ืœืžื•ืฆืจื™ ื”ืื‘ื˜ื—ื” ืฉื”ื•ืชืงื ื• ื‘ืžืืจื—ื™ ื”ืงืฆื”.

ื›ืขืช ื”ืžืฆื‘ ื”ืฉืชื ื” ื‘ืื•ืคืŸ ื“ืจืžื˜ื™. ืงื•ื ืกืคื˜ ืžื•ื“ืจื ื™ ืืคืก ืืžื•ืŸ ื ื•ื‘ืข ืžื›ืš ืฉื›ื‘ืจ ืื™ ืืคืฉืจ ืœื”ืชื™ื™ื—ืก ืœืžืขืจื›ื•ืช ืคื ื™ืžื™ื•ืช, ื›ืœื•ืžืจ ื›ืืœื• ืฉื ืžืฆืื•ืช ื‘ืชื•ืš ื”ื”ื™ืงืฃ, ื›ืืžื™ื ื•ืช, ื•ืžื•ืฉื’ ื”ื”ื™ืงืฃ ืขืฆืžื• ื”ื™ื˜ืฉื˜ืฉ.
ื‘ื ื•ืกืฃ ืœื—ื™ื‘ื•ืจ ืœืื™ื ื˜ืจื ื˜ ื™ืฉ ืœื ื• ื’ื

  • ืžืฉืชืžืฉื™ VPN ื‘ื’ื™ืฉื” ืžืจื—ื•ืง
  • ื’ืื“ื’'ื˜ื™ื ืื™ืฉื™ื™ื ืฉื•ื ื™ื, ืžื—ืฉื‘ื™ื ื ื™ื™ื“ื™ื ื”ื‘ื™ืื•, ืžื—ื•ื‘ืจื™ื ื‘ืืžืฆืขื•ืช WiFi ืœืžืฉืจื“
  • ืžืฉืจื“ื™ื ืื—ืจื™ื (ืกื ื™ืคื™ื).
  • ืื™ื ื˜ื’ืจืฆื™ื” ืขื ืชืฉืชื™ืช ืขื ืŸ

ืื™ืš ื ืจืื™ืช ื’ื™ืฉืช Zero Trust ื‘ืคื•ืขืœ?

ื‘ืื•ืคืŸ ืื™ื“ื™ืืœื™, ื™ืฉ ืœืืคืฉืจ ืจืง ืืช ื”ืชืขื‘ื•ืจื” ื”ื ื“ืจืฉืช, ื•ืื ืื ื—ื ื• ืžื“ื‘ืจื™ื ืขืœ ืื™ื“ื™ืืœ, ืื– ื”ืฉืœื™ื˜ื” ืฆืจื™ื›ื” ืœื”ื™ื•ืช ืœื ืจืง ื‘ืจืžืช L3/L4, ืืœื ื‘ืจืžืช ื”ื™ื™ืฉื•ื.

ืื, ืœืžืฉืœ, ื™ืฉ ืœืš ืืช ื”ื™ื›ื•ืœืช ืœื”ืขื‘ื™ืจ ืืช ื›ืœ ื”ืชืขื‘ื•ืจื” ื“ืจืš ื—ื•ืžืช ืืฉ, ืื– ืืชื” ื™ื›ื•ืœ ืœื ืกื•ืช ืœื”ืชืงืจื‘ ืœืื™ื“ื™ืืœ. ืื‘ืœ ื’ื™ืฉื” ื–ื• ื™ื›ื•ืœื” ืœื”ืคื—ื™ืช ืžืฉืžืขื•ืชื™ืช ืืช ืจื•ื—ื‘ ื”ืคืก ื”ื›ื•ืœืœ ืฉืœ ื”ืจืฉืช ืฉืœืš, ื•ื—ื•ืฅ ืžื–ื”, ืกื™ื ื•ืŸ ืœืคื™ ืืคืœื™ืงืฆื™ื” ืœื ืชืžื™ื“ ืขื•ื‘ื“ ื˜ื•ื‘.

ื‘ืขืช ืฉืœื™ื˜ื” ื‘ืชืขื‘ื•ืจื” ื‘ื ืชื‘ ืื• ืžืชื’ L3 (ื‘ืืžืฆืขื•ืช ACLs ืกื˜ื ื“ืจื˜ื™ื™ื), ืืชื” ื ืชืงืœ ื‘ื‘ืขื™ื•ืช ืื—ืจื•ืช:

  • ื–ื”ื• ืกื™ื ื•ืŸ L3/L4 ื‘ืœื‘ื“. ืื™ืŸ ืฉื•ื ื“ื‘ืจ ืฉืžืคืจื™ืข ืœืชื•ืงืฃ ืœื”ืฉืชืžืฉ ื‘ื™ืฆื™ืื•ืช ืžื•ืชืจื•ืช (ืœืžืฉืœ TCP 80) ืขื‘ื•ืจ ื”ื™ื™ืฉื•ื ืฉืœื• (ืœื http)
  • ื ื™ื”ื•ืœ ACL ืžื•ืจื›ื‘ (ืงืฉื” ืœื ืชื— ืจืฉื™ืžื•ืช ACL)
  • ื–ื• ืื™ื ื” ื—ื•ืžืช ืืฉ ืžื“ื™ื ืชื™ืช, ื›ืœื•ืžืจ ืขืœื™ืš ืœืืคืฉืจ ื‘ืžืคื•ืจืฉ ืชืขื‘ื•ืจื” ื”ืคื•ื›ื”
  • ืขื ืžืชื’ื™ื ืืชื” ื‘ื“ืจืš ื›ืœืœ ืžื•ื’ื‘ืœ ืœืžื“ื™ ืขืœ ื™ื“ื™ ื’ื•ื“ืœ ื”-TCAM, ืžื” ืฉืขืœื•ืœ ืœื”ืคื•ืš ื‘ืžื”ื™ืจื•ืช ืœื‘ืขื™ื” ืื ืืชื” ื ื•ืงื˜ ื‘ื’ื™ืฉื” ืฉืœ "ืืคืฉืจ ืจืง ืžื” ืฉืืชื” ืฆืจื™ืš"

ื”ืขืจื”:

ืื ื›ื‘ืจ ืžื“ื‘ืจื™ื ืขืœ ืชื ื•ืขื” ื”ืคื•ื›ื”, ืขืœื™ื ื• ืœื–ื›ื•ืจ ืฉื™ืฉ ืœื ื• ืืช ื”ื”ื–ื“ืžื ื•ืช ื”ื‘ืื” (ืกื™ืกืงื•)

ืœืืคืฉืจ tcp ื›ืœ ืฉื”ื•ืงื

ืื‘ืœ ืืชื” ืฆืจื™ืš ืœื”ื‘ื™ืŸ ืฉื”ืงื• ื”ื–ื” ืฉื•ื•ื” ืขืจืš ืœืฉืชื™ ืฉื•ืจื•ืช:
ืœืืคืฉืจ tcp ื›ืœ ack
ืœืืคืฉืจ tcp ื›ืœ ื“ื‘ืจ ืจืืฉื•ืŸ

ืžื” ืฉืื•ืžืจ ืฉื’ื ืื ืœื ื”ื™ื” ืงื˜ืข TCP ืจืืฉื•ื ื™ ืขื ื“ื’ืœ SYN (ื›ืœื•ืžืจ, ืกืฉืŸ TCP ืืคื™ืœื• ืœื ื”ืชื—ื™ืœ ืœื”ืชื‘ืกืก), ื”-ACL ื”ื–ื” ื™ืืคืฉืจ ื—ื‘ื™ืœื” ืขื ื“ื’ืœ ACK, ืฉืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื” ื›ื“ื™ ืœื”ืขื‘ื™ืจ ื ืชื•ื ื™ื.

ื›ืœื•ืžืจ, ื”ืงื• ื”ื–ื” ื‘ืฉื•ื ืื•ืคืŸ ืœื ื”ื•ืคืš ืืช ื”ื ืชื‘ ืื• ืžืชื’ ื”-L3 ืฉืœืš ืœื—ื•ืžืช ืืฉ ืžื“ื™ื ืชื™ืช.

ืจืžืช ื”ื’ื ื” ื’ื‘ื•ื”ื”

ะ’ ัั‚ะฐั‚ัŒะต ื‘ืกืขื™ืฃ ืขืœ ืžืจื›ื–ื™ ื ืชื•ื ื™ื, ืฉืงืœื ื• ืืช ืฉื™ื˜ื•ืช ื”ื”ื’ื ื” ื”ื‘ืื•ืช.

  • ื—ื•ืžืช ืืฉ ืžื“ื™ื ื” (ื‘ืจื™ืจืช ืžื—ื“ืœ)
  • ื”ื’ื ืช ddos/dos
  • ื—ื•ืžืช ืืฉ ืฉืœ ื™ื™ืฉื•ืžื™ื
  • ืžื ื™ืขืช ืื™ื•ืžื™ื (ืื ื˜ื™ ื•ื™ืจื•ืก, ืื ื˜ื™ ืชื•ื›ื ื•ืช ืจื™ื’ื•ืœ ื•ืคื’ื™ืขื•ืช)
  • ืกื™ื ื•ืŸ ื›ืชื•ื‘ื•ืช ืืชืจื™ื
  • ืกื™ื ื•ืŸ ื ืชื•ื ื™ื (ืกื™ื ื•ืŸ ืชื•ื›ืŸ)
  • ื—ืกื™ืžืช ืงื‘ืฆื™ื (ื—ืกื™ืžืช ืกื•ื’ื™ ืงื‘ืฆื™ื)

ื‘ืžืงืจื” ืฉืœ ืžืฉืจื“, ื”ืžืฆื‘ ื“ื•ืžื”, ืืš ืกื“ืจื™ ื”ืขื“ื™ืคื•ื™ื•ืช ืžืขื˜ ืฉื•ื ื™ื. ื–ืžื™ื ื•ืช ื”ืžืฉืจื“ (ื–ืžื™ื ื•ืช) ืœืจื•ื‘ ืื™ื ื” ืงืจื™ื˜ื™ืช ื›ืžื• ื‘ืžืงืจื” ืฉืœ ืžืจื›ื– ื ืชื•ื ื™ื, ื‘ืขื•ื“ ืฉื”ืกื‘ื™ืจื•ืช ืœืชืขื‘ื•ืจื” ื–ื“ื•ื ื™ืช "ืคื ื™ืžื™ืช" ื’ื‘ื•ื”ื” ื‘ืกื“ืจื™ ื’ื•ื“ืœ.
ืœื›ืŸ, ืฉื™ื˜ื•ืช ื”ื”ื’ื ื” ื”ื‘ืื•ืช ืขื‘ื•ืจ ืคืœื— ื–ื” ื”ื•ืคื›ื•ืช ืงืจื™ื˜ื™ื•ืช:

  • ื—ื•ืžืช ืืฉ ืฉืœ ื™ื™ืฉื•ืžื™ื
  • ืžื ื™ืขืช ืื™ื•ืžื™ื (ืื ื˜ื™ ื•ื™ืจื•ืก, ืื ื˜ื™ ืจื™ื’ื•ืœ ื•ืคื’ื™ืขื•ืช)
  • ืกื™ื ื•ืŸ ื›ืชื•ื‘ื•ืช ืืชืจื™ื
  • ืกื™ื ื•ืŸ ื ืชื•ื ื™ื (ืกื™ื ื•ืŸ ืชื•ื›ืŸ)
  • ื—ืกื™ืžืช ืงื‘ืฆื™ื (ื—ืกื™ืžืช ืกื•ื’ื™ ืงื‘ืฆื™ื)

ืœืžืจื•ืช ืฉื›ืœ ืฉื™ื˜ื•ืช ื”ื”ื’ื ื” ื”ืœืœื•, ืœืžืขื˜ ื—ื•ืžืช ืืฉ ืฉืœ ื™ื™ืฉื•ืžื™ื, ื ืคืชืจื• ื•ืžืžืฉื™ื›ื•ืช ืœื”ื™ืคืชืจ ื‘ืื•ืคืŸ ืžืกื•ืจืชื™ ื‘ืžืืจื—ื™ ื”ืงืฆื” (ืœื“ื•ื’ืžื”, ืขืœ ื™ื“ื™ ื”ืชืงื ืช ืชื•ื›ื ื•ืช ืื ื˜ื™-ื•ื™ืจื•ืก) ื•ืฉื™ืžื•ืฉ ื‘ืคืจื•ืงืกื™, NGFWs ืžื•ื“ืจื ื™ื™ื ืžืกืคืงื™ื ื’ื ืฉื™ืจื•ืชื™ื ืืœื”.

ืกืคืงื™ ืฆื™ื•ื“ ืื‘ื˜ื—ื” ืฉื•ืืคื™ื ืœื™ืฆื•ืจ ื”ื’ื ื” ืžืงื™ืคื”, ื•ืœื›ืŸ ื™ื—ื“ ืขื ื”ื’ื ื” ืžืงื•ืžื™ืช, ื”ื ืžืฆื™ืขื™ื ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ืขื ืŸ ืฉื•ื ื•ืช ื•ืชื•ื›ื ื•ืช ืœืงื•ื— ืœืžืืจื—ื™ื (ื”ื’ื ื” ืขืœ ื ืงื•ื“ื•ืช ืงืฆื”/EPP). ืื–, ืœืžืฉืœ, ืž 2018 Gartner Magic Quadrant ืื ื• ืจื•ืื™ื ืฉืœืคืืœื• ืืœื˜ื• ื•ืกื™ืกืงื• ื™ืฉ EPPs ืžืฉืœื”ื (PA: Traps, Cisco: AMP), ืื‘ืœ ื”ื ืจื—ื•ืงื™ื ืžื”ืžื ื”ื™ื’ื™ื.

ื”ืคืขืœืช ื”ื’ื ื•ืช ืืœื• (ื‘ื“ืจืš ื›ืœืœ ืขืœ ื™ื“ื™ ืจื›ื™ืฉืช ืจื™ืฉื™ื•ื ื•ืช) ื‘ื—ื•ืžืช ื”ืืฉ ืฉืœืš ืื™ื ื” ื—ื•ื‘ื” ื›ืžื•ื‘ืŸ (ืชื•ื›ืœ ืœืœื›ืช ื‘ื“ืจืš ื”ืžืกื•ืจืชื™ืช), ืืš ื”ื™ื ืžืกืคืงืช ื›ืžื” ื™ืชืจื•ื ื•ืช:

  • ื‘ืžืงืจื” ื–ื”, ื™ืฉ ื ืงื•ื“ืช ื™ื™ืฉื•ื ืื—ืช ืฉืœ ืฉื™ื˜ื•ืช ื”ื’ื ื”, ืืฉืจ ืžืฉืคืจืช ืืช ื”ื ืจืื•ืช (ืจืื” ืืช ื”ื ื•ืฉื ื”ื‘ื).
  • ืื ื™ืฉ ืžื›ืฉื™ืจ ืœื ืžื•ื’ืŸ ื‘ืจืฉืช ืฉืœืš, ืื– ื”ื•ื ืขื“ื™ื™ืŸ ื ื•ืคืœ ืชื—ืช "ื”ืžื˜ืจื™ื”" ืฉืœ ื”ื’ื ืช ื—ื•ืžืช ืืฉ
  • ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ื‘ื”ื’ื ื” ืขืœ ื—ื•ืžืช ืืฉ ื‘ืฉื™ืœื•ื‘ ืขื ื”ื’ื ืช ืžืืจื— ืงืฆื”, ืื ื• ืžื’ื“ื™ืœื™ื ืืช ื”ืกื‘ื™ืจื•ืช ืœื–ื™ื”ื•ื™ ืชืขื‘ื•ืจื” ื–ื“ื•ื ื™ืช. ืœื“ื•ื’ืžื”, ืฉื™ืžื•ืฉ ื‘ืžื ื™ืขืช ืื™ื•ืžื™ื ืขืœ ืžืืจื—ื™ื ืžืงื•ืžื™ื™ื ื•ืขืœ ื—ื•ืžืช ืืฉ ืžื’ื‘ื™ืจ ืืช ื”ืกื‘ื™ืจื•ืช ืœื–ื™ื”ื•ื™ (ื›ืžื•ื‘ืŸ ื‘ืชื ืื™ ืฉืคืชืจื•ื ื•ืช ืืœื• ืžื‘ื•ืกืกื™ื ืขืœ ืžื•ืฆืจื™ ืชื•ื›ื ื” ืฉื•ื ื™ื)

ื”ืขืจื”:

ืื, ืœืžืฉืœ, ืืชื” ืžืฉืชืžืฉ ื‘ืงืกืคืจืกืงื™ ื›ืื ื˜ื™ ื•ื™ืจื•ืก ื’ื ื‘ื—ื•ืžืช ื”ืืฉ ื•ื’ื ื‘ืžืืจื—ื™ื ื”ืงืฆื”, ืื– ื–ื”, ื›ืžื•ื‘ืŸ, ืœื ื™ื’ื“ื™ืœ ืžืื•ื“ ืืช ื”ืกื™ื›ื•ื™ื™ื ืฉืœืš ืœืžื ื•ืข ื”ืชืงืคืช ื•ื™ืจื•ืกื™ื ื‘ืจืฉืช ืฉืœืš.

ื ืจืื•ืช ืจืฉืช

ื”ืจืขื™ื•ืŸ ื”ืžืจื›ื–ื™ ื”ื•ื ืคืฉื•ื˜ - "ืจืื”" ืžื” ืงื•ืจื” ื‘ืจืฉืช ืฉืœืš, ื”ืŸ ื‘ื–ืžืŸ ืืžืช ื•ื”ืŸ ื‘ื ืชื•ื ื™ื ื”ื™ืกื˜ื•ืจื™ื™ื.

ื”ื™ื™ืชื™ ืžื—ืœืง ืืช ื”"ื—ื–ื•ืŸ" ื”ื–ื” ืœืฉืชื™ ืงื‘ื•ืฆื•ืช:

ืงื‘ื•ืฆื” ืจืืฉื•ื ื”: ืžื” ืฉืžืขืจื›ืช ื”ื ื™ื˜ื•ืจ ืฉืœืš ืžืกืคืงืช ืœืš ื‘ื“ืจืš ื›ืœืœ.

  • ื˜ืขื™ื ืช ืฆื™ื•ื“
  • ื˜ืขื™ื ืช ืขืจื•ืฆื™ื
  • ืฉื™ืžื•ืฉ ื‘ื–ื™ื›ืจื•ืŸ
  • ืฉื™ืžื•ืฉ ื‘ื“ื™ืกืง
  • ืฉื™ื ื•ื™ ื˜ื‘ืœืช ื”ื ื™ืชื•ื‘
  • ืžืฆื‘ ืงื™ืฉื•ืจ
  • ื–ืžื™ื ื•ืช ืฆื™ื•ื“ (ืื• ืžืืจื—ื™ื)
  • ...

ืงื‘ื•ืฆื” ืฉื ื™ื”: ืžื™ื“ืข ื”ืงืฉื•ืจ ืœื‘ื˜ื™ื—ื•ืช.

  • ืกื•ื’ื™ื ืฉื•ื ื™ื ืฉืœ ื ืชื•ื ื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื (ืœื“ื•ื’ืžื”, ืœืคื™ ืืคืœื™ืงืฆื™ื”, ืœืคื™ ืชืขื‘ื•ืจืช ื›ืชื•ื‘ื•ืช ืืชืจื™ื, ืื™ืœื• ืกื•ื’ื™ ื ืชื•ื ื™ื ื”ื•ืจื“ื•, ื ืชื•ื ื™ ืžืฉืชืžืฉื™ื)
  • ืžื” ื ื—ืกื ืขืœ ื™ื“ื™ ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื” ื•ืžืื™ื–ื• ืกื™ื‘ื”, ื›ืœื•ืžืจ
    • ื™ื™ืฉื•ื ืืกื•ืจ
    • ืืกื•ืจ ื‘ื”ืชื‘ืกืก ืขืœ ip/ืคืจื•ื˜ื•ืงื•ืœ/ื™ืฆื™ืื”/ื“ื’ืœื™ื/ืื–ื•ืจื™ื
    • ืžื ื™ืขืช ืื™ื•ืžื™ื
    • ืกื™ื ื•ืŸ ื›ืชื•ื‘ื•ืช ืืชืจื™ื
    • ืกื™ื ื•ืŸ ื ืชื•ื ื™ื
    • ื—ืกื™ืžืช ืงื‘ืฆื™ื
    • ...
  • ื ืชื•ื ื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื ืขืœ ื”ืชืงืคื•ืช DOS/DDOS
  • ื ื™ืกื™ื•ื ื•ืช ื–ื™ื”ื•ื™ ื•ื”ืจืฉืื” ื›ื•ืฉืœื™ื
  • ื ืชื•ื ื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื ืขื‘ื•ืจ ื›ืœ ืื™ืจื•ืขื™ ื”ืคืจืช ืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื” ืœืขื™ืœ
  • ...

ื‘ืคืจืง ื–ื” ืขืœ ืื‘ื˜ื—ื”, ืื ื• ืžืชืขื ื™ื™ื ื™ื ื‘ื—ืœืง ื”ืฉื ื™.

ื›ืžื” ื—ื•ืžื•ืช ืืฉ ืžื•ื“ืจื ื™ื•ืช (ืžื”ื ื™ืกื™ื•ืŸ ืฉืœื™ ื‘ืคืืœื• ืืœื˜ื•) ืžืกืคืงื•ืช ืจืžืช ื ืจืื•ืช ื˜ื•ื‘ื”. ืื‘ืœ, ื›ืžื•ื‘ืŸ, ื”ืชืขื‘ื•ืจื” ืฉืืชื” ืžืขื•ื ื™ื™ืŸ ื‘ื” ื—ื™ื™ื‘ืช ืœืขื‘ื•ืจ ื“ืจืš ื—ื•ืžืช ื”ืืฉ ื”ื–ื• (ื‘ืžืงืจื” ื›ื–ื” ื™ืฉ ืœืš ืืช ื”ื™ื›ื•ืœืช ืœื—ืกื•ื ืชืขื‘ื•ืจื”) ืื• ืžืฉื•ืงืคืช ืœื—ื•ืžืช ื”ืืฉ (ืžืฉืžืฉืช ืจืง ืœื ื™ื˜ื•ืจ ื•ื ื™ืชื•ื—), ื•ืืชื” ื—ื™ื™ื‘ ืœื”ื™ื•ืช ื‘ืขืœ ืจื™ืฉื™ื•ื ื•ืช ื›ื“ื™ ืœืืคืฉืจ ืืช ื›ืœ ืฉื™ืจื•ืชื™ื ืืœื”.

ื™ืฉ, ื›ืžื•ื‘ืŸ, ื“ืจืš ื—ืœื•ืคื™ืช, ืื• ื™ื•ืชืจ ื ื›ื•ืŸ ื”ื“ืจืš ื”ืžืกื•ืจืชื™ืช, ืœืžืฉืœ,

  • ื ื™ืชืŸ ืœืืกื•ืฃ ื ืชื•ื ื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื ืฉืœ ื”ืคืขืœื” ื‘ืืžืฆืขื•ืช netflow ื•ืœืื—ืจ ืžื›ืŸ ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ ืขื–ืจ ืžื™ื•ื—ื“ื™ื ืœื ื™ืชื•ื— ืžื™ื“ืข ื•ื”ื“ืžื™ื™ืช ื ืชื•ื ื™ื
  • ืžื ื™ืขืช ืื™ื•ืžื™ื - ืชื•ื›ื ื™ื•ืช ืžื™ื•ื—ื“ื•ืช (ืื ื˜ื™ ื•ื™ืจื•ืก, ืื ื˜ื™ ืจื™ื’ื•ืœ, ื—ื•ืžืช ืืฉ) ื‘ืžืืจื—ื™ ืงืฆื”
  • ืกื™ื ื•ืŸ ื›ืชื•ื‘ื•ืช ืืชืจื™ื, ืกื™ื ื•ืŸ ื ืชื•ื ื™ื, ื—ืกื™ืžืช ืงื‘ืฆื™ื - ื‘-proxy
  • ืืคืฉืจ ื’ื ืœื ืชื— tcpdump ื‘ืืžืฆืขื•ืช ืœืžืฉืœ. ืœื ื—ืจ

ืืชื” ื™ื›ื•ืœ ืœืฉืœื‘ ืืช ืฉืชื™ ื”ื’ื™ืฉื•ืช ื”ืœืœื•, ืœื”ืฉืœื™ื ืชื›ื•ื ื•ืช ื—ืกืจื•ืช ืื• ืœืฉื›ืคืœ ืื•ืชืŸ ื›ื“ื™ ืœื”ื’ื“ื™ืœ ืืช ื”ืกื‘ื™ืจื•ืช ืœื–ื™ื”ื•ื™ ื”ืชืงืคื”.

ื‘ืื™ื–ื• ื’ื™ืฉื” ื›ื“ืื™ ืœื‘ื—ื•ืจ?
ืชืœื•ื™ ืžืื•ื“ ื‘ื›ื™ืฉื•ืจื™ื ื•ื‘ื”ืขื“ืคื•ืช ืฉืœ ื”ืฆื•ื•ืช ืฉืœืš.
ื’ื ืฉื ื•ื’ื ื™ืฉ ื™ืชืจื•ื ื•ืช ื•ื—ืกืจื•ื ื•ืช.

ืžืขืจื›ืช ืื™ืžื•ืช ื•ื”ืจืฉืื” ืžืจื›ื–ื™ืช ืžืื•ื—ื“ืช

ื›ืืฉืจ ืžืชื•ื›ื ืŸ ื”ื™ื˜ื‘, ื”ื ื™ื™ื“ื•ืช ืขืœื™ื” ื“ื ื• ื‘ืžืืžืจ ื–ื” ืžื ื™ื—ื” ืฉื™ืฉ ืœืš ืืช ืื•ืชื” ื’ื™ืฉื” ื‘ื™ืŸ ืื ืืชื” ืขื•ื‘ื“ ืžื”ืžืฉืจื“ ืื• ืžื”ื‘ื™ืช, ืžืฉื“ื” ื”ืชืขื•ืคื”, ืžื‘ื™ืช ืงืคื” ืื• ืžื›ืœ ืžืงื•ื ืื—ืจ (ืขื ื”ืžื’ื‘ืœื•ืช ืฉื“ื ื• ืœืžืขืœื”). ื ืจืื”, ืžื” ื”ื‘ืขื™ื”?
ื›ื“ื™ ืœื”ื‘ื™ืŸ ื˜ื•ื‘ ื™ื•ืชืจ ืืช ื”ืžื•ืจื›ื‘ื•ืช ืฉืœ ืžืฉื™ืžื” ื–ื•, ื‘ื•ืื• ื ืกืชื›ืœ ืขืœ ืขื™ืฆื•ื‘ ื˜ื™ืคื•ืกื™.

ื“ื•ื’ืžื”

  • ื—ื™ืœืงืชื ืืช ื›ืœ ื”ืขื•ื‘ื“ื™ื ืœืงื‘ื•ืฆื•ืช. ื”ื—ืœื˜ืช ืœืกืคืง ื’ื™ืฉื” ืœืคื™ ืงื‘ื•ืฆื•ืช
  • ื‘ืชื•ืš ื”ืžืฉืจื“, ืืชื” ืฉื•ืœื˜ ื‘ื’ื™ืฉื” ื‘ื—ื•ืžืช ื”ืืฉ ืฉืœ ื”ืžืฉืจื“
  • ืืชื” ืฉื•ืœื˜ ื‘ืชื ื•ืขื” ืžื”ืžืฉืจื“ ืœืžืจื›ื– ื”ื ืชื•ื ื™ื ื‘ื—ื•ืžืช ื”ืืฉ ืฉืœ ืžืจื›ื– ื”ื ืชื•ื ื™ื
  • ืืชื” ืžืฉืชืžืฉ ื‘-Cisco ASA ื›ืฉืขืจ VPN ื•ื›ื“ื™ ืœืฉืœื•ื˜ ื‘ืชืขื‘ื•ืจื” ื”ื ื›ื ืกืช ืœืจืฉืช ืฉืœืš ืžืœืงื•ื—ื•ืช ืžืจื•ื—ืงื™ื, ืืชื” ืžืฉืชืžืฉ ื‘-ACL ืžืงื•ืžื™ื™ื (ื‘-ASA)

ื›ืขืช, ื ื ื™ื— ืฉืืชื” ืžืชื‘ืงืฉ ืœื”ื•ืกื™ืฃ ื’ื™ืฉื” ื ื•ืกืคืช ืœืขื•ื‘ื“ ืžืกื•ื™ื. ื‘ืžืงืจื” ื–ื”, ืืชื” ืžืชื‘ืงืฉ ืœื”ื•ืกื™ืฃ ื’ื™ืฉื” ืจืง ืœื• ื•ืœื ืœืืฃ ืื—ื“ ืื—ืจ ืžื”ืงื‘ื•ืฆื” ืฉืœื•.

ื‘ืฉื‘ื™ืœ ื–ื” ืื ื—ื ื• ืฆืจื™ื›ื™ื ืœื™ืฆื•ืจ ืงื‘ื•ืฆื” ื ืคืจื“ืช ืœืขื•ื‘ื“ ื”ื–ื”, ื›ืœื•ืžืจ

  • ืœื™ืฆื•ืจ ืžืื’ืจ IP ื ืคืจื“ ื‘-ASA ืขื‘ื•ืจ ืขื•ื‘ื“ ื–ื”
  • ื”ื•ืกืฃ ACL ื—ื“ืฉ ื‘-ASA ื•ืงืฉืจ ืื•ืชื• ืœืœืงื•ื— ื”ืžืจื•ื—ืง ื”ื–ื”
  • ืœื™ืฆื•ืจ ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื” ื—ื“ืฉื” ืขืœ ื—ื•ืžื•ืช ืืฉ ืฉืœ ืžืฉืจื“ื™ื ื•ืžืจื›ื–ื™ ื ืชื•ื ื™ื

ื–ื” ื˜ื•ื‘ ืื ื”ืื™ืจื•ืข ื”ื–ื” ื ื“ื™ืจ. ืื‘ืœ ื‘ืชืจื’ื•ืœ ืฉืœื™ ื”ื™ื” ืžืฆื‘ ืฉืขื•ื‘ื“ื™ื ื”ืฉืชืชืคื• ื‘ืคืจื•ื™ืงื˜ื™ื ืฉื•ื ื™ื, ื•ืžืขืจื›ืช ื”ืคืจื•ื™ืงื˜ื™ื ื”ื–ื• ืขื‘ื•ืจ ื—ืœืงื ื”ืฉืชื ืชื” ืœืขืชื™ื ืงืจื•ื‘ื•ืช ืœืžื“ื™, ื•ืœื ื”ื™ื• 1-2 ืื ืฉื™ื, ืืœื ืขืฉืจื•ืช. ื›ืžื•ื‘ืŸ ืฉื”ื™ื” ืฆืจื™ืš ืœืฉื ื•ืช ืคื” ืžืฉื”ื•.

ื–ื” ื ืคืชืจ ื‘ื“ืจืš ื”ื‘ืื”.

ื”ื—ืœื˜ื ื• ืฉ-LDAP ื™ื”ื™ื” ืžืงื•ืจ ื”ืืžืช ื”ื™ื—ื™ื“ ืฉืงื•ื‘ืข ืืช ื›ืœ ื”ื’ื™ืฉื” ื”ืืคืฉืจื™ืช ืœืขื•ื‘ื“ื™ื. ื™ืฆืจื ื• ื›ืœ ืžื™ื ื™ ืงื‘ื•ืฆื•ืช ืฉืžื’ื“ื™ืจื•ืช ืงื‘ื•ืฆื•ืช ืฉืœ ื’ื™ืฉื”, ื•ื”ืงืฆืื ื• ื›ืœ ืžืฉืชืžืฉ ืœืงื‘ื•ืฆื” ืื—ืช ืื• ื™ื•ืชืจ.

ืื–, ืœืžืฉืœ, ื ื ื™ื— ืฉื”ื™ื• ืงื‘ื•ืฆื•ืช

  • ืื•ืจื— (ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜)
  • ื’ื™ืฉื” ืžืฉื•ืชืคืช (ื’ื™ืฉื” ืœืžืฉืื‘ื™ื ืžืฉื•ืชืคื™ื: ื“ื•ืืจ, ื‘ืกื™ืก ื™ื“ืข, ...)
  • ื—ืฉื‘ื•ื ืื•ืช
  • ืคืจื•ื™ืงื˜ 1
  • ืคืจื•ื™ืงื˜ 2
  • ืžื ื”ืœ ืžืกื“ ื ืชื•ื ื™ื
  • ืžื ื”ืœ ืœื™ื ื•ืงืก
  • ...

ื•ืื ืื—ื“ ื”ืขื•ื‘ื“ื™ื ื”ื™ื” ืžืขื•ืจื‘ ื”ืŸ ื‘ืคืจื•ื™ืงื˜ 1 ื•ื”ืŸ ื‘ืคืจื•ื™ืงื˜ 2, ื•ื”ื•ื ื”ื™ื” ื–ืงื•ืง ืœื’ื™ืฉื” ื”ื“ืจื•ืฉื” ืœืขื‘ื•ื“ื” ื‘ืคืจื•ื™ืงื˜ื™ื ืืœื”, ืื– ืขื•ื‘ื“ ื–ื” ืฉื•ื‘ืฅ ืœืงื‘ื•ืฆื•ืช ื”ื‘ืื•ืช:

  • ืื•ืจื—
  • ื’ื™ืฉื” ืžืฉื•ืชืคืช
  • ืคืจื•ื™ืงื˜ 1
  • ืคืจื•ื™ืงื˜ 2

ื›ื™ืฆื“ ื ื•ื›ืœ ื›ืขืช ืœื”ืคื•ืš ืžื™ื“ืข ื–ื” ืœื’ื™ืฉื” ืขืœ ืฆื™ื•ื“ ืจืฉืช?

Cisco ASA ืžื“ื™ื ื™ื•ืช ื’ื™ืฉื” ื“ื™ื ืžื™ืช (DAP) (ืจืื” www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/108000-dap-deploy-guide.html) ื”ืคืชืจื•ืŸ ืžืชืื™ื ื‘ื“ื™ื•ืง ืœืžืฉื™ืžื” ื–ื•.

ื‘ืงืฆืจื” ืœื’ื‘ื™ ื”ื™ื™ืฉื•ื ืฉืœื ื•, ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ื–ื™ื”ื•ื™/ื”ืจืฉืื”, ASA ืžืงื‘ืœืช ืž-LDAP ืงื‘ื•ืฆื” ืฉืœ ืงื‘ื•ืฆื•ืช ื”ืชื•ืืžื•ืช ืœืžืฉืชืžืฉ ื ืชื•ืŸ ื•"ืื•ืกืคืช" ืžืžืกืคืจ ACLs ืžืงื•ืžื™ื™ื (ืฉื›ืœ ืื—ื“ ืžื”ื ืžืชืื™ื ืœืงื‘ื•ืฆื”) ACL ื“ื™ื ืžื™ ืขื ื›ืœ ื”ื’ื™ืฉื” ื”ื ื—ื•ืฆื” , ื”ืชื•ืื ื‘ืื•ืคืŸ ืžืœื ืœืจืฆื•ื ื•ืชื™ื ื•.

ืื‘ืœ ื–ื” ืจืง ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ VPN. ื›ื“ื™ ืฉื”ืžืฆื‘ ื™ื”ื™ื” ื–ื”ื” ื”ืŸ ืขื‘ื•ืจ ื”ืขื•ื‘ื“ื™ื ื”ืžื—ื•ื‘ืจื™ื ื‘ืืžืฆืขื•ืช VPN ื•ื”ืŸ ืขื‘ื•ืจ ืืœื• ื‘ืžืฉืจื“, ื ื ืงื˜ ื”ืฆืขื“ ื”ื‘ื.

ื‘ืขืช ื—ื™ื‘ื•ืจ ืžื”ืžืฉืจื“, ืžืฉืชืžืฉื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืคืจื•ื˜ื•ืงื•ืœ 802.1x ื”ื’ื™ืขื• ืœ-LAN ืื•ืจื— (ืขื‘ื•ืจ ืื•ืจื—ื™ื) ืื• LAN ืขื ื’ื™ืฉื” ืžืฉื•ืชืคืช (ืขื‘ื•ืจ ืขื•ื‘ื“ื™ ื”ื—ื‘ืจื”). ื™ืชืจื” ืžื›ืš, ื›ื“ื™ ืœืงื‘ืœ ื’ื™ืฉื” ืกืคืฆื™ืคื™ืช (ืœื“ื•ื’ืžื”, ืœืคืจื•ื™ืงื˜ื™ื ื‘ืžืจื›ื– ื ืชื•ื ื™ื), ื”ืขื•ื‘ื“ื™ื ื”ื™ื• ืฆืจื™ื›ื™ื ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช VPN.

ื›ื“ื™ ืœื”ืชื—ื‘ืจ ืžื”ืžืฉืจื“ ื•ืžื”ื‘ื™ืช, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืงื‘ื•ืฆื•ืช ืžื ื”ืจื•ืช ืฉื•ื ื•ืช ื‘-ASA. ื–ื” ื”ื›ืจื—ื™ ื›ื“ื™ ืฉืขื‘ื•ืจ ื”ืžืชื—ื‘ืจื™ื ืžื”ืžืฉืจื“, ื”ืชืขื‘ื•ืจื” ืœืžืฉืื‘ื™ื ืžืฉื•ืชืคื™ื (ื”ืžืฉืžืฉื™ื ืืช ื›ืœ ื”ืขื•ื‘ื“ื™ื, ื›ื’ื•ืŸ ื“ื•ืืจ, ืฉืจืชื™ ืงื‘ืฆื™ื, ืžืขืจื›ืช ื›ืจื˜ื™ืกื™ื, dns,...) ืœื ืชืขื‘ื•ืจ ื“ืจืš ื”-ASA, ืืœื ื“ืจืš ื”ืจืฉืช ื”ืžืงื•ืžื™ืช . ืœืคื™ื›ืš, ืœื ื”ืขืžืกื ื• ืขืœ ื”ืืก"ื ืชื ื•ืขื” ืžื™ื•ืชืจืช, ื›ื•ืœืœ ืชื ื•ืขื” ื‘ืขืฆื™ืžื•ืช ื’ื‘ื•ื”ื”.

ื›ืš, ื”ื‘ืขื™ื” ื ืคืชืจื”.
ื™ืฉ ืœื ื•

  • ืื•ืชื” ืกื˜ ืฉืœ ื’ื™ืฉื” ื”ืŸ ืœื—ื™ื‘ื•ืจื™ื ืžื”ืžืฉืจื“ ื•ื”ืŸ ืœื—ื™ื‘ื•ืจื™ื ืžืจื•ื—ืงื™ื
  • ื”ื™ืขื“ืจ ืคื’ื™ืขื” ื‘ืฉื™ืจื•ืช ื›ืืฉืจ ืขื•ื‘ื“ื™ื ืžื”ืžืฉืจื“ ื”ืงืฉื•ืจื™ื ืœื”ืขื‘ืจืช ืชืขื‘ื•ืจื” ื‘ืขืฆื™ืžื•ืช ื’ื‘ื•ื”ื” ื“ืจืš ASA

ืื™ืœื• ื™ืชืจื•ื ื•ืช ื ื•ืกืคื™ื ืฉืœ ื’ื™ืฉื” ื–ื•?
ื‘ื ื™ื”ื•ืœ ื’ื™ืฉื”. ื’ื™ืฉื” ื ื™ืชื ืช ืœืฉื™ื ื•ื™ ื‘ืงืœื•ืช ื‘ืžืงื•ื ืื—ื“.
ืœื“ื•ื’ืžื”, ืื ืขื•ื‘ื“ ืขื•ื–ื‘ ืืช ื”ื—ื‘ืจื”, ืืชื” ืคืฉื•ื˜ ืžืกื™ืจ ืื•ืชื• ืž-LDAP, ื•ื”ื•ื ืื•ื˜ื•ืžื˜ื™ืช ืžืื‘ื“ ืืช ื›ืœ ื”ื’ื™ืฉื”.

ื‘ื“ื™ืงืช ืžืืจื—

ืขื ืืคืฉืจื•ืช ืœื—ื™ื‘ื•ืจ ืžืจื—ื•ืง, ืื ื• ืžืกืชื›ื ื™ื ื‘ื›ื ื™ืกื” ืœื ืจืง ืœืขื•ื‘ื“ ื”ื—ื‘ืจื” ืœืจืฉืช, ืืœื ื’ื ืืช ื›ืœ ื”ืชื•ื›ื ื•ืช ื”ื–ื“ื•ื ื™ื•ืช ืฉื ืžืฆืื•ืช ื‘ืกื‘ื™ืจื•ืช ื’ื‘ื•ื”ื” ื‘ืžื—ืฉื‘ ืฉืœื• (ืœืžืฉืœ ื‘ื‘ื™ืช), ื•ื™ื•ืชืจ ืžื›ืš, ื‘ืืžืฆืขื•ืช ืชื•ื›ื ื” ื–ื• ืื ื• ื™ื™ืชื›ืŸ ืฉื”ื•ื ืžืกืคืง ื’ื™ืฉื” ืœืจืฉืช ืฉืœื ื• ืœืชื•ืงืฃ ื”ืžืฉืชืžืฉ ื‘ืžืืจื— ื–ื” ื›ืคืจื•ืงืกื™.

ื”ื’ื™ื•ื ื™ ืฉืžืืจื— ืžื—ื•ื‘ืจ ืžืจื—ื•ืง ื™ื—ื™ืœ ืืช ืื•ืชืŸ ื“ืจื™ืฉื•ืช ืื‘ื˜ื—ื” ื›ืžื• ืžืืจื— ื‘ืžืฉืจื“.

ื–ื” ื’ื ืžื ื™ื— ืืช ื”ื’ืจืกื” ื”"ื ื›ื•ื ื”" ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื”, ืชื•ื›ื ืช ื”ืื ื˜ื™-ื•ื™ืจื•ืก, ื”ืื ื˜ื™-ืจื™ื’ื•ืœ ื•ื—ื•ืžืช ื”ืืฉ ื•ืขื“ื›ื•ื ื™ื. ื‘ื“ืจืš ื›ืœืœ, ื™ื›ื•ืœืช ื–ื• ืงื™ื™ืžืช ื‘ืฉืขืจ ื”-VPN (ืขื‘ื•ืจ ASA ืจืื”, ืœืžืฉืœ, ื›ืืŸ).

ื–ื” ื’ื ื—ื›ื ืœื™ื™ืฉื ืืช ืื•ืชืŸ ื˜ื›ื ื™ืงื•ืช ื ื™ืชื•ื— ืชื ื•ืขื” ื•ื—ืกื™ืžื” (ืจืื” "ืจืžืช ื”ื’ื ื” ื’ื‘ื•ื”ื”") ืฉืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื” ืฉืœืš ื—ืœื” ืขืœ ืชืขื‘ื•ืจืช ืžืฉืจื“ื™ื.

ืกื‘ื™ืจ ืœื”ื ื™ื— ืฉื”ืจืฉืช ื”ืžืฉืจื“ื™ืช ืฉืœืš ืื™ื ื” ืžื•ื’ื‘ืœืช ืขื•ื“ ืœื‘ื ื™ื™ืŸ ื”ืžืฉืจื“ื™ื ื•ืœืžืืจื—ื™ื ืฉื‘ืชื•ื›ื•.

ื“ื•ื’ืžื”

ื˜ื›ื ื™ืงื” ื˜ื•ื‘ื” ื”ื™ื ืœืกืคืง ืœื›ืœ ืขื•ื‘ื“ ืฉื“ื•ืจืฉ ื’ื™ืฉื” ืžืจื—ื•ืง ืžื—ืฉื‘ ื ื™ื™ื“ ื˜ื•ื‘ ื•ื ื•ื— ื•ืœื“ืจื•ืฉ ืžืžื ื• ืœืขื‘ื•ื“, ื’ื ื‘ืžืฉืจื“ ื•ื’ื ืžื”ื‘ื™ืช, ืจืง ืžืžื ื•.

ื–ื” ืœื ืจืง ืžืฉืคืจ ืืช ื”ืื‘ื˜ื—ื” ืฉืœ ื”ืจืฉืช ืฉืœืš, ืืœื ืฉื”ื•ื ื’ื ืžืžืฉ ื ื•ื— ื•ื‘ื“ืจืš ื›ืœืœ ื ืจืื” ื‘ืขื™ืŸ ื™ืคื” ืขืœ ื™ื“ื™ ื”ืขื•ื‘ื“ื™ื (ืื ื–ื” ืžื—ืฉื‘ ื ื™ื™ื“ ืžืžืฉ ื˜ื•ื‘ ื•ื™ื“ื™ื“ื•ืชื™ ืœืžืฉืชืžืฉ).

ืขืœ ื—ื•ืฉ ืคืจื•ืคื•ืจืฆื™ื” ื•ืื™ื–ื•ืŸ

ื‘ืขืฆื, ืžื“ื•ื‘ืจ ื‘ืฉื™ื—ื” ืขืœ ื”ืงื•ื“ืงื•ื“ ื”ืฉืœื™ืฉื™ ืฉืœ ื”ืžืฉื•ืœืฉ ืฉืœื ื• โ€“ ืขืœ ื”ืžื—ื™ืจ.
ื‘ื•ืื• ื ืกืชื›ืœ ืขืœ ื“ื•ื’ืžื” ื”ื™ืคื•ืชื˜ื™ืช.

ื“ื•ื’ืžื”

ื™ืฉ ืœืš ืžืฉืจื“ ืœ-200 ืื™ืฉ. ื”ื—ืœื˜ืช ืœืขืฉื•ืช ืืช ื–ื” ื”ื›ื™ ื ื•ื— ื•ื‘ื˜ื•ื— ืฉืืคืฉืจ.

ืœื›ืŸ, ื”ื—ืœื˜ืช ืœื”ืขื‘ื™ืจ ืืช ื›ืœ ื”ืชืขื‘ื•ืจื” ื“ืจืš ื—ื•ืžืช ื”ืืฉ ื•ืœืคื™ื›ืš ืขื‘ื•ืจ ื›ืœ ืจืฉืชื•ืช ื”ืžืฉื ื” ืฉืœ ื”ืžืฉืจื“, ื—ื•ืžืช ื”ืืฉ ื”ื™ื ืฉืขืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ. ื‘ื ื•ืกืฃ ืœืชื•ื›ื ืช ื”ืื‘ื˜ื—ื” ื”ืžื•ืชืงื ืช ืขืœ ื›ืœ ืžืืจื— ืงืฆื” (ืื ื˜ื™ ื•ื™ืจื•ืก, ืื ื˜ื™ ืจื™ื’ื•ืœ ื•ืชื•ื›ื ื•ืช ื—ื•ืžืช ืืฉ), ื”ื—ืœื˜ืช ื’ื ืœื™ื™ืฉื ืืช ื›ืœ ืฉื™ื˜ื•ืช ื”ื”ื’ื ื” ื”ืืคืฉืจื™ื•ืช ืขืœ ื—ื•ืžืช ื”ืืฉ.

ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืžื”ื™ืจื•ืช ื—ื™ื‘ื•ืจ ื’ื‘ื•ื”ื” (ื”ื›ืœ ืžื˜ืขืžื™ ื ื•ื—ื•ืช), ื‘ื—ืจืช ื‘ืžืชื’ื™ื ืขื 10 ื™ืฆื™ืื•ืช Gigabit ื›ืžืชื’ื™ ื’ื™ืฉื”, ื•ื—ื•ืžื•ืช ืืฉ NGFW ื‘ืขืœื•ืช ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื ื‘ืชื•ืจ ื—ื•ืžื•ืช ืืฉ, ืœืžืฉืœ ืกื“ืจืช Palo Alto 7K (ืขื 40 ื™ืฆื™ืื•ืช Gigabit), ื›ืžื•ื‘ืŸ ืขื ื›ืœ ื”ืจื™ืฉื™ื•ื ื•ืช ื›ืœื•ืœ, ื•ื‘ืื•ืคืŸ ื˜ื‘ืขื™, ื–ื•ื’ ื–ืžื™ื ื•ืช ื’ื‘ื•ื”ื”.

ื›ืžื• ื›ืŸ, ื›ืžื•ื‘ืŸ, ื›ื“ื™ ืœืขื‘ื•ื“ ืขื ืงื• ื”ืฆื™ื•ื“ ื”ื–ื” ืื ื—ื ื• ืฆืจื™ื›ื™ื ืœืคื—ื•ืช ื›ืžื” ืžื”ื ื“ืกื™ ืื‘ื˜ื—ื” ืžื•ืกืžื›ื™ื.

ืœืื—ืจ ืžื›ืŸ, ื”ื—ืœื˜ืชื ืœืชืช ืœื›ืœ ืขื•ื‘ื“ ืžื—ืฉื‘ ื ื™ื™ื“ ื˜ื•ื‘.

ืกืš ื”ื›ืœ, ื›-10 ืžื™ืœื™ื•ืŸ ื“ื•ืœืจ ืœื™ื™ืฉื•ื, ืžืื•ืช ืืœืคื™ ื“ื•ืœืจื™ื (ืœื“ืขืชื™ ืงืจื•ื‘ ื™ื•ืชืจ ืœืžื™ืœื™ื•ืŸ) ืœืชืžื™ื›ื” ืฉื ืชื™ืช ื•ืžืฉื›ื•ืจื•ืช ืœืžื”ื ื“ืกื™ื.

ืžืฉืจื“, 200 ืื™ืฉ...
ื ื•ึนื—ึท? ืื ื™ ืžื ื™ื— ืฉื–ื” ื›ืŸ.

ืืชื” ื‘ื ืขื ื”ื”ืฆืขื” ื”ื–ื• ืœื”ื ื”ืœื” ืฉืœืš...
ืื•ืœื™ ื™ืฉื ืŸ ืžืกืคืจ ื—ื‘ืจื•ืช ื‘ืขื•ืœื ืฉื–ื”ื• ืคืชืจื•ืŸ ืžืงื•ื‘ืœ ื•ื ื›ื•ืŸ ืขื‘ื•ืจืŸ. ืื ืืชื” ืขื•ื‘ื“ ื‘ื—ื‘ืจื” ื–ื•, ื‘ืจื›ื•ืชื™ื™, ืืš ื‘ืจื•ื‘ ื”ืžื•ื—ืœื˜ ืฉืœ ื”ืžืงืจื™ื, ืื ื™ ื‘ื˜ื•ื— ืฉื”ื™ื“ืข ืฉืœืš ืœื ื™ื–ื›ื” ืœื”ืขืจื›ื” ืžืฆื“ ื”ื”ื ื”ืœื”.

ื”ืื ื”ื“ื•ื’ืžื” ื”ื–ื• ืžื•ื’ื–ืžืช? ื”ืคืจืง ื”ื‘ื ื™ืขื ื” ืขืœ ืฉืืœื” ื–ื•.

ืื ื‘ืจืฉืช ืฉืœืš ืื™ื ืš ืจื•ืื” ืืช ื›ืœ ื”ืืžื•ืจ ืœืขื™ืœ, ื–ื• ื”ื ื•ืจืžื”.
ืขื‘ื•ืจ ื›ืœ ืžืงืจื” ืกืคืฆื™ืคื™, ืขืœื™ืš ืœืžืฆื•ื ืคืฉืจื” ืกื‘ื™ืจื” ืžืฉืœืš ื‘ื™ืŸ ื ื•ื—ื•ืช, ืžื—ื™ืจ ื•ื‘ื˜ื™ื—ื•ืช. ืœืขืชื™ื ืงืจื•ื‘ื•ืช ืืชื” ืืคื™ืœื• ืœื ืฆืจื™ืš NGFW ื‘ืžืฉืจื“ ืฉืœืš, ื•ืœื ื ื“ืจืฉืช ื”ื’ื ืช L7 ืขืœ ื—ื•ืžืช ื”ืืฉ. ืžืกืคื™ืง ืœืกืคืง ืจืžื” ื˜ื•ื‘ื” ืฉืœ ื ืจืื•ืช ื•ื”ืชืจืื•ืช, ื•ื ื™ืชืŸ ืœืขืฉื•ืช ื–ืืช ื‘ืืžืฆืขื•ืช ืžื•ืฆืจื™ ืงื•ื“ ืคืชื•ื— ืœืžืฉืœ. ื›ืŸ, ื”ืชื’ื•ื‘ื” ืฉืœืš ืœืžืชืงืคื” ืœื ืชื”ื™ื” ืžื™ื™ื“ื™ืช, ืื‘ืœ ื”ืขื™ืงืจ ืฉืชืจืื” ืื•ืชื”, ื•ืขื ืชื”ืœื™ื›ื™ื ื ื›ื•ื ื™ื ื‘ืžื—ืœืงื” ืฉืœืš, ืชื•ื›ืœ ืœื ื˜ืจืœ ืื•ืชื” ื‘ืžื”ื™ืจื•ืช.

ื•ืชืŸ ืœื™ ืœื”ื–ื›ื™ืจ ืœืš ืฉืœืคื™ ื”ืงื•ื ืกืคื˜ ืฉืœ ืกื“ืจืช ื”ืžืืžืจื™ื ื”ื–ื•, ืืชื” ืœื ืžืขืฆื‘ ืจืฉืช, ืืชื” ืจืง ืžื ืกื” ืœืฉืคืจ ืืช ืžื” ืฉืงื™ื‘ืœืช.

ื ื™ืชื•ื— ื‘ื˜ื•ื— ืฉืœ ืืจื›ื™ื˜ืงื˜ื•ืจืช ืžืฉืจื“ื™ื

ืฉื™ืžื• ืœื‘ ืœืจื™ื‘ื•ืข ื”ืื“ื•ื ื”ื–ื” ืฉืžืžื ื• ื”ืงืฆืชื™ ืžืงื•ื ื‘ืชืจืฉื™ื ืžื“ืจื™ืš ื”ืื“ืจื™ื›ืœื•ืช ืฉืœ SAFE Secure Campusืฉืื ื™ ืจื•ืฆื” ืœื“ื•ืŸ ื‘ื• ื›ืืŸ.

ื›ื™ืฆื“ ืœื”ืฉืชืœื˜ ืขืœ ืชืฉืชื™ืช ื”ืจืฉืช ืฉืœืš. ืคืจืง ืฉืœื™ืฉื™. ืื‘ื˜ื—ืช ืจืฉืช. ื—ืœืง ืฉืœื™ืฉื™

ื–ื”ื• ืื—ื“ ืžืžืงื•ืžื•ืช ื”ืžืคืชื— ืฉืœ ื”ืื“ืจื™ื›ืœื•ืช ื•ืื—ื“ ืžืื™ ื”ื•ื•ื“ืื•ืช ื”ื—ืฉื•ื‘ื™ื ื‘ื™ื•ืชืจ.

ื”ืขืจื”:

ืžืขื•ืœื ืœื ื”ื’ื“ืจืชื™ ืื• ืขื‘ื“ืชื™ ืขื FirePower (ืžืงื• ื”ืืฉ ืฉืœ ืกื™ืกืงื• - ืจืง ASA), ืื– ืืชื™ื™ื—ืก ืœื–ื” ื›ืžื• ืœื›ืœ ื—ื•ืžืช ืืฉ ืื—ืจืช, ื›ืžื• Juniper SRX ืื• Palo Alto, ื‘ื”ื ื—ื” ืฉื™ืฉ ืœื” ืืช ืื•ืชืŸ ื™ื›ื•ืœื•ืช.

ืžื‘ื™ืŸ ื”ืขื™ืฆื•ื‘ื™ื ื”ืจื’ื™ืœื™ื, ืื ื™ ืจื•ืื” ืจืง 4 ืืคืฉืจื•ื™ื•ืช ืืคืฉืจื™ื•ืช ืœืฉื™ืžื•ืฉ ื‘ื—ื•ืžืช ืืฉ ืขื ื”ื—ื™ื‘ื•ืจ ื”ื–ื”:

  • ืฉืขืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืขื‘ื•ืจ ื›ืœ ืชืช ืจืฉืช ื”ื•ื ืžืชื’, ื‘ืขื•ื“ ื—ื•ืžืช ื”ืืฉ ื‘ืžืฆื‘ ืฉืงื•ืฃ (ื›ืœื•ืžืจ, ื›ืœ ื”ืชืขื‘ื•ืจื” ืขื•ื‘ืจืช ื“ืจื›ื”, ืื‘ืœ ื”ื™ื ืœื ื™ื•ืฆืจืช ื”ื•ืคืขืช L3)
  • ืฉืขืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืขื‘ื•ืจ ื›ืœ ืชืช-ืจืฉืช ื”ื•ื ืžืžืฉืงื™ ื”ืžืฉื ื” ืฉืœ ื—ื•ืžืช ื”ืืฉ (ืื• ืžืžืฉืงื™ SVI), ื”ืžืชื’ ืžืžืœื ืืช ื”ืชืคืงื™ื“ ืฉืœ L2
  • ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-VRFs ืฉื•ื ื™ื ืขืœ ื”ืžืชื’, ื•ืชืขื‘ื•ืจื” ื‘ื™ืŸ VRFs ืขื•ื‘ืจืช ื“ืจืš ื—ื•ืžืช ื”ืืฉ, ื”ืชืขื‘ื•ืจื” ื‘ืชื•ืš VRF ืื—ื“ ื ืฉืœื˜ืช ืขืœ ื™ื“ื™ ื”-ACL ืขืœ ื”ืžืชื’
  • ื›ืœ ื”ืชืขื‘ื•ืจื” ืžืฉืชืงืคืช ืœื—ื•ืžืช ื”ืืฉ ืœืฆื•ืจืš ื ื™ืชื•ื— ื•ื ื™ื˜ื•ืจ; ื”ืชืขื‘ื•ืจื” ืœื ืขื•ื‘ืจืช ื“ืจื›ื”

ื”ืขืจื” 1

ืฉื™ืœื•ื‘ื™ื ืฉืœ ืืคืฉืจื•ื™ื•ืช ืืœื” ืืคืฉืจื™ื™ื, ืืš ืœืฉื ื”ืคืฉื˜ื•ืช ืœื ื ืฉืงื•ืœ ืื•ืชื.

ืคืชืง 2

ื™ืฉื ื” ื’ื ืืคืฉืจื•ืช ืœื”ืฉืชืžืฉ ื‘-PBR (ืืจื›ื™ื˜ืงื˜ื•ืจืช ืฉืจืฉืจืช ืฉื™ืจื•ืชื™ื), ืื‘ืœ ื‘ื™ื ืชื™ื™ื ื–ื”, ืœืžืจื•ืช ืคืชืจื•ืŸ ื™ืคื” ืœื“ืขืชื™, ื”ื•ื ื“ื™ ืืงื–ื•ื˜ื™, ืื– ืื ื™ ืœื ืฉื•ืงืœ ืืช ื–ื” ื›ืืŸ.

ืžืชื™ืื•ืจ ื”ื–ืจื™ืžื•ืช ื‘ืžืกืžืš ืจื•ืื™ื ืฉื”ืชืขื‘ื•ืจื” ืขื“ื™ื™ืŸ ืขื•ื‘ืจืช ื“ืจืš ื—ื•ืžืช ื”ืืฉ, ื›ืœื•ืžืจ, ื‘ื”ืชืื ืœืชื›ื ื•ืŸ ืฉืœ ืกื™ืกืงื•, ื”ืื•ืคืฆื™ื” ื”ืจื‘ื™ืขื™ืช ืžืชื‘ื˜ืœืช.

ื‘ื•ืื• ื ืกืชื›ืœ ืชื—ื™ืœื” ืขืœ ืฉืชื™ ื”ืืคืฉืจื•ื™ื•ืช ื”ืจืืฉื•ื ื•ืช.
ืขื ืืคืฉืจื•ื™ื•ืช ืืœื”, ื›ืœ ื”ืชืขื‘ื•ืจื” ืขื•ื‘ืจืช ื“ืจืš ื—ื•ืžืช ื”ืืฉ.

ืขื›ืฉื™ื• ืื ื—ื ื• ืžืกืชื›ืœื™ื ื˜ื•ืคืก ืžื™ื“ืข, ืชืจืื” Cisco GPL ื•ืื ื—ื ื• ืจื•ืื™ื ืฉืื ืื ื—ื ื• ืจื•ืฆื™ื ืฉืจื•ื—ื‘ ื”ืคืก ื”ื›ื•ืœืœ ืฉืœ ื”ืžืฉืจื“ ืฉืœื ื• ื™ื”ื™ื” ืœืคื—ื•ืช ืกื‘ื™ื‘ 10 - 20 ื’ื™ื’ื”-ื‘ื™ื˜, ืื– ืื ื—ื ื• ื—ื™ื™ื‘ื™ื ืœืงื ื•ืช ืืช ื’ืจืกืช 4K.

ื”ืขืจื”:

ื›ืฉืื ื™ ืžื“ื‘ืจ ืขืœ ืจื•ื—ื‘ ื”ืคืก ื”ื›ื•ืœืœ, ืื ื™ ืžืชื›ื•ื•ืŸ ืœืชืขื‘ื•ืจื” ื‘ื™ืŸ ืจืฉืชื•ืช ืžืฉื ื” (ื•ืœื ื‘ืชื•ืš ื•ื™ืœืื ื” ืื—ืช).

ืžื”-GPL ืื ื• ืจื•ืื™ื ืฉืขื‘ื•ืจ ื—ื‘ื™ืœืช HA ืขื Threat Defense, ื”ืžื—ื™ืจ ื‘ื”ืชืื ืœื“ื’ื (4110 - 4150) ืžืฉืชื ื” ื‘ื™ืŸ ~0,5 - 2,5 ืžื™ืœื™ื•ืŸ ื“ื•ืœืจ.

ื›ืœื•ืžืจ, ื”ืขื™ืฆื•ื‘ ืฉืœื ื• ืžืชื—ื™ืœ ืœื”ื™ื“ืžื•ืช ืœื“ื•ื’ืžื” ื”ืงื•ื“ืžืช.

ื”ืื ื–ื” ืื•ืžืจ ืฉื”ืขื™ืฆื•ื‘ ื”ื–ื” ืฉื’ื•ื™?
ืœื, ื–ื” ืœื ืื•ืžืจ ืืช ื–ื”. ืกื™ืกืงื• ืžืขื ื™ืงื” ืœืš ืืช ื”ื”ื’ื ื” ื”ื˜ื•ื‘ื” ื‘ื™ื•ืชืจ ื”ืืคืฉืจื™ืช ื‘ื”ืชื‘ืกืก ืขืœ ืงื• ื”ืžื•ืฆืจื™ื ืฉื™ืฉ ืœื”. ืื‘ืœ ื–ื” ืœื ืื•ืžืจ ืฉื–ื” ื—ื•ื‘ื” ื‘ืฉื‘ื™ืœืš.

ื‘ืื•ืคืŸ ืขืงืจื•ื ื™ ื–ื• ืฉืืœื” ื ืคื•ืฆื” ืฉืขื•ืœื” ื‘ืชื›ื ื•ืŸ ืžืฉืจื“ ืื• ื“ืื˜ื” ืกื ื˜ืจ, ื•ื–ื” ืจืง ืื•ืžืจ ืฉืฆืจื™ืš ืœื—ืคืฉ ืคืฉืจื”.

ืœื“ื•ื’ืžื”, ืืœ ืชืชื ื• ืœื›ืœ ื”ืชืขื‘ื•ืจื” ืœืขื‘ื•ืจ ื“ืจืš ื—ื•ืžืช ืืฉ, ื•ื‘ืžืงืจื” ื–ื” ืืคืฉืจื•ืช 3 ื ืจืื™ืช ืœื™ ื“ื™ ื˜ื•ื‘ื”, ืื• (ืจืื” ืกืขื™ืฃ ืงื•ื“ื) ืื•ืœื™ ืื™ื ื›ื ื–ืงื•ืงื™ื ืœื”ื’ื ื” ืžืคื ื™ ืื™ื•ืžื™ื ืื• ืฉืื™ื ื›ื ืฆืจื™ื›ื™ื ื—ื•ืžืช ืืฉ ื›ืœืœ ืขืœ ื–ื”. ืงื˜ืข ืจืฉืช, ื•ืืชื” ืจืง ืฆืจื™ืš ืœื”ื’ื‘ื™ืœ ืืช ืขืฆืžืš ืœื ื™ื˜ื•ืจ ืคืกื™ื‘ื™ ื‘ืืžืฆืขื•ืช ืคืชืจื•ื ื•ืช ื‘ืชืฉืœื•ื (ืœื ื™ืงืจ) ืื• ืงื•ื“ ืคืชื•ื—, ืื• ืฉืืชื” ืฆืจื™ืš ื—ื•ืžืช ืืฉ, ืื‘ืœ ืžืกืคืง ืื—ืจ.

ื‘ื“ืจืš ื›ืœืœ ืชืžื™ื“ ื™ืฉ ืืช ื—ื•ืกืจ ื”ื•ื•ื“ืื•ืช ื”ื–ื” ื•ืื™ืŸ ืชืฉื•ื‘ื” ื‘ืจื•ืจื” ืื™ื–ื• ื”ื—ืœื˜ื” ื”ื™ื ื”ื˜ื•ื‘ื” ื‘ื™ื•ืชืจ ืขื‘ื•ืจืš.
ื–ื• ื”ืžื•ืจื›ื‘ื•ืช ื•ื”ื™ื•ืคื™ ืฉืœ ื”ืžืฉื™ืžื” ื”ื–ื•.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”