ããã«ã¡ã¯ãããã¯ãå瀟㮠NGFW ãœãªã¥ãŒã·ã§ã³ã«é¢ãã XNUMX çªç®ã®èšäºã§ãã
1.ã¯ããã«
ãŸãããã®ã²ãŒããŠã§ã€ããããã¯ãŒã¯ã«å®è£ ããããŸããŸãªæ¹æ³ã«ã€ããŠèª¬æããŸãã éžæããæ¥ç¶ãªãã·ã§ã³ã«ãã£ãŠã¯ãã²ãŒããŠã§ã€ã®ç¹å®ã®æ©èœãå©çšã§ããªãå Žåãããããšã«æ³šæããŠãã ããã UserGate ãœãªã¥ãŒã·ã§ã³ã¯ã次ã®æ¥ç¶ã¢ãŒãããµããŒãããŠããŸãã
-
L3-L7 ãã¡ã€ã¢ãŠã©ãŒã«
-
L2éæããªããž
-
L3éæããªããž
-
WCCP ãããã³ã«ã䜿çšããŠãä»®æ³çã«ã®ã£ããã«äŸµå ¥
-
ããªã·ãŒããŒã¹ã®ã«ãŒãã£ã³ã°ã䜿çšããŠä»®æ³çã«ã®ã£ããå ã«é 眮
-
ã¹ãã£ãã¯äžã®ã«ãŒã¿ãŒ
-
æ瀺çã«æå®ããã WEB ãããã·
-
ããã©ã«ãã²ãŒããŠã§ã€ãšããŠã®UserGate
-
ãã©ãŒããŒãç£èŠ
UserGate 㯠2 çš®é¡ã®ã¯ã©ã¹ã¿ãŒããµããŒãããŸãã
-
ã¯ã©ã¹ã¿ãŒæ§æã æ§æã¯ã©ã¹ã¿ãŒã«çµåãããããŒãã¯ãã¯ã©ã¹ã¿ãŒå šäœã§äžè²«ããèšå®ãç¶æããŸãã
-
ãã§ãŒã«ãªãŒã㌠ã¯ã©ã¹ã¿ãŒã æ倧 4 ã€ã®æ§æã¯ã©ã¹ã¿ãŒ ããŒãããã¢ã¯ãã£ã-ã¢ã¯ãã£ã ã¢ãŒããŸãã¯ã¢ã¯ãã£ã-ããã·ã ã¢ãŒãã§ã®åäœããµããŒããããã§ãŒã«ãªãŒã㌠ã¯ã©ã¹ã¿ãŒã«çµã¿åãããããšãã§ããŸãã è€æ°ã®ãã§ã€ã«ãªãŒã㌠ã¯ã©ã¹ã¿ãŒãæ§ç¯ããããšãå¯èœã§ãã
2. ã€ã³ã¹ããŒã«
åã®èšäºã§è¿°ã¹ãããã«ãUserGate ã¯ããŒããŠã§ã¢ãšãœãããŠã§ã¢ã®ããã±ãŒãžãšããŠæäŸãããããä»®æ³ç°å¢ã«å±éãããŸãã ãŠã§ããµã€ãäžã®å人ã¢ã«ãŠã³ããã
UserGate Web ãµã€ãã«ãããšãä»®æ³ãã·ã³ãæ£ããåäœããã«ã¯ãå°ãªããšã 8Gb ã® RAM ãš 2 ã³ã¢ã®ä»®æ³ããã»ããµã䜿çšããããšãæšå¥šãããŠããŸãã ãã€ããŒãã€ã¶ãŒã¯ 64 ããã ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ããµããŒãããå¿ èŠããããŸãã
ã€ã³ã¹ããŒã«ã¯ãéžæãããã€ããŒãã€ã¶ãŒ (VirtualBox ããã³ VMWare) ã«ã€ã¡ãŒãžãã€ã³ããŒãããããšããå§ãŸããŸãã Microsoft Hyper-v ããã³ KVM ã®å Žåãä»®æ³ãã·ã³ãäœæããããŠã³ããŒãããã€ã¡ãŒãžããã£ã¹ã¯ãšããŠæå®ããäœæããä»®æ³ãã·ã³ã®èšå®ã§çµ±åãµãŒãã¹ãç¡å¹ã«ããå¿ èŠããããŸãã
ããã©ã«ãã§ã¯ãVMWare ã«ã€ã³ããŒãããåŸã次ã®èšå®ã§ä»®æ³ãã·ã³ãäœæãããŸãã
äžã§è¿°ã¹ãããã«ãå°ãªããšã 8 GB ã® RAM ãå¿ èŠã§ãããããã« 1 ãŠãŒã¶ãŒããšã« 100 GB ãè¿œå ããå¿ èŠããããŸãã ããã©ã«ãã®ããŒã ãã©ã€ã ãµã€ãºã¯ 100 GB ã§ãããéåžžãããã§ã¯ãã¹ãŠã®ãã°ãšèšå®ãä¿åããã«ã¯ååã§ã¯ãããŸããã æšå¥šãµã€ãºã¯300GB以äžã§ãã ãããã£ãŠãä»®æ³ãã·ã³ã®ããããã£ã§ããã£ã¹ã¯ ãµã€ãºãç®çã®ãµã€ãºã«å€æŽããŸãã ä»®æ³ UserGate UTM ã«ã¯ãæåã¯ãŸãŒã³ã«å²ãåœãŠããã XNUMX ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ãä»å±ããŠããŸãã
管ç - ä»®æ³ãã·ã³ã®æåã®ã€ã³ã¿ãŒãã§ã€ã¹ãUserGate 管çãèš±å¯ãããŠããä¿¡é Œã§ãããããã¯ãŒã¯ã«æ¥ç¶ããããã®ãŸãŒã³ã
Trusted ã¯ä»®æ³ãã·ã³ã® XNUMX çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ãLAN ãããã¯ãŒã¯ãªã©ã®ä¿¡é Œã§ãããããã¯ãŒã¯ã«æ¥ç¶ããããã®ãŸãŒã³ã§ãã
Untrusted ã¯ä»®æ³ãã·ã³ã® XNUMX çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ãã€ã³ã¿ãŒããããªã©ã®ä¿¡é Œã§ããªããããã¯ãŒã¯ã«æ¥ç¶ãããŠããã€ã³ã¿ãŒãã§ã€ã¹ã®ãŸãŒã³ã§ãã
DMZ ã¯ä»®æ³ãã·ã³ã® XNUMX çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ãããDMZ ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããã€ã³ã¿ãŒãã§ã€ã¹ã®ãŸãŒã³ã§ãã
次ã«ãä»®æ³ãã·ã³ãèµ·åããŸããããã¥ã¢ã«ã«ã¯ããµããŒã ããŒã«ãéžæã㊠UTM ã®åºè·æèšå®ãžã®ãªã»ãããå®è¡ããå¿ èŠããããšèšèŒãããŠããŸãããã芧ã®ãšãããéžæè¢ã¯ XNUMX 〠(UTM ã®ååèµ·å) ã®ã¿ã§ãã ãã®æé äžã«ãUTM ã¯ãããã¯ãŒã¯ ã¢ããã¿ãèšå®ããããŒã ãã©ã€ã ããŒãã£ã·ã§ã³ã®ãµã€ãºããã£ã¹ã¯å šäœã®ãµã€ãºã«å¢ãããŸãã
UserGate Web ã€ã³ã¿ãŒãã§ã€ã¹ã«æ¥ç¶ããã«ã¯ã管çãŸãŒã³çµç±ã§ãã°ã€ã³ããå¿
èŠããããŸããeth0 ã€ã³ã¿ãŒãã§ã€ã¹ããããæ
åœããIP ã¢ãã¬ã¹ãèªåçã«ååŸããããã«æ§æãããŠããŸã (DHCP)ã DHCP ã䜿çšããŠç®¡çã€ã³ã¿ãŒãã§ã€ã¹ã®ã¢ãã¬ã¹ãèªåçã«å²ãåœãŠãããšãã§ããªãå Žåã¯ãCLI (ã³ãã³ã ã©ã€ã³ ã€ã³ã¿ãŒãã§ã€ã¹) ã䜿çšããŠæ瀺çã«èšå®ã§ããŸãã ãããè¡ãã«ã¯ãå®å
šãªç®¡çè
æš©é (ããã©ã«ãã§ã¯å€§æåã®ç®¡çè
) ãæã€ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã䜿çšã㊠CLI ã«ãã°ã€ã³ããå¿
èŠããããŸãã UserGate ããã€ã¹ãåæåãããŠããªãå ŽåãCLI ã«ã¢ã¯ã»ã¹ããã«ã¯ããŠãŒã¶ãŒåãšã㊠Admin ã䜿çšãããã¹ã¯ãŒããšã㊠utm ã䜿çšããå¿
èŠããããŸãã ãããŠã iface config âname eth0 âipv4 192.168.1.254/24 âenable true âmode static ã®ãããªã³ãã³ããå
¥åããŸãã åŸã§ãæå®ããã¢ãã¬ã¹ã«ãã UserGate Web ã³ã³ãœãŒã«ã«ã¢ã¯ã»ã¹ãããšã次ã®ããã«ãªããŸãã
Web ã³ã³ãœãŒã«ã§ã€ã³ã¹ããŒã«ãç¶è¡ããã€ã³ã¿ãŒãã§ãŒã¹èšèª (çŸæç¹ã§ã¯ãã·ã¢èªãŸãã¯è±èª)ãã¿ã€ã ãŸãŒã³ãéžæããã©ã€ã»ã³ã¹å¥çŽãèªãã§åæããå¿ èŠããããŸãã Web管çã€ã³ã¿ãŒãã§ãŒã¹ã«ãã°ã€ã³ããããã®ãã°ã€ã³åãšãã¹ã¯ãŒããèšå®ããŸãã
3.ã»ããã¢ãã
ã€ã³ã¹ããŒã«åŸã®ãã©ãããã©ãŒã 管ç Web ã€ã³ã¿ãŒãã§ã€ã¹ ãŠã£ã³ããŠã¯æ¬¡ã®ããã«ãªããŸãã
次ã«ããããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ãæ§æããå¿ èŠããããŸãã ãããè¡ãã«ã¯ããã€ã³ã¿ãŒãã§ã€ã¹ãã»ã¯ã·ã§ã³ã§ã€ã³ã¿ãŒãã§ã€ã¹ãæå¹ã«ããæ£ãã IP ã¢ãã¬ã¹ãèšå®ããé©åãªãŸãŒã³ãå²ãåœãŠãå¿ èŠããããŸãã
ãã€ã³ã¿ãŒãã§ã€ã¹ãã»ã¯ã·ã§ã³ã«ã¯ãã·ã¹ãã ã§äœ¿çšå¯èœãªãã¹ãŠã®ç©çã€ã³ã¿ãŒãã§ã€ã¹ãšä»®æ³ã€ã³ã¿ãŒãã§ã€ã¹ã衚瀺ããããããã®èšå®ãå€æŽããããVLAN ã€ã³ã¿ãŒãã§ã€ã¹ãè¿œå ãããã§ããŸãã ãŸããåã¯ã©ã¹ã¿ãŒ ããŒãã®ãã¹ãŠã®ã€ã³ã¿ãŒãã§ã€ã¹ã衚瀺ãããŸãã ã€ã³ã¿ãŒãã§ã€ã¹èšå®ã¯åããŒãã«åºæã§ããã€ãŸããã°ããŒãã«ã§ã¯ãããŸããã
ã€ã³ã¿ãŒãã§ãŒã¹ã®ããããã£ã§:
-
ã€ã³ã¿ãŒãã§ãŒã¹ãæå¹ãŸãã¯ç¡å¹ã«ãã
-
ã€ã³ã¿ãŒãã§ã€ã¹ ã¿ã€ããæå®ããŸã - ã¬ã€ã€ 3 ãŸãã¯ãã©ãŒ
-
ã€ã³ã¿ãŒãã§ã€ã¹ã«ãŸãŒã³ãå²ãåœãŠã
-
Netflow ãããã¡ã€ã«ãå²ãåœãŠãŠçµ±èšããŒã¿ã Netflow ã³ã¬ã¯ã¿ãŒã«éä¿¡ãã
-
ã€ã³ã¿ãŒãã§ã€ã¹ã®ç©çãã©ã¡ãŒã¿ã®å€æŽ - MAC ã¢ãã¬ã¹ãš MTU ãµã€ãº
-
IP ã¢ãã¬ã¹å²ãåœãŠã®ã¿ã€ããéžæããŸã - ã¢ãã¬ã¹ãªããéç IP ã¢ãã¬ã¹ããŸã㯠DHCP çµç±ã§ååŸ
-
éžæããã€ã³ã¿ãŒãã§ã€ã¹ã§ DHCP ãªã¬ãŒãæ§æããŸãã
ãè¿œå ããã¿ã³ã䜿çšãããšã次ã®ã¿ã€ãã®è«çã€ã³ã¿ãŒãã§ãŒã¹ãè¿œå ã§ããŸãã
-
VLAN
-
ãã³ã
-
æ©
-
PPPoEã®
-
VPN
-
ãã³ãã«
Usergate ã€ã¡ãŒãžã«å梱ãããŠããåè¿°ã®ãŸãŒã³ã«å ããŠãããã« XNUMX ã€ã®äºåå®çŸ©ãããã¿ã€ãããããŸãã
ã¯ã©ã¹ã¿ãŒ - ã¯ã©ã¹ã¿ãŒæäœã«äœ¿çšãããã€ã³ã¿ãŒãã§ãŒã¹ã®ãŸãŒã³
ãµã€ãéVPN - VPNçµç±ã§UserGateã«æ¥ç¶ãããŠãããã¹ãŠã®Office-Officeã¯ã©ã€ã¢ã³ããé 眮ããããŸãŒã³
ãªã¢ãŒã ã¢ã¯ã»ã¹çšã® VPN - VPN çµç±ã§ UserGate ã«æ¥ç¶ããŠãããã¹ãŠã®ã¢ãã€ã« ãŠãŒã¶ãŒãå«ããŸãŒã³
UserGate 管çè ã¯ãããã©ã«ã ãŸãŒã³ã®èšå®ãå€æŽããããè¿œå ã®ãŸãŒã³ãäœæãããã§ããŸãããããŒãžã§ã³ 5 ã®ããã¥ã¢ã«ã«èšèŒãããŠããããã«ãäœæã§ãããŸãŒã³ã¯æ倧 15 åã§ãã ããããå€æŽãŸãã¯äœæããã«ã¯ããŸãŒã³ã»ã¯ã·ã§ã³ã«ç§»åããå¿ èŠããããŸãã ãŸãŒã³ããšã«ãã±ãã ããããã®ãããå€ãèšå®ã§ããŸããSYNãUDPãICMP ããµããŒããããŠããŸãã Usergate ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ãæ§æããããªãããŸãã«å¯Ÿããä¿è·ãæå¹ã«ãªããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹ãèšå®ããåŸããã²ãŒããŠã§ã€ãã»ã¯ã·ã§ã³ã§ããã©ã«ã ã«ãŒããèšå®ããå¿ èŠããããŸãã ãããã®ã UserGate ãã€ã³ã¿ãŒãããã«æ¥ç¶ããã«ã¯ã2 ã€ä»¥äžã®ã²ãŒããŠã§ã€ã® IP ã¢ãã¬ã¹ãæå®ããå¿ èŠããããŸãã è€æ°ã®ãããã€ããŒã䜿çšããŠã€ã³ã¿ãŒãããã«æ¥ç¶ããå Žåã¯ãè€æ°ã®ã²ãŒããŠã§ã€ãæå®ããå¿ èŠããããŸãã ã²ãŒããŠã§ã€æ§æã¯ã¯ã©ã¹ã¿ãŒ ããŒãããšã«äžæã§ãã XNUMX ã€ä»¥äžã®ã²ãŒããŠã§ã€ãæå®ãããŠããå Žåã¯ãXNUMX ã€ã®ãªãã·ã§ã³ãå¯èœã§ãã
-
ã²ãŒããŠã§ã€éã®ãã©ãã£ãã¯ã®ãã©ã³ã¹ããšãã
-
ã¡ã€ã³ã²ãŒããŠã§ã€ãã¹ãã¢ã²ãŒããŠã§ã€ã«åãæ¿ããŸãã
ã²ãŒããŠã§ã€ã®ã¹ããŒã¿ã¹ (å©çšå¯èœ - ç·ãå©çšäžå¯ - èµ€) ã¯æ¬¡ã®ããã«æ±ºå®ãããŸãã
-
ãããã¯ãŒã¯ ãã§ãã¯ãç¡å¹ã«ãªã£ãŠããŸããUserGate ã ARP ãªã¯ãšã¹ãã䜿çšã㊠MAC ã¢ãã¬ã¹ãååŸã§ããå Žåãã²ãŒããŠã§ã€ã¯ã¢ã¯ã»ã¹å¯èœã§ãããšèŠãªãããŸãã ãã®ã²ãŒããŠã§ã€ãä»ããã€ã³ã¿ãŒããã ã¢ã¯ã»ã¹ã®ãã§ãã¯ã¯ãããŸããã ã²ãŒããŠã§ã€ã® MAC ã¢ãã¬ã¹ãç¹å®ã§ããªãå Žåãã²ãŒããŠã§ã€ã¯å°éäžèœãšã¿ãªãããŸãã
-
ãããã¯ãŒã¯ãã§ãã¯ãæå¹ã«ãªã£ãŠããŸã - 次ã®å Žåãã²ãŒããŠã§ã€ã¯ã¢ã¯ã»ã¹å¯èœã§ãããšã¿ãªãããŸãã
-
UserGate ã¯ãARP ãªã¯ãšã¹ãã䜿çšã㊠MAC ã¢ãã¬ã¹ãååŸã§ããŸãã
-
ãã®ã²ãŒããŠã§ã€ãä»ããã€ã³ã¿ãŒããã ã¢ã¯ã»ã¹ã®ãã§ãã¯ã¯æ£åžžã«å®äºããŸããã
ãã以å€ã®å Žåãã²ãŒããŠã§ã€ã¯äœ¿çšã§ããªããšã¿ãªãããŸãã
ãDNSãã»ã¯ã·ã§ã³ã§ã¯ãUserGate ã䜿çšãã DNS ãµãŒããŒãè¿œå ããå¿ èŠããããŸãã ãã®èšå®ã¯ã[ã·ã¹ãã DNS ãµãŒããŒ] é åã§æå®ããŸãã ãŠãŒã¶ãŒããã® DNS ãªã¯ãšã¹ãã管çããããã®èšå®ã¯æ¬¡ã®ãšããã§ãã UserGate ã䜿çšãããšãDNS ãããã·ã䜿çšã§ããŸãã DNS ãããã· ãµãŒãã¹ã䜿çšãããšããŠãŒã¶ãŒããã® DNS èŠæ±ãã€ã³ã¿ãŒã»ãããã管çè ã®ããŒãºã«å¿ããŠå€æŽã§ããŸãã DNS ãããã· ã«ãŒã«ã䜿çšããŠãç¹å®ã®ãã¡ã€ã³ãžã®èŠæ±ã®è»¢éå ãšãªã DNS ãµãŒããŒãæå®ã§ããŸãã ãŸããDNS ãããã·ã䜿çšãããšããã¹ãã¿ã€ãã®éçã¬ã³ãŒã (A ã¬ã³ãŒã) ãèšå®ã§ããŸãã
ãNAT ãšã«ãŒãã£ã³ã°ãã»ã¯ã·ã§ã³ã§ã¯ãå¿ èŠãª NAT ã«ãŒã«ãäœæããå¿ èŠããããŸãã ä¿¡é Œã§ãããããã¯ãŒã¯ã®ãŠãŒã¶ãŒãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããå ŽåãNAT ã«ãŒã«ãä¿¡é Œã§ãã -> ä¿¡é Œã§ããªããããã§ã«äœæãããŠãããããããšã¯ãããæå¹ã«ããã ãã§ãã ã«ãŒã«ã¯ãã³ã³ãœãŒã«ã«ãªã¹ããããŠããé åºã§äžããäžã«é©çšãããŸãã ã«ãŒã«ã§æå®ãããæ¡ä»¶ãäžèŽããæåã®ã«ãŒã«ã®ã¿ãåžžã«å®è¡ãããŸãã ã«ãŒã«ãããªã¬ãŒãããã«ã¯ãã«ãŒã« ãã©ã¡ãŒã¿ãŒã§æå®ããããã¹ãŠã®æ¡ä»¶ãäžèŽããå¿ èŠããããŸãã UserGate ã§ã¯ãäžè¬ç㪠NAT ã«ãŒã«ãããšãã°ããŒã«ã« ãããã¯ãŒã¯ (éåžžã¯ä¿¡é Œã§ãããŸãŒã³) ããã€ã³ã¿ãŒããã (éåžžã¯ä¿¡é Œã§ããªããŸãŒã³) ãžã® NAT ã«ãŒã«ãäœæãããã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ã䜿çšããŠãŠãŒã¶ãŒããµãŒãã¹ãããã³ã¢ããªã±ãŒã·ã§ã³ã«ããã¢ã¯ã»ã¹ãå¶éããããšããå§ãããŸãã
DNAT ã«ãŒã«ãããŒã転éãããªã·ãŒããŒã¹ã®ã«ãŒãã£ã³ã°ããããã¯ãŒã¯ ãããã³ã°ãäœæããããšãã§ããŸãã
ãã®åŸãããã¡ã€ã¢ãŠã©ãŒã«ãã»ã¯ã·ã§ã³ã§ãã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ãäœæããå¿ èŠããããŸãã ä¿¡é Œã§ãããããã¯ãŒã¯ã®ãŠãŒã¶ãŒãã€ã³ã¿ãŒãããã«ç¡å¶éã«ã¢ã¯ã»ã¹ã§ããããã«ããä¿¡é Œã§ããã€ã³ã¿ãŒãããããšãããã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ããã§ã«äœæãããŠãããæå¹ã«ããå¿ èŠããããŸãã 管çè ã¯ããã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ã䜿çšããŠãUserGate ãééããããããçš®é¡ã®ãã©ã³ãžãã ãããã¯ãŒã¯ ãã©ãã£ãã¯ãèš±å¯ãŸãã¯æåŠã§ããŸãã ã«ãŒã«æ¡ä»¶ã«ã¯ããŸãŒã³ãšéä¿¡å /å®å IP ã¢ãã¬ã¹ããŠãŒã¶ãŒãšã°ã«ãŒãããµãŒãã¹ãšã¢ããªã±ãŒã·ã§ã³ãå«ããããšãã§ããŸãã ã«ãŒã«ã¯ãNAT ãšã«ãŒãã£ã³ã°ãã»ã¯ã·ã§ã³ãšåãæ¹æ³ã§é©çšãããŸãã ãããããŠã³ã ã«ãŒã«ãäœæãããŠããªãå ŽåãUserGate ãééãããã©ã³ãžãã ãã©ãã£ãã¯ã¯çŠæ¢ãããŸãã
4ã çµè«
ããã§èšäºã¯çµããã§ãã UserGate ãã¡ã€ã¢ãŠã©ãŒã«ãä»®æ³ãã·ã³ã«ã€ã³ã¹ããŒã«ããã€ã³ã¿ãŒããããä¿¡é Œããããããã¯ãŒã¯ã§åäœããããã«å¿ èŠãªæå°éã®èšå®ãè¡ããŸããã 次ã®èšäºã§ããã«è©³ããæ§æãæ€èšããŸãã
ç§ãã¡ã®ãã£ã³ãã«ã§ææ°æ
å ±ããã§ãã¯ããŠãã ããïŒ
åºæïŒ habr.com