äžå°äŒæ¥åãã® NGFW ã«é¢ããäžé£ã®èšäºãç¶ããŠããŸãããæ°ãã 1500 ã·ãªãŒãº ã¢ãã«ç¯å²ãã¬ãã¥ãŒããŠããããšãæãåºããŠãã ããã ã§
- SMB åãã® VPN æ©èœã
- å°èŠæš¡ãªãã£ã¹åãã®ãªã¢ãŒã ã¢ã¯ã»ã¹ã®æ§æã
- æ¥ç¶å¯èœãªã¯ã©ã€ã¢ã³ãã
1. SMB åãã® VPN ãªãã·ã§ã³
ä»æ¥ã®è³æãæºåããããã«ãå
¬åŒ
- ãµã€ãéã ãªãã£ã¹éã« VPN ãã³ãã«ãäœæãããšããŠãŒã¶ãŒã¯åããããŒã«ã«ããããã¯ãŒã¯äžã«ãããã®ããã«äœæ¥ã§ããŸãã
- ãªã¢ãŒãã¢ã¯ã»ã¹ã ãŠãŒã¶ãŒãšã³ãããã€ã¹ (PCãæºåž¯é»è©±ãªã©) ã䜿çšãããªãã£ã¹ãªãœãŒã¹ãžã®ãªã¢ãŒãæ¥ç¶ã ããã«ãSSL Network Extender ããããããã䜿çšãããšãåã
ã®ã¢ããªã±ãŒã·ã§ã³ãå
¬éããJava ã¢ãã¬ããã䜿çšã㊠SSL çµç±ã§æ¥ç¶ããŠå®è¡ã§ããŸãã 泚æïŒ Mobile Access Portal (Gaia Embedded ã¯ãµããŒããããŠããŸãã) ãšæ··åããªãã§ãã ããã
ããã« èè
ã®ã³ãŒã¹ãTS Solutionãã匷ããå§ãããŸã -
2. å°èŠæš¡ãªãã£ã¹åãã®ãªã¢ãŒã ã¢ã¯ã»ã¹
ããªãã®ãªãã£ã¹ãžã®ãªã¢ãŒãæ¥ç¶ã®æºåãéå§ããŸãã
- ãŠãŒã¶ãŒãã²ãŒããŠã§ã€ã䜿çšã㊠VPN ãã³ãã«ãæ§ç¯ããã«ã¯ããããªã㯠IP ã¢ãã¬ã¹ãå¿
èŠã§ãã ãã§ã«åæèšå®ãå®äºããŠããå ŽåïŒ
2ã®èšäº ãµã€ã¯ã«ãã)ãéåžžãå€éšãªã³ã¯ã¯ãã§ã«ã¢ã¯ãã£ãã«ãªã£ãŠããŸãã æ å ±ã¯ãGaia Portal ã«ã¢ã¯ã»ã¹ããŠã芧ãã ããã ããã€ã¹ â ãããã¯ãŒã¯ â ã€ã³ã¿ãŒããã
äŒç€Ÿãåçãããªã㯠IP ã¢ãã¬ã¹ã䜿çšããŠããå Žåã¯ãåç DNS ãèšå®ã§ããŸãã ã«è¡ã ããã€ã¹ â DDNS ãšããã€ã¹ã¢ã¯ã»ã¹
çŸåšãDynDns ãš no-ip.com ã® XNUMX ã€ã®ãããã€ããŒããµããŒãããŠããŸãã ãã®ãªãã·ã§ã³ãæå¹ã«ããã«ã¯ãè³æ Œæ å ± (ãã°ã€ã³ããã¹ã¯ãŒã) ãå ¥åããå¿ èŠããããŸãã
- 次ã«ããŠãŒã¶ãŒ ã¢ã«ãŠã³ããäœæããŸããããããã¯èšå®ããã¹ãããã®ã«åœ¹ç«ã¡ãŸãã VPN â ãªã¢ãŒãã¢ã¯ã»ã¹ â ãªã¢ãŒãã¢ã¯ã»ã¹ãŠãŒã¶ãŒ
ã°ã«ãŒã (äŸ: ãªã¢ãŒãã¢ã¯ã»ã¹) ã§ãã¹ã¯ãªãŒã³ã·ã§ããã®æ瀺ã«åŸã£ãŠãŠãŒã¶ãŒãäœæããŸãã ã¢ã«ãŠã³ãã®ã»ããã¢ããã¯æšæºã§ããããã°ã€ã³ãšãã¹ã¯ãŒããèšå®ããããã«ãªã¢ãŒã ã¢ã¯ã»ã¹èš±å¯ãªãã·ã§ã³ãæå¹ã«ããŸãã
èšå®ãæ£åžžã«é©çšããããšãããŒã«ã« ãŠãŒã¶ãŒãšããŒã«ã« ãŠãŒã¶ãŒ ã°ã«ãŒãã® XNUMX ã€ã®ãªããžã§ã¯ãã衚瀺ãããŸãã
- 次ã®ã¹ãããã¯ã VPN â ãªã¢ãŒã ã¢ã¯ã»ã¹ â ãã¬ãŒã ã³ã³ãããŒã«ã ãã¬ãŒãã®é»æºããªã³ã«ãªã£ãŠããŠããªã¢ãŒã ãŠãŒã¶ãŒããã®ãã©ãã£ãã¯ãèš±å¯ãããŠããããšã確èªããŠãã ããã
- *äžèšã¯ããªã¢ãŒã ã¢ã¯ã»ã¹ãèšå®ããããã®æå°éã®æé ã§ãã ãã ããæ¥ç¶ããã¹ãããåã«ãã¿ãã«ç§»åããŠè©³çŽ°èšå®ã調ã¹ãŠã¿ãŸããã VPN â ãªã¢ãŒãã¢ã¯ã»ã¹ â 詳现
çŸåšã®èšå®ã«åºã¥ããšããªã¢ãŒã ãŠãŒã¶ãŒãæ¥ç¶ãããšããªãã£ã¹ ã¢ãŒã ãªãã·ã§ã³ã®ãããã§ãããã¯ãŒã¯ 172.16.11.0/24 ãã IP ã¢ãã¬ã¹ãåãåãããšãããããŸãã ããã¯ã200 ã®ç«¶åã©ã€ã»ã³ã¹ (1590 NGFW Check Point ã«ç€ºãããŠãã) ã䜿çšããããã®äºåãåãããã®ã§ååã§ãã
ãªãã·ã§ã³ ãæ¥ç¶ãããã¯ã©ã€ã¢ã³ãããã®ã€ã³ã¿ãŒããã ãã©ãã£ãã¯ããã®ã²ãŒããŠã§ã€çµç±ã§ã«ãŒãã£ã³ã°ããã ã¯ãªãã·ã§ã³ã§ããããªã¢ãŒã ãŠãŒã¶ãŒããã®ãã¹ãŠã®ãã©ãã£ãã¯ãã²ãŒããŠã§ã€çµç±ã§ã«ãŒãã£ã³ã°ããŸã (ã€ã³ã¿ãŒãããæ¥ç¶ãå«ã)ã ããã«ããããŠãŒã¶ãŒã®ãã©ãã£ãã¯ãæ€æ»ããããŸããŸãªè åšããã«ãŠã§ã¢ããã¯ãŒã¯ã¹ããŒã·ã§ã³ãä¿è·ã§ããŸãã
- *ãªã¢ãŒã ã¢ã¯ã»ã¹ã®ã¢ã¯ã»ã¹ ããªã·ãŒã®æäœ
ãªã¢ãŒã ã¢ã¯ã»ã¹ãæ§æããåŸãèªåã¢ã¯ã»ã¹ ã«ãŒã«ããã¡ã€ã¢ãŠã©ãŒã« ã¬ãã«ã§äœæãããŸãããããã衚瀺ããã«ã¯ã次ã®ã¿ãã«ç§»åããå¿ èŠããããŸãã ã¢ã¯ã»ã¹ ããªã·ãŒ â ãã¡ã€ã¢ãŠã©ãŒã« â ããªã·ãŒ
ãã®å Žåã以åã«äœæããã°ã«ãŒãã®ã¡ã³ããŒã§ãããªã¢ãŒã ãŠãŒã¶ãŒã¯ãäŒç€Ÿã®ãã¹ãŠã®å éšãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸããã«ãŒã«ã¯äžè¬ã»ã¯ã·ã§ã³ã«ããããšã«æ³šæããŠãã ããã ãåä¿¡ãã©ãã£ãã¯ãå éšãã©ãã£ãã¯ãVPN ãã©ãã£ãã¯ãã ã€ã³ã¿ãŒããããžã® VPN ãŠãŒã¶ãŒ ãã©ãã£ãã¯ãèš±å¯ããã«ã¯ãäžè¬ã»ã¯ã·ã§ã³ããã§å¥ã®ã«ãŒã«ãäœæããå¿ èŠããããŸããã€ã³ã¿ãŒããããžã®çºä¿¡ã¢ã¯ã»ã¹"ã
-
æåŸã«ããŠãŒã¶ãŒã NGFW ã²ãŒããŠã§ã€ãžã® VPN ãã³ãã«ãæ£åžžã«äœæããäŒç€Ÿã®å éšãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããããšã確èªããå¿ èŠããããŸãã ãããè¡ãã«ã¯ããã¹ã察象ã®ãã¹ãã« VPN ã¯ã©ã€ã¢ã³ããã€ã³ã¹ããŒã«ããå¿ èŠããããŸãããã«ããæäŸãããŠããŸãã
ãªã³ã¯ ç©ã¿èŸŒã¿çšã ã€ã³ã¹ããŒã«åŸãæ°ãããµã€ããè¿œå ããããã®æšæºæé ãå®è¡ããå¿ èŠããããŸã (ã²ãŒããŠã§ã€ã®ãããªã㯠IP ã¢ãã¬ã¹ãæå®ããŸã)ã 䟿å®äžãããã»ã¹ã¯ GIF 圢åŒã§è¡šç€ºãããŸã
æ¥ç¶ããã§ã«ç¢ºç«ãããŠããå Žåã¯ãCMD ã®ã³ãã³ãã䜿çšããŠããã¹ã ãã·ã³ã§åä¿¡ãã IP ã¢ãã¬ã¹ã確èªããŠã¿ãŸãããã IPCONFIG
ä»®æ³ãããã¯ãŒã¯ ã¢ããã¿ãŒã NGFW ã®ãªãã£ã¹ ã¢ãŒããã IP ã¢ãã¬ã¹ãåä¿¡ãããã±ãããæ£åžžã«éä¿¡ãããããšã確èªããŸããã å®äºããã«ã¯ãGaia Portal ã«ç§»åããŸãã VPN â ãªã¢ãŒãã¢ã¯ã»ã¹ â æ¥ç¶ãããŠãããªã¢ãŒããŠãŒã¶ãŒ
ãŠãŒã¶ãŒãntuserããæ¥ç¶æžã¿ãšããŠè¡šç€ºãããŸãã次ã®å Žæã«ç§»åããŠã€ãã³ã ãã°ã確èªããŠã¿ãŸãããã ãã°ãšç£èŠ â ã»ãã¥ãªãã£ãã°
æ¥ç¶ã¯ããœãŒã¹ãšã㊠IP ã¢ãã¬ã¹ã䜿çšããŠãã°ã«èšé²ãããŸã: 172.16.10.1 - ããã¯ããŠãŒã¶ãŒããªãã£ã¹ ã¢ãŒããéããŠåä¿¡ããã¢ãã¬ã¹ã§ãã
3. ãªã¢ãŒã ã¢ã¯ã»ã¹ã§ãµããŒããããã¯ã©ã€ã¢ã³ã
SMB ãã¡ããªã® NGFW Check Point ã䜿çšããŠãªãã£ã¹ãžã®ãªã¢ãŒãæ¥ç¶ãèšå®ããæé ã確èªããåŸãããŸããŸãªããã€ã¹ã®ã¯ã©ã€ã¢ã³ã ãµããŒãã«ã€ããŠæžããããšæããŸãã
Windows/Mac OS çšãšã³ããã€ã³ã VPN - ã¢ãã€ã«ã¯ã©ã€ã¢ã³ã (
Android /IOS ) - L2TP ãã€ãã£ã ã¯ã©ã€ã¢ã³ã (Check Point 㯠Microsoft ã®ãã€ãã£ã VPN ã¢ããªã®ãµããŒãã䞻匵ããŠããŸã)ã
ãµããŒããããŠãããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ãšããã€ã¹ã®çš®é¡ãè±å¯ãªãããNGFW ã«ä»å±ããã©ã€ã»ã³ã¹ãæ倧éã«æŽ»çšã§ããŸãã å¥ã®ããã€ã¹ãèšå®ããã«ã¯äŸ¿å©ãªãªãã·ã§ã³ããããŸã ãæ¥ç¶æ¹æ³ã
èšå®ã«åŸã£ãŠã¹ããããèªåçã«çæãããããã管çè ã¯åé¡ãªãæ°ããã¯ã©ã€ã¢ã³ããã€ã³ã¹ããŒã«ã§ããŸãã
çµè«ïŒ ãã®èšäºãèŠçŽããããã«ãNGFW Check Point SMB ãã¡ããªã® VPN æ©èœã調ã¹ãŸããã 次ã«ããŠãŒã¶ãŒããªãã£ã¹ã«ãªã¢ãŒãæ¥ç¶ããå Žåã®ãªã¢ãŒã ã¢ã¯ã»ã¹ã®èšå®æé ã説æããç£èŠããŒã«ã«ã€ããŠæ€èšããŸããã èšäºã®æåŸã§ã¯ããªã¢ãŒã ã¢ã¯ã»ã¹ã§å©çšå¯èœãªã¯ã©ã€ã¢ã³ããšæ¥ç¶ãªãã·ã§ã³ã«ã€ããŠèª¬æããŸããã ãããã£ãŠãæ¯åºã¯ãããŸããŸãªå€éšã®è åšãèŠå ã«ãããããããVPN ãã¯ãããžãŒã䜿çšããŠåŸæ¥å¡ã®æ¥åã®ç¶ç¶æ§ãšã»ãã¥ãªãã£ã確ä¿ã§ããŸãã
TS ãœãªã¥ãŒã·ã§ã³ã® Check Point ã«é¢ããè±å¯ãªè³æ ã ä¹ããæåŸ ïŒTelegram ,Facebook ,VK ,TSãœãªã¥ãŒã·ã§ã³ããã° ,Yandex.Den ).
åºæïŒ habr.com