ããã£ããããŸãïŒ ä»åã¯ã¡ãŒã«ã²ãŒããŠã§ã€ã®åæèšå®æ¹æ³ã説æããŸãã
çŸåšã®ã¬ã€ã¢ãŠãããå§ããŸãããã ãããäžã®å³ã«ç€ºããŸãã
å³åŽã«ã¯å€éšãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã衚瀺ãããŠãããããããå
éšãããã¯ãŒã¯äžã®ãŠãŒã¶ãŒã«ã¡ãŒã«ãéä¿¡ãããŸãã å
éšãããã¯ãŒã¯ã«ã¯ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãDNS ãµãŒããŒãå®è¡ãããŠãããã¡ã€ã³ ã³ã³ãããŒã©ãŒãããã³ã¡ãŒã« ãµãŒããŒãå«ãŸããŠããŸãã ãããã¯ãŒã¯ã®ãšããžã«ã¯ãã¡ã€ã¢ãŠã©ãŒã« - FortiGate ãããããã®äž»ãªæ©èœã¯ SMTP ããã³ DNS ãã©ãã£ãã¯è»¢éãæ§æããããšã§ãã
DNS ã«ã¯ç¹ã«æ³šæããŠãã ããã
ã€ã³ã¿ãŒãããäžã§é»åã¡ãŒã«ãã«ãŒãã£ã³ã°ããããã«äœ¿çšããã DNS ã¬ã³ãŒãã¯ãA ã¬ã³ãŒããš MX ã¬ã³ãŒãã® 10.10.30.210 ã€ã§ãã éåžžããããã® DNS ã¬ã³ãŒãã¯ãããªã㯠DNS ãµãŒããŒäžã«æ§æãããŸãããã¬ã€ã¢ãŠãã®å¶éã«ãããåã«ãã¡ã€ã¢ãŠã©ãŒã«çµç±ã§ DNS ã転éããŸã (ã€ãŸããå€éšãŠãŒã¶ãŒã®ã¢ãã¬ã¹ XNUMX ã DNS ãµãŒããŒãšããŠç»é²ãããŠããŸã)ã
MX ã¬ã³ãŒãã¯ããã¡ã€ã³ã«ãµãŒãã¹ãæäŸããã¡ãŒã« ãµãŒããŒã®ååãšããã®ã¡ãŒã« ãµãŒããŒã®åªå é äœãå«ãã¬ã³ãŒãã§ãã ãã®äŸã§ã¯ãtest.local -> mail.test.local 10 ã®ããã«ãªããŸãã
ã¬ã³ãŒãã¯ãã¡ã€ã³åã IP ã¢ãã¬ã¹ã«å€æããã¬ã³ãŒãã§ãããã§ã¯ mail.test.local -> 10.10.30.210 ãšãªããŸãã
å€éšãŠãŒã¶ãŒãé»åã¡ãŒã«ãéä¿¡ããããšãããšã [ã¡ãŒã«ä¿è·]ãDNS MX ãµãŒããŒã« test.local ãã¡ã€ã³ ã¬ã³ãŒããã¯ãšãªããŸãã DNS ãµãŒããŒã¯ã¡ãŒã« ãµãŒããŒã®åå mail.test.local ã§å¿çããŸãã ããã§ããŠãŒã¶ãŒã¯ãã®ãµãŒããŒã® IP ã¢ãã¬ã¹ãååŸããå¿ èŠããããããA ã¬ã³ãŒãã® DNS ã«å床ã¢ã¯ã»ã¹ããIP ã¢ãã¬ã¹ 10.10.30.210 ãåãåããŸã (ã¯ãããŸã :) )ã æçŽãéãããšãã§ããŸãã ãããã£ãŠãããŒã 25 ã§åä¿¡ãã IP ã¢ãã¬ã¹ãžã®æ¥ç¶ã確ç«ããããšããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã«ã䜿çšããŠããã®æ¥ç¶ã¯ã¡ãŒã« ãµãŒããŒã«è»¢éãããŸãã
çŸåšã®ã¬ã€ã¢ãŠãç¶æ ã§ã¡ãŒã«ã®æ©èœã確èªããŠã¿ãŸãããã ãããè¡ãã«ã¯ãå€éšãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ã§ swaks ãŠãŒãã£ãªãã£ã䜿çšããŸãã ãããå©çšãããšãããŸããŸãªãã©ã¡ãŒã¿ãŒã®ã»ãããå«ãã¬ã¿ãŒãåä¿¡è ã«éä¿¡ããŠãSMTP ã®ããã©ãŒãã³ã¹ããã¹ãã§ããŸãã 以åã¯ãã¡ãŒã«ããã¯ã¹ãæã€ãŠãŒã¶ãŒãã¡ãŒã« ãµãŒããŒäžã«ãã§ã«äœæãããŠããŸããã [ã¡ãŒã«ä¿è·]ã 圌ã«æçŽãéã£ãŠã¿ãŸããã:
次ã«ãå
éšãŠãŒã¶ãŒã®ãã·ã³ã«ç§»åããŠãæçŽãå°çããŠããããšã確èªããŸãããã
æçŽã¯å®éã«å±ããŸãã (ãªã¹ãå
ã§åŒ·èª¿è¡šç€ºãããŠããŸã)ã ããã¯ãã¬ã€ã¢ãŠããæ£ããæ©èœããŠããããšãæå³ããŸãã ä»åºŠã¯ FortiMail ã«ç§»ããŸãã ã¬ã€ã¢ãŠãã«è¿œå ããŸããã:
FortiMail 㯠XNUMX ã€ã®ã¢ãŒãã§å±éã§ããŸãã
- ã²ãŒããŠã§ã€ - æ¬æ Œç㪠MTA ãšããŠæ©èœããŸãããã¹ãŠã®ã¡ãŒã«ãåŒãç¶ãããã§ãã¯ããŠãã¡ãŒã« ãµãŒããŒã«è»¢éããŸãã
- éé - èšãæããã°ãééã¢ãŒãã ãµãŒããŒã®åã«ã€ã³ã¹ããŒã«ãããéåä¿¡ã¡ãŒã«ããã§ãã¯ããŸãã ãã®åŸããµãŒããŒã«éä¿¡ããŸãã ãããã¯ãŒã¯æ§æãå€æŽããå¿ èŠã¯ãããŸããã
- ãµãŒã㌠- ãã®å ŽåãFortiMail ã¯ãã¡ãŒã«ããã¯ã¹ã®äœæãã¡ãŒã«ã®éåä¿¡ããã®ä»ã®æ©èœãåããæ¬æ Œçãªã¡ãŒã« ãµãŒããŒã§ãã
FortiMail ãã²ãŒããŠã§ã€ ã¢ãŒãã§å±éããŸãã ä»®æ³ãã·ã³ã®èšå®ã«é²ã¿ãŸãããã ãã°ã€ã³ã¯ admin ã§ããã¹ã¯ãŒãã¯æå®ãããŠããŸããã åããŠãã°ã€ã³ãããšãã¯ãæ°ãããã¹ã¯ãŒããèšå®ããå¿ èŠããããŸãã
次ã«ãWeb ã€ã³ã¿ãŒãã§ã€ã¹ã«ã¢ã¯ã»ã¹ããããã«ä»®æ³ãã·ã³ãæ§æããŸãããã ãã·ã³ãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããããšãå¿ èŠã§ãã ã€ã³ã¿ãŒãã§ãŒã¹ãèšå®ããŸãããã å¿ èŠãªã®ã¯ããŒã1ã ãã§ãã ãã®å©ããåããŠãWeb ã€ã³ã¿ãŒãã§ã€ã¹ã«æ¥ç¶ããã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããããã«ã䜿çšãããŸãã ãµãŒãã¹ (ãŠã€ã«ã¹å¯Ÿçã·ã°ããã£ãªã©) ãæŽæ°ããã«ã¯ãã€ã³ã¿ãŒããã ã¢ã¯ã»ã¹ãå¿ èŠã§ãã èšå®ããã«ã¯ã次ã®ã³ãã³ããå ¥åããŸãã
ã·ã¹ãã ã€ã³ã¿ãŒãã§ã€ã¹ã®èšå®
ããŒã1ãç·šé
IP ãèšå® 192.168.1.40 255.255.255.0
èš±å¯ã¢ã¯ã»ã¹ https http ssh ping ãèšå®ããŸã
end
次ã«ãã«ãŒãã£ã³ã°ãèšå®ããŸãããã ãããè¡ãã«ã¯ã次ã®ã³ãã³ããå
¥åããå¿
èŠããããŸãã
ã·ã¹ãã ã«ãŒãã®èšå®
1ãç·šé
ã²ãŒããŠã§ã€192.168.1.1ãèšå®
ã€ã³ã¿ãŒãã§ã€ã¹ããŒã1ãèšå®ããŸã
end
ã³ãã³ããå
¥åãããšãã«ã¿ãã䜿çšãããšãã³ãã³ããå®å
šã«å
¥åããããšãé¿ããããšãã§ããŸãã ãŸãã次ã«ã©ã®ã³ãã³ããå
¥åããããå¿ããå Žåã¯ãã?ãããŒã䜿çšã§ããŸãã
次ã«ãã€ã³ã¿ãŒãããæ¥ç¶ã確èªããŠã¿ãŸãããã ãããè¡ãã«ã¯ãGoogle DNS ã« ping ãéä¿¡ããŸãããã
ã芧ã®ãšãããä»ã§ã¯ã€ã³ã¿ãŒãããããããŸãã ãã¹ãŠã®ãã©ãŒãã£ããã ããã€ã¹ã«å
±éã®åæèšå®ãå®äºããã®ã§ãWeb ã€ã³ã¿ãŒãã§ã€ã¹çµç±ã§èšå®ã«é²ãããšãã§ããŸãã ãããè¡ãã«ã¯ã管çããŒãžãéããŸãã
次ã®åœ¢åŒã®ãªã³ã¯ããã©ãå¿
èŠãããããšã«æ³šæããŠãã ããã /管çè
ã ããããªããšç®¡çããŒãžã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã ããã©ã«ãã§ã¯ãããŒãžã¯æšæºæ§æã¢ãŒãã§ãã èšå®ã«ã¯è©³çŽ°ã¢ãŒããå¿
èŠã§ãã [管ç] -> [衚瀺] ã¡ãã¥ãŒã«ç§»åããã¢ãŒãã [詳现] ã«åãæ¿ããŸãããã
次ã«ãè©Šçšçã©ã€ã»ã³ã¹ãããŠã³ããŒãããå¿
èŠããããŸãã ããã¯ã[ã©ã€ã»ã³ã¹æ
å ±] â [VM] â [æŽæ°] ã¡ãã¥ãŒã§å®è¡ã§ããŸãã
è©Šçšçã©ã€ã»ã³ã¹ããæã¡ã§ãªãå Žåã¯ããåãåããããã ãããšã§è©Šçšçã©ã€ã»ã³ã¹ããªã¯ãšã¹ãã§ããŸãã
ã©ã€ã»ã³ã¹ãå ¥åããåŸãããã€ã¹ã¯åèµ·åããå¿ èŠããããŸãã å°æ¥çã«ã¯ããµãŒããŒããããŒã¿ããŒã¹ãžã®æŽæ°ãååŸãå§ããäºå®ã§ãã ãããèªåçã«è¡ãããªãå Žåã¯ããã·ã¹ãã ãâãFortiGuardãã¡ãã¥ãŒã«ç§»åããããŠã€ã«ã¹å¯Ÿçãããã¹ãã 察çãã¿ãã§ãä»ããæŽæ°ããã¿ã³ãã¯ãªãã¯ããŸãã
ããã§åé¡ã解決ããªãå Žåã¯ãæŽæ°ã«äœ¿çšããããŒããå€æŽã§ããŸãã éåžžããã®åŸã«ãã¹ãŠã®ã©ã€ã»ã³ã¹ã衚瀺ãããŸãã æçµçã«ã¯æ¬¡ã®ããã«ãªããŸãã
æ£ããã¿ã€ã ãŸãŒã³ãèšå®ããŸããããããã¯ãã°ã調ã¹ããšãã«åœ¹ç«ã¡ãŸãã ãããè¡ãã«ã¯ããã·ã¹ãã ãâãæ§æãã¡ãã¥ãŒã«ç§»åããŸãã
DNSã®èšå®ãè¡ããŸãã å
éš DNS ãµãŒããŒãã¡ã€ã³ DNS ãµãŒããŒãšããŠæ§æãããã©ãŒãã£ããããæäŸãã DNS ãµãŒããŒãããã¯ã¢ãããšããŠæ®ããŸãã
ããŠã楜ããéšåã«ç§»ããŸãããã ãæ°ã¥ãããšæããŸãããããã€ã¹ã¯ããã©ã«ãã§ã²ãŒããŠã§ã€ ã¢ãŒãã«èšå®ãããŠããŸãã ãããã£ãŠãå€æŽããå¿
èŠã¯ãããŸããã ããã¡ã€ã³ãšãŠãŒã¶ãŒãâããã¡ã€ã³ããã£ãŒã«ãã«ç§»åããŸãããã ä¿è·ããå¿
èŠãããæ°ãããã¡ã€ã³ãäœæããŸãããã ããã§ã¯ããã¡ã€ã³åãšã¡ãŒã« ãµãŒã㌠ã¢ãã¬ã¹ãæå®ããã ãã§ã (ãã¡ã€ã³åãæå®ããããšãã§ããŸãããã®å Žå㯠mail.test.local)ã
次ã«ãã¡ãŒã«ã²ãŒããŠã§ã€ã®ååãæå®ããå¿
èŠããããŸãã ãã㯠MX ã¬ã³ãŒããš A ã¬ã³ãŒãã§äœ¿çšãããåŸã§å€æŽããå¿
èŠããããŸãã
ãã¹ãåãšããŒã«ã« ãã¡ã€ã³åã®ãã€ã³ããã FQDN ãã³ã³ãã€ã«ãããDNS ã¬ã³ãŒãã§äœ¿çšãããŸãã ãã®äŸã§ã¯ãFQDN = fortimail.test.local ã§ãã
次ã«ãåä¿¡ã«ãŒã«ãèšå®ããŸãããã å€éšããéä¿¡ããããã¡ã€ã³å ã®ãŠãŒã¶ãŒã«å²ãåœãŠãããŠãããã¹ãŠã®é»åã¡ãŒã«ãã¡ãŒã« ãµãŒããŒã«è»¢éããå¿ èŠããããŸãã ãããè¡ãã«ã¯ãã¡ãã¥ãŒã®ãããªã·ãŒãâãã¢ã¯ã»ã¹å¶åŸ¡ãã«ç§»åããŸãã èšå®äŸã以äžã«ç€ºããŸãã
[åä¿¡è
ããªã·ãŒ] ã¿ããèŠãŠã¿ãŸãããã ããã§ãæåããã§ãã¯ããããã®ç¹å®ã®ã«ãŒã«ãèšå®ã§ããŸããã¡ãŒã«ããã¡ã€ã³ example1.com ããéä¿¡ãããå Žåããã®ãã¡ã€ã³çšã«ç¹å¥ã«æ§æãããã¡ã«ããºã ã䜿çšããŠã¡ãŒã«ããã§ãã¯ããå¿
èŠããããŸãã ãã¹ãŠã®ã¡ãŒã«ã«å¯Ÿããããã©ã«ãã®ã«ãŒã«ããã§ã«ååšããŠãããçŸæç¹ã§ã¯ãããé©åã§ãã ãã®ã«ãŒã«ã¯æ¬¡ã®å³ã§ç¢ºèªã§ããŸãã
ãã®æç¹ã§ãFortiMail ã®ã»ããã¢ããã¯å®äºãããšèŠãªãããŸãã å®éã«ã¯ãããã«å€ãã®å¯èœãªãã©ã¡ãŒã¿ããããŸããããããããã¹ãŠæ€èšãå§ãããšãæ¬ã XNUMX åæžããŸã :) ãããŠãç§ãã¡ã®ç®æšã¯ãæå°éã®åŽå㧠FortiMail ããã¹ã ã¢ãŒãã§èµ·åããããšã§ãã
æ®ã£ãŠããäœæ¥ã¯ XNUMX ã€ãããŸããMX ã¬ã³ãŒããš A ã¬ã³ãŒããå€æŽããããšããããŠãã¡ã€ã¢ãŠã©ãŒã«ã®ããŒã転éã«ãŒã«ãå€æŽããããšã§ãã
MX ã¬ã³ãŒã test.local -> mail.test.local 10 㯠test.local -> fortimail.test.local 10 ã«å€æŽããå¿ èŠããããŸãããã ããéåžžã¯ãã€ãããäžã«ãåªå 床ã®é«ã XNUMX çªç®ã® MX ã¬ã³ãŒããè¿œå ãããŸãã äŸãã°ïŒ
ãã¹ã.ããŒã«ã« -> ã¡ãŒã«.ãã¹ã.ããŒã«ã« 10
test.local -> fortimail.test.local 5
MX ã¬ã³ãŒãå ã®ã¡ãŒã« ãµãŒããŒèšå®ã®åºæ°ãå°ããã»ã©ãåªå 床ãé«ããªããŸãã
ãã®ãšã³ããªã¯å€æŽã§ããªããããfortimail.test.local -> 10.10.30.210 ãšããæ°ãããšã³ããªãäœæããŸãã å€éšãŠãŒã¶ãŒãããŒã 10.10.30.210 ã®ã¢ãã¬ã¹ 25 ã«æ¥ç¶ãããšããã¡ã€ã¢ãŠã©ãŒã«ã¯æ¥ç¶ã FortiMail ã«è»¢éããŸãã
FortiGate ã®è»¢éã«ãŒã«ãå€æŽããã«ã¯ã察å¿ããä»®æ³ IP ãªããžã§ã¯ãã®ã¢ãã¬ã¹ãå€æŽããå¿ èŠããããŸãã
ãã¹ãŠæºåãæŽããŸããã 確èªãããã å€éšãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ããå床ã¬ã¿ãŒãéä¿¡ããŠã¿ãŸãããã 次ã«ããMonitorãâãLogsãã¡ãã¥ãŒã®ãFortiMailãã«ç§»åããŸãããã ãå±¥æŽããã£ãŒã«ãã«ã¯ãã¬ã¿ãŒãåçããããšããèšé²ã衚瀺ãããŸãã 詳现ã«ã€ããŠã¯ããšã³ããªãå³ã¯ãªãã¯ã㊠[詳现] ãéžæããŸãã
å
šäœåãå®æãããããã«ãçŸåšã®æ§æ㧠FortiMail ãã¹ãã ããŠã€ã«ã¹ãå«ãé»åã¡ãŒã«ããããã¯ã§ãããã©ããã確èªããŠã¿ãŸãããã ãããè¡ãããã«ãã¹ãã ã¡ãŒã« ããŒã¿ããŒã¹ (http://untroubled.org/spam/) ã® XNUMX ã€ã§èŠã€ãã£ã eicar ãã¹ã ãŠã€ã«ã¹ãšãã¹ã ã¬ã¿ãŒãéä¿¡ããŸãã ãã®åŸããã°è¡šç€ºã¡ãã¥ãŒã«æ»ããŸãããã
ã芧ã®ãšãããã¹ãã ãšãŠã€ã«ã¹ä»ãã®æçŽã®äž¡æ¹ãæ£åžžã«èå¥ãããŸããã
ãã®æ§æã¯ããŠã€ã«ã¹ãã¹ãã ã«å¯Ÿããåºæ¬çãªä¿è·ãæäŸããã«ã¯ååã§ãã ãã ããFortiMail ã®æ©èœã¯ããã«éå®ãããŸããã ããå¹æçãªä¿è·ãå®çŸããã«ã¯ãå©çšå¯èœãªã¡ã«ããºã ãæ€èšããããŒãºã«åãããŠã«ã¹ã¿ãã€ãºããå¿ èŠããããŸãã å°æ¥çã«ã¯ããã®ã¡ãŒã« ã²ãŒããŠã§ã€ã®ä»ã®ããé«åºŠãªæ©èœã玹ä»ããäºå®ã§ãã
解決çã«é¢ããŠåé¡ã質åãããå Žåã¯ãã³ã¡ã³ãã«æžã蟌ãã§ãã ãããããã«åçããããåªããŸãã
ãœãªã¥ãŒã·ã§ã³ããã¹ãããããã«è©Šçšçã©ã€ã»ã³ã¹ã®ãªã¯ãšã¹ããéä¿¡ã§ããŸã
èè
ïŒã¢ã¬ã¯ã»ã€ã»ãã¯ãªã³ã æ
å ±ã»ãã¥ãªãã£ãšã³ãžãã¢Fortiserviceã
åºæïŒ habr.com