ä»å¹Žã¯å€ãã®äŒæ¥ãæ¥ãã§ãªã¢ãŒãã¯ãŒã¯ã«åãæ¿ããã äžéšã®ã¯ã©ã€ã¢ã³ãã«ã€ããŠã¯ã
ãã®èšäºã§ã¯ãCitrix VDI ã«åºã¥ãä»®æ³ãã¹ã¯ããã ãµãŒãã¹ãæ å ±ã»ãã¥ãªãã£ã®èŠ³ç¹ããã©ã®ããã«æ©èœãããã説æããŸãã ã©ã³ãµã ãŠã§ã¢ãæšçåæ»æãªã©ã®å€éšã®è åšããã¯ã©ã€ã¢ã³ã ãã¹ã¯ããããä¿è·ããããã«åœç€Ÿãè¡ã£ãŠããåãçµã¿ã«ã€ããŠèª¬æããŸãã
ã©ã®ãããªã»ãã¥ãªãã£åé¡ã解決ã§ããã®ã§ãããã?
ãã®ãµãŒãã¹ã«å¯Ÿããããã€ãã®äž»èŠãªã»ãã¥ãªãã£äžã®è åšãç¹å®ããŸããã äžæ¹ã§ãä»®æ³ãã¹ã¯ãããã«ã¯ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ããææãããªã¹ã¯ããããŸãã äžæ¹ã§ãä»®æ³ãã¹ã¯ãããããã€ã³ã¿ãŒãããã®ãªãŒãã³ã¹ããŒã¹ã«åºãŠãææãããã¡ã€ã«ãããŠã³ããŒãããå±éºæ§ããããŸãã ããšããããèµ·ãã£ããšããŠããã€ã³ãã©ã¹ãã©ã¯ãã£å šäœã«åœ±é¿ãäžããããšã¯ãããŸããã ãããã£ãŠããµãŒãã¹ãäœæããéã«ãããã€ãã®åé¡ã解決ããŸããã
- VDIã¹ã¿ã³ãå šäœãå€éšã®è åšããå®ããŸãã
- ã¯ã©ã€ã¢ã³ããäºãã«åé¢ããŸãã
- ä»®æ³ãã¹ã¯ãããèªäœãä¿è·ããŸãã
- ããããããã€ã¹ãããŠãŒã¶ãŒãå®å šã«æ¥ç¶ããŸãã
ä¿è·ã®äžæ žã¯ããã©ãŒãã£ãããã®æ°äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ã§ãã FortiGate ã§ããã VDI ããŒã¹ã®ãã©ãã£ãã¯ãç£èŠããåã¯ã©ã€ã¢ã³ãã«åé¢ãããã€ã³ãã©ã¹ãã©ã¯ãã£ãæäŸãããŠãŒã¶ãŒåŽã®è匱æ§ããä¿è·ããŸãã ãã®æ©èœã¯ãã»ãšãã©ã®æ å ±ã»ãã¥ãªãã£ã®åé¡ã解決ããã®ã«ååã§ãã
ãã ããäŒæ¥ã«ç¹å¥ãªã»ãã¥ãªãã£èŠä»¶ãããå Žåã¯ãè¿œå ã®ãªãã·ã§ã³ãæäŸããŸãã
- èªå® ã®ã³ã³ãã¥ãŒã¿ãŒããäœæ¥ããããã®å®å šãªæ¥ç¶ãçµç¹ããŸãã
- ã»ãã¥ãªã㣠ãã°ãç¬ç«ããŠåæããããã®ã¢ã¯ã»ã¹ãæäŸããŸãã
- ãã¹ã¯ãããäžã®ãŠã€ã«ã¹å¯Ÿçä¿è·ã®ç®¡çãæäŸããŸãã
- ãŒããã€è匱æ§ããä¿è·ããŸãã
- äžæ£ãªæ¥ç¶ã«å¯Ÿããä¿è·ã匷åããããã«ãå€èŠçŽ èªèšŒãæ§æããŸãã
åé¡ãã©ã®ããã«è§£æ±ºãããã«ã€ããŠè©³ãã説æããŸãã
ã¹ã¿ã³ããä¿è·ãããããã¯ãŒã¯ã®ã»ãã¥ãªãã£ã確ä¿ããæ¹æ³
ãããã¯ãŒã¯éšåãã»ã°ã¡ã³ãåããŠã¿ãŸãããã ã¹ã¿ã³ãã§ã¯ããã¹ãŠã®ãªãœãŒã¹ã管çããã¯ããŒãºã管çã»ã°ã¡ã³ãã匷調ããŸãã 管çã»ã°ã¡ã³ãã«ã¯å€éšããã¢ã¯ã»ã¹ã§ããŸãããã¯ã©ã€ã¢ã³ããæ»æãããå Žåã§ããæ»æè ã¯ããã«ã¢ã¯ã»ã¹ã§ããŸããã
FortiGate ã¯ä¿è·ãæ åœããŸãã ãŠã€ã«ã¹å¯Ÿçããã¡ã€ã¢ãŠã©ãŒã«ãäŸµå ¥é²æ¢ã·ã¹ãã (IPS) ã®æ©èœãçµã¿åãããŠããŸãã
ã¯ã©ã€ã¢ã³ãããšã«ãä»®æ³ãã¹ã¯ãããçšã«åé¢ããããããã¯ãŒã¯ ã»ã°ã¡ã³ããäœæããŸãã ãã®ç®çã®ããã«ãFortiGate ã«ã¯ä»®æ³ãã¡ã€ã³ ãã¯ãããžãŒ (VDOM) ãæèŒãããŠããŸãã ããã«ããããã¡ã€ã¢ãŠã©ãŒã«ãè€æ°ã®ä»®æ³ãšã³ãã£ãã£ã«åå²ããåã¯ã©ã€ã¢ã³ãã«åå¥ã®ãã¡ã€ã¢ãŠã©ãŒã«ã®ããã«åäœããç¬èªã® VDOM ãå²ãåœãŠãããšãã§ããŸãã ãŸãã管çã»ã°ã¡ã³ãçšã«å¥ã® VDOM ãäœæããŸãã
ããã¯æ¬¡ã®å³ã®ããã«ãªããŸãã
ã¯ã©ã€ã¢ã³ãéã«ãããã¯ãŒã¯æ¥ç¶ã¯ãããŸããããããããç¬èªã® VDOM å
ã«ååšããä»æ¹ã«åœ±é¿ãäžããŸããã ãã®ãã¯ãããžãŒããªããã°ããã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ã§ã¯ã©ã€ã¢ã³ããåé¢ããå¿
èŠããããŸãããããã¯äººçãã¹ã«ããå±éºã䌎ããŸãã ãã®ãããªã«ãŒã«ã¯ãåžžã«éããªããã°ãªããªããã¢ã«ããšããããšãã§ããŸãã VDOM ã®å Žåãããã¢ãã¯ãŸã£ããæ®ããŸããã
å¥ã® VDOM ã§ã¯ãã¯ã©ã€ã¢ã³ãã¯ç¬èªã®ã¢ãã¬ã¹æå®ãšã«ãŒãã£ã³ã°ãæã¡ãŸãã ãããã£ãŠãç¯å²ãè¶ããããšã¯äŒç€Ÿã«ãšã£ãŠåé¡ã«ãªããŸããã ã¯ã©ã€ã¢ã³ãã¯ãå¿ èŠãª IP ã¢ãã¬ã¹ãä»®æ³ãã¹ã¯ãããã«å²ãåœãŠãããšãã§ããŸãã ããã¯ãç¬èªã® IP ãã©ã³ãæã€å€§äŒæ¥ã«ãšã£ãŠäŸ¿å©ã§ãã
ã客æ§ã®äŒæ¥ãããã¯ãŒã¯ãšã®æ¥ç¶ã®åé¡ã解決ããŸãã å¥ã®ã¿ã¹ã¯ã¯ãVDI ãã¯ã©ã€ã¢ã³ã ã€ã³ãã©ã¹ãã©ã¯ãã£ã«æ¥ç¶ããããšã§ãã äŒæ¥ãäŒæ¥ã·ã¹ãã ãããŒã¿ã»ã³ã¿ãŒã«ä¿ç®¡ããŠããå Žåããã®æ©åšãããã¡ã€ã¢ãŠã©ãŒã«ãŸã§ãããã¯ãŒã¯ ã±ãŒãã«ãé ç·ããã ãã§æžã¿ãŸãã ããããå€ãã®å Žåãç§ãã¡ã¯å¥ã®ããŒã¿ã»ã³ã¿ãŒãã¯ã©ã€ã¢ã³ãã®ãªãã£ã¹ãªã©ã®ãªã¢ãŒããµã€ããæ±ããŸãã ãã®å Žåããµã€ããšã®å®å šãªããåããèæ ®ããIPsec VPN ã䜿çšã㊠site2site VPN ãæ§ç¯ããŸãã
ã¹ããŒã ã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®è€éãã«å¿ããŠç°ãªãå ŽåããããŸãã å Žæã«ãã£ãŠã¯ãåäžã®ãªãã£ã¹ ãããã¯ãŒã¯ã VDI ã«æ¥ç¶ããã ãã§ååã§ãããããã§ã¯éçã«ãŒãã£ã³ã°ã§ååã§ãã 倧äŒæ¥ã«ã¯ãåžžã«å€åããå€ãã®ãããã¯ãŒã¯ããããŸãã ããã§ã¯ãã¯ã©ã€ã¢ã³ãã¯åçã«ãŒãã£ã³ã°ãå¿ èŠãšããŸãã åœç€Ÿã§ã¯ããŸããŸãªãããã³ã«ã䜿çšããŠããŸãããã§ã« OSPF (Open Shortest Path First)ãGRE ãã³ãã« (Generic Routing Encapsulation)ãBGP (Border Gateway Protocol) ã䜿çšããã±ãŒã¹ããããŸãã FortiGate ã¯ãä»ã®ã¯ã©ã€ã¢ã³ãã«åœ±é¿ãäžããããšãªããåå¥ã® VDOM ã§ãããã¯ãŒã¯ ãããã³ã«ããµããŒãããŸãã
ãã·ã¢é£éŠã® FSB ã«ãã£ãŠèªå®ãããæå·ä¿è·æ段ã«åºã¥ãæå·åã§ãã GOST-VPN ãæ§ç¯ããããšãã§ããŸãã ããšãã°ãä»®æ³ç°å¢ãS-Terra Virtual GatewayããŸãã¯PAK ViPNetãAPKSHãContinentãããS-Terraãã§KS1ã¯ã©ã¹ã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããŸãã
ã°ã«ãŒãããªã·ãŒã®èšå®ã VDI ã«é©çšãããã°ã«ãŒã ããªã·ãŒã«ã€ããŠã¯ã©ã€ã¢ã³ããšåæããŸãã ããã§ã®èšå®ã®ååã¯ããªãã£ã¹ã§ã®ããªã·ãŒã®èšå®ãšäœãå€ãããŸããã Active Directory ãšã®çµ±åãèšå®ããäžéšã®ã°ã«ãŒã ããªã·ãŒã®ç®¡çãã¯ã©ã€ã¢ã³ãã«å§ä»»ããŸãã ããã³ã管çè ã¯ãã³ã³ãã¥ãŒã¿ãŒ ãªããžã§ã¯ãã«ããªã·ãŒãé©çšããActive Directory ã§çµç¹åäœã管çãããŠãŒã¶ãŒãäœæã§ããŸãã
FortiGate ã§ã¯ãã¯ã©ã€ã¢ã³ã VDOM ããšã«ãããã¯ãŒã¯ ã»ãã¥ãªã㣠ããªã·ãŒãäœæããã¢ã¯ã»ã¹å¶éãèšå®ãããã©ãã£ãã¯æ€æ»ãæ§æããŸãã ããã€ãã® FortiGate ã¢ãžã¥ãŒã«ã䜿çšããŸãã
- IPS ã¢ãžã¥ãŒã«ã¯ãã©ãã£ãã¯ãã¹ãã£ã³ããŠãã«ãŠã§ã¢ãæ€åºããäŸµå ¥ãé²ããŸãã
- ãŠã€ã«ã¹å¯Ÿçã¯ãã¹ã¯ãããèªäœããã«ãŠã§ã¢ãã¹ãã€ãŠã§ã¢ããä¿è·ããŸãã
- Web ãã£ã«ã¿ãªã³ã°ã¯ãä¿¡é Œã§ããªããªãœãŒã¹ãæªæã®ããã³ã³ãã³ããŸãã¯äžé©åãªã³ã³ãã³ããå«ããµã€ããžã®ã¢ã¯ã»ã¹ããããã¯ããŸãã
- ãã¡ã€ã¢ãŠã©ãŒã«èšå®ã«ããããŠãŒã¶ãŒã¯ç¹å®ã®ãµã€ããžã®ã€ã³ã¿ãŒããã ã¢ã¯ã»ã¹ã®ã¿ãèš±å¯ãããå ŽåããããŸãã
ã¯ã©ã€ã¢ã³ããåŸæ¥å¡ã® Web ãµã€ããžã®ã¢ã¯ã»ã¹ãç¬èªã«ç®¡çãããå ŽåããããŸãã å€ãã®å Žåãéè¡ã¯æ¬¡ã®ãããªèŠæ±ãæã¡ãŸããã»ãã¥ãªã㣠ãµãŒãã¹ã§ã¯ãã¢ã¯ã»ã¹å¶åŸ¡ãäŒæ¥åŽã«ããããšãèŠæ±ããŸãã ãã®ãããªäŒæ¥ã¯èªããã©ãã£ãã¯ãç£èŠããå®æçã«ããªã·ãŒãå€æŽããŠããŸãã ãã®å ŽåãFortiGate ããã®ãã¹ãŠã®ãã©ãã£ãã¯ãã¯ã©ã€ã¢ã³ãã«åããããŸãã ãããè¡ãããã«ãäŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãšã®èšå®æžã¿ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŸãã ãã®åŸãã¯ã©ã€ã¢ã³ãèªèº«ãäŒæ¥ãããã¯ãŒã¯ãã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ã«ãŒã«ãèšå®ããŸãã
ç§ãã¡ã¯ã¹ã¿ã³ãã§ã€ãã³ããèŠå®ããŸãã FortiGate ãšãšãã«ãFortinet ã®ãã° ã³ã¬ã¯ã¿ãŒã§ãã FortiAnalyzer ã䜿çšããŸãã ãã®å©ããåããŠãVDI äžã®ãã¹ãŠã®ã€ãã³ã ãã°ã XNUMX ãæã§ç¢ºèªããäžå¯©ãªã¢ã¯ã·ã§ã³ãèŠã€ããŠçžé¢é¢ä¿ã远跡ããŸãã
åœç€Ÿã®é¡§å®¢ã® XNUMX 瀟ã¯ããªãã£ã¹ã§ãã©ãŒãã£ããã補åã䜿çšããŠããŸãã ãã®ããã«ããã°ã®ã¢ããããŒããæ§æããŸãããããã«ãããã¯ã©ã€ã¢ã³ãã¯ãªãã£ã¹ ãã·ã³ãšä»®æ³ãã¹ã¯ãããã®ãã¹ãŠã®ã»ãã¥ãªã㣠ã€ãã³ããåæã§ããããã«ãªããŸããã
ä»®æ³ãã¹ã¯ããããä¿è·ããæ¹æ³
æ¢ç¥ã®è åšããã ã客æ§ããŠã€ã«ã¹å¯Ÿçä¿è·ãç¬èªã«ç®¡çãããå Žåã¯ãä»®æ³ç°å¢çšã® Kaspersky Security ãè¿œå ã§ã€ã³ã¹ããŒã«ããŸãã
ãã®ãœãªã¥ãŒã·ã§ã³ã¯ã¯ã©ãŠãã§ããŸãæ©èœããŸãã ç§ãã¡ã¯çãå€å žç㪠Kaspersky ã¢ã³ããŠã€ã«ã¹ããéãããœãªã¥ãŒã·ã§ã³ã§ãããšããäºå®ã«æ £ããŠããŸãã å¯Ÿç §çã«ãKaspersky Security for Virtualization ã¯ä»®æ³ãã·ã³ãããŒãããŸããã ãã¹ãŠã®ãŠã€ã«ã¹ ããŒã¿ããŒã¹ã¯ãµãŒããŒäžã«ãããããŒãã®ãã¹ãŠã®ä»®æ³ãã·ã³ã«å¯ŸããŠå€å®ãçºè¡ããŸãã ä»®æ³ãã¹ã¯ãããã«ã¯ã©ã€ã ãšãŒãžã§ã³ãã®ã¿ãã€ã³ã¹ããŒã«ãããŸãã æ€èšŒã®ããã«ãã¡ã€ã«ããµãŒããŒã«éä¿¡ããŸãã
ãã®ã¢ãŒããã¯ãã£ã¯ããã¡ã€ã«ä¿è·ãã€ã³ã¿ãŒãããä¿è·ãæ»æã«å¯Ÿããä¿è·ãåæã«æäŸããä»®æ³ãã·ã³ã®ããã©ãŒãã³ã¹ãäœäžãããããšã¯ãããŸããã ãã®å Žåãã¯ã©ã€ã¢ã³ãã¯ãã¡ã€ã«ä¿è·ã«ç¬èªã«äŸå€ãå°å ¥ã§ããŸãã ãœãªã¥ãŒã·ã§ã³ã®åºæ¬çãªã»ããã¢ããããæäŒãããŸãã ãã®æ©èœã«ã€ããŠã¯å¥ã®èšäºã§èª¬æããŸãã
æªç¥ã®è åšããã ãããè¡ãããã«ãFortinet ã®ããµã³ãããã¯ã¹ãã§ãã FortiSandbox ãæ¥ç¶ããŸãã ãŠã€ã«ã¹å¯ŸçãœããããŒããã€è åšãèŠéããå Žåã«åããŠãããããã£ã«ã¿ãŒãšããŠäœ¿çšããŸãã ãã¡ã€ã«ãããŠã³ããŒãããåŸããŸããŠã€ã«ã¹å¯Ÿçãœããã§ã¹ãã£ã³ããŠããããµã³ãããã¯ã¹ã«éä¿¡ããŸãã FortiSandbox ã¯ä»®æ³ãã·ã³ããšãã¥ã¬ãŒããããã¡ã€ã«ãå®è¡ããŠããã®åäœ (ã¬ãžã¹ããªå ã®ã©ã®ãªããžã§ã¯ããã¢ã¯ã»ã¹ãããããå€éšãªã¯ãšã¹ããéä¿¡ãããã©ãããªã©) ãç£èŠããŸãã ãã¡ã€ã«ãäžå¯©ãªåäœãããå Žåããµã³ãããã¯ã¹åãããä»®æ³ãã·ã³ã¯åé€ãããæªæã®ãããã¡ã€ã«ããŠãŒã¶ãŒ VDI ã«å°éããããšã¯ãããŸããã
VDI ãžã®å®å šãªæ¥ç¶ãã»ããã¢ããããæ¹æ³
ããã€ã¹ãæ å ±ã»ãã¥ãªãã£èŠä»¶ã«æºæ ããŠãããã©ããã確èªããŸãã ãªã¢ãŒãã¯ãŒã¯ãå§ãŸã£ãŠä»¥æ¥ãã客æ§ããã¯ããŠãŒã¶ãŒã®ããœã³ã³ããã®å®å šãªæäœã確ä¿ããããšããèŠæãå¯ããããŠããŸããã æ å ±ã»ãã¥ãªãã£ã®å°é家ãªã誰ã§ãã家åºçšããã€ã¹ãä¿è·ããã®ãé£ããããšãç¥ã£ãŠããŸããããã¯ãªãã£ã¹æ©åšã§ã¯ãªããããå¿ èŠãªãŠã€ã«ã¹å¯Ÿçãœãããã€ã³ã¹ããŒã«ããããã°ã«ãŒã ããªã·ãŒãé©çšãããããããšãã§ããŸããã
ããã©ã«ãã§ã¯ãVDI ã¯å人ã®ããã€ã¹ãšäŒæ¥ãããã¯ãŒã¯ã®éã®å®å šãªãã¬ã€ã€ãŒãã«ãªããŸãã ãŠãŒã¶ãŒ ãã·ã³ããã®æ»æãã VDI ãä¿è·ããããã«ãã¯ãªããããŒããç¡å¹ã«ããUSB 転éãçŠæ¢ããŸãã ãã ããããã«ãã£ãŠãŠãŒã¶ãŒã®ããã€ã¹èªäœãå®å šã«ãªãããã§ã¯ãããŸããã
FortiClientã䜿çšããŠåé¡ã解決ããŸãã ããã¯ãšã³ããã€ã³ãä¿è·ããŒã«ã§ãã å瀟ã®ãŠãŒã¶ãŒã¯èªå® ã®ã³ã³ãã¥ãŒã¿ã« FortiClient ãã€ã³ã¹ããŒã«ããããã䜿çšããŠä»®æ³ãã¹ã¯ãããã«æ¥ç¶ããŸãã FortiClient 㯠3 ã€ã®åé¡ãäžåºŠã«è§£æ±ºããŸãã
- ãŠãŒã¶ãŒã«ãšã£ãŠã¯ã¢ã¯ã»ã¹ã®ãåäžãŠã£ã³ããŠãã«ãªããŸãã
- ããœã³ã³ã«ãŠã€ã«ã¹å¯Ÿçãœãããšææ°ã® OS ã¢ããããŒãããããã©ããã確èªããŸãã
- å®å šãªã¢ã¯ã»ã¹ã®ããã® VPN ãã³ãã«ãæ§ç¯ããŸãã
åŸæ¥å¡ã¯æ€èšŒã«åæ Œããå Žåã«ã®ã¿ã¢ã¯ã»ã¹ãèš±å¯ãããŸãã åæã«ãä»®æ³ãã¹ã¯ãããèªäœã¯ã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹ã§ããªããªããŸããããã¯ãä»®æ³ãã¹ã¯ããããæ»æããããããä¿è·ãããããšãæå³ããŸãã
äŒæ¥ããšã³ããã€ã³ãä¿è·ãèªç€Ÿã§ç®¡çãããå Žåã«ã¯ãFortiClient EMS (Endpoint Management Server) ãæäŸããŸãã ã¯ã©ã€ã¢ã³ãã¯ãã¹ã¯ããã ã¹ãã£ã³ãšäŸµå ¥é²åŸ¡ãèšå®ããã¢ãã¬ã¹ã®ãã¯ã€ã ãªã¹ããäœæã§ããŸãã
èªèšŒèŠçŽ ãè¿œå ããŸãã ããã©ã«ãã§ã¯ããŠãŒã¶ãŒã¯ Citrix netscaler ãéããŠèªèšŒãããŸãã ããã§ããSafeNet 補åã«åºã¥ãå€èŠçŽ èªèšŒã䜿çšããŠã»ãã¥ãªãã£ã匷åã§ããŸãã ãã®ãããã¯ã¯ç¹ã«æ³šç®ã«å€ããŸããããã«ã€ããŠã¯å¥ã®èšäºã§ã説æããŸãã
ç§ãã¡ã¯éå» XNUMX 幎éãããŸããŸãªãœãªã¥ãŒã·ã§ã³ã«åãçµãã§ããçµéšãèç©ããŠããŸããã VDI ãµãŒãã¹ã¯ã¯ã©ã€ã¢ã³ãããšã«åå¥ã«æ§æããããããæãæè»ãªããŒã«ãéžæããŸããã ããããè¿ãå°æ¥ãäœãä»ã®ãã®ãè¿œå ããç§ãã¡ã®çµéšãå ±æããã§ãããã
7 æ 17.00 æ¥ã® XNUMX:XNUMX ãããç§ã®ååããŠã§ãããŒãVDI ã¯å¿
èŠã§ãã? ãããšããªã¢ãŒãã¯ãŒã¯ãã©ã®ããã«çµç¹ããã?ãã§ä»®æ³ãã¹ã¯ãããã«ã€ããŠè©±ããŸãã
åºæïŒ habr.com