芪æãªããããäœæ°ã®çããããããŠã©ã³ãã ãªã²ã¹ãã®çãããããã«ã¡ã¯ããã®äžé£ã®èšäºã§ã¯ãIT ã€ã³ãã©ã¹ãã©ã¯ãã£ã«å¯ŸããèŠæ±ãããã»ã©é«ããªããåæã«åŸæ¥å¡ã«é«å質ã®ã€ã³ã¿ãŒãããæ¥ç¶ãå
±æãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ãæäŸããå¿
èŠãããäŒæ¥åãã®ã·ã³ãã«ãªãããã¯ãŒã¯ã®æ§ç¯ã«ã€ããŠèª¬æããŸãããªãœãŒã¹ãæäŸããåŸæ¥å¡ã«è·å Žãžã® VPN ã¢ã¯ã»ã¹ãæäŸããäžçäžã®ã©ãããã§ãã¢ã¯ã»ã¹ã§ãããããªç£èŠã·ã¹ãã ã«æ¥ç¶ããŸããäžå°äŒæ¥ã»ã°ã¡ã³ãã¯ãæ¥éãªæé·ãšãããã«äŒŽããããã¯ãŒã¯ã®åèšç»ãç¹åŸŽã§ãããã®èšäºã§ã¯ã15 ã€ã®ãªãã£ã¹ãš XNUMX ã®äœæ¥å Žããå§ããŠããããã¯ãŒã¯ãããã«æ¡å€§ããŠãããŸãããããã£ãŠãèå³æ·±ããããã¯ãããã°ãã³ã¡ã³ãã«æžã蟌ãã§ãã ãããèšäºã«å®è£
ããŠã¿ãŸããèªè
ãã³ã³ãã¥ãŒã¿ ãããã¯ãŒã¯ã®åºæ¬ã«ç²ŸéããŠããããšãåæãšããŠããŸããããã¹ãŠã®å°éçšèªã«ã€ããŠã¯ Wikipedia ãžã®ãªã³ã¯ãæäŸããŸããäžæãªç¹ãããå Žåã¯ãã¯ãªãã¯ããŠãã®äžåãä¿®æ£ããŠãã ããã
ããã§ã¯ãå§ããŸããããã©ã®ãããã¯ãŒã¯ãããšãªã¢ã調æ»ããã¯ã©ã€ã¢ã³ãã®èŠä»¶ãååŸããããšããå§ãŸãããã®åŸãæè¡ä»æ§ãšããŠåœ¢æãããŸããã客æ§èªèº«ãäœãæãã§ããã®ãããã®ããã«äœãå¿
èŠãªã®ããååã«ç解ããŠããªãå Žåãå€ããç§ãã¡ãã§ããããšããæ¡å
ããå¿
èŠããããŸãããããã¯å¶æ¥æ
åœè
以äžã®ä»äºã§ãããç§ãã¡ã¯æè¡çãªéšåãæäŸããã®ã§ã次ã®åæèŠä»¶ãæºãããŠãããšä»®å®ããŸãã
- ãã¹ã¯ããã PC çšã¯ãŒã¯ã¹ããŒã·ã§ã³ 17 å°
- ãããã¯ãŒã¯ ãã£ã¹ã¯ ã¹ãã¬ãŒãž (
NAS ) - CCTVã·ã¹ãã ã䜿çšããŠ
NVR IPã«ã¡ã©ïŒ8å°ïŒ - ãªãã£ã¹ Wi-Fi ã«ãã¬ããžã2 ã€ã®ãããã¯ãŒã¯ (å éšããã³ã²ã¹ã)
- ãããã¯ãŒã¯ããªã³ã¿ãŒãè¿œå å¯èœ(æ倧3å°)
- åžã®å察åŽã«2çªç®ã®ãªãã£ã¹ãéèšããèŠéã
æ©åšã®éžå®
ããã¯é·å¹Žã®è«äºãåŒãèµ·ããåé¡ã§ããããããã³ããŒã®éžæã«ã€ããŠã¯è©³ãã説æããŸãããããã©ã³ãããã§ã«æ±ºå®ãããŠãããããã Cisco ã§ãããšããäºå®ã«çŠç¹ãåœãŠãŸãã
ãããã¯ãŒã¯ã®åºç€ãšãªãã®ã¯ã
ã«ãŒã¿ã¯æ¬¡ã®ãšããã§ããå¿
èŠããããŸã
èšç»
ãŸããå¿ èŠãªä»®æ³ãããã¯ãŒã¯ã決å®ããŸããã (VLAN ã«ã€ããŠã¯ Wikipedia ã§èªãããšãã§ããŸã)ããããã£ãŠãããã€ãã®è«çãããã¯ãŒã¯ ã»ã°ã¡ã³ãããããŸãã
- ã¯ã©ã€ã¢ã³ã ã¯ãŒã¯ã¹ããŒã·ã§ã³ (PC)
- ãµãŒããŒïŒNASïŒ
- ãããªç£èŠ
- ã²ã¹ãããã€ã¹ (WiFi)
ãŸãããããŒã®ã«ãŒã«ã«åŸã£ãŠãããã€ã¹ç®¡çã€ã³ã¿ãŒãã§ã€ã¹ãå¥ã® VLAN ã«ç§»åããŸãã VLAN ã«ã¯ä»»æã®é åºã§çªå·ãä»ããããšãã§ããŸããããã§ã¯ãããéžæããŸãã
- VLAN10管ç(MGMT)
- VLAN50ãµãŒããŒ
- VLAN100 LAN+WiFi
- VLAN150 蚪åè çš WiFi (V-WiFi)
- VLAN200 CAM
次ã«ãç¥è²¡èšç»ãäœæãã䜿çšããŸãã
äºçŽãããããŒã«ã«ã¯ãéçã«æ§æãããã¢ãã¬ã¹ (ã¯ã©ã€ã¢ã³ãçšã®ããªã³ã¿ãŒããµãŒããŒã管çã€ã³ã¿ãŒãã§ã€ã¹ãªã©) ãå«ãŸããŸãã
ãã㧠IP ãæšå®ããŸãããã泚æãããç¹ãããã€ããããŸãã
- ãã¹ãŠã®ã¢ãã¬ã¹ã¯æ©åšã®èšå®æã«æåã§å²ãåœãŠãããããããµãŒã㌠ã«ãŒã ãšåæ§ã«ãå¶åŸ¡ãããã¯ãŒã¯ã« DHCP ãèšå®ããŠãæå³ããããŸãããæ°ããæ©åšãæ¥ç¶ããå Žåã«åããŠãåæèšå®ã®ããã«å°ã㪠DHCP ããŒã«ãæ®ããŠãã人ãããŸãããç§ã¯ããã«æ £ããŠããã®ã§ãæ©åšã顧客ã®å Žæã§ã¯ãªãèªåã®ãã¹ã¯ã§èšå®ããããšããå§ãããŸããããã§ãã®ããŒã«ããã£ãŠãã ããã
- äžéšã®ã«ã¡ã© ã¢ãã«ã§ã¯éçã¢ãã¬ã¹ãå¿ èŠãªå ŽåããããŸãããã«ã¡ã©ã¯ãããèªåçã«åä¿¡ãããšæ³å®ããŠããŸãã
- ãããã¯ãŒã¯å°å·ãµãŒãã¹ã¯åçã¢ãã¬ã¹ã§ã¯ç¹ã«ä¿¡é Œæ§ãé«ãåäœããªããããããŒã«ã« ãããã¯ãŒã¯ã§ã¯ããªã³ã¿ãŒçšã®ããŒã«ãæ®ããŠãããŸãã
ã«ãŒã¿ãŒã®ã»ããã¢ãã
ããŠãããããèšå®ã«ç§»ããŸãããããã³ãŒããååŸããŠãã«ãŒã¿ãŒã® 192.168.1.1 ã€ã® LAN ããŒãã® XNUMX ã€ã«æ¥ç¶ããŸããããã©ã«ãã§ã¯ãDHCP ãµãŒããŒã¯ã«ãŒã¿ãŒäžã§æå¹ã«ãªã£ãŠãããã¢ãã¬ã¹ XNUMX ã§å©çšã§ããŸããããã¯ãipconfig ã³ã³ãœãŒã« ãŠãŒãã£ãªãã£ã䜿çšããŠç¢ºèªã§ããŸãããã®åºåã§ã¯ãã«ãŒã¿ãŒãããã©ã«ã ã²ãŒããŠã§ã€ã«ãªããŸãã確èªãããïŒ
ãã©ãŠã¶ã§ãã®ã¢ãã¬ã¹ã«ã¢ã¯ã»ã¹ããå®å
šã§ãªãæ¥ç¶ã確èªãããã°ã€ã³/ãã¹ã¯ãŒã cisco/cisco ã䜿çšããŠãã°ã€ã³ããŸããããã«ãã¹ã¯ãŒããå®å
šãªãã®ã«å€æŽããŠãã ããããŸãæåã«ããã»ããã¢ãããã¿ãã®ããããã¯ãŒã¯ãã»ã¯ã·ã§ã³ã«ç§»åããŸããããã§ã«ãŒã¿ãŒã®ååãšãã¡ã€ã³åãå²ãåœãŠãŸãã
次ã«ãã«ãŒã¿ãŒã« VLAN ãè¿œå ããŸãããã ãããŒã管ç/VLAN ã¡ã³ããŒã·ãããã«ç§»åããŸããããã©ã«ãã§èšå®ãããŠãã VLAN-ok ãµã€ã³ã衚瀺ãããŸãã
ãããã¯å¿
èŠãããŸãããããã©ã«ãã§åé€ã§ããªããããæåã® VLAN ãé€ããã¹ãŠãåé€ããèšç»ãã VLAN ãããã«è¿œå ããŸããäžéšã®ããã¯ã¹ã«ãã§ãã¯ãå
¥ããããšãå¿ããªãã§ãã ããããŸãã管çãããã¯ãŒã¯ããã®ã¿ããã€ã¹ç®¡çãèš±å¯ããã²ã¹ã ãããã¯ãŒã¯ãé€ããã¹ãŠã®ãããã¯ãŒã¯éã®ã«ãŒãã£ã³ã°ãèš±å¯ããŸããããŒãã¯å°ãåŸã§èšå®ããŸãã
次ã«ãè¡šã«åŸã£ãŠ DHCP ãµãŒããŒãæ§æããŸãããããããè¡ãã«ã¯ãDHCP/DHCP ã»ããã¢ããã«ç§»åããŸãã
DHCP ãç¡å¹ã«ãªããããã¯ãŒã¯ã®å Žåã¯ããµããããå
ã®æåã®ã²ãŒããŠã§ã€ ã¢ãã¬ã¹ (ããã³ããã«å¿ããŠãã¹ã¯) ã®ã¿ãæ§æããŸãã
DHCP ã䜿çšãããããã¯ãŒã¯ã§ã¯ããã¹ãŠãéåžžã«ç°¡åã§ãããŸããã²ãŒããŠã§ã€ ã¢ãã¬ã¹ãæ§æãã以äžã®ããŒã«ãš DNS ãç»é²ããŸãã
ããã«ãããDHCP ãåŠçãããããŒã«ã« ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããã¯ã©ã€ã¢ã³ãã¯èªåçã«ã¢ãã¬ã¹ãåãåãããã«ãªããŸãã次ã«ãããŒããèšå®ããŸãããïŒããŒãã¯æšæºã«åŸã£ãŠèšå®ãããŠããŸãïŒ
ããã§ããããã¯ãŒã¯ ã«ãŒãäžã§ç®¡çãµããããããéçã¢ãã¬ã¹ãèšå®ããå¿
èŠããããŸããããã¯ããä¿åããã¯ãªãã¯ããåŸã«ãã®ãµããããã«ç§»åããããã§ãããããã«ã¯ DHCP ãµãŒããŒããããŸããããããã¯ãŒã¯ ã¢ããã¿ãŒã®èšå®ã«ç§»åããã¢ãã¬ã¹ãæ§æããŸãããã以éãã«ãŒã¿ãŒã¯ 192.168.10.1 ã§å©çšã§ããããã«ãªããŸãã
ã€ã³ã¿ãŒãããæ¥ç¶ãèšå®ããŸãããããããã€ããŒããéçã¢ãã¬ã¹ãåãåã£ããšä»®å®ããŸãããã [ã»ããã¢ãã/ãããã¯ãŒã¯] ã«ç§»åããäžéšã«ãã WAN1 ã«ããŒã¯ãä»ããŠã[ç·šé] ãã¯ãªãã¯ããŸããéç IP ãéžæããã¢ãã¬ã¹ãæ§æããŸãã
ä»æ¥ã®æåŸã¯ããªã¢ãŒã ã¢ã¯ã»ã¹ã®æ§æã§ãããããè¡ãã«ã¯ãããã¡ã€ã¢ãŠã©ãŒã«/äžè¬ãã«ç§»åããããªã¢ãŒã管çãããã¯ã¹ããã§ãã¯ããå¿
èŠã«å¿ããŠããŒããæ§æããŸãã
ä»æ¥ã¯ããããããã§çµããã§ãããã®èšäºã®çµæãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããåºæ¬çãªæ§æã®ã«ãŒã¿ãŒãå®æããŸãããèšäºã®é·ããäºæ³ããé·ããªã£ãŠããŸã£ãã®ã§ã次ã®ããŒãã§ã¯ã«ãŒã¿ãŒã®ã»ããã¢ãããVPN ã®ã€ã³ã¹ããŒã«ããã¡ã€ã¢ãŠã©ãŒã«ãšãã®ã³ã°ã®æ§æãã¹ã€ããã®æ§æãå®äºãããªãã£ã¹ã皌åã§ããããã«ããŸãã ããã®èšäºãå°ãã§ã圹ã«ç«ã¡ãåèã«ãªã£ããªã幞ãã§ããåããŠèšäºãæžããŸããã建èšçãªæ¹å€ã質åãããã ããã°å¹žãã§ããçããã®ã³ã¡ã³ããèæ
®ããŠãçããã«ãçãã§ããããåªããŸãããŸããæåã«æžããããã«ããªãã£ã¹ã«ä»ã«äœã衚瀺ããããããããŠä»ã«äœãæ§æãããã«ã€ããŠã®æèŠãæè¿ããŸãã
ç§ã®é£çµ¡å
ïŒ
é»å ±ïŒ
ã¹ã«ã€ã/ã¡ãŒã«: [ã¡ãŒã«ä¿è·]
ç§ãã¡ãè¿œå ããŠããã£ããããŸãããã
åºæïŒ habr.com