๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

์กฐ์ง ์ฃผ์ œ์— ๊ด€ํ•œ ์ผ๋ จ์˜ ๊ธฐ์‚ฌ๋ฅผ ๊ณ„์†ํ•ฉ๋‹ˆ๋‹ค. ์›๊ฒฉ ์•ก์„ธ์Šค VPN ๋‚ด ํฅ๋ฏธ๋กœ์šด ๋ฐฐํฌ ๊ฒฝํ—˜์„ ๊ณต์œ ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ๋งค์šฐ ์•ˆ์ „ํ•œ VPN ๊ตฌ์„ฑ. ํ•œ ๊ณ ๊ฐ(๋Ÿฌ์‹œ์•„ ๋งˆ์„์— ๋ฐœ๋ช…๊ฐ€๊ฐ€ ์žˆ์Œ)์ด ์‚ฌ์†Œํ•œ ์ž‘์—…์„ ์ œ์‹œํ–ˆ์ง€๋งŒ ์ฑŒ๋ฆฐ์ง€๊ฐ€ ์ˆ˜๋ฝ๋˜์–ด ์ฐฝ์˜์ ์œผ๋กœ ๊ตฌํ˜„๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ ๊ฒฐ๊ณผ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํŠน์ง•์„ ์ง€๋‹Œ ํฅ๋ฏธ๋กœ์šด ๊ฐœ๋…์ด ํƒ„์ƒํ–ˆ์Šต๋‹ˆ๋‹ค.

  1. ๋‹จ๋ง ์žฅ์น˜ ๋Œ€์ฒด์— ๋Œ€ํ•œ ์—ฌ๋Ÿฌ ๊ฐ€์ง€ ๋ณดํ˜ธ ์š”์†Œ(์‚ฌ์šฉ์ž์— ๋Œ€ํ•œ ์—„๊ฒฉํ•œ ๊ตฌ์†๋ ฅ ํฌํ•จ)
    • ์ธ์ฆ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์—์„œ ํ—ˆ์šฉ๋œ PC์˜ ํ• ๋‹น๋œ UDID์— ๋Œ€ํ•œ ์‚ฌ์šฉ์ž PC์˜ ์ค€์ˆ˜ ์—ฌ๋ถ€๋ฅผ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
    • Cisco DUO๋ฅผ ํ†ตํ•œ ๋ณด์กฐ ์ธ์ฆ์„ ์œ„ํ•ด ์ธ์ฆ์„œ์˜ PC UDID๋ฅผ ์‚ฌ์šฉํ•˜๋Š” MFA ์‚ฌ์šฉ (SAML/Radius ํ˜ธํ™˜ ํ•ญ๋ชฉ์„ ์ฒจ๋ถ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค);
  2. ๋‹ค๋‹จ๊ณ„ ์ธ์ฆ:
    • ํ•„๋“œ ๊ฒ€์ฆ๊ณผ ๊ทธ ์ค‘ ํ•˜๋‚˜์— ๋Œ€ํ•œ XNUMX์ฐจ ์ธ์ฆ์ด ํฌํ•จ๋œ ์‚ฌ์šฉ์ž ์ธ์ฆ์„œ
    • ๋กœ๊ทธ์ธ(๋ณ€๊ฒฝ ๋ถˆ๊ฐ€๋Šฅ, ์ธ์ฆ์„œ์—์„œ ๊ฐ€์ ธ์˜ด) ๋ฐ ๋น„๋ฐ€๋ฒˆํ˜ธ
  3. ์—ฐ๊ฒฐ ํ˜ธ์ŠคํŠธ์˜ ์ƒํƒœ ์ถ”์ •(Posture)

์‚ฌ์šฉ๋œ ์†”๋ฃจ์…˜ ๊ตฌ์„ฑ ์š”์†Œ:

  • Cisco ASA(VPN ๊ฒŒ์ดํŠธ์›จ์ด);
  • Cisco ISE(์ธ์ฆ/๊ถŒํ•œ ๋ถ€์—ฌ/ํšŒ๊ณ„, ์ƒํƒœ ํ‰๊ฐ€, CA);
  • Cisco DUO(๋‹ค๋‹จ๊ณ„ ์ธ์ฆ) (SAML/Radius ํ˜ธํ™˜ ํ•ญ๋ชฉ์„ ์ฒจ๋ถ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค);
  • Cisco AnyConnect(์›Œํฌ์Šคํ…Œ์ด์…˜ ๋ฐ ๋ชจ๋ฐ”์ผ OS์šฉ ๋‹ค๋ชฉ์  ์—์ด์ „ํŠธ);

๊ณ ๊ฐ์˜ ์š”๊ตฌ์‚ฌํ•ญ๋ถ€ํ„ฐ ์‹œ์ž‘ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

  1. ์‚ฌ์šฉ์ž๋Š” ๋กœ๊ทธ์ธ/๋น„๋ฐ€๋ฒˆํ˜ธ ์ธ์ฆ์„ ํ†ตํ•ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์—์„œ AnyConnect ํด๋ผ์ด์–ธํŠธ๋ฅผ ๋‹ค์šด๋กœ๋“œํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•˜๋ฉฐ, ํ•„์š”ํ•œ ๋ชจ๋“  AnyConnect ๋ชจ๋“ˆ์€ ์‚ฌ์šฉ์ž ์ •์ฑ…์— ๋”ฐ๋ผ ์ž๋™์œผ๋กœ ์„ค์น˜๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  2. ์‚ฌ์šฉ์ž๋Š” ์ธ์ฆ์„œ๋ฅผ ์ž๋™์œผ๋กœ ๋ฐœ๊ธ‰ํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•˜์ง€๋งŒ(์‹œ๋‚˜๋ฆฌ์˜ค ์ค‘ ํ•˜๋‚˜์˜ ๊ฒฝ์šฐ ์ฃผ์š” ์‹œ๋‚˜๋ฆฌ์˜ค๋Š” ์ˆ˜๋™์œผ๋กœ ๋ฐœ๊ธ‰ํ•˜๊ณ  PC์— ์—…๋กœ๋“œํ•˜๋Š” ๊ฒƒ์ž„) ์‹œ์—ฐ์„ ์œ„ํ•ด ์ž๋™ ๋ฐœ๊ธ‰์„ ๊ตฌํ˜„ํ–ˆ์Šต๋‹ˆ๋‹ค(์ œ๊ฑฐํ•˜๊ธฐ์—๋Š” ๋„ˆ๋ฌด ๋Šฆ์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค).
  3. ๊ธฐ๋ณธ ์ธ์ฆ์€ ์—ฌ๋Ÿฌ ๋‹จ๊ณ„๋กœ ์ด๋ฃจ์–ด์ ธ์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋จผ์ € ํ•„์š”ํ•œ ํ•„๋“œ์™€ ํ•ด๋‹น ๊ฐ’์„ ๋ถ„์„ํ•œ ์ธ์ฆ์„œ ์ธ์ฆ, ๋กœ๊ทธ์ธ/๋น„๋ฐ€๋ฒˆํ˜ธ, ์ด๋ฒˆ์—๋Š” ์ธ์ฆ์„œ ํ•„๋“œ์— ์ง€์ •๋œ ์‚ฌ์šฉ์ž ์ด๋ฆ„์„ ๋กœ๊ทธ์ธ ์ฐฝ์— ์‚ฝ์ž…ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ฃผ์ฒด ์ด๋ฆ„(CN) ํŽธ์ง‘ ๋Šฅ๋ ฅ ์—†์ด.
  4. ๋กœ๊ทธ์ธํ•˜๋Š” ์žฅ์น˜๊ฐ€ ์›๊ฒฉ ์•ก์„ธ์Šค๋ฅผ ์œ„ํ•ด ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ฐœ๊ธ‰๋œ ํšŒ์‚ฌ ๋…ธํŠธ๋ถ์ธ์ง€, ๋‹ค๋ฅธ ์žฅ์น˜๊ฐ€ ์•„๋‹Œ์ง€ ํ™•์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. (์ด ์š”๊ตฌ ์‚ฌํ•ญ์„ ์ถฉ์กฑํ•˜๊ธฐ ์œ„ํ•ด ์—ฌ๋Ÿฌ ๊ฐ€์ง€ ์˜ต์…˜์ด ๋งŒ๋“ค์–ด์กŒ์Šต๋‹ˆ๋‹ค.)
  5. ์—ฐ๊ฒฐ ์žฅ์น˜(์ด ๋‹จ๊ณ„์˜ PC) ์ƒํƒœ๋Š” ๊ณ ๊ฐ ์š”๊ตฌ ์‚ฌํ•ญ(์š”์•ฝ)์— ๋Œ€ํ•œ ์ „์ฒด ํ‘œ๋ฅผ ํ™•์ธํ•˜์—ฌ ํ‰๊ฐ€ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
    • ํŒŒ์ผ ๋ฐ ํ•ด๋‹น ์†์„ฑ
    • ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ•ญ๋ชฉ;
    • ์ œ๊ณต๋œ ๋ชฉ๋ก์˜ OS ํŒจ์น˜(๋‚˜์ค‘์— SCCM ํ†ตํ•ฉ)
    • ํŠน์ • ์ œ์กฐ์—…์ฒด์˜ ์•ˆํ‹ฐ ๋ฐ”์ด๋Ÿฌ์Šค ๊ฐ€์šฉ์„ฑ ๋ฐ ์„œ๋ช…์˜ ๊ด€๋ จ์„ฑ
    • ํŠน์ • ์„œ๋น„์Šค์˜ ํ™œ๋™
    • ์„ค์น˜๋œ ํŠน์ • ํ”„๋กœ๊ทธ๋žจ์˜ ๊ฐ€์šฉ์„ฑ

์šฐ์„ , ๊ฒฐ๊ณผ ๊ตฌํ˜„์— ๋Œ€ํ•œ ๋น„๋””์˜ค ๋ฐ๋ชจ๋ฅผ ๊ผญ ๋ณด์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค. ์œ ํŠœ๋ธŒ(5๋ถ„).

์ด์ œ ๋น„๋””์˜ค ํด๋ฆฝ์—์„œ ๋‹ค๋ฃจ์ง€ ์•Š์€ ๊ตฌํ˜„ ์„ธ๋ถ€ ์‚ฌํ•ญ์„ ๊ณ ๋ คํ•  ๊ฒƒ์„ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค.

AnyConnect ํ”„๋กœํ•„์„ ์ค€๋น„ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

์ด์ „์— ์„ค์ •์— ๋Œ€ํ•œ ๋‚ด ๊ธฐ์‚ฌ์—์„œ ํ”„๋กœํ•„ ์ƒ์„ฑ(ASDM์˜ ๋ฉ”๋‰ด ํ•ญ๋ชฉ ์ธก๋ฉด์—์„œ)์— ๋Œ€ํ•œ ์˜ˆ๋ฅผ ์ œ๊ณตํ–ˆ์Šต๋‹ˆ๋‹ค. VPN ๋ถ€ํ•˜ ๋ถ„์‚ฐ ํด๋Ÿฌ์Šคํ„ฐ. ์ด์ œ ํ•„์š”ํ•œ ์˜ต์…˜์„ ๋ณ„๋„๋กœ ๊ธฐ๋กํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค.

ํ”„๋กœํ•„์—๋Š” ์ตœ์ข… ํด๋ผ์ด์–ธํŠธ์— ์—ฐ๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ VPN ๊ฒŒ์ดํŠธ์›จ์ด์™€ ํ”„๋กœํ•„ ์ด๋ฆ„์ด ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

ํŠนํžˆ ์ธ์ฆ์„œ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ํ‘œ์‹œํ•˜๊ณ  ํŠน์ง•์ ์œผ๋กœ ํ•„๋“œ์— ์ฃผ์˜๋ฅผ ๊ธฐ์šธ์—ฌ ํ”„๋กœํ•„ ์ธก์—์„œ ์ธ์ฆ์„œ ์ž๋™ ๋ฐœ๊ธ‰์„ ๊ตฌ์„ฑํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์ด๋‹ˆ์…œ(I), ํŠน์ • ๊ฐ’์„ ์ˆ˜๋™์œผ๋กœ ์ž…๋ ฅํ•˜๋Š” ๊ฒฝ์šฐ UDID ํ…Œ์ŠคํŠธ ๋จธ์‹ (Cisco AnyConnect ํด๋ผ์ด์–ธํŠธ์—์„œ ์ƒ์„ฑ๋œ ๊ณ ์œ  ์žฅ์น˜ ์‹๋ณ„์ž).

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

์ด ๊ธฐ์‚ฌ์—์„œ๋Š” ๊ฐœ๋…์„ ์„ค๋ช…ํ•˜๋ฏ€๋กœ ์„œ์ •์ ์œผ๋กœ ์—ฌ๋‹ด์„ ๋งŒ๋“ค๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค. ๋ฐ๋ชจ ๋ชฉ์ ์œผ๋กœ ์ธ์ฆ์„œ ๋ฐœ๊ธ‰์„ ์œ„ํ•œ UDID๊ฐ€ AnyConnect ํ”„๋กœํ•„์˜ ์ด๋‹ˆ์…œ ํ•„๋“œ์— ์ž…๋ ฅ๋ฉ๋‹ˆ๋‹ค. ๋ฌผ๋ก  ์‹ค์ œ ์ƒํ™œ์—์„œ ์ด๋ ‡๊ฒŒ ํ•˜๋ฉด ๋ชจ๋“  ํด๋ผ์ด์–ธํŠธ๋Š” ์ด ํ•„๋“œ์—์„œ ๋™์ผํ•œ UDID๊ฐ€ ์žˆ๋Š” ์ธ์ฆ์„œ๋ฅผ ๋ฐ›๊ฒŒ ๋˜๋ฉฐ ํŠน์ • PC์˜ UDID๊ฐ€ ํ•„์š”ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์•„๋ฌด ๊ฒƒ๋„ ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์•ˆํƒ€๊น๊ฒŒ๋„ AnyConnect๋Š” ํ™˜๊ฒฝ ๋ณ€์ˆ˜(์˜ˆ: ๋ณ€์ˆ˜)๋ฅผ ํ†ตํ•ด UDID ํ•„๋“œ๋ฅผ ์ธ์ฆ์„œ ์š”์ฒญ ํ”„๋กœํ•„๋กœ ๋Œ€์ฒดํ•˜๋Š” ๊ธฐ๋Šฅ์„ ์•„์ง ๊ตฌํ˜„ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. %์‚ฌ์šฉ์ž%.

(์ด ์‹œ๋‚˜๋ฆฌ์˜ค์˜) ๊ณ ๊ฐ์€ ์ฒ˜์Œ์— ํ•ด๋‹น ๋ณดํ˜ธ๋œ PC์— ๋Œ€ํ•ด ์ˆ˜๋™ ๋ชจ๋“œ์—์„œ ์ง€์ •๋œ UDID๊ฐ€ ์žˆ๋Š” ์ธ์ฆ์„œ๋ฅผ ๋…๋ฆฝ์ ์œผ๋กœ ๋ฐœ๊ธ‰ํ•  ๊ณ„ํš์ด๋ฉฐ ์ด๋Š” ๋ฌธ์ œ๊ฐ€ ๋˜์ง€ ์•Š๋Š”๋‹ค๋Š” ์ ์€ ์ฃผ๋ชฉํ•  ๊ฐ€์น˜๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์šฐ๋ฆฌ ๋Œ€๋ถ€๋ถ„์€ ์ž๋™ํ™”๋ฅผ ์›ํ•ฉ๋‹ˆ๋‹ค(๋‚˜์—๊ฒŒ๋Š” ๊ทธ๊ฒƒ์ด ์‚ฌ์‹ค์ž…๋‹ˆ๋‹ค =)).

์ด๊ฒƒ์ด ์ œ๊ฐ€ ์ž๋™ํ™” ์ธก๋ฉด์—์„œ ์ œ๊ณตํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. AnyConnect๊ฐ€ ์•„์ง UDID๋ฅผ ๋™์ ์œผ๋กœ ๋Œ€์ฒดํ•˜์—ฌ ์ž๋™์œผ๋กœ ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•  ์ˆ˜ ์—†๋Š” ๊ฒฝ์šฐ ์•ฝ๊ฐ„์˜ ์ฐฝ์˜์ ์ธ ์ƒ๊ฐ๊ณผ ์ˆ™๋ จ๋œ ์†์ด ํ•„์š”ํ•œ ๋˜ ๋‹ค๋ฅธ ๋ฐฉ๋ฒ•์ด ์žˆ์Šต๋‹ˆ๋‹ค. ๊ฐœ๋…์„ ์•Œ๋ ค๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค. ๋จผ์ € AnyConnect ์—์ด์ „ํŠธ๊ฐ€ ๋‹ค์–‘ํ•œ ์šด์˜ ์ฒด์ œ์—์„œ UDID๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

  • Windows โ€” DigitalProductID์™€ Machine SID ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค ์กฐํ•ฉ์˜ SHA-256 ํ•ด์‹œ
  • OSX โ€” SHA-256 ํ•ด์‹œ PlatformUUID
  • Linux โ€” ๋ฃจํŠธ ํŒŒํ‹ฐ์…˜ UUID์˜ SHA-256 ํ•ด์‹œ์ž…๋‹ˆ๋‹ค.
  • ์• ํ”Œ ์•„์ดํฐ OS โ€” SHA-256 ํ•ด์‹œ PlatformUUID
  • Android โ€“ ๋ฌธ์„œ ์ฐธ์กฐ ๋งํฌ

๋”ฐ๋ผ์„œ ์šฐ๋ฆฌ๋Š” ํšŒ์‚ฌ Windows OS์šฉ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ์ด ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์•Œ๋ ค์ง„ ์ž…๋ ฅ์„ ์‚ฌ์šฉํ•˜์—ฌ ๋กœ์ปฌ๋กœ UDID๋ฅผ ๊ณ„์‚ฐํ•˜๊ณ  ํ•„์ˆ˜ ํ•„๋“œ์— ์ด UDID๋ฅผ ์ž…๋ ฅํ•˜์—ฌ ์ธ์ฆ์„œ ๋ฐœ๊ธ‰ ์š”์ฒญ์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ๋ฐ ๊ธฐ๊ณ„๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค. AD์—์„œ ๋ฐœ๊ธ‰ํ•œ ์ธ์ฆ์„œ(์ธ์ฆ์„œ๋ฅผ ์ด์šฉํ•œ ์ด์ค‘ ์ธ์ฆ์„ ์ฒด๊ณ„์— ์ถ”๊ฐ€ํ•˜์—ฌ) ๋‹ค์ค‘ ์ธ์ฆ์„œ).

Cisco ASA ์ธก์—์„œ ์„ค์ •์„ ์ค€๋น„ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

ISE CA ์„œ๋ฒ„์šฉ TrustPoint๋ฅผ ์ƒ์„ฑํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ํด๋ผ์ด์–ธํŠธ์— ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ํ‚ค์ฒด์ธ ๊ฐ€์ ธ์˜ค๊ธฐ ์ ˆ์ฐจ๋Š” ๊ณ ๋ คํ•˜์ง€ ์•Š๊ฒ ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋Š” ์„ค์ •์— ๋Œ€ํ•œ ๋‚ด ๊ธฐ์‚ฌ์— ์„ค๋ช…๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. VPN ๋ถ€ํ•˜ ๋ถ„์‚ฐ ํด๋Ÿฌ์Šคํ„ฐ.

crypto ca trustpoint ISE-CA
 enrollment terminal
 crl configure

์ธ์ฆ์— ์‚ฌ์šฉ๋˜๋Š” ์ธ์ฆ์„œ์˜ ํ•„๋“œ์— ๋”ฐ๋ฅธ ๊ทœ์น™์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ„ฐ๋„ ๊ทธ๋ฃน๋ณ„ ๋ฐฐํฌ๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค. ์ด์ „ ๋‹จ๊ณ„์—์„œ ๋งŒ๋“  AnyConnect ํ”„๋กœํ•„๋„ ์—ฌ๊ธฐ์—์„œ ๊ตฌ์„ฑ๋ฉ๋‹ˆ๋‹ค. ๊ฐ’์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์Œ์„ ์ฐธ๊ณ ํ•˜์„ธ์š”. ์‹œํ์–ด๋ฑ…ํฌ๋ผ, ๋ฐœ๊ธ‰๋œ ์ธ์ฆ์„œ๋ฅผ ๊ฐ€์ง„ ์‚ฌ์šฉ์ž๋ฅผ ํ„ฐ๋„ ๊ทธ๋ฃน์œผ๋กœ ์ „์†กํ•ฉ๋‹ˆ๋‹ค. ๋ณด์•ˆ-์€ํ–‰-VPN, AnyConnect ํ”„๋กœํ•„ ์ธ์ฆ์„œ ์š”์ฒญ ์—ด์— ์ด ํ•„๋“œ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

tunnel-group-map enable rules
!
crypto ca certificate map OU-Map 6
 subject-name attr ou eq securebank-ra
!
webvpn
 anyconnect profiles SECUREBANK disk0:/securebank.xml
 certificate-group-map OU-Map 6 SECURE-BANK-VPN
!

์ธ์ฆ ์„œ๋ฒ„๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ์ œ ๊ฒฝ์šฐ์—๋Š” XNUMX๋‹จ๊ณ„ ์ธ์ฆ์€ ISE์ด๊ณ , MFA๋Š” DUO(Radius Proxy)์ž…๋‹ˆ๋‹ค.

! CISCO ISE
aaa-server ISE protocol radius
 authorize-only
 interim-accounting-update periodic 24
 dynamic-authorization
aaa-server ISE (inside) host 192.168.99.134
 key *****
!
! DUO RADIUS PROXY
aaa-server DUO protocol radius
aaa-server DUO (inside) host 192.168.99.136
 timeout 60
 key *****
 authentication-port 1812
 accounting-port 1813
 no mschapv2-capable
!

๊ทธ๋ฃน ์ •์ฑ…, ํ„ฐ๋„ ๊ทธ๋ฃน ๋ฐ ํ•ด๋‹น ๋ณด์กฐ ๊ตฌ์„ฑ ์š”์†Œ๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

ํ„ฐ๋„ ๊ทธ๋ฃน ๊ธฐ๋ณธWEBVPN๊ทธ๋ฃน ์ฃผ๋กœ AnyConnect VPN ํด๋ผ์ด์–ธํŠธ๋ฅผ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ASA์˜ SCEP-Proxy ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•˜์—ฌ ์‚ฌ์šฉ์ž ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด ํ„ฐ๋„ ๊ทธ๋ฃน ์ž์ฒด์™€ ๊ด€๋ จ ๊ทธ๋ฃน ์ •์ฑ… ๋ชจ๋‘์—์„œ ํ•ด๋‹น ์˜ต์…˜์ด ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. AC-๋‹ค์šด๋กœ๋“œ๋ฐ ๋กœ๋“œ๋œ AnyConnect ํ”„๋กœํ•„(์ธ์ฆ์„œ ๋ฐœ๊ธ‰์„ ์œ„ํ•œ ํ•„๋“œ ๋“ฑ)์— ์žˆ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ ์ด ๊ทธ๋ฃน ์ •์ฑ…์—์„œ๋Š” ๋‹ค์šด๋กœ๋“œ๊ฐ€ ํ•„์š”ํ•จ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ISE ์ž์„ธ ๋ชจ๋“ˆ.

ํ„ฐ๋„ ๊ทธ๋ฃน ๋ณด์•ˆ-์€ํ–‰-VPN ์ด์ „ ๋‹จ๊ณ„์—์„œ ๋ฐœ๊ธ‰๋œ ์ธ์ฆ์„œ๋กœ ์ธ์ฆํ•  ๋•Œ ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์ž๋™์œผ๋กœ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ์™œ๋ƒํ•˜๋ฉด ์ธ์ฆ์„œ ๋งต์— ๋”ฐ๋ผ ์—ฐ๊ฒฐ์ด ํŠน๋ณ„ํžˆ ์ด ํ„ฐ๋„ ๊ทธ๋ฃน์— ์†ํ•˜๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ ํฅ๋ฏธ๋กœ์šด ์˜ต์…˜์— ๋Œ€ํ•ด ์„ค๋ช…ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

  • ๋ณด์กฐ ์ธ์ฆ ์„œ๋ฒ„ ๊ทธ๋ฃน DUO # DUO ์„œ๋ฒ„(Radius Proxy)์— XNUMX์ฐจ ์ธ์ฆ์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
  • ์‚ฌ์šฉ์ž ์ด๋ฆ„-์ธ์ฆ์„œCN # ๊ธฐ๋ณธ ์ธ์ฆ์˜ ๊ฒฝ์šฐ ์ธ์ฆ์„œ์˜ CN ํ•„๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์‚ฌ์šฉ์ž ๋กœ๊ทธ์ธ์„ ์ƒ์†ํ•ฉ๋‹ˆ๋‹ค.
  • ์ธ์ฆ์„œ์˜ ๋ณด์กฐ ์‚ฌ์šฉ์ž ์ด๋ฆ„ I # DUO ์„œ๋ฒ„์—์„œ์˜ XNUMX์ฐจ ์ธ์ฆ์„ ์œ„ํ•ด ์ถ”์ถœ๋œ ์‚ฌ์šฉ์ž ์ด๋ฆ„๊ณผ ์ธ์ฆ์„œ์˜ ์ด๋‹ˆ์…œ(I) ํ•„๋“œ๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.
  • ์‚ฌ์šฉ์ž ์ด๋ฆ„ ๋ฏธ๋ฆฌ ์ฑ„์šฐ๊ธฐ ํด๋ผ์ด์–ธํŠธ # ์‚ฌ์šฉ์ž ์ด๋ฆ„์„ ๋ณ€๊ฒฝํ•  ์ˆ˜ ์—†๋„๋ก ์ธ์ฆ ์ฐฝ์— ๋ฏธ๋ฆฌ ์ฑ„์›Œ ๋„ฃ์Šต๋‹ˆ๋‹ค.
  • ๋ณด์กฐ-์‚ฌ์ „ ์ฑ„์šฐ๊ธฐ-์‚ฌ์šฉ์ž ์ด๋ฆ„ ํด๋ผ์ด์–ธํŠธ ์ˆจ๊ธฐ๊ธฐ-๊ณตํ†ต ๋น„๋ฐ€๋ฒˆํ˜ธ ํ‘ธ์‹œ # XNUMX์ฐจ ์ธ์ฆ์„ ์œ„ํ•ด ๋กœ๊ทธ์ธ/๋น„๋ฐ€๋ฒˆํ˜ธ ์ž…๋ ฅ์ฐฝ์„ ์ˆจ๊ธฐ๊ณ  DUO ์•Œ๋ฆผ๋ฐฉ์‹(SMS/ํ‘ธ์‹œ/์ „ํ™”)์„ ์‚ฌ์šฉ - ๋น„๋ฐ€๋ฒˆํ˜ธ ์ž…๋ ฅ๋ž€ ๋Œ€์‹  ์ธ์ฆ์š”์ฒญ์„ ์œ„ํ•œ ๋„ํ‚น ์—ฌ๊ธฐ์—

!
access-list posture-redirect extended permit tcp any host 72.163.1.80 
access-list posture-redirect extended deny ip any any
!
access-list VPN-Filter extended permit ip any any
!
ip local pool vpn-pool 192.168.100.33-192.168.100.63 mask 255.255.255.224
!
group-policy SECURE-BANK-VPN internal
group-policy SECURE-BANK-VPN attributes
 dns-server value 192.168.99.155 192.168.99.130
 vpn-filter value VPN-Filter
 vpn-tunnel-protocol ssl-client 
 split-tunnel-policy tunnelall
 default-domain value ashes.cc
 address-pools value vpn-pool
 webvpn
  anyconnect ssl dtls enable
  anyconnect mtu 1300
  anyconnect keep-installer installed
  anyconnect ssl keepalive 20
  anyconnect ssl rekey time none
  anyconnect ssl rekey method ssl
  anyconnect dpd-interval client 30
  anyconnect dpd-interval gateway 30
  anyconnect ssl compression lzs
  anyconnect dtls compression lzs
  anyconnect modules value iseposture
  anyconnect profiles value SECUREBANK type user
!
group-policy AC-DOWNLOAD internal
group-policy AC-DOWNLOAD attributes
 dns-server value 192.168.99.155 192.168.99.130
 vpn-filter value VPN-Filter
 vpn-tunnel-protocol ssl-client 
 split-tunnel-policy tunnelall
 default-domain value ashes.cc
 address-pools value vpn-pool
 scep-forwarding-url value http://ise.ashes.cc:9090/auth/caservice/pkiclient.exe
 webvpn
  anyconnect ssl dtls enable
  anyconnect mtu 1300
  anyconnect keep-installer installed
  anyconnect ssl keepalive 20
  anyconnect ssl rekey time none
  anyconnect ssl rekey method ssl
  anyconnect dpd-interval client 30
  anyconnect dpd-interval gateway 30
  anyconnect ssl compression lzs
  anyconnect dtls compression lzs
  anyconnect modules value iseposture
  anyconnect profiles value SECUREBANK type user
!
tunnel-group DefaultWEBVPNGroup general-attributes
 address-pool vpn-pool
 authentication-server-group ISE
 accounting-server-group ISE
 default-group-policy AC-DOWNLOAD
 scep-enrollment enable
tunnel-group DefaultWEBVPNGroup webvpn-attributes
 authentication aaa certificate
!
tunnel-group SECURE-BANK-VPN type remote-access
tunnel-group SECURE-BANK-VPN general-attributes
 address-pool vpn-pool
 authentication-server-group ISE
 secondary-authentication-server-group DUO
 accounting-server-group ISE
 default-group-policy SECURE-BANK-VPN
 username-from-certificate CN
 secondary-username-from-certificate I
tunnel-group SECURE-BANK-VPN webvpn-attributes
 authentication aaa certificate
 pre-fill-username client
 secondary-pre-fill-username client hide use-common-password push
 group-alias SECURE-BANK-VPN enable
 dns-group ASHES-DNS
!

๋‹ค์Œ์œผ๋กœ ISE๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

๋กœ์ปฌ ์‚ฌ์šฉ์ž๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค(AD/LDAP/ODBC ๋“ฑ ์‚ฌ์šฉ ๊ฐ€๋Šฅ). ๋‹จ์ˆœํ™”๋ฅผ ์œ„ํ•ด ISE ์ž์ฒด์—์„œ ๋กœ์ปฌ ์‚ฌ์šฉ์ž๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ํ˜„์žฅ์—์„œ ํ• ๋‹นํ–ˆ์Šต๋‹ˆ๋‹ค. ์„ค๋ช… ์œ ๋””๋“œ PC VPN์„ ํ†ตํ•ด ๋กœ๊ทธ์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ISE์—์„œ ๋กœ์ปฌ ์ธ์ฆ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ํ•„๋“œ๊ฐ€ ๋งŽ์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— ํ•˜๋‚˜์˜ ๋””๋ฐ”์ด์Šค๋กœ๋งŒ ์ œํ•œ๋˜์ง€๋งŒ ํƒ€์‚ฌ ์ธ์ฆ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์—์„œ๋Š” ์ด๋Ÿฌํ•œ ์ œํ•œ์ด ์—†์Šต๋‹ˆ๋‹ค.

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

๊ถŒํ•œ ๋ถ€์—ฌ ์ •์ฑ…์„ ์‚ดํŽด๋ณด๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋„ค ๊ฐ€์ง€ ์—ฐ๊ฒฐ ๋‹จ๊ณ„๋กœ ๊ตฌ๋ถ„๋ฉ๋‹ˆ๋‹ค.

  • ๋‹จ๊ณ„ 1 โ€” AnyConnect ์—์ด์ „ํŠธ ๋‹ค์šด๋กœ๋“œ ๋ฐ ์ธ์ฆ์„œ ๋ฐœ๊ธ‰ ์ •์ฑ…
  • ๋‹จ๊ณ„ 2 โ€” ๊ธฐ๋ณธ ์ธ์ฆ ์ •์ฑ… ๋กœ๊ทธ์ธ(์ธ์ฆ์„œ์—์„œ)/๋น„๋ฐ€๋ฒˆํ˜ธ + UDID ๊ฒ€์ฆ์ด ํฌํ•จ๋œ ์ธ์ฆ์„œ
  • ๋‹จ๊ณ„ 3 โ€” ์‚ฌ์šฉ์ž ์ด๋ฆ„์œผ๋กœ UDID๋ฅผ ์‚ฌ์šฉํ•˜๋Š” Cisco DUO(MFA)๋ฅผ ํ†ตํ•œ ๋ณด์กฐ ์ธ์ฆ + ์ƒํƒœ ํ‰๊ฐ€
  • ๋‹จ๊ณ„ 4 โ€” ์ตœ์ข… ์Šน์ธ ์ƒํƒœ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.
    • ์ค€์ˆ˜;
    • UDID ๊ฒ€์ฆ(์ธ์ฆ์„œ + ๋กœ๊ทธ์ธ ๋ฐ”์ธ๋”ฉ์—์„œ),
    • ์‹œ์Šค์ฝ” ๋“€์˜ค MFA;
    • ๋กœ๊ทธ์ธ์„ ํ†ตํ•œ ์ธ์ฆ;
    • ์ธ์ฆ์„œ ์ธ์ฆ;

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

ํฅ๋ฏธ๋กœ์šด ์กฐ๊ฑด์„ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. UUID_๊ฒ€์ฆ๋จ, ์ธ์ฆ ์‚ฌ์šฉ์ž๊ฐ€ ์‹ค์ œ๋กœ ํ•„๋“œ์— ์—ฐ๊ฒฐ๋œ ํ—ˆ์šฉ๋œ UDID๊ฐ€ ์žˆ๋Š” PC์—์„œ ์˜จ ๊ฒƒ์ฒ˜๋Ÿผ ๋ณด์ž…๋‹ˆ๋‹ค. ์ƒํ’ˆ ์„ค๋ช… ๊ณ„์ •์˜ ์กฐ๊ฑด์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

1,2,3๋‹จ๊ณ„์—์„œ ์‚ฌ์šฉ๋˜๋Š” ์ธ์ฆ ํ”„๋กœํ•„์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

ISE์—์„œ ํด๋ผ์ด์–ธํŠธ ์„ธ์…˜ ์„ธ๋ถ€ ์ •๋ณด๋ฅผ ๋ณด๋ฉด AnyConnect ํด๋ผ์ด์–ธํŠธ์˜ UDID๊ฐ€ ์–ด๋–ป๊ฒŒ ์šฐ๋ฆฌ์—๊ฒŒ ๋„์ฐฉํ•˜๋Š”์ง€ ์ •ํ™•ํ•˜๊ฒŒ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ํ†ตํ•ด AnyConnect๊ฐ€ ACIDEX ํ”Œ๋žซํผ์— ๋Œ€ํ•œ ์ •๋ณด๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์žฅ์น˜์˜ UDID๋„ ์ „์†กํ•ฉ๋‹ˆ๋‹ค. Cisco-AV-์Œ:

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

์‚ฌ์šฉ์ž์—๊ฒŒ ๋ฐœ๊ธ‰๋˜๋Š” ์ธ์ฆ์„œ์™€ ํ˜„์žฅ์— ์ฃผ๋ชฉํ•˜์ž ์ด๋‹ˆ์…œ(I), Cisco DUO์—์„œ ๋ณด์กฐ MFA ์ธ์ฆ์„ ์œ„ํ•œ ๋กœ๊ทธ์ธ์œผ๋กœ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

๋กœ๊ทธ์˜ DUO Radius Proxy ์ธก์—์„œ ์ธ์ฆ ์š”์ฒญ์ด ์–ด๋–ป๊ฒŒ ์ด๋ฃจ์–ด์ง€๋Š”์ง€ ๋ช…ํ™•ํ•˜๊ฒŒ ํ™•์ธํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, UDID๋ฅผ ์‚ฌ์šฉ์ž ์ด๋ฆ„์œผ๋กœ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

DUO ํฌํ„ธ์—์„œ ์„ฑ๊ณต์ ์ธ ์ธ์ฆ ์ด๋ฒคํŠธ๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

๊ทธ๋ฆฌ๊ณ  ์‚ฌ์šฉ์ž ์†์„ฑ์—์„œ ์„ค์ •ํ–ˆ์Šต๋‹ˆ๋‹ค. ALIAS, ๋กœ๊ทธ์ธ์— ์‚ฌ์šฉํ•œ ๊ฒƒ์€ ๋กœ๊ทธ์ธ์ด ํ—ˆ์šฉ๋œ PC์˜ UDID์ž…๋‹ˆ๋‹ค.

๋ณด์•ˆ์„ฑ์ด ๋›ฐ์–ด๋‚œ ์›๊ฒฉ ์•ก์„ธ์Šค ๊ฐœ๋… ๊ตฌํ˜„

๊ฒฐ๊ณผ์ ์œผ๋กœ ์šฐ๋ฆฌ๋Š” ๋‹ค์Œ์„ ์–ป์—ˆ์Šต๋‹ˆ๋‹ค:

  • ๋‹ค๋‹จ๊ณ„ ์‚ฌ์šฉ์ž ๋ฐ ์žฅ์น˜ ์ธ์ฆ
  • ์‚ฌ์šฉ์ž ์žฅ์น˜์˜ ์Šคํ‘ธํ•‘์œผ๋กœ๋ถ€ํ„ฐ ๋ณดํ˜ธํ•ฉ๋‹ˆ๋‹ค.
  • ์žฅ์น˜ ์ƒํƒœ ํ‰๊ฐ€
  • ๋„๋ฉ”์ธ ๋จธ์‹  ์ธ์ฆ์„œ ๋“ฑ์„ ํ†ตํ•ด ์ œ์–ด๊ฐ€ ๊ฐ•ํ™”๋  ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์Šต๋‹ˆ๋‹ค.
  • ์ž๋™์œผ๋กœ ๋ฐฐํฌ๋œ ๋ณด์•ˆ ๋ชจ๋“ˆ์„ ํ†ตํ•œ ํฌ๊ด„์ ์ธ ์›๊ฒฉ ์ž‘์—… ๊ณต๊ฐ„ ๋ณดํ˜ธ

Cisco VPN ์‹œ๋ฆฌ์ฆˆ ๊ธฐ์‚ฌ ๋งํฌ:

์ถœ์ฒ˜ : habr.com

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€