Kukhazikitsidwa kwa lingaliro lachitetezo chakutali chotetezedwa
Kupitiliza mndandanda wa zolemba pamutu wa bungwe VPN yakutali kupeza sindingachitire mwina koma kugawana zomwe ndakumana nazo zosangalatsa za kutumiza kasinthidwe ka VPN kotetezedwa kwambiri. Ntchito yosakhala yaing'ono idaperekedwa ndi kasitomala m'modzi (pali oyambitsa m'midzi yaku Russia), koma Vutoli lidavomerezedwa ndikukhazikitsidwa mwaluso. Zotsatira zake ndi lingaliro losangalatsa lomwe lili ndi izi:
Zinthu zingapo zodzitchinjiriza pakulowa m'malo mwa cholumikizira (chomangirira kwambiri kwa wogwiritsa);
Kuwunika kutsata kwa PC ya wogwiritsa ntchito ndi UDID yopatsidwa ya PC yololedwa mu nkhokwe yotsimikizika;
Ndi MFA pogwiritsa ntchito PC UDID kuchokera ku satifiketi yotsimikizira yachiwiri kudzera pa Cisco DUO (Mutha kuphatikizira iliyonse yogwirizana ndi SAML/Radius);
Kutsimikizika kwazinthu zambiri:
Satifiketi ya wogwiritsa ntchito yotsimikizira kumunda ndi kutsimikizika kwachiwiri motsutsana ndi mmodzi wa iwo;
Lowani (osasinthika, otengedwa ku satifiketi) ndi mawu achinsinsi;
Kuyerekeza momwe wolumikizirayo alili (Posture)
Zomwe zimagwiritsidwa ntchito poyankha:
Cisco ASA (VPN Gateway);
Cisco ISE (Kutsimikizika / Kuvomerezeka / Kuwerengera, Kuwunika kwa State, CA);
Cisco DUO (Multi-Factor Authentication) (Mutha kuphatikizira iliyonse yogwirizana ndi SAML/Radius);
Cisco AnyConnect (Multi-purpose agent for workstations and mobile OS);
Tiyeni tiyambe ndi zomwe kasitomala amafuna:
Wogwiritsa ntchito ayenera, kudzera mu kutsimikizika kwake kwa Login/Password, athe kutsitsa kasitomala wa AnyConnect kuchokera pachipata cha VPN; ma module onse ofunikira a AnyConnect ayenera kukhazikitsidwa okha malinga ndi mfundo za wogwiritsa ntchito;
Wogwiritsa ntchitoyo azitha kutulutsa satifiketi (pachimodzi mwazinthuzi, chochitika chachikulu ndikutulutsa pamanja ndikuyika pa PC), koma ndidakhazikitsa zongowonetsera (sindinachedwe kuyichotsa).
Kutsimikizika koyambira kuyenera kuchitika m'magawo angapo, choyamba pamakhala chitsimikiziro cha satifiketi ndikuwunika magawo ofunikira ndi zikhalidwe zawo, kenako kulowa / mawu achinsinsi, nthawi ino yokha dzina la ogwiritsa lomwe latchulidwa m'gawo la satifiketi liyenera kuyikidwa pawindo lolowera. Dzina la Mutu (CN) wopanda luso lotha kusintha.
Tsopano ndikulingalira kuti tiganizire zambiri za kukhazikitsa zomwe sizinafotokozedwe muvidiyoyi.
Tiyeni tikonzekere mbiri ya AnyConnect:
M'mbuyomu ndidapereka chitsanzo chopanga mbiri (molingana ndi chinthu cha menyu mu ASDM) m'nkhani yanga yokhazikitsa VPN Load-Bancing Cluster. Tsopano ndikufuna kuzindikira padera zosankha zomwe tidzafunikira:
Pambiri, tiwonetsa chipata cha VPN ndi dzina la mbiri yolumikizira kasitomala womaliza:
Tiyeni tikonze kuperekedwa kwa chiphaso chodziwikiratu kuchokera kumbali ya mbiri, kuwonetsa, makamaka, magawo a satifiketi ndipo, makamaka, tcherani khutu kumunda. Zoyamba (I), pomwe mtengo wake umalowetsedwa pamanja UDID makina oyesera (Chizindikiritso cha chipangizo chapadera chomwe chimapangidwa ndi kasitomala wa Cisco AnyConnect).
Apa ndikufuna kuti ndisinthe mawu, popeza nkhaniyi ikufotokoza lingaliro; pazolinga zowonetsera, UDID yopereka satifiketi imalowetsedwa m'gawo loyambira la mbiri ya AnyConnect. Inde, m'moyo weniweni, ngati muchita izi, ndiye kuti makasitomala onse adzalandira chiphaso chokhala ndi UDID yomweyo m'munda uno ndipo palibe chomwe chidzawathandize, chifukwa amafunikira UDID ya PC yawo yeniyeni. AnyConnect, mwatsoka, sichikuyikabe m'malo mwa gawo la UDID m'malo ofunsira satifiketi kudzera pakusintha kwachilengedwe, monga momwe zimakhalira, mwachitsanzo, ndikusintha. %USER%.
Ndizofunikira kudziwa kuti kasitomala (mwachiwonetserochi) poyambirira akukonzekera kutulutsa ziphaso zodziyimira pawokha ndi UDID yoperekedwa mumayendedwe apamanja ku Ma PC Otetezedwa, omwe sivuto kwa iye. Komabe, kwa ambiri aife tikufuna zokha (chabwino, kwa ine ndizowona =)).
Ndipo izi ndi zomwe ndingathe kupereka pankhani ya automation. Ngati AnyConnect sanathebe kutulutsa satifiketi yokha mwa kulowetsa UDID mwachangu, pali njira ina yomwe ingafune kulingalira pang'ono ndi manja aluso - ndikuwuzani lingalirolo. Choyamba, tiyeni tiwone momwe UDID imapangidwira pamakina osiyanasiyana ogwiritsira ntchito ndi AnyConnect wothandizira:
Windows - SHA-256 hash ya kuphatikiza kwa DigitalProductID ndi kiyi yolembetsa ya Machine SID
Chifukwa chake, timapanga script ya Windows OS yathu yamakampani, ndi script iyi timawerengera UDID m'dera lanu pogwiritsa ntchito zolowa zodziwika ndikupanga pempho lopereka satifiketi polowetsa UDID iyi pagawo lofunikira, mwa njira, mutha kugwiritsanso ntchito makina. satifiketi yoperekedwa ndi AD (powonjezera kutsimikizika kawiri pogwiritsa ntchito satifiketi ku chiwembu Satifiketi Yambiri).
Tiyeni tikonzekere makonda kumbali ya Cisco ASA:
Tiyeni tipange TrustPoint ya seva ya ISE CA, ndi yomwe idzapereke ziphaso kwa makasitomala. Sindingaganizire njira yolowetsa Key-Chain; chitsanzo chikufotokozedwa m'nkhani yanga yokhazikitsira VPN Load-Bancing Cluster.
crypto ca trustpoint ISE-CA
enrollment terminal
crl configure
Timakonza zogawa ndi Tunnel-Group kutengera malamulo malinga ndi magawo omwe ali pa satifiketi yomwe imagwiritsidwa ntchito kutsimikizira. Mbiri ya AnyConnect yomwe tidapanga kale idakonzedwanso pano. Chonde dziwani kuti ndikugwiritsa ntchito mtengo wake Chithunzi cha SECUREBANK-RA, kusamutsa ogwiritsa ntchito satifiketi yoperekedwa ku gulu la ngalande SECURE-BANK-VPN, chonde dziwani kuti ndili ndi gawo ili pamndandanda wofunsira satifiketi ya mbiri ya AnyConnect.
Kukhazikitsa ma seva otsimikizira. Kwa ine, iyi ndi ISE pagawo loyamba la kutsimikizika ndi DUO (Radius Proxy) monga MFA.
! CISCO ISE
aaa-server ISE protocol radius
authorize-only
interim-accounting-update periodic 24
dynamic-authorization
aaa-server ISE (inside) host 192.168.99.134
key *****
!
! DUO RADIUS PROXY
aaa-server DUO protocol radius
aaa-server DUO (inside) host 192.168.99.136
timeout 60
key *****
authentication-port 1812
accounting-port 1813
no mschapv2-capable
!
Timapanga ndondomeko zamagulu ndi magulu a tunnel ndi zigawo zake zothandizira:
Gulu la tunnel ZokhazikikaWEBVPNGulu idzagwiritsidwa ntchito makamaka kutsitsa kasitomala wa AnyConnect VPN ndikupereka satifiketi yogwiritsa ntchito SCEP-Proxy function ya ASA; chifukwa cha ichi tili ndi zosankha zomwe zakhazikitsidwa pagulu lokha komanso pagulu lomwe likugwirizana nawo. AC-kutsitsa, ndi mbiri yodzaza ya AnyConnect (magawo operekera satifiketi, ndi zina). Komanso mu ndondomeko ya gululi tikuwonetsa kufunika kotsitsa ISE Posture Module.
Gulu la tunnel SECURE-BANK-VPN idzagwiritsidwa ntchito ndi kasitomala potsimikizira ndi satifiketi yomwe idaperekedwa kale, chifukwa, molingana ndi Mapu a Satifiketi, kulumikizanaku kudzagwera makamaka pagulu ili. Ndikuuzani zosankha zosangalatsa apa:
secondary-authentication-server-group DUO # Khazikitsani kutsimikizika kwachiwiri pa seva ya DUO (Radius Proxy)
username-from-certificateCN # Pakutsimikizira koyambirira, timagwiritsa ntchito gawo la CN la satifiketi kuti tilandire kulowa kwa wosuta
wachiwiri-wogwiritsa-kuchokera-satifiketi I # Pakutsimikizika kwachiwiri pa seva ya DUO, timagwiritsa ntchito dzina lolowera ndi magawo oyambira (I) a satifiketi.
Gawo 1 - Ndondomeko yotsitsa wothandizira wa AnyConnect ndikupereka satifiketi
Gawo 2 - Ndondomeko yotsimikizika yoyambira Lowani (kuchokera pa satifiketi)/Password + Sitifiketi yokhala ndi UDID yovomerezeka
Gawo 3 - Kutsimikizika kwachiwiri kudzera pa Cisco DUO (MFA) pogwiritsa ntchito UDID monga dzina lolowera + State assessment
Gawo 4 - Chilolezo chomaliza chili m'boma:
Wogwirizana;
Chitsimikizo cha UDID (kuchokera ku satifiketi + yomangiriza kulowa),
Cisco DUO MFA;
Kutsimikizira ndi kulowa;
Chitsimikizo cha satifiketi;
Tiyeni tiwone mkhalidwe wosangalatsa UUID_VALIDATED, zikuwoneka ngati wogwiritsa ntchitoyo adachokera pa PC yokhala ndi UDID yololedwa yolumikizidwa m'mundamo. Kufotokozera akaunti, zinthu zikuwoneka motere:
Mbiri yovomerezeka yomwe imagwiritsidwa ntchito pamagawo 1,2,3 ndi motere:
Mutha kuyang'ana ndendende momwe UDID yochokera kwa kasitomala wa AnyConnect imafikira kwa ife poyang'ana tsatanetsatane wamakasitomala mu ISE. Mwatsatanetsatane tiwona kuti AnyConnect kudzera pamakina ACIDEX imatumiza osati zambiri zokhudza nsanja, komanso UDID ya chipangizo monga Cisco-AV-PAIR:
Tiyeni tiyang'ane pa satifiketi yoperekedwa kwa wogwiritsa ntchito komanso gawo Zoyamba (I), yomwe imagwiritsidwa ntchito kuitenga ngati malowedwe ovomerezeka a MFA yachiwiri pa Cisco DUO:
Pa mbali ya DUO Radius Proxy mu chipikacho titha kuona bwino momwe pempho lovomerezeka limapangidwira, limabwera pogwiritsa ntchito UDID monga dzina lolowera:
Kuchokera pa doko la DUO tikuwona chochitika chotsimikizika chopambana:
Ndipo muzogwiritsa ntchito zomwe ndakhazikitsa ALIAS, yomwe ndidagwiritsa ntchito polowera, iyi ndiye UDID ya PC yololedwa kulowa:
Chifukwa chake tapeza:
Multi-factor wosuta ndi chipangizo kutsimikizika;
Chitetezo ku kuwonongeka kwa chipangizo cha wosuta;
Kuwunika momwe chipangizocho chilili;
Kuthekera kwa kuwongolera kowonjezereka ndi satifiketi yamakina amtundu, ndi zina;
Chitetezo chokwanira chakutali ndi ma module otetezedwa;