UTM(Unified Threat Management:çµ±ååè åšç®¡ç)ãšã¯ããããã¯ãŒã¯ãããŸããŸãªè åšããç·åçã«ä¿è·ããããã®ã¢ãã©ã€ã¢ã³ã¹ã®ããšã ãå ã ç¬ç«ããããŒããŠã§ã¢ãšããŠè£œååãããŠãããã¡ã€ã¢ãŠã©ãŒã«ã«ãæ°ããªè åšã«å¯Ÿå¿ããããã®ã»ãã¥ãªãã£æ©èœã次ã ã«è¿œå ããŠããåœ¢ã§æç«ããããã€ã¹ã ãšèããŠããã ããã
å®å šãªãããã¯ãŒã¯æ¥ç¶ãå®çŸããããã«VPN(Virtual Private Network)æ©èœãåããŠããã®ãäžè¬çã§ãIPS(äŸµå ¥é²æ¢ã·ã¹ãã )ãã¢ã³ããŠã€ã«ã¹ãªã©ã®æ©èœãçµã¿åãããããããŒããŠã§ã¢çãã¡ã€ã¢ãŠã©ãŒã«ã®çºå±ãšããäœçœ®ã¥ãããããäžè¬ã«ãããã¯ãŒã¯ã®å€éšãšå éšã®å¢çã«çœ®ãããå éšãããã¯ãŒã¯å šäœãå€éšããã®è åšããä¿è·ããããšãçã£ãæ©èœæ§æãæ¡ããããVPNæ©èœãäžè¬çãªã®ããå€éšãããã¯ãŒã¯ãšã®å¢çã«èšçœ®ããããšããç¹åŸŽãèããã°çè§£ããããã
UTMã¯åŸæ¥ãäžå°èŠæš¡ç°å¢åãã»ãã¥ãªãã£ã»ããã€ã¹ãšããèªèãäžè¬çã ã£ãããšããã®ãããããã¯ãŒã¯ã®å¢çã«1å°ãã³ãšçœ®ãã ãã§ã»ãã¥ãªãã£ãé«ãããããšãã簡䟿ãããå°ä»»ç®¡çè ã®ããªãäžå°èŠæš¡ã®ãããã¯ãŒã¯ã§éå®ãããããã ããŸããåæã®è£œåã¯æ§èœçã«å€§èŠæš¡ãããã¯ãŒã¯ã®èšå€§ãªãã©ãã£ãã¯ã«èãããããããã«ããã¯ãšãªã£ãŠããŸãæžå¿µããã£ãã
ãããUTMã®é«æ©èœåã¯ç¢ºå®ã«é²è¡ããŠãããçŸåšã§ã¯å€§èŠæš¡ãããã¯ãŒã¯ã«å¯Ÿå¿ã§ãã髿§èœæ©çš®ããå éšãè€æ°ã®ä»®æ³ã¢ãã©ã€ã¢ã³ã¹ã«åå²ããŠããããç°ãªãèšå®ã§éçšã§ãããããªæ©çš®ãåºçŸããŠããã
以äžãUTMã®ä»£è¡šçãªãã³ããŒã®ååã説æãããã
ã¢ãžã¥ã©ãŒåã¢ãŒããã¯ãã£ã§é«ãç®¡çæ§ãšæ¡åŒµæ§ãå®çŸ - ãã§ãã¯ã»ãã€ã³ã
ãã§ãã¯ã»ãã€ã³ãã»ãœãããŠã§ã¢ã»ãã¯ãããžãŒãºã¯ãUTMãšããŠå°èŠæš¡åããUTM-1 Edgeããæããããäžæ žãšãªãã®ã¯ããäžäœã®ãUTM-1ã·ãªãŒãºãã ãæäžäœã¢ãã«ãUTM-1 3070ãã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã»ã¹ã«ãŒãããã4.5Gbpsãšãªã£ãŠãããæè¿ã®é«éåååãèžãŸãã仿§ãšãªã£ãŠãããå瀟ã®UTMã¯ãSoftware BladeããšåŒã°ããã¢ãžã¥ã©ãŒåã¢ãŒããã¯ãã£ãæ¡çšããŠãããã»ãã¥ãªãã£æ©èœãä»»æã«è¿œå ã§ããããã«ãªã£ãŠãããããã«ãããç®¡çæ§ãšæ¡åŒµæ§ã«åªããã³ã¹ãããã©ãŒãã³ã¹ãé«ãŸããç®¡çæ§ãæãªãããšãªãæ¡åŒµæ§ã確ä¿ããã®ã«æå¹ãªã¢ãŒããã¯ãã£ã ããã
ç¬èªASICã«ããæ§èœåäžãè¿œæ± - ãã©ãŒãã£ããã
ãã©ãŒãã£ãããã¯ä»å¹Ž1æãåŸæ¥ã¢ãã«ã«æ¯ããŠå€§å¹ ã«ã¹ã«ãŒããããåäžãããæ°äžä»£æ©ãçºè¡šããããšã³ããªãŒã¢ãã«ãFortiGate-200Bãã¯ãã¡ã€ã¢ãŠã©ãŒã«ã»ã¹ã«ãŒããã5Gbpsã§ãèš16ããŒããåããããã€ãšã³ãã¢ãã«ãFortiGAte-1240Bãã¯ããã¡ã€ã¢ãŠã©ãŒã«ã»ã¹ã«ãŒããã40Gbpsã§ããŒãæ°ã¯40ã«éããã倧éãã©ãã£ãã¯ã«å¯Ÿå¿ããããã®é«ã¹ã«ãŒãããã®å®çŸãšããããã¯ãŒã¯ã»ããããžãŒã®æè»æ§ãé«ããå€ããŒãåãšãããã¬ã³ããé®®æã«ãªã£ãæ©çš®ãšèšãããå瀟ã¯ç¬èªASICã«ããæ§èœåäžã远æ±ããŠãããIPsec VPNãã¢ã³ããŠã€ã«ã¹ãªã©ãåçš®ã»ãã¥ãªãã£æ©èœãçšããéã®ã¹ã«ãŒããããé«éåããŠãããæ¥æ¬åžå Žã®éèŠã«å¯Ÿå¿ããåçš®ã®ã»ãã¥ãªãã£æ©èœã§IPv6ã«ã察å¿ããŠããŠããã®ãç¹åŸŽãšãªãã
ä»åŸã®é«éåã«æåŸ ããã - ãžã¥ãããŒ
ãžã¥ãããŒãããã¯ãŒã¯ã¹ã¯ãåœå ã§ãUTMã®ä»£è¡šçãªãã³ããŒãšããŠåºãèªç¥ãããŠããããæè¡é¢ã§ã¯ããäžå±€ã®é«éåã管çè² æ ã®è»œæžãç®æããŠãããçŸåšå瀟ãç¹ã«åãå ¥ããŠããã®ã¯ãã¯ã©ãŠãåããããŒã¿ã»ã³ã¿ãŒååãèŠæ®ãããããã¯ãŒã¯ã»ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ§ç¯ã®ããã®è£œå矀ã§ãç¹ã«ãã€ãšã³ãã»ã«ãŒã¿ãªã©ã®åéã§æ°ããªã¢ãŒããã¯ãã£ã®æ§ç¯ã«åãçµãã§ããããã®ããããUTMåéã§ã®è£œåæŽæ°ã¯ããé ãæ°å³ãšããå°è±¡ãåãããåºç¯ãªã¢ãã«çŸ€ãæããŠãããã代衚çãªUTM補åãSSGã·ãªãŒãºãã®æäžäœã«åœãããSSG550Mãã§ããã¡ã€ã¢ãŠã©ãŒã«ã»ããã©ãŒãã³ã¹ã®æå€§ã1Gbpsãšãªã£ãŠãããé«éåãé²ãã§ããçŸç¶ããèŠããšããç©è¶³ããªãå°è±¡ãããã
3æ©çš®ã§å°èŠæš¡ããå€§èŠæš¡ãŸã§ã«ã㌠- ãœããã¯ãŠã©ãŒã«
ãœããã¯ãŠã©ãŒã«ã¯ããSonicWALL TotalSecureããSonicWALL NSA(Network Security Appliance)ããSonicWALL NSA E-Classãã®3系統ã®è£œåãå±éããŠãããäŒæ¥ããããã¯ãŒã¯ã®èŠæš¡ã«å¿ããŠå°èŠæš¡ããå€§èŠæš¡ãŸã§ãã«ããŒãã圢ã ããããããé«ããããã¯ãŒã¯ã»ã¹ã«ãŒãããã«å¯Ÿå¿ããåŠçæ§èœãé«éåããããšã§è€éãªã»ãã¥ãªãã£å¯Ÿçãå®è¡ããäœå°ã確ä¿ãããšãã£ãéšåã§ã¯å ±éã®ã¢ãããŒããšãªã£ãŠããã
çŸåšãUTMã¯ããå€§èŠæš¡ãªæ§æã«å¯Ÿå¿ããããã®é«éåãæ¥éã«é²ã¿ã€ã€ãããäŒæ¥ãããã¯ãŒã¯ã§ã¯ãã¹ã¯ãããPCã§ã1Gbpsãåœããåã«ãªãããµãŒãã§ã¯10Gbpsãåºã䜿ãããããã«ãªã£ãŠããŠãããããUTMããããªãé«éåãæ±ããããŠãããšããããã ã
ããã«ããã±ããåŠçãé«éã§è¡ãæ§èœãããã°DDoSæ»æãªã©ãžã®èæ§ãé«ãŸããããã»ãã¥ãªãã£ã»ã¬ãã«ã®åäžã«ãã€ãªãããããã«ã¯ãããŒã¿ã»ã³ã¿ãŒã®éçšå¹çæ¹åã®ããããããã¯ã©ãŠããªã©ã®ããå€§èŠæš¡ãªç°å¢ãžã®éçŽãèµ·ããå§ããŠãããããã«ãããUTMãããå€§èŠæš¡ãªç°å¢ã«å¯Ÿå¿ããããã®åŠçæ§èœããæ¬æ¥ã®å©ç¹ã§ããããªãŒã«ã€ã³ã¯ã³ã§éçšç®¡çè² æ ãäœãããšããç¹ãç¶æãããŸãŸå€§èŠæš¡ç°å¢ã«å¯Ÿå¿ããããã®ç®¡çæ©èœã®åŒ·åãæ±ããããŠããã