ååã¯ããLANãšã€ã³ã¿ãŒãããã®å¢çãã§ã¯ãªããLANå éšãã«ãããŠã¢ã¯ã»ã¹å¶åŸ¡ãè¡ãå¿ èŠæ§ãšããã®ããã®ææ®µã«ã€ããŠèå¯ããããããŠãMACã¢ãã¬ã¹ãIPã¢ãã¬ã¹ãå©çšããæ¹æ³ã䜿ããããã管çé¢ã®è² æ ãå°ãªããšããçµè«ãå°ãåºããã
ããã§ä»åã¯ãããå ·çŸåããææ®µãšããŠããããã®ã¢è£œã®ã¹ã€ãã補åã䜿çšããèšå®ã®å ·äœäŸã«ã€ããŠåãäžããããããã¯ACL(Access Control List)ã®èšå®äœæ¥ãšããããšã«ãªãã®ã ããMACã¢ãã¬ã¹ã䜿çšããMAC ACLãšãIPã¢ãã¬ã¹ã䜿çšããIP ACLã«ã€ããŠãæŠèŠã玹ä»ããã
ä»å䜿çšãã補åãšãACLã«ãã£ãŠå®çŸã§ããããš
ä»åãACLèšå®ã«ã€ããŠç޹ä»ããããã«äœ¿çšããã®ãããã¹ã¿ãã£ãã¯ã«ãŒãã£ã³ã°æ©èœæèŒ48ããŒãL2ã®ã¬ããããã«ãããŒãžã¹ã€ããããšåŒã°ãã補åã®ãGSM7248v2ãã
|
ä»å䜿çšããã¹ã¿ãã£ãã¯ã«ãŒãã£ã³ã°æ©èœæèŒ48ããŒãL2ã®ã¬ããããã«ãããŒãžã¹ã€ãããGSM7248v2ã |
å®ã¯ãã®è£œåãåãªãã¬ã€ã€ãŒ2ã¹ã€ããã§ã¯ãªããVLAN(Vitrual LAN)ããšã«ç°ãªããããã¯ãŒã¯ã¢ãã¬ã¹ãå²ãåœãŠãŠVLANéã§ã«ãŒãã£ã³ã°ãè¡ããã¬ã€ã€ãŒ3ã¹ã€ãããšåæ§ã®æ©èœãåããŠããããã ããä»åã¯ACLãããŒããªã®ã§ãVLANãVLANéã«ãŒãã£ã³ã°ã®æ©èœã¯äœ¿çšããŠããªãã
ã§ã¯ãMAC ACLãIP ACLã§ã¯ãã©ãããèšå®ãè¡ããã©ãããããšãã§ããã®ã ãããã
MAC ACLã¯MACã¢ãã¬ã¹ãIP ACLã¯IPã¢ãã¬ã¹(IPv4ãšIPv6ã®ãããã«ã察å¿)ãæ¡ä»¶ã«äœ¿çšããã®ã ãããããããèšå®ã§ããåäœã¯ãèš±å¯(permit)ããšãæåŠ(deny)ãã®äž¡æ¹ããããã€ãŸããééã®èš±å¯ãããééã®æåŠããèšå®å¯èœã§ããããã®èŸºã¯ãã«ãŒã¿ã®ãã±ãããã£ã«ã¿æ©èœãšåãã§ããã
MAC ACLã«ã€ããŠã¯ãåžžã«éä¿¡å ã ãã§ãªãå®å ã¢ãã¬ã¹ãæ¡ä»¶ã«æå®ã§ãããã ããããç¹å®ã®PCãéåºãããã©ãã£ãã¯ãã ãã§ãªããç¹å®ã®PCã«å®ãŠããã©ãã£ãã¯ããèš±å¯ããããã¯é®æã§ãããç¹å®ã®ç€Ÿå¡ã«ããã¢ã¯ã»ã¹ãããããªãæ©åŸ®æ å ±ãæ±ã£ãŠãããµãŒãã«å¯ŸããŠãç©ççã«ã¢ã¯ã»ã¹å¶éãããããããªå Žé¢ã§äœ¿ãããã ã
äžæ¹ãIP ACLã¯äºæ ãç°ãªããåºæ¬ã®IP Basic ACLã§ã¯éä¿¡å ã¢ãã¬ã¹ã®æå®ã®ã¿ã§ãããæ¡åŒµçã®IP Extended ACLã§ã¯å®å ã®æå®ãå¯èœã ãã©ã¡ãã䜿çšãããã¯ãACLäœæã®éã«æå®ããã
IP ACLã¯IPãã©ãã£ãã¯ã察象ã ãããIPã¢ãã¬ã¹ã ãã§ãªãããŒãçªå·ã®æ å ±ã䜵çšããŠãç¹å®ã®IPã¢ããªã±ãŒã·ã§ã³ã ããã¢ã¯ã»ã¹å¶åŸ¡ã®å¯Ÿè±¡ã«ããããšãã§ããããã¡ãããIPã¢ãã¬ã¹æå®ã®éã«ã¯ç¹å®ã®åäžIPã¢ãã¬ã¹ã ãã§ãªããããããã¹ã¯ã®æ å ±ã䜵çšããŠãããã¯ãŒã¯ã¢ãã¬ã¹åäœã§æå®ããããšãã§ããã
å®ã¯ãããã¯MAC ACLãåãã§ããã¹ã¯æå®ã«ããMACã¢ãã¬ã¹ã®ã°ã«ãŒãåãå¯èœã§ããã48ãããã®é·ããæã€MACã¢ãã¬ã¹ã®ãã¡ãäžäœ24ãããã®OUI(Organizationally Unique Identifier)ã¯ãããã¯ãŒã¯æ©åšã®ãã³ãããšã«åºæã®å€ãå²ãåœãŠãã®ã§ãåäžãã³ãã®LANã¢ããã¿ã§ããã°ããã¹ã¯èšå®ã«ãã£ãŠäžæ¬æå®ã§ããçå±ã§ããã
MAC ACLãIP ACLããè€æ°ã®ã«ãŒã«ãç»é²ããããšãã§ããããã®å Žåãè€æ°ã®ã«ãŒã«ãé çªã«é©çšããŠãäžäœã«ãŒã«ã®å¯Ÿè±¡ããå€ãããã®ã«ã€ããŠå¥ã«ãŒã«ãé©çšããŠãã圢ã«ãªãã®ã§ãã«ãŒã«ã®èšå®ãšäžŠã³é ã«ã¯æ³šæãå¿ èŠã ããã£ãšããèãæ¹ã¯ã«ãŒã¿ã®ãã±ãããã£ã«ã¿ã§è€æ°ã®ã«ãŒã«ãç»é²ãããšããšäŒŒãŠããããããã¡ãã®çµéšãããã°ããã»ã©éåæã¯ãªããããããªãã
æ¬é¡ã«å ¥ãåã«ãããããåãäžããåé ç®ã«å ±éããã远å ã»åé€ã»å€æŽã®æäœã«ã€ããŠå ã«è¿°ã¹ãŠãããã
èšå®ç»é¢ã§æååãå€ã®å ¥åããããã¯éžæãè¡ã£ãåŸã«[ADD]ãã¯ãªãã¯ãããšãç»é²ããäžèЧã§å¯Ÿè±¡é ç®ã®ãã§ãã¯ããã¯ã¹ããªã³ã«ããŠãã[DELETE]ãã¯ãªãã¯ãããšãåé€ããäžèЧã§ãã§ãã¯ããã¯ã¹ããªã³ã«ããŠå 容ãä¿®æ£ããŠãã[APPLY]ãã¯ãªãã¯ãããšã倿Žãã§ããã
MAC ACLã®èšå®äŸ
ãŸããMAC ACLã®èšå®ããåãäžããããäœæ¥æé ã®æŠç¥ã¯ä»¥äžã®ããã«ãªãã
- [MAC ACL]ç»é¢ã§ãACL IDãèšå®ãã
- [MAC Rules]ç»é¢ã§ãACLäœæã®ããã®ã«ãŒã«ãèšå®ãã
- [MAC Binding Configuration]ç»é¢ã§ãACL IDãå²ãåœãŠãããŒããæå®ãã
- ããããŠèšå®ããå 容ã¯ã[MAC Binding Table]ç»é¢ã§ç¢ºèªã§ãã
ãŸã[MAC ACL]ç»é¢ã¯ãWebãã©ãŠã¶ã§ã¹ã€ããã®èšå®ç»é¢ã«ã¢ã¯ã»ã¹ããŠã[Security]ã¿ã以äžã®[ACL]â[Basic]â[MAC ACL]ãšãã©ãããšã§è¡šç€ºãããããã§[Name]ã«MAC ACLã®ååãå ¥åãããååã«äœ¿çšã§ããæåã¯ãè±æ°åã»ãã€ãã³ã»ã¹ããŒã¹ã»ã¢ã³ããŒã¹ã³ã¢ã§ãã¢ã«ãã¡ãããã§å§ãŸãååã«ããå¿ èŠãããã
MAC ACLãå¿ èŠãªæ°ã ãç»é²ããããMAC Rulesã®èšå®ã«ç§»ãã[MAC ACL]ç»é¢ã§ã¯ãç»é²ããACLã®ååããã€ããŒãªã³ã¯ã«ãªã£ãŠããã®ã§ããããã¯ãªãã¯ãããšMAC Rulesã®èšå®ãå¯èœã«ãªãããŸãã[Security]ã¿ã以äžã®[ACL]â[Basic]â[MAC Rules]ãšãã©ãæ¹æ³ã§ã衚瀺ã§ããã
MAC Rulesã®äž»ãªèšå®é ç®ã¯ä»¥äžã®éãã§ãããã²ãšã€ã®ACLã«è€æ°ã®ã«ãŒã«ãç»é²ããããšãã§ãããããã¯IDçªå·ã§èå¥ããã
ã»ID : ã«ãŒã«ããšã®èå¥çªå·(1ïœ12)
ã»Action : éé(permit)ãŸãã¯æåŠ(deny)
ã»Match Every : ãã¹ãŠã®ãã¬ãŒã ã«é©çšãããã©ãããæ±ºãããFalseãéžæãããšã以äžã®MACã¢ãã¬ã¹æå®ãå¯èœã«ãªã
ã»Source MAC : éä¿¡å MACã¢ãã¬ã¹
ã»Source MAC Mask : éä¿¡å MACã¢ãã¬ã¹ã«å¯Ÿãããã¹ã¯æå®ããxx:xx:xx:xx:xx:xxã圢åŒã§èšè¿°ãããããšãã°ãåäžã®MACã¢ãã¬ã¹ãªãã00:00:00:00:00:00ããäžäœ24ãããã§æ¬ãã®ã§ããã°ã00:00:00:ff:ff:ffããšãªã
ã»Destination MAC : å®å MACã¢ãã¬ã¹
ã»Destination MAC Mask : å®å MACã¢ãã¬ã¹ã«å¯Ÿãããã¹ã¯æå®
ã»Logging : ãã°èšé²ã®æç¡
MAC Ruleãå¿ èŠãªæ°ã ãç»é²ããããBinding Configurationã®èšå®ã«ç§»ãã[MAC Binding Configuration]ç»é¢ã¯ã[Security]ã¿ã以äžã®[ACL]â[Basic]â[MAC Binding Configuration]ãšãã©ãããšã§è¡šç€ºããã
ããã§ã¯ã[ACL ID]ã¡ãã¥ãŒã§ç»é²æžã¿ã®MAC ACLããªã¹ãããã¯ã¹ããéžæããŠãåªå é äœä»ããæå³ããã·ãŒã±ã³ã¹çªå·ãšãå²ãåœãŠå¯Ÿè±¡ã«ãªãããŒããæå®ããã
ãã®ãã¡ããŒãã®æå®ã¯ã[Port Selection Table]以äžã®[Unit 1]å·ŠåŽã«ãããã§ãã¯ããªã³ã«ããŠãããã«ãã®å·ŠåŽã«ããäžè§åœ¢ãã¯ãªãã¯ãããšå±éããããŒãäžèŠ§ã§æå®ããããã®ç¶æ ã§ã¯ãã¹ãŠã®ããŒãã«ãã§ãã¯ãå ¥ã£ãŠããã®ã§ã察象å€ã«ãããããŒãã®ãã§ãã¯ããªãã«ããã°ããã([Unit 1]å·ŠåŽã®ãã§ãã¯ããªãã«ãããŸãŸããŒãäžèЧãå±éããŠããããããããããšãã¡ãã¡ãªã³ã«ããå¿ èŠããããé©çšå¯Ÿè±¡ãšãªãããŒãã®å€å¯¡ã«å¿ããŠäœ¿ãåãããšè¯ãã ãã)
æåŸã«[APPLY]ãã¯ãªãã¯ãããšãèšå®ãåæ ããããã®çµæã¯ãç»é¢äžéšã®[Interface Binding Status]以äžã«çŸããã
|
[Unit 1]å·ŠåŽã®äžè§ãã¯ãªãã¯ãããšãããŒãäžèЧãå±éãããããã§é©çšå¯Ÿè±¡ããŒããæå®ãã |
|
[APPLY]ãã¯ãªãã¯ããŠèšå®ãé©çšãããšããã®çµæãäžã®[Interface Binding Status]以äžã«çŸãã |
ããããŠç»é²ããæ å ±ã確èªããããã®[Binding Table]ç»é¢ã¯ã[Security]ã¿ã以äžã®[ACL]â[Basic]â[Binding Table]ãšãã©ãããšã§è¡šç€ºãããããã§ã¯ãç»é²ããMAC ACLã«ã€ããŠãå²ãåœãŠå¯Ÿè±¡ã®ã€ã³ã¿ãã§ãŒã¹ãã¢ã¯ã»ã¹å¶åŸ¡å¯Ÿè±¡ã«ãªããã©ãã£ãã¯ã®åããACL IDãªã©ã®æ å ±ã確èªã§ããã
IP ACLã®èšå®äŸ
IP ACLã®èšå®ããæäœæé ã¯IP ACLãšäŒŒãŠãããããããèšå®ããé ç®ãããã®éã®å¶çŽäºé ã«ã¯éãããããäœæ¥æé ã®æŠç¥ã¯ä»¥äžã®ããã«ãªãã
- [IP ACL]ç»é¢ã§ãACL IDãèšå®ãã
- [IP Rules]ç»é¢ã§ãACLäœæã®ããã®ã«ãŒã«ãèšå®ãã
- [IP Binding Configuration]ç»é¢ã§ãACLã®IDãç®çã®ããŒãã«å²ãåœãŠã
- ããããŠèšå®ããå 容ã¯ã[IP Binding Table]ç»é¢ã§ç¢ºèªã§ãã
[IP ACL]ç»é¢ã¯ãWebãã©ãŠã¶ã§ã¹ã€ããã®èšå®ç»é¢ã«ã¢ã¯ã»ã¹ããŠã[Security]ã¿ã以äžã®[ACL]â[Advanced]â[IP ACL]ãšãã©ãããšã§è¡šç€ºããã
ããã§[Name]ã«IP ACLã®ååãå ¥åããã1ïœ99ã®ç¯å²ã®æ°åãå ¥åãããšIP Basic ACLã100ïœ199ã®ç¯å²ã®æ°åã¯IP Extended ACLãè±æ°æååã¯Named IP ACLããšèªåçã«èå¥ããŠã¿ã€ããæ±ºå®ãããNamed IP ACLã®ååã«äœ¿çšã§ããæåã¯è±æ°åã ãã§ãã¢ã«ãã¡ãããã§å§ããå¿ èŠãããã
ã€ãŸããå®å IPã¢ãã¬ã¹ãããŒãçªå·ã®æå®ãè¡ãã«ã¯ã100ïœ199ã®ç¯å²ã®æ°å€ããããã¯æååã®ååãæå®ããå¿ èŠãããããšã«ãªããéä¿¡å IPã¢ãã¬ã¹ã®æå®ã ãã§ãããã°ã1ïœ99ã®ç¯å²ã®æ°å€ãæå®ããæ¹ã簡䟿ã ã
|
IP ACLãããŸãååãå ¥åããŠç©ºçœã®ACLãç»é²ããã®ã¯åãããã ããå ¥åããååã«ãã£ãŠACLã®çš®é¡ãèªåèªèããŠæ±ºå®ããç¹ã«æ³šæ |
|
IP Basic ACLãšIP Extended ACLãšNamed IP ACLãã²ãšã€ãã€ç»é²ããäŸãååãšãå³åŽã«è¡šç€ºããŠããçš®é¡ã®é¢é£æ§ã«æ³šæ |
IP ACLãå¿ èŠãªæ°ã ãç»é²ããããIP Ruleã®èšå®ã«ç§»ããIP ACLç»é¢ããç§»åããå Žåãããããã®ACLã®ååããã€ããŒãªã³ã¯ã«ãªã£ãŠããã®ã§ããããã¯ãªãã¯ããã°ããã
ãŸãã[Security]ã¿ã以äžã®[ACL]â[Advanced]â[IP Rules]ãããã¯[IP Extended Rules]ãšãã©ãããšã§ã[IP Rules]ãããã¯[IP Extended Rules]ç»é¢ã衚瀺ããæ¹æ³ãããããã®å Žåã[IP Rules]以äžã®[ACL ID/NAME]ã§ããŸãèšå®å€æŽã®å¯Ÿè±¡ãšãªãACLãéžæããå¿ èŠãããã
ãããã®æäœã«ç¶ããŠç»é¢å³äžã®[ADD]ãã¯ãªãã¯ãããšãèšå®ç»é¢ã衚瀺ããä»çµã¿ã ãMAC ACLãšã¯æäœæé ãç°ãªãã®ã§æ³šæãããã
IP ACLçšã®ã«ãŒã«(IP Rule)ã«ããããäž»ãªèšå®é ç®ã¯ä»¥äžã®éãã§ããã
ã»Action : 転é(permit)ãŸãã¯æåŠ(deny)
ã»Logging : ãã°èšé²ã®æç¡
ã»Source IP Address : éä¿¡å IPv4ã¢ãã¬ã¹ (IP Basic ACLã®ã¿)
ã»Source IP Mask : éä¿¡å IPv4ã¢ãã¬ã¹ã«å¯Ÿãããã¹ã¯æå®ãäžè¬çãªãµãããããã¹ã¯ã®èšè¿°æ¹æ³ãšã¯éã§ãã(IP Basic ACLã®ã¿)
ã»Src IP Address : éä¿¡å IPv4ã¢ãã¬ã¹ (IP Extended ACLã®ã¿)
ã»Src IP Mask : éä¿¡å IPv4ã¢ãã¬ã¹ã«å¯Ÿãããã¹ã¯æå®ãäžè¬çãªãµãããããã¹ã¯ã®èšè¿°æ¹æ³ãšã¯éã§ãã(IP Extended ACLã®ã¿)
ã»Dst IP Address : å®å IPv4ã¢ãã¬ã¹ (IP Extended ACLã®ã¿)
ã»Dst IP Mask : å®å IPv4ã¢ãã¬ã¹ã«å¯Ÿãããã¹ã¯æå®ãäžè¬çãªãµãããããã¹ã¯ã®èšè¿°æ¹æ³ãšåãã§ãã(IP Extended ACLã®ã¿)
ã»Dst L4 Port : å®å ããŒããDOMAINãECHOãFTPãFTPDATAãHTTPãSMTPãSNMPãTELNETãTFTPãWWWã®ãããã (IP Extended ACLã®ã¿)
ã»Mirror Interface : å¥ã®ã€ã³ã¿ãã§ãŒã¹ã«ãã±ãããè€è£œãã
ã»Redirect Interface : å¥ã®ã€ã³ã¿ãã§ãŒã¹ã«ãã±ããããªãã€ã¬ã¯ããã
|
IP Extended ACLã®ã«ãŒã«ç»é²ç»é¢ãéä¿¡å IPã¢ãã¬ã¹ã«å ããŠå®å IPã¢ãã¬ã¹ãåããšãã倿§ãªæ¡ä»¶ãæå®ã§ãã |
ç»é²ãçµãããš[IP Rules]ãããã¯[IP Extended Rules]ç»é¢ã«æ»ãããã®ç¶æ ã§ã¯ã[Rule ID]ããã€ããŒãªã³ã¯ã«ãªã£ãŠããã®ã§ããããã¯ãªãã¯ããããšã§èšå®å€æŽãå¯èœã§ããã
IP Ruleãå¿ èŠãªæ°ã ãç»é²ããããBinding Configurationã®èšå®ã«ç§»ãã[IP Binding Configuration]ç»é¢ã¯ã[Security]ã¿ã以äžã®[ACL]â[Advanced]â[IP Binding Configuration]ãšãã©ãããšã§è¡šç€ºãããããã§ã¯ã[ACL ID]ã¡ãã¥ãŒã§ç»é²æžã¿ã®IP ACLãéžæããŠãåªå é äœä»ããæå³ããã·ãŒã±ã³ã¹çªå·ãšãå²ãåœãŠå¯Ÿè±¡ã«ãªãããŒããæå®ãããèšå®ã®å®¹éã¯ãMAC ACLã®ãšããšåãã ã
ããããŠç»é²ããæ å ±ã確èªããããã®[IP Binding Table]ç»é¢ã¯ã[Security]ã¿ã以äžã®[ACL]â[Advanced]â[IP Binding Table]ãšãã©ãããšã§è¡šç€ºãããããã§ã¯ãç»é²ããIP ACLã«ã€ããŠãå²ãåœãŠå¯Ÿè±¡ã®ã€ã³ã¿ãã§ãŒã¹ãã¢ã¯ã»ã¹å¶åŸ¡å¯Ÿè±¡ã«ãªããã©ãã£ãã¯ã®åããACL IDãªã©ã®æ å ±ã確èªã§ããããã¡ãããæäœæé ã¯MAC ACLãšåãèŠé ã§ããã
ãããã¯ãããŒãã«ã泚ç®
ACLã®è©±ããã¯å€ããã®ã§æåŸã«èšåããããšã«ãããããGSM7248v2ãã¯ç¹å®ã®ããŒãå士ã®ãã©ãã£ãã¯ã鮿ããæ©èœããããããšãã°ããã³ã·ã§ã³ãããã«ã®å®¢å®€ã§ã€ã³ã¿ãŒãããæ¥ç¶ãµãŒãã¹ãæäŸããå Žåãåã ã®éšå±ãšã€ã³ã¿ãŒãããã®éã®ãã©ãã£ãã¯ã¯éãäžæ¹ã§ãéšå±å士ã®ãã©ãã£ãã¯ã¯é®æããå¿ èŠãããããããã£ãå Žé¢ã§åœ¹ã«ç«ã€æ©èœã ã
ãã®æ©èœã«ã¯ã飿¥ããããŒãå士ã®éä¿¡é®æã ãã§ãªãããããŒããã£ã¹ããã¡ã€ã³ãåå²ããäœ¿ãæ¹ãèãããããæå€§ã§3ã€ã®ã°ã«ãŒããå®çŸ©ã§ããããã«ãªã£ãŠããã
ããã§æ³šæããªããšãããªãã®ã¯ããåäžã°ã«ãŒãã«åé¡ããããŒãå士ã§ã¯éä¿¡ã§ããªããªãããç°ãªãã°ã«ãŒãã«åé¡ããããŒãå士ã§ã¯éä¿¡ã§ããããšããç¹ã§ããããã£ããéã®è§£éãããŠãèšå®ãã¹ã«ã€ãªãããªãããã«çšå¿ããªããã°ãªããªãã
ãã®æ©èœã¯ã[Security]ã¿ã以äžã®[Traffic Control]â[Protected Port]ã§èšå®ããã[Group ID]ã¯0ïœ2ã®3çš®é¡ãéžæã§ããããã®ç¶æ ã§[APPLY]ãã¯ãªãã¯ãããšãã°ã«ãŒãã®ç»é²ãã§ããã
ç¶ããŠããã®äžã®[Unit 1]ãã¯ãªãã¯ãããšãããŒãäžèЧç»é¢ãçŸããã®ã§ãããã§èšå®äžã®ã°ã«ãŒãã«æå±ããããããŒããã¯ãªãã¯ããŠããã§ãã¯ããªã³ã«ãããæåŸã«[APPLY]ãã¯ãªãã¯ããã°èšå®å®äºã ã
ãªãã[Group Name]ã§ä»»æã®ååãå®çŸ©ããŠãããšãããŒããå²ãåœãŠãã°ã«ãŒãã®å¯Ÿè±¡ãåããããããªãã®ã§äŸ¿å©ã ãããéšçœ²åãå Žæãããã¢ãªã©ãå©çšãã圢ãèããããã
|
ã°ã«ãŒãéžæäžã®ç»é¢ãããã¯[Group Name]ãå®çŸ©ããŠããªãäŸã§ã[Group ID]ã¯ã2ã |