ä»åã¯ãVPN(Virtual Private Network)ã§çšãããããããã³ã«ã®ãã¡ããã£ãšãããã¥ã©ãŒãšãã£ãŠããIPsec(IP security)ã«ã€ããŠãããã€ãŸãã§è§£èª¬ããã
ã€ããã«ãŒã¿ã§VPNãæ§ç¯ããå ŽåããšãããLAN鿥ç¶VPNã«ãããŠã¯ãIPsecãå©çšããæ¹æ³ãäžè¬çã ããšãããIPsecã¯PPTPãšæ¯ã¹ããšä»æ§ãè€éã«ãªã£ãŠãããããèšå®ãã¹ãå ¥ã蟌ãå¯èœæ§ãé«ããåæç¥èãšããŠãIPsecã«é¢ããŠãã¡ããšçè§£ããŠããããšãéèŠã«ãªãã
IPsecãšã¯
IPsecã¯ãã®åã®éããIP(Internet Protocol)ã§åäœããæå·åãããã³ã«ã ãæå·åã«å ããŠèªèšŒã®æ©èœãããããããã§ããèªèšŒãšã¯ãŠãŒã¶ãŒèªèšŒãšããããããäžæ¹åããã·ã¥é¢æ°ãçšããæ¹ããæ€åºæ©èœãšããæ¹ãæ£ããããã®æ¹ããæ€åºã ãã䜿çšããŠãæå·åãè¡ããªãèšå®ãå¯èœã ããVPNã§ã¯å¿ ç¶æ§ã¯çç¡ã ãæå·åãšæ¹ããæ€åºã®äž¡æ¹ãè¡ããããã³ã«ããESP(Encapsulation Security Payload)ããæ¹ããæ€åºã ããè¡ããããã³ã«ããAH(Authentication Header)ããšããã
ãã¡ãããããããèªèšŒãããªãã¡éä¿¡çžæãæ¬ç©ãã©ããã確èªããæ©èœãããã
IPsecã®ç¹åŸŽã¯ããã®ãæå·åãããäžæ¹åããã·ã¥é¢æ°ãããæ¥ç¶çžæã®æ£åœæ§ç¢ºèªãã®ãããã«ã€ããŠããè€æ°ã®éžæè¢ãçšæããŠããç¹ã«ãããã€ãŸããåã«ãIPsecã䜿çšããããšæå®ããã ãã§ãªãããæå·åããäžæ¹åããã·ã¥é¢æ°ããæ¥ç¶çžæã®æ£åœæ§ç¢ºèªãã®ããããã«ã€ããŠãã©ã®éžæè¢ã䜿çšãããã®æå®ãå¿ èŠã«ãªãã
ãã£ãšããåäžãã³ãã®è£œåå士ã察åãããã®ã§ããã°ãæ¢å®å€ã¯æã£ãŠããã®ãæ®éãªã®ã§ããã®åã ãæéãçãããšãã§ãããèšãæããã°ãç°ãªããã³ãã®è£œåå士ã察åãããŠIPsecã䜿çšããå Žåãåäžãã³ãå士ã®çµã¿åãããšæ¯èŒãããšé£æåºŠãé«ãã
ããããã®éžæè¢ã«ã€ããŠã以äžã«äŸã瀺ãã
ã»æå·å : DES(Data Encryption Standard)ã3DES(ããªãã«DES)ãAES
ã»äžæ¹åããã·ã¥é¢æ° : MD5ãSHA-1
ã»æ¥ç¶çžæã®æ£åœæ§ç¢ºèª : äºåå ±æéµãããžã¿ã«èšŒææžãKerberos
ã€ããã«ãŒã¿ã®å Žåãæ¥ç¶çžæã®æ£åœæ§ç¢ºèªã«ã¯äºåå ±æéµãçšãããASCIIæååãš16é²å€ã®ããããå©çšå¯èœã ãäžæ¹ãæå·åãšäžæ¹åããã·ã¥é¢æ°ã«ã€ããŠã¯äžèšã®éžæè¢ããã¹ãŠå©çšã§ããã
ãããŸã§ã¯æå·åã«é¢é£ãã話ã ãããããšã¯å¥ã«ãåäœã¢ãŒããšããŠããã©ã³ã¹ããŒãã¢ãŒãããšããã³ãã«ã¢ãŒãããããã
åè ã¯åçŽã«IPãã±ããã®ãã€ããŒãéšãæå·åãããã®ã§ãLANå éšããããã¯L2TPãšã®çµã¿åããã§çšãããåŸè ã¯IPãã±ããå士ã®ã«ãã»ã«åãè¡ã£ãäžã§ãã«ãã»ã«åã®å¯Ÿè±¡ã«ãªã£ãIPãã±ããããŸãããšæå·åãããã®ã ãVPNã§ã¯åŸè ã®ãã³ãã«ã¢ãŒããçšãããããããããšã§ãIPsecã ãã§ãã³ããªã³ã°ãšæå·åãšæ¹ããæ€åºãäžåºŠã«å®çŸã§ããã
ããã«ãIPsecã®ãã³ãã«ã¢ãŒããçšããŠVPNãå®çŸããå Žåãåæ¹ã§åºå®IPã¢ãã¬ã¹ã確ä¿ããŠéä¿¡çžæã®IPã¢ãã¬ã¹ã決ãæã¡ã§æå®ãããã¡ã€ã³ã¢ãŒãããšãçæ¹ã«ã€ããŠã¯IPã¢ãã¬ã¹ãåºå®ããå¿ èŠããªããã¢ã°ã¬ãã·ãã¢ãŒããããããåŸè ã®ã¢ã°ã¬ãã·ãã¢ãŒãã§ã¯ãåæ¹ã®åœäºè ã§å ±éããäžæã®ååãæå®ããŠèå¥ã®ææãšããŠããã
IPsecèšå®ã®åºæ¬(ã¡ã€ã³ã¢ãŒã)
IPsecã«å¯Ÿå¿ããã€ããã«ãŒã¿ã§ã¯ãã³ãã³ããçšããŠèšå®ããæ¹æ³ãåºæ¬ã«ãªããIPsecãã¡ã€ã³ã¢ãŒãã§å©çšããããã«å¿ èŠãšãªãã³ãã³ãæäœã«ã¯ãå°ãªããšã以äžã®ãã®ãããã
ã»ãã³ããªã³ã°ã«äœ¿çšããtunnelã€ã³ã¿ãã§ãŒã¹ã®çªå·ãšããããšçµã¿åãããIPsecèšå®ã®çªå·ãæå®ãã
ã»tunnelã€ã³ã¿ãã§ãŒã¹ãšIPsecèšå®ã®çªå·ãæå®ããŠãESPã®äœ¿çšã宣èšããã®ã«å ããŠãæå·åæ¹åŒãšäžæ¹åããã·ã¥é¢æ°ã®çš®é¡ãæå®ãã
ã»èªæ©åŽãšçžæåŽã®IPã¢ãã¬ã¹ãæå®ãã
ã»åæ¹ã§åäžã®äºåå ±æéµãæå®ãã
ã»tunnelã€ã³ã¿ãã§ãŒã¹ãæå¹åãã
ã»IPsecã®èªåæŽæ°ãæå¹ã«ãããšãšãã«ããªããŒ(ESPã§çšããéµã®èªåæŽæ°)ãæå¹ã«ãã
ãã®ã»ããçžæåŽã®LANã«ã«ãŒãã£ã³ã°ãè¡ãããã®ã«ãŒãã£ã³ã°èšå®è¿œå ãå¿ èŠã ããããã¯IPsecã®èšå®ã§ã¯ãªãã«ãŒã¿ã®èšå®ãšããã¹ãã ããã
åæ¹ã®ã«ãŒã¿ã§ç°ãªãã®ã¯ããªã¢ãŒããšããŒã«ã«ã®IPã¢ãã¬ã¹æå®ãšã«ãŒãã£ã³ã°ã®èšå®ã§ããããã¯äž¡è ã§äºãã«å ¥ãæ¿ããããã®ä»ã®é ç®ã¯ãåæ¹ã§åäžã®å€ãæå®ããã
IPsecèšå®ã®åºæ¬(ã¢ã°ã¬ãã·ãã¢ãŒã)
IPsecãã¢ã°ã¬ãã·ãã¢ãŒãã§äœ¿çšããå Žåãåè¿°ããããã«åºå®IPã¢ãã¬ã¹ãå¿ èŠãšããã®ã¯çæ¹ã®æ ç¹ã ãã«ãªãããã®ã»ããåæ¹ã§äžæã®ååãç»é²ããç¹ãã¡ã€ã³ã¢ãŒããšã®çžéç¹ã«ãªãã
IPsecãã¢ã°ã¬ãã·ãã¢ãŒãã§å©çšããããã«å¿ èŠãšãªãã³ãã³ãæäœã«ã¯ãå°ãªããšã以äžã®ãã®ãããã
ã»ãã³ããªã³ã°ã«äœ¿çšããtunnelã€ã³ã¿ãã§ãŒã¹ã®çªå·ãšããããšçµã¿åãããIPsecèšå®ã®çªå·ãæå®ãã
ã»tunnelã€ã³ã¿ãã§ãŒã¹ãšIPsecèšå®ã®çªå·ãæå®ããŠãESPã®äœ¿çšã宣èšããã®ã«å ããŠãæå·åæ¹åŒãšäžæ¹åããã·ã¥é¢æ°ã®çš®é¡ãæå®ãã
ã»èªæ©åŽã®IPã¢ãã¬ã¹ãæå®ãã(åºå®IPã¢ãã¬ã¹ãæã€åŽã®ã¿)
ã»å¯ŸåããçžæåŽã®ã°ããŒãã«IPã¢ãã¬ã¹ãç¹å®ããªãããã«æå®ããäžã§ãååã®æå®ãè¡ã(åºå®IPã¢ãã¬ã¹ãçšããåŽã®ã¿)
ã»å¯ŸåããçžæåŽã§ããåãååã®æå®ãè¡ã(åºå®IPã¢ãã¬ã¹ãæããªãåŽã®ã¿) ã»åæ¹ã§åäžã®äºåå ±æéµãæå®ãã
ã»tunnelã€ã³ã¿ãã§ãŒã¹ãæå¹åãã
ã»IPsecã®èªåæŽæ°ãæå¹ã«ãããšãšãã«ããªããŒ(ESPã§çšããéµã®èªåæŽæ°)ãæå¹ã«ãã
ã¡ã€ã³ã¢ãŒãã§ã¯ãåæ¹ã§èšå®ãç°ãªãå€ããã£ãŠããããã¯åã«ãã©ã¡ãŒã¿ãå ¥ãæ¿ããã ãã ããšãããã¢ã°ã¬ãã·ãã¢ãŒãã§ã¯ãåºå®IPã¢ãã¬ã¹ã䜿çšããåŽãšãã®å察åŽãšã§ãèšå®ããé ç®ãã®ãã®ã«ãéããããããã®ãããç°¡åããã«èŠããŠãå®ã¯ãã¡ãã®æ¹ãééããããããç¥ããªãã
ã€ããã«ãŒã¿ã§ã€ããã€ã³ã¿ãŒãããVPN 第3ç
èè :äºäžååžãåå:ã€ãããäŸ¡æ Œ:4,515å
æ¬æžã¯ãã€ãã瀟ã®VPNã«ãŒã¿ NetVolante/RT/RTXã·ãªãŒãºã察象ã«ãã»ãã¥ãªãã£ã®é«ãVPNç°å¢ãæ§ç¯ããææ³ã解説ãVPNãIPsecå©çšç°å¢ã®åºç€ç¥èãã宿§ç¯ã»æå¹æŽ»çšãŸã§ããã€ããã«ãŒã¿ãã®æ©èœã掻çšãããããŸããŸãªVPNã®æå¹æŽ»çšããã®1åã§ã§ããããã«ãªãããŸããQoSãããã¯ã¢ããæ©èœããã«ãŒã¿ã®ç®¡çã»ã¡ã³ããã³ã¹ããããããã解説ããã