VPNãæ§ç¯ããã®ã«æ£åžžãªéä¿¡ã確ç«ã§ããªãå Žåã¯ããããã¯ãŒã¯æ©åšã«æ®ãããŠãããã°ãªã©ãææããã«ããªãããäžã€äžã€ã®èšå®ã现ããèŠçŽããŠããããšãéèŠã§ãããšããããŸã§èª¬æããŠããŸããã
ããããæ ç¹ééä¿¡ãªã©ã«ãããŠã¯ãã€ã³ã¿ãŒãããåç·ã䜿ã£ãŠããã®ã§ãé害ãçœå®³çºçãªã©ãåå ã§ãéä¿¡ã鮿ããããããªç¶æ³ãçºçããŠããŸããŸãããã®ãããªå Žåã«åããŠãå¥åç·ãããã¯ã¢ããåç·ãšããŠçšæããŠãããšããã§ãããã
ããã§ä»åã¯ããããã®æã«åããããã®ããã¯ã¢ããåç·ã®æ§ç¯ã«ã€ããŠè§£èª¬ããŠãããŸãã
æ ç¹éVPNæ¥ç¶ã§åç·ã«é害ãçºçãããšã©ããªãïŒ
ä»ååãäžãããããã¯ãŒã¯æ§æã¯ã次ã®ãããªãã®ã§ãã
- IPSecã«ããæ ç¹éVPNæ¥ç¶ãã»ã³ã¿ãŒã«ãŒã¿1å°ã§æ§æã
- ã»ã³ã¿ãŒã«ãŒã¿ãšæ ç¹ã«ãŒã¿ã®éã«ã¯ã2ã€ã®ã€ã³ã¿ãŒãããåç·ãæ·èšãã€ãŸããã¡ã€ã³åç·ä»¥å€ã«ãããã¯ã¢ããçµè·¯ãšãªãããã¯ã¢ããåç·ã远å ãã(ããã¯ãäžè¬çã«åé·åãšåŒã°ãã)ã
- ã¡ã€ã³åç·ã«äœããã®é害ãçºçããŠãããã¯ãŒã¯ã鮿ãããæãèªåçã«ããã¯ã¢ããåç·ã«åãæ¿ãããã€ã³ã¿ãŒãããæ¥ç¶ããã³VPNæ¥ç¶ãç¶ç¶ãããä»çµã¿ãšããã
äŸãã°ãæ ç¹åŽã§ã¡ã€ã³åç·ã«é害ãçºçãããšã次ã®ãããªç¶æ ãšãªããŸãã
æ ç¹2ãšã€ã³ã¿ãŒããããæ¥ç¶ããã¡ã€ã³åç·ãããŠã³ãããšãæ ç¹2ã®ã«ãŒã¿ã¯ããã¯ã¢ããåç·ã䜿ã£ãŠã»ã³ã¿ãŒã«ãŒã¿ãšã®æ¥ç¶ã詊ã¿ãããã®æãã»ã³ã¿ãŒãšæ ç¹2ã®VPNæ¥ç¶ãäžæçã«äžéã«ãªãããããã¯ã¢ããåç·ã«ããã€ã³ã¿ãŒãããæ¥ç¶ã埩æ§ãããšãã»ã³ã¿ãŒã«ãŒã¿ãšã®ãã³ãã«ãçæãã«ããã
ã¡ã€ã³åç·ã埩æ§ãããšãã€ã³ã¿ãŒãããæ¥ç¶ãèªåçã«ã¡ã€ã³åç·ã«åãæ¿ããããã®æããVPNæ¥ç¶ã¯äžæçã«äžéã«ãªããã埩æ§ããã¡ã€ã³åç·ã§ãã³ãã«ãçæãããéåžžéçšã«æ»ãããšã«ãªãã
äžæ¹ãã»ã³ã¿ãŒåŽã§ã¡ã€ã³åç·ã«é害ãçºçãããšã次ã®ãããªç¶æ ãšãªããŸãã
ã»ã³ã¿ãŒãšã€ã³ã¿ãŒããããæ¥ç¶ããã¡ã€ã³åç·ãããŠã³ããå Žåãã»ã³ã¿ãŒã«ãŒã¿ã¯ããã¯ã¢ããåç·ã䜿ã£ãŠãã€ã³ã¿ãŒãããæ¥ç¶ãéå§ããã
ããããã®æ ç¹ã§ã¯ãã»ã³ã¿ãŒã«ãŒã¿ãšã®VPNãã³ãã«ãåæãããããšãæ€ç¥ããŠãèªåçã«ããã¯ã¢ãããã³ãã«ãèµ·åããã»ã³ã¿ãŒã«ãŒã¿ãšæ ç¹1ã«ãŒã¿ãã»ã³ã¿ãŒã«ãŒã¿ãšæ ç¹2ã«ãŒã¿ã®ããããã«VPNãã³ãã«ãçæããã
ã¡ã€ã³åç·ã埩æ§ãããšãããããã®æ ç¹ãšã»ã³ã¿ãŒã«ãŒã¿ã®VPNãã³ãã«ã埩æ§ããã埩æ§ãããã³ãã«ã䜿ã£ãŠVPNæ¥ç¶ãè¡ãããã«ãªããéåžžéçšã«æ»ãããšã«ãªãã
VPNãã³ãã«ã®ããã¯ã¢ããã®èšå®æ¹æ³
ããã§ã¯ãã«ãŒã¿ãžã®ããã¯ã¢ããèšå®ã«ã€ããŠèª¬æããŠãããŸãããã
ãŸããã¡ã€ã³åç·çšãããã¯ã¢ããåç·çšãšã2ã€ã®ã€ã³ã¿ãŒãããæ¥ç¶ãèšå®ããããã«2ã€ã®IPSecã®èšå®ãè¡ããŸããVPNã®èšå®ã¯ãåäžåç·ã§ã®èšå®ãšå€§ããªéãã¯ãããŸããããæ¬¡ã®ç¹ã«æ³šæããŠãã ããã
ã¡ã€ã³åç·ãšããã¯ã¢ããåç·ã§åãã€ã³ã¿ãŒããããããã€ããŒãå©çšãããšããããã€ããŒåŽã§é害ãçºçããæã«å ±åãã«ãªã£ãŠããŸããã¡ã€ã³åç·ãšããã¯ã¢ããåç·ã¯ç°ãªãã€ã³ã¿ãŒããããããã€ããŒãçšæããã»ããããã
ã€ã³ã¿ãŒãããæ¥ç¶åç·ã2æ¬æã€ããšã«ãªããããppã€ã³ã¿ãã§ãŒã¹ãã¡ã€ã³åç·ãšããã¯ã¢ããåç·ã®ããããã«èšå®ããå¿ èŠãããã
ã€ã³ã¿ãŒãããæ¥ç¶åç·ã2æ¬ãããšããããšã¯ãWANåŽIPã¢ãã¬ã¹ã2ã€ååšããããšã«ãªããéçIPãã£ã«ã¿ã§ã¯ãåºå®çã«IPã¢ãã¬ã¹ãæå®ããŠãããããWANåŽIPã¢ãã¬ã¹ãç°ãªã2çš®é¡ã®ãã£ã«ã¿èšå®ãIPSecçšã«çšæããŠããããã察å¿ããppã€ã³ã¿ãã§ãŒã¹ã«é©çšããå¿ èŠãããã
VPNãã³ãã«ã¯ãã¡ã€ã³åç·ãšããã¯ã¢ããåç·ã®ããããã«èšå®ããå¿ èŠãããã®ã§ãtunnelã€ã³ã¿ãã§ãŒã¹ã§çšããã»ãã¥ãªãã£ã²ãŒããŠã§ã€èå¥åããIPSec SAèšå®ã®ããªã·ãŒIDãéè€ããªãããã«èšå®ããå¿ èŠããããäºåå ±æéµã¯ãã¹ãŠåãã§ãåé¡ãªãããç°ãªããã®ã«ããŠãããã»ããå®å šã
2ã€ã®ã€ã³ã¿ãŒãããæ¥ç¶ã2ã€ã®IPSecèšå®ãè¡ã£ãããšã以äžã®ããã«ãããããã®ã«ãŒã¿ã§ããã¯ã¢ããã®èšå®ãè¡ããŸãã
-
ã¡ã€ã³åç·ã®ppæ¥ç¶èšå®ã§æ¬¡ã®ããã«æå®ããç°åžžæã«pp 2ã€ã³ã¿ãã§ãŒã¹ã«åãæ¿ããããã«ãããããã¯ãã»ã³ã¿ãŒã«ãŒã¿ãæ ç¹1ã«ãŒã¿ãæ ç¹2ã«ãŒã¿ã®ãã¹ãŠã«ãããŠè¡ãã
pp select 1 pp backup pp 2
-
ã¡ã€ã³åç·ã®æ ç¹1åãã®ãã³ãã«èšå®ã§æ¬¡ã®ããã«æå®ããç°åžžæãããã¯ã¢ãããã³ãã«ã®tunnel 2ã«åãæ¿ããããã«æç€ºããã
tunnel select 1 tunnel backup tunnel 2 switch-interface=on
åæ§ã«ãæ ç¹2åãã®ãã³ãã«èšå®ããç°åžžæãããã¯ã¢ãããã³ãã«ã®tunnel 4ã«åãæ¿ããããã«æç€ºããã
tunnel select 3
tunnel backup tunnel 4 switch-interface=on
æ ç¹ããã¯ã¢ããåç·ã«åãæ¿ãã£ããšããã«ãŒãã£ã³ã°ãDNSãµãŒããåãæ¿ããããã«èšå®ãããèšå®äŸã¯ä»¥äžã®éãã
ip route default gateway pp 1 filter 100 gateway pp 2 filter 2 gateway pp 1
dns server select 101 pp 1 any . restrict pp 1
dns server select 102 pp 2 any . restrict pp 2
以äžã§ããã¯ã¢ããã®èšå®ã¯å®äºã§ãããããåç·ã«é害ãçºçããŠãã€ã³ã¿ãŒãããåç·ããã³ãã«ã®ã©ã¡ããæå¹ã«ãªã£ãŠãããã確èªããå Žåã¯ãshow status backupã³ãã³ãã䜿ãããšãã§ããŸããã¡ã€ã³åç·ã䜿ã£ãŠããå Žåã¯STATEã«masterãšè¡šç€ºãããããã¯ã¢ããåç·ã䜿ã£ãŠããå Žåã¯STATEã«backupãšè¡šç€ºãããŸãã
ä»åã¯ãVPNåç·ã鮿ãããŠããŸã£ãæã®å¯ŸçãšããŠãå¥åç·ãããã¯ã¢ããåç·ãšããŠçšæãããã³ãã«ãçµè·¯ã®ããã¯ã¢ãããäœã£ãŠããæ¹æ³ã«ã€ããŠèª¬æããŸãããæšä»ããããã¯ãŒã¯ã忢ãããšãæ¥åã«æ¯éãæ¥ããŠããŸããŸããé害ãèµ·ããæã«ç¬æã«å¯Ÿå¿ã§ããããã«ããŠããããšã«å ãããããã¯ãŒã¯ã®åé·åãåãå ¥ããŠãããã察çã®1ã€ã§ãã


