IT管çè ãšããŠåŸã ã«æŽ»åã®å ŽãåºããŠããAåã«ãããæ¥ãäžæ¬ã®é»è©±ãæãã£ãŠãããçžæã¯Aåãšåæå ¥ç€Ÿã®DãããDããã¯ãå ¥ç€Ÿä»¥æ¥ãã£ãšæ¯ç€Ÿã«é å±ãããŠããã建èšçŸå Žã®ç£ç£ãåããŠããã
|
Dãã |
|
Aå |
|
Dãã |
|
Aå |
|
Dãã |
|
Aå |
|
Dãã |
|
Aå |
å®ã¯ãVPNãšããèšèãåããŠèããAåãããã§ããŸã¯å¥æ¯ç€Ÿã§åããäŒèª¬ã®IT管çè ãšåŒã°ããŠããBããã«ãæ©éé»è©±ããŠã¿ãããšãšããã
VPNã£ãŠã©ããªãã®?
|
Aå |
|
Bãã |
|
Aå |
|
Bãã |
|
Aå |
|
Bãã |
|
Aå |
|
Bãã |
VPNãèšå®ãã
æ©éãAåã¯ãVPNã«ã€ããŠèª¿ã¹ãŠã¿ããVPNã«ã¯ããã€ãã®çš®é¡ããããããšãããäŒæ¥ã«é¢ä¿ãããã®ã¯ãIPSecVPNãšSSL-VPNã®2ã€ã§ããããã®2ã€ã¯ãå®è£ ããããããã³ã«éå±€ãéãããšã倧ããªç¹åŸŽã§ãå€éšããå©çšããã¢ããªã±ãŒã·ã§ã³ãSSL察å¿ãããŠãããåŠãã¯SSL-VPNãå°å ¥ããããã§éèŠãªãã€ã³ããšãªããããŸããŸãªã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿå¿ããããšãèãããšãä»åã¯IPSecVPNãå°å ¥ããã»ãããããããããªãã
IPSecVPNã§ã¯ãèªèšŒã¢ã«ãŽãªãºã ãšæå·ã¢ã«ãŽãªãºã ãšãã2çš®é¡ã®ã¢ã«ãŽãªãºã ã䜿çšããŸããèªèšŒéµãšããŠäœ¿ãæååãæ±ºå®ããå¿ èŠããããVPNã®æ¥ç¶å ãšã¯ãããã3ã€ã®å ±æãå¿ èŠã ã
(1)èªèšŒéµã®æååã«ã¯ãåè§è±æ°åã§128æåãŸã§ã®æååãèšå®ããã (2)èªèšŒã¢ã«ãŽãªãºã ãšæå·ã¢ã«ãŽãªãºã ã«ã€ããŠãã©ããéžæãã¹ããã®å€æã¯ãç¶æ³ã«ãã£ãŠç°ãªããããã§ã¯ãèªèšŒã¢ã«ãŽãªãºã ã«ãHMAC-SHAããæå·ã¢ã«ãŽãªãºã ã«ãAES-CBCãã䜿ããã®ãšããã
Aåã¯ãVPNã«ã€ããŠäžéã調ã¹ããšããã§ãRTX830ã®ç®¡çç»é¢ã§ããWebGUIã«ã¢ã¯ã»ã¹ããã
|
Aå |
Aåã¯ãããããèšå®ããããããããã©ã³ãDNSããéžæããããããã©ã³ãDNSã®èšå®ç»é¢ãéããã
ããã§ããã¹ãåãå ¥åãããããã©ã³ãDNSåãç»é²ããããã¹ãåã¯ä»»æã®æååãèšå®å¯èœãèšå®ããããã¹ãåã¯ããxxxxx.aa0.netvolante.jpãã®ãããªå®å šã«æå®ããããã¡ã€ã³å(FQDN) ãšãªãããã®FQDNã«åãåããããšãã«ãŒã¿ã«å²ãåœãŠãããŠããã°ããŒãã«ã®IPã¢ãã¬ã¹ãéåŒãã§ããã®ã ã
|
Aå |
ç¶ããŠããããããèšå®ããããVPNãããªã¢ãŒãã¢ã¯ã»ã¹ããšéžæãããªã¢ãŒãã¢ã¯ã»ã¹VPNã®èšå®ç»é¢ãéãAåããL2TP/IPsecã䜿çšãããã«ãã§ãã¯ãå ¥ãããã§ã«æ±ºããŠãããèªèšŒéµããèªèšŒã¢ã«ãŽãªãºã ããæå·ã¢ã«ãŽãªãºã ããéžæããŠãŒã¶ãŒèªèšŒæ¹åŒã¯ãæ¥ç¶å ã§ããDããã®PCãWindowsPCã§ããããšã«ãããããMSCHAP-V2ããéžæãããããã«ãæ¥ç¶ãŠãŒã¶ãŒãç»é²ãä»»æã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããèšå®ããèšå®ã確å®ããã
èšå®ã確å®ãããšä»¥äžã®ãããªç»é¢ãšãªããVPNæ¥ç¶ã確ç«ããŠããªãç¶æ ã§ã¯ãæ¥ç¶ç¶æ ã¯ã°ã¬ãŒã®ç¹ç·ã§è¡šç€ºãããã
|
Aå |
Aåã¯ãDããã«VPNã¯ã©ã€ã¢ã³ããœãããŠã§ã¢ã§ãããYMS-VPN8ããã€ã³ã¹ããŒã«ããããäŸé ŒããããYMS-VPN8ãã¯ãã€ããã®VPNã«ãŒã¿ããã¡ã€ã¢ãŠã©ãŒã«ãšWindows PCãL2TP/IPsecã§å®å šãªéä¿¡ãã§ããããã«ããããã®VPNã¯ã©ã€ã¢ã³ããœãããŠã§ã¢ã ã
ãYMS-VPN8ãã§ã¯ãAåãRTX830ã«èšå®ããŠããããããã©ã³ãDNS(ãã¹ãå)ãèªèšŒéµïŒäºåå ±æéµïŒããŠãŒã¶ãŒåããã¹ã¯ãŒããå ¥åããèšå®ãä¿åããŠãããèšå®ãããæ¥ç¶æ å ±ãéžãã§ãã¡ã€ã³ç»é¢ã«ãããæ¥ç¶ããã¿ã³ãã¯ãªãã¯ãããšãVPNæ¥ç¶ã確ç«ãVPNæ¥ç¶ã確ç«ãããšãRTX830ã®WebGUIã§ã¯ãæ¥ç¶ç¶æ ãã°ãªãŒã³ã®ç¢å°ã§è¡šç€ºãããã
ããã§ãªã¢ãŒãã¢ã¯ã»ã¹VPNã®æ§ç¯ãå®äºããŸããDããã¯ãVPNæ¥ç¶ã確ç«ããŠããç¶æ ã§ãæ¬ç€Ÿã®ãµãŒããŒïŒ192.168.100.4ïŒã®ãã£ã¬ã¯ããªã«ã¢ã¯ã»ã¹ã§ããããšã確èªããã
æ ç¹éVPNãæ§ç¯ãã
Aåããªã¢ãŒãã¢ã¯ã»ã¹VPNãæ§ç¯ãããšããåã¯ãç¬ãéã«åºãŸããŸã£ãããããšæ©éAåã®å ã«ãå¥ã®å¶æ¥æã®ç€Ÿå¡ããæ ç¹éVPNãæ§ç¯ããããšããçžè«ãæã¡ããããããZç€Ÿã®æ¯åºçŽèœã®å¶æ¥æã¯ãæ¬ç€Ÿã®ãã¡ã€ã«ãµãŒããŒã«ããèšèšå³ããã¡ã€ã«è»¢éãµãŒãã¹ã§éä¿¡ããŠãããããšã«ããŠãããéåžžã«é¢åãªããããã¡ã€ã«ãµãŒããŒã«çŽæ¥ã¢ã¯ã»ã¹ãããã®ã ãšããã
æ ç¹éVPNã¯ãã®åã®éããæ ç¹å士ãVPNã§æ¥ç¶ãããã®ã ãæ¥ç¶å ãVPNã«ãŒã¿ã§ããã°æ§ç¯ã¯å®¹æãä»åã®ã±ãŒã¹ã§ããå¶æ¥æã®ã«ãŒã¿ã«ã¯RTX830ã䜿ã£ãŠããã
æ ç¹éVPNã®èšå®ãããªã¢ãŒãã¢ã¯ã»ã¹VPNãšåãããã«ãWebGUIã«ã¢ã¯ã»ã¹ããããããèšå®ããVPNããæ ç¹éæ¥ç¶ããšé²ã¿èšå®ããããªããäºåã«ãããããã©ã³ãDNSãèªèšŒéµãèªèšŒã¢ã«ãŽãªãºã ãæå·ã¢ã«ãŽãªãºã ããæ¥ç¶å ãšå ±æããŠãããšããã®ãåæ§ã ã
ããã§æ³šæãã¹ãç¹ãšããŠãLANåŽã®ã¢ãã¬ã¹ãéè€ããªãããã«ããããšããããšãæãããããããšãã°ãæ¬ç€ŸåŽã®ã¢ãã¬ã¹ãã192.168.100.0/24ãã ãšããããå¶æ¥æåŽã¯ã192.168.200.0/24ããšããŠããå¿ èŠãããã®ã ã
æ¬ç€ŸåŽã®ã«ãŒã¿ã«èšå®ããããªããå¶æ¥æåŽã®ã«ãŒã¿ã«ãåãããã«èšå®ããããªãããšã§ãæ ç¹éVPNæ¥ç¶ã確ç«ãããããšãã§ãããVPNæ¥ç¶ã確ç«ã§ããã°ãããšã¯ãããããå°çšç·ã§æ¥ç¶ãããŠãããã®ããã«ãããã¯ãŒã¯ã䜿ãããšãå¯èœãZ瀟ã§ã¯å¶æ¥æããæ¬ç€Ÿã®ãã¡ã€ã«ãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããããã«ãªããæ¥åå¹çãæ¹åãããã
|
Bãã |
|
Aå |
RTXïŒïŒïŒã§ã®ãªã¢ãŒãã¢ã¯ã»ã¹èšå®ã¯ãæåæãããã»ã©å®¹æã«èšå®ã§ãããã瀟å¡ãããšãŠãåãã§ããããããšã§ãAåã¯IT管çè ãšããŠæŽ»åããåã³ãã²ãšã€ç¥ã£ãã®ã ã£ãã
[PR]æäŸïŒã€ãã




























