ͥåȥڥꥹ - SE̼η -

ͥåȥڥꥹȤλкȤǤͥåȥڥꥹȻι
̡ʤΥġ⡢μʤɤξǺܤޤкߥʡԤäƤޤ ͥåȥڥꥹ
кʤ麸κǤܤ֥ͥڡץ꡼ʵɾҡˤǡ
ͥåȥڥꥹȻ˹ʤȡͥåȥ˴ؤμ䵻ѤǤʤɲϤʸϤȤˤĤޤ
ˡλ˹ʤǤȤ뤳ȤǤޤ

ƥꡧ12.ƥ > 12.1 Firewall

ִͥåȥȥ󥿡ͥåȤ³ǡѥåȥե륿󥰵ǽʤɤѤƳɻߤΡH17AD-52ˡפϲ

ϴñǤ͡ǥФΥƥ뤿Ѥ뤳Ȥ⤢ޤϡ֥եFirewallˡפǤͥåȥڥꥹȻǤϡFirewallФ򤷤Ƥ餤ƤǤ

firewallͳ
⤦⤷ޤfireϡֱפwallϡɡפ̣ޤfirewallϡȤȲлʤɤΤȤˡɤɲɡפȤ̣Ǥ
ͥåȥˤfirewallʥեˤϡαʹ⡢ˤɤΤˤʤޤ

firewallεǽ
Ūʵǽϡե륿󥰤εǽǤȤСIPɥ쥹̿ġorݡˤꡢΥݡȡʤȤСHTTPSMTPʤɡˤ̿ġorݡˤޤ
ޤͥåȥ򭡥󥿡ͥåȡDMZȤ3Ĥʬ뵡ǽޤäơ롼ƥ󥰵ǽĤȤۤȤɤǤ

ݥꥷ
ʤΤ⤫鳰ʤΤȤˤäơFWݥꥷʥ롼ˤѤޤ
㤨СͻǤ쳤ƻʤɤ˴ؽ꤬ߤޤ
ǤϡŴˤнפػߤޤŪˤϡؤŴˤػߤͤФ򸷤åʹƤޤ
Ĥޤꡢˤäƥ롼뤬ۤʤޤ

ιŴˤˤɤν׻()ήФɤΤϡޤ˥եǤ͡

firewall
ѥåȥե륿󥰤ȥåȥȥץꥱ󥲡ȥΣĤ롣
ѥåȥե륿ǤϡѥåȤΥإåʬIPɥ쥹ݡֹʤɡˤ򸫤̿εĤȵݤȽǤ롣

DMZDeMilitarized ZoneˤȤϡmilitarizeˤdeˤZoneӡˤȤľ̤ꡢӤǤ
ͥåȥˤӤȤΤ狼ˤȻפޤ
̤ˤ褤򤷤Ƥ2֤¸ߤޤȤС˿Ǥ38򶭤ˡ2ҤĤӤޤͤ򤵤뤿δ˾׶ȤƤǤϰˤäƻϤȤʤ褦ǤDMZϡξ񤬹ԤǤ륨ꥢˤʤޤ
ef6167f8.jpg

ƱȤͥåȥˤ⤢Ǥ͡
̤ꡣ󥿡ͥåȡʳˤLAN֤ˤꡢξԤߤ˹ԤǤͣΥꥢDMZǤˤϥ᡼륵ФWebФʤɤθФ֤졢Ǥʤ󥿡ͥå¦ʳˤ⥢Ǥޤ

Τ褦˥ͥåȥ򥤥󥿡ͥåȡDMZLANʬĤΤեˤʤޤ

ͥåȥڥꥹȤβǤϡǯΤ褦˥ͥåȥޤޤȤСH26ǯ壱䣳ˤȡʲΤ褦ˡեˤơ󥿡ͥåȡDMZȡ3ĤʬΥƤޤ

ޤάƤޤ
DMZ_ͥåȥڥꥹȻ

եΥ롼ʥݥꥷˤˤĤ
ѥåȥե륿󥰷եFirewallˤΥ롼ʥݥꥷˤ򼨤ʢH20SVꡡ45

FirewallΥ롼ϡʲˤ褦˥ѥåȤΥإåʬǧʵĤػߡˤꤹ롣
IPѥåȤΥإå碌Ƴǧ

ˤ褦ˡ֥եǤνϡ롼˼ֹ1˹ԤĤΥ롼뤬ŬѤ줿ˤϻĤΥ롼ŬѤʤפȤΤŪǤ롣
ޤʤȤλͤǤäƵʤʤɤǷޤäƤ櫓ǤϤʤ롼뤬̵дŪ˵ݤǤ롣ʢۤDENYANY-ANY-DENYˤꤵƤȤͤ롣
rule

ѥåȤΥ롼
ɬפϤʤNetScreen/SSGξ硢ưŪե륿󥰤ˤꡢΥѥåȤϼưǵĤ롣㤨С鳰Υ󥿥륵ФPOP3ˤƥ᡼Ȥ롣ξ硢鳰ؤPOP3110ˤΤߤĤФ褯ؤPOP3פ CiscoΥ롼ʤɤǥե륿󥰤񤯾ϡưŪե륿ǤϤʤΤǡ⤭Ƚɬפ롣


Ūʥ롼ιͤ
ιͤϡ򤷤Ƥޤ礦


ŪˤƤΥѥåȤߤɬפʥ롼򳫤롣
pingˤ̻ѤICMP򤹤٤ƵĤȤ߷פ򤹤ͤ⤤뤬פʥݥꥷߤΤǤ롣
IPɥ쥹ǤΥݥꥷ¿ΥȤURLǻꤹ뤳Ȥ⤢롣ʤȤ⤢롣
ݥꥷϾ夫˥åפΤСΥ롼ŬѤ롣ĤޤꡢʹߤϸʤʤΤǡ֤

DMZ
WebФʤɤΤɬפʥݥꥷϡɬפʤĤ롣
㤨СWebФǤСHTTP80ˤHTTPS443ˤΤߤĤ롣ФIPɥ쥹ƤƵĤ褦Ϥ褯ʤ

ȤؤΥ
ȤؤΥϤ٤ƶػߤ롣
ޤˡؤΥݥꥷꤷƤȤ򸫤뤬Ф˿侩Ǥʤ٤ƶػߤˤ٤
̿Ϥ٤DMZΥФȤ٤ǤꡢɤƤĤ٤Τʤ顢DMZ֤٤Ǥ롣
ʤ餫λǤ줬Ǥʤ硢IPɥ쥹ꤹ٤Ǥ롣

鳰ؤΥ
饤󥿡ͥåȤؤ³⡢Υ鲿ǤĤΤϤ褯ʤʾϳɤ
WebProxyͳȤϡProxyΤߤ˸ꤹ롣
ޤץȥHTTPʤɤȶŪ˻ꤹ롣FTPȤʤʤɡȤʤץȥϵݡ

H24SC26ˤǤϡ֥եˤʥߥåѥåȥե륿󥰤ħפȤơΥѥåȤ˴ؤƤϡ̲ᤷꥯȥѥåȤбΤ̲ᤵ뤳ȤǤפȤ롣
ּLANΥ饤PC顢TCPȤä󥿡ͥåȾWebȻȤ˴ؤƤϡե륿󥰥ơ֥뤬ɽΤ褦ꤵƤ롣饤PC1WebA򻲾ȤݤαΥѥåȤ̲ᤵ뤿ˡ㤨Х饤PC192.168.10.5ˤե륿󥰥ơ֥ιֹ10ˤäƵĤѥåȤȡưŪѥåȥե륿󥰵ǽǤϹֹ10ȹֹ20δ֤˹ֹ15ιԤ롣ֹ15ιԤϡTCPåνλѥåȼ˺롣


ɽե륿󥰥ơ֥ȴ
̸ֹ͡͡IPɥ쥹͡IPɥ쥹̥͡ץȥ͡ݡֹ͡ݡֹ̽͡
10͡OUT͡C͡anywhere͡TCP͡any͡80̵͡ġ
20͡OUT/IN͡anywhere͡anywhere͡TCP͡80͡any̼͡ǡ

Ǥϡꡣ
ֹ15Υե륿󥰥ơ֥񤱡âWebФIPɥ쥹ϡ210.2yy.1yy.100Ȥ롣H21ǯAP9

ޤưŪѥåȥե륿󥰤Ȥϲ
ѥåȥե륿󥰤ˤϡŪưŪ2ब롣Cisco 롼ǤϰʲǤ뤬̿ϹԤȵ꤬ꡢξͤʤФʤ
Cisco롼ξ硢ǥեȤǤƤ̿Ĥ뤿ᡢԤĤСϼư̲᤹롣

ϰʲǤ
15͡IN͡210.2yy.1yy.100͡220.1xx.2xx.4͡TCP͡80͡1024̵͡ġ

ޤơȥե륤󥹥ڥǽˤĤƲ⤷ޤ
ͥåȥڥꥹȻǤϡۤȤ줿ȤϤޤ󤬡H21AP9ˤǤϡ֥ѥåȤν֤TCPإåΥֹǧ̲ᤵפȤޤ
ơȥե륤󥹥ڥ˴ؤƤϡCheck PointҤ󾧤Ȼפޤ٥ͭ̾ΤǤ⤢Τǡ뤳ȤϤޤʤǤ礦
¿ΥեǴŪˤϼƤ뵡ǽǤʤΤǡդȡλȤߤ򤷤Ƥޤ礦ޤϸ̤ꡢơȡʾ֡ˤեõʥ󥹥ڥˤȤ̣ǹͤƤޤ礦

ơȥե륤󥹥ڥưŪե륿󥰤ΰ㤤ϡ

ξԤΤʬΤǤϤʤХåפΤǤ롣
ʸˤξԤʬƤΤ⤢Сɤ餫ƤɽƤΤ⤢롣
Τʰ㤤ϲס֤εǽϤɤäؤƤΤפʤɤȤޤм˹ͤɬפϤʤ
礻ϡ֤θաפǤ롣
ef6167f8.jpg


Хܥɡʹ̼ҡˤˤơŷ̵ФȤϤθաפȽҤ٤Ƥޤ
Ʊʡ
ޤʴǤ礦
ʤΤϸդ̣Ƥ뤫ưŪե륿󥰤Ūե륿󥰤ФȤƤǤդǤ뤷ơȥե륤󥹥ڥȤ ֤եõȤ̣
򥷥ץ˹ͤƤФ褤

DMZΥԥ塼󥿡ͥåȤping˱ʤ褦˥եΥƥ롼Ȥ̲ػߡɤꤹΤϤɤ줫H22SCո11ˢץȥ

եˤĤƤ롣ݥȤping˱ʤȤȤpingΥץȥϲС줬Ǥ롣ICMP

c2f058cb

ʤƤ⤤Ȼפޤ
եϴؽ㤨뤳Ȥ¿ؽ˸¤餺Ȥθؤ⳰ʬȤ̣ǤϥեϻƤ롣
եϤʤɬפ餤ȥƥΰ층Ǥ롣
ƥФѥ󤬸ġ˥ѡʥե䥢ˤꡢƥζҤɤȤϤǤ롣DMZ˸Ƥ륵ФɤǤ롣̤к򤹤ΤѤƥк˺ʤϳ⤢롣եǰ층Ū˥򤷡򤷡ǶǤUTMɽ褦ʥ륹åSPAMåʤɤԤΤǤ롣顢󥿡ͥåȲ٤ȤäơʣΥץХȷ󤷤ʣνиĴȤϤʤ꾯ʤؽʤ٤ο̤ͤʤȤ֤ƤΤϡ줬ͳǤ롣
ե뤬ʤä饻ƥϼʤʤȤϤʤե뤬ʤƤȤΥƥϼ롣ġкΤϤȤƤѤǤ롣ʹ֤뤳ȤʤΤǡѤˤʤȥߥФ롣̣ǥե뤬뤳ȤˤꡢƥαѴڤˤʤꡢŪ˴ȤΥƥ٥뤬夬롣

ͥåȥڥꥹȻǤϡեΥݥꥷ˴ؤ꤬褯ޤȾüȡޤְ㤨ޤ
ͥڤܻǡɤ꤬ФƤбǤ褦ˡä򤷤Ƥޤޤ礦

Ǥϡʲοޤ򸫤ơFirewallΥݥꥷƤ
ȤƤٶˤʤΤǡ򸫤˼ʬǹͤޤ礦
ʽH19NW13)
FW
ʲ˥ݥꥷƤϤƤ
1ܡʥݡ0ˤ򻲹ͤˤƤ
1ܤʤʤ뤫ޤϹͤޤ礦
ޤݡ0ϥ󥿡ͥåȤĤʤäƤޤ
˥ݡ1ϸФΤǡDMZǤ
ݡ2ȤǤ
ݡ3ϴƻѥФΥȤˤʤޤ
mondai
ϰʲǤʬǼ褦ˤƤ
1ܡʥݡ0ˤ򻲹ͤˤƤ
ޤ1ܤʤʤ뤫ͤޤ礦1ܤϥ󥿡ͥåȤΥǤΤǡĤΤDMZθФΤߤǤ

2ܤDMZ̿Ǥ
󥿡ͥåȤDMZؤ̿DOMAINSMTPHTTPפʤΤǡDMZ饤󥿡ͥåȤؤ̿ƱȤñƤǤϤޤ
FWʥߥåѥåȥե륿󥰵ǽʤΤǤСԤΥ롼ϴŪƱˤʤޤϥʥߥåѥåȥե륿εǽĤΤǡԤȵ̡˹ͤɬפޤDMZ饤󥿡ͥåȤؤ̿ϡʲ3ĤǤ
DOMAINDNSΥžDNS䤤碌ʤ
SMTP鳰ؤΥ᡼ž
HTTPץСʸȤPCˤΥ󥿡ͥåȥ

3ܤϡȤ̿Ǥ
󥿡ͥåȤľܥ뤳Ȥ򤷤ʤ롼ˤʤäƤޤʹͤʤΤǡȤˤäưۤʤޤˡȤDMZؤ̿ϡʲ3ĤǤ
DOMAINPCDNS䤤碌
SMTP:᡼륵Ф᡼
HTTP󥿡ͥåȥ

Ȥƻ륻Ȥؤ̿ϡʲ2ĤǤ
Ȥε狼ƻ륵ФؤTrap
ƻPCƻ륵Фش̡WEBˤؤΥ

4ܤϡƻ륻Ȥ̿ǡDMZȤؤSNMPˤݡ󥰤ʤɤ̿ޤ
seikai


ݥ󥵡ɥ

ΥڡΥȥåץ