26-8. ½Ä¤ÈËȤȤ½¤ì¤Ë£°¡¥£±¡ó¤È¤ÎÀ襤 `2h/10¡Á -------------------------------------------------------------------------------- ²ø¤·¤¤¥á¡Ý¥ë¤Î£¹£¹¡¥£¹¡ó¤ÏÊ䪤Ǥ­¤Æ¤¤¤ë¡£²¿Æü¤«¤Ë°ìÄ̤°¤é¤¤¥¹¥Ñ¥à¥á¡Ý¥ë¤ä¥¦¥£¥ë ¥¹Æþ¤ê¥á¡Ý¥ë¤¬¤¬È´¤±¤Æ¤¯¤ë¡£¤³¤ì°Ì¤Î¾õÂ֤ǥÁ¥§¥Ã¥¯¹àÌܤò¥­¡Ý¥×¤¹¤ë¤·¤«¤Ê¤¤¡£¤³¤ì °Ê¾å¥Á¥§¥Ã¥¯¤òÁý¤ä¤¹¤È¸í¸¡ÃΤ¬À¸¤¸¤Æµ¯¤Æ¤·¤Þ¤¦¡£¤³¤Î¶Ï¤«¤Ê£°¡¥£±¡óÄøÅ٤θ¡ÃÎϳ¤ì ¤Î¥á¡Ý¥ë¤ËÂФ·¤Æ¡¢¥Á¥§¥Ã¥¯¤òÀºÅÙ¤ò¾å¤²¥¯¥ê¡Ý¥ó¤Ê¥á¡Ý¥ë¤À¤±¤ò¥æ¡Ý¥¶¤ËÆϤ±¤ë¤è¤¦¤Ë ¤·¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¡£ÀµÄ¾¤«¤Ê¤êº¤Æñ¤Ê²ÝÂê¤Ç¤¢¤ë¡£¥¦¥£¥ë¥¹¤òÊá³Í¤·¤½¤ì¤ò¸¡ÂΤȤ·¤Æ ¹¹¤Ê¤ë¥Á¥§¥Ã¥¯¤ÎÍ­¸úÀ­¤ò¸¡¾Ú¤¹¤ë¤³¤È¡£¿Í¹©ÃÎǽ¤Îµ»½Ñ¤Ç¤â¤Ã¤Æ¥Á¥§¥Ã¥¯¤·¸¡ÃΤǤ­¤ë ¤«¡¢¥Æ¥¹¥È´Ä¶­¤òºî¤Ã¤Æ»î¤·¤Æ¤ß¤ë¤³¤È¡£¤³¤ì¤Ï¤Þ¤µ¤ËÀïÁè¤À¡¢¥µ¥¤¥Ð¡ÝÀïÁè¡£½ª¤ï¤ê¤Î ¤Ê¤¤¾¡¤ÁÌܤÎ̵¤¤À襤¤«¤âÃΤì¤Ê¤¤¡£Äü¤á¤¿¤é¤½¤³¤Ç¤ª¤·¤Þ¤¤¤À¡ª¡£Î©¤Á¸þ¤«¤¦¤·¤«¤Ê¤¤¡£ -------------------------------------------------------------------------------- (1) ¥á¡Ý¥ë¤Î¥¦¥£¥ë¥¹¤Î¹¹¤Ê¤ë¸¡ÃΤò * ¥á¥â £×£å£â¥á¡Ý¥ë¤Ë¤¹¤êÈ´¤±¤¿ÉÔÀµ¥á¡Ý¥ë¤ò¥¦¥£¥ë¥¹ÅºÉդΥµ¥ó¥×¥ë¤ÇÁ÷¤ì¤Ð¥Á¥§¥Ã¥¯¤Ç¤­¤ë¡£ ¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤Ç¸¡ÃΤµ¤ì¤ë¤Ï¤º¤¬¡¢¥¹¥Ñ¥à¥Á¥§¥Ã¥¯¤Ç¸¡ÃΤµ¤ì¤Æ¤¤¤ë¡¢Í׳Îǧ¡ª¡£ FortiMail ¤Î¥á¡Ý¥ë¥Á¥§¥Ã¥¯¤Î½çÈÖ¤ò²þ¤á¤Æ³Îǧ¤¹¤ë¤³¤È¡£"IP¥Ù¡Ý¥¹¥Ý¥ê¥·¡Ý" ¤È"¼õ¿® ¼Ô¥Ý¥ê¥·¡Ý" ¤¬½ÅÊ£¤¹¤ë¾ì¹ç¤Ï "IP¥Ù¡Ý¥¹¥Ý¥ê¥·¡Ý" ¤¬Àè¤ËŬÍѤµ¤ì¤ë¡£ "IP¥Ù¡Ý¥¹¥Ý¥ê¥·¡Ý" ¤Î¥á¥Ë¥å¡Ý¤Ç "¢¢¼õ¿®¼Ô¥Ù¡Ý¥¹¥Ý¥ê¥·¡Ý¤ÎŬÍѤò¾Êά" ¤¢¤ê¡£ ¤³¤ì ¤ò¡º¤·¤Ê¤¤¸Â¤ê "¼õ¿®¼Ô¥Ý¥ê¥·¡Ý" ¤â¥Á¥§¥Ã¥¯¤¹¤ë¤È¤¤¤¦¤³¤È¡£ "25-2.¥µ¥ó¥É¥Ü¥Ã¥¯¥¹À½ÉʤÎÀßÃÖ¤Þ¤Ç,(4) ³FortiMail¤ÈFortiSandbox" ¤Ë¥á¡Ý¥ë¤Î¥Á¥§ ¥Ã¥¯¤Î½çÈÖ¡£¥á¡Ý¥ë¤ÎÉÔÀµ¤ÊźÉÕ¥Õ¥¡¥¤¥ë¤Î¸¡ÃΤȺï½ü¤Ï fortisd.txt forti4.txt »²¹Í¡£ ¥Ò¥å¡Ý¥ê¥¹¥Æ¥£¥Ã¥¯¥¹¥­¥ã¥ó¤ÎÀâÌÀ¤ò¥Í¥Ã¥È¤ä¤³¤ì¤Þ¤Ç¤â¤é¤Ã¤¿»ñÎÁ¤«¤é³Îǧ¤·¤Æ¤ß¤è¤¦¡£ Heuristic ¤È±Ñ¸ì¤Ç¤ÏÄ֤롣ȯ¸«Åª¤ÈÀΤ˳Ф¨¤¿¤¬¡¢¤É¤¦¤âºòº£¤Ï°ã¤¦¤è¤¦¤Êµ¤¤¬¤¹¤ë¡£ ¼õ¿®¤Î {¥¢¥ó¥Á¥¹¥Ñ¥à} ¤Ï²¼µ­¤ÎÀßÄê¤Ç±¿ÍÑ¡£¸¡ÃΤò¾å¤²¤ë¤Ë¤Ï "¥Ò¥å¡Ý¥ê¥¹¥Æ¥£¥Ã¥¯¥¹ ¥­¥ã¥ó" ¤ò¤ä¤é¤»¤ë¤°¤é¤¤¤·¤«¼Â¼Á¤Ê¤¤¡£¤½¤Î¥Ñ¥é¥á¡Ý¥¿¤ò¤É¤¦¤¹¤ë¤«¸¡Æ¤¤·¤è¤¦¡£ * FortiMail ¤Î¥¹¥Ñ¥à¥Á¥§¥Ã¥¯¤Î¥á¥Ë¥å¡Ý ¼«Ê¬°¸¤ËÍ褿¥á¡Ý¥ë ikken@nix.co.jj ¤ò¥¨¥¤¥ê¥¢¥¹¤ÇžÁ÷¤·¤Æ¡¢kensan@nix.co.jj ¤Ø¤â Á÷¤ë¡£¤³¤ì¤ò¥µ¥ó¥×¥ë¤Ë¤¹¤ë¡£ikken@nix.co.jj ¤Ø¤Î¥á¡Ý¥ë¤Ï FortiMail¤Î¥¦¥£¥ë¥¹¥Á¥§ ¥Ã¥¯¤Ï¤·¤Ê¤¤¡¢¥Ñ¥½¥³¥ó¤Î¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¥½¥Õ¥È¤Ç°ú¤Ã¤«¤«¤ë¤è¤¦¤Ë¤¹¤ë¡£kensan@ ¤Î Êý¤Ï°ìÈÌ¥æ¡Ý¥¶¤ÈƱ¤¸°·¤¤¤Ç¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤â¤ä¤ë¡¢¤½¤ì¤Ç²ø¤·¤¤ÅºÉÕ¥Õ¥¡¥¤¥ëÉÕ¤­¤Î ¥á¡Ý¥ë¤Ï¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤ËÁ÷¤é¤ì¥Á¥§¥Ã¥¯¤µ¤ì¤ë¡£ ¢¥¼õ¿®¼Ô¥Ý¥ê¥·¡Ý -------------------------------------------------------------------------------- |¿·µ¬ ÊÔ½¸ °ÜÆ° ºï½ü ¥É¥á¥¤¥ó:[--¤¹¤Ù¤Æ-- ¢¦] Êý¸þ[¼õ¿® ¢¦]| |------------------------------------------------------------------------------| |Í­ ¥Ý¥ê Êý¸þ Á÷¿®¼Ô ¼õ¿®¼Ô ¥É¥á¥¤¥ó̾ ¥¢¥ó¥Á ¥¢¥ó¥Á¥¦ ¥³¥ó ¥ê¥½¡Ý¥¹ | |¸ú ¥·ID ¥Ñ¥¿¡Ý¥ó ¥Ñ¥¿¡Ý¥ó ¥¹¥Ñ¥à ¥£¥ë¥¹ ¥Æ¥ó¥Ä | |------------------------------------------------------------------------------| |¡º 2 ¼õ¿® *@* ikken nix.co.jj NspamR | |¡º 1 ¼õ¿® *@* * nix.co.jj NspamR Nvirus | -------------------------------------------------------------------------------- ¢¨ikken ¤Ï ikken@nix.co.jj¡¢* ¤Ï *@nix.co.jj ¤Î°ÕÌ£¡£ [¥×¥í¥Õ¥¡¥¤¥ë]->[¥¢¥ó¥Á¥¹¥Ñ¥à]->{¥¢¥ó¥Á¥¹¥Ñ¥à} ------------------------------------------------------------------- | ¥¢¥ó¥Á¥¹¥Ñ¥à¥×¥í¥Õ¥¡¥¤¥ë | |¥É¥á¥¤¥ó: [--¥·¥¹¥Æ¥à-- ] ³¥¿§ NspamR-act ¤Ï¥æ¡Ý¥¶³ÖÎ¥¤¹¤ë¡£ |¥×¥í¥Õ¥¡¥¤¥ë̾: [NspamR ] ³¥¿§ |Êý¸þ: [¼õ¿® ¢¦] ³¥¿§ |¥Ç¥Õ¥©¥ë¥È¥¢¥¯¥·¥ç¥ó:[NspamR-act ¢¦] ¥Ç¥Õ¥©¥ë¥È¤È¤¤¤¦¤Î¤Ïº¸¤ÎÀßÄê | NspamR-act ¤ò»È¤¦¤È¤¤¤¦¤³¤È¡£ | ¥¹¥­¥ã¥óÀßÄê ¢­ | ¡º¢§FortiGuard¥¹¥­¥ã¥ó ¥¢¥¯¥·¥ç¥ó:[-¥Ç¥Õ¥©¥ë¥È- ¢¦] | ¡ºIP¥ì¥Ô¥å¥Æ¡Ý¥·¥ç¥ó ¥¢¥¯¥·¥ç¥ó:[-¥Ç¥Õ¥©¥ë¥È- ¢¦] | ¡º¥Ø¥Ã¥ÀÆâ¤ÎIP¤ò¥¹¥­¥ã¥ó | ¡º¥Õ¥£¥Ã¥·¥ó¥°URI [phishing ¢¦] ¥¢¥¯¥·¥ç¥ó:[-¥Ç¥Õ¥©¥ë¥È- ¢¦] | ¢¢¥¹¥Ñ¥à¥¢¥¦¥È¥Ö¥ì¡Ý¥¯Ëɸæ | ¢¢¥°¥ì¡Ý¥ê¥¹¥È¥¹¥­¥ã¥ó << antispam_basic_predefined_high ¤Ï¡º¤¢¤ê¡£ | ¢¢SPF¥Á¥§¥Ã¥¯ << ¤³¤ì¤Ï¥á¡Ý¥ë¥ê¥ì¡Ý¤Ç¤Ê¤¤¤ÈÍ­¸ú¤Ç¤Ï¤Ê¤¤¡£ | ¢¢DMARC¥Á¥§¥Ã¥¯ | ¢¢¿¶¤ëÉñ¤¤Ê¬ÀÏ | ¢¢¥Ø¥Ã¥À¡ÝʬÀÏ | ¢¢¢§¥Ò¥å¡Ý¥ê¥¹¥Æ¥£¥Ã¥¯¥¹¥­¥ã¥ó | ºÇÂ礷¤­¤¤ÃÍ: [3.50 ] | ¥ë¡Ý¥ë»ÈÍÑΨ: [25 ] | | [¥×¥í¥Õ¥¡¥¤¥ë]->[¥¢¥ó¥Á¥¹¥Ñ¥à]->{¥¢¥ó¥Á¥¹¥Ñ¥à} ¥×¥í¥Õ¥¡¥¤¥ë̾¤Ç¿¶¤ëÉñ¤¤Ê¬ÀÏ¡¢¥Ø ¥Ã¥À¡ÝʬÀÏ¡¢¥Ò¥å¡Ý¥ê¥¹¥Æ¥£¥Ã¥¯¥¹¥­¥ã¥ó¤Ïά¤·¤Æ(¥Ò¥å¡Ý)¤Èµ­ºÜ¡£Êý¸þ¤Ï¼õ¿®¡£¥Ò¥å¡Ý ¥ê¥¹¥Æ¥£¥Ã¥¯¥¹¥­¥ã¥ó¤ÎºÇÂ礷¤­¤¤ÃͤÏÁ´Éô 3.50¡¢²¼µ­¤Ë¤Ï¥ë¡Ý¥ë»ÈÍÑΨ¤ò»²¹Í¤Ëµ­ºÜ¡£ AS_Inbound ¡º¿¶¤ëÉñ¤¤¡¢¡º¥Ø¥Ã¥À¡ÝʬÀÏ¡¢¡º¥Ò¥å¡Ý(75) antispam_basic_predefined_high ¡º¿¶¤ëÉñ¤¤¡¢¡º¥Ø¥Ã¥À¡ÝʬÀÏ¡¢¡º¥Ò¥å¡Ý(50) antispam_basic_predefined_medium ¡º¿¶¤ëÉñ¤¤¡¢¢¢¥Ø¥Ã¥À¡ÝʬÀÏ¡¢¡º¥Ò¥å¡Ý(25) antispam_basic_predefined_low ¢¢¿¶¤ëÉñ¤¤¡¢¢¢¥Ø¥Ã¥À¡ÝʬÀÏ¡¢¢¢¥Ò¥å¡Ý(25) antispam_basic_predefined_off ¢¢¿¶¤ëÉñ¤¤¡¢¢¢¥Ø¥Ã¥À¡ÝʬÀÏ¡¢¢¢¥Ò¥å¡Ý(25) [¥Ý¥ê¥·¡Ý]->[¥Ý¥ê¥·¡Ý]->{¥Ý¥ê¥·¡Ý} ¤Î "IP¥Ý¥ê¥·¡Ý" -------------------------------------------------------------------------------- |Í­¸ú ¥Ý¥ê¥·¡ÝID Á÷¿®¸µ °¸Àè ¥»¥Ã¥·¥ç¥ó ¥¢¥ó¥Á¥¹¥Ñ¥à ¥¢¥ó¥Á¥¦¥£... |------------------------------------------------------------------------------- |¡º 1 0.0.0.0/0 0.0.0.0/0 Inboud_Session |¢¢ 2 ::/0 ::/0 Inboud_Session -------------------------------------------------------------------------------- [¥Ý¥ê¥·¡Ý]->[¥Ý¥ê¥·¡Ý]->{¥Ý¥ê¥·¡Ý} ¤Î "¼õ¿®¼Ô¥Ý¥ê¥·¡Ý" -------------------------------------------------------------------------------- |Í­¸ú ¥Ý¥ê¥·¡ÝID Êý¸þ Á÷¿®¼Ô¥Ñ¥¿¡Ý¥ó ¼õ¿®¼Ô¥Ñ¥¿¡Ý¥ó ¥É¥á¥¤¥ó̾ ¥¢¥ó¥Á¥¹¥Ñ¥àÅù |------------------------------------------------------------------------------- |¡º 1 ¼õ¿® *@* *@nix.co.jj nix.co.jj -------------------------------------------------------------------------------- * ¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤ÎÀ­Ç½¥Æ¥¹¥È Éݤ¯¤Æ¥¦¥£¥ë¥¹Æþ¤ê¥á¡Ý¥ë¤Î¥Æ¥¹¥È¤Ï¤³¤ì¤Þ¤Ç¡¢¤è¤¦¤ä¤ì¤Ê¤«¤Ã¤¿¡£FortiMail ¤Î£×£å£â ¥á¡Ý¥ë¤òÍѤ¤¤Æ¤ä¤ì¤ë¡£¤ä¤ì¤ë¤³¤È¤¬Ê¬¤«¤Ã¤¿¡£Í褿¥á¡Ý¥ë¤òžÁ÷¤¹¤ë¤À¤±¤Ê¤éÌäÂê¤Ê¤¤¡£ źÉÕ¥Õ¥¡¥¤¥ë¤Î¥¦¥£¥ë¥¹¤ò¥¯¥ê¥Ã¥¯¤·¤Ê¤±¤ì¤ÐÌäÂê¤Ê¤¤¡££×£å£â¥á¡Ý¥ë¤Ç¥á¡Ý¥ë¤òžÁ÷¤· ¤Æ¤â¥Ñ¥½¥³¥ó¤Î¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¥½¥Õ¥È¤Ë¤Ï°ú¤Ã¤«¤«¤é¤Ê¤¤¡££×£å£â¥á¡Ý¥ë¤Ë¤Æ {¼õ¿®¥È ¥ì¥¤} ¤Ë¤¢¤ë¥á¡Ý¥ë¤Î°ìÍ÷¤«¤é¡¢¥Æ¥¹¥È¥á¡Ý¥ë¤ò¥¯¥ê¥Ã¥¯¤·¤¿¤È¤³¤í¡£¤³¤³¤Þ¤Ç¤ÎÁàºî¤Ç ¤ÏźÉÕ¥¦¥£¥ë¥¹¤Ï¤½¤Î¤Þ¤ÞÉÕ¤¤¤Æ¤¤¤ë¡£ ------------------------------------------------------------- |https://192.168.1.1/mail |------------------------------------------------------------ | ¤¹¤Ù¤Æ¤Î¥Õ¥©¥ë¥À| ÊĤ¸¤ë ÊÖ¿® Á´°÷¤ËÊÖ¿® žÁ÷ °ÜÆ° ¤½¤Î¾ |-----------------|------------------------------------------ | ¼õ¿®¥È¥ì¥¤ | ·ï̾: Test1-desu | ²¼½ñ¤­ | From: "ikken" | Á÷¿®ºÑ¤ß¥¢¥¤¥Æ¥à| To: "ikken" | ³ÖÎ¥ |------------------------------------------ | ¥´¥ßÈ¢ | ¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤Î¥Æ¥¹¥È¤Ç¤¹ | °Å¹æ²½¥á¡Ý¥ë | | ------------------------------------------- | ¡÷EICAR_test.com ------------------------------------------------------------- ¤¹¤êÈ´¤±¤Æ£×£å£â¥á¡Ý¥ë¤ËÆþ¤Ã¤¿¥á¡Ý¥ë¤ò¡¢¥¦¥£¥ë¥¹Æþ¤ê¥á¡Ý¥ë¤È¤·¤ÆÁ÷¤êľ¤·¤Æ¥Á¥§¥Ã ¥¯¤·¤Æ¤ß¤ë¡£aaa@nix.co.jj ¤Ë¤­¤¿¥á¡Ý¥ë¤Ï bbb@nix.co.jj ¤Ë¤âÁ÷¤ë¡£ aaa ¤Ï¥Á¥§¥Ã¥¯ ¤Ê¤·¡¢Outlook ¤ÇÁàºî¤·¤Æ¤¤¤ëʬ¤Ë¤Æ¡£ bbb ¤Ï FortiMail ¤Î¼ÒÆâ¤ÎŬÍÑ¥Á¥§¥Ã¥¯¤ò¤·¤Æ ¤¤¤ë¡£aaa@nix.co.jj ¥á¡Ý¥ë¤ÏÄ̾ï»È¤Ã¤Æ¤¤¤ë Outlook ¤ËÍè¤ë¡£ FortiMail ¤Ç¤Î¥Á¥§¥Ã ¥¯¤Ï¤·¤Ê¤¤¤¬¡¢¥Ñ¥½¥³¥óÍѤΥ¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¥½¥Õ¥È¤Ç¤Î¸¡ÃΤϼ»ܤµ¤ì¤Æ¤¤¤ë¡£¾ì¹ç¤Ë ¤è¤Ã¤Æ¤Ï¥Ñ¥½¥³¥óÍѤΥ¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¥½¥Õ¥È¤Ç¡¢¥á¡Ý¥ë¤Î¥Á¥§¥Ã¥¯¤ò¥ª¥Õ¡¢¥ê¥¢¥ë¥¿¥¤ ¥à¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥àÊݸî¤ò°ì»þŪ¤Ë¥ª¥Õ¤Ë¤·¤Æ¡¢Æ°ºî¤ò¸¡¾Ú¤·¤Æ¹Ô¤¯É¬Íפ¬¤¢¤ë¡£ ¡¦bbb ¤Ç¤Ï¥Á¥§¥Ã¥¯¤µ¤ì¤¿¤Î¤¬ aaa ¤Ç¤Ï¥Á¥§¥Ã¥¯¤µ¤ì¤Ê¤«¤Ã¤¿¡£ ¡¦£×£å£â¥á¡Ý¥ë¤Î aaa ¤Ë¤Ï¥¦¥£¥ë¥¹Æþ¤ê¥á¡Ý¥ë¤¬¤¹¤êÈ´¤±¤Æ¤¤¤ë¡£ ¡¦£×£å£â¥á¡Ý¥ë¤Ç aaa ¤ò ccc ¤ËÁ÷¤ë¡£ccc °¸¤ÏÆÃÊ̤ʥÁ¥§¥Ã¥¯¤ò¤¹¤ë¡£ * FortiMail ¤Ç¤Î¥»¥­¥å¥ê¥Æ¥£¥Á¥§¥Ã¥¯¤ÎŬÍÑ [ ¥á¡Ý¥ë¥ê¥ì¡Ý¤Ç¤ÎÀßÄê ] ¢¬P1 ¡ÃR {IP¥Ý¥ê¥·¡Ý} ¤Î£±ÈÖÌÜ P2¡¢Á÷¿®¸µ¤Ï MS ¤ÎIP¥¢¥É¥ì ¡Ã ¢­ ¥¹¡¢°¸Àè¤ÏǤ°Õ 0.0.0.0/0¡££²ÈÖÌÜ P1 ¤ÏÁ÷¿®¸µ¤È°¸ ¢¢ Àè¤Ï¶¦¤ËǤ°Õ¡£¤³¤ì¤é¤Ï¥»¥Ã¥·¥ç¥ó¤Î¥Á¥§¥Ã¥¯¤Î¤ß¡£ MR¡Ã²¾ÁÛ ---------------------------- {¼õ¿®¼Ô¥Ý¥ê¥·¡Ý}¤ÎR ¤ÏÊý¸þ¤Ï¼õ¿®¡¢Á÷¿®¼Ô¥Ñ¥¿¡Ý¥ó P1 ¢¢MR | ¤Ï *@*¡¢¼õ¿®¼Ô¥Ñ¥¿¡Ý¥ó¤Ï *@nix.co.jj¡£SPAM Check¡£ ¡Ã ¡Ã ¢¬P2 ------- ¢­----¡Ã-------| | [¥á¡Ý¥ëÀßÄê]->[¥É¥á¥¤¥ó]->{¥É¥á¥¤¥ó}¥É¥á¥¤¥óFQDN ¢¢ ------- ¤Ï nix.co.jj¡¢¥ê¥ì¡Ý¥¿¥¤¥×¤Ï¥Û¥¹¥È¡¢SMTP¥µ¡Ý¥Ð¡Ý MS¡Ã | ¤Ï MS ¤ÎIP¥¢¥É¥ì¥¹¡£ ---------------------------- [ ¥á¡Ý¥ë¥¹¥È¥¢¤Ç¤ÎÀßÄê ] ¢¢ {IP¥Ý¥ê¥·¡Ý} ¤Î£±ÈÖÌÜ P2¡¢²¿¤â¥Á¥§¥Ã¥¯¤»¤º¡¢Á÷¿® MR¡Ã²¾ÁÛ ¸µ¤Ï£Ä£Í£Ú¤Î¼ÂIP¥¢¥É¥ì¥¹¡¢°¸Àè¤Ï MS ¤ÎIP¥¢¥É¥ì¥¹¡£ ---------------------------- £²ÈÖÌÜ P1 ¤ÏÁ÷¿®¸µ¤È°¸Àè¤Ï¶¦¤ËǤ°Õ¡£SPAM¤ÈVirus¡£ P2 ¢¢MR | ¡Ã ¡Ã ¢¬P1 ------- {¼õ¿®¼Ô¥Ý¥ê¥·¡Ý}¤ÎR ¤ÏÊý¸þ¤Ï¼õ¿®¡¢Á÷¿®¼Ô¥Ñ¥¿¡Ý¥ó R ¢­----¡Ã-------| | *@*¡¢¼õ¿®¼Ô¥Ñ¥¿¡Ý¥ó *@nix.co.jj¡£SPAM¤ÈVirus¡£ ¡½¡½¢ª ¢¢ ¢¤ ------- MS¡Ã¢«R¡½ ¡ÃPC | [¥á¡Ý¥ëÀßÄê]->[ÀßÄê]->{¥ê¥ì¡Ý¥Û¥¹¥È¥ê¥¹¥È}¤³¤³¤Ë ---------------------------- ¥á¡Ý¥ë¥ê¥ì¡Ý¤Î£Ä£Í£Ú¾å¤Î¼ÂIP¥¢¥É¥ì¥¹¤ò½ñ¤¤¤¿¡£ (2) ¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤Ë¿Í¹©ÃÎǽÅêÆþ * ¿Í¹©ÃÎǽ(£Á£É)¤òÅëºÜ¤·¤¿¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¥½¥Õ¥È Symantec ¼Ò¤Î¥¯¥é¥¦¥É¥µ¡Ý¥Ó¥¹¤Ç¥Ó¥Ã¥°¥Ç¡Ý¥¿¤È¿Í¹©ÃÎǽ¤Ç¥Á¥§¥Ã¥¯¤¹¤ë¤È¤¤¤¦SKEPTIC¡¢ ½é¤á¤Æ£É£Ô·Ï¤Ç¿Í¹©ÃÎǽ¤¦¤ó¤Ì¤ó¤Èʹ¤¤¤¿¡£¥È¥ì¥ó¥É¥Þ¥¤¥¯¥í¼Ò¤Ï¼Â¤Ï°ÊÁ°¤«¤é£Á£É¤Ï»È ¤Ã¤Æ¤­¤¿¤È¸À¤¦¡¢¹¹¤Ë XGen ¤È¤¤¤¦¿·¶¯¤¤£Á£Éµ»½Ñ¤òÅêÆþ¤¹¤ë¡£ ÃíÌÜ¤Ï CylancePROTECT¡¢ ¥¨¥ó¥É¥Ý¥¤¥ó¥È¤Ç̤ÃΤΥޥ륦¥§¥¢¤ò¸¡½Ð¤¹¤ë£Á£ÉÍøÍѤΥ½¥Õ¥È¡¢¥¢¥á¥ê¥« Cylance¼Ò¤¬ ³«È¯¡¢2016/08/24 ¤ËÆüËÜË¡¿Í¤òÀßΩ¡¢¥¯¥é¥¦¥ÉÍøÍѤʤ·¤Ç¤â£Ï£Ë¡£ * ¥È¥ì¥ó¥É¥Þ¥¤¥¯¥í¤Î IMSS ¤Ë¿Í¹©ÃÎǽµ»½ÑÅëºÜͽÄê 2017ǯ3·î29Æü¡¢Ë¡¿Í¸þ¤±»ö¶ÈÀïά¤òȯɽ¡£"Àè¿Êµ»½Ñ¤È¹â¤¤¼ÂÀÓ¤òÍ»¹ç¤·¤¿Ëɸ楢¥×¥í¡Ý ¥Á¡ÖXGen¡×" ¤È¥Ñ¡Ý¥È¥Ê¡Ý¶¨¶È¤Ë¤è¤êÉý¹­¤¤¸ÜµÒ´Ä¶­¤ËºÇŬ¤Ê¥»¥­¥å¥ê¥Æ¥£¥½¥ê¥å¡Ý¥·¥ç ¥ó¤òÄ󶡡£¼ç¤Ë£Á£Éµ»½Ñ¤È¥µ¥ó¥É¥Ü¥Ã¥¯¥¹Ï¢·È¤Ë¤è¤ëÀ½Éʳ«È¯¤Ï°Ê²¼¤Î¤è¤¦¤À¤Ã¤¿¡£ [ 2017¾åȾ´ü ] Trendo Micro Deep Security 10 TippingPoint Cloud Edge 5.0 ¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¥³¡Ý¥Ý¥ì¡Ý¥È¥¨¥Ç¥£¥·¥ç¥ó XG << ¤³¤ì¤Ï´ë¶È¸þ¤±¤Ç¥µ¡Ý¥Ð¤òΩ¤Æ¤ë ¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¥Ó¥¸¥Í¥¹¥»¥­¥å¥ê¥Æ¥£¥µ¡Ý¥Ó¥¹ ɬÍפ¬¤¢¤ë¡£ Trendo Micro Cloud App Security [ 2017²¼È¾´ü ] Trendo Micro Deep Security 10 Deep Discovery Inspector ¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¥³¡Ý¥Ý¥ì¡Ý¥È¥¨¥Ç¥£¥·¥ç¥ó XG Trend Micro Hosted Email Security InterScan Web Security as a Service << ¤³¤ì¤é¤ò¹¹¤ËÄ´¤Ù¤ë¤³¤È¡£¤É¤¦¤â InterScan Messaging security << ǯËö¤«¤éÍèǯ¤Ë¤«¤±¤Æ½Ð¤Æ¤­¤½¤¦¡£ £²£°£±£·Ç¯£´·î£²£±Æü¤Ë̾¸Å²°¤Ç¥»¥ß¥Ê¡Ý¤¬¤¢¤Ã¤¿¡£¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý Corp. XG ¥»¥­¥å ¥ê¥Æ¥£¶¯²½¼ÂÁ©½Î¡£½Ð¤Ê¤«¤Ã¤¿¤±¤É¡£2017ǯ9·î7Æü¡¢Àè¿Ê¤Î£Á£Éµ»½Ñ¤òÍ»¹ç¤·¤µ¤é¤Ë¶¯¤¯ ¡Ö¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¡×¥·¥ê¡Ý¥ººÇ¿·ÈǤòȯÇä¡¢¡ÁXGen¥¢¥×¥í¡Ý¥Á¤Ç̤ÃΤζ¼°Ò¤Ø¤ÎËɸæÎÏ ¤ò¶¯²½¡Á¡£¥³¥ó¥·¥å¡Ý¥Þ¸þ¤±¡Ö¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¡×¥·¥ê¡Ý¥º¤ÎºÇ¿·ÈǤˤâƳÆþ¤¹¤ë¡£¥¦¥£ ¥ë¥¹¥Ð¥¹¥¿¡Ý¥¯¥é¥¦¥É¡£¼«Âð¤Î¥Ñ¥½¥³¥ó¤Ç¹ØÆþ¤·¤Æ¤¤¤ë¡£¿·¤·¤¯ Windows 10 ÅëºÜ¤Î¥Î¡Ý ¥È¥Ñ¥½¥³¥ó¤òÇã¤Ã¤¿¤È¤³¤í¡£¤³¤ì¤òÉáÃʻȤ¤¤Ë¤·¤Æ¤³¤Î¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¤òÆþ¤ì¤Æ¤ß¤è¤¦¡£ * ¥È¥ì¥ó¥É¥Þ¥¤¥¯¥í¤Î IMSS ¤Ç¤Î¥Æ¥¹¥È¤ò¸¡Æ¤¤·¤è¤¦ ¤È¤â¤«¤¯¥¤¥ó¥¹¥È¡Ý¥ë¤Ç¤­¤ë IMSS ¤òÆ©²á·¿¤ÇÀßÃÖ¤·¤Æ¤ß¤ë¡£¥á¡Ý¥ë¥µ¡Ý¥Ð¤òÆ©²á·¿¤ÇÀß ÃÖ¤·¤¿¤³¤È¤¬¤Ê¤¤¡£¥¤¥á¡Ý¥¸¤¬Í¯¤«¤Ê¤¤¡£¤É¤ó¤Ê°ÄÇۤˤʤë¤Î¤«¡£À褺¤Ï¤³¤Î¸¡Æ¤¤«¤é¤À¡£ ¸í¸¡ÃΤ·¤¿¥á¡Ý¥ë¤Ï¤É¤¦¤¹¤ë¤Î¤«¡¢¤É¤¦¤Ê¤ë¤Î¤«¡£¸¡ÃΤÎÍ­¸úÀ­¤òÄ´¥Ù¤ë¤Î¤Ï¡¢¤È¤ê¤¢¤¨ ¤º¥Ñ¥½¥³¥óÍѤΥ¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¤Ç¤Ç¤­¤ë¡£¥Ñ¥½¥³¥ó¤Ê¤É»ÈÍѥ饤¥»¥ó¥¹¤Ï³Î¤«£³Â椢¤ë¡£ £±Âæ¤ò²ñ¼Ò¤Î¥Ñ¥½¥³¥ó¤Ë¤·¤Æ¤â¤¤¤¤¡¢¥¹¥Þ¡Ý¥È¥Õ¥©¥ó¤Ï»ý¤Ã¤Æ¤Ê¤¤¤·¡£ ¥Æ¥¹¥ÈÍѤΠIMSS ¤Ï²¾ÁÛ¥Þ¥·¥ó¤Ë°ÊÁ°¡¢Æ³Æþ¥Æ¥¹¥È¤Ëºî¤Ã¤¿¤Î¤¬¤¢¤ë¤«¤âÃΤì¤Ê¤¤¡£¤ß¤Æ¤ß¤è¤¦¡£ £²£°£°£¸Ç¯¤Î¥È¥ì¥ó¥É¥Þ¥¤¥¯¥í¤Î»ñÎÁ¤ò¤ß¤¿¤éÀßÃÖÊýË¡¤ËÆ©²á·¿¤Ï¤Ê¤«¤Ã¤¿¡££²£°£±£·Ç¯ ¤Ç¤âÊѤï¤Ã¤Æ¤Ê¤¤¤è¤¦¤Ç¤¢¤ë¡£»ñÎÁµ­ºÜ¤Î "³°Éô£Í£Ô£Á/ÆâÉô£Í£Ô£Á¥µ¥ó¥É¥¤¥Ã¥Á¹½À®"¤¬ »È¤¨¤½¤¦¡£¥á¡Ý¥ë¥ê¥ì¡Ý¤È¥á¡Ý¥ë¥¹¥È¥¢¤Î´Ö¤Ë¤³¤ì¤òÃÖ¤¯¡£ÅºÉÕ¥Õ¥¡¥¤¥ëÉÕ¤­¤Î¥á¡Ý¥ë¤ò £Á£É¤Ç¥Á¥§¥Ã¥¯¤µ¤»¤Æ¡¢ ¹õ¤ÈȽÄꤷ¤¿¤Ê¤é¥á¡Ý¥ë¤Î·ï̾¤Ë Spam ¤Ç¤â Trend ¤Ç¤â²¿¤«¼± ÊÌʸ»ú¤òÆþ¤ì¤ë¡£¥á¡Ý¥ë¤¬¥á¡Ý¥ë¥¹¥È¥¢¤ËÍ褿¤È¤³¤í¤Ç¡¢¤³¤Î·ï̾¤ò¸«¤Æ¥·¥¹¥Æ¥à³ÖÎ¥¤Ë ¤Û¤¦¤ê¤³¤à¡£·ï̾¤Ëʸ»ú¤òÆþ¤ì¤ë¤Î¤Ï¸Å¤¤ IMSS ¤Ç¤â¤Ç¤­¤ë¡¢¤³¤ì¤Ç¥Æ¥¹¥È¤·¤è¤¦¡£ MR ¢« AI ¢« MS MR ¤Ï¤³¤Ê¤¤¤À¤Þ¤Ç²ÔƯ¤·¤Æ FortiMail ¤ËÃÖ¤­´¹¤¨¤¿¥Þ¥· ¢¢ ¢ª ¢¢ ¢ª ¢¢ ¥ó¤Î Sun ¤« Cobalt Qube3¡¢ ¤¢¤ë¤¤¤Ï Windows ¤Î¥á¡Ý¥ë ¡Ã ¡Ã ¡Ã ¥½¥Õ¥È¡£MS ¤ÏͽÈ÷µ¡¤Î FortiMail-200D ¤Ç³ÎÄê¡£AI ¤Î¤Ï ------------------------- ²¾ÁÛ¥Þ¥·¥ó¤ò»È¤¦»ö¤Ë¤Ê¤ë¤«¤Ê¡¢¤¢¤ë¤¤¤ÏÀè¤Î Sun ¤«¡£ °ÂÁ´¤Ë´Ø¤¹¤ëÁõÃÖµ¡´ï¤Ï²¾ÁÛ¥Þ¥·¥ó¤Ï»È¤ï¤Ê¤¤¤³¤È¤Ë¤·¤è¤¦¤«¡£¤Ê¤é¤ÐñÂΤÎãþÂΤòÍѤ¤ ¤ëÌõ¤À¤¬ Sun ¤Ï¤â¤¦Çä¤Ã¤Æ¤Ê¤¤¡£ ̵Ää»ß¥µ¡Ý¥Ð¤È¤·¤ÆÀΤ«¤éÄêɾ¤Î¤¢¤ë ftServer ¤Ï¤É ¤¦¤«¡£¤¶¤Ã¤ÈÄ´¤Ù¤¿¤È¤³¤í£±£´£°Ëü±ß¤°¤é¤¤¤«¤é¤ß¤¿¤¤¡£¥µ¥¤¥º¤Ï£²£Õ¡£¤«¤Ä¤Æ¤Ï¿ôÀéËü ±ß¤·¤Æ¤¤¤¿¡£ÆâÉôŪ¤Ë£²½Å²½¤Ë¤Ê¤Ã¤Æ¤¤¤Æ£Ï£Ó¤Ï£±¤Ä¡£¾å¿Þ¤Î AI ¤Î½ê¤ËÀßÃÖ¤¹¤ë¡£ ¸¡Æ¤¤·»Ï¤á¤¿¤È¤­¡¢Æ©²á·¿¤Ë¥Þ¥·¥ó¤òÀßÃÖ¤¹¤ë»ö¤Ë¤Ê¤ë¤À¤í¤¦¤È»×¤Ã¤¿¡£²¾ÁÛ¥µ¡Ý¥Ð¤Îãþ ÂΤËÆ©²á·¿¤Ç²¾ÁÛ¥Þ¥·¥ó¤òºî¤ë¡£¤³¤³¤Ç£²¤Ä¤Î¥Ý¡Ý¥È¤¬¤¤¤ë¤Î¤À¤¬¡¢¤½¤Î¥¤¥á¡Ý¥¸¤â¤µ¤Ã ¤Èͯ¤«¤Ê¤«¤Ã¤¿¡£¤½¤ì¤â¤¢¤Ã¤Æ²¾ÁÛ¥Þ¥·¥ó¤Ï»È¤ï¤Ê¤¤¤È¹Í¤¨¤¿¡£¤Ç¤âÆ©²á·¿¤Ç¤Ê¤¤Ä̾ï¤Î ÀßÃ֤Ȥ¤¤¦¤³¤È¤¬Ê¬¤«¤Ã¤Æ¡¢²¾ÁÛ¥Þ¥·¥ó¤Ç¹½¤ï¤Ê¤¤¤Î¤Ç¤Ê¤¤¤«¤È¹Í¤¨Ä¾¤·¤Æ¤¤¤ë½ê¤Ç¤¢¤ë¡£ ¼ÂºÝ¤ÎÀßÄ걿ÍѤǤϤǤ­¤ì¤ÐźÉÕ¥Õ¥¡¥¤¥ë¤ò¡¢¤È¤Ã¤Æ¤â²ø¤·¤¤¥á¡Ý¥ë¤Î¤ß¤ò¥Á¥§¥Ã¥¯¤¹¤ë ¤È¤¤¤¦¤³¤È¤Ë¤Ç¤­¤Ê¤¤¤«¡£¤È¸À¤¦¤Î¤Ï¥á¡Ý¥ë¤Ï½ÐÍè¤ë¤À¤±Â®¤ä¤«¤ËÄ̲ᤵ¤»¤¿¤¤¤«¤é¤Ç¤¢ ¤ë¡£Á´Éô¤ÎźÉÕ¥Õ¥¡¥¤¥ëÉÕ¤­¥á¡Ý¥ë¤ò¥Á¥§¥Ã¥¯¤·¤Æ¤¤¤Æ¤Ï»þ´Ö¤¬¤«¤«¤ë¤Î¤Ç¤Ê¤¤¤«¤È¤¤¤¦ »ö¤Ç¤¢¤ë¡£¥á¡Ý¥ë¥¹¥È¥¢¤Ç¤Ï¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤Î¥Á¥§¥Ã¥¯¤Ï¹Ô¤Ê¤Ã¤Æ¤¤¤ë¤·¡£ ¥á¡Ý¥ë¥ê¥ì¡Ý¤ò¤³¤Ê¤¤¤À Sun ¤Î¥Þ¥·¥ó¤«¤é FortiMail ¤ËÃÖ¤­´¹¤¨¤Æ¡¢³°Éô¤Î¥á¡Ý¥ë¥µ¡Ý ¥Ð¤È¤Ï°Å¹æ²½¤¹¤ë¤³¤È¤Ë¤·¤¿¡£ ¥á¡Ý¥ë¥¹¥È¥¢¤Î FortiMail ¤È¤Ï°Å¹æ²½¤·¤Ê¤¤¤è¤¦¤Ë¤·¤¿¡£ ¤³¤Î´Ö¤ò°Å¹æ²½¤·¤Æ¤·¤Þ¤¦¤È¡¢¤³¤Î¥×¥é¥ó¤ÏºÎ¤ì¤Ê¤¤¤È¤³¤í¤À¤Ã¤¿¡£É¸Åª·¿¥á¡Ý¥ëÂкö¤Ç ¥á¡Ý¥ë¤Î̵³²²½¤ò¤ä¤ë¾ì¹ç¤â¡¢¤³¤Î¤è¤¦¤ËÁõÃÖ¤ò¥µ¥ó¥É¥¤¥Ã¥Á¤Ë¤¹¤ë¤È¤¤¤¦¡£ ¤È¤ê¤¢¤¨¤º Windows 7 ¤Î¥Ñ¥½¥³¥ó¤Ë¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¤Î¤ª»î¤·ÈǤòÆþ¤ì¤Æ¤ß¤è¤¦¡£ £³£° Æü´Ö¤Î̵ÎÁÂθ³ÈǤ¬¤¢¤ë¡£ ¼«Ê¬°¸¤Æ¤Î¥á¡Ý¥ë¤Ç FortiMail ¤Ç¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤·¤Æ¤Ê¤¯ ¤Æ Outlook ¤Ø¡¢aaa@nix.co.jj ¥á¡Ý¥ë¡£ ¥Ñ¥½¥³¥ó¤Î¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¥½¥Õ¥È¤Ç¥Á¥§¥Ã¥¯ ¤µ¤ì¤ë¡££×£å£â¥á¡Ý¥ë¤Ë¤ÏÀ¸¤Î¤Þ¤Þ¤ÇÍ­¤ë¡¢¤³¤ì¤ò¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¤Ç¥Á¥§¥Ã¥¯¤¹¤ë¡£ * ºÆ¤Ó InterScan ¤Ç¥á¡Ý¥ë¤Î¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤ò¤ä¤é¤»¤ë¤« ²¾ÁÛ¥Þ¥·¥ó¤âº£»þ¤Î¤ò²þ¤á¤ÆÍÑ°Õ¤·¤Ê¤¤¤È °ÊÁ°¤ËÇã¤Ã¤¿ OpenBlockS ¤Ëº£¤Î InterScan IMSS ¤ò¥¤¥ó¥¹¥È¡Ý¥ë¤Ç¤­¤Ê¤¤¤«¡£ Æȼ«£Ï£Ó¤Î¤¿¤á InterScan ¤¬Âбþ¤·¤Æ¤¤¤Ê¤¤¤Î¤Ç¥¤¥ó¥¹¥È¡Ý¥ë½ÐÍè¤Ê¤¤¡£ º£¤Î InterScan ¤ò¥¤¥ó¥¹¥È¡Ý¥ë¤¹¤ëÍ×·ï À½ÉÊ̾¤Ï InterScan Messaging Security¡£Red Hat Enterprise Linux 6 ¤È 7¡£ ¥È¥ì¥ó¥É¥Þ¥¤¥¯¥í¤Î¥é¥¤¥»¥ó¥¹¤Î¤³¤È¤Ï rinne5.txt ¤ÎÉÕÏ¿¤Ë½ñ¤¤¤¿¡£ InterScan7.1 ¤Î Readme ¤Î¤á¤Ü¤·¤¤µ­½Ò¤ò°Ê²¼½¦¤Ã¤¿¤Î¡£Red Hat ¾å¤Î SELinux ¤Ë¤Ï¥¤ ¥ó¥¹¥È¡Ý¥ë¤Ç¤­¤Ê¤¤¡£(Security-Enhanced Linux)¡£ÍÑ°Õ¤·¤¿ Red Hat Enterprise Linux ¤Ï²¾ÁÛ¥Þ¥·¥ó¤Î RHEL/5.6¡£²ÔƯÃæ¤Î¥Þ¥·¥ó¤Ë telnet ¤·¤Æ½Ð¤¿¤Î¤Ï Red Hat Enterprise Linux Server release 5.6 (Tikanga)¡¢Kernel 2.6.18-238.el5PAE on an i686 ¤À¤Ã¤¿¡£ * ¤â¤Ï¤ä¿Í¹©ÃÎǽ¤Ç¤âËɤ°¤Î¤Ï̵Íý ¥µ¥ó¥É¥Ü¥Ã¥¯¥¹¤¬¶¯ÎÏ¥¦¥£¥ë¥¹¤Ç¤¢¤ë£°£Ä£á£ù¥¦¥£¥ë¥¹¡¢¥Þ¥ë¥¦¥§¥¢¡¢¥é¥ó¥µ¥à¥¦¥§¥¢¤Ø ¤ÎºÇ¸å¤ÎºÖ¤Ë¤Ê¤ë¤È´üÂÔ¤·¤¿¡£¤·¤«¤·½êÁ§Windows £Ï£Ó¤ò¥¨¥ß¥å¥ì¡Ý¥·¥ç¥ó¤·¤Æ¤Î¥Á¥§¥Ã ¥¯¤Ç¤¢¤ë¡£Windows £Ï£Ó¤ÏŨ¤Î¼ê¤Ë¤â¤¢¤Ã¤Æ½½Ê¬¤Ê²òÀϤ¬¹Ô¤Ê¤ï¤ì¡¢ÀȼåÀ­¤Îȯ¸«¤¬¤Ê¤µ ¤ì¤Æ¤¤¤ë¤ÈÁÛÄê¤Ç¤­¤ë¡£¥µ¥ó¥É¥Ü¥Ã¥¯¥¹µ¡Ç½¤ò²óÈò¤¹¤ë¥Þ¥ë¥¦¥§¥¢¤¬½Ð¸½¤·¤Æ¤¤¤ë¤È¸À¤¦ ¥Ë¥å¡Ý¥¹¤Ï£±Ç¯¤°¤é¤¤Á°¤«¤é¸À¤ï¤ì»Ï¤á¤Æ¤¤¤ë¡£¤½¤ì¤ÈÁê¤Þ¤Ã¤Æº£Å٤Ͽ͹©ÃÎǽ¤Ç¸¡ÃΤ¹ ¤ëÀ½Éʤ¬¤Ç¤Æ¤­¤¿¡£¤·¤«¤·¤½¤ì¤µ¤¨¤â̵Îϲ½¤µ¤ì¤ë¶²¤ì¤¬½Ð¤Æ¤­¤¿¡£ ¥Þ¥ë¥¦¥§¥¢¤ÎÊý¤â¿Í¹©ÃÎǽ¤Ç¶¯ÎÏ¥¦¥£¥ë¥¹¤òÀ¸À®¤·¤è¤¦¤È¤·¤Æ¤¤¤ë¡£ a)¥»¥°¥á¥ó¥È¤ÎºÆÀ߷פȸ«Ä¾¤· ¶âÍ»¶È¤Ï¥Í¥Ã¥È¥ï¡Ý¥¯¤Ï¥»¥°¥á¥ó¥È²½¤·¤Æ£Õ£Ô£Í¤ÇʬΥ¡£ À½Â¤¶È¤Ï IoT ¥»¥°¥á¥ó¥È¤ò ʬΥ¤¹¤ë¤³¤È¡£Ìò½ê¤ÏÀ¸»ºÀ­¤ò¹Í¤¨¤Ê¤¤¤Î¤Ç½ÅÍ×¾ðÊó¤È¤Ï´°Á´¤ËʬΥ¤·¤Æ¤¤¤ë¡£ b)¥Í¥Ã¥È¥ï¡Ý¥¯¤Î²Ä»ë²½¤ÏɬÍ× FortiGate ¤ÎºÇ¿·µ¡Ç½¤ËÅëºÜ¤Î FortiSIEM¡¢"FortiView Physical Topology" ¤Ç¿Þ¤¬½Ð ¤ë¡£¤³¤ì¤ò¥·¡Ý¥à¤È¤¤¤¦¤é¤·¤¤¡£FortiSIEM ¤Ï Cisco ¤Î¥¨¥ó¥¸¥Ë¥¢¤¬¼­¤á¤Æºî¤Ã¤¿¡£ c)¹¶·â¤ÏËɤ®ÀÚ¤ì¤Ê¤¤»ö¤¬Á°Äó £±¤Ä¤Ï CSIRT¤òÀ°È÷¤¹¤ë¤³¤È¡£¤â¤¦£±¤Ä¤Ï¤ä¤ì¤ë¤À¤±¤ÎËɸ档¤½¤ì¤Ë¾ðÊó¤ÎÊݸî¤òÃÀ¤Ë¡£ CSIRT ¤Ï»ö¸Î¤¬µ¯¤³¤Ã¤¿ºÝ¤Ë¡¢À褺¤Ï´ë¶È¥¤¥á¡Ý¥¸¤Î¥À¥¦¥ó¤ò¤Ç¤­¤ë¤À¤±¾®¤µ¤¯¤¹¤ë¡£ * ºÇ¸å¤ÎºÖ¤ÏÆüì¥Õ¥¡¥¤¥ë¥µ¡Ý¥Ð¤Ç ¾ðÊóÇ˲õ¤Ë¤Ï¥é¥ó¥µ¥à¥¦¥§¥¢¤Î¿Í¼Á¹¶·â¤Ë¤è¤ë¥Õ¥¡¥¤¥ë¤Î°Å¹æ²½¤¢¤ë¤¤¤Ï¾ðÊó¤Î¾Ãµî¡£Åû ¾õ¤Ë¤Ê¤Ã¤¿¤¦¤Ê¤®³Í¤ê¤Î¤è¤¦¤Ê¹½Â¤¤ÎÆüì¤Ê¥Õ¥¡¥¤¥ë¥µ¡Ý¥Ð¤Ï¤É¤¦¤«¡£¤³¤ì¤Ë¼ÒÆâ¤Î¾ðÊó ¤òÊݴɤ·Êݸ¤ë¤Î¤Ç¤¢¤ë¡£¥Ç¡Ý¥¿¤¬Ç˲õ¤µ¤ì¤¿¤ê¾Ãµî¤µ¤ì¤¿¤ê¤·¤¿¤é¶È̳¤Î·Ñ³¤¬¤Ç¤­ ¤Ê¤¯¤Ê¤ë¡£»ö¶È·Ñ³À­¤Î³ÎÊݤ¬°ìÈÖ¤ÎÂкö¤Ë¤Ê¤ë¤È»×¤¦¡£ ¥¦¥£¥ë¥¹¤¬Æþ¤Ã¤Æ¤­¤Æ¤â´¶À÷¤·¤Ê¤¤¥Õ¥¡¥¤¥ë¥µ¡Ý¥Ð¡£ºÇ¾®¸Â¤Î¥Õ¥¡¥¤¥ëžÁ÷¤ò¤¹¤ëµ¡Ç½¤À ¤±¤â¤Ã¤¿£Ï£Ó¤òÅëºÜ¤¹¤ë¡£À¤¤ÎÃæ¤Ë¤¢¤ë¤Î¤«¤Ê¡£¤Ê¤¯¤Æ¤â¤¹¤°¤Ëºî¤ì¤ë¤Î¤Ç¤Ê¤¤¤«¡£»÷¤¿ ¤è¤¦¤Ê¤Î¤Ç AUSPEX¡¢¤³¤ì¤ÏÀΤ«¤é¤¢¤ëÀìÍÑ¥Õ¥¡¥¤¥ë¥µ¡Ý¥Ð¤ÇÆȼ«³«È¯¤Î£Ï£Ó¤Ç¤¢¤ë¡£ ¥Õ ¥©¥ì¥ó¥¸¥Ã¥¯¥µ¡Ý¥Ð¤âÀ½Éʤò½Ð¤·¤Æ¤¤¤ë¥á¡Ý¥«¤ÎÆȼ«³«È¯¤Î£Ï£Ó¤Ç¤Ê¤¤¤«¡£ Fortinet ¼Ò¤µ¤ó¡¢¤³¤ó¤ÊÁõÃÖ¤òºî¤Ã¤Æ²¼¤µ¤¤¡£PFS( Protected File Server ) ¤Ê¤ëÊÝ¸î ¥Õ¥¡¥¤¥ë¥µ¡Ý¥Ð¤Î¤Ç¤¢¤ë¡££²£°£±£·Ç¯£±£°·î£±£¸Æü»×¤¤ÉÕ¤¤¤¿¡¢¤½¤Î³¨¤Ï²¼µ­¤ËÉÁ¤¤¤Æ¤ª ¤¤¤¿¡£"18-2.¥Í¥Ã¥È¥ï¡Ý¥¯¡¦¥»¥ë¤Î¹Í¤¨Êý,(1)¥Í¥Ã¥È¥ï¡Ý¥¯´ÉÍýñ°Ì¤ÎÀß·×"¡£ ¥Õ¥¡¥¤¥ë žÁ÷¤Ë¤Ï CIFS/NFS/FTP/SSH ¤È¤«¤¢¤ë¡£Windows ¤Î¥Õ¥©¥ë¥À¤Ç¤Ï¤Ê¤¤ FTP/SSH¤¬¥Ù¡Ý¥¹¤«¡£ ÉôÌçÍѤÈÁ´¼ÒÍÑ¡£ÉôÌçÍѤϾ®·¿¤Î¥¢¥×¥é¥¤¥¢¥ó¥¹¡£Á´¼ÒÍѤÏÂç·¿¤Î¥¢¥×¥é¥¤¥¢¥ó¥¹¤òÀßÃÖ ¤¹¤ë¡£Á´¼ÒÍѤÏÉôÌçÍѤΥǡݥ¿¤òµÛ¤¤¾å¤²¤ÆÊݸ¤¹¤ë¡£¼ÒÆâ¤Î³Æ¥Ñ¥½¥³¥ó¤Ç¥æ¡Ý¥¶¤¬ºîÀ® ¤¹¤ë¥Õ¥¡¥¤¥ë¤Î¥Õ¥©¥ë¥À¤ò·è¤á¤Æ¤ª¤¯¡¢ ¤½¤³¤Î¥Õ¥¡¥¤¥ë¤òÂоݤˤ·¤Æ PFS ¤Ë¥³¥Ô¡Ý¤¹¤ë¡£ ¤È¤³¤í¤ÇÊݸ¤ÈÊݴɤΰ㤤¤Ï¡©¡¢´ÉÍý¤òȼ¤¦¤Î¤òÊÝ´É¡¢¤½¤¦¤Ç¤Ê¤¤¤Î¤¬Êݸ¤Ç¤·¤¿¡£ * ¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¤Ç£Á£É¤ÎǽÎϤòÄ´¤Ù¤Æ¤ß¤è¤¦¤Ç¤Ê¤¤¤« Mail-Store ¤Ë¤Æ ikken@nix.co.jj °¸¤ËÍ褿¥á¡Ý¥ë¤Ï¥¨¥¤¥ê¥¢¥¹¤Ç¡¢test1@nix.co.jj ¤Ë ¤âÁ÷¤ë¡£ikken@nix.co.jj ¤Ø¤Ï¥¹¥Ñ¥à¥Á¥§¥Ã¥¯¤Î¤ß¤ä¤ë¡£test1@nix.co.jj ¤Ï¥¹¥Ñ¥à¥Á¥§ ¥Ã¥¯¤È¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤ò¤ä¤ë¡£ ikken ¤ÇÈ´¤±¤¿Í褿¥á¡Ý¥ë¤¬ test1 ¤Ç¥¦¥£¥ë¥¹¸¡ÃΤµ ¤ì¤¿¤«¡¢¤µ¤ì¤Ê¤«¤Ã¤¿¤«¡£¥¦¥£¥ë¥¹¸¡ÃΤµ¤ì¤Ê¤«¤Ã¤¿¤«¥á¡Ý¥ë¤ò¥È¥ì¥ó¥É¥Þ¥¤¥¯¥í¤Î£Á£É ¥Á¥§¥Ã¥¯ÍѤθ¡ÂΤȤ¹¤ë¡£ ÉáÃʻȤ¤¤È¤ÏÊ̤Υƥ¹¥ÈÍѤΥѥ½¥³¥ó¤Î Outlook ¤Ç¤³¤Î¥á¡Ý ¥ë¤ò¼èÆÀ¤¹¤ë¡£¥Æ¥¹¥ÈÍѥѥ½¥³¥ó¤Ë¤Ï¥¦¥£¥ë¥¹¥Ð¥¹¥¿¡Ý¤ò¥¤¥ó¥¹¥È¡Ý¥ë¤·¡¢Àè¤Ë¥¦¥£¥ë¥¹ ¥Á¥§¥Ã¥¯¥½¥Õ¥È¤òÆþ¤ì¤Æ¤¤¤¿¤é¤½¤ì¤Ï¾Ã¤¹¤Ê¤ê̵¸ú¤Ë¤¹¤ë¤Ê¤ê¤¹¤ë¡£¤½¤ì¤Ç¥¦¥£¥ë¥¹¥Ð¥¹ ¥¿¡Ý¤Ç£Á£É¥Á¥§¥Ã¥¯¤ò¤ä¤Ã¤Æ¸¡ÃΤµ¤ì¤ì¤Ð¡¢¿Í¹©ÃÎǽ¤ÎÍ­ÍÑÀ­¤¬¾ÚÌÀ¤µ¤ì¤¿¤È¤¤¤¦¤³¤È¤Ë ¤Ê¤ë¡£ÌäÂê¤Ï¸¡ÂΤ¬ÌÇ¿¤Ë½Ð̵¤¤¤³¤È¡£`2h/11/m»þÅÀ¡¢Ãæ¹ñ¤ÎÂ礭¤ÊÂç²ñ¤¬½ª¤ï¤Ã¤¿¤»¤¤ ¤« FortiMail ¤Ç¤Î¥Á¥§¥Ã¥¯¤Ï°ÂÄꤷ¤Æ¤¤¤Æ¡¢£³Æü¤Ë°ìÄÌÄøÅÙ¤·¤«¤¹¤êÈ´¤±¥á¡Ý¥ë¤Ï¤Ê¤¤¡£ (3) FortiGate ¥Õ¥¡¥¤¥ë¥¢¥¯¥»¥¹¹â®²½ -------------------------------------------------------------------------------- ¤³¤ì¤Þ¤Ç£×£Á£Æ£ÓÀ½ÉʤòÄ´¤Ù¤Æ¸¡Æ¤¤ò¤·¤¿¤³¤È¤Ï£²Å٤ۤɤ¢¤ë¡£¤·¤«¤·¥Æ¥¹¥È¤Ï¤·¤¿¤³¤È ¤¬¤Ê¤¤¡£¤É¤¦¤ä¤Ã¤Æ»È¤¦¤Î¤«¡£ÀßÄê¤Î´ðËÜŪ¤Ê¤³¤È¤âÃΤé¤Ê¤¤¤Î¤Ç¡¢¤½¤³¤«¤é¼è¤êÁÈ¤Þ¤Ê ¤¤¤È¡£µîǯ½Ð¤¿ FortiGate ¤ÎËܤ˲¿¤«½ñ¤¤¤Æ¤Ê¤¤¤«¡£»ÄÇ°¡¢µ­½Ò¤Ï¤¢¤ê¤Þ¤»¤ó¤Ç¤·¤¿¡£ -------------------------------------------------------------------------------- * ¸¡Æ¤¥á¥â BlueCoat ¤È Steelhead À½ÉʤΥޥ˥奢¥ë¤È¤«ÀßÃÖÀßÄê¤Î»öÎã¤È¤«¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ë¤Ê¤¤ ¤«¡£http://www.jdsf.gr.jp/pdf/dse2007/09.pdf "¤³¤ì¤«¤é¤Î£×£Á£ÎºÇŬ²½¥½¥ê¥å¡Ý¥·¥ç ¥ó ¡ÁSteelhead ¤Ç°ìÊâÀè¤Î£×£Á£ÎºÇŬ²½¡Á" (³ô)¥Í¥Ã¥È¥Þ¡Ý¥¯¥¹¤ÎºîÀ®»ñÎÁ¡£Steelhead ¤Ï WAFS( Wide Area File Services ) ¤òĶ¤¨¤¿ WDS( Wide-area Data Services )¤òÄ󶡡£ BlueCoat ¤Ï¤Û¤È¤ó¤É½Ð¤Æ¤Ê¤¤¤Î¤Ç¤Ê¤¤¤«¡£¤ä¤Ï¤ê Steelhead ¤¬Ï·Êޤǽв٤Ï¿¤¤¡£ 2009/04/22 FortiOS 4.0 ¤òȯɽ¡£SSLÄÌ¿®¤ò²òÀϤ¹¤ë SSL¥¤¥ó¥¹¥Ú¥¯¥·¥ç¥ó¡¢DLP(¾ðÊóϳ ±ÌËÉ»ß)¡¢£×£Á£Î¹â®²½(WAFS)¤Ê¤ÉÉé²Ùʬ»¶¤ò½ü¤¯Á´ÉôÆþ¤ê¤Î£Ï£Ó¤ò»ÅΩ¤Æ¤¿¡£SSL¥¤¥ó¥¹ ¥Ú¥¯¥·¥ç¥ó ¤Ï SSL °Å¹æ²½ÄÌ¿®¤òÄ´¤Ù¤ë¤¿¤á¡¢SSL¤ò¤¤¤Ã¤¿¤ó½ªÃ¼¤·¤ÆÉü¹æ/°Å¹æ²½¤ò¤¹¤ë¡¢ ¤³¤ì¤Ë¤Ï SSL ¥¢¥¯¥»¥é¥ì¡Ý¥¿µ¡Ç½¤ò¤â¤ÄÀìÍÑ¥×¥í¥»¥Ã¥µ FortiASIC CP6 ÅëºÜ¥â¥Ç¥ë¤ÇÂÐ ±þ¤¹¤ë¡£WAFS ¤Ê¤É FortiOS 4.0 ¤Î¿·µ¡Ç½¤ÏÄɲå饤¥»¥ó¥¹ÉÔÍפÇÍøÍѤǤ­¤ë¡£ FortiOS Handbook WAN Optimization,Web Cache,Explicit Proxy,and WCCP for FortiOS 5.0¡¢±Ñʸ¥É¥­¥å¥á¥ó¥È¤¢¤ê¡¢£±£¶£´¥Ú¡Ý¥¸¤â¤¢¤ë¡¢¤¶¤Ã¤È¤ß¤¿¤±¤Éʬ¤«¤é¤ó¡£YouTube¤Ë FortiGate Cookbook - Explicit Proxy(5.2)¤ÏÀßÄê¤ÎÍͻҤ¬¤¢¤ë¤¬¡¢²èÌ̤¬¾®¤µ¤¯¤Æ¤è¤¯ ʬ¤«¤é¤Ê¤¤¡£ ¥Í¥Ã¥È¤«¤é¸«¤Ä¤±¤¿¤Î¤Ç¡¢WAN Optimization ¤Ï£´¤Ä¤Î¥Æ¥¯¥Ë¥Ã¥¯¤¬ÍøÍÑ¤Ç ¤­¤ë¡£Protocol Optimization¡¢Byte Caching¡¢Web Caching¡¢Transparent proxy¡£ * £×£Á£Æ£ÓÁõÃÖ¤ÎÀßÃ֥ѥ¿¡Ý¥ó PC HTTP ¤³¤ì¤¬ WAFS ¤Î¥ª¡Ý¥½¥É¥Ã¥¯¥¹¤Ê¹½À®¡£Æ©²á ¢¤ HTTP ---> ¢¢Web ·¿¤Ç£²¤ÄÀßÃÖ¡£ÁõÃÖ¤òÄ̲᤹¤ë¥Ñ¥±¥Ã¥È¤ËÂÐ ¡Ã FG2 ---> FG1 ¡Ã ¤·¤ÆWAFS¤ÎÁàºî¤¹¤ë¡£ -----¢£---||¡Ä¡Ä¡Ä¡Ä||--¢£------------ PC Proxy HTTP PC ¤Î¥Ö¥é¥¦¥¶¤Î¥×¥í¥­¥·»ØÄê¤Ï FG1¡£FG1¤È ¢¤ HTTP FG1¢£ ---> ¢¢Web ¤È FG2 ¤Î´Ö¤Ç WAFS ¤¬Æ¯¤¯¡£ ¡Ã FG2 ---> ¡Ã ¡Ã -----¢£---||¡Ä¡Ä¡Ä¡Ä||---------------- PC HTTP Proxy ¤³¤Î»È¤¤Êý¤Ï¥À¥á¤Ç¤Ï¤Ê¤¤¤«¡£FG2 ¤Î Proxy ¢¤ ---> ¢£FG2 FG1¢£ HTTP ¢¢Web ¤«¤é Web ¥Ø¤ÏľÀܤ¤¤Ã¤Æ¤·¤Þ¤¦¡£ FG1 ¤ÏÄÌ ¡Ã ¡Ã -------¡Ã-----> ¡Ã ¤é¤Ê¤¤¤Î¤Ç¤Ê¤¤¤«¡£ --------------||¡Ä¡Ä||---------------- PC ¤Î¥Ö¥é¥¦¥¶¤Ï FG1 ¤ò¥×¥í¥­¥·»ØÄê¡£¥Ñ¥±¥Ã¥È¤Îȯ¿®¸µ¤Ï PC ¤Ç¤¢¤ë»ö¤Ë¤ÏÊѤï¤ê¤Ê¤¤¡£ ¤À¤«¤é FortiGate ¤Î¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤ÇÀ©¸æ¤Ç¤­¤ë¤Î¤Ç¤Ê¤¤¤«¡£ ¤³¤ì¤Ï¸½¾õ¤Î¥Í¥Ã ¥È¥ï¡Ý¥¯¤ÇµóÆ°¤Ï³Îǧ¤Ç¤­¤ë¤Ï¤º¤ä¤Ã¤Æ¤ß¤è¤¦¡£Â¿Ê¬¤Ç¤­¤ë¤È»×¤¦¡£¤³¤ì¤ÇÀ߷פϤǤ­¤¿¡£ * FortiGate ¤Î¸õÊ両Ƥ FortiGate ¤Ç¥Ç¥£¥¹¥¯ÅëºÜ¥â¥Ç¥ë¤Ê¤é£×£Á£Æ£Ó¤Ï¤Ç¤­¤ë¡£¥Õ¥ë¥é¥¤¥»¥ó¥¹¤Ê¤éÍøÍѤǤ­¤ë¡£ ÊÌÅÓ£×£Á£Æ£Ó¤Î¥é¥¤¥»¥ó¥¹¤È¤«¤Ï¤Ê¤¤¡£¥×¥í¥­¥·¤È£×£Á£Æ£Ó¤Ï°ì½ï¤Ë»È¤¨¤ë¤«¤È±Ä¶È¤µ¤ó ¤Ëʹ¤¤¤¿¤é¤Ç¤­¤ë¤È¡£ ¥Í¥Ã¥È¤ÇÄ´¤Ù¤Æ¤¤¤Æ FortiGate ¤Ç£Î£Á£Ô¤·¤Æ¤â£×£Á£Æ£Ó¤Ë¤ÏÌäÂê ¤Ê¤·¡¢¤¹¤Ç¤Ë°µ½Ì¤µ¤ì¤¿¥Õ¥¡¥¤¥ë¤Ë¥Ð¥¤¥È°µ½Ì¤·¤Æ¤â®¤¯¤Ï¤Ê¤é¤Ê¤¤¤È¤¤¤¦µ­»ö¤¢¤ê¡£ FortiClient ¤Î¥Õ¥ê¡ÝÈǤˤâ£×£Á£Æ£Óµ¡Ç½¤Ï¤¢¤ë¤È¤Î¤³¤È¡££±Ç¯ÄøÁ°¤Ë SSL-VPN¤Î¥Æ¥¹¥È ¤Ç¥Ñ¥½¥³¥ó¤Ë¥¤¥ó¥¹¥È¡Ý¥ë¤·¤¿¤Î¤ò¸«¤Æ¤ß¤ë¡£FortiClient ¤Î¾®¤µ¤Ê¥¢¥¤¥³¥ó¤ò¥¯¥ê¥Ã¥¯¡¢ "FortiClient Console" ²èÌ̤¬¤Ç¤¿¡£"Security Features Not Installed" ¤È²èÌ̲¼¤ÎÊý ¤Ë½Ð¤Æ¤¤¤ë¡£¤³¤ì¤Ë¤Ï£×£Á£Æ£Óµ¡Ç½¤Ï¤Ê¤¤¤¾¡¢°ìÅÙ¥¤¥ó¥¹¥È¡Ý¥ë¤·Ä¾¤·¤Æ¤ß¤ë¤«¡£ °Ê²¼¤Î¤Ï³§£±£Õ¤Ç¤¢¤ë¡£201E ¥Õ¥ë¥é¥¤¥»¥ó¥¹¤ò£±Âæ¡¢101E ¥Õ¥ë¥é¥¤¥»¥ó¥¹¤ò£±Âæ¹ØÆþ¤· ¤Æ¤Ï¡£201E ¤Ï¥×¥í¥­¥·¥µ¡Ý¥Ð¤È¤·¤Æ¤¹¤°¤ËÀßÃÖ¡£101E ¤ÏͽÈ÷µ¡¤È¤¹¤ë¡£ 101E ¤ÈÀè¤ËÇ㠤ä¿ 100D ¤Ç¥Æ¥¹¥È¤¹¤ë¡£101E¡¢201E ¤ÏÆâ¡¥¹¥È¥ì¡Ý¥¸ 480 GB¡£300D ¤Ï Æâ¡¥¹¥È¥ì¡Ý ¥¸ 120GB SSD¡£100D ¤Ï 32 GB¡¢200D ¤Ï 16 GB¡£°ø¤ß¤Ë 310B ¤Ï¥Ç¥£¥¹¥¯ÅëºÜ¤·¤Æ¤Ê¤¤¡£ £²Âæ¤Ç£È£Á¹½À®¤Ë¤¹¤ë¤È¤É¤¦¤Ê¤ë¤«¡£¥Ç¥£¥¹¥¯¤Ë¥­¥ã¥Ã¥·¥å¤ÏºÇ½é¤«¤é£²Âæ¤ËÆþ¤Ã¤Æ¤¤¤ë ¤Î¤«¡£¥á¥¤¥ó¤¬¸Î¾ã¤·¤¿¤é¥µ¥Ö¤Ë¤Ï¥­¥ã¥Ã¥·¥å¤Ï¼õ¤±·Ñ¤¬¤ì¤Ê¤¤¤È¤«¡£ 201E ¤È 101E ¤Ç ¥â¥Ç¥ë¤¬°Û¤Ê¤ëʪ¤Ç£È£Á¤Ï¤Ç¤­¤ë¤Î¤«¡£°ì±þ¤½¤ó¤Ê¤³¤È¤âµ¿Ìä¤Ë»×¤Ã¤¿¤¬¡¢£È£Á¤Ï¤ä¤é¤Ê ¤¤¤Ç¤ª¤³¤¦¡£Í½»»Åª¤Ê¤³¤È¤â¤¢¤ë¤¬¡¢¤Ç¤­¤ë¤À¤±¹½À®¤Ï¥·¥ó¥×¥ë¤Ë¤·¤è¤¦¤È»×¤¦¡£ ¥Õ¥¡¥¤¥¢¥¦¥©¡Ý¥ë¤Î 800D ¤Ç¡¢£Ã£Ð£ÕÉé²Ù¤Ï£·£°¡ó¼å¡£¥×¥í¥­¥·µ¡Ç½¤â¹Ô¤±¤ë¤È»×¤¦¡£¤Ç ¤â£×£Á£Æ£Ó¤Þ¤Ç¤ä¤é¤»¤ë¤Î¤Ï¤·¤ó¤É¤¤¤Î¤Ç¤Ê¤¤¤«¡£¥¦¥£¥ë¥¹¥Á¥§¥Ã¥¯¤Ê¤É¤Ç HTTPS¥Ñ¥±¥Ã ¥È¤òÂоݤˤ¹¤ë¤Ë¤Ï 800D ¤Ç¤Ï;͵¤¬¤Ê¤«¤Ã¤¿¡£1000D ¤ò Fortinet ¼Ò¤Îµ»½Ñ¼Ô¤Ï´«¤á¤Æ ¤­¤¿¡£1000D ¤Ï°Å¹æ²½¤Î SSL ÄÌ¿®¤âÉü¹æ²½¤¹¤ëÀìÍÑ¥Á¥Ã¥×¤ò³Î¤«ÅëºÜ¤·¤Æ¤¤¤ë¡£ * ¹â®²½¤Î³Îǧ¤Ï¤É¤¦¤¹¤ë¤« ¹â®²½¤µ¤ì¤ë¤Î¤ò³Îǧ¤¹¤ë¤Î¤¬Ìñ²ð¡££É£Ó£Ä£Î²óÀþ¤Ï¥¨¥ß¥å¥ì¡Ý¥¿ INE-64II ¤ò²ð¤·¤Æ¼Â ¸³¤Ç¤­¤ë¤¬¡¢£É£Ó£Ä£Î¥Ý¡Ý¥È¤¬¤¢¤ë¥ë¡Ý¥¿¤Ï Cisco 2503 ¤Ï½èʬ¤·¤Æ¤·¤Þ¤Ã¤¿¡£¥Õ¥ê¡Ý¥½ ¥Õ¥È¤Ç¥Ñ¥±¥Ã¥È¤Î¥¹¥ë¡Ý¥×¥Ã¥È¤òÀ©¸æ¤¹¤ë¤Î¤¬¤¢¤Ã¤¿¡¢º£¤Ç¤â¤¢¤ë¤Î¤«¡¢»È¤¨¤ë¤Î¤«¡£³Î ¤« BSD·Ï¤Î£Ï£ÓÍѤÀ¤Ã¤¿µ¤¤¬¤¹¤ë¡£¤½¤ì¤³¤½ OpenBlockS ¤¬»È¤¨¤Ê¤¤¤«¡£dummynet¤À¤Ã¤¿¡£ http://info.iet.unipi.it/~luigi/dummynet ²èÌ̤ÏÂ꤬ "The dummynet project"¡¢Âбþ ¥Ñ¥½¥³¥ó¤Îµ­½Ò¤¬[ Availablity ] ¤Ë°Ê²¼¤Î¤è¤¦¤Ë¤¢¤ê¡£The source code distribution contains source code to build it on Linux and Windows, as well as precompiled mo dules for Windows XP/Win7(both 32 and 64 bit).¡£ Google ¤Ç [¥Í¥Ã¥È¥ï¡Ý¥¯ ÃÙ±ä ¥¨¥ß¥å¥ì¡Ý¥¿] ¤ÇÄ´¤Ù¤¿¤é¤¤¤í¤¤¤íÍ­¤ë¤³¤È¤¬Ê¬¤«¤Ã¤¿¡£ ¤É¤ì¤«£±¤Ä¤°¤é¤¤¥½¥Õ¥È¤¬»È¤¨¤ë¤À¤í¤¦¡£»ÔÈÎÁõÃ֤⤤¤í¤¤¤í¤¢¤ë¡££×£Á£Î¥¨¥ß¥å¥ì¡Ý¥¿ ¤ò»ÈÍѤ·¤Æ£×£Á£Î¤ò¥·¥ß¥å¥ì¡Ý¥È¤¹¤ë¡£ ¥Õ¥ê¡Ý¥½¥Õ¥È¤Ç¤Ï Linux TC ¥³¥Þ¥ó¥É( Traffic Control )¡¢¼ê·Ú¤Ë£×£Á£Î²óÀþ¤ÎÃÙ±ä¤ò¥·¥ß¥å¥ì¡Ý¥·¥ç¥ó¤Ç¤­¤ë¡£Windows ¤Ç¤Ï Wlinee¡£ ¥Í¥Ã¥È¤Ç¤¶¤Ã¤È¸«¤¿¤é Wlinee ¤ÏºÇÂçÃÙ±ä 1000ms ¤·¤«ÀßÄê¤Ç¤­¤Ê¤¤¡£ÀßÄꤷ¤¿ÃÙ±ä¤ÎÃÍ ¤¬Àµ³Î¤Ç¤Ê¤¤¤È½ñ¤¤¤Æ¤¤¤ë¥µ¥¤¥È¤¬¤Á¤é¤Û¤é¤¢¤Ã¤¿¡£»È¤¨¤Ê¤¤¤«¤Ê¤È»×¤Ã¤¿¤¬Âç¾æÉס¢»È ¤¨¤ë¤È»×¤¦¡£Ê̤ËÀµ³Î¤Ç¤¢¤ëɬÍפϤʤ¤¡£¤¶¤¯¤Ã¤È¥¹¥ë¡Ý¥×¥Ã¥È¤¬£±£°£°Ê¬¤Î£±¤È¤«£±£° ʬ¤Î£±¤È¤«¤Ê¤ì¤Ð¡¢£×£Á£Æ£Ó¤Î¥Æ¥¹¥È¤Ï¤Ç¤­¤ë¡£ * FG100D ¤Ç¥Æ¥¹¥È¤ò¤ä¤Ã¤Æ¤ß¤ë ¥í¥°¤ÎÎΰè¤ò£×£Á£Æ£ÓÍѤˤդ꤫¤¨¤ë¡©¡¢²èÌ̤ϸ«¤¿¡£¤³¤³¤ò¥ª¥ó¤Ë¤¹¤ë¤ÈÊ̤ˣףÁ£Æ£Ó ¤ÎÀßÄê¥á¥Ë¥å¡Ý¤¬¤Ç¤Æ¤¯¤ë¤Î¤Ç¤Ê¤¤¤«¡£À褺¤Ï¤½¤³¤«¤é¤ä¤Ã¤Æ¤ß¤ë¡£FG100D¤Ç¤Î£×£Á£Æ£Ó ¤Î´Ø·¸¥á¥Ë¥å¡Ý¤ò½Ð¤·¤Æ¤ß¤¿¡£100D ¤ò¸«¤¿¡¢[¥·¥¹¥Æ¥à]->[¥Õ¥£¡Ý¥Á¥ã¡ÝÁªÂò] ¤Ë"WANºÇ Ŭ²½" ¤Î¥á¥Ë¥å¡Ý¤¬Ìµ¤¤¤±¤É¡£¤³¤Î¸å¡¢100D ¿¨¤Ã¤Æ¹Ô¤Ã¤Æ¥á¥Ë¥å¡Ý¡¢½Ð¤Þ¤·¤¿¡£ [¥í¥°&¥ì¥Ý¡Ý¥È]->[¥í¥°ÀßÄê] ------------------------------------------ | ¥í¥°ÀßÄê |----------------------------------------- | ¥í¡Ý¥«¥ë¥í¥° | ¥Ç¥£¥¹¥¯ (¡û ) ¥Ç¥£¥¹¥¯»ÈÍÑÎÌ | ¥í¡Ý¥«¥ë¥ì¥Ý¡Ý¥ÈÍ­¸ú (¡û ) ¶õ¤­Îΰè 23.63GB(99.98%) | ¥Ò¥¹¥È¥ê¥«¥ëFortiView¤òÍ­¸ú (¡û ) »ÈÍѺѤߥ¹¥Ú¡Ý¥¹ 5.24GB(0.02%) | | ¥í¥°ÀßÄê | ¥í¡Ý¥«¥ë¥È¥é¥Õ¥£¥Ã¥¯¥í¥° ( ¡û) | ¥¤¥Ù¥ó¥È¥í¥®¥ó¥° (¡û ) ¡º¤¹¤Ù¤ÆÍ­¸ú | [¥·¥¹¥Æ¥à]->[¹âÅÙ] ¤Î²èÌ̤Ǻǽ餫¤é½Ð¤Æ¤¤¤¿²èÌÌ¡£ ------------------------------------------ | ¹âÅÙ¤ÊÀßÄê |----------------------------------------- | [+] Email¥µ¡Ý¥Ó¥¹ (i) | [+] ÀßÄꥹ¥¯¥ê¥×¥È (i) | [+] ¥³¥ó¥×¥é¥¤¥¢¥ó¥¹ (i) | [+] ¥Ç¥Ð¥Ã¥°¥í¥° (i) | [-] ¥Ç¥£¥¹¥¯ÀßÄê (i) | ¥â¥Ç¥ë ATA 32GB SATA Flash | ³ä¤êÅö¤Æ [¥í¡Ý¥«¥ë¥í¥°]|WANºÇŬ²½| | | [ ŬÍÑ ] ------------------------------------------ ------------------------------------------ | Warning: ¥Õ¥©¡Ý¥Þ¥Ã¥È¤È¥ê¥Ö¡Ý¥È |----------------------------------------- | ¥Ç¥£¥¹¥¯¤ò¥í¥®¥ó¥°¤«¤éWANºÇŬ²½¤ËÊѹ¹ | --------------------------------------------------- | | This action will: | | ¡ü¥Ç¥£¥¹¥¯¤ò¥Õ¥©¡Ý¥Þ¥Ã¥È¤·¡¢¸½ºß¤Î¥í¥°¤ò¾Ãµî | | (!) ¤·¤Þ¤¹¡£¥Ç¥£¥¹¥¯¥í¥®¥ó¥°µ¡Ç½¤ò̵¸ú¤Ë¤·¤Þ¤¹¡£ | | ¡ü¥Ç¥Ð¥¤¥¹¤ò¥ê¥Ö¡Ý¥È | --------------------------------------------------- | [¥Õ¥©¡Ý¥Þ¥Ã¥È¤È¥ê¥Ö¡Ý¥È][ ¥­¥ã¥ó¥»¥ë ] -------------------¢¬---------------------------------- ¤ä¤Ã¤¿¡£[ºÆµ¯Æ°Ãæ] ¤Î²èÌ̤¬¤Ç¤Æ¤­¤¿¡££±Ê¬°Ì¤Ç¥í¥°¥¤¥ó²èÌ̤¬¤Ç¤¿¡£ ¥á¥Ë¥å¡Ý¤Ç¤É¤³¤¬ÊѤï¤Ã¤¿¤Î¤«¡¢ÊѤï¤Ã¤Æ¤Ê¤¤¤¾¡£¥Õ¥£¡Ý¥Á¥ãÁªÂò¤Ç "WANºÇŬ²½&¥­¥ã¥Ã ¥·¥å" ¤ò¥ª¥ó¤Ë¤·¤¿¤é¥á¥¤¥ó¤Î¥á¥Ë¥å¡Ý¤Ë [WANºÇŬ²½&¥­¥ã¥Ã¥·¥å] ¤È¸À¤¦¤Î¤¬½Ð¤Æ¤­¤¿¡£ °Ê²¼¤Ë [¥×¥í¥Õ¥¡¥¤¥ë] [¥Ô¥¢] [ǧ¾Ú¥°¥ë¡Ý¥×] [ÀßÄê] ¤¬¤¢¤Ã¤¿¡£¤³¤ì¤Ç¤¹¤Ê¡£ ¿ʬ [¥Ô¥¢] ¤ÇÂиþ¤¹¤ë FortiGate ¤ò»ØÄê¡£[ÀßÄê] ¤Ç¥­¥ã¥Ã¥·¥å»þ´Ö¤Ê¤É [¥×¥í¥Õ¥¡¥¤¥ë] ¤Ç¥×¥í¥È¥³¥ë¤ò»ØÄê CIFS, FTP, HTTP, MAPI, TCP¡£ IPv4¥Ý¥ê¥·¡Ý ¤Ë ÆþÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ lan1¡¢½ÐÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ wan1 "Web¥­¥ã¥Ã¥·¥å (¡û )" ¤È "WANºÇŬ²½ (¡û )³¥¿§" ¥á¥Ë¥å¡Ý¤¬½Ð¤¿¡£ [¥â¥Ë¥¿] ¤Ë [WANºÇŬ²½¥â¥Ë¥¿] [¥­¥ã¥Ã¥·¥å¥â¥Ë¥¿] [¥Ô¥¢¥â¥Ë¥¿] ¤¬½Ð¤¿¡£ ¤È¤¤¤¦¤³¤È¤Ï¥¤¥ó¥È¥é¤ÎÆÃÄê¤Î¥Õ¥©¥ë¥À¤ËÆþ¤ì¤¿³ÈÄ¥»Ò .txt ¤È .doc ¤À¤±¤ò¹â®²½¤ÎÂÐ ¾Ý¤Ë¤¹¤ë¡£¤È¤¤¤¦¤³¤È¤ò¿ôÆüÁ°¤Ë¹Í¤¨¤¿¤¬¡¢¤½¤ó¤Ê¤³¤È¤Ï½ÐÍè¤Ê¤¤¤«¡£¤Þ¤¢°ìÅÙ¥×¥í¥­¥· ¤ÎÀßÄê¤â¤ä¤Ã¤Æ¡¢¤­¤Á¤ó¤ÈÀßÄꤷ¤¿¤é¤É¤¦¤Ê¤ë¤«¡¢¤Þ¤¿¸«¤Æ¤ß¤ë¤³¤È¤Ë¤·¤è¤¦¡££³ÆüÄø¸¡ Ƥ¤·¤Æ¤³¤³¤Þ¤Çʬ¤«¤Ã¤¿¡£¥³¥Þ¥ó¥É¤Ï¤É¤¦¤«¡¢ºÙ¤«¤¤»Ø¼¨¤¬½ÐÍè¤ë¤ä¤â¤·¤ì¤Ê¤¤¡£ * ¥Æ¥¹¥È´Ä¶­ ¢¢FG101E ¢¢Qube3 ¢¤PC2 ¤³¤ó¤Ê¥Æ¥¹¥È´Ä¶­¤Ë¤Ê¤ë¤«¡£ FG101E ¤È FG100D ¤Î´Ö¤Ç B .3¡ÃProxy .4¡ÃWeb ¡Ã £×£Á£Æ£Ó¤ÎÀßÄê¤ò¹Ô¤Ê¤¦¡£ FG100D ¤ÏÆ©²á·¿¤«£Î£Á£Ô·¿¡£ --------------------------- ¡Ã.1 ËÜ¼Ò ²óÀþÃÙ±ä¤Î¥½¥Õ¥È Wlinee ¤òÆþ¤ì¤¿¥Ñ¥½¥³¥ó¤ÏÆ©²á·¿¡© Windows¢¢²óÀþÃÙ±ä ¤ÇÀßÃÖ¤¹¤ë¤Î¤«¤Ê¡£¥Ñ¥½¥³¥ó¤Ç¤½¤ó¤Ê¤³¤È¤Ç¤­¤ë¤«¤Ê¡©¡£ XP ¡Ã.2 ¢¢FG100D ¢¤PC1 PC1 ¤Î¥Ö¥é¥¦¥¶IE ¤Î¥×¥í¥­¥·»ØÄê¤Ï B.3 ¤Ë¤Ê¤ë¤¬¡¢¤½ A .1¡Ã .2¡ÃIE µòÅÀ ¤ì¤Ç£×£Á£Æ£Ó¤Ï»È¤¨¤ë¤Î¤«¡£ --------------------------- ¸ú²Ì¤Î·×¬¤Ï Windows XP ¤Ë Wline ¤ò¥¤¥ó¥¹¥È¡Ý¥ë¤·¤Æ¡¢ ¥Í¥Ã¥È¥ï¡Ý¥¯¤ËÃÙ±ä¤òȯÀ¸¤µ ¤»¤Æµ¿»÷Ū¤ËÄ㮤ʣףÁ£Î²óÀþ¤ò¥¨¥ß¥å¥ì¡Ý¥·¥ç¥ó¤¹¤ë¡£¥·¥ß¥å¥ì¡Ý¥·¥ç¥ó¤È¤Ï¸À¤ï¤º¡£ ¤¢¤ë¤¤¤Ï¹½À®¤È¤·¤Æ¤Ï¡¢FG100D ¤Ç¤â¥×¥í¥­¥·µ¡Ç½¤ò¥ª¥ó¤Ë¤·¤Æ¡¢PC ¤Î IE ¥×¥í¥­¥·»ØÄê ¤Ï A.1 ¤Ë¤¹¤ë¡£A.1 ¥×¥í¥­¥· ¤È B.3 ¥×¥í¥­¥· ¤Î¿ÃÊ¥×¥í¥­¥·¤Ë¤¹¤ë¤È¤¤¤¦¡£ PC2 ¤«¤é¤Ï£×£Á£Æ£Ó¤Ï¸ú¤«¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¡£¤Ä¤Þ¤êËܼÒÆâ¤Î¥Ñ¥½¥³¥ó¤Ç¤ÎÍøÍѤǤϥե¡¥¤ ¥ë¥¢¥¯¥»¥¹¹â®²½¤¹¤ëɬÍפϤʤ¤¤È¸À¤¦¤³¤È¡£ ¥×¥í¥­¥·¥µ¡Ý¥Ð¤ò²ð¤¹¤ë¥¢¥¯¥»¥¹¤Ç¼ÒÆâ¤Ç¤Ï¥¤¥ó¥È¥é¥µ¡Ý¥Ð¤Ë¤¢¤ë¡¢ÆÃÄê¤Î¥Õ¥©¥ë¥À¤Ë¤¢ ¤ë¥Õ¥¡¥¤¥ë¤òÂоݤˤ¹¤ë¡£Qube3 Æâ¤Î¥Ç¥£¥ì¥¯¥È¥ê¤òÂоݤˤǤ­¤ë¤«¡¢¤³¤ì¤Ï¤Ç¤­¤Ê¤¤¡£ * »²¹Í "18-1.£²£°£°£·¡Á£¸Ç¯¤Î¥Í¥Ã¥È¥ï¡Ý¥¯,(5)£×£Á£Æ£ÓÁõÃÖ¤ÎƳÆþ¤Ïɬ¿Ü¤«"nizero1.txt¡¢¤½ ¤½¤ì¤Ë [ÉÕÏ¿] ¤Î BlueCoat ¤ÎÀ½ÉʤΥá¥â¤â»²¾È¤µ¤ì¤¿¤·¡£"20-2.£É£ÐÅÅÏûþÂå¤Î¥Í¥Ã¥È ¥ï¡Ý¥¯,(4)³¤³°µòÅÀ¤È¥¤¥ó¥¿¡Ý¥Í¥Ã¥È£Ö£Ð£Î" `28/06 ¤â¡£ (4) FortiGate ¤Î WAN LLB ²óÀþ¾éĹ²½ * ³µÍ× ¥ì¥¤¥ä£³¥¹¥¤¥Ã¥Á¤¬£±Â椢¤ì¤Ð¥Æ¥¹¥È¤Ç¤­¤ë¤Ê¡£Êݼ齪λ¤·¤¿¥·¥¹¥³¤Î Catalyst ¤¬ÌܤΠÁ°¤Ë¤¢¤ë¡££±Æü¤É¤¦¤«¤Ê¤È¸¡Æ¤¤·¤Æ¤¤¤Æ¡¢´û¤ËÀ©¸æ¤¹¤ë¥á¥Ë¥å¡Ý²èÌ̤â½Ð¤Æ¤¤¤¿¤Î¤ò¸«¤¿¡¢ ¤â¤¦³Îǧ¤Ï¤ä¤ì¤½¤¦¤Êµ¤¤¬¤·¤¿¡£µòÅÀ¥Ø¤Î FortiGate ÀßÃÖ¤Ç¤Ï VDOM¤Ï»È¤ï¤Ê¤¤¤Ç¤ª¤³¤¦¡£ VDOM ¤Ï¤ä¤ä¤³¤·¤¯¤¹¤ë¤À¤±¤À¤·¡¢¤¿¤Ö¤ó»È¤¦É¬Íפâ¤Ê¤¤¤À¤í¤¦¡£ ¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ë WAN LLB ¤ÎÆüËܸì¤Ç¤ÎÀßÄê¾ðÊ󤢤ꡣ YouTube ¤Ç¤ÎÀßÄêÆ°²è¤â¤¢¤Ã¤¿¡£ ¤³¤ì¤À¤±¾ðÊ󤬤¢¤ì¤Ð¤ª¤ó¤Î¤¸¤À¡£¤â¤¦¥Æ¥¹¥È¤¹¤ë¤Þ¤Ç¤â¤Ê¤¤¤È»×¤Ã¤Æ¤·¤Þ¤¦¤È¤³¤í¤À¤¬¡¢ ¤ä¤Ï¤ê²¿»ö¤â£±¤Ë³Îǧ£²¤Ë³Îǧ¤¬Âç»ö¡¢³Îǧ¤òÂդ俤Ȥ³¤í¤Ïɬ¤ºËÜÈ֤ǤϤޤ롣¥Ý¥¤¥ó ¥È¤Ï£×£Á£Æ£Ó¤È WAN LLB ¤ò£±Âæ¤Î FortiGate ¤ÇƱµï¤·¤Æ¤Á¤ã¤ó¤È¤ä¤ì¤ë¤«¤Ç¤¢¤ë¡£ ¤È¤ê¤¢¤¨¤º´ö¤Ä¤«¸¡Æ¤²ÝÂ꤬¤¢¤ëÃæ¤Ç¡¢Ä¾¤°¤Ë¥Æ¥¹¥È¤Ç¤­¤ë¤Î¤Ï¤³¤ì¤À¤í¤¦¡£¤Á¤ã¤Á¤ã¤Ã ¤È¤ä¤Ã¤Æ¤ß¤ë¤«¡££Ó£É¶È¼Ô¤Îµ»½Ñ¼Ô¤¬Ä¾¤ËÍè¼Ò¤·¤ÆÂǤÁ¹ç¤ï¤»¤¹¤ë¡£¤½¤Î¤È¤­¤Þ¤Ç¤Ë¥Æ¥¹ ¥È¤ò¤¶¤Ã¤È¤ä¤Ã¤Æ¤ª¤±¤ì¤Ð¤È»×¤¦¡£¤¤¤Ä¤â¤½¤ó¤Ê¤è¤¦¤Ëµ¡´ï¤ÎƳÆþ¤ò¿Ê¤á¤Æ¤¤¤ë¡£µòÅÀÀß Ã֤λÅÍͤò¤É¤¦¤¹¤ë¤«¡¢¤É¤¦À߷פ¹¤ë¤«¤È¤â´Ø·¸¤¹¤ë¡£ * ¥Æ¥¹¥È´Ä¶­ ¢¢Server ´û¸¥Í¥Ã¥È¥ï¡Ý¥¯¤ò D ¤È¤¹¤ë¡£ ¼«Ê¬¤Î¥Ñ¥½¥³¥ó¤¬¤¢ C¡Ã.2 ¤ë¥»¥°¥á¥ó¥È¡£ ¥Ç¥Õ¥©¥ë¥È¥²¡Ý¥È¥¦¥§¥¤¤ò D.1 ¤Ë¤· .1¡Ã ¤Æ Server C.2 ¤Ë¥¢¥¯¥»¥¹¤¹¤ë¡£·ÐÏ©£±¤È£²¡£·ÐÏ©£± A ------------- B ¤¬¥¢¥¯¥Æ¥£¥Ö¡¢·ÐÏ©£²¤¬¥¹¥¿¥ó¥Ð¥¤¤È¤«¡£ -------| L3 |------- ------------- ¥Ð¡Ý¥Á¥ã¥ë£É£Ð¤Ç¼ÒÆâ¥Í¥Ã¥È¥ï¡Ý¥¯¤Ë¤¢¤ë¥Û¥¹¥È¢¡¤ò (£±)A|.2 B|.2(£²) ²¾ÁÛ £×£Á£Î¦¤Ë½Ð¤¹¤³¤È¤ò¹Í¤¨¤ë¡£²¾ÁÛ¡þ¤ÇÎ㤨¤Ð A.9¤È | | ¤«ÉÕ¤±¤¿¤È¤¹¤ë¡£·ÐÏ©£±¤«¤é¤Ï¥¢¥¯¥»¥¹¤Ç¤­¤ë¡£·ÐÏ© ²¾ÁÛ¡þ .1| |.1 ¡þB.8 £²ÍѤˤϲ¾ÁÛ¡þ¤Ç B.8 ¤È¤«ÉÕ¤±¤ì¤Ð¤¤¤¤¤Î¤«¤Ê¡£ A.9 -------------NAT | FortiGate | ¤½¤ì¤È¤â¥í¡Ý¥É¥Ð¥é¥ó¥µ¡ÝŪ¤ÊÆ°¤­¤ò¤¹¤ë¤Î¤Ç¤¢¤ì¤Ð ¢¡ ------------- ¢¤PC ²¾ÁÛ¡þ¤ÏÂåɽ£É£Ð¥¢¥É¥ì¥¹¤Ç£±¸Ä¤ò²¿¤¬¤·¤«·è¤á¤ë¤Î D ¡Ã |.1 ¡Ã ¤«¤â¡£¤Þ¤¢¤½¤ÎÊý¤¬³°¤«¤é¥¢¥¯¥»¥¹¤¹¤ë¤Ë¤ÏÅԹ礬¤¤ --------------------------- ¤¤¡£FortiGate ¤Î£È£Á¹½À®¤Î¾ì¹ç¤ÎÁõÃ֣ɣФΤ褦¤Ë¡£ * FG100D ¤Ç¤Î´Ø·¸¥á¥Ë¥å¡Ý [¥·¥¹¥Æ¥à]->[¥Õ¥£¡Ý¥Á¥ã¡ÝÁªÂò] WAN¥ê¥ó¥¯¥í¡Ý¥É¥Ð¥é¥ó¥¹ ON ¤Ë¤·¤¿¡£[¥Í¥Ã¥È¥ï¡Ý¥¯] ¤Î²¼¤Ë [WAN LLB]¡¢[WAN¥¹¥Æ¡Ý¥¿¥¹³Îǧ]¡¢[WAN LLB¥ë¡Ý¥ë] ¥á¥Ë¥å¡Ý¤¬½Ð¤¿¡£ [WAN LLB] ²èÌÌ --------------------------------------------------------- |ÊÔ½¸ ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ |-------------------------------------------------------- | ̾Á° wan-load-balance | ¥¿¥¤¥× WAN¥ê¥ó¥¯¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ | ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹¥¹¥Æ¡Ý¥È |¢¬Í­¸ú|[¢­Ìµ¸ú] | | WAN LLB | ------------------------------------------------------- | | [¡Ü¿·µ¬ºîÀ®] [ÊÔ½¸] [ºï½ü] | |------------------------------------------------------ | | ¹àÈÖ# | ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ | ¥¹¥Æ¡Ý¥¿¥¹ | ¥²¡Ý¥È¥¦¥§¥¤ | ------------------------------------------------------- | ¤³¤ì¤¬ÎÐ | ¥í¡Ý¥É¥Ð¥é¥ó¥¹¥¢¥ê¥´¥ê¥º¥à ¢­ | ----------------------------------------------------------------------------- | |Volume|Weighted Round Robin|Spillover|Source-Destination IP based|Source IP| | ----------------------------------------------------------------------------- | | WAN¥ê¥ó¥¯»ÈÍÑÎÌ | [¥Ð¥ó¥ÉÉý]|Volume| | [ ŬÍÑ ] ------------------------------------------------------------------------------- WAN LLB¥ë¡Ý¥ë ------------------------------------------------------------- | [¡Ü¿·µ¬ºîÀ®] [ÊÔ½¸] [ºï½ü] |------------------------------------------------------------ | ̾Á° | Á÷¿®¸µ | °¸Àè | ¥¯¥é¥¤¥Æ¥ê¥¢ | ¥á¥ó¥Ð |-----------------|--------|-------|--------------|---------- |wan-load-balance |¤¹¤Ù¤Æ |¤¹¤Ù¤Æ | Source IP |¤¹¤Ù¤Æ ------------------------------------------------------------- ¥È¥é¥Õ¥£¥Ã¥¯¥·¥§¡Ý¥Ô¥ó¥°¤Ï´Ø·¸¤Ê¤¤¤À¤í¤¦¡£Ê£¿ô¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹¥Ý¥ê¥·¡Ý¤ÈÊ£¿ô¥»¥­ ¥å¥ê¥Æ¥£¥×¥í¥Õ¥¡¥¤¥ë¤Ï´Ø·¸¤¹¤ë¤Î¤Ç¤Ê¤¤¤«¡£¹âÅ٤ʥë¡Ý¥Æ¥£¥ó¥°¤Ï¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó ¥°°Ê³°¤Ï´Ø·¸¤Ê¤¤¤À¤í¤¦¡£¹âÅ٤ʥë¡Ý¥Æ¥£¥ó¥°¤òÍ­¸ú¤Ë¤¹¤ë¤È [¥Í¥Ã¥È¥ï¡Ý¥¯] ¤Ë¥Ý¥ê¥· ¡Ý¥ë¡Ý¥È¡¢RIP¡¢OSPF¡¢BGP¡¢¥Þ¥ë¥Á¥­¥ã¥¹¥È¤¬½Ð¤Æ¤¯¤ë¡£ * WAN LLB ¤Î¸¡Æ¤¤Ï¤³¤³¤Þ¤Ç £Ó£É¶È¼Ô¤Îµ»½Ñ¼Ô¤Ë¤è¤ì¤Ð¤³¤Îµ¡Ç½¤Ï½½Ê¬»È¤¨¤ë¤È¤ÎÏäǤ¢¤ë¡£¤·¤«¤·Ëܽñ¤Ç¤Ï¼ÂºÝ¤Ë»È ¤¦¤³¤È¤Ï¤Ê¤¤¤À¤í¤¦¡£ £Ä£Í£Ú¤Î SSL-VPN ÁõÃ֤ʤ󤫤ò¥¯¥é¥¦¥É¥µ¡Ý¥Ó¥¹¤Ë°Ü¹Ô¤¹¤ë¤Ê¤É ¤·¤Æ¡¢LinkProof ¤Î¹â³Û¤ÊÊݼéÈñÍѤòÈò¤±¤ë¤¿¤á¤³¤Ã¤Á¤Îµ»½Ñ¤òÍѤ¤¤ë¤È¤«¡£Ãæ¹ñµòÅÀ¤Ç ¤Î£×£Á£Î¤Ø¤Î²óÀþÀܳ¤Ç IPSec-VPN¡¢¤¤¤ï¤æ¤ë¥¤¥ó¥¿¡Ý¥Í¥Ã¥È£Ö£Ð£Î¤ò»È¤¦¾ì¹ç¡¢²óÀþÃÇ ¤òÈò¤±¤ë¤¿¤á²óÀþ¾éĹ²½¤Ë»È¤¦¤³¤È¤â¸¡Æ¤¤·¤¿¡£¤·¤«¤·Ãæ¹ñ¤ÇÊ£¿ô¤Î¥¤¥ó¥¿¡Ý¥Í¥Ã¥È²óÀþ ¤ò°ú¤¤¤¿½ê¤Çº¬ËÜŪ¤Ê²ò·è¤Ë¤Ï¤Ê¤é¤Ê¤¤¡£ÀìÍÑÀþ¤ò°ú¤¯¤·¤«¤Ê¤¯ WAN LLB¤Î½ÐÈ֤ǤϤʤ¤¡£ (5) µòÅÀ¤â FortiGate ¤Ç°ÂÁ´¤«¤Ä¹â®¤Ë * µòÅÀ¤¬³¤³°µòÅÀ¤Î¾ì¹ç¤Ç¤Ï ¸½ÃϤǤιØÆþ¡¢ÀßÃÖ¡¢ÀßÄ꤬ÌäÂê¤Ç¤¢¤ë¡£ ³¤³°µòÅÀ¤Ë¤â FortiGate ¤òÀßÃÖ¤·¤Æ¤½¤ì¤Ê¤ê ¤Î¥»¥­¥å¥ê¥Æ¥£Âкö¡¢²óÀþ¾éĹ²½¡¢¥Õ¥¡¥¤¥ë¥¢¥¯¥»¥¹¹â®²½¤ò·×¤ë¡£¤³¤ì¤Þ¤Ç¤Ê¤«¤Ê¤«¼Â ºÝ¤Ë¤ä¤ë¤Ë¤ÏÆñ¤·¤«¤Ã¤¿¡£¸½ÃϤΣӣɶȼԤÎÂбþ¤È¤«¡£Æä˥¢¥¸¥¢·÷¤Ç¤Ï¡¢¤¤¤í¤¤¤íÌäÂê ¤¬¤¢¤Ã¤¿¤À¤í¤¦¡£¤·¤«¤·¤â¤¦¤½¤í¤½¤í¤Ç¤­¤ë¤À¤í¤¦¡¢¤Ç¤­¤ë¤Î¤Ç¤Ê¤¤¤«¡¢¤Ç¤­¤Ê¤¤¤È¡£ ¿ʬ FortiGate ¤ÎÀßÄê¤Ï¡¢¤³¤Ã¤Á¤Ç¤ä¤é¤Ê¤¤¤È¤¤¤±¤Ê¤¤¤À¤í¤¦¡£ ʪ»ö¤¬±¿¤Ð¤Ê¤¤¡£ºÙ¤« ¤ÊÀßÄꡢ¨¤ÁÁ´Éô¤ÎÀßÄê¤À¡£¥Æ¥¹¥È¤ò¤·¤ÆÆ°ºî³Îǧ¤·¤¿¾å¤Ç¡¢¤³¤Î¤è¤¦¤Ë¤ä¤Ã¤Æ¤¯¤ì¤È¸½ ÃϤΥ¹¥¿¥Ã¥Õ¤Ê¤ê¤Ë»ñÎÁ¤òÅϤ¹¡£À褺¤Ï¸½ºß¤Î£×£Á£Î¤Î²óÀþÀܳ¤ÎÍͻҤòÄ´¤Ù¤ë¡£ADSL¤« ¸÷²óÀþ¤«¤È¤¤¤¦¤Î¤Ï´Ø·¸¤Ê¤¤¡£¥ë¡Ý¥¿¤Î£É£Ð¥¢¥É¥ì¥¹¤È¥Í¥Ã¥È¥Þ¥¹¥¯¤¬Ê¬¤«¤ì¤Ð¤¤¤¤¤«¡£ µ»½ÑŪ¤ÊÌäÂê¤è¤ê¤â¡¢¤ä¤ì¤ë¶È¼Ô¤¬¼ÂºÝ¤¤¤ë¤Î¤«¡£¤½¤Ã¤Á¤ÎÊý¤¬ÌäÂê¤Ç¤¢¤ë¡£¥Æ¥¹¥È¤Þ¤Ç ¤Ï¤¹¤ë¤±¤É¼ÂºÝ¤ÎÀßÃ֤κݤˤ½¤ì¤Ê¤ê¤ÎÈñÍѤò¶È¼Ô¤Ë»Ùʧ¤¦¤³¤È¤Ë¤Ê¤ë¤À¤í¤¦¡£¶È¼Ô¤Ï¹ñ Æâ¤Î²ñ¼Ò¤Ë¤Ê¤ë¤«³¤³°¤Î²ñ¼Ò¤Ë¤Ê¤ë¤«¤½¤ì¤âʬ¤«¤é¤Ê¤¤¤·¡£¤ä¤Ã¤Æ¤â¤é¤Ã¤¿¤È¤·¤Æ¤â¡¢¤· ¤Ð¤é¤¯¤·¤Æ¡¢Ìܤ¬¹Ô¤­ÆϤ«¤Ê¤¤¤È¤³¤í¤Ç¡¢¤ª¤«¤·¤Ê»ö¤Ë¤Ê¤Ã¤Æ¤¤¤Ê¤¤¤«¡£ Êݼé¤â¤É¤¦¤¹¤ë¤«¡£¸Î¾ã¤·¤¿ºÝ¤Ë¤É¤¦¤¹¤ë¤«¡£¤½¤¦¤·¤¿¤³¤È¤ÎÊý¤¬¼Â¤ÏÆñ¤·¤¤¡££±Âæ¤ÏËÜ ÈÖµ¡¤Ç²ÔƯ¡¢£±Âæ¤ÏͽÈ÷µ¡¤Ç¸þ¤³¤¦¤Î¥Í¥Ã¥È¥ï¡Ý¥¯¤Ë²¿¤¬¤·¤«·Ò¤¤¤ÇÀßÄê¤âËÜÈÖµ¡¤È°ì½ï ¤Ë¤·¤Æ¤ª¤¯¡£ËÜÈÖµ¡¤¬¸Î¾ã¤·¤¿¾ì¹ç¤Ë¤ÏͽÈ÷µ¡¤Î£É£Ð¥¢¥É¥ì¥¹¤òÊѤ¨¤ÆÀßÃÖ¤¹¤ë¡££É£Ð¥¢ ¥É¥ì¥¹¤òÊѤ¨¤ëÁàºî¤À¤±¸½ÃÏ¥¹¥¿¥Ã¥Õ¤Ë¤ä¤Ã¤Æ¤â¤é¤¦¡¢¤ä¤ì¤ë¤è¤¦¤Ë¶µ°é¤¹¤ë¡£ * ¤¤¤í¤¤¤í¸¡Æ¤ FortiGate ¤Î SSL ¥¤¥ó¥¹¥Ú¥¯¥·¥ç¥óµ¡Ç½¤ÎÍøÍѤˤϾÚÌÀ½ñ¤òÆþ¤ì¤Ê¤¤¤È¤¤¤±¤Ê¤¤¡£ ¥×¥í¥­¥·¥µ¡Ý¥Ð¤ÏÃÙ¤¯¤Æ¹â¤¤¤È¤¤¤¦¤Î¤¬Áê¾ì¡£ÀìÍÑÀ½ÉÊ¤Ï¤Û¤Ü BlueCoat ¤·¤«¤Ê¤¤¡£ FortiGate-800D ¤Î¥Õ¥¡¡Ý¥à¥¦¥§¥¢¤ò¥¢¥Ã¥×¤¹¤ë¤ÈÉé²Ù¤¬¤ä¤äÂ礭¤¯¤Ê¤ë¤È»×¤ï¤ì¤ë¡£ Office 365 ÍøÍѤˤʤ俤Ȥ­¤Ë FortiGate ¤ÎÉé²Ù¤¬ÁýÂ礹¤ë²ÄǽÀ­¤¬¸«¤¨¤Æ¤¤¤ë¡£ BlueCoat ¼Ò¤Ï¥·¥Þ¥ó¥Æ¥Ã¥¯¼Ò¤ËÇã¼ý¤µ¤ì¤¿¤È¡¢¥·¥Þ¥ó¥Æ¥Ã¥¯¼Ò¤«¤é¤ÎÅÅÏäÇʹ¤¤¤¿¡£ Office 365 ¤Î¥Ñ¥±¥Ã¥ÈÎ̤ò»«¤¯¤Ë¤ÏµòÅÀ¤«¤é¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ë½Ð¤ë¤·¤«¤Ê¤¤¤À¤í¤¦¡£ * µòÅÀ¤Ç¤Î²óÀþ¾éĹ²½¤Î¸¡Æ¤ ¥Þ¥ë¥Á¥Û¡Ý¥ß¥ó¥°¡¢´Ê°×£Â£Ç£Ð¡¢¥ä¥Þ¥Ï¤Î¥ë¡Ý¥¿¤Ç¤Î¤ä¤êÊý¤Ï¡£ VRRP ¤È´Ê°×£Â£Ç£Ð¤Ç¤Ï ¥ë¡Ý¥¿¤ò£²Âæ»È¤¦¡£´Ê°×£Â£Ç£Ð¤Ï£É£É£Ê¤¬¹ñÆâ¤Ç¤ä¤Ã¤Æ¤¤¤ë¥á¥Ë¥å¡Ý¤Ç¡¢³¤³°¤Ç¤ÏÆñ¤·¤¤ ¤Î¤Ç¤Ê¤¤¤«¡£VRRP ¤Ï¼«¼Ò¦¤ÈÀܳÀè¤Ç¤½¤ì¤¾¤ì£²Âæ¡¢·×£´Âæ¤Î¥ë¡Ý¥¿¤¬¤¤¤ë¡£ ¤³¤ì¤â³¤ ³°¤Ç¤ÎÀßÃÖ¡¢ÀßÄê¤ÏÆñ¤·¤¤¤È»×¤¦¡£¤»¤á¤Æ¼«¼Ò¤Ë¤Æ¹ñÆâ¤Ç´û¤Ë¤ä¤Ã¤Æ¤¤¤ì¤Ð¤¤¤¤¤¬¡£ LinkProof ¤Ë£²²óÀþ¤Ä¤Ê¤°¡££Õ£Ô£Í¤ÎÊ£¿ô²óÀþÀܳ¡¢FortiGate ¤Ç¤Ï£×£Á£Î¥ê¥ó¥¯¥í¡Ý¥É ¥Ð¥é¥ó¥¹µ¡Ç½(WAN LLB)¡£LinkProof ¤Ï¹â²Á¤À¤·ÀßÄê¤â°ìÈÌŪ¤Ë¤ÏÆëÀ÷¤ß¤¬¤Ê¤¯¡¢ ¼Â¼ÁŪ ¤Ë¤ÏÍøÍѤÏÆñ¤·¤¤¤È¸«¤Ê¤¹¤Î¤¬ÂÅÅö¤Ç¤¢¤ë¡£¤½¤¦¤Ê¤ë¤È FortiGate ¤Î WAN LLB ¤¬¸½¼ÂŪ ¤ÊÁªÂò»è¤Ë¤Ê¤ë¡££Ó£É¶È¼Ô¤Îµ»½Ñ¼Ô¤ÈÏ䷤ơ¢¤â¤¦½½Ê¬¤Ç¤­¤ë¤È¤¤¤¦´¶¿¨¤òÆÀ¤¿¡£ * £×£Á£Æ£Ó¤È¤·¤Æ¤ÎÀßÃÖ¸¡Æ¤ ËܼҤΣףÁ£Î²óÀþ¤Î½ê¡¢»Ù¼Ò¤Î£×£Á£Î²óÀþ¤Î¤È¤³¤í¤ËÆ©²á·¿¤ÇÀßÃÖ¤¹¤ë¥×¥é¥ó¤ò¤É¤³¤«¤Î ¶È¼Ô¤¬½Ð¤·¤ÆÍ褿¡££Ë£Ä£Ä£É¤Î¹ñºÝ IP-VPN ¤Ç¤Î¥ª¥×¥·¥ç¥ó¤À¤Ã¤¿¤«¡££×£Á£Æ£Óµ¡Ç½¤ò¼ê ¤Ã¼è¤êÁ᤯ÍøÍѤ¹¤ë¼êÃʤǤ¢¤ë¡£¤·¤«¤·£Ó£É¶È¼Ô¤â¤É¤³¤âÄó°Æ¤·¤Æ¤³¤Ê¤¤¡££×£Á£Æ£Ó¤Ë¤Ï BlueCoat À½ÉÊ¤È Riberbed À½Éʤ·¤«¤Ê¤¤¤Î¤Ç¤Ê¤¤¤«¡£¼ÂÀÓ¤¬Â¿¤¤¤Î¤Ï Riberbed ¤Ç¤¢¤ë¡£ ÀßÃÖ¾ì½ê¤Ï¹Í¤¨¤Æ¤ß¤ë¤È¿ʬ£²¥ö½ê¤·¤«¤Ê¤¤¤Î¤Ç¤Ê¤¤¤«¡£ËܼÒ¦¤ÎÀßÃÖ¾ì½ê¤À¤¬£×£Á£Î²ó Àþ¤ÎËܼҤÎÀܳ¸ý¤«£Ì£Á£Î¾å¤Ç¤¢¤ë¡£µ¡´ï¤ÎÀßÃ֤ϻټҤÏÆ©²á·¿¤Ç¤¤¤¤¤À¤í¤¦¤¬ËܼÒ¦¤Ç ¤âÆ©²á·¿¤È¤¤¤¦¤Î¤Ï¤É¤ó¤Ê¤â¤Î¤«¡£ËܼÒ¦¤Ç¤Ïµ¡´ï¤Î¸Î¾ã¤ò¹Í¤¨¤ë¤È£²½Å²½¤È¤¤¤¦ÏÃ¤Ë¤Ê ¤ë¡££Ì£Á£Î¾å¤ËÀßÃÖ¤À¤È FortiGate ¤Ç¥×¥í¥­¥·µ¡Ç½¤È°ì½ï¤Ë£×£Á£Æ£Óµ¡Ç½¤â»È¤¦¡£ * µòÅÀ¤Ç¤Î²óÀþ°ú¤­¹þ¤ß¸¡Æ¤ ´û¸²óÀþ¤ò FortiGate ¤Î WAN2 ¤Ë·Ò¤°¡£Active ¤Ç¡£´û¸²óÀþ¤Î¥ë¡Ý¥¿¤Î£Ì£Á£Î¦¥Í¥Ã¥È ¥ï¡Ý¥¯¥±¡Ý¥Ö¥ë¤ò³°¤·¤Æ FortiGate ¤Î WAN2 ¥Ý¡Ý¥È¤Ë·Ò¤®ÊѤ¨¤ë¤È¤¤¤¦¤³¤È¡£FortiGate ¤Î£Ì£Á£Î¦¤ÏµòÅÀÆâ¤Î¥Í¥Ã¥È¥ï¡Ý¥¯¤Ë¤Ä¤Ê¤°¡£À褺¤Ï¤³¤ì¤ò¤ä¤ë¡£ ËܼҤ«¤é WAN2 ·Ðͳ¤Ç FortiGate ¤Ë¥¢¥¯¥»¥¹¤·¤ÆÀßÄê¤Ç¤­¤ë¤³¤È¤ò³Îǧ¡£ ¼¡¤Ë¿·¤·¤¤²óÀþ¤ò°ú¤­¹þ¤à¡£¿·¤·¤¯¥ë¡Ý¥¿¤â·Ò¤°¡£²óÀþ¤Ë¤è¤Ã¤Æ¤Ï¥ë¡Ý¥¿¤Ï¤¤¤é¤Ê¤¤¡£¤È ¤ê¤¢¤¨¤º¥ë¡Ý¥¿¤¬É¬Íפʾì¹ç¤È¤·¤Æ¡£ ¿·¥ë¡Ý¥¿¤Î£Ì£Á£Î¦¤ò FortiGate ¤Î WAN1 ¤Ø·Ò¤°¡£ Standby ¤È¤¹¤ë¡£WAN1 ·Ðͳ¤Ç¤âËܼҤ˥¢¥¯¥»¥¹¤Ç¤­¤ë¤³¤È¤ò³Îǧ¡£ ËܼҤ«¤é WAN1 ·Ðͳ¤Ç FortiGate ¤Ë¥¢¥¯¥»¥¹¤·¤ÆÀßÄê¤Ç¤­¤ë¤³¤È¤ò³Îǧ¡£ Active ¤È Standby ¤òµÕ¤Ë¤¹¤ë¡£¾ï¤Ë¤Ï WAN1 ¤Î¿·¤·¤¤²óÀþ¤òµòÅÀ¤«¤é¤ÏÍøÍѤ¹¤ë¤³¤È¤Ë ¤Ê¤ë¡£¿·¤·¤¤²óÀþ¤Î¥Í¥Ã¥È¥ï¡Ý¥¯¾ðÊó¤¬Ê¬¤«¤Ã¤Æ¤«¤é¡¢ FortiGate ¤Î WAN LLB ¤ÎÀßÄê¤ò ¤¹¤ë¤«¡£WAN1 ¤¬ Active¡¢WAN2 ¤¬ Standby ¤ÎÀßÄê¤Ë¤·¤Æ¡£ [ Æ©²á·¿¤ÇÀßÃ֤ʤé¾å¤Î¤è¤¦¤Ê¤³¤È¤¬¤Ç¤­¤ë ] 1.0¡Ã 1.0¡Ã 1.0¡Ã Æ©²á·¿¤Ê¤é´û¸¤Î¥Í¥Ã¥È¥ï¡Ý¥¯¤Ë¶´¤ß¹þ¤à¤³ ¡Ã1.1 ¡Ã1.1 ¡Ã1.1 ¤È¤¬¤Ç¤­¤ë¡£¾å¤Î¤³¤È¤¬¤Ç¤­¤ë¡£´ù¾å¥·¥ß¥å ¢¢R ¢¢R ¢¢R ¥ì¡Ý¥·¥ç¥ó¤¬¤Ç¤­¤ì¤Ð¡¢¼ÂºÝ¤Ë¤ä¤ì¤ë¤À¤í¤¦¡£ ¡Ã2.2 ¡Ã2.2 ¡Ã3.2¢¨ 2.0¡Ã ¡Ã2.8 ¡Ã3.1 ²óÀþ¶È¼Ô¤ä²óÀþ¼ïÎà¤òÊѤ¨¤ì¤Ð¥ë¡Ý¥¿¼«ÂΤ½ -------- UTM¢£Æ©²á·¿ ¢¢NAT·¿ ¤ì¤Ë£É£Ð¥¢¥É¥ì¥¹¤ÏÊѤï¤ë¡£¥ë¡Ý¥¿¤Î¢¨¤³¤Î ¸½¾õ ¡Ã2.9 2.0 ¡Ã2.2 2.0 £É£Ð¥¢¥É¥ì¥¹¤ÏÊѤï¤ë¤³¤È¤Ë¤Ê¤ë¡£ ------------- ------------ * Á´ÂΥͥåȥï¡Ý¥¯¤ÎÀ߷פò¾°¤ä¤Ã¤Æ¤ß¤ë [ ¥Ý¥ê¥·¡Ý ] ¡¦³¤³°µòÅÀ¤Ç¤â¥»¥­¥å¥ê¥Æ¥£Âкö¤Ï¤·¤Ã¤«¤ê¤ä¤ë¤³¤È¡£ ¡¦¥»¥­¥å¥ê¥Æ¥£ÁõÃ֤ϲ¾ÁÛ¥¢¥×¥é¥¤¥¢¥ó¥¹¤Ï»È¤ï¤Ê¤¤¡£ ¡¦¥Õ¥¡¥¤¥ë¥¢¥¯¥»¥¹¹â®²½µ¡Ç½¤òÍøÍѤǤ­¤ë¤è¤¦¤Ë¤·¤Æ¤ª¤¯¡£ ¡¦IP-VPN Ì֤ؤΣףÁ£ÎÀܳ¤Î²óÀþ¤Ï£²·ÏÅý¤Ë¤·¤Æ¾éĹ²½¤¹¤ë¡£ ¡¦¥×¥í¥­¥·¥µ¡Ý¥Ð¤Î¥Þ¥·¥ó¤ÏÊÌ¤Ë FortiGate ¤òÍÑ°Õ¤¹¤ë¡£ ¡¦µòÅÀ¤Ï¤½¤³¤«¤é¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤ò°ú¤¤¤ÆÍøÍѤ¹¤ë¡£ ¡¦µòÅÀ¤Î¥»¥°¥á¥ó¥È¤Î£É£Ð¥¢¥É¥ì¥¹¤Ï¤½¤Î¤Þ¤Þ¤Ë¤¹¤ë¡£ [ Àß·× ] µòÅÀ¤Ï¤½¤³¤«¤é¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤òÍøÍѤ¹¤ë¤è¤¦¤Ë¤¹¤ë¡£¤³¤ì¤Þ¤Ç¤Ï£×£Á£Î¤«¤éËܼҤËÆþ¤Ã ¤Æ¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ø¥¢¥¯¥»¥¹¤À¤Ã¤¿¡¢FortiGate ¤Î¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤òÍѤ¤¤ë¤·¤«¤Ê ¤¤¤«¡£¥×¥í¥È¥³¥ë¤Çʬ¤±¤ë¤«£É£Ð¥¢¥É¥ì¥¹¤Çʬ¤±¤ë¤«¡£¥×¥í¥È¥³¥ë¤Çʬ¤±¤ë¤Î¤¬¤¤¤¤¤Î¤Ç ¤Ê¤¤¤«¡¢HTTP ¤È HTTPS ¤Ï WAN3 ¤Ë¤Ä¤Ê¤¬¤ë¥¤¥ó¥¿¡Ý¥Í¥Ã¥È²óÀþ¤È¤«¤Ë¤¹¤ë¡£Â¾¤Î¥Ñ¥±¥Ã ¥È¤Ï WAN1,WAN2 ²óÀþ¤Ø¡¢¤½¤ì°Ê³°¤Ï¤É¤¦¤¹¤ë¤ó¤À¤Ã¤¿¤±¡£ ¥×¥í¥­¥·¥µ¡Ý¥Ð¤Î¥Þ¥·¥ó¤Ë£×£Á£Æ£Óµ¡Ç½¤â¤â¤·Æ±»þ¤Ë¤ä¤ì¤ë¤Î¤Ê¤é¡¢¤Ê¤«¤Ê¤«¤¤¤¤¥×¥é¥ó ¤Ë¤Ê¤ë¤Î¤Ç¤Ê¤¤¤«¡£¤½¤ì¤ò FortiGate ¤Ç¤Ç¤­¤Ê¤¤¤«¡£¤É¤¦¤ä¤é FortiGate ¤Ç¤Ï£×£Á£Æ£Ó ¤Îµ¡Ç½¤Ï¤¢¤Ã¤Æ¤â¡¢¤Û¤È¤ó¤ÉÍøÍѼÂÀÓ¤¬¤Ê¤¤¤è¤¦¤Ç¤¢¤ë¡£¤Ê¤é¤ÐΨÀ褷¤ÆÍøÍѤ·¤Æ¤ä¤í¤¦ ¤Ç¤Ï¤Ê¤¤¤«¡£Â¿Ê¬¡¢Ãí°Õ¿¼¤¯Æ°ºî³Îǧ¤ò¤ä¤ì¤Ð¡¢²¿¤¬»È¤¨¤Æ¤É¤ì¤¬Ë§¤Ð¤·¤¯¤Ê¤¤¤Î¤«¸«¤¨ ¤Æ¤¯¤ë¤Ï¤º¤Ç¤¢¤ë¡£¤«¤Ê¤ê³ä¤êÀڤäƹâ˾¤ß¤·¤Ê¤±¤ì¤Ð»È¤¨¤ë¤È»×¤¦¡£ ¥×¥í¥­¥·¥µ¡Ý¥Ð¤ÏÊÌ¤Ë FortiGate ¤òÍÑ°Õ¤¹¤ë¤³¤È¤Ë¤¹¤ë¡£ ¥Õ¥¡¥¤¥¢¥¦¥©¡Ý¥ë¤ÇÆ°¤«¤·¤Æ ¤¤¤ë FortiGate 800D ¤Ï¥×¥í¥­¥·¥µ¡Ý¥Ð¤â¤ä¤ì¤ëǽÎϤϤ¢¤ë¡¢Éé²ÙŪ¤Ë¤Þ¤À¹Ô¤±¤ë¤È»×¤ï ¤ì¤ë¤¬¡£º£¸å¥Õ¥¡¥¤¥ë¥¢¥¯¥»¥¹¹â®²½µ¡Ç½¤âÍøÍѤǤ­¤ë¤è¤¦¤Ë¤È¹Í¤¨¤Æ 201E ¤òƳÆþ¤¹¤ë ¤³¤È¤Ë¤¹¤ë¡£°ø¤ß¤Ë 800D ¤Ï¥Ï¡Ý¥É¥Ç¥£¥¹¥¯ 240 GB ÅëºÜ¤·¤Æ¤¤¤ë¡£600D ¤Ï 120GB ÅëºÜ¡£ ¤³¤ì¤é¤Ç¤â¹â®²½µ¡Ç½¤Ï»È¤¨¤Ê¤¤¤³¤È¤Ï¤Ê¤¤¤¬¡¢¥Ç¥£¥¹¥¯¤ò¹â®²½ÍѤˤ·¤Ê¤¤¤È¤¤¤±¤Ê¤¤¡£ µòÅÀ¤Ë¤Ï FortiGate ¤Î 101E ¤òƳÆþ¤¹¤ë¡£ £×£Á£Î¥ê¥ó¥¯¥í¡Ý¥É¥Ð¥é¥ó¥¹µ¡Ç½¤Î WAN LLB ¤ò»È¤¦¡£¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ø¤Ï¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤Ç¤ä¤ë¡£Á´Éô¤Ç£³²óÀþɬÍפˤʤ롣£² ²óÀþ¤ÇºÑ¤Þ¤¹¤³¤È¤¬¤Ç¤­¤Ê¤¤¤«¡¢£±²óÀþ¤ò IP-VPN ÍѤȥ¤¥ó¥¿¡Ý¥Í¥Ã¥ÈÍѤËʬ¤±¤ÆÍøÍÑ¤Ç ¤­¤ë¤ÈÍ­Æñ¤¤¤Î¤À¤¬¡£¥Õ¥¡¥¤¥ë¥¢¥¯¥»¥¹¹â®²½µ¡Ç½¤Ïº£¸åÍøÍѤǤ­¤ë¤è¤¦¤Ë¤·¤Æ¤ª¤¯¤È¸À ¤¦¤³¤È¡¢¸½¾õ¤Ç¤Ï¤Þ¤ÀÂ礭¤ÊÀ¼¤Ç¤ä¤ì¤Þ¤¹¤È¸À¤¨¤ë¾õ¶·¤Ç¤Ï¤Ê¤µ¤½¤¦¤Ç¤¢¤ë¡£ ²¼¤Î¿Þ¤Ç DNSc ¤Ï£Ä£Î£Ó¥­¥ã¥·¥å¥µ¡Ý¥Ð¤Î NetAttest¡£¼ÒÆâ¤Î¥Ñ¥½¥³¥ó¤Î¥Ö¥é¥¦¥¶¤«¤é¼Ò Æâ¤Ë¤¢¤ë¥µ¡Ý¥Ð¤ä¼Ò³°¤Ë¤¢¤ë¥µ¡Ý¥Ð¤Ë http://server1 ¤È¤«¥Û¥¹¥È̾¤Ç¥¢¥¯¥»¥¹¤·¤¿¤¤¤È ¤¤¤¦Í×˾¤ËÅú¤¨¤ë¤¿¤áÀߤ±¤¿¡£¸¡Æ¤Åö½é FortiGate Æâ¤Î£Ä£Î£Óµ¡Ç½¤Ï¡¢ ¼ÒÆâÍѣģΣӥµ ¡Ý¥Ð¤Ë¤Ï»È¤¨¤Ê¤¤¤È»×¤¤¤³¤Î DNSc ¤òÀßÃÖ¤·¤¿¡£¤·¤«¤·¤½¤Î¸å¤³¤Î£Ä£Î£Óµ¡Ç½¤Ç¤â½ÐÍè¤ë ¤Èʬ¤«¤Ã¤¿¡£´ðËÜ DNSc ¤Ï»È¤ï¤Ê¤¤¤³¤È¤Ë¤·¤è¤¦¡£ÌÌÅݤߤëÁõÃÖ¤ò°ì¤Ä¤Ç¤â¸º¤é¤·¤¿¤¤¡£ ¢¨"26-6.FortiGate 80C ¤Ë¤Ï¤½¤í¤½¤í²Ë¤ò,[ÉÕÏ¿]³¤³¤ó¤Ê³¨¤òÉÁ¤¤¤Æ¹¹¤Ê¤ë¸¡Æ¤¤ò´üÂÔ"¡¢ ¤Îµ­»ö¤È¤³¤³¤Ç¤Îµ­»ö¤ò¹ç¤ï¤»¤ë¤È¥¤¥ó¥È¥é¥Í¥Ã¥ÈÁ´ÂΤÎÀ߷פˤʤ롣¤´¶ìÏ«ÍͤǤ·¤¿¡£ [ ¹½À® ] Internet FG0, FG1 ¤Ï FortiGate¡£FG0 ¤ÎDNS»ØÄê ¡§ DNSc FG1 Web1 PC2 ¤Ï Fortinet ¼Ò¤Î FortiGuard ¤Ç¤â¡¢¤É FG0¢¢ ¢¢ ¢¢ ¢¢ ¢¤ ¤³¤Ç¤â¹½¤ï¤Ê¤¤¡£FG1 ¤Ï¥×¥í¥­¥·¥µ¡Ý¥Ð ¡ÃËÜ¼Ò ¡Ã.2 ¡Ã.3 ¡Ã.4 ¡Ã A ¤Î¤¿¤á¡¢DNS ¤Ï®¤¤±þÅú¤¬¤¤¤ë¡£¤³¤³¤é ------------------------------------ ÊÕ¤ê¤Ï 26-6.¾Ï¤ÎÉÕÏ¿¤ÎºÇ¸å¤Ç¸¡Æ¤¤·¤¿¡£ ¡§ Proxy,WAFS | B ¡§ ------------ FG1 ¤Î£×£Á£Æ£Ó¤ÎÂоݤϼÒÆâ¤Î¥¤¥ó¥È¥é ¡§ IP-VPN £×£Á£Î ¥µ¡Ý¥Ð Web1 ¤À¤±¤Ë¤¹¤ë¡£¤½¤ó¤Ê¤³¤È¤¬ ¡¿¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡À ¤Ç¤­¤ë¤Î¤«Í׸¡Æ¤¡£ÂоݤϣɣХ¢¥É¥ì¥¹ ¡À¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡¿ »ØÄê¤Ï¤Ç¤­¤Ê¤¤¡©¡¢¥×¥í¥È¥³¥ë»ØÄê¤Î¤ß Active¡§ ¡§Standby ¤«¡£Æ°ºî¸¡¾Ú¤Ï¤³¤ì¤«¤é¤Ç¤¢¤ë¡£ ¡§ ¡§ ¢¢R ¢¢R Internet µòÅÀ FG1 ¤Î¥×¥í¥­¥·¥µ¡Ý¥Ð¤Ç¤Ï¥­¥ã¥Ã¥·¥å¤Ï WAN1¡Ã ¡ÃWAN2 ¡§ 10.10.*.* ¤·¤Ê¤¤¡¢¤È¤¤¤¦¤« FortiGate¤Î¥×¥í¥­¥· NAT------------ ¢¢R µ¡Ç½¤Ë¤Ï¥­¥ã¥Ã¥·¥åµ¡Ç½¤Ï¤Ê¤¤¡£¤½¤â¤½ | WAN LLB |WAN3 ¡Ã ¤â¤â¤¦¥×¥í¥­¥·¤Ë¥­¥ã¥Ã¥·¥å¤ÏÍפé¤Ê¤¤¡£ FG2| |¡½¡½¡½¡½ ¥Ý¥ê¥·£Ò £Ó£É¶È¼Ô¤Îµ»½Ñ¼Ô¤È¤âÁêÃ̤·¤¿¾å¤Ç¤ÎÏᣠ| WAFS | ------------ ¢¢SV1 ¢¤PC1 ¼ÒÆâ³°¤Î¥µ¡Ý¥Ð¤Ë¥Û¥¹¥È̾¤Ç telnet ¤ä µòÅÀ | LAN ¡Ã ¡ÃIE X FTP ¤Ç¤É¤¦¤·¤Æ¤â¥¢¥¯¥»¥¹¤·¤¿¤¤¤È¤¤¤¦ ------------------------------------ Í×˾¤¬¤¢¤ë¾ì¹ç¤Ë DNSc ¤òÀߤ±¤ë¤È¤¹¤ë¡£ ¡¦FG2 ¤Ç¤ÏËܼҤΠA,B ¥»¥°¥á¥ó¥È¤Ø¤Î¥Ý¥ê¥·£Ò¤òÀßÄê¡£ > LAN->WAN1 ·Ðͳ¡£WAN1 ¤Ï WAN2 ¤È¤Ç WAN LLB ¤â¡£ ¡¦FG2 ¤Ç¤ÏµòÅÀ¤Î¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ø¤Ï¥Ç¥Õ¥©¥ë¥È¥ë¡Ý¥È¤Ë¤¹¤ë¡£ > µòÅÀ¤«¤é¤ÏµòÅÀ¥µ¥¤¥È¤ò¸«¤é¤ì¤ë¤è¤¦¤Ë¤¹¤ë¡£ ¡¦µòÅÀ¤Î PC1 ¤Î¥Ö¥é¥¦¥¶¤Î¥×¥í¥­¥·»ØÄê¤Ï A.3 ¤Î FG1¡£ > ¤³¤ì¤Ç a) b) ¤ÎÆ°ºî¤¬¤Ç¤­¤ë¤Î¤«¡£Í×Æ°ºî³Îǧ¡£ ¡¦FG1 ¤Ï¥×¥í¥­¥·¤È£×£Á£Æ£Ó¤½¤ì¤Ë³Æ¼ï¥»¥­¥å¥ê¥Æ¥£µ¡Ç½¡£ > SSL ½ªÃ¼¤·¤Æ°Å¹æ²½¥Ñ¥±¥Ã¥È¤â¥Á¥§¥Ã¥¯Âоݤˤ¹¤ë¤«¡£ ¡¦ËܼҤΠPC2 ¤Î¥Ö¥é¥¦¥¶¤Î¥×¥í¥­¥·»ØÄê¤Ï A.3 ¤ÇÁ°¤Î¤Þ¤Þ¡£ > ËܼҤΥѥ½¥³¥ó¤Ï£×£Á£Æ£Ó¤Ï»È¤ï¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¡£ FortiGate ¤Ç¤Ï¥Ç¥Õ¥©¥ë¥È¥ë¡Ý¥È¤È¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤¬Í¥À褵¤ì¤ë¡£¸¡Æ¤¤·¤Æ¹Ô¤Ã¤Æ ʬ¤«¤Ã¤¿¤³¤È¤Ç¡¢FortiGate ¤ÎÆ©²á·¿¥â¡Ý¥É¤Ç¤Ï£×£Á£ÎºÇŬ²½¤·¤«¤Ç¤­¤Ê¤¤¡£WAN LLB ¤È ¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤âƱ»þ¤ËÍøÍѤ·¤¿¤±¤ì¤Ð£Î£Á£Ô·¿¥â¡Ý¥É¤Ç¤Ê¤¤¤È½ÐÍè¤Ê¤¤¡£ µòÅÀ¥Ñ¥½¥³¥ó¤Î¥Ö¥é¥¦¥¶¤Ï¡¢ËÜ¼Ò¤Î¥×¥í¥­¥·¥µ¡Ý¥Ð¤ò»ØÄꤷ¤Æ¤¤¤ë¡£¤³¤ì¤Þ¤Ç¤ÏµòÅÀ¤«¤é ¤Î¥¤¥ó¥¿¡Ý¥Í¥Ã¥ÈÍøÍѤÏËܼҤÎÆüËÜ·Ðͳ¤Ë¤Ê¤Ã¤Æ¤¤¤¿¡£¥¢¥¯¥»¥¹¤Ï¥¢¥¸¥¢Ãϰ褫¤é¤ÏÁêÅö ÃÙ¤«¤Ã¤¿¡£µòÅÀ¤Î PC1 ¤Î¥Ö¥é¥¦¥¶¤Î¥×¥í¥­¥·»ØÄê¤Ï A.3 ¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤È¤¤¤¦¤³¤È¡£ º£²ó¤Î¥×¥é¥ó¤Ç¤ÏµòÅÀ¤ÏµòÅÀ¤«¤é¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ë¥¢¥¯¥»¥¹¤¹¤ë¡£²¼µ­¤Ç¤â¸¡Æ¤¤Ï¤·¤Æ¤ß ¤¿¤¬µòÅÀ¤òÃæ¹ñ¤È²¾Äꤹ¤ë¤ÈÌñ²ð¤Ç¤¢¤ë¡£Ãæ¹ñ¤Ç¤Ï¾¹ñ¤Î¥µ¥¤¥È¤Ø¤Î¥¢¥¯¥»¥¹¡¢Â¾¹ñ¤«¤é ¤Î¥¢¥¯¥»¥¹¤òÀ©¸Â¤·¤Æ¤¤¤ë¡£¤¦¤Þ¤¤ÊýË¡¤Ï¤Ê¤¤¤«£Ó£É¶È¼Ô¤Ë¤âƬ¤ò¤Ò¤Í¤Ã¤Æ¤â¤é¤ª¤¦¡£ -------------------------------------------------------------------------------- µ¤¤Ë¤Ê¤ë¤³¤È¤Ç [¥·¥¹¥Æ¥à]->[¥Õ¥£¡Ý¥Á¥ãÁªÂò] ¤Ç "WANºÇŬ²½&¥­¥ã¥Ã¥·¥å" ¤Î»ö¡£¤Þ¤º ÀâÌÀ½ñ¤­¤ò "WANºÇŬ²½¤ÈWeb¥­¥ã¥Ã¥·¥å¤òWAN¥È¥é¥Õ¥£¥Ã¥¯¤òºï¸º¤¹¤ë¤¿¤á¤ËÍ­¸ú²½¡£WAN Opt.& ¥­¥ã¥Ã¥·¥å¥á¥Ë¥å¡Ý¤òÄɲä·¤Þ¤¹"¡£¥ª¥ó¤Ë¤¹¤ë¤È£²¥õ½ê¤Ë "Web¥­¥ã¥Ã¥·¥å" ¤È¤¤ ¤¤¤¦¤Î¤¬½Ð¤Æ¤­¤¿¡£¥ª¥Õ¤Ë¤¹¤ë¤È¾Ã¤¨¤¿¡£ ¤³¤ì¤Þ¤Ç FortiGate ¥×¥í¥­¥·µ¡Ç½¤Ë¤Ï¥­¥ã¥Ã ¥·¥åµ¡Ç½¤Ï̵¤¤¤È½ñ¤¤¤Æ¤­¤¿¤Î¤À¤¬¡¢¤¤¤ä£×£Á£Æ£ÓÍѤΥ­¥ã¥Ã¥·¥å¤À¤È»×¤¦¡£`2h/11/m [¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[IPv4¥Ý¥ê¥·¡Ý] Web¥­¥ã¥Ã¥·¥å(¡û ) WANºÇŬ²½(¡û )³¥¿§ [¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[Explicit¥×¥í¥­¥· ¥Ý¥ê¥·¡Ý] Web¥­¥ã¥Ã¥·¥å (¡û ) -------------------------------------------------------------------------------- * µòÅÀ¤ÈÆüËܤ«¤é¤Î¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ø¤Î¥¢¥¯¥»¥¹¤Ï µòÅÀ¤Ç¤ÏľÀÜ°ú¤¤¤¿¥¤¥ó¥¿¡Ý¥Í¥Ã¥È²óÀþ¤Ç³°¤Ë¹Ô¤¯¤è¤¦¤Ë¤¹¤ë¡£µòÅÀ¤«¤éËܼҤʤɤ˹Ԥ± ¤ë¥»¥°¥á¥ó¥È¤òÎóµó¤¹¤ë¡¢¤½¤ì°Ê³°¤ÏµòÅÀ¤Î¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ë¹Ô¤¯¤è¤¦¤Ë¤¹¤ë¡£¤³¤Î¤¿¤á ¤Ë¤Ï¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤ÎÀßÄê¤òËܼҤǤä¤Ã¤Æ¤¤¤ë¤Î¤È¤Ï¡¢µÕ¤Ë¤¹¤ì¤Ð¤¤¤¤¤Î¤Ç¤Ê¤¤¤«¡£ LAN->WAN1,WAN2 ¤Ï¥Ý¥ê¥·£Ò¤ÇÀÅŪ·ÐÏ© A,B ¤òÀßÄê¡£LAN->WAN3 ¤ò¥Ç¥Õ¥©¥ë¥È·ÐÏ©¤Ë¤¹¤ë¡£ µòÅÀ¤«¤éÆüËܤΥ¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Î¥µ¥¤¥È¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤Î¤Ï¤É¤¦¤¹¤ë¤Î¤«¡£¾å¤Î¤Ç¤ÏµòÅÀ ¤Î¥×¥í¥Ð¥¤¥À·Ðͳ¤Ë¤Ê¤ë¡£¤½¤Î¹ñ¤Ç¾ðÊóÅýÀ©¤·¤Æ¤¤¤ë¤ÈÆüËܤΥµ¥¤¥È¤Ï¸«¤¨¤Ê¤¤¤è¤¦¤Ë¤· ¤Æ¤¤¤ë¤«¤âÃΤì¤Ê¤¤¡£¤½¤¦¤Ê¤ë¤ÈÆüËÜ¥µ¥¤¥È¤ÏÆüËܤÎËܼҷÐͳ¤Ç¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ø¹Ô¤¯¤Î ¤Ç¤Ê¤¤¤È¤¤¤±¤Ê¤¤¡£¤Ï¤¿¤Þ¤¿¥Ç¥Õ¥©¥ë¥È·ÐÏ©¤ò WAN1¡¢WAN2 ¤Ë¤·¤Ê¤¤¤È¡£Î¾ÊýËþ¤¿¤¹¤Î¤Ï¡£ µòÅÀ¤Ç¤Ï¥×¥í¥­¥·»ØÄê¤Ï̵¤·¤Ë¤¹¤ë¤«¡£¤¤¤ä¤½¤¦¤Ç¤â¤Ê¤¤¡£FortiGate ¤Î£×£Á£Æ£Ó¤È¥×¥í ¥­¥·µ¡Ç½¤Ë¤Ä¤¤¤ÆµóÆ°¤¬Ê¬¤«¤é¤Ê¤¤¤ÈÀ߷פǤ­¤Ê¤¤¡£ËܼҤȵòÅÀ¶¦¤ËÆ©²á·¿¤Ç FortiGate ¤òÀßÃÖ¤¹¤ë¾ì¹ç¤Ïʬ¤«¤ë¡£ Á´Éô¤Î¥Ñ¥±¥Ã¥È¤¬Ä̲᤹¤ë¤«¤é¡¢¤½¤ÎÃæ¤Ç HTTP ¤À¤± FTP ¤â Âоݤˤ¹¤ë¤È¤¤¤¦Ïäˤʤ롣¥¤¥ó¥È¥é¥µ¡Ý¥Ð¤ÎÆÃÄê¥Ç¥£¥ì¥¯¥È¥ê¤È¤«¤ÏÂоݤˤǤ­¤Ê¤¤¡£ µòÅÀ¤Î¥Ñ¥½¥³¥ó¤Î¥Ö¥é¥¦¥¶¤Î¥×¥í¥­¥·ÀßÄê¤Ï "¼¡¤Ç»Ï¤Þ¤ë¥¢¥É¥ì¥¹¤Ë¤Ï¥×¥í¥­¥·¤ò»ÈÍѤ· ¤Ê¤¤" [ 10.10.*.* ]¡£WAN3 ¤ÏµòÅÀ¥Ø¤Î¥¤¥ó¥¿¡Ý¥Í¥Ã¥È²óÀþ¡£µòÅÀ¤Î¥µ¥¤¥È¤Ï¤³¤Î²óÀþ¤ò Ä̤ë¤è¤¦¤Ë¤·¤¿¤¤¡£10.10.*.* ¤Ø¤Ï¥Ö¥é¥¦¥¶¤Î¥×¥í¥­¥·Ìµ¤·¤Ç¡¢¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤Ç ¹Ô¤¯¤è¤¦¤Ë¤¹¤ë¡£µòÅÀ¤¬Î㤨¤Ð´Ú¹ñ¤Ç¡¢´Ú¹ñ¤Ë³ä¤êÅö¤Æ¤é¤ì¤¿¥Ñ¥Ö¥ê¥Ã¥¯£É£Ð¥¢¥É¥ì¥¹¤¬ 10.10.*.* £±¤Ä¤Ç¤¢¤ì¤Ð¤½¤ì¤Ç£Ï£Ë¡£Â¾¤Ë¤âÎóµó¤¹¤ë¤³¤È¤Ë¤Ê¤ë¤Ï¤º¤Ç¤½¤ì¤¬ÌäÂê¤À¡£ FortiGate ¤ÎºÇ¿·¥Õ¥¡¡Ý¥à¥¦¥§¥¢¤Ë¡¢SD-WAN µ¡Ç½¤Î "¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¡¦¥Ö¥ì¥¤¥¯¥¢¥¦¥È" ¤È¤¤¤¦¤Î¤¬¤Ç¤­¤¿¡£¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¾å¤Î¿¡¹¤¢¤ë¥µ¡Ý¥Ó¥¹¤òÁª¤ó¤Ç¡¢FortiGate ¤ÎÊÌ¥Ý¡Ý ¥È¤«¤é½Ð¤Æ¹Ô¤¯¤ë¤è¤¦¤Ë¤·¤Æ²óÀþ¤òÊ̤ˤ¹¤ë¤Î¤Ç¤¢¤ë¡£FortiOS 5.4 ¤Ç¤â½ÐÍè¤ë¤¬ 5.6¤¬ ¤¤¤¤¤À¤í¤¦¤È¤¤¤¦¤³¤È¤Ç¤¢¤ë¡£ISDB( Internet Service Data Base )¤È¤¤¤¦¡£¤³¤Îµ¡Ç½¤Î ¥Ç¡Ý¥¿¥Ù¡Ý¥¹¤Ë´Ú¹ñ¤Î¥Ñ¥Ö¥ê¥Ã¥¯£É£Ð¥¢¥É¥ì¥¹¤È¤«¤¢¤ì¤Ð¡¢¤¦¤ì¤·¤¤¤«¤âÃΤì¤Ê¤¤¡£ * ¥×¥í¥­¥·¤Ë¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤¬²Ã¤ï¤ë¾ì¹ç¤Ï ¥×¥í¥­¥·¥µ¡Ý¥Ð¤ò²ð¤¹¤ë¾ì¹ç¤Î¥Ö¥é¥¦¥¶¤«¤é¥Ñ¥±¥Ã¥È¤¬¤É¤¦¤Ê¤Ã¤Æ¤¤¤ë¤«²ä¤Ëʬ¤«¤é¤Ê¤¤¡£ µòÅÀ¤Î¥Ñ¥½¥³¥ó¤Î¥Ö¥é¥¦¥¶¤ÇËÜ¼Ò¥×¥í¥­¥·»ØÄꤹ¤ë¤È¤¤¤¦¤Î¤Ï¡¢µóÆ°¤Ï¤É¤¦¤Ê¤ë¤Î¤«¡£µò ÅÀ¤Î¥Ý¥ê¥·¡Ý¥ë¥Æ¥£¥ó¥°¤Ç Qube3 ¤Ø¤Ï¹Ô¤«¤Ê¤¯¤Ê¤ë¤Î¤Ç¤Ê¤¤¤«¡£ ¤³¤³¤éÊդ꤬¤³¤ÎÀß·× ¤Î¥Ý¥¤¥ó¥È¤Ë¤Ê¤ë¡£PC ¤Î¥Ö¥é¥¦¥¶¤Î¥×¥í¥­¥·¤Ï A.3 »ØÄê¤ò¤·¤Æ Qube3 ¤Ë¥¢¥¯¥»¥¹¡£ ¥× ¥í¥­¥··Ðͳ¤Ç¼ÒÆ⥵¡Ý¥Ð¤Ø¥¢¥¯¥»¥¹¡£¤È¤ê¤¢¤¨¤º¤³¤ì¤À¤±¤Ç¤­¤ë¤«³Îǧ¤¹¤ë¡£ Proxy ¼ÒÆ⥵¡Ý¥Ð £²»þ´ÖÄøÅÙ¤ÇÆ°ºî³Îǧ¤·¤Þ¤·¤¿¡£·ë²Ì¤«¤é¸À ¢¢ ¢¢ ¢¢ ¤¦¤È¥À¥á¡£IE ¤Ç¥×¥í¥­¥·»ØÄê A.3 ¤ò¤ä¤ë¤È A ¡Ã.3 ¡Ã ¡Ã 192.168.1.0 Qube3 ¤Ë¤Ï¥¢¥¯¥»¥¹¤Ç¤­¤Ê¤¯¤Ê¤Ã¤¿¡£IE¤Ç¥× ---------------------------------- ¥í¥­¥·¤ÎÂоݤˤ·¤Ê¤¤ [192.168.3.* ] ¤È¤· WAN1¡Ã ¤¿¤é¥¢¥¯¥»¥¹¤Ç¤­¤¿¡£PC ¤«¤é Qube3¤Ø ping ------------ ¢¢Qube3 ¤ä ftp ¤ÏÀè¤Ë¥Æ¥¹¥È¤·¤Æ¤Ç¤­¤¿¡¢ ¥×¥í¥­¥· | NAT |WAN3 ¡Ã192.168.3.0 ¤Ï¤³¤ì¤é¤Ë¤Ï´Ø·¸¤Ê¤¤¡££±¤ÄÃí°Õ¡¢Ìϼ°¿ÞŪ | FortiGate|¡½¡½¡½ ¥Ý¥ê¥·£Ò ¤Ë WAN3¤È¤¤¤¦¤Î¤ò½ñ¤¤¤¿¤¬ FortiGate-100D | 100D | ¤Ë¤Ï¤Ê¤¤¡£wan1 ¤È wan2 ¤Ï¤¢¤ë¡£ £Ì£Á£ÎÍÑ ------------ PC¢¤IE ¤Î¥Ý¡Ý¥È¤ò¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤ËήÍѤǤ­ B ¡ÃLAN ¡Ã192.168.2.0 ¤ë¤³¤È¤òÉÕÏ¿¤Î¤È¤³¤í¤Ç³Îǧ¤·¤¿¡£ÌäÂê¤Ê¤¤¡£ ---------------------------------- * µòÅÀÆâ¤Î¥µ¡Ý¥Ð¤âËܼҤä¾µòÅÀ¤«¤éÍøÍѤ¹¤ë¤Ë¤Ï ¤³¤ì¤Þ¤ÇËܼҤ«¤éµòÅÀ¤Î¥µ¡Ý¥Ð¤òÁàºî¤·¤Æ¤¤¤ë¤Î¤¬¤¢¤ë¡£µòÅÀ¤Ë¤Ï¥ë¡Ý¥¿¤¬¤¢¤ë¤À¤±¤Ç¤½ ¤ì¤¬¤Ç¤­¤¿¡£º£¸å¤â¤ä¤ë¤Ë¤ÏµòÅÀ¤Î FortiGate ¤òÆ©²á·¿¤ÇÀßÃÖ¤·¤Ê¤¤¤È¤¤¤±¤Ê¤¤¡£ Æ©²á ·¿¥â¡Ý¥É¤Ç WAN LLB ¤È¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤¬¤Ç¤Ç¤­¤ë¤Î¤«¡£ ¤³¤ì¤¬°ìÈ֤Υݥ¤¥ó¥È¤Ë ¤Ê¤ë¡£¼ê¸µ¤Î FG100D ¤Ï£Î£Á£Ô·¿¤Ç¤¢¤ë¡¢ ¥Ý¥ê¥·¡Ý¥ë¡Ý¥È¤Ë WAN LLB ¤Ë£×£Á£ÎºÇŬ²½¤Î ¥á¥Ë¥å¡Ý¤Ï½Ð¤Æ¤¤¤ë¡££Î£Á£Ô¤ËÊѹ¹¤·¤Æ³Îǧ¤·¤Æ¤ß¤è¤¦¡£ "¥ª¥Ú¥ì¡Ý¥·¥ç¥ó¥â¡Ý¥É NAT" ¤ò ¥È¥é¥ó¥¹¥Ú¥¢¥ì¥ó¥È ¤ËÊѤ¨¤¿¤¤¤Î¤À¤¬¡¢ ²èÌ̤ËÊѤ¨¤ë ¥á¥Ë¥å¡Ý¤¬½Ð¤Æ¤Ê¤¤¡¢v5.4.3 ¤Ç¡£¥Ñ¥½¥³¥ó¤«¤é Tera Term ¤ÇÆþ¤Ã¤Æ¥³¥Þ¥ó¥É¤ÇÊѹ¹¤·¤¿¡£ °ìȯ¤Ç¤¹¤ó¤Ê¤ê¤Ç¤­¤¿¡£¥ê¥¿¡Ý¥ó¥­¡Ýᤤ¤¿¤é "Changing to TP mode" ¤È½Ð¤¿¡£ ¤â¤¦ÊÑ ¤ï¤Ã¤Æ¤¤¤¿¡££×£Á£ÎºÇŬ²½¤Î¥á¥Ë¥å¡Ý¤·¤«½Ð¤Ê¤¤¡£¥À¥á¤À¡£Æ©²á·¿¥â¡Ý¥É¤Ç¤Ï£×£Á£ÎºÇŬ ²½¤·¤«¤Ç¤­¤Ê¤¤¡£WAN LLB¡¢¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤â¤ä¤ë¤Ë¤Ï£Î£Á£Ô·¿¤Ë¤¹¤ë¤·¤«¤Ê¤¤¡£ # config system settings Æ©²á·¿¤Ë¤·¤¿¤Î¤Ï¤¤¤¤¤¬ (settings) # set opmode transparent £Î£Á£Ô·¿¤ËÌ᤹¤Î¤¬´Êñ (settings) # set manageip 192.168.2.2/255.255.255.0 ¤Ë¤Ï¤Ç¤­¤½¤¦¤Ë¤Ê¤¤¡£¤Þ (settings) # set gateway 192.168.2.1 ¤¿Í¾Íµ¤Î¤¢¤ë»þ¤Ë²þ¤á¤Æ (settings) # end ¤ä¤Ã¤Æ¤ß¤ë¤³¤È¤Ë¤·¤è¤¦¡£ ¡¦´û¸²óÀþ¤Î¥ë¡Ý¥¿¤Î FortiGate £×£Á£Î¦¤Î£É£Ð¥¢¥É¥ì¥¹¤ÏÊѹ¹¤¹¤ëɬÍפ¬¤¢¤ë¡£ ¡¦°­¤¤»ö¤Ð¤«¤ê¤Ç¤Ï¤Ê¤¤¡£µòÅÀ£Õ£Ô£Í¤ò£Î£Á£Ô¤Ë¤¹¤ë¤³¤È¤ÇµòÅÀ¤Ï¤è¤ê°ÂÁ´¤Ë¤Ê¤ë¡£ µòÅÀ¥µ¡Ý¥Ð¤Ê¤É¤ËËܼҤ«¤é¥¢¥¯¥»¥¹¤·¤¿¤±¤ì¤Ð¥Ð¡Ý¥Á¥ã¥ë£É£Ð¤Ç³°¤Ë½Ð¤¹¡£¤¤¤ä¤³¤ì¤Ï¤À ¤á¤«¡£²óÀþ¤Î¥ë¡Ý¥¿Àܳ¤Î¤¿¤á¤Ë³ä¤ê¿¶¤é¤ì¤Æ¤¤¤ë¤À¤±¤À¡££Î£Á£Ô¤Î¤Þ¤Þ¤ÇµòÅÀÆâ¤Î¥µ¡Ý ¥Ð¤Ë¤½¤Î¤Þ¤Þ¥¹¥ë¡Ý¤·¤Æ¥¢¥¯¥»¥¹¤¹¤ëµ¡Ç½¤¬¤¢¤ì¤Ð¤¤¤¤¤¬¡£¤¤¤ä¤¤¤ä¥Ñ¥Ö¥ê¥Ã¥¯£É£Ð¤Ç¤Ê ¤¯¥×¥é¥¤¥Ù¡Ý¥È£É£Ð¤ÊÌõ¤Ç¡¢¥¯¥é¥¹£ÃÁêÅöʬ¤â¤é¤¨¤Ð¤¤¤¤¡£ ²óÀþ¦£É£Ð¤ÏÍøÍѤǤ­¤ë¤«¤É¤¦¤«¤¬ÌäÂê¤Ë¤Ê¤ë¤«¡£²óÀþ¶È¼Ô¦¤ÎÅÔ¹ç¤È¤¤¤¦¤«·ÐÏ©À©¸æ¤ò ¤ä¤ë¤«¤É¤¦¤«¡££×£Á£Î¤Î IP-VPN ¤È¹­°è¥¤¡Ý¥µ¥Í¥Ã¥È¤Î°ã¤¤¤Ï¡£IP-VPN ¤Ï IPSec-VPN ¤ò ¤É¤³¤ËÄ¥¤ë¤Î¤«¡£ ­¼þ¤ê¤ò¥¤¥ó¥¿¡Ý¥Í¥Ã¥È²óÀþ¤ò»È¤¦¾ì¹ç¤Ï IPSec-VPN ¤ò£×£Á£Î¤Î¥¢¥¯ ¥»¥¹¥Ý¥¤¥ó¥È¤È¤ä¤ë¤Î¤Ç¤Ê¤¤¤«¡£¤¤¤ï¤æ¤ë¥¤¥ó¥¿¡Ý¥Í¥Ã¥È£Ö£Ð£Î¤òÄ¥¤ë¡£ ¡¦FortiGate ¤Î SD-WAN µ¡Ç½¤ÇµòÅÀÆâ¤Î¥Û¥¹¥È¤Ë¥¢¥¯¥»¥¹¤Ç¤­¤Ê¤¤¤«¡£ ¡¦FortiGate ¤Î¥½¡Ý¥¹£Î£Á£Ô¤È¤«¥Ð¡Ý¥Á¥ã¥ë£É£Ð¤È¤«¤Ç¤ä¤ì¤Ê¤¤¤«¡£ -------------------------------------------------------------------------------- ¤³¤³¤Þ¤Ç¸¡Æ¤¤·¤Æ¤Õ¤È¤³¤ì¤Ï¤Þ¤µ¤Ë SD-WAN ¤Î²ÝÂê¤À¤È»×¤Ã¤¿¡£µòÅÀ¤Î£Õ£Ô£Í¤ò£Î£Á£Ô·¿ ¤ÇÀßÃÖ¤¹¤ë¤Î¤Ï¡¢¤Ò¤ç¤Ã¤È¤·¤Æ£É£Ð¥¢¥É¥ì¥¹¤¬Èï¤Ã¤Æ¤·¤Þ¤¦»Ò²ñ¼Ò¤ò£×£Á£Î¤Ë´Þ¤á¤ë¾ì¹ç ¤ÎÏäȰì½ï¤Ç¤¢¤ë¡£ÁÐÊý¤Ç¼ÒÆ⥵¡Ý¥Ð¤òÍøÍѤ·¤¿¤¤¤È¤¤¤¦Í×˾¤Ê¤ó¤«¤¬½Ð¤Æ¤¯¤ë¡£Ê£»¨¤Ê £Î£Á£Ôµ¡Ç½¤ò¶î»È¤¹¤ë¤Î¤Ç¤Ê¤¯ SD-WAN ¤Ç¤â¤Ã¤Æ¥¹¥Þ¡Ý¥È¤Ê¥Í¥Ã¥È¥ï¡Ý¥¯¤Ë¤¹¤ë¤Î¤Ç¤¢¤ë¡£ -------------------------------------------------------------------------------- * SD-WAN µ¤¤Ë¤Ê¤ê¥á¥â¤·¤Æ¤¿»ö¤Ê¤É SDN ¤Ï SD-WAN ¤«¤éÉáµÚ¤·¤Æ¤¤¤¯¤«¡©¡£¡ÖÆü·Ð£Î£Å£Ô£×£Ï£Ò£Ë¡×2017/03, P.80¡Á85, "´ë ¶È¥Í¥Ã¥È¥ï¡Ý¥¯¤Þ¤ë¤´¤È¹½Ã۽ѡ¢ºÇ½ª²ó SDN/SD-WAN ½¸Ãæ´ÉÍý¤¬ºÇÂç¤Î¥á¥ê¥Ã¥È"¡£SDN¥¹ ¥¤¥Ã¥Á´ÉÍý¤Î¤¿¤á¤Ë¤ÎÇÛÀþ¤¬ÌäÂê¡£¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¥Ö¥ì¡Ý¥¯¥¢¥¦¥È¤ÇÊ£¿ô¤Î¥¤¥ó¥¿¡Ý¥Í¥Ã ¥È²óÀþ¤òÀ©¸æ¤Ç¤­¤ë¡£¤³¤ì¤òÍøÍѤ¹¤ì¤Ð Office 365 ¤Ê¤É¤Î SaaS ¤Ø¤Î¥¢¥¯¥»¥¹¤ÏÊ̲óÀþ ¤òÄ̤¹¤È¤«¤Ç¤­¤ë¡£´ë¶È¸þ¤±À½ÉÊ¤Ë¤Ï UNIVERGE PF¡¢Cisco APIC-EM ¤Ê¤É¤¬¤¢¤ë¡£¥Ç¡Ý¥¿ ¥»¥ó¥¿¡Ý¸þ¤±¤Ë¤Ï Big Cloud Fabric ¤Ê¤É¡£ SD-WAN ¤òÍøÍѤ¹¤ë¤Ë¤Ï£×£Á£ÎÀܳÍѤΠCPE ¤òÀßÃÖ¤¹¤ëɬÍפ¬¤¢¤ë¡£ÄÌ¿®²óÀþ¶È¼Ô¡¢¥×¥í¥Ð¥¤¥À¤¬¥µ¡Ý¥Ó¥¹¤ò¤·¤Æ¤¤¤ë¤«¤¬ÌäÂê¤Ç¤¢¤ë¡£ Fortinet ¼Ò¤Î `2h/10 ¤Î¥»¥ß¥Ê¡Ý¤Ë¤Æ¡£FortiGate ¤Ï SD-WAN ¤¬¤Ç¤­¤ë¡£ Éû¼ÒŤ¬³ê¤é ¤«¤ÊÊÛÀå¤Ç SD-WAN ¤Ç¥­¥ã¥ê¥¢¤Î¸À¤¤¤Ê¤ê¤Ë¤Ï¤Ê¤é¤Ê¤¤¡¢£×£Á£Î¤ÎÀ߷פϥæ¡Ý¥¶Â¦¤¬¼çƳ ¸¢¤ò°®¤í¤¦¤ÈÏ䷤Ƥ¤¤¿¡£¤É¤¦¤â SD-WAN ¤Ï SDN ¤È¤Ï¤Á¤ç¤Ã¤È°ã¤¦¤Î¤Ç¤Ê¤¤¤«¡£ºÇ½éSDN ¤Î¤ä¤êÊý¤ò£×£Á£Î¤Ç¤â»È¤Ã¤¿¤éÊØÍø¤È¤¤¤¦¤³¤È¤Ç SD-WAN ¤È¾Î¤·¤Æ¤¤¤ë¤Î¤«¤È»×¤Ã¤¿¤Î¤À ¤¬¡£FortiGate ¤Ï SD-WAN ¤¬½ÐÍè¤ë¤È¤Ï¤É¤¦¤¤¤¦¤³¤È¤«¡£¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¥Ö¥ì¡Ý¥¯¥¢¥¦¥È µ¡Ç½¤¢¤ê¤È¤¤¤¦»ö¤ÇÀ褺¤½¤¦¤Ç¤¢¤ë¡£FortiGate ¤Ë CPEµ¡Ç½¤¬¤¢¤ë¤Î¤«Í׳Îǧ¡£`2h/10/E Ä´¤Ù¤¿¤é FortiHypervisor ¤È¤¤¤¦¥¢¥×¥é¥¤¥¢¥ó¥¹¤¬¤¢¤Ã¤Æ¡¢¤½¤ì¤Ë CPE ÅëºÜ¤µ¤ì¤Æ¤¤¤¿¡£ * »²¹Í ¡ÖÆü·Ð¥³¥ß¥å¥Ë¥±¡Ý¥·¥ç¥ó¡×2017/06, P.12¡Á27, "Æý¸:Àèʼ¤Ï SD-WAN (¥¯¥é¥¦¥ÉºÇŬ)¤Ç ´ë¶È¥Í¥Ã¥È¤ò¼è¤ë"¡£`2h/10/E ¤Ëµ­»ö¤ò¸«¤¿¡£2017/02¹æ P.70,71 ¤Î "¿·´Ö°ã¤¤¤À¤é¤±¤Î ¥Í¥Ã¥È¥ï¡Ý¥¯ºî¤ê" ¤Ë¤Ï SD-WAN ¤Ï´ë¶È¥Í¥Ã¥È¤Î¿ÌÜŪ²½¤ËÍøÅÀ¤¢¤ê¤È½ñ¤«¤ì¤Æ¤¢¤Ã¤¿¡£ ¾¼«¿È¤Îµ­½Ò¤Ç¡£"4-3.£×£Á£Î²óÀþ¤Î®ÅÙ¥¢¥Ã¥×¤È¾éĹ²½" Á´ÂΤǻ²¹Í¤Ë¤Ê¤ë ybase3.txt¡£ "20-5.¥·¥ó¥×¥ë¤Ë¥Í¥Ã¥È¥ï¡Ý¥¯¤ò,(4)³¤³°·Ï¥Í¥Ã¥È¥ï¡Ý¥¯´Ä¶­"network.txt¡£"24-1.¥Í¥Ã ¥È¥ï¡Ý¥¯¤Ç¥Í¥Ã¥ÈËô¥Í¥Ã¥È,(1)¥¤¥ó¥¿¡Ý¥Í¥Ã¥È²óÀþ¤Î£²ËÜΩ" netnet.txt¡£ ¡ÖÆü·Ð£Î£Å£Ô£×£Ï£Ò£Ë¡×2017/12, P.72¡Á76,"¥Í¥Ã¥È¥ï¡Ý¥¯¹½Ãۥƥ¯¥Ë¥Ã¥¯(Âè»°²ó)¥ë¡Ý¥¿ ¡Ý ¥¯¥é¥¦¥É¤Ë¤Ï³ÆµòÅÀ¤«¤é¥¢¥¯¥»¥¹"¡£ºÇ¶á¤Î¥ë¡Ý¥¿¤Ë¤Ï¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°µ¡Ç½¤¢¤ê¡£ ¤³¤ì¤¬»È¤¤Êª¤Ë¤Ê¤ì¤Ð FortiGate ¤ÏÆ©²á·¿¤Ç£×£Á£Æ£Ó¤À¤±¤ä¤é¤»¤ë¤³¤È¤¬¤Ç¤­¤ë¤¾¡ª¡£ ------------------------------------------------------------------------------------ [ ÉÕÏ¿ ] £²¤Ä¤Î¥Æ¥¹¥È¤½¤ì¤Ë¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥° ¡ü £×£Á£Æ£Óµ¡Ç½³Îǧ¤Ë¸þ¤±¤Æ¤Î¥Æ¥¹¥È * ¥Æ¥¹¥È£±:¥×¥í¥­¥·»ØÄê¤Î¾ì¹ç¤ÎÆ°ºî³Îǧ `2h/11/s ¥Ï¡Ý¥É¥¦¥§¥¢¥¹¥¤¥Ã¥Á¤Ç¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹Ì¾ lan ¤Ï port3 ¤«¤é port15 ¤ò³ä¤êÅö¤Æ¡¢¥¤ ¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹Ì¾ lan1 ¤Ï port1 ¤È port2 ¤ò³ä¤êÅö¤Æ¤Æ¤¢¤ë¡£ ʪÍý¤Ë¤Ï wan1 ¤È wan2 ¤¢¤ê¡£wan3 ¤È¤¤¤¦¤Î¤Ï FortiGate-100D ¤Ë¤Ï¤Ê¤¤¡£mgmt ¤È¤¤¤¦¤Î¤â¤¢¤ê¡£¥Ý¥ê¥·¡Ý¥ë¡Ý ¥Æ¥£¥ó¥°ÍѤ˰ì±þ wan2 ¤Ï¡¢WAN LLB ¤Ç wan1 ¤È¶¦¤Ë»È¤¨¤ë¤è¤¦¶õ¤±¤Æ¤ª¤­¤¿¤¤¡£¤É¤ì¤« portx ¤ò¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°¤È¤·¤ÆÍøÍѤǤ­¤ë¤«¡£¤½¤ì¤Ï¤Ç¤­¤Þ¤·¤¿£Ï£Ë¤Ç¤¹¡£FG100D ¤Î¥Õ¥¡¡Ý¥à¥¦¥§¥¢¥Ð¡Ý¥¸¥ç¥ó¤Ï v5.4.3¡£ ¥Ý¥ê¥·¡Ý¤Ï¥Ý¡Ý¥È¤Ç¤Ê¤¯Ì¾Á°»ØÄê¤Ë¤Ê¤Ã¤Æ¤¤¤ë¡£ ¤³¤ÎÀßÄê¤Ç¥á¥â¥ê»ÈÍÑÎÌ¤Ï 16%¡¢£Ã£Ð£Õ»ÈÍÑΨ¤Ï 0 ¤À¤Ã¤¿¡£¥»¥­¥å¥ê¥Æ¥£Åù¤Ï̵¤·¤Ç¡£ ¢¢Proxy ¡§ [IPv4¥Ý¥ê¥·¡Ý] ¡Ã.3 .9¡§ 192.168.1.0 ----------------------------------------------- -------------------------- |¹àÈÖ Á÷¿®¸µ °¸Àè ¥µ¡Ý¥Ó¥¹ ¥¢¥¯¥·¥ç¥ó NAT | ------- |---------------------------------------------- wan1|.1 |Qube3| | lan - lan1 ------------- ------- |---------------------------------------------- | NAT |.1 .2| 192.168.3.0 | 1 all all ALL ¡ºACECPT ¡ºÍ­¸ú | FortiGate |------- |---------------------------------------------- | 100D |lan1 Port1,2 | lan - wan1 ------------- |---------------------------------------------- lan| Port3¡Á16 PC¢¤IE | 2 all all ALL ¡ºACECPT ¡ºÍ­¸ú |.1 ¡Ã.2 |---------------------------------------------- -------------------------- | 3 Implicit Deny all all ALL (/)DENY ¡ß̵¸ú 192.168.2.0 ----------------------------------------------- ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹Ì¾ lan ¤Ï¥Ý¡Ý¥ÈÈֹ棳¤«¤é£±£¶¤ÏƱ¤¸ 192.168.2.0 ¥»¥°¥á¥ó¥È¤Ç¤¢¤ë¡£ PC ¤Ï¼ÂºÝ¤Ë¤Ï Port3 ¤ËľÀܤĤʤ²¤Æ¤¤¤ë¡£ [¥Í¥Ã¥È¥ï¡Ý¥¯]->[¥Ý¥ê¥·¡Ý¥ë¡Ý¥È] ----------------------------------------------------- |¼õ¿®¥È¥é¥Õ¥£¥Ã¥¯¤Î¥Þ¥Ã¥Á¥ó¥°¾ò·ï: wan1¤Ï¥Ç¥Õ¥©¥ë¥È·ÐÏ©¤òÀß |¥×¥í¥È¥³¥ë TCP UCP SCTP [ANY] »ØÄꤹ¤ë[0 ] Äꤷ¤Æ¤¢¤ë¡£ 192.168.1.9 |ÆþÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ lan ¡ß] ¤Ç¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤ØÈ´¤±¤ë |Á÷¿®¸µ¥¢¥É¥ì¥¹¥Þ¥¹¥¯ [ 192.168.2.2/255.255.255.255 ] ·ÐÏ©¤Ç¤¢¤ë¡£ 192.168.1.9 |°¸À襢¥É¥ì¥¹¥Þ¥¹¥¯ [ 192.168.3.2/255.255.255.255 ] ¤Ë¤Ï¥Õ¥¡¥¤¥¢¥¦¥©¡Ý¥ë¤Ê¤ê | ¤¬¤¢¤ë¡£Qube3 ¤Î¥Ç¥Õ¥©¥ë |¥¢¥¯¥·¥ç¥ó: ¥È·ÐÏ©¤ÏŬÅö 192.168.3.8¡£ |½ÐÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ lan1 ¢¦] |¥²¡Ý¥È¥¦¥§¥¤¥¢¥É¥ì¥¹ [ 192.168.3.2 ] << ¤³¤Î¥Æ¥¹¥È´Ä¶­¤Ç¤Ï¤³¤Î£É£Ð¤Ç¤Ê¤¤¤È¡£ ¤³¤ì¤À¤È¥×¥í¥­¥·»ØÄꤹ¤ë¤È¡¢¤½¤Î£É£Ð¥¢¥É¥ì¥¹¤¬°¸Àè¤Ë¤Ê¤Ã¤Æ¾å¤Ë¹çÃפ·¤Ê¤¤¡£ Qube3 ¤Ë http ¥¢¥¯¥»¥¹¤Ç¤­¤Ê¤¤¡£ °¸À襢¥É¥ì¥¹¥Þ¥¹¥¯¤ò [ 0.0.0.0/0.0.0.0 ] ¤Ë¤·¤Æ¤â¤À¤á ¤À¤Ã¤¿¡£¥Ý¥ê¥·£Ò¤Ï¤¢¤¯¤Þ¤Ç¤Î¤½¤Ã¤Á¤Î¥Í¥Ã¥È¥ï¡Ý¥¯¤Ø¤Î¥Ñ¥±¥Ã¥È¤òÂоݤˤ¹¤ë¤È¤¤¤¦¤³ ¤È¤Ç¡¢¥Ñ¥±¥Ã¥È¤ò²£¼è¤ê¤¹¤ë¤è¤¦¤Ê¿¶¤ëÉñ¤¤¤Ï¤·¤Ê¤¤¡£¥Ö¥é¥¦¥¶¤Ç¥×¥í¥­¥·¤ÎÂоݤˤ·¤Ê ¤¤ [192.168.3.* ] ¤È¤·¤¿¤é¹Ô¤±¤¿¡£Qube3 ¤Ï´ÉÍý²èÌÌ¤Ø¤Ï http://xxx:444/ ¤Ç¤¢¤ë¡£ * ¥Ý¥ê¥·¡Ý¥ë¡Ý¥Æ¥£¥ó¥°ÀßÄê¤Î¤ª¤µ¤é¤¤ `2h/11/s ¢¢Router ¤³¤Î FortiGate ¤Î¥Õ¥¡¡Ý¥à¥¦¥§¥¢¤Ï v5.2.10¡£ VDOM 192.168.1.0 ¡Ã.9 ¤Ï»ÈÍѤ»¤º¡£°Ê²¼¤Î¤è¤¦¤Ê»ØÄê¤Î»ÅÊý¤¬¤Ç¤­¤ë¡£ UDP --------- ---------------- 53 ¤Ï£Ä£Î£Ó¤ÎÌ䤤¹ç¤ï¤»¡£ »ØÄêIP ¤È¤¤¤¦¤Î¤Ï WAN2 | | 192.168.4.0 ·Ðͳ¤Î¥¤¥ó¥¿¡Ý¥Í¥Ã¥È²óÀþ¤Ç¡¢¤½¤Î¥×¥í¥Ð¥¤¥À¤¬ÍÑ°Õ WAN1| |WAN2 ¤·¤Æ¤¤¤ë£Ä£Î£Ó¥µ¡Ý¥Ð¤Ç¤¢¤ë¡£UDP 123 ¤Ï£Î£Ô£Ð¥×¥í ----------- ¥È¥³¥ë¤Ç¡¢£Î£Ô£Ð¥µ¡Ý¥Ð¤òÍøÍѤ¹¤ë¾ì¹ç¤Ï WAN2 ¤ò·Ð | (2) (3) | 192.168.3.0 ͳ¤¹¤ë¤è¤¦¤Ë¤·¤¿¤â¤Î¤Ç¤¢¤ë¡£ TCP 80 ¤Ï¸À¤ï¤º¤ÈÃÎ | |------------ ¤ì¤¿ http ¥¢¥¯¥»¥¹¡£¤³¤³¤Ë¤Ï https ¤Î 443 ¤Ïµ­ºÜ |FortiGate|(4) DMZ ¤·¤Æ¤Ê¤¤¤Î¤Ç https ¥¢¥¯¥»¥¹¤Ï¡¢WAN1 ·Ðͳ¤È¤¤¤¦¤³ Proxy----------- ¤È¤Ë¤Ê¤ë¡£1 ¤È 2 ¤Î¥×¥í¥È¥³¥ë¤Ï ANY ¤Ç¥²¡Ý¥È¥¦¥§ ¢¢ LAN|(1) ¥¤¥¢¥É¥ì¥¹¤Ï 0.0.0.0¡£ 3 ¤«¤é 5 ¤ÎÁ÷¿®¸µ¥Ý¡Ý¥È¤Ï ¡Ã.2 | 192.168.2.0 1-65535 ¤Ç¥²¡Ý¥È¥¦¥§¥¤¥¢¥É¥ì¥¹¤Ï 192.168.4.9¡£ ---------------------------- # ¼õ¿® Á÷¿® Á÷¿®¸µ¥¢¥É¥ì¥¹ °¸À襢¥É¥ì¥¹ °¸Àè¥Ý¡Ý¥È -------------------------------------------------------------------------------- 1 port1 port2 192.168.2.2/255.255.255.255 192.168.1.0/255.255.255.0 2 port1 port4 192.168.2.2/255.255.255.255 192.168.3.0/255.255.255.0 3 port1 port3 192.168.2.2/255.255.255.255 0.0.0.0 /0.0.0.0 TCP 80 4 port1 port3 192.168.2.2/255.255.255.255 »ØÄêIP/255.255.255.255 UDP 53 5 port1 port3 0.0.0.0/0.0.0.0 0.0.0.0 /0.0.0.0 UDP 123 * ¥Æ¥¹¥È£²:FortiGate ¤Î¥×¥í¥­¥·µ¡Ç½³Îǧ ¥Õ¥£¡Ý¥Á¥ã¡ÝÁªÂò²èÌÌ¤Ç {Explicit¥×¥í¥­¥·} ¤ò¥ª¥ó¤Ë¤·¤¿¤é¡¢£²¤Ä¥á¥Ë¥å¡Ý¤¬¤Ç¤Æ¤­¤¿¡£ [¥Í¥Ã¥È¥ï¡Ý¥¯]->[Explicit¥×¥í¥­¥·] ¤Ç {Explicit Web¥×¥í¥­¥·}¤ò¥ª¥ó¤Ë¤·¤¿¤é¥á¥Ë¥å ¡Ý¤¬¤º¤º¤Ã¤È¤Ç¤Æ¤­¤¿¡£[¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[Explicit¥×¥í¥­¥· ¥Ý¥ê¥·¡Ý]¡£PC¤Î ¥Ö¥é¥¦¥¶¤«¤é³°¤Î¥Û¡Ý¥à¥Ú¡Ý¥¸¤Ï½Ð¤¿¡£Qube3 ¤Î http://192.168.3.2 ¤Ø¤ÏµñÈݤµ¤ì¤Æ¤· ¤Þ¤Ã¤¿ "Access Denied" ¤È¤Ç¤¿¡£²¼µ­¤ÎÀßÄê¤Ë¤â¤¦°ì¹©Éפ·¤Ê¤¤¤È¡£¤³¤ì¤Ï¤Þ¤¿¸åÄø¤Ë¡£ .9¡Ã 192.168.1.0 -------------------------- | ------- wan1|.1 |Qube3| ------------- ------- | NAT | |192.168.3.2 | |------- | FG100D |¥×¥í¥­¥·ÀßÄê ------------- lan| Port3¡Á16 PC¢¤IE ¥×¥í¥­¥·»ØÄê |.1 ¡Ã.2 192.168.2.1 -------------------------- 192.168.2.0 [¥Í¥Ã¥È¥ï¡Ý¥¯]->[Explicit¥×¥í¥­¥·] ¤Î {Explicit Web¥×¥í¥­¥·} --------------------------------------------------------------- | Listen¤¹¤ë¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ lan ¡ß] | HTTP¥Ý¡Ý¥È [ 8080 ] << 80 ¤Ë¤·¤è¤¦¤È¤¹¤ë¤È Entry is used | HTTPS¥Ý¡Ý¥È [Use HTTP Port]|Specify| ¤È½Ð¤¿¡£ | ¥×¥í¥­¥·¼«Æ°ÀßÄê(PAC) (¡û ) | ¥Ç¥Õ¥©¥ë¥È¤Î¥Õ¥¡¥¤¥¢¥¦¥©¡Ý¥ë¥Ý¥ê¥·¡Ý¤Î¥¢¥¯¥·¥ç¥ó |µö²Ä|[µñÈÝ] | [-] Web¥×¥í¥­¥·¥Õ¥©¥ï¡Ý¥Ç¥£¥ó¥°¥µ¡Ý¥Ð | [-] URL¥Þ¥Ã¥Á¥ê¥¹¥È [¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[Explicit¥×¥í¥­¥· ¥Ý¥ê¥·¡Ý] ¤³¤ì¤âÀßÄꤷ¤Ê¤¤¤È¥Ö¥é¥¦ ----------------------------------------------------- ¥¶¤Ç¥¢¥¯¥»¥¹¤·¤è¤¦¤È¤¹¤ë | Explicit¥×¥í¥­¥·¥¿¥¤¥× [Web]|FTP ¤È½ÐÍè¤Ê¤¤¡£ | Í­¸ú¤Ë¤Ê¤Ã¤Æ¤¤¤ë¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ lan | ½ÐÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ wan1 ] | Á÷¿®¸µ¥¢¥É¥ì¥¹ [ all ] | °¸À襢¥É¥ì¥¹ [ all ] | ¥¢¥¯¥·¥ç¥ó [¡ºACCEPT]|(/)DENY|¡÷AUTHENTICATE| * ¥Æ¥¹¥È£³:FortiGate ¥×¥í¥­¥·¤Î¥ï¥ó¥¢¡Ý¥à¤Ç¤ÎÆ°ºî³Îǧ ¥ï¥ó¥¢¡Ý¥àÀßÃÖ¤Ç¥×¥í¥­¥·ÀßÄꤹ¤ë¤Î¤Ï¤É¤¦¤ä¤ë¤Î¤À¤Ã¤¿¤«¡£¤³¤ì¤À¤±¤Ç¤è¤«¤Ã¤¿¤«¡£¤³ ¤ì¤Ç PC ¤Î¥Ö¥é¥¦¥¶¤«¤é¥×¥í¥­¥· 192.168.2.1 ·Ðͳ¤Ç http://192.168.2.8/ ¥¢¥¯¥»¥¹¤Ç ¤­¤¿¡£Æ±¤¸¥»¥°¥á¥ó¥È¤Ë Qube3 ¤¬¤¢¤ë¤Î¤Ç³Îǧ¤·¤º¤é¤¤¤¬¡¢¤³¤ì¤Ç¤¤¤¤¤Ï¤º¤Ç¤¢¤ë¡£ [¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[Explicit¥×¥í¥­¥· ¥Ý¥ê¥·¡Ý] ---------------------------------------------------- | Explicit¥×¥í¥­¥·¥¿¥¤¥× [Web]|FTP| | Í­¸ú¤Ë¤Ê¤Ã¤Æ¤¤¤ë¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ lan | ½ÐÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ lan ] << wan1 ¤ò lan ¤ËÊѤ¨¤¿¤Î¤ß¡£ wan1|.1 ------------- | NAT |¥×¥í¥­¥·ÀßÄê | | | FG100D | ------------- ¥×¥í¥­¥·»ØÄê 192.168.2.1 lan| PC¢¤IE |.1 .2¡ÃPort3Àܳ -------------------------- ¡Ã.8 192.168.2.0 ¢¢Qube3 Port4Àܳ * ¥Æ¥¹¥È£´:FortiGate ¥×¥í¥­¥·¤Ë¤Æ¥»¥­¥å¥ê¥Æ¥£¥Á¥§¥Ã¥¯ ¥Õ¥£¡Ý¥Á¥ã¡ÝÁªÂò¤Ç¤ÏºÇ½é¤«¤é "Ê£¿ô¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹¥Ý¥ê¥·¡Ý" ¤È "Ê£¿ô¥»¥­¥å¥ê¥Æ¥£ ¥×¥í¥Õ¥¡¥¤¥ë" ¤Ï¥ª¥ó¤Ë¤·¤Æ¤¢¤ë¡£"¥¢¥ó¥Á¥¦¥£¥ë¥¹" ¤â¥ª¥ó¤Ë¤·¤Æ¤ß¤¿¡£ [¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[Explicit¥×¥í¥­¥· ¥Ý¥ê¥·¡Ý] ------------------------------------------------------------ | ¹àÈÖ Á÷¿®¸µ °¸Àè ¥¢¥¯¥·¥ç¥ó ¥»¥­¥å¥ê¥Æ¥£¥×¥í¥Õ¥¡¥¤¥ë |----------------------------------------------------------- | 1 all all ¡ºACCEPT [+] ------------------------------------¢¬---------------------- ¤³¤ì¥¯¥ê¥Ã¥¯¤·¤¿¤éº¸²¼¤Î²èÌ̤¬¤Ç¤Æ¤­¤¿¡£¥¢¥ó¥Á¥¦¥£¥ë ¥¹¤ÏÁª¤Ö¤Ë¤·¤Æ¤â¡¢¥×¥í¥­¥·¥ª¥×¥·¥ç¥ó¤Ï¤É¤¦¤¹¤ë¤Î¡©¡£ ---------------------------------- | ¥¨¥ó¥È¥ê¤òÁªÂò |--------------------------------- |[-]¥¢¥ó¥Á¥¦¥£¥ë¥¹¥×¥í¥Õ¥¡¥¤¥ë(1) << "¥¢¥ó¥Á¥¦¥£¥ë¥¹"¤â¥ª¥ó¤Ë¤·¤Æ½Ð¤Æ¤­¤¿¡£¤³¤ì | [ AV ]default ¤Ï¤è¤·¡£Â¾¤Ë¤âŬµ¹£É£Ð£Ó¤Ê¤ó¤«¤â´Þ¤á¤Æ¤¤¤¯¡£ |[-]¥×¥í¥­¥·¥ª¥×¥·¥ç¥ó(1) << ¤³¤ì¤â¤É¤³¤«¤éͯ¤¤¤Æ½Ð¤Æ¤­¤¿¤Î¤«¡£²¿¤ò¤·¤Æ | [ PRX ]default ¤¯¤ì¤ë¤Î¤«¡£ÁªÂò¤Ïɬ¿Ü¤È¿¨¤Ã¤Æ¤¤¤¿¤é½Ð¤¿¤¾¡£ |[-]SSL¥¤¥ó¥¹¥Ú¥¯¥·¥ç¥ó(2) << ¤³¤ì¤Ï¥Õ¥£¡Ý¥Á¥ã¡ÝÁªÂò¤Ë¤¢¤ëÌõ¤Ç¤Ê¤¤¡£¤É¤³ | [ SSL ]certificate-inspection ¤«¤éͯ¤¤¤Æ½Ð¤Æ¤­¤¿¤Î¤«¡£Â¿Ê¬¥Ñ¥Õ¥©¡Ý¥Þ¥ó¥¹ | [ SSL ]deep-inspection Ū¤ËǽÎϤ¬Â­¤é¤Ê¤¤¤À¤í¤¦¤È¤¤¤¦»ö¤ÇÁª¤Ð¤Ê¤¤¡£ * ¥Æ¥¹¥È£µ:FortiGate ¤Î¥×¥í¥­¥·¤È¼ÒÆâÍѣģΣӤγÎǧ ¢¢¼ÒÆâÍÑ ¢¢Qube3 ¼ÒÆâÍѣģΣӥµ¡Ý¥Ð NetAttest D3 ¤Ç¤Ï¼ÒÆâ .7¡ÃDNS .8¡Ã¥Û¥¹¥È̾ svr1 ÀßÃ֤Υµ¡Ý¥Ð¤Ë¥Û¥¹¥È̾¤Ç¥¢¥¯¥»¥¹¤Ç¤­¤ë¤è -------------------------------- ¤¦¤ËÆüì¤Ê£Ä£Î£Ó¤Î¥¨¥ó¥È¥ê¤òºîÀ®¤·¤Æ¤¢¤ë¡£ wan1|NAT 192.168.1.0 http://svr1 Åù¤È¤¤¤¦¥¢¥¯¥»¥¹¤¬¤Ç¤­¤ë¤è¤¦ ------------- ¤Ë¡£¤³¤³¤Ç¤Ï¥Ö¥é¥¦¥¶¤Ç¥×¥í¥­¥·»ØÄꤷ¤Æ¤ª | |¥×¥í¥­¥·ÀßÄê ¤¤¤Æ¡¢FortiGate ¤¬»²¾È¤¹¤ë£Ä£Î£Ó¤ò»È¤Ã¤Æ | FG100D |DNS»ØÄê 192.168.1.7 http://svr1 ¥¢¥¯¥»¥¹¤Ç¤­¤ë¤«³Îǧ¤·¤Æ¤ß¤¿¡£ | | ÌäÂê¤Ê¤·¡£ËÜÈÖÀßÃÖ¤Ç¤Ï FortiGate ¤Ï wan1 ------------- PC¢¤IE ¥×¥í¥­¥·»ØÄê ¤Ï²¿¤â¥Í¥Ã¥È¥ï¡Ý¥¯Àܳ¤·¤Æ¤Ê¤¤¥ï¥ó¥¢¡Ý¥à lan|.1 .2¡Ã 192.168.2.1 ¹½À®¤Ç¤¢¤ë¡£¼ÂºÝ¤Ë¤½¤Î¾ì¹ç¤Î¤âÆ°ºî³Îǧ¤¹ -------------------------------- ¤Ù¤­¤À¤¬¡¢¤È¤ê¤¢¤¨¤º FortiGate¤ò£Î£Á£Ô·¿ 192.168.2.0 ¥â¡Ý¥É¤Ë¤Æ¥Æ¥¹¥È¤·¤Æ¤ß¤¿¡£¤¹¤ó¤Ê¤ê¤Ç¤­¤¿¡£ ¤³¤³¤Î¤È¤³¤í¤â¤¦°ìÅÙ¡¢Æ°ºî³Îǧ¤Î¥Æ¥¹¥È¤ò¤ä¤Ã¤Æ¤ß¤¿ `2h/11/S¡£ ¤½¤ÎÍͻҤϤ³¤ÎÉÕÏ¿ ¤Î¹¹¤Ë²¼¤ÎÊý¤Ëµ­ºÜ¤·¤¿¡£Á°¤Ë¥Æ¥¹¥È¤·¤¿ºÝ¤Ë¤Ï¤Ç¤­¤Ê¤«¤Ã¤¿¤³¤È¤¬¤Ç¤­¤¿¡£ FortiGate ¤Î¥×¥í¥­¥·¥µ¡Ý¥Ðµ¡Ç½¤È£Ä£Î£Ó¥µ¡Ý¥Ðµ¡Ç½¤È¡¢ËÜÂΤǤΣģΣӻØÄê¤ËÍí¤àµóÆ°¤Ë´Ø¤·¤Æ¤Ç ¤¢¤ë¡£FortiGate ¤Ç¼ÒÆâÍѣģΣӥµ¡Ý¥Ð¤â¤Ç¤­¤ë¤³¤È¤¬Ê¬¤«¤Ã¤¿¡£ * ¥Æ¥¹¥È£¶:FortiGate ¤Ç¤Þ¤º¤Ï£×£Á£Æ£ÓÆ°ºî¤ÎÍͻҤò¸«¤ë¡Ý¤½¤Î£± ¥Õ¥£¡Ý¥Á¥ã¡ÝÁªÂò¤Ç¤Ï "WANºÇŬ²½&¥­¥ã¥Ã¥·¥å" ¤ò¥ª¥ó¤·¤¿¡£¥á¥¤¥ó¤Î¥á¥Ë¥å¡Ý¤Ë½Ð¤Æ¤­ ¤¿¡£¥×¥í¥­¥·¤È£×£Á£Æ£Ó¤ò¤É¤¦·ë¤ÓÉÕ¤±¤ë¤Î¤«¡£ÊÄ°è´Ä¶­¤Ç¥Æ¥¹¥È¤·¤è¤¦¤«¡£Windowx XP ¤ËÃÙ±äȯÀ¸¥½¥Õ¥È¥¦¥§¥¢¤òºÜ¤»¤Ê¤¤¤±¤Ê¤¤¡£ £×£Á£Æ£Óµ¡Ç½¤¬¤¢¤ë FortiClient ¤ò¥Ñ¥½¥³ ¥ó¤Ë¥¤¥ó¥¹¥È¡Ý¥ë¤¹¤ì¤Ð¥Æ¥¹¥È¤Ï¤Ç¤­¤ë¤Î¤Ç¤Ê¤¤¤«¡£ ¤½¤ÎÁ°¤Ë "WANºÇŬ²½&¥­¥ã¥Ã¥·¥å" ¤Î´ðËÜŪ¤ÊÀßÄê¤Î»ÅÊý¤¬Ê¬¤«¤é¤Ê¤¤¤È¡£¤È¤ê¤¢¤¨¤º¥Æ¥¹¥È£µ¤Î¹½À®¤Ç£×£Á£Æ£ÓÀßÄê¡¢¥×¥í ¥­¥·¤Ï»È¤ï¤º¡¢Qube3 ¤Î Web ¤È FTP ¥¢¥¯¥»¥¹¤òÂоݤˣףÁ£Æ£Ó¤¬¤É¤¦¤Ê¤ë¤«¥Æ¥¹¥È¤¹¤ë¡£ Qube3¢¢ ---------- ¢¤PC ¿ʬ lan->wan1 ¤Ø¤Î¥¢¥¯¥»¥¹¤Ç¡¢Qube3 ¡Ã.8 NAT| WAFS |.1 ¡Ã.2 ¤Ë¤Ä¤¤¤Æ²¿¤È¤«¤·¤¿¤¤¡£¥Õ¥¡¥¤¥ë¥¢¥¯¥» ----------------| FG100D |--------------- ¥¹¤Î¹â®²½¤ò¤·¤¿¤¤¡¢¤½¤ÎÀßÄê¤ò¤·¤è¤¦ 192.168.1.0 wan1----------lan 192.168.2.0 ¤È¤¤¤¦¤³¤È¤Ç¤Ê¤¤¤Î¤«¡£ IPv4 ¥Ý¥ê¥·¡Ý ----------------------------------------------- | ̾Á° [ ] << ¤³¤³¤â²¿¤«½ñ¤«¤Ê¤¤¤ÈÀßÄꤷ¤Æ[ŬÍÑ]¥¯¥ê¥Ã | ÆþÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ lan ] ¥¯¤·¤Æ¤âÀßÄê¤Ç¤­¤Æ¤¤¤Ê¤¤¡£ [¥Õ¥£¡Ý¥Á¥ã¡Ý | ½ÐÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ wan1 ¡ß] ÁªÂò] ¤Ç "̾Á°¤Ê¤·¥Ý¥ê¥·¡Ýµö²Ä" ¤ò¥ª¥ó¤Ë¡£ | Á÷¿®¸µ [ all ¡ß] | °¸À襢¥É¥ì¥¹ [ all ¡ß] << Qube3 ¤ËÊѹ¹¡£ | ¥µ¡Ý¥Ó¥¹ [ ALL ¡ß] | ¥¢¥¯¥·¥ç¥ó ¡ºACCEPT|(/)DENY|¢®LEARN| | | ¥Õ¥¡¥¤¥¢¥¦¥©¡Ý¥ë/¥Í¥Ã¥È¥ï¡Ý¥¯¥ª¥×¥·¥ç¥ó | | NAT ( ¡ü) | Web¥­¥ã¥Ã¥·¥å (¡û ) | WANºÇŬ²½ (¡û ) << ɽ¼¨¤Ï¤¢¤ë¤¬ÁªÂò¤Ç¤­¤Ê¤¤¡£¤³¤ì¤òÁª¤Ö»ö¤¬¤Ç¤­¤Ê¤±¤ì¤Ð | Á°¤Ë¿Ê¤Þ¤Ê¤¤¡£ ¤Ò¤ç¤Ã¤È¤·¤ÆÂиþ¤¹¤ë FortiGate ¤â»ØÄê | ¥»¥­¥å¥ê¥Æ¥£¥×¥í¥Õ¥¡¥¤¥ë ¤»¤Ê¤¤¤«¤ó¤Î¤«¡£ [WANºÇŬ²½&¥­¥ã¥Ã¥·¥å]->[¥Ô¥¢] ¤Ë¤Æ¡£ | | ¤·¤«¤· FortiGate £±Âæ¤È FortiClient ¤Ç¤ä¤ì¤ë¤Ï¤º¤À¤¬¡£ * ¥Æ¥¹¥È£·:FortiGate ¤Ç¤Þ¤º¤Ï£×£Á£Æ£ÓÆ°ºî¤ÎÍͻҤò¸«¤ë¡Ý¤½¤Î£² ¼ê¸µ¤Ë FortiGate-80C ¤â¤¢¤ë¡£¤³¤ì¤Ï¥¹¥È¥ì¡Ý¥¸¤¬ 8GB ¤¢¤ë¤È¥«¥¿¥í¥°¥¹¥Ú¥Ã¥¯¤Ë½ñ¤« ¤ì¤Æ¤¢¤Ã¤¿¡£FortiOS ¤Ïº£ v5.2.10¡¢¤Ò¤ç¤Ã¤È¤¹¤ë¤È£×£Á£Æ£Ó¤¬¤Ç¤­¤ë¤«¤â¡£¤³¤ì¤Þ¤Ç¿¨ ¤Ã¤Æ¤­¤Æ£×£Á£Æ£Ó¤Î¥á¥Ë¥å¡Ý¤Ï¸«¤¿¤³¤È¤Ï¤Ê¤«¤Ã¤¿¤è¤¦¤Ë»×¤¦¤±¤É¡£FortiGate-100D¤Ç¤â ¥á¥Ë¥å¡Ý¤ÏºÇ½é¤Ê¤«¤Ã¤¿¡£Â¿Ê¬ [¥·¥¹¥Æ¥à]->[¹âÅÙ] ¤Î¥Ç¥£¥¹¥¯ÀßÄê¤ò¤ä¤é¤Ê¤¤¤È¥À¥á¡£ ¤È¤ê¤¢¤¨¤º¤³¤³¤é¤Ç¥É¥­¥å¥á¥ó¥È¤òÆɤó¤Ç¤ß¤ë¤È¤¹¤ë¤«¡¢±Ñʸ¤Î http://help.fortinet. com/fos50hlp/ Æâ¤Î "Configuring WAN optimization" £±£¸¥Ú¡Ý¥¸¡£¥×¥ê¥ó¥È¤·¤¿¤é¤Û¤È ¤ó¤É¥Ö¥é¥ó¥¯¤Î¥Ú¡Ý¥¸¤â¤É¤ó¤É¤ó½Ð¤Æ¤¯¤ë¤Î¤Ç¹²¤Æ¤Æ»ß¤á¤¿¡£¤Û¤«¤Ã¤Æ¤ª¤¤¤¿¤éÉ´¥Ú¡Ý¥¸ ¤â½Ð¤ë¤È¤³¤í¤À¤Ã¤¿¡£¼¡¤ÎÆü¡¢³Ý¤«¤êÉÕ¤±¤Îɱ¡¤Ç¤ÎÂÔ¤Á»þ´Ö¤ËȾʬ¤°¤é¤¤Æɤó¤Ç¤ß¤¿¡£ ¢¢Qube3 Qube3¢¢ ---------- ---------- ¢¤PC .8¡Ã192.168.1.0 ¡Ã.8 NAT| WAFS |.1 .4|WAFSÆ©²á|.3 ¡Ã.2 ------------------ ----------------| FG100D |--------| FG80C |------------ wan1|NAT 192.168.1.0 wan1----------lan ---------- 192.168.2.0 ------------- | FG100D | ------------- Âиþ¤¹¤ë FortiGate ¤Î¥¯¥é¥¤¥¢¥ó¥È¦¤Ç¤¢¤ë»Ù¼Ò¤ÎÊý¤Ç¡¢ ËÜ lan|.1 ¼Ò¤Î¤É¤Î¥µ¡Ý¥Ð¤ò£×£Á£Æ£ÓÂоݤˤ¹¤ë¤«»ØÄꤹ¤ë¡£ | | Manual À©¸æ¤È Ative-Passive À©¸æ¤¬¤¢¤ë¡£ManualÀ©¸æ¤Ï£²ÅÀ wan1|.4 ´Ö Peer-to-Peer¡¢FortiGate ÂиþÀßÃ֤δ֤Ǥι⮲½ÀßÄê¡£ ------------- | FG80C Æ©²á| ¥¯¥é¥¤¥¢¥ó¥È¦¤Î¥Ý¥ê¥·¡Ý¤Î¥Þ¥Ë¥å¥¢¥ëÀ©¸æ¤Ï¥³¥Þ¥ó¥É¥é¥¤¥ó ------------- ¢¤PC ¤ÇÀßÄꤷ¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¡£ lan|.3 ¡Ã.2 ------------------ ¶È¼Ô¤Îµ»½Ñ¼Ô¤Ë¤â¤é¤Ã¤¿¥Ò¥ó¥È¤Ç¤Ï¥Þ¥Ë¥å¥¢¥ëÀ©¸æ¤ÇÆ©²á¥â¡Ý 192.168.2.0 ¥É( Transparent ) ¤Ï̵¤·¤ÇÀßÄꤷ¤Æ¤¤¤¤¤Î¤Ç¤Ê¤¤¤«¤È¤¤¤¦¡£ FortiGate-80C ¤À¤á¤«¡©¡£[¥°¥í¡Ý¥Ð¥ë]->[ÀßÄê]->[¹âÅÙ] "¥Ç¥£¥¹¥¯´ÉÍý" ¤È¤¤¤¦¤Î¤¬¤¢ ¤Ã¤Æ "No disks avaiilabe" ¤È½Ð¤Æ¤¤¤ë¡£[¥Õ¥£¡Ý¥Á¥ã¡Ý] ¤Ë WANºÇŬ²½ ¤Ï¸«Åö¤¿¤é¤Ê¤¤¡£ »ÄÇ°¤Ê¤¬¤é£×£Á£Æ£Ó¤Î¸¡Æ¤¤Ï¤³¤³¤Ç°ìöÃæÃǤÀ¡£FortiGate-100D ¤È 80C ¤È¤ÇÆ°ºî³Îǧ¤Ç ¤­¤ë¤À¤í¤¦¤È»×¤Ã¤¿¤Î¤À¤¬¡£¤½¤ì¤Ë¤·¤Æ¤â¤ª¤«¤·¤Ê¡¢¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ë FortiGate-80C¤Ç £×£Á£Æ£Ó¤â¤Ç¤­¤ë¤È½ñ¤«¤ì¤Æ¤¤¤ë¤Î¤ò¸«¤¿¤±¤É¡£È¯ÇäÆü¤Ç¥Ç¥£¥¹¥¯Í­¤ê̵¤·¤¬¤¢¤ë¤È¤«¡©¡£ ¤¤¤ä FortiOS ¤¬ v4.x Âå¤Ê¤é¤¤¤±¤ë¤«¤âÃΤì¤Ê¤¤¡£v5.x ¤Ç¤Ïµ¡Ç½¥¢¥Ã¥×¤Ê¤É¤Î¤¿¤áÉé²Ù ¤¬Â礭¤¯¤Ê¤Ã¤Æ£×£Á£Æ£Ó¤Ï¥µ¥Ý¡Ý¥È³°¤Ë¤·¤¿¤Î¤«¤âÃΤì¤Ê¤¤¡£¤¤¤Ã¤Ú¤ó£Ï£Ó¤ò¥À¥¦¥ó¥°¥ì ¡Ý¥É¤·¤Æ¤ß¤ë¤«¡££Ó£É¶È¼Ô¤Î Fortinet ¥µ¥Ý¡Ý¥È¤Î¥µ¥¤¥È¤Ë¥í¥°¥¤¥ó¤·¤Æ v4.x Âå¤ÎºÇ¸å ¤Î¥Ð¡Ý¥¸¥ç¥ó¤ò¼è¤Ã¤¿¡£ OS 4.0MR3P9¡¢FGT_80C-v400-build0637-FORTINET.out¡¢FortiOS v4.0.9,¥Ó¥ë¥É 637¡£²èÌÌ¤Ç "¢¢¥Ð¡Ý¥¸¥ç¥ó¤Î¥À¥¦¥ó¥í¡Ý¥É¤ò³Îǧ" ¤Î½ê¤Ë¡ºÆþ¤ì¤Æ³«»Ï¡£ ²èÌ̤ǤϤº¤Ã¤È reboot Ãæ¤È½Ð¤Æ¤¤¤¿¤¬¡¢£±Ê¬¤°¤é¤¤¤Ç¼Â¤Ïµ¯Æ°¤·¤Æ¤¤¤¿¤ß¤¿¤¤¡£¥¢¥¯¥» ¥¹¤Ï Mozilla ¤è¤ê IE ¤ÎÊý¤¬¤¤¤¤¤«¤â¡¢IE 9 ¤Ç¤¹¤¬¡££Ì£Á£Î¦¤«¤é¤â£×£Á£Î¦¤«¤é¤â¥¢ ¥¯¥»¥¹¤Ç¤­¤¿¡£ÀßÄꤷ¤Æ¤¢¤Ã¤¿¤Î¤Ï¤¶¤Ã¤È¸«¤Æ¤Û¤È¤ó¤É¤½¤Î¤Þ¤Þ¡¢ºî¤Ã¤¿ VDOM ¤â¤½¤Î¤Þ ¤Þ¤À¤Ã¤¿¡£WANºÇŬ²½¤Î¥á¥Ë¥å¡Ý¤¬¸«Åö¤¿¤é¤Ê¤¤¡£ G->[¥·¥¹¥Æ¥à]->[ÀßÄê]->[¾ÜºÙ] ²èÌÌ ¤Ç "¥Ç¥£¥¹¥¯´ÉÍý" ¤Î FLASH(0MB of 0MB)[¥Õ¥©¡Ý¥Þ¥Ã¥È]¡¢¥¯¥ê¥Ã¥¯¤·¤Æ¤âÊѲ½¤Ê¤·¡£ FLASH(0MB of 0MB)[¥Õ¥©¡Ý¥Þ¥Ã¥È] -------------------------------------------------------------------------------- | ¥Õ¥£¡Ý¥Á¥ã¡Ý | ¥¹¥È¥ì¡Ý¥¸¥µ¥¤¥º | ³ä¤êÅö¤ÆºÑ¤ß | »ÈÍÑºÑ¤ß | ¥¯¥ª¡Ý¥¿»ÈÍÑºÑ¤ß | -------------------------------------------------------------------------------- ºÆµ¯Æ°¤Î¥á¥Ë¥å¡Ý¤¬¸«Åö¤¿¤é¤Ê¤¤¡¢¥³¥ó¥½¡Ý¥ë¤Ç # config global¡¢# exec reboot ¤ä¤Ã ¤¿¡£[¥À¥Ã¥·¥å¥Ü¡Ý¥É] ¤Î [Status] ¤Ë "¥æ¥Ë¥Ã¥È¥ª¥Ú¥ì¡Ý¥·¥ç¥ó"¤òÄɲÃɽ¼¨¤¹¤ì¤ÐºÆµ¯ Æ°¤Î¥á¥Ë¥å¡Ý¤Ï¤Ç¤Æ¤­¤¿¡£Á´ÂβèÌ̤α¦¾å¤Î {¥Ø¥ë¥×} ¤ò¥¯¥ê¥Ã¥¯¤·¤¿¤é¡¢¾Ü¤·¤¤ÀâÌÀ¤¬ ½Ð¤Æ¤­¤¿¡£Chapter 17 WAN Optimization ¤Î¤È¤³¤í Formatting the hard disk ¤Î¤¯¤À¤ê¡¢ FortiGate-51B ¤òÎã¤Ë execute disk list ¤È¤ä¤ë¤È¤¤¤¦¤è¤¦¤Ë½ñ¤«¤ì¤Æ¤¤¤ë¡£ 80C ¤Ç¤³¤Î¥³¥Þ¥ó¥Éᤤ¤Æ¤â̵ȿ±þ¤Ç¤¢¤ë¡£# execute ? ¤ä¤Ã¤Æ»È¤¨¤ë¥³¥Þ¥ó¥É¤Î°ìÍ÷¤ò ¸«¤¿¤±¤É disk ¤Îʸ»ú¤¬¤Ê¤¤¡£80C ¤Ë£Õ£Ó£Â¥á¥â¥ê¤ò£±¤Äº¹¤·¤ÆºÆµ¯Æ°¤·¤Æ¤ß¤¿¡£ FLASH ¤Î (0MB of 0MB) ¤Ï 0MB ¤Î¤Þ¤Þ¤À¤Ã¤¿¡£ ²þ¤á¤Æ¥Í¥Ã¥È¤òÄ´¤Ù¤¿¤é Ver 4.0 MR3 Patch12 ¤Ç 80C ¤Ï¥¢¥Ã¥×¥Ç¡Ý¥È¸å¡¢ ¥Ï¡Ý¥É¥Ç¥£¥¹¥¯¥í¥°Êݸ¤Î¥³¥Þ¥ó¥É¤¬Ìµ¤¯¤Ê¤ë¤È¤¤¤¦µ­½Ò¤ò ¸«¤Ä¤±¤¿¡£flash disk ¤Ïµ­²±ÁǻҤȤ·¤Æ½ñ¤­¹þ¤ß¾Ãµî²ó¿ô¤Ë¸Â¤ê¤¬¤¢¤ë¤¿¤á¤Îµ¡Ç½Êѹ¹¡£ ¤Ò¤ç¤Ã¤È¤·¤Æ v4.x ¤Ç¤â½é´ü¤Î¥Ð¡Ý¥¸¥ç¥ó¤Ê¤é¡¢¥Ç¥£¥¹¥¯¤ò¥µ¥Ý¡Ý¥È¤·¤Æ¤¤¤ë¤«¤â¤È»×¤¤ OS 4.0MR1P1¡¢FGT_80C-v400-build0185-FORTINET.out ¤ò¤¤¤ì¤¿¡£ ¥À¥á¡¢¤É¤³¤Ë¤â Flash ¤È¤«¥Ç¥£¥¹¥¯¤È¤«¤¤¤¦¤Î¤¬Ìµ¤«¤Ã¤¿¡££Õ£Ó£Â¥á¥â¥ê¤Ï¤³¤³¤Ç¤Ï´Ø·¸¤Ê¤¤¡£ ¤³¤³¤Þ¤Ç VDOM ¤Ï¤½¤Î¤Þ¤Þ¤Ë¤·¤Æ¤ä¤Ã¤Æ¤­¤¿¡¢¸å¤ä¤ë¤È¤¹¤ì¤Ð VDOM ¤ò̵¤¯¤·¤Æ¤«¡£¤Ò¤ç¤Ã¤È¤¹¤ë¤È 80C ¤Ç¤Ï¸Å¤¤¥Õ¥¡¡Ý¥à¥¦¥§¥¢¤Ê¤é¥³¥Þ¥ó¥É¤Ç£×£Á£Æ£ÓÀßÄ꤬¤Ç¤­¤ë¤«¤âÃΤì¤Ê¤¤¡£ ¡ü FortiGate ¤Î¥×¥í¥­¥·¤È£Ä£Î£Ó¤òºÆ¤Ó¥Æ¥¹¥È `2h/11/S * ¥Æ¥¹¥È£Á ¡§Internet ¢¢Qube3 ¥Ñ¥½¥³¥ó PC ¤Î¥Ö¥é¥¦¥¶¤Ç¥×¥í¥­¥·»ØÄꤷ¤Æ¡£ ¡§ .8¡Ã ---------------------------------- http://qqq1/ ¤È http://coba.nix.co.jj/ wan1|.1 NAT 192.168.1.0 ------------- ¤È¤¤¤¦¥¢¥¯¥»¥¹¤¬¤Ç¤­¤¿¡£¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Î | | DNS»ØÄê {FortiGuard http://asahi.com/ ¤È¤«¤â¥¢¥¯¥»¥¹¤Ï¤Ç¤­¤¿¡£ | FG100D | ¥µ¡Ý¥Ð¤òÍøÍÑ}¤È¤¹¤ë ¤·¤«¤·²¿¤«²èÌ̤¬½Ð¤ë¤Î¤¬ÃÙ¤¤¤Ê¡Ý¡£ | v5.4.3 | ------------- PC¢¤IE ¥×¥í¥­¥·»ØÄê [¥Í¥Ã¥È¥ï¡Ý¥¯]->[DNS¥µ¡Ý¥Ð] ¤Ë¼ÒÆ⥵¡Ý¥Ð lan|.1 .2¡Ã 192.168.2.1 ÍѤΥ¨¥ó¥È¥ê¤òºî¤Ã¤¿¡£¥×¥í¥­¥·¥µ¡Ý¥Ð¤ÎÀß ---------------------------------- Äê¤â¤·¤¿¡¢HTTP¥Ý¡Ý¥È 8080¡£VDOM ¤Ê¤·¤Ë¤Æ¡£ 192.168.2.0 ¥µ¡Ý¥Ð¤Î¥Ý¡Ý¥ÈÈֹ椬¤¤¤í¤¤¤í¤Ë¤Ê¤Ã¤Æ¤¤¤ë¡¢¥×¥í¥­¥·¤ò²ð¤¹¤ë¥¢¥¯¥»¥¹¤Î³Îǧ¤òº£°ìÅÙ ¤·¤Æ¤ª¤¯¡£Qube3 ¤Î´ÉÍý²èÌ̤ΥݡݥÈÈÖ¹æ¤Ï 444 ¤Ç http://192.168.1.8:444/ ¤Ç¤Þ¤·¤¿¡£ IWSS ²èÌ̲èÌ̤ؤ⥢¥¯¥»¥¹¤Ç¤­¤¿¡¢http://192.168.1.x:1812/¡£ ¤³¤Î IWSS ¤Î¥×¥í¥­¥· ÀßÄê¤Ç¤Ï¥Ý¡Ý¥ÈÈÖ¹æ¤Ï¤¤¤Á¤¤¤Áµ­ºÜ¤·¤Ê¤¤¤È¤À¤á¤Ç¤¢¤ë¡£FortiGate ¤Ç¤Ï¤½¤ì¤Ï¤Ê¤¤¡£ [¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[IPv4¥Ý¥ê¥·¡Ý] -------------------------------------------------------------------------------- | ¹àÈÖ Ì¾Á° Á÷¿®¸µ °¸Àè ¥µ¡Ý¥Ó¥¹ ¥¢¥¯¥·¥ç¥ó NAT ¥»¥­¥å¥ê¥Æ¥£¥×¥í¥Õ |----------------------------------------------------------------- ¥¡¥¤¥ë | lan - wan1 |------------------------------------------------------------------------------- | 1 all all ALL ¡ºACECPT ¡ºÍ­¸ú [+] |------------------------------------------------------------------------------- | 2 Implicit Deny all all ALL (/)DENY ¡ß̵¸ú -------------------------------------------------------------------------------- [¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[Explicit¥×¥í¥­¥· ¥Ý¥ê¥·¡Ý] ---------------------------------------------------------------------------- | ¹àÈÖ Á÷¿®¸µ °¸Àè ¥¢¥¯¥·¥ç¥ó ¥»¥­¥å¥ê¥Æ¥£¥×¥í¥Õ¥¡¥¤¥ë ¥í¥° ¥Ð¥¤¥È |--------------------------------------------------------------------------- | [-]web proxy - wan1 |--------------------------------------------------------------------------- | 1 all all ¡ºACECPT [+] UTM 1.51MB ------------¢¬-------------------------------------------------------------- ¡Ã ¥¯¥ê¥Ã¥¯¤·¤Æ½Ð¤¿¤Î¤¬²¼µ­¡£ [¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[Explicit¥×¥í¥­¥· ¥Ý¥ê¥·¡Ý] ---------------------------------------------------------------------- |Explicit¥×¥í¥­¥·¥¿¥¤¥× [Web]|FTP| | | Í­¸ú¤Ë¤Ê¤Ã¤Æ¤¤¤ë¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ lan | ½ÐÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ wan1 ] | Á÷¿®¸µ¥¢¥É¥ì¥¹ [ all ] | °¸À襢¥É¥ì¥¹ [ all ] | ¥¢¥¯¥·¥ç¥ó [¡ºACCEPT]|(/)DENY|¡÷AUTHENTICATE| | |¥»¥­¥å¥ê¥Æ¥£¥×¥í¥Õ¥¡¥¤¥ë | ¥¢¥ó¥Á¥¦¥£¥ë¥¹ (¡û ) << ¥ª¥ó¤Ë¤·¤¿¤é "¥×¥í¥­¥·¥ª¥×¥·¥ç¥ó"¤È¤¤¤¦¤Î | SSL/SSH¥¤¥ó¥¹¥Ú¥¯¥·¥ç¥ó (¡û ) ¤â½Ð¤Æ¤­¤¿¡£[AV default],[PRX default] ¤Î | £²¤Ä¤òÁª¤ó¤À¤³¤È¤Ë¤Ê¤ë¡£ |¥Õ¥¡¥¤¥¢¥¦¥©¡Ý¥ë/¥Í¥Ã¥È¥ï¡Ý¥¯¥ª¥×¥·¥ç¥ó | Web¥­¥ã¥Ã¥·¥å (¡û ) [¥Í¥Ã¥È¥ï¡Ý¥¯]->[¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹] "¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹Ì¾ lan"¡¢"¥¿¥¤¥× ¥Ï¡Ý¥É¥¦¥§¥¢¥¹¥¤¥Ã¥Á"¡¢"ʪÍý¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹¥á ¥ó¥Ð port3¡Áport16" ¤Ç port3 ¤Ë¥Í¥Ã¥È¥ï¡Ý¥¯¥±¡Ý¥Ö¥ëÀܳ ¡¢"¥í¡Ý¥ë(i) LAN"¡¢"¥¢¥É ¥ì¥Ã¥·¥ó¥°¥â¡Ý¥É ¥Þ¥Ë¥å¥¢¥ë"¡¢"IP/¥Í¥Ã¥È¥ï¡Ý¥¯¥Þ¥¹¥¯ 192.168.2.1/255.255.255.0" ¤½¤Î¾¤ÎÀßÄê¤Ç "STP ( ¡ü)"¡¢"Botnet¥µ¥¤¥È¤ØÀܳ¤¹¤ë¥³¥Í¥¯¥·¥ç¥ó¤ò¥¹¥­¥ã¥ó [̵¸ú] ¥Ö¥í¥Ã¥¯|¥â¥Ë¥¿"¡¢"Explicit Web¥×¥í¥­¥·¤òÍ­¸ú ( ¡ü)"¡£ [¥Í¥Ã¥È¥ï¡Ý¥¯]->[Explicit¥×¥í¥­¥·] --------------------------------------------------------------- |( ¡ü) Explicit Web¥×¥í¥­¥· | | Listen¤¹¤ë¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ lan ¡ß] | HTTP¥Ý¡Ý¥È [ 8080 ] | HTTPS¥Ý¡Ý¥È [Use HTTP Port]|Specify| | FTP over HTTP (¡û ) | ¥×¥í¥­¥·¼«Æ°ÀßÄê(PAC) (¡û ) | | | ¥Ç¥Õ¥©¥ë¥È¤Î¥Õ¥¡¥¤¥¢¥¦¥©¡Ý¥ë¥Ý¥ê¥·¡Ý¤Î¥¢¥¯¥·¥ç¥ó |µö²Ä|[µñÈÝ] | [-] Web¥×¥í¥­¥·¥Õ¥©¥ï¡Ý¥Ç¥£¥ó¥°¥µ¡Ý¥Ð | [-] URL¥Þ¥Ã¥Á¥ê¥¹¥È [¥Í¥Ã¥È¥ï¡Ý¥¯]->[DNS¥µ¡Ý¥Ð] ------------------------------------------------------------------- |¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹¾å¤ÎDNS¥µ¡Ý¥Ó¥¹ |------------------------------------------------------------------ | ¢¢ ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ ¥â¡Ý¥É |------------------------------------------------------------------ | ¢¢ lan ºÆµ¢¸¡º÷ |------------------------------------------------------------------ | |DNS¥Ç¡Ý¥¿¥Ù¡Ý¥¹ |------------------------------------------------------------------ | ¢¢ DNS¥¾¡Ý¥ó ¥É¥á¥¤¥ó̾ ¥¿¥¤¥× ³Îǧ TTL ¥¨¥ó¥È¥ê¿ô |------------------------------------------------------------------ | ¢¢ zone1 qqq1 ¥Þ¥¹¥¿ ¥·¥ã¥É¡Ý 86400 2 |------------------------------------------------------------------ | ¢¢ zone2 nix.co.jj ¥Þ¥¹¥¿ ¥·¥ã¥É¡Ý 86400 1 ------------------------------------------------------------------- zone1 ¤Î DNS¥¨¥ó¥È¥ê -------------------------------------------------- | DNS¥¾¡Ý¥ó¤ÎÊÔ½¸ |------------------------------------------------- | ¥¿¥¤¥× ¡ý¥Þ¥¹¥¿ ³Îǧ ¡ý¥·¥ã¥É¡Ý¤Ê¤É << "¥·¥ã¥É¡Ý" ¤Ë¤¹¤ë¤Î¤¬¤­¤â¡£ | ¥×¥é¥¤¥Þ¥ê¡Ý¥Þ¥¹¥¿¡Ý¤Î¥Û¥¹¥È̾ dns | | DNS¥¨¥ó¥È¥ê |------------------------------------------------- | ¢¢ ¡ô ¥¿¥¤¥× ¾ÜºÙ |------------------------------------------------- | ¢¢ 1 ¥Í¡Ý¥à¥µ¡Ý¥Ð(NS) qqq1 << ¤³¤ì¤é£²¤Ä¤Ç http://qqq1/ |------------------------------------------------- | ¢¢ 2 ¥¢¥É¥ì¥¹(A) qqq1. -> 192.168.1.8 << ¤È¤¤¤¦¥¢¥¯¥»¥¹¤¬¤Ç¤­¤ë¡£ -------------------------------------------------- ¢¨¼Â¤Ï£²£°£±£·Ç¯£³·î¤Ë¤³¤Î¥Æ zone2 ¤Î DNS¥¨¥ó¥È¥ê ¥¹¥È¤ò¤·¤Æ³Îǧ¤·¤Æ¤¤¤¿¡£ -------------------------------------------------- | DNS¥¾¡Ý¥ó¤ÎÊÔ½¸ |------------------------------------------------- | ¥¿¥¤¥× ¡ý¥Þ¥¹¥¿ ³Îǧ ¡ý¥·¥ã¥É¡Ý¤Ê¤É | ¥×¥é¥¤¥Þ¥ê¡Ý¥Þ¥¹¥¿¡Ý¤Î¥Û¥¹¥È̾ dns | | DNS¥¨¥ó¥È¥ê |------------------------------------------------- | ¢¢ ¡ô ¥¿¥¤¥× ¾ÜºÙ |------------------------------------------------- | ¢¢ 1 ¥¢¥É¥ì¥¹(A) coba. -> 192.168.1.8 -------------------------------------------------- * ¥Æ¥¹¥È£Â DNS1¢¢ DNS2¢¢ ¢¢¢¢FortiGuard»ØÄê ¥Ñ¥½¥³¥ó PC ¤Î¥Ö¥é¥¦¥¶¤Ç¥×¥í¥­¥·»ØÄꤷ¤Æ¡£ X.1¡Ã X.2¡Ã ¡Ã¡Ã208.91.112.53,52 ¡¿¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡À http://qqq1/ ¤È http://coba.nix.co.jj/ ¡À¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡¿ ¡§ ¤È¤¤¤¦¥¢¥¯¥»¥¹¤¬¤Ç¤­¤¿¡£¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Î ¡§ ¢¢Qube3 ¢¢¼ÒÆâÍÑ http://asahi.com/ ¤È¤«¤â¥¢¥¯¥»¥¹¤Ï¤Ç¤­¤¿¡£ ¡§ .8¡Ã .7¡ÃDNS ²¿¤«²èÌ̤¬½Ð¤ë¤Î¤¬ÃÙ¤¤¡£100D ¤Î DNS »ØÄê ---------------------------------- 192.168.1.7 ¤ËÊѤ¨¤Æ¤ß¤¿¤é¡¢¤³¤Ã¤Á¤ÎÊý¤Ï wan1|.1 NAT 192.168.1.0 ¤¹¤°¤Ëɽ¼¨¤·¤Æ¤­¤¿¡£FortiGuard¥µ¡Ý¥Ð¤Ç¤Î ------------- 208.91.112.53 ¤Ïº®¤ó¤Ç¤¤¤ë¤Î¤Ç¤Ê¤¤¤«¡£¼Ò | | DNS»ØÄê {FortiGuard ÆâÍÑDNS¥µ¡Ý¥Ð¤¬»ý¤Ä¥¨¥ó¥È¥ê http://svr1/ | FG100D | ¥µ¡Ý¥Ð¤òÍøÍÑ}¤È¤¹¤ë ¥¢¥¯¥»¥¹¤Ç¤­¤¿¡£ http://qqq1/ ¤â¥¢¥¯¥»¥¹ | | ¤Ç¤­¤¿¡£100D ¤Î DNS»ØÄê¤ò X.1 ¤Ë¤·¤Æ¤ß¤¿¡¢ ------------- PC¢¤IE ¥×¥í¥­¥·»ØÄê ¤³¤ì¤â http://asahi.com/²èÌ̤Ϥ¹¤°¤Ë½Ð¤Æ lan|.1 .2¡Ã 192.168.2.1 ¤­¤¿¡£ http://qqq1/ ²èÌ̤⤹¤°¤Ë¤Ç¤Æ¤­¤¿¡£ ---------------------------------- DNS1,DNS2 ¤Ï¼«¼Ò£Ä£Î£Ó¥µ¡Ý¥Ð¤Î¥×¥é¥¤¥Þ¥ê 192.168.2.0 ¤È¥»¥«¥ó¥À¥ê¤Ç¥×¥í¥Ð¥¤¥À¤Ë´ÉÍý°ÑÂ÷¤·¤Æ¤ë¡£ ¤³¤ì¤é¤Î¤³¤È¤òƧ¤Þ¤¨¤Æ FortiGateËÜÂΤǤΠDNS»ØÄê¤Ï¤É¤¦¤¹¤ë¤Î¤¬¤¤¤¤¤«¹Í¤¨¤ë¡£¥Ñ¥Ã ¤È»×¤¤ÉÕ¤¤¤¿¤Î¤Ï¥Ï¥¤¥Ö¥ê¥Ã¥É»ØÄê¤Ç¤¢¤ë¡£¼ÒÆâÍÑDNS ¤Ï¥Ö¥é¥¦¥¶¤Î¥×¥í¥­¥·ÍøÍÑ¤Ç¤Ï¤Ê ¤¯¤Æ¤â¹½¤ï¤Ê¤¤¤Î¤Ç¤Ê¤¤¤«¡£FortiGate Æâ¤Î DNS¥µ¡Ý¥Ð¤Ç¤Þ¤«¤Ê¤¨¤ë¤³¤È¤¬Ê¬¤«¤Ã¤¿¤Î¤Ç¡£ ¼ÒÆâÍÑ DNS ¤Ï¥×¥í¥­¥·ÍøÍѤǤʤ¤ telnet ¤ä FTP ¤Ê¤ÉľÀÜ¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ë¥¢¥¯¥»¥¹¤¹ ¤ëºÝ¤Ë¤ÏɬÍפÀ¤¬¡£Amazon EC2 ¤Ë½Ð¤·¤¿£Ä£Î£Ó¥µ¡Ý¥Ð DNS1¡¢²¿¤È´ÉÍý°ÑÂ÷¤·¤¿¥×¥í¥Ð¥¤ ¥À¤«¤é Amazon ¥µ¥¤¥É¤Ç¥á¥ó¥Æ¥Ê¥ó¥¹¤Î¤¿¤áÊ¿Æü¤Î£±£·»þ¤«¤é£²»þ´ÖÄä»ß¤Ë¤Ê¤ë¤ÈÏ¢Íí¤¬ ¤¢¤Ã¤¿¡£ÍøÍѻϤá¤ÆȾǯ¤â¤Ê¤é¤Ê¤¤¡£¤Û¤È¤ó¤É̵Ää»ß¤Ç±¿ÍѤµ¤ì¤ë¤â¤Î¤À¤È¤Ð¤«¤ê»×¤Ã¤Æ ¤¤¤¿¤Î¤Ë¡£¤³¤ì¤Ï¶Ã¤­¤Ç¤¢¤ë¡£¤È¤¤¤¦¤³¤È¤â¤¢¤ë¤Î¤Ç¡¢¸¡Æ¤¹Íθ¤Ë¤Ï´Þ¤á¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê ¤¤¡£¤·¤«¤·¼ÂºÝ¤Î¤È¤³¤íÄä»ß¤Ï¤Û¤È¤ó¤É̵¤«¤Ã¤¿¡¢¤É¤¦¤â°ì½Ö¤ÇºÑ¤ó¤À¤ß¤¿¤¤¤À¤Ã¤¿¡£ a) {FortiGuard¥µ¡Ý¥Ð¤òÍøÍÑ} 208.91.112.53 ¤È 52¡£ ¤³¤ì¤Ç¤¤¤¤¤«¤È»×¤Ã¤Æ¤¤¤¿¤¬¡£ b) ºÇ½é¤Ë Amazon EC2 ¤Î X.1¡¢¼¡¤Ë 208.91.112.53¡£ ¤³¤Ã¤Á¤ÎÊý¤¬±þÅú¤Ï®¤¯¤Ê¤ë¡£ * ¥Æ¥¹¥È£Ã [¥·¥¹¥Æ¥à]->[ÀßÄê]->{´ÉÍý¼ÔÀßÄê} ¤Ë¤Æ¡£"HTTP¥Ý¡Ý¥È [80 ]"¡¢"HTTPS ¤Ø¥ê¥À¥¤¥ì¥¯¥È ¥ª¥ó"¡¢"HTTPS¥Ý¡Ý¥È [443 ]"¡£ "HTTP¥Ý¡Ý¥È [8088 ]" ¤Ë¤·¤Æ¤ß¤¿¡¢[ŬÍÑ] ¥¯¥ê¥Ã¥¯¤·¤Æ¡£¥Ö¥é¥¦¥¶¤«¤é¥¢¥¯¥»¥¹¤Ç¤­¤º¡£ https://192.168.2.1/ ¤Þ¤¿¤Ï https://192.168.2.1:443/ ¤Ï£Ï£Ë¤À¤Ã¤¿¡£ £Ì£Á£Î¦¤«¤é http://192.168.2.1:8088/¡¢£×£Á£Î¦¤«¤é http://192.168.1.1:8088/¥¢¥¯ ¥»¥¹¡£ÁõÃÖ¤òºÆµ¯Æ°¤·¤Æ¤â¤À¤á¤À¤Ã¤¿¡£"HTTP¥Ý¡Ý¥È [444 ]" ¤È¤«¤â¥À¥á¤À¤Ã¤¿¡£ [¥Í¥Ã¥È¥ï¡Ý¥¯]->[Explicit¥×¥í¥­¥·] ------------------------------------------------------ |( ¡ü) Explicit Web¥×¥í¥­¥· | | Listen¤¹¤ë¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ lan ¡ß] | HTTP¥Ý¡Ý¥È [ 80 ] << 8080 ¤À¤Ã¤¿¤Î¤òÊѹ¹¤·¤¿¡£ | HTTPS¥Ý¡Ý¥È [Use HTTP Port]|Specify| ¾åµ­¤Î "HTTP¥Ý¡Ý¥È [8088 ]" ¤Ï¤½¤Î¤Þ¤Þ¤Ë¤·¤Æ¡£¥Ö¥é¥¦¥¶¤Ç¥×¥í¥­¥·»ØÄê¤ò 80 ¤ËÊѹ¹ ¤·¤¿¡¢¥ä¥Õ¡Ý¤Î¥µ¥¤¥È¤Ê¤É¥¢¥¯¥»¥¹¤Ç¤­¤º¡£ºÆµ¯Æ°¤·¤¿¤é¥¢¥¯¥»¥¹¤Ç¤­¤¿¡£ºÆµ¯Æ°¤·¤Ê¤¯ ¤Æ¤â¥Ý¡Ý¥ÈÈÖ¹æ¤òÊѤ¨¤¿¤À¤±¤ÇÀßÄêÊѹ¹¤ÏÍ­¸ú¤Ë¤Ê¤ë¤Î¤Ç¤Ê¤¤¤Î¤«¡¢¤É¤¦¤â¤è¤¯Ê¬¤«¤é¤Ê ¤¤¡£¤È¤ê¤¢¤¨¤º¥Æ¥¹¥È¤·¤¿·ë²Ì¤ò»ö¼Â¤Î¤Þ¤Þ½ñ¤¤¤¿¡£¥×¥í¥­¥·¥µ¡Ý¥Ð¤Î¥Ý¡Ý¥ÈÈÖ¹æ¤ò80ÈÖ ¤Ë¤·¤¿¤«¤Ã¤¿¤Î¤Ï½ÐÍ褿¤Î¤ÇÎɤ·¤È¤·¤è¤¦¤«¡£ FortiGate ¥Ø¤Î´ÉÍý¥¢¥¯¥»¥¹¤Ï https ¤Ç ¤ä¤ì¤Ð¤¤¤¤Ìõ¤À¤·¡£¤·¤«¤·µ¤»ý¤Á°­¤¤¡¢¤ä¤Ï¤ê¤Á¤ç¤Ã¤ÈÄ´¤Ù¤Æ¤ß¤Ê¤¤¤È¤¤¤±¤Ê¤¤¡£ * ¥Æ¥¹¥È£Ä ¥¦¥£¥ë¥¹¤Ê¤É¤Î¥»¥­¥å¥ê¥Æ¥£¥Á¥§¥Ã¥¯¤ò¤«¤±¤ë¾ì½ê¤Ï£²¥ö½ê¡£¥í¥°¤ò¼è¤ë¾ì½ê¤â£²¥ö½ê¤¢ ¤ë¡£¤³¤Î FortiGate ¤Ç¤Ï VDOM ¤Ï»È¤Ã¤Æ¤Ê¤¤¡£ ¤µ¤Æ¡¢¤É¤Á¤é¤Ç¥»¥­¥å¥ê¥Æ¥£¥Á¥§¥Ã¥¯¤ò ¤«¤±¤ë¤Î¤¬¤¤¤¤¤Î¤«¡£¥í¥°¤ò¼è¤ë¤È¤¹¤ì¤Ð¤É¤Á¤é¤¬¤¤¤¤¤Î¤«¡¢¤½¤ì¤È¤â°ÕÌ£¤È¤·¤Æ¤ÏÊÌ¡¹ ¤Ë¤Ê¤ë¤È¤¤¤¦¤³¤È¤Ç¼è¤ë¤Ê¤éξÊý¤Ç¹Ô¤Ê¤¦¤Î¤¬¤Î¤¬¤¤¤¤¤È¤«¡£ [¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[IPv4¥Ý¥ê¥·¡Ý] ------------------------------------------------------------------------ | ÆþÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ lan ] | ½ÐÎÏ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ [ wan1 ] | | |¥»¥­¥å¥ê¥Æ¥£¥×¥í¥Õ¥¡¥¤¥ë | ¥¢¥ó¥Á¥¦¥£¥ë¥¹ (¡û ) | |¥í¥®¥ó¥°¥ª¥×¥·¥ç¥ó | µö²Ä¥È¥é¥Õ¥£¥Ã¥¯¤ò¥í¥° ( ¡ü)[¥»¥­¥å¥ê¥Æ¥£¥¤¥Ù¥ó¥È]|¤¹¤Ù¤Æ¤Î¥»¥Ã¥·¥ç¥ó| [¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[Explicit¥×¥í¥­¥· ¥Ý¥ê¥·¡Ý] ------------------------------------------------------------------------ | | |¥»¥­¥å¥ê¥Æ¥£¥×¥í¥Õ¥¡¥¤¥ë | ¥¢¥ó¥Á¥¦¥£¥ë¥¹ (¡û ) | | ¥í¥®¥ó¥°¥ª¥×¥·¥ç¥ó | µö²Ä¥È¥é¥Õ¥£¥Ã¥¯¤ò¥í¥° ( ¡ü)[¥»¥­¥å¥ê¥Æ¥£¥¤¥Ù¥ó¥È]|¤¹¤Ù¤Æ¤Î¥»¥Ã¥·¥ç¥ó| * ¥Æ¥¹¥È£Å << £Ä£Î£Ó¤ÎµóÆ°¤Î´ª°ã¤¤È½ÌÀ >> DNS1¢¢¼«¼Ò£±¼¡ ¢¢FortiGuard [¥°¥í¡Ý¥Ð¥ë] ¤Î [¥Í¥Ã¥È¥ï¡Ý¥¯]->[DNS] ¡ý¾ÜºÙ X.1¡ÃAmazon EC2 ¡Ã208.91.112.53 ¥×¥é¥¤¥Þ¥êDNS¥µ¡Ý¥Ð [ X.1 ] ¡¿¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡±¡À ¥»¥«¥ó¥À¥êDNS¥µ¡Ý¥Ð [ 208.91.112.53 ] ¡À¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡²¡¿ ¡§ ¥Ö¥é¥¦¥¶¤Ç¥×¥í¥­¥·»ØÄê 192.168.1.9¡£DNS¤ÏX.1 -------------------------------- ¤ò¸«¤ë¡£»ß¤Þ¤Ã¤Æ¤¤¤ì¤Ð¼¡¤Î 208.91.112.53¤ò¸« .2 | ¤ë¡£²Ã¤¨¤Æ vdom1 Æâ¤Î£Ä£Î£Ó¥µ¡Ý¥Ð DNSc¤ò¸«¤ë¡£ WAN1(11)|NAT ¤³¤ì¤Ç̾Á°²ò·è¤Ï£Ï£Ë¡ª¡£¤³¤ì¤¬£Ä£Î£Ó¤ÎµóÆ°¡£ ------------- | GLOBAL | vdom1 ¤Ç¤Ï£Ä£Î£Ó¥µ¡Ý¥ÐDNSc²ÔƯ¡¢¥×¥í¥­¥·¥µ¡Ý FortiGate| ----------|(13)LAN ¥ÐProxyB ¤ò 8080 ¥Ý¡Ý¥È¤Ç²ÔƯ¡£DNSc ¤Ï¼ÒÆâÍÑ 800D | | vdom1|----- ¤Î£Ä£Î£Ó¥µ¡Ý¥Ð¤Ç http://qqq1/ ¤ä http://coba | | (DNSc)| | .nix.co.jj/ ¤È¸À¤¦Ì¾Á°²ò·è¤ò¤·¥¢¥¯¥»¥¹¤¹¤ë¡£ | |---------| | | |NAT root | | root ¤Ç LAN->WAN1 ¥ë¡Ý¥ë¤ÎºÇ½é¤Ë 192.168.1.9 ------------- | PC ¤«¤é¤Î¥Ñ¥±¥Ã¥È¤òÁ´Éôµö²Ä¤·¤Æ¡¢¤³¤³¤Ç¤Ï¥»¥­¥å |(9)LAN | ¢¤IE ¥ê¥Æ¥£¤Î¥Á¥§¥Ã¥¯¤Ï¤·¤Ê¤¤¡£ProxyB ¤Î vdom1 Æâ 192.168.1.0 .2| .9| ¡Ã ¤Ç¥Á¥§¥Ã¥¯¤¹¤ë¡£¤É¤³¤«¤é¤Î¥¢¥¯¥»¥¹¤«Ê¬¤«¤ë¡£ --------------------------------- £Ä£Î£Ó¤ÎµóÆ°¤ò´ª°ã¤¤¤·¤Æ¤¤¤¿¤³¤È¤¬Ê¬¤«¤Ã¤¿¡£FortiGate Æâ¤ËÀߤ±¤¿£Ä£Î£Ó¥µ¡Ý¥Ð¤Ï£± ¸Ä¤Î£Ä£Î£Ó¥¢¥×¥é¥¤¥¢¥ó¥¹¤ß¤¿¤¤¤Êʪ¤À¤í¤¦¤È»×¤Ã¤Æ¤¤¤¿»ö¡£¤½¤ì¤Ë¤·¤Æ¤Ï¥ë¡Ý¥È£Ä£Î£Ó ¤ò¸«¤Ê¤¤¤Î¤Ï²ò¤»¤Ê¤¤¡£FortiGate ËÜÂΤǻØÄꤷ¤¿£Ä£Î£Ó¤È¤Ï´Ø·¸¤Ê¤¤¤È»×¤Ã¤Æ¤¤¤¿¤³¤È¡£ ¤½¤Î¤¿¤á°Ê²¼¤Î¤è¤¦¤Ë´ª°ã¤¤¤·¤Æ "(5)µòÅÀ¤â FortiGate ¤Ç°ÂÁ´¤«¤Ä¹â®¤Ë" ¤Ë½ñ¤¤¤Æ¤¿¡£ -------------------------------------------------------------------------------- FortiGate ¤Ç¥×¥í¥­¥·¥µ¡Ý¥Ð¤òÀߤ±¤ë¤È¡¢¤³¤ì¤¬¸«¤ë£Ä£Î£Ó¤Ï FortiGateËÜÂΤǻØÄꤷ¤¿ ¤Î¤ò¸«¤ë¡£¤³¤Î»ØÄêÀè¤Ï¥Ç¥Õ¥©¥ë¥È¤Ï Fortinet ¼Ò¤Î£Ä£Î£Ó¤Ç¤¢¤ë¡£¼ÒÆ⥵¡Ý¥ÐÍѤÎ̾Á° ²ò·è¤Î¤¿¤á¤Ë¼ÒÆâ£Ä£Î£Ó¥µ¡Ý¥Ð¤ÎÁõÃÖ¤òÀߤ±¤ë¾ì¹ç¡¢ ¤½¤Î¤¿¤á¤Ë FortiGate ËÜÂΤǻØÄê ¤¹¤ë£Ä£Î£Ó¤Ï¤³¤ÎÁõÃ֤ˤ¹¤ë¤·¤«¤Ê¤¯¤Ê¤ë¡£¤â¤·¼ÒÆâ£Ä£Î£Ó¥µ¡Ý¥Ð¤ÎÁõÃÖ¤¬¥À¥¦¥ó¤Ê¤É¤¹ ¤ë¤È¡¢FortiGate ¤Î¥»¥­¥å¥ê¥Æ¥£µ¡Ç½¤Ë¤â»Ù¾ã¤ò¤­¤¿¤¹¤³¤È¤Ë¤Ê¤ë¡£¤³¤ì¤Ï¤è¤í¤·¤¯¤Ê¤¤¡£ -------------------------------------------------------------------------------- root->[¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[¥Ý¥ê¥·¡Ý]->[IPv4] LAN->WAN1 ¤Î°ìÈÖ¾å¤Ë£±¤Ä¥ë¡Ý¥ë¤òºîÀ®¡£¤³¤³¤Ç¤Ï¥»¥­¥å¥ê¥Æ¥£¥Á¥§¥Ã¥¯¤Ï¤·¤Ê¤¤¡£ "PROXY-192.168.1.9 all ALL ¡ºACCEPT NATÍ­¸ú"¡£¥ª¥Ö¥¸¥§¥¯¥È PROXY-192.168.1.9¡£ vdom1->[¥·¥¹¥Æ¥à]->[¥Í¥Ã¥È¥ï¡Ý¥¯]->[¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹] ̾Á° port13(VDOM LAN)¡¢IP/¥Í¥Ã¥È¥Þ¥¹¥¯ 192.168.1.9/255.255.255.0¡¢¥¿¥¤¥×ʪÍý¡¢ ¥Ð¡Ý¥Á¥ã¥ë¥É¥á¥¤¥ó vdom1¡¢¡ºExplicit Web¥×¥í¥­¥·¤òÍ­¸ú¡£ vdom1->[¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È]->[¥Ý¥ê¥·¡Ý]->[¥×¥í¥­¥·¥ª¥×¥·¥ç¥ó] ÀßÄê¤Ê¤·¡£ ¥×¥í¥È¥³¥ë¥Þ¥Ã¥Ô¥ó¥°¤Ï HTTP ¤À¤±¤Ë¡º¤·¤Æ¤Ï¡£HTTP °Ê³°¤Ï´Ø·¸¤Ê¤¤¤Î¤Ç¤Ê¤¤¤«¡£ vdom1->[¥ë¡Ý¥¿]->[¥¹¥¿¥Æ¥£¥Ã¥¯]->[¥¹¥¿¥Æ¥£¥Ã¥¯¥ë¡Ý¥È] IP/¥Í¥Ã¥È¥Þ¥¹¥¯ 0.0.0.0/0.0.0.0¡¢¥²¡Ý¥È¥¦¥§¥¤ 192.168.1.2¡¢¥Ç¥Ð¥¤¥¹ port13¡£ [¥Ð¡Ý¥Á¥ã¥ë¥É¥á¥¤¥ó] root -> ¥·¥¹¥Æ¥à -> ¥Í¥Ã¥È¥ï¡Ý¥¯ ---> DNS¥µ¡Ý¥Ð ÀßÄê¥Ê¥· | --> Explicit¥×¥í¥­¥· ÀßÄê¥Ê¥· vdom1 ---> ¥·¥¹¥Æ¥à -> ¥Í¥Ã¥È¥ï¡Ý¥¯ ---> DNS¥µ¡Ý¥Ð [a] | | | --> Explicit¥×¥í¥­¥· [b] | --> ¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È -> ¥Ý¥ê¥·¡Ý ---> IPv4 [c] | --> Explicit¥×¥í¥­¥· [d] [a] vdom1 -> ¥·¥¹¥Æ¥à -> ¥Í¥Ã¥È¥ï¡Ý¥¯ -> DNS¥µ¡Ý¥Ð ¾å¤Ë½ñ¤¤¤¿ÆâÍƤȰì½ï¡£ ------------------------------------------------------------------- |¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹¾å¤ÎDNS¥µ¡Ý¥Ó¥¹ | ¢¢ ¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ ¥â¡Ý¥É |------------------------------------------------------------------ | ¢¢ port13 ºÆµ¢¸¡º÷ | |DNS¥Ç¡Ý¥¿¥Ù¡Ý¥¹ | ¢¢ DNS¥¾¡Ý¥ó ¥É¥á¥¤¥ó̾ ¥¿¥¤¥× ³Îǧ TTL ¥¨¥ó¥È¥ê¿ô |------------------------------------------------------------------ | ¢¢ zone1 qqq1 ¥Þ¥¹¥¿ ¥·¥ã¥É¡Ý 86400 2 | ¢¢ zone2 nix.co.jj ¥Þ¥¹¥¿ ¥·¥ã¥É¡Ý 86400 1 ------------------------------------------------------------------- [b] vdom1 -> ¥·¥¹¥Æ¥à -> ¥Í¥Ã¥È¥ï¡Ý¥¯ -> Explicit¥×¥í¥­¥· Explicit Web¥×¥í¥­¥·¤òÍ­¸ú ¡ºHTTP/HTTPS¡¢Listen¤¹¤ë¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹port13/!\¡¢ HTTP¥Ý¡Ý¥È 8080¡£¥Ç¥Õ¥©¥ë¥È¤Î¥Õ¥¡¥¤¥¢¥¦¥©¡Ý¥ë¥Ý¥ê¥·¡Ý¤Î¥¢¥¯¥·¥ç¥ó µö²Ä ???¡£ [c] vdom1 -> ¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È -> ¥Ý¥ê¥·¡Ý -> IPv4 ¤Ë£±¤Ä¥ë¡Ý¥ë¡¢ {port13(VDOM LAN) - port13(VDOM LAN)} "all all ALL ¡ºACCEPT NAT̵¸ú"¡£ {Implicit} "all all ALL (/)DENY"¡¢¤³¤ì¤Ï¼«Æ°Åª¤Ë¤Ç¤­¤Æ¤¤¤¿¡£ [d] vdom1 -> ¥Ý¥ê¥·¡Ý&¥ª¥Ö¥¸¥§¥¯¥È -> ¥Ý¥ê¥·¡Ý -> Explicit¥×¥í¥­¥· ¤Ë£±¤Ä¥ë¡Ý¥ë¡¢ {web proxy-port13(VDOM LAN)} "all all ¡ºACCEPT AV Web¥Õ¥£¥ë¥¿ ¤Ê¤É"¡£ ¡ü £×£Á£Î¤ÎµòÅÀ¤Ç¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ø¤Ï `2h/12/s [1] ºÇ½é¤Ë¹Í¤¨¤¿¹½À®¤Ç¤¹¤°¤Ë¤Ç¤â½ÐÍè¤ë [2] ºÇ¶á¤Î¥ë¡Ý¥¿¤Ë¤Ï¥Ý¥ê¥·£Òµ¡Ç½¤¬¤¢¤ë WAN ¢®¢®¢®¢® Internet WAN ¢®¢®¢®¢® Internet ¡§ ¡½¡½¡½¡½ ¡§ ¡½¡½¡½¡½ ¡§ ¡§ ¡§ PolicyR ¡§ R¢¢ ¡§ UTM¤ÎFortiGate¤Ï R¢¢¡Ä¡Ä¡Ä¡Ä¡Ä ¥ë¡Ý¥¿¤Ç¥Ý¥ê¥·£Ò ¡Ã PolicyR ¡§ £Î£Á£Ô·¿¡¢¤³¤Î¥â ¡Ã ¤ä¤ì¤Ð FortiGate UTM¢¢¡Ä¡Ä¡Ä¡Ä¡Ä ¡Ý¥É¤Ç¤Ï¥Ý¥ê¥·£Ò UTM¢¢ ¤ÏÆ©²á·¿¤Ç¤âÀßÃÖ ¡Ã ¤ÈWAN LLB ¤¬²Äǽ¡£ ¡Ã ²Ä¡£¤³¤Î¥â¡Ý¥É¤Ç ------------ Æ©²á·¿¤Ç¤ÏÉԲġ£ ------------ ¤Ï WAFS ¤Î¤ß²Äǽ¡£ [3] ¿ʬ¤³¤ó¤Ê¹½À®¤âºÎ¤ì¤ë¤Î¤Ç¤Ê¤¤¤«¤È [4] £×£Á£Î¤ÎÃæ¤Ë¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¸ý¤¬¤¢¤ë WAN ¢®¢®¢®¢® Internet ¡½¡½¡½¡½ Internet ¡Ã ¡½¡½¡½¡½ ¡§ PolicyR? ¡Ã ¡§ WAN ¢®¢®¢®¢® R¢¢¡Ä¡Ä¡Ä¡Ä¡Ä ξ¥×¥é¥ó¤Ï£×£Á£Î ¡Ã £×£Á£Î¤ÎÃæ¤Ë¥¤¥ó¥¿¡Ý ¡§ PolicyR ¥µ¡Ý¥Ó¥¹¶È¼Ô¤ÎÅÔ ¡Ã ¥Í¥Ã¥ÈÀܳ¤Î¥²¡Ý¥È¥¦ ¡§ ¹ç¤¬º¸±¦¤¹¤ë¡£Æà R¢¢ ¥§¥¤¤ò¥µ¡Ý¥Ó¥¹¤·¤Æ¤¤ R¢¢ ¤Ë [3]¤Î¥×¥é¥ó¤Ï ¡§ ¤ì¤Ð½ÐÍè¤ë¡££Ë£Ä£Ä£É ¡Ã ¤³¤ó¤Ê¥µ¡Ý¥Ó¥¹¤Ï ¡§ ¤Ç¥µ¡Ý¥Ó¥¹¤·¤Æ¤¤¤ëµ­ ------------ ¤·¤Æ¤Ê¤¤µ¤¤¬¤¹¤ë¡£ R¢¢ ½Ò¤ò³Î¤«¸«¤¿µ¤¤¬¤¹¤ë¡£ ¡Ã ------------ [5] £×£Á£Î¤Î IP-VPN Ì֤ǤϤ³¤ó¤Ê´¶¤¸¤« WAN ¢®¢®¢®¢® R2 ¤È R3 ¤Ç WAN ¤Ø¤Î·ÐÏ©¡¢WAN ¤ÎÃæ¤Ë¤¢¤ë¥»¥°¥á¥ó¥È¤Î£É£Ð ¡Ã ¥¢¥É¥ì¥¹¤ËÂФ·¤ÆÀÅŪ·ÐÏ©¤òÄ¥¤ë¡£Â¾¤Ï¥Ç¥Õ¥©¥ë¥È·ÐÏ©¤Ç¥¤¥ó R3¢¢ ¥¿¡Ý¥Í¥Ã¥È¤Ø¹Ô¤¯¤è¤¦¤Ë¤¹¤ë¡£¤³¤³¤¬»Ù¼Ò¤È¤¹¤ë¤ÈËܼҤʤɤΠ¡Ã Internet ¥Í¥Ã¥È¥ï¡Ý¥¯¤òÀÅŪ·ÐÏ©¤òÀßÄꤹ¤ë¡£¤³¤Î£×£Á£ÎÀܳ¤Î·ÁÂÖ¤Ï ¡¿¡±¡±¡±¡±¡À IP-VPN Ì֤ǭ¼þ¤ê¤Ë¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤ò»È¤¤¡¢R1 ¤È R2 ¤Î´Ö¤Ï ¡À¡²¡²¡²¡²¡¿ IPSec ¤Ë¤è¤ë£Ö£Ð£ÎÀܳ¤È¤¹¤ë¡£ ¡Ã R2¢¢ PolicyR ºÇ½é IPSecÄ¥¤Ã¤¿¥ë¡Ý¥¿¤Ï£±ÂУ±Âбþ¤Ê¤Î¤Ç¡¢ÀìÍÑÍøÍѤˤʤë .2¡§ ¤È»×¤Ã¤Æ¤¤¤¿¡£¤·¤«¤· IPSec ¤Ï R1¤Î¥¤¥ó¥¿¡Ý¥Õ¥§¡Ý¥¹ .1 ¤È ¡§IPSec R2 ¤Î .2 ¤È¤Î´Ö¤À¤«¤é¡¢R2 ¤Î¸þ¤³¤¦Â¦¤Ï´Ø·¸¤Ê¤¤¤Ï¤º¤Ç¤¢¤ë¡£ .1¡§ R2¤Ë¥Ý¥ê¥·£Ò¤Îµ¡Ç½¤¬¤¢¤ì¤Ð»È¤¨¤ë¤À¤í¤¦¤·¤È¸À¤¦¤³¤È¤Ç¤¢¤ë¡ R1¢¢ ¡Ã ¥ë¡Ý¥¿¤Î¥Ý¥ê¥·£Ò¤Ï¥½¥Õ¥È¥¦¥§¥¢¤ÇÀ©¸æ¤µ¤ì¤ë¡£¤É¤¦¤âÃÙ¤¤¤È ------------ ¤¤¤¦µ­»ö¤â¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤òÄ´¤Ù¤ë¤È»¶¸«¤¹¤ë¡£Ãí°Õ¤·¤¿¤¤¡ª¡£ ¡ü ¥ì¥¤¥ä£³¥¹¥¤¥Ã¥Á¤Î¥Í¥Ã¥È¥ï¡Ý¥¯¤½¤Î£² `2h/12/s "3-4.¼ÒÆâ¥Í¥Ã¥È¥ï¡Ý¥¯¤¤¤í¤¤¤í,(3)¥ì¥¤¥ä£³¥¹¥¤¥Ã¥Á¤ò»È¤Ã¤¿Àß·×" ¤Ë¤â½ñ¤¤¤Æ¤ª¤¤¤¿¡£ [1] [2] ¢¡ L3 ¤È L2¤Î´Ö¤Ïµ÷Î¥¤¬ ¡§¥¤¥ó¥¿¡Ý¥Í¥Ã¥È¤Ø ¡§ ¡Ã ¤¢¤ë¡£¥¿¥°VLAN¤Ç X¤ò -------------------------- -------------------------- Äɲä·¤¿¡£¥±¡Ý¥Ö¥ë¤ò A | | X ÍѤ˰ú¤¯¤Î¤Ï¼ê´Ö¤À --------- B ---- -------- ---- C ¤Ã¤¿¤Î¤Ç¡£¤·¤«¤·¼Â¤Ï B | L3 | C ---|L2| | L3 | |L2|--- X ¥»¥°¥á¥ó¥È¤Ë·Ò¤¬¤ë --------| |--------- ---| |--| |--| |--- ÁõÃÖ¤Ï IoT¤À¤Ã¤¿¤ê¤· --------- X ---- -------- ---- ¡ÃX ¤Æ´í¸±¤È¤¹¤ë¡£´û¸¤Î D | | ¡ü B,C ¤Ï¥Ñ¥½¥³¥óÅù¤¬·Ò -------------------------- -------------------------- ¤¬¤Ã¤Æ¤¤¤ÆÌäÂê¤Ê¤¤¡£ [3] [4] B,C ¤Ë´Ø¤·¤Æ¤Ï°ÂÁ´ÂÐ -------------------------- --------------- ºö¤Ï¤·¤Ê¤¯¤Æ¹½¤ï¤Ê¤¤¡£ | | UTM ---- C X ¤Ï°ÂÁ´Âкö¤¬É¬Í×¤Ç B ---- -------- ---- C -------- ---- |L2|-- ¤¢¤ë¡£¤Ñ¤Ã¤È»×¤¤ÉÕ¤¯ --|L2| UTM | L3 | UTM | |-- | L3 |--| |--| |-- ¤Î¤Ï [3]¡¢UTM ¤ÎÂæ¿ô --| |--¢¢--| |--¢¢--| |-- | | | | ---- X ¤¬ÌäÂê¤Ç¤¢¤ë¡£UTM ¤¬ X ---- -------- ---- X | | | | ---- B FortiGate ¤Ê¤éVDOM¤È | | |--| |--| |-- µ¡Ç½¤Ç²¾ÁÛŪ¤ËÊ£¿ôÂæ -------------------------- -------- ---- | |-- ¤Ë¤Ç¤­¤ë [4]¡£UTM ¤¬ | ---- X ¥¿¥°VLANÂбþ¤Ç¤­¤ë¤« --------------- Í׳Îǧ¡£Â¿Ê¬¤Ç¤­¤ë¡£ [5] ¢¥PC C¤ÈB ¤Î´Ö¤Î·ÐÏ©À©¸æ¤Ï L3 ¤Ç¹Ô¤Ê¤ï¤ì¤ë¡£X ¡§ ¡Ã A ¤Ï L3 ¤ÎÃæ¤òÄ̲᤹¤ë¤Î¤ß¡£¡ü¤È¢¡¤Î´Ö¤ÎÄÌ -------------------- ¿®¤Ï¾¤Î C,B¤Ë°ÂÁ´À­¤Î±Æ¶Á¤Ï¤Ê¤¤¡£Ä¾ÀÜ¡ü | ---- ¤Ï¢¡¤ÈÄÌ¿®¤Ç¤­¤Ê¤¤¤Î¤Ç¡þ¤ÈÄÌ¿®¤¹¤ë¡£PC¤Ï -------- C,X |L2|--- C ¢¡ Y.1¤Ë¥¢¥¯¥»¥¹¤·¡¢Î¯¤Þ¤Ã¤¿¥Ç¡Ý¥¿¤ò°·¤¦¡£ ----------|Y ¡Ä|-------| |--- X | Y UTM X | X¡§ | ---- ---- Y.8¤ÇL3¤ËÀܳ ----¢¢----| ¡Ä¡§ | B,X ---- | ¡ÃNAT ¡Ã |L3 ¡Ä|-------|L2|--- B | Y wan lan X ¢¡ ¡þ -------- | |--- X --------¢¢-------- SV | ---- ¡Ã ¡Ã NAT ¡Ã -------------------- ¡üCT ¢¡Y.1 ¡þX.9 (Y.1¤Î²¾ÁÛÀßÃÖ) ¢¨¤·¤«¤·¤³¤ó¤Ê¥Í¥Ã¥È¥ï¡Ý¥¯¹½À®¤¬¤Þ¤Ã¤È¤¦¤È¸À¤¨¤ë¤Î¤«¡£¤Ç¤­¤Ê¤¤¤³¤È¤Ï¤Ê¤µ¤½¤¦¤À¤¬ Èó¾ï¤Ë¥È¥ê¥Ã¥­¡Ý¤Ç¤¢¤ë¤È¸À¤ï¤¶¤ë¤òÆÀ¤Ê¤¤¡£[3] ¤« [4] ¤¬¤Þ¤Ã¤È¤¦¤À¤í¤¦¤È»×¤¦¡£ [6] ¹½À®[5]¤Ç UTM ¤¬Æ©²á·¿¤Î¾ì¹ç PC ¤«¤é SV ¤ØÄÌ¿®¤·¤¿¤¤¡£µÕ¤Î SV ¤«¤é PC ¤ÏÄÌ¿®¤Ç¤­¤Ê¤¤¡¢ X ¥»¥°¥á¥ó¥È¤ËÄÌ¿®¤Ç¤­ ¤ë¤Î¤Ï PC ¤À¤±¤Ë¤·¤¿¤¤¡£X¥»¥°¥á¥ó¥È ¤Ë¤Ï IoTµ¡´ï¤Ê¤É´í¸±¤Êʪ¤¬¤¢¤ë¤ÈÁÛÄꤹ¤ë¡£¤· ¤«¤·¥µ¡Ý¥Ð¤Î SV ¤Ë¤Ï²¿¤¬¤·¤«¡¢IoT µ¡´ï¤«¤é¤Î¥Ç¡Ý¥¿¤¬Î¯¤Þ¤Ã¤Æ¤¤¤Æ¡¢¤½¤ì¤Ï A ¤Î PC ¤«¤é SV ¥Ø¤ÎÀÅŪ·ÐÏ©¤òÀßÄꤹ¤ì¤Ð½ÐÍè¤ë¤Î¤Ç¤Ê¤¤¤«¤È»×¤Ã¤¿¤¬¤Ç¤­¤Ê¤¤¡£[5]¤Î¿Þ¤ÇUTM ¤ÎÁ°¸å¤ò X ¤Ë¤·¤¿¤é¡¢¥ë¡Ý¥×¤·¤Æ·Ò¤¬¤Ã¤Æ¤·¤Þ¤¦(b)¡£¤³¤ì¤Ï¤Þ¤º¤¤¡£(c) ¤Î¤è¤¦¤Ë·Ò¤² ¤Æ¤Ï¤¤¤±¤Ê¤¤¡£(a) ¤È (b) ¤Î¿Þ¤¬¾å²¼ÊѤï¤Ã¤Æ¤¤¤Æ¸«¤Ë¤¯¤¤»ö¤ò¤ªÏͤӤ·¤Þ¤¹¡£UTM¤ÏÆ© ²á·¿¤ÎÀßÃ֤ʤé¤Ð¡¢UTM ¤¬¤Ê¤¤¾ì¹ç¤Ç¤â·ÐϩŪ¤Ë¤Ï°ì½ï¤Ç¤¢¤ë¡£ SV¢¡ (a) (b) ¢¥PC (c) ¢¥PC ¡Ã.1 ¡Ã ¡Ã ------------------ X -------------------- A ---------------- ¡ÃX.6 | ---- | UTM¢¢Æ©²á -------- C,X |L2|-- C ------- ¡ÃX.7 ----------|X ¡Ä|------| |-- X X | | C,X X.8¡Ã | X UTM X | X¡§ | ---- ------ | |---- -------- C,X Åù ----¢¢----| ¡Ä¡§ | B,X ---- |·Ò¤¬¤é¤Ê| | | L3 |---¢¢--- ¡ÃÆ©²á |L3 ¡Ä|------|L2|-- B |¤¤¤è¤¦¤Ë| | B,X PC¢¥ -------- L2 ¢¡ -------- | |-- X -----¢¢--| L3 |---- ¡Ã.1 ¡ÃA.9 SV | ---- ¡ÃX UTM | | ------------------ A -------------------- ¢¡ -------