f5 japan
10 TopicsBIG-IP APMãšPassLogicãé£æºãããŠç«¯æ«åºææ å ±ã®ç»é²ãèªååããæ¹æ³
Technorati ã¿ã°: APM,BIG-IP,iRules SSLVPNå©çšåºç€ã®æ§ç¯ã«ãããŠã¯ã©ã€ã¢ã³ã蚌ææžãçšããã«ããã€ã¹ã®å¶éãç°¡æãªéçšã§å®çŸã§ããä»çµã¿ãæ€èšãããŠãããäžèšã®ãããªèŠä»¶ããã£ããšããŸãã ã»SSLVPNãå©çšããã ã»ãªã¹ãåæ»æã«ããã¢ã«ãŠã³ãä¹ã£åããé²ãç®çã§ã¯ã³ã¿ã€ã ãã¹ã¯ãŒããå©çšããã ã»ã¡ãŒã«ãåä¿¡ãã圢ã®ã¯ã³ã¿ã€ã ãã¹ã¯ãŒãã¯ããããã¡ãŒã«ãåä¿¡ããã·ã¹ãã ãžã®ãã°ã€ã³ã«äœ¿çšãããªã©ãã¡ãŒã«ãåä¿¡ã§ããªãç°å¢ã§ã®ãã°ã€ã³ãã§ããªãããä»åã¯æ€èšå¯Ÿè±¡å€ ã»ãŠãŒã¶ãŒã«èš±å¯ããããã€ã¹ä»¥å€ããã®ã¢ã¯ã»ã¹ã¯çŠæ¢ããã ã»ããã€ã¹ç»é²ã®ããã«ããã€ã¹åºææ å ±ã1å°1å°èª¿ã¹ãŠç»é²ããäœæ¥ã¯é²ããã ã»ããã€ã¹ã®ç¹å®ã®ããã«ã¯ã©ã€ã¢ã³ã蚌ææžã«ããèªèšŒã¯SSLãçµç«¯ããã¿ã€ãã®Proxyçµç±ã§ã®ã¢ã¯ã»ã¹ãããããšãšãéçšç®¡çãããç ©éã«ãªãããè¡ããããªã ã»1ãŠãŒã¶ãŒã䜿çšããããã€ã¹ã¯ã²ãšã1å°ã§ã¯ãªãMac, Windows, Linux, iOS, Androidãããæ倧5å°(ãã¡iOS/Androidã¯æ倧2å°) ã»ãŠãŒã¶ãŒã«çŽã¥ããããã€ã¹ã§ã¯ãªãããããããç»é²ããŠããå ±æçšããã€ã¹ (PC, Windows, iOS, Android)ããã®ãã°ã€ã³ã¯ç¡æ¡ä»¶ã«èªããã ã»ãžã§ã€ã«ãã¬ã€ã¯ãããiOS端æ«ãAndroid端æ«ã®ç»é²ã¯èš±å¯ããªã BIG-IP Access Policy Manager (以äžAPM)ãšãã¹ããžç€Ÿã®PassLogic Enterprise Edition 2.3.0(以äžPassLogic)ããããŠæ¬èšäºã§çŽ¹ä»ããAPMã®Access ProfileãšiRulesã§PassLogicã®APIãšé£æºããããšã§ãããã®èŠä»¶ãæºããããšãã§ããŸãã ã·ã¹ãã èŠä»¶ PassLogic Enterprise Edition 2.3.0 BIG-IP Access Policy Manager (APM) v12.0 HF1 ãã®iRulesã§ã¯ãSideband Connectionã䜿çšããŠAPMã»ãã·ã§ã³å€æ°ã®PassLogicã®RADIUS Attributeç»é²ãå®çŸããŠããŸãã Technorati ã¿ã°: Japan æ¬èšå®ãµã³ãã«ã§ã¯ãåOSã§ååŸå¯èœãªããã€ã¹åºææ å ± ã»(ä»»æã®)NICã®MACã¢ãã¬ã¹ (Windows, Mac, Linux) session.machine_info.last.net_adapter.list.[0].mac_address ã»ãã¶ãŒããŒãã®ã·ãªã¢ã«çªå· (Windowsã®ã¿) session.machine_info.last.motherboard.sn ã»(ä»»æã®)ããŒããã£ã¹ã¯ãã©ã€ãã®ã·ãªã¢ã«çªå· (Windowsã®ã¿) session.machine_info.last.hdd.list.[0].sn 詳ãã㯠About Machine Info https://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-visual-policy-editor-12-0-0/4.html ãåãããŠãåç §ãã ããã ã»iOSã®UDID session.client.unique_id 詳ãã㯠Support for using the BIG-IP Edge Client to check identifying information from Apple iOS client devices https://support.f5.com/kb/en-us/solutions/public/12000/700/sol12749.html ãåãããŠãåç §ãã ããã ã»Androidã®Unique ID session.client.unique_id 詳ãã㯠Overview of session variable support for BIG-IP Edge Client for Android devices https://support.f5.com/kb/en-us/solutions/public/13000/700/sol13731.html ãåãããŠãåç §ãã ããã APMã§ã¯äžèšã®ãããªããªã·ãŒãäœæããAccess ProfileããiRulesã€ãã³ããåŒã³åºããŸãã iRulesã§ã¯APMã»ãã·ã§ã³å€æ°ã䜿çšããŠPassLogicã®RADIUS Attributeãžæ å ±ãç»é²ããŸãã when RULE_INIT { # Set the IP:Port of PassLogic Enterprise Edition set static::passlogicip "192.168.10.201" set static::passlogicport 7080 } when ACCESS_POLICY_AGENT_EVENT { # Check Shared Device (Required to set HW Info to DataGroup SharedDevices HWInfo:=DeviceKind) if { [ACCESS::policy agent_id] eq "IsSharedDevice" } { set uname [ACCESS::session data get session.logon.last.username] set hwinfo [ACCESS::session data get session.passlogic.hwinfo] set devkind0 [ACCESS::session data get session.passlogic.devicekind] if { [class match -value $hwinfo eq SharedDevices] eq $devkind0 } { log local0. "User $uname is accessed with shared device kind=$devkind ($hwinfo)" ACCESS::session data set session.isshareddevice "yes" } else { log local0. "User $uname is accessed with non-shared device kind=$devkind0 ($hwinfo)" ACCESS::session data set session.isshareddevice "no" } } # Device HW Information will be registed to PassLogic RADIUS Attribute if { [ACCESS::policy agent_id] eq "RegistHWInfoToPassLogic" } { # Get APM session variables set uname [ACCESS::session data get session.logon.last.username] set dom [ACCESS::session data get session.logon.last.domain] set rattr [ACCESS::session data get session.passlogic.attr] set devkind [ACCESS::session data get session.passlogic.devicekind] set hwinfo [ACCESS::session data get session.passlogic.hwinfo] set rewrite9 [ACCESS::session data get session.passlogi.setrewrite9] set newattr "" log local0. "username = $uname device=$devkind hw=$hwinfo" log local0. "Old Attribute = $rattr" if { $rewrite9 eq "yes" } { log local0. "Rewrite not device kind ($devkind) but any device (9)" set devkind 9 } # flag for change attribute set addd 0 foreach i [split $rattr |] { if { $i eq $devkind } { if { $addd == 0 } { # Generate new attribute data for regist new device set tstr $newattr set newattr "$tstr$hwinfo|" set addd 1 } else { set tstr $newattr set newattr "$tstr$i|" } } else { set tstr $newattr set newattr "$tstr$i|" } } if { $addd == 1 } { log local0. "New DeviceID ($hwinfo) for user $uname will be registered to PassLogic. New RADIUS Attribute=$newattr" set conn [connect -timeout 3000 -idle 30 -status conn_status $static::passlogicip $static::passlogicport ] log local0. "Connect returns: <$conn> and conn status: <$conn_status> " set conn_info [connect info -idle -status $conn] log local0. "Connect info: <$conn_info>" set data "GET /passlogic/api/admin?mode=useredit&uid=$uname&domain=$dom&attribute1=$newattr HTTP/1.0\r\n\r\n" set send_info [send -timeout 3000 -status send_status $conn $data] log local0. "Sent <$send_info> bytes and send status: <$send_status>" set recv_data [recv -timeout 3000 -status recv_status 1024 $conn] log local0. "Recv data: <$recv_data> and recv status: <$recv_status>" close $conn log local0. "Closed; conn info: <[connect info -status $conn]>" log local0. "PassLogic response is correct." if { $recv_data contains "PassLogic" } { set ret [string range [findstr $recv_data " " 0 " "] 6 10] log local0. "Result Code = $ret" ACCESS::session data set session.passlogic.result $ret switch $ret { "50300"{ ACCESS::session data set session.passlogic.error "PassLogic Error: err Invalid input data." log local0. "PassLogic Error: err Invalid input data." } "50301"{ ACCESS::session data set session.passlogic.error "PassLogic Error: err The user does not exist." log local0. "PassLogic Error: err The user does not exist." } "50302"{ ACCESS::session data set session.passlogic.error "PassLogic Error: err Update parameter is required." log local0. "PassLogic Error: err Update parameter is required." } "50400"{ ACCESS::session data set session.passlogic.error "PassLogic Information: notice User information has updated successfully. New DeviceID ($hwinfo) for user $uname was registered." log local0. "PassLogic Information: notice User information has updated successfully. New DeviceID ($hwinfo) for user $uname was registered." } "50499"{ ACCESS::session data set session.passlogic.error "PassLogic Error: crit System error occurred." log local0. "PassLogic Error: crit System error occurred." } } } } else { ACCESS::session data set session.passlogic.result "NG" } } } 詳ããèšå®æé ãAccess ProfileãiRulesãµã³ãã«ã¯äžèšããããŠã³ããŒãã§ããŸãã https://f5.com/Portals/1/PDF/JAPAN/devcentral/PassLogic230_APM12_AP_iRule_v1.zip999Views0likes0CommentsBIG-IP ASMã§å¯Ÿå¿ããOWASP Top 10 - 2017幎ç
ãã®æçš¿ã¯ãF5ãããã¯ãŒã¯ã¹ã®ã·ãã¢ã»ãœãªã¥ãŒã·ã§ã³ã»ããããããŒã§ããPeter Silva ã®ããã°æçš¿ãThe OWASP Top 10 - 2017 vs. BIG-IP ASM ããå ã«ãæ¥æ¬åãã«åæ§æãããã®ã§ãã OWASP Top 10ã®2017幎æ£åŒçããªãªãŒã¹ãããŸããã®ã§ãBIG-IP ASMã®WAFæ©èœã§ã©ã®ããã察å¿ã§ãããæŠèŠã玹ä»ããããšæããŸãã ãŸãæåã«ã2013幎çãš2017幎çã®æ¯èŒã§ããããã€ãã®æ°èŠé ç®ã®è¿œå ãšãæ¢åé ç®ã®çµ±åãè¡ãããŠããŸãã ã§ã¯ãBIG-IP ASMã®å¯Ÿå¿ç¶æ³ãèŠãŠãããŸãããã Vulnerability BIG-IP ASM Controls A1 Injection Flaws ã€ã³ãžã§ã¯ã·ã§ã³ Attack signatures Meta character restrictions Parameter value length restrictions A2 Broken Authentication and Session Management èªèšŒãšã»ãã·ã§ã³ç®¡çã®äžå Brute Force protection Credentials Stuffing protection Login Enforcement Session tracking HTTP cookie tampering protection Session hijacking protection A3 Sensitive Data Exposure æ©å¯ããŒã¿ã®é²åº Data Guard Attack signatures (âPredictable Resource Locationâ and âInformation Leakageâ) A4 XML External Entities (XXE) XMLå€éšå®äœåç §(XXE) Attack signatures (âOther Application Attacksâ - XXE) XML content profile (Disallow DTD) (Subset of API protection) A5 Broken Access Control ã¢ã¯ã»ã¹å¶åŸ¡ã®äžå File types Allowed/disallowed URLs Login Enforcement Session tracking Attack signatures (âDirectory traversalâ) A6 Security Misconfiguration ã»ãã¥ãªãã£èšå®ã®ãã¹ Attack Signatures DAST integration Allowed Methods HTML5 Cross-Domain Request Enforcement A7 Cross-site Scripting (XSS) ã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°(XSS) Attack signatures (âCross Site Scripting (XSS)â) Parameter meta characters HttpOnly cookie attribute enforcement Parameter type definitions (such as integer) A8 Insecure Deserialization å®å šã§ãªããã·ãªã¢ã©ã€ãŒãŒã·ã§ã³ Attack Signatures (âServer Side Code Injectionâ) A9 Using components with known vulnerabilities æ¢ç¥ã®è匱æ§ãæã€ã³ã³ããŒãã³ãã®äœ¿çš Attack Signatures DAST integration A10 Insufficient Logging and Monitoring äžååãªãã®ã³ã°ããã³ç£èŠ Request/response logging Attack alarm/block logging On-device logging and external logging to SIEM system Event Correlation æ°èŠã«è¿œå ããããA4: XMLå€éšå®äœåç §ïŒXXEïŒãã®é ç®ã«ã€ããŠãããã§ã«ã·ã°ããã£ã§å¯Ÿå¿ããŠããŸãã 200018018 External entity injection attempt 200018030 XML External Entity (XXE) injection attempt (Content) ãŸããXXEæ»æã¯ãXMLãããã¡ã€ã«ã«ãã£ãŠæ±çšçãªé²åŸ¡ãå¯èœã§ãã ïŒDTDsãç¡å¹ã«ããŠã"Malformed XML data"ãã€ãªã¬ãŒã·ã§ã³ãæå¹ã«ããŸãïŒ ãŸããA8:å®å šã§ãªããã·ãªã¢ã©ã€ãŒãŒã·ã§ã³ãã®å¯Ÿå¿çãšããŠããã¡ããå€ãã®ã·ã°ããã£ããã§ã«æäŸãããŠããŸãã ãããã·ã°ããã£ã®å€ãã¯ãäžèšã®ããã«âserializationâ ãâserialized objectâ ãšãã£ãååãå«ãŸããŠããŸãã 200004188 PHP object serialization injection attempt (Parameter) 200003425 Java Base64 serialized object - java/lang/Runtime (Parameter) 200004282 Node.js Serialized Object Remote Code Execution (Parameter) 以äžãOWASP Top10 2017幎çã®ãªãªãŒã¹ã«ãšããªããBIG-IP ASMã®WAFæ©èœã®å¯Ÿå¿ç¶æ³ã®ã玹ä»ã§ããã é¢é£ãªã³ã¯ïŒ Whatâs New In The OWASP Top 10 And How TO Use It BIG-IP ASM Operations Guide684Views0likes0Commentsãããã¯ãŒã¯ã€ã³ãã©ã¯ãã€ãã¥ãŒã¿ãã«ãªãã®ã«ãªããã®ãïŒ
Please find the English language post, by Lori MacVittie, from which this was adapted here. ã€ãã¥ãŒã¿ããã«ã€ã³ãã©ã¹ãã©ã¯ãã£ãç§ã¯äœ¿ãæšãŠå¯èœãªã€ã³ãã©ã¹ãã© ãã£ãšåŒãããæ¹ãããµãããããšæãã®ãŠããããããã®1幎ãŠãDockerãšã³ã³ããåæ è¡ã®æåã«ãã£ãŠåã²ã泚ç®ã济ã²ããŸããããŸããDevOpsã¯ãèªååãšé¢é£ãã 䜿ãæšãŠå¯èœãªã€ã³ãã©ã¹ãã©ã¯ãã£ã®æŠå¿µãšãååŸããæ§æãŸãŠãã®ããžããŠã èªååããŠãã¢ãããªã±ãŒã·ã§ã³ãããŒã¿ããã¹ã®ãããããã®ãæäŸããããã³ãã ã¬ãŒããã®äœ¿çšã埩掻ããããããŠã圹å²ãæãããŠããŸããã æè¡ãã¬ã³ãããããæšä»ã®ããã·ããã¹ã®æ žãŠãããã¢ãããªã±ãŒã·ã§ã³éçºãããã¢ãã ãªã±ãŒã·ã§ã³ãããŒã¿ããã¹ã®çµç¹ãŠããããããã¯ãŒã¯ã«å¿ ç¶çã«ç§»è¡ããŠããã ãããããã¯ãŒã¯ ã€ã³ãã©ã¹ãã©ã¯ãã£ããã€ãã¥ãŒã¿ããã«(âäžå€â)ãŠããã ããšããããèããã®ã¯åœç¶ã®ããšãŠãããçµå±ãSDNã®ãããªãã¬ã³ããã«ãã£ãŠã ãŸã£ããå察ã®æ¹åãã€ãŸããå€ããããããéåžžã«æŽ»åçãªæ¹åã«é²ãããš ããç®æšãŠãããããšãããããããããããã¯ãŒã¯ã®ãããããã®ã«äžå€æ§ãé©çš ããããšã¯çŽæã«åããããšã®ããã«æããŸãã ãã®åé¡ã«çããåã«ãã€ãã¥ãŒã¿ããã«ã€ã³ãã©ã¹ãã©ã¯ãã£ããäœãæå³ãã ã®ãã«ã€ããŠã¡ãã£ãšèããŠã¿ã(å Žåã«ãã£ãŠã¯ãåèãã)å¿ èŠãããããŸãã ã·ã§ãã®ã·ãã¥ãªã¢ã³ã»ã¿ãã³æ°ããæžãããããã¯ããã€ãã¥ãŒã¿ããã« ã€ã³ãã©ã¹ãã© ã¯ãã£:å®çšçãŠãããããªãã?ããåŒçšããªããããçãããŸãã ã€ãã¥ãŒã¿ããã«ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯äžè¬çã«ãäžåºŠæ§ç¯ã(ä»®æ³ãã·ã³ã® ã€ã¡ãŒã·ããã³ã³ããã®ã€ã¡ãŒã·ããªãšã)ã1ã€ãŸãã¯å€æ°ã®ã€ã³ã¹ã¿ã³ã¹ãå®è¡ã ãããåã²ãå€æŽããããšã¯ãªãã¹ã¿ãã¯ãšããŠå®çŸ©ãããŠããŸããéçºã¢ããã« ã¯ãã€ã³ã¹ã¿ã³ã¹/ã³ã³ãããçµäºããåŸãæ°ããã€ã¡ãŒã·ããæ§ç¯ããŠãå€ã〠ã³ã¹ã¿ã³ã¹ãæšãŠããšããæåã®æé ãããäžåºŠããçŽãããšãŠããã ãããããªãããããªããšãããã®ãçåã«æã£ãŠãããããããŸãããããè ããã¯ããå®éã«ã¯ãæéã«ããå€åã«ãã£ãŠçºçããä¹±éãããåå ãããšããã ãŠããããã çç±ã¯ããšã³ãããããŒãŠããã ãœãããŠã§ã¢ãšã³ãããããŒã®æ³åã¯ãã€ãŠãã¡ãŒã»ã€ã³ãããœã³æ°ããã²ããã®ä»ã«ã ãèæžããªããã·ãã§ã¯ãæåãœãããŠã§ã¢å·¥åŠ:Use Caseã«ããã¢ããããŒãããŠã説 æãããŠããŸãã ç±ååŠã®ç¬¬2æ³åã«ã¯ãååãšããŠãæç±ç³»ã®ä¹±éãã¯æžå°ããããšã¯ãªããå€ åããªãããå¢å€§ããããããŠããããšèšè¿°ãããŠããŸãããã®ä¹±éãã®åºæºãããš ã³ãããããŒãŠãããã·ã¹ãã ãå€æŽãããšããã®ä¹±éããã€ãŸããšã³ãããããŒã¯ åžžã«å¢å€§ãããšãããŠããããããã®æ³åã¯ããœãããŠã§ã¢ã·ã¹ãã ã«å¯Ÿã㊠劥åœãããšãæããŸããããã¯ããœãããŠã§ã¢ãšã³ãããããŒãšããŠç¥ãããŠã ãŸãã ãã®æ³åã¯ããã¡ãŒã ãŠã§ã¢ãŸãã¯ã·ã¹ãã ã¬ããã«ã®æŽæ°ãé©çšããªããã¯ã㪠ããªãã·ã¹ãã ã«å¯ŸããŠãåœãŠã¯ãŸããŸããã·ã¹ãã ã«ã¯ãããããã£ãã¯ã¹ ãããããããå°å ¥ãããŸãããŸããç·æ¥ã®æ§æå€æŽããå¿ èŠãªå ŽåãŠãããçæ³ã®äž çãŠãã¯ãå³å¯ã«å®ãããå€æŽç®¡çãããã»ã¹ãéããŠã®ã¿å€æŽããªããŠã¯ãªã㟠ãããã€ãã¥ãŒã¿ããã«(䜿ãæšãŠå¯èœãª)ã€ã³ãã©ã¹ãã©ã¯ãã£ãã解決ããã ãšããŠããåé¡ã¯ãã·ã¹ãã ã«å°å ¥ããå€æŽããå€ãã»ãšããããä¹±éã«ãªããäž å®å®ãããå¢ãããã«èŠããããšãŠãããä¹±éãŠããç¡ç§©åºãªãšã³ãããããŒãŠããã ãããŠãã¯ã䜿ãæšãŠå¯èœãªã€ã³ãã©ã¹ãã©ã¯ãã£ã®æŠå¿µãèããŠã¿ãŸãããã 皌åäžã®ã·ã¹ãã ãå€æŽããªããšããåæã«åºã€ãããšã䜿ãæšãŠå¯èœãªã€ã³ã ã©ã¹ãã©ã¯ãã£ã¯ããããããã¢ãããã¯ãã¬ãŒãããšããŠæ§æãå€æŽããå¿ èŠãããã å Žåãæ°ããã€ã¡ãŒã·ããæ§ç¯ããŠãæ¢åã®ãã®ãå±éããéã«æåã«äœ¿çšãã åãããããã»ã¹ãŠããããå±éããå¿ èŠãããããšèšãããŠããŸãã ãããŠãå€ããã®ãç Žæ£ããŸãã ãã£ãããªããããããªããšãããã®ãŠããããã æ¢ç¥ã®ãããã»ã¹ã«åŸã£ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ãäœæããŠå±éããããšããå æãªã®ãŠããããããããæåãŠã/etc/resolv.confãç·šéããããšãããããå€éšããæ° ããã©ã€ããã©ãªãè¿œå ããããšããããæ°ã«ããå¿ èŠã¯ãããŸããããããããããã ãè¡ã£ããšããŠããå±éãããã»ã¹ã®ã³ã³ããã¹ãå ãŠãè¡ã£ãŠããã®ãŠãããã㯠ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ¢ç¥ã®ç¶æ ã«å«ãŸããŠããŸãã ããã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®å€åšçãªæ¢ç¥ã®ç¶æ ãç¶æãããšããéèŠãª æŠå¿µãŠãããèãèŠãããããå Žåã¯ãããããSDNã®æŠå¿µãšãããŒã¿ããã¬ãŒã³ããã®å¶ 埡ã®åé¢ãšå¯æ¥ãªé¢ä¿ããããããããã¯ãŒã¯å šäœã®ç¶æ ãããããéäžåã®ã³ã ã³ãããšå¶åŸ¡ã¢ããã«ãäœãäžãããŠãããããŠããããããã¯ãŒã¯å ã®åã ã®ããŒãã ãå€æŽããããšã¯ãªããããããŒããããè€éã«ãªãããšããã¢ãªã¹ããããæ©é ã ã«åé¡ãä¿®æ£ããããã«è¿œå ããã«ãŒãã«ã€ããŠå¿é ããå¿ èŠã¯ãããŸããã ããžããŠã¯ãããã¯ãŒã¯ã®ã³ã³ãããŒã©ãŠãç£èŠãããŠããŸãã ãã£ããã»ãã¡ãŠã©æ°ã¯ããã®æŠå¿µãããµãŒãããæšãŠãã³ãŒãããçŒãä»ãã:〠ãã¥ãŒã¿ããã« ã€ã³ãã©ã¹ãã©ã¯ãã£ãšããã£ã¹ãããŒãµãããã«ã³ã³ãããŒãã³ãããŠãã ãŸã説æããŠããŸãã ã·ã¹ãã ããèªåãŠãäœæãããäœæããããšããããŸã£ããå€æŽãããŠããªãã ãšããæãããŠãããå Žåã«ã¯ããããŸãŠãã«è¿°ãžããŠããåé¡ã®å€§éšåã¯è©²åœããŸã ããã¢ãããã¯ãã¬ãŒããããå¿ èŠãããããŸãããåé¡ãããŸãããæ°ãããã¢ããã ã¯ãã¬ãŒãããããã·ã¹ãã ãæ§ç¯ããå€ãã·ã¹ãã ãç Žæ£ããŸããããæ°ãããã㌠ã·ãã§ã³ã®ã¢ãããªããå¿ èŠãŠããããåããããšãŠãããæ°ãããããŒã·ãã§ã³ã®ãµãŒãã(㟠ãã¯ã€ã¡ãŒã·ã)ãæ§ç¯ããå€ããã®ãç Žæ£ããŸãããã ãŠãã¯ãç®ã®åã«ããåé¡ãã€ãŸããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ã€ãã¥ãŒ ã¿ããã«(䜿ãæšãŠå¯èœãª)ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãªãåŸããããšããåé¡ã« æ»ããŸãã çãã¯ããªãåŸãŸãã 次ã«ãæµ·å€ã®æåãªâé£ããâã¯ã€ã¹ãçªçµã64,000ããã«ã®è³ªåãã¬ããã«ã®æé« é£åºŠã®åé¡ãŠããããã®ãããªäœ¿ãæšãŠå¯èœãªãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ ãã£ããä»®æ³åãŸãã¯ã³ã³ããåããå¿ èŠãããããŠãããããã ããã¯ã¡ãã£ãšé£ããåé¡ãŠããããã®ãããªã€ã³ãã©ã¹ãã©ã¯ãã£ããã倧èŠæš¡ ãªã·ã¹ãã ã®äžéšãŠãã¯ãªããããèªäœãå±éãç Žæ£ãŠãããèªå·±å®çµåã®ãšã³ ãã£ãã£ãŠããããšä»®å®ããå Žåãçãã¯ã€ãšã¹ãŠãããéã«å·šå€§ãããã¯ãŒã¯äž ã®ãµãŒããã¹ã®æ§æãã¡ã€ã«ãéãããã®ã䜿ãæšãŠå¯èœãªã€ã³ãã©ã¹ãã©ã¯ ãã£ãšåŒãµãããšã¯ãŠãããŸããããªãããªããããã¯äœ¿ãæšãŠãŠãã¯ãªã倧èŠæš¡ãªã· ã¹ãã ã®äžéšãŠããããããŠãããã€ã³ãã©ã¹ãã©ã¯ãã£ã¯èªå·±å®çµåãŠããªããã¯ã ãªããããçã«äœ¿ãæšãŠå¯èœãªãšã³ããããŒãšã³ããã®ã¢ãããªã±ãŒã·ã§ã³ã€ã³ãã©ã¹ ãã©ã¯ãã£ããæ±ããããŠããã®ãªããä»®æ³åãŸãã¯ã³ã³ããåããããœãã ãŠã§ã¢ããæé©ãŠããã èããªããã¯ããªããªãçç± ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ããã€ãã¥ãŒã¿ããã«ããããŠããªãããèãã çç±ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ãšã¢ãããªããè¿ãã»ãšããã€ãŸãã€ã³ãã©ã¹ãã©ã¯ ãã£ãšã¢ãããªãšã®èŠªåæ§ããé«ãã»ãšãããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã³ã³ãããŒãã³ ããå€æŽããå Žåã«ã¢ãããªã«åœ±é¿ãäžããå¯èœæ§ããé«ããªããšããããšãŠããã ããšãã¯ããè² è·åæ£ã«ãã£ãŠã¢ãããªã±ãŒã·ã§ã³ã®åäœãã倧ããå€ããããšããã ããŸããè² è·åæ£ãµãŒããã¹ã®ãããããã¢ãããã¯ãã¬ãŒããããã¢ãããªã«åœ±é¿ãäžãã å¯èœæ§ãããããŸããåæ§ã«ãHTTPãããŒã¹æ»æãæ€ç¥ããŠåæ¢ãããã¹ã¯ãªããã ããããã©ãŒãã³ã¹ãåäžãããTCPæé©åãªãšããäžæµãµãŒããã¹ã¯åé¡ã«å¯Ÿå¿ãã ããã«å€éšãã£ãã«ãŠãæåã«ã埮調æŽããããããšãããããããŸãããã®ããã çžå¯Ÿçã«ããã«äžæµã«äœçœ®ãããµãŒããã¹ãããããšã³ãããããŒã®æªåœ±é¿ãåã ããããªããŸãã ããããã£ãŠãã¢ãããª(èšç®)ã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿ãæšãŠã«ããããšèã ãçç±ã¯ãäžæµã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãµãŒããã¹ã«ãåœãŠã¯ãŸããŸãã(ã¢ãã㪠ã±ãŒã·ã§ã³ãµãŒããã¹ ã€ã³ãã©ã¹ãã©ã¯ãã£ãå«ã)ã¢ãããªã±ãŒã·ã§ã³ã¢ãŒãã ã¯ãã£ã¹ã¿ãã¯å šäœãŠãã®ãšã³ãããããŒã®æªåœ±é¿ãæå¶ãããããŠããã ããã¯ããŒããããã©ã³ãµãããããã¯ãŒã¯ã«æ¿å ¥ããããŒãããŠã§ã¢ãããªãã¯ã®ãã ã¢ãšããŠèããã®ãæ¢ããä»®æ³åãããŠããããœãããŠã§ã¢ããããŒã¹ãšããã ã¯ã©ã¹ã¿åã®é²ããããã¢ãããªãããšã®ããµãŒããã¹ãããŒã¹ã®ã¢ããããŒãã«ã€ããŠã® æ€èšããå§ããããçç±ã®1ã€ãŠããããã®ãããªã¢ãããªã±ãŒã·ã§ã³ãµãŒããã¹ã®ä»®æ³ å/ãœãããŠã§ã¢ã€ã³ã¹ã¿ã³ã¹ã®äœ¿ãæšãŠã¯ããã«ç°¡åãŠããããå€åšçãŠãèªåå ããããããã»ã¹ã®ãããããã·ãã§ãã³ã¯ããããã²ã䜿ãæšãŠå¯èœãªã€ã³ãã©ã¹ãã©ã¯ ãã£ã¢ããããŒããå¯èœã«ããå±éã«é©åãããããªããŸãã ãããããšããããå®çšçã€ã³ãã©ã¹ãã©ã¯ãã£ã®ããã«ãã€ãŸãSDNã«ãã£ãŠ å®çŸããããã®ã®ããã«èãããããããŸããããv1ãã®ç Žæ£ãç¡èŠããŠãŸã£ã ãæ°ãããv2ããéžæããå Žåãåºæ¬çã«ã¯åããããšã«ãªããŸãããã®å Žåã åé¡ã¯ç Žæ£ã®è¿œå æé ã«ãã£ãŠã€ã³ãã©ã¹ãã©ã¯ãã£ãšã³ãããããŒããæå¶ãã ãããšããããšããããšã«ãªããŸãããŸããããã¯å©çšããŠããã€ã³ãã©ã¹ãã© ã¯ãã£ãŠãå®éã«è¡ãããå€æŽã®éã«å¿ãããŠãèªåãããããçããåºãã質åãŠãã ãããŸããåæã¯ãå€æŽã®éããå€ãã»ãšãããšã³ãããããŒãå¢å€§ãããšããããš ãŠããããããŸãŠãã®å€æŽéã«ãã£ãŠçãã¯å€ãããŸãã èŠçŽãããšããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯äœ¿ãæšãŠå¯èœ(ã€ãã¥ãŒã¿ ããã«)ã«ããããšãããŠãããã¢ãããªã±ãŒã·ã§ã³ã®ã¢ãããªã±ãŒã·ã§ã³ãµãŒããã¹ãšã® 芪åæ§ããé«ãã»ãšãããã®ãããªã€ã³ãã©ã¹ãã©ã¯ãã£ãã䜿ãæšãŠå¯èœãŠãããã ãšããæ©æµãåããå¯èœæ§ããé«ããªããŸããDevOpsãæ¡çšããŠã¢ãããªã±ãŒã·ã§ ã³ã€ã³ãã©ã¹ãã©ã¯ãã£ãå®çšåããŠããå Žåã¯ãèªåãŠãèªèããŠããããšã ãŸããšã䜿ãæšãŠå¯èœãªã¢ããããŒãã«ç§»è¡äžãŠãããå¯èœæ§ããé«ããªããŸãã ãŠãã¯ãå®å šã«äœ¿ãæšãŠå¯èœãªã€ã³ãã©ã¹ãã©ã¯ãã£ãå®æãããããšã¯ãŠããã ãŠããããããçŸå®çã«ã¯åé¡ããçºçããå¯èœæ§ããããããããããããŠãããŸã ããããããæ¬æ Œå±éãã¢ãããã¯ãã¬ãŒãããããã²ãèšç»ãããå€æŽã管çããæ¹ æ³ããèããŠãæçµçã«ã¢ãããªã±ãŒã·ã§ã³ã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžéšã䜿ã æšãŠå¯èœã«ããããšã¯ååã«å¯èœãŠããã æçµæŽæ°æ¥:2015幎2æ23æ¥538Views0likes1CommentAgility 2015ãã¯ãã«ã«è¬åº§ãAPMå®è·µå¿çšç·šã課é¡ïŒã®åçãïŒAPMã§ã°ã«ãŒãããšã«æ¥ç¶å ã®ã¢ã¯ã»ã¹å¶åŸ¡ããæ¹æ³ïŒ
ä»åããè€æ°åã«æž¡ãã2015幎2æ25æ¥ã«è¡ãããF5ã®ã€ãã³ãAgility 2015ã®äžã®ãã¯ãã«ã«è¬åº§ãAPMå®è·µå¿çšç·šãã®æåŸã«åºé¡ãããAPMã®5ã€ã®èª²é¡ã®åçã«ã€ããŠé çªã«çŽ¹ä»ãããŠããã ããŸãã åçã¯2015幎5æ15æ¥ã§ç· ãåããšãããŠããã ããæ£è§£è ã«ã¯ç²åãªãããã¬ãŒã³ãããéããããŠããã ããŸããããå¿ãããšããã®ãåå ããããšãããããŸããã ä»åã¯èª²é¡1ã®ãã°ã«ãŒãããšã«æ¥ç¶å ã®ã¢ã¯ã»ã¹å¶åŸ¡ããè¡ãæ¹æ³ã«ã€ããŠè©³ãã玹ä»ããããŸããå ·äœçãªå©çšã·ãŒã³ãå©çšäŸãšããŠãäžèšã®ãããªã±ãŒã¹ãèãããããšãã«åœ¹ã«ç«ã€ãœãªã¥ãŒã·ã§ã³ã§ãã 課é¡1 ã°ã«ãŒãããšã«æ¥ç¶å ã®ã¢ã¯ã»ã¹å¶åŸ¡ ããã客æ§ã§ãLDAP Attributeã®ç¹å®ã®ã°ã«ãŒã âMyGroupâ ã«å±ãããŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ã¯ç¹å®ã®ãããã¯ãŒã¯ã¢ãã¬ã¹ 10.24.0.0/12 ããã®ã¿èš±å¯ãããã ã°ã«ãŒãå±æ§æ å ±ã¯ session.ldap.last.attr.grp = âMyGroupâ ã®ã»ãã·ã§ã³å€æ°ã«æžãããŠããã ãããå®çŸããVPEã¢ã¯ã»ã¹ããªã·ãŒãäœæããã ããã¯ãäžèšã®ãããªèª²é¡ãæ±ããã客æ§ã«å®éã«åœ¹ç«ã€ãœãªã¥ãŒã·ã§ã³ãšãªããŸãã ãã€ã³ãã©ãããäžã®Webã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ç°å¢ã®æäŸã«ãAPMã瀟å€ããã®ãªã¢ãŒãã¢ã¯ã»ã¹ã ãã§ãªã瀟å ããã®ã¢ã¯ã»ã¹ã«ãå©çšããããšãæ€èšããŠããã瀟å ç°å¢ã¯ç€Ÿå¡ãšå¥çŽç€Ÿå¡ãå€éšã®åžžé§å¡ãªã©ãã°ã«ãŒãã«å¿ããŠã¢ã¯ã»ã¹ã®å¶åŸ¡ãè¡ãããç¹å®ã®ITã°ã«ãŒãã®ã¡ã³ããŒã¯ç€Ÿå€ããæ¥ç¶ããããšã¯ããåŸãªãã®ã§ãã€ã³ãã©ãããã®10.24.0.0/12ã®ãããã¯ãŒã¯ããã®æ¥ç¶ã®ã¿ãèš±å¯ãããã åçäŸ ãŸãã10.24.0.0/12ããã®ã¢ã¯ã»ã¹ã®ã¿ããšããéšåããèªäœããã©ããã«ãªã£ãŠããŸããå®éã«ã¯10.24.0.0/12ãšããè¡šçŸã¯äžé©åã§ã10.16.0.0/12ãšè§£éããŠ10.24.0.0ãå«ã10.16.0.0-10.31.255.254ããã®ã¿ã¢ã¯ã»ã¹èš±å¯ããã®ãããããšã10.24.0.0/13ãšè§£éããŠ10.24.0.0-10.31.255.254ããã®ã¿ã¢ã¯ã»ã¹èš±å¯ããã®ããæåã«ã客æ§ã«ãã®ããããæåã«ãç解ããã ããäžã§æ£ããèŠä»¶ã確èªãçŽãã®ã確å®ã§ããããã§ã¯ãã客æ§ããµãããããã¹ã¯ã®æå®ãã©ããã§èª€ã£ãŠããã10.24.0.0-10.31.255.254ããã®ã¢ã¯ã»ã¹ã®ã¿ãèš±å¯ããããšããæå³ã ã£ãããã10.24.0.0/13ãæ£ããèŠä»¶ã ã£ããšããŸãã 次ã«ã瀟å ããã®ã¢ã¯ã»ã¹ã§å©çšããVirtual Serverã«å¯ŸããSource Addressã§10.24.0.0/13ããã®ã¿ãèš±å¯ããã°è¯ãããšå®æã«èããã±ãŒã¹ãããããç¥ããŸããããããããš10.24.0.0/13以å€ããã®ã¢ã¯ã»ã¹ãèªããããã«å¥ã®Virtual ServerãçšæããããVirtual Serveræ¯ã«ç°ãªãAccess Profileãèšå®ããªããã°ãªããªããªããªã©ã®åé¡ãåºãŠããŸãããããã¯ãŒã¯ç°å¢ã«ãã£ãŠã¯WANåŽãšLANåŽã§å¥ã®Virtual Serverãç«ãŠãããªãã±ãŒã¹ãåºãŠãããããå®æã«ã°ã«ãŒã察å¿ã®ã¢ã¯ã»ã¹å¶åŸ¡ãç®çã«ããVirtual Serverãè€æ°ç«ãŠãŠããã®ã¯ãã»ãŒãã³ã»ã³ã¹ãšãªããŸãã Logon Pageã§å ¥åãããè³æ Œæ å ±ã䜿çšããŠLDAP AuthãšããåŸã«LDAP Queryã§ã°ã«ãŒãæ å ±ãååŸãããšããæµãã«ãªããŸãããèªèšŒãéã£ãåŸã¯ A) MyGroupã§ããã€IPã¢ãã¬ã¹ã10.24.0.0/13ã®å Žå B) MyGroupã§ãªãå Žå ã®ããããã¢ã¯ã»ã¹èš±å¯ãšããããããããã§ã¯ãã¯ããæ°ããäœããŸãããã¯ããäœãããšã§ãã¯ãã®Outã¯è€æ°åèšå®å¯èœã§ãäžèšã®A)ãB)ãããã®å ŽåãOKããã以å€ã® C) MyGroupã§ããã€IPã¢ãã¬ã¹ã10.24.0.0/13以å€ã®å Žå ã¯NGãšããŸãã ããããããšã§ãåå²ãå¢ããããšãªãåãAdvanced Resource Assignãå ±æã§ããã¡ãªããããããŸãããä»®ã«MyGroupã®å Žåã¯å²ãåœãŠãACLãç°ãªãå Žåã¯äžèšã®äŸã§ããšãã¯ãã®MyGroupIPChkã®äžã§åãããŠACLãå²ãåœãŠãŠãããšè¯ãã§ãããã session.ldap.last.attr.grp = âMyGroupâ ãæºãããå Žåã«ã®ã¿è¿œå ã®ãã§ãã¯ãè¡ãããã®IsIPOKã®éšåã¯[Empty]ããäœæããŸãã[Empty]ã¢ã€ãã ãè¿œå ããã¯ã©ã€ã¢ã³ãã®IPã¢ãã¬ã¹ãå ¥ã£ãŠããAPMã®ã»ãã·ã§ã³å€æ°session.user.clientipããã§ãã¯ãããšãã圢ã«ãªããŸãã ã®ããã«Emptyãè¿œå ããŠãããä»åã¯10.24.0.0/13ãªã®ã§8ã€ãããªãããORæ§æã§è€æ°æ¡ä»¶ãæ¥ç¶ã㊠ã®ãããªåœ¢ã§èšè¿°ããã®ãäžã€ã®æ¹æ³ã§ãããã®å Žåã¯8ã€ã§æžããããŸã 楜ã§ãããæ°åãæ°çŸã®æ¡ä»¶ãORã§æ¥ç¶ããã®ã¯ãšã¬ã¬ã³ãã§ã¯ãªãã»ãããã®æ¡ä»¶æã«èšè¿°ã§ããé·ãã«ãå¶éããããŸãã®ã§ãæ±çšçãªãã®ãšããŠã¯ ã®ããã«cidrAddrã«CIDR圢åŒã®ãããã¯ãŒã¯ã¢ãã¬ã¹/ãã¹ã¯ãèšè¿°ãã圢ã«ããã®ãäžã€ã®æ¹æ³ã§ãã345Views0likes0Commentsãã€ããªããç°å¢ãèŠæ±ããâããã¹ããŒããªâDNS
ãã€ããªããç°å¢ã§å€ããDNSã®åœ¹å² ãã¯ã©ãŠãã¯å®ã«å€ãã®ç°å¢ãå€åãããŠãããç§ãã¡ã¯ããããæ¥åé åã§ITæŠç¥ã®èŠçŽããè¿«ãããŠããŸããã¢ããªã±ãŒã·ã§ã³ã®éçºã»å±éã®æ¹æ³ã¯ãDevOpsãžãšå€åãã€ã€ãããITæ¥çã®ããžãã¹ ã¢ãã«ãåŸæ¥ã®ã©ã€ã»ã³ã¹ ã¢ãã«ãããé»æ°ãæ°Žéã®ãããªäœ¿çšéã«åºã¥ããµãã¹ã¯ãªãã·ã§ã³ ã¢ãã«ãžãšå€ããã€ã€ãããŸãã ãããããå¯çšæ§ãããã©ãŒãã³ã¹ãã»ãã¥ãªãã£ã«å¯ŸããèŠæ±ã¯ãäŸç¶ãšããŠå€ãããŸãããäŒæ¥ITãã¯ã©ãŠãã«ã·ããããŠããã®ãšåæ§ã«ãæ¶è²»è ã«ããã¢ãã€ã«ããŠã§ãã¢ããªã±ãŒã·ã§ã³ã®å©çšãæ¿å¢ããŠããŸããITç°å¢ãåçãªå€åãç¶ããäžãå¯çšæ§ã®äžè¶³ãããã©ãŒãã³ã¹ã®äœãã¯ãã¢ããªã±ãŒã·ã§ã³ã®æåŠãåãã倧ããªèŠå ã«ãªããŸãã ããã€ããªããç°å¢ã®å°å ¥ã»æŽ»çšãé²ãã«ã€ããŠã以åãããå¯çšæ§ãããã©ãŒãã³ã¹ã®ç¢ºä¿ã¯é£ãããªã£ãŠããŸãããã€ããªããç°å¢ã«ãããŠã¯ãè€æ°ã®ãããªã㯠ã¯ã©ãŠããããŒã¿ã»ã³ã¿ãŒã«ã¢ããªã±ãŒã·ã§ã³ãæ¡æ£ããŠããŸãããã®ãããå¯çšæ§ãããã©ãŒãã³ã¹ã¯ãæ§ã ãªå€åèŠå ã«ãã£ãŠå·Šå³ãããããåŸãªãç¶æ³ãçãŸããŠããŸããã ããããããã€ããªããç°å¢ã«ãããŠãå¯çšæ§ãããã©ãŒãã³ã¹ãç¶æããããã«ã¯ãé«ãã€ã³ããªãžã§ã³ã¹ãæ±ããããã®ã§ãã ããã®ã€ã³ããªãžã§ã³ã¹ãæäŸããèŠçŽ ãšããŠçç®ãããã®ããDNSã®ååšã§ãã DNSã¯ã€ã³ã¿ãŒãããã®å šãŠãã«ããŒããé»è©±åž³ã ãšãããŸããèšãæããã°ãäžçäžã®ããããã¢ããªã±ãŒã·ã§ã³ãã¢ããæ©åšãã©ãã«ããã®ããç¹å®ããããã®ããã¯ããŒã³ã§ããDNSããªããã°ããããã¢ããªã±ãŒã·ã§ã³ã¯ããã®æ©èœãæãããªããªããŸããDNSã®åœ¹å²ã¯ã極ããŠã¯ãªãã£ã«ã«ãªãã®ãªã®ã§ãã DNSã«æ±ããããã€ã³ããªãžã§ã³ã¹ãšã¯ DNSãé«ãã€ã³ããªãžã§ã³ã¹ãåããããšã¯ããã€ããªããç°å¢ã«ãããå¯çšæ§ãããã©ãŒãã³ã¹ãã»ãã¥ãªãã£ã確ä¿ããäžã§ãéèŠãªæå³ãæã¡ãŸãããã€ããªããç°å¢ã§ã¯ããç®çã®ã¢ããªã±ãŒã·ã§ã³ãã©ãã«ããã®ãããšããèŠæ±ã«å¿ããã ãã§ã¯ãªããã¯ã©ã€ã¢ã³ãã®ããå Žæãã¢ããªã±ãŒã·ã§ã³ã®ç¶æ³ãæ£ç¢ºã«ææ¡ããå Žåã«ãã£ãŠã¯ãç°ãªããµã€ãã«çœ®ãããã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ãããããšãã£ãå€æãããå¿ èŠã«è¿«ãããããã§ãã ããã®ã€ã³ããªãžã§ã³ããªå€æãå¯èœã«ããŠããã®ããF5ã®BIG-IP DNSã§ããBIG-IP DNSã¯å®¹éã倧ããæ¡å€§ãããã ãã§ã¯ãªãããã€ããªããç°å¢å šäœã«ããã£ãŠã¢ããªã±ãŒã·ã§ã³ã®ç¶æ³ãããã©ãŒãã³ã¹ãç£èŠããä»ã®å šãŠã®BIG-IP DNSãšé£æºããªãããããããã®ã¯ã©ã€ã¢ã³ããã©ããžã¢ã¯ã»ã¹ããããããªã¢ã«ã¿ã€ã ã§å€æããŸãã ãæã«ã¯ãDNS DDoSæ»æãé²æ¢ããããã®å¯Ÿå¿çãšããŠããã¯ã©ã€ã¢ã³ãããã®åãåããã«å¿çããªãããšããå€æãè¡ãããšããããŸãã DNS DDoSæ»æã®è¢«å®³ã¯ãæ¡å€§ã®äžéããã©ã£ãŠããŸããæè¿ã®ãã調æ»ã«ããã°ããDNSããŒã¹ã®DDoSæ»æã¯2014幎ã«æ¿å¢ããŠããã2015幎ãæ»æãæ¿ãããå¢ããŠããããšã¯æçœã§ããããšå ±åãããŠããŸããæ¥æ¬ã§ãã2014幎5æãã7æã«ãããŠãåœå ã®ã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããDNS DDoSæ»æãåããŠãæ°é±éã«ãããéä¿¡é害ãçºçããäºä»¶ããããŸããããŸãå¥ã®ã¬ããŒãã§ã¯ã極ããŠå€§éã®ããŒã¿ãéãã€ããâãã€ããªã¥ãŒã ãªDDoSæ»æâãã2015幎ãç¶ç¶çã«è¡ãããŠãããšææãããŠããŸããæšå¹Žã¯ãDNSãã€ãžã£ãã¯ãã¯ãããšããDNSããŒã¹ã®æ»æã«ãã£ãŠãè€æ°ã®èåäŒæ¥ãé倧ãªåé¡ã«çŽé¢ããŸãããä»åŸããã®ãããªç¶æ³ãããã«æªåããããšã¯ãééããªãã§ãããã ãã€ãŸãDNSã«ã¯ãã¢ããªã±ãŒã·ã§ã³ã«åœ±é¿ãåãŒãåŸãå šãŠã®æ»æãæ€åºãããšåæã«ãé²åŸ¡ããããã®ã€ã³ããªãžã§ã³ã¹ãäžå¯æ¬ ãªã®ã§ãã DNSã®ã»ãã¥ãªãã£ãã©ã確ä¿ããã ãæ¬æ¥ã®å®çŸ©ã«ãããŠãèšèšã»å®è£ ã«ãããŠããDNSã«ã¯ãªãŒãã³ã§ããããšãæ±ããããŸããäžè¬ã®ãŠãŒã¶ãŒãå©çšãããŠã§ãã¢ããªã±ãŒã·ã§ã³ãšåæ§ãDNSããªãŒãã³ãªç¶æ ã«ç¶æããããšãšãã«åžžã«å©çšå¯èœã§ãªããã°ãªããŸããããã€ããªã¥ãŒã ãªDDoSæ»æãåé¿ããããã«DNSãåæ¢ãããã°ãæ¬æ¥ã®æ©èœã倱ãããšã«ãªããŸãããã®ãããªç¶æ³ã«ãããŠDNSã«ã¯ã2ã€ã®æ©èœãåæã«å®çŸããããšãæ±ããããŠããŸãããæ»æãæ€åºããŠèªããä¿è·ãããæ©èœãšãæ£åœãªèŠæ±ã«ã¯è¿ éã«å¯Ÿå¿ãããæ©èœã§ãã ãããã§èšãâè¿ éâãšã¯ãâ極ããŠè¿ éã§ããâãšããããšã§ããã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ã®ã¬ã¹ãã³ã¹ãæªåãããèŠå ã®1ã€ãšããŠãDNSã®ã«ãã¯ã¢ããæéã¯ãã°ãã°éé£ãããŠããŸããDNSã®å¿çé床ã¯ãéããã°éãã»ã©å¿«é©æ§ããããããŸããããããæ»æããDNSèªèº«ãå®ãããã®åŠçã¯ãå¿çé床ã®æªåã«ã€ãªãããããŸããã ãäŸãã°ãDNSã¬ã³ãŒãã®ç Žå£ãé²æ¢ããããã®äžè¬çãªææ³ãšããŠããããã³ã«æ€èšŒããããŸãããããããããã³ã«æ€èšŒã«æéãããã£ãŠããŸããšãå¿çé床ãæªåãããŠãŠãŒã¶ãŒã®å¿«é©ãªäœéšãæãªãçµæã«ã€ãªãããããŸããããããã³ã«æ€èšŒã¯å¯èœãªéããé«éãã€æ£ç¢ºã«è¡ãã¹ããªã®ã§ããBIG-IP DNSã¯ããããã³ã«æ€èšŒãããŒããŠã§ã¢ã§è¡ãããšã«ããããã®èª²é¡ãã¯ãªã¢ããŠããŸãããœãããŠã§ã¢ã®ã¿ã®å Žåã«æ¯ã¹ãŠãåŠçé床ã¯7åãé«éåãããŠããŸããBIG-IP DNSã䜿çšããããšã§ãæ»æã«èããã»ãã¥ãªãã£èœåã確ä¿ããªãããå¿«é©ãªã¢ããªã±ãŒã·ã§ã³å©çšãå¯èœã«ãªããŸãã ããŸããBIG-IP DNSã¯ãããŒããŠã§ã¢ã«ãã£ãŠDNSãã£ãã·ã¥ãæ¡åŒµããããšãå¯èœã§ãããœãããŠã§ã¢ã«ãããã£ãã·ã¥ã«æ¯ã¹ãŠããã®å°çšããŒããŠã§ã¢ã¯æ倧5åã®ãµã€ãºã確ä¿ããããšã§ãããé«éãªå¿çãå¯èœã«ããŸããDNSã®å¿çæéãå€§å¹ ã«ççž®ãããã°ãã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ãã¹ã¯ã€ãããåŸã®ç»é¢è¡šç€ºãææ°ããŒã¿ãžã®æŽæ°ã«ãããæéãççž®ãããããå¿«é©ãªã¢ããªã±ãŒã·ã§ã³å©çšãå¯èœã«ãªããŸãã ããã®ããã«DNSã¯ãåã«ãã¢ããªã±ãŒã·ã§ã³ãã©ãã«ããã®ãããèŠã€ãåºãããã ãã®ããŒã«ã§ã¯ãããŸãããã©ã®ã¢ããªã±ãŒã·ã§ã³ãã©ã®ãµãŒãã¹ããããã¯ãã©ã®ãµã€ããžãšã¯ã©ã€ã¢ã³ããæ¯ãåãããã«ã€ããŠãã€ã³ããªãžã§ã³ããªå€æãã¹ããŒãã«äžãããã®åºç€ãªã®ã§ãããã€ããªããå±éã®æè»æ§ãç ç²ã«ããããšãªããå¯çšæ§ãããã©ãŒãã³ã¹ãé©åã«ã³ã³ãããŒã«ãããšãšãã«ãé«ãã»ãã¥ãªãã£ã確ä¿ããããã«ã¯ãDNSã®åœ¹å²ãæ·±ãç解ããç©æ¥µçã«æŽ»çšããããšãæ±ããããŠããŸãã251Views0likes0CommentsHTTP/2ãããããããžãã¹äžã®æ矩
ãããã©ãŒãã³ã¹ã®ç¢ºä¿ã¯ãã¢ããªã±ãŒã·ã§ã³ã«ãšã£ãŠéèŠãªèª²é¡ã§ããç¹ã«ã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ã§ã¯æéèŠèª²é¡ã ãšèšã£ãŠãéèšã§ã¯ãªãã§ãããããããŸã§è¡ãããŠããæ°ã ã®èª¿æ»çµæãèŠãã°ã誰ã§ããã®çµè«ã«éããããšãã§ããã¯ãã§ããã¢ããªã±ãŒã·ã§ã³ã5ç§ä»¥å ã«åå¿ããªããã°ãäžè¬æ¶è²»è ãäŒæ¥ãŠãŒã¶ããåãããã«èç«ã¡ãŸãããªãã§ãæ¶è²»è ãã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ã䜿ã£ãŠè³Œå ¥ãªã©ãè¡ãå Žåã«ã¯ãããã©ãŒãã³ã¹ã®äœããèŽåœå·ã«ãªãå±éºæ§ããããŸãã ããã®ãããªããã©ãŒãã³ã¹ã«å¯ŸããèŠæ±ãžã®å¯Ÿå¿ã念é ã«å ¥ããŠéçºãããã®ãHTTP/2ã§ãã HTTP/2ã«ã¯ããããŸã§éçºè ãHTTP/1.1ã«ãããããã©ãŒãã³ã¹æ¹åçãšããŠé »ç¹ã«äœ¿çšããçµæãæšæºçãªææ³ã«ãªã£ãŠãã£ããã®ãæ°å€ãå®è£ ãããŠããŸããäŸãã°ãå°ããªç»åãæååã«å€æããŠHTMLãCSSã«åã蟌ãããšã§HTTPãªã¯ãšã¹ããåæžããã€ã³ã©ã€ã³åããå°ããªãã¡ã€ã«ã®çµåïŒConcatenationïŒãéçãã¡ã€ã«ãå¥ã®ãã¡ã€ã³ããèªã¿èŸŒãããšã§åææ¥ç¶æ°ã®äžéãæ倧åãããã¡ã€ã³ ã·ã£ãŒãã£ã³ã°ãªã©ã®ææ³ã§ãããããã¯ããããããã©ãŒãã³ã¹æ¹åã«è²¢ç®ããŸããããæ®å¿µãªããéçºè ãšéå¶è ã®åæ¹ã«å¯Ÿãã倧ããªâæè¡çè² åµâãããããçµæãšãªããŸããã HTTP/1.1ãçã¿åºããâæè¡çè² åµâ ãããã§èšãâæè¡çè² åµâãšã¯ãç¹å®ã®æè¡ã補åãã¢ãŒããã¯ãã£ãæ¡çšããããšã§ããããããããã®åŸã®éçºãéå¶ãžã®ãã€ãã¹ã®åœ±é¿ãæå³ããŠããŸãããŸãç¹å®ã®ãœãªã¥ãŒã·ã§ã³ããã¢ãŒããã¯ãã£å ã®ã©ãã«å®è£ ãããã®å€æããæè¡çè² åµã®èŠå ã«ãªãå¯èœæ§ããããŸãã ãäŸãã°ãHTTP/1.1ã®å¶çŽãåé¿ããããã«å©çšãããŠããã€ã³ã©ã€ã³åããã¡ã€ã«çµåã¯ããããã¯ãŒã¯äžã®ãã£ãã·ã¥ã®å©çšãäžå¯èœã«ããŠããŸããŸããããŸããããã®ã€ã³ã©ã€ã³åãããã€ã¡ãŒãžããã¡ã€ã«çµåã¯ããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã«åæ ããå¿ èŠããããããã¢ããªã±ãŒã·ã§ã³ã®ã©ã€ããµã€ã¯ã«ã«ã泚æãæãå¿ èŠããããŸããã€ãŸããããã®ææ³ã䜿ãããšã§ãã¢ããªã±ãŒã·ã§ã³ã®ã¢ãžã¥ãŒã«æ§ã倱ãããŠããŸã£ãã®ã§ãããã®ãããªæè¡çè² åµã¯ã察象ãšãªãã¢ããªã±ãŒã·ã§ã³ã䜿ããç¶ããéããéçºè ãéå¶è ãæ©ãŸãç¶ããããšã«ãªãã§ãããã ãééçè² åµãšåæ§ãæè¡çè² åµã«ã察å¿ãå¿ èŠã§ãããã®ãŸãŸæŸçœ®ããŠããã°âå©åâãçºçããããã§ãããã®å©åã¯ã¢ããªã±ãŒã·ã§ã³ã®å€æŽãã¢ããããŒããè¡ããããã³ã«èç©ãããéçºè ã¯å¿ èŠä»¥äžã®æéãšæ³šæåãè²»ããããšã«ãªããŸãããŸããã¹ãã®ããã®ãªãœãŒã¹ãå¿ èŠã«ãªãããããã¯ãŒã¯ãã³ã³ãã¥ãŒãã£ã³ã°ã®ãªãœãŒã¹ãæ¶è²»ããŸãããã®çµæãäŒæ¥ã¯ã€ãããŒã·ã§ã³ãæé·ã®ããã§ã¯ãªããè² åµãžã®å¯Ÿå¿ã«æéãè²»ããããšã«ãªãã競äºåãçã¿åºãæ°ããæè¡ãææ³ãã¢ãŒããã¯ãã£äžã®ã³ã³ã»ãããªã©ã掻çšããããšãå°é£ã«ãªããŸãã HTTP/2ãžã®ç§»è¡ãå¯èœã«ããè² åµããã®è§£æŸ HTTP/1.1ã§çããæè¡çè² åµã¯ãå°æ¥çã«HTTP/2ãžãšç§»è¡ããããšã§è§£æ¶ã§ããŸããHTTP/2ã¯ãæè¡äžã»ãããã³ã«äžã®å¹ åºãå¶çŽã«åãçµãã çµæãéçºè ãéå»ã®è¿åçãæšãŠãæ°ããªéžæè¢ãæã«å ¥ããããšãå¯èœã«ããããã§ãããããŠãããã®æ°ããªéžæè¢ã«ã¯ãæè¡çè² åµã¯äŒŽããŸããããã¡ããæ¢åã¢ããªã±ãŒã·ã§ã³ã¯ãããŸã§ã®è² åµãæ±ãããŸãŸã«ãªããŸãããHTTP/2察å¿ã®ã¢ããªã±ãŒã·ã§ã³ãžã®ç§»è¡ã眮ãæããé²ããããšã§ãHTTP/1.1ãçã¿åºããŠããå¶çŽãããéçºè ãéå¶è ã解æŸãããŠããã§ãããã ããã®ããã«ãHTTP/2ã®æ矩ã¯é«éåã ãã§ã¯ãããŸãããæè¡çè² åµã«ããå¶çŽããéçºè ãéå¶è ã解æŸããäŒæ¥ã«ããã©ãŒãã³ã¹æ¹åã®ããã®æ°ããªæ段ã掻çšãããã£ã³ã¹ãããããããšããéèŠãªæ矩ã ãšèšããŸããæè¡ãã¢ãŒããã¯ãã£é¢ã§ã®è² åµãçãããã«ããæ段ã掻çšããã°ãäŒæ¥ã¯ã¢ããªã±ãŒã·ã§ã³ç«¶äºã«ãããŠãåå©ãåãããããªãã®ã§ãã æ°èŠäºç®ã®ãã¡ãã€ãããŒã·ã§ã³ã«äœ¿ãããå²åã¯ããã3åã®1æªæºã§ããããã®ä»ã¯åãªãæ¹åã«è²»ããããŠãããšCIOéã¯èªããŠããŸãã247Views0likes0CommentsäŒæ¥ã¢ããªã±ãŒã·ã§ã³ã§ãé²ãã¯ã©ãŠããžã®ç§»è¡
ããã€ãŠã¢ããªã±ãŒã·ã§ã³ã¯ãåäžã®ã€ã³ãã©ã¹ãã©ã¯ãã£äžã§éäžçã«ç®¡çãããŠãããããŒã¿ã»ã³ã¿ãŒå ã§ã¯ãå€éšãããã¯ãŒã¯ãšã®å¢çã«ããã€ãã®ã»ãã¥ãªãã£æ©èœãé 眮ããããšã§ä¿è·ãããŠããŸãããITéšéã®åœ¹å²ã¯ãããŒã¿ã»ã³ã¿ãŒå ã§çšŒåããã¢ããªã±ãŒã·ã§ã³ã®å¯çšæ§ãããã©ãŒãã³ã¹ãã»ãã¥ãªãã£ã確ä¿ããããšã§ãããã¢ããªã±ãŒã·ã§ã³ã®ã©ã€ããµã€ã¯ã«å šãŠã管çããããšãå¯èœã§ããã ããããããã®ãããªãããŒã¿ã»ã³ã¿ãŒã§å šãŠã管çã§ãããšãããããªç¶æ³ã¯ããã§ã«éå»ã®ãã®ã ãšãããŸããçŸåšã§ã¯ãå€ãã®ã¢ããªã±ãŒã·ã§ã³ã«ãããŠããã©ã€ããŒãã¯ã©ãŠãããããªã㯠ã¯ã©ãŠããžã®ç§»è¡ãé²ãã§ããŸããCIOã¯ç®¡çæ§ãšåŒãæãã«ãä¿ææ§ãšã³ã¹ãåæžãå¯èœã«ããã¯ã©ãŠãããŒã¹ã®ã¢ãã«ãéžæãã€ã€ãããŸãã ãå€ãã®æ¥åã¢ããªã±ãŒã·ã§ã³ã¯ããã§ã«ã¯ã©ãŠããžãšç§»è¡ããŠãããSaaSã®å©çšãåºãã£ãŠããŸãããŸããIaaSã¢ãã«ãæ¡çšããã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ã®æŽ»çšãæ¡å€§ããŠããŸãããã®ãããªå€æ§ãªç°å¢ã«ãããŠãä»æ¥ã®ITéšéã¯ãã¢ããªã±ãŒã·ã§ã³ã®å¯çšæ§ãããã©ãŒãã³ã¹ãã»ãã¥ãªãã£ãä¿èšŒããªããã°ãªããªãã®ã§ããé«ããµãŒãã¹ã¬ãã«ãæ±ããããã®ã¯ãããã·ã§ã³ã¯ãªãã£ã«ã«ãªã¢ããªã±ãŒã·ã§ã³ã ãã§ã¯ãããŸãããäŸãã°ãæ¶è²»è åãã®ã¢ããªã±ãŒã·ã§ã³ã§ã¯ãããŠã³ããŒãåæ°ããšã³ã²ãŒãžã¡ã³ãçãéèŠãããåŸåã«ãããŸããããããã«ãããŠããé«ãå¯çšæ§ãšããã©ãŒãã³ã¹ãã»ãã¥ãªãã£ãæ±ããããŸãã ããã®ãããªç¶æ³ã«é©åã«å¯ŸåŠããããã«ãå šãŠã®ã¢ããªã±ãŒã·ã§ã³ã«ã¯âã¢ããªã±ãŒã·ã§ã³äžå¿ã®æŠç¥âãå¿ èŠãšèšãããŠããŸãããããŠããã®æŠç¥ãå ·çŸåããããã«ã¯ãã¢ããªã±ãŒã·ã§ã³ãå±éãããŠããå Žæã«ããããããé©åãªã¢ããªã±ãŒã·ã§ã³ãµãŒãã¹ïŒL4-L7ãµãŒãã¹ïŒãäžå¯æ¬ ãšãªããŸãã ã¢ããªã±ãŒã·ã§ã³äžå¿ã®æŠç¥ãšã¯ ãããã§ã¯ãã¢ããªã±ãŒã·ã§ã³äžå¿ã®æŠç¥ãšã¯ãå ·äœçã«ã©ã®ãããªãã®ãªã®ã§ãããããããã¯ãã¢ããªã±ãŒã·ã§ã³ã®å±éã¢ãã«ïŒãããã€æ¹æ³ãå ŽæçïŒã«ããããããå šãŠã®ã¢ããªã±ãŒã·ã§ã³ã«äžè²«ãããµãŒãã¹æäŸãä¿èšŒããæŠç¥ã§ãã ãã¯ã©ãŠããžã®ç§»è¡ã¯ãåææè³ãéå¶ã³ã¹ãã®åæžãå¯èœã«ããŸãããããããâã¯ã©ãŠããã¡ãŒã¹ãæŠç¥âã ãã§ã¯ååã§ã¯ãããŸãããã¯ã©ãŠãã«ç§»è¡ããŠã³ã¹ããåæžã§ãããšããŠããããã©ãŒãã³ã¹ãå¯çšæ§ãäœäžããŠããŸãã°çç£æ§ã¯äœäžãã倧ããªæ倱ãæãå±éºæ§ãããããã§ããã¯ã©ãŠããžã®ç§»è¡ã¯ãITéšéã®ããžãã¹ã¢ãã«ããããã¯ãŒã¯ ã¢ãŒããã¯ãã£ãã¢ããªã±ãŒã·ã§ã³ã®å±éææ³ãããŒããŠã§ã¢ããœãããŠã§ã¢ã®éžæãªã©ãäŒæ¥ITã«ããããæ§ã ãªåŽé¢ãåŠå¿ãªãå€åãããŠããŸããããããã¢ããªã±ãŒã·ã§ã³ãéèŠã§ãããšããããšã¯ãäŸç¶ãšããŠå€ãããŸããããåžžã«é©åãªç¶æ ã§ã¢ããªã±ãŒã·ã§ã³ãå©çšã§ããããšããæåªå ã«ããæŠç¥ããã¢ããªã±ãŒã·ã§ã³äžå¿ã®æŠç¥ãªã®ã§ãã ããŸããã¯ã©ãŠã移è¡ã«ãã£ãŠè€éåããç°å¢ã«ãããŠã¯ããããŸã§å¹ã£ãŠããã¹ãã«ãããªã·ãŒã®ç¶ç¶çãªå©çšãå¯èœã«ããããšãéèŠã§ããäŒæ¥ã®ITéšéã«ãšã£ãŠããããã¯å€§åãªè³ç£ã ããã§ããããã«ä»åŸã¯ãDevOpsã«ããç¶ç¶çãªéçºã»å±éã»éçšã®å®çŸãæ±ããããŸããã¢ããªã±ãŒã·ã§ã³äžå¿ã®æŠç¥ã¯ããã®ãããªèŠæ±ã«ãå¿ããªããã°ãªããŸããã ãã¯ã©ãŠãæ代ã«ãããŠãã¢ããªã±ãŒã·ã§ã³äžå¿ã®æŠç¥ãé©åãããããã«ã¯ãã¢ããªã±ãŒã·ã§ã³ ãµãŒãã¹ãé²åããå¿ èŠããããŸãããªã³ãã¬ãã¹ãã¯ã©ãŠããSaaSã®ãããã®ç°å¢ã«ãããŠããã¢ããªã±ãŒã·ã§ã³ã®å¯çšæ§ãããã©ãŒãã³ã¹ãã»ãã¥ãªãã£ãä¿èšŒã§ããä»çµã¿ãå¿ èŠãªã®ã§ãããããŠãããããäžè²«ããŠå±éãã管çããããšãæ±ããããŸãã ã¢ããªã±ãŒã·ã§ã³äžå¿ã®æŠç¥ãæåã«å°ãã«ã¯ ãF5ã¯ãã®ãããªèŠä»¶ã«å¿ãããšãšãã«ãã¯ã©ãŠãæ代ã«ãããã¢ããªã±ãŒã·ã§ã³äžå¿ã®æŠç¥ãæåã«å°ããããã€ãããŒã·ã§ã³ãç¶ç¶çã«æšé²ãã補åã®æ¡åŒµã«åãçµãã§ããŸããããã®åãçµã¿ã®äžæ žã«ã¯ãBIG-IPã«ããé ä¿¡/ã»ãã¥ãªãã£ãµãŒãã¹æ©èœãšãBIG-IQãæã€ç®¡ç/ãªãŒã±ã¹ãã¬ãŒã·ã§ã³æ©èœã®åŒ·åããããŸããåãçµã¿ã®çµæãF5ã¯ãã¢ããªã±ãŒã·ã§ã³äžå¿ã®æŠç¥ãããã«åŒ·åã«ãµããŒãããæ°æ©èœãçã蟌ãã ãBIG-IP 12.0ã®ãªãªãŒã¹ã«è³ããŸããã BIG-IP 12.0ã¯ãSSL Everywhereãæ¡åŒµãããäžæ£é²æ¢æ©èœãOffice 365ãªã©ãã©ãŠã¶ã䜿çšããªãç°å¢ããµããŒãããæå 端ã®SAML匷åãã¯ãããšããSSOïŒã·ã³ã°ã« ãµã€ã³ãªã³ïŒã®æ¹åãECCïŒæ¥åæ²ç·æå·ïŒãFSïŒãã©ã¯ãŒã ã»ãã¥ãªãã£ïŒãCamelliaãšãã£ãæ°ããªæå·ã®ãµããŒãã«ãããã©ã€ãã·ãŒä¿è·ãšã¡ãã»ãŒãžæ¹ããé²æ¢ã®åŒ·åãªã©ãã¢ããªã±ãŒã·ã§ã³ ã»ãã¥ãªãã£ã®ããã®ææ°ã®æ段ãæäŸããŠããŸãããŸãããã£ãã·ã¥æ¡åŒµãHTTP/2ãžã®å¯Ÿå¿ããããŠãã€ããŒã¹ã±ãŒã«ãªDNSã«ãã£ãŠãã³ã¹ãã®ãããã¢ããªã±ãŒã·ã§ã³æ¹ä¿®ãè¡ãããšãªããå€æ§ãªç°å¢ã«ãããããã©ãŒãã³ã¹åäžãå¯èœã«ããŠããŸãã ããªã³ãã¬ãã¹ããã©ã€ããŒã ã¯ã©ãŠãããããªã㯠ã¯ã©ãŠããããã«ã¯SDNã«ã察å¿ãããããF5ã¯BIG-IQãšBIG-IPã«ãããªãŒã±ã¹ãã¬ãŒã·ã§ã³ãšç®¡çæ©èœã®æ¡åŒµãç¶ç¶ããŠããŸãããããŸã§ã«ããF5ã¯ãCisco ACIãVMware NSXãOpenStackãVMware vCloud AirãAmazon Web Servicesãã«ããŒãããšã³ã·ã¹ãã ãäœãäžããŠããŸããããä»åããã«Microsoft Azureãå ãããŸããããŸããã¯ã©ãŠããDevOpsãžã®åãçµã¿ãæ¯ãããããä»®æ³åããã軜éã®è² è·åæ£ãœãããŠã§ã¢ã§ããLineRate Pointãå«ããå¹ åºããœãããŠã§ã¢ããã§ã«æäŸããŠããŸãããããããè£å®ããæ¡åŒµãããããã°ã©ãã³ã° ããŒã«ãæ°ãã«æäŸããŠããŸããDevOpsã®ããã»ã¹ãèªååããŠããããã«ã¯ãAPIãšããŒã¿ ãã¹ ã¹ã¯ãªãããå¿ èŠã«ãªããŸããããã®èŠæ±ã«å¯Ÿå¿ããããF5ã¯ãiRulesãšãã£ã¿ãŒãšæ¡åŒµãããiControl APIã®æäŸãéå§ããŠããŸãã ãããã§ã¯çŽ¹ä»ããããŸããã§ããããF5ã¯è£œåã®æ¹åãšåŒ·åãæ©èœã®è¿œå ãç©æ¥µçã«é²ããŠããŸãããããã®åãçµã¿ãéããŠF5ã¯ãäŒæ¥ã®ITéšéãã¢ããªã±ãŒã·ã§ã³äžå¿ã®æŠç¥ã«åºã¥ããã¢ããªã±ãŒã·ã§ã³ã®éçºããå±éãéçšã«è³ããŸã§ããã¯ã©ãŠããžãšæ¡å€§ãç¶ããããšãæ¯æŽããŸãã244Views0likes0Comments埡瀟ã®ãå šãŠã®ããæ¥åã¢ããªã±ãŒã·ã§ã³ãå¯çšæ§ãé«éåãã»ãã¥ãªãã£ãæ ä¿ãããŠããŸããïŒæå€ã«ç¥ãããŠããªããäŒæ¥ã€ã³ãã©ã®ã¢ããªã±ãŒã·ã§ã³ç°å¢ã®èª²é¡ã«å¯ŸããF5 ã®åçãšã¯?
BYODïŒå人端æ«ã®æ¥åå©çšïŒãªã©ã®è¿œã颚ã«åŸæŒããããã¹ããŒãããã€ã¹ã®æ®åãã€ã³ã¿ãŒãããéä¿¡éã®æ¿å¢ã«ãããéä¿¡ã€ã³ãã©ã¯æ¿å€ã®çã£åªäžã«ãããŸããåžå Žèª¿æ»äŒç€Ÿã®ããã¹ãïŒãµãªãã³ç€Ÿã¯ãã¢ãã®ã€ã³ã¿ãŒããã(Internet Of Things, IoT)ã«ãããŠãæ¥ç¶ãããããã€ã¹ã®æ°ã¯ã2020幎ãŸã§ã«äžçã§800åå°ã«éãããšäºæž¬ããŠããŸãã ãŸããã¢ã«ã¬ã³ã»ã¹ã¿ã³ã¬ãŒã®æšèšã«ãããšãäžè¬çãªãã¡äŒæ¥ã«éçšãããŠããã¢ããªã±ãŒã·ã§ã³ã®æ°ã¯ãå¹³åã§1,000ã«ãäžããšãããŠããŸããèªç€Ÿããžãã¹ãã¢ããªã±ãŒã·ã§ã³ã«äŸåããã°ããã»ã©ããããã®ã¢ããªã±ãŒã·ã§ã³ãã»ãã¥ã¢ã§ããããšããèœã¡ãªããããšïŒããããé«å¯çšæ§ïŒããããŠé 延ç¥ããã§å®å®ããé«éãªã¢ã¯ã»ã¹ç°å¢ã§ããããšããããããªèŠæ±ã¯åœç¶ã®ãã®ãšãªããŸãããŸãããããã¯ãŒã¯å±€ãäž»ã«çã£ããã®ãããåŸã ã«ããé«åºŠãªã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ãçããã®ãžãšé²åããŠããDDoSæ»æãå§ãããµã€ããŒæ»æã®æå£ã¯ããã«å·§åŠåããŠããŠããŸãã ããããã¢ããªã±ãŒã·ã§ã³ãå¢ããã°å¢ããã»ã©ããããŠç°å¢ãé«åºŠåè€éåããã°ããã»ã©ãå šãŠã®ã¢ããªã±ãŒã·ã§ã³ã«å¿ ããããã®ã»ãã¥ãªãã£ãå¯çšæ§ãé«éåãªã©ã®åºç€ãæŒãç¡ãæäŸããããšã¯å°é£ã«ãªããŸããçµæãäºå®ãšããŠãåªå 床ã®é«ãã¯ãªãã£ã«ã«ãªã¢ããªã±ãŒã·ã§ã³ããé ã«ãã®ãããªåºç€ãå±éããŠãããäžæ¬æãªãããäžéšã®ã¢ããªã±ãŒã·ã§ã³ã¯è匱ãªåºç€ã®äžã§éçšãããŒã¢ããªã±ãŒã·ã§ã³ãããžãã¹ã«äžãã圱é¿ãæ¥å¢ãã«å€§ãããªã£ãŠããŠããã«ããããããããããªæ±ºå®ãäžãå¿ èŠãããäŒæ¥ã€ã³ãã©ã®çŸå Žã¯éåžžã«å€ãã®ã§ãã äžæ¹ãITã€ã³ãã©ã«ãããåçãªç°å¢ã®å€åã«ããããŒã¿ã»ã³ã¿å ã®ã¢ããªã±ãŒã·ã§ã³éçšã»ç®¡çã®çŸå Žã®ããŒãºãå€ãã£ãŠããŠããŸããã¯ã©ãŠããã¢ããªãã£ãã»ãã¥ãªãã£ãªã©ã®éèŠåºŠãå¢ãããã€ã§ããã©ã®ãããªç°å¢ã«ãããŠãã誰ã«å¯ŸããŠããã¢ããªã±ãŒã·ã§ã³ã確å®ã«æäŸããããšãä»ãŸã§ä»¥äžã«æ±ããããŠããããã§ãããããŠããžãã¹ãã³ã³ã·ã¥ãŒãå©çšãåãããã€ã³ã¿ãŒãããããããã¯ãŒã¯æ¥ç¶ãåæãšããããã€ã¹ãžã®äŸå床ãé«ãŸã£ãŠããããšãæŽã«ãã®åãã«æè»ããããŠããŸãã ãã®ããã«å€åããããŒãºã«å¯ŸããŠãSoftware Defined Networking (SDN)ã®ãããªããœãããŠã§ã¢ãšããã¢ãããŒãã§ãããã¯ãŒã¯ã®æ§ç¯ã»éçšãè¡ãããã¯ãããžãŒãåºçŸããŠããŠããŸãããããã¯ãŒã¯ãå©çšãããµãŒãã¹ãå€æ§åããäžãITã€ã³ãã©ã®éçšã®çŸå Žã§ã¯ãåœç¶æ°ããã¢ããªã±ãŒã·ã§ã³ããµãŒãã¹ãå±éã»å€æŽããããšããæ©äŒãåçã«å¢ããŠããŸãããã®ãããªäžãã¢ããªã±ãŒã·ã§ã³èªäœãçŽ æ©ãéçºããŠãµãŒãã¹ã€ã³ã§ãããšããŠãããããæ¯ããã€ã³ãã©ãçŽ æ©ãæºåã§ããªããã°ããèªäœãããžãã¹ã®è¶³ãããšãªã£ãŠããŸããŸãããã®åé¡ã解決ãããããSDNã®ãããªæè¡ã泚ç®ããããœãããŠã§ã¢ã®èŠç¹ã®ïŒãŸãã«ãœãããŠã§ã¢å®çŸ©ã®ïŒéçšãæåŸ ãããŠããŸãã ããŠããããŸã§ã®SDNã«ã€ããŠã¯ãäžè¬çã«è°è«ãããŠããããåãã®æ¹ãå€ãããšæããŸãã ãšããããçŸåšã®SDNã®è°è«ã«ãããŠãç€ç³ãªL2L3ã¬ã€ã€ã®æ§ç¯ãæšæºåã«è©±é¡ãéäžããäžæ¹ãL4L7ãããããã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ã®è°è«ã«ã¯è³ããªãåŸåãããããã§ãã ã¢ããªã±ãŒã·ã§ã³ãèœã¡ãããšãªããé«ãå¯çšæ§ãä¿ã¡ãäžã€ã»ãã¥ã¢ã§ããç¶ããã«ã¯ãã®ã¬ã€ã€ã®æè¡ïŒL4-L7ãã©ãã£ãã¯åŠçïŒããã£ããæ€èšã»èšèšããäºãäžå¯æ¬ ã§ããF5ã¯èªèº«ã®ãœãªã¥ãŒã·ã§ã³çŸ€ããL2-L3ã«ãããSDNã®ã¢ãããŒããL4-L7ïŒã®ã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ïŒã«å¿çšãããã€ããããL2-L3åºç€ã®SDNæè¡ãåŸæ¥åã®ãããã¯ãŒã¯æè¡ã«ã·ãŒã ã¬ã¹ã«å¯Ÿå¿ãããSoftware Defined Application Servicesããšäœçœ®ä»ããŸãããããã¯ãã¢ããªã±ãŒã·ã§ã³ãã®ãã®ãL2-L3ãããã¯ãŒã¯æè¡ãL4-L7ã¢ããªã±ãŒã·ã§ã³é ä¿¡æè¡ãäžäœåãããã¢ããªã±ãŒã·ã§ã³ã¢ããªãã£ãã»ãã¥ãªãã£ãã¢ã¯ã»ã¹ç®¡çããŠãŒã¶ã¢ã€ãã³ãã£ãã£ç®¡çãããã©ãŒãã³ã¹ãšå¯çšæ§ãšãã£ã課é¡ã«å¯Ÿãããœãªã¥ãŒã·ã§ã³ã§ãã ãSoftware Defined Application Servicesãã®äž»ãªç¹åŸŽãšããŠãããŒããŠã§ã¢ã¢ãã©ã€ã¢ã³ã¹ãä»®æ³ã¢ãã©ã€ã¢ã³ã¹ãå€éšã¯ã©ãŠããªã©ã®ããããç°å¢äžã§ã·ãŒã ã¬ã¹ã«åãæ©èœããœãªã¥ãŒã·ã§ã³ãééçã«æäŸã§ããç¹ããããããŸããããã«ãããèªç€Ÿã®ã€ã³ãã©ãããŒã¿ã»ã³ã¿ã ãã§ãªãããã©ã€ããŒãããããªãã¯ããã€ããªãããªã©æ§ã ãªã¯ã©ãŠãç°å¢ãã掻çšããã¹ã±ãŒã©ããªãã£ïŒæ¡åŒµæ§ïŒãå®çŸããããžãã¹ç°å¢ãã©ã®ããã«å€åããŠãæè»ã«ã€ã³ãã©ãå€å¹»èªåšã«å¯Ÿå¿ã§ãããŒãããªãŠãŒã¶ç°å¢ãã¢ããªã±ãŒã·ã§ã³ç°å¢ãæ§ç¯ããäºãå¯èœãšãªããŸãã éèŠãªã®ã¯ããSoftware Defined Application Servicesãã¯ããã åã«æ¬¡äžä»£ã®L2-L3ã€ã³ãã©æè¡ã®äžã§å®å®ããå¯çšæ§ã»é«éæ§ã»ã»ãã¥ãªãã£ãæäŸããã ãã§ã¯ç¡ããšããç¹ã§ããåé ã§ã玹ä»ãããããªãåªå 床ã®é«ãã¢ããªã±ãŒã·ã§ã³ãã«éããªããå šãŠã®ã¢ããªã±ãŒã·ã§ã³ã«å¿ èŠãšãããŠããæè¡ãç¡éã®æ¡åŒµæ§ã«ããæäŸããäºãã§ããã®ã§ããèªç€Ÿã®ãµãŒãã¹ã®éèŠåºŠã倩秀ã«ãããã©ã®ã¢ããªã±ãŒã·ã§ã³ã«ããè¯ãã€ã³ãã©ã®ãªãœãŒã¹ãå²ãåœãŠãããããšæ©ãå¿ èŠããªããªããŒF5ã¯ãããªäžçãç®æããŠãœãªã¥ãŒã·ã§ã³ãæäŸããŠãŸãããŸãã201Views0likes0Commentsäžè¬äŒæ¥åãã®F5 DDoSãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£
ä»åæçš¿ãããããã°ã¯ãF5ãããã¯ãŒã¯ã¹ã®ãã¯ãããžãŒã»ãšãã³ãžã§ãªã¹ãã§ããDavid Holmesã®ããã°æçš¿ãThe F5 DDoS Reference Architecture - Enterprise Editionããå ã«ãæ¥æ¬åãã«åæ§æãããã®ã§ãã DDoSã«ããæ»æã¯äŸç¶ãšããŠç¶ããŠãããçŸåšã§ãDDoSæ»æã«å¯Ÿããé²åŸ¡ã¯éèŠèª²é¡ã§ããç¶ããŠããŸãããã§ã«ãã®DevCentralã§ã¯ãã°ããŒãã«éèæ©é¢åãã®DDoSãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ã玹ä»ããŠããŸãããäžè¬äŒæ¥ã«ãšã£ãŠãDDoSæ»æ察çã¯æ¬ ãããŸãããããã§ä»åã¯ãäžè¬äŒæ¥ïŒãšã³ã¿ãŒãã©ã€ãºïŒåãã®DDoSãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ãæ瀺ããã°ããŒãã«éèæ©é¢åãã®DDoSãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ãšã©ã®ããã«ç°ãªãã®ãã解説ããŸãã ããã®å±éã·ããªãªã¯å€§éã®åä¿¡ãã©ãã£ãã¯ã ãã§ã¯ãªãã瀟å ãŠãŒã¶ããã®éä¿¡ãã©ãã£ãã¯ãããçšåºŠååšããããšãåæã«ããŠããŸãã ã°ããŒãã«éèæ©é¢åããšã®å·®ç° ãã°ããŒãã«éèæ©é¢åãã®ãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ãšã¯ã以äžã®ç¹ãç°ãªã£ãŠããŸãã 1.ãŸãå³ã®å³äžã«ç€Ÿå ãŠãŒã¶ïŒEmployeesïŒãæžã蟌ãŸããŠããã瀟å ãŠãŒã¶ãã瀟å€ã«å¯ŸããŠãŠãŒã¶çæãã©ãã£ãã¯ãçºä¿¡ãããŠããŸãããã®ãã©ãã£ãã¯ã¯æ¬¡äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ïŒNext-Generation FirewallïŒããããã¯Webã»ãã¥ãªãã£ãæäŸããäœããã®ããã€ã¹ãééããåŸãããŒã¿ã»ã³ã¿ãŒã®ã¡ã€ã³ã®ãã¡ã€ã¢ãŠã©ãŒã«ãããã€ã³ã¿ãŒããããžãšåºãŠãããŸãã 2.äžè¬äŒæ¥ã®ãŠãŒã¹ã±ãŒã¹ã§ã¯ãDNSãµãŒãã¹ãæ»æé²åŸ¡ã®ç¬¬1段ã«éçŽãããããå°ãªããšã第1段ã®ãã¡ã€ã¢ãŠã©ãŒã« ãããŒãžã£ã«ãã£ãŠä¿è·ãããã±ãŒã¹ãäžè¬çã§ããããã«ç€ºããå³ã§ã¯ãDNSãµãŒãã¹ãBIG-IPã«éçŽãããŠããŸãã 3.ã°ããŒãã«éèæ©é¢åãã®ãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ã§ã解説ããããã«ãéèæ©é¢ã§ã¯æå·éµãå€éšãããã¯ãŒã¯ããé ããããSSLã第2段ã®ãšããã§çµç«¯ãã¹ãã§ãããããäžè¬äŒæ¥ã®å Žåã«ã¯ããã»ã©å³å¯ã«èããå¿ èŠã¯ãªããããèªç±åºŠã¯ããé«ããªããŸããSSLã®çµç«¯å Žæã第1段ã«ãªãã第2段ã«ãªããã®å¯èœæ§ã¯ãã»ãŒåã ã«ãªããŸãã 4.äžè¬äŒæ¥ã®ãŠãŒã¹ã±ãŒã¹ã§ã¯ãSingle-Sign OnãVDIãSSL-VPNãµãŒãã¹ãæäŸããAccess Policy ManagerïŒAPMïŒã®æŽ»çšãã倧ããªã¡ãªãããããããå¯èœæ§ããããŸãããããã®ãµãŒãã¹ã«ãã£ãŠã瀟å ãŠãŒã¶ã®å©äŸ¿æ§åäžãšã»ãã¥ãªãã£åŒ·åãäž¡ç«ã§ããããã§ããã°ããŒãã«éèæ©é¢ã®ãŠãŒã¹ã±ãŒã¹ã§ã¯ããã®ã¡ãªããã¯ããã»ã©é¡èã§ã¯ãããŸããã ã°ããŒãã«éèæ©é¢åããšã®å ±éç¹ ããªããã®ã¢ãŒããã¯ãã£ã®æ¬è³ªã§ããã2段æ§æã®é²åŸ¡ãšããç¹ã«ã€ããŠã¯ãã°ããŒãã«éèæ©é¢åãã®ãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ãšå ±éããŠããŸãã第1段ã§ã¯DDoSãèªèãããããã¯ãŒã¯ ãã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠãããã¯ãŒã¯æ»æãé²åŸ¡ããæ¡åŒµæ§ã«å¯ãã 第2段ã§ã¢ããªã±ãŒã·ã§ã³æ»æãé²åŸ¡ããŸãã F5ã®DDoSãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ã®è©³çŽ°ã«ã€ããŠã¯ãæ°ããF5 Synthesisãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ã㣠ãµã€ããã芧ãã ããã195Views0likes0Commentsã°ããŒãã«éèæ©é¢åãã®F5 DDoSãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£
ä»åæçš¿ããããã°ã¯ãF5ãããã¯ãŒã¯ã¹ã®ãã¯ãããžãŒã»ãšãã³ãžã§ãªã¹ãã§ããDavid Holmesã®ããã°æçš¿ãThe F5 DDoS Reference Architecture - Global FSI Editionããå ã«ãæ¥æ¬åãã«åæ§æãããã®ã§ãã以äžã¯ãDavid Holmesã®å人çäœéšè«ã«åºã¥ããŠããŸãã ãçããã¯ããžã§ãŒãžã»ã¯ã«ãŒããŒäž»æŒã®ããã€ã¬ãŒãžããã€ã©ã€ãïŒåé¡ïŒUp in the AirïŒããšããæ ç»ã芳ãããšãããã§ããããã1000äžãã€ã«ïŒèªç©ºäŒç€Ÿã®ãã€ã¬ãŒãžããããåœå ç·ã ãã§ïŒéæã人çã®ç®æšã«ããŠããç·ã®ç©èªã§ãããã®æ ç»ã®äžã§äž»äººå ¬ãã幎é35äžãã€ã«ãé£ãã§ãããã ããšèªã£ãŠããããšãæãåºããŸããæãŸã§ã®è·é¢ãçŽ20äžãã€ã«ã§ãããã圌ã¯ããããããã«15äžãã€ã«ã圌æ¹ãžã幎éã§ç§»åããŠããããšã«ãªããŸããç§ïŒDavid HolmesïŒã¯ãã®æ ç»ã倧奜ãã§ãããªããªãç§ãåããããªç¶æ³ã«çœ®ãããŠãããå®ã¯ç§ããã®2幎äœãã®éã«ã30äžãã€ã«è¿ãã空ã®äžã§éãããŠããŸããã 空ã®äžã§æžãäžãã2段æ§æã®ã¢ãŒããã¯ã㣠ãç§ã®æ ã®ã»ãšãã©ã¯ãèåãªã°ããŒãã«éèæ©é¢ãžã®èšªåã§ãããçšä»¶ã¯DDoSæ»æã«å¯Ÿãã圌ãã®ãã£ã¬ã³ãžã«é¢ãããã®ã§ãããã®åãçµã¿ãããããã倧ããªææã®ã²ãšã€ããF5 DDoSãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ïŒF5 DDoS Reference ArchitectureïŒãã§ãããã®ã¢ãŒããã¯ãã£ã¯ãããªã¥ã¡ããªãã¯åãšé察称圢ã®äž¡æ¹ã®DDoSæ»æãé²åŸ¡ããããã«æé©åããããåå²åã®ãããã¯ãŒã¯ ã¢ãŒããã¯ãã£ã§ãããã§ã«ãã®ã¢ãŒããã¯ãã£ãå®çŸããŠããéèæ©é¢ãããã°ãæ§ç¯äžã®éèæ©é¢ããããã¯æ©æ¥ã«æ§ç¯ããããšåžæããŠããéèæ©é¢ããããŸãã ãç§ã¯ãã®ã¢ãŒããã¯ãã£ã«é¢ããããã¥ã¡ã³ããããã¹ãŠé£è¡æ©ã®äžã§æžãäžããæ°ãããF5 reference architecture siteãã«æ²èŒããŸãããé£è¡æ©ã®äžã§ã¯ãçŸäººã¢ãã³ãã³ãã«æææ°ãæ£ãããã以å€ã¯ãéäžããŠç©æžããã§ããããã§ãã ãã®ã¢ãŒããã¯ãã£ã®æ¬è³ªãšããŠãDDoSæ»æã«å¯Ÿããé²åŸ¡æ©èœã2段æ§æã«ããŠããç¹ãæããããŸãã 第1段ïŒãããã¯ãŒã¯é²åŸ¡ ã第1段ã®é²åŸ¡ã¯ããããã¯ãŒã¯ ãã¡ã€ã¢ãŠã©ãŒã«ã®è¿ãã«å®è£ ããŸãããã®é²åŸ¡æ©èœã¯ãSYNãã©ãããICMPãã©ãããšãã£ãæ»æãç·©åããããèšèšãããŠããä»ãã¢ã¯ã»ã¹åç·ã®åž¯å䜿çšçã80ïœ90ïŒ ã«ãªãçšåºŠã®ããªã¥ã¡ããªãã¯æ»æã«ã察å¿ããŸããå€ãã®éèæ©é¢ã¯ç¬èªã®IPã¬ãã¥ããŒã·ã§ã³ ããŒã¿ããŒã¹ïŒãã±ãããéã£ãŠãããœãŒã¹IPã¢ãã¬ã¹ãä¿¡çšã§ãããåŠããèå¥ããããã®ããŒã¿ããŒã¹ïŒãæ§ç¯ããŠãããDDoSæ»æãåããéã«ã¯ãã®æ å ±ã«åºã¥ããŠããœãŒã¹IPã¢ãã¬ã¹ããã®ãã±ãããå¶åŸ¡ããŸãã ããã®ãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ã¯ããããã¯ãŒã¯ ãã¡ã€ã¢ãŠã©ãŒã«ãF5補åãåŠããåããªãå 容ã«ãªã£ãŠããŸããããããããŠèšãããŠããã ããã°ãF5補åã»ã©DDoSæ»æé²åŸ¡ã匷ãæèãããã¡ã€ã¢ãŠã©ãŒã«ã¯ãä»ã«ååšããŸããã 第2段ïŒã¢ããªã±ãŒã·ã§ã³é²åŸ¡ ã第2段ã¯ãCPUè² è·ã®å€§ããé²åŸ¡ã¡ã«ããºã ã§ãããã¢ããªã±ãŒã·ã§ã³ãæèããäžã§å±éãã¹ããšãF5ãæå±ããŠãããã®ã§ãããã®çš®ã®ã¡ã«ããºã ãšããŠã¯ããã°ã€ã³ ãŠã©ãŒã«ãWebã¢ããªã±ãŒã·ã§ã³ ãã¡ã€ã¢ãŠã©ãŒã« ããªã·ãŒãF5 iRulesã掻çšãããã€ããã㯠ã»ãã¥ãªã㣠ã³ã³ããã¹ãããããŸãããŸãSSLã®çµç«¯ãããã®ç¬¬2段ã«å«ãŸããŸãã第ïŒæ®µã«ãããŠãç¹å®æ©èœã«ç¹åããå°çšã®IDS/IPSããã€ã¹ãæ¡çšããå Žåã«ã¯ãããªãã®ã©ãã¯ã¹ããŒã¹ãå°æãããå¯èœæ§ããããŸãã ã©ãã§SSLãçµç«¯ãããã¹ãã ããã®ãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ãçºè¡šããåŸãã第2段ã§ã¯ãªã第1段ã§SSLãçµç«¯ãããããšã¯å¯èœã ãããããšãã質åãè€æ°ã®æ¹ã ããããã ããŸãããçãã¯ãYesãã§ãããç§ãã¡ã®ã客æ§ã®äžã«ããã®ãããªã±ãŒã¹ã¯ååšããŸããããããããã®ã客æ§ã¯ã°ããŒãã«ãªéèæ©é¢ã§ã¯ãããŸãããã°ããŒãã«ãªéèæ©é¢ã¯ã§ããéãã圌ãã®æå·éµãæåç·ã®ãã¡ã€ã¢ãŠã©ãŒã«ã®åŸãã«é ãããšããŠããŸãã圌ãã®è³ç£ã¯ã€ã³ã¿ãŒãããã®äžã§æãé«ã䟡å€ãæã€æ»æã¿ãŒã²ããã§ãããSSLã®æå·éµã¯ãã®æãããã®ã ãšèšããããã§ãã ããã®ã¢ãŒããã¯ãã£ã«é¢ãã詳现ã¯ãF5 Synthesis reference architecture siteãã§è§£èª¬ããŠããŸãããŸããã®ãµã€ãã«ã¯DDoSæ»æé²åŸ¡ã ãã§ã¯ãªããã¯ã©ãŠãåãLTEããŒãã³ã°ããµãŒãã¹ ãããã€ããŒåãã»ãã¥ãªãã£ãªã©ã®è§£èª¬ãæ²èŒãããŠããŸãã ããã®ãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ã«å¯Ÿããåå¿ã¯ããžãã£ããªãã®ã§ãããã客æ§ã¯ãã²ãšããæè¡çãªè©³çŽ°ãç¥ããããšèšã£ãŠãã ãã£ãã®ã§ããé£è¡æ©ã®äžã§ã®å·çäœæ¥ã¯ããžã§ãŒãžã»ã¯ã«ãŒããŒãéãããæéããããééããªãæ矩ã®ãããã®ã§ããããšããã§ä»ãµãšæãåºããã®ã§ããããžã§ãŒãžã»ã¯ã«ãŒããŒäž»æŒæ ç»ã®äžã§ç§ãäžçªæ°ã«å ¥ã£ãŠããã®ã¯ãã©ã¹ãã»ã¿ãŒã²ããïŒåé¡ïŒThe AmericanïŒãã§ãããã²ã芧ã«ãªã£ãŠãã ããããã®DDoSãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ãèªã¿çµããéã«ããããããã¹ããªãŒãã³ã°ã§ããã¯ãã§ãããã181Views0likes0Comments