ããã©ãã¯ããã¢ã«ããããã¯ãŒã¯ã¹ã®æ¬¡äžä»£éäžåãã¡ã€ã¢ãŠã©ãŒã«ç£èŠããã³ç®¡çïŒNGFWïŒã·ã¹ãã ã§ãããæè¿ãŸããŸã人æ°ãé«ãŸã£ãŠããŸããç¹ã«ãAngara Professional Assistanceã§ã¯ããã®è£œåãé »ç¹ã«äœ¿çšããŠããŸãã 2019幎ãã¢ããªã¹ãæ©é¢ã§ããã¬ãŒãããŒã¯ãããžãã¯ã¯ã¢ãã©ã³ãã®ãªãŒããŒãšããŠ8åèªããããŸããã Panoramaã䜿çšãããšããã¹ãŠã®ãã¡ã€ã¢ãŠã©ãŒã«ããã®ãã°ã®éçŽãšä¿åãã¬ããŒãã®äœæãèšå®ã®ç®¡çïŒæè»ãªã¢ã¯ã»ã¹å¶åŸ¡ã䜿çšïŒãã©ã€ã»ã³ã¹ãæŽæ°ãããã«ã¯ããŒããŠã§ã¢ã®ç¶æ ã®ç£èŠãè¡ãããšãã§ããŸãã
ããããé çªã«å§ããŸãããã
ããã©ãã¯PAKãŸãã¯ä»®æ³ã¢ãã©ã€ã¢ã³ã¹ãšããŠæäŸãããŸããä»®æ³ã¢ãã¬ããã«ã¯PAKãšåãæ©èœããããŸããä»®æ³ã¢ãã¬ããã¯ãVMware ESXiãGoogle Cloud PlatformãAmazon Web ServicesãMicrosoft Azureã«ãããã€ã§ããŸããã©ã€ã»ã³ã¹ã¯ãã¹ãŠã®ãã©ãããã©ãŒã ã§åãã§ããããã©ãã¯ã¯ã©ã¹ã¿ãŒäœæ¥ããµããŒãããŸãã
ããã©ãã¯3ã€ã®ã¢ãŒãã§åäœããŸãïŒå®éã«ã¯4ã€ã§ãããåŸè ã¯éåžžã«å€ããæ°ããã€ã³ã¹ããŒã«ã«ã¯ãå§ãããŸããïŒã
- ããã©ãã¢ãŒãã¯ããã©ã«ãã®åäœã¢ãŒãã§ãããã®ã¢ãŒãã§ã¯ãããã€ã¹ã¯ä»ã®ãã¡ã€ã¢ãŠã©ãŒã«ãå¶åŸ¡ããããããããã°ãåéã§ããŸãã
- ãã°ã³ã¬ã¯ã¿ãŒã¢ãŒã-ãã®ã¢ãŒãã§ã¯ãPanoramaã¯å¯Ÿå¿ãããã¡ã€ã¢ãŠã©ãŒã«ããã®ã¿ãã°ãåéããŸãã
- 管çå°çšã¢ãŒã-èªæã§ããããã©ãã¯ããã€ã¹ã®ã¿ã管çããŸãã
ãããã£ãŠãPanoramaããããã¯ãŒã¯ã«çµ±åããããã®äžè¬çãªã¢ãŒããã¯ãã£ãœãªã¥ãŒã·ã§ã³ãããã€ããããŸãã
æã人æ°ã®ããã¢ãŒããã¯ãã£ãšããã©ãã¢ãŒããèŠãŠã¿ãŸãããããã®ã¢ãŒãã¯ããã©ã«ãã§äœ¿çšããããããã¢ã¯ãã£ãã«ããããã«è¿œå ã®æé ã¯å¿ èŠãããŸããã
ãµããŒãããŒã¿ã«ã§ããã€ã¹ãç»é²ããããIP 192.168.1.252ãadmin / adminã®MGTã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠPanoramaã«æ¥ç¶ããŸããä»®æ³ã¢ãã¬ããã䜿çšããå Žåã¯ãã³ãã³ãã©ã€ã³ã§åæèšå®ãè¡ãå¿ èŠããããŸãã
# set deviceconfig system ip-address <Panorama-IP> netmask <netmask> default-gateway <gateway-IP> dns-setting servers primary <DNS-IP>
æåã®ã€ã³ã¿ãŒãã§ãŒã¹ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã§èŠããããã®ãšéåžžã«äŒŒãŠããŸãã
å®å šãªã€ã³ã¿ãŒãã§ã€ã¹ã¯ããã³ãã¬ãŒããšããã€ã¹ã°ã«ãŒãã®ã»ã¯ã·ã§ã³ãæ§æããåŸã§äœ¿çšã§ããŸãããåŸã§è©³ãã説æããŸãã
ã©ã€ã»ã³ã·ã³ã°
ä»®æ³ããã€ã¹ã䜿çšããå Žåã¯ãããã¢ã«ããããã¯ãŒã¯ã®ã«ã¹ã¿ããŒãµããŒãããŒã¿ã«ã§ä»®æ³ããã€ã¹ã®ã·ãªã¢ã«çªå·ãçæããã»ã¯ã·ã§ã³ã«å ¥åããå¿ èŠããããŸã
Panorama > Setup > Management > General Settings
ã次ã«ãã»ã¯ã·ã§ã³ã§ã©ã€ã»ã³ã¹ãã¢ããããŒãããå¿
èŠããããŸãPanorama > Licenses > License Management
ã
ãã¬ãŒãã³ã°
ããã©ãã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«ã€ã³ã¹ããŒã«ãããŠããããŒãžã§ã³ä»¥äžã®PAN-OSããã³åçæŽæ°ãã€ã³ã¹ããŒã«ããããšããå§ãããŸããããã¯ã»ã¯ã·ã§ã³
Panorama > Software
ãšã§è¡ãããšãã§ããŸãPanorama > Dynamic Updates
ãåãã»ã¯ã·ã§ã³ã§ãèªå眲åæŽæ°ãæ§æããããšãæãŸããã§ããäžè¬ã«ãPanoramaããŒãžã§ã³ã¯ãã¡ã€ã³ãªãªãŒã¹ã®ãã¬ãŒã ã¯ãŒã¯å
ã§ãã¡ã€ã¢ãŠã©ãŒã«ãš5ã6ããŒãžã§ã³äžãŸã§ç°ãªãããšãèš±å¯ãããŠããŸããããšãã°ãPanoramaããŒãžã§ã³9.0.6ããã³ãã¡ã€ã¢ãŠã©ãŒã«ããŒãžã§ã³9.0.2ã
ããã€ã¹ã®åææ§æã¯ããã¡ã€ã¢ãŠã©ãŒã«ã§å®è¡ãããã®ãšããã»ã©å€ãããŸãããã»ã¯ã·ã§ã³ã§
Panorama > Setup > Management Services
ãDNSãµãŒããŒãšNTPãµãŒããŒãç»é²ããŸãïŒCLIã§æåã«ç»é²ããªãã£ãå ŽåïŒã
èšå®ã¯åãæ¹æ³ã§é©çšãããŸã-ããã§ã¯3ã€ã®éšåã«åããããŠãã[ã³ããã]ã¡ãã¥ãŒã䜿çšããŸãïŒããã©ãã«ã³ããããããã€ã¹ã«ããã·ã¥ãã³ããããšããã·ã¥ã
- ããã©ãã«ã³ããã-èšå®ãããã©ãããã€ã¹ã«ã®ã¿é©çšããŸãã
- ããã€ã¹ã«ããã·ã¥-é©çšãããïŒå®è¡äžã®æ§æïŒããã©ãããã¡ã€ã¢ãŠã©ãŒã«ã«éä¿¡ããŸããã¡ãªã¿ã«ããã®æäœãå®è¡ãããšè¡šç€ºããããŠã£ã³ããŠã§ããã¡ã€ã¢ãŠã©ãŒã«ããŒã¿ã®ãªã¹ãããã®ä»ã®èšå®ãéžæã§ããŸãã
- ã³ãããããŠããã·ã¥-èšå®ãããã©ãã«é©çšãããããã¹ã¬ãŒãããã€ã¹ã«éä¿¡ããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ããã¡ã€ã¢ãŠã©ãŒã«ã«è¿œå ãã
ããã§ã¯ããã®ãœãªã¥ãŒã·ã§ã³ãäœæãããæ©èœã«ç§»ããŸããããã€ãŸãããã®åŸã®ç®¡çã®ããã«ãã¡ã€ã¢ãŠã©ãŒã«ãè¿œå ããŸãã
ããã¯3ã€ã®ã¹ãããã§è¡ãããŸãã
- ãã¡ã€ã¢ãŠã©ãŒã«ã§ã®ããã©ããµãŒããŒã¢ãã¬ã¹ã®æ§æã
- ãã¡ã€ã¢ãŠã©ãŒã«ã®ã·ãªã¢ã«çªå·ãããã©ãã«è¿œå ããŸãã
- ã³ããããä»ããŠãã¹ãŠã®èšå®ãä¿åããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ã§ãã»ã¯ã·ã§ã³ã«ç§»åã
Device > Setup > Management
ãŸãããã®åŸã[ããã©ãèšå®]ã»ã¯ã·ã§ã³ã§ãããã©ããµãŒããŒã®IPã¢ãã¬ã¹ãæå®ããŸãã
ããã©ãã§ãã»ã¯ã·ã§ã³ã«ç§»åã
Panorama > Managed Devices > Summary
ãŸãã
[è¿œå ]ãã¿ã³ãã¯ãªãã¯ããŠããã¡ã€ã¢ãŠã©ãŒã«ã®ã·ãªã¢ã«çªå·ãè¿œå ããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ãšããã©ãã®ãã¹ãŠã®èšå®ãé©çšããŸãã
ãã®åŸãåãã¡ãã¥ãŒ
Panorama > Managed Devices > Summary
ã§ãããã€ã¹ã®ã¹ããŒã¿ã¹ããæ¥ç¶æžã¿ãã«ãªããã·ãªã¢ã«çªå·ãIPã¢ãã¬ã¹ãã¢ãã«ã眲åããŒã¹ã®ããŒãžã§ã³ãªã©ã®æ
å ±ã衚瀺ãããŸãã
ããšãã°ãé·æé䜿çšãããŠãããã¡ã€ã¢ãŠã©ãŒã«ãè¿œå ããŠãæ¢åã®ãã¹ãŠã®ããªã·ãŒãšèšå®ãããã©ãã®å¶åŸ¡äžã§è»¢éããå¿ èŠãããå Žåã¯ã埮åŠãªéãããããŸãããŸãã¯ãäœçŸãã®ãã¡ã€ã¢ãŠã©ãŒã«ã移è¡ããŠããã»ã¹ãèªååããå¿ èŠãããå Žåããã®æ®µéã§ã¯ãã¹ãŠã®ãã¥ã¢ã³ã¹ã«è§Šããããšã¯ãããããã»ã¹ã¯ãŸã£ããé£ãããšã¯èšããŸããã
ãã³ãã¬ãŒã
ãã³ãã¬ãŒããšããã€ã¹ã°ã«ãŒãã¯ãPanoramaã䜿çšããŠãã人ã«ãšã£ãŠæåã¯ç解ããã®ãæãé£ãã2ã€ã®äž»èŠãªèšå®ã§ãã
ãã³ãã¬ãŒãã¯ãPanoramaã§äœæããããªããžã§ã¯ãã§ããã¡ã€ã¢ãŠã©ãŒã«ã®ãããã¯ãŒã¯ã»ã¯ã·ã§ã³ãšããã€ã¹ã»ã¯ã·ã§ã³ã«é¢é£ããããŒã¿ãä¿åããŸãã
ãã³ãã¬ãŒãã¯ã»ã¯ã·ã§ã³ã§äœæãã
Panorama > Templates
ãŸãããã®ã»ã¯ã·ã§ã³ã¯æåã¯ç©ºã§ããè¿œå ãã¿ã³ãã¯ãªãã¯ããŠãæåã®ãã³ãã¬ãŒããè¿œå ããå¿
èŠããããŸãããã®çŽåŸã«ã2ã€ã®æ°ããã»ã¯ã·ã§ã³ïŒãããã¯ãŒã¯ãšããã€ã¹ïŒãããã©ãWebã€ã³ã¿ãŒãã§ãŒã¹ã«è¡šç€ºãããŸãã
è€æ°ã®ãã³ãã¬ãŒããååšããå¯èœæ§ããããããPanoramaã®[ãããã¯ãŒã¯]ããã³[ããã€ã¹]ã»ã¯ã·ã§ã³ã«å€æŽãå ããå Žåã¯ãé©åãªãã³ãã¬ãŒããéžæããå¿ èŠããããŸãã
ãã³ãã¬ãŒãéžæã¡ãã¥ãŒ
ãã³ãã¬ãŒãã¹ã¿ãã¯ã¯ã8ã€ã®ãã³ãã¬ãŒããã圢æã§ããã»ããã§ããéå±€çã«ã¯8å±€ã®ããã«èŠããŸããäžäœå±€ã®èšå®ã¯äžäœå±€ã«äŒéãããåªå é äœãé«ããªããŸããéåžžã®ãã³ãã¬ãŒããšåãã»ã¯ã·ã§ã³ã«äœæãããŸãã
ãã³ãã¬ãŒãå€æ°
Panoramaã«ãã£ãŠç®¡çããã10.0.1.1 / 24ãã10.0.100.1/24ãŸã§ã®å éšIPã¢ãã¬ã¹ãæã€å€ãã®ãã¡ã€ã¢ãŠã©ãŒã«ããããšããŸããããããã«å¯ŸããŠ100ã®ç°ãªããã³ãã¬ãŒããäœæããªãããã«ããããã«ãå€æ°å€æ©èœã䜿çšã§ããŸãã
äžèšã®ç¶æ³ã®äŸã䜿çšããŠããããè¡ãæ¹æ³ãèŠãŠã¿ãŸãããã
ã¡ãã¥ãŒã«
Panorama > Templates
移åããŠããã¡ã€ã¢ãŠã©ãŒã«ã€ã³ã¿ãŒãã§ãŒã¹ã®IPã¢ãã¬ã¹ãåŠçãããã³ãã¬ãŒããäœæããŸãããããããã¡ã€ã¢ãŠã©ãŒã«ã€ã³ã¿ãŒãã§ãŒã¹ããšåŒã³ãŸããããã¡ãã¥ãŒã«Network > Interfaces
移åããŠãäœæãããã³ãã¬ãŒããäžããéžæãããŠããããšã確èªããåŸãå¿
èŠãªã€ã³ã¿ãŒãã§ã€ã¹ã®èšå®ã«ç§»åããŸãïŒäŸïŒethernet1 / 1ïŒã IPv4ã»ã¯ã·ã§ã³ã«ç§»åãã[è¿œå ]ãã¿ã³ãã¯ãªãã¯ããŠIPã¢ãã¬ã¹å€ãè¿œå ããŠããã[æ°èŠX ]ãã¯ãªãã¯ããŸããå€æ°ãããã§æ°ããå€æ°ãäœæã§ããŸããååãšæå³ãä»ããŸããããããã©ãã«æ¥ç¶ãããŠãããã¹ãŠã®ãã¡ã€ã¢ãŠã©ãŒã«ã衚瀺ãã
ãŠããã¡ãã¥ãŒ
Panorama > Managed Devices > Summary
ã«ç§»åããŸããããã¢ã€ãã¢ã«åŸã£ãŠãã¢ãã¬ã¹10.0.2.1/24ãæã€ãã¡ã€ã¢ãŠã©ãŒã«ãéžæãã[å€æ°]åã®[äœæ]ãã¿ã³ãã¯ãªãã¯ãããšã[ããã€ã¹å€æ°å®çŸ©ã®äœæ]ãŠã£ã³ããŠãéããŸãã
[ããã]ãéžæããŠ[OK]ãã¯ãªãã¯ããŸãã Device $ nameã®ãã³ãã¬ãŒãå€æ°ãŠã£ã³ããŠãéããŸãã
次ã«ãäœæãã$ Inside_IPå€æ°ãéžæããŠã[äžæžã]ãã¿ã³ãã¯ãªãã¯ããŸããå¿ èŠãªIPã¢ãã¬ã¹10.0.2.1/24ãå ¥åããŸãã
å¿ èŠãªãã¹ãŠã®ãã¡ã€ã¢ãŠã©ãŒã«ã«å¯ŸããŠãããã®æé ãç¹°ãè¿ããŠãããæ§æãé©çšããŸã
Commit > Commit and Push
ã
ãããã®ã¢ã¯ã·ã§ã³ã«ãããPanoramaã䜿çšããŠã1ã€ã®ãã³ãã¬ãŒãå ã®è€æ°ã®ãã¡ã€ã¢ãŠã©ãŒã«ã«ç°ãªãå€ãå ¥åã§ããŸããããŸãããã¡ã€ã¢ãŠã©ãŒã«ã§çŽæ¥äžæžãæ©èœã䜿çšããããšã«ãããããŸã䟿å©ã§ã¯ãªãæ¹æ³ããšãããšãã§ããŸãã管çè ãããã©ãããã®å€ã®äžæžããèš±å¯ããŠããå Žåããã¡ã€ã¢ãŠã©ãŒã«ã§ãã®æ©èœãããŒã«ã«ã«äœ¿çšããŠãããã©ãããéä¿¡ãããå€ïŒãã®å Žåã¯IPã¢ãã¬ã¹ïŒãäžæžãã§ããŸãã
æåŸã«ãPanoramaã®ã€ã³ã¿ãŒãã§ã€ã¹ã®IPã¢ãã¬ã¹ããŸã£ããå®çŸ©ããªãå ŽåããããŸãããåITUã§ããŒã«ã«ã«å®çŸ©ããŸãã
å€æ°ïŒãã³ãã¬ãŒãå€æ°ïŒããã¡ã€ã«ã«ãšã¯ã¹ããŒãããç·šéããŠã€ã³ããŒãã§ããŸããããã¯ã»ã¯ã·ã§ã³ã§è¡ãããšãã§ããŸã
Panorama > Templates
ããããè¡ãã«ã¯ãå¿
èŠãªãã³ãã¬ãŒããéžæãããããéããã«ãX Variable CSV > Export
... ãã®ãã¡ã€ã«ãéãããã䜿çšããåãã¡ã€ã¢ãŠã©ãŒã«ã®å€ãå€æŽããåãæ¹æ³ã§ãã®ãã¡ã€ã«ãã€ã³ããŒãããå¿
èŠããããŸãããã®æ¹æ³ã¯ééããªãé«éã§ãå€æ°ã®ãã¡ã€ã¢ãŠã©ãŒã«ã管çããŠããå Žåã¯æéãç¯çŽã§ããŸãã
ããã€ã¹ã°ã«ãŒã
次ã«ãåæ§ã®æŠå¿µã§ããããã€ã¹ã°ã«ãŒãã«ã€ããŠèª¬æããŸãã
ããã€ã¹ã°ã«ãŒãã¯ããã¡ã€ã¢ãŠã©ãŒã«ã§äœæãããããªã·ãŒããã³ãªããžã§ã¯ãã»ã¯ã·ã§ã³ã«é¢é£ããããŒã¿ãæ ŒçŽãããPanoramaã§äœæããããªããžã§ã¯ãã§ãã
ããã€ã¹ã°ã«ãŒãã¯ã»ã¯ã·ã§ã³ã§äœæãã
Panorama > Device Groups
ãŸãããã®ã»ã¯ã·ã§ã³ã¯æåã¯ç©ºã§ããè¿œå ãã¿ã³ãã¯ãªãã¯ããŠãæåã®ã°ã«ãŒããè¿œå ããå¿
èŠããããŸãããã®çŽåŸã«ã2ã€ã®æ°ããã»ã¯ã·ã§ã³ïŒããªã·ãŒãšãªããžã§ã¯ãïŒãããã©ãWebã€ã³ã¿ãŒãã§ãŒã¹ã«è¡šç€ºãããŸãã
ãã³ãã¬ãŒããšåæ§ã«ãããã€ã¹ã°ã«ãŒãã¯ç¹å®ã®ãã¡ã€ã¢ãŠã©ãŒã«ã«å²ãåœãŠãããŸãããã¡ã€ã¢ãŠã©ãŒã«ã¯ãã°ã«ãŒãéå±€ã«å±ããããšãã§ããŸããåçã¯ãã³ãã¬ãŒããšã¯å°ãç°ãªããŸãã
ã°ã«ãŒãéå±€ã®äŸ
æåã®ã°ã«ãŒããäœæãããšãSharedãšããå ±éã®ã°ã«ãŒããäœæããããã®èšå®ãä»ã®ãã¹ãŠã®ã°ã«ãŒãã«é©çšãããããšã«æ³šæããŠãã ããã
ããã€ã¹ã°ã«ãŒãã«ããã€ã¹ãå²ãåœãŠããããã³ãã¬ãŒããå²ãåœãŠãªãã£ãå Žåã¯ã©ããªããŸããïŒ
ããšãã°ãæ°ããã»ãã¥ãªãã£ããªã·ãŒãäœæãããšãã«åé¡ãçºçããå¯èœæ§ããããŸãããŸãŒã³ãéžæããã»ã¯ã·ã§ã³ã§ã¯ã[Any]以å€ã¯äœ¿çšã§ããŸãããããã¯ããããã®ãŸãŒã³ãæå®ãããããã€ã¹ã«å²ãåœãŠããããã³ãã¬ãŒãã1ã€ããªãããã§ãããã®åé¡ã解決ãã1ã€ã®æ¹æ³ã¯ãåç §ãã³ãã¬ãŒãã䜿çšããããšã§ããããã€ã¹ã°ã«ãŒããäœæããŠããã€ã¹ãè¿œå ãããšãã«ããã³ãã¬ãŒããžã®ãªã³ã¯ãæäŸããããšãã§ããŸãã
åç §ãã³ãã¬ãŒã
ãŸãŒã³ãæå®ãããã³ãã¬ãŒããäœæããã¡ãã¥ãŒãããã®ãã³ãã¬ãŒãã«ãªã³ã¯ããŠãããã€ã¹ã°ã«ãŒããäœæãŸãã¯ç·šéã§ããŸãã
ããªã·ãŒ
ãã§ã«ç¥ã£ãŠããããã«ãããã€ã¹ã°ã«ãŒãã¯ãPanoramaãããã¡ã€ã¢ãŠã©ãŒã«ã«éä¿¡ãããããªã·ãŒã管çããŸããéåžžã®ããªã·ãŒãšãã£ã¿ãŒãšã¯ç°ãªããããã«ã¯æ°ããã»ã¯ã·ã§ã³ããããŸããäºåã«ãŒã«ãäºåŸã«ãŒã«ãããã©ã«ãã«ãŒã«ã§ãã
éå±€çãªèŠ³ç¹ããèŠããšããã¹ãŠã次ã®ããã«æ©èœããŸãïŒéåžžã®ããã€ã¹ã°ã«ãŒãã«å ããŠãå ±æã®å ±æã°ã«ãŒããããããšãå¿ããªãã§ãã ããïŒã
äžèŠãããšãããã¯å°ãæãããã«èŠãããããããŸããããå®éã«ã¯ããã¹ãŠãã¯ããã«åçŽã§ããããªã·ãŒã®éå±€ã¯ãæåã®ããã€ãã®ã«ãŒã«ãäœæãããåŸã«æ確ã«ãªããŸããããã«ãçµæã®ã«ãŒã«ããšã³ãããã€ã¹ã§ã©ã®ããã«è¡šç€ºãããããåžžã«ç¢ºèªã§ããŸãããããè¡ãã«ã¯ãããªã·ãŒç·šéã»ã¯ã·ã§ã³ã®[ ã«ãŒã«ã®ãã¬ãã¥ãŒ ]ãã¿ã³ã䜿çšã§ããŸãã
ã«ãŒã«ãäœæãããšãã«ãç¹å®ã®ããã€ã¹ã«ããªã·ãŒãå²ãåœãŠãã¿ãŒã²ãããéžæããããšãã§ããŸããå®éã«ã¯ãèšäºã®äœæè ã¯ããã®æ©èœãæã䟿å©ã§ã¯ãªããšèããŠããŸããããã¯ãããã€ã¹ãéåžž1ã€ã®ãŠã£ã³ããŠã«è¡šç€ºãããŠããå ŽåãããŸããŸãªããã€ã¹ã®ããªã·ãŒãšæ··åãããå¯èœæ§ãããããã§ããããããããã¯ãã¹ãŠäººã«äŸåããŸããããããããã¯äžéšã«ãšã£ãŠäŸ¿å©ã ãšæãããã§ãããã
ããªã·ãŒã®å¯Ÿè±¡ãšãªãããã€ã¹ã®éžæ
泚æãæãã人ã®ããã®éåžžã«èå³æ·±ãæ©èœããããŸããããã©ãèšå®ã§ã¯ãã«ãŒã«ã®äœææã«å ¥åããå¿ èŠãããå¿ é ãã£ãŒã«ããèšå®ã§ããŸããããããªããšããã³ããã倱æããçºçããŸããããã¯äŸ¿å©ã§ãããšãã°ã管çè ãäœæããã«ãŒã«ã«åžžã«èª¬æãè¿œå ããããã¿ã°ãè¿œå ãããããããã«æ瀺ããŸãã説æã«ãã£ãŠããã®ã«ãŒã«ãŸãã¯ãã®ã«ãŒã«ã®ã¢ã€ãã¢ãç解ã§ããŸããã¿ã°ã«ãã£ãŠãã«ãŒã«ãã°ã«ãŒãåããäžèŠãªã«ãŒã«ãé€å€ã§ããŸãã
ã°ããŒãã«ã«ãããã¯ã¡ãã¥ãŒã§èšå®ãããŸã
Panorama > Setup > Management > Policy Rulebase Settings
ã
ãã³ãã¬ãŒãã¬ãã«ã§ã¯ãããã¯ã¡ãã¥ãŒã§èšå®ãããŸã
Devices > Setup > Management > Policy Rulebase Settings
ã
ãã®ã³ã°
次ã«ããã°ã調ã¹ãŠã¿ãŸãããã
ããã©ãã¯ãããŒã«ã«ãšãªã¢ãŒãã®2ã€ã®ãœãŒã¹ãããã°ã«é¢ããæ å ±ãåãåããŸãã
ããŒã«ã«ãœãŒã¹-ãã¡ã€ã¢ãŠã©ãŒã«èªäœã«ãã£ãŠããã©ãã«éä¿¡ããããã°ãPanoramaããã°ã³ã¬ã¯ã¿ãŒããã³CortexããŒã¿ã¬ã€ã¯ããèŠæ±ããã³åä¿¡ãããã°ïŒãã®èšäºã§ã¯ãããã«ã€ããŠã¯è§ŠããŸããïŒã
ãªã¢ãŒããœãŒã¹-ãã¡ã€ã¢ãŠã©ãŒã«ããèŠæ±ããããã°ã
ãã°ã«ã¯ããµããªãŒããŒã¿ããŒã¹ãšè©³çŽ°ãã°ã®2çš®é¡ããããŸãã
- ãµããªãŒããŒã¿ããŒã¹-ãã¡ã€ã¢ãŠã©ãŒã«ã¯ããã°è»¢éã«ãŒã«ãèšå®ãããŠããªããŠãã15åããšã«ãã°ãéçŽããããããçµã¿ç«ãŠïŒäžéšã®ãã£ãŒã«ããšæ å ±ã¯ãã°ããåé€ãããŸãïŒãPanoramaã«éä¿¡ããŸãããããã®ãã°ã«ã¯ãã¢ããªã±ãŒã·ã§ã³çµ±èšãè åšããã©ãã£ãã¯ããã³ãã«æ€æ»ãããã³URLãã£ã«ã¿ãªã³ã°ã«é¢ããæ å ±ãå«ãŸããŠããŸãã
- 詳现ãªãã°-ãããã®ãã°ã«ã¯ãå®å šãªæ å ±ãšãã¹ãŠã®ãã£ãŒã«ããå«ãŸããŠããŸããããã©ãã¯ããã¡ã€ã¢ãŠã©ãŒã«èªäœã«ãããã®ãã°ãèŠæ±ããŸãããŸãããã¡ã€ã¢ãŠã©ãŒã«ã«ååšããããã«ã転éãã°ã®èšå®ãæ§æããå¿ èŠããããŸãã
ãã°èªäœã衚瀺ããããã®ã€ã³ã¿ãŒãã§ãŒã¹ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã§è¡šç€ºããããã®ãšã»ãŒåãã§ããACCãéåžžã®ããã·ã¥ããŒããããã³ã¢ãã¿ãŒã»ã¯ã·ã§ã³ããããŸãããŸããã¬ããŒããçæããããã®ã»ã¯ã·ã§ã³ãåãã§ãã
åé¡ãæ€çŽ¢
次ã«ãæäžäœã®åé¡ã®ãããã°ãèŠãŠã¿ãŸãããã
[ããã€ã¹ã®æŠèŠ]ã»ã¯ã·ã§ã³ãé »ç¹ã«ç¢ºèªãã䟡å€ããããŸããããã«ã¯ãPanoramaã«æ¥ç¶ãããŠããããã€ã¹ã®ã¹ããŒã¿ã¹ã«é¢ããæ å ±ããããŸããããšãã°ã次ã®ç¶æ³ã確èªã§ããŸã
ããã®å Žåããã³ããã倱æããšã©ãŒãåå ã§ãã¡ã€ã¢ãŠã©ãŒã«æ§æãããã©ããšåæããŠããªãããšãããããŸãããã®ãšã©ãŒã®åå ã«é¢ããæ å ±ã¯ãèµ€ãã³ããã倱æã®ãªã³ã¯ãã¯ãªãã¯ãããšè¡šç€ºã§ããŸãã
ã¡ãã¥ãŒäž
Panorama > Managed Devices > Health
ããã€ã¹ã®ç¶æ
ã«é¢ããæ
å ±ãååŸã§ããŸããã¹ã«ãŒãããã1ç§ãããã®æ°ããã»ãã·ã§ã³ã®æ°ãã»ãã·ã§ã³ã®ç·æ°ãããŒã¿ãã¬ãŒã³ãšç®¡çãã¬ãŒã³ã®ããã»ããµè² è·ãã¡ã¢ãªäœ¿çšéã1ç§ãããã®ãã°ã®æ°ããã¡ã³ãšé»æºã®ç¶æ
ã§ãããŸããããããã¹ãŠã®æ
å ±ã¯ã°ã©ãã®åœ¢ã§è¡šç€ºã§ããŸãã
ãªãœãŒã¹ãšãããã°ã«ã€ããŠèšåããã®ã§ããã®èšäºã®ãã¬ãŒã ã¯ãŒã¯å ã§ã¯ãPanïŒwïŒachromeãšåŒã°ããChromeãã©ãŠã¶ãŒçšã®çŽ æŽããããã©ã°ã€ã³ã«ã€ããŠèšåããŸãã...ãã¡ã€ã¢ãŠã©ãŒã«ã®Webã€ã³ã¿ãŒãã§ãŒã¹ã§è³æ Œæ å ±ãå ¥åãããšãªã³ã«ãªããŸãããã©ã°ã€ã³ã§ã¯ãããã€ã¹ã®ç¶æ ã«é¢ããäžè¬æ å ±ã衚瀺ããããã©ãã§è¡šç€ºãããããã詳现ãªãªãœãŒã¹ã®èªã¿èŸŒã¿ã«é¢ããæ å ±ãååŸã§ããã ãã§ãªããç¹å®ã®ã«ãŠã³ã¿ãŒã®çµ±èšã衚瀺ããããšãã§ããŸãïŒå®å šãªãªã¹ãã¯ã¹ã¯ãªãŒã³ã·ã§ããã«åãŸããŸããã§ããïŒïŒ
ãã¡ããããã®æ å ±ã¯ããã詳现ãªåœ¢åŒã§ãã«ãŠã³ã¿ã®èª¬æãšãšãã«ããã€ã¹ã®CLIã§ç¢ºèªã§ããŸãããããã¯ãããã°ã«é¢ããå¥ã®èšäºã®ãããã¯ã§ãããã®ãã©ã°ã€ã³ã䜿çšãããšãç¹å®ã®ããã€ã¹ã§äœãèµ·ãã£ãŠããããã°ã©ãã£ãã¯åœ¢åŒã§èŠèŠçã«è©äŸ¡ã§ããŸãããŸããæ°ãã«çºçããåé¡ã®70ïŒ ã§ã¯ãããã§ååã§ãã
ããŠããå°çã®ãåé¡ã«æ»ããŸãããããã¡ã€ã¢ãŠã©ãŒã«ãžã®ããã©ãæ¥ç¶ã«é¢é£ããæãäžè¬çãªåé¡ã®1ã€ããããè¡ãã«ã¯ã次ã®ããŒãã®å¯çšæ§ã確èªããå¿ èŠããããŸãã
- 3978-ãã¡ã€ã¢ãŠã©ãŒã«ããã³ãã°ã³ã¬ã¯ã¿ãŒãšã®ããã©ãéä¿¡ã
- 28443-ããã©ãããã¹ã¬ãŒãããã€ã¹ãžã®ãœãããŠã§ã¢ã®æŽæ°ã
- 28-ããã©ãHAããŒãéã®éä¿¡ïŒæå·åïŒ;
- 28260ã28769-ããã©ãHAããŒãéã®éä¿¡ïŒæå·åãããŠããªãïŒã
ãŸãããšã©ãŒã¯ãã¡ã€ã¢ãŠã©ãŒã«ã®[ã¢ãã¿ãŒ]ã»ã¯ã·ã§ã³
> Logs > System
ã§ç¢ºèªã§ãããã£ã«ã¿ãŒã§ãã£ã«ã¿ãŒã§ããŸãïŒã説æã«ã¯ããã©ããå«ãŸããŠããŸããïŒã
ããã€ã¹ã®äº€æ
æåŸã«ãPanoramaã«æ¥ç¶ãããŠãããã¡ã€ã¢ãŠã©ãŒã«ã®äº€æãªã©ãããŸãäžè¬çã§ã¯ãªãç¶æ³ã«è§ŠããŸããããå€ãããã€ã¹ããæ°ããããã€ã¹ã«ã©ã€ã»ã³ã¹ã転éããéã®ãã¥ã¢ã³ã¹ãçãïŒãã©ã€ã»ã³ã¹ãã¹ãã¢ããã€ã¹ã«è»¢éããæ¹æ³ãã®ãªã¯ãšã¹ãã«é¢ããå ¬åŒããã¥ã¢ã«ã§ç¢ºèªã§ããŸãïŒãçŽæ¥ã»ããã¢ããã·ãŒã±ã³ã¹ã«é²ã¿ãŸãã
- æ°ãããã¡ã€ã¢ãŠã©ãŒã«ã®åºæ¬èšå®ãè¡ããŸããmgmtã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠã¢ã¯ã»ã¹ãæ§æããPAN-OSããŒãžã§ã³ãäžèŽããŠããããšã確èªããå¿ èŠããããŸããåçæŽæ°ã»ã¯ã·ã§ã³ã§çœ²åããŒãžã§ã³ã確èªããããšã䟡å€ããããŸãã
- ããã©ããä»ããŠãå€ãããã€ã¹ã®ãããã€ã¹ã®ç¶æ
ãããšã¯ã¹ããŒãããŸããã³ãã³ãã©ã€ã³ã«ç§»åããŠã次ã®ã³ãã³ãã®ãããããå®è¡ããŸãïŒãµãŒããŒã§ãµããŒããããŠãããããã³ã«ã«å¿ããŠãæ§æããšã¯ã¹ããŒãããŸãïŒã
> scp export device-state device <old-serial#> to <login>@<serverIP>:<path>
ãŸãã¯ïŒ
> tftp export device-state device <old-serial#> to <login>@<serverIP>:<path>
, :
> replace device old <old-serial#> new <new-serial#>
- «device state» .
Device > Setup > Operations > Import device state
. - Commit.
ãã¡ãããç§ãã¡ã¯ããã©ãèšå®ã®äžçªäžãééããã ãã§ãå€ãã®ãã¥ã¢ã³ã¹ã«ã¯è§ŠããŸããã§ããããã ããäžéšãç解ããããšã§ããã¡ã€ã¢ãŠã©ãŒã«ãPanoramaã«æ¥ç¶ãããã®åºæ¬çãªæ©èœãç解ãããã现ããã«ã¹ã¿ãã€ãºãèªåã§éå§ã§ããŸãã
ãã®ãããã¯ãããªãã«ãšã£ãŠèå³æ·±ããã®ã§ããããšãå€æããå Žåã¯ã次ã®èšäºã§ãéåžžã¯ãã¯ãã«ã«ãµããŒããŸãã¯ASCïŒAuthorized Support CenterïŒã«è§£æ±ºçãæäŸãããããã°ïŒãã©ãã«ã·ã¥ãŒãã£ã³ã°ïŒã®åé¡ããã詳现ã«ã«ããŒããããã«åªããŸãã
次ã®ãããªãããã¯ã«ã€ããŠè§ŠããŸãã
- CLIããã¥ã¢ã³ã¹ãšã©ã€ãããã¯ã
- ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã®ããã®ãã¯ãã«ã«ãµããŒããã¡ã€ã«ã®äœ¿çšã
- ãããŒããžãã¯ã
- ãã±ããããã£ããã£ããŸãã
- ãã±ãã蚺æã
- çä¿¡ãã©ãã£ãã¯ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãVPNãIkeãIPsecã
- ééãã©ãã£ãã¯ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã
- ã·ã¹ãã ãµãŒãã¹ïŒDAEMONSïŒã
- 蚌ææžãšSSLã€ã³ã¹ãã¯ã·ã§ã³ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã
- User-IDã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã
- GlobalProtectãã©ãã«ã·ã¥ãŒãã£ã³ã°ã
ãã®ãããã¯ã«èå³ãããå Žåã¯ã³ã¡ã³ããæ®ããŠãã ããã