- å¯çšæ§;
- å®å šæ§;
- ãªãŒãã¡ãŒã·ã§ã³ã
調æ»çµæã以äžã«ç€ºããŸãã2019幎以éãCisco Catalyst 9800ã·ãªãŒãºã³ã³ãããŒã©ãŒã®æ©èœãå€§å¹ ã«æ¹åãããŸããããããã®ç¹ã¯ããã®èšäºã«ãåæ ãããŠããŸãã
Wi-Fi 6ãã¯ãããžãŒã®ä»ã®å©ç¹ãå®è£ äŸãããã³ã¢ããªã±ãŒã·ã§ã³ã«ã€ããŠã¯ããã¡ããã芧ãã ããã
ãœãªã¥ãŒã·ã§ã³ã®æŠèŠ
Cisco Catalyst9800ã·ãªãŒãºWi-Fi6ã³ã³ãããŒã©ãŒ
IOS-XEãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒCiscoã¹ã€ããããã³ã«ãŒã¿ãŒã«ã䜿çšãããŸãïŒã«åºã¥ãCisco Catalyst 9800ã·ãªãŒãºã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒã·ãªãŒãºã¯ãããŸããŸãªãªãã·ã§ã³ã§å©çšã§ããŸãã
å€ãã¢ãã«ã®9800-80ã³ã³ãããŒã©ãŒã¯ãæ倧80Gbpsã®ã¯ã€ã€ã¬ã¹åž¯åå¹ ããµããŒãããŸãã 1ã€ã®9800-80ã³ã³ãããŒã©ãŒã¯ãæ倧6,000ã®ã¢ã¯ã»ã¹ãã€ã³ããšæ倧64,000ã®ã¯ã€ã€ã¬ã¹ã¯ã©ã€ã¢ã³ãããµããŒãããŸãã
ãããã¬ã³ãžã¢ãã«ã®9800-40ã³ã³ãããŒã©ãŒã¯ãæ倧40 Gbpsã®ã¹ã«ãŒããããæ倧2,000ã®ã¢ã¯ã»ã¹ãã€ã³ããããã³æ倧32,000ã®ã¯ã€ã€ã¬ã¹ã¯ã©ã€ã¢ã³ãããµããŒãããŸãã
ãããã®ã¢ãã«ã«å ããŠã9800-CLã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒïŒCLã¯Cloudã®ç¥ïŒã競ååæã«å«ãŸããŠããŸããã9800-CLã¯ãVMWare ESXIããã³KVMãã€ããŒãã€ã¶ãŒã®ä»®æ³åç°å¢ã§å®è¡ããããã®ããã©ãŒãã³ã¹ã¯ãã³ã³ãããŒã©ãŒä»®æ³ãã·ã³ã®å°çšããŒããŠã§ã¢ãªãœãŒã¹ã«äŸåããŸããæ倧æ§æã§ã¯ãCisco 9800-CLã³ã³ãããŒã©ãŒã¯ãå€ã9800-80ã¢ãã«ãšåæ§ã«ãæ倧6,000ã®ã¢ã¯ã»ã¹ãã€ã³ããšæ倧64,000ã®ã¯ã€ã€ã¬ã¹ã¯ã©ã€ã¢ã³ãã®ã¹ã±ãŒã©ããªãã£ããµããŒãããŸãã
ã³ã³ãããŒã©ã䜿çšãã調æ»ã§ã¯ã2.4GHzãš5GHzããµããŒããããã¥ã¢ã«5GHzã¢ãŒãã«åçã«åãæ¿ããæ©èœãåããCiscoAironet AP4800ã·ãªãŒãºã䜿çšããŸããã
ãã¹ãã¹ã¿ã³ã
ãã¹ãã®äžç°ãšããŠãã¯ã©ã¹ã¿ãŒã§åäœãã2å°ã®Cisco Catalyst9800-CLã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒãšCiscoAironet AP 4800ã·ãªãŒãºã¢ã¯ã»ã¹ãã€ã³ãããã¹ã¿ã³ããçµã¿ç«ãŠãŸãã
ãã¯ã©ã€ã¢ã³ãããã€ã¹ãšããŠãDellãšAppleã®ã©ããããããšAppleiPhoneã䜿çšããŸããã
ã¢ã¯ã»ã·ããªãã£ãã¹ã
ã¢ã¯ã»ã·ããªãã£ã¯ãã·ã¹ãã ãŸãã¯ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããŠäœ¿çšãããŠãŒã¶ãŒã®èœåãšããŠå®çŸ©ãããŸããé«å¯çšæ§ãšã¯ãç¹å®ã®ã€ãã³ãã«é¢ä¿ãªããã·ã¹ãã ãŸãã¯ãµãŒãã¹ãžã®ç¶ç¶çãªã¢ã¯ã»ã¹ãæå³ããŸãã
é«å¯çšæ§ã¯4ã€ã®ã·ããªãªã§ãã¹ããããŠããŸããæåã®3ã€ã®ã·ããªãªã¯ãå¶æ¥æéäžãŸãã¯å¶æ¥æéåŸã«çºçããå¯èœæ§ã®ããäºæž¬å¯èœãŸãã¯ã¹ã±ãžã¥ãŒã«ãããã€ãã³ãã§ãã5çªç®ã®ã·ããªãªã¯ãäºæž¬ã§ããªãã€ãã³ãã§ããå€å žçãªã°ãªããã§ãã
ã·ããªãªã®èª¬æïŒ
- ãã°ä¿®æ£-ã·ã¹ãã ã®ãã€ã¯ãã¢ããããŒãïŒãã°ãã£ãã¯ã¹ãŸãã¯ã»ãã¥ãªãã£ãããïŒãããã«ãããã·ã¹ãã ãœãããŠã§ã¢ãå®å šã«æŽæ°ããã«ããã®ãšã©ãŒãŸãã¯è匱æ§ãä¿®æ£ã§ããŸãã
- æ©èœã¢ããããŒã-æ©èœã¢ããããŒããã€ã³ã¹ããŒã«ããããšã«ãããã·ã¹ãã ã®çŸåšã®æ©èœãè¿œå ãŸãã¯æ¡åŒµããŸãã
- â ;
- â ;
- â .
å€ãã®ç«¶åãœãªã¥ãŒã·ã§ã³ã§ã¯ãããããé©çšããã«ã¯ã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ã·ã¹ãã ãœãããŠã§ã¢ã®å®å šãªæŽæ°ãå¿ èŠã§ãããèšç»å€ã®ããŠã³ã¿ã€ã ãçºçããå¯èœæ§ããããŸããã·ã¹ã³ãœãªã¥ãŒã·ã§ã³ã®å Žåããããã¯è£œåãåæ¢ããã«å®è¡ãããŸãããããã¯ãã¯ã€ã€ã¬ã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ãåäœããŠããéãä»»æã®ã³ã³ããŒãã³ãã«é©çšã§ããŸãã
æé èªäœã¯éåžžã«ç°¡åã§ããããããã¡ã€ã«ã¯ãããããã®Ciscoã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ã®ããŒããã©ã«ãã«ã³ããŒãããGUIãŸãã¯ã³ãã³ãã©ã€ã³ãä»ããŠåäœã確èªãããŸããããã«ãã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ãŸãã¯ã³ãã³ãã©ã€ã³ãä»ããŠãã·ã¹ãã ãäžæããããšãªããããããå ã«æ»ãããåé€ãããã§ããŸãã
æ©èœã¢ããããŒã
æ©èœçãªãœãããŠã§ã¢ã¢ããããŒãã¯ãæ°ããæ©èœãã¢ã¯ãã£ãã«ããããã«é©çšãããŸãããã®ãããªæ©èœåŒ·åã®1ã€ã¯ãã¢ããªã±ãŒã·ã§ã³çœ²åããŒã¿ããŒã¹ã®æŽæ°ã§ãããã®ããã±ãŒãžã¯ããã¹ããšããŠCiscoã³ã³ãããŒã©ãŒã«ã€ã³ã¹ããŒã«ãããŸãããä¿®æ£ãšåæ§ã«ãæ©èœã®æŽæ°ã¯ãããŠã³ã¿ã€ã ãã·ã¹ãã ã®äžæãªãã«é©çšãã€ã³ã¹ããŒã«ããŸãã¯ã¢ã³ã€ã³ã¹ããŒã«ãããŸãã
å®å šãªæŽæ°
çŸæç¹ã§ã¯ãã³ã³ãããŒã©ãŒãœãããŠã§ã¢ã€ã¡ãŒãžã®å®å šãªæŽæ°ã¯ãæ©èœçãªãã®ãšåãæ¹æ³ã§ãã€ãŸãããŠã³ã¿ã€ã ãªãã§å®è¡ãããŸãããã ãããã®æ©èœã¯ãè€æ°ã®ã³ã³ãããŒã©ãŒãååšããã¯ã©ã¹ã¿ãŒæ§æã§ã®ã¿äœ¿çšã§ããŸããå®å šãªæŽæ°ã¯é çªã«å®è¡ãããŸããæåã«1ã€ã®ã³ã³ãããŒã©ãŒã§ã次ã«2çªç®ã®ã³ã³ãããŒã©ãŒã§å®è¡ãããŸãã
æ°ããã¢ã¯ã»ã¹ãã€ã³ãã¢ãã«ã®è¿œå
以åã¯äœ¿çšæžã¿ã®ã³ã³ãããŒã©ãŒãœãããŠã§ã¢ã€ã¡ãŒãžã§æäœãããŠããªãã£ãæ°ããã¢ã¯ã»ã¹ãã€ã³ããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã«æ¥ç¶ããããšã¯ãç¹ã«å€§èŠæš¡ãªãããã¯ãŒã¯ïŒç©ºæž¯ãããã«ãçç£æœèšïŒã§ã¯ããªãé »ç¹ãªæäœã§ãã競åä»ç€Ÿã®ãœãªã¥ãŒã·ã§ã³ã§ã¯ããã®æäœã§ã·ã¹ãã ãœãããŠã§ã¢ãæŽæ°ããããã³ã³ãããŒã©ãŒãåèµ·åããå¿ èŠããããŸãã
æ°ããWi-Fi6ã¢ã¯ã»ã¹ãã€ã³ããCiscoCatalyst 9800ã·ãªãŒãºã³ã³ãããŒã©ãŒã¯ã©ã¹ã¿ãŒã«æ¥ç¶ããå Žåããããã®åé¡ã¯çºçããŸãããã³ã³ãããŒã©ãžã®æ°ãããã€ã³ãã®æ¥ç¶ã¯ãã³ã³ãããŒã©ãœãããŠã§ã¢ãæŽæ°ããã«å®è¡ããããã®ããã»ã¹ã¯åèµ·åãå¿ èŠãšããªããããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã«åœ±é¿ãäžããããšã¯ãããŸããã
ã³ã³ãããŒã©ã®é害
ãã¹ãç°å¢ã§ã¯ã2ã€ã®Wi-Fi 6ã³ã³ãããŒã©ãŒïŒã¢ã¯ãã£ã/ã¹ã¿ã³ãã€ïŒã䜿çšãããã¢ã¯ã»ã¹ãã€ã³ãã¯äž¡æ¹ã®ã³ã³ãããŒã©ãŒã«çŽæ¥æ¥ç¶ãããŠããŸãã
äžæ¹ã®ã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒã¯ã¢ã¯ãã£ãã§ãããäžæ¹ã¯ã¹ã¿ã³ãã€ã§ããã¢ã¯ãã£ããªã³ã³ãããŒã©ãŒã«é害ãçºçãããšãããã¯ã¢ããã³ã³ãããŒã©ãŒãåŒãç¶ãããã®ã¹ããŒã¿ã¹ãã¢ã¯ãã£ãã«å€ãããŸãããã®æé ã¯ãã¢ã¯ã»ã¹ãã€ã³ããšã¯ã©ã€ã¢ã³ãã®Wi-Fiãäžæããããšãªãå®è¡ãããŸãã
å®å šæ§
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã§éåžžã«éèŠãªã»ãã¥ãªãã£ã®åŽé¢ã«ã€ããŠèª¬æããŸãããœãªã¥ãŒã·ã§ã³ã®å®å šæ§ã¯ã次ã®ç¹æ§ã«åŸã£ãŠè©äŸ¡ãããŸãã
- ã¢ããªã±ãŒã·ã§ã³ã®èªè;
- ãã©ãã£ãã¯ãããŒã®è¿œè·¡ïŒãããŒè¿œè·¡ïŒ;
- æå·åããããã©ãã£ãã¯ã®åæã
- äŸµå ¥ã®æ€åºãšé²æ¢;
- èªèšŒããŒã«;
- ã¯ã©ã€ã¢ã³ãããã€ã¹ä¿è·ããŒã«ã
ã¢ããªã±ãŒã·ã§ã³ã®èªè
ãšã³ã¿ãŒãã©ã€ãºããã³ç£æ¥çšWi-Fiåžå Žã®ããŸããŸãªè£œåã®äžã§ã補åãã¢ããªã±ãŒã·ã§ã³éã®ãã©ãã£ãã¯ãã©ã®çšåºŠé©åã«èå¥ãããã«ã¯éãããããŸããããŸããŸãªã¡ãŒã«ãŒã®è£œåã¯ãããŸããŸãªæ°ã®ã¢ããªã±ãŒã·ã§ã³ãèå¥ã§ããŸããåæã«ãèå¥ã®ããã«å¯èœãªéã競åãœãªã¥ãŒã·ã§ã³ã«ãã£ãŠç€ºãããã¢ããªã±ãŒã·ã§ã³ã®å€ãã¯ãå®éã«ã¯Webãµã€ãã§ãããäžæã®ã¢ããªã±ãŒã·ã§ã³ã§ã¯ãããŸããã
ã¢ããªã±ãŒã·ã§ã³èªèã®ãã1ã€ã®èå³æ·±ãæ©èœããããŸãããœãªã¥ãŒã·ã§ã³ã¯ãèå¥ç²ŸåºŠã倧ããç°ãªããŸãã
å®è¡ããããã¹ãŠã®ãã¹ããèæ ®ãããšãCisco Wi-Fi-6ãœãªã¥ãŒã·ã§ã³ãã¢ããªã±ãŒã·ã§ã³èªèãéåžžã«æ£ç¢ºã«å®è¡ããŠããããšã責任ãæã£ãŠè¿°ã¹ãããšãã§ããŸããJabberãNetflixãDropboxãYouTubeããã®ä»ã®äžè¬çãªã¢ããªã±ãŒã·ã§ã³ãããã³WebãµãŒãã¹ãæ£ç¢ºã«èå¥ãããŸããããŸããCiscoãœãªã¥ãŒã·ã§ã³ã¯ãDPIïŒDeep Packet InspectionïŒã䜿çšããŠããŒã¿ãã±ãããããã«æ·±ãæãäžããããšãã§ããŸãã
ãã©ãã£ãã¯ãããŒã®è¿œè·¡
ã·ã¹ãã ãããŒã¿ã¹ããªãŒã ïŒå€§ããªãã¡ã€ã«ã®ç§»åãªã©ïŒãæ£ç¢ºã«è¿œè·¡ããã³å ±åã§ãããã©ããã確èªããããã«ãå¥ã®ãã¹ããå®è¡ãããŸãããããããã¹ãããããã«ã6.5ã¡ã¬ãã€ãã®ãã¡ã€ã«ããã¡ã€ã«è»¢éãããã³ã«ïŒFTPïŒã䜿çšããŠãããã¯ãŒã¯çµç±ã§éä¿¡ãããŸããã
ã·ã¹ã³ã®ãœãªã¥ãŒã·ã§ã³ã¯ä»»åãéè¡ããNetFlowãšãã®ããŒããŠã§ã¢æ©èœã®ãããã§ãã®ãã©ãã£ãã¯ã远跡ããããšãã§ããŸããããã©ãã£ãã¯ã¯ã転éãããæ£ç¢ºãªéã®ããŒã¿ã§ããã«æ€åºããã³èå¥ãããŸããã
æå·åããããã©ãã£ãã¯ã®åæ
ãŠãŒã¶ãŒããŒã¿ãã©ãã£ãã¯ã¯ãŸããŸãæå·åãããŠããŸããããã¯ãäŸµå ¥è ã«ãã远跡ãååããä¿è·ããããã«è¡ãããŸãããããåæã«ãããã«ãŒã¯ãŸããŸãæå·åã䜿çšããŠãã«ãŠã§ã¢ãé ããMan-in-the-MiddleïŒMiTMïŒãããŒãã®ã³ã°æ»æãªã©ã®ä»ã®çãããæäœãå®è¡ããŠããŸãã
ã»ãšãã©ã®äŒæ¥ã¯ãæåã«ãã¡ã€ã¢ãŠã©ãŒã«ãŸãã¯äŸµå ¥é²æ¢ã·ã¹ãã ã䜿çšããŠæå·åããããã©ãã£ãã¯ã埩å·åããããšã«ãããæå·åããããã©ãã£ãã¯ã®äžéšãæ€æ»ããŸãããã ãããã®ããã»ã¹ã«ã¯æéããããããããã¯ãŒã¯å šäœã®ããã©ãŒãã³ã¹ã«ã¯ã¡ãªããããããŸãããããã«ã埩å·åããããšããã®ããŒã¿ã¯è©®çŽ¢å¥œããªç®ã«è匱ã«ãªããŸãã
Cisco Catalyst 9800ã·ãªãŒãºã³ã³ãããŒã©ã¯ãä»ã®æ¹æ³ã§æå·åããããã©ãã£ãã¯ãåæããåé¡ãæ£åžžã«è§£æ±ºããŸãããã®ãœãªã¥ãŒã·ã§ã³ã¯ãEncrypted Traffic AnalyticsïŒETAïŒãšåŒã°ããŸãã ETAã¯ãçŸåšã競åãœãªã¥ãŒã·ã§ã³ã«é¡äŒŒãããã®ããªããæå·åããããã©ãã£ãã¯å ã®ãã«ãŠã§ã¢ã埩å·åããã«æ€åºãããã¯ãããžãŒã§ãã ETAã¯ãæ¡åŒµNetFlowãå«ãåºæ¬çãªIOS-XEæ©èœã§ãããé«åºŠãªåäœã¢ã«ãŽãªãºã ã䜿çšããŠãæå·åããããã©ãã£ãã¯ã«æœãæªæã®ãããã©ãã£ãã¯ãã¿ãŒã³ãèå¥ããŸãã
ETAã¯ã¡ãã»ãŒãžã埩å·åããŸããããæå·åããããã©ãã£ãã¯ã¹ããªãŒã ã®ã¡ã¿ããŒã¿ãããã¡ã€ã«ïŒãã±ãããµã€ãºããã±ããéã®æéééãªã©ïŒãåéããŸãã次ã«ãã¡ã¿ããŒã¿ã¯NetFlowv9ã¬ã³ãŒãã§CiscoStealthwatchã«ãšã¯ã¹ããŒããããŸãã
Stealthwatchã®éèŠãªæ©èœã¯ãç¶ç¶çãªãã©ãã£ãã¯ã®ç£èŠãšãå®æçãªãããã¯ãŒã¯ã¢ã¯ãã£ããã£ã®ããŒã¹ã©ã€ã³ã€ã³ãžã±ãŒã¿ã®äœæã§ãã Stealthwatchã¯ãETAããéä¿¡ãããæå·åãããã¹ããªãŒã ã¡ã¿ããŒã¿ã䜿çšããŠãå€å±€ãã·ã³ã©ãŒãã³ã°ãé©çšããçãããã€ãã³ãã瀺ãå¯èœæ§ã®ãããã©ãã£ãã¯ã®åäœç°åžžãèå¥ããŸãã
æšå¹ŽãCiscoã¯Miercomãæ¡çšããŠãCisco Encrypted TrafficAnalyticsãœãªã¥ãŒã·ã§ã³ãç¬èªã«è©äŸ¡ããŸããããã®è©äŸ¡ã§ã¯ãMiercomã¯ãæ¢ç¥ããã³æªç¥ã®è åšïŒãŠã€ã«ã¹ãããã€ã®æšéŠ¬ãã©ã³ãµã ãŠã§ã¢ïŒãã倧èŠæš¡ãªETAããã³éETAãããã¯ãŒã¯å šäœã®æå·åããããã©ãã£ãã¯ãšæå·åãããŠããªããã©ãã£ãã¯ã§å¥ã ã«ãã£ã¹ãããããŠè åšãç¹å®ããŸããã
ãã¹ãã®ããã«ãæªæã®ããã³ãŒããäž¡æ¹ã®ãããã¯ãŒã¯ã§èµ·åãããŸãããã©ã¡ãã®å Žåããçãããã¢ã¯ãã£ããã£ãåŸã ã«æ€åºãããŸãããETAãããã¯ãŒã¯ã¯ãæåã«éETAãããã¯ãŒã¯ããã36ïŒ éãè åšãæ€åºããŸãããåæã«ãäœæ¥ã®éçšã§ãETAãããã¯ãŒã¯ã§ã®æ€åºã®çç£æ§ãåäžãå§ããŸããããã®çµæãETAãããã¯ãŒã¯ã§æ°æééçšããåŸãã¢ã¯ãã£ããªè åšã®3åã®2ãæ£åžžã«æ€åºãããŸãããããã¯ãéETAãããã¯ãŒã¯ã®2åã§ãã
ETAæ©èœã¯Stealthwatchãšååã«çµ±åãããŠããŸããè åšã¯é倧床ã«ãã£ãŠã©ã³ã¯ä»ãããã詳现æ å ±ãšãšãã«è¡šç€ºããã確èªãããåŸã®ä¿®æ£æªçœ®ã®ãªãã·ã§ã³ã衚瀺ãããŸããçµè«-ETAã¯æ©èœããŸãïŒ
äŸµå ¥ã®æ€åºãšé²æ¢
ã·ã¹ã³ã«ã¯ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯çšã®è åšæ€åºããã³é²æ¢ãšã³ãžã³ã§ããCisco Advanced Wireless Intrusion Prevention SystemïŒaWIPSïŒãšããå¥ã®åŒ·åãªã»ãã¥ãªãã£ããŒã«ããããŸãã AWIPSã¯ãCisco DNA Centerã®ã³ã³ãããŒã©ãŒãã¢ã¯ã»ã¹ãã€ã³ããããã³ç®¡çãœãããŠã§ã¢ã§æ©èœããŸããè åšã®æ€åºãèŠåãããã³é²æ¢ã®ããã»ã¹ã¯ããããã¯ãŒã¯ãã©ãã£ãã¯åæããããã¯ãŒã¯ããã€ã¹ãšãããã¯ãŒã¯ã®ããããžæ å ±ã眲åããŒã¹ã®ææ³ãããã³ç°åžžæ€åºãçµã¿åãããŠãæçµçã«é«ç²ŸåºŠãšã¯ã€ã€ã¬ã¹è åšã®é²æ¢ãå®çŸããŸãã
aWIPSããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã«å®å šã«çµ±åãããšãæç·ãããã¯ãŒã¯ãšã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®äž¡æ¹ã§ã¯ã€ã€ã¬ã¹ãã©ãã£ãã¯ãç¶ç¶çã«ç£èŠããããã䜿çšããŠå€ãã®ãœãŒã¹ããã®æœåšçãªæ»æãèªåçã«åæããæœåšçãªæ»æãå¯èœãªéãå æ¬çã«ç¹å®ããŠé²æ¢ã§ããŸãã
èªèšŒããŒã«
çŸæç¹ã§ã¯ãåŸæ¥ã®èªèšŒæ¹æ³ã«å ããŠãCisco Catalyst9800ã·ãªãŒãºãœãªã¥ãŒã·ã§ã³ã§WPA3ãµããŒããå©çšã§ããŸããWPA3ã¯WPAã®ææ°ããŒãžã§ã³ã§ãããWi-Fiãããã¯ãŒã¯ã«èªèšŒãšæå·åãæäŸããäžé£ã®ãããã³ã«ãšãã¯ãããžãŒã§ãã
WPA3ã¯ãSimultaneous Authentication of EqualsïŒSAEïŒã䜿çšããŠããµãŒãããŒãã£ã«ãããã«ãŒããã©ãŒã¹æ»æã«å¯Ÿããæãå®å šãªãŠãŒã¶ãŒä¿è·ãæäŸããŸããã¯ã©ã€ã¢ã³ããã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ãããšãSAE亀æãå®è¡ãããŸããæåãããšããããããæå·çã«åŒ·åãªããŒãäœæããããããã»ãã·ã§ã³ããŒãååŸããŠããã確èªç¶æ ã«ãªããŸãããã®åŸãã»ãã·ã§ã³ããŒãçæããå¿ èŠããããã³ã«ãã¯ã©ã€ã¢ã³ããšã¢ã¯ã»ã¹ãã€ã³ãã¯ç¢ºèªå¿çç¶æ ã«ãªããŸãããã®æ¹æ³ã§ã¯ãæ»æè ã1ã€ã®ããŒã解èªã§ããŸãããä»ã®ãã¹ãŠã®ããŒã解èªããããšã¯ã§ããªããã©ã¯ãŒãã·ãŒã¯ã¬ããã䜿çšããŸãã
ã€ãŸããSAEã¯ããã©ãã£ãã¯ãååããæ»æè ããååããããŒã¿ã圹ã«ç«ããªããªãåã«ãã¹ã¯ãŒããæšæž¬ããããšããè©Šã¿ã1åã ãã«ãªãããã«æ§ç¯ãããŠããŸããé·æçãªãã¹ã¯ãŒãæšæž¬ãæŽçããã«ã¯ãã¢ã¯ã»ã¹ãã€ã³ããžã®ç©ççãªã¢ã¯ã»ã¹ãå¿ èŠã«ãªããŸãã
ã¯ã©ã€ã¢ã³ãããã€ã¹ã®ä¿è·
ä»æ¥ã®CiscoCatalyst 9800ã·ãªãŒãºã¯ã€ã€ã¬ã¹ãœãªã¥ãŒã·ã§ã³ã®äž»ãªé¡§å®¢ä¿è·ã¯ãæ¢ç¥ã®è åšãšæ°ããªè åšã®äž¡æ¹ãèªåçã«æ€åºããã¯ã©ãŠãããŒã¹ã®DNSããŒã¹ã®ãããã¯ãŒã¯ã»ãã¥ãªãã£ãµãŒãã¹ã§ããCisco UmbrellaWLANã§ãã
Cisco Umbrella WLANã¯ãã¯ã©ã€ã¢ã³ãããã€ã¹ã«ã€ã³ã¿ãŒããããžã®å®å šãªæ¥ç¶ãæäŸããŸããããã¯ãã³ã³ãã³ããã£ã«ã¿ãªã³ã°ãã€ãŸãããšã³ã¿ãŒãã©ã€ãºããªã·ãŒã«åŸã£ãŠã€ã³ã¿ãŒãããäžã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ããããã¯ããããšã«ãã£ãŠå®çŸãããŸãããããã£ãŠãã€ã³ã¿ãŒãããäžã®ã¯ã©ã€ã¢ã³ãããã€ã¹ã¯ããã«ãŠã§ã¢ãã©ã³ãµã ãŠã§ã¢ãããã³ãã£ãã·ã³ã°ããä¿è·ãããŸããããªã·ãŒã®é©çšã¯ãç¶ç¶çã«æŽæ°ããã60ã®ã³ã³ãã³ãã«ããŽãªã«åºã¥ããŠããŸãã
ãªãŒãã¡ãŒã·ã§ã³
ææ°ã®ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã¯ã¯ããã«æè»ã§è€éã§ãããããã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒããæ å ±ãæ§æããã³ååŸããåŸæ¥ã®æ¹æ³ã§ã¯äžååã§ãããããã¯ãŒã¯ç®¡çè ãšæ å ±ã»ãã¥ãªãã£ã®å°é家ã¯ãèªååããã³åæããŒã«ãå¿ èŠãšããŠããŸããããã«ãããã¯ã€ã€ã¬ã¹ãã³ããŒã¯ãã®ãããªããŒã«ãæäŸããããã«ãªããŸãã
ãããã®èª²é¡ã«å¯ŸåŠããããã«ãCisco Catalyst 9800ã·ãªãŒãºã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒã¯ãåŸæ¥ã®APIã«å ããŠããã«å¥ã®æ¬¡äžä»£ïŒYANGïŒããŒã¿ã¢ããªã³ã°èšèªãåããRESTCONF / NETCONFãããã¯ãŒã¯æ§æãããã³ã«ããµããŒãããŸãã
NETCONFã¯ãã¢ããªã±ãŒã·ã§ã³ãæ å ±ãç §äŒããã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒãªã©ã®ãããã¯ãŒã¯ããã€ã¹ã®æ§æãå€æŽããããã«äœ¿çšã§ããXMLããŒã¹ã®ãããã³ã«ã§ãã
ãããã®æ¹æ³ã«å ããŠãCisco Catalyst 9800ã·ãªãŒãºã³ã³ãããŒã©ã¯ãNetFlowããã³sFlowã䜿çšããŠãããŒããŒã¿ãååŸããã§ãããããã³åæããæ©èœãæäŸããŸãã
ã»ãã¥ãªãã£ãšãã©ãã£ãã¯ã®ã¢ããªã³ã°ã§ã¯ãç¹å®ã®ãããŒã远跡ããæ©èœã¯è²ŽéãªããŒã«ã§ãããã®åé¡ã解決ããããã«ãsFlowãããã³ã«ãå®è£ ãããŸãããããã«ããã100åããšã«2åã®ãã±ããããã£ããã£ã§ããŸãããã ãããããŒã®åæããã³é©åãªèª¿æ»ãšè©äŸ¡ã«ã¯ãããã§ã¯äžååãªå ŽåããããŸãããããã£ãŠã代æ¿æ段ã¯Ciscoã«ãã£ãŠå®è£ ãããNetFlowã§ãããããã«ãããããã«åæããããã«ãæå®ãããã¹ããªãŒã å ã®ãã¹ãŠã®ãã±ããã100ïŒ åéããã³ãšã¯ã¹ããŒãã§ããŸãã
ãã1ã€ã®æ©èœã¯ãã³ã³ãããŒã©ãŒã®ããŒããŠã§ã¢å®è£ ã§ã®ã¿äœ¿çšã§ããŸãããCisco Catalyst 9800ã·ãªãŒãºã³ã³ãããŒã©ãŒã®ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãèªååããŸããããã¯ãã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒèªäœã§ã¹ã¯ãªãããçŽæ¥äœ¿çšããããã®ã¢ããªã³ãšããŠã®çµã¿èŸŒã¿ã®PythonãµããŒãã§ãã
æåŸã«ãå®çžŸã®ããSNMP v1ãv2ãããã³v3ã¯ãCisco Catalyst 9800ã·ãªãŒãºã³ã³ãããŒã©ãŒã®ç£èŠããã³ç®¡çæäœã§ãµããŒããããŠããŸãã
ãããã£ãŠãèªååã®èŠ³ç¹ãããCisco Catalyst 9800ã·ãªãŒãºãœãªã¥ãŒã·ã§ã³ã¯ãä»æ¥ã®ããžãã¹ããŒãºãå®å šã«æºãããæ°ããç¬èªã®ãœãªã¥ãŒã·ã§ã³ãæäŸããŸãããããããµã€ãºãšè€éãã®ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã§ã®èªåæäœãšåæã®ããã®ãå®çžŸã®ããããŒã«ã
çµè«
Cisco Catalyst 9800ã·ãªãŒãºã³ã³ãããŒã©ã«åºã¥ããœãªã¥ãŒã·ã§ã³ã«ãããCiscoã¯ãé«å¯çšæ§ãã»ãã¥ãªãã£ãããã³èªååã®ã«ããŽãªã§åªããããã©ãŒãã³ã¹ãçºæ®ããŸããã
ãã®ãœãªã¥ãŒã·ã§ã³ã¯ãèšç»å€ã®ã€ãã³ãäžã®1ç§æªæºã®ãã§ã€ã«ãªãŒããŒããã¹ã±ãžã¥ãŒã«ãããã€ãã³ãã®ãŒãããŠã³ã¿ã€ã ãªã©ããã¹ãŠã®é«å¯çšæ§èŠä»¶ãå®å šã«æºãããŠããŸãã
Cisco Catalyst 9800ã·ãªãŒãºã³ã³ãããŒã©ã¯ãã¢ããªã±ãŒã·ã§ã³ãèªèããã³ç®¡çããããã®è©³çŽ°ãªãã±ããæ€æ»ãããŒã¿ã¹ããªãŒã ã®å®å šãªå¯èŠæ§ãæå·åããããã©ãã£ãã¯ã«é ãããè åšã®èå¥ãé«åºŠãªèªèšŒããã³ã¯ã©ã€ã¢ã³ãä¿è·ã¡ã«ããºã ãæäŸããå æ¬çãªã»ãã¥ãªãã£ãæäŸããŸãã
éçšã®èªååãšåæã®ããã«ãCisco Catalyst 9800ã·ãªãŒãºã¯ãäžè¬çãªæšæºã¢ãã«ïŒYANGãNETCONFãRESTCONFãåŸæ¥ã®APIãããã³çµã¿èŸŒã¿Pythonã¹ã¯ãªããïŒã䜿çšããŠåŒ·åã§ãã
ãã®ããã«ãã·ã¹ã³ã¯ãæ代ã«å¯Ÿå¿ããçŸä»£ã®ããžãã¹ã®ãã¹ãŠã®èª²é¡ãèæ ®ã«å ¥ããŠããããã¯ãŒã¯ãœãªã¥ãŒã·ã§ã³ã®äžçææ°ã®ã¡ãŒã«ãŒãšããŠã®å°äœãåã³ç¢ºèªããŸãã
Catalystãã¡ããªã®ã¹ã€ããã®è©³çŽ°ã«ã€ããŠã¯ã Ciscoã®Webãµã€ãã«ã¢ã¯ã»ã¹ããŠãã ããã