ãã®èšäºã§ã¯ãæ å ±ã»ãã¥ãªãã£ã®èŠ³ç¹ãããCitrixVDIããŒã¹ã®ä»®æ³ãã¹ã¯ããããµãŒãã¹ãã©ã®ããã«æ©èœãããã説æããŸããã©ã³ãµã ãŠã§ã¢ãæšçåæ»æãªã©ã®å€éšã®è åšããã¯ã©ã€ã¢ã³ããã¹ã¯ããããä¿è·ããããã«ç§ãã¡ãè¡ã£ãŠããããšã玹ä»ããŸãã
ã©ã®ãããªã»ãã¥ãªãã£ã¿ã¹ã¯ã解決ããŸãã
ãµãŒãã¹ã«å¯Ÿããããã€ãã®äž»ãªã»ãã¥ãªãã£äžã®è åšãç¹å®ããŸãããäžæ¹ã§ã¯ãä»®æ³ãã¹ã¯ãããã¯ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒããææãããªã¹ã¯ããããŸããäžæ¹ãä»®æ³ãã¹ã¯ããããã€ã³ã¿ãŒãããã®ãªãŒãã³
- VDIã¹ã¿ã³ãå
šäœãå€éšã®è
åšããä¿è·ããŸãã
- ã¯ã©ã€ã¢ã³ããçžäºã«åé¢ããŸãã
- ä»®æ³ãã¹ã¯ãããèªäœãä¿è·ããŸãã
- ã©ã®ããã€ã¹ããã§ããŠãŒã¶ãŒãå®å
šã«æ¥ç¶ããŸãã
Fortinetã®æ°äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ã§ããFortiGateãä¿è·ã®äžæ žã«ãªããŸãããVDIã¹ã¿ã³ãã®ãã©ãã£ãã¯ãç£èŠããã¯ã©ã€ã¢ã³ãããšã«åé¢ãããã€ã³ãã©ã¹ãã©ã¯ãã£ãæäŸãããŠãŒã¶ãŒåŽã®è匱æ§ããä¿è·ããŸãããã®æ©èœã¯ãæ å ±ã»ãã¥ãªãã£ã®åé¡ã®ã»ãšãã©ã解決ããã®ã«ååã§ãã
ãã ããäŒç€Ÿã«ç¹å¥ãªã»ãã¥ãªãã£èŠä»¶ãããå Žåã¯ãè¿œå ã®ãªãã·ã§ã³ãæäŸããŸãã
- èªå®
ã®ã³ã³ãã¥ãŒã¿ãŒããäœæ¥ããããã®å®å
šãªæ¥ç¶ãçµç¹ããŸãã
- ã»ãã¥ãªãã£ãã°ã®èªå·±åæãžã®ã¢ã¯ã»ã¹ãæäŸããŸãã
- ãã¹ã¯ãããã§ã¢ã³ããŠã€ã«ã¹ä¿è·ç®¡çãæäŸããŸãã
- ãŒãæ¥ã®è匱æ§ããã®ä¿è·ã
- äžæ£æ¥ç¶ã«å¯Ÿããä¿è·ã匷åããããã«ãå€èŠçŽ èªèšŒãèšå®ããŸããã
åé¡ãã©ã®ããã«è§£æ±ºãããã«ã€ããŠè©³ãã説æããŸãã
ã¹ã¿ã³ããä¿è·ãããããã¯ãŒã¯ã»ãã¥ãªãã£ã確ä¿ããæ¹æ³
ãããã¯ãŒã¯éšåãã»ã°ã¡ã³ãåããŸããã¹ã¿ã³ãã§ã¯ããã¹ãŠã®ãªãœãŒã¹ã管çããããã®ã¯ããŒãºã管çã»ã°ã¡ã³ããéžã³åºããŸãã管çã»ã°ã¡ã³ãã«ã¯å€éšããã¢ã¯ã»ã¹ã§ããŸãããã¯ã©ã€ã¢ã³ããžã®æ»æãçºçããå Žåãæ»æè ã¯ããã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã
FortiGateã¯ä¿è·ã«è²¬ä»»ããããŸããã¢ã³ããŠã€ã«ã¹ããã¡ã€ã¢ãŠã©ãŒã«ãäŸµå ¥é²æ¢ã·ã¹ãã ïŒIPSïŒã®æ©èœãçµã¿åãããŠããŸãã
ã¯ã©ã€ã¢ã³ãããšã«ãä»®æ³ãã¹ã¯ãããçšã®åé¢ããããããã¯ãŒã¯ã»ã°ã¡ã³ããäœæããŸãããã®ãããFortiGateã«ã¯ä»®æ³ãã¡ã€ã³ãã¯ãããžãŒïŒVDOMïŒããããŸããããã«ããããã¡ã€ã¢ãŠã©ãŒã«ãè€æ°ã®ä»®æ³ãšã³ãã£ãã£ã«åå²ããåå¥ã®ãã¡ã€ã¢ãŠã©ãŒã«ã®ããã«åäœããåã¯ã©ã€ã¢ã³ãã«ç¬èªã®VDOMãå²ãåœãŠãããšãã§ããŸãã管çã»ã°ã¡ã³ãã«ã€ããŠã¯ãåå¥ã®VDOMãäœæããŸãã
次ã®ããã«ãªããŸãã
ã¯ã©ã€ã¢ã³ãéã«ãããã¯ãŒã¯æ¥ç¶ã¯ãããŸããããããããç¬èªã®VDOMã«ååšããä»ã®ã¯ã©ã€ã¢ã³ãã«åœ±é¿ãäžããŸããããã®ãã¯ãããžãŒããªããã°ããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã«ãã£ãŠã¯ã©ã€ã¢ã³ããåé¢ããå¿ èŠããããŸãããããã¯äººçèŠå ã«ããå±éºã§ãããã®ãããªã«ãŒã«ããåžžã«éããªããã°ãªããªããã¢ãšæ¯èŒããããšãã§ããŸãã VDOMã®å Žåãããã¢ãããŸã£ããæ®ããŸããã
å¥ã®VDOMã§ã¯ãã¯ã©ã€ã¢ã³ãã«ã¯ç¬èªã®ã¢ãã¬ã¹æå®ãšã«ãŒãã£ã³ã°ããããŸãããããã£ãŠãç¯å²ãè¶ããããšã¯äŒç€Ÿã«ãšã£ãŠåé¡ã§ã¯ãããŸãããã¯ã©ã€ã¢ã³ãã¯ãå¿ èŠãªIPã¢ãã¬ã¹ãä»®æ³ãã¹ã¯ãããã«å²ãåœãŠãããšãã§ããŸããããã¯ãç¬èªã®IPãã©ã³ãæã€å€§äŒæ¥ã«ãšã£ãŠäŸ¿å©ã§ãã
ã¯ã©ã€ã¢ã³ãã®äŒæ¥ãããã¯ãŒã¯ãšã®æ¥ç¶ã®åé¡ã解決ããŸããå¥ã®ã¿ã¹ã¯ã¯ãVDIãã¯ã©ã€ã¢ã³ãã€ã³ãã©ã¹ãã©ã¯ãã£ã«æ¥ç¶ããããšã§ããäŒç€ŸãäŒæ¥ã·ã¹ãã ãããŒã¿ã»ã³ã¿ãŒã«çœ®ããŠããå Žåã¯ãæ©åšãããã¡ã€ã¢ãŠã©ãŒã«ãŸã§ãããã¯ãŒã¯ã±ãŒãã«ãæ¥ç¶ããã ãã§ããããããå€ãã®å Žåãå¥ã®ããŒã¿ã»ã³ã¿ãŒãã¯ã©ã€ã¢ã³ãã®ãªãã£ã¹ãªã©ã®ãªã¢ãŒããµã€ããæ±ã£ãŠããŸãããã®å Žåããµã€ããšã®å®å šãªäº€æãæ€èšããIPsecVPNã䜿çšããŠsite2siteVPNãæ§ç¯ããŸãã
ã¹ããŒã ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®è€éãã«å¿ããŠç°ãªãå ŽåããããŸããã©ããã§ãåäžã®ãªãã£ã¹ãããã¯ãŒã¯ãVDIã«æ¥ç¶ããã®ã«ååã§ã-ååãªéçã«ãŒãã£ã³ã°ããããŸãã倧äŒæ¥ã«ã¯ã絶ããå€åããå€ãã®ãããã¯ãŒã¯ããããŸããããã§ãã¯ã©ã€ã¢ã³ãã«ã¯åçã«ãŒãã£ã³ã°ãå¿ èŠã§ããããŸããŸãªãããã³ã«ã䜿çšããŠããŸããOSPFïŒOpen Shortest Path FirstïŒãGREãã³ãã«ïŒGeneric Routing EncapsulationïŒãBGPïŒBorder Gateway ProtocolïŒã®ã±ãŒã¹ã¯ãã§ã«ãããŸãã FortiGateã¯ãä»ã®ã¯ã©ã€ã¢ã³ãã«åœ±é¿ãäžããããšãªããåå¥ã®VDOMã§ãããã¯ãŒã¯ãããã³ã«ããµããŒãããŸãã
ãã·ã¢é£éŠã®FSBã«ãã£ãŠèªå®ãããæå·åä¿è·ããŒã«ã«åºã¥ãæå·åã§ããGOST-VPNãæ§ç¯ããããšãå¯èœã§ããããšãã°ãä»®æ³ç°å¢ãS-Terraä»®æ³ã²ãŒããŠã§ã€ããŸãã¯PAK ViPNetãAPKSHãContinentãããS-Terraãã§KC1ã¯ã©ã¹ã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããŸãã
ã°ã«ãŒãããªã·ãŒãèšå®ããŸããVDIã«é©çšãããã°ã«ãŒãããªã·ãŒã«ã€ããŠã¯ã©ã€ã¢ã³ãã«åæããŸããããã§ã®æ§æã®ååã¯ããªãã£ã¹ã®ããªã·ãŒèšå®ãšåãã§ããActive Directoryãšã®çµ±åãæ§æããäžéšã®ã°ã«ãŒãããªã·ãŒã®ç®¡çãã¯ã©ã€ã¢ã³ãã«å§ä»»ããŠããŸããããã³ã管çè ã¯ãComputerãªããžã§ã¯ãã«ããªã·ãŒãé©çšããActive Directoryã§OUã管çãããŠãŒã¶ãŒãäœæã§ããŸãã
FortiGateã§ã¯ãã¯ã©ã€ã¢ã³ãVDOMããšã«ããããã¯ãŒã¯ã»ãã¥ãªãã£ããªã·ãŒãèšè¿°ããã¢ã¯ã»ã¹å¶éãèšå®ãããã©ãã£ãã¯ã¹ãã£ã³ãæ§æããŸããããã€ãã®FortiGateã¢ãžã¥ãŒã«ã䜿çšããŸãã
- IPSã¢ãžã¥ãŒã«ã¯ãã©ãã£ãã¯ãã¹ãã£ã³ããŠãã«ãŠã§ã¢ãæ€åºããäŸµå ¥ãé²ããŸãã
- ã¢ã³ããŠã€ã«ã¹ã¯ããã¹ã¯ãããèªäœããã«ãŠã§ã¢ãã¹ãã€ãŠã§ã¢ããä¿è·ããŸãã
- - ;
- .
ã¯ã©ã€ã¢ã³ãã¯ããµã€ããžã®åŸæ¥å¡ã®ã¢ã¯ã»ã¹ãåå¥ã«ç®¡çãããå ŽåããããŸããéè¡ã¯ããé »ç¹ã«ãã®ãããªèŠæ±ãåãåããŸãïŒã»ãã¥ãªãã£ãµãŒãã¹ã¯ã¢ã¯ã»ã¹å¶åŸ¡ãäŒç€Ÿã®åŽã«ããããšãèŠæ±ããŸãããããã®äŒæ¥ã¯ãã©ãã£ãã¯ãèªãç£èŠããå®æçã«ããªã·ãŒãå€æŽããŠããŸãããã®å ŽåãFortiGateããã®ãã¹ãŠã®ãã©ãã£ãã¯ãã¯ã©ã€ã¢ã³ãã«åããŸãããããè¡ãããã«ãäŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãšã®ã«ã¹ã¿ãã€ãºãããã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŸãããã®åŸãã¯ã©ã€ã¢ã³ãèªèº«ãäŒæ¥ãããã¯ãŒã¯ãšã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ã«é¢ããã«ãŒã«ãèšå®ããŸãã
ã¹ã¿ã³ãã§ã€ãã³ããèŠãŠããŸãã FortiGateãšäžç·ã«ãFortinetã®ãã°ã³ã¬ã¯ã¿ãŒã§ããFortiAnalyzerã䜿çšããŸãããã®å©ããåããŠãVDIã®ãã¹ãŠã®ã€ãã³ããã°ã1ãæã§èª¿ã¹ãçãããã¢ã¯ã·ã§ã³ãèŠã€ããçžé¢é¢ä¿ã远跡ããŸãã
ã¯ã©ã€ã¢ã³ãã®1人ã圌ã®ãªãã£ã¹ã§Fortinet補åã䜿çšããŠããŸãã圌ã®ããã«ããã°ã®ã¢ããããŒããæ§æããŸãããããã«ãããã¯ã©ã€ã¢ã³ãã¯ãªãã£ã¹ãã·ã³ãšä»®æ³ãã¹ã¯ãããã®ãã¹ãŠã®ã»ãã¥ãªãã£ã€ãã³ããåæã§ããŸããã
ä»®æ³ãã¹ã¯ããããä¿è·ããæ¹æ³
æ¢ç¥ã®è åšãããã¯ã©ã€ã¢ã³ããã¢ã³ããŠã€ã«ã¹ä¿è·ãç¬ç«ããŠç®¡çãããå Žåã¯ãKaspersky Security forVirtualizationãè¿œå ã§ã€ã³ã¹ããŒã«ããŸãã
ãã®ãœãªã¥ãŒã·ã§ã³ã¯ã¯ã©ãŠãã§ããŸãæ©èœããŸããç§ãã¡ã¯çãå€å žçãªKasperskyAnti-Virusããéãããœãªã¥ãŒã·ã§ã³ã§ãããšããäºå®ã«æ £ããŠããŸããå¯Ÿç §çã«ãKaspersky Security forVirtualizationã¯ä»®æ³ãã·ã³ãããŒãããŸããããã¹ãŠã®ãŠã€ã«ã¹ããŒã¿ããŒã¹ã¯ãµãŒããŒäžã«ããããã¹ãå ã®ãã¹ãŠã®ä»®æ³ãã·ã³ã«å¯ŸããŠå€å®ãçºè¡ããŸããã©ã€ããšãŒãžã§ã³ãã®ã¿ãä»®æ³ãã¹ã¯ãããã«ã€ã³ã¹ããŒã«ãããŸããæ€èšŒã®ããã«ãã¡ã€ã«ããµãŒããŒã«éä¿¡ããŸãã
ãã®ã¢ãŒããã¯ãã£ã¯ããã¡ã€ã«ä¿è·ãã€ã³ã¿ãŒãããä¿è·ãæ»æä¿è·ãåæã«æäŸããä»®æ³ãã·ã³ã®ããã©ãŒãã³ã¹ãäœäžãããŸããããã®å Žåãã¯ã©ã€ã¢ã³ãèªèº«ããã¡ã€ã«ä¿è·ã®äŸå€ãäœæã§ããŸãããœãªã¥ãŒã·ã§ã³ã®åºæ¬çãªã»ããã¢ãããæ¯æŽããŸãããã®æ©èœã«ã€ããŠã¯ãå¥ã®èšäºã§èª¬æããŸãã
æªç¥ã®è åšããããããè¡ãã«ã¯ãFortinetã®ããµã³ãããã¯ã¹ãã§ããFortiSandboxãæ¥ç¶ããŸããã¢ã³ããŠã€ã«ã¹ããŒãæ¥ã®è åšãèŠéããå Žåã®ãã£ã«ã¿ãŒãšããŠäœ¿çšããŸãããã¡ã€ã«ãããŠã³ããŒãããåŸããŸãã¢ã³ããŠã€ã«ã¹ã§ãã§ãã¯ããŠãããµã³ãããã¯ã¹ã«éä¿¡ããŸããFortiSandboxã¯ãä»®æ³ãã·ã³ããšãã¥ã¬ãŒããããã¡ã€ã«ãèµ·åããŠããã®åäœïŒã¢ã¯ã»ã¹ããã¬ãžã¹ããªå ã®ãªããžã§ã¯ããå€éšèŠæ±ãéä¿¡ãããã©ãããªã©ïŒãç£èŠããŸãããã¡ã€ã«ã®åäœãçãããå Žåããµã³ãããã¯ã¹ä»®æ³ãã·ã³ã¯åé€ãããæªæã®ãããã¡ã€ã«ã¯ãŠãŒã¶ãŒã®VDIã«è¡šç€ºãããŸããã
VDIãžã®å®å šãªæ¥ç¶ãèšå®ããæ¹æ³
ããã€ã¹ãISèŠä»¶ã«æºæ ããŠãããã©ããã確èªããŸãããªã¢ãŒãã³ã³ãããŒã«ã®æåãããã¯ã©ã€ã¢ã³ãã¯ç§ãã¡ã«ãªã¯ãšã¹ããé£çµ¡ããŠããŸããïŒåœŒãã®ããŒãœãã«ã³ã³ãã¥ãŒã¿ããã®ãŠãŒã¶ãŒã®å®å šãªä»äºã確å®ã«ããããã«ãæ å ±ã»ãã¥ãªãã£ã®å°é家ãªã誰ã§ãã家åºçšããã€ã¹ãä¿è·ããã®ã¯é£ããããšãç¥ã£ãŠããŸããããã¯ãªãã£ã¹æ©åšã§ã¯ãªããããå¿ èŠãªã¢ã³ããŠã€ã«ã¹ãã€ã³ã¹ããŒã«ããããã°ã«ãŒãããªã·ãŒãé©çšãããããããšã¯ã§ããŸããã
ããã©ã«ãã§ã¯ãVDIã¯å人çšããã€ã¹ãšäŒæ¥ãããã¯ãŒã¯ã®éã®å®å šãªã¬ã€ã€ãŒã«ãªããŸãããŠãŒã¶ãŒãã·ã³ããã®æ»æããVDIãä¿è·ããããã«ãã¯ãªããããŒããç¡å¹ã«ããUSB転éãçŠæ¢ããŸãããã ããããã«ãã£ãŠãŠãŒã¶ãŒããã€ã¹èªäœãå®å šã«ãªãããã§ã¯ãããŸããã
FortiClientã䜿çšããŠåé¡ã解決ããŸããããã¯ããšã³ããã€ã³ãã»ãã¥ãªãã£ã®ããã®ããŒã«ã§ããå瀟ã®ãŠãŒã¶ãŒã¯ãèªå® ã®ã³ã³ãã¥ãŒã¿ãŒã«FortiClientãã€ã³ã¹ããŒã«ããããã䜿çšããŠä»®æ³ãã¹ã¯ãããã«æ¥ç¶ããŸããFortiClientã¯ã3ã€ã®ã¿ã¹ã¯ãäžåºŠã«è§£æ±ºããŸãã
- ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ã®ãåäžãŠã£ã³ããŠãã«ãªããŸãã
- ããŒãœãã«ã³ã³ãã¥ãŒã¿ã«ã¢ã³ããŠã€ã«ã¹ãšææ°ã®OSã¢ããããŒãããããã©ããããã§ãã¯ããŸãã
- å®å šãªã¢ã¯ã»ã¹ã®ããã®VPNãã³ãã«ãæ§ç¯ããŸãã
åŸæ¥å¡ã¯ããã§ãã¯ã«åæ Œããå Žåã«ã®ã¿ã¢ã¯ã»ã¹ã§ããŸããåæã«ãä»®æ³ãã¹ã¯ãããèªäœã¯ã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹ã§ããªããããæ»æããã®ä¿è·ã匷åãããŸãã
äŒæ¥ããšã³ããã€ã³ãä¿è·èªäœã管çãããå Žåã¯ãFortiClient EMSïŒãšã³ããã€ã³ã管çãµãŒããŒïŒãæäŸããŸããã¯ã©ã€ã¢ã³ãã¯ããã¹ã¯ãããã¹ãã£ã³ãšäŸµå ¥é²æ¢ãèªåã§æ§æããã¢ãã¬ã¹ã®ãã¯ã€ããªã¹ããäœæã§ããŸãã
èªèšŒä¿æ°ãè¿œå ããŸããããã©ã«ãã§ã¯ããŠãŒã¶ãŒã¯Citrixãããã¹ã±ãŒã©ãŒãä»ããŠèªèšŒãããŸããããã§ããSafeNet補åã«åºã¥ãå€èŠçŽ èªèšŒã§ã»ãã¥ãªãã£ã匷åã§ããŸãããã®ãããã¯ã¯ç¹å¥ãªæ³šæãæã䟡å€ããããŸããããã«ã€ããŠã¯å¥ã®èšäºã§ã説æããŸãã
æšå¹Žã®äœæ¥ã§ãããŸããŸãªãœãªã¥ãŒã·ã§ã³ã䜿çšãããã®ãããªçµéšãèç©ããŠããŸãããVDIãµãŒãã¹ã¯ã¯ã©ã€ã¢ã³ãããšã«åå¥ã«æ§æãããŠãããããæãæè»ãªããŒã«ãéžæããŸãããããããè¿ãå°æ¥ãç§ãã¡ã¯äœãä»ã®ãã®ãè¿œå ããç§ãã¡ã®çµéšãå ±æããã§ãããã
10æ7æ¥ååŸ5æã«ãååããŠã§ãããŒã§ä»®æ³ãã¹ã¯ãããã«ã€ããŠè©±ããŸãããVDIãå¿ èŠã§ããããããšããªã¢ãŒãäœæ¥ãæŽçããæ¹æ³ã§ããïŒãVDIãã¯ãããžãŒãäŒæ¥ã«é©ããŠããå Žåãããã³ä»ã®æ¹æ³ã䜿çšããæ¹ãããå Žåã«ã€ããŠè©±ãåãããå Žåã¯ã
ç»é²ããŠãã ããã