12. ACL_åºç€
ãããã¯ãŒã¯ã»ãã¥ãªãã£ã®èŠïŒã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒACLïŒå ¥é
æ¬æ¥ã®ç ä¿®ã§ã¯ããããã¯ãŒã¯ã»ãã¥ãªãã£ã®åºæ¬ã§ããéåžžã«éèŠãªæè¡ã§ãããã¢ã¯ã»ã¹ã³ã³ãããŒã«ãªã¹ãïŒACLïŒãã«ã€ããŠåŠãã§ãããŸããACLãçè§£ã䜿ãããªãããšã§ãäžæ£ãªã¢ã¯ã»ã¹ãé²ãããããã¯ãŒã¯ãå®å šã«ä¿ã€ããšãã§ããŸãã
第1éšïŒACLè¬çŸ©ç·š ïœACLãšã¯äœãïŒãªãå¿ èŠãªã®ãïŒïœ
1. ACLãšã¯ïŒ
ACLïŒAccess Control ListïŒãšã¯ãã«ãŒã¿ãŒããã¡ã€ã¢ãŠã©ãŒã«ãªã©ã®ãããã¯ãŒã¯æ©åšãééãããã±ãããæ€æ»ãããã®ãã±ããããèš±å¯ãããããæåŠããããã倿ããããã®ã«ãŒã«ãªã¹ãã§ããã€ã¡ãŒãžãšããŠã¯ããããã¯ãŒã¯ã®äº€éæŽçãè¡ãéçªã®ãããªãã®ã§ãã
2. ãªãACLãå¿ èŠãªã®ãïŒ
- ã»ãã¥ãªãã£åäž: äžæ£ãªã¢ã¯ã»ã¹ãæ»æããå éšãããã¯ãŒã¯ãä¿è·ããŸããäŸãã°ãç¹å®ã®éšçœ²ä»¥å€ããã®æ©å¯æ å ±ãµãŒããŒãžã®ã¢ã¯ã»ã¹ãçŠæ¢ããããšãã£ãããšãå¯èœã§ãã
- ãããã¯ãŒã¯åž¯åã®å¶åŸ¡: äžèŠãªãã©ãã£ãã¯ãå¶éããããšã§ããããã¯ãŒã¯ã®ããã©ãŒãã³ã¹ãç¶æããŸãã
- ããªã·ãŒã®é©çš: äŒæ¥ãçµç¹ã®ã»ãã¥ãªãã£ããªã·ãŒã«åºã¥ããã¢ã¯ã»ã¹å¶åŸ¡ãå®çŸããŸãã
3. ACLã®ä»çµã¿
ACLã¯ãèšå®ãããã«ãŒã«ïŒãšã³ããªïŒã«åºã¥ããŠåäœããŸãã
- ãã±ãããã£ã«ã¿ãªã³ã°: ACLã¯ããã±ããã®ãããæ å ±ïŒéä¿¡å /å®å IPã¢ãã¬ã¹ãéä¿¡å /å®å ããŒãçªå·ããããã³ã«ã¿ã€ããªã©ïŒãèŠãŠãã«ãŒã«ã«åèŽãããã©ããã倿ããŸãã
- ã«ãŒã«ã®è©äŸ¡é åº: ã«ãŒã«ã¯ãªã¹ãã®äžããé ã«è©äŸ¡ãããŸããæåã«äžèŽããã«ãŒã«ã®åŠçïŒèš±å¯ãŸãã¯æåŠïŒãå®è¡ããããã以éã®ã«ãŒã«ã¯è©äŸ¡ãããŸããã
- æé»ã®Deny Any: ã©ã®ã«ãŒã«ã«ãäžèŽããªãã£ããã±ããã¯ãããã©ã«ãã§å šãŠæåŠãããŸãïŒæé»ã®Deny AnyïŒãããã¯ãæç€ºçã«èš±å¯ãããŠããªãéä¿¡ã¯ãã¹ãŠãããã¯ãããšããã»ãã¥ãªãã£ã®åºæ¬ååã«åºã¥ããŠããŸãã
-
ãã¯ã€ããªã¹ãæ¹åŒãšãã©ãã¯ãªã¹ãæ¹åŒ:
- ãã¯ã€ããªã¹ãæ¹åŒ: åºæ¬çã«ãã¹ãŠã®éä¿¡ãæåŠããèš±å¯ãããéä¿¡ã ããæç€ºçã«èšè¿°ããŸããACLã®ãæé»ã®Deny Anyãã®æ§è³ªäžããã®æ¹åŒãåºæ¬ãšãªããŸãã
- ãã©ãã¯ãªã¹ãæ¹åŒ: åºæ¬çã«ãã¹ãŠã®éä¿¡ãèš±å¯ããæåŠãããéä¿¡ã ããèšè¿°ããŸãã
4. ACLã®çš®é¡
ACLã«ã¯äž»ã«ä»¥äžã®2ã€ã®çš®é¡ããããŸãã
-
æšæºACL (Standard ACL):
- éä¿¡å IPã¢ãã¬ã¹ã®ã¿ãæ¡ä»¶ãšããŠãã±ããããã£ã«ã¿ãªã³ã°ããŸãã
- èšå®ãæ¯èŒçç°¡åã§ãããå¶åŸ¡ã§ããæ¡ä»¶ãéãããŸãã
- çªå·ä»ãïŒ1ïœ99ã1300ïœ1999ïŒãšååä»ãããããŸãã
-
æ¡åŒµACL (Extended ACL):
- éä¿¡å IPã¢ãã¬ã¹ãå®å IPã¢ãã¬ã¹ããããã³ã«ïŒTCP, UDP, ICMPãªã©ïŒãéä¿¡å /å®å ããŒãçªå·ïŒHTTPã®80çªãFTPã®21çªãªã©ïŒãšãã£ããããè©³çŽ°ãªæ¡ä»¶ã§ãã£ã«ã¿ãªã³ã°ãå¯èœã§ãã
- ããæè»ã§ãã现ããã¢ã¯ã»ã¹å¶åŸ¡ãå®çŸã§ããŸãã
- çªå·ä»ãïŒ100ïœ199ã2000ïœ2699ïŒãšååä»ãããããŸãã
5. ACLã®èšå®æé
ACLã®èšå®ã¯ãåºæ¬çã«ä»¥äžã®2ã¹ãããã§è¡ããŸãã
ã¹ããã1ïŒACLã®äœæ
ã«ãŒã«ãªã¹ããäœæããŸãã
-
ååä»ãæšæºACLã®äœæäŸ:
Router(config)# ip access-list standard <ãªã¹ãå> Router(config-std-nacl)# <è¡çªå·> permit | deny <éä¿¡å IPã¢ãã¬ã¹> <ã¯ã€ã«ãã«ãŒããã¹ã¯> -
çªå·ä»ãæšæºACLã®äœæäŸ:
Router(config)# access-list <ãªã¹ãçªå·> permit | deny <éä¿¡å IPã¢ãã¬ã¹> <ã¯ã€ã«ãã«ãŒããã¹ã¯> -
ååä»ãæ¡åŒµACLã®äœæäŸ:
Router(config)# ip access-list extended <ãªã¹ãå> Router(config-ext-nacl)# <è¡çªå·> permit | deny <ãããã³ã«> <éä¿¡å IPã¢ãã¬ã¹> <ã¯ã€ã«ãã«ãŒããã¹ã¯> [æŒç®å <éä¿¡å ããŒãçªå·>] <å®å IPã¢ãã¬ã¹> <ã¯ã€ã«ãã«ãŒããã¹ã¯> [æŒç®å <å®å ããŒãçªå·>]- æŒç®åã«ã¯
eq(çãã)ãneq(çãããªã)ãgt(ãã倧ãã)ãlt(ããå°ãã)ãrange(ç¯å²æå®) ãªã©ããããŸãã - ããŒãçªå·ã¯ããŒã¯ãŒãïŒäŸïŒ
www(80)ãtelnet(23)ïŒã§ãæå®å¯èœã§ãã - ç¹å®ã®ãã¹ããæå®ããå Žåã¯
host <IPã¢ãã¬ã¹>ã®ããã«èšè¿°ã§ããŸãã
- æŒç®åã«ã¯
ã¹ããã2ïŒACLã®ã€ã³ã¿ãŒãã§ãŒã¹ãžã®é©çš
äœæããACLãã«ãŒã¿ãŒã®ã€ã³ã¿ãŒãã§ãŒã¹ã«é©çšãããã±ãããã£ã«ã¿ãªã³ã°ãéå§ãããŸãã
Router(config-if)# ip access-group <ãªã¹ãåãŸãã¯çªå·> in | out
in: ã€ã³ã¿ãŒãã§ãŒã¹ãåä¿¡ãããã±ããïŒã€ã³ããŠã³ãïŒã«é©çšããŸãã
out: ã€ã³ã¿ãŒãã§ãŒã¹ãéä¿¡ãããã±ããïŒã¢ãŠãããŠã³ãïŒã«é©çšããŸãã
1ã€ã®ã€ã³ã¿ãŒãã§ãŒã¹ã1ã€ã®æ¹åïŒinãŸãã¯outïŒã«ã€ãã1ã€ã®ACLã®ã¿é©çšå¯èœã§ãã
6. ACLã®é©çšå ŽæïŒã©ãã«é 眮ãããïŒïŒ
ACLãã©ãã«é©çšãããã¯éåžžã«éèŠã§ãã
æšæºACL: éä¿¡å
IPã¢ãã¬ã¹ããèŠãªããããæå³ããªãéä¿¡ãŸã§ãããã¯ããŠããŸãå¯èœæ§ããããŸãããã®ãããã§ããã ãå®å
ã«è¿ãã«ãŒã¿ãŒã«é©çšããã®ãäžè¬çã§ãã
æ¡åŒµACL: è©³çŽ°ãªæ¡ä»¶ã§å¶åŸ¡ã§ãããããäžèŠãªãã©ãã£ãã¯ãæ©æã«é®æã§ããŸãããã®ãããã§ããã ãéä¿¡å
ã«è¿ãã«ãŒã¿ãŒã«é©çšããã®ãäžè¬çã§ãã
7. VTYã¢ã¯ã»ã¹ã®å¶é
ã«ãŒã¿ãŒãžã®TelnetãSSHã¢ã¯ã»ã¹ïŒVTYã¢ã¯ã»ã¹ïŒãç¹å®ã®ãã¹ãããã®ã¿ã«å¶éããå ŽåãACLã䜿çšã§ããŸãããã®å Žåãã€ã³ã¿ãŒãã§ãŒã¹ã§ã¯ãªãVTYã©ã€ã³ã«å¯ŸããŠACLãé©çšããŸããäžè¬çã«ã¯éä¿¡å IPã¢ãã¬ã¹ã§å¶éãããããæšæºACLãçšããããŸãã
Router(config)# line vty 0 4
Router(config-line)# access-class <ãªã¹ãåãŸãã¯çªå·> in
8. 確èªã³ãã³ã
èšå®ããACLã¯ä»¥äžã®ã³ãã³ãã§ç¢ºèªã§ããŸããã«ãŒã«ã«äžèŽãããã±ããæ°ã衚瀺ãããŸãã
Router# show access-lists
Discussion