sshæ¥ç¶
ãç ä¿®è³æãSSHã«ããã»ãã¥ã¢ãªãªã¢ãŒã管çïŒä»çµã¿ãšèšå®
æ¬èšäºã¯ãCiscoã«ãŒã¿ã䜿çšãããããã¯ãŒã¯ç ä¿®ãSSHæ¥ç¶ç·šãã®è¬çŸ©ã»ãã³ãºãªã³çšè³æã§ãã
TelnetãšSSHã®éããå
¬é鵿å·ã®ä»çµã¿ããããŠå®æ©ã§ã®èšå®æé ã解説ããŸãã
1. ãªã¢ãŒãæ¥ç¶ãšSSHã®æŠèŠ
ãããŸã§ã¯ãã«ãŒã¿ãèšå®ããããã«ãã³ã³ãœãŒã«ã±ãŒãã«ãã䜿ã£ãŠç©ççã«æ¥ç¶ããŠããŸãããããããå®éã®çŸå Žã§ã¯ãã«ãŒã¿ã¯é ãé¢ãããµãŒãã«ãŒã ãããŒã¿ã»ã³ã¿ãŒã«èšçœ®ãããŠããŸããèšå®å€æŽã®ãã³ã«çŸå°ã«è¡ãã®ã¯éå¹çã§ãã
ããã§ããããã¯ãŒã¯çµç±ã§é éæäœããããªã¢ãŒãæ¥ç¶ãã䜿çšããŸãã代衚çãªãããã³ã«ã¯ä»¥äžã®2ã€ã§ãã
Telnet (Teletype Network)
- æããããæšæºçãªãããã³ã«ã§ãã
- åé¡ç¹: éä¿¡å 容ïŒãã¹ã¯ãŒããèšå®æ å ±ïŒããã¹ãŠãå¹³æïŒã¯ãªã¢ããã¹ãïŒãã§éä¿¡ããŸããããæªæã®ãã第äžè ã«éä¿¡ããã±ãããã£ããã£ïŒçèŽïŒããããšããã¹ã¯ãŒãããã®ãŸãŸèŠããŠããŸããŸããçŸåšã¯ã»ãã¥ãªãã£ã®èгç¹ããã»ãšãã©äœ¿çšãããŸããã
SSH (Secure Shell)
- çŸåšã®æšæºçãªãªã¢ãŒãæ¥ç¶ãããã³ã«ã§ãã
- ç¹åŸŽ: éä¿¡å 容ããã¹ãŠæå·åããŸããäžãäžçèŽãããŠããäžèº«ã¯è§£èªã§ããªããããå®å šã«ãªã¢ãŒãæäœãå¯èœã§ãã
ä»åã¯ããã®SSHã®èšå®ãè¡ããŸãã
2. SSHã®ä»çµã¿ïŒå ¬é鵿巿¹åŒ
SSHãå®å šãªéä¿¡è·¯ã確ç«ã§ããã®ã¯ããå ¬é鵿巿¹åŒããšããæè¡ã䜿çšããŠããããã§ãã
å ±é鵿å·ãšå ¬é鵿å·ã®éã
-
å ±é鵿å·ïŒåŸæ¥ã®æ¹æ³ïŒ:
ãæå·åããšã埩å·ïŒå ã«æ»ãïŒãã«åãéµã䜿ããŸããå®¶ã®éµã®ãããªãã®ã§ãã
åé¡ç¹ã¯ãçžæã«éµãæž¡ãéããã®éµèªäœãçãŸããŠããŸããšèª°ã§ãéããããŠããŸãããšã§ãã -
å ¬é鵿å·ïŒSSHã®æ¹æ³ïŒ:
ãå ¬ééµïŒã¿ããªã«é ãéµïŒããšãç§å¯éµïŒèªåã ããæã€éµïŒãã®ãã¢ã䜿ããŸãã
ãã®2ã€ã®éµã«ã¯ã**ãå ¬ééµã§æå·åãããã®ã¯ã察ã«ãªãç§å¯éµã§ããå ã«æ»ããªãã**ãšããç¹åŸŽããããŸãã
SSHæ¥ç¶ã®æµãïŒå®å šãªéä¿¡ãã§ãããŸã§ïŒ
SSHã§ã¯ããã®ãã¢ã䜿ã£ãŠä»¥äžã®ããã«å®å šãªéä¿¡ãéå§ããŸãã
-
æ¥ç¶èŠæ±:
PCïŒã¯ã©ã€ã¢ã³ãïŒãã«ãŒã¿ïŒãµãŒããŒïŒã«æ¥ç¶ããŸãã -
å ¬ééµã®éä»ïŒèº«å蚌æïŒ:
ã«ãŒã¿ã¯ããããããäœã£ãŠãããèªèº«ã®ãå ¬ééµããPCã«éããŸãã
ïŒâ»ååæ¥ç¶æã«PCåŽã§ãæçŽïŒãã£ã³ã¬ãŒããªã³ãïŒãç°ãªããŸããçã®èŠåãåºãã®ã¯ããã®åãåã£ãå ¬ééµãæ¬åœã«æ¥ç¶ãããã«ãŒã¿ã®ãã®ãã人éã確èªããããã§ãïŒ -
å ±ééµã®çæãšæå·å:
PCã¯ããã®åŸã®éä¿¡ã§äœ¿ããå ±ééµïŒãã®å Žéãã®äœ¿ãæšãŠéµïŒããçæããŸãã
ãããŠããã®å ±ééµãã«ãŒã¿ã®å ¬ééµã䜿ã£ãŠæå·åããã«ãŒã¿ãžéããŸãã
â éèŠïŒãã®ããŒã¿ã¯ã察ã«ãªãç§å¯éµãæã€ã«ãŒã¿ããå ã«æ»ããŸãããçèŽãããŠãå®å šã§ãã -
埩å·:
ã«ãŒã¿ã¯ãèªåã ããæã£ãŠãããç§å¯éµãã䜿ã£ãŠãéãããŠããããŒã¿ãå ã«æ»ãïŒåŸ©å·ïŒãå ±ééµãåãåºããŸãã -
æå·åéä¿¡:
ããã§ããäºãã ããç¥ã£ãŠãããå ±ééµããå ±æã§ããŸããã以éã®éä¿¡ïŒãã°ã€ã³IDããã¹ã¯ãŒãéä¿¡ãªã©ïŒã¯ããã®å ±ééµã䜿ã£ãŠãã¹ãŠæå·åããŠè¡ãããŸãã
ãã®ä»çµã¿ãå®çŸããããã«ãã«ãŒã¿ã®èšå®ã§ã¯ãæå·éµïŒRSAéµïŒã®çæããšããæé ãå¿ é ãšãªããŸãã
3. ãline vtyããšã¯ïŒ
èšå®ã«å
¥ãåã«ãä»ååããŠç»å Žãã line vty ã«ã€ããŠè§£èª¬ããŸãã
Q. line vty ãšã¯ïŒ
**A. ããããã¯ãŒã¯è¶ãã«å ¥ã£ãŠãã人ã®ããã®ãä»®æ³çãªå ¥ãå£ã**ã§ãã
- ConsoleããŒã: ã«ãŒã¿ã«ç©ççã«ä»ããŠããå ¥ãå£ã§ããã±ãŒãã«ãæ¿ãã°å ¥ããŸãã
- VTY (Virtual Teletype): ãããã¯ãŒã¯äžã«ååšãããä»®æ³çãªãã¢ãã§ããLANã±ãŒãã«ãéã£ãŠãã£ãŠãã管çè ã¯ããã®VTYã®ãã¢ãéã£ãŠã«ãŒã¿å éšã«å ¥ããŸãã
Q. 0 4 ãšã¯ïŒ
A. ã0çªãã4çªãŸã§ãåèš5ã€ã®ãã¢ãçšæããããšããæå³ã§ãã
ã«ãŒã¿ã¯åæã«è€æ°ã®äººããªã¢ãŒãæ¥ç¶ã§ããããã«ãè€æ°ã®ä»®æ³ããŒããæã£ãŠããŸããline vty 0 4 ãšæå®ããããšã§ãã0, 1, 2, 3, 4ãã®5ã»ãã·ã§ã³åã®èšå®ãäžæ¬ã§è¡ããŸãã
Q. äœãèšå®ããã®ãïŒ
A. ãã®ãä»®æ³ãã¢ããéãããã®ã«ãŒã«ã決ããŸãã
- ã誰ãéããïŒïŒèªèšŒæ¹åŒïŒã
- ãã©ã®æ¹æ³ã§å ¥ããããïŒïŒSSHã®ã¿èš±å¯ããã®ããTelnetãèš±ãã®ãïŒã
4. SSHã®èšå®æé (ãã³ãºãªã³)
ããããã¯å®æ©ã§ã®æäœã«ãªããŸãã
ã¹ããã1: ãã¹ãåãšãã¡ã€ã³åã®èšå®
SSHã®æå·éµãçæããã«ã¯ããFQDNïŒå®å šä¿®é£Ÿãã¡ã€ã³åïŒããå¿ èŠã§ãããã®ããããã¹ãåãšãã¡ã€ã³åã®èšå®ãå¿ é æ¡ä»¶ãšãªããŸãã
Router> enable
Router# configure terminal
! 1. ãã¹ãåã®èšå®
Router(config)# hostname RT1
! 2. ãã¡ã€ã³åã®èšå® (æŒç¿çšãªã®ã§cisco.comçã§OK)
RT1(config)# ip domain-name cisco.com
### ã¹ããã2: ç¹æš©ã¢ãŒããã¹ã¯ãŒãïŒEnable SecretïŒã®èšå®
ãªã¢ãŒãæ¥ç¶ãè¡ãå Žåãã»ãã¥ãªãã£ã®èгç¹ããç¹æš©ã¢ãŒããžã®ç§»è¡ãã¹ã¯ãŒãïŒEnable SecretïŒãèšå®ãããŠããªããšããã°ã€ã³ã§ããªãå ŽåããããŸããå¿
ãèšå®ããŸãã
! ãã¹ã¯ãŒã㯠"cisco" ãšããŸã
RT1(config)# enable secret cisco
###ã¹ããã3: æå·éµ (RSAéµ) ã®çæ
ã«ãŒã¿èªèº«ã®ãç§å¯éµããšãå
¬ééµãã®ãã¢ãçæããŸãããã®ã³ãã³ããå®è¡ããããšã§ãã«ãŒã¿ã§SSHæ©èœãæå¹åãããŸãã
RT1(config)# crypto key generate rsa
! éµã®é·ããèãããŸããæšå¥šããã 1024 以äžãå
¥åããŸã
The name for the keys will be: RT1.cisco.com
Choose the size of the key modulus in the range of 360 to 4096 for your
General Purpose Keys. Choosing a key modulus greater than 512 may take
a few minutes.
How many bits in the modulus [512]: 1024
確èª: % Generating 1024 bit RSA keys, keys will be non-exportable... ãšè¡šç€ºãããã°æåã§ãã
### ã¹ããã4: ãŠãŒã¶ãŒã®äœæ
ã誰ããã°ã€ã³ã§ããããã®ã¢ã«ãŠã³ããäœæããŸãã
! ãŠãŒã¶ãŒå: admin, ãã¹ã¯ãŒã: cisco123
RT1(config)# username admin secret cisco123
### ã¹ããã5: VTYã©ã€ã³ïŒä»®æ³ãã¢ïŒã®èšå®
æåŸã«ãVTYããŒãã«å¯ŸããŠãSSHæ¥ç¶ã®ã¿èš±å¯ããããŒã«ã«ãŠãŒã¶ãŒã§èªèšŒããšããèšå®ãé©çšããŸãã
! 0çªãã4çªãŸã§ã®5ã€ã®ä»®æ³ããŒãèšå®ã¢ãŒãã«å
¥ã
RT1(config)# line vty 0 4
! ãlogin localã: ã«ãŒã¿ã«äœæããusername/passwordã䜿ã£ãŠèªèšŒãã
RT1(config-line)# login local
! ãtransport input sshã: SSHã®éä¿¡ã ããåãå
¥ãã (Telnetã¯æåŠ)
RT1(config-line)# transport input ssh
RT1(config-line)# end
### ã¹ããã6: éµçæã®ç¢ºèª
çæãããæå·éµãã¢ãã«ãŒã¿å
ã«æ£ããååšããã確èªããŸãã ã»ãã¥ãªãã£äžãç§å¯éµãèŠãããšã¯ã§ããŸãããã察ã«ãªããå
¬ééµãã衚瀺ããããšã§éµãã¢ã®ååšã確èªã§ããŸãã
RT1# show crypto key mypubkey rsa
% Key pair was generated at: ...
Key name: RT1.cisco.com
Key type: RSA KEYS
Storage Device: private-config
Usage: General Purpose Key
Key is not exportable.
Key Data:
30819F30 0D06092A ... (çç¥) ...
解説: Key Data ã®äžã«æååã衚瀺ãããŠããã°ãå
¬ééµïŒããã³å¯Ÿã«ãªãç§å¯éµïŒã¯æ£åžžã«äœæã»ä¿åãããŠããŸãã
5. æ¥ç¶ç¢ºèª (TeraTerm)
PCããTeraTermã䜿ã£ãŠæ¥ç¶ç¢ºèªãè¡ããŸãã
TeraTermãèµ·å:
ãæ°ããæ¥ç¶ãç»é¢ãéããŸãã
ãã¹ã: ã«ãŒã¿ã®IPã¢ãã¬ã¹ãå
¥åããŸãã
ãµãŒãã¹: ãSSHããéžæããŸããïŒTCPããŒãã¯èªåçã«22ã«ãªããŸãïŒ
ãOKããã¯ãªãã¯ããŸãã
ã»ãã¥ãªãã£èŠå:
ååæ¥ç¶æã®ã¿ããã»ãã¥ãªãã£èŠåãã衚瀺ãããŸãã
ããã¯ãã¹ããã3ã§çæããã«ãŒã¿ã®ãå
¬ééµãã®æçŽã衚瀺ãããŠããç»é¢ã§ããããã®ã«ãŒã¿ãä¿¡é ŒããŠéä¿¡ããŸããïŒããšãã確èªã§ãã®ã§ããç¶è¡ããã¯ãªãã¯ããŸãã
èªèšŒ:
SSHèªèšŒç»é¢ã衚瀺ãããŸããã¹ããã4ã§äœæãããŠãŒã¶ãŒæ
å ±ãå
¥åããŸãã
ãŠãŒã¶ãŒå: admin
ãã¹ãã¬ãŒãº: cisco123
ãOKããã¯ãªãã¯ããŸãã
ãã°ã€ã³å®äº:
RT1> ãšããããã³ããã衚瀺ãããã°ãSSHã«ãããªã¢ãŒãæ¥ç¶ã¯æåã§ãïŒ
enable ãšå
¥åããã¹ããã2ã§èšå®ãããã¹ã¯ãŒãïŒciscoïŒãå
¥åããŠç¹æš©ã¢ãŒãã«å
¥ããããšã確èªããŸãããã
(åè) ãã©ãã«ã·ã¥ãŒãã£ã³ã°
SSHããŒãžã§ã³: ã»ãã¥ãªãã£åŒ·åã®ãããSSH version 2 ã®äœ¿çšãæšå¥šãããŸãã以äžã®ã³ãã³ãã§åŒ·å¶ã§ããŸãã RT1(config)# ip ssh version 2
èšå®ã®ããçŽã: ãã¹ãåããã¡ã€ã³åã倿Žããå ŽåãéµãäœãçŽãå¿
èŠããããŸãã RT1(config)# crypto key zeroize rsa (éµã®åé€) ãã®åŸãå床 crypto key generate rsa ãå®è¡ããŸãã
Discussion