Paloalto ã§ãªãã¸ã§ã¯ãã®è¨å®ãæå ¥ããéã«ããå©ç¨ãã CLI ã³ãã³ããã¾ã¨ãã¦ã¿ã¾ããã ãã®è¨äºã§ã¯ URLã«ãã´ãªãURLãã£ã«ã¿ãªã³ã°ã®ï¼ã¤ã®ãªãã¸ã§ã¯ãã® CLI ã³ãã³ããã¾ã¨ãã¦ãã¾ãã PAN-OS㯠[10.2.3] ãå©ç¨ãã¦ãã¾ãã
#ã¹ã¿ãã£ãã¯ã«ã¼ãã®ä½æã¨ã¤ã³ã¿ã¼ãã§ã¼ã¹ã®æå® set network virtual-router ï¼ä»®æ³ã«ã¼ã¿ã¼åï¼ routing-table ip static-route ï¼ã«ã¼ãåï¼ interface ï¼ethernetã®ãã¼ãçªå·ï¼ #å®å ã¢ãã¬ã¹ã®æå® set network virtual-router ï¼ä»®æ³ã«ã¼ã¿ã¼åï¼ routing-table ip static-route ï¼ã«ã¼ãåï¼ destination ï¼IPã¢ãã¬ã¹ or ã¢ãã¬ã¹ãªãã¸ã§ã¯ãï¼ #ãã¯ã¹ããããã®æå® set network virtual-router ï¼ä»®æ³ã«ã¼ã¿ã¼åï¼ routing-table ip static-route ï¼ã«ã¼ãåï¼ nexthop ip-address ï¼IPã¢ãã¬ã¹ or ã¢ãã¬ã¹ãªãã¸ã§ã¯ãï¼ #ã¹ã¿ãã£ãã¯ã«ã¼ãã®ä½æã¨ã¤ã³ã¿ã¼ãã§ã¼ã¹ã®æå®
configã®è¡æ°ã¯ã»ã¨ãã©ã®å ´åãCLIã®è¡¨ç¤ºè¡æ°ãè¶ ããè¡æ°ã¨ãªãã®ã§ãã¼ã¸ã³ã°æ©è½ãåãã¾ãã æçµè¡ã¾ã§ã¹ã¯ãã¼ã«ããã®ã¯æéãããããããç§ã¯ããç¡å¹åã«ãã¦ãã¾ãã ã¡ãªã¿ã«ãã¼ã¸ã³ã°æ©è½ãåããå ´åã«ã¯ãShift ï¼ Qãã§æãããã¨ãå¯è½ã§ãã ï¼ï¼ã³ã³ãã£ã°ã¬ã¼ã·ã§ã³ã¢ã¼ãã«å ¥ããshowããå®è¡ãã¾ãã ããã¨ä»¥ä¸ã®ããã«setå½¢å¼ã®cofnigã表示ããã¾ãã xxxxxx@paloalto-test# show set deviceconfig system type dhcp-client send-hostname yes set deviceconfig system type dhcp-client send-client-id no set deviceconfig system type dhcp-client accept-dhcp-hostname
対象ãã¼ã¸ã§ã³ PAN-OS 10.2.4-h4 ãã±ãããã£ããã£ã¨ã¯ ãã±ãããã£ããã£ã¨ã¯ããããã¯ã¼ã¯ãæµãããã±ãããåéãããã¨ã§ãã ãã±ããã«ã¯è»¢éããããã¼ã¿ã¨ã¨ãã«éä¿¡ã®éä¿¡å ãå®å ããããã³ã«ãªã©ã®æ å ±ãå«ã¾ãã¦ãã¾ãã ãã£ã¦ããããã¯ã¼ã¯é害ãçºçããæãªã©ã«ãã±ãããã£ããã£ãè¡ã£ã¦åå 調æ»ãè¡ããã¨ãã§ãã¾ãã ãã±ããåå¾æé 1.PaloAltoã«ãã°ã¤ã³ãã[MONITOR] > [ãã±ãããã£ããã£]ã«ã¢ã¯ã»ã¹ãã¾ãã 2.[ãã£ã«ã¿ã®ç®¡ç]ãã¯ãªãã¯ãããã±ãããã£ããã£æã®ãã£ã«ã¿æ¡ä»¶ãä½æãã¾ãã æ大ã§4ã¤ã¾ã§ãã£ã«ã¿æ¡ä»¶ãå®ç¾©ãããã¨ãã§ãã¾ãã [è£è¶³1] å ¥åã¤ã³ã¿ã¼ãã§ã¤ã¹ï¼ãã±ããããã£ããã£ããã¤ã³ã¿ã¼ãã§ã¤ã¹ãæå®ãã¾ãã å ¥åã¤ã³ã¿ã¼ãã§ã¤ã¹ã«å¯¾ãã¦ãã±ããããã£ããã£ãããããå ¥åºåã§åå¾ããå ´åã«ã¯ãä¸è¨ã®ããã«ãã£ã«ã¿ã«ã¼
è¨å®åã®æºå ã¾ããSSL復å·åãã§ãã¦ãããã©ããã確èªããããããã©ãã£ãã¯ãã°ã®ãã©ã¼ããããå¤æ´ãã¾ãã Monitor > ãã° > ãã©ãã£ãã¯ã¸ç§»åããå·¦ä¸ã«ã«ã¼ã½ã«ãå½ã¦ãã¨ãä¸ç¢å°ã表示ãããã®ã§ãã¯ãªãã¯ãã¾ããããã¨ãã«ã©ã ã¨ããæåã表示ããã¾ãã®ã§ã復å·åã«ãã§ãã¯ãå ¥ãã¾ãã 以ä¸ã®ããã«ã復å·åã®ã«ã©ã ã追å ããã¾ããå é ã«é ç½®ããã¾ãã®ã§ããã©ãã°ã«ãã好ããªã¨ããã«é ç½®ãã¦ãã ãããä»åã¯å¾©å·åã®ãã¹ãã«ä½¿ç¨ããã®ã§ãå é ã«é ç½®ãã¾ãã 端æ«ããGoogleãTwitterãYoutubeã¸ã¢ã¯ã»ã¹ãã¦ã¿ã¾ãã復å·åããã¦ããªãï¼noï¼ã§ãããã¨ã確èªã§ãã¾ãã èªå·±ç½²åã«ã¼ãCA証ææ¸ï¼Self-Signed Root CA Certificateï¼ä½æ ä»åã¯ãã¨ã³ã¿ã¼ãã©ã¤ãºCAã«ãã£ã¦ç½²åããã証ææ¸ã§ã¯ãªããPaloaltoãèªå·±ç½²åãã証ææ¸ã
æè¿ã§ã¯SSL Decryption(復å·)æ©è½ã¯æ®ã©ã®UTM/Proxy製åã対å¿ãã¦ããã¨æãã¾ããPalo Altoã®å ´åãSSL Decryptionã«3種é¡ã®æ¹å¼ããããããè¦ä»¶ã«å¿ãã¦ä½¿ãåããå¿ è¦ãããã¾ãã (1) SSL Forward Proxy ä¸è¬çãªSSL Decryptionæ©è½ã§ãããClientããServeråãã®SSLéä¿¡ä¸ã«Proxyã¨ãã¦åå¨ãã¾ãããµã¼ã証ææ¸ãPalo Altoãåç½²å(çºè¡å ãRootCAã¨ãã¦ç½²åï¼ãããããã¯ã©ã¤ã¢ã³ãã®Webãã©ã¦ã¶ã«Palo Altoã®è¨¼ææ¸ãã¤ã³ãã¼ãããªããã°ãªãã¾ãããã¾ããTAPã¢ã¼ãã§ã¯ä½¿ç¨åºæ¥ã¾ããã ï¼å ¬ç証ææ¸ãã¤ã³ã¹ãã¼ã«ããã°ã¯ã©ã¤ã¢ã³ãã®Webãã©ã¦ã¶ã«ã¤ã³ã¹ãã¼ã«ããªãã¦ãããã¨ããã¥ã¢ã«ã«ã¯æ¸ãã¦ãããã§ããåºæ¥ãªããããããPaloèªä½ã«è¨¼ææ¸èªä½å ¥ãã¾ããã§ããã (2)SS
ãPALallaxï¼OSSçï¼ãã§ããããã ãã質åã«ã¤ãã¦ã¾ã¨ãã¦ãã¾ãã â»éææ´æ°ãã¦ããã¾ã è¨è¼ããã¦ããªãã質åã«ã¤ãã¦ã¯ããåãåããã©ã¼ã ãããé¡ããããã¾ãã ç®æ¬¡ æ©è½ PALallaxã¯ã¨ã¼ãã¼ã³ãã¥ãã±ã¼ã·ã§ã³ãºï¼å½ç¤¾ï¼ã«æ å ±ãéä¿¡ãã¾ããï¼ ãã°ç®¡ç PALallaxã§åä¿¡ããSyslogã¯ã©ãã«ä¿åããã¾ããï¼ ãã°ã¯ä½ä¸ä»£ä¿åããã¾ããï¼å¤æ´ãããã¨ã¯å¯è½ã§ããï¼ ãã¼ã¿ãã¼ã¹ã¯ã©ãã«ä¿åããã¾ããï¼ ãã¼ã¿ãã¼ã¹ã®å 容ãæéãæå®ãã¦åé¤ã§ãã¾ããï¼ ãã°ãã©ã¼ããã ãã¼ã¿ãã¼ã¹ã®ãã£ã¼ã«ãåã«ã¤ãã¦æãã¦ãã ããã ããã©ã¼ãã³ã¹ PALallaxã®æ§è½åèå¤ã¯ããã¾ããï¼ ãã¡ã¤ã¢ã¦ã©ã¼ã«ããéä¿¡ãããSYSLOGæ°ã®ç®å®ã¯ããã¾ããï¼ ä½æ¥/ä¿å®/ãµãã¼ãä¾é ¼ PALallaxã®æ§ç¯ãä¾é ¼ã§ãã¾ããï¼ PALallaxã®ä¿å®ã»ãµãã¼ããä¾é ¼ã§ãã¾ãã
æ¬è¨äºã¯ä¸è¨URLã«ç§»åãã¾ããã ï¼ç§å¾ã«èªåçã«ç§»åãã¾ãã https://needlework.jp/article/needlework-firewall-policytest ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®ããªã·ã¼ãã¹ããèªååãã製åãNEEDLEWORKãã®è²©å£²éå§ããï¼å¹´ãçµéããå æ¥ã¡ã¸ã£ã¼ãã¼ã¸ã§ã³ã¢ããããããã¾ããã ãã製åã®ãã¨ãç¥ã£ã¦ãããããã«ãä½åãã«åãã¦NEEDLEWORKã®ç´¹ä»è¨äºãæ¸ãã¦ããããã¨æãã¾ãã ç®æ¬¡ NEEDLEWORKã¨ã¯ï¼ ä»ã¾ã§ã®ãã¹ã ä»ã¾ã§ã®ãã¹ãæ§æ ä»ã¾ã§ã®ãã¹ãæ¹æ³ NEEDLEWORKã§ã®ãã¹ã NEEDLEWORKã§ã®ãã¹ãæ§æ NEEDLEWORKã§ã®ãã¹ãæ¹æ³ æå¾ã« è³æãã¦ã³ãã¼ã NEEDLEWORKã¨ã¯ï¼ ã¾ããNEEDLEWORKã¯ä½ãããããã®è£½åãã説æãã¾ãã NEEDLEWORKã¯ããã¡ã¤ã¢ã¦ã©ã¼ã«ã®ã»
æ¬è¨äºã®å 容ã¯PAN-OS7.1ç³»ããã¨ã«è¨è¼ãã¦ãã¾ã PAN-OS4.0ããå®è£ ãããBotnetï¼ããããããï¼ã¬ãã¼ãæ©è½ãçããæ´»ç¨ã§ãã¦ãã¾ããï¼ Botnetã¬ãã¼ãã¯ãBotåããå¯è½æ§ããããã¹ããæ¤åºããããã®æ©è½ã§ãï¼ç¡æã§ä½¿ç¨å¯è½ï¼ã â»Botåãããã¹ãã¯ãC&Cãµã¼ãã¼ï¼Command and Control Serverï¼ã«ã³ã³ããã¼ã«ãããæ»æã»æ å ±åéçã«å©ç¨ããã¾ã Botnetã¬ãã¼ãã®ç¢ºèª æ¥æ¬èªè¡¨è¨ã®å ´åã次ä¸ä»£ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®ç®¡çç»é¢ã§ãMonitorãâãããããããããã確èªãããã¨ãã§ãã¾ãã ããã¢ã«ããããã¯ã¼ã¯ã¹æ¬¡ä¸ä»£ãã¡ã¤ã¢ã¦ã©ã¼ã«ãBotnetã¬ãã¼ã Botæ¤ç¥ã®æ¹æ³ Botåãããã¹ãã¯ãã¢ã³ãã¦ã£ã«ã¹ã½ããã«æ¤åºãããªãããã«å¤§éã®äºç¨®ãçæããããææå¾ã«èªèº«ãã¢ãããã¼ãããããããããå¾æ¥ã®æ¹æ³ã§ã¯Botã®ææãè¦ã¤
æ©å¨æ¯ã§è¨å®ãèãæ¹ãéãå ´åãå¤ãNATè¨å®ã«ã¤ãã¦è¨è¼ãã¾ãã ä»åã¯PaloAltoã®ãã¡ã¤ã¢ã¦ã©ã¼ã«ãPAã·ãªã¼ãºã®ãå®å NATãã«ã¤ãã¦èª¬æãã¾ãã æ§æ ãµã¼ããå ¬éãããããå ´åã«ããããæ§æã§ãã ãµã¼ãAãã°ãã¼ãã«IPã¢ãã¬ã¹ãA.A.A.Aãã§å ¬éãã¦ãã¾ãã ãA.A.A.Aãå®ã®ãã©ãã£ãã¯ããµã¼ãAãB.B.B.Bãã®å®ã¢ãã¬ã¹ã«å®å å¤æãã¾ãã PaloAltoã®è¨å®ï¼NATå®ç¾©ï¼ ã¾ããNATããªã·ã¼ã®ååãå ¥åãã¾ãï¼â ï¼ãâ»æ大åè§31æåã¾ã§ 次ã«éä¿¡å ã¨å®å ã®ã¾ã¼ã³ãé¸æãã¾ãï¼â¡ï¼ãããã§ã¯å¤æåã®ã¾ã¼ã³ãé¸æãã¾ãã ã¤ã³ã¿ã¼ãããå´ããUntrustãã¾ã¼ã³ã®å ´åã¯ãéä¿¡å ãå®å å ±ã«ãUntrustãã«è¨å®ãã¾ãã éä¿¡å ã¢ãã¬ã¹ã¨å®å ã¢ãã¬ã¹ï¼â¢ï¼ãå¤æåã®ã¢ãã¬ã¹ãé¸æãã¾ãã ã¤ã³ã¿ã¼ãããå´ã®å ¨ã¦ã¼ã¶ããã®ãã©ãã£ãã¯ãå¤æ対象ã¨ããå ´
ã©ã³ãã³ã°
ãç¥ãã
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}