ããã«ã¡ã¯ðº
ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ã®å±±æ¬ã§ãã
社å ããã®æè¡åãåããã§ã解説ãã¦ãã¦ææç¾©ã ã£ããã®ããã£ãã®ã§ãããã°è¨äºã«ãã¾ãã
質å
AWS Network Firewall ã®ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ãã«ããã¦ããContinueãã鏿ããã±ã¼ã¹ã¯ããã§ããããã
åè
å
¬å¼ããã¥ã¡ã³ãï¼
ã¹ããªã¼ã ä¾å¤ããªã·ã¼
Stream exception policy in your firewall policy - AWS Network Firewall
2023/5 ã®ãã¥ã¼ã¹ï¼
AWS Network Firewall ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ã«ãããæå¦ã¢ã¯ã·ã§ã³ã®ãµãã¼ããéå§
AWS Network Firewall ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ã«ãããæå¦ã¢ã¯ã·ã§ã³ã®ãµãã¼ããéå§
TCP ã®ã¹ããªã¼ã éä¿¡ã¨åéå¶å¾¡ãã³ãã¯ã·ã§ã³
TCP ã¯ã³ãã¯ã·ã§ã³åã®ãããã³ã«ã§ãã
ã¯ã©ã¤ã¢ã³ãã®ããä¸ã¤ã®ãã¼ãã¨ããµã¼ãã¼ã®ããä¸ã¤ã®ãã¼ããçµã¿åããã¦ãã³ãã¯ã·ã§ã³ãä½ãã¾ãã
ã³ãã¯ã·ã§ã³ã®ä¸ã§ã¯ãã»ã°ã¡ã³ãåãããã¼ã¿ã®éåä¿¡ãè¡ãã¾ããã¹ããªã¼ã éä¿¡ã¨è¨ã£ãããã¾ãã䏿çãªãããã¯ã¼ã¯ã®åæãªã©ã§ããã¼ã¿ããã¹ãããéã¯ã¹ããªã¼ã å
ã§åéãè¡ãã¾ãã
åéã¯ä»¥ä¸ã®ããã«è¡ãã¾ãã
æåã®éä¿¡ï¼â¶ç¸æããã®å信確èªãåãåããªã
1 åç®ã®åéï¼æåã®éä¿¡ãã 1 ç§å¾â¶ç¸æããã®å信確èªãåãåããªã
2 åç®ã®åéï¼1 åç®ã®åéãã 2 ç§å¾â¶ç¸æããã®å信確èªãåãåããªã
3 åç®ã®åéï¼2 åç®ã®åéãã 4 ç§å¾â¶ç¸æããã®å信確èªãåãåããªã
ã»ã»ã»
n åç®ã®åéã§ç¸æããã®å信確èªãåãåããã°æ£å¸¸ã«åéã§ãã¦ãã¾ãã
ããããæå®åæ°ã«éããã¨ã¿ã¤ã ã¢ã¦ãã¨ãªãã¾ãã
åéã®ã¿ã¤ã ã¢ã¦ã㯠OS ãã¢ããªã±ã¼ã·ã§ã³æ¯ã«è¨å®ã§ãã¾ãã
ã¿ã¤ã ã¢ã¦ãããå ´åã«ã¯ã³ãã¯ã·ã§ã³ã¯åæããã¾ãã
ããä¸åº¦éä¿¡ãããå ´åã¯ãæ°ããã³ãã¯ã·ã§ã³ãä½ãã¾ãã
AWS Network Firewall ã® ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ã
AWS Network Firewall ã® ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ãã§ã¯ãã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãã¼ãTCPã³ãã¯ã·ã§ã³ãè²¼ã£ã¦ã¹ããªã¼ã éä¿¡ããã¦ããéã«ãä¸éã®ãããã¯ã¼ã¯ã§ä¸æçãªåæããã£ãéã®åä½ãå®ç¾©ãã¾ãã
ã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãã¼ã®éã§éä¿¡ãæ¤ç«ãã¦ãã Network Firewall ãããããã¯ã¼ã¯å
ã§ä¸æçãªåæããã£ãã¨ãã«ãå®è¡ä¸ã®ã¹ããªã¼ã éä¿¡ã«ã©ãé¢ä¸ãããã§ãã
AWS Network Firewall ã§ã¹ãã¼ããã«ã«ã¼ã«ãé©ç¨ãã¦ããéã«ã¯ãTCP ã¹ããªã¼ã ã®éä¿¡ã®æµãããã¡ã¤ã¢ã¼ã¦ã©ã¼ã«å
ã«ã³ã³ããã¹ãã¨ãã¦ä¿åãã¦ãã¾ããã³ã³ããã¹ããåç
§ãã¦ãã¹ããªã¼ã å
ã®åå¾ã®ã»ãã·ã§ã³æ
å ±ã確èªããæ¤é²ãããã±ãããæ£å¸¸ãªãã®ãå¤å®ãã¦ãã¾ãã
ãããã¯ã¼ã¯å
ã§ä¸æçãªåæããã£ãã¨ãã«ã¯ãAWS Network Firewall ãã³ã³ããã¹ãæ
å ±ã失ã£ã¦ããå¯è½æ§ãããã¾ããã³ã³ããã¹ãã失ãããã¨ãåæããã®å復æã«ã¹ããªã¼ã éä¿¡ãåéããå ´åã«ããæ£ããã«ã¼ã«ãé©ç¨ã§ããªããã¨ã«ãªãã¾ãã
ã¹ãã¼ããã«ã«ã¼ã«ãæ£ããåä½ãããã«ã¯ãã¹ããªã¼ã éä¿¡ããã¦ããã³ãã¯ã·ã§ã³èªä½ãã¯ãã¼ãºãã¦ãã¾ã£ã¦ãåæããã®å復æã«æ°ããã³ãã¯ã·ã§ã³ãä½ããããªãããã§ããæ°ããã³ãã¯ã·ã§ã³ãä½ã£ã¦ãæ°ããã³ã³ããã¹ããä¿æãããã¨ãããã¨ã§ãã
ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ãã¯ãDrop
ãReject
ãContinue
ããé¸ã³ã¾ãã
Drop
ã§ã¯ããããã¯ã¼ã¯å
ã§ä¸æçãªåæããã£ãã¨ãã«ãã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãã¼ã®éã§éä¿¡ãæ¤ç«ãã¦ãã Network Firewall ããã¹ããªã¼ã éä¿¡ã®ãã¼ã¿ããããããã¾ããããããããããã¨ã§ TCP ã®åéã失æãããã¿ã¤ã ã¢ã¦ãããã¾ãã
ã¿ã¤ã ã¢ã¦ãããå ´åã«ã¯ã³ãã¯ã·ã§ã³ã¯åæã¨ãªããããå¿
è¦ã«å¿ãã¦æ°è¦ã³ãã¯ã·ã§ã³ã使ããå¿
è¦ãããã¾ããæ°è¦ã³ãã¯ã·ã§ã³ã使ããéã«ã¯ãAWS Network Firewall ãã³ã³ããã¹ããå®å
¨ã«ä¿æã§ãããããæ£ããã«ã¼ã«ãé©ç¨ã§ããããã«ãªãã¾ããããã©ã«ãã¯ãã® Drop
ã§ãã
Reject
ãé¸ã¶å ´åã«ãããã¼ã¿ããããããã¾ããå ãã¦ãã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãã¼ã« TCP RESET ãéä¿¡ãã¾ããTCP RESET ãéä¿¡ããã¨ãéä¿¡ã¯ããã«åæãããããã drop ã¨ã¯ç°ãªãåéã¿ã¤ã ã¢ã¦ããå¾
ã¤å¿
è¦ã¯ãªããªãã¾ãããã ããTCP RESET ã¯å¼·å¶åæãªã®ã§ãã¢ããªã±ã¼ã·ã§ã³ã¨ãã¦ã¯æå³ããªãåä½ããããã¨ãããã¾ããã³ãã¯ã·ã§ã³ã¯åæã¨ãªããããå¿
è¦ã«å¿ãã¦æ°è¦ã³ãã¯ã·ã§ã³ã使ããå¿
è¦ãããã¾ããæ°è¦ã³ãã¯ã·ã§ã³ã使ããéã«ã¯ãAWS Network Firewall ãã³ã³ããã¹ããå®å
¨ã«ä¿æã§ãããããæ£ããã«ã¼ã«ãé©ç¨ã§ããããã«ãªãã¾ãã
Continue
ãé¸ã¶ã¨ãAWS Network Firewall ã¯é常ã¨åæ§ã«ãã¼ã¿ãå¦çãç¶ãã¾ããdrop ã¯ãããªãã®ã§ããããã¯ã¼ã¯ã®å復æã«ã¯åéå¦çãæåããå¯è½æ§ãããã¾ããããããAWS Network Firewall ãã³ã³ããã¹ãæ
å ±ã失ã£ã¦ããå¯è½æ§ãããã¾ããã³ã³ããã¹ãã失ãããã¨ãåæããã®å復æã«ã¹ããªã¼ã éä¿¡ãåéããå ´åã«ããæ£ããã«ã¼ã«ãé©ç¨ã§ããªããã¨ã«ãªãã¾ãã
å¾ãã¾ãã¦ãè¦ä»¶ã«å¿ãã¦Drop
ãReject
ãContinue
ããé¸ã¶ãã¨ã«ãªãã¾ãã
- ããããã¯ã¼ã¯ã®ä¸æçãªåæãèµ·ããéã«ã³ãã¯ã·ã§ã³ãåæã«ãªããã¨ã¯è¨±å®¹ãããã»ãã¥ãªãã£ãåªå
ã§ããããã¯ã¼ã¯ã®å復æã«ã¯ã¹ãã¼ããã«ã«ã¼ã«ã«ã¯å®ç§ãªã³ã³ããã¹ããæããã¦å¦çããããããâ¶
Drop
- ããããã¯ã¼ã¯ã®ä¸æçãªåæãèµ·ããéã«ã³ãã¯ã·ã§ã³ãåæã«ãªããã¨ã¯è¨±å®¹ãããã»ãã¥ãªãã£ãåªå
ã§ããããã¯ã¼ã¯ã®å復æã«ã¯ã¹ãã¼ããã«ã«ã¼ã«ã«ã¯å®ç§ãªã³ã³ããã¹ããæããã¦å¦çãããããã¿ã¤ã ã¢ã¦ãããªãããã³ãã¯ã·ã§ã³ãæ®ã£ã¦ãã¾ãã¢ããªã±ã¼ã·ã§ã³ããããNetwork Firewall ã§åæãããããâ¶
Reject
- ããããã¯ã¼ã¯ã®ä¸æçãªåæãèµ·ããéã«ã³ãã¯ã·ã§ã³ãåæã«ãªããã¨ã¯åé¡ã«ãªããåæå¾ã«ã³ãã¯ã·ã§ã³ãä½ãç´ãã®ã§ã¯å¦çãéã«åããªããå¯è½ãªéãåéå¦çãããããâ¶
Continue
ãã¼ã¿ãã¼ã¹ã®ã³ãã¯ã·ã§ã³ãã¼ãªã³ã°ããå ´åï¼ Keep alive ãåãã³ãã¯ã·ã§ã³ã使ãåãã¦å¹ççã«éä¿¡ããï¼ã¨ãããªãå ´åï¼ ã¢ããªããã®å¼ã³åºããã¨ã« DB æ¥ç¶ï¼åæï¼ã§èãã¦ã¿ãã¨åãããããããããã¾ããã
- ããããã¯ã¼ã¯ã®åææã«ã³ãã¯ã·ã§ã³ãã¼ãªã³ã°ãè²¼ãç´ãã®ã¯é常éç¨ãFirewall ã«æ£ããåä½ãã¦ã»ããããâ¶
drop
- ãã³ãã¯ã·ã§ã³ãã¼ãªã³ã°ã¯åæãã¡ããã¨è²¼ãç´ãå¿
è¦ããã£ã¦ãå¯è½ãªéãä¿æããããâ¶
Continue
ãè¦éã«å ¥ãã - ãã³ãã¯ã·ã§ã³ãã¼ãªã³ã°ã¯ãã¦ããªãããä¸åä¸åã® DB æ¥ç¶ã®ã¿ã¤ã ã¢ã¦ããçãè¨å®ã ãã
drop
ã§åé¡ãªãã - ããããã¯ã¼ã¯ã®åææã«ã³ãã¯ã·ã§ã³ãã¼ãªã³ã°ãåãã¦ãã¿ã¤ã ã¢ã¦ãã¾ã§ã«æéãããããNetwork Firewall ãã TCP RESET ã§åæããããã
Reject
ã
Drop
㨠Reject
㯠Network Firewall ã®ã¹ãã¼ããã«ã«ã¼ã«ã®ã³ã³ããã¹ãä¿æãéè¦è¦ãããã©ã¡ã¼ã¿ã§ãContinue
㯠Network Firewall ãããéä¿¡ã®æç¶æ§ãéè¦è¦ãããã©ã¡ã¼ã¿ã§ãã
AWS Network Firewall ã®ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ãã«ããã¦ããContinueãã鏿ããã±ã¼ã¹
è¦ä»¶ã¨ãã¦ã¯ä¸ã«æ¸ãã以ä¸ã«ãªãã¾ãã
ããããã¯ã¼ã¯ã®ä¸æçãªåæãèµ·ããéã«ã³ãã¯ã·ã§ã³ãåæã«ãªããã¨ã¯åé¡ã«ãªããåæå¾ã«ã³ãã¯ã·ã§ã³ãä½ãç´ãã®ã§ã¯å¦çãéã«åããªããå¯è½ãªéãåéå¦çããããã
æ³åã«ãªããã®ã®ä¾ã¨ãã¦ä»¥ä¸ã®ã·ããªãªãæãã¾ããï¼ AD ã®ã¬ããªã±ã¼ã·ã§ã³ã®åéå¦çãå®å ¨ã«çè§£ãã¦ããããã§ã¯ãªãã®ã¯ã許ããã ãããï¼
ã·ããªãªï¼ãAD ã®ãµã¤ãéã¬ããªã±ã¼ã·ã§ã³ã VPN ã®å¸¯åä¸è¶³ã§ä¸æåæããéã«ãAWS Network Firewall ãã¬ããªã±ã¼ã·ã§ã³å¦çã䏿ããã¦ãã¾ãã
Active Directory (AD) ãæ¡ç¨ãã¦ãã¦ãè¤æ°ã®ãµã¤ããããã¾ãããªãã¸ã§ã¯ãã®æ´æ°ãå¤ããã¬ããªã±ã¼ã·ã§ã³ã«ã¯ 2 æéãããã¾ãããã®ããããµã¤ãéã¬ããªã±ã¼ã·ã§ã³ã®ééã¯ããã©ã«ãã® 3 æéã®ã¾ã¾ã«ãã¦ãã¾ããã¿ã¤ã ã¢ã¦ã= 3æéã¨ãããã¨ã§ãã ãªã³ãã¬AD 㨠AWS ä¸ã® AD ã§ VPN åç·ãçµç±ãã¦ã¬ããªã±ã¼ã·ã§ã³ããã¦ãã¾ããVPN ã®éä¿¡ã AWS Network Firewall ã§æ¤é²ãã¦ãã¾ããVPN ã¯å¸¯åãååã§ãªãã夿°ã®ã¦ã¼ã¶ã¼ã®ä½¿ç¨ã«ãã£ã¦ã䏿çãªéä¿¡é害ã2-3 æéããã«çºçãã¦ãã¾ããAWS Network Firewall ã® ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ãã¯ããã©ã«ãã® drop
ã§ãã䏿çãªéä¿¡æã«ãããNetwork Firewall ã ã¬ããªã±ã¼ã·ã§ã³ã®ãã±ããã drop ããã¬ããªã±ã¼ã·ã§ã³å¦ç㯠3 æéå¾ã«ã¿ã¤ã ã¢ã¦ãã¨ãªãã¾ããã¬ããªã±ã¼ã·ã§ã³ã®å¤±æããå¾ã«ã¯ãæ°ãã AD ã«è¿½å ããã¦ã¼ã¶ã¼ããä»ã®ãµã¤ãã®ãµã¼ãã¼ã«ãã°ã¤ã³ã§ããªããã¨ãããã¾ããããã«ãããæ¥åä¸ã®æ¯éãåºã¾ããã¿ã¤ã ã¢ã¦ãããæéã«æ¬¡ã®ã¬ããªã±ã¼ã·ã§ã³ãåéãã¦ãããã®ã®ãæ´æ°ãªãã¸ã§ã¯ããå¤ãã1æéå¾ã«VPNã®ä¸æçãªéä¿¡æãçºçããã¬ããªã±ã¼ã·ã§ã³å¦çã¯æ¬¡ã® 3 æéå¾ã«ã¿ã¤ã ã¢ã¦ãã¨ãªãã¾ãã
ã¬ããªã±ã¼ã·ã§ã³ã失æããªããã¨ã®éè¦åº¦ãé«ããããAWS Network Firewall ã®ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ãã«ããã¦ãContinue
ã鏿ãã¾ããã
次ã®ã¬ããªã±ã¼ã·ã§ã³ããã¯ããããã¯ã¼ã¯ã®ä¸æçãªåææã«ããAD ã®ã¬ããªã±ã¼ã·ã§ã³å¦çã drop ããããå復æã«ã¯åéå¦çãç¶è¡ããç¡äºã«ã¬ããªã±ã¼ã·ã§ã³ãçµããã¾ããã
å¼å®³ã¨ãã¦ã¯ããããã¯ã¼ã¯ã®ä¸æçãªåææã«ãNetwork Firewall ã®ã¹ãã¼ããã«ã«ã¼ã«ãã³ã³ããã¹ããä¿æã§ããªããããæ¤é²ãä¸å®å
¨ã«ãªããã¨ã§ãã
ã¬ããªã±ã¼ã·ã§ã³ã失æãã¦ããã®ã¯ VPN ã®å¸¯åãååã§ãªããã¨ãªã®ã§ãå°ç¨ç·ãã帯åã®è¿½å ãæ¤è¨ãããã¨ã«ãã¾ããã
VPN ã®å¸¯åã確ä¿ã§ããéã«ã¯ãAWS Network Firewall ã®ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ãã drop
ã«æ»ããå®ç§ãªã³ã³ããã¹ãã§ã¹ãã¼ããã«ã«ã¼ã«ã§ã®æ¤é²ãè¡ãäºå®ã§ãã
çµããã
è£è¶³
æ¬è¨äºã§ã¯å³ãä¸åæ¸ããªãã£ãã®ã§ãTCP ã®ã¹ããªã¼ã éä¿¡ã«ã¤ãã¦ãã¤ã¡ã¼ã¸ãæã¡ã«ããã£ãããç¥ãã¾ããã
ãTCPã®åéå¶å¾¡ããªã©ã¨æ¤ç´¢ãã¦ãããã¾ãã¨ãã¤ã¡ã¼ã¸ãæã¦ããã¨æãã¾ãã
ç¡æã§è¦ããè³æã§ã¯ãé»åæ
å ±éä¿¡å¦ä¼ãç¥èã®æ£®ã
ã«ããè³æãåãããããã£ãã§ãã
1 ç« TCPï¼Transmission Control Protocolï¼ã®åºç¤
éè«
ååã¨å±±ç»ãã«è¡ã£ã¦ãã¾ããã
ãµã ãç¨ã«ãåçãè¼ãã¾ãã
æ¬æ æ¹ï¼å±±æ¢¨çï¼ã®æ¨ªã«ããç«ã¶å²³ã¨ããå±±ã§ãé²ããªããã°å¯å£«å±±ã綺éºã§ãã
é²ãããªããã°ã
å±±æ¬ å²ä¹ (è¨äºä¸è¦§)
ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ã®ã¤ã³ãã©ã¨ã³ã¸ãã¢ã
å±±ãèµ°ãã®ãè¶£å³ã§ãã