ãã¹ã¯ã¼ãä»ã ZIP ãã¡ã¤ã«ã®è©±
ãã¹ã¯ã¼ãä»ã ZIP ãã¡ã¤ã«ã®èå¼±æ§ããã¨ãã£ã話ãã話é¡ã«ãªã£ã¦ããããã§ãã
ã©ãããã
- é称: Traditional PKWARE Encryption ã®èå¼±æ§ã®è©±ãããã
- ãã¨ãã¨ãTraditional PKWARE Encryption ã¯ãå é¨ç¶æ ã® 96bit ãç·å½ããããã°è§£ãã¦ãã¾ããã®ã§ããããå®è³ªçãªéµé·ã«ãªãã
- 96bit ãããä»ã©ãã®æå·ã¨ãã¦ã¯ãå§åçã«çãã
- ã¨ãããã¨ã¯æããææããã¦ãããã©ãä»åã¯ãããããããã¹ã¯ã¼ããçæãããã¨ã«æåãããããã
ã®ããã§ãã
æå¤ã«ããã®ãå¤ãæå·åããç¥ããªã人ãå¤ãã¿ããã§ãããç§ã¯ãä¸è¨ãã¼ã¸ãèªãã ãã¨ããã£ãã®ã§ãæå·åã¢ã«ã´ãªãºã èªä½ããå¤èãã¦ã¤ã±ã¦ãªããã¨ããèªèã¯ããã¾ããã
æå·å ZIP æ¸åº« ã®è©ä¾¡ - EverQuestã§ããªãæ¥è¨
ãããæ¸ãããã®ã 11 å¹´åãç§èªèº«ããã®è¨äºãèªãã ç¥èãå ã«è¨åãã¦ããè¨äºãã2009 å¹´ã«æ¸ãã¦ãã¾ããã
åã«ãæ¸ãããã©... - JULYâs diary
ãããã 10 å¹´ãæªã ã«ããã¹ã¯ã¼ãä»ã ZIP ãã¡ã¤ã«ã使ãç¿æ £ã¯é§éããã¦ãã¾ããã
çµå±ããã¹ã¯ã¼ããã¡ã¼ã«ã§éããã ãããæå³ããªããã¨ããæèã§æ¹å¤ãããã®ã§ããããããããå¤ãæå·åæ¹å¼ã§ã®ãã¹ã¯ã¼ãä»ã ZIP ãã¡ã¤ã«ã¯ãä»®ã«ãã¹ã¯ã¼ãéç¨ããã¡ãã¨ãã£ã¦ãã¦ããæ¢ã«å¾©å·åããããããéæ¨å¥¨ã®å½¢å¼ã§ããã
Â
Office ç³»ã®ãã¡ã¤ã«ã PDF ãã¡ã¤ã«ãªã©ãããã¹ã¯ã¼ãä»ã ZIP ãã¡ã¤ã«ã«ãã人ãè¦ããã¾ãããZIP ã«ãã¦ãã¹ã¯ã¼ããä»ããããããªããOffice èªä½ã§ãã¹ã¯ã¼ãä»ãã«ããæ¹ãé¥ãã«ãã·ã§ããã£ã¡ã¯ããã¹ã¯ã¼ããããã¡ãã¨ãã¦ããã°å¾©å·åãããå¿é ã¯ãã»ã¨ãã©ããã¾ããããã¼ã¸ã§ã³ã«ãããã¾ãããæå·åã¯åºæ¬çã«ãAES ã使ã£ã¦ãã¾ãã
Â
ãã®ãã¹ã¯ã¼ãä»ã ZIP ãã¡ã¤ã«ã®åé¡ãWindows ã§ã® ZIP ãã¡ã¤ã«ã®æ±ããå½±ãè½ã¨ãã¦ãã¾ãã
Â
ZIP ãã¡ã¤ã«ã®æå·åæ¹å¼ã«é¢ãã¦ã¯ããã§ã« AES ã§æå·åãããªãã·ã§ã³ãåå¨ãã¾ããç¡æã§ä½¿ç¨ã§ããã½ããã¦ã§ã¢ã¨ãã¦ã¯ã7-zip ã«ããã®ãªãã·ã§ã³ãããã¾ãã
Â
å§ç¸®ã»è§£åã½ãã 7-Zip
Â
ã¨ããããWindows ã®å§ç¸®ãã©ã«ãã¨ãã¦ããã¹ã¯ã¼ãä»ã ZIP ãã¡ã¤ã«ãæ±ããã®ã¯ãå è¿°ã®ãTraditional PKWARE Encryptionãã ãã§ãã
Â
ãã¹ã¯ã¼ãä»ã ZIP ãã¡ã¤ã«ãæµéãã¦ããèæ¯ã«ã¯ã
- Windows ã®æ¨æºæ©è½ã§ä¸èº«ãåãåºããã
ã¨ããã®ãããã¾ãããã® Windows ã®æ¨æºæ©è½ã§ã¯ãAES ã§ã®æå·åããã ZIP ãã¡ã¤ã«ã¯æ±ããªãã
Â
Â
ã¾ãããã¨ãã¨ããã¹ã¯ã¼ãä»ããã¡ã¤ã«ãã¡ã¼ã«ã«æ·»ä»ãã¦éã£ã¦ãçµå±ãã¡ã¼ã«ã§ãã®ãã¹ã¯ã¼ããä¼ããï¼ãããããã¹ã¯ã¼ãèªä½ãåããããããã®ï¼ã¨ãããã¨èªä½ããæ°ä¼ããã«ãããããªãã®ã ããããã¾ãããããããè¨ã£ã¦ããã¨ããé¢ãããã¾ããã社å ã®ã¬ã¤ãã©ã¤ã³ã«ãæ·»ä»ãã¡ã¤ã«ãéãæã¯ããã¹ã¯ã¼ããè¨å®ãã ZIP ãã¡ã¤ã«ã«ãã¦...ãã¨æ¸ããã¦ããã±ã¼ã¹ãå¤ãã§ãããã
Â
ããã¦ãOffice ç³»ãã¡ã¤ã«ã¯ãZIP ãã¡ã¤ã«ã«ã¯ããã«ãOffice ã§ãã¹ã¯ã¼ããè¨å®ãããã¨ãã¦ããã°ããæ°ä¼ããããã¯ãã¡ãã£ã¨ã ãã¾ã¨ãã«ãªãã¨æãã¾ãã...
ãã¹ã¯ã¼ãé²å¾¡ã«å¯¾ãã風è©
å è¨äºã¯ãæééå®ã§ç¡æã§èªããè¨äºã ãããã¯ã¦ãã®ãã¼ã¸ã示ãã¦ããã
Â
Â
å è¨äºã®å 容ã¯ããã¹ã¯ã¼ããããã·ã¥åãã¦ãããã大ä¸å¤«ãã¨ããã®ã¯è¨ãããã ãã¨ããå 容ã§ãããã¯ããã£ã¨ããªã®ã ããå¾åã«ããã¦ãããã«å±éºãªã®ããç ½ãå 容ã«ãªã£ã¦ããã
Â
大éæã«è¨ãã°ããããã·ã¥åãã¦ããã¨ãã¦ãããã¹ã¯ã¼ããå¤æãããã¨ããããã¨ãããã¨ã主張ãã¦ããã®ã ããæ»æææ³ã¨é²è¡ææ³ããã¡ãã¨æ´çããã¦ããªãå°è±¡ã ã£ãã
Â
ãã¹ã¯ã¼ãã»ã¯ã©ããã³ã°ã®ææ³ã«ã¯ãä¸è¨ã®ãããªãã®ãããã
Â
éå¼ã
ããã·ã¥åãããå¤ãåã£ã¦ããããªãã©ã¤ã³ã»ã¯ã©ããã³ã°ãã®å ´åã«å¯è½ãªææ³ã§ãå¹³æã®ãã¹ã¯ã¼ãã¨ãããã·ã¥åå¾ã®å¤ã¨ã®çµã¿åããããã¼ã¿ãã¼ã¹åãããã®ãç¨æãããããæ¤ç´¢ãããã¨ã§å ã®ãã¹ã¯ã¼ãç¥ãæ¹æ³ã
æ®éã«ããã¨ããã®ãã¼ã¿ãã¼ã¹ãç°¡åã«å·¨å¤§ã«ãªã£ã¦ãã¾ãã®ã§ããã®ç®çã®ããã®å¹ççãªãã¼ã¿æ§é ã¨ãã¦ç»å ´ããã®ãããããããã¬ã¤ã³ãã¼ãã¼ãã«ãã
ãã®ææ³ã®ç¹å¾´ã¯ãä»ã®ææ³ã«æ¯ã¹ã¦å§åçã«çãæéã§ãã¹ã¯ã¼ããå¤æãããã¨ããã ãã
- ããã·ã¥åã®ã¢ã«ã´ãªãºã æ¯ã«ãã¼ã¿ãç¨æããå¿ è¦ãããã
- ã¬ã¤ã³ãã¼ãã¼ãã«ã§å®¹éãå°ããã§ãããã¨è¨ã£ã¦ãããã¹ã¯ã¼ãã1æåå¢ããã°ãç¨æãã¹ããã¼ã¿ã¯ï¼æ¡ããã大ãããªãã®ã§ãé·ããã¹ã¯ã¼ãã«å¯¾å¿ãããã¨ããã¨ãå¿ è¦ãªãªã½ã¼ã¹ãç°¡åã«å¤§ãããªã£ã¦ãã¾ãã
ã¨ããã®ãå¼±ç¹ã
è¾æ¸æ»æ
人éãã¤ããããªãã¹ã¯ã¼ãæååãæºåã»çæãããã®æååã«å¯¾ãã¦ããã·ã¥åã®è¨ç®ãããããå®éã«å¯¾è±¡ã·ã¹ãã ã«éä¿¡ããã
ãããããèå¼±ãªãã¹ã¯ã¼ããã¯é«ç¢ºçã§å ã®ãã¹ã¯ã¼ããçºè¦ãããã¨ãã§ããããæ¬æ°ã§ã©ã³ãã ãªé·ããã¹ã¯ã¼ãã¯ããããã試è¡ãããªããã¨ã«ãªãã®ã§ãçºè¦ããããã¨ã¯ãåºæ¬çã«ã¯ç¡ãã
ã©ã®ãããã®ç¢ºçã§ãã¹ã¯ã¼ããå¤æãããã¯ãè¾æ¸ãã©ãã ãè±å¯ãªã®ããã¨ãããã¨ã«ãªãããæè¿ã¯ããã§ã«æ¼æ´©ããã¦ããã¢ã«ã¦ã³ãæ å ±ãåºãæµéãã¦ãããã¨ãèããã¨ã人éãã¤ãããããã ããããªããä¸åº¦ã誰ããè¨å®ãããã¹ã¯ã¼ãã«åè´ãã¨ããã±ã¼ã¹ããããããããªãã
ç·å½ããæ»æ
ãã®ä¸ã®ãã¹ã¦ã®æååã試ããã¨ãããã®ãåççã«ã¯ãã©ããªãã¹ã¯ã¼ãã§ãçºè¦ã§ãããããã¹ã¯ã¼ãé·ãã¡ãã£ã¨é·ããªãã¨ããã£ã¨ããéã«ãã®æ»æã¯ç ´ç¶»ãããASCII å³å½¢æåã¨åè§ã¹ãã¼ã¹åãã㦠95 種ã®æåã使ããã¨ããããn æåã®ãã¹ã¯ã¼ã㯠95néãã¨ãªããå®éã«è¨ç®ãã¦è¦ãã°åãããã10 æåã§ã 59,873,693,923,837,890,625 éãã«éããã1æåå¢ããã°ã95 åã«ãªãã
ä¸ä¸ã風é¡ãã Ophcrack ããåºæ¬çã«ã¯ã¬ã¤ã³ãã¼ãã¼ãã«ã使ããã4æåã¾ã§ã¯ ASCII æåã®ç·å½ãããè¡ãã
Â
ãªãã©ã¤ã³ã»ã¯ã©ããã³ã°ã«å¯¾ãã¦ãé²å¾¡æ¹æ³ã¨ãã¦ã½ã«ãã¨ã¹ãã¬ããã³ã°ãããããã½ã«ãã¯ä¸è¨ã®æ»æã®ãã¡ãéå¼ãã«å¯¾æãããã®ã§ãããè¾æ¸æ»æãç·å½ããæ»æã«ã¯å¹æã¯ãªããéã«ãã¹ãã¬ããã³ã°ã¯ãã¹ãã¬ããã³ã°ã®åæ°ãã¢ã«ã´ãªãºã ãåãã£ã¦ããå ´åãéå¼ãã«ã¯å¹æã¯ç¡ã*1
- ã½ã«ã ... éå¼ã対ç
- ã¹ãã¬ããã³ã° ... è¾æ¸æ»æãç·å½ããæ»æã«å¯¾ãã対ç
 ãªã®ã§ãã½ã«ãä»ãã§ã¹ãã¬ãã³ã°æ¸ã¿ã§ããã°ãç°¡åã«å ã®ãã¹ã¯ã¼ããå¤æãããã¨ã¯ãªãã®ã ããå è¨äºã§ã
ãã 両æ¹ã®å·¥å¤«ãé©ç¨ãã¦ãã解æã«æéããããããã«ãªãã ãã ã解æã§ããªããªãããã§ã¯ãªãã
ã¨æ¸ãããã
ãã®æç« ã ã¨ã¾ãã§ãã½ã«ãä»ãã¹ãã¬ããã³ã°ãæ°ä¼ãã®ããã«èªãã¦ãã¾ãããå®éã¯ãããªãã¨ã¯ãªãããã¡ãã¨ã½ã«ããã¤ãã¦ããã°éå¼ãã¯å®è³ªçã«ä¸å¯è½ã ããã¹ãã¬ããã³ã°ããã¦ããã°ãä»®ã«ã1æéã§å¤æãããã¹ã¯ã¼ããã1,000 åã®ã¹ãã¬ããã³ã°ã§ 42 æ¥å¾ã«ãªãããã¹ã¯ã¼ããå¤æ´ãã¦æ¼æ´©ã®è¢«å®³ãåé¿ããæéãä½ããã¨ãã§ãã*2ã
 å è¨äºã§èªåãä¸çªæ°ã«ãªã£ãã®ã¯ãä¸è¨ã®æç« ã«ç¶ãã¦ããæ¸ããã¦ãããã¨ã ã£ãã
ä¾ãã°ãæ¼æ´©ãã¼ã¿ã®æ¤ç´¢ãµã¼ãã¹ãæä¾ãã¦ããLeakedSourceã2016å¹´9æãã½ã«ããæ¡ç¨ãã¦ãããµã¼ãã¹ããæ¼æ´©ãã4350ä¸ä»¶ä»¥ä¸ã®ã¢ã«ã¦ã³ãæ å ±ã2æéã§96ï¼ è§£æããã¨ãã¦ããã
ã½ã«ãä»ãã®ãã¹ã¯ã¼ã㧠4000 ä¸ä»¶ä»¥ä¸ã®ãã¹ã¯ã¼ãã 2 æéã§å¤æãã¨ããäºã«å¼·çãªéåæãæãããã½ã«ãä»ãã§ããã°ã
- ã½ã«ããã¢ã«ã¦ã³ãã«ãããåºå®
- ãã®åºå®ã®ã½ã«ããä»ãã¦ããã±ã¼ã¹ã®ãã¼ãã«ãæ´åæ¸ã¿
ãããªãã¨ã2æé㧠4000 ä¸ä»¶ãæ¯ç§ 5,500 件以ä¸ã®ã¨ããã®ã¯ãã¯ã©ã¦ãã®ãããã§è¨ç®ãªã½ã¼ã¹ã®èª¿éã容æã«ãªã£ããæä¸ã§ããç¾å®çãªæ°åã¨ã¯æããªãã
Â
è¨äºä¸ã«ã¯ããã® LeakedSource ã®è©±ã®ã½ã¼ã¹ã示ããã¦ããªãããããããããã§ã¯ãªãããã¨ãããã¼ã¸ãè¦ã¤ããã
ãããæ£ããã¨ããã¨ã
- å è¨äºã§ 2016 å¹´ 9 æã¨æ¸ãã¦ããããä¸è¨ãã¼ã¸ãæ¸ãããã®ã 2016 å¹´ 9 æã§ãã£ã¦ã話ã®å 容㯠2012 å¹´ 3 æã
- ã4350 ä¸ä»¶ãã96%ãã2æéãã¨è¨ã£ã¦ããã®ã¯ãLast.fm ããæ¼æ´©ãããã®ã
- ãPasswords were stored using unsalted MD5 hashing.ãã¨æ¸ãã¦ãããããã½ã«ããªãã® MD5 ããã·ã¥å¤ã
- å¾ããããã¹ã¯ã¼ããè¦ããããªãã¨å®æãªãã¹ã¯ã¼ãã®å¤ããã¨ã
ã¨ãã話ã«ãªãã
å®æãªãã¹ã¯ã¼ããå¤ãã¦ãã½ã«ããªãã® MD5ãªã*3ãæ®éã«ã¬ã¤ã³ãã¼ãã¼ãã«ã§çæéã«ãã¹ã¯ã¼ããè¦ã¤ããã®ã¯å½ç¶ã§ããã
å è¨äºã§ã¯ãã½ã«ããæ¡ç¨ãã¦ãããã¨æ¸ããã¦ããããç§ãè¦ã¤ãããã¼ã¸ãæ£ããã¨ããã°ã大ããªäºå®èª¤èªã¨ãããã¨ã«ãªããæ ã«ããã®è©±ããã£ã¦ãã½ã«ãä»ãã¹ãã¬ããã³ã°ã¯æ°ä¼ããã¨é¢¨æ½®ããã®ã¯ééãã¨è¨ããããå¾ãªãã
Â
ã¡ãã£ã¨è©±ã¯å¤ãããããã®ä»¶ã®ãã¯ãã³ã¡ã³ãã§ã徳丸ããã
BCryptã§ãArgon2ã§ãé常Saltã¯ããã·ã¥å¤ã¨ã¨ãã«ä¿åããã®ã§è¾æ¸æ»æã«ã¯å¯¾æã§ããªãã§ããã
ã¨æ¸ããã¦ãããè¾æ¸æ»æã§å¤æãã¦ãã¾ããã¹ã¯ã¼ãã¯ãã©ããªå½¢å¼ä¿åãã¦ãè¦ã¤ãããã¦ãã¾ããèå¼±ãªãã¹ã¯ã¼ãã«å¯¾ãã¦ã¯ãã½ã«ããã¹ãã¬ããã³ã°ãæ°ä¼ãè¨ããããå¾ãªãã
ã·ã¹ãã å´ãé å¼µã£ãã¨ããã§ãèå¼±ãªãã¹ã¯ã¼ããä»ããã¦ã¼ã¶ãå®ããã¨ã¯ã§ããªããä¿åå½¢å¼ãé©åã«ä¿ã¦ã°ããã¡ãã¨ããã¦ã¼ã¶ãå®ããã¨ã¯ã§ããã
Â
ã¨ãããã¨ã§ãçããã
- ååã«é·ããã¹ã¯ã¼ãã§
- 使ãåããããªã
ã¨ããååãå®ãã¾ãããã
*1:ãããåãã¹ãã¬ããã³ã°åæ°ã¨ã¢ã«ã´ãªãºã ã®ã¬ã¤ã³ãã¼ãã¼ãã«ãç¡ããªãããããä½ããªããã°ãããªãããã¹ãã¬ããã³ã°ãã¦ããã°ãã¼ãã«ä½æã«æéãããããã¨ããå¹æã¯ããã
*2:éã«ãæ¼æ´©ãããã¨ãã©ãã ãè¿ éã«æ¤ç¥ã§ãããããéè¦ã«ãªã£ã¦ãã
*3:ãMD5ãªããã¨ããã®ã¯ãMD5 ã®è¡çªèæ§ã®åé¡ã§ã¯ãªãããããé·ãæ¯è¼ççããã¡ã¸ã£ã¼ãªããã·ã¥é¢æ°ã ããããã§ã«ã¬ã¤ã³ãã¼ãã¼ãã«ãå å®ãã¦ãããã¨ããçç±ãä»»æã®ããã·ã¥å¤ã«å¯¾ãã¦ããã®ããã·ã¥å¤ãæã¤ãããåãæ±ããã®ã¯ãMD5 ã§ããããã¾ã§å®¹æã§ã¯ãªããMD5 ã使ããªãã®ã¯ãããã·ã¥å¤ã¯ä½ã§ãè¯ããããåãããã·ã¥å¤ãæã¤ã¦ãã¼ã¯ãªãããåãè¦ã¤ãããã¨ããå¼·è¡çªèæ§ã®åé¡ã
Path MTU Discovery ãåå ã®éä¿¡é害ã¯åãã¥ãã
æ®éãä½ããã®éä¿¡é害ãçºçããã¨ãå½ç¶ãéä¿¡ã®å½äºè ã«é¢ããäºã調ã¹åºãã¾ãã
ãµã¼ãå´ã«ä½ããã°ã¯åºã¦ããªããããã±ãããã£ããã£ããã¦ç¸æããã©ããªãã±ãããå±ãã¦ããã®ããFirewall çã§å½è©²ãã¹ãã«é¢ããã«ã¼ã«ãå¼ã£ããã£ã¦ããªãã....
ã¨ããããPath MTU Discovery ã«èµ·å ããåé¡ãçºçããã¨ãéä¿¡ã®å½äºè ã§ã¯ãä¸è¦ãç¸æãæªãããã«è¦ããããå®éãåå ãå½äºè ã¨ã¯ç¡é¢ä¿ã®ããã«è¦ããã¨ããã«ããã¾ãã
éä¿¡é害ã®æçµæ段ã¨ãã¦ç»å ´*1ãããã±ãããã£ããã£ããã¦ããåã«ãç¸æããã®ãã±ãããå±ããªãã ãã«è¦ãã¾ãã
ãããããPath MTU Discovery ã¨ã¯ï¼
ã¾ããMTU
ãã¬ãã網ãåºå§ããé ããããã¯ã¼ã¯ã¹ãã¼ãã®æ¹åæ¹æ³ã¨ã㦠MTU ã®ãµã¤ãºã調æ´ãã話ã§æåã«ãªã£ã MTU ã§ãããMaximum Transmission Unit ã®ç¥ã§ãï¼ã¤ã®ãã¬ã¼ã ã§éä¿¡ã§ããæ大ãµã¤ãºã®äºãè¨ãã¾ãã
å ã ãMTU èªä½ã¯åç·ã®ç¨®å¥ã«ãã£ã¦æ±ºã¾ããã®ã§ãä¸è¬ç㪠Ethernet ã§ã¯ 1500 ãã¤ãã§ãWAN åç·ã§ä½¿ããã PPP ã®å ´åã¯å¯å¤ã§ãããEthernet ã¨åã 1500 ãã¤ãã«ãªãäºãå¤ãããã§ããä»ã¯ã»ã¨ãã©è¦ãããªã FDDI ã§ã¯ 4352ãIP over ATM 㧠9180 ãã¤ããã¨ãã£ãå ·åã«ãæ¬æ¥ã¯æ§ã 㪠MTU ãæã¤åç·ãããã¾ãã
ãã¬ãã網ãç»å ´ããã¨ãã« MTU ã話é¡ã«ãªã£ãã®ã¯ãPPPoE ã¨ããã«ãã»ã«åæè¡ã使ã£ãããã§ã1500 ãã¤ãã® Ethernet ãã¬ã¼ã ã®ä¸ã«ãã¦ã¼ã¶å´ã®ç«¯æ«ã¨å¥ç´å ã® ISP ãã¤ãªãçºã® PPP ãå ¥ããããã«ãã®ä¸ã« IP ãå ¥ãããã¨ããä»çµã¿ã§ãã
ãã®ãããé常㮠Ehternet ã«æ¯ã¹ã¦ PPP ã®åã ããå ¥ãããã IP ã®ãµã¤ãºã¯å°ãããªãã¾ãã
Path MTU ã¨ã¯
ãPathãã¯ãçµè·¯ããæå³ãã¾ããç¸æã«ãã±ãããå±ãã¾ã§ãããã¤ãã®ã«ã¼ã¿ã渡ã£ã¦ããã¾ããããã®éã®åç·ãã©ããªç©ã使ããã¦ãããåãã¾ããã
ããç¸æã¨éä¿¡ããæã«ããã®çµè·¯å ¨ä½ã§ã® MTU ã Path MTU ã§ãã
ã¤ã¾ããçµè·¯å ¨ä½ã§ãæãå°ãã MTU ã Path MTU ã§ãã
Path MTU Discovery ã¯ãçµè·¯å ¨ä½ã§æãå°ãã MTU ãã©ããã£ããåããï¼ ã¨ããä»çµã¿ã§ãã
ã«ã¼ã¿ã«ãããã±ããã®åå²
ã«ã¼ã¿ãåãåã£ããã±ããã転éããéã転éå ã¨ãªãåç·ã® MTU ãåãåã£ããµã¤ãºããå°ããã£ãå ´åããã±ãããåå²ãã¦éããã¨ãããã¾ãã
ããããã°ãéä¿¡å½äºè ã¯çµè·¯ä¸ã® MTU ãªã©æèãããã¨ãªãããã±ãããéä¿¡ã§ãã¾ããããã®ä»£ãããã«ã¼ã¿ã«åã£ã¦ã¯è² æ ã«ãªãã¾ãã
Path MTU Discovery ã® RFC 1191 ãåºãããã®ã¯ 1990 å¹´ã§ããã1990 年代ã«å ¥ã£ã¦ãããISP ã®ã«ã¼ã¿ã®ãããªãå¤ãã®ãããã¯ã¼ã¯ã¨ã¤ãªãã£ã¦ã大éã®ãã±ãããè£ãã«ã¼ã¿ã«ãããè² è·ãåé¡ã«ãªã£ã¦ãã¾ããã
ææçã«æ¬¡æ IPï¼å¾ã® IPv6ï¼ã®çå®ãè¡ããã¦ãã¦ã次æ IP ã®ãã¼ãã®ä¸ã¤ã«ããã®ã«ã¼ã¿ã®è² è·åé¡ãããã¾ããã
çµè·¯ä¸ã® MTU ãåã£ã¦ãã¾ãã°ãæåã£ããããã«åããããµã¤ãºã§ãã±ãããéãåºããã¨ã«ãªãã®ã§ãã«ã¼ã¿ã§ã®åå²ã¯çºçãã¾ããã
ãã®ãããIPv6 ã§ã¯ Path MTU Discovery ã使ãããäºãåæã«ãªãã¾ããã
Path MTU Discovery ã®ä»çµã¿
ãã¨ãã¨ãIP ãã±ããã«ã¯ DFï¼Don't Fragmentï¼ãã©ã°ã¨ãããã©ã°ãããããã®ãã©ã°ãã»ããããã¦ãããã±ããã¯ãã«ã¼ã¿ã«ããåå²ããã¦ã¯ãªããªããã¨ãããã¨ã«ãªã£ã¦ãã¾ãã
ã«ã¼ã¿ãããå°ãã MTU ãæã¤åç·ã使ã£ã¦ãã±ããã転éãããã¨ããæã«ããåå²ã§ããªããã¨ããäºã¯ããã以ä¸ããã±ããã転éããäºãã§ããªããã¨ããäºãæå³ãã¾ãã
ãããã£ãäºæ ãçºçãã¦ãããã¨ãããã±ããã®éä¿¡å ã«ä¼ããããã« ICMP ã使ããã¾ãã
Type 3ï¼Destination Unreachable Messageï¼ã® Code 4ï¼fragmentation needed and DF setï¼ã¨ãã ICMP ãã«ã¼ã¿ããéä¿¡å ã«éããããã®ä¸ã«ãâââãã¤ãã ã£ãã転éã§ãããã ãã©...ãã¨ããæ å ±ãå ¥ã£ã¦ãã¾ãã
éä¿¡å ããããåãåã£ããããã®ãµã¤ãºã«åãã㦠IP ãã±ãããåéãã¾ãã
æçµçã«ç¸æã«ãã±ãããå±ãã¾ã§ãICMP ã®æ å ±ã«åããã¦å°ãããã¦ããã°ãçµè·¯ä¸ã®æå° MTU ãè¦ã¤ãããã¨ããä»çµã¿ã§ãã
ICMP ããã£ã«ã¿ããã㨠Path MTU Discovery ãæç«ããªã
Path MTU Discovery ã¯ããã±ãããåå²ã§ããªãã¨ãã«ã«ã¼ã¿ãè¿ã ICMP ãå©ç¨ãã¦å®ç¾ãã¦ãã¾ããã¨ãããã¨ã¯ããã ICMP ããã£ã«ã¿ããã¦ãã*2ã¨ã
- ã«ã¼ã¿ã¯ãã以ä¸è»¢éã§ããªããããåãåã£ããã±ãããæ¨ã¦ã¦ ICMP ãè¿ãã
- éä¿¡å ããè¦ãã¨ãéã£ããã±ããã«å¯¾ãã¦ãç¸æããä¸åå¿çããªãç¶æ ã
ã¨ãããã¨ã«ãªãã¾ãã
IPv6 ã§ã¯ Path MTU Discovery ã使ãããã®ã§ãICMP ããããµãªã¨ Firewall çã§è½ã¨ãã¦ãã¾ãã¨ãéä¿¡ã§ããªãäºæ ãçºçããå¯è½æ§ãããã¾ãããã®ããããããã RFC ã§ãICMPv6 ã®ãã£ã«ã¿ãªã³ã°ã«é¢ããæç« ãåºããã¦ãã¾ãã
RFC 4890: Recommendations for Filtering ICMPv6 Messages in Firewalls
èããªãã«ã¾ããã¨ãã£ã«ã¿ãªã³ã°ããã¦ã¯ããã¾ããã
å®ã¯ IPv4 ã§ãåããã¨ã...
IPv6 ã®è©±ã ã¨æã£ã¦ãããããªã®ä½¿ã£ã¦ããªãããã¨æã£ã¦ããã¨è½ã¨ãç©´ãããã¾ããPath MTU Discovery èªä½ã¯ IPv4 ã§ã使ããä»çµã¿ãªã®ã§ãåççã«ã¯åããã¨ãçºçããããã¨ã«ãªãã¾ãã
å®ã¯ãå²ã¨ä»¥åãã Linux ã§ã¯ IPv4 ã§ã Path MTU Discovery ãæå¹ã«ãªã£ã¦ãã¦ããã®ãã¨ã«ç§ãæ°ãã¤ããã®ã¯ï¼å¹´ã»ã©åã® CentOS Ver.6 ç³»ã§ãããCentOS ä¸ã§ Squid ãåããã HTTP Proxy ãçµç±ããã¨ãç¹ãã£ããç¹ãããªãã£ãããã¿ãããªãã¨ããã£ã¦ããã®ã¨ãã«ãã±ãããã£ããã£ãã㦠DF ãã©ã°ãç«ã£ã¦ãããã¨ã«æ°ãä»ãã¾ããã
Linux 㧠IPv4 ã® Path MTU Discovery ãæå¹ã«ãªã£ã¦ããã㯠sysctl ã³ãã³ãã§åãã¾ãã
$ sysctl net.ipv4.ip_no_pmtu_disc
net.ipv4.ip_no_pmtu_disc = 0
ã¡ãã£ã¨åãã¥ããã§ãããip_no_pmtu_disc ãªã®ã§ãå¤ã 0 ãªãæå¹ã§ãã
Linux 㧠IPv4 ã® Path MTU Discovery ãæå¹ã¨ãããã¨ã¯...
ä»ã Linux ã¯ãµã¼ã以å¤ã«ããããããªã¨ããã§ä½¿ããã¦ãã¾ããã¨ããäºã¯ãæ確ã«ãLinuxãã¨èªèãã¦ããªããã®ã§ããPath MTU Discovery ãæå¹ã«ãªã£ã¦ãããã¨ãããã¨ã«ãªãã¾ãããããã¯ã¼ã¯æ©å¨ã IoT ããã¤ã¹ã«ã Linux ã¯ä½¿ããã¦ãã¾ãã
ç§ãå®éã«çµé¨ããã®ã¯ãAWS ã®ãã¼ããã©ã³ãµã§ãã ELB ã§ãã
ELB ã«å¯¾ããæ¥ç¶ã VPN çµç±ã 㨠NGãã¨ããäºããã£ãã®ã§ããããELB ã®å®ä½ã£ã¦ãAmazon Linux ã®ã¤ã³ã¹ã¿ã³ã¹ã¨ããããªãããªããã¨æã£ã¦ãICMP ããããã¯ãã¦ãã Network ACL ã®è¨å®ãå¤æ´ããã解æ¶ãããã¨ããäºãããã¾ããã
IPv6 ã«éãã IPv4 ã«é¢ãã¦ããããããã«ãICMP ã丸ãã¨ãããã¯ããããã¹ãã§ã¯ããã¾ããã
Ping of Death*3 ã Smurf æ»æ*4ã¯ãæ£ç´ãéå»ã®ç©ã§ããICMP ã«å¯¾ãã¦é大ãªææå¿ãæããããã£ã«ã¿ãããªã ICMP ã®ãä¸èº«ããæèããããã®ã§ãã
*1:å人çã«ã¯ãã¬ã¤ã¤ã¼ 3 以ä¸ãåå ã«ãªããããªçç¶ã§ãå½äºè ã Linux ã ã£ãããæåã£ãã tcpdump ã®ç»å ´ããã¾ããã
*2:Firewall 製åã ã¨ãæå³çã«ãããã¯ããªãéãã許å¯ãã¦ããéä¿¡ã«å¯¾ãã¦çºçãã ICMP ã¯é©åã«è»¢éãã¦ãããäºãå¤ãã§ããL3 ã¹ã¤ããã® ACL ã®ããã«ãã¹ãã¼ãã¬ã¹ã«ãã±ãããå¤æããå ´åããã£ã«ã¿ããã¦ãã¾ããã¡ã§ãã
*3:Windows 95 ãç»å ´ããé ãUNIX ç³» OS ããµã¤ãºã®å¤§ãã ICMP Echo Request ãéãã¤ããããã¨ãã«ã¼ãã«ãããã¯ã«é¥ãæ¬ é¥ããã£ãã
*4:å®å ãããã¼ããã£ã¹ãã¢ãã¬ã¹ã¨ãªã£ã¦ãã ICMP Echo Request ã«å¯¾ãã¦ã該å½ãããã¹ããå¿çããåä½å©ç¨ããéä¿¡å ã¢ãã¬ã¹ãæ»æ対象ã®ã¢ãã¬ã¹ã«å½è£ ãã¦ãã±ãããéãã¤ããã¨ããã®ä½åãã®ãã±ãããæ»æ対象ã«åãããã¨ãã DDoS æ»æã®ä¸ç¨®
ããã ã½ã 22
ä»åã¯ãç«å½é¤¨å¤§å¦ã®ä¸åå²å¤ªéå çã«ããããã¤ãã³ãã¼ã®ã話ã§ããã
ãã¤ãã³ãã¼ã®è©±ã¨ãªãã¨ã
- ãã¤ãã³ãã¼ã管çããã¯ãã«ãªã£ãä¼æ¥åãã®è©±ã
- ãã©ã¤ãã·ã¼ã«é¢ãããã¤ãã³ãã¼å¶åº¦ã®åé¡ã
ã¨ãã£ãï¼ã¤ã®ãã¿ã¼ã³ã®ãå¤ãã¨æãã¾ããããã¡ããä¸è¨ã®ç¹ãå«ããé常ã«åºç¯å²ã®è©±ãèããã¨ãåºæ¥ã¾ããã
Slideshare ã§ä»æ¥ã®è³æãå ¬éããã¦ãã¾ãã
詳細ã¯ä¸è¨ã®è³æã«è²ãã¨ãã¦ãå°è±¡ã«æ®ã£ã話ãå°ãæ¸ãã¾ãã
ãå½æ°ç·èçªå·å¶ãã¯ãã§ã«å®æ½æ¸ã¿
å³å¯ã«è¨ãã¨ãä½åºãããã«åå ããªãã£ãä¸ã¤ã®èªæ²»ä½ãé¤ãã°ãã§ãããä½æ°ç¥¨ãããã°ãä½åºãããã§ä½¿ããã¦ããä½æ°ç¥¨ã³ã¼ããä»ä¸ããã¦ããã®ã§ããå½æ°ç·èçªå·å¶ãã¨ããæå³ã§ã¯ããã¤ãã³ãã¼ã§å°å ¥ããããã®ã§ã¯ãªãã§ãã
è¨ããã¦ã¿ãã°ãããã ããªããã¨ãã話ãªã®ã§ãããéã«ãä½åºãããããã¾ãæ´»ç¨åºæ¥ãªãã£ããã¨ã示åãã¦ããæãããã¾ãã
ãã§ãã¯ãã¸ãããããµã
ãã¤ãã³ãã¼ã®æå¾ã®æ°åã¯ãã§ãã¯ãã¸ãããªã®ã§ãããè¨ç®å¼ã§å¾ãããè¨ç®çµæ㯠1 ã 11 ã®æ´æ°ããã§ãã¯ãã¸ããã¯ä¸æ¡ã®æ°åãã§ãã©ããã¦ãããã¨ããã¨ã
ãè¨ç®çµæã 10 以ä¸ã®æ㯠0ã
ã ããã§ããã¤ã¾ããæ«å°¾ã 0 ã®äººã¯ãä»ã®æ°åã«æ¯ã¹ã¦ï¼åã®ç¢ºçã§åå¨ãããã¨ã«ãªãã¾ãã
ã¡ãªã¿ã«ããã®è¨ç®å¼ã¯å®å ±ã«ãè¼ã£ã¦ãã¦ãã§ãå®å ±ã¯ç¸¦æ¸ããã¨ãããã¨ã§ãè¨ç®å¼ãã©ãæ¸ããã¦ããã®ããæ°ã«ãªã人ã¯ãã§ãã¯ãã¦ã¿ã¾ããã*1ã
ã·ã¹ãã ã®ä»çµã¿ã¯çµæ§è¤é
Slideshare è³æã«ãããã¾ãããåç´ã«ä¸å¤®ã®ãã¼ã¿ãã¼ã¹ããã£ã¦ãããã«ã¢ã¯ã»ã¹ãããããªä»çµã¿ã§ã¯ãªããåºæ¬çã«ã¯ãåèªæ²»ä½ãçµç¹ãã¨ã«ãã¼ã¿ãã¼ã¹ããã£ã¦ãä¸å¤®ã§ã¯å¿ è¦ã«å¿ãã¦ã²ãä»ãããããããªä»çµã¿ã ããã§ãã
ãªã®ã§ããã¤ãã³ãã¼ã®ã·ã¹ãã ã«ãã£ã¦ãç¾ç¶ã®ä½åºãããããã»ãã¥ãªãã£ãªã¹ã¯ãç¹ã«é«ããªããããªãã¨ã¯ãªãæãã§ãã
ãã¤ãã³ãã¼ã«ãããã©ãã·ã¼åé¡ã®æ¬è³ªã¯ãåå¯ãã³ã¹ãã®æ¸å°ã
å人æ å ±ã®æ¼æ´©ãã¨ãããã¨ããã¥ã¼ã¹ã§å¤§ããåãæ±ããããæä¸ã§ãããæ¬å½ã«åé¡ãªã®ã¯ãå種ã®ãã©ã¤ãã·ã¼æ å ±ããåå¯ããããããã¨ã«ãã£ã¦ãèã¥ãå¼ã«å人é¢ããæ å ±ãåå¾ã§ãã¦ãã¾ããã¨ã§ããã¤ãã³ãã¼ã¯ããã®ãåå¯ããã®ã³ã¹ããåçã«ä¸ããå¹æãããã¾ãã
æ ã«ããã¤ãã³ãã¼ã®æ°éå©ç¨ã«é¢ãã¦ã¯æ éã«ãªãå¿ è¦ããããæ°éã使ãããã¨è¨ã£ã¦ãããç®çãã«å¯¾ãã¦ã¯ããã§ãã¬ã¼ã·ã§ã³ã®ãããªå¥ã®ãæ段ããé©å½ã§ã¯ãªãããã¨ãã£ãã話ãããã¾ããã
ãã¤ãã³ãã¼ã¯ãã¢ã«ã¦ã³ãã
ãã¤ãã³ãã¼ã¯ããã¾ã§ãèå¥ãããããã®çªå·ã§ãã£ã¦ããèªè¨¼ãã«å©ç¨ãããã®ã§ã¯ãªããããã°ãã¢ã«ã¦ã³ããã®ãããªãã®ãã¨ãã説æã¯åãããããã£ãã§ããã¢ã«ã¦ã³ãã ãã§ã¯æ¬äººãã©ããã¯å¤æã§ããªãã®ã¨åæ§ã«ããã¤ãã³ãã¼ã®çªå·ã ãã§æ¬äººæ§ã確èªã§ããããã¯ãªããã¨ãããã¨ã«ãªãã¾ãã
å ¨ä½çã«ãã¡ãã£ã¢ãç ½ããããªãªã¹ã¯æ¡å¤§ã¯ãªãããã«æãã¾ãããã ãä¸åå çããã£ããã£ã¦ãã¾ããããä»å¾ãæ°éæ´»ç¨ãå«ããå©ç¨æ¡å¤§ãæ¤è¨ããã¦ããã®ã§ããã®é¨åã§æ³¨è¦ãã¦ããå¿ è¦ã¯ããããã§ãã
*1:ç§ãå¾ã§æ¢ãã¦ã¿ã¾ã ... ããã¾ããï¼ http://www.soumu.go.jp/main_content/000327387.pdf
AWS Cloudformation 㨠IAM Policy ã§ã® IP ã¢ãã¬ã¹å¶é
AWS ã§ãããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«ã API ç㧠AWS ä¸ã®ãªã½ã¼ã¹ã®æä½ãç¹å®ã® IP ã¢ãã¬ã¹ããããå®è¡ã§ããªãããã«ããããã«ãIAM ããªã·ã¼ã® aws:SourceIp ã使ã£ã¦å¶éãããã¨ããã®ã¯å¸¸å¥æ段ã¨ãã¦ç¥ããã¦ããã¨æãã¾ãã
AWS管理コンソールへのアクセスをIPアドレスで制限したい | Developers.IO
ãã®ãã¼ã¸ã®æå¾ã§ãæ¸ããã¦ãã¾ããããã®å¸¸å¥å¥ã®è¨å®ã¯ CloudFormation ã使ã£ãã¹ã¿ãã¯ã®çæãæ´æ°ãåé¤ã¨ãã£ãæã«åé¡ã«ãªãã¾ãã
AWS Identity and Access Management によるアクセスの制御 - AWS CloudFormation
aws:SourceIp æ¡ä»¶ã使ç¨ããªãã§ãã ãããAWS CloudFormation ã¯ãªã¯ã¨ã¹ãã®éä¿¡å IP ã¢ãã¬ã¹ã§ã¯ãªããç¬èªã® IP ã¢ãã¬ã¹ã使ç¨ãã¦ãªã½ã¼ã¹ããããã¸ã§ãã³ã°ãã¾ãããã¨ãã°ãã¹ã¿ãã¯ãä½æããéãAmazon EC2 ã¤ã³ã¹ã¿ã³ã¹ãèµ·åããã Amazon S3 ãã±ãããä½æãããããããã«ãCreateStack å¼ã³åºãã aws cloudformation create-stack ã³ãã³ãã«ãã£ã¦å¾ããã IP ã¢ãã¬ã¹ã§ã¯ãªããã¹ã¿ãã¯ã® IP ã¢ãã¬ã¹ãããªã¯ã¨ã¹ããè¡ãã¾ãã
ï¼2015 å¹´ 3 æç¾å¨ï¼
ãç¬èªã® IP ã¢ãã¬ã¹ã使ç¨ãã¦ãªã½ã¼ã¹ããããã¸ã§ãã³ã°ãã¾ããã¨ãã£ã¦ãããç¬èªã® IP ã¢ãã¬ã¹ãã¨ããã®ãåããã°ãããã許å¯ãã¦ããã°ããªã©ã¨æã£ãã®ã§ãããå ¬éããã¦ãã AWS ã® IP ã¢ãã¬ã¹ã®ç¯å²*1ã試ãããããã©ã¤ãã¼ãã¢ãã¬ã¹ã®ç¯å²ãæå®ããããã¦è¦ã¾ãããããã¾ãããã¾ããã§ããã
Cloud Trail ã§è¦ã¦ããSource IP 㯠cloudformation.amazonaws.com ã¨ãªã£ã¦ãã¦ããã®åå㧠DNS ã«åãåããã¦ã A ã¬ã³ã¼ãã¯æã£ã¦ãã¾ããã
AWS 㧠su
UNIX ç³» OS ã§ããã°ããã¹ãã®ãã¡ã¤ã¤ã¼ã¦ã©ã¼ã«è¨å®ãã/etc/hosts.allow, /etc/hosts.deny ã使ã£ã¦ãç¹å®ã® IP ã¢ãã¬ã¹ããæ¥ç¶ã許å¯ãã/etc/ssh/sshd_config 㧠root ã§ã®ãã°ã¤ã³ãæå¦ãã¦ãä¸è¬ã¦ã¼ã¶ã§ãã°ã¤ã³ããããã«ãã¦ããã¦ãç¹æ¨©ãå¿ è¦ãªæã«ã¯ su 㧠root ã«ãªãããsudo ã使ããã¨ããéç¨ããã¦ããã±ã¼ã¹ãå¤ãã¨æãã¾ãã
ããã¨åãããã«ããé常ã¯ãå¶éãããã¢ã¯ã»ã¹æ¨©ã§ãå¿ è¦ã«å¿ãã¦å¤§ããªæ¨©å©ãåå¾ãããã¨ããæ段ã AWS ã«ç¨æããã¦ãã¾ããããããAssumeRoleãã§ãã
AssumeRole ã¯ãä»ã® AWS ã¢ã«ã¦ã³ããæä½ããçºã®æ¨©éãè¨å®ãããããå¤é¨ã®èªè¨¼åºç¤ã使ã£ãèªè¨¼å¦çãè¡ããã¨ããæèã§èª¬æããããã¨ãå¤ãã§ãã
ããããå¥ã® AWS ã¢ã«ã¦ã³ããããªãã¦ãèªåèªèº«ã® AWS ã¢ã«ã¦ã³ããæå®ãã¦ã OK?ãã¨æã£ããã£ãããããã¾ããã
AWS CLIがAssumeRoleによる自動クレデンシャル取得とMFAに対応しました! | Developers.IO
ä½æãã IAM ã¢ã«ã¦ã³ãã« MFA ãè¨å®ãã¦ãããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«å¯¾ãã¦ã¯ MFA ç¡ãã§ã¯å©ç¨ã§ããªããã¨ã¯ç¢ºèªããã®ã§ãããAWS CLI ã®æã«ã¯ã©ããªããã ï¼ ã¨æã£ã¦ãã©ãçããã®ãä¸è¨ã®è¨äºã§ãã
ãããèªãã¨ããããã¼ã¸ã§ã³ã® AWS CLI ããã¯ãMFA ãå¿ è¦ãªæã«ã¯ãã®ãã¼ã¯ã³ãè¦æ±ãããã¨ãã£ãåããã§ããããã«ãªã£ããã¨ãåããã¾ãã
ããèªãã¨ãä¿¡é ¼ããªã·ã¼ï¼trust plolicyï¼ã§ãMFA ã§ã®èªè¨¼ã«æåãã¦ããå ´åã« AssumeRole ã許å¯ãã¨ãã¦ãã¾ãããããããã®æ¡ä»¶ããç¹å®ã® IP ã¢ãã¬ã¹ããã®å ´åã ã£ãããã¨ãã¦ã¿ãã...
ã¨ãããã¨ã§ãæãã¤ããã·ããªãªã¯ä»¥ä¸ã®éãã§ãã
- IAM ã¦ã¼ã¶ã«ãAssumeRole ã許å¯ããããªã·ã¼ãå²ãå½ã¦ãã
- ä¿¡é ¼ããªã·ã¼ã§ãå ã®ãMFA ã§ã®èªè¨¼ãããã®æ¡ä»¶ã®æãããç¹å®ã® IP ã¢ãã¬ã¹ã ã£ããããã«å¤ãããã®ãè¨å®ããã
å®éã«ãã£ã¦ã¿ã
ã¾ããIAM ãã¼ã«ãä½æãã¾ãããã¼ã«åãå ¥åãã¦ããã¼ã«ã¿ã¤ããé¸æããç»é¢ãåºããããRole for Cross-Account Accessãã®ãProvide access between AWS accounts you ownããé¸æãã¾ããå ã ã¯ãããªããæã£ã¦ãã AWS ã¢ã«ã¦ã³ãéã§ã®ã¢ã¯ã»ã¹ãæä¾ãã¨ããæå³ã§ãããæã£ã¦ããã¢ã«ã¦ã³ããï¼ã¤ã§ããããé¸æãã¾ã*2ã
次ã«ããã©ã®ã¢ã«ã¦ã³ãã«å¯¾ãã¦ã¢ã¯ã»ã¹ãæä¾ãããï¼ããæå®ããã®ã§ãããæ¬æ¥ã®ã¯ãã¹ã¢ã«ã¦ã³ãã§ã®å©ç¨ã§ããã°ãã¢ã¯ã»ã¹ãä»ä¸ããå ã® AWS ã¢ã«ã¦ã³ãçªå·ãå ¥ããæã«ãèªåèªèº«ã®ã¢ã«ã¦ã³ãçªå·ãå ¥åãã¾ãã
ä¸è¨ç»é¢ã®ãRequire MFAãããã§ãã¯ããã°ãåè¿°ã®ãAWS CLI 㧠MFA ã使ããããã®ä¿¡é ¼ããªã·ã¼ãçæããã¾ãã
å¾ã¯ãä»ä¸ããã権å©ã®å 容ãé¸æããã°ããã¼ã«ã®ä½æã¯ã²ã¨ã¾ãå®äºã§ãã
ä½æãããã¼ã«ã®å 容ã確èªããã¨ãç»é¢ã®ä¸ã®æ¹ã«ãããTrust Relationshipãã§çæãããä¿¡é ¼ããªã·ã¼ã確èªã§ãã¾ãã
å®éã«çæãããããªã·ã¼ã¯ããããªæãã«ãªãã¾ãã
{ "Version": "2012-10-17", "Statement": [ { "Sid": "", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::èªåã® AWS Account ID:root" }, "Action": "sts:AssumeRole" } ] }
ãããç·¨éãã¦ãCondition å¥ã§ IP ã¢ãã¬ã¹ãæå®ãã¾ãã
{ "Version": "2012-10-17", "Statement": [ { "Sid": "", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::èªåã® AWS Account ID:root" }, "Action": "sts:AssumeRole", "Condition": { "IpAddress": { "aws:SourceIp": "xxx.xxx.xxx.xxx/xx" } } } ] }
ããã§ããã¼ã«ã®æºå㯠OK ã§ãã
次ã«ãIAM ã¦ã¼ã¶ã«å²ãå½ã¦ãçºã®ããªã·ã¼ãç¨æãã¾ããä»»æã®ãã¼ã«ã«åãæ¿ããããã®ãéå°ãªæ¨©å©ãªã®ã§ãResource ã«å ã«ä½ã£ããã¼ã«ãæå®ãã¾ãã
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "sts:AssumeRole" ], "Resource": "arn:aws:iam::èªåã® AWS Account ID:role/å ã«ä½ã£ããã¼ã«å" } ] }
å¾ã¯ããã®ããªã·ã¼ãã¦ã¼ã¶ã«é©ç¨ããã° OK ã§ãã
使ã£ã¦ã¿ã
åãããããããã«ãåè¿°ã® AssumeRole ã許å¯ããããªã·ã¼ã ããã¦ã¼ã¶ã«ä»ä¸ããç¶æ ã«ãã¦ã¿ã¾ããAssumeRole ã許å¯ããã¦ããã ããªã®ã§ãä¿¡é ¼ããªã·ã¼ã§è¨±å¯ããã¦ããã¢ãã¬ã¹ãå¦ãã«ããããããAWS ä¸ã®ãªã½ã¼ã¹ã«å¯¾ããä¸åã®æä½ãä¸åã®æ å ±åå¾ãã§ããªãç¶æ ã«ãªã£ã¦ãã¾ãã
ã§ã許å¯ããã IP ã¢ãã¬ã¹ããã¢ã¯ã»ã¹ããã¨ããã¼ã«ãåãæ¿ãããã¨ãã§ãã¾ãã
ããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«ã§ãã¼ã«ãåãæ¿ããã®ã¯ãç»é¢å³ä¸ã®ãã°ã¤ã³ä¸ã®ã¢ã«ã¦ã³ãæ å ±ã表示ãã¦ããæããã¡ãã¥ã¼ã表示ããã¦ããSwitch Roleããé¸æãã¾ãã
ãã¼ã«ã®åãæ¿ãç»é¢ã§ã¯ãåãæ¿ãå ã® AWS ã¢ã«ã¦ã³ãã¨ãå ã«ä½ã£ããã¼ã«ã®å称ãå ¥åãã¾ãã
ã表示åãã®æ¬ã¯ãã¢ã«ã¦ã³ãã¨ãã¼ã«ãå ¥åããã°ããã¼ã«@ã¢ã«ã¦ã³ããã®å½¢å¼ã«ãªãã¾ãã
ã§ãå®éã«åãæ¿ããã¨ãä¸å³ã®ããã«ãããã¾ã§ãIAM ã¦ã¼ã¶å@ã¢ã«ã¦ã³ããã ã£ãã®ããããã¼ã«å@ã¢ã«ã¦ã³ããã«ãªã£ã¦ãã¾ã*4ãå®éã«ããã¼ã«ãåãæ¿ããåã«ã§ã¯è»ä¸¦ã¿ã権å©ããªããã¨è¨ããã¦ããã®ããåãæ¿ãå¾ã¯ãã¡ãã¨è¡¨ç¤ºããã¦ãã¾ãã
ä¿¡é ¼ããªã·ã¼ã§æå®ãã IP ã¢ãã¬ã¹ã¨ã¯éãã¨ãããããã°ã¤ã³ãã¦ãã¼ã«ãåãæ¿ããã¨ãä¸å³ã®ããã«åãæ¿ãã«å¤±æãã¾ãã
ãã¼ã«ãåãæ¿ããããã°ããã®ãã¼ã«ã§ä»ä¸ããã¦ããããªã·ã¼ãé©ç¨ããã¾ãããã®æããã¼ã«ã«ä»ä¸ããããªã·ã¼ã« aws:SourceIp ã使ããªããã°ãCloudFormation ã§ã¹ã¿ãã¯çæãåé¡ãªãå®è¡ã§ãã¾ãã
AWS CLI ã§ã®å©ç¨
å ã«ç´¹ä»ãããAWS CLI 㧠MFA ã使ãã±ã¼ã¹ã«ä¼¼ã¦ãã¾ãã
AWS CLI ã®ãããã¡ã¤ã«ã§
- å ã«ãªããããã¡ã¤ã«ï¼source_profileï¼
- åãæ¿ãå ã®ãã¼ã«ï¼role_arnï¼
ãæå®ããç©ãä½æããå®éã®å¦çã®éã«ã--profile ãããã¡ã¤ã«åããä»ãã¦å®è¡ããäºã«ãªãã¾ããMFA ã¨ã®ä¾ã®éã㯠MFA ããã¤ã¹ãæå®ãããmfa_serialãã®æç¡ã ãã§ãã
ç´æ¥ããã¡ã¤ã«ãç·¨éãã¦ãè¯ãã§ãããAWS CLI ã使ã£ã¦å¿ è¦ãªè¨å®ãæ¸ãè¾¼ãäºãã§ãã¾ãã
ä»ãAssumeRole ã許å¯ãããã¦ã¼ã¶ã®ã¢ã¯ã»ã¹ãã¼ãã·ã¼ã¯ã¬ãããã¼ãããã©ã«ãã§ä½¿ãããããã«è¨å®ããã¦ããã¨ãã¾ãã
ããã«ãadminãã¨ãããããã¡ã¤ã«ã追å ãã¦ãAdministrationRole ã¨ããååã®ãã¼ã«ã¸åãæ¿ããããã«ããã«ã¯ãä¸è¨ã®ããã« AWS CLI ãå®è¡ãã¾ãããªããAWS Account ID ã 111122223333 ã ã£ãã¨ãã¾ãã
aws configure set profile.admin.region ap-northeast-1 aws configure set profile.admin.role_arn arn:aws:iam::111122223333:role/AdministrationRole aws configure set profile.admin.source_profile default
ããã§ãconfig ãã¡ã¤ã«ã®ä¸èº«ã¯ä¸è¨ã®ããã«ãªãã¾ãã
[default] region = ap-northeast-1 [profile admin] region = ap-northeast-1 source_profile = default role_arn = arn:aws:iam::111122223333:role/AdminRole
ãã®ç¶æ ã§ãaws cloudformation --profile admin create-stack --stack-name ......ãã¨ããã°ãã¹ã¿ãã¯ã®çæãã§ãã¾ãã
注æç¹
AssumeRole ã§åãæ¿ããå¾ã®æ¨©éã¯ãåãæ¿ãå ã®ãã¼ã«ã«å ¨é¢çã«åãæ¿ããã¾ãã
aws:SourceIp ã使ã£ãããªã·ã¼ãè¨å®ããéãããã®ã¢ãã¬ã¹ã«åè´ããã許å¯ãããã§ã¯ãªãããã®ã¢ãã¬ã¹ã«åè´ããªãã£ãããå ¨ã¦ãæå¦ãããã¨ããããªã·ã¼ãé©ç¨ããã®ãè¯ããã¨è¨ããã¾ããè¤æ°ã®ããªã·ã¼ãå²ãå½ã¦ããã¦ããå ´åãå ã«ãæå¦ãã®ããªã·ã¼ãè©ä¾¡ããã®ã§ãããã®ã¢ãã¬ã¹ã«åè´ããªãã£ãããã¹ã¦ãæå¦ãããã¨ããããªã·ã¼ãããã°ãä»ã®ããªã·ã¼ã§ IP ã¢ãã¬ã¹å¶éããªãã¦ãã確å®ã«å¶éã§ãã¾ãã
æ ã«ãCloudFormation ã®å®è¡ã®éã«åé¡ã«ãªã£ã訳ã§ãããåãæ¿ãå ã®ãã¼ã«ã«å ¨é¢çã«åãæ¿ãããããããå ã ã®ããªã·ã¼ã«å¶éããã£ã¦ããCloudFormation ã®ã¹ã¿ãã¯æä½ã«æåããäºã«ãªãã¾ãã
ã§ãã®ã§ãåæ¿å¾ã®æä½ã«å¶éãå ããããã°ãããã¾ã§ãããã¼ã«ã®ä¸èº«ã§å¶éããå¿ è¦ãããã¾ããåæ¿åã®ããªã·ã¼ã¯åæ¿å¾ã«ã¯åæ ãããªãäºãååã«æ³¨æããå¿ è¦ãããã¾ãã
*1:AWS IP アドレスの範囲 - アマゾン ウェブ サービス
*2:å®ã¯ããã¥ã¡ã³ãã«ãã®ã±ã¼ã¹ããã¡ãã¨æ¸ããã¦ãã¾ãããIAM ユーザーにアクセス権限を委任するロールの作成 - AWS Identity and Access Managementããã®ãªãã·ã§ã³ã¯ãã¦ã¼ã¶ã¼ããã¼ã«ãã¢ã¯ã»ã¹ããããªã½ã¼ã¹ããã¹ã¦åãã¢ã«ã¦ã³ãã«å±ãã¦ããå ´åã«ãé¸æãã¾ããã
*3:ãªãããã®ç»é¢ã¯æ¥æ¬èª...
*4:åãæ¿ãå ã®ãã¼ã«ãæå®ããç»é¢ã§ã表示åãã«è¨å®ãããã®ã«ãªããã¯ãã§ãï¼è©¦ãã¦ãªãï¼ã
ããã ã½ã 19
ä¹ ãã¶ãã«åå ããããã ã½ãã®åå¼·ä¼ã¯ãGoogle ã«ååãå ¥ããã¨ãåºå³¶åºèº«ã®ãã¯ããããã¢ã¤ãã«ã®ååããµã¸ã§ã¹ãã§ã³ããããè¾» 伸å¼ããã§ãããè¾»ããã¯ä½åº¦ãããã ã½ãã«ããã£ããã£ã¦ããã¯ãã§ãããç§å人ã¯åãã¦ã§ããã
ãã¼ãã¯ã¾ãæåã«ãæ¨ä»ã®ä¸æ£ãã°ã¤ã³ã«é¢ãã話ã§ããã
ãã¤ã¦ã¯ç·å½ãããè¾æ¸æ»æããã®å¿ç¨ã®ãªãã¼ã¹ã»ãã«ã¼ããã©ã¼ã¹ï¼ãã¹ã¯ã¼ããåºå®ã«ã㦠ID ã®æ¹ã次ã ã«ãããï¼ã主æµã ã£ãã¨æãã¾ããããã®ï¼ãï¼å¹´ã§æ¥éã«èå ãæµ´ã³ãã®ãããããããå ¥æããã¦ããã¢ã«ã¦ã³ãã¨ãã¹ã¯ã¼ãã®çµã¿åããã®ãªã¹ããå©ç¨ãããªã¹ãåæ»æã§ãã
ãã«ã¼ããã©ã¼ã¹åã®æ»æã ã¨ããã¹ã¯ã¼ããååãªé·ãã§è¤éã§ããã°ãç¾å®çãªæéã§çªç ´ãããäºã¯ãªããã¨ãããæé軸ãã§ã®åé¡ã ã£ãã®ã«å¯¾ãããªã¹ãåæ»æã®å ´åããããµã¤ãã§ä½¿ã£ã¦ãããã¹ã¯ã¼ãã使ãåãã¦ããã¨ãä»ã®ãµã¤ãã§çªç ´ããããããã°ã横å±éãã®åé¡ã«å¤åããã®ãç¹å¾´ã ã¨æãã¾ãã
è¾»ããããã人ããæã¡ãããããç¸è«ã§ã1000 ä¸ä»¶ã®ãªã¹ãã 400 ä¸åã§è²·ããªããï¼ ã¨ãã話ããã£ãããã§ãããã ããã®ãªã¹ãã®ãµã³ãã«ãè¾»ãããçºãã¦ãã¦ãä¼¼ããããªãã¹ã¯ã¼ãããã£ãããããããèå¼±ãªãã¹ã¯ã¼ããè¦å½ãããªãããªã©ãæ¬ç©ãã©ããæªããæãããã®ãªã¹ãã«ããã¡ã¼ã«ã¢ãã¬ã¹ã§æ¤ç´¢ãããããã¹ã¯ã¼ãã¯ããã·ã¥åããã¦ãããã©ãåãã¡ã¼ã«ã¢ãã¬ã¹ã®ä¸è¦§ãè¦ã¤ãã£ã¦ããªã¹ãã®ãã¹ã¯ã¼ãã¨ãæ¤ç´¢ãã¦è¦ã¤ãã£ããã¹ã¯ã¼ãã®ããã·ã¥å¤ãçªãåãããããã©ããããã®ãªã¹ãã¯å½ç©ã ã£ããã¨ãããã¨ããã£ãããã§ãã
ï¼ã¤ãã®ãã¼ãã¯ãPhishing ã«é¢ãã¦ãå®éã« Phishing ãµã¤ããä½ããã¼ã«ã使ã£ã¦ä½ããããå ¨ãåãç»é¢ã®ãµã¤ãã«ã¢ã«ã¦ã³ãã»ãã¹ã¯ã¼ããå ¥åããã¨ããã® Phishing ãµã¤ãã®ãã°ã«ãã¹ã¯ã¼ããè¨é²ãããã¨ããããå®éã®ãã¢ã§è¦ãã¦ãããã¾ããã
è¾»ããã¯æè¿ãPhishing ãµã¤ãã«å¼ã£ãããã®ã趣å³ã§ãä¸è¨ã®ãã¼ã¸ã§ããã®æ§åãèªãã¾ãã
(n) – life is penetration. geeks cheer. geeks be ambitious.
Phishing ã¯ãç¹å®ã®çµç¹ãçãã°æ¨çåæ»æã«ãªã訳ã§ããããããã£ãæ¨çåæ»æã¡ã¼ã«ã®å¯¾å¿è¨ç·´ã«é¢ãã¦ãééã£ãè¨ç·´ã«ãªã£ã¦ãããã¨ããææãããã¾ãããåç´ã«éå°çãã¯ãªãã¯çãè¦ã¦ä¸åä¸æããã®ã¯ç¡é§ã§ã誰ãéããããéè¦ã ãããããããéãã¦ãã¾ã£ãæã«ã©ãããã®ããã¨ããè¨ç·´ã«ãªããªãã¨æå³ããªããã¨ããã話ã¯ãã®éãã ã¨æãã¾ããã
ï¼ã¤ãã¯ãèªåèªèº«ã®ãã©ã¤ãã·ã¼ãå®ãããã«ãå©ç¨ã§ãããã¼ã«ã®ç´¹ä»ã§ãããå¿ååãæå·åãã¼ã«ã¯ãä»æ¹ã§ç¯ç½ªè ã«ä½¿ãããã®ã§ãã¼ãã£ãªã¤ã¡ã¼ã¸ããããã©ãå ä¸ã¨åãã§ãã¼ã«èªä½ã¯ã©ã£ã¡ã«ã使ãããã¨ããã話ãããã¾ããã
æå¾ã«ãå®éã«èªåã®ã»ãã¥ãªãã£ãå®ãããã«ãå°é家ã ããåèæ´»åããã ãã¯ãªããèã®æ ¹çãªåºããã大åãã¨ããäºã話ããã¦ãã¾ãããèªåããã®ç«¯ããã«ãªã£ã¦ããã°è¯ããªããã¨ããæããå¼·ããã¾ããã
ä½è«ï¼
æå¾ã®è³ªçå¿çã®ã¨ããã§ãã徳丸æ¬ããæå¤ã«ç¥ããã¦ããªãäºãå¤æã徳丸ãããããã
ã½ãã«æ¥ã¾ãããï¼
ããã·ã¥å¤ãã½ã«ããã¹ãã¬ããã³ã°ã«é¢ãã話é¡ã®å ´é¢ã§ããããæåå³åã§è¯ããã°ãç§ãæ¸ãããã¨ãããã®ã§ãåèã«ãªãã°å¹¸ãã§ãã
IPv6 ãã¿ã®è½ã¡ç©æ¾ã
IPv4 㨠IPv6 ã®ç¨èªã®éã
IPv6 ã«æ £ãã¦ãã¾ãã°ãIPv6 ç¨èªã使ã£ãæ¹ãããæ£ãã表ç¾ã«ãªãã®ã¯åãã£ã¦ãã¦ããIPv4 ã§æ £ã親ããã ç¨èªã使ããªãã¨ããªããªãã¤ã¡ã¼ã¸ãã¥ããäºãå¤ãã§ããä»åãæå³çã« IPv6 ç¨èªãæå°éã«ããæ¸ãæ¹ã«ããã®ããèªåèªèº«ã§ IPv6 ç¨èªã身ã«ã¤ãã¦ããªããã¨ããã®ãããã¾ãã
ã¨ãããã¨ã§ãã¡ãã£ã¨ç¨èªãæ¯è¼ãã¦ã¿ã¾ãã
ã°ãã¼ãã«ã¢ãã¬ã¹ããã©ã¤ãã¼ãã¢ãã¬ã¹
IPv4 ã®ãã©ã¤ãã¼ãã¢ãã¬ã¹ã«é¢ãã¦ã¯ãULA*1ã該å½ãã¾ããããã¯ä»åæ¸ããå 容ã«ãå¤ç¨ãã¦ãã¾ãã
è¥å¹²éãã®ã¯ãULA ã¯æåããããä¿è¨¼ã¯ã§ããªããã© Unique ã§ããããã«ãã¨ããäºãæèãã¦ãã¢ãã¬ã¹ã®æ±ºãæ¹ãç¨æãã¦ããç¹ã§ããIPv4 ã®ãã©ã¤ãã¼ãã¢ãã¬ã¹ã§ãã192.168.1.0/24ãã¨ããé¸ã°ããã¡ã§ãããããã¨ãã«ä¼æ¥åä½µãªã©ã§å é¨ãããã¯ã¼ã¯ããã¼ã¸ããªãããããªããªã£ãæã«é¢åãªäºã«ãªããã¨ãã話ããã£ãã®ã§ãããULA ããã¡ãã¨è¨ç®ãã¦æ±ºããã¨ãã¢ãã¬ã¹ãè¡çªããäºã¯ã»ã¨ãã©ç¡ããªãã¾ãã
ä¸æ¹ãã°ãã¼ãã«ã¢ãã¬ã¹ã«é¢ãã¦ã¯ãGUAï¼Global Unicast Addressï¼ã¨ããç¨èªã使ããã¾ãã
ã¢ãã¬ã¹ã®ãããã¯ã¼ã¯é¨ããã¹ãé¨
ã¢ãã¬ã¹ã§ãããã¯ã¼ã¯ã表ãé¨åã¨ãã¹ãã表ãé¨åã¯ãIPv6 ã§ã¯ãã¬ãã£ãã¯ã¹ã¨ã¤ã³ã¿ãã§ã¼ã¹ ID ã«ãªãã¾ãããã ãããã¬ãã£ãã¯ã¹ãå¿ ããããããã¯ã¼ã¯ã¨ããæ¦å¿µã¨çµã³ã¤ããªãã±ã¼ã¹ãããã¾ãã
ä¾ãã°ããµã¤ããã¬ãã£ãã¯ã¹ã¨å¼ã°ãã 48bit é·ã®ãã¬ãã£ãã¯ã¹ããã£ã¦ãããã¯çµç¹åä½ã«å²ãå½ã¦ããããã¨ããæå³åãã«ãªã£ã¦ãã¾ããULA ã®ãã¬ãã£ãã¯ã¹ã®æ±ºãæ¹ãããã®ãµã¤ããã¬ãã£ãã¯ã¹ã® 48bit ã決ãããã®ã§ããã®ãã¬ãã£ã¯ã¹ãåå²ãã¦ãé常㯠64 bit ã®ãã¬ãã£ãã¯ã¹é·ã§ãããã¯ã¼ã¯ã¢ãã¬ã¹ãä½ããã¨ãããã¨ã«ãªãã¾ãã
ä¸æ¹ããã¹ãé¨ã¯ã¤ã³ã¿ãã§ã¼ã¹ ID ã¨å¼ã°ããé常ã¯ä¸ä½ 64 bit ã®ã¢ãã¬ã¹ã®äºãè¨ãã¾ããæ£ç´ããã®ãã¤ã³ã¿ãã§ã¼ã¹ IDãã¨ããç¨èªã¯ããªããªã身ã«ã¤ããªãã§ãã
ARP 㨠ND
ç¨èªãã¨ããããã¯ãä»çµã¿ãã®ãã®ãéãã®ã§ãããã¤ã¼ãµãããä¸ã® IPv4 ã§ãMAC ã¢ãã¬ã¹ã¨ IP ã¢ãã¬ã¹ã®é¢ä¿ã解決ããããã« ARP ã¨ãããããã³ã«ãããã¾ããããIPv6 ã§ã¯ ARP ã¯ä½¿ãã¾ããããã®ä»£ãããICMPv6 ã®ä¸ã¤ã¨ãã¦å®è£ ããããNDï¼Neighbor Discovery: è¿é£æ¢ç´¢ï¼ã¨ããä»çµã¿ã使ãã¾ãã
ãªã®ã§ãIP ã¢ãã¬ã¹ã¨ MAC ã¢ãã¬ã¹ã®é¢ä¿ã確èªããããã«ãarp -aããªã©ã¨ã³ãã³ããæã£ã¦ããIPv6 ã¢ãã¬ã¹ã¯åºã¦ãã¾ãããWindows ã§ã¯ netsh ã§ãLinux ã§ã¯ ip ã³ãã³ãã§ãND ãã£ãã·ã¥ã®ç¶æ ã表示ããäºãã§ãã¾ã*2ã
IPv4 | IPv6 | |
---|---|---|
Windows | arp -a | netsh interface ipv6 show neighbors |
Linux | arp -a | ip -6 neigh |
Linux ã® ip ã³ãã³ãã®å ´åãã-6ããä»ããã«ãip neighãã¨ããã°ãIPv4 ã«é¢ãã¦ã¯ ARP ãã£ãã·ã¥ãIPv6 ã«é¢ãã¦ã¯ ND ãã£ãã·ã¥ã®ä¸¡æ¹ã表示ããã¾ãã
IPv6 ã«ã¯ç¡ããã®
NAT
NAT ãç¡ãã®ã¯æåã«ãæ¸ãã¾ãããåççã«ã§ããªããã¨ã¯ãªãã§ãããCentOS Ver.6 ã® ip6tables ã§ã¯ nat ãã¼ãã«ã使ãã¾ãã*3ãNAPTããããããIP ãã¹ã«ã¬ã¼ãã使ãã¾ãã*4ãã«ã¼ã¿ã§ã IPv6 ã® NAT ããµãã¼ããã¦ãããã®ã¯å°ãªãã§ããããç¾æç¹ã§ã¯ NAT ã¯ç¡ãã¨èããæ¹ãããã§ãã
IPv4 ã§ã¯å½ããåã®ããã« NAPT ããã¦ãã¦ããããçµæçã«ãæå³çãªè¨å®ãããªããã°ãã¤ã³ã¿ã¼ãããå´ããã¯ã¢ã¯ã»ã¹ã§ããªããã¨ããç¶æ ãä½ãã ããã»ãã¥ãªãã£ã«è²¢ç®ãã¦ããäºã¯äºå®ã§ã*5ã
NAT / NAPT ãç¡ãã¨ãããã¨ã¯ãæ®éã«ã«ã¼ã¿ã«ç¹ãã ãã½ã³ã³ãã°ãã¼ãã«ã¢ãã¬ã¹ãæã¡ãã¤ã³ã¿ã¼ãããå´ããã¢ã¯ã»ã¹ã§ããäºãæå³ãã¾ããå®éãその2ã§ç´¹ä»ãã¦ãããã¬ããå ãã¯ã¹ãã§ã®æ¥ç¶è¨å®ã ã¨ãã¤ã³ã¿ã¼ãããå´ããã¢ã¯ã»ã¹å¯è½ã§ã*6ããªã®ã§ãä¸è¬ç㪠IPv6 対å¿ã«ã¼ã¿ã®å ´åãã¤ã³ã¿ã¼ãããå´ããå é¨ã¸ã®æ¥ç¶ã¯è½ã¨ããããªãã£ã«ã¿ãããã©ã«ãã§æå¹ã«ãªã£ã¦ãããã¨ããäºã«ãªã£ã¦ãã¾ãã
å人㧠ISP ã¨å¥ç´ãã¦ã64 bit ã®ãã¬ãã£ãã¯ã¹ãä¸ãããããã¨ããããå°ãªãã¢ãã¬ã¹ãåãåãããã® NAPTãã¨ããå½¹å²ã¯çµãã£ãã¨è¨ãã¾ããããã¨ããã°ãã»ãã¥ãªãã£é¢ããã®è¦æã§ãIPv4 ã®æã®ããã«ãULA ã®ã¿ç«¯æ«ããã¤ã³ã¿ã¼ããããå©ç¨ã§ããããã«ããããã¨ãããã¨ã¯ããããããã¾ããããã®å ´åã® NAT 㯠NAPT ã®ãããªã1 対 Nãã§ã¯ãªãããN 対 Mãã§ãåçã« GUA 㨠ULA ããããã³ã°ãããããªãã®ã«ãªãããããã¾ããã
ãã ãå®éã«ã¤ãªããç°å¢ãã§ãã¦ãã¾ãã¨ãã°ãã¼ãã«ãªã¢ãã¬ã¹ãç´æ¥ãã¹ãã«å²ãå½ã¦ãããã®ã¯ãã·ã³ãã«ã§è¯ãæãããã¾ãã端æ«å´ããè¦ãã¨ãç§ã¿ããã« ULA ã使ããã¨ããã¨ãä¸ã¤ã®ã¤ã³ã¿ãã§ã¼ã¹ã«è¤æ°ã®ã¢ãã¬ã¹ãä»ä¸ããã¦ããªãã ãé¢åãªæãã«ãªãã¾ãããã¤ã³ã¿ã¼ãããå´ããã¢ã¯ã»ã¹ã§ãããã©ããã¯ãç´ç²ã«ã«ã¼ã¿ãã£ã«ã¿ã§ç©´ã空ãã¦ãããã©ãããã«ãªããIPv4 ã® NAPT ã使ã£ã¦ããç°å¢ã§ãããã®ãããã³ã«ã¯å¤§ä¸å¤«ã ãã©ãããã¯ãã¡ã§...ãã¿ãããªäºã¯ãã£ã¨å°ãªããªãã¯ãã§ãã
ããã¼ããã£ã¹ãã¢ãã¬ã¹
IPv4 ã¢ãã¬ã¹ã§ããã¹ãé¨ã All 1 ã®ã¢ãã¬ã¹ã¯ããã¼ããã£ã¹ãã¢ãã¬ã¹ãã¨ãã決ã¾ããããã¾ããããIPv6 ã¢ãã¬ã¹ã«ããã¼ããã£ã¹ãã¢ãã¬ã¹ã¯ããã¾ããã
ãã ãããã¼ããã£ã¹ãã¨åãå½¹å²ããããã«ããã£ã¹ãã¢ãã¬ã¹ãã¨ããã®ããã£ã¦ãff02::1 ã¨ããã¢ãã¬ã¹ã使ãã¨ãåä¸ã»ã°ã¡ã³ãã®å ¨ã¦ã®ãã¼ãå®ãã¨ããæå³ã«ãªãã¾ãããããããªã¼ã«ãã¼ããã«ããã£ã¹ãã¢ãã¬ã¹ãï¼ãããã¯ãå ¨ãã¼ããã«ããã£ã¹ãã¢ãã¬ã¹ãï¼ã¨ããã¾ãã
ãã£ã¨ãã使ãå ´é¢ã¯ãä½ããããã³ã«ãå®è£ ã§ãããªãéããã»ã¨ãã©ç¡ãã¨æãã¾ãã...ã
ã¾ã¨ã
æã家㮠IPv6 å°å ¥é¡æ«ã¯ãããã§ã²ã¨ã¾ãçµããã§ããã¾ããIPv6 ã使ããããã«ãªã£ãã¨è¨ã£ã¦ããããããGoogle ã« IPv6 ã§ã¤ãªãã£ã¦ããï¼ãæ°æã¡ãã¬ã¹ãã³ã¹è¯ããããã¨ããç¨åº¦ã§ãå®çã¯ä½ãããã¾ããããã§ãããããã¦å®éã«è¦å´ãã¦ã¿ãã¨ããåæãã IPv4 㨠IPv6 ã§éãã®ãå®æãã¾ããã
ãã£ã¨ãããããã¡ LAN ã« IPv6ããªãã¦äºãããªããã°ãä»ä»¥ä¸ã«ãã«ã¼ã¿ãç¹ãã ããã§ãã(^^;ã
*1:Unique Local Address ãã¨æãã¨ãRFC çã«ã¯ Unique Local IPv6 Unicast Address
*2:å³å¯ã«ã¯ããã£ãã·ã¥ã ããããªãã¦ãåºå®ã§ãããã³ã°ãã¦ãããã®ãããã°ããããã表示ããã¾ãã
*3:kernel 3.7.0 ãã使ããããã«ãªã£ããããã§ãã
*4:å°ãªãã¨ã kernel 3.9.0 ããã¯ä½¿ãããããã§ãã
*5:ãããæ²¹æãçãã§ããå´é¢ãããã¨ã¯æãã¾ãããä¸è¬ã®äººãé»æ°å±ããã§è²·ã£ã¦ããã«ã¼ã¿ã使ããã¨ã§ãç´æ¥æ»æããåé¿ã§ãããã¨ããã®ã¯ãã»ãã¥ãªãã£çã«ã¯é½åãè¯ãã£ãã¨æãã¾ãã
*6:Web ã¤ã³ã¿ãã§ã¼ã¹ã§ IPv6 ã®è¨å®ãããã¨ããã£ã«ã¿ã使ãï¼ä½¿ããªãã®è¨å®ããã£ã¦ãç°¡åã«ãå¤ããã¯ã¤ãªãããªãããã£ã«ã¿ãè¨å®ããäºãå¯è½ã§ãããã£ã¨ããããã«æ°ã¥ããã«åæãããæ¾ç½®ãã¦ãã¦ããIPv6 ã§ã® SSH ã«å¯¾ãããã«ã¼ããã©ã¼ã¹ã¢ã¿ãã¯ã¯ã¼ãã§ãããIPv6 ã¢ãã¬ã¹ã®ã¢ãã¬ã¹ç©ºéãåºå¤§ãªã®ã§ãä»®ã«ããã¼ããã¦ããç¸æã¨ãªããã¹ããã»ã¨ãã©è¦ã¤ãããªãã¦ãå¹çãæªããã§ããã