ã¯ããã«
iPad ã Azure ã« P2S æ¥ç¶ãããè¨é²ã§ãã
ããã«è³ãã¾ã§ã® iPad ã®è¨å®ã«æéåã£ãããã¾ã¨ãã¦ããã¾ãã
æ¥ç¶å¾ãAzure VM ã« Fiddler ãå ¥ãããããã·ãç¨æããããã³ãå¶éããããã¨ããã¾ã§è©¦ããã®ã§ãã¡ããå¾ã«ã¾ã¨ãã¾ãã
ç®æ¬¡
- ã¯ããã«
- ç®æ¬¡
- åèã«ããè¨äº
- ç°å¢
- ç°å¢ã®æ§ç¯
- çµããã«
åèã«ããè¨äº
ä»åã®å 容ã¯ã次ã®è¨äºãåèã«ãã¦å®ç¾ã§ãã¾ããã ã»ã¼ãã®ã¾ã¾ã§ã§ããé¨åãããã°ãä¸é¨å¤æ´ãå¿ è¦ãªç®æãããã¾ããã
ç°å¢
使ç¨ãã¦ããããã¤ã¹ãOS æ å ±ãªã©ã¯æ¬¡ã®ã¨ããã§ãã
- iPad (iOS 17.6.1)
- ãããã· (Fiddler Classic) ç¨ VM (Windows (Windows Server 2022 Datacenter Azure Edition)
- æå ã®æä½ç«¯æ« (Windows 11 24H2)
æºåãã Azure ç°å¢ã¯ãããªæãã§ãã
- VNet (10.3.0.0/16)
- VM ç¨ãµãããã (10.3.0.0/24)
- GatewaySubnet (10.3.250.0/24)
- ãããã·ç¨ VM (10.3.0.4)
- VPN ã²ã¼ãã¦ã§ã¤ (VpnGw1, ã¢ã¯ãã£ã/ã¢ã¯ãã£ããBGPãKey Vault ã¢ã¯ã»ã¹ã¯ç¡å¹)
NSG ã Bastion ãªã©ããã¾ãé¢ä¿ã®ãªããªã½ã¼ã¹ã¯çç¥ãã¦ãã¾ãã
ãããã使ã£ã¦ãããã£ããã§ããããã¨ããã®ãã¾ã¨ãã¾ãã
ç°å¢ã®æ§ç¯
ãªã½ã¼ã¹ã®ãããã¤
VNetãVMãVPN ã²ã¼ãã¦ã§ã¤ã®ãããã¤ã¯ç¹ã«ç¹å¥ãªãã¨ã¯ãªããããããã§ã¯çç¥ãã¾ãã
å¼·ãã¦æããã°ãããã§ã¯ VPN ã²ã¼ãã¦ã§ã¤ããããã¤ããã¨ãã®æ¬¡ã® 3 ã¤ã®é¸æã¯ãã¹ã¦ "ç¡å¹" ãé¸æãã¦ãã¾ãã
- ã¢ã¯ãã£ã/ã¢ã¯ãã£ã ã¢ã¼ãã®æå¹å
- BGP ã®æ§æ
- Key Vault ã¢ã¯ã»ã¹ãæå¹ã«ãã
P2S ç¨è¨¼ææ¸ã®ä½æ
ç¶ãã¦ãP2S ã®èªè¨¼ã§ä½¿ç¨ããèªå·±ç½²åã®ã«ã¼ã証ææ¸ãã¯ã©ã¤ã¢ã³ã証ææ¸ãä½æãã¾ãã次ã®ããã¥ã¡ã³ãã«å¾ãã¾ãã
ã«ã¼ã証ææ¸ã®ä½æ
ããã¥ã¡ã³ãã®ãèªå·±ç½²åã«ã¼ã証ææ¸ã®ä½æãã®æµãã§ã«ã¼ã証ææ¸ãä½æãã¾ãã
ç¹ã«ãã ããããªããã°ãããã¥ã¡ã³ãå ã®ãµã³ãã«ããã®ã¾ã¾ã³ããå®è¡ã§å¤§ä¸å¤«ã§ãã
管çè 権éã® PowerShell ã§å®è¡ãã¾ãã
PowerShell ã¯éããã«æ¬¡ã¸
ã¯ã©ã¤ã¢ã³ã証ææ¸ã®ä½æ
ãã¡ã㯠ãã¯ã©ã¤ã¢ã³ã証ææ¸ã®çæãã«å¾ãã¾ãã PowerShell ãéãã¦ãããããã ããããªããã°ãã®ã¾ã¾ãä¾ 1 - PowerShell ã³ã³ã½ã¼ã« ã»ãã·ã§ã³ãã¾ã éããã¾ã¾ãã®ã³ãã³ããã³ãããã¦å®è¡ããã° OK ã§ãã
ããã§ãå¿ è¦ãªè¨¼ææ¸ãä½æã§ãã¾ããã
証ææ¸ã®ã¨ã¯ã¹ãã¼ã
ä½æãã次㮠2 ã¤ã®è¨¼ææ¸ãã¨ã¯ã¹ãã¼ããã¾ãã
åãããã¥ã¡ã³ãã®ãã«ã¼ã証ææ¸ã®å ¬éãã¼ (.cer) ã®ã¨ã¯ã¹ãã¼ããã¨ãã¯ã©ã¤ã¢ã³ã証ææ¸ã®ã¨ã¯ã¹ãã¼ããã«å¾ãããããã .cer 㨠.pfx å½¢å¼ã§ã¨ã¯ã¹ãã¼ããã¾ãã
ã¯ã©ã¤ã¢ã³ã証ææ¸ã®ã¨ã¯ã¹ãã¼ãã§ã¯ããç§å¯ãã¼ã®ã¨ã¯ã¹ãã¼ãããå¿ããã«ï¼
VPN ã²ã¼ãã¦ã§ã¤ã®è¨å®
ã¨ã¯ã¹ãã¼ããã証ææ¸ãç¨ãã¦ãVPN ã²ã¼ãã¦ã§ã¤ã« P2S ç¨ã®è¨å®ãè¡ãã¾ãã ããã¥ã¡ã³ãã§è¨ãã¨ãVPN ã¯ã©ã¤ã¢ã³ã ã¢ãã¬ã¹ ãã¼ã«ã追å ããããããã³ãã«ã®ç¨®é¡ã¨èªè¨¼ã®ç¨®é¡ãæå®ãããããã«ã¼ã証ææ¸ã®å ¬éãã¼æ å ±ã®ã¢ãããã¼ãã ã®ç®æã«è©²å½ãã¾ãã
ãããã¨ã¯ã·ã³ãã«ããããªæã㧠VPN ã²ã¼ãã¦ã§ã¤ã®ããã¤ã³ã対ãµã¤ãã®æ§æãã«ã¢ãã¬ã¹ãã¼ã«ããã³ãã«ã®ç¨®é¡ãã¨ã¯ã¹ãã¼ããã証ææ¸ã®ä¸èº«ã®ã¢ãããã¼ããè¡ãã¾ãã
ã¢ãã¬ã¹ ãã¼ã«ã¯ P2S ã®ã¯ã©ã¤ã¢ã³ãã«æãåºããã IP ã¢ãã¬ã¹ã¨ãªããããæ¢åç°å¢ã¨éè¤ããªããã®ãæå®ãã¾ãã
ãã³ãã«ã®ç¨®é¡ã¯ãããã§ã¯ OpenVPN ãå©ç¨ãã¾ãã
å ¬é証ææ¸ãã¼ã¿ã«ã¯ãã¨ã¯ã¹ãã¼ããã証ææ¸ (.cer) ãã¡ã¢å¸³ã§éããBEGIN 㨠END ã®éã«ããå¤ã ããã³ãããã¾ãã ãã ãããã®ã¾ã¾ã³ããããã¨æ¹è¡ãå«ã¾ãã¦ãã¾ããããæ¹è¡ãæ¶ã㦠1 è¡ã®ç¶æ ã«ãã¦ãããã¼ã¿ã«ã¸è²¼ãä»ãã¾ãããã
â» â ãã®è¾ºã®æ¹è¡ãå«ã¾ãã¦ã㨠NG
VPN ã²ã¼ãã¦ã§ã¤ã®è¨å®ã¯ãã㧠OK ã§ãã
VPN æ§æãã¡ã¤ã«ã®ä½æ
ããã¾ã§ã¯ãããã P2S æ§æã¨åãã§ãããããããã«ã¹ã¿ãã¤ãºãã¦ããå¿ è¦ãããã¾ãã åèæé ã¯ãiOSããã¤ã¹ããAzureä¸ã®ä»®æ³ãããã¯ã¼ã¯ã«P2Sæ¥ç¶ãããã® æé 7 以éã§ãããå æ¥è©¦ããçµæã ã¨æ§æãã¡ã¤ã«ã«å°ãå¤æ´ãå¿ è¦ãªã®ã§ãä¸ã«ã¾ã¨ãã¦ãã¾ãã
pfx ããã®ãã¼æ å ±åãåºã
åèæé ã¨é çªãåå¾ãã¾ãããã»ã¯ã·ã§ã³åãããããã®ã§ãã¡ããå ã«è¡ãã¾ãã
ãã®å¾ãpfx ã«ã¨ã¯ã¹ãã¼ãããã¦ããç§å¯éµãªã©ã®ã³ãããå¿ è¦ã«ãªãã¾ãããpfx ã®ã¾ã¾ã§ã¯è¦ãããªãããã openssl ã®ã³ãã³ããç¨ã㦠pfx ã txt å½¢å¼ã«å¤æãã¾ãã
openssl ãã¤ã³ã¹ãã¼ã«ãããç°å¢ããªãã¦ããCloud Shell ã使ããã°ããã§ã§ãã¾ããä»ã¯ã¹ãã¬ã¼ã¸ ã¢ã«ã¦ã³ããä¸è¦ãªã®ã§ç°¡åã§ãã
Cloud Shell ãèµ·åãã¦ã[ãã¡ã¤ã«ã®ç®¡ç] - [ã¢ãããã¼ã] ããã¨ã¯ã¹ãã¼ããã pfx ãã¡ã¤ã«ãã¢ãããã¼ããã¾ãã
ã¢ãããã¼ããã pfx ãã¡ã¤ã«ã«å¯¾ãã¦ã次ã®ã³ãã³ããå®è¡ãã¾ãã
openssl pkcs12 -in "<pfx ãã¡ã¤ã«å>" -nodes -out "profileinfo.txt"
pfx ã®ãã¹ã¯ã¼ããå ¥åããã¨ãå¤æããããã¡ã¤ã«ãåºåããã¾ãã
ä»åº¦ã¯ [ãã¡ã¤ã«ã®ç®¡ç]-[ãã¦ã³ãã¼ã] ãã profileinfo.txt ãæå®ãããã¡ã¤ã«ããã¦ã³ãã¼ããã¾ãã
ãã㧠[ãã¦ã³ãã¼ã] ãé¸æããå¾ãå³ä¸ã®ãããã¢ãããé¸æããªãã¨ãã¦ã³ãã¼ããããªãã®ã§æ³¨æ
ããã§ãæ§æãã¡ã¤ã«ä½æã®æºåãã§ãã¾ããã
æ¢åæ§æãã¡ã¤ã«ã®ç·¨é
ç¶ãã¦ã VPN ã²ã¼ãã¦ã§ã¤ããã¯ã©ã¤ã¢ã³ãããã¦ã³ãã¼ããã¾ãã
zip ã§ãã¦ã³ãã¼ããããã®ã§è§£åãã¦ãOpenVPN ãã©ã«ãã«ãã vpnconfig.ovpn ãã¡ã¢å¸³ã§éããä¸ããé ã«å¤æ´ãã¦ããã¾ãã
ãªãã·ã§ã³åé¤
ä¸é¨ã«è¨è¼ããã¦ããã®ã¯ OpenVPN ã®ãªãã·ã§ã³ã®ããã§ããããã®ã¾ã¾ã ã¨ã¨ã©ã¼ãåºã¦ãã¾ã使ããªããªãã·ã§ã³ãããã¾ããã ãã®ããã"persist-key"ã"persist-tun"ã"log openvpn.log" ã® 3 è¡ãåé¤ãã¾ãã
証ææ¸æ å ±ã³ãã
P2S CA root certificate 㨠Pre Shared Key ã¯ãã®ã¾ã¾ã§åé¡ãªãããã®ä¸ã® P2S client certificate 㨠private key ã® $xxxx ã®é¨åã«ããããã®å¤ãè²¼ãä»ããå¿ è¦ãããã¾ãã
ããã§ãå ã»ã©ã® profileinfo.txt ã使ç¨ãã¾ãã
profileinfo å ã«ã¯ BEGIN PRIVATE KEYãBEGIN CERTIFICATEãBEGIN CERTIFICATE 㨠3 ã¤ããã¾ããã1 çªä¸ã® Private Key ã vpnconfig.ovpn ã® $PRIVATEKEY ã¨ç½®ãæãã¾ãã
ç½®ãæãå¾ã® vpnconfig
ç¶ãã¦ãçãä¸ã® BEGIN CERTIFICATE ãã END CERTIFICATE ã¾ã§ããvpnconfig.ovpn ã® $CLIENTCERTIFICATE ã¨ç½®ãæãã¾ãã
ç½®ãæãå¾ã® vpnconfig
ããã§ãæ§æãã¡ã¤ã«ã®ä½æã¯å®äºã§ãããã¨ã¯ããã使ã£ã¦ãiPad ãã VPN æ¥ç¶ãè¡ãã¾ãã
ã¡ã¼ã«ãªãä½ãªãã§ãiPad ã«ç·¨éãã vpnconfig.ovpn ãã¡ã¤ã«ããããã¦ããã¾ãã
iPad ãã VPN æ¥ç¶ãè¡ã
iPad ãã VPN æ¥ç¶ãè¡ããããã¯ã©ã¤ã¢ã³ãã¨ã㦠OpenVPN Connect ã¢ããªãã¤ã³ã¹ãã¼ã«ãã¾ãã
apps.apple.comvpnconfig.ovpn ãã¡ã¤ã«ã OpenVPN Connect ã§éãã¨ããããã¡ã¤ã«è¿½å ç»é¢ã«ãªããã Add ãã¾ãã
ãããã¡ã¤ã«ãç¨ãã¦æ¥ç¶ãè¡ãã°ãVPN æ¥ç¶ãæ§æããã¾ãã
æ¥ç¶ã®ç¢ºèªã«ã¯ãAzure VM ã«ã¢ã¯ã»ã¹ããã¦ã¿ããã ping ãéã£ã¦ã¿ããããã®ãããã§ããã
ãã㧠iPad ã§ã® Azure VPN P2S æ¥ç¶ã¯å®äºã§ãï¼
çµããã«
iPad (iOS) ã§ã®æ¥ç¶ã¯åãã¦ã ã£ãã®ã§ããããããªãã¨ããããã¹ã¿ã¼ããã¾ããããå 人ã®ç¥æµããåããã¦ç¡äºæ¥ç¶ã§ãã¾ããã config ã§æ¶ããªãã¨ãããªãé¨åããã£ããã¨çµæ§æããã£ãã®ã§ãåèã«ãªãã°ã¨æãã¾ãã
æ¬å½ã¯ç¶ã㦠Fiddler ãä»ããããã³ãå¶éã¾ã§æ¸ãã¤ããã ã£ãã®ã§ããããªããªãçãé²ãããããããã¾ã§ä½ãã®ã«ãçµæ§æéãããã£ã¦ãã¾ãã¾ããã æéãããã£ã¦çµå±ä½ãæ稿ããªãã®ãä¸çªãããªãã®ã§ãä¸æ¦å®æãã P2S æ¥ç¶ç·¨ã¾ã§ã®æ稿ã§ãã ããã³ãå¶å¾¡ç·¨ãæ¸ãã¾ãã