NetScalerとのインラインデバイス統合
-
暗号化されたトラフィックを検査する。ほとんどのIPSおよびNGFWアプライアンスは暗号化されたトラフィックをバイパスするため、サーバーは攻撃に対して脆弱なままになります。NetScalerアプライアンスはトラフィックを復号化し、インラインデバイスに送信して検査することができます。これにより、お客様のネットワークセキュリティが強化されます。
-
インラインデバイスを TLS/SSL 処理からオフロードする。TLS/SSL 処理にはコストがかかるため、IPS または NGFW アプライアンスがトラフィックを復号化すると、システム CPU の使用率が高くなる可能性があります。暗号化されたトラフィックが急速に増加するにつれて、これらのシステムは暗号化されたトラフィックの復号化と検査に失敗します。NetScalerは、インラインデバイスをTLS/SSL処理からオフロードするのに役立ちます。その結果、インラインデバイスは大量のトラフィック検査をサポートすることになります。
-
インラインデバイスの負荷分散。NetScalerアプライアンスは、大量のトラフィックがある場合に複数のインラインデバイスの負荷分散を行います。
-
トラフィックのスマートな選択。アプライアンスに流れ込むすべてのパケットは、テキストファイルのダウンロードなど、内容が検査される場合があります。ユーザーは、NetScalerアプライアンスを構成して、検査対象として特定のトラフィック(.exeファイルなど)を選択し、そのトラフィックをインラインデバイスに送信してデータを処理できます。
NetScalerをインラインデバイスと統合する方法
-
クライアントがNetScalerアプライアンスにリクエストを送信します。
-
アプライアンスは要求を受信し、ポリシー評価に基づいてインラインデバイスに送信します。 注:インラインデバイスが 2 つ以上ある場合、アプライアンスはデバイスの負荷分散を行い、トラフィックを送信します。 着信トラフィックが暗号化されたものである場合、アプライアンスはデータを復号化し、コンテンツを検査するためにプレーンテキストとしてインラインデバイスに送信します。
-
インラインデバイスは、データの脅威を検査し、データをドロップ、リセット、またはアプライアンスに戻すかどうかを決定します。
-
セキュリティ上の脅威がある場合、デバイスはデータを修正してアプライアンスに送信します。
-
NetScalerはデータを再暗号化し、リクエストをバックエンドサーバーに転送します。
-
バックエンドサーバーは、NetScalerアプライアンスに応答を送信します。
-
アプライアンスは再びデータを復号化し、検査のためにインラインデバイスに送信します。
-
アプライアンスはデータを再暗号化し、応答をクライアントに送信します
ソフトウェアライセンス
-
ADC Premium
-
ADC Advanced
-
Telco Advanced
-
Telco プレミアム
-
SWG ライセンス
インラインデバイス統合の設定
1 つのインラインデバイスを使用する場合のシナリオ 1
MBF (MAC ベース転送) モードを有効にする
enable ns mode mbf
コンテンツ検査を有効にする
enable ns feature contentInspection LoadBalancing
レイヤ 2 接続方法の追加
set l4param -l2ConnMethod <l2ConnMethod>
set l4param –l2ConnMethod VlanChannel
サービスのコンテンツ検査プロファイルの追加
add contentInspection profile <name> -type InlineInspection -egressInterface <interface_name> -ingressInterface <interface_name>[-egressVlan <positive_integer>] [-ingressVlan <positive_integer>]
add contentInspection profile Inline_profile1 -type InlineInspection -ingressinterface “1/2” -egressInterface “1/3”
IPS-TCP モニターの追加
add lb monitor <monitorName> <type> [-destIP <ip_addr|ipv6_addr>] [-destPort <port>] [-transparent ( YES | NO )]
add lb monitor ips_tcp TCP -destIP 192.168.10.2 -destPort 80 -transparent YES
サービスを追加する
use source IP address (USIP) を「はい」に設定します。useproxyportをNOに設定します。デフォルトでは、ヘルスモニタリングはオンになっており、サービスをヘルスモニターにバインドし、モニターの TRANSPARENT オプションもオンに設定します。コマンドプロンプトで入力します:
add service <Service_name> <IP> TCP * - contentinspectionProfileName <Name> -healthMonitor YES -usip ON –useproxyport OFF
add service ips_service 192.168.10.2 TCP * -healthMonitor YES -usip YES -useproxyport NO -contentInspectionProfileName ipsprof
ヘルスモニターの追加
add lb monitor <name> TCP -destIP <ip address> -destPort 80 -transparent <YES, NO>
add lb monitor ips_tcp TCP -destIP 192.168.10.2 -destPort 80 -transparent YES
サービスをヘルスモニターにバインドする
bind service <name> -monitorName <name>
bind service ips_svc -monitorName ips_tcp
サービスのコンテンツ検査アクションを追加
ifserverdown 次のアクションのいずれかを実行するようにアプライアンスのパラメータを設定できます。
add contentInspection action <name> -type <type> (-serverName <string> [-ifserverdown <ifserverdown>] [-reqTimeout <positive_integer>] [-reqTimeoutAction <reqTimeoutAction>]
add ContentInspection action <action_name> -type InlineINSPECTION -serverName Service_name/Vserver_name>
add ContentInspection action <Inline_action> -type InlineSPECTION –serverName Inline_service1
検査用のコンテンツ検査ポリシーを追加する
add contentInspection policy <policy_name> –rule <Rule> -action <action_name>
add contentInspection policy Inline_pol1 –rule true –action Inline_action
HTTP/SSL タイプのコンテンツスイッチングまたは負荷分散仮想サーバーを追加する
add lb vserver <name> <vserver name> -l2Conn ON
add lb vserver HTTP_vserver HTTP 10.102.29.200 8080 –l2Conn ON
コンテンツ検査ポリシーを HTTP/SSL タイプのコンテンツスイッチング仮想サーバーまたは負荷分散仮想サーバーにバインドする
bind lb vserver <vserver name> -policyName < policy_name > -priority < priority > -type <REQUEST>
bind lb vserver HTTP_vserver -policyName Inline_pol1 -priority 100 -type REQUEST
シナリオ 2: 専用インターフェイスを使用した複数のインラインデバイスの負荷分散
service1 のコンテンツ検査プロファイル 1 を追加
add contentInspection profile <name> -type InlineInspection -egressInterface <interface_name> -ingressInterface <interface_name>[-egressVlan <positive_integer>] [-ingressVlan <positive_integer>]
add contentInspection profile Inline_profile1 -type InlineInspection -ingressinterface “1/2” -egressInterface “1/3”
service2 のコンテンツ検査プロファイル 2 を追加
1/4``1/5 コマンドプロンプトで入力します:
add contentInspection profile <name> -type InlineInspection -egressInterface <interface_name> -ingressInterface <interface_name>[-egressVlan <positive_integer>] [-ingressVlan <positive_integer>]
add contentInspection profile Inline_profile2 -type InlineInspection -ingressinterface “1/4” -egressInterface “1/5”
インラインデバイス 1 にサービス 1 を追加
add service <Service_name_1> <Pvt_IP1> TCP * -contentInspectionProfileName <Inline_Profile_1> -healthmonitor OFF –usip ON –useproxyport OFF
add service Inline_service1 10.102.29.200 TCP 80 -contentInspectionProfileName Inline_profile1 -healthmonitor OFF -usip ON -useproxyport OFF
インラインデバイス 2 にサービス 2 を追加
add service <Service_name_1> <Pvt_IP1> TCP * -contentInspectionProfileName <Inline_Profile_2> -healthmonitor OFF –usip ON –useproxyport OFF
add service Inline_service1 10.29.20.205 TCP 80 -contentInspectionProfileName Inline_profile2 -healthmonitor OFF -usip ON -useproxyport OFF
負荷分散仮想サーバの追加
add lb vserver <vserver_name> TCP <Pvt_IP3> <port>
add lb vserver lb-Inline_vserver TCP *
サービス 1 を負荷分散仮想サーバーにバインドします
bind lb vserver <Vserver_name> <Service_name_1>
bind lb vserver lb-Inline_vserver Inline_service1
サービス 2 を負荷分散仮想サーバーにバインドします
bind lb vserver <Vserver_name> <Service_name_1>
bind lb vserver lb-Inline_vserver Inline_service2
サービスのコンテンツ検査アクションを追加
add contentInspection action <name> -type <type> (-serverName <string> [-ifserverdown <ifserverdown>] [-reqTimeout <positive_integer>] [-reqTimeoutAction <reqTimeoutAction>]
add ContentInspection action < action_name > -type InlineINSPECTION -serverName Service_name/Vserver_name>
add ContentInspection action Inline_action -type InlineINSPECTION –serverName lb-Inline_vserver
検査用のコンテンツ検査ポリシーを追加する
add contentInspection policy <policy_name> –rule <Rule> -action <action_name>
add contentInspection policy Inline_pol1 –rule true –action Inline_action
HTTP/SSL タイプのコンテンツスイッチングまたは負荷分散仮想サーバーを追加する
add lb vserver <name> <vserver name> -l2Conn ON
add lb vserver http_vserver HTTP 10.102.29.200 8080 –l2Conn ON
コンテンツ検査ポリシーを HTTP/SSL タイプの負荷分散仮想サーバーにバインドする
bind lb vserver <vserver name> -policyName < policy_name > -priority <> -type <L7InlineREQUEST | L4Inline-REQUEST>
bind lb vserver http_vserver -policyName Inline_pol1 -priority 100 -type REQUEST
シナリオ 3: 共有インターフェイスを使用した複数のインラインデバイスの負荷分散
共有オプションを有効にして VLAN A をバインドする
bind vlan <id> -ifnum <interface> -tagged
bind vlan 100 –ifnum 1/2 tagged
共有オプションを有効にして VLAN B をバインド
bind vlan <id> -ifnum <interface> -tagged
bind vlan 200 –ifnum 1/3 tagged
共有オプションが有効な状態で VLAN C をバインド
bind vlan <id> -ifnum <interface> -tagged
bind vlan 300 –ifnum 1/2 tagged
共有オプションを有効にして VLAN D をバインド
bind vlan <id> -ifnum <interface> -tagged
bind vlan 400 –ifnum 1/3 tagged
service1 のコンテンツ検査プロファイル 1 を追加
add contentInspection profile <name> -type InlineInspection -egressInterface <interface_name> -ingressInterface <interface_name>[-egressVlan <positive_integer>] [-ingressVlan <positive_integer>]
add contentInspection profile Inline_profile1 -type InlineInspection -ingressinterface “1/2” -egressInterface “1/3” –egressVlan 100 -ingressVlan 300
service2 のコンテンツ検査プロファイル 2 を追加
1/2``1/3
add contentInspection profile <name> -type InlineInspection -egressInterface <interface_name> -ingressInterface <interface_name>[-egressVlan <positive_integer>] [-ingressVlan <positive_integer>]
add contentInspection profile Inline_profile2 -type InlineInspection -ingressinterface “1/2” -egressInterface “1/3” –egressVlan 200 -ingressVlan 400
NetScaler GUIを使用してインラインサービス統合を構成する
-
NetScalerアプライアンスにログオンし、「 構成 」タブページに移動します。
-
「 モードの設定 」ページで、「 Mac ベースの転送」を選択します。
-
「 **OK」をクリックして「**閉じる」をクリックします。
-
「 拡張機能の設定 」ページで、「 コンテンツ検査」を選択します。
-
「 **OK」をクリックして「**閉じる」をクリックします。
-
「コンテンツ検査プロファイル」ページで、「追加」をクリックします。
-
「 コンテンツ検査プロファイルの作成 」ページで、次のパラメータを設定します。
-
プロファイル名。コンテンツ検査プロファイルの名前。
-
タイプ。プロファイルタイプをインライン検査として選択します。
-
出力インターフェイス。アプライアンスがNetScalerからインラインデバイスにトラフィックを送信するインターフェイス。
-
入力インターフェース。アプライアンスがインラインデバイスからNetScalerへのトラフィックを受信するインターフェイス。
-
出力VLAN。トラフィックがインラインデバイスに送信されるインターフェイス VLAN ID。
-
入力側の VLAN。アプライアンスがインラインからNetScalerへのトラフィックを受信するインターフェイスVLAN ID(構成されている場合)。
-
-
トラフィック管理 > 負荷分散 > サービスに移動し 、 追加をクリックします。
-
「 サービス 」ページで、次のパラメータを設定します。
-
サービス名。負荷分散サービスの名前。
-
IP アドレス。ダミー IP アドレスを使用してください。注:どのデバイスも IP アドレスを所有している必要はありません。
-
プロトコル。プロトコルタイプを TCP として選択します。
-
ポート。* を入力してください
-
ヘルスモニタリング。サービスを TCP タイプのモニターにバインドする場合にのみ、このオプションをオフにして有効にしてください。モニターをサービスにバインドする場合は、モニターの
TRANSPARENTオプションをオンにする必要があります。モニタの追加方法とサービスにバインドする方法については、手順 14 を参照してください。 -
[OK] をクリックします。
-
-
「 設定 」セクションで以下を編集し、「 **OK」**をクリックします。
-
プロキシポートを使用:オフにする
-
送信元 IP アドレスを使用:有効にする
-
-
「 プロファイル 」セクションに移動し、インラインコンテンツ検査プロファイルを追加して「 **OK」**をクリックします。
-
-
名前:モニターの名前
-
タイプ:TCP タイプを選択
-
送信先IP、ポート:送信先IPアドレスとポート。
-
透明:オンにする
注:インラインデバイスのステータスを監視するには、監視パケットがインラインデバイスを経由する必要があります。 -
-
**[作成]**をクリックします。
-
[完了] をクリックします。
-
サーバーの詳細を入力したら、「 OK」 をクリックし、もう一度「 **OK」**をクリックします。
-
負荷分散仮想サーバーのトラフィック設定セクションで 、レイヤー2パラメーターをオンにします。
-
「 ポリシー 」セクションに移動し、「+」アイコンをクリックしてコンテンツ検査ポリシーを設定します。
-
「ポリシーの選択」 ページで、「コンテンツ検査」を選択します。[続行] をクリックします。
-
「 ポリシーバインディング 」セクションで、「 追加 」をクリックしてコンテンツ検査ポリシーを追加します。
-
コンテンツ検査ポリシーの作成ページで 、インラインコンテンツ検査ポリシーの名前を入力します。
-
「 アクション 」フィールドで、「 追加 」をクリックしてインラインコンテンツ検査アクションを作成します。
-
「 CI アクションの作成 」ページで、次のパラメータを設定します。
-
Name:コンテンツ検査インラインポリシーの名前。
-
タイプ。タイプをインライン検査として選択します。
-
サーバー。サーバー/サービスをインラインデバイスとして選択します。
-
サーバーがダウンした場合。サーバがダウンした場合のオペレーションを選択します。
-
リクエストのタイムアウト。タイムアウト値を選択します。デフォルト値を使用できます。
-
タイムアウトアクションの要求。タイムアウトアクションを選択します。デフォルト値を使用できます。
-
-
**[作成]**をクリックします。
-
「 CI ポリシーの作成 」ページで、その他の詳細を入力します。
-
「 **OK」をクリックして「**閉じる」をクリックします。