IPsec
IP-Sec¤Îµ»ö°ìÍ÷
IP-Sec´ØÏ¢¤Î¸á¸åÌäÂê
IPsec¤Î»ÅÁȤß
IPsec¤ÎÌäÂê
IKE(Internet Key Excange)
¡Ú¸áÁ°ÌäÂê¡Û
Ê¿À®18ǯÅÙ¡¡¸áÁ°¡¡Ìä52¡¡ÄÌ¿®¤Î°Å¹æ²½
Ê¿À®17ǯÅÙ¡¡¸áÁ°¡¡Ìä40¡¡¥¤¥ó¥¿¡¼¥Í¥Ã¥ÈVPN
¡ÊSV)Ê¿À®19ǯÅÙ¡¡¸áÁ°¡¡Ìä12¡¡
°Ê²¼¤ÎËܤò»²¹Í¤Ë¤·¤Æ¤Þ¤¹¡£
IPsecŰÄìÆþÌç (ñ¹ÔËÜ)
½ÐÈǼҡ§³ô¼°²ñ¼ÒæÆ±Ë¼Ò
£±¡¥SA¡ÊSecurity¡¡Association)
£²¡¥¥»¥¥å¥ê¥Æ¥£¥×¥í¥È¥³¥ë
£³¡¥¥«¥×¥»¥ë²½¥â¡¼¥É
£´¡¥IKE(Internet Key Excange)
£µ¡¥¥»¥ì¥¯¥¿
¡Ê¾ÜºÙ¤Ï¸å¤Û¤É¡Ë
IPsec¤Î»ÅÁȤß

¡Ê¥Þ¥ë¥³¥Ý¡¼¥í¡Ë
IPsec¤ÏÆñ¤·¤¤¤¬¡¢°ì²óÍý²ò¤·¤Æ¤·¤Þ¤¨¤Ð´Êñ¤Ç¤¢¤ë¡£
ñ¤Ë¡Ö¥È¥ó¥Í¥ë¡×¤È¤¤¤¦³µÇ°¤Ç³Ð¤¨¤ë¤Î¤Ç¤Ï¤Ê¤¯¡¢¥Ñ¥±¥Ã¥È¥ì¥Ù¥ë¤Ç¤É¤¦¤Ê¤ë¤«¤òÍý²ò¤·¤Æ¤Û¤·¤¤¡£
ËܼÁ¤òÍý²ò¤¹¤ë¤³¤È¤¬¡¢¹ç³Ê¤Î¶áÆ»¤Ç¤¢¤ë¡£
°Ê²¼¤ÏIPsec¤Î¿Þ¤Ç¤¢¤ë¤¬¡¢Ä̾ï¤Î¥ë¡¼¥Æ¥£¥ó¥°¤Î¾ì¹ç¤È¤Î°ã¤¤¡¢¥Ñ¥±¥Ã¥È¹½Â¤¤òÍý²ò¤·¤Ê¤¬¤é¸«¤Æ¤Û¤·¤¤¡£

¼ÁÌä¡
¥ë¡¼¥Æ¥£¥ó¥°¤Î¤È¤¤Ï¡¢¤É¤Î¤è¤¦¤Êư¤¤Ë¤Ê¤ë¤«¡©¥Ñ¥±¥Ã¥È¹½Â¤¤ò´Þ¤á¤Æ¼¨¤·¤Æ¤Û¤·¤¤¡£
¼ÁÌä¢
IPsec¤Î¤È¤¤Î¥Ñ¥±¥Ã¥È¹½Â¤¤òPC1¤ò½Ð¤¿Ä¾¸å¤ÈIPsec¥È¥ó¥Í¥ë¤Î´Ö¡¢PC2¤ÎľÁ°¤Î3¥Ñ¥¿¡¼¥ó¤Ç¼¨¤·¤Æ¤Û¤·¤¤¡£
¼ÁÌä£
NAT¥È¥é¥Ð¡¼¥µ¥ë¤Ë¤Ä¤¤¤Æ¾Ü¤·¤¯ÀâÌÀ¤·¤Æ¤Û¤·¤¤¡£
¼ÁÌä¤
¤½¤â¤½¤â¡¢IPsec¤¬É¬Íפˤʤ俷аޤò¹Í¤¨¤Þ¤·¤ç¤¦¡£
IP-VPN¥µ¡¼¥Ó¥¹¤ä¹°è¥¤¡¼¥µ¥µ¡¼¥Ó¥¹¤Ç¤Ï¤Ê¤¯¡¢IPsec¤¬µá¤á¤é¤ì¤¿¤Î¤Ï¤Ê¤¼¤«¡©
IPsec¤Ï¥È¥ó¥Í¥ë¤Ç¤Ï¤¢¤ê¤Þ¤»¤ó
IPsec¤ÏÆñ¤·¤¤¡£
Æñ¤·¤¯¤·¤Æ¤¤¤ë¤Î¤¬¡¢³Æ½ñ¤¬¡Ö¥È¥ó¥Í¥ë¡×¤È¤¤¤¦É½¸½¤ò»È¤Ã¤Æ¤¤¤ë¤«¤é¤À¡£
¥È¥ó¥Í¥ë¤È¤¤¤¦³µÇ°¤Ï¼Î¤Æ¤Þ¤·¤ç¤¦¡£¤Ê¤¼¤Ê¤é¡¢IPsec¤ÎÄÌ¿®¤Ë¤ª¤¤¤Æ¡¢¥È¥ó¥Í¥ë¤Ï
¹½ÃÛ¤µ¤ì¤Æ¤¤¤Ê¤¤¤«¤é¤Ç¤¹¡£¤½¤â¤½¤â¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤ÎÀ¤³¦¤Ç¥È¥ó¥Í¥ë¤Ã¤Æ²¿¡©
¥È¥ó¥Í¥ë¤È¤¤¤¦ÀâÌÀ¤ò¤¹¤ë¤«¤é¡¢
¡Ö¥È¥ó¥Í¥ë¤òºî¤ì¤Ð¡¢¤½¤ÎÃæ¤Ï¥»¥¥å¥ê¥Æ¥£¤¬Êݤ¿¤ì¤Æ¤¤¤ë¤ó¤Ç¤¹¤è¤Í¡£¡×¡¦¡¦¡¦¥È¥ó¥Í¥ë¤ÎÃæ¤Ã¤Æ²¿¡©
¡ÖÄÌ¿®ÍѤΥե§¡¼¥º£²¤Î¥È¥ó¥Í¥ë¤ÎÃæ¤Ë¥Ç¡¼¥¿¤òÄ̤»¤Ð¤¤¤¤¤ó¤¸¤ã¤Ê¤¤¤Ç¤¹¤«¡©¡×¡¦¡¦¡¦
¥Õ¥§¡¼¥º£²¤Ë¥È¥ó¥Í¥ë¤Ï¤Ç¤¤Æ¤¤¤Þ¤»¤ó¡£
¤È¤¤¤Ã¤¿¡¢°ã¤¦µ¿Ìä¤äÌ·½â¤¬¤Ç¤Æ¤¤Þ¤¹¡£
¥È¥ó¥Í¥ë¤Ï¼Î¤Æ¤Æ¤¯¤À¤µ¤¤¡£
¢¡¼¡¤Î²òÀâ¤ÇÍý²ò¤·¤Æ¤¯¤À¤µ¤¤¡£
£±¡¥¸°¸ò´¹¡¡¡¦¡¦¡¦UDP¤ÎIKE¥Ñ¥±¥Ã¥È¤ò¸ò´¹¡£¥È¥ó¥Í¥ë¤Ï¤Ç¤¤Þ¤»¤ó¡£
¥¤¥ó¥¿¡¼¥Í¥Ã¥È¾å¤Ç°ÂÁ´¤ËÄÌ¿®¤ò¤¹¤ë¤¿¤á¤Ë¡¢¤ª¸ß¤¤¤òǧ¾Ú¤·¤¿¤ê¡¢°Å¹æÊý¼°¤ò·è¤á¤Þ¤¹¡£
¥Õ¥§¡¼¥º£±¤È¥Õ¥§¡¼¥º£²¤Ëʬ¤«¤ì¤Þ¤¹¡£
¥Õ¥§¡¼¥º¤Ï£±¤Ä¤Ç¤â¤¤¤¤¤Î¤Ç¤¹¤¬¡¢¤è¤ê¹â®¤Ë¤¹¤ë¤¿¤á¤Ëʬ¤±¤Æ¤Þ¤¹¡£¡Ê¤³¤Î¥ì¥Ù¥ë¤Ç»ß¤á¤Æ¤ª¤¤Þ¤¹¡£¡Ë
£²¡¥IPsec¤ÎÄÌ¿®¡¦¡¦¡¦ESP¤Î¥Ñ¥±¥Ã¥È¡£Ä̾ï¤Î¥×¥í¥È¥³¥ë¤¬TCP¤äUDP¤Ç¤Ï¤Ê¤¯ESP¤Î¥Ñ¥±¥Ã¥È¤Ç¤¹¡£
ÅöÁ³¡¢¥È¥ó¥Í¥ë¤Ï¤Ç¤¤Þ¤»¤ó¡£
¸°¸ò´¹¤Î¥Õ¥§¡¼¥º£²¤Ç·è¤á¤¿°Å¹æ²½¤äǧ¾Ú¤ÎÊý¼°¤ÇIPsec¤ÎÄÌ¿®¤ò¤·¤Þ¤¹¡£
¢¡ÍѸì
»î¸³Âкö¤È¤·¤Æ¡¢¤¤¤¯¤Ä¤«³Ð¤¨¤Þ¤·¤ç¤¦¡£
¡Ê£±¡ËSA¡ÊSecurity Assosiation)
¥Õ¥§¡¼¥º£±¡§ISAKMP¡¡SA¡¢¤Ä¤Þ¤êÀ©¸æÍѤÎSA¤òºî¤ë¡£¡¦¡¦¡¦¤³¤ÎSA¤ò¥Õ¥§¡¼¥º£²¤¬ÍøÍѤ¹¤ë¡£
¥Õ¥§¡¼¥º£²¡§IPsec¡¡SA¡¢¤Ä¤Þ¤êÄÌ¿®ÍѤÎSA¤òºî¤ë¡£¡¦¡¦¡¦¤³¤ÎSA¤òIPsecÄÌ¿®¤¬»ÈÍѤ¹¤ë¡£
¡Ê£²¡ËIKE(Internet Key Excange)
IKE¤Ïɬ¿Ü¤Ç¤Ï¤Ê¤¤¡£¤·¤«¤·¡¢»È¤¦¾ì¹ç¤¬Â¿¤¤¡£
Íפϡ¢IPsecÄÌ¿®¤Î¤¿¤á¤Î¸°¤¬Å¬Àڤˤʤµ¤ì¤ì¤Ð¤è¤¤¡£
£²¤Ä¤Î¥Õ¥§¡¼¥º¤Ç¥«¥®¸ò´¹¤ò¤¹¤ë¡£
¡Ê£³¡Ë¥×¥í¥È¥³¥ë
¡ESP(Encapsulating Security Payload)¡§°Å¹æ²½¡Üǧ¾Ú¡¦¡¦¡¦¤³¤Ã¤Á¤ò³Ð¤¨¤ì¤Ð¤è¤¤¡£
¢AH(Authentication Header)¡§Ç§¾Ú¤Î¤ß¡¦¡¦¡¦¤³¤Ã¤Á¤Ï»È¤ï¤ì¤Ê¤¤¡£
¡Ê£´¡Ë¥â¡¼¥É
¡¥È¥é¥ó¥¹¥Ý¡¼¥È¥â¡¼¥É¡§Ã¼Ëö´Ö
¢¥È¥ó¥Í¥ë¥â¡¼¥É¡§VPNÁõÃÖ´Ö¡¦¡¦¡¦¤³¤Ã¤Á¤¬¼çή¡£¤Ê¤¼¤«¡£
¥ë¡¼¥¿¤ËÀßÄꤹ¤ì¤Ð¡¢PC¤¹¤Ù¤Æ¤ËÀßÄꤹ¤ëɬÍפ¬¤Ê¤¤¤«¤é¡£
IKE(Internet Key Excange)
¥Õ¥§¡¼¥º£±¤ÇISAKAMP¡¡SAÍѤθ°¸ò´¹¤ò¼Â»Ü¤¹¤ë¡£
°ÂÁ´¤ËÈëÌ©¸°¤ò¸ò´¹¤¹¤ë¤¿¤á¤Ë¡ÖDiffie-Hellman¡Ê¥Ç¥£¥Õ¥£¡¼¥Ø¥ë¥Þ¥ó¡Ë¡×¤È¤¤¤¦µ»½Ñ¤òÍøÍѤ·¤Æ¤¤¤ë¡£
¢¨»ä¤Ï¿ô³Ø¹¥¤¤Î¿Í´Ö¤Ç¤¢¤Ã¤¿¤¿¤á¡¢Diffie-Hellmam¤Î
»ÅÁȤߤÏÎÞ¤¬½Ð¤ë¤Û¤É´¶Æ°¤·¤¿¡£
¥Õ¥§¡¼¥º£²¤Ç¤Ï
¥Õ¥§¡¼¥º£±¤ÇºîÀ®¤·¤¿SA¤ÎÃæ¤Ç¸°¤òºîÀ®¤¹¤ë¡£
Aggressive¡Ê¥¢¥°¥ì¥Ã¥·¥Ö¡Ë¥â¡¼¥É
¡Ê¥³¥í¥ó¥Ö¥¹¡Ë
¥ê¥â¡¼¥È¥¢¥¯¥»¥¹·¿VPN¤Î¾ì¹ç¤Ë¤â¡¢¥µ¥¤¥È´ÖÀܳ¤ÈƱ¤¸¤è¤¦¤Ë³Æ¥¯¥é¥¤¥¢¥ó¥È¤ÎIP¥¢¥É¥ì¥¹¤ò¸ÇÄê¤Ë¤Ç¤¤ë¤¬¡¢°ìÈÌŪ¤Ç¤Ï¤Ê¤¤¡£
¤½¤³¤Ç¡¢XAUTH¡ÊeXtended AUTHentication¡Ë¤È¤¤¤¦IKE¤Î³ÈÄ¥µ¡Ç½¤Çǧ¾Ú¤ò¶¯²½¤¹¤ë¡£
¡¦Ç§¾Ú¤Ë¤ÏVPNÁõÃÖÆâÉô¤ÎDB¤òÍøÍѤ·¤Æ¤â¤¤¤¤¤·¡¢RADIUS¤âÍøÍѲÄǽ¡£
¢£ºÆÅÙ¼ÁÌä
¤Ê¤¼¡¢¥ê¥â¡¼¥È¥¢¥¯¥»¥¹¤Î¾ì¹ç¤À¤±¡¢Xauth¤¬É¬ÍפʤΤ«¡©
¢£Íýͳ
¡¦Main¥â¡¼¥É¤Î¾ì¹ç¡¢Preshared-Key¤Ë²Ã¤¨¡¢Î¾¼Ô¤ÎIP¥¢¥É¥ì¥¹¤âǧ¾Ú¤Î°ì¤Ä¤Ç¤¢¤ë¡£
¡¦Aggressive¥â¡¼¥É¡Ê¥ê¥â¡¼¥È¥¢¥¯¥»¥¹¤Î·ÁÂ֡ˤò¹Í¤¨¤ë¤È¡¢¥¯¥é¥¤¥¢¥ó¥È¤ÎIP¥¢¥É¥ì¥¹¤Ë¤è¤ëǧ¾Ú¤Ïº¤Æñ¡£
¡¦¤½¤¦¤¹¤ë¤ÈPreshared-Key¤Ê¤É¡ÊIP¥¢¥É¥ì¥¹¤ËÈæ¤Ù¤Æ¡ËÅð¤Þ¤ì¤ä¤¹¤¤Ç§¾Ú¤Ë¤Ê¤Ã¤Æ¤·¤Þ¤¦¡£¤è¤Ã¤ÆÇ§¾Ú¤ò¶¯²½¤¹¤ë¤¿¤á¤ËXauth¤òÍøÍѤ¹¤ë¡£
IPsec¤ÎÌäÂê
¢IKE¤Î¥Ñ¥±¥Ã¥È¹½Â¤¤ò½ñ¤±
£IP-sec¤Î¥«¥×¥»¥ë²½¤Î2¤Ä¤Î¥â¡¼¥É¤ò½Ò¤Ù¤è¡£
¤°Å¹æ²½¥¢¥ë¥´¥ê¥º¥à¤ò£³¤Ä°Ê¾å½Ò¤Ù¤è¡£
¥Ç§¾Ú¥¢¥ë¥´¥ê¥º¥à¤ò£²¤Ä°Ê¾å½Ò¤Ù¤è¡£
¦SA¤È¤Ï²¿¤«¡©£²£°»ú¤Ç½Ò¤Ù¤è¡£
§SA¤òÁªÄꤹ¤ëȽÃÇ´ð½à¤Ç¤¢¤ê¡¢¥Õ¥£¥ë¥¿¤È¤·¤Æµ¡Ç½¤¹¤ë¤â¤Î¤Ï²¿¤«¡©
¨ISAKMP SA¤ÈIPsec SA¤ò¤ï¤±¤ëÍýͳ¤Ï¡©Â³¤¤òÆÉ¤à
Ê¿À®18ǯÅÙ¡¡¸áÁ°¡¡Ìä52¡¡ÄÌ¿®¤Î°Å¹æ²½
¥¢¡¡IPsec¤Î¥È¥é¥ó¥¹¥Ý¡¼¥È¥â¡¼¥É¤Ç¤Ï¡¢¥²¡¼¥È¥¦¥§¥¤´Ö¤ÎÄÌ¿®·ÐÏ©¾å¤À¤±¤Ç¤Ï¤Ê¤¯¡¢È¯¿®Â¦¥·¥¹¥Æ¥à¤È¼õ¿®Â¦¥·¥¹¥Æ¥à¤È¤Î´Ö¤ÎÁ´·ÐÏ©¾å¤Ç¥á¥Ã¥»¡¼¥¸¤¬°Å¹æ²½¤µ¤ì¤ë¡£
¥¤¡¡LADP¥¯¥é¥¤¥¢¥ó¥È¤¬LDAP¥µ¡¼¥Ð¤ËÀܳ¤¹¤ë¤È¤¡¢¤½¤ÎÄÌ¿®ÆâÍÆ¤Ï°Å¹æ²½¤¹¤ë¤³¤È¤¬¤Ç¤¤Ê¤¤¡£
¥¦¡¡S/MIME¤Ç°Å¹æ²½¤·¤¿ÅŻҥ᡼¥ë¤Ï¡¢¼õ¿®Â¦¤Î¥á¡¼¥ë¥µ¡¼¥ÐÆâ¤Ë³ÊǼ¤µ¤ì¤Æ¤¤¤ë´Ö¤Ï¡¢¥á¡¼¥ë´ÉÍý¼Ô¤¬Ê¿Ê¸¤È¤·¤Æ¸«¤ë¤³¤È¤¬¤Ç¤¤ë¡£
¥¨¡¡SSL¤ò»ÈÍѤ·¤ÆÀܳ¤·¤¿¤È¤¡¢°Å¹æ²½¤µ¤ì¤¿HTMLʸ½ñ¤Ï¥Ö¥é¥¦¥¶¤Ç¥¥ã¥Ã¥·¥å¤ÎÍ̵¤¬ÀßÄê¤Ç¤¤º¥Ç¥£¥¹¥¯Æâ¤Ëɬ¤ºÊݸ¤µ¤ì¤ë¡£
¡ÊSV)Ê¿À®19ǯÅÙ¡¡¸áÁ°¡¡Ìä12¡¡

¥¢¡¡ESP¥Ø¥Ã¥À¤«¤éESP¥È¥ì¡¼¥é¤Þ¤Ç
¥¤¡¡TCP¥Ø¥Ã¥À¤«¤éESPǧ¾Ú¥Ç¡¼¥¿¤Þ¤Ç
¥¦¡¡¥ª¥ê¥¸¥Ê¥ëIP¥Ø¥Ã¥À¤«¤éESP¥È¥ì¡¼¥é¤Þ¤Ç
¥¨¡¡¿·IP¥Ø¥Ã¥À¤«¤éESPǧ¾Ú¥Ç¡¼¥¿¤Þ¤Ç
