IceWall †IceWall¤È¤Ï †Web¥Ù¡¼¥¹¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥óÀ½Éʤǡ¢Web¥µ¡¼¥Ð¡¼¤Îǧ¾Ú¤ò°ì¸µ´ÉÍý¤¹¤ë IceWall¤Î´ðËܹ½À® †
¥Õ¥©¥ï¡¼¥À¤ÎÄÌ¿®¥È¥é¥ó¥¶¥¯¥·¥ç¥ó †¡¥¯¥é¥¤¥¢¥ó¥È¤«¤é¥Õ¥©¥ï¡¼¥À¤Ø¥¢¥¯¥»¥¹¤·¡¢¥í¥°¥¤¥ó¥Õ¥©¡¼¥à¤òɽ¼¨¤¹¤ë¡Ê¥í¥°¥¤¥óºÑ¤ß¤Ç¤¢¤ì¤Ð¤¤Ø¡Ë ¥¤¥ó¥¹¥È¡¼¥ë †Á´¤Æ/opt/icewall-sso/¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤µ¤ì¤ë rpm -iv --nodeps IceWall-SSO-certd_<ǧ¾Ú·Á¼°>_<¥Ð¡¼¥¸¥ç¥ó>_<¥¢¡¼¥¥Æ¥¯¥Á¥ã>.rpm rpm -iv --nodeps IceWall-SSO-dfw_<¥Ð¡¼¥¸¥ç¥ó>_<¥¢¡¼¥¥Æ¥¯¥Á¥ã>.rpm chown -R iwadmin /opt/icewal-sso/certd¡¡¡¡¡¡¡¡¡Å¡Åcertd¤ò¼Â¹Ô¤¹¤ë¥æ¡¼¥¶¡¼¤Î¸¢¸Â¤Ë¤¹¤ë chown -R apache:apache /opt/icewall-sso/dfw¡¡ ¡Å¡ÅApache¤ò¼Â¹Ô¤¹¤ë¥æ¡¼¥¶¡¼¤Î¸¢¸Â¤Ë¤¹¤ë Apache¤ÎÀßÄê †httpd.conf¤Ë°Ê²¼¤Îʸ¸À¤òÄɲ乤ë Alias /img/ "/opt/icewall-sso/dfw/html/image/" SetEnv LD_LIBRARY_PATH "/opt/icewall-sso/lib/dfw:/usr/lib64" ScriptAlias /fw/ "/opt/icewall-sso/dfw/cgi-bin/" <Directory "/opt/icewall-sso/dfw/cgi-bin/"> AllowOverride All Options ExecCGI SetHandler cgi-script Order allow,deny Allow from all </Directory> ¥Ç¥£¥ì¥¯¥È¥ê¹½À® †/opt/icewall-sso/ ¡¡certd¡¡¡¡¡¡¡¡¡¡¡¡Ç§¾Ú¥â¥¸¥å¡¼¥ë ¡¡¡¡bin¡¡¡¡¡¡¡¡¡¡¡¡Ç§¾Ú¥â¥¸¥å¡¼¥ë¤Î¥×¥í¥°¥é¥à¤ä¥¹¥¯¥ê¥×¥È ¡¡¡¡config¡¡¡¡¡¡¡¡ ǧ¾Ú¥â¥¸¥å¡¼¥ë¤ÎÀßÄê¥Õ¥¡¥¤¥ë ¡¡dfw¡¡¡¡¡¡¡¡¡¡¡¡¡¡¥Õ¥©¥ï¡¼¥À ¡¡¡¡cgi-bin¡¡¡¡¡¡¡¡¥Õ¥©¥ï¡¼¥À¤ÎCGI¥×¥í¥°¥é¥àµÚ¤ÓÀßÄê¥Õ¥¡¥¤¥ë ¡¡¡¡chtml¡¡¡¡¡¡¡¡¡¡¥í¥°¥¤¥ó¤ä¥¨¥é¡¼²èÌ̤Υ³¥ó¥Æ¥ó¥Ä¡Ê·ÈÂÓÍÑ¡Ë ¡¡¡¡html¡¡¡¡¡¡¡¡¡¡ ¥í¥°¥¤¥ó¤ä¥¨¥é¡¼²èÌ̤Υ³¥ó¥Æ¥ó¥Ä¡ÊPCÍÑ¡Ë ¡¡¡¡ IceWall¥·¥¹¥Æ¥àÍѥơ¼¥Ö¥ë¤ÎºîÀ® †$ cd /opt/ice-wall/tools $ sqlplus UID/PASS@oracleSID SQL > @cre_tbl_test.sql¡¡¡¡¡¡ ¡Å¡ÅICEWALLTEST¥Æ¡¼¥Ö¥ë¤òºîÀ®¤¹¤ë¡£Ì¾Á°¤òÊѤ¨¤¿¤±¤ì¤ÐSQL¤ò½¤Àµ¤¹¤ë SQL > @cre_tbl_history.sql¡¡¡¡¡Å¡ÅHISTORY¥Æ¡¼¥Ö¥ë¤òºîÀ®¤¹¤ë SQL > @cre_sequence.sql ICEWALLTEST¡¡¤Î¥«¥é¥à ̾Á° NULL? ·¿ -------------------------------- -------- ---------------------------- USERID NOT NULL VARCHAR2(20) PASSWD NOT NULL CHAR(37) PASSCHANGE NOT NULL CHAR(1) PASSWDEXP CHAR(14) PASSWDHIS CHAR(37) CHGDATE CHAR(14) LOGONDATE CHAR(14) LASTDATE CHAR(14) LOGONFAIL CHAR(14) FAILCOUNT NOT NULL NUMBER(38) LOCKOUT NOT NULL CHAR(1) LOGONSTOP NOT NULL CHAR(1) LOCKDATE CHAR(14) LOGSTATUS NOT NULL CHAR(1) ºîÀ®¤·¤¿¥Æ¡¼¥Ö¥ë¤È¥«¥é¥à¤ò¥Þ¥Ã¥Ô¥ó¥°¤¹¤ë †¤É¤Î¥«¥é¥à¤ò¥æ¡¼¥¶¡¼Ì¾¡¢¥Ñ¥¹¥ï¡¼¥É¤È¤¹¤ë¤«ÄêµÁ¤·¡¢IceWallǧ¾Ú¾ðÊó¤È¤·¤Æ¥Þ¥Ã¥Ô¥ó¥°¤¹¤ë UID=USERID¡¡¡¡¡¡¡¡¡¡¡¡ ¥æ¡¼¥¶¡¼ID PASSWORD=PASSWD¡¡¡¡¡¡¡¡¥Ñ¥¹¥ï¡¼¥É PWDEXPDATE=PASSWDEXP¡¡ ¥Ñ¥¹¥ï¡¼¥É͸ú´ü¸Â PWDHISTORY=PASSWDHIS¡¡ ¥Ñ¥¹¥ï¡¼¥ÉÍúÎò PCHGOK=PASSCHANGE¡¡¡¡¡¡¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹ON/OFF¡Ê1¤ÇON¡Ë PCHGDATE=CHGDATE¡¡¡¡¡¡ ¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹Æü PLOGINDATE=LOGONDATE¡¡ ¥í¥°¥¤¥ó»þ¹ï LLOGINDATE=LASTDATE¡¡¡¡ºÇ½ª¥í¥°¥¤¥ó»þ¹ï FLOGINDATE=LOGONFAIL¡¡ ¥í¥°¥¤¥ó¼ºÇÔ»þ¹ï PWDRETRY=FAILCOUNT¡¡¡¡ ¥Ñ¥¹¥ï¡¼¥É¥ê¥È¥é¥¤²ó¿ô PWDLOCK=LOCKOUT¡¡¡¡¡¡¡¡¥¢¥«¥¦¥ó¥È¥í¥Ã¥¯Í̵¡Ê1¤Ç¥í¥Ã¥¯¡Ë LOGINOK=LOGONSTOP¡¡¡¡¡¡¥í¥°¥¤¥óOK/NG¡Ê1¤ÇOK¡Ë LOCKDATE=LOCKDATE¡¡¡¡¡¡¥¢¥«¥¦¥ó¥È¥í¥Ã¥¯»þ¹ï LOGINSTAT=LOGSTATUS¡¡¡¡¥í¥°¥¤¥ó¥¹¥Æ¡¼¥¿¥¹¡Ê1¤Ç¥í¥°¥¤¥óÃæ¡Ë IceWall¥æ¡¼¥¶¡¼¤ÎºîÀ® †/opt/icewal-sso/tools/°Ê²¼¤Î3¤Ä¤Î¥Õ¥¡¥¤¥ë¤ò»ÈÍѤ¹¤ë
# ./mkuser TEMPLATE.sql DATA.txt > outputfile.sql $ sqlplus UID/PASS@oracleSID @outputfile.sql ǧ¾Ú¥â¥¸¥å¡¼¥ë¤Î´ðËÜÀßÄê †»ÈÍѤ¹¤ëDBµÚ¤ÓTABLE¤òÄêµÁ¤¹¤ë¡£ÄêµÁÆâÍƤϥե¡¥¤¥ë̾¤ËÀâÌÀ¤¢¤ê IceWallǧ¾Ú¤Ë´Ø¤¹¤ëÀßÄê †
¥í¥°¤Ë´Ø¤¹¤ëÀßÄê †
¥í¥°¥¤¥ó¥í¥°¥¢¥¦¥È¡¦¥Ñ¥¹¥ï¡¼¥É¥Ý¥ê¥·¡¼¤Ë´Ø¤¹¤ëÀßÄê †
¥Ñ¥Õ¥©¡¼¥Þ¥ó¥¹Ä´À°¤Ë´Ø¤¹¤ëÀßÄê †
¥¢¥¯¥»¥¹¥°¥ë¡¼¥×¤ÎÄêµÁ †¥æ¡¼¥¶¡¼¤ÏÆÃÄê¤Î¥°¥ë¡¼¥×¤Ëɬ¤º½ê°¤µ¤»¤ëɬÍפ¬¤¢¤ë USERID¤ÎÃͤËuser¤¬ÉÕÍ¿¤·¤Æ¤¤¤ëREMOTE_ADDR¤¬192.168.11.0/24¤Î¥æ¡¼¥¶¡¼¤ònormal¥°¥ë¡¼¥×¤È¤¹¤ë †normal,USERID=user.*&REMOTE_ADDR=192.168.11.1-192.168.11.254 Àµµ¬É½¸½µÚ¤Ó¡¢ÏÀÍý¼° ()¡¡!¡¡&¡¡| ¤Î»ÈÍѤ¬²Äǽ ¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¤Î¥¢¥¯¥»¥¹ÄêµÁ †ÆÃÄê¤Î¥°¥ë¡¼¥×¤ËÂФ·¤Æ¡¢¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¤ÎÀܳµö²Ä¤òÄêµÁ¤¹¤ë normal³î¤Äspecil¤Ë°¤¹¤ë¥æ¡¼¥¶¡¼¤ËÂФ·192.168.11.2¤Ø¤Î¥¢¥¯¥»¥¹¤òµö²Ä¤¹¤ë †http://192.168.11.2/=normal&special ǧ¾Ú¥â¥¸¥å¡¼¥ë¤ÎÀ©¸æ †/opt/icewall-sso/certd/bin ¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¤Î¥¹¥¯¥ê¥×¥È¤Ë¤ÆÀ©¸æ¤ò¹Ô¤¦
info-cert †cert.conf¤ÎACCESS¤Ç»ØÄꤷ¤¿¥í¥°¡Ê¥Ç¥Õ¥©¥ë¥È¤Ï/opt/icewall-sso/logs/cert.log¡Ë¤Ë¼Â¹Ô»þ¤Î²ÔÆ°¾õ¶·¤òµÏ¿¤¹¤ë
¥Õ¥©¥ï¡¼¥À¤ÎÀßÄê †¡Ú¥Õ¥¡¥¤¥ë¡Û /opt/icewall-sso/dfw/cgi-bin/dfw.conf ǧ¾Ú¥â¥¸¥å¡¼¥ë(certd)¤Î°ÌÃ֤ȥ¢¥¯¥»¥¹¥Ý¡¼¥È¤Î»ØÄê †CERT=ǧ¾Ú¥â¥¸¥å¡¼¥ë¥Û¥¹¥È:¥Ý¡¼¥ÈÈÖ¹æ ¥Ý¡¼¥ÈÈÖ¹æ¤Ï cert.conf ¤Î PORT ¤ÈƱ¤¸ÈÖ¹æ¤Ë¤¹¤ë¤³¤È ¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Î¥¨¥¤¥ê¥¢¥¹Ì¾¤È°ÌÃÖ»ØÄê †¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¥¢¥¯¥»¥¹¤¹¤ëºÝ¤ÎURL¤Ï°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤ë http://forwarder.com/fw/dfw/back01/index.html ¡¡¡¡¡¡ ¡¡¡¡¡¡¡¡¡¡¡¡¡¢¡¡¡¡ £¡¡¡¡ ¤ ¡¥Õ¥©¥ï¡¼¥À¤ÎFQDN HOST=back01=192.168.11.2¡¡¡Å¡Å192.168.11.2¤Î¥¨¥¤¥ê¥¢¥¹Ì¾¤òback01¤È¤¹¤ë SHOST=back01=192.168.11.3 ¡Å¡Å192.168.11.3¤Î¥¨¥¤¥ê¥¢¥¹Ì¾¤òback02¤È¤¹¤ë ¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¤Î¥¢¥¯¥»¥¹ÊýË¡¤Î»ØÄê †HOST/SHOST¤ÈÂФò¤Ê¤¹·Á¤Ç¡¢¤½¤ì¤¾¤ì¤Î¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¤Î¥¢¥¯¥»¥¹¤¹¤ëºÝ¤Î¾ò·ï¤ò»ØÄꤷ¤¿¡Ö¥Û¥¹¥ÈÀßÄê¡×¥Õ¥¡¥¤¥ë¤ò»ØÄꤹ¤ë SVRFILE=back01,./sample.conf SVRFILE=back02,./sample.conf html.conf †¥í¥°¥¤¥ó²èÌ̤ʤɡ¢¤É¤Î¥Õ¥¡¥¤¥ë¤ò»ÈÍѤ¹¤ë¤«ÄêµÁ¤¹¤ë
¾ðÊó·Ñ¾µµ¡Ç½¡Êǧ¾ÚÂå¹Ô¡Ë †IceWall¤Çǧ¾Ú¤·¤¿ºÝ¤Î¾ðÊó¤òÍѤ¤¤Æ¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤ÎBASICǧ¾Ú¤äFORMǧ¾Ú¤ò¼«Æ°Åª¤Ë¹Ô¤ï¤»¤ëµ¡Ç½ BASICǧ¾Ú¤ÎÂå¹Ô †¥Û¥¹¥ÈÀßÄê¥Õ¥¡¥¤¥ë¤ò¥³¥Ô¡¼¤·ÊÔ½¸¤¹¤ë cd /opt/icewall-sso/certd/config cp -ip sample.conf back01.conf vi back01.conf BASICAUTH=1¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡ ¡Å¡ÅBASICǧ¾ÚÂå¹Ô¤ò͸ú¤Ë¤¹¤ë SVRFILE=back01,./back01.conf¡¡¡Å¡Å¥Û¥¹¥ÈÀßÄê¥Õ¥¡¥¤¥ë¤òÊѹ¹¤¹¤ë BA-UID=<UID>¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡Å¡Åǧ¾Ú¤Ë»È¤¦¥æ¡¼¥¶¡¼Ì¾¤ÎDB¥«¥é¥à̾¤ò»ØÄê¡ÊDEFAULT¤Ë¤¹¤ë¤ÈIceWall¤Îǧ¾Ú¤ÎUID¤ò»ÈÍÑ¡Ë BA-PWD=<PWD>¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡Å¡Åǧ¾Ú¤Ë»È¤¦¥Ñ¥¹¥ï¡¼¥É¤ÎDB¥«¥é¥à̾¤ò»ØÄê¡ÊDEFAULT¤Ë¤¹¤ë¤ÈIceWall¤Îǧ¾Ú¤Î¥Ñ¥¹¥ï¡¼¥É¤ò»ÈÍÑ¡Ë FORMǧ¾Ú¤ÎÂå¹Ô †¥Û¥¹¥ÈÀßÄê¥Õ¥¡¥¤¥ë¤ò¥³¥Ô¡¼¤·ÊÔ½¸¤¹¤ë cd /opt/icewall-sso/certd/config cp -ip sample.conf back01.conf vi back01.conf FORM_FILE=FORM01,./form.conf ¡Å¡ÅFORM01¤È¤¤¤¦¥Õ¥©¡¼¥à¥°¥ë¡¼¥×̾¤òÄêµÁ¤·¡¢¥Õ¥©¡¼¥à¤ÎÀßÄê¥Õ¥¡¥¤¥ë¤Ïform.conf¤È¤¹¤ë ¥Õ¥©¡¼¥àÀßÄê¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤¹¤ë vi form.conf ¡Ú¡¡½ñ¼°¡¡¡Û ¹àÌÜ=¥Õ¥©¡¼¥à¥°¥ë¡¼¥×̾,ÀßÄêÃÍ
¡Ú¡¡½ñ¼°¡¡¡Û FORM_DATA_STR=¥Õ¥©¡¼¥à¥°¥ë¡¼¥×̾,¥á¥½¥Ã¥É,name°À,¸ÇÄêÃÍ FORM_DATA_STR=FORM01,POSTDATA,id,user01 FORM_DATA_STR=FORM01,POSTDATA,pwd,pass01 ¢¨¥á¥½¥Ã¥É¤ÏGET¤ÏQUERY_STRING¡¢POST¤ÏPOSTDATA ¡Ú¡¡½ñ¼°¡¡¡Û FORM_DATA_STR=¥Õ¥©¡¼¥à¥°¥ë¡¼¥×̾,¥á¥½¥Ã¥É,name°À,DB¥«¥é¥à̾ FORM_DATA_USR=FORM01,POSTDATA,id,EXTRAUID FORM_DATA_USR=FORM01,POSTDATA,pwd,EXTRAPWD ¢¨DB¥«¥é¥à¤Ïcert.conf¤ÎDBEXATTR¤ÇÄêµÁ¤·¤¿¥«¥é¥à¤ò»ØÄꤹ¤ë ¥Õ¥©¥ï¡¼¥À¤Î¥¢¥¯¥»¥¹¥í¥°¡Êdfw.log¡Ë †dfw.conf¤ÎACCESS¤Ç»ØÄꤷ¤¿¾ì½ê¡Ê¥Ç¥Õ¥©¥ë¥È¤Ï/opt/icewall-sso/logs/dfw.log¡Ë¤Ë½ÐÎϤµ¤ì¤ë ¡Ú½ÐÎÏÎã¡Û[2012/03/12 09:21:16] 0.024 0.117 0.000 user1 POST [web.test.com:443/sdrive/download.php] 56 192.168.11.10 TID=TID201¡Á
·Ð²á»þ´Ö¤Ë¤Ä¤¤¤Æ †
¥È¥é¥ó¥¶¥¯¥·¥ç¥óID †¥Õ¥©¥ï¡¼¥À¤Ë¤è¤ê¸Ä¡¹¤Î¥ê¥¯¥¨¥¹¥È¤ò¸ÄÊ̤˳ä¤ê¿¶¤é¤ì¤¿TID¤Ç¥í¥°¤ËµÏ¿¤¹¤ë dfw.conf TRANSID=1 ¥È¥é¥ó¥¶¥¯¥·¥ç¥óID½ÐÎϤò͸ú¤Ë¤¹¤ë TRANSID_STR¡¡¥È¥é¥ó¥¶¥¯¥·¥ç¥óID¤Î¸å¤ËǤ°Õ¤Îʸ»úÎó¤òÄɵ¤¹¤ë¡Ê¥Õ¥©¥ï¡¼¥ÀËè¤Ë°Û¤Ê¤ëʸ»úÎó¤òÆþ¤ì¤ë¤³¤È¤Ç¥µ¡¼¥Ð¡¼ÀÚ¤êʬ¤±¤¬°Â°×¤Ë¤Ê¤ë¡Ë cert.conf TRANSID=1¡¡¡¡Ç§¾Ú¥â¥¸¥å¡¼¥ë¥í¥°¤Ø¤Î¥È¥é¥ó¥¶¥¯¥·¥ç¥óID½ÐÎϤò͸ú¤Ë¤¹¤ë ǧ¾Ú¥â¥¸¥å¡¼¥ë¤Î¥¢¥¯¥»¥¹¥í¥°¡Êcert.log¡Ë †cert.conf¤ÎACCESS¤Ç»ØÄꤷ¤¿¾ì½ê¡Ê¥Ç¥Õ¥©¥ë¥È¤Ï/opt/icewall-sso/logs/dfw.log¡Ë¤Ë½ÐÎϤµ¤ì¤ë ¡Ú½ÐÎÏÎã¡Û[2012/03/12 09:21:05] User Login. TID=TID201¡Á UserID=user1 [AC10124-25065]
ǧ¾ÚDB¥¢¥¯¥»¥¹»þ´Ö¤ÎµÏ¿ †ALEVEL¤Ë1°Ê¾å³î¤Ä¡¢LOGPERF=1¤ËÀßÄꤷ¤¿¾ì¹ç¡¢Ç§¾ÚDB¤Ø¤Î¥¢¥¯¥»¥¹»þ´Ö¤¬µÏ¿¤µ¤ì¤ë ¡Ú½ÐÎÏÎã2¡Û[2012/03/12 09:21:05] PERF 1104244 LOGINUID user1 0.007303 S:0.024 U:0.014 TID=20121¡Á [AC28201-29999]
|