ããã¯ãUbuntu OnlineãFedora OnlineãWindows ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒããŸã㯠MAC OS ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒãªã©ã®è€æ°ã®ç¡æãªã³ã©ã€ã³ ã¯ãŒã¯ã¹ããŒã·ã§ã³ã® XNUMX ã€ã䜿çšããŠãOnWorks ç¡æãã¹ãã£ã³ã° ãããã€ããŒã§å®è¡ã§ããã³ãã³ã fwbedit ã§ãã
ããã°ã©ã ïŒ
NAME
fwbedit - æ±çšãªããžã§ã¯ã ããªãŒç·šéããŒã«
SYNOPSIS
fwbedit ã³ãã³ã[ãªãã·ã§ã³]
DESCRIPTION
fwbedit Firewall Builder çšã®æ±çšãªããžã§ã¯ã ããªãŒç·šéããŒã«ã§ã (ã
fwãã«ããŒ(1))ã ãã®ããŒã«ã¯ããããåŠççšã«äœæãããã·ã§ã« ã¹ã¯ãªããã§äœ¿çšã§ããŸãã
Firewall Builder ããŒã¿ ãã¡ã€ã«ã Fwbedit ã¯ã次ã®æäœãå®è¡ã§ããŸãã
ãªããžã§ã¯ããšããªãŒ: æ°ãããªããžã§ã¯ãã®äœæãæ¢åã®ãªããžã§ã¯ãã®åé€ããªããžã§ã¯ãã®å±æ§ã®å€æŽ
ãªããžã§ã¯ããæå®ããããªããžã§ã¯ããžã®åç §ãã°ã«ãŒãã«è¿œå ããªããžã§ã¯ããžã®åç §ãã°ã«ãŒãããåé€
ã°ã«ãŒããäœæããããŒã¿ ãã¡ã€ã«ãã¢ããã°ã¬ãŒããããã¡ã€ã«å ã®ãªããžã§ã¯ã ããªãŒã確èªããå¿ èŠã«å¿ããŠä¿®åŸ©ããŸãã
ãªããžã§ã¯ããšã°ã«ãŒãã¯ã©ã¡ãããID ãŸãã¯ååãšãã«ãã¹ã§å®çŸ©ã§ããŸãã
ããªãŒ (ã»ã¯ã·ã§ã³ãåç §) äŸ äžïŒã
ã³ãã³ã ãã㊠ãªãã·ã§ã³ïŒ
æ°è£œå -f ãã¡ã€ã«.fwb -t ãªããžã§ã¯ãã¿ã€ã -n å -p 芪 [-NS ã³ã¡ã³ã] [-NS å±æ§]
æ°ãããªããžã§ã¯ããäœæããŸãã
-f file.fwb ããŒã¿ ãã¡ã€ã«
-t objtype ãã®ã¿ã€ãã®æ°ãããªããžã§ã¯ããäœæããŸã
-pparent ãã®ãªããžã§ã¯ãã®åãšããŠæ°ãããªããžã§ã¯ããäœæããŸãã
ãã®ãã©ã¡ãŒã¿ã¯å¿ é ã§ãã äœæãè¿œå ããå Žå
ã€ã³ã¿ãŒãã§ã€ã¹ã«æ¥ç¶ããã«ã¯ã察å¿ããã€ã³ã¿ãŒãã§ã€ã¹ onkect ãæå®ããå¿ èŠããããŸãã
芪ãšããŠæå®ãããŸãã åæ§ã«ã
ãã¹ããŸãã¯ãã¡ã€ã¢ãŠã©ãŒã«ãžã®ã€ã³ã¿ãŒãã§ãŒã¹ã察å¿ãããã¹ããŸãã¯
ãã¡ã€ã¢ãŠã©ãŒã« ãªããžã§ã¯ãã芪ã§ãã è¿œå ããå Žåã¯ã
æšæºãã©ã«ããŒã® XNUMX ã€ã«ãªããžã§ã¯ããè¿œå ããå Žåã芪ã¯
ãªããžã§ã¯ããè¿œå ããã©ã€ãã©ãªããŸãã¯å®å šã«ä¿®æ£ããã©ã€ãã©ãª
ããªãŒå ã®ãã©ã«ããŒãžã®ãã¹ã
-n name æ°ãããªããžã§ã¯ãã®åå
-c txt æ°ãããªããžã§ã¯ãã®ã³ã¡ã³ããæå®ããŸã
-aattribute1[,attribute2...] : å±æ§ãæå®ããŸãã
æ°ãããªããžã§ã¯ãã®ãã©ã¡ãŒã¿ãå®çŸ©ããŸã (以äžãåç §)
åé€ -f ãã¡ã€ã«.fwb -o ãªããžã§ã¯ã
ããªãŒå ã®ãã«ãã¹ãŸãã¯ãªããžã§ã¯ãIDã§æå®ããããªããžã§ã¯ããåé€ããŸãã
-f file.fwb ããŒã¿ ãã¡ã€ã«
-o object åé€ãããªããžã§ã¯ãããã«ãã¹ãŸãã¯ID
ä¿®æ£ãã -f ãã¡ã€ã«.fwb -o ãªããžã§ã¯ã -c ã³ã¡ã³ã [-NS å±æ§]
ããªãŒå ã®ãã«ãã¹ãŸãã¯ãªããžã§ã¯ã ID ã§æå®ããããªããžã§ã¯ããå€æŽããŸãã ãªããžã§ã¯ãã¯ã§ããŸãã
ãã®æäœã䜿çšããŠååãå€æŽããŸãã
-f file.fwb ããŒã¿ ãã¡ã€ã«
-o object åé€ãããªããžã§ã¯ãããã«ãã¹ãŸãã¯ID
-c txt æ°ãããªããžã§ã¯ãã®ã³ã¡ã³ããæå®ããŸã
-aattribute1[,attribute2...] : å±æ§ãæå®ããŸãã
æ°ãããªããžã§ã¯ãã®ãã©ã¡ãŒã¿ãå®çŸ©ããŸã (以äžãåç §)
ãªã¹ã -f ãã¡ã€ã«.fwb -o ãªããžã§ã¯ã [-r|-c] [-d|-Fformat]
ãªããžã§ã¯ãã®ååãš ID ãåºåããŸãã
-f file.fwb ããŒã¿ ãã¡ã€ã«
-o object å°å·ãããªããžã§ã¯ãããã«ãã¹ãŸãã¯ID
-r æå®ããããªããžã§ã¯ããšãã®äžã®ããªãŒå ã®ãã¹ãŠã®ãªããžã§ã¯ããåºåããŸãã
-c æå®ããããªããžã§ã¯ãã®åãªããžã§ã¯ãã®ã¿ãåºåããŸãããåãªããžã§ã¯ãã¯åºåããŸãã
ãªããžã§ã¯ãèªäœãåºåããŸãã
-d å éšãå«ããã¹ãŠã®ãªããžã§ã¯ãã®å±æ§ã®å®å šãªãã³ããåºåããŸãã
å©çšå¯èœãªå Žåã¯ãããã°æ å ±ãããã¯éåžžã«éèŠã§ãã
詳现ã
-Fformat_string ããã°ã©ã ã¯ãã©ãŒãããæååå ã®ãã¯ããèªèããŸã
ãããŠãããã察å¿ãããªããžã§ã¯ãã®å€ã«çœ®ãæããŸãã
å±æ§ã ãã¯ãã¯å²ãŸããå±æ§ã®ååã§ã
ã%name%ããã%address%ããªã©ãã%ãã䜿çšããŸãã ããã«ãããŸã
ããã€ãã®å±æ§åã®ãªã¹ã: "id"ã"name"ã"path"ã
ãã³ã¡ã³ããããã¿ã€ããããã¢ãã¬ã¹ãããããããã¹ã¯ãããDNSåãã TCP
UDP ãµãŒãã¹ ãªããžã§ã¯ãã¯å±æ§ãæäŸããŸã
"src_range_start"ã"src_range_end"ã"dst_range_start"ã
éä¿¡å ããŒããšå®å ããŒãã®ãdst_range_endã
ç¯å²ã ICMP ããã³ ICMP6 ãµãŒãã¹ ãªããžã§ã¯ãã«ã¯å±æ§ããããŸã
ãicmp_typeããšãicmp_codeãã
å ããŸã -f ãã¡ã€ã«.fwb -g ã°ã«ãŒãããã -o ãªããžã§ã¯ã
ãã¹ãŸã㯠ID ã§æå®ããããªããžã§ã¯ããããã¹ãŸã㯠ID ã§æå®ãããã°ã«ãŒãã«è¿œå ããŸãã
-f file.fwb ããŒã¿ ãã¡ã€ã«
-g group ãªããžã§ã¯ããè¿œå ããã°ã«ãŒãã
ãã«ãã¹ãŸãã¯ID
-o object åé€ãããªããžã§ã¯ãããã«ãã¹ãŸãã¯ID
åé€ããŸã -f ãã¡ã€ã«.fwb -g ã°ã«ãŒãããã -o ãªããžã§ã¯ã
ã°ã«ãŒããããªããžã§ã¯ããåé€ããŸãã
-f file.fwb ããŒã¿ ãã¡ã€ã«
-g group ãªããžã§ã¯ããåé€ããã°ã«ãŒãã
ãã«ãã¹ãŸãã¯ID
-o object åé€ãããªããžã§ã¯ãããã«ãã¹ãŸãã¯ID
ã¢ããã°ã¬ãŒã -f ãã¡ã€ã«.fwb
ããŒã¿ãã¡ã€ã«ãææ°ã®ããŒã¿åœ¢åŒããŒãžã§ã³ã«ã¢ããã°ã¬ãŒãããŸãã
-f file.fwb ããŒã¿ ãã¡ã€ã«
ãã§ãã¯ããªãŒ -f ãã¡ã€ã«.fwb
æå®ãããããŒã¿ ãã¡ã€ã«å ã®ãªããžã§ã¯ã ããªãŒã®äžè²«æ§ãšæ£ç¢ºæ§ããã§ãã¯ãã修埩ããŸãã
å¿ èŠã«å¿ããŠã
-f file.fwb ããŒã¿ ãã¡ã€ã«
ããŒãž -f ãã¡ã€ã«1.fwb -i ãã¡ã€ã«2.fwb
file2.fwb ã®ãªããžã§ã¯ãã file1 ã®ãªããžã§ã¯ããšããŒãžãããçµåããããªããžã§ã¯ã ããªãŒãä¿åãããŸãã
file1.fwbå
-f file.fwb ããŒã¿ ãã¡ã€ã« #1
-i file.fwb ããŒã¿ ãã¡ã€ã« #2
import -f ãã¡ã€ã«1.fwb -i ãã¡ã€ã¢ãŠã©ãŒã«_config.txt -o ãã¡ã€ã¢ãŠã©ãŒã«ãªããžã§ã¯ããžã®ãã¹ [-NS]
ãã¡ã€ã« firewall_config.txt ã®ãã¡ã€ã¢ãŠã©ãŒã«æ§æã解æãããããŒã¿ ãã¡ã€ã«ã«ã€ã³ããŒããããŸã
ãã¡ã€ã«1.fwbã ããã°ã©ã ã¯ãã©ã€ãã©ãªå ã«æ°ãããã¡ã€ã¢ãŠã©ãŒã« ãªããžã§ã¯ããäœæãã
ãã¹ path_to_firewall_object ã«ãã£ãŠå®çŸ©ãããååã
-f file.fwb ããŒã¿ ãã¡ã€ã« #1
-i config.txt ãã¡ã€ã¢ãŠã©ãŒã«æ§æãã¡ã€ã«
-o object_path ãã¡ã€ã¢ãŠã©ãŒã« ãªããžã§ã¯ããžã®ãã« ãã¹ã
äœæããã ããã¯ãã«ãã¹ã§å§ãŸãå¿ èŠããããŸã
ã©ã€ãã©ãªåãæå®ãããšã次ã®ããã«ãªããŸãã
ã/ãŠãŒã¶ãŒ/ãã¡ã€ã¢ãŠã©ãŒã«/my_new_firewallã
-d ã€ã³ããŒãæã«éè€ãªããžã§ã¯ãã®äœæãåé¿ããŸã
çŸåš (v4.2.0 æç¹) fwbuilder ã¯ã次ã®ã³ãã³ãã§ä¿åããã iptables èšå®ã®ã€ã³ããŒãããµããŒãããŠããŸãã
iptables-save ã³ãã³ããããã³ Cisco ã«ãŒã¿ãŒ IOS èšå®ãCisco PIXãASA ã®ã€ã³ããŒã
ããã³ãshow runãã³ãã³ãã§ä¿åããã FWSM ãã¡ã€ã¢ãŠã©ãŒã«ã
ATTRIBUTES FOR ã NEW ãªããžã§ã¯ãã BY ã¿ã€ã
-t ãã¡ã€ã¢ãŠã©ãŒã« - ãã©ãããã©ãŒã ããã¹ã OS
-t IPv4 -a IP ã¢ãã¬ã¹ [,ããããã¹ã¯]
-t IPv6 -a IPv6 ã¢ãã¬ã¹ [,ãã¹ã¯ã¬ã³]
-t DNSName -DNS ã¬ã³ãŒããå®è¡æé
-t AddressRange -éå§ã¢ãã¬ã¹ãçµäºã¢ãã¬ã¹
-t ãªããžã§ã¯ãã°ã«ãŒã
-t ãããã¯ãŒã¯ - ã¢ãã¬ã¹ãããããã¹ã¯
-t NetworkIPv6 -a ipv6 ã¢ãã¬ã¹ãããããã¹ã¯é·
-t éé - éå§æå»ãéå§æ¥ãéå§æ¥ãçµäºæå»ãçµäºæ¥ãçµäºæ¥
-t ã€ã³ã¿ãŒãã§ã€ã¹ -a ã»ãã¥ãªã㣠ã¬ãã«ãã¢ãã¬ã¹ ã¿ã€ã (åçãŸãã¯çªå·ãªã)ã管ç
-t ãã¹ã
-t TCPService -éä¿¡å ããŒãç¯å²ã®éå§ãçµäºãå®å ããŒãç¯å²
éå§ãçµäºãUAPRSFãUAPRSF
-t UDPService -a éä¿¡å ããŒãç¯å²ã®éå§ãçµäºãå®å ããŒãç¯å²ã®éå§ãçµäº
-t ICMPService -a ICMP ã¿ã€ããICMP ã³ãŒã
-t IPService - ãããã³ã«çªå·ãlsrr/ssrr/rr/ts/fragm/short_fragm
äŸ
æäŸãããæ å ±ã«åŸã£ãŠããªããžã§ã¯ã /User/Firewalls/firewall/eth0 ã®å 容ãåºåããŸãã
ãã©ãŒãããã ãã€ã³ã¿ãŒãã§ã€ã¹ãã¿ã€ãã®ãªããžã§ã¯ãã«ã¯ãå®çŸ©ããå±æ§ããªãããšã«æ³šæããŠãã ããã
ãã®ã¢ãã¬ã¹ãIP ã¢ãã¬ã¹ã¯ãIPv4 ãŸã㯠IPv6 ã¿ã€ãã®åãªããžã§ã¯ãã«ãã£ãŠå®çŸ©ãããŸãã
fwbedit list -f x.fwb -o /User/Firewalls/firewall/eth0 -F "type=%type% name=%name%
id=%id% %ã³ã¡ã³ã%"
ãªããžã§ã¯ã /User/Firewalls/firewall/eth0 ãšãã®ãã¹ãŠã®åãªããžã§ã¯ãã®å 容ãåºåããŸãã ãã
ã¢ãã¬ã¹ãšããããã¹ã¯ã確èªããæ¹æ³ã§ãã ã€ã³ã¿ãŒãã§ãŒã¹ãªããžã§ã¯ãã«ã¯å±æ§ããããŸãã
"address" ãªã®ã§ãããã°ã©ã ã¯ã€ã³ã¿ãŒãã§ã€ã¹ãåºåãããšãã«ãã¯ã "%address%" ãç¡èŠããŸãã
fwbedit list -f x.fwb -o /User/Firewalls/firewall/eth0 -F "type=%type% name=%name%
id=%id% %ã³ã¡ã³ã% %ã¢ãã¬ã¹%" -r
å°å·ã°ã«ãŒã ãªããžã§ã¯ã /User/Objects/Addresses
fwbedit list -f x.fwb -o /User/Objects/Addresses -F "type=%type% name=%name% id=%id%
ïŒ ã³ã¡ã³ãïŒ "
ã°ã«ãŒã ãªããžã§ã¯ã /User/Objects/Addresses ãšãã®äžã®ãã¹ãŠã®ã¢ãã¬ã¹ ãªããžã§ã¯ããåºåããŸãã
fwbedit list -f x.fwb -o /User/Objects/Addresses -F "type=%type% name=%name% id=%id%
%ã³ã¡ã³ã%" -r
ã°ã«ãŒã /User/Objects/Addresses å ã®ã¢ãã¬ã¹ ãªããžã§ã¯ããå°å·ããŸãããã°ã«ãŒãã¯å°å·ããŸãã
ãªããžã§ã¯ãèªäœ:
fwbedit list -f x.fwb -o /User/Objects/Addresses -F "type=%type% name=%name% id=%id%
%ã³ã¡ã³ã%" -c
ãã¹ãŠã®ãã¡ã€ã¢ãŠã©ãŒã«ã®ãã¹ãŠã®ã€ã³ã¿ãŒãã§ã€ã¹ã®ã¢ãã¬ã¹ãšããããã¹ã¯ãå®å šãªåœ¢åŒã§åºåããŸãã
ãªããžã§ã¯ã ããªãŒ ãã¹ããã®åŸã«ã¿ã€ããIDãã¢ãã¬ã¹ãããããã¹ã¯ãç¶ããŸãã
fwbedit list -f x.fwb -o /User/Firewalls -F "%path% %type% %id% %address% %netmask%" -r |
grep IP
ããŒã¿å ã§å®çŸ©ãããŠãããã¹ãŠã®ãã¡ã€ã¢ãŠã©ãŒã« ãªããžã§ã¯ãã®ååããã©ãããã©ãŒã ãããã³ããŒãžã§ã³æ å ±ãåºåããŸãã
ãã¡ã€ã«ïŒ
fwbedit list -f x.fwb -o /User/Firewalls -F "%name% ãã©ãããã©ãŒã : %platform% ããŒãžã§ã³:
%ããŒãžã§ã³%" -c
TCP ãã©ã«ãå ã®ãã¹ãŠã® TCP ãµãŒãã¹ã®ååãéä¿¡å ããã³å®å ããŒãç¯å²ãåºåããŸãã
ãŠãŒã¶ãŒå®çŸ©ã°ã«ãŒã User:
fwbedit list -f x.fwb -o /User/Services/TCP -c -F "name='%name%' est=%確ç«%
%src_range_start%-%src_range_end% : %dst_range_start%-%dst_range_end%"
ãŠãŒã¶ãŒå®çŸ©ã®ãã©ã«ã㌠ICMP å ã®ãã¹ãŠã® ICMP ãµãŒãã¹ã® icmp ã¿ã€ããšã³ãŒããåºåããŸãã
ã°ã«ãŒããŠãŒã¶ãŒ:
fwbedit list -f x.fwb -o /User/Services/ICMP -c -F "name='%name%' icmp_type=%icmp_type%
icmp_code=%icmp_code%"
ãã¡ã€ã¢ãŠã©ãŒã« ãªããžã§ã¯ããfirewallãã®ã€ã³ã¿ãŒãã§ã€ã¹ã® 6 ã€ã« IPvXNUMX ã¢ãã¬ã¹ãè¿œå ããŸãã
fwbedit new -f x.fwb -p /ãŠãŒã¶ãŒ/ãã¡ã€ã¢ãŠã©ãŒã«/ãã¡ã€ã¢ãŠã©ãŒã«/eth3 -t IPv6 -n eth3-v6-addr -a
2001:470:1f05:590::2,64
ãã¹ã ãªããžã§ã¯ã 'A' ãžã®åç §ãã°ã«ãŒã 'B' ã«è¿œå ããŸãã
fwbedit add -f x.fwb -g /ãŠãŒã¶ãŒ/ãªããžã§ã¯ã/ã°ã«ãŒã/B -o /ãŠãŒã¶ãŒ/ãªããžã§ã¯ã/ãã¹ã/A
ID id3D71A1BA ã®ãªããžã§ã¯ããžã®åç §ã ID id3D151943 ã®ã°ã«ãŒãã«è¿œå ããŸãã ãªããžã§ã¯ãã®å Žå
æå®ããã ID ãååšããªãå Žåãfwbedit ã¯ãšã©ãŒ ã¡ãã»ãŒãžãåºåããå€æŽã¯è¡ããŸããã
ããŒã¿ãã¡ã€ã«å ã
fwbedit è¿œå -f x.fwb -o id3D71A1BA -g id3D151943
ID id3D71A1BA ã®ãªããžã§ã¯ããžã®åç §ãã°ã«ãŒããtestgroupãã«è¿œå ããŸãã
fwbedit add -f x.fwb -o id3D71A1BA -g /User/Objects/Groups/testgroup
次ã®ã¹ã¯ãªããã¯ãfwbedit "list" ã³ãã³ãã䜿çšããŠããã¹ãŠã® Address ãªããžã§ã¯ãã® ID ãåºåããŸãã
ãã©ã«ã㌠/User/Objects/Addresses ãåç §ããååŸãããªã¹ãã埪ç°ããŠäœ¿çšããŸãã
fwbedit ãå®è¡ããŠã°ã«ãŒããgroup1ãã«è¿œå ããŸãã
fwbedit list -f x.fwb -o /User/Objects/Addresses -F "%id%" -c | \
ID ã®èªã¿åãäžã ãã \
fwbedit add -f x.fwb -g /User/Objects/Groups/group1 -o $id; \
è¡ãã
ããã§ã¯ããå°ãè€éãªäŸã瀺ããŸãã 次ã®ã¹ã¯ãªããã¯ãfwbedit "list" ã³ãã³ãã䜿çšããŠã
/User/Objects/Addresses ãã©ã«ããŒå ã®ãã¹ãŠã® Address ãªããžã§ã¯ãã®ã¿ã€ããš ID ãåºåãããã®åŸ
grep ã䜿çšããŠãããããã£ã«ã¿ãªã³ã°ã㊠IPv6 ãªããžã§ã¯ãã®ã¿ãååŸããæåŸã«ååŸãããªããžã§ã¯ãã埪ç°ããŸãã
ãªã¹ããäœæããfwbedit ã䜿çšããŠã°ã«ãŒããgroup1ãã«è¿œå ããŸãã
fwbedit list -f x.fwb -o /User/Objects/Addresses -F "%type% %id%" -c | \
ã°ã¬ãã IPv6 | \
ã¿ã€ã ID ã®èªã¿åãäžã ãã \
fwbedit add -f x.fwb -g /User/Objects/Groups/group1 -o $id; \
è¡ãã
URL
Firewall Builder ã®ããŒã ããŒãžã¯æ¬¡ã® URL ã«ãããŸãã http://www.fwbuilder.org/
onworks.net ãµãŒãã¹ã䜿çšããŠãªã³ã©ã€ã³ã§ fwbedit ã䜿çšãã