ããã¯ãUbuntu OnlineãFedora OnlineãWindows ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒããŸã㯠MAC OS ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒãªã©ã®è€æ°ã®ç¡æãªã³ã©ã€ã³ ã¯ãŒã¯ã¹ããŒã·ã§ã³ã® XNUMX ã€ã䜿çšããŠãOnWorks ç¡æãã¹ãã£ã³ã° ãããã€ããŒã§å®è¡ã§ããã³ãã³ã ike-scan ã§ãã
ããã°ã©ã ïŒ
NAME
ike-scan - IKE ãã¹ã (IPsec VPN ãµãŒããŒ) ãæ€åºããŠãã£ã³ã¬ãŒããªã³ãããŸãã
SYNOPSIS
ikeã¹ãã£ã³ [ãªãã·ã§ã³] [ãã¹ã...]
ã¿ãŒã²ãã ãã¹ãã¯ã³ãã³ã ã©ã€ã³ã§æå®ããå¿ èŠããããŸãã - ãã¡ã€ã« ãªãã·ã§ã³ãæå®ãããŠããŸãã
DESCRIPTION
ikeã¹ãã£ã³ IKE ãã¹ããæ€åºããåéä¿¡ã䜿çšããŠãããã®ãã£ã³ã¬ãŒããªã³ããå®è¡ããããšãã§ããŸãã
ããã¯ãªããã¿ãŒã³ã
ikeã¹ãã£ã³ 次㮠XNUMX ã€ã®ããšãè¡ããŸãã
1) æ€åº: IKE ãå®è¡ããŠãããã¹ããç¹å®ããŸãã ããã¯ãããã衚瀺ããããšã§è¡ãããŸã
ã«ãã£ãŠéä¿¡ããã IKE ãªã¯ãšã¹ãã«å¿çãããã¹ã ã€ã±ã¹ãã£ã³ã
2) ãã£ã³ã¬ãŒããªã³ãã£ã³ã°: ãã¹ãã䜿çšããŠãã IKE å®è£ ãç¹å®ããŸãã ããã
ãããè¡ãã«ã¯ããã€ãã®æ¹æ³ããããŸã: (a) ããã¯ãªã ãã£ã³ã¬ãŒããªã³ãã£ã³ã° - æéã®èšé²
ã¿ãŒã²ãã ãã¹ãããã® IKE å¿çãã±ãããšã芳å¯ããããã±ããã®æ¯èŒ
æ¢ç¥ã®ãã¿ãŒã³ã«å¯Ÿããåéä¿¡ããã¯ãªã ãã¿ãŒã³ã (b) ãã³ã㌠ID ã®ãã£ã³ã¬ãŒããªã³ãã£ã³ã°
- ãã³ããŒåºæã®ãã³ã㌠ID ãæ¢ç¥ã®ãã³ã㌠ID ãã¿ãŒã³ãšç §åããã ããã³ (c)
ç¬èªã®éç¥ã¡ãã»ãŒãž ã³ãŒãã
åéä¿¡ããã¯ãªã ãã£ã³ã¬ãŒããªã³ãã£ã³ã°ã®æŠå¿µã«ã€ããŠã¯ãUDP ã§è©³ãã説æãããŠããŸãã
ããã¯ãªãæçŽæ¡åçšçŽã¯ãike-scan ãããã«å«ãŸããŠããå¿ èŠããããŸãã udp-ããã¯ãªã-
æçŽæ¡åçšçŽ.txtã
ããã°ã©ã ã¯ãæå®ããããã¹ãã« IKE ãã§ãŒãº 1 ãªã¯ãšã¹ããéä¿¡ããå¿çãããã°è¡šç€ºããŸãã
åãåã£ããã®ã ãã±ããã«å¯ŸåŠããããã«ããã¯ãªãã䜿çšããŠåè©Šè¡ããã³åéä¿¡ãåŠçããŸãã
æ倱ã ãŸããéä¿¡ IKE ãã±ããã«ãã£ãŠäœ¿çšããã垯åå¹ ã®éãå¶éãããŸãã
IKE ã¯ãéµäº€æãšèªèšŒãè¡ãã€ã³ã¿ãŒãããéµäº€æãããã³ã«ã§ãã
IPsec ã§äœ¿çšãããã¡ã«ããºã ã ææ°ã®ã»ãŒãã¹ãŠã® VPN ã·ã¹ãã 㯠IPsec ãå®è£ ããŠããã
ã»ãšãã©ã® IPsec VPN ã¯ããŒäº€æã« IKE ã䜿çšããŸãã
ãã§ãŒãº 1 ã«ã¯ãã¡ã€ã³ ã¢ãŒããšã¢ã°ã¬ãã·ã ã¢ãŒãã® XNUMX ã€ã®ã¢ãŒãããããŸãã ike-scan 㯠Main ãš
ã¢ã°ã¬ãã·ã ã¢ãŒããããã©ã«ãã§ã¡ã€ã³ ã¢ãŒãã䜿çšããŸãã RFC 2409 (IKE) ã»ã¯ã·ã§ã³ 5 ã§ã¯ã次ã®ããã«èŠå®ãããŠããŸãã
ã¡ã€ã³ ã¢ãŒããå®è£ ããå¿ èŠãããããããã¹ãŠã® IKE å®è£ ã¯æ¬¡ã®ããšãæåŸ ã§ããŸãã
ã¡ã€ã³ã¢ãŒãããµããŒãããŸãã
OPTIONS
- å©ã㊠or -h
ãã®äœ¿çšæ³ã¡ãã»ãŒãžã衚瀺ããŠçµäºããŸãã
--file= or -f
ã³ãã³ãããã§ã¯ãªããæå®ããããã¡ã€ã«ãããã¹ãåãŸãã¯ã¢ãã¬ã¹ãèªã¿åããŸãã
ã©ã€ã³ã XNUMX è¡ã« XNUMX ã€ã®ååãŸã㯠IP ã¢ãã¬ã¹ã æšæºå ¥åã«ã¯ã-ãã䜿çšããŸãã
--ã¹ããŒã= or -s
UDP éä¿¡å ããŒãã次ã®ããã«èšå®ããŸããããã©ã«ã = 500ã0 = ã©ã³ãã ã äžéšã® IKE å®è£
ã¯ã©ã€ã¢ã³ã㯠UDP ãœãŒã¹ ããŒã 500 ã䜿çšããå¿ èŠããããä»ã®ããŒããšã¯éä¿¡ããŸããã
ãŒã以å€ã®éä¿¡å ããŒãã䜿çšããã«ã¯ãéåžžãã¹ãŒããŒãŠãŒã¶ãŒæš©éãå¿ èŠã§ããããšã«æ³šæããŠãã ããã
ãŸããã·ã¹ãã äžã® 1024 ã€ã®ããã»ã¹ã®ã¿ããæå®ããããœãŒã¹ ããŒãã«ãã€ã³ãã§ããŸãã
ãã€ã§ãã --nat-t ãªãã·ã§ã³ã䜿çšãããšãããã©ã«ãã®éä¿¡å ããŒãã 4500 ã«å€æŽãããŸã
--dããŒã= or -d
UDP å®å ããŒãã次ã®ããã«èšå®ããŸããããã©ã«ã = 500ã UDP ããŒã 500 ãå²ãåœãŠãããããŒãã§ã
ISAKMP ã®çªå·ãããã¯ããã¹ãŠã§ã¯ãªãã«ããŠããã»ãšãã©ã® IKE å®è£ ã§äœ¿çšãããããŒãã§ãã
--nat-t ãªãã·ã§ã³ã䜿çšãããšãããã©ã«ãã®å®å ããŒãã 4500 ã«å€æŽãããŸãã
--åè©Šè¡= or -r
ãã¹ãããšã®åèšè©Šè¡åæ°ã次ã®ããã«èšå®ããŸãã ãããã©ã«ã = 3ã
--ã¿ã€ã ã¢ãŠã= or -t
ãã¹ãããšã®åæã¿ã€ã ã¢ãŠãã次ã®ããã«èšå®ããŸãããªç§ãããã©ã«ã = 500ã ãã®ã¿ã€ã ã¢ãŠãã¯æåã®ãã®ã§ã
ãã±ãããåãã¹ãã«éä¿¡ãããŸãã åŸç¶ã®ã¿ã€ã ã¢ãŠãã«ã¯ããã¯ãªãä¿æ°ãä¹ç®ãããŸã
ãã㯠--backoff ã§èšå®ãããŸãã
--垯åå¹ = or -B
å¿ èŠãªé信垯åå¹ ã次ã®ããã«èšå®ããŸãã ãããã©ã«ã=56000 å€ã¯ããã/ãããã§ãã
ããã©ã«ãã§ã¯ XNUMX çªç®ã§ãã å€ã«ãKããè¿œå ãããšãåäœã¯ããããããããã«ãªããŸãã
XNUMXçª; å€ã«ãMããè¿œå ãããšãåäœã¯ã¡ã¬ããã/ç§ã«ãªããŸãã ã®
ãKãããã³ãMãã®æ¥å°ŸèŸã¯ã64 é²æ°ã§ã¯ãªã XNUMX é²æ°ã®åæ°ãè¡šããŸãã ã€ãŸã XNUMXK ã¯
64000ã§ã¯ãªã65536ã§ãã
--éé= or -i
æå°ãã±ããééã次ã®ããã«èšå®ããŸãã MSã ãã±ããééã¯æ¬¡ã®å€ä»¥äžã«ãªããŸãã
ãã®çªå·ã ããã©ã«ãã§ã¯ãæå®ãããééã¯ããªç§åäœã§ãã ãããããªããã
å€ã«è¿œå ãããå Žåãééã¯ãã€ã¯ãç§åäœã§ããããsãã
è¿œå ãããééã¯ç§åäœã§ãã æå®ããã垯åå¹ ãŸã§äœ¿çšãããå Žåã¯ã
ãã®å Žåã¯ã代ããã« --bandwidth ãªãã·ã§ã³ã䜿çšããæ¹ãç°¡åã§ãã äž¡æ¹ãæå®ããããšã¯ã§ããŸãã
--interval ãš --bandwidth ã¯ãåãå€æŽæ¹æ³ãç°ãªãã ããªã®ã§ã
åºç€ãšãªãå€æ°ã
--ããã¯ãªã= or -b
ã¿ã€ã ã¢ãŠã ããã¯ãªãä¿æ°ã ã«èšå®ããŸã(ããã©ã«ã = 1.50)ã ãã¹ãããšã®ã¿ã€ã ã¢ãŠãã¯æ¬¡ã®ãšããã§ãã
ã¿ã€ã ã¢ãŠãããšã«ãã®ä¿æ°ãä¹ç®ãããŸãã ãããã£ãŠãåè©Šè¡åæ°ã 3 åã®å Žåã
ãã¹ãããšã®åæã¿ã€ã ã¢ãŠã㯠500 ããªç§ãããã¯ãªãä¿æ°ã¯ 1.5 ã§ããã®åŸãæåã®
ã¿ã€ã ã¢ãŠã㯠500 ããªç§ã750 çªç®ã¯ 1125 ããªç§ãXNUMX çªç®ã¯ XNUMX ããªç§ã«ãªããŸãã
-詳现 or -v
詳现ãªé²è¡ç¶æ³ã¡ãã»ãŒãžã衚瀺ããŸãã è€æ°å䜿çšãããšå¹æãé«ãŸããŸã: 1 - 衚瀺
åãã¹ãå®äºãããšããããã³ç¡å¹ãª Cookie ãå«ããã±ãããåä¿¡ããããšãã 2
- éåä¿¡ãããåãã±ãããšããã¹ãããã€ãªã¹ãããåé€ããããã衚瀺ããŸãã 3 -
ã¹ãã£ã³ãéå§ããåã«ããã¹ãããã³ã㌠IDãããã³ããã¯ãªãã®ãªã¹ãã衚瀺ããŸãã
- éã㪠or -q
è¿ããããã±ããããã³ãŒãããªãã§ãã ããã ããã«ãããåºåããããããã³ã«æ å ±ãå°ãªããªãããã
åºåè¡ãçããªããŸãã
-ãã«ãã©ã€ã³ or -M
ãã€ããŒãã®ãã³ãŒããè€æ°ã®è¡ã«åå²ããŸãã ãã®ãªãã·ã§ã³ã䜿çšãããšã
åãã€ããŒãã¯ãTAB ã§å§ãŸãå¥ã®è¡ã«åºåãããŸãã ãã®ãªãã·ã§ã³ã«ããã
ç¹ã«ãã€ããŒããå€ãå Žåãåºåãèªã¿ããããªããŸãã
--ã©ã€ãã¿ã€ã = or -l
IKE ã®æå¹æéãç§ã«èšå®ããŸã (ããã©ã«ã = 28800)ã RFC 2407 ã§ã¯ã28800 ã
ããã©ã«ãã§ãããå®è£ ã«ãã£ãŠã¯ç°ãªãå€ãå¿ èŠã«ãªãå ŽåããããŸãã æå®ããå Žå
ããã 86400 é²æŽæ° (äŸ: 4) ã«ãããšãå±æ§ã¯ XNUMX ãã€ãã䜿çšããŸãã
䟡å€ã 0 é²æ° (XNUMXxFF ãªã©) ã§æå®ããå Žåãå±æ§ã¯æ¬¡ã®å€ã䜿çšããŸãã
é©åãªãµã€ãºå€ (ãã®äŸã§ã¯ XNUMX ãã€ã)ã æååãæå®ããå Žå
ãnoneãã®å Žåãã©ã€ãã¿ã€ã å±æ§ã¯ãŸã£ããè¿œå ãããŸããã ãã®ãªãã·ã§ã³ã䜿çšã§ããŸã
--trans ãªãã·ã§ã³ãšçµã¿åãããŠè€æ°åå®è¡ãããšãè€æ°ã®ãã¡ã€ã«ãçæãããŸãã
ç°ãªãæå¹æéãæã€ãã€ããŒããå€æããŸãã å --trans ãªãã·ã§ã³ã¯ã
以åã«æå®ãããã©ã€ãã¿ã€ã å€ã
--lifesize= or -z
IKE ã©ã€ããµã€ãºããããã€ã (ããã©ã«ã = 0) ã«èšå®ããŸãã ããã XNUMX é²æ°ã§æå®ãããš
æŽæ° (äŸ: 86400) ã®å Žåãå±æ§ã¯ 4 ãã€ãå€ã䜿çšããŸãã æå®ããå Žå
0 é²æ° (äŸ: XNUMXxFF) ã®å Žåãå±æ§ã¯é©åãªãµã€ãºã䜿çšããŸãã
å€ (ãã®äŸã§ã¯ XNUMX ãã€ã)ã ãã®ãªãã·ã§ã³ã¯è€æ°å䜿çšã§ããŸãã
--trans ãªãã·ã§ã³ãšçµã¿åãããŠãè€æ°ã®å€æãã€ããŒããçæããŸãã
ããŸããŸãªç身倧ã å --trans ãªãã·ã§ã³ã¯ã以åã«æå®ãããã®ã䜿çšããŸãã
ç身倧ã®äŸ¡å€ã
--auth= or -m
èªèšŒãèšå®ããŸãã ããæ¹æ³ãããã©ã«ã = 1 (PSK)ã RFC ã§å®çŸ©ãããŠããå€ã¯ 1 ïœ 5 ã§ããRFC ãåç §ããŠãã ããã
2409 ä»é² A. ãã§ãã¯ãã€ã³ã ãã€ããªãã ã¢ãŒã㯠64221 ã§ããGSS (Windows "Kerberos") ã¯
65001ãXAUTH 㯠65001 ïœ 65010 ã䜿çšããŸãããã㯠IKEv2 ã«ã¯é©çšãããŸããã
- ããŒãžã§ã³ or -V
ããã°ã©ã ã®ããŒãžã§ã³ã衚瀺ããŠçµäºããŸãã
--ãã³ããŒ= or -e
ãã³ã㌠ID æååã XNUMX é²å€ã«èšå®ããŸãã ãã®ãªãã·ã§ã³ãè€æ°å䜿çšãããšã
è€æ°ã®ãã³ã㌠ID ãã€ããŒããéä¿¡ããŸãã
--trans= or -a
ã«ã¹ã¿ã å€æã䜿çšããããã©ã«ãã®ã»ããã®ä»£ããã«ã ãã®ãªãã·ã§ã³ã¯ä»¥äžä»¥å€ã«ã䜿çšã§ããŸã
ä»»æã®æ°ã®ã«ã¹ã¿ã å€æãäžåºŠéä¿¡ããŸãã æ¹æ³ã¯ XNUMX ã€ãããŸã
å€æãæå®ããŸããå±æ§ãšå€ã®ãã¢ãæå®ããæ°ããæ¹æ³ã§ãã
ãã XNUMX ã€ã¯ãå±æ§ã®åºå®ãªã¹ãã®å€ãæå®ããå€ãæ¹æ³ã§ãã ããã«
æ°ããã¡ãœããããã©ã³ã¹ãã©ãŒã (attr=value, attr=value, ...) ãšããŠæå®ãããŸãã
ããã§ããattrãã¯å±æ§çªå·ããvalueãã¯ãã®å±æ§ã«å²ãåœãŠãå€ã§ãã
å±æ§ã ä»»æã®æ°ã®å±æ§ãšå€ã®ãã¢ãæå®ã§ããŸãã RFCãåç §
2409 å±æ§ãšå€ã®è©³çŽ°ã«ã€ããŠã¯ãä»é² A ãåç §ããŠãã ããã æ¬åŒ§ã¯æ¬¡ã®ãšããã§ããããšã«æ³šæããŠãã ããã
äžéšã®ã·ã§ã«ã«ç¹æ®ãªãããåŒçšç¬Šã§å²ãå¿ èŠãããå ŽåããããŸãã
--trans="(1=1,2=2,3=3,4=4)". For example, --trans=(1=1,2=2,3=1,4=2) specifies
Enc=3DES-CBCãããã·ã¥=SHA1ãèªèšŒ=å ±æããŒãDHã°ã«ãŒã=2; ãš
--trans=(1=7,14=128,2=1,3=3,4=5) ã¯ãEnc=AES/128ãHash=MD5ãAuth=RSA sigãDH ãæå®ããŸãã
ã°ã«ãŒã=5ã å€ãã¡ãœããã®å Žåãtransform ãšããŠæå®ãããŸã
enc[/len]ãããã·ã¥ãèªèšŒãã°ã«ãŒãã ããã§ãenc ã¯æå·åã¢ã«ãŽãªãºã ãlen ã¯ããŒã§ã
length ã¯å¯å€é·æå·ã®å Žåãhash ã¯ããã·ã¥ ã¢ã«ãŽãªãºã ãgroup 㯠DH ã§ãã
ã°ã«ãŒãã ããšãã°ã--trans=5,2,1,2 ã¯ãEnc=3DES-CBCãHash=SHA1ãAuth=shared ãæå®ããŸãã
ããŒãDH ã°ã«ãŒã = 2; --trans=7/256,1,1,5 㯠Enc=AES-256ãHash=MD5 ãæå®ããŸãã
èªèšŒ = å ±æããŒãDH ã°ã«ãŒã = 5ã ãã®ãªãã·ã§ã³ã¯ IKEv2 ã§ã¯ãŸã ãµããŒããããŠããŸããã
--showbackoff[= ] or -o[ ã
ããã¯ãªããã£ã³ã¬ãŒããªã³ãããŒãã«ã衚瀺ããŸãã ããã¯ãªãããŒãã«ã衚瀺ããŠãã£ã³ã¬ãŒããªã³ããè¡ã
ãªã¢ãŒããã¹ãäžã® IKE å®è£ ã ãªãã·ã§ã³ã®åŒæ°ã¯æéãæå®ããŸã
æåŸã®ãã±ãããåä¿¡ããŠââããç§åäœã§åŸ æ©ããŸããããã©ã«ã = 60ã 䜿çšããŠããå Žå
ãªãã·ã§ã³ã®ç瞮圢 (-o) ã®å Žåãå€ã¯ãªãã·ã§ã³ã®çŽåŸã«ç¶ãå¿ èŠããããŸã
ã¹ããŒã¹ãå«ãŸãªãæåãããšãã° -o 25 ã§ã¯ãªã -o25ã
--fuzz= or -u
ãã¿ãŒã³ãããã³ã°ãã¡ãºã次ã®ããã«èšå®ããŸãããªç§ãããã©ã«ã = 500ã ããã«ããã蚱容å¯èœãªæ倧å€ãèšå®ãããŸã
芳枬ãããããã¯ãªãæéãšåºæºæéã®å·®
ããã¯ãªããã¿ãŒã³ãã¡ã€ã«ã å€ã倧ãããããšåæ£ã倧ãããªããŸãããåæ£ãå¢å ããŸãã
誀æ€ç¥ã®ãªã¹ã¯ã ãã¿ãŒã³ãšã³ããªãŒããšã®ãã¡ãº
ãã¿ãŒã³ ãã¡ã€ã«å ã®ä»æ§ã¯ãããã§èšå®ãããå€ããªãŒããŒã©ã€ãããŸãã
--ãã¿ãŒã³= or -p
IKE ããã¯ãªã ãã¿ãŒã³ ãã¡ã€ã«ã䜿çšãããããã©ã«ã=/usr/local/share/ike-scan/ike-backoff-
ãã¿ãŒã³ã ããã¯ãIKE ããã¯ãªã ãã¿ãŒã³ãå«ããã¡ã€ã«ã®ååãæå®ããŸãã
ãã®ãã¡ã€ã«ã¯ã--showbackoff ãæå®ãããŠããå Žåã«ã®ã¿äœ¿çšãããŸãã
--vidpatterns= or -I
ãã³ã㌠ID ãã¿ãŒã³ ãã¡ã€ã«ã䜿çšãããããã©ã«ã=/usr/local/share/ike-scan/ike-vendor-idsã
ãã³ã㌠ID ãã¿ãŒã³ãå«ããã¡ã€ã«ã®ååãæå®ããŸãã ãããã®ãã¿ãŒã³
ãã³ã㌠ID ãã£ã³ã¬ãŒããªã³ãã£ã³ã°ã«äœ¿çšãããŸãã
- æ»æç or -A
IKE ã¢ã°ã¬ãã·ã ã¢ãŒãã䜿çšããŸã (ããã©ã«ãã¯ã¡ã€ã³ ã¢ãŒãã§ã) --aggressive ãæå®ãããšã
--dhgroupã--idã--idtype ãæå®ã§ããŸãã ã«ã¹ã¿ã ã䜿çšããå Žå
--trans ãªãã·ã§ã³ã䜿çšããã¢ã°ã¬ãã·ã ã¢ãŒãã§ã®å€æããã¹ãŠã®å€æãè¡ãããããšã«æ³šæããŠãã ããã
åã DH ã°ã«ãŒããæã€å¿ èŠããããããã¯ã§æå®ãããã°ã«ãŒããšäžèŽããå¿ èŠããããŸãã
--dhgroupããŸã㯠--dhgroup ã䜿çšãããªãå Žåã®ããã©ã«ãã
--id= or -n
䜿çšèå¥å€ãšããŠã ãã®ãªãã·ã§ã³ã¯ã¢ã°ã¬ãã·ãã«ã®ã¿é©çšãããŸã
ã¢ãŒãã --id=test ãªã©ã®æååãšããŠããŸã㯠ã䜿çšãã XNUMX é²å€ãšããŠæå®ã§ããŸãã
å é ã«ã0xããä»ããŸã (äŸ: --id=0xdeadbeef)ã
--idtype= or -y
èå¥ã¿ã€ãã䜿çšããã ããã©ã«ã㯠3 (ID_USER_FQDN)ã ãã®ãªãã·ã§ã³ã¯ãããŸã§
ã¢ã°ã¬ãã·ãã¢ãŒãã«é©çšãããŸãã èå¥ã®è©³çŽ°ã«ã€ããŠã¯ãRFC 2407 4.6.2 ãåç §ããŠãã ããã
ã¿ã€ãã
--dhgroup= or -g
ãã£ãã£ãŒã»ãã«ãã³ã»ã°ã«ãŒãã䜿çšããã ããã©ã«ã 2ããã®ãªãã·ã§ã³ã¯æ¬¡ã®å Žåã«ã®ã¿é©çšãããŸãã
ã¢ã°ã¬ãã·ã ã¢ãŒããš IKEv2ã ã©ã¡ãã®å Žåãã次ã®ãµã€ãºã決å®ããããã«äœ¿çšãããŸãã
éµäº€æãã€ããŒãã ã«ã¹ã¿ã å€æã§ã¢ã°ã¬ãã·ã ã¢ãŒãã䜿çšããå Žåã
ããã©ã«ãã䜿çšããŠããªãéããé垞㯠--dhgroup ãªãã·ã§ã³ã䜿çšããå¿ èŠããããŸãã
DHã°ã«ãŒãã 蚱容å€ã¯ 1,2,5,14,15,16,17,18ãXNUMXãXNUMXãXNUMXãXNUMXãXNUMXãXNUMXãXNUMX (MODP ã®ã¿) ã§ãã
--gssid= or -G
GSS ID ã䜿çšããã©ã㯠16384 é²æååã§ãã ããã¯ãå€æå±æ§ã¿ã€ã XNUMX ã䜿çšããŸãã
Windows-07 ã§ã¯ãdraft-ietf-ipsec-isakmp-gss-auth-2000.txt ã§æå®ãããŠãããšããã§ãã
32001 ã䜿çšãããŠããããšã芳å¯ãããŠããŸãã Windows 2000 ã®å Žåã¯ã次ã䜿çšããå¿ èŠããããŸãã
--auth=65001 ã¯ãKerberos (GSS) èªèšŒãæå®ããŸãã
- ã©ã³ãã or -R
ãã¹ããªã¹ããã©ã³ãã åããŸãã ãã®ãªãã·ã§ã³ã¯ããã¹ãå ã®ãã¹ãã®é åºãã©ã³ãã åããŸãã
ãªã¹ãã«å«ãŸãããããIKE ãããŒãã¯ã©ã³ãã ãªé åºã§ãã¹ãã«éä¿¡ãããŸãã ã¯ããŒãã䜿çšããŸã
ã·ã£ããã«ã¢ã«ãŽãªãºã ã
--tcp[= ] or -T[ ]
UDP ã®ä»£ããã« TCP ãã©ã³ã¹ããŒãã䜿çšããŸãã ããã«ãããIKE ãå®è¡ããŠãããã¹ãããã¹ãã§ããŸãã
TCPã éåžžããã®ãªãã·ã§ã³ã¯å¿ èŠãããŸããããªããªããIPsec ã®å€§éšåã¯
ã·ã¹ãã 㯠IKE over UDP ã®ã¿ããµããŒãããŸãã ãªãã·ã§ã³ã®å€ã®ã¿ã€ããæå®ããŸã
TCP çµç±ã® IKEã çŸåšãå¯èœãªå€ã¯ 1 ã€ãããŸãã XNUMX = RAW IKE over TCP
ãã§ãã¯ãã€ã³ãã«ãã£ãŠäœ¿çšãããŸã (ããã©ã«ã)ã 2 = ã·ã¹ã³ã䜿çšããã«ãã»ã«åããã IKE over TCPã ããã
ãªãã·ã§ã³ã®ç瞮圢 (-T) ã䜿çšããŠããå Žåãå€ã¯ããã«å ¥åããå¿ èŠããããŸãã
ãªãã·ã§ã³æåã®åŸã«ã¯ã¹ããŒã¹ãå ¥ããŸãããããšãã°ã-T 2 ã§ã¯ãªã -T2 ãæå®ããŸããæå®ã§ããã®ã¯ã
ãã®ãªãã·ã§ã³ã䜿çšããå Žåã¯ãã¿ãŒã²ãã ãã¹ãã XNUMX ã€ã ãã«ãªããŸãã
--tcptimeout= or -O
TCP æ¥ç¶ã¿ã€ã ã¢ãŠãã次ã®ããã«èšå®ããŸãç§ (ããã©ã«ã = 10)ã ããã¯ä»¥äžã«ã®ã¿é©çšãããŸã
TCP ãã©ã³ã¹ããŒã ã¢ãŒãã
--pskcrack[= ã or -P[ ã
ã¢ã°ã¬ãã·ã ã¢ãŒãã®äºåå ±æããŒãã¯ã©ãã¯ããŸãã ãã®ãªãã·ã§ã³ã¯ã¢ã°ã¬ãã·ã ã¢ãŒããåºåããŸãã
ãpsk-crackãããã°ã©ã ã䜿çšãããªãã©ã€ã³ã¯ã©ããã³ã°çšã®äºåå ±æããŒïŒPSKïŒãã©ã¡ãŒã¿
ãã㯠ike-scan ã«ä»å±ããŠããŸãã ãªãã·ã§ã³ã§ãã¡ã€ã«åãæå®ã§ããŸãã ã ã«
PSKãã©ã¡ãŒã¿ãã«æžã蟌ã¿ãŸãã ãã¡ã€ã«åãæå®ããªãå ŽåãPSK
ãã©ã¡ãŒã¿ã¯æšæºåºåã«æžã蟌ãŸããŸãã ã®çã圢åŒã䜿çšããŠããå Žåã
ãªãã·ã§ã³ (-P) ã®å Žåããªãã·ã§ã³æåã®çŽåŸã«å€ãæå®ããå¿ èŠããããŸãã
ã¹ããŒã¹ãããšãã° -P file ã§ã¯ãªã -Pfileã 次ã®å Žåã¯ãã¿ãŒã²ãã ãã¹ãã XNUMX ã€ã ãæå®ã§ããŸãã
ãã®ãªãã·ã§ã³ã䜿çšããŠãã ããã ãã®ãªãã·ã§ã³ã¯ãIKE ã¢ã°ã¬ãã·ã ã¢ãŒãã«ã®ã¿é©çšãããŸãã
--ããªãã or -N
åå解決㫠DNS ã䜿çšããªãã§ãã ããã ãã®ãªãã·ã§ã³ã䜿çšããå Žåã¯ããã¹ãŠã®ãã¹ãã
IPã¢ãã¬ã¹ãšããŠæå®ããŸãã
--ãã³ã»ã¬ã³= or -c
ãã³ã¹ã®é·ãã次ã®ããã«èšå®ããŸãã ãã€ãã ããã©ã«ã = 20 ãã®ãªãã·ã§ã³ã¯ã
ã¢ã°ã¬ãã·ã ã¢ãŒããŸã㯠IKEv2 ãªã¯ãšã¹ãã§éä¿¡ããã nonce ãã€ããŒãã éåžžã¯
nonce ãµã€ãºãå°ãããããå Žåãé€ãããã®ãªãã·ã§ã³ã䜿çšããå¿ èŠã¯ãããŸããã
äºåå ±æããŒã®ã¯ã©ããã³ã°ãé«éåããå ŽåããŸãã¯ç¹å®ã®ãµãŒããŒãã©ã®ããã«ã¯ã©ããã³ã°ãããã確èªãããå Žå
ç°ãªãé·ãã® nonce ãã€ããŒããåŠçããŸãã RFC 2409 ã§ã¯ããã³ã¹ã®é·ãã¯æ¬¡ã®ããã«èŠå®ãããŠããŸãã
ãã€ããŒã㯠8 ïœ 256 ãã€ãã§ããå¿ èŠããããŸãããike-scan ã¯ããã匷å¶ããŸããã
é·ããã³ã¹é·ãæå®ãããšãike- ã«ãã£ãŠéä¿¡ããããã±ããã®ãµã€ãºãå¢å ããŸãã
ã¹ãã£ã³ã ãã³ã¹ã®é·ããéåžžã«é·ããšãæçåãçºçããããæ倧 IP ãè¶ ããå¯èœæ§ããããŸãã
ãã±ãããµã€ãºã ãã®ãªãã·ã§ã³ã¯ãIKE ã¢ã°ã¬ãã·ã ã¢ãŒãã«ã®ã¿é©çšãããŸãã
--headerlen= or -L
ISAKMP ããããŒã®é·ãã次ã®ããã«èšå®ããŸãã ãã€ãã ãã®ãªãã·ã§ã³ã䜿çšãããšã
ISAKMP ããããŒé·ã«äœ¿çšããå€ãæåã§æå®ããŸãã ããã©ã«ãã§ã¯ã
ike-scan ã¯æ£ããå€ãå ¥åããŸãã ãã®ãªãã·ã§ã³ã䜿çšããŠãæåã§æå®ããŸãã
é·ããééã£ãŠããŸãã é·ãã n ãã€ãã«èšå®ããã+nããšããŠæå®ã§ããŸãã
å¿ èŠä»¥äžã«å€§ããå Žåãã-nããæå®ãããš n ãã€ãå°ãªããªãããnããæå®ãããš n ãã€ãæžããŸãã
ãŸãã«ãã€ãã ããããŒã®é·ããééã£ãå€ã«å€æŽãããšãå Žåã«ãã£ãŠã¯
VPN ãµãŒããŒãäžæããŸãã
--mbz= or -Z
å€ã䜿çšããäºçŽæžã¿ (MBZ) ãã£ãŒã«ãã®å Žåãããã©ã«ã = 0ã ãã®ãªãã·ã§ã³ãæå®ãããš
çºä¿¡ãã±ããã RFC éæºæ ã«ããããã次ã®å Žåã«ã®ã¿äœ¿çšããŠãã ããã
VPN ãµãŒããŒãç¡å¹ãªãã±ããã«ã©ã®ããã«å¿çãããã確èªããŠãã ããã ã®å€ããã¹ãã§ã
0 ïœ 255 ã®ç¯å²ã§æå®ããŸãã
--headerver= or -E
ISAKMPããããŒã®ããŒãžã§ã³ãæå®ããŸãã ããã©ã«ã㯠0x10 (16) ã§ãããã¯æ¬¡ã®å€ã«çžåœããŸãã
v1.0ã ããã©ã«ã以å€ã®å€ãæå®ãããšãéä¿¡ãã±ãããé RFC ã«ãªããŸãã
ã«æºæ ããŠãããVPN ãµãŒããŒãã©ã®ããã«åå¿ãããã確èªãããå Žåã«ã®ã¿äœ¿çšããŠãã ããã
å¥åŠãªããŒãžã§ã³ã å€ã¯ 0 ïœ 255 ã®ç¯å²å ã§ããå¿ èŠããããŸãã
--certreq= or -C
CertificateRequest ãã€ããŒããè¿œå ããã XNUMX é²å€ãšããŠæå®ããå¿ èŠããããŸãã
XNUMX é²å€ã®æåã®ãã€ãã¯èšŒææžã®ã¿ã€ããšããŠè§£éãããŸãã ã®
æ®ãã®ãã€ãã¯ãRFC 2408 3.10 ã«èšèŒãããŠããèªèšŒå±ãšããŠäœ¿çšãããŸãã ã®
蚌ææžã®çš®é¡ã¯ RFC 2408 sec 3.9 ã«ãªã¹ããããŠããŸãã RFC 2048 ã«ã¯ãã蚌ææž
ãªã¯ãšã¹ãã®ãã€ããŒãã¯äº€æäžã®ã©ã®æç¹ã§ãåãå ¥ããããªããã°ãªããŸããã
--doi= or -D
SA DOI ã次ã®ããã«èšå®ããŸãã ãããã©ã«ã㯠1 (IPsec)ã éåžžã¯å€æŽããããªãã§ããã
ããã¯ãVPN ãµãŒããŒãéæšæºã® DOI ã«ã©ã®ããã«å¿çãããã確èªãããå Žåãé€ããŸãã
--ç¶æ³= or -S
SA ç¶æ³ã次ã®ããã«èšå®ããŸãã ãããã©ã«ã㯠1ãç¶æ³ã®æå³ã¯ä»¥äžã«ãã£ãŠç°ãªããŸãã
DOI ã§ãããé©å㪠DOI ææžã«è©³çŽ°ãèšèŒãããŠããŸãã IPsec DOI ã®å Žåã
ããã©ã«ãã®ç¶æ³ 1 㯠SIT_IDENTITY_ONLY ãè¡šããŸãã éåžžã¯ããããããªãã§ããã
VPN ãµãŒããŒãéæšæºã«ã©ã®ããã«å¿çãããã確èªããããªãå Žåã¯ããããå€æŽããŠãã ããã
ç¶æ³ã
--ãããã³ã«= or -j
ããããŒã¶ã«ãããã³ã« ID ã次ã®ããã«èšå®ããŸãã ãããã©ã«ã 1. ææ¡ã®æå³
ãããã³ã« ID 㯠DOI ã«ãã£ãŠç°ãªããé©å㪠DOI ææžã«è©³çŽ°ãèšèŒãããŠããŸãã
IPsec DOI ã®å Žåãããã©ã«ãã®ããããŒã¶ã« ãããã³ã« ID 1 㯠PROTO_ISAKMP ãè¡šããŸãã
VPN ãµãŒããŒãã©ã®ããã«åäœãããã確èªãããå Žåãé€ããéåžžã¯ãããå€æŽããå¿ èŠã¯ãããŸããã
éæšæºã®ãããã³ã« ID ã«å¿çããŸãã
--transid= or -k
å€æ ID ã次ã®ããã«èšå®ããŸãã ãããã©ã«ã㯠1ãå€æ ID ã®æå³ã¯æ¬¡ã«ãã£ãŠç°ãªããŸãã
DOI ã§ãããé©å㪠DOI ææžã«è©³çŽ°ãèšèŒãããŠããŸãã IPsec DOI ã®å Žåã
ããã©ã«ãã®å€æ ID ã® 1 㯠KEY_IKE ãè¡šããŸãã éåžžã¯å€æŽããããªãã§ããã
VPN ãµãŒããŒãéæšæºã®å€æã«ã©ã®ããã«å¿çãããã確èªããããªãå Žåãé€ããããã¯å¿ èŠã§ãã
IDãæå®ããŸãã
--spisize=
ããããŒã¶ã« SPI ãµã€ãºã次ã®ããã«èšå®ããŸãã ã ããã©ã«ã = 0 ããããŒã以å€ã®å Žåãã©ã³ãã 㪠SPI
æå®ããããµã€ãºã®ããŒã¿ââãããããŒã¶ã«ã®ãã€ããŒãã«è¿œå ãããŸãã ããã©ã«ãã¯ãŒã
SPIããªãããšãæå³ããŸãã
--hdrflags=
ISAKMP ããã㌠ãã©ã°ã次ã®ããã«èšå®ããŸãã ã ããã©ã«ã = 0 ãã©ã°ã®è©³çŽ°ã¯ RFC 2408 ã«èšèŒãããŠããŸãã
ã»ã¯ã·ã§ã³3.1
--hdrmsgid=
ISAKMP ããããŒã®ã¡ãã»ãŒãž ID ã次ã®ããã«èšå®ããŸãã ã ããã©ã«ã = 0 IKE ã®å Žåã¯ãŒãã«ããå¿ èŠããããŸãã
ãã§ãŒãº1ã
--ã¯ãããŒ=
ISAKMP ã€ãã·ãšãŒã¿ãŒ Cookie ã次ã®ããã«èšå®ããŸãã Cookie å€ã¯ XNUMX é²æ°ã§æå®ããå¿ èŠããããŸãã
ããã©ã«ãã§ã¯ãCookie ã¯èªåçã«çæãããäžæã®å€ãæã¡ãŸãã ããããããã
ãã®ãªãã·ã§ã³ãæå®ãããšãike-scan ã®ãã XNUMX ã€ã®ã¿ãŒã²ããã®ã¿ãæå®ã§ããŸãã
å¿çãã±ãããç §åããã«ã¯äžæã® Cookie å€ãå¿ èŠã§ãã
--亀æ=
亀æã¿ã€ãã次ã®ããã«èšå®ããŸãã ãã®ãªãã·ã§ã³ã䜿çšãããšã亀æã¿ã€ããå€æŽã§ããŸãã
ISAKMP ããããŒãä»»æã®å€ã«å€æŽããŸãã ike-scan 㯠Main ãš
ã¢ã°ã¬ãã·ã ã¢ãŒã (ããããå€ 2 ãš 4)ã ä»ã®å€ãæå®ãããšã
ISAKMP ããããŒã®äº€æã¿ã€ãã®å€ãå€æŽããŸãããä»ã®å€ã¯èª¿æŽããŸãã
ãã€ããŒãã 亀æã¿ã€ã㯠RFC 2408 sec 3.1 ã§å®çŸ©ãããŠããŸãã
--nextpayload=
ISAKMP ããããŒã®æ¬¡ã®ãã€ããŒãã次ã®ããã«èšå®ããŸãã éåžžã次ã®ãã€ããŒãã¯
èªåçã«æ£ããå€ã«èšå®ãããŸãã
--ã©ã³ãã ã·ãŒã=
䜿çšæ¬äŒŒä¹±æ°ãžã§ãã¬ãŒã¿ãŒãã·ãŒãããŸãã ãã®ãªãã·ã§ã³ã¯ PRNG ãã·ãŒãããŸã
æå®ããæ°å€ã䜿çšããŸããããã¯ã
ãã±ãã ããŒã¿ã«ã©ã³ãã ããŒã¿ãå«ããã€ããŒããå«ãŸããå Žåããã±ãã ããŒã¿ã¯æ£ç¢ºã«åçŸå¯èœã§ãã
ããŒäº€æãŸã㯠nonce ãšããŠã ããã©ã«ãã§ã¯ãPRNG ã«ã¯äºæž¬äžå¯èœãªããŒã¿ãã·ãŒããããŸãã
ã®å€ã§ãã
-ã¿ã€ã ã¹ã¿ã³ã
åä¿¡ãããã±ããã®ã¿ã€ã ã¹ã¿ã³ãã衚瀺ããŸãã ãã®ãªãã·ã§ã³ã«ãããã¿ã€ã ã¹ã¿ã³ãã¯æ¬¡ã®ããã«ãªããŸãã
åä¿¡ãããã±ããããšã«è¡šç€ºãããŸãã
--sourceip=
éä¿¡ãã±ããã®éä¿¡å IP ã¢ãã¬ã¹ã ã«èšå®ããŸãã ãã®ãªãã·ã§ã³ã«ãããéä¿¡ãè¡ãããŸãã
æå®ãããéä¿¡å IP ã¢ãã¬ã¹ãæ〠IKE ãã±ããã ã¢ãã¬ã¹ã¯æ¬¡ã®ããããã«ãªããŸãã
ãããåºåãã®ã¯ã¯ãã圢åŒã® IP ã¢ãã¬ã¹ããŸãã¯å¥ã®æååãã©ã³ãã ãã䜿çšããŸãã
éä¿¡ãããåãã±ããã®ã©ã³ãã ãªéä¿¡å ã¢ãã¬ã¹ã ãã®ãªãã·ã§ã³ã䜿çšããå Žåãããã
ãã±ãããåä¿¡ãããŸãããã®ãªãã·ã§ã³ã«ã¯çã®ãœã±ããã®ãµããŒããå¿ èŠã§ãã
é«ãéä¿¡å ããŒããæå®ããå Žåã§ãããã®ãªãã·ã§ã³ã䜿çšããã«ã¯ã¹ãŒããŒãŠãŒã¶ãŒæš©éãå¿ èŠã§ãã
ãã®ãªãã·ã§ã³ã¯ããã¹ãŠã®ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã§æ©èœããããã§ã¯ãããŸããã
--shownum
åä¿¡ãããã±ããã®ãã¹ãçªå·ã衚瀺ããŸãã ããã«ãããéåžžã®ãã¹ãã衚瀺ãããŸã
IP ã¢ãã¬ã¹ã®åã«å¿çãã¹ãã®çªå·ãä»ããŸãã éããšãã«äŸ¿å©ãããããŸãã
åãã¿ãŒã²ãã IP ãžã®å€æ°ã®ãã±ãããéä¿¡ããŠãç¡èŠãããŠãããããŒãããããã©ããã確èªããŸãã
--nat-t
RFC 3947 NAT-Traversal ã«ãã»ã«åã䜿çšããŸãã ãã®ãªãã·ã§ã³ã¯ãé ESP ããŒã«ãŒã
éä¿¡ãã±ããã®å é ãåãåºãã説æã®ããã«åä¿¡ãã±ãããããããåãé€ããŸãã
ãŸããããã©ã«ãã®éä¿¡å ããŒãã 3947 ã«å€æŽããããã©ã«ãã®ããŒãã 4500 ã«å€æŽããŸãã
å®å ããŒãã 4500 ã«èšå®ããŸãããã㯠NAT-T IKE çšã®ããŒãã§ãã ãããã®ããŒãçªå·
--sport ããã³ --dport ãªãã·ã§ã³ã䜿çšããŠå€æŽã§ããŸãããã ãããããã®ãªãã·ã§ã³ã¯åŸã§äœ¿çšãããŸãã
--nat-t ãªãã·ã§ã³ã
--rcookie=
ISAKMP ã¬ã¹ãã³ã㌠Cookie ã次ã®ããã«èšå®ããŸãã ã ããã«ãããã¬ã¹ãã³ã㌠Cookie ã次ã®ããã«èšå®ãããŸãã
æå®ããã XNUMX é²å€ã ããã©ã«ãã§ã¯ãã¬ã¹ãã³ã㌠Cookie ã¯ãŒãã«èšå®ãããŸãã
--ikev2 or -2
IKE ããŒãžã§ã³ 2 ã䜿çšããŸããããã«ãããéä¿¡ãã±ããã¯å®çŸ©ã©ããã« IKEv2 圢åŒã䜿çšããŸãã
ããã©ã«ãã®IKEv4306圢åŒã§ã¯ãªãRFC 1ã§ã è¿ããããã±ããã¯ãã¹ãŠã
ã«é¢ä¿ãªãããã€ããŒãã«å¿ã㊠IKE ãŸã㯠IKEv2 ãšããŠèªåçã«ãã³ãŒããããŸãã
ãã®ãªãã·ã§ã³ã --ikev2 ãªãã·ã§ã³ã¯çŸåšå®éšæ®µéã§ãã ããã§ã¯ãããŸãã
åºç¯å²ã«ãã¹ããããŠãããããã©ã«ãã®ããããŒã¶ã«ã®éä¿¡ã®ã¿ããµããŒãããŠããŸãã
onworks.net ãµãŒãã¹ã䜿çšããŠãªã³ã©ã€ã³ã§ ike-scan ã䜿çšãã