Èçäàòåëüñêèé äîì ÎÎÎ "Ãåéì Ëýíä"ÑÏÅÖÂÛÏÓÑÊ ÆÓÐÍÀËÀ ÕÀÊÅÐ #72, ÍÎßÁÐÜ 2006 ã.

ñîâåðøåííî ñåêðåòíî

ÐÎÌÀÍ ËÓÊÎÂÍÈÊÎÂ (LRB@SANDY.RU)

Ñïåöâûïóñê: Õàêåð, íîìåð #072, ñòð. 072-010-7


Íî ñàìîãî ñåðòèôèêàòà äëÿ IPSec ó íàñ ïîêà íåò. Ïîëó÷èì åãî:

1 Ñ ÊÎÌÏÜÞÒÅÐÀ, ÍÀ ÊÎÒÎÐÎÌ ÒÐÅÁÓÅÒÑß ÓÑÒÀÍÎÂÈÒÜ ÑÅÐÒÈÔÈÊÀÒÛ, Â ÀÄÐÅÑÍÎÉ ÑÒÐÎÊÅ ÍÀÁÈÐÀÅØÜ: HTTP://IP_ÖÅÍÒÐÀ_ÑÅÐÒ/CERTSRV.

2 ÂÛÁÈÐÀÅØÜ REQUEST A CERTIFICATE È ÆÌÅØÜ NEXT.

3 ÂÛÁÈÐÀÅØÜ ADVANCED REQUEST È ÆÌÅØÜ NEXT.

4 ÂÛÁÈÐÀÅØÜ SUBMIT A CERTIFICATE REQUEST TO THIS CA USING A FORM È ÆÌÅØÜ NEXT.

5 ÓÊÀÇÛÂÀÅØÜ ÏÀÐÀÌÅÒÐÛ ÇÀÏÐÎÑÀ. ÈÇ ÎÁßÇÀÒÅËÜÍÎÃÎ INTENDED PURPOSE ÂÛÁÈÐÀÅØÜ IPSEC CERTIFICATE (ÌÎÆÍÎ ÎÑÒÀÂÈÒÜ È CLIENT AUTHENTICATION CERTIFICATE, ÎÁËÀÑÒÜ ÅÃÎ ÏÐÈÌÅÍÅÍÈß ÁÎËÅÅ ØÈÐÎÊÀß).

6 ÂÛÁÈÐÀÅØÜ ÎÏÖÈÞ USE LOCAL MACHINE STORE, ÍÀÆÈÌÀÅØÜ ÍÀ SUBMIT È YES.

Äàëüíåéøèå äåéñòâèÿ âûïîëíÿþòñÿ íà êîìïüþòåðå ñ óñòàíîâëåííûì óäîñòîâåðÿþùèì öåíòðîì:

7 ÈÇ ÏÀÏÊÈ ADMINISTRATIVE TOOLS ÎÒÊÐÛÂÀÅØÜ ÎÑÍÀÑÒÊÓ CERTIFICATION AUTHORITY.

8 ÎÒÊÐÛÂÀÅØÜ ÄÅÐÅÂÎ ÊÎÍÑÎËÈ, ÍÀÆÈÌÀß ÍÀ ÏËÞÑÈÊ, È ÂÛÁÈÐÀÅØÜ PENDING REQUESTS.

9 Â ÏÐÀÂÎÉ ÏÀÍÅËÈ ÍÀÕÎÄÈØÜ ÇÀÏÐÎÑ ÍÀ ÍÀØ ÑÅÐÒÈÔÈÊÀÒ, ÍÀ ÍÅÌ ÏÐÀÂÛÉ ÊËÈÊ, ALL TASKS È ISSUE.

Òåïåðü ñ êîìïüþòåðà, ñ êîòîðîãî ñåðòèôèêàò çàïðàøèâàëñÿ, ìîæíî åãî ïîëó÷èòü. Äëÿ ýòîãî:

10 Ñ ÊÎÌÏÜÞÒÅÐÀ, ÍÀ ÊÎÒÎÐÎÌ ÒÐÅÁÓÅÒÑß ÓÑÒÀÍÎÂÈÒÜ ÑÅÐÒÈÔÈÊÀÒ, Â ÀÄÐÅÑÍÎÉ ÑÒÐÎÊÅ ÍÀÁÈÐÀÅØÜ: HTTP://IP_ÖÅÍÒÐÀ_ÑÅÐÒ/CERTSRV.

11 ÂÛÁÈÐÀÅØÜ CHECK ON A PENDING CERTIFICATE, ÄÀËÅÅ NEXT.

12  ÎÊÍÅ PLEASE SELECT THE CERTIFICATE REQUEST YOU WANT TO CHECK ÄÎËÆÅÍ ÏÎßÂÈÒÜÑß ÑÅÐÒÈÔÈÊÀÒ. ÊËÈÊÀÅØÜ NEXT È ÂÛÁÈÐÀÅØÜ INSTALL THIS CERTIFICATE,  ÎÊÍÅ ÍÀÆÈÌÀÅØÜ YES.

Ïðîâåðü, ÷òî â îñíàñòêå Certificate(Local Computer), â âåòâè Personal, Certificates ïîÿâèëñÿ ñåðòèôèêàò.

ÅÑËÈ ÑÅÐÒÈÔÈÊÀÒ ÅÑÒÜ, ÍÎ ÎÒÎÁÐÀÆÀÅÒÑß ÎÍ ÊÀÊ ÍÅÄÅÉÑÒÂÈÒÅËÜÍÛÉ, ÏÐÎÂÅÐÜ, ÍÀÕÎÄÈÒÑß ËÈ ÑÈÑÒÅÌÍÎÅ ÂÐÅÌß ÍÀ ÊÎÌÏÜÞÒÅÐÅ Â ÏÐÎÌÅÆÓÒÊÅ ÂÀËÈÄÍÎÑÒÈ ÑÅÐÒÈÔÈÊÀÒÀ (ÒÎ ÅÑÒÜ ÂÎÇÌÎÆÍÎ, ÑÅÐÒÈÔÈÊÀÒ ÅÙÅ ÍÅ ÂÑÒÓÏÈË Â ÑÈËÓ ÈËÈ ÑÐÎÊ ÅÃÎ ÄÅÉÑÒÂÈß ÓÆÅ ÇÀÊÎÍ×ÈËÑß)

Òåïåðü ïðîáóé îïÿòü óñòàíîâèòü IPSec-ñîåäèíåíèå. Òóííåëü äîëæåí ïîäíÿòüñÿ ñ àóòåíòèôèêàöèåé ñòîðîí ñ ïîìîùüþ ñåðòèôèêàòîâ.

[òðàíñïîðòíûé ðåæèì.]

[ñöåíàðèé 2]

Îáåñïå÷èì øèôðîâàíèå òðàôèêà ìåæäó ôàéëîâûì ñåðâåðîì è êîìïüþòåðàìè â ëîêàëüíîé ñåòè, èñïîëüçóÿ IPSec â òðàíñïîðòíîì ðåæèìå.

Äëÿ ôàéëîâîãî ñåðâåðà ðàçðåøè øèôðîâàííûé òðàôèê íà TCP/139 è TCP/445 ïîðòû è íåøèôðîâàííûå âõîäÿùèå ICMP-ïàêåòû. Âåñü îñòàëüíîé òðàôèê çàïðåòè.

Íàñòðàèâàé ôàéëîâûé ñåðâåð (ðîóòèòü çäåñü íè÷åãî íå íóæíî, ïîýòîìó â êà÷åñòâå ñåðâåðà ïîäîéäåò êîìïüþòåð è ïîä óïðàâëåíèåì íå ñåðâåðíîé ïëàòôîðìû Windows):

1 ÌÅÍÞ START, ÄÀËÅÅ RUN, ÍÀÁÈÐÀÅØÜ SECPOL.MSC È ÍÀÆÈÌÀÅØÜ ENTER.

2 ÏÐÀÂÛÉ ÊËÈÊ ÍÀ IP SECURITY POLICIES ON LOCAL MACHINE, ÄÀËÅÅ ÊËÈÊ CREATE IP SECURITY POLICY.

3 ÊËÈÊÀÅØÜ NEXT.

4 ÏÈØÅØÜ ÈÌß ÍÎÂÎÉ ÏÎËÈÒÈÊÈ, ÍÀÏÐÈÌÅÐ «IPSEC FOR FILE SERVER», ÊËÈÊÀÅØÜ NEXT.

5 ÑÍÈÌÀÅØÜ ÃÀËÊÓ ACTIVATE THE DEFAULT RESPONSE RULE, ÊËÈÊÀÅØÜ NEXT.

6 ÎÑÒÀÂËßÅØÜ ÎÏÖÈÞ EDIT PROPERTIES, ÊËÈÊÀÅØÜ FINISH.

7 ÄÎÁÀÂËßÅØÜ ÏÐÀÂÈËÎ IPSEC, ÊËÈÊÀß ADD...

8 ÄÎÁÀÂËßÅØÜ IP FILTER, ÊËÈÊÀß ADD...

9 ÍÀÇÛÂÀÅØÜ ÔÈËÜÒÐ INBOUND SMB È ÍÀÆÈÌÀÅØÜ ADD...

10  SOURCE ADDRESS ÂÛÁÈÐÀÅØÜ A SPECIFIC IP SUBNET È ÏÈØÅØÜ ÀÄÐÅÑ È ÌÀÑÊÓ ÄËß ÑÅÒÈ «À»,  DESTINATION ADDRESS ÓÊÀÇÛÂÀÅØÜ IP_ÔÀÉË.ÑÅÐÂÅÐÀ. ÎÑÒÀÂËßÅØÜ ÎÏÖÈÞ MIRRORED. ALSO MATCH PACKETS WITH THE EXACT OPPOSITE SOURCE AND DESTINATION ADDRESSES.

Íàçàä íà ñòð. 072-010-6  Ñîäåðæàíèå  Âïåðåä íà ñòð. 072-010-8