์นดํ…Œ๊ณ ๋ฆฌ ์—†์Œ

[10์›” 30์ผ] ASAv ๊ตฌ์ถ•ํ•˜๊ธฐ

ljm 2025. 10. 30. 16:37

 

 

 

 

  • Inside: 192.168.16.0/24
  • DMZ: 192.168.15.0/24
  • Outside: 10.10.10.0/24

 


 

๐Ÿ’ป ASAv ACL ์ •์ฑ… ๋ช…๋ น์–ด (Cisco ASA CLI)

์‹ค์Šต์„ ์œ„ํ•ด ๊ฐ ๊ตฌ์—ญ๋ณ„๋กœ ์ž„์˜์˜ ํ˜ธ์ŠคํŠธ IP๋ฅผ ๊ฐ€์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.

๊ตฌ์—ญ ๋Œ€์—ญ๋Œ€ ์˜ˆ์‹œ ํ˜ธ์ŠคํŠธ IP (VPC)
Inside 192.168.16.0/24 WebDB: 192.168.16.101 , DNS: 192.168.16.106
DMZ 192.168.15.0/24 R2: 192.168.15.254 (์›น ์„œ๋ฒ„)
Outside 10.10.10.0/24 Kali: 10.10.10.200 (์™ธ๋ถ€ ์„œ๋ฒ„)

 

๐ŸŒ ์ •์ฑ… 1: Outside → DMZ ์›น ์„œ๋ฒ„ ์ ‘๊ทผ ํ—ˆ์šฉ 

Outside ์ธํ„ฐํŽ˜์ด์Šค๋กœ ์ธ๋ฐ”์šด๋“œ๋˜๋Š” ํŠธ๋ž˜ํ”ฝ์— ์ ์šฉํ•˜์—ฌ, ์™ธ๋ถ€ ์‚ฌ์šฉ์ž๊ฐ€ DMZ ์›น ์„œ๋ฒ„์— HTTP/HTTPS๋กœ ์ ‘๊ทผํ•˜๋Š” ๊ฒƒ์„ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค.

// 1. Outside -> DMZ ์›น ์„œ๋น„์Šค ์ ‘๊ทผ ํ—ˆ์šฉ ACL ์ •์˜
access-list OUTSIDE_IN extended permit tcp any host 192.168.15.254 eq www 
access-list OUTSIDE_IN extended permit tcp any host 192.168.15.254 eq https

// 2. ACL์„ Outside ์ธํ„ฐํŽ˜์ด์Šค์— ์ธ๋ฐ”์šด๋“œ(in) ๋ฐฉํ–ฅ์œผ๋กœ ์ ์šฉ
access-group OUTSIDE_IN in interface outside

 

๐Ÿ“ก ์ •์ฑ… 2: Inside → DMZ ๊ด€๋ฆฌ์šฉ SSH/Telnet ์ ‘์† ์ œ์–ด

Inside ์ธํ„ฐํŽ˜์ด์Šค๋กœ ์ธ๋ฐ”์šด๋“œ๋˜๋Š” ํŠธ๋ž˜ํ”ฝ์— ์ ์šฉํ•˜์—ฌ, ํŠน์ • ๊ด€๋ฆฌ์ž๋งŒ DMZ ์›น ์„œ๋ฒ„์— SSH ์ ‘์†์„ ํ—ˆ์šฉํ•˜๊ณ , ๋ณด์•ˆ์ด ์ทจ์•ฝํ•œ Telnet์€ ๋ช…์‹œ์ ์œผ๋กœ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค.

// 1. Inside -> DMZ SSH ํ—ˆ์šฉ ๋ฐ Telnet ์ฐจ๋‹จ ACL ์ •์˜
// SSH ํ—ˆ์šฉ (ํŠน์ • ํ˜ธ์ŠคํŠธ)
access-list INSIDE_OUT_DMZ extended permit tcp host 192.168.16.101 host 192.168.15.254 eq ssh 

// Telnet ์ฐจ๋‹จ (๋ณด์•ˆ ๊ฐ•ํ™”)
access-list INSIDE_OUT_DMZ extended deny tcp host 192.168.16.101 host 192.168.15.254 eq telnet 

// **์ฐธ๊ณ **: Inside -> DMZ๋Š” ๊ธฐ๋ณธ ํ—ˆ์šฉ์ด๋ฏ€๋กœ, ์ด ACL์€ Inside ์ธํ„ฐํŽ˜์ด์Šค์— 'out' ๋ฐฉํ–ฅ์œผ๋กœ ์ ์šฉํ•˜๊ฑฐ๋‚˜, DMZ ์ธํ„ฐํŽ˜์ด์Šค์— 'in' ๋ฐฉํ–ฅ์œผ๋กœ ์ ์šฉํ•ด์•ผ ํšจ๊ณผ์ ์ž…๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ๋Š” Inside ์ธํ„ฐํŽ˜์ด์Šค 'out' ์ ์šฉ์„ ๊ฐ€์ •ํ•ฉ๋‹ˆ๋‹ค.
// 2. ACL์„ Inside ์ธํ„ฐํŽ˜์ด์Šค์— ์•„์›ƒ๋ฐ”์šด๋“œ(out) ๋ฐฉํ–ฅ์œผ๋กœ ์ ์šฉ
access-group INSIDE_OUT_DMZ out interface inside

 

๐Ÿ”€ ์ •์ฑ… 3: Inside → Outside Ping ํ†ต์‹  ์ œ์–ด (ICMP ํ•™์Šต)

Inside์˜ DNS์—์„œ๋งŒ Outside์˜ Kali๋กœ์˜ Ping ํ†ต์‹ ์„ ํ—ˆ์šฉํ•˜๊ณ , ๊ทธ ์™ธ Inside์˜ ๋‹ค๋ฅธ ๋ชจ๋“  ICMP ํ†ต์‹ ์„ ์ฐจ๋‹จํ•˜์—ฌ ICMP ์ œ์–ด๋ฅผ ํ•™์Šตํ•ฉ๋‹ˆ๋‹ค.

// 1. Inside -> Outside ICMP ์ œ์–ด ACL ์ •์˜
// Ping ํ—ˆ์šฉ (ํŠน์ • ํ˜ธ์ŠคํŠธ)
access-list ICMP_CONTROL extended permit icmp host 192.168.16.106 host 10.10.10.200 echo 

// ๊ทธ ์™ธ Inside ๋Œ€์—ญ์˜ ๋ชจ๋“  ICMP ์ฐจ๋‹จ (๋ณด์•ˆ ๊ฐ•ํ™”)
// ์ด ์ •์ฑ…์€ ์œ„์— ์ž‘์„ฑํ•œ permit ์ •์ฑ…๋ณด๋‹ค ํ›„์ˆœ์œ„์— ์œ„์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
access-list ICMP_CONTROL extended deny icmp 192.168.16.0 255.255.255.0 any 

// **์ฐธ๊ณ **: ์ด ACL์€ Inside ์ธํ„ฐํŽ˜์ด์Šค์— 'out' ๋ฐฉํ–ฅ์œผ๋กœ ์ ์šฉ๋˜์–ด์•ผ Outside๋กœ ๋‚˜๊ฐ€๋Š” ํŠธ๋ž˜ํ”ฝ์„ ์ œ์–ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
// 2. ACL์„ Inside ์ธํ„ฐํŽ˜์ด์Šค์— ์•„์›ƒ๋ฐ”์šด๋“œ(out) ๋ฐฉํ–ฅ์œผ๋กœ ์ ์šฉ
access-group ICMP_CONTROL out interface inside

 

โŒ ์ •์ฑ… 4: DMZ → Inside ์ „๋ฉด ์ฐจ๋‹จ (๋ณด์•ˆ ๊ฐ•ํ™”)

๋ณด์•ˆ ๋ ˆ๋ฒจ์ด ๋‚ฎ์€ DMZ์—์„œ ๋†’์€ Inside๋กœ์˜ ์ ‘๊ทผ์„ ๋ช…์‹œ์ ์œผ๋กœ ์ฐจ๋‹จํ•˜์—ฌ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•ฉ๋‹ˆ๋‹ค. (์ด ์ •์ฑ…๋„ ASA ๊ธฐ๋ณธ ๊ทœ์น™์— ์˜ํ•ด ์ด๋ฏธ ์ฐจ๋‹จ๋˜์ง€๋งŒ, ๋ช…์‹œ์  ์ฐจ๋‹จ ํ•™์Šต์„ ์œ„ํ•ด ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.)

// 1. DMZ -> Inside ์ „๋ฉด ์ฐจ๋‹จ ACL ์ •์˜
access-list DMZ_TO_INSIDE extended deny ip 192.168.15.0 255.255.255.0 192.168.16.0 255.255.255.0

// 2. ACL์„ DMZ ์ธํ„ฐํŽ˜์ด์Šค์— ์ธ๋ฐ”์šด๋“œ(in) ๋ฐฉํ–ฅ์œผ๋กœ ์ ์šฉ
access-group DMZ_TO_INSIDE in interface dmz

 


โš ๏ธ ์ค‘์š”: ACL ์ ์šฉ ๋ฐฉํ–ฅ

ACL์„ ์ ์šฉํ•  ๋•Œ๋Š” ๋ฐฉํ–ฅ(in ๋˜๋Š” out)์ด ๋งค์šฐ ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค.

  • in (์ธ๋ฐ”์šด๋“œ): ํŠธ๋ž˜ํ”ฝ์ด ํ•ด๋‹น ์ธํ„ฐํŽ˜์ด์Šค๋กœ ๋“ค์–ด์˜ฌ ๋•Œ ๊ฒ€์‚ฌํ•ฉ๋‹ˆ๋‹ค.
  • out (์•„์›ƒ๋ฐ”์šด๋“œ): ํŠธ๋ž˜ํ”ฝ์ด ํ•ด๋‹น ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ํ†ตํ•ด ๋‚˜๊ฐˆ ๋•Œ ๊ฒ€์‚ฌํ•ฉ๋‹ˆ๋‹ค.