ã¯ã©ãŠãæ代ã®æ°ããã«ã¿ãããããããã解説
SASEã£ãŠèããããšããïŒ
æè¿ãITã®äžçã§ããè³ã«ããããã«ãªã£ããSASEãïŒèªã¿æ¹ïŒãµã·ãŒããŸãã¯ãµãã·ãŒïŒããªãã ãé£ãããâŠãšæãããããããŸããããå®ã¯ç§ãã¡ã®åãæ¹ãã€ã³ã¿ãŒãããã®äœ¿ãæ¹ã«æ·±ãé¢ãããšãŠãéèŠãªèãæ¹ãªãã§ãã
ç¹ã«ããã¬ã¯ãŒã¯ãå¢ããããäŒç€Ÿã®ã·ã¹ãã ãã¯ã©ãŠãã«ç§»ã£ããããŠããä»ã泚ç®åºŠãæ¥äžæäžïŒð ãã®èšäºã§ã¯ãSASEãäžäœäœãªã®ãããªãå¿ èŠãªã®ããåå¿è ã®æ¹ã«ãåããããã解説ããŠãããŸãã
ð¡ SASEãšã¯ïŒ
SASEã¯ãSecure Access Service Edgeãã®ç¥ã§ããã¢ã¡ãªã«ã®èª¿æ»äŒç€Ÿã¬ãŒãããŒã2019幎ã«æå±ããããããã¯ãŒã¯ãšã»ãã¥ãªãã£ã®æ°ããæŠå¿µïŒãã¬ãŒã ã¯ãŒã¯ïŒã§ãã
ç°¡åã«èšããšãããããã¯ãŒã¯æ©èœããšãã»ãã¥ãªãã£æ©èœããã¯ã©ãŠãäžã§äžã€ã«ãŸãšããŠæäŸãã¡ãããïŒãšããèãæ¹ã§ããããã«ããããŠãŒã¶ãŒãã©ãã«ããŠããã©ããªããã€ã¹ã䜿ã£ãŠããŠããå®å šãã€å¿«é©ã«ç€Ÿå ã·ã¹ãã ãã¯ã©ãŠããµãŒãã¹ãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã
ãªãä»SASEãå¿ èŠãªã®ïŒ ð€
æã¯ãäŒç€Ÿã®æ å ±ãã·ã¹ãã ã¯ãã»ãšãã©ã瀟å ã®ããŒã¿ã»ã³ã¿ãŒã«ãããŸããã瀟å¡ã¯äŒç€Ÿã«åºç€Ÿãã瀟å ãããã¯ãŒã¯ããã·ã¹ãã ãå©çšããã®ãæ®éã§ããããã®ãããäŒç€Ÿã®ãããã¯ãŒã¯ã®åºå ¥ãå£ïŒå¢çç·ïŒãããã£ããå®ã£ãŠããã°ãããçšåºŠã®å®å šæ§ã¯ç¢ºä¿ã§ããŠããŸããð¡ïžã
ããããæ代ã¯å€§ããå€ãããŸããã
- ã¯ã©ãŠããµãŒãã¹ã®æ®åïŒ Microsoft 365ãGoogle WorkspaceãSalesforceãªã©ã䟿å©ãªã¯ã©ãŠããµãŒãã¹ã䜿ãã®ãåœããåã«ãªããŸãããããŒã¿ãã·ã¹ãã ã瀟å€ïŒã¯ã©ãŠãïŒã«ããããšãå¢ããŸããâïžã
- ãã¬ã¯ãŒã¯ã®æµžéïŒ èªå® ãã«ãã§ãªã©ããªãã£ã¹ä»¥å€ã®å Žæããä»äºããã人ãå¢ããŸããð âã
- ã¢ãã€ã«ããã€ã¹ã®å©çšïŒ ã¹ããŒããã©ã³ãã¿ãã¬ãããªã©ãæ§ã ãªããã€ã¹ããäŒç€Ÿã®æ å ±ã«ã¢ã¯ã»ã¹ããããã«ãªããŸããð±ã
ãããªããšãåŸæ¥ã®ãäŒç€Ÿã®åºå ¥ãå£ã ãå®ãããšããèãæ¹ïŒå¢çåé²åŸ¡ïŒã§ã¯ãã»ãã¥ãªãã£ã確ä¿ããã®ãé£ãããªã£ãŠããŸãããŠãŒã¶ãŒãããŒã¿ãè²ã ãªå Žæã«æ£ãã°ã£ãŠãããããã¢ã¯ã»ã¹ããå Žæããšã«ã»ãã¥ãªãã£å¯Ÿçãå¿ èŠã«ãªãã管çãè€éåããŠããŸããŸãã
ããã§ç»å Žããã®ãSASEã§ãïŒâš SASEã¯ããŠãŒã¶ãŒãããã€ã¹ããã©ãã«ããããã§ã¯ãªããã誰ãããäœã«ãã¢ã¯ã»ã¹ããããšããŠãããã«åºã¥ããŠãã¯ã©ãŠãäžã§äžæ¬ããŠã»ãã¥ãªãã£ãã§ãã¯ãšãããã¯ãŒã¯æ¥ç¶ãè¡ããŸãã
SASEã®äž»ãªæ§æèŠçŽ ð§©
SASEã¯ã倧ããåããŠããããã¯ãŒã¯æ©èœããšãã»ãã¥ãªãã£æ©èœããçµã¿åããã£ãŠããŸããå ·äœçã«ã¯ã以äžã®ãããªæè¡èŠçŽ ãå«ãŸããŸãã
ã«ããŽãª | æè¡èŠçŽ | ç°¡åãªèª¬æ |
---|---|---|
ãããã¯ãŒã¯æ©èœ | SD-WAN (Software-Defined Wide Area Network) |
ãœãããŠã§ã¢ã䜿ã£ãŠãæ ç¹éã®ãããã¯ãŒã¯æ¥ç¶ãè³¢ããå¹ççã«ç®¡çããæè¡ãéä¿¡çµè·¯ãæé©åããŠãããŸãã |
ã»ãã¥ãªãã£æ©èœ | SWG (Secure Web Gateway) |
ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹æã®ã»ãã¥ãªãã£å¯Ÿçãå±éºãªãµã€ããžã®ã¢ã¯ã»ã¹ããããã¯ãããããŠã€ã«ã¹ãã§ãã¯ããããããŸãã |
CASB (Cloud Access Security Broker) |
ã¯ã©ãŠããµãŒãã¹ã®å©çšç¶æ³ãç£èŠããã»ãã¥ãªãã£ããªã·ãŒãé©çšããä»çµã¿ãæ å ±æŒæŽ©ãªã©ãé²ããŸãã | |
ZTNA (Zero Trust Network Access) |
ãäœãä¿¡çšããªãããåæã«ãã¢ã¯ã»ã¹ããããã³ã«ãŠãŒã¶ãŒãããã€ã¹ãå³æ Œã«èªèšŒã»èªå¯ããä»çµã¿ãããŒããã©ã¹ããã®èãæ¹ã«åºã¥ããŠããŸãã | |
FWaaS (Firewall as a Service) |
ã¯ã©ãŠãäžã§æäŸããããã¡ã€ã¢ãŠã©ãŒã«æ©èœãå Žæãåãããäžè²«ãããã¡ã€ã¢ãŠã©ãŒã«ããªã·ãŒãé©çšã§ããŸãã |
ãããã®æ©èœãã¯ã©ãŠãäžã§çµ±åãããŠããããããŠãŒã¶ãŒã¯å Žæãããã€ã¹ã«é¢ããããåžžã«å®å šãªãããã¯ãŒã¯æ¥ç¶ãå©çšã§ããã®ã§ãã
SASEãå°å ¥ããã¡ãªãã âš
SASEãå°å ¥ããããšã§ãäŒæ¥ã¯æ§ã ãªã¡ãªãããåŸãããŸãã
- ã»ãã¥ãªãã£åŒ·å ðª: ã©ãããã®ã¢ã¯ã»ã¹ã§ãäžè²«ããã»ãã¥ãªãã£ããªã·ãŒãé©çšã§ãããŒããã©ã¹ãã®èãæ¹ã§ããå®å šã«ãªããŸãã
- éçšç®¡çã®ç°¡çŽ å ð§âð»: ãããã¯ãŒã¯ãšã»ãã¥ãªãã£ã®ç®¡çãã¯ã©ãŠãäžã§çµ±åããããããéçšãã·ã³ãã«ã«ãªãã管çè ã®è² æ ãæžããŸãã
- ã³ã¹ãåæž ð°: è€æ°ã®ã»ãã¥ãªãã£æ©åšããããã¯ãŒã¯æ©åšãåå¥ã«å°å ¥ã»éçšããããããã³ã¹ããæããããå¯èœæ§ããããŸãã
- ããã©ãŒãã³ã¹åäž â¡: ãŠãŒã¶ãŒã«æãè¿ãå ŽæïŒãšããžïŒã§åŠçãè¡ããããéä¿¡ã®é 延ãå°ãªããªããã¯ã©ãŠããµãŒãã¹ã®å©çšãªã©ãå¿«é©ã«ãªããŸãã
- æè»æ§ãšæ¡åŒµæ§ ð€ž: ããžãã¹ã®å€åããŠãŒã¶ãŒæ°ã®å¢æžã«åãããŠãæè»ã«æ§æãå€æŽããããã¹ã±ãŒã«ããããããããšã容æã§ãã
ãŸãšã
SASEã¯ãã¯ã©ãŠããšã¢ãã€ã«ãäžå¿ãšãªã£ãçŸä»£ã®åãæ¹ã«åãããŠç»å Žããããããã¯ãŒã¯ãšã»ãã¥ãªãã£ã®æ°ããã¢ãããŒãã§ãã
â ãããã¯ãŒã¯æ©èœãšã»ãã¥ãªãã£æ©èœãã¯ã©ãŠãã§çµ±åïŒ
â ã©ãããã§ãå®å šã»å¿«é©ã«ã¢ã¯ã»ã¹ïŒ
â ãŒããã©ã¹ãã«åºã¥ãã匷åãªã»ãã¥ãªãã£ïŒ
â éçšãã·ã³ãã«ã«ãªããã³ã¹ãåæžãæåŸ ã§ããïŒ
å°ãé£ããæãããããããŸãããããå Žæãåãããå®å šã§å¿«é©ãªãããã¯ãŒã¯æ¥ç¶ãå®çŸããããã®ãã¯ã©ãŠãæ代ã®æ°ããä»çµã¿ããšèŠããŠããã°å€§äžå€«ã§ãðãä»åŸãŸããŸãéèŠæ§ãé«ãŸã£ãŠããèãæ¹ãªã®ã§ããã²èŠããŠãããŠãã ãããïŒ
ã³ã¡ã³ã