๐Ÿšง ํŠธ๋ž˜ํ”ฝ์„ ํ†ต์ œํ•˜๊ณ  ์ฃผ์†Œ๋ฅผ ๋ฐ”๊พธ๋‹ค: ACL ๋ณด์•ˆ ์ •์ฑ…๊ณผ NAT/PAT (Part 6-7)

ํ†ต์‹ ์ด ์ž˜ ๋˜๋Š” ๊ฒƒ๋งŒํผ ์ค‘์š”ํ•œ ๊ฒŒ “ํ•ด์„œ๋Š” ์•ˆ ๋˜๋Š” ํ†ต์‹ ์„ ๋ง‰๋Š” ๊ฒƒ”์ž…๋‹ˆ๋‹ค. ์žฌ๋ฌดํŒ€ ์„œ๋ฒ„์— ๊ฐœ๋ฐœํŒ€์ด ์•„๋ฌด ์ œํ•œ ์—†์ด ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋‹ค๋ฉด ๋ณด์•ˆ์€ ์—†๋Š” ๊ฒƒ๊ณผ ๋งˆ์ฐฌ๊ฐ€์ง€์ž…๋‹ˆ๋‹ค. Part 6์—์„œ๋Š” ACL๋กœ ํŠธ๋ž˜ํ”ฝ์„ ์ •๋ฐ€ํ•˜๊ฒŒ ์ œ์–ดํ•˜๊ณ , Part 7์—์„œ๋Š” NAT/PAT๋กœ ๋‚ด๋ถ€ IP๋ฅผ ์™ธ๋ถ€์—์„œ ๋ณด์ด์ง€ ์•Š๊ฒŒ ๊ฐ์ถ”๋ฉด์„œ ๊ณต์ธ IP๋ฅผ ์ ˆ์•ฝํ•ฉ๋‹ˆ๋‹ค.


Part 6: ACL โ€” ๋„คํŠธ์›Œํฌ์˜ ๊ฒฝ๋น„์›

ACL์ด๋ž€?

ACL(Access Control List)์€ ๋ผ์šฐํ„ฐ์˜ ์ธํ„ฐํŽ˜์ด์Šค์—์„œ ํŒจํ‚ท์„ ํ•„ํ„ฐ๋งํ•˜๋Š” ๊ทœ์น™ ๋ชฉ๋ก์ž…๋‹ˆ๋‹ค. ํ†ต๊ณผ์‹œํ‚ฌ์ง€(permit) ์ฐจ๋‹จํ• ์ง€(deny)๋ฅผ ์กฐ๊ฑด์— ๋”ฐ๋ผ ๊ฒฐ์ •ํ•ฉ๋‹ˆ๋‹ค.

ACL์˜ 3๊ฐ€์ง€ ํ•ต์‹ฌ ๊ทœ์น™

  1. ์ˆœ์„œ๋Œ€๋กœ ๊ฒ€์‚ฌ: ์œ„์—์„œ ์•„๋ž˜๋กœ ์ˆœ์ฐจ์ ์œผ๋กœ ๋น„๊ต, ์ผ์น˜ํ•˜๋ฉด ์ฆ‰์‹œ ํ•ด๋‹น ๋™์ž‘ ์ˆ˜ํ–‰
  2. ์•”๋ฌต์  Deny: ACL ๋งจ ๋์— ๋ณด์ด์ง€ ์•Š๋Š” deny ip any any๊ฐ€ ํ•ญ์ƒ ์กด์žฌ
  3. ๋ฐฉํ–ฅ ์ง€์ • ํ•„์ˆ˜: Inbound(๋“ค์–ด์˜ค๋Š” ๋ฐฉํ–ฅ) ๋˜๋Š” Outbound(๋‚˜๊ฐ€๋Š” ๋ฐฉํ–ฅ) ์ค‘ ํ•˜๋‚˜

Standard vs Extended ACL

๊ตฌ๋ถ„Standard ACLExtended ACL
๊ฒ€์‚ฌ ํ•ญ๋ชฉ์ถœ๋ฐœ์ง€ IP๋งŒ์ถœ๋ฐœ์ง€ IP, ๋ชฉ์ ์ง€ IP, ํ”„๋กœํ† ์ฝœ, ํฌํŠธ ๋ฒˆํ˜ธ
๋ฒˆํ˜ธ ๋ฒ”์œ„1-99, 1300-1999100-199, 2000-2699
์ ์šฉ ์œ„์น˜๋ชฉ์ ์ง€ ๊ทผ์ฒ˜์ถœ๋ฐœ์ง€ ๊ทผ์ฒ˜

์ด๋ฒˆ ์‹ค์Šต์˜ ACL ์‹œ๋‚˜๋ฆฌ์˜ค

์š”๊ตฌ์‚ฌํ•ญACL ์œ ํ˜•์ ์šฉ ์žฅ๋น„์ธํ„ฐํŽ˜์ด์Šค๋ฐฉํ–ฅ
๊ฐœ๋ฐœํŒ€ โ†’ Server: HTTP/HTTPS๋งŒ ํ—ˆ์šฉExtendedCORE-RTR1Gi0/1.10In
์ธ์‚ฌํŒ€ โ†’ Server: ์™„์ „ ์ฐจ๋‹จExtendedCORE-RTR1Gi0/1.20In
์™ธ๋ถ€ โ†’ ๋‚ด๋ถ€: ์ฐจ๋‹จExtendedEDGE-RTRSe0/0/0In

CORE-RTR1 ACL ์„ค์ •

configure terminal

! ๊ฐœ๋ฐœํŒ€ ์ •์ฑ…: Server์— HTTP/HTTPS๋งŒ ํ—ˆ์šฉ, ๋‚˜๋จธ์ง€๋Š” ๋ถ€์„œ ๊ฐ„ ํ—ˆ์šฉ
ip access-list extended DEV_TO_SERVER
 permit tcp 10.10.10.0 0.0.0.255 host 10.10.30.100 eq 80   ! HTTP
 permit tcp 10.10.10.0 0.0.0.255 host 10.10.30.100 eq 443  ! HTTPS
 permit icmp 10.10.10.0 0.0.0.255 10.10.20.0 0.0.0.255     ! ping ํ—ˆ์šฉ
 permit icmp 10.10.10.0 0.0.0.255 10.10.30.0 0.0.0.255
 permit ip 10.10.10.0 0.0.0.255 any                        ! ๋‚˜๋จธ์ง€๋Š” ํ—ˆ์šฉ
 deny ip any any log                                        ! ๋‚˜๋จธ์ง€ ์ฐจ๋‹จ + ๋กœ๊ทธ

! ์ธ์‚ฌํŒ€ ์ •์ฑ…: Server ์ ‘๊ทผ ์™„์ „ ์ฐจ๋‹จ
ip access-list extended HR_RESTRICT
 deny ip 10.10.20.0 0.0.0.255 host 10.10.30.100 log        ! Server ์ฐจ๋‹จ
 permit icmp 10.10.20.0 0.0.0.255 10.10.10.0 0.0.0.255     ! ๊ฐœ๋ฐœํŒ€ ping์€ ํ—ˆ์šฉ
 permit ip any any                                          ! ๋‚˜๋จธ์ง€๋Š” ํ—ˆ์šฉ

! ACL ์ธํ„ฐํŽ˜์ด์Šค์— ์ ์šฉ
interface GigabitEthernet0/1.10
 ip access-group DEV_TO_SERVER in
interface GigabitEthernet0/1.20
 ip access-group HR_RESTRICT in

EDGE-RTR ์™ธ๋ถ€ ํŠธ๋ž˜ํ”ฝ ์ฐจ๋‹จ ACL

ip access-list extended OUTSIDE_IN
 permit icmp any any echo-reply           ! ping ์‘๋‹ต์€ ํ—ˆ์šฉ (๋‚ด๊ฐ€ ๋ณด๋‚ธ ping ํšŒ์‹ )
 permit tcp any any established           ! ๊ธฐ์กด ์„ธ์…˜ ์‘๋‹ต ํŒจํ‚ท ํ—ˆ์šฉ
 deny ip any 10.0.0.0 0.255.255.255 log  ! ๋‚ด๋ถ€ IP ์ง์ ‘ ์ ‘๊ทผ ์ฐจ๋‹จ
 permit ip any any                        ! ๋‚˜๋จธ์ง€ ํ—ˆ์šฉ

interface Serial0/0/0
 ip access-group OUTSIDE_IN in

established ํ‚ค์›Œ๋“œ๋Š” ๋‚ด๋ถ€์—์„œ ๋จผ์ € ์‹œ์ž‘ํ•œ ์—ฐ๊ฒฐ์˜ ์‘๋‹ต ํŒจํ‚ท๋งŒ ํ—ˆ์šฉํ•˜๋Š” ๊ฐ•๋ ฅํ•œ ํ•„ํ„ฐ์ž…๋‹ˆ๋‹ค. ์™ธ๋ถ€์—์„œ ๋จผ์ € ์—ฐ๊ฒฐ์„ ์‹œ์ž‘ํ•˜๋Š” ํŒจํ‚ท์€ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค.


Part 7: NAT/PAT โ€” ๊ณต์ธ IP ํ•˜๋‚˜๋กœ ์—ฌ๋Ÿฌ ๋ช…์ด ์ธํ„ฐ๋„ท์„

NAT์ด ํ•„์š”ํ•œ ์ด์œ 

๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ๋Š” 10.x.x.x์ฒ˜๋Ÿผ ์‚ฌ์„ค IP๋ฅผ ์”๋‹ˆ๋‹ค. ์‚ฌ์„ค IP๋Š” ์ธํ„ฐ๋„ท์—์„œ ๋ผ์šฐํŒ…๋˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์—, ์™ธ๋ถ€๋กœ ๋‚˜๊ฐˆ ๋•Œ๋Š” **๊ณต์ธ IP๋กœ ๋ณ€ํ™˜(NAT)**ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

Inside/Outside, Local/Global ๊ฐœ๋…

          NAT ๊ฒฝ๊ณ„
               โ”‚
Inside         โ”‚          Outside
(๋‚ด๋ถ€ ์‚ฌ์„ค)    โ”‚       (์™ธ๋ถ€ ๊ณต์ธ)
               โ”‚
[PC1]          โ”‚         [ISP-RTR]
10.10.10.10 โ”€โ”€โ–ถ [EDGE-RTR] โ”€โ”€โ–ถ 1.1.1.1
Inside Local   โ”‚ 1.1.1.2
               โ”‚ Inside Global
์šฉ์–ด์„ค๋ช…์˜ˆ์‹œ
Inside Local๋‚ด๋ถ€์˜ ์‹ค์ œ ์‚ฌ์„ค IP10.10.10.10
Inside Global์™ธ๋ถ€์—์„œ ๋ณด์ด๋Š” ๊ณต์ธ IP1.1.1.2
Outside Local๋‚ด๋ถ€์—์„œ ๋ณด๋Š” ์™ธ๋ถ€ IP1.1.1.1
Outside Global์™ธ๋ถ€์˜ ์‹ค์ œ IP1.1.1.1

NAT ์œ ํ˜• ๋น„๊ต

์œ ํ˜•๋ฐฉ์‹์‚ฌ์šฉ ์‚ฌ๋ก€
Static NAT1:1 ๊ณ ์ • ๋งคํ•‘์„œ๋ฒ„๋ฅผ ์™ธ๋ถ€์— ๊ณต๊ฐœ
Dynamic NATPool์—์„œ ๋™์  ํ• ๋‹น๊ฑฐ์˜ ์‚ฌ์šฉ ์•ˆ ํ•จ
PAT (Overload)ํฌํŠธ ๋ฒˆํ˜ธ๋กœ ๋‹ค์ˆ˜ ๊ตฌ๋ถ„๊ณต์œ ๊ธฐ, ๊ธฐ์—… ์ธํ„ฐ๋„ท

EDGE-RTR NAT/PAT ์„ค์ •

! Inside/Outside ์ธํ„ฐํŽ˜์ด์Šค ์ง€์ •
interface GigabitEthernet0/0
 ip nat inside      ! ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ ๋ฐฉํ–ฅ

interface GigabitEthernet0/1
 ip nat inside

interface Serial0/0/0
 ip nat outside     ! ISP ๋ฐฉํ–ฅ

! PAT ๋Œ€์ƒ ์ •์˜ (Standard ACL)
access-list 10 permit 10.10.10.0 0.0.0.255
access-list 10 permit 10.10.20.0 0.0.0.255
access-list 10 permit 10.10.30.0 0.0.0.255
access-list 10 permit 10.0.0.0 0.0.0.255

! PAT ์„ค์ •: ACL 10์— ํ•ด๋‹นํ•˜๋Š” ํŒจํ‚ท์„ Serial ์ธํ„ฐํŽ˜์ด์Šค IP๋กœ ๋ณ€ํ™˜
ip nat inside source list 10 interface Serial0/0/0 overload

! Static NAT: Server1์„ ์™ธ๋ถ€์—์„œ ์ง์ ‘ ์ ‘๊ทผ ๊ฐ€๋Šฅํ•˜๋„๋ก 1:1 ๊ณต๊ฐœ
ip nat inside source static 10.10.30.100 1.1.1.100

**overload**๊ฐ€ PAT์˜ ํ•ต์‹ฌ์ž…๋‹ˆ๋‹ค. ํ•˜๋‚˜์˜ ๊ณต์ธ IP(1.1.1.2)์— ํฌํŠธ ๋ฒˆํ˜ธ๋ฅผ ๋ถ™์—ฌ ์—ฌ๋Ÿฌ ๋‚ด๋ถ€ ํ˜ธ์ŠคํŠธ๋ฅผ ๊ตฌ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด PC1์˜ ์—ฐ๊ฒฐ์€ 1.1.1.2:10001, PC2์˜ ์—ฐ๊ฒฐ์€ 1.1.1.2:10002์ฒ˜๋Ÿผ ํฌํŠธ๋ฅผ ๋‹ฌ๋ฆฌํ•ด์„œ ๊ฐ๊ฐ์„ ์ถ”์ ํ•ฉ๋‹ˆ๋‹ค.

Static NAT์œผ๋กœ๋Š” Server1(10.10.30.100)์„ ์™ธ๋ถ€ IP(1.1.1.100)์— 1:1 ๊ณ ์ • ๋งคํ•‘ํ–ˆ์Šต๋‹ˆ๋‹ค. ISP์—์„œ 1.1.1.100์œผ๋กœ ์š”์ฒญํ•˜๋ฉด ์ž๋™์œผ๋กœ Server1์œผ๋กœ ์ „๋‹ฌ๋ฉ๋‹ˆ๋‹ค.

ISP-RTR์—๋„ Static NAT ์ฃผ์†Œ๋กœ ๊ฐ€๋Š” ๊ฒฝ๋กœ๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

ip route 1.1.1.100 255.255.255.255 1.1.1.2

NAT ๋™์ž‘ ๊ฒ€์ฆ

! NAT ๋ณ€ํ™˜ ํ…Œ์ด๋ธ” ํ™•์ธ
EDGE-RTR# show ip nat translations

๊ฒฐ๊ณผ:
Pro  Inside global    Inside local      Outside local   Outside global
tcp  1.1.1.2:10001   10.10.10.10:1025  8.8.8.8:80     8.8.8.8:80
icmp 1.1.1.100       10.10.30.100      ---            ---  โ† Static NAT

๐Ÿ’ก ์ด Part์˜ ํ•ต์‹ฌ ๊ตํ›ˆ

ACL๊ณผ NAT๋Š” ๋„คํŠธ์›Œํฌ์˜ “๊ฒฝ๋น„์›” ๊ณผ **”๋ฒˆ์—ญ๊ฐ€”**์ž…๋‹ˆ๋‹ค.

ACL์€ “๋ˆ„๊ฐ€ ์–ด๋””์— ์–ด๋–ค ๋ฐฉ๋ฒ•์œผ๋กœ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋Š”์ง€”๋ฅผ ์ •๋ฐ€ํ•˜๊ฒŒ ์ œ์–ดํ•ฉ๋‹ˆ๋‹ค. ํŠนํžˆ ACL์˜ ์ˆœ์„œ์™€ ์•”๋ฌต์  Deny๋ฅผ ์ดํ•ดํ•˜์ง€ ๋ชปํ•˜๋ฉด ์˜๋„์น˜ ์•Š๊ฒŒ ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ์„ ์ฐจ๋‹จํ•˜๊ฑฐ๋‚˜ ํ—ˆ์šฉํ•˜๋Š” ์‹ค์ˆ˜๋ฅผ ๋ฒ”ํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค. ์ง์ ‘ ์„ค์ •ํ•˜๋ฉด์„œ “์ข์€ ๋ฒ”์œ„๋ฅผ ๋จผ์ €, ๋„“์€ ๋ฒ”์œ„๋ฅผ ๋‚˜์ค‘์—”๋ผ๋Š” ์›์น™์„ ๋ชธ์œผ๋กœ ์ตํ˜”์Šต๋‹ˆ๋‹ค.

NAT/PAT๋Š” IPv4 ์ฃผ์†Œ ๊ณ ๊ฐˆ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๋Š” ํ˜„์‹ค์ ์ธ ๊ธฐ์ˆ ์ž…๋‹ˆ๋‹ค. ๊ณต์œ ๊ธฐ ํ•˜๋‚˜๋กœ ์ง‘์˜ ๋ชจ๋“  ๊ธฐ๊ธฐ๊ฐ€ ์ธํ„ฐ๋„ท์— ์ ‘์†ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ๋„ ๋ฐ”๋กœ PAT ๋•๋ถ„์ž…๋‹ˆ๋‹ค.