{"id":5760,"date":"2021-08-21T21:17:01","date_gmt":"2021-08-21T12:17:01","guid":{"rendered":"https:\/\/www.xenos.jp\/~zen\/blog2\/?p=5760"},"modified":"2021-08-21T21:17:04","modified_gmt":"2021-08-21T12:17:04","slug":"post-5760","status":"publish","type":"post","link":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/2021\/08\/21\/post-5760\/","title":{"rendered":"Cisco ASA\u30b7\u30ea\u30fc\u30ba\u3067\u3001\u30a2\u30af\u30c6\u30a3\u30d6\u306aNAT\u4ef6\u6570\u3092\u8abf\u3079\u308b\u30b3\u30de\u30f3\u30c9"},"content":{"rendered":"\n<p>Cisco\u306eASA\u30b7\u30ea\u30fc\u30ba\u3067\u3001\u73fe\u5728\u306eNAT\u3057\u3066\u3044\u308b\u4ef6\u6570\u3092\u8abf\u3079\u308b\u305f\u3081\u306e\u30b3\u30de\u30f3\u30c9\u3002\u30b3\u30de\u30f3\u30c9\u306f\u3001Enable\u30e2\u30fc\u30c9\u3067\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>show xlate count<\/code><\/pre>\n\n\n\n<p>NAT\u3060\u3051\u3067\u306a\u304f\u3001\u30bb\u30c3\u30b7\u30e7\u30f3\u6570\uff08\u30b3\u30cd\u30af\u30b7\u30e7\u30f3\u6570\uff09\u3092\u8abf\u3079\u308b\u5834\u5408\u306f\u3001\u4e0b\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>show conn count<\/code><\/pre>\n\n\n\n<p>HTTP\/3\uff08QUIC\uff09\u304c\u4f7f\u308f\u308c\u59cb\u3081\u3066\u3001UDP\u306eNAT\u306e\u6570\u304c\u5897\u3048\u305f\u3002\u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u306b\u4f7f\u3063\u3066\u3044\u308b\u6a5f\u5668\u306e\u8ca0\u62c5\u3082\u304b\u306a\u308a\u5897\u3048\u3066\u3044\u308b\u3002HTTP\/3\u3063\u3066\u4fbf\u5229\u3068\u601d\u3063\u3066\u3044\u305f\u3051\u308c\u3069\u3001\u3053\u3093\u306a\u3068\u3053\u308d\u306b\u843d\u3068\u3057\u7a74\u304c\u3042\u3063\u305f\u3002<\/p>\n\n\n\n<p>UDP\u3060\u304b\u3089\u3001\u7d42\u4e86\u304c\u308f\u304b\u3089\u305a\u3001\u30bf\u30a4\u30e0\u30a2\u30a6\u30c8\u3059\u308b\u307e\u3067\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u4e0a\u3067\u306f\u3001NAT\u30c6\u30fc\u30d6\u30eb\u4e0a\u306b\u6b8b\u308a\u3064\u3065\u3051\u308b\u308f\u3051\u3067\u3001\u901a\u4fe1\u6570\u304c\u5897\u3048\u308c\u3070\u3001\u305d\u306e\u5206\u4f7f\u3044\u7d42\u308f\u3063\u305fNAT\u306e\u30bb\u30c3\u30b7\u30e7\u30f3\u304c\u30b4\u30df\u3063\u307d\u304f\u6b8b\u3063\u3066\u3001\u30ea\u30bd\u30fc\u30b9\u3092\u4f7f\u3044\u679c\u305f\u3059\u3068\u3002\u305d\u308c\u3092\u8abf\u3079\u308b\u306b\u306f\u3001\u30b3\u30de\u30f3\u30c9\u3092\u305f\u305f\u304f\u306e\u3060\u308d\u3046\u306a\u3002<\/p>\n\n\n\n<p>\u5b9f\u884c\u4f8b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ciscoasa# show conn count\n594 in use, 3455 most used\nciscoasa# \nciscoasa# show xlate count \n448 in use, 4416 most used<\/code><\/pre>\n\n\n\n<p>\u307e\u305f\u3001NAT\u30c6\u30fc\u30d6\u30eb\u306e\u4f7f\u7528\u6570\u306e\u30d4\u30fc\u30af\u3092\u77e5\u308a\u305f\u3044\u5834\u5408\u306b\u306f\u3001\u4e0b\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u3067\u30ea\u30bd\u30fc\u30b9\u3092\u8abf\u3079\u308b\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>show resource usage<\/code><\/pre>\n\n\n\n<p>\u3053\u306e\u30b3\u30de\u30f3\u30c9\u306e\u5b9f\u884c\u7d50\u679c\u306e\u300cXlates\u300d\u306e\u300cPeak\u300d\u304c\u904e\u53bb\u306e\u6700\u5927\u5024\u3060\u3002<\/p>\n\n\n\n<p>\u5b9f\u884c\u4f8b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ciscoasa# show resource usage \nResource                 Current        Peak      Limit        Denied Context \nTelnet                         1           1          5             0 System \nSSH Server                     0           1          5             0 System \nASDM                           0           1         30             0 System \nSyslogs &#91;rate]                17       13933        N\/A             0 System \nConns                        728        3455     100000             0 System \nXlates                       564        4416        N\/A             0 System \nHosts                        299         787        N\/A             0 System \nConns &#91;rate]                   8         536        N\/A             0 System \nInspects &#91;rate]                2         535        N\/A             0 System \nRoutes                        58          91  unlimited             0 System \nciscoasa#<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Cisco\u306eASA\u30b7\u30ea\u30fc\u30ba\u3067\u3001\u73fe\u5728\u306eNAT\u3057\u3066\u3044\u308b\u4ef6\u6570\u3092\u8abf\u3079\u308b\u305f\u3081\u306e\u30b3\u30de\u30f3\u30c9\u3002\u30b3\u30de\u30f3\u30c9\u306f\u3001Enable\u30e2\u30fc\u30c9\u3067\u3002 NAT\u3060\u3051\u3067\u306a\u304f\u3001\u30bb\u30c3\u30b7\u30e7\u30f3\u6570\uff08\u30b3\u30cd\u30af\u30b7\u30e7\u30f3\u6570\uff09\u3092\u8abf\u3079\u308b\u5834\u5408\u306f\u3001\u4e0b\u8a18\u306e\u30b3\u30de\u30f3\u30c9\u3002 HTTP\/3\uff08QUIC\uff09 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[56,240],"class_list":["post-5760","post","type-post","status-publish","format-standard","hentry","category-network","tag-cisco","tag-http-3"],"_links":{"self":[{"href":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/wp-json\/wp\/v2\/posts\/5760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/wp-json\/wp\/v2\/comments?post=5760"}],"version-history":[{"count":2,"href":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/wp-json\/wp\/v2\/posts\/5760\/revisions"}],"predecessor-version":[{"id":5789,"href":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/wp-json\/wp\/v2\/posts\/5760\/revisions\/5789"}],"wp:attachment":[{"href":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/wp-json\/wp\/v2\/media?parent=5760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/wp-json\/wp\/v2\/categories?post=5760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.xenos.jp\/~zen\/blog2\/index.php\/wp-json\/wp\/v2\/tags?post=5760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}