> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/penetosuto/prepare-a-pentest/ip-addresses-for-pentest.md).

# ペネトスト用 IP アドレス

Aikidoは、専用のIPアドレスとリクエストヘッダーを使用して、あなたの環境に対してペンテストを実施します。接続の問題、レート制限、セキュリティブロックを防ぐため、これらのIPアドレスとヘッダーをファイアウォールの許可リスト、またはその他のセキュリティソフトウェアに追加してください。

## どのIPアドレスを許可リストに追加すべきですか？

ペンテストのトラフィックは、 **あなたのAikidoワークスペースが** ホストされているリージョンから発生し、アプリケーションが実行されているリージョンからではありません。Aikidoにログインする際に使用するURLを確認し、そのリージョンのIPアドレスを許可リストに追加してください:

| AikidoのURL                                     | リージョン | IPアドレス一覧     |
| ---------------------------------------------- | ----- | ------------ |
| [app.aikido.dev](https://app.aikido.dev)       | EU    | EUベースのIPアドレス |
| [app.us.aikido.dev](https://app.us.aikido.dev) | US    | USベースのIPアドレス |
| [app.au.aikido.dev](https://app.au.aikido.dev) | AU    | AUベースのIPアドレス |
| [app.me.aikido.dev](https://app.me.aikido.dev) | ME    | 近日公開         |

{% hint style="warning" %}
次でログインする場合 `app.aikido.dev`、接続チェックとペンテスト自体では **EU** IPアドレスが使用されます。エンドポイントが米国でホストされている場合でも同様です。その場合、USのIPアドレスのみを許可リストに入れると、ペンテストは失敗します。
{% endhint %}

## IPアドレス

### EUベースのIPアドレス（`app.aikido.dev`)

* 34.252.102.184
* 52.48.122.82
* 52.49.182.62
* 52.209.168.11
* 52.210.210.125
* 54.76.103.212
* 54.194.175.200
* 54.217.255.121

### USベースのIPアドレス（`app.us.aikido.dev`)

* 3.226.27.188
* 34.237.95.50
* 44.209.154.183
* 52.204.120.162
* 54.80.175.207
* 54.227.161.94
* 98.88.145.68
* 98.91.68.215

### AUベースのIPアドレス（`app.au.aikido.dev`)

* 13.237.12.233
* 13.55.70.235
* 15.134.62.222
* 15.135.1.99
* 3.105.20.219
* 3.24.155.132
* 52.64.105.187
* 54.253.33.136

### 任意のIPアドレス

サポートとのトラブルシューティングに使用します。

* 79.127.239.171

## リクエストヘッダー

Aikidoのペンテストからのすべてのリクエストには、次のいずれかの値が `User-Agent` ヘッダーに含まれます。これらは、SIEMやWAFのリクエストログでペンテストのリクエストを識別するために使用できます。

* `aikido-pentest-agent`
* `aikido-pentest-agent/1.0（エージェント <AGENT_UUID>）`

サードパーティプロバイダーで IP アドレスを許可リストに登録する方法については、以下のリソースを参照してください:

* [Cloudflare WAF](https://developers.cloudflare.com/waf/custom-rules/use-cases/allow-traffic-from-ips-in-allowlist/)
  * Cloudflare Turnstile は、特定のクライアント IP アドレスの許可リスト登録をサポートしていません。もし [Aikido のスキャン ट्रラフィックで Turnstile をバイパスする必要がある場合は、アプリケーションコード内で行う必要があります。](https://developers.cloudflare.com/turnstile/tutorials/conditionally-enforcing-turnstile/) 次の両方の条件が真のときのみバイパスすることを推奨します:
    1. リクエストの送信元が Aikido の IP 範囲である
    2. リクエストに `aikido` 上記のようにヘッダー内の User Agent が含まれている
* [Azure WAF](https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/custom-waf-rules-overview)
* [AWS WAF](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-type-ipset-match.html).
  * Application Load Balancer や CloudFront の背後にある WAF では、 [WAF は、末尾の IP アドレスを確認する必要があります。 `X-Forwarded-For` ヘッダー](https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-forwarded-ip-address.html).
* [Vercel WAF](https://vercel.com/docs/vercel-firewall/vercel-waf/custom-rules)
  * 使用する [「bypass」アクション](https://vercel.com/docs/vercel-firewall/firewall-concepts#bypass) 信頼済み IP 向けの

{% hint style="info" %}
[IP アドレスのリストは JSON 配列としても利用できます](https://aikido.help/ips/)
{% endhint %}

## 内部アプリケーションのテスト

アプリケーションが、外部インターネットからの着信トラフィックを受け付けられない完全にプライベートなネットワーク、VPN、またはイントラネット上でホストされている場合は、 [社内アプリケーション向け Aikido Broker](/docs/docs-ja/miscellaneous-info/aikido-broker-for-internal-applications.md)

{% hint style="info" %}
Brokerを利用するには、インフラストラクチャにエージェントをインストールする必要があります。標準的なIPの許可リスト化ができない場合にのみ推奨します。
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/penetosuto/prepare-a-pentest/ip-addresses-for-pentest.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
