<p>ãã¬ããã°ã«ã¼ãã¢ã¯ã»ã¹ã使ãããã«ãªããã¤ã³ã¿ã¼ãããVPNã¯ä½¿ãå¿ è¦ããªããªãã¾ããããconfigãæ®ãã¦ããã¾ãã</p>
<p>ã»ã³ã¿ã¼æ ç¹ãä¸å¿ã¨ãããã¹ã¿ã¼åã¤ã³ã¿ã¼ãããVPNãæ§æã§ãã</p>
<h3>VPNæ§æ</h3>
<ul>
<li>ã»ã³ã¿ã¼æ ç¹0ï¼RTX1100→192.168.10.1ï¼ï¼192.168.10.0/24ãISP0</li>
<li>æ ç¹1ï¼RT57i→192.168.11.1ï¼ï¼192.168.11.0/24 ISP1</li>
<li>æ ç¹2ï¼RTV700→192.168.12.1ï¼ï¼192.168.11.0/24 ISP2</li>
</ul>
<p>ã»ã³ã¿ã¼æ ç¹ã¨æ ç¹1ã¯PPTPã«ããLAN鿥ç¶<br />
ã»ã³ã¿ã¼æ ç¹ã¨æ ç¹2ã¯IPsecã«ããLAN鿥ç¶</p>
<h3>VPNè¨å®</h3>
<h4>ã»ã³ã¿ã¼æ ç¹ï¼YAMAHAãRTX1100使ç¨ï¼</h4>
<h5>lan1ã¢ãã¬ã¹è¨å®</h5>
<ul>
<li>ip lan1 address 192.168.10.1/24<br />
RTX1100ã®lan1ã¢ãã¬ã¹ã192.168.10.1/24ã«è¨å®ãã</li>
</ul>
<h5>ã¤ã³ã¿ã¼ãããæ¥ç¶ç¨ã®pp1ãå®ç¾©</h5>
<ul>
<li>pp select 1</li>
<li>pppoe auto connect on<br />
èªåæ¥ç¶ãæå¹ã«ãã</li>
<li>pppoe auto disconnect off<br />
èªååæãç¡å¹ã«ãã</li>
<li>pppoe use lan2<br />
lan2ãpp1ã«ä½¿ç¨ãã</li>
<li>pp auth accept pap chap mschap mschap-v2<br />
→èªè¨¼æ¹å¼ã®é¸æï¼papã¯å¹³æãchapã¯æå·åï¼</li>
<li>pp auth myname (ISP0ã«æ¥ç¶ããID) (ãã¹ã¯ã¼ã)<br />
→ISP0ã«æ¥ç¶ããããã®IDã¨ãã¹ã¯ã¼ããæå®</li>
<li>pp always-on on<br />
→PPPoEå¸¸ææ¥ç¶ãæå¹ã«ãã</li>
<li>ppp lcp mru on 1454<br />
→mru(maximum receive unit)ã1454ãã¤ãã«æå®</li>
<li>ppp ipcp ipaddress on<br />
→ISPããèªåçã«åºå®ã°ãã¼ãã«ã¢ãã¬ã¹ãåå¾ãã</li>
<li>ip pp mtu 1454<br />
→mtu(maximum transfer unit)ã1454ãã¤ãã«æå®</li>
<li>ppp ipcp msext on</li>
<li>ppp ccp type none<br />
→å§ç¸®ã使ç¨ããªã</li>
<li>ip pp secure filter in 1020 1030 1040 1041 1052 1053 2000</li>
<li>ip pp secure filter out 1010 1011 1012 1013 1014 1015 1050 1051 3000 dynamic 100 101 102 103 104 105 106 107</li>
<li>ip pp nat descriptor 1</li>
<li>ip pp intrusion detection in on reject=on</li>
<li>pp enable 1<br />
→pp1ãæå¹ã«ãã</li>
<li>ip route default gateway pp 1</li>
</ul>
<h5>IPãã£ã«ã¿ã¼è¨å®ä¸è¦§</h5>
<ul>
<li>ip filter source-route on</li>
<li>ip filter directed-broadcast on</li>
</ul>
<p>Windowsã®RPCã¨ãNBTé¢é£ã®éä¿¡ã鮿ãããã£ã«ã¿ã¼</p>
<ul>
<li>ip filter 1010 reject * * udp,tcp 135 *</li>
<li>ip filter 1011 reject * * udp,tcp * 135</li>
<li>ip filter 1012 reject * * udp,tcp netbios_ns-netbios_ssn *</li>
<li>ip filter 1013 reject * * udp,tcp * netbios_ns-netbios_ssn</li>
<li>ip filter 1014 reject * * udp,tcp 445 *</li>
<li>ip filter 1015 reject * * udp,tcp * 445</li>
</ul>
<p>#LANå´ã®IPã¢ãã¬ã¹ãéä¿¡å ããããã¯å®å ã¨ãã¦è©ç§°ãã¦ããéä¿¡ã鮿ãããã£ã«ã¿ã¼</p>
<ul>
<li>ip filter 1020 reject 192.168.10.0/24 *</li>
<li>ip filter 1030 pass * 192.168.10.0/24 icmp<br />
#PPTPãéãããã«å¿ è¦ãªãã£ã«ã¿ã¼</li>
<li>ip filter 1040 pass * 192.168.10.1 tcp * 1723</li>
<li>ip filter 1041 pass * 192.168.10.1 gre<br />
#IPsecãéãããã«å¿ è¦ãªãã£ã«ã¿ã¼</li>
<li>ip filter 1050 pass ï¼ã»ã³ã¿ã¼æ ç¹ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ ï¼æ ç¹2ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ udp * 500</li>
<li>ip filter 1051 pass ï¼ã»ã³ã¿ã¼æ ç¹ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ ï¼æ ç¹2ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ esp * *</li>
<li>ip filter 1052 pass ï¼æ ç¹2ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ 192.168.10.1 udp * 500</li>
<li>ip filter 1053 pass ï¼æ ç¹2ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ 192.168.10.1 esp * *<br />
#ãã¹ã¦ã®éä¿¡ãæç¤ºçã«é®æ</li>
<li>ip filter 2000 reject * *<br />
#ãã£ã«ã¿ã¼ã§é®æããªãéä¿¡ãããã¹ã¦æç¤ºçã«ééããã</li>
<li>ip filter 3000 pass * *<br />
#åçãã£ã«ã¿ã¼ã®è¨å®ä¸è¦§</li>
<li>ip filter dynamic 100 * * ftp</li>
<li>ip filter dynamic 101 * * www</li>
<li>ip filter dynamic 102 * * domain</li>
<li>ip filter dynamic 103 * * smtp</li>
<li>ip filter dynamic 104 * * pop3</li>
<li>ip filter dynamic 105 * * netmeeting</li>
<li>ip filter dynamic 106 * * tcp</li>
<li>ip filter dynamic 107 * * udp</li>
</ul>
<h5>natã®è¨å®</h5>
<ul>
<li>nat descriptor type 1 masquerade</li>
<li>nat descriptor address inner 1 192.168.10.1-192.168.10.254</li>
<li>nat descriptor address outer 1 ipcp</li>
<li>nat descriptor masquerade static 1 1 192.168.10.1 tcp 1723</li>
<li>nat descriptor masquerade static 1 2 192.168.10.1 gre</li>
<li>nat descriptor masquerade static 1 3 192.168.10.1 udp 500</li>
<li>nat descriptor masquerade static 1 4 192.168.10.1 esp</li>
</ul>
<h5>æ ç¹1ï¼PPTPç¨ï¼ã®pp2ãå®ç¾©</h5>
<p>pp select 2<br />
pp bind tunnel1→tunnelï¼ã¨bindããã<br />
pp auth request mschap<br />
pp auth username kyoten1 kyoten1<br />
→PPTPæ¥ç¶ç¨ã®IDã¨ãã¹ã¯ã¼ããã¨ãã«kyoten1ã¨ãã<br />
ppp ccp type mppe-any<br />
pptp service type server→pptpãµã¼ãã¼ã«è¨å®ãã<br />
pptp tunnel disconnect time off<br />
pptp keepalive use on<br />
pp enable 2</p>
<h5>tunnnel1ï¼PPTPç¨ï¼ãå®ç¾©</h5>
<p>tunnel select 1<br />
tunnel encapsulation pptp→PPTPã使ç¨<br />
tunnel endpoint address ï¼æ ç¹1ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼<br />
tunnel enable 1→pp1ãæå¹ã«ãã<br />
ip route 192.168.11.0/24 gateway tunnel 1</p>
<h5>tunnel2ï¼IPsecç¨ï¼ãå®ç¾©</h5>
<p>tunnel select 2<br />
ipsec tunnel 2<br />
ipsec sa policy 1 1 esp 3des-cbc sha-hmac<br />
→æå·åespãæå®ã3DESãæå®<br />
ipsec ike local address 1 192.168.10.1<br />
→localå´ã®ãã©ã¤ãã¼ãã¢ãã¬ã¹ãæå®<br />
ipsec ike pre-shared-key 1 text ï¼äºåå ±æéµãã¹ã¯ã¼ãï¼<br />
→äºåå ±æéµãã¹ã¯ã¼ããæå®ãã<br />
ipsec ike remote address 1 ï¼æ ç¹2対åã«ã¼ã¿ã¼ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼<br />
→対åå´ã®ã°ãã¼ãã«ã¢ãã¬ã¹<br />
tunnel enable 2<br />
→tunnel2ãæå¹ã«ãã<br />
ip route 192.168.12.0/24 gateway tunnel 2<br />
ipsec auto refresh on</p>
<h5>DNSã®è¨å®</h5>
<p>dns server (ISP0ããæå®ãããDNSãµã¼ãã®ã¢ãã¬ã¹)<br />
dns private address spoof on</p>
<h5>DHCPã®è¨å®</h5>
<p>dhcp service server<br />
dhcp server rfc2131 compliant except remain-silent<br />
dhcp scope 1 192.168.10.2-192.168.10.100/24<br />
→192.168.10.2ï½192.168.10.100ã¾ã§ãDHCPã§èªåè¨å®</p>
<h4>æ ç¹1ï¼YAMAHAãRT57i使ç¨ï¼</h4>
<p>ip lan1 address 192.168.11.1/24</p>
<h5>pp1ã®è¨å®</h5>
<p>pp select 1<br />
pp always-on on<br />
pppoe use lan2<br />
pppoe auto connect off<br />
pppoe auto disconnect off<br />
pp auth accept pap chap mschap mschap-v2<br />
pp auth myname (ISP1ã¸æ¥ç¶ããID) (ISP1ã¸æ¥ç¶ãããã¹ã¯ã¼ã)<br />
ppp lcp mru on 1454<br />
ppp ipcp ipaddress on<br />
ppp ipcp msext on<br />
ppp ccp type none<br />
ip pp secure filter in 1020 1030 1040 1041 2000<br />
ip pp secure filter out 1010 1011 1012 1013 1014 1015 3000 dynamic 100 101 102<br />
103 104 105 106 107<br />
ip pp nat descriptor 1<br />
pp enable 1<br />
ip route default gateway pp 1</p>
<h5>pp2ã®è¨å®</h5>
<p>pp select 2<br />
pp bind tunnel1<br />
pp always-on on<br />
pp auth accept mschap-v2<br />
pp auth mynameãkyoten1 kyoten1<br />
ppp ipcp ipaddress on<br />
ppp ccp type mppe-any<br />
ppp ipv6cp use off<br />
pptp service type client<br />
pp enable 1</p>
<h5>tunnnelã®è¨å®</h5>
<p>tunnel select 1→tunnnel1ï¼PPTPç¨ï¼ãå®ç¾©<br />
tunnel encapsulation pptp→PPTPã使ç¨<br />
tunnel endpoint address ï¼ã»ã³ã¿ã¼æ ç¹ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼<br />
pptp tunnel disconnect time off<br />
tunnel enable 1→pp1ãæå¹ã«ãã<br />
ip route 192.168.10.0/24 gateway tunnel 1<br />
ip route 192.168.12.0/24 gateway tunnel 1</p>
<h5>IPãã£ã«ã¿ã¼ã®è¨å®</h5>
<p>ip filter source-route on<br />
ip filter directed-broadcast on<br />
#Windowsã®RPCã¨ãNBTé¢é£ã®éä¿¡ã鮿ãããã£ã«ã¿ã¼<br />
ip filter 1010 reject * * udp,tcp 135 *<br />
ip filter 1011 reject * * udp,tcp * 135<br />
ip filter 1012 reject * * udp,tcp netbios_ns-netbios_ssn *<br />
ip filter 1013 reject * * udp,tcp * netbios_ns-netbios_ssn<br />
ip filter 1014 reject * * udp,tcp 445 *<br />
ip filter 1015 reject * * udp,tcp * 445<br />
#LANå´ã®IPã¢ãã¬ã¹ãéä¿¡å ããããã¯å®å ã¨ãã¦è©ç§°ãã¦ããéä¿¡ã鮿ãããã£ã«ã¿ã¼<br />
ip filter 1020 reject 192.168.11.0/24 *<br />
ip filter 1030 pass * 192.168.11.0/24 icmp<br />
#PPTPãéãããã«å¿ è¦ãªãã£ã«ã¿ã¼<br />
ip filter 1040 pass * 192.168.11.1 tcp * 1723<br />
ip filter 1041 pass * 192.168.11.1 gre<br />
#ãã¹ã¦ã®éä¿¡ãæç¤ºçã«é®æ<br />
ip filter 2000 reject * *<br />
#ãã£ã«ã¿ã¼ã§é®æããªãéä¿¡ãããã¹ã¦æç¤ºçã«ééããã<br />
ip filter 3000 pass * *<br />
#åçãã£ã«ã¿ã¼ã®è¨å®ä¸è¦§<br />
ip filter dynamic 100 * * ftp<br />
ip filter dynamic 101 * * www<br />
ip filter dynamic 102 * * domain<br />
ip filter dynamic 103 * * smtp<br />
ip filter dynamic 104 * * pop3<br />
ip filter dynamic 105 * * netmeeting<br />
ip filter dynamic 106 * * tcp<br />
ip filter dynamic 107 * * udp</p>
<h5>natã®è¨å®</h5>
<p>nat descriptor type 1 masquerade<br />
nat descriptor address inner 1 192.168.11.1-192.168.11.254<br />
nat descriptor address outer 1 ipcp<br />
nat descriptor masquerade static 1 1 192.168.11.1 tcp 1723<br />
nat descriptor masquerade static 1 2 192.168.11.1 gre</p>
<h5>DNSã®è¨å®</h5>
<p>dns server (ISP1ããæå®ãããDNSãµã¼ãã®ã¢ãã¬ã¹)<br />
dns private address spoof on</p>
<h5>DHCPã®è¨å®</h5>
<p>dhcp service server<br />
dhcp server rfc2131 compliant except remain-silent<br />
dhcp scope 1 192.168.11.2-192.168.11.100/24<br />
→192.168.11.2ï½192.168.11.100ã¾ã§ãDHCPã§èªåè¨å®</p>
<h4>æ ç¹2ï¼YAMAHA RTV700使ç¨ï¼</h4>
<p>ip lan1 address 192.168.12.1/24</p>
<h5>pp1ã®è¨å®</h5>
<p>pp select 1<br />
pp always-on on<br />
pppoe use lan2<br />
pp auth accept pap chap<br />
pp auth myname (ISP2ã¸æ¥ç¶ããID) (ISP2ã¸æ¥ç¶ãããã¹ã¯ã¼ã)<br />
ppp lcp mru on 1454<br />
ppp ipcp ipaddress on<br />
ip pp secure filter in 1020 1030 1040 1052 1053 2000<br />
ip pp secure filter out 1010 1011 1012 1013 1014 1015 1050 1051 3000 dynamic 100 101 102<br />
103 104 105 106 107<br />
ip pp nat descriptor 1<br />
pp enable 1<br />
ip route default gateway pp 1</p>
<h5>tunnelã®è¨å®</h5>
<p>tunnel select 1<br />
ipsec tunnel 1<br />
ipsec sa policy 1 1 esp 3des-cbc sha-hmac<br />
ipsec ike keepalive use 1 on<br />
ipsec ike local 1 192.168.12.1<br />
ipsec ike pre-shared-key 1 text ï¼äºåå ±æéµãã¹ã¯ã¼ãï¼<br />
ipsec ike remote address 1 ï¼ã»ã³ã¿ã¼æ ç¹ã°ãã¼ãã«ã¢ãã¬ã¹ï¼<br />
tunnel enable 1<br />
ip route 192.168.10.0/24 gateway tunnel 1<br />
ip route 192.168.11.0/24 gateway tunnel 1<br />
ipsec auto refresh on</p>
<h5>IPãã£ã«ã¿ã¼ã®è¨å®</h5>
<p>ip filter source-route on<br />
ip filter directed-broadcast on<br />
#Windowsã®RPCã¨ãNBTé¢é£ã®éä¿¡ã鮿ãããã£ã«ã¿ã¼<br />
ip filter 1010 reject * * udp,tcp 135 *<br />
ip filter 1011 reject * * udp,tcp * 135<br />
ip filter 1012 reject * * udp,tcp netbios_ns-netbios_ssn *<br />
ip filter 1013 reject * * udp,tcp * netbios_ns-netbios_ssn<br />
ip filter 1014 reject * * udp,tcp 445 *<br />
ip filter 1015 reject * * udp,tcp * 445<br />
#LANå´ã®IPã¢ãã¬ã¹ãéä¿¡å ããããã¯å®å ã¨ãã¦è©ç§°ãã¦ããéä¿¡ã鮿ãããã£ã«ã¿ã¼<br />
ip filter 1020 reject 192.168.12.0/24 *<br />
ip filter 1030 pass * 192.168.12.0/24 icmp<br />
ip filter 1050 pass ï¼æ ç¹2ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ ï¼ã»ã³ã¿ã¼æ ç¹ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ udp * 500<br />
ip filter 1051 pass ï¼æ ç¹2ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ ï¼ã»ã³ã¿ã¼æ ç¹ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼esp * *<br />
ip filter 1052 pass ï¼ã»ã³ã¿ã¼æ ç¹ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ 192.168.12.1 udp * 500<br />
ip filter 1053 pass ï¼ã»ã³ã¿ã¼æ ç¹ã®ã°ãã¼ãã«ã¢ãã¬ã¹ï¼ 192.168.12.1 esp * *<br />
#ãã¹ã¦ã®éä¿¡ãæç¤ºçã«é®æ<br />
ip filter 2000 reject * *<br />
#ãã£ã«ã¿ã¼ã§é®æããªãéä¿¡ãããã¹ã¦æç¤ºçã«ééããã<br />
ip filter 3000 pass * *<br />
#åçãã£ã«ã¿ã¼ã®è¨å®ä¸è¦§<br />
ip filter dynamic 100 * * ftp<br />
ip filter dynamic 101 * * www<br />
ip filter dynamic 102 * * domain<br />
ip filter dynamic 103 * * smtp<br />
ip filter dynamic 104 * * pop3<br />
ip filter dynamic 105 * * netmeeting<br />
ip filter dynamic 106 * * tcp<br />
ip filter dynamic 107 * * udp</p>
<h5>natã®è¨å®</h5>
<p>nat descriptor type 1 masquerade<br />
nat descriptor address inner 1 192.168.12.1-192.168.12.254<br />
nat descriptor address outer 1 ipcp<br />
nat descriptor masquerade static 1 1 192.168.12.1 udp 500<br />
nat descriptor masquerade static 1 2 192.168.12.1 esp</p>
<h5>DNSã®è¨å®</h5>
<p>dns server (ISP2ããæå®ãããDNSãµã¼ãã®ã¢ãã¬ã¹)<br />
dns private address spoof on</p>
<h5>DHCPã®è¨å®</h5>
<p>dhcp service server<br />
dhcp server rfc2131 compliant except remain-silent<br />
dhcp scope 1 192.168.12.2-192.168.12.100/24<br />
→192.168.12.2ï½192.168.12.100ã¾ã§ãDHCPã§èªåè¨å®</p>

- 18年 ago
管理人
Categories:
VPN
インターネットVPN
Leave a Comment
Related Post
-
Chromeリモートデスクトップ
YAMAHAルーター「RTX1…
-
YAMAHAルーター「RTX1200」を使って「IPv6折り返し通信」L2TPv3の設定方法(ソフトイーサーOPEN DDNS利用)
拠点間を接続をする方法として、…