<p>PPTPã«ãããªã¢ã¼ãã¢ã¯ã»ã¹è¨å®ãç´¹ä»ãã¾ããããå®å ¨æ§ãèæ ®ããå ´åPPTPã«ããå¸¸ææ¥ç¶ã¯åé¡ãããã¾ããç¡ç·LANã®WEPã®ããã«ç°¡åã«ç ´ãããããã§ã¯ãªãã®ã§ã䏿çãªãªã¢ã¼ãã¢ã¯ã»ã¹ãªãåé¡ããã¾ããã</p>
<p>PPTPã«ãããªã¢ã¼ãã¢ã¯ã»ã¹ã使ããããªãå ´åãIPsecã«ãããªã¢ã¼ãã¢ã¯ã»ã¹ã使ããã¨ã«ãªãã¾ãã</p>
<p>Windowsã«ã¯IPsecã«ãããªã¢ã¼ãã¢ã¯ã»ã¹ãè£ åãã¦ã¾ããããã¢ã°ã¬ãã·ãã¢ã¼ããã«å¯¾å¿ãã¦ããªãã®ã§ãã¡ã¤ã³ã¢ã¼ããã使ãäºã«ãªãã¾ããã¡ã¤ã³ã¢ã¼ãã ã¨ã¤ãã·ã¨ã¼ã¿ã¼å´ï¼çºä¿¡å´ï¼ã«ãåºå®ã¢ãã¬ã¹ãå¿ è¦ã¨ãªãããªã¢ã¼ãã¢ã¯ã»ã¹ã ã¨ä½¿ãã«ããã</p>
<p>YAMAHAã§ã¯IPsecã«ãããªã¢ã¼ãã¢ã¯ã»ã¹ãå®ç¾ããããã«ãYMS-VPN1ããæä¾ãã¦ãã¾ããã¢ã°ã¬ãã·ãã¢ã¼ãã«ã対å¿ã</p>
<p>ä»åã¯YMS-VPN1ã使ã£ãIPsecã«ãããªã¢ã¼ãã¢ã¯ã»ã¹è¨å®ãç´¹ä»ãã¾ãã</p>
<p> ;</p>
<h3>YMS-VPN1ã®è¨å®æ¹æ³</h3>
<p>RTX1100å´ã®LANã¢ãã¬ã¹ã<span style="color: #ff0000;">192.168.100.1/24</span>ã¨ãã¾ãã<br />
ãªã¢ã¼ãã¢ã¯ã»ã¹å´ã®<span style="color: #ff0000;">YMS-VPN1ã®ä»®æ³å é¨ã¢ãã¬ã¹ã192.168.110.1/24</span>ã¨ãã¾ãã</p>
<h4>RTX1100å´</h4>
<pre class="lang:default decode:true ">ip route default gateway pp 1 
ip route 192.168.110.0/24 gateway tunnel 1 
→ipsecã«ãããªã¢ã¼ãã¢ã¯ã»ã¹ã®å ´åã¯éççµè·¯æ å ±ãå¿ è¦ 
ip filter source-route on 
ip filter directed-broadcast on 
ip lan1 address 192.168.100.1/24 
ã¤ã³ã¿ã¼ãããæ¥ç¶ç¨ppè¨å® 
pp select 1 
pp always-on on 
pppoe use lan2 
pp auth accept pap chap mschap mschap-v2 
pp auth myname (ISPã®ID)ãï¼ISPæ¥ç¶ãã¹ã¯ã¼ãï¼ 
ppp lcp mru on 1454 
ppp ipcp ipaddress on 
ip pp mtu 1454 
ip pp secure filter in 1000 1001 1002 1003 1004 1020 1021 1022 1023 1024 1025 1041 1042 4000 2000 
ip pp secure filter out 1010 1011 1012 1013 1014 1020 1021 1022 1023 1024 1025 3000 dynamic 1080 1081 1082 1083 1084 105 1098 1099 
ip pp intrusion detection in on reject=on 
ip pp intrusion detection out on reject=on 
ip pp nat descriptor 1 
pp enable 1 
★以ä¸ãã£ã«ã¿ã¼è¨å® 
 
ip filter 1010 reject * * udp,tcp 135 * 
ip filter 1011 reject * * udp,tcp * 135 
ip filter 1012 reject * * udp,tcp netbios_ns-netbios_ssn * 
ip filter 1013 reject * * udp,tcp * netbios_ns-netbios_ssn 
ip filter 1014 reject * * udp,tcp 445 * 
ip filter 1015 reject * * udp,tcp * 445 
ip filter 1020 reject 192.168.100.0/24 * 
ip filter 1030 pass * 192.168.100.0/24 icmp 
ip filter 1041 pass * 192.168.100.1 udp * 500 
ip filter 1042 pass * 192.168.100.1 esp 
→ipsecã®éä¿¡ãã»ã³ã¿ã¼å´ãã©ã¤ãã¼ãã¢ãã¬ã¹ã«ééããã 
ip filter 2000 reject * * 
ip filter 3000 pass * * 
ip filter 4000 pass * 192.168.100.0/24 icmp * * 
ip filter dynamic 1080 * * ftp 
ip filter dynamic 1081 * * www 
ip filter dynamic 1082 * * domain 
ip filter dynamic 1083 * * smtp 
ip filter dynamic 1084 * * pop3 
ip filter dynamic 1098 * * tcp 
ip filter dynamic 1099 * * udp 
★以ä¸natã®è¨å® 
 
nat descriptor type 1 masquerade 
nat descriptor address inner 1 192.168.100.1-192.168.100.254 
nat descriptor address outer 1 ipcp 
nat descriptor masquerade static 1 1 192.168.100.1 udp 500 
nat descriptor masquerade static 1 2 192.168.100.1 esp 
→IPsecã§å©ç¨ããudp500ã¨espãNATãã¾ãã 
tunnelè¨å® 
tunnel select 1 
ipsec tunnel 1 
ipsec sa policy 1 1 esp aes-cbc sha-hmac 
ipsec ike pre-shared-key 1 text ï¼äºåå ±æéµï¼ 
→äºåå ±æéµãä»®ã«ABCD1234ã¨ãã 
ipsec ike remote address 1 any 
→æ¥ç¶ãããªã¢ã¼ãå´ãå¶éããªããanonymousæå® 
ipsec ike remote name 1 ï¼æ¥ç¶åï¼ 
→æ¥ç¶åãä»®ã«IPsec-VPNã¨ãã 
ipsec ike local address 1 192.168.100.1 
→ã»ã³ã¿ã¼å´ã«ã¼ã¿ã¼ã®ãã©ã¤ãã¼ãã¢ãã¬ã¹ãæå®ãã 
tunnel enable 1</pre>
<p> ;</p>
<h4>ã¤ããVPNã¯ã©ã¤ã¢ã³ã YMS-VPN1ã®è¨å®</h4>
<p>ã¤ããã®HPããYMS-VPN1ããã¦ã³ãã¼ããã¦ã¤ã³ã¹ãã¼ã«ãã¾ãã<br />
<a href="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0db3cff5.jpg" target="_blank"><img src="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0db3cff5.jpg" alt="" width="440" border="0" /></a><br clear="all" /><a href="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0dc4b4cd.jpg" target="_blank"><img src="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0dc4b4cd.jpg" alt="" width="440" border="0" /></a><br clear="all" /><a href="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0dd5c59f.jpg" target="_blank"><img src="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0dd5c59f.jpg" alt="" width="440" border="0" /></a><br clear="all" /><a href="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0de9894a.jpg" target="_blank"><img src="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0de9894a.jpg" alt="" width="440" border="0" /></a><br clear="all" /><a href="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0dfcb665.jpg" target="_blank"><img src="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0dfcb665.jpg" alt="" width="440" border="0" /></a><br clear="all" /><a href="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0e0d1835.jpg" target="_blank"><img src="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0e0d1835.jpg" alt="" width="440" border="0" /></a><br clear="all" /><a href="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0e2453b8.jpg" target="_blank"><img src="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0e2453b8.jpg" alt="" width="440" border="0" /></a><br clear="all" /><a href="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0e3be43a.jpg" target="_blank"><img src="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0e3be43a.jpg" alt="" width="440" border="0" /></a><br clear="all" />äºåå ±æéµã¯RTX1100ã§ä»®ã«è¨å®ããABCD1234ãå ¥åããæ¥ç¶å ã²ã¼ãã¦ã§ã¤ã¯RTX1100ã®ã°ãã¼ãã«ã¢ãã¬ã¹ãå ¥åããã<br />
<a href="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0e4ab702.jpg" target="_blank"><img src="https://bacque.biz/wp-content/uploads/imgs/blog_import_525bb0e4ab702.jpg" alt="" width="440" border="0" /></a></p>