X

YAMAHAルーター「RTX1210」でポートVLANの設定方法

<p>RTX1210のLAN1ポートは8個あり、通常は同一セグメントのスイッチングハブ(ギガビット)として機能しますが、「ポートVLAN機能」を使えばポートごとに仮想的に異なるセグメントにすることが可能になっています。例えば会社の部門ごとに異なるセグメントにしたい場合、LAN1を8個の仮想LANとして個別のIPアドレスを設定し、部門間の通信を遮断したり、ゲスト用のアクセスポイントを設定してセキュリティを高めることなどに利用されます。今回は8ポートすべてを異なるVLANで設定してみましょう。<&sol;p>&NewLine;<div class&equals;"kaerebalink-box" style&equals;"text-align&colon; left&semi; padding-bottom&colon; 20px&semi; font-size&colon; small&semi; &sol;zoom&colon; 1&semi; overflow&colon; hidden&semi;">&NewLine;<div class&equals;"kaerebalink-image" style&equals;"float&colon; left&semi; margin&colon; 0 15px 10px 0&semi;"><a href&equals;"https&colon;&sol;&sol;www&period;amazon&period;co&period;jp&sol;exec&sol;obidos&sol;ASIN&sol;B00NF2GN6U&sol;bacque-22&sol;" target&equals;"&lowbar;blank" rel&equals;"nofollow noopener"><img style&equals;"border&colon; none&semi;" src&equals;"https&colon;&sol;&sol;images-fe&period;ssl-images-amazon&period;com&sol;images&sol;I&sol;41x2HKj6VQL&period;&lowbar;SL160&lowbar;&period;jpg" &sol;><&sol;a><&sol;div>&NewLine;<div class&equals;"kaerebalink-info" style&equals;"line-height&colon; 120&percnt;&semi; &sol;zoom&colon; 1&semi; overflow&colon; hidden&semi;">&NewLine;<div class&equals;"kaerebalink-name" style&equals;"margin-bottom&colon; 10px&semi; line-height&colon; 120&percnt;&semi;">&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;amazon&period;co&period;jp&sol;exec&sol;obidos&sol;ASIN&sol;B00NF2GN6U&sol;bacque-22&sol;" target&equals;"&lowbar;blank" rel&equals;"nofollow noopener">ヤマハ ギガアクセスVPNルーター RTX1210<&sol;a><&sol;p>&NewLine;<div class&equals;"kaerebalink-powered-date" style&equals;"font-size&colon; 8pt&semi; margin-top&colon; 5px&semi; font-family&colon; verdana&semi; line-height&colon; 120&percnt;&semi;">posted with <a href&equals;"http&colon;&sol;&sol;kaereba&period;com" target&equals;"&lowbar;blank" rel&equals;"nofollow noopener">カエレバ<&sol;a><&sol;div>&NewLine;<&sol;div>&NewLine;<div class&equals;"kaerebalink-detail" style&equals;"margin-bottom&colon; 5px&semi;">ヤマハ&lpar;YAMAHA&rpar; 2014-11-27<&sol;div>&NewLine;<div class&equals;"kaerebalink-link1" style&equals;"margin-top&colon; 10px&semi;">&NewLine;<div class&equals;"shoplinkamazon" style&equals;"display&colon; inline&semi; margin-right&colon; 5px&semi;"><a href&equals;"https&colon;&sol;&sol;www&period;amazon&period;co&period;jp&sol;gp&sol;search&quest;keywords&equals;RTX1210&amp&semi;&lowbar;&lowbar;mk&lowbar;ja&lowbar;JP&equals;&percnt;E3&percnt;82&percnt;AB&percnt;E3&percnt;82&percnt;BF&percnt;E3&percnt;82&percnt;AB&percnt;E3&percnt;83&percnt;8A&amp&semi;tag&equals;bacque-22" target&equals;"&lowbar;blank" rel&equals;"nofollow noopener">Amazon<&sol;a><&sol;div>&NewLine;<div class&equals;"shoplinkrakuten" style&equals;"display&colon; inline&semi; margin-right&colon; 5px&semi;"><a href&equals;"https&colon;&sol;&sol;hb&period;afl&period;rakuten&period;co&period;jp&sol;hgc&sol;169e124b&period;ad18ba9f&period;169e124c&period;8664ddb0&sol;&quest;pc&equals;https&percnt;3A&percnt;2F&percnt;2Fsearch&period;rakuten&period;co&period;jp&percnt;2Fsearch&percnt;2Fmall&percnt;2FRTX1210&percnt;2F-&percnt;2Ff&period;1-p&period;1-s&period;1-sf&period;0-st&period;A-v&period;2&percnt;3Fx&percnt;3D0&percnt;26scid&percnt;3Daf&lowbar;ich&lowbar;link&lowbar;urltxt&percnt;26m&percnt;3Dhttp&percnt;3A&percnt;2F&percnt;2Fm&period;rakuten&period;co&period;jp&percnt;2F" target&equals;"&lowbar;blank" rel&equals;"nofollow noopener">楽天市場<&sol;a><&sol;div>&NewLine;<div class&equals;"shoplinkyahoo" style&equals;"display&colon; inline&semi; margin-right&colon; 5px&semi;"><a href&equals;"&sol;&sol;ck&period;jp&period;ap&period;valuecommerce&period;com&sol;servlet&sol;referral&quest;sid&equals;3395417&amp&semi;pid&equals;885190264&amp&semi;vc&lowbar;url&equals;http&percnt;3A&percnt;2F&percnt;2Fsearch&period;shopping&period;yahoo&period;co&period;jp&percnt;2Fsearch&percnt;3Fp&percnt;3DRTX1210&amp&semi;vcptn&equals;kaereba" target&equals;"&lowbar;blank" rel&equals;"nofollow noopener">Yahooショッピング<img src&equals;"&sol;&sol;ad&period;jp&period;ap&period;valuecommerce&period;com&sol;servlet&sol;gifbanner&quest;sid&equals;3395417&amp&semi;pid&equals;885190264" width&equals;"1" height&equals;"1" border&equals;"0" &sol;><&sol;a><&sol;div>&NewLine;<&sol;div>&NewLine;<&sol;div>&NewLine;<div class&equals;"booklink-footer" style&equals;"clear&colon; left&semi;"><&sol;div>&NewLine;<&sol;div>&NewLine;<p>RTX1210の初期IPアドレスは192&period;168&period;100&period;1ですが、ポート番号とIPアドレスの対応がわかりやすいように192&period;168&period;1&period;1に変更しました。以下のようなセグメントになるように設定します。<&sol;p>&NewLine;<ul>&NewLine;<li>ポート1(192&period;168&period;1&period;0&sol;24)<&sol;li>&NewLine;<li>ポート2(192&period;168&period;2&period;0&sol;24)<&sol;li>&NewLine;<li>ポート3(192&period;168&period;3&period;0&sol;24)<&sol;li>&NewLine;<li>ポート4(192&period;168&period;4&period;0&sol;24)<&sol;li>&NewLine;<li>ポート5(192&period;168&period;5&period;0&sol;24)<&sol;li>&NewLine;<li>ポート6(192&period;168&period;6&period;0&sol;24)<&sol;li>&NewLine;<li>ポート7(192&period;168&period;7&period;0&sol;24)<&sol;li>&NewLine;<li>ポート8(192&period;168&period;8&period;0&sol;24)<&sol;li>&NewLine;<&sol;ul>&NewLine;<h2>設定方法<&sol;h2>&NewLine;<p>YAMAHAのサイトからテキストをダウンロードして、一部改良してtftpコマンドで流し込む方法も取れますが、今の環境を維持しながら変更したい場合はRTX1210にログインしてWebからコマンド入力して変更していきます。<&sol;p>&NewLine;<h3>LAN1をポートVLANへの切り替え<&sol;h3>&NewLine;<p>RTX1210にログインしてコマンド入力する場合、<span class&equals;"ymarker" style&equals;"background-color&colon; &num;ffff00&semi;">設定用のPCを必ずLAN1ポートに接続<&sol;span><&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;77ed3feaa104b982b1fb18b1d950dc3e&period;jpg"><img data-attachment-id&equals;"8531" data-permalink&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;archives&sol;8512&sol;20180414&lowbar;175039&lowbar;rtx1210&percnt;e3&percnt;81&percnt;ae&percnt;e3&percnt;83&percnt;9d&percnt;e3&percnt;83&percnt;bc&percnt;e3&percnt;83&percnt;88vlan" data-orig-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;77ed3feaa104b982b1fb18b1d950dc3e&period;jpg&quest;fit&equals;600&percnt;2C318&amp&semi;ssl&equals;1" data-orig-size&equals;"600&comma;318" data-comments-opened&equals;"1" data-image-meta&equals;"&lbrace;&quot&semi;aperture&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;credit&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;camera&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;caption&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;created&lowbar;timestamp&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;copyright&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;focal&lowbar;length&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;iso&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;shutter&lowbar;speed&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;title&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;orientation&quot&semi;&colon;&quot&semi;0&quot&semi;&rcub;" data-image-title&equals;"20180414&lowbar;175039&lowbar;RTX1210のポートVLAN" data-image-description&equals;"" data-image-caption&equals;"" data-medium-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;77ed3feaa104b982b1fb18b1d950dc3e&period;jpg&quest;fit&equals;400&percnt;2C212&amp&semi;ssl&equals;1" data-large-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;77ed3feaa104b982b1fb18b1d950dc3e&period;jpg&quest;fit&equals;600&percnt;2C318&amp&semi;ssl&equals;1" class&equals;"alignnone size-medium wp-image-8531" src&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;77ed3feaa104b982b1fb18b1d950dc3e-400x212&period;jpg" alt&equals;"" width&equals;"400" height&equals;"212" &sol;><&sol;a><&sol;p>&NewLine;<p>lan type lan1 port-based&bsol;option&equals;divide-network<&sol;p>&NewLine;<p>と入力してLAN1ポートを分離設定しようとしたが、失敗。エラー:重複して使用できない設定がありますとログ表示<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;6c126ccc25bd22a6333a9ada277ffac8&period;jpg"><img data-attachment-id&equals;"8532" data-permalink&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;archives&sol;8512&sol;20180414&lowbar;175246&lowbar;rtx1210&percnt;e3&percnt;81&percnt;ae&percnt;e3&percnt;83&percnt;9d&percnt;e3&percnt;83&percnt;bc&percnt;e3&percnt;83&percnt;88vlan" data-orig-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;6c126ccc25bd22a6333a9ada277ffac8&period;jpg&quest;fit&equals;600&percnt;2C366&amp&semi;ssl&equals;1" data-orig-size&equals;"600&comma;366" data-comments-opened&equals;"1" data-image-meta&equals;"&lbrace;&quot&semi;aperture&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;credit&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;camera&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;caption&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;created&lowbar;timestamp&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;copyright&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;focal&lowbar;length&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;iso&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;shutter&lowbar;speed&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;title&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;orientation&quot&semi;&colon;&quot&semi;0&quot&semi;&rcub;" data-image-title&equals;"20180414&lowbar;175246&lowbar;RTX1210のポートVLAN" data-image-description&equals;"" data-image-caption&equals;"" data-medium-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;6c126ccc25bd22a6333a9ada277ffac8&period;jpg&quest;fit&equals;400&percnt;2C244&amp&semi;ssl&equals;1" data-large-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;6c126ccc25bd22a6333a9ada277ffac8&period;jpg&quest;fit&equals;600&percnt;2C366&amp&semi;ssl&equals;1" class&equals;"alignnone size-medium wp-image-8532" src&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;6c126ccc25bd22a6333a9ada277ffac8-400x244&period;jpg" alt&equals;"" width&equals;"400" height&equals;"244" &sol;><&sol;a><&sol;p>&NewLine;<p>原因はL2MSの設定がされていたためでした。L2MSとはヤマハ製スイッチ以外がルーターのLAN1に直接接続されることを防ぐための機能です。<&sol;p>&NewLine;<p>switch control use lan1 off<&sol;p>&NewLine;<p>が設定されていたためコマンド削除<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;e0d0ce188f7dcfd247d49ef1f4cfecaf&period;jpg"><img data-attachment-id&equals;"8533" data-permalink&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;archives&sol;8512&sol;20180414&lowbar;175328&lowbar;rtx1210&percnt;e3&percnt;81&percnt;ae&percnt;e3&percnt;83&percnt;9d&percnt;e3&percnt;83&percnt;bc&percnt;e3&percnt;83&percnt;88vlan" data-orig-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;e0d0ce188f7dcfd247d49ef1f4cfecaf&period;jpg&quest;fit&equals;600&percnt;2C320&amp&semi;ssl&equals;1" data-orig-size&equals;"600&comma;320" data-comments-opened&equals;"1" data-image-meta&equals;"&lbrace;&quot&semi;aperture&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;credit&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;camera&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;caption&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;created&lowbar;timestamp&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;copyright&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;focal&lowbar;length&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;iso&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;shutter&lowbar;speed&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;title&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;orientation&quot&semi;&colon;&quot&semi;0&quot&semi;&rcub;" data-image-title&equals;"20180414&lowbar;175328&lowbar;RTX1210のポートVLAN" data-image-description&equals;"" data-image-caption&equals;"" data-medium-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;e0d0ce188f7dcfd247d49ef1f4cfecaf&period;jpg&quest;fit&equals;400&percnt;2C213&amp&semi;ssl&equals;1" data-large-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;e0d0ce188f7dcfd247d49ef1f4cfecaf&period;jpg&quest;fit&equals;600&percnt;2C320&amp&semi;ssl&equals;1" class&equals;"alignnone size-medium wp-image-8533" src&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;e0d0ce188f7dcfd247d49ef1f4cfecaf-400x213&period;jpg" alt&equals;"" width&equals;"400" height&equals;"213" &sol;><&sol;a><&sol;p>&NewLine;<p>no switch control use lan1 off<&sol;p>&NewLine;<p>上のコマンドを入力して実行すると削除成功、保存成功<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;8cb78f9f54a8cf362ffc9cd60804d27b&period;jpg"><img data-attachment-id&equals;"8534" data-permalink&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;archives&sol;8512&sol;20180414&lowbar;175402&lowbar;rtx1210&percnt;e3&percnt;81&percnt;ae&percnt;e3&percnt;83&percnt;9d&percnt;e3&percnt;83&percnt;bc&percnt;e3&percnt;83&percnt;88vlan" data-orig-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;8cb78f9f54a8cf362ffc9cd60804d27b&period;jpg&quest;fit&equals;600&percnt;2C375&amp&semi;ssl&equals;1" data-orig-size&equals;"600&comma;375" data-comments-opened&equals;"1" data-image-meta&equals;"&lbrace;&quot&semi;aperture&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;credit&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;camera&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;caption&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;created&lowbar;timestamp&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;copyright&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;focal&lowbar;length&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;iso&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;shutter&lowbar;speed&quot&semi;&colon;&quot&semi;0&quot&semi;&comma;&quot&semi;title&quot&semi;&colon;&quot&semi;&quot&semi;&comma;&quot&semi;orientation&quot&semi;&colon;&quot&semi;0&quot&semi;&rcub;" data-image-title&equals;"20180414&lowbar;175402&lowbar;RTX1210のポートVLAN" data-image-description&equals;"" data-image-caption&equals;"" data-medium-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;8cb78f9f54a8cf362ffc9cd60804d27b&period;jpg&quest;fit&equals;400&percnt;2C250&amp&semi;ssl&equals;1" data-large-file&equals;"https&colon;&sol;&sol;i0&period;wp&period;com&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;8cb78f9f54a8cf362ffc9cd60804d27b&period;jpg&quest;fit&equals;600&percnt;2C375&amp&semi;ssl&equals;1" class&equals;"alignnone size-medium wp-image-8534" src&equals;"https&colon;&sol;&sol;bacque&period;biz&sol;wp-content&sol;uploads&sol;2018&sol;04&sol;8cb78f9f54a8cf362ffc9cd60804d27b-400x250&period;jpg" alt&equals;"" width&equals;"400" height&equals;"250" &sol;><&sol;a><&sol;p>&NewLine;<p>そのあと再度<&sol;p>&NewLine;<p>lan type lan1 port-based&bsol;option&equals;divide-network<&sol;p>&NewLine;<p>を実行したところポートVLAN設定が成功しました。<&sol;p>&NewLine;<h3>VLANとポートの対応付け<&sol;h3>&NewLine;<p>8ポートすべてを分離する場合<&sol;p>&NewLine;<ul>&NewLine;<li>ポート1をVLAN1<&sol;li>&NewLine;<li>ポート2をVLAN2<&sol;li>&NewLine;<li>ポート3をVLAN3<&sol;li>&NewLine;<li>ポート4をVLAN4<&sol;li>&NewLine;<li>ポート5をVLAN5<&sol;li>&NewLine;<li>ポート6をVLAN6<&sol;li>&NewLine;<li>ポート7をVLAN7<&sol;li>&NewLine;<li>ポート8をVLAN8<&sol;li>&NewLine;<&sol;ul>&NewLine;<p>に設定するには以下のコマンドを入力<&sol;p>&NewLine;<pre class&equals;"lang&colon;default decode&colon;true ">vlan port mapping lan1&period;1 vlan1 &NewLine;vlan port mapping lan1&period;2 vlan2 &NewLine;vlan port mapping lan1&period;3 vlan3 &NewLine;vlan port mapping lan1&period;4 vlan4 &NewLine;vlan port mapping lan1&period;5 vlan5 &NewLine;vlan port mapping lan1&period;6 vlan6 &NewLine;vlan port mapping lan1&period;7 vlan7 &NewLine;vlan port mapping lan1&period;8 vlan8<&sol;pre>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<p>※以下のように複数ポートを同じセグメントにする場合<&sol;p>&NewLine;<ul>&NewLine;<li>ポート1~6をVLAN1<&sol;li>&NewLine;<li>ポート7をVLAN7<&sol;li>&NewLine;<li>ポート8をVLAN8に設定する場合は<&sol;li>&NewLine;<&sol;ul>&NewLine;<pre class&equals;"lang&colon;default decode&colon;true ">vlan port mapping lan1&period;1 vlan1 &NewLine;vlan port mapping lan1&period;2 vlan1 &NewLine;vlan port mapping lan1&period;3 vlan1 &NewLine;vlan port mapping lan1&period;4 vlan1 &NewLine;vlan port mapping lan1&period;5 vlan1 &NewLine;vlan port mapping lan1&period;6 vlan1 &NewLine;vlan port mapping lan1&period;7 vlan7 &NewLine;vlan port mapping lan1&period;8 vlan8<&sol;pre>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<h3>VLANのIPアドレスを入力<&sol;h3>&NewLine;<p>以下のようにポート1~8のアドレスを設定するとします<&sol;p>&NewLine;<ul>&NewLine;<li>VLAN1のアドレスを192&period;168&period;1&period;1&sol;24<&sol;li>&NewLine;<li>VLAN2のアドレスを192&period;168&period;2&period;1&sol;24<&sol;li>&NewLine;<li>VLAN3のアドレスを192&period;168&period;3&period;1&sol;24<&sol;li>&NewLine;<li>VLAN4のアドレスを192&period;168&period;4&period;1&sol;24<&sol;li>&NewLine;<li>VLAN5のアドレスを192&period;168&period;5&period;1&sol;24<&sol;li>&NewLine;<li>VLAN6のアドレスを192&period;168&period;6&period;1&sol;24<&sol;li>&NewLine;<li>VLAN7のアドレスを192&period;168&period;7&period;1&sol;24<&sol;li>&NewLine;<li>VLAN8のアドレスを192&period;168&period;8&period;1&sol;24<&sol;li>&NewLine;<&sol;ul>&NewLine;<pre class&equals;"lang&colon;default decode&colon;true ">ip vlan2 192&period;168&period;2&period;1&sol;24 &NewLine;ip vlan3 192&period;168&period;3&period;1&sol;24 &NewLine;ip vlan4 192&period;168&period;4&period;1&sol;24 &NewLine;ip vlan5 192&period;168&period;5&period;1&sol;24 &NewLine;ip vlan6 192&period;168&period;6&period;1&sol;24 &NewLine;ip vlan7 192&period;168&period;7&period;1&sol;24 &NewLine;ip vlan8 192&period;168&period;8&period;1&sol;24<&sol;pre>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<p><span class&equals;"ymarker">VLAN1のアドレスはLAN1アドレスが反映されるので入力する必要はありません<&sol;span><&sol;p>&NewLine;<h3>各VLANからDNSのアクセスを許可<&sol;h3>&NewLine;<p>dns host any<&sol;p>&NewLine;<h3>DHCPサーバーの追加<&sol;h3>&NewLine;<p>ポート1DHCPサーバー設定済の場合、ポート2~8までを追加してください。ポートのアドレスは1なので2~191の190個のアドレスをDHCPサーバー機能により割り当てていきます。割り当てるアドレスの数は適宜変更してください。<&sol;p>&NewLine;<p>RTX1210のどれかのポートにローカルルーターを接続する場合、ローカルルーターによるDHCPサーバー機能を使うのでRTX1210側のDHCP機能は削除しておきます。例えばVLAN8に無線LANルーターを接続した場合、dhcp scope 8 192&period;168&period;8&period;2-192&period;168&period;8&period;191&sol;24を削除しておきます。<&sol;p>&NewLine;<pre class&equals;"lang&colon;default decode&colon;true ">dhcp service server &NewLine;dhcp server rfc2131 compliant except remain-silent &NewLine;dhcp scope 1 192&period;168&period;1&period;2-192&period;168&period;1&period;191&sol;24 &NewLine;dhcp scope 2 192&period;168&period;2&period;2-192&period;168&period;2&period;191&sol;24 &NewLine;dhcp scope 3 192&period;168&period;3&period;2-192&period;168&period;3&period;191&sol;24 &NewLine;dhcp scope 4 192&period;168&period;4&period;2-192&period;168&period;4&period;191&sol;24 &NewLine;dhcp scope 5 192&period;168&period;5&period;2-192&period;168&period;5&period;191&sol;24 &NewLine;dhcp scope 6 192&period;168&period;6&period;2-192&period;168&period;6&period;191&sol;24 &NewLine;dhcp scope 7 192&period;168&period;7&period;2-192&period;168&period;7&period;191&sol;24 &NewLine;dhcp scope 8 192&period;168&period;8&period;2-192&period;168&period;8&period;191&sol;24<&sol;pre>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<h3>フィルターの追加<&sol;h3>&NewLine;<p>もともと設定していた192&period;168&period;1&period;0&sol;24以外に7つのVLANが作成されたので、1022~1028 1032~1038を追加してください。<&sol;p>&NewLine;<pre class&equals;"lang&colon;default decode&colon;true ">ip pp secure filter in 1021 1022 1023 1024 1025 1026 1027 1028 1031 1032 1033 1034 1035 1036 1037 1038 2000 &NewLine;ip pp secure filter out 1010 1011 1012 1013 1014 1015 3000 dynamic 100 101 102 103 104 105 106 107 pp enable 1 &NewLine; &NewLine;ip filter source-route on &NewLine;ip filter directed-broadcast on &NewLine;ip filter 1010 reject &ast; &ast; udp&comma;tcp 135 &ast; &NewLine;ip filter 1011 reject &ast; &ast; udp&comma;tcp &ast; 135 &NewLine;ip filter 1012 reject &ast; &ast; udp&comma;tcp netbios&lowbar;ns-netbios&lowbar;ssn &ast; &NewLine;ip filter 1013 reject &ast; &ast; udp&comma;tcp &ast; netbios&lowbar;ns-netbios&lowbar;ssn &NewLine;ip filter 1014 reject &ast; &ast; udp&comma;tcp 445 &ast; &NewLine;ip filter 1015 reject &ast; &ast; udp&comma;tcp &ast; 445 &NewLine;ip filter 1021 reject 192&period;168&period;1&period;0&sol;24 &ast; &NewLine;ip filter 1022 reject 192&period;168&period;2&period;0&sol;24 &ast; &NewLine;ip filter 1023 reject 192&period;168&period;3&period;0&sol;24 &ast; &NewLine;ip filter 1024 reject 192&period;168&period;4&period;0&sol;24 &ast; &NewLine;ip filter 1025 reject 192&period;168&period;5&period;0&sol;24 &ast; &NewLine;ip filter 1026 reject 192&period;168&period;6&period;0&sol;24 &ast; &NewLine;ip filter 1027 reject 192&period;168&period;7&period;0&sol;24 &ast; &NewLine;ip filter 1028 reject 192&period;168&period;8&period;0&sol;24 &ast; &NewLine;ip filter 1031 pass &ast; 192&period;168&period;1&period;0&sol;24 icmp &NewLine;ip filter 1032 pass &ast; 192&period;168&period;2&period;0&sol;24 icmp &NewLine;ip filter 1033 pass &ast; 192&period;168&period;3&period;0&sol;24 icmp &NewLine;ip filter 1034 pass &ast; 192&period;168&period;4&period;0&sol;24 icmp &NewLine;ip filter 1035 pass &ast; 192&period;168&period;5&period;0&sol;24 icmp &NewLine;ip filter 1036 pass &ast; 192&period;168&period;6&period;0&sol;24 icmp &NewLine;ip filter 1037 pass &ast; 192&period;168&period;7&period;0&sol;24 icmp &NewLine;ip filter 1038 pass &ast; 192&period;168&period;8&period;0&sol;24 icmp &NewLine;ip filter 2000 reject &ast; &ast; &NewLine;ip filter 3000 pass &ast; &ast; &NewLine;ip filter dynamic 100 &ast; &ast; ftp &NewLine;ip filter dynamic 101 &ast; &ast; www &NewLine;ip filter dynamic 102 &ast; &ast; domain &NewLine;ip filter dynamic 103 &ast; &ast; smtp &NewLine;ip filter dynamic 104 &ast; &ast; pop3 &NewLine;ip filter dynamic 105 &ast; &ast; submission &NewLine;ip filter dynamic 106 &ast; &ast; tcp &NewLine;ip filter dynamic 107 &ast; &ast; udp<&sol;pre>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<h3>部門間の通信を遮断するには<&sol;h3>&NewLine;<p>以下のフィルターを追加します<&sol;p>&NewLine;<pre class&equals;"lang&colon;default decode&colon;true ">ip filter 1041 reject &ast; 192&period;168&period;1&period;0&sol;24 &NewLine;ip filter 1042 reject &ast; 192&period;168&period;2&period;0&sol;24 &NewLine;ip filter 1043 reject &ast; 192&period;168&period;3&period;0&sol;24 &NewLine;ip filter 1044 reject &ast; 192&period;168&period;4&period;0&sol;24 &NewLine;ip filter 1045 reject &ast; 192&period;168&period;5&period;0&sol;24 &NewLine;ip filter 1046 reject &ast; 192&period;168&period;6&period;0&sol;24 &NewLine;ip filter 1047 reject &ast; 192&period;168&period;7&period;0&sol;24 &NewLine;ip filter 1048 reject &ast; 192&period;168&period;8&period;0&sol;24 &NewLine; &NewLine;ip vlan1 secure filter in 1042 1043 1044 1045 1046 1047 1048 3000 &NewLine;ip vlan1 secure filter out 1022 1023 1024 1025 1026 1027 1028 3000 &NewLine;ip vlan2 secure filter in 1041 1043 1044 1045 1046 1047 1048 3000 &NewLine;ip vlan2 secure filter out 1021 1023 1024 1025 1026 1027 1028 3000 &NewLine;ip vlan3 secure filter in 1041 1042 1044 1045 1046 1047 1048 3000 &NewLine;ip vlan3 secure filter out 1021 1022 1024 1025 1026 1027 1028 3000 &NewLine;ip vlan4 secure filter in 1041 1042 1043 1045 1046 1047 1048 3000 &NewLine;ip vlan4 secure filter out 1021 1022 1023 1025 1026 1027 1028 3000 &NewLine;ip vlan5 secure filter in 1041 1042 1043 1044 1046 1047 1048 3000 &NewLine;ip vlan5 secure filter out 1021 1022 1023 1024 1026 1027 1028 3000 &NewLine;ip vlan6 secure filter in 1041 1042 1043 1044 1045 1047 1048 3000 &NewLine;ip vlan6 secure filter out 1021 1022 1023 1024 1025 1027 1028 3000 &NewLine;ip vlan7 secure filter in 1041 1042 1043 1044 1045 1046 1048 3000 &NewLine;ip vlan7 secure filter out 1021 1022 1023 1024 1025 1026 1028 3000 &NewLine;ip vlan8 secure filter in 1041 1042 1043 1044 1045 1046 1047 3000 &NewLine;ip vlan8 secure filter out 1021 1022 1023 1024 1025 1026 1027 3000<&sol;pre>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<p>以上で部門間の通信は遮断されます。<&sol;p>&NewLine;

管理人:

View Comments (2)

  • 参考にしました。
    x lan type lan1 port-based\option=divide-network
    ○ lan type lan1 port-based-option=divide-network
    でもVLAN間の通信ができないな-

Related Post