質問するログイン新規登録

質問編集履歴

1

拠点Aのコンフィグ追加

2018/02/13 03:15

投稿

ky1990
ky1990

スコア14

title CHANGED
File without changes
body CHANGED
@@ -5,4 +5,241 @@
5
5
  もし、設定に問題があったらご指摘頂ければ幸いです。
6
6
  その他、セキュリティやFW等、疑うべき箇所につきましてご指導頂ければ幸いです。
7
7
 
8
- 使用機器:RTX1210
8
+ 使用機器:RTX1210
9
+
10
+ 下記実際のコンフィグです。
11
+
12
+ 拠点A
13
+ ip route default gateway pp 1
14
+ ip filter source-route on
15
+ ip filter directed-broadcast on
16
+ bridge member bridge1 lan1 tunnel7
17
+ ip bridge1 address 172.27.1.253/24
18
+ ip lan1 address 172.27.1.253/24
19
+ ip lan1 proxyarp on
20
+ ip lan1 secure filter in 10 99
21
+ ip lan3 address 172.27.2.253/24
22
+ ip lan3 proxyarp on
23
+ ip lan3 secure filter in 11 99
24
+ pp select 1
25
+ pp always-on on
26
+ pppoe use lan2
27
+ pp auth accept pap chap
28
+ pp auth myname (ISP1へ接続するID) (ISP1へ接続するパスワード)
29
+ ppp lcp mru on 1454
30
+ ppp ipcp msext on
31
+ ppp ccp type none
32
+ ip pp address (拠点AのグローバルIP)
33
+ ip pp mtu 1454
34
+ ip pp secure filter in 1020 1030 1040 1041 1042 1043 1044 1045 2000
35
+ ip pp secure filter out 1010 1011 1012 1013 1014 1015 3000 dynamic 100 101 102 103 104 105 106 107
36
+ ip pp nat descriptor 1
37
+ pp enable 1
38
+ pp select anonymous
39
+ pp bind tunnel1-tunnel6 tunnel8-tunnel9
40
+ pp auth request mschap-v2
41
+ pp auth username (接続ユーザ名) (接続パスワード)
42
+ pp auth username (接続ユーザ名) (接続パスワード)
43
+ pp auth username (接続ユーザ名) (接続パスワード)
44
+ pp auth username (接続ユーザ名) (接続パスワード)
45
+ pp auth username (接続ユーザ名) (接続パスワード)
46
+ pp auth username (接続ユーザ名) (接続パスワード)
47
+ pp auth username (接続ユーザ名) (接続パスワード)
48
+ pp auth username (接続ユーザ名) (接続パスワード)
49
+ ppp ipcp ipaddress on
50
+ ppp ipcp msext on
51
+ ip pp remote address pool 172.27.1.200-172.27.1.209
52
+ ip pp mtu 1258
53
+ pp enable anonymous
54
+ tunnel select 1
55
+ tunnel encapsulation l2tp
56
+ ipsec tunnel 101
57
+ ipsec sa policy 101 1 esp 3des-cbc sha-hmac
58
+ ipsec ike keepalive use 1 off
59
+ ipsec ike local address 1 172.27.1.253
60
+ ipsec ike nat-traversal 1 on
61
+ ipsec ike remote address 1 any
62
+ ipsec ike license-key use 1 on
63
+ l2tp tunnel disconnect time off
64
+ l2tp keepalive use on 10 3
65
+ l2tp keepalive log on
66
+ l2tp syslog on
67
+ ip tunnel tcp mss limit auto
68
+ tunnel enable 1
69
+ tunnel select 2
70
+ tunnel encapsulation l2tp
71
+ ipsec tunnel 102
72
+ ipsec sa policy 102 2 esp 3des-cbc sha-hmac
73
+ ipsec ike keepalive use 2 off
74
+ ipsec ike local address 2 172.27.1.253
75
+ ipsec ike nat-traversal 2 on
76
+ ipsec ike remote address 2 any
77
+ ipsec ike license-key use 2 on
78
+ l2tp tunnel disconnect time off
79
+ l2tp keepalive use on 10 3
80
+ l2tp keepalive log on
81
+ l2tp syslog on
82
+ ip tunnel tcp mss limit auto
83
+ tunnel enable 2
84
+ tunnel select 3
85
+ tunnel encapsulation l2tp
86
+ ipsec tunnel 103
87
+ ipsec sa policy 103 3 esp 3des-cbc sha-hmac
88
+ ipsec ike keepalive use 3 off
89
+ ipsec ike local address 3 172.27.1.253
90
+ ipsec ike nat-traversal 3 on
91
+ ipsec ike remote address 3 any
92
+ ipsec ike license-key use 3 on
93
+ l2tp tunnel disconnect time off
94
+ l2tp keepalive use on 10 3
95
+ l2tp keepalive log on
96
+ l2tp syslog on
97
+ ip tunnel tcp mss limit auto
98
+ tunnel enable 3
99
+ tunnel select 4
100
+ tunnel encapsulation l2tp
101
+ ipsec tunnel 104
102
+ ipsec sa policy 104 4 esp 3des-cbc sha-hmac
103
+ ipsec ike keepalive use 4 off
104
+ ipsec ike local address 4 172.27.1.253
105
+ ipsec ike nat-traversal 4 on
106
+ ipsec ike remote address 4 any
107
+ ipsec ike license-key use 4 on
108
+ l2tp tunnel disconnect time off
109
+ l2tp keepalive use on 10 3
110
+ l2tp keepalive log on
111
+ l2tp syslog on
112
+ ip tunnel tcp mss limit auto
113
+ tunnel enable 4
114
+ tunnel select 5
115
+ tunnel encapsulation l2tp
116
+ ipsec tunnel 105
117
+ ipsec sa policy 105 5 esp 3des-cbc sha-hmac
118
+ ipsec ike keepalive use 5 off
119
+ ipsec ike local address 5 172.27.1.253
120
+ ipsec ike nat-traversal 5 on
121
+ ipsec ike remote address 5 any
122
+ ipsec ike license-key use 5 on
123
+ l2tp tunnel disconnect time off
124
+ l2tp keepalive use on 10 3
125
+ l2tp keepalive log on
126
+ l2tp syslog on
127
+ ip tunnel tcp mss limit auto
128
+ tunnel enable 5
129
+ tunnel select 6
130
+ tunnel encapsulation l2tp
131
+ ipsec tunnel 106
132
+ ipsec sa policy 106 6 esp 3des-cbc sha-hmac
133
+ ipsec ike keepalive use 6 off
134
+ ipsec ike local address 6 172.27.1.253
135
+ ipsec ike nat-traversal 6 on
136
+ ipsec ike remote address 6 any
137
+ ipsec ike license-key use 6 on
138
+ l2tp tunnel disconnect time off
139
+ l2tp keepalive use on 10 3
140
+ l2tp keepalive log on
141
+ l2tp syslog on
142
+ ip tunnel tcp mss limit auto
143
+ tunnel enable 6
144
+ tunnel select 7
145
+ tunnel encapsulation l2tpv3
146
+ tunnel endpoint address 172.27.1.253 (拠点BのグローバルIP)
147
+ ipsec tunnel 107
148
+ ipsec sa policy 107 7 esp aes-cbc sha-hmac
149
+ ipsec ike keepalive log 7 on
150
+ ipsec ike keepalive use 7 on
151
+ ipsec ike local address 7 172.27.1.253
152
+ ipsec ike pre-shared-key 7 text (事前共有鍵①)
153
+ ipsec ike remote address 7 (拠点BのグローバルIP)
154
+ l2tp always-on on
155
+ l2tp hostname surluster
156
+ l2tp tunnel auth on (L2TP トンネル認証に用いるパスワード①)
157
+ l2tp tunnel disconnect time off
158
+ l2tp keepalive use on 60 3
159
+ l2tp keepalive log on
160
+ l2tp syslog on
161
+ l2tp local router-id 172.27.1.253
162
+ l2tp remote router-id 172.27.1.254
163
+ l2tp remote end-id A
164
+ tunnel enable 7
165
+ tunnel select 8
166
+ tunnel encapsulation l2tp
167
+ ipsec tunnel 108
168
+ ipsec sa policy 108 8 esp aes-cbc sha-hmac
169
+ ipsec ike keepalive use 8 off
170
+ ipsec ike nat-traversal 8 on
171
+ ipsec ike pre-shared-key 8 text (事前共有鍵)
172
+ ipsec ike remote address 8 any
173
+ l2tp tunnel disconnect time off
174
+ l2tp keepalive use on 10 3
175
+ l2tp keepalive log on
176
+ l2tp syslog on
177
+ ip tunnel tcp mss limit auto
178
+ tunnel enable 8
179
+ tunnel select 9
180
+ tunnel encapsulation l2tp
181
+ ipsec tunnel 109
182
+ ipsec sa policy 109 9 esp aes-cbc sha-hmac
183
+ ipsec ike keepalive use 9 off
184
+ ipsec ike nat-traversal 9 on
185
+ ipsec ike pre-shared-key 9 text (事前共有鍵)
186
+ ipsec ike remote address 9 any
187
+ l2tp tunnel disconnect time off
188
+ l2tp keepalive use on 10 3
189
+ l2tp keepalive log on
190
+ l2tp syslog on
191
+ ip tunnel tcp mss limit auto
192
+ tunnel enable 9
193
+ ip filter 10 reject * 172.27.2.0/24 * * *
194
+ ip filter 11 reject * 172.27.1.0/24 * * *
195
+ ip filter 99 pass * * * * *
196
+ ip filter 1010 reject * * udp,tcp 135 *
197
+ ip filter 1011 reject * * udp,tcp * 135
198
+ ip filter 1012 reject * * udp,tcp netbios_ns-netbios_ssn *
199
+ ip filter 1013 reject * * udp,tcp * netbios_ns-netbios_ssn
200
+ ip filter 1014 reject * * udp,tcp 445 *
201
+ ip filter 1015 reject * * udp,tcp * 445
202
+ ip filter 1020 reject 172.27.1.0/24 *
203
+ ip filter 1030 pass * 172.27.1.0/24 icmp
204
+ ip filter 1040 pass * 172.27.1.253 udp * 500
205
+ ip filter 1041 pass * 172.27.1.253 udp * 4500
206
+ ip filter 1042 pass * 172.27.1.253 esp
207
+ ip filter 1043 pass * 172.27.1.254 udp * 500
208
+ ip filter 1044 pass * 172.27.1.254 udp * 4500
209
+ ip filter 1045 pass * 172.27.1.254 esp
210
+ ip filter 2000 reject * *
211
+ ip filter 3000 pass * *
212
+ ip filter dynamic 100 * * ftp
213
+ ip filter dynamic 101 * * www
214
+ ip filter dynamic 102 * * domain
215
+ ip filter dynamic 103 * * smtp
216
+ ip filter dynamic 104 * * pop3
217
+ ip filter dynamic 105 * * imap
218
+ ip filter dynamic 106 * * netmeeting
219
+ ip filter dynamic 107 * * tcp
220
+ ip filter dynamic 108 * * udp
221
+ ip filter dynamic 109 * * submission
222
+ nat descriptor type 1 masquerade
223
+ nat descriptor address outer 1 (拠点AのグローバルIP)
224
+ nat descriptor masquerade static 1 1 172.27.1.253 esp
225
+ nat descriptor masquerade static 1 2 172.27.1.253 udp 500
226
+ nat descriptor masquerade static 1 3 172.27.1.253 udp 4500
227
+ ipsec auto refresh on
228
+ ipsec ike license-key 1 (ライセンスキー)
229
+ ipsec transport 1 101 udp 1701
230
+ ipsec transport 2 102 udp 1701
231
+ ipsec transport 3 103 udp 1701
232
+ ipsec transport 4 104 udp 1701
233
+ ipsec transport 5 105 udp 1701
234
+ ipsec transport 6 106 udp 1701
235
+ ipsec transport 7 107 udp 1701
236
+ ipsec transport 8 108 udp 1701
237
+ ipsec transport 9 109 udp 1701
238
+ dhcp service server
239
+ dhcp server rfc2131 compliant except remain-silent
240
+ dhcp scope 1 172.27.1.2-172.27.1.191/24
241
+ dns server (拠点AのDNS① 拠点AのDNS②)
242
+ dns private address spoof on
243
+ l2tp service on
244
+ httpd host any
245
+ dashboard accumulate traffic on