質問編集履歴
1
拠点Aのコンフィグ追加
title
CHANGED
File without changes
|
body
CHANGED
@@ -5,4 +5,241 @@
|
|
5
5
|
もし、設定に問題があったらご指摘頂ければ幸いです。
|
6
6
|
その他、セキュリティやFW等、疑うべき箇所につきましてご指導頂ければ幸いです。
|
7
7
|
|
8
|
-
使用機器:RTX1210
|
8
|
+
使用機器:RTX1210
|
9
|
+
|
10
|
+
下記実際のコンフィグです。
|
11
|
+
|
12
|
+
拠点A
|
13
|
+
ip route default gateway pp 1
|
14
|
+
ip filter source-route on
|
15
|
+
ip filter directed-broadcast on
|
16
|
+
bridge member bridge1 lan1 tunnel7
|
17
|
+
ip bridge1 address 172.27.1.253/24
|
18
|
+
ip lan1 address 172.27.1.253/24
|
19
|
+
ip lan1 proxyarp on
|
20
|
+
ip lan1 secure filter in 10 99
|
21
|
+
ip lan3 address 172.27.2.253/24
|
22
|
+
ip lan3 proxyarp on
|
23
|
+
ip lan3 secure filter in 11 99
|
24
|
+
pp select 1
|
25
|
+
pp always-on on
|
26
|
+
pppoe use lan2
|
27
|
+
pp auth accept pap chap
|
28
|
+
pp auth myname (ISP1へ接続するID) (ISP1へ接続するパスワード)
|
29
|
+
ppp lcp mru on 1454
|
30
|
+
ppp ipcp msext on
|
31
|
+
ppp ccp type none
|
32
|
+
ip pp address (拠点AのグローバルIP)
|
33
|
+
ip pp mtu 1454
|
34
|
+
ip pp secure filter in 1020 1030 1040 1041 1042 1043 1044 1045 2000
|
35
|
+
ip pp secure filter out 1010 1011 1012 1013 1014 1015 3000 dynamic 100 101 102 103 104 105 106 107
|
36
|
+
ip pp nat descriptor 1
|
37
|
+
pp enable 1
|
38
|
+
pp select anonymous
|
39
|
+
pp bind tunnel1-tunnel6 tunnel8-tunnel9
|
40
|
+
pp auth request mschap-v2
|
41
|
+
pp auth username (接続ユーザ名) (接続パスワード)
|
42
|
+
pp auth username (接続ユーザ名) (接続パスワード)
|
43
|
+
pp auth username (接続ユーザ名) (接続パスワード)
|
44
|
+
pp auth username (接続ユーザ名) (接続パスワード)
|
45
|
+
pp auth username (接続ユーザ名) (接続パスワード)
|
46
|
+
pp auth username (接続ユーザ名) (接続パスワード)
|
47
|
+
pp auth username (接続ユーザ名) (接続パスワード)
|
48
|
+
pp auth username (接続ユーザ名) (接続パスワード)
|
49
|
+
ppp ipcp ipaddress on
|
50
|
+
ppp ipcp msext on
|
51
|
+
ip pp remote address pool 172.27.1.200-172.27.1.209
|
52
|
+
ip pp mtu 1258
|
53
|
+
pp enable anonymous
|
54
|
+
tunnel select 1
|
55
|
+
tunnel encapsulation l2tp
|
56
|
+
ipsec tunnel 101
|
57
|
+
ipsec sa policy 101 1 esp 3des-cbc sha-hmac
|
58
|
+
ipsec ike keepalive use 1 off
|
59
|
+
ipsec ike local address 1 172.27.1.253
|
60
|
+
ipsec ike nat-traversal 1 on
|
61
|
+
ipsec ike remote address 1 any
|
62
|
+
ipsec ike license-key use 1 on
|
63
|
+
l2tp tunnel disconnect time off
|
64
|
+
l2tp keepalive use on 10 3
|
65
|
+
l2tp keepalive log on
|
66
|
+
l2tp syslog on
|
67
|
+
ip tunnel tcp mss limit auto
|
68
|
+
tunnel enable 1
|
69
|
+
tunnel select 2
|
70
|
+
tunnel encapsulation l2tp
|
71
|
+
ipsec tunnel 102
|
72
|
+
ipsec sa policy 102 2 esp 3des-cbc sha-hmac
|
73
|
+
ipsec ike keepalive use 2 off
|
74
|
+
ipsec ike local address 2 172.27.1.253
|
75
|
+
ipsec ike nat-traversal 2 on
|
76
|
+
ipsec ike remote address 2 any
|
77
|
+
ipsec ike license-key use 2 on
|
78
|
+
l2tp tunnel disconnect time off
|
79
|
+
l2tp keepalive use on 10 3
|
80
|
+
l2tp keepalive log on
|
81
|
+
l2tp syslog on
|
82
|
+
ip tunnel tcp mss limit auto
|
83
|
+
tunnel enable 2
|
84
|
+
tunnel select 3
|
85
|
+
tunnel encapsulation l2tp
|
86
|
+
ipsec tunnel 103
|
87
|
+
ipsec sa policy 103 3 esp 3des-cbc sha-hmac
|
88
|
+
ipsec ike keepalive use 3 off
|
89
|
+
ipsec ike local address 3 172.27.1.253
|
90
|
+
ipsec ike nat-traversal 3 on
|
91
|
+
ipsec ike remote address 3 any
|
92
|
+
ipsec ike license-key use 3 on
|
93
|
+
l2tp tunnel disconnect time off
|
94
|
+
l2tp keepalive use on 10 3
|
95
|
+
l2tp keepalive log on
|
96
|
+
l2tp syslog on
|
97
|
+
ip tunnel tcp mss limit auto
|
98
|
+
tunnel enable 3
|
99
|
+
tunnel select 4
|
100
|
+
tunnel encapsulation l2tp
|
101
|
+
ipsec tunnel 104
|
102
|
+
ipsec sa policy 104 4 esp 3des-cbc sha-hmac
|
103
|
+
ipsec ike keepalive use 4 off
|
104
|
+
ipsec ike local address 4 172.27.1.253
|
105
|
+
ipsec ike nat-traversal 4 on
|
106
|
+
ipsec ike remote address 4 any
|
107
|
+
ipsec ike license-key use 4 on
|
108
|
+
l2tp tunnel disconnect time off
|
109
|
+
l2tp keepalive use on 10 3
|
110
|
+
l2tp keepalive log on
|
111
|
+
l2tp syslog on
|
112
|
+
ip tunnel tcp mss limit auto
|
113
|
+
tunnel enable 4
|
114
|
+
tunnel select 5
|
115
|
+
tunnel encapsulation l2tp
|
116
|
+
ipsec tunnel 105
|
117
|
+
ipsec sa policy 105 5 esp 3des-cbc sha-hmac
|
118
|
+
ipsec ike keepalive use 5 off
|
119
|
+
ipsec ike local address 5 172.27.1.253
|
120
|
+
ipsec ike nat-traversal 5 on
|
121
|
+
ipsec ike remote address 5 any
|
122
|
+
ipsec ike license-key use 5 on
|
123
|
+
l2tp tunnel disconnect time off
|
124
|
+
l2tp keepalive use on 10 3
|
125
|
+
l2tp keepalive log on
|
126
|
+
l2tp syslog on
|
127
|
+
ip tunnel tcp mss limit auto
|
128
|
+
tunnel enable 5
|
129
|
+
tunnel select 6
|
130
|
+
tunnel encapsulation l2tp
|
131
|
+
ipsec tunnel 106
|
132
|
+
ipsec sa policy 106 6 esp 3des-cbc sha-hmac
|
133
|
+
ipsec ike keepalive use 6 off
|
134
|
+
ipsec ike local address 6 172.27.1.253
|
135
|
+
ipsec ike nat-traversal 6 on
|
136
|
+
ipsec ike remote address 6 any
|
137
|
+
ipsec ike license-key use 6 on
|
138
|
+
l2tp tunnel disconnect time off
|
139
|
+
l2tp keepalive use on 10 3
|
140
|
+
l2tp keepalive log on
|
141
|
+
l2tp syslog on
|
142
|
+
ip tunnel tcp mss limit auto
|
143
|
+
tunnel enable 6
|
144
|
+
tunnel select 7
|
145
|
+
tunnel encapsulation l2tpv3
|
146
|
+
tunnel endpoint address 172.27.1.253 (拠点BのグローバルIP)
|
147
|
+
ipsec tunnel 107
|
148
|
+
ipsec sa policy 107 7 esp aes-cbc sha-hmac
|
149
|
+
ipsec ike keepalive log 7 on
|
150
|
+
ipsec ike keepalive use 7 on
|
151
|
+
ipsec ike local address 7 172.27.1.253
|
152
|
+
ipsec ike pre-shared-key 7 text (事前共有鍵①)
|
153
|
+
ipsec ike remote address 7 (拠点BのグローバルIP)
|
154
|
+
l2tp always-on on
|
155
|
+
l2tp hostname surluster
|
156
|
+
l2tp tunnel auth on (L2TP トンネル認証に用いるパスワード①)
|
157
|
+
l2tp tunnel disconnect time off
|
158
|
+
l2tp keepalive use on 60 3
|
159
|
+
l2tp keepalive log on
|
160
|
+
l2tp syslog on
|
161
|
+
l2tp local router-id 172.27.1.253
|
162
|
+
l2tp remote router-id 172.27.1.254
|
163
|
+
l2tp remote end-id A
|
164
|
+
tunnel enable 7
|
165
|
+
tunnel select 8
|
166
|
+
tunnel encapsulation l2tp
|
167
|
+
ipsec tunnel 108
|
168
|
+
ipsec sa policy 108 8 esp aes-cbc sha-hmac
|
169
|
+
ipsec ike keepalive use 8 off
|
170
|
+
ipsec ike nat-traversal 8 on
|
171
|
+
ipsec ike pre-shared-key 8 text (事前共有鍵)
|
172
|
+
ipsec ike remote address 8 any
|
173
|
+
l2tp tunnel disconnect time off
|
174
|
+
l2tp keepalive use on 10 3
|
175
|
+
l2tp keepalive log on
|
176
|
+
l2tp syslog on
|
177
|
+
ip tunnel tcp mss limit auto
|
178
|
+
tunnel enable 8
|
179
|
+
tunnel select 9
|
180
|
+
tunnel encapsulation l2tp
|
181
|
+
ipsec tunnel 109
|
182
|
+
ipsec sa policy 109 9 esp aes-cbc sha-hmac
|
183
|
+
ipsec ike keepalive use 9 off
|
184
|
+
ipsec ike nat-traversal 9 on
|
185
|
+
ipsec ike pre-shared-key 9 text (事前共有鍵)
|
186
|
+
ipsec ike remote address 9 any
|
187
|
+
l2tp tunnel disconnect time off
|
188
|
+
l2tp keepalive use on 10 3
|
189
|
+
l2tp keepalive log on
|
190
|
+
l2tp syslog on
|
191
|
+
ip tunnel tcp mss limit auto
|
192
|
+
tunnel enable 9
|
193
|
+
ip filter 10 reject * 172.27.2.0/24 * * *
|
194
|
+
ip filter 11 reject * 172.27.1.0/24 * * *
|
195
|
+
ip filter 99 pass * * * * *
|
196
|
+
ip filter 1010 reject * * udp,tcp 135 *
|
197
|
+
ip filter 1011 reject * * udp,tcp * 135
|
198
|
+
ip filter 1012 reject * * udp,tcp netbios_ns-netbios_ssn *
|
199
|
+
ip filter 1013 reject * * udp,tcp * netbios_ns-netbios_ssn
|
200
|
+
ip filter 1014 reject * * udp,tcp 445 *
|
201
|
+
ip filter 1015 reject * * udp,tcp * 445
|
202
|
+
ip filter 1020 reject 172.27.1.0/24 *
|
203
|
+
ip filter 1030 pass * 172.27.1.0/24 icmp
|
204
|
+
ip filter 1040 pass * 172.27.1.253 udp * 500
|
205
|
+
ip filter 1041 pass * 172.27.1.253 udp * 4500
|
206
|
+
ip filter 1042 pass * 172.27.1.253 esp
|
207
|
+
ip filter 1043 pass * 172.27.1.254 udp * 500
|
208
|
+
ip filter 1044 pass * 172.27.1.254 udp * 4500
|
209
|
+
ip filter 1045 pass * 172.27.1.254 esp
|
210
|
+
ip filter 2000 reject * *
|
211
|
+
ip filter 3000 pass * *
|
212
|
+
ip filter dynamic 100 * * ftp
|
213
|
+
ip filter dynamic 101 * * www
|
214
|
+
ip filter dynamic 102 * * domain
|
215
|
+
ip filter dynamic 103 * * smtp
|
216
|
+
ip filter dynamic 104 * * pop3
|
217
|
+
ip filter dynamic 105 * * imap
|
218
|
+
ip filter dynamic 106 * * netmeeting
|
219
|
+
ip filter dynamic 107 * * tcp
|
220
|
+
ip filter dynamic 108 * * udp
|
221
|
+
ip filter dynamic 109 * * submission
|
222
|
+
nat descriptor type 1 masquerade
|
223
|
+
nat descriptor address outer 1 (拠点AのグローバルIP)
|
224
|
+
nat descriptor masquerade static 1 1 172.27.1.253 esp
|
225
|
+
nat descriptor masquerade static 1 2 172.27.1.253 udp 500
|
226
|
+
nat descriptor masquerade static 1 3 172.27.1.253 udp 4500
|
227
|
+
ipsec auto refresh on
|
228
|
+
ipsec ike license-key 1 (ライセンスキー)
|
229
|
+
ipsec transport 1 101 udp 1701
|
230
|
+
ipsec transport 2 102 udp 1701
|
231
|
+
ipsec transport 3 103 udp 1701
|
232
|
+
ipsec transport 4 104 udp 1701
|
233
|
+
ipsec transport 5 105 udp 1701
|
234
|
+
ipsec transport 6 106 udp 1701
|
235
|
+
ipsec transport 7 107 udp 1701
|
236
|
+
ipsec transport 8 108 udp 1701
|
237
|
+
ipsec transport 9 109 udp 1701
|
238
|
+
dhcp service server
|
239
|
+
dhcp server rfc2131 compliant except remain-silent
|
240
|
+
dhcp scope 1 172.27.1.2-172.27.1.191/24
|
241
|
+
dns server (拠点AのDNS① 拠点AのDNS②)
|
242
|
+
dns private address spoof on
|
243
|
+
l2tp service on
|
244
|
+
httpd host any
|
245
|
+
dashboard accumulate traffic on
|