[index] AT-TQ7403-R コマンドリファレンス 5.5.5
WAN側物理インターフェース | eth2 |
WAN側(eth2)IPv6アドレス | リンクローカルアドレス |
LAN側(vap1.0)IPv6アドレス | ルーター通知(RA)で取得したIPv6プレフィックスにもとづいて設定 |
WAN側(tunnel0)IPv4アドレス | MAPルール配信サーバーから取得した情報にもとづいて自動設定 |
IPv4グローバルアドレス | 203.0.113.1/32 |
アドレス解決用ホスト名 | 1234567890abcdefghijk |
Note(注1) 本設定例では例示用IPアドレス等を使用しており、実際に設定する値とは異なります。実際の設定時には、ユーザー毎に通知される各種情報をご使用ください。
NoteNDプロキシー機能は本構成に特化した機能です。本構成以外での動作はサポート対象外です。
awplus(config)# wireless ↓ awplus(config-wireless)# ap-profile local ↓ awplus(config-wireless-ap-prof)# radio 1 ↓ awplus(config-wireless-ap-prof-radio)# enable ↓ awplus(config-wireless-ap-prof-radio)# end ↓
awplus# wireless ap-configuration apply ap local ↓
Note本設定例では、ルーターとしての全体的な設定を示すため、無線機能に関してはデフォルト設定を利用した最小限の設定のみを示しています。
実際の運用にあたっては、「無線機能」章にある設定のポイントなどをご参照の上、SSID、セキュリティーなど要件にあわせた適切な設定を行ってから本手順(無線設定の適用)を実行してください。
wireless security 33 mode enhanced-open network 1 ssid allied24 network 17 ssid allied5 network 33 ssid allied6 security 33 ap-profile local radio 1 enable vap 0 network 1 radio 2 vap 0 network 17 radio 3 vap 0 network 33 ap local
interface eth2 ipv6 enable no ipv6 nd accept-ra-pinfo ipv6 nd proxy interface vap1.0
interface vap1.0 ip address 192.168.10.1/24 ipv6 address autoconfig eth2 no ipv6 nd suppress-ra ipv6 nd dns-server vap1.0
ipv6 forwarding
ip dhcp pool pool10 network 192.168.10.0 255.255.255.0 range 192.168.10.100 192.168.10.131 dns-server 192.168.10.1 default-router 192.168.10.1 lease 0 2 0
service dhcp-server
softwire-configuration NTT-COM method proprietary map-version draft upstream-interface vap1.0 vendor-name NTT-COM vendor-userid 1234567890abcdefghijk
interface tunnel0 tunnel softwire NTT-COM tunnel mode map-e ip tcp adjust-mss pmtu
ip route 0.0.0.0/0 tunnel0
zone ipv4-internal network dhcp ip subnet 0.0.0.0/0 interface vap1.0 network lan ip subnet 192.168.10.0/24 interface vap1.0
zone ipv4-internet network wan ip subnet 0.0.0.0/0 interface tunnel0 host nat ip address 203.0.113.1
zone ipv6-internal network lan ipv6 subnet ::/0 interface vap1.0 host vap1.0 ipv6 address dynamic interface vap1.0
zone ipv6-internet network wan ipv6 subnet ::/0 interface eth2 host eth2 ipv6 address dynamic interface eth2
application dhcpv4 protocol udp dport 67 to 68
application dhcpv6 protocol udp dport 546 to 547
application icmpv6 protocol ipv6-icmp
firewall rule 10 permit dhcpv4 from ipv4-internal.dhcp to ipv4-internal.dhcp rule 20 permit any from ipv4-internal.lan to ipv4-internal.lan rule 30 permit any from ipv4-internal.lan to ipv4-internet rule 40 permit any from ipv4-internet.wan.nat to ipv4-internet rule 100 permit any from ipv6-internal to ipv6-internal rule 110 permit any from ipv6-internal to ipv6-internet rule 120 permit any from ipv6-internal.lan.vap1.0 to ipv6-internet rule 130 permit any from ipv6-internet.wan.eth2 to ipv6-internet rule 140 permit icmpv6 from ipv6-internet to ipv6-internal.lan.vap1.0 rule 150 permit dhcpv6 from ipv6-internet to ipv6-internet.wan.eth2 protect
nat rule 10 masq any from ipv4-internal to ipv4-internet enable
ip dns forwarding
end
copy running-config startup-config
」の書式で実行します。awplus# copy running-config startup-config ↓ Building configuration... [OK]
awplus# write memory ↓ Building configuration... [OK]
awplus(config)# log buffered level informational facility local5 ↓
awplus# show log | include Firewall ↓
! interface eth2 ipv6 enable no ipv6 nd accept-ra-pinfo ipv6 nd proxy interface vap1.0 ! interface vap1.0 ip address 192.168.10.1/24 ipv6 address autoconfig eth2 no ipv6 nd suppress-ra ipv6 nd dns-server vap1.0 ! ipv6 forwarding ! ip dhcp pool pool10 network 192.168.10.0 255.255.255.0 range 192.168.10.100 192.168.10.131 dns-server 192.168.10.1 default-router 192.168.10.1 lease 0 2 0 ! service dhcp-server ! softwire-configuration NTT-COM method proprietary map-version draft upstream-interface vap1.0 vendor-name NTT-COM vendor-userid 1234567890abcdefghijk ! interface tunnel0 tunnel softwire NTT-COM tunnel mode map-e ip tcp adjust-mss pmtu ! ip route 0.0.0.0/0 tunnel0 ! zone ipv4-internal network dhcp ip subnet 0.0.0.0/0 interface vap1.0 network lan ip subnet 192.168.10.0/24 interface vap1.0 ! zone ipv4-internet network wan ip subnet 0.0.0.0/0 interface tunnel0 host nat ip address 203.0.113.1 ! zone ipv6-internal network lan ipv6 subnet ::/0 interface vap1.0 host vap1.0 ipv6 address dynamic interface vap1.0 ! zone ipv6-internet network wan ipv6 subnet ::/0 interface eth2 host eth2 ipv6 address dynamic interface eth2 ! application dhcpv4 protocol udp dport 67 to 68 ! application dhcpv6 protocol udp dport 546 to 547 ! application icmpv6 protocol ipv6-icmp ! firewall rule 10 permit dhcpv4 from ipv4-internal.dhcp to ipv4-internal.dhcp rule 20 permit any from ipv4-internal.lan to ipv4-internal.lan rule 30 permit any from ipv4-internal.lan to ipv4-internet rule 40 permit any from ipv4-internet.wan.nat to ipv4-internet rule 100 permit any from ipv6-internal to ipv6-internal rule 110 permit any from ipv6-internal to ipv6-internet rule 120 permit any from ipv6-internal.lan.vap1.0 to ipv6-internet rule 130 permit any from ipv6-internet.wan.eth2 to ipv6-internet rule 140 permit icmpv6 from ipv6-internet to ipv6-internal.lan.vap1.0 rule 150 permit dhcpv6 from ipv6-internet to ipv6-internet.wan.eth2 protect ! nat rule 10 masq any from ipv4-internal to ipv4-internet enable ! ip dns forwarding ! end
(C) 2024-2025 アライドテレシスホールディングス株式会社
PN: 613-003360 Rev.C