[index] AT-AR3050S/AT-AR4050S/AT-AR4050S-5G コマンドリファレンス 5.5.3
ISP接続用ユーザー名 | user@ispA | user@ispB |
ISP接続用パスワード | isppasswdA | isppasswdB |
PPPoEサービス名 | 指定なし | 指定なし |
使用できるアドレス | 10.0.0.1/32 | 10.1.1.1/32 |
接続形態 | 端末型(アドレス1個固定) | 端末型(アドレス1個固定) |
WAN側物理インターフェース | eth1 | eth1 |
WAN側(ppp0)IPアドレス | 10.0.0.1/32 | 10.1.1.1/32 |
LAN側(vlan10)IPアドレス | 192.168.10.1/24 | 192.168.30.1/24 |
LAN側(vlan20)IPアドレス | 192.168.20.1/24 | 192.168.40.1/24 |
IKEバージョン・交換モード | ||
アルゴリズム | ||
アルゴリズム |
256 | 576 | |
10 | 10 | |
50 | 32 | |
127 | 127 | |
20 | 2 | |
無効 | 無効 |
no spanning-tree rstp enable
interface eth1 encapsulation ppp 0
interface ppp0 keepalive ppp username user@ispA ppp password isppasswdA ip address 10.0.0.1/32 ip tcp adjust-mss pmtu
vlan database vlan 10,20 state enable
interface port1.0.1-1.0.4 switchport switchport mode access switchport access vlan 10
interface port1.0.5-1.0.8 switchport switchport mode access switchport access vlan 20
interface vlan10 ip address 192.168.10.1/24
interface vlan20 ip address 192.168.20.1/24
zone private network lan ip subnet 0.0.0.0/0 interface tunnel1 ip subnet 172.16.0.0/30 ip subnet 192.168.10.0/24 ip subnet 192.168.20.0/24 network ospf ip subnet 224.0.0.5/32 ip subnet 224.0.0.6/32
zone public network wan ip subnet 0.0.0.0/0 interface ppp0 host ppp0 ip address 10.0.0.1
zone qos network ppp0 ip subnet 0.0.0.0/0 interface ppp0 network tunnel1 ip subnet 0.0.0.0/0 interface tunnel1 network vlan10 ip subnet 192.168.10.0/24 interface vlan10 network vlan20 ip subnet 192.168.20.0/24 interface vlan20
application esp protocol 50
application isakmp protocol udp dport 500
application ospf protocol 89
application tcp protocol tcp sport any dport any
application udp protocol udp sport any dport any
firewall rule 10 permit any from private to private rule 20 permit any from private to public rule 30 permit isakmp from public.wan.ppp0 to public rule 40 permit isakmp from public to public.wan.ppp0 rule 50 permit esp from public.wan.ppp0 to public rule 60 permit esp from public to public.wan.ppp0 protect
nat rule 10 masq any from private to public enable
crypto ipsec profile ipsec1 transform 1 protocol esp integrity SHA256 encryption AES128
crypto isakmp profile isakmp1 version 1 mode main transform 1 integrity SHA256 encryption AES128 group 15
crypto isakmp key secret address 10.1.1.1
crypto isakmp peer address 10.1.1.1 profile isakmp1
interface tunnel1 tunnel source ppp0 tunnel destination 10.1.1.1 tunnel protection ipsec profile ipsec1 tunnel mode ipsec ipv4 ip address 172.16.0.1/30 ip tcp adjust-mss 1260 mtu 1300
traffic-control red-curve TEST avpkt 256 max 50 probability 20 policy MYQOS priority class HIGH priority-level 11 class MED priority-level 10 class LOW priority-level 9 sub-class-policy wrr sub-class A weight 6 red-curve TEST sub-class B weight 3 red-curve TEST sub-class C weight 1 red-curve default rule 10 match ospf to qos.tunnel1 policy MYQOS.HIGH rule 20 match isakmp to qos.ppp0 policy MYQOS.MED rule 30 match esp to qos.ppp0 policy MYQOS.MED rule 40 match tcp from qos.vlan10 to qos.tunnel1 policy MYQOS.LOW.A rule 50 match tcp from qos.vlan20 to qos.tunnel1 policy MYQOS.LOW.B rule 60 match udp from qos.vlan10 to qos.tunnel1 policy MYQOS.LOW.C interface ppp0 virtual-bandwidth 100mbit interface tunnel1 virtual-bandwidth 70mbit traffic-control enable
router ospf ospf router-id 0.0.0.1 network 172.16.0.0/30 area 0 network 192.168.10.0/24 area 0 network 192.168.20.0/24 area 0
ip route 0.0.0.0/0 ppp0
end
no spanning-tree rstp enable
interface eth1 encapsulation ppp 0
interface ppp0 keepalive ppp username user@ispB ppp password isppasswdB ip address 10.1.1.1/32 ip tcp adjust-mss pmtu
vlan database vlan 10,20 state enable
interface port1.0.1-1.0.4 switchport switchport mode access switchport access vlan 10
interface port1.0.5-1.0.8 switchport switchport mode access switchport access vlan 20
interface vlan10 ip address 192.168.30.1/24
interface vlan20 ip address 192.168.40.1/24
zone private network lan ip subnet 0.0.0.0/0 interface tunnel1 ip subnet 172.16.0.0/30 ip subnet 192.168.30.0/24 ip subnet 192.168.40.0/24 network ospf ip subnet 224.0.0.5/32 ip subnet 224.0.0.6/32
zone public network wan ip subnet 0.0.0.0/0 interface ppp0 host ppp0 ip address 10.1.1.1
zone qos network ppp0 ip subnet 0.0.0.0/0 interface ppp0 network tunnel1 ip subnet 0.0.0.0/0 interface tunnel1 network vlan10 ip subnet 192.168.30.0/24 interface vlan10 network vlan20 ip subnet 192.168.40.0/24 interface vlan20
application esp protocol 50
application isakmp protocol udp dport 500
application ospf protocol 89
application tcp protocol tcp sport any dport any
application udp protocol udp sport any dport any
firewall rule 10 permit any from private to private rule 20 permit any from private to public rule 30 permit isakmp from public.wan.ppp0 to public rule 40 permit isakmp from public to public.wan.ppp0 rule 50 permit esp from public.wan.ppp0 to public rule 60 permit esp from public to public.wan.ppp0 protect
nat rule 10 masq any from private to public enable
crypto ipsec profile ipsec1 transform 1 protocol esp integrity SHA256 encryption AES128
crypto isakmp profile isakmp1 version 1 mode main transform 1 integrity SHA256 encryption AES128 group 15
crypto isakmp key secret address 10.0.0.1
crypto isakmp peer address 10.0.0.1 profile isakmp1
interface tunnel1 tunnel source ppp0 tunnel destination 10.0.0.1 tunnel protection ipsec profile ipsec1 tunnel mode ipsec ipv4 ip address 172.16.0.2/30 ip tcp adjust-mss 1260 mtu 1300
traffic-control red-curve TEST avpkt 256 max 50 probability 20 policy MYQOS priority class HIGH priority-level 11 class MED priority-level 10 class LOW priority-level 9 sub-class-policy wrr sub-class A weight 6 red-curve TEST sub-class B weight 3 red-curve TEST sub-class C weight 1 red-curve default rule 10 match ospf to qos.tunnel1 policy MYQOS.HIGH rule 20 match isakmp to qos.ppp0 policy MYQOS.MED rule 30 match esp to qos.ppp0 policy MYQOS.MED rule 40 match tcp from qos.vlan10 to qos.tunnel1 policy MYQOS.LOW.A rule 50 match tcp from qos.vlan20 to qos.tunnel1 policy MYQOS.LOW.B rule 60 match udp from qos.vlan10 to qos.tunnel1 policy MYQOS.LOW.C interface ppp0 virtual-bandwidth 100mbit interface tunnel1 virtual-bandwidth 70mbit traffic-control enable
router ospf ospf router-id 0.0.0.2 network 172.16.0.0/30 area 0.0.0.0 network 192.168.30.0/24 area 0.0.0.0 network 192.168.40.0/24 area 0.0.0.0
ip route 0.0.0.0/0 ppp0
end
copy running-config startup-config
」の書式で実行します。awplus# copy running-config startup-config ↓ Building configuration... [OK]
awplus# write memory ↓ Building configuration... [OK]
awplus(config)# log buffered level informational facility local5 ↓
awplus# show log | include Firewall ↓
! no spanning-tree rstp enable ! interface eth1 encapsulation ppp 0 ! interface ppp0 keepalive ppp username user@ispA ppp password isppasswdA ip address 10.0.0.1/32 ip tcp adjust-mss pmtu ! vlan database vlan 10,20 state enable ! interface port1.0.1-1.0.4 switchport switchport mode access switchport access vlan 10 ! interface port1.0.5-1.0.8 switchport switchport mode access switchport access vlan 20 ! interface vlan10 ip address 192.168.10.1/24 ! interface vlan20 ip address 192.168.20.1/24 ! zone private network lan ip subnet 0.0.0.0/0 interface tunnel1 ip subnet 172.16.0.0/30 ip subnet 192.168.10.0/24 ip subnet 192.168.20.0/24 network ospf ip subnet 224.0.0.5/32 ip subnet 224.0.0.6/32 ! zone public network wan ip subnet 0.0.0.0/0 interface ppp0 host ppp0 ip address 10.0.0.1 ! zone qos network ppp0 ip subnet 0.0.0.0/0 interface ppp0 network tunnel1 ip subnet 0.0.0.0/0 interface tunnel1 network vlan10 ip subnet 192.168.10.0/24 interface vlan10 network vlan20 ip subnet 192.168.20.0/24 interface vlan20 ! application esp protocol 50 ! application isakmp protocol udp dport 500 ! application ospf protocol 89 ! application tcp protocol tcp sport any dport any ! application udp protocol udp sport any dport any ! firewall rule 10 permit any from private to private rule 20 permit any from private to public rule 30 permit isakmp from public.wan.ppp0 to public rule 40 permit isakmp from public to public.wan.ppp0 rule 50 permit esp from public.wan.ppp0 to public rule 60 permit esp from public to public.wan.ppp0 protect ! nat rule 10 masq any from private to public enable ! crypto ipsec profile ipsec1 transform 1 protocol esp integrity SHA256 encryption AES128 ! crypto isakmp profile isakmp1 version 1 mode main transform 1 integrity SHA256 encryption AES128 group 15 ! crypto isakmp key secret address 10.1.1.1 ! crypto isakmp peer address 10.1.1.1 profile isakmp1 ! interface tunnel1 tunnel source ppp0 tunnel destination 10.1.1.1 tunnel protection ipsec profile ipsec1 tunnel mode ipsec ipv4 ip address 172.16.0.1/30 ip tcp adjust-mss 1260 mtu 1300 ! traffic-control red-curve TEST avpkt 256 max 50 probability 20 policy MYQOS priority class HIGH priority-level 11 class MED priority-level 10 class LOW priority-level 9 sub-class-policy wrr sub-class A weight 6 red-curve TEST sub-class B weight 3 red-curve TEST sub-class C weight 1 red-curve default rule 10 match ospf to qos.tunnel1 policy MYQOS.HIGH rule 20 match isakmp to qos.ppp0 policy MYQOS.MED rule 30 match esp to qos.ppp0 policy MYQOS.MED rule 40 match tcp from qos.vlan10 to qos.tunnel1 policy MYQOS.LOW.A rule 50 match tcp from qos.vlan20 to qos.tunnel1 policy MYQOS.LOW.B rule 60 match udp from qos.vlan10 to qos.tunnel1 policy MYQOS.LOW.C interface ppp0 virtual-bandwidth 100mbit interface tunnel1 virtual-bandwidth 70mbit traffic-control enable ! router ospf ospf router-id 0.0.0.1 network 172.16.0.0/30 area 0 network 192.168.10.0/24 area 0 network 192.168.20.0/24 area 0 ! ip route 0.0.0.0/0 ppp0 ! end
! no spanning-tree rstp enable ! interface eth1 encapsulation ppp 0 ! interface ppp0 keepalive ppp username user@ispB ppp password isppasswdB ip address 10.1.1.1/32 ip tcp adjust-mss pmtu ! vlan database vlan 10,20 state enable ! interface port1.0.1-1.0.4 switchport switchport mode access switchport access vlan 10 ! interface port1.0.5-1.0.8 switchport switchport mode access switchport access vlan 20 ! interface vlan10 ip address 192.168.30.1/24 ! interface vlan20 ip address 192.168.40.1/24 ! zone private network lan ip subnet 0.0.0.0/0 interface tunnel1 ip subnet 172.16.0.0/30 ip subnet 192.168.30.0/24 ip subnet 192.168.40.0/24 network ospf ip subnet 224.0.0.5/32 ip subnet 224.0.0.6/32 ! zone public network wan ip subnet 0.0.0.0/0 interface ppp0 host ppp0 ip address 10.1.1.1 ! zone qos network ppp0 ip subnet 0.0.0.0/0 interface ppp0 network tunnel1 ip subnet 0.0.0.0/0 interface tunnel1 network vlan10 ip subnet 192.168.30.0/24 interface vlan10 network vlan20 ip subnet 192.168.40.0/24 interface vlan20 ! application esp protocol 50 ! application isakmp protocol udp dport 500 ! application ospf protocol 89 ! application tcp protocol tcp sport any dport any ! application udp protocol udp sport any dport any ! firewall rule 10 permit any from private to private rule 20 permit any from private to public rule 30 permit isakmp from public.wan.ppp0 to public rule 40 permit isakmp from public to public.wan.ppp0 rule 50 permit esp from public.wan.ppp0 to public rule 60 permit esp from public to public.wan.ppp0 protect ! nat rule 10 masq any from private to public enable ! crypto ipsec profile ipsec1 transform 1 protocol esp integrity SHA256 encryption AES128 ! crypto isakmp profile isakmp1 version 1 mode main transform 1 integrity SHA256 encryption AES128 group 15 ! crypto isakmp key secret address 10.0.0.1 ! crypto isakmp peer address 10.0.0.1 profile isakmp1 ! interface tunnel1 tunnel source ppp0 tunnel destination 10.0.0.1 tunnel protection ipsec profile ipsec1 tunnel mode ipsec ipv4 ip address 172.16.0.2/30 ip tcp adjust-mss 1260 mtu 1300 ! traffic-control red-curve TEST avpkt 256 max 50 probability 20 policy MYQOS priority class HIGH priority-level 11 class MED priority-level 10 class LOW priority-level 9 sub-class-policy wrr sub-class A weight 6 red-curve TEST sub-class B weight 3 red-curve TEST sub-class C weight 1 red-curve default rule 10 match ospf to qos.tunnel1 policy MYQOS.HIGH rule 20 match isakmp to qos.ppp0 policy MYQOS.MED rule 30 match esp to qos.ppp0 policy MYQOS.MED rule 40 match tcp from qos.vlan10 to qos.tunnel1 policy MYQOS.LOW.A rule 50 match tcp from qos.vlan20 to qos.tunnel1 policy MYQOS.LOW.B rule 60 match udp from qos.vlan10 to qos.tunnel1 policy MYQOS.LOW.C interface ppp0 virtual-bandwidth 100mbit interface tunnel1 virtual-bandwidth 70mbit traffic-control enable ! router ospf ospf router-id 0.0.0.2 network 172.16.0.0/30 area 0.0.0.0 network 192.168.30.0/24 area 0.0.0.0 network 192.168.40.0/24 area 0.0.0.0 ! ip route 0.0.0.0/0 ppp0 ! end
(C) 2015 - 2023 アライドテレシスホールディングス株式会社
PN: 613-002107 Rev.AY