[index] AT-AR3050S/AT-AR4050S/AT-AR4050S-5G コマンドリファレンス 5.5.3
(センター) |
(拠点) |
|
WAN側物理インターフェース | eth1 | eth1 |
WAN側(eth1)IPアドレス | 10.0.0.1/32 | 10.0.0.2/32 |
LAN側(vlan1)IPアドレス | 192.168.10.1/24 | 192.168.100.1/24 |
DNSサーバー | 192.168.11.100 | |
PACファイルサーバー待ち受けポート | 8080 |
no spanning-tree rstp enable
interface eth1 encapsulation ppp 0
interface ppp0 keepalive ppp username user@isp01 ppp password passwd01 ip address 10.0.0.1/32 ip tcp adjust-mss pmtu
interface vlan1 ip address 192.168.10.1/24
zone private network branch ip subnet 192.168.100.0/24 network ospf ip subnet 224.0.0.5/32 ip subnet 224.0.0.6/32 network proxy ip subnet 192.168.10.0/24 ip subnet 192.168.11.0/24 network tunnel_if ip subnet 172.16.100.0/30
zone public network wan ip subnet 0.0.0.0/0 interface ppp0 host routerA ip address 10.0.0.1 host routerB ip address 10.0.0.2
application proxy protocol tcp dport 3128
firewall rule 10 permit any from public.wan.routerA to public.wan.routerB rule 20 permit any from public.wan.routerB to public.wan.routerA rule 40 permit any from private.proxy to private.proxy rule 50 permit any from private.tunnel_if to private.tunnel_if rule 60 permit any from private.tunnel_if to private.ospf rule 70 permit dns from private.tunnel_if to private.proxy rule 80 permit any from private.proxy to private.ospf rule 90 permit proxy from private.branch to private.proxy rule 100 permit any from private to public protect
crypto isakmp key secret address 10.0.0.2
interface tunnel0 tunnel source 10.0.0.1 tunnel destination 10.0.0.2 tunnel protection ipsec tunnel mode ipsec ipv4 ip address 172.16.100.1/30
router ospf network 172.16.100.0/30 area 0.0.0.0 network 192.168.10.0/24 area 0.0.0.0 default-information originate
ip route 0.0.0.0/0 192.168.10.100 ip route 10.0.0.2/32 ppp0
end
no spanning-tree rstp enable
interface eth1 encapsulation ppp 0
interface ppp0 keepalive ppp username user@isp02 ppp password passwd02 ip address 10.0.0.2/32 ip tcp adjust-mss pmtu
interface vlan1 ip address 192.168.100.1/24
zone private network lan ip subnet 192.168.100.0/24 host vlan1 ip address 192.168.100.1 network ospf ip subnet 224.0.0.5/32 ip subnet 224.0.0.6/32 network proxy ip subnet 192.168.10.0/24 ip subnet 192.168.11.0/24 network tunnel ip subnet 0.0.0.0/0 interface tunnel0 network tunnel_if ip subnet 172.16.100.0/30
zone public network wan ip subnet 0.0.0.0/0 interface ppp0 host routerA ip address 10.0.0.1 host routerB ip address 10.0.0.2
application proxy protocol tcp dport 3128
firewall rule 10 permit any from private.tunnel_if to private.tunnel_if rule 20 permit any from private.tunnel_if to private.ospf rule 25 permit any from private.lan to private.ospf rule 30 permit any from public.wan.routerB to public.wan.routerA rule 40 permit any from public.wan.routerA to public.wan.routerB rule 50 permit proxy from private.lan to private.proxy rule 60 permit http from private.lan to URL_Offload.include_entries rule 70 permit https from private.lan to URL_Offload.include_entries rule 80 permit any from private.lan to private.lan.vlan1 rule 90 permit any from private.tunnel_if to private.tunnel protect
nat rule 10 masq any from private to public enable
crypto isakmp key secret address 10.0.0.1
interface tunnel0 tunnel source 10.0.0.2 tunnel destination 10.0.0.1 tunnel protection ipsec tunnel mode ipsec ipv4 ip address 172.16.100.2/30
url-offload endpoint-source WORLDWIDE type office365 url https://endpoints.office.com/endpoints/worldwide update-interval minutes 30 filter-endpoint include key required boolean true filter-entry exclude type ipv6 filter-entry exclude type url pac-file proxy-address 192.168.10.100:3128 pac-file http-server port 8080 service url-offload
policy-based-routing ip policy-route 10 to URL_Offload.include_entries nexthop ppp0 policy-based-routing enable
ip name-server 192.168.11.100
ip dhcp option 252 name wpad ascii
ip dhcp pool vlan1 network 192.168.100.0 255.255.255.0 range 192.168.100.10 192.168.100.200 dns-server 192.168.100.1 default-router 192.168.100.1 option wpad http://192.168.100.1:8080/wpad.dat
service dhcp-server
router ospf network 172.16.100.0/30 area 0.0.0.0 network 192.168.100.0/24 area 0.0.0.0
ip route 10.0.0.1/32 ppp0
ip dns forwarding
end
copy running-config startup-config
」の書式で実行します。awplus# copy running-config startup-config ↓ Building configuration... [OK]
awplus# write memory ↓ Building configuration... [OK]
awplus(config)# log buffered level informational facility local5 ↓
awplus# show log | include Firewall ↓
! no spanning-tree rstp enable ! interface eth1 encapsulation ppp 0 ! interface ppp0 keepalive ppp username user@isp01 ppp password passwd01 ip address 10.0.0.1/32 ip tcp adjust-mss pmtu ! interface vlan1 ip address 192.168.10.1/24 ! zone private network branch ip subnet 192.168.100.0/24 network ospf ip subnet 224.0.0.5/32 ip subnet 224.0.0.6/32 network proxy ip subnet 192.168.10.0/24 ip subnet 192.168.11.0/24 network tunnel_if ip subnet 172.16.100.0/30 ! zone public network wan ip subnet 0.0.0.0/0 interface ppp0 host routerA ip address 10.0.0.1 host routerB ip address 10.0.0.2 ! application proxy protocol tcp dport 3128 ! firewall rule 10 permit any from public.wan.routerA to public.wan.routerB rule 20 permit any from public.wan.routerB to public.wan.routerA rule 40 permit any from private.proxy to private.proxy rule 50 permit any from private.tunnel_if to private.tunnel_if rule 60 permit any from private.tunnel_if to private.ospf rule 70 permit dns from private.tunnel_if to private.proxy rule 80 permit any from private.proxy to private.ospf rule 90 permit proxy from private.branch to private.proxy rule 100 permit any from private to public protect ! crypto isakmp key secret address 10.0.0.2 ! interface tunnel0 tunnel source 10.0.0.1 tunnel destination 10.0.0.2 tunnel protection ipsec tunnel mode ipsec ipv4 ip address 172.16.100.1/30 ! router ospf network 172.16.100.0/30 area 0.0.0.0 network 192.168.10.0/24 area 0.0.0.0 default-information originate ! ip route 0.0.0.0/0 192.168.10.100 ip route 10.0.0.2/32 ppp0 ! end
! no spanning-tree rstp enable ! interface eth1 encapsulation ppp 0 ! interface ppp0 keepalive ppp username user@isp02 ppp password passwd02 ip address 10.0.0.2/32 ip tcp adjust-mss pmtu ! interface vlan1 ip address 192.168.100.1/24 ! zone private network lan ip subnet 192.168.100.0/24 host vlan1 ip address 192.168.100.1 network ospf ip subnet 224.0.0.5/32 ip subnet 224.0.0.6/32 network proxy ip subnet 192.168.10.0/24 ip subnet 192.168.11.0/24 network tunnel ip subnet 0.0.0.0/0 interface tunnel0 network tunnel_if ip subnet 172.16.100.0/30 ! zone public network wan ip subnet 0.0.0.0/0 interface ppp0 host routerA ip address 10.0.0.1 host routerB ip address 10.0.0.2 ! application proxy protocol tcp dport 3128 ! firewall rule 10 permit any from private.tunnel_if to private.tunnel_if rule 20 permit any from private.tunnel_if to private.ospf rule 25 permit any from private.lan to private.ospf rule 30 permit any from public.wan.routerB to public.wan.routerA rule 40 permit any from public.wan.routerA to public.wan.routerB rule 50 permit proxy from private.lan to private.proxy rule 60 permit http from private.lan to URL_Offload.include_entries rule 70 permit https from private.lan to URL_Offload.include_entries rule 80 permit any from private.lan to private.lan.vlan1 rule 90 permit any from private.tunnel_if to private.tunnel protect ! nat rule 10 masq any from private to public enable ! crypto isakmp key secret address 10.0.0.1 ! interface tunnel0 tunnel source 10.0.0.2 tunnel destination 10.0.0.1 tunnel protection ipsec tunnel mode ipsec ipv4 ip address 172.16.100.2/30 ! url-offload endpoint-source WORLDWIDE type office365 url https://endpoints.office.com/endpoints/worldwide update-interval minutes 30 filter-endpoint include key required boolean true filter-entry exclude type ipv6 filter-entry exclude type url pac-file proxy-address 192.168.10.100:3128 pac-file http-server port 8080 service url-offload ! policy-based-routing ip policy-route 10 to URL_Offload.include_entries nexthop ppp0 policy-based-routing enable ! ip name-server 192.168.11.100 ! ip dhcp option 252 name wpad ascii ! ip dhcp pool vlan1 network 192.168.100.0 255.255.255.0 range 192.168.100.10 192.168.100.200 dns-server 192.168.100.1 default-router 192.168.100.1 option wpad http://192.168.100.1:8080/wpad.dat ! service dhcp-server ! router ospf network 172.16.100.0/30 area 0.0.0.0 network 192.168.100.0/24 area 0.0.0.0 ! ip route 10.0.0.1/32 ppp0 ! ip dns forwarding ! end
(C) 2015 - 2023 アライドテレシスホールディングス株式会社
PN: 613-002107 Rev.AZ