[index] AT-AR4000S-Cloud リファレンスマニュアル 5.5.3
WAN側物理インターフェース | eth1 |
WAN側(eth1)IPv6アドレス | リンクローカルアドレス |
LAN側(eth0)IPv6アドレス | DHCPv6 PDで取得したIPv6プレフィックスにもとづいて設定 |
LAN側(eth0)IPv4アドレス | 192.168.1.2/24(Web GUIアクセスなどの管理用) |
eth0 | 192.168.1.2/24 | 管理用IPアドレス |
eth1 | 未設定 |
Note構成が異なる場合はインターフェース名などを適宜読み替えてください。
interface eth1 no ipv6 nd accept-ra-pinfo no ipv6 nd accept-ra-default-routes ipv6 dhcp client pd IPoE default-route-to-server
interface eth0 ip address 192.168.1.2/24 no ipv6 nd suppress-ra no ipv6 nd accept-ra-pinfo ipv6 address IPoE ::1/64 eui64 ipv6 nd dns-server eth0
ipv6 forwarding
zone all network ipv6 ipv6 subnet ::/0
zone gui network ipv4 ip subnet 192.168.1.0/24
zone private_ipv6 network lan ipv6 subnet ::/0 interface eth0 host eth0 ipv6 address dynamic interface eth0
zone public_ipv6 network wan ipv6 subnet ::/0 interface eth1 host eth1 ipv6 address dynamic interface eth1
application dhcpv6 protocol udp dport 546 to 547
application icmpv6 protocol ipv6-icmp
firewall rule 10 permit any from gui to gui rule 20 permit dhcpv6 from all to all rule 30 permit icmpv6 from all to all rule 40 permit any from private_ipv6 to private_ipv6 rule 50 permit any from private_ipv6 to private_ipv6.lan.eth0 rule 60 permit any from private_ipv6 to public_ipv6 rule 70 permit any from private_ipv6.lan.eth0 to private_ipv6 rule 80 permit any from private_ipv6.lan.eth0 to public_ipv6 rule 90 permit any from public_ipv6.wan.eth1 to public_ipv6 protect
ip dns forwarding
end
copy running-config startup-config
」の書式で実行します。awplus# copy running-config startup-config ↓ Building configuration... [OK]
awplus# write memory ↓ Building configuration... [OK]
awplus(config)# log buffered level informational facility local5 ↓
awplus# show log | include Firewall ↓
! interface eth1 no ipv6 nd accept-ra-pinfo no ipv6 nd accept-ra-default-routes ipv6 dhcp client pd IPoE default-route-to-server ! interface eth0 ip address 192.168.1.2/24 no ipv6 nd suppress-ra no ipv6 nd accept-ra-pinfo ipv6 address IPoE ::1/64 eui64 ipv6 nd dns-server eth0 ! ipv6 forwarding ! zone all network ipv6 ipv6 subnet ::/0 ! zone gui network ipv4 ip subnet 192.168.1.0/24 ! zone private_ipv6 network lan ipv6 subnet ::/0 interface eth0 host eth0 ipv6 address dynamic interface eth0 ! zone public_ipv6 network wan ipv6 subnet ::/0 interface eth1 host eth1 ipv6 address dynamic interface eth1 ! application dhcpv6 protocol udp dport 546 to 547 ! application icmpv6 protocol ipv6-icmp ! firewall rule 10 permit any from gui to gui rule 20 permit dhcpv6 from all to all rule 30 permit icmpv6 from all to all rule 40 permit any from private_ipv6 to private_ipv6 rule 50 permit any from private_ipv6 to private_ipv6.lan.eth0 rule 60 permit any from private_ipv6 to public_ipv6 rule 70 permit any from private_ipv6.lan.eth0 to private_ipv6 rule 80 permit any from private_ipv6.lan.eth0 to public_ipv6 rule 90 permit any from public_ipv6.wan.eth1 to public_ipv6 protect ! ip dns forwarding ! end
(C) 2022 - 2023 アライドテレシスホールディングス株式会社
PN: 613-003066 Rev.F