[index] AT-AR4000S-Cloud リファレンスマニュアル 5.5.3
(本製品) |
(AR4050S) |
|
WAN側物理インターフェース | eth1 | eth1 |
WAN側(eth1)IPv6アドレス | 自動設定(SLAAC) | 自動設定(SLAAC) |
LAN側(eth0/vlan1)IPアドレス | 192.168.10.1/24 | 192.168.20.1/24 |
IKEバージョン | ||
ローカルID | sample1.i.open.ad.jp | sample2.i.open.ad.jp |
リモートID | sample2.i.open.ad.jp | sample1.i.open.ad.jp |
更新専用URL* | http://ddnsapi-v6.open.ad.jp/api/renew/?ABCDEFGHIJKLMNOPQR | http://ddnsapi-v6.open.ad.jp/api/renew/?RQPONMLKJIHGFEDCBA |
ホスト名(FQDN) | sample1.i.open.ad.jp | sample2.i.open.ad.jp |
* ルーターが取得したIPv6アドレスを「OPEN IPv6 ダイナミック DNS for フレッツ・光ネクスト」サービスに登録したホスト名(FQDN)と関連付けるには、「専用更新URL」を使用します。 * ルーターが使用するホスト名(FQDN)や専用更新URLは、あらかじめ取得してあるものとします。 |
eth0 | 192.168.10.1/24 | 管理用IPアドレス |
eth1 | 未設定 |
Note構成が異なる場合はインターフェース名などを適宜読み替えてください。
ddns enable
?
」をCLIから入力するには、Ctrl/V
キーを入力してから ?
を入力してください。単に ?
を入力するとCLIヘルプが表示されてしまうためご注意ください。ddns-update-method openddns update-url http://ddnsapi-v6.open.ad.jp/api/renew/?ABCDEFGHIJKLMNOPQR update-interval 1 suppress-ipv4-updates
interface eth1 ipv6 enable ipv6 ddns-update-method openddns
interface eth0 ip address 192.168.10.1/24
ipv6 forwarding
zone private_ipv4 network lan ip subnet 172.16.0.0/30 ip subnet 192.168.0.0/16
zone external_ipv6 network wan ipv6 subnet ::/0 interface eth1 host eth1 ipv6 address dynamic interface eth1
application dhcpv6 protocol udp dport 546 to 547
application esp protocol 50
application gre protocol 47
application icmpv6 protocol ipv6-icmp
application isakmp protocol udp dport 500
firewall rule 10 permit any from external_ipv6.wan.eth1 to external_ipv6 rule 20 permit isakmp from external_ipv6 to external_ipv6.wan.eth1 rule 30 permit esp from external_ipv6 to external_ipv6.wan.eth1 rule 40 permit gre from external_ipv6 to external_ipv6.wan.eth1 rule 50 permit dhcpv6 from external_ipv6 to external_ipv6.wan.eth1 rule 60 permit icmpv6 from external_ipv6 to external_ipv6.wan.eth1 rule 100 permit any from private_ipv4 to private_ipv4 protect
crypto isakmp key secret hostname sample2.i.open.ad.jp
interface tunnel0 tunnel source eth1 tunnel destination sample2.i.open.ad.jp tunnel local name sample1.i.open.ad.jp tunnel remote name sample2.i.open.ad.jp tunnel protection ipsec tunnel mode gre ipv6 ip address 172.16.0.1/30 ip tcp adjust-mss 1366
ip route 192.168.20.0/24 tunnel0
end
no spanning-tree rstp enable
ddns enable
?
」をCLIから入力するには、Ctrl/V
キーを入力してから ?
を入力してください。単に ?
を入力するとCLIヘルプが表示されてしまうためご注意ください。ddns-update-method openddns update-url http://ddnsapi-v6.open.ad.jp/api/renew/?RQPONMLKJIHGFEDCBA update-interval 1 suppress-ipv4-updates
interface eth1 ipv6 enable ipv6 ddns-update-method openddns
interface vlan1 ip address 192.168.20.1/24
ipv6 forwarding
zone private_ipv4 network lan ip subnet 172.16.0.0/24 ip subnet 192.168.0.0/16
zone external_ipv6 network wan ipv6 subnet ::/0 interface eth1 host eth1 ipv6 address dynamic interface eth1
application dhcpv6 protocol udp dport 546 to 547
application esp protocol 50
application gre protocol 47
application icmpv6 protocol ipv6-icmp
application isakmp protocol udp dport 500
firewall rule 10 permit any from external_ipv6.wan.eth1 to external_ipv6 rule 20 permit isakmp from external_ipv6 to external_ipv6.wan.eth1 rule 30 permit esp from external_ipv6 to external_ipv6.wan.eth1 rule 40 permit gre from external_ipv6 to external_ipv6.wan.eth1 rule 50 permit dhcpv6 from external_ipv6 to external_ipv6.wan.eth1 rule 60 permit icmpv6 from external_ipv6 to external_ipv6.wan.eth1 rule 100 permit any from private_ipv4 to private_ipv4 protect
crypto isakmp key secret hostname sample1.i.open.ad.jp
interface tunnel0 tunnel source eth1 tunnel destination sample1.i.open.ad.jp tunnel local name sample2.i.open.ad.jp tunnel remote name sample1.i.open.ad.jp tunnel protection ipsec tunnel mode gre ipv6 ip address 172.16.0.2/30 ip tcp adjust-mss 1366
ip route 192.168.10.0/24 tunnel0
end
copy running-config startup-config
」の書式で実行します。awplus# copy running-config startup-config ↓ Building configuration... [OK]
awplus# write memory ↓ Building configuration... [OK]
awplus(config)# log buffered level informational facility local5 ↓
awplus# show log | include Firewall ↓
! ddns enable ! ddns-update-method openddns update-url http://ddnsapi-v6.open.ad.jp/api/renew/?ABCDEFGHIJKLMNOPQR update-interval 1 suppress-ipv4-updates ! interface eth1 ipv6 enable ipv6 ddns-update-method openddns ! interface eth0 ip address 192.168.10.1/24 ! ipv6 forwarding ! zone private_ipv4 network lan ip subnet 172.16.0.0/30 ip subnet 192.168.0.0/16 ! zone external_ipv6 network wan ipv6 subnet ::/0 interface eth1 host eth1 ipv6 address dynamic interface eth1 ! application dhcpv6 protocol udp dport 546 to 547 ! application esp protocol 50 ! application gre protocol 47 ! application icmpv6 protocol ipv6-icmp ! application isakmp protocol udp dport 500 ! firewall rule 10 permit any from external_ipv6.wan.eth1 to external_ipv6 rule 20 permit isakmp from external_ipv6 to external_ipv6.wan.eth1 rule 30 permit esp from external_ipv6 to external_ipv6.wan.eth1 rule 40 permit gre from external_ipv6 to external_ipv6.wan.eth1 rule 50 permit dhcpv6 from external_ipv6 to external_ipv6.wan.eth1 rule 60 permit icmpv6 from external_ipv6 to external_ipv6.wan.eth1 rule 100 permit any from private_ipv4 to private_ipv4 protect ! crypto isakmp key secret hostname sample2.i.open.ad.jp ! interface tunnel0 tunnel source eth1 tunnel destination sample2.i.open.ad.jp tunnel local name sample1.i.open.ad.jp tunnel remote name sample2.i.open.ad.jp tunnel protection ipsec tunnel mode gre ipv6 ip address 172.16.0.1/30 ip tcp adjust-mss 1366 ! ip route 192.168.20.0/24 tunnel0 ! end
! no spanning-tree rstp enable ! ddns enable ! ddns-update-method openddns update-url http://ddnsapi-v6.open.ad.jp/api/renew/?RQPONMLKJIHGFEDCBA update-interval 1 suppress-ipv4-updates ! interface eth1 ipv6 enable ipv6 ddns-update-method openddns ! interface vlan1 ip address 192.168.20.1/24 ! ipv6 forwarding ! zone private_ipv4 network lan ip subnet 172.16.0.0/24 ip subnet 192.168.0.0/16 ! zone external_ipv6 network wan ipv6 subnet ::/0 interface eth1 host eth1 ipv6 address dynamic interface eth1 ! application dhcpv6 protocol udp dport 546 to 547 ! application esp protocol 50 ! application gre protocol 47 ! application icmpv6 protocol ipv6-icmp ! application isakmp protocol udp dport 500 ! firewall rule 10 permit any from external_ipv6.wan.eth1 to external_ipv6 rule 20 permit isakmp from external_ipv6 to external_ipv6.wan.eth1 rule 30 permit esp from external_ipv6 to external_ipv6.wan.eth1 rule 40 permit gre from external_ipv6 to external_ipv6.wan.eth1 rule 50 permit dhcpv6 from external_ipv6 to external_ipv6.wan.eth1 rule 60 permit icmpv6 from external_ipv6 to external_ipv6.wan.eth1 rule 100 permit any from private_ipv4 to private_ipv4 protect ! crypto isakmp key secret hostname sample1.i.open.ad.jp ! interface tunnel0 tunnel source eth1 tunnel destination sample1.i.open.ad.jp tunnel local name sample2.i.open.ad.jp tunnel remote name sample1.i.open.ad.jp tunnel protection ipsec tunnel mode gre ipv6 ip address 172.16.0.2/30 ip tcp adjust-mss 1366 ! ip route 192.168.10.0/24 tunnel0 ! end
(C) 2022 - 2023 アライドテレシスホールディングス株式会社
PN: 613-003066 Rev.F