[index] AT-AR2050V/AT-AR3050S/AT-AR4050S コマンドリファレンス 5.4.6
WAN側物理インターフェース | eth1 |
WAN側(eth1)IPv6アドレス | リンクローカルアドレス |
LAN側(vlan1)IPv6アドレス | DHCPv6 PDで取得したIPv6プレフィックスにもとづいて設定 |
no spanning-tree rstp enable |
interface eth1 no ipv6 nd accept-ra-default-routes ipv6 dhcp client pd IPoE default-route-to-server |
ipv6 dhcp pool IPoE-vlan1 dns-server interface vlan1 |
interface vlan1 ipv6 enable no ipv6 nd suppress-ra ipv6 nd other-config-flag ipv6 address IPoE ::1/64 ipv6 dhcp server IPoE-vlan1 |
ipv6 forwarding |
zone ngn network wan_ipv6 ipv6 subnet ::/0 interface eth1 host eth1 ipv6 address dynamic interface eth1 |
zone private_ipv6 network lan ipv6 subnet ::/0 interface vlan1 host vlan1 ipv6 address dynamic interface vlan1 |
application dhcpv6-r protocol udp dport 546 |
application dhcpv6-s protocol udp sport 546 |
application icmpv6 protocol ipv6-icmp |
firewall rule 10 permit any from private_ipv6 to private_ipv6 rule 20 permit any from private_ipv6 to ngn rule 30 permit dns from private_ipv6.lan.vlan1 to ngn rule 40 permit icmpv6 from private_ipv6.lan.vlan1 to ngn rule 50 permit icmpv6 from ngn to private_ipv6.lan.vlan1 rule 60 permit dhcpv6-s from ngn.wan_ipv6.eth1 to ngn rule 70 permit dhcpv6-r from ngn to ngn.wan_ipv6.eth1 protect |
ip dns forwarding |
end |
copy running-config startup-config
」の書式で実行します。awplus# copy running-config startup-config ↓ Building configuration... [OK] |
awplus# write memory ↓ Building configuration... [OK] |
awplus(config)# log buffered level informational program kernel msgtext Firewall ↓ |
awplus# show log | include firewall ↓ |
! no spanning-tree rstp enable ! interface eth1 no ipv6 nd accept-ra-default-routes ipv6 dhcp client pd IPoE default-route-to-server ! ipv6 dhcp pool IPoE-vlan1 dns-server interface vlan1 ! interface vlan1 ipv6 enable no ipv6 nd suppress-ra ipv6 nd other-config-flag ipv6 address IPoE ::1/64 ipv6 dhcp server IPoE-vlan1 ! ipv6 forwarding ! zone ngn network wan_ipv6 ipv6 subnet ::/0 interface eth1 host eth1 ipv6 address dynamic interface eth1 ! zone private_ipv6 network lan ipv6 subnet ::/0 interface vlan1 host vlan1 ipv6 address dynamic interface vlan1 ! application dhcpv6-r protocol udp dport 546 ! application dhcpv6-s protocol udp sport 546 ! application icmpv6 protocol ipv6-icmp ! firewall rule 10 permit any from private_ipv6 to private_ipv6 rule 20 permit any from private_ipv6 to ngn rule 30 permit dns from private_ipv6.lan.vlan1 to ngn rule 40 permit icmpv6 from private_ipv6.lan.vlan1 to ngn rule 50 permit icmpv6 from ngn to private_ipv6.lan.vlan1 rule 60 permit dhcpv6-s from ngn.wan_ipv6.eth1 to ngn rule 70 permit dhcpv6-r from ngn to ngn.wan_ipv6.eth1 protect ! ip dns forwarding ! end |
(C) 2015 - 2016 アライドテレシスホールディングス株式会社
PN: 613-002107 Rev.L