<前頁 次頁> << >> ↓ 目次 (番号順 (詳細)・ 回線別 (詳細)・ 機能別 (詳細))
CentreCOM ARX640S 設定例集 5.1.5 #6
IPフィルターは、IP、TCP、UDP、ICMPなどのヘッダー情報をもとに、パケットの通過・拒否を制御する機能です。この例では、IPフィルターの基本的な設定方法を、CUG(Closed Users Group)サービス接続環境における拠点間VPN接続の構成例をもとに解説します。
| PPPユーザー名 | user@isp |
| PPPパスワード | isppasswd |
| PPPoEサービス名 | 指定なし |
| IPアドレス | グローバルアドレス1個(動的割り当て) |
| DNSサーバー | 接続時に通知される |
| ユーザーID(PPPユーザー名) | userA@group | userB@group |
| パスワード(PPPパスワード) | grouppassA | grouppassB |
| IPアドレス | 4.4.4.1/32 | 4.4.4.2/32 |
| WAN側物理インターフェース | gigabitEthernet 0 | |
| WAN側(gigabitEthernet 0.1)IPアドレス | 接続時にCUGサービス網から取得する(毎回同じアドレスが割り当てられる) | |
| WAN側(gigabitEthernet 0.2)IPアドレス | 接続時にISPから取得する | - |
| LAN側(vlan 1)IPアドレス | 192.168.10.1/24 | 192.168.20.1/24 |
| VPN接続設定 | ||
| ローカルセキュアグループ | 0.0.0.0/0 | 192.168.20.0/24 |
| リモートセキュアグループ | 192.168.20.0/24 | 0.0.0.0/0 |
| トンネル終端アドレス | 4.4.4.2 | 4.4.4.1 |
| IKE設定 | ||
| 交換モード | Mainモード | |
| 認証方式 | 事前共有鍵(pre-shared key) | |
| 事前共有鍵 | secret(文字列) | |
| ローカルID/リモートID | なし/なし | |
| 暗号化認証アルゴリズム | 3DES & SHA1-DH2 | |
| 有効期限 | 21600秒(6時間)(デフォルト) | |
| DPDによる死活監視 | 行わない | |
| 起動時のISAKMPネゴシエーション | 行う | |
| IPsec設定 | ||
| SAモード | トンネルモード | |
| セキュリティープロトコル | ESP | |
| 暗号化認証アルゴリズム | 3DES & SHA1 | |
| PFSグループ | なし | |
| 有効期限 | 3600秒(1時間)(デフォルト) | |

| ルーターAの設定 |
ppp profile pppoe0 ↓
my-username userA@group password grouppassA ↓
ppp profile pppoe1 ↓
my-username user@isp password isppasswd ↓
interface gigabitEthernet 0 ↓
no shutdown ↓
interface gigabitEthernet 0.1 ↓
ip address ipcp ↓
ip tcp mss auto ↓
no shutdown ↓
pppoe enable ↓
ppp bind-profile pppoe0 ↓
interface gigabitEthernet 0.2 ↓
ip address ipcp ↓
ip tcp mss auto ↓
no shutdown ↓
pppoe enable ↓
ppp bind-profile pppoe1 ↓
ip napt inside any ↓
ip ids in protect ↓
interface vlan 1 ↓
ip address 192.168.10.1/24 ↓
ip address-up-always ↓
ip route default gigabitEthernet 0.2 ↓
ip route 4.4.4.2/32 gigabitEthernet 0.1 ↓
ip route 4.4.4.2/32 Null 254 ↓
access-list ip extended pppoe1-in ↓
access-list ip extended pppoe1-out ↓
dynamic permit ip any any ↓
interface gigabitEthernet 0.2 ↓
ip traffic-filter pppoe1-in in ↓
ip traffic-filter pppoe1-out out ↓
isakmp proposal isakmp encryption 3des hash sha1 group 2 ↓
isakmp policy isakmp ↓
peer 4.4.4.2 ↓
auth preshared key secret ↓
proposal isakmp ↓
access-list ip extended ipsec ↓
permit ip any any ↓
ipsec proposal ipsec esp encryption 3des hash sha1 ↓
ipsec policy ipsec ↓
peer 4.4.4.2 ↓
access-list ipsec ↓
local-id 0.0.0.0/0 ↓
remote-id 192.168.20.0/24 ↓
proposal ipsec ↓
always-up-sa ↓
interface tunnel 0 ↓
tunnel mode ipsec ↓
ip unnumbered vlan 1 ↓
ip tcp mss auto ↓
no shutdown ↓
tunnel policy ipsec ↓
ip route 192.168.20.0/24 tunnel 0 ↓
ip route 192.168.20.0/24 Null 254 ↓
access-list ip extended tunnel0-in ↓
dynamic permit tcp 192.168.20.4/32 192.168.10.2/32 eq 23 ↓
dynamic permit tcp 192.168.20.5/32 192.168.10.2/32 eq 23 ↓
dynamic permit udp 192.168.20.5/32 192.168.10.2/32 eq tftp ↓
dynamic permit udp 192.168.20.6/32 192.168.10.2/32 eq tftp ↓
deny ip any 192.168.10.2/32 ↓
dynamic permit ip any any ↓
access-list ip extended tunnel0-out ↓
dynamic permit ip any any ↓
interface tunnel 0 ↓
ip traffic-filter tunnel0-in in ↓
ip traffic-filter tunnel0-out out ↓
copy running-config startup-config ↓
| ルーターBの設定 |
ppp profile pppoe0 ↓
my-username userB@group password grouppassB ↓
interface gigabitEthernet 0 ↓
no shutdown ↓
interface gigabitEthernet 0.1 ↓
ip address ipcp ↓
ip tcp mss auto ↓
no shutdown ↓
pppoe enable ↓
ppp bind-profile pppoe0 ↓
interface vlan 1 ↓
ip address 192.168.20.1/24 ↓
ip address-up-always ↓
ip route 4.4.4.1/32 gigabitEthernet 0.1 ↓
isakmp proposal isakmp encryption 3des hash sha1 group 2 ↓
isakmp policy isakmp ↓
peer 4.4.4.1 ↓
auth preshared key secret ↓
proposal isakmp ↓
access-list ip extended ipsec ↓
permit ip any any ↓
ipsec proposal ipsec esp encryption 3des hash sha1 ↓
ipsec policy ipsec ↓
peer 4.4.4.1 ↓
access-list ipsec ↓
local-id 192.168.20.0/24 ↓
remote-id 0.0.0.0/0 ↓
proposal ipsec ↓
always-up-sa ↓
interface tunnel 0 ↓
tunnel mode ipsec ↓
ip unnumbered vlan 1 ↓
ip tcp mss auto ↓
no shutdown ↓
tunnel policy ipsec ↓
ip route default tunnel 0 ↓
copy running-config startup-config ↓
| まとめ |
ルーターAのコンフィグ
! service password-encryption ! clock timezone JST 9 ! ! ip address-up-always ppp profile pppoe0 my-username userA@group password 8 e$QOnYQDIRnplmrSlqsqIAdhQAA ppp profile pppoe1 my-username user@isp password 8 e$QNKMe2ohmPDFnghyVppETegAA ! interface gigabitEthernet 0 no shutdown ! interface gigabitEthernet 0.1 ip address ipcp ip tcp mss auto no shutdown pppoe enable ppp bind-profile pppoe0 ! interface gigabitEthernet 0.2 ip address ipcp ip tcp mss auto no shutdown pppoe enable ppp bind-profile pppoe1 ip napt inside any ip traffic-filter pppoe1-in in ip traffic-filter pppoe1-out out ip ids in protect ! interface gigabitEthernet 1 shutdown ! interface gigabitEthernet 2 no shutdown ! interface gigabitEthernet 3 no shutdown ! interface gigabitEthernet 4 no shutdown ! interface gigabitEthernet 5 no shutdown ! interface loop 0 shutdown ! interface loop 1 shutdown ! interface tunnel 0 tunnel mode ipsec ip unnumbered vlan 1 ip tcp mss auto no shutdown tunnel policy ipsec ip traffic-filter tunnel0-in in ip traffic-filter tunnel0-out out ! interface vlan 1 ip address 192.168.10.1/24 no shutdown ! ip route default gigabitEthernet 0.2 ip route 4.4.4.2/32 gigabitEthernet 0.1 ip route 4.4.4.2/32 Null 254 ip route 192.168.20.0/24 tunnel 0 ip route 192.168.20.0/24 Null 254 ! access-list ip extended ipsec permit ip any any access-list ip extended pppoe1-in access-list ip extended pppoe1-out dynamic permit ip any any access-list ip extended tunnel0-in dynamic permit tcp 192.168.20.4/32 192.168.10.2/32 eq 23 dynamic permit tcp 192.168.20.5/32 192.168.10.2/32 eq 23 dynamic permit udp 192.168.20.5/32 192.168.10.2/32 eq tftp dynamic permit udp 192.168.20.6/32 192.168.10.2/32 eq tftp deny ip any 192.168.10.2/32 dynamic permit ip any any access-list ip extended tunnel0-out dynamic permit ip any any ! isakmp proposal isakmp encryption 3des hash sha1 group 2 ! isakmp policy isakmp peer 4.4.4.2 auth preshared key 8 e$I3eQu7yNuLxQA proposal isakmp ! ipsec proposal ipsec esp encryption 3des hash sha1 ! ipsec policy ipsec peer 4.4.4.2 access-list ipsec local-id 0.0.0.0/0 remote-id 192.168.20.0/24 proposal ipsec always-up-sa ! ! ! ! end |
ルーターBのコンフィグ
! service password-encryption ! clock timezone JST 9 ! ! ip address-up-always ppp profile pppoe0 my-username userB@group password 8 e$QOnYQDIRnplklVTihIgEZVQAA ! interface gigabitEthernet 0 no shutdown ! interface gigabitEthernet 0.1 ip address ipcp ip tcp mss auto no shutdown pppoe enable ppp bind-profile pppoe0 ! interface gigabitEthernet 1 shutdown ! interface gigabitEthernet 2 no shutdown ! interface gigabitEthernet 3 no shutdown ! interface gigabitEthernet 4 no shutdown ! interface gigabitEthernet 5 no shutdown ! interface loop 0 shutdown ! interface loop 1 shutdown ! interface tunnel 0 tunnel mode ipsec ip unnumbered vlan 1 ip tcp mss auto no shutdown tunnel policy ipsec ! interface vlan 1 ip address 192.168.20.1/24 no shutdown ! ip route default tunnel 0 ip route 4.4.4.1/32 gigabitEthernet 0.1 ! access-list ip extended ipsec permit ip any any ! isakmp proposal isakmp encryption 3des hash sha1 group 2 ! isakmp policy isakmp peer 4.4.4.1 auth preshared key 8 e$I3eQu7yNuLxQA proposal isakmp ! ipsec proposal ipsec esp encryption 3des hash sha1 ! ipsec policy ipsec peer 4.4.4.1 access-list ipsec local-id 192.168.20.0/24 remote-id 0.0.0.0/0 proposal ipsec always-up-sa ! ! ! ! end |
(C) 2011-2014 アライドテレシスホールディングス株式会社
PN: 613-001568 Rev.E