bridge member bridge1 lan1 tunnel50
ip bridge1 address 192.168.1.254/24
ip bridge1 proxyarp on
■47行目~68行目 を追加
tunnel select 50
tunnel encapsulation l2tpv3
tunnel endpoint address 192.168.1.254 (本社別館の固定IPアドレス)
ipsec tunnel 101
ipsec sa policy 101 50 esp aes-cbc sha-hmac
ipsec ike keepalive log 50 on
ipsec ike keepalive use 50 on
ipsec ike local address 50 192.168.1.254
ipsec ike pre-shared-key 50 text (事前共有鍵)
ipsec ike remote address 50 (本社別館の固定IPアドレス)
l2tp always-on on
l2tp hostname (接続先に通知するホスト名)
l2tp tunnel auth on (L2TP認証用パスワード)
l2tp tunnel disconnect time off
l2tp keepalive use on 60 3
l2tp keepalive log on
l2tp syslog on
l2tp local router-id 192.168.1.254
l2tp remote router-id 192.168.1.253
l2tp remote end-id (L2TPv3リモートエンドID)
ip tunnel tcp mss limit auto
tunnel enable 50
■96行目 を追加
ipsec transport 50 101 udp 1701
■103行目~104行目 を追加
l2tp service on l2tpv3
httpd host 192.168.1.1-192.168.1.254
続いて本社の別館ルータBの設定内容です。
本社の別館ルータB設定内容
login password *
administrator password *
ip route default gateway pp 1
ip filter source-route on
ip filter directed-broadcast on
bridge member bridge1 lan1 tunnel1
ip bridge1 address 192.168.1.253/24
pp select 1
pp keepalive interval 30 retry-interval=30 count=12
pp always-on on
pppoe use lan2
pppoe auto connect on
pppoe auto disconnect on
pp auth accept pap chap
pp auth myname (ISPの接続アカウント) (ISPのパスワード)
ppp lcp mru on 1454
ppp ipcp ipaddress on
ppp ccp type none
ip pp mtu 1454
ip pp secure filter in 1020 1030 1040 1041 2000
ip pp secure filter out 1010 1011 1012 1013 1014 1015 3000 dynamic 100 101 102 103 104 105 106 107
ip pp nat descriptor 1
pp enable 1
tunnel select 1
tunnel encapsulation l2tpv3
tunnel endpoint address 192.168.1.253 (本社本館の固定IPアドレス)
ipsec tunnel 101
ipsec sa policy 101 1 esp aes-cbc sha-hmac
ipsec ike keepalive log 1 on
ipsec ike keepalive use 1 on
ipsec ike local address 1 192.168.1.253
ipsec ike pre-shared-key 1 text (事前共有鍵)
ipsec ike remote address 1 (本社本館の固定IPアドレス)
l2tp always-on on
l2tp hostname (接続先に通知するホスト名)
l2tp tunnel auth on (L2TP認証用パスワード)
l2tp tunnel disconnect time off
l2tp keepalive use on 60 3
l2tp keepalive log on
l2tp syslog on
l2tp local router-id 192.168.1.253
l2tp remote router-id 192.168.1.254
l2tp remote end-id (L2TPv3リモートエンドID)
ip tunnel tcp mss limit auto
tunnel enable 1
ip filter 1010 reject * * udp,tcp 135 *
ip filter 1011 reject * * udp,tcp * 135
ip filter 1012 reject * * udp,tcp netbios_ns-netbios_ssn *
ip filter 1013 reject * * udp,tcp * netbios_ns-netbios_ssn
ip filter 1014 reject * * udp,tcp 445 *
ip filter 1015 reject * * udp,tcp * 445
ip filter 1020 reject 192.168.1.0/24 *
ip filter 1030 pass * 192.168.1.0/24 icmp
ip filter 1040 pass * 192.168.1.253 udp * 500
ip filter 1041 pass * 192.168.1.253 esp
ip filter 2000 reject * *
ip filter 3000 pass * *
ip filter dynamic 100 * * ftp
ip filter dynamic 101 * * www
ip filter dynamic 102 * * domain
ip filter dynamic 103 * * smtp
ip filter dynamic 104 * * pop3
ip filter dynamic 105 * * netmeeting
ip filter dynamic 106 * * tcp
ip filter dynamic 107 * * udp
nat descriptor type 1 masquerade
nat descriptor address outer 1 ipcp
nat descriptor address inner 1 auto
nat descriptor masquerade static 1 1 192.168.1.253 udp 500
nat descriptor masquerade static 1 2 192.168.1.253 esp
nat descriptor masquerade static 1 3 192.168.1.253 udp 4500
ipsec auto refresh on
ipsec transport 1 101 udp 1701
telnetd host 192.168.1.1-192.168.1.254
dhcp service server
dhcp server rfc2131 compliant except remain-silent
dhcp scope 1 192.168.1.51-192.168.1.59/24
dns server 8.8.8.8 8.8.4.4
dns private address spoof on
l2tp service on l2tpv3
httpd host 192.168.1.1-192.168.1.254