LinuxãšçŽæ¥é¢ä¿ããªã質åã§æçž®ã§ãããLAN鿥ç¶ã«ã€ããŠæ
ããŠãã ããã
äžã®ãããã¯ãŒã¯æ§æã§128kã®å°çšç·ãä»ããŠãµããããåå²ã«
ããLAN鿥ç¶ãè¡ãããšããŠããŸãã
ã(Internetå°çšç·)
|
Router(CISCO1720)
|
HUB - FireWall - ã€ã³ã¿ãŒããããµãŒããŒ
|
Router(NTT IPMATE1300RD)
|
(128Kå°çšç·)
|
Router(YAMAHA RTA52i)
|
ã¯ã©ã€ã¢ã³ãããœã³ã³
äžèšæ§æã§ã«ãŒã¿ãŒã®èšå®ã¯æ¬¡ã®ããã«è¡ã£ãŠããŸã
CISCO1720 æ¬äœIP=aaa.bbb.ccc.1/255.255.255.0
IPMATE æ¬äœIP=aaa.bbb.ccc.126/255.255.255.128
çžæIP=aaa.bbb.ccc.193/255.255.255.192
ããã©ãŒã«ãã«ãŒã¿ãŒ=aaa.bbb.ccc.1
RTA52i æ¬äœIP=aaa.bbb.ccc.193/aaa.bbb.ccc.192
ã¯ã©ã€ã¢ã³ããšã®éã§ïŒïŒïŒNATãè¡ã£ãŠãã
ãããããïŒã°ããŒãã«ã¢ãã¬ã¹ãšããŠaaa.bbb.ccc.194-254ãå²ãä»ã
ãããããããŠããïŒ
以äžã®èšå®ã§æ¥ç¶ããŸããšã¯ã©ã€ã¢ã³ãããœã³ã³ããaaa.bbb.ccc.126ãžã®
pingã¯å±ããŸããä»ã®ã€ã³ã¿ãŒããããµãŒããŒãå€éšã®ãµã€ããžã®æ¥ç¶ã
ã§ããªãç¶æ³ã§ãã
ãµããããåå²ããLAN鿥ç¶ã®æ¹æ³ãšããŠäžèšã®èšå®ã§ã©ããããããã§
ããããããŸããäœãèšå®äžã§ç¢ºèªãã¹ãããšããããŸãã§ããããã
å¿
èŠãªæ
å ±ãããã°ãææãã ããã
ãæ°ã¥ãã®ç¹ãããã°ã¢ããã€ã¹ããã ããã°å¹žãã§ãã
ã§ã¯ããããããé¡ãããŸãã
--
Hiroki Uchida
in...@forest.tama.tokyo.jp
ç§ã®å Žå㯠2 ã€ã®ã«ãŒã¿ãŒéãé»è©±ç·æ¥ç¶ãªã®ã§ãããåèã«ãª
ãã°ãšæãäžããããŠããããŸããã
> å ç°ãšãããŸã
> (Internetå°çšç·)
> |
> Router(CISCO1720)
> |
> HUB - FireWall - ã€ã³ã¿ãŒããããµãŒããŒ
> |
> Router(NTT IPMATE1300RD)
> |
> (128Kå°çšç·)
> |
> Router(YAMAHA RTA52i)
> |
> ã¯ã©ã€ã¢ã³ãããœã³ã³
ç§ã®å Žåã¯é»è©±ç·ã䜿ã£ãŠç¹ãã§ãŸãã
ããªããžãããªãã§ãã®ã§ã192.168.72 系㚠192.168.1 ç³»ãšã«
åããŠãã®ãèèŠã§ãïŒklug ã® M ããããã®ã¢ããã€ã¹ã§ããïŒã
win2000ïŒ192.168.72.221ïŒhiroyuki.co.jp ç³»
ïœ
MN128ãã«ã«ãŒã¿ãŒAïŒ192.168.72.1ïŒ
ïœ
ïœ
ïœé»è©±ISDN
ïœ
ïœ
MN128ã«ãŒã¿ãŒBïŒ192.168.1.1ïŒ
ïœ
BSD3.51ïŒ192.168.1.22ïŒjiroyuki.co.jp ç³»
ã§ãã
ãããŠwin2000ïŒ192.168.72.221ïŒãããMN128ã«ãŒã¿ãŒïŒ192.168.1.1ïŒ
ã«é»è©±ããããŠããã®åŸ
telnet 192.168.1.22ãããŠïŒã»ããšã¯ ttssh ã§ããïŒ
BSD3.51ïŒ192.168.1.22ïŒã«å
¥ã£ãŠãããŸãã
--------------------------------------------------------------------------------
ãŸãMN128ãã«ã«ãŒã¿ãŒAïŒ192.168.72.1ïŒã§ãã
# MN128-SOHO PAL 1.01 06/22/00 16:30:21
# MAC Address: 00:80:b8:1c:06:e7
sys encrypt ca
user admin password uH encrypted
user 1 password uH encrypted
analog device 2 fax
analog directcall off
analog sendnumind 1 do
analog sendnumind 2 do
analog voice in off
analog voice out off
ip address 192.168.72.1/24
ip dhcp address 192.168.72.2/8
ip dhcp server off
ip dns relay off
ip filter 29 restrict out * * tcpfin * * remote *
ip filter 30 restrict out * * * * 137-139 remote *
ip filter 31 restrict out * * * 137-139 * remote *
ip filter 32 restrict out * * udp 137 domain remote *
ip las address 192.168.72.10
äžç¥
remote 1 name ---at---
remote 1 number 088-888-8888*1
remote 1 send id ssss
remote 1 send password XXXXXXXX encrypted
以äžç¥
--------------------------------------------------------------------------------
ç¶ããŠ
MN128ã«ãŒã¿ãŒïŒ192.168.1.1ïŒãåŒãããŸã
1ïŒãªã¢ãŒãã¢ã¯ã»ã¹ãµãŒããŒã ON ããŠããããã®ã¢ãã¬ã¹ã
192.168.1.222 ãšããŸãã
2ïŒãLANåŽDNSãµãŒããŒã¢ãã¬ã¹ãã192.168.1.22ããšããŸããâ
ã«ãŒã¿ãŒã¯ååã®è§£æ±ºãFreeBSD3.51ãã·ã³ïŒ192.168.1.22ïŒã§è¡ãã
ç§ã®è§£éã§ã
-------------
routerBã§ãNATã€ãŸããã¹ã«ã¬ãŒããããŸãã
192.168.72.221ïŒ192.168.1.222ãšãªããã§ãã
ã€ãŸããLAN192.168.1.ïœïŒjiroyuki.co.jpïŒ*ã*ãããïŒç³»ã§ã¯ã
192.168.72.221ã¯192.168.1.222ãšèªèãããŸãã
-------------
ç§ã«ã¯å°çšç·ãšããç¶æ³ã¯ãšãŠãæãåºããªãã®ã§ãã
ãªã http://www.ad.wakwak.com/~okoutakesima/2router.htm
ã«çµµå
¥ãã§æžããŠãŸãã
ãŸããhttp://okou.dyndns.org/ ã¯ãã¬ãã ISDN ãå©çšãã
dynamicã DNS ã§ããã®ããŒãžã« dynamicã DNS ã«ã€ããŠæžããŠ
ãŸã ã
_/_/_/_/_/_/_/_/ãµã€ãºé 衚瀺_/_/_/_/_/_/_/_/_/_/_/_/
okouta...@ad.wakwak.com
http://www.ad.wakwak.com/~okoutakesima/
http://okou.dyndns.org/
Thu, 19 Jul 2001 23:58:26 +0900 ã«æžããã
Hiroki Uchida <in...@forest.tama.tokyo.jp> ããã®ãè¿äºã§ãã
> äžã®ãããã¯ãŒã¯æ§æã§128kã®å°çšç·ãä»ããŠãµããããåå²ã«
> ããLAN鿥ç¶ãè¡ãããšããŠããŸãã
(snip)
> CISCO1720 æ¬äœIP=aaa.bbb.ccc.1/255.255.255.0
>
> IPMATE æ¬äœIP=aaa.bbb.ccc.126/255.255.255.128
> çžæIP=aaa.bbb.ccc.193/255.255.255.192
> ããã©ãŒã«ãã«ãŒã¿ãŒ=aaa.bbb.ccc.1
>
> RTA52i æ¬äœIP=aaa.bbb.ccc.193/aaa.bbb.ccc.192
> ã¯ã©ã€ã¢ã³ããšã®éã§ïŒïŒïŒNATãè¡ã£ãŠãã
> ãããããïŒã°ããŒãã«ã¢ãã¬ã¹ãšããŠaaa.bbb.ccc.194-254ãå²ãä»ã
> ãããããããŠããïŒ
VLSMïŒå¯å€é·ãµãããããã¹ã¯ïŒã䜿ãå Žåãã¡ãããšãµããããåå²ããªããš
ããããçŸè±¡ãããããŸãã
3ãªã¯ãããç®ïŒaaa.bbb.cccïŒãŸã§ãä»LANãšåäžã«ããããããããã¹ã¯ã
24bit ã«ãªã£ãŠããããã«ãåž°ãã®ãã±ãããã«ãŒãã£ã³ã°å¯Ÿè±¡ã«ãªã£ãŠ
ããªããšèããããŸãã
å
šãŠã®ãããã¯ãŒã¯ã®ãµãããããã¹ã¯ã®åãæ¹ãåèšèšãããããããã¯ãŒã¯
ã¢ãã¬ã¹ãåããïŒ192.168.1.0 / 192.168.2.0 ãªã©ïŒããšããå§ãããŸãã
------------------
ææŸ å¥åŸ | Global Com Service CO.,LTD
Kengo Muramatsu | System Solution Group
mailto : mura...@glcom.co.jp | Phone : +81-3-5765-8070
http : http://www.glcom.co.jp | FAX : +81-3-5765-8069
èŠèœãšããŠãŸããã...
Fri, 20 Jul 2001 07:59:42 +0900 ã«æžããã
Kengo Muramatsu <mura...@glcom.co.jp> ããã®ãè¿äºã§ãã
> > IPMATE æ¬äœIP=aaa.bbb.ccc.126/255.255.255.128
ããããäžã® 26bit Mask ã®ãããã¯ãŒã¯ãšéè€ããŠããŸããã
ãã©ã€ããŒãã¢ãã¬ã¹ã§å·®ãæ¯ããªããã°ããããã¯ãŒã¯ã¢ãã¬ã¹ãŸã§
æžããæ¹ãåå ã«è§ŠãããããããããŸããã
ã§ã¯
ãããŸãããèªã¿çŽãããå
šç¶èŠç¹ãåŸãŠãªãã£ãã®ã§è£è¶³ã§ãã
# ãŽãã°ã£ããã§ãããŸãã m(_ _)m
Fri, 20 Jul 2001 08:13:27 +0900 ã«æžããã
Kengo Muramatsu <mura...@glcom.co.jp> ããã®ãè¿äºã§ãã
> > > IPMATE æ¬äœIP=aaa.bbb.ccc.126/255.255.255.128
> ããããäžã® 26bit Mask ã®ãããã¯ãŒã¯ãšéè€ããŠããŸããã
>
> ãã©ã€ããŒãã¢ãã¬ã¹ã§å·®ãæ¯ããªããã°ããããã¯ãŒã¯ã¢ãã¬ã¹ãŸã§
> æžããæ¹ãåå ã«è§ŠãããããããããŸããã
ã€ãã§ãªã®ã§ãããã¡ãã£ãšè©³ããæžããŸã
ïŒ"aaa.bbb.ccc" ã 192.168.1 ãšããå ŽåïŒ
ãææã®æ§æã ãšã
192.168.1.0/24 ïŒRange : 0ïœ255ïŒ
192.168.1.126/26 ïŒRange : 0ïœ127ïŒ
192.168.1.193/27 ïŒRange : 192ïœ255ïŒ
ãšãªã£ãŠããŸãããããã ãšäžïŒ24bit -> 26bitã26bit -> 27bitïŒãžã®
éä¿¡ã¯åäžãããŒããã£ã¹ãã»ãã¡ã€ã³ãšããèªèã«ãªããããããã©ã«ã
ã«ãŒããžåãåãããè¡ããŸãããïŒã«ãŒãã£ã³ã°ãããªãïŒ
äžèšã®ãããªãµããããåå²ãè¡ãå Žåã¯ãéè€ããªãããã«åããå¿
èŠã
ãããŸãã äŸãã°...
192.168.1.0/26 ïŒRange : 0ïœ127ïŒ
192.168.1.128/26 ïŒRange : 128ïœ191ïŒ
192.168.1.192/28 ïŒRange : 192ïœ207ïŒ
ãšãã£ãæãã§ãã
# ããã§å€ããŠãã倧ã¿ã³ã ...ïŒæ±
ææŸæ§ãè¿ä¿¡ããããšãããããŸãã
>3ãªã¯ãããç®ïŒaaa.bbb.cccïŒãŸã§ãä»LANãšåäžã«ããããããããã¹ã¯ã
>24bit ã«ãªã£ãŠããããã«ãåž°ãã®ãã±ãããã«ãŒãã£ã³ã°å¯Ÿè±¡ã«ãªã£ãŠ
>ããªããšèããããŸãã
CISCO1720ã®æ¬äœã®ã¢ãã¬ã¹æå®ã aaa.bbb.ccc.1/255.255.255.0 ã®ã
ãIPMATEããã®æ»ããã±ãããCISCOã«ã«ãŒãã£ã³ã°ãããŠããŸã£ãŠã
ããšããããšã§ããããã
>
>ïŒ"aaa.bbb.ccc" ã 192.168.1 ãšããå ŽåïŒ
>
>ãææã®æ§æã ãšã
>
>192.168.1.0/24 ïŒRange : 0ïœ255ïŒ
>192.168.1.126/26 ïŒRange : 0ïœ127ïŒ
>192.168.1.193/27 ïŒRange : 192ïœ255ïŒ
>
>ãšãªã£ãŠããŸãããããã ãšäžïŒ24bit -> 26bitã26bit -> 27bitïŒãžã®
>éä¿¡ã¯åäžãããŒããã£ã¹ãã»ãã¡ã€ã³ãšããèªèã«ãªããããããã©ã«ã
>ã«ãŒããžåãåãããè¡ããŸãããïŒã«ãŒãã£ã³ã°ãããªãïŒ
>
>äžèšã®ãããªãµããããåå²ãè¡ãå Žåã¯ãéè€ããªãããã«åããå¿
èŠã
>ãããŸãã äŸãã°...
>
>192.168.1.0/26 ïŒRange : 0ïœ127ïŒ
>192.168.1.128/26 ïŒRange : 128ïœ191ïŒ
>192.168.1.192/28 ïŒRange : 192ïœ207ïŒ
>
>ãšãã£ãæãã§ãã
ãææããã ãã察å¿çãšããŠã¯æ¬¡ã®ãã®ã§ãã£ãŠããã§ããããã
ïŒaaa.bbb.ccc ã¯ã¯ã©ã¹cã®ã°ããŒãã«ã¢ãã¬ã¹ã§ãã®ã§ãã®ãŸãŸæžã
ããŠãã ããïŒ
ïŒïŒãµããããåå²ããã¡ããšããçŽã
ããå
·äœçã«ã¯ãCISCO1720ã®æ¬äœã¢ãã¬ã¹ã aaa.bbb.ccc.1/255.255.
255.128ã«ããã
ãããã®å ŽåãFireWallããã®ä»ã®ãã¹ãã aaa.bbb.ccc.n/255.255.
255.128 ã«ããå¿
èŠãããã§ããããã
ããããããaaa.bbb.ccc.128 - aaa.bbb.ccc.191 ãŸã§ã¯å¥ã®ãã¹ãã§
䜿çšããŠããããäžèšã®ãã¹ã¯ãããããšãã®ãã¹ããå©çšã§ããªããª
ãã(CISCO1720ã¯ã€ã³ã¿ãã§ãŒã¹ãïŒã€ãããªãã®ã§ïŒ
ãã=>çŸå®çã«ã¯aaa.bbb.cccã¯åäžãããã¯ãŒã¯ïŒãµããããåå²ã§
ããªã)ã«ããããããªãããã§ãã
ïŒïŒãããã¯ãŒã¯ã¢ãã¬ã¹ãåãã
ãããã®å Žåã°ããŒãã«ã®IPã¢ãã¬ã¹ããã
ãšãããããšã«ãªããŸãã
ããã£ãŠãããã€ãã«ãé¡ãããã°ããã ããã®ã§ããããã
ãããŸãããã®å Žåã®ãããã¯ãŒã¯ã¢ãã¬ã¹ãLANã®ãããã¯ãŒã¯ã¢ã
ã¬ã¹ïŒaaa.bbb.ccc)ãšå
šç¶éããšãªã«ãåé¡ãããã§ããããã
ïŒïŒRTA52Iã«ãŒã¿ãŒã®ããã®ã¯ã©ã€ã¢ã³ãããã€ã¬ã¯ãã«LANã«å容ã
ãïŒ
ãããã®å ŽåããããŒããã£ã¹ãã®éä¿¡ãå¢ãããšã»ãã¥ãªãã£äžã®å
é¡ãåºãŠãããã§ãããæ¹æ³ãšããŠã¯ãã£ãšãæè»œã§ã¯ãªãããšæãã
ãŸããã
ããå
·äœçãªæ¹æ³ãšããŠã¯ã
ããïœïŒRTA52Iã®å
ã®ã¯ã©ã€ã¢ã³ãã«ãã©ã€ããŒãã¢ãã¬ã¹(192.168.
50.1-)ãå²ãåœãŠãŠRTA52Iã§ã¯NATãããã®ãŸãŸIPMATEãŸã§éããŠ
IPMATEã§NATããŠå
šãŠ aaa.bbb.ccc.126 ã®ã°ããŒãã«ã¢ãã¬ã¹ã«å€æã
ãã
ããïœïŒRTA52Iã§ãã©ã€ããŒãã¢ãã¬ã¹ãïŒïŒïŒNATã§ã°ããŒãã«ã¢ã
ã¬ã¹ïŒaaa.bbb.ccc.194-)ã«å€æãIPMATEã§ãã®ãŸãŸLANã«ã€ãªãããã®
å ŽåIPMATEã®ã«ãŒãã£ã³ã°å¶åŸ¡ã§æ»ããã±ãããæŸãããšãã§ããã§ã
ãããã
ããããããã¡ããã¡ãæžããŠããŸããŸãããã誀ãçãææããã ã
ãã°ãããããã§ãã
以äžã§ãã
--
å
ç° åå
E-Mail : in...@forest.tama.tokyo.jp
URL : http://www.forest.tama.tokyo.jp
"takesima_OSã©ã€ã㌠<okouta...@ad.wakwak.com>"ããè¿ä¿¡ããã
ãšãããããŸãã
>ç§ã®å Žåã¯é»è©±ç·ã䜿ã£ãŠç¹ãã§ãŸãã
>ããªããžãããªãã§ãã®ã§ã192.168.72 系㚠192.168.1 ç³»ãšã«
>åããŠãã®ãèèŠã§ãïŒklug ã® M ããããã®ã¢ããã€ã¹ã§ããïŒã
>
>win2000ïŒ192.168.72.221ïŒhiroyuki.co.jp ç³»
>ïœ
>MN128ãã«ã«ãŒã¿ãŒAïŒ192.168.72.1ïŒ
>ïœ
>ïœ
>ïœé»è©±ISDN
>ïœ
>ïœ
>MN128ã«ãŒã¿ãŒBïŒ192.168.1.1ïŒ
>ïœ
>BSD3.51ïŒ192.168.1.22ïŒjiroyuki.co.jp ç³»
>ã§ãã
>
>ãããŠwin2000ïŒ192.168.72.221ïŒãããMN128ã«ãŒã¿ãŒïŒ192.168.1.1ïŒ
>ã«é»è©±ããããŠããã®åŸ
>telnet 192.168.1.22ãããŠïŒã»ããšã¯ ttssh ã§ããïŒ
>BSD3.51ïŒ192.168.1.22ïŒã«å
¥ã£ãŠãããŸãã
>
>ç¶ããŠ
>MN128ã«ãŒã¿ãŒïŒ192.168.1.1ïŒãåŒãããŸã
>
>1ïŒãªã¢ãŒãã¢ã¯ã»ã¹ãµãŒããŒã ON ããŠããããã®ã¢ãã¬ã¹ã
>192.168.1.222 ãšããŸãã
>
>
>2ïŒãLANåŽDNSãµãŒããŒã¢ãã¬ã¹ãã192.168.1.22ããšããŸããâ
ã«ãŒã¿ãŒã¯ååã®è§£
決ãFreeBSD3.51ãã·ã³ïŒ192.168.1.22ïŒã§è¡ãã
>
>
>ç§ã®è§£éã§ã
>-------------
>routerBã§ãNATã€ãŸããã¹ã«ã¬ãŒããããŸãã
>192.168.72.221ïŒ192.168.1.222ãšãªããã§ãã
>ã€ãŸããLAN192.168.1.ïœïŒjiroyuki.co.jpïŒ*ã*ãããïŒç³»ã§ã¯ã
>192.168.72.221ã¯192.168.1.222ãšèªèãããŸãã
>-------------
ãªã¢ãŒãã¢ã¯ã»ã¹ãµãŒããŒã«ãã€ã¢ã«ã€ã³ããŠãããã¹ããLANã«å容
ãããšããããšã§ãããå°çšç·ã®å Žåã§ãNATãå©çšããŠãã®ããã«ã§
ããªããæ€èšããŠã¿ãŸãã
ããããšãããããŸããã
å
ç°ãåå <in...@forest.tama.tokyo.jp> wrote:
> ãªã¢ãŒãã¢ã¯ã»ã¹ãµãŒããŒã«ãã€ã¢ã«ã€ã³ããŠãããã¹ããLANã«å容
> ãããšããããšã§ããã
ããã§ãã
ããçµæ§ããã§ãã
ã©ãããŠããšãããš
1ïŒé»è©±åç·ãå©çšãã€ã³ã¿ãŒãããã«æããªãç¹
2ïŒåããã»ãã®ã«ãŒã¿ãŒã§ åä»ãé»è©±çªå· + ID ãšãã¹ã¯ãŒãã§
é²åŸ¡
3ïŒTTSSH ãªã®ã§ä»®ã«ååãããŠãä¿¡å·ãœãã¢ããæå·åãããŠã
ã®ã§ããããªã
4ïŒTTSSH ã§ outlookã express ã§ã¡ãŒã«ã®ããåããåºæ¥ãŸã
ïŒãpopã overã sshããïŒã ãsmtpã overã sshãïŒã
ããããçŸåšã¯ ADSLïŒtyoeã 2ïŒ ãç®æããŠãŸãã®ã§ã
win2000 ããäžæŠ ISP ã«ç¹ãã åŸã TTSSH ã§ã€ã³ã¿ãŒããããã
çŸåšã¯å
¥ã£ãŠãã£ãŠãŸã (ttssh okou.dyndns.org ã£ãŠæãã§ã ) ã
_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/
okouta...@ad.wakwak.com
http://www.ad.wakwak.com/~okoutakesima/
http://okou.dyndns.org/ã <- èŠãŠãã ãããäœãéåºã¯åå 5
ããååïŒæãŸã§ã® 19 æéã ãã§ãã
Fri, 20 Jul 2001 13:24:37 +0900 ã«æžããã
å
ç°ãåå <in...@forest.tama.tokyo.jp> ããã®ãè¿äºã§ãã
> >3ãªã¯ãããç®ïŒaaa.bbb.cccïŒãŸã§ãä»LANãšåäžã«ããããããããã¹ã¯ã
> >24bit ã«ãªã£ãŠããããã«ãåž°ãã®ãã±ãããã«ãŒãã£ã³ã°å¯Ÿè±¡ã«ãªã£ãŠ
> >ããªããšèããããŸãã
>
> CISCO1720ã®æ¬äœã®ã¢ãã¬ã¹æå®ã aaa.bbb.ccc.1/255.255.255.0 ã®ã
> ãIPMATEããã®æ»ããã±ãããCISCOã«ã«ãŒãã£ã³ã°ãããŠããŸã£ãŠã
> ããšããããšã§ããããã
ãšããããCisco1720 ããèŠãå Žåã«ã¯ãã¯ã©ã€ã¢ã³ããããã»ã°ã¡ã³ã
ïŒaaa.bbb.ccc.192/26ïŒã¯èªåã®ãããŒããã£ã¹ãã»ãã¡ã€ã³ãšããŠèªè
ãããŠããŸããŸãã
# aaa.bbb.ccc.0/24 ã®äžã«ã¯ aaa.bbb.ccc.193ïœ254 ãå«ãŸããŸãã®ã§
ã€ãŸããServer ã®ããã©ã«ãã²ãŒããŠã§ã€ã« Cisco ãæå®ãããŠããå Žå
ã«ã¯ãCisco ã§ãã±ãããæ¢ãŸã£ãŠããå¯èœæ§ãé«ããšæããŸãã
# ServeråŽã«ãåããµãããããæå®ãããŠãããCiscoãŸã§ãå°éããŸãã
æ ã«ã
> ïŒïŒãµããããåå²ããã¡ããšããçŽã
> ããå
·äœçã«ã¯ãCISCO1720ã®æ¬äœã¢ãã¬ã¹ã aaa.bbb.ccc.1/255.255.
> 255.128ã«ããã
> ãããã®å ŽåãFireWallããã®ä»ã®ãã¹ãã aaa.bbb.ccc.n/255.255.
> 255.128 ã«ããå¿
èŠãããã§ããããã
> ããããããaaa.bbb.ccc.128 - aaa.bbb.ccc.191 ãŸã§ã¯å¥ã®ãã¹ãã§
> 䜿çšããŠããããäžèšã®ãã¹ã¯ãããããšãã®ãã¹ããå©çšã§ããªããª
> ãã(CISCO1720ã¯ã€ã³ã¿ãã§ãŒã¹ãïŒã€ãããªãã®ã§ïŒ
aaa.bbb.ccc.0/26 ã®ãããã¯ãŒã¯ã«ããå Žåã䜿çšã§ããã¢ãã¬ã¹ã®ç¯å²ã¯
aaa.bbb.ccc.1 ïœ aaa.bbb.ccc.127 ãŸã§ãšãªããŸãã
â» 0 ïŒ Subnet Address
â» 128 ïŒ Broadcast Address
ãŸãã128ïœ191 ã§äœ¿çšäžãšãããŸãããããã£ãŠ IPMATE ã§èšå®
ããŠãããµãããããšå€ãã£ãŠããŸããŸããã
ã©ãããµããããã¢ãã¬ã¹ããã£ã¡ãã«ãªã£ãŠããããã«èŠããŸãã
ç¹°ãè¿ããŸããããµããããåå²ãè¡ãå Žåãåå²ããåãµããããå
ã®ã¢ãã¬ã¹ã¯ä»ãµããããã®ã¢ãã¬ã¹ãšéè€ããªãããã«èšèšããŠäžããã
> ïŒïŒãããã¯ãŒã¯ã¢ãã¬ã¹ãåãã
> ãããã®å Žåã°ããŒãã«ã®IPã¢ãã¬ã¹ããã
ãšãããããšã«ãªããŸãã
> ããã£ãŠãããã€ãã«ãé¡ãããã°ããã ããã®ã§ããããã
>
> ãããŸãããã®å Žåã®ãããã¯ãŒã¯ã¢ãã¬ã¹ãLANã®ãããã¯ãŒã¯ã¢ã
> ã¬ã¹ïŒaaa.bbb.ccc)ãšå
šç¶éããšãªã«ãåé¡ãããã§ããããã
IPã¢ãã¬ã¹ãç¡çã«åããªããŠããæè§ Firewall ãããã®ãªãã
StaticNATïŒå®å
NAT ãšãããã€ã§ãïŒã䜿ã£ãŠãå€éšå
¬éçšã®ã¢ãã¬ã¹ã
é¢é£ä»ãã¡ããã°ãå
éšãããã¯ãŒã¯ã¯ãã©ã€ããŒãã¢ãã¬ã¹ã§æ§æã§ããŸãã
ãŸãããããã¯ãŒã¯ã¢ãã¬ã¹ãç°ãªã£ãå Žåã®åé¡ç¹ã¯ããã®ãããã¯ãŒã¯
äžã§åããŠããã¢ããªã±ãŒã·ã§ã³ã®èšèšã«ãããŸãã
IPã¢ãã¬ã¹æå®ã§ä»ãµãŒããšé£æºããŠããå Žåã¯ã¢ãã¬ã¹å€æŽãå¿
èŠã«ãªã
ãŸãããWinNT/2000ãªããã®ãµãŒãã§ NBTã䜿çšããŠããå Žåã«ã¯ WINSã
èµ·ãŠãå¿
èŠããããŸããã
> ïŒïŒRTA52Iã«ãŒã¿ãŒã®ããã®ã¯ã©ã€ã¢ã³ãããã€ã¬ã¯ãã«LANã«å容ã
> ãïŒ
> ãããã®å ŽåããããŒããã£ã¹ãã®éä¿¡ãå¢ãããšã»ãã¥ãªãã£äžã®å
> é¡ãåºãŠãããã§ãããæ¹æ³ãšããŠã¯ãã£ãšãæè»œã§ã¯ãªãããšæãã
> ãŸããã
> ããå
·äœçãªæ¹æ³ãšããŠã¯ã
> ããïœïŒRTA52Iã®å
ã®ã¯ã©ã€ã¢ã³ãã«ãã©ã€ããŒãã¢ãã¬ã¹(192.168.
> 50.1-)ãå²ãåœãŠãŠRTA52Iã§ã¯NATãããã®ãŸãŸIPMATEãŸã§éããŠ
> IPMATEã§NATããŠå
šãŠ aaa.bbb.ccc.126 ã®ã°ããŒãã«ã¢ãã¬ã¹ã«
> 倿ããã
å¥ã«ãåé¡ãªãããããªãã§ãããã
IPMATE ã§ NAT ããã®ã§ããã°ãã¯ã©ã€ã¢ã³ãåŽãµããããã®ãããŒããã£ã¹ã
㯠IPMATE ãŸã§å°éããŸããã®ã§ããã©ãã£ãã¯éäºã
ã¯ç¡ãã§ããããã
RTA52I - IPMATE éãããªããžã³ã°ãããªãå¥ã§ããã©...ãã®çµã¿åããã§
åºæ¥ãã®ããã...ïŒ
# ããããã°å¯Ÿåã«ãŒã¿åŽã§NATã£ãŠè©Šããããšãªããªã...ã§ããã®ããªïŒ
> ããïœïŒRTA52Iã§ãã©ã€ããŒãã¢ãã¬ã¹ãïŒïŒïŒNATã§ã°ããŒãã«ã¢ã
> ã¬ã¹ïŒaaa.bbb.ccc.194-)ã«å€æãIPMATEã§ãã®ãŸãŸLANã«ã€ãªãã
> ãã®å ŽåIPMATEã®ã«ãŒãã£ã³ã°å¶åŸ¡ã§æ»ããã±ãããæŸãããšã
> ã§ããã§ããããã
ïŒïŒïŒ èšãããšããŠãããšãè¯ãå€ããŸããã
RTA52Iã§NATãè¡ã£ãŠããããžãã¯ã¯åºæ¬çã«IPMATEã§NATããã®ãšåã
ã§ãããã
çµå±ãçµè«ãšããŠã¯ã·ã¹ãã æ§æãŸã§èšåããŠããªãã®ã§ããããŸã§
äžè¬çãªãããã¯ãŒã¯èšèšïŒïŒïŒã§ã®è§£æ±ºãšããåæã«ãªã£ãŠããŸãã
ãããã¯ãŒã¯æ©åšåŽã§è§£æ±ºãããå Žåã¯ãäžèšã®ã©ã®ææ®µã䜿ã£ãŠã
IPçã«ã¯åé¡ãªãã§ãããã
ãã®åŸãã©ã®è§£æ±ºçãæåããæ±ºããã®ã¯ãã·ã¹ãã åŽã§ã®äžæŽåã
ã»ãã¥ãªãã£ã«èšåããããšããã§ãã
ã§ã¯
èªå·±ã¡ãã¡ãïŒ
Sat, 21 Jul 2001 21:49:08 +0900 ã«æžããã
Kengo Muramatsu <mura...@glcom.co.jp> ããã®ãè¿äºã§ãã
> aaa.bbb.ccc.0/26 ã®ãããã¯ãŒã¯ã«ããå Žåã䜿çšã§ããã¢ãã¬ã¹ã®ç¯å²ã¯
>
> aaa.bbb.ccc.1 ïœ aaa.bbb.ccc.127 ãŸã§ãšãªããŸãã
> â» 0 ïŒ Subnet Address
> â» 128 ïŒ Broadcast Address
ãããŸããã255.255.255.128 㯠25bit ã§ãããã
ã¢ãã¬ã¹ã®ç¯å²ã¯äžèšã§ãã£ãŠãŸãã...
# æè¿ãµããããèšç®ã¯èšç®æ©ã«ãŸããã£ããã ã£ãã®ã§...
# ã£ãŠã®ã¯èšãèš³ã«ãªããªãã§ããã æ¥ãããã... (-_-;
ææŸæ§ãäžå¯§ã«èª¬æããã ããŠããããšãããããŸãã
å€éšLANãå
éšLANã«æ¥ç¶ããå Žåã®å
·äœçãªèšå®ã«ã€ããŠãæèŠããã
ãããšãããããã§ãã
>> ïŒïŒRTA52Iã«ãŒã¿ãŒã®ããã®ã¯ã©ã€ã¢ã³ãããã€ã¬ã¯ãã«LANã«å容ã
>> ãïŒ
>> ãããã®å ŽåããããŒããã£ã¹ãã®éä¿¡ãå¢ãããšã»ãã¥ãªãã£äžã®å
>> é¡ãåºãŠãããã§ãããæ¹æ³ãšããŠã¯ãã£ãšãæè»œã§ã¯ãªãããšæãã
>> ãŸããã
>> ããå
·äœçãªæ¹æ³ãšããŠã¯ã
>> ããïœïŒRTA52Iã®å
ã®ã¯ã©ã€ã¢ã³ãã«ãã©ã€ããŒãã¢ãã¬ã¹(192.168.
>> 50.1-)ãå²ãåœãŠãŠRTA52Iã§ã¯NATãããã®ãŸãŸIPMATEãŸã§éããŠ
>> IPMATEã§NATããŠå
šãŠ aaa.bbb.ccc.126 ã®ã°ããŒãã«ã¢ãã¬ã¹ã«
>> 倿ããã
>å¥ã«ãåé¡ãªãããããªãã§ãããã
>IPMATE ã§ NAT ããã®ã§ããã°ãã¯ã©ã€ã¢ã³ãåŽãµããããã®ãããŒããã£ã¹ã
>㯠IPMATE ãŸã§å°éããŸããã®ã§ããã©ãã£ãã¯éäºã
ã¯ç¡ãã§ããããã
>RTA52I - IPMATE éãããªããžã³ã°ãããªãå¥ã§ããã©...ãã®çµã¿åããã§
>åºæ¥ãã®ããã...ïŒ
>
> # ããããã°å¯Ÿåã«ãŒã¿åŽã§NATã£ãŠè©Šããããšãªããªã...ã§ããã®ããªïŒ
>
èŠçŽããŠã¿ããšãNATã®æ¹åãéã§ãããå°çšç·ããLANåŽãžã®NATã¯ïŒïŒ
ïŒã§ããã§ããªãããã§ãããããã£ãŠäžèšã®ã®ããæ¹ã¯ã§ããªããšæ
ãããŸãã
以äžã«ïŒæ¡ã»ã©èããŠã¿ãŸããããããããšããããææããã ãããš
å©ãããŸãã
æ¡1ïŒRTA52IïŒå€éšLANåŽã«ãŒã¿)ã§NATæ©èœã«ããaaa.bbb.ccc.126(å
éš
LANåŽã«ãŒã¿ã®æ¬äœã¢ãã¬ã¹ïŒã«å€æãããããã§å
éšLANå
ã§ã®æ»ãã
ã±ããã«ãŒãã£ã³ã°ã¯åé¡ãªããšæãã®ã§ãããæ»ããã±ãããå€éš
LANåŽã«è»¢éããããå¿é
ã§ãã
æ¡2ïŒåºæ¬çã«æ¡1ãšåãã§ããIPMATEã®ã»ã«ã³ããªIPã«aaa.bbb.ccc.
127ãæå®ãRTA52Iã§ãã®IPã¢ãã¬ã¹ã«NATãããããã«ãIPMATEã®éç
ã«ãŒãã£ã³ã°ã§aaa.bbb.ccc.127ãRTA52Iã«è»¢éãããããããªããšã
ã§ããã®ãïŒ
æ¡3ïŒRTA52Iã§192.168.1.1ã«NATãããã«IPMATEã§192.168.1.1ãaaa.
bbb.ccc.127(ã»ã«ã³ããªIPïŒã«ïŒïŒïŒNATãããNATã®NATãªããŠå€§äžå€«
ãªã®ã§ããããã
æ¡4ïŒRTA52IãIPMATEã§ã¯NATãããIPMATEãšå
éšLANã®éã«NATããã¯ã¹
ãèšçœ®ããNATãè¡ããNATããã¯ã¹ãæ°ãã«å¿
èŠã«ãªãããèšå®ã«æé
åãããã§ãã
ã§ããã°NATããã¯ã¹ã賌å
¥ããªãææ®µãããã®ã§ããããæèŠããã
ãããšå©ãããŸãã
ã¡ãã£ãšé·æã«ãªããŸã
æ¢ã«ïŒæåããïŒïŒ Linux ã®è°è«ããå€ããŠãŸããª...
å¿
èŠã§ããã° DM ãªãå¥ ML ã«ç§»ããŸãã®ã§ããéªéã§ããã°èšã£ãŠ
äžããã ïŒ MLã®çãã
Sun, 22 Jul 2001 16:17:32 +0900 ã«æžããã
å
ç°ãåå <in...@forest.tama.tokyo.jp> ããã®ãè¿äºã§ãã
èšèçã«ããããããªãã£ãã®ã§ããšãããã
ãå
éšLANã = ã¯ã©ã€ã¢ã³ãã®ãããµãããã
ãå€éšLANã = ãµãŒãã®ãããµãããã
ãšããŠèª¬æããŸãã
> æ¡1ïŒRTA52IïŒå€éšLANåŽã«ãŒã¿)ã§NATæ©èœã«ããaaa.bbb.ccc.126(å
éš
> LANåŽã«ãŒã¿ã®æ¬äœã¢ãã¬ã¹ïŒã«å€æãããããã§å
éšLANå
ã§ã®æ»ãã
> ã±ããã«ãŒãã£ã³ã°ã¯åé¡ãªããšæãã®ã§ãããæ»ããã±ãããå€éš
> LANåŽã«è»¢éããããå¿é
ã§ãã
ãã®ãæ»ããã±ããããšããã®ãäœãæãã®ãããããããŸãããã
å€éšLAN -> å
éšLAN ãžã®åž°ãã®ãã±ããïŒACKçïŒã§ããã°åé¡ã¯ãããŸããã
# åé¡ããã£ãã NAT/IP Masquerade ã®èãæ¹ãæãç«ããªãã§ã
ã¯ã©ã€ã¢ã³ãã®ãããµããããããã®ãã±ãããIP Masquerading
ãããã®ãã·ã¹ãã ã®*éçšäž*åé¡ç¡ãã®ã§ããã°ããã®æ¹æ³ã§ãåå
ã§ã¯ãªãããšæããŸãã
ããã§èšããéçšäžã®åé¡ãã¯ãäŸãã°ä»¥äžã®ãããªããšã§ã
ã» Server/Firewallã§ãPrivate Address ããã®ã¢ã¯ã»ã¹ãæåŠããŠããå Žå
ã» IP Address ã§ Client ãèå¥ïŒåºå¥ïŒããŠããå Žå
ãŸããå
éšLAN ïœ å€éšLAN 㯠NAT ããã«çŽæ¥éä¿¡ããŠãInternet ã«åºã
ãšãã®ã¿ NAT ãããšããæ¹æ³ãåãããšãã§ããŸãã
ããã¯ã«ãŒã¿ã®èšå®ã察å¿ã§ããããèæ
®ããå¿
èŠããããŸãããäŸãã°
å
ã®ã¡ãŒã«ã®
> ããïœïŒRTA52Iã®å
ã®ã¯ã©ã€ã¢ã³ãã«ãã©ã€ããŒãã¢ãã¬ã¹(192.168.
> 50.1-)ãå²ãåœãŠãŠRTA52Iã§ã¯NATãããã®ãŸãŸIPMATEãŸã§éããŠ
> IPMATEã§NATããŠå
šãŠ aaa.bbb.ccc.126 ã®ã°ããŒãã«ã¢ãã¬ã¹ã«
> 倿ããã
ã¿ãããªããšãå®çŸå¯èœã§ããã°ããã®å¿çšãšã㊠CiscoåŽã§NATãããšãã
æ¹æ³ããããŸãã
äŸãã°
interface Serial0/0
ip address xxx.xxx.xxx.xxx 255.255.255.yyyïŒInternetåŽã®ã¢ãã¬ã¹ïŒ
ip nat outside
!
interface FastEthernet1/0
ip address 192.168.1.126 255.255.255.0
ip nat inside
!
ip nat inside source list 100 interface Serial0/0 overload
!
access-list 100 permit ip 192.168.1.0 0.0.0.0 any
ã¿ãããªèšå®ãããã°ãå
éšLAN -> Internet ã®éä¿¡ã®ã¿ IP Masquerade
ããã圢ã«ãªããå
éšLAN ïœ å€éšLANéã¯ãã®ãŸãŸéä¿¡ãããããŸãã
èªå® ãªã®ã§ãæå ã«è©Šãç°å¢ãç¡ãã®ã§ç¢ºããªããšã¯èšããŸããã...
> æ¡2ïŒåºæ¬çã«æ¡1ãšåãã§ããIPMATEã®ã»ã«ã³ããªIPã«aaa.bbb.ccc.
> 127ãæå®ãRTA52Iã§ãã®IPã¢ãã¬ã¹ã«NATãããããã«ãIPMATEã®éç
> ã«ãŒãã£ã³ã°ã§aaa.bbb.ccc.127ãRTA52Iã«è»¢éãããããããªããšã
> ã§ããã®ãïŒ
ããã¯å¿
èŠãªãã§ãããã
1:1 ã§ NAT ãè¡ãå Žåã«ã¯ Pool Address ãå¿
èŠã«ãªããŸããããã®
æ¹æ³ã§è¡ãããšããŠããã®ã¯ IP Masquerade ã§ãã®ã§ãã¢ãã¬ã¹ã¯ 1ã€
ããã°è¶³ããŸãã
> æ¡3ïŒRTA52Iã§192.168.1.1ã«NATãããã«IPMATEã§192.168.1.1ãaaa.
> bbb.ccc.127(ã»ã«ã³ããªIPïŒã«ïŒïŒïŒNATãããNATã®NATãªããŠå€§äžå€«
> ãªã®ã§ããããã
ãããããŸãæå³ããããŸããã
å€éšLANã«ãããµãŒãã¯å
éšLAN ã®ã¢ãã¬ã¹ãçŽæ¥æå®ã§ããŸãã®ã§ã
å
éšLAN ã®ã¯ã©ã€ã¢ã³ãã¯ãInternetã«åºãæã«å¿
èŠãªã°ããŒãã«ã¢ãã¬ã¹ã
ã®ããšã ããæ°ã«ã㊠NAT ããã°ããã®ã§ãããã
> æ¡4ïŒRTA52IãIPMATEã§ã¯NATãããIPMATEãšå
éšLANã®éã«NATããã¯ã¹
> ãèšçœ®ããNATãè¡ããNATããã¯ã¹ãæ°ãã«å¿
èŠã«ãªãããèšå®ã«æé
> åãããã§ãã
çµå± NAT ããã®ã§ããã°ãããã¯ãŸã£ããæå³ããããŸããã
ã«ãŒã¿ã§è¡ãªãã®ãš NAT ããã¯ã¹ã§è¡ãªãã®ã«ã¯éãããããŸããã®ã§ã
> ã§ããã°NATããã¯ã¹ã賌å
¥ããªãææ®µãããã®ã§ããããæèŠããã
> ãããšå©ãããŸãã
ã«ãŒã¿ã§ NAT ã§ãããªããNATããã¯ã¹ã¯å¿
èŠãªãã§ããããã
ãŸãããããã«ããŠã IPMATE ã®ãµãããããã¹ã¯ aaa.bbb.ccc.126/25 ã¯
24bit MaskïŒ255.255.255.0ïŒã«çŽããŠããã¹ãã§ãã
ãŸãšãããšãéçšäžã®åé¡ãç¡ãããèæ
®ãã€ã€ãæ¡1ïŒãããã¯ãã®æ¡åŒµïŒ
ãæ¡çšããã®ããã¹ãã§ã¯ãªããããšã
以åã«ãLAN鿥ç¶ã«é¢ããŠè³ªåãããŠããã ããŸãããäœãšã解決ã
ãŸããã®ã§å ±åãããŠããã ããŸãã
å°çšç·äž¡ç«¯ã®ã«ãŒã¿ãŒãYAMAHA RTA52i ã«ããã«ãŒã¿BåŽã§IPãã¹ã«ã¬
ãŒãããã«ãŒã¿Aã§Proxyarpãèšå®ããããšã«ããæ¥ç¶ã§ããŸãããå
·
äœçãªèšå®ã³ãã³ãã¯YAMAHAã®ãµããŒãã«äŒºããŸããã
芪åã«æããŠããã ãããããšãããããŸããã
>LinuxãšçŽæ¥é¢ä¿ããªã質åã§æçž®ã§ãããLAN鿥ç¶ã«ã€ããŠæ
>ããŠãã ããã
>
>äžã®ãããã¯ãŒã¯æ§æã§128kã®å°çšç·ãä»ããŠãµããããåå²ã«
>ããLAN鿥ç¶ãè¡ãããšããŠããŸãã
>
>ã(Internetå°çšç·)
> |
> Router(CISCO1720)
> |
> HUB - FireWall - ã€ã³ã¿ãŒããããµãŒããŒ
> |
> Router(NTT IPMATE1300RD)ãA
> |
> (128Kå°çšç·)
> |
> Router(YAMAHA RTA52i)ãB
> |
> ã¯ã©ã€ã¢ã³ãããœã³ã³
>
>äžèšæ§æã§ã«ãŒã¿ãŒã®èšå®ã¯æ¬¡ã®ããã«è¡ã£ãŠããŸã
>
>CISCO1720 æ¬äœIP=aaa.bbb.ccc.1/255.255.255.0
>
>IPMATE æ¬äœIP=aaa.bbb.ccc.126/255.255.255.128
> çžæIP=aaa.bbb.ccc.193/255.255.255.192
> ããã©ãŒã«ãã«ãŒã¿ãŒ=aaa.bbb.ccc.1
>
>RTA52i æ¬äœIP=aaa.bbb.ccc.193/aaa.bbb.ccc.192
> ã¯ã©ã€ã¢ã³ããšã®éã§ïŒïŒïŒNATãè¡ã£ãŠãã
>ãããããïŒã°ããŒãã«ã¢ãã¬ã¹ãšããŠaaa.bbb.ccc.194-254ãå²ãä»ã
>ãããããããŠããïŒ
>
>以äžã®èšå®ã§æ¥ç¶ããŸããšã¯ã©ã€ã¢ã³ãããœã³ã³ããaaa.bbb.ccc.126ãžã®
>pingã¯å±ããŸããä»ã®ã€ã³ã¿ãŒããããµãŒããŒãå€éšã®ãµã€ããžã®æ¥ç¶ã
>ã§ããªãç¶æ³ã§ãã
>
>ãµããããåå²ããLAN鿥ç¶ã®æ¹æ³ãšããŠäžèšã®èšå®ã§ã©ããããããã§
>ããããããŸããäœãèšå®äžã§ç¢ºèªãã¹ãããšããããŸãã§ããããã
>å¿
èŠãªæ
å ±ãããã°ãææãã ããã
>