Mikrotikèªäœã¯åªããããŒããŠã§ã¢ã§ãããäœã³ã¹ãã§å€ãã®æ©èœãåããŠããŸãããæ®å¿µãªããæ¬ ç¹ããªãããã§ã¯ãããŸããã
次ã®ãããã¯ãŒã¯å³ããããŸãã
ROU1-Cisco c3845
ROU2-Cisco c3845
MT1-Mikrotik 1100Ahx2
MT2-Mikrotik 1100Ahx2
c3550-Cisco c3550
GW68-MikroTik RB751U-2HnD
GW69-MikroTik RB751U-2HnD
ROU1ãšROU2ã«ã¯ãMT1ãšMT2ãžã®ãã³ãã«ããããŸãïŒIPSecã¯ã¹ãããããŸãïŒãããã¯ããŒã³ã®OSPFããã»ã¹ãéå§ãããŸããã æšå¥šãµãããã10.0.0.0/19ïŒ
ROU1ããã³ROU2ã®æ§æ
ïŒROU1
ãã³ãã«Tunnel100641
説æïŒXXX_IRK64_YYYïŒ
IPã¢ãã¬ã¹172.20.64.1 255.255.255.252
ip access-group DMZ_IN in
ip access-group DMZ_OUT out
ip mtu 1450
IP ospfãããã¯ãŒã¯ãã€ã³ãããŒãã€ã³ã
ip ospfã³ã¹ã10
ip ospf mtu-ignore
ip ospf 1ãšãªã¢0.0.0.0
ãã³ãã«ãœãŒã¹194.xxx
ãã³ãã«ã¢ãŒãipip
ãã³ãã«å®å 195.xxx
ã«ãŒã¿ãŒospf 1
router-id 255.255.255.255
OSPF 100ã¡ããªãã¯ã¿ã€ã1ãµããããã«ãŒããããOSPF_100_to_BBãåé åžããŸã
ãããã¯ãŒã¯172.20.64.0 0.0.0.3ãšãªã¢0.0.0.0
ïŒROU2
ãã³ãã«Tunnel100642
説æïŒXXX_IRK64_YYYïŒ
IPã¢ãã¬ã¹172.20.64.5 255.255.255.252
ip access-group DMZ_IN in
ip access-group DMZ_OUT out
ip mtu 1450
IP ospfãããã¯ãŒã¯ãã€ã³ãããŒãã€ã³ã
ip ospfã³ã¹ã40
ip ospf mtu-ignore
ip ospf 1ãšãªã¢0.0.0.0
ãã³ãã«ãœãŒã¹109.xxx
ãã³ãã«ã¢ãŒãipip
ãã³ãã«å®å 85.xxx
ã«ãŒã¿ãŒospf 1
router-id 255.255.255.254
OSPF 100ã¡ããªãã¯ã¿ã€ã1ãµããããã«ãŒããããOSPF_100_to_BBãåé åžããŸã
ãããã¯ãŒã¯172.20.64.4 0.0.0.3ãšãªã¢0.0.0.0
ãã³ãã«Tunnel100641
説æïŒXXX_IRK64_YYYïŒ
IPã¢ãã¬ã¹172.20.64.1 255.255.255.252
ip access-group DMZ_IN in
ip access-group DMZ_OUT out
ip mtu 1450
IP ospfãããã¯ãŒã¯ãã€ã³ãããŒãã€ã³ã
ip ospfã³ã¹ã10
ip ospf mtu-ignore
ip ospf 1ãšãªã¢0.0.0.0
ãã³ãã«ãœãŒã¹194.xxx
ãã³ãã«ã¢ãŒãipip
ãã³ãã«å®å 195.xxx
ã«ãŒã¿ãŒospf 1
router-id 255.255.255.255
OSPF 100ã¡ããªãã¯ã¿ã€ã1ãµããããã«ãŒããããOSPF_100_to_BBãåé åžããŸã
ãããã¯ãŒã¯172.20.64.0 0.0.0.3ãšãªã¢0.0.0.0
ïŒROU2
ãã³ãã«Tunnel100642
説æïŒXXX_IRK64_YYYïŒ
IPã¢ãã¬ã¹172.20.64.5 255.255.255.252
ip access-group DMZ_IN in
ip access-group DMZ_OUT out
ip mtu 1450
IP ospfãããã¯ãŒã¯ãã€ã³ãããŒãã€ã³ã
ip ospfã³ã¹ã40
ip ospf mtu-ignore
ip ospf 1ãšãªã¢0.0.0.0
ãã³ãã«ãœãŒã¹109.xxx
ãã³ãã«ã¢ãŒãipip
ãã³ãã«å®å 85.xxx
ã«ãŒã¿ãŒospf 1
router-id 255.255.255.254
OSPF 100ã¡ããªãã¯ã¿ã€ã1ãµããããã«ãŒããããOSPF_100_to_BBãåé åžããŸã
ãããã¯ãŒã¯172.20.64.4 0.0.0.3ãšãªã¢0.0.0.0
MT1ããã³MT2ã§ã¯ããã³ãã«ã¢ãã¬ã¹ã¯ãããã172.20.64.2ããã³172.20.64.6ã§ãã ãšãªã¢ããã¯ããŒã³ã¯ããã©ã«ãã§ãã§ã«ååšããŠããŸãã
MT1ããã³MT2ã®æ§æ
ïŒMT1
ïŒãã³ãã«ãäœæãã
/ interface ipip add comment = YYY_VL03_ROU1 disabled = no local-address = 195.xxx mtu = 1450 name = ipip_yyy_vl03_rou1 remote-address = 194.xxx
ïŒäœæãæããŸã
/ ip address add address = 172.20.64.2 / 30 comment = YYY_VL03_XXX interface = ipip_yyy_vl03_rou1
ïŒãã£ã«ã¿ãŒãšIDãè¿œå ããŠã€ã³ã¹ã¿ã³ã¹ãä¿®æ£
/ã«ãŒãã£ã³ã°ospfã€ã³ã¹ã¿ã³ã¹ã»ãã[ããã©ã«ã= yesãæ€çŽ¢] in-filter = ospf-default-in out-filter = ospf-default-out redistribute-other-ospf = as-type-1 router-id = 30.0.64.1
ïŒãµããããããšãªã¢ããã¯ããŒã³ã«è¿œå
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢=ããã¯ããŒã³ã³ã¡ã³ã=ãããã¯ããŒã³ãããã¯ãŒã¯VLããããã¯ãŒã¯= 172.20.64.0 / 30
ïŒãã£ã«ã¿ãŒãäœæãã
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-outãã¬ãã£ãã¯ã¹= 10.0.64.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ãåãå ¥ãã= ospf-default-outãã¬ãã£ãã¯ã¹= 172.20.64.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ç Žæ£ãã§ãŒã³= ospf-default-out
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-inãã¬ãã£ãã¯ã¹= 10.0.0.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-inãã¬ãã£ãã¯ã¹= 172.20.0.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ç Žæ£ãã§ãŒã³= ospf-default-in
ïŒOSPFã€ã³ã¿ãŒãã§ãŒã¹ãäœæãã
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹è¿œå èªèšŒããŒ= 0ã€ã³ã¿ãŒãã§ã€ã¹= ipip_yyy_vl03_rou1ãããã¯ãŒã¯ã¿ã€ã=ãã€ã³ãããŒãã€ã³ããã©ã€ãªãªãã£= 255
ïŒMT2
ïŒãã³ãã«ãäœæãã
/ interface ipip add comment = YYY_VL03_ROU2 disabled = no local-address = 85.xxx mtu = 1450 name = ipip_yyy_vl03_rou2 remote-address = 109.xxx
ïŒäœæãæããŸã
/ ip address add address = 172.20.64.6 / 30 comment = YYY_VL03_ROU2 interface = ipip_yyy_vl03_rou2
ïŒãã£ã«ã¿ãŒãšIDãè¿œå ããŠã€ã³ã¹ã¿ã³ã¹ãä¿®æ£
/ã«ãŒãã£ã³ã°ospfã€ã³ã¹ã¿ã³ã¹ã»ãã[ããã©ã«ã= yesãæ€çŽ¢] in-filter = ospf-default-in out-filter = ospf-default-out redistribute-other-ospf = as-type-1 router-id = 30.0.64.2
ïŒãµããããããšãªã¢ããã¯ããŒã³ã«è¿œå
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢=ããã¯ããŒã³ã³ã¡ã³ã=ãããã¯ããŒã³ãããã¯ãŒã¯VLããããã¯ãŒã¯= 172.20.64.4 / 30
ïŒãã£ã«ã¿ãŒãäœæãã
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-outãã¬ãã£ãã¯ã¹= 10.0.64.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ãåãå ¥ãã= ospf-default-outãã¬ãã£ãã¯ã¹= 172.20.64.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ç Žæ£ãã§ãŒã³= ospf-default-out
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-inãã¬ãã£ãã¯ã¹= 10.0.0.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-inãã¬ãã£ãã¯ã¹= 172.20.0.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ç Žæ£ãã§ãŒã³= ospf-default-in
ïŒOSPFã€ã³ã¿ãŒãã§ãŒã¹ãäœæãã
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ãŒã¹èªèšŒããŒã®è¿œå = 0ã³ã¹ã= 40ã€ã³ã¿ãŒãã§ãŒã¹= ipip_yyy_vl03_rou2ãããã¯ãŒã¯ã¿ã€ã=ãã€ã³ãããŒãã€ã³ãã®åªå 床= 200
ïŒãã³ãã«ãäœæãã
/ interface ipip add comment = YYY_VL03_ROU1 disabled = no local-address = 195.xxx mtu = 1450 name = ipip_yyy_vl03_rou1 remote-address = 194.xxx
ïŒäœæãæããŸã
/ ip address add address = 172.20.64.2 / 30 comment = YYY_VL03_XXX interface = ipip_yyy_vl03_rou1
ïŒãã£ã«ã¿ãŒãšIDãè¿œå ããŠã€ã³ã¹ã¿ã³ã¹ãä¿®æ£
/ã«ãŒãã£ã³ã°ospfã€ã³ã¹ã¿ã³ã¹ã»ãã[ããã©ã«ã= yesãæ€çŽ¢] in-filter = ospf-default-in out-filter = ospf-default-out redistribute-other-ospf = as-type-1 router-id = 30.0.64.1
ïŒãµããããããšãªã¢ããã¯ããŒã³ã«è¿œå
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢=ããã¯ããŒã³ã³ã¡ã³ã=ãããã¯ããŒã³ãããã¯ãŒã¯VLããããã¯ãŒã¯= 172.20.64.0 / 30
ïŒãã£ã«ã¿ãŒãäœæãã
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-outãã¬ãã£ãã¯ã¹= 10.0.64.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ãåãå ¥ãã= ospf-default-outãã¬ãã£ãã¯ã¹= 172.20.64.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ç Žæ£ãã§ãŒã³= ospf-default-out
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-inãã¬ãã£ãã¯ã¹= 10.0.0.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-inãã¬ãã£ãã¯ã¹= 172.20.0.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ç Žæ£ãã§ãŒã³= ospf-default-in
ïŒOSPFã€ã³ã¿ãŒãã§ãŒã¹ãäœæãã
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹è¿œå èªèšŒããŒ= 0ã€ã³ã¿ãŒãã§ã€ã¹= ipip_yyy_vl03_rou1ãããã¯ãŒã¯ã¿ã€ã=ãã€ã³ãããŒãã€ã³ããã©ã€ãªãªãã£= 255
ïŒMT2
ïŒãã³ãã«ãäœæãã
/ interface ipip add comment = YYY_VL03_ROU2 disabled = no local-address = 85.xxx mtu = 1450 name = ipip_yyy_vl03_rou2 remote-address = 109.xxx
ïŒäœæãæããŸã
/ ip address add address = 172.20.64.6 / 30 comment = YYY_VL03_ROU2 interface = ipip_yyy_vl03_rou2
ïŒãã£ã«ã¿ãŒãšIDãè¿œå ããŠã€ã³ã¹ã¿ã³ã¹ãä¿®æ£
/ã«ãŒãã£ã³ã°ospfã€ã³ã¹ã¿ã³ã¹ã»ãã[ããã©ã«ã= yesãæ€çŽ¢] in-filter = ospf-default-in out-filter = ospf-default-out redistribute-other-ospf = as-type-1 router-id = 30.0.64.2
ïŒãµããããããšãªã¢ããã¯ããŒã³ã«è¿œå
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢=ããã¯ããŒã³ã³ã¡ã³ã=ãããã¯ããŒã³ãããã¯ãŒã¯VLããããã¯ãŒã¯= 172.20.64.4 / 30
ïŒãã£ã«ã¿ãŒãäœæãã
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-outãã¬ãã£ãã¯ã¹= 10.0.64.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ãåãå ¥ãã= ospf-default-outãã¬ãã£ãã¯ã¹= 172.20.64.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ç Žæ£ãã§ãŒã³= ospf-default-out
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-inãã¬ãã£ãã¯ã¹= 10.0.0.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®åãå ¥ã= ospf-default-inãã¬ãã£ãã¯ã¹= 172.20.0.0 / 19
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ç Žæ£ãã§ãŒã³= ospf-default-in
ïŒOSPFã€ã³ã¿ãŒãã§ãŒã¹ãäœæãã
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ãŒã¹èªèšŒããŒã®è¿œå = 0ã³ã¹ã= 40ã€ã³ã¿ãŒãã§ãŒã¹= ipip_yyy_vl03_rou2ãããã¯ãŒã¯ã¿ã€ã=ãã€ã³ãããŒãã€ã³ãã®åªå 床= 200
ãã ããMT1ãšMT2ãçŽæ¥æ¥ç¶ããå¿ èŠããããŸãã
ãããè¡ãã«ã¯ãæ°ãããšãªã¢IRKã䜿çšããŸãã Cisco c3550ã¹ã€ããã ãã§ãªããã«ãŒãããã€ã¹ãããããã¹ãŠã®VLANãã€ã³ã¹ããŒã«ããããããã€ããŒã転éãããvrfãäœæãããŸãã ïŒèå³æ·±ãå Žåã¯ããããã¯ãŒã¯ã®çµç¹å šäœã«ã€ããŠèª¬æããŸãïŒ
MT3ãšMT2ã«æ¥ç¶ããããã®c3550ãšãªã¢IRKãš2ã€ã®VLANãäœæããŸãã ãšãªã¢IRKã¯RUã®ã¡ã€ã³ãšãªã¢ã§ããRUã«æ¥ç¶ãããŠãããã¹ãŠã®ã«ãŒã¿ãŒãåäœãããªãŒãžã§ãã«ããŒãã§ãã
C3550ã®æ§æ
ã€ã³ã¿ãŒãã§ã€ã¹vlan66
説æïŒMGM 1 VLANïŒ
IPã¢ãã¬ã¹172.20.64.98 255.255.255.252
IPããªã·ãŒã«ãŒãããããã¹ã
ip ospfã³ã¹ã10
ip ospf hello-interval 5
ip ospf dead-interval 10
ip ospf priority 100
ïŒ
ã€ã³ã¿ãŒãã§ã€ã¹Vlan67
説æïŒMGM 2 VLANïŒ
IPã¢ãã¬ã¹172.20.64.102 255.255.255.252
ip ospfã³ã¹ã10
ip ospf hello-interval 5
ip ospf dead-interval 10
ip ospf priority 50
ã«ãŒã¿ãŒOSPF 100
router-id 10.0.64.0
ãã°é£æ¥å€æŽ
æ¥ç¶ãããã¡ããªãã¯ã¿ã€ã1ãµãããããåé åžããŸã
éçã¡ããªãã¯ã¿ã€ã1ãµãããããåé åžããŸã
ãããã¯ãŒã¯172.20.64.96 0.0.0.3ãšãªã¢10.0.64.0
ãããã¯ãŒã¯172.20.64.100 0.0.0.3ãšãªã¢10.0.64.0
ïŒ2ã€ã®ãã«ã«ãŒã
ip route 10.0.64.0 255.255.224.0 Null0 250
ip route 172.20.64.0 255.255.224.0 Null0 250
説æïŒMGM 1 VLANïŒ
IPã¢ãã¬ã¹172.20.64.98 255.255.255.252
IPããªã·ãŒã«ãŒãããããã¹ã
ip ospfã³ã¹ã10
ip ospf hello-interval 5
ip ospf dead-interval 10
ip ospf priority 100
ïŒ
ã€ã³ã¿ãŒãã§ã€ã¹Vlan67
説æïŒMGM 2 VLANïŒ
IPã¢ãã¬ã¹172.20.64.102 255.255.255.252
ip ospfã³ã¹ã10
ip ospf hello-interval 5
ip ospf dead-interval 10
ip ospf priority 50
ã«ãŒã¿ãŒOSPF 100
router-id 10.0.64.0
ãã°é£æ¥å€æŽ
æ¥ç¶ãããã¡ããªãã¯ã¿ã€ã1ãµãããããåé åžããŸã
éçã¡ããªãã¯ã¿ã€ã1ãµãããããåé åžããŸã
ãããã¯ãŒã¯172.20.64.96 0.0.0.3ãšãªã¢10.0.64.0
ãããã¯ãŒã¯172.20.64.100 0.0.0.3ãšãªã¢10.0.64.0
ïŒ2ã€ã®ãã«ã«ãŒã
ip route 10.0.64.0 255.255.224.0 Null0 250
ip route 172.20.64.0 255.255.224.0 Null0 250
次ã«ãMT1ãšMT2ã§ãããã®VLANãåãå ¥ããæ°ããospfã€ã³ã¹ã¿ã³ã¹ãšãšãªã¢ãäœæããMT1ãšMT2ã®éã«ãªã³ã¯ãè¿œå ããŠãã¢ãã¬ã¹ãæ·»ä»ããŸãã
MT1ããã³MT2ã®æ§æ
ïŒMT1
ïŒVLANãåãå ¥ãã
/ interface vlan add interface = ether1 l2mtu = 1594 name = vlan_66_mgm vlan-id = 66
ïŒãšãªã¢ãäœæãã
/ã«ãŒãã£ã³ã°OSPFãšãªã¢ã®è¿œå ãšãªã¢ID = 10.0.64.0ã€ã³ã¹ã¿ã³ã¹= IRKå= IRK
ïŒã€ã³ã¹ã¿ã³ã¹ãäœæ
/ routing ospf instance add distribute-default = if-installed-as-type-1 name = IRK redistribute-other-ospf = as-type-1 redistribute-static = as-type-1 router-id = 10.0.64.1
ïŒIPãæãã
/ ip address add address = 172.20.64.97 / 30 comment = MGM_Interface interface = vlan_66_mgm
/ ip address add address = 172.20.64.105 / 30 comment = MT-MT_Interface interface = ether2
ïŒãµããããããšãªã¢IRKã«è¿œå
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 172.20.64.96 / 30
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 172.20.64.104 / 30
ïŒOSPFã€ã³ã¿ãŒãã§ã€ã¹ãäœæãã
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹add dead-interval = 10s hello-interval = 5s interface = vlan_66_mgm network-type = broadcast priority = 255
ïŒMT2
ïŒVLANãåãå ¥ãã
/ interface vlan add interface = ether1 l2mtu = 1594 name = vlan_67_mgm vlan-id = 67
ïŒãšãªã¢ãäœæãã
/ã«ãŒãã£ã³ã°OSPFãšãªã¢ã®è¿œå ãšãªã¢ID = 10.0.64.0ã€ã³ã¹ã¿ã³ã¹= IRKå= IRK
ïŒã€ã³ã¹ã¿ã³ã¹ãäœæ
/ã«ãŒãã£ã³ã°ospfã€ã³ã¹ã¿ã³ã¹è¿œå distribute-default = if-installed-as-type-1 name = IRK redistribute-other-ospf = as-type-1 redistribute-static = as-type-1 router-id = 10.0.64.2
ïŒIPãæãã
/ ip address add address = 172.20.64.101 / 30 comment = MGM_Interface interface = vlan_67_mgm
/ ip address add address = 172.20.64.106 / 30 comment = MT-MT_Interface interface = ether2
ïŒãµããããããšãªã¢IRKã«è¿œå
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå é å= IRKãããã¯ãŒã¯= 172.20.64.100 / 30
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 172.20.64.104 / 30
ïŒOSPFã€ã³ã¿ãŒãã§ã€ã¹ãäœæãã
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹add dead-interval = 10s hello-interval = 5s interface = vlan_67_mgm network-type = broadcast priority = 200
ïŒVLANãåãå ¥ãã
/ interface vlan add interface = ether1 l2mtu = 1594 name = vlan_66_mgm vlan-id = 66
ïŒãšãªã¢ãäœæãã
/ã«ãŒãã£ã³ã°OSPFãšãªã¢ã®è¿œå ãšãªã¢ID = 10.0.64.0ã€ã³ã¹ã¿ã³ã¹= IRKå= IRK
ïŒã€ã³ã¹ã¿ã³ã¹ãäœæ
/ routing ospf instance add distribute-default = if-installed-as-type-1 name = IRK redistribute-other-ospf = as-type-1 redistribute-static = as-type-1 router-id = 10.0.64.1
ïŒIPãæãã
/ ip address add address = 172.20.64.97 / 30 comment = MGM_Interface interface = vlan_66_mgm
/ ip address add address = 172.20.64.105 / 30 comment = MT-MT_Interface interface = ether2
ïŒãµããããããšãªã¢IRKã«è¿œå
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 172.20.64.96 / 30
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 172.20.64.104 / 30
ïŒOSPFã€ã³ã¿ãŒãã§ã€ã¹ãäœæãã
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹add dead-interval = 10s hello-interval = 5s interface = vlan_66_mgm network-type = broadcast priority = 255
ïŒMT2
ïŒVLANãåãå ¥ãã
/ interface vlan add interface = ether1 l2mtu = 1594 name = vlan_67_mgm vlan-id = 67
ïŒãšãªã¢ãäœæãã
/ã«ãŒãã£ã³ã°OSPFãšãªã¢ã®è¿œå ãšãªã¢ID = 10.0.64.0ã€ã³ã¹ã¿ã³ã¹= IRKå= IRK
ïŒã€ã³ã¹ã¿ã³ã¹ãäœæ
/ã«ãŒãã£ã³ã°ospfã€ã³ã¹ã¿ã³ã¹è¿œå distribute-default = if-installed-as-type-1 name = IRK redistribute-other-ospf = as-type-1 redistribute-static = as-type-1 router-id = 10.0.64.2
ïŒIPãæãã
/ ip address add address = 172.20.64.101 / 30 comment = MGM_Interface interface = vlan_67_mgm
/ ip address add address = 172.20.64.106 / 30 comment = MT-MT_Interface interface = ether2
ïŒãµããããããšãªã¢IRKã«è¿œå
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå é å= IRKãããã¯ãŒã¯= 172.20.64.100 / 30
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 172.20.64.104 / 30
ïŒOSPFã€ã³ã¿ãŒãã§ã€ã¹ãäœæãã
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹add dead-interval = 10s hello-interval = 5s interface = vlan_67_mgm network-type = broadcast priority = 200
ç§ãã¡ãåŸããã®ã¯äœãå¿ããŠããªãã£ãããã§ãïŒ
1.äžå€®ã«ãŒã¿ãŒãžã®ãã³ãã«ã2ã€ãããåMikrotikãã1ã€ã§ãã
2.ã³ã¹ãã¯ãããã10ããã³40ã§ãã ã€ãŸããã©ã€ãã¡ã€ã³ã«ãŒã¿ãŒïŒãããã€ããŒïŒMT1ã䜿çšããŠãããã¯ããŒã³10.0.0.0/19ãããã³ãã«ãä»ããŠROU1ãžã®ã«ãŒããååŸãããããã«ãŒããROU2ãžã®ãã³ãã«ãä»ããŠååŸããŸãã
3.åžžã«c3550ãä»ããŠãã©ãã£ãã¯ãé§åããªãããã«ãMT1ãšMT2ã®éã«çŽæ¥ãªã³ã¯ããããŸãã
ã»ããã¢ãããã»ããã ãã¹ãŠãæ©èœããŸãïŒ
ïŒMT1
ADo dst-address = 10.0.0.0 / 19ã²ãŒããŠã§ã€= 172.20.64.1 gateway-status = 172.20.64.1 ipip_yyy_vl03_rou1çµç±ã§å°éå¯èœè·é¢= 110ã¹ã³ãŒã= 20ã¿ãŒã²ããã¹ã³ãŒã= 10 ospf-metric = 40 ospf-type = external-type-1
ïŒMT2
ADo dst-address = 10.0.0.0 / 19 gateway = 172.20.64.105 gateway-status = 172.20.64.105 ether2çµç±ã§å°éå¯èœdistance = 110 scope = 20 target-scope = 10 ospf-metric = 50 ospf-type = external-type-1
MT2ã§ã¯ãååãšããŠãether2ãä»ããã«ãŒãã¯æ倧10kã§ãã
åé¡çªå·1ïŒ
äžåºŠãMT1ã§ãããã€ããŒãæ»ã«ãŸãã ãµãããã10.0.0.0/19ã¯ãROU2ãžã®ãã³ãã«ãä»ããŠã¢ã¯ã»ã¹å¯èœã«ãªãããã¹ãŠã次ã®ããã«ãªããŸãã
ïŒMT2
ADo dst-address = 10.0.0.0 / 19 gateway = 172.20.64.5 gateway-status = 172.20.64.5 ipip_yyy_vl03_rou2 distance = 110 scope = 20 target-scope = 10 ospf-metric = 70 ospf-type = external-type-1ãä»ããŠå°éå¯èœ
ãããïŒ MT1ãããã€ããŒãç»å Žãããšããã«ã次ã®ããšãããããŸãã
ïŒMT1
ADo dst-address = 10.0.0.0 / 19ã²ãŒããŠã§ã€= 172.20.64.1 gateway-status = 172.20.64.1 ipip_yyy_vl03_rou1çµç±ã§å°éå¯èœè·é¢= 110ã¹ã³ãŒã= 20ã¿ãŒã²ããã¹ã³ãŒã= 10 ospf-metric = 40 ospf-type = external-type-1
ïŒMT2
ADo dst-address = 10.0.0.0 / 19 gateway = 172.20.64.5 gateway-status = 172.20.64.5 ipip_yyy_vl03_rou2 distance = 110 scope = 20 target-scope = 10 ospf-metric = 70 ospf-type = external-type-1ãä»ããŠå°éå¯èœ
åã«ãŒã¿ãŒãç¬èªã®ãã³ãã«ã調ã¹ãããšãããããŸãã ããã¯ç§ãã¡ã«ã¯ãŸã£ããé©ããŠããŸããã MT2ãåèµ·åããŸãã 圌ã¯MT1ããether2ãä»ããŠã«ãŒããåä¿¡ãå§ããŸãã æ··ä¹±ã
äžæçãªè§£æ±ºçãšããŠãå°åããŒãããROU1ããã³ROU2ã«ãã¹ãŠã®ãšãªã¢ãè¿œå ããŸããã ããæ¥ãtsiskaããã«ãŒãã£ã³ã°ããã»ã¹ãå€ãããããšèšããŸã§ããã¹ãŠãããŸãæ©èœããŠããŸããã
ãããŠãåã³ããã¯ããŒã³ã®åé¡ã«æ»ããŸããã ãµããŒããšã®é·ãæŠãã¯äœã«ãã€ãªãããŸããããããæç¹ã§ããšãªã¢ã¹éã§ã«ãŒããåé åžãããšãã«ãã¯ããã£ãã¯ãšããåçãåŸãããŸãïŒãã®å Žåãããã¯ããŒã³ããã®ã«ãŒãã¯IRKãä»ããŠåé åžãããŸãïŒ
ã«ãŒãã誀ã£ãŠã€ã³ã¹ããŒã«ãå§ããŸãã ãããŠãåã«ãŒã¿ãŒãç¬èªã®ãã³ãã«ã調ã¹ãç»åãååŸããŸãã
ãããã解決çã¯ããèªèº«ã§æ¥ãŸãïŒ
ether2ã«IPãè¿œå ããããã¯ããŒã³ã«æ°ãããµãããããè¿œå ããŸãã
ïŒMT1
/ ip address add address = 172.20.64.121 / 30 comment = "MT-MT BB" interface = ether2
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå é å=ããã¯ããŒã³ãããã¯ãŒã¯= 172.20.64.120 / 30
ïŒIRKãä»ããã«ãŒãã®åé åžãçŠæ¢ããŸã
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®ç Žæ£= ospf-inãã¬ãã£ãã¯ã¹= 10.0.0.0 / 19
ïŒMT2
/ ip address add address = 172.20.64.122 / 30 comment = "MT-MT BB" interface = ether2
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå é å=ããã¯ããŒã³ãããã¯ãŒã¯= 172.20.64.120 / 30
ïŒIRKãä»ããã«ãŒãã®åé åžãçŠæ¢ããŸã
/ã«ãŒãã£ã³ã°ãã£ã«ã¿ãŒã®è¿œå ã¢ã¯ã·ã§ã³=ãã§ãŒã³ã®ç Žæ£= ospf-inãã¬ãã£ãã¯ã¹= 10.0.0.0 / 19
ãããŠãã«ãŒã10.0.0.0/19ã¯ãä»ã®èª°ãã®eriaãä»ããŠåé åžãããã®ã§ã¯ãªãããã®eriaå ã§åãå ¥ããããŸãã Fufã1ã€ã®åé¡ãåã¡ãŸããã
2çªç®ã®åé¡ãæ€èšããããã«ãGWæ§æãæäŸããŸããMT1ããã³MT2ã®æ§æã¯çç¥ããŸãããããã«ã¯è€éãªãã®ã¯ãããŸããã
å³ã§ã¯GW68ãšGW69ããããŸãããèšå®ã¯1ã€ã ãã®ç¥èªã§ç€ºããŸãã
Mikrotik 751ã«ã€ããŠïŒ
ether2-ããã¯ã¢ãããããã€ããŒ
ether3-ã¡ã€ã³ãããã€ããŒ
ether5-LAN
åé¡ã¯ããªãether2ãã¡ã€ã³ãããã€ããŒã§ã¯ãªãããšããããšã§ãã æåã«ãã¡ã€ã³ãããã€ããŒã§ããether1ãäœæããŸããããããŒããååãœãããŠã§ã¢ã§ãããIPSecã®ããã©ãŒãã³ã¹ããŸã£ãããªãããšãããããŸãããèšå®ãããŸãç·šéããªãããã«ãether3ã«è»¢éããŸããã
GW68ã®æ§æ
ïŒãã³ãã«ãäœæãã
/ interface ipip add comment = X_GW64_X disabled = no local-address = 195.xxx mtu = 1440 name = ipip_x_gw64_x remote-address = 195.xxx
/ interface ipip add comment = Y_GW64_Y disabled = no local-address = 87.xxx mtu = 1440 name = ipip_y_gw64_y remote-address = 85.xxx
ïŒããªããžãäœæããwifi apãšether5ãçµã¿åãããŸã
/ interface bridge add l2mtu = 1594 name = bridge_private
/ interface bridge port add bridge = bridge_private interface = ether5
/ interface bridge port add bridge = bridge_private interface = wlan_private
ïŒDHCPãäœæ
/ IPããŒã«ã®è¿œå å= 10.0.68.0ã®ç¯å²= 10.0.68.64-10.0.68.160
/ ip dhcp-server add address-pool = 10.0.68.0 disabled = no interface = bridge_private name = 10.0.68.0
/ ip dhcp-server network add address = 10.0.68.0 / 24 dns-server = 10.0.64.14,10.0.3.6 domain = partner.ru gateway = 10.0.68.1
ïŒãã³ã°IP
/ ip address add address = 10.0.68.1 / 24 comment = LAN interface = bridge_private
/ ip address add address = 172.20.68.2 / 30 comment = X_GW64_X interface = ipip_x_gw64_x
/ ip address add address = 172.20.68.6 / 30 comment = Y_GW64_Y interface = ipip_y_gw64_y
/ ip address add address = 195.xxx / 30 comment = X interface = ether3
/ ip address add address = 87.xxx / 30 comment = Y interface = ether2
ïŒãããã€ããŒã®ã²ãŒããŠã§ã€ãä»ããŠã¢ãã¬ã¹MT1ããã³MT2ã«ã«ãŒããè¿œå ããŸã
/ ip route add check-gateway = ping comment = Route_over_Y_to_Y distance = 1 dst-address = 85.xxx / 32 gateway = 1.1.1.1
/ ip route add check-gateway = ping comment = Route_over_X_to_X distance = 1 dst-address = 195.xxx / 32 gateway = 2.2.2.2
ïŒãšãªã¢ãšã€ã³ã¹ã¿ã³ã¹ããããã¯ãŒã¯ãOSPFã€ã³ã¿ãŒãã§ãŒã¹ãè¿œå
/ã«ãŒãã£ã³ã°ospfã€ã³ã¹ã¿ã³ã¹ã»ãã[find default = yes] disabled = yes
/ã«ãŒãã£ã³ã°ospfã€ã³ã¹ã¿ã³ã¹add name = IRK router-id = 10.0.68.1
/ã«ãŒãã£ã³ã°OSPFãšãªã¢ã®è¿œå ãšãªã¢ID = 10.0.64.0ã€ã³ã¹ã¿ã³ã¹= IRKå= IRK
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 172.20.68.0 / 30
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 172.20.68.4 / 30
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 10.0.68.0 / 24
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹èªèšŒãè¿œå = md5 authentication-key = 0ã€ã³ã¿ãŒãã§ã€ã¹= ipip_x_gw64_xãããã¯ãŒã¯ã¿ã€ã=ãã€ã³ãããŒãã€ã³ããã©ã€ãªãªãã£= 0
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹èªèšŒã®è¿œå = md5èªèšŒããŒ= 0ã³ã¹ã= 40ã€ã³ã¿ãŒãã§ã€ã¹= ipip_y_gw64_yãããã¯ãŒã¯ã¿ã€ã=ãã€ã³ãããŒãã€ã³ããã©ã€ãªãªãã£= 0
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹èªèšŒã®è¿œå = md5èªèšŒããŒ= 0ã€ã³ã¿ãŒãã§ã€ã¹= bridge_privateãããã¯ãŒã¯ã¿ã€ã=ãããŒããã£ã¹ãããã·ã=ã¯ã
/ interface ipip add comment = X_GW64_X disabled = no local-address = 195.xxx mtu = 1440 name = ipip_x_gw64_x remote-address = 195.xxx
/ interface ipip add comment = Y_GW64_Y disabled = no local-address = 87.xxx mtu = 1440 name = ipip_y_gw64_y remote-address = 85.xxx
ïŒããªããžãäœæããwifi apãšether5ãçµã¿åãããŸã
/ interface bridge add l2mtu = 1594 name = bridge_private
/ interface bridge port add bridge = bridge_private interface = ether5
/ interface bridge port add bridge = bridge_private interface = wlan_private
ïŒDHCPãäœæ
/ IPããŒã«ã®è¿œå å= 10.0.68.0ã®ç¯å²= 10.0.68.64-10.0.68.160
/ ip dhcp-server add address-pool = 10.0.68.0 disabled = no interface = bridge_private name = 10.0.68.0
/ ip dhcp-server network add address = 10.0.68.0 / 24 dns-server = 10.0.64.14,10.0.3.6 domain = partner.ru gateway = 10.0.68.1
ïŒãã³ã°IP
/ ip address add address = 10.0.68.1 / 24 comment = LAN interface = bridge_private
/ ip address add address = 172.20.68.2 / 30 comment = X_GW64_X interface = ipip_x_gw64_x
/ ip address add address = 172.20.68.6 / 30 comment = Y_GW64_Y interface = ipip_y_gw64_y
/ ip address add address = 195.xxx / 30 comment = X interface = ether3
/ ip address add address = 87.xxx / 30 comment = Y interface = ether2
ïŒãããã€ããŒã®ã²ãŒããŠã§ã€ãä»ããŠã¢ãã¬ã¹MT1ããã³MT2ã«ã«ãŒããè¿œå ããŸã
/ ip route add check-gateway = ping comment = Route_over_Y_to_Y distance = 1 dst-address = 85.xxx / 32 gateway = 1.1.1.1
/ ip route add check-gateway = ping comment = Route_over_X_to_X distance = 1 dst-address = 195.xxx / 32 gateway = 2.2.2.2
ïŒãšãªã¢ãšã€ã³ã¹ã¿ã³ã¹ããããã¯ãŒã¯ãOSPFã€ã³ã¿ãŒãã§ãŒã¹ãè¿œå
/ã«ãŒãã£ã³ã°ospfã€ã³ã¹ã¿ã³ã¹ã»ãã[find default = yes] disabled = yes
/ã«ãŒãã£ã³ã°ospfã€ã³ã¹ã¿ã³ã¹add name = IRK router-id = 10.0.68.1
/ã«ãŒãã£ã³ã°OSPFãšãªã¢ã®è¿œå ãšãªã¢ID = 10.0.64.0ã€ã³ã¹ã¿ã³ã¹= IRKå= IRK
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 172.20.68.0 / 30
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 172.20.68.4 / 30
/ã«ãŒãã£ã³ã°OSPFãããã¯ãŒã¯è¿œå ãšãªã¢= IRKãããã¯ãŒã¯= 10.0.68.0 / 24
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹èªèšŒãè¿œå = md5 authentication-key = 0ã€ã³ã¿ãŒãã§ã€ã¹= ipip_x_gw64_xãããã¯ãŒã¯ã¿ã€ã=ãã€ã³ãããŒãã€ã³ããã©ã€ãªãªãã£= 0
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹èªèšŒã®è¿œå = md5èªèšŒããŒ= 0ã³ã¹ã= 40ã€ã³ã¿ãŒãã§ã€ã¹= ipip_y_gw64_yãããã¯ãŒã¯ã¿ã€ã=ãã€ã³ãããŒãã€ã³ããã©ã€ãªãªãã£= 0
/ã«ãŒãã£ã³ã°ospfã€ã³ã¿ãŒãã§ã€ã¹èªèšŒã®è¿œå = md5èªèšŒããŒ= 0ã€ã³ã¿ãŒãã§ã€ã¹= bridge_privateãããã¯ãŒã¯ã¿ã€ã=ãããŒããã£ã¹ãããã·ã=ã¯ã
ä»çµã¿ïŒ
GW68ã¯ããããããç¬èªã®ãããã€ããŒãä»ããŠMT1ãšMT2ã«2ã€ã®ãã³ãã«ãã€ã³ã¹ããŒã«ããŸãã Mikrotikã«ã¯ããã©ã«ãã¯ãããŸãããMT1ãšMT2ã®ã¢ãã¬ã¹ã¯éçã«ç»é²ãããŸãã
MT1ãžã®ãã³ãã«ã®ã³ã¹ãã¯10ãMT2ãžã®ãã³ãã«ã®ã³ã¹ãã¯40ã§ãããã³ãã«ãæå¹ã«ãªããšããã«ãMT1ããOSPFãŸã§ã®ããã©ã«ãããã³ãã¹ãŠã®ã«ãŒããååŸãããŸãã ãã¹ãŠã®ãã©ãã£ãã¯ã¯MT1ã§ã©ãããããŸãã ã¡ã€ã³ãããã€ããŒãè±èœãããšããã«ã
OSPFã¿ã€ããŒãåãããšããã³ãã«ãä»ããŠMT2ãžã®ã«ãŒããã¢ã¯ãã£ãã«ãªããŸãã
åé¡2ïŒ
ã©ã€ãã¡ã€ã³ãã£ãã«ã§ã¯ãGW68ãã°ã«è¡šç€ºãããŸã
20:12:26 routeãospfãinfoããŒã¿ããŒã¹èšè¿°ãã±ããã«ã¯ç°ãªããã¹ã¿ãŒã¹ããŒã¿ã¹ãã©ã°ããããŸã
20:12:26 routeãospfãinfo new master flag = false
ãã®æç¹ã§ããã©ãã£ãã¯èªäœãMT2ãžã®ãã³ãã«ãééãå§ããŸãã MT1ãžã®ãã³ãã«ã¯ã©ã€ãã§ããããã©ãã£ãã¯ã¯MT2ãžã®ãã³ãã«ãééããŸãã ãŸããåºèã«ã¯éåžžã¡ã¬ãã€ãã®äºåãããããã
ãã®åŸãçç±ããªãéãæ¯æžããŸãã
ãã¹ãŠãMT1ã®ãã³ãã«ã«æ»ãã«ã¯ãMT1ã®GW68ãžã®ãã³ãã«ã®ãªã³ãšãªããåãæ¿ããå¿ èŠããããŸããã ããã«ããã®åé¡ã¯äžéšã®éœåžã§ã®ã¿çºçãããã¹ãŠã®ã«ãŒã¿ãŒã§ã¯çºçããŸããã§ããã
ãããã§ãmicroticaãã©ãŒã©ã ã§ã 誰ããµããŒãããŠãããŸããã§ããã ååãMT1-Juniper SRX-650ãã³ãã«ãåŒãäžããããšãããšã倧éã®ã¢ã«ã³ãŒã«ãæ¢ç¥æ©ããããã¬ãè£ åããŸãã:)
ãŸããIPSecã®ãããã°äžã«ãOSPF MikrotikèªèšŒãšã©ãŒã«ééããŸããã OSPFã€ã³ã¿ãŒãã§ãŒã¹ãšåºæ¥äžããã€ã³ã¿ãŒãã§ãŒã¹ã®èªèšŒãç¡å¹ã«ãããšãåé¡ã¯èªåçã«è§£æ¶ãããŸããã
èªå¯ã¯ã©ã®ããã«è¡ããã倱æã¯ã©ãã«ããã®ããä»ã§ã¯åœŒãç§ãèŠããŠããªãã ããããåé¡ã¯è§£æ±ºãããŸããã ã©ãã§ãããå®ç§ã«æ©èœããæ¿èªãããã®ããç§ã«ã¯èšããŸããã
Mikrotikã䜿çšãããšãåãµããŒãã®åçã¯æ°ãã質åã§ãããæ°ãããã¡ãŒã ãŠã§ã¢ã¯ããããæ°ããåé¡ãæ瀺ãããããã³ãŒããŒãæšæž¬ããããšããã§ããŸãã:)