ã¿ã¹ã¯ããããŸãïŒRouterOSã«åºã¥ããŠã家åºãå°èŠæš¡ãªãã£ã¹åãã®SOHOã«ãŒã¿ãŒã®ä»£æ¿ãšããŠããã€ã¹ãæ§æããããšã§ãã ããã¯HOWTOã§ããæå°éã®æè¡çãªè©³çŽ°ãNext-Next-Next-Okããããããã«äœ¿çšã§ããããã€ã¹ãå ¥æã§ããã®ã§ãå§ããŸãããã
æºåãã
説æãããŠãããã®ã¯ãã¹ãŠRouterBOARD RB 951G-2HnDã§ãã¹ããããŠããŸãããRouterOS 6.25以éã«åºã¥ããããã€ã¹ã®æ§æã®æ瀺ãšããŠäœ¿çšã§ããŸãã ããã€ã¹ãæ§æããã«ã¯ãç¬èªã®winboxãŠãŒãã£ãªãã£ïŒWindowsã®å ŽåïŒããŸãã¯mactelnet-clientïŒLinuxã®å ŽåïŒãå¿ èŠã§ãããã¡ãããRouterOSã«ã¯telnet / http / sshããããŸãããä»ã®ãšãããããã«ã€ããŠã¯å¿ããŠãã ããã
PCã5çªç®ã®MikrotikããŒãã«æ¥ç¶ãïŒæåã®ããŒããé€ãä»»æã®ããŒãã䜿çšã§ããŸãïŒãããã€ã¹ãè£è¿ããŠããŒã³ãŒãã¹ããã«ãŒäžã®MACã¢ãã¬ã¹ã®ç¯å²ã確èªããŸããåŸè ã¯5çªç®ã®ããŒããåç §ããwinboxæ¥ç¶ãŠã£ã³ããŠã«å ¥åããããmactelnetãåŒæ°ãšããŠäœ¿çšããŸã ãŠãŒã¶ãŒã¯adminã§ããããã¹ã¯ãŒãã¯ãããŸããã
ææ¡ã衚瀺ãããŸããåºæ¬èšå®ãä¿åããããããã€ã¹ããªã»ããããŸãã [ æ§æã®åé€]ãéžæããŸãã ããã€ã¹ãåèµ·åããŸãã

ãŠãŒã¶ãŒãè¿œå
ãŸããæ°ãããŠãŒã¶ãŒãäœæããŠç®¡çè ãåé€ãããšã誰ãããããå¿ããŸãã
[ã·ã¹ãã ]â[ãŠãŒã¶ãŒ]â[+]ã«ç§»åããŸãã
ååïŒ login ;
ã°ã«ãŒãïŒãã«ïŒãã«ã¢ã¯ã»ã¹ïŒ;
ãã¹ã¯ãŒãïŒ password ;
ãã¹ã¯ãŒãã®ç¢ºèªïŒ ãã¹ã¯ãŒããããäžåºŠå ¥åããŸãã
[OK]ãã¯ãªãã¯ããŠç¢ºèªããŸãã
ãŠãŒã¶ãŒã®è¡šã§ãadminãéžæããŠ[]ãæŒããŸãã


ã³ã³ãœãŒã«ããŒãžã§ã³
/user add name= group=full password= /user remove admin
æ°ãããŠãŒã¶ãŒã®äžã§ããã€ã¹ãåæããããã€ã¹ã«ç§»åããŸãã
ãããã€ããŒã®ã»ããã¢ãã
ãããã€ããŒã¯RouterBOARDã®æåã®ããŒãã«æ¥ç¶ããæ®ãã®4ã€ãšã¯ã€ã€ã¬ã¹ã€ã³ã¿ãŒãã§ãŒã¹ã¯ããŒã ãµãããã192.168.10.0/24ãããŒã ãµããããã®ã«ãŒã¿ãŒã®ã¢ãã¬ã¹ïŒ192.168.10.1ããããã¯ãŒã¯ã¯ã©ã€ã¢ã³ãã«ã¯192.168.10.1.100-192.168.10.200ã®ç¯å²ã®ã¢ãã¬ã¹ãå²ãåœãŠãããŸãã
ãããã€ããŒã«æ¥ç¶ããã«ã¯ããŸããŸãªæ¹æ³ããããç©çã¬ãã«ã§ã€ãŒãµããããããå ŽåïŒxDLSã¢ãã ããã®å Žåã§ãïŒããããã¯ãŒã¯ãããã³ã«ã¯IPoEïŒéçãŸãã¯DHCPïŒãPPPoEãL2TPãPPTPããŸãã¯ãããã®çµã¿åããïŒäžè¬çã«ïŒ PPTPãL2TPã¯ãæ§æãããIPãªãã§ã¯æ©èœããŸããïŒããã¹ãŠã«å ããŠãMACã¢ãã¬ã¹ãžã®ãã€ã³ããååšããå ŽåããããŸãã æãäžè¬çãªã±ãŒã¹ãæ€èšããŠã¿ãŸãã
ãã ããæåã«ã䟿å®äžãether1ã€ã³ã¿ãŒãã§ã€ã¹ã®ååãeth1-wanã«å€æŽããŸãã [Interfaces]â[Ether1]â[NameïŒeth1-wan]â[OK] ã

ã³ã³ãœãŒã«ãªãã·ã§ã³
/interface ethernet set [find default-name=ether1] name=eth1-wan
ãããã€ããŒã±ãŒãã«ãããã€ã¹ã®æåã®ããŒãã«æ¥ç¶ããŸãã
Macã¢ãã¬ã¹ã®ãªãããŸã
ãã¹ãŠã®ãããã€ããŒãMacãã€ã³ãã£ã³ã°ã䜿çšãããšã¯èšããŸããããç¹ã«IPããã€ã³ãããŠããªãŒããŒããŒããä¿è·ããããã«IPoEã䜿çšãããå Žåããããã¯éåžžã«äžè¬çã§ãã
眮æã¯ã³ãã³ãã¢ãŒãã§ã®ã¿å®è¡ã§ããããã [æ°ããã¿ãŒããã«]ãã¯ãªãã¯ããŠæ¬¡ã®ããã«å ¥åããŸãã
/interface ethernet set eth1-wan mac-address=00:11:22:33:44:55
ããã§ã00ïŒ11ïŒ22ïŒ33ïŒ44ïŒ55ã¯ããããã€ããŒãäºçŽããMACã§ãã
DHCPã䜿çšããŠèšå®ãèªåçã«ååŸããŸãã
æãåçŽãªãªãã·ã§ã³ïŒ [IP]â[DHCPã¯ã©ã€ã¢ã³ã]â[+]â[ã€ã³ã¿ãŒãã§ãŒã¹ïŒeth1-wan]â[OK] ã

ã³ã³ãœãŒã«ãªãã·ã§ã³
/ip dhcp-client add interface eth1-wan disabled=no
éçIPèšå®
ãããç°¡åãªãªãã·ã§ã³ã§ããããããã€ããŒã§æ¬¡ã®ãã©ã¡ãŒã¿ãŒãæ確ã«ããå¿ èŠããããŸãïŒå€ã¯äŸãšããŠç€ºãããŠããŸãïŒã
IPïŒIPã¢ãã¬ã¹ïŒïŒ192.0.2.10;
ãã¹ã¯ïŒ255.255.255.0ïŒãŸãã¯/ 24ïŒ;
ã²ãŒããŠã§ã€ïŒ192.0.2.1;
DNS1ïŒ192.0.2.2;
DNS2ïŒ192.0.2.3ã
ã€ã³ã¿ãŒãã§ã€ã¹ã«IPãè¿œå ããŸãã [IP]â[ã¢ãã¬ã¹]â[+]â[ã¢ãã¬ã¹ïŒ192.0.2.10/255.255.255.0; ã€ã³ã¿ãŒãã§ã€ã¹ïŒeth1-wan]â[OK] ;
ããã©ã«ãã«ãŒããè¿œå ïŒ [IP]â[ã«ãŒã]â[+]â[Dst.AddressïŒ0.0.0.0/0; ã²ãŒããŠã§ã€ïŒ192.0.2.1; ã²ãŒããŠã§ã€ã®ç¢ºèªïŒping; è·é¢ïŒ1]â[OK] ;
DNSã®è¿œå ïŒ [IP]â[DNS]â[ãµãŒããŒïŒ192.0.2.2; 192.0.2.3]â[OK] ã



ã³ã³ãœãŒã«ãªãã·ã§ã³
/ip address add address=192.0.2.10/255.255.255.0 interface=eth1-wan /ip route add dst-address=0.0.0.0/0 gateway=192.0.2.1 check-gateway=ping distance=1 /ip dns set servers=192.0.2.2,192.0.2.3
PPPoEã»ããã¢ãã
PPPoEã¯ãIPã®äºåèšå®ãå¿ èŠãšããªããã³ããªã³ã°ãããã³ã«ã§ãã ãã¡ããããããã€ããŒã¯ä»ã®ãããã¯ãŒã¯ãšãã¢ãªã³ã°ããããé床å¶éãªãã§ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ãããã§ããŸãããPPPoEã€ã³ã¿ãŒãã§ã€ã¹ã®å€åŽã§åäœããå¥ã®ã«ãŒãïŒSOHOã«ãŒã¿ãŒã®ãã¥ã¢ã«ã¢ã¯ã»ã¹ãŸãã¯ãã·ã¢PPPoEïŒãè¿œå ããå¿ èŠããããŸããããã®ãããªæ§æã¯åå¿è åãã®HOWTOã®ç¯å²å€ã§ãã
PPPoEãèšå®ããã«ã¯ããããã¯ãŒã¯ã«æ¥ç¶ããããã®ãã°ã€ã³ãšãã¹ã¯ãŒããç¥ãå¿ èŠããããŸãïŒéåžžã¯å¥çŽã®ç· çµæã«çºè¡ãããŸãïŒã
ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ãè¿œå ããŸãïŒ [PPP]â[+]â[PPPoE Client] ã
[äžè¬]ã¿ãã§ãã€ã³ã¿ãŒãã§ã€ã¹åName = tap1-wanããã³ãããã€ããŒã€ã³ã¿ãŒãã§ã€ã¹Interface = eth1-wanãæå®ããŸãã
[Dial Out]ã¿ãã§ãæ¥ç¶çšã®ãã°ã€ã³ãšãã¹ã¯ãŒããã¹ã¯ãªãŒã³ã·ã§ããã®æ®ãã®ãªãã·ã§ã³ãæå®ããŸãã


ã³ã³ãœãŒã«ãªãã·ã§ã³
/interface pppoe-client add interface=eth1-wan name=tap1-wan disabled=no user= password= use-peer-dns=yes add-default-route=yes default-route-distance=0
éèŠïŒPPPoEã䜿çšããå Žåã¯ãeth1-wanã®ä»£ããã«tap1-wanã€ã³ã¿ãŒãã§ãŒã¹ã䜿çšããŸãã
L2TP / PPTPãæ§æãã
ããã§ãç§ãã¡ã¯æãè±å¯ãªèœãšãç©Žã®æ¥ç¶æ¹æ³ãèŠã€ããŸããã äž¡æ¹ã®ãããã³ã«ã¯åæ§ã®æ¹æ³ã§æ§æãããŸãããäºåã®IPæ§æãå¿ èŠã§ãïŒDHCPã䜿çšããããéçã«ïŒã mikrotikã®åé¡ã¯ããµãŒããŒã¢ãã¬ã¹ããã¡ã€ã³åã§èšå®ããããšã«ãããã¢ãã¬ã¹å ã§ããã1åèªèããã¢ãã¬ã¹ãå€æŽãããå ŽåïŒãŸãã¯ãããã€ããŒãRoundRobin DNSã䜿çšãããµãŒããŒãéè² è·ã«ãªã£ãå ŽåïŒã®ã¿ãã®ã¢ãã¬ã¹ã䜿çšãããããã€ã³ã¿ãŒããããªãã§æŸçœ®ãããå¯èœæ§ãé«ãããšã§ãã ãããã€ããŒã«ã¯ãããšãã°ãããŒã«ã«ãããã¯ãŒã¯ããã®ã¿ã¢ã¯ã»ã¹å¯èœãªDNSãµãŒããŒããPPTP / L2TPãµãŒããŒãžã®éçã«ãŒããäºåã«ç»é²ããå¿ èŠããããªã©ãé¢çœãããšããããŸãã幞éã«ãé»è²ã®çžæš¡æ§ã®ãããã€ããŒã®ã¯ã©ã€ã¢ã³ãã«ãªãã°ã察å¿ããåœä»€ãå®å šã«ããŠã³ããŒãããŠåŠç¿ã§ããŸãã DualAccess L2TP / PPTPã®ãªãã·ã§ã³ãå¯èœã§ãã
ãã ããIPã¢ãã¬ã¹ã¯DHCPã䜿çšããŠååŸããããããã€ããŒãããã°ã€ã³ããã¹ã¯ãŒããvpnãµãŒããŒãèŠã€ããã®ã§ããã¹ãŠãæ£åžžã§ãããšæ³å®ããŸããèšå®ãç¶è¡ã§ããŸãã
PPTP / L2TPã€ã³ã¿ãŒãã§ãŒã¹ãè¿œå ããŸãïŒ [PPP]â[+]â[PPTP Client or L2TP Client] ã
[å šè¬]ã¿ãã§ãæ¥ç¶åName = tun1-wanãæå®ããŸãã
[ãã€ã€ã«ã¢ãŠã]ã¿ãã§ãPPTPãŸãã¯L2TPãµãŒããŒããŠãŒã¶ãŒåããã¹ã¯ãŒããæå®ããŸãã


ã³ã³ãœãŒã«ãªãã·ã§ã³
l2tpã®å Žåãpptp-clientãl2tp-clientã«çœ®ãæããŸãã
/interface pptp-client add name=tun1-wan disabled=no connect-to=_vpn user= password= add-default-route=yes default-route-distance=1 profile=default
éèŠïŒL2TP / PPTPã䜿çšããå Žåã¯ãeth1-wanã®ä»£ããã«tun1-wanã€ã³ã¿ãŒãã§ãŒã¹ã䜿çšããŸãã
ãããããšãŒã¿ã¯ã©ãã§ããïŒ
ããããç°¡åã§ãã USBã¢ãã ã«åºããããšã [Interfaces]â[LTE]ã§ã€ãŒãµãããã€ã³ã¿ãŒãã§ãŒã¹ãšããŠå®çŸ©ãããå¯èœæ§ãé«ããDHCPã䜿çšããŠããããIPãååŸããã®ã«ååã§ãã ãã ããæåã®ã¢ã¯ãã£ããŒã·ã§ã³ã§ã¯ãã¢ãã ãPCã«æ¥ç¶ããå¿ èŠããããŸãã ãã¹ãŠã®ã¢ãã ã¢ãã«ããã®ããã«ç解ããŠããªããã倱æããŸãããã圌ã¯äºåã®ã¢ã¯ãã£ããŒã·ã§ã³ãªãã§PCã§ã®äœæ¥ãæåŠããŸããã
ãã®ä»ã®3G / 4Gã¢ãã
ã¢ãã ããããã¯ãŒã¯ã«ãŒããšããŠå®çŸ©ãããŠããªãããMikrotikã[System]â[Resources]â[USB]ã§è¡šç€ºããå Žåãusb1ã€ã³ã¿ãŒãã§ã€ã¹ã®PPPæ¥ç¶ãäœæããå¿ èŠããããŸããç¶æ³ã«ãã£ãŠã¯ãæåã«ã³ãã³ãã䜿çšããŠããã€ã¹ãATã¢ãŒãã«åãæ¿ããå¿ èŠããããŸãïŒå¯Ÿå¿ãããã®ãæ¢ããã©ãŒã©ã ïŒã ãããã«ãããéåžžã«å€ãã®ãªãã·ã§ã³ããããŸããããã®ãã¡ã®1ã€ãããã§èª¬æããŸã ã
ããŒã«ã«ãããã¯ãŒã¯ã®ã€ã³ã¿ãŒãã§ãŒã¹ã®æºå
çŸæç¹ã§ã¯ãether2-ether5ããã³wlan1ã€ã³ã¿ãŒãã§ãŒã¹ã¯äºãã«ç¬ç«ããŠåäœãããããåäžã®ããŒã¿äŒéåªäœã«çµåããå¿ èŠããããŸãã
ã€ãŒãµãããã€ã³ã¿ãŒãã§ã€ã¹ã¯ããŒããŠã§ã¢ã¬ãã«ã§çµã¿åãããããšãã§ããŸããããã«ãããããŒã¿è»¢éé床ãåäžããCPUã®è² è·ã軜æžãããŸãïŒãœãããŠã§ã¢ããªããžãšæ¯èŒããŠïŒã Ether5ã¯ãã¹ã¿ãŒããŒããšããŠäœ¿çšãããŸããããããããå²ãåœãŠãããšãã§ããŸãããå¥ã®ãããã€ããŒã衚瀺ãããå Žåãããã2çªç®ã®ããŒãã«æ¥ç¶ããïŒãããŠãã®äžã®ãã¹ã¿ãŒããŒããåæããïŒããšã¯è«ççã§ãã
6.41æªæºã®RoSã®å ŽåïŒ
ether5ã®ååãeth5-lanã«å€æŽïŒ [Interfaces]â[ether5]â[NameïŒeth5-lan]â[OK] ;
ether2-ether4ã®ååãå€æŽãããããã®ãã¹ã¿ãŒããŒããèšå®ããŸãã [Interfaces]â[ether2-4]â[NameïŒeth2-4-lan; ãã¹ã¿ãŒããŒã= eth5-lan]â[OK] ã

![eth [2-4] -lanã®æ§æ](https://habrastorage.org/getpro/habr/post_images/482/119/4a1/4821194a142383e5f4a563778cb65112.png)

ã³ã³ãœãŒã«ãªãã·ã§ã³
/interface ethernet set [find default-name=ether5] name=eth5-lan /interface ethernet set [find default-name=ether2] name=eth2-lan master-port=eth5-lan /interface ethernet set [find default-name=ether3] name=eth3-lan master-port=eth5-lan /interface ethernet set [find default-name=ether4] name=eth4-lan master-port=eth5-lan
èå³æ·±ãç¹ã ãã¹ã¿ãŒããŒãã䜿çšãããšã1ã€ã®ãããã»ããã«å±ããã€ã³ã¿ãŒãã§ã€ã¹ãçµã¿åãããããšãã§ããŸãããããã»ããã®å€ãã¢ãã«ã§ã¯ãè€æ°ïŒã¹ã€ããåïŒãååšããå¯èœæ§ããããç°ãªããããã»ããããã®ã€ã³ã¿ãŒãã§ã€ã¹ã¯ãœãããŠã§ã¢ããªããžãŸãã¯ãããã³ãŒãã«ãã£ãŠçµåãããŸãã
ããã§ããã¹ãŠã®ããŒã«ã«ã€ãŒãµãããã€ã³ã¿ãŒãã§ã€ã¹ãeth5-lanãšããååã§çµåãããŸãã
ã¯ã€ã€ã¬ã¹ã€ã³ã¿ãŒãã§ã€ã¹ã¯ã€ãŒãµããããšã¯å¥ã«ååšãããœãããŠã§ã¢ããªããžã«é Œãå¿ èŠãããçµã¿åããã«ãªããŸãã
ããªããžã€ã³ã¿ãŒãã§ã€ã¹ãäœæããŸãã [Bridge]â[+]â[NameïŒbr1-lan]â[OK] ;
ã€ã³ã¿ãŒãã§ãŒã¹ã®è¿œå ïŒ [ããªããž]â[ããŒã]â[+]â[ã€ã³ã¿ãŒãã§ãŒã¹ïŒeth5-lan; ããªããžïŒbr1-lan]â[OK]
[ããªããž]â[ããŒã]â[+]â[ã€ã³ã¿ãŒãã§ãŒã¹ïŒwlan1; ããªããžïŒbr1-lan]â[OK]



ã³ã³ãœãŒã«ãªãã·ã§ã³
/interface bridge add name=br1-lan /interface bridge port add interface=eth5-lan bridge=br1-lan /interface bridge port add interface=wlan1 bridge=br1-lan
RoS 6.41以éã®å ŽåïŒ
RouterOSã®çŸåšã®ããŒãžã§ã³ã§ã¯ããã¹ã¿ãŒããŒããªãã·ã§ã³ã¯ãªããªããŸããããã¹ãŠã®èšå®ã¯ããªããžã€ã³ã¿ãŒãã§ã€ã¹å ã§è¡ãããŸãã
br1-lanã€ã³ã¿ãŒãã§ã€ã¹ãäœæããŸãã
/interface bridge add name=br1-lan
ããªããžã«ã€ã³ã¿ãŒãã§ãŒã¹ãè¿œå ããŸãã
/interface bridge port add bridge=br1-lan interface=eth2-lan hw=yes add bridge=br1-lan interface=eth3-lan hw=yes add bridge=br1-lan interface=eth4-lan hw=yes add bridge=br1-lan interface=eth5-lan hw=yes add bridge=br1-lan interface=wlan1
ãã¹ãŠã¯GUIãä»ããŠå®è¡ã§ããŸããããã«ããããŒããŠã§ã¢ãªãããŒãã¯hwãªãã·ã§ã³ã§ãã
æç·ã€ã³ã¿ãŒãã§ã€ã¹ã®hwãªãã·ã§ã³ã«æ³šæãæã£ãŠããŸãããã¹ã€ããã®ããŒããæ åœããããã«ãªããŸããïŒå¯èœãªå ŽåïŒã è€æ°ã®ããªããžã€ã³ã¿ãŒãã§ã€ã¹ããããhwãªãã·ã§ã³ãã©ãã§ããªã³ã«ãªã£ãŠããå Žåãããã€ã¹ã¯ããŒããŠã§ã¢ãäœæããããªããžãåå¥ã«éžæãããããèªåã§æãéèŠã§ãªãå Žåã¯hwãç¡å¹ã«ããŸãã
çŸåšããã¹ãŠã®ããŒã«ã«ã€ãŒãµãããããã³wlanã€ã³ã¿ãŒãã§ã€ã¹ã¯ãbr1-lanãšããååã§çµåãããŠããŸãã
ã¯ã€ã€ã¬ã¹ã»ãã¥ãªãã£
éå±ãªããšïŒæ£ç¢ºã«ã¯ããããèšè¿°ããã®ã¯éå±ã§ãïŒããå¿ èŠã§ãã
ã»ãã¥ãªãã£ãããã¡ã€ã«ãè¿œå ããã¯ã€ã€ã¬ã¹æ¥ç¶ã®ãã¹ã¯ãŒããæå®ããŸãã [ã¯ã€ã€ã¬ã¹]â[ã»ãã¥ãªãã£ãããã¡ã€ã«]â[+]
åå-ãããã¡ã€ã«åã
WPA / WPA2äºåå ±æããŒ-WPA / WPA2ã®ããŒïŒwi-fiããã®ãã¹ã¯ãŒãïŒ;
[OK]ã®æåŸã®ã¹ã¯ãªãŒã³ã·ã§ããã®æ®ãã

ã³ã³ãœãŒã«ãªãã·ã§ã³
/interface wireless security-profiles add name=wpa2-protected mode=dynamic-keys authentication-types=wpa-psk,wpa2-psk unicast-chiphers=aes-ccm group-chiphers=aes-ccm wpa-pre-shared-key=_wpa wpa2-pre-shared-key=_wpa2
ã¯ã€ã€ã¬ã¹ã€ã³ã¿ãŒãã§ã€ã¹ãã¢ã¯ãã£ãã«ããŠèšå®ããŸãïŒ [Wireless]â[wlan1]â[Enable] ã
[ã¯ã€ã€ã¬ã¹]ã¿ãã§ïŒ
ã¢ãŒãïŒap bridge;
垯åïŒ2gHz-B / G / N ã¯ã€ã€ã¬ã¹ããã€ã¹ãæ°å¹Žåã«ãªãªãŒã¹ãããå Žåã2gHz-B / Gãéžæããæ¹ãè«ççã§ãã ;
é »åºŠïŒèªåã SOHOããã€ã¹ã§ã¯ããã£ãã«ã³ã³ãã©ã€ã¢ã³ã¹ãšåŒã°ãããã®ãã©ã¡ãŒã¿ãŒãããã§è¡šç€ºã§ããŸã ã äœãéžæããã°ãããããããªãå Žåã¯ãèªåã®ãŸãŸã«ããŠãã ããã ;
SSIDïŒã¢ã¯ã»ã¹ãã€ã³ãåã
ã¯ã€ã€ã¬ã¹ãããã³ã«ïŒ802.11;
ã»ãã¥ãªãã£ãããã¡ã€ã«ïŒwpa2-protectã åã®ã¹ãããã§äœæããããããã¡ã€ã«ã;
ããªããžã¢ãŒãïŒæå¹ã
ããã©ã«ãèªèšŒïŒã¯ã;
ããã©ã«ãã®è»¢éïŒã¯ãã
SSIDãé衚瀺ïŒãããã ã¢ã¯ã»ã¹ãã€ã³ããé衚瀺ã«ããããšãã§ããŸãã ãããããããäžèœè¬ãšã¯èããªãã§ãã ããã ;
次ã¯[Nstreme]ã¿ãã§ãã
ãã¹ãŠããªãã«ããŸãã
å®äºãããã [OK]ãæŒããŠæ¥ç¶ãè©Šã¿ãŸãïŒIPé»è©±ã¯åä¿¡ããŸããããæ¥ç¶ã¯ç¢ºç«ãããã¯ãã§ãïŒã



ã³ã³ãœãŒã«ãªãã·ã§ã³
/interface wireless set wlan1 disabled=no ssid=MyRouter mode=ap-bridge band=2ghz-b/g/n frequency=2412 bridge-mode=enabled wireless-protocol=802.11 security-profile=wpa2-protect default-authentication=yes default-forwarding=yes hide-ssid=no /interface wireless nstreme set wlan1 enable-nstreme=no enable-polling=no disable-csma=no
IPãdhcp-serverã®æ§æ
br1-lanã€ã³ã¿ãŒãã§ã€ã¹ã«ipãè¿œå ããŸãïŒ [IP]â[ã¢ãã¬ã¹]â[+]â[ã¢ãã¬ã¹ïŒ192.168.10.1/24; ã€ã³ã¿ãŒãã§ã€ã¹ïŒbr1-lan]â[OK]

ã³ã³ãœãŒã«ãªãã·ã§ã³
/ip address add address=192.168.10.1/24 interface=br1-lan
dhcpã®ã¢ãã¬ã¹ããŒã«ãäœæããŸãã [IP]â[ããŒã«]â[+]â[ååïŒdhcp-pc; ã¢ãã¬ã¹ïŒ192.168.10.100-192.168.10.200]â[OK]

ã³ã³ãœãŒã«ãªãã·ã§ã³
/ip pool add name=dhcp-pc address=192.168.10.100-192.168.10.200
br1-lanã€ã³ã¿ãŒãã§ã€ã¹ã§ãªãã¹ã³ããdhcp-requestsãæå¹ã«ããŸãã [IP]â[DHCPãµãŒããŒ]â[+]â[ååïŒdhcp-pc; ã€ã³ã¿ãŒãã§ã€ã¹ïŒbr1-lan; ãªãŒã¹æéïŒ08:00:00; ã¢ãã¬ã¹ããŒã«ïŒdhcp-pc]â[OK]

ããã§ãdhcpã«ãã£ãŠæäŸããããã©ã¡ãŒã¿ãŒã決å®ããå¿ èŠããããŸãã [IP]â[DHCPãµãŒããŒ]â[ãããã¯ãŒã¯]â[+]
ã¢ãã¬ã¹ïŒ192.168.10.0/24;
ã²ãŒããŠã§ã€ïŒ192.168.10.1;
ããããã¹ã¯ïŒ24;
DNSãµãŒããŒïŒ192.168.10.1
[OK]ã®æåŸã

ã¹ã¯ãªãŒã³ã·ã§ããã¯NTPãµãŒããŒãšããŠã®ã«ãŒã¿ãŒã®ã¢ãã¬ã¹ã瀺ããŠããŸãããMikrotikã¯åºæ¬çãªé ä¿¡ã§æ£ç¢ºãªæéãæäŸããããšã¯ã§ããŸããããããã¯ãŒã¯ããä»ã®ãµãŒããŒãæå®ããããntpããã±ãŒãžãè¿œå ããã³æ§æã§ããŸãïŒHOWTOã®æåŸã§èª¬æããŸãïŒã
ã³ã³ãœãŒã«ãªãã·ã§ã³
/ip dhcp-server add name=dhcp-pc interface=br1-lan lease-time=08:00:00 address-pool=dhcp-pc /ip dhcp-server network add address=192.168.10.0/24 dns-server=192.168.10.1 gateway=192.168.10.1 netmask=24
ãã¡ã€ã³ããŒã ãµãŒããŒã®æ§æ
ãããã€ããŒã®DNSã«æºè¶³ã§ããªãå Žåã¯ããªã¹ãã«ç¬èªã®DNSãè¿œå ã§ããŸãïŒå¯Ÿå¿ããæ¥ç¶ââã§[ãã¢DNSã䜿çš]ãªãã·ã§ã³ããªãã«ããããšã«ããããããã€ããŒDNSãå®å šã«åé€ã§ããŸãïŒã
DNSã«ãã¯ã¢ããããªã³ã«ããŸãã [IP]â[DNS]â[ãªã¢ãŒããªã¯ãšã¹ããèš±å¯ïŒã¯ã]â[OK]

ã³ã³ãœãŒã«ãªãã·ã§ã³
/ip dns set allow-remote-requests=yes
ããã§ããŒã«ã«ãããã¯ãŒã¯ãæ©èœãããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ïŒãŸãã¯dhcpã¯ã©ã€ã¢ã³ãïŒãåèµ·åããŠã«ãŒã¿ãŒããipãåä¿¡ããwinbox / http / ssh / telnet / ftp / scp ipïŒ192.168.10.1ãä»ããŠæ¥ç¶ããããã«äœ¿çšã§ããŸã
ããŒã«ã«ãããã¯ãŒã¯äžã®ããã€ã¹éã«æ¥ç¶ããããŸããããªãœãŒã¹ã«pingãå®è¡ãããšããã®ã¢ãã¬ã¹ã¯èªèãããŸãããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã¯ãŸã 倱ãããŠããŸãã æåŸã®äž»èŠãªãã€ã³ãã§ãããã±ãããã£ã«ã¿ãŒã®èšå®ãæ¥ãŸããã
ããããã£ã«ã¿ãŒ
RouterOSã¯GNU / Linux OSã®äžçš®ã§ãããnetfilterã¯ãã±ãããã£ã«ã¿ãŒãšããŠäœ¿çšãããŸããã€ã³ã¿ãŒãã§ã€ã¹ãã«ãŒãã«ã¢ãžã¥ãŒã«ãŸãã¯iptablesã䜿çšããŠçŽæ¥åäœãããšã¯èšããŸããããéçºè ã¯åŸè ã«ã§ããã ãè¿ãæ§æãäœæããããšããŸããã
åã³ãã³ããåå¥ã«èª¬æããªãããã«ãå°ãèŠãŠã¿ãŸãããã ãã±ãããã£ã«ã¿ãŒã¯[IP]â[ãã¡ã€ã¢ãŠã©ãŒã«]ã§æ§æãããŸããã¿ãïŒiptablesçšèªã®ããŒãã«ïŒ [ãã£ã«ã¿ãŒ] ã [ããã] ãããã³[ãã³ã°ã«]ã«æ³šç®ããŸãã ïŒ [+]ãã¿ã³ã䜿çšããŠä»ã®å Žæã«ããããã«ïŒåããŒãã«ã«å€æ°ã®ã«ãŒã«ãè¿œå ã§ããŸããã«ãŒã«ã¯äžããäžã«äº€äºã«åŠçããããããé åºãéèŠã§ãã åã«ãŒã«ã¯ã äžè¬ã詳现ãè¿œå ãã¢ã¯ã·ã§ã³ã®3ã€ã®ã¿ãã«é 眮ãããæ¡ä»¶ã§æ§æãããŸãã[ ã¢ã¯ã·ã§ã³ ]ã¿ãã«ã¯ãã«ãŒã«ã®çµ±èšããããŸãããèå³ã¯ãããŸããã ã«ãŒã«ã«ã¯å€ãã®æ¡ä»¶ãå«ããããšãã§ããŸãããäž»ãªããšã¯ããããççŸãããªãããšã§ãã ããã±ãŒãžã®ã«ãŒã«ã«åŸã£ãŠããã¹ãŠã®æ¡ä»¶ã«é©åããå Žåãé©åãªã¢ã¯ã·ã§ã³ã«ãã£ãŠåŠçãããããã«å ãžé²ãããšã¯ãããŸããïŒ å®éãäžéšã®ã¢ã¯ã·ã§ã³ã¯ããã±ãŒãžãããã«ã¹ãããããŸã ã å°æ¥netfilterãæ±ãäºå®ãããå Žåã¯ããã®äºå®ãèŠããŠãããŠãã ãã ïŒã åå¿è åãã®ãªãã·ã§ã³ã§ã¯ã[ å šè¬ ]ã¿ãããååãªæ¡ä»¶ãååŸã§ããŸãã

èšå®ã¯ã©ããªããŸããïŒ ããŒã«ã«ãããã¯ãŒã¯ã®ãŠãŒã¶ãŒã¯ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããŸãã ããŒã«ã«ãããã¯ãŒã¯ããã®mikrotikãžã®ã¢ã¯ã»ã¹ã¯ã䜿çšãããµãŒãã¹ïŒwebãwinboxãsshãdnsãntpïŒãWebãä»ããå€éšãããã¯ãŒã¯ããã®ã¢ã¯ã»ã¹ã«ãã£ãŠå¶éãããŸãããããŒãã¢ãã¬ã¹ã¯9999ã«å€æŽãããŸãã
å¿ èŠãªã«ãŒã«ã¯ãã¹ãŠè¡šåœ¢åŒã§èª¬æãããŠããŸããééãããæ ãããããã®ãæãå Žåã¯ã [æ°ãã端æ«]ãéããã»ã¯ã·ã§ã³ã®æåŸã«ããã³ã³ãœãŒã«ããŒãžã§ã³ããè¡ãã³ããŒããŸãã
[ãã£ã«ã¿ãŒ]ã¿ã
æ¡ä»¶ | ã¢ã¯ã·ã§ã³ | |||||||||
---|---|---|---|---|---|---|---|---|---|---|
ïŒ | ãã§ãŒã³ | Srcã äœæ | Dstã äœæ | ãããã³ã« | Dst.Port | ã§ã ã¿ãŒãã§ã€ã¹ | ã¢ãŠãã ã€ã³ã¿ãŒãã§ãŒã¹ | æ¥ç¶ããŒã¯ | æ¥ç¶ç¶æ | |
0 | å ¥å | icmp | åãå ¥ãã | |||||||
1 | å ¥å | 192.168.10.0/24 | tcp | 80.8291.22 | br1-lan | æ°ãã | åãå ¥ãã | |||
2 | å ¥å | tcp | 80 | eth1-wan | allow_in | æ°ãã | åãå ¥ãã | |||
3 | å ¥å | 192.168.10.0/24 | UDP | 53,123 | br1-lan | æ°ãã | åãå ¥ãã | |||
4 | å ¥å | 確ç«ããããé¢é£ãã | åãå ¥ãã | |||||||
5 | åºå | [ïŒ]ç¡å¹ | åãå ¥ãã | |||||||
6 | é²ã | 192.168.10.0/24 | br1-lan | eth1-wan | æ°èš | åãå ¥ãã | ||||
7 | é²ã | 192.168.10.0/24 | eth1-wan | br1-lan | 確ç«ããããé¢é£ãã | åãå ¥ãã | ||||
8 | å ¥å | æ絶ãã | ||||||||
9 | åºå | æ絶ãã | ||||||||
10 | é²ã | æ絶ãã |
[NAT]ã¿ã
æ¡ä»¶ | ã¢ã¯ã·ã§ã³ | ||||||
---|---|---|---|---|---|---|---|
ïŒ | ãã§ãŒã³ | Srcã äœæ | ãããã³ã« | Dst.Port | ã§ã ã¿ãŒãã§ã€ã¹ | ã¢ãŠãã ã€ã³ã¿ãŒãã§ãŒã¹ | |
0 | srcnat | 192.168.10.0/24 | eth1-wan | ä»®è£ | |||
1 | dstnat | tcp | 9999 | eth1-wan | ãªãã€ã¬ã¯ã
|
ã¿ã[ãã³ã°ã«]
æ¡ä»¶ | ã¢ã¯ã·ã§ã³ | |||||
---|---|---|---|---|---|---|
ïŒ | ãã§ãŒã³ | ãããã³ã« | Dst.Port | ã§ã ã¿ãŒãã§ã€ã¹ | æ¥ç¶ç¶æ | |
0 | äºåã«ãŒãã£ã³ã° | tcp | 9999 | eth1-wan | æ°ãã | æ¥ç¶ãããŒã¯
|
ã³ã³ãœãŒã«ãªãã·ã§ã³
/ip firewall filter add chain=input protocol=icmp add chain=input connection-state=new dst-port=80,8291,22 in-interface=br1-lan protocol=tcp src-address=192.168.10.0/24 add chain=input connection-mark=allow_in connection-state=new dst-port=80 in-interface=eth1-wan protocol=tcp add chain=input connection-state=new dst-port=53,123 protocol=udp src-address=192.168.10.0/24 add chain=input connection-state=established,related add chain=output connection-state=!invalid add chain=forward connection-state=established,new in-interface=br1-lan out-interface=eth1-wan src-address=192.168.10.0/24 add chain=forward connection-state=established,related in-interface=eth1-wan out-interface=br1-lan add action=drop chain=input add action=drop chain=output add action=drop chain=forward /ip firewall nat add action=masquerade chain=srcnat out-interface=eth1-wan src-address=192.168.10.0/24 add action=redirect chain=dstnat in-interface=eth1-wan dst-port=9999 protocol=tcp to-ports=80 /ip firewall mangle add action=mark-connection chain=prerouting dst-port=9999 new-connection-mark=allow_in protocol=tcp connection-state=new
ããã§ã€ã³ã¿ãŒããããå©çšã§ããããã«ãªããŸãããããã§ååãªå Žåã¯ãHOWTOãéããŠäœ¿çšããŸãã詳ããç¥ãããå Žåã¯ãè¿œå ããŠãã ããã
ä»é²1.ããã€ã¹å
ããã€ã¹ã«ååãä»ããŸãïŒ [ã·ã¹ãã ]â[ID]â[ååïŒMikRouter]â[OK]
DNSã§èšå®ããŸã ïŒ [IP]â[DNS]â[éç]â[+]â[ååïŒmikrouter; ã¢ãã¬ã¹ïŒ192.168.10.1]â[OK]
ããã§ãããã€ã¹ã¯mikrouterãã¡ã€ã³åã䜿çšããŠã¢ã¯ã»ã¹ã§ããŸãããããŒã«ã«ãµããããããã®ã¿ã¢ã¯ã»ã¹ã§ããŸãã
ã³ã³ãœãŒã«ãªãã·ã§ã³
/system identity set name=MikRouter /ip dns static add name=mikrouter address=192.168.12.10
ä»é²2.æéèšå®
ã¯ããã¯ãèšå®ããŸãïŒ [ã·ã¹ãã ]â[ã¯ããã¯]â[æé]â[ã¿ã€ã ãŸãŒã³åïŒ ã¿ã€ã ãŸãŒã³ ; æéïŒ çŸåšã®æé ; æ¥ä»ïŒ çŸåšã®æ¥ä» ]â[OK]
ä»é²3.ã¢ããããŒã
ããã€ã¹ãæŽæ°ããããã±ãŒãžãè¿œå ããŸãã
Mikrotik Webãµã€ãã«ã¢ã¯ã»ã¹ããã«ãŒã¿ãŒã®æŽæ°ïŒè¿œå ããã±ãŒãžïŒãå«ãã¢ãŒã«ã€ããããŠã³ããŒãããŸãã 解åããŠæ¬¡ã®ãã®ãæ®ããŸãïŒ6.30.2-å·çæç¹ã§ã®çŸåšã®ããŒãžã§ã³ãã¢ããããŒãã¯é »ç¹ã«å ¬éãããŸãïŒïŒ
advanced-tools-6.30.2-mipsbe.npk dhcp-6.30.2-mipsbe.npk multicast-6.30.2-mipsbe.npk ntp-6.30.2-mipsbe.npk ppp-6.30.2-mipsbe.npk routing-6.30.2-mipsbe.npk security-6.30.2-mipsbe.npk system-6.30.2-mipsbe.npk user-manager-6.30.2-mipsbe.npk wireless-6.30.2-mipsbe.npk
Winboxã§ã [ãã¡ã€ã«]ãéãããã©ãã°ã¢ã³ãããããã䜿çšããŠãæå®ãããéžææžã¿ããã±ãŒãžããã©ãã°ã¢ã³ãããããããŸãïŒãŸãã¯ãWebã€ã³ã¿ãŒãã§ãŒã¹ããŸãã¯scpã䜿çšããŠsshããããŠã³ããŒãã§ããŸãïŒã
æŽæ°ããã«ã¯ãããã€ã¹ãåèµ·åããã ãã§ãïŒ [ã·ã¹ãã ]â[åèµ·å]â[ã¯ã]
ã³ã³ãœãŒã«åèµ·åãªãã·ã§ã³
/system reboot
å°æ¥ãã¢ããããŒãçšã®ããã±ãŒãžãããŠã³ããŒãããå¿ èŠã¯ãããŸããã [ã·ã¹ãã ]â[ããã±ãŒãž]â[ã¢ããããŒãã®ç¢ºèª]â[ãã£ã³ãã«ïŒçŸåš]â[ããŠã³ããŒããšã€ã³ã¹ããŒã«]
ã³ã³ãœãŒã«ãªãã·ã§ã³
/system package update download /system package update install
è¿œå 4. ntpã®æ§æ
以åã®è¿œå ã§ã¯ãã¯ããã¯ãèšå®ããŠNTPããã±ãŒãžãè¿œå ããŸããããããã§æ§æããå¿ èŠããããŸãã
ntp-clientããªã³ã«ããŠãæ£ç¢ºãªæéã®ãµãŒããŒã¢ãã¬ã¹ïŒãæ°ã«å ¥ããèšå®ã§ããŸãïŒãèšå®ããŸãã [System]â[NTP Client]â[EnabledïŒyes; ãã©ã€ããªïŒ48.8.40.31; ã»ã«ã³ããªïŒ91.206.16.4]â[OK]
ntpãªã¯ãšã¹ãã®ãªã¹ãã³ã°ãæå¹ã«ããïŒ [ã·ã¹ãã ]â[NTPãµãŒããŒ]â[æå¹ïŒã¯ã]â[OK]

ã³ã³ãœãŒã«ãªãã·ã§ã³
/system ntp client set enabled=yes primaty-ntp=48.8.40.31 secondary-ntp=91.206.16.4 /system ntp server set enabled=yes
ä»é²5.äžèŠãªãµãŒãã¹ãç¡å¹ã«ãã
winbox / http / sshã®ãŸãŸã«ããŸããæ®ãã¯å¿ èŠã«å¿ããŠå«ããããšãã§ããŸãã [IP]â[ãµãŒãã¹]ã¹ã¯ãªãŒã³ã·ã§ããã®ããã«éžæããŠ[x]ãã¯ãªãã¯ããŸãã

ã³ã³ãœãŒã«ãªãã·ã§ã³
/ip service set telnet disabled=yes set ftp disabled=yes set api disabled=yes set api-ssl disabled=yes set https disabled=yes set www-ssl disabled=no set winbox disabled=no set www disabled=no
ä»é²6.çºèŠãç¡å¹ã«ããmactelnetçµç±ã®ã¢ã¯ã»ã¹ãå¶éãã
Winboxã«ã¯PCãšåãç©çãããã¯ãŒã¯äžã«ããããã€ã¹ãæ€åºããæ段ããããŸãããããã¯äŸ¿å©ã§ãããã©ãããŠé£äººãç§ãã¡ãæã£ãŠããããã€ã¹ã®çš®é¡ãç¥ãå¿ èŠãããã®ã§ããïŒ
ç¡å¹åïŒ [IP]â[ãã€ããŒ] Dis [æ€åºã€ã³ã¿ãŒãã§ã€ã¹] ã br1-lanïŒããŒã«ã«ãšãªã¢ãããã¯ãŒã¯ïŒã®æ€åºãæ®ãããšãã§ããŸããéžæãããã®ãåé€ã§ããŸãã æ°ããã€ã³ã¿ãŒãã§ã€ã¹ã®å Žåãæ€åºã¯ããã©ã«ãã§æå¹ã«ãªã£ãŠããŸããå¿ããªãã§ãã ããã
ã³ã³ãœãŒã«ãªãã·ã§ã³
/ip neighbor discovery :foreach i in=[find] do={ set $i discovery=no }
MACã¢ãã¬ã¹ïŒwinboxããã³mactelnetïŒã§ã¢ã¯ã»ã¹ãå¶éããããã«ãªããŸããïŒ [ããŒã«]â[MACãµãŒããŒ]â[Telnetã€ã³ã¿ãŒãã§ã€ã¹]
ãã¹ãŠç¡å¹ïŒ [x] ïŒã«ã ã br1-lanãè¿œå ããŸãã
[Winboxã€ã³ã¿ãŒãã§ã€ã¹]ã«ç§»åããŠç¹°ãè¿ããŸãã
ã³ã³ãœãŒã«ãªãã·ã§ã³
/tool mac-server set [ find default=yes ] disabled=yes add interface=br1-lan /tool mac-server mac-winbox set [ find default=yes ] disabled=yes add interface=br1-lan
ä»é²7. UPnPãæå¹ã«ãã
å€ãã®p2pã¢ããªã±ãŒã·ã§ã³ããã³ãªã³ã©ã€ã³ã²ãŒã ã§ã¯ãéåžžã®æäœã®ããã«UPnPïŒåçããŒããªãŒããã³ã°ãµãŒãã¹ïŒãå¿ èŠã§ãã
æå¹ïŒ [IP]â[UPnP]â[æå¹ïŒã¯ã]
ã€ã³ã¿ãŒãã§ãŒã¹ã®è¿œå ïŒ [ã€ã³ã¿ãŒãã§ãŒã¹]â[+]
å€éšïŒeth1-wan;
å éšïŒbr1-lanã
ã³ã³ãœãŒã«ãªãã·ã§ã³
/ip upnp set enabled=yes /ip upnp interfaces add interface=eth1-wan type=external add interface=br1-lan type=internal
è£éº8.ãªãŒããŒã¯ããã¯
ãããã¯ãŒã¯äžã®ããã€ã¹ã®æ°ãå¢ããããŠã«ãŒã¿ãŒã察åŠããªããªã£ãå Žåã¯ãããã»ããµãŒãå°ããªãŒããŒã¯ããã¯ã§ããŸãã [ã·ã¹ãã ]â[ã«ãŒã¿ãŒããŒã]â[èšå®]â[CPUåšæ³¢æ°ïŒ750 MHz]
RB 951Gã®å Žåãããã¯CPUã®æ倧åšæ³¢æ°ã§ãã
ã³ã³ãœãŒã«ãªãã·ã§ã³
/system routerboard settings set cpu-frequency=750MHz
ä»é²9.ããã¯ã¢ããèšå®
ããã¯ã¢ããèšå®ãäžèŠã«ãªãããšã¯ãããŸããïŒ[ãã¡ã€ã«]â[ããã¯ã¢ãã]
ååïŒãã¡ã€ã«åïŒæ¡åŒµåãªãïŒ;
ãã¹ã¯ãŒãïŒãã¹ã¯ãŒãïŒæå®ããªãå ŽåããŠãŒã¶ãŒããã®ãã¹ã¯ãŒãã䜿çšãããŸãïŒ;
æå·åããªãïŒããã¯ã¢ãããæå·åããå¿ èŠããªãå Žåã
ã³ã³ãœãŒã«ãªãã·ã§ã³
/system backup save name=router6.30.2 dont-encrypt=yes
埩å ããã«ã¯ããã¡ã€ã«ãå¥ã®ããã€ã¹ã«ã³ããŒããã ãã§ãïŒåãã·ãªãŒãºã§ãåãããŒãžã§ã³ã®RouterOSãæãŸããïŒã
[ãã¡ã€ã«]â[埩å ]ã«ç§»åãããã¡ã€ã«ãéžæããŸãã
ã³ã³ãœãŒã«ãªãã·ã§ã³
/system backup load name=router6.30.2.backup
PS RoSãšMikrotikã«é¢ããèšäºã®èå³æ·±ãã¢ã€ãã¢ãããå Žåã¯ãå人ã§æžããŠãã ããã