ãã®èšäºã§ã¯ããããžã§ã¯ãã®å®è£ äžã«ç§ã®åã«çŸããããã€ãã®è¿œå ã¿ã¹ã¯ã®ãœãªã¥ãŒã·ã§ã³ãå ±æããããšæããŸãã ãã®ãããªã¿ã¹ã¯ã«ã¯ãåºèããåºèã«ç§»åããç£æ»éšéã®åŸæ¥å¡ã®ããã€ã¹çšã®ãªãã£ã¹å ã®ãµãŒããŒãžã®ã¢ã¯ã»ã¹ã®ç·šæããããŸããïŒããŒã1ïŒã ãŸããOSPFåçã«ãŒãã£ã³ã°ãããã³ã«ã䜿çšããŠWi-Fiã·ã§ããã³ã°ããªã³ã¿ãŒããã£ããããæ¹æ³ã«ã€ããŠã説æããŸãïŒããŒã2ïŒã
åãšåãããã«ããã®è§£æ±ºçã誰ããŸãã¯æ°èŠåå ¥è ãåæ§ã®åé¡ã解決ããã®ã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã ç§ã¯å°é家ããã®æ¹å€ã«åãã§ããã§ãããã
èŠåºãã«èå³ããã人-ã«ããããé¡ãããŸãïŒ
ããŒã0.æäŸããããã®
åã®èšäºã§è¡ãããããšãç°¡åã«æãåºãããŠãã ããã çµç¹ã¯ç§ã«é ŒããŸãã-äºçŽã®å¯èœæ§ãšéãããäºç®ã§ã»ã°ã¡ã³ãåããããããã¯ãŒã¯ãçµç¹ããããšãèŠæ±ããå°å£²åºã®ãããã¯ãŒã¯ã
ç§ã®ä»äºã¯ãéœåžå šäœã«å°ççã«åæ£ãããã©ãããããã¯ãŒã¯ãäœæããããšã§ããéå±€åãããã¢ãã¬ãã·ã³ã°ãåããã»ã°ã¡ã³ãåããããããã¯ãŒã¯ã§ãããæãéèŠãªã®ã¯åé·æ§ã®å¯èœæ§ã§ãã
åžå ã®ãã¹ãŠã®åºèéã®æ¥ç¶ã¯ãããŒã«ã«ISPã«ãã£ãŠçµç¹åããããããã¯ãŒã¯å ã«å¥åã®VLANãäŒç€Ÿã«æäŸããŸãã ãããã£ãŠããã¹ãŠã®åºèãšãªãã£ã¹ã®ãããã¯ãŒã¯å šäœã1ã€ã®å€§ããªLayer2 Broadcastãã¡ã€ã³ã«å±ããŠããŸãã ã
ãã®ã¢ãã«ã«ã¯ããã€ãã®æ¬ ç¹ããããŸãã
- ãããã¯ãŒã¯äžã®ãã¹ãŠã®ããã€ã¹ã¯ãã¬ã€ã€ãŒ2ã§ãäºããèŠãããšãã§ããŸãã
- ãã©ãã£ãã¯ãã£ã«ã¿ãªã³ã°ããªã·ãŒã®æ¬ åŠã
- åäžã®ãããŒããã£ã¹ããã¡ã€ã³ããã®çµæã400åã®ããã€ã¹ã®ããããããã®ãããŒããã£ã¹ããã±ããã¯ãéœåžã®ããŸããŸãªéšåã«ãããããã®400åã®ããã€ã¹ãã¹ãŠã«å¿ ã転éãããŸãã
ãµãŒããŒã®ç°¡æœã§åçŽåãããã¬ã€ã¢ãŠããã以äžã®å³1ã«ç€ºããŸãã
ãããŠãç§ãã¡ãæã£ãŠãããã®ã®ç°¡åãªèª¬æïŒ
- äŒç€Ÿã«ã¯ãããŸããŸãªåœ¹å²ãå®è¡ããããŸããŸãªãµãŒããŒããããŸãã
- ç¹å¥ãªããŒã¿åé端æ«ïŒ TSD ïŒããããå³ã§ã¯ããããã¿ãã¬ãããšåŒãã§ããŸãã
- ç¹å®ã®ã¹ãã¢ã«çµã³ä»ããããå¶éãè¶ ããŠããªãåºå® TSDããããŸãã ãããã¯ãã¹ãã¢å ã®ããã€ã¹ããŒã«ããã®IPã¢ãã¬ã¹ãæã£ãŠããŸãã
- ãªããžã§ã³ TSDãšããããã察話ããå¥ã®ãªããžã§ã³ãµãŒããŒããããŸãã ãããã®TSDã¯ãç£æ»ãå®è¡ããã¹ãã¢ããã¹ãã¢ã«åžžã«ç§»è¡ããŸãã
ããŒã1.ããšã©ãŒãçºçããŸããããããã§ä¿®æ£ããŸãã
ãããã¯ãŒã¯ãžã®Mikrotikã«ãŒã¿ãŒã®å°å ¥åŸãæåã®åºèã§ã¯ãåãæ¥ã«ããã§ç£æ»ãè¡ãããŸãã
ç£æ»éšéã®ä»äºã®çµç¹ã¯éåžžã«èå³æ·±ããç¬ç¹ã§ãã ãã¹ãŠã®ã¹ãã¢ã«ã¯ãåãSSIDãšæå·åããŒãæã€Wi-Fiã¢ã¯ã»ã¹ãã€ã³ãããããŸãã ãããã£ãŠããªããžã§ã³TSDã«ã¯ç¬èªã®ããŒã«ïŒ192.168.3.0/24ïŒããã®éçIPã¢ãã¬ã¹ããããŸãã
ãããã¯ãŒã¯ã¯åœåãã©ããã ã£ããããããããã®ã¹ãã¢ã«ã¢ã¯ã»ã¹ãããªããžã§ã³TSDã¯ãã¹ãŠåäžã®ãã©ãããããã¯ãŒã¯ã«ãªããåé¡ãªãã©ãã«ã§ããããªããžã§ã³ãµãŒããŒã«æ¥ç¶ãããŸããã
ãªããžã§ã³ãµãŒããŒã¯ãç¹å¥ãªããŒã¿ããŒã¹ãåããRDPãµãŒããŒã§ããã ããã¯ãæ¹èšåã«ã¡ã€ã³ããŒã¿ããŒã¹ãµãŒããŒãšåæãããŠããŸããã ãªããžã§ã³ãµãŒããŒã¯ãã¹ãã¬ãŒãžãµãŒããŒããäœæ¥ã«å¿ èŠãªãã¡ã€ã«ãããŒãããŸããã äž»ã«ç£æ»ãµãŒããŒãšã®ã¿å¯Ÿè©±ããããŒã¿åé端æ«ïŒTSD-ã¿ãã¬ããïŒã ãã ãã極端ãªå Žåããªããžã§ã³ãµãŒããŒã§äœãåé¡ãçºçãããšããªãã£ã¹ã«ããRDPãµãŒããŒãšçŽæ¥ããåãããããšããããŸããã ä»ã®ãã¹ãŠã®TSDïŒã¹ãã¢ã«åžžæé 眮ããããããã«é¢é£ä»ããããŠããïŒã¯ãã¡ã€ã³RDPãµãŒããŒãšã®ã¿å¯Ÿè©±ããŸããã
ã ãããããã¯æ確ã§ã·ã³ãã«ãªããã§ãã å®æçã«åºèããåºèãžãšç§»åããåºèã®åŸæ¥å¡ã«ãšã£ãŠæãããããšãå®è¡ããããã€ã¹ã®ã¢ãã€ã«ã°ã«ãŒãããããŸã-ç£æ»ã
圌女ã¯ãã¹ãã¢å ã®ããŒã«ããåçã«IPãååŸãããªãã£ã¹ã«ãããªããžã§ã³ãµãŒããŒã«æ¥ç¶ãããã極端ãªå Žåã¯ã¡ã€ã³RDPãµãŒããŒã«æ¥ç¶ããã ãã§ãã
ããããå°å ã®ã·ã¹ãã 管çè ãç§ã«èšã£ãããã«ãäŒç€Ÿãé·å¹Žã«ããã£ãŠååšããŠãããããç£æ»äžã«ããŸããŸãªã±ãŒã¹ããããŸããã ãã®1ã€ã¯ãåºèãšæ¬ç€Ÿã®éã®éä¿¡ã®æå³çãªéåã§ãã ãç£æ»ã¯å€±æããŸããã
ãã®ããã æŽå²çã«ã¯ãç£æ»ãµãŒããŒã¯ã·ã§ããã³ã°ãªãã£ã¹ããTSDãšãšãã«ç§»åããŠããŸãã ã ããã¯éåžžãç£æ»æ¥ã®åæ¥ã®å€ã«çºçããŸããã 管çè ã¯ãµãŒããŒãã¹ãã¢ã«æã¡èŸŒã¿ãã¹ãã¢å ã®ä»»æã®ã¹ã€ããã§äœ¿çšå¯èœãªããŒãã«æ¥ç¶ããŸãïŒãããã¯ãŒã¯ããã©ããã§ããããã¹ãŠã®ããŒããåäžã®L2ãã¡ã€ã³ã«ãã£ãŠæ¥ç¶ãããŠããããšãæãåºããŠãã ããïŒã 圌ã¯TSDãæ åœããç«ã¡å»ããŸãã
ããã«ãå€éãã¹ã±ãžã¥ãŒã«ã«åŸã£ãŠãç£æ»ãµãŒããŒã¯æ¬ç€Ÿã«ããä»ã®ãµãŒããŒã«æ¥ç¶ããããŸããŸãªåæãšããŒã¿è€è£œãå®è¡ããŸãã æ¥ç¶ãµãŒããŒã¯åžžã«æ¹èšãµãŒããŒã§ããããšã«æ³šæããããšãéèŠã§ãã
æåã®ã¹ãã¢ã§ã®åæ£ã»ã°ã¡ã³ããããã¯ãŒã¯ã®å°å ¥ã«æ»ããŸãã ããã«ã«ãŒã¿ãŒãèšçœ®ãããŸããããã«ãããL2ã»ã°ã¡ã³ããäžè¬ãªãã£ã¹ããåé¢ããããããã€ããŒã®éä¿¡ãã£ãã«ã«åé·æ§ãæäŸãããŸãã
ã¹ãã¢ã§äœãå€æŽãããããæ確ã«ããããã«ãåã®èšäºã®ç»åããèŠãããŸãããã
å³ãããã¹ãã¢ã«ã€ã³ã¹ããŒã«ãããã«ãŒã¿ãŒãããã€ã¹ã®ãªããžã§ã³ã°ã«ãŒãã®ã¢ããªãã£ã奪ã£ãŠããããšãæããã§ãã
ã«ãŒã¿ãŒã®å°å ¥åŸãåºèã§ã®ã¢ãã¬ã¹æå®ãã©ã®ããã«ãªãããæãåºãããŠãã ããã
- 192.168.1.0/24-ã»ã³ãã©ã«ãªãã£ã¹ãããã¯ãŒã¯
- 192.168.2.0/24-12åºèããããã®192.168.13.0/24ããŒã«ã«ãããã¯ãŒã¯
- 10.10.10.0/24-ã¡ã€ã³ã€ãŒãµããããã£ãã«ãä»ããŠã¡ã€ã³ãªãã£ã¹ã«å°çãããããã¯ãŒã¯
- 10.10.20.0/24-ããã¯ã¢ãããã£ãã«ïŒPONïŒãä»ããŠæ¬ç€Ÿã«å°çãããããã¯ãŒã¯
- 10.20.30.0/24-VPNå ã®ãããã¯ãŒã¯ãå€éšãããã¯ãŒã¯ãä»ããŠISP-1ããIPã«åºå·ããåºèçš
- 10.30.40.0/24-VPNå ã®ãããã¯ãŒã¯ãå€éšãããã¯ãŒã¯ãä»ããŠISP-2ããIPã«åºå·ããåºèçš
ããã§ãç¹å®ã®ã¹ãã¢ã«å°çãããšã以åã®ããã«ãªããžã§ã³ãµãŒããŒãã¹ã€ããã®ç©ºãããŒãã«æ¥ç¶ããTSDã¯Wi-Fiã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããŸãã ãã®åŸã TSDã¯å°ççã«å°ççã«åãã¹ãã¢ã«ããç£æ»ãµãŒããŒãšèªç±ã«éä¿¡ ã§ããŸããããªãã£ã¹ã®ã¡ã€ã³RDPãµãŒããŒã«æ¥ç¶ããããšã¯ã§ããŸããã ãŸããç£æ»ãµãŒããŒèªäœã¯äžåšã®ãããããŒã¿ãåæã§ããŸããã
ãªããªããããã¯æåã®ç¿»èš³å¯èœãªã¹ãã¢ã§ããããããã¯ãŒã¯å šäœãæ°ããåäœã¢ãŒãã«å®å šã«ç§»è¡ãããããã§ã¯ãªãããã§ãã ç£æ»ããŒã ã®äœæ¥ã¹ã±ãžã¥ãŒã«ã¯ãã§ã«ã¹ã±ãžã¥ãŒã«ãããŠããŸããä»æ¥ã¯åœŒããããã«ããŠãææ¥ã¯å¥ã®åºã«ããããŠåã³ããã«ããªã©ã
ç£æ»ããŒã ïŒIPã¢ãã¬ã¹ã®ç¯å²ã¯éçïŒ192.168.3.0/24ïŒã®æ¥ç¶ã確ä¿ããããã®ç·æ¥ã®ãœãªã¥ãŒã·ã§ã³ãå¿ èŠã§ãã
ãã§ã«äžã§è¿°ã¹ãããã«ããã®ã¹ããŒã ã§ã¯ãåæã€ãã·ãšãŒã¿ãŒã¯ãªããžã§ã³ãµãŒããŒèªäœã§ããä»ã®ãµãŒããŒã«æ¥ç¶ããå¿ èŠãªã¿ã¹ã¯ãå®è¡ããŸãã ãªããžã§ã³TSDã¯ãå¿ èŠã«å¿ããŠããªãã£ã¹ã®ã¡ã€ã³RDPãµãŒããŒãšã®RDPã»ãã·ã§ã³ã®ã€ãã·ãšãŒã¿ãŒã§ããããŸãã
ç§ã®ä»äºã¯ããªãã£ã¹ãæã€åºèã®ããããã«ããã¢ãã€ã«ããã€ã¹ã®IPæ¥ç¶ãä¿èšŒããããšã§ãã åæã«ãããã€ã¹ã®ã¢ãã¬ã¹æå®ã¯å€æŽãããŸããã ç¹å®ã®ã¹ãã¢ã§DHCPã¢ãã¬ã¹ãååŸãããªãã·ã§ã³ã¯ãããŸããã
ãããã£ãŠãäžæçãªãã®ãšããŠïŒãããŠããã«äžå®ã®ãŸãŸã§ããããã«ïŒç§ã®é ã«æµ®ããã æåã®è§£æ±ºçã¯ã NATã®å®è£ ã§ãã
ã·ã¹ãã 管çè ã«èª¬æããŸããããç£æ»éšéã®åŸæ¥å¡ã«ããTSD以å€ã®ããã€ã¹ãç£æ»ãµãŒããŒã«æ¥ç¶ããå¿ èŠããªãã®ã¯æ¬åœã§ããïŒ çãã¯ããŒã§ããã 確ãã«ã RDPãä»ããŠããã°ã©ããŒã«ãªã¢ãŒãã§æ¥ç¶ããå¿ èŠãããå ŽåããããŸã ã ãã ããã¹ãã¢å ã®PCãããããã1ã€ã«æ¥ç¶ããããšã§ãããè¡ãããšãã§ããŸããPCããæ¢ã«ãµãŒããŒã«æ¥ç¶ããŠããŸãã ãã¡ãããã¹ãã¢å ã®PCããµãŒããŒãèŠãããšãã§ããå Žåãé€ããŸãã
ããã§ã¯ãã¿ã¹ã¯ã«åãããããŸãããã
ãŸãã管çè ã«ãã¹ãŠã®ãªããžã§ã³TSDãã€ã³ã¹ããŒã«ãããµãŒããŒã«ã¡ã€ã³ã²ãŒããŠã§ã€ã®ã¢ãã¬ã¹192.168.3.2ãã€ã³ã¹ããŒã«ããããã«äŸé ŒããŸãã
ã¹ãã¢ã«ããã«ãŒã¿ãŒã§ãã¹ãã¢ã«åãã£ãŠããã€ã³ã¿ãŒãã§ã€ã¹ã«æ¬¡ã®IPã¢ãã¬ã¹ãè¿œå ããŸãã
[s@VERTOLET-GW] > ip address export # jun/03/2016 21:22:19 by RouterOS 6.32.3 # /ip address add address=192.168.3.2/24 interface=bridge-VERTOLET network=192.168.3.0
ãããã£ãŠããã®æ¹èšãããã¯ãŒã¯ïŒ192.168.3.0/24ïŒã¯çµ¶å¯Ÿã«ãã¹ãŠã®åºèã«è¿œå ãããŸã ãããã«ããã åºèéã移åãããšãã«ããã€ã¹ã®ã¢ãã€ã«ã°ã«ãŒããèšå®ãåæ§æããã«ãåºèã®ã«ãŒã¿ãŒãåç §ã㊠ãããã€ã¹ããªãã£ã¹å ã®ã©ãã«ããããç¥ãããšãã§ããŸãã
ããããåãã¢ãã¬ã¹ãæã€12ã®ã¹ãã¢ãããå Žåããªãã£ã¹ã®ãµãŒããŒã¯ãã±ããã®éä¿¡å ãã©ã®ããã«ç¥ãã®ã§ããããïŒ
ããã§ã NATã¯ç§ãã¡ã®å©ãã«ãªããŸãããã®ç®çã¯ãã¢ãã€ã«ã°ã«ãŒããé£çµ¡ããIPã¢ãã¬ã¹ãå€æŽããããšã§ãã
ãããè¡ãã«ã¯ãã©ã®ãµãŒããŒãã¢ãã€ã«ã°ã«ãŒãã®ããã€ã¹ã«ã¢ã¯ã»ã¹ããå¿ èŠãããããèŠã€ãããããã®ããã€ã¹çšã«åå¥ã®ã¢ãã¬ã¹ãªã¹ããäœæããŸãã
[s@VERTOLET-GW] > ip firewall address-list export # jun/03/2016 21:32:00 by RouterOS 6.32.3 # /ip firewall address-list add address=192.168.1.2XX list=REVISION-Servers add address=192.168.1.2XX list=REVISION-Servers add address=192.168.1.2XX list=REVISION-Servers
次ã«ã NATå€æã®ã«ãŒã«ãäœæããŠãã¢ãã€ã«ã°ã«ãŒãã®é£çµ¡å ã®ã¢ãã¬ã¹ãé衚瀺ã«ããŸãã
[s@VERTOLET-GW] > ip firewall nat export # jun/03/2016 21:42:00 by RouterOS 6.32.3 /ip firewall nat add action=masquerade chain=srcnat comment=FROM-REVISION dst-address-list=REVISION-Servers src-address=192.168.3.0/24
ãã®NATã«ãŒã«ã¯ããªãã£ã¹å ã®å¿ èŠãªãµãŒããŒã«ã¢ã¯ã»ã¹ãããšãã«ãéä¿¡å ã¢ãã¬ã¹ïŒ192.168.3.0ïŒãäžç¶ãããã¯ãŒã¯ã®ã«ãŒã¿ãŒã®ã¢ãã¬ã¹ïŒ10.0.0.0/8ïŒã«å€æŽããŸãã
ãã®ãããåé¡ã¯ãã§ã«éšåçã«è§£æ±ºãããŠããŸãã ã¢ãã€ã«ã°ã«ãŒãã¯ä»»æã®åºèã«èªç±ã«æ¥ãŠãæ¢è£œã®ã²ãŒããŠã§ã€ãåŸ æ©ããŠãããããã¯ãŒã¯ã«æ¥ç¶ããäžå€®ãªãã£ã¹ãžã®æ¥ç¶ãéå§ã§ããŸãã
ãœãªã¥ãŒã·ã§ã³ãå®è£ ããæåã®æ¥ã«çŽé¢ãããã®åé¡ãæãåºãããŠãã ããã ãããã¯ãŒã¯å šäœãå€æŽã®æºåãã§ã㊠ããªãã£ãããã ãµãŒããŒãã¹ãã¢éã®ã¢ãã¬ã¹æå®ã«ã€ããŠäœãç¥ããªãã£ããšããç¶æ³ããããŸããã ãŸããKerioãµãŒããŒã¯ã翻蚳ãããã¹ãã¢ã®ãããã¯ãŒã¯ãžã®ã«ãŒããããªãã£ã¹å ã®ç¬ç«ããæ§ãããªMikrotikã«ãŒã¿ãŒã«éçã«ç»é²ãããããããã®ã²ãŒããŠã§ã€ã§ããã
åŸã«ã¡ã€ã³ã«ãŒã¿ãŒã«ãªãããšã§ããã
ããã¯ããªãã£ã¹ã§ïŒã¢ãã€ã«ã°ã«ãŒãã«ãã£ãŠã¢ã¯ã»ã¹ãããïŒãµãŒããŒããäžç¶ãããã¯ãŒã¯ïŒ10.0.0.0/8ïŒãé ãããã«å¥ã®NATå€æãè¡ãå¿ èŠãããããšãæå³ããŸãã
ã¹ãã¢ãšåãããã«ãã¢ãã¬ã¹ãªã¹ããè¿œå ããŸã
[s@MAIN-BORDER-ROUTER] > ip firewall address-list export # jun/03/2016 21:52:12 by RouterOS 6.32.2 # /ip firewall address-list add address=192.168.1.2XX list=REVISION add address=192.168.1.2XX list=REVISION add address=192.168.1.2XX list=REVISION
ãŸãã翻蚳ã«ãŒã«ïŒ
[s@MAIN-BORDER-ROUTER] > ip firewall nat export # jun/03/2016 21:52:12 by RouterOS 6.32.2 # /ip firewall nat add action=masquerade chain=srcnat comment=NAT-KOSTUL-REVISION dst-address-list=REVISION src-address=10.0.0.0/8
ã芧ã®ãšããããã®ãœãªã¥ãŒã·ã§ã³ã«ååãä»ããèãããªãã£ãããããã®ã«ãŒã«-æŸèæã«æ£çŽã«çœ²åããå¿ èŠããããŸããã
ãã®æ®µéã§ãã¢ãã€ã«ããã€ã¹ã°ã«ãŒããšä»»æã®ã¹ãã¢ãããªãã£ã¹å ã®ãµãŒããŒãšã®æ¥ç¶ã確ä¿ããã¿ã¹ã¯ãå®äºããŸããã
ããã°ã©ããŒã®ç£æ»ãµãŒããŒãžã®ãªã¢ãŒãã¢ã¯ã»ã¹ã¯ãå¿ èŠã«å¿ããŠãåºèã®ã«ãŒã¿ãŒãä»ããŠãããã¯ãŒã¯192.168.3.0/24ã«ã¢ã¯ã»ã¹ããåºèå ã®ä»»æã®PCã«æ¥ç¶ãããã®ãããã¯ãŒã¯ãçŽæ¥æ¥ç¶ããããããã¯ãŒã¯ãšããŠèªèããŠååŸã§ããŸãã
ããŒã2. Wi-Fiããªã³ã¿ãŒãå€æã®å°å·ãæåŠããŸãïŒ
æåã®ã¹ãã¢ã«ãããã¯ãŒã¯ãå°å ¥ãããæåŸã®ã¹ãã¢ããã®ã¹ããŒã ã«ç§»è¡ãããŠããçŽ3é±éãçµéããŸããã ãã®æç¹ã§ã軜埮ãªæ¬ ç¹ãè¡šé¢åããæ¥ãã§ä¿®æ£ãããŸããã äžè¬ã«ãèšç»éãã«ãã¹ãŠãããŸããããŸããã é¢çœãã®ã¯ãæåã®åºèãæ°ããæäœã¢ãŒãã«åãæ¿ããåŸãISPãäºæ ãèµ·ãããŠãã®åºèãéä¿¡ã§ãããã·ã¹ãã ãå®å šã«åäœããŠäºåã«åãæ¿ããããšã§ãã
æåŸã®åºèã§ã®å°å ¥ãè¡ããããšããã·ã¹ãã 管çè ã¯ãçµå¶è ã解決ããå¿ èŠãããã¿ã¹ã¯ãšããŠæ瀺ããå¥ã®ãã¥ã¢ã³ã¹ã«ã€ããŠäžç¢ºå®æ§ãæã£ãŠç§ã«èšã£ãã
ã¢ãã€ã«ã°ã«ãŒãã«ã¯ãå¥ã®åºèã«è¡ãç¯å²ïŒ192.168.3.0/24 ïŒã®TSDãæã€å¥ã®åŸæ¥å¡ãããŸããã圌ã®ã¿ã¹ã¯ã¯ãæå¹æéãåããååãåè©äŸ¡ããããšã§ãã
TSDããã圌ã¯ãªãã£ã¹ã«ããã¡ã€ã³RDPãµãŒããŒã«æ¥ç¶ããããŒã¿ããŒã¹ãæäœããŸãã 補åãã¹ãã£ã³ããæ°ããå€æãå°å·ããŸãã
ãã¹ãŠãé 調ã§ãåŸæ¥å¡ã¯éãã«1ã€ãŸãã¯å¥ã®åºã«æ¥ãŠã以åã®ããã«Wi-Fiãããã¯ãŒã¯ã«ããã¿ã€ããåé¡ãªããªãã£ã¹ã®RDPãµãŒããŒã«æ¥ç¶ããå¿ èŠãªããšãè¡ããããªã³ã¿ãŒãžã®å°å·ãéå§ããŸãããå€æãå°å·ãããŠããããªã³ã¿ãŒã¢ãã€ã«ïŒ 以åã¯192.168.1.0/24ã®ç¯å²ã®IPã¢ãã¬ã¹ãæã¡ãåäžã®L2ãæã€ãã©ãããããã¯ãŒã¯ã§ã¯ãã©ã®ã¹ãã¢ãããå©çšã§ããŸããã
ãŸãããªãã£ã¹ããæ¹èšãµãŒããŒã«æ¥ç¶ãããšããæ¹èšãè¡ãããåºèã®ã³ã³ãã¥ãŒã¿ãŒã®1ã€ããæ¹èšãµãŒããŒãNATã®èåŸã«ãããšããäºå®ã®ããã«ããã°ã©ããŒã«ãã£ãŠå æãããããã«ã¢ã¯ã»ã¹ããã«ã¯ãåºã
äžè¬ã«ãæ°ããã¿ã¹ã¯ãèšå®ãããŠããŸãã
- ãªãã£ã¹ããã¢ãã€ã«ããªã³ã¿ãŒã«å°å·ããæ©èœãæäŸãã
- ãªãã£ã¹ããçŽæ¥RDPçµç±ã§ç£æ»ãµãŒããŒã«æ¥ç¶ããæ©èœãæäŸãã
ããŠãä»ãç§ãã¡ã¯ãåçã«ãŒãã£ã³ã°ãããã³ã«ã®å°å ¥ããæ¥ãŸããããããããåºãŠããªãã§ãæåã®éšåã«æ®ãããšã«ããŸããã
OSPFãžããããïŒ
ããã§ãæåã®èšäºã§æžããããã«ã OSPFãã±ãããISP-1ãããã¯ãŒã¯ãééããªãã£ããããçå®ã¯åã³å¥ã®æŸèæãäœããªããã°ãªããŸããã§ãã ã CPEïŒHuaweiã®xPON端æ«ïŒãåã«ãããã³ã«89ãããããããããããã«ããã£ã¹ãã§ããŠããã£ã¹ãã§ããããŸããã
ãã®ãããäž»ã«åé·æ§ãç®çãšãããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã«OSPFãå®è£ ããããšã«ããŸããã
ãã®ç¶æ³ã§ã®OSPFã¯ã次ã®2ã€ã®ããšã«å¿ èŠã§ãã
- å°å·çšã®å°ããªãã¡ã€ã«ã転éããããã«ããªãã£ã¹ã®ã«ãŒã¿ãŒã«Wi-Fiããªã³ã¿ãŒãæ¢ãå Žæãåçã«æå®ããŸã
- ãªããžã§ã³ãµãŒããŒãæ¢ãå Žæããªãã£ã¹ã®ã«ãŒã¿ãŒã«åçã«ç€ºããããã«RDPå¶åŸ¡ã³ãã³ããéä¿¡ããŸãïŒãªããžã§ã³ãµãŒããŒãããªãã£ã¹ãžã®ãªã¿ãŒã³ãã©ãã£ãã¯ã¯ãæåã®èšäºã§æå³ãããšããã«ãªããŸãïŒ
OSPFãä»ããŠã¢ãã€ã«ã°ã«ãŒãïŒ192.168.3.0/24ïŒã®ãããã¯ãŒã¯å šäœãéä¿¡ããå¿ èŠã¯ãããŸãããããã«ããããè¡ãããšã¯ã§ããŸããã åè©äŸ¡æ åœè ãšç£æ»ããŒã ã¯ç°ãªãå Žæã«ããããšãå€ããåãšWi-Fiããªã³ã¿ãŒãåæã«æ¥ç¶ããå¿ èŠããããŸãã
ãããã£ãŠããã®åé¡ã«å¯Ÿããæãæé©ãªè§£æ±ºçã¯ã ããå ·äœçãªã¢ãã¬ã¹/ 32ãããã2ã€ã®ããã€ã¹ïŒããªã³ã¿ãŒãšãµãŒããŒïŒã«è»¢éããããšã§ãããšå€æããŸããã
ãããè¡ãã«ã¯ããªããOSPFæ©èœã®æ¬¡ã®ããŒã«ãå¿ èŠã§ãã
- ãã€ã³ãããŒãã€ã³ããããã¯ãŒã¯ã¿ã€ã
- éçã«ãŒãã®åé åž
- ãã£ã«ã¿ãªã³ã°
æåã«ãåºèãããªãã£ã¹ã«Wi-Fiããªã³ã¿ãŒãšãµãŒããŒã«é¢ããæ å ±ã転éããæ¹æ³ã®ã¢ã«ãŽãªãºã ã決å®ããŸãã
ãã®ãããOSPFã¯ããããã®ãããã¯ãŒã¯ããã®ã«ãŒã¿ãŒã«æ¥ç¶ãããŠããããšãããã³ãããã®ã«ãŒããäžå€®ã«ãŒã¿ãŒã«ã¢ããã¿ã€ãºãããå¿ èŠãããããšãèªèããŠããå¿ èŠããããŸãã
OSPFã¯ã2ã€ã®æ¹æ³ã§ãããã¯ãŒã¯ãã¢ããŠã³ã¹ããŸãã
- ãã®ã€ã³ã¿ãŒãã§ã€ã¹ãããã·ãã§ãªãå ŽåãOSPFãæå¹ã«ãªã£ãŠããã€ã³ã¿ãŒãã§ã€ã¹ã«å±ãããã¹ãŠã®ãããã¯ãŒã¯ãã¢ããŠã³ã¹ããŸãã
- ä»ã®åçã«ãŒãã£ã³ã°ãããã³ã«ãçŽæ¥æ¥ç¶ãããã«ãŒããéçã«ãŒãã®åé åžã«ãããããã¯ãŒã¯ã¢ããŠã³ã¹
ã ãããç§ã¯æ¬¡ã®ããšãããããšã«ããŸããïŒ
- ãã¹ãŠã®ã¹ãã¢ãšäžå€®ã«ãŒã¿ãŒã§OSPFããã»ã¹ãèµ·åãã
- ãã¹ãŠã®ã¹ãã¢ã®ãµãŒããŒããã³ããªã³ã¿ãŒçšã«éçã«ãŒã/ 32ãäœæããŸã
- åé åžäžããã³OSPFã§ã®äžèŠãª xéçã«ãŒãïŒããã³å€æ°ããïŒã®ãã£ã«ã¿ãªã³ã°
- NetWatchã 䜿çšããŠãç¹å®ã®ã¹ãã¢å ã®ããã€ã¹ã®å®éã®å¯çšæ§ã远跡ããéçã«ãŒãã管çããŸãã
ãã¹ãŠãæãããªããã§ãå®è£ ã«é²ã¿ãŸãã
åºèããã³ãªãã£ã¹ã®ã«ãŒã¿ãŒã§OSPFããã»ã¹ãèµ·åããŸãã
ãã¹ãŠã®åºèã¯1ã€ã®ããã©ã«ããšãªã¢0ã«ãããŸãã
OSPFã«ãŒã¿ãŒéã®è¿é£ç¶æ ã¯ããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã§çºçããŸã ãååºèãšãªãã£ã¹ã®éã«ã¯2ã€ãããŸãã
Mikrotikã«ãŒã¿ãŒã§ã¯ãããã©ã«ãã§ãã€ã³ãããŒãã€ã³ãã€ã³ã¿ãŒãã§ã€ã¹ã®ã³ã¹ãã¯-10ã§ãã ååºèãšãªãã£ã¹ã®éã«2ã€ã®VPNãã£ãã«ãããããããã£ãã«2ã®ã³ã¹ãã20ã«èšå®ããŸãã
[s@KREDO-MAIN-BORDER-ROUTER] > routing ospf export # jun/03/2016 22:42:36 by RouterOS 6.32.2 # /routing ospf instance set [ find default=yes ] router-id=255.255.255.255 /routing ospf interface add cost=20 interface=2.VERTOLET-VPN-RESERVE network-type=point-to-point /routing ospf network add area=backbone network=10.20.30.0/24 add area=backbone network=10.30.40.0/24
åºèå ã®ã«ãŒã¿ãŒã§åæ§ã®ã¢ã¯ã·ã§ã³ãå®è¡ããããã«éçã«ãŒããåé åžããå¿ èŠæ§ãææããããããã¿ã€ã1ãšããŠã¢ããŠã³ã¹ããããšã«ããŸããã
[s@KREDO-VERTOLET-GW] > routing ospf export # jun/03/2016 22:50:17 by RouterOS 6.32.3 # /routing ospf instance set [ find default=yes ] redistribute-static=as-type-1 router-id=192.168.15.2 in-filter=ospf-in out-filter=ospf-out /routing ospf interface add cost=20 interface=VPN-OFFICE-RESERVE network-type=point-to-point add interface=VPN-OFFICE network-type=point-to-point /routing ospf network add area=backbone network=10.20.30.0/24 add area=backbone network=10.30.40.0/24
æå®ãããæ§æã«ã¯ã ã¿ã€ã1ãªã©ã®éçã«ãŒãã®åé åžãæ åœããã³ãã³ããå«ãŸãããã®ã¿ã€ãã¯ã¿ã€ã2ãããåªå 床ãé«ããã«ãŒã¿ãŒéã§ã¢ããã¿ã€ãºããããšã¡ããªãã¯ãå€åããŸã ã ãŸãã OSPFèšå®ã§2ã€ã®ãã£ã«ã¿ãŒãæå®ããŸããïŒ ospf-inããã³ospf-out ã Mikrotikã®ãããã®ãã£ã«ã¿ãŒã¯ã Ciscoã«ãŒã¿ãŒã®ã«ãŒããããã«äŒŒã圹å²ãæãããŸãã
ãããã®ãã£ã«ã¿ãŒãæ€èšããããšãææ¡ããŸãã
[s@VERTOLET-GW] routing filter export # jun/03/2016 23:01:57 by RouterOS 6.32.3 # /routing filter add action=discard chain=ospf-in ospf-type=external-type-1 add action=discard chain=ospf-in ospf-type=intra-area add action=accept chain=ospf-out prefix=192.168.3.3 protocol=static add action=accept chain=ospf-out prefix=192.168.3.252 protocol=static add action=discard chain=ospf-out protocol=static
ospf-inãã£ã«ã¿ãŒã¯ã OSPFãçµç±ããŠã«ãŒã¿ãŒã«å°éããå¯èœæ§ã®ããã«ãŒãããã£ã«ã¿ãªã³ã°ããŸãã
ospf-outãã£ã«ã¿ãŒã¯ããµãŒããŒããã³Wi-Fiããªã³ã¿ãŒçšã®ããå ·äœçãª/ 32ã«ãŒããé€ããåé åžãéããŠã¢ããã¿ã€ãºã§ãããã¹ãŠã®å¯èœãªã«ãŒãããã£ã«ã¿ãŒã§é€å€ããŸãã
çŸåšãã¢ãã€ã«ããã€ã¹çšã«éç/ 32ã«ãŒããè¿œå ããå¿ èŠããããŸããããã®å Žæã«æ³šæããå¿ èŠããããŸãã
[s@VERTOLET-GW] > ip route export # jun/03/2016 23:08:46 by RouterOS 6.32.3 # /ip route add comment=MOBILE-WiFi-PRINTER disabled=yes distance=1 dst-address=192.168.3.3/32 gateway=bridge-VERTOLET add comment=Revision-SERVER disabled=yes distance=1 dst-address=192.168.3.252/32 gateway=bridge-VERTOLET
disabled = yesãã©ã¡ãŒã¿ãŒã䜿çšããŠãããã®éçã«ãŒããè¿œå ããŠããããšã«æ³šæããŠãã ãããã€ãŸãã ãããã®ã«ãŒãã¯ãªãã«ãªããã¢ã¯ã»ã¹ã§ããªããªããŸãã ã€ãŸãã OSPF ãéããŠã¢ããŠã³ã¹ãããŸãã ã
ãªãã§ïŒ ãªããªãããã¹ãŠã®ã¹ãã¢ã«ã¢ã¯ãã£ãã«ãŒããäžåºŠã«è¿œå ãããšãã¡ã€ã³ã«ãŒã¿ãŒäžã§ãããããã¹ãŠã®ã¹ãã¢ããèŠããããã«ãªããå ã®ã«ãŒãã«æ»ãããã§ãã Wi-Fiããªã³ã¿ãŒãã©ãã§ãã£ããããã®ãå ·äœçã«ããããªãå Žåã¯ã ãããã®ã«ãŒãã¯ãã¹ãŠã®åºèã«ååšããŸãã
ãããã£ãŠã éçã«ãŒãã¯ããã©ã«ãã§ãªãã«ãªã£ãŠ ãããããã€ã¹ãç¹å®ã®ã¹ãã¢ã«å®éã«è¡šç€ºããããŸã§èª°ãéçã«ãŒãã«ã€ããŠè©±ããŸããã
pingãä»ããããã€ã¹ã®å¯çšæ§ã«ãã£ãŠãããç解ã§ãããããåçŽãªã¹ã¯ãªããã䜿çšããŠ2ã€ã®NetWatchã«ãŒã«ãäœæããŸãã
[s@KREDO-VERTOLET-GW] >tool netwatch expoart # jun/03/2016 23:15:59 by RouterOS 6.32.3 # /tool netwatch add down-script="/ip route set [find comment=\"MOBILE-WiFi-PRINTER\"] disable=yes" host=192.168.3.3 interval=10s timeout=2s up-script="/ip route set [find comment=\"MOBILE-WiFi-PRINTER\"] disable=no" add down-script="/ip route set [find comment=\"Revision-SERVER\"] disable=yes" host=192.168.3.252 interval=10s timeout=2s up-script="/ip route set [find comment=\"Revision-SERVER\"] disable=no"
ãããã®ã«ãŒã«ã¯éåžžã«åçŽãªåœ¹å²ãæãããŸããããã¯ãã¡ãªã¿ã«ã·ã¹ã³ã®äžçã®ip sla + trackã«äŒŒãŠããŸãã
ãµãŒããŒãšWi-Fiããªã³ã¿ãŒã«2ç§ã®ã¿ã€ã ã¢ãŠãã§10ç§ããšã«pingãå®è¡ããŸãã pingãæåããå Žå㯠ã éçã«ãŒããæå¹ã«ããŸã ãããã«ããã åé åžã«ããOSPFã«å³åº§ã«åãæ¿ããããªãã£ã¹ã®ã¡ã€ã³ã«ãŒã¿ãŒãããã€ã¹ã®å ŽæãèŠã€ããŸãã
ãããã£ãŠã Wi-Fiããªã³ã¿ãŒã¯ä»¥åãšåãããã«åã³å°å·ãããããã«ãªããããã°ã©ããŒã¯ãªããžã§ã³ãµãŒããŒã§RDPãçŽæ¥æäœã§ããŸãã ãã©ãããããã¯ãŒã¯ããããã®ããã«ã
6ãæåŸããããžã§ã¯ããå®å šã«éå§ãããç¬éããèšäºãæžããŸããã éå»6ãæéããã¹ãŠãå®ç§ã«æ©èœãã倱æããããšã¯ãããŸããã§ããã Wi-Fiããªã³ã¿ãŒã¯æ£åžžã«ãã£ãããããæ®å¿µãªããISPã®ã¯ã©ãã·ã¥ãçºçããŸãããåºèã¯ããã«æ°ä»ããŸããã
ãã®èšäºã¯åã³å€§ããªèšäºã«ãªããŸãããã泚æãšå¿èã«æè¬ããŸãã æ¹å€ãšã³ã¡ã³ããæè¿ããŸãã ã質åãããå Žåã¯ãåãã§ãçããã ããã