ããã«ã¡ã¯habrïŒ ã·ã¹ã³ã®æ©åšã§VRFã䜿çšããŠVPNãèšå®ããããšã«ã€ããŠãã€ã³ã¿ãŒãããäžã«å€ãã®èšäºããããŸãã IPsec VPNãæå·åã«ãŒãããã³VTIãã³ãã«ãšVRFã®åœ¢åŒã§èšå®ããããã®åªããããŒãã·ãŒãããããŸãã ãã®èšäºã§ã¯ã HabrãVRFã䜿çšããDMVPNã®äŸãæäŸããŠããŸãã VRFã¯ãæ©åšã®ã»ããã¢ããæã«å€§ããªæè»æ§ãæäŸãããã®äœ¿çšäºäŸã¯å€§èŠæš¡ã§ãã äž»ãªããšã¯ããã®ãããªããŒã«ãããããšãå¿ããªãããšã§ãã ç§ã®èšäºã§ã¯ãIPsecãã³ãã«ãæ§ç¯ããããã®ããã³ããã¢VRFã®äœ¿çšãæçšã§ãã£ããç§ãã¡ã®å®è·µããå¥ã®èå³æ·±ãã¿ã¹ã¯ãæ€èšããããšã«ããŸããã ç°ãªãã€ã³ã¿ãŒããããããã€ããŒãä»ããŠäžŠåVPNãã³ãã«ãæ§ç¯ãããããã®ãã³ãã«ãä»ããŠãã©ãã£ãã¯ãåæ£ããããšã«ã€ããŠã§ãã
ä»®æ³ã«ãŒãã£ã³ã°ããã³è»¢éïŒVRFïŒãã¯ãããžã«ããã1ã€ã®ç©çã«ãŒã¿ãŒãè€æ°ã®è«çïŒä»®æ³ïŒã«ãŒã¿ãŒã«åå²ã§ããŸãã ãã®æè¡ã®ãããã§ãåãç©çã«ãŒã¿ãŒäžã«è€æ°ã®ç¬ç«ããã«ãŒãã£ã³ã°ããŒãã«ãæã€ããšãå¯èœã«ãªããŸãã VRFãã¯ãããžãŒã¯ãMPLSãããã¯ãŒã¯ã§åºãæ®åããŠããŸãã ãã ããVRFã¯MPLSãªãã§äœ¿çšã§ããŸãã ãã®å Žåãã·ã¹ã³ã®çšèªã§ã¯ããã¯ãããžãŒã¯VRF liteãšåŒã°ããŸãã ããæ£ç¢ºã«ã¯ãVRF-liteã¯ãã¢ãã¬ã¹ã¹ããŒã¹ãéè€ããç°å¢ã§ã1ã€ã®VPNã³ã³ã»ã³ãã¬ãŒã¿ãŒäžã«2ã€ä»¥äžã®VPNãã³ãã«ãæ§ç¯ã§ãããã¯ãããžãŒã§ãã ãã®ã¡ã¢ã§ã¯ãã¢ãã¬ã¹ã¹ããŒã¹ã®å ±ééšåã¯åœ±é¿ãåããŸããã
VRFãšçµã¿åãããŠVPNã䜿çšããçç±ãç°¡åã«æ€èšããŸãã ãã©ãã£ãã¯ãæå·åããå¿ èŠãããä¿è·ããããããã¯ãŒã¯ã¯ãã«ãŒã¿ãŒã®ã°ããŒãã«VRFã«é 眮ãããªãå ŽåããããŸãã ä¿è·ããããããã¯ãŒã¯ã®VRFã¯ãIVRF-Inside VRFãšåŒã°ããŸãã ãã ããããã©ã«ãã§ã¯ãã«ãŒã¿ãŒã¯ã°ããŒãã«VRFã§IPsecãæ§ç¯ããŸãã ã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒã¯ãã«ãŒã¿ãŒã®ã°ããŒãã«VRFã«ãååšããªãã«ãŒã¿ãŒã€ã³ã¿ãŒãã§ã€ã¹ã«æ¥ç¶ã§ããŸãã ãã®ã€ã³ã¿ãŒããããããã€ããŒã®æ¥ç¶ã«ãããã«ãŒã¿ãŒã®æ¢åã®ãã¹ãŠã®ã€ã³ã¿ãŒãããæ¥ç¶ã§ããªã¢ãŒããã€ã³ãããã®VPNãã³ãã«ãåæã«çµäºããŠå©çšã§ããŸãã
ISPãåãã°ããŒãã«VRFã«æ¥ç¶ãããŠããå Žå
ãã®å Žåãã°ããŒãã«VRFã®ã«ãŒã¿ãŒã«ã¯åäžã®ããã©ã«ãã«ãŒãããããŸãã ãªã¢ãŒããªãã£ã¹ã¯ãå©çšå¯èœãªãã¹ãŠã®ã€ã³ã¿ãŒããããã£ãã«ãä»ããŠãåé¡ã®ã«ãŒã¿ãŒãžã®äžŠåVPNãã³ãã«ãæ§ç¯ã§ããŸãã ãã ããåé¡ã®ã«ãŒã¿ãŒããã®å¿çãã©ãã£ãã¯ã¯ãåäžã®ã€ã³ã¿ãŒããããããã€ããŒãçµç±ããããã©ã«ãã«ãŒãã«åŸã£ãŠéä¿¡ãããŸãã ãã®çµæãããã©ã«ãã«ãŒãã§ç€ºãããã€ã³ã¿ãŒããããããã€ããŒã®ã¿ãå¿çãã©ãã£ãã¯ã§ç Žæ£ãããŸãã IPsec VTIãã³ãã«ã«åºã¥ããäŸãèããŠã¿ãŸãããã
R1ã«ãŒã¿ãŒã®ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹èšå®ïŒ
ã«ãŒã¿ãŒR2ã®ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹èšå®ïŒ
æ瀺ãããæ§æã®å Žåããã³ãã«åããããã©ãã£ãã¯ã¯ãã«ãŒã¿ãŒR1ã®ã€ã³ã¿ãŒããããããã€ããŒéã§æ¬¡ã®ããã«åæ£ãããŸãã
R1ããR2ãžã®Tunnel2 IPsecãã±ããã®ãœãŒã¹IPã¢ãã¬ã¹ã¯2.2.2.1ã§ãããæåã®ISP1ã€ã³ã¿ãŒããããããã€ããŒã®ãã£ãã«ãééããŸãã äžéšã®ã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒã¯ããå€éšã®ãã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒã«å±ãããœãŒã¹IPã¢ãã¬ã¹ãæã€ãã©ãã£ãã¯ããããã¯ããŸãã ãããã€ããŒãæå®ããããã§ãã¯ãè¡ãå ŽåãTunnel2ã¯ã€ã³ã¹ããŒã«ãããŸããïŒãããã£ãŠãR1ããR2ãžã®Tunnel2è¡ã®äžéšã¯ç Žç·ã§è¡šç€ºãããŸãïŒã
R1ã«ãŒã¿ãŒã®ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹èšå®ïŒ
interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ! interface GigabitEthernet0/1 ip address 1.1.1.1 255.255.255.252 ! interface GigabitEthernet0/2 ip address 2.2.2.2 255.255.255.252 ! interface Tunnel1 ip unnumbered GigabitEthernet0/0 tunnel source 1.1.1.1 tunnel mode ipsec ipv4 tunnel destination 3.3.3.1 tunnel path-mtu-discovery tunnel protection ipsec profile ipsec-prof ! interface Tunnel2 ip unnumbered GigabitEthernet0/0 tunnel source 2.2.2.1 tunnel mode ipsec ipv4 tunnel destination 3.3.3.1 tunnel path-mtu-discovery tunnel protection ipsec profile ipsec-prof ! ip route 0.0.0.0 0.0.0.0 1.1.1.2 ip route 0.0.0.0 0.0.0.0 2.2.2.2 10
ã«ãŒã¿ãŒR2ã®ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹èšå®ïŒ
interface GigabitEthernet0/0 ip address 192.168.2.1 255.255.255.0 ! interface GigabitEthernet0/1 ip address 3.3.3.1 255.255.255.252 ! interface Tunnel1 ip unnumbered GigabitEthernet0/0 tunnel source 3.3.3.1 tunnel mode ipsec ipv4 tunnel destination 1.1.1.1 tunnel path-mtu-discovery tunnel protection ipsec profile ipsec-prof ! interface Tunnel2 ip unnumbered GigabitEthernet0/0 tunnel source 3.3.3.1 tunnel mode ipsec ipv4 tunnel destination 2.2.2.1 tunnel path-mtu-discovery tunnel protection ipsec profile ipsec-prof ! ip route 0.0.0.0 0.0.0.0 3.3.3.2
æ瀺ãããæ§æã®å Žåããã³ãã«åããããã©ãã£ãã¯ã¯ãã«ãŒã¿ãŒR1ã®ã€ã³ã¿ãŒããããããã€ããŒéã§æ¬¡ã®ããã«åæ£ãããŸãã
R1ããR2ãžã®Tunnel2 IPsecãã±ããã®ãœãŒã¹IPã¢ãã¬ã¹ã¯2.2.2.1ã§ãããæåã®ISP1ã€ã³ã¿ãŒããããããã€ããŒã®ãã£ãã«ãééããŸãã äžéšã®ã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒã¯ããå€éšã®ãã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒã«å±ãããœãŒã¹IPã¢ãã¬ã¹ãæã€ãã©ãã£ãã¯ããããã¯ããŸãã ãããã€ããŒãæå®ããããã§ãã¯ãè¡ãå ŽåãTunnel2ã¯ã€ã³ã¹ããŒã«ãããŸããïŒãããã£ãŠãR1ããR2ãžã®Tunnel2è¡ã®äžéšã¯ç Žç·ã§è¡šç€ºãããŸãïŒã
ã€ã³ã¿ãŒããããããã€ããŒã®ãã£ãã«ãæ¥ç¶ããããã³ãã«åãããïŒç¹ã«æå·åãããïŒãã©ãã£ãã¯ã衚瀺ãããVRFã¯ãFVRF-ããã³ããã¢VRFãšåŒã°ããŸãã IPsecãVRFã§æ£ããæ§æãããšãIPsecã䜿çšããŠIVRFãšFVRFéã®æ¥ç¶ãååŸããŸãã ã€ãŸããä¿è·ããããã©ãã£ãã¯ã¯IVRFã«å ¥ããã«ãã»ã«åãããåŸããã³ãã«ã¯èªåçã«FVRFã«å ¥ããŸããFVRFã«ã¯ä»ã®ã«ãŒãã£ã³ã°ã«ãŒã«ãé©çšãããŸãã ãããŠãããã¯éåžžã«äŸ¿å©ã§ãã
äŸã®èª¬æã«æ»ããŸãã åæ£ãããã¯ãŒã¯ããããŸãã ã»ã³ãã©ã«ãªãã£ã¹ïŒä»¥äžãCHãšåŒã³ãŸãïŒã«ã¯ã2ã€ã®ã€ã³ã¿ãŒããããããã€ããŒãããããããããç¬èªã®ã·ã¹ã³ã«ãŒã¿ãŒã«æ¥ç¶ãããŠããŸãã æåã®ISP1 ISPã¯ãªã¢ãŒããªãã£ã¹ãžã®VPNã«äœ¿çšããã2çªç®ã®ISP2 ISPã¯ã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ã«äœ¿çšãããŸãã HSRPãã¡ãŒã¹ããããäºçŽãããã³ã«ã¯ãäžå€®ã«ãŒã¿ãŒã«ãŒã¿ãŒéã§æ§æãããŸãã ãªã¢ãŒããªãã£ã¹ã§ã¯ãå¢çæ©åšã«2ã€ã®ãªãã·ã§ã³ããããŸãã
- Ciscoã«ãŒã¿ãŒã ãããã®ãªãã£ã¹ã®åã«VTIãã³ãã«ãæ§ç¯ãããŠããŸãã
- Cisco NPEã«ãŒã¿ã¯Cisco ASAãšãã¢ã«ãªã£ãŠããŸãã ãããã®ãªãã£ã¹ã®åã«ãGRE over IPsecãã³ãã«ãæ§ç¯ãããŸããã GREã¯ã«ãŒã¿ã§çµç«¯ãããCisco ASAã§IPsecã§æå·åãããŸãã
ãããã¯ãŒã¯å³ïŒ
ã»ã³ãã©ã«ãªãã£ã¹ãšãªã¢ãŒããªãã£ã¹ã®éã§ãã«ãŒãã¯EIGRPãä»ããŠéä¿¡ãããŸãã ISP1ãŸãã¯ã«ãŒã¿ãŒR1ã«é害ãçºçããå Žåããã¹ãŠã®ãã©ãã£ãã¯ã¯ISP2ããã³ã«ãŒã¿ãŒR2ã«éãããŸãã ISP2ãŸãã¯R2ã«é害ãçºçããå Žåãã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã¯ããããISP1ããã³R1ãä»ããŠè¡ãããŸãã ãã®ã¹ããŒã ã¯ãEIGRPãHSRPãããã³PBRã«ããå®è£ ãããŠããŸãã PBRã¯ãISP2ãä»ããŠã€ã³ã¿ãŒãããã«ãã©ãã£ãã¯ããªãã€ã¬ã¯ãããããã«äœ¿çšãããŸãã PBRã¯ãISP2ãã«ã¹ãã©ããã³ã°ïŒIP SLA PBRãªããžã§ã¯ããã©ããã³ã°ïŒã䜿çšããŠæ§æãããŸãã
ææŠãã
3çªç®ã®ISP3 ISPã¯ãã«ãŒã¿ãŒR1ã®ã»ã³ãã©ã«ããŒãã£ã³ã°ã»ã³ã¿ãŒã«æ¥ç¶ãããŠããŸãã R1ã®ISP1ããã³ISP3ãä»ããŠãã³ãã«å šäœã«ãã©ãã£ãã¯ãåæ£ããå¿ èŠããããŸãã ãŸããã»ã³ãã©ã«ããŒãã£ã³ã°ã»ã³ã¿ãŒã®ã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒããã³ã»ã³ãã©ã«ããŒãã£ã³ã°ã·ã¹ãã ã®ã«ãŒã¿ãŒã®ãã©ãŒã«ããã¬ã©ã³ã¹èŠä»¶ãæºããå¿ èŠããããŸãã é害ã«é¢ãããã¹ãŠã®ãªãã·ã§ã³ãæžãçããããã§ã¯ãããŸãããæãéèŠãªèŠä»¶ã«ã€ããŠã®ã¿èšåããŸãïŒISP1ã¯ããªã¢ãŒããªãã£ã¹ïŒå³ã®ç·ã®ãã³ãã«ïŒãžã®éåžžã®ãã©ãã£ãã¯ãå®è¡ãããããã§ããã ãèªç±ã«ããŠããå¿ èŠããããŸãã ã€ãŸããISP2ã«é害ãçºçããå Žåãã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã¯ISP3ã«è¡ããISP3ã«é害ãçºçããå Žåãå±éããããµãŒãã¹ïŒå³ã®èµ€ããã³ãã«ïŒã®ãã©ãã£ãã¯ã¯ISP2ã«è¡ããŸãã
æ°ãããã£ãã«ïŒISP3ïŒãèæ ®ãããããã¯ãŒã¯å³ïŒ
解決ç
ç°¡åãªèª¬æ
éåžžã®ãããã¯ãŒã¯ã¢ãŒãã®R1ã«ãŒã¿ãŒïŒãã¹ãŠã®ã€ã³ã¿ãŒããããããã€ããŒãåäœããŠããå ŽåïŒã¯ãäž¡æ¹ã®ã€ã³ã¿ãŒããããããã€ããŒïŒISP1ããã³ISP3ïŒã§VPN IPsecãã³ãã«ãåæã«çµäºããå¿ èŠããããããå¥ã®FVRFã§æ°ããISP3ã€ã³ã¿ãŒããããããã€ããŒã«æ¥ç¶ã転éããããšã«ããŸããã åæã«ãä¿è·ãããïŒããŒã«ã«ïŒãããã¯ãŒã¯ãšãã°ããŒãã«VRFã®æåã®ã€ã³ã¿ãŒããããããã€ããŒãžã®æ¥ç¶ãæ®ãããšã決å®ãããŸããã
IPsecãFVRFãšå ±ã«æ£ããæ§æãããšãIPS1ããã³IPS3ãä»ãã䞊ååäœãã³ãã«ãã§ããŸãã FVRFã䜿çšããIPSecæ§æã®äŸã«ã€ããŠã¯ã次ã®ã»ã¯ã·ã§ã³ã§èª¬æããŸãã çŸåšã§ã¯ãæ¢åã®ãã³ãã«ãä»ããŠãã©ãã£ãã¯ãããŒãåæ£ããŸãã ãã®åé¡ã解決ããã«ã¯ã次ã®ã¢ãããŒããåºå¥ã§ããŸãã
- çã³ã¹ããã«ããã¹ïŒECMPïŒã åãã¡ããªãã¯ã®ã«ãŒãã䜿çšãããã³ãã«ãã©ã³ã·ã³ã°ã
- ã»ã³ãã©ã«ããŒãã£ã³ã°ã»ã³ã¿ãŒããªã¢ãŒããªãã£ã¹ã®ç°ãªãIPãµãããããç°ãªããã³ãã«ã§ã«ãŒãã£ã³ã°ããŸãã
- ããã©ãŒãã³ã¹ã«ãŒãã£ã³ã°ïŒPfRïŒ;
- ããªã·ãŒããŒã¹ã«ãŒãã£ã³ã°ïŒPBRïŒã
- ãããã¯ãŒã¯ã¢ãã¬ã¹å€æïŒNATïŒã䜿çšããŠç¹å®ã®IPã¢ãã¬ã¹ãå²ãåœãŠããããã®ç¹å®ã®IPã¢ãã¬ã¹ã®ã«ãŒãã£ã³ã°ãæ§æããŸãã
ç§ã®ã¿ã¹ã¯ã§ã¯ãæåŸã®ãªãã·ã§ã³ãæãæãŸããããšãå€æããŸãããNATã䜿çšããã¢ãããŒãã§ãã ãã®ãªãã·ã§ã³ã䜿çšãããšãäžæ¹ã§ïŒECMPãPfRãšã¯ç°ãªãïŒãã³ãã«å šäœã®ãã©ãã£ãã¯ã®åæ£ãå³å¯ã«èšå®ããä»æ¹ã§ïŒPBRãšã¯ç°ãªãïŒèšå®è¡ã®æ°ãæžããããšãã§ããŸãã ãã£ãšè©³ããèããŠã¿ãŸãããã
COã«ãŒã¿ãŒã§ã¯ãåçã¢ãã¬ã¹NATãããã¯ãŒã¯ã¢ãã¬ã¹å€æã«ãŒã«ãæ§æããŸãã ãã®ã«ãŒã«ã䜿çšããŠãã»ã³ãã©ã«ããŒãã£ã³ã°ã³ã³ãã¥ãŒã¿ãŒããªã¢ãŒããªãã£ã¹ã®æ¢ç¥ã®ãµãŒããŒã«ã¢ã¯ã»ã¹ãããšãã«ããã®ã³ã³ãã¥ãŒã¿ãŒã®IPã¢ãã¬ã¹ããç¹å¥ãªãIPã¢ãã¬ã¹ã«å€æŽããŸãã ãµãŒããŒã®æ¢ç¥ã®IPã¢ãã¬ã¹ã«ã¢ã¯ã»ã¹ããå Žåã«ã®ã¿ã ããªã·ãŒ NATã䜿çšããŠã¯ã©ã€ã¢ã³ãã®IPã¢ãã¬ã¹ãå€æŽããŸãã ããã«ãEIGRPæ§æã䜿çšããŠãISP3ãã³ãã«ãä»ããæé©ãªã¡ããªãã¯ãæã€ãç¹å¥ãªãIPã¢ãã¬ã¹ããªã¢ãŒããªãã£ã¹ã«é åžããŸããéã«ãã¢ã³ããŒããå¿ èŠãªISP1ãä»ãããã³ãã«ã§ã¯ããç¹å¥ãªãIPã¢ãã¬ã¹ã®ã¡ããªãã¯ãèªåŒµããŸãã
ãããã£ãŠãã»ã³ãã©ã«ãªãã£ã¹ã®é¡§å®¢ããã®èŠæ±ã¯ããœãŒã¹IPã¢ãã¬ã¹ãå€æŽããããªã¢ãŒããªãã£ã¹ã®ãµãŒããŒã«å°éããŸãã å¿çãšããŠããµãŒããŒã¯å€æŽãããIPã¢ãã¬ã¹ãžã®ãã©ãã£ãã¯ãçæãããªã¢ãŒããªãã£ã¹ã®ã«ãŒã¿ãŒããã®ãã©ãã£ãã¯ã¹ããªãŒã ãå¿ èŠãªãã³ãã«ã«ã«ãŒãã£ã³ã°ããŸãã åæã«ããªã¢ãŒããªãã£ã¹ã®ã«ãŒã¿ãŒã¯ãè¿œå ã®ã«ãŒãã£ã³ã°èšå®ãå¿ èŠãšããŸãããã«ãŒã管çã¯ãäžå€®ã«ãŒã¿ãŒã«ãŒã¿ãŒã®ã³ã³ãœãŒã«ããEIGRPã䜿çšããŠå®è¡ãããŸãã 以äžã¯ããªã¯ãšã¹ã/ã¬ã¹ãã³ã¹ã®ãããŒãã£ãŒãã§ãã ã¯ã©ã€ã¢ã³ãã®å®éã®IPã¢ãã¬ã¹ã¯192.168.1.100ã§ãã ã¯ã©ã€ã¢ã³ãã®IPã¢ãã¬ã¹ãå€æããããç¹å¥ãªãIPã¢ãã¬ã¹ïŒ10.10.10.10ã ãªã¢ãŒããªãã£ã¹ã®ãµãŒããŒã®IPã¢ãã¬ã¹ïŒ172.16.1.100ã
é察称ã«ãŒãã£ã³ã°
ãã®å³ã¯ãé察称ã«ãŒãã£ã³ã°ãèš±å¯ããããšã瀺ããŠããŸããèŠæ±ã¯ãã³ãã«ISP1ãééããå¿çã¯ãã³ãã«ISP3ãä»ããŠè¿ãããŸãã éåžžã®åäœã§ã¯ããã®åè·¯ãé©ããŠããŸãã ããããé察称ã«ãŒãã£ã³ã°ã¯ã»ãšãã©åžžã«åé¡ãåŒãèµ·ããæºåãã§ããŠããŸãã å°é£ããªãããã§ã¯ãããŸããã
ISP1ãæ éãããšãã®åè·¯ãæ³åããŠãã ããã ãã®å ŽåãèŠæ±ã¯ã«ãŒã¿ãŒR2ããã³ISP2ãã³ãã«ãééãå§ããèŠæ±/å¿çãããŒå³ã¯æ¬¡ã®åœ¢åŒãåããŸãã
ãã®å³ã¯ãèŠæ±ãã±ããã®å ŽåããœãŒã¹IPã¢ãã¬ã¹ãã«ãŒã¿ãŒR2ã§å€æãããããšã瀺ããŠããŸãã å¿çãã±ããã¯ãISP3ãã³ãã«ãä»ããŠR1ã«å°çããŸãã ãã ããUNNATæé ãå®è¡ããåä¿¡è ã®IPã¢ãã¬ã¹ãã¯ã©ã€ã¢ã³ãã®å®éã®IPã¢ãã¬ã¹ã«å€æããã«ã¯ããã±ãããã«ãŒã¿ãŒR2ã«éãè¿ãå¿ èŠããããŸãã
ã«ãŒã¿R2ã®UNNATæé ãæåããããã«ã¯ãå¿çãã±ããã¯æåã«ip nat outsideãã£ã¬ã¯ãã£ããæã€ã«ãŒã¿ã®ã€ã³ã¿ãŒãã§ã€ã¹ã«è¡ãã次ã«ip nat insideãã£ã¬ã¯ãã£ããæã€ã€ã³ã¿ãŒãã§ã€ã¹ã«è¡ãå¿ èŠããããŸãã ip nat outsideãã£ã¬ã¯ãã£ããæã€ã€ã³ã¿ãŒãã§ã€ã¹ãšããŠãã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšãããŸãã ip nat insideãã£ã¬ã¯ãã£ããæã€ã€ã³ã¿ãŒãã§ã€ã¹ã¯ããããã¯ãŒã¯ã³ã¢ã¹ã€ããã«æ¥ç¶ãããã«ãŒã¿ãŒã®å éšã€ã³ã¿ãŒãã§ã€ã¹ã§ãã ãããã¯ãŒã¯ã³ã¢ã¹ã€ããã«æ¥ç¶ãããŠããæ¢åã®å éšã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠã«ãŒã¿ãŒR1ããã«ãŒã¿ãŒR2ã«ãã©ãã£ãã¯ããªãã€ã¬ã¯ããããšããã±ããã¯æ¬¡ã®ãã¹ã«æ²¿ã£ãŠé²ãããšãããããŸãïŒR2å éšã€ã³ã¿ãŒãã§ã€ã¹ãšip nat insideãR2ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ãšip nat outsideããã³R2å éšã€ã³ã¿ãŒãã§ã€ã¹ã«æ»ãc ip nat insideã NATã®èŠ³ç¹ããèŠããšããã¹ã¯æ¬¡ã®ããã«ãªããŸããipnat inside-> ip nat outside-> ip nat inside UNNATã¯ããŸããããŸããã§ããã å éšã®æåã®ip natãã€ãŸãã«ãŒã¿ãŒR2ã®æ¢åã®å éšã€ã³ã¿ãŒãã§ã€ã¹ãä»ããUNNATã®å¯Ÿè±¡ãšãªããã±ããã®ãšã³ããªãé€å€ããå¿ èŠããããŸããã UNNATã®å¯Ÿè±¡ã§ããR1ãããã©ãã£ãã¯ãåä¿¡ããã«ã¯ãip nat insideãã£ã¬ã¯ãã£ããæããªãè¿œå ã®è«çãµãã€ã³ã¿ãŒãã§ã€ã¹ãã«ãŒã¿ãŒR2ã«æ§æããã«ãŒã¿ãŒR1ã«å¯Ÿå¿ããã«ãŒãã£ã³ã°ã«ãŒã«ãæ§æããå¿ èŠããããŸããã
ISP1ãæ éãããšãã®åè·¯ãæ³åããŠãã ããã ãã®å ŽåãèŠæ±ã¯ã«ãŒã¿ãŒR2ããã³ISP2ãã³ãã«ãééãå§ããèŠæ±/å¿çãããŒå³ã¯æ¬¡ã®åœ¢åŒãåããŸãã
ãã®å³ã¯ãèŠæ±ãã±ããã®å ŽåããœãŒã¹IPã¢ãã¬ã¹ãã«ãŒã¿ãŒR2ã§å€æãããããšã瀺ããŠããŸãã å¿çãã±ããã¯ãISP3ãã³ãã«ãä»ããŠR1ã«å°çããŸãã ãã ããUNNATæé ãå®è¡ããåä¿¡è ã®IPã¢ãã¬ã¹ãã¯ã©ã€ã¢ã³ãã®å®éã®IPã¢ãã¬ã¹ã«å€æããã«ã¯ããã±ãããã«ãŒã¿ãŒR2ã«éãè¿ãå¿ èŠããããŸãã
ã«ãŒã¿R2ã®UNNATæé ãæåããããã«ã¯ãå¿çãã±ããã¯æåã«ip nat outsideãã£ã¬ã¯ãã£ããæã€ã«ãŒã¿ã®ã€ã³ã¿ãŒãã§ã€ã¹ã«è¡ãã次ã«ip nat insideãã£ã¬ã¯ãã£ããæã€ã€ã³ã¿ãŒãã§ã€ã¹ã«è¡ãå¿ èŠããããŸãã ip nat outsideãã£ã¬ã¯ãã£ããæã€ã€ã³ã¿ãŒãã§ã€ã¹ãšããŠãã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšãããŸãã ip nat insideãã£ã¬ã¯ãã£ããæã€ã€ã³ã¿ãŒãã§ã€ã¹ã¯ããããã¯ãŒã¯ã³ã¢ã¹ã€ããã«æ¥ç¶ãããã«ãŒã¿ãŒã®å éšã€ã³ã¿ãŒãã§ã€ã¹ã§ãã ãããã¯ãŒã¯ã³ã¢ã¹ã€ããã«æ¥ç¶ãããŠããæ¢åã®å éšã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠã«ãŒã¿ãŒR1ããã«ãŒã¿ãŒR2ã«ãã©ãã£ãã¯ããªãã€ã¬ã¯ããããšããã±ããã¯æ¬¡ã®ãã¹ã«æ²¿ã£ãŠé²ãããšãããããŸãïŒR2å éšã€ã³ã¿ãŒãã§ã€ã¹ãšip nat insideãR2ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ãšip nat outsideããã³R2å éšã€ã³ã¿ãŒãã§ã€ã¹ã«æ»ãc ip nat insideã NATã®èŠ³ç¹ããèŠããšããã¹ã¯æ¬¡ã®ããã«ãªããŸããipnat inside-> ip nat outside-> ip nat inside UNNATã¯ããŸããããŸããã§ããã å éšã®æåã®ip natãã€ãŸãã«ãŒã¿ãŒR2ã®æ¢åã®å éšã€ã³ã¿ãŒãã§ã€ã¹ãä»ããUNNATã®å¯Ÿè±¡ãšãªããã±ããã®ãšã³ããªãé€å€ããå¿ èŠããããŸããã UNNATã®å¯Ÿè±¡ã§ããR1ãããã©ãã£ãã¯ãåä¿¡ããã«ã¯ãip nat insideãã£ã¬ã¯ãã£ããæããªãè¿œå ã®è«çãµãã€ã³ã¿ãŒãã§ã€ã¹ãã«ãŒã¿ãŒR2ã«æ§æããã«ãŒã¿ãŒR1ã«å¯Ÿå¿ããã«ãŒãã£ã³ã°ã«ãŒã«ãæ§æããå¿ èŠããããŸããã
æ§æã®èª¬æ
äžå€®IPã¢ãã¬ã¹æå®ïŒ
å éšãããã¯ãŒã¯ïŒ | 192.168.1.0/24 |
ISP1ãžã®æ¥ç¶ïŒ | 1.1.1.1/30ãã²ãŒããŠã§ã€1.1.1.2 |
ISP2ãžã®æ¥ç¶ïŒ | 2.2.2.1/30ã²ãŒããŠã§ã€2.2.2.2 |
ISP3ãžã®æ¥ç¶ïŒ | 3.3.3.1/30ã²ãŒããŠã§ã€3.3.3.2 |
ã¯ã©ã€ã¢ã³ãIPã¢ãã¬ã¹ïŒ | 192.168.1.100 |
ã¿ã€ã1ãªã¢ãŒããªãã£ã¹IPã¢ãã¬ãã·ã³ã°ïŒVTIãã³ãã«ïŒïŒ
å éšãããã¯ãŒã¯ïŒ | 172.16.1.0/24 |
ISPãžã®æ¥ç¶ïŒ | 4.4.4.1/30ã²ãŒããŠã§ã€4.4.4.2 |
ãµãŒããŒIPïŒ | 172.16.1.100 |
ã¿ã€ã2ãªã¢ãŒããªãã£ã¹IPã¢ãã¬ã¹æå®ïŒGRE over IPsecãã³ãã«ïŒïŒ
å éšãããã¯ãŒã¯ïŒ | 172.16.2.0/24 |
ISPãžã®æ¥ç¶ïŒ | 5.5.5.1/30ã²ãŒããŠã§ã€5.5.5.2 |
ã«ãŒã¿ãŒãšCisco ASAéã®ãµããããïŒ | 6.6.6.2-ã«ãŒã¿ãŒ
6.6.6.1-Cisco ASA ãã¹ã¯255.255.255.252 |
ãµãŒããŒIPïŒ | 172.16.2.100 |
ãããã¯ãŒã¯å³ïŒ
ã«ãŒã¿ãŒR1ã®æ§æãæ€èšããŠãã ããã æåã«ãã¿ã€ã1ïŒVTIãã³ãã«ïŒããã³ã¿ã€ã2ïŒGRE over IPsecãã³ãã«ïŒã®ãªã¢ãŒããªãã£ã¹ãžã®VPNãã³ãã«ã®ã»ããã¢ããäŸã瀺ããŸãã å³ãšæ§æã§ã¯ã次ã®VPNãã³ãã«è¡šèšã䜿çšããŠããŸãã
- ãã³ãã«10-ISP1ãéãVTIãã³ãã«ã
- ãã³ãã«11-VRFã䜿çšããŠèšå®ãããISP3ãä»ããVTIãã³ãã«ã
- ãã³ãã«20-ISP1ãä»ããGRE over IPsecãã³ãã«ã
- ãã³ãã«21-VRFã䜿çšããŠèšå®ãããISP3ãä»ããGRE over IPsecãã³ãã«ã
VRFãšã€ã³ã¿ãŒãã§ã€ã¹ãèšå®ããŸãã
! VRF - ISP3 ip vrf ISP3-vrf ! ! - ISP3 interface GigabitEthernet0/2 description === ISP3 === ip address 3.3.3.1 255.255.255.252 ip vrf forwarding ISP3-vrf ! ! - ISP3 ip route vrf ISP3-vrf 0.0.0.0 0.0.0.0 3.3.3.2 ! ! HSRP interface GigabitEthernet0/0 description === LAN === ip address 192.168.1.2 255.255.255.0 standby 1 ip 192.168.1.1 standby 1 priority 105 standby 1 preempt ! ! - ISP1 interface GigabitEthernet0/1 description === ISP1 === ip address 1.1.1.1 255.255.255.252 ! ! - ISP1 ip route 0.0.0.0 0.0.0.0 1.1.1.2
ã¿ã€ã1ãªã¢ãŒããªãã£ã¹ãšéä¿¡ããããã®ISP1ãä»ããVTIãã³ãã«ã®æ§æã
! ISAKMP crypto isakmp policy 10 encr aes hash sha authentication pre-share group 2 ! ! Pre-shared key crypto isakmp key STRONGKEY address 4.4.4.1 no-xauth ! ! IPsec crypto ipsec transform-set ESP-AES-SHA esp-aes 256 esp-sha-hmac mode tunnel ! ! IPsec crypto ipsec profile VTI set transform-set ESP-AES-SHA ! ! VTI interface Tunnel10 description === To office Type 1 over ISP1 === ip unnumbered GigabitEthernet0/0 tunnel source 1.1.1.1 tunnel mode ipsec ipv4 tunnel destination 4.4.4.1 tunnel path-mtu-discovery tunnel protection ipsec profile VTI
ã¿ã€ã1ã®ãªã¢ãŒããªãã£ã¹ãšéä¿¡ããããã®æ°ãããISP3-vrfãVRFã®ISP3ãããã€ããŒãä»ããVTIãã³ãã«ã®èšå®
! Keyring crypto keyring office1-keyring vrf ISP3-vrf pre-shared-key address 4.4.4.1 key STRONGKEY ! ! ISAKMP crypto isakmp policy 10 encr aes hash sha authentication pre-share group 2 ! ! ISAKMP crypto isakmp profile office1-ike-prof keyring office1-keyring match identity address 4.4.4.1 255.255.255.255 ISP3-vrf isakmp authorization list default local-address GigabitEthernet0/2 ! ! IPsec crypto ipsec transform-set ESP-AES-SHA esp-aes 256 esp-sha-hmac mode tunnel ! ! IPsec crypto ipsec profile office1-ipsec-prof set transform-set ESP-AES-SHA set isakmp-profile office1-ike-prof ! ! VTI. ISP3-vrf interface Tunnel11 description === To office Type 1 over ISP3 === ip unnumbered GigabitEthernet0/0 tunnel source 3.3.3.1 tunnel mode ipsec ipv4 tunnel destination 4.4.4.1 tunnel path-mtu-discovery tunnel vrf ISP3-vrf tunnel protection ipsec profile office1-ipsec-prof
ã¿ã€ã2ã®ãªã¢ãŒããªãã£ã¹ãšéä¿¡ããããã«ãISP1ãä»ããGRE over IPsecãã³ãã«ãèšå®ããŸãã
! ISAKMP crypto isakmp policy 10 encr aes hash sha authentication pre-share group 2 ! ! Pre-shared key crypto isakmp key STRONGKEY address 5.5.5.1 no-xauth ! ! IPsec crypto ipsec transform-set ESP-AES-SHA esp-aes 256 esp-sha-hmac mode tunnel ! ! - crypto map CMAP 10 ipsec-isakmp description === To office Type 2 over ISP1 === set peer 5.5.5.1 set transform-set ESP-AES-SHA match address cryptomap_10_acl ! ! GRE interface Tunnel520 description === To office Type 2 over ISP1 === ip unnumbered GigabitEthernet0/0 keepalive 10 3 tunnel source 1.1.1.1 tunnel destination 6.6.6.2 tunnel path-mtu-discovery ! ! -ACL ip access-list extended cryptomap_10_acl permit gre 1.1.1.1 host host 6.6.6.2 ! ! - ISP1 interface GigabitEthernet0/1 crypto map CMAP
ã¿ã€ã2ãªã¢ãŒããªãã£ã¹ãšéä¿¡ããããã«ãæ°ãããISP3-vrfãVRFã®ISP3ãããã€ããŒãä»ããŠGRE over IPsecãã³ãã«ãèšå®ããŸãã
crypto keyring office2-keyring vrf ISP3-vrf pre-shared-key address 5.5.5.1 key STRONGKEY ! ! ISAKMP crypto isakmp policy 10 encr aes hash sha authentication pre-share group 2 ! ! ISAKMP crypto isakmp profile office2-ike-prof vrf ISP3-vrf keyring office2-keyring match identity address 5.5.5.1 255.255.255.255 ISP3-vrf isakmp authorization list default ! ! IPsec crypto ipsec transform-set ESP-AES-SHA esp-aes 256 esp-sha-hmac mode tunnel ! ! - crypto map CMAP-vrf 10 ipsec-isakmp description === To office Type 2 over ISP3 === set peer 5.5.5.1 set transform-set ESP-AES-SHA set isakmp-profile office2-ike-prof match address cryptomap-vrf_10_acl ! interface Tunnel21 description === To office Type 2 over ISP3 === ip unnumbered GigabitEthernet0/0 keepalive 10 3 tunnel source 3.3.3.3 tunnel destination 6.6.6.2 tunnel path-mtu-discovery tunnel vrf ISP3-vrf ! ! -ACL ip access-list extended cryptomap-vrf_10_acl permit gre 3.3.3.3 host host 6.6.6.2 ! ! - ISP3 interface GigabitEthernet0/2 crypto map CMAP-vrf
äžèšã®äŸã䜿çšããŠããã¹ãŠã®ãªã¢ãŒããªãã£ã¹ãžã®VPNãã³ãã«ãæ§æãããŸãã ã»ã³ãã©ã«ããŒãã£ã³ã°ã»ã³ã¿ãŒã®ã«ãŒã¿ãŒR2ãããã³ãªã¢ãŒããªãã£ã¹ã®ã«ãŒã¿ãŒãšCisco ASAã®VPNãã³ãã«èšå®ã¯ããã®åçŽããèæ ®ããŠæ€èšããŸããã
ãã¹ãŠã®ãªã¢ãŒããªãã£ã¹ãžã®VPNãã³ãã«ã®æºåãã§ããã®ã§ãã«ãŒãã£ã³ã°èšå®ã«é²ãããšãã§ããŸãã ãããã¯ãŒã¯ã¯EIGRPã䜿çšããŸãã æåã«ãå±éãããã·ã¹ãã ã®ã¯ã©ã€ã¢ã³ãã匷調衚瀺ããããã«ããã€ãããã¯ããªã·ãŒNATã«ãŒã«ãèšå®ããå¿ èŠããããŸãã
! Loopback NAT ! interface Loopback1 description ===For System-Servers routing=== ip address 10.10.10.10 255.255.255.255 ! ! IP- object-group network System-Servers description === System-Servers === host 172.16.1.100 host 172.16.2.100 ! ! NAT ip access-list extended NAT-System-Servers permit ip any object-group System-Servers ! ! NAT route-map RM-NAT-System-Servers permit 10 match ip address NAT-System-Servers ! ! dynamic policy NAT ip nat inside source route-map RM-NAT-System-Servers interface Loopback1 overload ! ! ip nat inside ip nat outside interface GigabitEthernet0/0 ip nat inside ! interface Tunnel10 ip nat outside ! interface Tunnel11 ip nat outside interface Tunnel20 ip nat outside interface Tunnel21 ip nat outside
ãããã®NATèšå®ã¯ããªã¢ãŒããªãã£ã¹ã®ãµãŒããŒã«ã¢ã¯ã»ã¹ãããšãã«ãã¯ã©ã€ã¢ã³ãIPã¢ãã¬ã¹ããç¹å¥ãªãIPã¢ãã¬ã¹10.10.10.10ã«å€æããŸãã
10.10.10.10/32ã§ãããã¯ãŒã¯ãISP3ãããã€ããŒã®ãã³ãã«ãä»ããŠæé©ãªã¡ããªãã¯ã§ãªã¢ãŒããªãã£ã¹ã«ã¢ããŠã³ã¹ãããããã«ãã»ã³ãã©ã«ãªãã£ã¹ã®ã«ãŒã¿ã§EIGRPãèšå®ããããšã¯æ®ããŸãã ãã®äŸã§ã¯ããã³ãã«11ãšãã³ãã«21ã§ããEIGRPã¡ããªãã¯ã管çããããã«ãoffset-listã³ã³ã¹ãã©ã¯ãã䜿çšããããšã«ããŸããã offset-listãã£ã¬ã¯ãã£ãã䜿çšããŠãæå®ãããå€ãã¢ããŠã³ã¹ãããã«ãŒãã¡ããªãã¯ã«è¿œå ã§ããããšãæãåºããŠãã ããã EIGRPèšå®ïŒ
access-list 10 permit 10.10.10.10 ! router eigrp 1 network 192.168.1.0 0.0.0.255 offset-list 10 out 3000000 Tunnel10 offset-list 10 out 3000000 Tunnel20 passive-interface default no passive-interface Tunnel10 no passive-interface Tunnel11 no passive-interface Tunnel20 no passive-interface Tunnel21 no passive-interface GigabitEthernet0/0
説æããæ§æã«ããããªã¢ãŒããªãã£ã¹ã«æ°ãããµãŒããŒãè¿œå ããæé ãäœæãããŸãããã®ãµãŒããŒããã®ãã©ãã£ãã¯ã¯ãã§ããã ãç°¡åã«ãæ°ããISP3ã»ã³ãã©ã«ããŒã¿ãŒãããã€ããŒã®ãã³ãã«ãçµç±ããŠã«ãŒãã£ã³ã°ããå¿ èŠããããŸãã æ°ãããµãŒããŒã衚瀺ãããããSystem-Serversãªããžã§ã¯ãã°ã«ãŒãã«ãã®IPã¢ãã¬ã¹ãå ¥åããã ãã§ãã
! IP- object-group network System-Servers description === System-Servers === host 172.16.1.100 host 172.16.2.100
ããã§ãR1ã»ã³ãã©ã«ããŒã¿ãŒã«ãŒã¿ãŒã®æ§æã®ã¬ãã¥ãŒã¯çµäºã§ãã ã»ã³ãã©ã«ãªãã£ã¹ã®R2ã«ãŒã¿ãŒã®æ§æãšãªã¢ãŒããªãã£ã¹ã®ãããã¯ãŒã¯ããã€ã¹ã®æ§æã¯ããã®èšäºã§ã¯éèŠã§ã¯ãããŸããã
ãããã«
ãããã¯ãŒã¯ãšã³ãžãã¢ã®ããã«åçŽã§è«ççãªã¿ã¹ã¯ãèšå®ããããšããããŸãããåé¡ã解決ãããšãæ¯èŒçè€éãªæ§æã圢æãããŸãã ç§ã®äŸã§ã¯ãåºæ¬çãªã¿ã¹ã¯ãæ€èšããŸãããæ°ããã€ã³ã¿ãŒããããããã€ããŒãæ¢åã®ã«ãŒã¿ãŒã«æ¥ç¶ãããã®äžã®ãªã¢ãŒããªãã£ã¹ããããã€ãã®ãµãŒãã¹ã®ãã©ãã£ãã¯ãéå§ããããšã§ãã ãã ãããã®åé¡ã解決ããã«ã¯ãã«ãŒã¿ãŒãVRFã«åå²ããIPã¢ãã¬ã¹ãå€æããããã®ããªãããŒãªã«ãŒã«ãèŠå®ããåçã«ãŒãã£ã³ã°èšå®ã調æŽããé察称ã«ãŒãã£ã³ã°ã®çµæãä¿®æ£ããå¿ èŠããããŸããã
ãã®ã¿ã¹ã¯ãäŸãšããŠäœ¿çšããŠãããã³ããã¢VRFã䜿çšããŠIPsecãã³ãã«ãæ§ç¯ããããšãæ€èšããŸããã ããã«ãNATã«ãŒã«ã䜿çšããŠã¹ã¿ãŒããããžã®ã«ãŒãã£ã³ã°èšå®ãéäžåãããªãã·ã§ã³ã瀺ããŸããã IPsecãæ§ç¯ããããã®ããã³ããã¢VRFã¯ãã«ãŒã¿ãŒã®VRFéã§ãã©ãã£ãã¯ã転éããããã®ããªããžãæ§ç¯ã§ãã䟿å©ãªããŒã«ã§ããä¿è·ããããã©ãã£ãã¯ã¯IVRFãŸãã¯ã°ããŒãã«VRFã«ãããã«ãã»ã«åãããïŒæå·åãããïŒãã©ãã£ãã¯ã¯FVRFã«ãããŸãã FVRFã«ã¯ç¬èªã®ã«ãŒãã£ã³ã°ã«ãŒã«ããããããã«ãããè¿œå ã®éä¿¡ãã£ãã«ãç¹ã«è¿œå ã®ã€ã³ã¿ãŒããããããã€ããŒãä»ããŠFVRFãã©ãã£ãã¯ãéä¿¡ã§ããŸãã