çæ³ãèŠçŽ ãšã®éäºããããŠ
ãã®èšäºã§ã¯ãæ¢æã®ã«ãŒã«ã»ãããæäŸããã ãã§ãªããããããæ©èœããçç±ãšæ¹æ³ãã§ããéã説æããããã«ããŸãã

å ·äœçã«ã¯ãç§ã®å Žåãã«ãŒã¿ãŒãæ§æããŠããã®èåŸã®ããŒã«ã«ãããã¯ãŒã¯äžã®WebãµãŒããŒã3ã€ã®ãããã€ããŒã®ããããã®IPçµç±ã§ã¢ã¯ã»ã¹ã§ããããã«ããå¿ èŠããããŸããã
ããŒã1
æåã«ããã¹ãŠã®èšå®ã調ã¹ãŠããã£ãã¡ãªäººãèªãŸãã«ã³ããŒïŒããŒã¹ãã§ããããã«ããŸãã
RouterOSããŒãžã§ã³ïŒ
# oct/11/2016 22:02:32 by RouterOS 6.37.1 # software id = X62B-STGZ
ã€ã³ã¿ãŒãã§ãŒã¹ïŒ
/interface list add name=WAN /interface list member add interface=ISP1 list=WAN add interface=ISP2 list=WAN add interface=ISP3 list=WAN
ãã®æ©èœãç»å ŽããRouterOSã®ããŒãžã§ã³ããå§ããããšãèŠããŠããŸããã ããã«ãããã€ã³ã¿ãŒãã§ã€ã¹ãã°ã«ãŒãåã§ããŸããããã¯éåžžã«äŸ¿å©ã§ãïŒããšãã°ã/ ipãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã§ïŒã 3ã€ã®WANã€ã³ã¿ãŒãã§ã€ã¹ã®ã°ã«ãŒããäœæããŸããã
AcidVenomã¯6.36ã§
IPã¢ãã¬ã¹ïŒæãããªçç±ã«ãããã¢ãã¬ã¹ã¯ãå·Šãã§ãïŒïŒ
/ip address add address=192.168.0.1/24 comment=defconf interface=bridge network=192.168.0.0 add address=95.11.29.240/24 interface=ISP1 network=95.11.29.0 add address=5.35.59.162/27 interface=ISP2 network=5.35.59.160 add address=5.98.112.30/30 interface=ISP3 network=5.98.112.28
ã«ãŒãã£ã³ã°ïŒ
/ip route add distance=1 gateway=95.11.29.254 routing-mark=ISP1-route add distance=1 gateway=5.35.59.161 routing-mark=ISP2-route add distance=1 gateway=5.98.112.29 routing-mark=ISP3-route add check-gateway=ping distance=1 gateway=8.8.8.8 add check-gateway=ping distance=2 gateway=8.8.4.4 add check-gateway=ping distance=3 gateway=1.1.36.3 add distance=1 dst-address=8.8.4.4/32 gateway=5.35.59.161 scope=10 add distance=1 dst-address=8.8.8.8/32 gateway=95.11.29.254 scope=10 add distance=1 dst-address=1.1.36.3/32 gateway=5.98.112.29 scope=10
ãã§ãŒã«ãªãŒããŒãæŽçããããã«ãååž°ã«ãŒãã£ã³ã°ãèšå®ããŸãã第2éšã§è©³ãã説æããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ïŒãã®åºçç©ã§ã¯ããã¹ãŠãèš±å¯ããã«ãŒã«ãæå³çã«æäŸããŠããŸãã
ãããããªãã§ãã ããïŒïŒïŒ
/ip firewall filter add action=accept chain=forward add action=accept chain=input add action=accept chain=output
dstããã³src natïŒ
/ip firewall nat add action=masquerade chain=srcnat out-interface-list=WAN add action=dst-nat chain=dstnat comment="HTTP" dst-port=80 \ in-interface-list=WAN protocol=tcp to-addresses=192.168.0.83 to-ports=80 add action=dst-nat chain=dstnat comment="HTTPs" dst-port=443 \ in-interface-list=WAN protocol=tcp to-addresses=192.168.0.83 to-ports=443
ãã³ã°ã«
/ip firewall mangle add action=mark-connection chain=input in-interface=ISP1 \ new-connection-mark=ISP1-conn passthrough=yes add action=mark-routing chain=output connection-mark=ISP1-conn \ new-routing-mark=ISP1-route passthrough=no add action=mark-connection chain=input in-interface=ISP2 new-connection-mark=\ ISP2-conn passthrough=yes add action=mark-routing chain=output connection-mark=ISP2-conn \ new-routing-mark=ISP2-route passthrough=no add action=mark-connection chain=input in-interface=ISP3 \ new-connection-mark=ISP3-conn passthrough=yes add action=mark-routing chain=output connection-mark=ISP3-conn \ new-routing-mark=ISP3-route passthrough=no add action=mark-connection chain=forward in-interface=ISP1 \ new-connection-mark=ISP1-conn-f passthrough=no add action=mark-routing chain=prerouting connection-mark=ISP1-conn-f \ in-interface=bridge new-routing-mark=ISP1-route add action=mark-connection chain=forward in-interface=ISP2 \ new-connection-mark=ISP2-conn-f passthrough=no add action=mark-routing chain=prerouting connection-mark=ISP2-conn-f \ in-interface=bridge new-routing-mark=ISP2-route add action=mark-connection chain=forward in-interface=ISP3 \ new-connection-mark=ISP3-conn-f passthrough=no add action=mark-routing chain=prerouting connection-mark=ISP3-conn-f \ in-interface=bridge new-routing-mark=ISP3-route
ããŒã2
ãã¹ãŠã®è©³çŽ°ãèæ ®ããŠãã ããã
ã«ãŒãã£ã³ã°ïŒ
ã¹ãã€ã©ãŒã®äžãèŠãŠãå転ããªãããã«ããŸã
/ip route add distance=1 gateway=95.11.29.254 routing-mark=ISP1-route add distance=1 gateway=5.35.59.161 routing-mark=ISP2-route add distance=1 gateway=5.98.112.29 routing-mark=ISP3-route add check-gateway=ping distance=1 gateway=8.8.8.8 add check-gateway=ping distance=2 gateway=8.8.4.4 add check-gateway=ping distance=3 gateway=1.1.36.3 add distance=1 dst-address=8.8.4.4/32 gateway=5.35.59.161 scope=10 add distance=1 dst-address=8.8.8.8/32 gateway=95.11.29.254 scope=10 add distance=1 dst-address=1.1.36.3/32 gateway=5.98.112.29 scope=10
/ ipã«ãŒã
æåã®3è¡ã§ã¯ã3ã€ã®åãããã€ããŒã®ããã©ã«ãã²ãŒããŠã§ã€ã瀺ããŠããŸãã
ã«ãŒãã®ãŠã§ã€ãïŒ è·é¢ ïŒã¯åãã§ãããç°ãªãã«ãŒãã£ã³ã°ããŒãã«ã§æ©èœããŸãã
ã€ãŸãããããã®ã«ãŒãã¯ã察å¿ããïŒ routing-mark ïŒã¿ã°ã§ããŒã¯ããããã±ããã«å¯ŸããŠæ©èœããŸãã / ip firewall mangleã®ãã±ããã«ã¿ã°ãæããŸãïŒããã«ã€ããŠã¯ã以äžã§åæ§ã«èª¬æããŸãïŒã
次ã®3è¡ã¯ãã¡ã€ã³ã«ãŒãã£ã³ã°ããŒãã«ã®ããã©ã«ãã«ãŒãã瀺ããŠããŸãã
ããã§ã¯ã次ã®ããšã«æ³šæãã䟡å€ããããŸãã
- è·é¢ãã©ã¡ãŒã¿ åã«ãŒãããšã«ç°ãªããããã«å¿ããŠãã«ãŒãã®ãéã¿ããç°ãªããŸãã
ISP1-ã¡ã€ã³ãISP2ããã³ISP3ãç¶ããŸãã ISP1ãããã€ããŒã«é害ãçºçããå ŽåãISP2ãBoseã«ããå ŽåãISP2ãä»ããŠäœæ¥ããISP3ãåŒãç¶ããŸãã
- ã²ãŒããŠã§ã€ãã©ã¡ãŒã¿ãŒã®å€ã¯ãããæ··ä¹±ãæãå¯èœæ§ããããŸãã ãã®Google DNSãšããçš®ã®å·Šã®IPã¢ãã¬ã¹ãçªç¶ããã©ã«ãã«ãŒãã«ãªã£ãã®ã¯ã©ãããŠã§ããïŒ éæ³ã¯ãæåŸã®3è¡ã®scopeãã©ã¡ãŒã¿ãŒãšãNexthopã«ãã¯ã¢ããã¡ã«ããºã èªäœã«ãããŸãã
å®éããã©ãã£ãã¯ã¯ã¢ã¯ãã£ããªãããã€ããŒã«éããããã®åŸãã¢ãããªã³ã¯ãä»ããŠã€ã³ã¿ãŒãããã«éä¿¡ãããŸãã
- check-gateway = pingãã©ã¡ãŒã¿ãŒã«ã€ããŠã äžçªäžã®è¡ã¯ãæãåçŽãªãã§ãŒã«ãªãŒããŒãã«ãã¹ããŒã ã§ã¯ãããã©ã«ãã«ãŒãã§check-gateway = pingãæå®ããããšã«ããããããã€ããŒã®ã«ãŒã¿ãŒãžã®æ¥ç¶ã®ã¿ããã§ãã¯ãããšããããšã§ãã ã€ã³ã¿ãŒãããããããã€ããŒã®ã«ãŒã¿ãŒã®èåŸã§å©çšã§ããªãå Žåãããã¯ç解ã§ããŸããã ãŸãã scopeãã©ã¡ãŒã¿ãŒã䜿çšãããã§ã€ã³ãã®å©ããåããŠããããã€ããŒãšã®æ¥ç¶ã確èªããã®ã§ã¯ãªããã€ã³ã¿ãŒãããäžã§æ¢ããŸãã
ãã¿ãã¬ã®äžã§ããã®ãããã¯ã«é¢ããMikroTik wikiã®ç§ã®è©³çŽ°ãªç¿»èš³/é©å¿ã
MikroTikã Nexthop_lookup
ç§ã®æèŠã§ã¯ãè±èªã®èšäºhttp://wiki.mikrotik.com/wiki/Manual:IP/Routeã¯å°ãèŠèœãšãããŠããŸãã ããã¯äžæ°ã«èªãŸããCisco CCNAã®èª¿æ»ã§ã¯ãããŸããããã§ããéãæ確ã«ãã®ééã翻蚳ããããã«ããŸãã ã©ããã«åãç²ã匷ããèŠãããå Žåã¯ãç§ãä¿®æ£ããŠãã ããã
ãŸããããã€ãã®çšèªãå®çŸ©ããŸãããã
Nexthop-æåéãã次ã®ãžã£ã³ãã ãã€ã³ãAïŒããšãã°ãç§ã®ã«ãŒã¿ãŒããïŒãããã€ã³ãBïŒgoogle DNS 8.8.8.8ã«èšã£ãŠã¿ãŸãããïŒããã®ãã±ããã®ã«ãŒãäžã®æ¬¡ã®ã²ãŒããŠã§ã€/ã«ãŒã¿ãŒ/ã«ãŒã¿ãŒãã€ãŸã ãã±ãããåŠçããã次ã®äžç¶ã»ã¯ã·ã§ã³ã 翻蚳ã§ã¯ãnext hopããšãããã¬ãŒãºã䜿çšããŸãïŒè±èªäž»çŸ©ã§ã¯ããããªããïŒã
å³æãã¯ã¹ãããã -çŽæ¥ã¢ã¯ã»ã¹å¯èœãªããã€ã³ãAãããã€ã³ãBãžã®ãã±ããã®ã«ãŒãäžã®æ¬¡ã®ã²ãŒããŠã§ã€/ã«ãŒã¿ãŒ/ã«ãŒã¿ãŒã ç§ã®å®¶ã®MikroTikã®å Žåãããã©ã«ãã«ãŒãïŒ
89.189.163.1-ããã¯å³æã®ãã¯ã¹ããããã§ãã ether1-gatewayçµç±ã§ã¢ã¯ã»ã¹ã§ããŸãã ãçŽæ¥ã¢ã¯ã»ã¹å¯èœãªãã¯ã¹ããããããšãããã¬ãŒãºã翻蚳ã§äœ¿çšãããŸãã
æ¥ç¶ãããã«ãŒã -æ¥ç¶ãããã«ãŒãã ã²ãŒããŠã§ã€ã«çŽæ¥ã¢ã¯ã»ã¹ã§ããã«ãŒãã
ã²ãŒããŠã§ã€ -ãããã¯ãŒã¯ã²ãŒããŠã§ã€/ã«ãŒã¿ãŒ/ã«ãŒã¿ãŒã
3ã€ã®ç¿»èš³ãªãã·ã§ã³ãã¹ãŠã䜿çšããŸãã
ã¹ã³ãŒã -ãã¯ã¹ããããæ€çŽ¢ãšã³ãžã³ã§äœ¿çšãããŸãã 次ã¯ã©ããªãããã§ãããã ç®çã®ã«ãŒãã¯ãã¹ã³ãŒãå€ãã¿ãŒã²ããã¹ã³ãŒãå€ä»¥äžã®ã«ãŒãããã®ã¿éžæã§ããŸãã ããã©ã«ãå€ã¯ãããã³ã«ã«äŸåããŸãïŒ
target-scope-ãã¯ã¹ããããæ€çŽ¢ãšã³ãžã³ã§äœ¿çšãããŸãã 次ã¯ã©ããªãããã§ãããã ããã¯ããã¯ã¹ãããããèŠã€ããããšãã§ããã«ãŒãã®ã¹ã³ãŒããã©ã¡ãŒã¿ãŒã®æ倧å€ã§ãã iBGPã®å Žåãå€ã¯ããã©ã«ãã§30ã«èšå®ãããŠããŸãã
äž¡æ¹ã®ãã©ã¡ãŒã¿ãŒã®å€ã®ãã¬ãŒãã
次ã®ããããæ€çŽ¢ããŸãã
ãã¯ã¹ãããããèŠã€ããããšã¯ãã«ãŒãéžæããã»ã¹ã®äžéšã§ãã
FIBã«ããã«ãŒãã«ã¯ãåã²ãŒããŠã§ã€ã¢ãã¬ã¹ã«å¯Ÿå¿ããã€ã³ã¿ãŒãã§ã€ã¹ãå¿ èŠã§ãã ãã¯ã¹ããããã²ãŒããŠã§ã€ã®ã¢ãã¬ã¹ã¯ããã®ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠçŽæ¥ã¢ã¯ã»ã¹ã§ããå¿ èŠããããŸãã çºä¿¡ãã±ãããåã²ãŒããŠã§ã€ã«éä¿¡ããããã«äœ¿çšããå¿ èŠãããã€ã³ã¿ãŒãã§ã€ã¹ã¯ããã¯ã¹ãããããæ€çŽ¢ããããšã§èŠã€ãããŸãã
äžéšã®ã«ãŒãïŒiBGPãªã©ïŒã¯ãã²ãŒããŠã§ã€ã¢ãã¬ã¹ãšããŠãMikroTikããè€æ°ã®ãããã²ãŒããŠã§ã€ã«ããã«ãŒã¿ãŒã«å±ããã¢ãã¬ã¹ãæã€å ŽåããããŸãã ãã®ãããªã«ãŒããFIBã«ã€ã³ã¹ããŒã«ããã«ã¯ãçŽæ¥ã¢ã¯ã»ã¹ã§ããã²ãŒããŠã§ã€ã®ã¢ãã¬ã¹ïŒå³æãã¯ã¹ããããïŒãèŠã€ããå¿ èŠããããŸãã ãã®ã«ãŒãã§ã²ãŒããŠã§ã€ã¢ãã¬ã¹ã«å°éããããã«äœ¿çšãããŸãã ãã¯ã¹ããããã®å³æã¢ãã¬ã¹ã¯ããã¯ã¹ããããæ€çŽ¢ãšã³ãžã³ã䜿çšããŠèŠã€ããããšãã§ããŸãã
次ã®ãããã®æ€çŽ¢ã¯ãåªããã«ãŒãã£ã³ã°ããŒã¯å€ãæã€ã«ãŒãã§ãã£ãŠããã¡ã€ã³ã«ãŒãã£ã³ã°ããŒãã«mainã§ã®ã¿å®è¡ãããŸãã ããã¯ãçŽæ¥ã¢ã¯ã»ã¹å¯èœãªãããïŒå³æãã¯ã¹ããããïŒã®æ€çŽ¢ã«äœ¿çšã§ããã«ãŒãã®ã€ã³ã¹ããŒã«ãå¶éããããã«å¿ èŠã§ãã RIPãŸãã¯OSPFã®ã«ãŒãã§ã¯ã次ã®ã«ãŒã¿ãŒãçŽæ¥ã¢ã¯ã»ã¹å¯èœã§ãããæ¥ç¶ãããã«ãŒãã®ã¿ã䜿çšããŠèŠã€ããå¿ èŠããããšæ³å®ãããŠããŸãã
ã²ãŒããŠã§ã€ãšããŠã€ã³ã¿ãŒãã§ã€ã¹åãæã€ã«ãŒãã¯ããã¯ã¹ããããã®æ€çŽ¢ã§ã¯äœ¿çšãããŸããã ã€ã³ã¿ãŒãã§ã€ã¹åãæã€ã«ãŒããšã¢ã¯ãã£ããªIPã¢ãã¬ã¹ãæã€ã«ãŒããããå Žåãã€ã³ã¿ãŒãã§ã€ã¹ãæã€ã«ãŒãã¯ç¡èŠãããŸãã
èš±å¯ãããæ倧å€ããã倧ããã¹ã³ãŒããã©ã¡ãŒã¿å€ãæã€ã«ãŒãã¯ããã¯ã¹ããããã®æ€çŽ¢ã§ã¯äœ¿çšãããŸããã åã«ãŒãã¯ã ã¿ãŒã²ããã¹ã³ãŒããã©ã¡ãŒã¿ãŒã§ããã¯ã¹ããããã®ã¹ã³ãŒããã©ã¡ãŒã¿ãŒã®æ倧蚱容å€ãæå®ããŸãã ãã®ãã©ã¡ãŒã¿ãŒã®ããã©ã«ãå€ã«ãããæ¥ç¶ãããã«ãŒãã®ã¿ãä»ããŠãã¯ã¹ãããããæ€çŽ¢ã§ããŸããäŸå€ãšããŠãiBGPã«ãŒãã¯ããã©ã«ãå€ãé«ããIGPããã³éçã«ãŒããä»ããŠãã¯ã¹ãããããæ€çŽ¢ã§ããŸãã
次ã®çŽæ¥ã¢ã¯ã»ã¹å¯èœãªã«ãŒã¿ãŒã®ã€ã³ã¿ãŒãã§ãŒã¹ãšã¢ãã¬ã¹ã¯ã次ã®ãããã®æ€çŽ¢çµæã«åºã¥ããŠéžæãããŸãã
ãããŠä»ã圌ããKVNã§èšãããã«ããªããã®æ°åãèŠããã®ã§ããã æåŸã®3è¡ã®éçã«ãŒãã«scope = 10ãèšå®ããããšã«æ³šæããŠãã ãããããã«ãããMikroTikã¯ãã¯ã¹ããããã®æ€çŽ¢æã«ãããã®ã«ãŒããèæ ®ã«å ¥ããŸãã
ããã¯åãå ¥ãããããã£ãŠããã©ã«ãã§ä»¥äžãçµç±ããŸãïŒ
ååž°çã«ãªããããªãã¡ ãããã€ããŒã®ã²ãŒããŠã§ã€ã«ã¯çŽæ¥ã¢ã¯ã»ã¹ã§ããåžæããããããããä»ããŠãã©ãã£ãã¯ãéä¿¡ããŸãããcheck-gateway = pingã¯ãããã€ããŒãããã¯ãŒã¯ã®èåŸã«ããã¢ãã¬ã¹ã®å¯çšæ§ããã§ãã¯ããŸãã
ç§ã®ç¿»èš³ãšèª¬æãããªãã®åœ¹ã«ç«ã€ããšãé¡ã£ãŠããŸãã
ãŸããããã€ãã®çšèªãå®çŸ©ããŸãããã
Nexthop-æåéãã次ã®ãžã£ã³ãã ãã€ã³ãAïŒããšãã°ãç§ã®ã«ãŒã¿ãŒããïŒãããã€ã³ãBïŒgoogle DNS 8.8.8.8ã«èšã£ãŠã¿ãŸãããïŒããã®ãã±ããã®ã«ãŒãäžã®æ¬¡ã®ã²ãŒããŠã§ã€/ã«ãŒã¿ãŒ/ã«ãŒã¿ãŒãã€ãŸã ãã±ãããåŠçããã次ã®äžç¶ã»ã¯ã·ã§ã³ã 翻蚳ã§ã¯ãnext hopããšãããã¬ãŒãºã䜿çšããŸãïŒè±èªäž»çŸ©ã§ã¯ããããªããïŒã
å³æãã¯ã¹ãããã -çŽæ¥ã¢ã¯ã»ã¹å¯èœãªããã€ã³ãAãããã€ã³ãBãžã®ãã±ããã®ã«ãŒãäžã®æ¬¡ã®ã²ãŒããŠã§ã€/ã«ãŒã¿ãŒ/ã«ãŒã¿ãŒã ç§ã®å®¶ã®MikroTikã®å Žåãããã©ã«ãã«ãŒãïŒ
dst-address=0.0.0.0/0 gateway=89.189.163.1 gateway-status=89.189.163.1 reachable via ether1-gateway
89.189.163.1-ããã¯å³æã®ãã¯ã¹ããããã§ãã ether1-gatewayçµç±ã§ã¢ã¯ã»ã¹ã§ããŸãã ãçŽæ¥ã¢ã¯ã»ã¹å¯èœãªãã¯ã¹ããããããšãããã¬ãŒãºã翻蚳ã§äœ¿çšãããŸãã
æ¥ç¶ãããã«ãŒã -æ¥ç¶ãããã«ãŒãã ã²ãŒããŠã§ã€ã«çŽæ¥ã¢ã¯ã»ã¹ã§ããã«ãŒãã
ã²ãŒããŠã§ã€ -ãããã¯ãŒã¯ã²ãŒããŠã§ã€/ã«ãŒã¿ãŒ/ã«ãŒã¿ãŒã
3ã€ã®ç¿»èš³ãªãã·ã§ã³ãã¹ãŠã䜿çšããŸãã
ã¹ã³ãŒã -ãã¯ã¹ããããæ€çŽ¢ãšã³ãžã³ã§äœ¿çšãããŸãã 次ã¯ã©ããªãããã§ãããã ç®çã®ã«ãŒãã¯ãã¹ã³ãŒãå€ãã¿ãŒã²ããã¹ã³ãŒãå€ä»¥äžã®ã«ãŒãããã®ã¿éžæã§ããŸãã ããã©ã«ãå€ã¯ãããã³ã«ã«äŸåããŸãïŒ
- é¢é£ã«ãŒãïŒ10ïŒã€ã³ã¿ãŒãã§ãŒã¹ãå®è¡ãããŠããå ŽåïŒ
- OSPFãRIPãMMEã«ãŒãïŒ20
- éçã«ãŒãïŒ30
- BGPã«ãŒãïŒ40
- é¢é£ã«ãŒãïŒ200ïŒã€ã³ã¿ãŒãã§ã€ã¹ãå®è¡ãããŠããªãå ŽåïŒ
target-scope-ãã¯ã¹ããããæ€çŽ¢ãšã³ãžã³ã§äœ¿çšãããŸãã 次ã¯ã©ããªãããã§ãããã ããã¯ããã¯ã¹ãããããèŠã€ããããšãã§ããã«ãŒãã®ã¹ã³ãŒããã©ã¡ãŒã¿ãŒã®æ倧å€ã§ãã iBGPã®å Žåãå€ã¯ããã©ã«ãã§30ã«èšå®ãããŠããŸãã
äž¡æ¹ã®ãã©ã¡ãŒã¿ãŒã®å€ã®ãã¬ãŒãã

次ã®ããããæ€çŽ¢ããŸãã
ãã¯ã¹ãããããèŠã€ããããšã¯ãã«ãŒãéžæããã»ã¹ã®äžéšã§ãã
FIBã«ããã«ãŒãã«ã¯ãåã²ãŒããŠã§ã€ã¢ãã¬ã¹ã«å¯Ÿå¿ããã€ã³ã¿ãŒãã§ã€ã¹ãå¿ èŠã§ãã ãã¯ã¹ããããã²ãŒããŠã§ã€ã®ã¢ãã¬ã¹ã¯ããã®ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠçŽæ¥ã¢ã¯ã»ã¹ã§ããå¿ èŠããããŸãã çºä¿¡ãã±ãããåã²ãŒããŠã§ã€ã«éä¿¡ããããã«äœ¿çšããå¿ èŠãããã€ã³ã¿ãŒãã§ã€ã¹ã¯ããã¯ã¹ãããããæ€çŽ¢ããããšã§èŠã€ãããŸãã
äžéšã®ã«ãŒãïŒiBGPãªã©ïŒã¯ãã²ãŒããŠã§ã€ã¢ãã¬ã¹ãšããŠãMikroTikããè€æ°ã®ãããã²ãŒããŠã§ã€ã«ããã«ãŒã¿ãŒã«å±ããã¢ãã¬ã¹ãæã€å ŽåããããŸãã ãã®ãããªã«ãŒããFIBã«ã€ã³ã¹ããŒã«ããã«ã¯ãçŽæ¥ã¢ã¯ã»ã¹ã§ããã²ãŒããŠã§ã€ã®ã¢ãã¬ã¹ïŒå³æãã¯ã¹ããããïŒãèŠã€ããå¿ èŠããããŸãã ãã®ã«ãŒãã§ã²ãŒããŠã§ã€ã¢ãã¬ã¹ã«å°éããããã«äœ¿çšãããŸãã ãã¯ã¹ããããã®å³æã¢ãã¬ã¹ã¯ããã¯ã¹ããããæ€çŽ¢ãšã³ãžã³ã䜿çšããŠèŠã€ããããšãã§ããŸãã
次ã®ãããã®æ€çŽ¢ã¯ãåªããã«ãŒãã£ã³ã°ããŒã¯å€ãæã€ã«ãŒãã§ãã£ãŠããã¡ã€ã³ã«ãŒãã£ã³ã°ããŒãã«mainã§ã®ã¿å®è¡ãããŸãã ããã¯ãçŽæ¥ã¢ã¯ã»ã¹å¯èœãªãããïŒå³æãã¯ã¹ããããïŒã®æ€çŽ¢ã«äœ¿çšã§ããã«ãŒãã®ã€ã³ã¹ããŒã«ãå¶éããããã«å¿ èŠã§ãã RIPãŸãã¯OSPFã®ã«ãŒãã§ã¯ã次ã®ã«ãŒã¿ãŒãçŽæ¥ã¢ã¯ã»ã¹å¯èœã§ãããæ¥ç¶ãããã«ãŒãã®ã¿ã䜿çšããŠèŠã€ããå¿ èŠããããšæ³å®ãããŠããŸãã
ã²ãŒããŠã§ã€ãšããŠã€ã³ã¿ãŒãã§ã€ã¹åãæã€ã«ãŒãã¯ããã¯ã¹ããããã®æ€çŽ¢ã§ã¯äœ¿çšãããŸããã ã€ã³ã¿ãŒãã§ã€ã¹åãæã€ã«ãŒããšã¢ã¯ãã£ããªIPã¢ãã¬ã¹ãæã€ã«ãŒããããå Žåãã€ã³ã¿ãŒãã§ã€ã¹ãæã€ã«ãŒãã¯ç¡èŠãããŸãã
èš±å¯ãããæ倧å€ããã倧ããã¹ã³ãŒããã©ã¡ãŒã¿å€ãæã€ã«ãŒãã¯ããã¯ã¹ããããã®æ€çŽ¢ã§ã¯äœ¿çšãããŸããã åã«ãŒãã¯ã ã¿ãŒã²ããã¹ã³ãŒããã©ã¡ãŒã¿ãŒã§ããã¯ã¹ããããã®ã¹ã³ãŒããã©ã¡ãŒã¿ãŒã®æ倧蚱容å€ãæå®ããŸãã ãã®ãã©ã¡ãŒã¿ãŒã®ããã©ã«ãå€ã«ãããæ¥ç¶ãããã«ãŒãã®ã¿ãä»ããŠãã¯ã¹ãããããæ€çŽ¢ã§ããŸããäŸå€ãšããŠãiBGPã«ãŒãã¯ããã©ã«ãå€ãé«ããIGPããã³éçã«ãŒããä»ããŠãã¯ã¹ãããããæ€çŽ¢ã§ããŸãã

次ã®çŽæ¥ã¢ã¯ã»ã¹å¯èœãªã«ãŒã¿ãŒã®ã€ã³ã¿ãŒãã§ãŒã¹ãšã¢ãã¬ã¹ã¯ã次ã®ãããã®æ€çŽ¢çµæã«åºã¥ããŠéžæãããŸãã
- ãã¯ã¹ããããã¢ãã¬ã¹ã®æ€çŽ¢äžã«èŠã€ãã£ãæãæ£ç¢ºãªã¢ã¯ãã£ãã«ãŒããæ¥ç¶ã«ãŒãã§ããå Žåããã®æ¥ç¶ã«ãŒãã®ã€ã³ã¿ãŒãã§ã€ã¹ããã¯ã¹ããããã®ã€ã³ã¿ãŒãã§ã€ã¹ãšããŠäœ¿çšãããã²ãŒããŠã§ã€ã¯å°éå¯èœãšããŠããŒã¯ãããŸãã ã«ãŒã¿ãŒããã®ã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠçŽæ¥ã¢ã¯ã»ã¹å¯èœã«ãªã£ãåŸïŒããã¯ãæ¥ç¶ã«ãŒãããŸãã¯ãæ¥ç¶ã«ãŒãããšããŠç解ãããã¹ãã§ãïŒããã®ã¢ãã¬ã¹ã¯çŽæ¥ã¢ã¯ã»ã¹å¯èœãªã«ãŒã¿ãŒã®ã¢ãã¬ã¹ïŒå³æãã¯ã¹ããããã¢ãã¬ã¹ïŒãšããŠäœ¿çšãããŸãã
- ãã¯ã¹ããããã¢ãã¬ã¹ã®æ€çŽ¢äžã«èŠã€ãã£ãæãæ£ç¢ºãªã¢ã¯ãã£ãã«ãŒãã«ãã§ã«èŠã€ãã£ãã²ãŒããŠã§ã€ã¢ãã¬ã¹ãããå ŽåãçŽæ¥ã¢ã¯ã»ã¹å¯èœãªããããšã€ã³ã¿ãŒãã§ã€ã¹ããã®ã«ãŒãããã³ããŒãããã²ãŒããŠã§ã€ã¯ååž°çãšããŠããŒã¯ãããŸãã
- ãã¯ã¹ããããã¢ãã¬ã¹ã®æ€çŽ¢äžã«èŠã€ãã£ãæãæ£ç¢ºãªã¢ã¯ãã£ãã«ãŒããECMPã«ãŒãã§ããå Žåããã®ã«ãŒãã®æåã®å©çšå¯èœãªã«ãŒã¿ãŒã䜿çšãããŸãã
- ãã¯ã¹ããããã®ã¢ãã¬ã¹ãèŠã€ããã¡ã«ããºã ãã«ãŒããèŠã€ããããªãã£ãå Žåãã²ãŒããŠã§ã€ã¯å°éäžèœãšããŠããŒã¯ãããŸãã
ãããŠä»ã圌ããKVNã§èšãããã«ããªããã®æ°åãèŠããã®ã§ããã æåŸã®3è¡ã®éçã«ãŒãã«scope = 10ãèšå®ããããšã«æ³šæããŠãã ãããããã«ãããMikroTikã¯ãã¯ã¹ããããã®æ€çŽ¢æã«ãããã®ã«ãŒããèæ ®ã«å ¥ããŸãã
ããã¯åãå ¥ãããããã£ãŠããã©ã«ãã§ä»¥äžãçµç±ããŸãïŒ
- 8.8.8.8
- 8.8.4.4
- 1.1.36.3
ååž°çã«ãªããããªãã¡ ãããã€ããŒã®ã²ãŒããŠã§ã€ã«ã¯çŽæ¥ã¢ã¯ã»ã¹ã§ããåžæããããããããä»ããŠãã©ãã£ãã¯ãéä¿¡ããŸãããcheck-gateway = pingã¯ãããã€ããŒãããã¯ãŒã¯ã®èåŸã«ããã¢ãã¬ã¹ã®å¯çšæ§ããã§ãã¯ããŸãã
ç§ã®ç¿»èš³ãšèª¬æãããªãã®åœ¹ã«ç«ã€ããšãé¡ã£ãŠããŸãã
æãç±å¿ãªç¥èã¯ãã¿ãã¬ã®äžã§èªãŸããŸãããããå°ãçãç°¡åã«è©±ããŸãããã
æåŸã®3è¡ã§scope = 10ãæå®ãããšãMikroTikã«å¯ŸããŠæ¬¡ã®ããšãæ確ã«ãªããŸãã
- 8.8.8.8
- 8.8.4.4
- 1.1.36.3
çŽæ¥ã§ã¯ãªãããããã®éçã«ãŒããä»ããŠååž°çã«ã¢ã¯ã»ã¹ã§ããŸãã ãã©ã¶ãŒãããã€ããŒããšã«1ã€ã®IPã
/ IPãã¡ã€ã¢ãŠã©ãŒã«ãã³ã°ã«
ã«ãŒã«ã¯ãã¡ã
/ip firewall mangle add action=mark-connection chain=input in-interface=ISP1 \ new-connection-mark=ISP1-conn passthrough=yes add action=mark-routing chain=output connection-mark=ISP1-conn \ new-routing-mark=ISP1-route passthrough=no add action=mark-connection chain=input in-interface=ISP2 new-connection-mark=\ ISP2-conn passthrough=yes add action=mark-routing chain=output connection-mark=ISP2-conn \ new-routing-mark=ISP2-route passthrough=no add action=mark-connection chain=input in-interface=ISP3 \ new-connection-mark=ISP3-conn passthrough=yes add action=mark-routing chain=output connection-mark=ISP3-conn \ new-routing-mark=ISP3-route passthrough=no add action=mark-connection chain=forward in-interface=ISP1 \ new-connection-mark=ISP1-conn-f passthrough=no add action=mark-routing chain=prerouting connection-mark=ISP1-conn-f \ in-interface=bridge new-routing-mark=ISP1-route add action=mark-connection chain=forward in-interface=ISP2 \ new-connection-mark=ISP2-conn-f passthrough=no add action=mark-routing chain=prerouting connection-mark=ISP2-conn-f \ in-interface=bridge new-routing-mark=ISP2-route add action=mark-connection chain=forward in-interface=ISP3 \ new-connection-mark=ISP3-conn-f passthrough=no add action=mark-routing chain=prerouting connection-mark=ISP3-conn-f \ in-interface=bridge new-routing-mark=ISP3-route
ãã®ã»ã¯ã·ã§ã³ã®ã«ãŒã«ã説æããããã«ãããã€ãã®ã¢ã·ã¹ã¿ã³ããæåŸ ããŸãã
- MANGLE-ãã®è¡šã¯ããã±ãããšæ¥ç¶ã®åé¡ãšã©ãã«ä»ããããã³ãã±ããããããŒïŒTTLããã³TOSãã£ãŒã«ãïŒã®å€æŽïŒwikiããã¥ã¢ã«ïŒãç®çãšããŠããŸãã
ãã³ã°ã«ããŒãã«ã«ã¯ã次ã®ãã§ãŒã³ãå«ãŸããŠããŸãã
- PREROUTING-ã«ãŒãã£ã³ã°ã決å®ããåã«ãã±ãããå€æŽã§ããŸãã
- INPUT-ãã¹ãèªäœã察象ãšããããã±ãŒãžãå€æŽã§ããŸãã
- FORWARD-äžç¶ãã±ãããå€æŽã§ãããã§ãŒã³ã
- åºå -ãã¹ãèªäœããã®ãã±ãããå€æŽã§ããŸãã
- POSTROUTING-ãã¹ãèªäœã«ãã£ãŠçæããããã¹ãŠã®çºä¿¡ãã±ãããšãééãããã±ãããå€æŽã§ããŸãã
- CONNECTION TRACKINGã¯ãæ¥ç¶ã®ã¹ããŒã¿ã¹ãç£èŠããåã ã®ããã±ãŒãžã®éåœã決å®ãããšãã«ãã®æ å ±ã䜿çšã§ããããã«ããç¹å¥ãªãµãã·ã¹ãã ã§ãã
- MikroTikã®ãã±ãããããŒ
ã«ãŒã«ãç解ããããããã«ã°ã«ãŒãã«åããŸããã æåã®ã°ã«ãŒãã«ã¯ãã«ãŒã¿ãŒèªäœãšã®éã®ãã©ãã£ãã¯ãæ åœãã6ã€ã®ã«ãŒã«ãããã2çªç®ã®ã°ã«ãŒã6ã«ã¯ãäžç¶ãã©ãã£ãã¯ãæ åœããŸãã
æåã®2ã€ããå§ããŸãããã
æåã«ããã¹ãŠã®çä¿¡ãã§ãŒã³= ISP1ã€ã³ã¿ãŒãã§ã€ã¹ãžã®å ¥åæ¥ç¶ã«action = mark-connection new-connection-mark = ISP1-connã®ããŒã¯ãä»ããå¿ èŠãããããšãã«ãŒã¿ãŒã«äŒããŸãããŸãããã®ã«ãŒã«ãééããåŸããã±ãããããŒãã«ãé¢ããã«ãŒã«ã«åŸã£ãŠç¶ããŸããã
2çªç®ã§ã¯ãMikroTikã«ISP1-connãšããŠããŒã¯ãããåºåãã§ãŒã³=åºåæ¥ç¶ããã£ããããã«ãŒãã£ã³ã°ã©ãã«ãå²ãåœãŠãŸãïŒå¯Ÿå¿ããã«ãŒãã£ã³ã°ããŒãã«ã«é 眮ããããã«ãæåã®3ã€ã®ã«ãŒããèŠããŠããŸããïŒïŒããŸãpassthrough = no ãhowèšãããš-ãã®ã«ãŒã«ã®åŸã«ããã±ãŒãžãããã§è¡ãããšã¯ãããŸããã ãã±ããã¯ããŒãã«ãé¢ããŸãã
äžèšã®ãã¹ãŠã¯ãISP2ãšISPââ3ã®äž¡æ¹ã«åœãŠã¯ãŸããŸãã ãããã£ãŠãã«ãŒã¿ã¯ãèŠæ±ãæ¥ãã€ã³ã¿ãŒãã§ã€ã¹ããæ£ç¢ºã«å¿çããããšãéæããŸããã
æåŸã®6ã€ã®ã«ãŒã«ã«é²ã¿ãŸãã
ãã§ã«æããã§ãããããã¯ãISPããšã«2ã€ã®ãµãã°ã«ãŒãã«åããããŸãã
ãããã®æåã¯ã FORWARDãã§ãŒã³ãç£èŠããããã«ã«ãŒã¿ãŒã«æ瀺ããISP1ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠæ¥ç¶ãçºçããå Žåã action = mark-connectionã§æ°ããã¿ã°ã§ããŒã¯ãããŸãnew-connection-mark = ISP1-conn-f ïŒæ³šïŒã«ãŒã¿ãŒèªäœã®ãã©ãã£ãã¯ã¿ã°ãšã¯ç°ãªããŸããã®å Žåããã©ã³ãžãããã©ãã£ãã¯ãããŒã¯ããŸãïŒã ãã¹ã¹ã«ãŒ= n o ãã®ã«ãŒã«ã«è©²åœããããã±ãŒãžã¯ãä»ã®æ¹æ³ã§ããŒãã«ã§åŠçãããããšã¯æãŸãããããŸããã
2çªç®ã¯ã PREROUTINGãã§ãŒã³ã®ç®çã®ã«ãŒãã£ã³ã°ã©ãã«new-routing-mark = ISP1-routeããã³ã°ã¢ããããŸãã ã«ãŒãã£ã³ã°ã«ã€ããŠæ±ºå®ããåã«ãããŒã«ã«ãããã¯ãŒã¯in-interface = bridgeããå°çãããã©ãã£ãã¯ãç£èŠããŸãã
ããã§ã CONNECTION TRACKINGã¡ã«ããºã ã圹ã«ç«ã¡ãŸããããã«ãããäžèšã®ã«ãŒã«ã§ããŒã¯ãããæ¥ç¶ãããŒã«ã«ãããã¯ãŒã¯ïŒWEBãµãŒããŒããïŒã§ãã£ããããå¿ èŠãªã«ãŒãã£ã³ã°ã¿ã°ã§ãããããã³ã°ãããããšãã§ããŸãã
ããã«ãããééãã©ãã£ãã¯ïŒããã§WebãµãŒããŒãšã®éïŒãæ£ç¢ºã«ãã®ãŸãŸã®ç¶æ ã§éä¿¡ãããŸãã ISP1ãä»ããŠæ¥ã-ããããã®ãŸãŸã«ããŸãã
ãããã«
ç§ã®èª¬æãæ確ã§ããã®ä»äºã圹ã«ç«ã€ãªããç§ã¯ãšãŠãããããã§ãã
çæ³ã«è¡ã£ãŠãã¿ããªã«å¹žéãïŒ
ãæž èŽããããšãããããŸããïŒ