ã¿ã¹ã¯ãèšå®ããããšã§äŒçµ±ã«åŸã£ãŠå§ããŸã ã
ãã®ãããã»ã³ãã©ã«ãªãã£ã¹ãšè€æ°ã®ãã©ã³ããããããããããããªãã¯ã³ãã¥ãã±ãŒã·ã§ã³ãã£ãã«ïŒã€ã³ã¿ãŒãããïŒã䜿çšããŠå ±éã®ãããã¯ãŒã¯ã«çµ±åããããšèããŠããŸãã
説æãããŠããGET VPNãã¯ãããžãŒãšã¯å¯Ÿç §çã«ãã€ã³ã¿ãŒããããã£ãã«ã䜿çšããããã«ã¯ããã³ããªã³ã°ïŒããããŒã®çœ®æïŒã䜿çšããå¿ èŠããããŸãã
ãã€ãããã¯ãã«ããã€ã³ãVPNïŒDMVPNïŒãšã¯äœã§ããïŒ èŠããã«ãããã¯IPSecãšã®ãã«ããã€ã³ãGREïŒ mGRE ïŒ ã¢ãœã·ãšãŒã·ã§ã³ã§ãã
mGREã¯ãåãã€ã³ã¿ãŒãã§ã€ã¹äžã®è€æ°ã®ãã€ããŒãšã®ãã³ãã«ã確ç«ããæ©èœãåããåŸæ¥ã®GREãšã¯ç°ãªããã³ããªã³ã°ãããã³ã«ã§ãã åºç€ã¯ããã®ãããªæ¥ç¶ãåçã«ç¢ºç«ã§ããNext-Hop Resolution ProtocolïŒ NHRP ïŒã®äœ¿çšã§ãã NHRPãšå¯Ÿè©±ããIPSecã¯ãå¿ èŠã«å¿ããŠSAã確ç«ããåæ¥ç¶ã«åå¥ã«æå·åãæäŸããŸãã
æ¥ç¶ããããžã¯åŸæ¥ã®ããã¢ã³ãã¹ããŒã¯ã§ãããDMVPNã䜿çšãããšãã¹ããŒã¯éãã³ãã«ãåçã«ç¢ºç«ã§ããããšãéèŠã§ãã
ã€ãŸããNHRPã®èãæ¹ã¯ããã¹ãŠã®ã¹ããŒã¯ã«å¯ŸããŠéçã«æå®ããããããŸãã¯NHS ïŒãã¯ã¹ãããããµãŒããŒïŒãæå®ããããšã§ãã åã¹ããŒã¯ã¯åçã«ç»é²ãããŸãïŒã€ãŸããæåã¯NHSã¯ã¹ããŒã¯ã¢ãã¬ã¹ãèªèããŸããïŒãNHSãšã®æ°žç¶çãªãã³ãã«ã確ç«ããNHSã¯ãã®ãã³ãã«ã¢ãã¬ã¹ãšå®éã®ã¢ãã¬ã¹ïŒãããã³ã°ïŒããã€ããŒããŒã¿ããŒã¹ã«å¯Ÿå¿ãããå¿ èŠã«å¿ããŠä»ã«ãéç¥ããŸããããä»ããã«ãçŽæ¥çžäºã«æ¥ç¶ã確ç«ã§ããŸããã ã¹ããŒã¯ããŒã¹ããŒã¯ã¯ãããããŒã¹ããŒã¯ãšã¯ç°ãªããæ°žç¶çã§ã¯ãªãäžæçãªäŒè©±ã§ãã ãã©ã³ãéã®ãã©ãã£ãã¯ããã°ãããªããªããšããã©ã³ãéã®ãã³ãã«ã¯åé€ãããŸãã ããã«ãããã¹ããŒã«ãŒãšåãæ°ã®æ¥ç¶ãä¿æããå¿ èŠããªããããã¹ããŒã¯ã«ãŒã¿ãšããŠãã匱ãã¢ãã«ã䜿çšããããšãå¯èœã«ãªããŸãã ããã©ãããããããšããŠããã¹ãŠã®ã¹ããŒã¯ãšã®æ¥ç¶ã«èããã®ã«ååãªåŒ·åºŠã®ã«ãŒã¿ãŒãéžæããå¿ èŠããããŸãã
åãã©ã³ãã¯ïŒç»é²ãéããŠïŒããã®ååšãåçã«éç¥ããããããã©ã³ãã«ãŒã¿ãåçNATã®èåŸã«é ãããšãã§ããŸãã ãããŠä»¥æ¥ ããã¯åãã©ã³ãã«ãŒã¿ã§éçã«æ§æãããéçNATã®èåŸã«ã®ã¿é 眮ã§ããŸãã
次ã«ã ãã§ãŒãºDMVPNã®æŠå¿µã玹ä»ããŸã ã ãã®å Žåã®ãã§ãŒãºã¯ãã¹ããŒã¯ããŒã¹ããŒã¯ãŸãã¯ã¹ããŒã¯ããŒããã®çžäºäœçšã®ã¿ã€ãïŒãŸãã¯ãã£ã©ã¯ã¿ãŒïŒãšããŠç解ãããŸãã åèšã§3ã€ã®ãã§ãŒãºããããŸãã
ãã§ãŒãº1 ã ããããŒã¹ããŒã¯ãã³ãã«ã®ã¿ãå®è£ ãããã¹ããŒã¯ããŒã¹ããŒã¯ãã³ãã«ã¯ã€ã³ã¹ããŒã«ãããããã¹ãŠã®ãã©ãã£ãã¯ã¯ãããééããŸãã ãã®å Žåãã«ãŒãã£ã³ã°ãããã³ã«ã®ãã¯ã¹ãããããNHCã¢ãã¬ã¹ããNHSã¢ãã¬ã¹ã«çœ®ãæããã®ãè«ççã§ãã
ç»é²ã¯æ¬¡ã®ãšããã§ãã
ã€ãŸã æåã«ãIPSecãã³ãã«ã確ç«ããã次ã«NHCãNHRPç»é²èŠæ±ã¡ãã»ãŒãžãéä¿¡ããŸãã
ã¡ãã»ãŒãžã®ééã¯ã1/3ãip nhrp registration holdtimeããŸãã¯ãip nhrp registration timeoutãã§ãã NHSãå¿çããªãå Žåãééã¯1ïŒ1ã2ã4ã8 ...ã64ã...ïŒããå§ãŸãææ°é¢æ°çã«å¢å ããŸãã åæã«ã3åç®ã®è©Šè¡åŸãNHSã¯ããŠã³ãšããŠããŒã¯ããã䜿çšãããŸããã ã€ãŸããç»é²èŠæ±ã«ã¯ããŒãã¢ã©ã€ãæ©èœããããŸãã
åNHRPç»é²ã¡ãã»ãŒãžã«ã¯ãNHCãã³ãã«ã¢ãã¬ã¹ãšãã®å®éã®ã¢ãã¬ã¹ïŒNBMAïŒã®å¯Ÿå¿ãå«ãŸããŸãããŸããèªèšŒãNATãªã©ã®æ¡åŒµããããŒãå«ãŸããå ŽåããããŸãã
ãã®ã¡ãã»ãŒãžã«å¯Ÿããçãã¯ãåœç¶ãNHRPç»é²å¿çã§ãã NHCãšNHSã®å®éã®ã¢ãã¬ã¹ãšãã³ãã«ã¢ãã¬ã¹ã®å¯Ÿå¿ãããã³ãã¹ãŠã®åãæ¡åŒµããããŒãå«ãŸããŠããŸãã å®éãããã®æŽ»åã確èªããŸãã
NHCãç»é²ãããšãNHRPããŒãã«ã®åºåã¯æ¬¡ã®ããã«ãªããŸãã
ãã㧠ïŒ
HUB#sh ip nhrp
10.1.1.2/32 via 10.1.1.2, Tunnel0 created 15:17:10, expire 01:22:43
Type: dynamic, Flags: unique registered
NBMA address: 172.16.2.1
10.1.1.3/32 via 10.1.1.3, Tunnel0 created 15:17:10, expire 01:22:43
Type: dynamic, Flags: unique registered
NBMA address: 172.16.3.1
ã¹ããŒã¯1㧠ïŒ
SPOKE1#sh ip nhrp
10.1.1.1/32 via 10.1.1.1, Tunnel0 created 15:17:45, never expire
Type: static, Flags: used
NBMA address: 172.16.1.1
ãããã³ã°ã®åºåã«è§Šããã®ã§ããããã®ãããã³ã°ã«å¯Ÿå¿ãã
çš®é¡
- éç -ã€ã³ã¿ãŒãã§ã€ã¹ããã³ãã«ã¢ãã¬ã¹ãšå®éã®ã¢ãã¬ã¹ã«æ確ã«äžèŽããã¬ã³ãŒãïŒip nhrp map ...ïŒ
- åç -NHRPã«ãã£ãŠååŸãããã¬ã³ãŒãã 次ã®2ã€ã®ã¿ã€ãããããŸãã
- äžå®å š -ãã³ãã«ã¢ãã¬ã¹ãã¹ããŒã¯ããŠããããšã¯ããã£ãŠããŸãããNHRP解決èŠæ±ãžã®å¿çããŸã åä¿¡ããŠããŸããã
æ
- ãŠããŒã¯ ã€ãŸãããã®ãããã³ã°ã¯äžæã§ãããNBMAã¢ãã¬ã¹ãå€æŽãããå Žåããã®ã¬ã³ãŒãã¯æŽæ°ãããŸããã
- ç»é²æžã¿ -NHRPç»é²ããååŸãéåžžã¯ããäžã
- åŠãã -NHRPç»é²ããååŸãå察ã«ãé垞話ããã
- ä¿¡é Œã§ãã ã NHRP解決èŠæ±ãžã®å¿çã«äœ¿çšã§ããŸãã
- 䜿çšæžã¿ ã éå»60ç§éã«èšé²ã䜿çšãããŸããã
- ã«ãŒã¿ãŒ ãªã¢ãŒãã«ãŒã¿ãŒãŸãã¯ãã®èåŸã®ãããã¯ãŒã¯ã®ãšã³ããªã«ã¯ããã®ãã©ã°ãä»ããŠããŸãã
- æé»ç ã NHRPãã±ããã®ãœãŒã¹æ å ±ããååŸããã¬ã³ãŒãã
- ããŒã«ã« NHRPèŠæ±ãžã®å¿çã§ä»ã®ã¹ããŒã¯ã«æäŸããããŒã«ã«ãããã¯ãŒã¯ã«é¢ããæ å ±ã ãã®ã¹ããŒã¯ã®NBMAã¢ãã¬ã¹ãä¿åããŸãã
- NAT ïŒIOSã®12.4ïŒ6ïŒTããŒãžã§ã³ã§è¡šç€ºããã12.4ïŒ15ïŒTã®åŸã«è¡šç€ºãããŸããããªã¢ãŒããã¢ãNATãä»ããäœæ¥ããµããŒãããããšã瀺ããŸãã12.4ïŒ15ïŒTã®åŸãèŠæ±ãããNBMAã¢ãã¬ã¹ãåã«ã¬ã³ãŒãã«è¡šç€ºãããŸãã
- ãœã±ãããªã ã ãã®ãã³ãã«ãå¿ èŠãšãããã©ãã£ãã¯ããªããããã«ãŒã¿ãŒãIPSecãã³ãã«ãå¿ èŠãšããªãããŸãã¯ç¢ºç«ããããªãã¬ã³ãŒãã ãã®ãããªãã©ãã£ãã¯ããã®åŸè¡šç€ºãããå Žåããšã³ããªã¯ããœã±ãããã«å€æãããIPsecãã³ãã«ãçºçããŸãã Localãimplicitãªã©ã®ãšã³ããªã¯ãåžžã«æåã«ããœã±ãããªãããšããŒã¯ãããŸãã ããã«ãNHRPã¯ãããã©ã«ãã§ã¯ãNHRP解決èŠæ±ãŸãã¯å¿çãã«ãŒã¿ãŒãééãããšãã«ããããããã®ãœãŒã¹æ å ±ããã£ãã·ã¥ããŸãã ãã®ãã£ãã·ã¥ãèš±å¯ããããIPSecãã³ãã«ãäžããããšã¯ã§ããªããããïŒãœã±ãããªãïŒãšããŒã¯ãããŸãã ãããè¡ããªããšãããããã¹ããŒã¯ãžã®äžèŠãªIPSecãœã±ããã圢æããã䜿çšãããŸããã ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã«å°éããããããåºãããŒã¿ã¯ïŒãœã±ãããªãïŒã¬ã³ãŒãã䜿çšã§ããŸããããã®å Žåãã«ãŒã¿ãŒã¯éä¿¡ãã2ã€ã®éã®ãã¹äžã®äžéããŒãã§ãããäžéãã€ã³ããæã€å¥ã®ãã³ãã«ãäœæããå¯èœæ§ã¯äœãããã§ãã ããæç¹ã§ã«ãŒã¿ãŒããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ããæ¥ãŠããªãããŒã¿ãã±ãããåä¿¡ããïŒnmoãœã±ããïŒã¬ã³ãŒãã䜿çšããå¿ èŠãããå Žåãã«ãŒã¿ãŒã¯ãããïŒãœã±ããïŒã¬ã³ãŒãã«å€æããŸãããã®å Žåãã«ãŒã¿ãŒããã®ãã³ãã«ãžã®åºå£ãã€ã³ãã«ãªãããã§ããããŒã¿ã¹ããªãŒã ã ãŸããNHRPç»é²ããååŸãããã¬ã³ãŒãã®ã¿ãïŒä¿¡é Œã§ããïŒãšããŠããŒã¯ãããããããããã®ïŒãœã±ãããªãïŒãšã³ããªã¯ïŒä¿¡é Œã§ããªãïŒãšããŠããŒã¯ãããŸãã
- è² èŠæ±ããããããã³ã°ããŸã åä¿¡ãããŠããªãããšãæå³ããŸãã NHRPãNHRP解決èŠæ±ãéä¿¡ãããšããã®ïŒè² ã®ïŒãã©ã°ãäžå®å šãªã¿ã€ãã®ã¬ã³ãŒãã«èšå®ããŸããããã«ãããã«ãŒã¿ãŒã¯ãå¿çãèŠèŸŒãã ããIPSecæ¥ç¶ã確ç«ããããããšãã«ãããã®èŠæ±ãè€æ°åéä¿¡ããããšãé²ããŸãã
ç»é²åŸãã«ãŒãã£ã³ã°æ å ±ã®äº€æãè¡ãããããã¯ããèªäœãåã«ãŒãã®ãã¯ã¹ãããããšããŠèšå®ããŸãã ãã®åŸãNHCã¯ãããä»ããŠããŒã¿ã亀æã§ããŸãã
ãã®ãã¯ãããžãŒã®å©ç¹ã® 1ã€ã¯ãåNHCã«1ã€ã®ãã³ãã«ããååšããªãããšã§ããããã«ããããªãœãŒã¹ãç¯çŽãããŸãã
æ¬ ç¹ã¯æããã§ãããããä»ããŠã«ãŒãã£ã³ã°ãããšããããããŒããããã ãã§ãªããå€§å¹ ãªäŒéé 延ãçºçããŸãã
ãã§ãŒãº2 ã ããã§ã¯ãCEFããªãã¯ã䜿çšããã¹ããŒã¯éãã³ãã«ãæ¢ã«æ§ç¯ã§ããŸãã ãã¹ãŠã®ãã©ã³ãã¯ãåããã¯ã¹ããããã§å®å šãªã«ãŒãã£ã³ã°æ å ±ãåãåããŸãïŒãããè¡ãæ¹æ³ã«ã€ããŠã¯åŸã§èª¬æããŸãïŒã
NHSãããã®ãããªã«ãŒããåä¿¡ããNHCã¯ããã®ã«ãŒãã«ãç¡å¹ããšããŒã¯ããã察å¿ããCEFã¬ã³ãŒããé 眮ãã次ãããã¢ãã¬ã¹ïŒã€ãŸããå¥ã®NHCã®ã¢ãã¬ã¹ïŒã«ãåéã¿ã€ãã¬ã³ãŒãïŒã€ãŸããL3ã¢ãã¬ã¹ãã¢ãã¬ã¹L2ã«è§£æ±ºæžã¿ïŒã ãã®èš±å¯ã¯ãæåã®ãã±ããããã®ã«ãŒãã§éä¿¡ããããšãã«NHRPã«ãã£ãŠä»äžãããŸãã
ãã®ãããªãšã³ããªã®äŸïŒ
SPOKE1#sh ip cef 192.168.2.0
192.168.2.0/24, version 27, epoch 0
0 packets, 0 bytes
via 10.1.1.3, Tunnel0, 0 dependencies
next hop 10.1.1.3, Tunnel0
invalid adjacency
SPOKE1#sh ip cef 10.1.1.3
10.1.1.0/24, version 20, epoch 0, attached, connected
0 packets, 0 bytes
via Tunnel0, 0 dependencies
valid glean adjacency
NHRPã¬ãã«ã§ã¯ã第2ãã§ãŒãºã«å¯Ÿå¿ãã3çš®é¡ã®ã¬ã³ãŒãããããŸãã
- ãšã³ããªãŒãªãã ãã¹ãŠãééçã§ããããã©ãã£ãã¯ã¯NHSã«éä¿¡ããããã®åŸNHRP解決èŠæ±ãéä¿¡ãããŸãã
- ã¿ã€ãã¬ã³ãŒãïŒãœã±ãããªãïŒã éä¿¡ããçžæã¯ããã£ãŠããããã§ãããIPSecæ¥ç¶ã¯ç¢ºç«ãããŠããŸããã ãã©ãã£ãã¯ã¯ãŸã NHSã«é£ãã§ãå¥ã®NHCã«æ¥ç¶ããŸã
- ã¿ã€ãã¬ã³ãŒãïŒãœã±ããïŒã ãã©ãã£ãã¯ã¯ãIPSecãã³ãã«ãä»ããŠå¥ã®NHCã«éãããŸãã
æåã®ãã±ããã¯ãããã»ã¹ã¹ã€ããã³ã°ã䜿çšããŠNHSçµç±ã§éä¿¡ãããŸãã NHCã¯NHS NHRP解決èŠæ±ãéä¿¡ããŸããNHSã¯ãCEFãšã³ããªãè£å ã§ããã¢ãã¬ã¹ã§NHSã«å¿çããŸãã
æ©èœ iOS 12.4.5aããåã§ã¯ãèŠæ±ãšå¿çã¯NHSãã§ãŒã³å šäœãééããŠããŸããã ïŒ6500ããã³7600ã§ã¯ãªãïŒNHRP解決èŠæ±ãžã®å¿çæ©èœããèå³ã®ããNHCèªäœã«è»¢éãããŸããã æ°ãããã§ãŒãºã®å®è£ ã®çžäºäœçšã¹ããŒã ãå³ã«ç€ºããŸãã
ãã§ãŒãº2ã®ãããã°nhrpãã±ããã³ãã³ãã®åºåäŸ
SPOKE1#ping 192.168.2.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.2.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 8/41/72 ms
SPOKE1#
*Mar 1 00:30:01.367: NHRP: Send Resolution Request via Tunnel0 vrf 0, packet size: 81
*Mar 1 00:30:01.367: src: 10.1.1.2, dst: 10.1.1.3
*Mar 1 00:30:01.371: (F) afn: IPv4(1), type: IP(800), hop: 255, ver: 1
*Mar 1 00:30:01.371: shtl: 4(NSAP), sstl: 0(NSAP)
*Mar 1 00:30:01.371: (M) flags: "router auth src-stable", reqid: 4
*Mar 1 00:30:01.371: src NBMA: 172.16.2.1
*Mar 1 00:30:01.371: src protocol: 10.1.1.2, dst protocol: 10.1.1.3
*Mar 1 00:30:01.375: (C-1) code: no error(0)
*Mar 1 00:30:01.375: prefix: 0, mtu: 1514, hd_time: 7200
*Mar 1 00:30:01.375: addr_len: 0(NSAP), subaddr_len: 0(NSAP), proto_len: 0, pref: 0
*Mar 1 00:30:01.375: NHRP: Send Resolution Request via Tunnel0 vrf 0, packet size: 81
*Mar 1 00:30:01.379: src: 10.1.1.2, dst: 10.1.1.1
*Mar 1 00:30:01.379: (F) afn: IPv4(1), type: IP(800), hop: 255, ver: 1
*Mar 1 00:30:01.379: shtl: 4(NSAP), sstl: 0(NSAP)
*Mar 1 00:30:01.383: (M) flags: "router auth src-stable", reqid: 4
*Mar 1 00:30:01.383: src NBMA: 172.16.2.1
*Mar 1 00:30:01.383: src protocol: 10.1.1.2, dst protocol: 10.1.1.3
*Mar 1 00:30:01.383: (C-1) code: no error(0)
*Mar 1 00:30:01.387: prefix: 0, mtu: 1514, hd_time: 7200
*Mar 1 00:30:01.387: addr_len: 0(NSAP), subaddr_len: 0(NSAP), proto_len: 0, pref: 0
*Mar 1 00:30:01.415: NHRP: Receive Resolution Reply via Tunnel0 vrf 0, packet size: 109
*Mar 1 00:30:01.415: (F) afn: IPv4(1), type: IP(800), hop: 255, ver: 1
*Mar 1 00:30:01.415: shtl: 4(NSAP), sstl: 0(NSAP)
*Mar 1 00:30:01.415: (M) flags: "router auth dst-stable unique src-stable", reqid: 4
*Mar 1 00:30:01.419: src NBMA: 172.16.2.1
*Mar 1 00:30:01.419: src protocol: 10.1.1.2, dst protocol: 10.1.1.3
*Mar 1 00:30:01.419: (C-1) code: no error(0)
*Mar 1 00:30:01.423: prefix: 32, mtu: 1514, hd_time: 6089
*Mar 1 00:30:01.423: addr_len: 4(NSAP), subaddr_len: 0(NSAP), proto_len: 4, pref: 0
*Mar 1 00:30:01.423: client NBMA: 172.16.3.1
*Mar 1 00:30:01.423: client protocol: 10.1.1.3
src NBMAãã£ãŒã«ãã®ååšã«ãããNHCå®å ã¯ããããã€ãã¹ããŠå¿çã§ããŸãã
åè
- äžèŠãã¯ã¹ããããã¢ãã¬ã¹ãä¿åããããšã¯ãè«ççã§æ£ãã解決çã®ããã«æããŸãã ãã ããæ¬ ç¹ã1ã€ãããŸããåNHCã¯ãåèšã䜿çšããã«ãNHSããã«ãŒãã£ã³ã°ããŒãã«å šäœãåä¿¡ããå¿ èŠããããŸãã ããã«ããã1ã¬ãã«ã®NHSã®ã¿ã䜿çšã§ããŸãã NHCã®ååã1ã€ã®NHSã§åŠçããæ®ãã®ååããã1ã€ã®NHSã§åŠçã§ããŸãããããããäºãã«NHSãšããŠæ¥ç¶ããå¿ èŠããããŸãã ããã¯ãNHRP解決èŠæ±ããã¹ãŠã®æœåšçãªNHSãééã§ããããã«ããããã«å¿ èŠã§ãã ãŸããéç衚瀺ã«ãããå šäœçãªä¿¡é Œæ§ãäœäžããŸãã
- ãŸããæåã®ãã±ããã¯CEFçµç±ã§ã¯ãªããããã»ã¹ã¹ã€ããã³ã°çµç±ã§éä¿¡ãããŸãã
ãã§ãŒãº3 ã
ãã®ãã§ãŒãºã§ã¯ãNHCãNHRP解決èŠæ±ãžã®å¿çã«åå ã§ããããã«ãããã®ãå©ç¹ããNHSããååŸããŸãã
æé ãæ€èšããŠãã ããã
- NHCã¯äŒçµ±çã«NHSã«ç»é²ãããŠãããNHSã¯ã«ãŒãã£ã³ã°ãããã³ã«ã«åŸã£ãŠNHCãšè¿é£ã確ç«ããã«ãŒãã£ã³ã°æ å ±ã亀æã§ããŸãã åæã«ãNHSã¯å ã®åœ¢åŒã§ã«ãŒãã£ã³ã°æ å ±ãä¿åãã矩åããããŸãããããã¯ããã¯ã¹ãããããèªèº«ãšäº€æããåæã«èŠçŽããããšãã§ããŸãã ããã«ãNHCã«è¿éããã«ãŒããããäžè¬çã§ããã»ã©ãç°¡åã«ãªããŸã:)
- NHCã¯ã«ãŒãã£ã³ã°æ å ±ãåä¿¡ããCEFããŒãã«ã«å ¥åããŸãã ãã¯ã¹ããããããNHSèªäœãã§ããã®ã§ããç¡å¹ãªããŸãã¯ãç¡é§ã®ãªãããšã³ããªã¯ãããŸããã èšãæããã°ããã®ã«ãŒãã®æåã®ãã±ããã¯CEFã䜿çšããŠéä¿¡ãããŸã...ããã§... ...æ£ãããããã«ïŒ ããããããã¯ããšããããCEFã«ã誀ã£ãããšã³ããªããªããŠãNHRP解決èŠæ±ãããªã¬ãŒãããªãããšãæå³ããŸãïŒ ãããŠãããã§NHRPãªãã€ã¬ã¯ãã¡ãã»ãŒãžãã¢ãªãŒãã«å ¥ããŸã ïŒ
- ã¹ããã3ã¯ã2çªç®ã®ã¹ãããã®çŽæ¥ã®ç¶ç¶ã§ãã ãã®ãããã¹ããŒã¯ããå¥ã®ã¹ããŒã¯ã«éä¿¡ãããæåã®ãã±ããã¯NHSãééããŸãã NHSãmGREãã³ãã«ãä»ããŠãã±ãããåä¿¡ããåãã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠïŒãã ããå¥ã®NHCã«ïŒåŒ·å¶çã«éãè¿ããšãNHSã¯ãã®ãããªãã±ããã®ãœãŒã¹ã«ç¬¬3ãã§ãŒãºã®äž»èŠãªãããªãã¯ããNHRPãªãã€ã¬ã¯ãã¡ãã»ãŒãžãéä¿¡ããŸãã ãã®ã¡ãã»ãŒãžã¯ããã±ããã«ãŒãã£ã³ã°ã§ãæ£ãããªãã:)ãã¹ã䜿çšããŠããããšãNHCã«äŒããŸãã ãããŠã圌ã¯ãNHRPã®è§£æ±ºçã䜿çšããŠNHCã®ãã¹ãæ確ã«ãããšãããšã瀺åãããŠããŸãã ããã«ãããããããæåã®ãã±ããèªäœã¯NHSã«éä¿¡ãããŸãã
- ãŸãç¶ããŸãã ããã§ãæåã®ãã±ãããéä¿¡ããNHCã¯ããã®æåã®ãã±ããã®å®å ã¢ãã¬ã¹ãå«ããªãã€ã¬ã¯ãã¡ãã»ãŒãžãåä¿¡ããŸãã ãã®NHCã¯ãåãIPã«å¯ŸããŠNHRP解決èŠæ±ãéä¿¡ããŸãããïŒæ³šæ!!!ïŒNHSã«ã¯éä¿¡ãããåãã¢ãã¬ã¹ã«éä¿¡ããŸã ã ã€ãŸã NHCã¯å¥ã®NHCã«å®éã®äœæãå°ããŸãã ç¹°ãè¿ããŸãããNHRP解決èŠæ±ã®å®å ã¢ãã¬ã¹ã¯NHSã§ã¯ãªããïŒæåã®ãã±ããã®ããã«ïŒNHSãä»ããŠå°éããŸãããé¢å¿ã®ããNHCã§ãã NHSã¯ãæå³ãããšããã«éä¿¡ããŸãïŒã€ãŸãããã±ããã¯ãããééããŸãããæé©ã§ã¯ãããŸããïŒã
- ãã«ãããªã³ã°:)ããã§ãå®å NHCïŒNHSã§ã¯ãªã!!ïŒã解決èŠæ±ã«å¿çããŠããŸãã èŠæ±ã«æ·»ä»ãããå®éã®ã¢ãã¬ã¹ã䜿çšããŠããã®NHCã¯NHSããã€ãã¹ããŠéä¿¡è ã«çŽæ¥å¿çããŸãã ãã®å Žåãå¿çã«ã¯ãèŠæ±ãããã¢ãã¬ã¹ã ãã§ãªããRIBã§èŠã€ãã£ããããã¯ãŒã¯å šäœïŒã«ãŒãããã¬ãã£ãã¯ã¹ïŒãå«ãŸããŸãã NHCãªã¯ãšã¹ãéä¿¡è ããã®ãããªå¿çãåä¿¡ãããšããã®ã¢ãã¬ã¹ã®å®éã®ãã¯ã¹ãããããèŠã€ããNHRPããŒãã«ã«å ¥åããCEFã®ãšã³ããªãä¿®æ£ããŸãïŒãŸãã¯æ°ãããšã³ããªãäœæããŸãïŒã
åæ¹èšå ¥åºåã®äŸïŒ
SPOKE2#ping 192.168.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 32/51/84 ms
SPOKE2#
*Mar 1 00:07:57.151: NHRP: Receive Traffic Indication via Tunnel0 vrf 0, packet size: 97
*Mar 1 00:07:57.155: (F) afn: IPv4(1), type: IP(800), hop: 255, ver: 1
*Mar 1 00:07:57.155: shtl: 4(NSAP), sstl: 0(NSAP)
*Mar 1 00:07:57.159: (M) traffic code: redirect(0)
*Mar 1 00:07:57.159: src NBMA: 172.16.1.1
*Mar 1 00:07:57.159: src protocol: 10.1.1.1, dst protocol: 10.1.1.3
*Mar 1 00:07:57.163: Contents of nhrp traffic indication packet:
*Mar 1 00:07:57.167: 45 00 00 64 00 00 00 00 FE 01 EF EB 0A 01 01 03
*Mar 1 00:07:57.171: C0 A8 01 01 08 00 36 7F 00 00 00
*Mar 1 00:07:57.211: NHRP: Send Resolution Request via Tunnel0 vrf 0, packet size: 85
*Mar 1 00:07:57.215: src: 10.1.1.3, dst: 192.168.1.1
*Mar 1 00:07:57.219: (F) afn: IPv4(1), type: IP(800), hop: 255, ver: 1
*Mar 1 00:07:57.219: shtl: 4(NSAP), sstl: 0(NSAP)
*Mar 1 00:07:57.219: (M) flags: "router auth src-stable nat ", reqid: 5
*Mar 1 00:07:57.219: src NBMA: 172.16.3.1
*Mar 1 00:07:57.219: src protocol: 10.1.1.3, dst protocol: 192.168.1.1
*Mar 1 00:07:57.219: (C-1) code: no error(0)
*Mar 1 00:07:57.219: prefix: 0, mtu: 1514, hd_time: 7200
*Mar 1 00:07:57.219: addr_len: 0(NSAP), subaddr_len: 0(NSAP), proto_len: 0, pref: 0
*Mar 1 00:07:57.247: NHRP: Receive Resolution Request via Tunnel0 vrf 0, packet size: 105
*Mar 1 00:07:57.251: (F) afn: IPv4(1), type: IP(800), hop: 254, ver: 1
*Mar 1 00:07:57.251: shtl: 4(NSAP), sstl: 0(NSAP)
*Mar 1 00:07:57.255: (M) flags: "router auth src-stable nat ", reqid: 6
*Mar 1 00:07:57.255: src NBMA: 172.16.2.1
*Mar 1 00:07:57.259: src protocol: 10.1.1.2, dst protocol: 10.1.1.3
*Mar 1 00:07:57.263: (C-1) code: no error(0)
*Mar 1 00:07:57.263: prefix: 0, mtu: 1514, hd_time: 7200
*Mar 1 00:07:57.263: addr_len: 0(NSAP), subaddr_len: 0(NSAP), proto_len: 0, pref: 0
*Mar 1 00:07:57.271: NHRP: Send Resolution Reply via Tunnel0 vrf 0, packet size: 133
*Mar 1 00:07:57.275: src: 10.1.1.3, dst: 10.1.1.2
*Mar 1 00:07:57.279: (F) afn: IPv4(1), type: IP(800), hop: 255, ver: 1
*Mar 1 00:07:57.279: shtl: 4(NSAP), sstl: 0(NSAP)
*Mar 1 00:07:57.283: (M) flags: "router auth dst-stable unique src-stable nat ", reqid: 6
*Mar 1 00:07:57.283: src NBMA: 172.16.2.1
*Mar 1 00:07:57.287: src protocol: 10.1.1.2, dst protocol: 10.1.1.3
*Mar 1 00:07:57.291: (C-1) code: no error(0)
*Mar 1 00:07:57.291: prefix: 32, mtu: 1514, hd_time: 7200
*Mar 1 00:07:57.295: addr_len: 4(NSAP), subaddr_len: 0(NSAP), proto_len: 4, pref: 0
*Mar 1 00:07:57.299: client NBMA: 172.16.3.1
*Mar 1 00:07:57.299: client protocol: 10.1.1.3
*Mar 1 00:07:57.323: NHRP: Receive Resolution Reply via Tunnel0 vrf 0, packet size: 153
*Mar 1 00:07:57.331: (F) afn: IPv4(1), type: IP(800), hop: 254, ver: 1
*Mar 1 00:07:57.331: shtl: 4(NSAP), sstl: 0(NSAP)
*Mar 1 00:07:57.331: (M) flags: "router auth dst-stable unique src-stable nat ", reqid: 5
*Mar 1 00:07:57.335: src NBMA: 172.16.3.1
*Mar 1 00:07:57.339: src protocol: 10.1.1.3, dst protocol: 192.168.1.1
*Mar 1 00:07:57.343: (C-1) code: no error(0)
*Mar 1 00:07:57.343: prefix: 24, mtu: 1514, hd_time: 7200
*Mar 1 00:07:57.343: addr_len: 4(NSAP), subaddr_len: 0(NSAP), proto_len: 4, pref: 0
*Mar 1 00:07:57.347: client NBMA: 172.16.2.1
*Mar 1 00:07:57.347: client protocol: 10.1.1.2
NHRPãªãã€ã¬ã¯ãã®åä¿¡ã匷調ããäžç·ä»ãã
3çªç®ã®ãã§ãŒãºãèŠçŽããã«ã¯ ïŒ
- CEFã«ç¡å¹ãªãšã³ããªã¯ãããŸããã ãã¹ãŠã®ãã±ããã¯CEFã䜿çšããNHRPèŠæ±ã¯CEFã®ç¡å¹ãªãšã³ããªã§ã¯ãªããNHSããã®æ瀺çãªæ瀺ã«ãã£ãŠåŒã³åºãããããã«ãªããŸããã
- NHSãNHRPæ å ±ã®å¯äžã®ãœãŒã¹ã§ã¯ãªããªããŸããã æ®ãã®NHCãé¢äžããŠããŸããã peer2peerã«äŒŒãŠããŸãã
- NHC NHRPå¿çã«ã¯ããã¯ã¹ããããã ãã§ãªããã¬ãã£ãã¯ã¹å šäœãå«ãŸããŸãã ãšããã§ãããã«ãããNHSããNHCãžã®äžè¬çãªã«ãŒããéä¿¡ã§ããŸãã å®å ã®NHCã¯ãããã«å±ãããã¬ãã£ãã¯ã¹ãè¿ããŸããããã¯ãNHSããæåã«åä¿¡ãããã¬ãã£ãã¯ã¹ããããã©ã€ããŒããªå ŽåããããŸãã
- åæãã±ããã¯ãããééããŸãã
- çãã¯NHSã§ã¯ãªãNHCã§ãããããããããžã«ã¯è€æ°ã®ã¬ãã«ã®ãããååšããå¯èœæ§ããããŸãã
次ã«ããã§ãŒãºã®ç¥èãåããã«ãŒãã£ã³ã°ãå°ãèŠçŽããŸã ã
ä»®å®1 ã NHCã¯ãNHSãšã®ã¿ã«ãŒãã£ã³ã°ãããã³ã«ãã€ããŒãããã確ç«ããNHCãšã¯æ±ºããŠç¢ºç«ããŸããã NHCã¯ãããŒã«ã«NHSãããã¯ãŒã¯ãçºè¡šããŸãã
ä»®å®2 ã NHSã¯ãã¹ãŠã®NHCãšè¿é£ã確ç«ããŸãã åæã«ã圌ã¯ä»ã®NHCãšåœŒã®ããŒã«ã«ãããã¯ãŒã¯ããåŠç¿ãããã¹ãŠã®ãããã¯ãŒã¯ã«ã€ããŠNHCã«éç¥ããŸãã
ããã«ããã§ãŒãºã«é¢ä¿ãªããRIPãšEIGRPã®ã¹ããªãããã©ã€ãºã³ããªãã«ããå¿ èŠããããŸãã
ãã ãããã§ãŒãºã«ãã£ãŠæ©èœã«éãããããŸãã
- ãã§ãŒãº1ããã³ãã§ãŒãº3ã§ã¯ãããã¯ã«ãŒãã£ã³ã°æ å ±ã«ãã¯ã¹ããããïŒããšãã°ãBGPãã¯ã¹ããããã»ã«ããOSPFãããã¯ãŒã¯ãã€ã³ãããŒãã«ããã€ã³ãïŒãæ ŒçŽã§ããŸãããããã«ãããèŠçŽãé©çšã§ããŸãã ããã«ãããã®æ°ã¯å¶éãããŠããããåãã¬ãã«ã§ããå¿ èŠã¯ãããŸããã
- å察ã«ããã§ãŒãº2ã§ã¯ãããã¯ã«ãŒãã£ã³ã°æ å ±ïŒEIGRP no ip next-hop-self ãBGPããã©ã«ããOSPFãããã¯ãŒã¯ãããŒããã£ã¹ãïŒã«ãã¯ã¹ãããããä¿åããå¿ èŠããããŸãã䜿çšã§ããããã¯2ã€ãŸã§ã§ãã
ä»®å®3 ã NHSã¯ãä»ã®NHSãšã®ã«ãŒãã£ã³ã°ãããã³ã«ãã€ããŒãããã確ç«ããŸãã åæã«
- ãã§ãŒãº1ããã³ãã§ãŒãº3ã§ã¯ãããéã®ã«ãŒãã£ã³ã°ãããã³ã«ã¯ããããšNHCéã®ã«ãŒãã£ã³ã°ãããã³ã«ãšç°ãªãå ŽåããããŸãã
- ãã§ãŒãº2ã§ã¯ãåããããã³ã«ã䜿çšããããã«ãããå¿ èŠã§ãã
-DMVPNã®åäœã®çè«çåºç€ãæ€èšŒããã®ã§ãCiscoã«ãŒã¿ã§DMVPNãèšå®ããæ¹æ³ã確èªããŸãã
èšå®ã¯ãç®çã®ãã§ãŒãºãšã«ãŒã¿ãŒã®åœ¹å²ïŒãããŸãã¯ã¹ããŒã¯ïŒã«ãã£ãŠç°ãªããŸãã
é çªã«ïŒ
ãã㯠ããã§ãŒãº1ãšãã§ãŒãº2ã®NHRPã§åãããã«æ§æãããŸããéãã¯ãã«ãŒãã£ã³ã°ãããã³ã«ã®æ§æã§ãã
ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ãäœæããã¢ãã¬ã¹ãå²ãåœãŠãŸãã
Hub(config)# interface Tunnel0
Hub(config-if)# ip address 10.1.1.1 255.255.255.0
ãœãŒã¹ã€ã³ã¿ãŒãã§ã€ã¹ãšã¢ãŒãã®å®çŸ©-GREãã«ããã€ã³ã
Hub(config-if)# tunnel source FastEthernet0/0
Hub(config-if)# tunnel mode gre multipoint
次ã«ãNHRPãããã³ã«èšå®ãå®éã«èšå®ããŸãã
ãããã¯ãŒã¯IDïŒ
Hub(config-if)# ip nhrp network-id 123
ãªãã·ã§ã³ã®èªèšŒïŒ
Hub(config-if)# ip nhrp authentication cisco
ãã«ããã£ã¹ãã¡ãŒãªã³ã°ã®åçã«èªèãããã¢ãã¬ã¹ãžã®ãããã³ã°ãæ§æããŸã
Hub(config-if)# ip nhrp map multicast dynamic
ãã§ãŒãº3ããã§ãŒãº2ãååšããå Žåã®ã¿ç°ãªã
Hub(config-if)# ip nhrp redirect
ã¹ããŒã¯
ãã§ãŒãº1ã
ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ãäœæããã¢ãã¬ã¹ãå²ãåœãŠãŸãã
Spoke1(config)# interface Tunnel0
Spoke1(config-if)# ip address 10.1.1.2 255.255.255.0
ãœãŒã¹ã€ã³ã¿ãŒãã§ã€ã¹ãå®çŸ©ãã
Spoke1(config-if)# tunnel source FastEthernet0/0
ãããšã®ã¿éä¿¡ããäºå®ã§ãããããå®å ã¢ãã¬ã¹ãšãã³ãã«ã®ã¿ã€ããæ瀺çã«èšå®ã§ããŸã-éåžžã®GRE IPïŒããã©ã«ãïŒ
Spoke1(config-if)# tunnel destination 172.16.1.1
ãªããªã ããã§ãNHRPã䜿çšããŠç»é²ããå¿ èŠãããå Žåã¯ããããã¯ãŒã¯èå¥åãèšå®ããŸãã
Spoke1(config-if)# ip nhrp network-id 123
ãªãã·ã§ã³ã®èªèšŒïŒ
Spoke1(config-if)# ip nhrp authentication cisco
ãããŠããã«ããã£ã¹ãã¡ãŒãªã³ã°ã®ããã¢ãã¬ã¹ãžã®ãããã³ã°ãæ§æããŸãïŒæ³šæããã³ãã«ã§ã¯ãªãå®éïŒ
Spoke1(config-if)# ip nhrp map multicast 172.16.1.1
NHSãã³ãã«ã¢ãã¬ã¹ãæå®ããŸãã
Spoke1(config-if)# ip nhrp nhs 10.1.1.1
ãããŠããã®ãã³ãã«ã¢ãã¬ã¹ã®ãããã³ã°ãå®éã®ã¢ãã¬ã¹ã«äœæããŸãã
Spoke1(config-if)# ip nhrp map 10.1.1.1 172.16.1.1
ãã§ãŒãº2ã
ã»ãŒåãããšã§ãããã³ãã«ã¢ãŒããèšå®ããã ãã§ããã³ãã«ã®å®å ãæå®ããªãã§ãã ããã
Spoke1(config)# interface Tunnel0
Spoke1(config-if)# ip address 10.1.1.2 255.255.255.0
Spoke1(config-if)# tunnel source FastEthernet0/0
Spoke1(config-if)# tunnel mode gre multipoint
Spoke1(config-if)# ip nhrp network-id 123
Spoke1(config-if)# ip nhrp authentication cisco
Spoke1(config-if)# ip nhrp map multicast 172.16.1.1
Spoke1(config-if)# ip nhrp nhs 10.1.1.1
Spoke1(config-if)# ip nhrp map 10.1.1.1 172.16.1.1
ãã§ãŒãº3ããã§ãŒãº2ãååšããå Žåã®ã¿ç°ãªã
Spoke1(config-if)# ip nhrp shortcut
Spoke1(config-if)# ip nhrp redirect
ããã§ãmGREãã»ããã¢ããããŸããã IPSecãæ¥ç¶ããããã«æ®ããŸãã èšå®ã¯ãã¹ãŠã®ã«ãŒã¿ãŒã§åãã§ãã
ISAKMPããªã·ãŒãäœæãã
Router(config)#crypto isakmp policy 10
Router(config-isakmp)# encr aes
Router(config-isakmp)# authentication pre-share
Router(config-isakmp)# group 2
説æãç°¡åã«ããããã«ãå ±æããŒèªèšŒã䜿çšããŸã
Router(config-isakmp)#crypto isakmp key cisco address 0.0.0.0 0.0.0.0
ããŒãã¢ã©ã€ãããªã³ã«ãã
Router(config)#crypto isakmp keepalive 10 3 periodic
ãã©ã³ã¹ãã©ãŒã ã»ãããäœæãã IPSecãããã¡ã€ã«ã«ãã€ã³ãããŸã ã
Router(config)#crypto ipsec transform-set IPSEC_SET esp-aes esp-sha-hmac
Router(cfg-crypto-trans)#crypto ipsec profile IPSEC_PROFILE
Router(ipsec-profile)# set transform-set IPSEC_SET
ãããã¡ã€ã«ããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã«ããã¿ã€ããŸã
Router(config)#interface tunnel 0
Router(config-if)#tunnel protection ipsec profile IPSEC_PROFILE
次ã«ã ã«ãŒãã£ã³ã°ãããã³ã«ã®èšå®ã«ã€ããŠèª¬æããŸã ã ç°¡åã«ããããã«ã2ã€ã®æãäžè¬çãªIGPã§ããOSPFãšEIGRPã«å¶éããŸããããã«ããããã®1ã€ã¯ãªã³ã¯ç¶æ ããã1ã€ã®è·é¢ãã¯ãã«ã§ãã
ãããã£ãŠããã§ã«ããã£ãŠããããã«ã ãã§ãŒãº1ããã³3ã§ã¯ã ãããã«ãŒãã£ã³ã°æ å ±ã®ãã¯ã¹ããããããã®ã¢ãã¬ã¹ã«å€æŽããå¿ èŠãããããã
OSPFïŒ
Hub(config-if)# ip ospf network point-to-multipoint
EIGRPã®å Žåã次ãããã¯ããã©ã«ãã§å€æŽãããè¿œå ã®äœæ¥ã¯å¿ èŠãããŸããã
ããã«ãEIGRPããã³RIPã®å Žåãã¹ããªãããã©ã€ãºã³ãç¡å¹ã«ããå¿ èŠããããŸã
Hub(config-if)#no ip split-horizon eigrp AS_NUMBER
ã¹ããŒã¯ã§ã¯ããã¹ãŠãåçŽã§ããOSPFãããã¯ãŒã¯ã®ã¿ã€ããèšå®ããã¹ããŒã¯ãDRãŸãã¯BDRã«ããããšã匷å¶çã«çŠæ¢ããŸãã
OSPFïŒ
Spoke(config-if)# ip ospf network point-to-multipoint
Spoke(config-if)# ip ospf priority 0
Spoke(config-if)# ip ospf network point-to-multipoint
Spoke(config-if)# ip ospf priority 0
ãã§ãŒãº2ã§ã¯ãå°ãç°ãªããŸãã
ããã§ã¯ããã¯ã¹ãããããå€æŽããå¿ èŠã¯ãªããªããŸããããã¹ããªãããã©ã€ãºã³ã¯äŸç¶ãšããŠæ°ã«ãªããŸãã ã ãã
OSPFïŒ
Hub(config-if)# ip ospf network broadcast
ïŒtimers to tasteïŒ
EIGRPïŒ
Hub(config-if)#no ip next-hop-self eigrp AS_NUMBER
Hub(config-if)#no ip split-horizon eigrp AS_NUMBER
Hub(config-if)#no ip next-hop-self eigrp AS_NUMBER
Hub(config-if)#no ip split-horizon eigrp AS_NUMBER
ã¹ããŒã¯ã§ã¯ ãOSPFãããã¯ãŒã¯ã¿ã€ãããããŒããã£ã¹ããšããŠèšå®ããŸããããã«è¿æ¥ããã ãã§ãããããã¹ããŒã¯ãDRãŸãã¯BDRã«ããããšã¯çŠæ¢ãããŠããŸãã
OSPFïŒ
Spoke(config-if)# ip ospf network broadcast
Spoke(config-if)# ip ospf priority 0
Spoke(config-if)# ip ospf network broadcast
Spoke(config-if)# ip ospf priority 0
æè¡ãèŠçŽããŸãã
- DMVPNã¯ãå€ãã®åå è ãšVPNãæ§ç¯ã§ãããã¯ãããžãŒã§ãã ã¡ã€ã³ããããžã¯ããã¢ã³ãã¹ããŒã¯ã§ãããåçãªã¹ããŒã¯ããŒã¹ããŒã¯ãã³ãã«ãããã«ã¯ããã®éå±€ãããå¯èœã§ãã
- ããã¯mGREã«åºã¥ããŠããïŒNHRPã«åºã¥ããŠããŸãïŒãä¿è·ã¯IPSecãšå¯æ¥ã«é¢ä¿ããŠãããIPSecã¯ãããšå¯æ¥ã«å¯Ÿè©±ããŸãã
- äžè¬ã«ãããã®è² è·ã¯ã¹ããŒã¯ããã倧ãããªããŸãã ããã«ãããç¹å®ã®ãã©ã³ãã®ããŒãºã«å¿ããŠãããã©ãŒãã³ã¹ãç°ãªãæ©åšã䜿çšã§ããŸãã
- äœæ¥ã®æ§è³ªã¯ãæ§æããããã§ãŒãºã«ãã£ãŠç°ãªããŸãã
- ã«ãŒãã£ã³ã°ãããã³ã«ã®æ§æã«ã泚æãå¿ èŠã§ãã
- æ¬ ç¹ã®äžã§ããã«ããã£ã¹ãã®ãµããŒããå¶éãããŠããããšãšãCisco ASAïŒsob ...ïŒã®ãµããŒããäžè¶³ããŠããããšã«æ³šæããŠãã ããã
ã·ã ã®ããã«ç§ã¯ç§ã®äŒæãåãããšãã§ããŸã:)ãã¡ãããåã³ãç§ã¯æè¡ã®ãã¹ãŠã®åŽé¢ãæããã«ããããšãæãã§ããŸããã å°ãªããšãèå°è£ã§ã¯ãå€ãã®ãããªã©ã®æ§æããããŸããã ããããç§ã¯æè¡ã®äžè¬çãªã¢ã€ãã¢ãæ瀺ã§ããããšãé¡ã£ãŠããŸãã
ç§ã¯ããããæ¹æ³ã§å»ºèšçãªæ¹å€ãæã¿ãŸãã èšäºã¯å€§èŠæš¡ã§ãããã»ãšãã©ã®å Žåãäžæ£ç¢ºããšã©ãŒãã¿ã€ããã¹ã§ãã£ã±ãã§ãã
Podkopaev Ilyaãã€ã³ã¹ãã©ã¯ã¿ãŒ
UPDã èŠã€ãã£ããšã©ãŒã®ã¯ã€ãã¯ã·ã¥ãŒã¿ãŒã«æè¬ããŸã:)