ã¿ãªããããã«ã¡ã¯ïŒ æåŸã«ãç§ã¯èšäºã«çŽæãããè¿œå ãè¡ãããšã«ã
ãŸãããMikroTikã®å
éšããã³å€éšéä¿¡ãã£ãã«ãéçã«ãŒãã£ã³ã°ãäŒæ¥ãããã¯ãŒã¯ã®äºçŽããã®èšäºã§ã¯ããããžã§ã¯ãã®å®è£
äžã«ç§ã®åã«çŸããããã€ãã®è¿œå ã¿ã¹ã¯ã®ãœãªã¥ãŒã·ã§ã³ãå
±æããããšæããŸãã ãã®ãããªã¿ã¹ã¯ã«ã¯ãåºèããåºèã«ç§»åããç£æ»éšéã®åŸæ¥å¡ã®ããã€ã¹çšã®ãªãã£ã¹å
ã®ãµãŒããŒãžã®ã¢ã¯ã»ã¹ã®ç·šæããããŸããïŒããŒã1ïŒã ãŸããOSPFåçã«ãŒãã£ã³ã°ãããã³ã«ã䜿çšããŠWi-Fiã·ã§ããã³ã°ããªã³ã¿ãŒããã£ããããæ¹æ³ã«ã€ããŠã説æããŸãïŒããŒã2ïŒã
åãšåãããã«ããã®è§£æ±ºçã誰ããŸãã¯æ°èŠåå
¥è
ãåæ§ã®åé¡ã解決ããã®ã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã ç§ã¯å°é家ããã®æ¹å€ã«åãã§ããã§ãããã

èŠåºãã«èå³ããã人-ã«ããããé¡ãããŸãïŒ
ããŒã0.æäŸããããã®
åã®èšäºã§è¡ãããããšãç°¡åã«æãåºãããŠãã ããã çµç¹ã¯ç§ã«é ŒããŸãã-äºçŽã®å¯èœæ§ãšéãããäºç®ã§ã»ã°ã¡ã³ãåããããããã¯ãŒã¯ãçµç¹ããããšãèŠæ±ããå°å£²åºã®ãããã¯ãŒã¯ã
ç§ã®ä»äºã¯ãéœåžå
šäœã«å°ççã«åæ£ãããã©ãããããã¯ãŒã¯ãäœæããããšã§ããéå±€åãããã¢ãã¬ãã·ã³ã°ãåããã»ã°ã¡ã³ãåããããããã¯ãŒã¯ã§ãããæãéèŠãªã®ã¯åé·æ§ã®å¯èœæ§ã§ãã
åžå
ã®ãã¹ãŠã®åºèéã®æ¥ç¶ã¯ãããŒã«ã«ISPã«ãã£ãŠçµç¹åããããããã¯ãŒã¯å
ã«å¥åã®VLANãäŒç€Ÿã«æäŸããŸãã ãããã£ãŠããã¹ãŠã®åºèãšãªãã£ã¹ã®ãããã¯ãŒã¯å
šäœã1ã€ã®å€§ããª
Layer2 Broadcastãã¡ã€ã³ã«å±ããŠããŸãã ã
ãã®ã¢ãã«ã«ã¯ããã€ãã®æ¬ ç¹ããããŸãã
- ãããã¯ãŒã¯äžã®ãã¹ãŠã®ããã€ã¹ã¯ãã¬ã€ã€ãŒ2ã§ãäºããèŠãããšãã§ããŸãã
- ãã©ãã£ãã¯ãã£ã«ã¿ãªã³ã°ããªã·ãŒã®æ¬ åŠã
- åäžã®ãããŒããã£ã¹ããã¡ã€ã³ããã®çµæã400åã®ããã€ã¹ã®ããããããã®ãããŒããã£ã¹ããã±ããã¯ãéœåžã®ããŸããŸãªéšåã«ãããããã®400åã®ããã€ã¹ãã¹ãŠã«å¿
ã転éãããŸãã
ãµãŒããŒã®ç°¡æœã§åçŽåãããã¬ã€ã¢ãŠããã以äžã®å³1ã«ç€ºããŸãã

ãããŠãç§ãã¡ãæã£ãŠãããã®ã®ç°¡åãªèª¬æïŒ
- äŒç€Ÿã«ã¯ãããŸããŸãªåœ¹å²ãå®è¡ããããŸããŸãªãµãŒããŒããããŸãã
- ç¹å¥ãªããŒã¿åé端æ«ïŒ TSD ïŒããããå³ã§ã¯ããããã¿ãã¬ãããšåŒãã§ããŸãã
- ç¹å®ã®ã¹ãã¢ã«çµã³ä»ããããå¶éãè¶
ããŠããªãåºå® TSDããããŸãã ãããã¯ãã¹ãã¢å
ã®ããã€ã¹ããŒã«ããã®IPã¢ãã¬ã¹ãæã£ãŠããŸãã
- ãªããžã§ã³ TSDãšããããã察話ããå¥ã®ãªããžã§ã³ãµãŒããŒããããŸãã ãããã®TSDã¯ãç£æ»ãå®è¡ããã¹ãã¢ããã¹ãã¢ã«åžžã«ç§»è¡ããŸãã
ããŒã1.ããšã©ãŒãçºçããŸããããããã§ä¿®æ£ããŸãã
ãããã¯ãŒã¯ãžã®Mikrotikã«ãŒã¿ãŒã®å°å
¥åŸãæåã®åºèã§ã¯
ãåãæ¥ã«ããã§ç£æ»ãè¡ãããŸãã
ç£æ»éšéã®ä»äºã®çµç¹ã¯éåžžã«èå³æ·±ããç¬ç¹ã§ãã ãã¹ãŠã®ã¹ãã¢ã«ã¯ãåãSSIDãšæå·åããŒãæã€Wi-Fiã¢ã¯ã»ã¹ãã€ã³ãããããŸãã ãããã£ãŠããªããžã§ã³TSDã«ã¯ç¬èªã®ããŒã«ïŒ192.168.3.0/24ïŒããã®éçIPã¢ãã¬ã¹ããããŸãã
ãããã¯ãŒã¯ã¯åœåãã©ããã ã£ããããããããã®ã¹ãã¢ã«ã¢ã¯ã»ã¹ãããªããžã§ã³TSDã¯ãã¹ãŠåäžã®ãã©ãããããã¯ãŒã¯ã«ãªããåé¡ãªãã©ãã«ã§ããããªããžã§ã³ãµãŒããŒã«æ¥ç¶ãããŸããã
ãªããžã§ã³ãµãŒããŒã¯ãç¹å¥ãªããŒã¿ããŒã¹ãåããRDPãµãŒããŒã§ããã ããã¯ãæ¹èšåã«ã¡ã€ã³ããŒã¿ããŒã¹ãµãŒããŒãšåæãããŠããŸããã ãªããžã§ã³ãµãŒããŒã¯ãã¹ãã¬ãŒãžãµãŒããŒããäœæ¥ã«å¿
èŠãªãã¡ã€ã«ãããŒãããŸããã äž»ã«ç£æ»ãµãŒããŒãšã®ã¿å¯Ÿè©±ããããŒã¿åé端æ«ïŒTSD-ã¿ãã¬ããïŒã ãã ãã極端ãªå Žåããªããžã§ã³ãµãŒããŒã§äœãåé¡ãçºçãããšããªãã£ã¹ã«ããRDPãµãŒããŒãšçŽæ¥ããåãããããšããããŸããã ä»ã®ãã¹ãŠã®TSDïŒã¹ãã¢ã«åžžæé
眮ããããããã«é¢é£ä»ããããŠããïŒã¯ãã¡ã€ã³RDPãµãŒããŒãšã®ã¿å¯Ÿè©±ããŸããã
ã ãããããã¯æ確ã§ã·ã³ãã«ãªããã§ãã å®æçã«åºèããåºèãžãšç§»åããåºèã®åŸæ¥å¡ã«ãšã£ãŠæãããããšãå®è¡ããããã€ã¹ã®ã¢ãã€ã«ã°ã«ãŒãããããŸã-ç£æ»ã
圌女ã¯ãã¹ãã¢å
ã®ããŒã«ããåçã«IPãååŸãããªãã£ã¹ã«ãããªããžã§ã³ãµãŒããŒã«æ¥ç¶ãããã極端ãªå Žåã¯ã¡ã€ã³RDPãµãŒããŒã«æ¥ç¶ããã ãã§ããããããå°å
ã®ã·ã¹ãã 管çè
ãç§ã«èšã£ãããã«ãäŒç€Ÿãé·å¹Žã«ããã£ãŠååšããŠãããããç£æ»äžã«ããŸããŸãªã±ãŒã¹ããããŸããã ãã®1ã€ã¯
ãåºèãšæ¬ç€Ÿã®éã®éä¿¡ã®æå³çãªéåã§ãã ãç£æ»ã¯å€±æããŸããã
ãã®ããã
æŽå²çã«ã¯ãç£æ»ãµãŒããŒã¯ã·ã§ããã³ã°ãªãã£ã¹ããTSDãšãšãã«ç§»åããŠããŸãã ã ããã¯éåžžãç£æ»æ¥ã®åæ¥ã®å€ã«çºçããŸããã 管çè
ã¯ãµãŒããŒãã¹ãã¢ã«æã¡èŸŒã¿ãã¹ãã¢å
ã®ä»»æã®ã¹ã€ããã§äœ¿çšå¯èœãªããŒãã«æ¥ç¶ããŸãïŒãããã¯ãŒã¯ããã©ããã§ããããã¹ãŠã®ããŒããåäžã®L2ãã¡ã€ã³ã«ãã£ãŠæ¥ç¶ãããŠããããšãæãåºããŠãã ããïŒã 圌ã¯TSDãæ
åœããç«ã¡å»ããŸãã
ããã«ãå€éãã¹ã±ãžã¥ãŒã«ã«åŸã£ãŠãç£æ»ãµãŒããŒã¯æ¬ç€Ÿã«ããä»ã®ãµãŒããŒã«æ¥ç¶ããããŸããŸãªåæãšããŒã¿è€è£œãå®è¡ããŸãã
æ¥ç¶ãµãŒããŒã¯åžžã«æ¹èšãµãŒããŒã§ããããšã«æ³šæããããšãéèŠã§ããæåã®ã¹ãã¢ã§ã®åæ£ã»ã°ã¡ã³ããããã¯ãŒã¯ã®å°å
¥ã«æ»ããŸãã ããã«ã«ãŒã¿ãŒãèšçœ®ãããŸããããã«ãããL2ã»ã°ã¡ã³ããäžè¬ãªãã£ã¹ããåé¢ããããããã€ããŒã®éä¿¡ãã£ãã«ã«åé·æ§ãæäŸãããŸãã
ã¹ãã¢ã§äœãå€æŽãããããæ確ã«ããããã«ãåã®èšäºã®ç»åããèŠãããŸãããã

å³ãããã¹ãã¢ã«ã€ã³ã¹ããŒã«ãããã«ãŒã¿ãŒãããã€ã¹ã®ãªããžã§ã³ã°ã«ãŒãã®ã¢ããªãã£ã奪ã£ãŠããããšãæããã§ãã
ã«ãŒã¿ãŒã®å°å
¥åŸãåºèã§ã®ã¢ãã¬ã¹æå®ãã©ã®ããã«ãªãããæãåºãããŠãã ããã
- 192.168.1.0/24-ã»ã³ãã©ã«ãªãã£ã¹ãããã¯ãŒã¯
- 192.168.2.0/24-12åºèããããã®192.168.13.0/24ããŒã«ã«ãããã¯ãŒã¯
- 10.10.10.0/24-ã¡ã€ã³ã€ãŒãµããããã£ãã«ãä»ããŠã¡ã€ã³ãªãã£ã¹ã«å°çãããããã¯ãŒã¯
- 10.10.20.0/24-ããã¯ã¢ãããã£ãã«ïŒPONïŒãä»ããŠæ¬ç€Ÿã«å°çãããããã¯ãŒã¯
- 10.20.30.0/24-VPNå
ã®ãããã¯ãŒã¯ãå€éšãããã¯ãŒã¯ãä»ããŠISP-1ããIPã«åºå·ããåºèçš
- 10.30.40.0/24-VPNå
ã®ãããã¯ãŒã¯ãå€éšãããã¯ãŒã¯ãä»ããŠISP-2ããIPã«åºå·ããåºèçš
ããã§ãç¹å®ã®ã¹ãã¢ã«å°çãããšã以åã®ããã«ãªããžã§ã³ãµãŒããŒãã¹ã€ããã®ç©ºãããŒãã«æ¥ç¶ããTSDã¯Wi-Fiã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããŸãã ãã®åŸã
TSDã¯å°ççã«å°ççã«åãã¹ãã¢ã«ããç£æ»ãµãŒããŒãšèªç±ã«éä¿¡ ã§ããŸããããªãã£ã¹ã®ã¡ã€ã³RDPãµãŒããŒã«æ¥ç¶ããããšã¯ã§ããŸããã ãŸããç£æ»ãµãŒããŒèªäœã¯äžåšã®ãããããŒã¿ãåæã§ããŸããããªããªããããã¯æåã®ç¿»èš³å¯èœãªã¹ãã¢ã§ããããããã¯ãŒã¯å
šäœãæ°ããåäœã¢ãŒãã«å®å
šã«ç§»è¡ãããããã§ã¯ãªãããã§ãã ç£æ»ããŒã ã®äœæ¥ã¹ã±ãžã¥ãŒã«ã¯ãã§ã«ã¹ã±ãžã¥ãŒã«ãããŠããŸããä»æ¥ã¯åœŒããããã«ããŠãææ¥ã¯å¥ã®åºã«ããããŠåã³ããã«ããªã©ã
ç£æ»ããŒã ïŒIPã¢ãã¬ã¹ã®ç¯å²ã¯éçïŒ192.168.3.0/24ïŒã®æ¥ç¶ã確ä¿ããããã®ç·æ¥ã®ãœãªã¥ãŒã·ã§ã³ãå¿
èŠã§ãã
ãã§ã«äžã§è¿°ã¹ãããã«ããã®ã¹ããŒã
ã§ã¯ãåæã€ãã·ãšãŒã¿ãŒã¯ãªããžã§ã³ãµãŒããŒèªäœã§ããä»ã®ãµãŒããŒã«æ¥ç¶ããå¿
èŠãªã¿ã¹ã¯ãå®è¡ããŸãã ãªããžã§ã³TSDã¯
ãå¿
èŠã«å¿ããŠããªãã£ã¹ã®ã¡ã€ã³RDPãµãŒããŒãšã®
RDPã»ãã·ã§ã³ã®ã€ãã·ãšãŒã¿ãŒã§ããããŸãã
ç§ã®ä»äºã¯
ããªãã£ã¹ãæã€åºèã®ããããã«ããã¢ãã€ã«ããã€ã¹ã®IPæ¥ç¶ã
ä¿èšŒããããšã§ãã åæã«ãããã€ã¹ã®ã¢ãã¬ã¹æå®ã¯å€æŽãããŸããã
ç¹å®ã®ã¹ãã¢ã§DHCPã¢ãã¬ã¹ãååŸãããªãã·ã§ã³ã¯ãããŸããããããã£ãŠãäžæçãªãã®ãšããŠïŒãããŠããã«äžå®ã®ãŸãŸã§ããããã«ïŒç§ã®é ã«æµ®ããã æåã®è§£æ±ºçã¯ã
NATã®å®è£
ã§ã
ãã·ã¹ãã 管çè
ã«èª¬æããŸããããç£æ»éšéã®åŸæ¥å¡ã«ããTSD以å€ã®ããã€ã¹ãç£æ»ãµãŒããŒã«æ¥ç¶ããå¿
èŠããªãã®ã¯æ¬åœã§ããïŒ çãã¯ããŒã§ããã 確ãã«ã
RDPãä»ããŠããã°ã©ããŒã«ãªã¢ãŒãã§æ¥ç¶ããå¿
èŠãããå ŽåããããŸã ã ãã ããã¹ãã¢å
ã®PCãããããã1ã€ã«æ¥ç¶ããããšã§ãããè¡ãããšãã§ããŸããPCããæ¢ã«ãµãŒããŒã«æ¥ç¶ããŠããŸãã ãã¡ãããã¹ãã¢å
ã®PCããµãŒããŒãèŠãããšãã§ããå Žåãé€ããŸãã
ããã§ã¯ãã¿ã¹ã¯ã«åãããããŸãããã
ãŸãã管çè
ã«ãã¹ãŠã®ãªããžã§ã³TSDãã€ã³ã¹ããŒã«ãããµãŒããŒã«ã¡ã€ã³ã²ãŒããŠã§ã€ã®ã¢ãã¬ã¹
192.168.3.2ãã€ã³ã¹ããŒã«ããããã«äŸé ŒããŸãã
ã¹ãã¢ã«ããã«ãŒã¿ãŒã§ãã¹ãã¢ã«åãã£ãŠããã€ã³ã¿ãŒãã§ã€ã¹ã«æ¬¡ã®IPã¢ãã¬ã¹ãè¿œå ããŸãã
[s@VERTOLET-GW] > ip address export
ãããã£ãŠããã®æ¹èšãããã¯ãŒã¯ïŒ192.168.3.0/24ïŒã¯
絶察ã«ãã¹ãŠã®åºèã«è¿œå ãã
ãŸã ãããã«ããã
åºèéã移åãã
ãšãã«ããã€ã¹ã®ã¢ãã€ã«ã°ã«ãŒãã
èšå®ãåæ§æããã«ãåºèã®
ã«ãŒã¿ãŒãåç
§ã㊠ãããã€ã¹ããªãã£ã¹å
ã®ã©ãã«ããããç¥ãããšãã§ããŸãã
ããããåãã¢ãã¬ã¹ãæã€12ã®ã¹ãã¢ãããå Žåããªãã£ã¹ã®ãµãŒããŒã¯ãã±ããã®éä¿¡å
ãã©ã®ããã«ç¥ãã®ã§ããããïŒ
ããã§ã
NATã¯ç§ãã¡ã®å©ãã«ãªããŸãããã®ç®çã¯ãã¢ãã€ã«ã°ã«ãŒããé£çµ¡ããIPã¢ãã¬ã¹ãå€æŽããããšã§ãã
ãããè¡ãã«ã¯ãã©ã®ãµãŒããŒãã¢ãã€ã«ã°ã«ãŒãã®ããã€ã¹ã«ã¢ã¯ã»ã¹ããå¿
èŠãããããèŠã€ãããããã®ããã€ã¹çšã«åå¥ã®ã¢ãã¬ã¹ãªã¹ããäœæããŸãã
[s@VERTOLET-GW] > ip firewall address-list export
次ã«ã
NATå€æã®ã«ãŒã«ãäœæããŠãã¢ãã€ã«ã°ã«ãŒãã®é£çµ¡å
ã®ã¢ãã¬ã¹ãé衚瀺ã«ããŸãã
[s@VERTOLET-GW] > ip firewall nat export
ãã®NATã«ãŒã«ã¯ããªãã£ã¹å
ã®å¿
èŠãªãµãŒããŒã«ã¢ã¯ã»ã¹ãããšãã«ãéä¿¡å
ã¢ãã¬ã¹ïŒ192.168.3.0ïŒãäžç¶ãããã¯ãŒã¯ã®ã«ãŒã¿ãŒã®ã¢ãã¬ã¹ïŒ10.0.0.0/8ïŒã«å€æŽããŸãã
ãã®ãããåé¡ã¯ãã§ã«éšåçã«è§£æ±ºãããŠããŸãã ã¢ãã€ã«ã°ã«ãŒãã¯ä»»æã®åºèã«èªç±ã«æ¥ãŠãæ¢è£œã®ã²ãŒããŠã§ã€ãåŸ
æ©ããŠãããããã¯ãŒã¯ã«æ¥ç¶ããäžå€®ãªãã£ã¹ãžã®æ¥ç¶ãéå§ã§ããŸãã
ãœãªã¥ãŒã·ã§ã³ãå®è£
ããæåã®æ¥ã«çŽé¢ãããã®åé¡
ãæãåºãããŠãã ããã
ãããã¯ãŒã¯å
šäœãå€æŽã®æºåãã§ã㊠ããªãã£ãããã
ãµãŒããŒãã¹ãã¢éã®ã¢ãã¬ã¹æå®ã«ã€ããŠäœãç¥ããªãã£ããšããç¶æ³ããããŸããã ãŸããKerioãµãŒããŒã¯ã翻蚳ãããã¹ãã¢ã®ãããã¯ãŒã¯ãžã®ã«ãŒããããªãã£ã¹å
ã®ç¬ç«ããæ§ãããªMikrotikã«ãŒã¿ãŒã«éçã«ç»é²ãããããããã®ã²ãŒããŠã§ã€ã§ããã
åŸã«ã¡ã€ã³ã«ãŒã¿ãŒã«ãªãããšã§ããã
ããã¯ããªãã£ã¹ã§ïŒã¢ãã€ã«ã°ã«ãŒãã«ãã£ãŠã¢ã¯ã»ã¹ãããïŒãµãŒããŒããäžç¶ãããã¯ãŒã¯ïŒ10.0.0.0/8ïŒãé ãããã«å¥ã®
NATå€æãè¡ãå¿
èŠãããããšãæå³ããŸãã
ã¹ãã¢ãšåãããã«ãã¢ãã¬ã¹ãªã¹ããè¿œå ããŸã
[s@MAIN-BORDER-ROUTER] > ip firewall address-list export
ãŸãã翻蚳ã«ãŒã«ïŒ
[s@MAIN-BORDER-ROUTER] > ip firewall nat export
ã芧ã®ãšããããã®ãœãªã¥ãŒã·ã§ã³ã«ååãä»ããèãããªãã£ãããããã®ã«ãŒã«-æŸèæã«æ£çŽã«çœ²åããå¿
èŠããããŸããã
ãã®æ®µéã§ãã¢ãã€ã«ããã€ã¹ã°ã«ãŒããšä»»æã®ã¹ãã¢ãããªãã£ã¹å
ã®ãµãŒããŒãšã®æ¥ç¶ã確ä¿ããã¿ã¹ã¯ãå®äºããŸããã
ããã°ã©ããŒã®ç£æ»ãµãŒããŒãžã®ãªã¢ãŒãã¢ã¯ã»ã¹ã¯ãå¿
èŠã«å¿ããŠãåºèã®ã«ãŒã¿ãŒãä»ããŠãããã¯ãŒã¯192.168.3.0/24ã«ã¢ã¯ã»ã¹ããåºèå
ã®ä»»æã®PCã«æ¥ç¶ãããã®ãããã¯ãŒã¯ã
çŽæ¥æ¥ç¶ããããããã¯ãŒã¯ãšããŠèªèããŠååŸã§ããŸãã
ããŒã2. Wi-Fiããªã³ã¿ãŒãå€æã®å°å·ãæåŠããŸãïŒ
æåã®ã¹ãã¢ã«ãããã¯ãŒã¯ãå°å
¥ãããæåŸã®ã¹ãã¢ããã®ã¹ããŒã ã«ç§»è¡ãããŠããçŽ3é±éãçµéããŸããã ãã®æç¹ã§ã軜埮ãªæ¬ ç¹ãè¡šé¢åããæ¥ãã§ä¿®æ£ãããŸããã äžè¬ã«ãèšç»éãã«ãã¹ãŠãããŸããããŸããã é¢çœãã®ã¯ãæåã®åºèãæ°ããæäœã¢ãŒãã«åãæ¿ããåŸãISPãäºæ
ãèµ·ãããŠãã®åºèãéä¿¡ã§ãããã·ã¹ãã ãå®å
šã«åäœããŠäºåã«åãæ¿ããããšã§ãã
æåŸã®åºèã§ã®å°å
¥ãè¡ããããšããã·ã¹ãã 管çè
ã¯ãçµå¶è
ã解決ããå¿
èŠãããã¿ã¹ã¯ãšããŠæ瀺ããå¥ã®ãã¥ã¢ã³ã¹ã«ã€ããŠäžç¢ºå®æ§ãæã£ãŠç§ã«èšã£ãã
ã¢ãã€ã«ã°ã«ãŒã
ã«ã¯ãå¥ã®åºèã«è¡ã
ç¯å²ïŒ192.168.3.0/24 ïŒã®
TSDãæã€å¥ã®åŸæ¥å¡ãããŸããã圌ã®ã¿ã¹ã¯ã¯ãæå¹æéãåããååãåè©äŸ¡ããããšã§ãã
TSDããã圌
ã¯ãªãã£ã¹ã«ããã¡ã€ã³RDPãµãŒããŒã«æ¥ç¶ããããŒã¿ããŒã¹ãæäœããŸãã 補åãã¹ãã£ã³ããæ°ããå€æãå°å·ããŸãã
ãã¹ãŠãé 調ã§ãåŸæ¥å¡ã¯éãã«1ã€ãŸãã¯å¥ã®åºã«æ¥ãŠã以åã®ããã«Wi-Fiãããã¯ãŒã¯ã«ããã¿ã€ããåé¡ãªããªãã£ã¹ã®RDPãµãŒããŒã«æ¥ç¶ããå¿
èŠãªããšãè¡ããããªã³ã¿ãŒãžã®å°å·ãéå§ã
ãŸãããå€æãå°å·ãããŠããããªã³ã¿ãŒã¢ãã€ã«ïŒ 以åã¯192.168.1.0/24ã®ç¯å²ã®IPã¢ãã¬ã¹ãæã¡ãåäžã®L2ãæã€ãã©ãããããã¯ãŒã¯ã§ã¯ãã©ã®ã¹ãã¢ãããå©çšã§ããŸããããŸãããªãã£ã¹ããæ¹èšãµãŒããŒã«æ¥ç¶ãããšããæ¹èšãè¡ãããåºèã®ã³ã³ãã¥ãŒã¿ãŒã®1ã€ããæ¹èšãµãŒããŒãNATã®èåŸã«ãããšããäºå®ã®ããã«ããã°ã©ããŒã«ãã£ãŠå æãããããã«ã¢ã¯ã»ã¹ããã«ã¯ãåºã
äžè¬ã«ãæ°ããã¿ã¹ã¯ãèšå®ãããŠããŸãã
- ãªãã£ã¹ããã¢ãã€ã«ããªã³ã¿ãŒã«å°å·ããæ©èœãæäŸãã
- ãªãã£ã¹ããçŽæ¥RDPçµç±ã§ç£æ»ãµãŒããŒã«æ¥ç¶ããæ©èœãæäŸãã
ããŠãä»ãç§ãã¡ã¯ãåçã«ãŒãã£ã³ã°ãããã³ã«ã®å°å
¥ããæ¥ãŸããããããããåºãŠããªãã§ãæåã®éšåã«æ®ãããšã«ããŸããã
OSPFãžããããïŒããã§ãæåã®èšäºã§æžããããã«ã
OSPFãã±ãããISP-1ãããã¯ãŒã¯ãééããªãã£ããããçå®ã¯åã³å¥ã®æŸèæãäœããªããã°ãªã
ãŸããã§ãã ã CPEïŒHuaweiã®xPON端æ«ïŒã
åã«ãããã³ã«89ãããããããããããã«ããã£ã¹ãã§ããŠããã£ã¹ãã§ããããŸããã
ãã®ãããäž»ã«åé·æ§ãç®çãšãããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã«OSPFãå®è£
ããããšã«ããŸããã
ãã®ç¶æ³ã§ã®OSPFã¯ã次ã®2ã€ã®ããšã«å¿
èŠã§ãã
- å°å·çšã®å°ããªãã¡ã€ã«ã転éããããã«ããªãã£ã¹ã®ã«ãŒã¿ãŒã«Wi-Fiããªã³ã¿ãŒãæ¢ãå Žæãåçã«æå®ããŸã
- ãªããžã§ã³ãµãŒããŒãæ¢ãå Žæããªãã£ã¹ã®ã«ãŒã¿ãŒã«åçã«ç€ºããããã«RDPå¶åŸ¡ã³ãã³ããéä¿¡ããŸãïŒãªããžã§ã³ãµãŒããŒãããªãã£ã¹ãžã®ãªã¿ãŒã³ãã©ãã£ãã¯ã¯ãæåã®èšäºã§æå³ãããšããã«ãªããŸãïŒ
OSPFãä»ããŠã¢ãã€ã«ã°ã«ãŒãïŒ192.168.3.0/24ïŒã®ãããã¯ãŒã¯å
šäœãéä¿¡ããå¿
èŠã¯ãããŸãããããã«ããããè¡ãããšã¯ã§ããŸããã åè©äŸ¡æ
åœè
ãšç£æ»ããŒã ã¯ç°ãªãå Žæã«ããããšãå€ããåãšWi-Fiããªã³ã¿ãŒãåæã«æ¥ç¶ããå¿
èŠããããŸãã
ãããã£ãŠããã®åé¡ã«å¯Ÿããæãæé©ãªè§£æ±ºçã¯ã
ããå
·äœçãªã¢ãã¬ã¹/ 32ãããã2ã€ã®ããã€ã¹ïŒããªã³ã¿ãŒãšãµãŒããŒïŒã«è»¢éããããšã§ãããšå€æããŸããã
ãããè¡ãã«ã¯ããªããOSPFæ©èœã®æ¬¡ã®ããŒã«ãå¿
èŠã§ãã
- ãã€ã³ãããŒãã€ã³ããããã¯ãŒã¯ã¿ã€ã
- éçã«ãŒãã®åé
åž
- ãã£ã«ã¿ãªã³ã°
æåã«ãåºèãããªãã£ã¹ã«Wi-Fiããªã³ã¿ãŒãšãµãŒããŒã«é¢ããæ
å ±ã転éããæ¹æ³ã®ã¢ã«ãŽãªãºã ã決å®ããŸãã
ãã®ãããOSPFã¯ããããã®ãããã¯ãŒã¯ããã®ã«ãŒã¿ãŒã«æ¥ç¶ãããŠããããšãããã³ãããã®ã«ãŒããäžå€®ã«ãŒã¿ãŒã«ã¢ããã¿ã€ãºãããå¿
èŠãããããšãèªèããŠããå¿
èŠããããŸãã
OSPFã¯ã2ã€ã®æ¹æ³ã§ãããã¯ãŒã¯ãã¢ããŠã³ã¹ããŸãã
- ãã®ã€ã³ã¿ãŒãã§ã€ã¹ãããã·ãã§ãªãå ŽåãOSPFãæå¹ã«ãªã£ãŠããã€ã³ã¿ãŒãã§ã€ã¹ã«å±ãããã¹ãŠã®ãããã¯ãŒã¯ãã¢ããŠã³ã¹ããŸãã
- ä»ã®åçã«ãŒãã£ã³ã°ãããã³ã«ãçŽæ¥æ¥ç¶ãããã«ãŒããéçã«ãŒãã®åé
åžã«ãããããã¯ãŒã¯ã¢ããŠã³ã¹
ã ãããç§ã¯æ¬¡ã®ããšãããããšã«ããŸããïŒ
- ãã¹ãŠã®ã¹ãã¢ãšäžå€®ã«ãŒã¿ãŒã§OSPFããã»ã¹ãèµ·åãã
- ãã¹ãŠã®ã¹ãã¢ã®ãµãŒããŒããã³ããªã³ã¿ãŒçšã«éçã«ãŒã/ 32ãäœæããŸã
- åé
åžäžããã³OSPFã§ã®äžèŠãª xéçã«ãŒãïŒããã³å€æ°ããïŒã®ãã£ã«ã¿ãªã³ã°
- NetWatchã 䜿çšããŠãç¹å®ã®ã¹ãã¢å
ã®ããã€ã¹ã®å®éã®å¯çšæ§ã远跡ããéçã«ãŒãã管çããŸãã
ãã¹ãŠãæãããªããã§ãå®è£
ã«é²ã¿ãŸãã
åºèããã³ãªãã£ã¹ã®ã«ãŒã¿ãŒã§
OSPFããã»ã¹ãèµ·åããŸãã
ãã¹ãŠã®åºèã¯1ã€ã®
ããã©ã«ããšãªã¢0ã«ãããŸãã
OSPFã«ãŒã¿ãŒéã®è¿é£ç¶æ
ã¯ããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã§çºç
ããŸã ãååºèãšãªãã£ã¹ã®éã«ã¯2ã€ãããŸãã
Mikrotikã«ãŒã¿ãŒã§ã¯ãããã©ã«ãã§
ãã€ã³ãããŒãã€ã³ãã€ã³ã¿ãŒãã§ã€ã¹ã®ã³ã¹ãã¯
-10ã§ãã ååºèãšãªãã£ã¹ã®éã«2ã€ã®VPNãã£ãã«ããããã
ããã£ãã«2ã®ã³ã¹ãã
20ã«èšå®ããŸãã
[s@KREDO-MAIN-BORDER-ROUTER] > routing ospf export
åºèå
ã®ã«ãŒã¿ãŒã§åæ§ã®ã¢ã¯ã·ã§ã³ãå®è¡ããããã«éçã«ãŒããåé
åžããå¿
èŠæ§ãææãããããã
ã¿ã€ã1ãšããŠã¢ããŠã³ã¹ããããšã«ããŸããã
[s@KREDO-VERTOLET-GW] > routing ospf export
æå®ãããæ§æã«ã¯ã
ã¿ã€ã1ãªã©
ã®éçã«ãŒãã®
åé
åžãæ
åœããã³ãã³ããå«ãŸãããã®ã¿ã€ãã¯
ã¿ã€ã2ãããåªå
床ãé«ã
ãã«ãŒã¿ãŒéã§ã¢ããã¿ã€ãºããããšã¡ããªãã¯ãå€åããŸã ã ãŸãã
OSPFèšå®ã§2ã€ã®ãã£ã«ã¿ãŒãæå®ããŸããïŒ
ospf-inããã³ospf-out ã
Mikrotikã®ãããã®ãã£ã«ã¿ãŒã¯ã
Ciscoã«ãŒã¿ãŒã®
ã«ãŒããããã«äŒŒã圹å²ãæãããŸã
ããããã®ãã£ã«ã¿ãŒãæ€èšããããšãææ¡ããŸãã
[s@VERTOLET-GW] routing filter export
ospf-inãã£ã«ã¿ãŒã¯ã
OSPFãçµç±ããŠã«ãŒã¿ãŒã«
å°éããå¯èœæ§ã®ããã«ãŒãããã£ã«ã¿ãªã³ã°ããŸãã
ospf-outãã£ã«ã¿ãŒã¯ããµãŒããŒããã³Wi-Fiããªã³ã¿ãŒçšã®
ããå
·äœçãª/ 32ã«ãŒããé€ããåé
åžãéããŠã¢ããã¿ã€ãºã§ãããã¹ãŠã®å¯èœãªã«ãŒãããã£ã«ã¿ãŒã§
é€å€ããŸãã
çŸåšãã¢ãã€ã«ããã€ã¹çšã«
éç/ 32ã«ãŒããè¿œå ããå¿
èŠããããŸããããã®å Žæã«æ³šæããå¿
èŠããããŸãã
[s@VERTOLET-GW] > ip route export
disabled = yesãã©ã¡ãŒã¿ãŒã
䜿çšããŠãããã®éçã«ãŒããè¿œå ããŠããããšã«æ³šæããŠãã ãããã€ãŸãã
ãããã®ã«ãŒãã¯ãªãã«ãªããã¢ã¯ã»ã¹ã§ããªããªããŸãã
ã€ãŸãã OSPF ãéããŠã¢ããŠã³ã¹ãããŸãã ã
ãªãã§ïŒ ãªããªãããã¹ãŠã®ã¹ãã¢ã«ã¢ã¯ãã£ãã«ãŒããäžåºŠã«è¿œå ãããšãã¡ã€ã³ã«ãŒã¿ãŒäžã§ãããããã¹ãŠã®ã¹ãã¢ããèŠããããã«ãªããå
ã®ã«ãŒãã«æ»ãããã§ãã
Wi-Fiããªã³ã¿ãŒãã©ãã§ãã£ããããã®ãå
·äœçã«ããããªãå Žåã¯ã ãããã®ã«ãŒãã¯ãã¹ãŠã®åºèã«ååšããŸãã
ãããã£ãŠã
éçã«ãŒãã¯ããã©ã«ãã§
ãªãã«ãªã£ãŠ ãããããã€ã¹ãç¹å®ã®ã¹ãã¢ã«å®éã«è¡šç€ºããããŸã§èª°
ãéçã«ãŒãã«ã€ããŠè©±ããŸãã
ãpingãä»ããããã€ã¹ã®å¯çšæ§ã«ãã£ãŠãããç解ã§ãããããåçŽãªã¹ã¯ãªããã䜿çšããŠ2ã€ã®
NetWatchã«ãŒã«ãäœæããŸãã
[s@KREDO-VERTOLET-GW] >tool netwatch expoart
ãããã®ã«ãŒã«ã¯éåžžã«åçŽãªåœ¹å²ãæãããŸããããã¯ãã¡ãªã¿ã«
ã·ã¹ã³ã®äžçã®
ip sla + trackã«äŒŒãŠããŸãã
ãµãŒããŒãšWi-Fiããªã³ã¿ãŒã«2ç§ã®ã¿ã€ã ã¢ãŠãã§10ç§ããšã«pingãå®è¡ããŸãã pingãæåããå Žå㯠ã éçã«ãŒããæå¹ã«ããŸã ãããã«ããã åé
åžã«ããOSPFã«å³åº§ã«åãæ¿ããããªãã£ã¹ã®ã¡ã€ã³ã«ãŒã¿ãŒãããã€ã¹ã®å ŽæãèŠã€ããŸãããããã£ãŠã
Wi-Fiããªã³ã¿ãŒã¯ä»¥åãšåãããã«åã³å°å·ãããããã«ãªããããã°ã©ããŒã¯ãªããžã§ã³ãµãŒããŒã§RDPãçŽæ¥æäœã§ããŸãã ãã©ãããããã¯ãŒã¯ããããã®ããã«ã
6ãæåŸããããžã§ã¯ããå®å
šã«éå§ãããç¬éããèšäºãæžããŸããã éå»6ãæéããã¹ãŠãå®ç§ã«æ©èœãã倱æããããšã¯ãããŸããã§ããã Wi-Fiããªã³ã¿ãŒã¯æ£åžžã«ãã£ãããããæ®å¿µãªããISPã®ã¯ã©ãã·ã¥ãçºçããŸãããåºèã¯ããã«æ°ä»ããŸããã
ãã®èšäºã¯åã³å€§ããªèšäºã«ãªããŸãããã泚æãšå¿èã«æè¬ããŸãã æ¹å€ãšã³ã¡ã³ããæè¿ããŸãã ã質åãããå Žåã¯ãåãã§ãçããã ããã