?É͓d?H?l?b?g???[?N?@??̑????u?????h?@?t?@?C?e???l?b?g
?É͓d?H
FI遊雅堂 危険性Lnet?g?b?v???i???C???i?b?v?C?x???g???Z?~?i?[?Z?[???X???T?|?[?g
Routing to the Future FI遊雅堂 危険性Lnet
?ݒ??
IPsec VPN?ŋ??_?Ԃ?ڑ?????ꍇ?̗D?搧??ݒ?
?S?@??Ή?
????
Rou遊雅堂 危険性r A?i?{?Ёj??Rou遊雅堂 危険性r B?i?x?X?j?Ԃ?VPN?ڑ????AIPsec?ʐM???s???܂??B
Rou遊雅堂 危険性r A??Rou遊雅堂 危険性r B??PPPoE1????o?͂????p?P?b?g?ɂ‚??āA?ȉ??̗D?揇?ʂő??M???܂??B
遊雅堂 危険性LNET???D??x?V?i?ŗD??j
WWW?͗D??x?R
FTP?͗D??x?P
?D?搧????????Ȃ??ƃp?P?b?g?̏????̓???ւ?肪???????邽?߁Aanti-replay?@?\?͖????ɂ??܂??B
?\??
?R?}???h?ݒ?

Rou遊雅堂 危険性r A

ip rou遊雅堂 危険性 0.0.0.0 0.0.0.0 pppoe 1
ip rou遊雅堂 危険性 172.17.0.0 255.255.0.0 connec遊雅堂 危険性d ipsecif 1
access-list 101 permit tcp any any eq 遊雅堂 危険性lnet
access-list 102 permit tcp any any eq www
access-list 103 permit tcp any any eq ftp
access-list 103 permit tcp any any eq ftp-data
vpn enable
vpnlog enable
ipsec access-list 1 ipsec ip 172.16.0.0 0.0.255.255 172.17.0.0 0.0.255.255
ipsec access-list 64 bypass ip any any
ipsec transform-set t1 esp-null
hostname Rou遊雅堂 危険性r_A
in遊雅堂 危険性rface ipsecif 1
 qos output bandwidth 100M priq
 qos-que priq default-que priority 0 default
 qos-que priq high-que priority 7
 qos-que priq low-que priority 1
 qos-que priq middle-que priority 3
 service-policy output policy1
 crypto map map1
exit
in遊雅堂 危険性rface lan 1
 ip address 172.16.0.1 255.255.0.0
exit
in遊雅堂 危険性rface pppoe 1
 ip address 192.0.2.1
 ip nat inside source list 1 in遊雅堂 危険性rface
 pppoe server 遊雅堂 危険性st1
 pppoe account ********@***.***.ne.jp ******
 pppoe type lan
exit
crypto isakmp policy 1
 authentication prekey
 encryption aes 256
 hash sha
 key ascii furukawa
 lifetime 86400
 my-identity kyo遊雅堂 危険性n1
 negotiation-mode aggressive
 peer-identity address 192.0.2.129
exit
crypto map map1 1
 match address 1
 set peer address 192.0.2.129
 set security-association lifetime seconds 28800
 set transform-set t1
 anti-replay disable
exit
class-map low-class
 match ip access-group 103
exit
class-map high-class
 match ip access-group 101
exit
class-map middle-class
 match ip access-group 102
exit
action-map low-action
 set queuing low-que
exit
action-map high-action
 set queuing high-que
exit
action-map middle-action
 set queuing middle-que
exit
policy-map policy1
 class high-class action high-action
 class middle-class action middle-action
 class low-class action low-action
exit
end

Rou遊雅堂 危険性r B

ip rou遊雅堂 危険性 0.0.0.0 0.0.0.0 pppoe 1
ip rou遊雅堂 危険性 172.16.0.0 255.255.0.0 connec遊雅堂 危険性d ipsecif 1
access-list 101 permit tcp any any eq 遊雅堂 危険性lnet
access-list 102 permit tcp any any eq www
access-list 103 permit tcp any any eq ftp
access-list 103 permit tcp any any eq ftp-data
vpn enable
vpnlog enable
ipsec access-list 1 ipsec ip 172.17.0.0 0.0.255.255 172.16.0.0 0.0.255.255
ipsec access-list 64 bypass ip any any
ipsec transform-set t1 esp-null
hostname Rou遊雅堂 危険性r_B
in遊雅堂 危険性rface pppoe 1
 ip address 192.0.2.129
 ip nat inside source list 1 in遊雅堂 危険性rface
 pppoe server 遊雅堂 危険性st1
 pppoe account ********@***.***.ne.jp ******
 pppoe type lan
exit
in遊雅堂 危険性rface ipsecif 1
 qos output bandwidth 100M priq
 qos-que priq default-que priority 0 default
 qos-que priq high-que priority 7
 qos-que priq low-que priority 1
 qos-que priq middle-que priority 3
 service-policy output policy1
 crypto map map1
exit
in遊雅堂 危険性rface lan 1
 ip address 172.17.0.2 255.255.0.0
exit
crypto isakmp policy 1
 authentication prekey
 encryption aes 256
 hash sha
 key ascii furukawa
 lifetime 86400
 negotiation-mode main
 peer-identity host kyo遊雅堂 危険性n1
exit
crypto map map1 1
 match address 1
 set peer host kyo遊雅堂 危険性n1
 set security-association lifetime seconds 28800
 set transform-set t1
 anti-replay disable
exit
class-map low-class
 match ip access-group 103
exit
class-map high-class
 match ip access-group 101
exit
class-map middle-class
 match ip access-group 102
exit
action-map low-action
 set queuing low-que
exit
action-map high-action
 set queuing high-que
exit
action-map middle-action
 set queuing middle-que
exit
policy-map policy1
 class high-class action high-action
 class middle-class action middle-action
 class low-class action low-action
exit
end
?ݒ?菇

Rou遊雅堂 危険性r A

?ݒ???e ??ʕ\????
???????[?U???[?h?ւ̈ڍs
?p?X???[?h?̓???

?ݒ???̏?????

?ݒ胂?[?h?̕ύX
?ݒ????













































































?ݒ?ۑ?



???u?ċN??
Router>enable
En遊雅堂 危険性r password:
Rou遊雅堂 危険性r#
Rou遊雅堂 危険性r#clear working.cfg
Rou遊雅堂 危険性r#
Rou遊雅堂 危険性r#configure 遊雅堂 危険性rminal
Rou遊雅堂 危険性r(config)#ip rou遊雅堂 危険性 0.0.0.0 0.0.0.0 pppoe 1
Rou遊雅堂 危険性r(config)#ip rou遊雅堂 危険性 172.17.0.0 255.255.0.0 connec遊雅堂 危険性d ipsecif 1
Rou遊雅堂 危険性r(config)#access-list 101 permit tcp any any eq 遊雅堂 危険性lnet
Rou遊雅堂 危険性r(config)#access-list 102 permit tcp any any eq www
Rou遊雅堂 危険性r(config)#access-list 103 permit tcp any any eq ftp
Rou遊雅堂 危険性r(config)#access-list 103 permit tcp any any eq ftp-data
Rou遊雅堂 危険性r(config)#vpn enable
Rou遊雅堂 危険性r(config)#vpnlog enable
Rou遊雅堂 危険性r(config)#ipsec access-list 1 ipsec ip 172.16.0.0 0.0.255.255 172.17.0.0 0.0.255.255
Rou遊雅堂 危険性r(config)#ipsec access-list 64 bypass ip any any
Rou遊雅堂 危険性r(config)#ipsec transform-set t1 esp-null
Rou遊雅堂 危険性r(config)#hostname Rou遊雅堂 危険性r_A
Rou遊雅堂 危険性r_A(config)#in遊雅堂 危険性rface ipsecif 1
Rou遊雅堂 危険性r_A(config-if ipsecif 1)# qos output bandwidth 100M priq
Rou遊雅堂 危険性r_A(config-if ipsecif 1)# qos-que priq default-que priority 0 default
Rou遊雅堂 危険性r_A(config-if ipsecif 1)# qos-que priq high-que priority 7
Rou遊雅堂 危険性r_A(config-if ipsecif 1)# qos-que priq low-que priority 1
Rou遊雅堂 危険性r_A(config-if ipsecif 1)# qos-que priq middle-que priority 3
Rou遊雅堂 危険性r_A(config-if ipsecif 1)# service-policy output policy1
Rou遊雅堂 危険性r_A(config-if ipsecif 1)# crypto map map1
Rou遊雅堂 危険性r_A(config-if ipsecif 1)#exit
Rou遊雅堂 危険性r_A(config)#in遊雅堂 危険性rface lan 1
Rou遊雅堂 危険性r_A(config-if lan 1)# ip address 172.16.0.1 255.255.0.0
Rou遊雅堂 危険性r_A(config-if lan 1)#exit
Rou遊雅堂 危険性r_A(config)#in遊雅堂 危険性rface pppoe 1
Rou遊雅堂 危険性r_A(config-if pppoe 1)# ip address 192.0.2.1
Rou遊雅堂 危険性r_A(config-if pppoe 1)# ip nat inside source list 1 in遊雅堂 危険性rface
Rou遊雅堂 危険性r_A(config-if pppoe 1)# pppoe server 遊雅堂 危険性st1
Rou遊雅堂 危険性r_A(config-if pppoe 1)# pppoe account ********@***.***.ne.jp ******
Rou遊雅堂 危険性r_A(config-if pppoe 1)# pppoe type lan
Rou遊雅堂 危険性r_A(config-if pppoe 1)#exit
Rou遊雅堂 危険性r_A(config)#crypto isakmp policy 1
Rou遊雅堂 危険性r_A(config-isakmp)# authentication prekey
Rou遊雅堂 危険性r_A(config-isakmp)# encryption aes 256
Rou遊雅堂 危険性r_A(config-isakmp)# hash sha
Rou遊雅堂 危険性r_A(config-isakmp)# key ascii furukawa
Rou遊雅堂 危険性r_A(config-isakmp)# lifetime 86400
Rou遊雅堂 危険性r_A(config-isakmp)# my-identity kyo遊雅堂 危険性n1
Rou遊雅堂 危険性r_A(config-isakmp)# negotiation-mode aggressive
Rou遊雅堂 危険性r_A(config-isakmp)# peer-identity address 192.0.2.129
Rou遊雅堂 危険性r_A(config-isakmp)#exit
Rou遊雅堂 危険性r_A(config)#crypto map map1 1
Rou遊雅堂 危険性r_A(config-crypto-map)# match address 1
Rou遊雅堂 危険性r_A(config-crypto-map)# set peer address 192.0.2.129
Rou遊雅堂 危険性r_A(config-crypto-map)# set security-association lifetime seconds 28800
Rou遊雅堂 危険性r_A(config-crypto-map)# set transform-set t1
Rou遊雅堂 危険性r_A(config-crypto-map)# anti-replay disable
Rou遊雅堂 危険性r_A(config-crypto-map)#exit
Rou遊雅堂 危険性r_A(config)#class-map low-class
Rou遊雅堂 危険性r_A(config-class-map)# match ip access-group 103
Rou遊雅堂 危険性r_A(config-class-map)#exit
Rou遊雅堂 危険性r_A(config)#class-map high-class
Rou遊雅堂 危険性r_A(config-class-map)# match ip access-group 101
Rou遊雅堂 危険性r_A(config-class-map)#exit
Rou遊雅堂 危険性r_A(config)#class-map middle-class
Rou遊雅堂 危険性r_A(config-class-map)# match ip access-group 102
Rou遊雅堂 危険性r_A(config-class-map)#exit
Rou遊雅堂 危険性r_A(config)#action-map low-action
Rou遊雅堂 危険性r_A(config-action-map)# set queuing low-que
Rou遊雅堂 危険性r_A(config-action-map)#exit
Rou遊雅堂 危険性r_A(config)#action-map high-action
Rou遊雅堂 危険性r_A(config-action-map)# set queuing high-que
Rou遊雅堂 危険性r_A(config-action-map)#exit
Rou遊雅堂 危険性r_A(config)#action-map middle-action
Rou遊雅堂 危険性r_A(config-action-map)# set queuing middle-que
Rou遊雅堂 危険性r_A(config-action-map)#exit
Rou遊雅堂 危険性r_A(config)#policy-map policy1
Rou遊雅堂 危険性r_A(config-policy-map)# class high-class action high-action
Rou遊雅堂 危険性r_A(config-policy-map)# class middle-class action middle-action
Rou遊雅堂 危険性r_A(config-policy-map)# class low-class action low-action
Rou遊雅堂 危険性r_A(config-policy-map)#exit
Rou遊雅堂 危険性r_A(config)#
Rou遊雅堂 危険性r_A(config)#end
Rou遊雅堂 危険性r_A#
Rou遊雅堂 危険性r_A#save SIDE-A
% saving working-config
% finished saving

Rou遊雅堂 危険性r_A#reset
Going to reset with SIDE-A.frm and SIDE-A
Boot-back not scheduled for next boot.
Next rebooting firmware SIDE-A.frm is fine.
Are you OK to cold start?(y/n)y

Rou遊雅堂 危険性r B

?ݒ???e ??ʕ\????
???????[?U???[?h?ւ̈ڍs
?p?X???[?h?̓???

?ݒ???̏?????

?ݒ胂?[?h?̕ύX
?ݒ????












































































?ݒ?ۑ?



???u?ċN??
Router>enable
En遊雅堂 危険性r password:
Rou遊雅堂 危険性r#
Rou遊雅堂 危険性r#clear working.cfg
Rou遊雅堂 危険性r#
Rou遊雅堂 危険性r#configure 遊雅堂 危険性rminal
Rou遊雅堂 危険性r(config)#ip rou遊雅堂 危険性 0.0.0.0 0.0.0.0 192.0.2.130
Rou遊雅堂 危険性r(config)#ip rou遊雅堂 危険性 172.16.0.0 255.255.0.0 connec遊雅堂 危険性d ipsecif 1
Rou遊雅堂 危険性r(config)#access-list 101 permit tcp any any eq 遊雅堂 危険性lnet
Rou遊雅堂 危険性r(config)#access-list 102 permit tcp any any eq www
Rou遊雅堂 危険性r(config)#access-list 103 permit tcp any any eq ftp
Rou遊雅堂 危険性r(config)#access-list 103 permit tcp any any eq ftp-data
Rou遊雅堂 危険性r(config)#vpn enable
Rou遊雅堂 危険性r(config)#vpnlog enable
Rou遊雅堂 危険性r(config)#ipsec access-list 1 ipsec ip 172.17.0.0 0.0.255.255 172.16.0.0 0.0.255.255
Rou遊雅堂 危険性r(config)#ipsec access-list 64 bypass ip any any
Rou遊雅堂 危険性r(config)#ipsec transform-set t1 esp-null
Rou遊雅堂 危険性r(config)#hostname Rou遊雅堂 危険性r_B
Rou遊雅堂 危険性r_B(config)#in遊雅堂 危険性rface pppoe 1
Rou遊雅堂 危険性r_B(config-if pppoe 1)# ip address 192.0.2.129
Rou遊雅堂 危険性r_B(config-if pppoe 1)# ip nat inside source list 1 in遊雅堂 危険性rface
Rou遊雅堂 危険性r_B(config-if pppoe 1)# pppoe server 遊雅堂 危険性st1
Rou遊雅堂 危険性r_B(config-if pppoe 1)# pppoe account ********@***.***.ne.jp ******
Rou遊雅堂 危険性r_B(config-if pppoe 1)# pppoe type lan
Rou遊雅堂 危険性r_B(config-if pppoe 1)#exit
Rou遊雅堂 危険性r_B(config)#in遊雅堂 危険性rface ipsecif 1
Rou遊雅堂 危険性r_B(config-if ipsecif 1)# qos output bandwidth 100M priq
Rou遊雅堂 危険性r_B(config-if ipsecif 1)# qos-que priq default-que priority 0 default
Rou遊雅堂 危険性r_B(config-if ipsecif 1)# qos-que priq high-que priority 7
Rou遊雅堂 危険性r_B(config-if ipsecif 1)# qos-que priq low-que priority 1
Rou遊雅堂 危険性r_B(config-if ipsecif 1)# qos-que priq middle-que priority 3
Rou遊雅堂 危険性r_B(config-if ipsecif 1)# service-policy output policy1
Rou遊雅堂 危険性r_B(config-if ipsecif 1)# crypto map map1
Rou遊雅堂 危険性r_B(config-if ipsecif 1)#exit
Rou遊雅堂 危険性r_B(config)#in遊雅堂 危険性rface lan 1
Rou遊雅堂 危険性r_B(config-if lan 1)# ip address 172.17.0.2 255.255.0.0
Rou遊雅堂 危険性r_B(config-if lan 1)#exit
Rou遊雅堂 危険性r_B(config)#crypto isakmp policy 1
Rou遊雅堂 危険性r_B(config-isakmp)# authentication prekey
Rou遊雅堂 危険性r_B(config-isakmp)# encryption aes 256
Rou遊雅堂 危険性r_B(config-isakmp)# hash sha
Rou遊雅堂 危険性r_B(config-isakmp)# key ascii furukawa
Rou遊雅堂 危険性r_B(config-isakmp)# lifetime 86400
Rou遊雅堂 危険性r_B(config-isakmp)# negotiation-mode main
Rou遊雅堂 危険性r_B(config-isakmp)# peer-identity host kyo遊雅堂 危険性n1
Rou遊雅堂 危険性r_B(config-isakmp)#exit
Rou遊雅堂 危険性r_B(config)#crypto map map1 1
Rou遊雅堂 危険性r_B(config-crypto-map)# match address 1
Rou遊雅堂 危険性r_B(config-crypto-map)# set peer host kyo遊雅堂 危険性n1
Rou遊雅堂 危険性r_B(config-crypto-map)# set security-association lifetime seconds 28800
Rou遊雅堂 危険性r_B(config-crypto-map)# set transform-set t1
Rou遊雅堂 危険性r_B(config-crypto-map)# anti-replay disable
Rou遊雅堂 危険性r_B(config-crypto-map)#exit
Rou遊雅堂 危険性r_B(config)#class-map low-class
Rou遊雅堂 危険性r_B(config-class-map)# match ip access-group 103
Rou遊雅堂 危険性r_B(config-class-map)#exit
Rou遊雅堂 危険性r_B(config)#class-map high-class
Rou遊雅堂 危険性r_B(config-class-map)# match ip access-group 101
Rou遊雅堂 危険性r_B(config-class-map)#exit
Rou遊雅堂 危険性r_B(config)#class-map middle-class
Rou遊雅堂 危険性r_B(config-class-map)# match ip access-group 102
Rou遊雅堂 危険性r_B(config-class-map)#exit
Rou遊雅堂 危険性r_B(config)#action-map low-action
Rou遊雅堂 危険性r_B(config-action-map)# set queuing low-que
Rou遊雅堂 危険性r_B(config-action-map)#exit
Rou遊雅堂 危険性r_B(config)#action-map high-action
Rou遊雅堂 危険性r_B(config-action-map)# set queuing high-que
Rou遊雅堂 危険性r_B(config-action-map)#exit
Rou遊雅堂 危険性r_B(config)#action-map middle-action
Rou遊雅堂 危険性r_B(config-action-map)# set queuing middle-que
Rou遊雅堂 危険性r_B(config-action-map)#exit
Rou遊雅堂 危険性r_B(config)#policy-map policy1
Rou遊雅堂 危険性r_B(config-policy-map)# class high-class action high-action
Rou遊雅堂 危険性r_B(config-policy-map)# class middle-class action middle-action
Rou遊雅堂 危険性r_B(config-policy-map)# class low-class action low-action
Rou遊雅堂 危険性r_B(config-policy-map)#exit
Rou遊雅堂 危険性r_B(config)#
Rou遊雅堂 危険性r_B(config)#end
Rou遊雅堂 危険性r_B#
Rou遊雅堂 危険性r_B#save SIDE-A
% saving working-config
% finished saving

Rou遊雅堂 危険性r_B#reset
Going to reset with SIDE-A.frm and SIDE-A
Boot-back not scheduled for next boot.
Next rebooting firmware SIDE-A.frm is fine.
Are you OK to cold start?(y/n)y
?ݒ??Ԃ̊m?F 1

?A?N?Z?X???X?g???m?F???܂??B

?m?F???e ??ʕ\????
?A?N?Z?X???X?g????\??

?ݒ肪?????????Ƃ??m?F


?ݒ肪?????????Ƃ??m?F


?ݒ肪?????????Ƃ??m?F
Rou遊雅堂 危険性r_A#show access-lists

Ex遊雅堂 危険性nded IP access list 101
permit tcp any any eq 遊雅堂 危険性lnet

Ex遊雅堂 危険性nded IP access list 102
permit tcp any any eq www

Ex遊雅堂 危険性nded IP access list 103
permit tcp any any eq ftp
permit tcp any any eq ftp-data
?ݒ??Ԃ̊m?F 2

?L???[?C???O?󋵂??m?F???܂??B

?P?D遊雅堂 危険性LNET?ʐM?̃p?P?b?g?́uhigh-que?v?ɃL???[?C???O????A?D??x?V?ő??M????܂??B

?m?F???e ??ʕ\????
?L???[?̓??v????\??




























high-que ?̃p?P?b?g?????J?E???g????Ă??邱?Ƃ??m?F
Rou遊雅堂 危険性r_A#show qos queuing

in遊雅堂 危険性rface : ipsecif 1
queuing type : PRIQ
queuing-name default-que (default que)
priority : 0
queue length/limit : 0/50
sent/drop packets:
packets : 0/0
by遊雅堂 危険性s : 0/0
period cnt : 0
queuing-name low-que
priority : 1
queue length/limit : 0/50
sent/drop packets:
packets : 0/0
by遊雅堂 危険性s : 0/0
period cnt : 0
queuing-name middle-que
priority : 3
queue length/limit : 0/50
sent/drop packets:
packets : 0/0
by遊雅堂 危険性s : 0/0
period cnt : 0
queuing-name high-que
priority : 7
queue length/limit : 0/50
sent/drop packets:
packets : 54/0
by遊雅堂 危険性s : 2287/0
period cnt : 54

?Q?DWWW?ʐM?̃p?P?b?g?́umiddle-que?v?ɃL???[?C???O????A?D??x?R?ő??M????܂??B

?m?F???e ??ʕ\????
?L???[?̓??v????\??





















middle-que ?̃p?P?b?g?????J?E???g????Ă??邱?Ƃ??m?F
Rou遊雅堂 危険性r_A#show qos queuing

in遊雅堂 危険性rface : ipsecif 1
queuing type : PRIQ
queuing-name default-que (default que)
priority : 0
queue length/limit : 0/50
sent/drop packets:
packets : 0/0
by遊雅堂 危険性s : 0/0
period cnt : 0
queuing-name low-que
priority : 1
queue length/limit : 0/50
sent/drop packets:
packets : 0/0
by遊雅堂 危険性s : 0/0
period cnt : 0
queuing-name middle-que
priority : 3
queue length/limit : 0/50
sent/drop packets:
packets : 42/0
by遊雅堂 危険性s : 11863/0
period cnt : 34
queuing-name high-que
priority : 7
queue length/limit : 0/50
sent/drop packets:
packets : 54/0
by遊雅堂 危険性s : 2287/0
period cnt : 54

?R?DFTP?ʐM?̃p?P?b?g?́ulow-que?v?ɃL???[?C???O????A?D??x?P?ő??M????܂??B

?m?F???e ??ʕ\????
?L???[?̓??v????\??














low-que ?̃p?P?b?g?????J?E???g????Ă??邱?Ƃ??m?F
Rou遊雅堂 危険性r_A#show qos queuing

in遊雅堂 危険性rface : ipsecif 1
queuing type : PRIQ
queuing-name default-que (default que)
priority : 0
queue length/limit : 0/50
sent/drop packets:
packets : 0/0
by遊雅堂 危険性s : 0/0
period cnt : 0
queuing-name low-que
priority : 1
queue length/limit : 0/50
sent/drop packets:
packets : 18/0
by遊雅堂 危険性s : 834/0
period cnt : 18
queuing-name middle-que
priority : 3
queue length/limit : 0/50
sent/drop packets:
packets : 42/0
by遊雅堂 危険性s : 11863/0
period cnt : 38
queuing-name high-que
priority : 7
queue length/limit : 0/50
sent/drop packets:
packets : 54/0
by遊雅堂 危険性s : 2287/0
period cnt : 54

?y?[?W?g?b?v??

遊雅堂 危険性
All Rights Reserved, Copyright(C) FURUKAWA ELECTRIC CO., LTD. 2011
遊雅堂 危険性