接続方式デフォルト
httpd / 有効 / lan
telnetd / 有効 / any
sshd / 無効
ユーザー作成
WebGUI>保守>コマンドの実行>
login user skuser xxx
SSH有効化
WebGUI>アクセス管理>各種サーバーの設定
SSH有効化
※WebGUIでSSHを有効にするとKeyは自動で生成される。
※WebGUIコマンドからは生成できないので以下はコマンドでは実行しない。
sshd service on
sshd host key generate(手動で一度だけのコマンド)
SSH接続
ssh xxx@192.168.xxx.xxx
※SSHクライアントが新しい場合
ssh -oKexAlgorithms=+diffie-hellman-group14-sha1 -oHostKeyAlgorithms=+ssh-rsa xxx@192.168.xxx.xxx
管理権限昇格
administrator
>空白
パスワード設定
administrator password
>xxx
login password
>xxx
表示設定
console character en.ascii
console lines infinity
ログアウトタイマー
user attribute skuser login-timer=7200
TELNET無効
telnetd service off
アクセス範囲指定
httpd host 192.168.●.0-192.168.●.255 192.168.113.0-192.168.113.255
sshd host 192.168.●.0-192.168.●.255 192.168.113.0-192.168.113.255
httpd host 192.168.2.0-192.168.2.255 192.168.113.0-192.168.113.255
sshd host 192.168.2.0-192.168.2.255 192.168.113.0-192.168.113.255
名前なしユーザーをシリアル限定
user attribute connection=serial
PPTP/L2TP無効
※デフォルトでは無効だけど、もし有効な環境なら
pptp service off
l2tp service off
簡単設定>VPN>リモートアクセス
トンネル削除
Defaultgateway
ip route default gateway <>
pp 1
dhcp lan2
xxx.xxx.xxx.xxx
tunnel 1
LAN1 Address
ip lan1 address <>
xxx.xxx.xxx.xxx/24
LAN2 Address
ip lan2 address <>
dhcp
xxx.xxx.xxx.xxx
pp select 1
DNS
dns server <>
xxx
pp 1
NAT
ip lan2 nat descriptor 1000
nat descriptor type 1000 masquerade
nat descriptor address outer 1000 <>
ipcp / PPPoE
primary / DHCP
xxx.xxx.xxx.xxx / 静的IP
※これはデフォなので不要
nat descriptor address inner 1 auto
・IPsec定番ポート開放
nat descriptor masquerade static 1 1 192.168.13.1 udp 500
nat descriptor masquerade static 1 2 192.168.13.1 esp
nat descriptor masquerade static 1 3 192.168.13.1 udp 4500
DHCP
dhcp service server
dhcp scope 1 192.168.xxx.2-192.168.xxx.254/24
PP
※ 起動
pp select 1 ~ pp enable 1
※ 基本
pppoe use lan2
pp auth accept pap chap
pp auth myname (ID) (PASS)
ip pp nat descriptor 1000
※ 常時接続
pp always-on on
pppoe auto disconnect off
※ mtu / mru / mss
ppp lcp mru on 1454
ip pp mtu 1454
ip pp tcp mss limit auto
※ IPCPで貰うペア
ppp ipcp ipaddress on
ppp ipcp msext on
※ 圧縮なし
ppp ccp type none
拠点間VPN
ip route xxx.xxx.xxx.xxx/24 gateway tunnel 1
ipsec auto refresh on
※ 起動
tunnel select 1 ~ tunnel enable 1
※ トンネルIPsec紐づけ
ipsec tunnel 1
※ 暗号方式
ipsec sa policy 1 1 esp 3des-cbc sha-hmac
※ 認証手段
ipsec ike pre-shared-key 1 text xxx
※ 相手
ipsec ike remote address 1 xxx.xxx.xxx.xxx
<条件付必須>
※ 両側グローバルIPなら不要
ipsec ike nat-traversal 1 on
ip tunnel tcp mss limit auto
ipsec ike keepalive use 1 on heartbeat 10 6
ipsec ike local address 1 xxx.xxx.xxx.xxx
<以下なくてもOK>
※ メモ
description tunnel test
※ ログ量
ipsec ike keepalive log 1 off
その他
MTU
IP層で送信できるIPパケット全体サイズ
1454
MRU
PPP層で自分が受信できる最大サイズ
1454
MSS
TCP層でデータ部分の最大サイズ
MTU-40