アライド製のルータAR415SをIP8個用のルータとして最低設定を行う。
WANのIP:61.115.252.55/22 GW:61.115.255.254
LANのIP:61.122.218.214/29
WANからアクセス可ポート
TCP 22,25,80,443
UDP 53
ICMP
設定シリアルケーブルを使用。
マニュアルWeb上にある。
接続
INFO: Self tests beginning. INFO: RAM test beginning. PASS: RAM test, 32768k bytes found. INFO: Self tests complete. INFO: Downloading router software. Force EPROM download (Y) ? INFO: Initial download successful. INFO: Initialising Flash File System. INFO: Executing configuration script <flash:test01.cfg> INFO: Router startup complete login: manager Password: ***** <==defalt:friend
パスワード変更
Manager > set password Old password: ****** New password: ****** Confirm: *****
時刻の確認
Manager > show time System time is 08:55:12 on Wednesday 25-Jul-2007.
IPの設定
Manager > ENABLE IP Info (1005287): IP module has been enabled. Manager > ADD IP INT=ETH0 IP=61.115.252.55 MASK=255.255.252.0 Info (1005275): interface successfully added. Manager > ADD IP INT=VLAN1 IP=61.122.218.214 MASK=255.255.255.240 Manager > ADD IP ROUTE=0.0.0.0 MASK=0.0.0.0 INT=ETH0 NEXTHOP=61.115.255.254 Info (1005275): IP route successfully added.
インターフェイスIPの表示
Manager > show ip int Interface Type IP Address Bc Fr PArp Filt RIP Met. SAMode IPSc Pri. Filt Pol.Filt Network Mask MTU VJC GRE OSPF Met. DBcast Mul. VLAN Tag VLAN Priority InvArp -------------------------------------------------------------------------------- LOCAL --- Not set - - - --- -- Pass -- --- --- Not set 1500 - --- -- --- --- none none - vlan1 Static 61.122.218.214 1 n On --- 01 Pass No --- --- 255.255.255.240 1500 - --- 0000000001 No Rec none none - eth0 Static 61.115.252.55 1 n On --- 01 Pass No --- --- 255.255.252.0 1500 - --- 0000000001 No Rec none none - --------------------------------------------------------------------------------
ファイルの保存
Manager > create config=dc01.cfg Info (1034003): Operation successful.
ファイルの確認
Manager > show files Filename Device Size Created Locks ----------------------------------------------------------------------------- 54281-04.rez flash 4857208 24-Mar-2007 19:48:21 0 feature.lic flash 39 24-Mar-2007 19:49:20 0 help.hlp flash 75892 24-Mar-2007 19:49:17 0 longname.lfn flash 17 15-Jun-2007 16:01:08 0 prefer.ins flash 64 24-Mar-2007 19:48:54 0 release.lic flash 32 24-Mar-2007 19:48:53 0 dc01.cfg flash 2464 25-Jul-2007 09:04:00 0 -----------------------------------------------------------------------------
ファイル内容の表示
Manager > show file=dc01.cfg File : dc01.cfg 1: 2:# Command Handler configuration 3: 4:# System configuration 5: 6:# TIMEZONE configuration 7: 8:# Flash memory configuration 9: 10:# LOADER configuration 11: 12:# User configuration 13:set user=manager pass=a6d7b66b15077f4***********719b8dff priv=manager lo=yes 14:set user=manager telnet=yes desc="Manager Account" 15: 16:# TTY configuration 17: 18:# ASYN configuration --More-- (<space> = next page, <CR> = one line, C = continuous, Q = quit)19:
起動時のConfigファイルの指定
設定した内容は.cfgがつくファイル名で保存して起動時に読み出すように設定する必要がある。
Manager > set config=dc01.cfg Info (1049003): Operation successful. Manager > show config Boot configuration file: flash:dc01.cfg (exists) Current configuration: None
フィルタの指定
ADD IP FILT=1 SO=0.0.0.0 SMA=0.0.0.0 DEST=61.122.218.208 DMA=255.255.255.240 AC=INCLUDE ENTRY=1 PROTO=TCP DPORT=22 ADD IP FILT=1 SO=0.0.0.0 SMA=0.0.0.0 DEST=61.122.218.208 DMA=255.255.255.240 AC=INCLUDE ENTRY=2 PROTO=TCP DPORT=25 ADD IP FILT=1 SO=0.0.0.0 SMA=0.0.0.0 DEST=61.122.218.208 DMA=255.255.255.240 AC=INCLUDE ENTRY=3 PROTO=TCP DPORT=53 ADD IP FILT=1 SO=0.0.0.0 SMA=0.0.0.0 DEST=61.122.218.208 DMA=255.255.255.240 AC=INCLUDE ENTRY=4 PROTO=TCP DPORT=80 ADD IP FILT=1 SO=0.0.0.0 SMA=0.0.0.0 DEST=61.122.218.208 DMA=255.255.255.240 AC=INCLUDE ENTRY=5 PROTO=TCP DPORT=443 ADD IP FILT=1 SO=0.0.0.0 SMA=0.0.0.0 DEST=61.122.218.208 DMA=255.255.255.240 AC=INCLUDE ENTRY=11 PROTO=UDP DPORT=53 ADD IP FILT=1 SO=0.0.0.0 SMA=0.0.0.0 DEST=61.122.218.208 DMA=255.255.255.240 AC=INCLUDE ENTRY=99 PROTO=ICMP SET IP INT=ETH0 FILTER=1
フィルタの確認
Manager > show ip filter IP Filters -------------------------------------------------------------------------------- No. Filter Type Ent. Source Port Source Address Source Mask Session Size Dest. Port Dest. Address Dest. Mask Prot.(T/C) Options Pattern Type Act/Pol/Pri Logging Matches -------------------------------------------------------------------------------- 1 Traffic 1 Any Any Any Any Any 22:22 192.168.200.0 255.255.255.0 TCP Any General Include Off 0 2 --- Any Any --- Any --- 192.168.200.0 255.255.255.0 ICMP(**/**) Any General Include Off 0 Requests: 0 Passes: 0 Fails: 0 --------------------------------------------------------------------------------
フィルタの削除
Manager > del ip filt=1 entry=2
フィルタ内容の変更
SET IP FILT=1 ENTRY=4 PROTO=TCP DPORT=443
一度「SET IP INT=ETH0 FILTER=1」してると変更時は特に必要ない。
HTTPポートについて HTTPポートはサポートしていないにも関わらず、アクセスするとパスワード認証の画面が表示されるので、それを表示しないようにする
DISABLE HTTP SERVER