$Date: 2024/11/08 14:21:12 $
���}�n���[�^�[�ł͈ȉ��̋@�킨��уt�@�[���E�F�A�ŁAL2TP/IPsec���T�|�[�g���Ă��܂��B
���r�W�����ɂ���đΉ����Ă��鍀�ڂ��قȂ�܂��B�Ή����ڂ͈ȉ��̂悤�ɂȂ�܂�
�@�� | �t�@�[���E�F�A | �ő�ڑ��\��(��1) | NAT�g���o�[�T���� �p���� L2TP/IPsec�ڑ� |
�t�@�X�g�p�X�Ή� | PPTP�Ƃ� anonymous�ڑ����p |
�g���l���e���v���[�g�Ή� |
---|---|---|---|---|---|---|
vRX Amazon EC2�� | ���ׂẴ��r�W���� | 0�`1000 (��2) | �� | �� | PPTP��Ή� | �� |
vRX VMware ESXi�� | ||||||
vRX ������̃N���E�h�� | 0�`100 (��2) | |||||
RTX3510 | ���ׂẴ��r�W���� | 1000 (��3) | �� | �� | PPTP��Ή� | �� |
RTX1300 | Rev.23.00.03 | 100 | �� | �� | �� | �� |
Rev.23.00.14 �ȍ~ | 100 (��3) | �� | �� | �� | �� | |
RTX1220 | ���ׂẴ��r�W���� | 100 | �� | �� | �� | �� |
RTX830 | Rev.15.02.01 | 20 | �� | �� | �� | �� |
Rev.15.02.22 �ȍ~ | 20 (��3) | |||||
NVR510 | Rev.15.01.03 �ȍ~ | 4 | �� | �� | �� | �� |
NVR700W | Rev.15.00.02 | 6 | �� | �� | �� | �� |
Rev.15.00.10 �ȍ~ | 20 | |||||
RTX1210 | Rev.14.01.05 �ȍ~ | 100 | �� | �� | �� | �� |
RTX5000 | Rev.14.00.08 | 3000 | �� | �� | PPTP��Ή� | �~ |
Rev.14.00.12 �ȍ~ | �� | �� | PPTP��Ή� | �� | ||
RTX3500 | Rev.14.00.08 | 1000 | �� | �� | PPTP��Ή� | �~ |
Rev.14.00.12 �ȍ~ | �� | �� | PPTP��Ή� | �� | ||
FWX120 | Rev.11.03.02 | 30 | �� | �� | �� | �~ |
Rev.11.03.08 �ȍ~ | �� | �� | �� | �� | ||
RTX810 | Rev.11.01.04 | 6 | �~ | �~ | �~ | �~ |
Rev.11.01.06 �ȍ~ | �� | �� | �� | �~ | ||
Rev.11.01.21 �ȍ~ | �� | �� | �� | �� | ||
NVR500 | Rev.11.00.36 �ȍ~ | 4 | �� | �� | �� | �� |
RTX1200 | Rev.10.01.32 Rev.10.01.34 |
100 | �~ | �~ | �~ | �~ |
Rev.10.01.36 �ȍ~ | �� | �� | �� | �~ | ||
Rev.10.01.59 �ȍ~ | �� | �� | �� | �� | ||
SRT100 | Rev.10.00.60 | 10 | �~ | �~ | PPTP��Ή� | �~ |
Rev.10.00.61 �ȍ~ | �� | �� | PPTP��Ή� | �~ | ||
RTX3000 | Rev.9.00.60 �ȍ~ | 1000 | �� | �~ | PPTP��Ή� | �� |
RTX1500 | Rev.8.03.92 �ȍ~ | 100 | �� | �~ | �� | �~ |
RTX1100 | 30 | �� | �~ | �� | �~ | |
RT107e | 6 | �� | �~ | PPTP��Ή� | �~ |
L2TP�̐��䃁�b�Z�[�W +--------+----------------------------------------------------+ | | �y�C���[�h | | L2TP | +------+------------+------+------------+--------+ | | �w�b�_ | | ���� | �p�����[�^ | ���� | �p�����[�^ |����� | | | | +------+------------+------+------------+--------+ | | | <====== AVP ========> | | | <==================== AVPs ======================> | +--------+----------------------------------------------------+AVP�̑����ɂ͈ȉ��̂��̂�����܂��B
�����ԍ� | ������ | �����ԍ� | ������ | |
---|---|---|---|---|
0 | Message Type | 20 | - | |
1 | Result Code | 21 | Called Number | |
2 | Protocol Version | 22 | Calling Number | |
3 | Framing Capability | 23 | Sub-Address | |
4 | Bearer Capability | 24 | Tx Connect Speed | |
5 | Tie Breaker | 25 | Physical Channel ID | |
6 | Firmware Revision | 26 | Initial Received LCP CONFREQ | |
7 | Hostname | 27 | Last Sent LCP CONFREQ | |
8 | Vendor Name | 28 | Last Received LCP CONFREQ | |
9 | Assigned Tunnel ID | 29 | Proxy Authen Type | |
10 | Receive Window Size | 30 | Proxy Authen Name | |
11 | Challenge | 31 | Proxy Authen Challenge | |
12 | Q.931 Cause Code | 32 | Proxy Authen ID | |
13 | Challenge Response | 33 | Proxy Authen Response | |
14 | Assigned Session ID | 34 | Call Errors | |
15 | Call Serial Number | 35 | ACCM | |
16 | Minimum BPS | 36 | Random Vector | |
17 | Maximum BPS | 37 | Private Group ID | |
18 | Bearer Type | 38 | Rx Connect Speed | |
19 | Framing Type | 39 | Sequencing Required |
L2TP�̐��䃁�b�Z�[�W(AVP���Í��������ꍇ) +--------+--------------------------------------------------------------------------+ | | �y�C���[�h | | L2TP | +---+-------------+----+--------------+------+-------------------------+ | | �w�b�_ | | 0 | MessageType | 36 | RandomVector | ���� |�Í������ꂽ�p�����[�^�l | | | | +---+-------------+----+--------------+------+-------------------------+ | +--------+--------------------------------------------------------------------------+AVP�ɂ�AVP�w�b�_���t������Ă���A�����ԍ���p�����[�^�l�̒����A�p�����[�^�l���Í�������Ă��邩�ǂ����Ȃǂ̏��AVP�w�b�_�Ɋ܂܂�Ă��܂��BAVP�w�b�_���Q�Ƃ��Ă���AVP���Í�������Ă���ꍇ�ɂ́ARandom Vector AVP�̃p�����[�^�l��p���Đ������ꂽ���L���ŕ��������s���܂��B
+-----+PORT:XXXX SCCRQ PORT:1701+-----+ | |---------------------------------------->| | | |PORT:XXXX SCCRP PORT:YYYY| | | |<----------------------------------------| | | |PORT:XXXX ��� PORT:YYYY| | | LAC |---------------------------------------->| LNS | | |PORT:XXXX StopCCN PORT:YYYY| | | |---------------------------------------->| | | |PORT:XXXX ZLB PORT:YYYY| | | |<----------------------------------------| | +-----+ +-----+
+-----+ IPsec�R�l�N�V���� �̊m�� +-----+ | |<--------------------------------------->| | | | ESP(L2TP���䃁�b�Z�[�W) | | | LAC |<--------------------------------------->| LNS | | | ESP(L2TP�f�[�^�p�P�b�g) | | | |<--------------------------------------->| | | | ��� | | | |<--------------------------------------->| | +-----+ +-----+ �g�����X�|�[�g���[�h��ESP�ňÍ������ꂽL2TP���䃁�b�Z�[�W +--------+--------+--------+--------+------------+----------+------------+ | IP | ESP | UDP | L2TP | L2TP���� | ESP | ESP | | �w�b�_ | �w�b�_ | �w�b�_ | �w�b�_ | ���b�Z�[�W | �g���[�� | �F�f�[�^ | +--------+--------+--------+--------+------------+----------+------------+ <=========================================> �Í��������͈� �g�����X�|�[�g���[�h��ESP�ňÍ������ꂽL2TP�f�[�^�p�P�b�g +--------+--------+--------+--------+--------+--------+------------+----------+------------+ | IP | ESP | UDP | L2TP | PPP | IP | �y�C���[�h | ESP | ESP | | �w�b�_ | �w�b�_ | �w�b�_ | �w�b�_ | �w�b�_ | �w�b�_ | | �g���[�� | �F�f�[�^ | +--------+--------+--------+--------+--------+--------+------------+----------+------------+ <===========================================================> �Í��������͈�L2TP���䃁�b�Z�[�W�����L2TP�f�[�^�p�P�b�g��ESP�p�P�b�g�Ƃ��Ď�M���邽�߁A���}�n���[�^�[�̃C���^�[�l�b�g�ڑ����Ă���C���^�t�F�[�X��NAT���ݒ肳��Ă���ꍇ�ł��A�ÓIIP�}�X�J���[�h��ESP�̃|�[�g�ԍ������g��IP�A�h���X�Ɋ��蓖�ĂĂ����AL2TP�Ŏg�p����|�[�g�ԍ�(1701�Ȃ�)��ÓIIP�}�X�J���[�h�Ŏ��g��IP�A�h���X�Ɋ��蓖�Ă�K�v�͂���܂���B�������AL2TP�p�P�b�g�𑗐M����ꍇ�ɂ̓g�����X�|�[�g���[�h��ESP�ňÍ�������K�v�����邽�߁AL2TP�Ŏg�p����|�[�g�ԍ����g�����X�|�[�g���[�h�ŏ�������ݒ��lj�����K�v������܂��B
ipsec transport 1 1 udp 1701 * ipsec transport template 1 10 20-30 �ȉ���2�̐ݒ�͓������e�������Ă���B ipsec transport 1 1 udp 1701 * ipsec transport template 1 2 10-12 ipsec transport 1 1 udp 1701 * ipsec transport 2 2 udp 1701 * ipsec transport 10 10 udp 1701 * ipsec transport 11 11 udp 1701 * ipsec transport 12 12 udp 1701 *
���C�Z���X�� | �g����̏���l ( ���C�Z���X�{�����Ƃ̒l ) |
||||
---|---|---|---|---|---|
1�{ | 2�{ | 3�{ | 4�{ | 5�{ | |
YSL-VPN-EX1 | 100 | - | - | - | - |
YSL-VPN-EX2 | 300 | 500 | 700 | 900 | 1100 |
YSL-VPN-EX3 | 1500 | 2000 | 2500 | 3000 | - |
�R�}���h | �p�����[�^ |
---|---|
ipsec tunnel | �|���V�[ID |
ipsec sa policy | �|���V�[ID |
ipsec ike�Ŏn�܂�R�}���h | �Z�L�����e�B�E�Q�[�g�E�F�C�̎��ʎq |
ipsec auto refresh | �Z�L�����e�B�E�Q�[�g�E�F�C�̎��ʎq |
tunnel enable | �g���l���C���^�t�F�[�X�ԍ� |
�@�� | ���r�W���� |
---|---|
vRX�V���[�Y | ���ׂẴ��r�W���� |
RTX3510 | |
RTX5000, RTX3500 | |
RTX3000 | Rev.9.00.56�ȍ~ |
RTX1300 | ���ׂẴ��r�W���� |
RTX1220 | |
RTX1210 | |
RTX1200 | Rev.10.01.42�ȍ~ |
RTX830 | ���ׂẴ��r�W���� |
RTX810 | Rev.11.01.09�ȍ~ |
FWX120 | ���ׂẴ��r�W���� |
NVR700W | |
NVR510 | Rev.15.01.03�ȍ~ |
NVR500 | Rev.11.00.36�ȍ~ |
�@�� | ���r�W���� |
---|---|
vRX�V���[�Y | ���ׂẴ��r�W���� |
RTX3510 | |
RTX5000, RTX3500 | Rev.14.00.12�ȍ~ |
RTX3000 | Rev.9.00.60�ȍ~ |
RTX1300 | ���ׂẴ��r�W���� |
RTX1220 | |
RTX1210 | |
RTX1200 | Rev.10.01.59�ȍ~ |
RTX830 | ���ׂẴ��r�W���� |
RTX810 | Rev.11.01.21�ȍ~ |
FWX120 | Rev.11.03.08�ȍ~ |
NVR700W | ���ׂẴ��r�W���� |
NVR510 | Rev.15.01.03�ȍ~ |
NVR500 | Rev.11.00.36�ȍ~ |
tunnel select 1 tunnel template 8 10-20 tunnel select 2 tunnel template 100 200-300 400 �ȉ���2�̐ݒ�͓������e�������Ă���B tunnel select 1 tunnel template 2 ipsec tunnel 1 ipsec sa policy 1 1 esp aes-cbc sha-hmac ipsec ike encryption 1 aes-cbc ipsec ike group 1 modp1024 ipsec ike local address 1 192.168.0.1 ipsec ike pre-shared-key 1 text himitsu1 ipsec ike remote address 1 any ipsec ike remote name 1 pc tunnel enable 1 tunnel select 2 ipsec ike pre-shared-key 2 text himitsu2 tunnel select 1 ipsec tunnel 1 ipsec sa policy 1 1 esp aes-cbc sha-hmac ipsec ike encryption 1 aes-cbc ipsec ike group 1 modp1024 ipsec ike local address 1 192.168.0.1 ipsec ike pre-shared-key 1 text himitsu1 ipsec ike remote address 1 any ipsec ike remote name 1 pc tunnel enable 1 tunnel select 2 ipsec tunnel 2 ipsec sa policy 2 2 esp aes-cbc sha-hmac ipsec ike encryption 2 aes-cbc ipsec ike group 2 modp1024 ipsec ike local address 2 192.168.0.1 ipsec ike pre-shared-key 2 text himitsu2 ipsec ike remote address 2 any ipsec ike remote name 2 pc2 tunnel enable 2
���C�Z���X�� | �g����̏���l ( ���C�Z���X�{�����Ƃ̒l ) |
||||
---|---|---|---|---|---|
1�{ | 2�{ | 3�{ | 4�{ | 5�{ | |
YSL-VPN-EX1 | 100 | - | - | - | - |
YSL-VPN-EX2 | 300 | 500 | 700 | 900 | 1100 |
YSL-VPN-EX3 | 1500 | 2000 | 2500 | 3000 | - |
# show status l2tp ------------------- L2TP INFORMATION ------------------- Number of control table using Tunnel Control: 2, Session Control: 2 ... �S�̂�L2TP�g���l�����ƃZ�b�V������ TUNNEL[1] Information ... �g���l��[1]�̏���\�� Tunnel State: established ... �g���l���̏�� Version: L2TPv2 ... L2TP�̃o�[�W���� Local Tunnel ID: 10 ... �������̃g���l��ID Remote Tunnel ID: 7 ... ���葤�̃g���l��ID Local IP Address: 192.168.100.1 ... ������IP�A�h���X Remote IP Address: 203.0.113.2 ... �����IP�A�h���X Local Src port: 1701 ... �����̑��M���|�[�g�ԍ� Remote Src port: 1701 ... ����̑��M���|�[�g�ԍ� PP Bind: ANONYMOUS[1] ... �o�C���h����Ă���PP�C���^�t�F�[�X Vendor: VENDOR ... ���葤�̃x���_�[�� Hostname: HOST ... ���葤�̃z�X�g�� Next Transmit sequence(Ns): 2 ... ���M�V�[�P���X�ԍ� Next Receive sequence(Nr): 4 ... ��M�V�[�P���X�ԍ� Tunnel has 1 session. ... �g���l�����ێ�����Z�b�V������ Session Information ... �g���l��[1]���̃Z�b�V������� Session State: established ... �Z�b�V�����̏�� Local Session ID: 9 ... �������̃Z�b�V����ID Remote Session ID: 1 ... ���葤�̃Z�b�V����ID 30 seconds connection. ... �ʐM���� Received: 31 packets [2450 octets] ... ��M�p�P�b�g������ё��M�f�[�^�� Transmitted: 15 packets [517 octets] ... ���M�p�P�b�g������ё��M�f�[�^�� TUNNEL[2] Information ... �g���l��[2]�̏���\�� ��� |
# show status pp 1 PP[01]: L2TP�Z�b�V�����͐ڑ�����Ă��܂� �ڑ�����: �ʐM����: 54�b ��M: 74 �p�P�b�g [6280 �I�N�e�b�g] ���M: 23 �p�P�b�g [729 �I�N�e�b�g] PPP�I�v�V���� LCP Local: CHAP Magic-Number MRU, Remote: Magic-Number MRU IPCP Local: IP-Address, Remote: IP-Address Primary-DNS(192.168.100.1) PP IP Address Local: 192.168.100.1, Remote: 192.168.100.10 CCP: None �Ƃ���UserId: yamaha |
���C�Z���X�� | �g����̏���l ( ���C�Z���X�{�����Ƃ̒l ) |
||||
---|---|---|---|---|---|
1�{ | 2�{ | 3�{ | 4�{ | 5�{ | |
YSL-VPN-EX1 | 100 | - | - | - | - |
YSL-VPN-EX2 | 150 |
�z�X�g���F IP�A�h���X�F203.0.113.1(�Œ�) XXXX.aaX.netvolante.jp +--------------+ LAN2+----------+LAN1 | | L2TP |--------Internet--------| ���}�n |-----| +----+ | �N���C�A���g | PPPoE | ���[�^�[ | |----| PC | +--------------+ +----------+ | +----+ ���蓖�Ă���A�h���X�F | 192.168.100.10 | +----+ |----| PC | | +----+ �v���C�x�[�g�l�b�g���[�N 192.168.100.0/24
�y�o�H�ݒ�z ip route default gateway pp 1 �yLAN�ݒ�z ip lan1 address 192.168.100.1/24 ip lan1 proxyarp on �y�v���o�C�_�Ƃ̐ڑ��ݒ�z pp select 1 pp always-on on pppoe use lan2 pp auth accept (�F�ؕ���) pp auth myname (���[�U��) (�p�X���[�h) ppp lcp mru on 1454 ppp ipcp ipaddress on ppp ipcp msext on ppp ccp type none ip pp mtu 1454 ip pp nat descriptor 1 netvolante-dns hostname host pp server=1 XXXX.aaX.netvolante.jp pp enable 1 �yL2TP�ڑ�������邽�߂̐ݒ�z pp select 2 pp bind tunnel1 pp auth request (�F�ؕ���) pp auth username l2tp_user1 l2tp_password1 ppp ipcp ipaddress on ppp ipcp msext on ip pp remote address 192.168.100.10 pp enable 2 �yL2TP�ڑ��Ŏg�p����g���l���̐ݒ�z tunnel select 1 tunnel encapsulation l2tp tunnel endpoint address 203.0.113.1 ipsec tunnel 101 ipsec sa policy 101 1 esp (�Í��A���S���Y��) (�F�A���S���Y��) ipsec ike keepalive use 1 off ipsec ike local address 1 192.168.100.1 ipsec ike pre-shared-key 1 text yamaha1 ipsec ike remote address 1 203.0.113.1 l2tp tunnel disconnect time off l2tp keepalive use on 10 3 l2tp keepalive log on l2tp syslog on ip tunnel tcp mss limit auto tunnel enable 1 �yNAT�ݒ�z nat descriptor type 1 masquerade nat descriptor address outer 1 ipcp nat descriptor address inner 1 auto nat descriptor masquerade static 1 1 192.168.100.1 esp nat descriptor masquerade static 1 2 192.168.100.1 udp 500 �yDNS�ݒ�z dns server (�v���o�C�_���w�肳�ꂽDNS�T�[�o�[�̃A�h���X) �yIPsec�̃g�����X�|�[�g���[�h�ݒ�z ipsec transport 1 101 udp 1701 ipsec auto refresh on �yL2TP�ݒ�z l2tp service on |
���v���o�C�_�ڑ��p��PP�C���^�t�F�[�X�Ƀt�B���^��ݒ肵�Ă���ꍇ�ɂ� �ȉ��̃t�B���^�ݒ��lj�����K�v������܂��B���ɉ����ēK�Ȑݒ� ��lj����Ă��������B pp select 1 ip pp secure filter in ... 200080 200081 200082 ... ip filter 200080 pass * 192.168.100.1 esp * * ip filter 200081 pass * 192.168.100.1 udp * 500 ip filter 200082 pass * 192.168.100.1 udp * 1701
�z�X�g���F IP�A�h���X�F�s�� XXXX.aaX.netvolante.jp +---------------+ LAN2+----------+LAN1 | | L2TP |-------------Internet--------| ���}�n |-----| +----+ | �N���C�A���gA | | | PPPoE | ���[�^�[ | |----| PC | +---------------+ | | +----------+ | +----+ ���蓖�Ă���A�h���X�͈́F | | | 192.168.100.10-192.168.100.20 | | | +----+ | | |----| PC | IP�A�h���X�F�s�� | | | +----+ +---------------+ | | �v���C�x�[�g�l�b�g���[�N | L2TP |---------------+ | 192.168.100.0/24 | �N���C�A���gB | | +---------------+ | | IP�A�h���X�F�s�� | +---------------+ | | L2TP |-----------------+ | �N���C�A���gC | +---------------+
�y�o�H�ݒ�z ip route default gateway pp 1 �yLAN�ݒ�z ip lan1 address 192.168.100.1/24 ip lan1 proxyarp on �y�v���o�C�_�Ƃ̐ڑ��ݒ�z pp select 1 pp always-on on pppoe use lan2 pp auth accept (�F�ؕ���) pp auth myname (���[�U��) (�p�X���[�h) ppp lcp mru on 1454 ppp ipcp ipaddress on ppp ipcp msext on ppp ccp type none ip pp mtu 1454 ip pp nat descriptor 1 netvolante-dns hostname host pp server=1 XXXX.aaX.netvolante.jp pp enable 1 �yL2TP�ڑ�������邽�߂̐ݒ�z pp select anonymous pp bind tunnel1 tunnel2 tunnel3 pp auth request (�F�ؕ���) pp auth username l2tp_user1 l2tp_password1 pp auth username l2tp_user2 l2tp_password2 pp auth username l2tp_user3 l2tp_password3 ppp ipcp ipaddress on ppp ipcp msext on ip pp remote address pool 192.168.100.10-192.168.100.20 pp enable anonymous �yL2TP�ڑ��Ŏg�p����g���l���̐ݒ�z tunnel select 1 tunnel encapsulation l2tp ipsec tunnel 101 ipsec sa policy 101 1 esp (�Í��A���S���Y��) (�F�A���S���Y��) ipsec ike keepalive use 1 off ipsec ike local address 1 192.168.100.1 ipsec ike pre-shared-key 1 text yamaha1 ipsec ike remote address 1 any l2tp tunnel disconnect time off l2tp keepalive use on 10 3 l2tp keepalive log on l2tp syslog on ip tunnel tcp mss limit auto tunnel enable 1 �yL2TP�ڑ��Ŏg�p����g���l���̐ݒ�z tunnel select 2 tunnel encapsulation l2tp ipsec tunnel 102 ipsec sa policy 102 2 esp (�Í��A���S���Y��) (�F�A���S���Y��) ipsec ike keepalive use 2 off ipsec ike local address 2 192.168.100.1 ipsec ike pre-shared-key 2 text yamaha1 ipsec ike remote address 2 any l2tp tunnel disconnect time off l2tp keepalive use on 10 3 l2tp keepalive log on l2tp syslog on ip tunnel tcp mss limit auto tunnel enable 2 �yL2TP�ڑ��Ŏg�p����g���l���̐ݒ�z tunnel select 3 tunnel encapsulation l2tp ipsec tunnel 103 ipsec sa policy 103 3 esp (�Í��A���S���Y��) (�F�A���S���Y��) ipsec ike keepalive use 3 off ipsec ike local address 3 192.168.100.1 ipsec ike pre-shared-key 3 text yamaha1 ipsec ike remote address 3 any l2tp tunnel disconnect time off l2tp keepalive use on 10 3 l2tp keepalive log on l2tp syslog on ip tunnel tcp mss limit auto tunnel enable 3 �yNAT�ݒ�z nat descriptor type 1 masquerade nat descriptor address outer 1 ipcp nat descriptor address inner 1 auto nat descriptor masquerade static 1 1 192.168.100.1 esp nat descriptor masquerade static 1 2 192.168.100.1 udp 500 �yIPsec�̃g�����X�|�[�g���[�h�ݒ�z ipsec transport 1 101 udp 1701 ipsec transport 2 102 udp 1701 ipsec transport 3 103 udp 1701 ipsec auto refresh on �yL2TP�ݒ�z l2tp service on |
���v���o�C�_�ڑ��p��PP�C���^�t�F�[�X�Ƀt�B���^��ݒ肵�Ă���ꍇ�ɂ� �ȉ��̃t�B���^�ݒ��lj�����K�v������܂��B���ɉ����ēK�Ȑݒ� ��lj����Ă��������B pp select 1 ip pp secure filter in ... 200080 200081 200082 ... ip filter 200080 pass * 192.168.100.1 esp * * ip filter 200081 pass * 192.168.100.1 udp * 500 ip filter 200082 pass * 192.168.100.1 udp * 1701
�z�X�g���F IP�A�h���X�F�s�� XXXX.aaX.netvolante.jp +--------------+ +---------+ LAN2+----------+LAN1 | | L2TP |-----| NAT�@�� |-------Internet--------| ���}�n |-----| +----+ | �N���C�A���g | | | PPPoE | ���[�^�[ | |----| PC | +--------------+ +---------+ +----------+ | +----+ ���蓖�Ă���A�h���X�͈́F | 192.168.100.10-192.168.100.20 | +----+ |----| PC | | +----+ �v���C�x�[�g�l�b�g���[�N 192.168.100.0/24
�y�o�H�ݒ�z ip route default gateway pp 1 �yLAN�ݒ�z ip lan1 address 192.168.100.1/24 ip lan1 proxyarp on �y�v���o�C�_�Ƃ̐ڑ��ݒ�z pp select 1 pp always-on on pppoe use lan2 pp auth accept (�F�ؕ���) pp auth myname (���[�U��) (�p�X���[�h) ppp lcp mru on 1454 ppp ipcp ipaddress on ppp ipcp msext on ppp ccp type none ip pp mtu 1454 ip pp nat descriptor 1 netvolante-dns hostname host pp server=1 XXXX.aaX.netvolante.jp pp enable 1 �yL2TP�ڑ�������邽�߂̐ݒ�z pp select anonymous pp bind tunnel1 pp auth request (�F�ؕ���) pp auth username l2tp_user1 l2tp_password1 ppp ipcp ipaddress on ppp ipcp msext on ip pp remote address pool 192.168.100.10-192.168.100.20 pp enable anonymous �yL2TP�ڑ��Ŏg�p����g���l���̐ݒ�z tunnel select 1 tunnel encapsulation l2tp ipsec tunnel 101 ipsec sa policy 101 1 esp (�Í��A���S���Y��) (�F�A���S���Y��) ipsec ike keepalive use 1 off ipsec ike local address 1 192.168.100.1 ipsec ike nat-traversal 1 on ipsec ike pre-shared-key 1 text yamaha1 ipsec ike remote address 1 any l2tp tunnel disconnect time off l2tp keepalive use on 10 3 l2tp keepalive log on l2tp syslog on ip tunnel tcp mss limit auto tunnel enable 1 �yNAT�ݒ�z nat descriptor type 1 masquerade nat descriptor address outer 1 ipcp nat descriptor address inner 1 auto nat descriptor masquerade static 1 1 192.168.100.1 esp nat descriptor masquerade static 1 2 192.168.100.1 udp 500 nat descriptor masquerade static 1 3 192.168.100.1 udp 4500 �yIPsec�̃g�����X�|�[�g���[�h�ݒ�z ipsec transport 1 101 udp 1701 ipsec auto refresh on �yL2TP�ݒ�z l2tp service on |
���v���o�C�_�ڑ��p��PP�C���^�t�F�[�X�Ƀt�B���^��ݒ肵�Ă���ꍇ�ɂ� �ȉ��̃t�B���^�ݒ��lj�����K�v������܂��B���ɉ����ēK�Ȑݒ� ��lj����Ă��������B pp select 1 ip pp secure filter in ... 200080 200081 200082 200083 ... ip filter 200080 pass * 192.168.100.1 esp * * ip filter 200081 pass * 192.168.100.1 udp * 500 ip filter 200082 pass * 192.168.100.1 udp * 1701 ip filter 200083 pass * 192.168.100.1 udp * 4500
�z�X�g���F IP�A�h���X�F�s�� XXXX.aaX.netvolante.jp +--------------+ LAN2+----------+LAN1 | | L2TP |-------------Internet--------| ���}�n |-----| +----+ | �N���C�A���g | | PPPoE | ���[�^�[ | |----| PC | +--------------+ | +----------+ | +----+ ���蓖�Ă���A�h���X�͈́F | | 192.168.100.10-192.168.100.20 | | +----+ | |----| PC | IP�A�h���X�F�s�� | | +----+ +--------------+ | �v���C�x�[�g�l�b�g���[�N | PPTP |---------------+ 192.168.100.0/24 | �N���C�A���g | +--------------+
�y�o�H�ݒ�z ip route default gateway pp 1 �yLAN�ݒ�z ip lan1 address 192.168.100.1/24 ip lan1 proxyarp on �y�v���o�C�_�Ƃ̐ڑ��ݒ�z pp select 1 pp always-on on pppoe use lan2 pp auth accept (�F�ؕ���) pp auth myname (���[�U��) (�p�X���[�h) ppp lcp mru on 1454 ppp ipcp ipaddress on ppp ipcp msext on ppp ccp type none ip pp mtu 1454 ip pp nat descriptor 1 netvolante-dns hostname host pp server=1 XXXX.aaX.netvolante.jp pp enable 1 �yL2TP�ڑ���PPTP�ڑ�������邽�߂̐ݒ�z pp select anonymous pp bind tunnel1-tunnel2 pp auth request (�F�ؕ���) ��L2TP�N���C�A���g��PPTP�N���C�A���g�̗����őΉ����Ă���F�ؕ��� pp auth username l2tp_user1 l2tp_password1 pp auth username pptp_user1 pptp_password1 ppp ipcp ipaddress on ppp ipcp msext on ppp ccp type (CCP���k����) ��L2TP�N���C�A���g��PPTP�N���C�A���g�̗����őΉ����Ă���CCP���k���� ip pp remote address pool 192.168.100.10-192.168.100.20 pp enable anonymous �yL2TP�ڑ��Ŏg�p����g���l���̐ݒ�z tunnel select 1 tunnel encapsulation l2tp ipsec tunnel 101 ipsec sa policy 101 1 esp (�Í��A���S���Y��) (�F�A���S���Y��) ipsec ike keepalive use 1 off ipsec ike local address 1 192.168.100.1 ipsec ike pre-shared-key 1 text yamaha1 ipsec ike remote address 1 any l2tp tunnel disconnect time off l2tp keepalive use on 10 3 l2tp keepalive log on l2tp syslog on ip tunnel tcp mss limit auto tunnel enable 1 �yPPTP�ڑ��Ŏg�p����g���l���̐ݒ�z tunnel select 2 tunnel encapsulation pptp pptp tunnel disconnect time off tunnel enable 2 �yNAT�ݒ�z nat descriptor type 1 masquerade nat descriptor address outer 1 ipcp nat descriptor address inner 1 auto nat descriptor masquerade static 1 1 192.168.100.1 esp nat descriptor masquerade static 1 2 192.168.100.1 udp 500 nat descriptor masquerade static 1 3 192.168.100.1 tcp 1723 nat descriptor masquerade static 1 4 192.168.100.1 gre �yIPsec�̃g�����X�|�[�g���[�h�ݒ�z ipsec transport 1 101 udp 1701 ipsec auto refresh on �yL2TP�ݒ�z l2tp service on �yPPTP�ݒ�z pptp service on |
���v���o�C�_�ڑ��p��PP�C���^�t�F�[�X�Ƀt�B���^��ݒ肵�Ă���ꍇ�ɂ� �ȉ��̃t�B���^�ݒ��lj�����K�v������܂��B���ɉ����ēK�Ȑݒ� ��lj����Ă��������B pp select 1 ip pp secure filter in ... 200080 200081 200082 200083 200084 ... ip filter 200080 pass * 192.168.100.1 esp * * ip filter 200081 pass * 192.168.100.1 udp * 500 ip filter 200082 pass * 192.168.100.1 udp * 1701 ip filter 200083 pass * 192.168.100.1 tcp * 1723 ip filter 200084 pass * 192.168.100.1 gre * *
�z�X�g���F IP�A�h���X�F�s�� XXXX.aaX.netvolante.jp +---------------+ LAN2+----------+LAN1 | | L2TP |-------------Internet--------| ���}�n |-----| +----+ | �N���C�A���gA | | | PPPoE | ���[�^�[ | |----| PC | +---------------+ | | +----------+ | +----+ ���蓖�Ă���A�h���X�͈́F | | | 192.168.100.10-192.168.100.20 | | | +----+ | | |----| PC | IP�A�h���X�F�s�� | | | +----+ +---------------+ | | �v���C�x�[�g�l�b�g���[�N | L2TP |---------------+ | 192.168.100.0/24 | �N���C�A���gB | | +---------------+ | | IP�A�h���X�F�s�� | +---------------+ | | L2TP |-----------------+ | �N���C�A���gC | +---------------+
�y�o�H�ݒ�z ip route default gateway pp 1 �yLAN�ݒ�z ip lan1 address 192.168.100.1/24 ip lan1 proxyarp on �y�v���o�C�_�Ƃ̐ڑ��ݒ�z pp select 1 pp always-on on pppoe use lan2 pp auth accept (�F�ؕ���) pp auth myname (���[�U��) (�p�X���[�h) ppp lcp mru on 1454 ppp ipcp ipaddress on ppp ipcp msext on ppp ccp type none ip pp mtu 1454 ip pp nat descriptor 1 netvolante-dns hostname host pp server=1 XXXX.aaX.netvolante.jp pp enable 1 �yL2TP�ڑ�������邽�߂̐ݒ�z pp select anonymous pp bind tunnel1 tunnel2 tunnel3 pp auth request (�F�ؕ���) pp auth username l2tp_user1 l2tp_password1 pp auth username l2tp_user2 l2tp_password2 pp auth username l2tp_user3 l2tp_password3 ppp ipcp ipaddress on ppp ipcp msext on ip pp remote address pool 192.168.100.10-192.168.100.20 pp enable anonymous �yL2TP�ڑ��Ŏg�p����g���l���̐ݒ�z tunnel select 1 tunnel template 2-3 tunnel encapsulation l2tp ipsec tunnel 1 ipsec sa policy 1 1 esp (�Í��A���S���Y��) (�F�A���S���Y��) ipsec ike keepalive use 1 off ipsec ike local address 1 192.168.100.1 ipsec ike nat-traversal 1 on ipsec ike pre-shared-key 1 text yamaha1 ipsec ike remote address 1 any l2tp tunnel disconnect time off l2tp keepalive use on 10 3 l2tp keepalive log on l2tp syslog on tunnel enable 1 �yNAT�ݒ�z nat descriptor type 1 masquerade nat descriptor address outer 1 ipcp nat descriptor address inner 1 auto nat descriptor masquerade static 1 1 192.168.100.1 esp nat descriptor masquerade static 1 2 192.168.100.1 udp 500 nat descriptor masquerade static 1 3 192.168.100.1 udp 4500 �yIPsec�̃g�����X�|�[�g���[�h�ݒ�z ipsec transport 1 1 udp 1701 ipsec transport template 1 2-3 ipsec auto refresh on �yL2TP�ݒ�z l2tp service on |
���v���o�C�_�ڑ��p��PP�C���^�t�F�[�X�Ƀt�B���^��ݒ肵�Ă���ꍇ�ɂ� �ȉ��̃t�B���^�ݒ��lj�����K�v������܂��B���ɉ����ēK�Ȑݒ� ��lj����Ă��������B pp select 1 ip pp secure filter in ... 200080 200081 200082 200083 ... ip filter 200080 pass * 192.168.100.1 esp * * ip filter 200081 pass * 192.168.100.1 udp * 500 ip filter 200082 pass * 192.168.100.1 udp * 1701 ip filter 200083 pass * 192.168.100.1 udp * 4500
�p�u���b�NIP(Erastic IP�Ȃ�) +--------------+ LAN2+-----------------+LAN1 | | L2TP |---------Internet--------| vRX |-----| +--------+ | �N���C�A���g | | on AWS | |----| Server | +--------------+ +-----------------+ | +--------+ ���蓖�Ă���A�h���X�F �v���C�x�[�g�l�b�g���[�N 172.16.0.10�`100 192.168.10.0/24 VPC�T�u�l�b�g 192.168.20.0/24 | 192.168.10.0/24 �y�d�v�z �EAWS�̐����̂��߁AvRX�Ɋ��蓖�ĂĂ���T�u�l�b�g�Ƃ͈قȂ�T�u�l�b�g�̃A�h���X��L2TP�N���C�A���g�Ɋ��蓖�ĂĂ��܂��B �EL2TP�N���C�A���g�Ɋ��蓖�Ă���A�h���X��AWS�̃Z�L�����e�B�[�O���[�v���C���o�E���h�ɒlj����ĕK�v�ȒʐM�v���g�R���������Ă��������B
�y���[�U�[ID�ƃp�X���[�h�̐ݒ�z vrx user yamaha * �y�o�H�ݒ�z ip route default gateway dhcp lan2 �yLAN�ݒ�z ip lan1 address dhcp ip lan2 address dhcp �yL2TP�ڑ�������邽�߂̐ݒ�z pp select anonymous pp bind tunnel1 pp auth request (�F�ؕ���) pp auth username l2tp_user1 l2tp_password1 ppp ipcp ipaddress on ppp ipcp msext on ip pp remote address pool 172.16.0.10-172.16.0.100 pp enable anonymous �yL2TP�ڑ��Ŏg�p����g���l���̐ݒ�z tunnel select 1 tunnel encapsulation l2tp ipsec tunnel 101 ipsec sa policy 101 1 esp (�Í��A���S���Y��) (�F�A���S���Y��) ipsec ike keepalive use 1 off ipsec ike nat-traversal 1 on ipsec ike pre-shared-key 1 text yamaha1 ipsec ike remote address 1 any l2tp tunnel disconnect time off l2tp syslog on ip tunnel tcp mss limit auto tunnel enable 1 �yIPsec�̃g�����X�|�[�g���[�h�ݒ�z ipsec auto refresh on ipsec transport 1 101 udp 1701 �yTELNET�ݒ�z telnetd service off �yDNS�ݒ�z dns server dhcp lan2 �yL2TP�ݒ�z l2tp service on �ySSH�ݒ�z sshd service on sshd host key generate * |
�ʐM���Ǝ� | �@�� | OS�o�[�W���� |
---|---|---|
NTT�h�R�� | Xperia arc SO-01C | Android 2.3.2 |
Galaxy S2 SC-02C | Android 2.3.3 | |
Galaxy S4 SC-04E | Android 4.2.2 | |
Galaxy S5 SC-04F | Android 4.4.2 Android 5.0 Android 6.0.1 |
|
XPERIA XZ SO-01J | Android 8.0.0(*) | |
KDDI | Xperia acro IS11S | Android 2.3.3 |
iPhone 4S | iOS 9.3.6(*) | |
iPhone 5 | iOS 7.0.4 | |
iPhone 5S | iOS 12.4(*) | |
iPhone 6 | iOS 12.4.1(*) | |
SoftBank | iPhone 4 | iOS 4.3.3 iOS 5.0 |
iPad 2 | iOS 4.3.3 iOS 5.0 iOS 6.0.1 |
|
- | SonyTablet | Android 4.2.2(*) |
Nexus 4 | Android 4.3 | |
Nexus7 2013 | Android 6.0.1(*) | |
ASUS ZenPad 3 8.0 | Android 6.1.1(*) | |
Nexus9 2014 | Android 7.1.1(*) | |
iPad Air 2 (WiFi���f��) | iOS 8.1.3 | |
iPad mini 16G (WiFi���f��) | iOS 9.3.5(*) | |
iPad Pro 32G (WiFi���f��) | iOS 12.4.1(*) |
(*)2019�N9�����_�̕��Ђɂ����鎎�����ʂɊ�Â��܂��B �܂��A(*)���Ȃ�OS�o�[�W�����ɂ��܂��Ă�2016�N9�����_�̕��Ђɂ����鎎�����ʂɊ�Â��܂��B ���e�[���̏�����Ԃ���A�v���P�[�V�����������C���X�g�[�����Ă��Ȃ���ԂŁA �e�[�����烄�}�n���[�^�[�ւ�L2TP/IPsec�̐ڑ�������m�F�������̂ł��B ���쌟�ɂ͊e�[���ɕW�����ڂ���Ă���L2TP/IPsec�ڑ���p���Ă��܂��B ���ۂ̂����p�ɂ������ẮA���q�l���ł̓�������̏�A�����p���������B ��Microsoft�А�Windows OS��L2TP/IPsec�ڑ��̓T�|�[�g���܂���B �����쌟�ł́A�ڑ��E�ʐM�E�ؒf������ɍs���邱�Ƃ��m�F���Ă��܂��B �����Ԃ̐ڑ������͍s���Ă���܂���B ��Android 6, Android 4�n��Android 7�n�̈ꕔ��OS�ł́A�ؒf���Ƀ��[�^�[�ɑ��Đؒf���b�Z�[�W�𑗐M���Ȃ����̂�����܂��B ���̂��߁A���[�^�[���ŃZ�b�V�������c���Ă��܂��A���̐ڑ��������Ɏ邱�Ƃ��ł��Ȃ��Ȃ�܂��B ��Ƃ��āA���[�^�[���ő����ɐؒf�����m�ł���悤L2TP�L�[�v�A���C�u��L���ɂ��邱�Ƃ�E�߂܂��B���[�^�[���Őݒ�\�ȃp�����[�^�l�ł���AIPsec�Í����A���S���Y���A�F�A���S���Y��
�F�A���S���Y�� | ||||||
md5-hmac | sha-hmac | sha256-hmac | �ȗ� | |||
���� �A���S���Y�� |
des-cbc | �� | �� | �~ | �~ | |
3des-cbc | �� | �� | �~ | �~ | ||
aes-cbc | �� | �� | �~ | �~ | ||
aes256-cbc | �~ | �~ | �~ | �~ |
�F�A���S���Y�� | ||||||
md5-hmac | sha-hmac | sha256-hmac | �ȗ� | |||
���� �A���S���Y�� |
des-cbc | �� | �� | �� | �~ | |
3des-cbc | �� | �� | �� | �~ | ||
aes-cbc | �� | �� | �� | �~ | ||
aes256-cbc | �� | �� | �� | �~ |
�F�A���S���Y�� | ||||||
md5-hmac | sha-hmac | sha256-hmac | �ȗ� | |||
���� �A���S���Y�� |
des-cbc | �� | �� | �~ | �~ | |
3des-cbc | �� | �� | �~ | �~ | ||
aes-cbc | �� | �� | �~ | �~ | ||
aes256-cbc | �� | �� | �~ | �~ |
�F�A���S���Y�� | ||||||
md5-hmac | sha-hmac | sha256-hmac | �ȗ� | |||
���� �A���S���Y�� |
des-cbc | �~ | �~ | �~ | �~ | |
3des-cbc | �~ | �� | �� | �~ | ||
aes-cbc | �~ | �� | �� | �~ | ||
aes256-cbc | �~ | �� | �� | �~ |
�F�A���S���Y�� | ||||||
md5-hmac | sha-hmac | sha256-hmac | �ȗ� | |||
���� �A���S���Y�� |
des-cbc | �~ | �~ | �~ | �~ | |
3des-cbc | �� | �� | �~ | �~ | ||
aes-cbc | �� | �� | �~ | �~ | ||
aes256-cbc | �� | �� | �~ | �~ |
�ʐM���Ǝ� | �@�� | OS�o�[�V���� | �F�ؕ��� | |||
pap | chap | mschap | mschap-v2 | |||
NTT�h�R�� | XPERIA XZ SO-01J | Android 8.0.0 | �� | �� | �� | �� |
KDDI | iPhone 6 | iOS 12.4.1 | �� | �� | �� | �� |
- | SonyTablet | Android 4.2.2 | �� | �� | �� | �� |
- | Nexus7 2013 | Android 6.0.1 | �� | �� | �� | �� |
- | Nexus9 2014 | Android 7.1.1 | �� | �� | �� | �� |
�����Њ��ł̐ڑ��m�F���ʂł���A���q�l�̊��Őڑ���ۏ�����̂ł͂���܂���B �����p�̍ۂɂ͎��O�ɏ\���Ȍ������肢�������܂��B
�����ׂĂ�iOS�[�������L�ݒ�菇�ʂ��L2TP/IPsec�N���C�A���g��ݒ�ł���Ƃ͌���܂���B �ڂ����ݒ��iOS�[���̃}�j���A�����Q�Ƃ��Ă��������B ���܂��A�摜�́uiPhone 6�v���g�p���Ă��܂��B
-> | ||
-> |
|
-> |
�����ׂĂ�Android�[�������L�ݒ�菇�ʂ��L2TP/IPsec�N���C�A���g��ݒ�ł���Ƃ͌���܂���B �ڂ����ݒ��Android�[���̃}�j���A�����Q�Ƃ��Ă��������B ���܂��A�摜�́uXPERIA XZ SO-01J�v���g�p���Ă��܂��B
-> | ||
-> |
|
-> |
�{�@�\�ɂ����ďo�͂����SYSLOG���b�Z�[�W���ȉ��Ɏ����܂��B
���ۂɏo�͂���郁�b�Z�[�W�ɂ� "[L2TP]" �Ƃ����v���t�B�b�N�X���t������܂��B
���x�� | �o�̓��b�Z�[�W | �Ӗ� |
---|---|---|
INFO | opend port 1701/udp | UDP�̃|�[�g�ԍ�1701���J�� |
closed port 1701/udp | UDP�̃|�[�g�ԍ�1701��� | |
TUNNEL[XX] connected from IP�A�h���X | L2TP�N���C�A���g����R�l�N�V�����m���v��(SCCRQ)����M | |
TUNNEL[XX] tunnel �g���l���ԍ� established | L2TP�g���l�����m�� | |
TUNNEL[XX] session �Z�b�V�����ԍ� established | L2TP�Z�b�V�������m�� | |
TUNNEL[XX] disconnecting tunnel �g���l���ԍ� | L2TP�g���l���̐ؒf���������s�� | |
TUNNEL[XX] disconnect tunnel �g���l���ԍ� complete | L2TP�g���l���̍폜������ | |
TUNNEL[XX] disconnect session �Z�b�V�����ԍ� complete | L2TP�Z�b�V�����̍폜������ | |
state timer for waiting L2TP���䃁�b�Z�[�W expired | L2TP���䃁�b�Z�[�W�̎�M�҂��^�C�}�[�������������߁AL2TP�g���l���̐ؒf�������J�n | |
disconnect timer expired tunnel �g���l���ԍ� | L2TP�ؒf�^�C�}�[�������������߁AL2TP�g���l���̐ؒf�������J�n | |
keepalive timer expired tunnel �g���l���ԍ� | L2TP�L�[�v�A���C�u�Őڑ���̃_�E�������o�������߁AL2TP�g���l���̐ؒf�������J�n | |
authentication error tunnel �g���l���ԍ� | L2TP�g���l���F�G���[�ɂ��AL2TP�g���l���̐ؒf�������J�n | |
DEBUG | can't find tunnel number | L2TP�ڑ��Ŏg�p�����g���l���C���^�t�F�[�X���݂���Ȃ��B ipsec ike remote address�R�}���h�Őڑ������IP�A�h���X���Œ肵�Ă���Ƃ��ɁA tunnel endpoint address�R�}���h�Őڑ������IP�A�h���X��ݒ肢�Ȃ��ꍇ�Ȃǂɏo�͂���܂��B |
can't find valid pp interface | L2TP�ڑ��Ŏg�p�����g���l���C���^�t�F�[�X���o�C���h���ꂽPP�C���^�t�F�[�X���݂���Ȃ��B pp bind�R�}���h�ɂ���ăg���l���C���^�t�F�[�X���o�C���h����Ă��Ȃ��ꍇ��A �o�C���h���ꂽ PP�C���^�t�F�[�X�����łɎg�p����Ă���ꍇ�ɏo�͂���܂��B |
|
DEBUG (l2tp syslog on�ݒ莞) �ڑ�����ؒf�܂ł� ��A�̃��O�� |
recv message AVPs : -+ (0)message type SCCRQ | SCCRQ�̎�M���� (2)protocol version 1 revision 0 | (7)hostname anonymous | (�ԍ�) ���� �ݒ�l (3)framing capability Abit:1 Sbit:0 | �ԍ�... AVP�̑����ԍ� (9)assigned tunnel id 61471 | ����... AVP�̎�� (10)receive window size 1 | �ݒ�l... AVP�Œʒm���ꂽ��� recv SCCRQ in idle from 203.0.113.1 -+ TUNNEL[1] connected from 203.0.113.1 L2TP�ڑ����m�F(INFO) send message AVPs : -+ set (0)message type SCCRP | SCCRP�̑��M���� set (2)protocol version 1 revision 0 | set (3)framing capability sync | set (�ԍ�) ���� �ݒ�l set (4)bearer capability 0 | set (6)firmware revision 0x500 | �ԍ�... AVP�̑����ԍ� set (7)hostname RTX1200 | ����... AVP�̎�� set (8)vendorname YAMAHA Corporation | �ݒ�l... AVP�Ɋi�[���đ���ɒʒm������ set (9)assigned tunnel id 32882 | set (10)receive window size 1 | send SCCRP to 203.0.113.1 -+ recv message AVPs : -+ (0)message type SCCCN | SCCCN�̎�M���� recv SCCCN in wait_ctl_conn from 203.0.113.1 -+ send ZLB to 203.0.113.1 ZLB�̑��M���� TUNNEL[1] tunnel 32882 established L2TP�g���l���̊m��(INFO) recv message AVPs : -+ (0)message type ICRQ | ICRQ�̎�M���� (14)assigned session id 6819 | (15)call serial number 1548737386 | recv ICRQ in idle from 203.0.113.1 -+ send message AVPs : -+ set (0)message type ICRP | ICRP�̑��M���� set (14)assigned session id 16892 | send ICRP to 203.0.113.1 -+ recv message AVPs : -+ (0)message type ICCN | ICCN�̎�M���� (24)tx connect speed 100Mbit/s | (19)framing type 3 | recv ICCN in wait_connect from 203.0.113.1 -+ send ZLB to 203.0.113.1 ZLB�̑��M���� TUNNEL[1] session 16892 established L2TP�Z�b�V�����̊m��(INFO) recv message AVPs : -+ (0)message type StopCCN | StopCCN�̎�M���� (9)assigned StopCCN tunnel id 61471 | (1)result code 6 | recv StopCCN in established from 203.0.113.1 -+ send ZLB to 203.0.113.1 ZLB�̑��M���� TUNNEL[1] disconnect session 16892 complete L2TP�Z�b�V�����̍폜����(INFO) TUNNEL[1] disconnect tunnel 32882 complete L2TP�g���l���̍폜����(INFO) |
|
DEBUG (l2tp keepalive use on�ݒ莞) |
set (0)message type HELLO keepalive HELLO send to 203.0.113.1 HELLO�̑��M���� recv ZLB from 203.0.113.1 HELLO�ɑ���ZLB����M set (0)message type HELLO -+ keepalive HELLO send to 203.0.113.1 | L2TP�L�[�v�A���C�u�̃^�C�}�[�� keepalive timeout count=6 | �������ă^�C���A�E�g���J�E���g set (0)message type HELLO | keepalive HELLO send to 203.0.113.1 | keepalive timeout count=5 | ��� | set (0)message type HELLO | keepalive HELLO send to 203.0.113.1 | L2TP�L�[�v�A���C�u�ɂ���ă_�E�������m keepalive timeout count=1 -+ disconnecting tunnel 4795 L2TP�g���l���̐ؒf�J�n(INFO) send Message AVPs : -+ set (0)message type StopCCN | StopCCN�̑��M���� set (9)assigned tunnel id 4795 | set (1)resultcode 2 | send StopCCN to 203.0.113.1 -+ |