IPv6 ã« NAT ãç¡ããã¨ã®å½±é¿
æã家㫠IPv6 ç°å¢ããã£ã¦ãã¾ããããã¬ããå ãã¯ã¹ãã®åç·ã«ãã¦ãISP å´ã«ç³ãè¾¼ãã§ãIPoEï¼ãããããã¤ãã£ãæ¹å¼ï¼ã§ IPv6 ã®ã¤ã³ã¿ã¼ãããã«ã¤ãªããã¾ããã
ãããããå¤ãã®ä¸è¬å®¶åºã§ããã°ãä»æã®ã«ã¼ã¿ããç¨æããã°ãç¹æ®µãæèãããã¨ãªããIPv6 ã«ã¤ãªããç°å¢ã«ãªãã¨æãã¾ããããã¡ãµã¼ãããã£ã¦ãããèªå® å 㯠IPv4 ã§ååãã¨èããã°ãä½ãåé¡ã¯ããã¾ããã
ããä¸å¿ãåã®å¤§å°ã§æè¡ç³»ãµã©ãªã¼ãã³ã®ç«¯ããã¨ãã¦çæ´»ã®ç³§ãå¾ã¦ãã身ã¨ãã¦ã¯ãããã¡ LAN ã§ã IPv6 ã使ããªãã§ã©ããããã¨ãç¡é§ãªåªåãããã®ã§ãã(^^;
IPv6 ã¨ã¯
ãªãã¦è©±ã¯ã©ãã§ãããã§ãããç«æ´¾ãªå°é家ã®æ¹ã ããããã解説ãæ¸ãã¦ãã¾ãã
NAT ãç¡ã
ãããå²ã¨æåãªè©±ã ã¨æãã¾ãããããããNAT ã«ãã£ã¦ã°ãã¼ãã«ã¢ãã¬ã¹ã延å½ãããã¨ããã¢ã¤ãã¢ãåºãåã«ãã次ä¸ä»£ã® IP ãä½ããªããã°ãã¢ãã¬ã¹ãæ¯æ¸ãããã¨è¨ããã¦ã¾ãã*1ã
æ ã«ããã©ããã¯åããã¾ããããIPv6 ã«ã¯ NAT ãããã¾ãããã¨ããäºã¯ã©ãããäºãã¨ããã¨ããã¤ã³ã¿ã¼ãããã«ç¹ããããã°ãæ«ç«¯ã®ç«¯æ«ãä¸ã¤ä¸ã¤ã«ãã°ãã¼ãã«ã¢ãã¬ã¹ãæã¤ã¹ããã¨ããäºã«ãªãã¾ãã
å®éãIPv6 ã«å¯¾å¿ããã家åºç¨ããã¼ããã³ãã«ã¼ã¿ã§ãIPv6 ã§ã¤ãªããç°å¢ã«ãªãã¨ãIPv6 ã®ã¢ãã¬ã¹ã®èªåæ§æã«ãã£ã¦ãããã¡ã®ä¸ã® PC ã«ã°ãã¼ãã«ãª IPv6 ã¢ãã¬ã¹ãä»ä¸ããã¾ãããã®ç¶æ ã§ãä¾ãã° Google ã«ç¹ãã¨ãã©ãã«ã NAT ãå ¥ãããã°ãã¼ãã«ãª IPv6 ã¢ãã¬ã¹ã§ã¤ãªãã£ã¦ãã¾ãã
å人åãã®æ¥ç¶ãµã¼ãã¹ã ã¨ãIPv4 ã¢ãã¬ã¹ãã«ã¼ã¿ã® WAN å´ã«ä¸åãå²ãå½ã¦ãããã®ãæ®éã§ãããIPv6 ã®å ´åã¯ããã¬ãã£ãã¯ã¹ãã¤ã¾ããã¢ãã¬ã¹ã®ãããã¯ã¼ã¯é¨ãå²ãå½ã¦ããã¾ãã128 bit ã® IPv6 ã¢ãã¬ã¹ã®ãã¡ãä¸ä½ 64 bit ã®ã¢ãã¬ã¹ã ISP ããå²ãå½ã¦ãããä¸ä½ 64 bit ã¯ãåæã«ä»ãã¦ãããã¨ããç¶æ ã§ã*2ã
ãã©ã¤ãã¼ãã¢ãã¬ã¹
NAT ãç¡ããæ®éã«ã°ãã¼ãã«ã¢ãã¬ã¹ã PC ã«å²ãå½ã¦ããã¦ããã®ã ãããIPv4 ã®ãã©ã¤ãã¼ãã¢ãã¬ã¹ã®ãããªç©ã¯å¿ è¦ãªãããã¨ããã¨ãããããããã§ãããã¾ãããä¾ãã°ããµã¼ãã®ã¢ãã¬ã¹ã¯åºå®ããã訳ã§ããããããå人åãã®å®ãå¥ç´ã§æ¸ã¾ãããã¨ããã°ãå²ãå½ã¦ããããã¬ãã£ãã¯ã¹ãå¤ãããã³ã«ããµã¼ãã®ã¢ãã¬ã¹ãå¤æ´ããå¿ è¦ãããã¾ããåºå®ã®å¥ç´ãçµãã§ããISP ãå¤ãããããµã¼ãã®ã¢ãã¬ã¹ãå¤æ´ããªããã°ããã¾ãããã¤ã³ã¿ã¼ãããå´ããã¢ã¯ã»ã¹ããããã®ãµã¼ããªãããããªãã§ãããå é¨ã ãã§ä½¿ããµã¼ããããã§ã¯ãã¾ãã¾ããã
å½åã¯ããNAT ã¯æªã ï¼ ã ãããã©ã¤ãã¼ãã¢ãã¬ã¹ãªãã¦ä¸è¦ã ï¼ãã¿ãããªé°å²æ°ããã£ãã®ã§ãããçµå±ãä¸è¨ã®ãããªäºãèããã¨ããã©ã¤ãã¼ãã¢ãã¬ã¹ã«è©²å½ããç©ãå¿ è¦ãã¨ãããã¨ã§ãIPv6 ã§ã¯ ULA ã¨å¼ã°ããã¢ãã¬ã¹å¸¯ãç¨æããã¾ããã
ULA ã¯ãfdãã§å§ã¾ãã¢ãã¬ã¹ã§ãçµç¹çµ±åãªã©ããã£ãå ´åã«ãè¡çªããªãããã«ãè¨ç®æ¹æ³ãæ示ããã¦ãã¾ããã¾ããå®éã«è¨ç®ããããã® Web ãã¼ã¸ããBSD ç³» OS ã® IPv6 ãå®è£ ãã Kame ããã¸ã§ã¯ãã«ããã¾ãã
http://www.kame.net/~suz/gen-ula.html
èªåãæã£ã¦ãã PC ãæ©å¨ã® MAC ã¢ãã¬ã¹ãå ¥ããã°ã48bit ã®ãã¬ãã£ãã¯ã¹ãçæãã¦ããã¾ããããã§ãIPv4 ã§ã®ãã©ã¤ãã¼ãã¢ãã¬ã¹ã使ãäºãã§ããå é¨ãµã¼ãã«åºå®ã® IPv6 ã¢ãã¬ã¹ãå²ãå½ã¦ãäºãã§ãã¾ãã
åã³ãNAT ãç¡ã
IPv4 ã®ãã©ã¤ãã¼ãã¢ãã¬ã¹ã§å é¨ã®ãããã¯ã¼ã¯ãä½ããããã§ã¤ã³ã¿ã¼ãããã«æ¥ç¶ã§ããã®ã¯ãNAT ã®ãããã§ããããããIPv6 ã§ã¯ NAT ãããã¾ããããã®ã¾ã¾ã ã¨ã
- ã°ãã¼ãã«ã®ã¢ãã¬ã¹ãå²ãå½ã¦ãããç©ã¯ãã¤ã³ã¿ã¼ãããã«ã¯ã¤ãªãããã©ãULA ãä»ããå é¨ã®ãµã¼ãã«ãç´æ¥ã¯ã¤ãªãããªã*3ã
- ULA ãä»ãããã®ã¯ãå é¨ã®ãµã¼ãã«ã¯ã¢ã¯ã»ã¹ã§ããããã¤ã³ã¿ã¼ãããã«ã¯ã¤ãªãããªãã
ã¨ãããã¨ã«ãªãã¾ãããããããå é¨ã®ãµã¼ã㯠ULA ãä»ãã訳ã§ãããããããããã®ãµã¼ãã®ã¢ãããã¼ãã¨ãã¯ã©ããããã ï¼ ã¨ããäºã«ãªãã¾ãã
ã§ãã©ããããã¨ããã¨ããã©ã£ã¡ã®ã¢ãã¬ã¹ãä»ãããã¨ããäºã«ãªãã¾ããIPv6 ããè¤æ°ã®ã¢ãã¬ã¹ãæã¤ã®ãæ®éãã¨è¨ãæãé常使ãã¢ãã¬ã¹ã¨ãªã³ã¯ãã¼ã«ã«ã¢ãã¬ã¹ã®äºãæãã¦è§£èª¬ãã¦ããäºãå¤ãã®ã§ãããULA ã使ãå ´åã«ã¯ããULA ã¨ã°ãã¼ãã«ã®ä¸¡æ¹ã®ã¢ãã¬ã¹ãæã¤ãã¨ããäºã«ãªãã¾ããIPv4 ã ã¨å é¨ã®ãããã¯ã¼ã¯ããã©ã¤ãã¼ãã¢ãã¬ã¹ã ãã§æ¸ãã§ããã®ã¨ã大ããªéãã«ãªãã¾ã*4ã
Windows ä¸ã§ãipconfig ã§è¦ãã¨ããããªæãã«ãªãã¾ãã
èªåæ§ææå¹. . . . . . . . . . . : ã¯ã IPv6 ã¢ãã¬ã¹ . . . . . . . . . . . : 240b:1234:5678:9abc:def0:1234:5678:9abc(åªå ) IPv6 ã¢ãã¬ã¹ . . . . . . . . . . . : fdfe:dcba:9876:5432::beef(åªå ) ä¸æ IPv6 ã¢ãã¬ã¹. . . . . . . . . : 240b:1234:5678:9abc:fedc:ba09:8765:4321(åªå ) ãªã³ã¯ãã¼ã«ã« IPv6 ã¢ãã¬ã¹. . . . : fe80::123:4567:890a:bcde%11(åªå )
ä¸è¨ã®ä¾ã§ã¯ããã¬ãã£ãã¯ã¹ã¯ 64 bit ã§ã
- ã°ãã¼ãã«ãªã¢ãã¬ã¹ã¯ãã240b:1234:5678:9abc:def0:1234:5678:9abcãã¨ã240b:1234:5678:9abc:fedc:ba09:8765:4321ã
- ULA ã¯ãfdfe:dcba:9876:5432::beefã
- ãªã³ã¯ãã¼ã«ã«ã¢ãã¬ã¹ã¯ãfe80::123:4567:890a:bcdeã
ã«ãªãã¾ãã
ããã¡ãµã¼ãã«ã°ãã¼ãã«ãª IPv6 㨠ULA ãä»ãã
ã¨ãããã¨ã§ãããã¡ãµã¼ãã IPv6 対å¿ã«ããã«ã¯ãã°ãã¼ãã«ãªã¢ãã¬ã¹ã¨ ULA ã®ä¸¡æ¹ãæã¤ããã«è¨å®ããå¿ è¦ãããã¾ãã
ããããã§è½ã¨ãç©´ãã
ç§ã®ããã¡ãµã¼ã㯠CentOS ãªã®ã§ãããCentOS ã§æ®éã« GUI ã§ã¢ãã¬ã¹è¨å®ããããã¨ããã¨ã
- æåã§è¨å®ããã°ãèªåæ§æã®ã¢ãã¬ã¹ã¯çæãããªãã
- èªåæ§æã®ã¢ãã¬ã¹ãçæãããããã«ããã¨ãæåã§ã¢ãã¬ã¹ãè¨å®ã§ããªãã
ã¨ããç¶æ ã«ãªãã¾ãããµã¼ããªã®ã§ãULA ã®ã¢ãã¬ã¹ãæåã§è¨å®ãããã®ã§ãããããããã¨ãèªåæ§æã§å²ãå½ã¦ãããã¯ãã®ã°ãã¼ãã«ãªã¢ãã¬ã¹ã¯ä»ä¸ãããªããã¨ããç¶æ ã«ãªãã¾ããä¼æ¥ã®ããã«ãã°ãã¼ãã«ã®ãã¬ãã£ãã¯ã¹ãåºå®ã®å ´åã¯åé¡ãªãã§ãããããã¡ãµã¼ãã ã¨ããã¬ãã£ãã¯ã¹ãå¤ããå¯è½æ§ãããã®ã§ãã°ãã¼ãã«ã®ã¢ãã¬ã¹ãæåã§è¨å®ãã訳ã«ã¯ããã¾ããã
IPv6 ã®èªåæ§æã¢ãã¬ã¹ã¯ãã«ã¼ã¿ãéä¿¡ãã RAï¼Router Advertisementï¼ã«ã¼ã¿åºåï¼ã®ã¡ãã»ã¼ã¸ãåä¿¡ãããã®ã¡ãã»ã¼ã¸ã«å«ã¾ãããã¬ãã£ãã¯ã¹ã®æ å ±ã使ã£ã¦ãèªåã®ã¢ãã¬ã¹ã決å®ãã¾ããRA ãåä¿¡ãã¦èªåæ§æã¢ãã¬ã¹ãçæãã¤ã¤ãåºå®ã§ ULA ãä»ããããIPv4 ã§ä¾ããã°ãDHCP ã¨æåè¨å®ã®ä¸¡æ¹ã®ã¢ãã¬ã¹ãä»ããããã¨ãã£ãæãã§ãã
ããããå ãã¾ãã£ãã¨ãããã/proc/sys/net/ipv6/conf/eth0/accept_raãã 0 ãªäºãåããã¾ããããããããããã 1 ã«ããå¿ è¦ãããã ããã¨æã£ã¦ã
# echo 1 >/proc/sys/net/ipv6/conf/eth0/accept_ra
ã¨ãã¦ãservice network restartãã¨ãã¦ã¿ãã¨ã0 ã«æ»ã£ã¦ãã¾ãã¾ãã
# find /etc/sysconfig/network-scripts/ -type f -exec grep -Hn accept_ra {} \;
ã¨ããã¨ã確ãã«ããã®å¤ãæ¸ãæãã¦ããã¨ãããè¦ã¤ããã¾ãã
ããã追ããããã¨ãã©ããã IPV6_AUTOCONF ã yes ãªã accept_ra ã 1 ã«ãªãããã§ããGUI ãã IPv6 ã¢ãã¬ã¹ãæåããã¨ã/etc/sysconfig/network-scripts/ifcfg-eth0 ã« IPV6_AUTOCONF ã no ã«è¨å®ããã¾ããããã yes ã«ããã°è¯ãã®ã§ãããä»åº¦ã¯ NetworkManager ãä¸æ¸ããã¦ãã¾ãã¾ãã
ã¨ãããã¨ã§ã
- NetworkManager ãç¡å¹ã«ããããããã¯ãã¤ã³ã¿ãã§ã¼ã¹ã NetworkManager ã®ç®¡çå¤ã«ãã*5ã
- /etc/sysconfig/network-scripts/ifcfg-ã¤ã³ã¿ãã§ã¼ã¹å ã®ãã¡ã¤ã«ã§ãIPV6_AUTOCONF=yesãã¨ããã
ã¨ããä¸ã§ãULA ã®åºå®ã¢ãã¬ã¹ãè¨å®ããã¨ã両æ¹ã®ã¢ãã¬ã¹ãå²ãå½ã¦ãããããã«ãªãã¾ããifcfg-ã¤ã³ã¿ãã§ã¼ã¹å㧠IPv6 ã«å¿ è¦ãªè¨å®å 容ã¯ãããªæãã«ãªãã¾ãã
IPV6INIT=yes IPV6_AUTOCONF=yes IPV6ADDR=fdfe:dcba:9876:5432::1234/64
NetworkManager ãæ®å¿µ
NetworkManager ãåãã¦ããã¨ãããã¨ããæå³ããªãè¨å®ã«ãªã£ã¦ããç®ã«éã£ã¦ãããµã¼ãã ããããããªç©ã¯å¿ è¦ãªããã¿ãããªäºãè¨ã人ã¯å¤ãã®ã§ãããã¨ã¯ãããç¡ç· LAN ã VPN ã®ããã«ãã¦ã¼ã¶ã®ããã³ãã§æ¥ç¶ããå ´åã«ã¯ãNetworkManager ãããæ¹ã便å©ã ããæ £ãã¦ããªã人ã§ãããããªãã«è¨å®ã§ããã®ã§ãå人çã«ã¯ããªããæãªããã¦ãããã¨æã£ã¦ä½¿ã£ã¦ããã®ã§ãããNetworkManager ãæ¢ããããå¾ãªãã£ãã®ã¯ãKVM ã®ãã¹ãã§ããªãã¸ãä½ã£ãæã¨åããã¦ï¼åº¦ç®ãããããã¡ãã£ã¨æ®å¿µã
*1:ãã®é 㯠IPng (IP next generation) ã¨è¨ããã¦ãã¾ãã
*2:ãã¬ããå ãã¯ã¹ãã®ãã¤ãã£ãæ¥ç¶ã§å人å¥ç´ã®å ´åããµã¼ãã¹ã¡ãã¥ã¼ã«ãã£ã¦å¤ããå¯è½æ§ãç¡ãããã§ã¯ãªãã§ãããåºæ¬ã64 bit ã®ãã¬ãã£ãã¯ã¹ã¨æã£ã¦ãã¦ééããªãã¨æãã¾ãã
*3:ã«ã¼ã¿ãä»ãã¦ã«ã¼ãã£ã³ã°ããã°æ¥ç¶å¯è½ãã«ã¼ã¿ã¯å²ãå½ã¦ãåãã¦ãããã¬ãã£ãã¯ã¹ãæã¤ãã¹ãããå é¨ã«ããäºãç¥ã£ã¦ããã®ã§ãã«ã¼ã¿ã® LAN å´ã« ULA ã®ã¢ãã¬ã¹ãä»ãããã°ãåºæ¬çã«ã¯ OK
*4:ã¾ããã¤ã³ã¿ã¼ãããã¸ã®æ¥ç¶ã¯å ¨é¨ãProxy çµç±ãã¨ããæ§æãããå¾ã¾ããããã® Proxy ã¯å°ãªãã¨ããã°ãã¼ãã«ãªã¢ãã¬ã¹ã¨ ULA ã®ä¸¡æ¹ãæã¤å¿ è¦ãããã¾ãã
*5:/etc/sysconfig/network-scripts/ifcfg-ã¤ã³ã¿ãã§ã¼ã¹åã®ãã¡ã¤ã«ã§ NM_CONTROLLED=no ã¨ãã¾ãã