¡ÖVPN¤ÎÀßÄê¡×¤Îµ»ö°ìÍ÷

¡ÊÇî»Î¡Ë¤³¤Î¾Ï¤Ç¤Ï¡¢VPN¤ÎÀâÌÀ¤ò¤·¤Þ¤¹¡£
VPNÀܳ¤ÏPhase£±¤äPhase£²¤Ê¤É¤Î³µÇ°¤¬Æñ¤·¤¯¡¢Íý²ò¤¬Æñ¤·¤¤¤È»×¤¦¡£¤Þ¤º¤Ï¡¢¤³¤Î²òÀâ¤ËÃé¼Â¤Ë¼Â»Ü¤·¤Æ¤¯¤À¤µ¤¤¡£

¡Ê¥¢¥³¡ËÇî»Î¤â»Ï¤á¤ÆVPN¤òÀܳ¤µ¤ì¤¿¤È¤¤Ï¶ìÏ«¤µ¤ì¤¿¤Èʹ¤¤Þ¤·¤¿¡£ËÜÅö¤Ç¤¹¤«¡©

¡ÊÇî»Î¡Ë¤½¤¦¤Ê¤ó¤À¡£
Åö»þ¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤Ç¸¡º÷¤·¤Æ¤âÀßÄêÊýË¡¤¬¤«¤«¤ì¤¿¥µ¥¤¥È¤Ï°ìÀÚ̵¤¯¡¢ÌëÃÙ¤¯¤Þ¤ÇǺ¤ßÅݤ·¤¿¤è¡£
¤½¤ó¤Ê¶ìÏ«¤â¤¢¤Ã¤Æ¡¢¤³¤Î¥µ¥¤¥È¤òΩ¤Á¾å¤²¤¿¤ó¤À¤±¤É¤Í¡£
¡Îµ»ö°ìÍ÷¡Ï
¡ÀßÄê´Ä¶
¢½é´üÀßÄê
£Trust¡ÊLAN¡Ë¦¤ÎÀßÄê
¤Tunnel¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤ÎºîÀ®¡¡£±
¥Tunnel¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤ÎºîÀ®¡¡£²
¦Untrust¤ÎÀßÄê¡ÊPPPoE¤Î¾ì¹ç¡Ë
§Phase£±¤ÎÀßÄê
¨Phase2¤ÎÀßÄê
©Phase2¤ÎÀßÄê¡Ê³¤¡Ë
ªRouting¤ÎÀßÄê
«ÀßÄê¤Î´°Î»
¬¥í¥°¤Î³Îǧ
VPNÀܳ¤Î³ÎǧÊýË¡
ÀßÄê´Ä¶
¡ÚµòÅÀA¡Û
ÀßÄê¤ò¾Ò²ð¤·¤Æ¤¤¤ëµòÅÀ¤Ç¤¹¡£
LAN¥»¥°¥á¥ó¥È¡§192.168.1.0/24
NetscreenIP¥¢¥É¥ì¥¹¡ÊLAN¡§Trust¦¡Ë¡§192.168.1.200
NetscreenIP¥¢¥É¥ì¥¹¡ÊWAN¡§Untrust¦¡Ë¡§200.1.1.1
NetscreenIP¥¢¥É¥ì¥¹¡Ê²¾ÁÛIF¡§TunnelIF¡Ë¡§10.10.1.1
¡ÚµòÅÀB¡Û
LAN¥»¥°¥á¥ó¥È¡§192.168.2.0/24
NetscreenIP¥¢¥É¥ì¥¹¡ÊLAN¡§Trust¦¡Ë¡§192.168.2.200
NetscreenIP¥¢¥É¥ì¥¹¡ÊWAN¡§Untrust¦¡Ë¡§200.1.1.2
NetscreenIP¥¢¥É¥ì¥¹¡Ê²¾ÁÛIF¡§TunnelIF¡Ë¡§10.10.1.2
½é´üÀßÄê
£±¡¥Netscreen¤ÎÅŸ»¤òÆþ¤ì¤Þ¤¹¡£¡ÊNetscreen¤Ï½é´ü²½¤µ¤ì¤Æ¤¤¤ë¤È¤·¤Þ¤¹¡£¡Ë
£²¡¥PC¤ÈNetscreen¤ò¥¹¥È¥ì¡¼¥È¥±¡¼¥Ö¥ë¤ÇÀܳ¤·¤Þ¤¹¡£
Netscreen¤Î¥Ý¡¼¥È¤ÏTrust¦
£³¡¥Netscreen¤È¥¤¥ó¥¿¡¼¥Í¥Ã¥È²óÀþ¤òÀܳ¤·¤Þ¤¹¡£
Netscreen¤ÎUntrust¦¤òADSL¥â¥Ç¥à¤äB¥Õ¥ì¥Ã¥Ä¤ÎONU¤ÈÀܳ¤·¤Þ¤¹¡£
£´¡¥PC¤ÎÀßÄê
DHCP¤ÇIP¥¢¥É¥ì¥¹¤ò¼«Æ°¼èÆÀ¤¹¤ëÀßÄê¤Ë¤·¡¢Netscreen¤«¤éIP¤Î³ä¤êÅö¤Æ¤ò¼õ¤±¤Þ¤¹¡£
¢¨¶²¤é¤¯192.168.1.0/24¤ÎIP¥¢¥É¥ì¥¹¤¬³ä¤ê¿¶¤é¤ì¤ë
¢¨¥Ç¥Õ¥©¥ë¥È¥²¡¼¥È¥¦¥§¥¤¤¬192.168.1.1¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤«³Îǧ¡£
£µ¡¥Netscreen¤Ø¤Î¥¢¥¯¥»¥¹
http://192.168.1.1¡¡¤Ø¥Ö¥é¥¦¥¶¤òÄ̤¸¤Æ¥¢¥¯¥»¥¹¤¹¤ë¡£
£¶¡¥¥í¥°¥¤¥ó
¥æ¡¼¥¶Ì¾:netscreen
password:netscreen
Trust¡ÊLAN¡Ë¦¤ÎÀßÄê
LAN¦¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤ÎÀßÄê¤ò¤·¤Þ¤¹¡£
IP¥¢¥É¥ì¥¹¤òÊѹ¹¤¹¤ë¾ì¹ç¤Ë¤Ï¡¢ÀßÄêÊѹ¹¸å¤ËºÆ¥í¥°¥¤¥ó¤¬É¬ÍפǤ¹¡£¤Þ¤¿¡¢¾ì¹ç¤Ë¤è¤Ã¤Æ¤ÏüËö¤ÎIP¥¢¥É¥ì¥¹¤òÊѹ¹¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£
¡ÚÀßÄêÊýË¡¡Û
¡¥µ¥¤¥É¥á¥Ë¥å¡¼¤«¤é Network > Interfaces ¤ò³«¤¯
¢¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤Î°ìÍ÷¤¬É½¼¨¤µ¤ì¤ë¡£¢ª¡ÖName¡×¤¬¡Ötrust¡×¤Î¡ÖConfigure¡×¤ò¡ÖEdit¡×¡Ê¥¯¥ê¥Ã¥¯¡Ë
£trust¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤Î²èÌ̤¬É½¼¨¤µ¤ì¤ë¡£¢ªIP Address / Netmask¡¡¤òÀßÄꤹ¤ë¡£
¤OK¤ò²¡¤¹¤È¡¢ÀßÄ괰λ
¡Ú¥ª¥×¥·¥ç¥ó¤ÎÀßÄê¡Û
¡ManageIP
¡¦ManageIP¤òÀßÄꤹ¤ë¤È¡¢´ÉÍýÍѤÎIP¤¬³ä¤ê¿¶¤é¤ì¡¢¤³¤ÎIP
¤Ç´ÉÍý¼Ô¤Ï´ÉÍý¤¹¤ë¡£¡ÊÀßÄꤷ¤Ê¤¯¤Æ¤è¤¤¤Ç¤·¤ç¤¦¡Ë
¢Interface Mode
¡ÖNAT¡×¤Ë¤¹¤ë¡£¡ÊRoute¤Ç¤â¤è¤¤¤¬¡¢NAT¤ÎÊý¤¬ÍÑÅÓ¤¬¹¤¬¤ë¡Ë
£Service Options¡¡
ºÇÄã¸ÂWebUI¤ÈTelnet¡¢Ping¤òµö²Ä¤·¤Æ¤ª¤³¤¦¡£WebUI¤Ë¤è¤ê¥Ö¥é¥¦¥¶¤Ë¤è¤ëÀßÄ꤬²Äǽ¤Ë¤Ê¤ë¡£Telnet¤Ï¥³¥Þ¥ó¥É¤«¤é¤·¤«¤Ç¤Ê¤¤½èÍý¤ò¤¹¤ë¤È¤¤ËÊØÍø¡£Ping¤ÏÄÌ¿®¤ÎÀÚ¤êʬ¤±¤ËÊØÍø¡£
Tunnel¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤ÎºîÀ®¡¡£±
Tunnel¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤ÎÀßÄê¤ò¤·¤Þ¤¹¡£¤³¤ÎÀßÄê¤Ë¤è¤ê¡¢°ì¤Ä¤ÎʪÍý¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤ËÂФ·¤ÆÊ£¿ô¤Î²¾ÁÛ¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤òºîÀ®¤Ç¤¤Þ¤¹¡£
¤³¤ÎÀßÄê¤Ïɬ¿Ü¤Ç¤Ï¤¢¤ê¤Þ¤»¤ó¡£¤¿¤À¡¢Â¿µòÅÀ¤ÈVPNÄÌ¿®¤ò¤¹¤ëºÝ¤Ë¤Ï¤È¤Æ¤âÊØÍø¤Ç¤¹¡£¡Ê¤³¤Î¥µ¥¤¥È¤Ç¤Ï¡¢Tunnel¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤òºîÀ®¤¹¤ëÀßÄê¤ò¤´¾Ò²ð¤·¤Æ¤Þ¤¹¡£¡Ë
¡¥µ¥¤¥É¥á¥Ë¥å¡¼¤«¤é Network > Interfaces ¤ò³«¤¯
¢¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤Î°ìÍ÷¤¬É½¼¨¤µ¤ì¤ë¡£¢ª±¦¾å¤Î¥×¥ë¥À¥¦¥ó¥Ü¥Ã¥¯¥¹¤¬¡ÖTunnel IF¡×¤È¤Ê¤Ã¤Æ¤¤¤ë¤³¤È¤ò³Îǧ¤·¤¿¾å¤Ç
¤½¤Îº¸¤Î¡ÖNew¡×¥Ü¥¿¥ó¤ò²¡¤¹¡£
£Tunnel¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤Î²èÌ̤¬É½¼¨¤µ¤ì¤ë¡£¢ªFixed IP¤òÀßÄꤹ¤ë¡£¤½¤ì°Ê³°¤ÎÀßÄê¤Ï¥Ç¥Õ¥©¥ë¥È¤Î¤Þ¤Þ¡£
²¾ÁÛIP¥¢¥É¥ì¥¹¤Ê¤Î¤Ç¡¢²¿¤Ç¤â¤¤¤¤¤Î¤Ç¤¹¤¬¡¢¼¡¤Î¾ò·ï¤ò¼é¤Ã¤Æ¤¯¤À¤µ¤¤¡£
¡Ê¥¢¡Ë¥×¥é¥¤¥Ù¡¼¥ÈIP¥¢¥É¥ì¥¹¤È¤¹¤ë¤³¤È
¡Ê¥¤¡Ë¾¤Î¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤È½ÅÊ£¤·¤Ê¤¤¥»¥°¥á¥ó¥È¤Ë¤¹¤ë¤³¤È
¡Ê¥¦¡ËÂй³¤ÎTunnel¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹IP¥¢¥É¥ì¥¹¤ÈƱ°ì¥»¥°¥á¥ó¥È¤Ë¤¹¤ë¤³¤È
Î㤨¤Ð¡¢¤³¤ÎNetscreen¤ÎTunnelIP¤ò10.10.1.1/30¡¢Âй³¤ÎNetscreen¤ÎTunnelIP¤Ï10.10.1.2/30
¤OK¤ò²¡¤¹¤È¡¢ÀßÄ괰λ
Untrust¦¤ÎÀßÄê
http://www.viva-netscreen.net/archives/cat_50018634.html
Untrust¦¤ÎÊäÂÀâÌÀ¤ò¤·¤Þ¤¹¡£

¡Managed IP
´ÉÍý¼ÔÍѤÎIP¥¢¥É¥ì¥¹ÀßÄ꤬¤Ç¤¤Þ¤¹¡£
¼ÂºÝ¤ÎIP¥¢¥É¥ì¥¹¤È´ÉÍýÍѤÎIP¥¢¥É¥ì¥¹¤òʬ¤±¤ë¾ì¹ç¤Ë»È¤¤¤Þ¤¹¡£
¡Interface Mode
NAT¤Ç¤âRoute¤Ç¤â¤É¤Á¤é¤Ç¤â¤è¤¤¤Ç¤¹¡£
NAT¤Î¾ì¹ç¤ÏNAPT¤¹¤ë¤Î¤Ç¡¢Ä̾ï¤Ï¤³¤Á¤é¤Ç¤·¤ç¤¦¡£
Route¤Î¾ì¹ç¤Ç¤â¡¢Policy¤ÎÀßÄê¤ÇNAT¤Ç¤¤Þ¤¹¡£¤è¤Ã¤Æ¤É¤Á¤é¤Ç¤âƱ¤¸ÍøÍÑÊýË¡¤¬¤Ç¤¤Þ¤¹¡£
¢Service Opitons
untrust¦¤Ï´ðËÜŪ¤Ë¤¹¤Ù¤Æ¶Ø»ß¤·¤Æ¤¯¤À¤µ¤¤¡£
»È¤¦¤È¤·¤Æ¤âPing»î¸³¤Ê¤ÉÍѤ˰ì»þŪ¤ËON¤Ë¤¹¤ëÄøÅ٤Ǥ·¤ç¤¦¡£
Phase£±¤ÎÀßÄê

¢Gateway Name¡¡¤òÆþÎϡʤ狼¤ê¤ä¤¹¤¤Ì¾¤Ç¡Ë
£Static IP Address¡¡¤ËÂÐÃϤ˥°¥í¡¼¥Ð¥ëIP¥¢¥É¥ì¥¹¤òÆþÎϤ¹¤ë
¤Preshared Key¤òÆþÎϤ¹¤ë¡£¡ÊÂÐÃϤȤ¢¤ï¤»¤ë¡Ë
¥Outgoing Interface¤Ï¡Öuntrust¡×¤Ç¤¢¤ë¤³¤È¤ò³Îǧ
¦OK¤ÇÀßÄ괰λ
¢¨Advanced¤Ë¤è¤êÍÍ¡¹¤ÊÀßÄê¤ò¹Ô¤¦¤³¤È¤¬½ÐÍè¤ë¤¬¡¢
¤³¤³¤Ç¤Ï³ä°¦¤¹¤ë¡ÊÊÌÅÓµºÜ¤·¤Þ¤¹¡£¡Ë
Phase2¤ÎÀßÄê¡Ê³¤¡Ë

¥¡ÖBind to¡×¡ÖTunnel Interface¡×¤òÀè¤Û¤ÉºîÀ®¤·¤¿
Tunnnel¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤Ë¤¹¤ë¡£
¦¡ÖReturn¡×
§¡ÖOK¡×¤Ç´°Î»
¡Ú»²¹Í¡§¥Ñ¥é¥á¡¼¥¿¾ÜºÙ¡Û
G2¡ÊDiffe-Hellman Group2¡Ë¡§¤«¤®¸ò´¹¤Î»ÅÁȤß
Nopfs¡ÊNo Perfect Forwarding Secrecy¡Ë¡§ Phase1¤Îkey¤òPhase2¤ÇÍøÍѤ¹¤ë¡£
Des¡ÊData Encryption Standard¡Ë¡§¶¦Ä̸°°Å¹æÊý¼°¤Îɸ½à
3des¡ÊTriple-DES¡Ë¡§DES¤Î¶¯²½ÈÇ
Aes¡ÊAdvanced Encryption Standard¡Ë¡§3DES¤è¤ê¤Ï¤ë¤«¤Ë¶¯¸Ç¡£
Md5¡ÊMessage Digest version5¡Ë¡§¥á¥Ã¥»¡¼¥¸¥À¥¤¥¸¥§¥¹¥È128¥Ó¥Ã¥È
Sha-1¡ÊSecure Hash Algorithm1¡Ë¡§¥á¥Ã¥»¡¼¥¸¥À¥¤¥¸¥§¥¹¥È160¥Ó¥Ã¥È
Esp¡ÊEncapsulating Security Payload¡Ë¡§ °Å¹æ²½¤ÎÊý¼°¡£Â¾¤ËAH¤¬¤¢¤ë


