13
PA PPPoE Unnumbered 2018 3 ( ) Akira Hayashi SE Manager, Palo Alto Networks

PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

PA����������PPPoE Unnumbered � �

2018�3� (��)

Akira HayashiSE Manager, Palo Alto Networks

Page 2: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

����

PPPoE�&O#;M-/)�DIPQ\cX4�L�>KNMJ2B"�hLAN��%iC31>/�L�>KN<Udg]bIPQ\cXO$�DMZBA+Vg]C*�:>�#;M��O�(CUnnumbered PPPoE�%@�FG;0

PAWagY���^PRQSTgbE/)�D��bgZO�#;M7@? PPPoE LAN��%C36MUdg]bIPQ\cXD$�#4�'CBLG;0

�-D*�� I*�f#�D`Re[E�.�,O8 !5=910

7D*��EPAN-OS 7.1_gX?;4/PAN-OS 8.0 �,?H��D*�?��:G;0

2 | © 2018, Palo Alto Networks. Confidential and Proprietary.

Page 3: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

����������PA�����

3 | © 2018, Palo Alto Networks. Confidential and Proprietary.

[SOQ^`I����] [��"<��46PA=LMPV��]

L3-Trust L3-DMZ

Internet

L3-Untrust

ISP0A�B�8AD6J]`T[IPFR\M:203.0.113.8/29 (8�)

203.0.113.8 PA ethernet1/19��203.0.113.9 PA ethernet1/29��203.0.113.10 ��� IPFR\M 1203.0.113.11 ��� IPFR\M 2203.0.113.12 ��� IPFR\M 3203.0.113.13 ��� IPFR\M 4203.0.113.14 ��� IPFR\M 5203.0.113.15 Broadcast Address

PPPoE��ethernet1/1

ethernet1/3 ethernet1/2

�$K`T203.0.113.10

IYGF_QPC192.168.1.101

203.0.113.9/29192.168.1.1/24

203.0.113.8/32

PPPoEK`T1PA<�B�8C IPFR\M

trust-vr

untrust-vr

DMZNJW_Q9J]`T[IPFR\ME��.2D<@78�$K`T<��J]`T[IPFR\ME! 5C�1�<;BNAT:=��1�/FUZ1���<.

-�#�9>,)(&'%'9 3D6RHXW_Q���<��3D6J]`T[*+FR\ME��48/?5.

Page 4: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

PA��������������IP�������������

ü PPPoE�$�#�:�=LAN I/F<!71E5A=]6=��W[OG�%4E• untrust-vr: PPPoE�$<�#4EI/F (ethernet1/1)• trust-vr: �*NKUZQ(Trust)BDMZNKUZQ<�#4EI/F (ethernet1/2, 1/3)

ü ��W[OG@50)��=-�"((Static routing)G�%4E• trust-vr<> untrust-vr Gnexthop:38��35default route(0.0.0.0/0)G�%• untrust-vr<> trust-vr Gnexthop:35DMZ�?�*SPQY[J�1="(G�%

ü ���9� &;Global IPHRXM> {�D�8CF5Global IP} – {2(�)}• �D�8CF5�=IPHRXM> PPPoE�$ I/F<HLIZ2F PAT�:38��• 2� �+=IPHRXM>��=Broadcast AddressG,/.'�<� &

• �1^ IP8TVZ=��.5�=Global IPHRXM.\�=N�1 NAT� IPHRXM• �2^ IP16TVZ=��.13�=Global IPHRXM.\�=N�1 NAT� IPHRXM

4 | © 2018, Palo Alto Networks. Confidential and Proprietary.

Page 5: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

PA����������,��� (Network > �������, ��)

5 | © 2018, Palo Alto Networks. Confidential and Proprietary.

[CSITODCG��] *��9��;�� [HTS��] *��9��;��

$#2=��4?6###-�PTF�8NGRTM@��

GILBJEAMQG;�+-('+#.-/*)/@��5>�@�30 ���"-,*:<<�7�1

"%%OQJK��:�!%&;����@��

Page 6: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

PA���������� (Network > ������)

6 | © 2018, Palo Alto Networks. Confidential and Proprietary.

[� =?5��]

[PPPoE���� =?5? “untrust-vr” �] [*-�-LAN (DMZ, ��) I/F� � =?5? “trust-vr” �]

%�$"%#$�&" /��'$� !,)+8;1=9=?9/�$"%#$�&" /��'$� !,)+����.��:69>?2��3<:69�(-457062=?9/�

[��-���(trust-vr)] [��-���(untrust-vr)]

Page 7: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

PA��� �����, NAT���� (Policies > �����, NAT)

7 | © 2018, Palo Alto Networks. Confidential and Proprietary.

[>:FHA8EH<L] *��-�0��

[NATEH<L] *��-�0����/��.�5)+�6�(3&,

��D@BJL;/;G97KB%9K?LD@B.��(3�$�����7CI=0��/�# �"!�#���.�2�+14*��7CI=.��� '43

ISP ���� ������IP����:203.0.113.8/29 (8�)

203.0.113.8 PA ethernet1/1���203.0.113.9 PA ethernet1/2���203.0.113.10 ���� IP���� 1203.0.113.11���� IP���� 2203.0.113.12���� IP���� 3203.0.113.13���� IP���� 4203.0.113.14���� IP���� 5203.0.113.15 Broadcast Address

Page 8: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

PPPoE��������

8 | © 2018, Palo Alto Networks. Confidential and Proprietary.

[Web UI���] [CLI���]ahayashi@PA> show pppoe interface ethernet1/1

Interface: ethernet1/1PPPoE State: ConnectedPPP State: ConnectedConnected since: Tue Jan 23 12:17:17 2018Connection up for: 49709 days, 8:08:56Access Concentrator: PANW-Lab-PPPoE-ServerAC MAC: 00:**:**:9f:b9:b9Authentication via: CHAPPassive mode: DisabledUsername: pppoe-user01Local IP: 203.0.113.8Primary DNS IP: 8.8.8.8Secondary DNS IP: 8.8.4.4Primary WINS IP: 0.0.0.0Secondary WINS IP: 0.0.0.0Remote IP: 198.51.100.254Session ID: 30Link MTU: 1454PPPoE/PPP Counters:PPPoE control packets received: 2PPPoE control packets sent: 2PPP control packets received: 1918PPP control packets sent: 1918

�������

Page 9: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

��������� Untrust (PPPoE�) → DMZ (Global IP)

9 | © 2018, Palo Alto Networks. Confidential and Proprietary.

[&+)�%���- ] *Global IP�',"����DMZ# *.&��� !/(���#"

Global IP�',"�����DMZ# *.&��!/(���NAT�����$�,�&���������

Page 10: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

��������� DMZ (Global IP) → Untrust (PPPoE�)

10 | © 2018, Palo Alto Networks. Confidential and Proprietary.

[�$"�����&�]

DMZ��#'����(!���'�( ���� NAT��� ���%����������

Page 11: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

�������� ������ (Trust) → Untrust (PPPoE��)

11 | © 2018, Palo Alto Networks. Confidential and Proprietary.

[��������]

Page 12: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

�������� ������ (Trust) → DMZ (Global IP)

12 | © 2018, Palo Alto Networks. Confidential and Proprietary.

[��������]

Page 13: PAN-OS Unnumbered PPPoE 設定例 Mar2018 › twzvq79624 › attachments...PA IP üPPPoE $ # : =LAN I/F

THANK YOU

Email: [email protected] l Twitter: @PaloAltoNtwks