UBNT EdgeRouter ER-X ¼³Á¤À»ÇÏ·Á´Âµ¥ ¾îµðºÎÅÍ, ¹» ¾îÂî ¼Õ´ë¾ßµÉÁö °¨ÀÌ ¾ÈÀâÈ÷³×¿ä
WAN 2개에 LAN은 4개로 구성을 하려고합니다.
첨부된 네트워크맵 이미지를 보시면 KT망으로만 접속하는 네트워크, LG망으로만 접속하는 네트워크, LG망으로 접속을 하는데, IPTV와 인터넷전화기만 연결되는 네트워크, 그리고 KT망과 LG망 로드밸런싱된 네트워크
이렇게 총 4개의 네트워크가 분리되어 사용하고싶습니다.
구글링을 아무리해봐도 static routing 관련 내용밖에 안보이네요
조언좀 부탁드립니다.
WANµéÀº À¯µ¿¾ÆÀÌÇÇÀÏÅÙµ¥¸»ÀÌÁÒ...
Àû¾îµµ Edgerouter¿¡¼´Â¿ä.
set interfaces ethernet eth1 address 192.168.10.1/24
set interfaces ethernet eth2 description LAN2
set interfaces ethernet eth2 address 192.168.11.1/24
set interfaces ethernet eth3 description WAN1
set interfaces ethernet eth3 address dhcp
set interfaces ethernet eth4 description WAN2
set interfaces ethernet eth4 address dhcp
set service dhcp-server disabled false
set service dhcp-server shared-network-name LAN1 authoritative enable
set service dhcp-server shared-network-name LAN1 subnet 192.168.10.0/24 start 192.168.10.2 stop 192.168.10.254
set service dhcp-server shared-network-name LAN1 subnet 192.168.10.0/24 default-router 192.168.10.1
set service dhcp-server shared-network-name LAN1 subnet 192.168.10.0/24 dns-server 1.1.1.1
set service dhcp-server shared-network-name LAN1 subnet 192.168.10.0/24 dns-server 1.0.0.1
set service dhcp-server shared-network-name LAN1 subnet 192.168.10.0/24 lease 86400
set service dhcp-server shared-network-name LAN2 authoritative enable
set service dhcp-server shared-network-name LAN2 subnet 192.168.11.0/24 start 192.168.11.2 stop 192.168.11.254
set service dhcp-server shared-network-name LAN2 subnet 192.168.11.0/24 default-router 192.168.11.1
set service dhcp-server shared-network-name LAN2 subnet 192.168.11.0/24 dns-server 1.1.1.1
set service dhcp-server shared-network-name LAN2 subnet 192.168.11.0/24 dns-server 1.0.0.1
set service dhcp-server shared-network-name LAN2 subnet 192.168.11.0/24 lease 86400
set protocols static table 11 interface-route 0.0.0.0/0 next-hop-interface eth3
set protocols static table 12 interface-route 0.0.0.0/0 next-hop-interface eth4
set firewall modify PBR_policy rule 20 description WAN1
set firewall modify PBR_policy rule 20 source address 192.168.10.0/24
set firewall modify PBR_policy rule 20 modify table 11
set firewall modify PBR_policy rule 30 description WAN2
set firewall modify PBR_policy rule 30 source address 192.168.11.0/24
set firewall modify PBR_policy rule 30 modify table 12
set interfaces ethernet eth1 firewall in modify PBR_policy
set interfaces ethernet eth2 firewall in modify PBR_policy
ÀÌ·¸°Ô ¼³Á¤À» Çߴµ¥ µÇÁö¸¦ ¾Ê³×¿ä...
DNSÄõ¸®¸¦ ¸øÇÏ°í ÀÖ¾î¼ DNS¼³Á¤µµ ¹Ù²Ù¾ú½À´Ï´Ù.
³»ºÎ ³×Æ®¿öÅ©°£ Åë½ÅÀº µÇ´Âµ¥¿ä, ÀÎÅͳÝÀº ¿©ÀüÈ÷ ¾ÈµÇ³×¿ä...
set system offload hwnat enable
set system offload ipsec enable
set interfaces ethernet eth1 description LAN1
set interfaces ethernet eth1 address 192.168.10.1/24
set interfaces ethernet eth2 description LAN2
set interfaces ethernet eth2 address 192.168.11.1/24
set interfaces ethernet eth3 description WAN1
set interfaces ethernet eth3 address dhcp
set interfaces ethernet eth3 dhcp-options name-server no-update
set interfaces ethernet eth4 description WAN2
set interfaces ethernet eth4 address dhcp
set interfaces ethernet eth4 dhcp-options name-server no-update
set service dhcp-server disabled false
set service dhcp-server shared-network-name LAN1 authoritative enable
set service dhcp-server shared-network-name LAN1 subnet 192.168.10.0/24 start 192.168.10.2 stop 192.168.10.254
set service dhcp-server shared-network-name LAN1 subnet 192.168.10.0/24 default-router 192.168.10.1
set service dhcp-server shared-network-name LAN1 subnet 192.168.10.0/24 dns-server 192.168.10.1
set service dhcp-server shared-network-name LAN1 subnet 192.168.10.0/24 lease 86400
set service dhcp-server shared-network-name LAN2 authoritative enable
set service dhcp-server shared-network-name LAN2 subnet 192.168.11.0/24 start 192.168.11.2 stop 192.168.11.254
set service dhcp-server shared-network-name LAN2 subnet 192.168.11.0/24 default-router 192.168.11.1
set service dhcp-server shared-network-name LAN2 subnet 192.168.11.0/24 dns-server 192.168.11.1
set service dhcp-server shared-network-name LAN2 subnet 192.168.11.0/24 lease 86400
set protocols static table 11 interface-route 0.0.0.0/0 next-hop-interface eth3 distance 1
set protocols static table 12 interface-route 0.0.0.0/0 next-hop-interface eth4 distance 1
set firewall modify PBR_policy rule 20 description WAN1
set firewall modify PBR_policy rule 20 source address 192.168.10.0/24
set firewall modify PBR_policy rule 20 modify table 11
set firewall modify PBR_policy rule 30 description WAN2
set firewall modify PBR_policy rule 30 source address 192.168.11.0/24
set firewall modify PBR_policy rule 30 modify table 12
set interfaces ethernet eth1 firewall in modify PBR_policy
set interfaces ethernet eth2 firewall in modify PBR_policy
set service dns forwarding listen-on eth1
set service dns forwarding listen-on eth2
set service dns forwarding name-server 1.1.1.1
set service dns forwarding name-server 1.0.0.1
set system name-server 127.0.0.1
set service dns forwarding cache-size 300
set system domain-name home.local
set service dhcp-server shared-network-name LAN1 subnet 192.168.10.0/24 domain-name area1.home.local
set service dhcp-server shared-network-name LAN2 subnet 192.168.11.0/24 domain-name area2.home.local
set service nat rule 5010 description 'masquerade for WAN1'
set service nat rule 5010 outbound-interface eth3
set service nat rule 5010 type masquerade
set service nat rule 5010 protocol all
set service nat rule 5010 source address 192.168.10.0/24
set service nat rule 4010 description 'masquerade for WAN1'
set service nat rule 4010 inbound-interface eth3
set service nat rule 4010 type destination
set service nat rule 4010 protocol all
set service nat rule 4010 inside-address address 192.168.10.0/24
set service nat rule 4010 destination address 192.168.10.0/24
±×¸®°í PBR ¼³Á¤ÇϽŠµÚ ¶ó¿ìÆà °æ·Î´Â Á¤»óÀûÀ¸·Î ÀâÈ÷´ÂÁö, °ÔÀÌÆ®¿þÀÌ¿ÍÀÇ Åë½ÅÀº °¡´ÉÇÑÁö Á¡°ËÇØ º¸½Ã±¸¿ä.
[±âÁ¸°øÀ¯±â]---[ER-X]---[¼ÂÆÃPC]
+---[´Ù¸¥PC]
ÀÌ·¸°Ô ¿¬°áÇØµÎ°í ¼ÂÆü³Á¤ÁßÀä,
¼ÂÆÃPC¿¡¼ ±âÁ¸°øÀ¯±â³ª, ´Ù¸¥PC·Î ¿¬°áÀº Àߵ˴ϴÙ.
nslookupÀ¸·Î www.google.comÄõ¸®Çϸé IPµµ Àß Ã£½À´Ï´Ù.
ÇÏÁö¸¸ ÀÎÅͳÝÀ¸·Î´Â ºüÁ®³ª°¡Áö¸¦ ¸øÇϳ׿ä
masq·êÀº ¾Æ·¡Ã³·³ º¯°æÇÏ¿´½À´Ï´Ù.
set service nat rule 5010 description 'masquerade for WAN1'
set service nat rule 5010 outbound-interface eth3
set service nat rule 5010 type masquerade
set service nat rule 5010 protocol all
2. ¼¼ÆÃ(Å×½ºÆ®)ÀåºñÀÇ IP´Â ¾î¶»°Ô µÇ½Ã´ÂÁö¿ä.
3. Routing Table°ú default routeÀÇ ¸ÞÆ®¸¯ °ªÀº ¾î¶»°Ô µÇ¾î ÀÖ´ÂÁö¿ä
4. ·Îµå ¹ë·±½Ìµµ ÇÑ´Ù°í Çϼ̴µ¥ °ü·Ã ¼¼ÆÃÀ» Çϼ̴ÂÁö, ¾Æ´Ï¸é ÇÏÁö ¾ÊÀº °ÍÀÎÁö¿ä
2. Å×½ºÆ®ÀåºñIP´Â DHCP·ÎºÎÅÍ ÀÓ´ë¹Þ¾Æ¼ 192.168.10.2 ÀÔ´Ï´Ù.
3. er-x¿¡¼ Ç¥½ÃµÇ´Â routing tableÀ» ¸»¾¸ÇϽô°ÇÁö ¾Æ´Ï¸é ¼¼ÆÃPC¿¡¼ route printÇÞÀ»¶§ º¸¿©Áö´Â°É ¸»¾¸ÇϽô°ǰ¡¿ä?
4. ·Îµå ¹ë·±½Ì ¿ª½Ã WAN1->WAN2->·Îµå¹ë·±½Ì ¼øÀ¸·Î ¼ÂÆÃÀ» ÇÏ·Á°í ¾ÆÁ÷ À¯¿¹ÁßÀÔ´Ï´Ù.
ÀÎÅÍÆäÀ̽º¿¡¼ Proxy ARP¸¦ È°¼ºÈÇØÁÖ¸é µ¿ÀÛÇÏ°ÚÁö¸¸, ARP Entry ¹®Á¦°¡ »ý±æ °¡´É¼ºÀÌ ÀÖ¾î º¸ÀÔ´Ï´Ù.
Next-hop-address¸¦ »ç¿ëÇϰųª ´õ ³ªÀº ¹æ¹ýÀ» ã¾ÆºÁ¾ß ÇÒ °Í °°½À´Ï´Ù.