IX2015のコンフィグ

IX2015のコンフィグで来る人が多いので。
・ユーザ名/パスワード
・IPアドレス
・ルーティング
・NAPTサービス
・フィルタリング
以上を適宜書き換えてますが、当方のIX2015はフレッツ+スクウェアでやってます。

! NEC Portable Internetwork Core Operating System Software
! IX Series IX2010 (magellan-sec) Software, Version 8.1.15, RELEASE SOFTWARE
! Compiled Mar 10-Mon-2008 13:11:22 JST #1
! Current time Jan 20-Tue-2009 23:32:13 JST
!
!
hostname XXXXXX
timezone +09 00
!
syslog facility local1
syslog ip host 192.168.0.10
!
username XXXXX password hash XXXXXXXXXXX administrator
!
ntp ip enable
ntp server 210.173.160.27
ntp server 210.173.160.57
ntp server 210.173.160.87
ntp server 133.243.238.164
ntp retry 3
ntp interval 3600
!
logging buffered 1048576
logging subsystem circ notice
logging subsystem ike error
logging subsystem key error
logging subsystem ppoe notice
logging timestamp datetime

ip multicast-routing
ip route default FastEthernet0/0.2
ip route 220.210.194.0/25 FastEthernet0/0.2
ip route 220.210.195.0/26 FastEthernet0/0.2
ip route 220.210.195.64/26 FastEthernet0/0.2
ip route 220.210.196.0/25 FastEthernet0/0.2
ip route 220.210.196.128/26 FastEthernet0/0.2
ip route 220.210.197.0/25 FastEthernet0/0.2
ip route 220.210.198.0/26 FastEthernet0/0.2
ip route 220.210.199.32/27 FastEthernet0/0.2
ip route 220.210.199.64/28 FastEthernet0/0.2
ip route 220.210.199.144/28 FastEthernet0/0.2
ip route 220.210.199.160/27 FastEthernet0/0.2
ip route 220.210.199.192/27 FastEthernet0/0.2
ip route 220.210.199.200/29 FastEthernet0/0.2
ip access-list all-pass permit ip src any dest any
ip access-list management permit ip src 192.168.0.0/24 dest any
ip access-list nbt-block deny tcp src any sport any dest any dport eq 137
ip access-list nbt-block deny udp src any sport any dest any dport eq 137
ip access-list nbt-block deny udp src any sport any dest any dport eq 138
ip access-list nbt-block deny tcp src any sport any dest any dport eq 139
ip access-list nbt-block deny tcp src any sport any dest any dport eq 445
ip access-list nbt-block deny udp src any sport any dest any dport eq 445
ip access-list nbt-block deny udp src any sport any dest any dport eq 23
ip access-list nbt-block deny tcp src any sport any dest any dport eq 23
ip access-list specialuse deny ip src 0.0.0.0/8 dest any
ip access-list specialuse deny ip src 10.0.0.0/8 dest any
ip access-list specialuse deny ip src 172.16.0.0/12 dest any
ip access-list specialuse deny ip src 127.0.0.0/8 dest any
ip access-list specialuse deny ip src 169.254.0.0/16 dest any
ip access-list specialuse deny ip src 192.0.2.0/24 dest any
ip access-list specialuse deny ip src 224.0.0.0/3 dest any
ip ufs-cache max-entries 20000
ip ufs-cache enable
!
snmp-agent ip enable
snmp-agent ip community XXXXXX
!
proxy-dns ip enable
proxy-dns ip max-sessions 128
proxy-dns ip query-interval 1
!
telnet-server ip enable
telnet-server ip access-list management
!
route-map server permit 10
!
ppp profile ppp_profile
authentication myname XXX@XX.XX
authentication password XXX@XX.XX XXXX
!
ppp profile square
authentication myname guest@flets
authentication password guest@flets guest
!
device FastEthernet0/0
!
device FastEthernet0/1
speed 100
!
device FastEthernet1/0
!
device BRI1/0
isdn switch-type hsd128k
!
interface FastEthernet0/0.0
no ip address
no shutdown
!
interface FastEthernet0/1.0
description ###Local LAN1###
ip address 192.168.0.254/24
no shutdown
!
interface FastEthernet1/0.0
no ip address
shutdown
!
interface BRI1/0.0
encapsulation ppp
no auto-connect
no ip address
shutdown
!
interface FastEthernet0/0.1
description ###WAN_INTERNET
encapsulation pppoe
auto-connect
ppp binding ppp_profile
ip address ipcp
ip mtu 1454
ip tcp adjust-mss 1414
ip napt enable
ip napt service XXX 192.168.0.10 none tcp XX
ip filter nbt-block 1 in
ip filter specialuse 2 in
ip filter all-pass 65535 in
ip filter nbt-block 1 out
ip filter all-pass 65535 out
no shutdown
!
interface FastEthernet0/0.2
description ###WAN_FLETS-SQUARE
encapsulation pppoe
auto-connect
ppp binding square
ip address ipcp
ip mtu 1454
ip tcp adjust-mss 1414
ip napt enable
ipv6 enable
no shutdown
!
interface FastEthernet0/1.1
encapsulation pppoe
auto-connect
no ip address
shutdown
!
interface FastEthernet1/0.1
encapsulation pppoe
auto-connect
no ip address
shutdown
!
interface Loopback0.0
ip address 192.168.11.1/24
!
interface Null0.0
no ip address
!
interface AutoTunnel0.0
no ip address
shutdown

2009/1/20現在、ヤフオクのIX2015は諸々込で10000円が相場ってところでしょうか。
使用者という贔屓目で見ても、この価格でこの性能は大満足でしょう。
中古市場に大量流出→値崩れを起こしてくれた郵政局様に大感謝です。

シェアする

  • このエントリーをはてなブックマークに追加

フォローする