! ! Century Systems NXR-G110 Series ver 21.7.20 (build 4/19:47 15 03 2023) ! hostname NXR_C telnet-server enable telnet-server ip forbidden-access-wan telnet-server ipv6 forbidden-access-wan http-server enable http-server ip forbidden-access-wan http-server ipv6 forbidden-access-wan no rest http enable no rest https enable ! ! system power-management mode balance ! ! ! ipv6 forwarding no fast-forwarding enable ! ! ! ! ppp account username [モバイル(PPP)接続用ユーザID] password [モバイル(PPP)接続用パスワード] ! ! l2tp udp source-port 40001 ! l2tpv3 hostname NXRC l2tpv3 router-id 192.168.10.3 l2tpv3 path-mtu-discovery enable ! ipsec local policy 1 address ip self-identity fqdn NXRC ! ! ipsec isakmp policy 1 description NXR_A authentication pre-share IPsecKEY2 hash sha256 encryption aes128 group 5 lifetime 86400 isakmp-mode aggressive remote address ip 203.0.113.1 local policy 1 ! ! ipsec tunnel policy 1 description NXR_A set transform esp-aes128 esp-sha256-hmac set pfs group5 set key-exchange isakmp 1 set sa lifetime 28800 match address IPsec_ACL ! ! l2tpv3 tunnel 1 description NXR_A tunnel address 203.0.113.1 tunnel hostname NXRA tunnel router-id 192.168.10.1 ! l2tpv3 xconnect 1 description NXR_A tunnel 1 xconnect ethernet 0 xconnect end-id 1 retry-interval 30 ip tcp adjust-mss auto ! interface ppp 0 ip address negotiated ip tcp adjust-mss auto ip access-group in ppp0_IN ip access-group out ppp0_OUT ip masquerade ip spi-filter ppp username [モバイル(PPP)接続用ユーザID] ppp ipcp enable dial-up string *99***1# dial-up timeout 30 mobile apn [APN] cid 1 pdp-type ip ipsec policy 1 ! interface ethernet 0 ip address 192.168.10.3/24 ! interface ethernet 1 no ip address ! dns service enable ! ! syslog local enable exit-syslog ! ! mobile 1 ppp 0 mobile 1 carrier [キャリア] mobile error-recovery-reset mobile termination-recovery reset ! ! ! ! ! ! ! ! ip route 0.0.0.0/0 ppp 0 ! ! ! ip access-list ppp0_IN permit 203.0.113.1 any udp 500 500 ip access-list ppp0_IN permit 203.0.113.1 any 50 ip access-list ppp0_OUT deny any 203.0.113.1 115 ! ipsec access-list IPsec_ACL ip host host ! ! ! end