vpn01% sudo ip l2tp show tunnel
Tunnel 3939, encap UDP
From 192.168.122.24 to 192.168.122.32
Peer tunnel 3940
UDP source / dest ports: 1701/1701
UDP checksum: disabled
セッション設定を確認する際はshow sessionです。
1
2
3
4
5
vpn01% sudo ip l2tp show session
Session 3941 in tunnel 3939
Peer session 3942, tunnel 3940
interface name: l2tpeth0
offset 0, peer offset 0
うまく設定できれば、l2tpeth0デバイスができているはずです。
1
2
3
4
5
6
vpn01% ip link show dev l2tpeth0
4: l2tpeth0: <BROADCAST,MULTICAST> mtu 1446 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/ether 6a:02:f6:4d:d3:f0 brd ff:ff:ff:ff:ff:ff
vpn01% ip addr show dev l2tpeth0
4: l2tpeth0: <BROADCAST,MULTICAST> mtu 1446 qdisc noop state DOWN group default qlen 1000
link/ether 6a:02:f6:4d:d3:f0 brd ff:ff:ff:ff:ff:ff
vpn01% sudo ip link set dev l2tpeth0 up mtu 1446
vpn01% ip link show dev l2tpeth0
4: l2tpeth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1446 qdisc pfifo_fast state UNKNOWN mode DEFAULT group default qlen 1000
link/ether 6a:02:f6:4d:d3:f0 brd ff:ff:ff:ff:ff:ff
#!/bin/sh# L2TP
ip l2tp add tunnel \
tunnel_id 3939 \
peer_tunnel_id 3940 \
encap udp \local 192.168.122.24 \
remote 192.168.122.32 \
udp_sport 1701 \
udp_dport 1701
ip l2tp add session \
tunnel_id 3939 \
session_id 3941 \
peer_session_id 3942
ip link set dev l2tpeth0 up mtu 1446
# Bridge
ip link add br-l2tp0 type bridge
ip addr add 10.0.2.11/24 dev br-l2tp0
ip link set dev br-l2tp0 up
ip link set dev l2tpeth0 master br-l2tp0
ip link set dev eth1 master br-l2tp0
ip link set dev eth1 up
#!/bin/sh# L2TP
ip l2tp add tunnel \
tunnel_id 3940 \
peer_tunnel_id 3939 \
encap udp \local 192.168.122.32 \
remote 192.168.122.24 \
udp_sport 1701 \
udp_dport 1701
ip l2tp add session \
tunnel_id 3940 \
session_id 3942 \
peer_session_id 3941
ip link set dev l2tpeth0 up mtu 1446
# Bridge
ip link add br-l2tp0 type bridge
ip addr add 10.0.2.21/24 dev br-l2tp0
ip link set dev br-l2tp0 up
ip link set dev l2tpeth0 master br-l2tp0
ip link set dev eth1 master br-l2tp0
ip link set dev eth1 up
vpn01% ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether 52:54:00:ad:86:73 brd ff:ff:ff:ff:ff:ff
inet 192.168.122.24/24 brd 192.168.122.255 scope global eth0
valid_lft forever preferred_lft forever
inet6 fe80::5054:ff:fead:8673/64 scope link
valid_lft forever preferred_lft forever
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast master br-l2tp0 state UP group default qlen 1000
link/ether 52:54:00:54:ac:58 brd ff:ff:ff:ff:ff:ff
inet6 fe80::5054:ff:fe54:ac58/64 scope link
valid_lft forever preferred_lft forever
4: l2tpeth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1446 qdisc pfifo_fast master br-l2tp0 state UNKNOWN group default qlen 1000
link/ether 52:b1:7b:58:22:9c brd ff:ff:ff:ff:ff:ff
inet6 fe80::50b1:7bff:fe58:229c/64 scope link
valid_lft forever preferred_lft forever
5: br-l2tp0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1446 qdisc noqueue state UP group default qlen 1000
link/ether 52:54:00:54:ac:58 brd ff:ff:ff:ff:ff:ff
inet 10.0.2.11/24 scope global br-l2tp0
valid_lft forever preferred_lft forever
inet6 fe80::e862:2eff:fe1d:568b/64 scope link
valid_lft forever preferred_lft forever
1
2
3
4
vpn01% ip r
default via 192.168.122.1 dev eth0 metric 202
10.0.2.0/24 dev br-l2tp0 proto kernel scope link src 10.0.2.11
192.168.122.0/24 dev eth0 proto kernel scope link src 192.168.122.24
1
2
3
4
5
6
7
8
9
10
11
vpn01% ping -c 5 10.0.2.21
PING 10.0.2.21 (10.0.2.21): 56 data bytes
64 bytes from 10.0.2.21: seq=0 ttl=64 time=1.024 ms
64 bytes from 10.0.2.21: seq=1 ttl=64 time=0.999 ms
64 bytes from 10.0.2.21: seq=2 ttl=64 time=1.046 ms
64 bytes from 10.0.2.21: seq=3 ttl=64 time=0.631 ms
64 bytes from 10.0.2.21: seq=4 ttl=64 time=0.965 ms
--- 10.0.2.21 ping statistics ---
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max = 0.631/0.933/1.046 ms
vpn02% ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether 52:54:00:e3:36:13 brd ff:ff:ff:ff:ff:ff
inet 192.168.122.32/24 brd 192.168.122.255 scope global eth0
valid_lft forever preferred_lft forever
inet6 fe80::5054:ff:fee3:3613/64 scope link
valid_lft forever preferred_lft forever
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast master br-l2tp0 state UP group default qlen 1000
link/ether 52:54:00:fe:ad:9d brd ff:ff:ff:ff:ff:ff
inet6 fe80::5054:ff:fefe:ad9d/64 scope link
valid_lft forever preferred_lft forever
4: l2tpeth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1446 qdisc pfifo_fast master br-l2tp0 state UNKNOWN group default qlen 1000
link/ether 4a:4f:41:92:a9:b1 brd ff:ff:ff:ff:ff:ff
inet6 fe80::484f:41ff:fe92:a9b1/64 scope link
valid_lft forever preferred_lft forever
5: br-l2tp0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1446 qdisc noqueue state UP group default qlen 1000
link/ether 4a:4f:41:92:a9:b1 brd ff:ff:ff:ff:ff:ff
inet 10.0.2.21/24 scope global br-l2tp0
valid_lft forever preferred_lft forever
inet6 fe80::9822:3ff:fea5:7bd1/64 scope link
valid_lft forever preferred_lft forever
1
2
3
4
vpn02% ip r
default via 192.168.122.1 dev eth0 metric 202
10.0.2.0/24 dev br-l2tp0 proto kernel scope link src 10.0.2.21
192.168.122.0/24 dev eth0 proto kernel scope link src 192.168.122.32
1
2
3
4
5
6
7
8
9
10
11
vpn02% ping -c 5 10.0.2.11
PING 10.0.2.11 (10.0.2.11): 56 data bytes
64 bytes from 10.0.2.11: seq=0 ttl=64 time=0.790 ms
64 bytes from 10.0.2.11: seq=1 ttl=64 time=0.987 ms
64 bytes from 10.0.2.11: seq=2 ttl=64 time=0.922 ms
64 bytes from 10.0.2.11: seq=3 ttl=64 time=0.910 ms
64 bytes from 10.0.2.11: seq=4 ttl=64 time=1.176 ms
--- 10.0.2.11 ping statistics ---
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max = 0.790/0.957/1.176 ms