# OpenWRT V6プラス (MAP-E) 接続設定

**URL:** https://forum.ficusonline.com/t/topic/498
**Category:** Linux
**Created:** [2023 年 10 月 17 日午後 9:43 UTC](https://forum.ficusonline.com/t/topic/498 "2023-10-17T21:43:30Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2023 年 10 月 24 日午前 7:45 UTC](https://forum.ficusonline.com/t/topic/498/2 "2023-10-24T07:45:29Z")

</div>

## OpenWRTルータへのSSH接続

MAP-E対応にするためには、SSH接続でのリモート操作が必須です。以下SSH接続後に必要となるコマンドとMAP-Eに対応するために編集が必要なファイルを列挙します。

ルータへの接続

```auto
$ ssh root@192.168.1.1

```

ファイヤーウォールルールのリロード（システムデーモン）

```auto
# /etc/init.d/firewall reload

# service firewall reload

```

ファイヤーウォール設定ファイル

> `/etc/config/firewall`

ネットワーク設定ファイルのリロード（システムデーモン）

```auto
#/etc/init.d/network/reload

# service network reload

```

ネットワーク設定ファイル

> `/etc/config/network`

パッケージアップデート、アップグレード、インストール

```auto
# opkg update
# opkg upgrade <package_name>
# opkg install <package_name>

```

* * *

### ファイヤーウォールコマンド：nft, fw4

OpenWRTのファイヤーウォール **`fw4`** の実体は、 **`nftables`** のテーブル **`"table inet fw4”`** を作成・編集し、nftablesを起動・停止、設定ファイルの再読込などを行うスクリプトです。`(/sbin/fw4)`

ファイヤーウォール : fw4

> **[\[OpenWrt Wiki\] Firewall overview](https://openwrt.org/docs/guide-user/firewall/overview)**

設定例

> **[\[OpenWrt Wiki\] IPv4 firewall examples](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_config_examples)**

ファイヤーウォールのルール追加は、 **`uci`** コマンドか **`nft`** コマンドで行います。

全テーブルルール確認

```auto
# nft list ruleset

```

全ルールの削除

```auto
# nft flush ruleset

```

**`fw4`** が実行するルールセット

```auto
# fw4 print

```

```auto
table inet fw4
flush table inet fw4

table inet fw4 {
	#
	# Defines
	#

....................
....................

	#
	# User includes
	#

	include "/etc/nftables.d/*.nft"
.....................
....................

```

ルール追加は、デフォルトで読み込まれる設定ファイル

> **`/etc/nftables.d/*.nft`**

を作成することでも可能です（ただしテーブル **`inet fw4`** 限定です）。

* * *

MAP-Eを導入する場合、割当てられたパブリックIPv4のポート郡に効率的に通信パケットを割振るため（+ pingを実行可）、ロードバランスルールをICMP,TCP,UDPの各プロトコルに適用したテーブルを追加します。

```auto
table inet mape {
	chain srcnat {
		type nat hook postrouting priority filter; policy accept;
		ip protocol icmp oifname "map-wan6mape" snat ip to 10.20.30.40:numgen inc mod 240 map { 0 : xxxx, 1 : xxxx, ......., 239 : xxxx }
		ip protocol tcp oifname "map-wan6mape" snat ip to 10.20.30.40:numgen inc mod 240 map { 0 : xxxx, 1 : xxxx, ......., 239 : xxxx }
		ip protocol udp oifname "map-wan6mape" snat ip to 10.20.30.40:numgen inc mod 240 map { 0 : xxxx, 1 : xxxx, ......., 239 : xxxx }
	}
}

```

このテーブルを追加する以下のスクリプトを _ **/lib/netifd/proto/map.sh** _ と入替えます。

> <https://github.com/fakemanhk/openwrt-jp-ipoe/blob/main/map.sh.new>

```auto
# cd /lib/netifd/proto
# cp map.sh map.sh.old （バックアップ）
# vi map.sh （内容を削除してコピー＆ペースト）
# nft flush ruleset （全ルールセット削除）
# service network restart （ネットワーク再起動）

```

注）OpenWRTのファイヤーウォール **`fw4`** は、ルールセットテーブル **`inet fw4`** のみ管理するため、上記スクリプトでは再起動する度にテーブル **`inet mape`** にルールが追加されてしまいます。

修正）下記箇所にテーブルを削除する条件文スクリプト **`if ~ nft delete table inet mape ~fi`** 追加

`/lib/netifd/proto/map.sh`

```auto
#------------------------------------
            #MODIFICATION 2: Create mape table
#------------------------------------
            if nft list tables | grep -q "table inet mape"; then                                               
                nft delete table inet mape                                                                             
            fi                                                                                                         
            nft add table inet mape                                                                                    
            nft add chain inet mape srcnat {type nat hook postrouting priority 0\; policy accept\; }
#------------------------------------
	    #END MODIFICATION 2
#------------------------------------

```

---

_[View the full topic](https://forum.ficusonline.com/t/topic/498)._
