{"id":119,"date":"2022-10-13T23:03:13","date_gmt":"2022-10-13T14:03:13","guid":{"rendered":"https:\/\/origin.intinfinity.com\/?p=119"},"modified":"2023-04-17T00:50:55","modified_gmt":"2023-04-16T15:50:55","slug":"openwrt-22-03-0-%e3%81%a7-nat64dns64-%e3%82%92%e3%81%99%e3%82%8b","status":"publish","type":"post","link":"https:\/\/intinfinity.com\/index.php\/archives\/119","title":{"rendered":"OpenWrt 22.03.0 \u3067 NAT64+DNS64 \u3092\u3059\u308b"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">\u524d\u66f8\u304d<\/h2>\n\n\n\n<p>IPv6\u30b7\u30f3\u30b0\u30eb\u30b9\u30bf\u30c3\u30af\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3092\u4f5c\u308b\u3068\u3001IPv4\u306e\u307f\u306e\u30b5\u30fc\u30d0\u30fc\u306b\u63a5\u7d9a\u3067\u304d\u306a\u304f\u306a\u308b\u3002<br>NAT64\u3092\u4f7f\u3046\u3053\u3068\u3067\u3001IPv6\u30a2\u30c9\u30ec\u30b9\u3092\u4f7f\u3063\u3066IPv4\u30b5\u30fc\u30d0\u30fc\u306b\u63a5\u7d9a\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u3002<br>\u305f\u3060\u3057\u3001NAT64\u3092\u884c\u3046\u30eb\u30fc\u30bf\u30fc\u306fIPv6\u3068IPv4\u306e\u30c7\u30e5\u30a2\u30eb\u30b9\u30bf\u30c3\u30af\u3067\u3042\u308b\u3053\u3068\u304c\u5fc5\u8981\u3002<br>OpenWRT\u306bjool\u3068knot-resolver\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3066\u3001LAN\u5185\u3092\u30b7\u30f3\u30b0\u30eb\u30b9\u30bf\u30c3\u30af\u3067\u6e08\u3080\u3088\u3046\u306b\u3059\u308b\u3002<\/p>\n\n\n\n<p>\u3053\u3053\u3067\u306fknot-resolver\u3092\u4f7f\u3044\u307e\u3059\u304c\u3001\u305d\u308c\u306a\u308a\u306b\u30b9\u30c8\u30ec\u30fc\u30b8\u3092\u6d88\u8cbb\u3057\u307e\u3059\u306e\u3067\u3001unbound\u306e\u307b\u3046\u304c\u3088\u3044\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u3002<br>NanoPi R2S \u3092\u4f7f\u3063\u3066\u3044\u307e\u3059\u304c\u3001SquashFS \u6a19\u6e96\u306e\u5272\u308a\u5f53\u3066\u5bb9\u91cf\u3067\u306f\u4e0d\u8db3\u3057\u307e\u3057\u305f\u3002 ext4\u7248\u3092\u4f7f\u3063\u3066\u30b9\u30c8\u30ec\u30fc\u30b8\u3044\u3063\u3071\u3044\u307e\u3067\u9818\u57df\u3092\u62e1\u5f35\u3057\u3066\u4f7f\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>jool-tools-netfilter<\/li>\n\n\n\n<li>knot-resolver<\/li>\n<\/ul>\n\n\n\n<p>\u203b\u307b\u304b\u306e\u30d1\u30c3\u30b1\u30fc\u30b8\u306f\u4f9d\u5b58\u95a2\u4fc2\u3067\u81ea\u52d5\u7684\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u308b\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u30d1\u30c3\u30b1\u30fc\u30b8\u30d0\u30fc\u30b8\u30e7\u30f3<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code># jool --version\n(Xtables disabled)\n4.1.6.1\n# kresd --version\nKnot Resolver, version 5.5.3<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">jool<\/h2>\n\n\n\n<p>jool\u3092\u4f7f\u3063\u3066\u3001NAT64\u3092\u5b9f\u88c5\u3059\u308b\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u30b5\u30fc\u30d3\u30b9\u306e\u505c\u6b62<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># service jool stop<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u306e\u30d0\u30c3\u30af\u30a2\u30c3\u30d7<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># mv \/etc\/jool\/jool-nat64.conf.json \/etc\/jool\/jool-nat64.conf.json.bk<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># vi \/etc\/jool\/jool-nat64.conf.json<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>{\n\t\"instance\": \"nat64-minimal\",\n\t\"framework\": \"netfilter\",\n\n\t\"global\": {\n\t\t\"pool6\": \"64:ff9b::\/96\"\n\t}\n}<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code># vi \/etc\/config\/jool<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>config jool 'general'\n        option enabled '1'\n\nconfig jool 'nat64'\n        option enabled '1'\n\nconfig jool 'siit'\n        option enabled '0'<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u30b5\u30fc\u30d3\u30b9\u306e\u958b\u59cb<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># service jool start<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">knot-resolver<\/h2>\n\n\n\n<p>knot-resolver\u3092\u4f7f\u3063\u3066DNS64\u3092\u5b9f\u88c5\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># vi \/etc\/init.d\/kresd<\/code><\/pre>\n\n\n\n<p>\u7de8\u96c6\u524d<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>        # knot-resolver config\n        procd_append_param command -c \"$CONFIGFILE\"\n        procd_append_param command -a \"0.0.0.0#53\"\n        procd_append_param command -a \"::0#53\"\n        procd_set_param nice '-5'\n        procd_close_instance<\/code><\/pre>\n\n\n\n<p>\u7de8\u96c6\u5f8c<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>        # knot-resolver config\n        procd_append_param command -c \"$CONFIGFILE\"\n        <mark style=\"background-color:#fcb900\" class=\"has-inline-color has-black-color\">procd_append_param command -c \"\/etc\/knot-resolver\/kresd.conf\"<\/mark>\n        procd_append_param command -a \"0.0.0.0#53\"\n        procd_append_param command -a \"::0#53\"\n        procd_set_param nice '-5'\n        procd_close_instance<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code># vi \/etc\/knot-resolver\/kresd.conf<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>-- Enable DNS64<br>modules = { 'dns64' }<br>-- DNS64 Reconfigure<br>-- dns64.config({ prefix = '64:ff9b::' })<\/code><\/pre>\n\n\n\n<p>\u3053\u306e\u307e\u307e\u3060\u3068knot-resolver\u304c\u81ea\u3089DNS\u30b5\u30fc\u30d0\u30fc\u3078\u554f\u3044\u5408\u308f\u305b\u307e\u3059\u304c\u3001ISP\u304c\u63d0\u4f9b\u3059\u308bDNS\u30b5\u30fc\u30d0\u306b\u8ee2\u9001\u3057\u305f\u3044\u5834\u5408\u306f\u3001\u540c\u30d5\u30a1\u30a4\u30eb\u306b\u4ee5\u4e0b\u306e\u8a2d\u5b9a\u3092\u5165\u308c\u3066\u304a\u304d\u307e\u3059\u3002(\u79c1\u306e\u74b0\u5883\u3067\u306f\u3001HGW\u306e\u30a2\u30c9\u30ec\u30b9\u3092\u8a2d\u5b9a\u3059\u308b\u3068\u304d\u306bDNSSEC\u3092\u6709\u52b9\u306b\u3059\u308b\u3068\u30c0\u30e1\u3060\u3063\u305f\u306e\u3067\u3001\u4ee5\u4e0b\u306e\u4f8b\u306f\u4f7f\u7528\u3057\u306a\u3044\u4f8b\u3067\u3059\u3002)<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>policy.add(policy.all(policy.STUB({'192.168.1.1'})))<\/code><\/pre>\n\n\n\n<p>\"STUB\"\u306e\u90e8\u5206\u3092\"FORWARD\"\u306b\u3059\u308b\u3068DNSSEC\u3092\u3092\u6709\u52b9\u306b\u3057\u3001DNS over TLS\u3092\u4f7f\u7528\u3057\u305f\u3044\u5834\u5408\u306f\"TLS_FORWARD\"\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002\u8a73\u3057\u304f\u306f\u3001 <a href=\"https:\/\/knot-resolver.readthedocs.io\/en\/stable\/modules-policy.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/knot-resolver.readthedocs.io\/en\/stable\/modules-policy.html<\/a> \u3092\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\u3002<\/p>\n\n\n\n<p>Dnsmasq\u306eDNS\u30b5\u30fc\u30d0\u3092\u7121\u52b9\u306b\u3057\u3066knot-resolver\u3092\u6709\u52b9\u306b\u3059\u308b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># uci set dhcp.@dnsmasq&#91;0].port='0'\n# uci commit dhcp\n# service dnsmasq restart\n# service kresd restart<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">\u78ba\u8a8d<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code># jool instance display\n(Xtables disabled)\n+--------------------+-----------------+-----------+\n|          Namespace |            Name | Framework |\n+--------------------+-----------------+-----------+\n|           10db2440 |   nat64-minimal | netfilter |\n+--------------------+-----------------+-----------+\n# jool --instance \"nat64-minimal\" global display\n(Xtables disabled)\n  manually-enabled: true\n  pool6: 64:ff9b::\/96\n  lowest-ipv6-mtu: 1280\n  logging-debug: false\n  zeroize-traffic-class: false\n  override-tos: false\n  tos: 0\n  mtu-plateaus: 65535,32000,17914,8166,4352,2002,1492,1006,508,296,68\n  address-dependent-filtering: false\n  drop-externally-initiated-tcp: false\n  drop-icmpv6-info: false\n  source-icmpv6-errors-better: true\n  f-args: 11 (0b1011): SrcAddr:1 SrcPort:0 DstAddr:1 DstPort:1\n  handle-rst-during-fin-rcv: false\n  tcp-est-timeout: 2:00:00 (HH:MM:SS)\n  tcp-trans-timeout: 0:04:00 (HH:MM:SS)\n  udp-timeout: 0:05:00 (HH:MM:SS)\n  icmp-timeout: 0:01:00 (HH:MM:SS)\n  logging-bib: false\n  logging-session: false\n  maximum-simultaneous-opens: 10\n  ss-enabled: false\n  ss-flush-asap: true\n  ss-flush-deadline: 2000\n  ss-capacity: 512\n  ss-max-payload: 1452<\/code><\/pre>\n\n\n\n<p>\u554f\u984c\u306a\u304f\u52d5\u4f5c\u3057\u3066\u3044\u308b\u3088\u3046\u3067\u3042\u308c\u3070\u3001\u7aef\u672b\u3078\u306eIPv4\u30a2\u30c9\u30ec\u30b9\u306e\u5272\u308a\u5f53\u3066\u3092\u505c\u6b62\u3057\u307e\u3059\u3002\u7aef\u672b\u306bIPv6\u30a2\u30c9\u30ec\u30b9\u306e\u307f\u5272\u5f53\u305f\u3063\u3066\u3044\u308b\u72b6\u614b\u3067\u3001IPv4\u306eWeb\u30da\u30fc\u30b8\u3092\u958b\u304f\u3053\u3068\u304c\u3067\u304d\u308c\u3070\u5b8c\u4e86\u3067\u3059\u3002 <a rel=\"noreferrer noopener\" href=\"https:\/\/ipv6.test-ipv6.com\/\" target=\"_blank\">https:\/\/ipv6.test-ipv6.com\/<\/a> \u306a\u3069\u3092\u4f7f\u3063\u3066\u3001\u30c7\u30e5\u30a2\u30eb\u30b9\u30bf\u30c3\u30af\u306e\u74b0\u5883\u3068\u3057\u3066\u52d5\u4f5c\u3057\u3066\u308b\u304b\u78ba\u8a8d\u3059\u308b\u3068\u3088\u3044\u3067\u3059\u3002 <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u30bb\u30c3\u30b7\u30e7\u30f3\u30c6\u30fc\u30d6\u30eb<\/h2>\n\n\n\n<p>NAT64\u306e\u30bb\u30c3\u30b7\u30e7\u30f3\u30c6\u30fc\u30d6\u30eb\u3092\u78ba\u8a8d\u3059\u308b\u30b3\u30de\u30f3\u30c9<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>jool --instance \"nat64-minimal\" session display<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u306e\u6539\u5584<\/h2>\n\n\n\n<p>NanoPi R2S \u3092\u4f7f\u3063\u3066\u3044\u308b\u306e\u3067\u3059\u304c\u3001NAT64\u3060\u3068\u7279\u5b9a\u306e\u901a\u4fe1\u76f8\u624b\u3068\u306e\u901a\u4fe1\u304c\u7570\u5e38\u306b\u9045\u304f\u306a\u308b\u3068\u3044\u3046\u554f\u984c\u304c\u767a\u751f\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u8fbaMTU\u306a\u3069\u8abf\u67fb\u3057\u3066\u307f\u305f\u306e\u3067\u3059\u304c\u3088\u304f\u308f\u304b\u3089\u305a\u3002WAN\u5074\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u306e\u30aa\u30d5\u30ed\u30fc\u30c9\u3092\u7121\u52b9\u306b\u3057\u305f\u3089\u306a\u3093\u304b\u3088\u304f\u306a\u3063\u305f\u306e\u3067\u8a18\u8f09\u3057\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># ethtool --offload eth0 lro off\n# ethtool --offload eth0 gro off<\/code><\/pre>\n\n\n\n<p>\u8a2d\u5b9a\u72b6\u6cc1\u306f\u3001\u6b21\u306e\u30b3\u30de\u30f3\u30c9\u3067\u78ba\u8a8d\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># ethtool --show-offload eth0 | grep receive-offload<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">\u8ffd\u4f38(2023\/04\/17)<\/h2>\n\n\n\n<p>knot-resolver\u304b\u3089unbound\u306b\u4e57\u308a\u63db\u3048\u305f\u3002\u5225\u306e\u6a5f\u80fd\u304c\u4f7f\u3044\u305f\u304f\u3066knot-resolver\u3092\u4f7f\u3063\u3066\u3044\u305f\u306e\u3067\u3059\u304c\u3001\u305d\u306e\u5fc5\u8981\u304c\u306a\u304f\u306a\u3063\u305f\u306e\u3068\u3001\u30b3\u30e1\u30f3\u30c8\u3067\u3082\u8a00\u53ca\u304c\u3042\u3063\u305f\u306e\u3067\u3002<\/p>\n\n\n\n<p>luci-app-unbound \u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u5165\u308c\u308b\u3068\u3001LuCI(WebUI)\u304b\u3089\u8a2d\u5b9a\u3067\u304d\u3066\u4fbf\u5229\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u53c2\u8003\u8cc7\u6599<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a rel=\"noreferrer noopener\" href=\"https:\/\/www.jool.mx\/en\/run-nat64.html\" target=\"_blank\">https:\/\/www.jool.mx\/en\/run-nat64.html<\/a><\/li>\n\n\n\n<li><a rel=\"noreferrer noopener\" href=\"https:\/\/www.jool.mx\/en\/config-atomic.html\" target=\"_blank\">https:\/\/www.jool.mx\/en\/config-atomic.html<\/a><\/li>\n\n\n\n<li><a rel=\"noreferrer noopener\" href=\"https:\/\/qiita.com\/konosuke\/items\/a6fcb1709f46f396544f\" target=\"_blank\">https:\/\/qiita.com\/konosuke\/items\/a6fcb1709f46f396544f<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.jool.mx\/en\/offloads.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.jool.mx\/en\/offloads.html<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u524d\u66f8\u304d IPv6\u30b7\u30f3\u30b0\u30eb\u30b9\u30bf\u30c3\u30af\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3092\u4f5c\u308b\u3068\u3001IPv4\u306e\u307f\u306e\u30b5\u30fc\u30d0\u30fc\u306b\u63a5\u7d9a\u3067\u304d\u306a\u304f\u306a\u308b\u3002NAT64\u3092\u4f7f\u3046\u3053\u3068\u3067\u3001IPv6\u30a2\u30c9\u30ec\u30b9\u3092\u4f7f\u3063\u3066IPv4\u30b5\u30fc\u30d0\u30fc\u306b\u63a5\u7d9a\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u3002\u305f\u3060\u3057\u3001NAT64\u3092\u884c\u3046 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,10],"tags":[],"class_list":["post-119","post","type-post","status-publish","format-standard","hentry","category-linux","category-network"],"_links":{"self":[{"href":"https:\/\/intinfinity.com\/index.php\/wp-json\/wp\/v2\/posts\/119","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/intinfinity.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/intinfinity.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/intinfinity.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/intinfinity.com\/index.php\/wp-json\/wp\/v2\/comments?post=119"}],"version-history":[{"count":20,"href":"https:\/\/intinfinity.com\/index.php\/wp-json\/wp\/v2\/posts\/119\/revisions"}],"predecessor-version":[{"id":493,"href":"https:\/\/intinfinity.com\/index.php\/wp-json\/wp\/v2\/posts\/119\/revisions\/493"}],"wp:attachment":[{"href":"https:\/\/intinfinity.com\/index.php\/wp-json\/wp\/v2\/media?parent=119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/intinfinity.com\/index.php\/wp-json\/wp\/v2\/categories?post=119"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/intinfinity.com\/index.php\/wp-json\/wp\/v2\/tags?post=119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}