<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://lms.onnocenter.or.id/wiki/index.php?action=history&amp;feed=atom&amp;title=Open5gs%3A_Konfigurasi_ogstun_dan_ogstun2</id>
	<title>Open5gs: Konfigurasi ogstun dan ogstun2 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://lms.onnocenter.or.id/wiki/index.php?action=history&amp;feed=atom&amp;title=Open5gs%3A_Konfigurasi_ogstun_dan_ogstun2"/>
	<link rel="alternate" type="text/html" href="https://lms.onnocenter.or.id/wiki/index.php?title=Open5gs:_Konfigurasi_ogstun_dan_ogstun2&amp;action=history"/>
	<updated>2026-04-20T14:04:57Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://lms.onnocenter.or.id/wiki/index.php?title=Open5gs:_Konfigurasi_ogstun_dan_ogstun2&amp;diff=69707&amp;oldid=prev</id>
		<title>Unknown user: Created page with &quot;==Asumsi Konfigurasi==  * OS Ubuntu 22.04 * Open5GS &amp; IMS satu mesin * Satu Interface enp0s3 * IP Statik enp0s3 192.168.0.5/24 gateway 192.168.0.222 * IP Statik ogstun 10.45.0...&quot;</title>
		<link rel="alternate" type="text/html" href="https://lms.onnocenter.or.id/wiki/index.php?title=Open5gs:_Konfigurasi_ogstun_dan_ogstun2&amp;diff=69707&amp;oldid=prev"/>
		<updated>2023-08-15T03:31:03Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==Asumsi Konfigurasi==  * OS Ubuntu 22.04 * Open5GS &amp;amp; IMS satu mesin * Satu Interface enp0s3 * IP Statik enp0s3 192.168.0.5/24 gateway 192.168.0.222 * IP Statik ogstun 10.45.0...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Asumsi Konfigurasi==&lt;br /&gt;
&lt;br /&gt;
* OS Ubuntu 22.04&lt;br /&gt;
* Open5GS &amp;amp; IMS satu mesin&lt;br /&gt;
* Satu Interface enp0s3&lt;br /&gt;
* IP Statik enp0s3 192.168.0.5/24 gateway 192.168.0.222&lt;br /&gt;
* IP Statik ogstun 10.45.0.1/16 &amp;amp; 2001:db8:cafe::1/48&lt;br /&gt;
* IP Statik ogstun2 10.123.0.1/16 &amp;amp; 2001:db8:babe::1/48&lt;br /&gt;
* Domain mnc070.mcc999.3gppnetwork.org&lt;br /&gt;
* APN internet&lt;br /&gt;
* MCC 999 MNC 70&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Setup TUN device (not persistent)==&lt;br /&gt;
&lt;br /&gt;
Jika dibutuhkan kita dapat menset interface ogstun, tampaknya ini tidak dibutuhkan jika kita menginstall open5gs dari binary.&lt;br /&gt;
&lt;br /&gt;
Untuk membuat TUN device dengan nama interface ogstun, caranya adalah sebagai berikut,&lt;br /&gt;
&lt;br /&gt;
 ip tuntap add name ogstun mode tun&lt;br /&gt;
 ip addr add 10.45.0.1/16 dev ogstun&lt;br /&gt;
 ip addr add 2001:db8:cafe::1/48 dev ogstun&lt;br /&gt;
 ip link set ogstun mtu 1400&lt;br /&gt;
 ip link set ogstun up&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Tip: script ini tersedia di $GIT_REPO/misc/netconf.sh yang akan memudahkan kita dapat mengkonfigurasi TUN device:  &lt;br /&gt;
&lt;br /&gt;
 sudo ./misc/netconf.sh&lt;br /&gt;
&lt;br /&gt;
==Tambahkan Route Untuk UE ke WAN / Internet==&lt;br /&gt;
&lt;br /&gt;
Agar ada bridge antara PGWU/UPF dan WAN (Internet), kita perlu meng-enable IP forwarding dan NAT rule di IP Tables.&lt;br /&gt;
&lt;br /&gt;
Untuk mengaktifkan forwarding dan NAT rule, ketik,&lt;br /&gt;
&lt;br /&gt;
 ### Enable IPv4/IPv6 Forwarding&lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
 sudo sysctl -w net.ipv6.conf.all.forwarding=1&lt;br /&gt;
&lt;br /&gt;
 ### Add NAT Rule&lt;br /&gt;
 sudo iptables -t nat -A POSTROUTING -s 10.45.0.0/16 ! -o ogstun -j MASQUERADE&lt;br /&gt;
 sudo ip6tables -t nat -A POSTROUTING -s 2001:db8:cafe::/48 ! -o ogstun -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
Cek menggunakan perintah,&lt;br /&gt;
&lt;br /&gt;
 iptables -L -t nat&lt;br /&gt;
&lt;br /&gt;
Hasilnya harusnya NAT beroperasi seperti dibawah ini,&lt;br /&gt;
&lt;br /&gt;
 Chain POSTROUTING (policy ACCEPT)&lt;br /&gt;
 target     prot opt source               destination         &lt;br /&gt;
 MASQUERADE  all  --  10.45.0.0/16         anywhere &lt;br /&gt;
&lt;br /&gt;
Konfigurasi firewall dengan benar dan pastikan status ufw inactive.&lt;br /&gt;
&lt;br /&gt;
 sudo ufw status&lt;br /&gt;
&lt;br /&gt;
 Status: active&lt;br /&gt;
&lt;br /&gt;
Jika dibutuhkan, firewall dapat dimatikan menggunakan perintah berikut, dan disable waktu  start up,&lt;br /&gt;
&lt;br /&gt;
 sudo ufw disable&lt;br /&gt;
&lt;br /&gt;
Matikan firewall dan disable pada system startup&lt;br /&gt;
&lt;br /&gt;
 $ sudo ufw status&lt;br /&gt;
&lt;br /&gt;
 Status: inactive&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Optional, jika dibutuhkan, kita dapat melakukan konfigurasi berikut,&lt;br /&gt;
&lt;br /&gt;
 ### Ensure that the packets in the `INPUT` chain to the `ogstun` interface are accepted&lt;br /&gt;
 sudo iptables -I INPUT -i ogstun -j ACCEPT&lt;br /&gt;
&lt;br /&gt;
 ### Prevent UE&amp;#039;s from connecting to the host on which UPF is running&lt;br /&gt;
 sudo iptables -I INPUT -s 10.45.0.0/16 -j DROP &lt;br /&gt;
 sudo ip6tables -I INPUT -s 2001:db8:cafe::/48 -j DROP&lt;br /&gt;
&lt;br /&gt;
 ### If your core network runs over multiple hosts, you probably want to block&lt;br /&gt;
 ### UE originating traffic from accessing other network functions.&lt;br /&gt;
 ### Replace x.x.x.x/y with the VNFs IP/subnet&lt;br /&gt;
 sudo iptables -I FORWARD -s 10.45.0.0/16 -d x.x.x.x/y -j DROP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Konfigurasi dua interface TUN ogstun dan ogstun2==&lt;br /&gt;
&lt;br /&gt;
Jika dibutuhkan dua Interface, dapat menggunakan script di bawah ini:&lt;br /&gt;
&lt;br /&gt;
 #!/bin/bash&lt;br /&gt;
 &lt;br /&gt;
 sudo sysctl -w net.ipv4.ip_forward=1&lt;br /&gt;
 sudo sysctl -w net.ipv6.conf.all.forwarding=1&lt;br /&gt;
 &lt;br /&gt;
 ip tuntap add name ogstun mode tun&lt;br /&gt;
 ip addr add 10.45.0.1/16 dev ogstun&lt;br /&gt;
 ip addr add 2001:db8:cafe::1/48 dev ogstun&lt;br /&gt;
 ip link set ogstun mtu 1400&lt;br /&gt;
 ip link set ogstun up&lt;br /&gt;
 iptables -t nat -A POSTROUTING -s 10.45.0.0/16 ! -o ogstun -j MASQUERADE&lt;br /&gt;
 ip6tables -t nat -A POSTROUTING -s 2001:db8:cafe::/48 ! -o ogstun -j MASQUERADE&lt;br /&gt;
 iptables -I INPUT -i ogstun -j ACCEPT&lt;br /&gt;
 ip6tables -I INPUT -i ogstun -j ACCEPT&lt;br /&gt;
 &lt;br /&gt;
 ip tuntap add name ogstun2 mode tun&lt;br /&gt;
 ip addr add 10.123.0.1/16 dev ogstun2&lt;br /&gt;
 ip addr add 2001:db8:babe::1/48 dev ogstun2&lt;br /&gt;
 ip link set ogstun2 mtu 1400&lt;br /&gt;
 ip link set ogstun2 up&lt;br /&gt;
 iptables -t nat -A POSTROUTING -s 10.123.0.0/16 ! -o ogstun2 -j MASQUERADE&lt;br /&gt;
 ip6tables -t nat -A POSTROUTING -s 2001:db8:babe::/48 ! -o ogstun2 -j MASQUERADE&lt;br /&gt;
 iptables -I INPUT -i ogstun2 -j ACCEPT&lt;br /&gt;
 ip6tables -I INPUT -i ogstun2 -j ACCEPT&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Pranala Menarik==&lt;br /&gt;
&lt;br /&gt;
* [[5G]]&lt;/div&gt;</summary>
		<author><name>Unknown user</name></author>
	</entry>
</feed>