configの抜粋です。
ip lan3 address グローバルIP
ip lan3 secure filter in 30000 30001 30002 30003 30008 30009 30010 30011 30012
30013 30014 30015 30016 30018 30019 30020 30021
ip lan3 secure filter out 30004 30005 30006 30007 30008 30009 30010 30011 30012
30013 30099 dynamic 30080 30081 30082 30083 30084 30085 30098 30099
ip lan3 intrusion detection in on reject=on
ip lan3 intrusion detection out on reject=on
ip lan3 nat descriptor 1
tunnel select 1
tunnel name 名前
ipsec tunnel 1
ipsec sa policy 1 1 esp 3des-cbc md5-hmac
ipsec ike always-on 1 on
ipsec ike encryption 1 des-cbc
ipsec ike esp-encapsulation 1 off
ipsec ike group 1 modp768
ipsec ike hash 1 md5
ipsec ike keepalive log 1 on
ipsec ike keepalive use 1 on
ipsec ike local address 1 グローバルIP
ipsec ike pfs 1 off
ipsec ike pre-shared-key 1 text キー
ipsec ike remote address 1 接続先グローバルIP
tunnel enable 1
ip filter 30000 reject 10.0.0.0/8 * * * *
ip filter 30001 reject 172.16.0.0/12 * * * *
ip filter 30002 reject 192.168.0.0/16 * * * *
ip filter 30003 reject 192.168.0.0/24 * * * *
ip filter 30004 reject * 10.0.0.0/8 * * *
ip filter 30005 reject * 172.16.0.0/12 * * *
ip filter 30006 reject * 192.168.0.0/16 * * *
ip filter 30007 reject * 192.168.0.0/24 * * *
ip filter 30008 reject * * udp,tcp 135 *
ip filter 30009 reject * * udp,tcp * 135
ip filter 30010 reject * * udp,tcp netbios_ns-netbios_ssn *
ip filter 30011 reject * * udp,tcp * netbios_ns-netbios_ssn
ip filter 30012 reject * * udp,tcp 445 *
ip filter 30013 reject * * udp,tcp * 445
ip filter 30014 pass * * icmp * *
ip filter 30015 pass * * established * *
ip filter 30016 pass * * tcp * ident
ip filter 30018 pass * RT_LAN側IP tcp * 1723
ip filter 30019 pass * RT_LAN側IP gre * *
ip filter 30020 pass * RT_LAN側IP udp * 500
ip filter 30021 pass * RT_LAN側IP esp * *
ip filter 30099 pass * * * *
ip filter dynamic 30080 * * ftp
ip filter dynamic 30081 * * domain
ip filter dynamic 30082 * * www
ip filter dynamic 30083 * * smtp
ip filter dynamic 30084 * * pop3
ip filter dynamic 30085 * * telnet
ip filter dynamic 30098 * * tcp
ip filter dynamic 30099 * * udp
nat descriptor type 1 masquerade
nat descriptor address outer 1 グローバルIP
nat descriptor address inner 1 RT_LAN側IPクライアントの範囲
nat descriptor masquerade incoming 1 reject
nat descriptor masquerade static 1 1 RT_LAN側IP tcp 1723
nat descriptor masquerade static 1 2 RT_LAN側IP gre
nat descriptor masquerade static 1 3 RT_LAN側IP udp 500
nat descriptor masquerade static 1 4 RT_LAN側IP esp
ipsec auto refresh on
ipsec ike retry 10 5
upnp use on
変なところがあったらぜひご指摘ください。