一、实验拓扑图
二、实验
1.网段划分如下
AR1的Serial3/0/0接口:192.168.1.1/24;
AR2的Serial3/0/0接口:192.168.1.2/24;
AR2的Serial3/0/1和4/0/0的聚合接口:192.168.2.2/24;
AR3的Serial3/0/0和3/0/1的聚合接口:192.168.2.3/24。
2.配置接口IP并MP聚合R2和R3间的链路
对R1:
[R1]int s3/0/0
[R1-Serial3/0/0]ip address 192.168.1.1 24
对R2:
[R2]int s 3/0/0
[R2-Serial3/0/0]ip address 192.168.1.2 24
[R2]inter Mp-group 0/0/0
[R2-Mp-group0/0/0]ip ad 192.168.2.2 24
[R2-Mp-group0/0/0]q
[R2]inter ser3/0/1
[R2-Serial3/0/1]ppp mp Mp-group 0/0/0
[R2-Serial3/0/1]inter s4/0/0
[R2-Serial4/0/0]ppp mp Mp-group 0/0/0
对R3:
[R3]inter Mp-group 0/0/0
[R3-Mp-group0/0/0]ip address 192.168.2.3 24
[R3]inter s3/0/0
[R3-Serial3/0/0]ppp mp Mp-group 0/0/0
[R3-Serial3/0/0]inter s3/0/1
[R3-Serial3/0/1]ppp mp Mp-group 0/0/0
3.单向chap验证
(1).R2做主验证方,R1做被验证方
对R2:
[R2]aaa
[R2-aaa]local-user dumj password cipher 123456
[R2-aaa]local-user dumj service-type ppp
[R2]inter s3/0/0
[R2-Serial3/0/0]ppp authentication-mode chap
对R1:
[R1]int s3/0/0
[R1-Serial3/0/0]ppp chap user dumj
[R1-Serial3/0/0]ppp chap password cipher 123456
验证
4.双向chap
(1)R2做主验证方,R3做被验证方
对R2:
[R2]aaa
[R2-aaa]local-user dumj password cipher 123456
[R2-aaa]local-user dumj service-type ppp
[R2]inter s3/0/1
[R2-Serial3/0/1]ppp authentication-mode chap
[R2-Serial3/0/1]int s4/0/0
[R2-Serial4/0/0]ppp authentication-mode chap
对R3:
[R3]int s3/0/0
[R3-Serial3/0/0]ppp chap user dumj
[R3-Serial3/0/0]ppp chap password cipher 123456
[R3-Serial3/0/0]int s3/0/1
[R3-Serial3/0/1]ppp chap user dumj
[R3-Serial3/0/1]ppp chap password cipher 123456
(2)R3做主验证方,R2做被验证方
对R3:
[R3]aaa
[R3-aaa]local-user dumj password cipher 123456
[R3-aaa]local-user dumj service-type ppp
[R3]int s3/0/0
[R3-Serial3/0/0]ppp authentication-mode chap
[R3-Serial3/0/0]int s3/0/1
[R3-Serial3/0/1]ppp authentication-mode chap
对R2:
[R2]int s3/0/1
[R2-Serial3/0/1]ppp chap user dumj
[R2-Serial3/0/1]ppp chap password cipher 123456
[R2-Serial3/0/1]inter s4/0/0
[R2-Serial4/0/0]ppp chap user dumj
[R2-Serial4/0/0]ppp chap password cipher 123456