MGRE实验练习
首先我们进行实验环境的搭建
如图所示:
首先我们分析实验四台路由器相连的线路是Serial所以需要设置路由器加入2SA来保证线路正确。
PC配置
然后我们分析实验需要给三台PC配置IP地址、网关、子网掩码
接下来我们需要给路由的每个节点配置IP地址
路由配置
R1配置:
[R1-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[R1-Serial4/0/0]ip address 12.1.1.1 24
R3配置:
[R3-GigabitEthernet0/0/0]ip address 192.168.2.1 24
[R3-Serial4/0/0]ip address 32.1.1.1 24
R4配置:
[R4-GigabitEthernet0/0/0]ip address 192.168.3.1 24
[R4-Serial4/0/0]ip address 42.1.1.1 24
R2配置:
[R2-Serial4/0/0]ip address 12.1.1.2 24
[R2-Serial4/0/1]ip address 32.1.1.2 24
[R2-Serial3/0/0]ip address 42.1.1.2 24
[R2-LoopBack0]ip address 2.2.2.2 24
配置缺省路由
因为我们需要访问到外网所以我们也需要给每个路由器配置缺省路由
配置如下:
[R1]ip route-static 0.0.0.0 0 12.1.1.2
[R3]ip route-static 0.0.0.0 0 32.1.1.2
[R4]ip route-static 0.0.0.0 0 42.1.1.2
配置NAT(网络地址转换技术)
R1配置:
[R1]acl 2000
[R1-acl-basic-2000]rule 1 permit source any
[R1-acl-basic-2000]int s4/0/0
[R1-Serial4/0/0]nat outbound 2000
R3配置:
[R3]acl 2000
[R3-acl-basic-2000]rule 1 permit source any
[R3-acl-basic-2000]int s4/0/0
[R3-Serial4/0/0]nat outbound 2000
R4配置:
[R4]acl 2000
[R4-acl-basic-2000]rule 1 permit source any
[R4-acl-basic-2000]int s4/0/0
[R4-Serial4/0/0]nat outbound 2000
现在基础的配置已经完成我们回到题目,需要给R1R2进行dhlc封装
DHLC封装
R1:
[R1]int s4/0/0
[R1-Serial4/0/0]link-protocol hdlc
R2:
[R2]int s4/0/0
[R2-Serial4/0/0]link-protocol hdlc
配置ppp封装的PAP认证
由题可知我们需要进行pap认证
R2为主认证方:
[R2-aaa]local-user huawei password cipher huawei
[R2-aaa]local-user huawei service-type ppp
[R2-aaa]int s4/0/0
[R2-Serial4/0/0]link-protocol ppp
[R2-Serial4/0/0]ppp authentication-mode pap
被认证方:R1
[R1]int s4/0/0
[R1-Serial4/0/0]link-protocol ppp
[R1-Serial4/0/0]ppp pap local-user huawei password cipher huawei
配置ppp封装的chap认证
R2为主认证方:
[R2-aaa]local-user huawei service-type ppp
[R2-aaa]int s3/0/0
[R2-Serial3/0/0]ppp authentication-mode chap
R4被认证方:
[R4]int s4/0/0
[R4-Serial4/0/0]ppp chap user huawei
[R4-Serial4/0/0]ppp chap password cipher huawei
下来我们需要配置命令5.R1,R2,R3构建MGRE环境,仅R1IP地址固定,由题意可知R1为中心站点。
MGRE环境配置
R1中心站点配置:
[R1]int t0/0/0
[R1-Tunnel0/0/0]ip address 10.1.1.1 24
[R1-Tunnel0/0/0]tunnel-protocol gre p2mp
[R1-Tunnel0/0/0]source 12.1.1.1
[R1-Tunnel0/0/0]nhrp network-id 100
R3配置:
[R3]int t0/0/0
[R3-Tunnel0/0/0]ip address 10.1.1.2 24
[R3-Tunnel0/0/0]tunnel-protocol gre p2mp
[R3-Tunnel0/0/0]source s4/0/0
[R3-Tunnel0/0/0]nhrp network-id 100
[R3-Tunnel0/0/0]nhrp entry 10.1.1.1 12.1.1.1 register
R4配置:
[R4]int t0/0/0
[R4-Tunnel0/0/0]ip address 10.1.1.4 24
[R4-Tunnel0/0/0]tunnel-protocol gre p2mp
[R4-Tunnel0/0/0]source s4/0/0
[R4-Tunnel0/0/0]nhrp network-id 100
[R4-Tunnel0/0/0]nhrp entry 10.1.1.1 12.1.1.1 register
注意:MGRE环境下RIP需要开启伪广播和关闭水平分割
[R1]int t0/0/0
[R1-Tunnel0/0/0]undo rip split-horizon关闭水平分割
[R1-Tunnel0/0/0]nhrp entry multicast dynamic 开启伪广播
R1配置:
[R1]rip 1
[R1-rip-1]version 2
[R1-rip-1]network 192.168.1.0
[R1-rip-1]network 10.0.0.0
R3配置:
[R3]rip 1
[R3-rip-1]version 2
[R3-rip-1]network 192.168.2.0
[R3-rip-1]network 10.0.0.0
R4配置:
[R4]rip 1
[R4-rip-1]version 2
[R4-rip-1]network 192.168.3.0
[R4-rip-1]network 10.0.0.0
测试