实验要求
1.R5只进行IP地址配置,其所有地址均配为公有IP地址;
2.R1和R5间使用PPP的PAP认证,R5为主认证方;
3.R2与R5之间使用ppp的CHAP认证,R5为主认证方;
4.R3与R5之间使用HDLC封装;
5.R1、R2、R3构建一个MGRE环境,R1为中心站点,R1、R4间为点到点的GRE;
6.整个私有网络基本RIP全网可达,所有Pc设置私有IP为源IP,可以访问R5环回。
思路
1.配置IP。
2.为各AP之间使用ppp验证。
3.用HDLC协议封装AR3与AR5。
4.配置AR1、2、3、4的封装环境。
5.配置RIP。
6.配置ACL。
7.检查。
实验步骤
一
AR1
[banana]int g0/0/0
[banana-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[banana-GigabitEthernet0/0/0]int s4/0/0
[banana-Serial4/0/0]ip add 15.1.1.1 24
AR2
[apple]int g0/0/0
[apple-GigabitEthernet0/0/0]ip add 192.168.2.254 24
[apple-GigabitEthernet0/0/0]int s4/0/0
[apple-Serial4/0/0]ip add 25.1.1.2 24
AR3
[pear]int g0/0/0
[pear-GigabitEthernet0/0/0]ip add 192.168.3.254 24
[pear-GigabitEthernet0/0/0]int s4/0/0
[pear-Serial4/0/0]ip add 35.1.1.3 24
AR4
[watermelon]int g0/0/0
[watermelon-GigabitEthernet0/0/0]ip add 45.1.1.4 24
[watermelon-GigabitEthernet0/0/0]int g0/0/1
[watermelon-GigabitEthernet0/0/1]ip add 192.168.4.254 24
AR5
[peach]int s4/0/1
[peach-Serial4/0/1]ip add 15.1.1.5 24
[peach-Serial4/0/1]int s3/0/1
[peach-Serial3/0/1]ip add 25.1.1.5 24
[peach-Serial3/0/1]int s4/0/0
[peach-Serial4/0/0]ip add 35.1.1.5 24
[peach-Serial4/0/0]int g0/0/0
[peach-GigabitEthernet0/0/0]ip add 45.1.1.5 24
[peach-GigabitEthernet0/0/0]int l0
[peach-LoopBack0]ip add 5.5.5.5 24
二
AR1、5之间
AR5
[peach]aaa
[peach-aaa]local-user test password cipher 123
[peach-aaa]local-user test service-type ppp
[peach-aaa]quit
[peach]int s4/0/1
[peach-Serial4/0/1]ppp authentication-mode pap
AR1
[banana]int s4/0/0
[banana-Serial4/0/0]ppp pap local-user test password cipher 123
AR2、5之间
AR5
[peach]int s3/0/1
peach-Serial3/0/1]ppp authentication-mode chap
AR2
[apple]int s4/0/0
[apple-Serial4/0/0]ppp chap password cipher 123
三
AR5
[peach]int s4/0/0
[peach-Serial4/0/0]link-protocol hdlc
AR3
[pear]int s4/0/0
[pear-Serial4/0/0]link-protocol hdlc
四
AR1
[banana]ip route-static 0.0.0.0 0 15.1.1.5
[banana]int tunnel 0/0/0
[banana-Tunnel0/0/0]ip add 10.1.1.1 24
[banana-Tunnel0/0/0]tunnel-protocol gre p2mp
banana-Tunnel0/0/0]source 15.1.1.1
[banana-Tunnel0/0/0]nhrp network-id 100
[banana-Tunnel0/0/0]int Tunnel 0/0/1
[banana-Tunnel0/0/1]ip add 10.1.2.1 24
[banana-Tunnel0/0/1]tunnel-protocol gre
[banana-Tunnel0/0/1]source 15.1.1.1
[banana-Tunnel0/0/1]destination 45.1.1.4
AR2
[apple]ip route-static 0.0.0.0 0 25.1.1.5
[apple]int Tunnel 0/0/0
[apple-Tunnel0/0/0]ip add 10.1.1.2 24
[apple-Tunnel0/0/0]tunnel-protocol gre p2mp
[apple-Tunnel0/0/0]source Serial 4/0/0
[apple-Tunnel0/0/0]nhrp network-id 100
[apple-Tunnel0/0/0]nhrp entry 10.1.1.1 15.1.1.1 register
AR3
[pear]ip route-static 0.0.0.0 0 35.1.1.5
[pear]int Tunnel 0/0/0
[pear-Tunnel0/0/0]ip add 10.1.1.3 24
[pear-Tunnel0/0/0]tunnel-protocol gre p2mp
[pear-Tunnel0/0/0]source Serial 4/0/0
[pear-Tunnel0/0/0]nhrp network-id 100
[pear-Tunnel0/0/0]nhrp entry 10.1.1.1 15.1.1.1 register
AR4
[watermelon]ip route-static 0.0.0.0 0 45.1.1.5
[watermelon]int Tunnel 0/0/1
[watermelon-Tunnel0/0/1]ip add 10.1.2.4 24
[watermelon-Tunnel0/0/1]tunnel-protocol gre
[watermelon-Tunnel0/0/1]source 45.1.1.4
[watermelon-Tunnel0/0/1]destination 15.1.1.1
五
AR1
[banana]rip 1
[banana-rip-1]v 2
[banana-rip-1]undo summary
[banana-rip-1]net 192.168.1.0
[banana-rip-1]net 10.0.0.0
[banana-rip-1]int tunnel 0/0/0
[banana-Tunnel0/0/0]nhrp entry multicast dynamic
[banana-Tunnel0/0/0]undo rip split-horizon
AR2
[apple]rip 1
[apple-rip-1]v 2
[apple-rip-1]undo summary
[apple-rip-1]net 192.168.2.0
[apple-rip-1]net 10.0.0.0
[apple-rip-1]int tunnel 0/0/0
[apple-Tunnel0/0/0]undo rip split-horizon
AR3
[pear]rip 1
[pear-rip-1]v 2
[pear-rip-1]undo summary
[pear-rip-1]net 192.168.3.0
[pear-rip-1]net 10.0.0.0
[pear-rip-1]int tunnel 0/0/0
[pear-Tunnel0/0/0]undo rip split-horizon
AR4
[watermelon]rip 1
[watermelon-rip-1]v 2
[watermelon-rip-1]undo summary
[watermelon-rip-1]net 192.168.4.0
[watermelon-rip-1]net 10.0.0.0
[watermelon-rip-1]int tunnel 0/0/0
[watermelon-Tunnel0/0/0]undo rip split-horizon
六
AR1
[banana]acl 2000
[banana-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[banana-acl-basic-2000]int s4/0/0
[banana-Serial4/0/0]nat outbound 2000
AR2
[apple]acl 2000
[apple-acl-basic-2000]rule permit source 192.168.2.0 0.0.0.255
[apple-acl-basic-2000]int s4/0/0
[apple-Serial4/0/0]nat outbound 2000
AR3
[pear]acl 2000
[pear-acl-basic-2000]rule permit source 192.168.3.0 0.0.0.255
[pear-acl-basic-2000]int s4/0/0
[pear-Serial4/0/0]nat outbound 2000
AR4
[watermelon]acl 2000
[watermelon-acl-basic-2000]rule
[watermelon-acl-basic-2000]rule permit source 192.168.4.0 0.0.0.255
[watermelon-acl-basic-2000]int g0/0/0
[watermelon-GigabitEthernet0/0/0]nat outbound 2000
最后互相ping通便为实验成功