实验要求:
实验拓扑:
由于R1-R4都是边界路由器,因此都需要写一条缺省路由:
ip route-static 0.0.0.0 0.0.0.0 15.0.0.2
因为R1和R5之间使用PAP认证,因此要对R5进行设置:
[r5]aaa
[r5-aaa]
[r5-aaa]local-user w1 password cipher 123456
[r5-aaa]local-user w1 service-type ppp 指定服务
进入接口
[r5-Serial0/0/0]ppp authentication-mode pap
在R1对应接口上进行设置:
[Huawei-Serial0/0/0]ppp pap local-user w1 password cipher 123456
R5对R2和R3都提供服务,所以至于要在R2和R3上对应连接的接口上进行协议设置就行
[r5-Serial0/0/1]ppp authentication-mode chap
R2进行协议协商
[Huawei-Serial0/0/0]ppp chap user w1
[Huawei-Serial0/0/0]ppp chap password cipher 123456
[r5-Serial0/0/2]link-protocol hdlc
R3进行协议协商
[Huawei-Serial0/0/0]link-protocol hdlc
R1-R3构建MGRE环境
R1:
[Huawei]interface Tunnel 0/0/0 建立链路虚拟接口
[Huawei-Tunnel0/0/0]ip add 192.168.5.1 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]shutdown
[Huawei-Tunnel0/0/0]source 15.0.0.1
[Huawei-Tunnel0/0/0]nhrp network-id 50 目标以nhrp获取
R2:
[Huawei-Tunnel0/0/0]ip add 192.168.5.2 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source serial 0/0/0
[Huawei-Tunnel0/0/0]nhrp network-id 50
[Huawei-Tunnel0/0/0]nhrp entry 192.168.5.1 15.0.0.1 nhrp注册
R3
[Huawei-Tunnel0/0/0]ip add 192.168.5.3 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source serial 0/0/0
[Huawei-Tunnel0/0/0]nhrp network-id 50
[Huawei-Tunnel0/0/0]nhrp entry 192.168.5.1 15.0.0.1
R1和R4之间是GRE环境,需要重新搭建一个虚拟线路:
[Huawei]interface Tunnel 0/0/1 建立链路虚拟接口
[Huawei-Tunnel0/0/1]ip add 192.168.6.1 24
[Huawei-Tunnel0/0/1]tunnel-protocol gre
[Huawei-Tunnel0/0/1]source 15.0.0.1
[Huawei-Tunnel0/0/1]desecription
[Huawei-Tunnel0/0/1]destination 45.0.0.1 目标
R4
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip add 192.168.6.2 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre
[Huawei-Tunnel0/0/1]source 45.0.0.1
[Huawei-Tunnel0/0/1]desecription
[Huawei-Tunnel0/0/1]destination 45.0.0.1 目标
私有网路基于RIP可达
[Huawei]rip
[Huawei-rip-1]
[Huawei-rip-1]version 2
[Huawei-rip-1]network 192.168.1.0
[Huawei-rip-1]network 192.168.5.0
[Huawei-rip-1]network 192.168.6.0
RIP的设置 其它路由器都是一样的,注意要版本号一样。
设置完每个路由器之上的RIP之后,其中只有R1可以得到完整的全部RIP路由,因此需要再R1上开启伪广播:
[Huawei-Tunnel0/0/0]nhcp entry multicast dynam
同时还要关闭RIP的水平分割:
[Huawei-Tunnel0/0/0]undo rip summary-address
[Huawei-Tunnel0/0/0]undo rip split-horizon
PC的私有IP可以访问R5的环回,也就是访问互联网,那只需要在R1-R4的边界路由器上设置NAT就行。
[Huawei]acl 2000
[Huawei-acl-basic-2000]
[Huawei-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[Huawei-Serial0/0/0]nat outbound 2000 接口上开启NAT