目录
需求:
1.R2为ISP,其上只能配置IP地址
2. R1- R2之间为HDLC封装
3. R2- R3之间为ppp封装,pap认证,R2为主认证方
4.R2-R4之间为PPP封装,chap认证,R2为主认证方
5.R1、R2、R3构建MGRE环境,仅R1IP地址固定
6.内网使用RIP获取路由,所有PC可以互相访问,并且可访问R2的环回。
分析:
1.需要先配置好R1、R2、R3、R4的IP地址
2.需要分清Serial口和Tunnel口地址
3.仅R1IP地址固定,则将R1设为主
4.需要访问R2的环回,则需要设置NAT
拓扑
拓扑图如下:
配置
路由配置
R1
[r1]ip route-static 0.0.0.0 0 12.1.1.2
R2
[r2]ip route-static 0.0.0.0 0 23.1.1.2
R3
[r3]ip route-static 0.0.0.0 0 34.1.1.2
IP配置
R1
[r1]int s4/0/0
[r1-Serial4/0/0]ip add 12.1.1.1 24
[r1]int g0/0/2
[r1-GigabitEthernet0/0/2]ip add 192.168.1.1 24
R2
[ISPint s4/0/0
ISP-Serial4/0/0]ip add 12.1.1.2 24
[ISP]int s4/0/1
[ISP-Serial4/0/1]ip add 23.1.1.2 24
[ISP]int s3/0/0
[ISP-Serial3/0/0]ip add 34.1.1.2 24
R3
[r3]int s4/0/1
[r3-Serial4/0/1]ip add 23.1.1.1 24
[r3]int g0/0/0
[r3-GigabitEthernet0/0/0]ip add 192.168.2.1 24
R4
[r4]int s4/0/0
[r4-Serial4/0/0]ip add 34.1.1.1 24
[r4]int g0/0/0
[r4-GigabitEthernet0/0/0]ip add 192.168.3.1 24
HDLC配置
R1
[r1]int s4/0/0
[r1-Serial4/0/0]link-protocol hdlc
R2
[ISP]int s4/0/0
[ISP-Serial4/0/0]link-protocol hdlc
PaP配置
R2
[ISP]aaa
[ISP-aaa]local-user zz privilege level 15 password cipher 123
[ISP-aaa]local-user zz service-type ppp
[ISP-aaa]int s4/0/1
[ISP-Serial4/0/1]ppp authentication-mode pap
R3
[r3]int s4/0/1
[r3-Serial4/0/1]ppp pap local-user zz password cipher 123
chap配置
R2
[ISP]aaa
[ISP-aaa]local-user z privilege level 15 password cipher 123
[ISP-aaa]local-user z service-type chap
[ISP-aaa]int s3/0/0
[ISP-Serial3/0/0]ppp authentication-mode chap
R4
[r4]int s4/0/0
[r4-Serial4/0/0]ppp chap user z[r4-Serial4/0/0]ppp chap password cipher 123
NHRP配置
R1
[r1]int Tunnel 0/0/0
[r1-Tunnel0/0/0]ip add 10.1.1.1 24
[r1-Tunnel0/0/0]tunnel-protocol gre p2mp
[r1-Tunnel0/0/0]nhrp network-id 100
[r1-Tunnel0/0/0]nhrp entry multicast dynamic
[r1-Tunnel0/0/0]source 12.1.1.1
R3
[r3]int Tunnel 0/0/0
[r3-Tunnel0/0/0]ip add 10.1.1.3 24
[r3-Tunnel0/0/0]tunnel-protocol gre p2mp
[r3-Tunnel0/0/0]source s4/0/1
[r3-Tunnel0/0/0]nhrp entry 10.1.1.1 12.1.1.1 register
[r3-Tunnel0/0/0]nhrp network-id 100
R4
[r4]int Tunnel 0/0/0
[r4-Tunnel0/0/0]ip add 10.1.1.4 24
[r4-Tunnel0/0/0]tunnel-protocol gre p2mp
[r4-Tunnel0/0/0]source s4/0/0
[r4-Tunnel0/0/0]nhrp entry 10.1.1.1 12.1.1.1 register
[r4-Tunnel0/0/0]nhrp network-id 100
RIP配置
R1
[r1]rip
[r1-rip-1]ver 2[r1-rip-1]network 10.0.0.0
[r1-rip-1]network 192.168.1.0
R3
[r3]rip
[r3-rip-1]ver 2[r3-rip-1]network 10.0.0.0
[r3-rip-1]network 192.168.2.0
R4
[r4]rip
[r4-rip-1]ver 2[r4-rip-1]network 10.0.0.0
[r4-rip-1]network 192.168.3.0
验证:
1.全网可达
2.邻居表如下