开始
结束
实验要求
1,R5为ISP,只能进行IP地址配置;其所有地址均配为公有IP地址
2,R1和R5间使用PPP的PAP认证,R5为主认证方;
R2于R5之间使用PPP的chap认证,R5为主认证方;
R3于R5之间使用HDLC封装。
3,R1/R2/R3构建一个MGRE环境,R1为中心站点;R1、R4间为点到点的GRE。
4,整个私有网络基于RIP全网可达
5,所有Pc设置私有IP为源IP,可以访问R5环回。
ip划分
192.168.1---8.0 顺序 1,2,3。。。MGRE、gre
IP配置(R1例子)
interface Serial 4/0/0
ip add 15.0.0.1 24
int g 0/0/0
ip add 192.168.1.254 24
pap认证
【r5】 aaa local-user huawei password cipher 123456 local-user huawei service-type ppp int s 3/0/0 ppp authentication-mode pap
被认证方:
[r1-Serial4/0/0]ppp pap local-user huawei password cipher 123456
chap认证 (r5->r2)
aaa
local-user nanjing password cipher 654321
local-user nanjing service-type ppp
q
int s 3/0/1
ppp authentication-mode chap
int s 4/0/0
ppp chap user nanjing
ppp chap password cipher 654321
hdlc (r3-->r5)
int s 4/0/0
link-protocol hdlc
int s 4/0/0
link-protocol hdlc
MGRE(R1中心 r2r3分支)
interface Tunnel 0/0/0
ip add 192.168.5.1 24
tunnel-protocol gre p2mp
source 15.0.0.1
nhrp network-id 100
interface Tunnel 0/0/0
ip add 192.168.5.2 24
tunnel-protocol gre p2mp
source Serial 4/0/0
nhrp network-id 100
nhrp entry 192.168.5.1 15.0.0.1 register
int t 0/0/0
ip add 192.168.5.3 24
tunnel-protocol gre p2mp
source Serial 4/0/0
nhrp network-id 100
nhrp entry 192.168.5.1 15.0.0.1 register
GRE
int t 0/0/1
ip add 192.168.6.1 24
tunnel-protocol gre
source 15.0.0.1
destination 45.0.0.4
int t 0/0/0
ip add 192.168.6.2 24
tunnel-protocol gre
source 45.0.0.4
destination 15.0.0.1
rip
R1配置:
nhrp entry multicast dynamic
rip 1
version 2
network 192.168.1.0
network 192.168.5.0
network 192.168.6.0
R2配置:
rip 1
version 2
network 192.168.2.0
network 192.168.5.0
R3配置:
rip 1
version 2
network 192.168.3.0
network 192.168.5.0
R4配置:
rip 1
version 2
network 192.168.4.0
network 192.168.5.0
检验