目录
一、实验要求与拓扑搭建
实验前给R1、R2、R3右击设置中添加2SA接口;
二、实验过程
2.1 R1与R5之间进行PPP的PAP认证
[r5]aaa
[r5-aaa]local-user linxi password cipher 123456
Info: Add a new user.
[r5-aaa]local-user linxi service-type ppp
[r5-aaa]q
[r5]int s3/0/0
[r5-Serial3/0/0]ip add 15.1.1.2 24
[r5-Serial3/0/0]ppp authentication-mode pap
[r1]int s4/0/0
[r1-Serial4/0/0]ppp pap local-user linxi password cipher 123456
2.2 R2与R5之间使用PPP的CHAP认证
[r5]int s3/0/1
[r5-Serial3/0/1]ppp authentication-mode chap
[r5-Serial3/0/1]ip add 25.1.1.2 24
[r2]int s4/0/0
[r2-Serial4/0/0]ip add 25.1.1.1 24
[r2-Serial4/0/0]ppp chap user linxi
[r2-Serial4/0/0]ppp chap password cipher 123456
2.3 R3与R5之间使用HDLC封装
[r3-Serial4/0/0]link-protocol hdlc
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]
:y
[r5-Serial4/0/0]link-protocol hdlc
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]
:y
[r5-Serial4/0/0]ip add 35.1.1.2 24
2.4 实现公网可达——添加缺省路由
首先配置各个接口的IP地址:
[r1]int g0/0/2
[r1-GigabitEthernet0/0/2]ip add 192.168.1.1 24
[r2]int g0/0/2
[r2-GigabitEthernet0/0/2]ip add 192.168.2.1 24
[r3]int g0/0/2
[r3-GigabitEthernet0/0/2]ip add 192.168.3.1 24
[r4]int g0/0/0
[r4-GigabitEthernet0/0/0]ip add 45.1.1.1 24
[r4-GigabitEthernet0/0/0]int g0/0/2
[r4-GigabitEthernet0/0/2]ip add 192.168.4.1 24
[r5]int g0/0/0
[r5-GigabitEthernet0/0/0]ip add 45.1.1.2 24
[r5]int loopback 0
[r5-LoopBack0]ip add 5.5.5.5 24
添加缺省:
[r1]ip route-static 0.0.0.0 0 15.1.1.2
[r2]ip route-static 0.0.0.0 0 25.1.1.2
[r3]ip route-static 0.0.0.0 0 35.1.1.2
[r4]ip route-static 0.0.0.0 0 45.1.1.2
2.5 搭建GRE与MGRE环境
GRE环境搭建完成!
[r2]int t0/0/0
[r2-Tunnel0/0/0]ip add 10.1.2.2 24
[r2-Tunnel0/0/0]tunnel-protocol gre p2mp
[r2-Tunnel0/0/0]source s 4/0/0
[r2-Tunnel0/0/0]nhrp entry 10.1.2.1 25.1.1.2 register
[r2-Tunnel0/0/0]nhrp network-id 100
[r3]int t0/0/0
[r3-Tunnel0/0/0]ip add 10.1.2.3 24
[r3-Tunnel0/0/0]tunnel-protocol gre p2mp
[r3-Tunnel0/0/0]source s 4/0/0
[r3-Tunnel0/0/0]nhrp entry 10.1.2.1 15.1.1.1 register
[r3-Tunnel0/0/0]nhrp network-id 100
MGRE环境搭建完成!
2.6 RIP实现私有网络的全网可达
此时的私有网络如图:
[r3]rip 1
[r3-rip-1]version 2
[r3-rip-1]network 192.168.3.0
[r3-rip-1]network 10.0.0.0
[r4]rip 1
[r4-rip-1]version 2
[r4-rip-1]network 192.168.4.0
[r4-rip-1]network 10.0.0.0
关闭水平分割:
因为R2传递的信息会经过R1最终使R4也会接受到,所以必须关闭水平分割!
[r1]int t0/0/0
[r1-Tunnel0/0/0]undo rip split-horizon
2.7 Nat进行网络地址转换
[r1]acl 2000
[r1-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[r1-acl-basic-2000]q
[r1]int s4/0/0
[r1-Serial4/0/0]nat outbound 2000
R2、R3、R4操作同上,之后让每个路由器ping R5的环回,看是否能通