要求:
1.R2为ISP其上只能配置IP地址1.R2为ISP;R1与R2间为HDLC封装
2.R1-R3间为ppp封装,pap认证,R2为主认证方
3.R2-R3Z14.R2-R4之间为PPp封装,chap认证,R2为主认证方
5.R1、R2、R3构建MGRE环境,仅R1P地址固定
6.内网使用RIP获取路由,所有Pc可以互相访问,并且可访问R2的环回
一、r1和r2之间启用HDLC接口 (r2为例)
[r2]interface s4/0/0
[r2-Serial4/0/0]link-protocol hdlc
二、r1作为主认证方,配置如下
[r1]interface Tunnel 0/0/0
[r1-Tunnel0/0/0]ip address 192.168.4.1 24
[r1-Tunnel0/0/0]tunnel-protocol gre p2mp
[r1-Tunnel0/0/0]source 12.1.1.1
Jan 1 2023 17:54:35-08:00 r1 %%01IFNET/4/LINK_STATE(l)[0]:The line protocol IP
on the interface Tunnel0/0/0 has entered the UP state.
[r1-Tunnel0/0/0]nhrp entry multicast dynamic
[r1-Tunnel0/0/0]nhrp network-id 100
r3、r4作为被认证方配置(r4同理)
[r3]interface t0/0/0
[r3-Tunnel0/0/0]ip address 192.168.4.2 24
[r3-Tunnel0/0/0]tunnel-protocol gre p2mp
[r3-Tunnel0/0/0]source s4/0/0
Jan 1 2023 18:27:29-08:00 r3 %%01IFNET/4/LINK_STATE(l)[2]:The line protocol IP
on the interface Tunnel0/0/0 has entered the UP state.
[r3-Tunnel0/0/0]nhrp entry 192.168.4.1 12.1.1.1 register[r3-Tunnel0/0/0]nhrp network-id 100
三、内网使用rip协议打通(r3、r4上类似配置)
[r1]rip 1
[r1-rip-1]version 2
[r1-rip-1]network 192.168.1.0
[r1-rip-1]network 192.168.4.0
四、明文认证
[r2]aaa
[r2-aaa]local-user bb privilege level 15 password cipher 123456
[r3]interface s4/0/0
[r3-Serial4/0/0]ppp pap local-user bb password cipher 123456
五、密文认证
[r2-aaa]local-user bb privilege level 15 password cipher 123456
[r2]int
[r2]interface s3/0/0
[r2-Serial3/0/0]ppp authentication-mode chap
[r4]interface s4/0/0
[r4-Serial4/0/0]ppp chap user bb
[r4-Serial4/0/0]ppp chap password cipher 123456
最后查看是否能通信r1pingPC2