一、实验拓扑
二、实验要求:
1.R1和R2使用PPP链路直连,R2和R3把2条PPP链路捆绑为PPP MP直连
2.按照图示配置IP地址
3.R2对R1的PPP进行单向chap验证
4.R2和R3的PPP进行双向chap验证
三、实验思路
1.设备命好名后,先配置好IP
2.R2对R1进行ppp单向chap验证:
R2为主,R1为被
3.配置R2与R3之间的ppp MP
R2和R3进行ppp双向chap验证:
R2,R3都要配置主被
四、实验步骤
(1)R2对R1进行ppp单向chap验证:
R2配置:
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]sy R2
[R2]int s 3/0/0
[R2-Serial3/0/0]ip address 192.168.1.2 24
[R2]aaa
[R2-aaa]local-user mashaoye password cipher msy12345
Info: Add a new user.
[R2-aaa]local-user mashaoye service-type ppp
[R2]int s 3/0/0
[R2-Serial3/0/0]ppp authentication-mode chap
[R2-Serial3/0/0]link-protocol ppp
R1配置:
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]sy R1
[R1]int s 3/0/0
[R1-Serial3/0/0]ip ad 192.168.1.1 24
[R1-Serial3/0/0]
[R1-Serial3/0/0]ppp c
[R1-Serial3/0/0]ppp chap u
[R1-Serial3/0/0]ppp chap user mashaoye ?
<cr> Please press ENTER to execute command
[R1-Serial3/0/0]ppp chap user mashaoye
[R1-Serial3/0/0]ppp c
[R1-Serial3/0/0]ppp chap p
[R1-Serial3/0/0]ppp chap password msy12345
^
Error: Unrecognized command found at '^' position.
[R1-Serial3/0/0]ppp chap password c
[R1-Serial3/0/0]ppp chap password cipher msy12345
[R1-Serial3/0/0]
验证阶段:
R1pingR2:
(2)
1.ppp mp配置:
R2配置:
[R2]int Mp-group 0/0/0
[R2-Mp-group0/0/0]ip address 192.168.2.1 24
[R2-Mp-group0/0/0]int s 3/0/1
[R2-Serial3/0/1]ppp mp Mp-group 0/0/0
[R2-Serial3/0/1]int s 4/0/0
[R2-Serial4/0/0]ppp mp Mp-group 0/0/0
R3配置:
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]sy R3
[R3]int Mp-group 0/0/0
[R3-Mp-group0/0/0]int s 3/0/0
[R3-Serial3/0/0]ppp mp Mp-group 0/0/0
[R3-Serial3/0/0]int s 3/0/1
[R3-Serial3/0/1]ppp mp Mp-group 0/0/0
2.R2和R3进行ppp双向chap验证:
(1)R2为主,R3为被
R2配置:
[R2]aaa
[R2-aaa]local-user mashaoye password cipher msy12345
[R2-aaa]local-user mashaoye service-type ppp
[R2-aaa]int s 3/0/1
[R2-Serial3/0/1]ppp authentication-mode chap
[R2-Serial3/0/1]link-protocol ppp
[R2-Serial3/0/1]int s 4/0/0
[R2-Serial4/0/0]ppp authentication-mode chap
[R2-Serial4/0/0]link-protocol ppp
R3配置:
#先配IP地址
[R3-Serial3/0/0]int mp-group 0/0/0
[R3-Mp-group0/0/0]ip ad
[R3-Mp-group0/0/0]ip address 192.168.2.2 24
[R3-Mp-group0/0/0]int s 3/0/0
[R3-Serial3/0/0]ppp mp Mp-group 0/0/0
[R3-Serial3/0/0]int s 3/0/1
[R3-Serial3/0/1]ppp mp Mp-group 0/0/0
#R3作被验证方
[R3]int s 3/0/0
[R3-Serial3/0/0]ppp chap user mashaoye
[R3-Serial3/0/0]ppp chap password cipher msy12345
(1)R3为主,R2为被
R3配置:
[R3]aaa
[R3-aaa]local-user madaye password cipher mdy12345
Info: Add a new user.
[R3-aaa]local-user madaye service-type ppp
[R3-aaa]int s 3/0/0
[R3-Serial3/0/0]ppp authentication-mode chap
[R3-Serial3/0/0]link-protocol ppp
[R3-Serial3/0/0]int s 3/0/1
[R3-Serial3/0/1]ppp authentication-mode chap
[R3-Serial3/0/1]link-protocol ppp
R2配置:
[R2]interface se 3/0/1
[R2-Serial3/0/1]ppp chap user madaye
[R2-Serial3/0/1]ppp chap password cipher mdy12345
[R2-Serial3/0/1]int s 4/0/0
[R2-Serial4/0/0]ppp chap user madaye
[R2-Serial4/0/0]ppp chap password cipher mdy12345
因为之前已经协商好,所以,必须重启一下接口,即shutdown一下接口,再undo shutdown
验证:
R2pingR3: