1.R2为ISP,其上只能配置IP地址
2.R1-R2之间为HDLC封装,pap认证,R2为主认证方
3.R2-R3之间为ppp封装
4.R2-R4之间为PPp封装,chap认证,R2为主认证方
5.R1、R2、R3构建MGRE环境,仅R1P地址固定
6.内网使用RTP获取路中,所有pc可以五相访问,并日可访问B2的环回。
操作思路:
1.配置PC和路由器IP
2.配置RIP,缺省,做到公网内的互通
3.R1和R2上的S4/0/0都默认封装模式为PPP,都要修改为HDLC
4.在R2,R3,R4上设置pap和chap
5.在R1/R2/R3/R4之间构建MGRE,其中R1为中心站点,R3R4为分支站点。由于仅R1 IP地址固定,所以构建MGRE时,源写为接口模式,不直接写IP。
6.在R1上关闭RIP的水平分割,使PC2能够ping通PC3
7.在R1,R3,R4上做NAT,使PC1,2,3可以访问R2的环回。
具体配置如下:
R1
[Huawei]int g 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[Huawei]int s 4/0/0
[Huawei-Serial4/0/0]ip address 1.1.1.1 24
[Huawei-Serial4/0/0]link-protocol hdlc
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]
:y
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip address 192.168.4.1 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source 1.1.1.1
[Huawei-Tunnel0/0/0]nhrp entry multicast dynamic
[Huawei-Tunnel0/0/0]nhrp network-id 100
[Huawei-Tunnel0/0/0]q
[Huawei]rip 1
[Huawei-rip-1]v 2
[Huawei-rip-1]net
[Huawei-rip-1]network 192.168.1.0
[Huawei-rip-1]network 192.168.4.0
[Huawei-rip-1]default-route originate
[Huawei-rip-1]q
[Huawei]ip route-static 0.0.0.0 0.0.0.0 1.1.1.2
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]undo rip split-horizon
[Huawei-Tunnel0/0/0]q
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule per
[Huawei-acl-basic-2000]rule permit so
[Huawei-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[Huawei-acl-basic-2000]q
[Huawei]int s 4/0/0
[Huawei-Serial4/0/0]nat out
[Huawei-Serial4/0/0]nat outbound 2000
R2
[Huawei]int LoopBack 0
[Huawei-LoopBack0]ip address 8.8.8.8 24
[Huawei]int s 4/0/0
[Huawei-Serial4/0/0]ip address 1.1.1.2 24
[Huawei-Serial4/0/0]int s 3/0/0
[Huawei-Serial3/0/0]ip address 2.2.2.2 24
[Huawei-Serial3/0/0]int s 3/0/1
[Huawei-Serial3/0/1]ip address 3.3.3.2 24
[Huawei]aaa
[Huawei-aaa]local-user r4pap password cipher 123
[Huawei-aaa]local-user r4pap service-type ppp
[Huawei-aaa]int s 3/0/0
[Huawei-Serial3/0/0]ppp authentication-mode pap
[Huawei-Serial3/0/0]q
[Huawei]aaa
[Huawei-aaa]local-user r4chap password cipher 123
[Huawei-aaa]local-user r4chap service-type ppp
[Huawei-aaa]int s 3/0/1
[Huawei-Serial3/0/1]ppp authentication-mode chap
[Huawei-Serial3/0/1]q
[Huawei]int s 4/0/0
[Huawei-Serial4/0/0]lin
[Huawei-Serial4/0/0]link-protocol hdlc
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]
:y
R3
[Huawei]int g 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.2.1 24
[Huawei]int s 4/0/0
[Huawei-Serial4/0/0]ip address 2.2.2.1 24
[Huawei-Serial4/0/0]ppp pap local-user r4pap password cipher 123
[Huawei-Serial4/0/0]q
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip address 192.168.4.2 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source Serial 4/0/0
[Huawei-Tunnel0/0/0]nhrp entry 192.168.4.1 1.1.1.1 register
[Huawei-Tunnel0/0/0]nhrp network-id 100
[Huawei-Tunnel0/0/0]q
[Huawei]rip
[Huawei-rip-1]v 2
[Huawei-rip-1]network 192.168.2.0
[Huawei-rip-1]network 192.168.4.0
[Huawei-rip-1]default-route originate
[Huawei-rip-1]q
[Huawei]ip route-static 0.0.0.0 0.0.0.0 2.2.2.2
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 192.168.2.0 0.0.0.255
[Huawei-acl-basic-2000]q
[Huawei]int s 4/0/0
[Huawei-Serial4/0/0]nat outbound 2000
R4
[Huawei]int g 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.3.1 24
[Huawei]int s4/0/0
[Huawei-Serial4/0/0]ip address 3.3.3.1 24
[Huawei-Serial4/0/0]ppp chap password cipher 123
[Huawei]int t 0/0/0
[Huawei-Tunnel0/0/0]ip address 192.168.4.3 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source Serial 4/0/0
[Huawei-Tunnel0/0/0]nhrp entry 192.168.4.1 1.1.1.1 register
[Huawei-Tunnel0/0/0]nhrp network-id 100
[Huawei-Tunnel0/0/0]q
[Huawei]rip
[Huawei-rip-1]v 2
[Huawei-rip-1]network 192.168.3.0
[Huawei-rip-1]network 192.168.4.0
[Huawei-rip-1]default-route originate
[Huawei-rip-1]q
[Huawei]ip route-static 0.0.0.0 0.0.0.0 3.3.3.2
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 192.168.3.0 0.0.0.255
[Huawei-acl-basic-2000]q
[Huawei]int s4/0/0
[Huawei-Serial4/0/0]nat outbound 2000
结果如下: