在实际工作中一般很少用PPPOE来拨号,企业的网络都会采用静态的IP地址,因为企业都会有自己的门户网站、OA、邮箱,都会去申请静态的IP地址,出口都会安装防火墙,下面主要讲一下PPPOE具体的配置思路
1.首先配置基础配置 用户名和密码 以及远程管理和本地管理权限,方便以后远程调试设备。
2.配置虚拟接口的PPPOE 拨号
3.配置NAT所需的ACL
4.在虚拟接口下面启用NAT调用ACL
5.把虚拟接口应用到物理接口
6.最后来一条默认路由指向出口
7.内网采用DHCP分配IP地址
下面是我配置完成之后的dis cur 的内容。
[H3C]display current-configuration
#
version 5.20, Release 2105P26, Basic
#
sysname H3C
#
clock timezone #Web#8#01 add 08:00:00
#
configure-user count 5
#
domain default enable system
#
telnet server enable
#
acl number 2000
rule 0 permit source 192.168.1.0 0.0.0.255
#
vlan 1
#
radius scheme system
server-type extended
primary authentication 127.0.0.1 1645
primary accounting 127.0.0.1 1646
user-name-format without-domain
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
dhcp server ip-pool 0
network 192.168.1.0 mask 255.255.255.0
gateway-list 192.168.1.1
dns-list 192.168.1.253 202.101.172.35
#
dhcp server ip-pool 1
#
user-group system
#
local-user h3c-2011 password simple h3c-2011
authorization-attribute level 3
service-type telnet terminal
service-type web
#
interface Aux0
async mode flow
link-protocol ppp
#
interface Cellular0/0
async mode protocol
link-protocol ppp
#
interface Dialer0
nat outbound 2000
link-protocol ppp
ppp chap user hzhza03402240
ppp chap password simple 123456
ppp pap local-user hzhza03403240 password simple 123456
ip address ppp-negotiate
tcp mss 1024
dialer user hzhza03403240
dialer-group 1
dialer bundle 1
#
interface Ethernet0/0
port link-mode route
pppoe-client dial-bundle-number 1
#
interface Ethernet0/1
port link-mode route
ip address 192.168.1.1 255.255.255.0
#
interface NULL0
#
ip route-static 0.0.0.0 0.0.0.0 Dialer0
#
dhcp server forbidden-ip 192.168.1.2 192.168.1.149
dhcp server forbidden-ip 192.168.1.211 192.168.1.254
#
dhcp enable
#
load xml-configuration
#
user-interface con 0
authentication-mode scheme
user-interface tty 13
user-interface aux 0
user-interface vty 0 4
authentication-mode scheme
#
return
转载于:https://blog.51cto.com/liuxianlin/561755