说明:由于没有ip资源,只好用2M线传输数据,所用的设备是M262路由器,上联设备是华为的NE16,M262上各有一个4E1模块,华为的路由器上有一个8E1模块,中间通过传输连接。组网图如下:
图片点击可在新窗口打开查看


注意:如果是两台路由器直接通过e1连接,也就是背靠背连接,需要一方工作在DTE模式,一方工作在DCE模式,如果是经过传输,不需要设置双方的工作模式,默认都是工作在DTE模式。
调试中遇到的问题:路由器的Serial口的物理链路是up了,但是协议没有up。
登陆到华为的路由器上,发现上面的所有的口的协议都up了,很奇怪,查看配置没有问题,把我们的一个2m拔掉,华为相应的口也down了,说明我们两方设备互连起来了。后来传输把2m线重新检查后,我们这边的口的协议层也up了。
Virtual-Template的物理链路和协议提示起来了,但是当你通过命令显示是down的。
router# show interface virtual-template 0
  Interface virtual-template0 is down, Line protocol is down
  Internet address is 61.233.145.54/30 Point-To-Point 0.0.0.0
  mtu 1500 <POINTOPOINT,NOARP,MULTICAST>
Encapsulation PPP显示的时候是down的。
NE16的需模板口显示如下:
SD_TA-NE16A#sh inter Virtual-Template 2
Virtual-Template2 is up  line protocol is up (spoofing)
Description : HUAWEI, Quidway Series, Virtual-Template2 Interface
MTU is 1500(bytes)
Internet Address is 61.233.145.53/30
Encapsulation is PPP
LCP initial
  Queueing strategy: FIFO
  Output queue: (size/max/drops) 0/75/0
Slot 2 Virtual-Template2:0
  Queueing strategy: FIFO
  Output queue: (size/max/drops) 50/75/75183
NE16的配置
 hostname SD_TA-NE16A
 enable password level 15 7 NUaPUFS<;Y)(`_\_0/*Z(Q!!
 user tacrc service-type exec password 7 $TYJ2T!W-5_:C:"-501K]!!!
 user taian_crc service-type exec password 7 $TYJ2T!W-5_:C:"-501K]!!!
 user xintai service-type ppp password 0 xintai
 user taiancrc service-type ppp password 0 taiancrc
 user xinwen service-type ppp password 0 xinwen
 router id 61.233.144.2
 access-list 1 permit 10.0.0.0 0.255.255.255
 access-list 1 permit 168.10.0.0 0.0.255.255
 access-list 1 deny any
 access-list 2 deny 10.0.0.0 0.255.255.255
 access-list 2 deny 168.10.0.0 0.0.255.255
 access-list 2 permit any
 access-list 101 deny icmp any any
 access-list 101 deny tcp any any eq 69
 access-list 101 deny tcp any any eq 135
 access-list 101 deny tcp any any eq 139
 access-list 101 deny tcp any any eq 445
 access-list 101 deny udp any any eq tftp
 access-list 101 permit ip any any
 access-list 101 deny tcp any any eq 4444
 firewall enable slot 0
 firewall enable slot 1
 firewall enable slot 2
 firewall enable slot 7
 enable vlan mode L3
 multilink-user xintai bind Virtual-Template 1
 multilink-user taiancrc bind Virtual-Template 3
 multilink-user xinwen bind Virtual-Template 2
controller E1 2/1/0
 using e1
controller E1 2/1/1
 using e1
controller E1 2/1/2
 using e1
controller E1 2/1/3
 using e1
controller E1 2/1/4
 using e1
controller E1 2/1/5
 using e1
controller E1 2/1/6
 using e1
controller E1 2/1/7
 using e1
interface Ethernet0/2/0
 speed 100
 duplex full
 description to-ZhongXinJu-MA5100,100M FE
 ip access-group 101 in
 ip access-group 101 out
interface Ethernet0/2/0.10
 ip address 10.0.2.254 255.255.254.0
 ip access-group 101 in
 ip access-group 101 out
 encap dot1q 10
interface Ethernet0/2/0.20
 ip address 61.233.145.5 255.255.255.252
 ip access-group 101 in
 ip access-group 101 out
 encap dot1q 20
interface Ethernet1/0/0
 description To-LeYuan-MA5100,100M FE
interface Ethernet1/0/0.10
 ip address 61.233.145.1 255.255.255.252
 ip access-group 101 in
 ip access-group 101 out
 encap dot1q 10
interface Ethernet1/0/0.30
 ip address 10.0.0.254 255.255.254.0
 ip access-group 101 in
 ip access-group 101 out
 encap dot1q 30
interface Ethernet1/1/0
 description To-ShiSiJu-MA5100,100M FE
interface Ethernet1/1/0.10
 ip address 61.233.145.9 255.255.255.252
 encap dot1q 10
interface Ethernet1/1/0.20
 ip address 10.0.4.254 255.255.254.0
 ip access-group 101 in
 ip access-group 101 out
 encap dot1q 20
interface Ethernet1/2/0
 description to 3025m
 ip address 10.10.0.1 255.255.0.0
interface Ethernet1/2/0.2
 ip address 10.11.0.1 255.255.0.0
 ip access-group 101 in
 ip access-group 101 out
 encap dot1q 2
interface Ethernet1/2/0.3
 ip address 168.10.24.1 255.255.252.0
interface Ethernet1/2/0.4
 ip address 168.10.32.1 255.255.255.0
interface Ethernet1/2/0.5
 ip address 61.232.43.49 255.255.255.252
 encap dot1q 5
interface Ethernet1/2/0.6
 ip address 168.10.0.1 255.255.240.0
 encap dot1q 6
interface Ethernet1/2/0.7
 encap dot1q 7
interface Ethernet1/2/0.8
 encap dot1q 8
interface Ethernet1/2/0.9
 ip access-group 101 in
 ip access-group 101 out
 encap dot1q 9
interface Ethernet2/0/0
 description to zhongxinyiyan line
interface Ethernet2/2/0
 duplex full
 description to rs3000
 ip address 61.233.145.33 255.255.255.240
 ip address 61.233.145.17 255.255.255.240 secondary
 ip access-group 101 in
 ip access-group 101 out
interface Serial2/1/0:0
 encapsulation ppp
 ppp authentication pap
 ppp pap sent-username taian-crc password 0 taian-crc
 ppp multilink
interface Serial2/1/1:0
 encapsulation ppp
 ppp authentication pap
 ppp pap sent-username taian-crc password 0 taian-crc
 ppp multilink
interface Serial2/1/2:0
 encapsulation ppp
 ppp authentication pap
 ppp pap sent-username taian-crc password 0 taian-crc
 ppp multilink
interface Serial2/1/3:0
 encapsulation ppp
 ppp authentication pap
 ppp pap sent-username taian-crc password 0 taian-crc
 ppp multilink
interface Serial2/1/4:0
 encapsulation ppp
 ppp authentication pap
 ppp pap sent-username xinwen password 0 xinwen
 ppp multilink
interface Serial2/1/5:0
 encapsulation ppp
 ppp authentication pap
 ppp pap sent-username xinwen password 0 xinwen
 ppp multilink
interface Serial2/1/6:0
 encapsulation ppp
 ppp authentication pap
 ppp pap sent-username xinwen password 0 xinwen
 ppp multilink
interface Serial2/1/7:0
 encapsulation ppp
 ppp authentication pap
 ppp pap sent-username xinwen password 0 xinwen
 ppp multilink
interface Virtual-Template0
 ppp multilink
 description loopback
 ip address 61.233.144.2 255.255.255.252
 ip ospf network point-to-multipoint
interface Virtual-Template1
 ip address 10.255.254.1 255.255.255.252
interface Virtual-Template2
 ip address 61.233.145.53 255.255.255.252
interface Virtual-Template3
 multilink max-bind 8
 ip address 61.233.145.49 255.255.255.252
interface Pos0/0/0
 encapsulation ppp
 ip address 61.233.144.22 255.255.255.252
 ip access-group 101 in
 ip access-group 101 out
 nat inside list 1
 ip ospf cost 65
interface NULL0
router ospf
 network 61.233.144.2  0.0.0.0  area 0.0.0.0
 network 61.233.144.22  0.0.0.0  area 0.0.0.0
 redistribute static
 redistribute connected route-map deny
route-map deny permit 10
    match ip address 2
M262-1的配置
access-list 1 permit 192.168.0.0/16
access-list 110 permit icmp any 192.168.0.89/32
access-list 110 permit icmp 192.168.0.89/32 any
access-list 110 deny icmp any any
access-list 110 deny tcp any any eq 4444
access-list 110 deny udp any any eq 69
access-list 110 deny tcp any any eq 135
access-list 110 deny udp any any eq 135
access-list 110 deny tcp any any eq 139
access-list 110 deny udp any any eq 139
access-list 110 deny tcp any any eq 445
access-list 110 deny udp any any eq 445
access-list 110 deny tcp any any eq 593
access-list 110 deny udp any any eq 593
access-list 110 deny udp any any eq 1434
access-list 110 permit ip any any
ip inspect on
ip inspect net 1
ip inspect per-host-flows 1000
aaa-enable
aaa authentication ppp default local
username taian-crc privilege 1 password taian-crc
multilink virtual-template 0
controller e1 1/0
 using e1
controller e1 1/1
 using e1
controller e1 1/2
 using e1
controller e1 1/3
 using e1
interface eth0/0
 ip address 192.168.0.1/16
 ip nat inside
interface serial1/0:0
 ppp authentication pap default
 ppp pap sent-username taiancrc password taiancrc
 ppp multilink
interface serial1/1:0
 ppp authentication pap default
 ppp pap sent-username taiancrc password taiancrc
 ppp multilink
interface serial1/2:0
 ppp authentication pap default
 ppp pap sent-username taiancrc password taiancrc
 ppp multilink
interface serial1/3:0
 ppp authentication pap default
 ppp pap sent-username taiancrc password taiancrc
 ppp multilink
interface virtual-template0
 ip address 61.233.145.50/30
 ip nat outside
 ppp multilink
ip nat pool zhuanhuan
 address 61.233.145.50 61.233.145.50
ip route 0.0.0.0/0 61.233.145.49
ip nat on
ip nat inside source list 1 pool zhuanhuan
M262-2的配置
access-list 1 permit 192.168.0.0/16
access-list 110 deny icmp any any
access-list 110 deny tcp any any eq 4444
access-list 110 deny udp any any eq 69
access-list 110 deny tcp any any eq 135
access-list 110 deny udp any any eq 135
access-list 110 deny tcp any any eq 139
access-list 110 deny udp any any eq 139
access-list 110 deny tcp any any eq 445
access-list 110 deny udp any any eq 445
access-list 110 deny tcp any any eq 593
access-list 110 deny udp any any eq 593
access-list 110 deny udp any any eq 1434
access-list 110 permit ip any any
ip inspect on
ip inspect net 1
ip inspect per-host-flows 1000
aaa-enable
aaa authentication ppp default local
username xinwen privilege 1 password xinwen
multilink virtual-template 0
controller e1 1/0
 using e1
controller e1 1/1
 using e1
controller e1 1/2
 using e1
controller e1 1/3
 using e1
interface eth0/0
 ip address 192.168.0.1/16
 ip nat inside
interface serial1/0:0
 ppp authentication pap default
 ppp pap sent-username xinwen password xinwen
 ppp multilink
interface serial1/1:0
 ppp authentication pap default
 ppp pap sent-username xinwen password xinwen
 ppp multilink
interface serial1/2:0
 ppp authentication pap default
 ppp pap sent-username xinwen password xinwen
 ppp multilink
interface serial1/3:0
 ppp authentication pap default
 ppp pap sent-username xinwen password xinwen
 ppp multilink
interface virtual-template0
 ip address 61.233.145.54/30
 ip nat outside
 ppp multilink
ip nat pool zhuanhuan
 address 61.233.145.54 61.233.145.54
ip route 0.0.0.0/0 61.233.145.53
ip nat on
ip nat inside source list 1 pool zhuanhuan