一、实验拓扑
二、实验需求
1、R1和R2使用PPP链路直连,R2和R3把2条PPP链路捆绑为PPP MP直连
2、按照图示配置IP地址
3、R2对R1的PPP进行单向chap验证
4、R2和R3的PPP进行双向chap验证
三、实验思路
1、把2条PPP链路捆绑为PPP MP直连,手动配置ip地址
2、实验R2对R1的单向chap验证
3、实现R2和R3的双向chap验证
四、实验步骤
1、PPP MP配置,配置ip地址
[R1-Serial3/0/0]ip address 192.168.1.1 24
[R2-Serial3/0/0]ip address 192.168.1.2 24
[R2]int Mp-group 0/0/1
[R2-Serial3/0/1]ppp mp Mp-group 0/0/1
[R2-Serial4/0/0]ppp mp Mp-group 0/0/1
[R2-Mp-group0/0/1]ip address 192.168.2.1 24
[R3]int Mp-group 0/0/1
[R3-Serial3/0/0]ppp mp Mp-group 0/0/1
[R3-Serial3/0/1]ppp mp Mp-group 0/0/1
[R3-Mp-group0/0/1]ip address 192.168.2.2 24
2、单向chap验证
[R2]aaa
[R2-aaa]local-user AAA password cipher 123456 privilege level 15
[R2-aaa]local-user AAA service-type ppp
[R2-Serial3/0/0]ppp authentication-mode chap
[R1-Serial3/0/0]ppp chap user AAA
[R1-Serial3/0/0]ppp chap password 123456
通过R1的S3/0/0接口shutdown和undo shutdown重启进行测试
验证成功
3、双向chap验证
[R2]aaa
[R2-aaa]local-user BBB password cipher 456789 privilege level 15
[R2-aaa]local-user BBB service-type ppp
[R2-Serial3/0/1]ppp authentication-mode chap
[R2-Serial4/0/0]ppp authentication-mode chap
[R3-Serial3/0/0]ppp chap user BBB
[R3-Serial3/0/0]ppp chap password cipher 456789
[R3-Serial3/0/1]ppp chap user BBB
[R3-Serial3/0/1]ppp chap password cipher 456789
[R3]aaa
[R3-aaa]local-user CCC password cipher 789123 privilege level 15
[R3-aaa]local-user CCC service-type ppp
[R3-Serial3/0/0]ppp authentication-mode chap
[R3-Serial3/0/1]ppp authentication-mode chap
[R2-Serial3/0/1]ppp chap user CCC
[R2-Serial3/0/1]ppp chap password cipher 789123
[R2-Serial4/0/0]ppp chap user CCC
[R2-Serial4/0/0]ppp chap password cipher 789123
将R2的两个接口都shutdown后,再统一启动进行测试
验证成功