实验拓扑图
实验要求
1.r1和r2使用ppp链路直连,r2和r3把2条ppp链路捆绑为ppp Mp直连
2.按图所示配置ip地址
3.r2对r1的ppp进行单向chap验证
4.r2和r3的ppp进行双向chap验证
实验思路
一,在r2和r3上配置ppp Mp
(1)先在r2和r3上创建Mp - GROUP 口
r2
[r2]int Mp-group 0/0/0
[r2-Mp-group0/0/0]
r3
[r3]int Mp-group 0/0/0
[r3-Mp-group0/0/0]
(2)把r2和r3之间ppp链路的两端接口分别加入上一步创建的MP - GROUP口
r2
[r2-Mp-group0/0/0]int s3/0/1
[r2-Serial3/0/1]ppp mp
[r2-Serial3/0/1]ppp mp mp
[r2-Serial3/0/1]ppp mp Mp-group 0/0/0
[r2-Serial3/0/1]
[r2-Serial3/0/1]int s4/0/0
[r2-Serial4/0/0]ppp mp Mp-group 0/0/0
r3
[r3]int s3/0/0
[r3-Serial3/0/0]ppp mp
[r3-Serial3/0/0]ppp mp Mp
[r3-Serial3/0/0]ppp mp Mp-group 0/0/0
[r3-Serial3/0/0]
[r3-Serial3/0/0]int s3/0/1
[r3-Serial3/0/1]ppp mp Mp-group 0/0/0
二.按照拓扑图配置IP地址
(1)r1和r2的直连链路IP地址配置
r1
[r1]int s3/0/0
[r1-Serial3/0/0]ip a 192.168.1.1 24
[r1-Serial3/0/0]dis ip in br
Serial3/0/0 192.168.1.1/24 up up
r2
[r2]int s3/0/0
[r2-Serial3/0/0]ip a 192.168.1.2 24
[r2-Serial3/0/0]dis ip in br
Serial3/0/0 192.168.1.2/24 up up
(2)如果PPP链路上配置了PPP-MP,那么链路的IP就必须配置在MP-GROUP口上,而不是物理口上。所以r2和r3之间的PPP链路IP配置为给MP-GROUP口配置IP地址
r2
[r2]int mp
[r2]int Mp-group 0/0/0
[r2-Mp-group0/0/0]ip a 192.168.2.2 24
[r2-Mp-group0/0/0]dis ip in br
Mp-group0/0/0 192.168.2.2/24 up up
r3
[r3]int mp
[r3]int Mp-group 0/0/0
[r3-Mp-group0/0/0]ip a 192.168.2.3 24
[r3-Mp-group0/0/0]dis ip in br
Mp-group0/0/0 192.168.2.3/24 up up
三,实验r2对r1的PPP进行单向验证
由于是r2对r1进行单向验证,表明了r2为主验证方,r1为被动验证。所以需要在r2上创建用于验证的用户
(1)在r2上创建用户
[r2]aaa
[r2-aaa]local
[r2-aaa]local-user dameiza pa
[r2-aaa]local-user dameiza password ci
[r2-aaa]local-user dameiza password cipher 520
Info: Add a new user.
[r2-aaa]local-user dameiza ser
[r2-aaa]local-user dameiza service-type ppp
(2)在r2与r1链接的接口上配置需要进行的ppp验证,验证方式为chap
[r2-aaa]int s3/0/0
[r2-Serial3/0/0]ppp au
[r2-Serial3/0/0]ppp authentication-mode chap
(3)在r1与r2链接的接口上配置用于验证的用户名和密码
[r1]int s3/0/0
[r1-Serial3/0/0]ppp ch
[r1-Serial3/0/0]ppp chap u
[r1-Serial3/0/0]ppp chap user dameiza
[r1-Serial3/0/0]ppp cha
[r1-Serial3/0/0]ppp chap pas
[r1-Serial3/0/0]ppp chap password simple 520
(4)关闭再开启链路,检查能否通过
[r2]int s3/0/0
[r2-Serial3/0/0]shu
[r2-Serial3/0/0]shutdown
[r2-Serial3/0/0]un
[r2-Serial3/0/0]undo shu
[r2-Serial3/0/0]undo shutdown
实验成功
(5)尝试把r1的用户删除观察还可不可以通过
[r1]int s3/0/0
[r1-Serial3/0/0]un
[r1-Serial3/0/0]undo ppp char u
[r1-Serial3/0/0]undo ppp chap u
[r1-Serial3/0/0]undo ppp chap user
[r1-Serial3/0/0]shutdown
[r1-Serial3/0/0]undo shutdown
实验发现此时无法通过
再次把r1的用户添加回去
[r1-Serial3/0/0]ppp chap user dameiza
[r1-Serial3/0/0]shutdown
[r1-Serial3/0/0]undo shutdown
发现又可以了
实验结束
四,r2和r3的ppp进行双向验证
一,在r2和r3上创建验证的用户
r2
[r2]aaa
[r2-aaa]loc
[r2-aaa]local-user oi pa
[r2-aaa]local-user oi password cipher 123
[r2-aaa]local-user oi service-type ppp
r3
[r3]aaa
[r3-aaa]loc
[r3-aaa]local-user us
[r3-aaa]local-user oi pa
[r3-aaa]local-user oi password ci
[r3-aaa]local-user oi password cipher 123
[r3-aaa]local-user oi service-type ppp
二,在r2和r3连接的物理接口上配置需要ppp验证,验证方式为chap,并且配置用户名
r2
[r2-Serial3/0/1]ppp authentication-mode chap
[r2-Serial3/0/1]ppp chap user oi
[r2-Serial3/0/1]int s4/0/0
[r2-Serial4/0/0]ppp authentication-mode chap
[r2-Serial4/0/0]ppp chap user oi
r3
[r3]int s3/0/0
[r3-Serial3/0/0]ppp authentication-mode chap
[r3-Serial3/0/0]ppp chap user oi
[r3-Serial3/0/0]int s3/0/1
[r3-Serial3/0/1]ppp authentication-mode chap
[r3-Serial3/0/1]ppp chap user oi
三.关闭再开启这几个接口的链路
r2
[r2-Serial4/0/0]shutdown
[r2-Serial4/0/0]undo shutdown
[r2-Serial4/0/0]int s3/0/1
[r2-Serial3/0/1]shutdown
[r2-Serial3/0/1]undo shutdown
r3
[r3-Serial3/0/0]shutdown
[r3-Serial3/0/0]undo shutdown
[r3-Serial3/0/0]int s3/0/1
[r3-Serial3/0/1]shutdown
[r3-Serial3/0/1]undo shutdown
四,检验是否通过
成功