一、拓扑和要求
二、配置:
1、R1与R2之间为hdlc封装
R1上
[R1]interface Serial 4/0/0
[R1-Serial4/0/0]link-protocol hdlc
R2上
[R2]interface Serial 4/0/0
[R2-Serial4/0/0]link-protocol hdlc
2.R2-R3之间PPP封装,pap认证,R2为主认证方
R2
PAP 明文传递用户名和密码
[R2]aaa 主认证方—服务端
[R2-aaa]local-user huawei password cipher huawei123
[R2-aaa]local-user huawei service-type ppp
[R2]interface Serial 1/0/0 连接客户端的接口
[R2-Serial1/0/0]link-protocol ppp
[R2-Serial1/0/0]ppp authentication-mode pap
[R2-Serial1/0/0]ip address 10.1.1.1 30
R3
[R3]interface Serial 1/0/0 被认证方
[R3-Serial1/0/0]link-protocol ppp
[R3-Serial1/0/0]ppp pap local-user huawei password cipher huawei123
[R3-Serial1/0/0]ip address 10.1.1.2 30 先前配置过就可以
3、R2-R3之间ppp封装,chap认证,R2为主认证方
前面创建过同一个用户这可以不用创建
[R2]aaa 主认证方—服务端
[R2-aaa]local-user huawei password cipher huawei123
[R2-aaa]local-user huawei service-type ppp
[R]interface Serial 1/0/0 连接客户端的接口
[R2-Serial1/0/0]link-protocol ppp
[R2-Serial1/0/0]ppp authentication-mode chap
[R2-Serial1/0/0]ip address 10.1.1.1 30 先前配置过就不用
```bash
[R4]interface Serial 1/0/0 被认证方
[R4-Serial1/0/0]link-protocol ppp
[R4-Serial1/0/0]ppp chap user huawei
[R4-Serial1/0/0]ppp chap password cipher huawei123
[R4-Serial1/0/0]ip address 10.1.1.2 30 先前配置过就可以
4、R1、R2、R3构建MGRE环境,仅R1 IP 地址固定
[r1]interface Tunnel 0/0/0
[r1-Tunnel0/0/0]ip address 10.1.1.1 24
[r1-Tunnel0/0/0]tunnel-protocol gre
[r1-Tunnel0/0/0]source 12.1.1.1
[r1-Tunnel0/0/0]destination 23.1.1.2
[R3]interface Tunnel0/0/0
[R3-Tunnel0/0/0] ip address 10.1.1.2 255.255.255.0
[R3-Tunnel0/0/0] tunnel-protocol gre p2mp
[R3-Tunnel0/0/0]source Serial1 4/0/0 假设分支站点ip地址不固定
[R3-Tunnel0/0/0] nhrp network-id 100
[R3-Tunnel0/0/0] nhrp entry 10.1.1.1 15.1.1.1 register 分支需要到中心站点注册
切记:R1上删除rip的水平分割
[R1]interface Tunnel0/0/0
[R1-Tunnel0/0/0]undo rip split-horizon