要求:
实验配置(基于eNSP):
一:创建拓扑,PPP链路捆绑
(1)创建mp-group组并将AR2、AR3的四个serial接口划分在里面:
AR2:
[R2]interface Mp-group 0/0/0
[R2-Serial3/0/1]ppp mp Mp-group 0/0/0
[R2-Serial4/0/0]ppp mp Mp-group 0/0/0
[R2-Mp-group0/0/0]ip address 1.1.1.1 24
AR3:
[R3]interface Mp-group 0/0/0
[R3-Serial3/0/0]ppp mp Mp-group 0/0/0
[R3-Serial4/0/0]ppp mp Mp-group 0/0/0
[R3-Mp-group0/0/0]ip address 1.1.1.1 24
(二)在两台路由器上的mp-group组上配置IP地址(基于划分的网段)
二:配置IP地址
AR1:
[R1-Serial3/0/0]ip address 192.168.1.1 24
AR2:
[R2-Serial3/0/0]ip address 192.168.1.2 24
三:R2对R1的单向chap验证
(1)先在R2上配置秘钥、用户名与协议:
主验证方AR2:
[R2-aaa]local-user huang password cipher 123
[R2-aaa]local-user huang service-type ppp
[R2-Serial3/0/0]ppp authentication-mode chap
(2)再在R1上配置相应信息:
被验证方AR1:
[R1-Serial3/0/0]ppp chap user huang
[R1-Serial3/0/0]ppp chap password cipher 123
四:R2与R3之间的双向验证
在R2、R3上配置如下相同命令:
AR2主验证方:
[R2-aaa]local-user two password cipher 456
[R2-aaa]local-user two service-type ppp
[R2-Serial3/0/1]ppp authentication-mode chap
[R2-Serial4/0/0]ppp authentication-mode chap
AR3主验证方:
[R3-aaa]local-user twoo password cipher 123
[R3-aaa]local-user twoo service-type ppp
[R3-Serial3/0/0]ppp authentication-mode chap
[R3-Serial4/0/0]ppp authentication-mode chap
并且将R2、R3各自的两个Serial接口分别作为对方的接受端口:
AR2被验证方:
[R2-Serial3/0/1]ppp chap user twoo
[R2-Serial4/0/0]ppp chap user twoo
AR3被验证方:
[R3-Serial3/0/0]ppp chap user twoo
[R3-Serial3/0/0]ppp chap password cipher 123
[R3-Serial4/0/0]ppp chap user twoo
[R3-Serial4/0/0]ppp chap password cipher 123
ppp chap user two
ppp chap password cipher 456