ppp协议和GRE

1.R5为ISP,只能进行IP地址配置;其所有的IP地址均为共有IP地址

2.R1和R5之间使用PPP的PAP认证,R5为主认证方

R2和R5之间使用PPP的chap认证,R5为主认证方

R3和R5之间使用HDLC封装

3.R1/R2/R3构建一个MGRE环境,R1为Hub;

R1/R4之间构建一个GRE环境

4.整个私有网络基于RIP全网可达

5.所有PC设置私有IP为源IP,可以访问R5环回

一 、配置IP地址

复制代码
R1:

[R1]int g 0/0/0

[R1-GigabitEthernet0/0/0]ip address 192.168.1.254 24

[R1]int s 1/0/0

[R1-Serial1/0/0]ip address 15.0.0.1 24



R2:

[R2]int g 0/0/0

[R2-GigabitEthernet0/0/0]ip address 192.168.2.254 24

[R2]int s 2/0/0

[R2-Serial2/0/0]ip address 25.0.0.2 24



R3:

[R3]int g 0/0/0

[R3-GigabitEthernet0/0/0]ip address 192.168.3.254 24

[R3]int s 3/0/0

[R3-Serial3/0/0]ip address 35.0.0.3 24



R4:

[R4]int g 0/0/1

[R4-GigabitEthernet0/0/1]ip address 192.168.4.254 24

[R4]int g 0/0/0

[R4-GigabitEthernet0/0/0]ip address 45.0.0.4 24



R5:

[R5]int s 1/0/0

[R5-Serial1/0/0]ip address 15.0.0.5 24

[R5]int s 2/0/0

[R5-Serial2/0/0]ip address 25.0.0.5 24

[R5]int s 3/0/0

[R5-Serial3/0/0]ip address 35.0.0.5 24

[R5]int g 0/0/0

[R5-GigabitEthernet0/0/0]ip address 45.0.0.5 24

[R5]int LoopBack 0

[R5-LoopBack0]ip address 5.5.5.5 32

二、 配置PAP,CHAP,HDLC封装

(1)R1和R5间使用PPP的PAP认证,R5为主认证方

复制代码
认证方 R5:

[R5]aaa

[R5-aaa]local-user hcip password cipher 123456

[R5-aaa]local-user hcip service-type ppp

[R5-Serial1/0/0]ppp authentication-mode pap



被认证方 R1:

[R1]int s 1/0/0

[R1-Serial1/0/0]ppp pap local-user hcip password cipher 123456

(2)R2与R5之间使用PPP的CHAP认证,R5为主认证方

复制代码
认证方R5:

[R5-aaa]

[R5-aaa]local-user huawei password cipher 654321

[R5-aaa]local-user huawei service-type ppp

[R5-Serial2/0/0]ppp authentication-mode chap



被认证方R2:

[R2-Serial2/0/0]ppp chap user huawei
[R2-Serial2/0/0]ppp chap password cipher 654321

(3)R3与R5之间使用HDLC封装

复制代码
R3:

[R3]int s 3/0/0

[R3-Serial3/0/0]link-protocol hdlc




R5:

[R5]int s 3/0/0

[R5-Serial3/0/0]link-protocol hdlc 

三、 配置MGRE,GRE

复制代码
[R1]ip route-static 0.0.0.0 0 15.0.0.5

[R2]ip route-static 0.0.0.0 0 25.0.0.5

[R3]ip route-static 0.0.0.0 0 35.0.0.5

[R4]ip route-static 0.0.0.0 0 45.0.0.5

(1)R1/R2/R3构建一个MGRE环境,R1为Hub

复制代码
Hub R1:

[R1]int Tunnel 0/0/0

[R1-Tunnel0/0/0]ip address 192.168.5.1 24

[R1-Tunnel0/0/0]tunnel-protocol gre p2mp

[R1-Tunnel0/0/0]source 15.0.0.1



Spoke R2:

[R2]int Tunnel 0/0/0

[R2-Tunnel0/0/0]ip add 192.168.5.2 24

[R2-Tunnel0/0/0]tunnel-protocol gre p2mp

[R2-Tunnel0/0/0]source Serial 2/0/0

[R2-Tunnel0/0/0]nhrp entry 192.168.5.1 15.0.0.1 register



Spoke R3:

[R3]int Tunnel 0/0/0

[R3-Tunnel0/0/0]ip address 192.168.5.3 24

[R3-Tunnel0/0/0]tunnel-protocol gre p2mp

[R3-Tunnel0/0/0]source Serial 3/0/0

[R3-Tunnel0/0/0]nhrp entry 192.168.5.1 15.0.0.1 register 

(2)R1/R4之间构建一个GRE环境

复制代码
R1:

[R1]int Tunnel 0/0/1

[R1-Tunnel0/0/1]ip address 192.168.6.1 24

[R1-Tunnel0/0/1]tunnel-protocol gre

[R1-Tunnel0/0/1]source 15.0.0.1

[R1-Tunnel0/0/1]destination 45.0.0.4



R4:

[R4]int Tunnel 0/0/1

[R4-Tunnel0/0/1]ip address 192.168.6.4 24

[R4-Tunnel0/0/1]tunnel-protocol gre

[R4-Tunnel0/0/1]source 45.0.0.4

[R4-Tunnel0/0/1]destination 15.0.0.1

四、 配置RIP协议

复制代码
R1:

rip 1
 version 2
 network 192.168.1.0
 network 192.168.5.0
 network 192.168.6.0

[R1-Tunnel0/0/0]nhrp entry multicast dynamic 

[R1-Tunnel0/0/0]undo rip split-horizon 

[R1-Tunnel0/0/1]undo rip split-horizon
复制代码
R2:

rip 1
 version 2
 network 192.168.2.0
 network 192.168.5.0

[R2-Tunnel0/0/1]undo rip split-horizon
复制代码
R3:

rip 1
 version 2
 network 192.168.3.0
 network 192.168.5.0

[R3-Tunnel0/0/1]undo rip split-horizon
复制代码
R4:

rip 1
 version 2
 network 192.168.4.0
 network 192.168.6.0

[R4-Tunnel0/0/1]undo rip split-horizon

五、 配置NAT

复制代码
R1:

[R1]acl number 2000

[R1-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255

[R1]int Serial 1/0/0

[R1-Serial1/0/0]nat outbound 2000



R2:

[R2]acl 2000

[R2-acl-basic-2000]rule permit source 192.168.2.0 0.0.0.255

[R2]int Serial 2/0/0

[R2-Serial2/0/0]nat outbound 2000



R3:

[R3]acl 2000

[R3-acl-basic-2000]rule permit source 192.168.3.0 0.0.0.255

[R3]int Serial 3/0/0

[R3-Serial3/0/0]nat outbound 2000



R4:

[R4]acl 2000

[R4-acl-basic-2000]rule permit source 192.168.4.0 0.0.0.255

[R4]int g 0/0/0

[R4-GigabitEthernet0/0/0]nat outbound 2000
相关推荐
用户0328472220706 小时前
如何搭建本地yum源(上)
运维
大树883 天前
金刚石散热越强,管路越先见顶
大数据·运维·服务器·人工智能·ai
摇滚侠3 天前
Linux CentOS7 rpm 安装 MySQL 5.7
linux·运维·mysql
霸道流氓气质3 天前
领域驱动设计(DDD)在 Spring Boot 微服务中的实践指南
运维·spring boot·微服务
小宇宙Zz3 天前
Maven依赖冲突
java·服务器·maven
Inhand陈工3 天前
基于台达PLC与映翰通IG502的智慧水产养殖精准投喂与远程运维解决方案
运维·人工智能·物联网·阿里云·信息与通信
酣大智3 天前
ARP代理--工作原理
运维·网络·arp·arp代理
shushangyun_3 天前
2026年快消品B2B系统推荐:支持终端门店订货、促销政策自动化的工具?
java·运维·网络·数据库·人工智能·spring·自动化
古城小栈3 天前
Unix 与 Linux 异同小叙
linux·服务器·unix
施努卡机器视觉3 天前
SNK施努卡侧滑门锁上滑轮总成自动化装配线,从零件到组件,全流程精密制造方案
运维·自动化·制造