PPP PPPOE
ppp 点对点,串型链路,静态路由可以写出接口
网络层控制协议 NCP(协商IP地址)
链路控制协议 LCP (认证)
作用:认证功能 用户名+密码认证,MAC地址,IP地址认证
相关配置
PAP
认证方:
[R2]aaa
[R2-aaa]local-user abc password cipher huawei@123
[R2-aaa]local-user abc service-type ppp
[R2-aaa]q
[R2-Serial4/0/0]ppp authentication-mode pap 认证方选择认证模式
被认证方:
interface Serial4/0/0
ppp pap local-user abc password simple hhh 被认证方提供用户名密码
CHAP
认证方:
[R2]aaa
[R2-aaa]local-user abc password cipher huawei@123
[R2-aaa]local-user abc service-type ppp
[R2-aaa]q
[R2-Serial4/0/0]ppp authentication-mode chap 认证方选择认证模式
被认证方:
interface Serial4/0/0
ppp chap user abc
ppp chap password simple huawei@123
被认证方提供用户名密码
配置完shudown重新协商。
cipher密码密文显示 ,密码明文显示
PPPOE 配置 拓扑图如下
PPPOE服务器配置
一、配置全局地址池pool1
[Router] ip pool pool1
[Router-ip-pool-pool1] network 200.1.1.0 mask 255.255.255.0
[Router-ip-pool-pool1] gateway-list 200.1.1.1
[Router-ip-pool-pool1] quit
二、配置PPPoE认证用户
[Router] aaa
[Router-aaa] authentication-scheme 123
[Router-aaa-authen-system_a] authentication-mode local
[Router-aaa-authen-system_a] quit
[Router-aaa] authorization-scheme 123
[Router-aaa-author-system_a] authorization-mode local
[Router-aaa-author-system_a] quit
[Router-aaa] domain hhh
[Router-aaa-domain-hhh] authentication-scheme 123
[Router-aaa-domain-hhh] authorization-scheme 123
[Router-aaa-domain-hhh] quit
[Router-aaa] local-user user1@hhh password c Huawei
[Router-aaa] local-user user1@hhh service-type ppp
[Router-aaa] quit
三、创建并配置VT
[Router] interface virtual-template 1
[Router-Virtual-Template1] ppp authentication-mode chap domain hhh
[Router-Virtual-Template1] ip address 200.1.1.1 255.255.255.0
[Router-Virtual-Template1] remote address pool pool1
[Router-Virtual-Template1] ppp ipcp dns 114.114.114.114
[Router-Virtual-Template1] quit
四、在以太网接口GE1/0/0上启用PPPoE协议(绑定)
[Router] interface gigabitethernet 1/0/0
[Router-GigabitEthernet1/0/0] pppoe-server bind virtual-template 1
[Router-GigabitEthernet1/0/0] quit
PPPOE client 配置
一、配置拨号口
[Router] dialer-rule 规则
[Router-dialer-rule] dialer-rule 1 ip permit
[Router-dialer-rule] quit
[Router] interface dialer 1
[Router-Dialer1] dialer user liantong 随意配置,标记对端
[Router-Dialer1] dialer-group 1 拨号访问组1
[Router-Dialer1] dialer bundle 1 使能共享DCC并设置Dialer接口使用的Dialer bundle。(捆绑)
[Router-Dialer1] ppp chap user user1@hhh
[Router-Dialer1] ppp chap password cipher Huawei
[Router-Dialer1] ip address ppp-negotiate
[Router-Dialer1] quit
二、建立PPPoE会话(绑定)
[Router] interface gigabitethernet 2/0/0
[Router-GigabitEthernet2/0/0] pppoe-client dial-bundle-number 1
[Router-GigabitEthernet2/0/0] quit
三、路由部署
[Router] ip route-static 0.0.0.0 0 dialer 1
四、配置NAT技术
[Router] acl number 2000
[Router-acl-adv-3002] rule 5 permit
[Router-acl-adv-3002] quit
[Router] interface dialer 1
[Router-Dialer1] nat outbound 2000
[Router-Dialer1] quit
G/0/0/2地址自动学习到
server 查看地址
client 查看地址