[RT1]display interface Serial Serial1/0 Current state: UP # 端口状态UP Line protocol state: UP # 链路协议UP Description: Serial1/0 Interface Bandwidth: 64kbps Maximum Transmit Unit: 1500 Hold timer: 10 seconds, retry times: 5 Internet Address is 192.168.1.1/24 Primary Link layer protocol: PPP LCP: opened, IPCP: opened # LCP和IPCP都开启了 Output queue - Urgent queuing: Size/Length/Discards 0/100/0 Output queue - Protocol queuing: Size/Length/Discards 0/500/0 Output queue - FIFO queuing: Size/Length/Discards 0/75/0 Last link flapping: 0 hours 45 minutes 27 seconds Last clearing of counters: Never
此时互相 ping,能够 ping 通
PAP 双向验证配置
互相配置验证用户
RT1: [RT1]local-user zhangsan class network [RT1-luser-network-zhangsan]password simple 123 [RT1-luser-network-zhangsan]service-type ppp
RT2: [RT2]local-user lisi class network New local user added. [RT2-luser-network-lisi]password simple 321 [RT2-luser-network-lisi]service-type ppp
双方都要在串口配置 PPP 验证
RT1: [RT1-Serial1/0]ppp authentication-mode pap [RT1-Serial1/0]ppp pap local-user zhangsan password simple 123
RT2: [RT2-Serial1/0]ppp authentication-mode pap [RT2-Serial1/0]ppp pap local-user lisi password simple 321
同理检查串口状态,并互相 ping 检查。
CHAP 验证配置
CHAP 认证分为两种:认证方配置了用户名和认证方没有配置用户名。
当认证方配置了用户名:
RT1(验证方): # 配置对端的验证用户zhangsan [RT1]local-user zhangsan class network New local user added. [RT1-luser-network-zhangsan]password simple 123 [RT1-luser-network-zhangsan]service-type ppp
[RT1-Serial1/0]ppp authentication-mode chap # 配置对端验证本端的用户,即RT1对应了用户lisi [RT1-Serial1/0]ppp chap user lisi [RT1-Serial1/0]ppp chap password simple 321 # 密码,可选
RT2: # 配置对端验证用户lisi [RT2]local-user lisi class network New local user added. [RT2-luser-network-lisi]password simple 321 [RT2-luser-network-lisi]service-type ppp
[RT2-Serial1/0]ppp authentication-mode chap [RT2-Serial1/0]ppp chap user zhangsan [RT2-Serial1/0]ppp chap password simple 123
即:RT1的本地用户zhangsan是给RT2来验证的,RT2的本地用户lisi是给RT1来验证的
当验证方没有配置用户名:
RT1: [RT1]local-user zhangsan class network New local user added. [RT1-luser-network-zhangsan]password simple 123 [RT1-luser-network-zhangsan]service-type ppp
[RT1-Serial1/0]ppp authentication-mode chap
RT2: [RT2-Serial1/0]ppp chap user zhangsan [RT2-Serial1/0]ppp chap password simple 123
IP 地址协商
直接指定对端 IP 地址
RT1: [RT1-Serial1/0]remote address 192.168.1.2
RT2: [RT2-Serial1/0]ip address ppp-negotiate
然后查看 RT2 的串口端口 IP
[RT2-Serial1/0]display interface Serial 1/0 brief Brief information on interface(s) under route mode: Link: ADM - administratively down; Stby - standby Protocol: (s) - spoofing Interface Link Protocol Main IP Description Ser1/0 UP UP 192.168.1.2
配置地址池供对端选择
RT1: [RT1]ip pool pool-1 192.168.1.10 192.168.1.20 [RT1-Serial1/0]remote address pool pool-1
RT2: [RT2-Serial1/0]ip address ppp-negotiate
可在 RT1 上查看地址池的分配情况
[RT1]display ip pool pool-1 Group name: default Pool name Start IP address End IP address Free In use pool-1 192.168.1.10 192.168.1.20 10 1 In use IP addresses: IP address Interface 192.168.1.10 Ser1/0
ISP 域关联 IP 地址池
RT1: [RT1]ip pool pool-1 192.168.1.10 192.168.1.20 [RT1]local-user zhangsan class network New local user added. [RT1-luser-network-zhangsan]password simple 123 [RT1-luser-network-zhangsan]service-type ppp
[RT1]dis ppp mp ----------------------Slot0---------------------- Template: Virtual-Template1 max-bind: 16, fragment: enabled, min-fragment: 128 Master link: Virtual-Access0, Active members: 2, Bundle RT2 Peer's endPoint descriptor: RT2 Sequence format: long (rcv)/long (sent) Bundle Up Time: 2019/03/24 04:55:11:467 0 lost fragments, 0 reordered, 0 unassigned, 0 interleaved Sequence: 0 (rcv)/0 (sent) Active member channels: 2 members Serial1/0 Up-Time:2019/03/24 04:55:11:467 Serial2/0 Up-Time:2019/03/24 04:55:21:892
查看 VA 状态
[RT1]dis interface Virtual-Access Virtual-Access0 Current state: UP Line protocol state: UP Description: Virtual-Access0 Interface Bandwidth: 128kbps Maximum Transmit Unit: 1500 Hold timer: 10 seconds, retry times: 5 Internet Address is 192.168.1.1/24 Primary Link layer protocol: PPP LCP: opened, MP: opened, IPCP: opened Physical: MP, baudrate: 128000 bps Main interface: Virtual-Template1 ......
按用户名查找 VT
RT1: # 创建用户供RT2认证,需要为每个线路创一个 [RT1]local-user rt2-user1 class network New local user added. [RT1-luser-network-rt2-user1]password simple rt2-user1 [RT1-luser-network-rt2-user1]service-type ppp [RT1]local-user rt2-user2 class network New local user added. [RT1-luser-network-rt2-user2]password simple rt2-user2 [RT1-luser-network-rt2-user2]service-type ppp
# 串口配置,填写对端提供给本端的用户 # s1/0指定rt1-user1,s2/0指定rt1-user2 [RT1-Serial1/0]link-protocol ppp [RT1-Serial1/0]ppp authentication-mode pap [RT1-Serial1/0]ppp pap local-user rt1-user1 password simple rt1-user1 [RT1-Serial1/0]ppp mp
[RT1-Serial2/0]link-protocol ppp [RT1-Serial2/0]ppp authentication-mode pap [RT1-Serial2/0]ppp pap local-user rt1-user2 password simple rt1-user2 [RT1-Serial2/0]ppp mp
同理RT2配置: [RT2]local-user rt1-user1 class network New local user added. [RT2-luser-network-rt1-user1]password simple rt1-user1 [RT2-luser-network-rt1-user1]service-type ppp [RT2]local-user rt1-user2 class network New local user added. [RT2-luser-network-rt1-user2]password simple rt1-user2 [RT2-luser-network-rt1-user2]service-type ppp
[RT2]ppp mp user rt1-user1 bind Virtual-Template 1 [RT2]ppp mp user rt1-user2 bind Virtual-Template 1