找回密码
 注册
查看: 1122|回复: 1

华为路由器:PPPOE配置模拟实验及NAT配置

[复制链接]

1

主题

0

回帖

12

积分

管理员

积分
12
QQ
发表于 2022-3-16 09:39:13 | 显示全部楼层 |阅读模式
实验环境$ Y8 ?5 v9 p* T! o4 r+ ^! a
) U# h" C& \2 R7 E( _! p
pppoe-client上面的接口信息
0 q0 c- N+ T/ r2 x% T. D
* G) g& D. ?, m* W, p0 u/ F[AR1]dis ip interface brief
3 H! o* R7 w/ d9 F3 f*down: administratively down
. [& }8 C3 P* S^down: standby
3 }- b4 M/ s' Y* W: j2 |/ T: Q(l): loopback
2 g$ W, e6 E5 T(s): spoofing
7 J) ~% {" o% EThe number of interface that is UP in Physical is 2
% Q, g# p  G( A5 J; xThe number of interface that is DOWN in Physical is 1
+ y6 W9 d8 @- M% [; H# }8 PThe number of interface that is UP in Protocol is 1
! W& D+ w- G# |  `$ \The number of interface that is DOWN in Protocol is 2# e; [3 W* N. n

( F( s) R; f$ a2 fInterface                         IP Address/Mask      Physical   Protocol  
2 M; H! Y) c% U& A1 hGigabitEthernet0/0/0              unassigned           up         down      2 G5 B, _$ i& S1 K; p1 D; Q0 s
GigabitEthernet0/0/1              192.168.1.254/24     down       down      
* B; d# D0 s2 M1 U* j4 _# B& BNULL0                             unassigned           up         up(s)     
8 d# Q+ A4 y, a/ I7 L0 g; V/ C

# f/ v% r# T+ Y: q' P配置了基于接口的DHCP- j6 y# M3 k: y, Q$ T2 }

5 \- G% b& z% U$ j* ^- C9 Ginterface GigabitEthernet0/0/1
  R1 e: Y! n2 H: L ip address 192.168.1.254 255.255.255.0 # P6 }( _' U- s
dhcp select interface
% v9 j) A3 s& e% b9 M dhcp server dns-list 8.8.8.8 7 u8 S3 C1 X! S
dhcp server domain-name pokes.com  ~* Y0 M$ A: s( N6 a, A' I

9 \. `+ f2 p9 |6 l8 [0 G, B注意事项:AR1、AR2的物理接口g0/0/0不配地址.
( B5 O- l7 Y6 C/ l1 v# \. L) C! _. S2 V  h3 v6 l
一、pppoe-server的配置  M4 s8 a8 J1 r' F/ c
1、pppoe-server 配置地址池% E) ?: C1 w  X
[pppoe-server]ip pool pokes            #创建名为pokes的地址池,名字可以随便起,后面要调用
# [4 v5 m; B  gInfo: It's successful to create an IP address pool.% r+ R, f' i. Q2 G, U# a) T1 Z
[pppoe-server-ip-pool-pokes]network 10.1.12.0 mask 24   #地址池为10.1.12.0/24  |& S+ a. X! z- Y( j
[pppoe-server-ip-pool-pokes]dis th- H* ~" Y0 Z5 J* [
[V200R003C00]
& c1 `! \" s+ g1 v2 J7 x# B#/ i* {) R+ u  J" ^  e9 b0 D: [6 a
ip pool pokes7 [! \! [: h: K  p- C; d& I+ j
network 10.1.12.0 mask 255.255.255.0
2 `3 _4 e4 E! K, X/ q( M; [, f3 E0 C#
( y2 S! J6 A% a1 ireturn4 y/ K+ k. u, h7 W
[pppoe-server-ip-pool-pokes]q/ T1 n" h! q0 p" j+ a# O! `% w
7 ?% V" R- F. C! l/ T+ n* i
2、配置虚拟口关联地址池6 n5 ]( T/ r% l$ M* X2 H3 P
配置虚拟口关联地址池,即创建Virtual-Template 1模版。9 D- L$ x* ~1 o/ i) r: h, ~* y$ I; t
' w3 T% U; z9 i% j* q
[pppoe-server]interface Virtual-Template 1    #创建虚拟接口14 \' e% V7 c6 b  g, C" t; o8 G
[pppoe-server-Virtual-Template1]ip add 10.1.12.2 24                   #虚拟接口1的地址9 e# E2 W6 A5 ~7 x
[pppoe-server-Virtual-Template1]ppp authentication-mode chap   #认证类型( @2 B+ T2 h: s' p8 ~
[pppoe-server-Virtual-Template1]remote address pool pokes      #客户端的地址池pokes
+ A" i3 T/ z4 M% |$ L& |[pppoe-server-Virtual-Template1]dis th
* }+ z8 m1 i/ R3 m& cinterface Virtual-Template1
% a; ]+ i/ G8 x3 p" E2 a ppp authentication-mode chap 2 `. ~# O# ?( Q& m. X1 b2 Z
remote address pool pokes& U3 ~9 H8 x3 U! D
ip address 10.1.12.2 255.255.255.0
" y& C; m  Z5 J) ?  ?5 ]4 C+ L' }9 X4 D2 j3 S4 j, M% r$ Y
[pppoe-server]int g0/0/0       
8 |( W# h( R2 l8 n[pppoe-server-GigabitEthernet0/0/0]pppoe-server bind virtual-template 1   #将虚拟接口1关联到g0/0/0接口" ?" N( b6 e9 L
[pppoe-server-GigabitEthernet0/0/0]dis th. C( O) V" o* z8 Y0 o( x
[V200R003C00]
$ K$ o3 r3 Y0 C2 N#1 ^& }8 T* _3 b3 d
interface GigabitEthernet0/0/0
9 Y. ?# [9 r) W pppoe-server bind Virtual-Template 17 C$ K& [! i$ g  O. [- o3 A
#$ L! k  U3 ?7 E& h9 o- ]4 T
return
+ z" e; f+ U% b( V; T[pppoe-server-GigabitEthernet0/0/0]2 [/ ]. |3 o1 l9 @  ]

" O6 h0 e! [9 E3、创建pppoe拨号的账号% ^+ Y$ d. X/ \) Q0 e8 D) {4 B+ i
按理我们应该创建pppoe拨号的账号。( ]2 M7 V  [! i$ m( A) W0 j+ k
这里为了演示拨号失败,我们这里先不新建账号,后面再新建。
7 [) U3 H- O. s5 ]8 C2 N3 r. V. j7 k% W
二、pppoe-client的配置+ M) R, x8 i8 {3 {$ s1 u+ w3 J6 Y7 T
[pppoe-client]dialer-rule   
8 E0 I# n  {: g8 W[pppoe-client-dialer-rule]dialer-rule 1 ?
  [5 [4 P7 }* f3 m  acl   Permit or deny based on access-list   4 d. _- p2 t* |1 V( f7 i
  ip    Ip
7 p. R4 o* P' g- ^- A8 f  L& Q  ipv6  Ipv6       
" ~; e% E& D  r8 `/ G4 M4 F7 L/ y[pppoe-client-dialer-rule]dialer-rule 1 ip permit   #创建拨号规则,允许ip流量触发拨号7 h: k- q) m  q3 }' T, F2 a
& S* \, }) Y5 N$ ^& R
[pppoe-client]interface Dialer 14 y. u) R* i) H7 j& a, U
Jul 15 2021 18:55:22-08:00 pppoe-client %%01IFPDT/4/IF_STATE(l)[0]:Interface Dia! E, z2 ~( G% A2 {. O
ler1 has turned into UP state.2 K7 m, ~5 g; Q. I
[pppoe-client-Dialer1]ip add        , j3 g5 m$ [" P1 Y( ^+ e  Y' g5 v2 M2 {2 i
[pppoe-client-Dialer1]ip address ppp       
  x5 B' T6 G, i- P7 d+ K[pppoe-client-Dialer1]ip address ppp-negotiate  #地址采用ppp协商* G- x4 f( m& ?5 `; a; o- N

2 l+ A9 Y$ [# R5 f+ A4 l8 s[pppoe-client]interface Dialer 1                #创建接口拨号组1. f! M4 Z5 `5 u! K% i0 Q- j
[pppoe-client-Dialer1]ip address ppp-negotiate  #ip地址采用ppp协商% W( Z) X' T7 N* ]/ `6 y
[pppoe-client-Dialer1]dialer user zhprny        #此用户不用于认证,是标识作用以及和dialer绑定8 M6 U  r% s; Z; w) s
[pppoe-client-Dialer1]dialer bundle 1           #设备通过Dialer bundle将物理接口与拨号接口关联起来。
3 i& g5 T) D/ l[pppoe-client-Dialer1]dialer-group 1             #放到一个拨号访问组1中
) I8 A9 w9 P' ?+ M3 t- l[pppoe-client-Dialer1]ppp chap user pokes        #指定dialer1接口的编号,拨号账号
, W  p; ~! H! P3 Z9 b[pppoe-client-Dialer1]ppp chap password 123456   #拨号的密码
% K2 ?; L6 `# c5 ^) \6 u3 \- \4 K$ S  _* v8 ^8 @
5 ^- l/ E6 u7 L! m
[pppoe-client-Dialer1]dis th. I3 p9 }% y; V5 S; G5 \  d4 j; H1 R, o% i
[V200R003C00]# D- f1 h3 [: ~0 b6 d# r
#. u8 B1 `- k5 v" {
interface Dialer1
: @3 y8 d( S7 y4 q link-protocol ppp# f+ V' n1 g) \( r" [+ {% y# G$ v
ppp chap user pokes0 G3 a) [! X- F" O
ppp chap password cipher %$%$I/!'WCyd<7p[~8;,>51L,$sl%$%$# Z/ z/ D7 ?* W- t( Q7 m2 o
ip address ppp-negotiate) j" q( d1 U! l7 |# Q
dialer user zhprny7 o; b, |/ n- A$ {8 E5 i
dialer bundle 1
* p3 l3 H' `! c5 }& [& Y& c7 b4 s dialer-group 1  {9 b  ~$ U2 g5 J. g
! c+ H) ^7 }5 [
[pppoe-client-GigabitEthernet0/0/0]
' R$ ?, z, |- x( K7 CJul 15 2021 19:07:54-08:00 pppoe-client %%01IFNET/4/LINK_STATE(l)[0]:The line pr- ]4 h1 ]$ r( y+ K4 A& B. D8 P
otocol PPP on the interface Dialer1:0 has entered the UP state.  #PPP已进入启动状态
% u, ~8 d# d) b( v" U- j" K/ d[pppoe-client-GigabitEthernet0/0/0]
! |: X5 D) J+ M* l. d& g* m) FJul 15 2021 19:07:54-08:00 pppoe-client %%01IFNET/4/LINK_STATE(l)[1]:The line pr
/ N" k+ e& k# G( x# c3 ~otocol PPP on the interface Dialer1:0 has entered the DOWN state. #PPP已进入关闭状态" W) P: `: \7 l/ P
4 T+ D+ L$ C* z* @/ {7 B5 V
#不停的循环。。。。
; V- ~& w" U. C2 B- {3 v8 @
, ~  W) k) _4 f7 x9 D' X* b( s& W+ W5 [' C8 ]
#原因是没有认证成功,因为我们在PPPOE-server上面还没有创建认证用户和密码
) b: ~8 C: d3 E' t8 X
4 w* j% ?' {8 B: G三、pppoe服务器上新建认证用户
9 P& M. O0 H2 @: y: L3 c我们到服务器上直接新建认证用户:
9 o. I* ^0 o/ A' E; v0 W9 Z# B" P% |  K
[pppoe-server]aaa
0 T$ R; Q% a: m* V; a( D[pppoe-server-aaa]local-user pokes password cipher 123456: G  D, b+ S7 a6 g: N5 _/ W; n
Info: Add a new user.
- e* o" M. K9 T* X4 j: R& U[pppoe-server-aaa]local-user pokes service-type ppp    #类型为ppp2 U) G* c0 m' c7 x6 Q3 V  }, A
) X2 V/ b, v8 B! P' K7 H
- D- t; H3 h3 u& F
四、客户端验证结果
  @9 a; `7 C1 ~1、认证成功信息
& T4 I: w5 |2 v4 Y然后客户端就会出现认证成功的提示:+ P8 o$ |; L  h, D! K  x* s
: u, ~8 z3 B  o' V
[pppoe-client-GigabitEthernet0/0/0]
- T8 M  V9 X( I* b$ w4 q) _Jul 15 2021 19:09:23-08:00 pppoe-client %%01IFNET/4/LINK_STATE(l)[10]:The line p% U+ e. J% U& u5 b1 x8 F; ]$ G3 @
rotocol PPP on the interface Dialer1:0 has entered the UP state. % P! ^+ u1 k! c
[pppoe-client-GigabitEthernet0/0/0]
' @: D; {2 a  }Jul 15 2021 19:09:23-08:00 pppoe-client %%01IFNET/4/LINK_STATE(l)[11]:The line p
! V5 k, i3 N8 @/ n2 S; x# g. Z% Wrotocol PPP IPCP on the interface Dialer1:0 has entered the UP state. ) V" n- U7 C; u  m6 P. r; O& z4 G( W
[pppoe-client-GigabitEthernet0/0/0]q$ P' l; [1 ], y9 @+ P6 U
[pppoe-client]dis ip in b1 z4 F) v6 a( L$ @; N$ A
*down: administratively down, e) j' K, |5 ^8 i
^down: standby& e) {6 h3 z1 Z6 f" O" e- T5 p
(l): loopback
. P; m# }/ J) G0 x% L6 |5 O! z  D9 E(s): spoofing6 D$ [9 h4 G; u6 Y; Z
The number of interface that is UP in Physical is 4
' }6 l) [$ r; T! m" Z) YThe number of interface that is DOWN in Physical is 0/ z- N9 x7 ~8 d
The number of interface that is UP in Protocol is 37 }, S* J3 k& ?2 ^* U
The number of interface that is DOWN in Protocol is 1' o9 D- B: U; ]$ f7 b
+ f8 x3 d  L3 V/ Z( v
Interface                         IP Address/Mask      Physical   Protocol  $ w# r! @* n1 O/ H$ D
Dialer1                           10.1.12.254/32       up         up(s)     #拿到了PPPOE服务器上的地址
- c" S: w1 g& l* ~3 ~GigabitEthernet0/0/0              unassigned           up         down      ) @) @/ s( v- o- }$ ^0 X. x
GigabitEthernet0/0/1              192.168.1.254/24     up         up        
% T% D" W" ^5 Y+ N5 f! JNULL0                             unassigned           up         up(s) 0 _* u; F. n: [- D  u7 B+ [

& y8 \0 ?2 u9 l. s/ `3 J0 ~2 S) M. u- j5 L2 B4 e  c! U+ p
2、pppoe-server 信息
- _' W7 K  M- Y( p& y6 F5 p<pppoe-server>dis interface Virtual-Template 1/ \+ \7 `& u7 q6 _8 C7 P* B4 A3 W) f
Virtual-Template1 current state : UP- A+ C# J& k1 M1 y  b
Line protocol current state : UP
" D; H2 P" O4 m/ t; f% E5 _  `. [Last line protocol up time : 2021-07-15 19:09:22 UTC-08:00/ ^0 U* a) ]; D9 |/ B2 Z
Description:HUAWEI, AR Series, Virtual-Template1 Interface
0 N+ B- i6 U: s, J- w+ c$ k! oRoute Port,The Maximum Transmit Unit is 1492, Hold timer is 10(sec)
+ o1 Z2 i( d: oInternet Address is 10.1.12.2/24' V  U% ~8 ~; X/ _$ N
Link layer protocol is PPP& v, x* `/ w) Y3 h. v5 {
LCP initial" @, e2 q) N6 v
Physical is None
5 U- J) U5 y( M- @4 LCurrent system time: 2021-07-15 20:27:28-08:00
5 |# W/ Z' p! w6 C& |7 [: J* D    Last 300 seconds input rate 0 bits/sec, 0 packets/sec, s7 K% i: @  t/ S5 V1 Z
    Last 300 seconds output rate 0 bits/sec, 0 packets/sec& V) g9 P4 l$ |4 D
    Realtime 0 seconds input rate 0 bits/sec, 0 packets/sec1 l! I1 N% C- l' L
    Realtime 0 seconds output rate 0 bits/sec, 0 packets/sec
" A3 S" Z+ M7 n# ^* J9 b  a0 \( k    Input: 0 bytes- ~3 v% v# Y3 C3 |2 m' W
    Output:0 bytes
% Q+ b. p- V5 D1 a2 y    Input bandwidth utilization  :    0%  G4 M+ Z3 K) W5 X7 {: x
    Output bandwidth utilization :    0%3 u1 A) o3 j) Q& ~
6 _) N  G; y/ x, A% x
<pppoe-server>
* w) Z; ]( v; z  t
3 e/ K7 j7 \' G# c0 |+ p; i' C+ I+ ^$ x" m9 J* }' ]* W
3、pppoe-client信息
; @5 }" k2 Q7 O0 k4 {  D/ _% g7 |<pppoe-client>dis interface Dialer 1# ~. j3 Z% F9 [! x) V- N
Dialer1 current state : UP3 s! p- b/ g, m* [
Line protocol current state : UP (spoofing)4 @2 j: W2 m2 q7 U5 l6 \& n
Description:HUAWEI, AR Series, Dialer1 Interface
) g; [. u! d$ P9 ^; i0 C. y+ p7 e! DRoute Port,The Maximum Transmit Unit is 1500, Hold timer is 10(sec)
! r% \9 q7 R) T: b# g% P# {% F; s* nInternet Address is negotiated, 10.1.12.254/32
' x, U2 q  r7 L' ALink layer protocol is PPP
, ?. E* W# O' H6 iLCP initial8 _+ U- C' @: E# T) ^" j( ]0 V
Physical is Dialer( w! p1 q9 L+ ]; [- g" y
Current system time: 2021-07-15 20:23:56-08:004 Z& M4 C+ ~! B0 K
    Last 300 seconds input rate 0 bits/sec, 0 packets/sec
+ f; g2 q; @1 z# s2 z, I    Last 300 seconds output rate 0 bits/sec, 0 packets/sec
" z6 }9 H, W# p4 N) H    Realtime 0 seconds input rate 0 bits/sec, 0 packets/sec
* n$ M3 }; s+ P. Q2 Q+ ?    Realtime 0 seconds output rate 0 bits/sec, 0 packets/sec  c: C" l  z7 Z8 A) L
    Input: 0 bytes# P6 s" N* q% Y. s! H
    Output:0 bytes
4 k( ?& C9 }. q8 g$ a4 Z0 I4 x    Input bandwidth utilization  :    0%6 w7 q, N7 D5 J" b1 `
    Output bandwidth utilization :    0%
5 p  y; Z+ l( X1 K3 DBound to Dialer1:0:
/ S& \$ q) H8 r* F* y4 f  ?8 aDialer1:0 current state : UP ,3 M% N4 ^( `" B/ \4 O9 g* ~, r
Line protocol current state : UP
( D5 H: y. F. F/ S" F
& z$ `' b& c: m0 m' MLink layer protocol is PPP
$ g, c0 H- `- v% _LCP opened, IPCP opened
# O; ]4 z, c) p. t* q% b  U0 _6 L% dPackets statistics:
6 y1 L9 Q! s" r  Input packets:0,  0 bytes
+ k; m; r9 ]4 [7 \+ U  g' D2 q  Output packets:4, 336 bytes3 p) q7 o5 }2 ~, Q1 R
  FCS error packets:0  F$ j$ ?9 z" o- a! S
  Address error packets:0& \" b5 i' v" y! [+ x( y8 q  i
  Control field control error packets:0$ `) n" s/ N( b; e
9 c/ ^5 ^$ E5 ?
) ~1 X4 _0 t! w& ?8 [7 V5 J: {5 Q
<pppoe-client>7 E- B9 x  v, P9 u! r; N
1 z. C0 J- G) ~& A8 C
五、NAT的配置
( m  W: \; Z- _* l) E' R用PC2直接ping 10.1.12.254是可以通的。10.1.12.254是AR1的g0/0/0口获取到的地址,其实就是我们常说的WAN口地址。/ @# ~0 T  ^" f* y+ l# d' Y3 G% u

! a( N7 H# U# {5 ]. W$ }PC2>ping 10.1.12.254
3 j. H- C/ y- b/ R8 v& g( M6 b, S+ O4 X- V) Z* a! x6 e
Ping 10.1.12.254: 32 data bytes, Press Ctrl_C to break
, Q3 m  @+ D/ ^0 [: k: N7 bFrom 10.1.12.254: bytes=32 seq=1 ttl=255 time=63 ms% _+ J5 @9 B3 y8 T2 ~
From 10.1.12.254: bytes=32 seq=2 ttl=255 time=31 ms9 F: z$ I( O' s- j- u) Q
From 10.1.12.254: bytes=32 seq=3 ttl=255 time=47 ms* L& J) x) V% f0 u) J
From 10.1.12.254: bytes=32 seq=4 ttl=255 time=31 ms
* s. R, A$ D8 Q% ^. z- XFrom 10.1.12.254: bytes=32 seq=5 ttl=255 time=47 ms
# c& R8 v" }  d- v5 {5 o% m+ N/ M* t' U% e8 `" g  q# s
--- 10.1.12.254 ping statistics ---; t% w0 W- s& e7 H
  5 packet(s) transmitted
" Y0 t' B" p( r# F- g  5 packet(s) received
7 B% n" N& W7 L3 }( R3 D4 {  0.00% packet loss; D) r( u* p  U2 g4 r$ I* {) M
  round-trip min/avg/max = 31/43/63 ms$ d* ?6 ?: P2 Z* h. W, U* m
+ A0 H" t6 n9 @
PC2>ping 10.1.12.24 P8 [2 u* P: X

% A7 c, u  V0 C/ M# u7 h$ {6 O' zPing 10.1.12.2: 32 data bytes, Press Ctrl_C to break
$ y. E# W' X2 w( w0 PRequest timeout!
, k. `; C, B: c- ~7 |Request timeout!
1 X; r& r- S2 s, n; HRequest timeout!
7 i- g6 i% y* m( d7 `# P; \6 F& iRequest timeout!7 M& @: k, Z% y. t! P
Request timeout!2 \0 q1 S5 N+ m% `! G1 T
% z) x7 w4 g* E3 c3 o
--- 10.1.12.2 ping statistics ---
: g7 A" I* b% E' ~) u: i; R  5 packet(s) transmitted
5 k  \& Y2 t- s) Z: G" c  0 packet(s) received7 G% F# S& ?2 j& T5 w
  100.00% packet loss
$ E3 t8 u+ b" ]$ p#但是无法ping通10.1.12.2' e* R0 D/ E5 E. D/ s) h( S" c
, H  }4 h3 b# {

3 {! X6 _6 b% k# _& d无法ping通10.1.12.2的原因是:我们没有做NAT .接下来我们在pppoe-client上面做NAT
5 Y( S4 z2 U  s3 \
# \( D* M$ z  J$ N, H1、这里配置规则2000
! k1 g' \0 J8 q# `  B[pppoe-client]acl number 2000       
* H# E% \% v/ {( x7 l[pppoe-client-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
! C& I  Y0 W+ b2 R& u) b- z: v! k7 p3 H6 R( Y
2、将规则2000绑定到接口( L0 q, K( N# r# @; Y9 L/ H
如下接口信息,需要注意的是pppoe的接口是Dialer1,并不是GigabitEthernet0/0/0口。我们必须将规则绑定在Dialer1口,最容易犯错的就是直接绑定在g0/0/0口。
; B; E' m$ {5 i& p* P$ V
2 g. K( i: q% A/ T. ?" ?* C[pppoe-client]dis ip int b
$ P1 w5 S& l; t. w" C*down: administratively down
2 C' E8 L; ^  @+ w7 r0 P^down: standby
1 ]5 o! A0 o( S(l): loopback
$ W5 g& ?" |# K, g8 J" f& ~) s: Z(s): spoofing
* C! p; z: E; J& yThe number of interface that is UP in Physical is 45 _( [' \9 }4 f) V% |
The number of interface that is DOWN in Physical is 0
: R+ p5 L  g# s* X  YThe number of interface that is UP in Protocol is 3
7 F! ]6 j) G' g/ QThe number of interface that is DOWN in Protocol is 19 u* t( G# q3 S1 K
5 @" o3 q: j" O  {4 V) W! M. h
Interface                         IP Address/Mask      Physical   Protocol  ) _% E( C' L9 B. F! h; c, z3 a, M
Dialer1                           10.1.12.254/32       up         up(s)     
+ A( }' E# y$ ^! b& hGigabitEthernet0/0/0              unassigned           up         down      
0 `) f5 e- u1 ~2 DGigabitEthernet0/0/1              192.168.1.254/24     up         up        9 V# w$ @  f4 r3 l% d5 U) K, S* s/ K* N
NULL0                             unassigned           up         up(s)     
( v4 j/ J) |9 j$ t4 L9 V$ g! j[pppoe-client]
" E: b. N. K. A' |: }5 ~( ^$ M. d! |5 o/ C. k3 G7 t$ |" P
[pppoe-client]int Dialer 1       
& J# n1 k: E+ L( B[pppoe-client-Dialer1]nat outbound 2000
! I; y4 u' H. [# c- \& V; U  h[pppoe-client-Dialer1]dis th
0 I, @- @% H; k& I[V200R003C00]9 E. V$ e$ a: e
#3 D8 _+ X* S0 B# S7 S  g
interface Dialer1
4 I4 a1 ^* {# @$ R+ G  T/ D link-protocol ppp" z& k3 y6 o6 r1 b! G* m! u# g
ppp chap user pokes
% v( }' @: F7 v ppp chap password cipher %$%$I/!'WCyd<7p[~8;,>51L,$sl%$%$, L* t8 n0 I, O, g# X
ip address ppp-negotiate' o% Z9 r- d+ ^- W5 w8 o- }
dialer user zhprny2 }- q- T# Z* ]  B7 u/ ~
dialer bundle 1( m% d  k' O/ c- [& y
dialer-group 17 A; Z/ x! `# _" l) h9 E2 `' C
nat outbound 20001 H: f4 Y& K! n
#
2 r. y) Z7 `! wreturn2 |9 b$ }; K+ p7 R& r) d  K
[pppoe-client-Dialer1]
+ m% ^8 D& c1 P6 n7 ~8 F3 L
; b4 V( Y$ n* t接下来我们就可以ping通10.1.12.2 了。7 V+ [, e. i( @% T9 w. o0 D0 G

1 J' e/ ?; u" `; m6 F  e- {" iPC2>ping 10.1.12.24 e1 Q2 B8 O# ]5 s
3 O9 T3 v# d/ C/ D) h
Ping 10.1.12.2: 32 data bytes, Press Ctrl_C to break
/ ?( k2 J8 J5 d9 [4 d" nFrom 10.1.12.2: bytes=32 seq=1 ttl=254 time=31 ms+ o+ D: i0 r* W- f& W
From 10.1.12.2: bytes=32 seq=2 ttl=254 time=32 ms
# h  d! ~  e9 F5 U+ O" i6 sFrom 10.1.12.2: bytes=32 seq=3 ttl=254 time=46 ms
6 D4 T' }6 ]: nFrom 10.1.12.2: bytes=32 seq=4 ttl=254 time=32 ms
7 u, R/ [0 z  \' H. C" CFrom 10.1.12.2: bytes=32 seq=5 ttl=254 time=31 ms
5 \8 `( j0 C( I* v7 o1 ?
, i8 D& L( T' [; o& d0 ]) B' N% i--- 10.1.12.2 ping statistics ---$ c% g4 k3 W. I: i1 ]: v
  5 packet(s) transmitted
8 ]4 L7 q# G, k7 c% M' o. D  5 packet(s) received
$ B4 Q1 b# f9 e  0.00% packet loss
* S% i' g( z+ Q: C5 c  round-trip min/avg/max = 31/34/46 ms
/ [4 t) k$ k, a/ U! X$ W" W* n3 Z: f3 Q! Z
: O7 ?  q- C8 D0 K( a6 X% n

1

主题

0

回帖

12

积分

管理员

积分
12
QQ
 楼主| 发表于 2022-3-17 09:27:15 | 显示全部楼层
华为路由器:PPPoE实验; i0 v" l& \- S, s
PPPoE协议是基于C/S架构的一种网络拨号协议。分为客户端和服务器两部分,它的建立过程分为discovery和session两个阶段。本次实验的目标:掌握PPPoE拨号技术;% v, [& w$ Z1 H( k" V  ~+ L
实验拓扑:2 @. m' s6 _* A; B, u: m& k1 X2 \- v
0 C1 Z- s' C% q) r# _. @7 i
本实验结合虚拟机进行:, a( _# f+ x/ y! o. O" O$ R0 B
首先,必须在虚拟机的网络配置中加以设置,我新建了VM6,去掉了DHCP的钩。这个时候会在你的网卡界面多出来一个虚拟的VM6的网卡。但是当你打开ensp时,会出现检测不到VM6的情况,这个时候你重启一下电脑,就可以了。5 E. q" X  I- _9 t" x
+ k+ B; `. h: }: m
Cloud1的设置如下图:
4 i: W/ H! q6 o: I+ {5 m2 X2 r8 i* _/ B$ I" b" X$ T8 \( W" s
1、基本的IP配置
. D' i! K; }0 `# n4 ][pppoe-server]dis ip in b
9 t7 @; C2 b+ R8 w4 o, A" T+ Z/ \*down: administratively down
& [& P& h, Y$ G; g8 m# u^down: standby3 M$ N, j! G! G) @" q
(l): loopback
% x- o/ J/ F( R9 m  Y7 {8 @( [# m(s): spoofing
' `( o5 M+ ^% J' ~  EThe number of interface that is UP in Physical is 49 F) ]2 B/ ^1 d% R! W  r, C
The number of interface that is DOWN in Physical is 1
3 S4 ]7 y3 g! S3 \7 ~The number of interface that is UP in Protocol is 2
& r; D) E/ r8 N3 V* C# vThe number of interface that is DOWN in Protocol is 36 ?% K- u- I# g& M
Interface                         IP Address/Mask      Physical   Protocol  
5 a  ~3 G' e9 F/ R7 `" {GigabitEthernet0/0/0              unassigned           up         down      $ r; U" B) E: X
GigabitEthernet0/0/1              202.104.10.1/24      up         up        
- J- [0 o3 ]; Y8 E7 y  j5 Z; E. M* {GigabitEthernet0/0/2              unassigned           down       down      ! S! M# p: ^% \2 r; @# X$ U( V! h
NULL0                             unassigned           up         up(s)     
5 H1 P2 Q& R6 l. F: r% N/ dVirtual-Template1                 192.168.10.1/24      up         down      ! q) Y8 a8 e9 V4 N
[pppoe-server]
2 K$ w: m" i/ V! F# ]
' D) s, m. q; N5 X" F2、配置虚拟模板0 K- H# [! W0 X+ R) E
配置虚拟模板用来承载多种同层协议4 G/ u& ]! k6 Q% Y
[pppoe-server]int Virtual-Template 1                            #创建虚拟模板,编号为1! j) W9 d. y8 J- Z8 l; M5 [
[pppoe-server-Virtual-Template1]ppp authentication-mode chap    #PPP认证为chap
: H3 V2 n( V3 ~[pppoe-server-Virtual-Template1]remote address pool pokes       #指定使用地址池名为pokes
( c4 f( v! x3 P. g8 O6 @[pppoe-server-Virtual-Template1]ip add 192.168.10.1 24          #配置作为用户上网的网关IP8 Z8 U4 a( p8 M
[pppoe-server-Virtual-Template1]q
& x6 K. t1 \% g; O% s3 b9 W. m, \. \1 u. h5 m7 F. Q
3、创建地址池; N3 w) x. A! j0 S$ `# {9 q0 }4 ~
[pppoe-server]ip pool pokes                                            #创建地址池pokes& S- p4 O- v4 R5 S7 \0 z# d
Info: It's successful to create an IP address pool.+ {) E# a( P3 j1 K
[pppoe-server-ip-pool-pokes]gateway-list 192.168.10.1                  #配置网关地址8 f4 \( ]/ g' F5 H8 F$ k
[pppoe-server-ip-pool-pokes]network 192.168.10.0 mask 255.255.255.0    #配置给用户分配的ip网段7 H% U8 o- J, c: i
[pppoe-server-ip-pool-pokes]
( ?, n3 ^0 G( ^( y  S6 R[pppoe-server-ip-pool-pokes]excluded-ip-address 192.168.10.200 192.168.10.254    #排除地址
7 E$ b8 C7 N& u9 [/ _2 t[pppoe-server-ip-pool-pokes]lease day 8 hour 0 minute 0     #租约配置8小时; ~& y* o% V4 |( b) s
[pppoe-server-ip-pool-pokes]dns-list 114.114.114.114        #DNS; L8 `2 _% x/ m
[pppoe-server-ip-pool-pokes]dis th2 u6 h8 r% N( L
[V200R003C00]' h: }6 D; O) |0 F2 D% V( r" v9 p; Z
#0 c3 C; I# u, }9 t$ A
ip pool pokes% f4 y: O' a! G6 m4 p  @
gateway-list 192.168.10.1 $ T6 e; a0 r2 [7 I" V7 p" N
network 192.168.10.0 mask 255.255.255.0
- m# h9 J" i9 x( I9 h( W& D. }! ` excluded-ip-address 192.168.10.200 192.168.10.254
+ u$ t4 `0 e1 }/ [$ e( c1 S! R lease day 8 hour 0 minute 0 # p6 }: _  F7 h0 K
dns-list 114.114.114.1145 o% Z) Q" N  P3 |: S; ^2 e$ Z6 Y
#
3 P: T; o: j) x* Ireturn
$ G9 _6 v% k) H5 |" k  p[pppoe-server-ip-pool-pokes]: [  n* I: B7 J
+ Y8 ^( W1 D  t- `+ Q) O
4、创建PPPoE用户' ~; v8 B' n7 g: K& J
[pppoe-server]aaa$ ^6 L/ q* |# L7 m- L9 j- ]2 j
[pppoe-server-aaa]local-user user1 password cipher 1234564 o5 b3 R# G+ g8 x# t5 v8 s( d. f
Info: Add a new user.
9 _1 }4 w9 m# y6 I[pppoe-server-aaa]local-user user1 service-type ppp  e6 T' V) m' y) M% ~
[pppoe-server-aaa]dis th7 @. X! ~9 o( O* F" ^4 p
[V200R003C00]& _. h- V6 R% K' ^
#  L/ r/ n( k7 V8 m# p. M
aaa
5 M6 ]1 h8 ]3 l( Q2 c6 a4 e% l authentication-scheme default
: l) P1 R, ]/ R$ k1 W, f& s authorization-scheme default
8 Y6 C: a6 v. u' l accounting-scheme default) m4 ], l& n7 D) n0 L! O# M
domain default
6 o2 h4 c' v5 e! {  m2 {' g% u domain default_admin - Q4 L$ a# ]! S' k( A
local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$2 ]& G8 a, M2 E' w% p( b$ ~
local-user admin service-type http
) n6 n: m" [! {" |+ t local-user user1 password cipher %$%$aLq+.xS\rBJXJ}V|dJw'eZry%$%$" b; C3 L# D- j. q
local-user user1 service-type ppp
" m' g, p8 m# c% w$ n#
; n) X! b6 v. Y: hreturn' J) I; m/ S. F. `3 S! ~% X
[pppoe-server-aaa]: a, W; I$ u( g

" i. e2 q2 Q1 Y0 r: H' q5、绑定接口8 g$ A7 d: W; A% A2 z, H. K
将虚拟模板接口与物理接口绑定提供服务
; ^. x8 c3 x! m, C6 j( U& q[pppoe-server]int g0/0/0
. i+ \' i$ ~) {) [- s; B$ q[pppoe-server-GigabitEthernet0/0/0]pppoe-server bind virtual-template 1  #将虚拟模板1绑定在物理接口上& |# [& M: T6 s3 d. D# I- m
7 S- d- ?1 }3 \9 |+ K) q  \
至此,服务器端的配置基本完成,如果想对PPPoE的访问流量进行控制,还可以配置ACL。
& {5 }) Q- [* Z1 T: j' C' g' H' ?+ ]+ f" G- x, I' @
2 E& R& l; L7 i6 B6 c( J
虽然已经拨号成功,也能ping通网关192.168.10.1,但是因为没有nat所以无法ping通202.104.10.150的服务器
8 i1 }" _! k7 n, i7 N- B- p6、NAT配置. p2 \) w& D  _  \0 k0 o
[pppoe-server]acl number 2000
7 C& r- y; k1 p! L[pppoe-server-acl-basic-2000]rule permit source 192.168.10.0 0.0.0.2553 y% z* E; \$ h  N  I8 E; v4 C% r
[pppoe-server-acl-basic-2000]int g0/0/1. P) w3 H5 T- r. U% V# z3 [+ Y4 R
[pppoe-server-GigabitEthernet0/0/1]nat outbound 2000) C' e! K* g% f7 f1 q2 H
[pppoe-server-GigabitEthernet0/0/1]q
/ c& y2 e; k  _2 H& Z3 M0 `
9 h, Z' \2 h5 q( l: }2 K$ ^5 h! U说明:这里ACL的含义就是允许哪些网段可以上网,这里为192.168.10.0/24这个网段,然后调用在拨号接口下。
0 Q5 v4 o- a: O6 s- z4 c5 G& Y现在就可以ping通服务器了; p* E, L" v/ M0 C: F4 V
6 B# r- S4 \  D
您需要登录后才可以回帖 登录 | 注册

本版积分规则

返回首页|Archiver|手机版|小黑屋|易陆发现技术论坛 ( 蜀ICP备2026014127号-1 )

GMT+8, 2026-6-12 03:03 , Processed in 0.066073 second(s), 23 queries .

Powered by Discuz! X5.0

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表