易陆发现互联网技术论坛

 找回密码
 开始注册
查看: 1114|回复: 1
收起左侧

华为路由器:PPPOE配置模拟实验及NAT配置

[复制链接]
发表于 2022-3-16 09:39:13 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有账号?开始注册

x
实验环境' }" H5 k2 x! Y' p0 {2 _1 l' N3 }  j

4 ~2 Z$ h: V4 ]! n$ s9 ^" i: opppoe-client上面的接口信息
7 j) P7 I% T) d  ~, U$ ]" g! R) C4 K6 G! k
[AR1]dis ip interface brief
7 Y( Q+ {: P: L, q4 N6 d*down: administratively down3 t. h3 G8 o- W$ |9 M# r8 i
^down: standby
6 D5 u( `' R, w5 ]4 W- v(l): loopback
' B1 I! |! n- v. Y(s): spoofing& {) n# U! W5 a2 S
The number of interface that is UP in Physical is 22 s  b. j5 J5 r, @
The number of interface that is DOWN in Physical is 16 {% p5 z9 k# k+ E7 a7 @' v
The number of interface that is UP in Protocol is 1
% c4 S# p' @7 r. U9 v2 Q# Y7 oThe number of interface that is DOWN in Protocol is 2  |0 r1 ]2 Y; I% t" x

$ g9 `( l  q+ {" F5 ^* K( `Interface                         IP Address/Mask      Physical   Protocol  
4 b' r6 S0 I* r! RGigabitEthernet0/0/0              unassigned           up         down      ! E/ Z1 ^! C; R1 {) x7 ?2 P# R
GigabitEthernet0/0/1              192.168.1.254/24     down       down      / \! @9 C: L1 ~8 o7 {$ w: O
NULL0                             unassigned           up         up(s)     
0 Z, W6 ]$ U# s7 E5 ?$ _6 B+ N8 h: `; d

4 |* h+ p% h, I( _7 r配置了基于接口的DHCP
8 T" [6 l# J+ n: o$ |1 l) I$ ]# S3 I+ W7 U' e
interface GigabitEthernet0/0/13 A5 j7 M0 \. P+ x" [' S
ip address 192.168.1.254 255.255.255.0
! g  \- }, j( |1 b dhcp select interface
. x2 _3 l# d( C2 L" d4 s/ \ dhcp server dns-list 8.8.8.8 ; h! C* [8 o; u2 N6 r
dhcp server domain-name pokes.com
# l5 Y" Q9 c  g# S7 j
( O3 }1 i4 x5 x2 E+ k) y注意事项:AR1、AR2的物理接口g0/0/0不配地址.* ~( K# Q( l! E! W
& T5 f9 o  N3 s$ _7 s. o
一、pppoe-server的配置
) D! n# u$ B& S1 t& A* R1、pppoe-server 配置地址池
% J3 R4 G7 w7 O' C- n6 B* z- z[pppoe-server]ip pool pokes            #创建名为pokes的地址池,名字可以随便起,后面要调用: g. |  Q9 ^9 k+ ^" u
Info: It's successful to create an IP address pool.1 Y3 @2 {" l# I+ V/ n3 \5 A
[pppoe-server-ip-pool-pokes]network 10.1.12.0 mask 24   #地址池为10.1.12.0/24. Q# l" A  p! L" z8 t( K
[pppoe-server-ip-pool-pokes]dis th
! K# S6 `4 M: L[V200R003C00]
, I2 J/ R- D$ y& u8 \#
) ?1 I& f7 z. Aip pool pokes
) J/ m6 z! F% g network 10.1.12.0 mask 255.255.255.0
4 @7 R. C( c0 Z: a- I' q#
, h) N* v, P  Q+ nreturn
) c* a. `. P) ?2 L[pppoe-server-ip-pool-pokes]q9 e4 C8 ^6 w1 x4 u" w

% m& A4 v7 g8 B7 y3 y+ X2、配置虚拟口关联地址池
5 f$ y7 ^/ \5 l配置虚拟口关联地址池,即创建Virtual-Template 1模版。
/ W- s/ i3 g5 g8 h- z" W+ n( t3 L: o! M  Y* r
[pppoe-server]interface Virtual-Template 1    #创建虚拟接口1
" T: @0 D: [( P8 S1 @9 I+ |[pppoe-server-Virtual-Template1]ip add 10.1.12.2 24                   #虚拟接口1的地址* Q) W; i8 ^# x+ n
[pppoe-server-Virtual-Template1]ppp authentication-mode chap   #认证类型" D3 ]9 o7 V: D# T( c9 ^
[pppoe-server-Virtual-Template1]remote address pool pokes      #客户端的地址池pokes! D3 z8 M; ?- r, I$ ]8 D' Z
[pppoe-server-Virtual-Template1]dis th* M! G/ A/ U3 ^8 C+ q; r3 b
interface Virtual-Template19 V( E" |5 c$ Y5 F% T* l6 v1 m. v
ppp authentication-mode chap 5 o; {) f; _, ^6 x! E$ h
remote address pool pokes; T8 b0 Z$ [# d+ I% t# e1 q+ ~
ip address 10.1.12.2 255.255.255.0
4 F& ]. e& i. n
# Y* O" M: N8 v[pppoe-server]int g0/0/0        3 e9 a4 q* n& ]4 ~5 Q" }9 w0 k& O6 w
[pppoe-server-GigabitEthernet0/0/0]pppoe-server bind virtual-template 1   #将虚拟接口1关联到g0/0/0接口, W/ X/ ^9 t6 W( b" T" d
[pppoe-server-GigabitEthernet0/0/0]dis th
  c! t8 K4 K4 q6 k; R  n[V200R003C00]3 j) n0 O2 W3 `6 s9 R6 x
#( ?) q8 T! I1 e1 ]0 Y5 ]
interface GigabitEthernet0/0/0, K4 b* [) M" F( H+ ]4 L
pppoe-server bind Virtual-Template 1
  ]/ h" L  J5 d5 M, {#
8 A; c8 ~1 Y0 E# r' sreturn
* v$ Y: f% s* k; m  N( o[pppoe-server-GigabitEthernet0/0/0]6 L* ?3 ~1 z# o2 r& w" D

7 a) T1 l% K0 E3 z3、创建pppoe拨号的账号, C  y! i% A0 a1 \5 F+ G2 A
按理我们应该创建pppoe拨号的账号。5 K/ o# b; y, i, P
这里为了演示拨号失败,我们这里先不新建账号,后面再新建。* G/ Z. _0 P9 J! W) k% g( p  y$ v

# \$ m; H/ E& S7 ~7 `二、pppoe-client的配置
" v  @% A3 \' {% U; a& `[pppoe-client]dialer-rule   , |5 W0 |- G0 z' v
[pppoe-client-dialer-rule]dialer-rule 1 ?, U( L* k6 L, p* T
  acl   Permit or deny based on access-list   
; N" }; O- V( j. V# i  ip    Ip
. n+ m+ W, Y5 b" [. |; d: J; Q7 X  ipv6  Ipv6        # \% ?- K" F+ w- E% g( l! D
[pppoe-client-dialer-rule]dialer-rule 1 ip permit   #创建拨号规则,允许ip流量触发拨号( M: `. Q, i0 M- Z, C' Y

& f$ ?1 |( `# [5 c4 R2 z' \[pppoe-client]interface Dialer 1
- L8 [, U7 I% I: A9 E6 sJul 15 2021 18:55:22-08:00 pppoe-client %%01IFPDT/4/IF_STATE(l)[0]:Interface Dia1 l+ V6 f- x4 b- s8 a8 Z
ler1 has turned into UP state.
# _2 T: q0 v5 b0 T5 x[pppoe-client-Dialer1]ip add       
$ B9 k/ e+ A2 N, E$ |# i[pppoe-client-Dialer1]ip address ppp       
6 v4 W4 Y6 }1 _: e[pppoe-client-Dialer1]ip address ppp-negotiate  #地址采用ppp协商
. W3 e% o! `' c" w1 u7 H
- l0 z# w: O7 T1 n% f' {[pppoe-client]interface Dialer 1                #创建接口拨号组1
& h" M2 ?" L' [  e, A0 ?. U% M[pppoe-client-Dialer1]ip address ppp-negotiate  #ip地址采用ppp协商# a) a  Z1 {6 @. f/ U; _3 [$ h+ g
[pppoe-client-Dialer1]dialer user zhprny        #此用户不用于认证,是标识作用以及和dialer绑定) a. K4 _8 L/ A
[pppoe-client-Dialer1]dialer bundle 1           #设备通过Dialer bundle将物理接口与拨号接口关联起来。( i6 Y  o( l7 X
[pppoe-client-Dialer1]dialer-group 1             #放到一个拨号访问组1中
9 V% V" t' \; [& l" _1 i* A/ o[pppoe-client-Dialer1]ppp chap user pokes        #指定dialer1接口的编号,拨号账号
- m% a0 A' T$ e+ _& ][pppoe-client-Dialer1]ppp chap password 123456   #拨号的密码
; c( W) a' m2 f8 z4 h
7 L$ O3 A! i  {1 x# o, u
$ p# G7 S2 g) c$ `' e: F% w4 ^- s5 B[pppoe-client-Dialer1]dis th$ A" k8 ?3 X8 \, D
[V200R003C00]
* F; y- H) J) b1 ]# T! `#
3 B* K' @! }7 einterface Dialer1
1 B# |0 D  P0 A( k# U) ? link-protocol ppp* I, \4 D8 J! E: D# m5 G8 N
ppp chap user pokes/ W6 I' {: A  g) L' `9 O
ppp chap password cipher %$%$I/!'WCyd<7p[~8;,>51L,$sl%$%$* T1 {& d9 c0 o  M) g' d
ip address ppp-negotiate
, H- Z# B2 ~( Y dialer user zhprny8 q, ~  @+ E# Z! x: Z
dialer bundle 1
% h) s  q1 L. \; f1 J dialer-group 1$ K9 o6 e9 z  b- P# f
0 L# [" _9 @* K2 J/ g7 U$ E8 s) D) L
[pppoe-client-GigabitEthernet0/0/0]
: f, W. L' C- S; t* A; T& P) e6 `8 c1 VJul 15 2021 19:07:54-08:00 pppoe-client %%01IFNET/4/LINK_STATE(l)[0]:The line pr9 x/ b, h* R4 ~! _! l- H8 z+ g- E
otocol PPP on the interface Dialer1:0 has entered the UP state.  #PPP已进入启动状态
; C  {* n4 y. |9 p: G. c" s& h, F8 |" y[pppoe-client-GigabitEthernet0/0/0]
+ f; X, E7 M' X0 O: }Jul 15 2021 19:07:54-08:00 pppoe-client %%01IFNET/4/LINK_STATE(l)[1]:The line pr& T- L: _8 y8 f8 n0 o
otocol PPP on the interface Dialer1:0 has entered the DOWN state. #PPP已进入关闭状态9 G! K% V, S) A/ t& w
: `0 s- h% H( e0 g
#不停的循环。。。。
# j# n, B8 |7 `( X4 ^6 q$ D$ E( @8 W* c  |5 I
0 x' c5 M. Q  `$ e: p6 o9 y
#原因是没有认证成功,因为我们在PPPOE-server上面还没有创建认证用户和密码
  x! }5 h. Y/ ?- L5 X& v) L
- s8 G: `7 {1 E3 X三、pppoe服务器上新建认证用户* a; g( R7 w: h1 t
我们到服务器上直接新建认证用户:/ u! S. ]" N; |5 G: w/ H4 L
- ?$ l; G: Y; O, x6 s
[pppoe-server]aaa
1 r& x" B" T( D7 N. J8 U/ [[pppoe-server-aaa]local-user pokes password cipher 123456
/ `# [2 L% w3 j$ E. [- q& ~, jInfo: Add a new user.
7 G6 z* K: S% e1 \% t' y2 Y[pppoe-server-aaa]local-user pokes service-type ppp    #类型为ppp- W* w  F" ]* v/ i  Q9 H
2 ^  e3 y) }4 Z) \; @
- f1 b- g% z$ _; ?& E( c5 A
四、客户端验证结果
% {' E- M. q  j8 @/ v& ]6 |1、认证成功信息  c) {6 D  K, J% x8 O5 r
然后客户端就会出现认证成功的提示:: K( r' _/ k* s6 W2 W

. C+ a$ C) h( B+ W% v[pppoe-client-GigabitEthernet0/0/0]
- g* [( N2 P: X3 j) g% v4 l3 N. t' V) w" \Jul 15 2021 19:09:23-08:00 pppoe-client %%01IFNET/4/LINK_STATE(l)[10]:The line p
" i* U( a1 l, h1 A& Orotocol PPP on the interface Dialer1:0 has entered the UP state.
! B5 G8 A% t: _& Y+ U[pppoe-client-GigabitEthernet0/0/0]
4 b, L7 T2 z  B' W; \Jul 15 2021 19:09:23-08:00 pppoe-client %%01IFNET/4/LINK_STATE(l)[11]:The line p
% d# ?. Z6 L+ T3 S( [* w# o' irotocol PPP IPCP on the interface Dialer1:0 has entered the UP state.
" g( O, R/ K" k$ Y& B: t- P[pppoe-client-GigabitEthernet0/0/0]q1 v  ?1 H$ Q! ?2 T0 A
[pppoe-client]dis ip in b
4 n. F# I! c: v& a  P*down: administratively down
! s, B, E1 G- c9 \^down: standby
- ?7 ^/ Z' J6 r; [(l): loopback0 }  G) @- r- R9 [8 b7 }" P5 P. _
(s): spoofing
1 r5 q/ {/ z$ d1 n; X1 eThe number of interface that is UP in Physical is 4
1 v7 J& w" m7 n+ s$ Y9 @The number of interface that is DOWN in Physical is 0% M! o* O& n. ]
The number of interface that is UP in Protocol is 3" L! q# o2 ?! g& B: m
The number of interface that is DOWN in Protocol is 1
4 S6 e" U; A9 W; H2 G+ O/ Y
7 n2 m, M% P3 ^Interface                         IP Address/Mask      Physical   Protocol  
" c2 D, e- ^7 R$ t: {5 s3 lDialer1                           10.1.12.254/32       up         up(s)     #拿到了PPPOE服务器上的地址
5 s+ z8 J7 G9 q/ XGigabitEthernet0/0/0              unassigned           up         down      
$ D8 V* l0 B1 W) {1 aGigabitEthernet0/0/1              192.168.1.254/24     up         up        
2 a! V+ _# m- X' q: X8 ^6 l2 HNULL0                             unassigned           up         up(s)
+ |7 s% d3 h: j+ ?7 I% }  N) C
; ?/ ^; G% l  Y' ]" E; F
/ Z' V8 y- [5 s! h' R7 C; k2、pppoe-server 信息* d4 w  i0 U" G% l
<pppoe-server>dis interface Virtual-Template 1( U- e4 j2 Q) v; x8 E* v( m7 {
Virtual-Template1 current state : UP8 ^1 c0 _/ w& M' g
Line protocol current state : UP% D5 o& @- J" D
Last line protocol up time : 2021-07-15 19:09:22 UTC-08:00
, ?  C) Q; I$ z4 q  N; A! yDescription:HUAWEI, AR Series, Virtual-Template1 Interface0 F/ l7 A& J) L& q
Route Port,The Maximum Transmit Unit is 1492, Hold timer is 10(sec). x% X/ {$ I; I& h$ N5 W* Z( s
Internet Address is 10.1.12.2/24
5 W& J( w9 p8 O* n, _3 jLink layer protocol is PPP
3 z- K9 y8 I2 f" eLCP initial" H' \* R. b) F
Physical is None  T. j$ J4 o0 C
Current system time: 2021-07-15 20:27:28-08:00
3 z& T: e: K9 ^. K    Last 300 seconds input rate 0 bits/sec, 0 packets/sec
4 t/ a" H3 t! t5 e    Last 300 seconds output rate 0 bits/sec, 0 packets/sec; p1 K( H7 q" }5 I0 Z- k
    Realtime 0 seconds input rate 0 bits/sec, 0 packets/sec
7 R$ s$ D& m6 c3 |5 p( d* y/ h& N    Realtime 0 seconds output rate 0 bits/sec, 0 packets/sec, C* F4 j4 \/ M1 M" k# M
    Input: 0 bytes4 w' f* ~/ s2 j; J# ~4 h. U, q
    Output:0 bytes  c7 C3 o; F6 Q
    Input bandwidth utilization  :    0%/ n- o2 \) V! U) c& ~6 Q0 c3 e4 ], E
    Output bandwidth utilization :    0%
4 W9 i2 C/ [- x) j& V# W8 w! h$ j! z. ]1 X
<pppoe-server>2 a1 {9 b/ o# Z1 B
5 O2 l; Q4 P$ R& _# ?
& J! l- |/ w$ e% b% l' F$ }
3、pppoe-client信息
) c% U* R, A! S$ V<pppoe-client>dis interface Dialer 1+ z& W7 J) h. Z2 c% X) r
Dialer1 current state : UP
! D. f, t' \9 L$ }Line protocol current state : UP (spoofing)/ y; q$ T+ @4 g3 o, P' R2 ~* \
Description:HUAWEI, AR Series, Dialer1 Interface
, }% h9 l. ^  i* BRoute Port,The Maximum Transmit Unit is 1500, Hold timer is 10(sec): G# ]0 s: k% L) W2 h( k
Internet Address is negotiated, 10.1.12.254/32
# M, j! {) E# Y$ b- }* RLink layer protocol is PPP
+ M: E- S! {7 `! VLCP initial9 C) \* j0 r/ r2 S: \/ D8 L' h7 v6 \
Physical is Dialer4 w, x$ m/ F$ l- e- I7 x: g1 O
Current system time: 2021-07-15 20:23:56-08:009 A1 l+ k% _3 X5 O7 w3 J9 ^: m
    Last 300 seconds input rate 0 bits/sec, 0 packets/sec" s$ |$ x$ N% _
    Last 300 seconds output rate 0 bits/sec, 0 packets/sec/ \% E0 h( H/ p' c2 R
    Realtime 0 seconds input rate 0 bits/sec, 0 packets/sec
5 f& u1 n% t% W- z1 m    Realtime 0 seconds output rate 0 bits/sec, 0 packets/sec
& i/ X) F7 o2 ]. g- u    Input: 0 bytes
4 L% h8 z& Y, k. o6 g    Output:0 bytes  t" }3 s$ T/ |" l
    Input bandwidth utilization  :    0%
  R0 y* q# n2 M" |    Output bandwidth utilization :    0%
' j! C! I& G9 \3 w4 UBound to Dialer1:0:7 l% i) D* n# N# i6 _2 u& `
Dialer1:0 current state : UP ,) w' c- L$ t6 F, R/ ~& r9 u
Line protocol current state : UP$ L9 I: m2 D4 C( C- \

& }9 u4 ^  j9 M" M# _! r4 tLink layer protocol is PPP; o1 `' O. z3 ]9 i& D2 ~' F- Q4 Y
LCP opened, IPCP opened
9 U0 ?. w( }6 o2 z" j* m1 _0 z' APackets statistics:/ b$ P+ q# u( H! i' ^0 H
  Input packets:0,  0 bytes
" i9 H1 N1 L: O8 f8 L  Output packets:4, 336 bytes2 X- t$ p, n2 G1 L+ [
  FCS error packets:08 d2 y+ o/ {, r- M
  Address error packets:0
+ `. }# i5 {0 C+ x$ \  Control field control error packets:0; Z% A( s. q" L
# {. n, W% K' Q) o% }3 }

: Y$ `* m% x# e/ A1 ^4 s9 k<pppoe-client>4 R  S' b/ v; S4 y; J3 O; P
+ d# F9 Y0 m* b6 u
五、NAT的配置
- j4 O' F( a$ ?3 c8 ?- T) \$ y: m用PC2直接ping 10.1.12.254是可以通的。10.1.12.254是AR1的g0/0/0口获取到的地址,其实就是我们常说的WAN口地址。
& R8 O/ h6 {1 E: D4 C" ~, A3 o; x# R3 U- j9 ?
PC2>ping 10.1.12.254; s# T" w% m" V: p- ^9 u+ F/ y' l% n
, Z$ I; n" ?8 `9 X7 A2 v8 r
Ping 10.1.12.254: 32 data bytes, Press Ctrl_C to break
8 k* g. S+ M4 x' {+ U$ N8 zFrom 10.1.12.254: bytes=32 seq=1 ttl=255 time=63 ms9 A" K# P7 f  w* S6 S9 A
From 10.1.12.254: bytes=32 seq=2 ttl=255 time=31 ms* `# D8 x0 r" \' U3 O8 P7 E8 q+ P
From 10.1.12.254: bytes=32 seq=3 ttl=255 time=47 ms9 z3 k0 ]& u1 s3 P1 g
From 10.1.12.254: bytes=32 seq=4 ttl=255 time=31 ms
/ L9 c/ P5 x$ PFrom 10.1.12.254: bytes=32 seq=5 ttl=255 time=47 ms: m. A4 J1 }- w, W6 E' Q
2 D' F) g4 Z! B0 F; I8 n
--- 10.1.12.254 ping statistics ---
  W7 G& K4 v8 T- m  5 packet(s) transmitted
4 N+ j/ }7 ?1 }0 N: h; x  5 packet(s) received
* q5 S! j/ E% y' w0 Y+ p0 r  0.00% packet loss% ^7 S' a0 S2 x- g9 C
  round-trip min/avg/max = 31/43/63 ms" X2 ?& s0 t- _

% Q" @. d/ a& b9 s5 lPC2>ping 10.1.12.2
; O$ q3 G9 P% V5 ^$ Q: \3 y7 e5 k0 J  y) F0 ~, `- F
Ping 10.1.12.2: 32 data bytes, Press Ctrl_C to break+ j/ k% L5 f! X8 B) c
Request timeout!" @3 ~& ]# d: B
Request timeout!% S) V1 o- ~2 Q' l9 k& ]0 I5 G
Request timeout!
& }0 P  l8 v( n" H1 A8 SRequest timeout!
' j; f* y( ]2 Y8 aRequest timeout!, T5 v2 T1 d8 g: r4 F

; q7 v- v5 N8 u$ f--- 10.1.12.2 ping statistics ---4 p2 i9 _, w6 f  d
  5 packet(s) transmitted
* Q6 C4 N( r2 V9 \" g6 r7 |  0 packet(s) received
8 W6 W7 L2 h' f5 f$ j% y  100.00% packet loss; e% {0 y8 V' W- j  T) f7 k( g0 l& Y
#但是无法ping通10.1.12.2% s) H7 j/ q3 a/ |; ?0 n4 |
  F1 [& z7 o2 u2 s
& h& _% f! e& O$ ]4 @
无法ping通10.1.12.2的原因是:我们没有做NAT .接下来我们在pppoe-client上面做NAT5 d5 d6 p1 V6 ]. K7 @& x& @2 _

  A) K8 w# n, I7 e. o1、这里配置规则2000$ t: C# P1 ]. x
[pppoe-client]acl number 2000       
7 F7 X( s. U% k[pppoe-client-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
3 n( `3 c, @' u  K
9 k! x2 |& A: {. k1 n! q+ n2、将规则2000绑定到接口
: D/ T6 D7 J1 |5 Y* B如下接口信息,需要注意的是pppoe的接口是Dialer1,并不是GigabitEthernet0/0/0口。我们必须将规则绑定在Dialer1口,最容易犯错的就是直接绑定在g0/0/0口。) O% ?5 |/ U0 q; Z# r% K

/ }5 _6 A5 _; @0 Y* a[pppoe-client]dis ip int b
6 f: y9 R: E+ `' t+ O/ o. k% i) q*down: administratively down
3 \' h: m/ f2 G  l- B" k^down: standby
& ^3 i! G4 f/ b8 [(l): loopback
9 H3 T, B' V3 [$ A: ]: s(s): spoofing
* q' i7 ^+ K) F  E; RThe number of interface that is UP in Physical is 4
; [2 X2 t3 x3 {* iThe number of interface that is DOWN in Physical is 0
# C" a8 |# T% JThe number of interface that is UP in Protocol is 31 V$ d/ b. F' ~8 d+ G3 z- y
The number of interface that is DOWN in Protocol is 1* [; a. k9 Y; U$ x4 G: h$ x( M
8 O& s( C5 h/ V( r
Interface                         IP Address/Mask      Physical   Protocol  
+ d6 j- W5 O8 l. d  x6 fDialer1                           10.1.12.254/32       up         up(s)     & ~' w2 }& z8 v9 I$ l; n: J5 X
GigabitEthernet0/0/0              unassigned           up         down      
- D( D1 D+ Y$ V; kGigabitEthernet0/0/1              192.168.1.254/24     up         up        
, n; N6 g# N) P' N* D' `: r) ENULL0                             unassigned           up         up(s)     3 X3 y7 _  n9 G2 g+ v
[pppoe-client]6 R! E" u0 c! P+ U6 q
' }$ y4 H2 w& w4 _9 s6 b: [! ^
[pppoe-client]int Dialer 1       
& v9 v% }& o3 d2 H) p7 K* }[pppoe-client-Dialer1]nat outbound 2000
( o' d$ e2 C0 _4 R[pppoe-client-Dialer1]dis th
+ q# s1 G0 Y  J8 s[V200R003C00]
  a( V& g/ \0 ^1 E#! f; P4 [8 y; |# w4 M* Z0 h0 Y
interface Dialer1
; V; X% G7 X  ^( p/ X) _2 A. Y5 U link-protocol ppp
- H4 N, e, p& [% A  x ppp chap user pokes
- m4 y5 L" `' o- f7 V ppp chap password cipher %$%$I/!'WCyd<7p[~8;,>51L,$sl%$%$8 I1 F4 C" q$ G$ j
ip address ppp-negotiate
2 L; W7 A, Q1 M- B, M6 Q dialer user zhprny
1 j+ w+ I1 V* g& x3 Q dialer bundle 1! B% u9 T( m# y: |% j" [
dialer-group 1
3 I4 {* v% {3 h$ \ nat outbound 2000/ Y. J* ~% H# }; `) {
#2 K: i0 a3 q7 B8 Q0 c- v' j! x1 n
return& }, m6 f7 |' x
[pppoe-client-Dialer1]. M; }; n+ F4 h' c& G" O1 _) {( v
4 c, u  w6 Z+ s% v% _
接下来我们就可以ping通10.1.12.2 了。- T, F# q& E6 S4 B: C& j+ h
, b8 B$ O3 E4 M( I
PC2>ping 10.1.12.2  S) M" e. L; w, B# t2 n9 V

# |! g" K- Q; dPing 10.1.12.2: 32 data bytes, Press Ctrl_C to break8 a$ h, [) u: m) c
From 10.1.12.2: bytes=32 seq=1 ttl=254 time=31 ms
$ G: g$ Y: ]' O! D. yFrom 10.1.12.2: bytes=32 seq=2 ttl=254 time=32 ms
; X7 k9 f+ V8 t. z4 t0 B& p' ]From 10.1.12.2: bytes=32 seq=3 ttl=254 time=46 ms
6 h4 D0 G/ \4 U* {. H" A, k! yFrom 10.1.12.2: bytes=32 seq=4 ttl=254 time=32 ms
! _; Z; t8 ~% ?7 t5 F! dFrom 10.1.12.2: bytes=32 seq=5 ttl=254 time=31 ms, S3 i# r" [7 n

5 F) Y% u. {. G$ ?+ m: F--- 10.1.12.2 ping statistics ---7 T+ K/ O2 B3 p7 K8 L. r
  5 packet(s) transmitted
. o. m; z* C, d  5 packet(s) received6 Z% s2 r9 X9 l3 Y1 c6 v: B2 A' t
  0.00% packet loss
0 W2 c% I, z5 S7 ~! m' \/ N  round-trip min/avg/max = 31/34/46 ms
( s6 C9 }! [' X6 d3 o& Q, V5 J
$ k' Q5 V3 y9 }+ p' c9 U3 P0 J1 I& G5 A. q
 楼主| 发表于 2022-3-17 09:27:15 | 显示全部楼层
华为路由器:PPPoE实验
6 y& C, Y8 Q! O3 M8 E. `& T/ aPPPoE协议是基于C/S架构的一种网络拨号协议。分为客户端和服务器两部分,它的建立过程分为discovery和session两个阶段。本次实验的目标:掌握PPPoE拨号技术;
( T( X' q0 f' _* |! J实验拓扑:( F0 U* M3 i. Y" G& E3 D' W
9 l3 w& {8 g6 x( h
本实验结合虚拟机进行:+ F! k+ A3 B) {# L6 a6 F/ t
首先,必须在虚拟机的网络配置中加以设置,我新建了VM6,去掉了DHCP的钩。这个时候会在你的网卡界面多出来一个虚拟的VM6的网卡。但是当你打开ensp时,会出现检测不到VM6的情况,这个时候你重启一下电脑,就可以了。
5 x; L. u7 L, _, k, D
2 I6 [5 E& _% R: n' G* NCloud1的设置如下图:
+ W2 Q  H" @! N& Y0 N; j0 z( @' O
6 O' y! Y: @- j/ C& c4 I1、基本的IP配置3 n2 i( W. _0 I+ M; B
[pppoe-server]dis ip in b3 K1 I& E9 g- E; ?$ f$ U
*down: administratively down
: `" R4 X2 Z' x. [^down: standby/ p" t5 y6 b' @, K( v
(l): loopback
: z5 G6 S8 u. W$ P5 |0 K6 G6 F; m& k(s): spoofing
0 j! v1 m0 b5 D! D& fThe number of interface that is UP in Physical is 4
/ s# r& z  j) r( bThe number of interface that is DOWN in Physical is 1, [( A% M) S; c* a. }. g0 }
The number of interface that is UP in Protocol is 24 @( Y% m* S6 n# d
The number of interface that is DOWN in Protocol is 3
4 N" I+ E5 w2 R9 p  l1 N& ?Interface                         IP Address/Mask      Physical   Protocol  2 X( Q. y0 |4 D5 O& X  K
GigabitEthernet0/0/0              unassigned           up         down      : R8 z3 k& ]6 Q4 U
GigabitEthernet0/0/1              202.104.10.1/24      up         up        
8 {  o$ J2 ~+ k0 b% |- WGigabitEthernet0/0/2              unassigned           down       down      
) s; p' @: k) q* S, l$ J; aNULL0                             unassigned           up         up(s)     
6 _3 G" f. o8 R# fVirtual-Template1                 192.168.10.1/24      up         down      
; r; O6 r: M6 }3 }; @[pppoe-server]
' b; P7 T) r1 ^. L# u4 E
1 x& T* D1 `' m/ V( n( S2 ?2、配置虚拟模板
6 m/ q) `) E) _" M配置虚拟模板用来承载多种同层协议
" Y* U: J; T% W2 P[pppoe-server]int Virtual-Template 1                            #创建虚拟模板,编号为1
  ~" u$ M  k, f! A# R[pppoe-server-Virtual-Template1]ppp authentication-mode chap    #PPP认证为chap
1 r" q. o* z1 [( ^1 G[pppoe-server-Virtual-Template1]remote address pool pokes       #指定使用地址池名为pokes, u7 _1 X' `, K2 c& @
[pppoe-server-Virtual-Template1]ip add 192.168.10.1 24          #配置作为用户上网的网关IP
( J8 R8 K# V9 S[pppoe-server-Virtual-Template1]q/ }# v: Q* W* }; N8 e$ `8 ]2 D4 D

4 }0 F1 \  t8 Z. i3、创建地址池2 h8 q) V9 m! O% o
[pppoe-server]ip pool pokes                                            #创建地址池pokes
! r9 C% \0 v# Z1 C& vInfo: It's successful to create an IP address pool.1 ^* l) `, Z* S! s
[pppoe-server-ip-pool-pokes]gateway-list 192.168.10.1                  #配置网关地址, Z( f4 K% f0 c( b
[pppoe-server-ip-pool-pokes]network 192.168.10.0 mask 255.255.255.0    #配置给用户分配的ip网段8 M, {* C0 K9 M/ g0 |  ?
[pppoe-server-ip-pool-pokes]3 l$ x8 }8 t: F7 d, S
[pppoe-server-ip-pool-pokes]excluded-ip-address 192.168.10.200 192.168.10.254    #排除地址6 F# E5 A% G: z$ E% s# h
[pppoe-server-ip-pool-pokes]lease day 8 hour 0 minute 0     #租约配置8小时
) T- H) H! O' G3 n[pppoe-server-ip-pool-pokes]dns-list 114.114.114.114        #DNS2 W$ B# _6 N+ r% ~5 d$ R; k8 Q" j
[pppoe-server-ip-pool-pokes]dis th% Y2 n) k! G1 |8 [3 y4 d6 a
[V200R003C00]
/ O2 z( C8 q2 \% q#
8 d& D, o4 J2 \' a9 lip pool pokes
- f3 U0 F2 i1 q- ~* Z% z gateway-list 192.168.10.1 8 @- I6 o. I& s& Y( T0 m; k
network 192.168.10.0 mask 255.255.255.0 % i6 ]3 J# b" v
excluded-ip-address 192.168.10.200 192.168.10.254 - X$ J9 ?3 i0 _$ [* c
lease day 8 hour 0 minute 0 $ x* Z0 N9 H' f' b# t% l
dns-list 114.114.114.114
# `3 R5 V5 K  I$ c- D2 h#
' a* ~/ i0 o' ^! ?/ wreturn: |/ q+ E: J; K$ e: W
[pppoe-server-ip-pool-pokes]
! X& A5 i. G' p3 `" f+ e. C/ O; w% F0 s" k/ j  P3 N; z) j& {
4、创建PPPoE用户
: {, P! ]3 E* L1 k2 X7 U: G1 |5 |[pppoe-server]aaa7 R  I2 Y% r5 H0 v  s' S
[pppoe-server-aaa]local-user user1 password cipher 123456" [8 X4 N% S1 k; V9 W2 Z
Info: Add a new user.$ t) I% k9 U! Z  @* h4 a
[pppoe-server-aaa]local-user user1 service-type ppp; O: i  j" U9 j+ O! b
[pppoe-server-aaa]dis th
# ?5 {5 k8 @; Y4 K9 ^  s[V200R003C00]
% _3 p/ G6 s- V#
/ I. M- N" T$ O/ z+ T9 c% paaa
5 I8 @) W& Z$ s authentication-scheme default8 e4 x  V9 S9 l& M& _# D- O3 l& g
authorization-scheme default
8 W3 y& Q2 e4 x accounting-scheme default0 \9 ]" j- ?/ n
domain default
$ C  U4 ~* S' B domain default_admin . b2 Z: v: W9 Y9 o' ~4 r' d
local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$8 Q; L; \: }. V6 y6 |& o7 y7 @
local-user admin service-type http
7 n* ]4 Q! L% z0 E' N0 j local-user user1 password cipher %$%$aLq+.xS\rBJXJ}V|dJw'eZry%$%$
/ q# d9 {0 v6 E! r, n local-user user1 service-type ppp1 L. `6 O  G1 X- q& f( ?! E' B
#
! `  I& G4 n+ e# m# E  }7 A; N* Preturn
! o; C$ v- ?4 n: n; Y[pppoe-server-aaa]. _6 O" h. i3 v- E$ T" g
$ i: ^* s& d$ g  T
5、绑定接口; t/ t- m- E. V! ~2 n
将虚拟模板接口与物理接口绑定提供服务: Q# |  C4 R, h! W
[pppoe-server]int g0/0/0
0 O- Q# I6 B. U( e[pppoe-server-GigabitEthernet0/0/0]pppoe-server bind virtual-template 1  #将虚拟模板1绑定在物理接口上
5 R( `1 }  x8 F) z, j& S$ W6 z' s
. O9 a; Y# f$ C* |" _$ m2 F3 w至此,服务器端的配置基本完成,如果想对PPPoE的访问流量进行控制,还可以配置ACL。
5 O) T3 ~5 V1 ?
) K- \* y1 b# g- E% I( |8 z: S% A+ g2 R0 _5 E7 w
虽然已经拨号成功,也能ping通网关192.168.10.1,但是因为没有nat所以无法ping通202.104.10.150的服务器
$ `8 E8 h, |0 H$ o4 X( y6、NAT配置7 c8 [# ]2 |2 X$ b# I8 o. v
[pppoe-server]acl number 2000( J" F  c! J+ t7 T
[pppoe-server-acl-basic-2000]rule permit source 192.168.10.0 0.0.0.2558 u# B. ^, y! W) X/ _& M) w0 v
[pppoe-server-acl-basic-2000]int g0/0/1
  f0 a" j. ?% V/ m" L4 V[pppoe-server-GigabitEthernet0/0/1]nat outbound 2000
" t: B: d' ~1 W9 ?( V[pppoe-server-GigabitEthernet0/0/1]q
/ E5 p: z/ K* \" i. z& o& L+ T$ M
说明:这里ACL的含义就是允许哪些网段可以上网,这里为192.168.10.0/24这个网段,然后调用在拨号接口下。, W/ [7 K6 v/ k( ?. ]
现在就可以ping通服务器了
5 u8 g: E- n4 C4 |! ~  }/ F3 \( K6 G0 v5 M+ S8 a
您需要登录后才可以回帖 登录 | 开始注册

本版积分规则

关闭

站长推荐上一条 /4 下一条

北京云银创陇科技有限公司以云计算运维,代码开发

QQ|返回首页|Archiver|小黑屋|易陆发现技术论坛 点击这里给我发消息

GMT+8, 2026-4-9 09:13 , Processed in 0.047405 second(s), 22 queries .

Powered by Discuz! X3.4 Licensed

© 2012-2025 Discuz! Team.

快速回复 返回顶部 返回列表