cisco路由器ppp認證方式

  一、實驗拓撲

cisco路由器ppp認證方式

  二、實驗要求:

1、要求配置ppp協議

2、分別用pap、chap認證

3、配置總部的路由器給分部的路由器分配ip地址,並且從地址池中分配,

4、pc1最終能ping銅pc2

  三、實驗步驟:

1、配置各路由器接口的ip地址 如圖---

  2、封裝ppp協議

R1(config)#interface s1/0

R1(config-if)#encapsulation ppp

R1(config-if)#clock rate 64000

R1(config-if)#ip address

R1(config-if)#no shut

R2(config)#interface s1/0

R2(config-if)#encapsulation ppp

R2(config-if)#no shut

R2(config-if)#clock rate 64000 配置DCE端時鐘頻率

3、配置IP地址池協商,並從地址池中獲取

R1(config)#interface s1/0

R1(config-if)#peer default ip address pool aaa

R1(config-if)#ip local pool aaa

R2(config)#interface s1/0

R2(config-if)#ip address negotiated

查看 s1/0接口的`地址

R2#show interface s1/0

Serial1/0 is up, line protocol is up

Hardware is M4T

Internet address is 如果獲取不到地址將接 shutdown 然後再 no shudown

MTU 1500 bytes, BW 1544 Kbit, DLY 20000 usec,

reliability 255/255, txload 1/255, rxload 1/255

Encapsulation PPP, LCP Open

Open: CDPCP, IPCP, crc 16, loopback not set

Keepalive set (10 sec)

4、啓用rip協議 並查看路由表

R1(config)#router rip

R1(config-router)#network

R1(config-router)#network

查看路由表

R1#show ip route

Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP

D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter ar

N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type

E1 - OSPF external type 1, E2 - OSPF external type 2

i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-I

ia - IS-IS inter area, * - candidate default, U - per-user s

o - ODR, P - periodic downloaded static route

Gateway of last resort is not set

C is directly connected, FastEthernet0/0

is variably subnetted, 2 subnets, 2 masks

C is directly connected, Serial1/0

C is directly connected, Serial1/0

R [120/1] via , 00:00:47, Serial1/0

R2(config)#router rip

R2(config-router)#network

R2(config-router)#network

R2(config-router)#exit

查看路由表

R2#show ip route

Codes: C - connected, S - static, R - RIP, M - mobile, B - BG

D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF in

N1 - OSPF NSSA external type 1, N2 - OSPF NSSA externa

E1 - OSPF external type 1, E2 - OSPF external type 2

i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2

ia - IS-IS inter area, * - candidate default, U - per-

o - ODR, P - periodic downloaded static route

Gateway of last resort is not set

is subnetted, 2 subnets

C is directly connected, Serial1/0

C is directly connected, Serial1/0

C is directly connected, FastEthernet0/0

  5、配置PAP認證

R1(config)#username abc password 0 123

R1(config)#interface s1/0

R1(config-if)#ppp authentication pap

R2(config)#interface s1/0

R2(config-if)#ppp pap sent

R2(config-if)#ppp pap sent-username abc password 0 123

查看show run

interface Serial1/0

ip address negotiated

encapsulation ppp

serial restart-delay 0

clockrate 64000

ppp pap sent-username abc password 0 123

  6、配置chap認證

R1(config)#username abc password 0 123 以對方的主機名作爲用戶名,密碼要和對方的路由器一致

R1(config)#interface s1/0

R1(config-if)#ppp authentication pap

R1(config-if)#exit

R1(config)#username R2 password 0 123

R1(config)#interface s1/0

R1(config-if)#encapsulation ppp

R1(config-if)#ppp authentication chap chap 認證

R2(config)#username R1 password 0 123

R2(config)#interface s1/0

R2(config-if)#encapsulation ppp

R2#debug ppp authentication

PPP authentication debugging is on 驗證chap過程