?? route學(xué)習(xí).txt
字號(hào):
!
interface bri 0
ip address 192.200.10.1 255.255.255.0
encapsulation ppp
dialer map ip 192.200.10.2 name router2 572
dialer load-threshold 80
ppp multilink
dialer-group 1
ppp authentication chap
!
dialer-list 1 protocol ip permit
!
Router2:
hostname router2
user router1 password cisco
!
isdn switch-type basic-net3
!
interface bri 0
ip address 192.200.10.2 255.255.255.0
encapsulation ppp
dialer map ip 192.200.10.1 name router1 571
dialer load-threshold 80
ppp multilink
dialer-group 1
ppp authentication chap
!
dialer-list 1 protocol ip permit
!
Cisco路由器同時(shí)支持回?fù)芄δ埽覀儗⒙酚善鱎outer1作為Callback Server,Router2作為Callback Client。
與回?fù)芟嚓P(guān)命令:
任務(wù)
命令
映射協(xié)議地址和電話號(hào)碼,并在接口上使用在全局模式下定義的PPP回?fù)艿挠成漕悇e。
dialer map protocol address name hostname class classname dial-string
設(shè)置接口支持PPP回?fù)?
ppp callback accept
在全局模式下為PPP回?fù)茉O(shè)置映射類別
map-class dialer classname
通過(guò)查找注冊(cè)在dialer map里的主機(jī)名來(lái)決定回?fù)?
dialer callback-server [username]
設(shè)置接口要求PPP回?fù)?
ppp callback request
設(shè)置如下:
Router1:
hostname router1
user router2 password cisco
!
isdn switch-type basic-net3
!
interface bri 0
ip address 192.200.10.1 255.255.255.0
encapsulation ppp
dialer map ip 192.200.10.2 name router2 class s3 572
dialer load-threshold 80
ppp callback accept
ppp multilink
dialer-group 1
ppp authentication chap
!
map-class dialer s3
dialer callback-server username
dialer-list 1 protocol ip permit
!
Router2:
hostname router2
user router1 password cisco
!
isdn switch-type basic-net3
!
interface bri 0
ip address 192.200.10.2 255.255.255.0
encapsulation ppp
dialer map ip 192.200.10.1 name router1 571
dialer load-threshold 80
ppp callback request
ppp multilink
dialer-group 1
ppp authentication chap
!
dialer-list 1 protocol ip permit
!
相關(guān)調(diào)試命令:
debug dialer
debug isdn event
debug isdn q921
debug isdn q931
debug ppp authentication
debug ppp error
debug ppp negotiation
debug ppp packet
show dialer
show isdn status
舉例:執(zhí)行debug dialer命令觀察router2呼叫router1,router1回?fù)躵outer2的過(guò)程.
router1#debug dialer
router2#ping 192.200.10.1
router1#
00:03:50: %LINK-3-UPDOWN: Interface BRI0:1, changed state to up
00:03:50: BRI0:1:PPP callback Callback server starting to router2 572
00:03:50: BRI0:1: disconnecting call
00:03:50: %LINK-3-UPDOWN: Interface BRI0:1, changed state to down
00:03:50: BRI0:1: disconnecting call
00:03:50: BRI0:1: disconnecting call
00:03:51: %LINK-3-UPDOWN: Interface BRI0:2, changed state to up
00:03:52: callback to router2 already started
00:03:52: BRI0:2: disconnecting call
00:03:52: %LINK-3-UPDOWN: Interface BRI0:2, changed state to down
00:03:52: BRI0:2: disconnecting call
00:03:52: BRI0:2: disconnecting call
00:04:05: : Callback timer expired
00:04:05: BRI0:beginning callback to router2 572
00:04:05: BRI0: Attempting to dial 572
00:04:05: Freeing callback to router2 572
00:04:05: %LINK-3-UPDOWN: Interface BRI0:1, changed state to up
00:04:05: BRI0:1: No callback negotiated
00:04:05: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state to up
00:04:05: dialer Protocol up for Vi1
00:04:06: %LINEPROTO-5-UPDOWN: Line protocol on Interface BRI0:1, changed state
to up
00:04:06: %LINEPROTO-5-UPDOWN: Line protocol on Interface Virtual-Access1, chang
ed state to up
00:04:11: %ISDN-6-CONNECT: Interface BRI0:1 is now connected to 572
#router1
4. ISDN訪問(wèn)首都在線263網(wǎng)實(shí)例:
本地局部網(wǎng)地址為10.0.0.0/24,屬于保留地址,通過(guò)NAT地址翻譯功能,局域網(wǎng)用戶可以通過(guò)ISDN上263網(wǎng)訪問(wèn)Internet。263的ISDN電話號(hào)碼為2633,用戶為263,口令為263,所涉及的命令如下表:
任務(wù)
命令
指定接口通過(guò)PPP/IPCP地址協(xié)商獲得IP地址
ip address negotiated
指定內(nèi)部和外部端口
ip nat {inside | outside}
使用ppp/pap作認(rèn)證
ppp authentication pap callin
指定接口屬于撥號(hào)組1
dialer-group 1
定義撥號(hào)組1允許所有IP協(xié)議
dialer-list 1 protocol ip permit
設(shè)定撥號(hào),號(hào)碼為2633
dialer string 2633
設(shè)定登錄263的用戶名和口令
ppp pap sent-username 263 password 263
設(shè)定默認(rèn)路由
ip route 0.0.0.0 0.0.0.0 bri 0
設(shè)定符合訪問(wèn)列表2的所有源地址被翻譯為bri 0所擁有的地址
ip nat inside source list 2 interface bri 0 overload
設(shè)定訪問(wèn)列表2,允許所有協(xié)議
access-list 2 permit any
具體配置如下:
hostname Cisco2503
!
isdn switch-type basic-net3
!
ip subnet-zero
no ip domain-lookup
ip routing
!
interface Ethernet 0
ip address 10.0.0.1 255.255.255.0
ip nat inside
no shutdown
!
interface Serial 0
shutdown
no description
no ip address
!
interface Serial 1
shutdown
no description
no ip address
!
interface bri 0
ip address negotiated
ip nat outside
encapsulation ppp
ppp authentication pap callin
ppp multilink
dialer-group 1
dialer hold-queue 10
dialer string 2633
dialer idle-timeout 120
ppp pap sent-username 263 password 263
no cdp enable
no ip split-horizon
no shutdown
!
ip classless
!
! Static Routes
!
ip route 0.0.0.0 0.0.0.0 bri 0
!
! Access Control List 2
!
access-list 2 permit any
!
dialer-list 1 protocol ip permit
!
! Dynamic NAT
!
ip nat inside source list 2 interface bri 0 overload
snmp-server community public ro
!
line console 0
exec-timeout 0 0
!
line vty 0 4
!
end
5. Cisco765M通過(guò)ISDN撥號(hào)上263
由于Cisco765的設(shè)置命令與我們常用的Cisco路由器的命令不同,所以以下列舉了通過(guò)Cisco765上263訪問(wèn)Internet的具體命令行設(shè)置步驟。
>set system c765
c765> set multidestination on
c765> set switch net3
c765> set ppp multilink on
c765> cd lan
c765:LAN> set ip routing on
c765:LAN> set ip address 10.0.0.1
c765:LAN> set ip netmask 255.0.0.0
c765:LAN> set briding off
c765:LAN>cd
c765> set user remotenet
New user remotenet being created
c765:remotenet> set ip routing on
c765:remotenet> set bridging off
c765:remotenet> set ip framing none
c765:remotenet> set ppp clientname 263
c765:remotenet> set ppp password client
Enter new Password: 263
Re-Type new Password: 263
c765:remotenet> set ppp authentication out none
c765:remotenet> set ip address 0.0.0.0
c765:remotenet> set ip netmask 0.0.0.0
c765:remotenet> set ppp address negotiation local on
c765:remotenet> set ip pat on
c765:remotenet> set ip route destination 0.0.0.0/0 gateway 0.0.0.0
c765:remotenet> set number 2633
c765:remotenet> set active
命令描述如下:
任務(wù)
命令
設(shè)置路由器系統(tǒng)名稱
set system c765
允許路由器呼叫多個(gè)目的地
set multidestination on
設(shè)置ISDN交換機(jī)類型為NET3
set switch net3
允許點(diǎn)到點(diǎn)間多條通道連接實(shí)現(xiàn)負(fù)載均衡
set ppp multilink on
關(guān)掉橋接
set briding off
建立用戶預(yù)制文件用于設(shè)置撥號(hào)連接參數(shù)- 可以設(shè)置多個(gè)用戶預(yù)制文件用于相同的物理端口對(duì)應(yīng)于不同的連接。
set user remotenet
使用PPP/IPCP
set ip framing none
設(shè)置上網(wǎng)用戶帳號(hào)
set ppp clientname 263
設(shè)置上網(wǎng)口令
set ppp password client
Enter new Password: 263
Re-Type new Password: 263
不用PPP/CHAP或PAP做認(rèn)證
set ppp authentication out none
允許地址磋商
set ppp address negotiation local on
設(shè)置地址翻譯
set ip pat on
設(shè)置默認(rèn)路由
set ip route destination 0.0.0.0/0 gateway 0.0.0.0
設(shè)置ISP的電話號(hào)碼
set number 2633
激活用戶預(yù)制文件
set active
CISCO路由器配置手冊(cè)-第二章(廣域網(wǎng)協(xié)議設(shè)置PSTN)
六、PSTN
電話網(wǎng)絡(luò)(PSTN)是目前普及程度最高、成本最低的公用通訊網(wǎng)絡(luò),它在網(wǎng)絡(luò)互連中也有廣泛的應(yīng)用。電話網(wǎng)絡(luò)的應(yīng)用一般可分為兩種類型,一種是同等級(jí)別機(jī)構(gòu)之間以按需撥號(hào)(DDR)的方式實(shí)現(xiàn)互連,一種是ISP為撥號(hào)上網(wǎng)為用戶提供的遠(yuǎn)程訪問(wèn)服務(wù)的功能。
1. 遠(yuǎn)程訪問(wèn)
1.1.Access Server基本設(shè)置:
選用Cisco2511作為訪問(wèn)服務(wù)器,采用IP地址池動(dòng)態(tài)分配地址.遠(yuǎn)程工作站使用WIN95撥號(hào)網(wǎng)絡(luò)實(shí)現(xiàn)連接。
全局設(shè)置:
任務(wù)
命令
設(shè)置用戶名和密碼
username username password password
設(shè)置用戶的IP地址池
ip local pool {default | pool-name low-ip-address [high-ip-address]}
指定地址池的工作方式
ip address-pool [dhcp-proxy-client | local]
基本接口設(shè)置命令:
任務(wù)
命令
設(shè)置封裝形式為PPP
encapsulation ppp
啟動(dòng)異步口的路由功能
async default routing
設(shè)置異步口的PPP工作方式
async mode {dedicated | interactive}
設(shè)置用戶的IP地址
peer default ip address {ip-address | dhcp | pool [pool-name]}
設(shè)置IP地址與Ethernet0相同
ip unnumbered ethernet0
line撥號(hào)線設(shè)置:
任務(wù)
命令
設(shè)置modem的工作方式
modem {inout|dialin}
自動(dòng)配置modem類型
modem autoconfig discovery
設(shè)置撥號(hào)線的通訊速率
speed speed
設(shè)置通訊線路的流控方式
flowcontrol {none | software [lock] [in | out] | hardware [in | out]}
連通后自動(dòng)執(zhí)行命令
autocommand command
訪問(wèn)服務(wù)器設(shè)置如下:
Router:
hostname Router
enable secret 5 $1$EFqU$tYLJLrynNUKzE4bx6fmH//
!
interface Ethernet0
ip address 10.111.4.20 255.255.255.0
!
interface Async1
ip unnumbered Ethernet0
encapsulation ppp
keepalive 10
async mode interactive
peer default ip address pool Cisco2511-Group-142
!
ip local pool Cisco2511-Group-142 10.111.4.21 10.111.4.36
!
line con 0
exec-timeout 0 0
password cisco
!
line 1 16
modem InOut
modem autoconfigure discovery
flowcontrol hardware
!
line aux 0
transport input all
line vty 0 4
password cisco
!
end
相關(guān)調(diào)試命令:
show interface
show line
1.2. Access Server通過(guò)Tacacs服務(wù)器實(shí)現(xiàn)安全認(rèn)證:
使用一臺(tái)WINDOWS NT服務(wù)器作為Tacacs服務(wù)器,地址為10.111.4.2,運(yùn)行Cisco2511隨機(jī)帶的Easy ACS 1.0軟件實(shí)現(xiàn)用戶認(rèn)證功能.
相關(guān)設(shè)置:
任務(wù)
命令
激活A(yù)AA訪問(wèn)控制
aaa new-model
用戶登錄時(shí)默認(rèn)起用Tacacs+做AAA認(rèn)證
aaa authentication login default tacacs+
列表名為no_tacacs使用ENABLE口令做認(rèn)證
aaa authentication login no_tacacs enable
在運(yùn)行PPP的串行線上采用Tacacs+做認(rèn)證
aaa authentication ppp default tacacs+
由TACACS+服務(wù)器授權(quán)運(yùn)行EXEC
aaa authorization exec tacacs+
由TACACS+服務(wù)器授權(quán)與網(wǎng)絡(luò)相關(guān)的服務(wù)請(qǐng)求。
aaa authorization network tacacs+
為EXEC會(huì)話運(yùn)行記帳.進(jìn)程開始和結(jié)束時(shí)發(fā)通告給TACACS+服務(wù)器。
aaa accounting exec start-stop tacacs+
為與網(wǎng)絡(luò)相關(guān)的服務(wù)需求運(yùn)行記帳包括SLIP,PPP,PPP NCPs,ARAP等.在進(jìn)程開始和結(jié)束時(shí)發(fā)通告給TACACS+服務(wù)器。
aaa accounting network start-stop tacacs+
指定Tacacs服務(wù)器地址
tacacs-server host 10.111.4.2
在Tacacs+服務(wù)器和訪問(wèn)服務(wù)器設(shè)定共享的關(guān)鍵字,訪問(wèn)服務(wù)器和Tacacs+服務(wù)器使用這個(gè)關(guān)鍵字去加密口令和響應(yīng)信息。這里使用tac作為關(guān)鍵字。
tacacs-server key tac
?? 快捷鍵說(shuō)明
復(fù)制代碼
Ctrl + C
搜索代碼
Ctrl + F
全屏模式
F11
切換主題
Ctrl + Shift + D
顯示快捷鍵
?
增大字號(hào)
Ctrl + =
減小字號(hào)
Ctrl + -