學生按照神碼的配置手冊和實驗項目手冊做l2tp,結果又麼有成。還是信任自己,不信任神碼手冊,繼續總結。。
一、什麼是l2tp
l2tp(Layer 2 Tunneling Protocol第二層隧道協議)
L2TP是一種虛擬專用網絡協議,已成爲IETF有關二層隧道協議的工業標準。L2TP將PPP(Point-to-Point Protocol)幀封裝後,L2TP使用的是UDP封裝,端口號1701,可通過IP,X.25,幀中繼或ATM等網絡進行傳送。該協議是一種工業標準的Internet隧道協議,功能大致和PPTP協議類似,比如同樣可以對網絡數據流進行加密。不過也有不同之處,比如PPTP要求網絡爲IP網絡,L2TP要求面向數據包的點對點連接;PPTP使用單一隧道,L2TP使用多隧道;L2TP提供包頭壓縮、隧道驗證,而PPTP不支持。
二、l2tp的一些名詞解釋
三、具體實驗
實驗環境中,有兩臺路由器,R1模擬LAC,R2模擬LNS,目的是爲了分支機構和總部之間進行l2tp的通信。192.168.0.0網段爲分支機構內網,192.168.1.0網段模擬internet,192.168.2.0模擬總部內網。172.16.1.0網段爲l2tp隧道利用。
實驗完成後R1的配置文件。
R1_config#
!version 1.3.3H
service timestamps log date
service timestamps debug date
no service password-encryption
!
hostname R1
!
gbsc group default
!
aaa authentication ppp default local ;
!
username 123 password 0 123
!
interface Virtual-tunnel0 ;
ip address 172.16.1.2 255.255.255.0
no ip directed-broadcast
ppp chap hostname 123
ppp chap password 0 123
peer default ip address 172.16.1.1 ;
!
interface FastEthernet0/0
ip address 192.168.0.1 255.255.255.0
no ip directed-broadcast
ip nat inside
!
interface FastEthernet0/3
ip address 192.168.1.1 255.255.255.0
no ip directed-broadcast
ip nat outside
!
interface Serial0/1
no ip address
no ip directed-broadcast
!
interface Serial0/2
no ip address
no ip directed-broadcast
!
interface Async0/0
no ip address
no ip directed-broadcast
!
ip route 192.168.2.0 255.255.255.0 Virtual-tunnel0 ;
!
ip access-list standard 999
permit any
!
vpdn enable
!
vpdn-group 0
request-dialin ;
no domain
protocol l2tp ;
local-name R1 ;
initiate-to ip 192.168.1.2 priority 1 ;
!
!
ip nat inside source list 999 interface FastEthernet0/3 ;
!
實驗完成後R2的配置文件。
R2_config#show running-config
正在收集配置...
當前配置:
!
!version 1.3.3H
service timestamps log date
service timestamps debug date
no service password-encryption
!
hostname R2
!
gbsc group default
!
ip local pool 000 172.16.1.50 50 ;
!
aaa authentication ppp default local ;
username 123 password 0 123
!
interface Virtual-template0
ip address 172.16.1.1 255.255.255.0
no ip directed-broadcast
ppp authentication chap ;
ppp chap hostname 123
ppp chap password 0 123
peer default ip address 172.16.1.2 ;
!
interface FastEthernet0/0
ip address 192.168.2.1 255.255.255.0
no ip directed-broadcast
ip nat inside
!
interface FastEthernet0/3
ip address 192.168.1.2 255.255.255.0
no ip directed-broadcast
ip nat outside
!
interface Serial0/1
no ip address
no ip directed-broadcast
!
interface Serial0/2
no ip address
no ip directed-broadcast
!
interface Async0/0
no ip address
no ip directed-broadcast
!
ip route 192.168.0.0 255.255.255.0 Virtual-access0 ;
!
!
ip access-list standard 999
permit any
!
!
!
vpdn enable
!
vpdn-group 0
accept-dialin ;
port Virtual-template0 ;
protocol l2tp ;
local-name default ;
terminate-from R1 ;
!
ip nat inside source list 999 interface FastEthernet0/3 ;
!
R1:顯示虛擬接口
R1_config#show interface virtual-tunnel 0
Virtual-tunnel0 is up, line protocol is up ;
Hardware is Unknown device
MTU 1500 bytes, BW 100000 kbit, DLY 10000 usec
Interface address is 172.16.1.2/24
Encapsulation PPP, loopback not set
Keepalive set(10 sec)
LCP Opened
CHAP Opened, Message: ' Welcome to Digital China Router'
IPCP Opened
local IP address: 172.16.1.2 remote IP address: 172.16.1.1 ;
顯示路由表項
R1_config#show ip route
Codes: C - connected, S - static, R - RIP, B - BGP, BC - BGP connected
D - BEIGRP, DEX - external BEIGRP, O - OSPF, OIA - OSPF inter area
ON1 - OSPF NSSA external type 1, ON2 - OSPF NSSA external type 2
OE1 - OSPF external type 1, OE2 - OSPF external type 2
DHCP - DHCP type, L1 - IS-IS level-1, L2 - IS-IS level-2
VRF ID: 0
C 172.16.1.0/24 is directly connected, Virtual-tunnel0 ;
C 172.16.1.1/32 is directly connected, Virtual-tunnel0
C 192.168.0.0/24 is directly connected, FastEthernet0/0
C 192.168.1.0/24 is directly connected, FastEthernet0/3
S 192.168.2.0/24 is directly connected, Virtual-tunnel0 ;
R2:
R2_config# show interface virtual-access 0
Virtual-access0 is up, line protocol is up ;
Hardware is Virtual access interface
MTU 1500 bytes, BW 100000 kbit, DLY 10000 usec
Interface address is 172.16.1.1/24
Encapsulation PPP, loopback not set
Keepalive set(10 sec)
LCP Opened
CHAP Opened, Message: 'Request timeout'
IPCP Opened
local IP address: 172.16.1.1 remote IP address: 172.16.1.2 ;
R2_config#show ip route
Codes: C - connected, S - static, R - RIP, B - BGP, BC - BGP connected
D - BEIGRP, DEX - external BEIGRP, O - OSPF, OIA - OSPF inter area
ON1 - OSPF NSSA external type 1, ON2 - OSPF NSSA external type 2
OE1 - OSPF external type 1, OE2 - OSPF external type 2
DHCP - DHCP type, L1 - IS-IS level-1, L2 - IS-IS level-2
VRF ID: 0
C 172.16.1.0/24 is directly connected, Virtual-access0 ;
C 172.16.1.2/32 is directly connected, Virtual-access0
S 192.168.0.0/24 is directly connected, Virtual-access0 ;
C 192.168.1.0/24 is directly connected, FastEthernet0/3
C 192.168.2.0/24 is directly connected, FastEthernet0/0
未完待續。。。。。。。。。。。