发布时间: 2018-03-02 14:14:39
组网需求
如图1所示,RouterA的Serial1/0/0和RouterB的Serial1/0/0相连。
用户希望RouterA对RouterB进行可靠的认证,而RouterB不需要对RouterA进行认证。
配置思路如下:
1.用户希望进行可靠的认证,对安全的要求较高,所以需要配置CHAP认证且认证方需要配置用户名。
2.用户希望进行单向认证,所以仅需要配置RouterA作为CHAP认证的认证方,RouterB作为CHAP认证的被认证方。
操作步骤
配置RouterA
# 配置接口Serial1/0/0的IP地址及封装的链路层协议为PPP。
<Huawei>system-view
[Huawei] sysname RouterA
[RouterA] interface serial 1/0/0
[RouterA-Serial1/0/0]link-protocol ppp
[RouterA-Serial1/0/0]ip address 10.10.10.9 30
[RouterA-Serial1/0/0]quit
# 配置本地用户及域。
[RouterA] aaa
[RouterA-aaa]authentication-scheme system_a
[RouterA-aaa-authen-system_a]authentication-mode local
[RouterA-aaa-authen-system_a]quit
[RouterA-aaa] domain system
[RouterA-aaa-domain-system]authentication-scheme system_a
[RouterA-aaa-domain-system]quit
[RouterA-aaa]local-user user2@system password
Please configure the login password (8-128)
It is recommended that the password consist of at least 2 types of characters, including lowercase letters, uppercase letters, numerals and special characters.
Please enter password:
Please confirm password:
Info: Add a new user.
Warning: The new user supports all access modes. The management user access modes such as Telnet,SSH, FTP, HTTP, and Terminal have security risks. You are advi sed to configure the required access modes only.
[RouterA-aaa]local-user user2@system service-type ppp
[RouterA-aaa] quit
# 配置PPP认证方式为CHAP、认证域为system。
[RouterA] interfaceserial 1/0/0
[RouterA-Serial1/0/0]ppp authentication-mode chap domain system
# 重启接口,保证配置生效。
[RouterA-Serial1/0/0]shutdown
[RouterA-Serial1/0/0]undo shutdown
配置RouterB
# 配置接口Serial1/0/0的IP地址及封装的链路层协议为PPP。
<Huawei>system-view
[Huawei] sysname RouterB
[RouterB] interface serial 1/0/0
[RouterB-Serial1/0/0] link-protocol ppp
[RouterB-Serial1/0/0]ip address 10.10.10.10 30
# 配置本地被RouterA以CHAP方式认证时RouterB发送的CHAP用户名和密码。
[RouterB-Serial1/0/0]ppp chap user user2@system
[RouterB-Serial1/0/0]ppp chap password cipher huawei123
# 重启接口,保证配置生效。
[RouterB-Serial1/0/0]shutdown
[RouterB-Serial1/0/0]undo shutdown
验证配置结果
# 通过命令display interface serial 1/0/0查看接口的配置信息,接口的物理层和链路层的状态都是Up状态,并且PPP的LCP和IPCP都是opened状态,说明链路的PPP协商已经成功,并且RouterA和RouterB可以互相Ping通对方。
上一篇: {华为HCIE-RS}DHCP中继