1、rt1-Serial0 undo ip addressrt1-Serial0 ppp pap local-user user1 password simple bbrt1-Serial0 ip address ppp-negotiate路由器RT2的配置:rt2 local-user user1 password simple bb /配置用户列表rt2 l2tp enable /允许 VPDN功能rt2 aaa-enable /允许AAA验证rt2 aaa authentication-scheme ppp default localrt2 aaa accounting-scheme opt
2、ionalrt2 interface Serial0 rt2-Serial0 ip address 202.98.0.1 255.255.0.0rt2 -Serial0 interface serial 1rt2 -Serial1 ppp authentication-mode paprt2 -Serial1 quitrt2 l2tp-group 1 /创建 VPDN组rt2 -l2tp1 start l2tp ip 202.98.0.2 fullusername user1 rt2 -l2tp1 tunnel name lacrt2-l2tp1 tunnel authenticationrt
3、2-l2tp1 tunnel password simple asd路由器RT3的配置:rt3 local-user user1 password simple bbrt3 l2tp enablert3ip pool 1 172.31.0.2 172.31.0.10 /配置本地地址池rt3 interface Serial0 rt3 -Serial0 ip address 202.98.0.2 255.255.0.0rt3 -Serial0 quit rt3 aaa-enable rt3 aaa authentication-scheme ppp default local rt3 aaa a
4、ccounting-scheme optional rt3 -Serial0 interface Virtual-Template 1 /创建逻辑接口Virtual-Templatert3-Virtual-Template1 ip address 172.31.0.1 255.255.0.0rt3-Virtual-Template1 ppp authentication-mode paprt3 -Virtual-Template1 remote address pool 1 rt3 -Virtual-Template1 quitrt3 l2tp-group 1 rt3 -l2tp1 allow
5、 l2tp virtual-template 1 remote lac rt3 -l2tp1 tunnel name lns rt3 -l2tp1 tunnel authentication rt3 -l2tp1 tunnel password simple asd2. 下面我们来观察一下L2TP的隧道建立流程。首先在RT2和RT3上用“debugging l2tp control”命令打开控制报文调试开关,然后在RT1上ping 172.31.0.1。下面是在RT2上可以看到的有关隧道建立的调试信息:rt2 debugging l2tp controlL2TP:Put AVP Message
6、 Type: START_CONTROL_CONNECTION_REQUEST L2TP:Put AVP Protocol version: 100Put AVP Host name: lacPut AVP Vendor name: HuaWeiPut AVP Framing capability :3Put AVP Assigned Tunnel ID: 1Put AVP Receive window size: 60Put AVP Challenge : 0 0 27 81 0 0 44 6B 0 0 79 4B 0 0 15 FBTunnel 1 Create 60 seconds He
7、llo timer O Tunnel 1 Send SCCRQProc Peer control type=2, len = 117 I Tunnel 1 rcv SCCRP in state 2Tunnel 1 Resume 60 second Hello timerCheck SCCRP MSG Type 2Parse AVP Protocol version, value:Parse AVP Framing capability, value: 3Parse AVP Host name, value: lnsParse AVP Remote tunnel ID:Parse AVP Bea
8、rer capability, value:Parse AVP Receive window size:Parse AVP Challenge, Value: 0 0 27 81 0 0 44 6B 0 0 79 4B 0 0 15FBParse AVP Challenge response: ED 1E C5 D 1B C D3 29 D2 6C BB 3B 23 A4 A8 5F START_CONTROL_CONNECTION_CONNECTED /表示隧道已经成功建立起来了Put AVP Challenge response:44 FC 62 BC 45 C1 9F 1 CA 49 7
9、1 FA 12 ED 1B 56 O Tunnel 1 send SCCCN to tunnel 1Tunnel 1 Start Waiting Calls INCOMING_CALL_REQUESTPut AVP Assigned call ID:Put AVP Call serial number:Put AVP Bearer type :Put AVP Physical channel number: 0 O Call 1 send INCOMING_CALL_REQUEST.Proc Peer control type=11, len = 28 I Call 1 Recv ICRP i
10、n state 4 from Call 0Check ICRP MSG TYPE = 11Parse AVP remote call ID: INCOMING_CALL_CONNECTED /表示会话已经成功建立Put AVP Tx connect speed: 64000Put AVP Framing type :Put AVP Initial received LCP options.Put AVP Last sent LCP options.Put AVP Last received LCP options.Put AVP Proxy authen type :Put AVP Proxy
11、 authen Name : user1Put AVP Proxy authen ID :Parse AVP Proxy authenticate response:62 62Put AVP Proxy private group number :Put AVP Rx connect speed: O Call 1 send ICCN to Remote Call 1Proc Peer control len = 12Tunnel 1 Hello timer 60 second expired HELLOTunnel 1 send ctrl msg : HelloProc Peer contr
12、ol type=6, len = 20 I Tunnel 1 rcv Hello in state 4下面是在RT3上显示的调试信息:rt3 debugging l2tp controlRecv a SCCRQ or StopCCN pass to upper layerProc Peer control type=1, len = 97Tunnel 1 rcv SCCRQ in state 1 from 202.98.0.1Check SCCRQ MSG Type 1Parse AVP Protocol version:Tunnel Password in L2tp Group: asd%0
13、3:30:16: Line protocol ip on interface Virtual-Template1(Virtual-Template1:0), changed state to UPParse AVP Vendor name, value:Parse AVP Framing capability :Parse AVP Remote call number, value:Parse AVP Receive window size, value:Parse AVP Challenge, value: 00 00 27 81 00 00 44 6b 00 00 79 4b 00 00
14、15fb START_CONTROL_CONNECTION_REPLYPut AVP Bearer capability:ED 1E C5 D 1B C D3 29 D2 6C BB 3B 23 A4 A8 5F O Tunnel 1 send START_CONTROL_CONNECTION_REPLY to Tunnel 1Proc Peer control type=3, len = 42Tunnel 1 rcv SCCCN in state 3Check SCCCN MSG Type 3Parse AVP Challenge response44 FC 62 BC 45 C1 9F 1
15、 CA 49 71 FA 12 ED 1B 56Tunnel 1 Start Waiting Calls /表示隧道已经成功建立Proc Peer control type=10, len = 58Call 1 recv ICRQ in state 2 from Call 0Check ICRQ MSG Type 10Parse AVP Remote call ID 1Parse AVP Call serial number:Parse AVP Bearer type:Parse AVP Physical channel ID: INCOMING_CALL_REPLYCall 1 send I
16、NCOMING_CALL_REPLY to Remote Call 1Proc Peer control type=12, len = 158Call 1 rcv ICCN in state 5 from Remote Call 1Check ICCN MSG Type 12Parse AVP Tx connect speed:Parse AVP Framing type:Parse AVP Initial recv lcp config request: 1 4 5 DC 5 6 30 7 1F 92Parse AVP Last sent lcp config request: 1 4 5
17、DC 3 4 C0 23 5 6 E D3 7D 63Parse AVP Last received lcp config request:Parse AVP Proxy authenticate type 3.Parse AVP Proxy authenticate name:user1Parse AVP Proxy authen ID: 16170092Parse AVP Private group ID .Parse AVP (Rx)connect speed 64000另外,我们还可以在RT2和RT3上通过“display l2tp tunnel”命令来看隧道是否已经建立起来了,下面隧
18、道建立后显示的信息:rt2 display l2tp tunnelLocalID RemoteID ReName RemAddress Sessions Port 1 1 lns 202.98.0.2 1 1701 Total tunnel = 1同样,我们可以在RT2和RT3上通过“display l2tp session”命令来看会话是否建立起来,下面是会话建立后显示的信息:rt2 display l2tp session LocalID RemoteID TunnelID 1 1 1 Total session = 13. 下面我们来观察一下L2TP的隧道和会话的拆除过程。首先在RT1的
19、serial 0接口上执行“shutdown”命令,然后在RT2上可以看到下面的调试信息:rt2 debugging l2tp control %04:26:23: Interface Serial1 changed state to DOWN CALL_DISCONNECT_NOTIFYPut AVP Result code: LOSS_OF_CARRIER O Call 1 send CALL_DISCONNECT_NOTIFYClean Call Structure ID = 1 O Tunnel 1 Send StopCCN to Tunnel 1 STOP_CONTROL_CONNE
20、CTION_NOTIFICATION LOSS_OF_CARRIER 在RT3上可以看到如下的调试信息:rt3 debugging l2tp control 06:48: changed state to DOWNProc Peer control type=14, len = 38 I Call 1 recv CDN in state 9 from Remote CallCheck CDN MSG Type 14Parse AVP Result code :Parse AVP Remote call ID:Proc Peer control type=4, len = 38 I Tunnel 1 recv StopCCN in state 4Check StopCCN msg type 4Parse AVP Remote Tunnel ID:Parse AVP Result code:Reset Calls On Tunnel ID=1 Reason=0 L2T
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1