父亲节的礼物

AR151-S2设置L2TP及ACL策略路由代码

网络环境:

wan1通过PPPOE拨号,IP动态
wan2接入校园网,有固定IP,网关为:172.19.39.1,

要求:
组建VPN,使得在任何地方能够拨入VPN。
VPN账号分组,不同的账号拨入获取不同的IP。
两组VPN IP :192.168.20.0 192.168.10.0
(通过域实验失败)

现在做两组VPN隧道。默认隧道IP为192.168.10.0,通过ACL,走WAN2口(满足所有设备拨入后使图书馆能使)。
计算机名为ASUS的拨入VPN,走另外一隧道,IP为192.168.20.0,走WAN1口。

步骤:
1,设置WAN1口PPPOE
2,设置一个LAN变成WAN2口,然后设置这个WAN2口为固定IP(即我想PING的IP)
3,以上两WAN口均开通了NAT功能。
4,添加了静态路由,0.0.0.0 到WAN1下一跳。优先级1. 0.0.0.0 到WAN2下一跳,优先级60
5,在LAN口处设置开启DHCP.
6,设置静态路由 172.16.0.0 255.240.0.0 下一跳172.19.39.1 出口Gig 0/0/0 (这条是使得所有B类局域网走WAN2口,不然,从校园网PING路由WAN2的IP,会导致返回数据从WAN1口出去(即PING数据由WAN2口进,结果从WAN1口出了,导致PING不通))
7,设置静态路由202.202.0.0,222.198.0.0 掩码255.255.0.0 下一跳同6(校园网内网站IP均走WAN2)
8,暂时华为路由无法设置VPN使得IPHONE接入VPN(网上教程不靠谱。)



Login authentication


Username:
Password:
  -----------------------------------------------------------------------------

  User last login information:
  -----------------------------------------------------------------------------
  Access Type: Web
  IP-Address : 192.168.1.247
  Time       : 2016-06-12 13:40:06+00:00
  -----------------------------------------------------------------------------
<huawei>sys
Enter system view, return user view with Ctrl+Z.

//L2TP能使
[Huawei]l2tp enable

//设置地址池1
[Huawei]ip pool 1
Info: It's successful to create an IP address pool.
//网关
[Huawei-ip-pool-1]gateway-list 192.168.10.1
//网段,子网掩码
[Huawei-ip-pool-1]network 192.168.10.0 mask 255.255.255.0
[Huawei-ip-pool-1]quit

//设置地址池1
[Huawei]ip pool 2
Info: It's successful to create an IP address pool.
[Huawei-ip-pool-2]gateway-list 192.168.20.1
[Huawei-ip-pool-2]network 192.168.20.0 mask 255.255.255.0
[Huawei-ip-pool-2]quit

//设置账号
[Huawei]aaa
[Huawei-aaa]authentication-scheme lmt
Info: Create a new authentication scheme.
//设置域
[Huawei-aaa-authen-lmt]domain cqnv.com
Info: Success to create a new domain.
[Huawei-aaa-domain-cqnv.com]authentication-scheme lmt
//设置账号1@cqnv.com
[Huawei-aaa-domain-cqnv.com]local-user 1@cqnv.com password
Please configure the login password (8-128)
It is recommended that the password consist of at least 2 types of characters, including lowercase letters, 
uppercase letters, numerals and special characters.
Please enter password:
Please confirm password:
Info: Add a new user.
[Huawei-aaa]local-user 1@cqnv.com privilege level 0
Info: After you change the rights (including the password, access type, FTP directory, and level) of a local user, 
the rights of users already online do not change. The change takes effect to users who go online after the change.
[Huawei-aaa]local-user 1@cqnv.com service-type ppp
Info: After you change the rights (including the password, access type, FTP directory, and level) of a local user, 
the rights of users already online do not change. The change takes effect to users who go online after the change.
[Huawei-aaa]quit


[Huawei]aaa
[Huawei-aaa]authentication-scheme lmt
[Huawei-aaa-authen-lmt]domain cqnv.net
Info: Success to create a new domain.
[Huawei-aaa-domain-cqnv.net]authentication-scheme lmt
[Huawei-aaa-domain-cqnv.net]local-user 1@cqnv.net password
Please configure the login password (8-128)
It is recommended that the password consist of at least 2 types of characters, including lowercase letters, uppercase
 letters, numerals and special characters.
Please enter password:
Please confirm password:
Info: Add a new user.
[Huawei-aaa]local-user 1@cqnv.net privilege level 0
Info: After you change the rights (including the password, access type, FTP directory, and level) of a local user, 
the rights of users already online do not change. The change takes effect to users who go online after the change.
[Huawei-aaa]local-user 1@cqnv.net service-type ppp
Info: After you change the rights (including the password, access type, FTP directory, and level) of a local user, 
the rights of users already online do not change. The change takes effect to users who go online after the change.
[Huawei-aaa]quit

//设置模板1
[Huawei]interface Virtual-Template1
[Huawei-Virtual-Template1]ppp authentication-mode chap domain cqnv.com
[Huawei-Virtual-Template1]remote address pool 1
//设置VPN的DNS,以便拨入用户可以用域名访问网站
[Huawei-Virtual-Template1]ppp ipcp dns 61.128.128.68 8.8.8.8
[Huawei-Virtual-Template1]ip address 192.168.10.1 255.255.255.0
[Huawei-Virtual-Template1]quit

//设置模板2
[Huawei]interface Virtual-Template2
[Huawei-Virtual-Template2]ppp authentication-mode chap domain cqnv.net
[Huawei-Virtual-Template2]remote address pool 2
[Huawei-Virtual-Template2]ppp ipcp dns 202.202.96.33 61.128.128.68
[Huawei-Virtual-Template2]ip address 192.168.20.1 255.255.255.0
[Huawei-Virtual-Template2]quit

//设置组1
[Huawei]l2tp-group 1
[Huawei-l2tp1]undo tunnel authentication
 Warning: Tunnel authentication was disabled. There are security risks.
[Huawei-l2tp1]allow l2tp virtual-template 1
[Huawei-l2tp1]quit

//设置组2
[Huawei]l2tp-group 2
[Huawei-l2tp2]undo tunnel authentication
 Warning: Tunnel authentication was disabled. There are security risks.
//这里remote ABCD默认是可选命令,但超过两条隧道就必须设置。若用PC拨号,"ASUS"必须是PC(或路由器)的计算机名。
[Huawei-l2tp2]allow l2tp virtual-template 2 remote ASUS
[Huawei-l2tp2]quit






//配置ACL
[Huawei]acl 3001
//反掩码为0.0.0.255,表示IP段为192.168.10.1-192.168.10.255
[Huawei-acl-adv-3001]rule 5 permit ip source 192.168.10.0 0.0.0.255

//配置流分类,流分类命令为redirect:
[Huawei-acl-adv-3001]traffic classifier redirect operator or
[Huawei-classifier-redirect]if-match acl 3001


//配置流行为,命令为redirect
[Huawei-classifier-redirect]traffic behavior redirect
//重定向下一跳为172.19.39.1(这里的设置优先级大于静态路由优先级。)
[Huawei-behavior-redirect]redirect ip-nexthop 172.19.39.1

//配置流策略,命令为reditect,将流分类redirect和流行为redirect关联
[Huawei-behavior-redirect]traffic policy redirect
[Huawei-trafficpolicy-redirect]classifier redirect behavior redirect



//应用流策略将流策略reditect应用到virtual-template1 (这个是VPN的虚拟接口,应用之。)
[Huawei-trafficpolicy-redirect]interface virtual-template1
[Huawei-virtual-template1]traffic-policy  redirect inbound
[Huawei-virtual-template1]quit

//更改WEB管理界面端口,以便腾出443 和80端口
[Huawei]http secure-server port 1080
[Huawei]http server port 8080

[Huawei]quit
//查看路由配置
</huawei><huawei>disp cu 


</huawei>

五岁生日

IMG_1286

老爸大手笔,送给了米仔50部豪车,加上已有的13部,目前有63部风火轮了:

IMG_1237

好朋友:笑笑和米仔

照片传上来,才分析这两家伙穿的衣服花形一样:

IMG_1139 IMG_1141