某企业由于业务需要办理不少手机,套餐中都赠送了免费的宽带,想把这部分资源充分利用起来,无奈出口路由器的WAN口不够,为解决这个问题,可以采用另外购置WAN口扩展卡或另外的路由器,本次介绍低成本利用单臂路由方法配置子接口来解决这个问题。
拓扑说明:
AR1出口路由器,上联交换机,营运商的线路也分别连接在交换机上,内网PC DHCP方式自动获取IP。
ISP1 配置PPPOE SERVER
sysname ISP1
ip pool pppoe
gateway-list 20.1.1.2
network 20.1.1.0 mask 255.255.255.252
//配置PPPOE地址池
aaa
local-user pu1 password cipher aaa
local-user pu1 service-type ppp
//配置远程账户密码
interface Virtual-Template1
ppp authentication-mode chap
remote address pool pppoe
ip address 20.1.1.2 255.255.255.252
//配置虚拟模板
interface GigabitEthernet0/0/0
pppoe-server bind Virtual-Template 1
//接口PPPOE SEVER绑定模板
ISP2配置说明同上
sysname ISP2
ip pool pppoe
gateway-list 30.1.1.2
network 30.1.1.0 mask 255.255.255.252
aaa
local-user pu2 password cipher aaa
local-user pu2 service-type ppp
interface Virtual-Template1
ppp authentication-mode chap
remote address pool pppoe
ip address 30.1.1.2 255.255.255.252
interface GigabitEthernet0/0/0
pppoe-server bind Virtual-Template 1
交换机配置
sysname SW
VLAN batch 20 30
//划分VLAN
interface GigabitEthernet0/0/1
port link-type access
port default vlan 20
interface GigabitEthernet0/0/2
port link-type access
port default vlan 30
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 20 30
//1,2口分别连接两条外线,3口放行两个VLAN
AR路由器配置
sysname AR1
dhcp enable
interface GigabitEthernet0/0/1
ip address 192.168.1.1 255.255.255.0
dhcp select interface
//配置内网接口及DHCP方式
acl number 2000
rule 5 permit source 192.168.1.0 0.0.0.255
//ACL 匹配内网IP段
dialer-rule
dialer-rule 10 ip permit
//配置拨号规则
interface Dialer1
link-protocol ppp
ppp chap user pu1
ppp chap password simple aaa
mtu 1492
ip address ppp-negotiate
dialer user pu1
dialer bundle 2
dialer-group 10
nat outbound 2000
interface Dialer2
link-protocol ppp
ppp chap user pu2
ppp chap password simple aaa
mtu 1492
ip address ppp-negotiate
dialer user pu2
dialer bundle 3
dialer-group 10
nat outbound 2000
//创建两个Dialer口分别对应两个外线,采用PPPOE方式并进行NAT转换
interface GigabitEthernet0/0/0.20
pppoe-client dial-bundle-number 2
dot1q termination vid 20
arp broadcast enable
interface GigabitEthernet0/0/0.30
pppoe-client dial-bundle-number 3
dot1q termination vid 30
arp broadcast enable
//在子接口下终结对应VLAN,绑定对应Dialer口
ip route-static 0.0.0.0 0.0.0.0 Dialer1
ip route-static 0.0.0.0 0.0.0.0 Dialer2
//配置默认路由
配置完成后测试,所有线路正常。