华为的可以打800-810-0504 l2tp隧道技术至少要两台路由器,两边参数设置一致,应该可以的,我发一个华为跟思科联的案例,
; H/ f: n1 N6 Q- o, M0 ?7 \: l电脑ADSL不能上网,最好的方法换一台电脑看能不能上,也许是电信的问题
# t/ r4 R4 `% u: B9 ]& s. j2 G6 Q! Y5 ?3 ~, F0 G
+ l. G) x3 V# M
[Quidway]dis curr4 P9 B! |; A# `
#& i) J4 N! j5 C3 V1 u
sysname Quidway
9 [0 S" O: k Z9 o" H+ z#
\( b, ^3 m2 p, P l2tp enable
' ^# a( T- w6 e9 k( s" N2 i#5 S( Z3 f+ B' { ]
info-center console channel 14 p0 X5 b- {' B, u
#
) Y! o2 a5 g9 D" y8 ` dvpn service enable3 _0 j0 |; n+ t' b2 m* g
#
- y/ ^1 r& s9 q! q3 ? firewall packet-filter enable
9 {6 Y1 K' V5 m7 \+ h, N$ E firewall packet-filter default permit
1 U3 H2 x* k% h3 Q/ y#
% X0 V8 H4 X# k5 E8 y0 ^ insulate
, S4 J7 ^0 ?9 w: L! h* ?( a) j$ b#
8 T0 h. X% G- i firewall statistic system enable
% X+ ~8 B- H1 V4 X) L1 [, J& }6 S K#: C4 }) Q6 W: i! o. W
radius scheme system
0 \( ]/ X5 k8 Z: K#1 \/ O; C* j4 a: C+ w2 J* B0 }# I
domain system
% y: l0 L: `; j- D0 Xdomain aaagg.130vpdn.tj
: Y. k" |. g& r% x. W% C ip pool 2 10.0.0.101 10.0.0.2005 l( j. k8 x0 ^/ f
#7 N% ~! p5 n9 f: F7 n
local-user 1116 ]8 q! D* S# L
password simple 1113 k/ y& V- R- v: r
service-type ppp
, `8 k2 o( S0 |0 ^, A- x2 b2 nlocal-user 2222 V! e+ `# Y; y, j6 y" |
password cipher 3L94)(N%&:/Q=^Q`MAF4<1!!
; `5 [& A! s& Y* _: e service-type ppp' \# ^2 d& v, ~- x l
local-user admin
8 b. [$ u2 L7 K password cipher TCR7"#YZD5*.D:=;`8<.WA!!$ N' O5 ?6 N8 S- M, e* J
service-type telnet
6 Y8 q0 f, a4 `% r0 ~8 A: @ level 31 d" c3 f! u0 [+ o/ a9 n5 l" O
local-user wzggc001
& w, O8 } `+ g' q0 Y5 H password simple wzggc001 P5 z& X0 L0 ?! l7 R
service-type ppp
+ k; K! R/ q2 \* _( s9 v: Clocal-user wzhp
$ v; l+ d" j+ C1 i) b1 F password cipher C!!V0_a@T-CQ=^Q`MAF4<1!!
; a7 C: ^5 u+ ~+ u3 Z3 L! X9 m8 S' J% W service-type ssh8 o: ~* V* g' C4 A1 a: R9 N3 Q
level 36 V5 @1 V2 ?% _& v N* _; y. G, k
#( V5 g0 d+ n j+ T! s4 i
interface Virtual-Template1( t2 l( P v7 Z7 e; ?( i
ppp authentication-mode pap2 _; H; c7 y% y1 N" z& b3 C
ip address 10.0.0.100 255.255.255.0
0 M* ~1 v3 d" o, t remote address pool 2
! F5 j+ f Y/ ]5 V#. J* p8 Q2 d) N5 R- u
interface Aux0
7 V' O3 l6 {* M2 O H7 o4 t: t async mode flow! D! m- h9 l7 u7 T, Q: U! K
#
6 }# z$ J- r7 M/ W1 j* _interface Ethernet0/0- Y* |6 x3 r% h1 o
ip address 192.168.1.1 255.255.255.0
3 S( M! d5 l/ W+ U- ^#; Y" p& T; m) M/ Z8 \+ R, Q, g: o
interface Ethernet0/1
1 C: L) Y$ U5 c& J" C, E#
- f$ H& M% f" T4 Vinterface Ethernet0/2
. s* G1 a) _# ]% P#
" D( e2 I. X# T S4 c! F2 {5 O% tinterface Ethernet0/3
1 ~0 c! N. c8 g0 u& V7 y! `" J9 h#
/ Y& c4 L- K' e1 tinterface Ethernet1/0
5 f* a& s) z0 q( C3 U# O$ r ip address 21x.9x.1x.7x 255.255.255.248
1 \3 Y2 l* o a4 k3 S# Z- J" }! s7 y1 G#
$ n* L& X3 |0 C& D+ D6 Z5 f1 Ninterface Ethernet1/12 h. V7 L4 e7 a) B! M
#7 S0 w/ t& d7 A9 G0 x
interface Ethernet1/2/ b1 K; e; z' P* z$ T0 d
#
" H2 p- q3 s! `, V9 A7 ninterface Tunnel1
9 E0 _# @- Y% e5 m: }; N: a, d#7 W4 c1 Z0 D: V
interface NULL09 @# A7 |0 M, `, M! |, `5 G
#
1 x+ E4 M2 _ g% L/ ?& F [firewall zone local! q# [4 A# R- I5 `- V
set priority 100
* Z; [5 j; ^5 m m$ d7 \#
5 X1 G5 C$ \+ ?3 W8 ~: bfirewall zone trust
E5 C7 N/ t" ] add interface Ethernet0/02 |( r& ^, s! M- m
set priority 85
. m' ? X4 u0 k5 c8 Y1 l#
- s0 c8 T2 ]3 u5 ~& L+ Pfirewall zone untrust
' H ]8 `3 z3 g% c/ O# l6 P! _* \ add interface Ethernet1/0 h' t) e& }0 I% E0 N
add interface Virtual-Template1
4 I# ]; q6 U+ Y( Q/ ^ set priority 56 W5 b, @) R2 I. ?" i J; o2 a
#/ \ z/ o/ |; \# p6 j/ T
firewall zone DMZ
/ _$ A; W1 \, O5 ] set priority 508 M& m' h' U& ^) E+ N7 _! C
#& E, B+ S+ t$ ]( c4 O. @0 s
firewall interzone local trust ]0 @: t; H6 _; g. b( U
#
# S1 l/ K; b& ~0 l# U, L1 mfirewall interzone local untrust
: N& k* c+ D6 A# u4 M( d6 {3 r2 j6 H#
$ H9 F. B- @9 H/ P H7 M, X) ]: @firewall interzone local DMZ
* v) v6 x, F% f7 C) R" x#
- {1 _6 Q8 t N' k# Y. Yfirewall interzone trust untrust
/ Q4 W7 x% e) _+ Q9 Z0 s#% u9 s0 a: M# M" B+ E
firewall interzone trust DMZ
+ a/ g. D0 d) Q& L3 I* f' Q; e& U#3 h4 D7 m- W9 D& q; F
firewall interzone DMZ untrust; y8 ]" Z( q- b+ ?: B
#
; s: B9 @# S( G; k4 J" C" sl2tp-group 1' n: w' _/ x( D4 Z: L/ B6 q3 k
allow l2tp virtual-template 1
4 W6 F$ K( B+ p6 b a tunnel password simple cdma20008 k3 T( e6 @) @ V6 m
#6 W5 r: [" A6 F0 F- M1 H% _4 i
undo dhcp enable( l/ a; n$ }2 B1 f/ F4 J* m
#- z) M9 G1 v/ v8 F' q* D* t2 c" Q4 Y
ip route-static 0.0.0.0 0.0.0.0 21x.9x.1x.7x preference 60
/ i' f5 ]. F* I7 u#
; p+ g2 m' q* V snmp-agent: _1 n: z9 L9 V/ O1 A0 I
snmp-agent local-engineid 000007DB7F000001000010EC+ o; X& ^/ i D n- B/ ~
snmp-agent sys-info version v3 F. U8 @# U" c) V" \
#, f8 Y1 ~$ b! l1 X5 U: t% X1 x
ssh user wzhp authentication-type all- G) B2 s" U: [# h
ssh user wzhp service-type stelnet
% y* w: {* N, t+ s1 Y8 V* O#
, c8 Q- Q! u/ p1 T7 g g: |) a/ p& Auser-interface con 0( _- N, U! r" A& p& N8 r
user-interface aux 0 ~- j0 N4 ?) j5 [2 n' p6 E
user-interface vty 0 4' O) _/ R/ `: U8 W, U. O
user privilege level 3
0 @8 Y4 h+ q8 F# p set authentication password cipher TCR7"#YZD5*.D:=;`8<.WA!!
8 I, U& D9 [$ G. f+ U#
7 X! n3 h! Y: P' C5 t7 wreturn; t7 P* `/ z) O0 ^- A2 S
[Quidway] |