miércoles, 19 de octubre de 2011

Encapsulacion PPP con autenticacion PAP&CHAP...y SSH



Merida#sh running-config
!
hostname Merida
!
username Maracaibo password 0 ciscochap
username Margarita password 0 ciscopap
username martin privilege 15 password 0 ciscossh
!
ip domain-name ppp.con.ve
!
ip ssh time-out 15
!
interface Serial1/0
description Conexion serial al Margarita
ip address 192.168.0.1 255.255.255.252
encapsulation ppp
serial restart-delay 0
ppp authentication pap
ppp pap sent-username Merida password 0 ciscopap
!
interface Serial1/1
description Conexion serial a Maracaibo
ip address 192.168.1.1 255.255.255.252
encapsulation ppp
serial restart-delay 0
clock rate 56000
ppp authentication chap
!
line vty 0 4
login local
transport input ssh
line vty 5 15
login local
transport input ssh


***configuracion SSH
Merida(config)#ip domain-name ppp.con.ve
Merida(config)#crypto key generate rsa
The name for the keys will be: Merida.ppp.con.ve
Choose the size of the key modulus in the range of 360 to 2048 for your
General Purpose Keys. Choosing a key modulus greater than 512 may take
a few minutes.

How many bits in the modulus [512]: 1024
Generating RSA keys ...
[OK]
Merida(config)#ip ssh time-out 15
Merida(config)#ip ssh authentication-retries 3
Merida(config)#username martin privilege 15 password ciscossh
Merida(config)#line vty 0 15
Merida(config-line)#transport input ssh
Merida(config-line)#login local

____________________________________________________________________________

Margarita#sh running-config
!
hostname Margarita
!
username Merida password 0 ciscopap
!
interface Serial1/0
description Conexion serial a Merida
ip address 192.168.0.2 255.255.255.252
encapsulation ppp
serial restart-delay 0
clock rate 64000
ppp authentication pap
ppp pap sent-username Margarita password 0 ciscopap

____________________________________________________________________________

Maracaibo#sh running-config
!
hostname Maracaibo
!
username Merida password 0 ciscochap
!
interface Serial1/0
description Conexion serial a Merida
ip address 192.168.1.2 255.255.255.252
encapsulation ppp
serial restart-delay 0
ppp authentication chap
!
___________________________________________________________________________

Podemos ver los eventos de autenticacion PAP y CHAP con el momando debug ppp authentication
Type escape sequence to abort.

Merida#debug ppp authentication
00:29:07: Se1/1 CHAP: O CHALLENGE id 14 len 27 from "Merida"
00:29:07: Se1/1 CHAP: I CHALLENGE id 3 len 30 from "Maracaibo"
00:29:07: Se1/1 CHAP: O RESPONSE id 3 len 27 from "Merida"
00:29:07: Se1/1 CHAP: I RESPONSE id 14 len 30 from "Maracaibo"
00:29:07: Se1/1 CHAP: I SUCCESS id 3 len 4
00:29:07: Se1/1 CHAP: O SUCCESS id 14 len 4
Merida#
Merida#
00:30:21: Se1/0 PAP: I AUTH-REQ id 3 len 23 from "Margarita"
00:30:21: Se1/0 PAP: O AUTH-REQ id 2 len 20 from "Merida"
00:30:21: Se1/0 PAP: Authenticating peer Margarita
00:30:21: Se1/0 PAP: O AUTH-ACK id 3 len 5
00:30:21: Se1/0 PAP: I AUTH-ACK id 2 len 5
Merida#ping 192.168.1.2
Sending 5, 100-byte ICMP Echos to 192.168.1.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/8/16 ms
Merida#ping 192.168.0.2

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.0.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/6/8 ms

2 comentarios:

Anónimo dijo...

You really make it seem so easy with your presentation but
I find this topic to be really something that I think I would never understand.

It seems too complicated and extremely broad for me.
I am looking forward for your next post, I'll try to get the hang of it!

Also visit my web-site: military auto shipping locations

Anónimo dijo...

Pretty nice post. I just stumbled upon your weblog
and wanted to say that I've truly loved browsing your blog posts. In any case I'll
be subscribing on your rss feed and I am hoping you write once more very soon!



Feel free to visit my page; bet angel