Tampilkan postingan dengan label WAN. Tampilkan semua postingan
Tampilkan postingan dengan label WAN. Tampilkan semua postingan

Selasa, 25 Oktober 2011

PPP Principle

Components of PPP :
→ Datagram encapsulation method : define the method of encapsulating multi-protocol datagram
→ Link Control Protocol : define method of establishing, configuring, and testing data link conn.
→ Network Control Protocol : define a set of protocol for establishing connection and negotiating parameters for different network-layer protocols.

* | Protocol (2B) | Information | Padding (optional) |
\____________/
Max receive unit (MRU) [default: 1500 bytes]
0x0021 : IP datagram + padding (optional)
0xc021 : LCP + padding (optional)
0x8021 : IP control protocol (IPCP) + padding (optional)

| Flag | Address | Control | PPP frame | FCS | Flag |
01111110 11111111 00000011 * 16bits 01111110
\____HDLC standard___________/ \___follow HDLC standard__/

Messages Used by LCP Negotiation
→ Configure-Request : the beginning of link-layer parameter negotiation of the two ends
→ Configure-Ack : if the values of negotiated parameters are acceptable
→ Configure-Nak : if the values of negotiated parameters are not acceptable
→ Configure-Reject : if the values of negotiated parameters can not be identified
→ Terminate-Request : asks to close connection. 2 * 3 s. if not receive TA, forced close connection
→ Terminate-Ack : acknowledge terminate request from the peer.
→ Echo-Request : checks the status of link [on VRP every 10 s]
→ Echo-Reply : telling to the peer that the link is normal.

[Success] LCP negotiation : RTA sends CR to RTB. RTB sends CA. If CA is not received 10 * 3 s CR.
[Unsuccessful] : RTA sends CR. RTB sends CN. RTA re-sends modified CR. max 5 CR
[Unidentified] : RTA sends CR. RTB can not identify so returns CJ. RTA re-sends deleted CR params.

<photo>

Principle of PAP Authentication Mode → 2 way
RTA [Authenticator] –––––––––––––––– RTB [Authenticated]
RTB – Authenticate-Request (user name + password) → Authenticator.
RTA – Authenticate-Ack/Authenticate-Nak → RTB.

Principle of CHAP Authentication Mode → 3 way
RTA [Authenticator] –––––––––––––––– RTB [Authenticated]
→ RTA send CHALLENGE. RTB encrypt MD5 { identifier+password+challenge }=16-byte digest. RTB sends RESPONSE packet (CHAP user name & digest) to authenticator. A Success/Failure?→ B

Network Control Protocol
NCP has same mechanism (CR,CA,CN,CJ) like LCP but it doesn't invoke LCP.
→ NCP static configuration
→ NCP dynamic configuration : CR (use 0.0.0.0 address) → CN with IP → CR → CA → CR2 → CA

HDLC Protocol


High-level Data Link Control : bit based line protocol that run on synchronous serial link.
→ The protocol is independent of any set of characters
→ Packets can be transmitted transparently. The “0-bit insert method” for transparent transmission can be implemented based on hardware.
→ The full-duplex communication can be implemented. Data can be transmitted continuously without waiting. The data transmission on the link is highly efficient.
→ All the frames adopt CRC check. The frames are numbered. Thus no frame is lost or received repeatedly. The transmission reliability is high.
→ The transmission control is separated from processing, which makes HDLC flexible and controllable.

| Flag | Address | Control | Information | FCS | Flag |
01111110 01111110

Types of HDLC Frame
→ Information frame : transmit the valid information or data
→ Supervisory frame : control errors and traffic. First two bit of the control field: “10”. [48 bits]
→ Unnumbered frame : used to establish, delete, and control the link.

Frame Relay


Features:
→ Data is transmitted in the form of the frame. (the access rate is 64 Kbps – 2 Mbps)
→ Bandwidth multiplexing and dynamic bandwidth allocation
→ As a type of simplified X.25 WAN protocol, it completes statistical MUX, transparent transmission of frames and error detection in the data link layer, but doesn't provide retransmission function
→ It provides a set of bandwidth management (CIR) and congestion prevention mechanism
→ FR adopts the connection-oriented switching technology, and provides SVC and PVC service

FR Interface Types
→ DTE : Data Terminal Equipment
→ DCE : Data Circuit-terminating Equipment
→ NNI : Network-to-Network Interface
→ DLCI : Data Link Connection Identifier [FR Network] → [range: 16-1007, DLCI 0-1023 for LMI]

Virtual Circuit : → max 1024 VC
→ PVC (Permanent Virtual Circuit) : Once the link is established, it will always be valid.
→ SVC (Switched Virtual Circuit) : automatically allocated by protocol. → transmit burst data

LMI (Local Management Interface) → monitor PVC status. [ANSI: T1.617 Annex D, ITU-T: Q.933 Annex A, non-standard]

<photo_inverse_ARP>

<photo_horizontal_splitting_and_FR>

<photo_FR_sub-interface>

WAN Protocol

WAN Protocol Laboratory Guide

IP unnumbered configuration of HDLC

[RT1]interface Loopback 0
[ ]ip address 10.1.1.1 32
[]interface Serial 0/0/0
[ ]link-protocol hdlc
[ ]ip address unnumbered interface Loopback 0
[]ip route-static 10.1.1.0 24 Serial 0/0/0

[RT2]interface Serial 0/0/0
[ ]link-protocol hdlc
[ ]ip address 10.1.1.2 24

[RT1]display ip interface brief
[]ping 10.1.1.2

* Note that Serial 0/0/0 on RT1 doesn't has an IP address.

Configure PPP Dynamic Negotiation
[RT1]interface Serial 0
[ ]link-protocol ppp
[ ]ip address ppp-negotiate

[RT2]interface Serial 0
[ ]link-protocol ppp
[ ]ip address 10.1.1.2 30
[ ]remote address 10.1.1.1

Verify by using display ip routing-table command.


Configure PPP Authentication
# PAP Authentication
[RT1]local-user huawei
[ ]password simple hello
[ ]service-type ppp
[]interface Serial 0/0/0
[ ]link-protocol ppp
[ ]ppp authentication-mode pap
[ ]ip address 10.1.1.1 30

[RT2]interface Serial 0/0/0
[ ]link-protocol ppp
[ ]ppp pap local-user huawei password simple hello
[ ]ip address 10.1.1.2 30


# CHAP Authentication
[RT1]local-user huawei
[ ]password cipher hello
[ ]service-type ppp
[]interface Serial 0/0/0
[ ]link-protocol ppp
[ ]ppp authentication chap
[ ]ip address 10.1.1.1 30

[RT2]interface Serial 0/0/0
[ ]link-protocol ppp
[ ]ppp chap user huawei
[ ]ppp chap password cipher hello
[ ]ip address 10.1.1.2 30

Frame Relay Configuration