学员提问:
#pppoe enable
PPPoE create bba subblock failed
路由器重启时也这个提示,故障,拨不上号.不知道哪里出了问题
完整配置文件:
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname dgkxrouter
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 3 log
security passwords min-length 6
logging message-counter syslog
logging buffered 51200
logging console critical
enable secret 5 $1$cVHF$QSnMcLLB7/Ag6gNP/xful/
!
no aaa new-model
clock timezone PCTime 8
no ip source-route
!
!
!
!
ip cef
no ip bootp server
ip domain name kx
multilink bundle-name authenticated
!
!
username admin privilege 15 secret 5 $1$qWKS$LV3T.MCCt/SkqSrwlnzFX1
archive
log config
hidekeys
!
!
ip tcp synwait-time 10
!
!
!
interface FastEthernet0/0
description $ETH-LAN$$ETH-SW-LAUNCH$$INTF-INFO-FE 0$
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
duplex auto
speed auto
pppoe enable
pppoe-client dial-pool-number 1
no mop enabled
!
interface FastEthernet0/1
description $ES_WAN$$FW_OUTSIDE$
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
duplex auto
speed auto
pppoe enable
pppoe-client dial-pool-number 2
no mop enabled
!
interface FastEthernet0/0/0
switchport access vlan 10
!
interface FastEthernet0/0/1
switchport access vlan 20
!
interface FastEthernet0/0/2
switchport access vlan 30
!
interface FastEthernet0/0/3
switchport access vlan 40
!
interface Vlan1
description $ES_LAN$
ip address 192.168.100.254 255.255.255.0
!
interface Vlan10
ip address 192.168.10.250 255.255.255.0
ip access-group 110 in
ip nat inside
ip virtual-reassembly
ip virtual-reassembly
!
interface Vlan20
ip address 192.168.20.254 255.255.255.0
ip access-group 120 in
ip nat inside
ip virtual-reassembly
!
interface Vlan30
ip address 192.168.30.254 255.255.255.0
ip access-group 130 in
ip nat inside
ip virtual-reassembly
!
interface Vlan40
ip address 192.168.40.254 255.255.255.0
ip access-group 140 in
ip nat inside
ip virtual-reassembly
!
interface Dialer0
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1452
ip flow ingress
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication pap callin
ppp pap sent-username dg82061329@163.gd password 7 1543595F507F7D7370
!
interface Dialer1
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1452
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 2
dialer-group 1
no cdp enable
no cdp enable
ppp authentication pap callin
ppp pap sent-username dgadsld35865845@163.gd password 7 08066F652E282B2E24
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
ip route 0.0.0.0 0.0.0.0 Dialer1
!
!
ip http server
ip http access-class 23
ip http authentication local
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 10 interface Dialer0 overload
ip nat inside source list 20 interface Dialer1 overload
ip nat inside source static tcp 192.168.10.67 3389 interface Dialer0 3389
!
logging trap debugging
access-list 10 permit 192.168.10.0 0.0.0.255
access-list 10 permit 192.168.30.0 0.0.0.255
access-list 20 permit 192.168.20.0 0.0.0.255
access-list 20 permit 192.168.40.0 0.0.0.255
access-list 110 permit udp 192.168.10.0 0.0.0.255 any eq domain
access-list 110 permit ip 192.168.10.0 0.0.0.31 host 124.172.125.26
access-list 110 deny ip 192.168.10.0 0.0.0.31 any
access-list 110 permit ip 192.168.10.0 0.0.0.31 any
access-list 110 permit ip 192.168.10.0 0.0.0.255 host 124.172.125.26
access-list 110 permit ip host 192.168.10.32 any
access-list 110 permit ip host 192.168.10.67 any
access-list 110 permit ip 192.168.10.176 0.0.0.15 any
access-list 110 permit ip 192.168.10.192 0.0.0.31 any
access-list 110 permit ip 192.168.10.0 0.0.0.31 192.168.20.0 0.0.0.255
access-list 110 permit ip 192.168.10.0 0.0.0.31 192.168.30.0 0.0.0.255
access-list 110 permit ip 192.168.10.0 0.0.0.31 192.168.40.0 0.0.0.255
access-list 110 deny ip any any
access-list 120 deny ip 192.168.20.0 0.0.0.255 192.168.10.16 0.0.0.15
access-list 120 deny ip 192.168.20.0 0.0.0.255 192.168.10.32 0.0.0.31
access-list 120 deny ip 192.168.20.0 0.0.0.255 192.168.10.128 0.0.0.127
access-list 120 deny ip 192.168.20.0 0.0.0.255 192.168.30.0 0.0.0.255
access-list 120 deny ip 192.168.20.0 0.0.0.255 192.168.40.0 0.0.0.255
access-list 120 permit ip any any
access-list 130 deny ip 192.168.20.0 0.0.0.255 192.168.10.64 0.0.0.63
access-list 130 deny ip 192.168.30.0 0.0.0.255 192.168.10.0 0.0.0.255
access-list 130 deny ip 192.168.30.0 0.0.0.255 192.168.20.0 0.0.0.255
access-list 130 deny ip 192.168.30.0 0.0.0.255 192.168.40.0 0.0.0.255
access-list 130 permit udp 192.168.30.0 0.0.0.255 any eq domain
access-list 130 permit tcp 192.168.30.0 0.0.0.255 any eq www
access-list 130 permit tcp 192.168.30.0 0.0.0.255 any eq smtp
access-list 130 permit tcp 192.168.30.0 0.0.0.255 any eq pop3
access-list 130 permit tcp 192.168.30.0 0.0.0.255 any eq 443
access-list 130 deny ip any any
access-list 140 deny ip 192.168.40.0 0.0.0.255 192.168.20.0 0.0.0.255
access-list 140 deny ip 192.168.40.0 0.0.0.255 192.168.30.0 0.0.0.255
access-list 140 deny ip 192.168.40.0 0.0.0.255 192.168.40.0 0.0.0.255
access-list 140 permit ip 192.168.40.0 0.0.0.255 any
dialer-list 1 protocol ip permit
no cdp run
!
!
control-plane
!
banner login ^Cuthorized access only!
Disconnect IMMEDI^C
!
line con 0
login local
transport output telnet
line aux 0
login local
!
banner login ^Cuthorized access only!
Disconnect IMMEDI^C
!
line con 0
login local
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
password 7 141C1B1F1E0B24223C
login local
transport input telnet
line vty 5 15
privilege level 15
login local
transport input telnet
!
scheduler allocate 4000 1000
end
PPPoE create bba subblock failed
路由器重启时也这个提示,故障,拨不上号.不知道哪里出了问题
完整配置文件:
version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname dgkxrouter
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 3 log
security passwords min-length 6
logging message-counter syslog
logging buffered 51200
logging console critical
enable secret 5 $1$cVHF$QSnMcLLB7/Ag6gNP/xful/
!
no aaa new-model
clock timezone PCTime 8
no ip source-route
!
!
!
!
ip cef
no ip bootp server
ip domain name kx
multilink bundle-name authenticated
!
!
username admin privilege 15 secret 5 $1$qWKS$LV3T.MCCt/SkqSrwlnzFX1
archive
log config
hidekeys
!
!
ip tcp synwait-time 10
!
!
!
interface FastEthernet0/0
description $ETH-LAN$$ETH-SW-LAUNCH$$INTF-INFO-FE 0$
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
duplex auto
speed auto
pppoe enable
pppoe-client dial-pool-number 1
no mop enabled
!
interface FastEthernet0/1
description $ES_WAN$$FW_OUTSIDE$
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
duplex auto
speed auto
pppoe enable
pppoe-client dial-pool-number 2
no mop enabled
!
interface FastEthernet0/0/0
switchport access vlan 10
!
interface FastEthernet0/0/1
switchport access vlan 20
!
interface FastEthernet0/0/2
switchport access vlan 30
!
interface FastEthernet0/0/3
switchport access vlan 40
!
interface Vlan1
description $ES_LAN$
ip address 192.168.100.254 255.255.255.0
!
interface Vlan10
ip address 192.168.10.250 255.255.255.0
ip access-group 110 in
ip nat inside
ip virtual-reassembly
ip virtual-reassembly
!
interface Vlan20
ip address 192.168.20.254 255.255.255.0
ip access-group 120 in
ip nat inside
ip virtual-reassembly
!
interface Vlan30
ip address 192.168.30.254 255.255.255.0
ip access-group 130 in
ip nat inside
ip virtual-reassembly
!
interface Vlan40
ip address 192.168.40.254 255.255.255.0
ip access-group 140 in
ip nat inside
ip virtual-reassembly
!
interface Dialer0
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1452
ip flow ingress
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication pap callin
ppp pap sent-username dg82061329@163.gd password 7 1543595F507F7D7370
!
interface Dialer1
ip address negotiated
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1452
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 2
dialer-group 1
no cdp enable
no cdp enable
ppp authentication pap callin
ppp pap sent-username dgadsld35865845@163.gd password 7 08066F652E282B2E24
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
ip route 0.0.0.0 0.0.0.0 Dialer1
!
!
ip http server
ip http access-class 23
ip http authentication local
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 10 interface Dialer0 overload
ip nat inside source list 20 interface Dialer1 overload
ip nat inside source static tcp 192.168.10.67 3389 interface Dialer0 3389
!
logging trap debugging
access-list 10 permit 192.168.10.0 0.0.0.255
access-list 10 permit 192.168.30.0 0.0.0.255
access-list 20 permit 192.168.20.0 0.0.0.255
access-list 20 permit 192.168.40.0 0.0.0.255
access-list 110 permit udp 192.168.10.0 0.0.0.255 any eq domain
access-list 110 permit ip 192.168.10.0 0.0.0.31 host 124.172.125.26
access-list 110 deny ip 192.168.10.0 0.0.0.31 any
access-list 110 permit ip 192.168.10.0 0.0.0.31 any
access-list 110 permit ip 192.168.10.0 0.0.0.255 host 124.172.125.26
access-list 110 permit ip host 192.168.10.32 any
access-list 110 permit ip host 192.168.10.67 any
access-list 110 permit ip 192.168.10.176 0.0.0.15 any
access-list 110 permit ip 192.168.10.192 0.0.0.31 any
access-list 110 permit ip 192.168.10.0 0.0.0.31 192.168.20.0 0.0.0.255
access-list 110 permit ip 192.168.10.0 0.0.0.31 192.168.30.0 0.0.0.255
access-list 110 permit ip 192.168.10.0 0.0.0.31 192.168.40.0 0.0.0.255
access-list 110 deny ip any any
access-list 120 deny ip 192.168.20.0 0.0.0.255 192.168.10.16 0.0.0.15
access-list 120 deny ip 192.168.20.0 0.0.0.255 192.168.10.32 0.0.0.31
access-list 120 deny ip 192.168.20.0 0.0.0.255 192.168.10.128 0.0.0.127
access-list 120 deny ip 192.168.20.0 0.0.0.255 192.168.30.0 0.0.0.255
access-list 120 deny ip 192.168.20.0 0.0.0.255 192.168.40.0 0.0.0.255
access-list 120 permit ip any any
access-list 130 deny ip 192.168.20.0 0.0.0.255 192.168.10.64 0.0.0.63
access-list 130 deny ip 192.168.30.0 0.0.0.255 192.168.10.0 0.0.0.255
access-list 130 deny ip 192.168.30.0 0.0.0.255 192.168.20.0 0.0.0.255
access-list 130 deny ip 192.168.30.0 0.0.0.255 192.168.40.0 0.0.0.255
access-list 130 permit udp 192.168.30.0 0.0.0.255 any eq domain
access-list 130 permit tcp 192.168.30.0 0.0.0.255 any eq www
access-list 130 permit tcp 192.168.30.0 0.0.0.255 any eq smtp
access-list 130 permit tcp 192.168.30.0 0.0.0.255 any eq pop3
access-list 130 permit tcp 192.168.30.0 0.0.0.255 any eq 443
access-list 130 deny ip any any
access-list 140 deny ip 192.168.40.0 0.0.0.255 192.168.20.0 0.0.0.255
access-list 140 deny ip 192.168.40.0 0.0.0.255 192.168.30.0 0.0.0.255
access-list 140 deny ip 192.168.40.0 0.0.0.255 192.168.40.0 0.0.0.255
access-list 140 permit ip 192.168.40.0 0.0.0.255 any
dialer-list 1 protocol ip permit
no cdp run
!
!
control-plane
!
banner login ^Cuthorized access only!
Disconnect IMMEDI^C
!
line con 0
login local
transport output telnet
line aux 0
login local
!
banner login ^Cuthorized access only!
Disconnect IMMEDI^C
!
line con 0
login local
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
password 7 141C1B1F1E0B24223C
login local
transport input telnet
line vty 5 15
privilege level 15
login local
transport input telnet
!
scheduler allocate 4000 1000
end
捷盈讲师及学员解答:
有没有升级过ios?试试在pppoe enable后面加上group global看看。

