实验要求
1、R4为ISP,所连接的所有物理接口为公有网段,任意指定ip即可
2、R1-2-3 构建一个星型结构的MGRE结构,其中R1为中心点,假设R1的公有ip为固定地址
3、R1-5-6 构建另个全连网状的MGRE网络,其中R1/5均为中心区域
4、使用osPF实现整个私有网络的互通,同时所有pc可以正常访问R4的环回
实验步骤
如图所示构建配置
首先需要增加板卡
配置ip地址
我们先根据所给网段将PC IP地址进行划分,然后再配置路由节点的IP地址
R1:
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[R1-GigabitEthernet0/0/0]int g0/0/01
[R1-GigabitEthernet0/0/1]ip address 14.1.1.1 24
[R1-GigabitEthernet0/0/1]int g0/0/2
[R1-GigabitEthernet0/0/2]ip address 41.1.1.1 24
R2:
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip address 24.1.1.1 24
[R2-GigabitEthernet0/0/0]int g0/0/1
[R2-GigabitEthernet0/0/1]ip address 192.168.2.1 24
R3:
[R3]int g0/0/1
[R3-GigabitEthernet0/0/1]ip address 192.168.3.2 24
[R3-GigabitEthernet0/0/1]int g0/0/0
[R3-GigabitEthernet0/0/0]ip address 34.1.1.1 24
R4:
[R4]int l0
[R4-LoopBack0]ip address 4.4.4.4 24
[R4]int g0/0/0
[R4-GigabitEthernet0/0/0]ip address 14.1.1.2 24
[R4-GigabitEthernet0/0/0]int g0/0/1
[R4-GigabitEthernet0/0/1]ip address 41.1.1.2 24
[R4-GigabitEthernet0/0/1]int g0/0/2
[R4-GigabitEthernet0/0/2]ip address 24.1.1.2 24
[R4-GigabitEthernet0/0/2]int g4/0/0
[R4-GigabitEthernet4/0/0]ip address 34.1.1.2 24
[R4-GigabitEthernet4/0/0]int g4/0/1
[R4-GigabitEthernet4/0/1]ip address 64.1.1.2 24
[R4-GigabitEthernet4/0/1]int g4/0/2
[R4-GigabitEthernet4/0/2]ip address 54.1.1.2 24
R5:
[R5]int g0/0/1
[R5-GigabitEthernet0/0/1]ip address 192.168.4.1 24
[R5-GigabitEthernet0/0/1]int g0/0/0
[R5-GigabitEthernet0/0/0]ip address 54.1.1.1 24
R6:
[R6]int g0/0/1
[R6-GigabitEthernet0/0/1]ip address 192.168.5.1 24
[R6-GigabitEthernet0/0/1]int g0/0/0
[R6-GigabitEthernet0/0/0]ip address 64.1.1.1 24
配置OSPF
配置路由缺省
R1:
[R1]ip route-static 0.0.0.0 0 41.1.1.2
[R1]ip route-static 0.0.0.0 0 14.1.1.2
R2:
[R2]ip route-static 0.0.0.0 0 24.1.1.2
R3:
[R3]ip route-static 0.0.0.0 0 34.1.1.2
R5:
[R5]ip route-static 0.0.0.0 0 54.1.1.2
R6:
[R6]ip route-static 0.0.0.0 0 64.1.1.2
配置NAT服务
R1:
[R1]acl 2000
[R1-acl-basic-2000]rule 1 permit source any
[R1-acl-basic-2000]int g0/0/1
[R1-GigabitEthernet0/0/1]nat outbound 2000
[R1-GigabitEthernet0/0/1]int g0/0/2
[R1-GigabitEthernet0/0/2]nat outbound 2000
R2:
[R2]acl 2000
[R2-acl-basic-2000]rule 1 permit source any
[R2-acl-basic-2000]int g0/0/0
[R2-GigabitEthernet0/0/0]nat outbound 2000
R3:
[R3]acl 2000
[R3-acl-basic-2000]rule 1 permit source any
[R3-acl-basic-2000]int g0/0/0
[R3-GigabitEthernet0/0/0]nat outbound 2000
R5:
[R5]acl 2000
[R5-acl-basic-2000]rule 1 permit source any
[R5-acl-basic-2000]int g0/0/0
[R5-GigabitEthernet0/0/0]nat outbound 2000
R6:
[R6]acl 2000
[R6-acl-basic-2000]rule 1 permit source any
[R6-acl-basic-2000]int g0/0/0
[R6-GigabitEthernet0/0/0]nat outbound 2000
配置MGRE结构
配置R1-5-6全连的MGRE结构,R1和R5都是中心
R1:(中心站点)
[R1]int t0/0/0
[R1-Tunnel0/0/0]ip address 10.1.1.1 24
[R1-Tunnel0/0/0]tunnel-protocol gre p2mp
[R1-Tunnel0/0/0]source 14.1.1.1
[R1-Tunnel0/0/0]nhrp network-id 100
[R1-Tunnel0/0/0]nhrp entry 10.1.1.5 54.1.1.1 register
[R1-Tunnel0/0/0]nhrp entry 10.1.1.6 64.1.1.1 register
[R1-Tunnel0/0/0]ospf network-type broadcast
R5:
[R5]int t0/0/0
[R5-Tunnel0/0/0]ip address 10.1.1.5 24
[R5-Tunnel0/0/0]tunnel-protocol gre p2mp
[R5-Tunnel0/0/0]nhrp network-id 100
[R5-Tunnel0/0/0]source 54.1.1.1
[R5-Tunnel0/0/0]nhrp entry 10.1.1.1 14.1.1.1 register
[R5-Tunnel0/0/0]nhrp entry 10.1.1.6 64.1.1.1 register
R6:
[R6]int t0/0/0
[R6-Tunnel0/0/0]tunnel-protocol gre p2mp
[R6-Tunnel0/0/0]ip address 10.1.1.6 24
[R6-Tunnel0/0/0]source 64.1.1.1
[R6-Tunnel0/0/0]nhrp network-id 100
[R6-Tunnel0/0/0]nhrp entry 10.1.1.1 14.1.1.1 register
[R6-Tunnel0/0/0]nhrp entry 10.1.1.5 54.1.1.1 register
R5为中心站点
R5:
[R5]int t0/0/0
[R5-Tunnel0/0/0]ip address 20.1.1.5 24
[R5-Tunnel0/0/0]tunnel-protocol gre p2mp
[R5-Tunnel0/0/0]source 54.1.1.1
[R5-Tunnel0/0/0]nhrp network-id 101
[R5-Tunnel0/0/0]nhrp entry 20.1.1.1 14.1.1.1 register
[R5-Tunnel0/0/0]nhrp entry 20.1.1.6 64.1.1.1 register
[R5-Tunnel0/0/0]ospf network-type broadcast
R1:
[R1]int t0/0/0
[R1-Tunnel0/0/0]ip address 20.1.1.1 24
[R1-Tunnel0/0/0]tunnel-protocol gre p2mp
[R1-Tunnel0/0/0]nhrp network-id 101
[R1-Tunnel0/0/0]source 14.1.1.1
[R1-Tunnel0/0/0]nhrp entry 20.1.1.5 54.1.1.1 register
[R1-Tunnel0/0/0]nhrp entry 20.1.1.6 54.1.1.1 register
R6:
[R6]int t0/0/0
[R6-Tunnel0/0/0]ip address 20.1.1.6 24
[R6-Tunnel0/0/0]tunnel-protocol gre p2mp
[R6-Tunnel0/0/0]source 64.1.1.1
[R6-Tunnel0/0/0]nhrp network-id 101
[R6-Tunnel0/0/0]nhrp entry 20.1.1.1 14.1.1.1 register
[R6-Tunnel0/0/0]nhrp entry 20.1.1.5 54.1.1.1 register
[R6-Tunnel0/0/0]ospf network-type broadcast
添加伪广播
需要用OSPF则要在MGRE两个中心站点上添加伪广播
R1:
[R1-Tunnel0/0/0]nhrp entry multicast dynamic
[R1-Tunnel0/0/1]nhrp entry multicast dynamic
R5:
[R5-Tunnel0/0/0]nhrp entry multicast dynamic
配置OSPF:
R1:
[r1]ospf 1
[r1-ospf-1]area 0
[r1-ospf-1-area-0.0.0.0]ne
[r1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[r1-ospf-1-area-0.0.0.0]ne
[r1-ospf-1-area-0.0.0.0]network 20.1.1.0 0.0.0.255
[r1-ospf-1-area-0.0.0.0]ne
[r1-ospf-1-area-0.0.0.0]network 10.1.1.0 0.0.0.255
[r1-ospf-1-area-0.0.0.0]int t 0/0/0
[r1-Tunnel0/0/0]ospf network-type broadcast
R2:
[r2]ospf 1 router-id 2.2.2.2
Info: The configuration succeeded. You need to restart the OSPF process to valid
ate the new router ID.
[r2-ospf-1]ar
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 10.1.1.0 0.255.255.255
[r2-ospf-1-area-0.0.0.0]network 192.168.2.0 0.0.0.255
[r2-ospf-1-area-0.0.0.0]int t 0/0/0
[r2-Tunnel0/0/0]ospf network-type broadcast
R3:
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]ar
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]ne
[r3-ospf-1-area-0.0.0.0]network 10.1.1.0 0.0.0.255
[r3-ospf-1-area-0.0.0.0]network 192.168.3.0 0.0.0.255
[r3-ospf-1-area-0.0.0.0]int t 0/0/0
[r3-Tunnel0/0/0]os
[r3-Tunnel0/0/0]ospf n
[r3-Tunnel0/0/0]ospf network-type d
[r3-Tunnel0/0/0]ospf network-type b
[r3-Tunnel0/0/0]ospf network-type broadcast
R5:
[r5]ospf 1 router-id 5.5.5.5
[r5-ospf-1]ar
[r5-ospf-1]area 0
[r5-ospf-1-area-0.0.0.0]network 192.168.4.0 0.0.0.255
[r5-ospf-1-area-0.0.0.0]network 20.1.1.0 0.0.0.255
[r5-ospf-1-area-0.0.0.0]int t 0/0/1
[r5-Tunnel0/0/1]ospf network-type broadcast
[r5-Tunnel0/0/1]ospf dr-priority 0
R6:
[R6]ospf 1 router-id 6.6.6.6
[R6-ospf-1]ar
[R6-ospf-1]area 0
[R6-ospf-1-area-0.0.0.0]ne
[R6-ospf-1-area-0.0.0.0]network 20.1.1.0 0.0.0.255
[R6-ospf-1-area-0.0.0.0]network 192.168.5.0 0.0.0.255
[R6-ospf-1-area-0.0.0.0]network 192.168.5.0 0.0.0.255
[R6-Tunnel0/0/1]ospf dr-priority 0
全网通