一.ip配置:
因为划分了5个ospf区域有一个是公网所以需要从172.16.0.0/16划分出五个网段
area 1:172.16.192.0 /18
area 2:172.16.128.0 /18
area 3:172.16.64.0 /18
area 4:172.16.0.0 /18
rip:192.168.0.12 /32
R1:
GE0/0/0:172.16.192.1 /18
LoopBack0:192.168.0.1 /32
配置:
[r1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]ip address 172.16.192.1 18
[r1]interface LoopBack 0
[r1-LoopBack0]ip address 192.168.0.1 32
R2:
GE0/0/0:172.16.192.2 /18
LoopBack0:192.168.0.2 /32
配置:
[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]ip address 172.16.192.2 18
[r2]interface LoopBack 0
[r2-LoopBack0]ip address 192.168.0.2 32
R3:
GE0/0/0:172.16.192.3 /18
Serial4/0/0:15.0.0.3 /8
LoopBack0:192.168.0.3 /32
配置:
[r3]interface GigabitEthernet 0/0/0
[r3-GigabitEthernet0/0/0]ip address 172.16.192.3 18
[r3]interface Serial 4/0/0
[r3-Serial4/0/0]ip address 15.0.0.3 8
[r3]interface LoopBack 0
[r3-LoopBack0]ip address 192.168.0.3 32
R4:
GE0/0/0:25.0.0.4 /8
Serial3/0/0:15.0.0.4 /8
Serial3/0/1:45.0.0.4 /8
Serial4/0/0:35.0.0.4 /8
LoopBack0:192.168.0.4 32
配置:
[r4]interface GigabitEthernet 0/0/0
[r4-GigabitEthernet0/0/0]ip address 25.0.0.4 8
[r4]interface Serial 3/0/0
[r4-Serial3/0/0]ip address 15.0.0.4 /8
[r4]interface Serial 3/0/1
[r4-Serial3/0/1]ip address 45.0.0.4 /8
[r4]interface Serial 4/0/0
[r4-Serial4/0/0]ip address 35.0.0.4 /8
[r4]interface LoopBack 0
[r4-LoopBack0]ip address 192.168.0.4 /32
R5:
Serial4/0/0:45.0.0.5 /8
LoopBack0:192.168.0.5 /32
配置:
[r5]interface Serial 4/0/0
[r5-Serial4/0/0]ip address 45.0.0.5 8
[r5]interface LoopBack 0
[r5-LoopBack0]ip address 192.168.0.5 32
R6:
GE0/0/0:172.16.128.6 /19
Serial4/0/0:35.0.0.6 /8
LoopBack0:192.168.0.6 /32
配置:
[r6]interface Serial 4/0/0
[r6-Serial4/0/0]ip address 35.0.0.6 8
[r6]interface GigabitEthernet 0/0/0
[r6-GigabitEthernet0/0/0]ip address 172.16.128.6 19
[r6]interface LoopBack 0
[r6-LoopBack0]ip address 192.168.0.6 32
R7:
GE0/0/0:25.0.0.7 /8
GE0/0/1:172.16.64.7 /19
LoopBack0:192.168.0.7 /32
配置:
[r7]interface GigabitEthernet 0/0/0
[r7-GigabitEthernet0/0/0]ip address 25.0.0.7 8
[r7]interface GigabitEthernet 0/0/1
[r7-GigabitEthernet0/0/1]ip address 172.16.64.7 19
[r7]interface LoopBack 0
[r7-LoopBack0]ip address 192.168.0.7 32
R8:
GE0/0/0:172.16.64.8 /19
GE0/0/1:172.16.96.8 /19
LoopBack 0:192.168.0.8 /32
配置:
[r8]interface GigabitEthernet 0/0/0
[r8-GigabitEthernet0/0/0]ip address 172.16.64.8 19
[r8-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r8-GigabitEthernet0/0/1]ip address 172.16.96.8 19
[r8]interface LoopBack 0
[r8-LoopBack0]ip address 192.168.0.8 32
R9:
GE0/0/0:172.16.96.9 /19
GE0/0/1:172.16.0.9 /18
LoopBack0:192.168.0.9 /32
配置:
[r9]interface GigabitEthernet 0/0/0
[r9-GigabitEthernet0/0/0]ip address 172.16.96.9 19
[r9-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r9-GigabitEthernet0/0/1]ip address 172.16.0.9 18
[r9]interface LoopBack 0
[r9-LoopBack0]ip address 192.168.0.9 32
AR10:
GE0/0/0:172.16.0.10 /18
LoopBack 0:192.168.0.10 /32
配置:
[10]interface GigabitEthernet 0/0/0
[10-GigabitEthernet0/0/0]ip address 172.16.0.10 18
[10]interface LoopBack 0
[10-LoopBack0]ip address 192.168.0.10 32
AR11:
GE0/0/0:172.16.128.11 /19
GE0/0/1:172.16.192.11 /19
LoopBack 0:192.168.0.11 /32
配置:
[r11]interface GigabitEthernet 0/0/0
[r11-GigabitEthernet0/0/0]ip address 172.16.128.11 19
[r11-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r11-GigabitEthernet0/0/1]ip address 172.16.192.11 19
[r11]interface LoopBack 0
[r11-LoopBack0]ip address 192.168.0.11 32
AR12:
GE0/0/0:172.16.192.12 /19
LoopBack0:192.168.0.12 /32
配置:
[r12]interface GigabitEthernet 0/0/0
[r12-GigabitEthernet0/0/0]ip address 172.16.192.12 19
[r12]interface LoopBack 0
[r12-LoopBack0]ip address 192.168.0.12 32
缺省路由:
R3:[r3]ip route-static 0.0.0.0 0 15.0.0.4
R5:[r5]ip route-static 0.0.0.0 0 45.0.0.4
R6:[r6]IP route-static 0.0.0.0 0 35.0.0.4
R7:[r7]IP route-static 0.0.0.0 0 25.0.0.4
二.MGRE环境搭建:
公网隧道地址为192.168.80.0 24
R3(中心):
[r3]interface Tunnel 0/0/0
[r3-Tunnel0/0/0]ip address 192.168.80.3 24
[r3-Tunnel0/0/0]tunnel-protocol gre p2mp
[r3-Tunnel0/0/0]nhrp network-id 100
[r3-Tunnel0/0/0]source 15.0.0.3
R5(分支):
[r5]interface Tunnel 0/0/0
[r5-Tunnel0/0/0]ip address 192.168.80.5 24
[r5-Tunnel0/0/0]tunnel-protocol gre p2mp
[r5-Tunnel0/0/0]source 45.0.0.5
[r5-Tunnel0/0/0]nhrp network-id 100
[r5-Tunnel0/0/0]nhrp entry 192.168.80.3 15.0.0.3 register
R6(分支):
[r6]interface Tunnel 0/0/0
[r6-Tunnel0/0/0]ip address 192.168.80.6 24
[r6-Tunnel0/0/0]tunnel-protocol gre p2mp
[r6-Tunnel0/0/0]nhrp network-id 100
[r6-Tunnel0/0/0]source 35.0.0.6
[r6-Tunnel0/0/0]nhrp entry 192.168.80.3 15.0.0.3 register
R7(分支):
[r7]interface Tunnel 0/0/0
[r7-Tunnel0/0/0]IP address 192.168.80.7 24
[r7-Tunnel0/0/0]tunnel-protocol gre p2mp
[r7-Tunnel0/0/0]source 25.0.0.7
[r7-Tunnel0/0/0]nhrp network-id 100
[r7-Tunnel0/0/0]nhrp entry 192.168.80.3 15.0.0.3 register
验证:
三.配置OSPF协议和RIP实现全网通:
要想在MGRE环境下配置OSPF必须在MGRE中心开启伪广播
[r3-Tunnel0/0/0]nhrp entry multicast dynamic
因为ospf是以组播的方式发送hello报文所以得把接口协议改为broadcast
[r6-Tunnel0/0/0]ospf network-type broadcast
[r5-Tunnel0/0/0]ospf network-type broadcast
[r7-Tunnel0/0/0]ospf network-type broadcast
区域0:
R3:
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]network 192.168.80.3 0.0.0.255
R5:
[r5]ospf 1 router-id 5.5.5.5
[r5-ospf-1]area 0
[r5-ospf-1-area-0.0.0.0]network 192.168.80.5 0.0.0.255
[r5-ospf-1-area-0.0.0.0]network 192.168.0.5 0.0.0.0
R6:
[r6]ospf 1 router-id 6.6.6.6
[r6-ospf-1]area 0
[r6-ospf-1-area-0.0.0.0]network 192.168.80.6 0.0.0.255
[r6-ospf-1-area-0.0.0.0]network 192.168.0.6 0.0.0.0
R7:
[r7]ospf 1 router-id 7.7.7.7
[r7-ospf-1]area 0
[r7-ospf-1-area-0.0.0.0]network 192.168.80.7 0.0.0.255
[r7-ospf-1-area-0.0.0.0]network 192.168.0.7 0.0.0.255
区域1:
R1:
[r1]ospf 1 router-id 1.1.1.1
[r1-ospf-1]area 1
[r1-ospf-1-area-0.0.0.1]network 192.168.0.1 0.0.0.255
[r1-ospf-1-area-0.0.0.1]network 172.16.192.1 0.0.63.255
R2:
[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 1
[r2-ospf-1-area-0.0.0.1]network 192.168.0.2 0.0.0.255
[r2-ospf-1-area-0.0.0.1]network 172.16.192.2 0.0.63.255
R3:
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]network 192.168.0.3 0.0.0.255
[r3-ospf-1-area-0.0.0.1]network 12.16.192.3 0.0.63.255
区域3:
R7:
[r7]ospf 1 router-id 7.7.7.7
[r7-ospf-1]area 3
[r7-ospf-1-area-0.0.0.3]network 172.16.64.7 0.0.31.255
R8:
[r8]ospf 1 router-id 8.8.8.8
[r8-ospf-1]area 3
[r8-ospf-1-area-0.0.0.3]network 172.16.64.8 0.0.31.255
[r8-ospf-1-area-0.0.0.3]network 172.16.96.8 0.0.31.255
[r8-ospf-1-area-0.0.0.3]network 192.168.0.8 0.0.0.255
R9:
[r9]ospf 1 router-id 9.9.9.9
[r9-ospf-1]area 3
[r9-ospf-1-area-0.0.0.3]network 172.16.96.9 0.0.31.255
区域4:
R9:
[r9]ospf
[r9-ospf-1]area 4
[r9-ospf-1-area-0.0.0.4]network 172.16.0.9 0.0.63.255
[r9-ospf-1-area-0.0.0.4]network 192.168.0.9 0.0.0.255
R10:
[10]ospf 1 router-id 10.10.10.10
[10-ospf-1]area 4
[10-ospf-1-area-0.0.0.4]network 172.16.0.10 0.0.63.255
[10-ospf-1-area-0.0.0.4]network 192.168.0.10 0.0.0.255
区域2:
R6:
[r6]ospf 1
[r6-ospf-1]area 2
[r6-ospf-1-area-0.0.0.2]network 172.16.128.6 0.0.31.255
R11:
[r11]ospf 1 router-id 11.11.11.11
[r11-ospf-1]area 2
[r11-ospf-1-area-0.0.0.2]network 172.16.192.11 0.0.31.255
[r11-ospf-1-area-0.0.0.2]network 172.16.128.11 0.0.31.255
R12:
[r12]ospf 1 router-id 12.12.12.12
[r12-ospf-1]area 2
[r12-ospf-1-area-0.0.0.2]network 172.16.192.12 0.0.31.255
RIP:
R12:
[r12]rip
[r12-rip-1]version 2
[r12-rip-1]network 192.168.0.0
验证:
区域1能与区域3通信:
区域1能与区域2通信:
区域1不能与区域4和rip区域通信:
这个时候还不能全网通,只有与骨干区域直接相连的才能通行,因为
非法ABR设备无法传递路由表,因为ospf与rip所用算法不一样所以也
不能直接传递路由表,所以需要把rip区域重发布到ospf中,把区域4的进程改为2
更改配置:
area 3:
AR9:
[r9]undo ospf
Warning: The OSPF process will be deleted. Continue? [Y/N]:y
[r9]OSPF 1 router-id 9.9.9.9
[r9-ospf-1]area 3
[r9-ospf-1-area-0.0.0.3]network 172.16.96.9 0.0.31.255
area 4:
AR9:
[r9]ospf 2 router-id 9.9.9.9
[r9-ospf-2]area 4
[r9-ospf-2-area-0.0.0.4]network 192.168.0.9 0.0.0.0
[r9-ospf-2-area-0.0.0.4]network 172.16.0.9 0.0.63.255
AR10:
[10]undo ospf 1
Warning: The OSPF process will be deleted. Continue? [Y/N]:y
[10]ospf 2 router-id 10.10.10.10
[10-ospf-2]area 4
[10-ospf-2-area-0.0.0.4]network 172.16.0.10 0.0.63.255
[10-ospf-2-area-0.0.0.4]network 192.168.0.10 0.0.0.0
AR9(ABR):
[r9]ospf 1
[r9-ospf-1]import-route os
[r9-ospf-1]import-route ospf 2
[r9]ospf 2
[r9-ospf-2]import-route ospf 1
AR10(ASBR):
[r12]ospf 1
[r12-ospf-1]import-route rip 1
[r12]rip
[r12-rip-1]import-route ospf 1
验证:
与rip区域相通
与区域4相通
四.减少LSA更新,加快收敛
在area 1 area 2 area 3 area 4 的ABR配置stub区(减少4类5类LSA)
在area 2 rip 的ASBR配置NSSA区
ABR的stub区配置:
(以R3为例)
[r3]ospf 1
[r3-ospf-1]asbr-summary
[r3-ospf-1-area-0.0.0.1]network 172.16.192.0 0.0.63.255
其中重新宣告的网段是汇总后的网段
非ABR的stub区配置:
(以在同一area 1区的R2为例)
[r2]ospf 1
[r2-ospf-1]area 1
[r2-ospf-1-area-0.0.0.1]stub
验证:
这是配置完area 1区stub区的LSA信息
stub区配置完后: