一.IP配置:
AR1:
[r1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]ip address 15.0.0.1 8
[r1-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r1-GigabitEthernet0/0/1]ip address 45.0.0.1 8
[r1]interface LoopBack 0
[r1-LoopBack0]ip address 192.168.0.1 24
AR2:
[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]ip address 15.0.0.2 8
[r2]interface g 0/0/1
[r2-GigabitEthernet0/0/1]ip address 25.0.0.2 8
AR3:
[r3]interface g 0/0/0
[r3-GigabitEthernet0/0/0]ip address 45.0.0.3 8
[r3-GigabitEthernet0/0/0]interface g 0/0/1
[r3-GigabitEthernet0/0/1]ip address 35.0.0.3 8
AR4:
[r4]interface g 0/0/0
[r4-GigabitEthernet0/0/0]ip address 25.0.0.4 8
[r4-GigabitEthernet0/0/0]interface g 0/0/1
[r4-GigabitEthernet0/0/1]ip address 35.0.0.4 8
[r4]interface LoopBack 0
[r4-LoopBack0]ip address 192.168.0.4 24
二.OSPF,RIP配置:
RIP:
R1:
[r1]rip
[r1-rip-1]version 2
[r1-rip-1]network 192.168.1.0
[r1-rip-1]network 15.0.0.0
[r1-rip-1]network 45.0.0.0
R2:
[r2]rip
[r2-rip-1]version 2
[r2-rip-1]network 15.0.0.0
R3:
[r3]rip
[r3-rip-1]version 2
[r3-rip-1]network 45.0.0.0
OSPF:
R2:
[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 25.0.0.1 0.255.255.255
R3:
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]network 35.0.0.3 0.255.255.255
R4:
[r4]ospf 1 router-id 4.4.4.4
[r4-ospf-1]area 0
[r4-ospf-1-area-0.0.0.0]network 25.0.0.4 0.255.255.255
[r4-ospf-1-area-0.0.0.0]network 35.0.0.4 0.255.255.255
[r4-ospf-1-area-0.0.0.0]network 192.168.4.1 0.0.0.255
三.双节点重发布:
每一个ASBR都需要在一个动态协议里引入另外一个协议
R2:
[r2]rip
[r2-rip-1]import-route ospf 1
[r2]ospf
[r2-ospf-1]import-route rip 1
R3:
[r3]rip
[r3-rip-1]import-route ospf 1
[r3]ospf 1
[r3-ospf-1]import-route rip 1
验证:
此时R4的环回能ping通R1的环回说明此时全网通
四.优化最佳路径:
我们查看R1的路由表发现去往25.0.0.0 /8,35.0.0.0 /18网段都具能从俩个接口发出,但结合实际我们只希望去往25.0.0.0 /8只从0/0/0发出也就是经过AR2发送到25.0.0.0 /8,去往35.0.0.0的网段从接口0/0/1发出经过AR3到达35.0.0.0 /8网段
先看R1到R4的流量:
配置:
AR1(使用过滤列表配置):
[r1]ip ip-prefix aaa deny 25.0.0.0 8
[r1]ip ip-prefix aaa permit 0.0.0.0 0 less-equal 32
[r1]rip
[r1-rip-1]filter-policy ip-prefix aaa import GigabitEthernet 0/0/1
[r1]ip ip-prefix bbb deny 35.0.0.0 8
[r1]ip ip-prefix bbb permit 0.0.0.0 0 less-equal 32
[r1]rip
[r1-rip-1]filter-policy ip-prefix bbb import GigabitEthernet 0/0/0
验证:
这时候去25.0.0.0/8只能从0/0/0接口走,去35.0.0.0/8只能从0/0/1接口
现在看R4到R1的流量
R4到R1的流量必须经过R2或者R3所以我们可以在重发布的时候调用rote-policy
配置:
AR2:
[r2-acl-basic-2000]rule permit source 45.0.0.0 0.0.0.255
[r2]route-policy aaa deny node 10
[r2-route-policy]if-match acl 2000
[r2]route-policy aaa permit node 100
[r2]ospf
[r2-ospf-1]import-route rip route-policy aaa
AR3:
[r3-acl-basic-2333]rule permit source 15.0.0.0 0.0.0.255
[r3]route-policy ddd deny node 20
[r3-route-policy]if-match acl 2333
[r3]route-policy ddd permit node 1000
[r3]ospf
[r3-ospf-1]import-route rip route-policy ddd
验证: