实验拓扑图:
实验要求:
R1-R2-R3-R4-R5运行RIPv2
R6-R7运行RIPV1
1,使用合理地址规划网络,各自创建环回接口
2,R1创建环回172.16.1.1/24 172.16.2.1/24 172.16.3.1/24
3,要求R3使用R2访问R1环回
4,减少路由条自数量,R1-R2之间增加路由传递安全性
5,R5创建一个环回模拟运营商,不能宣告
6,R1 telnet_R2环回实际telnet到R7上
7,R6-R7路由器不能学习到达R1环回路由
8,全网可达
实验过程:
1.IP地址规划:
未作要求,自己合理划分,本实验划分如下:
2.基础配置:
R1:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 172.16.1.1 24
[Huawei-LoopBack0]q
[Huawei]interface LoopBack 1
[Huawei-LoopBack1]ip address 172.16.2.1 24
[Huawei-LoopBack1]q
[Huawei]interface LoopBack 2
[Huawei-LoopBack2]ip address 172.16.3.1 24
[Huawei-LoopBack2]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 172.16.4.1 30
[Huawei-GigabitEthernet0/0/0]q
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 172.16.10.1 30
[Huawei-GigabitEthernet0/0/1]q
R2:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 172.16.5.1 24
[Huawei-LoopBack0]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 172.16.4.2 30
[Huawei-GigabitEthernet0/0/0]q
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 172.16.6.1 30
[Huawei-GigabitEthernet0/0/1]q
R3:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 172.16.7.1 24
[Huawei-LoopBack0]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 172.16.6.2 30
[Huawei-GigabitEthernet0/0/0]q
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 172.16.8.2 30
[Huawei-GigabitEthernet0/0/1]q
R4:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 172.16.9.1 24
[Huawei-LoopBack0]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 172.16.8.1 30
[Huawei-GigabitEthernet0/0/0]q
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 172.16.10.2 30
[Huawei-GigabitEthernet0/0/1]q
[Huawei]interface g0/0/2
[Huawei-GigabitEthernet0/0/0]ip address 172.16.11.1 30
[Huawei-GigabitEthernet0/0/0]q
[Huawei]interface g4/0/0
[Huawei-GigabitEthernet0/0/1]ip address 192.168.1.1 30
[Huawei-GigabitEthernet0/0/1]q
R5:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 4.4.4.4 24
[Huawei-LoopBack0]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 172.16.11.2 30
[Huawei-GigabitEthernet0/0/0]q
R6:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 192.168.2.1 24
[Huawei-LoopBack0]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.3.1 30
[Huawei-GigabitEthernet0/0/0]q
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.1.2 30
[Huawei-GigabitEthernet0/0/1]q
R7:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 192.168.4.1 24
[Huawei-LoopBack0]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.3.2 30
[Huawei-GigabitEthernet0/0/0]q
3.R1-R2-R3-R4-R5运行RIPv2 R6-R7运行RIPV1
R1:
[Huawei]rip 1
[Huawei-rip-1]version 2
[Huawei-rip-1]network 172.16.0.0
R2:
[Huawei]rip 1
[Huawei-rip-1]version 2
[Huawei-rip-1]network 172.16.0.0
R3:
[Huawei]rip 1
[Huawei-rip-1]version 2
[Huawei-rip-1]network 172.16.0.0
R4:
[Huawei]rip 1
[Huawei-rip-1]version 2
[Huawei-rip-1]network 172.16.0.0
[Huawei-rip-1]network 192.168.1.0
R5:
[Huawei]rip 1
[Huawei-rip-1]version 2
[Huawei-rip-1]network 172.16.0.0
[Huawei-rip-1]default-route originate
R6:
[Huawei]rip 1
[Huawei-rip-1]version 1
[Huawei-rip-1]network 192.168.1.0
[Huawei-rip-1]network 192.168.2.0
[Huawei-rip-1]network 192.168.3.0
R7:
[Huawei]rip 1
[Huawei-rip-1]version 1
[Huawei-rip-1]network 192.168.4.0
[Huawei-rip-1]network 192.168.3.0
此时全网可达:
4.R3使用R2访问R1环回(增加另一条路径的开销值)
R3:
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 172.16.0.0 0.0.3.255
[Huawei-acl-basic-2000]q
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]rip metricin 2000 2
此时,完成要求:
5.减少路由条自数量,R1-R2之间增加路由传递安全性
R1:
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]rip summary-address 172.16.0.0 255.255.252.0
[Huawei-GigabitEthernet0/0/0]rip authentication-mode md5 usual cipher 123
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]rip summary-address 172.16.0.0 255.255.252.0
[Huawei]ip route-static 172.16.0.0 22 null 0
R2:
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]rip authentication-mode md5 usual cipher 123
6.R1 telnet_R2环回实际telnet到R7上
R7:
[Huawei]aaa
[Huawei-aaa]local-user litong privilege level 15 password cipher 123
[Huawei-aaa]local-user litong service-type telnet
[Huawei-aaa]q
[Huawei]user-interface vty 0 4
[Huawei-ui-vty0-4]au
[Huawei-ui-vty0-4]authentication-mode aaa
R2:
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]nat server protocol tcp global interface loopback 0 23 inside 192.168.4.1 23
Are you sure to continue?[Y/N]:y
注意要确保R1telnetR2环回的流量往返都要过R2
R2:
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 192.168.4.0 0.0.0.255
[Huawei-acl-basic-2000]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/1]rip metricin 2000 2
R4:
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 172.16.4.0 0.0.0.255
[Huawei-acl-basic-2000]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/1]rip metricin 2000 2
此时,完成要求
7.R6-R7路由器不能学习到达R1环回路由
R6:
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule deny source 172.16.0.0 0.0.3.255
[Huawei-acl-basic-2000]rule permit source any
[Huawei-acl-basic-2000]q
[Huawei]rip 1
[Huawei-rip-1]filter-policy 2000 import
效果如下: