实验拓扑图:
实验要求:
1.R6为ISP,只能配置IP地址,R1-R5的环回为私有网段
2.R1/4/5为全连的MGRE结构, R1/2/3为星型的拓扑结构,R1为中心站点
3.所有私有网段可以互相通讯,私有网段使用ospf协议完成
实验过程:
1.IP地址规划:
未作要求,随意给,本实验规划如下:
2.基础配置,并实现公网全通:
R1:
[Huawei]interface loopback 0
[Huawei-LoopBack0]ip address 192.168.1.1 24
[Huawei-LoopBack0]quit
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 24.1.1.1 24[Huawei-GigabitEthernet0/0/0]quit
[Huawei]ip route-static 0.0.0.0 0.0.0.0 14.1.1.2
[Huawei]ip route-static 0.0.0.0 0.0.0.0 24.1.1.2
R2:
[Huawei]interface loopback 0
[Huawei-LoopBack0]ip address 192.168.2.1 24
[Huawei-LoopBack0]quit
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 34.1.1.1 24
[Huawei-GigabitEthernet0/0/0]quit
[Huawei]ip route-static 0.0.0.0 0.0.0.0 34.1.1.2
R3:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 192.168.3.1 24
[Huawei-LoopBack0]quit
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 44.1.1.1 24
[Huawei-GigabitEthernet0/0/0]quit
[Huawei]ip route-static 0.0.0.0 0.0.0.0 44.1.1.2
R4:
[Huawei-LoopBack0]ip address 192.168.4.1 24
[Huawei-LoopBack0]quit
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 54.1.1.1 24
[Huawei-GigabitEthernet0/0/0]quit
[Huawei]ip route-static 0.0.0.0 0.0.0.0 54.1.1.2
R5:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 192.168.5.1 24
[Huawei-LoopBack0]quit
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 64.1.1.1 24
[Huawei-GigabitEthernet0/0/0]quit
[Huawei]ip route-static 0.0.0.0 0.0.0.0 64.1.1.2
R6:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 4.4.4.1 24
[Huawei-LoopBack0]quit
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 14.1.1.2 24
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 24.1.1.2 24
[Huawei-GigabitEthernet0/0/0]quit
[Huawei]interface g0/0/2
[Huawei-GigabitEthernet0/0/2]ip address 34.1.1.2 24
[Huawei-GigabitEthernet0/0/2]quit
[Huawei]interface g2/0/0
[Huawei-GigabitEthernet2/0/0]ip address 44.1.1.2 24
[Huawei-GigabitEthernet2/0/0]quit
[Huawei]interface g3/0/0
[Huawei-GigabitEthernet3/0/0]ip address 54.1.1.2 24
[Huawei-GigabitEthernet3/0/0]quit
[Huawei]interface g4/0/0
[Huawei-GigabitEthernet4/0/0]ip address 64.1.1.2 24
此时,公网全通,如图:
3.创建MGRE
R1:
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip address 192.168.6.1 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source 14.1.1.1
[Huawei-Tunnel0/0/0]nhrp entry multicast dynamic
[Huawei-Tunnel0/0/0]q
[Huawei]interface Tunnel 0/0/1
[Huawei-Tunnel0/0/1]ip address 192.168.7.1 24
[Huawei-Tunnel0/0/1]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/1]source 24.1.1.1
[Huawei-Tunnel0/0/1]nhrp entry multicast dynamic
[Huawei-Tunnel0/0/1]q
R2:
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip address 192.168.7.2 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source g0/0/0
[Huawei-Tunnel0/0/0]nhrp entry 192.168.7.1 24.1.1.1 register
R3:
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip address 192.168.7.3 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source g0/0/0
[Huawei-Tunnel0/0/0]nhrp entry 192.168.7.1 24.1.1.1 register
R4:
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip address 192.168.6.2 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source 54.1.1.1
[Huawei-Tunnel0/0/0]nhrp entry 192.168.6.1 14.1.1.1 register
[Huawei-Tunnel0/0/0]nhrp entry 192.168.6.3 64.1.1.1 register
R5:
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip address 192.168.6.3 24
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source 64.1.1.1
[Huawei-Tunnel0/0/0]nhrp entry 192.168.6.1 14.1.1.1 register
[Huawei-Tunnel0/0/0]nhrp entry multicast dynamic
4.用ospf实现私网全通
注意要手工修改接口的工作方式为broadcast,注意将星型结构MGRE的非中心站点接口优先级改为0;
R1:
[Huawei]ospf 1 router-id 1.1.1.1
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.0.0 0.0.255.255
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast
[Huawei-Tunnel0/0/0]q
[Huawei]interface Tunnel 0/0/1
[Huawei-Tunnel0/0/1]ospf network-type broadcast
[Huawei-Tunnel0/0/1]q
R2:
[Huawei]ospf 1 router-id 2.2.2.2
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.0.0 0.0.255.255
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast
[Huawei-Tunnel0/0/0]ospf dr-priority 0
R3:
[Huawei]ospf 1 router-id 3.3.3.3
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.0.0 0.0.255.255
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast
[Huawei-Tunnel0/0/0]ospf dr-priority 0
R4:
[Huawei]ospf 1 router-id 4.4.4.4
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.0.0 0.0.255.255
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast
R5:
[Huawei]ospf 1 router-id 5.5.5.5
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.0.0 0.0.255.255
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q
[Huawei]interface Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast
此时,私网全通,如下图:
由于本实验使用环回接口代替真实主机,所以就算做了nat也无法ping通4.4.4.1,所以就不做了,但命令与上期实验的nat命令相同;