HCIP实验-OSPF综合大实验

实验拓扑图:

实验要求:

1.R4为ISP,其上只能配置IP地址;R4与其他所有直连设备间使用公有IP;

2.R3...R5/6/7为MGRE环境,R3为中心站点;

3.整个OSPF环境IP地址为172.16.0.0/16;

4.所有设备均能访问R4的环回;

5.减少LSA的更新信息;

6.全网可达

实验过程:

1.IP地址规划:

公网随机给

私网基于172.16.0.0 /16进行合理划分

由拓扑图可知其私网分为6个区域,先将给定地址借3位分为8个子网,6个分配给6个区域,其余两个保留,在具体按各自区域的情况进一步划分,本实验地址规划如下图:

2.基础配置,实现公网通

R1:

[Huawei]interface LoopBack 0

[Huawei-LoopBack0]ip address 172.16.33.129 25

[Huawei-LoopBack0]q

[Huawei]interface g0/0/0

[Huawei-GigabitEthernet0/0/0]ip address 172.16.32.129 29

R2:

[Huawei]interface LoopBack 0

[Huawei-LoopBack0]ip address 172.16.34.1 25

[Huawei-LoopBack0]q

[Huawei]interface g0/0/0

[Huawei-GigabitEthernet0/0/0]ip address 172.16.32.130 29

R3:

[Huawei]interface LoopBack 0

[Huawei-LoopBack0]ip address 172.16.34.129 25

[Huawei-LoopBack0]q

[Huawei]interface g0/0/0

[Huawei-GigabitEthernet0/0/0]ip address 172.16.32.131 29

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]ip add 12.1.1.2 24

[Huawei-GigabitEthernet0/0/1]q

[Huawei]ip route-static 0.0.0.0 0 12.1.1.1

R4:

[Huawei]int l0

[Huawei-LoopBack0]ip add 4.4.4.4 24

[Huawei-LoopBack0]q

[Huawei]int g0/0/0

[Huawei-GigabitEthernet0/0/0]ip add 12.1.1.1 24

[Huawei-GigabitEthernet0/0/0]q

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]ip add 42.1.1.1 24

[Huawei-GigabitEthernet0/0/1]q

[Huawei]int g0/0/2

[Huawei-GigabitEthernet0/0/2]ip add 32.1.1.1 24

[Huawei-GigabitEthernet0/0/2]q

[Huawei]int g4/0/0

[Huawei-GigabitEthernet4/0/0]ip add 22.1.1.1 24

[Huawei-GigabitEthernet4/0/0]q

R5:

[Huawei]int l0

[Huawei-LoopBack0]ip add 172.16.1.1 25

[Huawei-LoopBack0]q

[Huawei]int g0/0/0

[Huawei-GigabitEthernet0/0/0]ip add 42.1.1.2 24

[Huawei-GigabitEthernet0/0/0]q

[Huawei]ip route-static 0.0.0.0 0 42.1.1.1

R6:

[Huawei]int l0

[Huawei-LoopBack0]ip add 172.16.1.129 25

[Huawei-LoopBack0]q

[Huawei]int g0/0/0

[Huawei-GigabitEthernet0/0/0]ip add 32.1.1.2 24

[Huawei-GigabitEthernet0/0/0]q

[Huawei]ip route-static 0.0.0.0 0 32.1.1.1

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]ip add 172.16.65.1 30

R7:

[Huawei]int l0

[Huawei-LoopBack0]ip add 172.16.2.129 25

[Huawei-LoopBack0]q

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]ip add 22.1.1.2 24

[Huawei-GigabitEthernet0/0/1]q

[Huawei]ip route-static 0.0.0.0 0 22.1.1.1

[Huawei]int g0/0/0

[Huawei-GigabitEthernet0/0/0]ip add 172.16.96.1 30

R8:

[Huawei]int l0

[Huawei-LoopBack0]ip add 172.16.97.1 25

[Huawei-LoopBack0]q

[Huawei]int g0/0/0

[Huawei-GigabitEthernet0/0/0]ip add 172.16.96.2 30

[Huawei-GigabitEthernet0/0/0]q

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]ip add 172.16.96.5 30

R9:

[Huawei]int l0

[Huawei-LoopBack0]ip add 172.16.129.1 25

[Huawei-LoopBack0]q

[Huawei]int g0/0/0

[Huawei-GigabitEthernet0/0/0]ip add 172.16.96.6 30

[Huawei-GigabitEthernet0/0/0]q

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]ip add 172.16.128.1 30

R10:

[Huawei]int l0

[Huawei-LoopBack0]ip add 172.16.129.129 25

[Huawei-LoopBack0]q

[Huawei]int g0/0/0

[Huawei-GigabitEthernet0/0/0]ip add 172.16.128.2 30

R11:

[Huawei]int l0

[Huawei-LoopBack0]ip add 172.16.65.1 25

[Huawei-LoopBack0]q

[Huawei]int g0/0/0

[Huawei-GigabitEthernet0/0/0]ip add 172.16.64.2 30

[Huawei-GigabitEthernet0/0/0]q

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]ip add 172.16.64.5 30

R12:

[Huawei]int l0

[Huawei-LoopBack0]ip add 172.16.161.1 25

[Huawei-LoopBack0]q

[Huawei]int l1

[Huawei-LoopBack1]ip add 172.16.161.129 25

[Huawei-LoopBack1]q

[Huawei]int g0/0/0

[Huawei-GigabitEthernet0/0/0]ip add 172.16.64.6 30

此时,公网通,如图:

3.做MGRE,做通道

R3:

[Huawei]int Tunnel 0/0/0

[Huawei-Tunnel0/0/0]ip add 172.16.0.129 29

[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp

[Huawei-Tunnel0/0/0]source 12.1.1.2

[Huawei-Tunnel0/0/0]nhrp entry multicast dynamic

R5:

[Huawei]int Tunnel 0/0/0

[Huawei-Tunnel0/0/0]ip add 172.16.0.130 29

[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp

[Huawei-Tunnel0/0/0]source g0/0/0

[Huawei-Tunnel0/0/0]nhrp entry 172.16.0.129 12.1.1.2 register

R6:

[Huawei]int Tunnel 0/0/0

[Huawei-Tunnel0/0/0]ip add 172.16.0.131 29

[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp

[Huawei-Tunnel0/0/0]source g0/0/0

[Huawei-Tunnel0/0/0]nhrp entry 172.16.0.129 12.1.1.2 register

R7:

[Huawei]int Tunnel 0/0/0

[Huawei-Tunnel0/0/0]ip add 172.16.0.132 29

[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp

[Huawei-Tunnel0/0/0]source g0/0/1

[Huawei-Tunnel0/0/0]nhrp entry 172.16.0.129 12.1.1.2 register

4.启ospf,实现私网通

R1:

[Huawei]ospf 1 router-id 1.1.1.1

[Huawei-ospf-1]area 1

[Huawei-ospf-1-area-0.0.0.1]network 172.16.33.129 0.0.0.0

[Huawei-ospf-1-area-0.0.0.1]network 172.16.32.129 0.0.0.0

R2:

[Huawei]ospf 1 router-id 2.2.2.2

[Huawei-ospf-1]area 1

[Huawei-ospf-1-area-0.0.0.1]network 172.16.34.1 0.0.0.0

[Huawei-ospf-1-area-0.0.0.1]network 172.16.32.130 0.0.0.0

R3:

[Huawei]ospf 1 router-id 3.3.3.3

[Huawei-ospf-1]area 1

[Huawei-ospf-1-area-0.0.0.1]network 172.16.34.129 0.0.0.0

[Huawei-ospf-1-area-0.0.0.1]network 172.16.32.131 0.0.0.0

[Huawei-ospf-1-area-0.0.0.1]q

[Huawei-ospf-1]area 0

[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.129 0.0.0.0

[Huawei-ospf-1-area-0.0.0.0]q

[Huawei-ospf-1]q

[Huawei]int Tunnel 0/0/0

[Huawei-Tunnel0/0/0]ospf network-type broadcast

R5:

[Huawei]int Tunnel 0/0/0

[Huawei-Tunnel0/0/0]ospf network-type broadcast

[Huawei-Tunnel0/0/0]ospf dr-priority 0

[Huawei-Tunnel0/0/0]q

[Huawei]ospf 1 router-id 5.5.5.5

[Huawei-ospf-1]area 0

[Huawei-ospf-1-area-0.0.0.0]network 172.16.1.1 0.0.0.0

[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.130 0.0.0.0

R6:

[Huawei]int Tunnel 0/0/0

[Huawei-Tunnel0/0/0]ospf network-type broadcast

[Huawei-Tunnel0/0/0]ospf dr-priority 0

[Huawei-Tunnel0/0/0]q

[Huawei]ospf 1 router-id 6.6.6.6

[Huawei-ospf-1]area 0

[Huawei-ospf-1-area-0.0.0.0]network 172.16.1.129 0.0.0.0

[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.131 0.0.0.0

[Huawei-ospf-1-area-0.0.0.0]q

[Huawei-ospf-1]area 2

[Huawei-ospf-1-area-0.0.0.2]network 172.16.64.1 0.0.0.0

R7:

[Huawei]int Tunnel 0/0/0

[Huawei-Tunnel0/0/0]ospf network-type broadcast

[Huawei-Tunnel0/0/0]ospf dr-priority 0

[Huawei-Tunnel0/0/0]q

[Huawei]ospf 1 router-id 7.7.7.7

[Huawei-ospf-1]area 0

[Huawei-ospf-1-area-0.0.0.0]network 172.16.2.129 0.0.0.0

[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.132 0.0.0.0

[Huawei-ospf-1-area-0.0.0.0]q

[Huawei-ospf-1]area 3

[Huawei-ospf-1-area-0.0.0.2]network 172.16.96.1 0.0.0.0

R8:

[Huawei]ospf 1 router-id 8.8.8.8

[Huawei-ospf-1]area 3

[Huawei-ospf-1-area-0.0.0.3]network 172.16.97.1 0.0.0.0

[Huawei-ospf-1-area-0.0.0.3]network 172.16.96.2 0.0.0.0

[Huawei-ospf-1-area-0.0.0.3]network 172.16.96.5 0.0.0.0

R9:

[Huawei]ospf 1 router-id 9.9.9.9

[Huawei-ospf-1]area 3

[Huawei-ospf-1-area-0.0.0.3]network 172.16.96.6 0.0.0.0

[Huawei-ospf-1-area-0.0.0.3]q

[Huawei-ospf-1]q

[Huawei]ospf 2 router-id 90.90.90.90

[Huawei-ospf-2]area 4

[Huawei-ospf-2-area-0.0.0.4]network 172.16.129.1 0.0.0.0

[Huawei-ospf-2-area-0.0.0.4]network 172.16.128.1 0.0.0.0

[Huawei-ospf-2-area-0.0.0.4]q

[Huawei-ospf-2]q

[Huawei]ospf 1

[Huawei-ospf-1]import-route ospf 2

[Huawei-ospf-1]q

[Huawei]ospf 2

[Huawei-ospf-2]import-route ospf 1

R10:

[Huawei]ospf 1 router-id 10.10.10.10

[Huawei-ospf-1]area 4

[Huawei-ospf-1-area-0.0.0.4]network 172.16.129.129 0.0.0.0

[Huawei-ospf-1-area-0.0.0.4]network 172.16.128.2 0.0.0.0

R11:

[Huawei]ospf 1 router-id 11.11.11.11

[Huawei-ospf-1]area 2

[Huawei-ospf-1-area-0.0.0.2]network 172.16.65.1 0.0.0.0

[Huawei-ospf-1-area-0.0.0.2]network 172.16.64.5 0.0.0.0

[Huawei-ospf-1-area-0.0.0.2]network 172.16.64.2 0.0.0.0

R12:

[Huawei]ospf 1 router-id 12.12.12.12

[Huawei-ospf-1]area 2

[Huawei-ospf-1-area-0.0.0.2]network 172.16.64.6 0.0.0.0

[Huawei]rip 1

[Huawei-rip-1]version 2

[Huawei-rip-1]network 172.16.0.0

[Huawei-rip-1]q

[Huawei]ospf

[Huawei-ospf-1]import-route rip

此时,私网全通,如图:

5.做优化

做汇总减少骨干区域的LSA

R3:

[Huawei]ospf

[Huawei-ospf-1]area 1

[Huawei-ospf-1-area-0.0.0.1]abr-summary 172.16.32.0 255.255.224.0

[Huawei-ospf-1-area-0.0.0.1]q

[Huawei-ospf-1]q

[Huawei]ip route-static 172.16.32.0 255.255.224.0 null 0

R6:

[Huawei]ospf

[Huawei-ospf-1]area 2

[Huawei-ospf-1-area-0.0.0.2]abr-summary 172.16.64.0 255.255.224.0

[Huawei-ospf-1-area-0.0.0.2]q

[Huawei-ospf-1]q

[Huawei]ip route-static 172.16.64.0 255.255.224.0 null 0

R7:

[Huawei]ospf 1

[Huawei-ospf-1]area 3

[Huawei-ospf-1-area-0.0.0.3]abr-summary 172.16.96.0 255.255.224.0

[Huawei-ospf-1-area-0.0.0.3]q

[Huawei-ospf-1]q

[Huawei]ip route-static 172.16.96.0 255.255.224.0 null 0

R9:

[Huawei]ospf

[Huawei-ospf-1]asbr-summary 172.16.128.0 255.255.224.0

[Huawei-ospf-1]q

[Huawei]ip route-static 172.16.128.0 255.255.224.0 null 0

R12:

[Huawei]ospf

[Huawei-ospf-1]asbr-summary 172.16.161.0 255.255.255.0

[Huawei-ospf-1]q

[Huawei]ip route-static 172.16.161.0 255.255.224.0 null 0

此时,汇总后骨干区域的ospf路由表简化如下:

特殊区域减少区域内的LSA

将区域1调为完全末梢区域

R1:

[Huawei]ospf

[Huawei-ospf-1]area 1

[Huawei-ospf-1-area-0.0.0.1]stub

R2:

[Huawei]ospf

[Huawei-ospf-1]area 1

[Huawei-ospf-1-area-0.0.0.1]stub

R3:

[Huawei]ospf

[Huawei-ospf-1]area 1

[Huawei-ospf-1-area-0.0.0.1]stub

[Huawei-ospf-1-area-0.0.0.1]stub no-summary

此时,区域1内简化后的ospf路由表如下图:

将区域3调为完全 nssa

R7:

[Huawei]ospf

[Huawei-ospf-1]area 3

[Huawei-ospf-1-area-0.0.0.3]nssa

[Huawei-ospf-1-area-0.0.0.3]nssa no-summary

R8:

[Huawei]ospf

[Huawei-ospf-1]area 3

[Huawei-ospf-1-area-0.0.0.3]nssa

R9:

[Huawei]ospf

[Huawei-ospf-1]area 3

[Huawei-ospf-1-area-0.0.0.3]nssa

此时,区域3内简化后ospf的路由表如下图:

将区域2调为完全 nssa

R6:

[Huawei]ospf

[Huawei-ospf-1]area 2

[Huawei-ospf-1-area-0.0.0.2]nssa

[Huawei-ospf-1-area-0.0.0.2]nssa no-summary

R11:

[Huawei]ospf

[Huawei-ospf-1]area 2

[Huawei-ospf-1-area-0.0.0.2]nssa

r12:

[Huawei]ospf

[Huawei-ospf-1]area 2

[Huawei-ospf-1-area-0.0.0.2]nssa

此时,区域2内简化后的ospf路由表如下图:

做完以上操作后,区域4只能访问区域3,因为区域3只有自己的路由和一条缺省,重发布进区域4后仅有区域3的路由,缺省不能重发布,此时的最优解时将区域3向区域4的重发布取消,直接一条缺省指向区域3;

R9:

[Huawei]ospf 2

[Huawei-ospf-2]undo import-route ospf 1

[Huawei-ospf-2]default-route-advertise always

此时区域4的ospf路由表:

6.在私网的边界路由器上做nat确保私网可以访问公网

缺省已齐,直接做nat

R3:

[Huawei]acl 2000

[Huawei-acl-basic-2000]rule permit source 172.16.32.0 0.0.31.255

[Huawei-acl-basic-2000]q

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]nat outbound 2000

R6:

[Huawei]acl 2000

[Huawei-acl-basic-2000]rule permit source 172.16.64.0 0.0.31.255

[Huawei-acl-basic-2000]rule permit source 172.16.160.0 0.0.31.255

[Huawei-acl-basic-2000]q

[Huawei]int g0/0/0

[Huawei-GigabitEthernet0/0/1]nat outbound 2000

R7:

[Huawei]acl 2000

[Huawei-acl-basic-2000]rule permit source 172.16.96.0 0.0.31.255

[Huawei-acl-basic-2000]rule permit source 172.16.128.0 0.0.31.255

[Huawei-acl-basic-2000]q

[Huawei]int g0/0/1

[Huawei-GigabitEthernet0/0/1]nat outbound 2000

效果图:

  • 13
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值