实验拓扑图:
实验要求:
1.R4为ISP,其上只能配置IP地址;R4与其他所有直连设备间使用公有IP;
2.R3...R5/6/7为MGRE环境,R3为中心站点;
3.整个OSPF环境IP地址为172.16.0.0/16;
4.所有设备均能访问R4的环回;
5.减少LSA的更新信息;
6.全网可达
实验过程:
1.IP地址规划:
公网随机给
私网基于172.16.0.0 /16进行合理划分
由拓扑图可知其私网分为6个区域,先将给定地址借3位分为8个子网,6个分配给6个区域,其余两个保留,在具体按各自区域的情况进一步划分,本实验地址规划如下图:
2.基础配置,实现公网通
R1:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 172.16.33.129 25
[Huawei-LoopBack0]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 172.16.32.129 29
R2:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 172.16.34.1 25
[Huawei-LoopBack0]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 172.16.32.130 29
R3:
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 172.16.34.129 25
[Huawei-LoopBack0]q
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 172.16.32.131 29
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 12.1.1.2 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ip route-static 0.0.0.0 0 12.1.1.1
R4:
[Huawei]int l0
[Huawei-LoopBack0]ip add 4.4.4.4 24
[Huawei-LoopBack0]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 12.1.1.1 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 42.1.1.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]int g0/0/2
[Huawei-GigabitEthernet0/0/2]ip add 32.1.1.1 24
[Huawei-GigabitEthernet0/0/2]q
[Huawei]int g4/0/0
[Huawei-GigabitEthernet4/0/0]ip add 22.1.1.1 24
[Huawei-GigabitEthernet4/0/0]q
R5:
[Huawei]int l0
[Huawei-LoopBack0]ip add 172.16.1.1 25
[Huawei-LoopBack0]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 42.1.1.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ip route-static 0.0.0.0 0 42.1.1.1
R6:
[Huawei]int l0
[Huawei-LoopBack0]ip add 172.16.1.129 25
[Huawei-LoopBack0]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 32.1.1.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ip route-static 0.0.0.0 0 32.1.1.1
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 172.16.65.1 30
R7:
[Huawei]int l0
[Huawei-LoopBack0]ip add 172.16.2.129 25
[Huawei-LoopBack0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 22.1.1.2 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ip route-static 0.0.0.0 0 22.1.1.1
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 172.16.96.1 30
R8:
[Huawei]int l0
[Huawei-LoopBack0]ip add 172.16.97.1 25
[Huawei-LoopBack0]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 172.16.96.2 30
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 172.16.96.5 30
R9:
[Huawei]int l0
[Huawei-LoopBack0]ip add 172.16.129.1 25
[Huawei-LoopBack0]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 172.16.96.6 30
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 172.16.128.1 30
R10:
[Huawei]int l0
[Huawei-LoopBack0]ip add 172.16.129.129 25
[Huawei-LoopBack0]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 172.16.128.2 30
R11:
[Huawei]int l0
[Huawei-LoopBack0]ip add 172.16.65.1 25
[Huawei-LoopBack0]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 172.16.64.2 30
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 172.16.64.5 30
R12:
[Huawei]int l0
[Huawei-LoopBack0]ip add 172.16.161.1 25
[Huawei-LoopBack0]q
[Huawei]int l1
[Huawei-LoopBack1]ip add 172.16.161.129 25
[Huawei-LoopBack1]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 172.16.64.6 30
此时,公网通,如图:
3.做MGRE,做通道
R3:
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip add 172.16.0.129 29
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source 12.1.1.2
[Huawei-Tunnel0/0/0]nhrp entry multicast dynamic
R5:
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip add 172.16.0.130 29
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source g0/0/0
[Huawei-Tunnel0/0/0]nhrp entry 172.16.0.129 12.1.1.2 register
R6:
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip add 172.16.0.131 29
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source g0/0/0
[Huawei-Tunnel0/0/0]nhrp entry 172.16.0.129 12.1.1.2 register
R7:
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ip add 172.16.0.132 29
[Huawei-Tunnel0/0/0]tunnel-protocol gre p2mp
[Huawei-Tunnel0/0/0]source g0/0/1
[Huawei-Tunnel0/0/0]nhrp entry 172.16.0.129 12.1.1.2 register
4.启ospf,实现私网通
R1:
[Huawei]ospf 1 router-id 1.1.1.1
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]network 172.16.33.129 0.0.0.0
[Huawei-ospf-1-area-0.0.0.1]network 172.16.32.129 0.0.0.0
R2:
[Huawei]ospf 1 router-id 2.2.2.2
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]network 172.16.34.1 0.0.0.0
[Huawei-ospf-1-area-0.0.0.1]network 172.16.32.130 0.0.0.0
R3:
[Huawei]ospf 1 router-id 3.3.3.3
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]network 172.16.34.129 0.0.0.0
[Huawei-ospf-1-area-0.0.0.1]network 172.16.32.131 0.0.0.0
[Huawei-ospf-1-area-0.0.0.1]q
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.129 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast
R5:
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast
[Huawei-Tunnel0/0/0]ospf dr-priority 0
[Huawei-Tunnel0/0/0]q
[Huawei]ospf 1 router-id 5.5.5.5
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 172.16.1.1 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.130 0.0.0.0
R6:
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast
[Huawei-Tunnel0/0/0]ospf dr-priority 0
[Huawei-Tunnel0/0/0]q
[Huawei]ospf 1 router-id 6.6.6.6
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 172.16.1.129 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.131 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]area 2
[Huawei-ospf-1-area-0.0.0.2]network 172.16.64.1 0.0.0.0
R7:
[Huawei]int Tunnel 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast
[Huawei-Tunnel0/0/0]ospf dr-priority 0
[Huawei-Tunnel0/0/0]q
[Huawei]ospf 1 router-id 7.7.7.7
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 172.16.2.129 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.132 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.2]network 172.16.96.1 0.0.0.0
R8:
[Huawei]ospf 1 router-id 8.8.8.8
[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.3]network 172.16.97.1 0.0.0.0
[Huawei-ospf-1-area-0.0.0.3]network 172.16.96.2 0.0.0.0
[Huawei-ospf-1-area-0.0.0.3]network 172.16.96.5 0.0.0.0
R9:
[Huawei]ospf 1 router-id 9.9.9.9
[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.3]network 172.16.96.6 0.0.0.0
[Huawei-ospf-1-area-0.0.0.3]q
[Huawei-ospf-1]q
[Huawei]ospf 2 router-id 90.90.90.90
[Huawei-ospf-2]area 4
[Huawei-ospf-2-area-0.0.0.4]network 172.16.129.1 0.0.0.0
[Huawei-ospf-2-area-0.0.0.4]network 172.16.128.1 0.0.0.0
[Huawei-ospf-2-area-0.0.0.4]q
[Huawei-ospf-2]q
[Huawei]ospf 1
[Huawei-ospf-1]import-route ospf 2
[Huawei-ospf-1]q
[Huawei]ospf 2
[Huawei-ospf-2]import-route ospf 1
R10:
[Huawei]ospf 1 router-id 10.10.10.10
[Huawei-ospf-1]area 4
[Huawei-ospf-1-area-0.0.0.4]network 172.16.129.129 0.0.0.0
[Huawei-ospf-1-area-0.0.0.4]network 172.16.128.2 0.0.0.0
R11:
[Huawei]ospf 1 router-id 11.11.11.11
[Huawei-ospf-1]area 2
[Huawei-ospf-1-area-0.0.0.2]network 172.16.65.1 0.0.0.0
[Huawei-ospf-1-area-0.0.0.2]network 172.16.64.5 0.0.0.0
[Huawei-ospf-1-area-0.0.0.2]network 172.16.64.2 0.0.0.0
R12:
[Huawei]ospf 1 router-id 12.12.12.12
[Huawei-ospf-1]area 2
[Huawei-ospf-1-area-0.0.0.2]network 172.16.64.6 0.0.0.0
[Huawei]rip 1
[Huawei-rip-1]version 2
[Huawei-rip-1]network 172.16.0.0
[Huawei-rip-1]q
[Huawei]ospf
[Huawei-ospf-1]import-route rip
此时,私网全通,如图:
5.做优化
做汇总减少骨干区域的LSA
R3:
[Huawei]ospf
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]abr-summary 172.16.32.0 255.255.224.0
[Huawei-ospf-1-area-0.0.0.1]q
[Huawei-ospf-1]q
[Huawei]ip route-static 172.16.32.0 255.255.224.0 null 0
R6:
[Huawei]ospf
[Huawei-ospf-1]area 2
[Huawei-ospf-1-area-0.0.0.2]abr-summary 172.16.64.0 255.255.224.0
[Huawei-ospf-1-area-0.0.0.2]q
[Huawei-ospf-1]q
[Huawei]ip route-static 172.16.64.0 255.255.224.0 null 0
R7:
[Huawei]ospf 1
[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.3]abr-summary 172.16.96.0 255.255.224.0
[Huawei-ospf-1-area-0.0.0.3]q
[Huawei-ospf-1]q
[Huawei]ip route-static 172.16.96.0 255.255.224.0 null 0
R9:
[Huawei]ospf
[Huawei-ospf-1]asbr-summary 172.16.128.0 255.255.224.0
[Huawei-ospf-1]q
[Huawei]ip route-static 172.16.128.0 255.255.224.0 null 0
R12:
[Huawei]ospf
[Huawei-ospf-1]asbr-summary 172.16.161.0 255.255.255.0
[Huawei-ospf-1]q
[Huawei]ip route-static 172.16.161.0 255.255.224.0 null 0
此时,汇总后骨干区域的ospf路由表简化如下:
特殊区域减少区域内的LSA
将区域1调为完全末梢区域
R1:
[Huawei]ospf
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]stub
R2:
[Huawei]ospf
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]stub
R3:
[Huawei]ospf
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]stub
[Huawei-ospf-1-area-0.0.0.1]stub no-summary
此时,区域1内简化后的ospf路由表如下图:
将区域3调为完全 nssa
R7:
[Huawei]ospf
[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.3]nssa
[Huawei-ospf-1-area-0.0.0.3]nssa no-summary
R8:
[Huawei]ospf
[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.3]nssa
R9:
[Huawei]ospf
[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.3]nssa
此时,区域3内简化后ospf的路由表如下图:
将区域2调为完全 nssa
R6:
[Huawei]ospf
[Huawei-ospf-1]area 2
[Huawei-ospf-1-area-0.0.0.2]nssa
[Huawei-ospf-1-area-0.0.0.2]nssa no-summary
R11:
[Huawei]ospf
[Huawei-ospf-1]area 2
[Huawei-ospf-1-area-0.0.0.2]nssa
r12:
[Huawei]ospf
[Huawei-ospf-1]area 2
[Huawei-ospf-1-area-0.0.0.2]nssa
此时,区域2内简化后的ospf路由表如下图:
做完以上操作后,区域4只能访问区域3,因为区域3只有自己的路由和一条缺省,重发布进区域4后仅有区域3的路由,缺省不能重发布,此时的最优解时将区域3向区域4的重发布取消,直接一条缺省指向区域3;
R9:
[Huawei]ospf 2
[Huawei-ospf-2]undo import-route ospf 1
[Huawei-ospf-2]default-route-advertise always
此时区域4的ospf路由表:
6.在私网的边界路由器上做nat确保私网可以访问公网
缺省已齐,直接做nat
R3:
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 172.16.32.0 0.0.31.255
[Huawei-acl-basic-2000]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]nat outbound 2000
R6:
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 172.16.64.0 0.0.31.255
[Huawei-acl-basic-2000]rule permit source 172.16.160.0 0.0.31.255
[Huawei-acl-basic-2000]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/1]nat outbound 2000
R7:
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 172.16.96.0 0.0.31.255
[Huawei-acl-basic-2000]rule permit source 172.16.128.0 0.0.31.255
[Huawei-acl-basic-2000]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]nat outbound 2000
效果图: