实验相关
实验要求
1、R4为ISP,其上只配置IP地址;R4与其他所直连设备间均使用公有IP;
2、R3-R5、R6、R7为MGRE环境,R3为中心站点;
3、整个OSPF环境IP基于172.16.0.0/16划分;除了R12有两个环回,其他路由器均有一个环回IP
4、所有设备均可访问R4的环回;
5、减少LSA的更新量,加快收敛,保障更新安全;
6、全网可达;
配置过程
OSPF宣告
R1
[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1-area-0.0.0.1]network 172.16.33.1 255.255.255.255
[R1-ospf-1-area-0.0.0.1]network 172.16.34.1 255.255.255.255
[R1-ospf-1-area-0.0.0.1]dis th
[V200R003C00]
#
area 0.0.0.1
network 172.16.33.1 0.0.0.0
network 172.16.34.1 0.0.0.0
#
return
[R1-ospf-1-area-0.0.0.1]
R2
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1-area-0.0.0.1]network 172.16.33.2 0.0.0.0
[R2-ospf-1-area-0.0.0.1]network 172.16.35.1 0.0.0.0
[R2-ospf-1-area-0.0.0.1]dis th
[V200R003C00]
#
area 0.0.0.1
network 172.16.33.2 0.0.0.0
network 172.16.35.1 0.0.0.0
#
return
R3
R3]ospf 1 router-id 3.3.3.3
[R3-ospf-1]a 1
[R3-ospf-1-area-0.0.0.1]ne 172.16.33.3 0.0.0.0
[R3-ospf-1-area-0.0.0.1]ne 172.16.36.1 0.0.0.0
[R3-ospf-1-area-0.0.0.1]dis th
[V200R003C00]
#
area 0.0.0.1
network 172.16.33.3 0.0.0.0
network 172.16.36.1 0.0.0.0
#
Return
R4
R5
[R5]ospf 1 router-id 5.5.5.5
[R5-ospf-1]a 0
[R5-ospf-1-area-0.0.0.0]ne 172.168.3.0 0.0.0.255
R6
[R6]ospf 1 router-id 6.6.6.6
[R6-ospf-1]a 0
[R6-ospf-1-area-0.0.0.0]ne 172.168.4.1 255.255.255.255
[R6-ospf-1]a 2
[R6-ospf-1-area-0.0.0.2]network 172.16.65.1 0.0.0.0
[R6-ospf-1]dis th
[V200R003C00]
#
ospf 1 router-id 6.6.6.6
area 0.0.0.0
network 172.168.4.1 0.0.0.0
area 0.0.0.2
network 172.16.65.1 0.0.0.0
#
R7
[R7]ospf 1 router-id 7.7.7.7
[R7-ospf-1]a 0
[R7-ospf-1-area-0.0.0.0]ne 172.16.5.1 255.255.255.255
[R7-ospf-1]a 3
[R7-ospf-1-area-0.0.0.3]ne 172.16.97.1 0.0.0.0
[R7-ospf-1]dis th
[V200R003C00]
#
ospf 1 router-id 7.7.7.7
area 0.0.0.0
network 172.16.5.1 0.0.0.0
area 0.0.0.3
network 172.16.97.1 0.0.0.0
#
R8
[R8]ospf 1 router-id 8.8.8.8
[R8-ospf-1]a 3
[R8-ospf-1-area-0.0.0.3]ne 172.16.98.0 0.0.0.255
[R8-ospf-1-area-0.0.0.3]network 172.16.97.2 0.0.0.0
[R8-ospf-1]dis th
[V200R003C00]
#
ospf 1 router-id 8.8.8.8
area 0.0.0.3
network 172.16.97.2 0.0.0.0
network 172.16.97.5 0.0.0.0
network 172.16.98.0 0.0.0.255
#
R9
[V200R003C00]
#
ospf 1 router-id 9.9.9.9
area 0.0.0.3
network 172.16.97.6 0.0.0.0
ospf 2
area 0.0.0.4
network 172.16.129.1 0.0.0.0
network 172.16.130.0 0.0.0.255
#
R10
[V200R003C00]
#
ospf 1 router-id 10.10.10.10
area 0.0.0.4
network 172.16.129.2 0.0.0.0
network 172.16.131.0 0.0.0.255
#
R11
[R11-ospf-1]dis th
[V200R003C00]
#
ospf 1 router-id 11.11.11.11
area 0.0.0.2
network 172.16.65.2 0.0.0.0
network 172.16.65.5 0.0.0.0
network 172.16.66.0 0.0.0.255
#
R12
[R12-ospf-1]dis th
[V200R003C00]
#
ospf 1 router-id 12.12.12.12
area 0.0.0.2
network 172.16.65.6 0.0.0.0
network 172.16.160.0 0.0.0.255
network 172.16.161.0 0.0.0.255
#
虚拟隧道
R3
[R3-Tunnel0/0/0]dis th
[V200R003C00]
#
interface Tunnel0/0/0
ip address 172.16.6.3 255.255.255.0
tunnel-protocol gre p2mp
nhrp entry multicast dynamic
nhrp network-id 100
#
R5
#
interface Tunnel0/0/0
ip address 172.16.6.5 255.255.255.0
tunnel-protocol gre p2mp
source Serial1/0/0
nhrp network-id 100
nhrp entry 172.16.6.3 34.0.0.3 register
#
R6
[R6-Tunnel0/0/0]dis th
[V200R003C00]
#
interface Tunnel0/0/0
ip address 172.16.6.6 255.255.255.0
tunnel-protocol gre p2mp
source Serial3/0/0
nhrp network-id 100
nhrp entry 172.16.6.3 34.0.0.3 register
#
R7
[R7-Tunnel0/0/0]dis th
[V200R003C00]
#
interface Tunnel0/0/0
ip address 172.16.6.7 255.255.255.0
tunnel-protocol gre p2mp
source GigabitEthernet0/0/0
nhrp network-id 100
nhrp entry 172.16.6.3 34.0.0.3 register
#
宣告虚拟隧道网段
ne 172.16.6.0 0.0.0.255
改变隧道类型
[R2-Tunnel0/0/0]ospf network-type broadcast
改变bdr选举优先级
Ospf dr-priority _
Ospf进程相互学习
[R9]ospf 1
[R9-ospf-1]import-route ospf 2
[R9-ospf-1]ospf 2
[R9-ospf-2]import-route ospf 1
全网已通
[R1]dis ip routing-table protocol ospf
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Public routing table : OSPF
Destinations : 16 Routes : 16
OSPF routing table status : <Active>
Destinations : 16 Routes : 16
Destination/Mask Proto Pre Cost Flags NextHop Interface
172.16.3.1/32 OSPF 10 1563 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.5.1/32 OSPF 10 1563 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.6.0/24 OSPF 10 1563 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.35.1/32 OSPF 10 1 D 172.16.33.2 GigabitEthernet
0/0/0
172.16.36.1/32 OSPF 10 1 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.65.0/30 OSPF 10 1564 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.65.4/30 OSPF 10 1565 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.66.11/32 OSPF 10 1564 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.97.0/30 OSPF 10 1564 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.97.4/30 OSPF 10 1565 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.98.1/32 OSPF 10 1564 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.129.0/30 O_ASE 150 1 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.130.0/24 O_ASE 150 1 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.131.1/32 O_ASE 150 1 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.160.0/24 O_ASE 150 1 D 172.16.33.3 GigabitEthernet
0/0/0
172.16.161.0/24 O_ASE 150 1 D 172.16.33.3 GigabitEthernet
0/0/0
OSPF routing table status : <Inactive>
Destinations : 0 Routes : 0
全网可以访问R4的环回
配置easy ip
R3
[R3]acl 2000
[R3-acl-basic-2000]rule permit so 172.16.0.0 0.0.255.255
[R3-acl-basic-2000]q
[R3]int s1/0/0
[R3-Serial1/0/0]nat outbound 2000
路由聚合 减少LSA的更新量,加快收敛,保障更新安全
区域内
[R3]ospf 1
[R3-ospf-1]a 1
[R3-ospf-1-area-0.0.0.1]abr-summary 172.16.32.0 255.255.224.0
[R6]ospf 1
[R6-ospf-1]a 2
[R6-ospf-1-area-0.0.0.2]abr-summary 172.16.64.0 255.255.224.0
[R7]ospf 1
[R7-ospf-1]a 3
[R7-ospf-1-area-0.0.0.3]abr-summary 172.16.96.0 255.255.224.0
区域外
[R12]ospf 1
[R12-ospf-1]asbr-summary 172.16.160.0 255.255.224.0
[R9]ospf 1
[R9-ospf-1]asbr-summary 172.16.128.0 255.255.224.0
由于仅仅使a 0区域减少了路由,现在还需要配置特殊区域
[R3]ospf 1
[R3-ospf-1]a 1
[R3-ospf-1-area-0.0.0.1]stub no-summary
R1 R2一样
[R6]ospf 1
[R6-ospf-1]a 2
[R6-ospf-1-area-0.0.0.2]nssa no-summary
R7,8,9,11,12一样
由于域内使用缺省路由,导致无法向区域外发送准确路由,所以在R9上给R10下发缺省路由
[R9]ospf 2
[R9-ospf-2]default-route-advertise
配置加快收敛速度
Int ______
ospf timer hello 5
公网不需要配置
配置保障更新安全
[R6]ospf
[R6-ospf-1]a 2
[R6-ospf-1-area-0.0.0.2]authentication-mode md5 1 cipher 12345
其他一样
公网不需要配置