题目:
第一步IP划分
R1:
R2:
R3:
R4:
R5:
R6:
R7:
检查IP:查看路由接口表或者ping对端IP地址
(1)[R1]display ip interface brief
(2)
第二步:宣告
R1:
[R1]rip
[R1-rip-1]v 2
[R1-rip-1]network 12.0.0.0
[R1-rip-1]network 14.0.0.0
[R1-rip-1]network 1.0.0.0
[R1-rip-1]network 172.16.0.0
R2:
[R2]rip
[R2-rip-1]v 2
[R2-rip-1]network 12.0.0.0
[R2-rip-1]network 23.0.0.0
[R2-rip-1]network 2.0.0.0
R3:
[R3]rip
[R3-rip-1]v 2
[R3-rip-1]network 23.0.0.0
[R3-rip-1]network 34.0.0.0
[R3-rip-1]network 3.0.0.0
R4:
[R4]rip
[R4-rip-1]v 2
[R4-rip-1]network 14.0.0.0
[R4-rip-1]network 34.0.0.0
[R4-rip-1]network 4.0.0.0
[R4-rip-1]network 45.0.0.0
[R4-rip-1] v 1
[R4-rip-1]network 46.0.0.0
R5:环回不用宣告,用来模拟运营商
[R5]rip
[R5-rip-1]v 2
[R5-rip-1]network 45.0.0.0
R6:
[R6]rip
[R6-rip-1]v 1
[R6-rip-1]network 46.0.0.0
[R6-rip-1]network 67.0.0.0
[R6-rip-1]network 6.0.0.0
R7:
[R7]rip
[R7-rip-1]v 1
[R7-rip-1]network 67.0.0.0
[R7-rip-1]network 7.0.0.0
第三步:汇总,减少路由条目
[R1]int g0/0/1
[R1-GigabitEthernet0/0/1]rip summary-address 172.16.0.0 255.255.252.0
[R1-GigabitEthernet0/0/1]int g0/0/0
[R1-GigabitEthernet0/0/0]rip summary-address 172.16.0.0 255.255.252.0
第四步:修改开销值,让R1的环回只走上面一条,不走负载均衡
修改前:
修改后:
[R3]acl 2000
[R3-acl-basic-2000]rule permit source 172.16.0.0 0
[R3-acl-basic-2000]rule permit source 1.1.1.0 0
[R3-acl-basic-2000]q
[R3]int g0/0/1
[R3-GigabitEthernet0/0/1]rip metricin 2000 10
[R3-GigabitEthernet0/0/1]display ip routing-table protocol rip
第五步:增加路由传递安全性,添加认证
R1:
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]rip authentication-mode md5 usual cipher 123456
R2:
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]rip authentication-mode md5 usual cipher 123456
第六步:创建缺省路由,让别的路由能访问R5的换回
创建缺省路由:
[R4]ip route-static 0.0.0.0 0 45.0.0.2
下发缺省路由给别的路由:
[R4]rip
[R4-rip-1]default-route originate
R1能ping通R5的环回了
第七步:修改R6路由器的0/0/0端口的RIP版本,让上下能互相ping通,做到全网可达
[R6]int g0/0/0
[R6-GigabitEthernet0/0/0]rip version 2
第八步:R1 telnet R2的换回实际 telnet 到R7上
R7:
[R7]aaa
[R7-aaa]local-user admin privilege level 15 password cipher 123456
[R7-aaa]local-user admin service-type telnet
[R7-aaa]q
[R7]user-interface vty 0 4
[R7-ui-vty0-4]authentication-mode aaa
R2:
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]nat server protocol tcp global interface loopback 0 23 inside 7.7.7.7 23
Warning:The port 23 is well-known port. If you continue it may cause function failure.
Are you sure to continue?[Y/N]:y
[R2]acl 2000
[R2-acl-basic-2000]rule permit source 7.0.0.0 0
[R2-acl-basic-2000]q
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]rip
[R2-GigabitEthernet0/0/0]rip metricout 2000 5
R4:
[R4]acl 2000
[R4-acl-basic-2000]rule permit source 12.0.0.0 0
[R4-acl-basic-2000]q
[R4]int g0/0/0
[R4-GigabitEthernet0/0/0]rip metricin 2000 10
第九步:路由过滤,让R6、R7不能学习到达R1的环回路由
[R6]acl 2000
[R6-acl-basic-2000]rule deny source 1.1.1.0 0
[R6-acl-basic-2000]rule deny source 172.16.0.0 0.0.255.255
[R6-acl-basic-2000]rule permit source any
[R6-acl-basic-2000]q
[R6]rip
[R6-rip-1]filter-policy 2000 import
[R6-rip-1]display ip routing-table