配这个会疯

实验图

实验步骤:

子网划分,IP地址规划如上图

1.配置IP和环回地址

R1: 

[R1]int G 0/0/0

[R1-GigabitEthernet0/0/1]ip address 172.16.16.1  29

[R1]int LoopBack 0

[R1-LoopBack0]ip address 172.16.17.1  24

R2: 

[R2]int G 0/0/0

[R2-GigabitEthernet0/0/0]ip address 172.16.16.2  29

[R2]int LoopBack 0

[R2-LoopBack0]ip address 172.16.18.1 24

R3: 

[R3]int G 0/0/0

[R3-GigabitEthernet0/0/0]ip address 172.16.16.3  

29

[R3]int S 4/0/0

[R3-Serial4/0/0/0]ip address 35.1.1.3 24

[R3]int LoopBack 0

[R3-LoopBack0]ip address 172.16.19.1 24

R4: 

[R4]int S 4/0/0

[R4-Serial4/0/0/0]ip address 45.1.1.4 24

[R4]int S 4/0/1

[R4-Serial4/0/0/1]ip address 25.1.1.1 24

[R4]int S 3/0/0

[R4-Serial3/0/0/0]ip address 35.1.1.4 24

[R4]int G 0/0/0

[R4-GigabitEthernet0/0/0]ip address 45.1.1.4 24

[R4]int LoopBack 0

[R4-LoopBack0]ip address 4.4.4.4 24

R5: 

[R5]int S 4/0/0

[R5-Serial4/0/0/0]ip address 54.1.1.2 24

[R5]int LoopBack 0

[R5-LoopBack0]ip address 172.16.1.1 24

R6: 

[R6]int S 4/0/0

[R6-Serial4/0/0/0]ip address 64.1.1.6 24

[R6]int G 0/0/0

[R6-GigabitEthernet0/0/0]ip address 172.16.32.1 30

[R6]int LoopBack 0

[R6-LoopBack0]ip address 172.16.2.1  24

R7: 

[R7]int G 0/0/0

[R7-GigabitEthernet0/0/0]ip address 74.1.1.7 24

[R7]int G 0/0/1

[R7-GigabitEthernet0/0/1]ip address 172.16.48.1  30

[R7]int LoopBack 0

[R7-LoopBack0]ip address 172.16.3.1  24

R8: 

[R8]int G 0/0/0

[R8-GigabitEthernet0/0/0]ip address 172.16.48.2 30

[R8]int G 0/0/1

[R8-GigabitEthernet0/0/1]ip address 1720.16.48.5 30

[R8]int LoopBack 0

[R8-LoopBack0]ip address 172.16.49.1  24

R9: 

[R9]int G 0/0/0

[R9-GigabitEthernet0/0/0]ip address 172.16.48.6 30

[R9]int G 0/0/1

[R9-GigabitEthernet0/0/1]ip address 172.16.66.1 30

[R9]int LoopBack 0

[R9-LoopBack0]ip address 172.16.64.1  24

R10: 

[R10]int G 0/0/0

[R10-GigabitEthernet0/0/0]ip address 172.16.66.2 30

[R10]int LoopBack 0

[R10-LoopBack0]ip address 172.16.65.1  24

R11: 

[R11]int G 0/0/0

[R11-GigabitEthernet0/0/0]ip address 172.16.32.2 30

[R11]int G 0/0/1

[R11-GigabitEthernet0/0/1]ip address 172.16.32.5 30

[R11]int LoopBack 0

[R11-LoopBack0]ip address 172.16.33.1  24

R12: 

[R12]int G 0/0/0

[R12-GigabitEthernet0/0/0]ip address 172.16.32.6 30

[R12]int LoopBack 0

[R12-LoopBack0]ip address 172.16.128.1  18

[R12]int LoopBack 1

[R12-LoopBack1]ip address 172.16.192.1  18

2.对R3R5R6R7配置缺省路由

[R3]IP route-static 0.0.0.0 0 15.1.1.2

[R5]IP route-static 0.0.0.0 0 25.1.1.1

[R6]IP route-static 0.0.0.0 0 35.1.1.1

[R7]IP route-static 0.0.0.0 0 45.1.1.1

3.R3-R5R6R7构建MGRE环境,R3为中心站点,R4R5R6R7为分支站点。

R3配置: 

[R3]int T 0/0/0 创建隧道

[R3-Tunnel0/0/0]ip address 172.16.0.1 24

//接口配置IP

[R3-Tunnel0/0/0]tunnel-protocol gre p2mp 接口模式为多点GRE

[R3-Tunnel0/0/0]source 15.1.1.1 定义公有源IP地址

[R3-Tunnel0/0/0]Ospf Network-type broadcast 修改MGRE网段接口工作方式,加快收敛。

[R3-Tunnel0/0/0]ospf timer hello 5 //10s以内

[R3-Tunnel0/0/0]Nhrp entry multicast dynamic

//定义本地成为NHRP中心

[R3-Tunnel0/0/0]nhrp network-id 100

[R3-Tunnel0/0/0]q

[R3]ospf 1 route-id 3.3.3.3//各个网段宣告ospf

[R3-ospf-1]area 0

[R3-ospf-1-area 0]network 172.16.0.1  0.0.0.0

[R3-ospf-1-area 0]q

[R3-ospf-1]area 1

[R3-ospf-1-area 1]network 172.16.16.3  0.0.0.0

[R3-ospf-1-area 1]abr-summary 172.16.16.0  255.255.240.0 //优化网络,尽量减少LSA更新量,在R3R6R7手工汇总,尽量减少骨干区域area0的LSA更新量。汇总R3R6R7上的三类lsa

[R3-ospf-1-area 1]stub summary

[R3-ospf-1-area 1] authentication-mode md5 1 cipher 123456

R4配置: 

[R4]int T 0/0/0

[R4-Tunnel0/0/0]ip address 172.16.0.2 24

[R4-Tunnel0/0/0]tunnel-protocol gre p2mp

[R4-Tunnel0/0/0]source S4/0/0

[R4-Tunnel0/0/0]Ospf Network-type broadcast

[R4-Tunnel0/0/0]ospf timer hello 5

[R4-Tunnel0/0/0]nhrp entry 172.16.0.1 15.1.1.1 register

[R4-Tunnel0/0/0]nhrp network-id 100

[R4-Tunnel0/0/0]q

[R4]ospf 1 route-id 4.4.4.4

[R4-ospf-1]area 0

[R4-ospf-1-area 0]network 172.16.0.2  0.0.0.0

[R4-ospf-1-area 0]network 4.4.4.4  0.0.0.0

R5配置: 

[R5]int T 0/0/0

[R5-Tunnel0/0/0]ip address 172.16.0.3 24

[R5-Tunnel0/0/0]tunnel-protocol gre p2mp

[R5-Tunnel0/0/0]source S4/0/0

[R5-Tunnel0/0/0]Ospf Network-type broadcast

[R5-Tunnel0/0/0]ospf timer hello 5

[R5-Tunnel0/0/0]nhrp entry 172.16.0.1 15.1.1.1 register

[R5-Tunnel0/0/0]nhrp network-id 100

[R5-Tunnel0/0/0]q

[R5]ospf 1 route-id 5.5.5.5

[R5-ospf-1]area 0

[R5-ospf-1-area 0]network 172.16.0.3  0.0.0.0

[R5-ospf-1-area 0]network 172.16.1.1  0.0.0.0

R6配置: 

[R6]int T 0/0/0

[R6-Tunnel0/0/0]ip address 172.16.0.4 24

[R6-Tunnel0/0/0]tunnel-protocol gre p2mp

[R6-Tunnel0/0/0]source S4/0/0

[R6-Tunnel0/0/0]Ospf Network-type broadcast

[R6-Tunnel0/0/0]ospf timer hello 5

[R6-Tunnel0/0/0]nhrp entry 172.16.0.1 15.1.1.1 register

[R6-Tunnel0/0/0]nhrp network-id 100

[R6-Tunnel0/0/0]q

[R6]ospf 1 route-id 6.6.6.6

[R6-ospf-1]area 0

[R6-ospf-1-area 0] network 172.16.0.4  0.0.0.0

[R6-ospf-1-area 0] network 172.16.2.1  0.0.0.0

[R6-ospf-1-area 0] q

[R6-ospf-1]area 2

[R6-ospf-1-area 2] abr-summary 172.16.32.0 255.255.240.0

[R6-ospf-1-area 2] Nssa no-summary

R7配置: 

[R7]int T 0/0/0

[R7-Tunnel0/0/0]ip address 172.16.0.5 24

[R7-Tunnel0/0/0]tunnel-protocol gre p2mp

[R7-Tunnel0/0/0]source S4/0/0

[R7-Tunnel0/0/0]Ospf Network-type broadcast

[R7-Tunnel0/0/0]ospf timer hello 5

[R7-Tunnel0/0/0]nhrp entry 172.16.0.1 15.1.1.1 register

[R7-Tunnel0/0/0]nhrp network-id 100

[R7-Tunnel0/0/0]q

[R7]ospf 1 route-id 7.7.7.7

[R7-ospf-1]area 0

[R7-ospf-1-area 0]network 172.16.0.4  0.0.0.0

[R7-ospf-1-area 0]network 172.16.3.1  0.0.0.0

[R7-ospf-1-area 0]q

[R7-ospf-1]area 3

[R7-ospf-1-area 3]network 172.16.48.1  0.0.0.0

[R7-ospf-1-area 3]abr-summary 172.16.48.0 255.255.240.0

[R7-ospf-1-area 3] nssa no-summary

[R7-ospf-1-area 3]q

[R7-ospf-1]default-route-advertise always

4.R1R2ospf宣告

R1配置: 

[R1]ospf 1 route-id 1.1.1.1

[R1-ospf-1]area 1

[R1-ospf-1-area 1] network 0.0.0.0 32

[R1-ospf-1-area 1] stub//将area 1设置末梢区域,该区域所有设备均需要定义,否则无法建立邻居关系。

[R1-ospf-1-area 1]authentication-mode md5 1 cipher 123456

R2配置: 

[R2]ospf 1 route-id 2.2.2.2

[R2-ospf-1]area 1

[R2-ospf-1-area 1]network 0.0.0.0  32

[R2-ospf-1-area 1] stub

[R2-ospf-1-area 1]authentication-mode md5 1 cipher 123456

R8配置: 

[R8]ospf 1 route-id 8.8.8.8

[R8-ospf-1]area 3

[R8-ospf-1-area 3]network 172.16.49.1 0

[R8-ospf-1-area 3]network 172.16.48.2 0

[R8-ospf-1-area 3]network 172.16.48.5 0

[R8-ospf-1-area 3] nssa//将area2与area3设置nssa

该区域所有设备均需要定义,否则无法建立邻居关系。

R9配置: 

[R9]ospf 1 route-id 9.9.9.9

[R9-ospf-1]area 3

[R9-ospf-1-area 3]network 172.16.48.6 0

[R9-ospf-1-area 0]q

[R9-ospf-1]q

[R9]ospf 2 route-id 9.9.9.9

[R9-ospf-2]area 0

[R9-ospf-2-area 0]network 172.16.64.1 0

[R9-ospf-2-area 0]network 172.16.66.1 0

[R9-ospf-2-area 0]q

[R9-ospf-2]default-route-advertise always

[R9-ospf-2]q

[R9]ospf 1 route-id 9.9.9.9

[R9-ospf-1] import-route ospf 2

[R9-ospf-1] ospf 2 route-id 9.9.9.9

[R9-ospf-1] import-route ospf 1//重发布

[R9-ospf-1]abr-summary 172.16.64.0 255.255.240.0

R10配置: 

[R10]ospf 1 route-id 10.10.10.10

[R10-ospf-1]area 0

[R10-ospf-1-area 0]network 0.0.0.0  32

R11配置: 

[R11]ospf 1 route-id 11.11.11.11

[R11-ospf-1]area 2

[R11-ospf-1-area 2]network 0.0.0.0  32

[R11-ospf-1-area 2]nssa//将area2与area3设置nssa

该区域所有设备均需要定义,否则无法建立邻居关系。

R12配置: 

[R12]ospf 1 route-id 12.12.12.12

[R12-ospf-1] area 2

[R12-ospf-1-area 2] network 172.16.32.6  0

[R12-ospf-1-area 2]nssa

[R12]rip 1

[R12-rip-1] version2//启动rip进程,将两条环回宣告进rip,再重发布,将不同协议产生的路由进行双向共享。

[R12-rip-1] network 172.16.0.0

[R12-rip-1] q

[R12] ospf 1 route-id 12.12.12.12

[R12-ospf-1] import-route rip 1

[R12-ospf-1]q

[R12]rip 1

[R12-rip-1] import-route ospf 1

[R12-ospf-1]abr-summary 172.16.128.0 255.255.240.0//域外路由汇总--在5类/7类LSA向ospf发布时进行汇总。

5.配通NAT(R3R4R5R6R7配置)

例如:R1配置:

[R1]acl 2000

[R1-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255

[R1]int S 4/0/0

[R1-Serial4/0/0]not outbound 2000  

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值