1,R4为ISP,其上只能配置IP地址;R4与其他所有直连设备间均使用公有IP
[ISP-Serial4/0/0]ip add 172.16.0.2 19
[ISP-Serial4/0/1]ip add 172.16.32.2 19
[ISP-Serial3/0/0]ip add 172.16.64.2 19
[ISP-GigabitEthernet0/0/0]ip add 172.16.96.2 19
2,R3-R5/6/7为MGRE环境,R3为中心站点;
[R3]ip route-static 0.0.0.0 0 172.16.0.2
[R5]ip route-static 0.0.0.0 0 172.16.32.2
[R6]ip route-static 0.0.0.0 0 172.16.64.2
[R7]ip route-static 0.0.0.0 0 172.16.96.2
(通公网)
中心站点(R3):
[R3]int Tunnel 0/0/0
[R3-Tunnel0/0/0]ip add 192.168.2.3 24
[R3-Tunnel0/0/0]tunnel-protocol gre p2mp
[R3-Tunnel0/0/0]source Serial 4/0/0
[R3-Tunnel0/0/0]nhrp network-id 100
[R3-Tunnel0/0/0]nhrp entry multicast dynamic
[R3-Tunnel0/0/0]ospf network-type p2mp
分支(R5/6/7):
[R5-Tunnel0/0/0]ip add 192.168.2.5 24
[R5-Tunnel0/0/0]tunnel-protocol gre p2mp
[R5-Tunnel0/0/0]source Serial 4/0/0
[R5-Tunnel0/0/0]nhrp network-id 100
[R5-Tunnel0/0/0]nhrp entry 192.168.2.3 172.16.0.1 register
[R5-Tunnel0/0/0]ospf network-type p2mp
R6/7同理
3,整个OSPF环境IP基于172.16.0.0/16划分;
[R12-ospf-1]import-route rip 1
[R12-rip-1]import-route ospf 1
4,所有设备均可访问R4的环回;
[ISP-LoopBack0]ip add 192.168.1.1 24
[R3-ospf-1-area-0.0.0.0]network 192.168.2.0 0.0.0.255
[R3-ospf-1-area-0.0.0.1]network 172.16.128.0 0.0.31.255
[R3-acl-basic-2000]rule permit source 172.16.128.0 0.0.31.255
[R3-Serial4/0/0]nat outbound 2000
(其他同理)
[R7-ospf-1-area-0.0.0.3]vlink-peer 9.9.9.9
[R9-ospf-1-area-0.0.0.3]vlink-peer 7.7.7.7
[R9-acl-basic-2000]rule permit source 172.16.224.0 0.0.31.255
[R9-GigabitEthernet0/0/0]nat outbound 2000
(区域3,4没有缺省,用的虚链接,没用特殊区域,如stub no-summary )(可以不用虚链接,用双向重发布)
[R8]ip route-static 0.0.0.0 0 172.16.192.1
[R9]ip route-static 0.0.0.0 0 172.16.208.1
[R10]ip route-static 0.0.0.0 0 172.16.224.1
5,减少LSA的更新量,加快收敛,保障更新安全;
[R7-ospf-1-area-0.0.0.3]abr-summary 172.16.192.0 255.255.224.0
[R6-ospf-1-area-0.0.0.2]abr-summary 172.16.160.0 255.255.224.0
[R3-ospf-1-area-0.0.0.1]stub no-summary
[R1-ospf-1-area-0.0.0.1]stub
[R2-ospf-1-area-0.0.0.1]stub
[R6-ospf-1-area-0.0.0.2]nssa no-summary
[R11-ospf-1-area-0.0.0.2]nssa
[R12-ospf-1-area-0.0.0.2]nssa
[ISP]aaa
[ISP-aaa]local-user huawei password cipher 123456
[ISP-aaa]local-user huawei service-type ppp
[ISP-Serial4/0/0]ppp authentication-mode chap
[ISP-Serial4/0/0]shutdown
[ISP-Serial4/0/0]undo shutdown
[R3-Serial4/0/0]ppp chap user huawei
[R3-Serial4/0/0]ppp chap password cipher 123456
(其他同理)ISP与R3/R5/R6做ppp协议的chap认证,保证安全
6,全网可达