一、实验拓扑
(一)实验目的:
1、配置BGP团体属性并查看其宣告特点
2、对AS1和AS2宣告的路由(1.1.1.1和2.2.2.2)进行过滤,不允许通过AS345向另外AS进行宣告,阻止AS1和AS2通过AS345进行通信
(二)拓扑图
二、基础配置
(一)按拓扑所示配置相应的接口地址(此处省略)
(二)在R3R4R5配置OSPF路由(此处省略)
三、详细配置
(一)在R1、R2、R3R4R5分别配置AS号为1、2、345的BGP路由。在R1及R2上针对1.1.1.1和2.2.2.2地址配置团体属性
#
bgp 1
peer 10.1.13.3 as-number 345
#
ipv4-family unicast
undo synchronization
network 1.1.1.1 255.255.255.255 route-policy comm
peer 10.1.13.3 enable
#
route-policy comm permit node 10
apply community 1:100
#
#
bgp 2
peer 10.1.24.4 as-number 345
#
ipv4-family unicast
undo synchronization
network 2.2.2.2 255.255.255.255 route-policy comm
peer 10.1.24.4 enable
#
route-policy comm permit node 10
apply community 2:200
#
(二)在R3及R4上宣告传送团体属性,并根据团队属性禁止向其他AS宣告路由
R3路由器设置
#
bgp 345
peer 4.4.4.4 as-number 345
peer 4.4.4.4 connect-interface LoopBack0
peer 10.1.13.1 as-number 1
#
ipv4-family unicast
undo synchronization
network 5.5.5.5 255.255.255.255
peer 4.4.4.4 enable
peer 4.4.4.4 next-hop-local
peer 4.4.4.4 advertise-community
peer 10.1.13.1 enable
peer 10.1.13.1 route-policy test import
#
route-policy test permit node 10
if-match community-filter 1:100
apply community no-export additive
#
route-policy test permit node 20
#
ip community-filter 1 permit 1:100
#
R4路由器设置
#
bgp 345
peer 3.3.3.3 as-number 345
peer 3.3.3.3 connect-interface LoopBack0
peer 10.1.24.2 as-number 2
#
ipv4-family unicast
undo synchronization
network 5.5.5.5 255.255.255.255
peer 3.3.3.3 enable
peer 3.3.3.3 next-hop-local
peer 3.3.3.3 advertise-community
peer 10.1.24.2 enable
peer 10.1.24.2 route-policy test import
#
route-policy test permit node 10
if-match community-filter 2:200
apply community no-export additive
#
route-policy test permit node 20
#
ip community-filter 1 permit 2:200
四、结果验证
R1和R2都无法获取对方路由信息,实现了隔离
<R1>dis bgp routing-table
BGP Local router ID is 1.1.1.1
Total Number of Routes: 2
Network NextHop MED LocPrf PrefVal Path/Ogn
*> 1.1.1.1/32 0.0.0.0 0 0 i
*> 5.5.5.5/32 10.1.13.3 1 0 345i
<R2>dis bgp routing-table
BGP Local router ID is 10.1.24.2
Total Number of Routes: 2
Network NextHop MED LocPrf PrefVal Path/Ogn
*> 2.2.2.2/32 0.0.0.0 0 0 i
*> 5.5.5.5/32 10.1.24.4 1 0 345i