一,拓扑
二,要求
1,r4为ISP上只配ip,r3与其他设备之间只使用公有IP
2,r3-r5/6/7为MGRE环境,r3为中心
3,整个OSPF的ip地址基于172.16.0.0/16划分
所以设备都可以访问r4的环回4减少LSA的数量加快收敛保障更新安全、
5,全网可达
三,路由划分
172.16.0.0/16
172.16.0.0/17---ospf
172.16.0.0/20--area0
172.16.0.0/24---MGRE
172.16.1.0/24---R5
172.16.2.0/24---R6
172.16.3.0/24---R7
.....
172.16.15.0/24
172.16.0.16/20--area1
172.16.16.0/24---骨干172.16.16.0/29--骨干实际
172.16.17.0/24--R1
172.16.18.0/24--R2
172.16.19.0/24--R3
...
172.16.31.0/24
172.16.32.020--area2
172.16.32.0/24---骨干172.16.32.0/30--骨干实际
172.16.33.0/30--骨干实际172.16.34.0/24--R8
...
172.16.49.0/24172.16.48.0/20--area3
172.16.48.0/24---骨干172.16.48.0/30--骨干实际
172.16.49.0/30--骨干实际172.16.50.0/24--R10
...
172.16.63.0/24172.16.0.64/20--area4
172.16.64.0/24---骨干172.16.64.0/30--骨干实际
172.16.65.0/24--R11
172.16.66.0/24--R12...
172.16.79.0/24
172.16.0.80/20
172.16.0.96/20
172.16.0.112/20
172.16.128.0/17---rip
172.16.128.0/18
172.16.192.0/18
四,配置
R1
配置IP
[R1]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]ip address 172.16.16.1 29
[R1]interface LoopBack 0
[R1-LoopBack0]ip address 172.16.17.1 24
[R1-LoopBack0]ospf network-type broadcast--修改接口类型OSPF
[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1]area 1
[R1-ospf-1-area-0.0.0.1]network 0.0.0.0 255.255.255.255[R1]ospf 1---stub区域
[R1-ospf-1]area 1
[R1-ospf-1-area-0.0.0.1]stub[R1]ospf 1
[R1-ospf-1]silent-interface LoopBack 0---静默接口R2
配置IP
[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]ip address 172.16.16.2 29
[r2]interface LoopBack 0
[r2-LoopBack0]ip address 172.16.18.1 24
[R2-LoopBack0]ospf network-type broadcast[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 1
[r2-ospf-1-area-0.0.0.1]network 0.0.0.0 255.255.255.255[r2-ospf-1-area-0.0.0.1】stub---stub区域
[r2]ospf 1
[r2-ospf-1]silent-interface LoopBack 0--静默接口
R3配置IP
[r3]interface Serial 4/0/0
[r3-Serial4/0/0]ip address 13.0.0.1 24
[r3]interface GigabitEthernet 0/0/0
[r3-GigabitEthernet0/0/0]ip address 172.16.16.3 29
[r3]interface LoopBack 0
[r3-LoopBack0]ip address 172.16.19.1 24
[R3-LoopBack0]ospf network-type broadcast[r3]ip route-static 0.0.0.0 0 13.0.0.2---缺省路由
[r3]ip route-static 172.16.16.0 20 NULL 0---空接口防环隧道接口
[r3]interface Tunnel 0/0/0
[r3-Tunnel0/0/0]ip address 172.16.0.1 24
[r3-Tunnel0/0/0]tunnel-protocol gre p2mp
[r3-Tunnel0/0/0]source 13.0.0.1
[r3-Tunnel0/0/0]nhrp entry multicast dynamic ---开启伪广播
[r3-Tunnel0/0/0]ospf network-type p2mp---修改接口类型为P2MP,不需要DR,BDR 选举但HELLO时间长,要改
[r3-Tunnel0/0/0]ospf timer hello 1---修改HELLO时间为1,加快收敛OSPF
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]network 172.16.0.1 0.0.0.0
[r3]ospf 1
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]network 172.16.16.0 0.15.255.255
[r3-ospf-1-area-0.0.0.1]network 172.16.19.0 0.0.0.255
[r3-ospf-1-area-0.0.0.1]abr-summary 172.16.16.0 255.255.240.0----路由汇总[r3]ospf 1 ---stub no-summary区域
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]stub no-summarynat
[r3]acl 2000
[r3-acl-basic-2000]rule permit source 172.16.16.0 0.0.15.255
[r3]interface Serial 4/0/0
[r3-Serial4/0/0]nat outbound 2000
R4配置IP
[R4]interface Serial 3/0/0
[[R4]-Serial3/0/0]ip address 13.0.0.2 24
[R4]interface Serial 3/0/1
[[R4]-Serial3/0/1]ip address 16.0.0.2 24
[R4]interface Serial 4/0/0
[[R4]-Serial4/0/0]ip address 17.0.0.2 24
[R4]interface GigabitEthernet 0/0/0
[[R4]-GigabitEthernet0/0/0]ip address 15.0.0.2 24
[R4]interface LoopBack 0
[[R4]-LoopBack0]ip address 4.4.4.4 32
R5配置IP
[R5]interface GigabitEthernet 0/0/0
[R5-GigabitEthernet0/0/0]ip address 15.0.0.1 24
[R5]interface GigabitEthernet 0/0/1
[R5-GigabitEthernet0/0/1]ip address 172.16.48.1 30
[R5]interface LoopBack 0
[R5-LoopBack0]ip address 172.16.1.1 24
[R5-LoopBack0]ospf network-type broadcast----修改接口类型[R5]ip route-static 0.0.0.0 0 15.0.0.2---缺省路由
[R5]ip route-static 172.16.48.0 20 NULL 0--空接口防环隧道接口
[R5]interface Tunnel 0/0/0
[R5-Tunnel0/0/0]ip address 172.16.0.2 24
[R5-Tunnel0/0/0]tunnel-protocol gre p2mp
[R5-Tunnel0/0/0]source GigabitEthernet 0/0/0
[R5-Tunnel0/0/0]nhrp entry 172.16.0.1 13.0.0.1 register
[r5-Tunnel0/0/0]ospf network-type p2mp---修改接口类型
[r5-Tunnel0/0/0]ospf timer hello 1---修改hello时间OSPF
[R5]ospf 1 router-id 5.5.5.5
[R5-ospf-1]area 0
[R5-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[R5-ospf-1-area-0.0.0.0]network 172.16.1.0 0.0.0.255
[R5-ospf-1]area 3
[R5-ospf-1-area-0.0.0.3]network 172.16.48.1 0.0.0.0
[R5-ospf-1-area-0.0.0.3]abr-summary 172.16.48.0 255.255.240.0--路由汇总[R5]ospf 1 ---nssa no-summary区域
[R5-ospf-1]area 3
[R5-ospf-1-area-0.0.0.3]nssa no-summarynAT
[R5]acl 2000
[R5-acl-basic-2000]rule permit source 172.16.48.0 0.0.15.255
[R5-acl-basic-2000]rule permit source 172.16.64.0 0.0.15.255
[R5]interface GigabitEthernet 0/0/0
[R5-GigabitEthernet0/0/0]nat outbound 2000
R6配置IP
[R6]interface Serial 4/0/0
[R6-Serial4/0/0]ip address 16.0.0.1 24
[R6]interface GigabitEthernet 0/0/0
[R6-GigabitEthernet0/0/0]ip address 172.16.32.1 30
[R6]interface LoopBack 0
[R6-LoopBack0]ip address 172.16.2.1 24
[R6-LoopBack0]ospf network-type broadcast ---修改接口类型,让172.16.2.0在其他路由器路由表中掩码为24[R6]ip route-static 0.0.0.0 0 16.0.0.2--缺省路由
[R6]ip route-static 172.16.32.0 20 NULL 0--空接口防环隧道接口
[R6]interface Tunnel 0/0/0
[R6-Tunnel0/0/0]ip address 172.16.0.3 24
[R6-Tunnel0/0/0]tunnel-protocol gre p2mp
[R6-Tunnel0/0/0]source Serial 4/0/0
[R6-Tunnel0/0/0]nhrp entry 172.16.0.1 13.0.0.1 register
[r6-Tunnel0/0/0]ospf network-type p2mp---修改接口类型
[r6-Tunnel0/0/0]ospf timer hello 1--修改HELLO时间OSPF
[R6]ospf 1 router-id 6.6.6.6
[R6-ospf-1]area 0
[R6-ospf-1-area-0.0.0.0]network 172.16.0.3 0.0.0.0
[R6-ospf-1-area-0.0.0.0]network 172.16.2.0 0.0.0.255
[R6]ospf 1
[R6-ospf-1]area 2
[R6-ospf-1-area-0.0.0.2]network 172.16.32.1 0.0.0.0
[R6-ospf-1-area-0.0.0.2]abr-summary 172.16.32.0 255.255.240.0--路由汇总[R6]ospf 1---nssa no-summary区域
[R6-ospf-1]area 2
[R6-ospf-1-area-0.0.0.2]nssa no-summarynat
[R6]acl 2000
[R6-acl-basic-2000]rule permit source 172.16.32.0 0.0.15.255
[R6-acl-basic-2000]rule permit source 172.16.128.0 0.0.127.255
[R6]interface Serial 4/0/0
[R6-Serial4/0/0]nat outbound 2000R7
配置IP
[r7]interface Serial 4/0/0
[r7-Serial4/0/0]ip address 17.0.0.1 24
[r7]interface LoopBack 0
[r7-LoopBack0]ip address 172.16.3.1 24
[R7-LoopBack0]ospf network-type broadcast--修改接口类型[r7]ip route-static 0.0.0.0 0 17.0.0.2--缺省路由
隧道接口
[r7]interface Tunnel 0/0/0
[r7-Tunnel0/0/0]ip address 172.16.0.4 24
[r7-Tunnel0/0/0]tunnel-protocol gre p2mp
[r7-Tunnel0/0/0]source Serial 4/0/0
[r7-Tunnel0/0/0]nhrp entry 172.16.0.1 13.0.0.1 register
[r7-Tunnel0/0/0]ospf network-type p2mp---修改接口类型
[r7-Tunnel0/0/0]ospf timer hello 1---修改HELLO时间OSPF
[r7]ospf 1 router-id 7.7.7.7
[r7-ospf-1]area 0
[r7-ospf-1-area-0.0.0.0]network 172.16.0.4 0.0.0.0
[r7-ospf-1-area-0.0.0.0]network 172.16.3.0 0.0.0.255
R8配置IP
[r8]interface GigabitEthernet 0/0/0
[r8-GigabitEthernet0/0/0]ip address 172.16.32.2 30
[r8]interface GigabitEthernet 0/0/1
[r8-GigabitEthernet0/0/1]ip address 172.16.33.1 30
[r8]interface LoopBack 0
[r8-LoopBack0]ip address 172.16.34.1 24OSPF
[r8]ospf 1 router-id 8.8.8.8
[r8-ospf-1]area 2
[r8-ospf-1-area-0.0.0.2]network 0.0.0.0 255.255.255.255[r8]ospf 1----nssa区域
[r8-ospf-1]area 2
[r8-ospf-1-area-0.0.0.2]nssaR9
配置IP
[r9]interface GigabitEthernet 0/0/0
[r9-GigabitEthernet0/0/0]ip address 172.16.33.2 30
[r9]interface LoopBack 0
[r9-LoopBack0]ip address 172.16.128.1 18
[r9]interface LoopBack 1
[r9-LoopBack1]ip address 172.16.192.1 24OSPF
[r9]ospf 1 router-id 9.9.9.9
[r9-ospf-1]area 2
[r9-ospf-1-area-0.0.0.2]network 172.16.33.2 0.0.0.0rip
[r9]rip 1
[r9-rip-1]verify-source
[r9-rip-1]version 2
[r9-rip-1]undo summary
[r9-rip-1]network 172.16.0.0重发布
[r9]ospf 1
[r9-ospf-1]import-route rip 1
[r9]rip 1
[r9-rip-1]import-route ospf 1[r9-ospf-1]asbr-summary 172.16.128.0 255.255.128.0--路由汇总
[r9]ospf 1---nssa区域
[r9-ospf-1]area 2
[r9-ospf-1-area-0.0.0.2]nssa
R10配置IP
[r10]interface GigabitEthernet 0/0/0
[r10-GigabitEthernet0/0/0]ip address 172.16.48.2 30
[r10]interface GigabitEthernet 0/0/1
[r10-GigabitEthernet0/0/1]ip address 172.16.49.1 30
[r10]interface LoopBack 0
[r10-LoopBack0]ip address 172.16.50.1 24
[R10-LoopBack0]ospf network-type broadcast---修改接口类型OSPF
[r10]ospf 1 router-id 10.10.10.10
[r10-ospf-1]area 3
[r10-ospf-1-area-0.0.0.3]network 0.0.0.0 255.255.255.255[r10]ospf 1 ---nssa区域
[r10-ospf-1]area 3
[r10-ospf-1-area-0.0.0.3]nssa
R11配置IP
[r11]interface GigabitEthernet 0/0/0
[r11-GigabitEthernet0/0/0]ip address 172.16.49.2 30
[r11]interface GigabitEthernet 0/0/1
[r11-GigabitEthernet0/0/1]ip address 172.16.64.1 30
[r11]interface LoopBack 0
[r11-LoopBack0]ip address 172.16.65.1 24
[R11-LoopBack0]ospf network-type broadcast---修改接口类型OSPF
[r11]ospf 1 router-id 11.11.11.11
[r11-ospf-1]area 3
[r11-ospf-1-area-0.0.0.3]network 172.16.49.2 0.0.0.0
[r11]ospf 2 router-id 11.11.11.11
[r11-ospf-2]area 4
[r11-ospf-2-area-0.0.0.4]network 172.16.65.0 0.15.255.255重发布
[r11]ospf 1
[r11-ospf-1]import-route ospf 2
[r11]ospf 2
[r11-ospf-2]import-route ospf 1[r11-ospf-1]asbr-summary 172.16.64.0 255.255.240.0--路由汇总
[r11]ospf 1 --nssa区域有
[r11-ospf-1]area 3
[r11-ospf-1-area-0.0.0.3]nssa[r11-ospf-2]default-route-advertise---下发缺省
[r11-GigabitEthernet0/0/1]ospf authentication-mode md5 1 cipher 123456---OSPF认证
R12配置IP
[r12]interface GigabitEthernet 0/0/0
[r12-GigabitEthernet0/0/0]ip address 172.16.64.2 30
[r12]interface LoopBack 0
[r12-LoopBack0]ip address 172.16.66.1 24
[R12-LoopBack0]ospf network-type broadcast---修改接口类型OSPF
[r12]ospf 1 router-id 12.12.12.12
[r12-ospf-1]area 4
[r12-ospf-1-area-0.0.0.4]network 0.0.0.0 255.255.255.255[r12-GigabitEthernet0/0/0]ospf authentication-mode md5 1 cipher 123456---OSPF认证
[r12]ospf 1
[r12-ospf-1]silent-interface LoopBack 0 --静默接口
五,测试
1,路由表
2,pingR4环回
3,全网可达