1、R1/R2/R3的IP地址配置
[AR1]int g0/0/0
[AR1-GigabitEthernet0/0/0]ip add 192.168.1.1 24
[AR1-GigabitEthernet0/0/0]int g0/0/1
[AR1-GigabitEthernet0/0/1]ip add 12.1.1.1 24
[AR2]int g0/0/0
[AR2-GigabitEthernet0/0/0]ip add 12.1.1.2 24
[AR2-GigabitEthernet0/0/0]int g0/0/1
[AR2-GigabitEthernet0/0/1]ip add 23.1.1.2 24
[AR3]int g0/0/0
[AR3-GigabitEthernet0/0/0]ip add 23.1.1.1 24
[AR3-GigabitEthernet0/0/0]int g0/0/1
[AR3-GigabitEthernet0/0/1]ip add 192.168.2.1 24
2、在R1/R2/R3上配置OSPF
R1不能拼通192.168.2.254; R3不能拼通过192.168.1.254
[AR1]ospf
[AR1-ospf-1]area 0
[AR1-ospf-1-area-0.0.0.0]net 12.1.1.0 0.0.0.255
[AR2]ospf
[AR2-ospf-1]area 0
[AR2-1-area-0.0.0.0]net 12.1.1.0 0.0.0.255
[AR2-ospf-1-area-0.0.0.0]net 23.1.1.0 0.0.0.25
[AR3]ospf
[AR3-ospf-1]area 0
[AR3-ospf-1-area-0.0.0.0]net 23.1.1.0 0.0.0.255
3、配置R1/R3的出口路由:
在R1和R3上配置缺省路由,到达12.1.1.2: 和23.1.1.2的路由
[AR1]ip route-static 0.0.0.0 0.0.0.0 12.1.1.2
[AR3]ip route-static 0.0.0.0 0.0.0.0 23.1.1.2
4、NAT配置:接口NAT
[AR1]acl 2000
[AR1-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[AR1-GigabitEthernet0/0/1]nat outbound 2000
[AR3]acl 2000
[AR3-acl-basic-2000]rule permit source 192.168.2.0 0.0.0.255
[AR3-GigabitEthernet0/0/0]nat outbound 2000
5、建立隧道
[AR1]interface Tunnel 0/0/0
[AR1-Tunnel0/0/0]tu
[AR1-Tunnel0/0/0]tunnel-protocol gre
[AR1-Tunnel0/0/0]de
[AR1-Tunnel0/0/0]destination 23.1.1.1
[AR1-Tunnel0/0/0]s
[AR1-Tunnel0/0/0]shutdown
[AR1-Tunnel0/0/0]source 12.1.1.1
[AR1-Tunnel0/0/0]ip add 172.16.1.1 24
[AR1]ip route-static 192.168.2.0 255.255.255.0 172.16.1.2
[AR3]interface Tunnel 0/0/0
[AR3-Tunnel0/0/0]tu
[AR3-Tunnel0/0/0]tunnel-protocol gre
[AR3-Tunnel0/0/0]de
[AR3-Tunnel0/0/0]destination 12.1.1.1
[AR3-Tunnel0/0/0]s
[AR3-Tunnel0/0/0]shutdown
[AR3-Tunnel0/0/0]source 23.1.1.1
[AR3-Tunnel0/0/0]ip add 172.16.1.2 24
[AR3]ip route-static 192.168.1.0 255.255.255.0 172.16.1.1
验证
中间运用的查询命令
[AR1-Tunnel0/0/0]dis this
[AR1]dis ip routing-table