一个HCNA的综合性小实验,知识点涉及OSPF,链路聚合,VRRP,VLAN,GRE,BGP,要求如下:
1、在area 0区域要保证路由最优,下面的不同的vlan分别在不同的area
2、R1和sw1和sw2起ibgp,通过修改med只保障ibgp路由最优,使办公区之间内网互通
3、两个办公区之间通过gre建立隧道,并建立EBGP管理,互相宣告路由
4、SW1:11.11.11.11 ,VRRP中 VLAN 10 30的主,MSTP中10 30的根
5、SW2:22.22.22.22,VRRP中VLAN 20的主,MSTP中20的根
6、设置nat使pc1 3 5能访问internet
配置:
sw3:
<sw3>dis cu
#
sysname sw3
#
vlan batch 10 20 30
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#配置mstp
stp region-configuration
region-name VL10
instance 1 vlan 10 30
instance 2 vlan 20
active region-configuration
#
drop-profile default
#
interface Vlanif1
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 20 30
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 10 20 30
#
interface GigabitEthernet0/0/10
port link-type access
port default vlan 10
#
interface GigabitEthernet0/0/11
port link-type access
port default vlan 20
#
interface GigabitEthernet0/0/12
port link-type access
port default vlan 30
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
return
<sw3>dis stp brief
MSTID Port Role STP State Protection
0 GigabitEthernet0/0/1 ROOT FORWARDING NONE
0 GigabitEthernet0/0/3 ALTE DISCARDING NONE
0 GigabitEthernet0/0/10 DESI FORWARDING NONE
0 GigabitEthernet0/0/11 DESI FORWARDING NONE
0 GigabitEthernet0/0/12 DESI FORWARDING NONE
1 GigabitEthernet0/0/1 ALTE DISCARDING NONE
1 GigabitEthernet0/0/3 ROOT FORWARDING NONE
1 GigabitEthernet0/0/10 DESI FORWARDING NONE
1 GigabitEthernet0/0/12 DESI FORWARDING NONE
2 GigabitEthernet0/0/1 ROOT FORWARDING NONE
2 GigabitEthernet0/0/3 ALTE DISCARDING NONE
2 GigabitEthernet0/0/11 DESI FORWARDING NONE
SW1:
<sw1>dis current-configuration
#
sysname sw1
#
vlan batch 10 20 30 100
#vl 100 为sw1和R1互联的vlanif接口
stp instance 1 root primary
#设置该设备为MSTP中instance 1的主设备
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#配置mstp
stp region-configuration
region-name VL10
instance 1 vlan 10 30
instance 2 vlan 20
active region-configuration
#
drop-profile default
#
interface Vlanif1
#设置vrrp,为VLAN10的主
interface Vlanif10
ip address 192.168.10.2 255.255.255.0
vrrp vrid 10 virtual-ip 192.168.10.1
vrrp vrid 10 priority 120
vrrp vrid 10 track interface GigabitEthernet0/0/1 reduced 30
ospf enable 10 area 0.0.0.10
#设置vrrp 设置cost,保证ospf的路由最优,默认为1
interface Vlanif20
ip address 192.168.20.2 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.20.1
ospf cost 2
ospf enable 10 area 0.0.0.20
#设置vrrp
interface Vlanif30
ip address 192.168.30.2 255.255.255.0
vrrp vrid 30 virtual-ip 192.168.30.2
vrrp vrid 30 virtual-ip 192.168.30.1
vrrp vrid 30 priority 120
ospf enable 10 area 0.0.0.30
#和R1的互联地址
interface Vlanif100
ip address 100.100.100.1 255.255.255.252
ospf enable 10 area 0.0.0.0
#
interface MEth0/0/1
#心跳线 链路聚合
interface Eth-Trunk1
port link-type trunk
port trunk allow-pass vlan 10 20 30
mode lacp-static
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 100
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 10 20 30
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
eth-trunk 1
#
interface GigabitEthernet0/0/6
eth-trunk 1
#
interface NULL0
#
interface LoopBack0
ip address 11.11.11.11 255.255.255.255
ospf enable 10 area 0.0.0.0
#
bgp 1
peer 1.1.1.1 as-number 1
peer 1.1.1.1 connect-interface LoopBack0
#设置路由策略改变IBGP的MED保证IBGP选路到192.168.20.0 的时候优先走SW2
ipv4-family unicast
undo synchronization
network 192.168.10.0
network 192.168.20.0 route-policy MED
network 192.168.30.0
peer 1.1.1.1 enable
#
ospf 10 router-id 11.11.11.11
area 0.0.0.0
area 0.0.0.10
area 0.0.0.20
area 0.0.0.30
#
route-policy MED permit node 10
apply cost 10
#
user-interface con 0
user-interface vty 0 4
#
return
[sw1]dis bgp routing-table
Total Number of Routes: 5
Network NextHop MED LocPrf PrefVal Path/Ogn
i 100.64.15.0/24 3.3.3.3 0 100 0 2i
i 100.64.17.0/24 3.3.3.3 0 100 0 2i
*> 192.168.10.0 0.0.0.0 0 0 i
*> 192.168.20.0 0.0.0.0 10 0 i
*> 192.168.30.0 0.0.0.0 0 0 i
[sw1]