项目经验(BGP+ISIS&路由策略)

AR1
g0/0/0 10.10.14.1 24
g0/0/1 10.10.15.1 24
g0/0/2 10.10.13.1 24 isis en
isis 1
net 49.0372.0000.0002.00
level 2
cost wide

int g0/0/2
isis enable 1
bgp 65002
peer 10.10.14.4 as 65001
peer 10.10.15.5 as 65001
运用策略将下级单位引入bgp中
acl 2000 rule permit source 192.168.0.0 0.0.255.255
route-policy dish-office permit node 10
if-match acl 2000
bgp 65002
import isis 1 route-policy dish-office
配置地市isis路由引入
ip ip-prefix gugan-10 permit 172.16.10.0 24
ip ip-prefix gugan-20 permit 172.16.20.0 24
]route-policy sheng-to-di permit node 10
if-match ip-prefix gugan-10
apply cost 1000
route-policy sheng-to-di permit node 20
if-match ip-prefix gugan-20
apply cost 2000
isis 1
import bgp route-policy sheng-to-di
配置地市isis路由过滤
acl 2003
rule deny source 172.16.0.0 0.0.255.255
rule permit source any 
isis 1
filter-policy 2003 import

AR2
g0/0/0 10.10.24.2 24
g0/0/1 10.10.25.2 24
g0/0/2 10.10.23.224 isis en
isis 1
net 49.0372.0000.0003.00
level 2
cost wide

int g0/0/2
isis enable 1
bgp 65002
peer 10.10.24.4 as 65001
peer 10.10.25.5 as 65001
运用策略将下级单位引入bgp中
acl 2000 rule permit source 192.168.0.0 0.0.255.255
route-policy dish-office permit node 10
if-match acl 2000
bgp 65002
import isis 1 route-policy dish-office
配置地市isis路由引入
ip ip-prefix gugan-10 permit 172.16.10.0 24
ip ip-prefix gugan-20 permit 172.16.20.0 24
]route-policy sheng-to-di permit node 10
if-match ip-prefix gugan-10
apply cost 2000
route-policy sheng-to-di permit node 20
if-match ip-prefix gugan-20
apply cost 1000
isis 1
import bgp route-policy sheng-to-di
配置地市isis路由过滤
acl 2003
rule deny source 172.16.0.0 0.0.255.255
rule permit source any 
isis 1
filter-policy 2003 import

AR3
g0/0/0 10.10.13.3 24
g0/0/1 10.10.23.3 24
单臂路由
int g0/0/2.10
dot1q termination vid 10
ip add 192.168.10.254 24
arp brocast enable

int g0/0/2.20
dotq1 termination vid 20
ip add 192.168.20.254 24
arp brocast enable

isis 1
net 49.0372.0000.0001.00
level 2
cost wide
int g0/0/0
isis enable 1
int g0/0/1 
isis enable 1
int g0/0/2.10
isis enable 1
int g0/0/2.20
isis enable 1

AR4
g0/0/0 10.10.46.4 24 isis en 
g0/0/1 10.10.14.4 24
g0/0/2 10.10.24.4 24
e4/0/0 10.10.47.4 24 isis en
int loop 0 4.4.4.4 32 isis en
isis 1 level-2  cost wide
net 49.0001.0000.0004.00
bgp 65001
peer 10.10.14.1 as 65002
peer 10.10.24.2 as 65002
将AR6作为反射器并绑定接口loop0
peer 6.6.6.6 as 65001
peer 6.6.6.6 connect-interface loop 0
修改下一跳属性为本地

peer 6.6.6.6 next-hop-local
因192.168.10段与20段全走4.4.4.4导致压力过载需要分流
通过修改LP属性,为192.168.20.x路由配置优选路径

ip ip-prefix dishi-10 permit 192.168.10.0 24
ip ip-prefix dishi-20 permit 192.168.20.0 24
route-policy di-to-gu permit node 10
if-match ip-prefix dish-10
apply local-preference 2000
route-policy di-to-gu permit node 20
if-match ip-prefix dish-20
apply local-preference 1000
bgp 65001 peer 6.6.6.6 route-policy di-to-gu export
将骨干路由引入地市网络 
acl 2000 rule permit source 172.16.0.0 0.0.255.255
route-policy gugan-fuwuqi permit node 10
if-match acl 2000
bgp 65001
import-route isis 1 route-policy gugan-fuwuqi
控制下级单位路由选择
ip ip-prefix gugan-10 permit 172.16.10.0 24
ip ip-prefix gugan-20 permit 172.16.20.0 24
route-policy gu-to-di permit node 10
if-match ip-prefix gugan-10
apply cost 1000
route-policy gu-to-di permit node 20
if-match ip-prefix gugan-20
apply cost 2000
bgp 65001
peer 10.10.14.1 route-policy gu-to-di export
peer 10.10.24.2 route-policy gu-to-di export

AR5
g0/0/0 10.10.56.5 24 isis en
g0/0/1 10.10.15.5 24
g0/0/2 10.10.25.5 24
e4/0/0 10.10.57.5 24 isis en
int loop 0 5.5.5.5 32 isis en
isis level-2 cost wide
net 49.0001.0000.0005.00
bgp 65001
peer 10.10.25.2 as 65002
peer 10.10.15.1 as 65002
将AR6作为反射器并绑定接口loop0
peer 6.6.6.6 as 65001
peer 6.6.6.6 connect-interface loop 0
修改下一跳属性为本地
bgp 65001
peer 6.6.6.6 next-hop-local
因192.168.10段与20段全走4.4.4.4导致压力过载需要分流
通过修改LP属性,为192.168.20.x路由配置优选路径

ip ip-prefix dishi-10 permit 192.168.10.0 24
ip ip-prefix dishi-20 permit 192.168.20.0 24
route-policy di-to-gu permit node 10
if-match ip-prefix dish-10
apply local-preference 1000
route-policy di-to-gu permit node 20
if-match ip-prefix dish-20
apply local-preference 2000
bgp 65001 peer 6.6.6.6 route-policy di-to-gu export
将骨干路由引入地市网络 
acl 2000 rule 5 permit source 172.16.0.0 0.0.255.255
route-policy gugan-fuwuqi permit node 10
if-match acl 2000
bgp 65001
import-route isis 1 route-policy guguan-fuwuqi
控制下级单位路由选择
ip ip-prefix gugan-10 permit 172.16.10.0 24
ip ip-prefix gugan-20 permit 172.16.20.0 24
route-policy gu-to-di permit node 10
if-match ip-prefix gugan-10
apply cost 2000
route-policy gu-to-di permit node 20
if-match ip-prefix gugan-20
apply cost 1000
bgp 65001
peer 10.10.25.2 route-policy gu-to-di export
peer 10.10.15.1 route-policy gu-to-di export

AR6
g0/0/0 10.10.46.6 24 isis en
g0/0/1 10.10.56.6 24 isis en
g0/0/2 10.10.67.6 24 isis en
int loop 0 6.6.6.6 32 isis en
isis 1 levle-2 cost wide
net 49.0001.0000.0006.00
bgp 65001
配置对等体及绑定反射器客户端
peer 4.4.4.4 as 65001
peer 4.4.4.4 connect-interface loop 0
peer 4.4.4.4 reflect-client
peer 5.5.5.5 as 65001
peer 5.5.5.5 connect-unterface loop 0
peer 5.5.5.5 reflect-client
peer 7.7.7.7 as 65001
peer 7.7.7.7 connect-unterface loop 0
peer 7.7.7.7 reflect-client

AR7
e4/0/0.10 172.16.10.254 24 isis en
e4/0/0.20 172.16.20.254 24 isis en
g0/0/0 10.10.67.7 24 isis en
g0/0/1 10.10.47.7 24 isis en
g0/0/2 10.10.57.7 24 isis en
loop 0 7.7.7.7 32 isis en
isis 1 level-2 cost wide 
net 49.0001.0000.0007.00
bgp 65001
将AR6作为反射器并绑定接口loop0
peer 6.6.6.6 as 65001
peer 6.6.6.6 connect-interface loop 0

  • 40
    点赞
  • 33
    收藏
    觉得还不错? 一键收藏
  • 2
    评论
评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值