HCIP-Day5(OSPF综合实验)
实验要求具体如下:
1、R4为ISP,其上只能配置IP地址;R4与其他所有直连设备间使用公有IP ;
2、R3—R5/6/7为MGRE环境,R3为中心站点
3、整个OSPF环境IP地址为172.16.0.0/16
4、所有设备均可访问R4的环回;
5、减少LSA的更新量,加快收敛,保障更新安全
6、全网可达
一、拓扑搭建
二、规划IP
11个网段 ->借八位
172.16.0.0/20
172.16.16.0/20
172.16.32.0/20
172.16.48.0/20
172.16.64.0/20
172.16.80.0/20
172.16.96.0/20
172.16.112.0/20
172.16.128.0/20
172.16.144.0/20
172.16.160.0/20
环回12.0.1.1 -12.0.1.12
tunnel 10.0.1.1
区域0 - area0
172.16.32.0/20
172.16.48.0/20
172.16.64.0/20
172.16.80.0/20
12.0.0.4 -R4环回
12.0.0.5 -R5环回
12.0.0.6 -R6环回
12.0.0.7 -R7环回
区域1 - area1
172.16.0.0/20
172.16.16.0/20
12.0.0.1 -R1环回
12.0.0.2 -R2环回
12.0.0.3 -R3环回
区域2 - area2
172.16.144.0/20
172.16.160.0/20
12.0.0.11 -R11环回
12.0.0.12 -R12环回
区域3 - area3
172.16.96.0/20
172.16.112.0/20
12.0.0.8 -R8环回
12.0.0.9 -R9环回
区域4 - area4
172.16.128.0/20
12.0.0.10 -R10环回
三、配置IP及环回
R1
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add
[R1-GigabitEthernet0/0/0]ip address 172.16.0.1 20
[R1-GigabitEthernet0/0/0]q
[R1]int loo 0
[R1-LoopBack0]ip add
[R1-LoopBack0]ip address 12.0.1.1 24
R2
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip ad
[R2-GigabitEthernet0/0/0]ip address 172.16.16.1 20
[R2-GigabitEthernet0/0/0]int loo 0
[R2-LoopBack0]ip add
[R2-LoopBack0]ip address 12.0.1.2 24
R3
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]ip add
[R3-GigabitEthernet0/0/0]ip address 172.16.0.2 20
[R3-GigabitEthernet0/0/0]int g0/0/1
[R3-GigabitEthernet0/0/1]ip add
[R3-GigabitEthernet0/0/1]ip address 172.16.16.2 20
[R3-GigabitEthernet0/0/1]int s3/0/0
[R3-Serial3/0/0]ip ad
[R3-Serial3/0/0]ip address 172.16.32.1 20
[R3-Serial3/0/0]int loo 0
[R3-LoopBack0]ip add
[R3-LoopBack0]ip address 12.0.1.3 24
R4
[R4]int s3/0/0
[R4-Serial3/0/0]ip ad
[R4-Serial3/0/0]ip address 172.16.32.2 20
[R4-Serial3/0/0]int s1/0/0
[R4-Serial1/0/0]ip add
[R4-Serial1/0/0]ip address 172.16.48.1 20
[R4-Serial1/0/0]int s2/0/0
[R4-Serial2/0/0]ip ad
[R4-Serial2/0/0]ip address 172.16.80.1 20
[R4-Serial2/0/0]int s4/0/0
[R4-Serial4/0/0]ip ad
[R4-Serial4/0/0]ip address 172.16.64.1 20
[R4-Serial4/0/0]int
R5
[R5]int s3/0/0
[R5-Serial3/0/0]ip ad
[R5-Serial3/0/0]ip address 172.16.48.2 20
[R5-Serial3/0/0]int loo 0
[R5-LoopBack0]ip ad
[R5-LoopBack0]ip address 12.0.1.5 24
R6
[R6]int s3/0/0
[R6-Serial3/0/0]ip ad
[R6-Serial3/0/0]ip address 172.16.64.2 20
[R6-Serial3/0/0]int s4/0/0
[R6-Serial4/0/0]ip ad
[R6-Serial4/0/0]ip address 172.16.144.1 20
[R6-Serial4/0/0]int loo 0
[R6-LoopBack0]ip ad
[R6-LoopBack0]ip address 12.0.1.6 24
R7
[R7]int s3/0/0
[R7-Serial3/0/0]ip ad
[R7-Serial3/0/0]ip address 172.16.80.2 20
[R7-Serial3/0/0]int s4/0/0
[R7-Serial4/0/0]ip
[R7-Serial4/0/0]ip ad
[R7-Serial4/0/0]ip address 172.16.96.1 20
[R7-Serial4/0/0]int loo 0
[R7-LoopBack0]ip ad
[R7-LoopBack0]ip address 12.0.1.7 24
R8
[R8]int s4/0/0
[R8-Serial4/0/0]ip ad
[R8-Serial4/0/0]ip address 172.16.96.2 20
[R8-Serial4/0/0]int s3/0/0
[R8-Serial3/0/0]ip ad
[R8-Serial3/0/0]ip address 172.16.112.1 20
[R8-Serial3/0/0]int loo 0
[R8-LoopBack0]ip ad
[R8-LoopBack0]ip address 12.0.1.8 24
R9
[R9]int s3/0/0
[R9-Serial3/0/0]ip ad
[R9-Serial3/0/0]ip address 172.16.112.2 20
[R9-Serial3/0/0]int s4/0/0
[R9-Serial4/0/0]ip ad
[R9-Serial4/0/0]ip address 172.16.128.1 20
[R9-Serial4/0/0]int loo 0
[R9-LoopBack0]ip ad
[R9-LoopBack0]ip address 12.0.1.9 24
R10
[R10-Serial4/0/0]ip ad
[R10-Serial4/0/0]ip address 172.16.128.2 20
[R10-Serial4/0/0]int loo 0
[R10-LoopBack0]ip ad
[R10-LoopBack0]ip address 12.0.1.10 24
R11
[R11]int s4/0/0
[R11-Serial4/0/0]ip ad
[R11-Serial4/0/0]ip address 172.16.144.2 20
[R11-Serial4/0/0]int s3/0/0
[R11-Serial3/0/0]ip ad
[R11-Serial3/0/0]ip address 172.16.160.1 20
[R11-Serial3/0/0]int loo 0
[R11-LoopBack0]ip ad
[R11-LoopBack0]ip address 12.0.1.11 24
R12
[R12]int s3/0/0
[R12-Serial3/0/0]ip ad
[R12-Serial3/0/0]ip address 172.16.160.2 20
[R12-Serial3/0/0]int loo 0
[R12-LoopBack0]ip ad
[R12-LoopBack0]ip address 12.0.1.12 24
四、配置MGRE R3为中心站点
R3-中心站点配置
[R3]int t0/0/0
[R3-Tunnel0/0/0]ip ad
[R3-Tunnel0/0/0]ip address 10.0.1.1 255.255.255.0
[R3-Tunnel0/0/0]tu
[R3-Tunnel0/0/0]tunnel-protocol gre p2mp
[R3-Tunnel0/0/0]sou
[R3-Tunnel0/0/0]source 172.16.32.1
[R3-Tunnel0/0/0]ospf network-type p2mp
[R3-Tunnel0/0/0]nh
[R3-Tunnel0/0/0]nhrp e
[R3-Tunnel0/0/0]nhrp entry m
[R3-Tunnel0/0/0]nhrp entry multicast d
[R3-Tunnel0/0/0]nhrp entry multicast dynamic
[R3-Tunnel0/0/0]nh
[R3-Tunnel0/0/0]nhrp n
[R3-Tunnel0/0/0]nhrp network-id 100
R5
[R5]int t0/0/0
[R5-Tunnel0/0/0]ospf network-type broadcast
[R5-Tunnel0/0/0]ip ad
[R5-Tunnel0/0/0]ip address 10.0.1.2 255.255.255.0
[R5-Tunnel0/0/0]tu
[R5-Tunnel0/0/0]tunnel-protocol gre p2mp
[R5-Tunnel0/0/0]so
[R5-Tunnel0/0/0]source s3/0/0
[R5-Tunnel0/0/0]ospf network-type p2mp
[R5-Tunnel0/0/0]nhr
[R5-Tunnel0/0/0]nhrp n
[R5-Tunnel0/0/0]nhrp network-id 100
[R5-Tunnel0/0/0]n
[R5-Tunnel0/0/0]nh
[R5-Tunnel0/0/0]nhrp e
[R5-Tunnel0/0/0]nhrp entry 10.0.1.1 172.16.32.1 reg
[R5-Tunnel0/0/0]nhrp entry 10.0.1.1 172.16.32.1 register
R6
[R6]int t0/0/0
[R6-Tunnel0/0/0]ospf network-type broadcast
[R6-Tunnel0/0/0]ip ad
[R6-Tunnel0/0/0]ip address 10.0.1.3 255.255.255.0
[R6-Tunnel0/0/0]tu
[R6-Tunnel0/0/0]tunnel-protocol gre p2mp
[R6-Tunnel0/0/0]so
[R6-Tunnel0/0/0]source s3/0/0
[R6-Tunnel0/0/0]osp
[R6-Tunnel0/0/0]ospf ne
[R6-Tunnel0/0/0]ospf network-type p2mp
[R6-Tunnel0/0/0]nhr
[R6-Tunnel0/0/0]nhrp
[R6-Tunnel0/0/0]nhrp n
[R6-Tunnel0/0/0]nhrp network-id 100
[R6-Tunnel0/0/0]nh
[R6-Tunnel0/0/0]nhrp e
[R6-Tunnel0/0/0]nhrp entry 10.0.1.1 172.16.32.1 r
[R6-Tunnel0/0/0]nhrp entry 10.0.1.1 172.16.32.1 register
R7
[R7]int t0/0/0
[R7-Tunnel0/0/0]ospf network-type broadcast
[R7-Tunnel0/0/0]ip ad
[R7-Tunnel0/0/0]ip address 10.0.1.4 255.255.255.0
[R7-Tunnel0/0/0]tu
[R7-Tunnel0/0/0]tunnel-protocol gre p2mp
[R7-Tunnel0/0/0]sou
[R7-Tunnel0/0/0]source s3/0/0
[R7-Tunnel0/0/0]ospf network-type p2mp
[R7-Tunnel0/0/0]nhr
[R7-Tunnel0/0/0]nhrp net
[R7-Tunnel0/0/0]nhrp network-id 100
[R7-Tunnel0/0/0]nh
[R7-Tunnel0/0/0]nhrp e
[R7-Tunnel0/0/0]nhrp entry 10.0.1.1 172.16.32.1 r
[R7-Tunnel0/0/0]nhrp entry 10.0.1.1 172.16.32.1 register
[R3]dis nhrp peer all
-------------------------------------------------------------------------------
Protocol-addr Mask NBMA-addr NextHop-addr Type Flag
-------------------------------------------------------------------------------
10.0.1.2 32 172.16.48.2 10.0.1.2 dynamic route tunnel
-------------------------------------------------------------------------------
Tunnel interface: Tunnel0/0/0
Created time : 17:02:57
Expire time : 17:57:03
-------------------------------------------------------------------------------
Protocol-addr Mask NBMA-addr NextHop-addr Type Flag
-------------------------------------------------------------------------------
10.0.1.3 32 172.16.64.2 10.0.1.3 dynamic route tunnel
-------------------------------------------------------------------------------
Tunnel interface: Tunnel0/0/0
Created time : 17:01:24
Expire time : 17:58:36
-------------------------------------------------------------------------------
Protocol-addr Mask NBMA-addr NextHop-addr Type Flag
-------------------------------------------------------------------------------
10.0.1.4 32 172.16.80.1 10.0.1.4 dynamic route tunnel
-------------------------------------------------------------------------------
Tunnel interface: Tunnel0/0/0
Created time : 17:00:31
Expire time : 17:59:29
五、所有设备均可访问R4的环回
设置R3、R5、R6、R7缺省路由
R3:
[R3]ip route-static 0.0.0.0 0 172.16.32.2
R5:
[R5]ip route-static 0.0.0.0 0 172.16.48.1
R6:
[R6]ip route-static 0.0.0.0 0 172.16.64.1
R7:
[R7]ip route-static 0.0.0.0 0 172.16.80.2
六、OSPF宣告及不规则区域处理
1、AREA 0 宣告OSPF打通内网
R3
[R3]OSPF 1 R
[R3]OSPF 1 router-id 3.3.3.3
[R3-ospf-1]AREA 0.0.0.0
[R3-ospf-1-area-0.0.0.0]NET
[R3-ospf-1-area-0.0.0.0]network 172.16.32.1 0.0.0.0
R5
[R5]ospf 1 router-id 5.5.5.5
[R5-ospf-1]area
[R5-ospf-1]area 0.0.0.0
[R5-ospf-1-area-0.0.0.0]net
[R5-ospf-1-area-0.0.0.0]network 12.0.1.5 0.0.0.0
[R5-ospf-1-area-0.0.0.0]net
[R5-ospf-1-area-0.0.0.0]network 172.16.48.2 0.0.0.0
R6
[R6]ospf 1 router-id 6.6.6.6
[R6-ospf-1]area 0.0.0.0
[R6-ospf-1-area-0.0.0.0]net
[R6-ospf-1-area-0.0.0.0]network 12.0.1.6 0.0.0.0
[R6-ospf-1-area-0.0.0.0]net
[R6-ospf-1-area-0.0.0.0]network 172.16.64.2 0.0.0.0
R7
[R7]ospf 1 router-id 7.7.7.7
[R7-ospf-1]net
[R7-ospf-1]are
[R7-ospf-1]area 0.0.0.0
[R7-ospf-1-area-0.0.0.0]net
[R7-ospf-1-area-0.0.0.0]network 12.0.1.7 0.0.0.0
[R7-ospf-1-area-0.0.0.0]net
[R7-ospf-1-area-0.0.0.0]network 172.16.80.1 0.0.0.0
此处省略AREA1、AREA2 、AREA 3的宣告 ,下面看一下AREA4不规则区域的宣告处理
2、不规则区域处理-采用OSPF多进程重发布解决
R9
[R9]ospf 1 router-id 9.9.9.9
[R9-ospf-1]area
[R9-ospf-1]area 0.0.0.4
[R9-ospf-1-area-0.0.0.4]net
[R9-ospf-1-area-0.0.0.4]network 12.0.1.9 0.0.0.0
[R9-ospf-1-area-0.0.0.4]net
[R9-ospf-1-area-0.0.0.4]network 172.16.128.1 0.0.0.0
R10
[R10]ospf 1 router-id 10.10.10.10
[R10-ospf-1]area 0.0.0.4
[R10-ospf-1-area-0.0.0.4]net
[R10-ospf-1-area-0.0.0.4]network 12.0.1.10 0.0.0.0
[R10-ospf-1-area-0.0.0.4]net
[R10-ospf-1-area-0.0.0.4]network 172.16.128.2 0.0.0.0
多进程双向重发布——边界路由器R9
[R9-ospf-2]import-route ospf 1
[R9-ospf-1]import-route ospf 2
七、在R12上配置RIP,并重发布到ospf中
[R12]rip 1 距离矢量路由
[R12-rip-1]ver 2 //版本2
[R12-rip-1]net 12.0.0.0 //宣告主类网的网段
[R12-rip-1]import-route ospf 1
[R12-ospf-1]import-route rip 1
八、配置NAT,使内网可以访问公网
R3
[R3]acl 2000
[R3-acl-basic-2000]rule 5 p
[R3-acl-basic-2000]rule 5 permit s
[R3-acl-basic-2000]rule 5 permit source 172.16.32.2 0.0.0.0
[R3-acl-basic-2000]q
[R3]int s4/0/0
[R3-Serial4/0/0]nat o
[R3-Serial4/0/0]nat outbound 2000
[R3-Serial4/0/0]dis
[R3-Serial4/0/0]disp
[R3-Serial4/0/0]display nat
[R3-Serial4/0/0]display nat o
[R3-Serial4/0/0]display nat outbound
NAT Outbound Information:
--------------------------------------------------------------------------
Interface Acl Address-group/IP/Interface Type
--------------------------------------------------------------------------
Serial4/0/0 2000 172.16.32.1 easyip
--------------------------------------------------------------------------
Total : 1
R6
[R6]acl 2000
[R6-acl-basic-2000]rule 5 p
[R6-acl-basic-2000]rule 5 permit s
[R6-acl-basic-2000]rule 5 permit source 172.16.64.2 0.0.0.0
[R6-acl-basic-2000]int s4/0/0
[R6-Serial4/0/0]nat o
[R6-Serial4/0/0]nat outbound 2000
[R6-Serial4/0/0]dis nat outbound
NAT Outbound Information:
--------------------------------------------------------------------------
Interface Acl Address-group/IP/Interface Type
--------------------------------------------------------------------------
Serial4/0/0 2000 172.16.64.2 easyip
--------------------------------------------------------------------------
Total : 1
R7
[R7]acl 2000
[R7-acl-basic-2000]ru
[R7-acl-basic-2000]rule 5 p
[R7-acl-basic-2000]rule 5 permit s
[R7-acl-basic-2000]rule 5 permit source 172.16.80.1 0.0.0.0
[R7-acl-basic-2000]int s4/0/0
[R7-Serial4/0/0]nat o
[R7-Serial4/0/0]nat outbound 2000
[R7-Serial4/0/0]dis nat out
NAT Outbound Information:
--------------------------------------------------------------------------
Interface Acl Address-group/IP/Interface Type
--------------------------------------------------------------------------
Serial4/0/0 2000 172.16.80.2 easyip
--------------------------------------------------------------------------
Total : 1