目录
【实验题目】
【实验思路】
1、R1和R8的两个不能宣告的环回可以考虑使用GRE的VPN隧道实现相互通讯
2、R2到R7的所有设备都要有一个环回
3、R2到R4处于AS号为64512的联邦中,R5到R7处于AS号为64513的联邦中;联邦内需配置R3和R6为路由反射器
4、AS2的IGP私网IP地址划分:
P2P网段 | 172.16.0.0/16 | - |
MA网段 | 172.16.1.0/16 | R2-R3:172.16.1.0/29 |
R3-R4:172.16.1.8/29 | ||
R4-R7:172.16.1.16/29 | ||
R7-R6:172.16.1.24/29 | ||
R6-R5:172.16.1.32/29 | ||
R5-R2:172.16.1.40/29 | ||
…… | ||
STUB网段 | 172.16.2.0/16 | R2环回:172.16.2.0/24 |
172.16.3.0/16 | R3环回:172.16.3.0/24 | |
172.16.4.0/16 | R4环回:172.16.4.0/24 | |
172.16.5.0/16 | R5环回:172.16.5.0/24 | |
172.16.6.0/16 | R6环回:172.16.6.0/24 | |
172.16.7.0/16 | R7环回:172.16.7.0/24 | |
…… | …… |
5、AS间的骨干链路网段:R1-R2:12.0.0.0/24;R7-R8:78.0.0.0/24
6、所有设备的环回接口均可达,则需将AS 2的路由发布到AS 1和AS 3中,此时可用路由聚合的发布方式,以减少路由条目,并做好防环
【实验记录】
一、配置IP地址
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip address 12.0.0.1 24
[r1]int LoopBack 0
[r1-LoopBack0]ip address 192.168.1.1 24
[r1]int LoopBack 1
[r1-LoopBack1]ip address 10.0.0.1 24
[r2]int g0/0/0
[r2-GigabitEthernet0/0/0]ip address 12.0.0.2 24
[r2]int LoopBack 0
[r2-LoopBack0]ip address 172.16.2.1 24
[r2]interface g0/0/1
[r2-GigabitEthernet0/0/1]ip address 172.16.1.1 29
[r2]interface g0/0/2
[r2-GigabitEthernet0/0/2]ip address 172.16.1.42 29
[r3]int g0/0/0
[r3-GigabitEthernet0/0/0]ip address 172.16.1.2 29
[r3]int g0/0/1
[r3-GigabitEthernet0/0/1]ip address 172.16.1.9 29
[r3]int LoopBack 0
[r3-LoopBack0]ip address 172.16.3.1 24
[r4]int g0/0/0
[r4-GigabitEthernet0/0/0]ip address 172.16.1.10 29
[r4]int g0/0/1
[r4-GigabitEthernet0/0/1]ip address 172.16.1.17 29
[r4]int LoopBack 0
[r4-LoopBack0]ip address 172.16.4.1 24
[r5]int g0/0/0
[r5-GigabitEthernet0/0/0]ip address 172.16.1.41 29
[r5]int g0/0/1
[r5-GigabitEthernet0/0/1]ip address 172.16.1.34 29
[r5]int LoopBack 0
[r5-LoopBack0]ip address 172.16.5.1 24
[r6]int g0/0/0
[r6-GigabitEthernet0/0/0]ip address 172.16.1.33 29
[r6]int g0/0/1
[r6-GigabitEthernet0/0/1]ip add
[r6-GigabitEthernet0/0/1]ip address 172.16.1.26 29
[r6]int LoopBack 0
[r6-LoopBack0]ip address 172.16.6.1 24
[r7]int g0/0/0
[r7-GigabitEthernet0/0/0]ip address 172.16.1.25 29
[r7]int g0/0/1
[r7-GigabitEthernet0/0/1]ip address 172.16.1.18 29
[r7]int g0/0/2
[r7-GigabitEthernet0/0/2]ip address 78.0.0.1 24
[r7]int LoopBack 0
[r7-LoopBack0]ip address 172.16.7.1 24
[r8]int g0/0/0
[r8-GigabitEthernet0/0/0]ip address 78.0.0.2 24
[r8]int LoopBack 0
[r8-LoopBack0]ip address 192.168.2.1 24
[r8]int LoopBack 1
[r8-LoopBack1]ip address 11.0.0.1 24
二、AS2内配置OSPF
[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]a 0
[r2-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]a 0
[r3-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r4]ospf 1 router-id 4.4.4.4
[r4-ospf-1]a 0
[r4-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r5]ospf 1 router-id 5.5.5.5
[r5-ospf-1]a 0
[r5-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r6]ospf 1 router-id 6.6.6.6
[r6-ospf-1]a 0
[r6-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r7]ospf 1 router-id 7.7.7.7
[r7-ospf-1]a 0
[r7-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
为确保无误,可通过display ip routing-table protocol ospf命令检查路由是否获取完整
三、建立BGP对等体关系
[r1]bgp 1
[r1-bgp]router-id 1.1.1.1
[r1-bgp]peer 12.0.0.2 as 2
[r2]bgp 64512
[r2-bgp]router-id 2.2.2.2
[r2-bgp]confederation id 2
[r2-bgp]peer 12.0.0.1 as 1
[r2-bgp]peer 172.16.3.1 as 64512
[r2-bgp]peer 172.16.3.1 connect-interface LoopBack 0
[r2-bgp]confederation peer-as 64513
[r2-bgp]peer 172.16.5.1 as 64513
[r2-bgp]peer 172.16.5.1 connect-interface LoopBack 0
[r2-bgp]peer 172.16.5.1 ebgp-max-hop
[r3]bgp 64512
[r3-bgp]router-id 3.3.3.3
[r3-bgp]confederation id 2
[r3-bgp]peer 172.16.2.1 as 64512
[r3-bgp]peer 172.16.2.1 connect-interface LoopBack 0
[r3-bgp]peer 172.16.4.1 as 64512
[r3-bgp]peer 172.16.4.1 connect-interface LoopBack 0
[r4]bgp 64512
[r4-bgp]router-id 4.4.4.4
[r4-bgp]confederation id 2
[r4-bgp]peer 172.16.3.1 as 64512
[r4-bgp]peer 172.16.3.1 connect-interface LoopBack 0
[r4-bgp]confederation peer-as 64513
[r4-bgp]peer 172.16.7.1 as 64513
[r4-bgp]peer 172.16.7.1 connect-interface LoopBack 0
[r4-bgp]peer 172.16.7.1 ebgp-max-hop
[r5]bgp 64513
[r5-bgp]router-id 5.5.5.5
[r5-bgp]confederation id 2
[r5-bgp]confederation peer-as 64512
[r5-bgp]peer 172.16.2.1 as 64512
[r5-bgp]peer 172.16.2.1 connect-interface LoopBack 0
[r5-bgp]peer 172.16.2.1 ebgp-max-hop
[r5-bgp]peer 172.16.6.1 as 64513
[r5-bgp]peer 172.16.6.1 connect-interface LoopBack 0
[r6]bgp 64513
[r6-bgp]router-id 6.6.6.6
[r6-bgp]confederation id 2
[r6-bgp]peer 172.16.5.1 as 64513
[r6-bgp]peer 172.16.5.1 connect-interface LoopBack 0
[r6-bgp]peer 172.16.7.1 as 64513
[r6-bgp]peer 172.16.7.1 connect-interface LoopBack 0
[r7]bgp 64513
[r7-bgp]router-id 7.7.7.7
[r7-bgp]confederation id 2
[r7-bgp]confederation peer-as 64512
[r7-bgp]peer 172.16.6.1 as 64513
[r7-bgp]peer 172.16.6.1 connect-interface LoopBack 0
[r7-bgp]peer 172.16.4.1 as 64512
[r7-bgp]peer 172.16.4.1 connect-interface LoopBack 0
[r7-bgp]peer 172.16.4.1 ebgp-max-hop
[r7-bgp]peer 78.0.0.2 as 3
[r8]bgp 3
[r8-bgp]router-id 8.8.8.8
[r8-bgp]peer 78.0.0.1 as 2
使用 display bgp peer 命令检查对等体关系是否建立正常
四、配置R3、R6为路由反射器
R3指定R2为客户端
[r3-bgp]peer 172.16.2.1 reflect-client
R6指定R5为客户端
[r6-bgp]peer 172.16.5.1 reflect-client
五、发布R1和R8的环回路由
[r1-bgp]network 10.0.0.0 24
注意:要在R2上配置下一跳为本地
[r2]bgp 64512
[r2-bgp]peer 172.16.3.1 next-hop-local
[r2-bgp]peer 172.16.5.1 next-hop-local
[r8-bgp]network 11.0.0.0 24
注意:要在R7上配置下一跳为本地
[r7]bgp 64513
[r7-bgp]peer 172.16.4.1 next-hop-local
[r7-bgp]peer 172.16.6.1 next-hop-local
查看BGP路由是否完整
ping通测试
六、AS2路由聚合
要将172.16.2.0/24 、172.16.3.0/24 、172.16.4.0/24 、172.16.5.0/24 、172.16.6.0/24 、172.16.7.0/24聚合,则可聚合为172.16.0.0/21
[r2]ip route-static 172.16.0.0 21 NULL 0
[r2]bgp 64512
[r2-bgp]network 172.16.0.0 21
此时R1和R8上都有到达AS 2所有环回接口的路由
ping通测试
此时虽已达到要求,但由于R7上没有指向172.16.0.0/21的NULL 0接口,可能出现路由黑洞,且由于BGP的MED属性的特性,可能会造成选路不佳
因此需要在R7上也进行路由聚合并发布的动作,可同时解决以上两个问题
[r7]ip route-static 172.16.0.0 21 NULL 0
[r7]bgp 64513
[r7-bgp]network 172.16.0.0 21
七、为R1和R8的未宣告的环回接口做GRE隧道
注意:此时封装的内容不能是12.0.0.1和78.0.0.2这样的物理接口,因为R1和R8上的物理接口不通。所以要封装在已通的10.0.0.1和11.0.0.1虚拟接口上
[r1]int Tunnel 0/0/0
[r1-Tunnel0/0/0]ip address 18.0.0.1 24
[r1-Tunnel0/0/0]tunnel-protocol gre
[r1-Tunnel0/0/0]source 10.0.0.1
[r1-Tunnel0/0/0]destination 11.0.0.1
[r1]ip route-static 192.168.2.0 24 18.0.0.2
[r8]int Tunnel 0/0/0
[r8-Tunnel0/0/0]ip address 18.0.0.2 24
[r8-Tunnel0/0/0]tunnel-protocol gre
[r8-Tunnel0/0/0]source 11.0.0.1
[r8-Tunnel0/0/0]destination 10.0.0.1
[r8]ip route-static 192.168.1.0 24 18.0.0.1
ping通测试
至此,实验全部完成