1.题目要求:
2.考虑环回情况,图中一共有5个网段,根据子网划分如下图:
AR1
AR2
AR3
AR4
启动OSPF
AR1
[r1]ospf 1 router-id 1.1.1.1
[r1-ospf-1]area 0
[r1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.127 -----宣告汇总后的网段192.168.1.0/25
AR2
[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.127-----宣告汇总后的网段192.168.1.0/25
AR3
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.127----宣告汇总后的网段192.168.1.128/25
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]network 192.168.1.128 0.0.0.127
AR4
[r4]ospf 1 router-id 4.4.4.4
[r4-ospf-1]area 1
[r4-ospf-1-area-0.0.0.1]network 192.168.1.128 0.0.0.127
要求AR3为DR
进入r1 r2的GigabitEthernet0/0/0的接口
[r1-GigabitEthernet0/0/0]ospf dr-priority 0
[r2-GigabitEthernet0/0/0]ospf dr-priority 0
DR的优先级数值设为0(默认为1)不参与DR选举
查看r3邻居表
[r4]ospf 1
[r4-ospf-1]default-route-advertise always----强制下发缺省
查看路由表
AR1
AR2
AR3
AR1pingAR4的虚拟外网:
sw2创建VLAN分区
[sw2]vlan batch 2 to 3
[sw2-GigabitEthernet0/0/2]port link-type access
[sw2-GigabitEthernet0/0/2]port default vlan 2
[sw2-GigabitEthernet0/0/3]port link-type access
[sw2-GigabitEthernet0/0/3]port default vlan 3
[sw2]interface GigabitEthernet 0/0/1
[sw2-GigabitEthernet0/0/1]port link-type trunk
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 3
r3创建子接口
[r3]interface GigabitEthernet 0/0/2.1
[r3-GigabitEthernet0/0/2.1]ip addrss 192.168.1.81 28
[r3-GigabitEthernet0/0/2.1]dot1q termination vid 2
[r3-GigabitEthernet0/0/2.1]arp broadcast enable
[r3]interface GigabitEthernet 0/0/2.2
[r3-GigabitEthernet0/0/2.2]ip addrss 192.168.1.98 28
[r3-GigabitEthernet0/0/2.2]dot1q termination vid 3
[r3-GigabitEthernet0/0/2.2]arp broadcast enable
两台PC配置IP
PC1
PC2
PC1 ping PC2
防环
[r3]ip route-static 192.168.1.49 28 NULL 0----空接口
手工认证,使其更加安全:
全网可达