实验要求:
1、AS1存在两个环回,一个地址为192.168.1.0/24该地址不能在任何协议中宣告,AS3中存在两个环回,一个地址为192.168.2.0/24该地址不能在任何协议中宣告,最终要求这两个环回可以互相通讯
2、整个AS2的Ip地址为172.16.0.0/16,请合理划分
3、AS间的骨干链路IP地址随意定制
4、使用BGP协议让整个网络所有设备的环回可以互相访问
5、减少路由条自数量,避免环路出现
实验分析:
1、要求1中提到的不可将R1 R8上的环回宣告在协议中且要求能跨域公网进行通讯。这里使用VPN技术下的GRE构建隧道
2、将172.16.0.0 16进行合理划分 根据题意其中共需要6个网段
3、配置BGP建邻
IBGP的水平分割--使用联邦解决
AS by AS原则 修改下一跳为本地
4、BGP优化进行防环处理和路由聚合
实验配置:
1、基础配置(配置IP地址)
R1:
[R1]interface g 0/0/0
[R1-GigabitEthernet0/0/0]ip address 15.0.0.1 24
[R1]interface LoopBack 0
[R1-LoopBack0]ip address 1.1.1.1 24
[R1]interface LoopBack 1
[R1-LoopBack1]ip address 192.168.1.1 24
R2:
[R2]interface g 0/0/0
[R2-GigabitEthernet0/0/0]ip address 15.0.0.2 24
[R2]interface LoopBack 0
[R2-LoopBack0]ip address 2.2.2.2 24
[R2]interface g 0/0/1
[R2-GigabitEthernet0/0/1]ip address 172.16.1.1 30
[R2]interface g 0/0/2
[R2-GigabitEthernet0/0/2]ip address 172.16.1.21 30
R3:
[R3]interface LoopBack 0
[R3-LoopBack0]ip address 3.3.3.3 24
[R3]interface g 0/0/0
[R3-GigabitEthernet0/0/0]ip address 172.16.1.2 30
[R3]interface GigabitEthernet 0/0/1
[R3-GigabitEthernet0/0/1]ip address 172.16.1.5 30
R4:
[R4]interface LoopBack 0
[R4-LoopBack0]ip address 4.4.4.4 24
[R4]interface GigabitEthernet 0/0/0
[R4-GigabitEthernet0/0/0]ip address 172.16.1.6 30
[R4]interface GigabitEthernet 0/0/1
[R4-GigabitEthernet0/0/1]ip address 172.16.1.9 30
R5:
[R5]interface LoopBack 0
[R5-LoopBack0]ip address 5.5.5.5 24
[R5]interface GigabitEthernet 0/0/1
[R5-GigabitEthernet0/0/1]ip address 172.16.1.22 30
[R5]interface GigabitEthernet 0/0/0
[R5-GigabitEthernet0/0/0]ip address 172.16.1.13 30
R6:
[R6]interface LoopBack 0
[R6-LoopBack0]ip address 6.6.6.6 24
[R6]interface GigabitEthernet 0/0/1
[R6-GigabitEthernet0/0/1]ip address 172.16.1.14 30
[R6]interface GigabitEthernet 0/0/0
[R6-GigabitEthernet0/0/0]ip address 172.16.1.17 30
R7:
[R7-LoopBack0]ip address 7.7.7.7 24
[R7]interface GigabitEthernet 0/0/1
[R7-GigabitEthernet0/0/1]ip address 172.16.1.18 30
[R7]interface GigabitEthernet 0/0/2
[R7-GigabitEthernet0/0/2]ip address 25.0.0.1 24
[R7]interface GigabitEthernet 0/0/0
[R7-GigabitEthernet0/0/0]ip address 172.16.1.10 30
R8:
[R8]interface lo 0
[R8-LoopBack0]ip address 8.8.8.8 24
[R8]interface lo 1
[R8-LoopBack1]ip address 192.168.2.1 24
[R8]interface GigabitEthernet 0/0/0
[R8-GigabitEthernet0/0/0]ip address 25.0.0.2 24
2、配置OSPF
R2:
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]area 0
[R2-ospf-1-area-0.0.0.0]network 2.2.2.0 0.0.0.255
[R2-ospf-1-area-0.0.0.0]network 172.16.1.0 0.0.0.3
[R2-ospf-1-area-0.0.0.0]network 172.16.1.20 0.0.0.3
R3:
[R3]ospf 1 router-id 3.3.3.3
[R3-ospf-1]area 0
[R3-ospf-1-area-0.0.0.0]network 3.3.3.0 0.0.0.255
[R3-ospf-1-area-0.0.0.0]network 172.16.1.0 0.0.0.3
[R3-ospf-1-area-0.0.0.0]network 172.16.1.4 0.0.0.3
R4:
[R4]ospf 1 router-id 4.4.4.4
[R4-ospf-1]area 0
[R4-ospf-1-area-0.0.0.0]network 4.4.4.0 0.0.0.255
[R4-ospf-1-area-0.0.0.0]network 172.16.1.4 0.0.0.3
[R4-ospf-1-area-0.0.0.0]network 172.16.1.8 0.0.0.3
R5:
[R5]ospf 1 router-id 5.5.5.5
[R5-ospf-1]area 0
[R5-ospf-1-area-0.0.0.0]network 5.5.5.0 0.0.0.255
[R5-ospf-1-area-0.0.0.0]network 172.16.1.20 0.0.0.3
[R5-ospf-1-area-0.0.0.0]network 172.16.1.12 0.0.0.3
R6:
[R6]ospf 1 router-id 6.6.6.6
[R6-ospf-1]area 0
[R6-ospf-1-area-0.0.0.0]network 6.6.6.0 0.0.0.255
[R6-ospf-1-area-0.0.0.0]network 172.16.1.12 0.0.0.3
[R6-ospf-1-area-0.0.0.0]network 172.16.1.16 0.0.0.3
R7:
[R7]ospf 1 router-id 7.7.7.7
[R7-ospf-1]area 0
[R7-ospf-1-area-0.0.0.0]network 7.7.7.0 0.0.0.255
[R7-ospf-1-area-0.0.0.0]network 172.16.1.161 0.0.0.3
[R7-ospf-1-area-0.0.0.0]network 172.16.1.16 0.0.0.3
[R7-ospf-1-area-0.0.0.0]network 25.0.0.0 0.0.0.255
3、配置BGP:
R1:
[R1]bgp 1
[R1-bgp]peer 15.0.0.2 as-number 2
R2:
bgp 64512
confederation id 2
confederation peer-as 64513
peer 3.3.3.3 as-number 64512
peer 3.3.3.3 connect-interface LoopBack0
peer 5.5.5.5 as-number 64513
peer 5.5.5.5 ebgp-max-hop 100
peer 5.5.5.5 connect-interface LoopBack0
peer 15.0.0.1 as-number 1
#
ipv4-family unicast
undo synchronization
peer 3.3.3.3 enable
peer 3.3.3.3 next-hop-local
peer 5.5.5.5 enable
peer 5.5.5.5 next-hop-local
peer 15.0.0.1 enable
R3:
bgp 64512
confederation id 2
peer 2.2.2.2 as-number 64512
peer 2.2.2.2 connect-interface LoopBack0
peer 4.4.4.4 as-number 64512
peer 4.4.4.4 connect-interface LoopBack0
#
ipv4-family unicast
undo synchronization
network 172.16.3.0 255.255.255.0
peer 2.2.2.2 enable
peer 2.2.2.2 next-hop-local
peer 4.4.4.4 enable
peer 4.4.4.4 reflect-client
peer 4.4.4.4 next-hop-local
R6:
#
bgp 64513
confederation id 2
peer 5.5.5.5 as-number 64513
peer 5.5.5.5 connect-interface LoopBack0
peer 7.7.7.7 as-number 64513
peer 7.7.7.7 connect-interface LoopBack0
#
ipv4-family unicast
undo synchronization
network 172.16.6.0 255.255.255.0
peer 5.5.5.5 enable
peer 5.5.5.5 next-hop-local
peer 7.7.7.7 enable
peer 7.7.7.7 reflect-client
peer 7.7.7.7 next-hop-local
#
R7:
#
bgp 64513
confederation id 2
confederation peer-as 64512
peer 4.4.4.4 as-number 64512
peer 4.4.4.4 ebgp-max-hop 111
peer 4.4.4.4 connect-interface LoopBack0
peer 6.6.6.6 as-number 64513
peer 6.6.6.6 connect-interface LoopBack0
peer 25.0.0.2 as-number 3
#
ipv4-family unicast
undo synchronization
network 172.16.7.0 255.255.255.0
peer 4.4.4.4 enable
peer 4.4.4.4 next-hop-local
peer 6.6.6.6 enable
peer 6.6.6.6 next-hop-local
peer 25.0.0.2 enable
peer 25.0.0.2 next-hop-local
#
4、优化路由条目
在各个路由器上宣告自身的环回网段,然后查看路由表。
R1:
R2:
R3:
R4:
R5:
R6:
R7:
R8:
5、配置GRE使得r1 r8环回能够互相访问
R1:
#
interface Tunnel0/0/0
ip address 192.168.8.1 255.255.255.0
tunnel-protocol gre
source 1.1.1.1
destination 8.8.8.8
#
R8:
#
interface Tunnel0/0/0
ip address 192.168.8.2 255.255.255.0
tunnel-protocol gre
source 8.8.8.8
destination 1.1.1.1
#
此时需要将R1和R8上的隧道接口宣告在BGP中,再手写一条静态指向Tunnel0/0/0
配置如下:
R1:
[R1-bgp]network 192.168.8.1 24
[R1]ip route-static 192.168.2.0 24 Tunnel 0/0/0
R8:
[R8-bgp]network 192.168.8.2 24
[R8]ip route-static 192.168.1.0 24 Tunnel 0/0/0
测试: