划分网段
192.168.1.0 0000000/25 192.168.1.0/25
环回
192.168.1.0 00 00000/27 192.168.1.0/27
192.168.1.0 01 00000/27 192.168.1.32/27
192.168.1.0 10 00000/27 192.168.1.64/27
192.168.1.0 11 00000/27 192.168.1.96/27
骨干
192.168.1.1 0000000/25 192.168.1.128/25
配置ip 环回
AR1
[AR1]int g 0/0/1
[AR1-GigabitEthernet0/0/1]ip address 192.168.1.97 27
[AR1-GigabitEthernet0/0/1]int l 0
[AR1-LoopBack0]ip address 192.168.1.1 27
AR2
[AR2]int g 0/0/2
[AR2-GigabitEthernet0/0/2]ip address 192.168.1.98 27
[AR2-GigabitEthernet0/0/2]int l 0
[AR2-LoopBack0]ip address 192.168.1.33 27
AR3
[AR3]int g 0/0/1
[AR3-GigabitEthernet0/0/1]ip address 192.168.1.99 27
[AR3-GigabitEthernet0/0/1]int g 0/0/0
[AR3-GigabitEthernet0/0/0]ip address 192.168.1.129 25
[AR3-GigabitEthernet0/0/0]int l 0
[AR3-LoopBack0]ip address 192.168.1.65 27
AR4
[AR4]int g 0/0/0
[AR4-GigabitEthernet0/0/0]ip address 192.168.1.130 25
[AR4-GigabitEthernet0/0/0]int l 0
[AR4-LoopBack0]ip address 4.4.4.1 24
取消BDR选举
AR1
[AR1-ospf-1]int g 0/0/1
[AR1-GigabitEthernet0/0/1]ospf dr-priority 0
AR2
[AR2]int g 0/0/2
[AR2-GigabitEthernet0/0/2]ospf dr-priority 0
AR4
[AR4-LoopBack0]int g 0/0/0
[AR4-GigabitEthernet0/0/0]ospf dr-priority 0
宣告
AR1
[AR1]ospf 1
[AR1-ospf-1]area 0
[AR1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
AR2
[AR2-GigabitEthernet0/0/2]ospf
[AR2-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
AR3
[AR3]ospf 1
[AR3-ospf-1]area 0
[AR3-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.31
[AR3-ospf-1-area-0.0.0.0]area 1
[AR3-ospf-1-area-0.0.0.1]network 192.168.1.128 0.0.0.127
AR4
[AR4]ospf 1
[AR4-ospf-1]area 1
[AR4-ospf-1-area-0.0.0.1]network 192.168.1.128 0.0.0.127
会发现没有BDR,因为上面已经配置其他路由接口取消BDR选举
配置认证
AR1
[AR1-GigabitEthernet0/0/0]int g 0/0/1
[AR1-GigabitEthernet0/0/1]ospf authentication-mode md5 1 cipher 123456
AR2
[AR2]int g 0/0/2
[AR2-GigabitEthernet0/0/2]ospf authentication-mode md5 1 cipher 123456
AR3
[AR3]int g 0/0/1
[AR3-GigabitEthernet0/0/1]ospf
[AR3-GigabitEthernet0/0/1]ospf authentication-mode md5 1 cipher 123456
[AR3-GigabitEthernet0/0/1]int g 0/0/0
[AR3-GigabitEthernet0/0/0]ospf authentication-mode md5 1 cipher 123456
AR4
[AR4]int g 0/0/0
[AR4-GigabitEthernet0/0/0]ospf authentication-mode md5 1 cipher 123456
手工汇总
在区域边界路由汇总,按照区域汇总
area 0
[AR3-GigabitEthernet0/0/1]ospf
[AR3-ospf-1]area 0
[AR3-ospf-1-area-0.0.0.0]abr-summary 192.168.1.0 255.255.255.128
area 1
[AR3-ospf-1]area 1
[AR3-ospf-1-area-0.0.0.1]abr-summary 192.18.1.128 255.255.255.128
缺省路由
AR4
[AR4-ospf-1]default-route-advertise always
空接口
AR3
[AR3]ip route-static 192.168.1.0 25 NULL 0
测试
缺省路由在边界路由配置,两台缺省路由相邻可能会造成冲突。
只宣告接口外部无法ping通环回地址。