题目
一、实验拓扑
二、实验需求
1.R4为ISP,其上只能配置IP地址: R4与其他所有直连设备间使用公有IP
2.R3---R5/6/7为MGRE环境,R3为中心站点
3.整个OSPF环境IP地址为172.16.0.0/16
4.所有设备均可访问R4的环回
5.减少LSA的更新量,加快收敛,保障更新安全
6.全网可达
三、实验思路
1.规划并配置IP
2.配置公网路由
3.配置MGRE环境
4.配置私网路由
5.减少LSA更新量
四、实验步骤
1.规划IP,配置公网IP
[r4]int lo 0
[r4-LoopBack0]ip address 4.4.4.4 24
[r4-LoopBack0]q
[r4]int g0/0/0
[r4-GigabitEthernet0/0/0]ip address 34.1.1.1 24
[r4-GigabitEthernet0/0/0]q
[r4]int g0/0/1
[r4-GigabitEthernet0/0/1]ip address 54.1.1.1 24
[r4-GigabitEthernet0/0/1]q
[r4]int g0/0/2
[r4-GigabitEthernet0/0/2]ip address 64.1.1.1 24
[r4-GigabitEthernet0/0/2]q
[r4]int g 4/0/0
[r4-GigabitEthernet4/0/0]ip address 74.1.1.1 24
[r3]int g0/0/1
[r3-GigabitEthernet0/0/1]ip address 34.1.1.2 24
[r5]int g 0/0/1
[r5-GigabitEthernet0/0/1]ip address 54.1.1.2 24
[r6]int g 0/0/1
[r6-GigabitEthernet0/0/1]ip address 64.1.1.2 24
[r7]int g 0/0/1
[r7-GigabitEthernet0/0/1]ip address 74.1.1.2 24
2.配置公网路由
(1)配置缺省路由
[r3]ip route-static 0.0.0.0 0 34.1.1.1
[r5]ip route-static 0.0.0.0 0 54.1.1.1
[r6]ip route-static 0.0.0.0 0 64.1.1.1
[r7]ip route-static 0.0.0.0 0 74.1.1.1
(2)公网全通
3.R3/5/6/7配置MGRE,R3为中心站点
(1)配置隧道
[r3]int t 0/0/0
[r3-Tunnel0/0/0]ip address 172.16.0.129 29
[r3-Tunnel0/0/0]tunnel-protocol gre p2mp
[r3-Tunnel0/0/0]source 34.1.1.2
[r5]int t 0/0/0
[r5-Tunnel0/0/0]ip address 172.16.0.130 29
[r5-Tunnel0/0/0]tunnel-protocol gre p2mp
[r5-Tunnel0/0/0]source GigabitEthernet 0/0/1
[r5-Tunnel0/0/0]nhrp entry 172.16.0.129 34.1.1.2 register
[r6]int t 0/0/0
[r6-Tunnel0/0/0]ip address 172.16.0.131 29
[r6-Tunnel0/0/0]tunnel-protocol gre p2mp
[r6-Tunnel0/0/0]source GigabitEthernet 0/0/1
[r6-Tunnel0/0/0]nhrp entry 172.16.0.129 34.1.1.2 register
[r7]int t 0/0/0
[r7-Tunnel0/0/0]ip address 172.16.0.132 29
[r7-Tunnel0/0/0]tunnel-protocol gre p2mp
[r7-Tunnel0/0/0]source GigabitEthernet 0/0/1
[r7-Tunnel0/0/0]nhrp entry 172.16.0.129 34.1.1.2 register
(2)打开R3伪广播
[r3]int t 0/0/0
[r3-Tunnel0/0/0]nhrp entry multicast dynamic
4.配置私网IP
[r1]int lo 0
[r1-LoopBack0]ip address 172.16.33.1 25
[r1-LoopBack0]q
[r1]int g 0/0/0
[r1-GigabitEthernet0/0/0]ip address 172.16.32.130 29
[r2]int lo 0
[r2-LoopBack0]ip address 172.16.33.129 25
[r2-LoopBack0]q
[r2]int g 0/0/0
[r2-GigabitEthernet0/0/0]ip address 172.16.32.131 29
[r3]int lo 0
[r3-LoopBack0]ip address 172.16.34.1 25
[r3-LoopBack0]q
[r3]int g 0/0/0
[r3-GigabitEthernet0/0/0]ip address 172.16.32.129 29
[r5]int lo 0
[r5-LoopBack0]ip address 172.16.1.1 25
[r6]int lo 0
[r6-LoopBack0]ip address 172.16.1.129 25
[r6-LoopBack0]q
[r6]int g 0/0/0
[r6-GigabitEthernet0/0/0]ip address 172.16.64.1 30
[r7]int lo 0
[r7-LoopBack0]ip address 172.16.2.1 25
[r7-LoopBack0]q
[r7]int g 0/0/0
[r7-GigabitEthernet0/0/0]ip address 172.16.96.1 30
[r8]int lo 0
[r8-LoopBack0]ip address 172.16.97.1 25
[r8-LoopBack0]q
[r8]int g 0/0/0
[r8-GigabitEthernet0/0/0]ip address 172.16.96.2 30
[r8-GigabitEthernet0/0/0]q
[r8]int g 0/0/1
[r8-GigabitEthernet0/0/1]ip address 172.16.96.5 30
[r9]int lo 0
[r9-LoopBack0]ip address 172.16.129.1 25
[r9-LoopBack0]q
[r9]int g 0/0/0
[r9-GigabitEthernet0/0/0]ip address 172.16.96.6 30
[r9-GigabitEthernet0/0/0]q
[r9]int g 0/0/1
[r9-GigabitEthernet0/0/1]ip address 172.16.128.1 30
[r10]int lo 0
[r10-LoopBack0]ip address 172.16.129.129 25
[r10-LoopBack0]q
[r10]int g 0/0/0
[r10-GigabitEthernet0/0/0]ip address 172.16.128.2 30
[r11]int lo 0
[r11-LoopBack0]ip address 172.16.65.1 25
[r11-LoopBack0]q
[r11]int g 0/0/0
[r11-GigabitEthernet0/0/0]ip address 172.16.64.2 30
[r11-GigabitEthernet0/0/0]q
[r11]int g 0/0/1
[r11-GigabitEthernet0/0/1]ip address 172.16.64.5 30
[r12]int lo 0
[r12-LoopBack0]ip address 172.16.160.1 20
[r12-LoopBack0]q
[r12]int lo 1
[r12-LoopBack1]ip address 172.16.176.1 20
[r12-LoopBack1]q
[r12]int g 0/0/0
[r12-GigabitEthernet0/0/0]ip address 172.16.64.6 30
5.配置私网路由
(1)OSPF
[r1]ospf 1 router-id 1.1.1.1
[r1-ospf-1]area 1
[r1-ospf-1-area-0.0.0.1]network 172.16.33.1 0.0.0.0
[r1-ospf-1-area-0.0.0.1]network 172.16.32.130 0.0.0.0
[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 1
[r2-ospf-1-area-0.0.0.1]network 172.16.33.129 0.0.0.0
[r2-ospf-1-area-0.0.0.1]network 172.16.32.131 0.0.0.0
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]network 172.16.34.1 0.0.0.0
[r3-ospf-1-area-0.0.0.1]network 172.16.32.129 0.0.0.0
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]network 172.16.0.129 0.0.0.0
[r5]ospf 1 router-id 5.5.5.5
[r5-ospf-1]area 0
[r5-ospf-1-area-0.0.0.0]network 172.16.1.1 0.0.0.0
[r5-ospf-1-area-0.0.0.0]network 172.16.0.130 0.0.0.0
[r6]ospf 1 router-id 6.6.6.6
[r6-ospf-1]area 0
[r6-ospf-1-area-0.0.0.0]network 172.16.1.129 0.0.0.0
[r6-ospf-1-area-0.0.0.0]network 172.16.0.131 0.0.0.0
[r6-ospf-1-area-0.0.0.0]q
[r6-ospf-1]area 2
[r6-ospf-1-area-0.0.0.2]network 172.16.64.1 0.0.0.0
[r7]ospf 1 router-id 7.7.7.7
[r7-ospf-1]area 0
[r7-ospf-1-area-0.0.0.0]network 172.16.2.1 0.0.0.0
[r7-ospf-1-area-0.0.0.0]network 172.16.0.132 0.0.0.0
[r7-ospf-1-area-0.0.0.0]q
[r7-ospf-1]area 3
[r7-ospf-1-area-0.0.0.3]network 172.16.96.1 0.0.0.0
[r8]ospf 1 router-id 8.8.8.8
[r8-ospf-1]area 3
[r8-ospf-1-area-0.0.0.3]network 172.16.97.1 0.0.0.0
[r8-ospf-1-area-0.0.0.3]network 172.16.96.2 0.0.0.0
[r8-ospf-1-area-0.0.0.3]network 172.16.96.5 0.0.0.0
[r9]ospf 1 router-id 9.9.9.9
[r9-ospf-1]area 3
[r9-ospf-1-area-0.0.0.3]network 172.16.96.6 0.0.0.0
[r9-ospf-1-area-0.0.0.3]q
[r9-ospf-1]area 4
[r9-ospf-1-area-0.0.0.4]network 172.16.129.1 0.0.0.0
[r9-ospf-1-area-0.0.0.4]network 172.16.128.1 0.0.0.0
[r10]ospf 1 router-id 10.10.10.10
[r10-ospf-1]area 4
[r10-ospf-1-area-0.0.0.4]network 172.16.129.129 0.0.0.0
[r10-ospf-1-area-0.0.0.4]network 172.16.128.2 0.0.0.0
[r11]ospf 1 router-id 11.11.11.11
[r11-ospf-1]area 2
[r11-ospf-1-area-0.0.0.2]network 172.16.65.1 0.0.0.0
[r11-ospf-1-area-0.0.0.2]network 172.16.64.2 0.0.0.0
[r11-ospf-1-area-0.0.0.2]network 172.16.64.5 0.0.0.0
[r12]ospf 1 router-id 12.12.12.12
[r12-ospf-1]area 2
[r12-ospf-1-area-0.0.0.2]network 172.16.64.6 0.0.0.0
(2)R12配置RIP
[r12]rip 1
[r12-rip-1]vers 2
[r12-rip-1]network 172.16.0.0
(3)查看邻居表
(4)更改R3/5/6/7接口工作方式
[r3]int t 0/0/0
[r3-Tunnel0/0/0]ospf network-type broadcast
[r5]int t 0/0/0
[r5-Tunnel0/0/0]ospf network-type broadcast
[r6]int t 0/0/0
[r6-Tunnel0/0/0]ospf network-type broadcast
[r7]int t 0/0/0
[r7-Tunnel0/0/0]ospf network-type broadcast
(5)更改参选接口优先级
[r5-Tunnel0/0/0]ospf dr-priority 0
[r6-Tunnel0/0/0]ospf dr-priority 0
[r7-Tunnel0/0/0]ospf dr-priority 0
(6)查看R3的邻居关系
(7)区域0.1.2.3全通,测试
(8)R12引入RIP路由
[r12]ospf 1
[r12-ospf-1]import-route rip
(9)R9上多进程双向发布
[r9]ospf 1
[r9-ospf-1]display this
[V200R003C00]
#
ospf 1 router-id 9.9.9.9
area 0.0.0.3
network 172.16.96.6 0.0.0.0
area 0.0.0.4
network 172.16.129.1 0.0.0.0
#
return
[r9-ospf-1]area 4
[r9-ospf-1-area-0.0.0.4]undo network 172.16.128.0 0.0.1.255
[r9-ospf-1-area-0.0.0.4]q
[r9-ospf-1]q
[r9]ospf 2
[r9-ospf-2]area 4
[r9-ospf-2-area-0.0.0.4]network 172.16.128.0 0.0.1.255
[r9]display ospf peer brief
OSPF Process 1 with Router ID 9.9.9.9
Peer Statistic Information
----------------------------------------------------------------------------
Area Id Interface Neighbor id State
0.0.0.3 GigabitEthernet0/0/0 8.8.8.8 Full
----------------------------------------------------------------------------
OSPF Process 2 with Router ID 172.16.129.1
Peer Statistic Information
----------------------------------------------------------------------------
Area Id Interface Neighbor id State
0.0.0.4 GigabitEthernet0/0/1 10.10.10.10 Full
----------------------------------------------------------------------------
[r9]ospf 1
[r9-ospf-1]import-route ospf 2
[r9-ospf-1]q
[r9]ospf 2
[r9-ospf-2]import-route ospf 1
(10)私网全网通
6.减少LSA更新量
(1)路由汇总
[r3]ospf 1
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]abr-summary 172.16.32.0 255.255.224.0
[r7]ospf 1
[r7-ospf-1]area 3
[r7-ospf-1-area-0.0.0.3]abr-summary 172.16.96.0 255.255.224.0
[r6]ospf 1
[r6-ospf-1]area 2
[r6-ospf-1-area-0.0.0.2]abr-summary 172.16.64.0 255.255.224.0
[r12]ospf 1
[r12-ospf-1]asbr-summary 172.16.160.0 255.255.224.0
[r9]ospf 1
[r9-ospf-1]asbr-summary 172.16.128.0 255.255.224.0
(2)特殊区域
[r1]ospf 1
[r1-ospf-1]area 1
[r1-ospf-1-area-0.0.0.1]stub
[r2]ospf 1
[r2-ospf-1]area 1
[r2-ospf-1-area-0.0.0.1]stub
[r3]ospf 1
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]stub no-summary
[r1]display ospf lsdb
OSPF Process 1 with Router ID 1.1.1.1
Link State Database
Area: 0.0.0.1
Type LinkState ID AdvRouter Age Len Sequence Metric
Router 2.2.2.2 2.2.2.2 106 48 80000006 0
Router 1.1.1.1 1.1.1.1 105 48 80000008 0
Router 3.3.3.3 3.3.3.3 105 48 80000004 0
Network 172.16.32.130 1.1.1.1 105 36 80000004 0
Sum-Net 0.0.0.0 3.3.3.3 113 28 80000001 1
[r12]ospf 1
[r12-ospf-1]area 2
[r12-ospf-1-area-0.0.0.2]nssa
[r11]ospf 1
[r11-ospf-1]area 2
[r11-ospf-1-area-0.0.0.2]nssa
[r6]ospf 1
[r6-ospf-1]area 2
[r6-ospf-1-area-0.0.0.2]nssa no-summary
[r11]dis ospf lsdb
OSPF Process 1 with Router ID 11.11.11.11
Link State Database
Area: 0.0.0.2
Type LinkState ID AdvRouter Age Len Sequence Metric
Router 6.6.6.6 6.6.6.6 64 36 80000004 1
Router 11.11.11.11 11.11.11.11 55 60 80000007 0
Router 12.12.12.12 12.12.12.12 149 36 80000006 1
Network 172.16.64.2 11.11.11.11 55 32 80000002 0
Network 172.16.64.6 12.12.12.12 149 32 80000002 0
Sum-Net 0.0.0.0 6.6.6.6 67 28 80000001 1
NSSA 0.0.0.0 6.6.6.6 67 36 80000001 1
NSSA 172.16.160.0 12.12.12.12 211 36 80000001 2
NSSA 172.16.64.4 12.12.12.12 211 36 80000001 1
(3)区域4调成NSSA
[r7]ospf 1
[r7-ospf-1]area 3
[r7-ospf-1-area-0.0.0.3]nssa no-summary
[r8]ospf 1
[r8-ospf-1]area 3
[r8-ospf-1-area-0.0.0.3]nssa
[r9]ospf 1
[r9-ospf-1]area 3
[r9-ospf-1-area-0.0.0.3]nssa
[r8]display ospf lsdb
OSPF Process 1 with Router ID 8.8.8.8
Link State Database
Area: 0.0.0.3
Type LinkState ID AdvRouter Age Len Sequence Metric
Router 7.7.7.7 7.7.7.7 101 36 80000006 1
Router 9.9.9.9 9.9.9.9 71 36 80000004 1
Router 8.8.8.8 8.8.8.8 65 60 80000008 0
Network 172.16.96.1 7.7.7.7 101 32 80000002 0
Network 172.16.96.5 8.8.8.8 65 32 80000002 0
Sum-Net 0.0.0.0 7.7.7.7 190 28 80000001 1
NSSA 0.0.0.0 7.7.7.7 190 36 80000001 1
NSSA 172.16.128.0 9.9.9.9 77 36 80000001 2
(4)R9给R10缺省
[r9]ospf 2
[r9-ospf-2]undo import-route ospf 1
[r9-ospf-2]default-route-advertise
(5)空接口防环
[r3]ip route-static 172.16.32.0 19 NULL 0
[r6]ip route-static 172.16.64.0 19 NULL 0
[r7]ip route-static 172.16.96.0 19 NULL 0
[r9]ip route-static 172.16.128.0 19 NULL 0
[r12]ip route-static 172.16.160.0 19 NULL 0
7.NAT
[r3]acl 2000
[r3-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[r3-acl-basic-2000]q
[r3]int g0/0/1
[r3-GigabitEthernet0/0/1]nat outbound 2000
[r6]acl 2000
[r6-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[r6-acl-basic-2000]q
[r6]int g0/0/1
[r6-GigabitEthernet0/0/1]nat outbound 2000
[r7]acl 2000
[r7-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[r7-acl-basic-2000]q
[r7]int g 0/0/1
[r7-GigabitEthernet0/0/1]nat outbound 2000