BGP策略实验

BGP策略实验

1.拓扑

外链图片转存失败,源站可能有防盗链机制,建议将图片保存下来直接上传

2.要求

1.使用配用preva1策略,确保R4通过R2到达192.168.10.0/24

2.用AS Path策略,确保R4通过R3到达192.168.11.0/24

3.配置MED策略,确保R4通过R3到达192.168.12.0/24

4.使用Local Preference策略,确保R1通过R2到达192.168.1.0/24

5.使用Local Preference策略,确保R1通过R3到达192.168.2.0/24

6.配置负载均衡,确保R1通过R2和R3到达192.168.3.0/24

7.使用As策略,As 500不接受任何始发于AS 123的路由

8.使用自定义community策略,确保192.168.3.0/24路由不会被发布到AS 500

9.IBGP使用环回接口建邻,EBGP使用物理接口建邻

10.修改AS 123中的用户网段为Broadcast,方便后续在BGP中宣告

11、BGP宣告路由时,仅宣告24网段的用户路由

3.配置

配置IP

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip ad	
[Huawei-GigabitEthernet0/0/0]ip address 12.0.0.2 24
May 23 2024 17:07:36-08:00 Huawei %%01IFNET/4/LINK_STATE(l)[0]:The line protocol
 IP on the interface GigabitEthernet0/0/0 has entered the UP state. 
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip ad	
[Huawei-GigabitEthernet0/0/1]ip address 13.0.0.2 24
May 23 2024 17:07:45-08:00 Huawei %%01IFNET/4/LINK_STATE(l)[1]:The line protocol
 IP on the interface GigabitEthernet0/0/1 has entered the UP state. 
[Huawei-GigabitEthernet0/0/1]int g0/0/2	
[Huawei-GigabitEthernet0/0/2]ip address 15.0.0.1 24
[Huawei]int l0
[Huawei-LoopBack0]ip ad	
[Huawei-LoopBack0]ip address 1.1.1.1 32
[Huawei-LoopBack0]int l1
[Huawei-LoopBack1]ip address 192.168.100.1 24
[Huawei-LoopBack1]q
[Huawei]sys R1
[R1-LoopBack1]ospf network-type broadcast
[R2-GigabitEthernet0/0/0]ip address 24.0.0.1 24
May 23 2024 17:08:50-08:00 R2 %%01IFNET/4/LINK_STATE(l)[0]:The line protocol IP 
on the interface GigabitEthernet0/0/0 has entered the UP state. 
[R2-GigabitEthernet0/0/0]undo ipad	
[R2-GigabitEthernet0/0/0]undo ip ad	
[R2-GigabitEthernet0/0/0]undo ip address 
May 23 2024 17:08:55-08:00 R2 %%01IFNET/4/LINK_STATE(l)[1]:The line protocol IP 
on the interface GigabitEthernet0/0/0 has entered the DOWN state. 
[R2-GigabitEthernet0/0/0]ip ad	
[R2-GigabitEthernet0/0/0]ip address 24.0.0.2 24
May 23 2024 17:09:00-08:00 R2 %%01IFNET/4/LINK_STATE(l)[2]:The line protocol IP 
on the interface GigabitEthernet0/0/0 has entered the UP state. 
[R2-GigabitEthernet0/0/0]int g0/0/01
[R2-GigabitEthernet0/0/1]ip ad	
[R2-GigabitEthernet0/0/1]ip address 12.0.0.1 24
[R2-GigabitEthernet0/0/1]
May 23 2024 17:09:11-08:00 R2 %%01IFNET/4/LINK_STATE(l)[3]:The line protocol IP 
on the interface GigabitEthernet0/0/1 has entered the UP state. 
[R2-GigabitEthernet0/0/1]q
[R2]int l0
[R2-LoopBack0]ip ad	
[R2-LoopBack0]ip address 2.2.2.2 32
[R2-LoopBack0]int l1
[R2-LoopBack1]ip ad	
[R2-LoopBack1]ip address 192.168.20.1 24
[R2-LoopBack1]os	
[R2-LoopBack1]ospf n	
[R2-LoopBack1]ospf network-type broadcast 
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]ip ad	
[R3-GigabitEthernet0/0/0]ip address 13.0.0.1 24
[R3-GigabitEthernet0/0/0]
May 23 2024 17:09:53-08:00 R3 %%01IFNET/4/LINK_STATE(l)[0]:The line protocol IP 
on the interface GigabitEthernet0/0/0 has entered the UP state. 
[R3-GigabitEthernet0/0/0]int g0/0/1
[R3-GigabitEthernet0/0/1]ip ad	
[R3-GigabitEthernet0/0/1]ip address 34.0.0.2 24
May 23 2024 17:10:05-08:00 R3 %%01IFNET/4/LINK_STATE(l)[1]:The line protocol IP 
on the interface GigabitEthernet0/0/1 has entered the UP state. 
[R3-GigabitEthernet0/0/1]q
[R3]int l0
[R3-LoopBack0]ip ad	
[R3-LoopBack0]ip address 3.3.3.3 32
[R3-LoopBack0]q
[R3]int l1
[R3-LoopBack1]ip ad	
[R3-LoopBack1]ip address 192.168.30.1 24
[R3-LoopBack1]int l0
[R3-LoopBack0]ospf n	
[R3-LoopBack0]ospf network-type b	
[R3-LoopBack0]ospf network-type broadcast 
[R4-GigabitEthernet0/0/0]ip address 24.0.0.1 24
[R4-GigabitEthernet0/0/0]
May 23 2024 17:10:42-08:00 R4 %%01IFNET/4/LINK_STATE(l)[0]:The line protocol IP 
on the interface GigabitEthernet0/0/0 has entered the UP state. 
[R4-GigabitEthernet0/0/0]int g0/0/01
[R4-GigabitEthernet0/0/1]ip ad	
[R4-GigabitEthernet0/0/1]ip address 34.0.0.1 24
May 23 2024 17:10:51-08:00 R4 %%01IFNET/4/LINK_STATE(l)[1]:The line protocol IP 
on the interface GigabitEthernet0/0/1 has entered the UP state. 
[R4-GigabitEthernet0/0/1]q
[R4]int l0
[R4-LoopBack0]ip ad	
[R4-LoopBack0]ip address 192.168.1.1 24
[R4-LoopBack0]int l1
[R4-LoopBack1]ip ad	
[R4-LoopBack1]ip address 192.168.2.1 24
[R4-LoopBack1]int l2
[R4-LoopBack2]ip ad	
[R4-LoopBack2]ip address 192.168.3.1 24
[R5-GigabitEthernet0/0/0]ip address 15.0.0.2 24
[R5-GigabitEthernet0/0/0]
May 23 2024 17:11:59-08:00 R5 %%01IFNET/4/LINK_STATE(l)[0]:The line protocol IP 
on the interface GigabitEthernet0/0/0 has entered the UP state. 
[R5-GigabitEthernet0/0/0]q
[R5]int l0
[R5-LoopBack0]ip ad	
[R5-LoopBack0]ip address 192.168.10.1 24
[R5-LoopBack0]int l1
[R5-LoopBack1]ip ad	
[R5-LoopBack1]ip address 192.168.11.1 24
[R5-LoopBack1]int l2
[R5-LoopBack2]ip address 192.168.12.1 24

宣告环回

[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]ne	
[R1-ospf-1-area-0.0.0.0]network 1.1.1.1 0.0.0.0
[R1-ospf-1-area-0.0.0.0]n	
[R1-ospf-1-area-0.0.0.0]network 192.168.100.1 0.0.0.0
[R1-ospf-1-area-0.0.0.0]n	
[R1-ospf-1-area-0.0.0.0]ne	
[R1-ospf-1-area-0.0.0.0]network 12.0.0.2 0.0.0.0
[R1-ospf-1-area-0.0.0.0]ne	
[R1-ospf-1-area-0.0.0.0]network 13.0.0.2 0.0.0.0
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]area 0
[R2-ospf-1-area-0.0.0.0]ne	
[R2-ospf-1-area-0.0.0.0]network 2.2.2.2 0.0.0.0
[R2-ospf-1-area-0.0.0.0]ne	
[R2-ospf-1-area-0.0.0.0]network 192.168.20.1 0.0.0.0
[R2-ospf-1-area-0.0.0.0]ne	
[R2-ospf-1-area-0.0.0.0]network 24.0.0.2 0.0.0.0
[R2-ospf-1-area-0.0.0.0]ne	
[R2-ospf-1-area-0.0.0.0]network 12.0.0.1 0.0.0.0
[R3]ospf 1 router-id 3.3.3.3
[R3-ospf-1]area 0
[R3-ospf-1-area-0.0.0.0]ne	
[R3-ospf-1-area-0.0.0.0]network 3.3.3.3 0.0.0.0
[R3-ospf-1-area-0.0.0.0]ne	
[R3-ospf-1-area-0.0.0.0]network 192.168.30.1 0.0.0.0
[R3-ospf-1-area-0.0.0.0]ne	
[R3-ospf-1-area-0.0.0.0]network 34.0.0.2 0.0.0.0
[R3-ospf-1-area-0.0.0.0]ne	
[R3-ospf-1-area-0.0.0.0]network 13.0.0.1 0.0.0.0

BGP宣告

[R1]bgp 123
[R1-bgp]ROU	
[R1-bgp]route-select
[R1-bgp]router-id 1.1.1.1
[R1-bgp]peer 15.0.0.2 as	
[R1-bgp]peer 15.0.0.2 as-number 500
[R1-bgp]pe	
[R1-bgp]peer 2.2.2.2 as	
[R1-bgp]peer 2.2.2.2 as-number 123
[R1-bgp]peer 2.2.2.2 connect-interface l0
[R1-bgp]peer 2.2.2.2 n	
[R1-bgp]peer 2.2.2.2 next-hop-local
[R1-bgp]peer 3.3.3.3 as	
[R1-bgp]peer 3.3.3.3 as-number 123
[R1-bgp]peer 3.3.3.3 c	
[R1-bgp]peer 3.3.3.3 connect-interface l0
[R1-bgp]peer 3.3.3.3 n	
[R1-bgp]peer 3.3.3.3 next-hop-invariable
[R1-bgp]peer 3.3.3.3 next-hop-local
[R2]bgp 123
[R2-bgp]rou	
[R2-bgp]route-select
[R2-bgp]router-id 2.2.2.2
[R2-bgp]peer 24.0.0.1 as	
[R2-bgp]peer 24.0.0.1 as-number 400
[R2-bgp]peer 1.1.1.1 as	
[R2-bgp]peer 1.1.1.1 as-path-filter
[R2-bgp]peer 1.1.1.1 as-number 123
[R2-bgp]peer 1.1.1.1 con	
[R2-bgp]peer 1.1.1.1 connect-interface l0
[R2-bgp]peer 1.1.1.1 n	
[R2-bgp]peer 1.1.1.1 next-hop-invariable
[R2-bgp]peer 1.1.1.1 next-hop-local
[R3]bgp 123
[R3-bgp]ro	
[R3-bgp]route-select
[R3-bgp]router-id 3.3.3.3
[R3-bgp]peer 34.0.0.1 as	
[R3-bgp]peer 34.0.0.1 as-number 400
[R3-bgp]peer 1.1.1.1 as	
[R3-bgp]peer 1.1.1.1 as-path-filter
[R3-bgp]peer 1.1.1.1 as-number 123
[R3-bgp]peer 1.1.1.1 c	
[R3-bgp]peer 1.1.1.1 connect-interface l0
[R3-bgp]peer 1.1.1.1 n	
[R3-bgp]peer 1.1.1.1 next-hop-invariable
[R3-bgp]peer 1.1.1.1 next-hop-local
[R4]bgp 400	
[R4-bgp]peer 24.0.0.2 as-number 123
[R4-bgp]peer 34.0.0.2 as	
[R4-bgp]peer 34.0.0.2 as-number 123
[R5]bgp 500
[R5-bgp]rou	
[R5-bgp]route-select
[R5-bgp]router-id 5.5.5.5
[R5-bgp]peer 15.0.0.1 as	
[R5-bgp]peer 15.0.0.1 as-number 123

外链图片转存失败,源站可能有防盗链机制,建议将图片保存下来直接上传

宣告环回

[R4-bgp]network 192.168.1.0 24
[R4-bgp]n	
[R4-bgp]nexthop
[R4-bgp]network 192.168.2.0 24
[R4-bgp]ne	
[R4-bgp]nexthop
[R4-bgp]network 192.168.3.0 24
[R5-bgp]network 192.168.10.0 24
[R5-bgp]ne	
[R5-bgp]nexthop
[R5-bgp]network 192.168.11.0 24
[R5-bgp]net	
[R5-bgp]network 192.168.12.0 24
[R1-bgp]network 192.168.100.0 24
[R1-bgp]ne	
[R1-bgp]nexthop
[R1-bgp]network 192.168.20.0 24
[R1-bgp]net	
[R1-bgp]network  192.168.30.0 2
[R3-bgp]network 192.168.30.0 24
[R3-bgp]ne	
[R3-bgp]nexthop 	
[R3-bgp]network 192.168.100.0 24
[R3-bgp]ne	
[R3-bgp]nexthop 	
[R3-bgp]network 192.168.20.0 24
[R2-bgp]network 192.168.20.0 24
[R2-bgp]net	
[R2-bgp]network 192.168.100.0 24
[R2-bgp]ne	
[R2-bgp]network 192.168.30.0 24

做策略

[R4]ip ip-prefix aa permit 192.168.10.0 24
[R4]rou	
[R4]route
[R4]route-policy aa p	
[R4]route-policy aa permit  node	
[R4]route-policy aa permit  node 10
Info: New Sequence of this List.
[R4-route-policy]if	
[R4-route-policy]if-match ip	
[R4-route-policy]if-match ip
[R4-route-policy]if-match ip-prefix aa
[R4-route-policy]ap	
[R4-route-policy]apply p	
[R4-route-policy]apply preference
[R4-route-policy]apply preferred-value 100
[R4-route-policy]q
[R4]rou	
[R4]route
[R4]route-policy aa p	
[R4]route-policy aa permit n	
[R4]route-policy aa permit node 20
Info: New Sequence of this List.
[R4-route-policy]q
[R4]bgp 400
[R4-bgp]peer 24.0.0.2 route-policy aa i	
[R4-bgp]peer 24.0.0.2 route-policy aa import 
[R4]ip ip-prefix bb permit 192.168.11.0 24
[R4]if	
[R4]if
[R4]rou	
[R4]route-policy aa p	
[R4]route-policy aa permit n	
[R4]route-policy aa permit node 15
Info: You are overwriting this sequence.
[R4-route-policy]if	
[R4-route-policy]if-match ip 	
[R4-route-policy]if-match ip
[R4-route-policy]if-match ip-prefix bb
[R4-route-policy]ap	
[R4-route-policy]apply as	
[R4-route-policy]apply as-path 123 123 500	
[R4-route-policy]apply as-path 123 123 500 o	
[R4-route-policy]apply as-path 123 123 500 overwrite 
[R2]route-policy aa p	
[R2]route-policy aa permit n	
[R2]route-policy aa permit node 10
Info: New Sequence of this List.
[R2-route-policy]if-match ip-prefix aa
[R2-route-policy]a	
[R2-route-policy]apply  con	
[R2-route-policy]apply con	
[R2-route-policy]apply con
[R2-route-policy]apply c	
[R2-route-policy]apply community
[R2-route-policy]apply cost 200
[R2-route-policy]q
[R2]rou	
[R2]router	
[R2]route
[R2]route-policy aa p	
[R2]route-policy aa permit n	
[R2]route-policy aa permit node 20
Info: New Sequence of this List.
[R2-route-policy]q
[R2]bgp 123	
[R2-bgp]peer 24.0.0.1 route-policy aa e	
[R2-bgp]peer 24.0.0.1 route-policy aa export 
[R2-bgp]
[R3]ip ip-prefix aa permit 192.168.12.0 24
[R3]rou	
[R3]route
[R3]route-policy aa p	
[R3]route-policy aa permit no	
[R3]route-policy aa permit node 10
Info: New Sequence of this List.
[R3-route-policy]if	
[R3-route-policy]if-match ip	
[R3-route-policy]if-match ip
[R3-route-policy]if-match ip-prefix aa
[R3-route-policy]ap	
[R3-route-policy]apply co	
[R3-route-policy]apply comm-filter
[R3-route-policy]apply community
[R3-route-policy]apply cost 20
[R3-route-policy]q
[R3]rou	
[R3]router
[R3]route	
[R3]route-policy aa p	
[R3]route-policy aa permit n	
[R3]route-policy aa permit node 20
Info: New Sequence of this List.
[R3-route-policy]q
[R3]bgp 123
[R3-bgp]p	
[R3-bgp]peer 34.0.0.1 r	
[R3-bgp]peer 34.0.0.1 route-limit
[R3-bgp]peer 34.0.0.1 route-policy aa e	
[R3-bgp]peer 34.0.0.1 route-policy aa export 
[R1]ip ip-prefix bb permit 192.168.1.0 24
[R1]ip 	
[R1]ip ip	
[R1]ip ipv6-prefix
[R1]ip ip-prefix bb p	
[R1]ip ip-prefix bb permit 192.168.2.0 24
[R1]rou	
[R1]route
[R1]route-policy aa 	
[R1]route-policy aap	
[R1]route-policy aa 	
[R1]route-policy aa p	
[R1]route-policy aa permit n	
[R1]route-policy aa permit node 10
Info: New Sequence of this List.
[R1-route-policy]if	
[R1-route-policy]if-match ip	
[R1-route-policy]if-match ip
[R1-route-policy]if-match ip-prefix aa
[R1-route-policy]ap	
[R1-route-policy]apply l	
[R1-route-policy]apply local-preference 200
[R1-route-policy]q
[R1]rou	
[R1]route
[R1]route-policy aa p	
[R1]route-policy aa permit n	
[R1]route-policy aa permit node  20
Info: New Sequence of this List.
[R1-route-policy]q
[R1]bgp 123
[R1-bgp]q
[R1]rou	
[R1]route
[R1]route-policy bb p	
[R1]route-policy bb permit no	
[R1]route-policy bb permit node 10
Info: New Sequence of this List.
[R1-route-policy]if	
[R1-route-policy]if-match ip	
[R1-route-policy]if-match ip
[R1-route-policy]if-match ip-prefix bb
[R1-route-policy]ap	
[R1-route-policy]apply l	
[R1-route-policy]apply local-preference 200
[R1-route-policy]q
[R1]rou	
[R1]route
[R1]route-policy bb p	
[R1]route-policy bb permit node 20
Info: New Sequence of this List.
[R1-route-policy]bgp 123
[R1-bgp]peer 2.2.2.2 r	
[R1-bgp]peer 2.2.2.2 reflect-client
[R1-bgp]peer 2.2.2.2 route-limit 	
[R1-bgp]peer 2.2.2.2 route-policy aa i	
[R1-bgp]peer 2.2.2.2 route-policy aa import 
[R1-bgp]pe	
[R1-bgp]peer 3.3.3.3 r	
[R1-bgp]peer 3.3.3.3 reflect-client
[R1-bgp]peer 3.3.3.3 route-limit
[R1-bgp]peer 3.3.3.3 route-policy bb i	
[R1-bgp]peer 3.3.3.3 route-policy bb import

负载均衡

[R1-bgp]maximum load-balancing 2

不接受始发as123的路由

[R5]ip as-path-filter 1 deny ^123$
[R5]ip as	
[R5]ip as-path-filter 1 p	
[R5]ip as-path-filter 1 permit .*
[R5]bpg 500
    ^
Error: Unrecognized command found at '^' position.
[R5]pe	
[R5]bgp 500
[R5-bgp]peer 15.0.0.1 as	
[R5-bgp]peer 15.0.0.1 as-number	
[R5-bgp]peer 15.0.0.1 as-path-filter 1 i	
[R5-bgp]peer 15.0.0.1 as-path-filter 1 import 

自定义community策略

[R1]ip ip-prefix cc permit 192.168.3.0 24
[R1]rou	
[R1]route
[R1]route-policy aa p	
[R1]route-policy aa permit node 15
Info: New Sequence of this List.
[R1-route-policy]if	
[R1-route-policy]if-match ip	
[R1-route-policy]if-match ip
[R1-route-policy]if-match ip-prefix cc
[R1-route-policy]a	
[R1-route-policy]apply ci	
[R1-route-policy]apply co	
[R1-route-policy]apply community no	
[R1-route-policy]apply community no-export-subconfed
[R1-route-policy]apply community none
[R1-route-policy]apply community no-advertise
[R1-route-policy]apply community no-export
[R1-route-policy]q
[R1]rou	
[R1]route-policy-change
[R1]router
[R1]route
[R1]route-polic bb p	
[R1]route-polic bb p
[R1]route-polic bb pe	
[R1]route-polic bb pe
[R1]rou	
[R1]route-policy-change
[R1]router
[R1]route
[R1]route-policy bb pe	
[R1]route-policy bb permit node 15
Info: New Sequence of this List.
[R1-route-policy]if	
[R1-route-policy]if-match ip	
[R1-route-policy]if-match ip
[R1-route-policy]if-match ip-prefix cc
[R1-route-policy]ap	
[R1-route-policy]apply co	
[R1-route-policy]apply comm-filter
[R1-route-policy]apply community no	
[R1-route-policy]apply community no-export-subconfed
[R1-route-policy]apply community none
[R1-route-policy]apply community no-advertise
[R1-route-policy]apply community no-export


e-policy-change
[R1]router
[R1]route
[R1]route-policy bb pe	
[R1]route-policy bb permit node 15
Info: New Sequence of this List.
[R1-route-policy]if	
[R1-route-policy]if-match ip	
[R1-route-policy]if-match ip
[R1-route-policy]if-match ip-prefix cc
[R1-route-policy]ap	
[R1-route-policy]apply co	
[R1-route-policy]apply comm-filter
[R1-route-policy]apply community no	
[R1-route-policy]apply community no-export-subconfed
[R1-route-policy]apply community none
[R1-route-policy]apply community no-advertise
[R1-route-policy]apply community no-export
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值