OSPF综合实验 HCIP课程

该实验涉及OSPF协议的配置,包括区域划分、IP地址规划、路由汇总、P2MP隧道、NAT转换、区域认证和收敛速度优化。通过配置,确保了不同区域间的路由可达性,并实施了安全措施以保护路由更新。实验还涵盖了RIP路由协议的集成以及LSA更新量的减少策略。

OSPF综合实验

实验要求如下:

 拓扑图如上

IP地址规划如下:

要求:根据给定IP地址进行IP地址规划。

划定6个区域(6<8)介三位为:16+3=19      172.16.0.0 16

A0:172.16.0.0 19 

172.16.0.0 25 -------P2P骨干

172.16.0.0 29
172.16.0.8 29
172.16.0.16 29

172.16.1.0 24 -------MA骨干

172.16.1.0 29
172.16.1.8 29
172.16.1.16  29

172.16.0.130 29 — 用户网段

172.16.0.131 29 — 用户网段

172.16.0.132 29— 用户网段

A1:172.16.32.0 19

172.16.32.0 24 -------P2P骨干

172.16.32.0 29
172.16.32.8 29
172.16.32.16 29

172.16.33.0 24 -------MA骨干

172.16.33.0 29
172.16.33.8 29
172.16.33.16 29

172.16.33.1 25 —r1环回
172.16.33.129 25 —r2环回
172.16.34.1 25 —r3环回

A2:172.16.64.0 19

172.16.64.0 24 -------P2P骨干

172.16.64.0 29
172.16.64.8 29
172.16.64.16 30

172.16.65.0 24 -------MA骨干

172.16.64.0 29
172.16.64.8 29
172.16.64.16 30


172.16.65.1/25——r11环回

A3:172.16.96.0 19 

172.16.96.0/24 -------P2P骨干

172.16.96.0 29
172.16.96.8 29
172.16.96.16 30

172.16.97.0/24 -------MA骨干

172.16.97.0 29
172.16.97.8 29
172.16.97.16 30

172.16.97.1  25 —r5环回
 

A4:172.16.128.0 19

172.16.128.0 24 -------P2P骨干

172.16.128.0 29
172.16.128.8 29
172.16.128.16 29

172.16.129.0/24 -------MA骨干

172.16.128.0 29
172.16.128.8 29
172.16.128.16 29

172.16.129.1 25 ——r7环回
172.16.129.129 25 ——r8环回
 

172.16.160.0/19 ------rip

172.16.160.0/20 —r12环回
172.16.176.0/20 —r12环回

A0区域配置:172.16.0.0 19

R3

GigabitEthernet0/0/1              34.1.1.1/24          up         up

ip route-static 0.0.0.0 0 34.1.1.2缺省)

Tunnel0/0/0                       172.16.0.129/29

R4

GigabitEthernet0/0/0              34.1.1.2/24          up         up        

GigabitEthernet0/0/1              64.1.1.2/24          up         up        

GigabitEthernet0/0/2              94.1.1.2/24          up         up        

GigabitEthernet4/0/0              104.1.1.2/24         up         up  

R9

[r9]int g0/0/0

[r9-GigabitEthernet0/0/0]ip add 94.1.1.1 24

[r9]ip route-static 0.0.0.0 0 94.1.1.2缺省)

[r9]int t0/0/0

[r9-Tunnel0/0/0]ip add 172.16.0.130 29

[r9-Tunnel0/0/0]tunnel-protocol gre p2mp

[r9-Tunnel0/0/0]source g0/0/0 (目标物理端口,线路IP)

[r9-Tunnel0/0/0]nhrp entry 172.16.0.129 34.1.1.1 register

[r9-LoopBack0]ip add 172.16.1.1 25

R10

[r10]int g0/0/0

[r10-GigabitEthernet0/0/0]ip add 104.1.1.1 24

[r10]ip route-static 0.0.0.0 0 104.1.1.2

[r10]int t0/0/0

[r10-Tunnel0/0/0]ip add 172.16.0.131 29

[r10-Tunnel0/0/0]tunnel-protocol gre p2mp

[r10-Tunnel0/0/0]source g0/0/0

[r10-Tunnel0/0/0]nhrp entry 172.16.0.129 34.1.1.1 register

[r10-LoopBack0]ip add 172.16.1.129 25

R6

[r6]int g0/0/0

[r6-GigabitEthernet0/0/0]ip add 64.1.1.1 24

[r6]ip route-static 0.0.0.0 0 64.1.1.2

[r6]interface t0/0/0

[r6-Tunnel0/0/0]tunnel-protocol gre p2mp

[r6-Tunnel0/0/0]source g0/0/0

[r6-Tunnel0/0/0]nhrp entry 172.16.0.129 34.1.1.1 register

[r6-LoopBack0]ip add 172.16.2.1 25

A1区域配置:172.16.32.0 19

R1

[r1]int lo0

[r1-LoopBack0]ip add 172.16.33.1 25

[r1-LoopBack0]int g0/0/0

[r1-GigabitEthernet0/0/0]ip add 172.16.32.129 29

R2

[r2]int lo0

[r2-LoopBack0]ip add 172.16.33.129 25

[r2-LoopBack0]int g0/0/0

[r2-GigabitEthernet0/0/0]ip add 172.16.32.130 29

R3

[r3]int lo0

[r3-LoopBack0]ip add 172.16.34.1 25

[r3-LoopBack0]int g0/0/0

[r3-GigabitEthernet0/0/0]ip add 172.16.32.131 29

A2配置:172.16.64.0 19

R10

[r10]int g0/0/1

[r10-GigabitEthernet0/0/1]ip add 172.16.64.1 29

R11

[r11]int lo0

[r11-LoopBack0]ip add 172.16.65.1 25

[r11]int g0/0/0

[r11-GigabitEthernet0/0/0]ip add 172.16.64.2 29

[r11-GigabitEthernet0/0/2]ip add 172.16.64.9 29

R12

[r12]int g0/0/0

[r12-GigabitEthernet0/0/0]ip add 172.16.64.10 29

A3配置:172.16.96.0 19

R6

[r6]int g0/0/2

[r6-GigabitEthernet0/0/2]ip add 172.16.96.1 29

R5

[r5-LoopBack0]ip add 172.16.97.1 25

[r5-LoopBack0]int g0/0/0

[r5-GigabitEthernet0/0/0]ip add 172.16.96.2 29

[r5-GigabitEthernet0/0/1]ip add 172.16.96.9 29

R7

[r7]int g0/0/1

[r7-GigabitEthernet0/0/1]ip add 172.16.96.10 29

A4配置:172.16.128.0 19

R7

[r7-GigabitEthernet0/0/1]ip add 172.16.96.10 29

[r7-LoopBack0]ip add 172.16.129.1 25

[r7-GigabitEthernet0/0/0]ip add 172.16.128.1 29

R8

[r8-LoopBack0]ip add 172.16.129.129 25

[r8-GigabitEthernet0/0/2]ip add 172.16.128.2 29

RIP配置:172.16.160.0 20

[r12-LoopBack0]ip add 172.16.160.1 20

[r12-LoopBack1]ip add 172.16.176.1 20

配置OSPF,在A1中,r1,r2汇总宣告,r3取相同去不同

R1

[r1]ospf 1 router-id 1.1.1.1

[r1-ospf-1]area 1

[r1-ospf-1-area-0.0.0.1]network 172.16.0.0 0.0.255.255

R2

[r2]ospf 1 router-id 2.2.2.2

[r2-ospf-1]area 1

[r2-ospf-1-area-0.0.0.1]network 172.16.0.0 0.0.255.255

R3

[r3]ospf 1 router-id 3.3.3.3

[r3-ospf-1]area 1

[r3-ospf-1-area-0.0.0.1]network 172.16.32.0 0.0.31.255

[r3-ospf-1]area 0

[r3-ospf-1-area-0.0.0.0]network 172.16.0.129 0.0.0.0

R5

[r5]ospf 1 router-id  5.5.5.5

[r5-ospf-1]area 3

[r5-ospf-1-area-0.0.0.3]network 172.16.0.0 0.0.255.255

R6

[r6]ospf 1 router-id 6.6.6.6

[r6-ospf-1]area 0

[r6-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.3.255

[r6-ospf-1]area 3

[r6-ospf-1-area-0.0.0.3]network 172.16.96.0 0.0.0.255

R7

[r7]ospf 1 router-id 7.7.7.7

[r7-ospf-1]area 3

[r7-ospf-1-area-0.0.0.3]network 172.16.96.0 0.0.0.255

[r7-ospf-1]area 4

[r7-ospf-1-area-0.0.0.4]network 172.16.128.0 0.0.1.255

R8

[r8]ospf 1 router-id 8.8.8.8

[r8-ospf-1]area 4

[r8-ospf-1-area-0.0.0.4]network  172.16.0.0 0.0.255.255

R9

[r9]ospf 1 router-id 9.9.9.9

[r9-ospf-1]area 0

[r9-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255

R10

[r10]ospf 1 router-id 10.10.10.10

[r10-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.1.255

[r10-ospf-1]area 2

[r10-ospf-1-area-0.0.0.2]network 172.16.64.0 0.0.0.255

R11

[r11]ospf 1 router-id 11.11.11.11

[r11-ospf-1]area 2

[r11-ospf-1-area-0.0.0.2]network 172.16.0.0 0.0.255.255

R12

[r12]ospf 1 router-id 12.12.12.12

[r12-ospf-1]area 2

[r12-ospf-1-area-0.0.0.2]network 172.16.64.10 0.0.0.0

RIP:

[r12-rip-1]version 2

[r12-rip-1]network 172.16.0.0

因为P2P类型是无法与其他路由之间建立邻居关系,我们需要更改MGRE类型 — P2MP类型

[r3-Tunnel0/0/0]ospf network-type p2mp

[r9-Tunnel0/0/0]ospf network-type p2mp

[r10-Tunnel0/0/0]ospf network-type p2mp

[r6-Tunnel0/0/0]ospf network-type p2mp

area4区域和rip区域间缺失的路由信息,需要我们手工使用重发布的方式导入rip路由和area4的路由信息

[r7-ospf-1-area-0.0.0.4]undo network 172.16.128.0 0.0.1.255

[r7-ospf-2]area 4

[r7-ospf-2-area-0.0.0.4]network 172.16.128.0 0.0.1.255

[r12]ospf 1

[r12-ospf-1]import-route rip

减少LSA的更新量:

减少LSA的更新量,需要做汇总和特殊区域(减少路由条目)在汇总时为避免环路需配置空接口

特殊区域:

A1

[r1]ospf 1

[r1-ospf-1]a 1

[r1-ospf-1-area-0.0.0.1]stub

[r2]ospf 1

[r2-ospf-1]area 1

[r2-ospf-1-area-0.0.0.1]stub

[r3]ospf 1

[r3-ospf-1]area 1

[r3-ospf-1-area-0.0.0.1]stub  no-summary

A2

[r10]ospf 1

[r10-ospf-1]area 2

[r10-ospf-1-area-0.0.0.2]nssa no-summary

[r11]ospf 1

[r11-ospf-1]area 2

[r11-ospf-1-area-0.0.0.2]nssa

[r12]ospf 1

[r12-ospf-1]area 2

[r12-ospf-1-area-0.0.0.2]nssa

A3

[r6]ospf 1

[r6-ospf-1]area 3

[r6-ospf-1-area-0.0.0.3]nssa no-import-route

[r5]ospf 1

[r5-ospf-1]area 3

[r5-ospf-1-area-0.0.0.3]nssa

[r7-ospf-1]area 3

[r7-ospf-1-area-0.0.0.3]nssa

对ABR及ASBR做过子网汇总的路由器做空接口来进行防环

R3

[r3]ip route-static 172.16.32.0 19 NULL 0

R10

[r10]ip route-static 172.16.64.0 19 NULL 0

R6

[r6]ip route-static 172.16.96.0 19 NULL 0

R12

[r12]ip route-static 172.16.160.0 19 NULL 0

R7

[r7]ip route-static 172.16.128.0 19 NULL 0

访问公网。进行NAT协议的配置

R3

[r3]acl 2000

[r3-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255

[r3]int s g0/0/0

[r3-GigabitEthernet0/0/0]nat outbound 2000

R9

[r9]acl 2000   

[r9-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255

[r9]int g0/0/0

[r9-GigabitEthernet0/0/0]nat outbound 2000

R10

[r10]acl 2000   

[r10-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255

[r10]int g0/0/0

[r10-GigabitEthernet0/0/0]nat outbound 2000

R6

[r6]acl 2000

[r6-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255

[r6]int g0/0/0

[r6-GigabitEthernet0/0/0]nat outbound 2000

对A1进行区域认证的配置,保证更新安全

R1

[r1]ospf 1

[r1-ospf-1]a 1

[r1-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 123456

R2

[r2]ospf 1

[r2-ospf-1]a 1

[r2-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 123456

R3

[r3]ospf 1

[r3-ospf-1]a 1

[r3-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 123456

加快收敛

R3

[r3]int t0/0/0

[r3-Tunnel0/0/0]ospf timer hello 10

R9

[r9]int t0/0/0

[r9-Tunnel0/0/0]ospf timer hello 10

10

[r10]int t0/0/0

[r10-Tunnel0/0/0]ospf timer  hello 10

R6

[r6]int t0/0/0   

[r6-Tunnel0/0/0]ospf timer  hello  10

到此实验完成,可ping通R4环回。

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值