HCIP学习
前言
HCIP实验 第十一天实验作业 BGP-2
实验要求
1、AS 1存在两个环回,一个地址为192.168.1.0 24 该地址不能在任何协议中宣告 。
AS 3存在两个环回,一个地址为192.168.2.0 24 该地址不能在任何协议中宣告
最终要求这两个环回可以互相通讯
AS 1的另一个环回为10.1.1.0 24
AS 3的另一个环回为10.1.2.0 24
2、整个AS2的IP地址为172.16.0.0 合理划分
3、AS间的骨干链路IP地址随意定制
4、使用BGP协议让整个网络所有设备的环回可以相互访问
5、减少条目数量,避免环路出现
分析规划
地址规划根据内部的IGP
开启BGP前需要开启IGP
配置
1、根据题目要求配置所有环回和接口
2、开启OSPF协议
[r2]ospf
[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r4]ospf 1 router-id 4.4.4.4
[r4-ospf-1]area 0
[r4-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r5]ospf 1 router-id 5.5.5.5
[r5-ospf-1]area 0
[r5-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r6]ospf 1 router-id 6.6.6.6
[r6-ospf-1]area 0
[r6-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r7]ospf 1 router-id 7.7.7.7
[r7-ospf-1]area 0
[r7-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
3、开启BGP协议和联邦
[r1]bgp 1
[r1-bgp]router-id 1.1.1.1
[r1-bgp]peer 12.1.1.2 as-number 2
[r2]bgp 64512
[r2-bgp]peer 12.1.1.1 as
[r2-bgp]peer 12.1.1.1 as-number 1
[r2]bgp 64512
[r2-bgp]confederation id 2
[r2-bgp]confederation peer-as 64513
[r2-bgp]
[r2-bgp]
[r2-bgp]peer 172.16.3.1 as-number 64512
[r2-bgp]peer 172.16.3.1 connect-interface LoopBack 0
[r2-bgp]peer 172.16.5.1 as-number 64513
[r2-bgp]peer 172.16.5.1 connect-interface LoopBack 0
[r2-bgp]peer 172.16.5.1 ebgp-max-hop
[r3]bgp 64512
[r3-bgp]confederation id 2
[r3-bgp]peer 172.16.2.1 as-number 64512
[r3-bgp]peer 172.16.2.1 connect-interface LoopBack 0
[r3-bgp]peer 172.16.4.1 as-number 64512
[r3-bgp]peer 172.16.4.1 connect-interface LoopBack 0
[r4]bgp 64512
[r4-bgp]confederation id 2
[r4-bgp]confederation peer-as 64513
[r4-bgp]peer 172.16.3.1 as-number 64512
[r4-bgp]peer 172.16.3.1 connect-interface LoopBack 0
[r4-bgp]peer 172.16.7.1 as-number 64513
[r4-bgp]peer 172.16.7.1 connect-interface LoopBack 0
[r4-bgp]peer 172.16.7.1 ebgp-max-hop
[r5]BGP 64513
[r5-bgp]router-id 5.5.5.5
[r5-bgp]confederation id 2
[r5-bgp]confederation peer-as 64512
[r5-bgp]peer 172.16.2.1 as-number 64512
[r5-bgp]peer 172.16.2.1 connect-interface LoopBack 0
[r5-bgp]peer 172.16.2.1 ebgp-max-hop
[r5-bgp]
[r5-bgp]peer 172.16.6.1 as-number 64513
[r5-bgp]peer 172.16.6.1 connect-interface LoopBack 0
[r6]bgp 64513
[r6-bgp]router-id 6.6.6.6
[r6-bgp]confederation id 2
[r6-bgp]peer 172.16.5.1 as-number 64513
[r6-bgp]peer 172.16.5.1 connect-interface LoopBack 0
[r6-bgp]peer 172.16.7.1 as-number 64513
[r6-bgp]peer 172.16.7.1 connect-interface LoopBack 0
[r7]bgp 64513
[r7-bgp]router-id 7.7.7.7
[r7-bgp]confederation id 2
[r7-bgp]confederation peer-as 64512
[r7-bgp]peer 172.16.4.1 as-number 64512
[r7-bgp]peer 172.16.4.1 connect-interface l0
[r7-bgp]peer 172.16.4.1 ebgp-max-hop
[r7-bgp]peer 172.16.6.1 as-number 64513
[r7-bgp]peer 172.16.6.1 connect-interface LoopBack 0
[r7-bgp]peer 78.1.1.2 as-number 3
[r7-bgp]
[r8]bgp 3
[r8-bgp]peer 78.1.1.1 as-
[r8-bgp]peer 78.1.1.1 as-number 2
4、宣告
[r1]bgp 1
[r1-bgp]network 10.1.1.0 24
由于R3R5 不优
[r2]bgp 64512
[r2-bgp]peer 172.16.3.1 next-hop-local
[r2-bgp]peer 172.16.5.1 next-hop-local
写R3 R6 反射器
[r3]bgp 64512
[r3-bgp]peer 172.16.2.1 re
[r3-bgp]peer 172.16.2.1 reflect-client
[r6]bgp 64513
[r6-bgp]peer 172.16.7.1 re
[r6-bgp]peer 172.16.7.1 reflect-client
然后R4就可以收到这条反射的路由了
R8宣告
[r8]bgp 3
[r8-bgp]network 10.1.2.1 24
R8到R7 R6都不优,所以要改下一跳
[r7]bgp 64513
[r7-bgp]peer 172.16.4.1 next-hop-local
[r7-bgp]peer 172.16.6.1 next-hop-local
现在全网拿到这两个环回(10.1.1.0 24 10.1.2.0 24)
现在R1 R8环回可以相互访问
现在要让所有环回可以互相访问,使用汇总
[r2]ip route-static 172.16.0.0 21 NULL 0
[r2]bgp 64512
[r2-bgp]network 172.16.0.0 21
[r7]bgp 64513
[r7-bgp]network 172.16.2.1 32
[r7-bgp]network 172.16.3.1 32
[r7-bgp]network 172.16.4.1 32
[r7-bgp]network 172.16.5.1 32
[r7-bgp]network 172.16.6.1 32
[r7-bgp]network 172.16.7.1 32
[r7-bgp]
[r7-bgp]network 172.16.0.0 30
[r7-bgp]network 172.16.0.4 30
[r7-bgp]network 172.16.0.8 30
[r7-bgp]network 172.16.0.12 30
[r7-bgp]network 172.16.0.16 30
[r7-bgp]network 172.16.0.20 30
[r7-bgp]
[r7-bgp]
[r7-bgp]aggregate 172.16.0.0 21 de
[r7-bgp]aggregate 172.16.0.0 21 detail-suppressed
此时两个192的环回地址还没有通,使用GRE
[r1]interface Tunnel 0/0/0
[r1-Tunnel0/0/0]ip address 10.1.3.1 24
[r1-Tunnel0/0/0]tunnel-protocol gre
[r1-Tunnel0/0/0]source 10.1.1.1
[r1-Tunnel0/0/0]destination 10.1.2.1
[r8]interface Tunnel 0/0/0
[r8-Tunnel0/0/0]ip address 10.1.3.2 24
[r8-Tunnel0/0/0]tunnel-protocol gre
[r8-Tunnel0/0/0]source 10.1.2.1
[r8-Tunnel0/0/0]destination 10.1.1.1
[r1]ip route-static 192.168.2.0 24 Tunnel 0/0/0
[r8]ip route-static 192.168.1.0 24 10.1.3.1