高职网络系统管理国赛–网络赛题1路由选路解析
题目要求如下:
(1)龙首原支行的原生产网段(VLAN 410)、办公网段(VLAN 460)需要与省行的业务区、生产办公区的业务互联互通,需要在交换机S7本地以Network发布明细路由。因业务连通的需要,所有增加的网络终端数据之间的通信,一并划入办公网段进行转发。
(2)在S3、S4交换机中引入路由时,需要进行路由标记。其中,生产网段(VLAN 10)标记为10;办公网段(VLAN 60)标记为20。因业务连通需要,所有增加的网络终端数据之间的通信,一并划入办公网段进行路由标记,路由图定义为SET_TAG。
(3)在S1、S2交换机上,要求通过OSPF双进程实施重发布。其中,在OSPF 100进程发布至OSPF 200进程时,关联路由图定义为OSPF100_TO_OSPF200;在OSPF200进程发布至OSPF100进程时,关联路由图定义为OSPF200_TO_OSPF100。
(4)为了防止路由环路以及次优路径的风险,在S1和S2交换机上配置FILTER-LIST。其中,把OSPF200进程内路由过滤关联路由图定义为FILTER_OSPF100_Route;OSPF100进程内关联路由图定义为FILTER_OSPF200_Route。
(5)各路由图以及连接的各接口中,凡是涉及COST值的调整,要求其值必须调整为5或10。
(6)通过部署策略,使得生产网段的业务(VLAN 410-VLAN 10)的主路径为S7-R1-S1-S3-VSU;办公网段的业务(VLAN 460-VLAN 60)的主路径为S7-R2-S2-S4-VSU;并且要求来回路径一致。
(7)在交换机S1连接S2、路由器R1连接R2的主链路或主设备发生故障时,可以无缝地切换到备用链路或备用设备上。
(8)配置省区业务区中的办公数据(VLAN 60)访问Internet的路径为S4-S2-EG1;配置各支行/网点中的办公数据(VLAN 460)访问Internet的路径为:S7-R2-S2-EG1;并且要求来回路径一致。
拓扑如下:
解析如下:
一、S1配置
ACL配置
ip access-list standard 1
10 permit 194.1.10.0 0.0.0.255
ip access-list standard 2
10 permit 194.1.50.0 0.0.0.255
20 permit 194.1.60.0 0.0.0.255
ip access-list standard 3
30 deny 194.1.50.0 0.0.0.255
40 deny 194.1.60.0 0.0.0.255
50 permit any
ip access-list standard 4
10 deny 194.1.10.0 0.0.0.255
20 permit any
route-map配置
route-map OSPF100_TO_OSPF200 permit 10
match tag 10
set metric 5
route-map OSPF100_TO_OSPF200 permit 20
match tag 20
set metric 10
route-map OSPF200_TO_OSPF100 permit 10
match ip address 1
set metric 5
route-map OSPF200_TO_OSPF100 permit 20
match ip address 2
set metric 10
route-map FITER_OSPF100_Route deny 10
match tag 10 20
route-map FITER_OSPF100_Route permit 20
route-map FITER_OSPF200_Route deny 10
match ip address 1 2
route-map FITER_OSPF200_Route permit 20
路由重分布配置
router ospf 100
graceful-restart
redistribute ospf 200 metric-type 1 route-map OSPF200_TO_OSPF100 subnets
bfd all-interfaces
network 10.1.0.1 0.0.0.0 area 0
network 10.1.1.0 0.0.0.3 area 0
network 10.1.1.4 0.0.0.3 area 0
network 10.1.254.252 0.0.0.3 area 0
distribute-list route-map FITER_OSPF200_Route in
distribute-list 4 in GigabitEthernet 0/5
default-information originate metric 10 metric-type 1
router ospf 200
graceful-restart
redistribute ospf 100 metric-type 1 route-map OSPF100_TO_OSPF200 subnets
network 10.1.2.0 0.0.0.3 area 0
network 10.1.2.4 0.0.0.3 area 0
distribute-list route-map FITER_OSPF100_Route in
distribute-list 3 in GigabitEthernet 0/4
distribute-list 4 in GigabitEthernet 0/5
default-information originate metric 10 metric-type 1
二、S2配置
ACL配置
ip access-list standard 1
10 permit 194.1.10.0 0.0.0.255
ip access-list standard 2
10 permit 194.1.50.0 0.0.0.255
20 permit 194.1.60.0 0.0.0.255
ip access-list standard 3
10 deny 194.1.50.0 0.0.0.255
20 deny 194.1.60.0 0.0.0.255
30 permit any
ip access-list standard 4
10 deny 194.1.10.0 0.0.0.255
20 permit any
route-map配置
route-map OSPF100_TO_OSPF200 permit 10
match tag 10
set metric 10
route-map OSPF100_TO_OSPF200 permit 20
match tag 20
set metric 5
route-map OSPF200_TO_OSPF100 permit 10
match ip address 1
set metric 10
route-map OSPF200_TO_OSPF100 permit 20
match ip address 2
set metric 5
route-map FITER_OSPF100_Route deny 10
match tag 10 20
route-map FITER_OSPF100_Route permit 20
route-map FITER_OSPF200_Route deny 10
match ip address 1 2
route-map FITER_OSPF200_Route permit 20
路由重分布配置
router ospf 100
graceful-restart
redistribute ospf 200 metric-type 1 route-map OSPF200_TO_OSPF100 subnets
bfd all-interfaces
network 10.1.0.2 0.0.0.0 area 0
network 10.1.1.8 0.0.0.3 area 0
network 10.1.1.12 0.0.0.3 area 0
network 10.1.254.252 0.0.0.3 area 0
distribute-list route-map FITER_OSPF200_Route in
default-information originate metric 5 metric-type 1
router ospf 200
graceful-restart
redistribute ospf 100 metric-type 1 route-map OSPF100_TO_OSPF200 subnets
network 10.1.2.8 0.0.0.3 area 0
network 10.1.2.12 0.0.0.3 area 0
distribute-list route-map FITER_OSPF100_Route in
distribute-list 3 in GigabitEthernet 0/4
distribute-list 4 in GigabitEthernet 0/5
default-information originate metric 5 metric-type 1
三、S7配置
S7根据答题卡要求理性选路即可