实验要求
1、R4为ISP,其上只能配置IP地址: R4与其他所有直连设备间使用公有
2、R3---R5/6/7为MGRE环境,R3为中心站点
3、整个OSPF环境IP地址为172.16.0.0/16
4、所有设备均可访问R4的环回
5、减少LSA的更新量,加快收敛,保障更新安全
6、全网可达
第一步IP划分/配置IP
如图
第二步搭建MGRE环境
r3
[r3-Tunnel0/0/0]ip add 172.16.0.129 29
[r3-Tunnel0/0/0]tunnel-protocol gre p2mp
[r3-Tunnel0/0/0]source 34.1.1.1
[r3-Tunnel0/0/0]nhrp entry multicast dynamic
[r3-Tunnel0/0/0]nhrp network-id 100
[r3-Tunnel0/0/0]ospf network-type broadcast
r5
[r5-Tunnel0/0/0]ip add 172.16.0.130 29
[r5-Tunnel0/0/0]tunnel-protocol gre p2mp
[r5-Tunnel0/0/0]source g0/0/0
[r5-Tunnel0/0/0]nhrp network-id 100
[r5-Tunnel0/0/0]nhrp entry 172.16.0.129 34.1.1.1 register
[r5-Tunnel0/0/0]ospf network-type broadcast
[r5-Tunnel0/0/0]ospf dr-priority 0
r6
[r6-Tunnel0/0/0]ip add 172.16.0.131 29
[r6-Tunnel0/0/0]tunnel-protocol gre p2mp
[r6-Tunnel0/0/0]source g0/0/0
[r6-Tunnel0/0/0]nhrp entry 172.16.0.129 34.1.1.1 register
[r6-Tunnel0/0/0]nhrp network-id 100
[r6-Tunnel0/0/0]ospf network-type broadcast
[r6-Tunnel0/0/0]ospf dr-priority 0
r7
[r7-Tunnel0/0/0]ip add 172.16.0.132 29
[r7-Tunnel0/0/0]tunnel-protocol gre p2mp
[r7-Tunnel0/0/0]source g0/0/0
[r7-Tunnel0/0/0]nhrp entry 172.16.0.129 34.1.1.1 register
[r7-Tunnel0/0/0]nhrp network-id 100
[r7-Tunnel0/0/0]ospf network-type broadcast
[r7-Tunnel0/0/0]ospf dr-priority 0
第三步配置OSPF
R1
[Huawei]ospf 1 router-id 1.1.1.1
[Huawei-ospf-1-area-0.0.0.1]network 172.16.32.0 0.0.1.255
R2
[Huawei]ospf 1 router-id 2.2.2.2
[Huawei-ospf-1-area-0.0.0.1]network 172.16.32.0 0.0.1.255
R3
[Huawei]ospf 1 router-id 3.3.3.3
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]network 172.16.32.0 0.0.3.25[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.129 0.0.0.0
R5
[Huawei]ospf 1 router-id 5.5.5.5
[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.1.255
R6
[Huawei]ospf 1 router-id 6.6.6.6
[Huawei-ospf-1-area-0.0.0.0]area 1
[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.1.255[Huawei-ospf-1-area-0.0.0.0]area 2
[Huawei-ospf-1-area-0.0.0.2]network 172.16.96.1 0.0.0.0
R7
[Huawei]ospf 1 router-id 7.7.7.7
[Huawei-ospf-1]are 0
[Huawei-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.3.255[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.3]network 172.16.64.1 0.0.0.0
R8
[Huawei]ospf 1 router-id 8.8.8.8
[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.3]network 172.16.64.0 0.0.1.255
R9
[Huawei]ospf 1 router-id 9.9.9.9
[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.3]network 172.16.64.6 0.0.0.0[Huawei-ospf-1-area-0.0.0.3]are 4
[Huawei-ospf-1-area-0.0.0.4]network 172.16.128.0 0.0.1.255
R10
[Huawei]ospf 1 router-id 10.10.10.10
[Huawei-ospf-1]area 4
[Huawei-ospf-1-area-0.0.0.4]network 172.16.128.0 0.0.1.255
R11
[Huawei]ospf 1 router-id 11.11.11.11
[Huawei-ospf-1]are 2
[Huawei-ospf-1-area-0.0.0.2]network 172.16.96.0 0.0.1.255
R12
[Huawei]ospf 1 router-id 12.12.12.12
[Huawei-ospf-1]area 2
[Huawei-ospf-1-area-0.0.0.2]network 172.16.96.6 0.0.0.0配置RIP配置
[Huawei]rip
[Huawei-rip-1]ver 2
[Huawei-rip-1]network 172.16.0.0
第四步:完善R3/5/6/7 OSPF工作状态
R3
[Huawei]int t 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast
R5
[Huawei]int t 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast[Huawei-Tunnel0/0/0]ospf dr-priority 0
R6
[Huawei]int t 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast[Huawei-Tunnel0/0/0]ospf dr-priority 0
R7
[Huawei]int t 0/0/0
[Huawei-Tunnel0/0/0]ospf network-type broadcast[Huawei-Tunnel0/0/0]ospf dr-priority 0
查询R4邻居关系DR选举
查询R5 OSPF路由条目
area0/1/2/3全通
第五步:完善不规则区域路由,建立多进程双向重发布
[Huawei]ospf 1
[Huawei-ospf-1]import-route rip
再次查询R5 OSPF路由表
域外路由添加成功
然后将区域4通过ospf 进程2 双向重发布 建立拓扑共享
[Huawei]ospf 1
[Huawei-ospf-1]are 4
[Huawei-ospf-1-area-0.0.0.4]undo network 172.16.128.0 0.0.1.255
[Huawei]ospf 2
[Huawei-ospf-2]area 4
[Huawei-ospf-2-area-0.0.0.4]network 172.16.128.0 0.0.1.255
[Huawei]ospf 2
[Huawei-ospf-2]import-route ospf 1[Huawei]ospf 1
[Huawei-ospf-1]import-route ospf 1
查询R10 OSPF路由
添加多进程路由成功
测试R1pingR10
私网内部全网可达
第六步:减少LSA更新量
将每个区域发送到中心area0的路由汇成一条
R3
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]abr-summary 172.16.32.0 255.255.224.0
R7
[Huawei]ospf 1
[Huawei-ospf-1]area 3
[Huawei-ospf-1-area-0.0.0.2]abr-summary 172.16.64.0 255.255.224.0
R6
[Huawei]ospf 1
[Huawei-ospf-1]area 2
[Huawei-ospf-1-area-0.0.0.2]abr-summary 172.16.96.0 255.255.224.0
将RIP汇成一条发给R6
R12
[Huawei]ospf 1
[Huawei-ospf-1]asbr-summary 172.16.160.0 255.255.224.0
将特殊区域area4汇成一条发给R7
R9
[Huawei]ospf 1
[Huawei-ospf-1]asbr-summary 172.16.128.0 255.255.224.0
查询R5 OSPF路由表
区域1为完全末梢区域
R1,R2
[Huawei]ospf 1
[Huawei-ospf-1]asbr-summary
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]stub no-summary
R3
[Huawei]ospf 1
[Huawei-ospf-1]area 1
[Huawei-ospf-1-area-0.0.0.1]stub no-summary
区域234完全nssa
R12
[Huawei]ospf 1
[Huawei-ospf-1]area 2[Huawei-ospf-1-area-0.0.0.2]nssa
R11
[Huawei]ospf 1
[Huawei-ospf-1]area 2[Huawei-ospf-1-area-0.0.0.2]nssa
R6
[Huawei]ospf 1
[Huawei-ospf-1]area 2[Huawei-ospf-1-area-0.0.0.2]nssa no-summary
[Huawei]ospf 1
[Huawei-ospf-1]area 2[Huawei-ospf-1-area-0.0.0.3]nssa
[Huawei]ospf 1
[Huawei-ospf-1]area 2[Huawei-ospf-1-area-0.0.0.3]nssa
[Huawei]ospf 1
[Huawei-ospf-1]area 2[Huawei-ospf-1-area-0.0.0.3]nssa no-summary
第七步配置nat 为简化配置,先优化
R3/5/6/7 设置acl rule 允许对应网段进入 在对应接口上开启改acl
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[Huawei-GigabitEthernet0/0/1]nat outbound 2000