实验要求:
r1-r3为区域0 ,r3-r4为区域1,r3的环回也在区域0
r1-r3,r3为dr设备,没有bdr
r4环回地址已固定,其他所有网段使用192.168.1.0/24进行合理分配
r4环回不能宣告,全网可达,保障更新安全,避免环路,减少路由条目
步骤:
1)划分子网
2)配置ip以及换回地址
3)启动ospf,划分区域并宣告网段
4)将r1,r2的端口优先级改为0,使其放弃dr和bdr的选举
5)边界路由器配置缺省
6)在路由器接口配置密文认证
7)在中间路由器上进行汇总
配置命令:
[1]
sysname 1
interface GigabitEthernet0/0/0
ip address 192.168.1.1 255.255.255.192
ospf authentication-mode md5 1 cipher %
%
Cq;\C|^9kW=sSD&C|MH@~kC3%
%
端口加密
ospf dr-priority 0
interface LoopBack0
ip address 192.168.1.65 255.255.255.240
ospf 1 router-id 1.1.1.1
area 0.0.0.0
network 192.168.1.0 0.0.0.255
R2
sysname 2
interface GigabitEthernet0/0/0
ip address 192.168.1.2 255.255.255.192
ospf authentication-mode md5 1 cipher %
%
vi\BGtv!p:fN6E/=Pk(kze%
%
ospf dr-priority 0
interface LoopBack0
ip address 192.168.1.81 255.255.255.240
ospf 1 router-id 2.2.2.2
area 0.0.0.0
network 192.168.1.0 0.0.0.255
R3
sysname 3
interface GigabitEthernet0/0/0
ip address 192.168.1.3 255.255.255.192
ospf authentication-mode md5 1 cipher Xg&0;n6czPjKUGU-KkpB{k>#
interface GigabitEthernet0/0/1
ip address 192.168.1.129 255.255.255.192
interface LoopBack0
ip address 192.168.1.97 255.255.255.240
ospf 1 router-id 3.3.3.3
area 0.0.0.0
abr-summary 192.168.1.0 255.255.255.128 网段汇总
network 192.168.1.3 0.0.0.0
network 192.168.1.97 0.0.0.0
area 0.0.0.1
abr-summary 192.168.1.128 255.255.255.128
network 192.168.1.129 0.0.0.0
R4
sysname 4
interface GigabitEthernet0/0/0
ip address 192.168.1.130 255.255.255.192
interface LoopBack0
ip address 4.4.4.1 255.255.255.0
ospf 1 router-id 4.4.4.4
default-route-advertise always 缺省
area 0.0.0.1
network 192.168.1.0 0.0.0.255