1,合理的划分网络,各自创建环回接口
2,建立r1环回接口
- [r1-LoopBack0]ip address 1.1.1.1 24
- [r1-LoopBack1]ip address 172.16.1.1 24
- [r1-LoopBack2]ip address 172.16.2.1 24
- [r1-LoopBack3]ip address 172.16.3.1 24(其它同理)
3,要求R3使用R2访问R1的环回
- [r3]acl 2000
- [r3-acl-basic-2000]rule permit source 172.16.0.0 0
- [r3-acl-basic-2000]rule permit source 1.1.1.0 0
- [r3-GigabitEthernet0/0/1]rip metricin 2000 2
4,减少路由的条目数量,增加路由传递的安全性
- [r1]int g0/0/0
- [r1-GigabitEthernet0/0/0]rip summary-address 172.16.0.0 255.255.252.0
- [r1]int g0/0/1
- [r1-GigabitEthernet0/0/1]rip summary-address 172.16.0.0 255.255.252.0
- [r1]ip route-static 172.16.0.0 22 null 0
- [r1-GigabitEthernet0/0/1]rip authentication-mode md5 usual cipher 123456
- [r2-GigabitEthernet0/0/1]rip authentication-mode md5 usual cipher 123456
5,r5创建一个环回模拟运营商,不能宣告
- [r5]default-route originate
6,r1 telnet r2环回实际telnet到r7上
- [r7]aaa
- [r7-aaa]local-user admin privilege level 15 password cipher 123456
- [r7-aaa]local-user admin service-type telnet
- [r7]user-interface vty 0 4
- [r7-ui-vty0-4]authentication-mode aaa
- [r2-GigabitEthernet0/0/1]nat server protocol tcp global interface loopback 0 23
inside 7.7.7.7 23
Warning:The port 23 is well-known port. If you continue it may cause function fa
ilure.
Are you sure to continue?[Y/N]:y - [r2]acl 2000
- [r2-acl-basic-2000]rule permit source 7.0.0.0 0
- [r2]interface g 0/0/1
- [r2-GigabitEthernet0/0/1]rip metricin 2000 10
- [r4-acl-basic-2000]rule permit source 12.0.0.0 0
- [r4-GigabitEthernet0/0/1]rip metricin 2000 10
7,r6-r7路由器不能学习到达r1的环路由
- [r6-acl-basic-200o]rule 5 deny source 1.1.1.0 0
- [r6-acl-basic-2000]rule 10 deny soarce 172.16.0.0 0
- [r6-acl-basic-2000]rule permit source any
- [r6-rip-1]filter-policy 2000 import
8,全网可达
9,其他(rip设置)
[r6]rip 1
[r6-rip-1]version 1
[r6-rip-1]net 46.0.0.0
[r6-rip-1]network 67.0.0.0(r7同理)
[r6]int g 0/0/0
[r6-GigabitEthernet0/0/0]rip version 2
[r1]rip 1
[r1-rip-1]version 2
[r1-rip-1]network 12.0.0.0
[r1-rip-1]network 14.0.0.0(r1-r5同理)