实验要求
搭建拓扑图 并进行网段划分
网段划分按区域划分
172.16.0.0/16划分成8个网段使用6个保留2个
再将其进行细分
1.首先做基本配置
[r1]interface g0/0/0
[r1-GigabitEthernet0/0/0]ip address 172.16.33.2 29
[r1]interface LoopBack 0
[r1-LoopBack0]ip address 172.16.34.1 24
[r2]interface g0/0/2
[r2-GigabitEthernet0/0/2]inter g0/0/0
[r2-GigabitEthernet0/0/0]ip address 172.16.33.3 29
[r2-GigabitEthernet0/0/0]inter loopback 0
[r2-LoopBack0]ip address 172.16.35.1 24
其他同理
2.搭建mgre
r3中心
[r3]ip route-static 0.0.0.0 0 1.0.0.2 缺省
[r3]interface t0/0/0
[r3-Tunnel0/0/0]ip address 172.16.1.1 29
[r3-Tunnel0/0/0]tunnel-protocol gre p2mp
[r3-Tunnel0/0/0]source 1.0.0.1
[r3-Tunnel0/0/0]nhrp network-id 100[r3-Tunnel0/0/0]nhrp entry multicast dynamic 开启伪广播
分支
[r5]ip route-static 0.0.0.0 0 3.0.0.2
[r5]interface t0/0/0
[r5-Tunnel0/0/0]ip address 172.16.1.2 29
[r5-Tunnel0/0/0]tunnel-protocol gre p2mp
[r5-Tunnel0/0/0]source Serial 4/0/0
[r5-Tunnel0/0/0]nhrp network-id 100
[r5-Tunnel0/0/0]nhrp entry 172.16.1.1 1.0.0.1 register
[r6]ip route-static 0.0.0.0 0 2.0.0.2[r6]interface t0/0/0
[r6-Tunnel0/0/0]ip address 172.16.1.3 29
[r6-Tunnel0/0/0]tunnel-protocol gre p2mp
[r6-Tunnel0/0/0]source Serial 4/0/0
[r6-Tunnel0/0/0]nhrp network-id 100
[r6-Tunnel0/0/0]nhrp entry 172.16.1.1 1.0.0.1 register[r7]ip route-static 0.0.0.0 0 4.0.0.2
[r7]interface t0/0/0
[r7-Tunnel0/0/0]ip address 172.16.1.4 29
[r7-Tunnel0/0/0]tunnel-protocol gre p2mp
[r7-Tunnel0/0/0]source GigabitEthernet 0/0/0
[r7-Tunnel0/0/0]nhrp network-id 100
[r7-Tunnel0/0/0]nhrp entry 172.16.1.1 1.0.0.1 register
3.开启ospf协议
[r1]ospf 1 router-id 1.1.1.1
[r1-ospf-1]area 1
[r1-ospf-1-area-0.0.0.1]network 172.16.34.0 0.0.0.255
[r1-ospf-1-area-0.0.0.1]network 172.16.33.0 0.0.0.255
[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1-area-0.0.0.1]network 172.16.35.0 0.0.0.255
[r2-ospf-1-area-0.0.0.1]network 172.16.33.0 0.0.0.255
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]network 172.16.32.0 0.0.0.255
[r3-ospf-1-area-0.0.0.1]network 172.16.33.0 0.0.0.255[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]network 172.16.1.1 0.0.0.0
[r5]ospf 1 router-id 5.5.5.5
[r5-ospf-1]area 0
[r5-ospf-1-area-0.0.0.0]network 172.16.1.2 0.0.0.0其他同理
4.r12上开启rip协议
[r12]rip 1
[r12-rip-1]version2
[r12-rip-1]network 172.16.0.0
[r3]interface t0/0/0
[r3-Tunnel0/0/0]ospf network-type broadcast
5.更改mgre环境中的接口类型
[r3]interface t0/0/0
[r3-Tunnel0/0/0]ospf network-type broadcast[r5]interface t0/0/0
[r5-Tunnel0/0/0]ospf network-type broadcast[r6]interface t0/0/0
[r6-Tunnel0/0/0]ospf network-type broadcast[r7]interface t0/0/0
[r7-Tunnel0/0/0]ospf network-type broadcast
6.修改R567的接口优先级
[r5-Tunnel0/0/0]ospf dr-priority 0
[r6-Tunnel0/0/0]ospf dr-priority 0
[r7-Tunnel0/0/0]ospf dr-priority 0
不参与dr,bdr选举避免冲突
7.测试一下mgre
![]()
![]()
![]()
互相能通mgre没有问题
7. 在R9和R12上进行多进程双向重发布
[r9]ospf 1
[r9-ospf-1]import-route ospf 2[r12]ospf 1
[r12-ospf-1]import-route rip
8.abr上做域间路由汇总asbr上域外路由汇总
[r3]ospf 1
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]abr-summary 172.16.32.0 255.255.255.0[r6]ospf 1
[r6-ospf-1]area 2
[r6-ospf-1-area-0.0.0.2]abr-summary 172.168.128.0 255.255.255.0[r7]ospf 1
[r7-ospf-1]area 3
[r7-ospf-1-area-0.0.0.3]abr-summary 172.16.64.0 255.255.255.0
[r9]ospf 2
[r9-ospf-2]area 4
[r9-ospf-2-area-0.0.0.4]abr-summary 172.16.96.0 255.255.255.0[r12]ospf 1
[r12-ospf-1-area-0.0.0.1]abr-summary 172.168.129.0 255.255.255.0
9.将area1做成完全末梢区域area2area3做成完全的nssa区域
[r3]ospf 1
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]stub1区域r1,r2同理
[r6]ospf 1
[r6-ospf-1]area 2
[r6-ospf-1-area-0.0.0.2]nssa no-summary[r11]ospf 1
[r11-ospf-1]area 2
[r11-ospf-1-area-0.0.0.2]nssa[r12]ospf 1
[r12-ospf-1]area 2
[r12-ospf-1-area-0.0.0.2]nssa[r7]ospf
[r7-ospf-1]area 3
[r7-ospf-1-area-0.0.0.3]nssa no-summary[r8]ospf 1
[r8-ospf-1]area 3
[r8-ospf-1-area-0.0.0.3]nssa[r9]ospf 1
[r9-ospf-1]area 3
[r9-ospf-1-area-0.0.0.3]nssa
10.配置空接口防环
[r3]ip route-static 172.16.32.0 19 NULL 0
[r6]ip route-static 172.16.128.0 19 NULL 0
[r7]ip route-static 172.16.64.0 19 NULL 0
[r9]ip route-static 172.16.96.0 19 NULL 0
[r12]ip route-static 172.16.160.0 19 NULL 0
11.配置nat
[r3]acl 2000
[r3-acl-basic-2000]rule permit source 172.16.32.0 0.0.255.255
[r3-acl-basic-2000]q
[r3]interface s4/0/0
[r3-Serial4/0/0]nat outbound 2000[r7]acl 2000
[r7-acl-basic-2000]rule permit source 172.16.64.0 0.0.255.255
[r7-acl-basic-2000]q
[r7]interface g0/0/0
[r7-GigabitEthernet0/0/0]nat outbound 2000[r6]acl 2000
[r6-acl-basic-2000]rule permit source 172.16.128.0 0.0.255.255
[r6-acl-basic-2000]q
[r6]interface g0/0/0
[r6-GigabitEthernet0/0/0]nat outbound 2000[r5]acl 2000
[r5-acl-basic-2000]rule permit source 172.16.1.0 0.0.0.255
[r5-acl-basic-2000]q
[r5]interface s4/0/0
[r5-Serial4/0/0]nat outbound 2000
12.区域认证保证安全
[r1]ospf
[r1-ospf-1]area 1
[r1-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 1234[r2]ospf
[r2-ospf-1]area 1
[r2-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 1234[r3]ospf
[r3-ospf-1]area 1
[r3-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 1234其他区域同理
13.加快收敛速度
[r3]interface t0/0/0
[r3-Tunnel0/0/0]ospf timer hello 5
[r3-Tunnel0/0/0]ospf timer dead 20[r5]interface t0/0/0
[r5-Tunnel0/0/0]ospf timer hello 5
[r5-Tunnel0/0/0]ospf timer dead 20[r6]interface t0/0/0
[r6-Tunnel0/0/0]ospf timer hello 5
[r6-Tunnel0/0/0]ospf timer dead 20[r7]interface t0/0/0
[r7-Tunnel0/0/0]ospf timer hello 5
[r7-Tunnel0/0/0]ospf timer dead 20
14.测试结果