1.R4为ISP,其上只能配置IP地址,R4与其他所有直连设备间均使用公用IP
2.R3-R5/R6/R7为MGRE环境,R3为中心站点
3.整个OSPF环境IP基于172.16.0.0/16划分
4.所有设备均可访问R4的环回
5.减少LSA的更新量,加快收敛,保障更新安全
6.全网可达
子网划分
172.16.0.0 16
172.16.0.0 19——area 0
172.16.0.0 25
172.16.1.0 25
172.16.2.0 25
172.16.3.0 25
172.16.4.0 25
172.16.32.0 19
172.16.32.0 25——链路
172.16.33.0 25——area 1
172.16.34.0 25
172.16.35.0 25
172.16.64.0 19——area 2
172.16.96.0 19——area 3
172.16.128.0 19——area 4
172.16.160.0 19——rip
mgre环境下
R3 S4/0/0 34.1.1.3 24
R4 S4/0/0 34.1.1.4 24
R4 S4/0/1 45.1.1.5 24
R4 S3/0/0 46.1.1.6 24
R4 GE0/0/0 47.1.1.7 24
R5 S4/0/0 45.1.1.5 24
R6 S4/0/0 46.1.1.4 24
R7 GE0/0/0 47.1.1.4 24
R1配置
[R1]interface LoopBack 0
[R1-LoopBack0]ip ad
[R1-LoopBack0]ip address 172.16.33.1 25
[R1-LoopBack0]q
[R1]int
[R1]interface g 0/0/0
[R1-GigabitEthernet0/0/0]ip ad
[R1-GigabitEthernet0/0/0]ip address 172.16.32.1 25
R2配置
[R2]interface LoopBack 0
[R2-LoopBack0]ip ad
[R2-LoopBack0]ip address 172.16.34.1 25
[R2-LoopBack0]q
[R2]int
[R2]interface g 0/0/0
[R2-GigabitEthernet0/0/0]ip ad
[R2-GigabitEthernet0/0/0]ip address 172.16.32.2 25
R3配置
[R3-LoopBack0]ip address 172.16.35.1 25
[R3-LoopBack0]q
[R3]interface GigabitEthernet 0/0/0
[R3-GigabitEthernet0/0/0]ip ad
[R3-GigabitEthernet0/0/0]ip address 172.16.32.3 25
[R3-Serial4/0/0]ip address 34.1.1.3 24
R4配置
[R4-Serial4/0/0]ip address 34.1.1.4 24
[R4-Serial4/0/1]ip address 45.1.1.4 24
[R4-Serial3/0/0]ip address 46.1.1.4 24
[R4-GigabitEthernet0/0/0]ip address 47.1.1.4 24
[R4-LoopBack0]ip address 4.4.4.4 24
R5配置
[R5-Serial4/0/0]ip address 45.1.1.5 24
[R5]interface LoopBack 0
[R5-LoopBack0]ip ad
[R5-LoopBack0]ip address 172.16.1.1 25
R6配置
[R6-Serial4/0/0]ip address 46.1.1.6 24
[R6-LoopBack0]ip address 172.16.2.1 25
[R6-GigabitEthernet0/0/0]ip address 172.16.64.1 30
R7配置
[R7-GigabitEthernet0/0/0]ip address 47.1.1.4 24
[R7-LoopBack0]ip address 172.16.3.1 25
[R7-GigabitEthernet0/0/1]ip address 172.16.96.1 30
R8配置
[R8-GigabitEthernet0/0/0]ip address 172.16.96.2 30
[R8-LoopBack0]ip address 172.16.97.1 25
[R8-GigabitEthernet0/0/1]ip address 172.16.96.5 30
R9配置
[R9-GigabitEthernet0/0/0]ip address 172.16.96.6 30
[R9-LoopBack0]ip address 172.16.129.1 25
[R9-GigabitEthernet0/0/1]ip address 172.16.128.1 30
R10配置
[R10-LoopBack0]ip address 172.16.130.1 25
[R10-GigabitEthernet0/0/0]ip address 172.16.128.2 30
R11配置
[R11-LoopBack0]ip address 172.16.65.1 25
[R11-GigabitEthernet0/0/0]ip address 172.16.64.2 30
[R11-GigabitEthernet0/0/1]ip address 172.16.64.5 30
R12配置
[R12-GigabitEthernet0/0/0]ip address 172.16.64.6 30
[R12-LoopBack0]ip address 172.16.160.1 25
[R12-LoopBack1]ip address 172.16.161.1 25
第三步:配置缺省
[R3]ip route-static 0.0.0.0 0 34.1.1.4
[R5]ip route-static 0.0.0.0 0 45.1.1.4
[R6]ip route-static 0.0.0.0 0 46.1.1.4
[R7]ip route-static 0.0.0.0 0 47.1.1.4
第四步:NAT
第五步:R3-R5/R6/R7为MGRE环境,R3为中心站点
第六步:宣告OSPF
[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1]ar
[R1-ospf-1]area 1
[R1-ospf-1-area-0.0.0.1]ne
[R1-ospf-1-area-0.0.0.1]network 172.16.0.0 0.0.255.255
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]ar
[R2-ospf-1]area 1
[R2-ospf-1-area-0.0.0.1]ne
[R2-ospf-1-area-0.0.0.1]network 172.16.0.0 0.0.255.255
[R3]ospf 1 router-id 3.3.3.3
[R3-ospf-1]ar
[R3-ospf-1]area 1
[R3-ospf-1-area-0.0.0.1]ne
[R3-ospf-1-area-0.0.0.1]network 172.16.32.3 0.0.0.0
[R3-ospf-1-area-0.0.0.0]network 172.16.0.1 0.0.0.0
[R3-ospf-1-area-0.0.0.1]network 172.16.35.1 0.0.0.0
[R5]ospf 1 router-id 5.5.5.5
[R5-ospf-1]ar
[R5-ospf-1]area 0
[R5-ospf-1-area-0.0.0.0]ne
[R5-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[R6]ospf 1 router-id 6.6.6.6
[R6-ospf-1]ar
[R6-ospf-1]area 0
[R6-ospf-1-area-0.0.0.0]ne
[R6-ospf-1-area-0.0.0.0]network 172.16.0.3 0.0.0.0
[R6-ospf-1-area-0.0.0.0]network 172.16.2.1 0.0.0.0
[R6-ospf-1-area-0.0.0.2]network 172.16.64.1 0.0.0.0
[R11-ospf-1-area-0.0.0.2]network 172.16.0.0 0.0.255.255
[R12]ospf 1 router-id 12.12.12.12
[R12-ospf-1]ar
[R12-ospf-1]area 2
[R12-ospf-1-area-0.0.0.2]ne
[R12-ospf-1-area-0.0.0.2]network 172.16.64.6 0.0.0.0
[R12]rip 1
[R12-rip-1]ver
[R12-rip-1]verify-source
[R12-rip-1]version 2
[R12-rip-1]ne
[R12-rip-1]network 172.16.0.0
[R7]ospf 1 router-id 7.7.7.7
[R7-ospf-1]ar
[R7-ospf-1]area 0
[R7-ospf-1-area-0.0.0.0]ne
[R7-ospf-1-area-0.0.0.0]network 172.16.0.4 0.0.0.0
[R7-ospf-1-area-0.0.0.0]network 172.16.3.1 0.0.0.0
[R7-ospf-1]area 3
[R7-ospf-1-area-0.0.0.3]ne
[R7-ospf-1-area-0.0.0.3]network 172.16.96.1 0.0.0.0
[R8]ospf 1 router-id 8.8.8.8
[R8-ospf-1]ar
[R8-ospf-1]area 3
[R8-ospf-1-area-0.0.0.3]ne
[R8-ospf-1-area-0.0.0.3]network 172.16.0.0 0.0.255.255
[R9]ospf 1 router-id 9.9.9.9
[R9-ospf-1]ar
[R9-ospf-1]area 3
[R9-ospf-1-area-0.0.0.3]ne
[R9-ospf-1-area-0.0.0.3]network 172.16.96.6 0.0.0.0
[R9-ospf-1]area 4
[R9-ospf-1-area-0.0.0.4]ne
[R9-ospf-1-area-0.0.0.4]network 172.16.128.1 0.0.0.0
[R9-ospf-1-area-0.0.0.4]ne
[R9-ospf-1-area-0.0.0.4]network 172.16.129.1 0.0.0.0
[R10]ospf 1 router-id 10.10.10.10
[R10-ospf-1]ar
[R10-ospf-1]area 4
[R10-ospf-1-area-0.0.0.4]ne
[R10-ospf-1-area-0.0.0.4]network 172.16.0.0 0.0.255.255
第七步:更改网络类型
[R3-Tunnel0/0/0]ospf network-type broadcast
[R5-Tunnel0/0/0]ospf network-type broadcast
[R5-Tunnel0/0/0]ospf dr-priority 0
[R6-Tunnel0/0/0]ospf network-type broadcast
[R6-Tunnel0/0/0]ospf dr-priority 0
[R7-Tunnel0/0/0]ospf network-type broadcast
[R7-Tunnel0/0/0]ospf dr-priority 0
第八步:重发布
[R9-ospf-1-area-0.0.0.4]undo network 172.16.128.1 0.0.0.0
[R9-ospf-1-area-0.0.0.4]undo network 172.16.129.1 0.0.0.0
[R9-ospf-1]undo area 4
[R9-ospf-2]area 4
[R9-ospf-2-area-0.0.0.4]ne
[R9-ospf-2-area-0.0.0.4]network 172.16.128.1 0.0.0.0
[R9-ospf-2-area-0.0.0.4]network 172.16.129.1 0.0.0.0
[R9-ospf-1]import-route ospf 2
[R12]ospf 1
[R12-ospf-1]im
[R12-ospf-1]import-route r
[R12-ospf-1]import-route rip
第九步:减少LSA的数量
区域1
[R3]ospf 1
[R3-ospf-1]ar
[R3-ospf-1]arp-ping
[R3-ospf-1]area 1
[R3-ospf-1-area-0.0.0.1]abr
[R3-ospf-1-area-0.0.0.1]abr-summary 172.16.32.0 255.255.224.0
区域2
[R6]ospf 1
[R6-ospf-1]ar
[R6-ospf-1]arp-ping
[R6-ospf-1]area 2
[R6-ospf-1-area-0.0.0.2]ab
[R6-ospf-1-area-0.0.0.2]abr-summary 172.16.64.0 255.255.224.0
区域3
[R7]ospf 1
[R7-ospf-1]ar
[R7-ospf-1]arp-ping
[R7-ospf-1]area 3
[R7-ospf-1-area-0.0.0.3]ab
[R7-ospf-1-area-0.0.0.3]abr-summary 172.16.96.0 255.255.224.0
域外路由汇总
[R9]ospf 1
[R9-ospf-1]as
[R9-ospf-1]asbr-summary 172.16.128.0 255.255.224.0
[R12]ospf 1
[R12-ospf-1]as
[R12-ospf-1]asbr-summary 172.16.160.0 255.255.224.0
末梢区域
[R1-ospf-1-area-0.0.0.1]stub
[R2-ospf-1]area 1
[R2-ospf-1-area-0.0.0.1]sr
[R2-ospf-1-area-0.0.0.1]st
[R2-ospf-1-area-0.0.0.1]stub
[R3-ospf-1-area-0.0.0.1]stub no-summary
[R6]ospf 1
[R6-ospf-1]ar
[R6-ospf-1]arp-ping
[R6-ospf-1]area 2
[R6-ospf-1-area-0.0.0.2]ns
[R6-ospf-1-area-0.0.0.2]nssa
R11-ospf-1-area-0.0.0.2]nssa
[R12-ospf-1-area-0.0.0.2]nssa
[R6-ospf-1-area-0.0.0.2]nssa no-import-route
[R7]ospf 1
[R7-ospf-1]ar
[R7-ospf-1]arp-ping
[R7-ospf-1]area 3
[R7-ospf-1-area-0.0.0.3]nss
[R7-ospf-1-area-0.0.0.3]nssa
[R8]ospf 1
[R8-ospf-1]ar
[R8-ospf-1]arp-ping
[R8-ospf-1]area 3
[R8-ospf-1-area-0.0.0.3]nss
[R8-ospf-1-area-0.0.0.3]nssa
[R9]ospf 1
[R9-ospf-1]ar
[R9-ospf-1]arp-ping
[R9-ospf-1]area 3
[R9-ospf-1-area-0.0.0.3]nss
[R9-ospf-1-area-0.0.0.3]nssa
[R7-ospf-1-area-0.0.0.3]nssa no-import-route
测试:
配置空接口,配置防环
[R3]ip route-static 172.16.32.0 19 NULL 0
[R6]ip route-static 172.16.64.0 19 NULL 0
[R7]ip route-static 172.16.96.0 19 NULL 0
[R9]ip route-static 172.16.128.0 19 NULL 0
[R12]ip route-static 172.16.160.0 19 NULL 0
加快收敛
[R3]interface Tunnel 0/0/0
[R3-Tunnel0/0/0]os
[R3-Tunnel0/0/0]ospf t
[R3-Tunnel0/0/0]ospf trans-delay
[R3-Tunnel0/0/0]ospf timer h
[R3-Tunnel0/0/0]ospf timer hello 5
[R5]interface Tunnel 0/0/0
[R5-Tunnel0/0/0]os
[R5-Tunnel0/0/0]ospf t
[R5-Tunnel0/0/0]ospf trans-delay
[R5-Tunnel0/0/0]ospf timer h
[R5-Tunnel0/0/0]ospf timer hello 5
[R6]interface Tunnel 0/0/0
[R6-Tunnel0/0/0]os
[R6-Tunnel0/0/0]ospf t
[R6-Tunnel0/0/0]ospf trans-delay
[R6-Tunnel0/0/0]ospf timer h
[R6-Tunnel0/0/0]ospf timer hello 5
[R7]interface Tunnel 0/0/0
[R7-Tunnel0/0/0]os
[R7-Tunnel0/0/0]ospf t
[R7-Tunnel0/0/0]ospf trans-delay
[R7-Tunnel0/0/0]ospf timer h
[R7-Tunnel0/0/0]ospf timer hello 5
保障更新安全
[R3-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 123456
[R2-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 123456
[R1-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 123456
[R6-ospf-1-area-0.0.0.2]authentication-mode md5 1 cipher 234567
[R11-ospf-1-area-0.0.0.2]authentication-mode md5 1 cipher 234567
[R12-ospf-1-area-0.0.0.2]authentication-mode md5 1 cipher 234567
[R7-ospf-1-area-0.0.0.3]authentication-mode md5 1 cipher 345678
[R8-ospf-1-area-0.0.0.3]authentication-mode md5 1 cipher 345678
[R9-ospf-1-area-0.0.0.3]authentication-mode md5 1 cipher 345678
全网可达