hcip---ospf综合实验

一:实验要求

1、R4为ISP,其上只能配置IP地址,R4与其所有直连设备间均使用公有IP

2、R3-R5/6/7为MGRE环境,R3为中心站点

3、整个OSPF环境IP基于R4的环回

4、所有设备均可访问R4的环回

5、减少LSA的更新量,加快收敛,保障更新安全

6、全网可达

二:实验分析

1:子网划分

基于172.16.0.0/16划分网段

172.16.0.0/16

172.16.0.0/19 area 0
172.16.0.0/24 p2p骨干
172.16.1.0/24 MA骨干
172.16.1.0/29 T通道
172.16.2.0/24 R5环回
172.16.3.0/24 R6环回
172.16.4.0/24 R7环回
172.16.5.0/24 R4环回

172.16.32.0/19 area 1
172.16.32.0/24 p2p
172.16.33.0/24 MA
172.16.33.0/29
172.16.34.0/24 R1环回
172.16.35.0/24 R2环回
172.16.36.0/24 R3环回

172.16.64.0/19 area 2 172.16.65.0/24 p2p****172.16.64.0/24 MA
172.16.64.0/30
172.16.64.4/30
172.16.66.0/24 R11环回

172.16.96.0/19 area 3
172.16.96.0/24 MA
172.16.96.0/30
172.16.96.4/30
172.16.97.0/24 p2p
172.16.98.0/24 R8环回

172.16.128.0/19 area 4
172.16.128.0/24 MA
172.16.128.0/30
172.16.129.0/24 p2p
172.16.130.0/24 R9环回
172.16.131.0/24 R10环回

172.16.160.0/19 rip
172.16.160.0/24 MA
172.16.161.0/24 P2P
172.16.162.0/24 R12环回
172.16.163.0/24 R12环回

2、实验拓扑

三:实验配置

配置IP地址

r1-GigabitEthernet0/0/0\]ip address 172.16.33.1 29 \[r1-LoopBack0\]ip addres9999s 172.16.34.1 24 \[r2-GigabitEthernet0/0/0\]ip address 172.16.33.2 29 \[r2-LoopBack0\]ip address 172.16.35.1 24 \[r3-GigabitEthernet0/0/0\]ip address 172.16.33.3 29 \[r3-Serial4/0/0\]ip address 34.1.1.1 24 \[r3-LoopBack0\]ip address 172.16.36.1 24 \[r4-Serial4/0/0\]ip address 34.1.1.2 24 \[r4-Serial4/0/1\]ip address 45.1.1.2 24 \[r4-Serial3/0/0\]ip address 46.1.1.2 24 \[r4-GigabitEthernet0/0/0\]ip address 47.1.1.2 24 \[r4-LoopBack0\]ip address 172.16.5.1 24 \[r5-Serial4/0/0\]ip address 45.1.1.1 24 \[r5-LoopBack0\]ip address 172.16.2.1 24 \[r6-Serial4/0/0\]ip address 46.1.1.1 24 \[r6-GigabitEthernet0/0/0\]ip address 172.16.64.1 30 \[r6-LoopBack0\]ip address 172.16.3.1 24 \[r7-GigabitEthernet0/0/0\]ip address 47.1.1.1 24 \[r7-GigabitEthernet0/0/1\]ip address 172.16.96.1 30 \[r7-LoopBack0\]ip address 172.16.4.1 24 \[r8-GigabitEthernet0/0/0\]ip address 172.16.96.2 30 \[r8-GigabitEthernet0/0/1\]ip address 172.16.96.5 30 \[r8-LoopBack0\]ip address 172.16.98.1 24 \[r9-GigabitEthernet0/0/0\]ip address 172.16.96.6 30 \[r9-GigabitEthernet0/0/1\]ip address 172.16.128.1 30 \[r9-LoopBack0\]ip address 172.16.130.1 24 \[r10-GigabitEthernet0/0/0\]ip address 172.16.128.2 30 \[r10-LoopBack0\]ip address 172.16.131.1 24 \[r11-GigabitEthernet0/0/0\]ip address 172.16.64.2 30 \[r11-GigabitEthernet0/0/1\]ip address 172.16.64.5 30 \[r11-LoopBack0\]ip address 172.16.66.1 24 \[r12-GigabitEthernet0/0/0\]ip address 172.16.64.6 30 \[r12-LoopBack0\]ip address 172.16.162.1 24 \[r12-LoopBack1\]ip address 172.16.163.1 24 **配置MGRE** ![](https://file.jishuzhan.net/article/1753752821364166657/ace1cab6a117ad297216b458926807d6.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/93d1fc3b157aebf07b8fa09dfa3b68cd.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/ed28dd57834a1a1ebb49a5ff27bcc089.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/a4a256f304026e70f41afbef8072f2d3.webp) **写缺省让公网以及通道连接,修改通道ospf优先级以及MGRE修改为BMA网络,或者修改成p2mp** **网络就不用选举来修改ospf优先级** \[r3\]ip route-static 0.0.0.0 0 34.1.1.2 \[r5\]ip route-static 0.0.0.0 0 45.1.1.2 \[r6\]ip route-static 0.0.0.0 0 46.1.1.2 \[r7\]ip route-static 0.0.0.0 0 47.1.1.2 \[r3-Tunnel0/0/0\]ospf dr-priority 100 \[r3-Tunnel0/0/0\]ospf network-type broadcast \[r5-Tunnel0/0/0\]ospf dr-priority 0 \[r5-Tunnel0/0/0\]ospf network-type broadcast \[r6-Tunnel0/0/0\]ospf dr-priority 0 \[r6-Tunnel0/0/0\]ospf network-type broadcast \[r7-Tunnel0/0/0\]ospf dr-priority 0 \[r7-Tunnel0/0/0\]ospf network-type broadcast **宣告ospf和rip** ![](https://file.jishuzhan.net/article/1753752821364166657/0a689ecb5c041046cd08d08875364889.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/26f0e104385fca47bd58a7d5f4ff12b7.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/e86bb2dafd5ed2ace6659b6be7f4502c.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/e2dc6de90c913001a2e535291f63b2f5.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/643e46364ac81f92370ab08ed7b349a5.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/839dbf5551ea6b0301bdda57cc3fb336.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/320abac0085e0220663ac52468ea2c20.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/a1074e71a2ef099a2f6c3a113942ead9.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/ecbd1cf4c8492e190b1a42644ebc5dd5.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/ecbd1cf4c8492e190b1a42644ebc5dd5.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/6af1938de4231d92edd3a44ac7c6b43d.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/c85917f7227d2c2a906396a919d5c7ef.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/58e495b652f6ae6b192f0068031e7c90.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/4def57baaf69c536a0a16039578a72cf.webp) **r12路由器用单点单向重发布。r9路由器做一个单点单向重发布,r10路由器写一条缺省指向R9接** **口,或者在R9进程2下放一个缺省** \[r9-ospf-1\]import-route ospf 2 \[r12-ospf-1\]import-route rip 1 \[r10\]ip route-static 0.0.0.0 0 172.16.128.1 **r3/5/6/7路由器上做一个easy ip 使得其他路由器能访问r4的环回** \[r3\]acl 2000 \[r3-acl-basic-2000\]rule permit source 172.16.0.0 0.0.0.255 \[r3-Serial4/0/0\]nat outbound 2000 \[r7\]acl 2000 \[r7-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[r7-GigabitEthernet0/0/0\]nat outbound 2000 \[r6\]acl 2000 \[r6-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[r6-Serial4/0/0\]nat outbound 2000 \[r5\]acl 2000 \[r5-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[r5-Serial4/0/0\]nat outbound 2000 **路由汇总以及空接口** \[r3-ospf-1-area-0.0.0.1\]abr-summary 172.16.32.0 255.255.224.0 \[r6-ospf-1-area-0.0.0.2\]abr-summary 172.16.64.0 255.255.224.0 \[r7-ospf-1-area-0.0.0.3\]abr-summary 172.16.96.0 255.255.224.0 \[r9-ospf-1\]asbr-summary 172.16.128.0 255.255.224.0 \[r12-ospf-1\]asbr-summary 172.16.160.0 255.255.224.0 \[r3\]ip route-static 172.16.32.0 19 NULL 0 \[r6\]ip route-static 172.16.64.0 19 NULL 0 \[r7\]ip route-static 172.16.96.0 19 NULL 0 \[r9\]ip route-static 172.16.128.0 19 NULL 0 \[r12\]ip route-static 172.16.160.0 19 NULL 0 **做特殊区域减少LSA** \[r1-ospf-1-area-0.0.0.1\]stub \[r2-ospf-1-area-0.0.0.1\]stub \[r3-ospf-1-area-0.0.0.1\]stub no-summary \[r6-ospf-1-area-0.0.0.2\]nssa no-summary \[r11-ospf-1-area-0.0.0.2\]nssa \[r12-ospf-1-area-0.0.0.2\]nssa \[r7-ospf-1-area-0.0.0.3\]nssa no-summary \[r8-ospf-1-area-0.0.0.3\]nssa \[r9-ospf-1-area-0.0.0.3\]nssa **加快收敛** \[r1-GigabitEthernet0/0/0\]ospf timer hello 5 \[r2-GigabitEthernet0/0/0\]ospf timer hello 5 \[r3-GigabitEthernet0/0/0\]ospf timer hello 5 **区域认证** \[r1-ospf-1-area-0.0.0.1\]authentication-mode simple plain 123456 \[r2-ospf-1-area-0.0.0.1\]authentication-mode simple plain 123456 \[r3-ospf-1-area-0.0.0.1\]authentication-mode simple plain 123456 ![](https://file.jishuzhan.net/article/1753752821364166657/d22ef4dafc72786f9b6c7f6e1ff01c8a.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/65407a33e439e7c5d2b757c8c2df3a00.webp) **四、测试** **所以用户可以r4 环回** ![](https://file.jishuzhan.net/article/1753752821364166657/e5ede9b5fcb2c8b6848843d6cca02bf9.webp) ![](https://file.jishuzhan.net/article/1753752821364166657/fab26abba97ed5fc983248b6b449e23d.webp) 全网可达 ![](https://file.jishuzhan.net/article/1753752821364166657/978df921d0a8407d221028f90a41853e.webp)![](https://file.jishuzhan.net/article/1753752821364166657/d43dbe003da2a0d63a9912d1811cf119.webp)

相关推荐
唯独失去了从容1 小时前
WebRTC服务器Coturn服务器的管理平台功能
运维·服务器·webrtc
PassLink_5 小时前
[Kaggle]:使用Kaggle服务器训练YOLOv5模型 (白嫖服务器)
运维·服务器·yolo
朴拙数科5 小时前
MongoDB Atlas与MongoDB连接MCP服务器的区别解析
服务器·数据库·mongodb
程序猿(雷霆之王)6 小时前
Linux——进程间通信
linux·运维·服务器
一颗星星辰6 小时前
路由交换网络专题 | 第八章 | GVRP配置 | 端口安全 | 端口隔离 | Mux-VLAN | Hybrid
网络·安全
自由鬼6 小时前
高性能的开源网络入侵检测和防御引擎:Suricata介绍
网络·安全·网络安全·开源·系统安全·入侵检测
老六ip加速器6 小时前
如何获取静态IP地址?完整教程
网络·网络协议·tcp/ip
riveting7 小时前
SD2351核心板:重构AI视觉产业价值链的“超级节点”
大数据·linux·图像处理·人工智能·重构·智能硬件
易保山8 小时前
MIT6.S081 - Lab10 mmap(文件&内存映射)
linux·操作系统·c
NoneCoder8 小时前
HTML 模板技术与服务端渲染
服务器·servlet·html