
实验需求
1、R4为ISP,其上只配置IP地址;R4与其他所直连设备间均使用公有IP;
2、R3-R5、R6、R7为MGRE环境,R3为中心站点;
3、整个OSPF环境IP基于172.16.0.0/16划分;除了R12有两个环回,其他路由器均有一个环回IP
4、所有设备均可访问R4的环回;
5、减少LSA的更新量,加快收敛,保障更新安全;
6、全网可达;
思路
1、划分地址、配置IP地址
2、公网通,并做测试
3、各个内网通,重发布,做测试--邻居表-OSPF路由表
4、配置MGRE VPN
5、NAT
6、做区域间的路由聚合,防环--精简area 0的LSDB、路由表
7、做域外路由聚合,防环--精简area 0的LSDB、路由表
8、做特殊区域,精简除了AREA 0外的其他ospf区域的LSDB\路由表
9、加快收敛---更改HELLO时间
10、区域认证、接口
配ip及环回
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 172.16.33.1 24
[R1-GigabitEthernet0/0/0]int l0
[R1-LoopBack0] ip add 172.16.34.1 24
[R1-LoopBack0]q
R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 172.16.33.2 24
[R2-GigabitEthernet0/0/0]int l0
[R2-LoopBack0]ip add 172.16.35.2 24
[R2-LoopBack0]
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]ip add 172.16.33.3 24
[R3-GigabitEthernet0/0/0]int l0
[R3-LoopBack0]ip add 172.16.36.3 24
[R3-LoopBack0]int s4/0/0
[R3-Serial4/0/0]ip add 34.0.0.3 24
[R3-Serial4/0/0]q
R4]int s4/0/0
[R4-Serial4/0/0]ip add 34.0.0.4 24
[R4-Serial4/0/0]int s4/0/1
[R4-Serial4/0/1]ip add 45.0.0.4 24
[R4-Serial4/0/1]int s3/0/0
[R4-Serial3/0/0]ip add 46.0.0.4 24
[R4-Serial3/0/0]int g0/0/0
[R4-GigabitEthernet0/0/0]ip add 47.0.0.4 24
[R4-GigabitEthernet0/0/0]int l0
[R4-LoopBack0]ip add 172.16.2.4 24
[R4-LoopBack0]q
[R5]int s4/0/0
[R5-Serial4/0/0]ip add 45.0.0.5 24
[R5-Serial4/0/0]int l0
[R5-LoopBack0]ip add 172.16.3.5 24
[R5-LoopBack0]q
[R6]int s4/0/0
[R6-Serial4/0/0]ip add 46.0.0.6 24
[R6-Serial4/0/0]int g0/0/0
[R6-GigabitEthernet0/0/0]ip add 172.16.65.1 30
[R6-GigabitEthernet0/0/0]int l0
[R6-LoopBack0]ip add 172.16.4.6 24
[R6-LoopBack0]q
[R7]int g0/0/0
[R7-GigabitEthernet0/0/0]ip add 47.0.0.7 24
[R7-GigabitEthernet0/0/0]int g0/0/1
[R7-GigabitEthernet0/0/1]ip add 172.16.97.1 30
[R7-GigabitEthernet0/0/1]int l0
[R7-LoopBack0]ip add 172.16.5.7 24
[R7-LoopBack0]q
[R8]int g0/0/0
[R8-GigabitEthernet0/0/0]ip add 172.16.97.2 30[R8-GigabitEthernet0/0/0]int g0/0/1
[R8-GigabitEthernet0/0/1]ip add 172.16.97.5 30
[R8-GigabitEthernet0/0/1]int l0
[R8-LoopBack0]ip add 172.16.98.8 24
[R8-LoopBack0]q
[R9]int g0/0/0
[R9-GigabitEthernet0/0/0]ip add 172.16.97.6 30
[R9-GigabitEthernet0/0/0]int g0/0/1
[R9-GigabitEthernet0/0/1]ip add 172.16.129.1 30[R9-GigabitEthernet0/0/1]int l0
[R9-LoopBack0]ip add 172.16.130.9 24
[R9-LoopBack0]q
[R10]int g0/0/0
[R10-GigabitEthernet0/0/0]ip add 172.16.129.2 30
[R10-GigabitEthernet0/0/0]int l0
[R10-LoopBack0]ip add 172.16.131.10 24
[R10-LoopBack0]q
[R11]int g0/0/0
[R11-GigabitEthernet0/0/0]ip add 172.16.65.2 30
[R11-GigabitEthernet0/0/0]int g0/0/1
[R11-GigabitEthernet0/0/1]ip add 172.16.65.5 30
[R11-GigabitEthernet0/0/1]int l0
[R11-LoopBack0]ip add 172.16.66.11 24
[R12]int g0/0/0
[R12-GigabitEthernet0/0/0]ip add 172.16.65.6 30
[R12-GigabitEthernet0/0/0]int l0
[R12-LoopBack0]ip add 172.16.160.12 24
[R12-LoopBack0]int l1
[R12-LoopBack1]ip add 172.16.161.12 24
公网通(在公网部分配置缺省路由指向r4)
[R3]ip route-static 0.0.0.0 0 34.0.0.4
[R5]ip route-static 0.0.0.0 0 45.0.0.4
[R6]ip route-static 0.0.0.0 0 46.0.0.4
[R7]ip route-static 0.0.0.0 0 47.0.0.4
测试

配置ospf
a1
R1\]ospf 1 router-id 1.1.1.1 \[R1-ospf-1\]a 1 \[R1-ospf-1-area-0.0.0.1\]ne 172.16.33.0 0.0.0.255 \[R1-ospf-1-area-0.0.0.1\]net 172.16.34.0 0.0.0.255 \[R1-ospf-1-area-0.0.0.1\]q \[R2\]ospf 1 router-id 2.2.2.2 \[R2-ospf-1\]a 1 \[R2-ospf-1-area-0.0.0.1\]net 172.16.33.0 0.0.0.255 \[R2-ospf-1-area-0.0.0.1\]ne 172.16.35.0 0.0.0.255 \[R3\]ospf 1 router-id 3.3.3.3 \[R3-ospf-1\]a 1 \[R3-ospf-1-area-0.0.0.1\]net 172.16.33.0 0.0.0.255 \[R3-ospf-1-area-0.0.0.1\]net 172.16.36.0 0.0.0.255 **a0** \[R5\]ospf 1 router-id 5.5.5.5 \[R5-ospf-1\]a 0 \[R5-ospf-1-area-0.0.0.0\]net 172.16.3.0 0.0.0.255 \[R6\]ospf 1 router-id 6.6.6.6 \[R6-ospf-1\]a 0 \[R6-ospf-1-area-0.0.0.0\]net 172.16.4.0 0.0.0.255 \[R7\]ospf 1 router-id 7.7.7.7 \[R7-ospf-1\]a 0 \[R7-ospf-1-area-0.0.0.0\]net 172.16.5.0 0.0.0.255 **a2** \[R6-ospf-1\]a 2 \[R6-ospf-1-area-0.0.0.2\]net 172.16.65.1 0.0.0.0 \[R11\]ospf 1 router-id 11.11.11.11 \[R11-ospf-1\]a 2 \[R11-ospf-1-area-0.0.0.2\]net 172.16.65.2 0.0.0.0 \[R11-ospf-1-area-0.0.0.2\]net 172.16.65.5 0.0.0.0 \[R11-ospf-1-area-0.0.0.2\]net 172.16.66.0 0.0.0.255 \[R12\]ospf 1 router-id 12.12.12.12 \[R12-ospf-1\]a 2 \[R12-ospf-1-area-0.0.0.2\]net 172.16.65.6 0.0.0.0 **a3 \[R7\]ospf 1 \[R7-ospf-1\]a 3 \[R7-ospf-1-area-0.0.0.3\]ne 172.16.97.1 0.0.0.0 \[R7-ospf-1-area-0.0.0.3\]q \[R8\]ospf 1 router-id 8.8.8.8 \[R8-ospf-1\]a 3 \[R8-ospf-1-area-0.0.0.3\]ne 172.16.97.2 0.0.0.0 \[R8-ospf-1-area-0.0.0.3\]ne 172.16.97.5 0.0.0.0 \[R8-ospf-1-area-0.0.0.3\]net 172.16.98.0 0.0.0.255 \[R9\]ospf 1 router-id 9.9.9.9 \[R9-ospf-1\]a 3 \[R9-ospf-1-area-0.0.0.3\]ne 172.16.97.6 0.0.0.0 \[R9-ospf-1-area-0.0.0.3\]q** **a4 \[R9\]ospf 2 router-id 9.9.9.9 \[R9-ospf-2\]a 4 \[R9-ospf-2-area-0.0.0.4\]net 172.16.129.1 0.0.0.0 \[R9-ospf-2-area-0.0.0.4\]net 172.16.130.0 0.0.0.255 \[R9-ospf-2-area-0.0.0.4\]q \[R10\]ospf 2 router-id 10.10.10.10 \[R10-ospf-2\]a 4 \[R10-ospf-2-area-0.0.0.4\]net 172.16.129.1 0.0.0.0 \[R10-ospf-2-area-0.0.0.4\]undo net 172.16.129.1 0.0.0.0 \[R10-ospf-2-area-0.0.0.4\]net 172.16.129.2 0.0.0.0 \[R10-ospf-2-area-0.0.0.4\]net 172.16.131.0 0.0.0.25** **RIP** \[R12\]rip 1 \[R12-rip-1\]v 2 \[R12-rip-1\]undo summary \[R12-rip-1\]net 172.16.0.0 \[R12-rip-1\]q \[R12\]ospf 1 \[R12-ospf-1\]import-route rip
建立MGRE虚拟隧道,R3为中心站点,R567为分支站点
R3\]int Tunnel 0/0/0 \[R3-Tunnel0/0/0\]ip add 172.16.6.3 24 \[R3-Tunnel0/0/0\]tunnel-protocol gre p2mp \[R3-Tunnel0/0/0\]source s4/0/0 \[R3-Tunnel0/0/0\]nhrp network-id 100 \[R3-Tunnel0/0/0\]nhrp entry multicast dynamic \[R5\]int Tunnel 0/0/0 \[R5-Tunnel0/0/0\]ip add 172.16.6.5 24 \[R5-Tunnel0/0/0\]tunnel-protocol gre p2mp \[R5-Tunnel0/0/0\]source s4/0/0 \[R5-Tunnel0/0/0\]nhrp network-id 100 \[R5-Tunnel0/0/0\]nhrp entry 172.16.6.3 34.0.0.3 register \[R6\]int Tunnel 0/0/0 \[R6-Tunnel0/0/0\]ip add 172.16.6.6 24 \[R6-Tunnel0/0/0\]tunnel-protocol gre p2mp \[R6-Tunnel0/0/0\]source s4/0/0 \[R6-Tunnel0/0/0\]nhrp network-id 100 \[R6-Tunnel0/0/0\]nhrp entry 172.16.6.3 34.0.0.3 register \[R7\]int t0/0/0 \[R7-Tunnel0/0/0\]ip add 172.16.6.7 24 \[R7-Tunnel0/0/0\]tunnel-protocol gre p2mp \[R7-Tunnel0/0/0\]source g0/0/0 \[R7-Tunnel0/0/0\]nhrp network-id 100 \[R7-Tunnel0/0/0\]nhrp entry 172.16.6.3 34.0.0.3 register ## a0宣告隧道网段 \[R3\]ospf 1 \[R3-ospf-1\]a 0 \[R3-ospf-1-area-0.0.0.0\]ne 172.16.6.0 0.0.0.255 \[R5\]ospf 1 \[R5-ospf-1\]a 0 \[R5-ospf-1-area-0.0.0.0\]net 172.16.6.0 0.0.0.255 \[R6\]ospf 1 \[R6-ospf-1\]a 0 \[R6-ospf-1-area-0.0.0.0\]net 172.16.6.0 0.0.0.255 \[R7\]ospf 1 \[R7-ospf-1\]a 0 \[R7-ospf-1-area-0.0.0.0\]net 172.16.6.0 0.0.0.255

更改隧道类型
R3\]ospf 1 \[R3-ospf-1\]a 0 \[R3-ospf-1-area-0.0.0.0\]ne 172.16.6.0 0.0.0.255 \[R5\]ospf 1 \[R5-ospf-1\]a 0 \[R5-ospf-1-area-0.0.0.0\]net 172.16.6.0 0.0.0.255 \[R6\]ospf 1 \[R6-ospf-1\]a 0 \[R6-ospf-1-area-0.0.0.0\]net 172.16.6.0 0.0.0.255 \[R7\]ospf 1 \[R7-ospf-1\]a 0 \[R7-ospf-1-area-0.0.0.0\]net 172.16.6.0 0.0.0.255 取消分站点选举资格 \[R5\]int t0/0/0 \[R5-Tunnel0/0/0\]ospf dr-priority 0 \[R6\]int t0/0/0 \[R6-Tunnel0/0/0\]ospf dr-priority 0 \[R7\]int t0/0/0 \[R7-Tunnel0/0/0\]ospf dr-priority 0
公私通(引入ospf)
R9\]ospf 1 \[R9-ospf-1\]import-route os \[R9-ospf-1\]import-route ospf 2 \[R9-ospf-1\]q \[R9\]ospf 2 \[R9-ospf-2\]import-route os \[R9-ospf-2\]import-route ospf 1 \[R9-ospf-2\]q 出口设备上抓取流量 \[R3\]acl 2000\[R3-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[R3-acl-basic-2000\]int s4/0/0 \[R3-Serial4/0/0\]nat outbound 2000 \[R3-Serial4/0/0\]q \[R5\]acl 2000 \[R5-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[R5-acl-basic-2000\]int s4/0/0 \[R5-Serial4/0/0\]nat outbound 2000 \[R5-Serial4/0/0\]q \[R6\]acl 2000 \[R6-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[R6-acl-basic-2000\]int s4/0/0 \[R6-Serial4/0/0\]nat outbound 2000 \[R6-Serial4/0/0\]q \[R7\]acl 2000\[R7-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[R7-acl-basic-2000\]int g0/0/0 \[R7-GigabitEthernet0/0/0\]nat outbound 2000 \[R7-GigabitEthernet0/0/0\]q
路由聚合
R3\]acl 2000\[R3-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[R3-acl-basic-2000\]int s4/0/0 \[R3-Serial4/0/0\]nat outbound 2000 \[R3-Serial4/0/0\]q \[R5\]acl 2000 \[R5-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[R5-acl-basic-2000\]int s4/0/0 \[R5-Serial4/0/0\]nat outbound 2000 \[R5-Serial4/0/0\]q \[R6\]acl 2000 \[R6-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[R6-acl-basic-2000\]int s4/0/0 \[R6-Serial4/0/0\]nat outbound 2000 \[R6-Serial4/0/0\]q \[R7\]acl 2000\[R7-acl-basic-2000\]rule permit source 172.16.0.0 0.0.255.255 \[R7-acl-basic-2000\]int g0/0/0 \[R7-GigabitEthernet0/0/0\]nat outbound 2000 \[R7-GigabitEthernet0/0/0\]q
建立特殊区域
R1\]ospf 1 \[R1-ospf-1\]a 1 \[R1-ospf-1-area-0.0.0.1\]stub no-summary \[R2\]ospf 1 \[R2-ospf-1\]a 1 \[R2-ospf-1-area-0.0.0.1\]stub no-summary \[R3\]ospf 1 \[R3-ospf-1\]a 1 \[R3-ospf-1-area-0.0.0.1\]stub no-summary \[R6\]ospf 1 \[R6-ospf-1\]a 2 \[R6-ospf-1-area-0.0.0.2\]nssa no-import-route \[R11\]ospf 1 \[R11-ospf-1\]a 2 \[R11-ospf-1-area-0.0.0.2\]nssa no-summary \[R12\]ospf 1 \[R12-ospf-1\]a 2\[R12-ospf-1-area-0.0.0.2\]nssa no-summary \[R7\]ospf 1 \[R7-ospf-1\]a 3 \[R7-ospf-1-area-0.0.0.3\]nssa no-summary \[R8\]ospf 1 \[R8-ospf-1\]a 3 \[R8-ospf-1-area-0.0.0.3\]nssa no-summary \[R9\]ospf 1\[R9-ospf-1\]a 3 \[R9-ospf-1-area-0.0.0.3\]nssa no-summary
访问r4的环回
下发缺省使r10能访问其他区域
**[R9]ospf 2
R9-ospf-2\]default-route-advertise \[R9-ospf-2\]q** **修改hello时间加快收敛** **\[R1\]int g0/0/0 \[R1-GigabitEthernet0/0/0\]ospf timer hello 5 \[R1-GigabitEthernet0/0/0\]q \[R2\]int g0/0/0 \[R2-GigabitEthernet0/0/0\]ospf timer hello 5 \[R3\]int g0/0/0 \[R3-GigabitEthernet0/0/0\]ospf timer hello 5 \[R4-Serial4/0/0\]ospf timer hello 5 \[R4-Serial4/0/0\]q \[R4\]int s4/0/1 \[R4-Serial4/0/1\]ospf timer hello 5 \[R4-Serial4/0/1\]q \[R4\]int s3/0/0 \[R4-Serial3/0/0\]ospf timer hello 5 \[R4-Serial3/0/0\]q \[R4\]int g0/0/0 \[R4-GigabitEthernet0/0/0\]ospf timer hello 5 \[R4-GigabitEthernet0/0/0\]q \[R5\]int s4/0/0 \[R5-Serial4/0/0\]ospf timer hello 5 \[R5-Serial4/0/0\]q \[R6\]int s4/0/0\[R6-Serial4/0/0\]ospf timer hello 5 \[R6-Serial4/0/0\]q \[R6\]int g0/0/0 \[R6-GigabitEthernet0/0/0\]ospf timer hello 5 \[R7\]int g0/0/0 \[R7-GigabitEthernet0/0/0\]ospf timer hello 5 \[R7-GigabitEthernet0/0/0\]q \[R7\]int g0/0/1 \[R7-GigabitEthernet0/0/1\]ospf timer hello 5 \[R7-GigabitEthernet0/0/1\]q \[R8\]int g0/0/0 \[R8-GigabitEthernet0/0/0\]ospf timer hello 5 \[R8-GigabitEthernet0/0/0\]q \[R8\]int g0/0/1 \[R8-GigabitEthernet0/0/1\]ospf timer hello 5 \[R8-GigabitEthernet0/0/1\]q \[R9\]int g0/0/0 \[R9-GigabitEthernet0/0/0\]ospf timer hello 5 \[R9-GigabitEthernet0/0/0\]q \[R9\]int g0/0/1 \[R9-GigabitEthernet0/0/1\]ospf timer hello 5 \[R9-GigabitEthernet0/0/1\]q \[R10\]int g0/0/0 \[R10-GigabitEthernet0/0/0\]ospf timer hello 5 \[R10-GigabitEthernet0/0/0\]q \[R11\]int g0/0/0 \[R11-GigabitEthernet0/0/0\]ospf t \[R11-GigabitEthernet0/0/0\]ospf timer hello 5 \[R11-GigabitEthernet0/0/0\]q \[R11\]int g0/0/1 \[R11-GigabitEthernet0/0/1\]ospf timer hello 5 \[R11-GigabitEthernet0/0/1\]q \[R12\]int g0/0/0 \[R12-GigabitEthernet0/0/0\]ospf timer hello 5 \[R12-GigabitEthernet0/0/0\]q**
R1\]ospf 1 \[R1-ospf-1\]a 1 \[R1-ospf-1-area-0.0.0.1\]authentication-mode md5 1 cipher 12345 \[R1-ospf-1-area-0.0.0.1\]q \[R2\]ospf 1 \[R2-ospf-1\]a 1 \[R2-ospf-1-area-0.0.0.1\]authentication-mode md5 1 cipher 12345 \[R2-ospf-1-area-0.0.0.1\]q \[R3\]ospf 1 \[R3-ospf-1\]a 1 \[R3-ospf-1-area-0.0.0.1\]authentication-mode md5 1 cipher 12345 \[R3-ospf-1-area-0.0.0.1\]q \[R4\]ospf 1 \[R4-ospf-1\]a 0 \[R4-ospf-1-area-0.0.0.0\]authentication-mode md5 1 cipher 12345 \[R4-ospf-1-area-0.0.0.0\]q \[R5\]ospf 1 \[R5-ospf-1\]a 0 \[R5-ospf-1-area-0.0.0.0\]authentication-mode md5 1 cipher 12345 \[R5-ospf-1-area-0.0.0.0\]q \[R6\]ospf 1 \[R6-ospf-1\]a 0 \[R6-ospf-1-area-0.0.0.0\]authentication-mode md5 1 cipher 12345 \[R6-ospf-1-area-0.0.0.0\]q \[R7\]ospf 1 \[R7-ospf-1\]a 0 \[R7-ospf-1-area-0.0.0.0\]authentication-mode md5 1 cipher 12345 \[R7-ospf-1-area-0.0.0.0\]q \[R6\]ospf 1 \[R6-ospf-1\]a 2 \[R6-ospf-1-area-0.0.0.2\]authentication-mode md5 1 cipher 12345 \[R6-ospf-1-area-0.0.0.2\]q \[R11\]ospf 1 \[R11-ospf-1\]a 2 \[R11-ospf-1-area-0.0.0.2\]authentication-mode md5 1 cipher 12345 \[R11-ospf-1-area-0.0.0.2\]q \[R12\]ospf 1 \[R12-ospf-1\]a 2 \[R12-ospf-1-area-0.0.0.2\]authentication-mode md5 1 cipher 12345 \[R12-ospf-1-area-0.0.0.2\]q \[R7\]ospf 1 \[R7-ospf-1\]a 3 \[R7-ospf-1-area-0.0.0.3\]authentication-mode md5 1 cipher 12345 \[R7-ospf-1-area-0.0.0.3\]q \[R8\]ospf 1 \[R8-ospf-1\]a 3 \[R8-ospf-1-area-0.0.0.3\]authentication-mode md5 1 cipher 12345 \[R8-ospf-1-area-0.0.0.3\]q \[R9\]ospf 1 \[R9-ospf-1\]a 3 \[R9-ospf-1-area-0.0.0.3\]authentication-mode md5 1 cipher 12345 \[R9\]ospf 2 \[R9-ospf-2\]a 4 \[R9-ospf-2-area-0.0.0.4\]authentication-mode md5 1 cipher 12345 \[R9-ospf-2-area-0.0.0.4\]q \[R10\]ospf 2 \[R10-ospf-2\]a 4 \[R10-ospf-2-area-0.0.0.4\]authentication-mode md5 1 cipher 12345 \[R10-ospf-2-area-0.0.0.4\]q
全网通