各位问一下这个实验题,AR2是RR反射器,AR1\AR4是他的客户端,AR6是AR2的EBGP对等体。现在想在AR2上做策略修改发送给IBGP对等体AR4路由的Local_Preference跟Cost属性,为什么从客户端AR1学到的路由(192.168.1.1/32)修改不成功?作为对比的本地引入的路由(172.16.0.1/32)跟Ebgp路由(66.66.66.66/32)却能修改成功?底层IGP都用ospf打通了的* s+ } C- O& M8 o8 z
; `7 A* P5 e7 H; `
<AR2>dis cu/ Z# s4 ^8 }! }- M1 P- A
[V200R003C00]
5 w* j# B! z4 l4 ]- ?#
+ b4 L3 f% D C6 H8 Bsysname AR2
/ Z0 t. t0 v- e#/ ]$ ^& f7 y O3 a9 c: N0 |$ i
snmp-agent local-engineid 800007DB03000000000000
9 D; J6 `: z+ s0 Bsnmp-agent
j6 }$ q5 S+ Z- o' ^ h#
; o- { _( l; D. [/ lclock timezone China-Standard-Time minus 08:00:005 [" E3 T2 q1 r* B! ?; Z, {
#; n; I4 F* I) X
portal local-server load flash:/portalpage.zip6 x6 A# W0 E5 w: e
#& O/ P9 H( }8 d( V5 ^
drop illegal-mac alarm
7 ?: I' t0 G$ g## e; S5 k; c; v. }5 {
wlan ac-global carrier id other ac id 03 h3 S$ B1 {3 c* P4 x
#0 D/ b) A0 o$ p: k8 g% u1 o: ]0 d2 c" k
set cpu-usage threshold 80 restore 75
" `3 _ S: `& C9 K7 C) [" X& f#) w$ b3 _ M2 ]; H, J6 m' J4 V5 j
acl number 2000 ( J! u3 U5 ]' w8 x3 R
rule 5 permit source 192.168.1.1 0 5 j8 s, P! F' Y9 m' k3 c0 s
rule 10 permit source 172.16.0.1 0
1 v# H T6 G' I* M( u( lrule 15 permit source 66.66.66.66 0
2 J. b6 t5 T. _% L2 o) Hrule 1000 deny
; c/ e0 U( o* }- \: w0 x#0 ^. ^9 R* f: d2 w3 M
aaa + L! q3 j" U. u% t+ t2 _/ S
authentication-scheme default
( s) j m- {& K3 W0 |% Mauthorization-scheme default9 k* k C. _$ P9 X! o$ ?( A
accounting-scheme default6 e3 A# Q. d: z. \9 ~) u
domain default
7 X2 X6 j, A8 J) E- s3 E8 T% {domain default_admin
5 U$ ]" u9 W6 `/ P7 J9 N. Q$ mlocal-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$3 S3 O3 ?" X4 U9 l" J' l: _( K
local-user admin service-type http
; c) a* G# {; {1 |# r#
4 N' A/ ?+ _+ f% f: b# P8 Y. ]firewall zone Local
. [& ~6 E9 Y! K# L2 m7 P6 [priority 15, t) g. p7 r1 j
#* q8 @4 N' k8 D$ V0 D8 T
interface GigabitEthernet0/0/0
. @6 @4 D; z, i' \& eip address 10.0.12.2 255.255.255.0
( T6 N/ X; W" W! W! M; M9 ?, ?#7 H6 e; ^; t' L: T) c2 {- A
interface GigabitEthernet0/0/10 b8 F6 o! L8 G/ y9 H
ip address 10.0.24.2 255.255.255.0 0 o. s2 ^7 `# n0 Y; z
#
2 K p: ^9 d% K& xinterface GigabitEthernet0/0/2( Z B; r" V" d9 b2 H4 e9 {
ip address 10.0.26.2 255.255.255.0 ! o, g1 D" z: m( J) A) J5 b
#
|1 E- Y+ y4 h3 C- V- U |$ Sinterface NULL0
8 n- T8 _' E) H# L* f$ v9 h#; D f# R6 J2 J) }8 s0 I7 M4 K S
interface LoopBack0
8 T+ ^; }5 y. F0 ~5 jip address 2.2.2.2 255.255.255.255
- y' a1 M J8 J8 c% g5 l% P#/ Z( Y) q/ b3 ~. W
interface LoopBack1
) `' n. S3 n: \/ }# gip address 172.16.0.1 255.255.255.255
: N0 G; E& c% r2 _ Z; a#! i) a. r6 i6 F5 R8 s H x
bgp 12 t4 p# j, W& m( y; W, A$ Y( Q8 G
router-id 2.2.2.21 [* z$ t, ?0 }; Y
peer 1.1.1.1 as-number 1
6 |+ N9 j/ o6 k( mpeer 1.1.1.1 connect-interface LoopBack0
% m8 H4 t% |6 ~/ d9 Zpeer 4.4.4.4 as-number 1 % x$ a) h# M! O
peer 4.4.4.4 connect-interface LoopBack02 Q6 {* ?9 ?) m- P: v; N8 A5 W0 g
peer 6.6.6.6 as-number 2 , n+ c# {% J) x- V+ o7 D
peer 6.6.6.6 ebgp-max-hop 2 & x5 G9 B0 l j# v( j
peer 6.6.6.6 connect-interface LoopBack0, R5 a) { t. J7 J5 i
#% p7 G3 Y. X, K$ e! S$ O: }7 ~+ O
ipv4-family unicast! ^# N, B3 @( i7 t" ~4 I/ ~, b
undo synchronization
+ E' f8 r. U0 [ c7 m- M6 a8 s6 h6 P0 H network 172.16.0.1 255.255.255.255 0 J: ]" f+ A5 v( e0 q8 S; e( r
peer 1.1.1.1 enable3 P* Z _ _) }
peer 1.1.1.1 reflect-client
" a. I$ H& p( J/ D peer 4.4.4.4 enable2 g2 b' I* X3 l! Y* M: u2 c2 c
peer 4.4.4.4 route-policy LocPre export- i& O; G# Y% j
peer 4.4.4.4 reflect-client! g" n( ?# ? o
peer 4.4.4.4 advertise-community5 }6 a; Y$ ^6 s% t i2 U
peer 4.4.4.4 advertise-ext-community
( F8 j6 E: Y' X& J1 Y peer 6.6.6.6 enable
5 U& j" l, u1 Z* K$ r#7 s9 f; t M2 }: Z" Q9 }, k( k
ospf 1 router-id 2.2.2.2 " N0 x$ T; j/ n; _" }9 f: P
area 0.0.0.0
3 v' p0 |* i$ N ]. L! Q# z6 S% q network 2.2.2.2 0.0.0.0
( R" ^ W4 o! [# l! M network 10.0.12.2 0.0.0.0
6 ^! x: b4 p7 Y8 H% S" | network 10.0.24.2 0.0.0.0
; G2 e; `6 d e, O, U( l4 T' d network 10.0.26.2 0.0.0.0 4 {1 {+ Q2 @( @" Y0 x
#1 s' _3 D2 w( b$ j
route-policy LocPre permit node 10 6 m' e) f: u: M+ }/ E
if-match acl 2000
' B, Z0 I! q* L; r Vapply local-preference 200
% G+ {: e0 @6 B% Capply cost 1000 $ j! Z: `, v7 B% P3 x
#
9 r u% c" E: \: ^! B( Kroute-policy LocPre permit node 20
1 [+ ]' q" J3 ]3 L- e8 ]" L6 m' U#
3 I" F4 E) \$ H+ V% ^% E) P7 nuser-interface con 0) x c3 w2 c; J& P: U
authentication-mode password
! Y0 o4 G1 P' a4 Vuser-interface vty 0 4
: b% E* |- L" W. {user-interface vty 16 20
2 j% k) X( i. P- Y3 b! w) T' p#
" h0 `! b$ l0 e) j+ ~" m E" wwlan ac
/ D$ R+ Q. P, p# i& K. u#
- T ?0 G7 G$ h9 P: ~ |