一、需求:1 配置主机名和地址7 W% H/ S1 R; l( y2 ]2 l
2 配置OSPF$ K+ M% Y" W0 x0 U
3 手动配置RID0 j. K6 f i! ]% `8 c
4 R1为DR,R2为BDR
0 \- k: S, F9 ^/ y5 R3\R4之间启用MD5认证
2 N8 F9 s. g0 N0 y% N9 a. d9 r6 验证R1到4.4.4.4的开销
) y- u7 n5 H" u7 R8模拟运营商网络
! F: N" o/ [" W8 j! H8 全网通% g; f+ Z) b! P( t: P
' E: p& e8 }, @" f( }7 `0 q) U
; R; B4 f* J k G6 I4 q二、拓扑:+ A* Y% e0 x6 ^- _" t; Y# x
OSPF综合实验(认证+缺省路由发布)
+ A2 p' o0 I' t: w0 @5 V) D
( n+ Q, N3 a! Y, d3 w8 {1 B三、命令配置+ z* N4 @8 J: D/ S) v; W
( Z$ Z: J* c* ]& P- Z, w7 A, v% E
# }/ m" u5 X9 R
sy
+ [9 \4 J( }1 g- ]$ o9 dsy R1
2 u, K' `1 f) d: ?! Ointer e0/0/1
4 P1 h# `9 C& [" Lip ad 192.168.0.1 24
5 l" s: b1 P: v: tospf dr-priority 200
0 q2 Z* t1 M1 _; h' R INTEGER<0-255> Router priority value
6 ], {: f b5 P. [& }* Bq
; |9 G" d: _# \2 n, T8 eospf 1 router-id 1.1.1.17 T2 B, _7 t: i6 a/ \
area 0
& H6 h/ a3 Z( znet 192.168.0.0 0.0.0.255
& ?$ D8 F" E# a M. A& {, J. B9 M: E* `7 M1 b
8 U$ q; B( i, Y* C
/ l1 H. c7 M3 ]$ v, g$ d9 ]: g; s
# R2配置( K- }* d9 i! B8 L& U& w
sy
/ |% r+ p# D# Y8 e# n( ksy R20 [/ t. h4 }; S! a1 ?3 {: C
inter g0/0/1
' J' V, E1 ]( X5 E& Cip ad 192.168.0.2 24- M9 f- L6 K! T7 T
ospf dr-priority 100' S- {1 P6 i% @# `( s, b
INTEGER<0-255> Router priority value1 f4 j+ f7 l! T! n; y# O+ K
q
3 n9 X1 f4 E1 G) }. r& G6 mospf 1 r 2.2.2.20 _% }" o: e% T& E* N+ U
area 07 J. C2 g& |% ? p
net 192.168.0.0 0.0.0.255
: b0 {5 {/ G9 J* q# c# d- H6 L+ `" J3 m& F5 m
) I0 x& r0 o0 B: ?( I' p' `! I- y& q. y$ U) K; o. O; ]0 k4 o
# R3配置
/ o6 d* V' M* e- ? D8 P) U- e$ Ssy
) ~4 O+ D9 m! X# D& e5 ksy R3; S4 b2 D" k8 w
inter g0/0/2
2 E' @6 F7 g% }! E3 c, iip ad 192.168.0.3 24$ D/ w; x1 Y$ l
inter s0/0/15 L; c% ~. e7 n8 I. T- K' Z
ip ad 34.0.0.3 8
6 w- T1 Y1 i! v7 h6 a8 ~; N6 m" S: {//接口认证
( `% \' Q* X: w' a. t7 v# kospf auth md5 1 cipher huawei" C2 z4 r% G4 v; T5 P4 J
q
v7 _* O( Q5 Qosp 1 r 3.3.3.3
9 v G# t% ]. I3 s; S+ `area 0 * J6 x Y9 A# h; b( v0 ?) g
net 192.168.0.0 0.0.0.255! f# h' x: j0 @3 g7 X2 S) q& P6 I/ `0 E
net 34.0.0.0 0.255.255.255
. c+ K+ e1 J1 @3 s//区域认证) o ^1 N z: U4 A
auth md5 1 cipher huawei
* H4 P% X) A W9 r' ~1 t//区域和接口认证均开,接口认证优先3 C; u5 ?' ]* c% [- C) x; E3 A4 d* b
//当一台router上多个接口开启认证,仅个别不开,可以选择使用区域认证,单独在接口取消认证
" v {0 E$ @- i$ I1 T1 |
' x1 i' u X7 E4 o4 v/ I) S8 b8 [8 D* W. o2 }
2 q0 ~1 `# K, \6 Q# R4配置
$ D H( H# [& |; F- O5 _. Psy
8 D, P' k4 \2 ?. @3 V! |, |sy R4
. i4 L [; u7 C3 q% l: h* {; U# D" Pinter s0/0/1
; ^1 i0 B6 Q. J" F7 {ip ad 34.0.0.4 81 m, ^; r7 U9 F1 w) h) g2 F
ospf auth md5 1 cipher huawei
: W' g) o& |0 R: z7 D; D! a9 I6 [inter g0/0/0" _ |# G0 ~; W* S3 I
ip ad 48.0.0.4 8
% l5 t2 v8 \. ]q
: j# Z( y7 L' x9 h, N. Linter loopback14 T( i! ]4 B M- ` `2 @1 m
ip ad 4.4.4.4 32" l Y" o7 j4 q% Y
q0 x6 @: ~, t# ?$ c" R( j, _
osp 1 rou 4.4.4.4
: q8 J& Z9 M8 { Narea 0 7 }7 k0 g; i- w+ ?0 l, y" a
net 34.0.0.0 0.255.255.2553 _' ?/ u) }4 i; r2 B
auth md5 1 cipher huawei7 f9 ~8 o$ [+ N3 Q
q
' N2 {0 \" f% B% m# O2 J/ @q- K6 D$ K) u$ E8 f( b# A0 }
//全网通1:下发到运营商网络路由,出口router需要有缺省静态路由,在配置下发命令即可
6 r! j% V: c- M& e& I+ }! xip rou 0.0.0.0 0 48.0.0.8
$ o8 M1 I# y y5 m; }ospf 11 W5 K J+ a- @- r2 ^0 W" H# t6 H
default-route-advertise
& Q- ]) {1 G: U//全网通2:引入直连路由
, @; a7 j" Z7 J/ \; N7 }( N O( wospf 1# p! o0 B" a1 i% b
import-route direct
: N3 C5 [/ P9 K! X* k
3 E. @# M! N0 A' x( l
9 }( l! G6 `5 `3 e8 l& p
, Z# ^- e% F3 x1 T" V# R6配置
' b4 {' A1 _7 t' n6 R w* Hsy, U" ^7 Z# U& |% V3 C5 g2 Q4 O) b9 ~3 B3 R
sy R6
/ e2 h; P- {" j$ O/ }' J1 b6 Cinter e0/0/0
) G4 b$ \" f( ?3 O5 K: r: y3 sip ad 192.168.0.6 24( U6 i' W6 K& X+ m% ], H" E
q
, ?) z: a' O; W& `" w9 n/ n2 X5 @ospf 1 rou 6.6.6.6
( f& [* b7 [6 w& Y% s. {7 o' S/ Zarea 0: S7 g/ z( y$ s7 q! u; i
net 192.168.0.0 0.0.0.255 |" `+ K) m! G" r
' f8 g# b) K0 u* t. Q O. M" Y' B( X7 s/ L
9 G& |% C2 f8 k# l# R8配置
& ]5 H, o/ b. K# Vsy
. L: A H( q- J O' i# x/ ]' lsy R8
) Y+ I1 F1 q8 J$ Q- O Z! Z einter g0/0/0& z- k' d: g; z& Z0 G- W7 N
ip ad 48.0.0.8 8
! I% J3 r0 H% u X9 V
U( ^' {2 q% ~* M( q/ [7 D: g |