H3C OSPF綜合實(shí)驗(yàn)_第1頁(yè)
H3C OSPF綜合實(shí)驗(yàn)_第2頁(yè)
H3C OSPF綜合實(shí)驗(yàn)_第3頁(yè)
H3C OSPF綜合實(shí)驗(yàn)_第4頁(yè)
H3C OSPF綜合實(shí)驗(yàn)_第5頁(yè)
已閱讀5頁(yè),還剩10頁(yè)未讀, 繼續(xù)免費(fèi)閱讀

下載本文檔

版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡(jiǎn)介

1、一:實(shí)驗(yàn)步驟:配置各臺(tái)設(shè)備的ip地址測(cè)試直連的連通性配置OSPF路由協(xié)議和RIP路由協(xié)議配置虛鏈路查看全網(wǎng)連通性配置OSPF area 0 的認(rèn)證和RIP的認(rèn)證配置路由匯總,實(shí)現(xiàn)區(qū)域0中只有一條192網(wǎng)絡(luò)的路由,且保證通訊。配置area 1為NSSA區(qū)域,保證area 1不出現(xiàn) type 4和 type5 LSA。配置area 3為絕對(duì)末節(jié)區(qū)域,保證area 3不出現(xiàn)type 3和 type 4和type5 LSA配置包過(guò)濾防火墻,實(shí)現(xiàn)192網(wǎng)絡(luò)的3網(wǎng)段用戶不能夠訪問(wèn)到area 0,其他網(wǎng)絡(luò)均可以正常訪問(wèn)。且172網(wǎng)絡(luò)0網(wǎng)段用戶不能訪問(wèn)到area 0,area 1,area 2,area 3.

2、其他用戶均可以訪問(wèn)。完成以上需求后,所有節(jié)點(diǎn)均能夠訪問(wèn)到internet接口地址命令:wcg-RT1:interface GigabitEthernet0/0/0 ip address 10.1.14.1 255.255.255.0quitinterface GigabitEthernet0/0/1 ip address 10.1.16.2 255.255.255.0quitinterface LoopBack0 ip address 1.1.1.1 255.255.255.255wcg-RT2:interface GigabitEthernet0/0/0 ip address 10.1.23

3、.1 255.255.255.0quitinterface GigabitEthernet0/0/1 ip address 27.1.1.2 255.255.255.0quitinterface LoopBack0 ip address 2.2.2.2 255.255.255.255wcg-RT3:interface GigabitEthernet0/0/0 ip address 10.1.35.1 255.255.255.0quitinterface GigabitEthernet0/0/1 ip address 10.1.23.2 255.255.255.0quitinterface Gi

4、gabitEthernet0/0/2 ip address 10.1.34.2 255.255.255.0quitinterface LoopBack0 ip address 3.3.3.3 255.255.255.255wcg-RT4:interface GigabitEthernet0/0/0 ip address 10.1.45.1 255.255.255.0quitinterface GigabitEthernet0/0/1 ip address 10.1.14.2 255.255.255.0quitinterface GigabitEthernet0/0/2 ip address 1

5、0.1.34.1 255.255.255.0quitinterface LoopBack0 ip address 4.4.4.4 255.255.255.255wcg-RT5:interface GigabitEthernet0/0/0 ip address 202.112.1.1 255.255.255.240quitinterface GigabitEthernet0/0/1 ip address 10.1.45.2 255.255.255.0quitinterface GigabitEthernet0/0/2 ip address 10.1.35.2 255.255.255.0quiti

6、nterface LoopBack0 ip address 5.5.5.5 255.255.255.255quitinterface LoopBack10 ip address 172.16.5.100 255.255.255.255quitinterface LoopBack20 ip address 172.16.5.200 255.255.255.255wcg-RT6:interface GigabitEthernet0/0/0 ip address 10.1.16.1 255.255.255.0quitinterface LoopBack0 ip address 6.6.6.6 255

7、.255.255.255quitinterface LoopBack10 ip address 192.168.0.100 255.255.255.255quitinterface LoopBack20 ip address 192.168.1.100 255.255.255.255quitinterface LoopBack30 ip address 192.168.2.100 255.255.255.255quitinterface LoopBack40 ip address 192.168.3.100 255.255.255.255wcg-RT7:interface GigabitEth

8、ernet0/0/0 ip address 27.1.1.1 255.255.255.0quitinterface LoopBack0 ip address 7.7.7.7 255.255.255.255quitinterface LoopBack10 ip address 172.16.0.100 255.255.255.255quitinterface LoopBack20 ip address 172.16.1.100 255.255.255.255quitinterface LoopBack30 ip address 172.16.2.100 255.255.255.255quitin

9、terface LoopBack40 ip address 172.16.3.100 255.255.255.255wcg-RT8:interface GigabitEthernet0/0/1 ip address 202.112.1.14 255.255.255.240quitinterface LoopBack0 ip address 8.8.8.8 255.255.255.255測(cè)試直連接口的連通性-略O(shè)SPF配置命令wcg-RT1:ospf 1 router-id 1.1.1.1 area 0.0.0.2 network 10.1.14.1 0.0.0.0 network 1.1.1.

10、1 0.0.0.0quit area 0.0.0.3 network 10.1.16.2 0.0.0.0wcg-RT2:ospf 1 router-id 2.2.2.2 area 0.0.0.1 network 2.2.2.2 0.0.0.0 network 10.1.23.1 0.0.0.0quit wcg-RT3:ospf 1 router-id 3.3.3.3 area 0.0.0.0 network 10.1.34.2 0.0.0.0 network 10.1.35.1 0.0.0.0quit area 0.0.0.1 network 10.1.23.2 0.0.0.0 network

11、 3.3.3.3 0.0.0.0quitwcg-RT4:ospf 1 router-id 4.4.4.4 area 0.0.0.0 network 10.1.34.1 0.0.0.0 network 10.1.45.1 0.0.0.0quit area 0.0.0.2 network 10.1.14.2 0.0.0.0 network 4.4.4.4 0.0.0.0quitwcg-RT5:ospf 1 router-id 5.5.5.5 area 0.0.0.0 network 5.5.5.5 0.0.0.0 network 10.1.45.2 0.0.0.0 network 10.1.35.

12、2 0.0.0.0 network 172.16.5.0 0.0.0.255quitwcg-RT6:ospf 1 router-id 6.6.6.6 area 0.0.0.3 network 10.1.16.1 0.0.0.0 network 192.168.0.0 0.0.0.255 network 192.168.1.0 0.0.0.255 network 192.168.2.0 0.0.0.255 network 192.168.3.0 0.0.0.255quit虛鏈路的配置命令wcg-RT1: ospf 1 area 0.0.0.2 vlink-peer 4.4.4.4 wcg-RT4

13、: ospf 1 area 0.0.0.2 vlink-peer 1.1.1.1 RIP協(xié)議配置命令wcg-RT2:rip 1 undo summary version 2 network 27.0.0.0RT7:wcg-rip 1 undo summary version 2 network 27.0.0.0 network 172.16.0.0路由的引入wcg-RT2:ospf 1 import-route rip 1 type 1quitwcg-rip 1 import-route ospf 1quit查看全網(wǎng)的路由,只許看wcg-RT5和wcg-RT2就行。dis ip routing

14、-table 用ping命令測(cè)試連通性NAT地址轉(zhuǎn)換wcg-RT5: ip route-static 0.0.0.0 0.0.0.0 202.112.1.14acl number 2000 rule 0 permitquitinterface GigabitEthernet0/0/0 nat outbound 2000quitospf 1 default-route-advertise type 1用ping命令測(cè)試網(wǎng)絡(luò)能去往Internet4.骨干區(qū)域?yàn)榱藚f(xié)議安全要求啟用OSPF認(rèn)證,R2和R7之間要求保證rip協(xié)議安全OSPF的骨干區(qū)域認(rèn)證命令wcg-RT5:ospf 1 area 0.0

15、.0.0 authentication-mode simplequitquitinterface GigabitEthernet0/0/1 ospf authentication-mode simple plain helloquitinterface GigabitEthernet0/0/2 ospf authentication-mode simple plain hellowcg-RT4:ospf 1 area 0.0.0.0 authentication-mode simplequitquitinterface GigabitEthernet0/0/0 ospf authenticat

16、ion-mode simple plain helloquitinterface GigabitEthernet0/0/2 ospf authentication-mode simple plain helloquitwcg-RT3:ospf 1 area 0.0.0.0 authentication-mode simplequitquitinterface GigabitEthernet0/0/0 ospf authentication-mode simple plain helloquitinterface GigabitEthernet0/0/2 ospf authentication-

17、mode simple plain hello區(qū)域 0 開(kāi)啟認(rèn)證 虛鏈路必須開(kāi)啟認(rèn)證wcg-RT4:ospf 1 area 0.0.0.2 vlink-peer 1.1.1.1 simple plain helloquitwcg-RT1:ospf 1 area 0.0.0.0 authentication-mode simplequit area 0.0.0.2 vlink-peer 4.4.4.4 simple plain helloquitwcg-RIP協(xié)議的認(rèn)證RT2:interface GigabitEthernet0/0/1 rip authentication-mode simpl

18、e helloquitwcg-RT7:interface GigabitEthernet0/0/0 rip authentication-mode simple helloquit骨干區(qū)域要求只能出現(xiàn)一條192網(wǎng)絡(luò)的路由,并且保證192網(wǎng)絡(luò)下每個(gè)節(jié)點(diǎn)正常通訊wcg-RT1:ospf 1 area 0.0.0.3 abr-summary 192.168.0.0 255.255.252.0quit查看wcg-RT5的路由表,觀察實(shí)驗(yàn)結(jié)果。區(qū)域1中要求不能存在 OSPF type 4和 type5 LSAwcg-RT2:ospf 1 area 0.0.0.1 nssaquitwcg-RT3:ospf

19、 1 area 0.0.0.1 nssa default-route-advertisequit在wcg-RT2上查看OSPF的LSDB 區(qū)域3中要求不能存在 OSPF type 3和 type 4和type5 LSAwcg-RT1:ospf 1 area 0.0.0.3 stub no-summaryquitwcg-RT6:ospf 1 area 0.0.0.3 stub no-summaryquit在wcg-RT6上查看OSPF的LSDB7.要求area 0中只能出現(xiàn)一條192網(wǎng)絡(luò)的路由信息,并且R6下除192網(wǎng)絡(luò)的3網(wǎng)段用戶不能夠訪問(wèn)到area 0中,其他網(wǎng)絡(luò)均可以正常訪問(wèn)到area0 及其他區(qū)域wcg-RT6: firewall enableacl number 3000 rule deny ip source 192.168.3.0 0.0.0.255 destination 10.1.34.0 0.0.0.255 rule deny ip source 192.168.3.0 0.0.0.255 destination 1

溫馨提示

  • 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。

評(píng)論

0/150

提交評(píng)論