一,拓扑
二,需求介绍
1.配置area 0 区域为修改OSPF的网络类型为NBMA
2.将R2的环回口L0 10引入OSPF区域,R5写静态路由访问R10的环回口
3.将R7、R8的环回口的10网段宣告进入OSPF,其他非Area40区域不能看到10网段的明细路由。Area40不能有3,4,5类LSA(默认路由除外),但是可以访问100.100.100.100。
4.Area 0 做MD5认证,密码Huawei@123
5.R5将静态路由引入OSPF路由,其各站点都可以访问100.100.100.100
6.R2的环回口L010通过Area20访问100.100.100.100/32
7.全网互通
三,配置过程
1.按图配置IP地址和OSPF(略)
2.将Area 0区域修改网络类型为NBMA
①配置网络类型
R1:
[R1-GigabitEthernet0/0/2]ospf network-type nbma
R2:
[R2-GigabitEthernet0/0/1]ospf network-type nbma
R3:
[R3-GigabitEthernet0/0/1]ospf network-type nbma
②因为NBMA网络类型不支持组播,所以需要指定邻居地址
R1:
[R1-ospf-1]peer 172.16.10.2
[R1-ospf-1]peer 172.16.10.3
R2:
[R2-ospf-1]peer 172.16.10.1
[R2-ospf-1]peer 172.16.10.3
R3:
[R3-ospf-1]peer 172.16.10.1
[R3-ospf-1]peer 172.16.10.2
③配置完会多一个attempt然后进入邻接状态,查看邻居表
[R3]display ospf peer brief
OSPF Process 1 with Router ID 3.3.3.3
Peer Statistic Information
----------------------------------------------------------------------------
Area Id Interface Neighbor id State
0.0.0.0 GigabitEthernet0/0/1 1.1.1.1 Full
0.0.0.0 GigabitEthernet0/0/1 2.2.2.2 Full
④查看网络类型
[R3]display ospf interface GigabitEthernet 0/0/1
OSPF Process 1 with Router ID 3.3.3.3
Interfaces
Interface: 172.16.10.3 (GigabitEthernet0/0/1)
Cost: 1 State: DR Type: NBMA MTU: 1500
Priority: 1
Designated Router: 172.16.10.3
Backup Designated Router: 172.16.10.1
Timers: Hello 30 , Dead 120 , Poll 120 , Retransmit 5 , Transmit Delay 1
3.将R2的环回口L10引入OSPF,R5配置静态路由目的是R10的环回口
①将R2的L10引入OSPF
[R2-LoopBack10]ospf enable area 0
②R5配置静态路由
[R5]ip route-static 100.100.100.100 32 51.1.1.10
4.将R7、R8环回口的10网段按要求宣告进OSPF,并可以访问100.100.100.100
①由于area40没有连接骨干区域,先配置虚连接
R3:
[R3]ospf
[R3-ospf-1]area 30
[R3-ospf-1-area-0.0.0.30]vlink-peer 6.6.6.6
R4:
[R6]ospf
[R6-ospf-1]area 30
[R6-ospf-1-area-0.0.0.30]vlink-peer 3.3.3.3
②检查虚连接
[R6]display ospf vlink
OSPF Process 1 with Router ID 6.6.6.6
Virtual Links
Virtual-link Neighbor-id -> 3.3.3.3, Neighbor-State: Full
Interface: 36.1.1.6 (GigabitEthernet0/0/0)
Cost: 1 State: P-2-P Type: Virtual
Transit Area: 0.0.0.30
Timers: Hello 10 , Dead 40 , Retransmit 5 , Transmit Delay 1
GR State: Normal
③R7、R8将环回口引入OSPF
R7:
[R7-LoopBack1]ospf enable area 40
[R7-LoopBack1]int l2
[R7-LoopBack2]ospf enable area 40
R8:
[R8-LoopBack1]ospf enable area 40
[R8-LoopBack1]int l2
[R8-LoopBack2]ospf enable area 40
④这样宣告产生的3类LSA会产生明细路由
10.1.0.1/32 3 Inter-area 172.16.10.3 6.6.6.6 0.0.0.0
10.1.1.1/32 3 Inter-area 172.16.10.3 6.6.6.6 0.0.0.0
10.1.2.1/32 3 Inter-area 172.16.10.3 6.6.6.6 0.0.0.0
10.1.3.1/32 3 Inter-area 172.16.10.3 6.6.6.6 0.0.0.0
⑤在ABR:R6上做三类汇总
[R6-ospf-1-area-0.0.0.40] abr-summary 10.1.0.0 255.255.252.0
Type : Sum-Net
Ls id : 10.1.0.0
Adv rtr : 6.6.6.6
Ls age : 48
Len : 28
Options : E
seq# : 80000001
chksum : 0x2319
Net mask : 255.255.252.0
Tos 0 metric: 1
Priority : Low
⑥将Area40配置为Totally NSSA区域
R6:
[R6-ospf-1-area-0.0.0.40]nssa no-summary
R7:
[R7-ospf-1-area-0.0.0.40]nssa no-summary
R8:
[R8-ospf-1-area-0.0.0.40]nssa no-summary
⑦Area40内只有1类2类,和3类7类的默认路由
[R8-ospf-1]display ospf lsdb
OSPF Process 1 with Router ID 8.8.8.8
Link State Database
Area: 0.0.0.40
Type LinkState ID AdvRouter Age Len Sequence Metric
Router 7.7.7.7 7.7.7.7 12 60 80000006 1
Router 6.6.6.6 6.6.6.6 5 36 80000007 1
Router 8.8.8.8 8.8.8.8 4 60 80000006 1
Network 192.168.10.6 6.6.6.6 5 36 80000004 0
Sum-Net 0.0.0.0 6.6.6.6 91 28 80000001 1
NSSA 0.0.0.0 6.6.6.6 91 36 80000001 1
5.在Area 0做OSPF的MD5认证,密码为Huawei@123
R1:
[R1-ospf-1-area-0.0.0.0]authentication-mode md5 1 cipher Huawei@123
R2:
[R2-ospf-1-area-0.0.0.0]authentication-mode md5 1 cipher Huawei@123
R3:
[R3-ospf-1-area-0.0.0.0]authentication-mode md5 1 cipher Huawei@123
R6:
[R6-ospf-1-area-0.0.0.0]authentication-mode md5 1 cipher Huawei@123
6.在R5上将静态路由引入OSPF,使得其他站点都能访问100.100.100.100
[R5-ospf-1]import-route static
[R8]ping 100.100.100.100
PING 100.100.100.100: 56 data bytes, press CTRL_C to break
Reply from 100.100.100.100: bytes=56 Sequence=1 ttl=251 time=80 ms
7.R2的环回口L10通过Area20访问100.100.100.100
①如果不配置,R2是从G0/0/1Area0区域访问100.100.100.100
在R2的G0/0/1接口抓包内容如下
②