25. 旁路部署的环路问题
旁路部署的环路问题
Ip route 10.1.2.0 255.255.255.0 10.1.2.2 Ip route 10.1.2.2 255.255.255.255 10.1.3.1
10.1.3.1
Leadsec-Detector leadsec-Guard
10.1.1.2
目标主机 10.1.2.2
26. 规避环路: PBR 注入
旁路部署的环路问题
Ip rout 10.1.2.0 255.255.255.0 10.1.2.2
Ip rout 10.1.2.2 255.255.255.255 10.1.3.1
10.1.3.1
Leadsec-Detector
interface Guard
ip address 10.1.3.2 255.255.255.0 leadsec-Guard
ip policy route-map pbr 10.1.1.2
!
ip access-list extended guard
permit ip any any
!
route-map pbr permit 10
match ip address guard 目标主机 10.1.2.2
set ip next-hop 10.1.1.2
27. 规避环路的方法
Guard Guard
二层回注 PBR 回注
环路问题
解决方案
Guard
Guard
GRE
VRF
GRE 回注
MPLS 回注
GRE