1.实验拓补图
2.实验要求
1.R5为ISP:R5作为网络中的核心节点,提供互联网连接服务,但其功能将被限制在基本的IP路由和转发上
2.R4作为企业边界路由器:R4负责连接企业内部网络和外部网络(即ISP提供的网络)。
3出口公网地址需要通过PPP(点对点协议)获取,这是一种常用于广域网连接的协议。
4.需要进行CHAP(挑战握手认证协议)认证,以确保连接的安全性。CHAP是一种通过三次握手在链路建立初始化阶段进行认证的方法。
3.实验要求分析
1. 网络角色与连接要求
-
R5 作为 ISP:功能限定为基本的 IP 路由和转发,仅配置 IP 地址,在网络中提供互联网连接服务,是外部网络接入点 。
-
R4 作为企业边界路由器:承担企业内部网络与外部 ISP 网络连接的任务。出口公网地址需借助 PPP 协议获取,且要进行 CHAP 认证,以保障连接的安全性和合法性 。
2. 地址规划要求
整个 OSPF 环境的 IP 地址基于 172.16.0.0/16
进行划分,意味着所有设备的 IP 需在该网段内合理分配,以确保网络地址的统一性和规划性 。
3. 网络可达性要求
所有设备必须能够访问 R5 的环回地址,这要求在 OSPF 配置中合理宣告网段、配置路由协议参数,保证网络路由的正确性和完整性,最终实现全网可达的目标 。
4. 网络优化与安全要求
-
减少 LSA 更新量:通过合理划分 OSPF 区域(如 area 0、area 1 等多个区域),减少不必要的链路状态通告更新,降低网络资源消耗 。
-
加快收敛:配置合适的 OSPF 参数,如 hello 时间、dead 时间等,使网络在拓扑变化时能快速重新计算路由,恢复网络连通性 。
-
保障更新安全:采用认证机制(如可能用到的 MD5 认证等),防止非法设备接入和恶意路由更新,确保 OSPF 路由更新过程的安全性 。
4.实验配置
1、IP地址划分
- 172.16.0.0/19 ---A0:
/19
表示子网掩码为255.255.224.0
,将172.16.0.0/16
网段进一步划分。此网段用于区域 A0 ,能容纳 213−2=8190 个主机地址(减去网络地址和广播地址 ) ,为 A0 区域内设备提供地址空间。 - 172.16.0.0/24-﹣骨干:
/24
即子网掩码255.255.255.0
,可容纳 254 个主机地址 。用于骨干区域,为骨干区域内设备分配地址,骨干区域在 OSPF 网络中承担核心路由传输功能 。 - 172.16.0.0/30--R3-R4:
/30
子网掩码是255.255.255.252
,只有 2 个可用主机地址 。适用于 R3 与 R4 之间的链路连接,因为点到点链路只需两个地址用于两端设备通信 。 - 172.16.0.4/30--R4-R6:同样
/30
掩码,此网段为 R4 与 R6 链路分配地址,仅两个可用主机地址用于这两台设备间通信 。 - 172.16.0.8/30--R4-R7:也是
/30
子网,用于 R4 与 R7 链路连接,提供两个可用主机地址实现设备互联 。 - 45.0.0.0/30---R4-R5:若完整网段是
172.16.45.0/30
,则是/30
子网掩码 。用于 R4 与 R5 链路连接,提供两个可用地址用于这两台设备通信 。 - 100.1.1.0/24---R5 环回:
/24
子网掩码 。环回地址用于标识 R5 设备本身,方便管理和测试,该网段能提供 254 个主机地址,一般只使用其中一个配置在环回接口 。 - 172.16.32.0/19 ---A1:
/19
子网掩码255.255.224.0
,用于区域 A1 ,可容纳 8190 个主机地址,为 A1 区域设备分配地址 。 - 172.16.32.0/24--R1:
/24
子网掩码,为 R1 设备所在网段分配地址,可容纳 254 个主机地址,供 R1 及其连接设备使用 。 - 172.16.33.0/24--R2:同样
/24
子网掩码,用于 R2 设备所在网段,提供 254 个主机地址 。 - 172.16.34.0/24--R3:
/24
子网掩码,为 R3 设备所在网段分配地址,可容纳 254 个主机地址 。 - 172.16.35.0/24-- 骨干:
/24
子网掩码,用于骨干区域相关部分,为骨干区域内设备提供地址 。 - 172.16.35.0/29 -- 骨干:
/29
子网掩码255.255.255.248
,有 6 个可用主机地址 。用于骨干区域特定链路或设备连接 。 - 172.16.64.0/19---A2:
/19
子网掩码255.255.224.0
,用于区域 A2 ,提供 8190 个主机地址用于 A2 区域设备 。 - 172.16.96.0/19 ---Α3:
/19
子网掩码,用于区域 A3 ,可容纳 8190 个主机地址,为 A3 区域设备分配地址 。 - 172.16.128.0/19---A4:
/19
子网掩码,用于区域 A4 ,能提供 8190 个主机地址,满足 A4 区域设备地址需求 。
2、配置接基础路由
[R1-GigabitEthernet0/0/0]ip address 172.16.35.1 29
[R1-LoopBack0]ip address 172.16.32.1 24
[R1-LoopBack0]ospf network-type broadcast
3、配置ospf
[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1]a 1
[R1-ospf-1-area-0.0.0.1]network 172.16.32.1 0.0.0.0
[R1-ospf-1-area-0.0.0.1]network 172.16.35.1 0.0.0.0
4、配置RIP
[R12]rip 1
[R12-rip-1]version 2
[R12-rip-1]network 10.0.0.0
5、配置双向重发布
[R9]ospf 1
[R9-ospf-1]import-route ospf 2
[R12]ospf 1
[R12-ospf-1]import-route rip 1
6、路由汇总
[R3]ospf 1
[R3-ospf-1]area 1
[R3-ospf-1-area-0.0.0.1]abr-summary 172.16.32.0 255.255.224.0
7、划分特殊区域,下放缺省路由
[R1-ospf-1-area-0.0.0.1]stub
[R3-ospf-1-area-0.0.0.1]stub no-summary
[R9-ospf-2]default-route-advertise
8、加快收敛
p2p:
[R3-GigabitEthernet0/0/1]ospf network-type p2p
p2mp:
[R1-GigabitEthernet0/0/0]ospf network-type p2mp
9、更改hello包更新时长
[R1-GigabitEthernet0/0/0]ospf timer hello 1
10、保障网络更新安全(区域认证)
[R4-ospf-1-area-0.0.0.0]authentication-mode md5 1 cipher 123456
11、连通外网
[R4]acl 2000
[R4-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[R4]int s 4/0/1
[R4-Serial4/0/1]nat outbound 2000
5.具体配置
R1
<Huawei>system-view
[Huawei]sysname R1
[R1]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]ip address 172.16.35.1 29
[R1]interface LoopBack 0
[R1-LoopBack0]ip address 172.16.32.1 24
[R1-LoopBack0]ospf network-type broadcast
[R1]ospf router-id 1.1.1.1
[R1-ospf-1]area 1
[R1-ospf-1-area-0.0.0.1]network 172.16.32.1 0.0.0.0
[R1-ospf-1-area-0.0.0.1]network 172.16.35.1 0.0.0.0
[R1-ospf-1-area-0.0.0.1]stub
[R1]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]ospf network-type p2mp
[R1-GigabitEthernet0/0/0]ospf timer hello 1
R2
<Huawei>system-view
[Huawei]sysname R2
[R2]interface GigabitEthernet 0/0/0
[R2-GigabitEthernet0/0/0]ip address 172.16.35.2 29
[R2]interface LoopBack 0
[R2-LoopBack0]ip address 172.16.33.1 24
[R2-LoopBack0]ospf network-type broadcast
[R2]ospf router-id 2.2.2.2
[R2-ospf-1]area 1
[R2-ospf-1-area-0.0.0.1]network 172.16.33.1 0.0.0.0
[R2-ospf-1-area-0.0.0.1]network 172.16.35.1 0.0.0.0
[R2-ospf-1-area-0.0.0.1]stub
[R2]interface GigabitEthernet 0/0/0
[R2-GigabitEthernet0/0/0]ospf network-type p2mp
[R2-GigabitEthernet0/0/0]ospf timer hello 1
R3
<Huawei>system-view
[Huawei]sysname R3
[R3]interface GigabitEthernet 0/0/0
[R3-GigabitEthernet0/0/0]ip address 172.16.35.3 29
[R3]interface GigabitEthernet 0/0/1
[R3-GigabitEthernet0/0/1]ip address 172.16.0.1 30
[R3]interface LoopBack 0
[R3-LoopBack0]ip address 172.16.34.1 24
[R3-LoopBack0]ospf network-type broadcast
[R3]ospf 1 router-id 3.3.3.3
[R3-ospf-1]area 1
[R3-ospf-1-area-0.0.0.1]network 172.16.35.3 0.0.0.0
[R3-ospf-1-area-0.0.0.1]network 172.16.34.1 0.0.0.0
[R3-ospf-1]area 0
[R3-ospf-1-area-0.0.0.0]network 172.16.0.1 0.0.0.0
[R3]ospf 1
[R3-ospf-1]area 1
[R3-ospf-1-area-0.0.0.1]abr-summary 172.16.32.0 255.255.224.0
[R3-ospf-1-area-0.0.0.1]stub no-summary
[R3]interface GigabitEthernet 0/0/1
[R3-GigabitEthernet0/0/1]ospf network-type p2p
[R3]interface GigabitEthernet 0/0/0
[R3-GigabitEthernet0/0/0]ospf network-type p2mp
[R3-GigabitEthernet0/0/0]ospf timer hello 1
[R3]ospf 1
[R3-ospf-1]area 0
[R3-ospf-1-area-0.0.0.0]authentication-mode md5 1 cipher 123456
R4
<Huawei>system-view
[Huawei]sysname R4
[R4]interface GigabitEthernet 0/0/0
[R4-GigabitEthernet0/0/0]ip address 172.16.0.9 30
[R4]interface GigabitEthernet 0/0/1
[R4-GigabitEthernet0/0/1]ip address 172.16.0.2 30
[R4]interface GigabitEthernet 0/0/2
[R4-GigabitEthernet0/0/2]ip address 172.16.0.5 30
[R4]interface Serial 4/0/1
[R4-Serial4/0/1]ip address 45.0.0.1 30
[R4]ospf 1 router-id 4.4.4.4
[R4-ospf-1]area 0
[R4-ospf-1-area-0.0.0.0]network 172.16.0.2 0.0.0.0
[R4-ospf-1-area-0.0.0.0]network 172.16.0.5 0.0.0.0
[R4-ospf-1-area-0.0.0.0]network 172.16.0.9 0.0.0.0
[R4]ip route-static 0.0.0.0 0 45.0.0.2
[R4]ospf 1
[R4-ospf-1]default-route-advertise
[R4]interface GigabitEthernet 0/0/0
[R4-GigabitEthernet0/0/0]ospf network-type p2p
[R4]interface GigabitEthernet 0/0/1
[R4-GigabitEthernet0/0/1]ospf network-type p2p
[R4]interface GigabitEthernet 0/0/2
[R4-GigabitEthernet0/0/2]ospf network-type p2p
[R4]interface Serial 4/0/1
[R4-Serial4/0/1]ospf network-type p2p
[R4]ospf 1
[R4-ospf-1]area 0
[R4-ospf-1-area-0.0.0.0]authentication-mode md5 1 cipher 123456
[R4]acl 2000
[R4-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[R4]int Serial 4/0/1
[R4-Serial4/0/1]nat outbound 2000
R5
<Huawei>system-view
[Huawei]sysname R5
[R5]interface Serial 4/0/0
[R5-Serial4/0/0]ip address 45.0.0.2 30
[R5]interface LoopBack 0
[R5-LoopBack0]ip address 100.1.1.1 24
[R5]interface Serial 4/0/0
[R5-Serial4/0/0]ospf network-type p2p
R6
<Huawei>system-view
[Huawei]sysname R6
[R6]interface GigabitEthernet 0/0/0
[R6-GigabitEthernet0/0/0]ip address 172.16.66.1 30
[R6]interface GigabitEthernet 0/0/1
[R6-GigabitEthernet0/0/1]ip address 172.16.0.6 30
[R6]interface Loopback 0
[R6-LoopBack0]ip address 172.16.64.1 24
[R6-LoopBack0]ospf network-type broadcast
[R6]ospf 1 router-id 6.6.6.6
[R6-ospf-1]area 0
[R6-ospf-1-area-0.0.0.0]network 172.16.0.6 0.0.0.0
[R6-ospf-1]area 2
[R6-ospf-1-area-0.0.0.2]network 172.16.66.1 0.0.0.0
[R6-ospf-1-area-0.0.0.2]network 172.16.64.1 0.0.0.0
[R6-ospf-1-area-0.0.0.2]abr-summary 172.16.64.0 255.255.224.0
[R6-ospf-1-area-0.0.0.2]nssa no-summary
[R6]interface GigabitEthernet 0/0/0
[R6-GigabitEthernet0/0/0]ospf network-type p2p
[R6]interface GigabitEthernet 0/0/1
[R6-GigabitEthernet0/0/1]ospf network-type p2p
[R6]ospf 1
[R6-ospf-1]area 0
[R6-ospf-1-area-0.0.0.0]authentication-mode md5 1 cipher 123456
R7
<Huawei>system-view
[Huawei]sysname R7
[R7]interface GigabitEthernet 0/0/0
[R7-GigabitEthernet0/0/0]ip address 172.16.0.10 30
[R7]interface GigabitEthernet 0/0/1
[R7-GigabitEthernet0/0/1]ip address 172.16.98.1 30
[R7]interface Loopback 0
[R7-LoopBack0]ip address 172.16.96.1 24
[R7-LoopBack0]ospf network-type broadcast
[R7]ospf 1 router-id 7.7.7.7
[R7-ospf-1]area 0
[R7-ospf-1-area-0.0.0.0]network 172.16.0.10 0.0.0.0
[R7-ospf-1]area 3
[R7-ospf-1-area-0.0.0.3]network 172.16.96.1 0.0.0.0
[R7-ospf-1-area-0.0.0.3]network 172.16.98.1 0.0.0.0
[R7-ospf-1-area-0.0.0.3]abr-summary 172.16.96.0 255.255.224.0
[R7-ospf-1-area-0.0.0.3]nssa no-summary
[R7]interface GigabitEthernet 0/0/0
[R7-GigabitEthernet0/0/0]ospf network-type p2p
[R7]interface GigabitEthernet 0/0/1
[R7-GigabitEthernet0/0/1]ospf network-type p2p
[R7]ospf 1
[R7-ospf-1]area 0
[R7-ospf-1-area-0.0.0.0]authentication-mode md5 1 cipher 123456
R8
<Huawei>system-view
[Huawei]sysname R8
[R8]interface GigabitEthernet 0/0/0
[R8-GigabitEthernet0/0/0]ip address 172.16.98.2 30
[R8]interface GigabitEthernet 0/0/1
[R8-GigabitEthernet0/0/1]ip address 172.16.98.5 30
[R8]interface Loopback 0
[R8-LoopBack0]ip address 172.16.97.1 24
[R8-LoopBack0]ospf network-type broadcast
[R8]ospf 1 router-id 8.8.8.8
[R8-ospf-1]area 3
[R8-ospf-1-area-0.0.0.3]network 172.16.98.2 0.0.0.0
[R8-ospf-1-area-0.0.0.3]network 172.16.97.1 0.0.0.0
[R8-ospf-1-area-0.0.0.3]network 172.16.98.5 0.0.0.0
[R8-ospf-1-area-0.0.0.3]nssa
[R8]interface GigabitEthernet 0/0/0
[R8-GigabitEthernet0/0/0]ospf network-type p2p
[R8]interface GigabitEthernet 0/0/1
[R8-GigabitEthernet0/0/1]ospf network-type p2p
R9
<Huawei>system-view
[Huawei]sysname R9
[R9]interface GigabitEthernet 0/0/0
[R9-GigabitEthernet0/0/0]ip address 172.16.98.6 30
[R9]interface GigabitEthernet 0/0/1
[R9-GigabitEthernet0/0/1]ip address 172.16.130.1 24
[R9]interface LoopBack 0
[R9-LoopBack0]ip address 172.16.128.1 24
[R9-LoopBack0]ospf network-type broadcast
[R9]ospf 2 router-id 9.9.9.9
[R9-ospf-2]area 4
[R9-ospf-2-area-0.0.0.4]network 172.16.128.1 0.0.0.0
[R9-ospf-2-area-0.0.0.4]network 172.16.130.1 0.0.0.0
[R9]ospf 1
[R9-ospf-1]import-route ospf 2
[R9-ospf-1]asbr-summary 172.16.128.0 255.255.224.0
[R9]ospf 1
[R9-ospf-1]area 3
[R9-ospf-1-area-0.0.0.3]nssa
[R9]ospf 2
[R9-ospf-2]default-route-advertise
[R9]interface GigabitEthernet 0/0/0
[R9-GigabitEthernet0/0/0]ospf network-type p2p
[R9]interface GigabitEthernet 0/0/1
[R9-GigabitEthernet0/0/1]ospf network-type p2p
R10
<Huawei>system-view
[Huawei]sysname R10
[R10]interface GigabitEthernet 0/0/0
[R10-GigabitEthernet0/0/0]ip address 172.16.130.2 30
[R10]interface LoopBack 0
[R10-LoopBack0]ip address 172.16.129.1 24
[R10-LoopBack0]ospf network-type broadcast
[R10]ospf 1 router-id 10.10.10.10
[R10-ospf-1]area 4
[R10-ospf-1-area-0.0.0.4]network 172.16.129.1 0.0.0.0
[R10-ospf-1-area-0.0.0.4]network 172.16.130.2 0.0.0.0
[R10]interface GigabitEthernet 0/0/0
[R10-GigabitEthernet0/0/0]ospf network-type p2p
R11
<Huawei>system-view
[Huawei]sysname R11
[R11]interface GigabitEthernet 0/0/0
[R11-GigabitEthernet0/0/0]ip address 172.16.66.2 30
[R11]interface GigabitEthernet 0/0/1
[R11-GigabitEthernet0/0/1]ip address 172.16.66.5 30
[R11]interface LoopBack 0/0/0
[R11-LoopBack0]ip address 172.16.65.1 24
[R11-LoopBack0]ospf network-type broadcast
[R11]ospf 1 router-id 11.11.11.11
[R11-ospf-1]area 0
[R11-ospf-1-area-0.0.0.2]network 172.16.66.2 0.0.0.0
[R11-ospf-1-area-0.0.0.2]network 172.16.65.1 0.0.0.0
[R11-ospf-1-area-0.0.0.2]network 172.16.66.5 0.0.0.0
[R11-ospf-1-area-0.0.0.2]nssa
[R11]interface GigabitEthernet 0/0/0
[R11-GigabitEthernet0/0/0]ospf network-type p2p
[R11]interface GigabitEthernet 0/0/1
[R11-GigabitEthernet0/0/1]ospf network-type p2p
R12
<Huawei>system-view
[Huawei]sysname R12
[R12]interface GigabitEthernet 0/0/0
[R12-GigabitEthernet0/0/0]ip address 172.16.66.6 30
[R12]interface LoopBack 0
[R12-LoopBack0]ip address 10.1.1.1 24
[R12-LoopBack1]ip address 10.1.2.1 24
[R12]ospf 1 router-id 12.12.12.12
[R12-ospf-1]area 2
[R12-ospf-1-area-0.0.0.2]network 172.16.66.6 0.0.0.0
[R12]rip 1
[R12-rip-1]version 2
[R12-rip-1]network 10.0.0.0
[R12]ospf 1
[R12-ospf-1]import-route rip 1
[R12-ospf-1]asbr-summary 10.1.0.0 255.255.252.0
[R12]ospf 1
[R12-ospf-1]area 2
[R12-ospf-1-area-0.0.0.2]nssa
[R12]interface GigabitEthernet 0/0/0
[R12-GigabitEthernet0/0/0]ospf network-type p2p
6.检查结果
R1
[R1]ping 172.16.32.1PING 172.16.32.1: 56 data bytes, press CTRL_C to breakReply from 172.16.32.1: bytes=56 Sequence=1 ttl=255 time=30 msReply from 172.16.32.1: bytes=56 Sequence=2 ttl=255 time=1 msReply from 172.16.32.1: bytes=56 Sequence=3 ttl=255 time=1 msReply from 172.16.32.1: bytes=56 Sequence=4 ttl=255 time=1 msReply from 172.16.32.1: bytes=56 Sequence=5 ttl=255 time=1 ms--- 172.16.32.1 ping statistics ---5 packet(s) transmitted5 packet(s) received0.00% packet lossround-trip min/avg/max = 1/6/30 ms[R1]ping 100.1.1.1PING 100.1.1.1: 56 data bytes, press CTRL_C to breakReply from 100.1.1.1: bytes=56 Sequence=1 ttl=253 time=210 msReply from 100.1.1.1: bytes=56 Sequence=2 ttl=253 time=90 msReply from 100.1.1.1: bytes=56 Sequence=3 ttl=253 time=50 msReply from 100.1.1.1: bytes=56 Sequence=4 ttl=253 time=70 msReply from 100.1.1.1: bytes=56 Sequence=5 ttl=253 time=90 ms--- 100.1.1.1 ping statistics ---5 packet(s) transmitted5 packet(s) received0.00% packet lossround-trip min/avg/max = 50/102/210 ms
R8
[R8]ping 172.16.97.1PING 172.16.97.1: 56 data bytes, press CTRL_C to breakReply from 172.16.97.1: bytes=56 Sequence=1 ttl=255 time=30 msReply from 172.16.97.1: bytes=56 Sequence=2 ttl=255 time=1 msReply from 172.16.97.1: bytes=56 Sequence=3 ttl=255 time=1 msReply from 172.16.97.1: bytes=56 Sequence=4 ttl=255 time=1 msReply from 172.16.97.1: bytes=56 Sequence=5 ttl=255 time=1 ms--- 172.16.97.1 ping statistics ---5 packet(s) transmitted5 packet(s) received0.00% packet lossround-trip min/avg/max = 1/6/30 ms[R8]ping 100.1.1.1PING 100.1.1.1: 56 data bytes, press CTRL_C to breakReply from 100.1.1.1: bytes=56 Sequence=1 ttl=253 time=60 msReply from 100.1.1.1: bytes=56 Sequence=2 ttl=253 time=90 msReply from 100.1.1.1: bytes=56 Sequence=3 ttl=253 time=60 msReply from 100.1.1.1: bytes=56 Sequence=4 ttl=253 time=60 msReply from 100.1.1.1: bytes=56 Sequence=5 ttl=253 time=60 ms--- 100.1.1.1 ping statistics ---5 packet(s) transmitted5 packet(s) received0.00% packet lossround-trip min/avg/max = 60/66/90 ms
R11
[R11]ping 172.16.65.1PING 172.16.65.1: 56 data bytes, press CTRL_C to breakReply from 172.16.65.1: bytes=56 Sequence=1 ttl=255 time=20 msReply from 172.16.65.1: bytes=56 Sequence=2 ttl=255 time=1 msReply from 172.16.65.1: bytes=56 Sequence=3 ttl=255 time=1 msReply from 172.16.65.1: bytes=56 Sequence=4 ttl=255 time=1 msReply from 172.16.65.1: bytes=56 Sequence=5 ttl=255 time=1 ms--- 172.16.65.1 ping statistics ---5 packet(s) transmitted5 packet(s) received0.00% packet lossround-trip min/avg/max = 1/4/20 ms[R11]ping 100.1.1.1PING 100.1.1.1: 56 data bytes, press CTRL_C to breakReply from 100.1.1.1: bytes=56 Sequence=1 ttl=253 time=60 msReply from 100.1.1.1: bytes=56 Sequence=2 ttl=253 time=40 msReply from 100.1.1.1: bytes=56 Sequence=3 ttl=253 time=40 msReply from 100.1.1.1: bytes=56 Sequence=4 ttl=253 time=70 msReply from 100.1.1.1: bytes=56 Sequence=5 ttl=253 time=30 ms--- 100.1.1.1 ping statistics ---5 packet(s) transmitted5 packet(s) received0.00% packet lossround-trip min/avg/max = 30/48/70 ms