OSPF协议综合实验
实验任务需要完成的任务如下。1在总部和分公司相应交换机上完成 VLAN 相关配置包括 VLAN 创建和端口划分、Trunk 配置、以太网通道配置和 MSTP 配置等。2在总部和分公司的网络中完成 IP 地址配置包括配置路由器接口的 IP 地址为三层交换机创建 VLANIF 并配置 IP 地址配置计算机和服务器的 IP 地址、子网掩码和网关。3为总部核心交换机配置 VRRP为主机提供冗余网关。4配置 NAT使总部和分公司的主机可以通过 SZ 路由器访问 Internet。5测试以上所有直连链路的连通性。6OSPF 区域划分广州分公司和深圳总部网络划分到 OSPF Area 1 中深圳总部和北京分公司网络划分到 OSPF Area 2 中深圳总部网络划分到 OSPF Area 0 中修改 OSPF 计算度量值参考带宽为 1000Mbit/s。路由器 SZ 的 Router ID 为 1.1.1.1路由器 GZ 的 Router ID 为 2.2.2.2路由器 BJ 的 Router ID 为 3.3.3.3交换机 S1 的 Router ID 为 4.4.4.4交换机 S2 的 Router ID 为 5.5.5.5交换机 S5 的 Router ID 为 6.6.6.6交换机 S6 的 Router ID 为 7.7.7.7。7在深圳总部路由器上分别配置 OSPF Area 0、1 和 2 的 ABR 路由聚合以便减少路由表大小提高路由查找效率。8为了减少向局域网发送不必要的 OSPF 更新将分公司交换机适当接口配置为静默接口。9为了提高网络安全性在深圳总部到分公司的两条链路上配置 OSPF MD5 验证在深圳总部的 OSPF Area 0 设备上配置 MD5 验证。10在深圳总部和北京分公司的链路上将接口发送 Hello 报文间隔改为 5sDead 时间改为 20s。11将 Area 2 配置为完全末节区域。12控制 DR 选举使深圳总部路由器成为连接三层交换机 S1 和 S2 的相应网段的 DR。13在深圳总部路由器上配置指向 ISP 的静态默认路由并向 OSPF 网络注入默认路由。14查看各路由器的 OSPF 邻居表、链路状态数据库和路由表并进行网络连通性测试。15保存配置文件完成项目测试报告。3. 项目目的通过本项目可以掌握如下知识点和技能点同时积累项目经验。1启动 OSPF 路由进程和启用参与 OSPF 协议接口的方法。2配置 OSPF 计时器参数的方法。3OSPF 计算度量值参考带宽的修改方法。4修改 OSPF 接口优先级控制 DR 选举的方法。5广播多路访问链路上 OSPF 的特征。6基于链路和基于区域的 OSPF 验证的配置方法。7区域间路由汇聚和向 OSPF 网络注入默认路由的方法。8OSPF 不同路由器类型的功能和 OSPF LSA 的类型及特征。9OSPF 链路状态数据库的特征和含义以及 OSPF 第一类外部路由和第二类外部路由的区别。10查看和调试 OSPF 协议相关信息的方法。实验拓扑SZ路由器配置#sysname SZ#aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher OOCM4m($F4ajUn1vMEIBNUw#local-user admin service-type http#firewall zone Local priority16#interface Ethernet0/0/0#interface Ethernet0/0/1#interface Serial0/0/0 link-protocol ppp#interface Serial0/0/1 link-protocol ppp#interface Serial0/0/2 link-protocol ppp#interface Serial0/0/3 link-protocol ppp#interface GigabitEthernet0/0/0ipaddress172.16.12.1255.255.255.252 ospf authentication-mode hmac-md51cipher pFgcIB7-wIECB7Ie7/)9\3##interface GigabitEthernet0/0/1ipaddress192.168.12.1255.255.255.252 ospf authentication-mode hmac-md51cipher t-j(lln939_G-B0Y2H\b##interface GigabitEthernet0/0/2ipaddress10.2.2.1255.255.255.252 ospf dr-priority2#interface GigabitEthernet0/0/3ipaddress10.2.3.1255.255.255.252 ospf dr-priority2#wlan#interface NULL0#ospf1router-id1.1.1.1 default-route-advertise bandwidth-reference1000area0.0.0.0 abr-summary10.1.12.0255.255.252.0 authentication-mode hmac-md51cipher :ZeeDxthRS939O4.(ZG/\g#network10.2.3.10.0.0.0 network10.2.2.10.0.0.0 area0.0.0.1 abr-summary172.16.8.0255.255.252.0 network172.16.12.10.0.0.0 area0.0.0.2 abr-summary192.168.2.0255.255.254.0 network192.168.12.10.0.0.0 stub no-summary#iproute-static0.0.0.00.0.0.0218.18.12.2#user-interface con0user-interface vty04user-interface vty1620#returnGZ路由器配置#sysname GZ#aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher *X%D|%Wg7H)H2[EInBTQO#local-user admin service-type http#firewall zone Local priority16#interface Ethernet0/0/0#interface Ethernet0/0/1#interface Serial0/0/0 link-protocol ppp#interface Serial0/0/1 link-protocol ppp#interface Serial0/0/2 link-protocol ppp#interface Serial0/0/3 link-protocol ppp#interface GigabitEthernet0/0/0ipaddress172.16.12.2255.255.255.252 ospf authentication-mode hmac-md51cipher;bXQ8blpC3IF$:[285ua1##interface GigabitEthernet0/0/1ipaddress172.16.6.1255.255.255.252#interface GigabitEthernet0/0/2#interface GigabitEthernet0/0/3#wlan#interface NULL0#ospf1router-id2.2.2.2 bandwidth-reference1000area0.0.0.1 network172.16.12.20.0.0.0 network172.16.6.10.0.0.0#user-interface con0user-interface vty04user-interface vty1620#returnBJ路由器配置#sysname BJ#aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher B3wPB^]SX$H)H2[EInB3QO#local-user admin service-type http#firewall zone Local priority16#interface Ethernet0/0/0#interface Ethernet0/0/1#interface Serial0/0/0 link-protocol ppp#interface Serial0/0/1 link-protocol ppp#interface Serial0/0/2 link-protocol ppp#interface Serial0/0/3 link-protocol ppp#interface GigabitEthernet0/0/0ipaddress192.168.6.1255.255.255.252#interface GigabitEthernet0/0/1ipaddress192.168.12.2255.255.255.252 ospf authentication-mode hmac-md51cipher t-j(lln9ECB7Ie7/)2W##interface GigabitEthernet0/0/2#interface GigabitEthernet0/0/3#wlan#interface NULL0#ospf1router-id3.3.3.3 bandwidth-reference1000area0.0.0.2 network192.168.12.20.0.0.0 network192.168.6.10.0.0.0 stub#user-interface con0user-interface vty04user-interface vty1620#return交换机S1配置#sysname S1#vlan batch12to15100#stp instance0root primary stp instance1root primary stp instance2root secondary stp bpdu-protection#clusterenablentdpenablendpenable#drop illegal-mac alarm#diffserv domain default#stp region-configuration region-name RG1 instance1vlan12to13instance2vlan14to15active region-configuration#drop-profile default#aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password simple admin local-user admin service-type http#interface Vlanif1#interface Vlanif12ipaddress10.1.12.252255.255.255.0 vrrp vrid1virtual-ip10.1.12.254 vrrp vrid1priority120vrrp vrid1preempt-mode timer delay20#interface Vlanif13ipaddress10.1.13.252255.255.255.0 vrrp vrid2virtual-ip10.1.13.254 vrrp vrid2priority120vrrp vrid2preempt-mode timer delay20#interface Vlanif14ipaddress10.1.14.252255.255.255.0 vrrp vrid3virtual-ip10.1.14.254#interface Vlanif15ipaddress10.1.15.252255.255.255.0 vrrp vrid4virtual-ip10.1.15.254#interface Vlanif100ipaddress10.2.2.2255.255.255.252#interface MEth0/0/1#interface Eth-Trunk1 port link-type trunk undo port trunk allow-pass vlan1port trunk allow-pass vlan2to4094#interface GigabitEthernet0/0/1 port link-type access port default vlan100stp edged-portenable#interface GigabitEthernet0/0/2 port link-type trunk undo port trunk allow-pass vlan1port trunk allow-pass vlan2to4094#interface GigabitEthernet0/0/3#interface GigabitEthernet0/0/4#interface GigabitEthernet0/0/5#interface GigabitEthernet0/0/6#interface GigabitEthernet0/0/7#interface GigabitEthernet0/0/8#interface GigabitEthernet0/0/9#interface GigabitEthernet0/0/10#interface GigabitEthernet0/0/11#interface GigabitEthernet0/0/12#interface GigabitEthernet0/0/13#interface GigabitEthernet0/0/14#interface GigabitEthernet0/0/15#interface GigabitEthernet0/0/16#interface GigabitEthernet0/0/17#interface GigabitEthernet0/0/18#interface GigabitEthernet0/0/19#interface GigabitEthernet0/0/20#interface GigabitEthernet0/0/21#interface GigabitEthernet0/0/22#interface GigabitEthernet0/0/23 eth-trunk1#interface GigabitEthernet0/0/24 eth-trunk1#interface NULL0#ospf1router-id4.4.4.4 bandwidth-reference1000area0.0.0.0 authentication-mode hmac-md51cipher{\Z8/Rs$sPddVIN17BbZ#network10.2.2.20.0.0.0 network10.1.12.2520.0.0.0 network10.1.13.2520.0.0.0 network10.1.14.2520.0.0.0 network10.1.15.2520.0.0.0#user-interface con0user-interface vty04#return交换机S2配置#sysname S2#vlan batch12to15200#stp instance0root secondary stp instance1root secondary stp instance2root primary stp bpdu-protection#clusterenablentdpenablendpenable#drop illegal-mac alarm#diffserv domain default#stp region-configuration region-name RG1 instance1vlan12to13instance2vlan14to15active region-configuration#drop-profile default#aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password simple admin local-user admin service-type http#interface Vlanif1#interface Vlanif12ipaddress10.1.12.253255.255.255.0 vrrp vrid1virtual-ip10.1.12.254#interface Vlanif13ipaddress10.1.13.253255.255.255.0 vrrp vrid2virtual-ip10.1.13.254#interface Vlanif14ipaddress10.1.14.253255.255.255.0 vrrp vrid3virtual-ip10.1.14.254 vrrp vrid3priority120vrrp vrid3preempt-mode timer delay20#interface Vlanif15ipaddress10.1.15.253255.255.255.0 vrrp vrid4virtual-ip10.1.15.254 vrrp vrid4priority120vrrp vrid4preempt-mode timer delay20#interface Vlanif200ipaddress10.2.3.2255.255.255.252#interface MEth0/0/1#interface Eth-Trunk1 port link-type trunk undo port trunk allow-pass vlan1port trunk allow-pass vlan2to4094#interface GigabitEthernet0/0/1 port link-type access port default vlan200stp edged-portenable#interface GigabitEthernet0/0/2 port link-type trunk undo port trunk allow-pass vlan1port trunk allow-pass vlan2to4094#interface GigabitEthernet0/0/3#interface GigabitEthernet0/0/4#interface GigabitEthernet0/0/5#interface GigabitEthernet0/0/6#interface GigabitEthernet0/0/7#interface GigabitEthernet0/0/8#interface GigabitEthernet0/0/9#interface GigabitEthernet0/0/10#interface GigabitEthernet0/0/11#interface GigabitEthernet0/0/12#interface GigabitEthernet0/0/13#interface GigabitEthernet0/0/14#interface GigabitEthernet0/0/15#interface GigabitEthernet0/0/16#interface GigabitEthernet0/0/17#interface GigabitEthernet0/0/18#interface GigabitEthernet0/0/19#interface GigabitEthernet0/0/20#interface GigabitEthernet0/0/21#interface GigabitEthernet0/0/22#interface GigabitEthernet0/0/23 eth-trunk1#interface GigabitEthernet0/0/24 eth-trunk1#interface NULL0#ospf1router-id5.5.5.5 bandwidth-reference1000area0.0.0.0 authentication-mode hmac-md51cipherXfQyVFm)uqcXT}kOI7bK#network10.2.3.20.0.0.0 network10.1.12.2530.0.0.0 network10.1.13.2530.0.0.0 network10.1.14.2530.0.0.0 network10.1.15.2530.0.0.0#user-interface con0user-interface vty04#return交换机S3配置#sysname S3#vlan batch12to15#stp bpdu-protection#clusterenablentdpenablendpenable#drop illegal-mac alarm#diffserv domain default#stp region-configuration region-name RG1 instance1vlan12to13instance2vlan14to15active region-configuration#drop-profile default#aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password simple admin local-user admin service-type http#interface Vlanif1#interface Vlanif12#interface Vlanif13#interface Vlanif14#interface Vlanif15#interface MEth0/0/1#interface GigabitEthernet0/0/1 port link-type trunk undo port trunk allow-pass vlan1port trunk allow-pass vlan2to4094#interface GigabitEthernet0/0/2 port link-type trunk undo port trunk allow-pass vlan1port trunk allow-pass vlan2to4094#interface GigabitEthernet0/0/3 port link-type access port default vlan12stp edged-portenable#interface GigabitEthernet0/0/4 port link-type access port default vlan13stp edged-portenable#interface GigabitEthernet0/0/5 port link-type access port default vlan14stp edged-portenable#interface GigabitEthernet0/0/6 port link-type access port default vlan15stp edged-portenable#interface GigabitEthernet0/0/7#interface GigabitEthernet0/0/8#interface GigabitEthernet0/0/9#interface GigabitEthernet0/0/10#interface GigabitEthernet0/0/11#interface GigabitEthernet0/0/12#interface GigabitEthernet0/0/13#interface GigabitEthernet0/0/14#interface GigabitEthernet0/0/15#interface GigabitEthernet0/0/16#interface GigabitEthernet0/0/17#interface GigabitEthernet0/0/18#interface GigabitEthernet0/0/19#interface GigabitEthernet0/0/20#interface GigabitEthernet0/0/21#interface GigabitEthernet0/0/22#interface GigabitEthernet0/0/23#interface GigabitEthernet0/0/24#interface NULL0#user-interface con0user-interface vty04#return交换机S5配置#sysname S5#vlan batch22334455100#clusterenablentdpenablendpenable#drop illegal-mac alarm#diffserv domain default#drop-profile default#aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password simple admin local-user admin service-type http#interface Vlanif1#interface Vlanif22ipaddress172.16.8.254255.255.255.0#interface Vlanif33ipaddress172.16.9.254255.255.255.0#interface Vlanif44ipaddress172.16.10.254255.255.255.0#interface Vlanif55ipaddress172.16.11.254255.255.255.0#interface Vlanif100ipaddress172.16.6.2255.255.255.252#interface MEth0/0/1#interface GigabitEthernet0/0/1 port link-type access port default vlan100#interface GigabitEthernet0/0/2#interface GigabitEthernet0/0/3#interface GigabitEthernet0/0/4#interface GigabitEthernet0/0/5#interface GigabitEthernet0/0/6#interface GigabitEthernet0/0/7#interface GigabitEthernet0/0/8#interface GigabitEthernet0/0/9#interface GigabitEthernet0/0/10#interface GigabitEthernet0/0/11#interface GigabitEthernet0/0/12#interface GigabitEthernet0/0/13#interface GigabitEthernet0/0/14#interface GigabitEthernet0/0/15#interface GigabitEthernet0/0/16#interface GigabitEthernet0/0/17#interface GigabitEthernet0/0/18#interface GigabitEthernet0/0/19#interface GigabitEthernet0/0/20#interface GigabitEthernet0/0/21 port link-type access port default vlan22#interface GigabitEthernet0/0/22 port link-type access port default vlan33#interface GigabitEthernet0/0/23 port link-type access port default vlan44#interface GigabitEthernet0/0/24 port link-type access port default vlan55#interface NULL0#ospf1router-id6.6.6.6 silent-interface Vlanif22 silent-interface Vlanif33 silent-interface Vlanif44 silent-interface Vlanif55 bandwidth-reference1000area0.0.0.1 network172.16.6.20.0.0.0 network172.16.8.2540.0.0.0 network172.16.9.2540.0.0.0 network172.16.10.2540.0.0.0 network172.16.11.2540.0.0.0#user-interface con0user-interface vty04#return交换机S6配置#sysname S6#vlan batch100222333#clusterenablentdpenablendpenable#drop illegal-mac alarm#diffserv domain default#drop-profile default#aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password simple admin local-user admin service-type http#interface Vlanif1#interface Vlanif100ipaddress192.168.6.2255.255.255.252#interface Vlanif222ipaddress192.168.2.254255.255.255.0#interface Vlanif333ipaddress192.168.3.254255.255.255.0#interface MEth0/0/1#interface GigabitEthernet0/0/1 port link-type access port default vlan100#interface GigabitEthernet0/0/2#interface GigabitEthernet0/0/3#interface GigabitEthernet0/0/4#interface GigabitEthernet0/0/5#interface GigabitEthernet0/0/6#interface GigabitEthernet0/0/7#interface GigabitEthernet0/0/8#interface GigabitEthernet0/0/9#interface GigabitEthernet0/0/10#interface GigabitEthernet0/0/11#interface GigabitEthernet0/0/12#interface GigabitEthernet0/0/13#interface GigabitEthernet0/0/14#interface GigabitEthernet0/0/15#interface GigabitEthernet0/0/16#interface GigabitEthernet0/0/17#interface GigabitEthernet0/0/18#interface GigabitEthernet0/0/19#interface GigabitEthernet0/0/20#interface GigabitEthernet0/0/21#interface GigabitEthernet0/0/22#interface GigabitEthernet0/0/23 port link-type access port default vlan222#interface GigabitEthernet0/0/24 port link-type access port default vlan333#interface NULL0#ospf1router-id7.7.7.7 silent-interface Vlanif222 silent-interface Vlanif333 bandwidth-reference1000area0.0.0.2 network192.168.6.20.0.0.0 network192.168.2.2540.0.0.0 network192.168.3.2540.0.0.0 stub#user-interface con0user-interface vty04#return路由器R1配置#sysname Huawei#aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password cipher cy9C$[HHtRH)H2[EInBQO#local-user admin service-type http#firewall zone Local priority16#interface Ethernet0/0/0ipaddress218.18.12.2255.255.255.252#interface Ethernet0/0/1#interface Serial0/0/0 link-protocol ppp#interface Serial0/0/1 link-protocol ppp#interface Serial0/0/2 link-protocol ppp#interface Serial0/0/3 link-protocol ppp#interface GigabitEthernet0/0/0#interface GigabitEthernet0/0/1#interface GigabitEthernet0/0/2#interface GigabitEthernet0/0/3#wlan#interface NULL0#iproute-static0.0.0.00.0.0.0218.18.12.1#user-interface con0user-interface vty04user-interface vty1620#return
本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如若转载,请注明出处:http://www.coloradmin.cn/o/2422497.html
如若内容造成侵权/违法违规/事实不符,请联系多彩编程网进行投诉反馈,一经查实,立即删除!