RIP, OSPF, EIGRP在网络中的再分发
实验步骤:R1/R2/R5的frame relay链路参与ospf area 0R5/R6的s2/1链路参与EIGRP 100R2的l0接口参与area 20R2/R4的frame relay链路参与area 4R1/R3的frame relay链路运行rip v2,不允许多余的接口发送rip路由在R1实施rip和ospf的双向再发布在R5实施eigrp到ospf的双向再发布R4的L1口配置4.4.5.4/32,参与ospf 40配置实例R1conf tint l 0ip ad 1.1.1.1 255.255.255.255ip ad 10.1.5.1 255.255.255.0encap fno arp fno frame inverframe map ip 10.1.5.5 105 bframe map ip 10.1.5.2 105 bip ospf priority 0no shutexitint s 2/1ip ad 10.1.1.1 255.255.255.0encap fno arp fno frame inverframe map ip 10.1.1.3 113 bno shutexitrouter ripver 2no aunet 10.0.0.0passive-interface s2/0redistribute ospf 1 metric 5router ospf 1router-id 1.1.1.1net 10.1.5.1 0.0.0.0 a 0net 1.1.1.1 0.0.0.0 a 0nei 10.1.5.5redistribute rip metric 100 metric-type 1 subnets endR2conf tint l 0ip ad 2.2.2.2 255.255.255.255int s2/0ip ad 10.1.5.2 255.255.255.0encap fno frame inverno arp frameframe map ip 10.1.5.5 205 bframe map ip 10.1.5.1 205 bip ospf priority 0exitint s2/1ip ad 10.1.2.2 255.255.255.0 encap fno arp fno frame inverframe map ip 10.1.2.4 214 b no shutip ospf network point-to-point exitrouter ospf 1router-id 2.2.2.2net 10.1.5.2 0.0.0.0 a 0net 2.2.2.2 0.0.0.0 a 20net 10.1.2.2 0.0.0.0 a 4nei 10.1.5.5area 4 virtual-link 4.4.4.4endR3conf tint l 0ip ad 3.3.3.3 255.255.255.255 int s2/1ip ad 10.1.1.3 255.255.255.0 encap fno arp fno frame inverframe map ip 10.1.1.3 311 b no shutexitrouter ripver 2no aunet 3.0.0.0net 10.0.0.0endR4conf tint l 0ip ad 4.4.4.4 255.255.255.255ip ad 4.4.5.4 255.255.255.255int s 2/1ip ad 10.1.2.4 255.255.255.0encap fno arp fno frame inverframe map ip 10.1.2.2 412 bno shutip ospf network point-to-pointrouter ospf 1router-id 4.4.4.4net 4.4.4.4 0.0.0.0 a 4net 10.1.2.4 0.0.0.0 a 4net 4.4.5.4 0.0.0.0 a 40area 4 virtual-link 2.2.2.2endR5conf tint l 0ip ad 5.5.5.5 255.255.255.255int s2/0ip ad 10.1.5.5 255.255.255.0encap fno arp fno frame inverframe map ip 10.1.5.1 501 bframe map ip 10.1.5.2 502 bno shutint s2/1ip ad 10.1.6.5 255.255.255.0encap fno arp fno frame inverframe map ip 10.1.6.6 516 bno shutrouter ospf 1router-id 5.5.5.5nei 10.1.5.1nei 10.1.5.2net 10.1.5.5 0.0.0.0 a 0net 5.5.5.5 0.0.0.0 a 0redistribute eigrp 100 subnets metric 100 metric-type 1router eigrp 100no autonet 10.1.6.5 0.0.0.0redistribute ospf 1 metric 10000 100 255 1 1500endR6conf tint l 0ip ad 6.6.6.6 255.255.255.255int s2/1ip ad 10.1.6.6 255.255.255.0encap fno arp fno frame inveframe map ip 10.1.6.5 615 bno shutrouter eigrp 100no aunet 6.6.6.6 0.0.0.0net 10.1.6.6 0.0.0.0end校验R1#sh ip routeCodes: C - connected, S - static, R - RIP, M - mobile, B - BGPD - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter areaN1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2ia - IS-IS inter area, * - candidate default, U - per-user static routeo - ODR, P - periodic downloaded static routeGateway of last resort is not set1.0.0.0/32 is subnetted, 1 subnetsC 1.1.1.1 is directly connected, Loopback02.0.0.0/32 is subnetted, 1 subnetsO IA 2.2.2.2 [110/65] via 10.1.5.2, 00:00:40, Serial2/03.0.0.0/32 is subnetted, 1 subnetsR 3.3.3.3 [120/1] via 10.1.1.3, 00:00:11, Serial2/14.0.0.0/32 is subnetted, 2 subnetsO IA 4.4.4.4 [110/129] via 10.1.5.2, 00:00:40, Serial2/0O IA 4.4.5.4 [110/129] via 10.1.5.2, 00:00:40, Serial2/05.0.0.0/32 is subnetted, 1 subnetsO 5.5.5.5 [110/65] via 10.1.5.5, 00:00:40, Serial2/06.0.0.0/32 is subnetted, 1 subnetsO E1 6.6.6.6 [110/164] via 10.1.5.5, 00:00:40, Serial2/010.0.0.0/24 is subnetted, 4 subnetsO IA 10.1.2.0 [110/128] via 10.1.5.2, 00:00:40, Serial2/0C 10.1.1.0 is directly connected, Serial2/1O E1 10.1.6.0 [110/164] via 10.1.5.5, 00:00:40, Serial2/0C 10.1.5.0 is directly connected, Serial2/0R2#sh ip routeCodes: C - connected, S - static, R - RIP, M - mobile, B - BGPD - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter areaN1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2ia - IS-IS inter area, * - candidate default, U - per-user static routeo - ODR, P - periodic downloaded static routeGateway of last resort is not set1.0.0.0/32 is subnetted, 1 subnetsO 1.1.1.1 [110/65] via 10.1.5.1, 00:00:44, Serial2/02.0.0.0/32 is subnetted, 1 subnetsC 2.2.2.2 is directly connected, Loopback03.0.0.0/32 is subnetted, 1 subnetsO E1 3.3.3.3 [110/164] via 10.1.5.1, 00:00:44, Serial2/04.0.0.0/32 is subnetted, 2 subnetsO 4.4.4.4 [110/65] via 10.1.2.4, 00:01:13, Serial2/1O IA 4.4.5.4 [110/65] via 10.1.2.4, 00:00:44, Serial2/15.0.0.0/32 is subnetted, 1 subnetsO 5.5.5.5 [110/65] via 10.1.5.5, 00:00:44, Serial2/06.0.0.0/32 is subnetted, 1 subnetsO E1 6.6.6.6 [110/164] via 10.1.5.5, 00:00:44, Serial2/010.0.0.0/24 is subnetted, 4 subnetsC 10.1.2.0 is directly connected, Serial2/1O E1 10.1.1.0 [110/164] via 10.1.5.1, 00:00:44, Serial2/0O E1 10.1.6.0 [110/164] via 10.1.5.5, 00:00:44, Serial2/0C 10.1.5.0 is directly connected, Serial2/0R3#sh ip routeCodes: C - connected, S - static, R - RIP, M - mobile, B - BGPD - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter areaN1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2ia - IS-IS inter area, * - candidate default, U - per-user static routeo - ODR, P - periodic downloaded static routeGateway of last resort is not set1.0.0.0/32 is subnetted, 1 subnetsR 1.1.1.1 [120/5] via 10.1.1.1, 00:00:13, Serial2/12.0.0.0/32 is subnetted, 1 subnetsR 2.2.2.2 [120/5] via 10.1.1.1, 00:00:13, Serial2/13.0.0.0/32 is subnetted, 1 subnetsC 3.3.3.3 is directly connected, Loopback04.0.0.0/32 is subnetted, 2 subnetsR 4.4.4.4 [120/5] via 10.1.1.1, 00:00:13, Serial2/1R 4.4.5.4 [120/5] via 10.1.1.1, 00:00:13, Serial2/15.0.0.0/32 is subnetted, 1 subnetsR 5.5.5.5 [120/5] via 10.1.1.1, 00:00:13, Serial2/16.0.0.0/32 is subnetted, 1 subnetsR 6.6.6.6 [120/5] via 10.1.1.1, 00:00:13, Serial2/110.0.0.0/24 is subnetted, 4 subnetsR 10.1.2.0 [120/5] via 10.1.1.1, 00:00:16, Serial2/1C 10.1.1.0 is directly connected, Serial2/1R 10.1.6.0 [120/5] via 10.1.1.1, 00:00:16, Serial2/1R 10.1.5.0 [120/1] via 10.1.1.1, 00:00:16, Serial2/1R4#sh ip routeCodes: C - connected, S - static, R - RIP, M - mobile, B - BGPD - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter areaN1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2ia - IS-IS inter area, * - candidate default, U - per-user static routeo - ODR, P - periodic downloaded static routeGateway of last resort is not set1.0.0.0/32 is subnetted, 1 subnetsO 1.1.1.1 [110/129] via 10.1.2.2, 00:01:04, Serial2/12.0.0.0/32 is subnetted, 1 subnetsO IA 2.2.2.2 [110/65] via 10.1.2.2, 00:01:04, Serial2/13.0.0.0/32 is subnetted, 1 subnetsO E1 3.3.3.3 [110/228] via 10.1.2.2, 00:01:04, Serial2/14.0.0.0/32 is subnetted, 2 subnetsC 4.4.4.4 is directly connected, Loopback0C 4.4.5.4 is directly connected, Loopback15.0.0.0/32 is subnetted, 1 subnetsO 5.5.5.5 [110/129] via 10.1.2.2, 00:01:04, Serial2/16.0.0.0/32 is subnetted, 1 subnetsO E1 6.6.6.6 [110/228] via 10.1.2.2, 00:01:04, Serial2/110.0.0.0/24 is subnetted, 4 subnetsC 10.1.2.0 is directly connected, Serial2/1O E1 10.1.1.0 [110/228] via 10.1.2.2, 00:01:04, Serial2/1O E1 10.1.6.0 [110/228] via 10.1.2.2, 00:01:04, Serial2/1O 10.1.5.0 [110/128] via 10.1.2.2, 00:01:04, Serial2/1R5#sh ip routeCodes: C - connected, S - static, R - RIP, M - mobile, B - BGPD - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter areaN1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2ia - IS-IS inter area, * - candidate default, U - per-user static routeo - ODR, P - periodic downloaded static routeGateway of last resort is not set1.0.0.0/32 is subnetted, 1 subnetsO 1.1.1.1 [110/65] via 10.1.5.1, 00:00:59, Serial2/02.0.0.0/32 is subnetted, 1 subnetsO IA 2.2.2.2 [110/65] via 10.1.5.2, 00:00:59, Serial2/03.0.0.0/32 is subnetted, 1 subnetsO E1 3.3.3.3 [110/164] via 10.1.5.1, 00:00:59, Serial2/04.0.0.0/32 is subnetted, 2 subnetsO IA 4.4.4.4 [110/129] via 10.1.5.2, 00:00:59, Serial2/0O IA 4.4.5.4 [110/129] via 10.1.5.2, 00:00:59, Serial2/05.0.0.0/32 is subnetted, 1 subnetsC 5.5.5.5 is directly connected, Loopback06.0.0.0/32 is subnetted, 1 subnetsD 6.6.6.6 [90/2297856] via 10.1.6.6, 00:14:35, Serial2/110.0.0.0/24 is subnetted, 4 subnetsO IA 10.1.2.0 [110/128] via 10.1.5.2, 00:01:00, Serial2/0O E1 10.1.1.0 [110/164] via 10.1.5.1, 00:01:00, Serial2/0C 10.1.6.0 is directly connected, Serial2/1C 10.1.5.0 is directly connected, Serial2/0R6#sh ip routeCodes: C - connected, S - static, R - RIP, M - mobile, B - BGPD - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter areaN1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2ia - IS-IS inter area, * - candidate default, U - per-user static routeo - ODR, P - periodic downloaded static routeGateway of last resort is not set1.0.0.0/32 is subnetted, 1 subnetsD EX 1.1.1.1 [170/2195456] via 10.1.6.5, 00:14:36, Serial2/12.0.0.0/32 is subnetted, 1 subnetsD EX 2.2.2.2 [170/2195456] via 10.1.6.5, 00:14:36, Serial2/13.0.0.0/32 is subnetted, 1 subnetsD EX 3.3.3.3 [170/2195456] via 10.1.6.5, 00:14:36, Serial2/14.0.0.0/32 is subnetted, 2 subnetsD EX 4.4.4.4 [170/2195456] via 10.1.6.5, 00:14:36, Serial2/1D EX 4.4.5.4 [170/2195456] via 10.1.6.5, 00:01:03, Serial2/15.0.0.0/32 is subnetted, 1 subnetsD EX 5.5.5.5 [170/2195456] via 10.1.6.5, 00:14:36, Serial2/16.0.0.0/32 is subnetted, 1 subnetsC 6.6.6.6 is directly connected, Loopback010.0.0.0/24 is subnetted, 4 subnetsD EX 10.1.2.0 [170/2195456] via 10.1.6.5, 00:14:38, Serial2/1D EX 10.1.1.0 [170/2195456] via 10.1.6.5, 00:14:38, Serial2/1C 10.1.6.0 is directly connected, Serial2/1D EX 10.1.5.0 [170/2195456] via 10.1.6.5, 00:14:38, Serial2/1本文出自“穿过地狱去看海” 博客,谢绝转载!。
BGP和OSPF在路由重分发时的注意点
RGNOSv10.3(3)BGP和OSPF在路由重分发时的注意点2008-5-15福建星网锐捷网络有限公司版权所有侵权必究前言本文档介绍了RGNOS V10.3(3)中BGP和OSPF路由重发布时的一些实现特点。
由于这些特点区别于友商CISCO的BGP功能实现,在具体的项目实施过程中需要注意。
1.☹本文档仅限公司内部使用,严禁外传。
1.☺如果您在阅读中产生疑问,请与文档维护人联系。
目录1. 1OSPF重分发BGP路由1. 1.1注意点1. 这里Cisco验证的版本为c7200-adventerprisek9-mz.124-9.T1.bin2. 1.2应用实例1. 1.2.1网络拓扑四台设备之间建立EBGP/IBGP/EBGP连接。
C1为CISCO 3550、C2、C3是Cisco模拟器,R1是我司设备,实验设备为RG-S5750。
C1和R1建立EBGP连接,R1和C2建立IBGP连接,C2和C3建立EBGP连接。
其中C1和C3主要是发送路由,具体的操作在R1和C2。
2. 1.2.2配置文件C1 简化配置C1#sho running-configBuilding configuration...Current configuration : 2557 bytes!version 12.2no service padservice timestamps debug uptimeservice timestamps log uptimeno service password-encryption!hostname C1!!no aaa new-modelip subnet-zeroip routing!!!!!!no file verify autospanning-tree mode pvstspanning-tree extend system-id!vlan internal allocation policy ascending!!interface Loopback0ip address 1.1.1.1 255.255.255.255!interface FastEthernet0/1no switchportip address 192.168.16.1 255.255.255.248!interface FastEthernet0/2switchport mode dynamic desirable!interface FastEthernet0/3switchport mode dynamic desirable!...!router bgp 1no synchronizationbgp log-neighbor-changesredistribute staticneighbor 192.168.16.2 remote-as 23no auto-summary!ip classlessip route 192.168.111.0 255.255.255.0 Loopback0ip route 192.168.112.0 255.255.255.0 Loopback0ip http serverip http secure-server!!!control-plane!!line con 0line vty 0 4privilege level 15password wlogin!!endC1#C2简化配置C2#sho runnBuilding configuration...Current configuration : 1450 bytes!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname C2!boot-start-markerwarm-rebootboot-end-marker!!no aaa new-model!resource policy!ip cef!!!!interface Loopback0ip address 192.168.125.1 255.255.255.0 secondary ip address 192.168.126.1 255.255.255.0 secondary ip address 2.2.2.2 255.255.255.255!interface FastEthernet0/0ip address 192.168.26.2 255.255.255.248duplex full!interface Ethernet1/0no ip addressshutdownduplex half!interface Ethernet1/1no ip addressshutdownduplex half!interface Ethernet1/2no ip addressshutdownduplex half!interface Ethernet1/3ip address 192.168.23.1 255.255.255.248duplex full!router ospf 1log-adjacency-changesnetwork 2.2.2.2 0.0.0.0 area 0network 192.168.26.0 0.0.0.7 area 0!router bgp 23no synchronizationbgp log-neighbor-changesnetwork 192.168.125.0network 192.168.126.0neighbor 6.6.6.6 remote-as 23neighbor 6.6.6.6 update-source Loopback0neighbor 6.6.6.6 next-hop-selfneighbor 192.168.23.2 remote-as 3no auto-summary!no ip http serverno ip http secure-server!!...!line con 0stopbits 1line aux 0line vty 0 4privilege level 15password wlogin!!endC2#C3简化配置C3#sho runnBuilding configuration...Current configuration : 1178 bytes!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname C3!boot-start-markerboot-end-marker!!no aaa new-model!resource policy!ip cef!!!!!!interface Loopback0ip address 3.3.3.3 255.255.255.255!interface FastEthernet0/0no ip addressshutdownduplex full!interface Ethernet1/0no ip addressshutdownduplex half!interface Ethernet1/1no ip addressshutdownduplex half!interface Ethernet1/2no ip addressshutdownduplex half!interface Ethernet1/3ip address 192.168.23.2 255.255.255.248duplex full!router bgp 3no synchronizationbgp log-neighbor-changesredistribute staticneighbor 192.168.23.1 remote-as 23no auto-summary!ip route 192.168.131.0 255.255.255.0 Loopback0ip route 192.168.132.0 255.255.255.0 Loopback0no ip http serverno ip http secure-server!!!logging alarm informational!...!line con 0stopbits 1line aux 0line vty 0 4privilege level 15password wlogin!!endC2#R1简化配置R1#show runnBuilding configuration...Current configuration : 2080 bytes!version RGNOS 10.3.00(3), Release(38105)(Fri Apr 25 15:29:44 CST 2008 -ngcf31)hostname R1co-operate enable!!!!route-map ospf_redist permit 10match route-type external!vlan 1!!!!!interface GigabitEthernet 0/1no switchportno ip proxy-arpip address 192.168.26.1 255.255.255.248!interface GigabitEthernet 0/2!...!interface GigabitEthernet 0/23!interface GigabitEthernet 0/24no switchportno ip proxy-arpip address 192.168.16.2 255.255.255.248!interface Loopback 0ip address 6.6.6.6 255.255.255.255ip address 192.168.165.1 255.255.255.0 secondaryip address 192.168.166.1 255.255.255.0 secondary!!!!!!!!router bgp 23neighbor 2.2.2.2 remote-as 23neighbor 2.2.2.2 update-source Loopback 0neighbor 192.168.16.1 remote-as 1!address-family ipv4network 192.168.165.0network 192.168.166.0neighbor 2.2.2.2 activateneighbor 2.2.2.2 next-hop-selfneighbor 192.168.16.1 activateexit-address-family!!router ospf 1router-id 6.6.6.6network 6.6.6.6 0.0.0.0 area 0network 192.168.26.0 0.0.0.7 area 0!!!ip route 192.168.161.0 255.255.255.0 Loopback 0ip route 192.168.162.0 255.255.255.0 Loopback 0!!line con 0line vty 0 10privilege level 15loginpassword w!!end3. 1.2.3检验配置效果C2使用show ip bgp可以看到125.0/126.0是源发路由,111.0/112.0/165.0/166.0是IBGP路由,131.0/132.0是EBGP路由。
08路由重分布
注意事项( 注意事项(续)
5、因为EIGRP的度量相对复杂,所以在重分 因为EIGRP的度量相对复杂, EIGRP的度量相对复杂 布时,需要分别指定带宽、延迟、可靠性、 布时,需要分别指定带宽、延迟、可靠性、 带宽 负载以及MTU参数的值。 负载以及MTU参数的值。 以及MTU参数的值 6、EIGRP能够识别内部路由和外部路由,默 EIGRP能够识别内部路由和外部路由, 能够识别内部路由和外部路由 认情况下,内部路由的管理距离是90,外 认情况下,内部路由的管理距离是90, 90 170( 部路由的管理距离是170 部路由的管理距离是170(路由代码为 EX” ”D EX )。
3、注入默认路由
EIGRP:ip defaultEIGRP:ip default-network (D* 1.0.0.0/8) OR:redistribute static (D*EX 0.0.0.0/0) RIP:defaul defaulRIP:defaul-information originate defaultOR:ip default-network OR:redistribute static 0.0.0.0/0) (R* 0.0.0.0/0) OSPF:defaul defaulOSPF:defaul-information originate (O*E2 0.0.0.0/0)
度量
路由重分布时,必须给重分布而来的路 由指定的度量值被称为默认度量值或 由指定的度量值被称为默认度量值或种 子度量值,它是在重分布期间定义的。 子度量值,它是在重分布期间定义的。
路由协议 RIP EIGRP OSPF IS-IS BGP 默认种子度量值 无限大 无限大 BGP为1,其他为20 0 IGP的度量值
配置重分布( 配置重分布(续)
交换路由协议
交换路由协议交换路由协议是指计算机网络中用于交换路由信息的协议,它可以帮助网络设备(如路由器、交换机)通过各种方式发现网络拓扑,并决定下一跳路由。
本文将介绍一些常见的交换路由协议,包括RIP、OSPF、BGP以及EIGRP。
1. 路由信息协议(RIP)是一种最早出现的交换路由协议之一。
它使用跳数作为度量标准,能够自动学习和交换路由信息。
RIP最初使用的是RIP v1协议,后来进化为RIP v2协议,支持更多功能和更高的可扩展性。
RIP协议适用于小型网络环境,但由于其较为简单的设计,不适合在大型复杂网络中使用。
2. 开放最短路径优先(OSPF)是一种基于链路状态的交换路由协议。
它能够通过洪泛(flooding)方式传递链路状态信息,计算网络中最短路径,并支持构建层次结构路由体系。
OSPF使用开销(cost)作为路径度量标准,可以适应不同的网络环境,并具备较高的可扩展性和稳定性。
OSPF属于内部网关协议(IGP),适用于大型企业网络或互联网服务提供者(ISP)网络。
3. 边界网关协议(BGP)是一种基于向量的交换路由协议,主要用于互联网中的自治系统(AS)之间的路由交换。
BGP协议通过路径属性(path attributes)和路由策略(route policies)控制路由选择和传播,支持多路径和路由策略的灵活配置。
BGP是一个复杂的协议,具有较高的可扩展性和稳定性,广泛应用于大型互联网服务提供商。
4. 增强内部网关路由协议(EIGRP)是思科系统开发的专有交换路由协议,适用于运行思科设备的网络环境。
EIGRP采用混合距离矢量与链路状态的路由算法,在传输路由信息时只发送必要的更新,减少网络带宽的占用。
EIGRP还支持快速收敛和较高的可靠性,适用于企业级网络环境。
以上是一些常见的交换路由协议,每种协议都具有其特定的优势和适用场景。
选取合适的交换路由协议可以根据网络规模、复杂度、性能需求和安全性等因素进行综合考虑。
常用动态路由协议安全性的评价3篇
常用动态路由协议安全性的评价3篇全文共3篇示例,供读者参考篇1常用动态路由协议安全性的评价随着互联网的不断发展和普及,网络安全问题逐渐成为人们关注的焦点。
在网络通信中,路由协议是一个至关重要的组成部分,它决定了数据包在网络中的传输路径。
常用的动态路由协议包括RIP、OSPF、EIGRP和BGP等,它们在网络中起着至关重要的作用。
然而,这些动态路由协议的安全性也备受人们关注。
本文将对常用动态路由协议的安全性进行评价,并提出相关建议。
1. RIP(Routing Information Protocol)RIP是最早的动态路由协议之一,它采用跳数作为路由选择的标准,但其安全性很差。
RIP协议中的信息是明文传输的,容易受到窃听和篡改攻击。
此外,RIP协议没有机制来验证路由更新的真实性,因此容易受到路由劫持攻击。
针对RIP协议的安全问题,可以采取加密通信、认证机制等方式来提高其安全性。
2. OSPF(Open Shortest Path First)OSPF是一种动态路由协议,它通过计算最短路径来选择最优路由。
相比于RIP协议,OSPF具有更好的安全性。
OSPF协议中的路由更新信息可以使用MD5密码进行认证,确保信息的完整性和真实性。
此外,OSPF协议还支持区域域间路由信息交换,可以降低对网络整体的负载和风险。
不过,OSPF协议的安全性仍然有待进一步改进,可以考虑增强认证机制和加密传输。
3. EIGRP(Enhanced Interior Gateway Routing Protocol)EIGRP是一种优化的动态路由协议,它结合了距离向量和链路状态两种路由选择算法。
EIGRP协议具有较高的安全性,它支持MD5密码认证来保证路由更新信息的完整性和真实性。
此外,EIGRP协议还具有快速收敛的特点,可以快速适应网络拓扑的变化。
不过,EIGRP协议的安全性还可以进一步加强,例如增加密钥管理机制和加密传输。
4. BGP(Border Gateway Protocol)BGP是一种用于互联网中的动态路由协议,它是当前互联网中使用最广泛的路由协议之一。
路由重分发工作原理
路由重分发工作原理路由重分发工作原理网络协议有很多种,例如isis、rip、ospf、bgp等,在大型公司中经常会出现网络设备之间运行多种网络协议的情况,各种网络协议之间如果不进行一定的配置那么设备之间是不能进行互通信息的,在这种情况下就出现了路由重分发技术,路由重分发的作用就是为了实现多种路由协议之间的协同工作。
路由重分发的工作原理:通过在各种路由协议的配置中添加一定的配置使将路由协议广播到另外的路由协议中,让各个路由协议都能检测到运行其他的路由协议的网段,从而实现数据的传输。
路由重分发技术需要用到redistribute命令rip协议的redistribute命令redistribute protocol 【metric metric-value】【match internal | external nssa-external type】【route-map map-tag】protocol:路由重分发的源路由协议 metric metric-value:设置路由重分发的度量值(1···6),没有将使用default-metric命令设置的metric值 match internal | external nssa-external type:设置重分发路由的条件,只适合重分发的源路由协议是ospf route-map map-tag应用路由图进行重分发ospf协议的redistribute命令 redistribute protocol 【subnets】【metric metric-value】【metric-type{1 | 2}】【tag tag-value】【route-map map-tag】protocol:路由重分发的源路由协议subnets:设置是否重分发子网metric metric-value:设置路由重分发的度量值(1···16777214),没有将使用default-metric命令设置的metric值metric metric-type:设置重分发的路由度量类型,默认值为2 tag tag-value:设置重分发的路由的tag(0···2147483647)默认为0 route-map map-tag应用路由图进行重分发重分发到ospf中的时候,除了直连路由和默认路由外,其他重分发的路由的默认的度量值是20,默认度量值类型是2,且默认不重分发子网。
RIP EIGRP BGP OSPF的防环机制
RIP 防环机制:
1.设置最大跳数(默认15,16条为不可达);
2.水平分割:从某接口收到的路由信息不会再从该接口发送出去;
3.毒性逆转:从某接口收到的路由信息会从该接口发送出去,但是该路由信息被设置
为不可达;
4.路由毒化
5.触发更新;
EIGRP 防环机制:
1.在主网络边界将自动汇总,同时在路由器上将产生一条指向NULL 0的路由;
2.水平分割;
BGP 防环机制:
1.AS-PATH:当收到的BGP路由信息中AS-PATH列表中包含自己的AS号,回丢弃该路
由;
2.IBGP水平分割:不把从IBGP邻居学到的路由信息发送给其他IBGP邻居;
3.cluster_list:是一种可选非传递性属性,用于记录簇ID,就像AS-PATH记录AS号一样,
当RR将来自客户的路由反射给给客户时,同时将其簇ID附加到cluster_list中,如果cluster_list为空,则RR将创建一个cluster_list。
RR接受到update消息后,就会检查cluster_list,如果发现其簇ID位于簇列表中,则知道已经出现了路由环路,从而忽略该update消息;
4.BGP同步:开启同步时,BGP路由器不会把从IBGP邻居收到的路由信息放入自己的
路由表或发送给其他EBGP邻居,除非该路由信息已经存在于IGP路由表中;
OSPF 防环机制:
1.区域内SPF算法保证区域内无环;
2.区域间:其他区域必须和区域0相连,区域间的通信需要通过区域0来进行通信;。
OSPF双点双向重分布
【实验要求】按照拓扑搭建网络,对RIP 和OSPF 做双点双向重分发。
使得全网全互联。
并对重分发带来的故障解决和分析。
【实验步骤】一、 按照拓扑,对各个路由器的基本命令及重分发配置完成,可参考实验《重分发一》和《重分发二》。
R1:interface Loopback0ip address 1.1.1.1 255.255.255.0interface Serial0/0ip address 192.168.13.1 255.255.255.0serial restart-delay 0interface Serial0/1ip address 192.168.14.1 255.255.255.0serial restart-delay 0router ospf 1router-id 1.1.1.1log-adjacency-changesredistribute rip subnetsnetwork 1.1.1.0 0.0.0.255 area 0network 192.168.14.0 0.0.0.255 area 0router ripversion 2redistribute ospf 1 metric 1network 192.168.13.0no auto-summaryRIP OSPFR1R2R3R4S 0/0 192.168.13.0/24 S 0/0S 0/0 192.168.24.0/24 S 0/0S 0/1 192.168.14.0/24 S 0/1S 0/1 192.168.23.0/24 S 0/1lo 0:1.1.1.1/24lo 0:2.2.2.2/24lo 0:3.3.3./24lo 0:3.3.3.3/24IGP 中4种路由协议的重分布三、OSPF 双点双向重分布R2:!interface Loopback0ip address 2.2.2.2 255.255.255.0interface Serial0/0ip address 192.168.24.2 255.255.255.0serial restart-delay 0interface Serial0/1ip address 192.168.23.2 255.255.255.0serial restart-delay 0router ospf 1router-id 2.2.2.2log-adjacency-changesredistribute rip subnetsnetwork 2.2.2.0 0.0.0.255 area 0network 192.168.24.0 0.0.0.255 area 0!router ripversion 2redistribute ospf 1 metric 1network 192.168.23.0no auto-summaryR3:interface Loopback0ip address 3.3.3.3 255.255.255.0interface Serial0/0ip address 192.168.13.3 255.255.255.0serial restart-delay 0interface Serial0/1ip address 192.168.23.3 255.255.255.0serial restart-delay 0router ripversion 2network 3.0.0.0network 192.168.13.0network 192.168.23.0R4:interface Loopback0ip address 4.4.4.4 255.255.255.0interface Serial0/0ip address 192.168.24.4 255.255.255.0serial restart-delay 0interface Serial0/1ip address 192.168.14.4 255.255.255.0serial restart-delay 0router ospf 1router-id 4.4.4.4log-adjacency-changesnetwork 4.4.4.0 0.0.0.255 area 0network 192.168.14.0 0.0.0.255 area 0network 192.168.24.0 0.0.0.255 area 0R1#sh ip rou//查看R1的路由表1.0.0.0/24 is subnetted, 1 subnetsC 1.1.1.0 is directly connected, Loopback0C 192.168.13.0/24 is directly connected, Serial0/02.0.0.0/8 is variably subnetted, 2 subnets, 2 masksO 2.2.2.2/32 [110/129] via 192.168.14.4, 00:03:05, Serial0/1 R 2.2.2.0/24 [120/2] via 192.168.13.3, 00:00:24, Serial0/0C 192.168.14.0/24 is directly connected, Serial0/13.0.0.0/24 is subnetted, 1 subnetsO E2 3.3.3.0 [110/20] via 192.168.14.4, 00:03:05, Serial0/14.0.0.0/32 is subnetted, 1 subnetsO 4.4.4.4 [110/65] via 192.168.14.4, 00:03:06, Serial0/1O 192.168.24.0/24 [110/128] via 192.168.14.4, 00:03:06, Serial0/1 O E2 192.168.23.0/24 [110/20] via 192.168.14.4, 00:03:06, Serial0/1 R1#R2#sh ip rou//查看R2的路由表1.0.0.0/8 is variably subnetted, 2 subnets, 2 masksO 1.1.1.1/32 [110/129] via 192.168.24.4, 00:02:46, Serial0/0 R 1.1.1.0/24 [120/2] via 192.168.23.3, 00:00:23, Serial0/1O E2 192.168.13.0/24 [110/20] via 192.168.24.4, 00:02:46, Serial0/02.0.0.0/24 is subnetted, 1 subnetsC 2.2.2.0 is directly connected, Loopback0O 192.168.14.0/24 [110/128] via 192.168.24.4, 00:02:46, Serial0/03.0.0.0/24 is subnetted, 1 subnetsR 3.3.3.0 [120/1] via 192.168.23.3, 00:00:23, Serial0/14.0.0.0/32 is subnetted, 1 subnetsO 4.4.4.4 [110/65] via 192.168.24.4, 00:02:46, Serial0/0C 192.168.24.0/24 is directly connected, Serial0/0C 192.168.23.0/24 is directly connected, Serial0/1R1#traceroute 3.3.3.3//R1上跟踪路由3.3.3.3Type escape sequence to abort.Tracing the route to 3.3.3.31 192.168.14.4 116 msec 112 msec 100 msec2 192.168.24.2 136 msec 104 msec 44 msec3 192.168.23.3 152 msec * 244 msecR1#//发现,R1去往3.3.3.0/24的路由,要通过R4,再通过R2,才到达R3,在OSPF区域绕了一圈之后进入RIP,OSPF双点双向重分布会造成环路。
OSPF,EIGRP(RIP),BGP的network的区别
内部网关协议IGP(包括ospf,eigrp,rip)的network命令都是为了说明哪一个接口启用该igp 协议:
ospf协议的network命令通告的是端口~
rip协议eigrp协议network命令在没有追加子网掩码的情况下通告的是网段~
其实两者就是有类和无类的区别,通告网段中的“网段”2字就是指有类的大网段,通告端口则可以理解为通告无类网段的另一个说法而已~
~~在没有标注子网掩码的情况下,rip和eigrp两个协议的命令
network 192.168.1.0 ----> network 192.168.0.0
会自动将写入的无类网段通告转换成有类网段通告,这一点在running configure中会体现~~依上所述,如果在rip协议和eigrp协议的network命令后面上加上了子网掩码的话,那么这两个协议network命令和ospf协议network命令所到达的效果就没有什么不同了
外部网关协议EGP(仅仅说明BGP)的network命令则是为了提取IGP的路由条目:对于BGP而言,只有在IGP路由表中包含这条路由条目的时候,才可能被BGP路由协议提取并发布~
其精髓就是匹配IGP路由表,而这种匹配的重点就在于他的精确性:
1. S 19
2.168.1.0 255.255.255.0
2. S 192.168.1.1 255.255.255.255
对于以上两个路由条目,如果写入(GBP)network 192.168.1.0 mask 255.255.255.0 ~~那么只会匹配第一条路由条目(序号1),不会匹配第二条路由条目,这就是BGP与IGP的network 命令的最大区别所在。
多点双向重分发
d第一步:先在R1上把RIP重分发进OSPF中,然后在R3上查看路由表R3#show ip routeCodes: C - connected, S - static, R - RIP, M - mobile, B - BGPD - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter areaN1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static routeGateway of last resort is not set34.0.0.0/24 is subnetted, 1 subnetsC 34.34.34.0 is directly connected, Serial1/11.0.0.0/32 is subnetted, 1 subnetsO 1.1.1.1 [110/129] via 34.34.34.4, 00:00:15, Serial1/12.0.0.0/24 is subnetted, 1 subnetsO E2 2.2.2.0 [110/20] via 34.34.34.4, 00:00:15, Serial1/13.0.0.0/24 is subnetted, 1 subnetsC 3.3.3.0 is directly connected, Loopback04.0.0.0/32 is subnetted, 1 subnetsO 4.4.4.4 [110/65] via 34.34.34.4, 00:00:15, Serial1/123.0.0.0/24 is subnetted, 1 subnetsC 23.23.23.0 is directly connected, Serial1/012.0.0.0/24 is subnetted, 1 subnetsO E2 12.12.12.0 [110/20] via 34.34.34.4, 00:00:16, Serial1/114.0.0.0/24 is subnetted, 1 subnetsO 14.14.14.0 [110/128] via 34.34.34.4, 00:00:17, Serial1/1R4#config tR4(config)#access-list 10 permit 2.2.2.0R4(config)#access-list 10 permit 12.12.12.0R4(config)#router ospf 100R4(config-router)#distance 121 1.1.1.1 0.0.0.0 10R4(config-router)#endR4#show ip routeCodes: C - connected, S - static, R - RIP, M - mobile, B - BGPD - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter areaN1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static routeGateway of last resort is not set34.0.0.0/24 is subnetted, 1 subnetsC 34.34.34.0 is directly connected, Serial1/11.0.0.0/32 is subnetted, 1 subnetsO 1.1.1.1 [110/65] via 14.14.14.1, 00:01:48, Serial1/02.0.0.0/24 is subnetted, 1 subnetsO E2 2.2.2.0 [121/20] via 14.14.14.1, 00:01:48, Serial1/04.0.0.0/24 is subnetted, 1 subnetsC 4.4.4.0 is directly connected, Loopback012.0.0.0/24 is subnetted, 1 subnetsO E2 12.12.12.0 [121/20] via 14.14.14.1, 00:01:48, Serial1/014.0.0.0/24 is subnetted, 1 subnetsC 14.14.14.0 is directly connected, Serial1/0第二步:在R4上将OSPF重分发进RIP。
OSPF多进程之间的路由重发布
OSPF多进程之间的路由重发布1、实验拓扑如下图:R1R4R3 R2Area 00spf 10Area 0Ospf 1002、实验目的:1、实现R2与R3之间互相访问时的数据分流。
R2访问R3的3.3.3.3/32时走R1,R2访问R3的30.30.30.30/32时走R4。
R3访问R2的2.2.2.2/32时走R1,R3访问R2的20.20.20.20/32时走R1。
2、实现线路的冗余备份。
当R1链路故障时数据可以走R4,当R4链路故障时数据可以走R1。
实现链路的冗余备份。
3、理解并掌握route-map在控制路由方面的应用。
3、实验配置文档R1配置:config terint f0/0ip add 10.0.0.1 255.255.255.252no shutint f1/0ip add 10.0.0.5 255.255.255.252no shutint lo 0ip add 1.1.1.1 255.255.255.255endwriteconfig terrouter ospf 10router-id 1.1.1.1network 10.0.0.0 0.0.0.3 area 0redistribute ospf 100 metric-type 1 subnets route-map ospf100_to_ospf10 distribute-list deny_ospf100 inendconfig terrouter ospf 100router-id 1.1.1.1network 10.0.0.4 0.0.0.3 area 0redistribute ospf 10 metric-type 1 subnets route-map ospf10_to_ospf100 distribute-list deny_ospf10 inendwriteip access-list standard deny_ospf10deny 2.2.2.2 0.0.0.0deny 20.20.20.20 0.0.0.0permit anyip access-list standard deny_ospf100deny 3.3.3.3 0.0.0.0deny 30.30.30.30 0.0.0.0permit anyaccess-list 10 permit 2.2.2.2 0.0.0.0access-list 11 permit 3.3.3.3 0.0.0.0access-list 20 permit 20.20.20.20 0.0.0.0access-list 21 permit 30.30.30.30 0.0.0.0route-map ospf100_to_ospf10 permit 10match ip address 11set metric 100route-map ospf100_to_ospf10 permit 20match ip address 21set metric 200route-map ospf10_to_ospf100 permit 10match ip address 10set metric 100route-map ospf10_to_ospf100 permit 20match ip address 20set metric 200R4配置:config terint f0/0ip add 172.16.0.1 255.255.255.252no shutint f1/0ip add 172.16.0.5 255.255.255.252no shutint lo 0ip add 4.4.4.4 255.255.255.255endwriteconfig terrouter ospf 10router-id 4.4.4.4network 172.16.0.4 0.0.0.3 area 0redistribute ospf 100 metric-type 1 subnets route-map ospf100_to_ospf10 distribute-list deny_ospf100 inendconfig terrouter ospf 100router-id 4.4.4.4network 172.16.0.0 0.0.0.3 area 0redistribute ospf 10 metric-type 1 subnets route-map ospf10_to_ospf100 distribute-list deny_ospf10 inendwriteip access-list standard deny_ospf10deny 2.2.2.2 0.0.0.0deny 20.20.20.20 0.0.0.0permit anyip access-list standard deny_ospf100deny 3.3.3.3 0.0.0.0deny 30.30.30.30 0.0.0.0permit anyaccess-list 10 permit 2.2.2.2 0.0.0.0access-list 11 permit 3.3.3.3 0.0.0.0access-list 20 permit 20.20.20.20 0.0.0.0access-list 21 permit 30.30.30.30 0.0.0.0route-map ospf100_to_ospf10 permit 10 match ip address 11set metric 200route-map ospf100_to_ospf10 permit 20 match ip address 21set metric 100route-map ospf10_to_ospf100 permit 10 match ip address 10set metric 200route-map ospf10_to_ospf100 permit 20 match ip address 20set metric 100R2的配置:config terint f0/0ip add 10.0.0.2 255.255.255.252no shutint f1/0ip add 172.16.0.6 255.255.255.252no shutint lo 0ip add 2.2.2.2 255.255.255.255int lo 1ip add 20.20.20.20 255.255.255.255 endwriteconfig terrouter ospf 10router-id 2.2.2.2network 172.16.0.4 0.0.0.3 area 0 network 10.0.0.0 0.0.0.3 area 0 network 2.2.2.2 0.0.0.0 area 0network 20.20.20.20 0.0.0.0 area 0endwriteR3的配置:config terint f0/0ip add 10.0.0.6 255.255.255.252no shutint f1/0ip add 172.16.0.2 255.255.255.252no shutint lo 0ip add 3.3.3.3 255.255.255.255int lo 1ip add 30.30.30.30 255.255.255.255endwriteconfig termrouter ospf 100router-id 3.3.3.3network 172.16.0.0 0.0.0.3 area 0network 10.0.0.4 0.0.0.3 area 0network 3.3.3.3 0.0.0.0 area 0network 30.30.30.30 0.0.0.0 area 0endwrite4、实验测试1、在R2上show ip route查看结果,可以看出实现了数据分流。
