2.路由策略配置

1.路由策略Route-policy

規(guī)定路由器在發(fā)布路由時只發(fā)布某些滿足特定條件的路由,在接收路由時只接收滿足特定條件的路由,在引入路由時只引入某些滿足特定條件的路由,等等。

Route-policy由一個或多個節(jié)點(Node)構(gòu)成,Node之間是“或”的關(guān)系。每個Node都有一個編號,路由項按照Node編號由小到大的順序通過各個Node。每個Node下可以有若干個if-match和apply子句,if-match之間是“與”的關(guān)系。If-match子句用來定義匹配規(guī)則,即路由項通過當(dāng)前Node所需要滿足的條件,匹配對象是路由項的某個屬性,比如路由前綴、NextHop、Cost、路由優(yōu)先級等;apply子句用來規(guī)定處理動作。

Route-policy的每個Node都有相應(yīng)的permit模式或deny模式。如果是permit模式,則當(dāng)路由項滿足該Node的所有if-match子句時,就被允許通過該Node的過濾并執(zhí)行該Node的apply子句,不再進(jìn)入下一個Node;如果路由項沒有滿足該Node的所有if-match子句,則會進(jìn)入下一個Node繼續(xù)進(jìn)行過濾。如果是deny模式,則當(dāng)路由項滿足該Node的所有if-match子句時,就被拒絕通過該Node的過濾,這時apply子句不會被執(zhí)行,并且不進(jìn)入下一個Node;否則就進(jìn)入下一個Node繼續(xù)進(jìn)行過濾。


拓?fù)浣Y(jié)構(gòu)


1.基本接口配置(略)

2.RIPv2和OSPF配置

[R1]rip

[R1-rip-1]version 2

[R1-rip-1]undo summary

[R1-rip-1]network 10.0.0.0

[R1-rip-1]network 192.168.1.0

[R1-rip-1]network 192.168.2.0

[R1-rip-1]network 192.168.3.0

[R1-rip-1]network 192.168.4.0

[R2]rip

[R2-rip-1]version 2

[R2-rip-1]undo summary

[R2-rip-1]network 10.0.0.0

[R2]ospf 1

[R2-ospf-1]area 0

[R2-ospf-1-area-0.0.0.0]network10.0.23.1 0.0.0.0

[R3]ospf 1

[R3-ospf-1]area 0

[R3-ospf-1-area-0.0.0.0]network10.0.23.2 0.0.0.0

[R3-ospf-1-area-0.0.0.0]network10.0.34.2 0.0.0.0

[R4]rip

[R4-rip-1]version 2

[R4-rip-1]undo summary

[R4-rip-1]network 10.0.0.0

[R4-rip-1]ospf 1

[R4-ospf-1]area 0

[R4-ospf-1-area-0.0.0.0]network10.0.34.1 0.0.0.0

在R2和R4上將RIP路由引入到OSPF協(xié)議中

[R2]ospf 1

[R2-ospf-1]import-route rip 1

[R4]ospf 1

[R4-ospf-1]import-route rip 1

配置完成后查看R3的IP路由表

[R3]dis ip routing-table

Route Flags: R - relay, D - downloadto fib

------------------------------------------------------------------------------

Routing Tables: Public

Destinations : 19Routes : 26

Destination/MaskProtoPreCostFlags NextHopInterface

10.0.1.1/32O_ASE1501D10.0.23.1Serial1/0/0

O_ASE1501D10.0.34.1Serial1/0/1

10.0.12.0/24O_ASE1501D10.0.23.1Serial1/0/0

O_ASE1501D10.0.34.1Serial1/0/1

10.0.14.0/24O_ASE1501D10.0.23.1Serial1/0/0

O_ASE1501D10.0.34.1Serial1/0/1

10.0.23.0/24Direct00D10.0.23.2Serial1/0/0

10.0.23.1/32Direct00D10.0.23.1Serial1/0/0

10.0.23.2/32Direct00D127.0.0.1Serial1/0/0

10.0.23.255/32Direct00D127.0.0.1Serial1/0/0

10.0.34.0/24Direct00D10.0.34.2Serial1/0/1

10.0.34.1/32Direct00D10.0.34.1Serial1/0/1

10.0.34.2/32Direct00D127.0.0.1Serial1/0/1

10.0.34.255/32Direct00D127.0.0.1Serial1/0/1

127.0.0.0/8Direct00D127.0.0.1InLoopBack0

127.0.0.1/32Direct00D127.0.0.1InLoopBack0

127.255.255.255/32Direct00D127.0.0.1InLoopBack0

192.168.1.0/24O_ASE1501D10.0.34.1Serial1/0/1

O_ASE1501D10.0.23.1Serial1/0/0

192.168.2.0/24O_ASE1501D10.0.23.1Serial1/0/0

O_ASE1501D10.0.34.1Serial1/0/1

192.168.3.0/24O_ASE1501D10.0.34.1Serial1/0/1

O_ASE1501D10.0.23.1Serial1/0/0

192.168.4.0/24O_ASE1501D10.0.23.1Serial1/0/0

O_ASE1501D10.0.34.1Serial1/0/1

255.255.255.255/32Direct00D127.0.0.1InLoopBack0

3.使用Route-policy對引入到OSPF進(jìn)程的路由進(jìn)行過濾和修改。

要求:從R3去往192.168.1.0/24和192.168.3.0/24這兩個網(wǎng)段的流量經(jīng)由路徑R3-R2-R1,并且被引入OSPF時Cost值為20,cost-type為type-1。而在R4上引入兩條路由時cost值為30,cost-type為type-1。

#首先使用ACL來進(jìn)行匹配網(wǎng)段

[R2]acl 2000

[R2-acl-basic-2000]rule permitsource 192.168.1.0 0.0.254.255

[R4]acl 2000

[R4-acl-basic-2000]rule permitsource 192.168.1.0 0.0.254.255

#創(chuàng)建Route-policy,并進(jìn)行相應(yīng)設(shè)置

[R2]route-policy import-ospf permitnode 5

[R2-route-policy]if-match acl 2000

[R2-route-policy]apply cost 20

[R2-route-policy]apply cost-typetype-1

[R4]route-policy import-ospf permitnode 5

[R4-route-policy]if-match acl 2000

[R4-route-policy]apply cost 30

[R4-route-policy]apply cost-typetype-1

在R2、R4上將RIP引入OSPF時,應(yīng)用Route-policy

[R2]ospf 1

[R2-ospf-1]import-route riproute-policy import-ospf

[R4]ospf 1

[R4-ospf-1]import-route riproute-policy import-ospf

配置完成后查看R3的IP路由表

[R3]dis ip routing-table

Route Flags: R - relay, D - downloadto fib

------------------------------------------------------------------------------

Routing Tables: Public

Destinations : 19Routes : 20

Destination/MaskProtoPreCostFlags NextHopInterface

10.0.1.1/32O_ASE1501D10.0.23.1Serial1/0/0

O_ASE1501D10.0.34.1Serial1/0/1

10.0.12.0/24O_ASE1501D10.0.34.1Serial1/0/1

10.0.14.0/24O_ASE1501D10.0.34.1Serial1/0/1

10.0.23.0/24Direct00D10.0.23.2Serial1/0/0

10.0.23.1/32Direct00D10.0.23.1Serial1/0/0

10.0.23.2/32Direct00D127.0.0.1Serial1/0/0

10.0.23.255/32Direct00D127.0.0.1Serial1/0/0

10.0.34.0/24Direct00D10.0.34.2Serial1/0/1

10.0.34.1/32Direct00D10.0.34.1Serial1/0/1

10.0.34.2/32Direct00D127.0.0.1Serial1/0/1

10.0.34.255/32Direct00D127.0.0.1Serial1/0/1

127.0.0.0/8Direct00D127.0.0.1InLoopBack0

127.0.0.1/32Direct00D127.0.0.1InLoopBack0

127.255.255.255/32Direct00D127.0.0.1InLoopBack0

192.168.1.0/24O_ASE15068D10.0.23.1Serial1/0/0

192.168.2.0/24O_ASE1501D10.0.34.1Serial1/0/1

192.168.3.0/24O_ASE15068D10.0.23.1Serial1/0/0

192.168.4.0/24O_ASE1501D10.0.34.1Serial1/0/1

255.255.255.255/32Direct00D127.0.0.1InLoopBack0

發(fā)現(xiàn)已經(jīng)少了兩條。

此外同時要求從R3去往192.168.2.0/24和192.18.4.0/24這兩個網(wǎng)段的流量經(jīng)由路徑R3-R4-R1,并且cost值為20、cost-type為type-2。在R2上引入這兩條路由時的Cost值為30。

[R2]acl 2001

[R2-acl-basic-2001]rule permitsource 192.168.2.0 0.0.254.255

[R4]acl 2001

[R4-acl-basic-2001]rule permitsource 192.168.2.0 0.0.254.255

#在R2、R4上添加新的策略node

[R2]route-policy import-ospf permitnode 10

[R2-route-policy]if-match acl 2001

[R2-route-policy]apply cost 30

[R2-route-policy]apply cost-typetype-2

[R4]route-policy import-ospf permitnode 10

[R4-route-policy]if-match acl 2001

[R4-route-policy]apply cost 20

[R4-route-policy]apply cost-typetype-2

//f???M?)i

最后編輯于
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請聯(lián)系作者
【社區(qū)內(nèi)容提示】社區(qū)部分內(nèi)容疑似由AI輔助生成,瀏覽時請結(jié)合常識與多方信息審慎甄別。
平臺聲明:文章內(nèi)容(如有圖片或視頻亦包括在內(nèi))由作者上傳并發(fā)布,文章內(nèi)容僅代表作者本人觀點,簡書系信息發(fā)布平臺,僅提供信息存儲服務(wù)。

相關(guān)閱讀更多精彩內(nèi)容

友情鏈接更多精彩內(nèi)容