组网需求
如图,运行OSPF协议的网络中,RouterA从Internet网络接收路由,并为OSPF网络提供了Internet路由。要求OSPF网络中只能访问172.16.17.0/24、172.16.18.0/24和172.16.19.0/24三个网段的网络,其中RouterC连接的网络只能访问172.16.18.0/24网段的网络。
配置思路
采用如下的思路配置对路由进行过滤:
- 在RouterA上配置ACL,在路由发布时应用ACL,使RouterA仅提供路由172.16.17.0/24、172.16.18.0/24、172.16.19.0/24给RouterB,实现OSPF网络中只能访问172.16.17.0/24、172.16.18.0/24、172.16.19.0/24三个网段的网络。
- 在RouterC上配置ACL,在路由引入时应用ACL,使RouterC仅接收路由172.16.18.0/24,实现RouterC连接的网络只能访问172.16.18.0/24网段的网络。
操作步骤
配置各接口的IP地址
Router A
<Huawei>sys <Huawei>sys Router A [Router A]interface GigabitEthernet0/0/0 [Router A-GigabitEthernet0/0/0]ip address 192.168.1.1 24 [Router A-GigabitEthernet0/0/0]quit
Router B
<Huawei>sys <Huawei>sys Router B [Router B]interface GigabitEthernet0/0/0 [Router B-GigabitEthernet0/0/0]ip address 192.168.3.1 24 [Router B-GigabitEthernet0/0/0]quit [Router B]interface GigabitEthernet0/0/1 [Router B-GigabitEthernet0/0/1]ip address 192.168.2.1 24 [Router B-GigabitEthernet0/0/1]quit [Router B]interface GigabitEthernet0/0/2 [Router B-GigabitEthernet0/0/2]ip address 192.168.1.2 24 [Router B-GigabitEthernet0/0/2]quit
Router C
<Huawei>sys <Huawei>sys Router C [Router C]interface GigabitEthernet0/0/0 [Router C-GigabitEthernet0/0/0]ip address 192.168.3.2 24 [Router C-GigabitEthernet0/0/0]quit
Router D
<Huawei>sys <Huawei>sys Router D [Router D]interface GigabitEthernet0/0/0 [Router D-GigabitEthernet0/0/0]ip address 192.168.2.2 24 [Router D-GigabitEthernet0/0/0]quit
配置OSPF基本功能
Router A
[Router A]ospf 1 [Router A-ospf-1]area 0.0.0.1 [Router A-ospf-1-area-0.0.0.1]network 192.168.1.0 0.0.0.255 [Router A-ospf-1-area-0.0.0.1]quit [Router A-ospf-1]quit
Router B
[Router B]ospf 1 [Router B-ospf-1]area 0.0.0.1 [Router B-ospf-1-area-0.0.0.1]network 192.168.1.0 0.0.0.255 [Router B-ospf-1-area-0.0.0.1]network 192.168.2.0 0.0.0.255 [Router B-ospf-1-area-0.0.0.1]network 192.168.3.0 0.0.0.255 [Router B-ospf-1-area-0.0.0.1]quit [Router B-ospf-1]quit
Router C
[Router C]ospf 1 [Router C-ospf-1]area 0.0.0.1 [Router C-ospf-1-area-0.0.0.1]network 192.168.3.0 0.0.0.255 [Router C-ospf-1-area-0.0.0.1]quit [Router C-ospf-1]quit
Router D
[Router D]ospf 1 [Router D-ospf-1]area 0.0.0.1 [Router D-ospf-1-area-0.0.0.1]network 192.168.2.0 0.0.0.255 [Router D-ospf-1-area-0.0.0.1]quit [Router D-ospf-1]quit
在RouterA上配置静态路由,并引入OSPF协议
Router A
[RouterA]ip route-static 172.16.16.0 24 NULL 0 [RouterA]ip route-static 172.16.17.0 24 NULL 0 [RouterA]ip route-static 172.16.18.0 24 NULL 0 [RouterA]ip route-static 172.16.19.0 24 NULL 0 [RouterA]ip route-static 172.16.20.0 24 NULL 0 [RouterA]ospf [RouterA-ospf-1]import-route static [RouterA-ospf-1]quit
查看RouterB路由表是否有配置的静态路由
[Router B]display ospf routing OSPF Process 1 with Router ID 192.168.3.1 Routing Tables Routing for Network Destination Cost Type NextHop AdvRouter Area 192.168.1.0/24 1 Transit 192.168.1.2 192.168.3.1 0.0.0.1 192.168.2.0/24 1 Transit 192.168.2.1 192.168.3.1 0.0.0.1 192.168.3.0/24 1 Transit 192.168.3.1 192.168.3.1 0.0.0.1 Routing for ASEs Destination Cost Type Tag NextHop AdvRouter 172.16.16.0/24 1 Type2 1 192.168.1.1 192.168.1.1 172.16.17.0/24 1 Type2 1 192.168.1.1 192.168.1.1 172.16.18.0/24 1 Type2 1 192.168.1.1 192.168.1.1 172.16.19.0/24 1 Type2 1 192.168.1.1 192.168.1.1 172.16.20.0/24 1 Type2 1 192.168.1.1 192.168.1.1 Total Nets: 8 Intra Area: 3 Inter Area: 0 ASE: 5 NSSA: 0
[Router B]display ip routing-table Route Flags: R - relay, D - download to fib ------------------------------------------------------------------------------ Routing Tables: Public Destinations : 18 Routes : 18 Destination/Mask Proto Pre Cost Flags NextHop Interface 127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0 127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0 127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0 172.16.16.0/24 O_ASE 150 1 D 192.168.1.1 GigabitEthernet0/0/2 172.16.17.0/24 O_ASE 150 1 D 192.168.1.1 GigabitEthernet0/0/2 172.16.18.0/24 O_ASE 150 1 D 192.168.1.1 GigabitEthernet0/0/2 172.16.19.0/24 O_ASE 150 1 D 192.168.1.1 GigabitEthernet0/0/2 172.16.20.0/24 O_ASE 150 1 D 192.168.1.1 GigabitEthernet0/0/2 192.168.1.0/24 Direct 0 0 D 192.168.1.2 GigabitEthernet0/0/2 192.168.1.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/2 192.168.1.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/2 192.168.2.0/24 Direct 0 0 D 192.168.2.1 GigabitEthernet0/0/1 192.168.2.1/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/1 192.168.2.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/1 192.168.3.0/24 Direct 0 0 D 192.168.3.1 GigabitEthernet0/0/0 192.168.3.1/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/0 192.168.3.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/0 255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
配置路由发布策略
在RouterA配置 过滤器 ACL 2021 ,允许172.16.17.0/24、172.16.18.0/24和172.16.19.0/24通过
[RouterA]acl number 2021 [RouterA-acl-basic-2021]rule permit source 172.16.17.0 0.0.0.255 [RouterA-acl-basic-2021]rule permit source 172.16.18.0 0.0.0.255 [RouterA-acl-basic-2021]rule permit source 172.16.19.0 0.0.0.255 [RouterA-acl-basic-2021]quit [RouterA]
在RouterA OSPF中配置发布策略,引用ACL 2021进行过滤
[RouterA]ospf [RouterA-ospf-1]filter-policy 2021 export static [RouterA-ospf-1]quit
再次查看RouterB路由表,可以看到RouterB仅接收到ACL 2021中定义的3条路由
[Router B]display ip routing-table Route Flags: R - relay, D - download to fib ------------------------------------------------------------------------------ Routing Tables: Public Destinations : 16 Routes : 16 Destination/Mask Proto Pre Cost Flags NextHop Interface 127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0 127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0 127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0 172.16.17.0/24 O_ASE 150 1 D 192.168.1.1 GigabitEthernet0/0/2 172.16.18.0/24 O_ASE 150 1 D 192.168.1.1 GigabitEthernet0/0/2 172.16.19.0/24 O_ASE 150 1 D 192.168.1.1 GigabitEthernet0/0/2 192.168.1.0/24 Direct 0 0 D 192.168.1.2 GigabitEthernet0/0/2 192.168.1.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/2 192.168.1.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/2 192.168.2.0/24 Direct 0 0 D 192.168.2.1 GigabitEthernet0/0/1 192.168.2.1/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/1 192.168.2.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/1 192.168.3.0/24 Direct 0 0 D 192.168.3.1 GigabitEthernet0/0/0 192.168.3.1/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/0 192.168.3.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/0 255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
配置路由接收策略
先查看Router C路由表,以便区别
[Router C]display ip routing-table Route Flags: R - relay, D - download to fib ------------------------------------------------------------------------------ Routing Tables: Public Destinations : 14 Routes : 14 Destination/Mask Proto Pre Cost Flags NextHop Interface 127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0 127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0 127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0 172.16.17.0/24 O_ASE 150 1 D 192.168.3.1 GigabitEthernet0/0/0 172.16.18.0/24 O_ASE 150 1 D 192.168.3.1 GigabitEthernet0/0/0 172.16.19.0/24 O_ASE 150 1 D 192.168.3.1 GigabitEthernet0/0/0 192.168.1.0/24 OSPF 10 2 D 192.168.3.1 GigabitEthernet0/0/0 192.168.2.0/24 OSPF 10 2 D 192.168.3.1 GigabitEthernet0/0/0 192.168.3.0/24 Direct 0 0 D 192.168.3.2 GigabitEthernet0/0/0 192.168.3.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/0 192.168.3.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/0 255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
在RouterC配置ACL 2022,允许172.16.18.0/24通过
[RouterC]acl number 2022 [RouterC-acl-basic-2022]rule permit source 172.16.18.0 0.0.0.255 [RouterC-acl-basic-2022]quit
在RouterC配置接收策略,引用ACL 2022进行过滤
[RouterC]ospf [RouterC-ospf-1]filter-policy 2022 import [RouterC-ospf-1]q [RouterC]
再次查看RouterC的IP路由表,可以看到RouterC的本地路由表中,仅接收了ACL 2022定义的1条路由
[Router C]display ip routing-table Route Flags: R - relay, D - download to fib ------------------------------------------------------------------------------ Routing Tables: Public Destinations : 14 Routes : 14 Destination/Mask Proto Pre Cost Flags NextHop Interface 127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0 127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0 127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0 172.16.18.0/24 O_ASE 150 1 D 192.168.3.1 GigabitEthernet0/0/0 192.168.3.0/24 Direct 0 0 D 192.168.3.2 GigabitEthernet0/0/0 192.168.3.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/0 192.168.3.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet0/0/0 255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
公众号:刘俊辉个人博客