
使用IS-IS协议作为IGP,AR4和AR5运行在49.0002区域,为L2路由器。AR1、AR2、AR3运行在49.0001区域,其中AR1是L1路由器,AR2、AR3是L1-2路由器。在AR5中,我们还引入了外部路由192.168.1.0/24
目的:AR1可以访问AR5引入的外部路由,AR1的GE0/0/1接口作为DIS,而且AR1与AR5之间的双向流量要求沿着AR3、AR4这条路径转发,可以通过cost和路由渗透进行选路控制
展开代码# AR1配置 [AR1]interface GigabitEthernet 0/0/1 [AR1-GigabitEthernet0/0/1]ip address 10.0.123.1 24 [AR1-GigabitEthernet0/0/1]q [AR1]interface LoopBack 0 [AR1-LoopBack0]ip address 10.0.1.1 32 [AR1-LoopBack0]q [AR1] # AR2配置 [AR2]interface GigabitEthernet 0/0/1 [AR2-GigabitEthernet0/0/1]ip address 10.0.123.2 24 [AR2-GigabitEthernet0/0/1]q [AR2]interface LoopBack 0 [AR2-LoopBack0]ip address 10.0.2.2 32 [AR2-LoopBack0]q [AR2]interface GigabitEthernet 0/0/2 [AR2-GigabitEthernet0/0/2]ip address 10.0.24.2 24 [AR2-GigabitEthernet0/0/2]q # AR3配置 [AR3]interface GigabitEthernet 0/0/1 [AR3-GigabitEthernet0/0/1]ip address 10.0.123.3 24 [AR3-GigabitEthernet0/0/1]q [AR3]interface GigabitEthernet 0/0/2 [AR3-GigabitEthernet0/0/2]ip address 10.0.34.3 24 [AR3-GigabitEthernet0/0/2]q [AR3]interface LoopBack 0 [AR3-LoopBack0]ip address 10.0.3.3 32 [AR3-LoopBack0]q # AR4配置 [AR4]interface GigabitEthernet 0/0/1 [AR4-GigabitEthernet0/0/1]ip address 10.0.24.4 24 [AR4-GigabitEthernet0/0/1]q [AR4]interface GigabitEthernet 0/0/2 [AR4-GigabitEthernet0/0/2]ip address 10.0.34.4 24 [AR4-GigabitEthernet0/0/2]q [AR4]interface GigabitEthernet 0/0/0 [AR4-GigabitEthernet0/0/0]ip address 10.0.45.4 24 [AR4-GigabitEthernet0/0/0]q [AR4]interface LoopBack 0 [AR4-LoopBack0]ip address 10.0.4.4 32 [AR4-LoopBack0]q # AR5配置 [AR5]interface GigabitEthernet 0/0/0 [AR5-GigabitEthernet0/0/0]ip address 10.0.45.5 24 [AR5-GigabitEthernet0/0/0]q [AR5]interface LoopBack 0 [AR5-LoopBack0]ip address 10.0.5.5 32 [AR5-LoopBack0]q
检查连通性

展开代码# AR1配置 [AR1]isis 1 [AR1-isis-1]is-level level-1 [AR1-isis-1]network-entity 49.0001.0000.0000.0001.00 [AR1-isis-1]q [AR1]interface LoopBack 0 [AR1-LoopBack0]isis enable 1 [AR1-LoopBack0]q [AR1]interface GigabitEthernet 0/0/1 [AR1-GigabitEthernet0/0/1]isis enable 1 [AR5-GigabitEthernet0/0/0]isis authentication-mode md5 cipher ren123456 [AR1-GigabitEthernet0/0/1]q [AR1] # AR2配置 [AR2]isis 1 [AR2-isis-1]network-entity 49.0001.0000.0000.0002.00 [AR2-isis-1]q [AR2]interface LoopBack 0 [AR2-LoopBack0]isis enable 1 [AR2-LoopBack0]q [AR2]interface GigabitEthernet 0/0/1 [AR2-GigabitEthernet0/0/1]isis enable 1 [AR5-GigabitEthernet0/0/0]isis authentication-mode md5 cipher ren123456 [AR2-GigabitEthernet0/0/1]q [AR2]interface GigabitEthernet 0/0/2 [AR2-GigabitEthernet0/0/2]isis enable 1 [AR5-GigabitEthernet0/0/0]isis authentication-mode md5 cipher ren123456 [AR2-GigabitEthernet0/0/2]q [AR2] # AR3配置 [AR3]isis 1 [AR3-isis-1]network-entity 49.0001.0000.0000.0003.00 [AR3-isis-1]q [AR3]interface LoopBack 0 [AR3-LoopBack0]isis enable 1 [AR3-LoopBack0]q [AR3]interface GigabitEthernet 0/0/1 [AR3-GigabitEthernet0/0/1]isis enable 1 [AR5-GigabitEthernet0/0/0]isis authentication-mode md5 cipher ren123456 [AR3-GigabitEthernet0/0/1]q [AR3]interface GigabitEthernet 0/0/2 [AR3-GigabitEthernet0/0/2]isis enable 1 [AR5-GigabitEthernet0/0/0]isis authentication-mode md5 cipher ren123456 [AR3-GigabitEthernet0/0/2]q [AR3] # AR4配置 [AR4]isis 1 [AR4-isis-1]is-level level-2 [AR4-isis-1]network-entity 49.0002.0000.0000.0004.00 [AR4-isis-1]q [AR4]interface LoopBack 0 [AR4-LoopBack0]isis enable 1 [AR4-LoopBack0]q [AR4]interface GigabitEthernet 0/0/0 [AR4-GigabitEthernet0/0/0]isis enable 1 [AR5-GigabitEthernet0/0/0]isis authentication-mode md5 cipher ren123456 [AR4-GigabitEthernet0/0/0]q [AR4]interface GigabitEthernet 0/0/1 [AR4-GigabitEthernet0/0/1]isis enable 1 [AR5-GigabitEthernet0/0/0]isis authentication-mode md5 cipher ren123456 [AR4-GigabitEthernet0/0/1]q [AR4]interface GigabitEthernet 0/0/2 [AR4-GigabitEthernet0/0/2]isis enable 1 [AR5-GigabitEthernet0/0/0]isis authentication-mode md5 cipher ren123456 [AR4-GigabitEthernet0/0/2]q [AR4] # AR5配置 [AR5]isis 1 [AR5-isis-1]is-level level-2 [AR5-isis-1]network-entity 49.0002.0000.0000.0005.00 [AR5-isis-1]q [AR5]interface LoopBack 0 [AR5-LoopBack0]isis enable 1 [AR5-LoopBack0]q [AR5]interface GigabitEthernet 0/0/0 [AR5-GigabitEthernet0/0/0]isis enable 1 [AR5-GigabitEthernet0/0/0]isis authentication-mode md5 cipher ren123456 [AR5-GigabitEthernet0/0/0]q [AR5]
查看AR1、AR4的IS-IS邻居
展开代码<AR1>display isis peer

AR1已经成功与AR2、AR3建立IS-IS邻居,并且是L1类型

AR4也与AR2、AR3、AR5建立IS-IS邻居,并且是L2类型
在L2路由器AR4上查看IS-IS路由表
展开代码<AR1>display isis route

L2路由器AR4学习到整网的路由,并且前往10.0.123.0/24、10.0.1.1/32的路由已经是负载均衡的一个状态
AR1、AR2、AR3是处于同一个广播网络,他们会选举出一个DIS,通过修改DIS优先级手动指定AR1的GE0/0/1作为DIS
修改AR1的GE0/0/1接口的优先级
展开代码[AR1]interface GigabitEthernet 0/0/1 [AR1-GigabitEthernet0/0/1]isis dis-priority 127
在AR1上查看IS-IS接口状态
展开代码<AR1>display isis interface

AR1的GE0/0/1接口成功变为DIS
在AR5上创建Loopback 1接口,配置IP地址为192.168.1.1 作为外部路由引入到IS-IS中
展开代码[AR5]interface LoopBack 1 [AR5-LoopBack1]ip address 192.168.1.1 32 [AR5-LoopBack1]q [AR5]isis 1 [AR5-isis-1]import-route direct [AR5-isis-1]q [AR5]
在AR5上查看IS-IS路由表
展开代码<AR5>display isis route

在L2的路由表发布表中可以引入的外部路由
在AR4上查看IS-IS路由192.168.1.1
展开代码<AR4>display isis route 192.168.1.1

AR4也学到了IS-IS路由192.168.1.1/32
在AR1上查看IS-IS路由表
展开代码<AR1>display isis route

在AR1的路由表上没有看到192.168.1.1/32的踪迹。这是因为AR1是L1路由器,默认情况下L1-2路由器不会向其传递L2路由,所以在AR1上没有看到引入的外部路由192.168.1.1/32,但AR1上存在前往骨干区域的默认路由,并且为负载均衡状态
在AR1测试与AR5的Loopback 1接口的连通性

AR1和AR5的Loopback 1接口正常通信
AR4前往AR1的流量在通过AR2、AR3时,进行负载分担,现在进行手工控制AR4前往AR1的流量经过AR2,所以在AR4上手动修改接口Cost
在AR4上查看IS-IS路由10.0.1.1/32
展开代码<AR4>display isis route 10.0.1.1

现在AR4前往AR1的Loopback 0接口为负载分担,其下一跳为10.0.34.3、10.0.24.2
修改AR4的GE0/0/2接口的IS-IS的Cost值
展开代码[AR4]interface GigabitEthernet 0/0/2 [AR4-GigabitEthernet0/0/2]isis cost 15 [AR4-GigabitEthernet0/0/2]q [AR4]
再次在AR4上查看IS-IS路由10.0.1.1/32
展开代码<AR1>display isis route 10.0.1.1

现在AR4前往AR1的Loopback 0接口只存在一个下一跳,就是10.0.24.2
由于缺省时AR1并不知道到达L2区域的具体路由,仅仅通过L1-2路由器发布的缺省路由到达L2区域,所以当前AR1只能选择AR2及AR3作为等价的下一跳设备到达L2区域。为了将AR1发往AR5的流量引导到AR3的进行转发,可以在AR3上配置路由渗透,将到达L2区域的路由渗透到L1区域,使得AR1能够通过IS-IS学习到相关路由
在AR1的IP路由表中查看AR5的Loopback 0接口路由
展开代码<AR1>display ip routing-table 10.0.5.5

AR1到10.0.5.5是通过AR2、AR3的负载均衡
在AR3上配置路由渗透
展开代码[AR3]isis 1 [AR3-isis-1]import-route isis level-2 into level-1 [AR3-isis-1]q [AR3]
再次在AR1的IP路由表上查看AR5的Loopback 0接口路由
展开代码<AR1>display ip routing-table 10.0.5.5

现在AR1到10.0.5.5的路由下一跳为10.0.123.3,就是AR3,并且是明细路由而不是默认路由!
本文作者:zzz
本文链接:
版权声明:本博客所有文章除特别声明外,均采用 BY-NC-SA 许可协议。转载请注明出处!