H3C ISIS

NET地址轉換:

假設一臺路由器使用接口LoopBack0的IP地址168.10.1.1作爲Router_ID,則它在IS-IS使用的System ID可通過如下方法轉換得到:

將IP地址168.10.1.1的每一部分都擴展爲3位,不足3位的在前面補0;將擴展後的地址168.010.001.001分爲3部分,每部分由4位數字組成;

重新組合的1680.1000.1001就是System ID


ISIS的簡單配置:

[R1]isis

[R1-isis-1]network-entity 86.0001.1111.1111.1111.00

[R1]int vlan 100

[R1-Vlan-interface100]isis enable

[R1-Vlan-interface100]int vlan 200

[R1-Vlan-interface200]isis enable

[R1-Vlan-interface200]int lo 0

[R1-LoopBack0]isis enable


修改接口的優先級:(手工指定DIS)

[R1]int vlan 100

[R1-Vlan-interface100]isis dis-priority 100

缺省情況下,接口上的優先級爲64。如果命令中不指定Level-1Level-2,則默認爲Level-1Level-2都設置


查看接口信息:

[R1-Vlan-interface100]dis isis interface

路由引入:

[RouterD] isis 1

[RouterD–isis-1] address-family ipv4

[RouterD–isis-1-ipv4] import-route rip level-2


修改路由器的角色:

[R2]isis 1

[R2-isis-1]is-level level-1

缺省情況下,路由器的類型爲level-1-2

注意:當路由器修改爲level-1路由器時,他不會再接收level-2的路由,本地會有一條缺省路由指向level-2路由器


路由***:

[R1]isis 1

[R1-isis-1]address-family ipv4

[R1-isis-1-ipv4]import-route isis level-2 into level-1

可以使level-1的路由器接收到level-2的路由


ISIS的認證:

[R1]int g0/1

[R1-GigabitEthernet0/1]isis authentication-mode md5 plain 123

區域認證:

[R1]isis 1

[R1-isis-1]area-authentication-mode md5 plain h3c


ISIS與BFD的聯動:(拓撲見QQ收藏)

[RouterA] bfd session init-mode active

[RouterA] interface gigabitethernet 2/1/1

[RouterA-GigabitEthernet2/1/1] isis bfd enable

[RouterA-GigabitEthernet2/1/1] bfd min-receive-interval 500

[RouterA-GigabitEthernet2/1/1] bfd min-transmit-interval 500

[RouterA-GigabitEthernet2/1/1] bfd detect-multiplier 7

[RouterB] bfd session init-mode active

[RouterB] interface gigabitethernet 2/1/1

[RouterB-GigabitEthernet2/1/1] isis bfd enable

[RouterB-GigabitEthernet2/1/1] bfd min-receive-interval 500

[RouterB-GigabitEthernet2/1/1] bfd min-transmit-interval 500

[RouterB-GigabitEthernet2/1/1] bfd detect-multiplier 8


ISIS的GE:(平滑重啓)

[R1]isis 1

[R1-isis-1]graceful-restart

[R1-isis-1]graceful-restart t2 100 重啓間隔,默認爲300s

<R1>dis isis graceful-restart status


引入外部路由:

[R3]isis 1

[R3-isis-1]address-family ipv4

[R3-isis-1-ipv4]import-route rip level-2

[R3-rip-1]import-route isis allow-direct 沒有這條命令本地路由不會重分發出去

缺省情況引入的路由類型爲level-2


路由過濾:

[R1]acl basic 2000

[R1-acl-ipv4-basic-2000]rule deny source 4.4.4.4 0

[R1-acl-ipv4-basic-2000]rule permit source any

[R1-acl-ipv4-basic-2000]quit

[R1]isis

[R1-isis-1]address-family ipv4

[R1-isis-1-ipv4]filter-policy 2000 import


路由聚合:

[R1]isis

[R1-isis-1]address-family ipv4

[R1-isis-1-ipv4]summary 192.168.8.0 22 level-1-2


缺省路由配置:

[R1]isis

[R1-isis-1]address-family ipv4

[R1-isis-1-ipv4]default-route-advertise  

Level-1的缺省路由不需要配置,Level-2的缺省路由需要手工配置


修改管理距離:

[R1]isis 1

[R1-isis-1]address-family ipv4

[R1-isis-1-ipv4]preference 20   該命令只對路由器本地有效,不影響其他路由器

缺省情況下,IS-IS路由的優先級爲15


修改路由的cost值:

[R1-isis-1]int g0/1

[R1-GigabitEthernet0/1]isis cost 13   默認下不指定類型修改的是level-1

缺省情況下,IS-IS在接口上的路由權值爲10


修改發送hello的時間:

[R1]int g0/0

[R1-GigabitEthernet0/0]isis timer hello 15

缺省情況下,接口上Hello報文的發送間隔時間爲10


<R1>reset isis peer 2222.2222.2222 1  清除指定鄰居

<R1>reset isis all  清除所有

<R1>dis isis route  查看路由

<R1>dis isis peer   查看鄰居

<R1>dis isis lsdb   查看數據庫







發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章