發表於:2007-3-13 14:20
7.1. 配置EIGRP 提問 ONT-FAMILY: 宋體">配置網絡使用EIGRP路由協議 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#interface Ethernet0 Router1(config-if)#ip address 192.168.20.1 255.255.255.0 Router1(config-if)#exit Router1(config)#interface Serial0.1 point-to-point Router1(config-subif)#ip address 172.25.2.2 255.255.255.252 Router1(config-subif)#exit Router1(config)#router eigrp 55 Router1(config-router)#network 172.25.0.0 Router1(config-router)#network 192.168.20.0 Router1(config-router)#exit Router1(config)#end Router1# 註釋 要確保啓用此路由協議的所有路由器配置的EIGRP後面的進程號相同,可以使用show ip eigrp neighbors 來驗證鄰居關係。同時支持network 192.168.20.0 0.0.0.255 來定義發佈的網絡
7.2. 路由過濾 提問 對EIGRP學到或者宣告的路由進行過濾 回答 入方向過濾 Router2#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router2(config)#access-list 34 deny 192.168.30.0 Router2(config)#access-list 34 permit any Router2(config)#router eigrp 55 Router2(config-router)#distribute-list 34 in Serial0.1 Router2(config-router)#exit Router2(config)#end Router2# 出方向過濾 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#access-list 57 permit 172.25.1.0 Router1(config)#access-list 57 deny any Router1(config)#router eigrp 55 Router1(config-router)#distribute-list 57 out Serial0/0.2 Router1(config-router)#exit Router1(config)#end Router1# 使用prefix方式過濾,並且支持gateway 選項 Router9#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router9(config)#ip prefix-list ALLOWED-PREFIXES permit 10.0.0.0/8 le 32 Router9(config)#ip prefix-list ALLOWED-PREFIXES deny 0.0.0.0/0 le 32 Router9(config)#ip prefix-list ALLOWED-NEIGHBORS permit 172.18.19.1/32 Router9(config)#ip prefix-list ALLOWED-NEIGHBORS permit 172.18.19.4/32 Router9(config)#ip prefix-list ALLOWED-NEIGHBORS deny 0.0.0.0/0 le 32 Router9(config)#router eigrp 55 Router9(config-router)#distribute-list prefix ALLOWED-PREFIXES gateway ALLOWED-NEIGHBORS in Router9(config-router)#exit Router9(config)#end Router9#
註釋 在路由過濾時推薦使用prefix方式而不用ACL形式。Gateway參數只能用於入方向控制,同時建議不用和interface混和使用 7.3. 再發布路由到EIGRP 提問 再發布其他方式學到的路由到EIGRP路由進程 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#router eigrp 55 Router1(config-router)#redistribute rip Router1(config-router)#default-metric 1000 100 250 100 1500 Router1(config-router)#exit Router1(config)#end Router1# 註釋 如果再發布的是靜態路由可以不用配置default-metric命令,對於其他協議都必須配置此命令否則無法成功再發布。再發布之前也可以使用過濾列表進行路由過濾,從而只再發佈特定路由 Router1(config)#router eigrp 55 Router1(config-router)#redistribute ospf 99 Router1(config-router)#distribute-list 7 out ospf 99 7.4. 使用Route Map方式來配置再發布 提問 使用控制粒度更好的Route Map方式來配置再發布 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#ip route 192.168.10.0 255.255.255.0 172.22.1.4 Router1(config)#ip route 192.168.11.0 255.255.255.0 172.22.1.4 Router1(config)#ip route 192.168.12.0 255.255.255.0 172.22.1.4 Router1(config)#access-list 20 permit 192.168.10.0 Router1(config)#access-list 21 permit 192.168.11.0 Router1(config)#route-map STATIC permit 10 Router1(config-route-map)#match ip address 20 Router1(config-route-map)#set metric 56 100 255 1 1500 Router1(config-route-map)#set tag 2 Router1(config-route-map)#exit Router1(config)#route-map STATIC permit 20 Router1(config-route-map)#match ip address 21 Router1(config-route-map)#set metric 128 200 255 1 1500 Router1(config-route-map)#exit Router1(config)#route-map STATIC deny 30 Router1(config-route-map)#exit Router1(config)#router eigrp 55 Router1(config-router)#redistribute static route-map STATIC Router1(config-router)#exit Router1(config)#end Router1# 註釋 此處配置和前面6.3的配置差不多,唯一需要注意的就是前面提到的必須要加上metric的設置 7.5. 特定接口禁止EIGRP 提問 禁止某個端口參與EIGRP 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#router eigrp 55 Router1(config-router)#passive-interface Serial0/1 Router1(config-router)#exit Router1(config)#end Router1# 註釋 這裏的被動接口和RIP不同,由於結果是不能形成鄰居在此接口所以使用該命令以後就不能發送也不能接收路由信息 7.6. 調整EIGRP度量值 提問 修改學到的EIGRP路由器度量值 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#access-list 22 permit 192.168.30.0 Router1(config)#access-list 33 permit 192.168.30.0 Router1(config)#router eigrp 55 Router1(config-router)#offset-list 33 out 10000 Serial0.1 Router1(config-router)#offset-list 22 in 10000 Serial0.1 Router1(config-router)#exit Router1(config)#end Router1#
註釋
7.7. 定時器調整 提問 調整定時器優化收斂 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#interface Serial0.1 Router1(config-subif)#ip hello-interval eigrp 55 3 Router1(config-subif)#ip hold-time eigrp 55 9 Router1(config-subif)#exit Router1(config)#end Router1# 註釋 EIGRP的一個特性就是定時器的調整可以基於端口,並且不用保持整個網絡中所有設備的定時器設置一致,各個定時器都是獨立的 7.8. 啓用EIGRP認證 提問 增強路由信息安全性 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#key chain ORA Router1(config-keychain)#key 1 Router1(config-keychain-key)#key-string oreilly Router1(config-keychain-key)#exit Router1(config-keychain)#exit Router1(config)#interface Serial0/1 Router1(config-if)#ip authentication mode eigrp 55 md5 Router1(config-if)#ip authentication key-chain eigrp 55 ORA Router1(config-if)#exit Router1(config)#end Router1# 註釋 注意這裏只是認證不是加密路由信息包。下面提供一種更改key方法,幫助網絡平穩過渡到新的key Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#key chain Mars Router1(config-keychain)#key 1 Router1(config-keychain-key)#key-string rocket Router1(config-keychain-key)#accept-lifetime 00:00:00 Jan 1 1993 00:15:00 Nov 1 2006 Router1(config-keychain-key)#send-lifetime 00:00:00 Jan 1 1993 00:00:00 Nov 1 2006 Router1(config-keychain-key)#key 2 Router1(config-keychain-key)#key-string martian Router1(config-keychain-key)#accept-lifetime 23:45:00 Oct 31 2006 infinite Router1(config-keychain-key)#send-lifetime 00:00:00 Nov 1 2006 infinite Router1(config-keychain-key)#end Router1# 7.9. 配置EIGRP路由彙總 提問 通過路由彙總來減少路由表大小和增強穩定性 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#interface Serial0/0.2 Router1(config-subif)#ip summary-address eigrp 55 172.25.0.0 255.255.0.0 Router1(config-subif)#exit Router1(config)#end Router1# 缺省會自動路由彙總,使用no auto-summary關閉(12.2(8)T後自動關閉) 同時可以配置彙總路由的同時,宣告部分子網路由 Router9# configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router9(config)#ip prefix-list 10.5.5/24 permit 10.5.5.0/24 Router9(config)#route-map LEAK10-5-5 permit 10 Router9(config-route-map)#match ip address prefix-list 10.5.5/24 Router9(config-route-map)#exit Router9(config)#interface Serial0/0 Router9(config-if)#ip summary-address eigrp 55 10.5.0.0 255.255.0.0 leak-map LEAK10-5-5 Router9(config-if)#exit Router9(config)#end Router9# 註釋 路由彙總也是EIGRP的特性之一,可以配置在任意路由器的接口進行彙總,不象OSPF那樣只能在ABR彙總。彙總路由的度量值和所彙總路由中的最好的子網路由的度量值一致。Leakmap特性在12.3(14)T後引入,可以在彙總路由的同時發佈某些更匹配的路由 7.10. 記錄鄰居狀態變化 提問 記錄鄰居狀態變化 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#router eigrp 55 Router1(config-router)#eigrp log-neighbor-changes Router1(config-router)#exit Router1(config)#end Router1# 註釋 缺省開啓 7.11. 限制EIGRP路由更新佔用帶寬 提問 限制EIGRP路由更新佔用帶寬的百分比 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#interface Serial0.1 Router1(config-subif)#ip bandwidth-percent eigrp 55 40 Router1(config-subif)#exit Router1(config)#end Router1# 註釋 這裏的百分比可以大於100%,當我們人爲的設定了某端口帶寬用於計算度量值時 7.12. EIGRP Stub路由 提問 向邊緣網絡發佈較小的路由表 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#router eigrp 55 Router1(config-router)#eigrp stub Router1(config-router)#exit Router1(config)#end Router1# 註釋 7.13. 路由標籤 提問 通過對特定路由進行標籤,防止再分發時出現路由迴環 回答 Router1#configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router1(config)#ip route 0.0.0.0 0.0.0.0 172.25.1.1 Router1(config)#access-list 7 permit 0.0.0.0 Router1(config)#route-map TAGGING permit 10 Router1(config-route-map)#match ip address 7 Router1(config-route-map)#set tag 5 Router1(config-route-map)#exit Router1(config)#router eigrp 55 Router1(config-router)#redistribute static route-map TAGGING Router1(config-router)#exit Router1(config)#end Router1# 註釋 7.14. 查看EIGRP狀態 提問 查看狀態命令 回答 Router1#show ip protocols Router1#show ip route eigrp Router1#show ip eigrp neighbors Router1#show ip eigrp interfaces Router9#show ip eigrp accounting Router1#show ip eigrp topology
註釋 12.3(14)T引入了show ip eigrp accounting Router9#show ip eigrp accounting IP-EIGRP accounting for AS(55)/ID(172.18.5.9) Total Prefix Count: 50 States: A-Adjacency, P-Pending, D-Down State Address/Source Interface Prefix Restart Restart/ Count Count Reset(s) A 172.20.10.1 Se0/0 1 0 0 A 172.18.19.1 Fa0/0 39 0 0 A 172.18.19.4 Fa0/0 1 0 0 A 172.18.19.6 Fa0/0 6 0 0 Router9# Router1#show ip eigrp topology IP-EIGRP Topology Table for AS(55)/ID(172.25.25.1)
Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply, r - reply Status, s - sia Status
P 0.0.0.0/0, 1 successors, FD is 28160, tag is 5 via Rstatic (28160/0) via Summary (28160/0), Null0 P 10.2.2.0/24, 1 successors, FD is 156160 via 172.22.1.4 (156160/128256), FastEthernet0/1 P 10.1.1.0/30, 1 successors, FD is 3845120 via Connected, Serial0/1 P 192.168.10.0/24, 1 successors, FD is 28160, tag is 5 via Rstatic (28160/0) P 192.168.30.0/24, 1 successors, FD is 156160 via 172.22.1.4 (156160/128256), FastEthernet0/1 P 192.168.20.0/24, 1 successors, FD is 2195456 via 172.25.2.2 (2195456/281600), Serial0/0.2 P 172.25.25.6/32, 1 successors, FD is 156160 via 172.25.1.7 (156160/128256), FastEthernet0/0.1 P 172.25.25.1/32, 1 successors, FD is 128256 via Connected, Loopback0 P 172.25.25.2/32, 1 successors, FD is 2297856 via 172.25.2.2 (2297856/128256), Serial0/0.2 P 172.25.1.0/24, 1 successors, FD is 28160 via Connected, FastEthernet0/0.1 P 172.25.2.0/30, 1 successors, FD is 2169856 via Connected, Serial0/0.2 P 172.22.1.0/24, 1 successors, FD is 28160 via Connected, FastEthernet0/1 Router1#
|