9.2 路由过滤

图片[1]-9.2 路由过滤-大赛人网
图9-2路由过滤网络拓扑

1.R1配置ISIS

[R1]isis 1
[R1-isis-1]network-entity 49.0001.0000.0000.1111.00
[R1]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]isis enable 1
[R1]interface Serial 1/0/0 
[R1-Serial1/0/0]isis enable 1
[R1]interface LoopBack 0
[R1-LoopBack0]isis enable 1

2.R2配置ISIS

[R2]isis 1
[R2-isis-1]network-entity 49.0001.0000.0000.2222.00
[R2]interface LoopBack 0
[R2-LoopBack0]isis enable 1
[R2]interface GigabitEthernet 0/0/0
[R2-GigabitEthernet0/0/0]isis enable 1
[R2]interface Serial 1/0/0
[R2-Serial1/0/0]isis enable 1

3.R3配置ISIS

[R3]isis 1
[R3]interface LoopBack 0
[R3-LoopBack0]isis enable 1
[R3]interface GigabitEthernet 0/0/0
[R3-GigabitEthernet0/0/0]isis enable 1
[R3]interface GigabitEthernet 0/0/2
[R3-GigabitEthernet0/0/2]isis enable 1

4.R4配置ISIS

[R4]isis 1
[R4-isis-1]network-entity 49.0001.0000.0000.4444.00
[R4]interface LoopBack 0
[R4-LoopBack0]isis enable 1
[R4]interface GigabitEthernet 0/0/0
[R4-GigabitEthernet0/0/0]isis enable 1
[R4]interface GigabitEthernet 0/0/1
[R4-GigabitEthernet0/0/1]isis enable 1

5.R5配置ISIS

[R5]isis 1
[R5-isis-1]network-entity 49.0002.0000.0000.5555.00
[R5]interface LoopBack 0
[R5-LoopBack0]isis enable 1
[R5]interface GigabitEthernet 0/0/0
[R5-GigabitEthernet0/0/0]isis enable 1
[R5]interface GigabitEthernet 0/0/1
[R5-GigabitEthernet0/0/1]isis enable 1
[R5]interface GigabitEthernet 0/0/2
[R5-GigabitEthernet0/0/2]isis enable 1

6.R6配置ISIS

[R6]isis 1
[R6-isis-1]network-entity 49.0003.0000.0000.6666.00
[R6]interface LoopBack 0
[R6-LoopBack0]isis e
[R6-LoopBack0]isis enable 1
[R6-LoopBack0]quit
[R6]int
[R6]interface g
[R6]interface GigabitEthernet 0/0/0
[R6-GigabitEthernet0/0/0]isis enable 1
[R6]interface GigabitEthernet 0/0/1
[R6-GigabitEthernet0/0/1]isis enable 1
[R6]interface LoopBack 0
[R6-LoopBack0]isis enable 1

7.R7配置ISIS

[R7]isis 1
[R7-isis-1]network-entity 49.0003.0000.0000.7777.00
[R7]interface LoopBack 0
[R7-LoopBack0]isis enable 1
[R7]interface GigabitEthernet 0/0/1
[R7-GigabitEthernet0/0/1]isis enable 1

8.R6查看路由

<R6>display ip routing-table protocol isis
  1.1.1.1/32  ISIS-L2 15   30          D   56.1.1.5        GigabitEthernet0/0/0
        2.2.2.2/32  ISIS-L2 15   30          D   56.1.1.5        GigabitEthernet0/0/0
        3.3.3.3/32  ISIS-L2 15   20          D   56.1.1.5        GigabitEthernet0/0/0
        4.4.4.4/32  ISIS-L2 15   20          D   56.1.1.5        GigabitEthernet0/0/0
        5.5.5.5/32  ISIS-L2 15   10          D   56.1.1.5        GigabitEthernet0/0/0
        7.7.7.7/32  ISIS-L1 15   10          D   67.1.1.7        GigabitEthernet0/0/1
       12.1.1.0/30  ISIS-L2 15   40          D   56.1.1.5        GigabitEthernet0/0/0
       13.0.0.0/8   ISIS-L2 15   30          D   56.1.1.5        GigabitEthernet0/0/0
       24.0.0.0/8   ISIS-L2 15   30          D   56.1.1.5        GigabitEthernet0/0/0
       35.0.0.0/8   ISIS-L2 15   20          D   56.1.1.5        GigabitEthernet0/0/0
       45.0.0.0/8   ISIS-L2 15   20          D   56.1.1.5        GigabitEthernet0/0/0

9.R5 ISIS引入直连路由

[R5]isis 1
[R5-isis-1] import-route direct

10.R6查看路由(R5两条直连路由被引入)

<R6>display ip routing-table protocol isis
 5.5.1.1/32  ISIS-L2 15   74          D   56.1.1.5        GigabitEthernet0/0/0
        5.5.2.1/32  ISIS-L2 15   74          D   56.1.1.5        GigabitEthernet0/0/0

11.方法1:利用ACL匹配路由,用filter-policy过滤一条路由

[R5]acl 2000
[R5-acl-basic-2000]rule permit source 5.5.1.1 0
[R5]isis 1
[R5-isis-1]filter-policy 2000 export 

12.R6查看路由

<R6>display ip routing-table protocol isis
  5.5.1.1/32  ISIS-L2 15   74          D   56.1.1.5        GigabitEthernet0/0/0

13.方法2:利用ip-prefix匹配路由,利用filter-policy过滤一条路由

[R5-isis-1]undo filter-policy 2000 export
[R5]ip ip-prefix dsrw index 10 permit 5.5.2.1 32
[R5-isis-1]filter-policy ip-prefix dsrw export 

14.R6查看路由

<R6>display ip routing-table protocol isis
 5.5.2.1/32  ISIS-L2 15   74          D   56.1.1.5        GigabitEthernet0/0/0

15.方法3:利用利用ACL匹配路由,利用router-policy过滤一条路由

[R5-isis-1]undo filter-policy ip-prefix dsrw export
[R5]acl 2001
[R5-acl-basic-2001]rule permit source 5.5.1.1 0
[R5]route-policy dsrw permit node 10 
[R5-route-policy]if-match acl 2001
[R5-isis-1]undo import-route  direct 
[R5-isis-1]import-route direct route-policy dsrw
//route-policy缺省是不允许所有
//filter-policy匹配route-policy只能用作于路由入向

16.R6查看路由

<R6>display ip routing-table protocol isis
 5.5.1.1/32  ISIS-L2 15   74          D   56.1.1.5        GigabitEthernet0/0/0

17.R2配置OSPF,引入ISIS

[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]are
[R2-ospf-1]area 0
[R2-ospf-1-area-0.0.0.0]network 2.2.1.1 0.0.0.0
[R2]isis 1
[R2-isis-1]import-route ospf 1
© 版权声明
THE END
喜欢就支持一下吧
点赞11 分享
评论 抢沙发
头像
欢迎您留下宝贵的见解!
提交
头像

昵称

取消
昵称

    请登录后查看评论内容