5.4 基于路由协议的双机热备

图片[1]-5.4 基于路由协议的双机热备-大赛人网

1.R1配置

ospf 1 router-id 1.1.1.1 
 area 0 
interface GigabitEthernet0/0/0
 ip address 10.2.0.2 255.255.255.0 
 ospf enable 1 area 0

interface GigabitEthernet0/0/1
 ip address 10.20.0.1 255.255.255.0 
 ospf enable 1 area 0

interface GigabitEthernet0/0/2
 ip address 10.1.0.254 255.255.255.0 
 ospf enable 1 area 0

2.R2配置

ospf 1 router-id 2.2.2.2 
 area 0 

interface GigabitEthernet0/0/0
 ip address 10.2.1.2 255.255.255.0 
 ospf enable 1 area 0

interface GigabitEthernet0/0/1
 ip address 10.20.0.2 255.255.255.0 
 ospf enable 1 area 0

interface GigabitEthernet0/0/2
 ip address 10.1.1.254 255.255.255.0 
 ospf enable 1 area 0

3.R3配置

ospf 1 router-id 3.3.3.3 
 area 0 
interface GigabitEthernet0/0/0
 ip address 10.3.0.2 255.255.255.0 
 ospf enable 1 area 0

interface GigabitEthernet0/0/1
 ip address 10.4.0.3 255.255.255.0 
 ospf enable 1 area 0

4.R4配置

ospf 1 router-id 4.4.4.4 
 area 0 

interface GigabitEthernet0/0/0
 ip address 10.3.1.2 255.255.255.0 
 ospf enable 1 area 0

interface GigabitEthernet0/0/1
 ip address 10.4.1.4 255.255.255.0 
 ospf enable 1 area 0

5.R5配置

ospf 1 router-id 5.5.5.5 
 area 0 

interface GigabitEthernet0/0/1
 ip address 10.4.0.5 255.255.255.0 
 ospf enable 1 area 0

interface GigabitEthernet0/0/2
 ip address 10.4.1.5 255.255.255.0 
 ospf enable 1 area 0

interface LoopBack0
 ip address 5.5.5.5 255.255.255.255 
 ospf enable 1 area 0.0.0.0

6.FW1配置

firewall zone trust
 add interface GigabitEthernet1/0/1

firewall zone untrust
 add interface GigabitEthernet1/0/2

firewall zone dmz
 add interface GigabitEthernet1/0/6

ospf 1 router-id 6.6.6.6 
 area 0 

interface GigabitEthernet1/0/1
 ip address 10.2.0.1 255.255.255.0
 ospf enable 1 area 0.0.0.0
 service-manage all permit

interface GigabitEthernet1/0/2
 ip address 10.3.0.1 255.255.255.0
 ospf enable 1 area 0
 service-manage all permit

#开启双机热备链路监控
hrp track interface GigabitEthernet 1/0/1
hrp track interface GigabitEthernet 1/0/2

#设置OSPF双机热备开销自动调整
hrp adjust ospf-cost enable

#开启设置双机热备
hrp enable
hrp interface GigabitEthernet 1/0/6 remote 10.10.0.2

security-policy
 rule name t_2_un
  source-zone trust
  destination-zone untrust
  source-address 10.1.0.0 mask 255.255.255.0
  source-address 10.1.1.0 mask 255.255.255.0
  destination-address 5.5.5.5 mask 255.255.255.255
  action permit

7.FW2配置

firewall zone trust
 add interface GigabitEthernet1/0/1

firewall zone untrust
 add interface GigabitEthernet1/0/2

firewall zone dmz
 add interface GigabitEthernet1/0/6

ospf 1 router-id 7.7.7.7 
 area 0 

interface GigabitEthernet1/0/1
 ip address 10.2.1.1 255.255.255.0
 ospf enable 1 area 0
 service-manage all permit

interface GigabitEthernet1/0/2
 ip address 10.3.1.1 255.255.255.0
 ospf enable 1 area 0
 service-manage all permit

#开启双机热备链路监控
hrp track interface GigabitEthernet 1/0/1
hrp track interface GigabitEthernet 1/0/2

#设置OSPF双机热备开销自动调整
hrp adjust ospf-cost enable

#开启设置双机热备
hrp enable
hrp interface GigabitEthernet 1/0/6 remote 10.10.0.1
#设置FW2为备设备
hrp standby-device

display ospf lsdb
 Type      LinkState ID    AdvRouter          Age  Len   Sequence   Metric
 Router    7.7.7.7         7.7.7.7            638  48    80000023    65500
 Router    6.6.6.6         6.6.6.6            650  48    8000000A       1

8.R1查看路由

dis ip routing-table
 5.5.5.5/32  OSPF    10   3           D   10.2.0.1        GigabitEthernet0/0/0

9.R2查看路由

 5.5.5.5/32  OSPF    10   4           D   10.20.0.1       GigabitEthernet0/0/1
© 版权声明
THE END
喜欢就支持一下吧
点赞10 分享
评论 抢沙发
头像
欢迎您留下宝贵的见解!
提交
头像

昵称

取消
昵称

    请登录后查看评论内容