1、网络拓扑图
2、next-hop属性
若某AS的边界路由器从EBGP对等体所接收到一条路由,则该边界路由器不会将本条路由转发至自身所属的AS中,该边界路由器将使用下一跳属性向本AS内部的其他路由器进行宣告,让其他的本AS内的路由器以这台边界路由器为下一跳。
3、核心配置命令
1)基础配置
sysname xxx
//aaa认证
aaa
local-user xxx password cipher xxxxxx
local-user xxx service-type ssh telnet http
local-user xxx privilege level 0-15
//console 设置登录
user-interface console 0
authentication password
xxxxxxx
2)igp路由配置
ospf 100 router-id xxx.xxx.xxx.xxx
area 0
接口启用ospf
int g0/0/0
ospf enable 100 area 0
3)bgp路由配置
bgp 100
router-id 2.2.2.2
peer xxx.xxx.xxx.xxx as 100 //对内
peer xxx.xxx.xxx.xxx connect-interface LoopBack0 //环回口
peer xxx.xxx.xxx.xxx next-hop-local
ipv4-family unicast
peer xxx.xxx.xxx.xxx enable
4、详细配置
<r2>display current-configuration
[V200R003C00]
#
sysname r2
#
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
#
clock timezone China-Standard-Time minus 08:00:00
#
portal local-server load portalpage.zip
#
drop illegal-mac alarm
#
set cpu-usage threshold 80 restore 75
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user yhs password cipher %$%$_SF,Vaj(F-bG{j%3wZ2IcN1M%$%$
local-user yhs privilege level 15
local-user yhs service-type terminal ssh http
local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-user admin service-type http
#
firewall zone Local
priority 15
#
interface GigabitEthernet0/0/0
ip address 20.1.1.2 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 40.1.1.1 255.255.255.0
ospf enable 100 area 0.0.0.0
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
interface LoopBack0
ip address 2.2.2.2 255.255.255.255
ospf enable 100 area 0.0.0.0
#
bgp 200
router-id 2.2.2.2
peer 3.3.3.3 as-number 200
peer 3.3.3.3 connect-interface LoopBack0
peer 4.4.4.4 as-number 200
peer 4.4.4.4 connect-interface LoopBack0
peer 20.1.1.1 as-number 100
peer 20.1.1.1 connect-interface GigabitEthernet0/0/0
#
ipv4-family unicast
undo synchronization
peer 3.3.3.3 enable
peer 3.3.3.3 next-hop-local
peer 4.4.4.4 enable
peer 4.4.4.4 next-hop-local
peer 20.1.1.1 enable
#
ospf 100 router-id 2.2.2.2
area 0.0.0.0
#
user-interface con 0
authentication-mode password
set authentication password cipher %$%$cl/O$Lz+-#CEdB!8#S_X,/<5'2.:V(<ziD=Z_`UR
Cc+#/<8,%$%$
idle-timeout 0 0
user-interface vty 0 4
user-interface vty 16 20
#
wlan ac
#
return
<r2>