CCNP Lab Guide CCIE University

6,194 views

Published on

CCNP Lab Guide from CCIE University

Published in: Technology
1 Comment
2 Likes
Statistics
Notes
  • شكرا
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
No Downloads
Views
Total views
6,194
On SlideShare
0
From Embeds
0
Number of Embeds
13
Actions
Shares
0
Downloads
1,195
Comments
1
Likes
2
Embeds 0
No embeds

No notes for slide

CCNP Lab Guide CCIE University

  1. 1. www.ccieuniversity.comConfiguring Basic EIGRP Lab ............................................................................................................ 3Configuring Default-network for EIGRP Lab .................................................................................... 6Manually Summarizing EIGRP Routes Lab ..................................................................................... 11Configuring EIGRP Unequal Cost Paths Lab ................................................................................... 15Configuring EIGRP Authentication Lab .......................................................................................... 18Understand EIGRP Query Lab ........................................................................................................ 20Configuring Basic Multi Area OSPF and Area Summary Lab ......................................................... 28Configuring OSPF in NBMA Lab ..................................................................................................... 32Configuring OSPF Authentication Lab ........................................................................................... 37Configuring OSPF External Summary Lab ...................................................................................... 43Configuring OSPF Default Route With Metric Lab ......................................................................... 46Configuring OSPF Stub Area Lab .................................................................................................... 49Configuring OSPF Totally Stub Area Lab ........................................................................................ 53Configuring OSPF NSSA Area and NSSA Totally Stub Lab .............................................................. 56Configuring OSPF Virtual-Link between normal area and backbone area Lab ............................. 62Configuring OSPF Virtual-Link between 2 backbone areas Lab .................................................... 65Understand OSPF Routing Between Inter Area Lab ...................................................................... 68Configuring Basic IS-IS Lab ............................................................................................................. 70Configuring IS-IS Multi Area and Summary Route Lab .................................................................. 74Migrate IS-IS Area Lab ................................................................................................................... 78Redistributing into RIP and OSPF Lab ............................................................................................ 81Redistributing Between EIGRP and IS-IS Lab ................................................................................. 83Redistribution Using Administrative Distance Lab ........................................................................ 87Filtering Routing Updates with a Distribute List Lab ..................................................................... 89Filtering Routing Updates with a Route Map Lab ......................................................................... 91Using Route Tag Filtering Routing Updates Lab ............................................................................ 93Policy-based route Lab .................................................................................................................. 96Configuring Basic BGP Lab ............................................................................................................. 99Configuring BGP Using Loopback Addresses Lab ........................................................................ 101Understand BGP Auto-Summary Lab .......................................................................................... 103Configuring BGP Summarization Lab ........................................................................................... 106Understand BGP Split Horizon Rule Lab ...................................................................................... 108
  2. 2. www.ccieuniversity.comUnderstand BGP Synchronization Rule Lab ................................................................................. 111BGP Neighbor Authentication Lab............................................................................................... 114Configuring BGP Local Preference Lab ........................................................................................ 117Using Route Maps to Configuring BGP Local Preference Lab ..................................................... 121Configuring BGP Multi-Exit Discriminator Lab............................................................................. 124Configuring BGP Weight Lab ....................................................................................................... 128Affects the BGP Routing By Path Prepend Lab ............................................................................ 131Configuring BGP Routes Reflector Lab ........................................................................................ 134Configuring BGP Confederation Lab ............................................................................................ 135Using Route Tag to Store BGP AS-Path Lab ................................................................................. 139Using Distribute-list to Filtering BGP Routing Lab ....................................................................... 143Using Route-Map to Filtering BGP Routing Lab .......................................................................... 145Using Prefix-List to Filtering BGP Routing Lab ............................................................................. 146Configuring 802.1x Port-Based Authentication Lab .................................................................... 150Routing Between VLANs and VTP Protocol Lab .......................................................................... 154Configuring L2 & L3 EtherChannel with PAGP Lab ...................................................................... 163Configuring L2 & L3 EtherChannel with LACP Lab ....................................................................... 169Configuring Layer 3 Redundancy with HSRP Lab ......................................................................... 172Configuring Layer 3 Redundancy with VRRP Lab......................................................................... 179
  3. 3. www.ccieuniversity.com Configuring Basic EIGRP LabTopologyLab Purpose:1、Master EIGRP basic configuration.2、Master EIGRP wild card bits configuration.3、Master EIGRP auto summary feature, and learn how to disable auto summary.4、Master EIGRP manually summary.Lab Steps:1、Config IP address for each router.2、EIGRP AS number should be 50.3、Enable EIGRP for the 3 routers.R1#configure terminalR1(config-if)#router eigrp 50R1(config-router)#network 172.16.0.0R1(config-router)#network 10.1.1.0R1(config-router)#network 10.1.2.0R1(config-router)#network 10.1.3.0R1(config-router)#network 10.1.4.0R2#configure terminalR2(config-if)#router eigrp 50R2(config-router)#network 172.16.0.0R2(config-router)#network 131.131.0.0R3#configure terminalR3(config-if)#router eigrp 50R3(config-router)#network 172.16.0.0
  4. 4. www.ccieuniversity.comR3(config-router)#network 192.168.0.0R3(config-router)#network 192.168.1.0R3(config-router)#network 192.168.2.0R3(config-router)#network 192.168.3.04、Check the EIGRP neighbour relationship on R2.R2#show ip eigrp 50 neighborsIP-EIGRP neighbors for process 50H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num1 172.16.1.6 Se1/1 13 00:00:37 436 2616 0 20 172.16.1.1 Se1/0 13 00:02:34 736 4416 0 4TIPS: H stands for neighbor sequence number, address is the neighbor address, Interface is the localinterface which connect with neighbor.5、Check the routing table on R2.R2#show ip route 172.16.0.0/16 is variably subnetted, 3 subnets, 2 masksC 172.16.1.4/30 is directly connected, Serial1/1D 172.16.0.0/16 is a summary, 00:06:33, Null0C 172.16.1.0/30 is directly connected, Serial1/0D 192.168.4.0/24 [90/2297856] via 172.16.1.6, 00:04:39, Serial1/1D 10.0.0.0/8 [90/2297856] via 172.16.1.1, 00:06:34, Serial1/0C 131.131.0.0/16 is directly connected, Loopback0D 192.168.0.0/24 [90/2297856] via 172.16.1.6, 00:04:39, Serial1/1D 192.168.1.0/24 [90/2297856] via 172.16.1.6, 00:04:39, Serial1/1D 192.168.2.0/24 [90/2297856] via 172.16.1.6, 00:04:39, Serial1/1D 192.168.3.0/24 [90/2297856] via 172.16.1.6, 00:04:39, Serial1/16、 Check EIGRP routing table on R2.R2#show ip route eigrp 172.16.0.0/16 is variably subnetted, 3 subnets, 2 masksD 172.16.0.0/16 is a summary, 00:10:09, Null0D 192.168.4.0/24 [90/2297856] via 172.16.1.6, 00:08:14, Serial1/1D 10.0.0.0/8 [90/2297856] via 172.16.1.1, 00:10:10, Serial1/0D 192.168.0.0/24 [90/2297856] via 172.16.1.6, 00:08:14, Serial1/1D 192.168.1.0/24 [90/2297856] via 172.16.1.6, 00:08:14, Serial1/1D 192.168.2.0/24 [90/2297856] via 172.16.1.6, 00:08:14, Serial1/1D 192.168.3.0/24 [90/2297856] via 172.16.1.6, 00:08:14, Serial1/17、There is a summary route 10.0.0.0/8 via 172.16.1.1 on R2 by auto summary feature,we could use "no auto-summary" command to disable it.R1(config)R1(config)#router eigrp 50R1(config-router)#no auto-summaryR1(config-router)#exitThen check the eigrp route on R2 again.
  5. 5. www.ccieuniversity.comR2#show ip route eigrp 172.16.0.0/16 is variably subnetted, 3 subnets, 2 masksD 172.16.0.0/16 is a summary, 00:07:26, Null0D 192.168.4.0/24 [90/2297856] via 172.16.1.6, 00:05:09, Serial1/1 10.0.0.0/24 is subnetted, 4 subnetsD 10.1.3.0 [90/2297856] via 172.16.1.1, 00:02:31, Serial1/0D 10.1.2.0 [90/2297856] via 172.16.1.1, 00:02:31, Serial1/0D 10.1.1.0 [90/2297856] via 172.16.1.1, 00:02:31, Serial1/0D 10.1.4.0 [90/2297856] via 172.16.1.1, 00:02:31, Serial1/0D 192.168.0.0/24 [90/2297856] via 172.16.1.6, 00:05:09, Serial1/1D 192.168.1.0/24 [90/2297856] via 172.16.1.6, 00:05:09, Serial1/1D 192.168.2.0/24 [90/2297856] via 172.16.1.6, 00:05:09, Serial1/1D 192.168.3.0/24 [90/2297856] via 172.16.1.6, 00:05:09, Serial1/18、Manually summarize network 192.168.0.0/24 192.168.1.0/24 192.168.2.0/24192.168.3.0/24 to 1 item on R3.R3(config)#interface serail 1/0R3(config-if)#ip summary eigrp 50 192.168.0.0 255.255.252.0R3(config-if)#exit9、Check routing table on R2 again.R2#show ip route eigrp………D 10.1.1.0 [90/2297856] via 172.16.1.1, 00:02:31, Serial1/0D 10.1.4.0 [90/2297856] via 172.16.1.1, 00:02:31, Serial1/0D 192.168.0.0/22 [90/2297856] via 172.16.1.6, 00:05:09, Serial1/1………10、Use wild card bits on R2s EIGRP configuration.R2(config)#no router eigrp 50R2(config)#router eigrp 50R2(config-router)#network 172.16.1.0 0.0.0.3R2(config-router)#network 131.131.0.0R2(config-router)#exit11、This time there is only R1 in R2s neighbor table.R2#show ip eigrp neighborsIP-EIGRP neighbors for process 50H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num0 172.16.1.1 Se1/0 12 00:04:57 1510 5000 0 512、Check EIGRP routing table on R1.R1#show ip route eigrp 172.16.0.0/16 is variably subnetted, 2 subnets, 2 masksD 172.16.0.0/16 is a summary, 00:02:55, Null0
  6. 6. www.ccieuniversity.com 10.0.0.0/8 is variably subnetted, 5 subnets, 2 masksD 10.0.0.0/8 is a summary, 00:02:55, Null0D 131.131.0.0/16 [90/2297856] via 172.16.1.2, 00:00:06, Serial1/1By www.ccieuniversity.com Configuring Default-network for EIGRP LabTopologyLab Purpose:1、Learn to use "ip default-network" command instead of " ip route 0.0.0.0 0.0.0.0 " inEIGRP network.Lab Steps:1、Finish the basic ip address configuration on all the routers.2、Lets suppose R3 is the external router, so there is no EIGRP relationship between R2and R3. What we need is a default route to the internal network on R3.R3(config)#R3(config)#ip route 0.0.0.0 0.0.0.0 192.168.10.1R3(config)#3、Enable EIGRP 50 on the internal routers.R1(config)#router eigrp 50R1(config-router)#network 172.16.0.0R1(config-router)#exitR5(config)#router eigrp 50
  7. 7. www.ccieuniversity.comR5(config-router)#network 172.16.0.0R5(config-router)#exitR2(config)#router eigrp 50R2(config-router)#network 172.16.0.0R2(config-router)#exit4、Check EIGRP neighbor relationship on R2.R2#show ip eigrp neighborsIP-EIGRP neighbors for process 50H Address Interface Hold Uptime SRTT RTO Q Seq Type (sec) (ms) Cnt Num1 172.16.1.6 Et1/2 11 00:00:54 1 3000 0 20 172.16.1.1 Et1/0 12 00:00:54 1 3000 0 25、Add a default route on R2 to reach the external network.R2(config)#ip route 0.0.0.0 0.0.0.0 192.168.10.2R2(config)#R2#ping 192.168.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:.!!!!Success rate is 80 percent (4/5), round-trip min/avg/max = 4/43/92 msR2#6、R1 and R5 do not have route to external network, so they can not access externalnetwork.R1#show ip routeGateway of last resort is not set 172.16.0.0/30 is subnetted, 2 subnetsD 172.16.1.4 [90/284160] via 172.16.1.2, 00:06:40, FastEthernet0/1C 172.16.1.0 is directly connected, FastEthernet0/1R1#R1#ping 192.168.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:.....Success rate is 0 percent (0/5)R1#
  8. 8. www.ccieuniversity.comR5#show ip routeGateway of last resort is not set 172.16.0.0/30 is subnetted, 2 subnetsC 172.16.1.4 is directly connected, Ethernet1/1D 172.16.1.0 [90/307200] via 172.16.1.5, 00:12:15, Ethernet1/1R5#R5#ping 192.168.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:.....Success rate is 0 percent (0/5)R5#7、One solution is to add a default route with the next hop R2 on both R1 and R5 .R1(config)#ip route 0.0.0.0 0.0.0.0 172.16.1.2R1(config)#exitR1#show ip routeGateway of last resort is 172.16.1.2 to network 0.0.0.0 172.16.0.0/30 is subnetted, 2 subnetsD 172.16.1.4 [90/284160] via 172.16.1.2, 00:09:19, FastEthernet0/1C 172.16.1.0 is directly connected, FastEthernet0/1S* 0.0.0.0/0 [1/0] via 172.16.1.2R1#R1#ping 192.168.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 48/71/92 msR1#R5(config)#ip route 0.0.0.0 0.0.0.0 172.16.1.5R5(config)#exitR5#R5#show ip routeGateway of last resort is 172.16.1.5 to network 0.0.0.0 172.16.0.0/30 is subnetted, 2 subnetsC 172.16.1.4 is directly connected, Ethernet1/1
  9. 9. www.ccieuniversity.comD 172.16.1.0 [90/307200] via 172.16.1.5, 00:13:57, Ethernet1/1S* 0.0.0.0/0 [1/0] via 172.16.1.5R5#R5#ping 192.168.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 32/53/64 msR5#8、Another solution is to let R2 announce the external route to R1 and R5, this solutionis better for large internal network, as it gets less configuration work.9、So lets delete the default route on R1 and R5 first.R1(config)#no ip route 0.0.0.0 0.0.0.0 172.16.1.2R1(config)#exitR1#R1#show ip routeGateway of last resort is not set 172.16.0.0/30 is subnetted, 2 subnetsD 172.16.1.4 [90/284160] via 172.16.1.2, 00:19:02, FastEthernet0/1C 172.16.1.0 is directly connected, FastEthernet0/1R1#R1#ping 192.168.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:.....Success rate is 0 percent (0/5)R1#R5(config)#no ip route 0.0.0.0 0.0.0.0 172.16.1.5R5(config)#exitR5#R5#show ip routeGateway of last resort is not set 172.16.0.0/30 is subnetted, 2 subnetsC 172.16.1.4 is directly connected, Ethernet1/1D 172.16.1.0 [90/307200] via 172.16.1.5, 00:19:42, Ethernet1/1R5#
  10. 10. www.ccieuniversity.comR5#ping 192.168.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:.....Success rate is 0 percent (0/5)R5#10、Then lets R2 announce the external network 192.168.10.0 to R1 and R5.R2(config)#router eigrp 50R2(config-router)#network 192.168.10.0R2(config-router)#exitR2(config)#ip default-network 192.168.10.0R2(config)#exitR2#show ip routeGateway of last resort is 192.168.10.2 to network 0.0.0.0* 192.168.10.0/24 is variably subnetted, 2 subnets, 2 masksD* 192.168.10.0/24 is a summary, 00:00:53, Null0C 192.168.10.0/30 is directly connected, Ethernet1/1 172.16.0.0/16 is variably subnetted, 3 subnets, 2 masksC 172.16.1.4/30 is directly connected, Ethernet1/2D 172.16.0.0/16 is a summary, 00:22:22, Null0C 172.16.1.0/30 is directly connected, Ethernet1/0S* 0.0.0.0/0 [1/0] via 192.168.10.2R2#11、Check the routing table of R1 and R5 again, to make sure they have the externalroute.R1#show ip routeGateway of last resort is 172.16.1.2 to network 192.168.10.0D* 192.168.10.0/24 [90/284160] via 172.16.1.2, 00:02:03, FastEthernet0/1 172.16.0.0/30 is subnetted, 2 subnetsD 172.16.1.4 [90/284160] via 172.16.1.2, 00:02:04, FastEthernet0/1C 172.16.1.0 is directly connected, FastEthernet0/1R1#R1#ping 192.168.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 48/105/188 ms
  11. 11. www.ccieuniversity.comR1#R5#show ip routeGateway of last resort is 172.16.1.5 to network 192.168.10.0D* 192.168.10.0/24 [90/307200] via 172.16.1.5, 00:04:15, Ethernet1/1 172.16.0.0/30 is subnetted, 2 subnetsC 172.16.1.4 is directly connected, Ethernet1/1D 172.16.1.0 [90/307200] via 172.16.1.5, 00:04:19, Ethernet1/1R5#R5#ping 192.168.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 76/87/96 msBy www.ccieuniversity.com Manually Summarizing EIGRP Routes LabTopologyLab Purpose:1、Understand the weakness of EIGRP auto summarization.2、Master EIGRP manually summary configuration.
  12. 12. www.ccieuniversity.comLab Steps:1、Finish basic ip configuration.2、Enable EIGRP on all the routers, do not disable auto summary.3、Ping on R2 to R1s 10.1.X.0/24 network and R4s 10.1.X.0/24 network, you will findto R1 is good, but to R4 fails.R2#ping 10.1.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 1/46/92 msR2#ping 10.1.16.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.16.1, timeout is 2 seconds:U.U.USuccess rate is 0 percent (0/5)R2#R2#ping 10.1.17.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.17.1, timeout is 2 seconds:U.U.USuccess rate is 0 percent (0/5)4、Check the routing table of R2.R2#show ip routeGateway of last resort is not set 172.16.0.0/30 is subnetted, 3 subnetsD 172.16.1.8 [90/307200] via 172.16.1.6, 00:06:25, Ethernet1/1C 172.16.1.4 is directly connected, Ethernet1/1C 172.16.1.0 is directly connected, Ethernet1/0D 10.0.0.0/8 [90/409600] via 172.16.1.1, 00:06:09, Ethernet1/0D 192.168.0.0/24 [90/409600] via 172.16.1.6, 00:06:25, Ethernet1/1D 192.168.1.0/24 [90/409600] via 172.16.1.6, 00:06:25, Ethernet1/1D 192.168.2.0/24 [90/409600] via 172.16.1.6, 00:06:25, Ethernet1/1D 192.168.3.0/24 [90/409600] via 172.16.1.6, 00:06:25, Ethernet1/15、Check the EIGRP topology database of R2.R2#show ip eigrp topology all-linksIP-EIGRP Topology Table for AS(50)/ID(172.16.1.5)Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply, r - Reply statusP 10.0.0.0/8, 1 successors, FD is 409600, serno 3 via 172.16.1.1 (409600/128256), Ethernet1/0 via 172.16.1.6 (435200/409600), Ethernet1/1P 192.168.0.0/24, 1 successors, FD is 409600, serno 4 via 172.16.1.6 (409600/128256), Ethernet1/1
  13. 13. www.ccieuniversity.comP 192.168.1.0/24, 1 successors, FD is 409600, serno 5 via 172.16.1.6 (409600/128256), Ethernet1/1P 192.168.2.0/24, 1 successors, FD is 409600, serno 6 via 172.16.1.6 (409600/128256), Ethernet1/1P 192.168.3.0/24, 1 successors, FD is 409600, serno 7 via 172.16.1.6 (409600/128256), Ethernet1/1P 172.16.1.8/30, 1 successors, FD is 307200, serno 8 via 172.16.1.6 (307200/281600), Ethernet1/1P 172.16.1.4/30, 1 successors, FD is 281600, serno 2 via Connected, Ethernet1/1P 172.16.1.0/30, 1 successors, FD is 281600, serno 1 via Connected, Ethernet1/06、The specific 10.1.X.0/24 networks on both R1 and R4 were automatically summarizeto 10.0.0.0/8 before R2 receives. So R2 has two next hop to network 10.0.0.0/8,according to the topology database R1s (172.16.1.1) FD 409600 is better than R3s(172.16.1.6) FD 435200, then R2 will choose R1 172.16.1.1 as the next hop in the routingtable, so ping traffic to the networks behind R4 will not going to R4.7、To solve this issue, we need to use manual summary instead of auto summary.R1(config)#router eigrp 50R1(config-router)#no auto-summaryR1(config-router)#exitR1(config)#R1(config)#interface fastEthernet 0/1R1(config-if)#ip summary-address eigrp 50 10.1.0.0 255.255.252.0R1(config-if)#exitR1(config)#exitR4(config)#router eigrp 50R4(config-router)#no auto-summaryR4(config-router)#exitR4(config)#R4(config)#interface fastEthernet 0/0R4(config-if)#ip summary-address eigrp 50 10.1.16.0 255.255.252.0R4(config-if)#exitR4(config)#exit8、Check the routing table of R2.R2#show ip routeGateway of last resort is not set 172.16.0.0/30 is subnetted, 3 subnetsD 172.16.1.8 [90/307200] via 172.16.1.6, 00:21:08, Ethernet1/1C 172.16.1.4 is directly connected, Ethernet1/1C 172.16.1.0 is directly connected, Ethernet1/0 10.0.0.0/22 is subnetted, 2 subnetsD 10.1.0.0 [90/409600] via 172.16.1.1, 00:03:13, Ethernet1/0D 10.1.16.0 [90/435200] via 172.16.1.6, 00:01:02, Ethernet1/1D 192.168.0.0/24 [90/409600] via 172.16.1.6, 00:21:08, Ethernet1/1D 192.168.1.0/24 [90/409600] via 172.16.1.6, 00:21:08, Ethernet1/1
  14. 14. www.ccieuniversity.comD 192.168.2.0/24 [90/409600] via 172.16.1.6, 00:21:08, Ethernet1/1D 192.168.3.0/24 [90/409600] via 172.16.1.6, 00:21:08, Ethernet1/19、Ping the networks behind R1 and R4 again.R2#ping 10.1.0.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.0.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 16/69/145 msR2#ping 10.1.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 16/44/64 msR2#ping 10.1.16.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.16.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 60/97/140 msR2#ping 10.1.17.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.17.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 48/93/149 ms10、To decrease the size of routing table, we could manually summarize the networksfrom 192.168.0.0/24 to 192.168.3.0/24 behind R3.R3(config)#router eigrp 50R3(config-router)#no auto-summaryR3(config-router)#exitR3(config)#R3(config)#interface ethernet 1/1R3(config-if)#ip summary-address eigrp 50 192.168.0.0 255.255.252.0R3(config-if)#exitR3(config)#R3(config)#inter ethernet 1/0R3(config-if)#ip summary-address eigrp 50 192.168.0.0 255.255.252.0R3(config-if)#exitR3(config)#11、Check the routing table of R2 and R4.R4#show ip routeGateway of last resort is not set 172.16.0.0/30 is subnetted, 3 subnetsC 172.16.1.8 is directly connected, FastEthernet0/0D 172.16.1.4 [90/284160] via 172.16.1.9, 00:02:41, FastEthernet0/0
  15. 15. www.ccieuniversity.comD 172.16.1.0 [90/309760] via 172.16.1.9, 00:02:23, FastEthernet0/0 10.0.0.0/8 is variably subnetted, 6 subnets, 2 masksD 10.1.0.0/22 [90/437760] via 172.16.1.9, 00:02:23, FastEthernet0/0C 10.1.19.0/24 is directly connected, Loopback0C 10.1.18.0/24 is directly connected, Loopback0C 10.1.17.0/24 is directly connected, Loopback0D 10.1.16.0/22 is a summary, 00:03:33, Null0C 10.1.16.0/24 is directly connected, Loopback0D 192.168.0.0/22 [90/156160] via 172.16.1.9, 00:02:41, FastEthernet0/0R2#show ip routeGateway of last resort is not set 172.16.0.0/30 is subnetted, 3 subnetsD 172.16.1.8 [90/307200] via 172.16.1.6, 00:02:54, Ethernet1/1C 172.16.1.4 is directly connected, Ethernet1/1C 172.16.1.0 is directly connected, Ethernet1/0 10.0.0.0/22 is subnetted, 2 subnetsD 10.1.0.0 [90/409600] via 172.16.1.1, 00:16:13, Ethernet1/0D 10.1.16.0 [90/435200] via 172.16.1.6, 00:02:54, Ethernet1/1D 192.168.0.0/22 [90/409600] via 172.16.1.6, 00:02:54, Ethernet1/112、Ping the networks behind R3 from R2 and R4.R2#ping 192.168.0.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.0.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 1/28/60 msR4#ping 192.168.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 24/37/48 msBy www.ccieuniversity.com Configuring EIGRP Unequal Cost Paths LabTopology
  16. 16. www.ccieuniversity.comLab Purpose:1、Master EIGRP unequal cost load balance.2、Master EIGRP metric modifying.3、Master EIGRP AD、FD、FC、Successor、FS principal.Lab Steps:1、Finish basic ip configuration.2、Enable EIGRP 50 on the 3 routers.3、Check the routing table of R1.R1#show ip route 172.16.0.0/30 is subnetted, 3 subnetsC 172.16.1.8 is directly connected, FastEthernet0/0D 172.16.1.4 [90/2172416] via 172.16.1.10, 00:00:11, FastEthernet0/0C 172.16.1.0 is directly connected, Serial1/1D 192.168.1.0/24 [90/156160] via 172.16.1.10, 00:00:11, FastEthernet0/04、We can see there is only one way to network 192.168.1.0/24, to increase thecapability of transmission, we need to use all the usable links.5、If we want to use 172.16.1.2 as a unequal cost path, then we should make sure it isthe FS of network 192.168.1.0/24.6、Check the EIGRP 50 topology database we found that 172.16.1.2 is not in the192.168.1.0/24 list, not a FS.R1#show ip eigrp 50 topology………P 192.168.1.0/24, 1 successors, FD is 156160 via 172.16.1.10 (156160/128256), FastEthernet0/0P 172.16.1.8/30, 1 successors, FD is 28160 via Connected, FastEthernet0/0………7、Check the full EIGRP topology table we found that 172.16.1.2 could be the next hopof network 192.168.1.0/24, just not in use by the restriction of algorithm.R1#show ip eigrp 50 topology all-links
  17. 17. www.ccieuniversity.com………P 192.168.1.0/24, 1 successors, FD is 156160, serno 6 via 172.16.1.10 (156160/128256), FastEthernet0/0 via 172.16.1.2 (2809856/2297856), Serial1/1………8、According to the FS formula.AD of secondary-best route < FD of best route(Successor) = Feasible SuccessorWe could do the math.Distance from R2 to network 192.168.1.0/24 should less than 156160, then 172.16.1.2would be the FS.9、Lets change the EIGRP metrics of R2 to make it work as a FS of R1.R2#configure terminalR2(config)#interface serial 1/1R2(config-if)#bandwidth 10000000R2(config-if)#delay 10R2(config)#exit10、Check the topology table of R1, we see 130816 is less than 15160.R1#show ip eigrp topology all-links………P 192.168.1.0/24, 1 successors, FD is 156160, serno 6 via 172.16.1.10 (156160/128256), FastEthernet0/0 via 172.16.1.2 (2300416/130816), Serial1/1………11、This time we could enable unequal cost load balance, and give the right variancevalue.According to the variance formula.FD of FS route < FD of best route(Successor) * VarinceSo the math is2300416 < 156160 * xx≈14.7312、Let test 14 as the variance number.R1(config)#router eigrp 50R1(config-router)#variance 14R1(config-router)#exitR1(config)#exitR1#clear ip router *R1#show ip route………C 172.16.1.0 is directly connected, Serial1/1D 192.168.1.0/24 [90/156160] via 172.16.1.10, 00:00:00, FastEthernet0/0………Seems 14 is not enough.13、Lets change it to 15.
  18. 18. www.ccieuniversity.comR1(config)#router eigrp 50R1(config-router)#variance 15R1(config-router)#exitR1(config)#exitR1#clear ip router *R1#show ip route………C 172.16.1.0 is directly connected, Serial1/1D 192.168.1.0/24 [90/156160] via 172.16.1.10, 00:00:01, FastEthernet0/0 [90/2300416] via 172.16.1.2, 00:00:01, Serial1/1This time both 172.16.1.10 and 172.16.1.2 are the next hop for network 192.168.1.0/24.By www.ccieuniversity.com Configuring EIGRP Authentication LabTopologyLab Purpose:1、Master EIGRP authentication principal.2、Master EIGRP authentication configuration.Lab Steps:1、Finish basic ip configuration.2、Enable EIGRP 50 on the 2 routers.3、Check the routing tables of R1 and R2.R1#show ip route 172.16.0.0/16 is variably subnetted, 2 subnets, 2 masksC 172.16.1.8/30 is directly connected, Serial1/1D 172.16.0.0/16 is a summary, 00:00:37, Null0 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masksC 10.1.1.0/24 is directly connected, Loopback0D 10.0.0.0/8 is a summary, 00:00:37, Null0D 192.168.1.0/24 [90/2297856] via 172.16.1.10, 00:00:09, Serial1/1R1#
  19. 19. www.ccieuniversity.comR2#show ip route 172.16.0.0/16 is variably subnetted, 2 subnets, 2 masksC 172.16.1.8/30 is directly connected, Serial1/0D 172.16.0.0/16 is a summary, 00:00:53, Null0D 10.0.0.0/8 [90/2297856] via 172.16.1.9, 00:00:51, Serial1/0C 192.168.1.0/24 is directly connected, Loopback0R2#4、Config EIGRP authentication on R1.R1#configure terminalR1(config)#key chain edurainbowR1(config-keychain)#key 1R1(config-keychain-key)#key-string ciscoR1(config-keychain-key)#exitR1(config-keychain)#exitR1(config)#R1(config)#interface serial 1/1R1(config-if)#ip authentication key-chain eigrp 50 edurainbowR1(config-if)#ip authentication mode eigrp 50 md5R1(config-if)#endR1(config)#5、"Use clear ip route *" command to speed up converge.6、Then check the routing table of R1 and R2 again.R1#show ip routeC 172.16.1.8/30 is directly connected, Serial1/1D 172.16.0.0/16 is a summary, 00:00:16, Null0 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masksC 10.1.1.0/24 is directly connected, Loopback0D 10.0.0.0/8 is a summary, 00:00:16, Null0R1#R2#show ip route………C 172.16.1.8/30 is directly connected, Serial1/0D 172.16.0.0/16 is a summary, 00:02:53, Null0C 192.168.1.0/24 is directly connected, Loopback0R2#This time the neighbor is down and EIGRP routes are missing.*Mar 14 15:35:27.343: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 50: Neighbor 172.16.1.9 (Serial1/0) is up:new adjacency*Mar 14 15:35:29.767: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 50: Neighbor 172.16.1.9 (Serial1/0) is down:Auth failure7 Check the neighbor table of R2 we found no item there.R2#show ip eigrp 50 neighborsIP-EIGRP neighbors for process 508、Config EIGRP authentication on R2.R2#
  20. 20. www.ccieuniversity.comR2#configure terminalR2(config)#key chain edurainbowR2(config-keychain)#key 1R2(config-keychain-key)#key-string ciscoR2(config-keychain-key)#exitR2(config-keychain)#exitR2(config)#R2(config)#interface serial 1/0R2(config-if)#ip authentication key-chain eigrp 50 edurainbowR2(config-if)#ip authentication mode eigrp 50 md5R2(config-if)#exitR2(config)#exitR2(config)#9、Then we found neighbor is up again.*Mar 14 15:46:04.071: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 50: Neighbor 172.16.1.9 (Serial1/0) is up:new adjacencyR2#show ip eigrp 50 neighborsIP-EIGRP neighbors for process 50H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num0 172.16.1.9 Se1/0 11 00:01:17 28 200 0 810、Check the routing table of R1 and R2 we found the RIGRP routes are back.R1#show ip route 172.16.0.0/16 is variably subnetted, 2 subnets, 2 masksC 172.16.1.8/30 is directly connected, Serial1/1D 172.16.0.0/16 is a summary, 00:08:41, Null0 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masksC 10.1.1.0/24 is directly connected, Loopback0D 10.0.0.0/8 is a summary, 00:08:42, Null0D 192.168.1.0/24 [90/2297856] via 172.16.1.10, 00:02:54, Serial1/1R1#R2#show ip route 172.16.0.0/16 is variably subnetted, 2 subnets, 2 masksC 172.16.1.8/30 is directly connected, Serial1/0D 172.16.0.0/16 is a summary, 00:08:28, Null0D 10.0.0.0/8 [90/2297856] via 172.16.1.9, 00:03:44, Serial1/0C 192.168.1.0/24 is directly connected, Loopback0By www.ccieuniversity.com Understand EIGRP Query LabTopology
  21. 21. www.ccieuniversity.comLab Purpose:1、Understand EIGRP route update mechanism.2、Master EIGRP debug command.3、Master stub configuration.Lab Steps:1、Finish basic ip configuration.2、Enable EIGRP 50 on the 3 routers.3、Check EIGRP routing table of R1 R2 R3.R1#show ip route eigrp 172.16.0.0/16 is variably subnetted, 3 subnets, 2 masksD 172.16.1.4/30 [90/2681856] via 172.16.1.2, 00:01:20, Serial1/1D 172.16.0.0/16 is a summary, 00:01:00, Null0 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masksD 10.0.0.0/8 is a summary, 00:00:59, Null0R1#R2#show ip route eigrpD 10.0.0.0/8 [90/2297856] via 172.16.1.1, 00:01:16, Serial1/0D 192.168.1.0/24 [90/2172416] via 172.16.1.1, 00:01:21, Serial1/0 [90/2172416] via 172.16.1.6, 00:01:21, Serial1/1R2#R3#sh ip route eigrp 172.16.0.0/16 is variably subnetted, 3 subnets, 2 masksD 172.16.0.0/16 is a summary, 00:01:30, Null0D 172.16.1.0/30 [90/2681856] via 172.16.1.5, 00:01:36, Serial1/0D 10.0.0.0/8 [90/156160] via 192.168.1.1, 00:01:30, FastEthernet0/0R3#4、Debug EIGRP on R2 to track update.R2#debug eigrp fsmEIGRP FSM Events/Actions debugging is on
  22. 22. www.ccieuniversity.comR2#debug eigrp packets queryEIGRP Packets debugging is on (QUERY)5、Shutdown loopback0 on R1 to simulate a network issue.R1(config)#interface loopback 0R1(config-if)#shutdown6、Check debug information on R2.*Mar 15 22:03:26.087: EIGRP: Received QUERY on Serial1/0 nbr 172.16.1.1*Mar 15 22:03:26.091: AS 50, Flags 0x0, Seq 127/192 idbQ 0/0 iidbQun/rely 0/0 peerQ un/rely 0/0*Mar 15 22:03:26.095: DUAL: rcvquery: 10.1.1.0/24 via 172.16.1.1 metric4294967295/4294967295, RD is 2297856*Mar 15 22:03:26.095: DUAL: Find FS for dest 10.1.1.0/24. FD is 2297856,RD is 2297856*Mar 15 22:03:26.099: DUAL: 172.16.1.1 metric 4294967295/4294967295*Mar 15 22:03:26.099: DUAL: 172.16.1.6 metric 2300416/156160 foundDmin is 2300416*Mar 15 22:03:26.099: DUAL: send REPLY(R1/n1) about 10.1.1.0/24 to172.16.1.1*Mar 15 22:03:26.099: DUAL: RT installed 10.1.1.0/24 via 172.16.1.6*Mar 15 22:03:26.099: DUAL: Send update about 10.1.1.0/24. Reason:metric chg*Mar 15 22:03:26.099: DUAL: Send update about 10.1.1.0/24. Reason: newif*Mar 15 22:03:26.147: EIGRP: Received QUERY on Serial1/1 nbr 172.16.1.6*Mar 15 22:03:26.151: AS 50, Flags 0x0, Seq 144/194 idbQ 0/0 iidbQun/rely 0/0 peerQ un/rely 0/0*Mar 15 22:03:26.155: DUAL: rcvquery: 10.1.1.0/24 via 172.16.1.6 metric4294967295/4294967295, RD is 2300416*Mar 15 22:03:26.155: DUAL: Find FS for dest 10.1.1.0/24. FD is 2297856,RD is 2300416*Mar 15 22:03:26.159: DUAL: 172.16.1.6 metric 4294967295/4294967295*Mar 15 22:03:26.159: DUAL: 172.16.1.1 metric 4294967295/4294967295not found Dmin is 4294967295*Mar 15 22:03:26.159: DUAL: Peer total/stub 2/0 template/full-stub 2/0*Mar 15 22:03:26.159: DUAL: Dest 10.1.1.0/24 entering active state.*Mar 15 22:03:26.159: DUAL: Set reply-status table. Count is 2.*Mar 15 22:03:26.159: DUAL: Not doing split horizon*Mar 15 22:03:26.159: DUAL: Going from state 1 to state 3*Mar 15 22:03:26.171: EIGRP: Enqueueing QUERY on Serial1/1 iidbQ un/rely0/1 serno 148-148
  23. 23. www.ccieuniversity.com*Mar 15 22:03:26.175: EIGRP: Enqueueing QUERY on Serial1/1 nbr172.16.1.6 iidbQ un/rely 0/0 peerQ un/rely 0/0 serno 148-148*Mar 15 22:03:26.179: EIGRP: Sending QUERY on Serial1/1 nbr 172.16.1.6*Mar 15 22:03:26.179: AS 50, Flags 0x0, Seq 195/144 idbQ 0/0 iidbQun/rely 0/0 peerQ un/rely 0/1 serno 148-148*Mar 15 22:03:26.199: EIGRP: Enqueueing QUERY on Serial1/0 iidbQ un/rely0/1 serno 148-148*Mar 15 22:03:26.203: EIGRP: Enqueueing QUERY on Serial1/0 nbr172.16.1.1 iidbQ un/rely 0/0 peerQ un/rely 0/0 serno 148-148*Mar 15 22:03:26.207: EIGRP: Sending QUERY on Serial1/0 nbr 172.16.1.1*Mar 15 22:03:26.207: AS 50, Flags 0x0, Seq 196/127 idbQ 0/0 iidbQun/rely 0/0 peerQ un/rely 0/1 serno 148-148*Mar 15 22:03:26.215: DUAL: rcvreply: 10.1.1.0/24 via 172.16.1.6 metric4294967295/4294967295*Mar 15 22:03:26.219: DUAL: reply count is 2*Mar 15 22:03:26.219: DUAL: Clearing handle 1, count now 1*Mar 15 22:03:26.267: DUAL: rcvreply: 10.1.1.0/24 via 172.16.1.1 metric4294967295/4294967295*Mar 15 22:03:26.267: DUAL: reply count is 1*Mar 15 22:03:26.267: DUAL: Clearing handle 0, count now 0*Mar 15 22:03:26.271: DUAL: Freeing reply status table*Mar 15 22:03:26.271: DUAL: Find FS for dest 10.1.1.0/24. FD is4294967295, RD is 4294967295 found………According to the debug output there are 4 query packets and 4 respond packets, thing ifthere are hundreds of routers the query will be huge. We could use manually summarizeand stub feature to restrict the query scope.7、Manually summary on R1 and R3.R1(config)#interface loopback 0R1(config-if)#no shutdownR1(config)#interface serial 1/1R1(config-if)#ip summary-address eigrp 50 10.0.0.0 255.0.0.0R3(config)#interface serial 1/0R3(config-if)#ip summary-address eigrp 50 10.0.0.0 255.0.0.08、Check routing table of R2 and R3 again to make sure they have learned the summaryroute.R2#show ip route eigrp 172.16.0.0/16 is variably subnetted, 3 subnets, 2 masks
  24. 24. www.ccieuniversity.comD 172.16.0.0/16 [90/2684416] via 172.16.1.1, 00:15:27, Serial1/0 10.0.0.0/24 is subnetted, 1 subnetsD 10.1.1.0 [90/2297856] via 172.16.1.1, 00:00:27, Serial1/0D 192.168.1.0/24 [90/2172416] via 172.16.1.1, 00:15:09, Serial1/0 [90/2172416] via 172.16.1.6, 00:15:09, Serial1/1R2#ping 10.1.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 48/78/104 msR2#R3>show ip route eigrp 172.16.0.0/16 is variably subnetted, 3 subnets, 2 masksD 172.16.0.0/16 is a summary, 00:15:43, Null0D 172.16.1.0/30 [90/2172416] via 192.168.1.1, 00:15:43,FastEthernet0/0 10.0.0.0/24 is subnetted, 1 subnetsD 10.1.1.0 [90/156160] via 192.168.1.1, 00:00:57, FastEthernet0/0R3>R3>ping 10.1.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 24/62/96 msR3>9、Shutdown loopback0 on R1 again to check the debug message on R2.*Mar 15 22:11:17.867: EIGRP: Received QUERY on Serial1/0 nbr 172.16.1.1*Mar 15 22:11:17.871: AS 50, Flags 0x0, Seq 135/207 idbQ 0/0 iidbQun/rely 0/0 peerQ un/rely 0/0*Mar 15 22:11:17.875: DUAL: dest(10.1.1.0/24) not active*Mar 15 22:11:17.875: DUAL: rcvquery: 10.1.1.0/24 via 172.16.1.1 metric4294967295/4294967295, RD is 4294967295*Mar 15 22:11:17.879: DUAL: send REPLY(R1/n1) about 10.1.1.0/24 to172.16.1.1*Mar 15 22:11:17.879: DUAL: rcvquery: 10.0.0.0/8 via 172.16.1.1 metric4294967295/4294967295, RD is 2297856
  25. 25. www.ccieuniversity.com*Mar 15 22:11:17.883: DUAL: Find FS for dest 10.0.0.0/8. FD is 2297856,RD is 2297856*Mar 15 22:11:17.883: DUAL: 172.16.1.1 metric 4294967295/4294967295*Mar 15 22:11:17.887: DUAL: 172.16.1.6 metric 2300416/156160 foundDmin is 2300416*Mar 15 22:11:17.887: DUAL: send REPLY(R1/n1) about 10.0.0.0/8 to172.16.1.1*Mar 15 22:11:17.891: DUAL: RT installed 10.0.0.0/8 via 172.16.1.6*Mar 15 22:11:17.895: DUAL: Send update about 10.0.0.0/8. Reason:metric chg*Mar 15 22:11:17.895: DUAL: Send update about 10.0.0.0/8. Reason: newif*Mar 15 22:11:17.899: EIGRP: Received QUERY on Serial1/1 nbr 172.16.1.6*Mar 15 22:11:17.903: AS 50, Flags 0x0, Seq 154/208 idbQ 0/0 iidbQun/rely 0/0 peerQ un/rely 0/0*Mar 15 22:11:17.907: DUAL: dest(10.1.1.0/24) not active*Mar 15 22:11:17.907: DUAL: rcvquery: 10.1.1.0/24 via 172.16.1.6 metric4294967295/4294967295, RD is 4294967295*Mar 15 22:11:17.911: DUAL: send REPLY(R1/n1) about 10.1.1.0/24 to172.16.1.6*Mar 15 22:11:17.951: DUAL: Removing dest 10.1.1.0/24, nexthop172.16.1.1*Mar 15 22:11:17.955: DUAL: Removing dest 10.0.0.0/8, nexthop 172.16.1.1*Mar 15 22:11:18.015: DUAL: Removing dest 10.1.1.0/24, nexthop172.16.1.6*Mar 15 22:11:18.015: DUAL: No routes. Flushing dest 10.1.1.0/24*Mar 15 22:11:18.019: EIGRP: Received QUERY on Serial1/1 nbr 172.16.1.6*Mar 15 22:11:18.023: AS 50, Flags 0x0, Seq 157/212 idbQ 0/0 iidbQun/rely 0/0 peerQ un/rely 0/0*Mar 15 22:11:18.027: DUAL: rcvquery: 10.0.0.0/8 via 172.16.1.6 metric4294967295/4294967295, RD is 2300416*Mar 15 22:11:18.027: DUAL: Find FS for dest 10.0.0.0/8. FD is 2297856,RD is 2300416*Mar 15 22:11:18.031: DUAL: 172.16.1.6 metric 4294967295/4294967295not found Dmin is 4294967295*Mar 15 22:11:18.031: DUAL: Peer total/stub 2/0 template/full-stub 2/0*Mar 15 22:11:18.035: DUAL: Dest 10.0.0.0/8 entering active state.*Mar 15 22:11:18.035: DUAL: Set reply-status table. Count is 1.*Mar 15 22:11:18.039: DUAL: Doing split horizon on Serial1/1*Mar 15 22:11:18.039: DUAL: Going from state 1 to state 3
  26. 26. www.ccieuniversity.com*Mar 15 22:11:18.047: EIGRP: Enqueueing QUERY on Serial1/1 iidbQ un/rely0/1 serno 161-161*Mar 15 22:11:18.051: EIGRP: Enqueueing QUERY on Serial1/0 iidbQ un/rely0/1 serno 161-161*Mar 15 22:11:18.051: EIGRP: Enqueueing QUERY on Serial1/1 nbr172.16.1.6 iidbQ un/rely 0/0 peerQ un/rely 0/0 serno 161-161*Mar 15 22:11:18.055: EIGRP: Enqueueing QUERY on Serial1/0 nbr172.16.1.1 iidbQ un/rely 0/0 peerQ un/rely 0/0 serno 161-161*Mar 15 22:11:18.063: EIGRP: Sending QUERY on Serial1/0 nbr 172.16.1.1*Mar 15 22:11:18.063: AS 50, Flags 0x0, Seq 214/135 idbQ 0/0 iidbQun/rely 0/0 peerQ un/rely 0/1 serno 161-161*Mar 15 22:11:18.119: DUAL: dest(10.0.0.0/8) active*Mar 15 22:11:18.119: DUAL: rcvreply: 10.0.0.0/8 via 172.16.1.1 metric4294967295/4294967295*Mar 15 22:11:18.123: DUAL: reply count is 1*Mar 15 22:11:18.123: DUAL: Clearing handle 0, count now 0*Mar 15 22:11:18.123: DUAL: Freeing reply status table*Mar 15 22:11:18.123: DUAL: Find FS for dest 10.0.0.0/8. FD is4294967295, RD is 4294967295 found*Mar 15 22:11:18.127: DUAL: send REPLY(R1/n1) about 10.0.0.0/8 to172.16.1.6*Mar 15 22:11:18.131: DUAL: Removing dest 10.0.0.0/8, nexthop 172.16.1.1*Mar 15 22:11:18.131: DUAL: Going from state 3 to state 1*Mar 15 22:11:18.171: DUAL: Removing dest 10.0.0.0/8, nexthop 172.16.1.6*Mar 15 22:11:18.171: DUAL: No routes. Flushing dest 10.0.0.0/8Obviously query packets for network 10.1.1.0/24 decrease to 2 this time.10、To deeply solve the issue, we enable EIGRP stub feature on R2 to stop querypackets for network 10.1.1.0/24.R2(config)#router eigrp 50R2(config-router)#eigrp stub11、Check the neighbor table on R1 to see the stub feature.R1#show ip eigrp neighbors detailIP-EIGRP neighbors for process 50H Address Interface Hold Uptime SRTT RTO QSeq (sec) (ms) CntNum
  27. 27. www.ccieuniversity.com0 172.16.1.2 Se1/1 12 00:01:01 216 1296 0220 Version 12.3/1.2, Retrans: 0, Retries: 0 Stub Peer Advertising ( CONNECTED SUMMARY ) Routes Suppressing queries1 192.168.1.2 Fa0/0 14 01:09:11 75 450 0159 Version 12.3/1.2, Retrans: 1, Retries: 012、Shutdown loopback0 of R1 again to see the debug output of R2.*Mar 15 22:22:31.371: DUAL: rcvupdate: 10.0.0.0/8 via 172.16.1.1 metric4294967295/4294967295*Mar 15 22:22:31.371: DUAL: Find FS for dest 10.0.0.0/8. FD is 2297856,RD is 2297856*Mar 15 22:22:31.375: DUAL: 172.16.1.1 metric 4294967295/4294967295*Mar 15 22:22:31.375: DUAL: 172.16.1.6 metric 2300416/156160 foundDmin is 2300416*Mar 15 22:22:31.379: DUAL: Removing dest 10.0.0.0/8, nexthop 172.16.1.1*Mar 15 22:22:31.383: DUAL: RT installed 10.0.0.0/8 via 172.16.1.6*Mar 15 22:22:31.383: DUAL: Send update about 10.0.0.0/8. Reason:metric chg*Mar 15 22:22:31.387: DUAL: Send update about 10.0.0.0/8. Reason: newif*Mar 15 22:22:31.587: DUAL: rcvupdate: 10.0.0.0/8 via 172.16.1.6 metric4294967295/4294967295*Mar 15 22:22:31.587: DUAL: Find FS for dest 10.0.0.0/8. FD is 2297856,RD is 2300416*Mar 15 22:22:31.591: DUAL: 172.16.1.6 metric 4294967295/4294967295not found Dmin is 4294967295*Mar 15 22:22:31.591: DUAL: Peer total/stub 2/0 template/full-stub 2/0*Mar 15 22:22:31.595: DUAL: Dest 10.0.0.0/8 entering active state.*Mar 15 22:22:31.595: DUAL: Set reply-status table. Count is 2.*Mar 15 22:22:31.595: DUAL: Not doing split horizon*Mar 15 22:22:31.607: EIGRP: Enqueueing QUERY on Serial1/1 iidbQ un/rely0/1 serno 169-169*Mar 15 22:22:31.607: EIGRP: Enqueueing QUERY on Serial1/0 iidbQ un/rely0/1 serno 169-169*Mar 15 22:22:31.611: EIGRP: Enqueueing QUERY on Serial1/1 nbr172.16.1.6 iidbQ un/rely 0/0 peerQ un/rely 0/0 serno 169-169*Mar 15 22:22:31.615: EIGRP: Enqueueing QUERY on Serial1/0 nbr172.16.1.1 iidbQ un/rely 0/0 peerQ un/rely 0/0 serno 169-169
  28. 28. www.ccieuniversity.com*Mar 15 22:22:31.619: EIGRP: Sending QUERY on Serial1/1 nbr 172.16.1.6*Mar 15 22:22:31.623: AS 50, Flags 0x0, Seq 226/169 idbQ 0/0 iidbQun/rely 0/0 peerQ un/rely 0/1 serno 169-169*Mar 15 22:22:31.627: EIGRP: Sending QUERY on Serial1/0 nbr 172.16.1.1*Mar 15 22:22:31.627: AS 50, Flags 0x0, Seq 227/148 idbQ 0/0 iidbQun/rely 0/0 peerQ un/rely 0/1 serno 169-169*Mar 15 22:22:31.711: DUAL: dest(10.0.0.0/8) active*Mar 15 22:22:31.715: DUAL: rcvreply: 10.0.0.0/8 via 172.16.1.1 metric4294967295/4294967295*Mar 15 22:22:31.715: DUAL: reply count is 2…………This time R2 will not receive any query packet for network 10.1.1.0/24By www.ccieuniversity.com Configuring Basic Multi Area OSPF and Area Summary Lab TopologyLab Purpose:1、Master OSPF multi area configuration.2、Distinguish routes from different areas.3、Master OSPF route summary configuration.4、Master OSPF basic configuration.Lab Steps:1、Finish basic ip configuration.2、Enable OSPF 1 on R1, assign interfaces to the relevant area according to thetopology.R1(config)#router ospf 1R1(config-router)#network 10.1.2.0 0.0.0.255 area 1R1(config-router)#network 10.1.1.0 0.0.0.255 area 1R1(config-router)#network 192.168.1.0 0.0.0.3 area 1
  29. 29. www.ccieuniversity.comR1(config-router)#exit3、Enable OSPF 1 on R2, assign interfaces to relevant area according to the topology.R2(config)#router ospf 1R2(config-router)#network 192.168.1.0 0.0.0.3 area 1R2(config-router)#network 192.168.1.4 0.0.0.3 area 0R2(config)#exit4、Refer to R1 and R2, finish the OSPF configuration on R3 and R4.5、Check OSPF neighbor relationship on R2.R2#show ip ospf neighborNeighbor ID Pri State Dead Time Address Interface192.168.1.9 1 FULL/ - 00:00:39 192.168.1.6 Serial1/110.1.2.1 1 FULL/ - 00:00:37 192.168.1.1 Serial1/06、Check the routing table of R1 to see OSPF route from different areas.R1#show ip routeCodes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter areaN1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP…………Gateway of last resort is not set 172.16.0.0/32 is subnetted, 2 subnetsO IA 172.16.1.1 [110/193] via 192.168.1.2, 00:02:23, Serial1/1O IA 172.16.2.1 [110/193] via 192.168.1.2, 00:02:23, Serial1/1 10.0.0.0/24 is subnetted, 2 subnetsC 10.1.2.0 is directly connected, Loopback1C 10.1.1.0 is directly connected, Loopback0 192.168.1.0/30 is subnetted, 3 subnetsO IA 192.168.1.8 [110/192] via 192.168.1.2, 00:02:58, Serial1/1C 192.168.1.0 is directly connected, Serial1/1O IA 192.168.1.4 [110/128] via 192.168.1.2, 00:05:06, Serial1/17、Check OSPF link state database of R1.R1#show ip ospf database OSPF Router with ID (10.1.2.1) (Process ID 1) Router Link States (Area 1)Link ID ADV Router Age Seq# Checksum Link count10.1.2.1 10.1.2.1 492 0x80000004 0x00C83F 4192.168.1.5 192.168.1.5 486 0x80000003 0x002BB5 2
  30. 30. www.ccieuniversity.com Summary Net Link States (Area 1)Link ID ADV Router Age Seq# Checksum172.16.1.1 192.168.1.5 315 0x80000001 0x00CCC0172.16.2.1 192.168.1.5 315 0x80000001 0x00C1CA192.168.1.4 192.168.1.5 479 0x80000001 0x00E33E192.168.1.8 192.168.1.5 350 0x80000001 0x003E9F8、Use ping to test the connectivity on R1.R1#ping 172.16.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 172.16.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 216/240/288msR1#9、Check the routing table and OSPF link state database on R4.R4#show ip route 172.16.0.0/24 is subnetted, 2 subnetsC 172.16.1.0 is directly connected, Loopback0C 172.16.2.0 is directly connected, Loopback1 10.0.0.0/24 is subnetted, 2 subnetsO IA 10.1.2.0 [110/193] via 192.168.1.9, 00:15:14, Serial1/0O IA 10.1.1.0 [110/193] via 192.168.1.9, 00:15:14, Serial1/0 192.168.1.0/30 is subnetted, 3 subnetsC 192.168.1.8 is directly connected, Serial1/0O IA 192.168.1.0 [110/192] via 192.168.1.9, 00:15:14, Serial1/0O IA 192.168.1.4 [110/128] via 192.168.1.9, 00:15:14, Serial1/0R4#R4#show ip ospf database OSPF Router with ID (172.16.2.1) (Process ID 1) Router Link States (Area 2)Link ID ADV Router Age Seq# Checksum Link count172.16.2.1 172.16.2.1 1223 0x80000004 0x00B871 4192.168.1.9 192.168.1.9 1224 0x80000002 0x00EA2E 2 Summary Net Link States (Area 2)Link ID ADV Router Age Seq# Checksum10.1.1.0 192.168.1.9 2 0x80000001 0x00B58610.1.2.0 192.168.1.9 2 0x80000001 0x00AA90192.168.1.0 192.168.1.9 1265 0x80000001 0x00766B
  31. 31. www.ccieuniversity.com192.168.1.4 192.168.1.9 1265 0x80000001 0x00CB52As you see all the area 1 specific routes are in the routing table of R4, we could dosomething to make it smaller.10、Config OSPF area summary on R2.R2(config)#router ospf 1R2(config-router)#area 1 range 10.1.0.0 255.255.0.0R2(config-router)#exitR2(config)#exit11、Check the routing table and OSPF database on R4 again.R4#show ip route 172.16.0.0/24 is subnetted, 2 subnetsC 172.16.1.0 is directly connected, Loopback0C 172.16.2.0 is directly connected, Loopback1 10.0.0.0/16 is subnetted, 1 subnetsO IA 10.1.0.0 [110/193] via 192.168.1.9, 00:00:32, Serial1/0 192.168.1.0/30 is subnetted, 3 subnetsC 192.168.1.8 is directly connected, Serial1/0O IA 192.168.1.0 [110/192] via 192.168.1.9, 00:18:36, Serial1/0O IA 192.168.1.4 [110/128] via 192.168.1.9, 00:18:36, Serial1/0R4#R4#show ip ospf database OSPF Router with ID (172.16.2.1) (Process ID 1) Router Link States (Area 2)Link ID ADV Router Age Seq# Checksum Link count172.16.2.1 172.16.2.1 6 0x80000005 0x00B672 4192.168.1.9 192.168.1.9 13 0x80000004 0x00E630 2 Summary Net Link States (Area 2)Link ID ADV Router Age Seq# Checksum10.1.0.0 192.168.1.9 29 0x80000001 0x00C07C192.168.1.0 192.168.1.9 1325 0x80000001 0x00766B192.168.1.4 192.168.1.9 1325 0x80000001 0x00CB52By www.ccieuniversity.com
  32. 32. www.ccieuniversity.com Configuring OSPF in NBMA LabTopologyLab Purpose:1、Master OSPF in NBMA network configuration.2、Master OSPF interface network type configuration.3、Master OSPF interface priority configuration.Lab Steps:1、Finish basic ip configuration.2、Enable OSPF on all routers and use default network type.R1(config)#interface loopback 0R1(config-if)#ip address 172.16.1.1 255.255.255.0R1(config-if)#ip ospf network point-to-pointR1(config-if)#exitR1(config)#R1(config)#interface serial 1/2R1(config-if)#ip add 192.168.1.1 255.255.255.0R1(config-if)#encapsulation frame-relayR1(config-if)#no frame-relay inverse-arpR1(config-if)#frame-relay map ip 192.168.1.2 102 broadcastR1(config-if)#frame-relay map ip 192.168.1.3 103 broadcastR1(config-if)#exitR1(config)#R1(config)#router ospf 1R1(config-router)#network 192.168.1.0 0.0.0.255 area 0R1(config-router)#network 172.16.1.0 0.0.0.255 area 0R1(config-router)#exitR1(config)#R2(config)#interface loopback 0R2(config-if)#ip address 172.16.3.1 255.255.255.0R2(config-if)#ip ospf network point-to-pointR2(config-if)#exitR2(config)#
  33. 33. www.ccieuniversity.comR2(config)#interface serial 1/2R2(config-if)#encapsulation frame-relayR2(config-if)#ip address 192.168.1.2 255.255.255.0R2(config-if)#no frame-relay inverse-arpR2(config-if)#frame-relay map ip 192.168.1.1 201 broadcastR2(config-if)#no shutdownR2(config-if)#exitR2(config)#R2(config)#router ospf 1R2(config-router)#network 172.16.3.0 0.0.0.255 area 0R2(config-router)#network 192.168.1.0 0.0.0.255 area 0R2(config-router)#exitR2(config)#R3(config)#interface loopback 0R3(config-if)#ip address 172.16.4.1 255.255.255.0R3(config-if)#ip ospf network point-to-pointR3(config-if)#exitR3(config)#R3(config)#interface serial 1/2R3(config-if)#ip address 192.168.1.3 255.255.255.0R3(config-if)#encapsulation frame-relayR3(config-if)#no frame-relay inverse-arpR3(config-if)#frame-relay map ip 192.168.1.1 301 broadcastR3(config-if)#no shutdownR3(config-if)#exitR3(config)#R3(config)#router ospf 1R3(config-router)#network 172.16.4.0 0.0.0.255 area 0R3(config-router)#network 192.168.1.0 0.0.0.255 area 0R3(config-router)#exitR3(config)#3、Check the OSPF neighbor table on R1 we can see no neighbor is up.R1#show ip ospf neighbor4、Check Serial 1/2 OSPF information on R1.R1#show ip ospf interface serial 1/2Serial1/2 is up, line protocol is up Internet Address 192.168.1.1/24, Area 0 Process ID 1, Router ID 172.16.1.1, Network Type NON_BROADCAST, Cost: 64 Transmit Delay is 1 sec, State DR, Priority 1 Designated Router (ID) 172.16.1.1, Interface address 192.168.1.1
  34. 34. www.ccieuniversity.com No backup designated router on this network Timer intervals configured, Hello 30, Dead 120, Wait 120, Retransmit 5 oob-resync timeout 120 Hello due in 00:00:15 Index 1/1, flood queue length 0 Next 0x0(0)/0x0(0) Last flood scan length is 0, maximum is 0 Last flood scan time is 0 msec, maximum is 0 msec Neighbor Count is 0, Adjacent neighbor count is 0 Suppress hello for 0 neighbor(s)5、According to the above information we could see the default OSPF network type forNBMA is NON_BROADCAST, So OSPF will not send out its hello packet which based onmulti-cast.6、One solution is to manually assign OSPF neighbor.R1(config)#router ospf 1R1(config-router)#neighbor 192.168.1.2R1(config-router)#neighbor 192.168.1.3R2(config)#router ospf 1R2(config-router)#neighbor 192.168.1.1R3(config)#router ospf 1R3(config-router)#neighbor 192.168.1.17、Then we can see the neighbors are up.*Jun 18 15:36:16.743: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.4.1 on Serial1/2 fromLOADING to FULL, Loading Done*Jun 18 15:36:16.747: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.3.1 on Serial1/2 fromLOADING to FULL, Loading Don8、Check the OSPF neighbor table on R1.R1#show ip ospf neighborNeighbor ID Pri State Dead Time Address Interface172.16.3.1 1 FULL/DROTHER 00:01:31 192.168.1.2 Serial1/2172.16.4.1 1 FULL/DR 00:01:57 192.168.1.3 Serial1/29、Beside manually allocate, we could also change the OSPF network type to build theneighbor relationship. Lets first remove the manually allocate configuration, thenchange the OSPF network type to broadcast.R1(config)#router ospf 1
  35. 35. www.ccieuniversity.comR1(config-router)#no neighbor 192.168.1.2R1(config-router)#no neighbor 192.168.1.3R2(config)#router ospf 1R2(config-router)#no neighbor 192.168.1.1R3(config)#router ospf 1R3(config-router)#no neighbor 192.168.1.1R1(config)#interface serial 1/2R1(config-if)#ip ospf network broadcastR1(config-if)#exitR2(config)#interface serial 1/2R2(config-if)#ip ospf network broadcastR2(config-if)#exitR3(config)#interface serial 1/2R3(config-if)#ip ospf network broadcastR3(config-if)#exit10、Check serial 1/2 OSPF information on R1.R1#show ip ospf interface serial 1/2Serial1/2 is up, line protocol is up Internet Address 192.168.1.1/24, Area 0 Process ID 1, Router ID 172.16.1.1, Network Type BROADCAST, Cost: 64Transmit Delay is 1 sec, State DR, Priority 1…………Network type is BROADCAST now.11、Check OSPF neighbor table on R1 R2 R3.R1#show ip ospf neighborNeighbor ID Pri State Dead Time Address Interface172.16.3.1 1 FULL/DROTHER 00:00:32 192.168.1.2 Serial1/2172.16.4.1 1 FULL/DR 00:00:33 192.168.1.3 Serial1/2R1#R2#show ip ospf neighborNeighbor ID Pri State Dead Time Address Interface172.16.1.1 1 FULL/BDR 00:00:30 192.168.1.1 Serial1/2R2#
  36. 36. www.ccieuniversity.comR3#show ip ospf neighborNeighbor ID Pri State Dead Time Address Interface172.16.1.1 1 FULL/BDR 00:00:39 192.168.1.1 Serial1/2R3#12、Look at the above OSPF neighbor table we can see:R1 considers 172.16.4.1(R3) as DR, 172.16.3.1(R2) as DROTHER, itself as BDR.R2 considers 172.16.1.1(R1) as BDR, itself as DR.R3 considers 172.16.1.1(R1) as BDR, itself as DR.As the frame-relay network is not full mesh, it has only two PVC one is between R1 andR2, the other is between R1 and R3, to make sure everyone will receive LSU (LASupdate), R1 should be the DR.13、Change interface OSPF priority to 0 on R2 and R3, so neither R2 nor R3 willparticipate in DR/BDR selection.R2(config)#interface serial 1/2R2(config-if)#ip ospf priority 0R2(config-if)#exitR2(config)#R3(config)#interface serial 1/2R3(config-if)#ip ospf priority 0R3(config-if)#exit14、Check OSPF neighbor table on R1 R2 R3, we can see R1 is always the DR.R1#show ip ospf neighborNeighbor ID Pri State Dead Time Address Interface172.16.3.1 0 FULL/DROTHER 00:00:38 192.168.1.2 Serial1/2172.16.4.1 0 FULL/DROTHER 00:00:39 192.168.1.3 Serial1/2R1#
  37. 37. www.ccieuniversity.comR2#show ip ospf neighborNeighbor ID Pri State Dead Time Address Interface172.16.1.1 1 FULL/DR 00:00:31 192.168.1.1 Serial1/2R2#R3#show ip ospf neighborNeighbor ID Pri State Dead Time Address Interface172.16.1.1 1 FULL/DR 00:00:38 192.168.1.1 Serial1/215、We could also change the OSPF network type to P2P, then there will be no DR/BDRselection.OSPF network type diagram.By www.ccieuniversity.com Configuring OSPF Authentication LabTopology
  38. 38. www.ccieuniversity.comLab Purpose:1、Master OSPF interface and area authentication configuration.Lab Steps:1、Master OSPF in NBMA network configuration.2、Finish OSPF basic configuration.3、 Check the routing table of R1 and R2R1#show ip routeGateway of last resort is not set 172.16.0.0/24 is subnetted, 2 subnetsO IA 172.16.1.0 [110/193] via 192.168.1.2, 00:01:02, Serial1/1O IA 172.16.2.0 [110/193] via 192.168.1.2, 00:01:02, Serial1/1 10.0.0.0/24 is subnetted, 2 subnetsC 10.1.2.0 is directly connected, Loopback0C 10.1.1.0 is directly connected, Loopback1 192.168.1.0/30 is subnetted, 3 subnetsO IA 192.168.1.8 [110/192] via 192.168.1.2, 00:01:12, Serial1/1C 192.168.1.0 is directly connected, Serial1/1O IA 192.168.1.4 [110/128] via 192.168.1.2, 00:05:47, Serial1/1R2#show ip routeGateway of last resort is not set 172.16.0.0/24 is subnetted, 2 subnetsO IA 172.16.1.0 [110/129] via 192.168.1.6, 00:09:16, Serial1/1O IA 172.16.2.0 [110/129] via 192.168.1.6, 00:09:16, Serial1/1 10.0.0.0/24 is subnetted, 2 subnetsO 10.1.2.0 [110/65] via 192.168.1.1, 00:14:00, Serial1/0O 10.1.1.0 [110/65] via 192.168.1.1, 00:14:00, Serial1/0 192.168.1.0/30 is subnetted, 3 subnetsO IA 192.168.1.8 [110/128] via 192.168.1.6, 00:09:26, Serial1/1C 192.168.1.0 is directly connected, Serial1/0
  39. 39. www.ccieuniversity.comC 192.168.1.4 is directly connected, Serial1/14、Enable OSPF interface simple password authentication on R1.R1(config)#interface serial 1/1R1(config-if)#ip ospf authenticationR1(config-if)#ip ospf authentication-key www.ccieuniversity.comR1(config-if)#exit5、Enable OSPF debug on R1.R1#Debug ip ospf adj00:30:33: OSPF: 192.168.1.5 address 192.168.1.2 on Serial1/1 is dead00:30:33: OSPF: 192.168.1.5 address 192.168.1.2 on Serial1/1 is dead, state DOWN00:30:33: %OSPF-5-ADJCHG: Process 1, Nbr 192.168.1.5 on Serial1/1 from FULL toDOWN, Neighbor Down: Dead timer expired00:30:35: OSPF: Rcv pkt from 192.168.1.2, Serial1/1 : Mismatch Authentication type.Input packet specified type 0, we use type 100:54:45: OSPF: Rcv pkt from 192.168.1.2, Serial1/1 : Mismatch Authentication Key -Clear Text6、Enable OSPF interface simple password authentication on R2.R2(config)#interface s1/1R2(config-if)#ip ospf authenticationR2(config-if)#ip ospf authentication-key www.ccieuniversity.comR2(config-if)#exitR2(config)#exit7、Check the debug output again on R1.00:54:55: OSPF: 2 Way Communication to 192.168.1.5 on Serial1/1, state 2WAY00:54:55: OSPF: Send DBD to 192.168.1.5 on Serial1/1 seq 0x2154 opt 0x42 flag 0x7 len3200:54:55: OSPF: Rcv DBD from 192.168.1.5 on Serial1/1 seq 0x182 opt 0x42 flag 0x7 len32 mtu 1500 state EXSTART00:54:55: OSPF: NBR Negotiation Done. We are the SLAVE00:54:55: OSPF: Send DBD to 192.168.1.5 on Serial1/1 seq 0x182 opt 0x42 flag 0x2 len15200:54:55: OSPF: Rcv DBD from 192.168.1.5 on Serial1/1 seq 0x183 opt 0x42 flag 0x3 len152 mtu 1500 state EXCHANGE00:54:55: OSPF: Send DBD to 192.168.1.5 on Serial1/1 seq 0x183 opt 0x42 flag 0x0 len3200:54:55: OSPF: Database request to 192.168.1.500:54:55: OSPF: sent LS REQ packet to 192.168.1.2, length 6000:54:55: OSPF: Rcv DBD from 192.168.1.5 on Serial1/1 seq 0x184 opt 0x42 flag 0x1 len32 mtu 1500 state EXCHANGE
  40. 40. www.ccieuniversity.com00:54:55: OSPF: Exchange Done with 192.168.1.5 on Serial1/100:54:55: OSPF: Send DBD to 192.168.1.5 on Serial1/1 seq 0x184 opt 0x42 flagR1#0x0 len 3200:54:55: OSPF: Synchronized with 192.168.1.5 on Serial1/1, state FULL00:54:55: %OSPF-5-ADJCHG: Process 1, Nbr 192.168.1.5 on Serial1/1 from LOADING toFULL, Loading Done00:54:56: OSPF: Build router LSA for area 1, router ID 10.1.2.1, seq 0x8000000CR1#show ip routeGateway of last resort is not set 172.16.0.0/24 is subnetted, 2 subnetsO IA 172.16.1.0 [110/193] via 192.168.1.2, 00:01:53, Serial1/1O IA 172.16.2.0 [110/193] via 192.168.1.2, 00:01:53, Serial1/1 10.0.0.0/24 is subnetted, 2 subnetsC 10.1.2.0 is directly connected, Loopback0C 10.1.1.0 is directly connected, Loopback1 192.168.1.0/30 is subnetted, 3 subnetsO IA 192.168.1.8 [110/192] via 192.168.1.2, 00:01:53, Serial1/1C 192.168.1.0 is directly connected, Serial1/1O IA 192.168.1.4 [110/128] via 192.168.1.2, 00:01:53, Serial1/18、Remove OSPF interface simple password authentication and enable interface MD5authentication on R1 and R2.R1(config)#interface s1/1R1(config-if)#no ip ospf authenticationR1(config-if)#no ip ospf authentication-key www.ccieuniversity.comR1(config-if)#exitR1(config)#exitR2(config)#interface s1/1R2(config-if)#no ip ospf authenticationR2(config-if)#no ip ospf authentication-key www.ccieuniversity.comR2(config-if)#exitR2(config)#exitR1(config)#interface serial 1/1R1(config-if)#ip ospf authentication message-digestR1(config-if)#ip ospf message-digest-key 1 md5 www.ccieuniversity.comR1(config-if)#exitR1(config)#R2(config)#interface serial 1/0
  41. 41. www.ccieuniversity.comR2(config-if)#ip ospf authentication message-digestR2(config-if)#ip ospf message-digest-key 1 md5 www.ccieuniversity.comR2(config-if)#exitR2(config)#9、Check the routing table of R1.R1#show ip routeGateway of last resort is not set 172.16.0.0/24 is subnetted, 2 subnetsO IA 172.16.1.0 [110/193] via 192.168.1.2, 00:00:05, Serial1/1O IA 172.16.2.0 [110/193] via 192.168.1.2, 00:00:05, Serial1/1 10.0.0.0/24 is subnetted, 2 subnetsC 10.1.2.0 is directly connected, Loopback0C 10.1.1.0 is directly connected, Loopback1 192.168.1.0/30 is subnetted, 3 subnetsO IA 192.168.1.8 [110/192] via 192.168.1.2, 00:00:05, Serial1/1C 192.168.1.0 is directly connected, Serial1/1O IA 192.168.1.4 [110/128] via 192.168.1.2, 00:00:05, Serial1/110、Remove OSPF interface MD5 authentication and enable OSPF area simplepassword authentication on R1 and R2.R1(config)#interface serial 1/1R1(config-if)#no ip ospf authentication message-digestR1(config-if)#no ip ospf message-digest-key 1 md5 www.ccieuniversity.comR1(config-if)#exitR1(config)#R2(config)#interface serial 1/0R2(config-if)#no ip ospf authentication message-digestR2(config-if)#no ip ospf message-digest-key 1 md5 www.ccieuniversity.comR2(config-if)#exitR1(config)#router ospf 1R1(config-router)#area 1 authenticationR1(config-router)#exitR1(config)#interface serial 1/1R1(config-if)#ip ospf authentication-key www.ccieuniversity.comR1(config-if)#exitR1(config)#exitR2(config)#router ospf 1
  42. 42. www.ccieuniversity.comR2(config-router)#area 1 authenticationR2(config-router)#exitR2(config)#interface serial 1/0R2(config-if)#ip ospf authentication-key www.ccieuniversity.comR2(config-if)#exit11、Check the routing table on R1.R1#show ip routeGateway of last resort is not set 172.16.0.0/24 is subnetted, 2 subnetsO IA 172.16.1.0 [110/193] via 192.168.1.2, 00:01:19, Serial1/1O IA 172.16.2.0 [110/193] via 192.168.1.2, 00:01:19, Serial1/1 10.0.0.0/24 is subnetted, 2 subnetsC 10.1.2.0 is directly connected, Loopback0C 10.1.1.0 is directly connected, Loopback1 192.168.1.0/30 is subnetted, 3 subnetsO IA 192.168.1.8 [110/192] via 192.168.1.2, 00:01:19, Serial1/1C 192.168.1.0 is directly connected, Serial1/1O IA 192.168.1.4 [110/128] via 192.168.1.2, 00:01:19, Serial1/112、Remove OSPF area simple password authentication and enable OSPF area MD5authentication on R1 and R2.R1(config)#router ospf 1R1(config-router)#no area 1 authenticationR1(config-router)#exitR1(config)#interface serial 1/1R1(config-if)#no ip ospf authentication-key www.ccieuniversity.comR1(config-if)#exitR1(config)#exitR2(config)#router ospf 1R2(config-router)#no area 1 authenticationR2(config-router)#exitR2(config)#interface serial 1/0R2(config-if)#no ip ospf authentication-key www.ccieuniversity.comR2(config-if)#exitR1(config)#router ospf 1R1(config-router)#area 1 authentication message-digestR1(config-router)#exitR1(config)#interface serial 1/1
  43. 43. www.ccieuniversity.comR1(config-if)#ip ospf message-digest-key 1 md5 www.ccieuniversity.comR1(config-if)#exitR1(config)#R2(config)#router ospf 1R2(config-router)#area 1 authentication message-digestR2(config-router)#exitR2(config)#interface serial 1/0R2(config-if)#ip ospf message-digest-key 1 md5 www.ccieuniversity.comR2(config-if)#exitR2(config)#13、Check the routing table on R1.R1#show ip routeGateway of last resort is not set 172.16.0.0/24 is subnetted, 2 subnetsO IA 172.16.1.0 [110/193] via 192.168.1.2, 00:01:19, Serial1/1O IA 172.16.2.0 [110/193] via 192.168.1.2, 00:01:19, Serial1/1 10.0.0.0/24 is subnetted, 2 subnetsC 10.1.2.0 is directly connected, Loopback0C 10.1.1.0 is directly connected, Loopback1 192.168.1.0/30 is subnetted, 3 subnetsO IA 192.168.1.8 [110/192] via 192.168.1.2, 00:01:19, Serial1/1C 192.168.1.0 is directly connected, Serial1/1O IA 192.168.1.4 [110/128] via 192.168.1.2, 00:01:19, Serial1/1By www.ccieuniversity.com Configuring OSPF External Summary LabTopology
  44. 44. www.ccieuniversity.comLab Purpose:1、Master OSPF external route summary configuration.Lab Steps:1、Finish basic IP configuration, and routing configuration.2、Make R3 as the ASBR.R3(config)#router ospf 1R3(config-router)#network 192.168.1.4 0.0.0.3 area 0R3(config-router)#exitR3(config)#exitR3(config)#router ripR3(config-router)#network 172.16.0.0R3(config-router)#exit3、check the routing table on R1 and R2.R1#show ip routeGateway of last resort is not set 10.0.0.0/24 is subnetted, 2 subnetsC 10.1.2.0 is directly connected, Loopback1C 10.1.1.0 is directly connected, Loopback0 192.168.1.0/30 is subnetted, 2 subnetsC 192.168.1.0 is directly connected, Serial1/1O IA 192.168.1.4 [110/128] via 192.168.1.2, 00:03:50, Serial1/14、Enable redistribution on R3.R3(config)#router ospf 1R3(config-router)#redistribute rip metric 200 subnetsR3(config-router)#exit
  45. 45. www.ccieuniversity.comR3(config)#router ripR3(config-router)#redistribute ospf 1 metric 10R3(config-router)#exitR3(config)#5、Check the routing table on R1 again.R1#show ip routeGateway of last resort is not set 172.16.0.0/24 is subnetted, 3 subnetsO E1 172.16.1.0 [110/328] via 192.168.1.2, 00:04:22, Serial1/1O E1 172.16.2.0 [110/328] via 192.168.1.2, 00:04:22, Serial1/1O E1 172.16.3.0 [110/328] via 192.168.1.2, 00:04:22, Serial1/1 10.0.0.0/24 is subnetted, 2 subnetsC 10.1.2.0 is directly connected, Loopback1C 10.1.1.0 is directly connected, Loopback0 192.168.1.0/30 is subnetted, 2 subnetsC 1929999.168.1.0 is directly connected, Serial1/1O IA 192.168.1.4 [110/128] via 192.168.1.2, 00:16:54, Serial1/16、Check OSPF link state database on R1.R1#show ip ospf database OSPF Router with ID (10.1.2.1) (Process ID 1) Router Link States (Area 1)Link ID ADV Router Age Seq# Checksum Link count10.1.2.1 10.1.2.1 1413 0x80000009 0x0003FD 4192.168.1.5 192.168.1.5 1413 0x80000006 0x0025B8 2 Summary Net Link States (Area 1)Link ID ADV Router Age Seq# Checksum192.168.1.4 192.168.1.5 1437 0x80000001 0x00E33E Summary ASB Link States (Area 1)Link ID ADV Router Age Seq# Checksum192.168.1.6 192.168.1.5 1061 0x80000001 0x00D348 Type-5 AS External Link StatesLink ID ADV Router Age Seq# Checksum Tag172.16.1.0 192.168.1.6 3603 0x80000003 0x00CF35 0172.16.2.0 192.168.1.6 3603 0x80000003 0x00C43F 0
  46. 46. www.ccieuniversity.com172.16.3.0 192.168.1.6 3603 0x80000003 0x00B949 07、In order to decrease the routing table on R1, we could enable OSPF externalsummary on R3.R3(config)#router ospf 1R3(config-router)#summary-address 172.16.0.0 255.255.0.0R3(config-router)#exitR3(config)#exit8、Check the routing table on R1 again.R1#show ip routeGateway of last resort is not setO E1 172.16.0.0/16 [110/328] via 192.168.1.2, 00:01:29, Serial1/1 10.0.0.0/24 is subnetted, 2 subnetsC 10.1.2.0 is directly connected, Loopback1C 10.1.1.0 is directly connected, Loopback0 192.168.1.0/30 is subnetted, 2 subnetsC 192.168.1.0 is directly connected, Serial1/1O IA 192.168.1.4 [110/128] via 192.168.1.2, 00:24:56, Serial1/1By www.ccieuniversity.com Configuring OSPF Default Route With Metric LabTopology
  47. 47. www.ccieuniversity.comLab Purpose:1、Learn how to use metrics to control OSPF default route selection.Lab Steps:1、Finish basic IP configuration, and routing configuration.2、Finish frame-relay configuration on R1 and R4.R1(config)#interface serial 1/2R1(config-if)#encapsulation frame-relayR1(config-if)#ip ospf network broadcastR1(config-if)#ip address 172.16.1.1 255.255.255.252R1(config)#exitR4(config)#interface serial 1/2R4(config-if)#encapsulation frame-relayR4(config-if)#ip ospf network broadcastR4(config-if)#ip address 172.16.1.2 255.255.255.252R4(config)#exit3、Check routing table on R2, and try to ping the below RIP network.R2#show ip routeGateway of last resort is not set 192.168.1.0/30 is subnetted, 2 subnetsC 192.168.1.0 is directly connected, Serial1/0C 192.168.1.4 is directly connected, Serial1/1R2#R2#ping 10.1.1.1
  48. 48. www.ccieuniversity.comType escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:.....Success rate is 0 percent (0/5)4、To make sure the whole network is reachable, enable redistribution on R1 and R3.R1(config)#router ripR1(config-router)#redistribute ospf 1 metric 10R1(config-router)#exitR1(config)#R1(config)#router ospf 1R1(config-router)# default-information originate alwaysR1(config-router)#exitR1(config)#exitR3(config)#router ripR3(config-router)#redistribute ospf 1 metric 10R3(config-router)#exitR3(config)#R3(config)#router ospf 1R3(config-router)# default-information originate alwaysR3(config-router)#exitR3(config)#exit5、Check the routing table on R2 again and try to ping the below RIP network.R2#show ip routeGateway of last resort is not setO E2 10.0.0.0/8 [110/20] via 192.168.1.1, 00:01:19, Serial1/0 192.168.1.0/30 is subnetted, 2 subnetsC 192.168.1.0 is directly connected, Serial1/0C 192.168.1.4 is directly connected, Serial1/1O*E2 0.0.0.0/0 [110/1] via 192.168.1.6, 00:01:19, Serial1/1 [110/1] via 192.168.1.1, 00:01:19, Serial1/0R2#R2#ping 172.16.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 172.16.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 28/82/120 ms
  49. 49. www.ccieuniversity.com6、If we would like to make R3 as the major next-hop, R1 as the backup next-hop, thenwe could change the OSPF default route metric.R1(config)#router ospf 1R1(config-router)#default-information originate always metric 100R1(config-router)#exitR3(config)#router ospf 1R3(config-router)#default-information originate always metric 50R3(config-router)#exit7、Check the routing table of R2, we can see R3 is the next-hop now.R2#show ip routeCodes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static routeGateway of last resort is 192.168.1.6 to network 0.0.0.0O E2 10.0.0.0/8 [110/20] via 192.168.1.1, 00:08:05, Serial1/0 192.168.1.0/30 is subnetted, 2 subnetsC 192.168.1.0 is directly connected, Serial1/0C 192.168.1.4 is directly connected, Serial1/1O*E2 0.0.0.0/0 [110/50] via 192.168.1.6, 00:00:32, Serial1/1By www.ccieuniversity.com Configuring OSPF Stub Area LabTopology
  50. 50. www.ccieuniversity.comLab Purpose:1、Master OSPF stub area configuration.Lab Steps:1、Finish basic IP configuration.2、Finish basic OSPF and RIP configuration.3、Enable redistribution between OSPF and RIP on R3.R3(config)#router ospf 1R3(config-router)#redistribute rip subnets metric 200R3(config-router)#exitR3(config)#R3(config)#router ripR3(config-router)#redistribute ospf 1 metric 10R3(config-router)#exitR3(config)#exit4、Check routing table on R1.R1#show ip routeGateway of last resort is not set 172.16.0.0/16 is variably subnetted, 5 subnets, 2 masksC 172.16.255.0/30 is directly connected, Serial1/1O IA 172.16.255.4/30 [110/128] via 172.16.255.2, 00:07:32, Serial1/1O IA 172.16.255.8/30 [110/192] via 172.16.255.2, 00:06:57, Serial1/1C 172.16.1.0/24 is directly connected, Loopback0
  51. 51. www.ccieuniversity.comO IA 172.16.2.0/24 [110/193] via 172.16.255.2, 00:06:05, Serial1/1O E2 10.0.0.0/8 [110/200] via 172.16.255.2, 00:02:01, Serial1/1O E2 192.168.1.0/24 [110/200] via 172.16.255.2, 00:02:01, Serial1/1R1#R1#ping 10.1.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 672/788/984 msR1#5、Check OSPF link state database on R1.R1#show ip ospf database OSPF Router with ID (172.16.1.1) (Process ID 1) Router Link States (Area 1)Link ID ADV Router Age Seq# Checksum Link count172.16.1.1 172.16.1.1 682 0x80000003 0x003BE1 3172.16.255.5 172.16.255.5 677 0x80000003 0x0035B1 2 Summary Net Link States (Area 1)Link ID ADV Router Age Seq# Checksum172.16.2.0 172.16.255.5 581 0x80000001 0x004CEE172.16.255.4 172.16.255.5 668 0x80000001 0x009BE1172.16.255.8 172.16.255.5 633 0x80000001 0x00F543 Summary ASB Link States (Area 1)Link ID ADV Router Age Seq# Checksum192.168.1.1 172.16.255.5 342 0x80000001 0x008648 Type-5 AS External Link StatesLink ID ADV Router Age Seq# Checksum Tag10.0.0.0 192.168.1.1 348 0x80000001 0x005B1B 0192.168.1.0 192.168.1.1 348 0x80000001 0x0021F4 06、According to the above output we can see external routes are in the routing table ofR1, if we would like to use a default route instead of the specific external routes, wecould set stub area.R1(config)#router ospf 1R1(config-router)#area 1 stubR1(config-router)#exitR1(config)#exit
  52. 52. www.ccieuniversity.comR2(config)#router ospf 1R2(config-router)#area 1 stubR2(config-router)#exitR2(config)#7、Check OSPF link state database again.R1#show ip ospf database OSPF Router with ID (172.16.1.1) (Process ID 1) Router Link States (Area 1)Link ID ADV Router Age Seq# Checksum Link count172.16.1.1 172.16.1.1 155 0x80000005 0x0055C7 3172.16.255.5 172.16.255.5 155 0x80000005 0x004F97 2 Summary Net Link States (Area 1)Link ID ADV Router Age Seq# Checksum0.0.0.0 172.16.255.5 168 0x80000001 0x00017B172.16.2.0 172.16.255.5 168 0x80000002 0x0068D3172.16.255.4 172.16.255.5 168 0x80000002 0x00B7C6172.16.255.8 172.16.255.5 168 0x80000002 0x001228Type 4 and type 5 LSA is not in the database of R1.8、Check the routing table of R1 we can see there is a default route instead theprevious external routes.R1#show ip routeGateway of last resort is 172.16.255.2 to network 0.0.0.0 172.16.0.0/16 is variably subnetted, 5 subnets, 2 masksC 172.16.255.0/30 is directly connected, Serial1/1O IA 172.16.255.4/30 [110/128] via 172.16.255.2, 00:04:19, Serial1/1O IA 172.16.255.8/30 [110/192] via 172.16.255.2, 00:04:19, Serial1/1C 172.16.1.0/24 is directly connected, Loopback0O IA 172.16.2.0/24 [110/193] via 172.16.255.2, 00:04:19, Serial1/1O*IA 0.0.0.0/0 [110/65] via 172.16.255.2, 00:04:19, Serial1/19、Ping to test the connectivity.R1#ping 10.1.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:
  53. 53. www.ccieuniversity.com!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 240/393/684 msBy www.ccieuniversity.com Configuring OSPF Totally Stub Area LabTopologyLab Purpose:1、Master OSPF totally stub area configuration.Lab Steps:1、Finish basic IP configuration.2、Finish basic OSPF and RIP configuration.3、Enable redistribution between OSPF and RIP on R3.R3(config)#router ospf 1R3(config-router)#redistribute rip subnets metric 200R3(config-router)#exitR3(config)#R3(config)#router ripR3(config-router)#redistribute ospf 1 metric 10R3(config-router)#exitR3(config)#exit
  54. 54. www.ccieuniversity.com4、First Set area 1 as ospf stub area.5、Check OSPF routing table and OSPF links state database.R1#show ip ospf database OSPF Router with ID (172.16.1.1) (Process ID 1) Router Link States (Area 1)Link ID ADV Router Age Seq# Checksum Link count172.16.1.1 172.16.1.1 155 0x80000005 0x0055C7 3172.16.255.5 172.16.255.5 155 0x80000005 0x004F97 2 Summary Net Link States (Area 1)Link ID ADV Router Age Seq# Checksum0.0.0.0 172.16.255.5 168 0x80000001 0x00017B172.16.2.0 172.16.255.5 168 0x80000002 0x0068D3172.16.255.4 172.16.255.5 168 0x80000002 0x00B7C6172.16.255.8 172.16.255.5 168 0x80000002 0x001228Type 4 and 5 LSA have gone.R1#show ip routeGateway of last resort is 172.16.255.2 to network 0.0.0.0 172.16.0.0/16 is variably subnetted, 5 subnets, 2 masksC 172.16.255.0/30 is directly connected, Serial1/1O IA 172.16.255.4/30 [110/128] via 172.16.255.2, 00:04:19, Serial1/1O IA 172.16.255.8/30 [110/192] via 172.16.255.2, 00:04:19, Serial1/1C 172.16.1.0/24 is directly connected, Loopback0O IA 172.16.2.0/24 [110/193] via 172.16.255.2, 00:04:19, Serial1/1O*IA 0.0.0.0/0 [110/65] via 172.16.255.2, 00:04:19, Serial1/16、We can see there is a default route instead of external routes, we can still decreasethe size of routing table.R2(config)#router ospf 1R2(config-router)#area 1 stub no-summaryR2(config-router)#exitR2(config)#exitR1(config)#router ospf 1R1(config-router)#area 1 stubR1(config-router)#exitR1(config)#exit
  55. 55. www.ccieuniversity.com7、Check the routing table of R1.R1#show ip routeCodes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static routeGateway of last resort is 172.16.255.2 to network 0.0.0.0 172.16.0.0/16 is variably subnetted, 2 subnets, 2 masksC 172.16.255.0/30 is directly connected, Serial1/1C 172.16.1.0/24 is directly connected, Loopback0O*IA 0.0.0.0/0 [110/65] via 172.16.255.2, 00:34:32, Serial1/1We can see the default route instead of all the external and inter-area routes.8、Check the OSPF link state database of R1, we can see there are only type 1 LSA andtype 3 for default route link LSA.R1#show ip ospf database OSPF Router with ID (172.16.1.1) (Process ID 1) Router Link States (Area 1)Link ID ADV Router Age Seq# Checksum Link count172.16.1.1 172.16.1.1 387 0x80000006 0x0053C8 3172.16.255.5 172.16.255.5 412 0x80000006 0x004D98 2 Summary Net Link States (Area 1)Link ID ADV Router Age Seq# Checksum0.0.0.0 172.16.255.5 295 0x80000003 0x00FC7D9、Ping to test.R1#ping 10.1.1.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:.!!!!Success rate is 80 percent (4/5), round-trip min/avg/max = 216/570/1488 msBy www.ccieuniversity.com
  56. 56. www.ccieuniversity.com Configuring OSPF NSSA Area and NSSA Totally Stub LabTopologyLab Purpose:1、Master NSSA area and NSSA totally stub area configuration.Lab Steps:1、Finish basic IP configuration.2、Finish basic OSPF and RIP configuration.3、Enable redistribution on R2 and R5.R2(config)#router ospf 1R2(config-router)#redistribute rip metric 200 subnetsR2(config-router)#exitR2(config)#R2(config)#router ripR2(config-router)#redistribute ospf 1 metric 10R2(config-router)#exitR2(config)#exitR5(config)#router ospf 1R5(config-router)#redistribute rip metric 200 subnetsR5(config-router)#exitR5(config)#R5(config)#router ripR5(config-router)#redistribute ospf 1 metric 10R5(config-router)#exitR5(config)#exit4、Check OSPF routing table and link state database on R3.
  57. 57. www.ccieuniversity.comR3#show ip ospf database OSPF Router with ID (172.16.255.5) (Process ID 1) Router Link States (Area 1)Link ID ADV Router Age Seq# Checksum Link count172.16.255.1 172.16.255.1 534 0x80000005 0x008564 2172.16.255.5 172.16.255.5 679 0x80000004 0x007390 4172.16.255.9 172.16.255.9 672 0x80000003 0x00A42F 2 Summary Net Link States (Area 1)Link ID ADV Router Age Seq# Checksum172.16.255.8 172.16.255.9 662 0x80000001 0x005B1A Summary ASB Link States (Area 1)Link ID ADV Router Age Seq# Checksum192.168.1.1 172.16.255.9 98 0x80000001 0x006E5C Type-5 AS External Link StatesLink ID ADV Router Age Seq# Checksum Tag131.131.1.0 172.16.255.1 513 0x80000001 0x007BAA 0131.131.2.0 172.16.255.1 513 0x80000001 0x0070B4 0192.168.1.0 192.168.1.1 94 0x80000002 0x001FF5 0192.168.2.0 192.168.1.1 94 0x80000002 0x0014FF 0R3#R3#show ip routeGateway of last resort is not set 172.16.0.0/30 is subnetted, 3 subnetsC 172.16.255.0 is directly connected, Serial1/0C 172.16.255.4 is directly connected, Serial1/1O IA 172.16.255.8 [110/128] via 172.16.255.6, 00:07:46, Serial1/1 131.131.0.0/24 is subnetted, 2 subnetsO E2 131.131.1.0 [110/200] via 172.16.255.1, 00:00:30, Serial1/0O E2 131.131.2.0 [110/200] via 172.16.255.1, 00:00:30, Serial1/0O E2 192.168.1.0/24 [110/200] via 172.16.255.6, 00:00:30, Serial1/1O E2 192.168.2.0/24 [110/200] via 172.16.255.6, 00:00:30, Serial1/14、As area1 connects to an external network, so we could not set area1 to a pure stubarea.
  58. 58. www.ccieuniversity.com5、Set area1 to NSSA stub area on R4.R4(config)#router ospf 1R4(config-router)#area 1 nssa default-information-originateR4(config-router)#exitR4(config)#6、Set area1 to NSSA stub area on R3.R3(config)#router ospf 1R3(config-router)#area 1 nssaR3(config-router)#exitR3(config)#exit7、Set area1 to NSSA stub area on R2.R2(config)#router ospf 1R2(config-router)#area 1 nssaR2(config-router)#exitR2(config)#exit8、Check OSPF routing table and link state database on R3 again.R3#show ip routeGateway of last resort is 172.16.255.6 to network 0.0.0.0 172.16.0.0/30 is subnetted, 3 subnetsC 172.16.255.0 is directly connected, Serial1/0C 172.16.255.4 is directly connected, Serial1/1O IA 172.16.255.8 [110/128] via 172.16.255.6, 00:01:10, Serial1/1 131.131.0.0/24 is subnetted, 2 subnetsO N2 131.131.1.0 [110/200] via 172.16.255.1, 00:01:10, Serial1/0O N2 131.131.2.0 [110/200] via 172.16.255.1, 00:01:10, Serial1/0O*N2 0.0.0.0/0 [110/1] via 172.16.255.6, 00:01:10, Serial1/1R3#show ip ospf database OSPF Router with ID (172.16.255.5) (Process ID 1) Router Link States (Area 1)Link ID ADV Router Age Seq# Checksum Link count172.16.255.1 172.16.255.1 314 0x80000007 0x0027BA 2172.16.255.5 172.16.255.5 314 0x80000008 0x0011E8 4172.16.255.9 172.16.255.9 450 0x80000005 0x004C7D 2
  59. 59. www.ccieuniversity.com Summary Net Link States (Area 1)Link ID ADV Router Age Seq# Checksum172.16.255.8 172.16.255.9 850 0x80000002 0x00FE6F Type-7 AS External Link States (Area 1)Link ID ADV Router Age Seq# Checksum Tag0.0.0.0 172.16.255.9 850 0x80000001 0x00C464 0131.131.1.0 172.16.255.1 318 0x80000001 0x00213D 0131.131.2.0 172.16.255.1 318 0x80000001 0x001647 09、Check routing table on R1 and R2.R2#show ip routeGateway of last resort is 172.16.255.2 to network 0.0.0.0 172.16.0.0/30 is subnetted, 3 subnetsC 172.16.255.0 is directly connected, Serial1/1O 172.16.255.4 [110/128] via 172.16.255.2, 00:07:26, Serial1/1O IA 172.16.255.8 [110/192] via 172.16.255.2, 00:07:26, Serial1/1 131.131.0.0/24 is subnetted, 2 subnetsR 131.131.1.0 [120/1] via 131.131.2.2, 00:00:06, Serial1/0C 131.131.2.0 is directly connected, Serial1/0O*N2 0.0.0.0/0 [110/1] via 172.16.255.2, 00:07:26, Serial1/1R1#show ip routeGateway of last resort is 131.131.2.1 to network 0.0.0.0R 172.16.0.0/16 [120/10] via 131.131.2.1, 00:00:28, Serial1/1 131.131.0.0/24 is subnetted, 2 subnetsC 131.131.1.0 is directly connected, Loopback0C 131.131.2.0 is directly connected, Serial1/1R* 0.0.0.0/0 [120/10] via 131.131.2.1, 00:00:28, Serial1/110、Ping test on R1.R1#ping 192.168.2.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.2.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 288/384/432 ms11、To deeply decrease the routing table in area1, we need to set area1 to Totally NSSAarea.
  60. 60. www.ccieuniversity.com12、Only one command need to add on ABR router (R4) to change NSSA to totally NSSA.R4(config)#router ospf 1R4(config-router)#area 1 nssa no-summaryR4(config-router)#exit13、Check OSPF routing table and link state database on R3 again.R3#show ip routeGateway of last resort is 172.16.255.6 to network 0.0.0.0 172.16.0.0/30 is subnetted, 2 subnetsC 172.16.255.0 is directly connected, Serial1/0C 172.16.255.4 is directly connected, Serial1/1 131.131.0.0/24 is subnetted, 2 subnetsO N2 131.131.1.0 [110/200] via 172.16.255.1, 00:20:24, Serial1/0O N2 131.131.2.0 [110/200] via 172.16.255.1, 00:20:24, Serial1/0O*IA 0.0.0.0/0 [110/65] via 172.16.255.6, 00:02:10, Serial1/1R3#show ip ospf database OSPF Router with ID (172.16.255.5) (Process ID 1) Router Link States (Area 1)Link ID ADV Router Age Seq# Checksum Link count172.16.255.1 172.16.255.1 1504 0x80000007 0x0027BA 2172.16.255.5 172.16.255.5 1504 0x80000008 0x0011E8 4172.16.255.9 172.16.255.9 1640 0x80000005 0x004C7D 2 Summary Net Link States (Area 1)Link ID ADV Router Age Seq# Checksum0.0.0.0 172.16.255.9 396 0x80000001 0x0070FF Type-7 AS External Link States (Area 1)Link ID ADV Router Age Seq# Checksum Tag0.0.0.0 172.16.255.9 66 0x80000002 0x00C265 0131.131.1.0 172.16.255.1 1508 0x80000001 0x00213D 0131.131.2.0 172.16.255.1 1508 0x80000001 0x001647 014、Check routing table on R1 and R2 and do the ping test.R2#show ip routeGateway of last resort is 172.16.255.2 to network 0.0.0.0
  61. 61. www.ccieuniversity.com 172.16.0.0/30 is subnetted, 2 subnetsC 172.16.255.0 is directly connected, Serial1/1O 172.16.255.4 [110/128] via 172.16.255.2, 00:23:09, Serial1/1 131.131.0.0/24 is subnetted, 2 subnetsR 131.131.1.0 [120/1] via 131.131.2.2, 00:00:17, Serial1/0C 131.131.2.0 is directly connected, Serial1/0O*IA 0.0.0.0/0 [110/129] via 172.16.255.2, 00:04:46, Serial1/1R2#R1#show ip routeGateway of last resort is 131.131.2.1 to network 0.0.0.0R 172.16.0.0/16 [120/10] via 131.131.2.1, 00:00:13, Serial1/1 131.131.0.0/24 is subnetted, 2 subnetsC 131.131.1.0 is directly connected, Loopback0C 131.131.2.0 is directly connected, Serial1/1R* 0.0.0.0/0 [120/10] via 131.131.2.1, 00:00:13, Serial1/1R1#ping 192.168.2.1Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.2.1, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 336/454/528 ms15、Finally we can see the type 7 LSA has been changed to type 5 LAS.R5#show ip ospf database OSPF Router with ID (192.168.1.1) (Process ID 1) Router Link States (Area 0)Link ID ADV Router Age Seq# Checksum Link count172.16.255.9 172.16.255.9 338 0x80000004 0x005DC2 2192.168.1.1 192.168.1.1 767 0x80000004 0x002753 2 Summary Net Link States (Area 0)Link ID ADV Router Age Seq# Checksum172.16.255.0 172.16.255.9 81 0x80000002 0x002C10172.16.255.4 172.16.255.9 1337 0x80000002 0x0081F6 Type-5 AS External Link StatesLink ID ADV Router Age Seq# Checksum Tag
  62. 62. www.ccieuniversity.com131.131.1.0 172.16.255.9 1761 0x80000001 0x0085DA 0131.131.2.0 172.16.255.9 1761 0x80000001 0x007AE4 0192.168.1.0 192.168.1.1 767 0x80000003 0x001DF6 0192.168.2.0 192.168.1.1 767 0x80000003 0x001201 0By www.ccieuniversity.comConfiguring OSPF Virtual-Link between normal area and backbone area LabTopologyLab Purpose:1、Master OSPF Virtual-Link between normal area and backbone area configuration.Lab Steps:1、Finish basic IP configuration.2、Finish basic OSPF configuration on R1 R2 R3 R4.R1(config)#router ospf 1R1(config-router)#network 172.16.255.0 0.0.0.3 area 3R1(config-router)#network 172.16.1.0 0.0.0.255 area 3R1(config-router)#exitR1(config)#exitR2(config)#router ospf 1R2(config-router)#network 172.16.255.4 0.0.0.3 area 2R2(config-router)#network 172.16.255.0 0.0.0.3 area 3
  63. 63. www.ccieuniversity.comR2(config-router)#exitR2(config)#exitR3(config)#router ospf 1R3(config-router)#network 172.16.255.4 0.0.0.3 area 2R3(config-router)#network 172.16.255.8 0.0.0.3 area 0R3(config-router)#exitR3(config)#exitR4(config)#router ospf 1R4(config-router)#network 172.16.255.8 0.0.0.3 area 0R4(config-router)#network 172.16.16.0 0.0.0.255 area 1R4(config-router)#exitR4(config)#exit3、Check the neighbor table on R1 and R2.R1#show ip ospf neighborNeighbor ID Pri State Dead Time Address Interface172.16.255.5 1 FULL/ - 00:00:38 172.16.255.2 Serial1/1R2#show ip ospf neighborNeighbor ID Pri State Dead Time Address Interface172.16.255.9 1 FULL/ - 00:00:37 172.16.255.6 Serial1/1172.16.1.1 1 FULL/ - 00:00:30 172.16.255.1 Serial1/04、Check the routing table on R1.R1#show ip routeGateway of last resort is not set 172.16.0.0/16 is variably subnetted, 2 subnets, 2 masksC 172.16.255.0/30 is directly connected, Serial1/1C 172.16.1.0/24 is directly connected, Loopback0Above information tells us R1 could not learn route from area 0, area1, area2, as area3is not directly connected with area0.5、To solve this issue, we could establish a virtual-link between R2 and R3.R2(config)#router ospf 1R2(config-router)#area 2 virtual-link 172.16.255.9 (RID of R3)R2(config-router)#exitR2(config)#exit

×