《12、RIP防环.pptx》由会员分享,可在线阅读,更多相关《12、RIP防环.pptx(27页珍藏版)》请在得力文库 - 分享文档赚钱的网站上搜索。
1、路由环路及解决方法RIP目 录1RIP路由环路2环路解决方法3基本配置RIP-环路Page 3l当网络发生故障时,RIP网络有可能产生路由环路。10.0.0.0/810.0.0.0/8 Metric=2RTBRTADestination/Mask Nexthop metric10.0.0.0/8 192.168.1.2 2192.168.1.2/24192.168.1.1/241R1R2R310.0.0.020.0.0.030.0.0.040.0.0.0.1.1.2.2Routing TableNetHopNext Hop10.0.0.0120.0.0.120.0.0.0030.0.0.004
2、0.0.0.0130.0.0.2Routing TableNetHopNext Hop10.0.0.0230.0.0.120.0.0.0130.0.0.130.0.0.0040.0.0.00Routing TableNetHopNext Hop10.0.0.0020.0.0.0030.0.0.0120.0.0.240.0.0.0220.0.0.2路由环路是指数据包在一系列路由器之间不断传输却始终无法到达其预期目的网络的一种现象。RIP-环路1R1R2R310.0.0.020.0.0.030.0.0.040.0.0.0.1.1.2.2发送发送40.0.0.0的跳数的跳数为为2的的更新信息更新信息
3、Routing TableNetHopNext Hop10.0.0.0120.0.0.120.0.0.0030.0.0.0040.0.0.0130.0.0.2Routing TableNetHopNext Hop10.0.0.0230.0.0.120.0.0.0130.0.0.130.0.0.0040.0.0.016Routing TableNetHopNext Hop10.0.0.0020.0.0.0030.0.0.0120.0.0.240.0.0.0220.0.0.2被标记为无效被标记为无效RIP-环路1R1R2R310.0.0.020.0.0.030.0.0.040.0.0.0.1.1.
4、2.2Routing TableNetHopNext Hop10.0.0.0120.0.0.120.0.0.0030.0.0.0040.0.0.0130.0.0.2Routing TableNetHopNext Hop10.0.0.0230.0.0.120.0.0.0130.0.0.130.0.0.0040.0.0.0230.0.0.1Routing TableNetHopNext Hop10.0.0.0020.0.0.0030.0.0.0120.0.0.240.0.0.0220.0.0.2发送发送40.0.0.0的路由更的路由更新,跳数新,跳数为为3跳数为跳数为2跳,下一条地跳,下一条地址为
5、址为30.0.0.1RIP-环路1R1R2R310.0.0.020.0.0.030.0.0.040.0.0.0.1.1.2.2产生路由环路,直到产生路由环路,直到跳数增加到跳数增加到16为止为止Routing TableNetHopNext Hop10.0.0.0120.0.0.120.0.0.0030.0.0.0040.0.0.0330.0.0.2Routing TableNetHopNext Hop10.0.0.0230.0.0.120.0.0.0130.0.0.130.0.0.0040.0.0.0230.0.0.1Routing TableNetHopNext Hop10.0.0.002
6、0.0.0.0030.0.0.0120.0.0.240.0.0.0220.0.0.2将跳数改变为将跳数改变为3跳跳RIP-环路1环路避免-水平分割Page 8l路由器从某个接口学到的路由,不会从该接口再发回给邻居路由器。10.0.0.0/810.0.0.0/8 Metric=2RTBRTA192.168.1.2/24192.168.1.1/242环路避免-毒性反转Page 9l毒性反转是指路由器从某个接口学到路由后,将该路由的跳数设置为16,并从原接收接口发回给邻居路由器。10.0.0.0/810.0.0.0/8 Metric=16RTBRTADestination/Mask Nexthop
7、metric10.0.0.0/8 192.168.1.2 16192.168.1.2/24192.168.1.1/242环路避免-触发更新Page 10l触发更新是指当路由信息发生变化时,立即向邻居设备发送触发更新报文。10.0.0.0/810.0.0.0/8 Metric=16RTBRTA192.168.1.2/24192.168.1.1/242Page11RIPv1 vs.RIPv2RIPv1是有类别路由协议,不支持VLSM和CIDR。以广播的形式发送报文。不支持认证。RIPv2为无类别路由协议,支持VLSM,支持路由聚合与CIDR。支持以广播或者组播(224.0.0.9)方式发送报文。支
8、持明文认证和 MD5 密文认证。3RIPv1报文格式Page 12UDP 端口:520目的地址:255.255.255.255Must be ZeroMust be ZeroG0/0/0 G0/0/0 IP AddressMetricCommandAddress Family IdentifierVersionRTBRTAMust be ZeroMust be Zero3RIPv2报文格式Page 13UnusedIP AddressSubnet MaskMetricCommandAddress Family IdentifierVersionRoute TagNext HopUDP端口:52
9、0目的地址:224.0.0.9G0/0/0 G0/0/0 RTBRTA3RIPv2认证Page 14lRIPv2支持对协议报文进行认证,认证方式有明文认证和MD5认证两种。Authentication0XFFFFAuthentication TypePassword:huaweiUnusedCommandVersionG0/0/0 G0/0/0 RTBRTAPassword:huawei3RIP基本配置Page 15RTARTBRTCRTD10.0.0.0/8启动RIP进程:RTArip定义RIP的版本:RTA-rip-1version 2 宣告网段:RTA-rip-1network 10.0
10、.0.04RIP配置实例172.16.1.0/2410.1.1.0/3010.1.2.0172.16.4.0/24.1.1.2.2路由器路由器A路由器路由器B路由器路由器C.1.1F 0/1F0/0F0/0F0/1F0/0RTArip RTA-rip-1version 2 RTA-rip-1undo summaryRTA-rip-1network network 172.16.0.0172.16.0.0RTA-rip-1network network 10.0.0.010.0.0.0路由路由路由路由B B、C C配置类似配置类似配置类似配置类似F 0/1关闭RIPv2自动汇总Routerund
11、o summary RIP缺省将进行路由自动汇总:当子网路由穿越有类网络边界时,将自动汇总成有类网络路由手工精确汇总R2rip summary-address 172.16.0.0 255.255.252.0 172.16.0.0/24172.16.1.0/24172.16.2.0/24172.16.3.0/24R1R210.1.1.0.1.2RIP基本配置4RIP配置-MetricinPage 18RTARTCRTD10.0.0.0/810.0.0.0/8 Metric=1RTBG0/0/0 192.168.1.0/24RTCinterface GigabitEthernet 0/0/0 R
12、TC-GigabitEthernet0/0/0rip metricin 24RIP配置-MetricoutPage 19RTARTCRTD10.0.0.0/8RTBG0/0/0 Metric=1192.168.1.0/24RTAinterface GigabitEthernet 0/0/0 RTA-GigabitEthernet0/0/0rip metricout 24水平分割&毒性逆转Page 20l两个特性同时配置后,只有rip poison-reverse会生效。RTARTCRTD10.0.0.0/8RTBG0/0/0 RTCinterface GigabitEthernet 0/0/0
13、 RTC-GigabitEthernet0/0/0rip split-horizonRTC-GigabitEthernet0/0/0rip poison-reverse4配置验证Page 21RTC display rip 1 interface GigabitEthernet0/0/0 verbose GigabitEthernet0/0/0(192.168.1.2)State :UP MTU :500 Metricin :2 Metricout :1 Input :Enabled Output:Enabled Protocol :RIPv2 Multicast Send version :
14、RIPv2 Multicast Packets Receive version:RIPv2 Multicast and Broadcast Packets Poison-reverse :Enabled Split-Horizon :Enabled Authentication type :None Replay Protection :Disabled l虽然两者都显示“Enabled”,但只有“Poison-reverse”生效。4RIP配置-OutputPage 22l配置RTA的G0/0/0 接口禁止发送RIP报文。RTARTCRTD10.0.0.0/8RTBG0/0/0 10.0.0
15、.0/8 Metric=1 RTAinterface GigabitEthernet 0/0/0RTA-GigabitEthernet0/0/0undo rip output4RIP配置-InputPage 23l配置RTD的G0/0/0 接口禁止接收RIP报文。RTARTCRTD10.0.0.0/8RTB10.0.0.0/8 Metric=1 G0/0/1 192.168.1.1RTDinterface GigabitEthernet 0/0/1RTD-GigabitEthernet0/0/1undo rip inputG0/0/0 192.168.1.24抑制接口Page 24l配置G0/
16、0/1接口为抑制状态,只接收RIP 报文。l此命令的优先级大于rip input和rip output。RTDripRTD-rip-1silent-interface GigabitEthernet 0/0/1RTARTCRTD10.0.0.0/8RTB10.0.0.0/8 Metric=1 G0/0/1 192.168.1.1G0/0/0 192.168.1.24配置验证Page 25RTD display ripPublic VPN-instance RIP process:1 RIP version :2 Preference :100 Checkzero :Enabled Default-cost :0 Summary :Enabled Host-route :Enabled Maximum number of balanced paths:8 Update time :30 sec Age time:180 sec Garbage-collect time:120 sec Graceful restart :Disabled BFD :Disabled Silent-interfaces:GigabitEthernet0/0/14Page 26总结lRIP环路的避免方法lRIP的配置27 作业:第九章单元测试9.3和9.4视频、随堂测试