跳到主要內容

OSPF 指令小記

1.Classless
2.Link-State Protocol
3.靠Hello Packets建鄰居關係,定時送Link-State Advertisement(LSA), LSA會丟給同一個Area的Router(要先建鄰居關係才會交換路由與RIP不同),每個Router會把收到LSA集合成Link State Database,並用SPF演算法算出最佳路徑

Hello Packets(Router ID(獨一無二),Hello and dead Intervals,Area ID,Authentication,Stub Area Flag.....)
Hello Packets每10秒丟一次


OSPF有3張Table
Adjacency Table (鄰居關係)
需要Hello And Dead Intervals,AreaID,Authentication,Stub Area Flag相同,鄰居關才才會建起來!


Topology Database(Link State Database)

     |
     |    (SPF演算法)
     |
    V

Routing Table(Forwarding Table)

OSPF不會定時會更新,只有Topology改變時,才會更新Routing Table


-------------------------------------------------------
Router ID
-------------------------------------------------------
預設為所有UP的介面,最大的IP
例如:

Router#show ip ospf
 Routing Process "ospf 168" with ID 10.2.2.2
 Supports only single TOS(TOS0) routes
 Supports opaque LSA
 SPF schedule delay 5 secs, Hold time between two SPFs 10 secs
 Minimum LSA interval 5 secs. Minimum LSA arrival 1 secs
 Number of external LSA 0. Checksum Sum 0x000000
 Number of opaque AS LSA 0. Checksum Sum 0x000000
 Number of DCbitless external and opaque AS LSA 0
 Number of DoNotAge external and opaque AS LSA 0
 Number of areas in this router is 1. 1 normal 0 stub 0 nssa
 External flood list length 0
    Area BACKBONE(0) (Inactive)
        Number of interfaces in this area is 0
        Area has no authentication
        SPF algorithm executed 1 times
        Area ranges are
        Number of LSA 1. Checksum Sum 0x009dc7
        Number of opaque link LSA 0. Checksum Sum 0x000000
        Number of DCbitless LSA 0
        Number of indication LSA 0
        Number of DoNotAge LSA 0
        Flood list length 0


Router#show ip interface brief
Interface              IP-Address      OK? Method Status                Protocol

FastEthernet0/0        10.1.1.2        YES manual up                    down

FastEthernet0/1        10.2.2.2        YES manual up                    down

Vlan1                  unassigned      YES unset  administratively down down

( Protocol Down 的原因是我沒接網路線,如果要重設Router ID,要先把原本的OSPF no掉)



-------------------------------------------------------
假設有一Router有兩個介面
-------------------------------------------------------

FA 0   ==> IP  10.2.2.2/16
FA 1   ==> IP  10.1.1.2/16


B2#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
B2(config)#router ospf 100   --->100為 Process ID (Process ID不同也不會影響鄰居關係的建立)
B2(config-router)#network 10.2.2.2 0.0.0.0 area 0  (在這個介面啟用OSPF)
B2(config-router)#network 10.1.1.2 0.0.0.0 area 0  (在這個介面啟用OSPF)


-------------------------------------------------------
如果有介面不想收送Routing Update,可以使用以下指令
-------------------------------------------------------
B2(config-router)#passive-interface serial 0/0/0




---------------------------------------------------
Loopback (設完可以當OSPF的Router ID)
-------------------------------------------------------

B1(config)#interface loopback 0

%LINK-5-CHANGED: Interface Loopback0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface Loopback0, changed state to up

B1(config-if)#ip address 1.1.1.1 255.255.255.0

(不用no shutdown)


---------------------------------------------------
檢查指令
-------------------------------------------------------
show ip route
show ip protocol
show ip ospf
show ip ospf interface  (列出有哪些介面啟用OSPF)

show ip ospf neighbor



---------------------------------------------------
啟用Load Balancing
-------------------------------------------------------
maximum-paths 6



-------------------------------------------------------
停用Load Balancing
-------------------------------------------------------
maximum-paths 1


-------------------------------------------------------
啟用驗證,在介面下(收送都做驗證)
-------------------------------------------------------
Core(config-if)#ip ospf authentication-key abc   (密碼為abc)
Core(config-if)#ip ospf authentication message-digest   (打完這行才有啟用,並且用MD5加密)


相關介紹請參考這裡

留言

這個網誌中的熱門文章

HP A5120 Switch 基本設定

沒用過HP的Switch,指令跟Cisco完全不同,花了一些時間熟悉~ 1.啟動Spanning-Tree,預設沒有開啟 (黑色粗體是我敲的指令) <HP> system-view System View: return to User View with Ctrl+Z. [HP] stp enable [HP] %Apr 26 12:03:59:826 2000 HP MSTP/6/MSTP_ENABLE: STP is now enabled on the device. %Apr 26 12:03:59:918 2000 HP MSTP/6/MSTP_FORWARDING: Instance 0's GigabitEthernet1/0/17 has been set to forwarding state. %Apr 26 12:04:00:068 2000 HP MSTP/6/MSTP_DETECTED_TC: Instance 0's GigabitEthernet1/0/17 detected a topology change. #Apr 26 12:04:00:208 2000 HP MSTP/1/PFWD: hwPortMstiStateForwarding: Instance 0's Port 0.9437200 has been set to forwarding state! 2.DHCP Snooping   (黑色粗體是我敲的指令) 假設我的DHCP Server接在24 Port,其他Port不允許有DHCP Server <HP> system-view System View: return to User View with Ctrl+Z. [HP] dhcp-snooping  DHCP Snooping is enabled. [HP] interface GigabitEthernet 1/0/24 [HP-GigabitEthernet1/0/24 ]dhcp-snooping trust 若是沒有Port 設成dhcp-snooping trust,那麼這台Switch就沒有Client可以從DHCP Serv...

2台 Vigor 2920建立 LAN To LAN VPN (IPsec)

我有兩台Vigor 2920,環境如下: Vigor B 撥出 LAN:192.168.1.0/24 Vigor A 撥入 LAN:172.16.1.0/24 設定如下: Vigor B設定 Vigor A設定 詳細設定請參考官網 http://www.draytek.com/index.php?option=com_k2&view=item&id=2666&Itemid=264&lang=tw

Draytek Vigor 2927

其實心中一直感覺用了十年的Vigor 2920n會掛掉,因為先前也有一台2920n壞過,所以心中也有個底,但突然壞了也真讓人心驚驚! 其實最近都在用Unifi的設備,但考量目前的工作環境與網路需求,就直接更換最新的Vigor 2927,雖然2920n的備份檔不能直接倒回去,不過之前的設定參數都有抓圖下來,所以很快就把設定設回去,這也算是用習慣Draytek的好處~ 下一篇會說明怎麼建立Unifi Dream Machine Pro與Vigor 2927的Site To Site VPN。