BGP联邦反射器

BGP联邦反射器

Itachi

实验要求

  1. R2-7 每台路由器均存在一个环回接口用于建邻,同时还存在一个环回来代表连接用户的接口
  2. 连接用户的接口网络需要可以和 R1/8 的环回通讯
  3. AS2 网段地址为 172.16.0.0/16,要求减少路由条目
    img

实验过程

IP地址划分

在AS 2中,基于 172.16.0.0/16 进行IP地址划分
首先6个环回建邻接口:

1
2
3
4
5
6
172.16.0.2/32
172.16.0.3/32
172.16.0.4/32
172.16.0.5/32
172.16.0.6/32
172.16.0.7/32

然后每台路由器上都有模拟用户的网段:

1
2
3
4
5
6
172.16.2.0/24
172.16.3.0/24
172.16.4.0/24
172.16.5.0/24
172.16.6.0/24
172.16.7.0/24

最后路由器间的网段公有6个:

1
2
3
4
5
6
7
8
9
10
172.16.1.0/24
-------------
172.16.1.0/27
172.16.1.32/27
172.16.1.64/27
172.16.1.96/27
172.16.1.128/27
172.16.1.160/27
172.16.1.192/27(弃)
172.16.1.224/27(弃)

OSPF

路由表展示:
img

建邻(联邦+反射器)

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
//R1 - AS 1
bgp 1
router-id 1.1.1.1
peer 12.1.1.2 as-number 2
#
ipv4-family unicast
undo synchronization
peer 12.1.1.2 enable
//R2 - AS 64512
bgp 64512 //联邦
router-id 2.2.2.2
confederation id 2
confederation peer-as 64513
peer 12.1.1.1 as-number 1
peer 172.16.0.3 as-number 64512
peer 172.16.0.3 connect-interface LoopBack0
peer 172.16.0.5 as-number 64513
peer 172.16.0.5 ebgp-max-hop 2
peer 172.16.0.5 connect-interface LoopBack0
#
ipv4-family unicast
undo synchronization
peer 12.1.1.1 enable
peer 172.16.0.3 enable
peer 172.16.0.3 next-hop-local
peer 172.16.0.5 enable
peer 172.16.0.5 next-hop-local
//R3 - AS 64512
bgp 64512
router-id 3.3.3.3
confederation id 2
peer 172.16.0.2 as-number 64512
peer 172.16.0.2 connect-interface LoopBack0
peer 172.16.0.4 as-number 64512
peer 172.16.0.4 connect-interface LoopBack0
#
ipv4-family unicast
undo synchronization
peer 172.16.0.2 enable
peer 172.16.0.2 reflect-client //反射器
peer 172.16.0.4 enable
//R4 - AS 64512
bgp 64512
router-id 4.4.4.4
confederation id 2
confederation peer-as 64513
peer 172.16.0.3 as-number 64512
peer 172.16.0.3 connect-interface LoopBack0
peer 172.16.0.7 as-number 64513
peer 172.16.0.7 ebgp-max-hop 2
peer 172.16.0.7 connect-interface LoopBack0
#
ipv4-family unicast
undo synchronization
peer 172.16.0.3 enable
peer 172.16.0.7 enable
//R5-8 同上

img

宣告路由

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
//R2
bgp 64512
ipv4-family unicast
undo synchronization
network 172.16.2.0 255.255.255.0
network 172.16.3.0 255.255.255.0
network 172.16.4.0 255.255.255.0
network 172.16.5.0 255.255.255.0
network 172.16.6.0 255.255.255.0
network 172.16.7.0 255.255.255.0
//R7
bgp 64513
ipv4-family unicast
undo synchronization
network 172.16.2.0 255.255.255.0
network 172.16.3.0 255.255.255.0
network 172.16.4.0 255.255.255.0
network 172.16.5.0 255.255.255.0
network 172.16.6.0 255.255.255.0
network 172.16.7.0 255.255.255.0

BGP展示:
img
img

聚合

1
2
3
4
5
[R2]ip ip-prefix aa deny 172.16.1.0 24
[R2]ip ip-prefix aa permit 0.0.0.0 0 le 32
[R2]bgp 64512
[R2-bgp]aggregate 172.16.0.0 16 detail-suppressed //聚合
[R2-bgp]peer 12.1.1.1 ip-prefix aa export //调用前缀列表

BGP表展示:
img
连通性测试:
R1环回 ping R8环回
img
R1环回 ping AS 2内部环回(R7)
img

  • 标题: BGP联邦反射器
  • 作者: Itachi
  • 创建于 : 2022-07-31 19:13:01
  • 更新于 : 2022-07-31 23:09:13
  • 链接: https://blog.tarchi.top/hcip/BGP联邦反射器/
  • 版权声明: 本文章采用 CC BY-NC-SA 4.0 进行许可。
 评论