a我考网

 找回密码
 立即注册

QQ登录

只需一步,快速开始

扫一扫,访问微社区

查看: 114|回复: 1

[其他] 思科认证:思科路由实验项目全程记录及知识点归纳(5)

[复制链接]
发表于 2012-8-3 10:16:48 | 显示全部楼层 |阅读模式
尝试5 全区域中经由过程桢中继实现RIPv2路由和谈 + 密钥验证
" n8 R' F8 ^1 k# N8 k, b/ I3 o$ b为什么非冲要手密钥验证部门,因为现实中它根基上是必需的 0 X1 H. `8 ?4 n
[P1&P2&BBR]通用部门
8 c) L% j" Z0 @! A, @9 c
9 T$ f# Q. e  v" i9 `) t4 y% P+ d& N0 q6 [" N' h( K& w
router rip
. O- J; I2 G% X  o8 }( ^ver 2
4 t: h8 Q7 ?2 z% }net x.x.x.x
* _; A/ e' a  z0 t9 r& _key chain cisco3 C; \- |! R8 l' h$ I' e3 [  h
key 1
4 |& J3 G8 j$ B; Hkey-string mypass; @! ?# B0 I! x4 o
int x/x.x7 `) N  v2 p' G0 R9 b
ip rip auth key cisco# q6 P/ ?; R$ S% W7 V$ [* l
ip rip auth mod md5
) n* v" f9 l: @+ k- \: u+ {[P1R1]# m" y2 ]' T) F7 i& i8 g! L
int s1/0
7 W0 I! K3 p/ |# l( b  C& lip add 10.0.0.2 255.0.0.0- }* s3 M0 Q3 d* ?' J3 r: x
no shut
1 g4 p3 |' o6 C. u; wip rip auth key cisco
( D: c2 S5 v& x5 H( [4 p7 Zip rip auth mod md5
1 T5 l5 u2 e/ }; W' \+ i$ d  Kencpa fr
! O% Y6 Q5 F' F' @: U+ Yfr map ip 10.0.0.1 103 br % j/ ^$ H% _; W; `6 @) W

/ T9 U! |+ w4 {% \# O. V8 ?9 D$ \# Q[P1R2|P2R1|P2R2]设置装备摆设都是这样,不再阐述 9 h) }. E  j) k, u% d- w5 v, P5 I  C# X

* B- u2 J7 A  n: I3 I# o[BBR1]
, B1 x; j& {; n8 }1 b- nint s1/0
. P8 h6 J( T: y% j5 @" \no ip add9 _; M! E! e$ d1 J. x0 D
no shut5 R& F. _. v: D  e
int s1/0.1 mu
3 C# l* _' P% q, o8 ]# hip add 10.0.0.1
) ?# l; \* m# R  Wfr map ip 10.0.0.2 301 br
' R+ U2 v6 |! F$ M- Nfr map ip 10.0.0.3 302 br
, X- \$ ?5 h; @  r4 R2 x& Uip rip auth key cisco2 d" o7 `* i" j# ]6 K
ip rip auth mod md5* a2 N1 I, ]% ~; a2 H% s
[BBR2]% p: B4 k; E) {$ P0 d) X1 e( l
int s1/0
0 |: d' b2 l: |) Eno ip add
5 K8 ~* O3 N3 n! S: rno shut
! f4 ]* G: ?7 a. p) N, eint s1/0.1 mu
7 y7 `7 c& b+ \  Y* x9 `ip add 11.0.0.16 v; D4 z5 K* u& e) G
fr map ip 11.0.0.2 604 br& N! @8 g* a% s5 J* I7 p. x
fr map ip 11.0.0.3 605 br
# p9 v" I4 [1 F5 r  s! {9 }ip rip auth key cisco& Z4 i$ O2 N; d! }
ip rip auth mod md58 \2 N& H5 ~" A; A

8 S5 l: f4 C1 G6 ?) ^验证结不美观:
  U% F0 c9 a0 |
1 L" I* h, p; b( W( a3 u1 I; A+ I* H% b
[Copy to clipboard]
' N3 Z1 \; J8 w( _6 _CODE:
7 x! c5 w) t9 \' u6 psh ip route
& x4 Z6 ?2 a* gR 200.200.200.0/24 [120/2] via 219.146.241.2, 00:00:02, FastEthernet0/04 o" K6 h6 ^( G$ [, O* J& n
R 100.0.0.0/8 [120/1] via 11.0.0.2, 00:00:01, Serial1/0.16 a3 o# h" {  E& m
R 172.17.0.0/16 [120/3] via 11.0.0.3, 00:00:00, Serial1/0.1
( a0 D0 c$ f) N+ f# c1 e3 MR 172.16.0.0/16 [120/1] via 11.0.0.3, 00:00:00, Serial1/0.1
- F) G/ P5 Y+ P/ R3 b  g" l& @R 172.19.0.0/16 [120/1] via 11.0.0.3, 00:00:00, Serial1/0.1
% ?- y* y9 X& a" H) e- L7 |R 172.18.0.0/16 [120/2] via 11.0.0.3, 00:00:00, Serial1/0.1
- j1 k3 L) L' _' KC 219.146.241.0/24 is directly connected, FastEthernet0/0: ^) b5 f/ d; F: Z6 R2 y% i; q! @
R 192.168.4.0/24 [120/3] via 219.146.241.2, 00:00:02, FastEthernet0/0& o  P# K- a) J3 D% f! e
R 10.0.0.0/8 [120/1] via 219.146.241.2, 00:00:02, FastEthernet0/02 p2 O% A* k1 t$ Z) t% B
C 11.0.0.0/8 is directly connected, Serial1/0.1
9 f# n1 V& v% |R 192.168.1.0/24 [120/2] via 219.146.241.2, 00:00:02, FastEthernet0/0$ d* t0 F$ O; ~, ]& Y
R 192.168.2.0/24 [120/2] via 219.146.241.2, 00:00:02, FastEthernet0/0
# b0 U/ p# U# jR 192.168.3.0/24 [120/3] via 219.146.241.2, 00:00:02, FastEthernet0/0
3 Y2 Z- E9 N4 |/ V7 D* iBBR膳缦沔sh fr map
2 {* H2 l0 m3 ]0 c& R$ \[Copy to clipboard]
/ u  f; R  G0 xCODE:1 n; Q0 d& V) V  n: i
BBR2#sh fr map
$ m4 s* j2 a4 Z$ u" Qkey chain cisco& E7 D: y- ]$ ]; [0 Y* w
key 1& ^! L: M" N4 }$ {+ \: f
key-string mypass$ i1 M6 x, L' i4 @+ Q; ]* ^
int x/x.x
( u9 E% B1 g& Y2 X: u1 T  xip rip auth key cisco" j3 d/ Z' J% b- Y& w
ip rip auth mod md5; N+ a! A7 Q  x5 v
[P1R1], A0 c* v: H7 X  R: Z. k3 C
int s1/0( I/ Y- D  g: E+ M
ip add 10.0.0.2 255.0.0.08 f# ^* W+ g" o" ~( [
no shut! ^% K$ j# q6 u0 w  I
ip rip auth key cisco
9 T  y0 ^0 J% E& {0 Nip rip auth mod md5
7 {, U% `1 ]8 K5 nencpa fr
) s4 Y) h; ^5 g/ Lfr map ip 10.0.0.1 103 br
回复

使用道具 举报

 楼主| 发表于 2012-8-3 10:16:49 | 显示全部楼层

思科认证:思科路由实验项目全程记录及知识点归纳(5)

[P1R2|P2R1|P2R2]设置装备摆设都是这样,不再阐述
; p+ V5 |. [6 j5 t4 p
# J& y! R' T* G% j) w) G2 P' k3 P$ u/ d
[BBR1]
& b. M# C5 S. iint s1/0
  n% w/ G5 R2 ino ip add
$ q( ]) R0 d' E$ }( X* L; Vno shut
) f6 b* y" w) l: K* i: U* y! kSerial1/0.1 (up): ip 11.0.0.2 dlci 604(0x25C,0x94C0), static,
, v% i) r3 H' Y4 ubroadcast,6 @- s$ U% o& [9 u
CISCO, status defined, active
6 C5 y. C7 {' `" y6 O, W1 X/ XSerial1/0.1 (up): ip 11.0.0.3 dlci 605(0x25D,0x94D0), static,
5 ^9 n. C8 h& j7 R% t7 G4 ?: Mbroadcast,
9 o; d. T8 ]1 xCISCO, status defined, active
6 v0 L, B# J- P% I. [, T2 {, u
注重: $ P/ y& s# Y: v+ k5 O
1.界说密钥,不需要在每台router上全数设定,这样是没有意义的一再劳动,在此收集结构中,只需要在P1,P2还有BBR区域的鸿沟路由器上的鸿沟端口设定key验证,现实傍边也一样,不管跑什么和谈,除非是不撑持此功能的,否则为了平安起见,至少鸿沟路由器要设定验证
9 y, z+ |7 H$ p- k3 p: X  g2.此结构中的BBR区域桢中搜检用获得多点接口,所以,密钥的实现必然要在子接口琅缦沔实现,如不美观在物理接口上去敲呼吁,那么你debug必定会告诉你invaild auth
2 R% o7 k9 A2 o8 e常识点:
$ }* [! y+ A; f$ f# Y0 }; Q桢中继交流机设置装备摆设 ' H% I# E) Z2 ]- r" t/ ]: u
界说交流机frame switch7 L2 n  s- c- F6 e
进入端口# x0 q' F6 c3 w8 v
no ip no shut
% S, Y# h7 Z- n  H0 u封装frame) F" a, a, r' z8 B3 t
界说frame intf-type dce5 Z" J8 s3 f$ w  f2 V* x, Z
界说lmi
% I+ E7 h( W; o% ?界说clockrate
! A0 a  S- U% j( I; w界说frame route 100 interface s1/1 200 2 @# `2 G/ a& V. |
典型设置装备摆设 - \* ~; w5 K2 B+ C4 ]2 _* e
, }% b2 `" H$ d* H# [" x

# H6 d$ b: V, m$ v! Hinterface Serial1/0- F( |* M2 Y1 n" y) c% ~6 M* s
no ip address
' A* h/ T$ @" d. ]encapsulation frame-relay
$ P/ Y$ c$ a! l* `7 p3 u2 l3 E. yno fair-queue
/ Y+ I1 v, f- S& ]serial restart-delay 0
3 I4 ?- k; o$ V0 T' k" w$ f. Hclock rate 64000
/ g' ]% @8 Y9 Lframe-relay intf-type dce
( r& v9 E7 G% F0 j; G/ |frame-relay route 100 interface Serial1/1 2001 J1 d6 X- a4 g$ m
frame-relay route 600 interface Serial1/2 500
! k& B/ y( F: o; u2 @!' z8 `( C& s+ \+ G
interface Serial1/1
% e% R4 N9 M/ i; n9 I- ano ip address( D: k9 i+ \1 S6 J. R
encapsulation frame-relay
- l1 W2 R8 s/ B1 N7 Kserial restart-delay 0( R* C8 N) d2 K7 e# y( Z
clock rate 64000
6 X8 e7 F4 n  M1 p* r" j& \# f, m# @. uframe-relay intf-type dce' A- c% m5 y" p; b" H3 o
frame-relay route 200 interface Serial1/0 100
# |, o( _& e+ H" `3 {6 Z( `- |frame-relay route 300 interface Serial1/2 400
# u  x9 Q0 @( L/ ~" i1 ]!! _- `4 v" I8 T5 G
interface Serial1/2
) i0 c. K2 v( d9 N9 fno ip address
) D  c+ I  K* ]* x5 pencapsulation frame-relay
9 O) `- g% B# U  s/ D6 n6 ~  userial restart-delay 0
5 ^% F2 ^1 G% Q/ d  t6 Yclock rate 64000
( R7 x3 x& |; l/ aframe-relay intf-type dce
" f$ X5 E1 ~; F; V- kframe-relay route 400 interface Serial1/1 300+ N# \0 z  q* U2 m  l+ ]! |
frame-relay route 500 interface Serial1/0 600
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Archiver|手机版|小黑屋|Woexam.Com ( 湘ICP备18023104号 )

GMT+8, 2024-6-6 09:40 , Processed in 0.250538 second(s), 24 queries .

Powered by Discuz! X3.4 Licensed

© 2001-2017 Comsenz Inc.

快速回复 返回顶部 返回列表