</p> R4 是通过一条默认路由将子网通告给 ISP 的,R1 和 R2 若想访问 ISP,则必须将这条默认路 由通告给内网,R4 的 OSPF 路由进程中缺少了默认路由的通告。另外访问控制列表缺少反掩 码,应该加上去。
3 i/ \- E5 a; K& o 解决方法:$ F9 m" R) _: w7 K
r4(config)#router ospf 1
6 D. t' j8 v0 G& o r4(config-router)#default-information originate r4(config)#no access-list 1
0 K. w, f) u/ K r4(config)#access-list 1 permit 172.16.0.0 0.0.255.255
8 Y N* {5 @ B; t: z 再进行 show ip rou:. u) a" D3 i0 z" D5 k
SW4#show ip rou& R$ i2 N/ L" n0 ~& I' A
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP9 T- a1 R3 f* D. Y2 T% s) f
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
) o. x, X8 M/ X: b1 c N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2/ v; Y0 e8 H9 ^3 I4 D' ^' s
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP! {3 U; j) \- G" y( P) i
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route
- ]5 i7 E5 Q1 g7 X, j Gateway of last resort is 172.16.44.44 to network 0.0.0.04 o) p( _: h2 @: k0 a5 c( x7 }
172.16.0.0/24 is subnetted, 6 subnets
* Q! D# }" I. f" P R C 172.16.44.0 is directly connected, FastEthernet0/42 M k: {) i8 B
C 172.16.34.0 is directly connected, FastEthernet0/24# H7 [# Y2 m0 Y6 F- J, s! o
O 172.16.30.0 [110/2] via 172.16.24.2, 00:05:07, FastEthernet0/20: @0 W* [" r- g) K) b2 ?
C 172.16.24.0 is directly connected, FastEthernet0/20$ w% @1 N8 ]+ i% S
O 172.16.20.0 [110/2] via 172.16.34.3, 00:05:07, FastEthernet0/24/ L: l! e7 N; W y: c$ i |
[110/2] via 172.16.24.2, 00:05:07, FastEthernet0/20
# a2 d' ^, m9 v( p1 t$ P! f O 172.16.10.0 [110/2] via 172.16.34.3, 00:05:07, FastEthernet0/24$ L7 R7 T- t& O1 P" h* R& C
[110/2] via 172.16.24.2, 00:05:08, FastEthernet0/20; R# k1 k: K+ l* N$ i, Z0 p0 B
O*E2 0.0.0.0/0 [110/1] via 172.16.44.44, 00:05:08, FastEthernet0/4; b( p6 v( Q( E/ T* g1 R
OSPF 默认路由已经通告进内网,使用 R1 和 R2 ping 5.5.5.5:( L: F: m8 _9 N! ?+ d) \* l
r1#ping 5.5.5.5: s% F& D5 @3 P* b1 X& o8 r
Type escape sequence to abort.; m8 Z. A1 m5 M7 g
Sending 5, 100-byte ICMP Echos to 5.5.5.5, timeout is 2 seconds:
8 O' p9 F. U* m !!!!!6 _% q7 C7 G4 F" e9 Y
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/4 ms; U i& x9 b3 P N6 y9 B
R2#ping 5.5.5.5' E# G. e# z0 b; }3 C% y# B
Type escape sequence to abort.( U& _, O% p0 ?0 K
Sending 5, 100-byte ICMP Echos to 5.5.5.5, timeout is 2 seconds:& k& _( O' w- ]' z1 f7 @1 `2 B, W
!!!!!
* R: l2 V9 d" h5 g0 ^- D+ {: {# a Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/4 ms
& e" c# ^& Z, e. q- |) c 7、网关 R4 上的 ARP 条目过多5 }% K$ C4 f+ Q( _ l
使用 R1 去 ping R5 上所有的环回口,然后再在 R4 上 show ip arp:4 P4 J* N; B7 A) Q! O
r4#show ip arp
9 @& I, E+ k% W% _/ v3 d: C Protocol Address Age (min) Hardware Addr Type Interface
& P2 |6 g8 R6 N Internet 6.6.6.6 1 0024.14dd.a908 ARPA FastEthernet0/1
( D" c* I5 I( U' }1 t2 L Internet 5.5.5.5 1 0024.14dd.a908 ARPA FastEthernet0/1
/ B! e3 h* t7 ~! H: i. K0 m) H) W( | Internet 7.7.7.7 1 0024.14dd.a908 ARPA FastEthernet0/19 e, H' Z2 H0 y& Z0 @% \
Internet 8.8.8.8 6 0024.14dd.a908 ARPA FastEthernet0/1, ^5 b3 y9 X- B: b8 @
Internet 45.45.45.5 0 0024.14dd.a908 ARPA FastEthernet0/1( z+ F% P# p/ s5 E# b9 t4 f( z
Internet 45.45.45.4 - 0024.14ec.6719 ARPA FastEthernet0/1
/ J5 V5 x6 F7 L. B7 g# k8 N Internet 172.16.44.4 0 0012.8077.3200 ARPA FastEthernet0/0! s4 f) c* M. E+ T9 L& N1 _
Internet 172.16.44.44 - 0024.14ec.6718 ARPA FastEthernet0/0) A9 w" V& i$ ~* K8 j
ARP 表中的条目过多,原因是默认路由使用了以太网下一跳出口所致,由于没有指定的下一 跳,导致数据每次从接口出去时都要发送一次 ARP 报文,从而增加了 ARP 表中的 ARP 条目。
K3 D3 m: F& x( o5 a 解决方法:" s6 V3 i! X1 T X
将以太网一下跳出口改为下一跳地址
2 F, L' x& V7 Q# o9 I M! k. w3 b0 @ r4(config)#no ip route 0.0.0.0 0.0.0.0 FastEthernet0/14 h- Q5 n/ s2 |9 l! M; n6 |
r4(config)#ip route 0.0.0.0 0.0.0.0 45.45.45.5
3 z# Z, N$ X$ s- x 再次 show ip arp:
: {7 F: {8 f) `3 {0 u( ~ r4#show ip arp
8 \- e& L5 H% d+ e, w Protocol Address Age (min) Hardware Addr Type Interface2 d: w' r% f5 w! L: N' w, |( T
Internet 45.45.45.5 0 0024.14dd.a908 ARPA FastEthernet0/1
& u. v' `; s# \4 F# U- h Internet 45.45.45.4 - 0024.14ec.6719 ARPA FastEthernet0/1- @6 \. e! e, i6 n
Internet 172.16.44.4 0 0012.8077.3200 ARPA FastEthernet0/0' B2 w' ]' Z8 H( e' ]) \9 C# @
Internet 172.16.44.44 - 0024.14ec.6718 ARPA FastEthernet0/0, j" p& v' j$ p. {9 W, V1 L# v
ARP 表中的条目即固定为以上几条。 |