Pagina 1 di 1
Rotta statica con peso maggiore rispetto all' OSPF
Inviato: mer 04 ott , 2006 5:03 pm
da mscoppettuolo
Ciao a tutti, mi serve una mano, secondo voi è possibile avendo OSPF come protocollo di routing creare delle rotte statiche che abbiano peso maggiore rispetto alle rotte dell' OSPF? In pratica, la nostra rete WAN è composta da 5 0 6 sedi. E' una situazione ereditata ed ho constatato che OSPF per come è stato configurato genera molti problemi. Credo che con EIGRP la gestione possa semplificarsi, anche perchè ogni sede ha una situazione abbastanza statica. Come posso creare delle statiche su ogni router in maniera tale che abbiano un peso maggiore dell'OSPF? E soprattutto è Possibile? Una volta eliminato OSPF passerò ad eigrp
O al limite potrei abilitare entrambi e fare in modo che il controllo lo abbia EIGRP piuttosto che OSPF, che ne pensate?
Grazie a tutti
Inviato: mer 04 ott , 2006 5:50 pm
da kobaiachi
certo che si puo fare !!!!
le route statiche hanno distanza ammministrativa 1 mentre ospf 110 quindi se vi sono due rotte che puntano alla stessa destinazione la rotta statica vince su ospf in generale una rotta statica vince su qualsiasi protocollo di routing.
per quanto riguarda avere funzionanate eigrp insieme ad ospf anche questo si puo fare ed anche in questo caso essendo la distanza amministrativa di eigrp (90) minore di quella di ospf se due rotte puntano alla ,medesma destinazione vince la rotta eigrp.
cmq se ci dai maggiori info sulla conf della rete potremmo aiutarti meglio.
ciao
Inviato: gio 05 ott , 2006 11:55 am
da mscoppettuolo
Con molto piacere, posto una parte della configurazione del router cisco 3660 che si occupa di distribuire le rotte dell' OSPF
router eigrp 1
redistribute connected
redistribute static metric 1 200000 255 1 1500
redistribute ospf 1 metric 2000 20000 255 1 1500 route-map O-to-D
passive-interface Ethernet3/0
network 10.10.0.0 0.0.255.255
network 10.12.0.0 0.0.255.255
network 131.80.0.0
no auto-summary
no eigrp log-neighbor-changes
!
router ospf 1
router-id 10.12.3.3
log-adjacency-changes
area 0.0.0.0 range 10.0.0.0 255.0.0.0 cost 500
area 10.0.0.0 stub no-summary
area 10.70.0.0 nssa no-redistribution no-summary
area 10.120.0.0 stub
area 10.120.0.0 range 10.120.0.0 255.252.0.0
redistribute static metric 1000 metric-type 1 subnets route-map S-to-O
redistribute eigrp 1 metric 5000 subnets route-map D-to-O
network 10.0.10.1 0.0.0.0 area 10.0.0.0
network 10.0.70.1 0.0.0.0 area 10.70.0.0
network 10.0.120.1 0.0.0.0 area 10.120.0.0
network 10.10.3.2 0.0.0.0 area 0.0.0.0
network 10.11.254.1 0.0.0.0 area 0.0.0.0
network 10.12.3.3 0.0.0.0 area 0.0.0.0
network 172.29.10.10 0.0.0.0 area 0.0.0.0
network 172.29.12.3 0.0.0.0 area 0.0.0.0
network 172.29.12.4 0.0.0.0 area 0.0.0.0
network 172.29.12.5 0.0.0.0 area 0.0.0.0
network 172.30.30.9 0.0.0.0 area 0.0.0.0
network 172.30.34.1 0.0.0.0 area 0.0.0.0
network 172.30.38.1 0.0.0.0 area 0.0.0.0
network 172.30.45.1 0.0.0.0 area 0.0.0.0
network 172.30.50.1 0.0.0.0 area 0.0.0.0
network 172.30.64.1 0.0.0.0 area 0.0.0.0
network 172.30.70.1 0.0.0.0 area 10.70.0.0
network 172.30.71.9 0.0.0.0 area 10.70.0.0
network 172.30.100.1 0.0.0.0 area 0.0.0.0
network 172.30.120.1 0.0.0.0 area 10.120.0.0
network 172.30.140.1 0.0.0.0 area 0.0.0.0
network 172.30.141.1 0.0.0.0 area 0.0.0.0
default-information originate metric 500
distance ospf external 180
---------------------------------------------------------------------------
il router periferico è
router eigrp 1
redistribute static
redistribute ospf 1 metric 1000 10000 255 1 1500 route-map O-to-D
network 10.0.0.0
no auto-summary
no eigrp log-neighbor-changes
!
router ospf 1
router-id 10.70.3.1
log-adjacency-changes
area 10.70.0.0 nssa no-summary
redistribute static metric 200000 metric-type 1 subnets tag 1070
redistribute eigrp 1 metric 150000 metric-type 1 subnets tag 1070 route-map D-to-O
network 10.70.3.1 0.0.0.0 area 10.70.0.0
network 10.71.3.1 0.0.0.0 area 10.70.0.0
network 10.72.3.1 0.0.0.0 area 10.70.0.0
network 172.29.70.12 0.0.0.0 area 10.70.0.0
network 172.30.70.2 0.0.0.0 area 10.70.0.0
network 172.31.70.2 0.0.0.0 area 10.70.0.0
Inviato: gio 05 ott , 2006 3:24 pm
da kobaiachi
come è la topologia della rete ?, se posti la configurazione delle interfaccie in parte potremmo ricavarla da li .
che tipo di link sono usati tra i vari router (isdn, linea dedicata, frame relay)
potresti postare anche le route-map che gestiscono la redistribuzione delle rotte tra ospf ed eigrp e viceversa?.
ciao.
Inviato: gio 05 ott , 2006 4:10 pm
da mscoppettuolo
Ciao, la topologia della rete è la seguente:
Abbiamo un'interfaccia ATM\IMA con 4 flussi da 2 mega aggregati, ogni sede ha un cir garantito ovviamente. Le sedi remote sono collegate in Frame Relay
Router centrale :
interface Tunnel10
description ** OSPF area 10.0.0.0 intra-area int **
bandwidth 10000
ip address 10.0.10.1 255.255.255.252
ip mtu 1440
tunnel source Loopback6
tunnel destination 172.29.12.11
!
interface Tunnel70
description ** OSPF area 10.70.0.0 intra-area int **
bandwidth 10000
ip address 10.0.70.1 255.255.255.252
ip mtu 1440
tunnel source Loopback5
tunnel destination 172.29.12.10
!
interface Tunnel120
bandwidth 10000
ip address 10.0.120.1 255.255.255.252
ip mtu 1440
tunnel source Loopback7
tunnel destination 172.29.12.12
!
interface FastEthernet0/0
ip address 172.19.3.3 255.255.255.192 secondary
ip address 10.12.3.3 255.255.0.0
no ip redirects
speed 100
full-duplex
ipx input-sap-filter 1001
ipx network 12 encapsulation SAP
interface TokenRing3/0
ip address 192.9.201.253 255.255.255.0 secondary
ip address 10.10.3.2 255.255.0.0
no ip redirects
ipx input-sap-filter 1001
ipx network 1
ring-speed 16
no cdp enable
interface ATM4/0
no ip address
no atm ilmi-keepalive
atm voice aal2 aggregate-svc upspeed-number 0
ima-group 2
scrambling-payload
impedance 120-ohm
!
interface ATM4/1
no ip address
no atm ilmi-keepalive
atm voice aal2 aggregate-svc upspeed-number 0
ima-group 2
scrambling-payload
impedance 120-ohm
!
interface ATM4/2
no ip address
no atm ilmi-keepalive
atm voice aal2 aggregate-svc upspeed-number 0
ima-group 2
scrambling-payload
impedance 120-ohm
!
interface ATM4/3
no ip address
no atm ilmi-keepalive
atm voice aal2 aggregate-svc upspeed-number 0
ima-group 2
scrambling-payload
impedance 120-ohm
!
interface ATM4/IMA2
no ip address
no atm ilmi-keepalive
atm voice aal2 aggregate-svc upspeed-number 0
!
interface ATM4/IMA2.200 point-to-point
mtu 1500
ip address 172.30.70.1 255.255.255.252
ip access-group 111 in
ip policy route-map DLSwPriority
oam-pvc manage 0
encapsulation aal5snap
!
!
router eigrp 1
redistribute connected
redistribute static metric 1 200000 255 1 1500
redistribute ospf 1 metric 2000 20000 255 1 1500 route-map O-to-D
passive-interface Ethernet3/0
network 10.10.0.0 0.0.255.255
network 10.12.0.0 0.0.255.255
network 131.80.0.0
no auto-summary
no eigrp log-neighbor-changes
!
router ospf 1
router-id 10.12.3.3
log-adjacency-changes
area 0.0.0.0 range 10.0.0.0 255.0.0.0 cost 500
area 10.0.0.0 stub no-summary
area 10.70.0.0 nssa no-redistribution no-summary
area 10.120.0.0 stub
area 10.120.0.0 range 10.120.0.0 255.252.0.0
redistribute static metric 1000 metric-type 1 subnets route-map S-to-O
redistribute eigrp 1 metric 5000 subnets route-map D-to-O
network 10.0.10.1 0.0.0.0 area 10.0.0.0
network 10.0.70.1 0.0.0.0 area 10.70.0.0
network 10.0.120.1 0.0.0.0 area 10.120.0.0
network 10.10.3.2 0.0.0.0 area 0.0.0.0
network 10.11.254.1 0.0.0.0 area 0.0.0.0
network 10.12.3.3 0.0.0.0 area 0.0.0.0
network 172.29.10.10 0.0.0.0 area 0.0.0.0
network 172.29.12.3 0.0.0.0 area 0.0.0.0
network 172.29.12.4 0.0.0.0 area 0.0.0.0
network 172.29.12.5 0.0.0.0 area 0.0.0.0
network 172.30.30.9 0.0.0.0 area 0.0.0.0
network 172.30.34.1 0.0.0.0 area 0.0.0.0
network 172.30.38.1 0.0.0.0 area 0.0.0.0
network 172.30.45.1 0.0.0.0 area 0.0.0.0
network 172.30.50.1 0.0.0.0 area 0.0.0.0
network 172.30.64.1 0.0.0.0 area 0.0.0.0
network 172.30.70.1 0.0.0.0 area 10.70.0.0
network 172.30.71.9 0.0.0.0 area 10.70.0.0
network 172.30.100.1 0.0.0.0 area 0.0.0.0
network 172.30.120.1 0.0.0.0 area 10.120.0.0
network 172.30.140.1 0.0.0.0 area 0.0.0.0
network 172.30.141.1 0.0.0.0 area 0.0.0.0
default-information originate metric 500
distance ospf external 180
!
ip local pool pool_lucchin 10.1.6.2 10.1.6.254
ip classless
ip route 0.0.0.0 0.0.0.0 10.12.3.251
ip route 10.0.1.100 255.255.255.255 10.48.0.1
ip route 10.10.1.1 255.255.255.255 172.19.3.50
ip route 10.10.1.5 255.255.255.255 172.19.3.50
ip route 10.12.1.1 255.255.255.255 172.19.3.50
ip route 10.12.1.5 255.255.255.255 172.19.3.50
ip route 10.12.1.14 255.255.255.255 172.19.3.5
ip route 10.30.0.0 255.255.0.0 10.12.3.5
ip route 10.32.0.0 255.255.0.0 10.12.3.5
ip route 10.41.11.69 255.255.255.255 10.12.3.5
ip route 10.41.11.134 255.255.255.255 10.12.3.5
ip route 10.82.12.0 255.255.255.0 10.12.3.5
ip route 10.105.3.0 255.255.255.0 10.101.3.1
ip route 10.130.0.0 255.255.0.0 10.11.250.242
ip route 10.151.1.20 255.255.255.255 10.12.3.5
ip route 10.171.128.0 255.255.255.0 10.12.3.100
ip route 131.81.255.0 255.255.255.0 10.12.3.100
ip route 140.101.0.0 255.255.0.0 10.12.3.100
ip route 140.102.0.0 255.255.0.0 10.12.3.100
ip route 140.103.0.0 255.255.0.0 10.12.3.100
ip route 140.104.0.0 255.255.0.0 10.12.3.100
ip route 140.105.0.0 255.255.0.0 10.12.3.100
ip route 140.106.0.0 255.255.0.0 10.12.3.100
ip route 140.108.0.0 255.255.0.0 10.12.3.100
ip route 140.109.2.0 255.255.255.0 10.12.3.100
ip route 140.109.100.0 255.255.255.0 10.12.3.100
ip route 140.110.0.0 255.255.0.0 10.12.3.100
ip route 140.113.0.0 255.255.0.0 10.12.3.100
ip route 140.114.0.0 255.255.0.0 10.12.3.100
ip route 140.115.0.0 255.255.0.0 10.12.3.100
ip route 140.116.0.0 255.255.0.0 10.12.3.100
ip route 140.122.0.0 255.255.0.0 10.12.3.100
ip route 140.123.0.0 255.255.0.0 10.12.3.100
ip route 161.27.9.128 255.255.255.240 10.101.3.1
ip route 172.16.2.51 255.255.255.255 10.12.3.5
ip route 172.16.3.13 255.255.255.255 10.12.3.5
ip route 172.16.3.139 255.255.255.255 10.12.3.5
ip route 172.16.5.97 255.255.255.255 10.12.3.5
ip route 172.16.5.119 255.255.255.255 10.12.3.5
ip route 172.16.5.219 255.255.255.255 10.12.3.5
ip route 172.16.5.229 255.255.255.255 10.12.3.5
ip route 172.16.100.22 255.255.255.255 10.12.3.5
ip route 172.29.10.10 255.255.255.255 172.19.3.50
ip route 172.29.10.11 255.255.255.255 172.19.3.50
ip route 172.29.12.20 255.255.255.255 172.19.3.50
ip route 192.168.120.0 255.255.255.0 10.120.3.1
ip route 192.168.220.0 255.255.255.0 10.12.3.251
ip route 192.168.254.0 255.255.255.0 10.12.3.100
ip tacacs source-interface FastEthernet0/0
no ip http server
ip pim bidir-enable
!
access-list 1 permit 10.10.0.0
access-list 1 permit 10.14.0.0
access-list 1 permit 10.12.0.0
access-list 1 permit 10.72.0.0
access-list 1 permit 10.64.0.0
access-list 1 permit 10.70.0.0
access-list 1 permit 10.71.0.0
access-list 1 permit 10.11.102.0
access-list 1 permit 10.100.0.0
access-list 1 permit 10.101.0.0
access-list 1 permit 10.150.0.0
access-list 1 permit 10.171.3.0
access-list 1 permit 131.80.24.20
access-list 1 permit 10.171.64.0
access-list 1 permit 172.30.70.0
access-list 51 permit 10.10.1.1
access-list 51 permit 10.12.1.5
access-list 51 permit 10.10.1.5
access-list 51 permit 10.12.1.1
access-list 51 permit 194.235.164.2
access-list 51 permit 172.29.12.20
access-list 51 permit 172.29.10.11
access-list 51 permit 172.29.10.10
access-list 51 permit 10.50.0.0 0.0.255.255
access-list 51 permit 10.55.0.0 0.0.255.255
access-list 51 permit 10.190.0.0 0.0.255.255
access-list 51 permit 192.156.194.0 0.0.0.255
access-list 51 permit 161.27.9.128 0.0.0.15
access-list 51 permit 140.101.0.0 0.0.255.255
access-list 51 permit 140.102.0.0 0.0.255.255
access-list 51 permit 140.103.0.0 0.0.255.255
access-list 51 permit 140.104.0.0 0.0.255.255
access-list 51 permit 140.105.0.0 0.0.255.255
access-list 51 permit 140.106.0.0 0.0.255.255
access-list 51 permit 140.110.0.0 0.0.255.255
access-list 51 permit 140.108.0.0 0.0.255.255
access-list 51 permit 140.113.0.0 0.0.255.255
access-list 51 permit 140.114.0.0 0.0.255.255
access-list 51 permit 140.115.0.0 0.0.255.255
access-list 51 permit 140.116.0.0 0.0.255.255
access-list 51 permit 140.122.0.0 0.0.255.255
access-list 51 permit 10.171.128.0 0.0.0.255
access-list 51 permit 131.81.255.0 0.0.0.255
access-list 51 permit 140.109.2.0 0.0.0.255
access-list 51 permit 140.109.100.0 0.0.0.255
access-list 51 permit 192.168.254.0 0.0.0.255
access-list 51 deny 10.82.12.0 0.0.0.255
access-list 73 permit 10.14.204.102
access-list 100 permit tcp host 172.29.10.10 host 172.29.70.12
access-list 101 permit tcp host 10.10.4.1 host 10.70.4.1 eq 1352
access-list 101 permit tcp host 10.10.4.1 host 10.71.4.14 eq 1352
access-list 101 permit tcp any any eq ftp
access-list 101 permit tcp any any eq ftp-data
access-list 101 permit tcp any any eq www
access-list 101 permit tcp any eq ftp any
access-list 101 permit tcp any eq ftp-data any
access-list 101 permit tcp any eq www any
access-list 105 permit ip 10.14.200.0 0.0.1.255 10.29.0.0 0.0.0.255
access-list 105 permit ip 10.14.200.0 0.0.1.255 host 10.30.4.14
access-list 105 permit ip 10.14.200.0 0.0.1.255 host 10.30.4.15
access-list 111 deny ip 192.9.56.0 0.0.0.255 any
access-list 111 permit ip any any
access-list 150 permit icmp 172.16.0.0 0.0.255.255 10.30.0.0 0.0.255.255
access-list 150 permit icmp 10.14.0.0 0.0.3.255 10.30.0.0 0.0.255.255
access-list 1001 deny FFFFFFFF 142
access-list 1001 deny FFFFFFFF 30C
access-list 1001 deny FFFFFFFF 3D7
access-list 1001 deny FFFFFFFF 3D8
access-list 1001 deny FFFFFFFF 55E
access-list 1001 deny FFFFFFFF 640
access-list 1001 deny FFFFFFFF 1900
access-list 1001 permit FFFFFFFF 0
dialer-list 1 protocol ip permit
!
route-map S-to-O permit 10
match ip address 51
set tag 3660
!
route-map O-to-D deny 5
match tag 3620 3660
!
route-map O-to-D permit 10
match ip address 1
set tag 3660
!
route-map D-to-O deny 5
match tag 3620 3660
!
route-map D-to-O permit 10
set tag 3660
!
route-map DLSwPriority permit 10
match ip address 100
set ip precedence internet
!
route-map DLSwPriority permit 20
match ip address 101
set ip precedence routine
!
route-map DLSwPriority permit 30
set ip precedence priority
-----------------------------------------------------------------
Rorouter periferico:
!
!
ip subnet-zero
no ip source-route
no ip domain-lookup
!
ipx routing 0050.7309.4521
isdn switch-type basic-net3
isdn voice-call-failure 0
!
!
!
!
source-bridge ring-group 170
dlsw local-peer peer-id 172.29.70.12
dlsw remote-peer 0 tcp 172.29.10.10 lf 1500
dlsw remote-peer 0 tcp 172.29.10.11 lf 1500
!
interface Loopback2
ip address 172.29.70.12 255.255.255.255
!
interface Ethernet0/0
ip address 10.72.3.1 255.255.0.0 secondary
ip address 10.71.3.1 255.255.0.0
ip access-group 102 in
ip access-group 102 out
no ip redirects
ip route-cache same-interface
ipx input-sap-filter 1001
ipx network 5E encapsulation SAP
!
interface Serial0/0
no ip address
encapsulation frame-relay
no ip route-cache
no ip mroute-cache
random-detect
!
interface Serial0/0.100 point-to-point
ip address 172.30.70.2 255.255.255.252
no ip route-cache
no ip mroute-cache
ip policy route-map DLSwPriority
no arp frame-relay
no cdp enable
frame-relay interface-dlci 200 IETF
!
interface BRI0/0
no ip address
encapsulation ppp
dialer pool-member 1
isdn switch-type basic-net3
fair-queue 64 256 0
no cdp enable
ppp authentication chap
!
interface TokenRing0/0
ip address 10.70.3.1 255.255.0.0
ip helper-address 10.72.4.20
no ip redirects
ip route-cache flow
ipx input-sap-filter 1001
ipx network 5
ring-speed 16
multiring all
no cdp enable
source-bridge 161 1 170
source-bridge spanning
no cdp enable
!
interface Dialer0
description ****
bandwidth 64
ip address
encapsulation ppp
dialer pool 1
dialer remote-name BS-3640
dialer string 0303719007
dialer load-threshold 128 either
dialer-group 1
no cdp enable
ppp authentication chap
ppp chap password 7 test
ppp multilink
!
interface Dialer6
no ip address
no cdp enable
!
router eigrp 1
redistribute static
redistribute ospf 1 metric 1000 10000 255 1 1500 route-map O-to-D
network 10.0.0.0
no auto-summary
no eigrp log-neighbor-changes
!
router ospf 1
router-id 10.70.3.1
log-adjacency-changes
area 10.70.0.0 nssa no-summary
redistribute static metric 200000 metric-type 1 subnets tag 1070
redistribute eigrp 1 metric 150000 metric-type 1 subnets tag 1070 route-map D-to-O
network 10.70.3.1 0.0.0.0 area 10.70.0.0
network 10.71.3.1 0.0.0.0 area 10.70.0.0
network 10.72.3.1 0.0.0.0 area 10.70.0.0
network 172.29.70.12 0.0.0.0 area 10.70.0.0
network 172.30.70.2 0.0.0.0 area 10.70.0.0
network 172.31.70.2 0.0.0.0 area 10.70.0.0
!
ip classless
ip route 10.10.0.0 255.255.0.0 10.12.3.1
ip route 10.12.0.0 255.255.0.0 10.12.3.1
ip route 10.84.0.0 255.255.0.0 10.81.3.7
ip route 10.85.1.0 255.255.255.0 10.72.3.4
ip route 10.95.0.0 255.255.0.0 10.98.3.8
ip route 10.99.0.0 255.255.0.0 10.72.3.5
ip http server
!
!
ip prefix-list D-to-O seq 10 permit 0.0.0.0/0 le 31
logging trap debugging
logging facility syslog
access-list 101 deny tcp any any eq 135
access-list 101 permit ip any any
access-list 102 deny ip any host 10.71.4.11
access-list 102 deny ip 99.98.97.0 0.0.0.255 any
access-list 102 deny ip 192.9.71.0 0.0.0.255 any
access-list 102 permit ip any any
access-list 110 deny eigrp any any
access-list 110 permit ip any any
access-list 1001 deny FFFFFFFF 142
access-list 1001 deny FFFFFFFF 30C
access-list 1001 deny FFFFFFFF 3D7
access-list 1001 deny FFFFFFFF 3D8
access-list 1001 deny FFFFFFFF 55E
access-list 1001 deny FFFFFFFF 640
access-list 1001 deny FFFFFFFF 1900
access-list 1001 permit FFFFFFFF 0
priority-list 1 protocol dlsw high
priority-list 1 protocol ip low tcp 1352
priority-list 1 protocol ip medium tcp telnet
dialer-list 1 protocol ip list 110
route-map O-to-D deny 5
match tag 1070
!
route-map O-to-D permit 10
!
route-map D-to-O permit 10
!
In questa configurazione l'OSPF non funziona adeguatamente, mi chiedo come posso disabilitarlo e introdurre eigrp??
Grazie a tutti veramente
Inviato: ven 06 ott , 2006 6:46 pm
da Roberto82
invece di mettere 50.000 permit e i deny alla fine non conviene mettere i deny in testa e poi il permit ip any any?
Sarebbe tutto uguale ma con molte meno righe.