Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Destination Exit Port Network to Use 1.0 2.0 3.0 1.1 2.1 3.1
8-2
DYNAMIC ROUTING
Dynamic Routing: Dynamic routing is the process of routing protocols running on the router communicating with neighbor routers. If a change occurs in the network the dynamic routing protocols automatically inform all routers about the change.
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-3
Dynamic Routing
Most internetworks use dynamic routing
A D
B C
A D
B C
Routing Protocols
Routing protocols are used between routers to determine paths and maintain routing tables. Once the path is determined a router can route a routed protocol.
E0
S0
Exit Interface E0 S0 S1
172.17.3.0
8-7
E Router C Router D
8-8
D Routing Table
C Routing Table
B Routing Table
A Routing Table
Pass periodic copies of routing table to neighbor routers and accumulate distance vectors
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-10
10.2.0.0 A
S0 S0
10.3.0.0 B
S1 S0
10.4.0.0 C
E0
8-11
10.2.0.0 A
S0 S0
10.3.0.0 B
S1 S0
10.4.0.0 C
E0
8-12
10.2.0.0 A
S0 S0
10.3.0.0 B
S1 S0
10.4.0.0 C
E0
8-13
T1 B
RIP Overview
19.2 kbps T1 T1
Hop count metric selects the path Routes update every 30 seconds
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-18
T1
RIP Configuration
ter(config)#router rip
(config-router)#network network-number Selects participating attached networks The network number must be a major classful network number
8-19
A 172.16.1.1 10.1.1.1
8-20
RouterA#sh ip protocols Routing Protocol is "rip" Sending updates every 30 seconds, next due in 0 seconds Invalid after 180 seconds, hold down 180, flushed after 240 Outgoing update filter list for all interfaces is Incoming update filter list for all interfaces is Redistributing: rip Default version control: send version 1, receive any version Interface Send Recv Key-chain Ethernet0 1 1 2 Serial2 1 1 2 Routing for Networks: 10.0.0.0 172.16.0.0 Routing Information Sources: Gateway Distance Last Update 10.1.1.2 120 00:00:10 Distance: (default is 120)
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-21
RouterA#sh ip route Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, * - candidate default U - per-user static route, o - ODR T - traffic engineered route Gateway of last resort is not set 172.16.0.0/24 is subnetted, 1 subnets 172.16.1.0 is directly connected, Ethernet0 10.0.0.0/24 is subnetted, 2 subnets 10.2.2.0 [120/1] via 10.1.1.2, 00:00:07, Serial2 10.1.1.0 is directly connected, Serial2 192.168.1.0/24 [120/2] via 10.1.1.2, 00:00:07, Serial2
2009, Velocis Systems 8-22
C R C R
After initial flood, pass small event-triggered link-state updates to all other routers
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-23
EIGRP Overview
6-24
EIGRP supports:
EIGRP Features
Advanced distance vector 100% loop free Fast convergence Easy configuration Less network design constraints than OSPF
8-26
8-27
Advantages of EIGRP
Uses multicast instead of broadcast Utilizes link bandwidth Unequal cost path load balancing Manual summarization can be done in any interface at any router within the network
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-28
172.16.0.0 /16
Configuring EIGRP
6-30
Configuring Summarization
(config-router)#
no auto-summary
Displays the neighbors discovered by IP EIGRP Displays the IP EIGRP topology table Displays current EIGRP entries in the routing table Displays the parameters and current state of the active routing protocol process Displays the number of IP EIGRP packets sent and received
show ip protocols
Router#
8-33
8-34
R2 EIGRP Configuration
<output omitted> interface FastEthernet0/0 ip address 172.17.2.2 255.255.255.0 <output omitted> interface Serial0/0/1 bandwidth 64 ip address 192.168.1.102 255.255.255.224 <output omitted> router eigrp 100 network 172.17.2.0 0.0.0.255 network 192.168.1.0
8-35
8-36
8-37
R1#show ip eigrp interfaces IP-EIGRP interfaces for process 100 Xmit Queue Interface Peers Un/Reliable Fa0/0 0 0/0 Se0/0/1 1 0/0
Mean SRTT 0 10
Pending Routes 0 0
8-39
8-40
8-41
OSPF Overview
2009, Velocis Systems 4-42
What Is OSPF?
Has fast convergence Supports VLSM Processes updates efficiently Selects paths based on bandwidth
8-43
OSPF Terminology
2009, Velocis Systems 4-44
OSPF Terminology
8-45
OSPF Areas
8-46
The initial discovery causes flooding Link-state routing is memory and processor intensive.
8-47
OSPF Cost
Places router at the root of the tree and calculates the shortest path to each destination based on cumulative cost cost = 100000000/bandwidth bps
8-48
OSPF Operation
2009, Velocis Systems 4-49
Router ID
Number by which the router is known to OSPF Default: The highest IP address on an active interface at the moment of OSPF process startup Can be overridden by a loopback interface: Highest IP address of any active loopback interface
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-50
Exchange Process
A
172.16.5.1/24 E0
Down State
172.16.5.2/24 E1
8-51
Exchange Process
A
172.16.5.1/24 E0
Down State
172.16.5.2/24 E1
8-52
Exchange Process
A
172.16.5.1/24 E0
Down State
172.16.5.2/24 E1
Router B Neighbors List 172.16.5.1/24, int E1 I am router ID 172.16.5.2, and I see 172.16.5.1.
8-53
Exchange Process
A
172.16.5.1/24 E0
Down State
172.16.5.2/24 E1
Router B Neighbors List 172.16.5.1/24, int E1 I am router ID 172.16.5.2, and I see 172.16.5.1. Router A Neighbors List 172.16.5.2/24, int E0
Two-Way State
8-54
Discovering Routes
E0 172.16.5.1
afadjfjorqpoeru 39547439070713
DR E0 172.16.5.3
Exstart State
Hello
Hello
8-55
Discovering Routes
E0 172.16.5.1
afadjfjorqpoeru 39547439070713
DR E0 172.16.5.3
Exstart State
Hello
Hello
afadjfjorqpoeru 39547439070713
DBD
DBD
E0 172.16.5.3
afadjfjorqpoeru 39547439070713
LSAck
LSAck
8-57
Point-to-Point Neighborship
Router dynamically detects its neighboring router using the Hello protocol Adjacency is automatic as soon as the two routers can communicate
Networking FundamentalsLayer 3 Switching
8-59
Point-to-Point Network B
S0 10.2.1.2 10. 2.1.1 S1
<Output Omitted> interface Ethernet0 ip address 10.64.0.2 255.255.255.0 ! interface Serial0 ip address 10.2.1.2 255.255.255.0 <Output Omitted> router ospf 50 network 10.2.1.2 0.0.0.0 area 0 network 10.64.0.2 0.0.0.0 area 0
show ip protocols
show ip route
show ip ospf
Router#
clear ip route *
Displays router interaction during the hello, exchange, and flooding processes
8-65
ACCESS-LISTS
8-66
Token Ring
FDDI
8-67
Token Ring
FDDI
Internet
172.17.0.0
Permit or deny packets moving through the router Permit or deny vty access to or from the router Without access lists all packets could be transmitted onto all parts of your network
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-69
Outgoing Packet
S0
Standard Checks Source address Generally permits or denies entire protocol suite
8-70
Outgoing Packet
S0
Standard Checks Source address Generally permits or denies entire protocol suite Extended Checks Source and Destination address Generally permits or denies specific protocols
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-71
Outgoing Packet
S0
Standard Checks Source address Generally permits or denies entire protocol suite Extended Checks Source and Destination address Generally permits or denies specific protocols Inbound or Outbound
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-72
?
N
Access N List ?
Y
?
N
?
N
Discard Packet Notify Sender Packet Discard Bucket If no access list statement matches then discard the packet
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-75
Deny
Deny
2009, Velocis Systems 8-76
Deny Deny
Y Match Next Test(s) ? Y
Deny
2009, Velocis Systems 8-77
8-78
8-79
Standard IP lists (1 to 99) test conditions of all IP packets from source addresses
8-81
Standard IP lists (1 to 99) test conditions of all IP packets from source addresses Extended IP lists (100 to 199) can test conditions of source and destination addresses, specific TCP/IP protocols, and destination ports
8-82
IPX
Standard IP lists (1 to 99) test conditions of all IP packets from source addresses Extended IP lists (100 to 199) can test conditions of source and destination addresses, specific TCP/IP protocols, and destination ports
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-83
8-85
Router(config-if)#
ip access-group access-list-number Activates the list on an interface Sets inbound or outbound testing Default = Outbound no ip access-group access-list-number removes access-list from the interface Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-86 { in | out }
access-list 1 deny 172.16.4.13 0.0.0.0 access-list 1 permit 0.0.0.0 255.255.255.255 (implicit deny all) (access-list 1 deny 0.0.0.0 255.255.255.255)
0 1 2 34
Five virtual terminal lines (0 through 4) Filter addresses that can access into the routers vty ports Filter vty access out from the router
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-90
0 1 2 34
Physical port (e0) (Telnet)
Router#
Setup IP address filter with standard access list statement Use line configuration mode to filter access with the access-class command Set identical restrictions on all vtys
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-91
Restricts incoming or outgoing vty connections for address in the access list
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-92
8-93
Extended
Filters Based on Source and destination. Specifies a specific IP protocol and port number. Range is 100 through 199.
8-95
8-96
8-97
access-list 101 deny tcp 172.16.4.0 0.0.0.255 172.16.3.0 0.0.0.255 eq 21 access-list 101 deny tcp 172.16.4.0 0.0.0.255 172.16.3.0 0.0.0.255 eq 20
8-98
access-list 101 deny tcp 172.16.4.0 0.0.0.255 172.16.3.0 0.0.0.255 eq 21 access-list 101 deny tcp 172.16.4.0 0.0.0.255 172.16.3.0 0.0.0.255 eq 20 access-list 101 permit ip any any (implicit deny all) (access-list 101 deny ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255)
8-99
access-list 101 deny tcp 172.16.4.0 0.0.0.255 172.16.3.0 0.0.0.255 eq 21 access-list 101 deny tcp 172.16.4.0 0.0.0.255 172.16.3.0 0.0.0.255 eq 20 access-list 101 permit ip any any (implicit deny all) (access-list 101 deny ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255) interface ethernet 0 ip access-group 101 out
0.0.0.255
any eq 23
Deny only Telnet from subnet 172.16.4.0 out of E0 Permit all other traffic
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-101
access-list 101 deny tcp 172.16.4.0 access-list 101 permit ip any any (implicit deny all)
0.0.0.255
any eq 23
Deny only Telnet from subnet 172.16.4.0 out of E0 Permit all other traffic
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-102
access-list 101 deny tcp 172.16.4.0 access-list 101 permit ip any any (implicit deny all) interface ethernet 0 ip access-group 101 out
0.0.0.255
any eq 23
Deny only Telnet from subnet 172.16.4.0 out of E0 Permit all other traffic
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-103
S0 S1 S1
C
E0
To0
Token Ring
E0
E1
Place extended access lists close to the source Place standard access lists close to the destination
Networking FundamentalsLayer 3 Switching 2009, Velocis Systems 8-104
Recommended:
wg_ro_a#show access-lists Standard IP access list 1 permit 10.2.2.1 permit 10.3.3.1 permit 10.4.4.1 permit 10.5.5.1 Extended IP access list 101 permit tcp host 10.22.22.1 any eq telnet permit tcp host 10.33.33.1 any eq ftp permit tcp host 10.44.44.1 any eq ftp-data
8-105