华为 HCDP 学习笔记
华为 HCDP 学习笔记 .................................................................................................................1
一、华为 HCDP IERN 学习笔记 ........................................................................................................ 1
1、OSPF 路由协议基础(OSPF 基本配置)...........................................................................1
2、理解 OSPF 邻居与邻接关系( OSPF 网络类型(NBMA、P2MP))............................. 2
3、理解 OSPF 邻居与邻接关系( Virtual Link) ...................................................................4
4、 理解 OSPF 邻居与邻接关系(OSPF 网络类型(P2P、Broadcast))........................... 5
5、 OSPF 协议报文和链路状态通告...................................................................................... 6
6、 建立 OSPF 邻居与邻接关系 ............................................................................................. 8
7、计算 OSPF 区域内路由......................................................................................................10
8、 OSPF 区域间路由.............................................................................................................10
9、OSPF 区域间路由(Vlink) .............................................................................................. 11
10、 OSPF 区域间路由(区域间汇聚) .............................................................................. 12
11、OSPF 外部路由 .................................................................................................................13
12、OSPF 特殊区域 .................................................................................................................15
13、BGP 工作原理 .................................................................................................................. 17
14、BGP 路径选择 .................................................................................................................. 18
15、 Next-Hop.........................................................................................................................19
16、BGP 路由汇聚 .................................................................................................................. 20
17、BGP 路由策略(1 2)..................................................................................................... 22
18、BGP 路由策略(3 4)..................................................................................................24
19、 BGP 路由策略(5 6 ).....................................................................................................26
20、BGP 路由策略(7 8 9 10 11 ).............................................................................................27
21、 BGP 路由策略(BGP 路由过滤)...................................................................................28
22、 BGP 反射........................................................................................................................ 30
23、 BGP 联盟........................................................................................................................ 32
24、路由选择工具 ..................................................................................................................33
25、引入路由 1.......................................................................................................................35
26、引入路由 2.......................................................................................................................36
27、默认路由 .......................................................................................................................... 39
28、PBR ....................................................................................................................................40
29、IGMP ................................................................................................................................. 42
30、PIM-DM.............................................................................................................................44
31、PIM-SM ............................................................................................................................. 44
二、华为 HCDP IESN 学习笔记 .......................................................................................................46
1、 VLAN 1.............................................................................................................................. 46
2、 VLAN 2 (Hybrid)......................................................................................................... 48
3、 VLAN 3 (Mux VLAN) ................................................................................................... 49
4、 VLAN 4(Super VLAN)...................................................................................................50
5、 VLAN 5(VLAN Mapping)..............................................................................................51
6、 VLAN 6(端口隔离) ...................................................................................................... 51
7、 QinQ 配置 .........................................................................................................................52
8、STP...................................................................................................................................... 54
9、RSTP.................................................................................................................................... 55
10、MSTP .................................................................................................................................56
11、 802.1x 原理与配置........................................................................................................ 58
12、 DHCP Snooping...............................................................................................................59
13、 DHCP 原理......................................................................................................................61
14、DHCP Snooping1 ...............................................................................................................63
15、MPLS 概述 ........................................................................................................................ 65
16、MPLS 基本原理 ................................................................................................................66
17、MPLS 环路检测 ................................................................................................................69
18、 LDP 邻居发现和会话建立 .............................................................................................70
19、 LDP 标签管理 .................................................................................................................74
20、MPLS VPN ......................................................................................................................... 75
三、华为 HCDP IESN 学习笔记 .......................................................................................................81
1、(华为安全技术)USG 防火墙产品基本功能特性与配置 ............................................. 81
2、防火墙的基本功能............................................................................................................82
3、Qos 分类与标记................................................................................................................84
4、流量的监管 ........................................................................................................................ 85
5、流量整形............................................................................................................................ 86
6、ASPF .................................................................................................................................... 87
7、华为防火墙基本功能 1.....................................................................................................89
8、防火墙扩展功能 ................................................................................................................90
9、 USG 防火墙防范业务配置..............................................................................................93
10、 配置双机热备份............................................................................................................94
11、拥塞管理 .......................................................................................................................... 95
12、拥塞避免 .......................................................................................................................... 96
13、 链路效率机制..............................................................................................................101
一、华为 HCDP IERN 学习笔记
1、OSPF 路由协议基础(OSPF 基本配置)
OSPF的基本配置
[R4]router id 4.4.4.4
[R4]ospf
[R4-ospf-1]
[R4-ospf-1]area 0
[R4-ospf-1-area-0.0.0.0]network 4.4.4.4 0.0.0.0
[R4-ospf-1-area-0.0.0.0]network 14.1.1.4 0.0.0.0
[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]network 1.1.1.1 0.0.0.0
[R1-ospf-1-area-0.0.0.0]network 14.1.1.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]area 1
[R1-ospf-1-area-0.0.0.1]network 12.1.1.1 0.0.0.0
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]area 1
[R2-ospf-1-area-0.0.0.1]network 0.0.0.0 255.255.255.255
[R3]ospf 1 router-id 3.3.3.3
[R3-ospf-1]area 1
[R3-ospf-1-area-0.0.0.1]network 3.3.3.3 0.0.0.0
[R3-ospf-1-area-0.0.0.1]network 23.1.1.3 0.0.0.0
1 / 103
查看OSPF路由:
[R4]display ip routing-table protocol ospf
2、理解 OSPF 邻居与邻接关系( OSPF 网络类型(NBMA、
P2MP))
1、修改OSPF的网络类型:
[R1-Serial1/0/0]ospf network-type ?
broadcast Specify OSPF broadcast network
nbma
p2mp
Specify OSPF NBMA network
Specify OSPF point-to-multipoint
network
Specify OSPF point-to-point
network
p2p
[R1-Serial1/0/0]ospf network-type broadcast
[R1-Serial1/0/0]fr map ip 123.1.1.2 102 broadcast
[R1-Serial1/0/0]fr map ip 123.1.1.3 103 broadcast
[R2-Serial1/0/0]ospf network-type broadcast
[R2-Serial1/0/0]fr map ip 123.1.1.1 201 broadcast
[R3-Serial1/0/0]fr map ip 123.1.1.1 301 broadcast
[R3-Serial1/0/0]ospf network-type p2p
一端是Broadcast,另一端是P2P,可以建立OSPF邻居关系,但无路由P2MP
[R1-Serial1/0/0]ospf network-type p2mp
一端是P2MP,另一端是Broadcast(Hello Time=30s)可以建立OSPF邻居关系,但无路由
一端是P2MP,另一端是是P2P(Hello Time=30s)可以建立OSPF邻居关系,而有路由
没有任何2层封装接口默认的OSPF网络类型是P2MP,只能手工将接口配置为P2MP的OSPF网络型
2 / 103
自动建立OSPF邻居关系,不选举DR和BDR
2、工作在NBMA中的OSPF:
[R1]interface s1/0/0
[R1-Serial1/0/0] link-protocol fr
[R1-Serial1/0/0] undo fr inarp
[R1-Serial1/0/0] fr map ip 123.1.1.2 102 broadcast
[R1-Serial1/0/0] fr map ip 123.1.1.3 103 broadcast
[R1-Serial1/0/0] ip address 123.1.1.1 255.255.255.0
[R2-Serial1/0/0] link-protocol fr
[R2-Serial1/0/0] undo fr inarp
[R2-Serial1/0/0] fr map ip 123.1.1.1 201 broadcast
[R2-Serial1/0/0] ip address 123.1.1.2 255.255.255.0
[R3-Serial1/0/0]interface Serial1/0/0
[R3-Serial1/0/0] link-protocol fr
[R3-Serial1/0/0] undo fr inarp
[R3-Serial1/0/0] fr map ip 123.1.1.1 301 broadcast
[R3-Serial1/0/0] ip address 123.1.1.3 255.255.255.0
当串行接口被封装为FR时,在参与OSPF进程时,默认的OSPF网络类型是NBMA(Non-Broadcast
Multiple Access,非广播多路访问)
NMBA的OSPF网络类型不能使用Hello包自动发现邻居,必须手工指定邻居
[R1]ospf 1
[R1-ospf-1]peer 123.1.1.2
[R1-ospf-1]peer 123.1.1.3
[R2/3-ospf-1]peer 123.1.1.1
手工指定OSPF邻居之后,OSPF使用单播的Hello包建立OSPF邻居关系
在华为设备中必须双向指定OSPF邻居
在NBMA的OSPF网络类型中,选举DR和BDR,需要手工调整DR
[R1]interface s1/0/0
[R1-Serial1/0/0]ospf dr-priority 10
[R2/3-Serial1/0/0]ospf dr-priority 0
reset ospf process
[R2-Serial1/0/0]fr map ip 123.1.1.3 201
[R3-Serial1/0/0]fr map ip 123.1.1.2 301
3 / 103
3、理解 OSPF 邻居与邻接关系( Virtual Link)
配置虚链路(Vlink):
[R1]ospf 1
[R1-ospf-1]area 1
[R1-ospf-1-area-0.0.0.1]vlink-peer 3.3.3.3
[R3]ospf 1
[R3-ospf-1]area 1
[R3-ospf-1-area-0.0.0.1]vlink-peer 1.1.1.1
查看vlink状态
[R1]display ospf vlink
4 / 103
4、 理解 OSPF 邻居与邻接关系(OSPF 网络类型(P2P、
Broadcast))
1、在R1上查看S1/0/0接口
串行接口的数据链路层的封装默认类型是PPP时,参与到OSPF
进程时的默认OSPF网络类型是P2P
OSPF网络类型为P2P时,形成邻居关系之后直接形成邻接关系
2、在R3上查看G0/0/0接口
以太网接口参与到OSPF进程时默认OSPF网络类型是Broadcast
DRother与DRother只能形成邻居关系;
DRother与DR和BDR,以及DR与BDR之间形成邻接关系
5 / 103
5、 OSPF 协议报文和链路状态通告
1、OSPF报文结构
2、OSPF报头格式
3、配置OSPF的认证
[R1-Serial3/0/0]ospf authentication-mode simple cipher 123456
[R4-Serial1/0/0]ospf authentication-mode simple plain 123456
4、LSA报头
5、LSA类型——区域内路由的计算
1)Type 1 LSA:Router LSA
区域内的每个OSPF路由器为每个区域的所有接口产生一条Type 1 LSA;
在区域内泛洪;
查看1类LSA:[R4]display ospf lsdb [router] [x.x.x.x]
Advertsing Router(通告路由器):使用自己的Router-ID表示;
Link State ID(LS ID):使用自己的Router-ID表示;
Link State Age(LS Age):3600s
Sequence Number:序列号。LSA的起源者每30分钟,重新泛洪自己的LSA,而且序列号加1
Link count(链路数量)
(1)Loopback使用一个Link表示,Link内部如下:
Link ID:使用Loopback接口的IP地址表示;
Data:使用Loopback接口的子网掩码;
Link Type:环回接口使用Stubnet(末稍)表示,表明接口无OSPF邻居
Metric:表示接口的成本。环回接口使用0;
Priority:环回接口使用中(Medium)
(2)P2P/P2MP的OSPF网络类型的接口在1类LSA中使用2个Link count表示。
一个Link Count用于描述接口上邻居
Link ID:邻居的Router-ID
Data:邻居的接口IP地址;
Link Type:P2P
另一个Link Cout用于描述接口的状态信息:
Link ID:接口的子网;
Data:接口的子网掩码
6 / 103