基于路由策略的BGP路径控制实验笔记
基于路由策略的BGP路径控制实验笔记
基于路由策略的BGP路径控制实验笔记
一、实验需求分析
通过BGP路由策略实现R1与R4的互访流量路径控制:
-
R1访问R4:
- 访问4.4.4.3时走R1-R3-R4路径
- 访问4.4.4.4时走R1-R2-R4路径
-
R4访问R1:
- 访问1.1.1.1时走R4-R3-R1路径
- 访问1.1.1.2时走R4-R2-R1路径
二、关键配置技术点
-
路由映射(Route-Map) :
- 用于修改路由属性(如weight、origin)
- 结合ACL匹配特定路由条目
-
标准ACL:
- 精确匹配目标主机地址
-
BGP策略应用:
- 在邻居关系上应用入向/出向策略
-
OSPF与BGP联动:
- 使用环回口建立iBGP邻居
三、四大厂商配置对比(BGP路由策略)
| 配置项 | 思科(Cisco) | 华为(Huawei) | 华三(H3C) | 锐捷(Ruijie) |
|---|---|---|---|---|
| 路由映射创建 | route-map <NAME> permit <SEQ> |
route-policy <NAME> permit node <SEQ> |
route-policy <NAME> permit node <SEQ> |
route-map <NAME> permit <SEQ> |
| 设置权重 | set weight <VALUE> |
apply weight <VALUE> |
apply weight <VALUE> |
set weight <VALUE> |
| 匹配ACL | match ip address <ACL-NAME> |
if-match acl <ACL-NUMBER> |
if-match acl <ACL-NUMBER> |
match ip address <ACL-NAME> |
| 应用策略到BGP邻居 | neighbor <IP> route-map <NAME> out |
peer <IP> route-policy <NAME> export |
peer <IP> route-policy <NAME> export |
neighbor <IP> route-map <NAME> out |
| 标准ACL格式 | ip access-list standard <NAME> |
acl number <NUMBER> |
acl basic <NUMBER> |
ip access-list standard <NAME> |
四、锐捷设备核心配置示例
! R1配置(锐捷)
router bgp 100
neighbor 12.1.1.2 remote-as 200
neighbor 13.1.1.3 remote-as 200
!
address-family ipv4
neighbor 12.1.1.2 activate
neighbor 12.1.1.2 route-map FROM_R2_IN in
neighbor 13.1.1.3 activate
neighbor 13.1.1.3 route-map FROM_R3_IN in
route-map FROM_R2_IN permit 10
match ip address TO_R2_ACL
set weight 200
ip access-list standard TO_R2_ACL
10 permit host 1.1.1.2
! R4配置(锐捷)
router bgp 200
neighbor 2.2.2.2 route-map FROM_R2_IN in
neighbor 3.3.3.3 route-map FROM_R3_IN in
!
address-family ipv4
network 4.4.4.4 mask 255.255.255.255
network 4.4.4.5 mask 255.255.255.255
route-map FROM_R3_IN permit 10
match ip address TO_R3_ACL
set weight 200
ip access-list standard TO_R3_ACL
10 permit host 1.1.1.1
五、验证方法
-
路径追踪:
R1#traceroute 4.4.4.4 source 1.1.1.1 R4#traceroute 1.1.1.2 source 4.4.4.5
-
BGP表查看:
show ip bgp show ip bgp neighbors <IP> advertised-routes
浙公网安备 33010602011771号