Lab - 140520091029
Dear Networkers.
IS-IS routing protocol dan Route Leak akan menjadi tema Lab kali ini.
Berikut topologi lab,
Spesifikasi Lab,
- Konfigurasi ISIS routing protocol
- Terdiri dari Area-1 dan Area-2
- ’sh ip route’ di L1 router, yaitu R2 dan R3, L1 router hanya akan menampilkan default route.
- Konfigurasi Route Leak dari R0 sebagai L2/L1 router ke R2 dengan distribute-list,
- izinkan prefix 192.168.4.0/24 untuk ditampilkan pada routing table R2
- Konfigurasi Route Leak dari R1 sebagai L2/L1 router ke R3 dengan route-map,
- izinkan prefix 192.168.1.0/24 untuk ditampilkan pada routing table R3
- Verifikasi dengan ping
Berikut konfigurasi Cisco router berturut-turut R0 - R2 - R1 - R3,
R0#sh run
Building configuration…
Current configuration : 981 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R0
!
boot-start-marker
boot-end-marker
!
!
memory-size iomem 5
no aaa new-model
ip subnet-zero
!
!
ip cef
!
!
no ftp-server write-enable
!
!
!
!
interface FastEthernet0/0
ip address 201.1.1.1 255.255.255.252
ip router isis
duplex auto
speed auto
isis circuit-type level-2-only
!
interface FastEthernet1/0
ip address 200.1.1.2 255.255.255.252
ip router isis
duplex auto
speed auto
isis circuit-type level-1
!
router isis
net 49.0001.4444.4444.4444.00
redistribute isis ip level-2 into level-1 distribute-list 100
!
ip http server
ip classless
!
!
!
access-list 100 permit ip 192.168.4.0 0.0.0.255 any
!
!
control-plane
!
!
line con 0
transport preferred all
transport output all
line aux 0
transport preferred all
transport output all
line vty 0 4
login
transport preferred all
transport input all
transport output all
!
end
R2#sh run
Building configuration…
Current configuration : 951 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R2
!
boot-start-marker
boot-end-marker
!
!
memory-size iomem 5
no aaa new-model
ip subnet-zero
!
!
ip cef
!
!
no ftp-server write-enable
!
!
!
!
interface Loopback0
ip address 192.168.1.1 255.255.255.0
ip router isis
isis circuit-type level-1
!
interface Loopback1
ip address 192.168.2.1 255.255.255.0
ip router isis
isis circuit-type level-1
!
interface FastEthernet0/0
ip address 200.1.1.1 255.255.255.252
ip router isis
duplex auto
speed auto
isis circuit-type level-1
!
router isis
net 49.0001.2222.2222.2222.00
is-type level-1
!
ip http server
ip classless
!
!
!
!
!
control-plane
!
!
line con 0
transport preferred all
transport output all
line aux 0
transport preferred all
transport output all
line vty 0 4
login
transport preferred all
transport input all
transport output all
!
end
R1#sh run
Building configuration…
Current configuration : 1020 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R1
!
boot-start-marker
boot-end-marker
!
!
memory-size iomem 5
no aaa new-model
ip subnet-zero
!
!
ip cef
!
!
no ftp-server write-enable
!
!
!
!
interface FastEthernet0/0
ip address 202.1.1.1 255.255.255.252
ip router isis
duplex auto
speed auto
isis circuit-type level-1
!
interface FastEthernet1/0
ip address 201.1.1.2 255.255.255.252
ip router isis
duplex auto
speed auto
isis circuit-type level-2-only
!
router isis
net 49.0002.1111.1111.1111.00
redistribute isis ip level-2 into level-1 route-map leaking
!
ip http server
ip classless
!
!
!
access-list 1 permit 192.168.1.0 0.0.0.255
route-map leaking permit 10
match ip address 1
!
!
!
control-plane
!
!
line con 0
transport preferred all
transport output all
line aux 0
transport preferred all
transport output all
line vty 0 4
login
transport preferred all
transport input all
transport output all
!
end
R3#sh run
Building configuration…
Current configuration : 951 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R3
!
boot-start-marker
boot-end-marker
!
!
memory-size iomem 5
no aaa new-model
ip subnet-zero
!
!
ip cef
!
!
no ftp-server write-enable
!
!
!
!
interface Loopback0
ip address 192.168.3.1 255.255.255.0
ip router isis
isis circuit-type level-1
!
interface Loopback1
ip address 192.168.4.1 255.255.255.0
ip router isis
isis circuit-type level-1
!
interface FastEthernet0/0
ip address 202.1.1.2 255.255.255.252
ip router isis
duplex auto
speed auto
isis circuit-type level-1
!
router isis
net 49.0002.3333.3333.3333.00
is-type level-1
!
ip http server
ip classless
!
!
!
!
!
control-plane
!
!
line con 0
transport preferred all
transport output all
line aux 0
transport preferred all
transport output all
line vty 0 4
login
transport preferred all
transport input all
transport output all
!
end
Verifikasi, ’sh ip route’ pada saat Route Leak belum aktif, R2 dan R3 sebagai L1 router hanya menampilkan deafult route selain directly connected.
Selanjutnya adalah ’sh ip route’ di pada R2 dan R3 setelah Route Leak aktif. R2 routing table akan menampilkan ‘prefix bocoran’ yang diterima dari R0. Sedangkan R3 routing table akan menampilkan ‘prefix bocoran’ yang diterima dari R1.
Verifikasi ping
credit: thanks to Johnson Liu, CCIE #11440 for his note about Route Leak with route-map, many thanks man

