客户端无法访问路由器以太网端口 ip

网络工程 路由 ospf 高铁
2021-07-23 05:47:54

我使用 Cisco 和 Ubiquiti Edge 路由器以及 Vyos 的混合设备进行了此设置。我的 Cisco Nexus 配置了 HSRP,192.168.1.243 上的所有 SVI 作为 HSRP 上的活动,SVI 都在区域 0.0.0.0 上,192.168.1.242 上的 SVI 接口配置为 ip ospf 成本 50,因为默认 ip osp9.16.16.16.16.16.16.16438438 成本是 40。我还在 192.168.1.243 的所有 SVI 上配置 ip ospf priority 100,并在 192.168.1.242 的所有 SVI 上配置 ip ospf priority 90。192.168.0.0/24 上的所有路由器环回接口和以太网都位于区域 0.0.0.0。这个设置是让我在我的核心网络中有冗余。OSPF 邻居在所有路由器上看起来都不错。

安装在新的 Edge 路由器中,路由器 ID 为 192.168.1.241,OSPF 配置与 192.168.1.240 相同,因为我需要替换 192.168.1.240,但是我无法从连接到 Cisco Nexus SVI 子网/vlan 的任何客户端访问它。我可以从远程站点甚至同一区域的路由器访问它。我的 WAN 站点通过 192.168.1.240、192.168.1.254 和 10.11.1.50 连接,来自该端的客户端可以访问这个新路由器 (192.168.1.241)。我注意到 OSPF 运行良好,因为它设法从同一子网上的各个邻居获取路由,并从远程站点以及我的其他 WAN 路由器获取路由。通过故障排除,我注意到如果我在 192.168.1.243 上以更高的成本配置 SVI,我可以访问它,但无法访问同一主干区域中的其他路由器。

我相信我的 Nexus 配置中肯定缺少某些东西。附上我的设置,如果需要,我可以在我的两个 Nexus 上发布 SVI 的配置。希望有人能帮助我

谢谢 在此处输入图片说明

这是 SVI 和 OSPF 的配置

**cisco-nexus01**
interface Vlan2
  ip address 192.168.0.20/24
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0
  hsrp 2
    preempt
    priority 105
    ip 192.168.0.21
  no shutdown

interface Vlan3
  ip address 192.168.2.4/24
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0
  hsrp 3
    preempt
    priority 105
    ip 192.168.2.1
  no shutdown

interface Vlan4
  ip address 192.168.4.4/24
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0
  hsrp 4
    preempt
    priority 105
    ip 192.168.4.1
    no shutdown

interface Vlan5
  ip address 192.168.60.11/24
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0
  hsrp 5
    preempt
    priority 105
    ip 192.168.60.1
  no shutdown

interface Vlan6
  ip address 192.168.61.7/24
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0
  hsrp 6
    preempt
    priority 105
    ip 192.168.61.1
  no shutdown

interface Vlan8
  ip address 192.168.8.4/24
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0
 hsrp 8
    peempt
    riority 105
   ip 192.168.8.1
  no shutdown

interface Vlan10
  ip address 192.168.3.38/24
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0
  hsrp 10
    preempt
    priority 105
    ip 192.168.3.1
    no shutdown

interface Vlan52
  ip address 192.168.52.4/24
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0
  hsrp 52
    preempt
    priority 105
    ip 192.168.52.1
  no shutdown

cisco-nexus02

interface Vlan2
  ip address 192.168.0.19/24
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0
  hsrp 2
    preempt
    ip 192.168.0.21
  no shutdown

interface Vlan3
  ip address 192.168.2.3/24
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0
  hsrp 3
    preempt
    ip 192.168.2.1
  no shutdown

interface Vlan4
  ip address 192.168.4.3/24
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0
  hsrp 4
    preempt
    ip 192.168.4.1
  no shutdown

interface Vlan5
  ip address 192.168.60.10/24
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0
  hsrp 5
    preempt
    ip 192.168.60.1
  no shutdown

interface Vlan6
  ip address 192.168.61.6/24
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0
  hsrp 6
    preempt
    ip 192.168.61.1
  no shutdown

interface Vlan8
  ip address 192.168.8.3/24
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0
  hsrp 8
    preempt
    ip 192.168.8.1
  no shutdown

interface Vlan10
  ip address 192.168.3.37/24
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  hsrp 10
    preempt
    ip 192.168.3.1
  no shutdown

interface Vlan52
  ip address 192.168.52.3/24
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  hsrp 52
    preempt
    ip 192.168.52.1
  no shutdown
 

cisco-nexus01

router ospf 100
  router-id 192.168.1.242
  default-information originate
  redistribute static route-map static-in-ospf
  rfc1583compatibility

interface Vlan2
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0

interface Vlan3
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0

interface Vlan4
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0

interface Vlan5
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0

interface Vlan6
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0

interface Vlan8
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0

interface Vlan10
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0

interface Vlan52
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0

interface loopback0
  ip ospf priority 100
  ip router ospf 100 area 0.0.0.0

cisco-nexus02

router ospf 100
  router-id 192.168.1.243
  rfc1583compatibility

interface Vlan2
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0

interface Vlan3
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0

interface Vlan4
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0

interface Vlan5
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0

interface Vlan6
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0

interface Vlan8
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0

interface Vlan10
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0

interface Vlan52
  ip ospf cost 50
  no ip ospf passive-interface
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0

interface loopback0
  ip ospf priority 90
  ip router ospf 100 area 0.0.0.0
1个回答

问题1:你应该有一致的ospf cost,L3路由独立于L2 hsrp网关冗余

问题 1b:您的主机 vlan 挂在 Nexus 设备上对于 OSPF 应该是被动的,您为什么要在这里使用主动 ospf?

问题 2:在你的 vlan2 (192.168.0.0/24) 上你不应该有 hsrp,如果所有设备都使用 ospf 互连不需要 L2 共享 ip,只有在你做静态路由和需要 l2 ip 故障转移时才需要。

问题 3:如果你有双 Nexus 设备,你可能已经配置了 vPC,尽管你没有附加任何配置。vPC 具有用于互连 L3 设备和遍历对等链路的特定规则。请参阅https://www.cisco.com/c/en/us/support/switches/nexus-5000-series-switches/products-implementation-design-guides-list.html

问题3:建议使用专用的L3链路(不是Vlan)连接其他ospf路由器。