1.a1

[r2-GigabitEthernet0/0/0]ip address 172.16.33.2 29

[r2-LoopBack0]ip address 172.16.35.1 24

[r3-GigabitEthernet0/0/0]ip address 172.16.33.3 29

[r3-LoopBack0]ip address 172.16.36.1 24

2.a0

 [r3-Serial4/0/0]ip address 34.0.0.1 24
[r3]ip route-static 0.0.0.0 0 34.0.0.2 
[r3-Tunnel0/0/0]ip address 172.16.1.1 29
[r3-Tunnel0/0/0]tunnel-protocol gre p2mp  
[r3-Tunnel0/0/0]source 34.0.0.1
[r3-Tunnel0/0/0]nhrp network-id 100
[r3-Tunnel0/0/0]nhrp entry multicast dynamic 

[r4-Serial4/0/0]ip address 34.0.0.2 24
[r4-Serial4/0/1]ip address 45.0.0.2 24
[r4-Serial3/0/0]ip address 46.0.0.2 24 
[r4-GigabitEthernet0/0/0]ip address 47.0.0.2 24
[r4-LoopBack0]ip address 4.4.4.4 24

[r5-Serial4/0/0]ip address 45.0.0.1 24
[r5-LoopBack0]ip address 172.16.2.1 24
[r5]ip route-static 0.0.0.0 0 45.0.0.2
[r5-Tunnel0/0/0]ip address 172.16.1.2 29   
[r5-Tunnel0/0/0]tunnel-protocol gre  p2mp 
[r5-Tunnel0/0/0]source s 4/0/0
[r5-Tunnel0/0/0]nhrp network-id 100
[r5-Tunnel0/0/0]nhrp entry 172.16.1.1 34.0.0.1 register 

[r6-Serial4/0/0]ip address 46.0.0.1 24
[r6-LoopBack0]ip address 172.16.3.1 24
[r6]ip route-static 0.0.0.0 0 46.0.0.2
[r6-Tunnel0/0/0]tunnel-protocol gre p2mp    
[r6-Tunnel0/0/0]source s 4/0/0
[r6-Tunnel0/0/0]nhrp network-id 100
[r6-Tunnel0/0/0]nhrp entry 172.16.1.1 34.0.0.1 register 

[r7-GigabitEthernet0/0/0]ip address 47.0.0.1 24
[r7-LoopBack0]ip address 172.16.4.1 24
[r7]ip route-static 0.0.0.0 0 47.0.0.2
[r7-Tunnel0/0/0]ip address 172.16.1.4 29
[r7-Tunnel0/0/0]tunnel-protocol gre p2mp 
[r7-Tunnel0/0/0]source g 0/0/0
[r7-Tunnel0/0/0]nhrp network-id 100
[r7-Tunnel0/0/0]nhrp entry 172.16.1.1 34.0.0.1 register 

2.配置a2

[r6-GigabitEthernet0/0/0]ip address 172.16.65.1 29

[r11-GigabitEthernet0/0/0]ip address 172.16.65.2 29
[r11-GigabitEthernet0/0/1]ip address 172.16.65.9 29
[r11-LoopBack0]ip address 172.16.66.1 24

[r12-GigabitEthernet0/0/0]ip address 172.16.65.10 29

3.配置a3

[r7-GigabitEthernet0/0/1]ip address 172.16.97.1 29

[r8-GigabitEthernet0/0/0]ip address 172.16.97.2 29
[r8-LoopBack0]ip address 172.16.98.1 24
[r8-GigabitEthernet0/0/1]ip address 172.16.97.9 29

[r9-GigabitEthernet0/0/0]ip address 172.16.97.10 29

4.配置R4

[r9-GigabitEthernet0/0/1]ip address 172.16.129.1 29
[r9-LoopBack0]ip address 172.16.130.1 24

[r10-GigabitEthernet0/0/0]ip address 172.16.129.2 29
[r10-LoopBack0]ip address 172.16.131.1 24

5.配置RIP

[r12-LoopBack0]ip address 172.16.160.1 20
[r12-LoopBack1]ip address 172.16.176.1 20

配置OSPF

[r1-ospf-1-area-0.0.0.1]network 172.16.0.0 0.0.255.255

[r2-ospf-1-area-0.0.0.1]network 172.16.0.0 0.0.255.255

[r3-ospf-1-area-0.0.0.1]network 172.16.32.0 0.0.7.255

[r3-ospf-1-area-0.0.0.0]network 172.16.1.1 0.0.0.0

[r5-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255

[r6-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.3.255
[r6-ospf-1-area-0.0.0.2]network 172.16.65.1 0.0.0.0

[r7-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.7.255
[r7-ospf-1-area-0.0.0.3]network 172.16.97.1 0.0.0.0

[r8-ospf-1-area-0.0.0.3]network 172.16.0.0 0.0.255.255
 

[r9-ospf-1-area-0.0.0.4]network 172.16.0.0 0.0.255.255
[r9-ospf-1-area-0.0.0.3]network 172.16.97.10 0.0.0.0

[r10-ospf-1-area-0.0.0.4]network 172.16.0.0 0.0.255.255

[r11-ospf-1-area-0.0.0.2]network 172.16.0.0 0.0.255.255

[r12-rip-1]network 172.16.0.0

[r12-ospf-1-area-0.0.0.2]network 172.16.65.10 0.0.0.0

更改MGRE类型为P2MP类型

[r3-Tunnel0/0/0]ospf network-type p2mp

[r5-Tunnel0/0/0]ospf network-type p2mp
[r6-Tunnel0/0/0]ospf network-type p2mp

[r7-Tunnel0/0/0]ospf network-type p2mp

a4区域为不规则OSPF区域,rip区域间缺失路由信息,需要重发布导入RIP路由和a4路由信息

[r12-ospf-1]import-route rip 1

[r9-ospf-1]import-route ospf  2

写一条缺省指向R9

[r9-ospf-2]default-route-advertise

做特殊区域,减少LSA更新量

[r3-ospf-1-area-0.0.0.1]abr-summary 172.16.32.0 255.255.224.0
[r3]ip route-static 172.16.32.0 19 NULL 0

[r6-ospf-1-area-0.0.0.2]abr-summary 172.16.64.0 255.255.224.0
[r6]ip route-static 172.16.64.0 19 NULL 0

[r7-ospf-1-area-0.0.0.3]abr-summary 172.16.96.0 255.255.224.0
[r7]ip route-static 172.16.96.0 19 NULL 0

[r9-ospf-1]asbr-summary 172.16.128.0 255.255.224.0
[r9]ip route-static 172.16.128.0 19 NULL 0

[r12-ospf-1]asbr-summary 172.16.160.0 255.255.224.0
[r12]ip route-static 172.16.160.0 19 NULL 0

[r1-ospf-1-area-0.0.0.1]stub

[r2-ospf-1-area-0.0.0.1]stub

[r3-ospf-1-area-0.0.0.1]stub no-summary 

[r7-ospf-1-area-0.0.0.3]nssa no-summary

[r8-ospf-1-area-0.0.0.3]nssa 

[r9-ospf-1-area-0.0.0.3]nssa 

[r6-ospf-1-area-0.0.0.2]nssa no-summary 

[r11-ospf-1-area-0.0.0.2]nssa 

[r12-ospf-1-area-0.0.0.2]nssa 

配置NET,访问R4环回

[r3-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255 
[r3-Serial4/0/0]nat outbound 2000

[r7-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[r7-GigabitEthernet0/0/0]nat outbound 2000

[r6-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[r6-Serial4/0/0]nat outbound 2000

加快收敛

[r3-Tunnel0/0/0]ospf timer hello 5

[r5-Tunnel0/0/0]ospf timer hello 5

[r6-Tunnel0/0/0]ospf timer hello 5

[r7-Tunnel0/0/0]ospf timer hello 5

手工认证,确保区域安全

[r1-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 123456
[r2-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 123456

[r3-ospf-1-area-0.0.0.1]authentication-mode md5 1 cipher 123456