NET地址转换:
假设一台路由器使用接口LoopBack0的IP地址168.10.1.1作为Router_ID,则它在IS-IS使用的System ID可通过如下方法转换得到:
将IP地址168.10.1.1的每一部分都扩展为3位,不足3位的在前面补0;将扩展后的地址168.010.001.001分为3部分,每部分由4位数字组成;
重新组合的1680.1000.1001就是System ID
ISIS的简单配置:
[R1]isis
[R1-isis-1]network-entity 86.0001.1111.1111.1111.00
[R1]int vlan 100
[R1-Vlan-interface100]isis enable
[R1-Vlan-interface100]int vlan 200
[R1-Vlan-interface200]isis enable
[R1-Vlan-interface200]int lo 0
[R1-LoopBack0]isis enable
修改接口的优先级:(手工指定DIS)
[R1]int vlan 100
[R1-Vlan-interface100]isis dis-priority 100
缺省情况下,接口上的优先级为64。如果命令中不指定Level-1或Level-2,则默认为Level-1、Level-2都设置
查看接口信息:
[R1-Vlan-interface100]dis isis interface
路由引入:
[RouterD] isis 1
[RouterD–isis-1] address-family ipv4
[RouterD–isis-1-ipv4] import-route rip level-2
修改路由器的角色:
[R2]isis 1
[R2-isis-1]is-level level-1
缺省情况下,路由器的类型为level-1-2
注意:当路由器修改为level-1路由器时,他不会再接收level-2的路由,本地会有一条缺省路由指向level-2路由器
路由***:
[R1]isis 1
[R1-isis-1]address-family ipv4
[R1-isis-1-ipv4]import-route isis level-2 into level-1
可以使level-1的路由器接收到level-2的路由
ISIS的认证:
[R1]int g0/1
[R1-GigabitEthernet0/1]isis authentication-mode md5 plain 123
区域认证:
[R1]isis 1
[R1-isis-1]area-authentication-mode md5 plain h3c
ISIS与BFD的联动:(拓扑见QQ收藏)
[RouterA] bfd session init-mode active
[RouterA] interface gigabitethernet 2/1/1
[RouterA-GigabitEthernet2/1/1] isis bfd enable
[RouterA-GigabitEthernet2/1/1] bfd min-receive-interval 500
[RouterA-GigabitEthernet2/1/1] bfd min-transmit-interval 500
[RouterA-GigabitEthernet2/1/1] bfd detect-multiplier 7
[RouterB] bfd session init-mode active
[RouterB] interface gigabitethernet 2/1/1
[RouterB-GigabitEthernet2/1/1] isis bfd enable
[RouterB-GigabitEthernet2/1/1] bfd min-receive-interval 500
[RouterB-GigabitEthernet2/1/1] bfd min-transmit-interval 500
[RouterB-GigabitEthernet2/1/1] bfd detect-multiplier 8
ISIS的GE:(平滑重启)
[R1]isis 1
[R1-isis-1]graceful-restart
[R1-isis-1]graceful-restart t2 100 重启间隔,默认为300s
<R1>dis isis graceful-restart status
引入外部路由:
[R3]isis 1
[R3-isis-1]address-family ipv4
[R3-isis-1-ipv4]import-route rip level-2
[R3-rip-1]import-route isis allow-direct 没有这条命令本地路由不会重分发出去
缺省情况引入的路由类型为level-2
路由过滤:
[R1]acl basic 2000
[R1-acl-ipv4-basic-2000]rule deny source 4.4.4.4 0
[R1-acl-ipv4-basic-2000]rule permit source any
[R1-acl-ipv4-basic-2000]quit
[R1]isis
[R1-isis-1]address-family ipv4
[R1-isis-1-ipv4]filter-policy 2000 import
路由聚合:
[R1]isis
[R1-isis-1]address-family ipv4
[R1-isis-1-ipv4]summary 192.168.8.0 22 level-1-2
缺省路由配置:
[R1]isis
[R1-isis-1]address-family ipv4
[R1-isis-1-ipv4]default-route-advertise
Level-1的缺省路由不需要配置,Level-2的缺省路由需要手工配置
修改管理距离:
[R1]isis 1
[R1-isis-1]address-family ipv4
[R1-isis-1-ipv4]preference 20 该命令只对路由器本地有效,不影响其他路由器
缺省情况下,IS-IS路由的优先级为15
修改路由的cost值:
[R1-isis-1]int g0/1
[R1-GigabitEthernet0/1]isis cost 13 默认下不指定类型修改的是level-1
缺省情况下,IS-IS在接口上的路由权值为10
修改发送hello的时间:
[R1]int g0/0
[R1-GigabitEthernet0/0]isis timer hello 15
缺省情况下,接口上Hello报文的发送间隔时间为10秒
<R1>reset isis peer 2222.2222.2222 1 清除指定邻居
<R1>reset isis all 清除所有
<R1>dis isis route 查看路由
<R1>dis isis peer 查看邻居
<R1>dis isis lsdb 查看数据库