在实验室环境中设置Juniper Netscreen SSG5 5‘S“区域和Cisco路由器之间的OSPF存在问题。在Netscreen设备的接口放置到“信任”区域之前,状态不会过渡到EXSTART。下面的配置与清除两个设备上的所有配置后输入的配置完全相同。
GNS3用IOS 12.4(23)模拟思科3640
configure terminal
interface fastethernet0/0
ip address 172.16.1.1 255.255.255.252
no shutdown
router ospf 1
network 172.16.1.1 0.0.0.0 area 1
default-info originate alwaysJuniper SSG5与ScreenOS 6.2.0r5.0
set interface ethernet0/0 ip 172.16.1.2 255.255.255.252
set vrouter trust-vr protocol ospf
set vrouter trust-vr protocol ospf enable
set vrouter trust-vr protocol ospf area 1
set interface ethernet0/0 protocol ospf area 1
set interface ethernet0/0 protocol ospf enable输入这些命令后,在Netscreen上发出此命令
get vrouter trust-vr protocol ospf neighbor结果:
Neighbor(s) on interface ethernet0/0 (Area 0.0.0.1)
IpAddr/IfIndex RouterId Pri State Opt Up StateChg
------------------------------------------------------------------------------
172.16.1.1 172.16.1.1 1 ExStart E 00:01:26 (+4 -0)在思科
show ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
172.16.1.2 1 EXCHANGE/BDR 00:00:38 172.16.1.2 FastEthernet0/0一旦我在Netscreen上输入以下命令,状态就会转换为FULL
set interface ethernet0/0 zone Trust以下是Cisco上的调试输出
debug ip ospf adj
*Mar 1 00:02:18.971: OSPF: 2 Way Communication to 172.16.1.2 on FastEthernet0/0, state 2WAY
*Mar 1 00:02:18.971: OSPF: Backup seen Event before WAIT timer on FastEthernet0/0
*Mar 1 00:02:18.971: OSPF: DR/BDR election on FastEthernet0/0
*Mar 1 00:02:18.971: OSPF: Elect BDR 172.16.1.1
*Mar 1 00:02:18.971: OSPF: Elect DR 172.16.1.2
*Mar 1 00:02:18.971: OSPF: Elect BDR 172.16.1.1
*Mar 1 00:02:18.971: OSPF: Elect DR 172.16.1.2
DR: 172.16.1.2 (Id) BDR: 172.16.1.1 (Id)
*Mar 1 00:02:18.971: OSPF: Send DBD to 172.16.1.2 on FastEthernet0/0 seq 0x2212 opt 0x52 flag 0x7 len 32
*Mar 1 00:02:23.971: OSPF: Send DBD to 172.16.1.2 on FastEthernet0/0 seq 0x2212 opt 0x52 flag 0x7 len 32
*Mar 1 00:02:23.971: OSPF: Retransmitting DBD to 172.16.1.2 on FastEthernet0/0 [1]
*Mar 1 00:02:24.003: OSPF: Rcv DBD from 172.16.1.2 on FastEthernet0/0 seq 0x436 opt 0x2 flag 0x7 len 32 mtu 1500 state EXSTART
*Mar 1 00:02:24.003: OSPF: NBR Negotiation Done. We are the SLAVE
*Mar 1 00:02:24.003: OSPF: Send DBD to 172.16.1.2 on FastEthernet0/0 seq 0x436 opt 0x52 flag 0x2 len 72
*Mar 1 00:02:24.003: OSPF: Rcv DBD from 172.16.1.2 on FastEthernet0/0 seq 0x436 opt 0x2 flag 0x7 len 32 mtu 1500 state EXCHANGE
(last two lines repeat indefinitely)我不认为这是MTU错配,这两个设备被设置为1500。而且,就像我说的,一旦Netscreen接口被放置到“信任”区域,它就能工作。
在Netscreen上输入以下内容似乎不会更改任何内容。
set policy default-permit-all
unset policy 1Wireshark捕获显示,当Netscreen界面处于“不信任”区域时,一系列ICMP TTL超过了从Netscreen到Cisco的数据包。
不管它的价值是什么,iBGP在“不信任”区域工作。
发布于 2014-01-06 21:14:26
这个问题已经解决了。这似乎是一个暂时的问题,在第一层。我不能再再现它后,重新布线。
https://networkengineering.stackexchange.com/questions/5723
复制相似问题