NET地址轉換:數據庫
假設一臺路由器使用接口LoopBack0的IP地址168.10.1.1做爲Router_ID,則它在IS-IS使用的System ID可經過以下方法轉換獲得:session
將IP地址168.10.1.1的每一部分都擴展爲3位,不足3位的在前面補0;將擴展後的地址168.010.001.001分爲3部分,每部分由4位數字組成;ide
從新組合的1680.1000.1001就是System IDoop
ISIS的簡單配置:ui
[R1]isisspa
[R1-isis-1]network-entity 86.0001.1111.1111.1111.00rest
[R1]int vlan 100orm
[R1-Vlan-interface100]isis enablexml
[R1-Vlan-interface100]int vlan 200接口
[R1-Vlan-interface200]isis enable
[R1-Vlan-interface200]int lo 0
[R1-LoopBack0]isis enable
修改接口的優先級:(手工指定DIS)
[R1]int vlan 100
[R1-Vlan-interface100]isis dis-priority 100
缺省狀況下,接口上的優先級爲64。若是命令中不指定Level-1或Level-2,則默認爲Level-1、Level-2都設置
查看接口信息:
[R1-Vlan-interface100]dis isis interface
路由引入:
[RouterD] isis 1
[RouterD–isis-1] address-family ipv4
[RouterD–isis-1-ipv4] import-route rip level-2
修改路由器的角色:
[R2]isis 1
[R2-isis-1]is-level level-1
缺省狀況下,路由器的類型爲level-1-2
注意:當路由器修改成level-1路由器時,他不會再接收level-2的路由,本地會有一條缺省路由指向level-2路由器
路由***:
[R1]isis 1
[R1-isis-1]address-family ipv4
[R1-isis-1-ipv4]import-route isis level-2 into level-1
能夠使level-1的路由器接收到level-2的路由
ISIS的認證:
[R1]int g0/1
[R1-GigabitEthernet0/1]isis authentication-mode md5 plain 123
區域認證:
[R1]isis 1
[R1-isis-1]area-authentication-mode md5 plain h3c
ISIS與BFD的聯動:(拓撲見QQ收藏)
[RouterA] bfd session init-mode active
[RouterA] interface gigabitethernet 2/1/1
[RouterA-GigabitEthernet2/1/1] isis bfd enable
[RouterA-GigabitEthernet2/1/1] bfd min-receive-interval 500
[RouterA-GigabitEthernet2/1/1] bfd min-transmit-interval 500
[RouterA-GigabitEthernet2/1/1] bfd detect-multiplier 7
[RouterB] bfd session init-mode active
[RouterB] interface gigabitethernet 2/1/1
[RouterB-GigabitEthernet2/1/1] isis bfd enable
[RouterB-GigabitEthernet2/1/1] bfd min-receive-interval 500
[RouterB-GigabitEthernet2/1/1] bfd min-transmit-interval 500
[RouterB-GigabitEthernet2/1/1] bfd detect-multiplier 8
ISIS的GE:(平滑重啓)
[R1]isis 1
[R1-isis-1]graceful-restart
[R1-isis-1]graceful-restart t2 100 重啓間隔,默認爲300s
<R1>dis isis graceful-restart status
引入外部路由:
[R3]isis 1
[R3-isis-1]address-family ipv4
[R3-isis-1-ipv4]import-route rip level-2
[R3-rip-1]import-route isis allow-direct 沒有這條命令本地路由不會重分發出去
缺省狀況引入的路由類型爲level-2
路由過濾:
[R1]acl basic 2000
[R1-acl-ipv4-basic-2000]rule deny source 4.4.4.4 0
[R1-acl-ipv4-basic-2000]rule permit source any
[R1-acl-ipv4-basic-2000]quit
[R1]isis
[R1-isis-1]address-family ipv4
[R1-isis-1-ipv4]filter-policy 2000 import
路由聚合:
[R1]isis
[R1-isis-1]address-family ipv4
[R1-isis-1-ipv4]summary 192.168.8.0 22 level-1-2
缺省路由配置:
[R1]isis
[R1-isis-1]address-family ipv4
[R1-isis-1-ipv4]default-route-advertise
Level-1的缺省路由不須要配置,Level-2的缺省路由須要手工配置
修改管理距離:
[R1]isis 1
[R1-isis-1]address-family ipv4
[R1-isis-1-ipv4]preference 20 該命令只對路由器本地有效,不影響其餘路由器
缺省狀況下,IS-IS路由的優先級爲15
修改路由的cost值:
[R1-isis-1]int g0/1
[R1-GigabitEthernet0/1]isis cost 13 默認下不指定類型修改的是level-1
缺省狀況下,IS-IS在接口上的路由權值爲10
修改發送hello的時間:
[R1]int g0/0
[R1-GigabitEthernet0/0]isis timer hello 15
缺省狀況下,接口上Hello報文的發送間隔時間爲10秒
<R1>reset isis peer 2222.2222.2222 1 清除指定鄰居
<R1>reset isis all 清除全部
<R1>dis isis route 查看路由
<R1>dis isis peer 查看鄰居
<R1>dis isis lsdb 查看數據庫