DYNAMIC MAPPING ( PHASE 2 ) - DMVPN #5 ( CCNP )
DMVPN #5 :
DYNAMIC MAPPING ( PHASE 2 )
Required :
- Laptop
- VMware
- EVE NG
Dalam DMVPN Phase 1 kita melihat bahwa tidak ada komunikasi Spoke – Spoke langsung. Nah, didalam Phase 2 akan ada Multipoint Tunnel GRE pada Spokes, bukan Tunnel point to Point GRE.Jadi kita bisa tunneling point to point langsung di Phase 2. Perbedaanya antara Spoke 1 dan spoke 2 adalah didalam Phase 2, Spokes sekarang memiliki Interface Multipoint GRE Tunnel dan Tidak akan ada Destination yang dikonfigurasi secara manual pada Spokes.
R1 :
Router(config)#int e0/0
Router(config-if)#ip address 30.30.30.1 255.255.255.0
Router(config-if)#no sh
R2 :
Router(config)#int e0/0
Router(config-if)#ip address 30.30.30.2 255.255.255.0
Router(config-if)#no sh
Router(config-if)#int e0/1
Router(config-if)#ip address 10.10.10.1 255.255.255.0
Router(config-if)#no sh
Router(config-if)#int e0/2
Router(config-if)#ip address 20.20.20.1 255.255.255.0
Router(config-if)#no sh
R3 :
Router(config)#int e0/0
Router(config-if)#ip address 10.10.10.2 255.255.255.0
Router(config-if)#no sh
R4 :
Router(config)#int e0/0
Router(config-if)#ip address 20.20.20.2 255.255.255.0
Router(config-if)#no sh
Setelah menambahkan IP Address, saatnya menambahkan Default Route untuk Connectivity pada HUB,Spoke 1 dan 2 :
R1 :
Router(config)#ip route 0.0.0.0 0.0.0.0 30.30.30.2
R3 :
Router(config)#ip route 0.0.0.0 0.0.0.0 10.10.10.1
R4 :
Router(config)#ip route 0.0.0.0 0.0.0.0 20.20.20.1
Setelah menambahkan Default Route, saatnya membuat Dynamic Mapping menggunakan NHRP :
R1 :
Router(config)#int tun0
Router(config-if)#ip address 192.168.10.1 25
Router(config-if)#ip address 192.168.10.1 255.255.255.0
Router(config-if)#tunnel mode gre multipoint
Router(config-if)#tunnel source 10.10.10.1
Router(config-if)#ip nhrp network-id 1
Router(config-if)#ip nhrp authentication IDN
Router(config-if)#ip nhrp map multicast dynamic
Router(config-if)#no tunnel source 10.10.10.1
Router(config-if)#tunnel source 30.30.30.1
R3 :
Router(config)#int tun0
Router(config-if)#ip address 192.168.10.2 255.255.255.0
Router(config-if)#tunnel source 10.10.10.2
Router(config-if)#ip nhrp authentication IDN
Router(config-if)#ip nhrp map 192.168.10.1 30.30.30.1
Router(config-if)#ip nhrp nhs 192.168.10.1
Router(config-if)#ip nhrp map multicast 30.30.30.1
R4 :
Router(config)#int tun0
Router(config-if)#ip add 192.168.10.3 255.255.255.0
Router(config-if)#tunnel source 20.20.20.2
Router(config-if)#ip nhrp network-id 1
Router(config-if)#ip nhrp authentication IDN
Router(config-if)#ip nhrp map 192.168.10.1 30.30.30.1
Router(config-if)#ip nhrp nhs 192.168.10.1
Router(config-if)#ip nhrp map multicast 30.30.30.1
Untuk mengubah Dynamic Mapping menjadi Phase 2, kita harus menambahkan Konfigurasi tunnel mode gre multipoint bukan pada HUB tetapi pada Spoke 1 dan 2 :
R3 :
Legend: Attrb --> S - Static, D - Dynamic, I - Incomplete
N - NATed, L - Local, X - No Socket
# Ent --> Number of NHRP entries with same NBMA peer
NHS Status: E --> Expecting Replies, R --> Responding, W --> Waiting
UpDn Time --> Up or Down Time for a Tunnel
==========================================================================
Interface: Tunnel0, IPv4 NHRP Details
Type:Hub, NHRP Peers:2,
# Ent Peer NBMA Addr Peer Tunnel Add State UpDn Tm Attrb
----- --------------- --------------- ----- -------- -----
1 10.10.10.2 192.168.10.2 UP 00:00:58 D
1 20.20.20.2 192.168.10.3 UP 00:04:30 D= sudah terdaftar di list dmvpn
Router(config)#do show Ip nhrp
192.168.10.2/32 via 192.168.10.2
Tunnel0 created 00:09:27, expire 01:50:32
Type: dynamic, Flags: unique registered used nhop
NBMA address: 10.10.10.2
192.168.10.3/32 via 192.168.10.3
Tunnel0 created 00:12:58, expire 01:47:01
Type: dynamic, Flags: unique registered used nhop
NBMA address: 20.20.20.2= mereka berdua dynamic
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.10.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Router(config)#do ping 192.168.10.3
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.10.3, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Router(config)#= semua spoke bisa di ping
Komentar
Posting Komentar