38
38.1 Àí½â²ßÂÔ·ÓÉ
38.1.1 ²ßÂÔ·ÓɸÅÊö
²ßÂÔ·ÓÉÅäÖÃ
²ßÂÔ·ÓÉ£¨PBR£ºPolicy-Based Routing£©ÌṩÁËÒ»ÖֱȻùÓÚÄ¿µÄµØÖ·½øÐзÓÉת·¢¸ü¼ÓÁé»îµÄÊý¾Ý°ü·ÓÉת·¢»úÖÆ¡£²ßÂÔ·ÓÉ¿ÉÒÔ¸ù¾ÝIP/IPv6±¨ÎÄÔ´µØÖ·¡¢Ä¿µÄµØÖ·¡¢¶Ë¿Ú¡¢±¨Îij¤¶ÈµÈÄÚÈÝÁé»îµØ½øÐзÓÉÑ¡Ôñ¡£
ÏÖÓÐÓû§ÍøÂ磬³£³£»á³öÏÖʹÓõ½¶à¸öISP£¨Internet Server Provider£¬Internet·þÎñÌṩÉÌ£©×ÊÔ´µÄÇéÐΣ¬²»Í¬ISPÉêÇëµ½µÄ´ø¿í²»Ò»£»Í¬Ê±£¬Í¬Ò»Óû§»·¾³ÖÐÐèÒª¶ÔÖØµãÓû§×ÊÔ´±£Ö¤µÈÄ¿µÄ£¬¶ÔÕⲿ·ÖÓû§²»Äܹ»ÔÙÒÀ¾ÝÆÕͨ·ÓÉ±í½øÐÐת·¢£¬ÐèÒªÓÐÑ¡ÔñµÄ½øÐÐÊý¾Ý±¨ÎĵÄת·¢¿ØÖÆ£¬Òò´Ë£¬²ßÂÔ·Óɼ¼Êõ¼´Äܹ»±£Ö¤ISP×ÊÔ´µÄ³ä·ÖÀûÓã¬ÓÖÄܹ»ºÜºÃµÄÂú×ãÕâÖÖÁé»î¡¢¶àÑùµÄÓ¦ÓᣠIP/IPv6²ßÂÔ·ÓÉÖ»»á¶Ô½Ó¿Ú½ÓÊյı¨ÎĽøÐвßÂÔ·ÓÉ£¬¶ø¶ÔÓڴӸýӿÚת·¢³öÈ¥µÄ±¨ÎIJ»ÊܲßÂÔ·ÓɵĿØÖÆ£»Ò»¸ö½Ó¿ÚÓ¦ÓòßÂÔ·Óɺ󣬽«¶Ô¸Ã½Ó¿Ú½ÓÊÕµ½µÄËùÓаü½øÐмì²é£¬²»·ûºÏ·ÓÉͼÈκβßÂÔµÄÊý¾Ý°ü½«°´ÕÕÆÕͨµÄ·ÓÉת·¢½øÐд¦Àí£¬·ûºÏ·ÓÉͼÖÐij¸ö²ßÂÔµÄÊý¾Ý°ü¾Í°´ÕոòßÂÔÖж¨ÒåµÄ²Ù×÷½øÐÐת·¢¡£
Ò»°ãÇé¿öÏ£¬²ßÂÔ·ÓɵÄÓÅÏȼ¶¸ßÓÚÆÕͨ·ÓÉ£¬Äܹ»¶ÔIP/IPv6±¨ÎÄÒÀ¾Ý¶¨ÒåµÄ²ßÂÔת·¢£»¼´Êý¾Ý±¨ÎÄÏȰ´ÕÕIP/IPv6²ßÂÔ·ÓɽøÐÐת·¢£¬Èç¹ûûÓÐÆ¥ÅäÈÎÒâÒ»¸öµÄ²ßÂÔ·ÓÉÌõ¼þ£¬ÄÇôÔÙ°´ÕÕÆÕͨ·ÓɽøÐÐת·¢¡£Óû§Ò²¿ÉÒÔÅäÖòßÂÔ·ÓɵÄÓÅÏȼ¶±ÈÆÕͨ·Óɵͣ¬½Ó¿ÚÉÏÊÕµ½µÄIP/IPv6±¨ÎÄÔòÏȽøÐÐÆÕͨ·ÓɵÄת·¢£¬Èç¹ûÎÞ·¨Æ¥ÅäÆÕͨ·ÓÉ£¬ÔÙ½øÐвßÂÔ·ÓÉת·¢¡£
Óû§¿ÉÒÔ¸ù¾Ýʵ¼ÊÇé¿öÅäÖÃÉ豸ת·¢Ä£Ê½£¬ÈçÑ¡Ôñ¸ºÔؾùºâ»òÕßÈßÓ౸·Ýģʽ£¬Ç°ÕßÉèÖõĶà¸öÏÂÒ»Ìø»á½øÐиºÔؾùºâ£¬»¹¿ÉÒÔÉ趨¸ºÔØ·Öµ£µÄ±ÈÖØ£»ºóÕßÊÇÓ¦Óöà¸öÏÂÒ»Ìø´¦ÓÚÈßÓàģʽ£¬¼´Ç°ÃæÓÅÏÈÉúЧ£¬Ö»ÓÐÇ°ÃæµÄÏÂÒ»ÌøÎÞЧʱ£¬ºóÃæ´ÎÓŵÄÏÂÒ»Ìø²Å»áÉúЧ¡£Óû§¿ÉÒÔͬʱÅäÖöà¸öÏÂÒ»ÌøÐÅÏ¢¡£
²ßÂÔ·ÓÉ¿ÉÒÔ·ÖΪÁ½ÖÖÀàÐÍ£º
Ò»¡¢¶Ô½Ó¿ÚÊÕµ½µÄIP±¨ÎĽøÐвßÂÔ·ÓÉ¡£¸ÃÀàÐ͵IJßÂÔ·ÓÉÖ»»á¶Ô´Ó½Ó¿Ú½ÓÊյı¨ÎĽøÐвßÂÔ·ÓÉ£¬¶ø¶ÔÓڴӸýӿÚת·¢³öÈ¥µÄ±¨ÎIJ»ÊܲßÂÔ·ÓɵĿØÖÆ£»
¶þ¡¢¶Ô±¾É豸·¢³öµÄIP±¨ÎĽøÐвßÂÔ·ÓÉ¡£¸ÃÀàÐͲßÂÔ·ÓÉÓÃÓÚ¿ØÖƱ¾»ú·¢ÍùÆäËüÉ豸µÄIP±¨ÎÄ£¬¶ÔÓÚÍⲿÉ豸·¢Ë͸ø±¾»úµÄIP±¨ÎÄÔò²»ÊܸòßÂÔ·ÓÉ¿ØÖÆ¡£
38.1.2 ²ßÂÔ·ÓÉ»ù±¾¸ÅÄî/ÌØÐÔ
38.1.2.1²ßÂÔ·ÓÉÓ¦Óùý³Ì
Ó¦ÓòßÂÔ·ÓÉ£¬±ØÐëÏÈ´´½¨Â·ÓÉͼ£¬È»ºóÔÚ½Ó¿ÚÉÏÓ¦ÓøÃ·ÓÉͼ¡£Ò»¸ö·ÓÉͼÓɺܶàÌõ²ßÂÔ×é³É£¬Ã¿Ìõ²ßÂÔ¶¼ÓжÔÓ¦µÄÐòºÅ£¨Sequence£©£¬ÐòºÅԽС£¬¸ÃÌõ²ßÂÔµÄÓÅÏȼ¶Ô½¸ß¡£
ÿÌõ²ßÂÔÓÖÓÉÒ»Ìõ»òÕß¶àÌõmatchÓï¾äÒÔ¼°¶ÔÓ¦µÄÒ»Ìõ»òÕß¶àÌõsetÓï¾ä×é³É¡£matchÓï¾ä¶¨ÒåÁËIP/IPv6±¨Îĵį¥Å乿Ôò£¬setÓï¾ä¶¨ÒåÁ˶ԷûºÏÆ¥Å乿ÔòµÄIP/IPv6±¨ÎÄ´¦Àí¶¯×÷¡£ÔÚ²ßÂÔ·ÓÉת·¢¹ý³Ì£¬±¨ÎÄÒÀÓÅÏȼ¶´Ó¸ßµ½µ×ÒÀ´ÎÆ¥Å䣬ֻҪƥÅäÇ°ÃæµÄ²ßÂÔ£¬¾ÍÖ´ÐиòßÂÔ¶ÔÓ¦µÄ¶¯×÷£¬È»ºóÍ˳ö²ßÂÔ·ÓɵÄÖ´ÐС£
IP²ßÂÔ·ÓÉʹÓÃIP±ê×¼»òÕßÀ©Õ¹ACL×÷ΪIP±¨Îĵį¥Å乿Ôò£¬IPv6²ßÂÔ·ÓÉʹÓÃIPv6À©Õ¹ACL×÷ΪIPv6±¨Îĵį¥Å乿Ôò¡£IPv6²ßÂÔ·ÓɶÔÓÚͬһÌõ²ßÂÔ×î¶àÖ»ÄÜÅäÖÃÒ»¸ömatch ipv6 address¡£
38.1.2.2·ÓÉͼ²ßÂÔÆ¥Åäģʽ
ÔÚÅäÖ÷ÓÉͼʱ£¬¿ÉÒÔÖ¸¶¨Ã¿Ò»Ìõ²ßÂÔµÄÆ¥ÅäģʽΪpermit»òÕß deny£¬ÆäÒâÒåÈçÏ£º
? permit£ºÖ¸¶¨¸Ã²ßÂÔµÄÆ¥ÅäģʽΪÔÊÐíģʽ£¬¼´µ±±¨ÎÄÂú×ã¸Ã²ßÂÔµÄmatch¹æÔòʱ£¬»á¶Ô
¸ÃIP/IPv6±¨ÎÄÓ¦ÓÃÏàÓ¦µÄset¹æÔò£»È籨ÎIJ»Âú×ã²ßÂÔµÄËùÓÐmatch¹æÔò£¬±¨ÎĽ«»áʹÓÃ
¸Ã·ÓÉͼµÄÏÂÒ»Ìõ²ßÂÔ½øÐÐÆ¥Åä¡£
? deny£ºÖ¸¶¨¸Ã²ßÂÔµÄÆ¥ÅäģʽΪ¾Ü¾øÄ£Ê½£¬¼´µ±±¨ÎÄÂú×ã¸Ã½ÚµãµÄËùÓÐmatchÓï¾äʱ£¬²»
¶Ô¸ÃIP/IPv6±¨ÎÄÖ´ÐвßÂÔת·¢¶øÊÇÖ´ÐÐÆÕͨµÄ·ÓÉת·¢¡£
IP/IPv6±¨Îİ´ÕÕ·ÓÉͼÖÐÿһÌõ²ßÂÔµÄÓÅÏȼ¶Óɸߵ½µÍÒÀ´Î½øÐÐÆ¥Å䣬ֻҪƥÅäÁËÇ°ÃæµÄ²ßÂÔ¾ÍÖ´ÐÐÏàÓ¦µÄ¶¯×÷²¢Í˳ö²ßÂÔת·¢Á÷³Ì£»Èç¹ûIP/IPv6±¨ÎIJ»ÄÜÆ¥Åä·ÓÉͼÖеÄÈκβßÂÔ£¬ÄÇô½«»á¶ÔIP/IPv6±¨ÎÄÖ´ÐÐÆÕͨµÄ·ÓÉת·¢¡£
38.1.2.3ÏÂÒ»Ìø¹æÔò¸ÅÄî
µ±Ç°²ßÂÔ·ÓÉÌṩÁËset {ip | ipv6} next-hop¡¢set {ip | ipv6} default next-hopÁ½Ìõת·¢¹æÔò¡£ºóÃæÁ½ÌõΪÉèÖÃȱʡÏÂÒ»ÌøºÍ³ö½Ó¿Ú¡£ÕâÁ½Ìõ¹æÔòµÄÒâÒåÈçÏ£º
? set {ip | ipv6} next-hop£ºÅäÖòßÂÔ·ÓÉÏÂÒ»ÌøIP/IPv6µØÖ·£¬ÓÅÏȼ¶±ÈÆÕͨ·Óɸߣ¬´Ó½Ó¿Ú
ÉÏÊÕµ½µÄÆ¥Åämatch¹æÔòµÄIP/IPv6±¨ÎĽ«ÓÅÏÈת·¢µ½set {ip | ipv6} next-hopËùÖ¸¶¨µÄÏÂÒ»Ìø£¬¶ø²»¹Ü¸ÃIP/IPv6±¨ÎÄÔÚ·ÓɱíÖеÄʵ¼Êѡ·½á¹ûºÍ²ßÂÔ·ÓÉÖ¸¶¨µÄÏÂÒ»ÌøÊÇ·ñÒ»Ö¡£ ? set {ip | ipv6} default next-hop£º¸ÃÃüÁîÖ¸¶¨µÄ²ßÂÔ·ÓɵÄÓÅÏȼ¶±ÈÆÕͨ·Óɵĵͣ¬µ«ÊDZÈ
ĬÈÏ·Óɸߡ£´Ó½Ó¿ÚÉÏÊÕµ½µÄÆ¥Åämatch¹æÔòµÄIP/IPv6±¨ÎÄ£¬Èç¹û¸Ã±¨ÎÄÔÚ·ÓɱíÖÐѡ·ʧ°Ü»òÕßÑ¡µ½Ä¬ÈÏ·ÓÉ£¬ÄÇôIP/IPv6±¨ÎĽ«×ª·¢µ½¸ÃÃüÁîÖ¸¶¨µÄÏÂÒ»Ìø¡£
ÉÏÊöǰÁ½Ìõ¹æÔòÖ¸¶¨µÄÏÂÒ»Ìø±ØÐëÊÇÖ±Á¬µÄ£¬·ñÔò²»»áÉúЧ£»Èç¹ûÏÂÒ»Ìø²»ÊÇÖ±Á¬µÄ£¬²ßÂÔ·ÓɵÄЧ¹ûÏ൱ÓÚûÓÐÅäÖøÃÃüÁî¡£
ÉÏÊöÁ½ÌõÃüÁîµÄÓÅÏȼ¶Ë³ÐòΪ£ºset {ip | ipv6} next-hop > ÍøÂç·ÓÉ/Ö÷»ú·ÓÉ > set {ip | ipv6} default next-hop >ȱʡ·ÓÉ¡£ÕâÁ½ÌõÃüÁîÄܹ»Ö§³ÖͬʱÅäÖ㬵«Ö»ÓиßÓÅÏȼ¶µÄÉúЧ¡£
38.1.2.4²ßÂÔ·ÓÉÏÂÒ»Ìø¸ºÔؾùºâģʽ
Ò»¸ö·ÓÉͼSequenceÖÐÄܹ»ÅäÖöà¸öÏÂÒ»Ìø£¬¶à¸öÏÂÒ»ÌøÖ®¼äÄܹ»ÊµÏÖÁ½ÖÖ¸ºÔؾùºâģʽ£º ? ÈßÓ౸·Ýģʽ£¬Ö§³ÖÓÅÏÈÉúЧ£¬Ê§Ð§½Ó¹ÜµÄģʽ£¬¶à¸öÏÂÒ»ÌøÖ®¼äͬһʱ¿ÌÖ»ÓÐÒ»¸öÏÂÒ»
ÌøÉúЧ¡£
? Ç°ÃæµÄÏÂÒ»ÌøR1ʧЧ»á×Ô¶¯Çл»µ½ÏÂÒ»¸öÏÂÒ»ÌøR2£¬µ±R1ÖØÐ»ָ´ÉúЧʱ£¬»áÔÙ
×Ô¶¯ÔÙÇл»»ØR1£» ? µ±´æÔÚ¶à¸öÏÂÒ»Ìø£¬ÈçR1/R2/R3µÈ£¬É¾³ýR1ÔÙÌí¼ÓR1ʱ£¬»áÔÚºóÃæÌí¼Ó£¬ÈçR2/R3/R1£¬
´ÎÖ®µÄR2ÉúЧ¡£
? ¸ºÔؾùºâģʽ£¬¶à¸öÏÂÒ»ÌøÖ®¼ä»ùÓÚÁ÷½øÐиºÔØ·Öµ£¡£ÏÂÒ»ÌøÎª³ö½Ó¿ÚÐÎʽ£¬¶ÔÕâ¸ö¹¦Äܲ»Ö§³Ö¡£
1¡¢Èñ½Ý²úÆ·ÉÏÒ»¸ö½Ó¿Ú×î¶àÖ»ÄÜÅäÖÃÒ»¸ö·ÓÉͼ£¬ÔÚͬһ¸ö½Ó¿ÚÉ϶à´ÎÅäÖ÷ÓÉͼ»áÏ໥¸²¸Ç£¬¼´ºóÅäÖõÄÉúЧ¡£
2¡¢²ßÂÔ·ÓÉ×Ó·ÓÉͼ(route-map sequence)ÖÐ×î¶àÖ»ÄÜÅäÖÃÒ»¸öIPV6 ACL¡£ 3¡¢Èç¹ûÅäÖõÄ×Ó·ÓÉͼÖÐÖ»ÓÐnext-hop¶øÃ»ÓÐÅäÖÃACL£¬ÔòµÈ¼ÛÓÚËùÓб¨ÎĶ¼Æ¥Å䣻Èç¹û×Ó·ÓÉͼÖÐÖ»ÓÐACL¶øÃ»ÓÐnext-hopÔòÆ¥ÅäµÄ±¨ÎÄÆÕͨת·¢£»Èç¹û×Ó·ÓÉͼÖм´Ã»ÓÐACLҲûÓÐnext-hop£¬ÔòµÈ¼ÛËùÓб¨ÎÄÆÕͨת·¢¡£
4¡¢²ßÂÔ·ÓÉÈç¹ûÅäÖÃÁËACL£¬µ«ÊǸÃACL²»´æÔÚ£¬µÈ¼ÛËùÓб¨ÎĶ¼Æ¥Å䣻Èç¹ûÅäÖÃÁËACL£¬µ«ÊÇÆäÖÐûÓÐÈκÎACE£¬Ï൱ÓÚÆ¥Åäµ½ÁËÇý¶¯Ìí¼ÓµÄdeny anyÌõÄ¿£¬
²»»á´ÓÏÂÒ»¸ö×Ó·ÓÉͼµÄACL¿ªÊ¼Æ¥Å䣻
5¡¢½»»»»úÉÏ£¬ACEµÄdenyÑ¡ÏîÐÐΪ£¬Ö´ÐÐÆÕͨת·¢£»²¢ÇÒΪÁËÂú×ã²ßÂÔ·Óɵį¥Åä˳Ðò£¬deny any anyÐÐΪÊÇÌøµ½Ï¸öIPV6 ACL¿ªÊ¼Æ¥Åä¡£
6¡¢½»»»»úÉÏ£¬ÅäÖÃÁËPBR¹¦ÄÜ£¬»á¶Ô·¢Íù±¾»úµÄ±¨ÎÄͬʱÉúЧ£¬Èç¹ûÓû§Ï£Íû·¢Íù±¾»úµÄIP/IPv6±¨ÎIJ»Ê¹ÓòßÂÔ·ÓÉ£¬ÔòÓû§ÐèÒªÔÚPBR¹æÔòÖÐÔÚIP/IPV6 ACLÇ°ÃæÊÖ¹¤Ìí¼Ó¡°denyÉ豸IP/IPv6µØÖ·¡±µÄACE¡£
7¡¢¹¤×÷ÔÚÈßÓ౸·ÝģʽÏÂʱ£¬Æ¥Åä·ÓÉ×ÓͼµÄ²ßÂÔ¹æÔòµÄIP±¨ÎÄת·¢µ½¸Ã·ÓÉ×ÓͼÖеÚÒ»¸ö½âÎöµÄÏÂÒ»Ìø£»Èç¹ûËùÓеÄÏÂÒ»Ìø¶¼Î´½âÎö£¬ÔòÆ¥Åä²ßÂÔ¹æÔòµÄIP±¨Îı»¶ªÆú£»Èç¹ûµÚÒ»¸öÏÂÒ»ÌøÔÏÈδ½âÎöºóÀ´½âÎöÁË£¬ÔòÆ¥Åä²ßÂÔ¹æÔòIP±¨ÎĵÄת·¢½«Çл»µ½µÚÒ»¸öÏÂÒ»Ìø¡£
? ×¢Òâ
? ˵Ã÷ PBRÓëBFDÁª¶¯¹¦ÄÜÇë²Î¼ûÈñ½Ý¡¶BFDÅäÖá·£¬¡¶ÅäÖÃBFDÃüÁî¡·¡£
38.1.3 ²ßÂÔ·ÓÉʹÓÃBFD¹¦ÄÜ
²ßÂÔ·ÓÉÓëBFDÁª¶¯£¬¿ÉÒÔ±ÜÃâÔÚÅäÖõIJßÂÔ·Óɲ»¿É´ïµÄÇé¿öÏ£¬Â·ÓÉѡ·²»»áÑ¡Ôñ¸Ã²ßÂÔ·ÓÉ×÷Ϊת·¢Â·¾¶¡£Èç¹û´æÔÚ±¸·Ý·ÓÉת·¢Â·¾¶£¬½«¿ÉÒÔ¿ìËÙµØÇл»µ½¸Ã±¸·Ýת·¢Â·¾¶¡£
38.1.4 ¹¤×÷ÔÀí
²ßÂÔ·ÓÉ£¬Ê×ÏÈÐèÒª¶¨ÒåÒ»¸ö·ÓÉͼ£¬ÓÃÓÚÖ¸¶¨±¨ÎÄת·¢µ½ÄĶùÈ¥µÄ²ßÂÔ£»Â·ÓÉͼÊÇÒ»×éÓï¾ä×é³É£¬¿ÉÒÔ¶¨ÒåΪ¡°Permit¡±ºÍ¡°Deny¡±ÐÐΪ£»
Æä´Î£¬Ê¹ÓÃsetÓï¾ä¿ØÖƱ¨ÎÄת·¢ÐÐΪ¡£±¨ÎÄת·¢¿ØÖÆÊÇͨ¹ýÔÚPBR·ÓÉͼÖж¨ÒåÒ»×ésetÓï¾äʵ
ÏÖ£»ÒÀÐòʹÓÃÿһ¸ösetÓï¾ä½øÐб¨ÎÄת·¢£»Ã¿Ò»¸öÓï¾ä¶¼²»»á²Î¿¼Ç°Ãæ»òÕߺóÃæµÄÓï¾ä¡£