OSPF Advanced: Summarization, Filtering & Authentication

CCNP ENARSI 300-410 EVE-NG / GNS3

مقصدObjectiveObjective

اس لیب میں آپ OSPF route summarization (ABR اور ASBR پر)، distribute-list سے فلٹرنگ، اور OSPF authentication کنفیگر کرنا سیکھیں گے۔Is lab mein aap OSPF route summarization (ABR aur ASBR par), distribute-list se filtering, aur OSPF authentication configure karna seekhenge.In this lab you will learn OSPF route summarization (on ABR and ASBR), filtering with distribute-list, and OSPF authentication.

آسان مثالSimple AnalogySimple Analogy

Summarization ایسے ہے جیسے پورے محلے کے پتوں کی بجائے صرف محلے کا نام بتا دینا — ڈیٹا بیس چھوٹا، اپ ڈیٹس کم۔ Authentication ایسے ہے جیسے ہمسایوں کے درمیان خفیہ کوڈ ورڈ — بغیر کوڈ کے کوئی routing بات چیت میں شامل نہیں ہو سکتا۔Summarization aise hai jaise poore mahalle ke paton ki bajaye sirf mahalle ka naam bata dena — database chhota, updates kam. Authentication aise hai jaise hamsayon ke darmiyan khufiya code word — baghair code ke koi routing baat-cheet mein shamil nahi ho sakta.Summarization is like giving the district name instead of every street address — smaller database, fewer updates. Authentication is like a secret code word between neighbors — nobody joins the routing conversation without it.

سیٹ اپLab SetupLab Setup

R1 ایریا 0 میں، R2 ABR (ایریا 0 اور 1)، R3 ایریا 1 میں جس کے پیچھے LANs 10.10.1.0/24 تا 10.10.4.0/24 ہیں۔ R1 پر ایک external راستہ redistribute کیا گیا ہے۔R1 area 0 mein, R2 ABR (area 0 aur 1), R3 area 1 mein jis ke peeche LANs 10.10.1.0/24 ta 10.10.4.0/24 hain. R1 par ek external rasta redistribute kiya gaya hai.R1 in area 0, R2 as ABR (areas 0 and 1), R3 in area 1 with LANs 10.10.1.0/24 through 10.10.4.0/24 behind it. An external route is redistributed on R1.

اقداماتStepsSteps

Step 1

ABR پر summarization لگائیں۔ R2 (ABR) پر area 1 range کمانڈ سے ایریا 1 کے چاروں LANs کو ایک 10.10.0.0/22 summary میں بدلیں۔ یہ Type 3 LSAs کی تعداد کم کرے گا۔ABR par summarization lagayein. R2 (ABR) par area 1 range command se area 1 ke charon LANs ko ek 10.10.0.0/22 summary mein badlein. Ye Type 3 LSAs ki tadad kam karega.Configure summarization on the ABR. On R2 (ABR), use area 1 range to collapse area 1's four LANs into one 10.10.0.0/22 summary. This reduces the number of Type 3 LSAs.

configure terminal
router ospf 1
area 1 range 10.10.0.0 255.255.252.0
exit

Step 2

Summary کا اثر دیکھیں۔ R1 پر show ip route ospf میں اب چار الگ راستوں کی بجائے ایک O IA 10.10.0.0/22 راستہ نظر آنا چاہیے۔Summary ka asar dekhein. R1 par show ip route ospf mein ab chaar alag raston ki bajaye ek O IA 10.10.0.0/22 rasta nazar aana chahiye.Observe the summary's effect. On R1, show ip route ospf should now show one O IA 10.10.0.0/22 route instead of four separate routes.

show ip route ospf
show ip ospf database summary

Step 3

ASBR پر summarization لگائیں۔ External راستوں کے لیے summary-address کمانڈ ASBR پر لگتی ہے۔ R1 پر external نیٹ ورکس کو ایک summary میں بدلیں۔ASBR par summarization lagayein. External raston ke liye summary-address command ASBR par lagti hai. R1 par external networks ko ek summary mein badlein.Configure summarization on the ASBR. For external routes, the summary-address command goes on the ASBR. Summarize the external networks on R1.

configure terminal
router ospf 1
summary-address 172.16.0.0 255.255.0.0
exit

Step 4

Distribute-list سے فلٹرنگ کریں۔ R3 پر distribute-list سے مخصوص راستے کو routing table میں آنے سے روکیں۔ یاد رکھیں: distribute-list صرف local RIB کو فلٹر کرتی ہے، LSA ڈیٹا بیس کو نہیں۔Distribute-list se filtering karein. R3 par distribute-list se makhsoos raste ko routing table mein aane se rokein. Yaad rakhein: distribute-list sirf local RIB ko filter karti hai, LSA database ko nahi.Filter with a distribute-list. On R3, block a specific route from entering the routing table. Remember: distribute-list only filters the local RIB, not the LSA database.

configure terminal
ip prefix-list BLOCK-ONE seq 5 deny 10.10.3.0/24
ip prefix-list BLOCK-ONE seq 10 permit 0.0.0.0/0 le 32
router ospf 1
distribute-list prefix BLOCK-ONE in
exit

Step 5

OSPF authentication لگائیں۔ انٹرفیس پر message-digest authentication آن کریں اور key chain بنائیں۔ دونوں نیبرز پر key ایک جیسی ہونی چاہیے۔OSPF authentication lagayein. Interface par message-digest authentication on karein aur key chain banayein. Dono neighbors par key ek jaisi honi chahiye.Configure OSPF authentication. Enable message-digest authentication on the interface and create a key. The key must match on both neighbors.

configure terminal
key chain OSPF-KEY
key 1
key-string OspF$ecure
exit
interface GigabitEthernet0/0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 OspF$ecure
exit

Step 6

دوسرے راؤٹر پر بھی authentication لگائیں اور adjacency چیک کریں۔ show ip ospf neighbor سے state FULL نظر آنی چاہیے۔ غلط key پر adjacency INIT یا DOWN رہے گی۔Doosre router par bhi authentication lagayein aur adjacency check karein. show ip ospf neighbor se state FULL nazar aani chahiye. Ghalat key par adjacency INIT ya DOWN rahegi.Apply authentication on the other router and check adjacency. show ip ospf neighbor should show state FULL. With a wrong key the adjacency stays INIT or DOWN.

show ip ospf neighbor
show ip ospf interface GigabitEthernet0/0

تصدیقVerifyVerify

R1 پر summary راستے (O IA اور O E2 summary) نظر آئیں، R3 پر فلٹر شدہ راستہ routing table میں نہ ہو، اور تمام adjacencies FULL ہوں۔R1 par summary raste (O IA aur O E2 summary) nazar aayein, R3 par filter shuda rasta routing table mein na ho, aur tamam adjacencies FULL hon.R1 should show summary routes (O IA and O E2 summary), the filtered route should be absent from R3's routing table, and all adjacencies should be FULL.

show ip route ospf
show ip ospf neighbor

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ Summary لگانے کے بعد بھی پرانے specific راستے نظر آ رہے ہیں۔Summary lagane ke baad bhi purane specific raste nazar aa rahe hain.Old specific routes still appear after configuring the summary.

✅ Summary کے ساتھ ساتھ specific LSAs بھی advertise ہوتے ہیں جب تک contributing راستے موجود ہوں — یہ نارمل ہے۔ اگر صرف summary چاہیے تو distribute-list یا filter-list سے specifics روکیں۔Summary ke saath saath specific LSAs bhi advertise hote hain jab tak contributing raste mojood hon — ye normal hai. Agar sirf summary chahiye to distribute-list ya filter-list se specifics rokein.Specific LSAs are still advertised alongside the summary while contributing routes exist — that's normal. To send only the summary, block specifics with distribute-list or filter-list.

⚠️ Authentication لگانے کے بعد neighbor INIT state میں پھنسا ہے۔Authentication lagane ke baad neighbor INIT state mein phansa hai.Neighbor is stuck in INIT after applying authentication.

✅ Key number اور key-string دونوں طرف ایک جیسے چیک کریں۔ debug ip ospf adj سے دیکھیں کہ authentication failure آ رہی ہے یا نہیں۔Key number aur key-string dono taraf ek jaise check karein. debug ip ospf adj se dekhein ke authentication failure aa rahi hai ya nahi.Verify key number and key-string match on both sides. Use debug ip ospf adj to check for authentication failures.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ area range اور summary-address میں کیا فرق ہے؟area range aur summary-address mein kya farq hai?What is the difference between area range and summary-address?

area range ABR پر لگتی ہے inter-area (Type 3) راستوں کے لیے۔ summary-address ASBR پر لگتی ہے external (Type 5/7) راستوں کے لیے۔area range ABR par lagti hai inter-area (Type 3) raston ke liye. summary-address ASBR par lagti hai external (Type 5/7) raston ke liye.area range goes on the ABR for inter-area (Type 3) routes. summary-address goes on the ASBR for external (Type 5/7) routes.

❓ OSPF میں distribute-list LSA ڈیٹا بیس کو کیوں فلٹر نہیں کرتی؟OSPF mein distribute-list LSA database ko kyun filter nahi karti?Why doesn't distribute-list filter the OSPF LSA database?

کیونکہ OSPF link-state پروٹوکول ہے — ہر راؤٹر کے پاس مکمل ڈیٹا بیس ہونا ضروری ہے۔ distribute-list صرف اس راؤٹر کی اپنی routing table (RIB) میں راستے ڈالنے سے روکتی ہے۔Kyunke OSPF link-state protocol hai — har router ke paas mukammal database hona zaroori hai. distribute-list sirf us router ki apni routing table (RIB) mein raste dalne se rokti hai.Because OSPF is link-state — every router must hold the full database. distribute-list only stops routes from entering that router's own routing table (RIB).