ipv6 6to4 tunnel测试

一.测试拓扑:

二.基本要求:
A.两边IPV4的网络能够访问互联网
B.两边的IPV6的网络能够互访
C.两边的IPV6的网络能否访问native IPV6的网络

三.基础配置:
A.R1:
ipv6 unicast-routing
interface FastEthernet0/0
    ip address 172.16.1.1 255.255.255.0
    no shut
interface FastEthernet0/1
    ipv6 address 2002:CA64:101::1/48
    no shut
interface FastEthernet1/0
    ip address 202.100.1.1 255.255.255.0
    no shut
ip route 0.0.0.0 0.0.0.0 202.100.1.2
B.R2:
interface FastEthernet0/0
    ip address 202.100.1.2 255.255.255.0
    no shut
interface FastEthernet0/1
    ip address 202.100.2.2 255.255.255.0
    no shut
interface FastEthernet1/0
    ip address 202.100.3.2 255.255.255.0
    no shut
C.R3:
ipv6 unicast-routing
interface FastEthernet0/0
    ip address 192.168.1.3 255.255.255.0
    no shut
interface FastEthernet0/1
    ipv6 address 2002:CA64:203::3/48
    no shut
interface FastEthernet1/0
    ip address 202.100.2.3 255.255.255.0
    no shut
ip route 0.0.0.0 0.0.0.0 202.100.2.2
D.R4:
interface FastEthernet0/0
    ip address 172.16.1.4 255.255.255.0
    no shut
ip route 0.0.0.0 0.0.0.0 172.16.1.1
E.R5:
ipv6 unicast-routing
interface FastEthernet0/0
    ipv6 address 2002:CA64:101::5/48
    no shut
ipv6 route ::/0 2002:CA64:101::1
F.R6:
interface FastEthernet0/0
    ip address 192.168.1.6 255.255.255.0
    no shut
ip route 0.0.0.0 0.0.0.0 192.168.1.3
G.R7:
ipv6 unicast-routing
interface FastEthernet0/0
    ipv6 address 2002:CA64:203::7/48
    no shut
ipv6 route ::/0 2002:CA64:203::3
H.R8:
ipv6 unicast-routing
interface FastEthernet0/0
    ip address 202.100.3.8 255.255.255.0
    no shut
interface FastEthernet0/1
    ipv6 address 2001:1::8/64
    ipv6 enable
    no shut
ip route 0.0.0.0 0.0.0.0 202.100.3.2
I.R9:
ipv6 unicast-routing
interface FastEthernet0/0
    ipv6 address 2001:1::9/64
    ipv6 enable
    no shut
ipv6 route ::/0 2001:1::8
四.需求配置:
A.两边IPV4的网络能够访问互联网
----通过配置R1和R3的PAT实现
①R1:
interface FastEthernet0/0
    ip nat inside
interface FastEthernet1/0
    ip nat outside
ip access-list extended PAT
    permit ip 172.16.1.0 0.0.0.255 any
ip nat inside source list NAT interface FastEthernet1/0 overload
验证:
R4#PING 202.100.1.2

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 202.100.1.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 56/82/132 ms
②R3:
interface FastEthernet0/0
    ip nat enable
interface FastEthernet1/0
    ip nat enable
ip access-list extended PAT
    permit ip 192.168.1.0 0.0.0.255 any
ip nat source list PAT interface FastEthernet1/0 overload
验证:
R6#PING 202.100.2.2

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 202.100.2.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 44/78/144 ms
B.两边的IPV6的网络能够互访
----通过配置R1和R4的6to4 tunnel实现
①R1:
interface Tunnel0
    ipv6 unnumbered FastEthernet0/1
    tunnel source FastEthernet1/0
    tunnel mode ipv6ip 6to4
ipv6 route 2002::/16 Tunnel0
②R3:
interface Tunnel0
    ipv6 unnumbered FastEthernet0/1
    tunnel source FastEthernet1/0
    tunnel mode ipv6ip 6to4
ipv6 route 2002::/16 Tunnel0
③验证:
R5#ping 2002:CA64:203::7

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2002:CA64:203::7, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 132/195/384 ms
R5#
R7#debug ipv6 icmp
 ICMP Packet debugging is on
R7#
*Dec 29 16:27:54.439: ICMPv6: Received N-Solicit, Src=FE80::C823:10FF:FEA0:6, Dst=FF02::1:FF00:7
*Dec 29 16:27:54.447: ICMPv6: Sent N-Advert, Src=2002:CA64:203::7, Dst=FE80::C823:10FF:FEA0:6
*Dec 29 16:27:54.471: ICMPv6: Received echo request, Src=2002:CA64:101::5, Dst=2002:CA64:203::7
*Dec 29 16:27:54.479: ICMPv6: Sent echo reply, Src=2002:CA64:203::7, Dst=2002:CA64:101::5
*Dec 29 16:27:54.483: ICMPv6: Sent N-Solicit, Src=2002:CA64:203::7, Dst=FF02::1:FF00:3
*Dec 29 16:27:54.595: ICMPv6: Received N-Advert, Src=2002:CA64:203::3, Dst=2002:CA64:203::7
*Dec 29 16:27:54.739: ICMPv6: Received echo request, Src=2002:CA64:101::5, Dst=2002:CA64:203::7
R7#
*Dec 29 16:27:54.739: ICMPv6: Sent echo reply, Src=2002:CA64:203::7, Dst=2002:CA64:101::5
*Dec 29 16:27:54.907: ICMPv6: Received echo request, Src=2002:CA64:101::5, Dst=2002:CA64:203::7
*Dec 29 16:27:54.907: ICMPv6: Sent echo reply, Src=2002:CA64:203::7, Dst=2002:CA64:101::5
*Dec 29 16:27:55.031: ICMPv6: Received echo request, Src=2002:CA64:101::5, Dst=2002:CA64:203::7
*Dec 29 16:27:55.035: ICMPv6: Sent echo reply, Src=2002:CA64:203::7, Dst=2002:CA64:101::5
*Dec 29 16:27:55.163: ICMPv6: Received echo request, Src=2002:CA64:101::5, Dst=2002:CA64:203::7
*Dec 29 16:27:55.163: ICMPv6: Sent echo reply, Src=2002:CA64:203::7, Dst=2002:CA64:101::5
R7#
*Dec 29 16:27:59.451: ICMPv6: Sent N-Solicit, Src=FE80::C827:10FF:FE34:8, Dst=FE80::C823:10FF:FEA0:6
*Dec 29 16:27:59.471: ICMPv6: Received N-Advert, Src=FE80::C823:10FF:FEA0:6, Dst=FE80::C827:10FF:FE34:8
*Dec 29 16:28:00.035: ICMPv6: Sent R-Advert, Src=FE80::C827:10FF:FE34:8, Dst=FF02::1
R7#
*Dec 29 16:28:04.487: ICMPv6: Received N-Solicit, Src=FE80::C823:10FF:FEA0:6, Dst=FE80::C827:10FF:FE34:8
*Dec 29 16:28:04.491: ICMPv6: Sent N-Advert, Src=FE80::C827:10FF:FE34:8, Dst=FE80::C823:10FF:FEA0:6
C.两边的IPV6的网络能否访问native IPV6的网络
----配置R8为IPV6 6to4 Relay实现,并且R1和R3需要将IPV6默认路由指向R8
①R8:
interface Tunnel2002
    description 6to4 relay service
    ipv6 address 2002:CA64:308::1/48
    ipv6 enable
    tunnel source FastEthernet0/0
    tunnel mode ipv6ip 6to4
----CA64:308为202.100.3.8对应的16位编码
②R1和R3:
ipv6 route ::/0 2002:CA64:308::1
----IPV6默认路由指向R8的tunnel2002接口地址
③验证:
R5#PING 2001:1::9

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:1::9, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 92/135/152 ms
R9#debug ipv6 icmp
R9#
*Dec 29 16:35:38.083: ICMPv6: Received echo request, Src=2002:CA64:101::5, Dst=2001:1::9
*Dec 29 16:35:38.083: ICMPv6: Sent echo reply, Src=2001:1::9, Dst=2002:CA64:101::5
*Dec 29 16:35:38.207: ICMPv6: Received echo request, Src=2002:CA64:101::5, Dst=2001:1::9
*Dec 29 16:35:38.207: ICMPv6: Sent echo reply, Src=2001:1::9, Dst=2002:CA64:101::5
*Dec 29 16:35:38.375: ICMPv6: Received echo request, Src=2002:CA64:101::5, Dst=2001:1::9
*Dec 29 16:35:38.375: ICMPv6: Sent echo reply, Src=2001:1::9, Dst=2002:CA64:101::5
*Dec 29 16:35:38.491: ICMPv6: Received echo request, Src=2002:CA64:101::5, Dst=2001:1::9
R9#
*Dec 29 16:35:38.491: ICMPv6: Sent echo reply, Src=2001:1::9, Dst=2002:CA64:101::5
*Dec 29 16:35:38.579: ICMPv6: Received echo request, Src=2002:CA64:101::5, Dst=2001:1::9
*Dec 29 16:35:38.583: ICMPv6: Sent echo reply, Src=2001:1::9, Dst=2002:CA64:101::5


你可能感兴趣的:(ipv6 6to4 tunnel测试)