<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="cs">
		<id>https://czfree.net/wiki/index.php?action=history&amp;feed=atom&amp;title=CZF-RFC-ROUTING</id>
		<title>CZF-RFC-ROUTING - Historie editací</title>
		<link rel="self" type="application/atom+xml" href="https://czfree.net/wiki/index.php?action=history&amp;feed=atom&amp;title=CZF-RFC-ROUTING"/>
		<link rel="alternate" type="text/html" href="https://czfree.net/wiki/index.php?title=CZF-RFC-ROUTING&amp;action=history"/>
		<updated>2026-04-05T03:02:54Z</updated>
		<subtitle>Historie editací této stránky</subtitle>
		<generator>MediaWiki 1.30.0</generator>

	<entry>
		<id>https://czfree.net/wiki/index.php?title=CZF-RFC-ROUTING&amp;diff=1659&amp;oldid=prev</id>
		<title>Hwsoft: /* CZF-RFC-ROUTING */</title>
		<link rel="alternate" type="text/html" href="https://czfree.net/wiki/index.php?title=CZF-RFC-ROUTING&amp;diff=1659&amp;oldid=prev"/>
				<updated>2007-04-14T16:54:40Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;CZF-RFC-ROUTING&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr style=&quot;vertical-align: top;&quot; lang=&quot;cs&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Starší verze&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Verze z 14. 4. 2007, 16:54&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l129&quot; &gt;Řádek 129:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Řádek 129:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; !&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; !&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; ip prefix-list cloudtransin description CZFree.NET inter-cloud filter IN&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; ip prefix-list cloudtransin description CZFree.NET inter-cloud filter IN&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; ip prefix-list cloudtransin seq 10 permit 10.0.0.0/8 ge 15 le &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;10&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; ip prefix-list cloudtransin seq 10 permit 10.0.0.0/8 ge 15 le &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;20&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; ip prefix-list cloudtransin seq 20 deny any&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; ip prefix-list cloudtransin seq 20 deny any&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; ip prefix-list cloudtransout description CZFree.NET inter-cloud filter OUT&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; ip prefix-list cloudtransout description CZFree.NET inter-cloud filter OUT&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key czfree-wiki_:diff:version:1.11a:oldid:1397:newid:1659 --&gt;
&lt;/table&gt;</summary>
		<author><name>Hwsoft</name></author>	</entry>

	<entry>
		<id>https://czfree.net/wiki/index.php?title=CZF-RFC-ROUTING&amp;diff=1397&amp;oldid=prev</id>
		<title>Danny v 30. 12. 2006, 22:35</title>
		<link rel="alternate" type="text/html" href="https://czfree.net/wiki/index.php?title=CZF-RFC-ROUTING&amp;diff=1397&amp;oldid=prev"/>
				<updated>2006-12-30T22:35:38Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Nová stránka&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== CZF-RFC-ROUTING ==&lt;br /&gt;
&lt;br /&gt;
Toto CZF-RFC popisuje implementaci dynamickych smerovacich protokolu na jednotlivych NODEch v CZFree.Netu.&lt;br /&gt;
&lt;br /&gt;
Dokument CZF-RFC-ROUTING pouziva pojmy NODE, CLOUD a POINT tak, jak jsou definovany v [[CZF-RFC-BASE]]. Prikladove konfigurace smerovacich daemonu vychazeji z adresniho planu tvoreneho podle [[CZF-RFC-ADDRESSING]].&lt;br /&gt;
&lt;br /&gt;
Cely CZFree.Net je rozdelen na CLOUDy. Z hlediska smerovani zastava CLOUD autonomni system (dale jen AS) s vlastnim ASN pro peerovani s ostatnimi CLOUDy. Jako externi smerovaci protokol musi byt v celem CZFree.Netu pouzito BGP. Podle CZF-RFC-BASE je kazdemu CLOUDu pridelen prave jeden /16 IPv4 rozsah, coz je take jediny rozsah, ktery smi propagovat pres BGP. Kazdy CLOUD musi poskytovat plny tranzit vsem ostatnim CLOUDum. Nedeje se tak pouze v pripade, ze se na tom obe strany dobrovolne dohodly a nema to vliv na prenaseny traffic ostatnich CLOUDu. BGP smerovaci daemon bezi pouze na routerech, ktere zprostredkovavaji spojeni s ostatnimi CLOUDy (dale jen CBR - 'Cloud Border Routery'). CBR jednoho CLOUDu vzajemne peeruji pomoci iBGP.&lt;br /&gt;
&lt;br /&gt;
Pro smerovani uvnitr CLOUDu, jako interni smerovaci protokol, muze byt pouzito OSPF. V tom pripade plati pro jeho implementaci nasledujici doporuceni: Z adresniho prostoru CLOUDu je vyhrazen rozsah 10.C.0.0/26, ktery je pouzit pro alokaci loopback adres jednotlivych NODU, ktere jsou pouzity jako router-id adresy. Mezi vsemi NODY v CLOUDu je na area 0 pouzita OSPF message-digest md5 authentizace. Vsude je pouzito jednotne ocenovani linek (viz. priloha A). Na CBR je do OSPF distribuovana BGP smerovaci tabulka. V OSPF se nikdy nesmi objevit vychozi cesta, internetovy traffic je smerovan podle zdrojove adresy do tunelu. Kazdy NODE propaguje pres OSPF pouze svoji loopback adresu (/32)+/30 rozsahy pro p2p spoje+vsechny /24 adresove prostory, ktere mu byly na zaklade opodstatnene zadosti prideleny CLOUD mastery podle CZF-RFC-ADDRESSING. Pokud NODE pripojuje nejake stub networks (koncove podsite, nepripojujici dalsi NODY), vytvari pro ne area s cislem N (viz 10.C.0.N/32 loopback) a sumarizuje rozdelene podsite na /24 prefixy.&lt;br /&gt;
&lt;br /&gt;
(v prikladovych konfiguracich neni uvazeno smerovani internetoveho trafficu prez tunely a jeste bude doplnena OSPF md5 authentizace na area 0)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''priloha A: staticke ocenovani OSPF linek'''&lt;br /&gt;
&lt;br /&gt;
 bit / sec             byte/sec        OSPF cost&lt;br /&gt;
 eth    1G               100M                1&lt;br /&gt;
 eth  100M                10M               10&lt;br /&gt;
 eth   10M                 1M              100&lt;br /&gt;
 sbni   2M               200K              500&lt;br /&gt;
 sbni   1M               100K             1000&lt;br /&gt;
 sbni 500K                50K             2000&lt;br /&gt;
 sbni 250K                25K             4000&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''priloha B: bgpd.conf'''&lt;br /&gt;
&lt;br /&gt;
 !&lt;br /&gt;
 ! hostname nastavuje jmeno systemu. &lt;br /&gt;
 ! password a enable password jsou hesla pro pristup do bgpd. enable password se od password&lt;br /&gt;
 !   lisi v tom, ze umoznuje primo konfigurovat bgpd pres terminal. Obe hesla jsou diky&lt;br /&gt;
 !   service password-encryption zasifrovana, takze muzete svuj config libovolne ukazovat&lt;br /&gt;
 !   a nemusite porad mazat ty dve radky. &lt;br /&gt;
 ! log file nastavuje soubor, do ktereho se budou zapisovat hlaseni bgpd.&lt;br /&gt;
 ! service advanced-vty nastavi rozsireni mod pro ovladani terminalu.&lt;br /&gt;
 !&lt;br /&gt;
 hostname kojott&lt;br /&gt;
 password 8 EprZLRtwJRfUM&lt;br /&gt;
 enable password 8 bCPeRwRCRo4mE&lt;br /&gt;
 log file /var/log/zebra-bgpd.log&lt;br /&gt;
 service advanced-vty&lt;br /&gt;
 service password-encryption&lt;br /&gt;
 !&lt;br /&gt;
 ! debug bgp zapina ladici funkce BGP.&lt;br /&gt;
 !   debug bgp events zapina ladeni udalost, debug bgp updates ladeni aktualizaci&lt;br /&gt;
 !   a konecne debug bgp filters ladeni filtrovani. Toto nastaveni negeneruje prilis velike logy,&lt;br /&gt;
 !   ale na druhou stranu je dobre pouzitelne pro ladeni chyb.&lt;br /&gt;
 !&lt;br /&gt;
 debug bgp events&lt;br /&gt;
 debug bgp updates&lt;br /&gt;
 debug bgp filters&lt;br /&gt;
 !&lt;br /&gt;
 ! router bgp definuje BGP smerovaci proces asociovany ke konkretnimu ASN&lt;br /&gt;
 !   bgp router-id podobne jako ospf router-id definuje ID, pod kterym router vystupuje&lt;br /&gt;
 !                 pri BGP relacich.&lt;br /&gt;
 !   neighbor definuje souseda. Soused je BGP router, se kterym ma byt navazana BGP relace.&lt;br /&gt;
 !            Misto urceni konkretniho souseda se da vytvorit tzv. peer-group,&lt;br /&gt;
 !            podle ktere se nasledne daji sousedi sdruzovat.&lt;br /&gt;
 !            V tomto pripade jsou zde dve peer-groupy:&lt;br /&gt;
 !                EXTERNAL:  Do teto skupiny jsou sdruzeny vsechny sousedi, se kterymi tento&lt;br /&gt;
 !                           router peeruje, a nejsou soucasti jeho AS. Pro tuto peer-groupu&lt;br /&gt;
 !                           jsou definovane vstupni a vystupni filtery prefixu, ktere budou&lt;br /&gt;
 !                           popsany dale. Parametr next-hop-self zajisti, ze tento router&lt;br /&gt;
 !                           bude propagovat sam sebe radsi, nezli externiho peera,&lt;br /&gt;
 !                           jako dalsi skok.&lt;br /&gt;
 !&lt;br /&gt;
 !                INTERNAL:  Do teto peer-groupy budou patrit vsechny routery, ktere patri do&lt;br /&gt;
 !                           stejneho AS. Narozdil od peer-groupy EXTERNAL zde chybi filtery&lt;br /&gt;
 !                           (protoze je zde jednotna sprava), je zde definovan remote-as atribut,&lt;br /&gt;
 !                           protoze vzdalene ASN je vzdy stejne a konecne jako zdrojova adresa&lt;br /&gt;
 !                           pro peering je pouzita loopback adresa, jejiz odroutovani zajistuje IGP.&lt;br /&gt;
 !                           (parametr update-source)&lt;br /&gt;
 !&lt;br /&gt;
 !            Co se tyce konkretnich, v teto konfiguraci definovanych, sousedu:&lt;br /&gt;
 !                10.15.3.33:   Faust. Uplink AS do stare patere CZFree.NETu. Zde je nasledujici:&lt;br /&gt;
 !                                  * vzdalene ASN&lt;br /&gt;
 !                                  * prislusnost k peer-groupe EXTERNAL&lt;br /&gt;
 !                                  * komentar &lt;br /&gt;
 !                10.13.0.71:     mototechna-1. Internetova brana, kam vede VPN z Moravy a Ostravy.&lt;br /&gt;
 !                                  * prislusnost k peer-groupe INTERNAL&lt;br /&gt;
 !                                  * komentar &lt;br /&gt;
 !                10.13.0.7:     mototechna-2. Tranzitni router, ktery peeruje s ASN64521 (Repy)&lt;br /&gt;
 !                10.13.0.6:     networ. Access-point na Velke Ohrade, odkud vede linka do slivence (AS64516)&lt;br /&gt;
 !&lt;br /&gt;
 router bgp 64513&lt;br /&gt;
   bgp router-id 10.13.0.3&lt;br /&gt;
   network 10.13.0.0/16&lt;br /&gt;
   neighbor EXTERNAL peer-group&lt;br /&gt;
   neighbor EXTERNAL description Exterier BGP&lt;br /&gt;
   neighbor EXTERNAL next-hop-self&lt;br /&gt;
   neighbor EXTERNAL prefix-list cloudtransin in&lt;br /&gt;
   neighbor EXTERNAL prefix-list cloudtransout out&lt;br /&gt;
   neighbor INTERNAL peer-group&lt;br /&gt;
   neighbor INTERNAL remote-as 64513&lt;br /&gt;
   neighbor INTERNAL description Interier BGP&lt;br /&gt;
   neighbor INTERNAL update-source 10.13.0.3&lt;br /&gt;
   neighbor 10.15.3.33 remote-as 64515&lt;br /&gt;
   neighbor 10.15.3.33 peer-group EXTERNAL&lt;br /&gt;
   neighbor 10.15.3.33 description Faust - jbohac's cloud&lt;br /&gt;
   neighbor 10.13.0.7 peer-group INTERNAL&lt;br /&gt;
   neighbor 10.13.0.7 description mototechna-2&lt;br /&gt;
   neighbor 10.13.0.71 peer-group INTERNAL&lt;br /&gt;
   neighbor 10.13.0.71 description mototechna-1&lt;br /&gt;
   neighbor 10.13.0.6 peer-group INTERNAL&lt;br /&gt;
   neighbor 10.13.0.6 description networ&lt;br /&gt;
 !&lt;br /&gt;
 ! access-list definuje nastaveni pristupovych prav. &lt;br /&gt;
 !             Jde o seznam, ktery je cten podle poradi zapsanych pravidel,&lt;br /&gt;
 !             kde se podle IP adresy nastavi pristup. (viz. atributy deny a permit)&lt;br /&gt;
 !             V tomto pripade jde o pristupovy seznam pro pristup na konzoli bgpd.&lt;br /&gt;
 !&lt;br /&gt;
 access-list login remark Administrator access to zebra&lt;br /&gt;
 access-list login permit 127.0.0.0/8&lt;br /&gt;
 access-list login deny any&lt;br /&gt;
 !&lt;br /&gt;
 ! prefix-list je nejvykonnejsi mechanizmus na filtrovani prefixu.&lt;br /&gt;
 !             Narozdil od access-listu jeste oplyva funkci pro vyber rozsahu prefixu a moznost&lt;br /&gt;
 !             specifikace poradi, ve kterem budou jednotliva pravidla ctena. Atribut ge urcuje&lt;br /&gt;
 !             minimalni odpovidajici delku prefixu a atribut le minimalni.&lt;br /&gt;
 !             Dale atribut seq urcuje poradeove cislo pro cteni.&lt;br /&gt;
 !             Nyni popis dvou zde definovanych filtru :&lt;br /&gt;
 !                 cloudtransin:    Tento filtr je aplikovan na prichozi prefixy z ostatnich AS.&lt;br /&gt;
 !                                  Nejdrive (seq 10) povoli vsechny prefixy /15 az /20 prefixy&lt;br /&gt;
 !                                  z adresoveho rozsahu 10.0.0.0/8. Potom (seq 20) zakaze vse ostatni. &lt;br /&gt;
 !                 cloudtransout:   Analogicky, tento filtr filtruje odchozi prefixy pro ostatni AS.&lt;br /&gt;
 !                                  Opet se zde povoluje pouze z rozsahu 10.0.0.0/8 a to prefixy &lt;br /&gt;
 !                                  o standardni delce prefixu cloudu (/15) - /20, coz je delka&lt;br /&gt;
 !                                  prefixu z Moravy.&lt;br /&gt;
 !&lt;br /&gt;
 ip prefix-list cloudtransin description CZFree.NET inter-cloud filter IN&lt;br /&gt;
 ip prefix-list cloudtransin seq 10 permit 10.0.0.0/8 ge 15 le 10&lt;br /&gt;
 ip prefix-list cloudtransin seq 20 deny any&lt;br /&gt;
 ip prefix-list cloudtransout description CZFree.NET inter-cloud filter OUT&lt;br /&gt;
 ip prefix-list cloudtransout seq 10 permit 10.0.0.0/8 ge 15 le 20&lt;br /&gt;
 ip prefix-list cloudtransout seq 20 deny any&lt;br /&gt;
 !&lt;br /&gt;
 ! line vty popisuje konfiguraci terminalu.&lt;br /&gt;
 !   access-class nastavuje access-list, ktery ma byt pouzit pro vzdaleny pristup na terminal.&lt;br /&gt;
 !   exec-timeout nastavuje cas v minutach a vterinach, po kterem budete pri necinnosti odhlaseni z terminalu.&lt;br /&gt;
 !&lt;br /&gt;
 line vty&lt;br /&gt;
   access-class login&lt;br /&gt;
   exec-timeout 60 0&lt;br /&gt;
 !&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''priloha C: ospfd.conf'''&lt;br /&gt;
&lt;br /&gt;
 !&lt;br /&gt;
 ! hostname nastavuje jmeno systemu. &lt;br /&gt;
 ! password a enable password jsou hesla pro pristup do ospfd. enable password se od password&lt;br /&gt;
 !   lisi v tom, ze umoznuje primo konfigurovat ospfd pres terminal. Obe hesla jsou diky&lt;br /&gt;
 !   service password-encryption zasifrovana, takze muzete svuj config libovolne ukazovat&lt;br /&gt;
 !   a nemusite porad mazat ty dve radky. &lt;br /&gt;
 ! log file nastavuje soubor, do ktereho se budou zapisovat hlaseni ospfd.&lt;br /&gt;
 ! service advanced-vty nastavi rozsireni mod pro ovladani terminalu.&lt;br /&gt;
 !&lt;br /&gt;
 hostname kojott&lt;br /&gt;
 password 8 15eHtTCZsVk3Q&lt;br /&gt;
 enable password 8 3Z.lHJs5XguTU&lt;br /&gt;
 log file /var/log/zebra-ospfd.log&lt;br /&gt;
 service advanced-vty&lt;br /&gt;
 service password-encryption&lt;br /&gt;
 !&lt;br /&gt;
 !  interface definuje rozhrani, na kterych bude OSPF fungovat.&lt;br /&gt;
 !   description pridava komentar k danemu rozhrani. &lt;br /&gt;
 !&lt;br /&gt;
 interface lo&lt;br /&gt;
   description system loopback&lt;br /&gt;
 !&lt;br /&gt;
 interface eth0&lt;br /&gt;
   description lan&lt;br /&gt;
 !&lt;br /&gt;
 interface wlan0&lt;br /&gt;
   description bb-pajoslav-kojott&lt;br /&gt;
 !&lt;br /&gt;
 interface wlan1&lt;br /&gt;
   description bb-faust-kojott&lt;br /&gt;
 !&lt;br /&gt;
 interface wlan2&lt;br /&gt;
   description AP&lt;br /&gt;
 !&lt;br /&gt;
 interface dummy0&lt;br /&gt;
   description loopback interface&lt;br /&gt;
 !&lt;br /&gt;
 ! router ospf definuje OSPF smerovaci proces.&lt;br /&gt;
 !   ospf router-id podobne jako bgp router-id definuje ID, pod kterym router vystupuje&lt;br /&gt;
 !                  v ospf relacich.&lt;br /&gt;
 !   redistribute zajistuje distribuci urcitych (connected, bgp) smerovacich informaci.&lt;br /&gt;
 !                V pripade distribuce connected je zde jeste aplikovana route-mapa just-cloud,&lt;br /&gt;
 !                ktera zajistuje, aby se do OSPF nedostalo nic, co tam nema byt.&lt;br /&gt;
 !                metric-type 1 zajistuje, ze se bude k metrice pripojeneho rozhrani pricitat metrika trasy&lt;br /&gt;
 !                Takto musi byt nastaveno i sireni ostatnich rout (redistribute static metric-type 1 )&lt;br /&gt;
 !   network definuje podsite na zarizenich se zaplym OSPF a prisuzuje je konkretnim areas.&lt;br /&gt;
 !           Jestlize je v podsiti dalsi OSPF router, jedna se o area 0.&lt;br /&gt;
 !           V opacnem pripade je dane zarizeni oznaceno jako passive-interface&lt;br /&gt;
 !           a spada do area X, kde X je odvozene z loopback adresy (v tomto pripade 10.13.0.3).&lt;br /&gt;
 !   area nastavuje atributy oblasti. Zde definuje oblast 3 jako koncovou,&lt;br /&gt;
 !        a provadi jeji sumarizaci na rozsah 10.13.3.0/24.&lt;br /&gt;
 !        Dale je zde rozsah 10.13.67.0/24, ktery je delen na mensi podsite,&lt;br /&gt;
 !        ktere jsou smerovany ke klientum. (viz zebra.conf)&lt;br /&gt;
 !   neighbor deklaruje sousedy, se kterymi ma byt navazana OSPF relace.&lt;br /&gt;
 !            Zde je definovan jeden, 10.13.0.2 (pajoslav).&lt;br /&gt;
 !&lt;br /&gt;
 router ospf&lt;br /&gt;
   ospf router-id 10.13.0.3&lt;br /&gt;
   redistribute bgp metric-type 1&lt;br /&gt;
   network 10.13.0.3/32 area 0&lt;br /&gt;
   network 10.13.2.0/25 area 0&lt;br /&gt;
   network 10.13.3.0/25 area 3&lt;br /&gt;
   network 10.13.3.128/25 area 3&lt;br /&gt;
   network 10.13.67.0/24 area 3&lt;br /&gt;
   area 3 stub&lt;br /&gt;
   area 3 range 10.13.3.0/24&lt;br /&gt;
   neighbor 10.13.2.1&lt;br /&gt;
 !&lt;br /&gt;
 ! access-list definuje nastaveni pristupovych prav. &lt;br /&gt;
 !             Jde o seznam, ktery je cten podle poradi zapsanych pravidel,&lt;br /&gt;
 !             kde se podle IP adresy nastavi pristup. (viz. atributy deny a permit)&lt;br /&gt;
 !             V tomto pripade jde o pristupovy seznam s nazvem login, ktery je urcen&lt;br /&gt;
 !             pro specifikaci pristupu na konzoli ospfd.&lt;br /&gt;
 !&lt;br /&gt;
 access-list login remark Administrator access&lt;br /&gt;
 access-list login permit 127.0.0.1/32 &lt;br /&gt;
 access-list login deny any&lt;br /&gt;
 !&lt;br /&gt;
 ! line vty popisuje konfiguraci terminalu&lt;br /&gt;
 !   access-class nastavuje access-list, ktery ma byt pouzit pro vzdaleny pristup na terminal&lt;br /&gt;
 !   exec-timeout nastavuje cas v minutach a vterinach, po kterem budete pri necinnosti odhlaseni z terminalu&lt;br /&gt;
 !&lt;br /&gt;
 line vty&lt;br /&gt;
   access-class login&lt;br /&gt;
   exec-timeout 60 0&lt;br /&gt;
 !&lt;br /&gt;
&lt;br /&gt;
'''priloha D: zebra.conf'''&lt;br /&gt;
&lt;br /&gt;
 !&lt;br /&gt;
 ! hostname nastavuje jmeno systemu. &lt;br /&gt;
 ! password a enable password jsou hesla pro pristup do zebry. enable password se od password&lt;br /&gt;
 !   lisi v tom, ze umoznuje primo konfigurovat zebru pres terminal. Obe hesla jsou diky&lt;br /&gt;
 !   service password-encryption zasifrovana, takze muzete svuj config libovolne ukazovat&lt;br /&gt;
 !   a nemusite porad mazat ty dve radky. &lt;br /&gt;
 ! log file nastavuje soubor, do ktereho se budou zapisovat hlaseni zebry.&lt;br /&gt;
 ! service advanced-vty nastavi rozsireni mod pro ovladani terminalu.&lt;br /&gt;
 !&lt;br /&gt;
 hostname kojott&lt;br /&gt;
 password 8 mW/NIfgJNeq3M&lt;br /&gt;
 enable password 8 gVV7SXob3at2Q&lt;br /&gt;
 log file /var/log/zebra-zebra.log&lt;br /&gt;
 service advanced-vty&lt;br /&gt;
 service password-encryption&lt;br /&gt;
 !&lt;br /&gt;
 ! interface zahajuje konfiguraci sitoveho rozhrani.&lt;br /&gt;
 !   ip address prirazuje danemu rozhrani IPv4 adresu s konkretni maskou.&lt;br /&gt;
 !             Takto nakonfigurovana zebra ocekava od systemu pouze nahrani potrebnych modulu&lt;br /&gt;
 !             pro vytvoreni sitovych rozhrani a jejich pripadnou hardwarovou konfiguraci (L1 &amp;amp; L2).&lt;br /&gt;
 !             Veskera nasledna IP konfigurace jiz probiha pres zebru.&lt;br /&gt;
 !             Za povsimnuti stoji rozhodne loopback adresa routeru - 10.13.0.3/32.&lt;br /&gt;
 !&lt;br /&gt;
 interface lo&lt;br /&gt;
   ip address 127.0.0.1/8&lt;br /&gt;
 !&lt;br /&gt;
 interface wlan0&lt;br /&gt;
   ip address 10.13.2.3/25&lt;br /&gt;
 !&lt;br /&gt;
 interface wlan1&lt;br /&gt;
   ip address 10.15.3.45/27&lt;br /&gt;
 !&lt;br /&gt;
 interface wlan2&lt;br /&gt;
   ip address 10.13.3.1/25&lt;br /&gt;
 !&lt;br /&gt;
 interface eth0&lt;br /&gt;
   ip address 10.13.3.129/25&lt;br /&gt;
 !&lt;br /&gt;
 interface dummy0&lt;br /&gt;
   ip address 10.13.0.3/32&lt;br /&gt;
 !&lt;br /&gt;
 !  ip route definice staticke cesty, vedouci pres konkretni branu nebo rozhrani.&lt;br /&gt;
 !          Prvni cesta je vychozi a vede pres branu 10.13.2.1. Druhe dve cesty&lt;br /&gt;
 !          jsou pouzity pro smerovani mensich podsiti klientum. Podsit 10.13.67.0/26&lt;br /&gt;
 !          patri klientovi s IP 10.13.1.10. Dalsi cesta je takzvana blackhole,&lt;br /&gt;
 !          ktera je zde pouze kvuli nasledne 'manualni' sumarizaci,&lt;br /&gt;
 !          protoze obecne staticke definice cest se sumarizovat nedaji.&lt;br /&gt;
 !          A konecne posledni cesta je reject (unreachable), ktera ma za nasledek to,&lt;br /&gt;
 !          ze smerovane packety zahodi a zdroji posle ICMP Unreachable zpravu.&lt;br /&gt;
 !&lt;br /&gt;
 ip route 0.0.0.0/0 10.13.2.1&lt;br /&gt;
 !&lt;br /&gt;
 ip route 10.13.67.0/26 10.13.1.10&lt;br /&gt;
 ip route 10.13.67.0/24 Null0&lt;br /&gt;
 !&lt;br /&gt;
 ip route 10.0.0.0/8 reject&lt;br /&gt;
 !&lt;br /&gt;
 ! access-list definuje nastaveni pristupovych prav. &lt;br /&gt;
 !             Jde o seznam, ktery je cten podle poradi zapsanych pravidel,&lt;br /&gt;
 !             kde se podle IP adresy nastavi pristup. (viz. atributy deny a permit)&lt;br /&gt;
 !             V tomto pripade jde o pristupovy seznam pro pristup na konzoli zebra.&lt;br /&gt;
 !&lt;br /&gt;
 access-list login remark Administrator access&lt;br /&gt;
 access-list login permit 127.0.0.0/8&lt;br /&gt;
 access-list login deny any&lt;br /&gt;
 !&lt;br /&gt;
 ! line vty popisuje konfiguraci terminalu&lt;br /&gt;
 !   access-class nastavuje access-list, ktery ma byt pouzit pro vzdaleny pristup na terminal&lt;br /&gt;
 !   exec-timeout nastavuje cas v minutach a vterinach, po kterem budete pri necinnosti odhlaseni z terminalu&lt;br /&gt;
 !&lt;br /&gt;
 line vty&lt;br /&gt;
   access-class login&lt;br /&gt;
   exec-timeout 60 0&lt;br /&gt;
 !&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Zpět na [[CZF-RFC]]&lt;/div&gt;</summary>
		<author><name>Danny</name></author>	</entry>

	</feed>