LAM的實現主要是利用了主機路由(host routes)與ARP技術,如圖1中所示。This obviously is a technique that doesn't scale well (add an "E" and it becomes LAME?). Contrary to the rumor I'm starting right now, it was not invented by Cabletron. However, from what I've heard, SecureFast "Routing" is based on a somewhat similar idea: tracking IP hosts and doing PRoxy ARP.
interface ethernet0 ip address 192.16.100.1 255.255.255.0 ! router eigrp 100 network 192.16.100.0 redistribute mobile ! ! 注釋 啟動移動IP 支持 router mobile ! ! 定義一個虛擬網絡10.0.0.0 ip mobile network 10.0.0.0 255.0.0.0 ! ! 定義虛擬網絡上的主機及轉發地址訪問控制列表 ip mobile host 10.0.0.1 10.0.0.5 virtual-network 10.0.0.0 255.0.0.0 care-of-access 2 ! ip mobile host 192.16.100.51 192.16.100.55 interface Ethernet0 lifetime 3600 ! ! 虛擬網絡10.0.0.0上的安全性設置 ip mobile secure host 10.0.0.1 spi 100 key secret1 ... ip mobile secure host 10.0.0.5 spi 200 key secret5 ! ! Ethernet0 接口上的安全性設置 ip mobile secure host 192.16.100.51 spi a1 key sanfran1 ... ip mobile secure host 192.16.100.55 spi a1 key sanfran5 ! ! 定義訪問控制列表 access-list 2 deny 13.0.0.0 access-list 2 permit any router mobile命令用于啟動移動IP支持,ip mobile network 定義了一個虛擬網絡,而redistribute mobile命令則定義了虛擬網絡的重分布。虛擬網絡可以允許本地路由器支持一個總是處于外地子網的移動終端。路由重發布將使得通訊主機首先將目的為移動終端的數據包發往本地代理。
接下來,ip mobile host ... virtual network 命令指明了虛擬網絡上所包含的移動終端地址。在這里,我們利用care-of-access選項來通過訪問控制列表定義移動終端可以利用哪些地址。
外地代理配置
interface Ethernet0 ip address 192.16.150.17 255.255.255.252 ! interface Ethernet1 ip address 192.16.200.1 255.255.255.0 ip irdp ip irdp maxadvertinterval 10 ip irdp minadvertinterval 7 ip mobile foreign-service ip mobile registration-lifetime 3600 ! router mobile ! ip mobile foreign-agent care-of Ethernet0 同樣,router mobile 命令用于啟動移動IP支持,ip mobile foreign-agent care-of command 指定從哪個接口得到轉發地址,ip mobile foreign-service接口命令使得路由器對外宣布自己將作為一個外地代理工作,這是通過CISCO的IRDP (ICMP Router Discovery Protocol)協議完成的。
show ip mobile globals show ip mobile host [addr | interface int | network addr | group] show ip mobile interface [interface] show ip mobile secure {host | visitor | foreign-agent | home-agent} address show ip mobile binding show ip mobile traffic show ip mobile tunnel [interface] show ip mobile violation [address] show ip mobile visitor [pending] [address] show ip route mobile clear ip mobile traffic clear ip mobile binding ! (CAUTION: can break sessions) clear ip mobile secure ! (CAUTION: can break sessions) clear ip mobile visitor ! (CAUTION: can break sessions) debug ip mobile advertise debug ip mobile host 至此,我們介紹了移動IP的基本概念以及兩種實現手段。