• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

MER5200 两网段ping不通

  • 0关注
  • 1收藏,1047浏览
粉丝:0人 关注:0人

问题描述:

MER5200 两个网口个建立了一个vlan 分别时51与52地址分别时192.168.51.0和192.168.52.0网段,52网段给的ap用,现在51网段可以ping通52的手机电脑.但是用52ping不通51内的服务器,

配置和诊断信息都在下面,求大神相小白解答解答

组网及组网描述:

  1. #
  2. version 7.1.064, Release 0821P18
  3. #
  4. sysname MER5200
  5. #
  6. clock timezone Beijing add 08:00:00
  7. clock protocol ntp
  8. #
  9. telnet server enable
  10. telnet server acl 2176
  11. #
  12. security-zone intra-zone default permit
  13. #
  14. dialer-group 1 rule ip permit
  15. dialer-group 2 rule ip permit
  16. #
  17. ip unreachables enable
  18. ip ttl-expires enable
  19. #
  20. dhcp enable
  21. dhcp server always-broadcast
  22. dhcp server mini-ap ip-pool vlan-interface52
  23. #
  24. dns proxy enable
  25. #
  26. password-recovery enable
  27. #
  28. vlan 1
  29. #
  30. vlan 41
  31. #
  32. vlan 52
  33. #
  34. object-group ip address _web_manageTelnet_group_
  35. 0 network range 192.168.51.1 192.168.51.254
  36. #
  37. dhcp server ip-pool ge3
  38. gateway-list 192.168.100.1
  39. network 192.168.100.0 mask 255.255.255.0
  40. address range 192.168.100.1 192.168.100.254
  41. dns-list 192.168.100.1
  42. forbidden-ip-range 192.168.100.1 192.168.100.1
  43. #
  44. dhcp server ip-pool lan1
  45. gateway-list 192.168.51.1
  46. network 192.168.51.0 mask 255.255.255.0
  47. address range 192.168.51.2 192.168.51.199
  48. dns-list 192.168.51.1 223.5.5.5
  49. #
  50. dhcp server ip-pool vlan-interface41
  51. gateway-list 192.168.41.1
  52. network 192.168.41.0 mask 255.255.255.0
  53. address range 192.168.41.2 192.168.41.99
  54. dns-list 192.168.41.1 114.114.114.114
  55. forbidden-ip-range 192.168.41.1 192.168.41.1
  56. #
  57. dhcp server ip-pool vlan-interface52
  58. gateway-list 192.168.52.1
  59. network 192.168.52.0 mask 255.255.255.0
  60. address range 192.168.52.1 192.168.52.254
  61. dns-list 192.168.52.1 223.5.5.5
  62. forbidden-ip-range 192.168.52.1 192.168.52.1
  63. option 43 hex 8007000001c0a83401
  64. option 60 ascii H3C
  65. #
  66. ddns policy WAN0(GE0)
  67. url ***.***/dyndns/update?system=dyndns&hostname=<h>&myip=<a>
  68. username htsm1990
  69. password cipher $c$3$58xDNFdxAvWd9imUQGKfMbGAzoJWd9CKiJD9dg6YoQ==
  70. #
  71. controller Cellular0/0
  72. #
  73. interface Dialer0
  74. mtu 1492
  75. ppp chap password cipher $c$3$x3PvALA5FuuRQwWmT0K/w74HXZ1vGGlrJBe7 
  76. ppp chap user CD61741101 
  77. ppp ipcp dns admit-any 
  78. ppp ipcp dns request 
  79. ppp pap local-user CD61741101 password cipher $c$3$kgB8CsqMVReSnU5R2DVbg2kxioP0Gf3XPwsG 
  80. dialer bundle enable
  81. dialer-group 1
  82. dialer timer idle 0
  83. dialer timer autodial 5
  84. ip address ppp-negotiate
  85. tcp mss 1280
  86. ip last-hop hold
  87. nat outbound
  88. ddns apply policy WAN0(GE0) fqdn ***.***
  89. ipsec apply policy WAN0(GE0)
  90. ipsec no-nat-process enable 
  91. #
  92. interface Dialer1
  93. mtu 1492
  94. ppp chap password cipher $c$3$v8N1a9LPffVuhmZpakpmynsTPUhC3fPh7gEw 
  95. ppp chap user CD02885880539 
  96. ppp ipcp dns admit-any 
  97. ppp ipcp dns request 
  98. ppp pap local-user CD02885880539 password cipher $c$3$u4fAJ7d0btLow4pJj42+QLFF2/cDUPaYgM60 
  99. dialer bundle enable
  100. dialer-group 2
  101. dialer timer idle 0
  102. dialer timer autodial 5
  103. ip address ppp-negotiate
  104. tcp mss 1280
  105. ip last-hop hold
  106. nat outbound
  107. #
  108. interface Virtual-PPP0
  109. ppp chap password cipher $c$3$As19Tu5t7AK8h6+ifWVsYGIiHm8XHGt6PNIL 
  110. ppp chap user admin 
  111. ip address 10.10.10.10 255.255.255.254
  112. l2tp-auto-client l2tp-group 1
  113. nat outbound
  114. #
  115. interface NULL0
  116. #
  117. interface Vlan-interface1
  118. description LAN-interface
  119. ip address 192.168.51.1 255.255.255.0
  120. tcp mss 1280
  121. ip subscriber l2-connected enable
  122. ip subscriber initiator dhcp enable
  123. ip subscriber initiator unclassified-ip enable
  124. ip subscriber dhcp domain ipoeenabledomain
  125. ip subscriber unclassified-ip domain ipoeenabledomain
  126. #
  127. interface Vlan-interface41
  128. description LAN-interface
  129. ip address 192.168.41.1 255.255.255.0
  130. tcp mss 1280
  131. ip subscriber l2-connected enable
  132. ip subscriber initiator dhcp enable
  133. ip subscriber initiator unclassified-ip enable
  134. ip subscriber dhcp domain ipoeenabledomain
  135. ip subscriber unclassified-ip domain ipoeenabledomain
  136. #
  137. interface Vlan-interface52
  138. description LAN-interface
  139. ip address 192.168.52.1 255.255.255.0
  140. tcp mss 1280
  141. ip subscriber l2-connected enable
  142. ip subscriber initiator dhcp enable
  143. ip subscriber initiator unclassified-ip enable
  144. ip subscriber dhcp domain ipoeenabledomain
  145. ip subscriber unclassified-ip domain ipoeenabledomain
  146. #
  147. interface GigabitEthernet0/0
  148. port link-mode route
  149. description Double_Line1
  150. combo enable copper
  151. pppoe-client dial-bundle-number 0
  152. #
  153. interface GigabitEthernet0/1
  154. port link-mode route
  155. description Double_Line2
  156. pppoe-client dial-bundle-number 1
  157. #
  158. interface GigabitEthernet0/2
  159. port link-mode bridge
  160. port link-type trunk
  161. port trunk permit vlan 1
  162. #
  163. interface GigabitEthernet0/3
  164. port link-mode bridge
  165. port link-type trunk
  166. port trunk permit vlan 1
  167. #
  168. interface GigabitEthernet0/4
  169. port link-mode bridge
  170. port link-type trunk
  171. undo port trunk permit vlan 1
  172. port trunk permit vlan 52
  173. port trunk pvid vlan 52
  174. #
  175. interface GigabitEthernet0/5
  176. port link-mode bridge
  177. port link-type trunk
  178. undo port trunk permit vlan 1
  179. port trunk permit vlan 41
  180. port trunk pvid vlan 41
  181. #
  182. object-policy ip Any-Any
  183. rule 65533 inspect 8048_url_profile_global disable
  184. rule 65534 pass
  185. #
  186. security-zone name Local
  187. #
  188. security-zone name Trust
  189. #
  190. security-zone name DMZ
  191. #
  192. security-zone name Untrust
  193. #
  194. security-zone name Management
  195. #
  196. zone-pair security source Any destination Any
  197. object-policy apply ip Any-Any
  198. #
  199. zone-pair security source Local destination Trust
  200. packet-filter name SWXWSGL
  201. #
  202. zone-pair security source Local destination Untrust
  203. packet-filter name SWXWSGL
  204. #
  205. zone-pair security source Trust destination Local
  206. packet-filter name SWXWSGL
  207. #
  208. zone-pair security source Untrust destination Local
  209. packet-filter name SWXWSGL
  210. #
  211. scheduler logfile size 16
  212. #
  213. line class console
  214. user-role network-admin
  215. #
  216. line class tty
  217. user-role network-operator
  218. #
  219. line class vty
  220. user-role network-operator
  221. #
  222. line con 0
  223. user-role network-admin
  224. #
  225. line vty 0 63
  226. authentication-mode scheme
  227. user-role network-operator
  228. #
  229. ip route-static 0.0.0.0 0 Dialer0 track 1023
  230. ip route-static 0.0.0.0 0 Dialer1 preference 100
  231. ip route-static 192.168.3.0 24 Virtual-PPP0
  232. #
  233. info-center loghost 127.0.0.1 port 3301
  234. info-center source CFGLOG loghost level informational
  235. #
  236. arp static 192.168.52.202 c85a-cf2c-f28c 52 GigabitEthernet0/4
  237. #
  238. ntp-service enable
  239. ntp-service unicast-server ***.***
  240. ntp-service unicast-server ***.***
  241. ntp-service unicast-server ***.***
  242. ntp-service unicast-server ***.***
  243. ntp-service unicast-server ***.***
  244. ntp-service unicast-server ***.***
  245. ntp-service unicast-server ***.***
  246. #
  247. acl basic 2176
  248. rule 1 permit source object-group _web_manageTelnet_group_
  249. #
  250. acl advanced 3999
  251. rule 0 permit ip source 10.10.10.10 0 destination 192.168.3.1 0
  252. rule 5 permit ip source 192.168.3.1 0 destination 10.10.10.10 0
  253. rule 10 permit ip source 10.10.10.10 0 destination 192.168.51.2 0
  254. rule 15 permit ip source 192.168.51.2 0 destination 10.10.10.10 0
  255. #
  256. acl advanced name SWXWSGL
  257. rule 1 permit ip
  258. #
  259. acl mac 4998
  260. rule 0 permit source-mac f460-e2c2-6d32 ffff-ffff-ffff
  261. rule 0 comment HSL手机
  262. rule 5 permit source-mac a81e-8429-20f8 ffff-ffff-ffff
  263. rule 10 permit source-mac 6ce5-f7d5-23ad ffff-ffff-ffff
  264. rule 10 comment AP1
  265. rule 15 permit source-mac 6ce5-f7d3-64f5 ffff-ffff-ffff
  266. rule 15 comment AP2
  267. rule 20 permit source-mac 7862-5692-5049 ffff-ffff-ffff
  268. rule 20 comment 李黄进手机
  269. rule 25 deny
  270. #
  271. password-control enable 
  272. undo password-control aging enable 
  273. undo password-control history enable 
  274. password-control length 6
  275. password-control login-attempt 3 exceed lock-time 10
  276. password-control update-interval 0
  277. password-control login idle-time 0
  278. #
  279. domain ipoeenabledomain
  280. authorization-attribute idle-cut 5 1
  281. authentication ipoe none
  282. authorization ipoe none
  283. accounting ipoe none
  284. #
  285. domain system
  286. #
  287. domain default enable system
  288. #
  289. role name level-0
  290. description Predefined level-0 role
  291. #
  292. role name level-1
  293. description Predefined level-1 role
  294. #
  295. role name level-2
  296. description Predefined level-2 role
  297. #
  298. role name level-3
  299. description Predefined level-3 role
  300. #
  301. role name level-4
  302. description Predefined level-4 role
  303. #
  304. role name level-5
  305. description Predefined level-5 role
  306. #
  307. role name level-6
  308. description Predefined level-6 role
  309. #
  310. role name level-7
  311. description Predefined level-7 role
  312. #
  313. role name level-8
  314. description Predefined level-8 role
  315. #
  316. role name level-9
  317. description Predefined level-9 role
  318. #
  319. role name level-10
  320. description Predefined level-10 role
  321. #
  322. role name level-11
  323. description Predefined level-11 role
  324. #
  325. role name level-12
  326. description Predefined level-12 role
  327. #
  328. role name level-13
  329. description Predefined level-13 role
  330. #
  331. role name level-14
  332. description Predefined level-14 role
  333. #
  334. user-group system
  335. #
  336. local-user admin class manage
  337. service-type telnet http https
  338. authorization-attribute user-role network-admin
  339. #
  340. local-user kbj class network
  341. password cipher $c$3$jVomuLnzB7dzzH2ZcqSP5E1cksQaaaCcxQ==
  342. service-type ppp
  343. authorization-attribute user-role network-operator
  344. #
  345. session statistics enable
  346. #
  347. ipsec transform-set WAN0(GE0)@MER5200ZX
  348. esp encryption-algorithm 3des-cbc 
  349. esp authentication-algorithm sha1 
  350. pfs dh-group1
  351. #
  352. ipsec policy-template WAN0(GE0) 65535
  353. transform-set WAN0(GE0)@MER5200ZX 
  354. description WAN0(GE0)@MER5200ZX
  355. ike-profile WAN0(GE0)@MER5200ZX
  356. sa duration time-based 3600
  357. sa duration traffic-based 1843200
  358. reverse-route dynamic
  359. reverse-route preference 100
  360. #
  361. ipsec policy WAN0(GE0) 65535 isakmp template WAN0(GE0)
  362. #
  363. l2tp-group 1 mode lac
  364. lns-ip host-name ***.*** host-name ***.***
  365. undo tunnel authentication
  366. tunnel name H3C-LAC
  367. tunnel password cipher $c$3$E5TbYQeX9tQa5kj/KUVRimMk5odbjDD+ag==
  368. #
  369. l2tp enable
  370. #
  371. ike profile WAN0(GE0)@MER5200ZX
  372. keychain WAN0(GE0)@MER5200ZX
  373. dpd interval 60 on-demand
  374. exchange-mode aggressive
  375. local-identity fqdn zongbu
  376. match remote identity address 0.0.0.0 0.0.0.0
  377. match remote identity fqdn fenbu
  378. proposal 65535 
  379. #
  380. ike proposal 65535
  381. #
  382. ike keychain WAN0(GE0)@MER5200ZX
  383. pre-shared-key address 0.0.0.0 0.0.0.0 key cipher $c$3$T1d42ty/nm6aeseu7hBb0GjVhKMuY/qPJ+Ny
  384. #
  385. ip http enable
  386. ip https enable
  387. #
  388. url-filter category custom severity 65535
  389. #
  390. traffic-policy 
  391. rule 1 name web_AppTraffRank 
  392.   application app http 
  393. #
  394. dac log-collect service dpi traffic enable
  395. dac traffic-statistic application enable
  396. #
  397. dac storage service dpi traffic limit hold-time 1
  398. dac storage service traffic limit hold-time 1
  399. #
  400. cloud-management server domain oasis.h3c.com
  401. #
  402. return

2 个回答
已采纳
知了小白
粉丝: 关注:

1、先看服务器的防火墙关闭没有,在看服务器的网关是否填写,并能平通手机网段的网关

2、看你配置了acl ,安全策略,检查是否和这些有关系,先关闭后测试一下

3、无线服务模板里有没有开启用户隔离

暂无评论

粉丝:5人 关注:0人

服务器开了防火墙吧 把防火墙和杀毒软件都关了

暂无评论

编辑答案

你正在编辑答案

如果你要对问题或其他回答进行点评或询问,请使用评论功能。

分享扩散:

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作

举报

×

侵犯我的权益 >
对根叔社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 pub.zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明