当前业务运行正常,UPF服务器往外ping 也是正常的,但是如果从锐捷交换机快ping 服务器会出现丢包问题,怀疑是锐捷交换机快ping机制问题导致,为了进一步定位,在防火墙上通过流量统计,看看是否丢在设备上。
流统测试结果:
acl advanced 3990
description liutong
rule 0 permit icmp source x.x.x.2 0 destination x.x.x.40 0 counting
rule 5 permit icmp source x.x.x.40 0 destination x.x.x.2 0 counting
#
traffic classifier liutong operator and
if-match acl 3990
#
traffic behavior liutong
filter permit
#
qos policy liutong
classifier liutong behavior liutong
#
interface Route-Aggregation1.51
description uT:Global:internet_untrust
qos apply policy liutong inbound
qos apply policy liutong outbound
vlan-type dot1q vid 51
#
interface Route-Aggregation1.52
description dT:Global:internet_trust
qos apply policy liutong inbound
qos apply policy liutong outbound
vlan-type dot1q vid 52
远程查看现场锐捷交换机ping的方式,发现是每个包都会更改参数,因此在防火墙上每个包都会建立一条会话。并且现场流量跨框。
<SC-CD-4L&01-11A07&16U-FW-F5000M-01>dis session table ipv4 destination-ip x.x.x.40 p i v
Slot 1:
Initiator:
Source IP/port: x.x.x.2/36860
Destination IP/port: x.x.x.40/2048
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Route-Aggregation1.51
Source security zone: internet_Untrust
Responder:
Source IP/port: x.x.x.40/36860
Destination IP/port: x.x.x.2/0
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Route-Aggregation1.52
Source security zone: internet_trust
State: ICMP_REQUEST
Application: ICMP
Rule ID: 15
Rule name: icmp_any
Start time: 2021-08-30 12:51:53 TTL: 28s
Initiator->Responder: 1 packets 128 bytes
Responder->Initiator: 0 packets 0 bytes
Initiator:
Source IP/port: x.x.x.2/36710
Destination IP/port: x.x.x.40/2048
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Route-Aggregation1.51
Source security zone: internet_Untrust
Responder:
Source IP/port: x.x.x.40/36710
Destination IP/port: x.x.x.2/0
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Route-Aggregation1.52
Source security zone: internet_trust
State: ICMP_REQUEST
Application: ICMP
Rule ID: 15
Rule name: icmp_any
Start time: 2021-08-30 12:51:38 TTL: 12s
Initiator->Responder: 1 packets 128 bytes
Responder->Initiator: 0 packets 0 bytes
Initiator:
Source IP/port: x.x.x.2/36677
Destination IP/port: x.x.x.40/2048
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Route-Aggregation1.51
Source security zone: internet_Untrust
Responder:
Source IP/port: x.x.x.40/36677
Destination IP/port: x.x.x.2/0
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Route-Aggregation1.52
Source security zone: internet_trust
State: ICMP_REQUEST
Application: ICMP
Rule ID: 15
Rule name: icmp_any
Start time: 2021-08-30 12:51:35 TTL: 9s
Initiator->Responder: 1 packets 128 bytes
Responder->Initiator: 0 packets 0 bytes
在这种情况下,会出现热备会话慢于ICMP回包的情况,通过debugging和会话也能看出。如下操作记录是先debugging看到后,再看的会话,可以看到回报上送二框后被丢弃。而查看备份会话的状态是非激活的状态,收到的报文个数也为0。说明报文先上了CPU处理,备份会话滞后导致无法匹配会话正常转发。
*Aug 30 12:55:07:882 2021 SC-CD-4L&01-11A07&16U-FW-F5000M-01 ASPF/7/PACKET: -COntext=1-Slot=2; The first packet was dropped by ASPF for invalid status. Src-ZOne=internet_trust, Dst-ZOne=internet_Untrust;If-In=Route-Aggregation1.52(155), If-Out=Route-Aggregation1.51(153); Packet Info:Src-IP=x.x.x.40, Dst-IP=x.x.x.2, VPN-Instance=none, Src-Port=37973, Dst-Port=0. Protocol=ICMP(1).
Initiator:
Source IP/port: x.x.x.2/37973
Destination IP/port: x.x.x.40/2048
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Route-Aggregation1.51
Source security zone: internet_Untrust
Responder:
Source IP/port: x.x.x.40/37973
Destination IP/port: x.x.x.2/0
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Route-Aggregation1.52
Source security zone: internet_trust
State: INACTIVE
Application: ICMP
Rule ID: 15
Rule name: icmp_any
Start time: 2021-08-30 12:55:07 TTL: 284s
Initiator->Responder: 0 packets 0 bytes
Responder->Initiator: 0 packets 0 bytes
现场情况特殊,正常PCping是使用同一条流,同一条流只会建立一条会话,现场锐捷交换机快速ping的方式比较特殊导致。处理方式有两种。
1. 组网改为主备模式,减少流量跨框情况。
2. 开启会话宽松,并放通反向策略。//不建议这种方式,会导致无法进行会话状态检查,安全性下降
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作