拓扑图如下,
1.BRI5是PC端对应物理端口G1/2/0/5、G2/2/0/5(IRF)
2.准入采用PBR方式引流,连接核心交换机G2/1/0/39口
3.上行口G2/1/0/27
产品版本Version 5.20, Release 1210P03
故障现象:
从PC去访问防火墙外网地址出现不定时随机丢包现象
首先在相应的接口做流统测试
[S10508-NW-hx]dis qos po int g1/2/0/5
Interface: GigabitEthernet1/2/0/5
Direction: Inbound
Policy: 3998
Classifier: 3998
Operator: AND
Rule(s) : If-match acl 3998
Behavior: 3998
Accounting Enable:
0 (Packets)
Direction: Outbound
Policy: 3998
Classifier: 3998
Operator: AND
Rule(s) : If-match acl 3998
Behavior: 3998
Accounting Enable:
0 (Packets)
[S10508-NW-hx]dis qos po int g2/2/0/5
Interface: GigabitEthernet2/2/0/5
Direction: Inbound
Policy: 3998
Classifier: 3998
Operator: AND
Rule(s) : If-match acl 3998
Behavior: 3998
Accounting Enable:
100 (Packets)
Direction: Outbound
Policy: 3998
Classifier: 3998
Operator: AND
Rule(s) : If-match acl 3998
Behavior: 3998
Accounting Enable:
81 (Packets)
[S10508-NW-hx]dis qos po int g2/1/0/39
Interface: GigabitEthernet2/1/0/39
Direction: Inbound
Policy: 3998
Classifier: 3998
Operator: AND
Rule(s) : If-match acl 3998
Behavior: 3998
Accounting Enable:
100 (Packets)
Direction: Outbound
Policy: 3998
Classifier: 3998
Operator: AND
Rule(s) : If-match acl 3998
Behavior: 3998
Accounting Enable:
100 (Packets)
[S10508-NW-hx]dis qos po int g2/1/0/27
Interface: GigabitEthernet2/1/0/27
Direction: Inbound
Policy: 3998
Classifier: 3998
Operator: AND
Rule(s) : If-match acl 3998
Behavior: 3998
Accounting Enable:
81 (Packets)
Direction: Outbound
Policy: 3998
Classifier: 3998
Operator: AND
Rule(s) : If-match acl 3998
Behavior: 3998
Accounting Enable:
81 (Packets)
流统发现从g2/2/0/5进来了100个包,但是最后回包只有81个,和ping测试相符合。看到从g2/1/0/27口进出都是81个说明报文出去之后是正常返回的。从当前现象看报文是丢在了10508设备上了,由于报文进入交换机之后要经过一次准入设备再返回到交换机才能去访问外网。怀疑有可能是准入设备的特殊配置原因导致,但是修改交换机配置让流量不经过准入设备还是有丢包现象。
进一步查看设备丢包情况
[S10508-NW-hx-diagnose] bcm 19 0 show/c 19为slot1+18得来
IBCAST.cpu0 : 13,067,062 +835
PERQ_PKT(0).cpu0 : 3,402,812,244 +408,314 54/s
PERQ_PKT(3).cpu0 : 1,187,487,217 +81,718 49/s
PERQ_PKT(5).cpu0 : 100,614,000 +6,454 2/s
PERQ_PKT(6).cpu0 : 1,995,804,306 +350,156 3/s
PERQ_PKT(7).cpu0 : 279,642,653 +19,587 12/s
PERQ_PKT(12).cpu0 : 103,935,197 +7,515 9/s
PERQ_PKT(18).cpu0 : 35,364,905 +2,263 1/s
PERQ_PKT(24).cpu0 : 2,170,216 +216
PERQ_PKT(36).cpu0 : 438,449 +24
PERQ_PKT(42).cpu0 : 2,303,897,075 +142,841 84/s
PERQ_BYTE(0).cpu0 : 2,184,135,805 +151,898
PERQ_BYTE(3).cpu0 : 1,362,943,742,961 +89,257,353 53,596/s
PERQ_BYTE(5).cpu0 : 15,994,243,340 +1,085,088 166/s
PERQ_BYTE(6).cpu0 : 231,545,530,275 +28,285,606 400/s
PERQ_BYTE(7).cpu0 : 52,637,911,156 +3,623,756 2,256/s
PERQ_BYTE(12).cpu0: 7,067,634,156 +511,020 627/s
PERQ_BYTE(18).cpu0: 3,073,657,211 +197,248 78/s
[S10508-NW-hx]display interface GigabitEthernet 2/1/0/27 ------------------无错包
[S10508-NW-hx-diagnose]bcm 19 0 show/c/ge27 -----------------------------无丢包
[S10508-NW-hx]display ip routing-table 10.61.152.33 -------------------查看路由表正常
Routing Table : Public
Summary Count : 3
Destination/Mask Proto Pre Cost NextHop Interface
0.0.0.0/0 Static 60 0 172.16.1.9 GE1/1/0/45
10.0.0.0/8 Static 60 0 192.168.1.139 Vlan100
10.61.0.0/16 Static 60 0 192.168.1.5 Vlan100
[S10508-NW-hx-diagnose]bcm 20 0 l3/defip/show
Unit 0, Total Number of DEFIP entries: 16385
# VRF Net addr Next Hop Mac INTF MODID PORT PRIO CLASS HIT VLAN
0 0 172.16.100.255/32 00:00:00:00:00:00 100002 0 0 0 32 n
0 0 172.20.70.255/32 00:00:00:00:00:00 100002 0 0 0 32 n
0 0 172.16.1.3/32 00:00:00:00:00:00 100002 0 0 0 32 y
0 0 172.16.1.255/32 00:00:00:00:00:00 100002 0 0 0 32 n
0 0 172.16.2.255/32 00:00:00:00:00:00 100002 0 0 0 32 n
0 0 192.168.206.255/32 00:00:00:00:00:00 100002 0 0 0 32 n
0 0 172.16.1.5/32 00:00:00:00:00:00 100001 0 0 1 32 y
0 0 172.16.2.1/32 00:00:00:00:00:00 100001 0 0 1 32 n
0 0 192.168.219.255/32 00:00:00:00:00:00 100002 0 0 0 32 n
[S10508-NW-hx-diagnose]debug ipv4-drv show route 0 10.61.152.33 16 slo 19
**********************************************************
- IPv4 Route Information Slot 19
**********************************************************
UNIT: 0
- VRF: 0
- IP ADDR: 10.61.152.33
- MASK: 255.255.0.0
- EGRESS ID: 100284
- FLAGS: 0xc
- TUNNEL OPT: 0
- VC LABEL: 0
- HITBIT: Source Dest
- PRI: 0
- CLASS ID: 32
- HWINDEX: 7203
- EGRESS NUM: 0
- EGRESS FLAGS: 0x0
- INTF NUM: 10
- MAC ADDR: f474-885d-8c70
- VLAN: 100
- DMOD: 35
- DPORT: 8
[S10508-NW-hx-diagnose]display ip routing-table 10.58.10.3 后来通过在丢包的瞬间查看到路由表出现变化
Routing Table : Public
Summary Count : 3
Destination/Mask Proto Pre Cost NextHop Interface
0.0.0.0/0 Static 60 0 172.16.1.9 GE1/1/0/45
10.0.0.0/8 Static 60 0 192.168.1.139 Vlan100
10.58.0.0/16 Static 1 0 192.168.1.5 Vlan100
[S10508-NW-hx-diagnose]
[S10508-NW-hx-diagnose]display ip routing-table 10.58.10.3
Routing Table : Public
Summary Count : 4
Destination/Mask Proto Pre Cost NextHop Interface
0.0.0.0/0 Static 60 0 172.16.1.9 GE1/1/0/45
10.0.0.0/8 Static 60 0 192.168.1.139 Vlan100
10.58.0.0/16 Static 1 0 192.168.1.5 Vlan100
10.58.10.0/24 O_ASE 150 20 172.20.70.6 GE1/1/0/34 出现了这个掩码24位的路由
- TRUNK: 0
- FRR LABEL: 0
--
**********************************************************
从这个接口出去的是一个市教育局公共网络,IP地址规划之前不是很清晰,并且无法断开与他们的OSPF邻居关系。根据最长掩码匹配原则会优先匹配这个路由
有这个24位掩码的话肯定会最长匹配上24位掩码的,其他设备给发布过来这个路由我们就有这个路由,其他设备撤销了我们设备上就没有了,最终是写32位明细路由方式解决。
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作