目的端服务器------公网----- fw-------内网---pc源
pc ping 服务器 不通
debugging ip packet 发现回包被路由备动丢弃
prompt: FIB BLACKHOLE.
IPFW/7/IPFW_PACKET: -COntext=1;
Discarding, interface = Route-Aggregation1.1
version = 4, headlen = 20, tos = 0 pktlen = 84, pktid = 2203, offset = 0, ttl = 251, protocol = 1
checksum = 9440, s = 1.1.1.1, d = 2.2.2.2 channelID = 0, vpn-InstanceIn = 1, vpn-InstanceOut = 0.
VsysID = 1
prompt: FIB BLACKHOLE.
Payload: ICMP type = 0, code = 0, checksum = 0x680b.
源nat不通,源nat 不通,从公网口收到的回包被丢弃
外网口配置了vpn实例,nat outbound后没有加vpn实例
interface Route-Aggregation1.1
ip binding vpn-instance test
ip address 3.3.3.3
nat outbound address-group 1
interface Route-Aggregation1.1
nat outbound address-group 1 vpn-instance test
接口下修改如上配置后正常
出口有vpn实例,nat中也要配置vpn实例
否则 流量匹配不上会话就查路由命中黑洞 (地址池中的地址暴露出去产生指向null的路由)
[H3C]session statistics enable
<H3C>display session table ipv4 source-ip 发起端ip destination-ip 发起端访问的目的地址 verbose
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作