组网如下:
防火墙设备之前运行正常,突然出现走PPPoE的业务全部中断的问题,查看PPPoE的状态都是正常的,接口上也获取到IP地址了,但是所有访问外网的业务均不通,但是在防火墙上能ping通自己的下一跳网关172.16.1.81。
1.首先排查PPPoE配置是否正常
#
dialer-group 10 rule ip permit
#
interface Dialer10
ppp chap password cipher $c$3$rIVbz0KGyKwcysXObJ0=
ppp chap user 0458564
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user 0458564 password cipher $c$3$2jcC5Mue9gxJxdq
dialer bundle enable
dialer-group 10
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1024
connection-limit apply policy 10
nat outbound 3000
#
interface GigabitEthernet1/0/2
port link-mode route
description TO_LTong
combo enable copper
nat outbound 3000
pppoe-client dial-bundle-number 10
#
2.查看PPPoE的会话状态正常
Bundle ID Interface VA RemoteMAC LocalMAC State
10 14888 GE1/0/2 VA254 5860-5f82-e180 9428-2eb7-f8b0 SESSION
查看dialer口是否有分配地址
Dialer10
Current state: UP
Line protocol state: UP
Description: Dialer10 Interface
Bandwidth: 64 kbps
Maximum transmission unit: 1500
Hold timer: 10 seconds, retry times: 5
Internet address: 172.28.66.172/32 (PPP-negotiated)
Link layer protocol: PPP
LCP: initial
Physical: Dialer, baudrate: 64000 bps
Last clearing of counters: Never
Last 300 seconds input rate: 8807 bytes/sec, 70456 bits/sec, 192 packets/sec
Last 300 seconds output rate: 72680 bytes/sec, 581440 bits/sec, 1510 packets/sec
Input: 399791 packets, 362710004 bytes, 0 drops
Output: 479916 packets, 48184423 bytes, 0 drops
以上结果表明,PPPoE拨号成功
内网访问公网DNS服务器查看会话没有回包:
Initiator:
Source IP/port: 10.1.101.84/55605
Destination IP/port: 114.114.114.114/53
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: UDP(17)
Inbound interface: Vlan-interface4001
Source security zone: Trust
Responder:
Source IP/port: 114.114.114.114/53
Destination IP/port: 172.28.66.172/6080
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: UDP(17)
Inbound interface: Dialer10
Source security zone: Untrust
State: UDP_OPEN
Application: DNS
Start time: 2018-11-16 17:12:09 TTL: 26s
Initiator->Responder: 2 packets 136 bytes
Responder->Initiator: 0 packets 0 bytes
怀疑是外网运营商侧做了限制
取消PPPOE接口的NAT配置,删除缺省路由
Destination/Mask Proto Pre Cost NextHop Interface
0.0.0.0/0 Static 60 0 0.0.0.0 Dia10
undo nat outbound 3000
在设备上ping114.114.114.114可以通了,再在PPPOE接口加上NAT的配置就不通了
该结论说明,运营商侧做了基于每IP的连接数限制,需协调运营商进行处理
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作