• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

某局点使用CR16018-F CGN单板做NAT444之后网吧用户看视频卡顿问题

  • 0关注
  • 0收藏 2181浏览
粉丝:27人 关注:0人

组网及说明

某运营商局点使用CR16018-F+CGN单板,设备做BRAS PPPoE Server,并采用CGN单板做NAT转换,组网图可以简化为:

终端-------网吧路由器------CR16018-F--------外网


问题描述

在使用过程中网吧用户反馈,当上网用户较多的时候,存在有普遍的打开网页慢,视频卡顿情况。

调研发现,个人用户报障极少,报障用户都集中于网吧用户。   

过程分析

要取一个网吧用户的IP地址,从BRAS上使用display ppp access-user ip-address  100.X.114.X  可以看到该用户已在线很久,在线信息并无异常,且从BRASping测试该用户地址无异常。

因该运营商局点对于PPPoE拨号用户做了端口限制,每个用户分配了2048NAT端口,所以怀疑可能是网吧用户大量用户并发访问时,导致分配的NAT端口数被耗尽。

在设备上查看用户NAT端口占用情况,发现给该终端分配的NAT端口号已经被耗尽,如下:

[H3C]display nat user-information local ipv4 100.X.114.X                                                                                                                                 

Slot 9:                                                                                                                            

Total Users found: 0                                                                                                                

                                                                                                                                   

Slot 10:                                                                                                                            

Total Users found: 0                                                                                                               

                                                                                                                                    

Slot 11:                                                                                                                           

Total Users found: 0                                                                                                                

                                                                                                                                   

Slot 12:                                                                                                                            

Total Users found: 0                                                                                                               

                                                                                                                                    

Slot 13:                                                                                                                           

User ID                                            : 0x2868ec62                                                                    

Local IP                                           : 100.X.114.X                                                                

VPN instacne                                       : ---(0)                                                                        

Address group                                      : 1                                                                              

NAT instance                                       : nat1                                                                          

Global IP                                          : 122.X.151.X                                                                 

Start port                                         : 62465                                                                         

Block size                                         : 2048                                                                           

Port total                                         : 2048                                                                          

Extend port alloc times                            : 0                                                                                                                                                     

Extend port alloc number                           : 0                                                                             

First/Second/Third/Fourth/Fifth extend port start  : 0/0/0/0/0                                                                     

Total/TCP/UDP/ICMP port limit                      : ---/---/---/---                                                                

TCP/UDP/ICMP port current                          : 2048/526/25                                                                   

                                                                                                                                    

Total Users found: 1                                                                                                               

                                                                                                                                    

Slot 14:                                                                                                                           

User ID                                            : 0x2868ec62                                                                     

Local IP                                           : 100.X.114.X                                                               

VPN instacne                                       : ---(0)                                                                         

Address group                                      : 1                                                                             

NAT instance                                       : nat1                                                                           

Global IP                                          : 122.X.151X                                                                

Start port                                         : 62465                                                                         

Block size                                         : 2048                                                                          

Port total                                         : 2048                                                                          

Extend port alloc times                            : 0                                                                             

Extend port alloc number                           : 0                                                                             

First/Second/Third/Fourth/Fifth extend port start  : 0/0/0/0/0                                                                     

Total/TCP/UDP/ICMP port limit                      : ---/---/---/---                                                               

TCP/UDP/ICMP port current                          : 2048/523/22                                                                   

                                                                                                                                   

Total Users found: 1    

从信息可见,给该用户分配的端口块大小为2048,当前已经占用完,这样前面连接不释放端口的话,后面的报文将无NAT端口可用,无法进行NAT转换,进而导致网页无法打开,点新视频卡顿。   

解决方法

在NAT地址池组中扩大端口段,增加弹性增量端口块,当2048个端口占完之后,可以弹性扩展2048个端口,使用命令:

NAT地址组中视图下

[H3C-address-group-1]port-block block-size 2048 extended-block-number 1

针对大并发需求的网吧用户,扩展弹性增量端口块端口也无法解决的,直接通过Radius服务器授权公网IP   

该案例对您是否有帮助:

您的评价:1

若您有关于案例的建议,请反馈:

0 个评论

该案例暂时没有网友评论

编辑评论

举报

×

侵犯我的权益 >
对根叔知了社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔知了社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作