防火墙分配地址的网段(10.18.126.0),操作系统是server 2012以上版本的,360测速异常;server2008以下版本的操作系统,正常。server2012以上版本的,在S7510E分配地址的网段(10.18.0.0),测试正常。想知道到底是防火墙配置问题,还是操作系统需要设置什么?
[GS_F1000_1]dis cur
#
sysname GS_F1000_1
#
firewall packet-filter enable
firewall packet-filter default permit
#
firewall statistic system enable
#
radius scheme system
server-type extended
#
domain system
#
local-user GS
password simple GS
service-type telnet
level 3
#
aspf-policy 1
detect tcp
detect udp
#
dhcp server ip-pool 20
network 10.18.34.0 mask 255.255.254.0
gateway-list 10.18.34.1
dns-list 202.99.192.68 202.99.192.66
#
dhcp server ip-pool 21
network 10.18.40.0 mask 255.255.255.0
gateway-list 10.18.40.1
dns-list 202.99.192.66
#
acl number 2001
rule 0 permit
#
acl number 3001
rule 0 permit ospf
rule 1 permit icmp
rule 2 permit tcp destination-port eq telnet
rule 10 deny ip
acl number 3010
rule 0 permit ip source 10.18.35.0 0.0.0.255 destination 10.18.34.0 0.0.0.255
rule 1 deny ip source 10.18.0.0 0.0.255.255 destination 10.18.34.0 0.0.0.255
rule 2 deny ip source 10.18.0.0 0.0.255.255 destination 10.18.36.0 0.0.0.255
rule 3 permit ip source 10.18.36.0 0.0.0.255 destination 10.18.36.0 0.0.0.255
rule 10 permit ip
#
interface Aux0
async mode flow
#
interface GigabitEthernet0/0
ip address 10.18.253.2 255.255.255.252
firewall packet-filter 3010 inbound
#
interface GigabitEthernet0/1
firewall aspf 1 inbound
#
interface GigabitEthernet0/1.20
ip address 10.18.34.1 255.255.254.0
vlan-type dot1q vid 20
#
interface GigabitEthernet0/1.21
description ceshi
ip address 10.18.40.1 255.255.255.0
vlan-type dot1q vid 21
#
interface GigabitEthernet0/1.22
ip address 10.18.36.1 255.255.255.0
vlan-type dot1q vid 22
#
interface GigabitEthernet0/1.100
description server
ip address 10.18.126.1 255.255.255.224
vlan-type dot1q vid 100
#
interface GigabitEthernet1/0
#
interface GigabitEthernet1/0.100
#
interface GigabitEthernet1/1
#
interface Encrypt2/0
#
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
add interface GigabitEthernet0/1
add interface GigabitEthernet0/1.20
add interface GigabitEthernet0/1.21
add interface GigabitEthernet0/1.22
add interface GigabitEthernet0/1.100
set priority 85
#
firewall zone untrust
add interface GigabitEthernet0/0
set priority 5
#
firewall zone DMZ
set priority 50
#
firewall interzone local trust
#
firewall interzone local untrust
#
firewall interzone local DMZ
#
firewall interzone trust untrust
#
firewall interzone trust DMZ
#
firewall interzone DMZ untrust
#
ospf 10
area 0.0.0.0
network 10.18.34.0 0.0.1.255
network 10.18.36.0 0.0.0.255
network 10.18.40.0 0.0.0.255
network 10.18.126.0 0.0.0.255
network 10.18.253.0 0.0.0.3
#
info-center loghost 10.18.126.2
#
dhcp server forbidden-ip 10.18.34.1
dhcp server forbidden-ip 10.18.34.7
dhcp server forbidden-ip 10.18.40.1
#
snmp-agent
snmp-agent local-engineid 800063A203000FE290048E
snmp-agent community write GS
snmp-agent sys-info version all
snmp-agent target-host trap address udp-domain 10.18.126.2 params securityname GS
#
ntp-service unicast-server 10.18.253.1
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
user privilege level 3
set authentication password simple GS
#
return
[GS_F1000_1]
(0)
问题描述的不太清楚,再说一下。测速异常的时间,可以ping通,网页也可以打开,但比较慢。还有,有用友的服务器,每次都能ping通,大多数时候能打开,但它的测试工具,测试失败,连不上服务器。
(0)
您好,请知:
调整下防火墙端口的TCP MSS看下,以下是参考命令:
int gi 1/0/1
tcp mss 1200
quit
另外可以配置QOS对流量打标记,让优先级高的流量优先转发。
检查防火墙的CPU、内存、端口利用率是否高。
(0)
改了tcp mss,还是不行。检查了防火墙CPU、内存、端口利用率不高。现在的网络下,server 2008的服务器网络正常,server 2012以上版本的不正常。同样的线路,也是这样。操作系统上有什么设置吗?
改了tcp mss,还是不行。检查了防火墙CPU、内存、端口利用率不高。现在的网络下,server 2008的服务器网络正常,server 2012以上版本的不正常。同样的线路,也是这样。操作系统上有什么设置吗?
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
麻烦说具体点,不会改。