外部电信接入0/3口能ping通vlan1000的管理ip,但是无法ping通vlan1000内部的主机,比如我在外部ping 172.5.4.254能通,但是却ping不通接在0/6口上的IP地址为172.5.4.100的主机
# version 7.1.064, Release 0605P05 # sysname H3C # telnet server enable # dialer-group 33 rule ip permit # ip load-sharing mode per-flow src-ip global # dhcp enable dhcp server always-broadcast # dns proxy enable # password-recovery enable # vlan 1 # vlan 1000 # dhcp server ip-pool lan1 gateway-list 172.5.4.254 network 172.5.4.0 mask 255.255.255.0 address range 172.5.4.1 172.5.4.250 dns-list 8.8.8.8 # controller Cellular0/0 description Single_Line1-OTHER serial-set 0 # interface Aux0 # interface Dialer0 # interface Dialer1 # interface Dialer2 # interface Dialer3 # interface Dialer4 # interface Dialer5 # interface Dialer6 # interface Dialer7 # interface Dialer8 # interface Dialer1023 # interface Serial0/0:0 ppp ipcp dns admit-any ppp ipcp dns request dialer circular enable dialer-group 33 dialer timer autodial 5 ip address ppp-negotiate nat outbound # interface NULL0 # interface Vlan-interface1 ip address 192.168.0.1 255.255.254.0 tcp mss 1280 # interface Vlan-interface1000 ip address 172.5.4.254 255.255.255.0 # interface GigabitEthernet0/0 port link-mode route # interface GigabitEthernet0/1 port link-mode route # interface GigabitEthernet0/2 port link-mode route ip address 172.5.99.1 255.255.255.0 # interface GigabitEthernet0/3 port link-mode route combo enable fiber duplex full speed 100 ip address 16.5.4.2 255.255.255.252 # interface GigabitEthernet0/4 port link-mode bridge port access vlan 1000 # interface GigabitEthernet0/5 port link-mode bridge port access vlan 1000 # interface GigabitEthernet0/6 port link-mode bridge port access vlan 1000 # interface GigabitEthernet0/7 port link-mode bridge # interface GigabitEthernet0/8 port link-mode bridge port access vlan 1000 # interface GigabitEthernet0/9 port link-mode bridge port access vlan 1000 # scheduler logfile size 16 # line class aux user-role network-operator # line class console user-role network-admin # line class tty user-role networ
(0)
最佳答案
(0)
补充一点,我从鑫源这边,是可以访问到服务器区内部电脑的,
# version 7.1.064, Release 0605P05 # sysname H3C # telnet server enable # dialer-group 33 rule ip permit # ip load-sharing mode per-flow src-ip global # dhcp enable dhcp server always-broadcast # dns proxy enable # password-recovery enable # vlan 1 # vlan 1000 # dhcp server ip-pool lan1 gateway-list 172.5.4.254 network 172.5.4.0 mask 255.255.255.0 address range 172.5.4.1 172.5.4.250 dns-list 8.8.8.8 # controller Cellular0/0 description Single_Line1-OTHER serial-set 0 # interface Aux0 # interface Dialer0 # interface Dialer1 # interface Dialer2 # interface Dialer3 # interface Dialer4 # interface Dialer5 # interface Dialer6 # interface Dialer7 # interface Dialer8 # interface Dialer1023 # interface Serial0/0:0 ppp ipcp dns admit-any ppp ipcp dns request dialer circular enable dialer-group 33 dialer timer autodial 5 ip address ppp-negotiate nat outbound # interface NULL0 # interface Vlan-interface1 ip address 192.168.0.1 255.255.254.0 tcp mss 1280 # interface Vlan-interface1000 ip address 172.5.4.254 255.255.255.0 # interface GigabitEthernet0/0 port link-mode route # interface GigabitEthernet0/1 port link-mode route # interface GigabitEthernet0/2 port link-mode route ip address 172.5.99.1 255.255.255.0 # interface GigabitEthernet0/3 port link-mode route combo enable fiber duplex full speed 100 ip address 16.5.4.2 255.255.255.252 # interface GigabitEthernet0/4 port link-mode bridge port access vlan 1000 # interface GigabitEthernet0/5 port link-mode bridge port access vlan 1000 # interface GigabitEthernet0/6 port link-mode bridge port access vlan 1000 # interface GigabitEthernet0/7 port link-mode bridge # interface GigabitEthernet0/8 port link-mode bridge port access vlan 1000 # interface GigabitEthernet0/9 port link-mode bridge port access vlan 1000 # scheduler logfile size 16 # line class aux user-role network-operator # line class console user-role network-admin # line class tty user-role networ
(0)
你这配置贴的格式乱了,看一下,你这里没有配置路由啊。另外,外网要ping 通内网,你需要做nat server,也没看到这个配置
配置一条默认路由 ip route-s 0.0.0.0 0 16.5.4.1
在配置一个nat ser
int g1/0/3
nat server global 16.5.4.2 inside 172.5.4.100
(0)
大佬有空给看看嘛,我下面发图了,在真实环境,我从服务器区里面的内部主机,可以ping通到鑫源的哪个VLAN1000的ip地址172.5.4.254,缺ping不通VLAN内部的主机172.5.4.100,
大佬有空给看看嘛,我下面发图了,在真实环境,我从服务器区里面的内部主机,可以ping通到鑫源的哪个VLAN1000的ip地址172.5.4.254,缺ping不通VLAN内部的主机172.5.4.100,
虽说你外网直接能访问内网有点奇怪,肯定是有什么东西没说清;但我就照你的逻辑来吧。
那么我的推测如下:
1.由于你的配置只截了一半,无法看到你的静态路由,但可以明显看到3口下并没有nat,所以所谓的外网ip是走路由进来的,而且对172.5.4.254路由可达。
2.既然数据能到达172.5.4.254,那就可以走直连路由发给172.5.4.100。
3.虽然无法确认全部配置,但6口下没有包过滤。已知配置中也未发现其他具有报文阻断能力的配置。如此,172.5.4.100大概率是能收到数据的。
4.那么先假设172.5.4.100收到了数据却没回包。
5.根据如上假设,推测问题为172.5.4.100上的网关错误(或路由错误),另一种可能性是该终端未关闭windows防火墙这类机制导致ping包直接被丢弃。
建议检查终端的网关和系统防火墙(或其它安全机制)。以上推测仅供参考。
复原配置(下次记得先放到word里再重新复制粘贴,不然格式容易乱掉):
#
version 7.1.064, Release 0605P05
#
sysname H3C
#
telnet server enable
#
dialer-group 33 rule ip permit
#
ip load-sharing mode per-flow src-ip global
#
dhcp enable
dhcp server always-broadcast
#
dns proxy enable
#
password-recovery enable
#
vlan 1
#
vlan 1000
#
dhcp server ip-pool lan1
gateway-list 172.5.4.254
network 172.5.4.0 mask 255.255.255.0
address range 172.5.4.1 172.5.4.250
dns-list 8.8.8.8
#
controller Cellular0/0
description Single_Line1-OTHER
serial-set 0
#
interface Aux0
#
interface Dialer0
#
interface Dialer1
#
interface Dialer2
#
interface Dialer3
#
interface Dialer4
#
interface Dialer5
#
interface Dialer6
#
interface Dialer7
#
interface Dialer8
#
interface Dialer1023
#
interface Serial0/0/0
ppp ipcp dns admit-any
ppp ipcp dns request
dialer circular enable
dialer-group 33
dialer timer autodial 5
ip address ppp-negotiate
nat outbound
#
interface NULL0
#
interface Vlan-interface1
ip address 192.168.0.1 255.255.254.0
tcp mss 1280
#
interface Vlan-interface1000
ip address 172.5.4.254 255.255.255.0
#
interface GigabitEthernet0/0
port link-mode route
#
interface GigabitEthernet0/1
port link-mode route
#
interface GigabitEthernet0/2
port link-mode route
ip address 172.5.99.1 255.255.255.0
#
interface GigabitEthernet0/3
port link-mode route
combo enable fiber
duplex full
speed 100
ip address 16.5.4.2 255.255.255.252
#
interface GigabitEthernet0/4
port link-mode bridge
port access vlan 1000
#
interface GigabitEthernet0/5
port link-mode bridge
port access vlan 1000
#
interface GigabitEthernet0/6
port link-mode bridge
port access vlan 1000
#
interface GigabitEthernet0/7
port link-mode bridge
#
interface GigabitEthernet0/8
port link-mode bridge
port access vlan 1000
#
interface GigabitEthernet0/9
port link-mode bridge
port access vlan 1000
#
scheduler logfile size 16
#
line class aux
user-role network-operator
#
line class console
user-role network-admin
#
line class tty
user-role networ。。。。。。
(0)
我用电脑把拓扑图发上来了,配置也编辑了下,大佬有空看看嘛,,内网ping 172.5.4.100是通的,就说明不是防火墙的问题,路由器没有加任何访问策略的,我也搞懵了
分段ping都是这个情况吗?就是服务器区的主机、服务器区的路由器、鑫源的路由器、同局域网其他主机,都是能ping通254但ping不通100?
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
补充一点,我从鑫源这边,是可以访问到服务器区内部电脑的,