默认路由走电信,明细路由走移动,电信线路有问题自动切换到移动线路,为了做到网络不断效果,结合NQA,TRACK,但实际一应用会3分钟有规律丢包
ACL 3001是服务器网段,3002是办公网络网段
#
nqa entry admin dianxin
type icmp-echo
destination ip 电信IP
frequency 1000
next-hop 电信网关
reaction 1 checked-element probe-fail threshold-type consecutive 8 action-type trigger-only
source interface GigabitEthernet0/1
#
nqa entry admin yidong
type icmp-echo
destination ip 移动IP
frequency 1000
next-hop 移动网关
reaction 1 checked-element probe-fail threshold-type consecutive 1 action-type trigger-only
source interface GigabitEthernet0/3
#
policy-based-route aaa permit node 3
if-match acl 3002
apply ip-precedence immediate
apply ip-address next-hop 移动网关 track 2
apply ip-address default next-hop 电信网关 track 1
policy-based-route aaa permit node 5
if-match acl 3001
apply ip-precedence flash
apply ip-address next-hop 电信网关 track 1
#
ip route-static 0.0.0.0 0.0.0.0 电信网关 track 1
ip route-static 0.0.0.0 0.0.0.0 移动网关 track 2 preference 70
ip route-static 1.51.64.0 255.255.192.0 移动网关 track 2
ip route-static 1.88.0.0 255.252.0.0 移动网关 track 2
#
track 1 nqa entry admin dianxin reaction 1
track 2 nqa entry admin yidong reaction 2
#
nqa schedule admin yidong start-time now lifetime forever
nqa schedule admin dianxin start-time now lifetime forever
#
电信外网口
interface GigabitEthernet0/1
port link-mode route
description this port is link to China Telecom's Fiber Converter
nat outbound 3003
ip address x.x.x.x 255.255.255.248
qos apply policy av inbound
ipsec policy center
qos car inbound acl 3008 cir 1000 cbs 62500 ebs 0 green pass red discard
arp send-gratuitous-arp interval 2000
#
内网口
interface GigabitEthernet0/2
port link-mode route
description this port is link to 7506E's g2/0/24
ip address 192.168.60.251 255.255.255.0
arp send-gratuitous-arp interval 2000
ip policy-based-route aaa
#
移动外网口
interface GigabitEthernet0/3
port link-mode route
description this port is link to China Mobile's Fiber Converter
nat outbound 3003
ip address x.x.x. 255.255.255.248
qos car inbound acl 3008 cir 1000 cbs 62500 ebs 0 green pass red discard
arp send-gratuitous-arp interval 2000
电信光纤接出口防火墙U200-M g0/1口,移动光纤接g0/3,内网接g0/2,三层核心7506E接到内网口上,接入交换机连到核心,办公电脑和服务器网段直连交换机
(0)
最佳答案
丢包的位置在哪里?丢包时设备上路由、ARP是否存在是否正确?
(0)
丢包在外网上,就是不同的机子同时PING外部网站,3分钟左右连续丢几个包,就掉线了。路由、ARP这些都没去改动过
丢包在外网上,就是不同的机子同时PING外部网站,3分钟左右连续丢几个包,就掉线了。路由、ARP这些都没去改动过
什么款型设备?建议打400电话处理吧,提供信息太少。
(0)
设备是H3C U200-M防火墙,还要提供什么信息?设备过保了,400售后不理
设备是H3C U200-M防火墙,还要提供什么信息?设备过保了,400售后不理
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明