目前第三方设备抓包排查,pingF1000这边gre接口IP 在gre口上抓包 没有回包
[SFZ_FengHuangShan_FW2]dis interface Tunnel 1
Tunnel1
Current state: UP
Line protocol state: UP
Description: to_fenzhongxin_sangforAF
Bandwidth: 64 kbps
Maximum transmission unit: 1476
Internet address: 221.73.0.58/30 (primary)
Tunnel source 21.73.10.58, destination 21.73.10.89
Tunnel keepalive enabled, Period(10 s), Retries(3)
Tunnel TTL 255
Tunnel protocol/transport GRE/IP
GRE key disabled
Checksumming of GRE packets disabled
Last clearing of counters: Never
Last 300 seconds input rate: 27 bytes/sec, 216 bits/sec, 0 packets/sec
Last 300 seconds output rate: 2 bytes/sec, 16 bits/sec, 0 packets/sec
Input: 6390 packets, 239812 bytes, 1 drops
Output: 936 packets, 22464 bytes, 32818 drops
[SFZ_FengHuangShan_FW2]dis ip rou
[SFZ_FengHuangShan_FW2]dis ip routing-table 221.73.0.57
Summary count : 2
Destination/Mask Proto Pre Cost NextHop Interface
0.0.0.0/0 Static 60 0 0.0.0.0 Tun1
221.73.0.56/30 Direct 0 0 221.73.0.58 Tun1
[SFZ_FengHuangShan_FW2]
[SFZ_FengHuangShan_FW2]ping -a 221.73.0.58 221.73.0.57
Ping 221.73.0.57 (221.73.0.57) from 221.73.0.58: 56 data bytes, press CTRL_C to break
Request time out
--- Ping statistics for 221.73.0.57 ---
2 packet(s) transmitted, 0 packet(s) received, 100.0% packet loss
[SFZ_FengHuangShan_FW2]ping -a 21.73.10.58 21.73.10.89
Ping 21.73.10.89 (21.73.10.89) from 21.73.10.58: 56 data bytes, press CTRL_C to break
56 bytes from 21.73.10.89: icmp_seq=0 ttl=64 time=3.618 ms
56 bytes from 21.73.10.89: icmp_seq=1 ttl=64 time=3.231 ms
56 bytes from 21.73.10.89: icmp_seq=2 ttl=64 time=3.408 ms
56 bytes from 21.73.10.89: icmp_seq=3 ttl=64 time=3.314 ms
56 bytes from 21.73.10.89: icmp_seq=4 ttl=64 time=3.364 ms
--- Ping statistics for 21.73.10.89 ---
5 packet(s) transmitted, 5 packet(s) received, 0.0% packet loss
round-trip min/avg/max/std-dev = 3.231/3.387/3.618/0.130 ms
[SFZ_FengHuangShan_FW2]
(0)
建议下配置和组网详情吧
先把源目的搞清楚,然后在检查下安全策略和设备debug交互进一步分析定位吧
目前信息判断不了啥,gre tunnel源目的都没有
咋分析,交互过程也没有
建议尽快拨打400热线或联系对接渠道H3C认证代理商方面由专业工程师协助下吧
(0)
IPSec vpn封装的GRE源目的IP 这部分已经正常 GRE原目的IP可以相互通,切GRE的状态也是正常的 就是GRE的接口IP ping不通
源目的IP 上面不是有嘛 下面还ping测试l 难道我理解错了
Tunnel source 21.73.10.58, destination 21.73.10.89
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
Tunnel source 21.73.10.58, destination 21.73.10.89