学校以前的路由是配置在外网防火墙上的,现在外网防火墙性能下降,因此就把路由配置在了一台华为ar3200-s的路由器上。 路由器(10.10.10.254)配置完成接入到核心交换机s7506e(10.10.10.1)上后其他网络都正常,但就是无线AC的地址(10.10610.2)ping不通,将路由器的网线拔掉后无线AC可以正常ping通。联系了华为工程师检查了路由器说配置没有问题。 现在不知道是什么原因,接上路由器就不通,拔掉路由器就恢复正常了。
路由器地址:10.10.10.254/24,vlan1000;接到了核心23口,access模式。 无线AC:10.10.10.2/24,vlan1000;接到了核心22口,trunk模式。 核心交换机:10.10.10.1/24,vlan1000;
1,核心直接ping ac测试,看通不通(接路由器前后都ping一下看看)
华为的路由: ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/0/0 113.56.119.193 ip route-static 192.168.0.0 255.255.0.0 Vlanif1000 10.10.10.1 核心的路由: ip route-static 0.0.0.0 0 10.10.10.254 AC的路由: ip route-static 0.0.0.0 0 10.10.10.1 下面是路由器的配置,麻烦看看是否开启了ARP代理功能: <Huawei>sys Enter system view, return user view with Ctrl+Z. [Huawei]disp [Huawei]display cu [Huawei]display current-configuration [V200R005C20SPC200] # board add 0/4 4ES2G-S # drop illegal-mac alarm # ipv6 # dns resolve dns server 218.104.111.114 dns server 218.104.111.122 dns proxy enable # vlan batch 1000 # wlan ac-global carrier id other ac id 0 # dhcp enable # pki realm default enrollment self-signed # acl number 2001 rule 5 permit source 192.168.0.0 0.0.255.255 acl name GigabitEthernet0/0/1 2998 rule 5 permit acl name GigabitEthernet0/0/0 2999 rule 5 permit # aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password irreversible-cipher %@%@X\s.'-lz!>/Bw-:dp\z7$|>=jC0n)*cdG>0L]nL7%:y&|>@$%@%@ local-user admin privilege level 15 local-user admin service-type telnet terminal ssh http # firewall zone Local priority 64 # interface Vlanif1000 ip address 10.10.10.254 255.255.255.0 # interface GigabitEthernet0/0/0 tcp adjust-mss 1460 ip address 113.56.119.196 255.255.255.192 nat outbound 2999 # interface GigabitEthernet0/0/1 # interface GigabitEthernet0/0/2 ip address 192.168.200.1 255.255.255.0 # interface GigabitEthernet4/0/0 port hybrid pvid vlan 1000 undo port hybrid vlan 1 port hybrid untagged vlan 1000 # interface GigabitEthernet4/0/1 port hybrid pvid vlan 1000 undo port hybrid vlan 1 port hybrid untagged vlan 1000 # interface GigabitEthernet4/0/2 port hybrid pvid vlan 1000 undo port hybrid vlan 1 port hybrid untagged vlan 1000 # interface GigabitEthernet4/0/3 port hybrid pvid vlan 1000 undo port hybrid vlan 1 port hybrid untagged vlan 1000 # interface Cellular0/0/0 # interface Cellular0/0/1 # interface NULL0 # info-center timestamp log format-date # snmp-agent local-engineid 800007DB039C37F49387B7 # http server enable http secure-server enable # ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/0/0 113.56.119.193 ip route-static 192.168.0.0 255.255.0.0 Vlanif1000 10.10.10.1 # user-interface con 0 authentication-mode password set authentication password cipher %@%@<RvbGxAm^'T5b"W#Q%S4,.iKG/k:,Ak{4-N(5p>=<EM2.iN,%@%@ user-interface vty 0 4 # wlan ac # voice # diagnose # return
华为的路由: ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/0/0 113.56.119.193 ip route-static 192.168.0.0 255.255.0.0 Vlanif1000 10.10.10.1 核心的路由: ip route-static 0.0.0.0 0 10.10.10.254 AC的路由: ip route-static 0.0.0.0 0 10.10.10.1 下面是路由器的配置,麻烦看看是否开启了ARP代理功能: <Huawei>sys Enter system view, return user view with Ctrl+Z. [Huawei]disp [Huawei]display cu [Huawei]display current-configuration [V200R005C20SPC200] # board add 0/4 4ES2G-S # drop illegal-mac alarm # ipv6 # dns resolve dns server 218.104.111.114 dns server 218.104.111.122 dns proxy enable # vlan batch 1000 # wlan ac-global carrier id other ac id 0 # dhcp enable # pki realm default enrollment self-signed # acl number 2001 rule 5 permit source 192.168.0.0 0.0.255.255 acl name GigabitEthernet0/0/1 2998 rule 5 permit acl name GigabitEthernet0/0/0 2999 rule 5 permit # aaa authentication-scheme default authorization-scheme default accounting-scheme default domain default domain default_admin local-user admin password irreversible-cipher %@%@X\s.'-lz!>/Bw-:dp\z7$|>=jC0n)*cdG>0L]nL7%:y&|>@$%@%@ local-user admin privilege level 15 local-user admin service-type telnet terminal ssh http # firewall zone Local priority 64 # interface Vlanif1000 ip address 10.10.10.254 255.255.255.0 # interface GigabitEthernet0/0/0 tcp adjust-mss 1460 ip address 113.56.119.196 255.255.255.192 nat outbound 2999 # interface GigabitEthernet0/0/1 # interface GigabitEthernet0/0/2 ip address 192.168.200.1 255.255.255.0 # interface GigabitEthernet4/0/0 port hybrid pvid vlan 1000 undo port hybrid vlan 1 port hybrid untagged vlan 1000 # interface GigabitEthernet4/0/1 port hybrid pvid vlan 1000 undo port hybrid vlan 1 port hybrid untagged vlan 1000 # interface GigabitEthernet4/0/2 port hybrid pvid vlan 1000 undo port hybrid vlan 1 port hybrid untagged vlan 1000 # interface GigabitEthernet4/0/3 port hybrid pvid vlan 1000 undo port hybrid vlan 1 port hybrid untagged vlan 1000 # interface Cellular0/0/0 # interface Cellular0/0/1 # interface NULL0 # info-center timestamp log format-date # snmp-agent local-engineid 800007DB039C37F49387B7 # http server enable http secure-server enable # ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet0/0/0 113.56.119.193 ip route-static 192.168.0.0 255.255.0.0 Vlanif1000 10.10.10.1 # user-interface con 0 authentication-mode password set authentication password cipher %@%@<RvbGxAm^'T5b"W#Q%S4,.iKG/k:,Ak{4-N(5p>=<EM2.iN,%@%@ user-interface vty 0 4 # wlan ac # voice # diagnose # return
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明