%Dec 17 03:18:27:966 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:18:28:363 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:18:30:965 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:18:32:370 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:18:34:966 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:18:53:669 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:18:55:966 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:18:56:359 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:18:58:966 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:21:01:520 2025 XinHangLou DRVPLAT/4/SOFTCAR DROP:
PktType=ARP, SrcMAC=307b-acb5-bb8c, Dropped from interface=Ten-GigabitEthernet1/0/28 at Stage=63, StageCnt=143617, TotalCnt=2966792, MaxRateInterface=Ten-GigabitEthernet1/0/28.
%Dec 17 03:21:01:617 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:21:03:967 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:21:04:341 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:21:06:967 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:23:20:050 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Dec 17 03:23:22:968 2025 XinHangLou STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
TC报文震荡这个是STP引起来的,这个可能非正常的(arp超限速的记录)
%Dec 17 03:21:01:520 2025 XinHangLou DRVPLAT/4/SOFTCAR DROP:
PktType=ARP, SrcMAC=307b-acb5-bb8c, Dropped from interface=Ten-GigabitEthernet1/0/28 at Stage=63, StageCnt=143617, TotalCnt=2966792, MaxRateInterface=Ten-GigabitEthernet1/0/28.
针对arp超限速的问题,我们可以通过抓包或者debug arp packet interface +对应的端口(能不能加端口跟设备型号有关) 来找到大量arp报文的来源:
如果arp杂乱无序,那多半确实是大量arp上来了,可以看看是不是业务高峰期、或者下游TC抖动引起arp刷新等等,如果是正常上送突发太多,可以考虑优化交换机的arp限速值,或者分散业务部署,或者网关下沉;
如果arp源ip固定、或者源mac固定,那攻击的可能性就比较大,需要找到攻击源 。
最后,现场经过抓包确认某一个mac遍历arp,速率在3681pps,而接口G1/0/15配置是broadcast-suppression pps 800,超出限速了,这样就找到了其中的一个源头。继续确认发现这是一个无线终端(从认证平台上看是个手机),考虑到有一些APP是会在后台运行的时候发送arp遍历请求的,且从SW的日志看又不止这一个源mac的arp超限速,因此考虑(1)首先保证先把沿途交换机下行口的端口隔离做上,防止流量冲击到AP有线口;(2)如果用户有报障:偶发业务不通这种的问题,可以考虑升级版本并配置rrop ul-arp attack-suppression enable开启AP上行ARP攻击抑制功能。
这种情况会让交换机崩溃吗
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
崩溃不会的