设备触发严重警告,提示镜像目的口【Ten-GigabitEthernet1/3/0/47】:入方向流量速率【38538986】 bytes/sec超1000bytes/sec,这个怎么消除?,这个口是连深信服设备分析流量的。接口信息如下:
Ten-GigabitEthernet1/3/0/47
Current state: UP
Line protocol state: UP
IP packet frame type: Ethernet II, hardware address: 9c09-71cd-3a00
Description: shenxinfu-tanzhen
Bandwidth: 10000000 kbps
Loopback is not set
Media type is optical fiber, port hardware type is 10G_BASE_SR_SFP
10Gbps-speed mode, full-duplex mode
Link speed type is autonegotiation, link duplex type is autonegotiation
Flow-control is not enabled
Maximum frame length: 9216
Allow jumbo frames to pass
Broadcast max-ratio: 100%
Multicast max-ratio: 100%
Unicast max-ratio: 100%
Known-unicast max-ratio: 100%
PVID: 1
Port link-type: Access
Tagged VLANs: None
Untagged VLANs: 1
Port priority: 0
Last link flapping: 47 weeks 6 days 16 hours 0 minutes
Last clearing of counters: 20:58:46 Fri 07/19/2024
Current system time:2026-03-02 16:10:20 beijing+08:00:00
Last time when physical state changed to up:2025-04-01 00:09:43 beijing+08:00:00
Last time when physical state changed to down:2025-03-31 20:51:09 beijing+08:00:00
Peak input rate: 38578026 bytes/sec, at 2025-07-26 18:06:11
Peak output rate: 133974721 bytes/sec, at 2025-02-21 11:28:54
Last 300 seconds input: 602171 packets/sec 38538986 bytes/sec 4%
Last 300 seconds output: 77475 packets/sec 30809545 bytes/sec 3%
Input (total): 14976649143312 packets, 958505545172224 bytes
0 unicasts, 0 broadcasts, 0 multicasts, 14976649143313 pauses
Input (normal): 0 packets, - bytes
0 unicasts, 0 broadcasts, 0 multicasts, 14976649143313 pauses
Input: 0 input errors, 0 runts, 0 giants, 0 throttles
0 CRC, 0 frame, - overruns, 0 aborts
- ignored, - parity errors
Output (total): 1866119879887 packets, 909480135854490 bytes
1866030299006 unicasts, 758 broadcasts, 89580123 multicasts, 0 pauses
Output (normal): 1866119879887 packets, - bytes
1866030299006 unicasts, 758 broadcasts, 89580123 multicasts, 0 pauses
Output: 0 output errors, - underruns, - buffer failures
0 aborts, 0 deferred, 0 collisions, 0 late collisions
0 lost carrier, - no carrier
IPv4 traffic statistics:
Last 300 seconds input rate: 0 packets/sec, 0 bytes/sec
Last 300 seconds output rate: 0 packets/sec, 0 bytes/sec
Input: 0 packets, 0 bytes
Output: 0 packets, 0 bytes
IPv6 traffic statistics:
Last 300 seconds input rate: 0 packets/sec, 0 bytes/sec
Last 300 seconds output rate: 0 packets/sec, 0 bytes/sec
Input: 0 packets, 0 bytes
Output: 0 packets, 0 bytes
这个告警的原因是 镜像目的端口入方向的流量速率(约 38.5 MB/s ≈ 308 Mbps)超过了该端口配置的阈值(仅 1000 bytes/s ≈ 8 Kbps),触发了设备的限速告警。
从您提供的接口信息来看,该端口带宽为 10Gbps,当前入方向流量仅占 4%,流量本身并未超出端口物理能力,问题出在端口上配置的入方向限速阈值过低。
调整或取消该端口入方向的限速阈值配置即可。
登录设备命令行(或通过 Web 界面找到对应端口配置)。
进入该端口视图:
检查并修改入方向限速命令(具体命令取决于限速配置方式,常见为 QoS 或风暴控制):
如果是用 qos lr 限速,执行 undo qos lr inbound 取消入方向限速;
如果是用 storm-constrain 配置的广播/组播/未知单播限速,执行 undo storm-constrain 相关命令取消或调高阈值;
如果只配置了入方向承诺信息速率(CIR),执行 undo qos car inbound 取消。
重新观察告警:执行 undo 命令后,告警通常会在下一轮流量采样后自动清除。如果仍存在,可执行 reset counters interface Ten-GigabitEthernet1/3/0/47 清除接口统计信息。
镜像目的端口特性:镜像端口接收的是被监控端口的流量副本,流量速率取决于被监控端口的实际流量,可能远高于普通业务端口的入方向流量。因此镜像端口不建议配置入方向限速,否则极易触发告警甚至丢包。
当前流量正常:您提供的接口信息显示入方向 38.5 MB/s 对 10G 端口而言是正常负载,无需限速。
暂无评论
Ten-GigabitEthernet1/3/0/47(连接深信服流量分析设备)1000 bytes/sec38538986 bytes/sec(约 309 Mbps),远高于阈值Input全是镜像包,IPv4/IPv6 input为 0,符合镜像口特征),本身就会持续高流量。1000 bytes/sec(约 8 Kbps)是一个极低的阈值,对 10G 镜像口来说几乎必然触发告警。1000 bytes/sec提升到合理值(比如100000000 bytes/sec,即 800Mbps,接近 10G 带宽的 80%)。system-view
interface Ten-GigabitEthernet1/3/0/47
qos threshold input-rate 100000000 # 单位bytes/sec,根据需要调整
若网管平台单独配置了阈值,需要在网管平台同步修改。
system-view
undo alarm threshold interface Ten-GigabitEthernet1/3/0/47 input-rate
或在网管平台(如 iMC)中,针对该接口取消 “入方向流量速率过高” 的告警规则。
system-view
acl number 3000
rule permit ip source 192.168.1.0 0.0.0.255 # 只镜像需要分析的网段
mirroring-group 1 local
mirroring-group 1 mirroring-port Ten-GigabitEthernet1/3/0/1 acl 3000 inbound # 源口+ACL过滤
mirroring-group 1 monitor-port Ten-GigabitEthernet1/3/0/47 # 目的口不变
display mirroring-group all,确认Ten-GigabitEthernet1/3/0/47是monitor-port(镜像目的口)。Input全是镜像包,IPv4/IPv6 input为 0,说明没有非法流量,是正常镜像业务。
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论