如何排查接口自动防御功能阻断掉的终端
%Mar 26 08:01:24:797 2026 Core-S10512X-G-H3C DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=11; Auto port-defend started.SourceAttackInterface=Ten-GigabitEthernet2/11/0/35, AttackProtocol=IP_ROUTE
%Mar 26 08:00:59:652 2026 Core-S10512X-G-H3C DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=11; Auto port-defend stopped.SourceAttackInterface=Ten-GigabitEthernet2/11/0/35, AttackProtocol=IP_ROUTE
%Mar 26 08:00:26:547 2026 Core-S10512X-G-H3C DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=11; Auto port-defend started.SourceAttackInterface=Ten-GigabitEthernet2/11/0/35, AttackProtocol=IP_ROUTE
%Mar 26 07:58:45:455 2026 Core-S10512X-G-H3C DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=11; Auto port-defend stopped.SourceAttackInterface=Ten-GigabitEthernet2/11/0/35, AttackProtocol=IP_ROUTE
%Mar 26 07:58:22:203 2026 Core-S10512X-G-H3C IFNET/4/IF_BOARD_EGRESS_DROP_RECOVER: -Chassis=2-Slot=13; Packet loss recovers on chassis 2 slot 13.
%Mar 26 07:58:22:176 2026 Core-S10512X-G-H3C IFNET/4/IF_EGRESS_DROP_RECOVER: -Chassis=2-Slot=13; Packet loss recovers in queue 2 of GigabitEthernet2/13/0/16.
%Mar 26 07:58:18:448 2026 Core-S10512X-G-H3C DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=11; Auto port-defend started.SourceAttackInterface=Ten-GigabitEthernet2/11/0/35, AttackProtocol=IP_ROUTE
%Mar 26 07:57:20:600 2026 Core-S10512X-G-H3C IFNET/4/IF_BOARD_EGRESS_DROP: -Chassis=2-Slot=13; Packet loss occurs on chassis 2 slot 13.
%Mar 26 07:57:20:568 2026 Core-S10512X-G-H3C IFNET/4/IF_EGRESS_DROP: -Chassis=2-Slot=13; Packet loss occurs in queue 2 of GigabitEthernet2/13/0/16.
%Mar 26 07:56:16:193 2026 Core-S10512X-G-H3C DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=11; Auto port-defend stopped.SourceAttackInterface=Ten-GigabitEthernet2/11/0/35, AttackProtocol=IP_ROUTE
%Mar 26 07:55:45:788 2026 Core-S10512X-G-H3C DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=11; Auto port-defend started.SourceAttackInterface=Ten-GigabitEthernet2/11/0/35, AttackProtocol=IP_ROUTE
%Mar 26 07:51:13:883 2026 Core-S10512X-G-H3C ARP/6/DUPIFIP: -Chassis=1-Slot=13; Duplicate address 131.146.105.1 on interface Vlan-interface1005, sourced from 586a-d3a9-bfe7
<Core-S10512X-G-H3C>dis version
H3C Comware Software, Version 7.1.070, Release 7755P03
Copyright (c) 2004-2024 New H3C Technologies Co., Ltd. All rights reserved.
H3C S10512X-G uptime is 42 weeks, 0 days, 23 hours, 47 minutes
Last reboot reason : USER reboot
Boot image: flash:/S10500XG-CMW710-BOOT-R7755P03.bin
Boot image version: 7.1.070, Release 7755P03
Compiled Jan 08 2024 16:00:00
System image: flash:/S10500XG-CMW710-SYSTEM-R7755P03.bin
System image version: 7.1.070, Release 7755P03
Compiled Jan 08 2024 16:00:00
Feature image(s) list:
flash:/S10500XG-CMW710-FREERADIUS-R7755P03.bin, version: 7.1.070, Release 7755P03
Compiled Jan 08 2024 16:00:00
Patch image(s) list:
flash:/S10500XG-CMW710-SYSTEM-R7755P03HS10.bin, version: R7755P03HS10
Compiled Feb 07 2025 11:00:00
没有display port-defend 。。。这条命令
Ten-GigabitEthernet2/11/0/35 接口上的设备。Ten-GigabitEthernet2/11/0/35IP_ROUTEIP_ROUTE 攻击通常意味着该接口收到了大量发往设备本身(本交换机)的、需要CPU进行路由转发的IP报文,超过了设备设定的阈值,从而触发了CP保护(Control Plane Protection)机制。Ten-GigabitEthernet2/11/0/35 接口上的具体是哪台设备。1display mac-address interface Ten-GigabitEthernet2/11/0/35IP_ROUTE 攻击流量。常见原因包括:ip-route)被丢弃的报文数量,可以验证攻击是否持续。Ten-GigabitEthernet2/11/0/35 接口 shutdown,或者将该终端从网络中断开,以消除对核心交换机CPU的冲击。1 interface Ten-GigabitEthernet2/11/0/35
2 shutdownip-route 协议的防御阈值,但这需要非常谨慎。1cpu-defend policy <policy-name>
2 protocol ip-route car cir <new-value>%Mar 26 07:51:13:883 ... ARP/6/DUPIFIP: ... Duplicate address 131.146.105.1 on interface Vlan-interface1005, sourced from 586a-d3a9-bfe7131.146.105.1 同时被 Vlan-interface1005(通常是网关接口)和MAC地址为 586a-d3a9-bfe7 的终端使用。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
没有display port-defend 。。。这条命令