区分两种现象:①完全 ping 不通路由器管理 IP;②能 ping 通,但是 SNMP/SSH 访问失败。
<H3C> ping x.x.x.x //省调网管IP
<H3C> tracert x.x.x.x
很多现场错误:设备管理 IP 放在公网实例,省调网管在 VPN 实例,双向隔离。
<H3C> display ip vpn-instance
<H3C> display ip interface brief
接口必须绑定省调调度 VPN,管理 IP 在 VPN 内。
<H3C> display ip routing-table vpn-instance XXX
必须存在去往省调网管网段的有效路由;电力调度网常用 OSPF、BGP 带 MD5 认证,邻居起不来会缺失路由。 3. 核对运营商 / 调度侧 PE 配置:VPN 实例、路由发布是否把本站路由发布给省调主站。
业务报文(远动 104)可以过,访问路由器本机的管理报文被拦截,这是电力接入最常见问题。 普通转发流量和去往路由器 CPU 的本机报文是两套过滤逻辑。
调度网接入一般配置 ACL 做安全加固,ACL 不仅过滤业务,也过滤访问路由器本机报文。
<H3C> display acl all
<H3C> display current-configuration | include ip access-group
检查接入接口下 ip access-group xxx in,ACL 必须permit 省调网管 IP 访问路由器管理 IP;很多现场只放通远动装置业务网段,拒绝 SNMP、SSH 去往路由器本机。
⚠️注意:ACL 中
permit ip 业务网段只放通穿越转发流量;访问路由器 CPU 的管理流量同样需要 permit。
MSR V7 平台control‑plane下配置 ACL 过滤上 CPU 报文,如果配置了防攻击策略,会直接丢弃省调网管过来的 SNMP/SSH 报文,业务转发不受影响。
<H3C> display current‑configuration configuration control‑plane
检查是否有:
control‑plane
security acl xxx
引用的 ACL 必须允许省调网管 IP 访问本设备 SNMP (UDP161)、SSH (TCP22);否则直接丢弃到 CPU 的管理报文。
省调网管大多依靠 SNMP 监控路由器状态,即使 SSH 不通,SNMP 是核心。
<H3C> display snmp‑agent sys‑info version
display snmp‑agent community
display snmp‑agent usm‑user
典型错误:snmp‑agent community read public acl 2000,而 ACL2000 没有 permit 省调网管 IP,直接拒绝 SNMP 查询。
snmp‑agent vpn‑instance 调度VPN名称
<H3C> display current‑configuration | include vty
user‑interface vty 0 15
acl 2001 inbound
authentication‑mode scheme
protocol ssh
acl 2001 inbound:只允许 ACL 内的源 IP 登录,必须把省调网管 / 运维网段放进去。
ntp‑service enable
ntp‑service unicast‑server x.x.x.x vpn‑instance 调度VPN
Console 口收集以下输出:
display version
display ip vpn‑instance
display ip routing‑table vpn‑instance XXX
display acl all
display current‑configuration
display snmp‑agent sys‑info
display snmp‑agent community
display current‑configuration configuration control‑plane
display logbuffer
⚠️电力调度专网,修改 ACL、VPN、路由配置需要和省调 / 调度运维提前确认,避免影响远动业务通道。
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论