7503E 端口9横向接1个7503,端口10,11,12下接3个5120,通过27号端口 上面接一个出口网关。现在想把网关换成H3C 8300G2.
同样的ip换上发现无法通信(pc ping 路由)。
于是做了如下测试,发现7503上的VLAN间无法互通:
新建vlan 800,指定ip 192.168.8.3 /24. 端口21. 连接pc。
新建vlan 2,指定ip 200.1.1.3/24, 端口22,连接新路由(路由ip设为:200.1.1.1/24)。
在7503上ping pc和路由,ok。
在pc上ping 7503,ok。
在pc上ping 新路由,不通。
在pc上ping其他网段,不通。
将pc接到5503下面的5120,ping 新路由,不通。ping其他网段,ok。
将22端口设为trunk口,允许所有vlan,问题依旧。
路由表已经自动产生。
没发现7503上有任何acl策略。
7503配置见附件。
(0)
最佳答案
pc终端ping路由不通,能否再交换机的两个接口上做下入和出的流统,判断下报文是否是丢在了S75E上了。
(0)
reset counters 后从21口ping 22口: <S7503E_S_2>dis int g 0/0/22 GigabitEthernet0/0/22 current state: UP IP Packet Frame Type: PKTFMT_ETHNT_2, Hardware Address: c4ca-d9dd-ca70 Description: GigabitEthernet0/0/22 Interface Loopback is not set Media type is twisted pair Port hardware type is 1000_BASE_T 100Mbps-speed mode, full-duplex mode Link speed type is autonegotiation, link duplex type is autonegotiation Flow-control is not enabled The Maximum Frame Length is 9216 Broadcast MAX-ratio: 100% Unicast MAX-ratio: 100% Multicast MAX-ratio: 100% Allow jumbo frame to pass PVID: 2 Mdi type: auto Link delay is 0(sec) Port link-type: access Tagged VLAN ID : none Untagged VLAN ID : 2 Port priority: 0 Peak value of input: 0 bytes/sec, at 2019-01-18 15:36:16 Peak value of output: 54 bytes/sec, at 2019-01-18 15:38:06 Last 300 seconds input: 0 packets/sec 0 bytes/sec 0% Last 300 seconds output: 0 packets/sec 54 bytes/sec 0% Input (total): 3 packets, 192 bytes 3 unicasts, 0 broadcasts, 0 multicasts, 0 pauses Input (normal): 3 packets, - bytes 3 unicasts, 0 broadcasts, 0 multicasts, 0 pauses Input: 0 input errors, 0 runts, 0 giants, 0 throttles 0 CRC, 0 frame, - overruns, 0 aborts - ignored, - parity errors Output (total): 151 packets, 16564 bytes 93 unicasts, 0 broadcasts, 58 multicasts, 0 pauses Output (normal): 151 packets, - bytes 93 unicasts, 0 broadcasts, 58 multicasts, 0 pauses Output: 0 output errors, - underruns, - buffer failures 0 aborts, 0 deferred, 0 collisions, 0 late collisions 0 lost carrier, - no carrier <S7503E_S_2>dis int g 0/0/21 GigabitEthernet0/0/21 current state: UP IP Packet Frame Type: PKTFMT_ETHNT_2, Hardware Address: c4ca-d9dd-ca70 Description: GigabitEthernet0/0/21 Interface Loopback is not set Media type is twisted pair Port hardware type is 1000_BASE_T 1000Mbps-speed mode, full-duplex mode Link speed type is autonegotiation, link duplex type is autonegotiation Flow-control is not enabled The Maximum Frame Length is 9216 Broadcast MAX-ratio: 100% Unicast MAX-ratio: 100% Multicast MAX-ratio: 100% Allow jumbo frame to pass PVID: 800 Mdi type: auto Link delay is 0(sec) Port link-type: access Tagged VLAN ID : none Untagged VLAN ID : 800 Port priority: 0 Peak value of input: 172 bytes/sec, at 2019-01-18 15:38:26 Peak value of output: 119 bytes/sec, at 2019-01-18 15:38:26 Last 300 seconds input: 2 packets/sec 172 bytes/sec 0% Last 300 seconds output: 1 packets/sec 119 bytes/sec 0% Input (total): 710 packets, 53135 bytes 710 unicasts, 0 broadcasts, 0 multicasts, 0 pauses Input (normal): 710 packets, - bytes 710 unicasts, 0 broadcasts, 0 multicasts, 0 pauses Input: 0 input errors, 0 runts, 0 giants, 0 throttles 0 CRC, 0 frame, - overruns, 0 aborts - ignored, - parity errors Output (total): 413 packets, 36631 bytes 263 unicasts, 0 broadcasts, 150 multicasts, 0 pauses Output (normal): 413 packets, - bytes 263 unicasts, 0 broadcasts, 150 multicasts, 0 pauses Output: 0 output errors, - underruns, - buffer failures 0 aborts, 0 deferred, 0 collisions, 0 late collisions 0 lost carrier, - no carrier <S7503E_S_2>
ping数据包应该没有到达21口。
说错了,应该是 ping数据包应该没有从21口到达22口。数据的确丢在了s7503上面。
可以参考官网上的流量统计案例在交换机接口做下流量统计只匹配一条流来观察一下。:http://www.h3c.com/cn/d_201811/1123120_30005_0.htm#_Toc528265127
刚刚的统计应该和这个策略统计类似,因为21端口只用这一个pc,直接连接,22端口只用那一个路由,并且路由没有接其他设备。这个策略统计的意思就是过滤掉其他源ip的数据包吧?
好的,那我试下
Interface: GigabitEthernet0/0/21 Direction: Inbound Policy: p_1 Classifier: cl_1 Operator: AND Rule(s) : If-match acl 2000 Behavior: tj_1 Accounting Enable: 1235 (Packets) ----------------------- Interface: GigabitEthernet0/0/22 Direction: Inbound Policy: p_1 Classifier: cl_1 Operator: AND Rule(s) : If-match acl 2000 Behavior: tj_1 Accounting Enable: 0 (Packets) --------------------- 数据的确丢在了S7503上。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
有没有什么办法啊