我们公司通过SMTP数字专线使用双路由备份使用的;两条路由关了一条线路都能正常发送文件,使用配置了双路由后,内部通讯软件和OA系统上传功能中,部分word文档的(.doc和.xls)无法发送上传,压缩包等能正常发送。请大神帮看一下什么原因,感谢!
两台路由配置如下:
undo
password-control aging enable
#
firewall enable
#
domain default enable system
#
router id 172.17.112.54
#
telnet server enable
#
dar p2p signature-file flash:/p2p_default.mtd
#
port-security enable
#
acl number 3002
rule 10 deny tcp destination-port eq 445
rule 20 deny udp destination-port eq 445
rule 25 permit ip
#
vlan 1
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
qos policy PolicyLimit
#
user-group system
group-attribute allow-guest
#
local-user JSHA-XYSHGC-DX
local-user admin
password cipher $c$3$4HsEjmLj1MnXNg3DGKkCrz+1urGu2DrXes7niQ==
authorization-attribute level 3
service-type ssh telnet
service-type web
password-control length 4
password-control composition type-number 1
#
cwmp
undo cwmp enable
#
controller E1 0/0
#
interface Aux0
async mode flow
link-protocol ppp
#
interface Cellular0/0
async mode protocol
link-protocol ppp
firewall packet-filter 4999 outbound
#
interface Ethernet0/0
port link-mode route
firewall packet-filter 4999 outbound
ip address 172.17.123.253 255.255.255.0
ip address 172.17.124.253 255.255.255.0 sub
ospf network-type broadcast
vrrp vrid 1 virtual-ip 172.17.123.254
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 4
vrrp vrid 1 track interface Ethernet0/1 reduced 50
vrrp vrid 2 virtual-ip 172.17.124.254
vrrp vrid 2 priority 120
vrrp vrid 2 preempt-mode timer delay 4
vrrp vrid 2 track interface Ethernet0/1 reduced 50
ip flow-ordering internal
#
interface Ethernet0/1
port link-mode route
firewall packet-filter 3002 inbound
firewall packet-filter 3002 outbound
firewall packet-filter 4999 outbound
ip address 172.17.112.54 255.255.255.252
ospf cost 1000
ip netstream inbound
ip netstream outbound
#
interface NULL0
#
interface Vlan-interface1
#
interface Ethernet0/2
port link-mode bridge
#
interface Ethernet0/3
port link-mode bridge
#
interface Ethernet0/4
port link-mode bridge
#
ospf 100
peer 172.17.112.53
area 0.0.2.5
network 172.17.112.52 0.0.0.3
network 172.17.123.0 0.0.0.255
network 172.17.124.0 0.0.0.255
nssa
#
snmp-agent
snmp-agent local-engineid 800063A20370F96D1A8D7E
snmp-agent community read suning1
snmp-agent sys-info version v2c
#
ssh server enable
ssh server authentication-timeout 30
ssh user admin service-type stelnet authentication-type password
#
load xml-configuration
#
load tr069-configuration
#
user-interface tty 12
user-interface aux 0
authentication-mode password
user-interface vty 0 4
authentication-mode scheme
user privilege level 3
idle-timeout 100 0
#
return
第二台配置
undo password-control aging enable
#
firewall enable
#
domain default enable system
#
router id 172.17.112.14
#
telnet server enable
#
dar p2p signature-file flash:/p2p_default.mtd
#
port-security enable
#
password-recovery enable
#
acl number 3002
rule 10 deny tcp destination-port eq 445
rule 20 deny udp destination-port eq 445
rule 25 permit ip
#
vlan 1
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
qos policy PolicyLimit
#
user-group system
group-attribute allow-guest
#
local-user JSHA-XYSHGC-DX
local-user admin
password cipher $c$3$4HsEjmLj1MnXNg3DGKkCrz+1urGu2DrXes7niQ==
authorization-attribute level 3
service-type ssh telnet
service-type web
password-control length 4
password-control composition type-number 1
#
cwmp
undo cwmp enable
#
controller E1 0/0
#
interface Aux0
async mode flow
link-protocol ppp
#
interface Cellular0/0
async mode protocol
link-protocol ppp
firewall packet-filter 4999 outbound
#
interface Ethernet0/0
port link-mode route
firewall packet-filter 4999 outbound
ip address 172.17.123.252 255.255.255.0
ip address 172.17.124.252 255.255.255.0 sub
ospf network-type broadcast
vrrp vrid 1 virtual-ip 172.17.123.254
vrrp vrid 1 priority 110
vrrp vrid 1 preempt-mode timer delay 4
vrrp vrid 1 track interface Ethernet0/1 reduced 50
vrrp vrid 2 virtual-ip 172.17.124.254
vrrp vrid 2 priority 110
vrrp vrid 2 preempt-mode timer delay 4
vrrp vrid 2 track interface Ethernet0/1 reduced 50
#
interface Ethernet0/1
port link-mode route
description TO HUAIAN-YD-10M
firewall packet-filter 3002 inbound
firewall packet-filter 3002 outbound
firewall packet-filter 4999 outbound
ip address 172.17.112.14 255.255.255.252
ospf cost 1000
#
interface NULL0
#
interface Vlan-interface1
#
interface Ethernet0/2
port link-mode bridge
#
interface Ethernet0/3
port link-mode bridge
#
interface Ethernet0/4
port link-mode bridge
#
ospf 100
peer 172.17.112.13
area 0.0.2.5
network 172.17.112.12 0.0.0.3
network 172.17.124.0 0.0.0.255
network 172.17.123.0 0.0.0.255
nssa
#
snmp-agent
snmp-agent local-engineid 800063A20370F96D1A8940
snmp-agent community read suning1
snmp-agent sys-info version v2c v3
undo snmp-agent trap enable voice dial
#
ssh server enable
ssh server authentication-timeout 30
ssh user admin service-type stelnet authentication-type password
#
load xml-configuration
#
load tr069-configuration
#
user-interface tty 12
user-interface aux 0
authentication-mode password
set authentication password cipher $c$3$hNlkAom0+Ek9MXMkLzy25wYBEe7H2XUGkTKMwg=
=
user-interface vty 0 4
authentication-mode scheme
user privilege level 3
set authentication password cipher $c$3$iXVXQzBmAnUv8edq+DJmW5OtLetnW+jXKR2hnQ=
=
idle-timeout 100 0
#
return
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论