现象:S7610可以ping同华为,可以ping通中兴,但是中兴和华为之间不能互通,我们设备做二层透传也不行。
S7610主要配置如下:
#
interface GigabitEthernet7/0/8
port link-mode bridge
description DongHuaRuanJian
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 3300 to 3301 3304
speed 1000
duplex full
qos apply policy AT inbound
qos apply policy AT outbound
#
port link-aggregation group 3配置:
#
port link-mode bridge
description DongHuaRuanJian
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 3300 to 3301 3304
speed 1000
duplex full
qos apply policy AT inbound
qos apply policy AT outbound
1.
如下:
S7610设备的ND表项:
<S7610>dis ipv6 neighbors all
Type: S-Static D-Dynamic O-Openflow R-Rule IS-Invalid static
IPv6 address MAC address VID Interface State T Aging
2408:8000:C06C:1::9:8 4c09-b4fc-9d70 3302 BAGG2 REACH D 176
FE80::4E09:B4FF:FEFC:9D70 4c09-b4fc-9d70 3302 BAGG2 REACH D 165
2408:8000:C06C:1::9:A c4b8-b46d-4da3 3302 GE7/0/45 REACH D 317
FE80::C6B8:B4FF:FE6D:4DA3 c4b8-b46d-4da3 3302 GE7/0/45 REACH D 698
华为设备的ND表项,有我们S7610的的ND,而没有中兴设备的ND:
<HUAWEI>dis ipv6 neighbors
-----------------------------------------------------------------------------
IPv6 Address : 2408:8000:C06C:1::9:9
Link-layer : 5098-b858-9a01 State : STALE
Interface : GE0/0/22 Age : 00h04m12s
VLAN : 3302 CEVLAN: -
VPN name : Is Router: TRUE
IPv6 Address : FE80::5298:B8FF:FE58:9A01
Link-layer : 5098-b858-9a01 State : STALE
Interface : GE0/0/22 Age : 00h16m56s
VLAN : 3302 CEVLAN: -
VPN name : Is Router: TRUE
-----------------------------------------------------------------------------
Total: 2 Dynamic: 2 Static: 0
2、在我司设备上做流统,当华为设备ping中兴设备时,发现我们收到了报文,并没有转出去。确定丢包丢在了我司设备上。
[S7610]dis qos policy interface
Interface: GigabitEthernet4/0/8
Direction: Outbound
Policy: AT
Classifier: AT
Operator: AND
Rule(s) :
If-match acl ipv6 3999
Behavior: AT
Accounting enable:
1 (Packets)
0 (pps)
Interface: GigabitEthernet7/0/9
Direction: Outbound
Policy: AT
Classifier: AT
Operator: AND
Rule(s) :
If-match acl ipv6 3999
Behavior: AT
Accounting enable:
95 (Packets)
0 (pps)
Interface: GigabitEthernet7/0/45
Direction: Inbound
Policy: AT
Classifier: AT
Operator: AND
Rule(s) :
If-match acl ipv6 3999
Behavior: AT
Accounting enable:
1679 (Packets)
0 (pps)
4、查看配置信息发现有关IGMP的配置:
问题原因为 7610上配置有igmp-snooping并使能了drop-unknow, 所以7610丢弃了该NS报文。
igmp-snooping
drop-unknown
global-enable
建议现场与客户交流是否有需要配置drop-unknow,如果有需求,建议在vlan下配置drop-unknow,不要在全局配置,保证透传vlan入未知组播不会drop。
(1) 删除全局的igmp-snooping恢复;
(2) 建议如果有配置drop-unknow需求,在全局下配置,而不要在端口下配置。
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作