• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

S6520-24ST-SI-GL needs long routing time after ospf is established

2020-10-12 Published
  • 0关注
  • 0收藏 975浏览
粉丝:0人 关注:0人

Network Topology

H3C LS6520-24ST-SI-GL=====Cisco Switch  

H3C Comware Software, Version 7.1.070, Release 6312

This equipment is connected to Cisco equipment, using vlan-int 800 for interconnection.
interface Vlan-interface800
ip address 10.37.131.2 255.255.255.252
ospf mtu-enable//Delete and prompt that mtu does not match

Message from other side:
05-Mar-2020 22:21:28 %OSPF-W-RXBAD: Packet RX on interface 10.37.131.1 from 10.37.131.2 type DB DSC-MTU mismatch
05-Mar-2020 22:22:58 %OSPF-W-RXBAD: Packet RX on interface 10.37.131.1 from 10.37.131.2 type DB DSC-MTU mismatch
    

Problem Description

It took more than an hour to establish an ospf neighbor,
The first debugg, you can see that it only takes 17 seconds for the device to establish a neighbor:
<h3c-bog53k3>%Jun 23 05:12:38:329 2020 h3c-bog53k3 OSPF/5/OSPF_NBR_CHG: OSPF 1 Neighbor 10.37.131.1(Vlan-interface800) changed from FULL to DOWN.
%Jun 23 05:12:55:626 2020 h3c-bog53k3 OSPF/5/OSPF_NBR_CHG: OSPF 1 Neighbor 10.37.131.1(Vlan-interface800) changed from LOADING to FULL.

Second debugg
It is still 17 seconds to see the neighbor establishment, but it takes a long time to learn the routing table in the domain. The complete process:
<h3c-bog53k3>reset ospf process
Before pressing ENTER you must choose'YES' or'NO'[Y/N]:y
<h3c-bog53k3>%Jun 24 23:04:56:446 2020 h3c-bog53k3 OSPF/5/OSPF_NBR_CHG: OSPF 1 Neighbor 10.37.131.1(Vlan-interface800) changed from FULL to DOWN.
%Jun 24 23:05:13:586 2020 h3c-bog53k3 OSPF/5/OSPF_NBR_CHG: OSPF 1 Neighbor 10.37.131.1(Vlan-interface800) changed from LOADING to FULL.
Since then, the following has been prompted, and the routing table has been 21:
*Jun 24 23:05:14:522 2020 h3c-bog53k3 OSPF/7/DEBUG: LSA age: 4 Options: External routing:OFF.

Destinations: 21 Routes: 21

Destination/Mask Proto Pre Cost NextHop Interface
0.0.0.0/32 Direct 0 0 127.0.0.1 InLoop0
10.35.11.64/26 Direct 0 0 10.35.11.65 Vlan2020
10.35.11.64/32 Direct 0 0 10.35.11.65 Vlan2020
10.35.11.65/32 Direct 0 0 127.0.0.1 InLoop0

The intra-domain routing does not appear until around 23:35:
<h3c-bog53k3>show ip routing-table

Destinations: 505 Routes: 505

Destination/Mask Proto Pre Cost NextHop Interface
0.0.0.0/0 O_INTER 10 17 10.37.131.1 Vlan800
0.0.0.0/32 Direct 0 0 127.0.0.1 InLoop0
10.32.0.40/29 O_INTRA 10 15 10.37.131.1 Vlan800
10.32.9.0/24 O_INTRA 10 44 10.37.131.1 Vlan800
10.32.13.128/25 O_INTRA 10 44 10.37.131.1 Vlan800
10.32.26.0/25 O_INTRA 10 29 10.37.131.1 Vlan800

LSA age: age Options: External routing: ON/OFF LSA header information:
• age: LSA age field
• ON/OFF: indicates that external routing is supported or not
  

Process Analysis

Positioning progress:
The router-id of our company's equipment is larger than that of Cisco. When the dd message is exchanged during the neighbor establishment process, our company is the master and the Cisco equipment is the slave.

After collecting debug information many times, the following phenomena are found:
In the early stage, the main and standby elections of our equipment and Cisco equipment are normal. Our company is the master and Cisco is the slave. Our company leads the dd exchange. When our company sends the last dd message, the more flag is set to 0, indicating that the current is the last A packet was subsequently received from a Cisco device's dd packet, and the more flag was also 0. Therefore, our device ended the dd interaction phase, and the neighbor status moved out from exchange and eventually rose to full.
After the Cisco device sends the packet with more marked as 0, it still sends dd packets uninterruptedly, and prints the log Retransmit DB DSC xxxxxx, indicating that dd is retransmitted. This behavior does not comply with the rfc regulations. According to the RFC, only the master can Actively initiate a dd message, and the slave can only respond.
After the Cisco device continuously retransmitted the dd message for more than 20 minutes, it switched to the full state and sent the remaining part of the lsa to our device.

After analysis, our equipment could not learn the route within a period of just resetting. This is because Cisco equipment did not send network lsa to our equipment. As a result, the topology of our equipment was incomplete and could not be calculated during spf-tree calculation. Unable to figure out the route.
After more than 20 minutes, the Cisco equipment synchronized the remaining lsa with our equipment, the topology tree of our equipment became complete, and the routing calculation was normal.

In terms of the environment, the router-id of our company’s equipment has been modified and changed to a router-id smaller than that of Cisco. At this time, the Cisco device is the master during dd interaction. At this time, the dd message interaction is normal, and Cisco sends to our equipment normally. lsa, the problem has been circumvented. After repeatedly resetting the ospf process of our equipment, we can learn the route quickly. After the router-id is changed back, the problem will surely appear.

Therefore, the problem is because Cisco did not negotiate the neighbor state machine according to the agreement, and the Cisco equipment failed to synchronize all the lsa with our equipment, which caused our equipment to be unable to calculate the spf tree and routing, and the subsequent Cisco equipment recovered and synchronized by itself lsa, our equipment is back to normal.
  

Solution

1. Modify the router-id of our equipment to be smaller than Cisco 

2. Upgrade the Cisco switch version to resolve

该案例对您是否有帮助:

您的评价:1

若您有关于案例的建议,请反馈:

作者在2020-10-12对此案例进行了修订
0 comments

No comments

Add Comments:

举报

×

侵犯我的权益 >
对根叔知了社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 pub.zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔知了社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作