摄像头192.168.1.4------0/1分支设备0/0----运营商-------0/9总部设备0/2------总部服务器11.11.11.11
无
总部从分支拉视频
总部同时从同一个分支拉两个摄像头的流量就卡
视频卡顿,怀疑是丢包导致
如何确认丢包位置
1. ipsec流量统计

2 出口镜像,看identification

3,隧道两边查看看ipsec隧道统计
<Sysname> display ipsec tunnel brief
----------------------------------------------------------------------------
Tunn-id Src Address Dst Address Inbound SPI Outbound SPI Status
----------------------------------------------------------------------------
0 192.168.0.61 192.168.0.64 54321 12345 --
# 显示ID为1的IPsec隧道处理的报文统计信息。
<Sysname> display ipsec statistics tunnel-id 0
IPsec packet statistics:
Received/sent packets: 5124/8231
Received/sent bytes: 52348/643561
Dropped packets (received/sent): 0/0
Dropped packets statistics
No available SA: 0
Wrong SA: 0
Invalid length: 0
Authentication failure: 0
Encapsulation failure: 0
Decapsulation failure: 0
Replayed packets: 0
ACL check failure: 0
MTU check failure: 0
Loopback limit exceeded: 0
清除IPsec的所有报文统计信息。
<Sysname> reset ipsec statistics
发现丢在运营商,排查运营商
debugging ipsec all 中可以看到,类似如下回显
outbound IPsec processing: src Ip = 192.168.1.5, dst IP = 10.2.2.254, SPI = 2013677202
(0)
<FW>display acl 3104
Advanced IPv4 ACL 3104, 3 rules,
ACL's step is 5
rule 0 permit ip source 192.168.12.0 0.0.0.255 destination 192.168.6.0 0.0.0.255 (96654 times matched)
rule 5 permit ip source 192.168.12.0 0.0.0.255 destination 192.168.216.0 0.0.0.255 (192 times matched)
rule 10 permit ip source 192.168.12.0 0.0.0.255 destination 192.168.217.0 0.0.0.255
<FW>display ipsec sa
-------------------------------
Interface: GigabitEthernet1/0/10
-------------------------------
-----------------------------
IPsec policy: map1
Sequence number: 10
Mode: ISAKMP
-----------------------------
Tunnel id: 2
Encapsulation mode: tunnel
Perfect Forward Secrecy:
Inside VPN:
Extended Sequence Numbers enable: N
Traffic Flow Confidentiality enable: N
Transmitting entity: Responder
Path MTU: 1424
Tunnel:
local address: 120.86.184.129
remote address: 183.47.54.218
Flow:
sour addr: 192.168.12.0/255.255.255.0 port: 0 protocol: ip acl里一个rule 对应一个ipsec sa的flow
dest addr: 192.168.6.0/255.255.255.0 port: 0 protocol: ip
[Inbound ESP SAs]
SPI: 3494636767 (0xd04becdf)
Connection ID: 253403070465
Transform set: ESP-ENCRYPT-AES-CBC-256 ESP-AUTH-SHA256
SA duration (kilobytes/sec): 1843200/3600
SA remaining duration (kilobytes/sec): 1843178/3301
Max received sequence-number: 230
Anti-replay check enable: Y
Anti-replay window size: 64
UDP encapsulation used for NAT traversal: N
Status: Active
[Outbound ESP SAs]
SPI: 442940909 (0x1a66bded)
Connection ID: 7932804595712
Transform set: ESP-ENCRYPT-AES-CBC-256 ESP-AUTH-SHA256
SA duration (kilobytes/sec): 1843200/3600
SA remaining duration (kilobytes/sec): 1843178/3301
Max sent sequence-number: 230
UDP encapsulation used for NAT traversal: N
Status: Active
-----------------------------
IPsec policy: map1
Sequence number: 10
Mode: ISAKMP
-----------------------------
Tunnel id: 0
Encapsulation mode: tunnel
Perfect Forward Secrecy:
Inside VPN:
Extended Sequence Numbers enable: N
Traffic Flow Confidentiality enable: N
Transmitting entity: Responder
Path MTU: 1424
Tunnel:
local address: 120.86.184.129
remote address: 183.47.54.218
Flow:
sour addr: 192.168.12.0/255.255.255.0 port: 0 protocol: ip
dest addr: 192.168.216.0/255.255.255.0 port: 0 protocol: ip
[Inbound ESP SAs]
SPI: 4169742112 (0xf8893720)
Connection ID: 4599909974019
Transform set: ESP-ENCRYPT-AES-CBC-256 ESP-AUTH-SHA256
SA duration (kilobytes/sec): 1843200/3600
SA remaining duration (kilobytes/sec): 1843200/3301
Max received sequence-number: 0
Anti-replay check enable: Y
Anti-replay window size: 64
UDP encapsulation used for NAT traversal: N
Status: Active
[Outbound ESP SAs]
SPI: 584202424 (0x22d238b8)
Connection ID: 1000727379970
Transform set: ESP-ENCRYPT-AES-CBC-256 ESP-AUTH-SHA256
SA duration (kilobytes/sec): 1843200/3600
SA remaining duration (kilobytes/sec): 1843195/3301
Max sent sequence-number: 46
UDP encapsulation used for NAT traversal: N
Status: Active
-----------------------------
IPsec policy: map1
Sequence number: 10
Mode: ISAKMP
-----------------------------
Tunnel id: 1
Encapsulation mode: tunnel
Perfect Forward Secrecy:
Inside VPN:
Extended Sequence Numbers enable: N
Traffic Flow Confidentiality enable: N
Transmitting entity: Responder
Path MTU: 1424
Tunnel:
local address: 120.86.184.129
remote address: 183.47.54.218
Flow:
sour addr: 192.168.12.0/255.255.255.0 port: 0 protocol: ip
dest addr: 192.168.217.0/255.255.255.0 port: 0 protocol: ip
[Inbound ESP SAs]
SPI: 4066521980 (0xf262337c)
Connection ID: 313532612614
Transform set: ESP-ENCRYPT-AES-CBC-256 ESP-AUTH-SHA256
SA duration (kilobytes/sec): 1843200/3600
SA remaining duration (kilobytes/sec): 1843200/3301
Max received sequence-number: 0
Anti-replay check enable: Y
Anti-replay window size: 64
UDP encapsulation used for NAT traversal: N
Status: Active
[Outbound ESP SAs]
SPI: 1421458572 (0x54b9bc8c)
Connection ID: 1404454305800
Transform set: ESP-ENCRYPT-AES-CBC-256 ESP-AUTH-SHA256
SA duration (kilobytes/sec): 1843200/3600
SA remaining duration (kilobytes/sec): 1843200/3301
Max sent sequence-number: 0
UDP encapsulation used for NAT traversal: N
Status: Active
<FW>display ipsec
tunnel brief
----------------------------------------------------------------------------
Tunn-id Src Address Dst Address Inbound SPI Outbound SPI Status
----------------------------------------------------------------------------
0 120.86.184.129 183.47.54.218 4169742112 584202424 Active
1 120.86.184.129 183.47.54.218 4066521980 1421458572 Active
2 120.86.184.129 183.47.54.218 3494636767 442940909 Active
<FW>display
ipsec statistics
IPsec packet statistics:
Received/sent packets: 0/265
Received/sent bytes: 0/25440
Received/sent packet rate: 0/1 packets/sec
Received/sent byte rate: 0/58 bytes/sec
Dropped packets (received/sent): 0/0
Dropped packets statistics
No available SA: 0
Wrong SA: 0
Invalid length: 0
Authentication failure: 0
Encapsulation failure: 0
Decapsulation failure: 0
Replayed packets: 0
ACL check failure: 0
MTU check failure: 0
Loopback limit exceeded: 0
Crypto speed limit exceeded: 0
<FW>display ipsec statistics tunnel-id 0
IPsec packet statistics:
Received/sent packets: 0/265
Received/sent bytes: 0/25824
Received/sent packet rate: 0/1 packets/sec
Received/sent byte rate: 0/58 bytes/sec
Dropped packets (received/sent): 0/0
Dropped packets statistics
No available SA: 0
Wrong SA: 0
Invalid length: 0
Authentication failure: 0
Encapsulation failure: 0
Decapsulation failure: 0
Replayed packets: 0
ACL check failure: 0
MTU check failure: 0
Loopback limit exceeded: 0
Crypto speed limit exceeded: 0
<FW>
<FW>
<FW>display ipsec statistics tunnel-id 1
IPsec packet statistics:
Received/sent packets: 0/0
Received/sent bytes: 0/0
Received/sent packet rate: 0/0 packets/sec
Received/sent byte rate: 0/0 bytes/sec
Dropped packets (received/sent): 0/0
Dropped packets statistics
No available SA: 0
Wrong SA: 0
Invalid length: 0
Authentication failure: 0
Encapsulation failure: 0
Decapsulation failure: 0
Replayed packets: 0
ACL check failure: 0
MTU check failure: 0
Loopback limit exceeded: 0
Crypto speed limit exceeded: 0
<FW>
<FW>
<FW>display ipsec statistics tunnel-id 2
IPsec packet statistics:
Received/sent packets: 0/0
Received/sent bytes: 0/0
Received/sent packet rate: 0/0 packets/sec
Received/sent byte rate: 0/0 bytes/sec
Dropped packets (received/sent): 0/0
Dropped packets statistics
No available SA: 0
Wrong SA: 0
Invalid length: 0
Authentication failure: 0
Encapsulation failure: 0
Decapsulation failure: 0
Replayed packets: 0
ACL check failure: 0
MTU check failure: 0
Loopback limit exceeded: 0
Crypto speed limit exceeded: 0
(0)
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作