天天看点

(华为CE交换机排故)二层可通,三层不通,网关不通

问题现象10.125.10.162 ping 不通网关,二层arping可以通网关

配置流量统计方法

#在接入CE交换机配置流量统计
acl number 3333
rule 5 permit ip source 10.125.10.162 0 destination 10.125.10.1 0
rule 10 permit ip source 10.125.10.1 0 destination 10.125.10.162 0


traffic classifier test01 type and
if-match acl 3333

traffic behavior test01
statistics enable 

traffic policy test01
classifier test01 behavior test01

int 10GE 1/0/40    #下联业务口
traffic-policy test01 inbound
traffic-policy test01 outbound

int Eth-Trunk  1    #上联口
traffic-policy test01 inbound
traffic-policy test01 outbound      
#主机ping网关
dis traffic-policy  statistics  interface 10GE1/0/40
Traffic policy: test01, inbound 
--------------------------------------------------------------------------------
 Slot: 1
 Item                  Packets                Bytes           pps           bps
 -------------------------------------------------------------------------------
 Matched                     4                  424             0           144
  Passed                     4                  424             0           144
  Dropped                    0                    0             0             0
   Filter                    0                    0             0             0
   CAR                       0                    0             0             0
 -------------------------------------------------------------------------------
Traffic policy: test01, outbound 
--------------------------------------------------------------------------------
 Slot: 1
 Item                  Packets                Bytes           pps           bps
 -------------------------------------------------------------------------------
 Matched                     4                  424             0            80
  Passed                     4                  424             0            80
  Dropped                    0                    0             0             0
   Filter                    0                    0             0             0
   CAR                       0                    0             0             0
 -------------------------------------------------------------------------------



dis traffic-policy  statistics  interface  Eth-Trunk  1 
Traffic policy: test01, inbound 
--------------------------------------------------------------------------------
 Slot: 1
 Item                  Packets                Bytes           pps           bps
 -------------------------------------------------------------------------------
 Matched                     4                  424             0            56
  Passed                     4                  424             0            56
  Dropped                    0                    0             0             0
   Filter                    0                    0             0             0
   CAR                       0                    0             0             0
 -------------------------------------------------------------------------------
 Slot: 2
 Item                  Packets                Bytes           pps           bps
 -------------------------------------------------------------------------------
 Matched                     0                    0             0             0
  Passed                     0                    0             0             0
  Dropped                    0                    0             0             0
   Filter                    0                    0             0             0
   CAR                       0                    0             0             0
 -------------------------------------------------------------------------------
Traffic policy: test01, outbound 
--------------------------------------------------------------------------------
 Slot: 1
 Item                  Packets                Bytes           pps           bps
 -------------------------------------------------------------------------------
 Matched                     4                  424             0             0
  Passed                     4                  424             0             0
  Dropped                    0                    0             0             0
   Filter                    0                    0             0             0
   CAR                       0                    0             0             0
 -------------------------------------------------------------------------------
 Slot: 2
 Item                  Packets                Bytes           pps           bps
 -------------------------------------------------------------------------------
 Matched                     0                    0             0             0
  Passed                     0                    0             0             0
  Dropped                    0                    0             0             0
   Filter                    0                    0             0             0
   CAR                       0                    0             0             0
 -------------------------------------------------------------------------------




capture-packet  interface Eth-Trunk  1 acl  3333 destination  terminal  packet-num  100 packet-len  64 
[16:37:14]Warning: Capture-packet will be shown on terminal.
[16:37:28]  Packet: 0 Interface: Eth-Trunk1
[16:37:28]
[16:37:28]  -------------------------------------------------------
[16:37:28]
[16:37:28]  00 50 56 a6 a8 92 60 12 3c 4c 0b d4 81 00 03 f2
[16:37:28]
[16:37:28]  08 00 45 00 00 54 bc 33 40 00 fe 01 96 d8 0a 7d
[16:37:28]
[16:37:28]  0a 01 0a 7d 0a a2 00 00 f3 cb 09 53 00 01 47 ec
[16:37:28]
[16:37:28]  67 61 00 00 00 00 87 bf 0d 00 00 00 00 00 10 11
[16:37:28]
[16:37:28]  -------------------------------------------------------
[16:37:29]
[16:37:29]  Packet: 1 Interface: Eth-Trunk1
[16:37:29]
[16:37:29]  -------------------------------------------------------
[16:37:29]
[16:37:29]  00 50 56 a6 a8 92 60 12 3c 4c 0b d4 81 00 03 f2
[16:37:29]
[16:37:29]  08 00 45 00 00 54 bf 3b 40 00 fe 01 93 d0 0a 7d
[16:37:29]
[16:37:29]  0a 01 0a 7d 0a a2 00 00 27 cc 09 53 00 02 48 ec
[16:37:29]
[16:37:29]  67 61 00 00 00 00 52 be 0d 00 00 00 00 00 10 11
[16:37:29]
[16:37:29]  -------------------------------------------------------
[16:37:30]
[16:37:30]  Packet: 2 Interface: Eth-Trunk1
[16:37:30]
[16:37:30]  -------------------------------------------------------
[16:37:30]
[16:37:30]  00 50 56 a6 a8 92 60 12 3c 4c 0b d4 81 00 03 f2
[16:37:30]
[16:37:30]  08 00 45 00 00 54 bf c9 40 00 fe 01 93 42 0a 7d
[16:37:30]
[16:37:30]  0a 01 0a 7d 0a a2 00 00 2d cb 09 53 00 03 49 ec
[16:37:30]
[16:37:30]  67 61 00 00 00 00 4b be 0d 00 00 00 00 00 10 11
[16:37:30]
[16:37:30]  -------------------------------------------------------
[16:37:31]
[16:37:31]  Packet: 3 Interface: Eth-Trunk1
[16:37:31]
[16:37:31]  -------------------------------------------------------
[16:37:31]
[16:37:31]  00 50 56 a6 a8 92 60 12 3c 4c 0b d4 81 00 03 f2
[16:37:31]
[16:37:31]  08 00 45 00 00 54 c1 06 40 00 fe 01 92 05 0a 7d
[16:37:31]
[16:37:31]  0a 01 0a 7d 0a a2 00 00 2d ca 09 53 00 04 4a ec
[16:37:31]
[16:37:31]  67 61 00 00 00 00 4a be 0d 00 00 00 00 00 10 11
[16:37:31]
[16:37:31]  -------------------------------------------------------
[16:37:37]
[16:38:14]  ------------------capture report-----------------------
[16:38:14]
[16:38:14]  Capture-Packet Index 1
[16:38:14]  Type        : forwarding
[16:38:14]  Interface   : Eth-Trunk1
[16:38:14]  Direction   : inbound
[16:38:14]  ACL         : 3333
[16:38:14]  Time-out    : 60 seconds
[16:38:14]  Packet-num  : 100
[16:38:14]  Packet-len  : 64
[16:38:14]  BufferOnly  : disabled
[16:38:14]
[16:38:14]  -------------------------------------------------------



#目mac:00 50 56 a6 a8 92
#源mac:60 12 3c 4c 0b d4


#网关查看mac信息
dis arp network   10.125.10.162
[16:32:12]ARP Entry Types: D - Dynamic, S - Static, I - Interface, O - OpenFlow, RD - Redirect
[16:32:12]EXP: Expire-time VLAN: VLAN or Bridge Domain
[16:32:12]
[16:32:12]IP ADDRESS      MAC ADDRESS    EXP(M) TYPE/VLAN       INTERFACE        VPN-INSTANCE
[16:32:12]----------------------------------------------------------------------------------------
[16:32:12]10.125.10.162   0050-56a6-32b2   18   D/1010          Eth-Trunk12      
[16:32:12]----------------------------------------------------------------------------------------
[16:32:12]Total:1         Dynamic:1       Static:0    Interface:0    OpenFlow:0
[16:32:12]Redirect:0

[16:32:20]dis arp network   10.125.10.1   
[16:32:20]ARP Entry Types: D - Dynamic, S - Static, I - Interface, O - OpenFlow, RD - Redirect
[16:32:20]EXP: Expire-time VLAN: VLAN or Bridge Domain
[16:32:20]
[16:32:20]IP ADDRESS      MAC ADDRESS    EXP(M) TYPE/VLAN       INTERFACE        VPN-INSTANCE
[16:32:20]----------------------------------------------------------------------------------------
[16:32:20]10.125.10.1     6012-3c4c-0bd4        I               Vlanif1010       
[16:32:20]----------------------------------------------------------------------------------------
[16:32:20]Total:1         Dynamic:0       Static:0    Interface:1    OpenFlow:0
[16:32:20]Redirect:0



#发现网关回包的目的mac不对
#找客服处理
#问题是CE交换机有bug,导致mac地址表紊乱(这里我们是运行keepalived(vrrp))出的问题,更新补丁后正常