tks_333 2005-5-18 16:40
我把所有的配置都已经发给cisco的工程师了,他们也没有看出来什么,请大家讨论讨论是什么原因
目前的情况如下:防火墙双机,在防火墙上做透明,内部全部是校园网地址并且是一个网段(暂时使用),4503的地址是251,4503-2的地址是252,虚拟地址是250,45下面的服务器双千兆网卡邦定分别连到4503,4503做hsrp,4503中间有一对光纤连接,
问题如下:从服务器上面ping虚拟地址250,时通时不通,如果关掉一台4503,切换正常,而且可以一直ping通,如果再打开的话,过了几十分钟,又不通了,在45上面用clear arp的命令,通了有不到10个ping包,继续不通,在校园网内的任何地址都可以ping通250,在4503-1上面用show spanning-tree detail查看,发现4503-1上面和另外一台4503连接的端口gi3/1状态blocking,说明他们目前协商包是通过上面的防火墙来传递的,就是在ping不通的时候,我通过debug standby
查看协商,包也是正常的,in out
可能情况:1、ios的bug
2、服务器---〉4503——〉服务器中间 出现环路,网络不稳定
一些配置:
CISCO4503-1#show standby
Vlan2 - Group 1
Local state is Active, priority 180, may preempt
Hellotime 3 sec, holdtime 10 sec
Next hello sent in 0.528
Virtual IP address is 202.197.191.250 configured
Active router is local
Standby router is 202.197.191.252 expires in 7.784
Virtual mac address is 0000.0c07.ac01
1 state changes, last state change 00:41:49
IP redundancy name is "hsrp-Vl2-1" (default)
CISCO4503-1#show span
CISCO4503-1#show spanning-tree de
VLAN0002 is executing the ieee compatible Spanning Tree protocol
Bridge Identifier has priority 32768, sysid 2, address 0012.dabc.1600
Configured hello time 2, max age 20, forward delay 15
Current root has priority 32768, address 0011.bc64.d402
Root port is 131 (GigabitEthernet3/3), cost of root path is 8
Topology change flag not set, detected flag not set
Number of topology changes 6 last change occurred 00:21:58 ago
from GigabitEthernet3/6
Times: hold 1, topology change 35, notification 2
hello 2, max age 20, forward delay 15
Timers: hello 0, topology change 0, notification 0, aging 300
Port 2 (GigabitEthernet1/2) of VLAN0002 is forwarding
Port path cost 19, Port priority 128, Port Identifier 128.2.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.1600
Designated port id is 128.2, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 1288, received 0
Port 4 (GigabitEthernet1/4) of VLAN0002 is forwarding
Port path cost 19, Port priority 128, Port Identifier 128.4.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.1600
Designated port id is 128.4, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
The port is in the portfast mode
Link type is point-to-point by default
BPDU: sent 1288, received 0
Port 8 (GigabitEthernet1/8) of VLAN0002 is forwarding
Port path cost 19, Port priority 128, Port Identifier 128.8.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.1600
Designated port id is 128.8, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
The port is in the portfast mode
Link type is point-to-point by default
BPDU: sent 1289, received 0
Port 129 (GigabitEthernet3/1) of VLAN0002 is blocking
Port path cost 4, Port priority 128, Port Identifier 128.129.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.15c0
Designated port id is 128.129, designated path cost 8
Timers: message age 2, forward delay 0, hold 0
Number of transitions to forwarding state: 0
Link type is point-to-point by default
BPDU: sent 1, received 1286
Port 131 (GigabitEthernet3/3) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.131.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32769, address 0090.fb01.6e92
Designated port id is 128.4, designated path cost 4
Timers: message age 1, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 6, received 1290
Port 132 (GigabitEthernet3/4) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.132.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.1600
Designated port id is 128.132, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 1290, received 0
Port 134 (GigabitEthernet3/6) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.134.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.1600
Designated port id is 128.134, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 683, received 0
Port 135 (GigabitEthernet3/7) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.135.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.1600
Designated port id is 128.135, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 1290, received 0
Port 136 (GigabitEthernet3/8) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.136.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.1600
Designated port id is 128.136, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 1290, received 0
Port 138 (GigabitEthernet3/10) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.138.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.1600
Designated port id is 128.138, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 1290, received 0
4503-2的配置:
how spn an
VLAN0002
Spanning tree enabled protocol ieee
Root ID Priority 32768
Address 0011.bc64.d402
Cost 8
Port 131 (GigabitEthernet3/3)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32770 (priority 32768 sys-id-ext 2)
Address 0012.dabc.15c0
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 300
Interface Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- --------------------------------
Gi1/1 Desg FWD 19 128.1 P2p
Gi3/1 Desg FWD 4 128.129 P2p
Gi3/3 Root FWD 4 128.131 P2p
Gi3/4 Desg FWD 4 128.132 Edge P2p
Gi3/5 Desg FWD 4 128.133 Edge P2p
Gi3/6 Desg FWD 4 128.134 Edge P2p
Gi3/7 Desg FWD 4
Interface Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- --------------------------------
Gi3/9 Desg FWD 4 128.137 Edge P2p
CISCO4503-2#show span
CISCO4503-2#show spanning-tree de
VLAN0002 is executing the ieee compatible Spanning Tree protocol
Bridge Identifier has priority 32768, sysid 2, address 0012.dabc.15c0
Configured hello time 2, max age 20, forward delay 15
Current root has priority 32768, address 0011.bc64.d402
Root port is 131 (GigabitEthernet3/3), cost of root path is 8
Topology change flag not set, detected flag not set
Number of topology changes 6 last change occurred 00:23:51 ago
from GigabitEthernet1/3
Times: hold 1, topology change 35, notification 2
hello 2, max age 20, forward delay 15
Timers: hello 0, topology change 0, notification 0, aging 300
Port 1 (GigabitEthernet1/1) of VLAN0002 is forwarding
Port path cost 19, Port priority 128, Port Identifier 128.1.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.15c0
Designated port id is 128.1, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 31588, received 0
Port 129 (GigabitEthernet3/1) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.129.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.15c0
Designated port id is 128.129, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 1151, received 1
Port 131 (GigabitEthernet3/3) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.131.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32769, address 0090.fb01.6e92
Designated port id is 128.3, designated path cost 4
Timers: message age 1, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 6, received 31591
Port 132 (GigabitEthernet3/4) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.132.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.15c0
Designated port id is 128.132, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
The port is in the portfast mode
Link type is point-to-point by default
BPDU: sent 2977, received 0
Port 133 (GigabitEthernet3/5) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.133.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.15c0
Designated port id is 128.133, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
The port is in the portfast mode
Link type is point-to-point by default
BPDU: sent 31591, received 0
Port 134 (GigabitEthernet3/6) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.134.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.15c0
Designated port id is 128.134, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
The port is in the portfast mode
Link type is point-to-point by default
BPDU: sent 31591, received 0
Port 135 (GigabitEthernet3/7) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.135.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.15c0
Designated port id is 128.135, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
The port is in the portfast mode
Link type is point-to-point by default
BPDU: sent 806, received 0
Port 137 (GigabitEthernet3/9) of VLAN0002 is forwarding
Port path cost 4, Port priority 128, Port Identifier 128.137.
Designated root has priority 32768, address 0011.bc64.d402
Designated bridge has priority 32770, address 0012.dabc.15c0
Designated port id is 128.137, designated path cost 8
Timers: message age 0, forward delay 0, hold 0
Number of transitions to forwarding state: 1
The port is in the portfast mode
Link type is point-to-point by default
BPDU: sent 1258, received 0
CISCO4503-2# show span
CISCO4503-2#show spanning-tree roo
Root Hello Max Fwd
Vlan Root ID Cost Time Age Dly Root Port
---------------- -------------------- ------ ----- --- --- ----------------
VLAN0002 32768 0011.bc64.d402542789000 2 20 15 Gi3/3
wgh 2005-5-24 17:32
问题应该有可能是在你服务器上,你服务器都是双网卡绑定,我想问一下,你的服务器双网卡的模式是做成出错冗余方式,还是负载均衡方式,还是链路汇聚方式?这几种方式协议标准和工作方式都是有区别的,当然有些也是要交换机也支持,就比如链路汇聚一样,注意,建议你把网卡的绑定方式和两台4503的配置最好帖出来,就明白了,我初步估计你是在服务器那边做了链路汇聚或负载均衡,而交换机那边的端口又没有正确配置.
服务器的网卡是用INTEL 的PROSET程序配置的,还是3COM的?
tks_333 2005-10-8 10:32
现在又出现新的情况,客户又在下面增加一个网段的教育网地址,在2950管理区用,于是我就在2950以及6506之间做了trunk,不得已在3750以及4503上面也需要做trunk.
问题出现了,4503又出现了环路,4503-2的上联端口和3/1(对接4503-1)提示两个端口同时收到一个mac地址(其中有6506的mac地址还有其它区的mac地址),断断续续的丢包 ,环路又出现了,各位分析一下
永不妥协 2006-1-16 09:46
[quote]Originally posted by [i]tks_333[/i] at 2005-10-8 10:32 AM:
现在又出现新的情况,客户又在下面增加一个网段的教育网地址,在2950管理区用,于是我就在2950以及6506之间做了trunk,不得已在3750以及4503上面也需要做trunk.
问题出现了,4503又出现了环路,4503-2的上联端口和3/1( ... [/quote]
是ARP广播环,不能全部都做成trunk,建议把NGFW-4000之间再做一组VRRP
即使要做TRUNK也只能对部分VLAN做穿透,用户网段不要穿透在核心上,如果穿透在核心上,第一丧失了做VLAN的意义(不能有效隔离广播),第二违背了网络的设计原则(层次化的网络结构).