• 全部
  • 經驗案例
  • 典型配置
  • 技術公告
  • FAQ
  • 漏洞說明
  • 全部
  • 全部
  • 大數據引擎
  • 知了引擎
產品線
搜索
取消
案例類型
發布者
是否解決
是否官方
時間
搜索引擎
匹配模式
高級搜索

交換機下聯的傻瓜交換機掉包!

2025-04-08提問
  • 0關注
  • 0收藏,447瀏覽
粉絲:0人 關注:0人

問題描述:

設備為S5130

DEVICE_NAME          : S5130-28S-EI

DEVICE_SERIAL_NUMBER : 210235A1C9H165000803

MAC_ADDRESS          : 8CE6-6667-6225

MANUFACTURING_DATE   : 2016-05-18

VENDOR_NAME          : H3C

問題:AP分配的ip地址,ping 從華為S2100交換機獲得的地址大量掉包,不知道原因。

 

 

 

 

拓撲結構 

華為ap-華為ac-(23口)華三S5130(上連)-外網核心交換機-出口防火牆

華為S2100(無配置,當傻瓜交換機使用)-(21口)華三S5130(上連)-外網核心交換機-出口防火牆

華三配置:

[H3C]dis ip  routing-table 

 

Destinations : 29       Routes : 29

 

Destination/Mask    Proto  Pre  Cost         NextHop         Interface

0.0.0.0/0           Static 60   0            192.168.1.1     Vlan100

0.0.0.0/32          Direct 0    0            127.0.0.1       InLoop0

127.0.0.0/8         Direct 0    0            127.0.0.1       InLoop0

127.0.0.0/32        Direct 0    0            127.0.0.1       InLoop0

127.0.0.1/32        Direct 0    0            127.0.0.1       InLoop0

127.255.255.255/32  Direct 0    0            127.0.0.1       InLoop0

172.16.0.0/24       Static 60   0            192.168.200.2   Vlan200

172.16.2.0/24       Static 60   0            192.168.200.2   Vlan200

172.16.3.0/24       Static 60   0            192.168.200.2   Vlan200

192.168.0.0/24      Direct 0    0            192.168.0.254   Vlan9

192.168.0.0/32      Direct 0    0            192.168.0.254   Vlan9

192.168.0.254/32    Direct 0    0            127.0.0.1       InLoop0

192.168.0.255/32    Direct 0    0            192.168.0.254   Vlan9

192.168.1.0/24      Direct 0    0            192.168.1.2     Vlan100

192.168.1.0/32      Direct 0    0            192.168.1.2     Vlan100

192.168.1.2/32      Direct 0    0            127.0.0.1       InLoop0

192.168.1.255/32    Direct 0    0            192.168.1.2     Vlan100

192.168.10.0/24     Static 60   0            192.168.200.2   Vlan200

192.168.200.0/30    Direct 0    0            192.168.200.1   Vlan200

192.168.200.0/32    Direct 0    0            192.168.200.1   Vlan200

192.168.200.1/32    Direct 0    0            127.0.0.1       InLoop0

192.168.200.3/32    Direct 0    0            192.168.200.1   Vlan200

192.168.253.0/24    Direct 0    0            192.168.253.254 Vlan4000

192.168.253.0/32    Direct 0    0            192.168.253.254 Vlan4000

192.168.253.254/32  Direct 0    0            127.0.0.1       InLoop0

192.168.253.255/32  Direct 0    0            192.168.253.254 Vlan4000

224.0.0.0/4         Direct 0    0            0.0.0.0         NULL0

224.0.0.0/24        Direct 0    0            0.0.0.0         NULL0

255.255.255.255/32  Direct 0    0            127.0.0.1       InLoop0

[H3C] dis cu

#

 version 7.1.045, Release 3109P09

#

 sysname H3C

#

 telnet server enable

#

 irf mac-address persistent timer

 irf auto-update enable

 undo irf link-delay

 irf member 1 priority 1

#

 dhcp enable

#

 lldp global enable

#

 password-recovery enable

#

vlan 1

#

vlan 4

 description yewu

#

vlan 9         

#

vlan 100

 description TO-hexin

#

vlan 200

 description TO-ac

#

vlan 4000

#

 stp global enable

#

dhcp server ip-pool client

 gateway-list 192.168.0.254

 network 192.168.0.0 mask 255.255.255.0

 address range 192.168.0.1 192.168.0.245

 dns-list 221.13.65.34 8.8.8.8

#

interface NULL0

#

interface Vlan-interface9

 ip address 192.168.0.254 255.255.255.0

 dhcp server apply ip-pool client

#              

interface Vlan-interface100

 ip address 192.168.1.2 255.255.255.0

#

interface Vlan-interface200

 ip address 192.168.200.1 255.255.255.252

#

interface Vlan-interface4000

 ip address 192.168.253.254 255.255.255.0

#

interface GigabitEthernet1/0/1

 port access vlan 4

#

interface GigabitEthernet1/0/2

 port access vlan 4

#

interface GigabitEthernet1/0/3

 port access vlan 4

#

interface GigabitEthernet1/0/4

 port access vlan 4

#

interface GigabitEthernet1/0/5

 port access vlan 4

#

interface GigabitEthernet1/0/6

 port access vlan 4

#

interface GigabitEthernet1/0/7

 port access vlan 4

#

interface GigabitEthernet1/0/8

 port access vlan 4

#

interface GigabitEthernet1/0/9

#

interface GigabitEthernet1/0/10

#

interface GigabitEthernet1/0/11

#

interface GigabitEthernet1/0/12

#

interface GigabitEthernet1/0/13

#

interface GigabitEthernet1/0/14

#

interface GigabitEthernet1/0/15

#

interface GigabitEthernet1/0/16

#

interface GigabitEthernet1/0/17

#

interface GigabitEthernet1/0/18

#

interface GigabitEthernet1/0/19

#

interface GigabitEthernet1/0/20

#

interface GigabitEthernet1/0/21

 port access vlan 9

#

interface GigabitEthernet1/0/22

#

interface GigabitEthernet1/0/23

 port access vlan 200

#

interface GigabitEthernet1/0/24

 port link-type trunk

 port trunk permit vlan all

#              

interface Ten-GigabitEthernet1/0/25

#

interface Ten-GigabitEthernet1/0/26

#

interface Ten-GigabitEthernet1/0/27

#

interface Ten-GigabitEthernet1/0/28

#

 scheduler logfile size 16

#

line class aux

 user-role network-admin

#

line class vty

 user-role network-operator

#

line aux 0

 authentication-mode password

 user-role level-15

 user-role network-admin

#

line vty 0 4

 authentication-mode scheme

 user-role level-15

 user-role network-admin

 user-role network-operator

#

line vty 5 63

 user-role network-operator

#

 ip route-static 0.0.0.0 0 192.168.1.1

 ip route-static 172.16.0.0 24 192.168.200.2

 ip route-static 172.16.2.0 24 192.168.200.2

 ip route-static 172.16.3.0 24 192.168.200.2

 ip route-static 192.168.10.0 24 192.168.200.2

#

radius scheme system

 user-name-format without-domain

#

domain system

#

 domain default enable system

#

role name level-0

 description Predefined level-0 role

#              

role name level-1

 description Predefined level-1 role

#

role name level-2

 description Predefined level-2 role

#

role name level-3

 description Predefined level-3 role

#

role name level-4

 description Predefined level-4 role

#

role name level-5

 description Predefined level-5 role

#

role name level-6

 description Predefined level-6 role

#

role name level-7

 description Predefined level-7 role

#

role name level-8

 description Predefined level-8 role

#

role name level-9

 description Predefined level-9 role

#

role name level-10

 description Predefined level-10 role

#

role name level-11

 description Predefined level-11 role

#

role name level-12

 description Predefined level-12 role

#

role name level-13

 description Predefined level-13 role

#

role name level-14

 description Predefined level-14 role

#

user-group system

#

local-user admin class manage

 password hash $h$6$Bd4qf7a8AItOcUDu$2mWoPIxtiTEY2gyGP42wZY4llcxmJDbFrGdDj+zAKgwHuySLJ+2MsmWA2p8NC+W6xvo1Y62VfkC2nzE8mVxbnQ==

 service-type ssh telnet http https

 authorization-attribute user-role network-operator

#

return

 

weibo.com/ttarticle/p/show?id=2309405152949834744092

weibo.com/ttarticle/p/show?id=2309405152952154456203

weibo.com/ttarticle/p/show?id=2309405152953110757394

weibo.com/ttarticle/p/show?id=2309405152951705665625

weibo.com/ttarticle/p/show?id=2309405152948589035691

weibo.com/ttarticle/p/show?id=2309405152948459274910

weibo.com/ttarticle/p/show?id=2309405152949398798411

weibo.com/ttarticle/p/show?id=2309405152951684694324

weibo.com/ttarticle/p/show?id=2309405152949633679746

weibo.com/ttarticle/p/show?id=2309405152951227253000

weibo.com/ttarticle/p/show?id=2309405152950304506064

weibo.com/ttarticle/p/show?id=2309405152950992634270

weibo.com/ttarticle/p/show?id=2309405152950010904592

weibo.com/ttarticle/p/show?id=2309405152950501900604

weibo.com/ttarticle/p/show?id=2309405152948404749004

weibo.com/ttarticle/p/show?id=2309405152948123730422

weibo.com/ttarticle/p/show?id=2309405152947255509706

weibo.com/ttarticle/p/show?id=2309405152947704037464

weibo.com/ttarticle/p/show?id=2309405152946949325302

weibo.com/ttarticle/p/show?id=2309405152946789941254

weibo.com/ttarticle/p/show?id=2309405152945674256546

weibo.com/ttarticle/p/show?id=2309405152944243998922

weibo.com/ttarticle/p/show?id=2309405152944398925903

weibo.com/ttarticle/p/show?id=2309405152944839327752

weibo.com/ttarticle/p/show?id=2309405152945930108950

weibo.com/ttarticle/p/show?id=2309405152944449257600

weibo.com/ttarticle/p/show?id=2309405152944084615211

weibo.com/ttarticle/p/show?id=2309405152943794946147

weibo.com/ttarticle/p/show?id=2309405152943962718245

weibo.com/ttarticle/p/show?id=2309405152940951470503

weibo.com/ttarticle/p/show?id=2309405152940657869145

weibo.com/ttarticle/p/show?id=2309405152940397822253

weibo.com/ttarticle/p/show?id=2309405152943786557454

weibo.com/ttarticle/p/show?id=2309405152943652339772

weibo.com/ttarticle/p/show?id=2309405152941597130795

weibo.com/ttarticle/p/show?id=2309405152941463175239

weibo.com/ttarticle/p/show?id=2309405152942591443139

weibo.com/ttarticle/p/show?id=2309405152942486585409

weibo.com/ttarticle/p/show?id=2309405152940267798700

weibo.com/ttarticle/p/show?id=2309405152941865566293

weibo.com/ttarticle/p/show?id=2309405152940221661226

weibo.com/ttarticle/p/show?id=2309405152940167135432

weibo.com/ttarticle/p/show?id=2309405152940070666246

weibo.com/ttarticle/p/show?id=2309405152938384556111

weibo.com/ttarticle/p/show?id=2309405152938510385410

weibo.com/ttarticle/p/show?id=2309405152937746759772

weibo.com/ttarticle/p/show?id=2309405152937923182797

weibo.com/ttarticle/p/show?id=2309405152939982586164

weibo.com/ttarticle/p/show?id=2309405152938208395295

weibo.com/ttarticle/p/show?id=2309405152938040623118

weibo.com/ttarticle/p/show?id=2309405152939923865966

weibo.com/ttarticle/p/show?id=2309405152939340595273

weibo.com/ttarticle/p/show?id=2309405152939474813006

weibo.com/ttarticle/p/show?id=2309405152939047256114

weibo.com/ttarticle/p/show?id=2309405152936954298391

weibo.com/ttarticle/p/show?id=2309405152937176334408

weibo.com/ttarticle/p/show?id=2309405152936723611774

weibo.com/ttarticle/p/show?id=2309405152936228683910

weibo.com/ttarticle/p/show?id=2309405152935377240322

weibo.com/ttarticle/p/show?id=2309405152932654874800

weibo.com/ttarticle/p/show?id=2309405152934500368642

weibo.com/ttarticle/p/show?id=2309405152933099733414

weibo.com/ttarticle/p/show?id=2309405152932978098365

weibo.com/ttarticle/p/show?id=2309405152931145187380

weibo.com/ttarticle/p/show?id=2309405152930687746288

weibo.com/ttarticle/p/show?id=2309405152930105000088

weibo.com/ttarticle/p/show?id=2309405152930138554973

weibo.com/ttarticle/p/show?id=2309405152929504952576

 

 

最佳答案

已采納
粉絲:0人 關注:0人

檢查下接口有沒有錯包,中間設備做流量統計定位丟包位置

暫無評論

2 個回答
粉絲:108人 關注:9人

看下日誌情況,接口流量

暫無評論

粉絲:32人 關注:1人

抓包看一下

暫無評論

編輯答案

你正在編輯答案

如果你要對問題或其他回答進行點評或詢問,請使用評論功能。

分享擴散:

提出建議

    +

親~登錄後才可以操作哦!

確定

親~檢測到您登陸的賬號未在http://hclhub.h3c.com進行注冊

注冊後可訪問此模塊

跳轉hclhub

你的郵箱還未認證,請認證郵箱或綁定手機後進行當前操作

舉報

×

侵犯我的權益 >
對根叔社區有害的內容 >
辱罵、歧視、挑釁等(不友善)

侵犯我的權益

×

泄露了我的隱私 >
侵犯了我企業的權益 >
抄襲了我的內容 >
誹謗我 >
辱罵、歧視、挑釁等(不友善)
騷擾我

泄露了我的隱私

×

您好,當您發現根叔知了上有泄漏您隱私的內容時,您可以向根叔知了進行舉報。 請您把以下內容通過郵件發送到pub.zhiliao@h3c.com 郵箱,我們會盡快處理。
  • 1. 您認為哪些內容泄露了您的隱私?(請在郵件中列出您舉報的內容、鏈接地址,並給出簡短的說明)
  • 2. 您是誰?(身份證明材料,可以是身份證或護照等證件)

侵犯了我企業的權益

×

您好,當您發現根叔知了上有關於您企業的造謠與誹謗、商業侵權等內容時,您可以向根叔知了進行舉報。 請您把以下內容通過郵件發送到 pub.zhiliao@h3c.com 郵箱,我們會在審核後盡快給您答複。
  • 1. 您舉報的內容是什麼?(請在郵件中列出您舉報的內容和鏈接地址)
  • 2. 您是誰?(身份證明材料,可以是身份證或護照等證件)
  • 3. 是哪家企業?(營業執照,單位登記證明等證件)
  • 4. 您與該企業的關係是?(您是企業法人或被授權人,需提供企業委托授權書)
我們認為知名企業應該坦然接受公眾討論,對於答案中不準確的部分,我們歡迎您以正式或非正式身份在根叔知了上進行澄清。

抄襲了我的內容

×

原文鏈接或出處

誹謗我

×

您好,當您發現根叔知了上有誹謗您的內容時,您可以向根叔知了進行舉報。 請您把以下內容通過郵件發送到pub.zhiliao@h3c.com 郵箱,我們會盡快處理。
  • 1. 您舉報的內容以及侵犯了您什麼權益?(請在郵件中列出您舉報的內容、鏈接地址,並給出簡短的說明)
  • 2. 您是誰?(身份證明材料,可以是身份證或護照等證件)
我們認為知名企業應該坦然接受公眾討論,對於答案中不準確的部分,我們歡迎您以正式或非正式身份在根叔知了上進行澄清。

對根叔社區有害的內容

×

垃圾廣告信息
色情、暴力、血腥等違反法律法規的內容
政治敏感
不規範轉載 >
辱罵、歧視、挑釁等(不友善)
騷擾我
誘導投票

不規範轉載

×

舉報說明