4、SW2 和 SW3 之间的 HSRP 无法实现自动切换 + A$ M0 p/ S6 j5 a1 Q$ L
对 SW2 和 SW3 分别进行 show standby 和 show standby vlan 20 brief: 8 W; f! T2 j' w1 \) I3 K
Sw3#show standby
$ t: Y8 w0 ], ?Vlan10 - Group 1
b9 y; B) n, R* p2 ^- n8 IState is Active
+ p6 C P! j+ \( K1 A1 m; H2 state changes, last state change 00:33:02
6 g/ P& c" z; x* t8 aVirtual IP address is 172.16.10.254
# c9 m6 r) Z$ [ K' m y# RActive virtual MAC address is 0000.0c07.ac01 % n- T% U/ ~; q; [9 \. g7 b' J
Local virtual MAC address is 0000.0c07.ac01 (v1 default) Hello time 3 sec, hold time 10 sec
0 P& l$ J* M. ]' u4 t8 Z$ I' tNext hello sent in 2.820 secs
' c6 G2 y0 p# S( y! S+ GPreemption disabled & [7 Z. b9 a0 U; ^# K$ ]- |" M
Active router is local
/ h2 W- G& k5 YStandby router is 172.16.10.3, priority 100 (expires in 8.048 sec) Priority 105 (configured 105)
. s$ Q: R( G) T; p; j( K" e& XIP redundancy name is "hsrp-Vl10-1" (default) Vlan20 - Group 2 & ^/ ?6 X ~. z! ^- e4 _
State is Active 4 V) \- [7 A/ K! b9 O
2 state changes, last state change 00:34:19
2 U: y" M, L# w. y$ g; m9 KVirtual IP address is 172.16.20.254 / |; U, C) Z! A( {3 P: r3 @: p
Active virtual MAC address is 0000.0c07.ac02 x% s5 M! o, s* j- A
Local virtual MAC address is 0000.0c07.ac02 (v1 default) Hello time 3 sec, hold time 10 sec
- [4 v5 H+ a( m* u- ?7 l/ ^- h, X5 ~) lNext hello sent in 1.708 secs 4 K' X1 {( G, I: n" J5 W- q
Preemption disabled
2 V' f! M/ M) n( L4 w( aActive router is local
% ]: S7 c9 ~) L* P2 t- KStandby router is 172.16.20.3, priority 105 (expires in 7.536 sec) Priority 100 (default 100)
. _' E$ X5 b; q' V5 aIP redundancy name is "hsrp-Vl20-2" (default)
- K2 B% D9 b- u- B3 e! S9 [sw2#show standby vlan 20 br 0 i3 s* B$ g% i; l" f6 Q0 ? g: B
P indicates configured to preempt.
9 w `: g" C5 l1 n|
3 w2 }* K* {# H! l! ~8 n6 yInterface Grp Prio P State Active Standby Virtual IP
( I1 r$ V6 E. lVl20 2 100 Active local 172.16.20.3 172.16.20.254 2 f$ M) t( p8 u, n( u1 y/ D! C
sw3#show standby vlan 20 br 4 A& p! c7 c8 s; [
P indicates configured to preempt.
: J9 l9 T r; S|
/ A5 s- A1 V1 f1 J3 f$ ZInterface Grp Prio P State Active Standby Virtual IP 7 o4 `! h) x2 r
Vl20 2 105 Standby 172.16.20.2 local 172.16.20.254 4 h6 b2 P' J0 o9 q3 F6 ?
SW3 的 HSRP 优先级为 105,明显高于 SW2 的优先级 100,为什么却处于 standby 模式呢?通 过 show standby 可以发现,SW3 的抢占是关闭的,所以没有主动去争取 active 模式。
* o" h+ Y5 h7 v5 b解决方法:
1 c, ]# c3 M& f9 m& n9 b0 a( x在 SVI 接口中开启抢占。
: y# Z9 B: `% N9 ]sw3(config)#int vlan 10 3 d7 `3 O* A2 `; |/ o7 u, k
sw3(config-if)#standby 1 preempt
3 g$ s- b7 Y6 M7 c: Bsw3(config-if)#int vlan 20 8 d6 r3 c3 W3 I9 a- n! n
sw3(config-if)#standby 2 preempt + `) p; z. s' k' ?3 G( C
( K- @/ F- F6 p- Y6 w' U/ T5、R1 和 R2 无法从 DHCP 服务器获取地址 ; U) Q' r9 O0 U
通过 SW1 和 SW2 的 show vlan,我们发现 DHCP 服务器(R3)属于 VLAN30,而 R1 和 R2 分别 属于 VLAN10 和 VLAN20,三者分别属于不同的广播域内,因此 DHCP 发现报文无法到达 DHCP 服务器。
% U0 R( T! f% Q3 h2 i解决方法:
, n6 ?9 w" Q5 N9 S6 G在网关的 SVI 接口中配置 DHCP 中继。
0 o- K4 t) a0 H$ g) V+ {* p5 z+ esw2(config-if)#int vlan 10 + x4 t: x' V. E Y
sw2(config-if)#ip helper-address 172.16.30.3 sw2(config-if)#int vlan 20 ; E/ W: T$ i$ a
sw2(config-if)#ip helper-address 172.16.30.3
1 ], q+ d' o2 P1 A2 q. B配置完成后,R1 和 R2 获取了地址:
, o2 Q" t! b: c0 m) a* a* W*Mar 1 04:48:33.990: %DHCP-6-ADDRESS_ASSIGN: Interface FastEthernet0/0 assigned DHCP ; o% b% ?, u+ T5 M( E, F3 @
address 172.16.10.1, mask 255.255.255.0, hostname r1 a/ l+ d' ]( V
*Mar 1 00:56:24.915: %DHCP-6-ADDRESS_ASSIGN: Interface FastEthernet0/0 assigned DHCP
# \% w( h; X- w% ]) ~3 G! Daddress 172.16.20.1, mask 255.255.255.0, hostname r2 9 R' g! P- Y: U, J
7 T0 ]. B: j2 U3 j% I, R
6、R1 和 R2 无法访问 ISP R5 上的服务器 5.5.5.5
* w5 p7 b; _% k' r% D# z& J2 u2 y对网关 R4 进行 show run: 8 e: T# u+ D! }; f4 m) H# r3 Y
R4#show run router ospf 1
% H8 [8 ?0 k* V6 w4 E& |log-adjacency-changes b1 _( Y$ f; Z* M- ?
network 172.16.44.44 0.0.0.0 area 0 % ?* h, M& [5 }/ }* @
! $ o5 m/ l/ l) X; h" y
ip classless
+ h# R: L; l, _% a8 V1 rip route 0.0.0.0 0.0.0.0 FastEthernet0/1
! F- E1 _/ |! a6 O!
, E0 F7 {" J+ y2 v) Vaccess-list 1 permit 172.16.0.0 % M. x. n4 y4 V* \" h8 x8 n
R4 是通过一条默认路由将子网通告给 ISP 的,R1 和 R2 若想访问 ISP,则必须将这条默认路 由通告给内网,R4 的 OSPF 路由进程中缺少了默认路由的通告。另外访问控制列表缺少反掩 码,应该加上去。 ' _# A# [; T+ l: z
解决方法: ) a* Z7 Q4 i0 t' }( m
r4(config)#router ospf 1
( ~3 q3 q" p3 N) N, r, E, ?r4(config-router)#default-information originate r4(config)#no access-list 1 8 Y4 I8 o" V F4 T4 ~
r4(config)#access-list 1 permit 172.16.0.0 0.0.255.255
' R) H3 a- _& C5 C再进行 show ip rou: . G8 y) @% _ U. _# h5 f0 H& k3 M6 B
SW4#show ip rou 5 ^& l/ f0 l* X$ m3 p6 T$ v; {2 j. F
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
! x6 n% T' R2 S0 uD - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area # r( J9 t T, B
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 5 x9 N. `# C# g% ]( b' }6 ^
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP ) E j1 d9 B6 U" N4 Q
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route 7 B9 Y) t+ A: R9 m' l V
Gateway of last resort is 172.16.44.44 to network 0.0.0.0 ; `+ Q- h& U: K+ v. W
172.16.0.0/24 is subnetted, 6 subnets
0 ~ ^3 T- g- f, Q3 ]3 q) ]7 w3 N, [C 172.16.44.0 is directly connected, FastEthernet0/4
/ P: j+ o% h4 f. S" x2 V) WC 172.16.34.0 is directly connected, FastEthernet0/24 - G" }! E+ r/ f+ Z
O 172.16.30.0 [110/2] via 172.16.24.2, 00:05:07, FastEthernet0/20
- x& O. G2 q6 H( n; D! q' b2 IC 172.16.24.0 is directly connected, FastEthernet0/20 4 A) c9 n4 H/ {4 U
O 172.16.20.0 [110/2] via 172.16.34.3, 00:05:07, FastEthernet0/24 8 j% \1 S* T: h# {
[110/2] via 172.16.24.2, 00:05:07, FastEthernet0/20 0 k6 v& b, ]: O* d8 M' V
O 172.16.10.0 [110/2] via 172.16.34.3, 00:05:07, FastEthernet0/24 ) g0 ?3 T+ I; z. u: { i: _6 s5 j: O
[110/2] via 172.16.24.2, 00:05:08, FastEthernet0/20
- ~8 m/ T4 B" e. pO*E2 0.0.0.0/0 [110/1] via 172.16.44.44, 00:05:08, FastEthernet0/4 / `+ R. s4 h6 S
OSPF 默认路由已经通告进内网,使用 R1 和 R2 ping 5.5.5.5: 7 u6 Y, z0 v, i9 u1 A, j
r1#ping 5.5.5.5
# D" {$ _3 k, z s( E2 u8 XType escape sequence to abort.
- `1 S. H* F8 |: a: H' qSending 5, 100-byte ICMP Echos to 5.5.5.5, timeout is 2 seconds:
/ S3 Q+ G- u! f!!!!! 7 H, U" D, y* w% ~7 i9 u
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/4 ms 4 G- c1 \! O: ]; I$ y
R2#ping 5.5.5.5
) Y1 _4 `# ?: e. {, d/ V9 o; N( e2 xType escape sequence to abort.
f8 }7 a+ Z) L2 vSending 5, 100-byte ICMP Echos to 5.5.5.5, timeout is 2 seconds:
, o3 z& B" J& X$ m: X!!!!!
2 W+ l+ f/ e7 e; mSuccess rate is 100 percent (5/5), round-trip min/avg/max = 1/2/4 ms + h8 G D; F/ W9 m, O
/ K/ K0 N- _ \ y) V& u( [
7、网关 R4 上的 ARP 条目过多
6 R( d- @/ I. ]) e: P" S/ o1 M使用 R1 去 ping R5 上所有的环回口,然后再在 R4 上 show ip arp: 0 X, p* F# n; y# A) ?0 m7 ~4 O
r4#show ip arp 4 _" J6 w4 f- t
Protocol Address Age (min) Hardware Addr Type Interface
5 _% Q" n4 i; r. LInternet 6.6.6.6 1 0024.14dd.a908 ARPA FastEthernet0/1 ) N, C9 W' Y) R( o4 |; t! k6 O5 [
Internet 5.5.5.5 1 0024.14dd.a908 ARPA FastEthernet0/1
3 H) Q8 u# O' {2 V, ^6 j: lInternet 7.7.7.7 1 0024.14dd.a908 ARPA FastEthernet0/1
9 V$ M/ E6 m/ O; s- q7 PInternet 8.8.8.8 6 0024.14dd.a908 ARPA FastEthernet0/1
3 t* x! g# b2 r4 h6 d4 DInternet 45.45.45.5 0 0024.14dd.a908 ARPA FastEthernet0/1 / V1 A5 b, N' ?3 l
Internet 45.45.45.4 - 0024.14ec.6719 ARPA FastEthernet0/1 7 Y+ e9 \5 x+ g/ Y3 q
Internet 172.16.44.4 0 0012.8077.3200 ARPA FastEthernet0/0 * G. l/ N$ U1 u+ O
Internet 172.16.44.44 - 0024.14ec.6718 ARPA FastEthernet0/0 $ Z+ G% I: {( F Q3 F
ARP 表中的条目过多,原因是默认路由使用了以太网下一跳出口所致,由于没有指定的下一 跳,导致数据每次从接口出去时都要发送一次 ARP 报文,从而增加了 ARP 表中的 ARP 条目。
0 T B' m" g* l7 y解决方法: - n; }7 H0 b: ]( A7 y
将以太网一下跳出口改为下一跳地址
4 Y* c' `% _) J1 Fr4(config)#no ip route 0.0.0.0 0.0.0.0 FastEthernet0/1 ; T* h/ b% I7 }2 `# s' h8 W
r4(config)#ip route 0.0.0.0 0.0.0.0 45.45.45.5 : g/ h" g: N* ^2 z. v: I* ]6 R7 {! _6 W0 e
再次 show ip arp: 8 ~( E/ @0 T1 }) x* j
r4#show ip arp / m- N/ @$ g C- A7 D% T
Protocol Address Age (min) Hardware Addr Type Interface
+ S2 ?* N" \- ?: U) k8 n7 {Internet 45.45.45.5 0 0024.14dd.a908 ARPA FastEthernet0/1
, y$ g9 M7 w: ~, MInternet 45.45.45.4 - 0024.14ec.6719 ARPA FastEthernet0/1 8 Q A+ }3 ], j, P& t6 `8 \0 O* W2 H
Internet 172.16.44.4 0 0012.8077.3200 ARPA FastEthernet0/0
4 k* J% B% N4 b' e( e" oInternet 172.16.44.44 - 0024.14ec.6718 ARPA FastEthernet0/0 0 y- V* ~) r' {* s) j8 R) y
ARP 表中的条目即固定为以上几条。</p> |