6. E320日常检查

上传人:新** 文档编号:587519070 上传时间:2024-09-06 格式:PPT 页数:32 大小:521KB
返回 下载 相关 举报
6. E320日常检查_第1页
第1页 / 共32页
6. E320日常检查_第2页
第2页 / 共32页
6. E320日常检查_第3页
第3页 / 共32页
6. E320日常检查_第4页
第4页 / 共32页
6. E320日常检查_第5页
第5页 / 共32页
点击查看更多>>
资源描述

《6. E320日常检查》由会员分享,可在线阅读,更多相关《6. E320日常检查(32页珍藏版)》请在金锄头文库上搜索。

1、6. E320的日常检查的日常检查 E320系统日常检查系统日常检查做做show操作之前,先做操作之前,先做ter wi 139操作。操作。E320# ter wi 139 (列宽(列宽139)1、系统运行时间检查、系统运行时间检查 show version allE320#sh ver allJuniper Edge Routing Switch E320Copyright (c) 1999-2008 Juniper Networks, Inc. All rights reserved.System Release: e320_8-2-4p0-16.rel Version: 8.2.4 pa

2、tch-0.16 BuildId 11168 (July 2, 2009 11:58)Active Hotfixes: e320_8-2-4p0-16_hf650.hfx e320_8-2-4p0-16_hf651.hfx e320_8-2-4p0-16_hf733.hfxSystem running for: 91 days, 11 hours, 36 minutes, 49 seconds (since MON OCT 19 2009 10:53:54 UTC)slot state type admin spare running release slot uptime - - - - -

3、 - -0 online LM-10 enabled - e320_8-2-4p0-16.rel 33d16h:17m:39s0/0 present GE-8 IOA enabled - - 0/1 present GE-8 IOA enabled - - 1 online LM-10 enabled - e320_8-2-4p0-16.rel 91d11h:25m:51s 检查设备前后卡的板卡类型检查设备前后卡的板卡类型 检查各板卡正常运行时间,可以判断是否发生过重启检查各板卡正常运行时间,可以判断是否发生过重启 以以SRP时间为准查看时间为准查看 可以查看运行可以查看运行junose版本和

4、版本和hotfix类型。类型。 E320系统日常检查系统日常检查做做show操作之前,先做操作之前,先做ter wi 139操作。操作。E320# ter wi 139 (列宽(列宽139)2、系统硬件检查、系统硬件检查 show hardwareE320#sh hardwareChassis - serial assembly assembly Major/Minor type number number rev. rev - - - - -Chassis 4709129305 4580002400 A09 0.9 Modules - serial assembly assembly ram

5、 Major/Minorslot type number number rev. (MB) rev - - - - - - -0 LM-10 4709118287 4500009501 A10 1024 1.10 1 LM-10 4709085663 4500009501 A10 1024 1.10 2LM-4 4709118605 4500006306 A10 512 6.10。 E320系统日常检查系统日常检查做做show操作之前,先做操作之前,先做ter wi 139操作。操作。E320# ter wi 139 (列宽(列宽139)2、系统硬件检查、系统硬件检查 show hardwar

6、eE320#sh hardwareAdapters - number of serial assembly assembly MAC base Major/Minorslot type number number rev. addresses MAC address rev - - - - - - - -0/0 GE-8 IOA 4709063300 4500009103 A05 8 0090.1aa2.d013 3.5 0/1 GE-8 IOA 4709110175 4500009103 A05 8 0090.1aa2.d1e3 3.5 1/0 GE-8 IOA 4709063272 450

7、0009103 A05 8 0090.1aa2.d14b 3.5 1/1 GE-8 IOA 4709063276 4500009103 A05 8 0090.1aa2.d03b 3.5 2/0 OC3/STM1-8 ATM IOA 4708495867 4500006903 A04 3.4 2/1 OC3/STM1-8 ATM IOA 4708495863 4500006903 A04 3.4Fan(s) - serial assembly assembly Major/MinorTray type number number rev. rev - - - - - -0 Primary FAN

8、 4709139633 4580002500 A05 1.5 检查设备前后卡的板卡类型检查设备前后卡的板卡类型 检查各板卡序列号、物理端口检查各板卡序列号、物理端口mac地址等地址等 E320系统日常检查系统日常检查3、系统运行环境检查、系统运行环境检查show env allE320#show env all chassis: 17 slot (id 0x3, rev. 0x0) fabric: 320 Gbps (rev. 1) fans: fanSubsystemOk nvs: ok (977MB flash disk, 15% full), matches running config

9、 power: A ok, B ok srp redundancy: mode is high-availability, state active auto-sync enabled, switch-on-error enabled in sync slots: ok online: 0 1 4 6 standby: 7 empty: 2 3 5 11 12 13 14 15 16 fabric slots: ok online: 6 7 8 9 10 line redundancy: none temperature: ok timing: primary primary: interna

10、l SC oscillator (ok) secondary: internal SC oscillator (ok) tertiary: internal SC oscillator (ok) auto-upgrade enabled fabric redundancy: ok system operational: yes temperature temperatureslot type (10C - 56C) status - - - -0 LM-10 48 normal 0/0 GE-8 IOA 35 normal 0/1 GE-8 IOA 31 normal 1 LM-10 48 n

11、ormal 1/0 GE-8 IOA 32 normal 1/1 GE-8 IOA 30 normal 4 LM-4 30 normal 4/0 OC3/STM1-8 ATM IOA 44 normal 4/1 OC3/STM1-8 ATM IOA 37 normal 6 SRP-320 41 normal 6 SFM-320 40 normal 6/0 SRP IOA 30 normal 7 SRP-320 40 normal 7 SFM-320 39 normal 8 SFM-320 28 normal 9 SFM-320 29 normal 10SFM-320 29 normal fab

12、ric temperature ranges below -5C is too cold above 79C is too hot low temperature warning below 10C high temperature warning above 56Cprocessor temperature ranges below -5C is too cold above 79C is too hot low temperature warning below 10C high temperature warning above 51CIOA temperature ranges bel

13、ow -5C is too cold above 79C is too hot low temperature warning below 10C high temperature warning above 56C 风扇运行状态风扇运行状态 NVS空间使用情况空间使用情况 HA功能已经打开功能已经打开 查看板卡温度是否在正常范围内查看板卡温度是否在正常范围内 E320系统日常检查系统日常检查4、CPU和内存利用率检查和内存利用率检查show uti deE320#sh uti detail Please wait. System Resource Utilization - 5 1 5 la

14、st sec min min heap available cpu cpu cpuslot type (%) cpu (%) (%) (%) (%)- - - - - - -0 LM-10 44 10 10 11 12 1 LM-10 44 7 7 5 6 2 - - - - - -3 - - - - - -4 LM-4 35 9 9 8 8 5 - - - - - -6 SRP-320 16 23 23 23 23 7 SRP-320 9 4 4 4 6 8 SFM-320 - - - - -9 SFM-320 - - - - -10 SFM-320 - - - - -11 - - - -

15、- -12 - - - - - -13 - - - - - -14 - - - - - -15 - - - - - -16 - - - - - - Note: - indicates empty slots or fabric slices. Heap为板卡内存利用率,该内存利用率接近为板卡内存利用率,该内存利用率接近80%时需要特别关注,可能是板卡配置量大,最大可能性时需要特别关注,可能是板卡配置量大,最大可能性是由于内存溢出造成,请通知我们做检查判断。是由于内存溢出造成,请通知我们做检查判断。主要注意主要注意5m内内cpu利用率是否高,多利用率是否高,多show几次,发几次,发现该值一直持

16、续高于现该值一直持续高于70%,清通知我们做相关检查。,清通知我们做相关检查。ttl、arp、异常流量、异常流量、null0没配置、路由协议等都没配置、路由协议等都可能导致可能导致srp、业务板卡、业务板卡cpu利用率达到利用率达到100%。E320系统日常检查系统日常检查5、pppoe用户在线数检查用户在线数检查show subscribers sum | show subscribers sum portE320#sh subscribers sum Virtual Router Subscribers Ppp Ip Tnl Total - - - - - -default 11490 1

17、1490 0 339 11829 campus-pre 1220 1220 0 0 1220 djiptv 5 5 0 0 5 WLAN 45 0 45 0 45 MPLS-VPN:gxi 4 4 0 0 4 ptv Total Subscribers : 13103 (chassis-wide total)Peak Subscribers : 16410 (chassis-wide total)E320#sh subscribers summary port Interface Count - -0/0/4 1221 0/0/5 2304 0/0/6 3551 1/0/5 984 1/0/6

18、 2720 1/0/7 4 4/0/0 19 4/0/1 446 4/0/2 7 4/0/3 124 4/0/4 4 4/0/5 596 4/1/0 125 4/1/1 472 4/1/2 197 4/1/3 156 4/1/5 78 4/1/6 15 Total Subscribers : 13068 (chassis-wide total)Peak Subscribers : 16410 (chassis-wide total) ppp代表代表pppoe拨号类型用户拨号类型用户 ip代表代表ip子接口业务用户,子接口业务用户,DHCP方式等。方式等。 Tnl代表代表l2tp用户用户 Tot

19、al Subscribers 目前在线用户总数目前在线用户总数 Peak Subscribers 代表历史最高值。代表历史最高值。 各物理端口所接业务总数各物理端口所接业务总数E320系统日常检查系统日常检查6、检查、检查VR的配置情况的配置情况show virtual-routerE320#sh virVirtual Router : defaultVirtual Router : campus-preVirtual Router : MPLS-VPN VRF : GXNN-ITMS-MGMT VRF : CT_softswitch_yw VRF : CTVPN52476-GX_LAODON

20、GTING VRF : GXNN-WLAN-AP-MGMT VRF : CTVPN53031-GX_LIQUAN VRF : gxiptvVirtual Router : djiptvVirtual Router : WLANVirtual Router : static-user 进入不同进入不同VR时,在时,在#和配置模式下都能直接用和配置模式下都能直接用vir vir-name进入。比如进入。比如vir campus-pre 进入不同的进入不同的VRF,在,在#和配置模式下都能直接用和配置模式下都能直接用vir vir-name:vrf-name 进入。比如进入。比如vir MPLS-V

21、PN:GXNN-ITMS-MGMT以下大多数检查均是基于以下大多数检查均是基于VR虚拟路由器虚拟路由器7、检查、检查PPPoE许可证的配置情况许可证的配置情况show license b-rasE320#sh license b-ras b-ras license is 1r1Knae9k7 for 32000 users E320系统日常检查系统日常检查8、路由信息检查、路由信息检查show ip router summaryE320#sh ip route summary Unicast Routes: 15121 total routes, 1088712 bytes in route

22、entries0 isis routes0 rip routes53 static routes12 connected routes0 bgp routes3863 ospf routes, 44 intra-area, 40 inter-area, 3779 external31 other internal routes0 access routes11162 internally created access host routesLast route added/deleted: 222.218.88.18/32 by AccessInternalAt MON JAN 18 2010

23、 23:20:12 UTC 主要查看单播路由具体情况主要查看单播路由具体情况 11162为为pppoe用户的路由用户的路由 static为专线路由为专线路由 应用应用ospf协议发布路由协议发布路由 E320系统日常检查系统日常检查9、Ip地址池检查地址池检查show ip local poolE320#sh ip local pool High Abated Pool Thresh Thresh Trap- - - -PPPOE-1 85 75 N In Begin End Free Use - - - - 118.116.96.1 118.116.103.254 1 2045 use代表正

24、在使用的地址代表正在使用的地址 free代表地址池中剩余的地址代表地址池中剩余的地址10、系统资源检查、系统资源检查show resource (不是基于(不是基于VR) E320#sh resource Resource Threshold Trap: enabled max current rising type location capacity value threshold- - - - -ip interface system 96001 14309 86401ip interface slot 0 16383 7467 14745ip interface slot 1 16383

25、 4054 14745ip interface slot 4 16383 2787 14745atm-sub-if interface system 98304 4758 88474atm-sub-if interface slot 4 16000 4758 14400atm-vc interface system 98304 4744 88474 E320系统日常检查系统日常检查atm-vc interface slot 4 16000 4744 14400ppp-link interface system 96000 13946 86400ppp-link interface slot 0

26、 16000 7377 14400ppp-link interface slot 1 16000 4049 14400ppp-link interface slot 4 16000 2520 14400atm-active-sub-if interface system 98304 2836 88474atm-active-sub-if interface slot 4 16000 2836 14400 falling hold-down type location threshold time - - - -ip interface system 960 300ip interface sl

27、ot 0 164 300ip interface slot 1 164 300ip interface slot 4 164 300atm-sub-if interface system 983 300atm-sub-if interface slot 4 160 300atm-vc interface system 983 300atm-vc interface slot 4 160 300ppp-link interface system 960 300ppp-link interface slot 0 160 300ppp-link interface slot 1 160 300ppp

28、-link interface slot 4 160 300atm-active-sub-if interface system 983 300atm-active-sub-if interface slot 4 160 300 E320-320G和和100G整框可同时在线整框可同时在线pppoe用户用户96k-理论值理论值 LM4、LM10线卡支持线卡支持16K 注意单线卡最高用户数,配置量不要超过注意单线卡最高用户数,配置量不要超过16KE320系统日常检查系统日常检查11、GE端口检查端口检查show interface g x/y.zE320#sh int g1/1/0GigabitE

29、thernet1/1/0 is Up, Administrative status is Up Hardware is Intel IXF1110, address is 0090.1aa2.d2e3 MAU is 1000BASE-SX MTU: Operational 1522, Administrative 1522 Duplex Mode: Operational Full Duplex, Administrative Full Duplex Speed: Operational 1000 Mbps, Administrative 1000 Mbps 5 minute input ra

30、te 545634304 bits/sec, 103927 packets/sec 5 minute output rate 355124224 bits/sec, 89304 packets/sec In: Bytes 261889974371434, Unicast 387536577297 Multicast 20166309, Broadcast 501755 Errors 0, Discards 0, Mac Errors 0, Alignment 0 CRC 0, Too Longs 0, Symbol Errors 0 Out: Bytes 176782647751471, Un

31、icast 380086382926 Multicast 21915610, Broadcast 56 Errors 0, Discards 0, Mac Errors 0, Deferred 0, No Carrier 0 Collisions: Single 0, Multiple 0, Late 0, Excessive 0Policed Statistics: In: 0, Out: 0ARP Statistics: In: ARP requests 0, ARP responses 0 Errors 0, Discards 0 Out: ARP requests 0, ARP res

32、ponses 0 Errors 0, Discards 0 可以看到端口可以看到端口mac地址,地址,spf的类型,端口的类型,端口MTU值,端口容值,端口容量。量。 GE-4 IOA和和GE-8 IOA支持的支持的SPF有有SX、LX、LX40、ZX四种。四种。 SX:850M;传:;传:9.5 dBm 到到-4dBm;收:;收:-20dbm到到0dbm LX:10KM;传:;传:-9.5dbm到到-3dbm;收:;收:-20dbm到到-3dbm;1510 LX40:40KM;传:;传:-4.5dbm到到-0dbm;收:;收:-35dbm到到-22.5dbm;1510ZX:70KM;传:传:

33、传:传:-2dbm到到3dbm;收:;收:-22dbm到到-3dbm;1550discard报文:到本地的报文,包括报文:到本地的报文,包括ftp、ping、snmp等等 CRC和和symbol为物理链路诊断报文,这二项不断增多表明为物理链路诊断报文,这二项不断增多表明物理链路出现问题,物理链路出现问题,symbol更能说明问题,更接近低层。更能说明问题,更接近低层。 arp请求情况可以观察收发。请求情况可以观察收发。E320系统日常检查系统日常检查12、检查检查junose防止攻击功能的统计防止攻击功能的统计 sh suspicious-control-flow-detection info

34、 E320#sh suspicious-control-flow-detection info Protocol Information Protocol State Transitions- - - -Ppp Echo Request OK 0Ppp Echo Reply OK 0Ppp Echo Reply Fastpath OK 0Ppp Control OK 0Atm Control (ILMI) OK 0Atm OAM OK 0Atm Dynamic Interface Column Creation OK 0Atm Inverse ARP OK 0Frame Relay Contr

35、ol (LMI) OK 0Frame Relay Inverse Arp OK 0Pppoe Control OK 0Pppoe Ppp Config Dynamic Interface Column Crea OK 0tion Ethernet ARP Miss OK 0Ethernet ARP OK 0Ethernet FC based ARP OK 0Ethernet LACP packet OK 0Ethernet Dynamic Interface Column Creation OK 0IpLocalL2tpCtrlIc OK 0Slep SLARP Reply Fastpath

36、OK 0Mpls TTL Exceeded On Receive OK 0Mpls TTL Exceeded On Transmit OK 0Mpls MTU Exceeded OK 0Ipsec Transport Mode L2tp Control OK 0NAT/Firewall Payload OK 0IP TTL Expired OK 2940 分为分为layer2和和layer3报文。报文。 红色标出的为红色标出的为layer2层报文层报文 黑字标出为黑字标出为layer3层报文层报文 当当SRP、线卡、线卡cpu利用率很高,可以辅助进行诊利用率很高,可以辅助进行诊断。断。 E32

37、0系统日常检查系统日常检查13、检查整机检查整机ip流量情况流量情况 sh suspicious-control-flow-detection info E320#baseline ipE320#baseline ip tcpE320#baseline ip udpE320#show ip traffic deIP statistics: Router Id: 118.114.236.4 Rcvd: 688037086498 total, 30921091 local destination 0 hdr errors, 0 addr errors 2064 unkn proto, 0 disc

38、ards 不正常报文被端口直接不正常报文被端口直接discard 6767802 multicast Sent: 628091209021 forwarded, 32718115 generated, 0 out disc 590933 no routes,0 routing discards 存在存在icmp不可达,有源地址攻击。不可达,有源地址攻击。 0 multicast forwarded Local Frags: 0 reassembled, 0 reasm req 0 reasm fails, 0 frag ok, 7234534 frag fail 0 frag creates

39、Route: 38015 routes in tableICMP statistics: Rcvd: 258262202 total, 23811 errors, 4671 dst unreach 144 time exceed, 1 param probs, 0 src quench 352 redirects, 258227689 echo req, 5428 echo rpy 0 timestamp req, 0 timestamp rpy 0 addr mask req, 0 addr mask rpySent: 385196324 total, 0 errors, 7821743 d

40、est unreach 119145785 time excd, 0 param prob, 0 src quench 存在存在TTL=1攻击攻击 0 redirects, 5511 echo req, 258227689 echo rpy 0 timestamp req, 0 timestamp rpy 0 addr mask req, 0 addr mask rpy 2064 unkn 持续增长,同时线卡持续增长,同时线卡cpu达达到到100%,很有可能是板卡没插好,前后,很有可能是板卡没插好,前后连接不紧密。连接不紧密。 E320系统日常检查系统日常检查UDP Statistics: R

41、cvd: 24107054 total, 0 checksum errors, 19135 no port Sent: 24204950 total, 0 errorsTCP Global Statistics: Connections: 39 attempted, 185 accepted, 187 established 0 dropped, 221 closed, 3 currently established Rcvd: 2623130 total pkts, 2287145 in-sequence pkts, 127994166 bytes 0 chksum err pkts, 0

42、authentication err pkts, 0 bad offset pkts 0 short pkts, 186 duplicate pkts, 184 out of order pkts Sent: 2620019 total pkts, 348571 data pkts, 11974937 bytes 18 retransmitted pkts, 1353 retransmitted bytes E320系统日常检查系统日常检查14、所定义策略应用检查、所定义策略应用检查sh policy-list brief E320# sh policy-list brief Policy T

43、able - -IP User_Local_Input enable 0 referencesIP pro512K enable 5881 referencesIP pro4M enable 73 referencesIP static-pro1M enable 0 referencesIP pro2M enable 2292 referencesIP pro1M enable 8737 referencesIP pro3M enable 24 referencesIP pro5M enable 5 referencesIP pro6M enable 3 referencesIP pro7M

44、enable 0 referencesIP pro8M enable 11 referencesIP pro9M enable 0 referencesIP pro10M enable 43 referencesIP pro1536K enable 0 referencesIP pro256k enable 0 referencesIP pro128k enable 0 referencesIP pro256K enable 0 referencesIP static-pro2M enable 0 referencesIP ADSL_E8_1M_ingress enable 1789 refe

45、rencesIP ADSL_E8_1M_egress enable 1789 referencesIP ADSL_E8_2M_ingress enable 1002 referencesIP ADSL_E8_2M_egress enable 1002 referencesIP ADSL_E8_3M_ingress enable 0 referencesIP ADSL_E8_3M_egress enable 0 referencesIP ADSL_E8_4M_ingress enable 80 referencesIP ADSL_E8_4M_egress enable 80 references

46、IP ADSL_512K_ingress enable 0 references 显示包括限速策略、安全策略的定义和使用情况显示包括限速策略、安全策略的定义和使用情况 8737 references表明目前被调用表明目前被调用8737个,包括了个,包括了input和和output方向方向 要查看策略详细定义情况,用要查看策略详细定义情况,用show policy-list XXX来查看来查看 E320系统日常检查系统日常检查15、策略定义查看步骤、策略定义查看步骤sh policy-list XXX 和和show classifier-list xxxE320#sh policy-list U

47、ser_Local_Input Policy Table - -IP Policy User_Local_Input Administrative state: enable Reference count: 0 Classifier control list: isLocal_ICMP, precedence 100 forward Classifier control list: isLocal_Other, precedence 100 filterE320#sh classifier-list isLocal_ICMP Classifier Control List Table - -

48、 - -IP isLocal_ICMP.2 local true icmp any any precedence代表优先级别,可设代表优先级别,可设 forward代表转发代表转发 filter代表过滤掉代表过滤掉 local表示本地流量表示本地流量 icmp定义了流量类型定义了流量类型 E320系统日常检查系统日常检查15、策略定义查看步骤、策略定义查看步骤sh policy-list XXX 和和show rate-limit-profile xxxshow policy-list pro1M Policy Table - -IP Policy pro1M Administrative s

49、tate: enable Reference count: 6258 Classifier control list: isVirus, precedence 50 filter Classifier control list: multicast, precedence 80 filter Classifier control list: broadcast, precedence 90 filter Classifier control list: *, precedence 100 rate-limit-profile pro1M Referenced by interface(s):

50、ATM2/0/3.1238.1 output policy, statistics disabled, virtual-router default lag lag01.18020504.1 output policy, statistics disabled, virtual-router default precedence代表优先级别,可设代表优先级别,可设 forward代表转发代表转发 filter代表过滤掉代表过滤掉 E320系统日常检查系统日常检查15、策略定义查看步骤、策略定义查看步骤sh policy-list XXX 和和show rate-limit-profile xx

51、xE320# sh rate-limit-profile pro1M Rate Limit Profile Table - - - -IP Rate-Limit-Profile: pro1M Profile Type: two-rate Reference count: 2 Committed rate: 1152000 (1024000 * 1.125,区公司,区公司/集团规定集团规定112.5%的超卖的超卖) Committed burst: 144000 Peak rate: 1267200 Peak burst: 16384 Mask: 255 Committed rate actio

52、n: transmit Conformed rate action: transmit Exceeded rate action: drop E320系统日常检查系统日常检查16、检查系统时钟、检查系统时钟show clock detail (不是基于(不是基于VR)E320#show clock detail WED JAN 20 2010 23:42:44 UTCtime source: manually entered by usertimezone: UTC (0 minutes from UTC) 检查时钟是否正确检查时钟是否正确 NTP和人工设置二种和人工设置二种17、系统时钟设置

53、、系统时钟设置clock set 23:49:30 jan 20 2010 (不是基于(不是基于VR) E320#clock set 23:49:30 jan 20 2010 18、检查、检查log系统配置情况系统配置情况show log conf E320#sh log configuration log destination console severity WARNING log destination nv-file severity CRITICAL log destination syslog 61.188.5.120 facility 7 severity DEBUG log

54、destination syslog 61.188.5.120 source loopback 0 log destination syslog 202.103.194.99 facility 3 severity ERROR log destination syslog 202.103.194.99 source loopback 0 no log engineering log fields timestamp instance no-calling-task no log hereWarning: Logging to this terminal is disabled no log s

55、everity console为为con口显示口显示log配置信息类型,为告警。配置信息类型,为告警。 NV-file为为nvs系统记录的系统记录的log信息类型,信息类型,nvs为为junose活动部分存放空间,硬件错误信息会记录到里面。活动部分存放空间,硬件错误信息会记录到里面。 可以配置带外可以配置带外log服务器,建议各地设置一个带外网管服务器,建议各地设置一个带外网管服务器。服务器。 E320系统日常检查系统日常检查 category severity verbosity filters notes- - - - -aaaAtm1483Cfg ERROR low aaaEngineG

56、eneral ERROR low aaaQosCfg ERROR low aaaServerGeneral ERROR low aaaUserAccess ERROR low addressServerGeneral ERROR low ar1AaaServerGeneral ERROR low atm ERROR low atm1483 ERROR low category severity verbosity filters notes- - - - -atm1483VcClass ERROR low atmAal5 ERROR low atmVcClass ERROR low audit

57、Ipsec ERROR low bfdAdaptivity ERROR low bfdEvents ERROR low bfdGeneral ERROR low 路由协议、路由协议、pppoe、radius等具体等具体log信息级别默认信息级别默认定义为定义为ERROR 排错时,针对具体信息开排错时,针对具体信息开debug。19、如何开启、查看和关闭、如何开启、查看和关闭debug信息?信息?E320#conf tE320(config)#log severity debug aaaUserAccess E320#baseline log E320#show log data categor

58、y aaaUserAccess severity 7 delta E320(config)#no log severity debug aaaUserAccess 备注:备注:debug信息占用大量信息占用大量srp资源和资源和log存放空间,检查完毕后需要关闭。存放空间,检查完毕后需要关闭。 E320系统日常检查系统日常检查20、检查、检查NVS信息信息show log data nv-fileE320#sh log data nv-file CRITICAL 09/08/2009 19:19:58 system: fan subsystem failure (critical)CRITIC

59、AL 08/19/2009 11:47:57 system (slot 5):(hwImageLoad.0.tRootTask.critical.11) Test Failure, #0, Ioa0 GE20-HDE FPGAloader CRITICAL 09/08/2009 21:14:21 system (slot 6): temp sensor near maximum limit (was normal)CRITICAL 09/08/2009 21:14:42 system (slot 6): temp sensor near maximum limit (was normal)CR

60、ITICAL 09/08/2009 21:15:07 system (slot 6): temp sensor near maximum limit (was normal)CRITICAL 09/08/2009 21:15:28 system (slot 6): temp sensor near maximum limit (was normal)CRITICAL 09/08/2009 21:16:08 system (slot 6): temp sensor near maximum limit (was normal)CRITICAL 09/08/2009 21:16:34 system

61、 (slot 6): temp sensor near maximum limit (was normal)该命令主要检查该命令主要检查NVS中的信息,中的信息,NVS存储存储junose的活动部分、存储故障信息、的活动部分、存储故障信息、SRP同步时的交换空间同步时的交换空间 CRITCAL级别为级别为2,多为硬件、系统故障。,多为硬件、系统故障。 fan subsystem failure ,该信息在插拔、安装风扇时可能出现,如果信息条数比较多并且,该信息在插拔、安装风扇时可能出现,如果信息条数比较多并且show env中看到风扇报警,以及风扇面板灯亮红灯中看到风扇报警,以及风扇面板灯亮红

62、灯则表示风扇有故障,需要更换。则表示风扇有故障,需要更换。Test Failure, #0, Ioa0 GE20-HDE FPGA loader,更换过前卡时保留下的信息,不表示该槽位有问题。,更换过前卡时保留下的信息,不表示该槽位有问题。 sensor为板卡探测器,接近报警级别,但为为板卡探测器,接近报警级别,但为normal。 查看时,请注意时间和信息条数查看时,请注意时间和信息条数 E320系统日常检查系统日常检查21、槽位的包转发检查、槽位的包转发检查show fabric-queue detailE320#sh fabric-queue detail traffic egress f

63、orwarded dropped class slot type packets forwarded bytes packets dropped bytes- - - - - - -best-effort 0 committed 1793792647603 986029793487006 0 0best-effort 0 conformed 0 0 2120199256 2020752584058best-effort 0 exceeded 0 0 0 0 best-effort 1 committed 1419042305630 739688693982989 0 0best-effort

64、1 conformed 0 0 5310178263 4741066843324best-effort 1 exceeded 0 0 0 0best-effort 4 committed 93553465327 59795765859225 4 757944722331best-effort 4 conformed 2657396 2229007211 0 17533744best-effort 4 exceeded 0 0 0 0 主要查看各业务槽位包转发情况。主要查看各业务槽位包转发情况。 best-effort为为qos默认配置下优先流量。默认配置下优先流量。 该命令需要多该命令需要多s

65、how 几遍,然后观察几遍,然后观察dropped packets和和droped bytes项目中数量是否增长,正常情况下数量可能增加或减少,数量变换不大;项目中数量是否增长,正常情况下数量可能增加或减少,数量变换不大;如果持续增加,表明有不正常如果持续增加,表明有不正常drop报文情况存在。报文情况存在。 发现某槽位用户用掉包情况时,需要检查该命令。发现某槽位用户用掉包情况时,需要检查该命令。 E320系统日常检查系统日常检查22、L2TP用户检查用户检查show l2tp tunnle 、show l2tp tunnle detailE320#sh l2tp tunnel L2TP tu

66、nnel 23/default is Up with 49 active sessionsL2TP tunnel 458/222.216.27.2 is Up with 64 active sessionsL2TP tunnel 19/default is Up with 14 active sessionsL2TP tunnel 25/222.216.27.1 is Up with 76 active sessionsL2TP tunnel 886/default is Up with 42 active sessionsL2TP tunnel 946/default is Up with

67、16 active sessionsL2TP tunnel 1269/adsl is Up with 39 active sessionsL2TP tunnel 1279/default is Up with 5 active sessionsL2TP tunnel 1280/default is Up with 13 active sessionsL2TP tunnel 1281/default is Up with 1 active sessionL2TP tunnel 1282/szyy is Up with 2 active sessionsL2TP tunnel 1283/defau

68、lt is Up with 2 active sessionsL2TP tunnel 1285/default is Up with 1 active sessionL2TP tunnel 1284/default is Up with 1 active session14 L2TP tunnels found 23/default为为tunnel的名称的名称 64 active sessions为为tunnel下目前在线的下目前在线的l2tp用户数用户数 14表示目前整机有表示目前整机有14个个tunnel用用show l2tp tunnel detail可以看到更详细的信可以看到更详细的信

69、息息E320#sh l2tp tunnel detail L2TP tunnel 23/default is Up with 48 active sessionsConfiguration Administrative state is enabled SNMP traps are disabled No peer host name is configured Local host name is gahl No local address is configured Failover resync is not configuredTunnel address 23/default的详细显

70、示的详细显示 E320系统日常检查系统日常检查Transport ipUdp Virtual router default Local address 218.65.148.30, peer address 218.65.219.149 Local UDP port 1701, peer UDP port 1701Tunnel status Effective administrative state is enabled State is established Failover resync is silent failover Local tunnel id is 821, peer t

71、unnel id is 36498 Host profile is noneSub-interfaces total active failed Sessions 18140 48 613 Switched-sessions 0 0 0 Statistics packets octets discards errors Control rx 23778 2876540 1366 0 Control tx 173145 9982831 0 0 Data rx 47493313 2721156851 2 0 Data tx 91976120 6059045629 9 0 Control chann

72、el statistics Receive window size = 64 Receive ZLB = 144873 Receive out-of-sequence = 104 Receive out-of-window = 1210 Transmit window size = 1400 Transmit ZLB = 7044 Transmit queue depth = 0 Retransmissions = 3432Tunnel operational configuration Peer host name is cisco Peer vendor name is Cisco Sys

73、tems, Inc. Peer protocol version is 1.0 Peer firmware revision is 0x1120 可以查看到对端可以查看到对端LNS的的ip地址地址 通信端口号是通信端口号是1701 可以查看到控制、数据报文的传递情况可以查看到控制、数据报文的传递情况 LNS系统是系统是cisco设备。设备。 E320系统日常检查系统日常检查23、检查、检查dhcp binding情况情况show dhcp binding detailE320#sh dhcp binding local detail BindingId HwAddress IpSubnet I

74、pAddress Type State Server Giaddr Lease Remaining- - - - - - - - - -2415888185 0026.5e53.1127 0.0.0.0 113.14.64.8 local bound 113.14.64.1 0.0.0.0 120 97 2415888230 0021.000d.b88c 0.0.0.0 113.14.64.170 local bound 113.14.64.1 0.0.0.0 120 112 2415888292 0016.6fbd.8538 0.0.0.0 113.14.64.15 local bound

75、113.14.64.1 0.0.0.0 120 76 2415888302 0092.c380.bb8d 0.0.0.0 113.14.64.190 local bound 113.14.64.1 0.0.0.0 120 88 2415888303 0016.e361.8fa8 0.0.0.0 113.14.64.191 local bound 113.14.64.1 0.0.0.0 120 113 2415888305 0026.c646.ae8a 0.0.0.0 113.14.64.193 local bound 113.14.64.1 0.0.0.0 120 82 2415888315

76、0026.5e5d.8339 0.0.0.0 113.14.64.133 local bound 113.14.64.1 0.0.0.0 120 70 2415888510 001f.3cd0.a740 0.0.0.0 113.14.64.33 local bound 113.14.64.1 0.0.0.0 120 110 2415888511 0024.2305.2a8f 0.0.0.0 113.14.64.246 local bound 113.14.64.1 0.0.0.0 120 91 2415888553 0022.430c.6e08 0.0.0.0 113.14.64.12 loc

77、al bound 113.14.64.1 0.0.0.0 120 103 2415888572 0025.d327.a3f3 0.0.0.0 113.14.64.249 local bound 113.14.64.1 0.0.0.0 120 109 2415888574 0025.d381.e959 0.0.0.0 113.14.64.232 local bound 113.14.64.1 0.0.0.0 120 110 2415888681 001e.65b6.bf60 0.0.0.0 113.14.64.59 local bound 113.14.64.1 0.0.0.0 120 109

78、lease可以进行设置可以进行设置 remaining为动态计数器,归零时向客户端发一次为动态计数器,归零时向客户端发一次arp询问。询问。 E320系统日常检查系统日常检查24、检查、检查DHCP local状态状态show ip dhcp-local statisticsE320#sh ip dhcp-local statistics DHCP Local Server Statistics - Item Count - -memUsage 133644bindings 111-Receive Statistics- discover 65726 request(accept) 58066

79、 request(renew) 230788 request(rebind) 3822 request(other) 2805 decline 25 release 16 inform 89883 total in packet 451131 in error 159 in discard 13 unknown client packet 54987-Transmit Statistics- offer 65713 ack(accept) 94850 ack(renew) 230687 ack(rebind) 3764 nak 544 nak(renew) 101 nak(rebind) 58

80、 total out packet 395717 out error 0 out discard 0 discover和和offer是一对值,是一对值,dis是用户端发出请求报文,是用户端发出请求报文,offer是是BAS提供提供ip地址给用户地址给用户request有几种类型,有几种类型,accept是租约完成后收到,是租约完成后收到,renew是客户端租是客户端租用更新信息,用更新信息,rebind是收到用户重新绑定请求。是收到用户重新绑定请求。 ack是是bas回应用户报文,回应用户报文,ack与与request一直对不同请求做回应。一直对不同请求做回应。Nak是用户收到是用户收到bas

81、的的nak信息时,重新租赁、重新绑定新的信息时,重新租赁、重新绑定新的ip地址地址报文,用户端初始化,再进行报文,用户端初始化,再进行dhcp请求。请求。 E320系统日常检查系统日常检查25、检查、检查Radius server配置状态配置状态show radius servers E320#sh radius servers RADIUS Authentication Configuration - Udp Retry Maximum Dead IP Address Port Count Timeout Sessions Time Secret - - - - - - -202.103.1

82、94.201 1812 3 3 2000 10 troytroy202.103.194.205 1812 3 3 2000 10 troytroy RADIUS Accounting Configuration - Udp Retry Maximum Dead IP Address Port Count Timeout Sessions Time Secret - - - - - - -202.103.194.201 1813 3 3 2000 10 troytroy202.103.194.205 1813 3 3 2000 10 troytroy server ip key udp port

83、 retry count, timeout, dead time E320系统日常检查系统日常检查26、检查、检查Radius server统计统计show radius statisticsE320# baseline radiusE320# sh radius statistics delta RADIUS Authentication Statistics - Statistic 202.103.194.201 202.103.194.205- - -UDP Port 1812 1812 Round Trip Time 0 0 Access Requests 821 0 Rollover

84、 Requests 0 0 Retransmissions 0 0 Access Accepts 47 0 Access Rejects 774 0 Access Challenges 0 0 Malformed Responses 0 0 Bad Authenticators 0 0 Requests Pending 0 0 Request Timeouts 0 0 Unknown Responses 0 0 Packets Dropped 0 0 Statistics baseline set TUE JAN 26 2010 14:55:54 UTC E320系统日常检查系统日常检查26、

85、检查、检查Radius server统计统计show radius statistics RADIUS Accounting Statistics - Statistic 202.103.194.201 202.103.194.205- - -UDP Port 1813 1813 Round Trip Time 0 0 Requests 385 0 Start Requests 44 0 Interim Requests 275 0 Stop Requests 66 0 Reject Requests 0 0 Rollover Requests 0 0 Retransmissions 0 0

86、Responses 385 0 Start Responses 44 0 Interim Responses 275 0 Stop Responses 66 0 Reject Responses 0 0 Malformed Responses 0 0 Bad Authenticators 0 0 Requests Pending 0 0 Request Timeouts 0 0 Unknown Responses 0 0 Packets Dropped 0 0 Statistics baseline set TUE JAN 26 2010 14:55:54 UTC E320系统日常检查系统日常

87、检查27、检查当前是否由、检查当前是否由Radius进行认证及计费进行认证及计费show aaa authentication ppp default show aaa accounting ppp default E320# sh aaa authentication ppp default RadiusE320# sh aaa accounting ppp default Radius若需临时关闭认证,可将其上若需临时关闭认证,可将其上2个配置设置为个配置设置为“None”28、检查当前、检查当前Radius在线计费报文发送间隔时间在线计费报文发送间隔时间show aaa accounting interval E320# sh aaa accounting interval user-acct-interval 45service-acct-interval 45E320系统日常检查系统日常检查 有什么有什么

展开阅读全文
相关资源
正为您匹配相似的精品文档
相关搜索

最新文档


当前位置:首页 > 建筑/环境 > 施工组织

电脑版 |金锄头文库版权所有
经营许可证:蜀ICP备13022795号 | 川公网安备 51140202000112号