分类: 系统运维
2012-10-09 13:15:58
环境是这样的
internet
|
FW
/ \
6503---5624P
\ /
3928TP(5台)
6503上有III代 引擎+20口1G电口
分成5个vlan,各设备用6503与5624P之间起VRRP+OSPF,全网起stp!
现在用接在3928TP里的PC,ping 6503上的三层口,返回来的ping 包time很不稳定,在2MS到5MS之间有个别到23MS,总之非常不移定!请问各位大大们,是什么样的原因造成的?
配置如下:
[Quidway S6503]dis cur
#
sysname Quidway S6503
#
super password level 3 cipher IQKC8>5Z'M_Q=^Q`MAF4<1!!
#
local-server nas-ip 127.0.0.1 key huawei
#
domain default enable system
#
temperature-limit 0 10 70
temperature-limit 1 10 70
#
poe power max-value 2400
#
link-aggregation group 1 mode manual
#
vrrp ping-enable
#
radius scheme system
primary authentication 127.0.0.1 1645
primary accounting 127.0.0.1 1646
user-name-format without-domain
#
domain system
vlan-assignment-mode integer
access-limit disable
state active
idle-cut disable
self-service-url disable
messenger time disable
#
stp instance 0 root primary
stp bpdu-protection
stp TC-protection enable
stp enable
#
acl number 3001
rule 0 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
rule 2 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 3 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
acl number 3002
rule 0 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
rule 2 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 3 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
acl number 3003
rule 0 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
rule 2 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 3 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
acl number 3004
rule 0 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 2 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 3 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
rule 4 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.5.0 0.0.0.255
rule 5 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.0.224 0.0.0.31
rule 6 permit ip source 192.168.0.224 0.0.0.31 destination 192.168.1.0 0.0.0.255
acl number 3005
rule 0 deny ip source 192.168.0.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
#
vlan 1
broadcast-suppression pps 5000
#
vlan 10
broadcast-suppression 50
#
vlan 20
#
vlan 30
#
vlan 40
#
vlan 50
#
interface Vlan-interface1
ip address 192.168.0.253 255.255.255.0
#
interface Vlan-interface10
ip address 192.168.1.253 255.255.255.0
vrrp vrid 10 virtual-ip 192.168.1.1
vrrp vrid 10 priority 130
#
interface Vlan-interface20
ip address 192.168.2.253 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.2.1
vrrp vrid 20 priority 130
#
interface Vlan-interface30
ip address 192.168.3.253 255.255.255.0
vrrp vrid 30 virtual-ip 192.168.3.1
vrrp vrid 30 priority 130
#
interface Vlan-interface40
ip address 192.168.4.253 255.255.255.0
vrrp vrid 40 virtual-ip 192.168.4.1
vrrp vrid 40 priority 130
#
interface Vlan-interface50
ip address 192.168.5.253 255.255.255.0
vrrp vrid 50 virtual-ip 192.168.5.1
vrrp vrid 50 priority 130
#
interface Aux0/0/0
#
interface M-Ethernet0/0/0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet1/0/1
port link-type trunk
port trunk permit vlan all
qos
packet-filter inbound 3001 rule 0 system-index 1
packet-filter inbound ip-group 3001 rule 1 system-index 2
packet-filter inbound ip-group 3001 rule 2 system-index 3
packet-filter inbound ip-group 3001 rule 3 system-index 4
#
interface GigabitEthernet1/0/2
port link-type trunk
port trunk permit vlan all
qos
packet-filter inbound ip-group 3001 rule 0 system-index 5
packet-filter inbound ip-group 3001 rule 1 system-index 6
packet-filter inbound ip-group 3001 rule 2 system-index 7
packet-filter inbound ip-group 3001 rule 3 system-index 8
#
interface GigabitEthernet1/0/3
port link-type trunk
port trunk permit vlan all
qos
packet-filter inbound ip-group 3001 rule 0 system-index 9
packet-filter inbound ip-group 3001 rule 1 system-index 10
packet-filter inbound ip-group 3001 rule 2 system-index 11
packet-filter inbound ip-group 3001 rule 3 system-index 12
packet-filter inbound ip-group 3002 rule 0 system-index 13
packet-filter inbound ip-group 3002 rule 1 system-index 14
packet-filter inbound ip-group 3002 rule 2 system-index 15
packet-filter inbound ip-group 3002 rule 3 system-index 16
#
interface GigabitEthernet1/0/4
port link-type trunk
port trunk permit vlan all
qos
packet-filter inbound ip-group 3002 rule 0 system-index 17
packet-filter inbound ip-group 3002 rule 1 system-index 18
packet-filter inbound ip-group 3002 rule 2 system-index 19
packet-filter inbound ip-group 3002 rule 3 system-index 20
#
interface GigabitEthernet1/0/5
port link-type trunk
port trunk permit vlan all
qos
packet-filter inbound ip-group 3002 rule 0 system-index 21
packet-filter inbound ip-group 3002 rule 1 system-index 22
packet-filter inbound ip-group 3002 rule 2 system-index 23
packet-filter inbound ip-group 3002 rule 3 system-index 24
packet-filter inbound ip-group 3003 rule 0 system-index 25
packet-filter inbound ip-group 3003 rule 1 system-index 26
packet-filter inbound ip-group 3003 rule 2 system-index 27
packet-filter inbound ip-group 3003 rule 3 system-index 28
#
interface GigabitEthernet1/0/6
port link-type trunk
port trunk permit vlan all
qos
packet-filter inbound ip-group 3003 rule 0 system-index 29
packet-filter inbound ip-group 3003 rule 1 system-index 30
packet-filter inbound ip-group 3003 rule 2 system-index 31
packet-filter inbound ip-group 3003 rule 3 system-index 32
#
interface GigabitEthernet1/0/7
port link-type trunk
port trunk permit vlan all
qos
packet-filter inbound ip-group 3003 rule 0 system-index 33
packet-filter inbound ip-group 3003 rule 1 system-index 34
packet-filter inbound ip-group 3003 rule 2 system-index 35
packet-filter inbound ip-group 3003 rule 3 system-index 36
#
interface GigabitEthernet1/0/8
port link-type trunk
port trunk permit vlan all
qos
packet-filter inbound ip-group 3003 rule 0 system-index 37
packet-filter inbound ip-group 3003 rule 1 system-index 38
packet-filter inbound ip-group 3003 rule 2 system-index 39
packet-filter inbound ip-group 3003 rule 3 system-index 40
packet-filter inbound ip-group 3004 rule 0 system-index 41
packet-filter inbound ip-group 3004 rule 1 system-index 42
packet-filter inbound ip-group 3004 rule 2 system-index 43
packet-filter inbound ip-group 3004 rule 3 system-index 44
packet-filter inbound ip-group 3004 rule 4 system-index 45
packet-filter inbound ip-group 3004 rule 5 system-index 46
packet-filter inbound ip-group 3004 rule 6 system-index 47
#
interface GigabitEthernet1/0/9
port link-type trunk
port trunk permit vlan all
qos
packet-filter inbound ip-group 3004 rule 0 system-index 48
packet-filter inbound ip-group 3004 rule 1 system-index 49
packet-filter inbound ip-group 3004 rule 2 system-index 50
packet-filter inbound ip-group 3004 rule 3 system-index 51
packet-filter inbound ip-group 3004 rule 4 system-index 52
packet-filter inbound ip-group 3004 rule 5 system-index 53
packet-filter inbound ip-group 3004 rule 6 system-index 54
#
interface GigabitEthernet1/0/10
port link-type trunk
port trunk permit vlan all
qos
packet-filter inbound ip-group 3005 rule 0 system-index 55
packet-filter inbound ip-group 3004 rule 0 system-index 56
packet-filter inbound ip-group 3004 rule 1 system-index 57
packet-filter inbound ip-group 3004 rule 2 system-index 58
packet-filter inbound ip-group 3004 rule 3 system-index 59
packet-filter inbound ip-group 3004 rule 4 system-index 60
packet-filter inbound ip-group 3004 rule 5 system-index 61
packet-filter inbound ip-group 3004 rule 6 system-index 100
interface GigabitEthernet1/0/11
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
qos
packet-filter inbound ip-group 3001 rule 0 system-index 62
packet-filter inbound ip-group 3001 rule 1 system-index 64
packet-filter inbound ip-group 3001 rule 2 system-index 66
packet-filter inbound ip-group 3001 rule 3 system-index 68
packet-filter inbound ip-group 3002 rule 0 system-index 70
packet-filter inbound ip-group 3002 rule 1 system-index 72
packet-filter inbound ip-group 3002 rule 2 system-index 74
packet-filter inbound ip-group 3002 rule 3 system-index 76
packet-filter inbound ip-group 3003 rule 0 system-index 78
packet-filter inbound ip-group 3003 rule 1 system-index 80
packet-filter inbound ip-group 3003 rule 2 system-index 82
packet-filter inbound ip-group 3003 rule 3 system-index 84
packet-filter inbound ip-group 3004 rule 0 system-index 86
packet-filter inbound ip-group 3004 rule 1 system-index 88
packet-filter inbound ip-group 3004 rule 2 system-index 90
packet-filter inbound ip-group 3004 rule 3 system-index 92
packet-filter inbound ip-group 3004 rule 4 system-index 94
packet-filter inbound ip-group 3004 rule 5 system-index 96
packet-filter inbound ip-group 3004 rule 6 system-index 98
#
interface GigabitEthernet1/0/12
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
qos
packet-filter inbound ip-group 3001 rule 0 system-index 63
packet-filter inbound ip-group 3001 rule 1 system-index 65
packet-filter inbound ip-group 3001 rule 2 system-index 67
packet-filter inbound ip-group 3001 rule 3 system-index 69
packet-filter inbound ip-group 3002 rule 0 system-index 71
packet-filter inbound ip-group 3002 rule 1 system-index 73
packet-filter inbound ip-group 3002 rule 2 system-index 75
packet-filter inbound ip-group 3002 rule 3 system-index 77
packet-filter inbound ip-group 3003 rule 0 system-index 79
packet-filter inbound ip-group 3003 rule 1 system-index 81
packet-filter inbound ip-group 3003 rule 2 system-index 83
packet-filter inbound ip-group 3003 rule 3 system-index 85
packet-filter inbound ip-group 3004 rule 0 system-index 87
packet-filter inbound ip-group 3004 rule 1 system-index 89
packet-filter inbound ip-group 3004 rule 2 system-index 91
packet-filter inbound ip-group 3004 rule 3 system-index 93
packet-filter inbound ip-group 3004 rule 4 system-index 95
packet-filter inbound ip-group 3004 rule 5 system-index 97
packet-filter inbound ip-group 3004 rule 6 system-index 99
#
interface GigabitEthernet1/0/13
#
interface GigabitEthernet1/0/14
#
interface GigabitEthernet1/0/15
#
interface GigabitEthernet1/0/16
#
interface GigabitEthernet1/0/17
#
interface GigabitEthernet1/0/18
#
interface GigabitEthernet1/0/19
#
interface GigabitEthernet1/0/20
#
interface NULL0
#
ospf 1
area 0.0.0.0
network 192.168.0.0 0.0.0.255
network 192.168.1.0 0.0.0.255
network 192.168.2.0 0.0.0.255
network 192.168.3.0 0.0.0.255
network 192.168.4.0 0.0.0.255
network 192.168.5.0 0.0.0.255
#
user-interface aux 0
user-interface vty 0 4
set authentication password cipher IQKC8>5Z'M_Q=^Q`MAF4<1!!
#
return
[Quidway_5624P]dis cur
#
sysname Quidway_5624P
#
vrrp ping-enable
#
link-aggregation group 1 mode manual
#
radius scheme system
#
domain system
#
stp instance 0 root secondary
stp bpdu-protection
stp enable
#
acl number 3001
rule 0 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
rule 2 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 3 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
acl number 3002
rule 0 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
rule 2 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 3 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
acl number 3003
rule 0 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
rule 2 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 3 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
acl number 3004
rule 0 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 2 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 3 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
rule 4 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.5.0 0.0.0.255
rule 5 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.0.224 0.0.0.31
rule 6 permit ip source 192.168.0.224 0.0.0.31 destination 192.168.1.0 0.0.0.255
#
vlan 1
#
vlan 10
#
vlan 20
#
vlan 30
#
vlan 40
#
vlan 50
#
interface Vlan-interface1
ip address 192.168.0.254 255.255.255.0
#
interface Vlan-interface10
ip address 192.168.1.254 255.255.255.0
vrrp vrid 10 virtual-ip 192.168.1.1
vrrp vrid 10 priority 120
#
interface Vlan-interface20
ip address 192.168.2.254 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.2.1
vrrp vrid 20 priority 120
#
interface Vlan-interface30
ip address 192.168.3.254 255.255.255.0
vrrp vrid 30 virtual-ip 192.168.3.1
vrrp vrid 30 priority 120
#
interface Vlan-interface40
ip address 192.168.4.254 255.255.255.0
vrrp vrid 40 virtual-ip 192.168.4.1
vrrp vrid 40 priority 120
#
interface Vlan-interface50
ip address 192.168.5.254 255.255.255.0
vrrp vrid 50 virtual-ip 192.168.5.1
vrrp vrid 50 priority 120
#
interface Aux1/0/0
#
interface GigabitEthernet1/0/1
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3001 rule 0
packet-filter inbound ip-group 3001 rule 1
packet-filter inbound ip-group 3001 rule 2
packet-filter inbound ip-group 3001 rule 3
qos-profile port-based
#
interface GigabitEthernet1/0/2
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3001 rule 0
packet-filter inbound ip-group 3001 rule 1
packet-filter inbound ip-group 3001 rule 2
packet-filter inbound ip-group 3001 rule 3
#
interface GigabitEthernet1/0/3
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3001 rule 0
packet-filter inbound ip-group 3001 rule 1
packet-filter inbound ip-group 3001 rule 2
packet-filter inbound ip-group 3001 rule 3
packet-filter inbound ip-group 3002 rule 0
packet-filter inbound ip-group 3002 rule 1
packet-filter inbound ip-group 3002 rule 2
packet-filter inbound ip-group 3002 rule 3
#
interface GigabitEthernet1/0/4
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3002 rule 0
packet-filter inbound ip-group 3002 rule 1
packet-filter inbound ip-group 3002 rule 2
packet-filter inbound ip-group 3002 rule 3
#
interface GigabitEthernet1/0/5
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3002 rule 0
packet-filter inbound ip-group 3002 rule 1
packet-filter inbound ip-group 3002 rule 2
packet-filter inbound ip-group 3002 rule 3
packet-filter inbound ip-group 3003 rule 0
packet-filter inbound ip-group 3003 rule 1
packet-filter inbound ip-group 3003 rule 2
packet-filter inbound ip-group 3003 rule 3
#
interface GigabitEthernet1/0/6
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3003 rule 0
packet-filter inbound ip-group 3003 rule 1
packet-filter inbound ip-group 3003 rule 2
packet-filter inbound ip-group 3003 rule 3
#
interface GigabitEthernet1/0/7
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3003 rule 0
packet-filter inbound ip-group 3003 rule 1
packet-filter inbound ip-group 3003 rule 2
packet-filter inbound ip-group 3003 rule 3
#
interface GigabitEthernet1/0/8
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3003 rule 0
packet-filter inbound ip-group 3003 rule 1
packet-filter inbound ip-group 3003 rule 2
packet-filter inbound ip-group 3003 rule 3
packet-filter inbound ip-group 3004 rule 0
packet-filter inbound ip-group 3004 rule 1
packet-filter inbound ip-group 3004 rule 2
packet-filter inbound ip-group 3004 rule 3
packet-filter inbound ip-group 3004 rule 4
packet-filter inbound ip-group 3004 rule 5
packet-filter inbound ip-group 3004 rule 6
#
interface GigabitEthernet1/0/9
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3004 rule 0
packet-filter inbound ip-group 3004 rule 1
packet-filter inbound ip-group 3004 rule 2
packet-filter inbound ip-group 3004 rule 3
packet-filter inbound ip-group 3004 rule 4
packet-filter inbound ip-group 3004 rule 5
packet-filter inbound ip-group 3004 rule 6
#
interface GigabitEthernet1/0/10
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3004 rule 0
packet-filter inbound ip-group 3004 rule 1
packet-filter inbound ip-group 3004 rule 2
packet-filter inbound ip-group 3004 rule 3
packet-filter inbound ip-group 3004 rule 4
packet-filter inbound ip-group 3004 rule 5
packet-filter inbound ip-group 3004 rule 6
#
interface GigabitEthernet1/0/11
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3001 rule 0
packet-filter inbound ip-group 3001 rule 1
packet-filter inbound ip-group 3001 rule 2
packet-filter inbound ip-group 3001 rule 3
packet-filter inbound ip-group 3002 rule 0
packet-filter inbound ip-group 3002 rule 1
packet-filter inbound ip-group 3002 rule 2
packet-filter inbound ip-group 3002 rule 3
packet-filter inbound ip-group 3003 rule 0
packet-filter inbound ip-group 3003 rule 1
packet-filter inbound ip-group 3003 rule 2
packet-filter inbound ip-group 3003 rule 3
packet-filter inbound ip-group 3004 rule 0
packet-filter inbound ip-group 3004 rule 1
packet-filter inbound ip-group 3004 rule 2
packet-filter inbound ip-group 3004 rule 3
packet-filter inbound ip-group 3004 rule 4
packet-filter inbound ip-group 3004 rule 5
packet-filter inbound ip-group 3004 rule 6
port link-aggregation group 1
#
interface GigabitEthernet1/0/12
port link-type trunk
port trunk permit vlan all
packet-filter inbound ip-group 3001 rule 0
packet-filter inbound ip-group 3001 rule 1
packet-filter inbound ip-group 3001 rule 2
packet-filter inbound ip-group 3001 rule 3
packet-filter inbound ip-group 3002 rule 0
packet-filter inbound ip-group 3002 rule 1
packet-filter inbound ip-group 3002 rule 2
packet-filter inbound ip-group 3002 rule 3
packet-filter inbound ip-group 3003 rule 0
packet-filter inbound ip-group 3003 rule 1
packet-filter inbound ip-group 3003 rule 2
packet-filter inbound ip-group 3003 rule 3
packet-filter inbound ip-group 3004 rule 0
packet-filter inbound ip-group 3004 rule 1
packet-filter inbound ip-group 3004 rule 2
packet-filter inbound ip-group 3004 rule 3
packet-filter inbound ip-group 3004 rule 4
packet-filter inbound ip-group 3004 rule 5
packet-filter inbound ip-group 3004 rule 6
port link-aggregation group 1
#
interface GigabitEthernet1/0/13
#
........
interface GigabitEthernet1/0/25
shutdown
#
interface GigabitEthernet1/0/26
shutdown
#
interface GigabitEthernet1/0/27
shutdown
#
interface GigabitEthernet1/0/28
shutdown
#
interface Cascade1/2/1
#
interface Cascade1/2/2
#
interface NULL0
#
ospf 1
area 0.0.0.0
network 192.168.0.0 0.0.0.255
network 192.168.1.0 0.0.0.255
network 192.168.2.0 0.0.0.255
network 192.168.3.0 0.0.0.255
network 192.168.4.0 0.0.0.255
network 192.168.5.0 0.0.0.255
#
voice vlan mac-address 0001-e300-0000 mask ffff-ff00-0000
#
user-interface aux 0 7
user-interface vty 0 4
user privilege level 3
set authentication password cipher IQKC8>5Z'M_Q=^Q`MAF4<1!!
#
return
|