mouay 发表于 2015-08-13 13:12

求助,cisco 3550 ping不通,可以telnet

本帖最后由 mouay 于 2015-08-13 13:37 编辑

突然出现网关ping不通,可以telnet。 配置如下:

Current configuration : 3504 bytes
!
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname 1f-3550
!
enable secret 5 $1$YK6c$9bgk9x/aRvf0pUsAvku5k.
enable password cisco
!
ip subnet-zero
ip routing
no ip domain-lookup
!
vtp mode transparent
!
spanning-tree mode pvst
spanning-tree extend system-id
!
!
!
interface FastEthernet0/1
no ip address
!
interface FastEthernet0/2
no ip address
!
interface FastEthernet0/3
no ip address
!
interface FastEthernet0/4
no ip address
!
interface FastEthernet0/5
no ip address
!
interface FastEthernet0/6
no ip address
!
interface FastEthernet0/7
no ip address
!
interface FastEthernet0/8
no ip address
!
interface FastEthernet0/9
no ip address
!
interface FastEthernet0/10
no ip address
!
interface FastEthernet0/11
no ip address
!
interface FastEthernet0/12
no ip address
!
interface FastEthernet0/13
no ip address
!
interface FastEthernet0/14
no ip address
!
interface FastEthernet0/15
no ip address
!
interface FastEthernet0/16
no ip address
!
interface FastEthernet0/17
no ip address
!
interface FastEthernet0/18
no ip address
!
interface FastEthernet0/19
no ip address
!
interface FastEthernet0/20
no ip address
!
interface FastEthernet0/21
no ip address
!
interface FastEthernet0/22
no ip address
!
interface FastEthernet0/23
no ip address
!
interface FastEthernet0/24
no ip address
!
interface GigabitEthernet0/1
no switchport
ip address 10.116.254.66 255.255.255.252
ip access-group 115 in
ip access-group 115 out
no ip unreachables
!
interface GigabitEthernet0/2
no switchport
ip address 10.116.253.66 255.255.255.252
ip access-group 115 in
ip access-group 115 out
no ip unreachables
!
interface Vlan1
ip address 10.117.1.254 255.255.255.0
ip access-group 115 in
ip access-group 115 out
no ip unreachables
!
router ospf 100
log-adjacency-changes
network 10.116.253.64 0.0.0.3 area 0
network 10.116.254.64 0.0.0.3 area 0
network 10.117.1.0 0.0.0.255 area 0
!
ip default-gateway 10.117.1.254
ip classless
ip route 0.0.0.0 0.0.0.0 10.116.253.65
ip route 0.0.0.0 0.0.0.0 10.116.254.65 2
ip http server
!
!
access-list 115 deny   icmp any any echo
access-list 115 deny   icmp any any echo-reply
access-list 115 deny   tcp any any eq 135
access-list 115 deny   udp any any eq 135
access-list 115 deny   udp any any eq tftp
access-list 115 deny   udp any any eq netbios-ns
access-list 115 deny   udp any any eq netbios-dgm
access-list 115 deny   udp any any eq netbios-ss
access-list 115 deny   tcp any any eq 139
access-list 115 deny   tcp any any eq 445
access-list 115 deny   tcp any any eq 593
access-list 115 permit ip any any
snmp-server community chenling RO
snmp-server community wangling RW
snmp-server enable traps snmp authentication warmstart linkdown linkup coldstart
snmp-server enable traps config
snmp-server enable traps entity
snmp-server enable traps flash insertion removal
snmp-server enable traps bridge
snmp-server enable traps rtr
snmp-server enable traps port-security
snmp-server enable traps vlan-membership
snmp-server enable traps vtp
snmp-server enable traps vlancreate
snmp-server enable traps vlandelete
snmp-server enable traps envmon fan shutdown supply temperature
snmp-server enable traps MAC-Notification
snmp-server enable traps hsrp
snmp-server enable traps cluster
snmp-server enable traps syslog
snmp-server enable traps bgp
snmp-server host 10.116.1.100 public
!
line con 0
line vty 0 4
password cisco
login
line vty 5 15
login   
!
end

1f-3550#ping 10.117.1.254

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.117.1.254, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
1f-3550#



mouay 发表于 2015-08-13 13:27

路由列表

Gateway of last resort is 10.116.253.65 to network 0.0.0.0

   10.0.0.0/8 is variably subnetted, 29 subnets, 3 masks
O E2    10.0.0.0/8 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.117.20.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.117.14.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.117.13.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.117.12.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.117.11.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.117.8.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.117.7.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.117.6.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.2.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.3.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
C       10.117.1.0/24 is directly connected, Vlan1
O       10.116.1.0/24 via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.254.4/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.253.4/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.254.8/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.253.8/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.254.12/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.253.12/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.254.16/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.254.20/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.254.24/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.253.24/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.254.28/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.253.28/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.254.32/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.254.36/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
O       10.116.253.36/30
          via 10.116.253.65, 00:20:30, GigabitEthernet0/2
C       10.116.253.64/30 is directly connected, GigabitEthernet0/2
S*   0.0.0.0/0 via 10.116.253.65

xiangbalao_2 发表于 2015-08-13 13:47

表示看不懂 ,大牛给分析分析

lnwu 发表于 2015-08-14 14:18

access-list 115 deny   icmp any any echo
access-list 115 deny   icmp any any echo-reply
这个阻止ping了
页: [1]
查看完整版本: 求助,cisco 3550 ping不通,可以telnet