免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 3214 | 回复: 8
打印 上一主题 下一主题

[请求帮助]我们的骨干设备端口down掉 [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2003-02-09 15:15 |只看该作者 |倒序浏览
我们的骨干设备无故重启!搞的这个年都没过好,
网络成天断,莫明奇妙,接入交换机(dlink3225,3226)无故端口就被关掉了,而且被关的都是上行口。原本设定的远程登陆口令都没变,而且口令不可能遗失,请问这是怎么回事?
   前两天,我们的骨干交换机6509无故上行口down掉了,当时没有了头绪,重新启动,就恢复了,还有其他的两个三层交换机上行口shutdown,而上层的路由器,一切正常,很奇怪,请问在CISCO的6509上如何查看日志?
     请高手指教,如何在6509的二层和三层加访问列表,关闭远程登陆和ping的功能,只能一台主机远程访问,或者如何将二层和三层的远程功能都关掉?总之如何增加核心设备的安全性?

论坛徽章:
0
2 [报告]
发表于 2003-02-09 22:21 |只看该作者

[请求帮助]我们的骨干设备端口down掉

为什么没有人应答?
报的希望太大了

论坛徽章:
0
3 [报告]
发表于 2003-02-10 08:25 |只看该作者

[请求帮助]我们的骨干设备端口down掉

你的设备LOG记录有吗?从新启动有可能是环境造成的!

论坛徽章:
0
4 [报告]
发表于 2003-02-10 08:39 |只看该作者

[请求帮助]我们的骨干设备端口down掉

你能谈一下大致的配置情况吗

论坛徽章:
0
5 [报告]
发表于 2003-02-10 10:25 |只看该作者

[请求帮助]我们的骨干设备端口down掉

配置如下:#version 6.3(4)
!
set password $2$djtm$GiuyPXxkqAsKq1cFU1rF.0
set enablepass $2$GhbF$tnGFTP4Q0.C.akLfS7vqg0
set banner motd ^CWelcome To Weinan HuiJie ZhongXin 6509 Switch Module^C
!
#errordetection
set errordetection portcounter enable
!
#system
set system name  sc0-sw1-a-wnhj
set system highavailability enable
!
#!
#vtp
set vtp domain weinanhuijie
set vtp mode transparent
set vlan 1 name default type ethernet mtu 1500 said 100001 state active
set vlan 101 name account type ethernet mtu 1500 said 100101 state active
set vlan 102 name connect type ethernet mtu 1500 said 100102 state active
set vlan 103 name access type ethernet mtu 1500 said 100103 state active
set vlan 104 name ebusiness type ethernet mtu 1500 said 100104 state active
set vlan 105 name offlan type ethernet mtu 1500 said 100105 state active
set vlan 106 name wideband type ethernet mtu 1500 said 100106 state active
set vlan 200 name DHCP type ethernet mtu 1500 said 100200 state active
set vlan 201 name KuanDai_ZX5200 type ethernet mtu 1500 said 100201 state active
set vlan 202 name zhongxin_UTSTARCOM type ethernet mtu 1500 said 100202 state active
set vlan 203 name minhang type ethernet mtu 1500 said 100203 state active
set vlan 204 name xi1luadsl type ethernet mtu 1500 said 100204 state active
set vlan 205 name 215_ma5100 type ethernet mtu 1500 said 100205 state active
set vlan 206 name 211_ma5100 type ethernet mtu 1500 said 100206 state active
set vlan 207 name erjianadsl type ethernet mtu 1500 said 100207 state active
set vlan 208 name xi5luma5100 type ethernet mtu 1500 said 100208 state active
set vlan 209 name zhuangli type ethernet mtu 1500 said 100209 state active
set vlan 210 name pu-cheng-5100 type ethernet mtu 1500 said 100210 state active
set vlan 211 name honghua type ethernet mtu 1500 said 100211 state active
set vlan 212 name gusi type ethernet mtu 1500 said 100212 state active
set vlan 213 name yuliu type ethernet mtu 1500 said 100213 state active
set vlan 215 name nat type ethernet mtu 1500 said 100215 state active
set vlan 216 name pc5200 type ethernet mtu 1500 said 100216 state active
set vlan 217 name han-cheng-5200 type ethernet mtu 1500 said 100217 state active
set vlan 218 name xiaolingtong type ethernet mtu 1500 said 100218 state active
set vlan 219 name hckwj type ethernet mtu 1500 said 100219 state active
set vlan 220 name SWT_VDSL type ethernet mtu 1500 said 100220 state active
set vlan 221 name vdsl type ethernet mtu 1500 said 100221 state active
set vlan 1002 name fddi-default type fddi mtu 1500 said 101002 state active
set vlan 1004 name fddinet-default type fddinet mtu 1500 said 101004 state active stp ieee
set vlan 1005 name trnet-default type trbrf mtu 1500 said 101005 state active stp ibm
set vlan 100
set vlan 1003 name token-ring-default type trcrf mtu 1500 said 101003 state active mode srb aremaxhop 7 stemaxhop 7 backupcrf off
!
#ip
set interface sc0 100 172.16.0.10/255.255.255.224 172.16.0.1

set arp agingtime 0
set ip route 0.0.0.0/0.0.0.0         172.16.0.1  
!
#dns
set ip dns server 10.10.0.1 primary
!
#set boot command
set boot config-register 0x102
set boot system flash bootflash:cat6000-sup.6-3-4.bin
!
#igmp
set igmp disable
!
#qos
set qos wred 1p2q2t tx queue 1 40:80 70:100
set qos wred 1p2q2t tx queue 2 40:80 70:100
!
#port channel
set port channel 3/45-48 324
!
# default port status is enable
!
!
#module 1 : 2-port 1000BaseX Supervisor
set module name    1     
set vlan 102  1/1
set vlan 201  1/2
set port negotiation 1/1-2 disable
!
#module 2 : 2-port 1000BaseX Supervisor
set module name    2     
set vlan 102  2/1
set vlan 201  2/2
set port negotiation 2/1-2 disable
set udld disable 2/1
!
#module 3 : 48-port 10/100BaseTX Ethernet
set vlan 100  3/2-5
set vlan 101  3/6-9
set vlan 102  3/10-11
set vlan 103  3/12-15
set vlan 104  3/16-17
set vlan 105  3/18-19,3/43-46
set vlan 106  3/20
set vlan 200  3/21
set vlan 202  3/23
set vlan 203  3/24
set vlan 204  3/25
set vlan 205  3/26
set vlan 206  3/27
set vlan 207  3/28
set vlan 208  3/29
set vlan 209  3/30
set vlan 210  3/31
set vlan 211  3/32
set vlan 212  3/33
set vlan 213  3/22,3/40,3/42
set vlan 215  3/36,3/47-48
set vlan 216  3/37
set vlan 217  3/38
set vlan 218  3/39
set vlan 219  3/41
set vlan 220  3/34
set vlan 221  3/35
set port speed      3/10,3/12-15,3/24-27,3/30-31,3/35-38,3/41-42,3/45-46  100
set port duplex     3/10,3/12-15,3/24-27,3/30-31,3/35-38,3/41-42,3/45-46  full
set trunk 3/1  nonegotiate isl 1-1005,1025-4094
set port channel 3/45-46 mode off
!
#module 4 empty
!
#module 5 empty
!
#module 6 empty
!
#module 7 empty
!
#module 8 empty
!
#module 9 empty
!
#module 15 : 1-port Multilayer Switch Feature Card
!
#module 16 : 1-port Multilayer Switch Feature Card
end     
boot system flash bootflash:c6msfc2-jsv-mz.121-8b.E8
logging facility local3
logging 61.134.1.4
enable secret 5 $1$3uWK$MJtjL1btc6vLm8fDn1/yR0
enable password 7 0462181E5C3056775848
!
ip subnet-zero
!
!
!
!
!
!
interface Vlan20
no ip address
shutdown
!
interface Vlan21
no ip address
shutdown
!
interface Vlan100
description VLAN Vlan100
ip address 192.168.0.1 255.255.255.224
no ip redirects
standby 100 priority 99 preempt
standby 100 ip 192.168.0.2
!
interface Vlan101
description VLAN Account
ip address 192.168.0.50 255.255.255.240
no ip redirects
standby 101 priority 99 preempt
standby 101 ip 192.168.0.51
!

interface Vlan226
no ip address
shutdown
!
router ospf 88
log-adjacency-changes
auto-cost reference-bandwidth 200000
redistribute connected metric-type 1 subnets
redistribute static metric-type 1 subnets

!
ip classless
7
no ip http server
!
access-list 1 permit 192.168.10.0 0.0.31.255
access-list 2 permit 10.10.0.0 0.0.31.255

!
!         
line con 0
line vty 0 4
access-class 60 in
password 7 110E1610051B0F0900232A2A303A3B
login
transport input lat pad mop telnet rlogin udptn nasi
!
end

论坛徽章:
0
6 [报告]
发表于 2003-02-10 10:57 |只看该作者

[请求帮助]我们的骨干设备端口down掉

检查一下端口流量是否异常 或许有帮助
另外,提个醒,下次贴config文件 passwd,banner,描述之类的敏感信息还是稍加工一下比较稳妥。

论坛徽章:
0
7 [报告]
发表于 2003-02-11 09:42 |只看该作者

[请求帮助]我们的骨干设备端口down掉

是呀!很有可以是蠕虫病毒引起的!

论坛徽章:
0
8 [报告]
发表于 2003-02-11 09:42 |只看该作者

[请求帮助]我们的骨干设备端口down掉

是呀!很有可以是蠕虫病毒引起的!

论坛徽章:
0
9 [报告]
发表于 2003-02-11 09:43 |只看该作者

[请求帮助]我们的骨干设备端口down掉

是呀!很有可以是蠕虫病毒引起的!
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP