- 论坛徽章:
- 0
|
Cisco 7609: \r\n\r\n! \r\nip nat translation timeout 10800 \r\nip nat pool internet 192.168.1.5 192.168.1.126 netmask 255.255.255.128 \r\nip nat inside source list 101 pool internet overload \r\nip nat inside source static 10.1.0.1 192.168.1.1\r\nip nat inside source static 10.1.0.2 192.168.1.2\r\n! \r\naccess-list 101 permit ip any any \r\naccess-list 101 permit icmp any any \r\naccess-list 101 permit tcp any any \r\naccess-list 101 permit udp any any \r\n! \r\n\r\n\r\n使用NAT的网段有10.1.0.0/16,10.2.0.0/16,10.3.0.0/16,\r\n实际使用的才200多人,\r\n\r\n但是却有大量如下错误出现\r\n1w5d: %IPNAT-4-ADDR_ALLOC_FAILURE: Address allocation failed for 10.1.0.98, pool internet might be exhausted\r\n1w5d: %IPNAT-4-ADDR_ALLOC_FAILURE: Address allocation failed for 10.1.0.113, pool internet might be exhausted\r\n\r\n使用show ip nat tran查看有10100多条,clear ip nat tran后,还是会出现相同问题\r\n\r\n\r\nIOS (tm) s72033_rp Software (s72033_rp-ADVIPSERVICESK9_WAN-M), Version 12.2(1 S\r\n\r\n\r\n\r\n问题一直没有解决,cisco方面的答复也比较含糊,说7609NAT的性能不太好,现在临时使用pix525单臂路由模式接入做NAT,故障解决,后续将加一个FWSM替换PIX525。\r\n\r\n关于 cheveu 的解释,感觉也是有问题的,因为根据观察一次NAT translations达到100K的统计看:\r\nshow ip nat statistics \r\nTotal active translations: 106485 (3 static, 106482 dynamic; 106359 extended)\r\nOutside interfaces:\r\n GigabitEthernet3/1.1, GigabitEthernet3/2.2\r\nInside interfaces: \r\n Vlan101\r\nHits: 375709164 Misses: 0\r\nCEF Translated packets: 312114347, CEF Punted packets: 1084925942\r\nExpired translations: 109929073\r\nDynamic mappings:\r\n-- Inside Source\r\n[Id: 1] access-list 103 pool internet refcount 39564\r\n pool internet: netmask 255.255.255.128\r\n start 192.168.1.5 end 192.168.1.126\r\n type generic, total addresses 122, allocated 122 (100%), misses 2759737\r\n\r\n106482 dynamic - 106359 extended =123\r\n\r\n\n\n[ 本帖最后由 knightxp 于 2008-8-20 14:52 编辑 ] |
|