- 论坛徽章:
- 0
|
网络情况:
中心交换机:c4503,楼层:c2950 ;网络:电信adsl 8mB/S,固定ip;
故障现象:经常出现不能够访问互联网上的网站;故障出现时qq正常使用,如果使用ip地址可以访问主页,dns解析失败,但是能够ping 通dns的地址;然后过了一段时间,又能够使用dns接到网站了;出现这种现象的时候,如果重启动交换机后,网络也能恢复正常。请大家帮忙分析一下。
中心交换机的配置如下:
CBJT_CENTER_C4503#sh run
Building configuration...
Current configuration : 8324 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
service compress-config
!
hostname CBJT_CENTER_C4503
!
enable secret 5 $1$N6AU$c21cxFU3HjwlhPnH0Dzru0
!
qos
ip subnet-zero
no ip domain-lookup
!
!
no file verify auto
spanning-tree mode pvst
spanning-tree extend system-id
power redundancy-mode redundant
!
!
!
vlan internal allocation policy ascending
!
interface GigabitEthernet1/1
switchport access vlan 21
switchport mode access
!
interface GigabitEthernet1/2
description connect to IDS
switchport access vlan 21
switchport mode access
!
interface GigabitEthernet1/3
switchport access vlan 4
!
interface GigabitEthernet1/4
!
interface GigabitEthernet1/5
!
interface GigabitEthernet1/6
!
interface GigabitEthernet1/7
!
interface GigabitEthernet1/8
switchport mode access
!
interface GigabitEthernet1/9
!
interface GigabitEthernet1/10
!
interface GigabitEthernet1/11
switchport trunk encapsulation dot1q
switchport mode trunk
mtu 1545
!
interface GigabitEthernet1/12
switchport access vlan 100
switchport mode access
mtu 1545
!
interface GigabitEthernet1/13
switchport trunk encapsulation dot1q
switchport mode trunk
mtu 1545
!
interface GigabitEthernet1/14
switchport trunk encapsulation dot1q
switchport mode trunk
mtu 1545
!
interface GigabitEthernet1/15
switchport trunk encapsulation dot1q
switchport mode trunk
mtu 1545
!
interface GigabitEthernet1/16
switchport trunk encapsulation dot1q
switchport mode trunk
mtu 1545
!
interface GigabitEthernet1/17
switchport trunk encapsulation dot1q
switchport mode trunk
mtu 1545
!
interface GigabitEthernet1/18
switchport trunk encapsulation dot1q
switchport mode trunk
mtu 1545
!
interface GigabitEthernet1/19
switchport trunk encapsulation dot1q
switchport mode trunk
mtu 1545
!
interface GigabitEthernet1/20
switchport trunk encapsulation dot1q
switchport mode trunk
mtu 1545
!
interface Vlan1
description wangguan_gateway
ip address 192.168.200.254 255.255.255.0
!
interface Vlan2
description jituan
ip address 192.168.2.1 255.255.255.0
ip access-group 100 out
!
interface Vlan3
description gongsi
ip address 192.168.3.1 255.255.255.0
ip access-group 101 out
!
interface Vlan4
description bashushushe
ip address 192.168.4.1 255.255.255.0
ip access-group 102 out
!
interface Vlan5
description shaoershe
ip address 192.168.5.1 255.255.255.0
ip access-group 103 out
!
interface Vlan6
description wenyishe
ip address 192.168.6.1 255.255.255.0
ip access-group 104 out
!
interface Vlan7
description jiaoyushe
ip address 192.168.7.1 255.255.255.0
ip access-group 105 out
!
interface Vlan8
description renmingshe
ip address 192.168.8.1 255.255.255.0
ip access-group 106 out
!
interface Vlan9
description yinxiangzhongxin
ip address 192.168.9.1 255.255.255.0
ip access-group 107 out
!
interface Vlan10
description gonggongqu
ip address 192.168.10.1 255.255.255.0
ip access-group 108 out
!
interface Vlan11
description wuguan
ip address 192.168.11.1 255.255.255.0
ip access-group 109 out
!
interface Vlan13
description yinhang
ip address 192.168.13.1 255.255.255.0
ip access-group 110 out
!
interface Vlan14
description qita
ip address 192.168.14.1 255.255.255.0
ip access-group 111 out
!
interface Vlan21
description Gig-FireWall
ip address 192.168.21.1 255.255.255.0
!
interface Vlan100
description firewall
mtu 1545
ip address 192.168.100.1 255.255.255.252
ip access-group 20 out
!
interface Vlan200
no ip address
shutdown
!
ip route 0.0.0.0 0.0.0.0 192.168.100.2
no ip http server
!
!
!
logging trap debugging
logging 192.168.2.240
access-list 20 permit 192.168.0.0 0.0.255.255
access-list 100 permit ip 192.168.200.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 100 permit ip 192.168.20.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 100 permit ip 192.168.0.0 0.0.255.255 192.168.2.0 0.0.0.255
access-list 100 permit ip any 192.168.2.0 0.0.0.255
access-list 100 permit ip 192.168.21.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 101 permit ip 192.168.20.0 0.0.0.255 192.168.3.0 0.0.0.255
access-list 101 permit ip 192.168.21.0 0.0.0.255 192.168.3.0 0.0.0.255
access-list 101 deny ip 192.168.0.0 0.0.255.255 192.168.3.0 0.0.0.255
access-list 101 permit ip any 192.168.3.0 0.0.0.255
access-list 102 permit ip 192.168.20.0 0.0.0.255 192.168.4.0 0.0.0.255
access-list 102 permit ip 192.168.21.0 0.0.0.255 192.168.4.0 0.0.0.255
access-list 102 deny ip 192.168.0.0 0.0.255.255 192.168.4.0 0.0.0.255
access-list 102 permit ip any 192.168.4.0 0.0.0.255
access-list 103 permit ip 192.168.20.0 0.0.0.255 192.168.5.0 0.0.0.255
access-list 103 permit ip 192.168.21.0 0.0.0.255 192.168.5.0 0.0.0.255
access-list 103 deny ip 192.168.0.0 0.0.255.255 192.168.5.0 0.0.0.255
access-list 103 permit ip any 192.168.5.0 0.0.0.255
access-list 104 permit ip 192.168.20.0 0.0.0.255 192.168.6.0 0.0.0.255
access-list 104 permit ip 192.168.21.0 0.0.0.255 192.168.6.0 0.0.0.255
access-list 104 deny ip 192.168.0.0 0.0.255.255 192.168.6.0 0.0.0.255
access-list 104 permit ip any 192.168.6.0 0.0.0.255
access-list 105 permit ip 192.168.20.0 0.0.0.255 192.168.7.0 0.0.0.255
access-list 105 permit ip 192.168.21.0 0.0.0.255 192.168.7.0 0.0.0.255
access-list 105 deny ip 192.168.0.0 0.0.255.255 192.168.7.0 0.0.0.255
access-list 105 permit ip any 192.168.7.0 0.0.0.255
access-list 106 permit ip 192.168.20.0 0.0.0.255 192.168.8.0 0.0.0.255
access-list 106 permit ip 192.168.21.0 0.0.0.255 192.168.8.0 0.0.0.255
access-list 106 deny ip 192.168.0.0 0.0.255.255 192.168.8.0 0.0.0.255
access-list 106 permit ip any 192.168.8.0 0.0.0.255
access-list 107 permit ip 192.168.20.0 0.0.0.255 192.168.9.0 0.0.0.255
access-list 107 permit ip 192.168.21.0 0.0.0.255 192.168.9.0 0.0.0.255
access-list 107 deny ip 192.168.0.0 0.0.255.255 192.168.9.0 0.0.0.255
access-list 107 permit ip any 192.168.9.0 0.0.0.255
access-list 108 permit ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255
access-list 108 permit ip 192.168.21.0 0.0.0.255 192.168.10.0 0.0.0.255
access-list 108 deny ip 192.168.0.0 0.0.255.255 192.168.10.0 0.0.0.255
access-list 108 permit ip any 192.168.10.0 0.0.0.255
access-list 109 permit ip 192.168.20.0 0.0.0.255 192.168.11.0 0.0.0.255
access-list 109 permit ip 192.168.21.0 0.0.0.255 192.168.11.0 0.0.0.255
access-list 109 deny ip 192.168.0.0 0.0.255.255 192.168.11.0 0.0.0.255
access-list 109 permit ip any 192.168.11.0 0.0.0.255
access-list 110 permit ip 192.168.20.0 0.0.0.255 192.168.13.0 0.0.0.255
access-list 110 permit ip 192.168.21.0 0.0.0.255 192.168.13.0 0.0.0.255
access-list 110 deny ip 192.168.0.0 0.0.255.255 192.168.13.0 0.0.0.255
access-list 110 permit ip any 192.168.13.0 0.0.0.255
access-list 111 permit ip 192.168.20.0 0.0.0.255 192.168.14.0 0.0.0.255
access-list 111 permit ip 192.168.21.0 0.0.0.255 192.168.14.0 0.0.0.255
access-list 111 deny ip 192.168.0.0 0.0.255.255 192.168.14.0 0.0.0.255
access-list 111 permit ip any 192.168.14.0 0.0.0.255
access-list 199 permit ip any host 192.168.2.200
access-list 199 permit ip host 192.168.2.200 any
access-list 199 permit icmp host 192.168.2.200 any
access-list 199 permit icmp any host 192.168.2.200
!
snmp-server community sccbjt RO
snmp-server community liuyonghang RW
snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart
snmp-server enable traps tty
snmp-server enable traps vtp
snmp-server enable traps vlancreate
snmp-server enable traps vlandelete
snmp-server enable traps stpx
snmp-server enable traps port-security
snmp-server enable traps config
snmp-server enable traps entity
snmp-server enable traps copy-config
snmp-server enable traps fru-ctrl
snmp-server enable traps flash insertion removal
snmp-server enable traps syslog
snmp-server enable traps bridge
snmp-server enable traps envmon fan shutdown supply temperature status
snmp-server enable traps hsrp
snmp-server enable traps bgp
snmp-server enable traps pim neighbor-change rp-mapping-change invalid-pim-message
snmp-server enable traps ipmulticast
snmp-server enable traps msdp
snmp-server enable traps rtr
snmp-server enable traps vlan-membership
snmp-server host 192.168.2.200 version 2c liuyonghang
!
!
line con 0
stopbits 1
line vty 0 4
password 761128
login
!
!
monitor session 1 source interface Gi1/1
monitor session 1 destination interface Gi1/2
end |
|