祁振峰本尊,设备运行过程中终端和接入交换机突然无法通过DHCP获取地址
问题描述
现场反馈,设备运行过程中突然无法通过DHCP获取地址
5130---6520---7560
DHCP服务器配置在7560上,5130下接终端和AP,中间6520二层透传。
过程分析
通过DHCP方式的流统,发现报文是丢在了5130上联6520的聚合口上,即从终端或AP收到的DHCP请求报文没有从5130的上联口发出去。
[2#-2F-OFFICE-POE-SW-a.a.a.a]dis qos policy interface inbound
Interface: GigabitEthernet1/0/19
Direction: Inbound
Policy: dhcp-c
Classifier: dhcp-c
Operator: AND
Rule(s) :
If-match acl 3010
If-match source-mac xxxx-xxxx-xxxx //测试终端mac
Behavior: dhcp-c
Accounting enable:
18 (Packets)
Interface: Ten-GigabitEthernet1/0/27
Direction: Inbound
Policy: dhcp-s
Classifier: dhcp-s
Operator: AND
Rule(s) :
If-match acl 3011
If-match source-mac yyyy-yyyy-yyyy
If-match destination-mac xxxx-xxxx-xxxx
Behavior: dhcp-s
Accounting enable:
0 (Packets)
Interface: Ten-GigabitEthernet1/0/28
Direction: Inbound
Policy: dhcp-s
Classifier: dhcp-s
Operator: AND
Rule(s) :
If-match acl 3011
If-match source-mac yyyy-yyyy-yyyy
If-match destination-mac xxxx-xxxx-xxxx
Behavior: dhcp-s
Accounting enable:
0 (Packets)
[2#-2F-OFFICE-POE-SW-a.a.a.a]dis qos policy interface out
[2#-2F-OFFICE-POE-SW-a.a.a.a]dis qos policy interface outbound
Interface: GigabitEthernet1/0/19
Direction: Outbound
Policy: dhcp-s
Classifier: dhcp-s
Operator: AND
Rule(s) :
If-match acl 3011
If-match source-mac yyyy-yyyy-yyyy
If-match destination-mac xxxx-xxxx-xxxx
Behavior: dhcp-s
Accounting enable:
0 (Packets)
Interface: Ten-GigabitEthernet1/0/27
Direction: Outbound
Policy: dhcp-c
Classifier: dhcp-c
Operator: AND
Rule(s) :
If-match acl 3010
If-match source-mac xxxx-xxxx-xxxx
Behavior: dhcp-c
Accounting enable:
0 (Packets)
Interface: Ten-GigabitEthernet1/0/28
Direction: Outbound
Policy: dhcp-c
Classifier: dhcp-c
Operator: AND
Rule(s) :
If-match acl 3010
If-match source-mac xxxx-xxxx-xxxx
Behavior: dhcp-c
Accounting enable:
0 (Packets)
在5130配置业务接口同样无法自动获取地址,手工配置地址可以和DHCP网关互通。
设备全局使能了 DHCP Snooping enable,上行朝向 dhcp server的接口 bagg1下没有配置为信任端口,因此转发不出去 dhcp请求报文;另外,开启了 dhcp snooping功能后, dhcp报文会上 cpu处理,因此出方向统计不到;
至于为什么之前获取地址正常,后续又不能获取了;
沟通得知, bagg1聚合口是最近才加上去的,终端之前拿地址应该是在只用单根线的时候拿到的,等到地址最后老化超时了,再申请、设备 bagg1有没有配置为信任端口,也就拿不到了;
将 bagg1上配置为信任端口,问题已经解决;
解决方法
将bagg1上配置为信任端口,问题已经解决;
CRM论坛(CRMbbs.com)——一个让用户更懂CRM的垂直性行业内容平台,CRM论坛致力于互联网、客户管理、销售管理、SCRM私域流量内容输出5年。 如果您有好的内容,欢迎向我们投稿,共建CRM多元化生态体系,创建CRM客户管理一体化生态解决方案。,设备运行过程中终端和接入交换机突然无法通过DHCP获取地址