Анализ трафика не проводился, просто анализировалась загрузка.
Код:
sh ver
System description : DGS-3610-26G Gigabit Ethernet Switch
System start time : 2010-08-25 10:12:49
System uptime : 34:1:46:31
System hardware version : A1.0
System software version : v10.3(5), Release(70398)
System BOOT version : 10.3.70398
System CTRL version : 10.3.70398
Device information:
Device-1
Hardware version : A1.0
Software version : v10.3(5), Release(70398)
BOOT version : 10.3.70398
CTRL version : 10.3.70398
sh run
Building configuration...
Current configuration : 8515 bytes
!
version v10.3(5), Release(70398)(Mon Nov 30 20:26:30 CST 2009 -ngcf49)
hostname c0re
co-operate enable
!
!
aaa new-model
!
!
!
aaa authentication login default local
!
!
vlan 1
!
vlan 3
name Noname
!
vlan 4
name Noname
!
vlan 5
name Noname
!
vlan 10
name Noname
!
vlan 11
name Noname
!
vlan 12
name Noname
!
vlan 40
name Noname
!
vlan 45
name Noname
!
vlan 51
name Noname
!
vlan 52
name Noname
!
vlan 61
name Noname
!
vlan 242
name Noname
!
vlan 482
name Noname
!
vlan 501
name Noname
!
vlan 800
name Noname
!
vlan 899
name Noname
!
vlan 2000
name Noname
!
!
username admin password 7 *************
service password-encryption
service sequence-numbers
no service timestamps debug
!
!
no ip domain-lookup
!
!
!
!
ip pim rp-address 10.50.2.62
ip pim cisco-register-checksum
!
!
!
!
!
!
!
ip multicast-routing
!
!
!
!
ip access-list standard 22
10 permit 10.147.0.0 0.0.255.255
!
!
ip access-list standard 82
10 permit host 10.147.0.25
20 permit host 10.147.0.1
30 permit host 10.147.0.50
!
!
ip access-list extended 151
10 permit ip 10.147.0.0 0.0.255.255 10.147.0.0 0.0.255.255
!
!
ip access-list extended OfficeNet
10 deny tcp any any range 135 139
20 deny udp any any range 135 netbios-ss
30 deny tcp any any eq 445
40 deny udp any any eq 445
50 permit ip any any
!
!
no ip source-route
ip pim snooping
clock timezone NOVST 7 0
logging trap debugging
logging facility local6
logging server 10.147.0.1
enable secret 5 **********************
enable password 7 ***************
enable service ssh-server
enable service web-server
!
!
!
!
!
!
!
!
interface GigabitEthernet 0/1
switchport mode trunk
switchport trunk allowed vlan remove 1-241,243-481,483-4094
description Intex-Peering
!
interface GigabitEthernet 0/2
switchport access vlan 45
description to_Intex-Multicast
!
interface GigabitEthernet 0/3
switchport mode trunk
switchport trunk allowed vlan remove 1-4094
!
interface GigabitEthernet 0/4
switchport mode trunk
switchport trunk allowed vlan remove 1-4094
!
interface GigabitEthernet 0/5
switchport mode trunk
switchport trunk allowed vlan remove 1-4094
!
interface GigabitEthernet 0/6
switchport mode trunk
switchport trunk allowed vlan remove 1-4094
!
interface GigabitEthernet 0/7
switchport mode trunk
switchport trunk allowed vlan remove 1-4094
!
interface GigabitEthernet 0/8
switchport mode trunk
switchport trunk allowed vlan remove 1-4094
!
interface GigabitEthernet 0/9
switchport mode trunk
switchport trunk allowed vlan remove 1-4094
!
interface GigabitEthernet 0/10
switchport mode trunk
switchport trunk allowed vlan remove 1-2,5-44,46-51,53-4094
description 50let40-1p-9et
!
interface GigabitEthernet 0/11
switchport mode trunk
switchport trunk allowed vlan remove 1-2,5-9,11-44,46-4094
description Str47-4p-5et
!
interface GigabitEthernet 0/12
switchport mode trunk
switchport trunk allowed vlan remove 1-2,5-9,11-44,46-4094
description Pushk12-4p-5et
!
interface GigabitEthernet 0/13
switchport mode trunk
switchport trunk allowed vlan remove 1-3,6-50,52-4094
description 2_kitten.g0/13
!
interface GigabitEthernet 0/14
switchport mode trunk
switchport trunk allowed vlan remove 1-2,5-9,11-39,41-44,46-4094
description Okt11-5p-9et
!
interface GigabitEthernet 0/15
description *****
!
interface GigabitEthernet 0/16
switchport mode trunk
switchport trunk allowed vlan remove 1-2,5-44,46-51,53-4094
description 50let40-1p-9et
!
interface GigabitEthernet 0/17
switchport mode trunk
switchport trunk allowed vlan remove 1-2,6-9,11-44,46-50,52-71,73-799,801-4094
description Kuzn26-4p-5et
!
interface GigabitEthernet 0/18
switchport mode trunk
switchport trunk allowed vlan remove 1-2,5-9,11-44,46-60,62-4094
description Str67-1p-1et
!
interface GigabitEthernet 0/19
switchport mode trunk
switchport trunk allowed vlan remove 1-4094
!
interface GigabitEthernet 0/20
switchport mode trunk
switchport trunk allowed vlan remove 1-4094
!
interface GigabitEthernet 0/21
switchport mode trunk
switchport trunk allowed vlan remove 1-3,5-9,13-39,41-44,46-50,53-898,900-4094
description BASE
!
interface GigabitEthernet 0/22
switchport mode trunk
switchport trunk allowed vlan remove 1-3,5-51,53-4094
description Boomer.bge0
!
interface GigabitEthernet 0/23
switchport mode trunk
description 2_GS
!
interface GigabitEthernet 0/24
!
interface VLAN 3
ip ospf message-digest-key 1 md5 ***********
no ip proxy-arp
ip address 10.50.254.254 255.255.255.0
description Nodesc
!
interface VLAN 4
ip pim sparse-mode
no ip proxy-arp
ip access-group 151 in
ip access-group 151 out
no ip unreachables
ip address 10.147.0.254 255.255.0.0
description Nodesc
!
interface VLAN 5
no ip proxy-arp
description Nodesc
!
interface VLAN 10
ip pim sparse-mode
no ip proxy-arp
description Nodesc
!
interface VLAN 11
no ip proxy-arp
ip address 192.168.0.10 255.255.255.0
description Nodesc
!
interface VLAN 12
no ip proxy-arp
description Nodesc
!
interface VLAN 40
ip pim sparse-mode
no ip proxy-arp
no ip unreachables
no ip redirects
ip address 10.50.0.254 255.255.255.0
no snmp trap link-status
description Nodesc
!
interface VLAN 45
ip pim sparse-mode
no ip proxy-arp
ip address 10.50.2.62 255.255.255.192
description Nodesc
!
interface VLAN 51
no ip proxy-arp
ip address 82.200.96.226 255.255.255.248
description Nodesc
!
interface VLAN 52
ip pim sparse-mode
no ip proxy-arp
no ip unreachables
no ip redirects
ip address 82.200.96.241 255.255.255.240
description Nodesc
!
interface VLAN 242
no ip proxy-arp
ip address 213.110.37.2 255.255.255.252
description Nodesc
!
interface VLAN 482
ip pim sparse-mode
no ip proxy-arp
ip address 10.50.250.253 255.255.255.252
description Nodesc
!
interface VLAN 501
no ip proxy-arp
ip address 10.50.155.1 255.255.255.0
description Nodesc
!
interface VLAN 800
no ip proxy-arp
no ip unreachables
no ip redirects
no snmp trap link-status
description Nodesc
!
interface VLAN 899
no ip proxy-arp
ip address 10.50.1.254 255.255.255.252
description Nodesc
!
interface VLAN 2000
ip pim sparse-mode
no ip proxy-arp
ip address 10.0.0.1 255.255.255.0
description Nodesc
!
ntp server 10.147.0.250 prefer
!
!
!
!
!
monitor session 1 destination interface GigabitEthernet 0/15
monitor session 1 source interface GigabitEthernet 0/13 both
monitor session 1 source interface GigabitEthernet 0/22 both
!
!
!
router ospf 1
router-id 10.147.0.240
redistribute connected subnets
log-adj-changes detail
area 0.0.0.0 authentication message-digest
network 10.50.254.0 0.0.0.255 area 0.0.0.0
network 82.200.96.224 0.0.0.3 area 0.0.0.0
!
!
!
ip route 0.0.0.0 0.0.0.0 82.200.96.225 199
ip route 10.50.0.0 255.255.0.0 Null 0 250
ip route 10.70.0.0 255.255.0.0 82.200.96.228
ip route 10.147.0.0 255.255.0.0 Null 0
ip route 81.161.208.0 255.255.240.0 Null 0 250
ip route 193.93.244.0 255.255.252.0 213.110.37.1
ip route 193.169.60.0 255.255.254.0 82.200.96.228
ip route 213.110.32.0 255.255.224.0 213.110.37.1
!
!
snmp-server location Str67
snmp-server host 10.147.0.50 traps ******************
snmp-server host 10.147.0.1 traps version 2c *****************
snmp-server enable traps snmp
snmp-server community **************** ro 82
snmp-server community **************** rw 82
line con 0
password 7 ****************
line vty 0 4
transport input telnet
password 7 ****************
line vty 5 35
transport input telnet
password 7 ****************
!
!
end
sh log
000401: *Sep 20 13:13:34: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000402: *Sep 20 15:11:42: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000403: *Sep 20 17:33:17: %AAA-5-USER_UNLOCKED: User admin unlocked by .
000404: *Sep 21 01:52:06: %LINK-3-UPDOWN: Interface GigabitEthernet 0/15, changed state to down.
000405: *Sep 21 01:52:06: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet 0/15, changed state to down.
000406: *Sep 21 02:05:11: %LINK-3-UPDOWN: Interface GigabitEthernet 0/15, changed state to up.
000407: *Sep 21 02:05:11: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet 0/15, changed state to up.
000408: *Sep 21 02:05:41: %LINK-3-UPDOWN: Interface GigabitEthernet 0/15, changed state to down.
000409: *Sep 21 02:05:41: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet 0/15, changed state to down.
000410: *Sep 21 02:05:44: %LINK-3-UPDOWN: Interface GigabitEthernet 0/15, changed state to up.
000411: *Sep 21 02:05:44: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet 0/15, changed state to up.
000412: *Sep 21 09:26:47: %OSPF-4-AUTH_ERR: Received [LS-Upd] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000413: *Sep 21 20:59:30: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000414: *Sep 23 12:25:38: %ARPGUARD-4-DOS_DETECTED: ARP DoS attack was detected.
000415: *Sep 23 13:34:36: %OSPF-4-AUTH_ERR: Received [LS-Upd] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000416: *Sep 23 20:53:44: %SYS-6-CLOCKUPDATE: System clock has been updated to 20:53:44 NOVST Thu Sep 23 2010.
000417: *Sep 23 20:54:48: %SYS-6-CLOCKUPDATE: System clock has been updated to 20:54:48 NOVST Thu Sep 23 2010.
000418: *Sep 24 11:00:19: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000419: *Sep 24 19:01:20: %ARPGUARD-4-DOS_DETECTED: ARP DoS attack was detected.
000420: *Sep 24 21:30:44: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000421: *Sep 25 12:59:13: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000422: *Sep 25 21:53:03: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000423: *Sep 25 21:53:23: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000424: *Sep 26 08:16:06: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000425: *Sep 26 17:06:16: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000426: *Sep 26 19:06:44: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000427: *Sep 26 19:09:54: %OSPF-4-AUTH_ERR: Received [LS-Upd] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000428: *Sep 27 14:27:28: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000429: *Sep 27 19:44:37: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000430: *Sep 27 23:16:48: %OSPF-4-AUTH_ERR: Received [Hello] packet from 10.147.16.254 via VLAN 3:10.50.254.254: MD5 authentication.
000431: *Sep 28 11:04:38: %SYS-6-CLOCKUPDATE: System clock has been updated to 11:04:38 NOVST Tue Sep 28 2010.
000432: *Sep 28 11:04:39: %SYS-5-CONFIG_I: Configured from console by admin on vty0(10.147.0.50)
000433: *Sep 28 11:08:13: %SYS-5-CONFIG_I: Configured from console by admin on vty0(10.147.0.50)
sh int count summ
Interface InOctets InUcastPkts InMulticastPkts InBroadcastPkts
------------- -------------------- -------------------- -------------------- --------------------
Gi0/1 9431407792960 9344526608 6779991 2443873
Gi0/2 2346012845299 2185070505 1819158 304836
Gi0/3 0 0 0 0
Gi0/4 7242380 0 112114 1044
Gi0/5 0 0 0 0
Gi0/6 0 0 0 0
Gi0/7 0 0 0 0
Gi0/8 0 0 0 0
Gi0/9 231705 125 750 489
Gi0/10 2981836645646 4487167515 428858206 9758435
Gi0/11 1731554784724 2572177864 21026239 3335911
Gi0/12 1926525829440 3224998259 27820397 4505599
Gi0/13 72809919725116 102739695168 48784 185792
Gi0/14 15102489134764 29960160974 1448678977 29679942
Gi0/15 0 0 0 0
Gi0/16 5157720807859 7529419282 654051073 17558314
Gi0/17 49078816391521 76155779597 116253157 21630991
Gi0/18 6582509306548 10816154474 1331589112 28678051
Gi0/19 2349036864893 4710629755 44304632 6292349
Gi0/20 3750597039305 5025508055 34062009 5954936
Gi0/21 91605121799668 46466872832 25525547450 12266277
Gi0/22 347701976378 472917636 8 7702
Gi0/23 4345997405055 4128678861 242977122 8236827
Gi0/24 0 0 0 0
Interface OutOctets OutUcastPkts OutMulticastPkts OutBroadcastPkts
------------- -------------------- -------------------- -------------------- --------------------
Gi0/1 3785533485671 6338796743 909091 550
Gi0/2 28718283074148 1477763306 20397430257 5881764
Gi0/3 0 0 0 0
Gi0/4 6176367035832 342 4516369231 1206009
Gi0/5 0 0 0 0
Gi0/6 0 0 0 0
Gi0/7 0 0 0 0
Gi0/8 0 0 0 0
Gi0/9 960 0 15 0
Gi0/10 22590143407514 5771716451 11977326576 3758701
Gi0/11 19546812997886 3031052365 12226101716 7399289
Gi0/12 20510302063380 3753349661 12267284686 7475993
Gi0/13 70336483860814 109765188516 27139068 1854873
Gi0/14 67087488155632 35961928026 25827812636 23382933
Gi0/15 143500472209078 213281784292 31132449 2456988
Gi0/16 28431997808905 9561636608 13581204862 5804767
Gi0/17 95476743314982 75268944011 25836488139 19792748
Gi0/18 51342894926371 14797571972 25839480102 19716774
Gi0/19 25025177222516 5992119844 13565744732 11878432
Gi0/20 23341868814436 5376131878 13606989712 12162179
Gi0/21 10922490757142 29215430692 743201767 18933730
Gi0/22 81634147215 367900362 25790934 2253129
Gi0/23 37842620942358 2994962776 26240135995 39588484
Gi0/24 8435337097686 521 6158064502 1820240