Maxim Klyus писал(а):
Спасибо, что рассказали про проблему...
Можно увидеть схему включения, конфигурацию?
схема достаточно сложная, древообразная. сеть поделена на кластера, в качестве узлов кластера как раз и используется или cat3560 или dgs3610. один кластер - это примерно 500-1000 абонентов. абоненты подключены к des3526, des3200-xx
IPTV приезжает вообще с другого города, конфиг типичного 3610-26:
)#sh run
Building configuration...
Current configuration : 6834 bytes
!
version v10.3(5p1), Release(94612)(Wed Aug 4 18:51:17 CST 2010 -ngcf65)
hostname bnl-sw-cl-65(1)
co-operate enable
!
!
aaa new-model
!
!
aaa group server radius compatible
!
!
aaa authorization exec default local
aaa authentication login default local
!
!
vlan 1
!
vlan 101
!
vlan 102
!
vlan 103
!
vlan 106
!
vlan 130
name cisco-mgmnt-vlan
!
vlan 132
name dlink-mgmnt-vlan
!
vlan 134
name ups-vlan
!
vlan 135
name netping-vlan
!
vlan 141
name multicast-vlan
!
vlan 240
!
vlan 434
!
vlan 436
!
vlan 447
!
vlan 463
!
vlan 963
name TAL_cluster_63
!
vlan 965
name TAL_cluster_65
!
vlan 966
name TAL_cluster_66
!
vlan 967
name TAL_cluster_67
!
vlan 969
name TAL_cluster_69
!
vlan 991
name Enter-Office-LAN
!
vlan 1000
!
vlan 1200
!
vlan 1202
!
vlan 1204
!
!
username bas password 7 *******************
username bas privilege 5
username avs password 7 *******************
username avs privilege 5
service password-encryption
ip ssh version 2
!
ip name-server 10.22.100.12
ip name-server 10.22.100.14
!
ip pim rp-address 10.22.201.25 1
ip pim rp-address 10.22.201.252 2
!
ip multicast-routing
!
ip access-list standard 1
10 permit any
!
ip access-list standard 2
10 permit 239.0.0.0 0.0.127.255
20 permit 10.22.201.0 0.0.0.255
30 deny any
!
ip access-list standard 20
10 permit 10.77.100.0 0.0.0.255
20 permit 10.22.0.0 0.0.0.255
30 permit 10.22.4.0 0.0.0.255
40 permit 10.22.100.0 0.0.0.127
50 permit 10.22.101.0 0.0.0.255
60 permit host 46.42.232.243
70 permit host 46.42.232.229
!
!
ip access-list extended filter_acl
10 deny tcp any any eq 135
20 deny tcp any any eq 136
30 deny tcp any any eq 137
40 deny tcp any any eq 138
50 deny tcp any any eq 139
60 deny tcp any any eq 445
70 deny udp any any eq 135
80 deny udp any any eq 136
90 deny udp any any eq netbios-ns
100 deny udp any any eq netbios-dgm
110 deny udp any any eq netbios-ss
120 deny udp any any eq 445
130 permit ip any any
!
!
no ip source-route
clock timezone BNL 7 0
logging buffered 40960
logging trap debugging
logging facility local5
logging server 10.22.100.13
logging server 10.77.0.25
enable secret 5 **********************
enable service ssh-server
!
!
interface GigabitEthernet 0/1
switchport mode trunk
description -link-to-OUD1-cat6500-gi1/2
!
interface GigabitEthernet 0/2
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
!
interface GigabitEthernet 0/3
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
!
interface GigabitEthernet 0/4
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
description Brestskaya,5
!
interface GigabitEthernet 0/5
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
!
interface GigabitEthernet 0/6
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
!
interface GigabitEthernet 0/7
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
!
interface GigabitEthernet 0/8
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
description Brestskaya 4,2
!
interface GigabitEthernet 0/9
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
!
interface GigabitEthernet 0/10
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
!
interface GigabitEthernet 0/11
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
!
interface GigabitEthernet 0/12
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
!
interface GigabitEthernet 0/13
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
medium-type fiber
description Souza Respublic 34
!
interface GigabitEthernet 0/14
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
medium-type fiber
!
interface GigabitEthernet 0/15
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
medium-type fiber
!
interface GigabitEthernet 0/16
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
medium-type fiber
!
interface GigabitEthernet 0/17
switchport mode trunk
switchport trunk native vlan 965
storm-control broadcast 2
description Sovetskaia 13
!
interface GigabitEthernet 0/18
switchport mode trunk
medium-type fiber
description -link-to-dgs3610-67-gi0/1
!
interface GigabitEthernet 0/19
switchport mode trunk
medium-type fiber
!
interface GigabitEthernet 0/20
switchport access vlan 135
storm-control broadcast 2
!
interface GigabitEthernet 0/21
switchport mode trunk
medium-type fiber
!
interface GigabitEthernet 0/22
switchport mode trunk
description -link-to-dgs3610(2)-65-gi0/24
!
interface GigabitEthernet 0/23
switchport mode trunk
switchport trunk native vlan 134
storm-control broadcast 2
description ---UPS---
!
interface GigabitEthernet 0/24
switchport mode trunk
medium-type fiber
description -link-to-dgs3610-63-gi0/1
!
interface VLAN 130
no ip proxy-arp
ip address 10.22.101.65 255.255.255.0
description cisco-mngmnt-vlan
!
interface VLAN 134
no ip proxy-arp
description UPS
!
interface VLAN 141
ip pim sparse-mode
no ip proxy-arp
ip address 10.22.201.65 255.255.255.0
description multicast-vlan
!
interface VLAN 965
ip pim sparse-mode
no ip proxy-arp
ip access-group filter_acl in
no ip redirects
ip address 109.203.212.1 255.255.255.0
description claster-iptal-users
!
ntp server 10.22.100.126
ntp server 10.22.100.124
!
!
!
!
!
errdisable recovery interval 30
!
!
!
router ospf 1
router-id 10.22.101.65
redistribute connected subnets
passive-interface default
no passive-interface VLAN 130
network 10.22.101.0 0.0.0.255 area 0.0.0.0
network 172.16.0.0 0.15.255.255 area 0.0.0.0
!
!
!
ip route 0.0.0.0 0.0.0.0 10.22.101.254
!
!
snmp-server location Barnaul
snmp-server community entwork ro 20
line con 0
line vty 0 4
!
!
end
В настоящее время с проблемой перегрузки CPU справились, путем использования акля:
ip pim rp-address 10.22.201.252 2
ip access-list standard 2
10 permit 239.0.0.0 0.0.127.255
20 permit 10.22.201.0 0.0.0.255
30 deny any
но как-то коряво это, мне кажется...
ЗЫ более свежей прошивочки, чем v10.3(5p1), Release(94612) не появилось ?