Нашел проблему:
Вариант копи-паста в свитч №1 в случае которого проблемы. ( смотрим где находится enable dhcp_relay )
Код:
enable address_binding trap_log
config address_binding dhcp_snoop max_entry ports 1-26 limit 5
config address_binding ip_mac ports 1-24 state enable
enable address_binding acl_mode
enable address_binding dhcp_snoop
enable dhcp_relay <==================
config dhcp_relay hops 4 time 0
config dhcp_relay option_82 state enable
config dhcp_relay option_82 check disable
config dhcp_relay option_82 policy replace
config dhcp_relay option_82 remote_id default
config dhcp_relay option_60 state disable
config dhcp_relay option_60 default mode drop
config dhcp_relay option_61 state disable
config dhcp_relay option_61 default drop
config dhcp_relay add ipif System x.x.x.x
config address_binding ip_mac ports 1-26 forward_dhcppkt disable
Вариант копи-паста в свитч №2 в случае которого проблемы НЕТ. ( смотрим где находится enable dhcp_relay )
Код:
enable dhcp_relay <==================
enable address_binding trap_log
config address_binding dhcp_snoop max_entry ports 1-26 limit 5
config address_binding ip_mac ports 1-24 state enable
enable address_binding acl_mode
enable address_binding dhcp_snoop
config dhcp_relay hops 4 time 0
config dhcp_relay option_82 state enable
config dhcp_relay option_82 check disable
config dhcp_relay option_82 policy replace
config dhcp_relay option_82 remote_id default
config dhcp_relay option_60 state disable
config dhcp_relay option_60 default mode drop
config dhcp_relay option_61 state disable
config dhcp_relay option_61 default drop
config dhcp_relay add ipif System x.x.x.x
config address_binding ip_mac ports 1-26 forward_dhcppkt disable
В свитче это замечается в виде неправильного составления ACL
Смотрим внимательно на отличия:
Код:
Access Profile Table
Access Profile ID : 1 Type : Packet Content
================================================================================
Owner : Address_binding
Masks :
Offset 0-15 : 0x00000000 0000ffff ffffffff 00000000
Offset 16-31 : 0x00000000 00000000 00000000 0000ffff
Offset 32-47 : 0xffff0000 00000000 00000000 00000000
Access ID: 1 Mode: Permit
Owner : Address_binding
Port : 1
----------------------------------------------------
Offset 0-15 : 0x00000000 000090f6 52024713 00000000
Offset 16-31 : 0x00000000 00000000 00000000 0000ac1a
Offset 32-47 : 0x0ce40000 00000000 00000000 00000000
================================================================================
Access Profile ID : 2 Type : Packet Content
================================================================================
Owner : Address_binding
Masks :
и тд............
Код:
Access Profile Table
Access Profile ID : 1 Type : Packet Content
================================================================================
Owner : DHCP_Relay / DHCP_Local_Relay
Masks :
Offset 16-31 : 0xffff0000 00000000 000000ff 00000000
Offset 32-47 : 0x00000000 00000000 ffff0000 00000000
Access ID: 1 Mode: Deny
Owner : DHCP_Relay / DHCP_Local_Relay
Port : 1
----------------------------------------------------
Offset 16-31 : 0x08000000 00000000 00000011 00000000
Offset 32-47 : 0x00000000 00000000 00430000 00000000
Access ID: 2 Mode: Deny
Owner : DHCP_Relay / DHCP_Local_Relay
Port : 2
----------------------------------------------------
Offset 16-31 : 0x08000000 00000000 00000011 00000000
Offset 32-47 : 0x00000000 00000000 00430000 00000000
Access ID: 3 Mode: Deny
и тд............
В конфигурации позиция соот тоже меняется.
Значит ребуты или тп не спасут если сохранились.
diff:
Код:
config address_binding ip_mac ports 1-24 state enable
+enable dhcp_relay
enable address_binding acl_mode
enable address_binding dhcp_snoop
-enable dhcp_relay
enable address_binding arp_inspection
disable dhcp_local_relay
config pppoe circuit_id_insertion state disable