здравствуйте. поставили свитч 3627g. аплинк на него идет с dgs3120. (отмечено красным)
все свитчи стоящие под ним начали вести себя так
падают все порты кроме магистральных.
на самих же 3627g в логах, опять же на всех портах кроме магистральных, вижу это
Прошивки 3623g - 3.00.B42
Прошивки 3200 - 1.28.009, 4.37.B014 (rev A1/C1)
конфиг 3200
Код:
# STORM
config traffic control 1-27 broadcast enable multicast enable unicast enable action drop threshold 64 countdown 0 time_interval 5
config traffic control auto_recover_time 0
config traffic trap none
config traffic control log state enable
# LOOP_DETECT
enable loopdetect
config loopdetect ports 1-27 state enable
config loopdetect ports 28 state disable
config loopdetect recover_timer 600 interval 5 mode port-based
config loopdetect trap none
config loopdetect log state enable
# VLAN
enable pvid auto_assign
config vlan default delete 1-28
config vlan default advertisement enable
create vlan manager tag 10
config vlan manager add tagged 28 advertisement disable
config vlan manager add untagged 25 advertisement disable
create vlan vlan59 tag 59
config vlan vlan59 add tagged 28 advertisement disable
config vlan vlan59 add untagged 1-24,26,27 advertisement disable
disable gvrp
disable asymmetric_vlan
disable vlan_trunk
# ADDRBIND
config address_binding dhcp_snoop max_entry ports 28 limit no_limit
config address_binding dhcp_snoop max_entry ports 1-27 limit 5
config address_binding ip_mac ports 1-27 arp_inspection disable ip_inspection enable allow_zeroip enable forward_dhcppkt enable
config address_binding ip_mac ports 28 forward_dhcppkt disable
enable address_binding dhcp_snoop
enable address_binding trap_log
config address_binding dhcp snooping recovery_timer 300
disable address_binding dhcp_snoop ipv6
disable address_binding nd_snoop
# DhcpServerScreening
config filter netbios all state enable
config filter extensive_netbios all state enable
config filter dhcp_server ports 1-27 state enable
config filter dhcp_server ports 28 state disable
# IP
config ipif System vlan manager ipa 172.21.0.87/24 st en
create iproute default 172.21.0.1
# DHCP_LOCAL_RELAY
enable dhcp_local_relay
config dhcp_local_relay option_82 circuit_id default
config dhcp_local_relay option_82 remote_id default
config dhcp_local_relay vlan vlanid 59 state enable
config dhcp_local_relay option_82 ports 28 policy keep
config dhcp_local_relay option_82 ports 1-27 policy replace
enable dhcp_relay
config dhcp_relay hops 16 time 10
config dhcp_relay option_82 state enable
config dhcp_relay option_82 check disable
config dhcp_relay option_82 policy replace
config dhcp_relay option_82 remote_id default
config dhcp_relay option_60 state disable
config dhcp_relay option_61 state disable
config dhcp_relay option_60 default mode drop
config dhcp_relay option_61 default drop
config dhcp_relay add vlanid 59 172.20.59.1
config dhcp_relay option_82 circuit_id default
конфиг 3627g
Код:
# STORM
config traffic control 10-24 broadcast enable multicast enable action shutdown threshold 100 countdown disable time_interval 5
config traffic control auto_recover_time 5
config traffic trap none
config traffic control log state enable
# LOOP_DETECT
enable loopdetect
config loopdetect recover_timer 600
config loopdetect interval 5
config loopdetect mode port-based
config loopdetect trap both
config loopdetect ports 1-9,25-27 state disabled
config loopdetect ports 10-24 state enabled
enable snmp
# VLAN
enable pvid auto_assign
config vlan default delete 1-27
config vlan default advertisement enable
create vlan manager tag 10
config vlan manager add tagged 1-9,25-27 advertisement disable
create vlan vlan59 tag 59
config vlan vlan59 add tagged 1-3, 9 advertisement disable
config vlan vlan59 add untagged 10-24 advertisement disable
create vlan vlan63 tag 63
config vlan vlan63 add tagged 1,4,5,8 advertisement disable
create vlan vlan67 tag 67
config vlan vlan67 add tagged 1,6 advertisement disable
create vlan vlan72 tag 72
config vlan vlan72 add tagged 1,7 advertisement disable
create vlan vlan73 tag 73
config vlan vlan73 add tagged 1,7 advertisement disable
create vlan vlan74 tag 74
config vlan vlan74 add tagged 1,7 advertisement disable
create vlan vlan75 tag 75
config vlan vlan75 add tagged 1,7 advertisement disable
disable gvrp
disable asymmetric_vlan
disable vlan_trunk
# ADDRBIND
config address_binding dhcp_snoop max_entry ports 1-9,25-27 limit no_limit
config address_binding dhcp_snoop max_entry ports 10-24 limit 5
config address_binding ip_mac ports 10-24 ip_inspection en
config address_binding ip_mac ports 10-24 arp_inspection dis
config address_binding ip_mac ports 10-24 allow_zeroip ena
config address_binding ip_mac ports 1-9,25-27 forward_dhcppkt disable
enable address_binding dhcp_snoop
enable address_binding trap_log
config address_binding dhcp snooping recovery_timer 300
disable address_binding dhcp_snoop ipv6
disable address_binding nd_snoop
# DhcpServerScreening
config filter netbios all state enable
config filter extensive_netbios all state enable
config filter dhcp_server ports 10-24 state enable
config filter dhcp_server ports 1-9,25-27 state disable
# IP
config ipif System vlan manager ipa 172.21.0.61/24 st en
create iproute default 172.21.0.1
# DHCP_LOCAL_RELAY
enable dhcp_local_relay
config dhcp_local_relay vlan vlan59 state enable
enable dhcp_relay
config dhcp_relay hops 16 time 10
config dhcp_relay option_82 state enable
config dhcp_relay option_82 check disable
config dhcp_relay option_82 policy replace
config dhcp_relay option_82 remote_id default
config dhcp_relay option_60 state disable
config dhcp_relay option_61 state disable
config dhcp_relay option_60 default mode drop
config dhcp_relay option_61 default drop
config dhcp_relay add vlanid 59 172.20.59.1
config dhcp_relay option_82 circuit_id default
config traffic_segmentation 1-27 forward_list 1-27