Имеем
Код:
System description : DGS-3610-26G Gigabit Ethernet Switch
System start time : 2012-02-13 21:1:45
System uptime : 0:11:41:22
System hardware version : A1.0
System software version : v10.4(3) Release(117920)
System BOOT version : 10.3 Release(94612)
System CTRL version : 10.3 Release(94612)
Device information:
Device-1
Hardware version : A1.0
Software version : v10.4(3) Release(117920)
BOOT version : 10.3 Release(94612)
CTRL version : 10.3 Release(94612)
Фрагмент конфига используем PBR
track 1 rns 1
delay up 10 down 10
!
track 2 rns 2
delay up 10 down 10
!
track 3 rns 3
delay up 10 down 10
route-map For_Office deny 10
match ip address Local_network
!
route-map For_Office permit 20
match ip address Office1_network
set ip next-hop 172.28.200.4
!
route-map For_Office permit 30
match ip address Office2_network
set ip next-hop 172.28.200.5
!
route-map For_Office permit 40
match ip address Office3_network
set ip next-hop 172.28.200.112 1
!
route-map For_Office permit 50
match ip address Office_network
set ip next-hop verify-availability 172.28.200.5 5 track 1
set ip next-hop verify-availability 172.28.200.4 8 track 3
set ip next-hop verify-availability 172.28.200.112 3 track 2
!
route-map For_Users_in_Default deny 10
match ip address Local_network
!
route-map For_Users_in_Default permit 20
match ip address network_0_5
set ip next-hop verify-availability 172.28.200.5 8 track 1
set ip next-hop verify-availability 172.28.200.4 5 track 3
set ip next-hop verify-availability 172.28.200.112 3 track 2
!
route-map For_Users_in_Default permit 30
match ip address network_6-9_17
set ip next-hop verify-availability 172.28.200.112 8 track 2
set ip next-hop verify-availability 172.28.200.4 5 track 3
set ip next-hop verify-availability 172.28.200.5 3 track 1
!
route-map For_Users_in_Default permit 40
match ip address network_10_16
set ip next-hop verify-availability 172.28.200.4 8 track 3
set ip next-hop verify-availability 172.28.200.5 5 track 1
set ip next-hop verify-availability 172.28.200.112 3 track
ip access-list extended Local_network
10 deny ip any 172.0.0.0 0.31.255.255
20 deny ip any 37.9.64.0 0.0.63.255
30 deny ip any 77.88.0.0 0.0.63.255
40 deny ip any 84.201.128.0 0.0.63.255
50 deny ip any 87.250.224.0 0.0.31.255
60 deny ip any 93.158.128.0 0.0.63.255
70 deny ip any 95.108.128.0 0.0.127.255
80 deny ip any 100.43.64.0 0.0.31.255
90 deny ip any 130.193.32.0 0.0.31.255
100 deny ip any 141.8.128.0 0.0.63.255
110 deny ip any 178.154.128.0 0.0.127.255
120 deny ip any 199.21.96.0 0.0.3.255
130 deny ip any 199.36.240.0 0.0.3.255
140 deny ip any 213.180.192.0 0.0.31.255
160 deny ip any host 109.197.112.17
170 deny ip any host 109.197.112.26
!
!
ip access-list extended Office1_network
10 permit ip host 172.20.254.10 any
!
!
ip access-list extended Office2_network
10 permit ip host 172.20.254.9 any
!
!
ip access-list extended Office3_network
10 permit ip host 172.20.254.6 any
!
!
ip access-list extended Office_network
10 permit ip 172.20.254.0 0.0.0.255 any
!
!
ip access-list extended network_0_5
10 permit ip 172.28.0.0 0.0.0.255 any
20 permit ip 172.28.1.0 0.0.0.255 any
30 permit ip 172.28.2.0 0.0.0.255 any
40 permit ip 172.28.3.0 0.0.0.255 any
50 permit ip 172.28.4.0 0.0.0.255 any
60 permit ip 172.28.5.0 0.0.0.255 any
!
!
ip access-list extended network_10_16
10 permit ip 172.28.10.0 0.0.0.255 any
20 permit ip 172.28.11.0 0.0.0.255 any
30 permit ip 172.28.12.0 0.0.0.255 any
40 permit ip 172.28.13.0 0.0.0.255 any
50 permit ip 172.28.14.0 0.0.0.255 any
60 permit ip 172.28.16.0 0.0.0.255 any
!
!
ip access-list extended network_6-9_17
10 permit ip 172.28.6.0 0.0.0.255 any
20 permit ip 172.28.7.0 0.0.0.255 any
30 permit ip 172.28.8.0 0.0.0.255 any
40 permit ip 172.28.9.0 0.0.0.255 any
50 permit ip 172.28.17.0 0.0.0.255 any
ip rns 1
icmp-echo 172.28.200.5 source-ipaddr 172.28.200.10
frequency 4000
timeout 3000
!
ip rns 2
icmp-echo 172.28.200.112 source-ipaddr 172.28.200.10
frequency 4000
timeout 3000
!
ip rns 3
icmp-echo 172.28.200.4 source-ipaddr 172.28.200.10
frequency 4000
timeout 3000
Проблема номер 1 - когда меняешь вес у маршрута например было так
Код:
set ip next-hop verify-availability 172.28.200.5 5 track 1
set ip next-hop verify-availability 172.28.200.4 8 track 3
set ip next-hop verify-availability 172.28.200.112 3 track 2
а стало
Код:
set ip next-hop verify-availability 172.28.200.5 8 track 1
set ip next-hop verify-availability 172.28.200.4 2 track 3
set ip next-hop verify-availability 172.28.200.112 3 track 2
все равно пакеты проматченные бегут через прежний хоп. Чем больше цифра тем приоритетней вес маршрута. Это не работает.
Проблема номер 2 - проработав около недели такая схема, возникло следующее - у абонентов шли пинги до ядра сети но трасировка например до майла уже на первом хопе показывала * * * а не шлюз. Лечилось снятием no ip policy route-map с влан интерфейса и потом возвратом полиси на место. До этого чистил арп кэш не помогало. Помогите разобратся.