faq обучение настройка
Текущее время: Пт июл 18, 2025 16:41

Часовой пояс: UTC + 3 часа




Начать новую тему Ответить на тему  [ Сообщений: 1355 ]  На страницу Пред.  1 ... 18, 19, 20, 21, 22, 23, 24 ... 91  След.
Автор Сообщение
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Пт апр 17, 2015 15:29 
Не в сети

Зарегистрирован: Чт апр 16, 2015 16:58
Сообщений: 6
Немного картинок:
При таком варианте не переставая дропаются пакеты с портов 5 и 49 на первом DGSе. На порту 50 первого DGSa тишина.
Вложение:
Комментарий к файлу: Вариант 1
schem1.jpg
schem1.jpg [ 25.18 KiB | Просмотров: 9358 ]

При таком варианте не переставая дропаются пакеты с портов 49 и 50 на первом DGSе. На портах 5 и 49 второго DGSа тишина. Изредка на 49 пропадёт 1-2 пакета.
Вложение:
Комментарий к файлу: Вариант 2
schem2.jpg
schem2.jpg [ 25.29 KiB | Просмотров: 9358 ]


Меняю DGSы местами, картина точно такая-же.


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Пт апр 17, 2015 17:57 
Не в сети
Сотрудник D-LINK
Сотрудник D-LINK

Зарегистрирован: Ср май 10, 2006 16:40
Сообщений: 12251
Откуда: D-Link, Moscow
С какой частотой появляются дропы?


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Пт апр 17, 2015 18:04 
Не в сети

Зарегистрирован: Вс май 22, 2005 10:19
Сообщений: 895
Откуда: Moscow
дропы эти тут вообще не при чём

как диагностировалась плохая связь у клиентов? замеры скорости, потери, лаги?


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Пн апр 20, 2015 08:11 
Не в сети

Зарегистрирован: Чт апр 16, 2015 16:58
Сообщений: 6
Alexandr Zaitsev писал(а):
С какой частотой появляются дропы?

Ежесекундно.

RDC писал(а):
дропы эти тут вообще не при чём

как диагностировалась плохая связь у клиентов? замеры скорости, потери, лаги?

Клиенты жаловались на медленную работу интернета. Замеры скорости не производили, т.к. клиент важный решили просто заменить коммутатор на DES-3052, а эти забрали в офис. На днях будем тестировать.
UPD: снял видео. подключился, работаю через этот коммутатор. на аплинке дропаются пакеты, на моём порту потихоньку появляются дропы. На момент записи видео было 99 дропов, на сейчас 114.
http://youtu.be/79WP2bBdxkM
На моём(пользовательском) порту начали расти Excessive Deferral
https://youtu.be/msZeVMDWjDE

Конфиг:
Скрытый текст: показать
#------------------------------------------------------------------------
# DGS-1210-52/ME Gigabit Ethernet Switch Configuration
#
# Firmware: Build 6.11.B052
# Copyright(C) 2010 D-Link Corporation. All rights reserved.
#------------------------------------------------------------------------

command-start

# User Account
disable password encryption


# Basic
config syslogintimeout 5
enable web 80
enable clipaging
config command_prompt default
config serial_port baud_rate 9600
config serial_port auto_logout 10_minutes

# Gratuitous Arp
config gratuitous_arp send ipif_status_up disable
config gratuitous_arp send dup_ip_detected disable
config gratuitous_arp learning disable
config gratuitous_arp send periodically interval 0

# Arp Aging Time
config arp_aging time 5

# FDB Aging Time
config fdb aging_time 300

# Telnet Setting
enable telnet 23

# Vlan
disable asymmetric_vlan
create vlan "mgmt" tag 2
create vlan "adtv" tag 4
create vlan "VLAN12" tag 12
create vlan "VLAN15" tag 15
create vlan "VLAN58" tag 58
create vlan "VLAN60" tag 60
create vlan "VLAN113" tag 113
create vlan "VLAN115" tag 115
create vlan "VLAN210" tag 210
create vlan "VLAN235" tag 235
create vlan "VLAN238" tag 238
create vlan "VLAN275" tag 275
create vlan "VLAN465" tag 465
create vlan "VLAN757" tag 757
create vlan "VLAN831" tag 831
create vlan "VLAN963" tag 963
create vlan "VLAN1100" tag 1100
create vlan "VLAN1111" tag 1111
create vlan "VLAN1500" tag 1500
create vlan "VLAN2065" tag 2065
create vlan "VLAN2183" tag 2183
create vlan "VLAN2500" tag 2500
create vlan "VLAN2924" tag 2924
create vlan "VLAN2925" tag 2925
create vlan "VLAN2926" tag 2926
create vlan "VLAN2927" tag 2927
create vlan "VLAN2928" tag 2928
create vlan "VLAN2929" tag 2929
create vlan "VLAN2930" tag 2930
create vlan "VLAN2931" tag 2931
create vlan "VLAN2932" tag 2932
create vlan "VLAN2933" tag 2933
create vlan "VLAN2934" tag 2934
create vlan "VLAN2935" tag 2935
create vlan "VLAN2936" tag 2936
create vlan "VLAN2937" tag 2937
create vlan "VLAN2938" tag 2938
create vlan "VLAN2939" tag 2939
create vlan "VLAN2940" tag 2940
create vlan "VLAN2941" tag 2941
create vlan "VLAN2942" tag 2942
create vlan "VLAN2943" tag 2943
create vlan "VLAN2944" tag 2944
create vlan "VLAN2945" tag 2945
create vlan "VLAN2946" tag 2946
create vlan "VLAN2947" tag 2947
create vlan "VLAN3100" tag 3100
create vlan "VLAN3105" tag 3105
create vlan "VLAN3110" tag 3110
create vlan "VLAN3115" tag 3115
create vlan "VLAN3120" tag 3120
create vlan "VLAN3124" tag 3124
create vlan "VLAN3128" tag 3128
create vlan "VLAN3132" tag 3132
create vlan "VLAN3136" tag 3136
create vlan "VLAN3140" tag 3140
create vlan "VLAN3144" tag 3144
create vlan "VLAN3148" tag 3148
create vlan "VLAN3152" tag 3152
create vlan "VLAN3156" tag 3156
create vlan "VLAN3159" tag 3159
create vlan "VLAN3160" tag 3160
create vlan "VLAN3161" tag 3161
create vlan "VLAN3164" tag 3164
create vlan "VLAN3168" tag 3168
create vlan "VLAN3172" tag 3172
create vlan "VLAN3176" tag 3176
create vlan "VLAN3180" tag 3180
create vlan "VLAN3185" tag 3185
create vlan "VLAN3190" tag 3190
create vlan "VLAN3195" tag 3195
create vlan "VLAN3200" tag 3200
create vlan "VLAN3205" tag 3205
create vlan "VLAN3210" tag 3210
create vlan "VLAN3215" tag 3215
create vlan "VLAN3220" tag 3220
create vlan "VLAN3225" tag 3225
create vlan "VLAN3228" tag 3228
create vlan "VLAN3230" tag 3230
create vlan "VLAN3235" tag 3235
create vlan "VLAN3240" tag 3240
create vlan "VLAN3245" tag 3245
create vlan "VLAN3250" tag 3250
create vlan "VLAN3255" tag 3255
create vlan "VLAN3260" tag 3260
create vlan "VLAN3262" tag 3262
create vlan "VLAN3265" tag 3265
create vlan "VLAN3270" tag 3270
create vlan "VLAN3275" tag 3275
create vlan "VLAN3280" tag 3280
create vlan "VLAN3285" tag 3285
create vlan "VLAN3290" tag 3290
create vlan "VLAN3295" tag 3295
create vlan "VLAN3300" tag 3300
create vlan "VLAN3305" tag 3305
create vlan "VLAN3310" tag 3310
create vlan "VLAN3315" tag 3315
create vlan "VLAN3320" tag 3320
create vlan "VLAN3325" tag 3325
create vlan "VLAN3330" tag 3330
create vlan "VLAN3335" tag 3335
create vlan "VLAN3340" tag 3340
create vlan "VLAN3345" tag 3345
create vlan "VLAN3355" tag 3355
create vlan "VLAN3365" tag 3365
create vlan "VLAN3370" tag 3370
create vlan "VLAN3375" tag 3375
create vlan "VLAN3380" tag 3380
create vlan "VLAN3385" tag 3385
create vlan "VLAN3390" tag 3390
create vlan "VLAN3395" tag 3395
create vlan "VLAN3400" tag 3400
create vlan "VLAN3405" tag 3405
create vlan "VLAN3409" tag 3409
create vlan "VLAN3410" tag 3410
create vlan "VLAN3411" tag 3411
create vlan "VLAN3412" tag 3412
create vlan "VLAN3414" tag 3414
create vlan "VLAN3420" tag 3420
create vlan "VLAN3430" tag 3430
create vlan "VLAN3435" tag 3435
create vlan "VLAN3440" tag 3440
create vlan "VLAN3450" tag 3450
config vlan vlanid 1-2,4,12,15,58,60,113,115,210,235,238,275,465,757,831,963,1100,1111,1500 delete 1-52
config vlan vlanid 2065,2183,2500,2924-2947,3100,3105,3110,3115,3120,3124,3128,3132,3136,3140 delete 1-52
config vlan vlanid 3144,3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200 delete 1-52
config vlan vlanid 3205,3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265 delete 1-52
config vlan vlanid 3270,3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325,3330,3335,3340 delete 1-52
config vlan vlanid 3345,3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420 delete 1-52
config vlan vlanid 3430,3435,3440,3450 delete 1-52
config vlan vlanid 1-2,4,12,15,58,60,113,115,210,235,238,275,465,757,831,963,1100,1111,1500 advertisement disable
config vlan vlanid 2065,2183,2500,2924-2947,3100,3105,3110,3115,3120,3124,3128,3132,3136,3140 advertisement disable
config vlan vlanid 3144,3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200 advertisement disable
config vlan vlanid 3205,3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265 advertisement disable
config vlan vlanid 3270,3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325,3330,3335,3340 advertisement disable
config vlan vlanid 3345,3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420 advertisement disable
config vlan vlanid 3430,3435,3440,3450 advertisement disable
config vlan vlanid 2,4,12,15,58,60,113,115,210,235,238,275,465,757,831,963,1100,1111,1500,2065 add tagged 48-52
config vlan vlanid 2183,2500,2924-2947,3100,3105,3110,3115,3120,3124,3128,3132,3136,3140,3144 add tagged 48-52
config vlan vlanid 3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200,3205 add tagged 48-52
config vlan vlanid 3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265,3270 add tagged 48-52
config vlan vlanid 3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325,3330,3335,3340,3345 add tagged 48-52
config vlan vlanid 3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420,3430 add tagged 48-52
config vlan vlanid 3435,3440,3450 add tagged 48-52
config vlan vlanid 4 add untagged 47
enable pvid auto_assign
config vlan_auto_learn vlanid 4089-4096 disable

# IMPBv2
disable address_binding dhcp_snoop ports 1-52 all
config address_binding ip_mac ports 1-52 arp_inspection disable nd_inspection disable ip_inspection disable protocol all state disable allow_zeroip disable forward_dhcppkt enable
config address_binding dhcp_snoop max_entry ports 1-52 limit no_limit
config address_binding dhcp_snoop max_entry ports 1-52 limit no_limit IPv6
enable address_binding roaming
config address_binding vlan vlan_mode state disable
config address_binding ip_mac log all
disable address_binding dhcp_pd_snoop
config filter dhcp_server illegal_server_log_suppress_duration 5min

# IP
config ipif System state enable
config ipif System ipaddress 10.2.6.165/255.255.0.0
create iproute default 10.2.0.1 1
disable jumbo_frame
config ipif System dhcp_option12 state disable
config ipif System dhcp_option12 hostname DGS-1210-52/ME
config ipif System dhcpv6_client disable
config ipv6 nd ns ipif System retrans_time 1
enable ipif_ipv6_link_local_auto System
config ipif System ipv6 state enable
disable autoconfig
config autoconfig timeout 50
disable autoimage

# STP
disable stp
config stp version rstp
config stp priority 32768 instance_id 0
config stp txholdcount 6 maxage 20 hellotime 2 forwarddelay 15
config stp fbpdu enable
config stp ports 1-52 externalcost auto edge auto restricted_tcn false restricted_role false p2p auto state enable priority 128 fbpdu enable
config stp mst_config_id name 70:62:b8:9d:62:3e revision_level 0
config stp trap new_root disable
config stp trap topo_change disable
disable address_binding trap_log

# Multi Interface
config ipif System vlan mgmt

# traffic segmentation
config traffic_segmentation 1-52 forward_list 1-52

# LLDP
enable lldp
config lldp message_tx_hold_multiplier 4
config lldp message_tx_interval 30
config lldp reinit_delay 2
config lldp tx_delay 2
config lldp ports 1-52 mgt_addr ipv4 10.2.6.165 disable
config lldp ports 1-52 mgt_addr ipv6 fe80::7262:b8ff:fe9d:623e disable
config lldp ports 1-52 admin_status tx_and_rx
config lldp ports 1-52 notification disable
config lldp ports 1-52 basic_tlvs all disable
config lldp ports 1-52 dot1_tlv_pvid disable
config lldp ports 1-52 dot1_tlv_vlan_name vlanid 1-4094 disable
config lldp ports 1-52 dot1_tlv_protocol_identity eapol disable
config lldp ports 1-52 dot1_tlv_protocol_identity lacp disable
config lldp ports 1-52 dot1_tlv_protocol_identity gvrp disable
config lldp ports 1-52 dot1_tlv_protocol_identity stp disable
config lldp ports 1-52 dot3_tlvs all disable

# QoS
config scheduling_mechanism strict
config scheduling 0 weight 1
config scheduling 1 weight 2
config scheduling 2 weight 3
config scheduling 3 weight 4
config scheduling 4 weight 5
config scheduling 5 weight 6
config scheduling 6 weight 7
config scheduling 7 weight 8
config 802.1p default_priority 1-52 0
config 802.1p user_priority 0 2
config 802.1p user_priority 1 0
config 802.1p user_priority 2 1
config 802.1p user_priority 3 3
config 802.1p user_priority 4 4
config 802.1p user_priority 5 5
config 802.1p user_priority 6 6
config 802.1p user_priority 7 7
config dscp_mapping dscp_value 0 class 0
config dscp_mapping dscp_value 1 class 0
config dscp_mapping dscp_value 2 class 0
config dscp_mapping dscp_value 3 class 0
config dscp_mapping dscp_value 4 class 0
config dscp_mapping dscp_value 5 class 0
config dscp_mapping dscp_value 6 class 0
config dscp_mapping dscp_value 7 class 0
config dscp_mapping dscp_value 8 class 0
config dscp_mapping dscp_value 9 class 0
config dscp_mapping dscp_value 10 class 0
config dscp_mapping dscp_value 11 class 0
config dscp_mapping dscp_value 12 class 0
config dscp_mapping dscp_value 13 class 0
config dscp_mapping dscp_value 14 class 0
config dscp_mapping dscp_value 15 class 0
config dscp_mapping dscp_value 16 class 0
config dscp_mapping dscp_value 17 class 0
config dscp_mapping dscp_value 18 class 0
config dscp_mapping dscp_value 19 class 0
config dscp_mapping dscp_value 20 class 0
config dscp_mapping dscp_value 21 class 0
config dscp_mapping dscp_value 22 class 0
config dscp_mapping dscp_value 23 class 0
config dscp_mapping dscp_value 24 class 0
config dscp_mapping dscp_value 25 class 0
config dscp_mapping dscp_value 26 class 0
config dscp_mapping dscp_value 27 class 0
config dscp_mapping dscp_value 28 class 0
config dscp_mapping dscp_value 29 class 0
config dscp_mapping dscp_value 30 class 0
config dscp_mapping dscp_value 31 class 0
config dscp_mapping dscp_value 32 class 0
config dscp_mapping dscp_value 33 class 0
config dscp_mapping dscp_value 34 class 0
config dscp_mapping dscp_value 35 class 0
config dscp_mapping dscp_value 36 class 0
config dscp_mapping dscp_value 37 class 0
config dscp_mapping dscp_value 38 class 0
config dscp_mapping dscp_value 39 class 0
config dscp_mapping dscp_value 40 class 0
config dscp_mapping dscp_value 41 class 0
config dscp_mapping dscp_value 42 class 0
config dscp_mapping dscp_value 43 class 0
config dscp_mapping dscp_value 44 class 0
config dscp_mapping dscp_value 45 class 0
config dscp_mapping dscp_value 46 class 0
config dscp_mapping dscp_value 47 class 0
config dscp_mapping dscp_value 48 class 0
config dscp_mapping dscp_value 49 class 0
config dscp_mapping dscp_value 50 class 0
config dscp_mapping dscp_value 51 class 0
config dscp_mapping dscp_value 52 class 0
config dscp_mapping dscp_value 53 class 0
config dscp_mapping dscp_value 54 class 0
config dscp_mapping dscp_value 55 class 0
config dscp_mapping dscp_value 56 class 0
config dscp_mapping dscp_value 57 class 0
config dscp_mapping dscp_value 58 class 0
config dscp_mapping dscp_value 59 class 0
config dscp_mapping dscp_value 60 class 0
config dscp_mapping dscp_value 61 class 0
config dscp_mapping dscp_value 62 class 0
config dscp_mapping dscp_value 63 class 0
config cos mapping port 1-52 none
config cos mapping port 1-52 802.1p
config cos mapping port 1-52 dscp
config cos tos value 0 class 0
config cos tos value 1 class 0
config cos tos value 2 class 0
config cos tos value 3 class 0
config cos tos value 4 class 0
config cos tos value 5 class 0
config cos tos value 6 class 0
config cos tos value 7 class 0
config dscp mode
config bandwidth_control 1-52 rx_rate no_limit tx_rate no_limit

# FDB (forwarding data base)
enable auto learning

# Syslog
enable syslog
config log_save_timing on_demand
create syslog host 1 ipaddress 10.1.1.5 severity all facility local2 udp_port 514 state enable

# ACL

# SNMP
enable snmp
disable community_encryption
create snmp user ReadOnly ReadOnly v1
create snmp user ReadOnly ReadOnly v2c
create snmp user ReadWrite ReadWrite v1
create snmp user ReadWrite ReadWrite v2c
create snmp group ReadOnly v1 read_view ReadWrite notify_view ReadWrite
create snmp group ReadOnly v2c read_view ReadWrite notify_view ReadWrite
create snmp group ReadWrite v1 read_view ReadWrite write_view ReadWrite notify_view ReadWrite
create snmp group ReadWrite v2c read_view ReadWrite write_view ReadWrite notify_view ReadWrite
create snmp view ReadWrite 1 1 view_type included
create snmp community public ReadOnly
create snmp community private ReadWrite
create snmp host 10.1.1.5 v2c public
config snmp engineID 4447532d313231302d35327062b89d623e
disable snmp authenticate traps
config snmp coldstart_traps enable
config snmp warmstart_traps enable
enable snmp linkchange_traps
config snmp linkchange_traps ports 1-52 enable
enable snmp rstpport_state_change traps
enable snmp firmware_upgrade_state traps
enable snmp port_security_violation traps
enable snmp IMPB_violation traps
enable snmp LBD traps
enable snmp DHCP_screening traps
enable snmp duplicate_IP_detected traps

# IPv6 Neighbor_cache

# MAC address table notification
disable mac_notification
config mac_notification interval 1
config mac_notification historysize 1
config mac_notification ports 1-52 disable

# SNTP
config sntp primary 10.1.1.5 secondary 0.0.0.0 poll-interval 720
enable sntp
config time_zone operator + hour 3 minute 0
config dst annual s_mth 1 s_date 1 s_time 00:00 e_mth 1 e_date 1 e_time 00:00 offset 60
config dst repeat s_mth 3 s_week 1 s_day sun s_time 02:00 e_mth 10 e_week last e_day sun e_time 02:00 offset 60

# DHCP_RELAY
disable dhcp_relay
config dhcp_relay hops 4
config dhcp_relay time 0
config dhcp_relay port 1-52 state disable
config dhcp_relay port 1-52 state enable
config dhcp_relay vlan vlanid 2,4,8,12,15,58,60,113,115 state disable
config dhcp_relay vlan vlanid 1 state enable
config dhcp_relay vlan vlanid 210,235,238 state disable
config dhcp_relay vlan vlanid 275 state disable
config dhcp_relay vlan vlanid 465 state disable
config dhcp_relay vlan vlanid 757 state disable
config dhcp_relay vlan vlanid 831 state disable
config dhcp_relay vlan vlanid 963 state disable
config dhcp_relay vlan vlanid 1100,1111 state disable
config dhcp_relay vlan vlanid 1500 state disable
config dhcp_relay vlan vlanid 2065 state disable
config dhcp_relay vlan vlanid 2183 state disable
config dhcp_relay vlan vlanid 2500 state disable
config dhcp_relay vlan vlanid 2924-2944 state disable
config dhcp_relay vlan vlanid 2945-2947 state disable
config dhcp_relay vlan vlanid 3100,3105,3110,3115,3120,3124,3128,3132,3136,3140,3144,3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200 state disable
config dhcp_relay vlan vlanid 3205,3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265,3270,3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325 state disable
config dhcp_relay vlan vlanid 3330,3335,3340,3345,3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420,3430,3435,3440,3450 state disable
config dhcp_relay option_82 state enable
config dhcp_relay option_82 check disable
config dhcp_relay option_82 policy replace
config dhcp_relay option_82 remote_id default
config dhcp_relay option_82 circuit_id default
disable dhcp_local_relay
disable dhcpv6_relay
config dhcpv6_relay hop_count 4
config dhcpv6_relay option_37 state enable
config dhcpv6_relay option_37 check enable
config dhcpv6_relay option_37 remote_id default
config dhcpv6_relay option_38 ports 1-52 state disable subscriber_id default
config dhcpv6_relay option_18 state enable
config dhcpv6_relay option_18 check enable
config dhcpv6_relay option_18 interface_id default

# GVRP
disable gvrp
config gvrp 1-46,48-52 pvid 1
config gvrp 1-52 state disable
config gvrp 1-52 ingress_checking enable
config gvrp 1-52 acceptable_frame All_Frames
config gvrp 47 pvid 4
config gvrp timer join_timer 200
config gvrp timer leave_timer 600
config gvrp timer leave-all_timer 10000

# Loopback Detection
disable loopdetect

# Power Saving
config power_saving mode led disable
config power_saving led add time_range1 time_range2
config power_saving mode port disable
config power_saving port add time_range1 time_range2
config power_saving mode hibernation disable
config power_saving hibernation add time_range1
config power_saving hibernation add time_range2
config power_saving mode link_detection disable

# BPDU Attack Protection
disable bpdu_protection
config bpdu_protection recovery_timer 60
config bpdu_protection ports 1-52 state disable mode shutdown
config bpdu_protection trap none
config bpdu_protection log none

# SMTP
disable smtp
config smtp server 0.0.0.0 server_port 25

# traffic control
config traffic trap none
config traffic control 1-52 broadcast disable multicast disable unicast disable action drop

# RMON
disable rmon

# ISM vlan
enable igmp_snooping multicast_vlan
create igmp_snooping multicast_vlan "mcast" 8
config igmp_snooping multicast_vlan "mcast" add member_port 1-47
config igmp_snooping multicast_vlan "mcast" add source_port 48-52
config igmp_snooping multicast_vlan "mcast" state enable
config igmp_snooping multicast_vlan "mcast" replace_source_ip 10.2.6.165
config mld_snooping multicast_vlan "mcast" replace_source_ipv6 none
config igmp_snooping multicast_vlan "mcast" remap_priority none
config igmp_snooping multicast_vlan_group "mcast" add ipv4_range 239.1.1.1 239.1.1.254

# IGMP snooping
enable igmp_snooping
config igmp_snooping all router_timeout 125
config igmp_snooping all host_timeout 260
config igmp_snooping data_driven_learning max_learned_entry 256
disable igmp_snooping forward_mcrouter_only
config igmp_snooping vlanid 1-2,4,12,15,58,60,113,115,210,235,238,275,465,757,831,963,1100,1111,1500 state disable fast_leave disable report_suppression enable
config igmp_snooping vlanid 2065,2183,2500,2924-2947,3100,3105,3110,3115,3120,3124,3128,3132,3136,3140 state disable fast_leave disable report_suppression enable
config igmp_snooping vlanid 3144,3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200 state disable fast_leave disable report_suppression enable
config igmp_snooping vlanid 3205,3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265 state disable fast_leave disable report_suppression enable
config igmp_snooping vlanid 3270,3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325,3330,3335,3340 state disable fast_leave disable report_suppression enable
config igmp_snooping vlanid 3345,3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420 state disable fast_leave disable report_suppression enable
config igmp_snooping vlanid 3430,3435,3440,3450 state disable fast_leave disable report_suppression enable
config igmp_snooping vlanid 8 state enable fast_leave disable report_suppression enable
config igmp_snooping data_driven_learning vlanid 1-2,4,8,12,15,58,60,113,115,210,235,238,275,465,757,831,963,1100,1111,1500 state disable
config igmp_snooping data_driven_learning vlanid 2065,2183,2500,2924-2947,3100,3105,3110,3115,3120,3124,3128,3132,3136,3140 state disable
config igmp_snooping data_driven_learning vlanid 3144,3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200 state disable
config igmp_snooping data_driven_learning vlanid 3205,3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265 state disable
config igmp_snooping data_driven_learning vlanid 3270,3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325,3330,3335,3340 state disable
config igmp_snooping data_driven_learning vlanid 3345,3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420 state disable
config igmp_snooping data_driven_learning vlanid 3430,3435,3440,3450 state disable
config igmp_snooping data_driven_learning vlanid 1-2,4,8,12,15,58,60,113,115,210,235,238,275,465,757,831,963,1100,1111,1500 aged_out disable
config igmp_snooping data_driven_learning vlanid 2065,2183,2500,2924-2947,3100,3105,3110,3115,3120,3124,3128,3132,3136,3140 aged_out disable
config igmp_snooping data_driven_learning vlanid 3144,3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200 aged_out disable
config igmp_snooping data_driven_learning vlanid 3205,3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265 aged_out disable
config igmp_snooping data_driven_learning vlanid 3270,3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325,3330,3335,3340 aged_out disable
config igmp_snooping data_driven_learning vlanid 3345,3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420 aged_out disable
config igmp_snooping data_driven_learning vlanid 3430,3435,3440,3450 aged_out disable
config igmp_snooping querier vlanid 1-2,4,8,12,15,58,60,113,115,210,235,238,275,465,757,831,963,1100,1111,1500 state disable querier_version 2 last_member_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config igmp_snooping querier vlanid 2065,2183,2500,2924-2947,3100,3105,3110,3115,3120,3124,3128,3132,3136,3140 state disable querier_version 2 last_member_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config igmp_snooping querier vlanid 3144,3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200 state disable querier_version 2 last_member_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config igmp_snooping querier vlanid 3205,3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265 state disable querier_version 2 last_member_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config igmp_snooping querier vlanid 3270,3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325,3330,3335,3340 state disable querier_version 2 last_member_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config igmp_snooping querier vlanid 3345,3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420 state disable querier_version 2 last_member_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config igmp_snooping querier vlanid 3430,3435,3440,3450 state disable querier_version 2 last_member_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config router_ports vlan_name "mcast" add 48-52
config igmp access_authentication ports 1-52 state disable

# MLD Snooping
disable mld_snooping
config mld_snooping all router_timeout 125
config mld_snooping all host_timeout 260
config mld_snooping data_driven_learning max_learned_entry 256
config mld_snooping vlanid 1-2,4,12,15,58,60,113,115,210,235,238,275,465,757,831,963,1100,1111,1500 state disable fast_done disable
config mld_snooping vlanid 2065,2183,2500,2924-2947,3100,3105,3110,3115,3120,3124,3128,3132,3136,3140 state disable fast_done disable
config mld_snooping vlanid 3144,3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200 state disable fast_done disable
config mld_snooping vlanid 3205,3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265 state disable fast_done disable
config mld_snooping vlanid 3270,3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325,3330,3335,3340 state disable fast_done disable
config mld_snooping vlanid 3345,3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420 state disable fast_done disable
config mld_snooping vlanid 3430,3435,3440,3450 state disable fast_done disable
config mld_snooping vlanid 8 state enable fast_done disable
config mld_snooping data_driven_learning vlanid 1-2,4,8,12,15,58,60,113,115,210,235,238,275,465,757,831,963,1100,1111,1500 state disable
config mld_snooping data_driven_learning vlanid 2065,2183,2500,2924-2947,3100,3105,3110,3115,3120,3124,3128,3132,3136,3140 state disable
config mld_snooping data_driven_learning vlanid 3144,3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200 state disable
config mld_snooping data_driven_learning vlanid 3205,3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265 state disable
config mld_snooping data_driven_learning vlanid 3270,3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325,3330,3335,3340 state disable
config mld_snooping data_driven_learning vlanid 3345,3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420 state disable
config mld_snooping data_driven_learning vlanid 3430,3435,3440,3450 state disable
config mld_snooping querier vlanid 1-2,4,8,12,15,58,60,113,115,210,235,238,275,465,757,831,963,1100,1111,1500 state disable version 2 last_listener_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config mld_snooping querier vlanid 2065,2183,2500,2924-2947,3100,3105,3110,3115,3120,3124,3128,3132,3136,3140 state disable version 2 last_listener_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config mld_snooping querier vlanid 3144,3148,3152,3156,3159-3161,3164,3168,3172,3176,3180,3185,3190,3195,3200 state disable version 2 last_listener_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config mld_snooping querier vlanid 3205,3210,3215,3220,3225,3228,3230,3235,3240,3245,3250,3255,3260,3262,3265 state disable version 2 last_listener_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config mld_snooping querier vlanid 3270,3275,3280,3285,3290,3295,3300,3305,3310,3315,3320,3325,3330,3335,3340 state disable version 2 last_listener_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config mld_snooping querier vlanid 3345,3355,3365,3370,3375,3380,3385,3390,3395,3400,3405,3409-3412,3414,3420 state disable version 2 last_listener_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config mld_snooping querier vlanid 3430,3435,3440,3450 state disable version 2 last_listener_query_interval 1 max_response_time 10 query_interval 125 robustness_variable 2
config mld_snooping mrouter_ports vlan_name "mcast" add 48-52

# Multicast Filter
config multicast vlan_filtering_mode vlan "default" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "mgmt" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "adtv" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "mcast" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN12" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN15" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN58" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN60" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN113" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN115" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN210" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN235" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN238" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN275" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN465" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN757" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN831" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN963" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN1100" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN1111" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN1500" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2065" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2183" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2500" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2924" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2925" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2926" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2927" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2928" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2929" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2930" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2931" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2932" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2933" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2934" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2935" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2936" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2937" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2938" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2939" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2940" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2941" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2942" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2943" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2944" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2945" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2946" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN2947" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3100" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3105" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3110" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3115" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3120" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3124" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3128" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3132" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3136" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3140" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3144" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3148" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3152" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3156" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3159" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3160" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3161" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3164" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3168" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3172" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3176" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3180" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3185" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3190" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3195" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3200" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3205" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3210" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3215" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3220" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3225" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3228" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3230" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3235" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3240" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3245" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3250" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3255" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3260" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3262" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3265" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3270" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3275" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3280" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3285" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3290" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3295" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3300" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3305" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3310" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3315" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3320" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3325" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3330" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3335" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3340" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3345" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3355" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3365" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3370" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3375" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3380" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3385" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3390" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3395" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3400" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3405" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3409" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3410" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3411" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3412" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3414" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3420" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3430" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3435" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3440" forward_unregistered_groups
config multicast vlan_filtering_mode vlan "VLAN3450" forward_unregistered_groups

# 8021X
disable 802.1x
config 802.1x auth_mode port_based
config 802.1x auth_protocol local
config 802.1x feap enable
config 802.1x capability ports 1-52 none
config 802.1x auth_parameter ports 1-52 port_control force_auth
config 802.1x auth_parameter ports 1-52 direction both quiet_period 60 tx_period 30 supp_timeout 30 server_timeout 30 max_req 2 reauth_period 3600 enable_reauth disable

# port mirroring

# trusted host
disable trusted_host

# SSL
disable ssl ciphersuite RSA-NULL-MD5 RSA-NULL-SHA1 RSA-DES-SHA1 RSA-3DES-SHA1 DH-RSA-DES-SHA1 DH-RSA-3DES-SHA1 RSA-EXP1024-DES-SHA1

# SSH
disable ssh
config ssh server authfail 2
config ssh server rekey 60min
config ssh server maxsession 4
config ssh server contimeout 120
config ssh authmode password disable
config ssh authmode publickey disable
config ssh authmode hostbased disable
config ssh algorithm 3DES enable
config ssh algorithm MD5 enable
config ssh algorithm SHA1 enable
config ssh algorithm RSA enable

# access authentication control
disable authen_policy
disable aaa_server_password_encryption
config authen parameter response_timeout 30
config authen parameter attempt 3
create authen server_group tacacs+
create authen server_group radius
create authen_login method_list_name default
config authen_login default method local
create authen_enable method_list_name default
config authen_enable default method none
config authen application console login method_list_name default
config authen application telnet login method_list_name default
config authen application ssh login method_list_name default
config authen application http login method_list_name default
config authen application console enable method_list_name default
config authen application telnet enable method_list_name default
config authen application ssh enable method_list_name default
config authen application http enable method_list_name default

# PPPoE
config pppoe circuit_id_insertion state disable
config pppoe circuit_id_insertion ports 1-52 circuit_id ip state disable
config pppoe circuit_id_insertion ports 1-52 remote_id default

# safeguard_engine
config safeguard_engine state enable
disable command logging

# QinQ
config qinq inner_tpid 0x8100
config qinq ports 1-52 role nni missdrop disable outer_tpid 0x88a8 add_inner_tag disable
disable qinq
disable vlan_trunk

# Ethernet OAM
config ethernet_oam ports 1-52 state disable mode active remote_loopback stop received_remote_loopback ignore
config ethernet_oam ports 1-52 critical_link_event dying_gasp notify_state enable
config ethernet_oam ports 1-52 critical_link_event critical_event notify_state enable
config ethernet_oam ports 1-52 link_monitor error_symbol threshold 1 window 1000 notify_state enable
config ethernet_oam ports 1-52 link_monitor error_frame threshold 1 window 1000 notify_state enable
config ethernet_oam ports 1-52 link_monitor error_frame_seconds threshold 1 window 60000 notify_state enable
config ethernet_oam ports 1-52 link_monitor error_frame_period threshold 1 window 1488100 notify_state enable

# DULD
config duld ports 1-52 state disable mode normal discovery_time 5
config duld recover_timer 60

# port security
config port_security 1-52 admin_state disable max_learning_addr 0 lock_address_mode DeleteOnTimeout

# LACP
config link_aggregation state disable
config link_aggregation algorithm mac_source
config lacp port_priority 1-52 128 timeout long
config lacp_ports 1-52 mode active

# Limited IP Multicast
config max_mcast_group ports 1-52 ipv4 max_group 256
config max_mcast_group ports 1-52 ipv6 max_group 256
config limited_multicast_addr ports 1-52 ipv4 access permit
config limited_multicast_addr ports 1-52 ipv6 access permit

# DoS Prevention
config dos_prevention dos_type land_attack action drop state disable
config dos_prevention dos_type blat_attack action drop state disable
config dos_prevention dos_type tcp_null_scan action drop state disable
config dos_prevention dos_type tcp_xmascan action drop state disable
config dos_prevention dos_type tcp_synfin action drop state disable
config dos_prevention dos_type tcp_syn_srcport_less_1024 action drop state disable
config dos_prevention dos_type ping_death_attack action drop state disable
config dos_prevention dos_type tcp_tiny_frag_attack action drop state disable
disable dos_prevention trap_log

# DDM
config ddm power_unit mw
config ddm ports 49-52 state disable
config ddm ports 49-52 shutdown none
config ddm ports 49-52 temperature_threshold high_alarm +95.000 low_alarm -25.000 high_warning +90.000 low_warning -20.000
config ddm ports 49-52 voltage_threshold high_alarm 3.80 low_alarm 2.80 high_warning 3.70 low_warning 2.90
config ddm ports 49-52 bias_current_threshold high_alarm 20.0 low_alarm 0.5 high_warning 18.0 low_warning 1.0
config ddm ports 49-52 tx_power_threshold high_alarm 1.5900 low_alarm 0.1599 high_warning 1.2599 low_warning 0.2000
config ddm ports 49-52 rx_power_threshold high_alarm 1.2599 low_alarm 0.0099 high_warning 1.0000 low_warning 0.0126

# Flood FDB
disable flood_fdb

# L2 Protocol Tunnel
disable l2protocol_tunnel

# Cpu Protection
disable cpu_protect
config cpu_protect type arp pps no_limit
config cpu_protect type bpdu pps no_limit
config cpu_protect type icmp pps no_limit
config cpu_protect type igmp pps no_limit
config cpu_protect type snmp pps no_limit

# MAC-based VLAN
config mac_based_vlan method single

# Accounting
create accounting method_list_name default
config accounting default method none
config accounting service network state disable
config accounting service shell state disable
config accounting service system state disable
config accounting service command administrator none
config accounting service command operator none
config accounting service command power_user none
config accounting service command user none

# Energy Efficient Ethernet
config EEE port 1 state disable
config EEE port 2 state disable
config EEE port 3 state disable
config EEE port 4 state disable
config EEE port 5 state disable
config EEE port 6 state disable
config EEE port 7 state disable
config EEE port 8 state disable
config EEE port 9 state disable
config EEE port 10 state disable
config EEE port 11 state disable
config EEE port 12 state disable
config EEE port 13 state disable
config EEE port 14 state disable
config EEE port 15 state disable
config EEE port 16 state disable
config EEE port 17 state disable
config EEE port 18 state disable
config EEE port 19 state disable
config EEE port 20 state disable
config EEE port 21 state disable
config EEE port 22 state disable
config EEE port 23 state disable
config EEE port 24 state disable
config EEE port 25 state disable
config EEE port 26 state disable
config EEE port 27 state disable
config EEE port 28 state disable
config EEE port 29 state disable
config EEE port 30 state disable
config EEE port 31 state disable
config EEE port 32 state disable
config EEE port 33 state disable
config EEE port 34 state disable
config EEE port 35 state disable
config EEE port 36 state disable
config EEE port 37 state disable
config EEE port 38 state disable
config EEE port 39 state disable
config EEE port 40 state disable
config EEE port 41 state disable
config EEE port 42 state disable
config EEE port 43 state disable
config EEE port 44 state disable
config EEE port 45 state disable
config EEE port 46 state disable
config EEE port 47 state disable
config EEE port 48 state disable
config EEE port 49 state disable
config EEE port 50 state disable
config EEE port 51 state disable
config EEE port 52 state disable

# port
config ports 1-52 capability_advertised 10_half 10_full 100_half 100_full 1000_full
config ports 1-48 speed auto state enable flow_control disable MDI/MDIX auto learning enable description ""
config ports 49-52 speed auto state enable flow_control disable learning enable description ""
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control
disable global flow control

# DDP
disable ddp
config ddp report state disable
config ddp report timer 30
config ddp ports 1 state disable
config ddp ports 2 state disable
config ddp ports 3 state disable
config ddp ports 4 state disable
config ddp ports 5 state disable
config ddp ports 6 state disable
config ddp ports 7 state disable
config ddp ports 8 state disable
config ddp ports 9 state disable
config ddp ports 10 state disable
config ddp ports 11 state disable
config ddp ports 12 state disable
config ddp ports 13 state disable
config ddp ports 14 state disable
config ddp ports 15 state disable
config ddp ports 16 state disable
config ddp ports 17 state disable
config ddp ports 18 state disable
config ddp ports 19 state disable
config ddp ports 20 state disable
config ddp ports 21 state disable
config ddp ports 22 state disable
config ddp ports 23 state disable
config ddp ports 24 state disable
config ddp ports 25 state disable
config ddp ports 26 state disable
config ddp ports 27 state disable
config ddp ports 28 state disable
config ddp ports 29 state disable
config ddp ports 30 state disable
config ddp ports 31 state disable
config ddp ports 32 state disable
config ddp ports 33 state disable
config ddp ports 34 state disable
config ddp ports 35 state disable
config ddp ports 36 state disable
config ddp ports 37 state disable
config ddp ports 38 state disable
config ddp ports 39 state disable
config ddp ports 40 state disable
config ddp ports 41 state disable
config ddp ports 42 state disable
config ddp ports 43 state disable
config ddp ports 44 state disable
config ddp ports 45 state disable
config ddp ports 46 state disable
config ddp ports 47 state disable
config ddp ports 48 state disable
config ddp ports 49 state disable
config ddp ports 50 state disable
config ddp ports 51 state disable
config ddp ports 52 state disable
command-end


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Пн апр 20, 2015 22:13 
Не в сети

Зарегистрирован: Пн мар 28, 2011 12:50
Сообщений: 282
Откуда: Санкт-Петербург
Прошивка 6.11.B52
коммутатор периодически становится недоступным (статический ip)
Нет ответа даже на ARP запросы. В логах тихо.

Заметил, что время начинает отставать, не смотря на то, что работает sntp.
5 минут на 3 часа работы - это слишком много.


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Вт апр 21, 2015 08:13 
Не в сети

Зарегистрирован: Чт апр 16, 2015 16:58
Сообщений: 6
В моём случае есть идеи из-за чего дропаются пакеты на аплинке и почему на юзерском порту появляются "отложенные" (Excessive Deferral - количество пакетов, первая попытка отправки которых была отложена по причине занятости среды передачи) пакеты ? На данный момент вышестоящий коммутатор D-Link DGS-3120-24SC.

48 порт - Аплинк
47 порт - Юзерский
Вчера:
Код:
Port Number : 48
                 RX Frames                                  TX Frames
                 ---------                                  ---------
 CRC Error       0                    Excessive Deferral    140       
 Undersize       0                    CRC Error             0         
 Oversize        0                    Late Collision        0         
 Fragment        0                    Excessive Collision   0         
 Jabber          0                    Single Collision      0         
 Drop Pkts       965171               Collision             0         


 Port Number : 47
                 RX Frames                                  TX Frames
                 ---------                                  ---------
 CRC Error       0                    Excessive Deferral    76911     
 Undersize       0                    CRC Error             0         
 Oversize        0                    Late Collision        0         
 Fragment        0                    Excessive Collision   0         
 Jabber          0                    Single Collision      0         
 Drop Pkts       5235                 Collision             0       


Сегодня:
Код:
 Port Number : 48
                 RX Frames                                  TX Frames
                 ---------                                  ---------
 CRC Error       0                    Excessive Deferral    140       
 Undersize       0                    CRC Error             0         
 Oversize        0                    Late Collision        0         
 Fragment        0                    Excessive Collision   0         
 Jabber          0                    Single Collision      0         
 Drop Pkts       1756280              Collision             0         


 Port Number : 47
                 RX Frames                                  TX Frames
                 ---------                                  ---------
 CRC Error       0                    Excessive Deferral    361253   
 Undersize       0                    CRC Error             0         
 Oversize        0                    Late Collision        0         
 Fragment        0                    Excessive Collision   0         
 Jabber          0                    Single Collision      0         
 Drop Pkts       5820                 Collision             0


На замененном DES-3052 (которым заменили эти DGSы) на данный момент нет ни одной ошибки на портах, дело не в сети.
Я пока не заметил ухудшения в работе сети у себя но эти ошибки немножко напрягают.


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Вт апр 21, 2015 11:53 
Не в сети

Зарегистрирован: Пн мар 28, 2011 12:50
Сообщений: 282
Откуда: Санкт-Петербург
vel21ripn писал(а):
Прошивка 6.11.B52
коммутатор периодически становится недоступным (статический ip)
Нет ответа даже на ARP запросы. В логах тихо.

Уточнение: не помогло ни создание arp-entry, ни static-mac.

Запустил arping с интервалом в 5 сек.
На коммутаторе перестает работать IP с периодом примерно 10 минут. ~5 минут работает, ~5 минут недоступен. telnet при этом не обрывается. Потом все становится хуже и хуже, и через несколько часов перестает отвечать вообще.
Скрытый текст: показать
03:00:05 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2.710ms
...
03:02:10 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 3.090ms
03:02:15 TIMEOUT
...
03:11:25 TIMEOUT
03:11:30 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 3548.326ms
...
03:20:25 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2.448ms
03:20:30 TIMEOUT
...
03:31:35 TIMEOUT
03:31:40 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2936.473ms
...
03:42:55 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2.305ms
03:43:00 TIMEOUT
...
03:52:10 TIMEOUT
03:52:15 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2010.821ms
...
03:58:50 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2.599ms
03:58:55 TIMEOUT
...
04:07:40 TIMEOUT
04:07:45 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 1424.288ms
...
04:17:10 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2.782ms
04:17:15 TIMEOUT
...
04:26:10 TIMEOUT
04:26:15 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 4730.606ms
...
04:37:45 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 6.815ms
04:37:50 TIMEOUT
...
04:50:45 TIMEOUT
04:50:50 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 501.856ms
...
05:00:50 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2.584ms
05:00:55 TIMEOUT
...
05:09:50 TIMEOUT
05:09:55 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 4313.110ms
...
05:19:15 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2.426ms
05:19:20 TIMEOUT
...
05:30:25 TIMEOUT
05:30:30 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 896.542ms
...
05:37:40 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2.044ms
05:37:45 TIMEOUT
...
05:53:35 TIMEOUT
05:53:40 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 435.655ms
...
06:03:10 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 4.083ms
06:03:15 TIMEOUT
...
06:14:20 TIMEOUT
06:14:25 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2714.918ms
...
06:22:15 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 3.989ms
06:22:20 TIMEOUT
...
06:31:35 TIMEOUT
06:31:40 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 607.603ms
...
06:39:30 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 187.548ms
06:39:35 TIMEOUT
...
07:18:50 TIMEOUT
07:18:55 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 3899.435ms
...
07:26:45 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2.591ms
07:26:50 TIMEOUT
...
07:57:10 TIMEOUT
07:57:15 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2133.223ms
...
08:05:05 Unicast reply from 10.252.21.46 [B0:C5:54:F0:AF:D0] 2.919ms
08:05:10 TIMEOUT

За 11 часов 8270 запросов, 1420 ответов. Лог ответов на arp-запросы приложил.
Обратите внимание, что коммутатор принимает запросы и даже отвечает на последние 90 после восстановления.

В это время коммутатор с периодом в 2 минуты опрашивается через snmp (состояние портов + fdb)


Вложения:
10.252.21.46.arp.txt.gz [27.58 KiB]
Скачиваний: 622
Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Чт апр 23, 2015 16:42 
Не в сети

Зарегистрирован: Чт апр 16, 2015 16:58
Сообщений: 6
Купили один DES-1210-28/ME/B2 для тестов, подключили от DGS-1210-52/ME/A1 и вот что заметили.
На DES-1210-28 пункт с ошибками "FWD Disc Pkts" и в нем счётчик растёт так-же быстро как и в DGS-1210-52 в пункте "Drop Pkts". Скорее всего это одни и те-же пакеты, только в DESе их вынесли в отдельный раздел.

https://youtu.be/gK5SLfLJWZk


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Вт апр 28, 2015 16:16 
Не в сети

Зарегистрирован: Вт май 11, 2010 23:43
Сообщений: 11
Откуда: Москва
Здравствуйте!
Имеется девайс DGS-1210-28/ME А1 с прошивкой 6.11.B048.
В данной прошивке присутствуют проблемы в работе VLAN.
Может уже доступны новые прошивки? Нигде не могу найти.

Заранее благодарю.


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Вт апр 28, 2015 16:28 
Не в сети

Зарегистрирован: Вс май 22, 2005 10:19
Сообщений: 895
Откуда: Moscow
6.11.B052
viewtopic.php?f=2&t=92700


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Чт май 07, 2015 13:35 
Не в сети

Зарегистрирован: Вт окт 14, 2014 14:21
Сообщений: 30
Какие измненения в 56 прошивке?


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Пт май 08, 2015 11:21 
Не в сети

Зарегистрирован: Пн мар 28, 2011 12:50
Сообщений: 282
Откуда: Санкт-Петербург
Напомните кто-нибудь админам cloud.dlink.ru про просроченный серитфикат


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Пт май 08, 2015 16:12 
Не в сети
Сотрудник D-LINK
Сотрудник D-LINK

Зарегистрирован: Вт янв 18, 2011 13:29
Сообщений: 8999
Исправления прошивки b056 относительно b052
Скрытый текст: показать
1.Исправлена работа sntp при динамическом ip адресе на интерфейсе System
2.Исправлена работа 64bit счетчиков
3.Исправлена работа autoimage
4.Исправлена запись в лог при radius авторизации
5.Исправлен синтаксис создаения acl
6.Исправлены маски acl
7.Исправлена работа dhcp relay
8.Исправлен выбор querier при включенном replace source ip
9.Исправлена проблема с настройкой syslog
10.Исправлена работа bandwidth control
11.Исправлен вывод команды "show igmp_snooping group vlan"
12.Добавлен функционал traffic control auto recover


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Чт май 14, 2015 13:11 
Не в сети

Зарегистрирован: Вт окт 14, 2014 14:21
Сообщений: 30
Какие измненения в 57 прошивке? :)


Вернуться наверх
 Профиль  
 
 Заголовок сообщения: Re: DGS-1210/ME - проблемы и пожелания
СообщениеДобавлено: Пн май 18, 2015 18:08 
Не в сети

Зарегистрирован: Вс май 17, 2015 02:22
Сообщений: 5
Ребят, вопрос по CoS на основе порта коммутатора - позволяет назначить самому приоритет (0-7) на каждый физический порт? Хочу использоваться для NAS торрент качалке, чтобы не мешал просмотру видео и тп, т.е. чтобы NAS был в низком приоритете. Так же поставить наивысший приоритет для wifi точки.


Вернуться наверх
 Профиль  
 
Показать сообщения за:  Сортировать по:  
Начать новую тему Ответить на тему  [ Сообщений: 1355 ]  На страницу Пред.  1 ... 18, 19, 20, 21, 22, 23, 24 ... 91  След.

Часовой пояс: UTC + 3 часа


Кто сейчас на форуме

Сейчас этот форум просматривают: Bing [Bot], Google [Bot], Ivan Karbovskii и гости: 116


Вы не можете начинать темы
Вы не можете отвечать на сообщения
Вы не можете редактировать свои сообщения
Вы не можете удалять свои сообщения
Вы не можете добавлять вложения

Найти:
Перейти:  
Создано на основе phpBB® Forum Software © phpBB Group
Русская поддержка phpBB