Когда у абонента из за проблемы с кабелем начинает постоянно флапать порт в логах появляется сообщение вида:
%2SWPORT-W-LOCKPORTACTIVE: A packet with source MAC 00:11:22:33:44:56 tried to access through port gi1/0/13 which is locked
После этого порт перестает изучать MAC адрес.
Код: Выделить всё
04-Jun-2019 19:31:34 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:31:32 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:30:33 :%2SWPORT-W-LOCKPORTACTIVE: A packet with source MAC 00:11:22:33:44:56 tried to access through port gi1/0/13 which is locked
04-Jun-2019 19:30:15 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:30:13 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:29:33 :%2SWPORT-W-LOCKPORTACTIVE: A packet with source MAC 00:11:22:33:44:56 tried to access through port gi1/0/13 which is locked
04-Jun-2019 19:28:15 :%2SWPORT-W-LOCKPORTACTIVE: A packet with source MAC 00:11:22:33:44:56 tried to access through port gi1/0/13 which is locked
04-Jun-2019 19:26:56 :%2SWPORT-W-LOCKPORTACTIVE: A packet with source MAC 00:11:22:33:44:56 tried to access through port gi1/0/13 which is locked
04-Jun-2019 19:26:47 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:44 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:26:43 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:41 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:26:41 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:39 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:26:38 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:35 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:26:34 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:32 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:26:32 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:30 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:26:29 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:27 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:26:27 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:23 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:26:22 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:20 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:26:20 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:18 :%LINK-W-Down: gi1/0/13
04-Jun-2019 19:26:17 :%LINK-I-Up: gi1/0/13
04-Jun-2019 19:26:12 :%LINK-W-Down: gi1/0/13
Когда проблему с кабелем устраняем, порт по прежнему не изучает MAC. В логах все то же сообщение:
Код: Выделить всё
05-Jun-2019 14:47:13 :%2SWPORT-W-LOCKPORTACTIVE: A packet with source MAC 00:11:22:33:44:56 tried to access through port gi1/0/13 which is locked
05-Jun-2019 14:46:13 :%2SWPORT-W-LOCKPORTACTIVE: A packet with source MAC 00:11:22:33:44:56 tried to access through port gi1/0/13 which is locked
05-Jun-2019 14:45:04 :%2SWPORT-W-LOCKPORTACTIVE: A packet with source MAC 00:11:22:33:44:56 tried to access through port gi1/0/13 which is locked
05-Jun-2019 14:44:03 :%2SWPORT-W-LOCKPORTACTIVE: A packet with source MAC 00:11:22:33:44:56 tried to access through port gi1/0/13 which is locked
05-Jun-2019 14:42:53 :%2SWPORT-W-LOCKPORTACTIVE: A packet with source MAC 00:11:22:33:44:56 tried to access through port gi1/0/13 which is locked
sh ports security addresses GigabitEthernet0/13 показывает что на порту изучен 1 адрес:
Код: Выделить всё
#sh ports security addresses GigabitEthernet0/13
Port status Learning Current Maximum
------- -------- --------------- ---------- ----------
gi1/0/13 Enabled Max-Addresses 1 1
Но:
Код: Выделить всё
#sh mac address-table interface GigabitEthernet0/13
Flags: I - Internal usage VLAN
Aging time is 300 sec
Vlan Mac Address Port Type
------------ --------------------- ---------- ----------
Помогает только выкл\вкл port security на интерфейсе:
Код: Выделить всё
(config)#int GigabitEthernet 0/13
(config-if)#no port security
(config-if)#port security discard trap 60
После этого MAC на порту появляется:
Код: Выделить всё
#sh mac address-table interface GigabitEthernet0/13
Flags: I - Internal usage VLAN
Aging time is 300 sec
Vlan Mac Address Port Type
------------ --------------------- ---------- ----------
2196 00:11:22:33:44:56 gi1/0/13 dynamic
Типовые настройки порта:
Код: Выделить всё
interface gigabitethernet1/0/13
loopback-detection enable
ip source-guard
rate-limit 102400
storm-control broadcast kbps 64 trap
storm-control unicast kbps 128 trap
storm-control multicast kbps 64 trap
port security mode max-addresses
port security discard trap 60
spanning-tree disable
traffic-shape 102400
switchport protected-port
switchport access vlan 2196
switchport forbidden default-vlan
Так же включено:
Код: Выделить всё
errdisable recovery interval 120
errdisable recovery cause port-security
версия ПО:
Active-image: flash://system/images/mes3300-4011-1R5.ros
Version: 4.0.11.1
Commit: 7e58bb30
Build: 5 (master)
MD5 Digest: 22b6c55932434e6e17777dee53885c8e
Date: 26-Feb-2019
Time: 12:36:02
Такая же история и на MES1124
У меня что-то не так настроено или это ошибка в работе свича?