MES2124M AC 28-port 1G Managed Switch
Добавлено: 20 окт 2016 10:13
Здравствуйте! В последнее время на коммутаторе eltex MES2124M AC 28-port 1G Managed Switch наблюдается частые срывы авторизации по РРРоЕ с Ethernet портов (это происходит уже в течении нескольких недель, причем срывается каждый час, бывает чаще).
Схема организации следующая: Оборудование IP/MPLS - Коммутатор Zelax 2028C - Коммутатор Eltex MES2124M - router (клиент).
Причем порты Access, в коммутаторе Zelax 2028С проблем с сессией РРРоЕ нет, роутеры клиентов и TP-link и КП4402W. проблемы на любых роутерах. Подскажите что можно сделать. Вот конфигурации коммутаторов ZELAX:
Deribasa_10# show run
!
no service password-encryption
!
hostname Deribasa_10
sysLocation Russia, 124681, Moscow, Zelenograd, Zavodskaya st., 1B, bldg 2
sysContact +7 495 7487178
!
username admin privilege 15 password 0 managepvl
!
!
logging 10.3.249.62 facility local1
logging 10.3.249.62 facility local5 level informational
logging executed-commands enable
!
snmp-server enable
snmp-server securityip 10.3.249.78
snmp-server securityip 20.3.203.2
snmp-server community ro 0 public
snmp-server community rw 0 private
!
ip dhcp snooping enable
ip dhcp snooping binding enable
!
!
!
!
!
spanning-tree
spanning-tree mode rstp
!
!
!
loopback-detection interval-time 10 5
!
!
!
vlan 1
!
vlan 439
name pppoe
!
vlan 461
name PPPoE_2
!
vlan 493
name Int_nonat
!
vlan 550
name Native550
!
vlan 1701
name New_Manage
!
firewall enable
!
mac-access-list extended only_pppoe
permit host-source-mac a8-b1-d4-e2-a3-00 any-destination-mac ethertype 34915
permit any-source-mac host-destination-mac ff-ff-ff-ff-ff-ff ethertype 34915
permit any-source-mac host-destination-mac a8-b1-d4-e2-a3-00 ethertype 34915
permit host-source-mac a8-b1-d4-e2-a3-00 any-destination-mac ethertype 34916
permit any-source-mac host-destination-mac a8-b1-d4-e2-a3-00 ethertype 34916
deny any-source-mac any-destination-mac
exit
!
Interface Ethernet1/1
description Kuznetcova_10/1-14
bandwidth control 40000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/2
description number2
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/3
description number3
bandwidth control 40000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/4
description _
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/5
description Volotko_10-3
bandwidth control 40000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 493
!
Interface Ethernet1/6
description Konurbaeva_10-2
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/7
description Neyderova_10/1-1
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/8
description number8
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/9
description Nehotychaya_10/1-12
bandwidth control 100000 both
switchport access vlan 439
!
Interface Ethernet1/10
description Maruhina_10/1-11
bandwidth control 30000 both
switchport access vlan 439
!
Interface Ethernet1/11
bandwidth control 30000 both
switchport access vlan 439
!
Interface Ethernet1/12
description .
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/13
switchport access vlan 439
!
Interface Ethernet1/14
description Voskoboinikova_2
switchport access vlan 439
!
Interface Ethernet1/15
switchport access vlan 439
!
Interface Ethernet1/16
switchport access vlan 439
!
Interface Ethernet1/17
switchport access vlan 439
!
Interface Ethernet1/18
switchport access vlan 439
!
Interface Ethernet1/19
description Kayakin_10-7
switchport access vlan 439
!
Interface Ethernet1/20
switchport access vlan 439
!
Interface Ethernet1/21
switchport access vlan 439
!
Interface Ethernet1/22
switchport access vlan 439
!
Interface Ethernet1/23
switchport access vlan 439
!
Interface Ethernet1/24
switchport access vlan 439
!
Interface Ethernet1/25
switchport mode trunk
switchport trunk allowed vlan 439;461;493;1701
switchport trunk native vlan 550
ip dhcp snooping trust
!
Interface Ethernet1/26
switchport mode trunk
switchport trunk allowed vlan 439;1701
switchport trunk native vlan 550
ip dhcp snooping trust
!
Interface Ethernet1/27
switchport mode trunk
switchport trunk allowed vlan 439;461;493;1701
switchport trunk native vlan 550
ip dhcp snooping trust
!
Interface Ethernet1/28
switchport mode trunk
switchport trunk allowed vlan 439;1701
switchport trunk native vlan 550
ip dhcp snooping trust
!
interface Vlan1
ip address 192.168.100.18 255.255.255.0
!
interface Vlan1701
ip address 20.3.203.64 255.255.255.0
!
!
no login
!
!
isolate-port group pppoe_clients switchport interface Ethernet1/24
isolate-port group pppoe_clients switchport interface Ethernet1/23
isolate-port group pppoe_clients switchport interface Ethernet1/22
isolate-port group pppoe_clients switchport interface Ethernet1/21
isolate-port group pppoe_clients switchport interface Ethernet1/20
isolate-port group pppoe_clients switchport interface Ethernet1/19
isolate-port group pppoe_clients switchport interface Ethernet1/18
isolate-port group pppoe_clients switchport interface Ethernet1/17
isolate-port group pppoe_clients switchport interface Ethernet1/16
isolate-port group pppoe_clients switchport interface Ethernet1/15
isolate-port group pppoe_clients switchport interface Ethernet1/14
isolate-port group pppoe_clients switchport interface Ethernet1/13
isolate-port group pppoe_clients switchport interface Ethernet1/12
isolate-port group pppoe_clients switchport interface Ethernet1/11
isolate-port group pppoe_clients switchport interface Ethernet1/10
isolate-port group pppoe_clients switchport interface Ethernet1/9
isolate-port group pppoe_clients switchport interface Ethernet1/8
isolate-port group pppoe_clients switchport interface Ethernet1/7
isolate-port group pppoe_clients switchport interface Ethernet1/6
isolate-port group pppoe_clients switchport interface Ethernet1/5
isolate-port group pppoe_clients switchport interface Ethernet1/4
isolate-port group pppoe_clients switchport interface Ethernet1/3
isolate-port group pppoe_clients switchport interface Ethernet1/2
isolate-port group pppoe_clients switchport interface Ethernet1/1
end
И конфигурация ELTEX
Toragirova_66#sh run
vlan database
vlan 439,493,550,1701
exit
!
loopback-detection enable
loopback-detection vlan-based
loopback-detection vlan-based recovery-time 180
!
mac access-list extended only_pppoe
permit a8:b1:d4:e2:a3:00 00:00:00:00:00:00 any 8863 0000
permit any ff:ff:ff:ff:ff:ff 00:00:00:00:00:00 8863 0000
permit any a8:b1:d4:e2:a3:00 00:00:00:00:00:00 8863 0000
permit a8:b1:d4:e2:a3:00 00:00:00:00:00:00 any 8864 0000
permit any a8:b1:d4:e2:a3:00 00:00:00:00:00:00 8864 0000
deny any any
exit
!
hostname Toragirova_66
!
username admin password encrypted b4e3f30cfeff3865f4bd5d613012532ec454e06a privilege 15
!
interface gigabitethernet 1/0/1
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
negotiation 100f
exit
!
interface gigabitethernet 1/0/2
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
negotiation 100f
exit
!
interface gigabitethernet 1/0/3
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
negotiation 100f
exit
!
interface gigabitethernet 1/0/4
loopback-detection enable
switchport access vlan 439
description Dzhumadilov_8
service-acl input only_pppoe
negotiation 100f
exit
!
interface gigabitethernet 1/0/5
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
negotiation 100f
exit
!
interface gigabitethernet 1/0/6
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/7
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/8
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/9
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/10
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/11
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/12
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/13
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/14
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/15
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/16
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/17
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/18
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/19
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/20
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/21
loopback-detection enable
switchport access vlan 493
exit
!
interface gigabitethernet 1/0/22
loopback-detection enable
switchport access vlan 493
exit
!
interface gigabitethernet 1/0/23
loopback-detection enable
switchport access vlan 493
exit
!
interface gigabitethernet 1/0/24
loopback-detection enable
switchport access vlan 1701
exit
!
interface gigabitethernet 1/0/25
switchport mode trunk
switchport trunk allowed vlan add 493,1701
switchport trunk native vlan 550
exit
!
interface gigabitethernet 1/0/26
switchport mode trunk
switchport trunk allowed vlan add 493,1701
switchport trunk native vlan 550
exit
!
interface gigabitethernet 1/0/27
switchport mode trunk
switchport trunk allowed vlan add 493,1701
switchport trunk native vlan 550
exit
!
interface gigabitethernet 1/0/28
switchport mode trunk
switchport trunk allowed vlan add 439,493,1701
switchport trunk native vlan 550
description to_Toraygyr_68
exit
!
interface vlan 439
name "Nat FTTB"
exit
!
interface vlan 493
name No_NAT_Internet
exit
!
interface vlan 550
name Native_Vlan
exit
!
interface vlan 1701
ip address 20.3.203.70 255.255.255.0
exit
!
что можно предпринять???
Заранее спасибо!
Схема организации следующая: Оборудование IP/MPLS - Коммутатор Zelax 2028C - Коммутатор Eltex MES2124M - router (клиент).
Причем порты Access, в коммутаторе Zelax 2028С проблем с сессией РРРоЕ нет, роутеры клиентов и TP-link и КП4402W. проблемы на любых роутерах. Подскажите что можно сделать. Вот конфигурации коммутаторов ZELAX:
Deribasa_10# show run
!
no service password-encryption
!
hostname Deribasa_10
sysLocation Russia, 124681, Moscow, Zelenograd, Zavodskaya st., 1B, bldg 2
sysContact +7 495 7487178
!
username admin privilege 15 password 0 managepvl
!
!
logging 10.3.249.62 facility local1
logging 10.3.249.62 facility local5 level informational
logging executed-commands enable
!
snmp-server enable
snmp-server securityip 10.3.249.78
snmp-server securityip 20.3.203.2
snmp-server community ro 0 public
snmp-server community rw 0 private
!
ip dhcp snooping enable
ip dhcp snooping binding enable
!
!
!
!
!
spanning-tree
spanning-tree mode rstp
!
!
!
loopback-detection interval-time 10 5
!
!
!
vlan 1
!
vlan 439
name pppoe
!
vlan 461
name PPPoE_2
!
vlan 493
name Int_nonat
!
vlan 550
name Native550
!
vlan 1701
name New_Manage
!
firewall enable
!
mac-access-list extended only_pppoe
permit host-source-mac a8-b1-d4-e2-a3-00 any-destination-mac ethertype 34915
permit any-source-mac host-destination-mac ff-ff-ff-ff-ff-ff ethertype 34915
permit any-source-mac host-destination-mac a8-b1-d4-e2-a3-00 ethertype 34915
permit host-source-mac a8-b1-d4-e2-a3-00 any-destination-mac ethertype 34916
permit any-source-mac host-destination-mac a8-b1-d4-e2-a3-00 ethertype 34916
deny any-source-mac any-destination-mac
exit
!
Interface Ethernet1/1
description Kuznetcova_10/1-14
bandwidth control 40000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/2
description number2
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/3
description number3
bandwidth control 40000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/4
description _
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/5
description Volotko_10-3
bandwidth control 40000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 493
!
Interface Ethernet1/6
description Konurbaeva_10-2
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/7
description Neyderova_10/1-1
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/8
description number8
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/9
description Nehotychaya_10/1-12
bandwidth control 100000 both
switchport access vlan 439
!
Interface Ethernet1/10
description Maruhina_10/1-11
bandwidth control 30000 both
switchport access vlan 439
!
Interface Ethernet1/11
bandwidth control 30000 both
switchport access vlan 439
!
Interface Ethernet1/12
description .
bandwidth control 30000 both
spanning-tree portfast bpduguard recovery 30
switchport access vlan 439
!
Interface Ethernet1/13
switchport access vlan 439
!
Interface Ethernet1/14
description Voskoboinikova_2
switchport access vlan 439
!
Interface Ethernet1/15
switchport access vlan 439
!
Interface Ethernet1/16
switchport access vlan 439
!
Interface Ethernet1/17
switchport access vlan 439
!
Interface Ethernet1/18
switchport access vlan 439
!
Interface Ethernet1/19
description Kayakin_10-7
switchport access vlan 439
!
Interface Ethernet1/20
switchport access vlan 439
!
Interface Ethernet1/21
switchport access vlan 439
!
Interface Ethernet1/22
switchport access vlan 439
!
Interface Ethernet1/23
switchport access vlan 439
!
Interface Ethernet1/24
switchport access vlan 439
!
Interface Ethernet1/25
switchport mode trunk
switchport trunk allowed vlan 439;461;493;1701
switchport trunk native vlan 550
ip dhcp snooping trust
!
Interface Ethernet1/26
switchport mode trunk
switchport trunk allowed vlan 439;1701
switchport trunk native vlan 550
ip dhcp snooping trust
!
Interface Ethernet1/27
switchport mode trunk
switchport trunk allowed vlan 439;461;493;1701
switchport trunk native vlan 550
ip dhcp snooping trust
!
Interface Ethernet1/28
switchport mode trunk
switchport trunk allowed vlan 439;1701
switchport trunk native vlan 550
ip dhcp snooping trust
!
interface Vlan1
ip address 192.168.100.18 255.255.255.0
!
interface Vlan1701
ip address 20.3.203.64 255.255.255.0
!
!
no login
!
!
isolate-port group pppoe_clients switchport interface Ethernet1/24
isolate-port group pppoe_clients switchport interface Ethernet1/23
isolate-port group pppoe_clients switchport interface Ethernet1/22
isolate-port group pppoe_clients switchport interface Ethernet1/21
isolate-port group pppoe_clients switchport interface Ethernet1/20
isolate-port group pppoe_clients switchport interface Ethernet1/19
isolate-port group pppoe_clients switchport interface Ethernet1/18
isolate-port group pppoe_clients switchport interface Ethernet1/17
isolate-port group pppoe_clients switchport interface Ethernet1/16
isolate-port group pppoe_clients switchport interface Ethernet1/15
isolate-port group pppoe_clients switchport interface Ethernet1/14
isolate-port group pppoe_clients switchport interface Ethernet1/13
isolate-port group pppoe_clients switchport interface Ethernet1/12
isolate-port group pppoe_clients switchport interface Ethernet1/11
isolate-port group pppoe_clients switchport interface Ethernet1/10
isolate-port group pppoe_clients switchport interface Ethernet1/9
isolate-port group pppoe_clients switchport interface Ethernet1/8
isolate-port group pppoe_clients switchport interface Ethernet1/7
isolate-port group pppoe_clients switchport interface Ethernet1/6
isolate-port group pppoe_clients switchport interface Ethernet1/5
isolate-port group pppoe_clients switchport interface Ethernet1/4
isolate-port group pppoe_clients switchport interface Ethernet1/3
isolate-port group pppoe_clients switchport interface Ethernet1/2
isolate-port group pppoe_clients switchport interface Ethernet1/1
end
И конфигурация ELTEX
Toragirova_66#sh run
vlan database
vlan 439,493,550,1701
exit
!
loopback-detection enable
loopback-detection vlan-based
loopback-detection vlan-based recovery-time 180
!
mac access-list extended only_pppoe
permit a8:b1:d4:e2:a3:00 00:00:00:00:00:00 any 8863 0000
permit any ff:ff:ff:ff:ff:ff 00:00:00:00:00:00 8863 0000
permit any a8:b1:d4:e2:a3:00 00:00:00:00:00:00 8863 0000
permit a8:b1:d4:e2:a3:00 00:00:00:00:00:00 any 8864 0000
permit any a8:b1:d4:e2:a3:00 00:00:00:00:00:00 8864 0000
deny any any
exit
!
hostname Toragirova_66
!
username admin password encrypted b4e3f30cfeff3865f4bd5d613012532ec454e06a privilege 15
!
interface gigabitethernet 1/0/1
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
negotiation 100f
exit
!
interface gigabitethernet 1/0/2
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
negotiation 100f
exit
!
interface gigabitethernet 1/0/3
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
negotiation 100f
exit
!
interface gigabitethernet 1/0/4
loopback-detection enable
switchport access vlan 439
description Dzhumadilov_8
service-acl input only_pppoe
negotiation 100f
exit
!
interface gigabitethernet 1/0/5
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
negotiation 100f
exit
!
interface gigabitethernet 1/0/6
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/7
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/8
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/9
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/10
loopback-detection enable
switchport access vlan 439
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/11
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/12
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/13
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/14
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/15
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/16
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/17
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/18
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/19
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/20
loopback-detection enable
switchport access vlan 493
service-acl input only_pppoe
exit
!
interface gigabitethernet 1/0/21
loopback-detection enable
switchport access vlan 493
exit
!
interface gigabitethernet 1/0/22
loopback-detection enable
switchport access vlan 493
exit
!
interface gigabitethernet 1/0/23
loopback-detection enable
switchport access vlan 493
exit
!
interface gigabitethernet 1/0/24
loopback-detection enable
switchport access vlan 1701
exit
!
interface gigabitethernet 1/0/25
switchport mode trunk
switchport trunk allowed vlan add 493,1701
switchport trunk native vlan 550
exit
!
interface gigabitethernet 1/0/26
switchport mode trunk
switchport trunk allowed vlan add 493,1701
switchport trunk native vlan 550
exit
!
interface gigabitethernet 1/0/27
switchport mode trunk
switchport trunk allowed vlan add 493,1701
switchport trunk native vlan 550
exit
!
interface gigabitethernet 1/0/28
switchport mode trunk
switchport trunk allowed vlan add 439,493,1701
switchport trunk native vlan 550
description to_Toraygyr_68
exit
!
interface vlan 439
name "Nat FTTB"
exit
!
interface vlan 493
name No_NAT_Internet
exit
!
interface vlan 550
name Native_Vlan
exit
!
interface vlan 1701
ip address 20.3.203.70 255.255.255.0
exit
!
что можно предпринять???
Заранее спасибо!