1. <form id='Nv6Fzy'></form>
        <bdo id='Nv6Fzy'><sup id='Nv6Fzy'><div id='Nv6Fzy'><bdo id='Nv6Fzy'></bdo></div></sup></bdo>

          • 当前位置:首页 >> 表格类模板 >>

            7750BRAS维护与配置(SR功能篇)


            7750SR/BRAS 维护与配置 (SR 功能篇)

            第 1 页 共 77 页

            1.

            设备配置命令说明 ................................................................... 4 1.1. 1.2. 1.3. SYSTEM 基本配置 .................................................................... 4 LOG 配置 .......................................................................... 7 PORT 配置 ......................................................................... 9

            1.3.1 上行端口和互联 PORT 端口配置 .................................................... 9 1.3.2 下联端口配置 ................................................................... 10
            1.4. IGP 协议配置 .................................................................... 14

            1.4.1 OSPF 协议配置 .................................................................. 14 1.4.2 ISIS 协议配置 .................................................................. 17
            1.5. 1.6. MPLS、LDP 协议配置 ............................................................... 19 设备安全配置(SECURITY) .......................................................... 24

            1.6.1 设备访问安全 ................................................................. 24 1.6.2 主 CPU 保护 .................................................................... 28
            1.7. 1.8. 1.9. VPN-BGP 配置 .................................................................... 35 POLICY 配置....................................................................... 38 业务配置 ........................................................................ 40

            1.9.1 IES 业务配置 ................................................................... 41 1.9.2 二层 VPN vpls 业务配置 .......................................................... 45 1.9.3 三层 VPN VPRN 业务配置 .......................................................... 48
            1.10. SNMP 配置 ....................................................................... 52 1.11. CFLOWD 配置....................................................................... 53 2. 业务运行状态检查命令 .............................................................. 55 2.1 查看设备 PORT 端口运行状态........................................................... 55

            2.1.1 查看设备所有 Port 端口运行状态 ................................................ 55 2.1.2 查看设备单个 Port 端口运行状态 ................................................ 57
            2.2 查看 SERVICE 业务运行状态 ............................................................ 60 2.3 检查路由器接口运行状态 ............................................................. 62

            2.3.1 查看所有接口状态 .............................................................. 62 2.3.1 查看单个业务的接口状态 ........................................................ 64
            2.4 查看设备 MAC 地址表信息 ............................................................. 66

            2.4.1 查看所有 MAC 地址表 ............................................................ 66 2.4.2 查看单个业务的 MAC 地址表 ...................................................... 69
            2.5 查看设备路由表信息 ................................................................. 70

            2.5.1 查看所有路由表地址表 .......................................................... 70 2.5.2 查看某个业务的路由表 .......................................................... 71
            3. 故障排除方法说明 .................................................................. 73 3.1 光路正常但 PORT 端口 DOWN ............................................................. 73 3.2 3.3 3.4 3.5
            PING

            不通对端地址 ................................................................ 73

            ISIS 邻接关系无法建立 ........................................................... 73 BGP 邻居无法正常建立............................................................. 73 BGP 表中有路由,但路由没有被放进 VPN 路由表中 ..................................... 73
            第 2 页 共 77 页

            3.6

            VPN 中用户 CE 设备无法访问远端 .................................................... 74

            3.7 VPLS 故障分析 ...................................................................... 74

            3.7.1 按照下列配置做 mac-filter ...................................................... 74 3.7.2 在 VPLS 中应用 MAC-FILTER ....................................................... 75 3.8.3 通过分析 LOG 找出问题 .......................................................... 75
            4 删除 SERVICE 配置步骤 ................................................................ 76 4.1 删除单个 SAP SERVICE 配置步骤 ......................................................... 76 4.2 删除多个 SAP SERVICE 配置步骤 ......................................................... 76

            第 3 页 共 77 页

            1. 设备配置命令说明
            1.1. System 基本配置
            1. chassis-mode 要配置为 C,以支持新的 feature。 2. 关闭外部参考时钟(一般现场均没有接) 3. 多链路负载平衡 4. SNMP 报文大小 9216 5. telnet 的 session 限制为设置为最大数 7。 6. 最好定义预设登陆消息,避免设备信息泄露 7. 时间同步由用户提供时钟源(一般是上级路由器,也可能是一台服务器,可能加密) 8. 时区自定义为 GMT8 08 (BJ 08) (BEIJ 08) 配置示例: configure system
            name "ZJJIH-MC-CMNET-SR/BRAS3-DYYDJF1" chassis-mode c l4-load-balancing lsr-load-balancing lbl-ip sync-if-timing begin ref1 shutdown exit ref2 shutdown exit bits shutdown exit commit exit snmp packet-size 9216 exit login-control ftp inbound-max-sessions 5 exit telnet inbound-max-sessions 7 outbound-max-sessions 7 第 4 页 共 77 页

            idle-timeout 15 exit pre-login-message "Authorised access only , This system is the property of Internet , Disconnect IMMEDIATELY if you are not an authorised user! Contact manager for help." no login-banner exit time ntp authentication-key 1 key "OAwgNUlbzgI" hash2 type message-digest server 61.174.90.1 key 1 version 3 prefer server 61.174.90.2 key 1 version 3 server 61.175.255.59 no shutdown exit sntp shutdown exit zone BJ 08 (zone GMT8 08 exit thresholds rmon exit exit exit #-------------------------------------------------echo "Redundancy Configuration" #-------------------------------------------------redundancy synchronize config (boot-env) exit zone BEIJ 08)

            检查命令:
            show chassis 查看 chassis mode 是否为 C。 Show time 查看系统时间。 修改时间 admin set-time 2010/11/12 19:04:38 admin set-time - set-time <date> <time>

            <date> <time>

            : YYYY/MM/DD : hh:mm[:ss]
            第 5 页 共 77 页

            #-------------------------------------------------echo "Card Configuration" #-------------------------------------------------card 5 card-type iom2-20g mda 1 mda-type m10-1gb-sfp-b ingress mcast-path-management shutdown exit exit exit mda 2 mda-type m2-oc48-sfp ingress mcast-path-management shutdown exit exit exit exit 注:mcast-path-management 为加强安全,关闭 mcast-path,

            第 6 页 共 77 页

            1.2. Log 配置
            1. 配置本地 log 用于保存 7750SR 的日常设备信息,log-id 为 50,file-id 为 50。 配置示例: 根据 log 99 报告情况,适当抑制一些报告,避免系统报告太多 #-------------------------------------------------echo "Log Configuration" #-------------------------------------------------log event-control "chassis" 2063 generate event-control "system" 2006 suppress event-control "system" 2007 suppress event-control "system" 2008 suppress event-control "system" 2009 suppress event-control "system" 2011 suppress file-id 30 location cf3: rollover 600 retention 24 exit log-id 30 time-format local from debug-trace to file 30 exit syslog 1 address 220.188.118.250 facility local4 level critical exit log-id 97 from main security change to syslog 1 exit syslog 2 description "To-Syslog-Server" address 202.101.186.1 facility local5 level critical exit log-id 96
            第 7 页 共 77 页

            from main security change to syslog 2 exit snmp-trap-group 98 trap-target "211.140.137.84:162" address 211.140.137.84 snmpv2c notify-community "SR/BRAS11-DYYDJF1" exit log-id 98 from main to snmp exit exit
            l #-------------------------------------------------echo "Filter Log Configuration" #-------------------------------------------------filter log 102 create exit exit

            检查命令:
            Show log log-id 10 查看本地 LOG Show log event-control 查看系统报告数量和开关情况

            第 8 页 共 77 页

            1.3. Port 配置 1.3.1 上行端口和互联 PORT 端口配置
            根据上行或互联的端口类型和协商方式配置。 1. 根据端口不同,配置相应协议 Ethernet, sonnet-sdh, 2. 根据时钟同步要求,确定是否提取时钟 clock-source node-timed 3.多链路捆绑,多个端口属性必须一致 4.多链路捆绑,链路协议需要和对端一致,对端启用 lacp,本地也启用 lacp 5.多链路捆绑,active 表示主动发链路消息,passive 表示只是被动回应链路消息 至少有一端必须是 active

            例子一:10GE config port 2/1/1 description "To ZJJXI-MB-CMNET-RT02 ge-1/1/0 10G" ethernet mtu 1550 exit no shutdown 例子二:1GE configure port 1/1/1 description "To_JH_JH_NE5000E_1ge" ethernet mtu 1550 no autonegotiate exit no shutdown 例子三:10G POS configure port 6/1/1 description "TO-QZ-QZ-NJ-t320-so-2/1/1" sonet-sdh framing sdh clock-source node-timed path mtu 4472 scramble no shutdown exit exit no shutdown exit
            第 9 页 共 77 页

            例子四:2.5G POS configure port 6/1/1 description "To_QZ_XDL_R1_T320_1.MAN_so-6/0/1" sonet-sdh framing sdh path mtu 4470 scramble report-alarm pais prdi prei no shutdown exit exit no shutdown exit 例子三:多端口捆绑 lag 2*1GE configure port 1/1/1 description "To ZJJXI-MC-CMNET-RT07-TXYDJF_7750 ge-1/1/1 1G lag1-1" ethernet mtu 1550 no autonegotiate exit no shutdown configure port 1/1/2 description "To ZJJXI-MC-CMNET-RT07-TXYDJF_7750 ge-1/1/2 1G lag1-2" ethernet mtu 1550 no autonegotiate exit no shutdown ---------------------------------------------configure lag 1 description "To ZJJXI-MC-CMNET-RT07-TXYDJF_7750 lag1 2G" port 1/1/1 port 1/1/2 no shutdown

            1.3.2 下联端口配置
            根据下联交换机的端口类型和协商方式灵活配置。 1. 采用 7750 物理端口与下联设备直联就不需要封装 dot1Q,如果有 VLAN 则需要封装 dot1Q 或 qinq 目前移动要求全部采用 QINQ 方式。 2. 端口下配置的用户数据,如需配置 IES、VLL、VPLS、VPRN 等数据就需要设置 mode 为 access。
            第 10 页 共 77 页

            3. 与下联设备不需要协商需要配置 no autonegotiate。 4.多链路捆绑,多个端口属性必须一致 5.多链路捆绑,链路协议需要和对端一致,对端启用 lacp,本地也启用 lacp 6.多链路捆绑,lactive 表示主动发链路消息,passive 表示只是被动回应链路消息

            配置示例:
            下联二层路由器: 单端口 QINQ configure port 1/1/4 description "NanH-S6503" ethernet mode access encap-type qinq no autonegotiate exit no shutdown exit exit all configure port 1/1/15 description "JHWY-xiacheng-OLT" ethernet mode access encap-type qinq no autonegotiate exit no shutdown exit exit all 下联二层路由器:多链路捆绑 configure port 1/1/3 description "LAG2-To-GuangDian-LAG-port1" ethernet mode access encap-type qinq no autonegotiate exit no shutdown exit all configure port 1/1/4 description "LAG2-To-GuangDian-LAG-port2" ethernet mode access encap-type qinq no autonegotiate 第 11 页 共 77 页

            exit no shutdown configure lag 2 description "To-GuangDian-LAG2" mode access encap-type qinq port 1/1/3 port 1/1/4 lacp active administrative-key 32768 no shutdown

            检查命令:
            Show port show lag

            查看端口状态是否 UP。
            查看 LAG 状态是否 up

            *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show port =============================================================================== Ports on Slot 1 =============================================================================== Port Id 1/1/1 1/1/2 1/1/3 1/1/4 1/1/5 1/1/6 1/1/7 1/1/8 1/1/9 1/1/10 1/1/11 1/1/12 1/1/13 1/1/14 1/1/15 1/1/16 1/1/17 1/1/18 1/1/19 Admin Link Port State Up Up Down Down Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up State Yes Up Yes Up No No Down Down Cfg Oper LAG/ Port Port Port MTU MTU 1550 1550 1550 1550 9212 9212 9212 9212 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1522 1518 1518 1522 1522 Bndl Mode Encp Type 1 netw null xcme 1 netw null xcme - netw null xcme - netw null xcme - accs qinq xcme - accs qinq xcme - accs qinq xcme - accs qinq xcme - accs qinq xcme 3 accs qinq xcme 3 accs qinq xcme 4 accs qinq xcme 4 accs qinq xcme - accs qinq xcme - accs qinq xcme - accs qinq xcme - accs qinq xcme - accs dotq xcme 5 accs qinq xcme SFP/XFP/ MDIMDX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX GIGE-LX 10KM 10KM 80KM 40KM 10KM 40KM 40KM 10KM 10KM 40KM 40KM 40KM 40KM 40KM 40KM 10KM 10KM 10KM 80KM

            -------------------------------------------------------------------------------

            Yes Up Yes Up Yes Up No Down Yes Up Yes Up No No Down Down Yes Up Yes Up Yes Up Yes Up Yes Up Yes Up No Down

            第 12 页 共 77 页

            1/1/20

            Up

            Yes Up

            1522 1522

            5 accs qinq xcme

            GIGE-LX

            10KM

            =============================================================================== Ports on Slot 2 =============================================================================== Port Id 2/1/1 Admin Link Port State Up State Yes Up Cfg Oper LAG/ Port Port Port MTU MTU 1550 1550 Bndl Mode Encp Type SFP/XFP/ MDIMDX

            ------------------------------------------------------------------------------- netw null xgige 10GBASE-LR 10*

            =============================================================================== Ports on Slot A =============================================================================== Port Id A/1 Admin Link Port State Up No State Down Cfg Oper LAG/ Port Port Port MTU MTU 1514 1514 Bndl Mode Encp Type - netw null faste SFP/XFP/ MDIMDX

            -------------------------------------------------------------------------------

            =============================================================================== Ports on Slot B =============================================================================== Port Id B/1 Admin Link Port State Up No State Down Cfg Oper LAG/ Port Port Port MTU MTU 1514 1514 Bndl Mode Encp Type - netw null faste SFP/XFP/ MDIMDX

            ------------------------------------------------------------------------------=============================================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show lag =============================================================================== Lag Data =============================================================================== Lag-id 1 2 3 4 5 11 Adm up down up up up down Opr up down up up up down Port-Threshold 0 0 0 0 0 0 Up-Link-Count 2 0 1 1 1 0 MC Act: 0 MC Act/Stdby N/A N/A N/A N/A N/A N/A MC Stdby: 0 -------------------------------------------------------------------------------

            ------------------------------------------------------------------------------Total Lag-ids: 6 Single Chassis: 6 =============================================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#

            第 13 页 共 77 页

            1.4. IGP 协议配置 1.4.1 OSPF 协议配置
            1 设备的唯一标识地址系统默认名字为 system,配置 IP 地址 X.X.X.X 。 2 设备管理地址 loopback 配置 IP 地址 Y.Y.Y.Y 3 配置系统自治号为 64850。 4 打开多链路负载均衡 ECMP 设置为 16。 5 配置设备 router-id 为协议互联地址,必须是 loopback /32 地址,一般使用 system 地址。 配置示例: a 定义 network 互联接口
            #-------------------------------------------------echo "IP Configuration" #-------------------------------------------------interface "ge-2/1/1" address 221.131.199.230/30 description "To ZJJXI-MB-CMNET-RT02 ge-1/0/1 10G" port 2/1/1 exit interface "lag1" address 221.131.199.154/30 description "To ZJJXI-MC-CMNET-RT03-NanHu_7750 lag1 2G" port lag-1 exit interface "loopback0" address 221.131.199.17/32 loopback exit interface "system" address 221.131.199.18/32 local-dhcp-server "pppoe" exit autonomous-system 64850 ecmp 8 router-id 221.131.199.18 exit all b 定义 access 互联接口 configure service ies 10002 customer 10002 create

            //equal cost multi-path

            第 14 页 共 77 页

            interface "to-gaozhongyuanqu6503" address 211.140.102.93/30 sap 1/1/14:18.0 create exit exit no shutdown exit exit all C 在 OSPF 协议加入接口 configure router asbr reference-bandwidth 40000000 export "export-direct-to-ospf" graceful-restart exit area 0.0.0.4 interface "system" exit interface "lag1" metric 10 exit interface "ge-2/1/1" exit interface "loopback0" exit ospf

            create

            interface "to-gaozhongyuanqu6503" exit exit exit

            检查命令:
            show router ospf interface show router ecmp show router ospf neighter show router ospf status show router ospf database 查看 OSPF 路由数据库

            查看 interface 是否 UP。 查看 ecmp 是否打开。 查看邻居状态是否正常

            -database[type{router|network|summary|asbr-summary|external|nssa|all}] <area-id>] [adv-router <router-id>] [<link-state-id>] [detail] *A:ZJJXI-MC-CMNET-RT002-XieXi_7750>config>service# show router ospf interface ============================================================================= OSPF Interfaces =============================================================================
            第 15 页 共 77 页

            [area

            If Name Area Id Designated Rtr Bkup Desig Rtr Adm Oper ------------------------------------------------------------------------------system 0.0.0.4 221.131.199.17 0.0.0.0 Up DR lag1 0.0.0.4 221.131.199.17 221.131.199.19 Up DR ge-2/1/1 0.0.0.4 211.140.0.236 221.131.199.17 Up BDR loopback0 0.0.0.4 221.131.199.17 0.0.0.0 Up DR to-gaozhongyuanqu6503 0.0.0.4 221.131.199.17 0.0.0.0 Up DR ------------------------------------------------------------------------------No. of OSPF Interfaces: 5 ============================================================================= *A:ZJJXI-MC-CMNET-RT002-XieXi_7750>config>service# *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router ospf neighbor ============================================================================= OSPF Neighbors ============================================================================= Interface-Name Rtr Id State Pri RetxQ TTL ------------------------------------------------------------------------------lag1 221.131.199.19 Full 1 0 37 ge-2/1/1 211.140.0.236 Full 1 0 35 ------------------------------------------------------------------------------No. of Neighbors: 2 =============================================================================

            第 16 页 共 77 页

            1.4.2 ISIS 协议配置
            1. 配置 ISIS 为 leverl-1 2. 配置 area-id 为 86.4661.0573 ( 按照规划配置) 3. 将 system、上联,互联的接口、与下联设备互联接口加入到 ISIS 进程。 配置示例: isis level-capability level-1 area-id 86.4665.0514 traffic-engineering level 1 wide-metrics-only exit interface "system" level-capability level-1 exit interface "to_SYL12416-1_1" level-capability level-1 level 1 metric 200 exit exit interface "to_SYL12416-1_2" level-capability level-1 level 1 metric 200 exit exit interface "to_DBL12416-1_1" level-capability level-1 level 1 metric 200 exit exit interface "to_DBL12416-1_2" level-capability level-1 level 1 metric 200 exit exit exit
            第 17 页 共 77 页

            检查命令:
            show router isis adjacency

            查看 ISIS 邻接是否建立。

            第 18 页 共 77 页

            1.5. Mpls、LDP 协议配置
            1. 将 system、上联设备的接口,互联设备的接口加入到 MPLS 和 LDP 进程。 2. 按照需要将下联设备的接口加入到 MPLS 和 LDP 进程。 配置示例: a 配置标签限制策略 configure router policy-options begin prefix-list "system1" prefix 0.0.0.0/0 prefix-length-range 32-32 exit policy-statement "label-filter" entry 10 from prefix-list "system1" exit action accept exit exit entry 20 action reject exit exit commit exit all b 配置 MPLS 接口(router id 地址必须加入 MPLS) configure router mpls no shutdown interface "system" exit interface "ge-1/1/1" exit interface "ge-1/1/2" exit exit c 配置 LDP 接口(引用标签限制策略) ldp export "label-filter" interface-parameters
            第 19 页 共 77 页

            interface "ge-1/1/1" exit interface "ge-1/1/2" exit exit targeted-session exit exit exit all 检查命令:
            show router mpls interface show router ldp session show router ldp discovery show router ldp binding

            查看 Mpls 接口是否正常 up 查看 LDP 邻接是否成功建立 查看 LDP 邻接是否成功建立 查看 LDP 标签发布情况 l。

            Established 。 Establ。

            show router ldp binding prefix x.x.x.x/32

            查看 LDP 某个目的地的标签发布情况 。

            *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router mpls interface ================================================== MPLS Interfaces ================================================== Interface Port-id Adm Opr TE-metric ------------------------------------------------------------------------------system system Up Up None Admin Groups None Srlg Groups None lag1 lag-1 Up Up None Admin Groups None Srlg Groups None ge-2/1/1 2/1/1 Up Up None Admin Groups None Srlg Groups None ------------------------------------------------------------------------------Interfaces : 3 ================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router ldp session ================================================== LDP Sessions ================================================== Peer LDP Id Adj Type State Msg Sent Msg Recv Up Time
            第 20 页 共 77 页

            -----------------------------------------------------------------------------211.138.130.10:0 Link Established 4340179 4303139 18d 02:08:22 221.131.199.20:0 Link Established 3049446 1887831 17d 17:09:49 -----------------------------------------------------------------------------No. of Sessions: 2 ================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#show router ldp discovery ================================================== LDP Hello Adjacencies ================================================== Interface Name Local Addr Peer Addr AdjType State ------------------------------------------------------------------------------lag1 221.131.199.18 221.131.199.20 Link Estab ge-2/1/1 221.131.199.18 211.138.130.10 Link Estab ------------------------------------------------------------------------------No. of Hello Adjacencies: 2 ================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router ldp bindings prefix 221.131.199.40/32 ================================================== LDP LSR ID: 221.131.199.18 ================================================== Legend: U - Label In Use, N - Label Not In Use, W - Label Withdrawn WP - Label Withdraw Pending ================================================== LDP Prefix Bindings ================================================== Prefix Peer IngLbl EgrLbl EgrIntf EgrNextHop ------------------------------------------------------------------------------221.131.199.40/32 211.138.130.10 128578N 1202 2/1/1 221.131.199.229 221.131.199.40/32 221.131.199.20 128578U 128458 --------------------------------------------------------------------------------No. of Prefix Bindings: 2 ==================================================*A:ZJJXI-MC-CMNET-RT002-XieXi_775 0# show router ldp bindings active prefix 221.131.199.40/32 ================================================== Legend: (S) - Static (M) - Multi-homed Secondary Support (B) - BGP Next Hop ================================================== LDP Prefix Bindings (Active) ==================================================
            第 21 页 共 77 页

            Prefix Op IngLbl EgrLbl EgrIntf/LspId EgrNextHop ------------------------------------------------------------------------------221.131.199.40/32 Push -1202 2/1/1 221.131.199.229 221.131.199.40/32 Swap 128578 1202 2/1/1 221.131.199.229 ------------------------------------------------------------------------------No. of Prefix Active Bindings: 2 *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router ldp bindings - bindings [fec-type <prefixes|services>] [detail | summary] [session <ip-addr[:label-space]>] - bindings [fec-type p2mp] [p2mp-id <identifier> root <ip-address>] [detail | summary] [session <ip-addr[:label-space]>] - bindings <label-type> <start-label> [<end-label>] - bindings {prefix <ip-prefix/mask> [detail]}[session <ip-addr[:label-space]>] - bindings active [fec-type prefixes] [prefix <ip-prefix/mask>] [egress-nh <ip-prefix/mask> | egress-if <port-id> | egress-lsp <tunnel-id>] [summary] - bindings active [fec-type p2mp] [p2mp-id <identifier> root <ip-address>] [egress-nh <ip-prefix/mask> | egress-if <port-id> | egress-lsp <tunnel-id>] [summary] - bindings service-id <service-id> [detail] bindings vc-type <vc-type> [{vc-id <vc-id>|agi <agi>} [session <ip-addr[:label-space]>]] - bindings p2mp-id <identifier> root <ip-address> [detail] <fec-type> : prefixes|services|p2mp - keywords <ip-addr[:label-sp*> : ip-addr - a.b.c.d label-space - [0..65535] <ip-prefix/mask> : ip-prefix a.b.c.d (host bits must be 0) mask [0..32] <vc-type> : <ethernet|vlan|mirror|frdlci|atmsdu|atmcell|atmvcc|atmvpc|ipipe|satop-e1|satop-t1|cesop sn|cesopsn-cas> - keywords <vc-id> : [1..4294967295] <service-id> : [1..2147483648]|<svc-name:64 char max> <label-type> : ingress-label|egress-label - keywords <start-label> : [16..1048575] <end-label> : [17..1048575] <active> : keyword <detail> : keyword <agi> : <ip-addr:comm-val>|<2byte-asnumber:ext-comm-val>|<4byte-asnumber:comm-val> ip-addr - a.b.c.d comm-val - [0..65535]
            第 22 页 共 77 页

            <identifier> <ip-address> <tunnel-id> <port-id>

            : : : :

            2byte-asnumber - [1..65535] ext-comm-val - [0..4294967295] 4byte-asnumber - [1..4294967295] [0..4294967295] a.b.c.d [0..4294967295] slot[/mda[/port]] or slot/mda/port[.channel] aps-id - aps-<group-id>[.channel] aps - keyword group-id - [1..64] ccag-id - slot/mda/<path-id>[cc-type] path-id - [a|b] cc-type - [.sap-net|.net-sap]

            第 23 页 共 77 页

            1.6. 设备安全配置(security) 1.6.1 设备访问安全
            1. 开启 telnet、snmp 服务。并对访问 IP 进行限制。 2. 全网 7750SR 设备关闭 FTP,SSH 服务。 3. 配置 IPV6-filter。对每台 7750SR 的普通上网用户和每个 VPRN 用户都要进行 IPV6 包的 过滤。 配置示例: configure system security telnet-server no ftp-server management-access-filter ip-filter default-action permit entry 1 description "for ssh,entry 001-100" src-ip 61.175.255.39/32 dst-port 22 65535 action permit exit entry 2 src-ip 218.75.102.96/27 dst-port 22 65535 action permit exit entry 100 description "for ssh security,reject other ip" dst-port 22 65535 action deny exit entry 101 description "for telnet,entry 101-200" src-ip 61.175.255.39/32 dst-port 23 65535 action permit exit entry 102 src-ip 218.75.102.96/27 dst-port 23 65535

            第 24 页 共 77 页

            action permit exit entry 200 description "for telnet security,reject other ip" dst-port 23 65535 action deny exit entry 201 description "for snmp security,entry 201-300" src-ip 202.96.102.0/23 dst-port 161 65535 action permit exit entry 202 src-ip 220.188.118.240/28 dst-port 161 65535 action permit exit entry 300 description "for snmp security,reject other ip" dst-port 161 65535 action deny exit exit exit password authentication-order tacplus local exit-on-reject attempts 3 time 5 lockout 0 exit
            tacplus accounting authorization server 1 address 202.96.102.141 secret "c0U/mpLwwC03lOPC3MHySE" hash2 server 2 address 61.153.176.183 secret "WZBK9MwJl5FLJURrtaiD6." hash2 exit

            source-address xxx.xxx.xxx.xxx //default system address if not define
            exit all

            注:exit-on-reject --提供AAA认证取TACPLUS内容,如果加了EXIT-ONF-REJECT,则3A 服务器上没有这个用户名密码的话,则本地帐号也无法登陆

            第 25 页 共 77 页

            本地用户权限管理: 1 系统默认账号 user "admin" password "VeuGBy9agmYtpDhhW0yi359H.JvK5.8c" hash2 access console ftp snmp console member "administrative" exit exit 3. 创建一个新权限,并且应用(注:对本地用户有效,AAA 认证由服务器控制) 例子 a:开放全部权限并应用与用户账号 profile "zcuc" default-action permit-all exit user "zcuc" password "f9GWVwcz08n3aMW6R1aHek" hash2 access console ftp snmp console member "default" member "zcuc" exit exit 例子 b: 有限制的权限并且应用于用户账号 profile "showonly" default-action permit-all entry 10 match "configure" action deny exit entry 20 match "admin" action deny exit entry 30 match "debug" action deny exit entry 40 match "tools" action deny exit entry 50 match "clear" action deny
            第 26 页 共 77 页

            exit entry 60 match "file" action deny exit entry 70 match "bof" action deny exit exit user "hzjk" password "Pa6ZqXTlv590utAHE1WjJ." hash2 access console ftp console no member "default" member "showonly" exit exit

            第 27 页 共 77 页

            1.6.2 主 CPU 保护
            系统硬件保护 (注:复制添加注意首先关闭 ip-filter,修改完成后再打开) configure system security per-peer-queuing cpm-queue queue 40 create cbs 1000 mbs 1000 rate 3000 cir 2000 exit queue 50 create cbs 1000 mbs 1000 rate 2000 cir 2000 exit exit exit all #-------------------------------------------------echo "System Security Cpm Hw Filters Configuration" #-------------------------------------------------configure system security cpm-filter ip-filter shutdown entry 10 create action queue 40 match protocol tcp tcp-syn true exit exit entry 20 create action queue 40 match protocol icmp exit exit entry 50 create action queue 50 match protocol tcp src-ip 10.0.0.0/8 tcp-syn true exit exit
            第 28 页 共 77 页

            entry 51 create action queue 50 match protocol tcp src-ip 172.16.0.0/12 tcp-syn true exit exit entry 52 create action queue 50 match protocol tcp src-ip 192.168.0.0/16 tcp-syn true exit exit #以下是限制端口设置 entry 101 create action drop match protocol udp dst-port 69 65535 exit exit entry 102 create action drop match protocol udp dst-port 135 65535 exit exit entry 103 create action drop match protocol tcp dst-port 135 65535 exit exit entry 104 create action drop match protocol dst-port 137 65535 exit exit entry 105 create action drop match protocol udp dst-port 138 65535 exit
            第 29 页 共 77 页

            exit entry 106 create action drop match protocol tcp dst-port 138 65535 exit exit entry 107 create action drop match protocol udp dst-port 139 65535 exit exit entry 108 create action drop match protocol tcp dst-port 139 65535 exit exit entry 109 create action drop match protocol udp dst-port 445 65535 exit exit entry 110 create action drop match protocol tcp dst-port 445 65535 exit exit entry 111 create action drop match protocol udp dst-port 539 65535 exit exit entry 112 create action drop match protocol tcp dst-port 539 65535 exit exit entry 113 create
            第 30 页 共 77 页

            action drop match protocol udp dst-port 593 65535 exit exit entry 114 create action drop match protocol tcp dst-port 593 65535 exit exit entry 115 create action drop match protocol tcp dst-port 1068 65535 exit exit entry 116 create action drop match protocol udp dst-port 1433 65535 exit exit entry 117 create action drop match protocol udp dst-port 1434 65535 exit exit entry 118 create action drop match protocol tcp dst-port 1871 65535 exit exit entry 119 create action drop match protocol tcp dst-port 3208 65535 exit exit entry 120 create action drop match protocol tcp
            第 31 页 共 77 页

            dst-port 3333 65535 exit exit entry 121 create action drop match protocol tcp dst-port 4331 65535 exit exit entry 122 create action drop match protocol udp dst-port 4334 65535 exit exit entry 123 create action drop match protocol udp dst-port 4444 65535 exit exit entry 124 create action drop match protocol tcp dst-port 4444 65535 exit exit entry 125 create action drop match protocol tcp dst-port 4510 65535 exit exit entry 126 create action drop match protocol tcp dst-port 4557 65535 exit exit entry 127 create action drop match protocol tcp dst-port 5554 65535 exit
            第 32 页 共 77 页

            exit entry 128 create action drop match protocol tcp dst-port 5800 65535 exit exit entry 129 create action drop match protocol tcp dst-port 5900 65535 exit exit entry 130 create action drop match protocol tcp dst-port 9995 65535 exit exit entry 131 create action drop match protocol tcp dst-port 9996 65535 exit exit entry 132 create action drop match protocol tcp dst-port 10080 65535 exit exit no shutdown ?必须开启才起作用 exit exit exit exit
            cpu-protection policy 1 create exit policy 2 create overall-rate max exit port-overall-rate max exit 第 33 页 共 77 页

            ipv6-filter entry 10 create log 110 match router Base exit exit entry 20 create match router ***(VPRN Service ID) exit exit no shutdown exit exit

            检查命令:
            Show system security cpm-filter ip-filter show system security cpm-filter ipv6-filter

            查看 IPV6 包的数量。 注意:default-action permit 必须首先配置

            第 34 页 共 77 页

            1.7. VPN-BGP 配置
            1. 所有 7750SR 和 RR 建立 VPN-BGP IBGP 邻居关系,一般核心作为 RR。 2. 路由策略只有在需要引用外部路由时需要定义 configure router bgp multipath 8 ibgp-multipath local-as 64850 router-id 221.131.201.228 group "BGP-vpn" family vpn-ipv4 type internal export "prefix2bgp" peer-as 64850 local-address 221.131.201.228 neighbor 211.138.130.17 description "To-JHYISHU-NE5000E" exit neighbor 211.138.130.18 description "To-JHERSHU-NE5000E" exit exit exit all 检查命令:
            show router bgp neighbor

            查看 BGP 邻居是否建立成功(Established) 。

            *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router bgp neighbor ================================================== BGP Neighbor ================================================== ------------------------------------------------------------------------------Peer : 211.138.130.9 Group : BGP-vpn ------------------------------------------------------------------------------Peer AS : 64850 Peer Port : 179 Peer Address : 211.138.130.9 Local AS : 64850 Local Port : 51031 Local Address : 221.131.199.18 Peer Type : Internal
            第 35 页 共 77 页

            State : Last Event : Last Error : Local Family : Remote Family : Hold Time : Active Hold Time : Cluster Id : Preference : Recd. Paths : IPv4 Recd. Prefixes : IPv4 Suppressed Pfxs : VPN-IPv4 Recd. Pfxs : Mc IPv4 Recd. Pfxs. : Mc IPv4 Suppr. Pfxs : IPv6 Recd. Prefixes : VPN-IPv6 Recd. Pfxs : VPN-IPv6 Suppr. Pfxs : L2-VPN Recd. Pfxs : MVPN-IPv4 Suppr. Pfxs: MVPN-IPv4 Active Pfxs: MDT-SAFI Recd. Pfxs : Input Queue : i/p Messages : i/p Octets : i/p Updates : TTL Security : Graceful Restart : Advertise Inactive : Advertise Label : Auth key chain : Bfd Enabled : Local Capability : Remote Capability : Import Policy : Export Policy :

            Established Last State recvKeepAlive Unrecognized Error VPN-IPv4 VPN-IPv4 90 Keep Alive 90 Active Keep Alive None 170 Num of Update Flaps 8803 0 IPv4 Active Prefixes 0 VPN-IPv4 Suppr. Pfxs 3469 VPN-IPv4 Active Pfxs 0 Mc IPv4 Active Pfxs. 0 IPv6 Suppressed Pfxs 0 IPv6 Active Prefixes 0 VPN-IPv6 Active Pfxs 0 L2-VPN Suppr. Pfxs 0 L2-VPN Active Pfxs 0 MVPN-IPv4 Recd. Pfxs 0 MDT-SAFI Suppr. Pfxs 0 MDT-SAFI Active Pfxs 0 Output Queue 138141 o/p Messages 13204614 o/p Octets 83518 o/p Updates Disabled Min TTL Value Disabled Stale Routes Time Disabled Peer Tracking None n/a Disabled L2 VPN Cisco Interop RtRefresh MPBGP 4byte ASN RtRefresh MPBGP 4byte ASN None Specified / Inherited None Specified / Inherited

            : Active

            : 30 : 30 : 29649 : : : : : : : : : : : : : : : : : : : 0 0 2624 0 0 0 0 0 0 0 0 0 0 49812 1031148 648 n/a n/a Disabled

            : Disabled

            ------------------------------------------------------------------------------Peer : 211.138.130.10 Group : BGP-vpn ------------------------------------------------------------------------------Peer AS : 64850 Peer Port : 50105 Peer Address : 211.138.130.10 Local AS : 64850 Local Port : 179
            第 36 页 共 77 页

            Local Address : Peer Type : State : Last Event : Last Error : Local Family : Remote Family : Hold Time : Active Hold Time : Cluster Id : Preference : Recd. Paths : IPv4 Recd. Prefixes : IPv4 Suppressed Pfxs : VPN-IPv4 Recd. Pfxs : Mc IPv4 Recd. Pfxs. : Mc IPv4 Suppr. Pfxs : IPv6 Recd. Prefixes : VPN-IPv6 Recd. Pfxs : VPN-IPv6 Suppr. Pfxs : L2-VPN Recd. Pfxs : MVPN-IPv4 Suppr. Pfxs: MVPN-IPv4 Active Pfxs: MDT-SAFI Recd. Pfxs : Input Queue : i/p Messages : i/p Octets : i/p Updates : TTL Security : Graceful Restart : Advertise Inactive : Advertise Label : Auth key chain : Bfd Enabled : Local Capability : Remote Capability : Import Policy : Export Policy :

            221.131.199.18 Internal Established Last State recvKeepAlive Cease VPN-IPv4 VPN-IPv4 90 Keep Alive 90 Active Keep Alive None 170 Num of Update Flaps 9141 0 IPv4 Active Prefixes 0 VPN-IPv4 Suppr. Pfxs 3469 VPN-IPv4 Active Pfxs 0 Mc IPv4 Active Pfxs. 0 IPv6 Suppressed Pfxs 0 IPv6 Active Prefixes 0 VPN-IPv6 Active Pfxs 0 L2-VPN Suppr. Pfxs 0 L2-VPN Active Pfxs 0 MVPN-IPv4 Recd. Pfxs 0 MDT-SAFI Suppr. Pfxs 0 MDT-SAFI Active Pfxs 0 Output Queue 155772 o/p Messages 15003795 o/p Octets 94321 o/p Updates Disabled Min TTL Value Disabled Stale Routes Time Disabled Peer Tracking None n/a Disabled L2 VPN Cisco Interop RtRefresh MPBGP 4byte ASN RtRefresh MPBGP 4byte ASN None Specified / Inherited None Specified / Inherited

            : Established

            : 30 : 30 : 30209 : : : : : : : : : : : : : : : : : : : 0 0 1 0 0 0 0 0 0 0 0 0 0 49810 1027579 661 n/a n/a Disabled

            : Disabled

            ------------------------------------------------------------------------------Neighbors : 2 ================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#

            第 37 页 共 77 页

            1.8. Policy 配置
            1、 设置对 LDP 0.0.0.0/0 的 FEC 安全过滤。 配置示例: configure router policy-options begin prefix-list "system1" prefix 0.0.0.0/0 prefix-length-range 32-32 exit policy-statement "label-filter" entry 10 from prefix-list "system1" exit action accept exit exit entry 20 action reject exit exit commit exit all 2、 配置静态黑洞路由,并通过设置指定的 Prefix list 发布到 OSPF。
            static-route 61.132.39.88/29 black-hole preference 200

            -----(省略)----prefix-list "direct-to-ospf" prefix 61.132.38.96/28 exact -----(省略)----exit policy-statement "export-direct-to-ospf" entry 10 from protocol direct prefix-list "direct-to-ospf" exit to protocol ospf exit action accept
            第 38 页 共 77 页

            metric set 10 exit exit entry 20 from protocol static exit to protocol ospf exit action accept exit exit exit

            第 39 页 共 77 页

            1.9. 业务配置
            业务编号按照规划

            SR7750业务ID规划. doc

            配置 customer 10 与 IES server 关联。customer 20 与 VPRN,customer 30 与 VPLS server 关联。 1. 每个 VPRN 都有一个 server-id。 2. 每个 IES 也有一个 server-id,定义规则为总位数是 8 位,1-4 位为 port 号(如 1/1/1 为 1101) ,5-8 为 VLAN ID,不足 4 位用 0 补齐。 3. Server 下的 Interface 命名规则是连接用户简称。 配置示例: service customer 1 create description "Default customer" exit customer 10 create description "to_IES" exit customer 20 create description "to_VPRN" exit customer 30 create description "to_VPLS" exit

            第 40 页 共 77 页

            1.9.1 IES 业务配置
            1.9.1.1 单SAP接口IES业务配置
            configure service ies 104002 customer 10 create interface "jiansheju" create address 61.132.39.89/29 sap 1/2/1:4002.0 create exit exit no shutdown exit all 注意:一个 interface 下仅仅可以绑定一个 sap,sap 叫做 Service Access Point。同时一个 sap 仅仅可以绑定在唯 一一个 service 中,比如本例 1/2/1:4002.0 就不能再被绑定到其他 service 中去。 (激活这个 service) (ies 号与 sap-id 对应,后 4 位为 vlan-id) (建立一个逻辑 interface) (配置地址及 Mask) (为该 interface 绑定一个 sap,一般全面采用 qinq)

            检查命令:
            Show service service-using Show service id xxxx 例子: *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show service id 101032 arp ============================================================== ARP Table ============================================================== IP Address 112.11.125.65 112.11.125.66 MAC Address Type Expiry Interface SAP 1/1/5:20* 1/1/5:20* ------------------------------------------------------------------------------00:23:3e:96:f1:d0 Other 00h00m00s ge-1/1/5:2018.0 84:2b:2b:56:5c:28 Dynamic 03h58m57s ge-1/1/5:2018.0 arp 查看已配置的 service 查看 arp 表

            ============================================================== * indicates that the corresponding row element may have been truncated. *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#

            第 41 页 共 77 页

            1.9.1.2 多SAP 接口IES业务配置
            1 2 3 4 5 6 7 主要为解决一个网关下有多个 sap 接入 必须采用 subscriber-interface 每个网段一个 每个物理端口必须起一个 group-interface 采用 default 假认证实现,可以避免主机需要逐个静态配置 需要提供 ESM 相关 default 系统 default 相同 sap 只允许一个主机, 多个主机 需要修改 multi-sub-sap 带宽策略必须尽量放大,避免出现拥塞 default 值

            configure subscriber-mgmt authentication-policy "auth-VPN" create radius-authentication-server fallback-action accept timeout 1 router "Base" exit exit sub-profile "sub-prof-VPN" create sla-profile-map use-direct-map-as-default exit exit sla-profile "sla-prof-VPN" create ingress qos 800 exit exit egress qos 800 exit exit exit sub-ident-policy "sub-ident-VPN" create sla-profile-map use-direct-map-as-default exit strings-from-option 254 exit exit all configure service ies 10001 customer 10001 create
            第 42 页 共 77 页

            description "to-switchmangement" subscriber-interface "to-switchmangement" create address 112.11.126.145/28 group-interface "ge-1/1/14:7.0" create description "To-gaozhongyuanqu6503" arp-populate authentication-policy "auth-VPN" sap 1/1/14:7.0 create sub-sla-mgmt def-sub-id use-sap-id def-sub-profile "sub-prof-VPN" def-sla-profile "sla-prof-VPN" sub-ident-policy "sub-ident-VPN" multi-sub-sap 4000 no shutdown exit exit arp-host host-limit 4000 sap-host-limit 4000 no shutdown exit exit group-interface "ge-1/1/15:7.0" create description "To-yixueyuan6503" arp-populate authentication-policy "auth-VPN" sap 1/1/15:7.0 create sub-sla-mgmt def-sub-id use-sap-id def-sub-profile "sub-prof-VPN" def-sla-profile "sla-prof-VPN" sub-ident-policy "sub-ident-VPN" no shutdown exit exit 。。 相同的物理端口下的逐个 sap 接口添加 。。 arp-host host-limit 4000 sap-host-limit 4000 no shutdown exit exit 。。。逐个物理接口添加 。。
            第 43 页 共 77 页

            exit no shutdown exit 检查命令:
            Show service service-using Show service id xxxx arp 查看已配置的 service 查看 arp 表

            *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show service id 10001 arp ============================================================================= ARP Table ============================================================================= IP Address MAC Address Type Expiry Interface SAP ------------------------------------------------------------------------------112.11.126.145 00:23:3e:65:3e:50 Other 00h00m00s to-switchmangeme* subscrib* 00:23:3e:96:f1:d9 ge-1/1/14:7.0 1/1/14 00:23:3e:96:f1:da ge-1/1/15:7.0 1/1/15 00:23:3e:96:f1:db ge-1/1/16:7.0 1/1/16 00:23:3e:96:f1:d0 ge-1/1/5:7.0 1/1/5 00:23:3e:96:f1:d1 ge-1/1/6:7.0 1/1/6 00:23:3e:96:f1:d2 ge-1/1/7:7.0 1/1/7 112.11.126.149 00:0f:e2:22:c3:b1 Managed 00h00m00s ge-1/1/14:7.0 1/1/14:7* 112.11.126.151 00:0f:e2:22:c0:91 Managed 00h00m00s ge-1/1/15:7.0 1/1/15:7* 112.11.126.150 00:0f:e2:5a:e0:ce Managed 00h00m00s ge-1/1/16:7.0 1/1/16:7* 112.11.126.146 00:0f:e2:1e:97:0c Managed 00h00m00s ge-1/1/5:7.0 1/1/5:7.0 112.11.126.147 00:0f:e2:1e:8d:7f Managed 00h00m00s ge-1/1/6:7.0 1/1/6:7.0 112.11.126.148 00:0f:e2:df:16:c7 Managed 00h00m00s ge-1/1/7:7.0 1/1/7:7.0 ============================================================================= * indicates that the corresponding row element may have been truncated. *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#

            第 44 页 共 77 页

            1.9.2 二层 VPN vpls 业务配置
            1.9.2.1 配置全网SR设备全互联的SDP,用于VPLS的业务开展
            sdp 102 mpls create description "to-qinghe-SR2" far-end 58.220.170.34 ldp
            path-mtu 1514 (定义 SDP 封装为 mpls,gre 可选) (定义对端设备的讯息) (定义远端地址,一定要为 system 地址) (用 ldp 作为 mpls 的标签分发协议) (path-mtu 要大于等于 service mtu)

            keep-alive shutdown exit no shutdown exit sdp 103 mpls create far-end 58.220.170.1 ldp keep-alive shutdown exit no shutdown exit ………………

            (激活 keep-alive 检测对端是否工作正常)

            注意:SDP 叫做 service distribute point,概念类似与 cisco 的 tunnel interface,SDP 具有单向性,配置时需要 对两端均进行配置。7750 通过使用 SDP,将本地的流量泛洪到远端。SDP 可以为 mpls 封装,也可以为 gre 封装,默认 情况下采用 t-ldp 对分配的标签进行自动映射,

            1.9.2.2 配置VPLS
            1 MAC 地址表 fdb-table-size default 配置 250 超过 系统会有告警 2 水平分割 split-horizon-group 可以限制各个分割点的 sap 端口间的 arp 报文泛洪 3 sap spoke-sdp 该端口收到的报文会泛洪到除自身外的其他端口 4 mesh-sdp 该端口收到的报文会泛洪到除 mesh-sdp 外的其他端口 vpls 1001 customer 11 create (建立 vpls 1001) description "xiaofang-vpls" fdb-table-size 32767 split-horizon-group "3000022" residential-group create exit stp
            第 45 页 共 77 页

            shutdown exit sap 1/1/3:1401.0 split-horizon-group "300022" create (将 sap binding 进该 vpls) description "hangjiangzhidui" ingress qos 10 exit egress qos 10 exit exit sap 1/2/2:4013.0 split-horizon-group "300022" create (将 sap binding 进该 vpls) description "guanglingchanyezhidui" ingress qos 10 exit egress qos 10 exit exit spoke-sdp 104:303201 create exit spoke-sdp 130:303201 create exit mesh-sdp 104:1001 create (binding 指向对端 sdp 进 vpls) exit mesh-sdp 109:1001 create exit exit

            注意:在 vpls 中的 sap mtu 必须要大于等于 service mtu,在 port 被定义为 access 模式和 dot1q 封装后,mtu 为 1518,剥去 4 字节的 vlan-tag 后 mtu 应当为 1514。如果 service mtu 设的过大,那么 vpls 中 sap 会起不来,并且 报错 port mtu too small.

            检查命令: Show service show service show service show service show service show service

            service-using 查看已配置的 service sdp-using id xxxxxx id xxxxxx fdb detail 查看 VPLS 学习到的 MAC id xxxxxx sdp fdb-mac |match xxxxxx (在两侧设备上看 MAC 地址是否学习到)

            第 46 页 共 77 页

            oam mac-ping service 1001 destination ff:ff:ff:ff:ff:ff

            mac-pinning
            Syntax [no] mac-pinning Context config>service>vpls>sap config>service>vpls>endpoint config>service>vpls>spoke-sdp config>service>vpls>mesh-sdp Description Enabling this command will disable re-learning of MAC addresses on other SAPs within the VPLS. The MAC address will remain attached to a given SAP for duration of its age-timer. The age of the MAC address entry in the FIB is set by the age timer. If mac-aging is disabled on a given VPLS service, any MAC address learned on a SAP/SDP with mac-pinning enabled will remain in the FIB on this SAP/SDP forever. Every event that would otherwise result in re-learning will be logged (MAC address; original-SAP; new-SAP). Note that MAC addresses learned during DHCP address assignment (DHCP snooping enabled) are not impacted by this command. MAC-pinning for such addresses is implicit. Default When a SAP or spoke SDP is part of a Residential Split Horizon Group (RSHG), MAC pinning is activated at creation of the SAP. Otherwise MAC pinning is not enabled by default

            第 47 页 共 77 页

            1.9.3 三层 VPN VPRN 业务配置
            1.9.3.1 普通VPN节点配置,SR间可以互访,不同VPN间不能互访。
            configure service vprn 514001001 customer 11 create (创建 vprn 业务)

            description "wuxiandian-vprn" route-distinguisher 514:1001
            (配置 RD 值)

            auto-bind ldp (使用 ldp 协议分发的标签) vrf-target target:514:1001 (配置 RT 值,RT 取与 RD 相同值,相同 VRF 的两个节点可以互通) interface "wuxiandian" create (建立一个逻辑 interface) address 192.168.1.2/30 sap 2/2/1:4029.0 create ingress qos 2 exit egress qos 2 exit exit exit static-route 172.17.22.0/24 next-hop 192.168.1.1 (配置 VPN 静态路由) exit exit

            1.9.3.2 不同VPN间互访
            1 需要配置进行策略控制的 VPRN 业务 2 其他 SR 有相同的 RD:RT 就必须将这个 RD:RT 也加入,否则路由学不到(6.1R10) configure router policy-options
            begin

            (开始编辑一定需要输入 begin 关键词)
            (定义该字符串匹配

            community "wuxiandian-vpn-in1" members "target:1001:2"
            RT1001:2)

            community "wuxiandian-vpn-in2" members "target:1001:3" community "wuxiandian-vpn-out" members "target:1001:1" policy-statement "wuxiandian-vpn-in" entry 10 (条项序列号 10,越小越优先) from
            第 48 页 共 77 页

            protocol bgp-vpn community "wuxiandian-vpn-in1" exit action accept exit exit entry 20 from protocol bgp-vpn community "wuxiandian-vpn-in2" exit action accept exit exit exit policy-statement "wuxiandian-vpn-out" entry 10 action accept

            (从 bgp-vpn 收到的 ipv4-vpn 路由) (匹配 RT 1001:2)

            (定义条项 10 的行为为允许)

            (条项序列号 20,越小越优先) (从 bgp-vpn 收到的 ipv4-vpn 路由) (匹配 RT 1001:3)

            (条项序列号 10,越小越优先)

            community add "wuxiandian-vpn-out" exit exit exit commit

            (匹配 RT 1001:1)

            (编辑完一定要 commit 策略才会生效)

            exit all configure service vprn 514001001 customer 11 create description "wuxiandian-vprn" vrf-import "wuxiandian-vpn-in" (应用 VPN 路由导入策略) vrf-export "wuxiandian-vpn-out" (应用 VPN 路由导出策略) route-distinguisher 514:1001 auto-bind ldp interface "wuxiandian" create address 192.168.1.2/30 sap 2/2/1:4029 create ingress qos 2 (应用 QOS 限速策略) exit egress qos 2 exit exit exit static-route 172.17.22.0/24 next-hop 192.168.1.1 (配置 VPN 静态路由)
            第 49 页 共 77 页

            shutdown exit exit
            注:如果需要 import 多个 RT 值,需要分别定义 vrf-import 及 vrf-export 策略,策略在 policy-option 中进行编辑

            检查命令

            show ping show show show show show show

            service service-using router 514001001 172.17.22.1 router 514001001 route-table router 514001002 static-route router 514001002 route-table protocol local router 514001002 route-table summary router 514001002 route-table protocol bgp-vpn service id 514001001 arp

            Remote-proxy-arp 定义本地不检测 proxy Local-proxy-arp 本地作为 proxy 添加静态 blackhole 及 Prefix list 配置,用于在 BGP 中发布路由 static-route 61.132.39.88/29 black-hole preference 200 prefix-list "networks" prefix 61.132.38.96/28 exact exit policy-statement "prefix2bgp" entry 10 from prefix-list "networks" exit to protocol bgp exit action accept origin igp exit exit exit bgp

            第 50 页 共 77 页

            family ipv4 vpn-ipv4 multipath 8 ibgp-multipath router-id 58.220.170.3 group "ibgp" type internal export "prefix2bgp" peer-as 64665 local-address 58.220.170.3 neighbor 61.177.176.253 exit neighbor 61.177.176.254 exit exit exit exit

            第 51 页 共 77 页

            1.10.

            SNMP 配置

            #-------------------------------------------------echo "System Configuration" #-------------------------------------------------system snmp packet-size 9216 exit exit #-------------------------------------------------echo "System Security Configuration" #-------------------------------------------------system security snmp community "GatCyWjiRaEJWSIIkwI6u." hash2 rwa version both community "V8InRiDu4AuIYCmYq/D4ME" hash2 rwa version both community "xN78SJ07GZMZz/XrczJeqU" hash2 rwa version both exit exit exit #-------------------------------------------------echo "Log Configuration" #-------------------------------------------------log snmp-trap-group 98 trap-target "10.1.100.254:162" address 10.1.100.254 snmpv2c notify-community "jhdxwlan" trap-target "220.188.118.249:162" address 220.188.118.249 snmpv2c notify-community "jhdd@99cc" trap-target "61.175.253.59:162" address 61.175.253.59 snmpv2c notify-community "JH-JH-CZ-SRtrap98" exit log-id 98 from main to snmp exit

            第 52 页 共 77 页

            1.11.

            Cflowd 配置

            1 需要进行 cflowd 记录分析的端口需根据连接情况确认 一般 SR 上行和互联的接口需要加入,和 BRAS 连接的接口也需要加入 2 cflowd 记录服务器 IP 和 port 由用户提供,可能有多个 #-------------------------------------------------echo "Router (Network Side) Configuration" #-------------------------------------------------router interface "so-6/1/1" address 220.185.59.190/30 port 6/1/1 cflowd interface exit #-------------------------------------------------echo "Cflowd Configuration" #-------------------------------------------------cflowd active-timeout 20 inactive-timeout 10 overflow 50 collector 202.96.113.42:9996 aggregation protocol-port source-prefix raw exit exit collector 202.96.113.174:9990 aggregation protocol-port source-prefix raw exit exit exit

            第 53 页 共 77 页

            第 54 页 共 77 页

            2. 业务运行状态检查命令
            2.1 查看设备 Port 端口运行状态 2.1.1 查看设备所有 Port 端口运行状态

            show port 命令可以看到路由器物理端口的状态,包括 mode,mtu,encapsulation,光模块类型等等 端口状态分 Admin 状态-管理状态,Port 状态 端口实际的工作状态. 如果该端口要加入 service,必须将其模式改为 access 模式, 如果该端口要使用多个 vlan 来对应多个业务,则必须将 port 封装模式改成 dot1q 如果该端口要使用两层 vlan 来对应多个业务,则必须将 port 封装模式改成 qinq *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show port =============================================================================== Ports on Slot 1 =============================================================================== Port Admin Link Port Cfg Oper LAG/ Port Port Port SFP/XFP/ Id State State MTU MTU Bndl Mode Encp Type MDIMDX ------------------------------------------------------------------------------1/1/1 Up Yes Up 1550 1550 1 netw null xcme GIGE-LX 10KM 1/1/2 Up Yes Up 1550 1550 1 netw null xcme GIGE-LX 10KM 1/1/3 Down No Down 9212 9212 - netw null xcme GIGE-LX 80KM 1/1/4 Down No Down 9212 9212 - netw null xcme GIGE-LX 40KM 1/1/5 Up Yes Up 1522 1522 - accs qinq xcme GIGE-LX 10KM 1/1/6 Up Yes Up 1522 1522 - accs qinq xcme GIGE-LX 40KM 1/1/7 Up Yes Up 1522 1522 - accs qinq xcme GIGE-LX 40KM 1/1/8 Up No Down 1522 1522 - accs qinq xcme GIGE-LX 10KM 1/1/9 Up Yes Up 1522 1522 - accs qinq xcme GIGE-LX 10KM 1/1/10 Up Yes Up 1522 1522 3 accs qinq xcme GIGE-LX 40KM 1/1/11 Up No Down 1522 1522 3 accs qinq xcme GIGE-LX 40KM 1/1/12 Up Yes Up 1522 1522 4 accs qinq xcme GIGE-LX 40KM 1/1/13 Up No Down 1522 1522 4 accs qinq xcme GIGE-LX 40KM 1/1/14 Up Yes Up 1522 1522 - accs qinq xcme GIGE-LX 40KM 1/1/15 Up Yes Up 1522 1522 - accs qinq xcme GIGE-LX 40KM 1/1/16 Up Yes Up 1522 1522 - accs qinq xcme GIGE-LX 10KM 1/1/17 Up Yes Up 1522 1522 - accs qinq xcme GIGE-LX 10KM 1/1/18 Up Yes Up 1518 1518 - accs dotq xcme GIGE-LX 10KM
            第 55 页 共 77 页

            1/1/19 1/1/20

            Up Up

            No Down Yes Up

            1522 1522 1522 1522

            5 accs qinq xcme 5 accs qinq xcme

            GIGE-LX 80KM GIGE-LX 10KM

            ===================================================== Ports on Slot 2 ===================================================== Port Admin Link Port Cfg Oper LAG/ Port Port Port SFP/XFP/ Id State State MTU MTU Bndl Mode Encp Type MDIMDX ------------------------------------------------------------------------------2/1/1 Up Yes Up 1550 1550 - netw null xgige 10GBASE-LR 10* ===================================================== Ports on Slot A =============================================================================== Port Admin Link Port Cfg Oper LAG/ Port Port Port SFP/XFP/ Id State State MTU MTU Bndl Mode Encp Type MDIMDX ------------------------------------------------------------------------------A/1 Up No Down 1514 1514 - netw null faste =============================================================================== Ports on Slot B =============================================================================== Port Admin Link Port Cfg Oper LAG/ Port Port Port SFP/XFP/ Id State State MTU MTU Bndl Mode Encp Type MDIMDX ------------------------------------------------------------------------------B/1 Up No Down 1514 1514 - netw null faste =============================================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#

            第 56 页 共 77 页

            2.1.2

            查看设备单个 Port 端口运行状态

            show port 1/1/2 命令可以看到路由器某个物理端口的具体状态,包括光模块类型,序列号,接口光功率等讯息 *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show port 1/1/2 ===================================================== Ethernet Interface ===================================================== Description : To ZJJXI-MC-CMNET-RT03-NanHu_7750 ge-1/1/2 Interface : 1/1/2 Oper Speed Link-level : Ethernet Config Speed Admin State : up Oper Duplex Oper State : up - Active in LAG 1 Config Duplex Physical Link : Yes MTU Single Fiber Mode : No IfIndex : 35717120 Hold time up Last State Change : 10/26/2010 21:44:37 Hold time down Last Cleared Time : 10/26/2010 13:07:32 DDM Events Configured Mode : Dot1Q Ethertype : PBB Ethertype : Ing. Pool % Rate : Ing. Pool Policy : Egr. Pool Policy : Net. Egr. Queue Pol: Egr. Sched. Pol : Auto-negotiate : Accounting Policy : Egress Rate : Load-balance-algo : network 0x8100 0x88e7 100 n/a n/a default n/a false None Default default Encap Type QinQ Ethertype

            1G : : : : :

            lag1-2 1 Gbps 1 Gbps full full 1550

            : 0 seconds : 0 seconds : Enabled : null : 0x8100

            Egr. Pool % Rate : 100

            MDI/MDX Collect-stats Ingress Rate LACP Tunnel Keep-alive Retry

            : : : :

            unknown Disabled Default Disabled

            Down-when-looped : Disabled Loop Detected : False Use Broadcast Addr : False Sync. Status Msg. : Disabled Tx DUS/DNU : Disabled SSM Code Type : sdh Configured Address : 00:23:3e:96:f1:cd

            : 10 : 120

            Rx Quality Level : N/A Tx Quality Level : N/A

            第 57 页 共 77 页

            Hardware Address Cfg Alarm Alarm Status Transceiver Data

            : 00:23:3e:96:f1:cd : :

            Transceiver Type : Model Number : TX Laser Wavelength: Connector Code : Manufacture date : Serial Number : Part Number : Optical Compliance : Link Length support:

            SFP 3HE00028AAAA02 ALA IPUIAEMDAB 1310 nm Diag Capable : yes LC Vendor OUI : 00:00:5f 2009/10/20 Media : Ethernet 9XT402908006 SCP6F44-A8-AWH GIGE-LX 10km for SMF; 550m for OM2 50u MMF; 550m for OM1 62.5u M*

            =============================================================================== Transceiver Digital Diagnostic Monitoring (DDM), Internally Calibrated =============================================================================== Value High Alarm High Warn Low Warn Low Alarm ------------------------------------------------------------------------------Temperature (C) +30.8 +98.0 +88.0 -43.0 -45.0 Supply Voltage (V) 3.28 4.12 3.60 3.00 2.80 Tx Bias Current (mA) 5.5 60.0 50.0 0.1 0.0 Tx Output Power (dBm) -5.94 0.00 -2.00 -10.50 -12.50 Rx Optical Power (avg dBm) -14.06 -3.00 -4.00 -19.51 -20.51 ===================================================== ===================================================== Traffic Statistics ===================================================== Input Output ------------------------------------------------------------------------------Octets 5741723331701 5883796033147 Packets 10935757135 11141199266 Errors 0 0 =============================================================================== * indicates that the corresponding row element may have been truncated. ===================================================== Port Statistics ===================================================== Input Output ------------------------------------------------------------------------------第 58 页 共 77 页

            Unicast Packets 10932058174 Multicast Packets 3698961 Broadcast Packets 0 Discards 0 Unknown Proto Discards 0 ===================================================== ===================================================== Ethernet-like Medium Statistics ===================================================== Alignment Errors : 0 Sngl Collisions FCS Errors : 0 Mult Collisions SQE Test Errors : 0 Late Collisions CSE : 0 Excess Collisns Too long Frames : 0 Int MAC Tx Errs Symbol Errors : 0 Int MAC Rx Errs In Pause Frames : 0 Out Pause Frames ===================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# : : : : : : :

            11137949897 3249369 0 0

            0 0 0 0 0 0 0

            第 59 页 共 77 页

            2.2 查看 Service 业务运行状态
            show service service-using 该命令可以查看设备上用户 service 的开展情况,包括 IES 和 VPRN *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show service service-using =====================================================Services =====================================================ServiceId Type Adm CustomerId Service Name Template Used ------------------------------------------------------------------------------1 VPLS Up Up 1 3000 IES Up Up 1 10001 IES Up Up 10001 10002 IES Up Up 10002 10003 IES Up Up 1 101000 IES Up Up 1000 101001 IES Up Up 1001 101002 IES Up Up 1002 101003 IES Up Up 1003 101004 IES Up Up 1004 101005 IES Up Up 1005 101006 IES Up Up 1006 101007 IES Up Up 1007 101008 IES Up Up 1008 101009 IES Up Up 1009 101010 IES Up Up 1010 101011 IES Up Up 1011 101012 IES Up Up 1012 101013 IES Up Up 1013 101014 IES Up Up 1014 101015 IES Up Up 1015 101016 IES Up Up 1016 101017 IES Up Up 1017 101018 IES Up Up 1018 101019 IES Up Up 1019 101020 IES Up Up 1020 101021 IES Up Up 1021 101022 IES Up Up 1022 101023 IES Up Up 1023 101024 IES Up Up 1024 101025 IES Up Up 1025

            Opr

            第 60 页 共 77 页

            101026 IES Up Up 1026 101027 IES Up Up 1027 101028 IES Up Up 1028 101030 IES Up Up 1030 101031 IES Up Up 1031 101032 IES Up Up 1032 209000 VPRN Up Up 9000 209001 VPRN Up Up 9001 209002 VPRN Up Up 9002 209003 VPRN Up Up 9003 209004 VPRN Up Up 9004 209005 VPRN Up Up 9005 209006 VPRN Up Up 9006 2147483648 IES Up Down 1 _tmnx_InternalIesS* ------------------------------------------------------------------------------Matching Services : 45 ------------------------------------------------------------------------------=============================================================================== * indicates that the corresponding row element may have been truncated. *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#

            第 61 页 共 77 页

            2.3 检查路由器接口运行状态 2.3.1 查看所有接口状态
            show router interface 命令用于查看路由器接口运行情况 端口状态分 Adm 状态-管理状态,Opr 状态 端口实际的工作状态. port/sapId 代表该 interface 使用的是那个端口 *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router interface ===================================================== Interface Table (Router: Base) ===================================================== Interface-Name Adm Opr(v4/v6) Mode Port/SapId IP-Address PfxState ------------------------------------------------------------------------------BRAS Up Up/Down IES Sub subscriber 112.11.82.1/23 n/a WLAN-1/1/18 Up Up/Down IES Grp 1/1/18 ge-1/1/14:7.0 Up Up/Down IES Grp 1/1/14 ge-1/1/15:2543.0 Up Up/Down IES 1/1/15:2543.0 221.131.229.245/30 n/a ge-1/1/15:3994.0 Up Up/Down IES 1/1/15:3994.0 221.131.227.97/27 n/a ge-1/1/15:3999.0 Up Up/Down IES 1/1/15:3999.0 211.140.108.113/30 n/a ge-1/1/15:4000.0 Up Up/Down IES 1/1/15:4000.0 211.140.103.253/30 n/a ge-1/1/15:7.0 Up Up/Down IES Grp 1/1/15 ge-1/1/16:7.0 Up Up/Down IES Grp 1/1/16 ge-1/1/5:2018.0 Up Up/Down IES 1/1/5:2018.0 112.11.125.65/30 n/a ge-1/1/5:2030.0 Up Up/Down IES 1/1/5:2030.0 211.140.94.141/30 n/a ge-1/1/5:2539.0 Up Up/Down IES 1/1/5:2539.0 221.131.199.110/28 n/a ge-1/1/5:2542.0 Up Up/Down IES 1/1/5:2542.0 211.140.103.189/30 n/a ge-1/1/5:2547.0 Up Up/Down IES 1/1/5:2547.0 221.131.230.129/29 n/a
            第 62 页 共 77 页

            ge-1/1/5:2550.0 221.131.228.109/30 ge-1/1/5:2551.0 221.131.228.17/29 ge-1/1/5:2552.0 211.140.103.69/30 ge-1/1/5:2553.0 211.140.108.137/30 ge-1/1/5:2554.0 211.140.103.105/29 ge-1/1/5:2555.0 211.140.106.137/29 ge-1/1/5:2556.0 211.140.106.81/28 ge-1/1/5:2557.0 211.140.106.69/30 ge-1/1/5:2558.0 211.140.106.61/30 ge-1/1/5:2559.0 211.140.103.185/30 ge-1/1/5:7.0 ge-1/1/6:2500.0 112.11.127.101/30 ge-1/1/6:7.0 ge-1/1/7:2400.0 221.131.229.9/30 ge-1/1/7:7.0 ge-2/1/1 221.131.199.230/30 hexinnanluOLT lag-3:2544.0 221.131.229.225/30 lag-3:2546.0 221.131.229.125/30 lag-3:2558.0 221.131.229.69/30 lag-3:2559.0 221.131.228.245/30 lag-4:2019.0 112.11.125.17/29 lag-4:2021.0 112.11.127.113/30 lag-4:2556.0 221.131.229.149/30

            Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up Up

            Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down Up/Down

            IES IES IES IES IES IES IES IES IES IES IES Grp IES IES Grp IES IES Grp Network IES Grp IES IES IES IES IES IES IES

            1/1/5:2550.0 n/a 1/1/5:2551.0 n/a 1/1/5:2552.0 n/a 1/1/5:2553.0 n/a 1/1/5:2554.0 n/a 1/1/5:2555.0 n/a 1/1/5:2556.0 n/a 1/1/5:2557.0 n/a 1/1/5:2558.0 n/a 1/1/5:2559.0 n/a 1/1/5 1/1/6:2500.0 n/a 1/1/6 1/1/7:2400.0 n/a 1/1/7 2/1/1 n/a lag-3 lag-3:2544.0 n/a lag-3:2546.0 n/a lag-3:2558.0 n/a lag-3:2559.0 n/a lag-4:2019.0 n/a lag-4:2021.0 n/a lag-4:2556.0 n/a

            第 63 页 共 77 页

            lag-4:2557.0 Up Up/Down IES lag-4:2557.0 221.131.229.85/30 n/a lag-4:2558.0 Up Up/Down IES lag-4:2558.0 221.131.229.73/30 n/a lag-4:2559.0 Up Up/Down IES lag-4:2559.0 221.131.228.217/30 n/a lag1 Up Up/Down Network lag-1 221.131.199.154/30 n/a loopback0 Up Up/Down Network loopback 221.131.199.17/32 n/a msap Up Down/Down IES Grp n/a nanhuyouzhengOLT Up Up/Down IES Grp lag-4 sanshuiwan503 Up Up/Down IES Grp 1/1/6 system Up Up/Down Network system 221.131.199.18/32 n/a to-ALC-JiaYeYangGuangChengOLT Up Up/Down IES Grp lag-5 to-gaozhongyuanqu6503 Up Up/Down IES 1/1/14:18.0 211.140.102.93/30 n/a to-hexinnanlu6503 Up Up/Down IES Grp 1/1/16 to-jxydsjfwwhzx Up Up/Down IES lag-3:2020.0 112.11.127.253/30 n/a to-switchmangement Up Up/Down IES Sub subscriber 112.11.126.145/28 n/a to-yuxin6503 Up Up/Down IES Grp 1/1/7 to-zhongxingAC-W908 Up Up/Down IES 1/1/18:3502 112.11.124.1/29 n/a xiexi6503 Up Up/Down IES Grp 1/1/5 ------------------------------------------------------------------------------Interfaces : 55 ===================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#

            2.3.1 查看单个业务的接口状态
            show router 209001 interface 命令可以查看某个指定业务的接口状态
            *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router 209001 interface ===================================================== Interface Table (Service: 209001) ===============================================================================
            第 64 页 共 77 页

            Interface-Name Adm Opr(v4/v6) Mode Port/SapId IP-Address PfxState ------------------------------------------------------------------------------To_gpon_voip Up Up/Down VPRN S* subscriber 10.176.44.1/23 n/a To_maipu_ippbx Up Up/Down VPRN S* subscriber 10.176.4.1/23 n/a lag-3:96.0 Up Up/Down VPRN G* lag-3 lag-3:98.0 Up Up/Down VPRN G* lag-3 lag-4:96.0 Up Up/Down VPRN G* lag-4 lag-4:98.0 Up Up/Down VPRN G* lag-4 lag-5:98.0 Up Up/Down VPRN G* lag-5 ------------------------------------------------------------------------------Interfaces : 7 =============================================================================== * indicates that the corresponding row element may have been truncated. *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#

            第 65 页 共 77 页

            2.4 查看设备 MAC 地址表信息 2.4.1 查看所有 MAC 地址表
            show router arp 命令可以查看用户的 mac 地址有没有被 7750 学到 另外,show router arp 命令可以接具体参数,查看具体接口或 IP 地址对应 mac 的关系 show router arp - arp [<ip-int-name|ip-address>|mac <ieee-mac-address>|summary] 如 show router arp to_GM7750 或 show router arp 218.90.152.33 等

            *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router arp =============================================================================== ARP Table (Router: Base) =============================================================================== IP Address MAC Address Expiry Type Interface ------------------------------------------------------------------------------221.131.199.18 00:23:3e:65:3e:50 00h00m00s Oth system 221.131.199.153 00:23:3e:4a:ef:91 03h02m22s Dyn[I] lag1 221.131.199.154 00:23:3e:65:3f:91 00h00m00s Oth[I] lag1 221.131.199.229 28:6e:d4:0f:ed:a4 03h57m41s Dyn[I] ge-2/1/1 221.131.199.230 00:25:ba:30:5a:3c 00h00m00s Oth[I] ge-2/1/1 221.131.199.17 00:23:3e:65:3e:50 00h00m00s Oth loopback0 112.11.126.145 00:23:3e:65:3e:50 00h00m00s Oth[I] to-switchmangement 00:23:3e:96:f1:d9 ge-1/1/14:7.0 00:23:3e:96:f1:da ge-1/1/15:7.0 00:23:3e:96:f1:db ge-1/1/16:7.0 00:23:3e:96:f1:d0 ge-1/1/5:7.0 00:23:3e:96:f1:d1 ge-1/1/6:7.0 00:23:3e:96:f1:d2 ge-1/1/7:7.0 112.11.126.149 00:0f:e2:22:c3:b1 00h00m00s Man[I] ge-1/1/14:7.0 112.11.126.151 00:0f:e2:22:c0:91 00h00m00s Man[I] ge-1/1/15:7.0 112.11.126.150 00:0f:e2:5a:e0:ce 00h00m00s Man[I] ge-1/1/16:7.0 112.11.126.146 00:0f:e2:1e:97:0c 00h00m00s Man[I] ge-1/1/5:7.0 112.11.126.147 00:0f:e2:1e:8d:7f 00h00m00s Man[I] ge-1/1/6:7.0 112.11.126.148 00:0f:e2:df:16:c7 00h00m00s Man[I] ge-1/1/7:7.0 112.11.82.1 00:23:3e:65:3e:50 00h00m00s Oth[I] BRAS 00:23:3e:96:f1:d0 xiexi6503 00:23:3e:96:f1:d2 to-yuxin6503

            第 66 页 共 77 页

            211.140.102.93 211.140.102.94 211.140.94.141 211.140.94.142 112.11.127.113 112.11.127.114 112.11.127.101 112.11.127.102 221.131.199.97 221.131.199.98 221.131.199.99 221.131.199.100 221.131.199.110 211.140.103.189 211.140.103.190 221.131.229.245 221.131.229.246 221.131.229.225 221.131.229.226 221.131.229.125 221.131.229.126 221.131.230.129 221.131.230.130 221.131.228.109 221.131.228.110 221.131.228.17 221.131.228.18 221.131.228.19 221.131.228.20 221.131.228.21 221.131.228.22 211.140.103.69 211.140.103.70 211.140.108.137 211.140.108.138 211.140.103.105 211.140.103.106 211.140.103.107

            00:23:3e:65:3f:93 00:23:3e:96:f1:d1 00:23:3e:65:3f:94 00:23:3e:96:f1:db 00:23:3e:65:3f:95 00:23:3e:96:f1:dd 00:23:3e:96:f1:d9 00:0f:e2:22:c3:b1 00:23:3e:96:f1:d0 00:18:b9:64:7a:2c 00:23:3e:65:3f:94 00:22:6b:3a:ca:d9 00:23:3e:96:f1:d1 00:22:aa:9c:23:16 d8:d3:85:97:4a:ce d8:d3:85:97:4a:ce d8:d3:85:97:f1:ae d8:d3:85:97:4a:ce 00:23:3e:96:f1:d0 00:23:3e:96:f1:d0 84:2b:2b:4d:06:ac 00:23:3e:96:f1:da 00:18:e7:f2:0f:cf 00:23:3e:65:3f:93 00:21:27:ba:35:9b 00:23:3e:65:3f:93 00:40:48:21:99:4b 00:23:3e:96:f1:d0 a4:ba:db:1b:aa:55 00:23:3e:96:f1:d0 00:1e:73:96:ce:d1 00:23:3e:96:f1:d0 00:0d:48:01:47:1b 00:0d:48:01:47:1b 00:0d:48:01:47:1b 00:0d:48:01:47:1b 00:0d:48:01:47:1b 00:23:3e:96:f1:d0 00:04:27:48:5a:e0 00:23:3e:96:f1:d0 00:11:43:eb:14:ea 00:23:3e:96:f1:d0 00:e0:fc:06:2b:f8 00:13:72:58:91:61

            00h00m00s 03h43m10s 00h00m00s 00h11m12s 00h00m00s 00h40m58s 00h00m00s 03h59m58s 00h42m19s 03h59m56s 03h50m30s 00h24m56s 00h00m00s 00h00m00s 03h55m49s 00h00m00s 03h59m45s 00h00m00s 03h59m50s 00h00m00s 03h57m54s 00h00m00s 03h48m55s 00h00m00s 03h54m35s 00h00m00s 03h59m26s 00h26m22s 02h48m14s 03h56m26s 02h05m35s 00h00m00s 03h30m50s 00h00m00s 03h56m11s 00h00m00s 03h25m06s 00h16m46s

            Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Dyn[I] Dyn[I] Dyn[I] Dyn[I] Oth[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Dyn[I] Dyn[I] Dyn[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Dyn[I]

            hexinnanluOLT sanshuiwan503 nanhuyouzhengOLT to-hexinnanlu6503 to-ALC-JiaYeYangGuangChengO* WLAN-1/1/18 to-gaozhongyuanqu6503 to-gaozhongyuanqu6503 ge-1/1/5:2030.0 ge-1/1/5:2030.0 lag-4:2021.0 lag-4:2021.0 ge-1/1/6:2500.0 ge-1/1/6:2500.0 ge-1/1/5:2539.0 ge-1/1/5:2539.0 ge-1/1/5:2539.0 ge-1/1/5:2539.0 ge-1/1/5:2539.0 ge-1/1/5:2542.0 ge-1/1/5:2542.0 ge-1/1/15:2543.0 ge-1/1/15:2543.0 lag-3:2544.0 lag-3:2544.0 lag-3:2546.0 lag-3:2546.0 ge-1/1/5:2547.0 ge-1/1/5:2547.0 ge-1/1/5:2550.0 ge-1/1/5:2550.0 ge-1/1/5:2551.0 ge-1/1/5:2551.0 ge-1/1/5:2551.0 ge-1/1/5:2551.0 ge-1/1/5:2551.0 ge-1/1/5:2551.0 ge-1/1/5:2552.0 ge-1/1/5:2552.0 ge-1/1/5:2553.0 ge-1/1/5:2553.0 ge-1/1/5:2554.0 ge-1/1/5:2554.0 ge-1/1/5:2554.0

            第 67 页 共 77 页

            211.140.103.109 211.140.103.110 211.140.106.137 211.140.106.138 221.131.229.149 221.131.229.150 211.140.106.81 211.140.106.82 211.140.106.83 211.140.106.86 211.140.106.87 211.140.106.88 211.140.106.90 211.140.106.91 211.140.106.93 211.140.106.94 221.131.229.85 221.131.229.86 211.140.106.69 211.140.106.70 221.131.229.73 221.131.229.74 221.131.229.69 221.131.229.70 211.140.106.61 221.131.229.9 221.131.229.10 221.131.228.245 221.131.228.246 221.131.228.217 221.131.228.218 211.140.103.185 211.140.103.186 221.131.227.97 211.140.108.113 211.140.108.114 211.140.103.253 211.140.103.254 112.11.127.253 112.11.125.17 112.11.125.18 112.11.125.19 112.11.125.65 112.11.125.66

            00:0b:db:e6:8a:0b 00:14:78:b9:07:8d 00:23:3e:96:f1:d0 00:0e:0c:b5:56:11 00:23:3e:65:3f:94 00:40:48:21:99:3f 00:23:3e:96:f1:d0 00:22:aa:91:30:09

            00:40:36:35:d3:3b 00:73:06:05:46:96 00:18:8b:7a:0c:01 00:23:3e:65:3f:94 00:18:e7:fb:9e:e9 00:23:3e:96:f1:d0 00:14:78:da:3a:95 00:23:3e:65:3f:94 00:22:b0:9e:7b:77 00:23:3e:65:3f:93 00:22:b0:a0:8a:35 00:23:3e:96:f1:d0 00:23:3e:96:f1:d2 00:27:19:7b:2c:cf 00:23:3e:65:3f:93 00:22:b0:9e:7c:83 00:23:3e:65:3f:94 00:22:b0:9e:7d:a5 00:23:3e:96:f1:d0 00:06:5b:3d:a8:31 00:23:3e:96:f1:da 00:23:3e:96:f1:da e0:05:c5:1f:d1:2b 00:23:3e:96:f1:da 00:25:86:29:85:7d 00:23:3e:65:3f:93 00:23:3e:65:3f:94 00:e0:b0:f5:8b:13 00:04:61:8f:a3:2e 00:23:3e:96:f1:d0 84:2b:2b:56:5c:28

            00h15m07s 03h55m13s 00h00m00s 03h56m06s 00h00m00s 03h55m54s 00h00m00s 04h00m00s 03h05m56s 04h00m00s 04h00m00s 01h51m21s 03h56m10s 04h00m00s 02h51m40s 04h00m00s 00h00m00s 03h59m20s 00h00m00s 03h56m12s 00h00m00s 03h59m58s 00h00m00s 01h13m35s 00h00m00s 00h00m00s 03h59m12s 00h00m00s 03h59m54s 00h00m00s 03h59m55s 00h00m00s 03h53m11s 00h00m00s 00h00m00s 03h22m46s 00h00m00s 03h55m42s 00h00m00s 00h00m00s 03h59m57s 03h59m32s 00h00m00s 03h57m59s

            Dyn[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn Dyn[I] Dyn Dyn Dyn[I] Dyn[I] Dyn Dyn[I] Dyn Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Oth[I] Dyn[I] Oth[I] Dyn[I] Oth[I] Oth[I] Dyn[I] Dyn[I] Oth[I] Dyn[I]

            ge-1/1/5:2554.0 ge-1/1/5:2554.0 ge-1/1/5:2555.0 ge-1/1/5:2555.0 lag-4:2556.0 lag-4:2556.0 ge-1/1/5:2556.0 ge-1/1/5:2556.0 ge-1/1/5:2556.0 ge-1/1/5:2556.0 ge-1/1/5:2556.0 ge-1/1/5:2556.0 ge-1/1/5:2556.0 ge-1/1/5:2556.0 ge-1/1/5:2556.0 ge-1/1/5:2556.0 lag-4:2557.0 lag-4:2557.0 ge-1/1/5:2557.0 ge-1/1/5:2557.0 lag-4:2558.0 lag-4:2558.0 lag-3:2558.0 lag-3:2558.0 ge-1/1/5:2558.0 ge-1/1/7:2400.0 ge-1/1/7:2400.0 lag-3:2559.0 lag-3:2559.0 lag-4:2559.0 lag-4:2559.0 ge-1/1/5:2559.0 ge-1/1/5:2559.0 ge-1/1/15:3994.0 ge-1/1/15:3999.0 ge-1/1/15:3999.0 ge-1/1/15:4000.0 ge-1/1/15:4000.0 to-jxydsjfwwhzx lag-4:2019.0 lag-4:2019.0 lag-4:2019.0 ge-1/1/5:2018.0 ge-1/1/5:2018.0

            第 68 页 共 77 页

            112.11.82.239 00:1f:3b:79:2e:91 00h00m00s Man[I] WLAN-1/1/18 112.11.83.3 00:19:d2:d6:ad:45 00h00m00s Man[I] WLAN-1/1/18 112.11.83.9 00:17:c4:63:28:18 00h00m00s Man[I] WLAN-1/1/18 112.11.83.16 00:1e:e3:00:54:75 00h00m00s Man[I] WLAN-1/1/18 112.11.83.17 f0:7d:68:15:9e:b3 00h00m00s Man[I] WLAN-1/1/18 112.11.83.19 00:1b:77:2e:5b:3e 00h00m00s Man[I] WLAN-1/1/18 112.11.83.21 08:00:28:56:9a:82 00h00m00s Man[I] WLAN-1/1/18 112.11.83.22 00:1f:3c:3b:28:03 00h00m00s Man[I] WLAN-1/1/18 112.11.83.25 dc:2b:61:23:3b:89 00h00m00s Man[I] WLAN-1/1/18 112.11.83.26 00:1b:77:d4:18:4c 00h00m00s Man[I] WLAN-1/1/18 112.11.83.27 00:e0:4c:83:4e:57 00h00m00s Man[I] WLAN-1/1/18 112.11.83.28 00:22:43:0c:f9:28 00h00m00s Man[I] WLAN-1/1/18 112.11.124.1 00:23:3e:96:f1:dd 00h00m00s Oth[I] to-zhongxingAC-W908 112.11.124.2 08:18:1a:78:ee:2f 03h39m31s Dyn[I] to-zhongxingAC-W908 112.11.124.3 08:18:1a:78:ee:2f 02h15m57s Dyn[I] to-zhongxingAC-W908 ------------------------------------------------------------------------------No. of ARP Entries: 111 =============================================================================== * indicates that the corresponding row element may have been truncated. *A:ZJJXI-MC-CMNET-RT002-XieXi_7750 ping 218.90.152.33 service 100005

            2.4.2 查看单个业务的 MAC 地址表
            show router 209006 arp show service id 209006 arp 命令可以查看用户的 mac 地址有没有被 7750 学到

            *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router 209006 arp ============================================================================= ARP Table (Service: 209006) ============================================================================= IP Address MAC Address Expiry Type Interface ------------------------------------------------------------------------------10.176.224.5 00:23:3e:65:3e:50 00h00m00s Oth[I] To-jxyd_shengjiankong 00:23:3e:96:f1:d0 ge-1/1/5:191.0 ------------------------------------------------------------------------------No. of ARP Entries: 1

            第 69 页 共 77 页

            *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show service id 209006 arp ============================================================================= ARP Table =============================================================================== IP Address MAC Address Type Expiry Interface SAP ------------------------------------------------------------------------------10.176.224.5 00:23:3e:65:3e:50 Other 00h00m00s To-jxyd_shengjia* subscrib* 00:23:3e:96:f1:d0 ge-1/1/5:191.0 1/1/5 ============================================================================= * indicates that the corresponding row element may have been truncated. *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#

            2.5 查看设备路由表信息 2.5.1 查看所有路由表地址表
            show router router-table summary 命令可以查看所有学到的路由数 *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router route-table summary =============================================================================== Route Table Summary (Router: Base) =============================================================================== Active Available ------------------------------------------------------------------------------Static 2 2 Direct 40 40 Host 0 38 BGP 0 0 VPN Leak 0 0 OSPF 9744 9744 ISIS 0 0 RIP 0 0 LDP 0 0 Aggregate 0 0 Sub Mgmt 30 30 Managed 0 0 -------------------------------------------------------------------------------

            第 70 页 共 77 页

            Total 9816 9854 =============================================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router route-table route-table [<family>] [<ip-prefix[/prefix-length]> [longer|exact|protocol <protocol-name>] [all]] [next-hop-type <type>] - route-table [<family>] summary - route-table <tunnel-endpoints> [<ip-prefix[/prefix-length]>] [longer|exact] [detail] <ip-prefix[/prefix*> : ipv4-prefix - a.b.c.d (host bits must be 0) ipv4-prefix-le - [0..32] ipv6-prefix - x:x:x:x:x:x:x:x (eight 16-bit pieces) x:x:x:x:x:x:d.d.d.d x - [0..FFFF]H d - [0..255]D ipv6-prefix-le - [0..128] <summary> : keyword <protocol-name> local|sub-mgmt|managed|static|ldp|ospf|ospf3|isis|rip|aggregate|bgp|bgp-vpn|vpn-leak <family> : ipv4|ipv6|mcast-ipv4|mcast-ipv6 <longer|exact> : keywords <all> : keyword - include inactive routes <tunnel-endpoints> : keyword <detail> : keyword <type> : tunneled

            :

            *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router route-table

            2.5.2 查看某个业务的路由表
            show router 209001 router-table summary 命令可以查看某个业务所学到的路由数 *A:ZJJXI-MC-CMNET-RT002-XieXi_7750# show router 209001 route-table summary ===================================================== Route Table Summary (Service: 209001) ===================================================== Active Available
            第 71 页 共 77 页

            ------------------------------------------------------------------------------Static 0 0 Direct 2 2 Host 0 2 BGP 0 0 BGP VPN 1293 1294 OSPF 0 0 ISIS 0 0 RIP 0 0 LDP 0 0 Aggregate 0 0 Sub Mgmt 35 35 Managed 0 0 ------------------------------------------------------------------------------Total 1330 1333 ===================================================== *A:ZJJXI-MC-CMNET-RT002-XieXi_7750#

            第 72 页 共 77 页

            3. 故障排除方法说明
            3.1 光路正常但 port 端口 down
            检查两端端口是否进行协商,7750 port 默认为自协商开启 configure port x/x/x ethernet no auto 验证命令 show port (关闭端口自协商)

            3.2

            ping 不通对端地址

            检查 port 是否采用正确的封装模式,interface 下 binding 的 port 是否正确 configure port x/x/x ethernet encap-type qinq/dot1q/null

            3.3

            ISIS 邻接关系无法建立

            检查两端的 ISIS 参数是否一致 show router ISIS adj x.x.x.x detail show router isis interface

            3.4

            BGP 邻居无法正常建立

            使用命令 show router bgp neighbor 检查邻居关系,如显示为 no-type 则表明本地 AS 号没有被配置或者 BGP type 没 有 被 配 置 , 如 果 显 示 Bad Peer AS 则 说 明 对 端 指 向 本 地 的 as 号 配 错 了 。 并 且 检 查 两 端 BGP 配 置 中 的 authentication-key 及 family-address 等其他参数。

            3.5

            BGP 表中有路由,但路由没有被放进 vpn 路由表中

            检查 BGP 路由的下一跳地址是否可达,并且由于是 vpn 路由,7750 要求下一跳的 ldp 也要可达。 show router bgp routes prefix

            第 73 页 共 77 页

            3.6

            VPN 中用户 CE 设备无法访问远端

            首先应该检查本端 VPN 实例是否配置完整,包括 RD、RT 策略、LDP 等 接着应该检查本端 PE 与本端 CE 的连通性,在 PE 使用 ping router xxxxx address,并查看 arp 表 然后检查 7750 的 VPN 路由表,看远端路由学习是否正常 show router xxxxx route-table 使用 ping remote-address router xxxxx 看本端 PE 是否能成功访问远端 在远端 PE 重复上述检查过程

            3.7 VPLS 故障分析
            3.7.1 按照下列配置做 mac-filter
            *B:r2-g-ncxjx-1.Mnet>config>filter# info ---------------------------------------------log 102 create exit log 103 create exit mac-filter 10 create default-action forward entry 10 create match src-mac 00:00:00:00:00:01 ff:ff:ff:ff:ff:ff dst-mac 00:00:00:00:00:02 ff:ff:ff:ff:ff:ff exit log 102 action forward exit exit mac-filter 20 create default-action forward entry 10 create match
            第 74 页 共 77 页

            src-mac 00:00:00:00:00:02 ff:ff:ff:ff:ff:ff dst-mac 00:00:00:00:00:01 ff:ff:ff:ff:ff:ff exit log 103 action forward exit exit

            3.7.2 在 VPLS 中应用 MAC-FILTER
            *B:r2-g-ncxjx-1.Mnet>config>service>vpls# info ---------------------------------------------description "tangshanpaichusuo" stp shutdown exit sap 1/1/3:501.0 create ingress filter mac 1 exit egress filter mac 20 exit exit mesh-sdp 1002:3029 create exit no shutdown ----------------------------------------------

            3.8.3 通过分析 LOG 找出问题
            Show filter log 102 Show filter log 103

            第 75 页 共 77 页

            4 删除 Service 配置步骤
            如果要删除或修改一个 service,有以下步骤

            4.1 删除单个 sap Service 配置步骤
            1 首先将 interface 中的 sap shutdown 并移除(IES,VPRN,VPLS) interface to_xxxxx_80 sap 1/1/8:200.0 shutdown no sap 1/1/8:200.0 2 接着将 interface shutdown 并从 service 业务中移除(IES,VPRN) interface to_xxxxx_80 shutdown no interface to_xxxxx_80 3 最后将 ies shutdown 并从 service 中移除(IES,VPRN,VPLS) ies 11180200 shutdown no ies 11180200 vprn 209008 shutdown no vprn 209008 vpls 1000 shutdown no vpls 1000 如须更换 sap,须将 sap shutdown 移除后再配置新的 sap 上去 interface to_xxxxx_80 sap 1/1/8:200 shutdown no sap 1/1/8:200 sap 1/1/8:2000 create ingress qos 10 egress qos 10

            4.2 删除多个 sap Service 配置步骤
            1 逐个将 group-interface 中的 sap shutdown 并移除(IES,VPRN,VPLS) group-interface gi-1/1/8 sap 1/1/8:200.0 shutdown no sap 1/1/8:200.0 2 逐个将 group-interface shutdown 并从 subscriber-interface 中移除(IES,VPRN)
            第 76 页 共 77 页

            group-interface gi-1/1/8 shutdown no group-interface gi-1/1/8 3 逐个将 subscriber-interface shutdown 并从 service 业务中移除(IES,VPRN) subscriber-interface to_xxxxx_80 shutdown no subscriber-interface to_xxxxx_80 3 最后将业务 shutdown 并从 service 中移除(IES,VPRN,VPLS) ies 11180200 shutdown no ies 11180200 vprn 209008 shutdown no vprn 209008 vpls 1000 shutdown no vpls 1000

            第 77 页 共 77 页


            相关文章:
            湖南广电7750SR-BRAS功能测试手册-xiaohe
            10W篇文档免费专享 每天抽奖多种福利 立即开通 意见...湖南广电7750SR-BRAS功能测试手册-xiaohe_IT/计算机_...(1)Local-DCHP 配置 //配置 router Interface ...
            浙江移动7750BRAS配置规范-v3.0-20150310
            浙江移动城域网 SR/BRAS 路由器 (Alcatel-Lucent 7750) 设备配置规范 上海贝尔...“to_xxxx_xx” #必须配置描述方便维护,内容包含对端设备和端口 ethernet e...
            广东移动IP城域网BRAS业务配置规范7750分册V1.1(试行稿)
            考虑到城域网网络设备维护分工明确,配置规范按分册进行编写,本篇 只针对阿尔卡特...7.0 版本将 PPPOE 与 L2TP 业务关联,7750SR 可以支持 L2TPv2 的 LAC 功能。...
            7750BRAS业务开局手册
            7750SR+BRAS业务配置手册... 27页 免费 7750-BRAS故障高级培训 48页 免费 BRAS配置及其维护 26页 免费 PTN产品介绍及开局经验交... 59页 2下载券©...
            7750BRAS pppoe配置脚本
            7750BRAS pppoe配置脚本_计算机硬件及网络_IT/计算机_专业资料。阿尔卡特7750 BRAS pppoe基本配置新增端口的pppoe配置: config port 1/1/5 description "tes" etherne...
            7750 BRAS 734、629故障案例-20160812
            7750 BRAS 734、629故障案例-20160812_计算机硬件及网络_IT/计算机_专业资料。小...7750SR BRAS业务配置手册... 27页 免费 7750BRAS操作维护手册 46页 1下载券...
            更多相关标签: