Добрый день всем. Имеем Cisco 861.
Cisco IOS Software, C860 Software (C860-UNIVERSALK9-M), Version 12.4(24)T4, RELEASE SOFTWARE (fc2)
version 12.4
parser config cache interface
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname Cisco
!
boot-start-marker
boot system flash c860-universalk9-mz.124-24.T4.bin
boot-end-marker
!
logging message-counter syslog
logging buffered 4096 errors
enable secret
enable password
!
no aaa new-model
memory-size iomem 10
!
!
ip source-route
ip dhcp excluded-address 192.168.104.1 192.168.104.99
ip dhcp excluded-address 192.168.104.200 192.168.104.255
!
ip dhcp pool lan
network 192.168.104.0 255.255.255.0
default-router 192.168.104.1
domain-name cisco
dns-server 192.168.104.1
!
!
ip cef
ip name-server 82.*
ip name-server 82.*
ip name-server 213.*
ip name-server 195.*
no ip dhcp-client broadcast-flag
!
!
vpdn enable
!
!
!
!
no spanning-tree vlan 1
no spanning-tree vlan 2
username!
!
!
archive
log config
hidekeys
!
!
!
track 1 ip sla 1 reachability
delay down 2 up 2
!
!
bba-group pppoe global
!
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
switchport access vlan 2
!
interface FastEthernet4
description Internet 2
ip virtual-reassembly
no ip route-cache cef
no ip route-cache
duplex auto
speed auto
pppoe enable group global
pppoe-client dial-pool-number 1
!
interface Vlan1
ip address 192.168.104.1 255.255.255.0
ip nat inside
ip virtual-reassembly
no ip route-cache cef
no ip route-cache
!
interface Vlan2
description Internet 1
ip address dhcp
ip nat outside
ip virtual-reassembly
!
interface Dialer0
description ADSL to Internet 2
ip address negotiated
ip mtu 1492
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication pap callin
ppp pap sent-username *** password ***
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 82.*.*.1 100 Track 1
ip route 0.0.0.0 0.0.0.0 213.*.*.252 200
no ip http server
no ip http secure-server
!
ip dns server
ip nat inside source route-map ISP-1 interface Vlan2 overload
ip nat inside source route-map ISP-2 interface Dialer0 overload
!
ip sla 1
icmp-echo Internet1-g source-interface vlan2
timeout 1000
threshold 2
frequency 3
ip sla schedule 1 life forever start-time nowaccess-list 11 remark NAT
access-list 11 permit 192.168.104.0 0.0.0.255
dialer-list 1 protocol ip permitroute-map ISP-2 permit 20
match ip address 11
match interface Dialer0
!
route-map ISP-1 permit 10
match ip address 11
match interface vlan2
!
!
control-planeline con 0
password
login
no modem enable
transport preferred none
line aux 0
line vty 0
password
login
no activation-character
transport preferred none
transport input all
line vty 1 4
password
login
!
scheduler max-task-time 5000
endПроблема в следующем:
При соединении с провайдером по ADSL интерфейс FastEthernet4 постоянно шлет запросы
*Mar 2 00:16:44.863: PPPoE 0: I PADI R:0023.f8a7.61f6 L:ffff.ffff.ffff 3 Fa4
*Mar 2 00:16:45.383: PPPoE 0: I PADI R:0013.49e9.5bfb L:ffff.ffff.ffff 3 Fa4
*Mar 2 00:16:47.855: PPPoE 0: I PADI R:0023.f8a7.61f6 L:ffff.ffff.ffff 3 Fa4
*Mar 2 00:16:48.383: PPPoE 0: I PADI R:0013.49e9.5bfb L:ffff.ffff.ffff 3 Fa4
*Mar 2 00:16:50.847: PPPoE 0: I PADI R:0023.f8a7.61f6 L:ffff.ffff.ffff 3 Fa4
*Mar 2 00:16:51.383: PPPoE 0: I PADI R:0013.49e9.5bfb L:ffff.ffff.ffff 3 Fa4
(на дату не смотрите - не выставлял)
и при этом IP от провайдера я получаю.Interface IP-Address OK? Method Status Protocol
Dialer0 213.*.*.81 YES IPCP up up
FastEthernet0 unassigned YES unset up up
FastEthernet1 unassigned YES unset up up
FastEthernet2 unassigned YES unset up up
FastEthernet3 unassigned YES unset up up
FastEthernet4 unassigned YES NVRAM up up
NVI0 unassigned YES unset administratively down down
Virtual-Access1 unassigned YES unset up up
Vlan1 192.168.104.1 YES NVRAM up up
Vlan2 82.*.*.53 YES DHCP up upПомогите разобраться в чем может быть затык. Заранее спасибо.
>[оверквотинг удален]
> 192.168.104.1
> YES NVRAM up
>
> up
> Vlan2
> 82.*.*.53
> YES DHCP up
>
> up
> Помогите разобраться в чем может быть затык. Заранее спасибо.А что пров на эту тему говорит?
>[оверквотинг удален]
>> YES NVRAM up
>>
>> up
>> Vlan2
>> 82.*.*.53
>> YES DHCP up
>>
>> up
>> Помогите разобраться в чем может быть затык. Заранее спасибо.
> А что пров на эту тему говорит?Я не думаю, что это проблема со стороны прова ... я IP от них получаю, их шлюз пингую с Di0 интерфейса ... а вот достучаться с самой Циски на Di0 не могу.
На правах АПа ... все еще актуально. Гуру помогите разобраться, пожалуйста.
> Помогите разобраться в чем может быть затык. Заранее спасибо.ip route 0.0.0.0 0.0.0.0 213.*.*.252 200
замените на
ip route 0.0.0.0 0.0.0.0 Dialer0 200остальное - в дебаг
deb pppoe events
deb ppp nego
deb ppp authen
>> Помогите разобраться в чем может быть затык. Заранее спасибо.
> ip route 0.0.0.0 0.0.0.0 213.*.*.252 200
> замените на
> ip route 0.0.0.0 0.0.0.0 Dialer0 200
> остальное - в дебаг
> deb pppoe events
> deb ppp nego
> deb ppp authenСпасибо, сегодня попробую
>>> Помогите разобраться в чем может быть затык. Заранее спасибо.
>> ip route 0.0.0.0 0.0.0.0 213.*.*.252 200
>> замените на
>> ip route 0.0.0.0 0.0.0.0 Dialer0 200
>> остальное - в дебаг
>> deb pppoe events
>> deb ppp nego
>> deb ppp authen*Mar 2 17:18:31.483: Sending PADI: Interface = FastEthernet4
*Mar 2 17:18:31.491: PPPoE 0: I PADO R:0030.4866.a3b3 L:2894.0fc3.aeb8 Fa4
*Mar 2 17:18:31.539: PPPoE 0: I PADI R:0023.f8a7.61f6 L:ffff.ffff.ffff Fa4
*Mar 2 17:18:33.531: PPPOE: we've got our pado and the pado timer went off
*Mar 2 17:18:33.531: OUT PADR from PPPoE Session
*Mar 2 17:18:33.535: PPPoE 6809: I PADS R:0030.4866.a3b3 L:2894.0fc3.aeb8 Fa4
*Mar 2 17:18:33.539: IN PADS from PPPoE Session
*Mar 2 17:18:33.539: %DIALER-6-BIND: Interface Vi1 bound to profile Di0
*Mar 2 17:18:33.539: PPPoE: Virtual Access interface obtained.
*Mar 2 17:18:33.539: PPPoE : encap string prepared
*Mar 2 17:18:33.539: [0]PPPoE 6809: data path set to Virtual Acess
*Mar 2 17:18:33.539: Vi1 PPP: Phase is DOWN, Setup
*Mar 2 17:18:33.539: Vi1 PPP: Using dialer call direction
*Mar 2 17:18:33.539: Vi1 PPP: Treating connection as a callout
*Mar 2 17:18:33.539: Vi1 PPP: Session handle[42000018] Session id[0]
*Mar 2 17:18:33.539: Vi1 PPP: Phase is ESTABLISHING, Active Open
*Mar 2 17:18:33.539: Vi1 PPP: Authorization required
*Mar 2 17:18:33.539: Vi1 PPP: No remote authentication for call-out
*Mar 2 17:18:33.539: Vi1 LCP: O CONFREQ [Closed] id 1 len 10
*Mar 2 17:18:33.543: Vi1 LCP: MagicNumber 0x97D2AD91 (0x050697D2AD91)
*Mar 2 17:18:33.543: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state to up
*Mar 2 17:18:33.547: Vi1 LCP: I CONFACK [REQsent] id 1 len 10
*Mar 2 17:18:33.547: Vi1 LCP: MagicNumber 0x97D2AD91 (0x050697D2AD91)
*Mar 2 17:18:34.219: PPPoE 0: I PADI R:0017.9a78.be9d L:ffff.ffff.ffff Fa4
*Mar 2 17:18:34.303: PPPoE 0: I PADI R:0013.49e9.5bfb L:ffff.ffff.ffff Fa4
*Mar 2 17:18:34.531: PPPoE 0: I PADI R:0023.f8a7.61f6 L:ffff.ffff.ffff Fa4
*Mar 2 17:18:35.539: Vi1 LCP: Timeout: State ACKrcvd
*Mar 2 17:18:35.539: Vi1 LCP: O CONFREQ [ACKrcvd] id 2 len 10
*Mar 2 17:18:35.539: Vi1 LCP: MagicNumber 0x97D2AD91 (0x050697D2AD91)
*Mar 2 17:18:35.539: Vi1 LCP: I CONFREQ [REQsent] id 2 len 20
*Mar 2 17:18:35.539: Vi1 LCP: PFC (0x0702)
*Mar 2 17:18:35.539: Vi1 LCP: MRU 1492 (0x010405D4)
*Mar 2 17:18:35.539: Vi1 LCP: MagicNumber 0xDDAA6352 (0x0506DDAA6352)
*Mar 2 17:18:35.539: Vi1 LCP: AuthProto PAP (0x0304C023)
*Mar 2 17:18:35.539: Vi1 LCP: O CONFNAK [REQsent] id 2 len 8
*Mar 2 17:18:35.539: Vi1 LCP: MRU 1500 (0x010405DC)
*Mar 2 17:18:35.547: Vi1 LCP: I CONFACK [REQsent] id 2 len 10
*Mar 2 17:18:35.547: Vi1 LCP: MagicNumber 0x97D2AD91 (0x050697D2AD91)
*Mar 2 17:18:35.547: Vi1 LCP: I CONFREQ [ACKrcvd] id 3 len 20
*Mar 2 17:18:35.547: Vi1 LCP: PFC (0x0702)
*Mar 2 17:18:35.547: Vi1 LCP: MRU 1492 (0x010405D4)
*Mar 2 17:18:35.547: Vi1 LCP: MagicNumber 0xDDAA6352 (0x0506DDAA6352)
*Mar 2 17:18:35.547: Vi1 LCP: AuthProto PAP (0x0304C023)
*Mar 2 17:18:35.547: Vi1 LCP: O CONFNAK [ACKrcvd] id 3 len 8
*Mar 2 17:18:35.547: Vi1 LCP: MRU 1500 (0x010405DC)
*Mar 2 17:18:35.555: Vi1 LCP: I CONFREQ [ACKrcvd] id 4 len 20
*Mar 2 17:18:35.555: Vi1 LCP: PFC (0x0702)
*Mar 2 17:18:35.555: Vi1 LCP: MRU 1492 (0x010405D4)
*Mar 2 17:18:35.555: Vi1 LCP: MagicNumber 0xDDAA6352 (0x0506DDAA6352)
*Mar 2 17:18:35.555: Vi1 LCP: AuthProto PAP (0x0304C023)
*Mar 2 17:18:35.555: Vi1 LCP: O CONFNAK [ACKrcvd] id 4 len 8
*Mar 2 17:18:35.555: Vi1 LCP: MRU 1500 (0x010405DC)
*Mar 2 17:18:35.563: Vi1 LCP: I CONFREQ [ACKrcvd] id 5 len 20
*Mar 2 17:18:35.563: Vi1 LCP: PFC (0x0702)
*Mar 2 17:18:35.563: Vi1 LCP: MRU 1492 (0x010405D4)
*Mar 2 17:18:35.563: Vi1 LCP: MagicNumber 0xDDAA6352 (0x0506DDAA6352)
*Mar 2 17:18:35.563: Vi1 LCP: AuthProto PAP (0x0304C023)
*Mar 2 17:18:35.563: Vi1 LCP: O CONFNAK [ACKrcvd] id 5 len 8
*Mar 2 17:18:35.563: Vi1 LCP: MRU 1500 (0x010405DC)
*Mar 2 17:18:35.571: Vi1 LCP: I CONFREQ [ACKrcvd] id 6 len 20
*Mar 2 17:18:35.571: Vi1 LCP: PFC (0x0702)
*Mar 2 17:18:35.571: Vi1 LCP: MRU 1492 (0x010405D4)
*Mar 2 17:18:35.571: Vi1 LCP: MagicNumber 0xDDAA6352 (0x0506DDAA6352)
*Mar 2 17:18:35.571: Vi1 LCP: AuthProto PAP (0x0304C023)
*Mar 2 17:18:35.571: Vi1 LCP: O CONFNAK [ACKrcvd] id 6 len 8
*Mar 2 17:18:35.571: Vi1 LCP: MRU 1500 (0x010405DC)
*Mar 2 17:18:35.579: Vi1 LCP: I CONFREQ [ACKrcvd] id 7 len 20
*Mar 2 17:18:35.579: Vi1 LCP: PFC (0x0702)
*Mar 2 17:18:35.579: Vi1 LCP: MRU 1492 (0x010405D4)
*Mar 2 17:18:35.579: Vi1 LCP: MagicNumber 0xDDAA6352 (0x0506DDAA6352)
*Mar 2 17:18:35.579: Vi1 LCP: AuthProto PAP (0x0304C023)
*Mar 2 17:18:35.579: Vi1 LCP: O CONFREJ [ACKrcvd] id 7 len 8
*Mar 2 17:18:35.583: Vi1 LCP: MRU 1492 (0x010405D4)
*Mar 2 17:18:35.591: Vi1 LCP: I CONFREQ [ACKrcvd] id 8 len 16
*Mar 2 17:18:35.591: Vi1 LCP: PFC (0x0702)
*Mar 2 17:18:35.591: Vi1 LCP: MagicNumber 0xDDAA6352 (0x0506DDAA6352)
*Mar 2 17:18:35.591: Vi1 LCP: AuthProto PAP (0x0304C023)
*Mar 2 17:18:35.591: Vi1 LCP: O CONFACK [ACKrcvd] id 8 len 16
*Mar 2 17:18:35.591: Vi1 LCP: PFC (0x0702)
*Mar 2 17:18:35.591: Vi1 LCP: MagicNumber 0xDDAA6352 (0x0506DDAA6352)
*Mar 2 17:18:35.591: Vi1 LCP: AuthProto PAP (0x0304C023)
*Mar 2 17:18:35.591: Vi1 LCP: State is Open
*Mar 2 17:18:35.591: Vi1 PPP: No authorization without authentication
*Mar 2 17:18:35.591: Vi1 PPP: Phase is AUTHENTICATING, by the peer
*Mar 2 17:18:35.591: Vi1 PAP: Using hostname from interface PAP
*Mar 2 17:18:35.591: Vi1 PAP: Using password from interface PAP
*Mar 2 17:18:35.591: Vi1 PAP: O AUTH-REQ id 1 len 24 from "*********"
*Mar 2 17:18:35.623: Vi1 PAP: I AUTH-ACK id 1 len 12 msg is "Welcome"
*Mar 2 17:18:35.623: Vi1 PPP: Phase is FORWARDING, Attempting Forward
*Mar 2 17:18:35.627: Vi1 PPP: Phase is ESTABLISHING, Finish LCP
*Mar 2 17:18:35.627: Vi1 PPP: Phase is UP
*Mar 2 17:18:35.627: Vi1 IPCP: O CONFREQ [Closed] id 1 len 10
*Mar 2 17:18:35.627: Vi1 IPCP: Address 0.0.0.0 (0x030600000000)
*Mar 2 17:18:35.627: Vi1 CDPCP: O CONFREQ [Closed] id 1 len 4
*Mar 2 17:18:35.627: Vi1 PPP: Process pending ncp packets
*Mar 2 17:18:35.627: Vi1 IPCP: I CONFREQ [REQsent] id 1 len 10
*Mar 2 17:18:35.627: Vi1 IPCP: Address 213.*.*.252 (0x0306D5E3C0FC)
*Mar 2 17:18:35.627: Vi1 IPCP: O CONFACK [REQsent] id 1 len 10
*Mar 2 17:18:35.627: Vi1 IPCP: Address 213.*.*.252 (0x0306D5E3C0FC)
*Mar 2 17:18:35.643: Vi1 IPCP: I CONFNAK [ACKsent] id 1 len 10
*Mar 2 17:18:35.643: Vi1 IPCP: Address 213.*.*.81 (0x0306D5E3C651)
*Mar 2 17:18:35.643: Vi1 IPCP: O CONFREQ [ACKsent] id 2 len 10
*Mar 2 17:18:35.643: Vi1 IPCP: Address 213.*.*.81 (0x0306D5E3C651)
*Mar 2 17:18:35.647: Vi1 LCP: I PROTREJ [Open] id 1 len 10 protocol CDPCP (0x820701010004)
*Mar 2 17:18:35.647: Vi1 CDPCP: State is Closed
*Mar 2 17:18:35.647: Vi1 CDPCP: State is Listen
*Mar 2 17:18:35.655: Vi1 IPCP: I CONFACK [ACKsent] id 2 len 10
*Mar 2 17:18:35.655: Vi1 IPCP: Address 213.*.*.81 (0x0306D5E3C651)
*Mar 2 17:18:35.655: Vi1 IPCP: State is Open
*Mar 2 17:18:35.655: Di0 IPCP: Install negotiated IP interface address 213.*.*.81
*Mar 2 17:18:35.659: Di0 IPCP: Install route to 213.*.*.252
*Mar 2 17:18:35.659: Vi1 IPCP: Add link info for cef entry 213.*.*.252
*Mar 2 17:18:36.627: %LINEPROTO-5-UPDOWN: Line protocol on Interface Virtual-Access1, changed state to up
*Mar 2 17:18:37.303: PPPoE 0: I PADI R:0013.49e9.5bfb L:ffff.ffff.ffff Fa4
*Mar 2 17:18:37.527: PPPoE 0: I PADI R:0023.f8a7.61f6 L:ffff.ffff.ffff Fa4
*Mar 2 17:18:40.303: PPPoE 0: I PADI R:0013.49e9.5bfb L:ffff.ffff.ffff Fa4
*Mar 2 17:18:40.519: PPPoE 0: I PADI R:0023.f8a7.61f6 L:ffff.ffff.ffff Fa4
*Mar 2 17:18:43.303: PPPoE 0: I PADI R:0013.49e9.5bfb L:ffff.ffff.ffff Fa4
*Mar 2 17:18:43.511: PPPoE 0: I PADI R:0023.f8a7.61f6 L:ffff.ffff.ffff Fa4
*Mar 2 17:18:46.303: PPPoE 0: I PADI R:0013.49e9.5bfb L:ffff.ffff.ffff Fa4
*Mar 2 17:18:46.503: PPPoE 0: I PADI R:0023.f8a7.61f6 L:ffff.ffff.ffff Fa4
*Mar 2 17:18:49.303: PPPoE 0: I PADI R:0013.49e9.5bfb L:ffff.ffff.ffff Fa4
*Mar 2 17:18:49.499: PPPoE 0: I PADI R:0023.f8a7.61f6 L:ffff.ffff.ffff Fa4
*Mar 2 17:18:52.303: PPPoE 0: I PADI R:0013.49e9.5bfb L:ffff.ffff.ffff Fa4
Вот такая картина получаетсяP.S. traceroute на 213.*.*.252 (шлюз провайдера) идет напрямую.
P.S.S. раз в минуту дебаг показывает - *Mar 2 17:31:27.655: Vi1 PPP: Outbound cdp packet dropped