C300 V1.2.0¿ª¾ÖÖ¸µ¼Êé ÏÂÔر¾ÎÄ

ͼ2-1 MFFʵÏÖÔ­Àí

Switch AºÍSwitch B×÷ΪÒÔÌ«Íø½ÓÈë½Úµã£¨Ethernet Access Nodes£¬EAN£©£¬ÌṩÁË¿Í»§¶ËÖ÷»úÓë»ã¾Û½Úµã£¨Switch C£©Ö®¼äµÄÁ¬½Ó¡£ÔÚÒÔÌ«Íø½ÓÈë½ÚµãÉÏÅäÖÃMFF¹¦ÄÜ£¬¿ÉÒÔʹ¿Í»§¶ËµÄÊý¾Ý±¨ÎĽ»»¥È«²¿Í¨¹ýÍø¹Øת·¢£¬ÊµÏÖÁË¿Í»§¶ËÖ®¼äµÄÈý²ã»¥Í¨£¬ÓÖ±£Ö¤Á˶þ²ãÊý¾ÝµÄ¸ôÀë¡£

Host A¿´µ½µÄHost BµÄMACÒ²ÊÇgatewayµÄ£¬ÕâÑù±£Ö¤¼´Ê¹Host AºÍHost BÊÇͬһÍø¶Î£¬Í¬Ò»Vlan£¬ËûÃǵĽ»»»Ò²±ØÐë¾­¹ýgateway£¬´Ó¶øʵÏÖ¶þ²ã¸ôÀë¡£

1£© ÅäÖÃ

Óû§Îª¾²Ì¬IPµØÖ·Óû§Ê±£¬ÐèÒªµÄÅäÖÃÈçÏ£º ÅäÖõ¥tagµÄservice-port£¨Ë«tagµÄÄ¿Ç°²»Ö§³Ö£©£¬²¢ÅäÖÃÉÏÁª¿ÚºÍONUÉϵÄÏà¹ØVLAN£¬Ê¹ÒµÎñÄÜͨ¡£

¿ªÆômff¿ª¹Ø¡£ ÅäÖÃmffÍø¹Ø¡£

Óû§ÎªdhcpÓû§Ê±£¬ÐèÒªµÄÅäÖÃÈçÏ£º Ç°ÈýÏîͬÉÏ£¬ÁíÍ⻹ÐèÒªÅäÖãº

ÔÚÈ«¾ÖºÍservice-portÉÏ¿ªÆôdhcp snooping¹¦ÄÜ¡£

×¢Ò⣺²»ÄÜÅäÖöÔÓ¦VLANµÄÈý²ã½Ó¿Ú¡£²»È»¸Ã¹¦ÄÜÎÞЧÁË¡£ 2£© ÃüÁî

ZXAN(config)#Ip-service mac-forced-forwarding {enable | disable} ÅäÖÃmacµØÖ·Ç¿ÖÆת·¢¹¦ÄÜ¿ª¹Ø״̬¡£

ZXAN(config)# [no] ip-service mac-forced-forwarding vlan gateway [mac-address]

ÅäÖÃÆôÓÃij¸övlanϵÄmac-forced-forwarding Íø¹ØIP\\MAC¡£ Ŀǰϵͳ֧³ÖÅäÖÃ×î¶à°Ë¸övlanµÄMFFÍø¹ØÊý¾Ý¡£

ÔÚZXAN# Show ip-service arp [ dhcp | ipoa-dynamic | ipoa-static | dynamic |fixed | ip-addr ] [vlan ]

ÏÔʾmac-forced-forwarding ¹¦ÄÜʹÓõÄarpÓ³Éä±íÐÅÏ¢¡£ ZXAN# show ip-service mac-forced-forwarding ÏÔʾMAC forced forwarding È«¾Ö¿ª¹Ø״̬¡£

ZXAN#show ip-service mac-forced-forwarding gateway ÏÔʾMAC forced forwarding ¸÷vlanÏÂÍø¹ØÐÅÏ¢¡£

1.43 MAC·ÀƯ¹¦ÄÜ

¹¦ÄܽéÉÜ

MACµØַƯÒƾ­³£³öÏÖÔÚ´æÔÚMACµØÖ·ÆÛÆ­»òÕßϵͳ£¨ÌرðÊÇÓû§²à£©³É»·µÈÇé¿öÏ£¬·ÀÖ¹MAµØÖ·µÄƯÒÆ£¬¿ÉÒÔÒ»¶¨³Ì¶ÈÉϱ£Ö¤ÏµÍ³µÄÎȶ¨ÔËÐС£

ϵͳʵÏÖ

ϵͳʵÏÖÊôÓÚÓ²¼þ·ÀƯ£¬²»Äܲ鿴·ÀƯ¼Ç¼¡£ ÅäÖÃ

C300V1.1ϵͳµÄMACµØÖ··ÀƯÒÆÉæ¼°µ½µÄÃüÁîÓУº

1¡¢ security mac-anti-spoofing enable/ disable¡ª¡ªMACµØÖ··ÀƯÒÆ×Ü¿ª¹Ø

2¡¢ security mac-anti-spoofing uplink-protect enable/ disable¡ª¡ªÉÏÁª¿ÚÓÅÏÈ¿ª¹Ø 3¡¢ security uplink-protected-mac¡ª¡ªÍø¹Ø±£»¤µØÖ· ˵Ã÷

1£© ËùÓзÀƯÒƹ¦Äܶ¼ÒªÔÚMACµØÖ··ÀƯÒÆ×Ü¿ª¹Ø¿ªÆôºó²ÅÄÜÉúЧ¡£

2£© µ±Î´¿ªÆô×Ü¿ª¹Øʱ£¬MACµØÖ·¿ÉÒÔÔÚÓû§²à£¬ÉÏÁª²à¶Ë¿Ú¼äÀ´»ØƯÒÆ¡£ 3£© µ±¿ªÆô×Ü¿ª¹Ø£¬Î´¿ªÆôÆäËü¿ª¹Øʱ£¬MACµØÖ·ÔÚÒ»¸ö¶Ë¿Úѧϰµ½ºó£¬ÒªµÈÀÏ»¯ÒԺ󣬲ÅÄÜÔÚÁíÒ»¸ö¶Ë¿Úѧϰµ½¡£

4£© µ±¿ªÆô×Ü¿ª¹Ø£¬Î´ÅäÖÃÍø¹Ø±£»¤µØÖ·£¬Ö»¿ªÆôÉÏÁª¿ÚÓÅÏÈʱ£¬MACµØÖ·ÔÚÓû§²àѧϰµ½ºó£¬Èç¹ûÍøÂç²àÒ²ÓÐÏàͬµÄµØÖ·£¬²»ÓõÈÓû§²àµØÖ·ÀÏ»¯£¬¾Í¿ÉÒÔǨÒƵ½ÍøÂç²à¡£µ«ÊÇÍøÂç²àѧϰµ½µØÖ·ÒÔºó£¬Èç¹ûÓû§²àÓÐÏàͬµÄµØÖ·£¬ÐèÒªµÈÍøÂç²àµØÖ·ÀÏ»¯ÒԺ󣬲ÅÄÜǨÒƵ½Óû§²à¡£

5£© µ±¿ªÆô×Ü¿ª¹Ø£¬ÅäÖÃÍø¹Ø±£»¤µØÖ·ºó£¬²»ÓÿªÆôÉÏÁª¿ÚÓÅÏÈ¿ª¹Ø£¬¶ÔÓÚÅäÖõÄÍø¹ØµØÖ·£¬´¦ÀíºÍÉÏÁª¿ÚÓÅÏÈ¿ª¹Ø¿ªÆôʱһÑù£¬¶ÔÓÚûÅäÖóÉÍø¹ØµØÖ·µÄµØÖ·£¬´¦ÀíºÍÆÕͨµØÖ·Ò»Ñù¡£Èç¹û¿ªÆôÁËÉÏÁª¿ÚÓÅÏÈ¿ª¹Ø£¬ËùÓеØÖ·µÄ´¦Àí¶¼°´ÕÕÖ»¿ªÆôÁËÉÏÁª¿ÚÓÅÏÈ¿ª¹ØÒ»Ñù´¦Àí¡£

6£© Á½¿ª¹Ø¶¼Ê¹ÄÜÇé¿öÏ£¬ÐÅÈÎÉÏÁª¿Ú£¬ÈÏΪÉÏÁª¿ÚÖ®¼ä²»»á´æÔڳɻ·ÏÖÏó£¬Ö»ÒªÉÏÁª¿ÚÀ´MACÄÄųåÍ»µÄ£¬¶¼»áƯÒƹýÀ´£¬ËùÒÔÓû§¿Ú¿ÉÒÔƯÒƵ½ÉÏÁª¿Ú£¬ÉÏÁª¿ÚÖ®¼ä¿ÉÒÔƯÒÆ£»ÉÏÁª¿ÚÓÅÏÈDISÇé¿öÏ£¬ËùÓж˿ڶ¼²»¿ÉÐÅÈΣ¬¶¼¿ÉÄܳɻ·£¬ËùÒÔËùÓж˿ÚÉ϶¼²»ÔÊÐíƯÒÆ¡££¨T7°æ±¾¸Ä¶¯£©

1.44 ARP·ÀÆÛÆ­

Arp anti-spoofingÉæ¼°µ½Á½¸ö·½Ã棬һÊǶÔÓû§²à½øÐÐarp ·ÀÆÛÆ­£¬Ò»ÊǶÔÍøÂç²â½øÐÐarp·ÀÆÛÆ­¡£

ÔÚÅäÖ÷½Ã棬¿ÉÒÔ¶ÔÌض¨vlanÖ¸¶¨arp anti-spoofingΪÆäÖÐÒ»¸ö·½Ïò£¬Ò²¿ÉÒÔÁ½¸ö·½Ïò¾ùÖ¸¶¨¡£

ZXAN(config)#show ip-service arp-anti-spoofing Arp Anti-Spoofing status:Enabled. vlan direction ----------------------

666 all£¨C300V1.1T7Ö»ÄÜʵÏÖÉÏÐз½ÏòµÄ·ÀÆÛÆ­£©

Óû§²àµÄarp·ÀÆÛÆ­µÄÂß¼­ÊÇ£ºÊÕµ½Óû§²àÀ´µÄarp°üºó£¬²éÕÒmffµÄarp±íÖÐÊÇ·ñÓÐdhcpÀ´Ô´µÄ¸ÃÓû§ip¶ÔÓ¦µÄarpÌõÄ¿£¬ÓÐÔò½øÐÐmacµØÖ·Åжϣ¬ÈôÓëarp±íÖÐÒ»Ö£¬Ôò¸Ãarp°ü¼ÌÐøµÃÒÔ´¦Àí£¬Èç¹û²»Ò»Ö£¬Ôò¶ªÆú¸Ã±¨ÎÄ¡£Èç¹û²éÕÒ²»µ½dhcpÀ´Ô´µÄarpÌõÄ¿£¬Ôò

²éÕҹ̶¨Óû§À´Ô´µÄarpÌõÄ¿£¬½øÐÐÏàͬµÄÅжϴ¦Àí¡£

Óû§Îª¾²Ì¬IPµØÖ·Óû§Ê±£¬ÐèÒªµÄÅäÖÃÈçÏ£º ÅäÖõ¥tagµÄservice-port£¨Ë«tagµÄÄ¿Ç°²»Ö§³Ö£©£¬²¢ÅäÖÃÉÏÁª¿ÚºÍONUÉϵÄÏà¹ØVLAN£¬Ê¹ÒµÎñÄÜͨ¡£

¿ªÆômff¿ª¹Ø¡£ ÅäÖÃmffÍø¹Ø¡£

Óû§ÎªdhcpÓû§Ê±£¬ÐèÒªµÄÅäÖÃÈçÏ£º Ç°ÈýÏîͬÉÏ£¬ÁíÍ⻹ÐèÒªÅäÖãº

ÔÚÈ«¾ÖºÍservice-portÉÏ¿ªÆôdhcp snooping¹¦ÄÜ¡£

¿ªÆôÈ«¾ÖDHCP-OPTION82£¬¿ªÆôONU½Ó¿ÚϵÄDHCP-OPTION82¡££¨Èô²»¿ªÆô£¬Ôòshow ip-ser arpÖУ¬DHCPÓû§Ò²ÏÔʾΪ¶¯Ì¬£©

ÍøÂç²àµÄarp·ÀÆÛÆ­µÄÂß¼­ÊÇ£ºÊÕµ½ÍøÂç²àÀ´µÄarp°üºó£¬ÏÈÅжϸðüµÄÔ´ipÊÇ·ñÊÇÅäÖõÄmffµÄÍø¹Øip£¬²»ÊÇÔò¶ªÆú¡£ÊÇ£¬ÔòÅжÏmffÅäÖõÄÍø¹ØMACÀàÐÍÊÇ·ñΪ¾²Ì¬µÄ¡£µ±Îª¾²Ì¬ÅäÖÃÍø¹Ømacʱ£¬½øÐÐmacµÄÅжϣ¬Ò»ÖÂÔò¼ÌÐø´¦Àí£¬²»Ò»ÖÂÔò¶ªÆú¡£µ±Îª¶¯Ì¬ÅäÖÃÍø¹Ømacʱ£¬Ôò½ö×ö¸üÐÂmac´¦Àí£¬²»×ö¶ªÆúÅжϡ£

¿ÉÒÔʹÓÃetheekpeek·¢°ü£¬½øÐÐarp·ÀÆÛÆ­²âÊÔ£¬Ò²¿ÉÒÔʹÓÃTC´´½¨HOST·½Ê½²âÊÔ¡£ ¸Ã¹¦ÄÜÖ»¶Ô ARP±¨ÎĽøÐÐÌá°ü´¦Àí¡£

1.45 IP source-guard¹¦ÄÜÒÔ¼°¹Ì¶¨/¶¯Ì¬DHCPÓû§µÄIP°ó¶¨

IPÔ´±£»¤£¬ÔÚONU½Ó¿ÚʹÄÜÁËIP SOURCEGUARDµÄVLAN£¨service-port£©£¬Ö»ÔÊÐíDHCPÓû§ÒѾ­ÅäÖÃÁ˾²Ì¬IPµÄÓû§µÄIP±¨ÎIJÅÄÜͨ¹ý¡£

Èç¹û²»ÅäÖÃÈκξ²Ì¬IP£¬ÔòÖ»ÔÊÐíIPµØַΪȫ£°µÄ±¨ÎÄͨ¹ý¡£ ʹÄÜIP SOURCEGUARD¹¦ÄÜ£º È«¾ÖģʽÏ£º

ZXAN(config)#ip-service ip-source-guard enable

½øÈëonu½Ó¿Úģʽ£º

ZXAN(config)#interface gpon-onu_1/5/5:1

onu½Ó¿ÚģʽÏÂ:

Ê×ÏÈ´´½¨service-port

ZXAN(config-if)#service-port 1 user-vlan 100 cvlan 200 ZXAN(config-if)#ip-service ip-source-guard enable sport 1 ZXAN(config)#show ip-service ip-source-guard global ip-source-guard status :enable

ZXAN(config)#show ip-service ip-source-guard GPON-onu_1/5/5:1 Port Sport ip-source-guard status gpon-onu_1/5/5:1 1 enable

´Ëʱ£¬·ÇDHCPÓû§£¬Ö»ÄÜͨ¹ýIPµØַΪȫ£°µÄ±¨ÎÄ¡£ Ö´Ðй̶¨IPÓû§ÅäÖ㺠onu½Ó¿ÚģʽÏ£º

ZXAN(config-if)#ip-service ip-fixed-user 2.2.2.3 mac-address 0000.0000.0001 vlan 200 sport 1

ZXAN(config)#show ip-service user interface GPON-onu_1/5/5:1

Port Sport IP-addr MAC-addr Vlan Source

gpon-onu_1/5/5:1 1 2.2.2.3 0000.0000.0001 200 fixed-user Ö»ÓÐIPºÍMAC¶¼Æ¥ÅäµÄ±¨ÎIJÅÄÜͨ¹ý£¬ÆäËû¶¼¶ªÆú¡£

Ö´ÐÐdhcp snoopingÅäÖãº

ÔÚÈ«¾ÖÏÂip dhcp snooping enable ip dhcp snooping vlan 200

ip dhcp snooping trust gei_1/21/1 dhcp-option82 enable

Óû§²à¶Ë¿ÚÏÂinterface GPON-onu_1/5/5:1 ip dhcp snooping enable vport 1 dhcp-option82 enable

ʹÓÃdhcpclient´ÓÓû§²à·¢Æð1¸öÇëÇó»ñÈ¡ipµØÖ·¡£

1.46 µäÐ͹¦ÄܲâÊÔ

×éÍø£ºÁ½¸öÉÏÁª¿Ú£¬Á½¸öÓû§¿Ú£¬ÆäÖÐÒ»¸öÉÏÁª¿ÚºÍÒ»¸öÓû§¿ÚÄ£ÄâÕý³£µÄ¶Ô·¢µ¥²¥Á÷Á¿£¬ÁíÒ»¸öÉÏÁª¿ÚÄ£ÄâÉÏÁª¿ÚÉϵķÇÕý³£Á÷Á¿£¬ÁíÒ»¸öÓû§¿Ú£¬Ä£ÄâÓû§¿ÚµÄ·ÇÕý³£Á÷Á¿¡£

²½Ö裺

²»¿ªÆô·ÀƯÒƹ¦ÄÜ ÅäÖ÷ÀƯ¹¦ÄÜÈ¡Ïû

Óû§²àÏÈ·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬ÍøÂç²àÈ»ºó·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1¿ÉÄÜÔÚÍøÂç²à»òÕßÓû§²àѧϰµ½£¬ÒµÎñ²ÉÓú鷶·½Ê½Í¨¡£

ÍøÂç²àÏÈ·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬Óû§²àÈ»ºó·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1¿ÉÄÜÔÚÍøÂç²à»òÕßÓû§²àѧϰµ½£¬ÒµÎñ²ÉÓú鷶·½Ê½Í¨¡£

ÉÏÁª¿ÚÓÅÏÈģʽ

ÅäÖ÷ÀƯ¹¦ÄÜʹÄÜÒÔ¼°ÉÏÁª¿Ú±£»¤·½Ê½

Óû§²àÏÈ·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬ÍøÂç²àÈ»ºó·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1Ö»ÊÇÔÚÍøÂç²àѧϰµ½£¬ÏÂÐÐÒµÎñͨ£¬¶øÓû§²àûÓÐѧϰµ½mac1£¬²¢ÇÒÉÏÐÐÒµÎñ²»Í¨¡£

ÍøÂç²àÏÈ·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬Óû§²àÈ»ºó·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1Ö»ÊÇÔÚÍøÂç²àѧϰµ½£¬ÏÂÐÐÒµÎñͨ£¬¶øÓû§²àûÓÐѧϰµ½mac1£¬²¢ÇÒÉÏÐÐÒµÎñ²»Í¨¡£

ÉÏÁª¿ÚÍø¹ØMACµØÖ·±£»¤Ä£Ê½

ÅäÖ÷ÀƯ¹¦ÄÜʹÄÜÒÔ¼°ÉÏÁª¿Ú±£»¤È¡Ïû·½Ê½ ÅäÖÃÉÏÁª¿Ú±£»¤µÄÍø¹Ømac

Óû§²àÏÈ·¢ËÍÔ´mac1£¨Íø¹Ømac£©µÄ±¨ÎÄ£¬ÍøÂç²àÈ»ºó·¢ËÍÔ´mac1£¨Íø¹Ømac£©µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1Ö»ÊÇÔÚÍøÂç²àѧϰµ½£¬ÏÂÐÐÒµÎñͨ£¬¶øÓû§²àûÓÐѧϰµ½mac1£¬²¢ÇÒÉÏÐÐÒµÎñ²»Í¨¡£

ÍøÂç²àÏÈ·¢ËÍÔ´mac1£¨Íø¹Ømac£©µÄ±¨ÎÄ£¬Óû§²àÈ»ºó·¢ËÍÔ´mac1£¨Íø¹Ømac£©µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1Ö»ÊÇÔÚÍøÂç²àѧϰµ½£¬ÏÂÐÐÒµÎñͨ£¬¶øÓû§²àûÓÐѧϰµ½mac1£¬²¢ÇÒÉÏÐÐÒµÎñ²»Í¨¡£

Óû§²àÏÈ·¢ËÍÔ´mac2£¨·ÇÍø¹Ømac£©µÄ±¨ÎÄ£¬ÍøÂç²àÈ»ºó·¢ËÍÔ´mac2£¨·ÇÍø¹Ømac£©µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac2¿ÉÄÜÔÚÍøÂç²à»òÕßÓû§²àѧϰµ½£¬ÒµÎñ²ÉÓú鷶·½Ê½Í¨¡£

ÍøÂç²àÏÈ·¢ËÍÔ´mac2£¨·ÇÍø¹Ømac£©µÄ±¨ÎÄ£¬È»ºóÓû§²à·¢ËÍÔ´mac2£¨·ÇÍø¹Ømac£©µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac2¿ÉÄÜÔÚÍøÂç²à»òÕßÓû§²àѧϰµ½£¬ÒµÎñ²ÉÓú鷶·½Ê½Í¨¡£

×¢£ºÍø¹ØMACµØÖ·±£»¤Êý32Ìõ¡£

1.22 ¹âÄ£¿é²ÎÊý¼ì²â¹¦ÄÜ

±ØÐëÓÃÖ§³Ö¹â¹¦Âʼì²éµÄ¹âÄ£¿é£¬²ÅÄܲâÊÔPON¿ÚµÄ·¢¹â¹¦ÂÊ¡£Èç¹ûÒª²âÊÔONU²àµÄ½ÓÊÕ¹¦ÂÊ£¬ONUÉÏÒ²±ØÐëʹÓÃÖ§³Ö¹â¹¦Âʼì²éµÄ¹âÄ£¿é¡£¼ì²âÊý¾Ý£¬¿ÉÒÔͨ¹ýÍø¹ÜÉϵÄÐÔÄÜͳ¼Æ£¬»òÕßCLIÃüÁî²éѯ¡£

OLT¹âÄ£¿éÕï¶Ï£º

ZXAN(config)#sho pon transceiver info gpon-olt_1/7/4

RxPower : N/A (dbm) TxPower : 4.025 (dbm) Bias-Current : 13.114 (mA) Laser-Rate : 2488 (MBd) Supply-Vol : 3.181 (V) Wavelength : N/A (nm) Temperature : 47.600 (C) Vender-PN : SOGQ4321-PSGA

Vender-Name : SUPERXON MaxDistance: 20 (km) ZXAN(config)#sho pon power olt-rx gpon-onu_1/7/4:1 Rx power: -11.693(dbm) ONU¹âÄ£¿éÕï¶Ï£º

ZXAN(config)#sho gpon remote-onu interface pon gpon-onu_1/7/4:1

Interface: pon_0/1 GEM-blocklen: 48 (bytes) Sf-threshold: 5 Sd-threshold: 9

Alarm: enable AlarmDisableInterval: 0 TotalTcontNum: 8

PiggybackDbaRptMode: mode0 only WholeOnuDbaRptMode: support RxOpticalLevel: -11.712(dBm) LowerRxOpticalThreshold: ont internal policy UpperRxOpticalThreshold: ont internal policy