ͼ2-1 MFFʵÏÖÔÀí
Switch AºÍSwitch B×÷ΪÒÔÌ«Íø½ÓÈë½Úµã£¨Ethernet Access Nodes£¬EAN£©£¬ÌṩÁË¿Í»§¶ËÖ÷»úÓë»ã¾Û½Úµã£¨Switch C£©Ö®¼äµÄÁ¬½Ó¡£ÔÚÒÔÌ«Íø½ÓÈë½ÚµãÉÏÅäÖÃMFF¹¦ÄÜ£¬¿ÉÒÔʹ¿Í»§¶ËµÄÊý¾Ý±¨ÎĽ»»¥È«²¿Í¨¹ýÍø¹Øת·¢£¬ÊµÏÖÁË¿Í»§¶ËÖ®¼äµÄÈý²ã»¥Í¨£¬ÓÖ±£Ö¤Á˶þ²ãÊý¾ÝµÄ¸ôÀë¡£
Host A¿´µ½µÄHost BµÄMACÒ²ÊÇgatewayµÄ£¬ÕâÑù±£Ö¤¼´Ê¹Host AºÍHost BÊÇͬһÍø¶Î£¬Í¬Ò»Vlan£¬ËûÃǵĽ»»»Ò²±ØÐë¾¹ýgateway£¬´Ó¶øʵÏÖ¶þ²ã¸ôÀë¡£
1£© ÅäÖÃ
Óû§Îª¾²Ì¬IPµØÖ·Óû§Ê±£¬ÐèÒªµÄÅäÖÃÈçÏ£º ÅäÖõ¥tagµÄservice-port£¨Ë«tagµÄÄ¿Ç°²»Ö§³Ö£©£¬²¢ÅäÖÃÉÏÁª¿ÚºÍONUÉϵÄÏà¹ØVLAN£¬Ê¹ÒµÎñÄÜͨ¡£
¿ªÆômff¿ª¹Ø¡£ ÅäÖÃmffÍø¹Ø¡£
Óû§ÎªdhcpÓû§Ê±£¬ÐèÒªµÄÅäÖÃÈçÏ£º Ç°ÈýÏîͬÉÏ£¬ÁíÍ⻹ÐèÒªÅäÖãº
ÔÚÈ«¾ÖºÍservice-portÉÏ¿ªÆôdhcp snooping¹¦ÄÜ¡£
×¢Ò⣺²»ÄÜÅäÖöÔÓ¦VLANµÄÈý²ã½Ó¿Ú¡£²»È»¸Ã¹¦ÄÜÎÞЧÁË¡£ 2£© ÃüÁî
ZXAN(config)#Ip-service mac-forced-forwarding {enable | disable} ÅäÖÃmacµØÖ·Ç¿ÖÆת·¢¹¦ÄÜ¿ª¹Ø״̬¡£
ZXAN(config)# [no] ip-service mac-forced-forwarding vlan
ÅäÖÃÆôÓÃij¸övlanϵÄmac-forced-forwarding Íø¹ØIP\\MAC¡£ Ŀǰϵͳ֧³ÖÅäÖÃ×î¶à°Ë¸övlanµÄMFFÍø¹ØÊý¾Ý¡£
ÔÚZXAN# Show ip-service arp [ dhcp | ipoa-dynamic | ipoa-static | dynamic |fixed | ip-addr
ÏÔʾmac-forced-forwarding ¹¦ÄÜʹÓõÄarpÓ³Éä±íÐÅÏ¢¡£ ZXAN# show ip-service mac-forced-forwarding ÏÔʾMAC forced forwarding È«¾Ö¿ª¹Ø״̬¡£
ZXAN#show ip-service mac-forced-forwarding gateway ÏÔʾMAC forced forwarding ¸÷vlanÏÂÍø¹ØÐÅÏ¢¡£
1.43 MAC·ÀƯ¹¦ÄÜ
¹¦ÄܽéÉÜ
MACµØַƯÒƾ³£³öÏÖÔÚ´æÔÚMACµØÖ·ÆÛÆ»òÕßϵͳ£¨ÌرðÊÇÓû§²à£©³É»·µÈÇé¿öÏ£¬·ÀÖ¹MAµØÖ·µÄƯÒÆ£¬¿ÉÒÔÒ»¶¨³Ì¶ÈÉϱ£Ö¤ÏµÍ³µÄÎȶ¨ÔËÐС£
ϵͳʵÏÖ
ϵͳʵÏÖÊôÓÚÓ²¼þ·ÀƯ£¬²»Äܲ鿴·ÀƯ¼Ç¼¡£ ÅäÖÃ
C300V1.1ϵͳµÄMACµØÖ··ÀƯÒÆÉæ¼°µ½µÄÃüÁîÓУº
1¡¢ security mac-anti-spoofing enable/ disable¡ª¡ªMACµØÖ··ÀƯÒÆ×Ü¿ª¹Ø
2¡¢ security mac-anti-spoofing uplink-protect enable/ disable¡ª¡ªÉÏÁª¿ÚÓÅÏÈ¿ª¹Ø 3¡¢ security uplink-protected-mac¡ª¡ªÍø¹Ø±£»¤µØÖ· ˵Ã÷
1£© ËùÓзÀƯÒƹ¦Äܶ¼ÒªÔÚMACµØÖ··ÀƯÒÆ×Ü¿ª¹Ø¿ªÆôºó²ÅÄÜÉúЧ¡£
2£© µ±Î´¿ªÆô×Ü¿ª¹Øʱ£¬MACµØÖ·¿ÉÒÔÔÚÓû§²à£¬ÉÏÁª²à¶Ë¿Ú¼äÀ´»ØƯÒÆ¡£ 3£© µ±¿ªÆô×Ü¿ª¹Ø£¬Î´¿ªÆôÆäËü¿ª¹Øʱ£¬MACµØÖ·ÔÚÒ»¸ö¶Ë¿Úѧϰµ½ºó£¬ÒªµÈÀÏ»¯ÒԺ󣬲ÅÄÜÔÚÁíÒ»¸ö¶Ë¿Úѧϰµ½¡£
4£© µ±¿ªÆô×Ü¿ª¹Ø£¬Î´ÅäÖÃÍø¹Ø±£»¤µØÖ·£¬Ö»¿ªÆôÉÏÁª¿ÚÓÅÏÈʱ£¬MACµØÖ·ÔÚÓû§²àѧϰµ½ºó£¬Èç¹ûÍøÂç²àÒ²ÓÐÏàͬµÄµØÖ·£¬²»ÓõÈÓû§²àµØÖ·ÀÏ»¯£¬¾Í¿ÉÒÔǨÒƵ½ÍøÂç²à¡£µ«ÊÇÍøÂç²àѧϰµ½µØÖ·ÒÔºó£¬Èç¹ûÓû§²àÓÐÏàͬµÄµØÖ·£¬ÐèÒªµÈÍøÂç²àµØÖ·ÀÏ»¯ÒԺ󣬲ÅÄÜǨÒƵ½Óû§²à¡£
5£© µ±¿ªÆô×Ü¿ª¹Ø£¬ÅäÖÃÍø¹Ø±£»¤µØÖ·ºó£¬²»ÓÿªÆôÉÏÁª¿ÚÓÅÏÈ¿ª¹Ø£¬¶ÔÓÚÅäÖõÄÍø¹ØµØÖ·£¬´¦ÀíºÍÉÏÁª¿ÚÓÅÏÈ¿ª¹Ø¿ªÆôʱһÑù£¬¶ÔÓÚûÅäÖóÉÍø¹ØµØÖ·µÄµØÖ·£¬´¦ÀíºÍÆÕͨµØÖ·Ò»Ñù¡£Èç¹û¿ªÆôÁËÉÏÁª¿ÚÓÅÏÈ¿ª¹Ø£¬ËùÓеØÖ·µÄ´¦Àí¶¼°´ÕÕÖ»¿ªÆôÁËÉÏÁª¿ÚÓÅÏÈ¿ª¹ØÒ»Ñù´¦Àí¡£
6£© Á½¿ª¹Ø¶¼Ê¹ÄÜÇé¿öÏ£¬ÐÅÈÎÉÏÁª¿Ú£¬ÈÏΪÉÏÁª¿ÚÖ®¼ä²»»á´æÔڳɻ·ÏÖÏó£¬Ö»ÒªÉÏÁª¿ÚÀ´MACÄÄųåÍ»µÄ£¬¶¼»áƯÒƹýÀ´£¬ËùÒÔÓû§¿Ú¿ÉÒÔƯÒƵ½ÉÏÁª¿Ú£¬ÉÏÁª¿ÚÖ®¼ä¿ÉÒÔƯÒÆ£»ÉÏÁª¿ÚÓÅÏÈDISÇé¿öÏ£¬ËùÓж˿ڶ¼²»¿ÉÐÅÈΣ¬¶¼¿ÉÄܳɻ·£¬ËùÒÔËùÓж˿ÚÉ϶¼²»ÔÊÐíƯÒÆ¡££¨T7°æ±¾¸Ä¶¯£©
1.44 ARP·ÀÆÛÆ
Arp anti-spoofingÉæ¼°µ½Á½¸ö·½Ã棬һÊǶÔÓû§²à½øÐÐarp ·ÀÆÛÆ£¬Ò»ÊǶÔÍøÂç²â½øÐÐarp·ÀÆÛÆ¡£
ÔÚÅäÖ÷½Ã棬¿ÉÒÔ¶ÔÌض¨vlanÖ¸¶¨arp anti-spoofingΪÆäÖÐÒ»¸ö·½Ïò£¬Ò²¿ÉÒÔÁ½¸ö·½Ïò¾ùÖ¸¶¨¡£
ZXAN(config)#show ip-service arp-anti-spoofing Arp Anti-Spoofing status:Enabled. vlan direction ----------------------
666 all£¨C300V1.1T7Ö»ÄÜʵÏÖÉÏÐз½ÏòµÄ·ÀÆÛÆ£©
Óû§²àµÄarp·ÀÆÛƵÄÂß¼ÊÇ£ºÊÕµ½Óû§²àÀ´µÄarp°üºó£¬²éÕÒmffµÄarp±íÖÐÊÇ·ñÓÐdhcpÀ´Ô´µÄ¸ÃÓû§ip¶ÔÓ¦µÄarpÌõÄ¿£¬ÓÐÔò½øÐÐmacµØÖ·Åжϣ¬ÈôÓëarp±íÖÐÒ»Ö£¬Ôò¸Ãarp°ü¼ÌÐøµÃÒÔ´¦Àí£¬Èç¹û²»Ò»Ö£¬Ôò¶ªÆú¸Ã±¨ÎÄ¡£Èç¹û²éÕÒ²»µ½dhcpÀ´Ô´µÄarpÌõÄ¿£¬Ôò
²éÕҹ̶¨Óû§À´Ô´µÄarpÌõÄ¿£¬½øÐÐÏàͬµÄÅжϴ¦Àí¡£
Óû§Îª¾²Ì¬IPµØÖ·Óû§Ê±£¬ÐèÒªµÄÅäÖÃÈçÏ£º ÅäÖõ¥tagµÄservice-port£¨Ë«tagµÄÄ¿Ç°²»Ö§³Ö£©£¬²¢ÅäÖÃÉÏÁª¿ÚºÍONUÉϵÄÏà¹ØVLAN£¬Ê¹ÒµÎñÄÜͨ¡£
¿ªÆômff¿ª¹Ø¡£ ÅäÖÃmffÍø¹Ø¡£
Óû§ÎªdhcpÓû§Ê±£¬ÐèÒªµÄÅäÖÃÈçÏ£º Ç°ÈýÏîͬÉÏ£¬ÁíÍ⻹ÐèÒªÅäÖãº
ÔÚÈ«¾ÖºÍservice-portÉÏ¿ªÆôdhcp snooping¹¦ÄÜ¡£
¿ªÆôÈ«¾ÖDHCP-OPTION82£¬¿ªÆôONU½Ó¿ÚϵÄDHCP-OPTION82¡££¨Èô²»¿ªÆô£¬Ôòshow ip-ser arpÖУ¬DHCPÓû§Ò²ÏÔʾΪ¶¯Ì¬£©
ÍøÂç²àµÄarp·ÀÆÛƵÄÂß¼ÊÇ£ºÊÕµ½ÍøÂç²àÀ´µÄarp°üºó£¬ÏÈÅжϸðüµÄÔ´ipÊÇ·ñÊÇÅäÖõÄmffµÄÍø¹Øip£¬²»ÊÇÔò¶ªÆú¡£ÊÇ£¬ÔòÅжÏmffÅäÖõÄÍø¹ØMACÀàÐÍÊÇ·ñΪ¾²Ì¬µÄ¡£µ±Îª¾²Ì¬ÅäÖÃÍø¹Ømacʱ£¬½øÐÐmacµÄÅжϣ¬Ò»ÖÂÔò¼ÌÐø´¦Àí£¬²»Ò»ÖÂÔò¶ªÆú¡£µ±Îª¶¯Ì¬ÅäÖÃÍø¹Ømacʱ£¬Ôò½ö×ö¸üÐÂmac´¦Àí£¬²»×ö¶ªÆúÅжϡ£
¿ÉÒÔʹÓÃetheekpeek·¢°ü£¬½øÐÐarp·ÀÆÛƲâÊÔ£¬Ò²¿ÉÒÔʹÓÃTC´´½¨HOST·½Ê½²âÊÔ¡£ ¸Ã¹¦ÄÜÖ»¶Ô ARP±¨ÎĽøÐÐÌá°ü´¦Àí¡£
1.45 IP source-guard¹¦ÄÜÒÔ¼°¹Ì¶¨/¶¯Ì¬DHCPÓû§µÄIP°ó¶¨
IPÔ´±£»¤£¬ÔÚONU½Ó¿ÚʹÄÜÁËIP SOURCEGUARDµÄVLAN£¨service-port£©£¬Ö»ÔÊÐíDHCPÓû§ÒѾÅäÖÃÁ˾²Ì¬IPµÄÓû§µÄIP±¨ÎIJÅÄÜͨ¹ý¡£
Èç¹û²»ÅäÖÃÈκξ²Ì¬IP£¬ÔòÖ»ÔÊÐíIPµØַΪȫ£°µÄ±¨ÎÄͨ¹ý¡£ ʹÄÜIP SOURCEGUARD¹¦ÄÜ£º È«¾ÖģʽÏ£º
ZXAN(config)#ip-service ip-source-guard enable
½øÈëonu½Ó¿Úģʽ£º
ZXAN(config)#interface gpon-onu_1/5/5:1
onu½Ó¿ÚģʽÏÂ:
Ê×ÏÈ´´½¨service-port
ZXAN(config-if)#service-port 1 user-vlan 100 cvlan 200 ZXAN(config-if)#ip-service ip-source-guard enable sport 1 ZXAN(config)#show ip-service ip-source-guard global ip-source-guard status :enable
ZXAN(config)#show ip-service ip-source-guard GPON-onu_1/5/5:1 Port Sport ip-source-guard status gpon-onu_1/5/5:1 1 enable
´Ëʱ£¬·ÇDHCPÓû§£¬Ö»ÄÜͨ¹ýIPµØַΪȫ£°µÄ±¨ÎÄ¡£ Ö´Ðй̶¨IPÓû§ÅäÖ㺠onu½Ó¿ÚģʽÏ£º
ZXAN(config-if)#ip-service ip-fixed-user 2.2.2.3 mac-address 0000.0000.0001 vlan 200 sport 1
ZXAN(config)#show ip-service user interface GPON-onu_1/5/5:1
Port Sport IP-addr MAC-addr Vlan Source
gpon-onu_1/5/5:1 1 2.2.2.3 0000.0000.0001 200 fixed-user Ö»ÓÐIPºÍMAC¶¼Æ¥ÅäµÄ±¨ÎIJÅÄÜͨ¹ý£¬ÆäËû¶¼¶ªÆú¡£
Ö´ÐÐdhcp snoopingÅäÖãº
ÔÚÈ«¾ÖÏÂip dhcp snooping enable ip dhcp snooping vlan 200
ip dhcp snooping trust gei_1/21/1 dhcp-option82 enable
Óû§²à¶Ë¿ÚÏÂinterface GPON-onu_1/5/5:1 ip dhcp snooping enable vport 1 dhcp-option82 enable
ʹÓÃdhcpclient´ÓÓû§²à·¢Æð1¸öÇëÇó»ñÈ¡ipµØÖ·¡£
1.46 µäÐ͹¦ÄܲâÊÔ
×éÍø£ºÁ½¸öÉÏÁª¿Ú£¬Á½¸öÓû§¿Ú£¬ÆäÖÐÒ»¸öÉÏÁª¿ÚºÍÒ»¸öÓû§¿ÚÄ£ÄâÕý³£µÄ¶Ô·¢µ¥²¥Á÷Á¿£¬ÁíÒ»¸öÉÏÁª¿ÚÄ£ÄâÉÏÁª¿ÚÉϵķÇÕý³£Á÷Á¿£¬ÁíÒ»¸öÓû§¿Ú£¬Ä£ÄâÓû§¿ÚµÄ·ÇÕý³£Á÷Á¿¡£
²½Ö裺
²»¿ªÆô·ÀƯÒƹ¦ÄÜ ÅäÖ÷ÀƯ¹¦ÄÜÈ¡Ïû
Óû§²àÏÈ·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬ÍøÂç²àÈ»ºó·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1¿ÉÄÜÔÚÍøÂç²à»òÕßÓû§²àѧϰµ½£¬ÒµÎñ²ÉÓú鷶·½Ê½Í¨¡£
ÍøÂç²àÏÈ·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬Óû§²àÈ»ºó·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1¿ÉÄÜÔÚÍøÂç²à»òÕßÓû§²àѧϰµ½£¬ÒµÎñ²ÉÓú鷶·½Ê½Í¨¡£
ÉÏÁª¿ÚÓÅÏÈģʽ
ÅäÖ÷ÀƯ¹¦ÄÜʹÄÜÒÔ¼°ÉÏÁª¿Ú±£»¤·½Ê½
Óû§²àÏÈ·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬ÍøÂç²àÈ»ºó·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1Ö»ÊÇÔÚÍøÂç²àѧϰµ½£¬ÏÂÐÐÒµÎñͨ£¬¶øÓû§²àûÓÐѧϰµ½mac1£¬²¢ÇÒÉÏÐÐÒµÎñ²»Í¨¡£
ÍøÂç²àÏÈ·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬Óû§²àÈ»ºó·¢ËÍÔ´mac1µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1Ö»ÊÇÔÚÍøÂç²àѧϰµ½£¬ÏÂÐÐÒµÎñͨ£¬¶øÓû§²àûÓÐѧϰµ½mac1£¬²¢ÇÒÉÏÐÐÒµÎñ²»Í¨¡£
ÉÏÁª¿ÚÍø¹ØMACµØÖ·±£»¤Ä£Ê½
ÅäÖ÷ÀƯ¹¦ÄÜʹÄÜÒÔ¼°ÉÏÁª¿Ú±£»¤È¡Ïû·½Ê½ ÅäÖÃÉÏÁª¿Ú±£»¤µÄÍø¹Ømac
Óû§²àÏÈ·¢ËÍÔ´mac1£¨Íø¹Ømac£©µÄ±¨ÎÄ£¬ÍøÂç²àÈ»ºó·¢ËÍÔ´mac1£¨Íø¹Ømac£©µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1Ö»ÊÇÔÚÍøÂç²àѧϰµ½£¬ÏÂÐÐÒµÎñͨ£¬¶øÓû§²àûÓÐѧϰµ½mac1£¬²¢ÇÒÉÏÐÐÒµÎñ²»Í¨¡£
ÍøÂç²àÏÈ·¢ËÍÔ´mac1£¨Íø¹Ømac£©µÄ±¨ÎÄ£¬Óû§²àÈ»ºó·¢ËÍÔ´mac1£¨Íø¹Ømac£©µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac1Ö»ÊÇÔÚÍøÂç²àѧϰµ½£¬ÏÂÐÐÒµÎñͨ£¬¶øÓû§²àûÓÐѧϰµ½mac1£¬²¢ÇÒÉÏÐÐÒµÎñ²»Í¨¡£
Óû§²àÏÈ·¢ËÍÔ´mac2£¨·ÇÍø¹Ømac£©µÄ±¨ÎÄ£¬ÍøÂç²àÈ»ºó·¢ËÍÔ´mac2£¨·ÇÍø¹Ømac£©µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac2¿ÉÄÜÔÚÍøÂç²à»òÕßÓû§²àѧϰµ½£¬ÒµÎñ²ÉÓú鷶·½Ê½Í¨¡£
ÍøÂç²àÏÈ·¢ËÍÔ´mac2£¨·ÇÍø¹Ømac£©µÄ±¨ÎÄ£¬È»ºóÓû§²à·¢ËÍÔ´mac2£¨·ÇÍø¹Ømac£©µÄ±¨ÎÄ£¬·¢ÏÖÔ´mac2¿ÉÄÜÔÚÍøÂç²à»òÕßÓû§²àѧϰµ½£¬ÒµÎñ²ÉÓú鷶·½Ê½Í¨¡£
×¢£ºÍø¹ØMACµØÖ·±£»¤Êý32Ìõ¡£
1.22 ¹âÄ£¿é²ÎÊý¼ì²â¹¦ÄÜ
±ØÐëÓÃÖ§³Ö¹â¹¦Âʼì²éµÄ¹âÄ£¿é£¬²ÅÄܲâÊÔPON¿ÚµÄ·¢¹â¹¦ÂÊ¡£Èç¹ûÒª²âÊÔONU²àµÄ½ÓÊÕ¹¦ÂÊ£¬ONUÉÏÒ²±ØÐëʹÓÃÖ§³Ö¹â¹¦Âʼì²éµÄ¹âÄ£¿é¡£¼ì²âÊý¾Ý£¬¿ÉÒÔͨ¹ýÍø¹ÜÉϵÄÐÔÄÜͳ¼Æ£¬»òÕßCLIÃüÁî²éѯ¡£
OLT¹âÄ£¿éÕï¶Ï£º
ZXAN(config)#sho pon transceiver info gpon-olt_1/7/4
RxPower : N/A (dbm) TxPower : 4.025 (dbm) Bias-Current : 13.114 (mA) Laser-Rate : 2488 (MBd) Supply-Vol : 3.181 (V) Wavelength : N/A (nm) Temperature : 47.600 (C) Vender-PN : SOGQ4321-PSGA
Vender-Name : SUPERXON MaxDistance: 20 (km) ZXAN(config)#sho pon power olt-rx gpon-onu_1/7/4:1 Rx power: -11.693(dbm) ONU¹âÄ£¿éÕï¶Ï£º
ZXAN(config)#sho gpon remote-onu interface pon gpon-onu_1/7/4:1
Interface: pon_0/1 GEM-blocklen: 48 (bytes) Sf-threshold: 5 Sd-threshold: 9
Alarm: enable AlarmDisableInterval: 0 TotalTcontNum: 8
PiggybackDbaRptMode: mode0 only WholeOnuDbaRptMode: support RxOpticalLevel: -11.712(dBm) LowerRxOpticalThreshold: ont internal policy UpperRxOpticalThreshold: ont internal policy