1、00 by kellythwImage text-base: 0x40101040, data-base: 0x42DD04B0检查结果:正常 不正常二、检查设备持续运行时间C-A-02cisco设备持续运行时间一般情况下网络设备在网络上线后不会中断。如果设备uptime时间比较短,一定在利用show version命令查看设备最近一次重启动的时间和原因,便于分析各种潜在风险。(由于现实内容过多,这里只截取部分)ksy_c6509_1 uptime is 1 year, 22 weeks, 4 days, 17 hours, 2 minutesTime since ksy_c6509_1 sw
2、itched to active is 1 year, 22 weeks, 4 days, 17 hours, 1 minuteSystem returned to ROM by reload at 08:57:57 PST Tue Feb 5 2008 (SP by reload)System restarted at 12:19:06 UTC Wed Oct 15 2008System image sup-bootdisk:/s72033-ipservicesk9_wan-mz.122-18.SXF15.bin三、设备CPU利用率情况检查C-A-03cisco设备CPU利用率情况检查 CI
3、SCO#show processes cpu CISCO#show processes cpu historyCPU利用率平均值50%;最大值2M ,Free memory 2*largest(b), i/o free memory 2Mshow memory显示了存储器的一般信息,它表明系统可用的内存。同时它还显示内存中有没有碎片,内存碎片表明内存被划分为了许多不连续的块。它将导致内存的利用率降低,严重时可能产生内存错误从而也严重影响路由器的性能。 如下例,此时我们有足够多的可用内存(317.2兆),但是其中最大的块为226.5兆。说明连续内存中还有足够大的可用块。路由器中存在一定数量的内存
4、碎片是正常的。虽然并没有一个很严格的界限来划分内存碎片的可接受程度,但是可用块的大小至少应该不小于可用内存的一半。否则,有可能导致严重的内存分配问题。这些问题有时表现为一个或多个接口间歇性的丢失报文,此例中可用块226.5大于可用内存312兆字节的一半156兆,内存处于正常状态。ksy_c6509_1#show memory summary Head Total(b) Used(b) Free(b) Lowest(b) Largest(b)Processor 44B0B830 391038928 73832336 317206592 305248408 226509608 I/O 800000
5、0 67108864 10418792 56690072 45613312 56614072五、设备系统模块运行状况检查C-A-05cisco设备模块运行状况检查 CISCO#show module检查期待结果:所有模块运行OK此命令还可以看到设备各个模块的SN号及各个设备模块的型号。ksy_c6509_1#show module Mod Ports Card Type Model Serial No.- - - - - 1 48 CEF720 48 port 10/100/1000mb Ethernet WS-X6748-GE-TX SAL1213KCUP 2 24 CEF720 24 po
6、rt 1000mb SFP WS-X6724-SFP SLA11509Y03 3 6 Firewall Module WS-SVC-FWM-1 SAD121703WP 5 2 Supervisor Engine 720 (Active) WS-SUP720-3B JAF1201AHHRMod MAC addresses Hw Fw Sw Status- - - - - - 1 001e.4a9f.e320 to 001e.4a9f.e34f 2.7 12.2(14r)S5 12.2(18)SXF1 Ok 2 001d.a27d.7eb8 to 001d.a27d.7ecf 3.1 12.2(1
7、8r)S1 12.2(18)SXF1 Ok 3 001f.9e53.4076 to 001f.9e53.407d 4.2 7.2(1) 4.0(2) Ok 5 001b.d50d.aa34 to 001b.d50d.aa37 5.6 8.5(2) 12.2(18)SXF1 OkMod Sub-Module Model Serial Hw Status - - - - - - 1 Centralized Forwarding Card WS-F6700-CFC SAL1213K3XH 4.0 Ok 2 Centralized Forwarding Card WS-F6700-CFC SAL114
8、55X9M 4.0 Ok 5 Policy Feature Card 3 WS-F6K-PFC3B JAF1202AKTB 2.3 Ok 5 MSFC3 Daughterboard WS-SUP720 JAF1202ACCD 3.1 Ok六、设备电源及风扇检查C-A-06cisco设备系统电源及风扇检查 CISCO#show environment status Cisco#show power Cisco# show power status fan-tray Cisco#show environment all电源及风扇运行正常备注:对于思科的交换机和路由器命令可能会不大相同,此外命令sh
9、ow power还能看到电源的冗余状态(对于有两个或两个以上电源的设备),电源冗余状态有两种模式: redundant(冗余)和combined(组合)。根据用户实际网络环境和设备负载模块的数量决定电源模式。ksy_c6509_2#show environment statusfan-tray 1: fan-tray 1 type: WS-C6509-E-FAN fan-tray 1 mode: Restricted-power fan-tray 1 fan-fail: OKpower-supply 1: power-supply 1 fan-fail: power-supply 1 powe
10、r-input: AC high power-supply 1 power-output-mode: high power-supply 1 power-output-fail:七、设备运行温度检查C-A-07cisco设备运行检查 CISCO#show environment status 设备内部各部分工作温度小于45摄氏度ksy_c6509_2#show environment temperature all VTT 1 outlet temperature: 28C VTT 2 outlet temperature: 30C VTT 3 outlet temperature: 26C八
11、、设备系统LOG日志检查C-A-08cisco设备系统LOG日志检查 CISCO#show logging 如果有SYSLOG日志服务器可以更好的分析日志的时间及错误级别。ksy_c6509_2# show loggingLog Buffer (8192 bytes):NDBY-6-STATECHANGE: Vlan140 Group 140 state Active - Init2w6d: %STANDBY-6-STATECHANGE: Vlan150 Group 150 state Active - Vlan251 Group 210 state Active - Vlan100 Grou
12、p 100 state Standby - Active有无异常日志:有 没有九、设备冗余协议检查C-B-01HSRP、VRRP、GLBP热备协议检查CISCO#show standby brief Cisco#show standby all Cisco# show standby (以HSRP协议为例,其他协议原理基本上差不多)主备用状态正常ksy_c6509_2#show standby brief P indicates configured to preempt. |Interface Grp Prio P State Active addr Standby addr Group a
13、ddr Vl1 1 100 P Standby 192.168.200.252 local 192.168.200.254Vl2 2 100 P Standby 192.168.160.252 local 192.168.160.254Vl3 3 100 P Standby 192.168.20.252 local 192.168.20.254ksy_c6509_2#show standby Vlan1 - Group 1 Local state is Standby, priority 100, may preempt Hellotime 3 sec, holdtime 10 sec Nex
14、t hello sent in 1.695 Virtual IP address is 192.168.200.254 configured Active router is 192.168.200.252, priority 120 expires in 8.104 Standby router is local 63 state changes, last state change 1w3d IP redundancy name is hsrp-Vl1-1 (default)一十、VLAN状态检查C-B-02VLAN状态检查CISCO#show vlan Vlan名称、标示符合设计要求,v
15、lan里所含端口符合设计ksy_c6509_2#show vlanVLAN Name Status Ports- - - -1 default active Gi1/7, Gi1/8, Gi1/34, Gi1/42, Gi1/46, Gi2/8 Gi2/9, Gi2/10, Gi2/11, Gi2/12, Gi2/13 Gi2/14, Gi2/15, Gi2/16, Gi2/17, Gi2/18 Gi2/19, Gi2/20, Gi2/21, Gi2/222 VLAN0002 active Gi1/1, Gi1/2, Gi1/19, Gi1/20, Gi1/23 Gi1/24, Gi1/25,
16、 Gi1/26, Gi1/27, Gi1/28 Gi1/403 VLAN0003 active Gi1/3, Gi1/44 VLAN0004 active Gi1/5, Gi1/6一十一、EtherChannel检查C-B-03EtherChannel检查CISCO#show etherchannel port-channel 显示正确的etherchannel数量及每个etherchannel 包含应有的端口 show etherchannel port-channel 显示本交换机中含有的portchannl的情况,具体查看每个portchannel的状态使用show int port-c
17、hannel nksy_c6509_2#show etherchannel port-channel Channel-group listing: -Group: 1 - Port-channels in the group: -Port-channel: Po1Ports in the Port-channel:Index Load Port EC state No of bits-+-+-+-+- 1 55 Gi5/1 On 4 0 AA Gi5/2 On 4一十二、trunk检查C-B-04trunk检查CISCO#show interface trunk trunk正常命令显示trun
18、k信息,其中port是指参和trunk的端口,应和设计相符,mode应为on模式,status 状态为trunking, 同时对于每个trunk端口,正在trunking的vlan应和设计相符ksy_c6509_2#show interfaces trunk Port Mode Encapsulation Status Native vlanGi2/1 on 802.1q trunking 1Gi2/2 on 802.1q trunking 1Gi2/3 on 802.1q trunking 1Gi2/4 on 802.1q trunking 1Gi2/5 on 802.1q trunking
19、 1Gi2/6 on 802.1q trunking 1Gi2/7 on 802.1q trunking 1Po1 on 802.1q trunking 1Port Vlans allowed on trunkGi2/1 1-4094Gi2/2 1-4094Gi2/3 1-4094Gi2/4 1-4094Gi2/5 1-4094Gi2/6 1-4094Gi2/7 1-4094Po1 1-4094Port Vlans allowed and active in management domainGi2/1 1-15,20,100-112,120,130-132,140,150,251,253-2
20、54,430Gi2/2 1-15,20,100-112,120,130-132,140,150,251,253-254,430Po1 1-15,20,100-112,120,130-132,140,150,251,253-254,430一十三、路由状况检查C-B-05路由状况检查CISCO#show ip route 6509_1#show ip route summary路由表应包含正确的路由信息 对于企业一般都是交换网,一条默认路由指出,只是注意VLAN信息和此直连路由是否相符。ksy_c6509_2# show ip route Codes: C - connected, S - sta
21、tic, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static routeGateway of last resort is 192.168.254.1 to network 0.0.0.0C 192.168.106.0/24 is directly connected, Vlan106C 192.168.107.0/24 is directly connected, Vlan107C 192.168.105.0/24 is directly connected, Vlan105C 192.168.70.0/24 is directly connecte
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1