前言:
在網絡管理中,網絡故障排查是一個非常重要的環節。當網絡出現故障時,我們需要快速定位問題并解決它。華為交換機提供了遠程端口鏡像技術,可以幫助我們快速定位網絡故障。在本文中,我們將介紹如何使用華為交換機的遠程端口鏡像技術進行網絡故障排查。
實驗要求:
某醫院的行政部門網絡經常斷網,需要通過LSW6接入交換機組網,然后通過SwitchA與互聯網通信。Server端通過SwitchB與SwitchA相連?,F在需要通過Server端,對醫院的行政部門進行遠程流量監控,以監控訪問外網的數據流量,從而排查網絡故障。
網絡拓撲:

操作步驟如下:
我這里以華為交換機為例
1、配置觀察端口,在SwitchA上
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]undo inf
[Huawei]undo info-center en
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]
[Huawei]sysna
[Huawei]sysname SwitchA
[SwitchA]
[SwitchA]observe-port 1 in
[SwitchA]observe-port 1 interface gi
[SwitchA]observe-port 1 interface GigabitEthe.NET 0/0/2 vlan 10
[SwitchA]
[SwitchA]
通過上述配置,遠端的觀察接口會將相關的鏡像報文轉發給vlan10,如果不進行遠端觀察接口的配置,我們就的將遠端觀察口加入到vlan中。
2、配置鏡像端口,在SwitchA上
[SwitchA]interface GigabitEthernet 0/0/1
[SwitchA-GigabitEthernet0/0/1]port-mi
[SwitchA-GigabitEthernet0/0/1]port-mirroring to ?
observe-port Observe port
[SwitchA-GigabitEthernet0/0/1]port-mirroring to ob
[SwitchA-GigabitEthernet0/0/1]port-mirroring to observe-port 1 in
[SwitchA-GigabitEthernet0/0/1]port-mirroring to observe-port 1 inbound
[SwitchA-GigabitEthernet0/0/1]return
3、在SwitchB上創建VLAN10,并關閉該VLAN的mac地址學習功能,并將接口GE0/0/1和GE0/0/2加入VLAN10。
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]sysn
[Huawei]sysname SwitchB
[SwitchB]vlan 10
[SwitchB-vlan10]mac-address learning disable
[SwitchB-vlan10]
[SwitchB-vlan10]quit
[SwitchB]
[SwitchB]inter
[SwitchB]interface gi
[SwitchB]interface GigabitEthernet 0/0/1
[SwitchB-GigabitEthernet0/0/1]port lin
[SwitchB-GigabitEthernet0/0/1]port link-t
[SwitchB-GigabitEthernet0/0/1]port link-type ac
[SwitchB-GigabitEthernet0/0/1]port link-type access
[SwitchB-GigabitEthernet0/0/1]por
[SwitchB-GigabitEthernet0/0/1]port def
[SwitchB-GigabitEthernet0/0/1]port default valn
[SwitchB-GigabitEthernet0/0/1]port default va
[SwitchB-GigabitEthernet0/0/1]port default vl
[SwitchB-GigabitEthernet0/0/1]port default vlan 10
[SwitchB-GigabitEthernet0/0/1]
[SwitchB-GigabitEthernet0/0/1]quit
[SwitchB]
[SwitchB]interface GigabitEthernet 0/0/2
[SwitchB-GigabitEthernet0/0/2]
[SwitchB-GigabitEthernet0/0/2]port link-type trunk
[SwitchB-GigabitEthernet0/0/2]port trunk allow-pass vlan 10
[SwitchB-GigabitEthernet0/0/2]retu
[SwitchB-GigabitEthernet0/0/2]return
<SwitchB>
4、結果驗證
1)查看遠程觀察接口的相關信息
<SwitchA>dis observe-port
----------------------------------------------------------------------
Index : 1
Interface: GigabitEthernet0/0/2
Used : 1
Vlan : 10
----------------------------------------------------------------------
<SwitchA>

2)查看鏡像端口的配置信息
<SwitchA>dis port-mirroring
Port-mirror:
----------------------------------------------------------------------
Mirror-port Direction Observe-port
----------------------------------------------------------------------
GigabitEthernet0/0/1 Inbound GigabitEthernet0/0/2
----------------------------------------------------------------------
<SwitchA>

通過上述配置后,我們就可以在server端,捕捉到行政部門接入外網的相關網絡流量,從而對其故障進行排查。