H3C S5560-EI Series Troubleshooting Manual page 51

Hide thumbs Also See for S5560-EI Series:
Table of Contents

Advertisement

[Sysname-probe]bcm slot 1 chip 0 show/c/ge17
R64.ge17
R127.ge17
RPKT.ge17
RMCA.ge17
RBCA.ge17
RPOK.ge17
RBYT.ge17
2.
Verify that packets are not mistakenly filtered out by ACLs:
a.
Examine the ACL and QoS policy configurations for packet filtering on the port, on the VLAN
of the port, or globally. If packets are mistakenly filtered out, modify the ACL or QoS policy
configuration.
To display the ACL configuration on the port for packet filtering, execute the display
packet-filter command.
To display the QoS policy configuration on the port, execute the display qos policy
command.
To display the QoS policy configuration on the VLAN of the port, execute the display qos
vlan-policy command.
To display the global QoS policy configuration, execute the display qos policy global
command.
b.
Verify that packets are not filtered out by ACLs automatically created by some features.
Execute the display this command in Ethernet interface view to verify that the ip source
binding or ip verify source command is configured on the port. To display source guard
binding entries, execute the display ip source binding or display ipv6 source binding
command. If IP source guard is configured but the packets match no entry, further
troubleshoot the problem based on the way the binding entries are created.
Determine whether the port is configured with the portal authentication. If portal
authentication is configured, packets of users that fail to pass the portal authentication will
be dropped by the port. Use the display portal interface command to display the portal
configuration information of the specified VLAN interface. Determine whether the portal
authentication can be disabled based on the network conditions. To disable the portal
authentication at Layer 3, use the undo portal server server-name command in VLAN
interface view of the VLAN to which the port belongs.
Use the display dot1x command to check whether 802.1X EAD assistant is enabled on the
interface.
If 802.1X EAD assistant is enabled on the interface, packets will be discarded for
unauthenticated users who access the network segments other than the Free IP.
Determine whether MFF is configured on the VLAN to which the port belongs. Use the
display mac-forced-forwarding vlan command to display the MFF information of the
specified VLAN. If no gateway information is displayed in the output, verify that ARP
snooping is correctly configured based on the MFF operation mode.
3.
Verify that the port is not blocked:
Execute the display stp brief command to verify that STP does not set the state of the port to
discarding. When the port is in discarding state, it cannot forward traffic. H3C recommends
disabling STP on the port, or configuring the port as an edge port if the port is connected to a
terminal device.
:
:
:
:
:
:
:
21,974
47
20
168
204
141
63
204
+1
+5
+6
+5
+1
+6
+582
261/s
2/s
2/s
2/s
2/s

Advertisement

Table of Contents
loading

Table of Contents