background image

Mypower 

S4100 

Troubleshooting 

    

 

 

 

 

 

 

 

 

 

 

 Maipu Confidential & Proprietary Information 

     Page 

29 

of 

124 

 
 

L2PC Troubleshooting 

 

This chapter describes the common problems when using L2 Protocol 
Control (L2PC) to help the network administrator analyze and solve the 

network faults quickly and improve the production efficiency of enterprises. 

 

Main contents: 

z

 

Basic idea of L2PC troubleshooting 

z

 

Common L2PC troubleshooting 

 

Basic Idea of L2PC 
Troubleshooting 

The basic idea of analyzing faults: First check the link and then confirm 
the protocol configuration. 

First analyze the physical reasons, including whether the device works 
normally, whether the cables are normal, and whether the configuration is 

normal. 

 

Common L2PC Troubleshooting 

Fault 1: The protocol packets cannot be forwarded in the pre-set VLAN 

after being converted to the tunnel packets. 

Possible Reasons 

Judging Methods and Solutions 

The pvid configuration of the 
port on which L2PC is 
enabled is inconsistent with 
the VLAN ID that needs to 
be transmitted by the tunnel 
packet. 

Use the show vlan command to view whether the port on 
which L2PC is enabled belongs to the VLAN that needs to be 
transmitted by the tunnel packet. If not in one vlan, you can 
modify the pvid configuration of the port on which L2PC is 
enabled to be consistent with the vlan that needs to be 
transmitted by the tunnel packet. 

 

Summary of Contents for MyPower S4100 Series

Page 1: ...wer S4100 Troubleshooting Maipu Communication Technology Co Ltd No 16 Jiuxing Avenue Hi tech Park Chengdu Sichuan Province People s Republic of China 610041 Tel 86 28 85148850 85148041 Fax 86 28 85148...

Page 2: ...ny implied warranties of merchantability or fitness for any specific purpose Further Maipu reserves the right to revise this document and to make changes from time to time in its content without being...

Page 3: ...eness arrangement appearance Good Fair Average Poor Accessibility Contents index headings numbering Good Fair Average Poor Evaluate this document Editorial Language vocabulary readability clarity tech...

Page 4: ...g 16 MSTP Troubleshooting 20 Basic Idea of MSTP Troubleshooting 20 Common MSTP Troubleshooting 20 Common MSTP Display Information 22 MSTP information 22 MSTP Details 22 Common MSTP Error Information 2...

Page 5: ...ooting 58 Super VLAN Troubleshooting 61 Basic Idea of Super Vlan Troubleshooting 61 Common Super Vlan Troubleshooting 62 Loopback Test Troubleshooting 64 Basic Idea of Loopback Test Troubleshooting 64...

Page 6: ...tion Instance 102 BGP Troubleshooting 102 Basic Idea of BGP Troubleshooting 102 Tools for Removing BGP Faults 103 BGP Troubleshooting 106 BGP Error Information Instance 108 IS IS Troubleshooting 109 B...

Page 7: ...ame segment as the FTP server In the config mode use the interface vlan command to enter the interface and then use the ip address command to add or modify the IP address 2 During the FTP upgrade the...

Page 8: ...ot parameters are correct If not correct use the bootloader command to set the boot parameters and re start the correct IOS 2 The IOS is deleted Enter the monitor and use the dir command to view wheth...

Page 9: ...nt Troubleshooting 1 Analyze the physical reason Checking method Use the show port command to view whether the physical signals are all up and check whether the cables are normal and whether the devic...

Page 10: ...the switch is full 3 The port is configured with the MAC address filtering and the specified MAC address packets are dropped 4 The port belongs to one aggregation group and the MAC address learning fu...

Page 11: ...nd the indicators are off Here maybe the port rate and duplex mode are set wrongly which results in the negotiation failure between the two sides of the link You can check the peer setting and ensure...

Page 12: ...w whether the port is err disabled and then use the show port xxx status err disabled command to view which module err disables the port 2 The port is configured with err disable recovery You can conf...

Page 13: ...ents z Basic idea of VLAN troubleshooting z Common VLAN troubleshooting Basic Idea of Vlan Troubleshooting 1 Analyze whether the VLAN exists Checking method Use the show vlan command to view whether V...

Page 14: ...or ip vlan or protocol vlan are not set globally Use the show mac vlan and show ip subnet vlan show protocol vlan commands to view whether the corresponding rules are set up 2 The port is not configu...

Page 15: ...nd Solutions The configured mac vlan distributes the hardware resources according to the hash algorithm and as a result the hardware resources are not enough According to hash algorithm some MACs are...

Page 16: ...er the cables are normal whether the device is normal and whether the environment has the bad influence for the link aggregation 2 Check whether the status of the link group is normal and whether the...

Page 17: ...d Lacp_Enabled_Full_Duplex actor information 1 000122334450 32768 3 0x0501 Passive LongTimeout Aggregatable IN_SYNC Collecting Distributing Received Unexpired partner information 32768 00017A334401 32...

Page 18: ...ith the consistent rate to add to one aggregation port Fault 3 The common ports cannot be added to one aggregation group Possible Reasons Judging Methods and Solutions 1 The aggregation group to which...

Page 19: ...er the type of the sent packets does not match the load balance mode of the set aggregation group View the load balance mode of the link aggregation group If the load balance mode is src mac and the s...

Page 20: ...ing Basic idea of analyzing the faults First check the link and then confirm the protocol configuration First analyze the physical reason including whether the device works normally and whether the ca...

Page 21: ...hole MSTA domain are different and the port role error may appear Use the show running config command to check whether the configured pathcost algorithms are the same Fault 2 The MSTP line switches an...

Page 22: ...cluding root bridge specified bridge port role and so on Router show spanning tree mst MST Instance 00 vlans mapped 1 3 5 4094 Bridge address 0001 7a4f 47b6 priority 32768 Region root address 0001 7a4...

Page 23: ...signated root address 0001 7a4f 47b6 priority 32772 Designated brdige address 0001 7a4f 47b6 priority 32772 root 0 rpc 0 hop 20 port 5 0 role Master state Forwarding infoIs Aged vlanref 1 portid 32769...

Page 24: ...gards that the peer VLAN mapping configuration is the same as the local device that is the configurations of the peer and the local devices are in one domain and the port works in the PRE STANDARD mod...

Page 25: ...on the port is correct Checking method Use the show run command to view whether the dot1q tunnel configuration of the port is correct for example whether dot1q tunnel is enabled 2 View whether the vla...

Page 26: ...ow QINQ configuration of the port Fault 2 QINQ cannot be configured on the port Possible Reasons Judging Methods and Solutions 1 The port is the access port Configure the selective QinQ SW2 config por...

Page 27: ...nal data during the QinQ communication so it is normal that the QinQ forwarding cannot reach the wire speed The MTU value is not enough The QinQ packet is added with 4 bytes The forwarding cannot be p...

Page 28: ...o matter whether the untag packet is configured with drop it is encapsulated with PVID on QinQ port and then is forwarded Fault 7 H02 cannot perform the QinQ data communication with Cisco device Possi...

Page 29: ...ns including whether the device works normally whether the cables are normal and whether the configuration is normal Common L2PC Troubleshooting Fault 1 The protocol packets cannot be forwarded in the...

Page 30: ...ts 3 The port that needs to recover to the protocol packet belongs to the VLAN that transmits the tunnel packets but the L2PC Tunnel of the protocol is not enabled Use the show l2protocol control port...

Page 31: ...l signals become up whether the cables are normal whether the device is normal and whether the environment has bad influence for the L2 multicast work Use the ping command to view whether the unicast...

Page 32: ...e port but there is the information about the group on other ports Use the show run command to view that the maximum limitation group is set on the port As a result the groups that need to receive can...

Page 33: ...and Solutions It is not configured to drop the unknown multicast Use the show run vlan xx command on the switch to view whether l2 multicast drop unknown is configured If IPMC forwarding mode is used...

Page 34: ...itch show l2 multicast mac entry static Current L2 Static Multicast 2 entries NO VID Group MAC address Port Number 1 1 0100 5E00 0101 2 1 0100 5E00 0102 M port 0 20 The static multicast indicates that...

Page 35: ...show multicast vlan command to display the enabling status of the multicast VLAN and the setting of the multicast VLAN and its sub VLAN as follows switch show multicast vlan Multicast Vlan Table VLAN...

Page 36: ...rface To receive the multicast flow in the multicast sub VLAN normally you need to configure interface in the sub VLAN so that the sub VLAN can work normally Use the show run int command to view wheth...

Page 37: ...ting 1 Analyze the network connectivity Checking method Use the show port 0 x x is the physical port number command to view whether the port is in the up state whether the cables are normal and whethe...

Page 38: ...whether the route is reachable Fault 2 The accounting cannot be performed normally on the server Possible Reasons Judging Methods and Solutions The AAA accounting is not enabled on the device Use the...

Page 39: ...r the authentication device works in the port based authentication mode If not change it to work in the port based authentication mode Besides view whether there is the desired vlan id on the device Y...

Page 40: ...ort based mode the other hosts cannot access the network after passing the authentication Possible Reasons Judging Methods and Solutions In port based mode the single host mode is set After being conf...

Page 41: ...roubleshooting Basic Idea of Port Security Troubleshooting 1 Analyze the network connectivity Checking method Use the show port 0 x command to view whether the port is in the up state whether the cabl...

Page 42: ...upper threshold of MAX rule 2 so another 2 users in the port can be permitted to access the network Fault 2 After enabling the MAC rule of the port security the MAC address cannot be aged Possible Rea...

Page 43: ...is set up and add the VLAN to RSPAN Use the remote vlan command in vlan to set up remote vlan and add the VLAN to rspan according to the configuration requirement One port can bear the remote vlan of...

Page 44: ...s discard the TAG flag of the packet and as a result the mirrored packet does not have TAG flag It is recommended to change a PC to test The L2 protocol packets cannot be captured such as STP and LACP...

Page 45: ...method Use the show acl object command to view whether the ACL is correctly applied on the appropriate object global VLAN and port Common ACL Troubleshooting Fault 1 The configured ACL does not take e...

Page 46: ...g cannot be performed sw201 show access list ip access list standard 1 10 deny 10 0 0 0 0 0 0 255 time range 33 inactive Fault 2 After configuring the rule of denying the access of one segment or host...

Page 47: ...group If yes you can only configure ACL on the link group or exit the link aggregation port and then enable the ACL The object is bound to the same type of ACL Use the show acl object command to view...

Page 48: ...hardware resources are fixed so if you increase the number of the hardware resources of Port IP ACL the number of the hardware resources on other objects are decreased such as VLAN IP ACL or EVC func...

Page 49: ...troubleshooting Basic Idea of QOS Troubleshooting 1 Analyze packets or tester setting Analyze whether the packets match the specified data flow If using the tester for the QoS test check whether the t...

Page 50: ...e lp and cos queue If the packet cannot enter the queue after mapping the packet by dot1p maybe because it conflicts with the dscp mapping If the conflict happens the dscp mapping takes effect first F...

Page 51: ...on and at last deny the packet regardless of the configured rule on the object with lower priority You can use the show acl object command to view the configured ACL rule Switch show acl object Port B...

Page 52: ...ket dot1p as 5 At last process according to the priority and the dot1p value of the packet is 3 regardless of the rule configured on the object with lower priority You can use the show evc policy and...

Page 53: ...gured by the user are not matched match the last drop policy To let the un matching data flow pass you need to configure one policy of matching all packets of the port in the end the inner out VLAN an...

Page 54: ...ing and sending of the control packets Checking method Use the show eips ring command to view the EIPS ring status and the receiving sending of the control packets Use the show eips port link aggregat...

Page 55: ...hods and Solutions 1 EIPS is not enabled correctly View whether there is the configuration of EIPS start in EIPS Meanwhile execute the show eips ring command to view whether the EIPS status is init If...

Page 56: ...e EIPS domain configuration of the node is inconsistent Use the debug eips ring command to verify whether it is caused by the inconsistent configuration You can check the configuration Fault 4 The sta...

Page 57: ...f 802 AG Troubleshooting 1 Check whether the same CFM MD and MA are configured correctly on the devices Checking method Use the show ethernet cfm domain command to view whether the MD and MA configure...

Page 58: ...th the MEP ID configured on the port The inward MD of the MEP device can only send CFM packets on the port that is not configured with MEP ID while the outward MD can only send CFM packets on the port...

Page 59: ...enance points local command to view whether the device is configured with MEP If not the device is MIP and does not support link tracking function The MD and MA are not configured on the device The de...

Page 60: ...Mypower S4100 Troubleshooting Maipu Confidential Proprietary Information Page 60 of 124 tracking By default the TTL value is 64 The maximum TTL can reach 255...

Page 61: ...r Vlan command to view whether Super Vlan exists 2 Check whether Super Vlan is added with Sub Vlan and whether the Sub Vlan exists Checking method Check whether there is Sub vlan in the specified Supe...

Page 62: ...ting the association of the vlan and the L3 interface The vlan ID is the ID of one super vlan If there is the following prompt information when adding sub vlan Switch config super vlan4 sub vlan 5 Fai...

Page 63: ...mation Page 63 of 124 Super vlan is not configured with arp proxy Use the show Super Vlan command to view whether the super vlan is configured with arp proxy enable Different suv vlans can perform L3...

Page 64: ...f loopback test troubleshooting z Common looback test troubleshooting Basic Idea of Loopback Test Troubleshooting 1 Check network environment Check whether there is broadcast storm in the network envi...

Page 65: ...en FORWARDING and BLOCKING repeatedly Once the problem appears the administrator should shut down the faulty ports check the downstream network and delete the remote loop with the broadcast storm Faul...

Page 66: ...ults Main contents z Basic idea of IP SOURCE GUARD troubleshooting z Common IP SOURCE GUARD troubleshooting Basic Idea of IP SOURCE GUARD Troubleshooting 1 Analyze the packets Analyze whether the sour...

Page 67: ...rce binding One is to permit DHCP packets to pass and the other is to deny all un permitted packets Therefore if the number of the ports on which IP SOURCE GUARD is enabled is different the maximum nu...

Page 68: ...Mypower S4100 Troubleshooting Maipu Confidential Proprietary Information Page 68 of 124 invalid binding entries of the port with small serial number become valid...

Page 69: ...heck whether the configuration and parameter setting are reasonable Common OAM Troubleshooting Fault 1 The OAM neighbor cannot be set up Possible Reasons Judging Methods and Solutions The switch is im...

Page 70: ...of the connection disables the loopback test function View the OAM neighbor information view whether the two parties both support the loopback test view whether the party that does not support loopbac...

Page 71: ...abled View the port configuration and view whether the port detection function is disabled If yes delete the related configuration Whether the link check parameters are set correctly on the port The d...

Page 72: ...er E LMI is enabled globally or on the port Checking method Use the show ethernet lmi parameters command to view whether the port is e lmi port 2 View whether the CE and PE type of E LMI are configure...

Page 73: ...to view whether the port status between PE and CE is up If it is down check whether the cable between the two ports is correct Fault 2 The port of PE cannot be bound to EVC normally Possible Reasons J...

Page 74: ...P SNOOPING faults Main contents z Basic idea of DHCP SNOOPING troubleshooting z Common DHCP SNOOPING troubleshooting Basic Idea of DHCP SNOOPING Troubleshooting 1 show dhcp snooping database View whet...

Page 75: ...the L3 interface of the address must be in the same VLAN as the client and server ports Use the dhcp snooping relay address command to specify the address The attack detection function is enabled and...

Page 76: ...tial Proprietary Information Page 76 of 124 global configuration mode so that the port can become up within some time The default interval from shutdown to up is 5 minutes The interval can be modified...

Page 77: ...c idea of DYNAMIC ARP INSPECTION troubleshooting z Common DYNAMIC ARP INSPECTION troubleshooting Basic Idea of DYNAMIC ARP INSPECTION Troubleshooting 1 Analyze the arp packets Analyze whether the Send...

Page 78: ...ured For example DYNAMIC ARP INSPECTION is enabled on the port but no any IP SOURCE GUARD binding item the port drops call received arp packets The number of the entries exceeds the maximum value and...

Page 79: ...own by err disable because the received arp packets exceeds the limitation you need to execute the command errdisable recovery cause dai in the global configuration mode so that the port can automatic...

Page 80: ...indicates the physical port number to check whether the port is up Check the connection cable and the device Check whether the device can be connected with the PS server 2 Check the configuration and...

Page 81: ...ete the configuration 8 The mac vlan is not enabled at the port When the ps binds vlan for roles the user delivers vlan and joins the vlan in the mac vlan mode when the user logs in for authentication...

Page 82: ...role network segment and the client non authentication IP address are not in the same network segment Set the address of the PC NIC in the client to the IP address in the user role network segment If...

Page 83: ...tial Proprietary Information Page 83 of 124 There is no vlan id bound with default roles on the device Check the vlan id of the default role on the ps Then run the show vlan command to check whether t...

Page 84: ...are of lack in the routing table Check whether the routing devices are connected The dynamic routing protocol is running over the IP layer To exchange routing protocol packets between routing devices...

Page 85: ...the two parties of the OSPF negotiation Basic Idea of OSPF Neighbor Relation Troubleshooting OSPF Neighbor Table is Empty OSPF Neighbor is in the Attempt Status Only when the network status is NBMA a...

Page 86: ...the route filtering is configured to prevent adding routes to the core Step 4 If OSPF routing table does not have relevant routes check whether the OSPF database has relevant route LSA Step 5 Calculat...

Page 87: ...e ospf Display the OSPF route information in the core routing table show run router ospf Display the current running OSPF process The application of the show tools is as follows As shown in the preced...

Page 88: ...State DR Priority 1 TE Metric 0 4 Designated Router ID 2 2 2 4 Interface Address 129 255 19 20 5 Backup Designated Router ID 11 0 0 1 Interface Address 129 255 19 10 6 Timer intervals configured Hello...

Page 89: ...5 19 160 vlan500 O 129 255 0 0 1 is directly connected vlan500 Area 0 0 0 0 The routes contained in the OSPF routing table include route type metric value the area of the switch that learned the route...

Page 90: ...of routing table debug ip ospf ifsm events status timers Trace interface state machine debug ip ospf nfsm events status timers Trace neighbor state machine OSPF Troubleshooting Fault 1 Failed to crea...

Page 91: ...of the OSPF interface of the two parties are not matched How to find out the cause Use the show ip ospf neighbor command and no neighbors are found for a long time Open the debug ip ospf packet hello...

Page 92: ...not received For the NBMA you should configure neighbor route switching devices Solution in the OSPF mode configure the OSPF neighbor neighbor A B C D Neighbor IP address 8 The network mask of the two...

Page 93: ...ble is returned Run the show ip ospf neighbor command to check that the neighbor interface is in the INIT status Open the debug ip ospf packet hello Find that the interface can receive the opposite he...

Page 94: ...when the route cannot be learned for example the point to point network mode and the broadcast network mode after the two parties are set to the mode the neighbor status can be full but the routing in...

Page 95: ...xternal route filtering is performed on the ASBR the configuration of the ACL corresponding to the distribute list ACL out command is incorrect Solution Check the configuration of the corresponding AC...

Page 96: ...s change the stub area into nssa area or common OSPF area OSPF Error Information Instance OSPF Error Information major statements and Causes Information Cause Information 1 OSPF Authentication error T...

Page 97: ...namic routing protocol is running over the IP layer To exchange routing protocol packets between routing devices the link layers must be connected Step 3 Locate the faulty routing switching device On...

Page 98: ...s follows Switch A router rip network 21 0 0 0 version 2 no auto summary exit Switch B router rip network 14 0 0 0 network 21 0 0 0 version 2 no auto summary exit Use the show tool to collect the foll...

Page 99: ...can send RIP packets 7 The interface sends RIP packets through RIPv2 8 The interface can receive RIP packets 9 The interface receives RIP packets through RIPv2 10 Enable poison reverse 11 The interfac...

Page 100: ...to the RIP interface table Possible Reasons Judging Methods and Solutions The interface is down How to find out the cause Use the show ip rip interface command to check the interface table Use the sho...

Page 101: ...But debug ip rip events cannot receive the update packets of the opposite end Solution Cancel the configuration of the passive interface Use the neighbor command if there is only one passive interfac...

Page 102: ...re available Step 2 Locate the faulty routing switching device On the routing switching device use the show tool to check the relevant information for example BGP neighbor table and routing table Step...

Page 103: ...ctions created between neighbors Show ip bgp summary To display the status of all BGP neighbors and the duration of the established status The commands in the preceding table are the basic tools for t...

Page 104: ...14 3 BGP State Established up for 00 41 12 Flags 4 BGP Last State OpenConfirm Last Event RecvKeepAlive Last Error None Last read update keepalive 00 01 12 5 Hold time is 180 keepalive interval is 60 s...

Page 105: ...The routes contained in the BGP routing table are the route configured by the network The route must exist in the IGP table the BGP route learned from the neighbor other routing information imported...

Page 106: ...ble TCP MD5 authentication failed How to find out the cause Use the show ip bgp neighbor or show ip bgp summary command to find that the neighbor cannot be created but the peer IP address is available...

Page 107: ...e the show ip bgp command to check the specific route Check whether the gateway route exists in the next hop of show ip route core routing table Solution Add the route that can reach the next hop of t...

Page 108: ...dicates that the protocol is enabled at the interface BGP indicates the route of the network should be added to the BGP and the route must exist in the core routing table How to find out the cause Use...

Page 109: ...e routing switching table Step 2 Check whether the routing devices are connected ISIS is different from other dynamic routing protocols It is running on the link layer protocol and independent from th...

Page 110: ...esh groups at the ISIS interface show isis neighbors Check the information about the neighbor created by the ISIS including a specific interface neighbor neighbor detail and brief neighbor information...

Page 111: ...f disabling ISIS protocol is enabled at the expected interface or ISIS process Open the bebug isis adj packets to check whether IIH packets are sent at the relevant interface Solution Check the config...

Page 112: ...iguration of the ISIS process in the two negotiation parties Modify the level parameter to ensure consistency 9 Parameter setting of the interface layer is not matched How to find out the cause Open d...

Page 113: ...to check whether the LSP SNP authentication types are the same Solution Modify the LSP SNP authentication types to ensure consistency The LSP SNP authentication parameters do not match How to find ou...

Page 114: ...r you have to change the metric modes of all switches to narrow Otherwise the database may be unsynchronized and thus the routes cannot be learned Failed to redistributes default routes How to find ou...

Page 115: ...o find out the cause Run the show isis database detail command to check whether the summary route has the Extended tag Run the show run router isis command to check whether the metric mode is wide Sol...

Page 116: ...H packet prompt message mismatch with circuit type Indicates that the ISIS or interface level parameters are not matched Information 6 IIH packet prompt message IPv4 interface address mismatch Indicat...

Page 117: ...SP of the device and the port Method use the show run command to check whether the NDSP protocol is enabled globally and under the device port 2 Check whether the NDSP information is correct Method us...

Page 118: ...tatus of sending topology requests MCMP protocol is not enabled in the switch Use the show run command to whether the MCMP protocol is enabled in the switch that is not collected The NDSP protocol is...

Page 119: ...switch is not active On the command switch use the show cluster mcmp member command to check whether the member is active If the status is not active find the reason The tunnel connection of the memb...

Page 120: ...ooting 1 Check whether the show private vlan exists Method use the show private vlan command to check whether the vlan exists and the mode is pvlan 2 Check whether the port belongs to the specified vl...

Page 121: ...rrelated primary vlan and secondary vlan are not in the same MSTP instance If the MSTP function is enabled when the PVLAN is used ensure that the interrelated primary vlan and secondary vlan are in th...

Page 122: ...the Voice VLAN is enabled Method Use the show voice vlan all command 2 Check whether the voice vlan function of the port is enabled Method run the show voice vlan all command to check whether the voi...

Page 123: ...at the port The pvid of the port is set to the vid of the voice vlan But the voice vlan function of the port is not enabled As a result the packets are forwarded in the voice vlan but the sent packet...

Page 124: ...L3 communication the packets sent from VLAN2 interface should be received by VLAN3 interface in this case pay attention to the following restrictions 1 When the local port encounters a loopback note t...

Reviews: