版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、MX960 PPPo配己置注释普天国脉网络科技版权所有侵权必究11 / 42内部文档,未经许可不得扩散Porpvio文档类别设备维护口工程实施口流程标准口配置案例故障案例口行政治理口根底理论口文档密级内部公开 口内部限制 口外部公开 口外部限制绝密文档口文档作者童建喜文档审核文档摘要当前文档版本V1.0文档所属部门杭州售后效劳支持部文档使用对象售后技术支持工程师记修订录版本修订日期修订说明编写/修订人V1.02021-09-9第一次发布童建喜目录1. 配置注释42. 相关维护命令312.1. 如何查看用户在线数量 3122如何查看根据用户名查该用户所在的VLAN信息 312.3. 如何查看当前
2、用户会话数或者ppp会话数 322.4. PPPOE中地址池分配IP机制322.5. 如何查看BRAS上收到PPPoE各个阶段的报文统计数量 332.6. 怎么查看BRAS中不同VR中不同地址池的使用情况 382.7. PPPoE在没有匹配限速策略时,默认获得的速度是多少 392.8. 如何查看PPPoE用户被分配的带宽大小 392.9. 如何配置 PPPoE中QinQ的内层和外层标签的范围 412.10. 如何根据用户名查看用户所在地址池和分配的IP地址421.配置注释*WARNING* Authorised access only, all of your done will be rec
3、orded!* * IMMEDIATELY disconnect if you are not an authorised user!*YWGD_MX480-1.RE0 (ttypO)login:login: guomaiPassword:-JUNOS 11.4X27.51 built 2021-07-15 19:29:27 UTCmasterguomaiYWGD_MX480-1.RE0> sh6Aunknown command.guomaiYWGD_MX480-1.RE0> show configuration | no-more # Last commit: 2021-08-0
4、9 12:12:46 CST by guomai version 11.4X27.51;groups re0 system host-name YWGD_MX480-1.RE0;re1 system host-name YWGD_MX480-1.RE1;apply-groups re0 re1 ;dynamic-profiles pppoe predefined-variable-defaults input-filter 512k;output-filter 512k;routing-instances "$junos-routing-instance" interfac
5、e "$junos-interface-name" unicast;routing-options access-internal route $junos-subscriber-ip-address qualified-next-hop "$junos-interface-name"interfaces pp0 unit "$junos-interface-unit" no-traps;ppp-options pap;pppoe-options underlying-interface "$junos-underlying
6、-interface"server;keepalives interval 30;family inet rpf-check;filter input "$junos-input-filter"output "$junos-output-filter"unnumbered-address "$junos-loopback-interface"autovlan interfaces "$junos-interface-ifd-name" unit "$junos-interface-unit&qu
7、ot; vlan-id "$junos-vlan-id"family pppoe duplicate-protection;dynamic-profile pppoe;short-cycle-protection lockout-time-min 1;lockout-time-max 900;system time-zone Asia/Shanghai;ports console log-out-on-disconnect;root-authentication encrypted-password "$1$dWomk0w2$05fWN35qBcDZCtoeJxW
8、86." # SECRET-DATAdynamic-profile-options versioning;login message“*n*WARNING*n*n* Authorised access only, all of your done will be recorded!*n*n*IMMEDIATELY disconnect if you are not an authorised user! *n*n*n*n"class super-user-remote idle-timeout 120;permissions all;user guomai uid 2000
9、;class super-user;authentication encrypted-password "$1$qxE/F8LR$H5EPD2W1LQzr8HkQjAdwP." #SECRET-DATAuser ywgd uid 2001;class super-user;authentication encrypted-password "$1$6jYddKE5$vUTQBONcH9xwfcUH6CEmH0" # SECRET-DATAservices ftp;telnet;syslog user * any emergency;file messag
10、es any warning;authorization info;explicit-priority;file interactive-commands interactive-commands any;file troubleshooting any any;archive size 10m files 10;explicit-priority;time-format year;commit synchronize;ddos-protection protocols PPPoe padt fpc 0 bandwidth-scale 60; burst-scale 60;fpc 1 band
11、width-scale 60; burst-scale 60;chassis redundancy failover on-loss-of-keepalives; on-disk-failure;graceful-switchover;aggregated-devices ethernet device-count 8;alarm management-ethernet link-down ignore;interfaces xe-0/0/0 description TO_CR16008-1_Tg1/3/0/1;flexible-vlan-tagging;auto-configure vlan
12、-ranges dynamic-profile autovlan accept pppoe;ranges any;remove-when-no-subscribers;link-mode full-duplex;gigether-options no-auto-negotiation;unit 11 description TO_manage;vlan-id 900;family inet address 1/24;xe-0/1/0 description T0_CR16008-2_Tg1/3/0/2;flexible-vlan-tagging;auto-config
13、ure vlan-ranges dynamic-profile autovlan accept pppoe; ranges any;remove-when-no-subscribers;link-mode full-duplex;gigether-options no-auto-negotiation;ge-1/0/0 description to_MX480-2_ge-1/0/0;gigether-options 802.3ad ae1;ge-1/0/1 description to_MX480-2_ge-1/0/1;gigether-options 802.3ad ae1;ge-1/1/0
14、 description T0_wasu_0TN-G3;speed 1g;link-mode full-duplex;gigether-options no-auto-negotiation;unit 0 family inet address 42/30;ge-1/1/9 unit 0 family inet address /24;ae1 flexible-vlan-tagging;unit 10 description T0_MX480-2_ae1.10_for_wasu;vlan-id 10;family inet address 30.2
15、54.244.149/30;fxp0 unit 0 family inet address /24;loO unit 0 family inet filter input Protect_RE_ACL;address /32;unit 1 family inet address 21/32;snmp community "TswcbyyQjsjhfl14!" authorization read-only;client-list-name SNMPAccessACL;routing-options nonstop
16、-routing;static route /16 next-hop ;forwarding-table export please-load-balance-traffic;protocols ppp-service dns-group-profile dns;lldp interface ge-1/0/0;interface ge-1/0/1;interface ge-1/1/0;interface ge-1/1/9;policy-options prefix-list ftp-permit;prefix-list ospf-permit 3
17、41/32;50/32;prefix-list bgp-permit apply-path "protocols bgp group <*> n eighbor <*>"prefix-list bfd-permit;prefix-list snmp-permit;prefix-list ntp-permit;prefix-list tacacs_permit;prefix-list radius-permit 38/32;39/32;prefix-lis
18、t rsvp-permit;prefix-list ldp-permit;prefix-list msdp-permit apply-path "protocols msdp group <*> peer <*>"prefix-list tacacs-permit;prefix-list gre-permit;prefix-list telnet-permit /0;prefix-list MAN_RT /8;/15;/16;/15;/1
19、6;policy-statement please-load-balance-traffic then load-balance per-packet;policy-statement static-to-ospf term 1 from protocol static;route-filter /19 exact;route-filter /19 exact;route-filter /19 exact;route-filter /19 exact; then accept;firewall family ine
20、t filter Protect_RE_ACL term ospf from source-prefix-list ospf-permit;protocol ospf;then accept;term bgp from source-prefix-list bgp-permit;protocol tcp;port bgp;then count bgp;accept;term fragment from first-fragment;then count fragment1;discard;term fragment2 from is-fragment;then count fragment2;
21、discard;term icmp-ping from protocol icmp;icmp-type echo-request echo-reply ;then policer 10m;count icmp-ping;accept;term icmp-ttl from protocol icmp;icmp-type time-exceeded;icmp-code ttl-eq-zero-during-transit;then policer 500k;count icmp-ttl;accept;term traceroute from protocol udp;destination-por
22、t 33434-33678;then policer 500k;count traceroute;accept;term telnet_ssh from source-prefix-list telnet-permit;protocol tcp;port telnet ssh ;then policer 3m;count telnet_ssh; accept;term radius from source-prefix-list radius-permit;source-port radius;then accept;term tacacs from source-prefix-list ta
23、cacs-permit;protocol tcp; source-port tacacs;then policer 500k;count tacacs; accept;term ntp from protocol udp; source-port ntp;then policer 500k;count ntp_permit;accept;term snmp from source-prefix-list snmp-permit;protocol udp;destination-port snmp;then policer 3m;count snmp;accept;term ftp from p
24、rotocol tcp;port ftp ftp-data ;then policer 1m;count ftp;accept;term bfd from source-prefix-list bfd-permit;protocol udp;source-port 49152-65535; destination-port 3784;then policer 3m;count bfd;accept;term rsvp from source-prefix-list rsvp-permit;protocol rsvp;then policer 1m;count rsvp; accept;term
25、 Idp from source-prefix-list Idp-permit;protocol tcp udp ;port ldp;then policer 10m;count Idp;accept;term lsp-ping from protocol udp;port 3503;then policer 500k;count lsp-ping; accept;term pim from protocol pim;then policer 1m;count pim; accept;term msdp from source-prefix-list msdp-permit;protocol
26、tcp udp ;port msdp;then count msdp; accept;term igmp from protocol igmp;then policer 1m;count igmp; accept;term gre from source-prefix-list gre-permit;then policer 1m;count gre;accept;term vrrp from destination-address 8/32;then policer 3m;count vrrp;accept;term mcast_bcast from destination
27、-address /32; /32; 55/32;then policer 1m;count multicast-broadcast; accept;term l2tp from protocol udp;port 1701;then policer 10m;count l2tp;accept;term discard_else then count discard-else;discard;filter 512k interface-specific;term 1 then policer 512k; accept;filter
28、1024k interface-specific;term 1 from source-prefix-list MAN_RT; destination-prefix-list MAN_RT;then policer 3m;term 2 then policer 1m;filter 2048k interface-specific;term 1 from source-prefix-list MAN_RT; destination-prefix-list MAN_RT;then policer 4m;term 2 then policer 2m;filter 4096k 25 / 42内部文档,
29、未经许可不得扩散interface-specific;term 1 from source-prefix-list MAN_RT; destination-prefix-list MAN_RT;then policer 6m;term 2 then policer 4m;filter 6144k interface-specific;term 1 from source-prefix-list MAN_RT; destination-prefix-list MAN_RT;then policer 8m;term 2 then policer 6m;filter 8192k interface-
30、specific;term 1 from source-prefix-list MAN_RT; destination-prefix-list MAN_RT;then policer 10m;term 2 then policer 8m;filter 10240k interface-specific;term 1 from source-prefix-list MAN_RT; destination-prefix-list MAN_RT;then policer 12m;term 2 then policer 10m;filter 20480k interface-specific;term
31、 1 then policer 20m;filter company_2048k interface-specific;term 1 from source-prefix-list MAN_RT; destination-prefix-list MAN_RT;then policer 4m;27 / 42内部文档,未经许可不得扩散term 2 then policer 2m;filter company_4096k interface-specific;term 1 from source-prefix-list MAN_RT; destination-prefix-list MAN_RT;t
32、hen policer 7m;term 2 then policer 4m;filter company_6144k interface-specific;term 1 from source-prefix-list MAN_RT; destination-prefix-list MAN_RT;then policer 10m;term 2 then policer 6m;filter company_8192k interface-specific;term 1 from source-prefix-list MAN_RT;destination-prefix-list MAN_RT;the
33、n policer 12m;term 2 then policer 8m;filter company_10240k interface-specific;term 1 from source-prefix-list MAN_RT; destination-prefix-list MAN_RT;then policer 15m;term 2 then policer 10m;filter company_20480k interface-specific;term 1 then policer 20m;policer 1m if-exceeding bandwidth-limit 102400
34、0;burst-size-limit 100k;then discard;policer 3m if-exceeding bandwidth-limit 3072000; burst-size-limit 300k;then discard;policer 5m if-exceeding bandwidth-limit 5120000; burst-size-limit 100k;then discard;policer 500k if-exceeding bandwidth-limit 500k; burst-size-limit 15k;then discard;policer 10m i
35、f-exceeding bandwidth-limit 10240000; burst-size-limit 450k;then discard;policer 512k if-exceeding bandwidth-limit 512k; burst-size-limit 20k;then discard;policer 6m if-exceeding bandwidth-limit 6144000; burst-size-limit 300k;then discard;policer 8m 29 / 42内部文档,未经许可不得扩散if-exceeding bandwidth-limit 8
36、192000;burst-size-limit 400k;then discard;policer 20m if-exceeding bandwidth-limit 20480000; burst-size-limit 900k;then discard;policer 4m if-exceeding bandwidth-limit 4096000; burst-size-limit 400k;then discard;policer 7m if-exceeding bandwidth-limit 7168000; burst-size-limit 400k;then discard;poli
37、cer 12m if-exceeding bandwidth-limit 12288000; burst-size-limit 600k;then discard;policer 2m if-exceeding bandwidth-limit 2048000; burst-size-limit 200k;then discard;policer 15m if-exceeding bandwidth-limit 15360000;burst-size-limit 800k;then discard;access radius-server 39 secret "
38、;$9$qf3/CA0lhr0BRcrlXxNdb2JD" # SECRETDATA38 secret "$9$hj-rWX7Nb2oGbsgaGUmP5QF/pB" # SECRETDATAgroup-profile dns PPP primary-dns 28;secondary-dns 00;profile none authentication-order none;profile pro_pppoe_wasu authentication-order radius;radius
39、 authentication-server 38 39 ;accounting-server 38 39 ;options interface-description-format exclude-sub-interface;nas-identifier YIWU-BRAS-01;nas-port-extended-format stacked-vlan-width 32;accounting-session-id-format decimal;vlan-nas-port-stacked-
40、format;client-authentication-algorithm direct;client-accounting-algorithm direct;radius-server 39 secret "$9$EWFyMLx7VY4ZVw2oZG.mfTz6tO" # SECRET-DATA source-address 21;38 secret "$9$8qr7w24oGiqfGDH.f5/9Ap0ISe" # SECRET-DATA source-address 2
41、21;accounting order radius;accounting-stop-on-failure;immediate-update;update-interval 60;statistics volume-time;address-assignment pool test family inet network /24;range 1 low ;high 55;domain map ywgd aaa-routing-instance vr-wasu;access-profile pro_pppoe_w
42、asu;target-routing-instance vr-wasu;strip-domain;routing-instances vr-wasu instance-type virtual-router;access address-assignment pool internetpool family inet network /19; range 1 low ;high 55;pool companypool family inet network /19;range 1 low ;h
43、igh 55;interface ge-1/1/0.0;interface ge-1/1/9.0;interface ae1.10;interface lo0.1;routing-options static route /19 discard;route /19 discard;router-id 21;protocols ospf export static-to-ospf;area 5 nssa;interface ge-1/1/0.0;interface lo0.1 passive;
44、interface ge-1/1/9.0;interface ae1.10;masterguomaiYWGD_MX480-1.RE0>masterguomaiYWGD_MX480-1.RE0>masterguomaiYWGD_MX480-1.RE0>master57 / 42内部文档,未经许可不得扩散2.相关维护命令2.1. 如何查看用户在线数量guomaitechD-05-BRAS-A-JuniperMX960.RE0> show subscribers summarySubscribers by StateInit: 44Configured: 1Active: 2
45、1833Terminating: 2Total: 21880#当前用户的总数量 #Subscribers by Client TypeVLAN: 324#当前用户vlan 总数#PPPoE: 21556# 当前 PPPoE 用户总数 #Total: 218802.2. 如何查看根据用户名查该用户所在的 VLAN信息1. 查出该用户所使用 PP0接口guomaitechD-05-BRAS-A-JuniperMX960.RE0> show subscribers user-name ywj080441Interface IP Address/VLAN IDUser NameLS:RIpp0.
46、10738822697ywj080441default:vr222. 查出该pp0所使用underlying 接口guomaitechD-05-BRAS-A-JuniperMX960.RE0> show pppoe interfaces pp0.1073882261 pp0.1073882261 Index 1088State: Session Up, Session ID: 251, Type: Dynamic,Service name: <empty>, Remote MAC address: 00:1C:F0:85:04:0D,Session A
47、C name: HZCNC-22-BRAS-04,Session uptime: 1w6d 19:34 ago,Dynamic Profile: pppoe,Underlying interface:xe-0/1/0.1073741844Index 3953. 根据underlying信息查询该用户所在VLANguomaitechD-05-BRAS-A-JuniperMX960.RE0> show interfaces xe-0/1/0.1073741844Logical interface xe-0/1/0.1073741844 (Index 395) (SNMP ifIndex 58
48、7)Flags: SNMP-Traps 0x4000 VLAN-Tag 0x8100.909 Encapsulation: ENET2Input packets : 6284196371Output packets: 6514168692Protocol multiservice, MTU: UnlimitedProtocol pppoeDynamic Profile: pppoe,Service Name Table: snt-vr22.Max Sessions: 32000, Max Sessions VSA Ignore: Off,Duplicate Protection: Off, S
49、hort Cycle Protection: Off,AC Name: HZCNC-22-BRAS-042.3. 如何查看当前用户会话数或者 ppp会话数guomaiJHDY-GSXY-MX960-1> show ppp statisticsSession statistics from PPP processTotal sessions: 0Sessions in disabled phase : 0Sessions in establish phase : 0Sessions in authenticate phase: 0Sessions in network phase : 0Bundles in pending phase : 0Session statistics from PPP universal edge processTotal subscriber sessions: 1Subscriber sessions in disabled phase : 0Subscriber sessions in establish phase : 0Subscriber sessions in
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 东营绿化施工方案(3篇)
- 墙纸机械施工方案(3篇)
- 供电迁移施工方案(3篇)
- 审核绿色施工方案(3篇)
- 别墅河边施工方案(3篇)
- 泡沫雕塑施工方案(3篇)
- 注塑加工数字化管理系统实施方案
- MPA备考社会保障制度测验题试卷
- 特色构架施工方案(3篇)
- 瓷瓶清洗施工方案(3篇)
- 北京市东城区2025-2026学年高三上学期期末考试地理 有答案
- 2025年健康体检中心服务流程手册
- 2026年黑龙江林业职业技术学院高职单招职业适应性测试备考题库有答案解析
- 贵金属产业2026年发展趋势与市场价格波动分析
- 现代环境监测技术
- 2026福建能源石化集团校招面笔试题及答案
- 华东理工大学2026年公开招聘工作人员46名备考题库及参考答案详解
- 云南师大附中2026届高三高考适应性月考卷(六)历史试卷(含答案及解析)
- 2025桐梓县国土空间规划城市年度体检报告成果稿
- ISO-26262功能安全培训
- 2025浙江杭州钱塘新区建设投资集团有限公司招聘5人备考笔试试题及答案解析
评论
0/150
提交评论