我目前正在处理一个让我感到困惑的问题......我有一个网络 172.16.144.0/20,它通过 Cisco 3850 外部交换机连接到我们的 fortigate 300D 防火墙。由于硬件限制,正在使用的端口具有 100mbps SFP,其余端口使用 1gbps。
问题是我可以从交换机 ping 到我的所有设备,但我无法 ping 防火墙,也无法从防火墙 ping 交换机。使用与交换机相同的 IP 和防火墙端口,我使用笔记本电脑并能够 ping 防火墙。
我假设 SFP 是罪魁祸首,但不确定如何...
Current configuration : 17202 bytes
!
! Last configuration change at 20:16:42 UTC Fri Mar 1 2019
!
version 15.2
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service compress-config
no service dhcp
service unsupported-transceiver
!
hostname SW
!
boot-start-marker
boot-end-marker
!
!
vrf definition Mgmt-vrf
--More--
address-family ipv4
exit-address-family
!
address-family ipv6
exit-address-family
!
logging console critical
logging monitor critical
!
!
aaa session-id common
switch 1 provision ws-c3850-12s
!
!
no ip source-route
no ip gratuitous-arps
ip icmp rate-limit unreachable 1000
!
ip domain-name
ip name-server 172.16.201.101
!
!
qos queue-softmax-multiplier 100
vtp domain
vtp mode transparent
udld aggressive
!
!
errdisable recovery cause udld
errdisable recovery cause bpduguard
errdisable recovery cause security-violation
errdisable recovery cause channel-misconfig
errdisable recovery cause pagp-flap
errdisable recovery cause dtp-flap
errdisable recovery cause link-flap
errdisable recovery cause sfp-config-mismatch
errdisable recovery cause gbic-invalid
errdisable recovery cause psecure-violation
errdisable recovery cause port-mode-failure
errdisable recovery cause dhcp-rate-limit
errdisable recovery cause mac-limit
errdisable recovery cause vmps
errdisable recovery cause storm-control
errdisable recovery cause inline-power
errdisable recovery cause loopback
diagnostic bootup level minimal
!
spanning-tree mode rapid-pvst
spanning-tree loopguard default
spanning-tree portfast default
spanning-tree portfast bpduguard default
spanning-tree extend system-id
spanning-tree vlan 32,101,172,201 priority 4096
hw-switch switch 1 logging onboard message level 3
!
redundancy
mode sso
!
vlan 3
!
vlan 5
!
vlan 6
!
vlan 2
!
Vlan 8
!
vlan 11
!
vlan 12
!
vlan 5
!
vlan 21
name UNUSED
no cdp run
!
ip tcp synwait-time 10
ip ssh time-out 30
ip ssh version 2
!
!
!
!
interface Null0
no ip unreachables
!
interface GigabitEthernet0/0
vrf forwarding Mgmt-vrf
no ip address
shutdown
negotiation auto
!
interface GigabitEthernet1/0/1
description spare
switchport access vlan 8
switchport mode access
no logging event link-status
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
!
interface GigabitEthernet1/0/2
switchport access vlan 8
switchport mode access
no logging event link-status
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
interface GigabitEthernet1/0/3
switchport access vlan 8
switchport mode access
no logging event link-status
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
!
interface GigabitEthernet1/0/4
switchport access vlan 8
switchport mode access
no logging event link-status
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
!
interface GigabitEthernet1/0/5
switchport access vlan 8
switchport mode access
no logging event link-status
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
!
interface GigabitEthernet1/0/6
switchport access vlan 8
switchport mode access
no logging event link-status
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
!
interface GigabitEthernet1/0/7
switchport access vlan 8
switchport mode access
no logging event link-status
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
!
interface GigabitEthernet1/0/8
switchport access vlan 8
switchport mode access
no logging event link-status
speed 100
duplex full
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
!
interface GigabitEthernet1/0/9
switchport access vlan 8
switchport mode access
no logging event link-status
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
!
interface GigabitEthernet1/0/10
switchport access vlan 8
switchport mode access
no logging event link-status
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
!
interface GigabitEthernet1/0/11
switchport access vlan 8
switchport mode access
no logging event link-status
speed 100
duplex full
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
spanning-tree portfast
!
interface GigabitEthernet1/0/12
switchport trunk native vlan 55
switchport trunk allowed vlan 8
switchport mode trunk
switchport nonegotiate
no logging event link-status
duplex full
storm-control broadcast level 50.00 20.00
storm-control multicast level 5.00 2.00
!
!
interface Vlan1
no ip address
no ip route-cache
shutdown
!
interface Vlan8
ip address 172.16.150.200 255.255.240.0
!
interface Vlan3
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
no ip route-cache
!
ip default-gateway 172.16.201.27
ip forward-protocol nd
no ip http server
no ip http secure-server
!
ip access-list extended ALL_IP_TRAFFIC
permit ip any any
!
!