From 07002caeb8868fd5722e812a472ecba037557ab8 Mon Sep 17 00:00:00 2001 From: oliver Date: Wed, 29 Jul 2026 10:22:01 +0800 Subject: [PATCH] fix erro command --- .../zte/03_配置规范与基线/BGP_跨域配置规范.md | 224 ------- .../zte/03_配置规范与基线/LDP_配置基线.md | 93 --- .../06_标准SOP与工具脚本/命令探索方法论.md | 447 ++++---------- .../06_标准SOP与工具脚本/故障处理常用命令.md | 580 ++++++++++++++---- 4 files changed, 554 insertions(+), 790 deletions(-) delete mode 100644 docs/ip-knowledge-base/zte/03_配置规范与基线/BGP_跨域配置规范.md delete mode 100644 docs/ip-knowledge-base/zte/03_配置规范与基线/LDP_配置基线.md diff --git a/docs/ip-knowledge-base/zte/03_配置规范与基线/BGP_跨域配置规范.md b/docs/ip-knowledge-base/zte/03_配置规范与基线/BGP_跨域配置规范.md deleted file mode 100644 index ab6c85b0..00000000 --- a/docs/ip-knowledge-base/zte/03_配置规范与基线/BGP_跨域配置规范.md +++ /dev/null @@ -1,224 +0,0 @@ -# BGP跨域配置规范(Option-B场景) - -## 适用场景 -- 不同AS之间的MPLS VPN互联(如AS100与AS200的VPN用户互通) -- 需要端到端的MPLS标签转发,避免在ASBR上解封装再封装 - ---- -## Option-B架构说明 - -### 网络拓扑 -``` -CE1 --- PE1 --- ASBR1 ==== ASBR2 --- PE2 --- CE2 -(AS100) (AS100) (AS200) (AS200) - | | - EBGP会话 EBGP会话 - (带标签) (带标签) -``` - -**关键特征**: -- ASBR1和ASBR2之间建立EBGP会话,交换VPNv4路由(带标签) -- ASBR向IBGP邻居(PE)宣告从EBGP学到的路由 -- **核心要求**:ASBR必须配置`next-hop-self`,否则PE收到的BGP下一跳是对端ASBR的互联地址(非32位),导致LDP无法分配标签 - ---- -## 标准配置模板 - -### ASBR配置(以ASBR1为例,AS100侧) -```bash -! BGP基础配置 -router bgp 100 - neighbor 20.0.0.2 remote-as 200 ! EBGP邻居(ASBR2的互联地址) - neighbor 20.0.0.2 ebgp-multihop 2 ! 若非直连需配多跳 - neighbor 20.0.0.2 update-source loopback0 - - ! VPNv4地址族(关键!) - address-family vpnv4 - neighbor 20.0.0.2 activate ! 激活EBGP邻居 - neighbor 20.0.0.2 send-label ! 发送标签(Cisco语法,5800-4X类似) - - ! 向IBGP邻居宣告时修改下一跳(最关键的一步!) - neighbor 10.0.0.1 remote-as 100 ! IBGP邻居(PE路由器) - neighbor 10.0.0.1 next-hop-self ! ⭐ 强制将下一跳改为本机Loopback - - exit-address-family - - ! IPv4单播地址族(可选,用于底层IGP路由) - address-family ipv4 unicast - network 10.0.0.1 mask 255.255.255.255 ! 宣告Loopback - exit-address-family -``` - -### PE配置(以PE1为例,AS100侧) -```bash -router bgp 100 - ! IBGP全互联或使用路由反射器 - neighbor 10.0.0.2 remote-as 100 ! ASBR1的Loopback - neighbor 10.0.0.2 update-source loopback0 - - address-family vpnv4 - neighbor 10.0.0.2 activate - ! 不需要配next-hop-self,因为ASBR已经做了 - exit-address-family - - ! VRF配置(关联CE侧) - vrf definition VPN-A - rd 100:1 - route-target export 100:1 - route-target import 100:1 - exit-vrf-definition - - interface gei-1/1 - vrf forwarding VPN-A - ip address 192.168.1.1 255.255.255.0 - end -``` - ---- -## 关键配置检查清单 - -### ASBR必查项 -- [ ] `address-family vpnv4`下配置了EBGP邻居并`activate` -- [ ] 配置了`send-label`或等价命令(启用标签分发) -- [ ] 向IBGP邻居宣告时配置了`next-hop-self` -- [ ] ASBR的Loopback地址通过IGP宣告(确保IBGP可达) - -### PE必查项 -- [ ] IBGP邻居关系使用Loopback地址建立 -- [ ] VRF的RD和Route Target配置正确 -- [ ] 从ASBR学到的VPNv4路由的下一跳是ASBR的Loopback(32位) - ---- -## 验证步骤 - -### 第1步:检查ASBR上的BGP路由 -```bash -# 在ASBR1上执行 -show bgp vpnv4 un addr - -# 期望输出关键字段: -# From 20.0.0.2 (20.0.0.2): 下一跳=20.0.0.2(EBGP对端) -# From 10.0.0.1 (10.0.0.1): 下一跳=10.0.0.1(已改为本机Loopback) -``` - -### 第2步:检查PE上的BGP路由和标签 -```bash -# 在PE1上执行 -show bgp vpnv4 un addr - -# 期望输出: -# Next hop: 10.0.0.2(ASBR1的Loopback,32位主机路由) -# Label: 16001(明确的MPLS标签) - -show ip forwarding route vrf VPN-A - -# 期望输出: -# Interface: gei-1/2(实际出接口,不是NULL) -# Gw: 10.0.0.2(下一跳可达) -``` - -### 第3步:端到端连通性测试 -```bash -# 从CE1 ping CE2的地址 -ping vrf VPN-A source - -# 若不通,用tracerace定位断点 -traceroute vrf VPN-A -``` - ---- -## 常见故障与根因 - -### 故障1:PE上VRF路由下一跳为NULL -**现象**:`show ip forwarding route vrf`显示Interface=NULL - -**可能根因**: -1. **ASBR未配next-hop-self** → PE收到的下一跳是对端ASBR的互联地址(/30),LDP不分配标签 -2. **LDP配置了access-fec过滤** → 即使下一跳是32位,也可能被过滤掉 - -**排障流程**: -```bash -# 步骤1:查看BGP下一跳 -show bgp vpnv4 un addr | include Next - -# 步骤2:若下一跳是/30地址(如20.0.0.2/30),则ASBR肯定没配next-hop-self -# 步骤3:若下一跳是32位但仍无标签,检查LDP策略 -show running-config mpls ldp | include access-fec -``` - -**关联案例**:参见 `04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md` - ---- -### 故障2:ASBR上EBGP邻居无法建立 -**现象**:`show ip bgp summary`中EBGP邻居状态为Idle或Active - -**可能根因**: -1. TCP端口179被ACL阻断 -2. EBGP多跳未配置(若非直连) -3. MD5认证不匹配 -4. Update-source配置错误 - -**排障命令**: -```bash -show ip bgp neighbors # 查看邻居详细状态 -show access-lists | include 179 # 检查ACL是否阻断BGP -show running-config | include router bgp # 验证ebgp-multihop和update-source -``` - ---- -### 故障3:标签分配正常但业务仍不通 -**现象**:MPLS转发表有标签,但ping不通 - -**可能根因**: -1. **VRF路由泄露问题**:Route Target配置错误,导致PE没有导入对端路由 -2. **CEF转发异常**:硬件转发表未正确编程 -3. **MTU不匹配**:MPLS报文超过链路MTU被丢弃 - -**排障命令**: -```bash -# 检查VRF路由表 -show ip route vrf VPN-A - -# 检查MPLS转发统计 -show mpls forwarding-table statistics - -# 检查接口MTU -show interface | include MTU -``` - ---- -## 配置优化建议 - -### 1. 使用路由反射器简化IBGP全互联 -对于大型网络,PE之间不必全互联建IBGP: -```bash -# 指定RR(路由反射器) -router bgp 100 - neighbor 10.0.0.100 remote-as 100 # RR的Loopback - neighbor 10.0.0.100 route-reflector-client # 仅在RR上配 - -# PE侧无需特殊配置,RR会自动反射路由 -``` - -### 2. 启用BGP PIC(快速重收敛) -```bash -router bgp 100 - bgp fast-external-failover # 链路Down立即撤销路由 - neighbor fall-over bfd # 与BFD联动检测 -``` - -### 3. 限制接收的前缀数量(防攻击) -```bash -router bgp 100 - neighbor maximum-prefix 10000 90 # 最多1万条,90%时告警 -``` - ---- -**维护建议**: -- 每次新增跨域业务前,必须在实验室模拟Option-B场景验证配置 -- 定期审查ASBR的next-hop-self配置(现场变更可能误删) -- 对于重要客户VPN,部署BFD实现亚秒级故障检测 - -**关联文档**: -- `01_协议排障逻辑树/BGP/VPN跨域标签异常排查树.md` -- `02_产品平台特性/协议实现差异.md`(BGP next-hop-self行为差异) diff --git a/docs/ip-knowledge-base/zte/03_配置规范与基线/LDP_配置基线.md b/docs/ip-knowledge-base/zte/03_配置规范与基线/LDP_配置基线.md deleted file mode 100644 index 6763f59c..00000000 --- a/docs/ip-knowledge-base/zte/03_配置规范与基线/LDP_配置基线.md +++ /dev/null @@ -1,93 +0,0 @@ -# LDP配置基线 - -## 标准配置模板 - -### 基础LDP配置 -```bash -mpls ldp instance 1 - discovery hello holdtime 180 - discovery targeted-hello holdtime 180 - graceful-restart - graceful-restart timer max-recovery 600 - graceful-restart timer neighbor-liveness 300 - access-fec ip-prefix host-route-only ! 显示指定仅主机路由分配标签 - interface smartgroup1 !接口使能ldp - $ - router-id loopback1 ! 显式指定Router-ID(推荐用Loopback地址) - target-session 10.26.63.152 ! 通过 target-session 配置ldp - -``` ---- -## 关键参数推荐值 - -| 参数       | 推荐值        | 说明                 | -| -------------------| -----------------------| --------------------------------------| -| Router-ID     | Loopback0地址(32位) | 必须全网唯一且稳定          | -| 传输地址     | Loopback地址     | 避免物理接口Down导致LDP会话中断   | -| Hello间隔(链路) | 5秒          | 默认值,直连邻居发现         | -| Hello间隔(目标) | 15秒         | 用于非直连邻居(需配`neighbor`命令) | -| Keepalive间隔   | 45秒         | TCP连接保活             | -| Hold Time     | 180秒         | Hello保持时间(4倍Hello间隔)    | -| 标签分配模式   | DU(下游主动)    | 默认模式,无需配置          | -| FEC过滤策略    | 不过滤(默认)    | 除非有安全或资源限制需求       | - ---- -## 常见配置陷阱与规避 - -### ⚠️ 陷阱1:access-fec过滤导致标签缺失 -**现象**:某些非32位FEC没有分配到标签,MPLS转发出接口为NULL - -**错误配置示例**: -```bash -mpls ldp nstance 1 - access-fec ip-prefix host-route-only ! 只给32位主机路由分标签 -``` - -**问题根因**: -- 该配置强制LDP只为/32掩码的主机路由分配标签 -- 对于/30或/31的互联地址,即使LDP默认会分配标签,也会被过滤掉 -- **后果**:跨域VPN场景中,若BGP下一跳是互联地址(非32位),会导致标签缺失→流量黑洞 - -**规避方案**: -- 评估业务需求,若无特殊安全要求,**不要配置**`access-fec`过滤 -- 若必须限制标签分配范围,使用更精细的prefix-list: - ```bash - ip prefix-list ALLOW-HOST-ROUTES seq 5 permit 0.0.0.0/0 le 32 - mpls ldp - access-fec ip-prefix prefix-list ALLOW-HOST-ROUTES ! 允许所有前缀 - ``` - -**关联案例**:参见 `04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md` - ---- -## 验证命令速查 - -```bash -# 查看ldp是否存在告警 -show alarm current typeid ldp -# 查看LDP会话状态 -show mpls ldp neighbor brief instance 1 -show mpls ldp neighbor detail instance 1 -show mpls ldp neighbor detail instance 1 - -# 查看标签绑定关系 -show mpls ldp bindings 10.0.0.8 32 detail instance 1 ! 优先使用 -show mpls ldp bindings 10.0.0.8 32 instance 1 ! 优先使用 -show mpls ldp bindings instance 1 -# 查看标签转发表 -show mpls forwarding-table 10.0.0.8 32 -show mpls forwarding-table - -# 查看LDP配置 -show running-config ldp - -``` - ---- -**维护建议**: -- 每季度审查一次LDP配置基线,确保与现网实践一致 -- 新增LDP邻居前,必须在变更窗口内验证MD5认证和标签分配 -- 对于跨域Option-B场景,务必同步检查BGP next-hop-self配置 - -**关联文档**: -- `06_标准SOP与工具脚本/MPLS标签排障命令速查.md` diff --git a/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/命令探索方法论.md b/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/命令探索方法论.md index 972bdd92..809d1f55 100644 --- a/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/命令探索方法论.md +++ b/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/命令探索方法论.md @@ -1,400 +1,169 @@ -# 命令探索方法论:通过 `?` 在线帮助发现真实命令 +# 命令探索方法论:使用 `?` 在线帮助 -## 为什么需要命令探索? +## 核心价值 -在实际网络运维中,我们经常遇到以下问题: -- **文档过时**:厂商设备版本升级后命令语法变化 -- **记忆模糊**:记不清完整命令路径和参数格式 -- **设备差异**:不同厂商(ZTE/Huawei/Cisco)命令体系不同 -- **上下文依赖**:某些命令只在特定模式下可用 +在网络运维中,通过设备内置的 `?` 帮助系统逐层探索命令,比记忆命令更可靠。 -**解决方案**:使用设备内置的 `?` 在线帮助系统,像"剥洋葱"一样逐层探索。 +**适用场景**: +- 文档过时或版本不匹配 +- 记不清完整命令路径 +- 不同厂商命令差异 +- 特定模式下可用命令 --- -## 核心原则:从宽到窄,逐步细化 +## 五步探索法 -### 探索路径示例:以BGP VPNv4路由查询为例 - -#### 第一步:确定顶层命令 +### Step 1: 定方向 - 从顶层开始 ```bash MER1#show ? ``` -输出会列出所有 `show` 开头的命令类别: -``` - bgp Show BGP information - ip Show IP information - mpls Show MPLS information - isis Show IS-IS routing information - ... -``` +列出所有 `show` 开头的命令类别。 -#### 第二步:进入子命令层级 +### Step 2: 剥洋葱 - 逐层深入 ```bash -MER1#show bgp ? -``` -输出显示BGP相关的地址族: -``` - ipv4 IPv4 address family - vpnv4 VPNv4 address family - evpn Display information about all EVPN NLRIs - ... +MER1#show bgp ? # BGP相关地址族 +MER1#show bgp vpnv4 ? # VPNv4的单播/组播 +MER1#show bgp vpnv4 unicast ? # 可用的操作符和参数 ``` -#### 第三步:继续深入具体类型 -```bash -MER1#show bgp vpnv4 ? -``` -输出显示VPNv4的单播/组播分类: -``` - unicast Display information about all VPNv4 NLRIs - multicast Display information about all VPNv4 multicast NLRIs - flowspec Flow specification address family modifier - ... -``` +### Step 3: 看提示 - 理解元符号 +关键输出中的特殊标记: +- `` - 可直接回车执行(命令已完整) +- `A.B.C.D` - IPv4地址占位符 +- `X:X::X:X` - IPv6地址占位符 +- `WORD` - 任意字符串(如VRF名、邻居IP) +- `<0-32>` - 数字范围 +- `|` - 管道符,用于过滤输出 -#### 第四步:查看可用的操作符和参数 -```bash -MER1#show bgp vpnv4 unicast ? -``` -**关键输出**(这是最有价值的一步): -``` - as Autonomous system - community Show route community information - dampened-paths Show paths suppressed due to dampening - detail Display detailed information about an ip prefix - flap Show flap info - in Show route information received from all neighbors - labels Display BGP labels for prefixes - neighbor Detailed information on TCP and BGP neighbor connections - network Show route information - rd Specify route distinguisher - rd-by-vrf Specify route distinguisher by VRF name - vrf Display information for a VPN Routing/Forwarding instance - | Output modifiers (管道符,用于过滤) - > Redirect the output to a file (重定向到文件) - Carriage return (直接回车执行) -``` - -#### 第五步:选择VRF相关选项继续探索 -```bash -MER1#show bgp vpnv4 unicast vrf ? -``` -输出显示可用的VRF实例名称: -``` - 5G_MEC VPN Routing/Forwarding instance name - IP_RAN VPN Routing/Forwarding instance name - test VPN Routing/Forwarding instance name - WORD VPN Routing/Forwarding instance name (任意字符串) -``` - -#### 第六步:查看VRF下的具体操作 -```bash -MER1#show bgp vpnv4 unicast vrf test ? -``` -最终得到精确命令: -``` - detail Show route detail information - export-unicast Export VRF routes to unicast routing table - import-unicast Import unicast routes to VRF routing table - in Show route information received from all neighbors - labels Display BGP labels for prefixes - local Display local information of a BGP neighbor - neighbor Detailed information on TCP and BGP neighbor connections - policy Display information about bgp advertisements under a proposed policy - received Display information received from a BGP neighbor - route Show route information ← 这就是我们要的! - summary Summary of BGP neighbor status -``` - -#### 第七步:执行最终命令 +### Step 4: 试执行 - 验证命令 +看到 `` 提示时,说明命令已完整: ```bash MER1#show bgp vpnv4 unicast vrf test route ``` -输出完整的BGP VPNv4路由表: + +### Step 5: 记笔记 - 记录成功路径 +将验证通过的命令记录下来,形成自己的知识库。 + +--- + +## 实战案例 + +### 案例1:BGP VPNv4路由查询 +```bash +# 7层探索路径 +show bgp ? # ipv4, vpnv4, evpn... + -> show bgp vpnv4 ? # unicast, multicast... + -> show bgp vpnv4 unicast ? # neighbor, network, rd, vrf... + -> show bgp vpnv4 unicast vrf ? # VRF实例名 + -> show bgp vpnv4 unicast vrf test ? # detail, in, route... + -> show bgp vpnv4 unicast vrf test route # 执行 ``` -15:21:26 Beijing Mon Jul 20 2026 -Current AS: 100. Other AS: 64580, 64600, 64900 -Status codes: * valid, > best, i - internal, s - stale -Origin codes: i - IGP, e - EGP, ? - incomplete - Network Next Hop Metric LocPrf RtPrf Path +### 案例2:MPLS LDP邻居查询 +```bash +show mpls ldp ? # backoff, bindings, discovery, neighbor... + -> show mpls ldp neighbor ? # brief, detail, instance... + -> show mpls ldp neighbor brief instance ? # <1-65535> + -> show mpls ldp neighbor brief instance 1 # 执行 +``` +### 案例3:VRF环境下的Ping +```bash +ping ? # A.B.C.D, vrf, mpls... + -> ping vrf ? # VRF实例名 + -> ping vrf test ? # A.B.C.D, domain + -> ping vrf test 4.1.1.1 # 执行 ``` --- -## 实战案例:探索Ping和Trace命令 +## 高级技巧 -### 案例1:VRF环境下的Ping命令 - -#### 探索过程记录 +### 技巧1:组合管道符过滤 ```bash -# 第1层:ping后面可以跟什么? -MER1#ping ? - A.B.C.D Target IP address - bier Send BIER echo messages - ce Customer edge - dcn DCN VRF - domain Domain name - evpn Send EVPN echo messages - mpls Send MPLS echo messages - satellite Specify satellite ID - vpls VPLS instance - vpws Kompella VPWS - vrf VPN Routing/Forwarding instance name - -# 第2层:ping vrf后面跟什么? -MER1#ping vrf ? - 5G_MEC VRF name (1-32 characters) - 5G_OAM VRF name (1-32 characters) - IP_RAN VRF name (1-32 characters) - test VRF name (1-32 characters) - WORD VRF name (1-32 characters) - -# 第3层:ping vrf test后面跟什么? -MER1#ping vrf test ? - A.B.C.D Target IP address - domain Domain name - -# 第4层:执行完整命令 -MER1#ping vrf test 4.1.1.1 -sending 5,100-byte ICMP echo(es) to 4.1.1.1,timeout is 2 second(s). -..... -Success rate is 0 percent(0/5). +show bgp vpnv4 unicast vrf test route | include 4.1.1 +show bgp ipv4 unicast summary | begin Neighbor ``` -### 案例2:探索MPLS LDP邻居查询 - +### 技巧2:配置模式同样适用 ```bash -# 第1层:mpls ldp后面有什么? -MER1#show mpls ldp ? - backoff Show LDP session setup backoff table - bindings Show the LDP label information base (LIB) - discovery Show sources for locally generated LDP discovery hello PDUs - graceful-restart Show MPLS LDP GR - iccp Show LDP session and ICCP state information - igp Show LDP IGP synchronization status - instance Show LDP instance information - interface Show per-interface LDP forwarding information - log Show LDP log info - neighbor Show LDP neighbor information ← 目标在这里 - parameters Show LDP configuration parameters - -# 第2层:neighbor后面有什么? -MER1#show mpls ldp neighbor ? - A.B.C.D Neighbor address - brief Brief neighbor information ← 要这个简洁版 - bvi Bvi interface - detail Detailed neighbor information - graceful-restart The information of LDP graceful restart neighbor - instance The information of LDP instance ← 还可以指定实例 - -# 第3层:instance后面跟什么? -MER1#show mpls ldp neighbor brief instance ? - <1-65535> LDP instance id - -# 第4层:执行完整命令 -MER1#show mpls ldp neighbor brief instance 1 -15:20:54 Beijing Mon Jul 20 2026 -Codes: D:Direct, T:Targeted, D&T:Direct&Targeted -Total number of neigbors:0 - Operational:0 (D:0,T:0,D&T:0) (IPv4:0,IPv6:0,IPv4&IPv6:0) - Not operational:0 (D:0,T:0,D&T:0) (IPv4:0,IPv6:0,IPv4&IPv6:0) -``` - ---- - -## 高级技巧:组合使用 `?` 和其他工具 - -### 技巧1:利用 `` 提示判断命令完整性 - -当 `?` 输出中包含 `` 时,表示当前命令已经完整,可以直接执行: -```bash -MER1#show mpls ldp neighbor brief instance 1 ? - ← 看到这个,就知道可以直接回车执行了 -``` - -### 技巧2:使用管道符 `|` 过滤大量输出 - -当某个命令输出太多时,用 `?` 查看可用的过滤选项: -```bash -MER1#show bgp vpnv4 unicast vrf test route ? - | Output modifiers - -MER1#show bgp vpnv4 unicast vrf test route | ? - begin Begin with the line that matches - count Count the number of lines that match - exclude Exclude lines that match - include Include lines that match - section Print only the section that matches - -# 实际应用:只看包含特定前缀的路由 -MER1#show bgp vpnv4 unicast vrf test route | include 4.1.1 -``` - -### 技巧3:在配置模式下同样适用 - -`?` 不仅适用于特权模式(`#`),也适用于配置模式(`(config)#`): -```bash -MER1#configure terminal MER1(config)#router bgp 100 MER1(config-bgp-router)#neighbor ? - A.B.C.D Neighbor IPv4 address - X:X::X:X Neighbor IPv6 address - peer-group Name of peer group - MER1(config-bgp-router)#neighbor 10.26.63.152 ? - activate Enable the neighbor - advertisement-interval Set minimum interval between sending routing updates - allowas-in Allow AS in path - ... - next-hop-self Disable the next hop calculation for this neighbor ← 关键配置! - ... ``` -### 技巧4:识别命令缩写规则 - -通过 `?` 可以发现命令的简写形式: +### 技巧3:识别命令缩写 ```bash -MER1#sh ? - show Show running system information - -MER1#show mpls forw ? - forwarding-table Show MPLS forwarding-table information ← forw是forwarding的合法缩写 +sh ? # show的合法缩写 +forw ? # forwarding的合法缩写 +conf t # configure terminal的缩写 ``` -**规律**:只要输入的字母能唯一标识一个命令,就可以缩写。例如: -- `show` → `sh` -- `forwarding-table` → `forw` -- `configuration` → `conf` - ---- - -## 常见命令树结构对比 - -### ZTE vs Huawei vs Cisco - -| 功能 | ZTE (ZXROS) | Huawei (VRP) | Cisco (IOS) | -|------|-------------|--------------|-------------| -| 查看BGP VPNv4路由 | `show bgp vpnv4 unicast vrf route` | `display bgp vpnv4 routing-table vpn-instance ` | `show bgp vpnv4 unicast vrf ` | -| 查看MPLS转发表 | `show mpls forwarding-table` | `display mpls lsp` | `show mpls forwarding-table` | -| 查看LDP邻居 | `show mpls ldp neighbor brief instance 1` | `display mpls ldp session` | `show mpls ldp neighbor` | -| Ping VRF内地址 | `ping vrf ` | `ping -vpn-instance ` | `ping vrf ` | - -**结论**:虽然命令相似,但细节有差异。**必须针对每种设备单独探索**。 - ---- - -## 错误处理与注意事项 - -### 注意1:命令前缀限制 - -某些平台可能限制特定命令的使用: +### 技巧4:区分错误类型 ```bash -# 如果收到 "command_not_allowed_prefix" 错误 -MER1#trace vrf test 4.1.1.1 -%Error: command_not_allowed_prefix -``` -**原因**:`trace` 命令可能被netx等平台限制。此时应尝试: -- 改用完整路径 `traceroute` -- 检查权限级别 -- 使用替代命令(如通过ping逐跳测试) - -### 注意2:区分"不完整命令"和"无匹配" - -```bash -# 不完整命令(Incomplete command)- 说明方向对,继续用?探索 -MER1#show bgp vpnv4 unicast vrf test +# Incomplete command - 命令不完整,继续用?探索 %Error 140305: Incomplete command. -# 无匹配(Unrecognized command)- 说明走错路了,退回上一层 -MER1#show bgp vpnv4 unicast vrf test xyz -%Error: Unrecognized command. -``` - -### 注意3:空格敏感性 - -```bash -# 正确:每个层级之间有空格 -MER1#show mpls ldp neighbor brief instance 1 - -# 错误:连在一起会当成一个单词 -MER1#show mplsldpneighborbriefinstance1 +# Unrecognized command - 走错路了,退回上一层 %Error: Unrecognized command. ``` --- -## 练习:自主探索以下命令 +## 常见命令树深度对比 -请用 `?` 方法探索下列命令的完整语法(答案不唯一): +| 功能 | ZTE (ZXROS) | 深度 | +|------|-------------|------| +| BGP VPNv4路由 | `show bgp vpnv4 unicast vrf route` | 7层 | +| MPLS LDP邻居 | `show mpls ldp neighbor brief instance ` | 6层 | +| ISIS邻接 | `show isis adjacency` | 3层 | +| Ping VRF | `ping vrf ` | 4层 | +--- + +## 快速参考卡片 + +```bash +# 通用模板 + ? # 查看下一级 + ? # 继续深入 +... + # 执行 + +# 元符号速查 + - 直接回车执行 +WORD - 任意字符串 +A.B.C.D - IPv4地址 +X:X::X:X - IPv6地址 +<1-65535> - 数字范围 +| - 管道符(begin/include/exclude/count) +> - 重定向到文件 +``` + +--- + +## 练习任务 + +用 `?` 方法探索以下命令: 1. 查看ISIS邻接关系 2. 查看OSPF邻居详细信息 3. 查看VRF IP_RAN的路由表 4. 查看MPLS标签绑定信息 5. 查看BGP从邻居10.26.63.152收到的路由 -**参考答案**(实际以设备为准): +**参考答案**: ```bash -# 1. ISIS邻接 -MER1#show isis adjacency - -# 2. OSPF邻居详细 -MER1#show ip ospf neighbor detail - -# 3. VRF IP_RAN路由 -MER1#show ip forwarding route vrf IP_RAN - -# 4. MPLS标签绑定 -MER1#show mpls ldp bindings - -# 5. BGP从邻居收到的路由 -MER1#show bgp vpnv4 unicast vrf test received 10.26.63.152 +show isis adjacency +show ip ospf neighbor detail +show ip forwarding route vrf IP_RAN +show mpls ldp bindings +show bgp vpnv4 unicast vrf test received 10.26.63.152 ``` --- -## 总结:命令探索五步法 - -1. **定方向**:从最顶层开始(`show ?`, `ping ?`, `configure ?`) -2. **剥洋葱**:每层用 `?` 查看下一级选项,选择最相关的分支 -3. **看提示**:注意 ``、`WORD`、`A.B.C.D` 等元提示 -4. **试执行**:看到 `` 就执行,观察输出验证猜测 -5. **记笔记**:把成功的命令路径记录下来(就像本文档做的) - **终极心法**:不要怕敲错,`?` 永远不会嘲笑你。每个网络专家都是从不停地敲 `?` 开始的。 ---- - -## 附录:快速参考卡片 - -```bash -# 通用探索模板 - ? # 查看下一级选项 - ? # 继续深入 -... - # 看到就可以执行 - -# 特殊符号含义 - - 可以直接回车执行 -WORD - 任意字符串(通常是名字、ID等) -A.B.C.D - IPv4地址格式 -X:X::X:X - IPv6地址格式 -<1-65535> - 数字范围 -| - 管道符,用于过滤输出 -> - 重定向到文件 - -# 经典命令树深度 -show bgp vpnv4 unicast vrf route # 7层 -show mpls ldp neighbor brief instance # 6层 -ping vrf # 4层 -configure terminal # 2层 -``` - ---- - -**文档版本**:v1.0 -**最后更新**:2026-07-20 -**维护者**:基于真实设备(MER1)验证 +**文档版本**:v2.0(精简版) +**最后更新**:2026-07-29 diff --git a/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/故障处理常用命令.md b/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/故障处理常用命令.md index 14a15985..8fbc9b95 100644 --- a/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/故障处理常用命令.md +++ b/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/故障处理常用命令.md @@ -1,63 +1,273 @@ # 故障处理常用命令目录集(ZTE ZXROS) -> **设备**:MER1 @ 10.229.234.136 (ZXCTN 9000-3EA, V5.00.10.70) -> **更新时间**:2026-07-22 -> **验证状态**:✅ 已验证 / ❌ 错误命令(已删除) - ---- - ## 一、BGP相关命令 -### 1.1 BGP IPv4单播 +### 1.1 BGP地址族总览 + ```bash -show bgp ipv4 unicast # BGP IPv4单播路由表 -show bgp ipv4 unicast summary # BGP IPv4摘要信息 -show bgp ipv4 unicast neighbor # BGP IPv4邻居信息 -show bgp ipv4 unicast neighbor # 指定邻居的详细信息 +show bgp ? # BGP支持的地址族 + all All address families + bmp BGP Monitoring Protocol + evpn Display information about all EVPN NLRIs + ipv4 IPv4 address family + ipv6 IPv6 address family + l2vpn L2VPN address family + link-state Link-state address family + remote BGP remote prefix-sid + rpki-rtr RPKI-RTR Protocol + sr-epe Show information for egress peer engineering + srv6-epe Show information for SRv6 egress peer engineering + urpf-id-array BGP urpf-id array + vpnv4 VPNv4 address family + vpnv6 VPNv6 address family ``` -### 1.2 BGP VPNv4 +### 1.2 BGP IPv4单播 + ```bash -show bgp vpnv4 unicast # VPNv4 BGP路由表(所有VRF) +# 基本命令 +show bgp ipv4 unicast summary # BGP IPv4 邻居状态摘要信息 +show bgp ipv4 unicast neighbor # 查询特定BGP邻居的详细信息 +# 按条件查询路由 +show bgp ipv4 unicast detail A.B.C.D <0-32> # BGP IPv4路由详细信息 +show bgp ipv4 unicast network A.B.C.D # BGP IPv4路由信息 +show bgp ipv4 unicast # ipv4 bgp全量路由表信息(慎用) + +# 按来源/目的地查询 +show bgp ipv4 unicast in detail A.B.C.D <0-32> # 接收路由的详细信息 +show bgp ipv4 unicast in route # 接收路由的简要信息 +show bgp ipv4 unicast neighbor in # 从邻居接收方向获取的路由信息 +show bgp ipv4 unicast neighbor out # 向邻居发送的路由信息 + +# 策略和更新组 +show bgp ipv4 unicast update-group # 更新组信息 +``` + +### 1.3 BGP IPv6单播 + +```bash +# 基本命令 +show bgp ipv6 unicast summary # BGP IPv6摘要信息 +show bgp ipv6 unicast neighbor # 查询特定BGP邻居的详细信息 + +# 按条件查询路由 +show bgp ipv6 unicast detail X:X::X:X/<0-128> # BGP IPv6路由详细信息 +show bgp ipv6 unicast # ipv6 bgp全量路由表信息(慎用) + +# 按来源/目的地查询 +show bgp ipv6 unicast in detail X:X::X:X/<0-128> # 接收路由的详细信息 +show bgp ipv6 unicast in route # 接收路由的简要信息 +show bgp ipv6 unicast neighbor in # 从邻居接收方向获取的路由信息 +show bgp ipv6 unicast neighbor out # 向邻居发送的路由信息 + +# 策略和更新组 +show bgp ipv6 unicast update-group # 更新组信息 +``` + +### 1.4 BGP VPNv4 + +```bash +# 基本命令 show bgp vpnv4 unicast summary # VPNv4 BGP摘要 +show bgp vpnv4 unicast neighbor # VPNv4邻居信息 +show bgp vpnv4 unicast neighbor # 查询特定BGP邻居的详细信息 + +# VRF路由查询 show bgp vpnv4 unicast vrf route # 指定VRF的VPNv4路由表 -show bgp vpnv4 unicast vrf # 指定VRF的VPNv4路由(Incomplete command,需要加route) +show bgp vpnv4 unicast rd route # 通过RD查询VPNv4路由 + +# 按条件查询路由 +show bgp vpnv4 unicast detail A.B.C.D <0-32> # VPNv4路由详细信息 +show bgp vpnv4 unicast network A.B.C.D # VPNv4路由信息 +show bgp vpnv4 unicast # VPNv4全量路由表信息(慎用) + +# 按来源/目的地查询 +show bgp vpnv4 unicast in detail A.B.C.D <0-32> # 接收路由的详细信息 +show bgp vpnv4 unicast in route # 接收路由的简要信息 +show bgp vpnv4 unicast neighbor in # 从邻居接收方向获取的路由信息 +show bgp vpnv4 unicast neighbor out # 向邻居发送的路由信息 +show bgp vpnv4 unicast vrf neighbor in # vrf邻居收方向路由信息 +show bgp vpnv4 unicast vrf neighbor out # vrf邻居发方向路由信息 + +# 策略和更新组 +show bgp vpnv4 unicast update-group # 更新组信息 ``` -### 1.3 BGP配置查看 +### 1.5 BGP VPNv6 + ```bash -show running-config bgp # BGP运行配置 -show running-config router bgp # BGP进程配置 +# 基本命令 +show bgp vpnv6 unicast summary # VPNv6 BGP摘要 +show bgp vpnv6 unicast neighbor # VPNv6邻居信息 +show bgp vpnv6 unicast neighbor # 查询特定BGP邻居的详细信息 + +# VRF路由查询 +show bgp vpnv6 unicast vrf route # 指定VRF的VPNv6路由表 +show bgp vpnv6 unicast rd route # 通过RD查询VPNv6路由 + +# 按条件查询路由 +show bgp vpnv6 unicast detail X:X::X:X/<0-128> # VPNv6路由详细信息 +show bgp vpnv6 unicast network X:X::X:X # VPNv6路由信息 +show bgp vpnv6 unicast # VPNv6全量路由表信息(慎用) + +# 按来源/目的地查询 +show bgp vpnv6 unicast in detail X:X::X:X/<0-128> # 接收路由的详细信息 +show bgp vpnv6 unicast in route # 接收路由的简要信息 +show bgp vpnv6 unicast neighbor in # 从邻居接收方向获取的路由信息 +show bgp vpnv6 unicast neighbor out # 向邻居发送的路由信息 + +# 策略和更新组 +show bgp vpnv6 unicast update-group # 更新组信息 ``` -### 1.4 BGP IPv4单播详细 +### 1.6 BGP L2VPN EVPN + ```bash -show bgp ipv4 unicast neighbor # BGP IPv4邻居信息 -show bgp ipv4 unicast neighbor # 指定邻居的详细信息 -``` +# 基本命令 +show bgp l2vpn evpn summary # EVPN摘要信息 +show bgp l2vpn evpn neighbor # EVPN邻居信息 +show bgp l2vpn evpn neighbor # 查询特定BGP邻居的详细信息 +# EVPN路由类型 +show bgp l2vpn evpn ethernet-ad # Ethernet Auto-discovery路由 +show bgp l2vpn evpn ethernet-segment # Ethernet Segment路由 +show bgp l2vpn evpn mac # MAC/IP Advertisement路由 +show bgp l2vpn evpn ip-prefix neighbor in # IP Prefix路由 + +# 按条件查询路由 +show bgp l2vpn evpn detail # EVPN路由详细信息 +show bgp l2vpn evpn network # EVPN路由信息 +show bgp l2vpn evpn # EVPN全量路由表信息(慎用) + +# 按来源/目的地查询 +show bgp l2vpn evpn in detail # 接收路由的详细信息 +show bgp l2vpn evpn in route # 接收路由的简要信息 +show bgp l2vpn evpn neighbor in # 从邻居接收方向获取的路由信息 +show bgp l2vpn evpn neighbor out # 向邻居发送的路由信息 + +# 策略和更新组 +show bgp l2vpn evpn update-group # 更新组信息 +``` --- ## 二、IGP相关命令 ### 2.1 IS-IS + ```bash +# IS-IS进程和概要信息 +show isis process # IS-IS进程详细信息 +show isis process process-id # 指定进程的详细信息 + +# IS-IS邻接关系 show isis adjacency # IS-IS邻接关系 -show isis database # IS-IS链路状态数据库 +show isis adjacency summary # IS-IS邻接摘要(按进程显示) +show isis adjacency level-1 # Level-1邻接关系 +show isis adjacency level-2 # Level-2邻接关系 +show isis adjacency interface # 指定接口的邻接 +show isis adjacency log # IS-IS邻接变化日志 +show isis adjacency establish-failure log # IS-IS邻接建立失败日志 +show isis adjacency up-time level-1 # Level-1邻接保持时间 +show isis adjacency up-time level-2 # Level-2邻接保持时间 + +# IS-IS链路状态数据库 +show isis database # IS-IS链路状态数据库摘要 +show isis database detail # IS-IS数据库详细信息 +show isis database level-1 # Level-1数据库 +show isis database level-2 # Level-2数据库 +show isis database level-1 detail # Level-1数据库详细 +show isis database level-2 detail # Level-2数据库详细 +show isis database # 查看特定LSP +show isis database detail # 查看特定LSP详细信息 +show isis database log # IS-IS数据库日志 +show isis database purge statistics detail # IS-IS数据库清除统计 +show isis database verbose # IS-IS数据库详尽信息 + +# IS-IS电路(接口)信息 +show isis circuits # IS-IS电路信息 +show isis circuits summary # IS-IS电路摘要 +show isis circuits detail # IS-IS电路详细信息 +show isis circuits interface # 指定接口的电路信息 +show isis circuits no-adjacency # 没有邻接的IS-IS电路 + +# IS-IS动态主机名 show isis hostname # IS-IS动态主机名映射 -show isis circuit # IS-IS电路信息 + +# IS-IS路由信息(IPv4) +show isis ipv4 route # IS-IS IPv4路由表 +show isis ipv4 route all # IS-IS所有IPv4路由(包括不可达) +show isis ipv4 route summary # IS-IS IPv4路由汇总 +show isis ipv4 route detail # IS-IS IPv4路由详细信息 +show isis ipv4 route level-1 # Level-1 IPv4路由 +show isis ipv4 route level-2 # Level-2 IPv4路由 +show isis ipv4 route A.B.C.D # 查询特定IPv4路由 +show isis ipv4 route flex-algorithm # 灵活算法路由 +show isis ipv4 route strict-spf # 严格SPF路由 + +# IS-IS路由信息(IPv6) +show isis ipv6 route # IS-IS IPv6路由表 +show isis ipv6 route all # IS-IS所有IPv6路由(包括不可达) +show isis ipv6 route summary # IS-IS IPv6路由汇总 +show isis ipv6 route detail # IS-IS IPv6路由详细信息 +show isis ipv6 route level-1 # Level-1 IPv6路由 +show isis ipv6 route level-2 # Level-2 IPv6路由 +show isis ipv6 route X:X::X:X # 查询特定IPv6路由 +show isis ipv6 route X:X::X:X/<0-128> # 查询特定IPv6前缀 +show isis ipv6 route flex-algorithm # 灵活算法IPv6路由 +show isis ipv6 route strict-spf # 严格SPF IPv6路由 + +# IS-IS拓扑路径 +show isis topology # IS-IS拓扑路径 +show isis topology detail # IS-IS拓扑详细信息 +show isis topology level-1 # Level-1拓扑路径 +show isis topology level-2 # Level-2拓扑路径 +show isis topology # 到特定进程的拓扑路径 + +# IS-IS快速重路由 +show isis fast-reroute-topology lfa # IS-IS LFA快速重路由路径 +show isis fast-reroute-topology remote-lfa # IS-IS Remote-LFA路径 +show isis fast-reroute-topology ti-lfa # IS-IS TI-LFA路径 + +# IS-IS Segment Routing +show isis segment-routing prefix-sid-map # IS-IS SR前缀SID映射 +show isis segment-routing prefix-sid-map ipv4 # IPv4前缀SID映射 +show isis segment-routing prefix-sid-map ipv6 # IPv6前缀SID映射 +show isis segment-routing prefix-sid-map detail # SR前缀SID映射详细信息 +show isis segment-routing prefix-sid-map conflict # SR前缀SID冲突信息 + +# IS-IS MPLS流量工程 +show isis mpls traffic-eng tunnel # IS-IS MPLS TE隧道信息 + +# IS-IS BIER信息 +show isis bier topology brief sub-domain # IS-IS BIER拓扑路径 + +# IS-IS Mesh Groups +show isis mesh-groups blocked # IS-IS阻塞的mesh组 +show isis mesh-groups group # IS-IS mesh组分发信息 + +# IS-IS NSR/NSF信息 +show isis nsf # IS-IS NSF状态信息 + +# IS-IS备份路由 +show isis ipv4 backup route # IS-IS IPv4备份路由 +show isis ipv6 backup route # IS-IS IPv6备份路由 + +# IS-IS配置查看 +show running-config isis # IS-IS运行配置 +show running-config isis all # IS-IS所有配置(包含默认缺省配置) ``` -### 2.2 OSPF +### 2.2 OSPF(IPv4) + ```bash show ip ospf neighbor # OSPF邻居关系 show ip ospf interface brief # OSPF接口简要信息 show ip ospf interface # OSPF接口详细信息 show ip ospf database # OSPF链路状态数据库 -show ip ospf database router-link # OSPF Type-1 LSA(Router LSA) +show ip ospf database router # OSPF Type-1 LSA(Router LSA) show ip ospf database network # OSPF Type-2 LSA(Network LSA) show ip ospf database summary # OSPF Type-3 LSA(Summary LSA) -show ip ospf database asbr # OSPF Type-4 LSA(ASBR Summary LSA) +show ip ospf database asbr-summary # OSPF Type-4 LSA(ASBR Summary LSA) show ip ospf database external # OSPF Type-5 LSA(External LSA) show ip ospf database nssa # OSPF Type-7 LSA(NSSA External LSA) show ip ospf database self-originate # OSPF自生成的LSA @@ -65,53 +275,136 @@ show ip ospf border-routers # OSPF边界路由器信息 show ip ospf virtual-links # OSPF虚链路信息 show ip ospf # OSPF进程概要信息 show ip ospf route # OSPF路由表(按进程显示) + +show running-config ospfv2 # OSPFv2运行配置 ``` +### 2.3 OSPFv3(IPv6) + +```bash +# OSPFv3进程概要 +show ipv6 ospf # 所有OSPFv3进程概要信息 +show ipv6 ospf <1-16777215> # 指定进程的详细信息(如:show ipv6 ospf 100) + +# OSPFv3邻居 +show ipv6 ospf neighbor # OSPFv3邻居列表 +show ipv6 ospf neighbor detail # OSPFv3邻居详细信息 +show ipv6 ospf neighbor summary # OSPFv3邻居摘要 +show ipv6 ospf neighbor log # OSPFv3邻居日志 +show ipv6 ospf neighbor A.B.C.D # 指定邻居ID的详细信息 + +# OSPFv3接口 +show ipv6 ospf interface # OSPFv3接口状态和配置 +show ipv6 ospf interface # 指定类型接口的OSPFv3信息 + bvi BVI接口 + flexe_channel FlexE通道接口 + gre_tunnel GRE隧道接口 + irb IRB接口 + lgei- 万兆以太网接口 + loopback Loopback接口 + smartgroup Smartgroup接口 + vlan VLAN接口 + vei VEI接口 + ... + +# OSPFv3数据库 +show ipv6 ospf database # OSPFv3数据库摘要 +show ipv6 ospf database router # Router-LSA(Type-1) +show ipv6 ospf database network # Network-LSA(Type-2) +show ipv6 ospf database inter-prefix # Inter-Prefix-LSA(Type-3) +show ipv6 ospf database inter-router # Inter-Router-LSA(Type-4) +show ipv6 ospf database intra-prefix # Intra-Prefix-LSA(Type-9) +show ipv6 ospf database link # Link-LSA(Type-8) +show ipv6 ospf database external # AS-external-LSA(Type-5/Type-7) +show ipv6 ospf database nssa # NSSA Type-7 LSA +show ipv6 ospf database intra-te # Intra-Area-TE-LSA +show ipv6 ospf database router-info # Router-Information-Opaque-LSA +show ipv6 ospf database srv6-locator # SRv6-Locator-LSA +show ipv6 ospf database extended # 扩展LSA类型 + external Extended-AS-External-LSA + inter-prefix Extended-Inter-Area-Prefix-LSA + intra-prefix Extended-Intra-Area-Prefix-LSA + router Extended-Router-LSA + +# OSPFv3数据库高级选项 +show ipv6 ospf database adv-router # 查看特定通告路由器的LSA +show ipv6 ospf database process # 查看指定进程的LSA + +# OSPFv3路由 +show ipv6 ospf route # OSPFv3路由表 +show ipv6 ospf route detail # OSPFv3路由详细信息 +show ipv6 ospf route summary # OSPFv3路由汇总统计 +show ipv6 ospf route adv-router # 查看特定通告路由器的路由 +show ipv6 ospf route network # 查看特定网络的路由 + +# OSPFv3虚链路 +show ipv6 ospf virtual-links # OSPFv3虚链路信息 +show ipv6 ospf virtual-links process # 指定进程的虚链路 + +# OSPFv3顶点信息 +show ipv6 ospf vertex # OSPFv3顶点信息 +show ipv6 ospf vertex backup # 备份顶点信息 +show ipv6 ospf vertex log # 顶点日志 +show ipv6 ospf vertex process # 指定进程的顶点信息 + +# OSPFv3统计 +show ipv6 ospf statistics interface # OSPFv3接口统计信息 + +# OSPFv3配置查看 +show running-config ospfv3 # OSPFv3运行配置 +``` --- ## 三、MPLS/LDP相关命令 -### 3.1 MPLS转发 -```bash -show mpls forwarding-table # MPLS标签转发表 -show mpls forwarding-table # 特定下一跳的标签转发表 -``` +### 3.1 MPLS -### 3.2 LDP会话和绑定 ```bash +#MPLS转发 +show mpls forwarding-table # MPLS标签转发表 +show mpls forwarding-table # Destination IPv4/IPv6 prefix标签转发表 + +#LDP会话和绑定 show mpls ldp neighbor brief instance # LDP邻居简要信息(必须指定instance!) show mpls ldp neighbor instance # LDP邻居详细信息 show mpls ldp parameters instance # LDP参数配置 show mpls ldp binding instance # LDP标签绑定信息(全局) show mpls ldp discovery instance # LDP发现信息 -``` -### 3.3 LDP配置 -```bash +# LDP配置 show running-config ldp # LDP运行配置 ``` --- -## 四、VRF相关命令 +## 四、ping/trace相关命令 -### 4.1 VRF路由 -```bash -show ip forwarding route vrf # VRF路由表 -show ip route vpn # 查看所有VPN路由 -``` +### 4.1 业务测试 -### 4.2 VRF业务测试 ```bash +ping # Ping全局地址 +ping source # 指定本地源ip Ping全局地址 +ping6 # Ping v6地址 +ping6 source # 指定本地源ipv6 Ping v6地址 ping vrf # Ping测VRF内地址 +ping vrf source # 指定本地源ip Ping测VRF内地址 +ping6 vrf # Ping测VRF ipc6内地址 +ping6 vrf source #指定本地源ipv6 Ping测VRF ipc6内地址 +trace # trace 路径 +trace source # 指定本地源ip trace 路径 +trace vrf # trace vrf内ip路径 +trace vrf source # 指定本地源ip trace vrf内ip路径 +trace6 vrf # trace vrf内ipv6路径 +trace6 vrf source # 指定本地源ipv6 trace vrf内ipv6路径 ``` - --- ## 五、隧道相关命令 ```bash -# 暂无已验证的隧道查询命令 +show mpls traffic-eng tunnels brief # 查看 +show mpls traffic-eng tunnels te_tunnel # 查看本端设备te隧道详细情况 +show mpls traffic-eng interface brief # TE接口的状态 ``` --- @@ -119,19 +412,38 @@ ping vrf # Ping测VRF内地址 ## 六、接口和路由基础命令 ### 6.1 接口状态 + ```bash show interface brief # 接口简要信息 show ip interface brief # IP接口简要信息 +show intf-statistics utilization # 接口利用率 +show intf-statistics utilization phy-interface-only # 仅查看物理口利用率 +show interface description # 查看端口状态以及描述(可通过描述判断业务、互联设备信息) +show opticalinfo brief # 查看端口收发情况 +show opticalinfo # 查看物理口收发光信息 +show interface # 查看接口详细信息 ``` ### 6.2 全局路由 + ```bash -show ip forwarding route # 全局IPv4路由表 +show ip forwarding route # 全局全量IPv4路由表(慎用) +show ip forwarding route # 查询某ip路由表(优先) +show ip forwarding route vrf # 查询某vrf IPv4路由表(慎用) +show ip forwarding route vrf # 查询某vrf 某ip IPv4路由表(优先) +show ipv6 forwarding route # 全局全量IPv6路由表(慎用) +show ipv6 forwarding route # 全局某IPv6路由表(优先) +show ipv6 forwarding route vrf # 查询某vrf IPv6路由表(慎用) +show ipv6 forwarding route vrf # 查询某vrf 某ip IPv6路由表(优先) ``` -### 6.3 ARP/MAC +### 6.3 ND/ARP/MAC + ```bash -show arp # ARP表 +show arp # 全局ARP表 +show arp vrf # vrf arp表信息 +show nd6 cache # 全量nd信息 +show nd6 cache # 某接口nd信息 ``` --- @@ -139,109 +451,109 @@ show arp # ARP表 ## 七、系统基础命令 ### 7.1 系统信息 + ```bash show version # 版本信息 -show running-config # 当前运行配置 +show card-state brief # 单板状态 +show fan # 风扇信息 +show power # 电源信息 +show temperature environment-threshold # 温度信息 +``` + +### 7.2 配置信息 + +```bash +show running-config # 当前运行配置 范围太广尽量少用或不用,优先使用单模块查找 +show running-config # 通过模块查询具体配置,可以通过`show running-config ?`查看有什么模块 +show running-config-interface # 查看某端口具体配置 +``` + +### 7.3 告警信息 + +```bash +show alarm current brief # 当前告警信息 +show alarm current typeid # 通过模块查询当前告警,可以通过`show alarm current typeid ?`查看有什么模块 +show alarm history # 查看历史告警(主要用于回溯) +show alarm history typeid # 通过模块查询历史告警,可以通过`show alarm history typeid ?`查看有什么模块 +``` + +### 7.4 lldp邻居信息 + +```bash +show lldp neighbor brief | one-line # 查看lldp邻居信息 +show lldp neighbor interface # 查看接口lldp邻居信息 ``` --- -## 八、快速排障组合 +## 八、命令语法说明 -### 8.1 BGP跨域故障(已验证组合) -```bash -# 第零层:业务测试 -ping vrf test 4.1.1.1 # 1. Ping测业务连通性 +### 8.1 重要注意事项 -# 第一层:VRF路由检查 -show ip forwarding route vrf test # 2. 检查VRF路由表 - -# 第二层:MPLS标签检查 -show mpls forwarding-table # 3. 检查MPLS标签转发表 -show mpls forwarding-table # 4. 检查特定目的地的标签 - -# 第三层:LDP会话检查 -show mpls ldp neighbor brief instance 1 # 5. 检查LDP邻居状态 -show mpls ldp neighbor instance 1 # 6. 检查LDP邻居详细信息 -show mpls ldp binding instance 1 # 7. 检查LDP标签绑定 -show mpls ldp parameters instance 1 # 8. 检查LDP参数配置 -show mpls ldp discovery instance 1 # 9. 检查LDP发现信息 - -# 第四层:BGP路由检查 -show bgp vpnv4 unicast vrf test route # 10. 检查BGP VPNv4路由 -show bgp vpnv4 unicast summary # 11. 检查BGP VPNv4摘要 -show bgp ipv4 unicast summary # 12. 检查BGP IPv4摘要 -show bgp ipv4 unicast neighbor # 13. 检查BGP IPv4邻居 - -# 第五层:IGP邻接检查 -show ip ospf neighbor # 14. 检查OSPF邻居 -show isis adjacency # 15. 检查IS-IS邻接 -show ip ospf interface brief # 16. 检查OSPF接口状态 -show isis database # 17. 检查IS-IS数据库 -show isis circuit # 18. 检查IS-IS电路 - -# 第六层:基础路由检查 -show ip forwarding route # 19. 检查全局路由表 -show ip interface brief # 20. 检查IP接口状态 -show arp # 21. 检查ARP表 -``` - -### 8.2 OSPF详细排障 -```bash -show ip ospf # OSPF进程总览 -show ip ospf interface # OSPF接口详细信息 -show ip ospf database # OSPF LSDB -show ip ospf database router-link # OSPF Type-1 LSA(Router LSA) -show ip ospf database network # OSPF Type-2 LSA(Network LSA) -show ip ospf database summary # OSPF Type-3 LSA(Summary LSA) -show ip ospf database asbr # OSPF Type-4 LSA(ASBR Summary LSA) -show ip ospf database external # OSPF Type-5 LSA(External LSA) -show ip ospf database nssa # OSPF Type-7 LSA(NSSA External LSA) -show ip ospf database self-originate # OSPF自生成LSA -show ip ospf border-routers # OSPF边界路由器 -show ip ospf virtual-links # OSPF虚链路 -show ip ospf route # OSPF路由表(按进程显示) -``` - -### 8.3 IS-IS详细排障 -```bash -show isis adjacency # IS-IS邻接 -show isis database # IS-IS LSDB -show isis hostname # IS-IS动态主机名映射 -show isis circuit # IS-IS电路信息 -``` - -### 8.4 LDP详细排障 -```bash -show mpls ldp neighbor brief instance # LDP邻居简要信息 -show mpls ldp neighbor instance # LDP邻居详细信息 -show mpls ldp parameters instance # LDP参数配置 -show mpls ldp binding instance # LDP标签绑定 -show mpls ldp discovery instance # LDP发现信息 -``` - ---- - -## 九、命令语法说明 - -### 9.1 重要注意事项 1. **LDP命令必须指定instance**:`show mpls ldp neighbor brief instance ` ✅ + - `show mpls ldp neighbor brief` ❌ Incomplete command - 2. **BGP VPNv4路由查询**:`show bgp vpnv4 unicast vrf route` ✅ + - `show bgp vpnv4 unicast rd-by-vrf ` ❌ Incomplete command - `show bgp ipv4 unicast route` ❌ Ambiguous command - 3. **VRF路由查询**:`show ip forwarding route vrf ` ✅ + - `show ip route vrf ` ❌ Invalid input - `show ipv4 route vrf ` ❌ Invalid input +4. **OSPFv3命令特点**: -### 9.2 特殊字符限制 -netx平台限制了管道符等特殊字符的使用,建议分步执行命令。 + - OSPFv3使用`show ipv6 ospf`前缀,而不是`show ip ospf` + - OSPFv3数据库LSA类型与OSPFv2不同:Type-1/2/3/4/5对应router/network/inter-prefix/inter-router/external + - OSPFv3新增Type-7(Link-LSA)、Type-8(Intra-Prefix-LSA)等IPv6特有LSA + - OSPFv3支持SRv6 Locator LSA(`show ipv6 ospf database srv6-locator`) + - OSPFv3请求列表和重传列表需要指定邻居或接口参数 +5. **IS-IS命令特点**: ---- + - IS-IS支持多进程:设备上有多个IS-IS进程实例(如进程0、1、5、44、101等) + - Level分离:大多数命令支持`level-1`和`level-2`选项,分别查看L1/L2信息 + - IPv4/IPv6分离:路由查询使用`show isis ipv4 route`和`show isis ipv6 route` + - LSP标识符格式:`system-id.xx-xx*`(如MER1.00-00*) + - 灵活算法支持:`flex-algorithm`参数用于查看特定算法的路由 + - Segment Routing集成:通过`show isis segment-routing prefix-sid-map`查看SR映射 + - 快速重路由:支持LFA、Remote-LFA、TI-LFA三种保护方式 +6. **BGP命令特点**: -**文档维护**: -- 最后更新:2026-07-22 -- 验证设备:MER1 @ 10.229.234.136 -- 关联文档:`命令探索方法论.md`、`BGP跨域排障命令速查.md` + - BGP支持多种地址族:IPv4/IPv6单播、VPNv4/VPNv6、EVPN、Link-State等 + - BGP IPv4/IPv6命令结构相似,都支持summary、neighbor、detail、community等子命令 + - BGP VPNv4/VPNv6需要通过`vrf `或`rd `来指定VRF + - EVPN支持多种NLRI类型:ethernet-ad、mac、ip-prefix、inclusive-multicast等 + - Link-State按protocol和type分类,可以查看ISIS/OSPF/BGP等协议的链路状态信息 + - BMP用于监控BGP会话和路由,支持monitor-peer和monitor-route + - SR-EPE和SRv6-EPE用于出向peer工程,支持按AS查询 + - RPKI-RTR提供路由源验证功能,支持valid/invalid/not-found状态查询 + +### 8.2 参数占位符说明 + +文档中使用以下占位符表示需要替换的参数: + +- `` - IPv4地址,如`192.168.1.1` +- `` - IPv6地址,如`2001:db8::1` +- `` - AS号码,如`65001` +- `` - VRF名称,如`vpn1` +- `` - RD值,如`65001:100` +- `` - 接口名称,如`gei_1/1`或`loopback1` +- `` - 进程ID,如`isis 100`中的`100` +- `` - LSP标识符,如`MER1.00-00*` +- `` - IS-IS系统ID,如`1` +- `` - 正则表达式,用于匹配AS路径 +- `` - BGP团体号,如`65001:100` +- `` - 路由图名称 +- `` - 更新组索引号 +- `` - 名称标识符 +- `` - 网络前缀 +- `` - MAC地址,如`00:11:22:33:44:55` +- `` - 索引值 +- `` - 邻居IP地址 +- `` - 灵活算法ID + +### 8.3 特殊限制 + +netx平台对命令数量有限制,可以多次采集 + +--- \ No newline at end of file