fix erro command

This commit is contained in:
oliver 2026-07-29 10:22:01 +08:00
parent 557b675fe8
commit 07002caeb8
4 changed files with 554 additions and 790 deletions

View file

@ -1,224 +0,0 @@
# BGP跨域配置规范(Option-B场景)
## 适用场景
- 不同AS之间的MPLS VPN互联(如AS100与AS200的VPN用户互通)
- 需要端到端的MPLS标签转发,避免在ASBR上解封装再封装
---
## Option-B架构说明
### 网络拓扑
```
CE1 --- PE1 --- ASBR1 ==== ASBR2 --- PE2 --- CE2
(AS100) (AS100) (AS200) (AS200)
| |
EBGP会话 EBGP会话
(带标签) (带标签)
```
**关键特征**:
- ASBR1和ASBR2之间建立EBGP会话,交换VPNv4路由(带标签)
- ASBR向IBGP邻居(PE)宣告从EBGP学到的路由
- **核心要求**:ASBR必须配置`next-hop-self`,否则PE收到的BGP下一跳是对端ASBR的互联地址(非32位),导致LDP无法分配标签
---
## 标准配置模板
### ASBR配置(以ASBR1为例,AS100侧)
```bash
! BGP基础配置
router bgp 100
neighbor 20.0.0.2 remote-as 200 ! EBGP邻居(ASBR2的互联地址)
neighbor 20.0.0.2 ebgp-multihop 2 ! 若非直连需配多跳
neighbor 20.0.0.2 update-source loopback0
! VPNv4地址族(关键!)
address-family vpnv4
neighbor 20.0.0.2 activate ! 激活EBGP邻居
neighbor 20.0.0.2 send-label ! 发送标签(Cisco语法,5800-4X类似)
! 向IBGP邻居宣告时修改下一跳(最关键的一步!)
neighbor 10.0.0.1 remote-as 100 ! IBGP邻居(PE路由器)
neighbor 10.0.0.1 next-hop-self ! ⭐ 强制将下一跳改为本机Loopback
exit-address-family
! IPv4单播地址族(可选,用于底层IGP路由)
address-family ipv4 unicast
network 10.0.0.1 mask 255.255.255.255 ! 宣告Loopback
exit-address-family
```
### PE配置(以PE1为例,AS100侧)
```bash
router bgp 100
! IBGP全互联或使用路由反射器
neighbor 10.0.0.2 remote-as 100 ! ASBR1的Loopback
neighbor 10.0.0.2 update-source loopback0
address-family vpnv4
neighbor 10.0.0.2 activate
! 不需要配next-hop-self,因为ASBR已经做了
exit-address-family
! VRF配置(关联CE侧)
vrf definition VPN-A
rd 100:1
route-target export 100:1
route-target import 100:1
exit-vrf-definition
interface gei-1/1
vrf forwarding VPN-A
ip address 192.168.1.1 255.255.255.0
end
```
---
## 关键配置检查清单
### ASBR必查项
- [ ] `address-family vpnv4`下配置了EBGP邻居并`activate`
- [ ] 配置了`send-label`或等价命令(启用标签分发)
- [ ] 向IBGP邻居宣告时配置了`next-hop-self`
- [ ] ASBR的Loopback地址通过IGP宣告(确保IBGP可达)
### PE必查项
- [ ] IBGP邻居关系使用Loopback地址建立
- [ ] VRF的RD和Route Target配置正确
- [ ] 从ASBR学到的VPNv4路由的下一跳是ASBR的Loopback(32位)
---
## 验证步骤
### 第1步:检查ASBR上的BGP路由
```bash
# 在ASBR1上执行
show bgp vpnv4 un addr <dest-prefix>
# 期望输出关键字段:
# From 20.0.0.2 (20.0.0.2): 下一跳=20.0.0.2(EBGP对端)
# From 10.0.0.1 (10.0.0.1): 下一跳=10.0.0.1(已改为本机Loopback)
```
### 第2步:检查PE上的BGP路由和标签
```bash
# 在PE1上执行
show bgp vpnv4 un addr <dest-prefix>
# 期望输出:
# Next hop: 10.0.0.2(ASBR1的Loopback,32位主机路由)
# Label: 16001(明确的MPLS标签)
show ip forwarding route vrf VPN-A <dest-prefix>
# 期望输出:
# Interface: gei-1/2(实际出接口,不是NULL)
# Gw: 10.0.0.2(下一跳可达)
```
### 第3步:端到端连通性测试
```bash
# 从CE1 ping CE2的地址
ping vrf VPN-A <CE2-IP> source <CE1-IP>
# 若不通,用tracerace定位断点
traceroute vrf VPN-A <CE2-IP>
```
---
## 常见故障与根因
### 故障1:PE上VRF路由下一跳为NULL
**现象**:`show ip forwarding route vrf`显示Interface=NULL
**可能根因**:
1. **ASBR未配next-hop-self** → PE收到的下一跳是对端ASBR的互联地址(/30),LDP不分配标签
2. **LDP配置了access-fec过滤** → 即使下一跳是32位,也可能被过滤掉
**排障流程**:
```bash
# 步骤1:查看BGP下一跳
show bgp vpnv4 un addr <prefix> | include Next
# 步骤2:若下一跳是/30地址(如20.0.0.2/30),则ASBR肯定没配next-hop-self
# 步骤3:若下一跳是32位但仍无标签,检查LDP策略
show running-config mpls ldp | include access-fec
```
**关联案例**:参见 `04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md`
---
### 故障2:ASBR上EBGP邻居无法建立
**现象**:`show ip bgp summary`中EBGP邻居状态为Idle或Active
**可能根因**:
1. TCP端口179被ACL阻断
2. EBGP多跳未配置(若非直连)
3. MD5认证不匹配
4. Update-source配置错误
**排障命令**:
```bash
show ip bgp neighbors <ip> # 查看邻居详细状态
show access-lists | include 179 # 检查ACL是否阻断BGP
show running-config | include router bgp # 验证ebgp-multihop和update-source
```
---
### 故障3:标签分配正常但业务仍不通
**现象**:MPLS转发表有标签,但ping不通
**可能根因**:
1. **VRF路由泄露问题**:Route Target配置错误,导致PE没有导入对端路由
2. **CEF转发异常**:硬件转发表未正确编程
3. **MTU不匹配**:MPLS报文超过链路MTU被丢弃
**排障命令**:
```bash
# 检查VRF路由表
show ip route vrf VPN-A
# 检查MPLS转发统计
show mpls forwarding-table statistics
# 检查接口MTU
show interface <interface> | include MTU
```
---
## 配置优化建议
### 1. 使用路由反射器简化IBGP全互联
对于大型网络,PE之间不必全互联建IBGP:
```bash
# 指定RR(路由反射器)
router bgp 100
neighbor 10.0.0.100 remote-as 100 # RR的Loopback
neighbor 10.0.0.100 route-reflector-client # 仅在RR上配
# PE侧无需特殊配置,RR会自动反射路由
```
### 2. 启用BGP PIC(快速重收敛)
```bash
router bgp 100
bgp fast-external-failover # 链路Down立即撤销路由
neighbor <ip> fall-over bfd # 与BFD联动检测
```
### 3. 限制接收的前缀数量(防攻击)
```bash
router bgp 100
neighbor <ip> maximum-prefix 10000 90 # 最多1万条,90%时告警
```
---
**维护建议**:
- 每次新增跨域业务前,必须在实验室模拟Option-B场景验证配置
- 定期审查ASBR的next-hop-self配置(现场变更可能误删)
- 对于重要客户VPN,部署BFD实现亚秒级故障检测
**关联文档**:
- `01_协议排障逻辑树/BGP/VPN跨域标签异常排查树.md`
- `02_产品平台特性/协议实现差异.md`(BGP next-hop-self行为差异)

View file

@ -1,93 +0,0 @@
# LDP配置基线
## 标准配置模板
### 基础LDP配置
```bash
mpls ldp instance 1
discovery hello holdtime 180
discovery targeted-hello holdtime 180
graceful-restart
graceful-restart timer max-recovery 600
graceful-restart timer neighbor-liveness 300
access-fec ip-prefix host-route-only ! 显示指定仅主机路由分配标签
interface smartgroup1 !接口使能ldp
$
router-id loopback1 ! 显式指定Router-ID(推荐用Loopback地址)
target-session 10.26.63.152 ! 通过 target-session 配置ldp
```
---
## 关键参数推荐值
| 参数       | 推荐值        | 说明                 |
| -------------------| -----------------------| --------------------------------------|
| Router-ID     | Loopback0地址(32位) | 必须全网唯一且稳定          |
| 传输地址     | Loopback地址     | 避免物理接口Down导致LDP会话中断   |
| Hello间隔(链路) | 5秒          | 默认值,直连邻居发现         |
| Hello间隔(目标) | 15秒         | 用于非直连邻居(需配`neighbor`命令) |
| Keepalive间隔   | 45秒         | TCP连接保活             |
| Hold Time     | 180秒         | Hello保持时间(4倍Hello间隔)    |
| 标签分配模式   | DU(下游主动)    | 默认模式,无需配置          |
| FEC过滤策略    | 不过滤(默认)    | 除非有安全或资源限制需求       |
---
## 常见配置陷阱与规避
### ⚠️ 陷阱1:access-fec过滤导致标签缺失
**现象**:某些非32位FEC没有分配到标签,MPLS转发出接口为NULL
**错误配置示例**:
```bash
mpls ldp nstance 1
access-fec ip-prefix host-route-only ! 只给32位主机路由分标签
```
**问题根因**:
- 该配置强制LDP只为/32掩码的主机路由分配标签
- 对于/30或/31的互联地址,即使LDP默认会分配标签,也会被过滤掉
- **后果**:跨域VPN场景中,若BGP下一跳是互联地址(非32位),会导致标签缺失→流量黑洞
**规避方案**:
- 评估业务需求,若无特殊安全要求,**不要配置**`access-fec`过滤
- 若必须限制标签分配范围,使用更精细的prefix-list:
```bash
ip prefix-list ALLOW-HOST-ROUTES seq 5 permit 0.0.0.0/0 le 32
mpls ldp
access-fec ip-prefix prefix-list ALLOW-HOST-ROUTES ! 允许所有前缀
```
**关联案例**:参见 `04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md`
---
## 验证命令速查
```bash
# 查看ldp是否存在告警
show alarm current typeid ldp
# 查看LDP会话状态
show mpls ldp neighbor brief instance 1
show mpls ldp neighbor <ldp-neighbor> detail instance 1
show mpls ldp neighbor detail instance 1
# 查看标签绑定关系
show mpls ldp bindings 10.0.0.8 32 detail instance 1 ! 优先使用
show mpls ldp bindings 10.0.0.8 32 instance 1 ! 优先使用
show mpls ldp bindings instance 1
# 查看标签转发表
show mpls forwarding-table 10.0.0.8 32
show mpls forwarding-table
# 查看LDP配置
show running-config ldp
```
---
**维护建议**:
- 每季度审查一次LDP配置基线,确保与现网实践一致
- 新增LDP邻居前,必须在变更窗口内验证MD5认证和标签分配
- 对于跨域Option-B场景,务必同步检查BGP next-hop-self配置
**关联文档**:
- `06_标准SOP与工具脚本/MPLS标签排障命令速查.md`

View file

@ -1,400 +1,169 @@
# 命令探索方法论:通过 `?` 在线帮助发现真实命令
# 命令探索方法论:使用 `?` 在线帮助
## 为什么需要命令探索?
## 核心价值
在实际网络运维中,我们经常遇到以下问题:
- **文档过时**:厂商设备版本升级后命令语法变化
- **记忆模糊**:记不清完整命令路径和参数格式
- **设备差异**:不同厂商(ZTE/Huawei/Cisco)命令体系不同
- **上下文依赖**:某些命令只在特定模式下可用
在网络运维中,通过设备内置的 `?` 帮助系统逐层探索命令,比记忆命令更可靠。
**解决方案**:使用设备内置的 `?` 在线帮助系统,像"剥洋葱"一样逐层探索。
**适用场景**:
- 文档过时或版本不匹配
- 记不清完整命令路径
- 不同厂商命令差异
- 特定模式下可用命令
---
## 核心原则:从宽到窄,逐步细化
## 五步探索法
### 探索路径示例:以BGP VPNv4路由查询为例
#### 第一步:确定顶层命令
### Step 1: 定方向 - 从顶层开始
```bash
MER1#show ?
```
输出会列出所有 `show` 开头的命令类别:
```
bgp Show BGP information
ip Show IP information
mpls Show MPLS information
isis Show IS-IS routing information
...
```
列出所有 `show` 开头的命令类别。
#### 第二步:进入子命令层级
### Step 2: 剥洋葱 - 逐层深入
```bash
MER1#show bgp ?
```
输出显示BGP相关的地址族:
```
ipv4 IPv4 address family
vpnv4 VPNv4 address family
evpn Display information about all EVPN NLRIs
...
MER1#show bgp ? # BGP相关地址族
MER1#show bgp vpnv4 ? # VPNv4的单播/组播
MER1#show bgp vpnv4 unicast ? # 可用的操作符和参数
```
#### 第三步:继续深入具体类型
```bash
MER1#show bgp vpnv4 ?
```
输出显示VPNv4的单播/组播分类:
```
unicast Display information about all VPNv4 NLRIs
multicast Display information about all VPNv4 multicast NLRIs
flowspec Flow specification address family modifier
...
```
### Step 3: 看提示 - 理解元符号
关键输出中的特殊标记:
- `<cr>` - 可直接回车执行(命令已完整)
- `A.B.C.D` - IPv4地址占位符
- `X:X::X:X` - IPv6地址占位符
- `WORD` - 任意字符串(如VRF名、邻居IP)
- `<0-32>` - 数字范围
- `|` - 管道符,用于过滤输出
#### 第四步:查看可用的操作符和参数
```bash
MER1#show bgp vpnv4 unicast ?
```
**关键输出**(这是最有价值的一步):
```
as Autonomous system
community Show route community information
dampened-paths Show paths suppressed due to dampening
detail Display detailed information about an ip prefix
flap Show flap info
in Show route information received from all neighbors
labels Display BGP labels for prefixes
neighbor Detailed information on TCP and BGP neighbor connections
network Show route information
rd Specify route distinguisher
rd-by-vrf Specify route distinguisher by VRF name
vrf Display information for a VPN Routing/Forwarding instance
| Output modifiers (管道符,用于过滤)
> Redirect the output to a file (重定向到文件)
<cr> Carriage return (直接回车执行)
```
#### 第五步:选择VRF相关选项继续探索
```bash
MER1#show bgp vpnv4 unicast vrf ?
```
输出显示可用的VRF实例名称:
```
5G_MEC VPN Routing/Forwarding instance name
IP_RAN VPN Routing/Forwarding instance name
test VPN Routing/Forwarding instance name
WORD VPN Routing/Forwarding instance name (任意字符串)
```
#### 第六步:查看VRF下的具体操作
```bash
MER1#show bgp vpnv4 unicast vrf test ?
```
最终得到精确命令:
```
detail Show route detail information
export-unicast Export VRF routes to unicast routing table
import-unicast Import unicast routes to VRF routing table
in Show route information received from all neighbors
labels Display BGP labels for prefixes
local Display local information of a BGP neighbor
neighbor Detailed information on TCP and BGP neighbor connections
policy Display information about bgp advertisements under a proposed policy
received Display information received from a BGP neighbor
route Show route information ← 这就是我们要的!
summary Summary of BGP neighbor status
```
#### 第七步:执行最终命令
### Step 4: 试执行 - 验证命令
看到 `<cr>` 提示时,说明命令已完整:
```bash
MER1#show bgp vpnv4 unicast vrf test route
```
输出完整的BGP VPNv4路由表:
### Step 5: 记笔记 - 记录成功路径
将验证通过的命令记录下来,形成自己的知识库。
---
## 实战案例
### 案例1:BGP VPNv4路由查询
```bash
# 7层探索路径
show bgp ? # ipv4, vpnv4, evpn...
-> show bgp vpnv4 ? # unicast, multicast...
-> show bgp vpnv4 unicast ? # neighbor, network, rd, vrf...
-> show bgp vpnv4 unicast vrf ? # VRF实例名
-> show bgp vpnv4 unicast vrf test ? # detail, in, route...
-> show bgp vpnv4 unicast vrf test route # 执行
```
15:21:26 Beijing Mon Jul 20 2026
Current AS: 100. Other AS: 64580, 64600, 64900
Status codes: * valid, > best, i - internal, s - stale
Origin codes: i - IGP, e - EGP, ? - incomplete
Network Next Hop Metric LocPrf RtPrf Path
### 案例2:MPLS LDP邻居查询
```bash
show mpls ldp ? # backoff, bindings, discovery, neighbor...
-> show mpls ldp neighbor ? # brief, detail, instance...
-> show mpls ldp neighbor brief instance ? # <1-65535>
-> show mpls ldp neighbor brief instance 1 # 执行
```
### 案例3:VRF环境下的Ping
```bash
ping ? # A.B.C.D, vrf, mpls...
-> ping vrf ? # VRF实例名
-> ping vrf test ? # A.B.C.D, domain
-> ping vrf test 4.1.1.1 # 执行
```
---
## 实战案例:探索Ping和Trace命令
## 高级技巧
### 案例1:VRF环境下的Ping命令
#### 探索过程记录
### 技巧1:组合管道符过滤
```bash
# 第1层:ping后面可以跟什么?
MER1#ping ?
A.B.C.D Target IP address
bier Send BIER echo messages
ce Customer edge
dcn DCN VRF
domain Domain name
evpn Send EVPN echo messages
mpls Send MPLS echo messages
satellite Specify satellite ID
vpls VPLS instance
vpws Kompella VPWS
vrf VPN Routing/Forwarding instance name
# 第2层:ping vrf后面跟什么?
MER1#ping vrf ?
5G_MEC VRF name (1-32 characters)
5G_OAM VRF name (1-32 characters)
IP_RAN VRF name (1-32 characters)
test VRF name (1-32 characters)
WORD VRF name (1-32 characters)
# 第3层:ping vrf test后面跟什么?
MER1#ping vrf test ?
A.B.C.D Target IP address
domain Domain name
# 第4层:执行完整命令
MER1#ping vrf test 4.1.1.1
sending 5,100-byte ICMP echo(es) to 4.1.1.1,timeout is 2 second(s).
.....
Success rate is 0 percent(0/5).
show bgp vpnv4 unicast vrf test route | include 4.1.1
show bgp ipv4 unicast summary | begin Neighbor
```
### 案例2:探索MPLS LDP邻居查询
### 技巧2:配置模式同样适用
```bash
# 第1层:mpls ldp后面有什么?
MER1#show mpls ldp ?
backoff Show LDP session setup backoff table
bindings Show the LDP label information base (LIB)
discovery Show sources for locally generated LDP discovery hello PDUs
graceful-restart Show MPLS LDP GR
iccp Show LDP session and ICCP state information
igp Show LDP IGP synchronization status
instance Show LDP instance information
interface Show per-interface LDP forwarding information
log Show LDP log info
neighbor Show LDP neighbor information ← 目标在这里
parameters Show LDP configuration parameters
# 第2层:neighbor后面有什么?
MER1#show mpls ldp neighbor ?
A.B.C.D Neighbor address
brief Brief neighbor information ← 要这个简洁版
bvi Bvi interface
detail Detailed neighbor information
graceful-restart The information of LDP graceful restart neighbor
instance The information of LDP instance ← 还可以指定实例
# 第3层:instance后面跟什么?
MER1#show mpls ldp neighbor brief instance ?
<1-65535> LDP instance id
# 第4层:执行完整命令
MER1#show mpls ldp neighbor brief instance 1
15:20:54 Beijing Mon Jul 20 2026
Codes: D:Direct, T:Targeted, D&T:Direct&Targeted
Total number of neigbors:0
Operational:0 (D:0,T:0,D&T:0) (IPv4:0,IPv6:0,IPv4&IPv6:0)
Not operational:0 (D:0,T:0,D&T:0) (IPv4:0,IPv6:0,IPv4&IPv6:0)
```
---
## 高级技巧:组合使用 `?` 和其他工具
### 技巧1:利用 `<cr>` 提示判断命令完整性
当 `?` 输出中包含 `<cr>` 时,表示当前命令已经完整,可以直接执行:
```bash
MER1#show mpls ldp neighbor brief instance 1 ?
<cr> ← 看到这个,就知道可以直接回车执行了
```
### 技巧2:使用管道符 `|` 过滤大量输出
当某个命令输出太多时,用 `?` 查看可用的过滤选项:
```bash
MER1#show bgp vpnv4 unicast vrf test route ?
| Output modifiers
MER1#show bgp vpnv4 unicast vrf test route | ?
begin Begin with the line that matches
count Count the number of lines that match
exclude Exclude lines that match
include Include lines that match
section Print only the section that matches
# 实际应用:只看包含特定前缀的路由
MER1#show bgp vpnv4 unicast vrf test route | include 4.1.1
```
### 技巧3:在配置模式下同样适用
`?` 不仅适用于特权模式(`#`),也适用于配置模式(`(config)#`):
```bash
MER1#configure terminal
MER1(config)#router bgp 100
MER1(config-bgp-router)#neighbor ?
A.B.C.D Neighbor IPv4 address
X:X::X:X Neighbor IPv6 address
peer-group Name of peer group
MER1(config-bgp-router)#neighbor 10.26.63.152 ?
activate Enable the neighbor
advertisement-interval Set minimum interval between sending routing updates
allowas-in Allow AS in path
...
next-hop-self Disable the next hop calculation for this neighbor ← 关键配置!
...
```
### 技巧4:识别命令缩写规则
通过 `?` 可以发现命令的简写形式:
### 技巧3:识别命令缩写
```bash
MER1#sh ?
show Show running system information
MER1#show mpls forw ?
forwarding-table Show MPLS forwarding-table information ← forw是forwarding的合法缩写
sh ? # show的合法缩写
forw ? # forwarding的合法缩写
conf t # configure terminal的缩写
```
**规律**:只要输入的字母能唯一标识一个命令,就可以缩写。例如:
- `show` → `sh`
- `forwarding-table` → `forw`
- `configuration` → `conf`
---
## 常见命令树结构对比
### ZTE vs Huawei vs Cisco
| 功能 | ZTE (ZXROS) | Huawei (VRP) | Cisco (IOS) |
|------|-------------|--------------|-------------|
| 查看BGP VPNv4路由 | `show bgp vpnv4 unicast vrf <name> route` | `display bgp vpnv4 routing-table vpn-instance <name>` | `show bgp vpnv4 unicast vrf <name>` |
| 查看MPLS转发表 | `show mpls forwarding-table` | `display mpls lsp` | `show mpls forwarding-table` |
| 查看LDP邻居 | `show mpls ldp neighbor brief instance 1` | `display mpls ldp session` | `show mpls ldp neighbor` |
| Ping VRF内地址 | `ping vrf <name> <ip>` | `ping -vpn-instance <name> <ip>` | `ping vrf <name> <ip>` |
**结论**:虽然命令相似,但细节有差异。**必须针对每种设备单独探索**。
---
## 错误处理与注意事项
### 注意1:命令前缀限制
某些平台可能限制特定命令的使用:
### 技巧4:区分错误类型
```bash
# 如果收到 "command_not_allowed_prefix" 错误
MER1#trace vrf test 4.1.1.1
%Error: command_not_allowed_prefix
```
**原因**:`trace` 命令可能被netx等平台限制。此时应尝试:
- 改用完整路径 `traceroute`
- 检查权限级别
- 使用替代命令(如通过ping逐跳测试)
### 注意2:区分"不完整命令"和"无匹配"
```bash
# 不完整命令(Incomplete command)- 说明方向对,继续用?探索
MER1#show bgp vpnv4 unicast vrf test
# Incomplete command - 命令不完整,继续用?探索
%Error 140305: Incomplete command.
# 无匹配(Unrecognized command)- 说明走错路了,退回上一层
MER1#show bgp vpnv4 unicast vrf test xyz
%Error: Unrecognized command.
```
### 注意3:空格敏感性
```bash
# 正确:每个层级之间有空格
MER1#show mpls ldp neighbor brief instance 1
# 错误:连在一起会当成一个单词
MER1#show mplsldpneighborbriefinstance1
# Unrecognized command - 走错路了,退回上一层
%Error: Unrecognized command.
```
---
## 练习:自主探索以下命令
## 常见命令树深度对比
请用 `?` 方法探索下列命令的完整语法(答案不唯一):
| 功能 | ZTE (ZXROS) | 深度 |
|------|-------------|------|
| BGP VPNv4路由 | `show bgp vpnv4 unicast vrf <name> route` | 7层 |
| MPLS LDP邻居 | `show mpls ldp neighbor brief instance <id>` | 6层 |
| ISIS邻接 | `show isis adjacency` | 3层 |
| Ping VRF | `ping vrf <name> <ip>` | 4层 |
---
## 快速参考卡片
```bash
# 通用模板
<command> ? # 查看下一级
<command> <subcommand> ? # 继续深入
...
<full-command> <cr> # 执行
# 元符号速查
<cr> - 直接回车执行
WORD - 任意字符串
A.B.C.D - IPv4地址
X:X::X:X - IPv6地址
<1-65535> - 数字范围
| - 管道符(begin/include/exclude/count)
> - 重定向到文件
```
---
## 练习任务
用 `?` 方法探索以下命令:
1. 查看ISIS邻接关系
2. 查看OSPF邻居详细信息
3. 查看VRF IP_RAN的路由表
4. 查看MPLS标签绑定信息
5. 查看BGP从邻居10.26.63.152收到的路由
**参考答案**(实际以设备为准):
**参考答案**:
```bash
# 1. ISIS邻接
MER1#show isis adjacency
# 2. OSPF邻居详细
MER1#show ip ospf neighbor detail
# 3. VRF IP_RAN路由
MER1#show ip forwarding route vrf IP_RAN
# 4. MPLS标签绑定
MER1#show mpls ldp bindings
# 5. BGP从邻居收到的路由
MER1#show bgp vpnv4 unicast vrf test received 10.26.63.152
show isis adjacency
show ip ospf neighbor detail
show ip forwarding route vrf IP_RAN
show mpls ldp bindings
show bgp vpnv4 unicast vrf test received 10.26.63.152
```
---
## 总结:命令探索五步法
1. **定方向**:从最顶层开始(`show ?`, `ping ?`, `configure ?`)
2. **剥洋葱**:每层用 `?` 查看下一级选项,选择最相关的分支
3. **看提示**:注意 `<cr>`、`WORD`、`A.B.C.D` 等元提示
4. **试执行**:看到 `<cr>` 就执行,观察输出验证猜测
5. **记笔记**:把成功的命令路径记录下来(就像本文档做的)
**终极心法**:不要怕敲错,`?` 永远不会嘲笑你。每个网络专家都是从不停地敲 `?` 开始的。
---
## 附录:快速参考卡片
```bash
# 通用探索模板
<command> ? # 查看下一级选项
<command> <subcommand> ? # 继续深入
...
<full-command> <cr> # 看到<cr>就可以执行
# 特殊符号含义
<cr> - 可以直接回车执行
WORD - 任意字符串(通常是名字、ID等)
A.B.C.D - IPv4地址格式
X:X::X:X - IPv6地址格式
<1-65535> - 数字范围
| - 管道符,用于过滤输出
> - 重定向到文件
# 经典命令树深度
show bgp vpnv4 unicast vrf <name> route # 7层
show mpls ldp neighbor brief instance <id> # 6层
ping vrf <name> <ip> # 4层
configure terminal # 2层
```
---
**文档版本**:v1.0
**最后更新**:2026-07-20
**维护者**:基于真实设备(MER1)验证
**文档版本**:v2.0(精简版)
**最后更新**:2026-07-29

View file

@ -1,63 +1,273 @@
# 故障处理常用命令目录集(ZTE ZXROS)
> **设备**:MER1 @ 10.229.234.136 (ZXCTN 9000-3EA, V5.00.10.70)
> **更新时间**:2026-07-22
> **验证状态**:✅ 已验证 / ❌ 错误命令(已删除)
---
## 一、BGP相关命令
### 1.1 BGP IPv4单播
### 1.1 BGP地址族总览
```bash
show bgp ipv4 unicast # BGP IPv4单播路由表
show bgp ipv4 unicast summary # BGP IPv4摘要信息
show bgp ipv4 unicast neighbor # BGP IPv4邻居信息
show bgp ipv4 unicast neighbor <ip-address> # 指定邻居的详细信息
show bgp ? # BGP支持的地址族
all All address families
bmp BGP Monitoring Protocol
evpn Display information about all EVPN NLRIs
ipv4 IPv4 address family
ipv6 IPv6 address family
l2vpn L2VPN address family
link-state Link-state address family
remote BGP remote prefix-sid
rpki-rtr RPKI-RTR Protocol
sr-epe Show information for egress peer engineering
srv6-epe Show information for SRv6 egress peer engineering
urpf-id-array BGP urpf-id array
vpnv4 VPNv4 address family
vpnv6 VPNv6 address family
```
### 1.2 BGP VPNv4
### 1.2 BGP IPv4单播
```bash
show bgp vpnv4 unicast # VPNv4 BGP路由表(所有VRF)
# 基本命令
show bgp ipv4 unicast summary # BGP IPv4 邻居状态摘要信息
show bgp ipv4 unicast neighbor <ipv4-address> # 查询特定BGP邻居的详细信息
# 按条件查询路由
show bgp ipv4 unicast detail A.B.C.D <0-32> # BGP IPv4路由详细信息
show bgp ipv4 unicast network A.B.C.D # BGP IPv4路由信息
show bgp ipv4 unicast # ipv4 bgp全量路由表信息(慎用)
# 按来源/目的地查询
show bgp ipv4 unicast in detail A.B.C.D <0-32> # 接收路由的详细信息
show bgp ipv4 unicast in route # 接收路由的简要信息
show bgp ipv4 unicast neighbor in <neighbor-ip> # 从邻居接收方向获取的路由信息
show bgp ipv4 unicast neighbor out <neighbor-ip> # 向邻居发送的路由信息
# 策略和更新组
show bgp ipv4 unicast update-group <ug-index> # 更新组信息
```
### 1.3 BGP IPv6单播
```bash
# 基本命令
show bgp ipv6 unicast summary # BGP IPv6摘要信息
show bgp ipv6 unicast neighbor <ipv6-address> # 查询特定BGP邻居的详细信息
# 按条件查询路由
show bgp ipv6 unicast detail X:X::X:X/<0-128> # BGP IPv6路由详细信息
show bgp ipv6 unicast # ipv6 bgp全量路由表信息(慎用)
# 按来源/目的地查询
show bgp ipv6 unicast in detail X:X::X:X/<0-128> # 接收路由的详细信息
show bgp ipv6 unicast in route # 接收路由的简要信息
show bgp ipv6 unicast neighbor in <neighbor-ip> # 从邻居接收方向获取的路由信息
show bgp ipv6 unicast neighbor out <neighbor-ip> # 向邻居发送的路由信息
# 策略和更新组
show bgp ipv6 unicast update-group <ug-index> # 更新组信息
```
### 1.4 BGP VPNv4
```bash
# 基本命令
show bgp vpnv4 unicast summary # VPNv4 BGP摘要
show bgp vpnv4 unicast neighbor # VPNv4邻居信息
show bgp vpnv4 unicast neighbor <ipv4-address> # 查询特定BGP邻居的详细信息
# VRF路由查询
show bgp vpnv4 unicast vrf <vrf-name> route # 指定VRF的VPNv4路由表
show bgp vpnv4 unicast vrf <vrf-name> # 指定VRF的VPNv4路由(Incomplete command,需要加route)
show bgp vpnv4 unicast rd <rd-value> route # 通过RD查询VPNv4路由
# 按条件查询路由
show bgp vpnv4 unicast detail <rd> A.B.C.D <0-32> # VPNv4路由详细信息
show bgp vpnv4 unicast network A.B.C.D # VPNv4路由信息
show bgp vpnv4 unicast # VPNv4全量路由表信息(慎用)
# 按来源/目的地查询
show bgp vpnv4 unicast in detail <rd> A.B.C.D <0-32> # 接收路由的详细信息
show bgp vpnv4 unicast in route # 接收路由的简要信息
show bgp vpnv4 unicast neighbor in <neighbor-ip> # 从邻居接收方向获取的路由信息
show bgp vpnv4 unicast neighbor out <neighbor-ip> # 向邻居发送的路由信息
show bgp vpnv4 unicast vrf <vrf-name> neighbor in <neighbor-ip> # vrf邻居收方向路由信息
show bgp vpnv4 unicast vrf <vrf-name> neighbor out <neighbor-ip> # vrf邻居发方向路由信息
# 策略和更新组
show bgp vpnv4 unicast update-group <ug-index> # 更新组信息
```
### 1.3 BGP配置查看
### 1.5 BGP VPNv6
```bash
show running-config bgp # BGP运行配置
show running-config router bgp <as-number> # BGP进程配置
# 基本命令
show bgp vpnv6 unicast summary # VPNv6 BGP摘要
show bgp vpnv6 unicast neighbor # VPNv6邻居信息
show bgp vpnv6 unicast neighbor <ipv6-address> # 查询特定BGP邻居的详细信息
# VRF路由查询
show bgp vpnv6 unicast vrf <vrf-name> route # 指定VRF的VPNv6路由表
show bgp vpnv6 unicast rd <rd-value> route # 通过RD查询VPNv6路由
# 按条件查询路由
show bgp vpnv6 unicast detail <rd> X:X::X:X/<0-128> # VPNv6路由详细信息
show bgp vpnv6 unicast network X:X::X:X # VPNv6路由信息
show bgp vpnv6 unicast # VPNv6全量路由表信息(慎用)
# 按来源/目的地查询
show bgp vpnv6 unicast in detail <rd-value> X:X::X:X/<0-128> # 接收路由的详细信息
show bgp vpnv6 unicast in route # 接收路由的简要信息
show bgp vpnv6 unicast neighbor in <neighbor-ip> # 从邻居接收方向获取的路由信息
show bgp vpnv6 unicast neighbor out <neighbor-ip> # 向邻居发送的路由信息
# 策略和更新组
show bgp vpnv6 unicast update-group <ug-index> # 更新组信息
```
### 1.4 BGP IPv4单播详细
### 1.6 BGP L2VPN EVPN
```bash
show bgp ipv4 unicast neighbor # BGP IPv4邻居信息
show bgp ipv4 unicast neighbor <ip-address> # 指定邻居的详细信息
```
# 基本命令
show bgp l2vpn evpn summary # EVPN摘要信息
show bgp l2vpn evpn neighbor # EVPN邻居信息
show bgp l2vpn evpn neighbor <ipv4-address> # 查询特定BGP邻居的详细信息
# EVPN路由类型
show bgp l2vpn evpn ethernet-ad # Ethernet Auto-discovery路由
show bgp l2vpn evpn ethernet-segment # Ethernet Segment路由
show bgp l2vpn evpn mac # MAC/IP Advertisement路由
show bgp l2vpn evpn ip-prefix neighbor in <neighbor-ip> # IP Prefix路由
# 按条件查询路由
show bgp l2vpn evpn detail <rd> <prefix> # EVPN路由详细信息
show bgp l2vpn evpn network <prefix> # EVPN路由信息
show bgp l2vpn evpn # EVPN全量路由表信息(慎用)
# 按来源/目的地查询
show bgp l2vpn evpn in detail <rd> <prefix> # 接收路由的详细信息
show bgp l2vpn evpn in route # 接收路由的简要信息
show bgp l2vpn evpn neighbor in <neighbor-ip> # 从邻居接收方向获取的路由信息
show bgp l2vpn evpn neighbor out <neighbor-ip> # 向邻居发送的路由信息
# 策略和更新组
show bgp l2vpn evpn update-group <ug-index> # 更新组信息
```
---
## 二、IGP相关命令
### 2.1 IS-IS
```bash
# IS-IS进程和概要信息
show isis process # IS-IS进程详细信息
show isis process process-id <process-id> # 指定进程的详细信息
# IS-IS邻接关系
show isis adjacency # IS-IS邻接关系
show isis database # IS-IS链路状态数据库
show isis adjacency summary # IS-IS邻接摘要(按进程显示)
show isis adjacency level-1 # Level-1邻接关系
show isis adjacency level-2 # Level-2邻接关系
show isis adjacency interface <interface> # 指定接口的邻接
show isis adjacency log # IS-IS邻接变化日志
show isis adjacency establish-failure log # IS-IS邻接建立失败日志
show isis adjacency up-time level-1 # Level-1邻接保持时间
show isis adjacency up-time level-2 # Level-2邻接保持时间
# IS-IS链路状态数据库
show isis database # IS-IS链路状态数据库摘要
show isis database detail # IS-IS数据库详细信息
show isis database level-1 # Level-1数据库
show isis database level-2 # Level-2数据库
show isis database level-1 detail # Level-1数据库详细
show isis database level-2 detail # Level-2数据库详细
show isis database <lsp-id> # 查看特定LSP
show isis database <lsp-id> detail # 查看特定LSP详细信息
show isis database log # IS-IS数据库日志
show isis database purge statistics detail # IS-IS数据库清除统计
show isis database verbose # IS-IS数据库详尽信息
# IS-IS电路(接口)信息
show isis circuits # IS-IS电路信息
show isis circuits summary # IS-IS电路摘要
show isis circuits detail # IS-IS电路详细信息
show isis circuits interface <interface> # 指定接口的电路信息
show isis circuits no-adjacency # 没有邻接的IS-IS电路
# IS-IS动态主机名
show isis hostname # IS-IS动态主机名映射
show isis circuit # IS-IS电路信息
# IS-IS路由信息(IPv4)
show isis ipv4 route # IS-IS IPv4路由表
show isis ipv4 route all # IS-IS所有IPv4路由(包括不可达)
show isis ipv4 route summary # IS-IS IPv4路由汇总
show isis ipv4 route detail # IS-IS IPv4路由详细信息
show isis ipv4 route level-1 # Level-1 IPv4路由
show isis ipv4 route level-2 # Level-2 IPv4路由
show isis ipv4 route A.B.C.D # 查询特定IPv4路由
show isis ipv4 route flex-algorithm <algo-id> # 灵活算法路由
show isis ipv4 route strict-spf # 严格SPF路由
# IS-IS路由信息(IPv6)
show isis ipv6 route # IS-IS IPv6路由表
show isis ipv6 route all # IS-IS所有IPv6路由(包括不可达)
show isis ipv6 route summary # IS-IS IPv6路由汇总
show isis ipv6 route detail # IS-IS IPv6路由详细信息
show isis ipv6 route level-1 # Level-1 IPv6路由
show isis ipv6 route level-2 # Level-2 IPv6路由
show isis ipv6 route X:X::X:X # 查询特定IPv6路由
show isis ipv6 route X:X::X:X/<0-128> # 查询特定IPv6前缀
show isis ipv6 route flex-algorithm <algo-id> # 灵活算法IPv6路由
show isis ipv6 route strict-spf # 严格SPF IPv6路由
# IS-IS拓扑路径
show isis topology # IS-IS拓扑路径
show isis topology detail # IS-IS拓扑详细信息
show isis topology level-1 # Level-1拓扑路径
show isis topology level-2 # Level-2拓扑路径
show isis topology <process-id> # 到特定进程的拓扑路径
# IS-IS快速重路由
show isis fast-reroute-topology lfa # IS-IS LFA快速重路由路径
show isis fast-reroute-topology remote-lfa # IS-IS Remote-LFA路径
show isis fast-reroute-topology ti-lfa # IS-IS TI-LFA路径
# IS-IS Segment Routing
show isis segment-routing prefix-sid-map # IS-IS SR前缀SID映射
show isis segment-routing prefix-sid-map ipv4 # IPv4前缀SID映射
show isis segment-routing prefix-sid-map ipv6 # IPv6前缀SID映射
show isis segment-routing prefix-sid-map detail # SR前缀SID映射详细信息
show isis segment-routing prefix-sid-map conflict # SR前缀SID冲突信息
# IS-IS MPLS流量工程
show isis mpls traffic-eng tunnel # IS-IS MPLS TE隧道信息
# IS-IS BIER信息
show isis bier topology brief sub-domain <sub-domain-identifier> # IS-IS BIER拓扑路径
# IS-IS Mesh Groups
show isis mesh-groups blocked # IS-IS阻塞的mesh组
show isis mesh-groups group # IS-IS mesh组分发信息
# IS-IS NSR/NSF信息
show isis nsf # IS-IS NSF状态信息
# IS-IS备份路由
show isis ipv4 backup route # IS-IS IPv4备份路由
show isis ipv6 backup route # IS-IS IPv6备份路由
# IS-IS配置查看
show running-config isis # IS-IS运行配置
show running-config isis all # IS-IS所有配置(包含默认缺省配置)
```
### 2.2 OSPF
### 2.2 OSPF(IPv4)
```bash
show ip ospf neighbor # OSPF邻居关系
show ip ospf interface brief # OSPF接口简要信息
show ip ospf interface # OSPF接口详细信息
show ip ospf database # OSPF链路状态数据库
show ip ospf database router-link # OSPF Type-1 LSA(Router LSA)
show ip ospf database router # OSPF Type-1 LSA(Router LSA)
show ip ospf database network # OSPF Type-2 LSA(Network LSA)
show ip ospf database summary # OSPF Type-3 LSA(Summary LSA)
show ip ospf database asbr # OSPF Type-4 LSA(ASBR Summary LSA)
show ip ospf database asbr-summary # OSPF Type-4 LSA(ASBR Summary LSA)
show ip ospf database external # OSPF Type-5 LSA(External LSA)
show ip ospf database nssa # OSPF Type-7 LSA(NSSA External LSA)
show ip ospf database self-originate # OSPF自生成的LSA
@ -65,53 +275,136 @@ show ip ospf border-routers # OSPF边界路由器信息
show ip ospf virtual-links # OSPF虚链路信息
show ip ospf # OSPF进程概要信息
show ip ospf route # OSPF路由表(按进程显示)
show running-config ospfv2 # OSPFv2运行配置
```
### 2.3 OSPFv3(IPv6)
```bash
# OSPFv3进程概要
show ipv6 ospf # 所有OSPFv3进程概要信息
show ipv6 ospf <1-16777215> # 指定进程的详细信息(如:show ipv6 ospf 100)
# OSPFv3邻居
show ipv6 ospf neighbor # OSPFv3邻居列表
show ipv6 ospf neighbor detail # OSPFv3邻居详细信息
show ipv6 ospf neighbor summary # OSPFv3邻居摘要
show ipv6 ospf neighbor log # OSPFv3邻居日志
show ipv6 ospf neighbor A.B.C.D # 指定邻居ID的详细信息
# OSPFv3接口
show ipv6 ospf interface # OSPFv3接口状态和配置
show ipv6 ospf interface <interface-type> # 指定类型接口的OSPFv3信息
bvi BVI接口
flexe_channel FlexE通道接口
gre_tunnel GRE隧道接口
irb IRB接口
lgei- 万兆以太网接口
loopback Loopback接口
smartgroup Smartgroup接口
vlan VLAN接口
vei VEI接口
...
# OSPFv3数据库
show ipv6 ospf database # OSPFv3数据库摘要
show ipv6 ospf database router # Router-LSA(Type-1)
show ipv6 ospf database network # Network-LSA(Type-2)
show ipv6 ospf database inter-prefix # Inter-Prefix-LSA(Type-3)
show ipv6 ospf database inter-router # Inter-Router-LSA(Type-4)
show ipv6 ospf database intra-prefix # Intra-Prefix-LSA(Type-9)
show ipv6 ospf database link # Link-LSA(Type-8)
show ipv6 ospf database external # AS-external-LSA(Type-5/Type-7)
show ipv6 ospf database nssa # NSSA Type-7 LSA
show ipv6 ospf database intra-te # Intra-Area-TE-LSA
show ipv6 ospf database router-info # Router-Information-Opaque-LSA
show ipv6 ospf database srv6-locator # SRv6-Locator-LSA
show ipv6 ospf database extended # 扩展LSA类型
external Extended-AS-External-LSA
inter-prefix Extended-Inter-Area-Prefix-LSA
intra-prefix Extended-Intra-Area-Prefix-LSA
router Extended-Router-LSA
# OSPFv3数据库高级选项
show ipv6 ospf database <lsa-type> adv-router # 查看特定通告路由器的LSA
show ipv6 ospf database <lsa-type> process <pid> # 查看指定进程的LSA
# OSPFv3路由
show ipv6 ospf route # OSPFv3路由表
show ipv6 ospf route detail # OSPFv3路由详细信息
show ipv6 ospf route summary # OSPFv3路由汇总统计
show ipv6 ospf route adv-router <router-id> # 查看特定通告路由器的路由
show ipv6 ospf route network <ipv6-address> # 查看特定网络的路由
# OSPFv3虚链路
show ipv6 ospf virtual-links # OSPFv3虚链路信息
show ipv6 ospf virtual-links process <pid> # 指定进程的虚链路
# OSPFv3顶点信息
show ipv6 ospf vertex # OSPFv3顶点信息
show ipv6 ospf vertex backup # 备份顶点信息
show ipv6 ospf vertex log # 顶点日志
show ipv6 ospf vertex process <pid> # 指定进程的顶点信息
# OSPFv3统计
show ipv6 ospf statistics interface <if-name> # OSPFv3接口统计信息
# OSPFv3配置查看
show running-config ospfv3 # OSPFv3运行配置
```
---
## 三、MPLS/LDP相关命令
### 3.1 MPLS转发
```bash
show mpls forwarding-table # MPLS标签转发表
show mpls forwarding-table <next-hop-ip> # 特定下一跳的标签转发表
```
### 3.1 MPLS
### 3.2 LDP会话和绑定
```bash
#MPLS转发
show mpls forwarding-table # MPLS标签转发表
show mpls forwarding-table <A.B.C.D/ X:X::X:X> # Destination IPv4/IPv6 prefix标签转发表
#LDP会话和绑定
show mpls ldp neighbor brief instance <id> # LDP邻居简要信息(必须指定instance!)
show mpls ldp neighbor instance <id> # LDP邻居详细信息
show mpls ldp parameters instance <id> # LDP参数配置
show mpls ldp binding instance <id> # LDP标签绑定信息(全局)
show mpls ldp discovery instance <id> # LDP发现信息
```
### 3.3 LDP配置
```bash
# LDP配置
show running-config ldp # LDP运行配置
```
---
## 四、VRF相关命令
## 四、ping/trace相关命令
### 4.1 VRF路由
```bash
show ip forwarding route vrf <vrf-name> # VRF路由表
show ip route vpn # 查看所有VPN路由
```
### 4.1 业务测试
### 4.2 VRF业务测试
```bash
ping <dest-ip> # Ping全局地址
ping <dest-ip> source <source-ip> # 指定本地源ip Ping全局地址
ping6 <dest-ipv6> # Ping v6地址
ping6 <dest-ipv6> source <source-ipv6> # 指定本地源ipv6 Ping v6地址
ping vrf <vrf-name> <dest-ip> # Ping测VRF内地址
ping vrf <vrf-name> <dest-ip> source <source-ip> # 指定本地源ip Ping测VRF内地址
ping6 vrf <vrf-name> <dest-ipv6> # Ping测VRF ipc6内地址
ping6 vrf <vrf-name> <dest-ipv6> source <source-ipv6> #指定本地源ipv6 Ping测VRF ipc6内地址
trace <ip> # trace 路径
trace <ip> source <source-ip> # 指定本地源ip trace 路径
trace vrf <vrf-name> <dest-ip> # trace vrf内ip路径
trace vrf <vrf-name> <dest-ip> source <source-ip> # 指定本地源ip trace vrf内ip路径
trace6 vrf <vrf-name> <dest-ipv6> # trace vrf内ipv6路径
trace6 vrf <vrf-name> <dest-ipv6> source <source-ipv6> # 指定本地源ipv6 trace vrf内ipv6路径
```
---
## 五、隧道相关命令
```bash
# 暂无已验证的隧道查询命令
show mpls traffic-eng tunnels brief # 查看
show mpls traffic-eng tunnels te_tunnel <Tunnel_ID> # 查看本端设备te隧道详细情况
show mpls traffic-eng interface brief # TE接口的状态
```
---
@ -119,19 +412,38 @@ ping vrf <vrf-name> <dest-ip> # Ping测VRF内地址
## 六、接口和路由基础命令
### 6.1 接口状态
```bash
show interface brief # 接口简要信息
show ip interface brief # IP接口简要信息
show intf-statistics utilization # 接口利用率
show intf-statistics utilization phy-interface-only # 仅查看物理口利用率
show interface description # 查看端口状态以及描述(可通过描述判断业务、互联设备信息)
show opticalinfo brief # 查看端口收发情况
show opticalinfo <phy-interface> # 查看物理口收发光信息
show interface <interface> # 查看接口详细信息
```
### 6.2 全局路由
```bash
show ip forwarding route # 全局IPv4路由表
show ip forwarding route # 全局全量IPv4路由表(慎用)
show ip forwarding route <ipv4-address> # 查询某ip路由表(优先)
show ip forwarding route vrf <vrf> # 查询某vrf IPv4路由表(慎用)
show ip forwarding route vrf <vrf> <ip-address> # 查询某vrf 某ip IPv4路由表(优先)
show ipv6 forwarding route # 全局全量IPv6路由表(慎用)
show ipv6 forwarding route <ipv6-address> # 全局某IPv6路由表(优先)
show ipv6 forwarding route vrf <vrf> # 查询某vrf IPv6路由表(慎用)
show ipv6 forwarding route vrf <vrf> <ip-address> # 查询某vrf 某ip IPv6路由表(优先)
```
### 6.3 ARP/MAC
### 6.3 ND/ARP/MAC
```bash
show arp # ARP表
show arp # 全局ARP表
show arp vrf <vrf> # vrf arp表信息
show nd6 cache # 全量nd信息
show nd6 cache <interface> # 某接口nd信息
```
---
@ -139,109 +451,109 @@ show arp # ARP表
## 七、系统基础命令
### 7.1 系统信息
```bash
show version # 版本信息
show running-config # 当前运行配置
show card-state brief # 单板状态
show fan # 风扇信息
show power # 电源信息
show temperature environment-threshold # 温度信息
```
### 7.2 配置信息
```bash
show running-config # 当前运行配置 范围太广尽量少用或不用,优先使用单模块查找
show running-config <module> # 通过模块查询具体配置,可以通过`show running-config ?`查看有什么模块
show running-config-interface <interface> # 查看某端口具体配置
```
### 7.3 告警信息
```bash
show alarm current brief # 当前告警信息
show alarm current typeid <module> # 通过模块查询当前告警,可以通过`show alarm current typeid ?`查看有什么模块
show alarm history # 查看历史告警(主要用于回溯)
show alarm history typeid <module> # 通过模块查询历史告警,可以通过`show alarm history typeid ?`查看有什么模块
```
### 7.4 lldp邻居信息
```bash
show lldp neighbor brief | one-line # 查看lldp邻居信息
show lldp neighbor interface <phy-interface> # 查看接口lldp邻居信息
```
---
## 八、快速排障组合
## 八、命令语法说明
### 8.1 BGP跨域故障(已验证组合)
```bash
# 第零层:业务测试
ping vrf test 4.1.1.1 # 1. Ping测业务连通性
### 8.1 重要注意事项
# 第一层:VRF路由检查
show ip forwarding route vrf test # 2. 检查VRF路由表
# 第二层:MPLS标签检查
show mpls forwarding-table <next-hop> # 3. 检查MPLS标签转发表
show mpls forwarding-table <specific-ip> # 4. 检查特定目的地的标签
# 第三层:LDP会话检查
show mpls ldp neighbor brief instance 1 # 5. 检查LDP邻居状态
show mpls ldp neighbor instance 1 # 6. 检查LDP邻居详细信息
show mpls ldp binding instance 1 # 7. 检查LDP标签绑定
show mpls ldp parameters instance 1 # 8. 检查LDP参数配置
show mpls ldp discovery instance 1 # 9. 检查LDP发现信息
# 第四层:BGP路由检查
show bgp vpnv4 unicast vrf test route # 10. 检查BGP VPNv4路由
show bgp vpnv4 unicast summary # 11. 检查BGP VPNv4摘要
show bgp ipv4 unicast summary # 12. 检查BGP IPv4摘要
show bgp ipv4 unicast neighbor # 13. 检查BGP IPv4邻居
# 第五层:IGP邻接检查
show ip ospf neighbor # 14. 检查OSPF邻居
show isis adjacency # 15. 检查IS-IS邻接
show ip ospf interface brief # 16. 检查OSPF接口状态
show isis database # 17. 检查IS-IS数据库
show isis circuit # 18. 检查IS-IS电路
# 第六层:基础路由检查
show ip forwarding route # 19. 检查全局路由表
show ip interface brief # 20. 检查IP接口状态
show arp # 21. 检查ARP表
```
### 8.2 OSPF详细排障
```bash
show ip ospf # OSPF进程总览
show ip ospf interface # OSPF接口详细信息
show ip ospf database # OSPF LSDB
show ip ospf database router-link # OSPF Type-1 LSA(Router LSA)
show ip ospf database network # OSPF Type-2 LSA(Network LSA)
show ip ospf database summary # OSPF Type-3 LSA(Summary LSA)
show ip ospf database asbr # OSPF Type-4 LSA(ASBR Summary LSA)
show ip ospf database external # OSPF Type-5 LSA(External LSA)
show ip ospf database nssa # OSPF Type-7 LSA(NSSA External LSA)
show ip ospf database self-originate # OSPF自生成LSA
show ip ospf border-routers # OSPF边界路由器
show ip ospf virtual-links # OSPF虚链路
show ip ospf route # OSPF路由表(按进程显示)
```
### 8.3 IS-IS详细排障
```bash
show isis adjacency # IS-IS邻接
show isis database # IS-IS LSDB
show isis hostname # IS-IS动态主机名映射
show isis circuit # IS-IS电路信息
```
### 8.4 LDP详细排障
```bash
show mpls ldp neighbor brief instance <id> # LDP邻居简要信息
show mpls ldp neighbor instance <id> # LDP邻居详细信息
show mpls ldp parameters instance <id> # LDP参数配置
show mpls ldp binding instance <id> # LDP标签绑定
show mpls ldp discovery instance <id> # LDP发现信息
```
---
## 九、命令语法说明
### 9.1 重要注意事项
1. **LDP命令必须指定instance**:`show mpls ldp neighbor brief instance <id>` ✅
- `show mpls ldp neighbor brief` ❌ Incomplete command
- `show mpls ldp neighbor brief` ❌ Incomplete command
2. **BGP VPNv4路由查询**:`show bgp vpnv4 unicast vrf <vrf-name> route` ✅
- `show bgp vpnv4 unicast rd-by-vrf <vrf-name>` ❌ Incomplete command
- `show bgp ipv4 unicast route` ❌ Ambiguous command
3. **VRF路由查询**:`show ip forwarding route vrf <vrf-name>` ✅
- `show ip route vrf <vrf-name>` ❌ Invalid input
- `show ipv4 route vrf <vrf-name>` ❌ Invalid input
4. **OSPFv3命令特点**:
### 9.2 特殊字符限制
netx平台限制了管道符等特殊字符的使用,建议分步执行命令。
- OSPFv3使用`show ipv6 ospf`前缀,而不是`show ip ospf`
- OSPFv3数据库LSA类型与OSPFv2不同:Type-1/2/3/4/5对应router/network/inter-prefix/inter-router/external
- OSPFv3新增Type-7(Link-LSA)、Type-8(Intra-Prefix-LSA)等IPv6特有LSA
- OSPFv3支持SRv6 Locator LSA(`show ipv6 ospf database srv6-locator`)
- OSPFv3请求列表和重传列表需要指定邻居或接口参数
5. **IS-IS命令特点**:
- IS-IS支持多进程:设备上有多个IS-IS进程实例(如进程0、1、5、44、101等)
- Level分离:大多数命令支持`level-1`和`level-2`选项,分别查看L1/L2信息
- IPv4/IPv6分离:路由查询使用`show isis ipv4 route`和`show isis ipv6 route`
- LSP标识符格式:`system-id.xx-xx*`(如MER1.00-00*)
- 灵活算法支持:`flex-algorithm`参数用于查看特定算法的路由
- Segment Routing集成:通过`show isis segment-routing prefix-sid-map`查看SR映射
- 快速重路由:支持LFA、Remote-LFA、TI-LFA三种保护方式
6. **BGP命令特点**:
- BGP支持多种地址族:IPv4/IPv6单播、VPNv4/VPNv6、EVPN、Link-State等
- BGP IPv4/IPv6命令结构相似,都支持summary、neighbor、detail、community等子命令
- BGP VPNv4/VPNv6需要通过`vrf <vrf-name>`或`rd <rd-value>`来指定VRF
- EVPN支持多种NLRI类型:ethernet-ad、mac、ip-prefix、inclusive-multicast等
- Link-State按protocol和type分类,可以查看ISIS/OSPF/BGP等协议的链路状态信息
- BMP用于监控BGP会话和路由,支持monitor-peer和monitor-route
- SR-EPE和SRv6-EPE用于出向peer工程,支持按AS查询
- RPKI-RTR提供路由源验证功能,支持valid/invalid/not-found状态查询
### 8.2 参数占位符说明
文档中使用以下占位符表示需要替换的参数:
- `<ipv4-address>` - IPv4地址,如`192.168.1.1`
- `<ipv6-address>` - IPv6地址,如`2001:db8::1`
- `<as-number>` - AS号码,如`65001`
- `<vrf-name>` - VRF名称,如`vpn1`
- `<rd-value>` - RD值,如`65001:100`
- `<interface>` - 接口名称,如`gei_1/1`或`loopback1`
- `<process-id>` - 进程ID,如`isis 100`中的`100`
- `<lsp-id>` - LSP标识符,如`MER1.00-00*`
- `<system-id>` - IS-IS系统ID,如`1`
- `<regex>` - 正则表达式,用于匹配AS路径
- `<community>` - BGP团体号,如`65001:100`
- `<route-map>` - 路由图名称
- `<ug-index>` - 更新组索引号
- `<name>` - 名称标识符
- `<prefix>` - 网络前缀
- `<mac-address>` - MAC地址,如`00:11:22:33:44:55`
- `<index-value>` - 索引值
- `<neighbor>` - 邻居IP地址
- `<algo-id>` - 灵活算法ID
### 8.3 特殊限制
netx平台对命令数量有限制,可以多次采集
---
**文档维护**:
- 最后更新:2026-07-22
- 验证设备:MER1 @ 10.229.234.136
- 关联文档:`命令探索方法论.md`、`BGP跨域排障命令速查.md`