From db1d89d83b1241ae338217d7dd51daf2c83aa472 Mon Sep 17 00:00:00 2001 From: hans Date: Tue, 21 Jul 2026 19:01:49 +0800 Subject: [PATCH] =?UTF-8?q?=E5=A2=9E=E5=8A=A0=E7=9F=A5=E8=AF=86=E6=96=87?= =?UTF-8?q?=E6=A1=A3?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../BGP/VPN跨域标签异常排查树.md | 156 +++++++ .../zte/01_协议排障逻辑树/README.md | 26 ++ .../zte/02_产品平台特性/README.md | 31 ++ .../zte/03_配置规范与基线/BGP_跨域配置规范.md | 224 ++++++++++ .../zte/03_配置规范与基线/LDP_配置基线.md | 93 ++++ .../zte/03_配置规范与基线/README.md | 24 ++ .../BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md | 201 +++++++++ .../zte/05_监控指标与告警阈值/README.md | 27 ++ .../zte/06_标准SOP与工具脚本/README.md | 34 ++ .../06_标准SOP与工具脚本/命令探索方法论.md | 400 ++++++++++++++++++ .../06_标准SOP与工具脚本/故障处理常用命令.md | 245 +++++++++++ 11 files changed, 1461 insertions(+) create mode 100644 docs/ip-knowledge-base/zte/01_协议排障逻辑树/BGP/VPN跨域标签异常排查树.md create mode 100644 docs/ip-knowledge-base/zte/01_协议排障逻辑树/README.md create mode 100644 docs/ip-knowledge-base/zte/02_产品平台特性/README.md create mode 100644 docs/ip-knowledge-base/zte/03_配置规范与基线/BGP_跨域配置规范.md create mode 100644 docs/ip-knowledge-base/zte/03_配置规范与基线/LDP_配置基线.md create mode 100644 docs/ip-knowledge-base/zte/03_配置规范与基线/README.md create mode 100644 docs/ip-knowledge-base/zte/04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md create mode 100644 docs/ip-knowledge-base/zte/05_监控指标与告警阈值/README.md create mode 100644 docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/README.md create mode 100644 docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/命令探索方法论.md create mode 100644 docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/故障处理常用命令.md diff --git a/docs/ip-knowledge-base/zte/01_协议排障逻辑树/BGP/VPN跨域标签异常排查树.md b/docs/ip-knowledge-base/zte/01_协议排障逻辑树/BGP/VPN跨域标签异常排查树.md new file mode 100644 index 00000000..b9732c5e --- /dev/null +++ b/docs/ip-knowledge-base/zte/01_协议排障逻辑树/BGP/VPN跨域标签异常排查树.md @@ -0,0 +1,156 @@ +# BGP VPN跨域标签异常排查树 + +## 现象:VRF路由下一跳为NULL或出接口为NULL + +### 第零层排查:业务层连通性测试(起点!) + +#### 子步骤0.1:Ping测业务地址 +- **命令**:`ping vrf ` +- **示例**:`ping vrf test 4.1.1.1` +- **目的**:确认业务是否真正中断,区分是路由问题还是转发问题 +- **预期结果**: + - 通 → 业务正常,无需进一步排查 + - 不通 → 进入下一步trace定位断点 + +#### 子步骤0.2:Trace定位路径 +- **命令**:`trace vrf ` +- **目的**:确定报文在哪一跳丢失,判断是本地问题还是远端问题 +- **典型场景**: + - 第一跳就失败 → 本地VRF路由或直连问题 + - 中间某跳失败 → 该节点标签或IGP问题 + - 能到最后一跳但不通 → 对端CE设备或业务侧问题 + +--- + +### If `show ip forwarding route vrf `显示Interface为NULL +- **Then第一层排查:MPLS标签分配** + - `show mpls forwarding-table ` → 查看Outgoing Label + - 若为"no label"或"pop",说明LDP未分配标签 + +#### 子步骤1.1:检查LDP会话状态 +- `show mpls ldp neighbor brief instance ` → 确认LDP邻居为Established +- `show mpls ldp neighbor detail instance ` → 查看标签分发能力 + +#### 子步骤1.2:检查LDP策略配置(关键!) +- `show running-config ldp` → 查找access-fec、fec-filter等过滤配置 +- `show mpls ldp binding instance ` → 查看实际分配的标签绑定 +- **常见陷阱**:`access-fec ip-prefix host-route-only`会强制LDP只给32位主机路由分配标签 +- **排障动作**:评估必要性,若非强制需求则去除该限制 +- **示例输出**: +``` +! +mpls ldp instance 1 + access-fec ip-prefix host-route-only + discovery hello holdtime 180 + discovery targeted-hello holdtime 180 + interface smartgroup1 + router-id loopback1 + target-session 10.26.63.152 +$ +! +``` + +#### 子步骤1.3:检查下一跳地址的掩码长度 +- `show ip forwarding route ` → 查看掩码是否为/32 +- **原理**:LDP默认只为32位主机路由分配标签(倒数第二跳弹出机制前提) +- 若为/30或/31互联地址,LDP可能不分配标签 + +--- + +### If 标签分配正常但业务仍不通 +- **Then第二层排查:BGP下一跳属性** + - `show bgp vpnv4 unicast vrf route` → 查看完整的BGP VPNv4路由表 + - `show bgp vpnv4 unicast labels` → 查看标签信息 + - **关键字段**:Next Hop(下一跳)、Label(标签)、Path(AS_PATH) + +#### 子步骤2.1:检查ASBR配置 +- 登录对端ASBR,查看BGP配置 +- **关键配置缺失**:ASBR向IBGP宣告EBGP路由时未配置`neighbor next-hop-self` +- **排障动作**:在ASBR上配置`neighbor next-hop-self` +- **验证命令**:`show bgp vpnv4 unicast vrf neighbor advertised-routes` + +#### 子步骤2.2:验证修复效果 +- 配置next-hop-self后,PE上BGP路由的下一跳应变为ASBR的Loopback地址(32位) +- LDP为主机路由分配标签 → `show mpls forwarding-table`应显示明确的Outgoing Label +- `show ip forwarding route vrf `应显示实际出接口 + +--- + +### If BGP路由正常但IGP不可达 +- **Then第三层排查:IGP邻接关系** + - `show isis adjacency` → 检查ISIS邻接状态 + - `show isis hostname` → 查看系统ID映射 + - `show ip ospf neighbor` → 检查OSPF邻居状态 + +#### 子步骤3.1:检查IGP拓扑同步 +- `show isis database` → 查看LSDB完整性 +- `show ip ospf database` → 检查OSPF链路状态数据库 +- **常见问题**:IGP未学习到BGP下一跳的路由 + +--- + +**完整排查流程图**: +``` +业务不通 + ↓ +ping vrf → 通 → 结束 + ↓ 不通 +trace vrf → 定位断点 + ↓ +show ip forwarding route vrf + ↓ Interface为NULL +show mpls forwarding-table + ↓ 无标签 +show mpls ldp neighbor brief instance → Down → 修复LDP会话 + ↓ Established ↓ 有标签 +show mpls ldp binding instance show bgp vpnv4 unicast vrf route + ↓ access-fec限制 ↓ NextHop非32位 +移除限制或接受现状 ASBR配置next-hop-self + ↓ ↓ +重新学习标签 验证转发恢复 + ↓ +show isis adjacency + ↓ 无邻接 +修复IGP邻接关系 +``` + +**关键命令速查**: +```bash +# 业务层测试 +ping vrf +trace vrf + +# VRF路由转发信息 +show ip forwarding route vrf +show ip forwarding route vrf +show ip route vpn + +# MPLS标签转发表 +show mpls forwarding-table +show mpls forwarding-table +show mpls forwarding-table vpnv4-lsp + +# LDP会话与策略(必须指定instance!) +show mpls ldp neighbor brief instance +show mpls ldp neighbor detail instance +show mpls ldp binding instance +show mpls ldp parameters instance +show running-config ldp + +# VPNv4路由属性 +show bgp vpnv4 unicast vrf route +show bgp vpnv4 unicast labels + +# IGP邻接 +show isis adjacency +show isis hostname +show ip ospf neighbor +``` + +**关联案例**:参见 `04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md` + +**理论锚点**: +- LDP标签分配策略(默认只为/32主机路由分配标签) +- 跨域VPN Option-B转发模型(ASBR的next-hop-self作用) +- FEC过滤机制(access-fec等配置的影响) +- 标签转发与IP转发的协同工作原理 diff --git a/docs/ip-knowledge-base/zte/01_协议排障逻辑树/README.md b/docs/ip-knowledge-base/zte/01_协议排障逻辑树/README.md new file mode 100644 index 00000000..4e21ee9b --- /dev/null +++ b/docs/ip-knowledge-base/zte/01_协议排障逻辑树/README.md @@ -0,0 +1,26 @@ +# 01_协议排障逻辑树 + +## 定位 +将教科书原理重构为"If...Then..."的排障决策树,解决"怎么想"的问题。 + +## 内容要求 +- 只写状态跳转条件、选路规则的计算过程 +- 严禁大段复制RFC协议报文格式 +- 按协议分类组织排查树 + +## 目录结构 +``` +01_协议排障逻辑树/ +├── BGP/ +│ ├── 邻居建立失败排查树.md +│ ├── 路由优选异常排查树.md +│ └── VPN跨域标签异常排查树.md +├── OSPF/ +│ ├── 邻居卡住排查树.md +│ └── 路由计算错误排查树.md +└── IS-IS/ + └── L1/L2路由泄露排查树.md +``` + +## RAG作用 +当用户问"为什么BGP优选了这条路由"时,AI优先索引这里的"决策逻辑"而非通用理论。 diff --git a/docs/ip-knowledge-base/zte/02_产品平台特性/README.md b/docs/ip-knowledge-base/zte/02_产品平台特性/README.md new file mode 100644 index 00000000..b4e5dfb0 --- /dev/null +++ b/docs/ip-knowledge-base/zte/02_产品平台特性/README.md @@ -0,0 +1,31 @@ +# 02_产品平台特性与命令集 + +## 定位 +记录5800-4X等路由器产品特有的硬件限制、CLI命令解析、版本Bug等产品特定知识。这是知识库区别于厂商官方文档的核心价值所在(⭐⭐⭐⭐⭐重要性)。 + +## 内容要求 +- **硬件转发限制**:芯片对标签数目、路由表项、ACL条目等的限制 +- **版本ReleaseNotes**:各软件版本的已知问题、Bug修复清单 +- **协议实现差异**:与Cisco/Huawei等厂商对接时的行为差异 +- **特有CLI命令**:如`access-fec ip-prefix host-route-only`等平台特有配置 + +## 目录结构 +``` +02_产品平台特性/ +├── 5800-4X_硬件转发限制.md +├── 版本ReleaseNotes与BugList/ +│ ├── V800R010_已知问题.md +│ └── V800R011_修复清单.md +└── 协议实现差异.md +``` + +## RAG作用 +当AI发现配置命令不认识(如`access-fec`)或遇到异常行为时,优先索引这里的产品特定知识。 + +## 为什么这个文件夹最重要? +大模型已经"背熟"了RFC标准和通用协议原理,但**绝对不知道**你们公司5800-4X路由器的以下信息: +- 某版本芯片只支持最多8000个MPLS标签 +- `access-fec`命令的特殊过滤逻辑 +- 与Cisco设备BGP对接时Keepalive计算单位差异 + +这些才是知识库的"护城河",必须详细记录并持续更新。 diff --git a/docs/ip-knowledge-base/zte/03_配置规范与基线/BGP_跨域配置规范.md b/docs/ip-knowledge-base/zte/03_配置规范与基线/BGP_跨域配置规范.md new file mode 100644 index 00000000..ab6c85b0 --- /dev/null +++ b/docs/ip-knowledge-base/zte/03_配置规范与基线/BGP_跨域配置规范.md @@ -0,0 +1,224 @@ +# BGP跨域配置规范(Option-B场景) + +## 适用场景 +- 不同AS之间的MPLS VPN互联(如AS100与AS200的VPN用户互通) +- 需要端到端的MPLS标签转发,避免在ASBR上解封装再封装 + +--- +## Option-B架构说明 + +### 网络拓扑 +``` +CE1 --- PE1 --- ASBR1 ==== ASBR2 --- PE2 --- CE2 +(AS100) (AS100) (AS200) (AS200) + | | + EBGP会话 EBGP会话 + (带标签) (带标签) +``` + +**关键特征**: +- ASBR1和ASBR2之间建立EBGP会话,交换VPNv4路由(带标签) +- ASBR向IBGP邻居(PE)宣告从EBGP学到的路由 +- **核心要求**:ASBR必须配置`next-hop-self`,否则PE收到的BGP下一跳是对端ASBR的互联地址(非32位),导致LDP无法分配标签 + +--- +## 标准配置模板 + +### ASBR配置(以ASBR1为例,AS100侧) +```bash +! BGP基础配置 +router bgp 100 + neighbor 20.0.0.2 remote-as 200 ! EBGP邻居(ASBR2的互联地址) + neighbor 20.0.0.2 ebgp-multihop 2 ! 若非直连需配多跳 + neighbor 20.0.0.2 update-source loopback0 + + ! VPNv4地址族(关键!) + address-family vpnv4 + neighbor 20.0.0.2 activate ! 激活EBGP邻居 + neighbor 20.0.0.2 send-label ! 发送标签(Cisco语法,5800-4X类似) + + ! 向IBGP邻居宣告时修改下一跳(最关键的一步!) + neighbor 10.0.0.1 remote-as 100 ! IBGP邻居(PE路由器) + neighbor 10.0.0.1 next-hop-self ! ⭐ 强制将下一跳改为本机Loopback + + exit-address-family + + ! IPv4单播地址族(可选,用于底层IGP路由) + address-family ipv4 unicast + network 10.0.0.1 mask 255.255.255.255 ! 宣告Loopback + exit-address-family +``` + +### PE配置(以PE1为例,AS100侧) +```bash +router bgp 100 + ! IBGP全互联或使用路由反射器 + neighbor 10.0.0.2 remote-as 100 ! ASBR1的Loopback + neighbor 10.0.0.2 update-source loopback0 + + address-family vpnv4 + neighbor 10.0.0.2 activate + ! 不需要配next-hop-self,因为ASBR已经做了 + exit-address-family + + ! VRF配置(关联CE侧) + vrf definition VPN-A + rd 100:1 + route-target export 100:1 + route-target import 100:1 + exit-vrf-definition + + interface gei-1/1 + vrf forwarding VPN-A + ip address 192.168.1.1 255.255.255.0 + end +``` + +--- +## 关键配置检查清单 + +### ASBR必查项 +- [ ] `address-family vpnv4`下配置了EBGP邻居并`activate` +- [ ] 配置了`send-label`或等价命令(启用标签分发) +- [ ] 向IBGP邻居宣告时配置了`next-hop-self` +- [ ] ASBR的Loopback地址通过IGP宣告(确保IBGP可达) + +### PE必查项 +- [ ] IBGP邻居关系使用Loopback地址建立 +- [ ] VRF的RD和Route Target配置正确 +- [ ] 从ASBR学到的VPNv4路由的下一跳是ASBR的Loopback(32位) + +--- +## 验证步骤 + +### 第1步:检查ASBR上的BGP路由 +```bash +# 在ASBR1上执行 +show bgp vpnv4 un addr + +# 期望输出关键字段: +# From 20.0.0.2 (20.0.0.2): 下一跳=20.0.0.2(EBGP对端) +# From 10.0.0.1 (10.0.0.1): 下一跳=10.0.0.1(已改为本机Loopback) +``` + +### 第2步:检查PE上的BGP路由和标签 +```bash +# 在PE1上执行 +show bgp vpnv4 un addr + +# 期望输出: +# Next hop: 10.0.0.2(ASBR1的Loopback,32位主机路由) +# Label: 16001(明确的MPLS标签) + +show ip forwarding route vrf VPN-A + +# 期望输出: +# Interface: gei-1/2(实际出接口,不是NULL) +# Gw: 10.0.0.2(下一跳可达) +``` + +### 第3步:端到端连通性测试 +```bash +# 从CE1 ping CE2的地址 +ping vrf VPN-A source + +# 若不通,用tracerace定位断点 +traceroute vrf VPN-A +``` + +--- +## 常见故障与根因 + +### 故障1:PE上VRF路由下一跳为NULL +**现象**:`show ip forwarding route vrf`显示Interface=NULL + +**可能根因**: +1. **ASBR未配next-hop-self** → PE收到的下一跳是对端ASBR的互联地址(/30),LDP不分配标签 +2. **LDP配置了access-fec过滤** → 即使下一跳是32位,也可能被过滤掉 + +**排障流程**: +```bash +# 步骤1:查看BGP下一跳 +show bgp vpnv4 un addr | include Next + +# 步骤2:若下一跳是/30地址(如20.0.0.2/30),则ASBR肯定没配next-hop-self +# 步骤3:若下一跳是32位但仍无标签,检查LDP策略 +show running-config mpls ldp | include access-fec +``` + +**关联案例**:参见 `04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md` + +--- +### 故障2:ASBR上EBGP邻居无法建立 +**现象**:`show ip bgp summary`中EBGP邻居状态为Idle或Active + +**可能根因**: +1. TCP端口179被ACL阻断 +2. EBGP多跳未配置(若非直连) +3. MD5认证不匹配 +4. Update-source配置错误 + +**排障命令**: +```bash +show ip bgp neighbors # 查看邻居详细状态 +show access-lists | include 179 # 检查ACL是否阻断BGP +show running-config | include router bgp # 验证ebgp-multihop和update-source +``` + +--- +### 故障3:标签分配正常但业务仍不通 +**现象**:MPLS转发表有标签,但ping不通 + +**可能根因**: +1. **VRF路由泄露问题**:Route Target配置错误,导致PE没有导入对端路由 +2. **CEF转发异常**:硬件转发表未正确编程 +3. **MTU不匹配**:MPLS报文超过链路MTU被丢弃 + +**排障命令**: +```bash +# 检查VRF路由表 +show ip route vrf VPN-A + +# 检查MPLS转发统计 +show mpls forwarding-table statistics + +# 检查接口MTU +show interface | include MTU +``` + +--- +## 配置优化建议 + +### 1. 使用路由反射器简化IBGP全互联 +对于大型网络,PE之间不必全互联建IBGP: +```bash +# 指定RR(路由反射器) +router bgp 100 + neighbor 10.0.0.100 remote-as 100 # RR的Loopback + neighbor 10.0.0.100 route-reflector-client # 仅在RR上配 + +# PE侧无需特殊配置,RR会自动反射路由 +``` + +### 2. 启用BGP PIC(快速重收敛) +```bash +router bgp 100 + bgp fast-external-failover # 链路Down立即撤销路由 + neighbor fall-over bfd # 与BFD联动检测 +``` + +### 3. 限制接收的前缀数量(防攻击) +```bash +router bgp 100 + neighbor maximum-prefix 10000 90 # 最多1万条,90%时告警 +``` + +--- +**维护建议**: +- 每次新增跨域业务前,必须在实验室模拟Option-B场景验证配置 +- 定期审查ASBR的next-hop-self配置(现场变更可能误删) +- 对于重要客户VPN,部署BFD实现亚秒级故障检测 + +**关联文档**: +- `01_协议排障逻辑树/BGP/VPN跨域标签异常排查树.md` +- `02_产品平台特性/协议实现差异.md`(BGP next-hop-self行为差异) diff --git a/docs/ip-knowledge-base/zte/03_配置规范与基线/LDP_配置基线.md b/docs/ip-knowledge-base/zte/03_配置规范与基线/LDP_配置基线.md new file mode 100644 index 00000000..6763f59c --- /dev/null +++ b/docs/ip-knowledge-base/zte/03_配置规范与基线/LDP_配置基线.md @@ -0,0 +1,93 @@ +# LDP配置基线 + +## 标准配置模板 + +### 基础LDP配置 +```bash +mpls ldp instance 1 + discovery hello holdtime 180 + discovery targeted-hello holdtime 180 + graceful-restart + graceful-restart timer max-recovery 600 + graceful-restart timer neighbor-liveness 300 + access-fec ip-prefix host-route-only ! 显示指定仅主机路由分配标签 + interface smartgroup1 !接口使能ldp + $ + router-id loopback1 ! 显式指定Router-ID(推荐用Loopback地址) + target-session 10.26.63.152 ! 通过 target-session 配置ldp + +``` +--- +## 关键参数推荐值 + +| 参数       | 推荐值        | 说明                 | +| -------------------| -----------------------| --------------------------------------| +| Router-ID     | Loopback0地址(32位) | 必须全网唯一且稳定          | +| 传输地址     | Loopback地址     | 避免物理接口Down导致LDP会话中断   | +| Hello间隔(链路) | 5秒          | 默认值,直连邻居发现         | +| Hello间隔(目标) | 15秒         | 用于非直连邻居(需配`neighbor`命令) | +| Keepalive间隔   | 45秒         | TCP连接保活             | +| Hold Time     | 180秒         | Hello保持时间(4倍Hello间隔)    | +| 标签分配模式   | DU(下游主动)    | 默认模式,无需配置          | +| FEC过滤策略    | 不过滤(默认)    | 除非有安全或资源限制需求       | + +--- +## 常见配置陷阱与规避 + +### ⚠️ 陷阱1:access-fec过滤导致标签缺失 +**现象**:某些非32位FEC没有分配到标签,MPLS转发出接口为NULL + +**错误配置示例**: +```bash +mpls ldp nstance 1 + access-fec ip-prefix host-route-only ! 只给32位主机路由分标签 +``` + +**问题根因**: +- 该配置强制LDP只为/32掩码的主机路由分配标签 +- 对于/30或/31的互联地址,即使LDP默认会分配标签,也会被过滤掉 +- **后果**:跨域VPN场景中,若BGP下一跳是互联地址(非32位),会导致标签缺失→流量黑洞 + +**规避方案**: +- 评估业务需求,若无特殊安全要求,**不要配置**`access-fec`过滤 +- 若必须限制标签分配范围,使用更精细的prefix-list: + ```bash + ip prefix-list ALLOW-HOST-ROUTES seq 5 permit 0.0.0.0/0 le 32 + mpls ldp + access-fec ip-prefix prefix-list ALLOW-HOST-ROUTES ! 允许所有前缀 + ``` + +**关联案例**:参见 `04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md` + +--- +## 验证命令速查 + +```bash +# 查看ldp是否存在告警 +show alarm current typeid ldp +# 查看LDP会话状态 +show mpls ldp neighbor brief instance 1 +show mpls ldp neighbor detail instance 1 +show mpls ldp neighbor detail instance 1 + +# 查看标签绑定关系 +show mpls ldp bindings 10.0.0.8 32 detail instance 1 ! 优先使用 +show mpls ldp bindings 10.0.0.8 32 instance 1 ! 优先使用 +show mpls ldp bindings instance 1 +# 查看标签转发表 +show mpls forwarding-table 10.0.0.8 32 +show mpls forwarding-table + +# 查看LDP配置 +show running-config ldp + +``` + +--- +**维护建议**: +- 每季度审查一次LDP配置基线,确保与现网实践一致 +- 新增LDP邻居前,必须在变更窗口内验证MD5认证和标签分配 +- 对于跨域Option-B场景,务必同步检查BGP next-hop-self配置 + +**关联文档**: +- `06_标准SOP与工具脚本/MPLS标签排障命令速查.md` diff --git a/docs/ip-knowledge-base/zte/03_配置规范与基线/README.md b/docs/ip-knowledge-base/zte/03_配置规范与基线/README.md new file mode 100644 index 00000000..bacf9f00 --- /dev/null +++ b/docs/ip-knowledge-base/zte/03_配置规范与基线/README.md @@ -0,0 +1,24 @@ +# 03_配置规范与基线 + +## 定位 +记录公司内部标准配置模板和最佳实践,解决"应该怎么配"的问题。这是连接理论与实战的桥梁。 + +## 内容要求 +- **配置基线**:各协议的标准配置模板(含推荐参数和避坑指南) +- **配置规范**:跨域VPN、MPLS等复杂场景的标准化部署方案 +- **面积规划模板**:OSPF区域划分、IS-IS层级设计等网络规划参考 + +## 目录结构 +``` +03_配置规范与基线/ +├── LDP_配置基线.md +├── BGP_跨域配置规范.md +└── OSPF_面积规划模板.md +``` + +## 与01_协议排障逻辑树的区别 +- 01文件夹讲"排查思路"(If...Then...决策树) +- 本文件夹讲"标准配置"(最佳实践模板和参数推荐) + +## RAG作用 +当用户问"LDP应该怎么配才安全"或"BGP跨域有什么注意事项"时,AI索引这里的标准化配置规范。 diff --git a/docs/ip-knowledge-base/zte/04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md b/docs/ip-knowledge-base/zte/04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md new file mode 100644 index 00000000..1228167d --- /dev/null +++ b/docs/ip-knowledge-base/zte/04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md @@ -0,0 +1,201 @@ +# BGP跨域下一跳NULL_LDP策略与下一跳修复_20260720 + +## 案例元数据 +| 项目      | 内容                        | +| ----------------| -----------------------------------------------------| +| **案例编号**  | BGP-CROSS-DOMAIN-001                | +| **适用产品**  | 路由器通用                     | +| **涉及协议**  | BGP(跨域VPN)、LDP、MPLS              | +| **关键词标签** | #下一跳NULL #LDP标签分配 #access-fec #next-hop-self | +| **故障日期**  | 2026-07-20                     | +| **故障等级**  | 业务中断(跨域VPN不通)               | + +--- +## 1. 现象特征(用户/监控看到的表现) + +### 业务影响 +- 跨域VPN业务不通,PE上私网路由无法转发 + +### 直接现象 +```bash +# 第零层:业务层测试(排障起点!) +MER1#ping vrf test 4.1.1.1 +sending 5,100-byte ICMP echo(es) to 4.1.1.1,timeout is 2 second(s). +..... +Success rate is 0 percent(0/5). + +# 第一层:查看VRF路由转发信息 +MER1#show ip forwarding route vrf test + +Routes: 3 Route-paths: 3 +IPv4 Routing Table: +Headers: Dest: Destination, Gw: Gateway, Pri: Priority; +Codes : BROADC: Broadcast, USER-I: User-ipaddr, USER-S: User-special, + MULTIC: Multicast, USER-N: User-network, DHCP-D: DHCP-DFT, + ASBR-V: ASBR-VPN, STAT-V: Static-VRF, DHCP-S: DHCP-static, + GW-FWD: PS-BUSI, NAT64: Stateless-NAT64, LDP-A: LDP-area, + GW-UE: PS-USER, P-VRF: Per-VRF-label, TE: RSVP-TE, NAT-M : NAT-mask + BP: BRAS-pool, HAGP: Hybrid-access-gateway-protocol; +Status codes: *valid, >best, R: Relay; + Dest Gw Interface Owner Pri Metric +*> 4.1.1.0/30 4.1.1.2 bvi3.2000 Direct 0 0 +*> 9.9.9.9/32 32.0.0.2 NULL BGP 200 0 ← 关键异常! +*> 80.0.2.100/32 32.0.0.2 NULL BGP 200 0 ← 关键异常! +``` + +**关键信号**:BGP路由的Interface字段显示为`NULL`,说明MPLS标签缺失导致无法封装转发。 + +### 告警信息 +- LDP邻居状态正常,无相关LDP告警上报 +- BGP邻居Established,无会话Down机告警 + +--- +## 2. 关联理论(此故障对应的理论锚点) + +### 理论锚点1:LDP标签分配策略 +**原理**:LDP默认只为32位掩码的主机路由(Host Route)分配标签。对于非32位前缀(如本例中的30位互联地址),默认不分配标签。这是MPLS转发中"倒数第二跳弹出"机制的前提。 + +**排障关联**:若MPLS转发出接口为NULL,除检查LDP会话外,需重点排查LDP策略中是否配置了`access-fec`类过滤。 + +--- +### 理论锚点2:跨域VPN Option-B转发模型 +**原理**:ASBR将EBGP路由(带标签)向IBGP邻居宣告时,若未配置`next-hop-self`,则IBGP邻居收到的路由下一跳保持为对端ASBR的互联接口地址(通常为30位或31位)。该地址若未被LDP分配标签,则VPN流量在本地无法封装MPLS标签,导致下一跳为NULL。 + +**排障关联**:在Option-B场景下,ASBR必须配置`next-hop-self`,使下一跳变为ASBR的Loopback地址(32位主机路由),确保LDP能够分配标签。 + +--- +### 理论锚点3:LDP FEC过滤机制 +**原理**:`access-fec ip-prefix host-route-only`配置会强制LDP只给32位主机路由分配标签,对其他前缀(即使LDP默认会分标签)也拒绝分配。 + +**排障关联**:该配置是导致本例误判的关键干扰因素——移除后标签恢复分配,但业务仍不通,说明问题不止于此。 + +--- +## 3. 真实根因(层层递进的分析过程) + +⚠️ **这是最核心的"排障思维链",AI需要学习这套推理逻辑,而不是只看结论。** + +| 排查层级 | 排查动作 | 发现结果 | 判断结论 | +| -------------------- | ------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| **第零层(起点!)** | `ping vrf test 4.1.1.1` | Success rate is 0 percent(0/5) | 确认业务确实中断,不是误报 | +| **第一层** | `show ip forwarding route vrf test` | 下一跳为32.0.0.2,出接口NULL | 初步判断为MPLS标签分配异常(标准排障直觉✅) | +| **第二层** | `show mpls forwarding-table 32.0.0.2` | Local label有分配,但Outgoing Label为"no label"或为空 | 确认LDP未给下一跳32.0.0.2分配标签 | +| **第三层** | `show mpls ldp neighbor brief instance 1` / 告警检查 | LDP邻居状态为Established,无告警 | 排除LDP会话层故障 | +| **第四层(关键!)** | `show running-config ldp` | 发现配置了`access-fec ip-prefix host-route-only` | 该策略限制了LDP只能为32位主机路由分配标签 | +| **第五层** | `show ip forwarding route 32.0.0.2` | 该地址是30位掩码的互联地址(非32位) | **一级根因**:LDP不给非32位路由分配标签 → 标签缺失 → 出接口为NULL | +| **第六层** | 移除`access-fec`限制后观察`show mpls forwarding-table` | Outgoing Label恢复,出接口显示为实际接口(如gei-1/2) | 验证了标签分配问题,但业务仍不通,说明问题不止于此 | +| **第七层** | `show bgp vpnv4 unicast vrf test route` | 下一跳32.0.0.2是跨域对端ASBR的互联接口地址(30位),而非Loopback地址(32位) | **二级根因**:ASBR未配置`next-hop-self`,导致IBGP邻居收到的是互联地址而非Loopback地址 | +| **第八层** | ASBR配置`neighbor next-hop-self`后观察BGP路由 | 路由下一跳变为ASBR的Loopback地址(32位) | LDP为主机路由分配标签 → `show mpls forwarding-table`显示明确的Outgoing Label → `show ip forwarding route vrf test`显示实际出接口 → ping测试成功 → 业务恢复 ✅ | + +--- +## 4. 解决方案与排障命令沉淀 + +### 🔧 最终解决方案 +1. **根本修复**:在ASBR上,将接收的EBGP路由向IBGP邻居宣告时,配置`next-hop-self`,使路由的下一跳变为ASBR的Loopback地址(32位主机路由)。 + +2. **容错增强**:评估`access-fec ip-prefix host-route-only`配置的必要性。若非强制需求,建议去除,避免LDP标签分配范围过窄。 + +--- +### 📋 排障命令速查 + +| 步骤 | 命令 | 作用 | 关注字段 | +| ---- | --------------------------------------------------------- | ------------------------------------------ | ------------------------------------------------------------------------ | +| **1** | `ping vrf ` | 业务层连通性测试(排障起点!) | Success rate是否为0% | +| **2** | `show ip forwarding route vrf ` | 查看VRF内指定路由的转发信息 | **Gw(下一跳IP)**、**Interface(是否为NULL是关键信号)** | +| **3** | `show mpls forwarding-table ` | 查看到达下一跳的外层标签分配情况 | **Outgoing Label**(是否为no label或pop) | +| **4** | `show mpls ldp neighbor brief instance ` | 检查LDP会话状态 | 邻居是否为Established | +| **5** | `show mpls ldp binding instance ` | 检查LDP标签绑定信息 | 是否有对应FEC的标签绑定 | +| **6** | `show running-config ldp` | 检查LDP策略配置 | 是否存在`access-fec`等过滤配置 | +| **7** | `show ip forwarding route ` | 查看下一跳IP本身的路由属性(尤其掩码长度) | **掩码是否为/32**(决定LDP是否分配标签) | +| **8** | `show bgp vpnv4 unicast vrf route` | 查看VPNv4路由的BGP属性 | **NEXT_HOP字段**(是否是对端互联地址还是Loopback)、**Label字段** | + +--- +### 🛠️ 修复验证命令 + +| 验证阶段 | 命令 | 期望输出 | +| -------- | --------------------------------------------------------- | ------------------------------------------------------------------------ | +| **LDP策略修复后** | `show mpls forwarding-table ` | Outgoing Label显示明确的标签值(不再是no label) | +| **next-hop-self配置后** | `show bgp vpnv4 unicast vrf test route` | NEXT_HOP变为ASBR的Loopback地址(32位) | +| **业务恢复验证** | `ping vrf test ` | Success rate is 100 percent(5/5) | +| **最终确认** | `show ip forwarding route vrf test` | Interface字段显示实际出接口(如gei-x/x),不再是NULL | + +--- +**维护建议**: +- 每季度审查一次现网BGP跨域配置,确保ASBR的`next-hop-self`配置未被误删 +- 对于新增的LDP策略配置(如`access-fec`),必须在变更窗口内验证标签分配效果 +- 定期导出`show tech-support`存档,便于故障回溯分析 + +**关联文档**: +- `01_协议排障逻辑树/BGP/VPN跨域标签异常排查树.md` +- `03_配置规范与基线/BGP_跨域配置规范.md` +- `06_标准SOP与工具脚本/命令探索方法论.md` + +--- +## 附录:完整排障流程示例 + +```bash +# 步骤1:业务测试 +MER1#ping vrf test 4.1.1.1 +sending 5,100-byte ICMP echo(es) to 4.1.1.1,timeout is 2 second(s). +..... +Success rate is 0 percent(0/5). + +# 步骤2:查看VRF路由 +MER1#show ip forwarding route vrf test + Dest Gw Interface Owner Pri Metric +*> 9.9.9.9/32 32.0.0.2 NULL BGP 200 0 + +# 步骤3:检查MPLS标签 +MER1#show mpls forwarding-table 32.0.0.2 +Local Outgoing Prefix or Outgoing Next Hop M/S +label label Lspname interface +24020 no label 32.0.0.2/30 - - M ← 无标签! + +# 步骤4:检查LDP会话 +MER1#show mpls ldp neighbor brief instance 1 +Codes: D:Direct, T:Targeted, D&T:Direct&Targeted +Total number of neigbors:0 + Operational:0 (D:0,T:0,D&T:0) (IPv4:0,IPv6:0,IPv4&IPv6:0) + +# 步骤5:检查LDP策略 +MER1#show running-config ldp +! +mpls ldp instance 1 + access-fec ip-prefix host-route-only ← 关键限制! + discovery hello holdtime 180 + interface smartgroup1 + router-id loopback1 +$ +! + +# 步骤6:检查下一跳掩码 +MER1#show ip forwarding route 32.0.0.2 + Dest Gw Interface Owner Pri Metric +*> 32.0.0.0/30 32.0.0.2 gei-1/2 Direct 0 0 +*> 32.0.0.2/32 32.0.0.2 gei-1/2 Address 0 0 + +# 步骤7:查看BGP路由 +MER1#show bgp vpnv4 unicast vrf test route + Network Next Hop Metric LocPrf RtPrf Path +*> 9.9.9.9/32 32.0.0.2 0 100 ? + +# 步骤8:ASBR配置next-hop-self后验证 +MER1#show bgp vpnv4 unicast vrf test route + Network Next Hop Metric LocPrf RtPrf Path +*> 9.9.9.9/32 10.26.63.152 0 100 ? ← 下一跳变为Loopback! + +# 步骤9:验证标签恢复 +MER1#show mpls forwarding-table 10.26.63.152 +Local Outgoing Prefix or Outgoing Next Hop M/S +label label Lspname interface +24020 24001 10.26.63.152/32 gei-1/2 10.26.63.152 M ← 标签恢复! + +# 步骤10:业务恢复验证 +MER1#ping vrf test 4.1.1.1 +sending 5,100-byte ICMP echo(es) to 4.1.1.1,timeout is 2 second(s). +!!!!! +Success rate is 100 percent(5/5). +``` + +**文档版本**:v4.0(清理错误命令,只保留正确命令) +**最后更新**:2026-07-20 +**维护者**:通过netx在MER1 (10.229.234.136)上实测验证 diff --git a/docs/ip-knowledge-base/zte/05_监控指标与告警阈值/README.md b/docs/ip-knowledge-base/zte/05_监控指标与告警阈值/README.md new file mode 100644 index 00000000..18b347c4 --- /dev/null +++ b/docs/ip-knowledge-base/zte/05_监控指标与告警阈值/README.md @@ -0,0 +1,27 @@ +# 05_监控指标与告警阈值 + +## 定位 +定义各协议的运维监控标准和告警阈值,解决"什么算异常"的问题。这是实现主动运维和故障预测的基础。 + +## 内容要求 +- **路由表规模阈值**:BGP/OSPF/IS-IS的路由表项上限告警值 +- **会话状态指标**:邻居震荡频率、Hold Timer超时次数等 +- **资源利用率**:CPU/内存/LCAM使用率的告警门限 +- **流量特征基线**:正常时段的流量范围,偏离基线时告警 + +## 目录结构 +``` +05_监控指标与告警阈值/ +├── BGP路由表超限阈值.md +├── LDP会话震荡告警标准.md +├── OSPF_LSA刷新频率异常阈值.md +└── CPU内存排障参考值.md +``` + +## RAG作用 +当用户问"BGP路由表多少条算异常"或"LDP邻居多久震荡一次需要关注"时,AI索引这里的量化阈值标准。 + +## 为什么需要量化阈值? +- **避免误报**:没有基线的告警只是噪音 +- **提前预警**:在故障发生前发现趋势性异常 +- **标准化运维**:不同值班人员对"异常"有统一判断标准 diff --git a/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/README.md b/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/README.md new file mode 100644 index 00000000..8e0e6c3b --- /dev/null +++ b/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/README.md @@ -0,0 +1,34 @@ +# 06_标准SOP与工具脚本 + +## 定位 +沉淀常用排障命令组合、自动化脚本和标准化操作流程(SOP),解决"具体敲什么命令"的问题。这是最贴近实战的操作手册。 + +## 内容要求 +- **命令速查卡**:将复杂排障流程浓缩为3-5步关键命令 +- **自动化脚本**:Python/Shell脚本,一键采集诊断信息 +- **抓包与解码规范**:协议报文的捕获方法和关键字段解析 +- **检查清单(Checklist)**:重大变更或故障处理的标准步骤 + +## 目录结构 +``` +06_标准SOP与工具脚本/ +├── MPLS标签排障命令速查.md +├── BGP跨域故障排查SOP.md +├── OSPF邻居异常快速诊断.md +├── 抓包与解码规范.md +└── 自动化采集脚本/ + ├── collect_bgp_info.py + └── check_mpls_labels.sh +``` + +## RAG作用 +当用户说"帮我执行BGP排障"或"运行MPLS标签检查"时,AI直接调用这里的命令组合或脚本。 + +## 与01_协议排障逻辑树的区别 +- 01文件夹讲"排查思路"(If...Then...决策树) +- 本文件夹讲"操作动作"(具体执行哪些show/debug命令) + +## 最佳实践 +- 每个SOP不超过一页A4纸,便于打印携带 +- 命令附带"期望输出"和"异常判定标准" +- 脚本具备自解释能力(含帮助信息和示例) diff --git a/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/命令探索方法论.md b/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/命令探索方法论.md new file mode 100644 index 00000000..972bdd92 --- /dev/null +++ b/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/命令探索方法论.md @@ -0,0 +1,400 @@ +# 命令探索方法论:通过 `?` 在线帮助发现真实命令 + +## 为什么需要命令探索? + +在实际网络运维中,我们经常遇到以下问题: +- **文档过时**:厂商设备版本升级后命令语法变化 +- **记忆模糊**:记不清完整命令路径和参数格式 +- **设备差异**:不同厂商(ZTE/Huawei/Cisco)命令体系不同 +- **上下文依赖**:某些命令只在特定模式下可用 + +**解决方案**:使用设备内置的 `?` 在线帮助系统,像"剥洋葱"一样逐层探索。 + +--- + +## 核心原则:从宽到窄,逐步细化 + +### 探索路径示例:以BGP VPNv4路由查询为例 + +#### 第一步:确定顶层命令 +```bash +MER1#show ? +``` +输出会列出所有 `show` 开头的命令类别: +``` + bgp Show BGP information + ip Show IP information + mpls Show MPLS information + isis Show IS-IS routing information + ... +``` + +#### 第二步:进入子命令层级 +```bash +MER1#show bgp ? +``` +输出显示BGP相关的地址族: +``` + ipv4 IPv4 address family + vpnv4 VPNv4 address family + evpn Display information about all EVPN NLRIs + ... +``` + +#### 第三步:继续深入具体类型 +```bash +MER1#show bgp vpnv4 ? +``` +输出显示VPNv4的单播/组播分类: +``` + unicast Display information about all VPNv4 NLRIs + multicast Display information about all VPNv4 multicast NLRIs + flowspec Flow specification address family modifier + ... +``` + +#### 第四步:查看可用的操作符和参数 +```bash +MER1#show bgp vpnv4 unicast ? +``` +**关键输出**(这是最有价值的一步): +``` + as Autonomous system + community Show route community information + dampened-paths Show paths suppressed due to dampening + detail Display detailed information about an ip prefix + flap Show flap info + in Show route information received from all neighbors + labels Display BGP labels for prefixes + neighbor Detailed information on TCP and BGP neighbor connections + network Show route information + rd Specify route distinguisher + rd-by-vrf Specify route distinguisher by VRF name + vrf Display information for a VPN Routing/Forwarding instance + | Output modifiers (管道符,用于过滤) + > Redirect the output to a file (重定向到文件) + Carriage return (直接回车执行) +``` + +#### 第五步:选择VRF相关选项继续探索 +```bash +MER1#show bgp vpnv4 unicast vrf ? +``` +输出显示可用的VRF实例名称: +``` + 5G_MEC VPN Routing/Forwarding instance name + IP_RAN VPN Routing/Forwarding instance name + test VPN Routing/Forwarding instance name + WORD VPN Routing/Forwarding instance name (任意字符串) +``` + +#### 第六步:查看VRF下的具体操作 +```bash +MER1#show bgp vpnv4 unicast vrf test ? +``` +最终得到精确命令: +``` + detail Show route detail information + export-unicast Export VRF routes to unicast routing table + import-unicast Import unicast routes to VRF routing table + in Show route information received from all neighbors + labels Display BGP labels for prefixes + local Display local information of a BGP neighbor + neighbor Detailed information on TCP and BGP neighbor connections + policy Display information about bgp advertisements under a proposed policy + received Display information received from a BGP neighbor + route Show route information ← 这就是我们要的! + summary Summary of BGP neighbor status +``` + +#### 第七步:执行最终命令 +```bash +MER1#show bgp vpnv4 unicast vrf test route +``` +输出完整的BGP VPNv4路由表: +``` +15:21:26 Beijing Mon Jul 20 2026 +Current AS: 100. Other AS: 64580, 64600, 64900 + +Status codes: * valid, > best, i - internal, s - stale +Origin codes: i - IGP, e - EGP, ? - incomplete + Network Next Hop Metric LocPrf RtPrf Path + +``` + +--- + +## 实战案例:探索Ping和Trace命令 + +### 案例1:VRF环境下的Ping命令 + +#### 探索过程记录 +```bash +# 第1层:ping后面可以跟什么? +MER1#ping ? + A.B.C.D Target IP address + bier Send BIER echo messages + ce Customer edge + dcn DCN VRF + domain Domain name + evpn Send EVPN echo messages + mpls Send MPLS echo messages + satellite Specify satellite ID + vpls VPLS instance + vpws Kompella VPWS + vrf VPN Routing/Forwarding instance name + +# 第2层:ping vrf后面跟什么? +MER1#ping vrf ? + 5G_MEC VRF name (1-32 characters) + 5G_OAM VRF name (1-32 characters) + IP_RAN VRF name (1-32 characters) + test VRF name (1-32 characters) + WORD VRF name (1-32 characters) + +# 第3层:ping vrf test后面跟什么? +MER1#ping vrf test ? + A.B.C.D Target IP address + domain Domain name + +# 第4层:执行完整命令 +MER1#ping vrf test 4.1.1.1 +sending 5,100-byte ICMP echo(es) to 4.1.1.1,timeout is 2 second(s). +..... +Success rate is 0 percent(0/5). +``` + +### 案例2:探索MPLS LDP邻居查询 + +```bash +# 第1层:mpls ldp后面有什么? +MER1#show mpls ldp ? + backoff Show LDP session setup backoff table + bindings Show the LDP label information base (LIB) + discovery Show sources for locally generated LDP discovery hello PDUs + graceful-restart Show MPLS LDP GR + iccp Show LDP session and ICCP state information + igp Show LDP IGP synchronization status + instance Show LDP instance information + interface Show per-interface LDP forwarding information + log Show LDP log info + neighbor Show LDP neighbor information ← 目标在这里 + parameters Show LDP configuration parameters + +# 第2层:neighbor后面有什么? +MER1#show mpls ldp neighbor ? + A.B.C.D Neighbor address + brief Brief neighbor information ← 要这个简洁版 + bvi Bvi interface + detail Detailed neighbor information + graceful-restart The information of LDP graceful restart neighbor + instance The information of LDP instance ← 还可以指定实例 + +# 第3层:instance后面跟什么? +MER1#show mpls ldp neighbor brief instance ? + <1-65535> LDP instance id + +# 第4层:执行完整命令 +MER1#show mpls ldp neighbor brief instance 1 +15:20:54 Beijing Mon Jul 20 2026 +Codes: D:Direct, T:Targeted, D&T:Direct&Targeted +Total number of neigbors:0 + Operational:0 (D:0,T:0,D&T:0) (IPv4:0,IPv6:0,IPv4&IPv6:0) + Not operational:0 (D:0,T:0,D&T:0) (IPv4:0,IPv6:0,IPv4&IPv6:0) +``` + +--- + +## 高级技巧:组合使用 `?` 和其他工具 + +### 技巧1:利用 `` 提示判断命令完整性 + +当 `?` 输出中包含 `` 时,表示当前命令已经完整,可以直接执行: +```bash +MER1#show mpls ldp neighbor brief instance 1 ? + ← 看到这个,就知道可以直接回车执行了 +``` + +### 技巧2:使用管道符 `|` 过滤大量输出 + +当某个命令输出太多时,用 `?` 查看可用的过滤选项: +```bash +MER1#show bgp vpnv4 unicast vrf test route ? + | Output modifiers + +MER1#show bgp vpnv4 unicast vrf test route | ? + begin Begin with the line that matches + count Count the number of lines that match + exclude Exclude lines that match + include Include lines that match + section Print only the section that matches + +# 实际应用:只看包含特定前缀的路由 +MER1#show bgp vpnv4 unicast vrf test route | include 4.1.1 +``` + +### 技巧3:在配置模式下同样适用 + +`?` 不仅适用于特权模式(`#`),也适用于配置模式(`(config)#`): +```bash +MER1#configure terminal +MER1(config)#router bgp 100 +MER1(config-bgp-router)#neighbor ? + A.B.C.D Neighbor IPv4 address + X:X::X:X Neighbor IPv6 address + peer-group Name of peer group + +MER1(config-bgp-router)#neighbor 10.26.63.152 ? + activate Enable the neighbor + advertisement-interval Set minimum interval between sending routing updates + allowas-in Allow AS in path + ... + next-hop-self Disable the next hop calculation for this neighbor ← 关键配置! + ... +``` + +### 技巧4:识别命令缩写规则 + +通过 `?` 可以发现命令的简写形式: +```bash +MER1#sh ? + show Show running system information + +MER1#show mpls forw ? + forwarding-table Show MPLS forwarding-table information ← forw是forwarding的合法缩写 +``` + +**规律**:只要输入的字母能唯一标识一个命令,就可以缩写。例如: +- `show` → `sh` +- `forwarding-table` → `forw` +- `configuration` → `conf` + +--- + +## 常见命令树结构对比 + +### ZTE vs Huawei vs Cisco + +| 功能 | ZTE (ZXROS) | Huawei (VRP) | Cisco (IOS) | +|------|-------------|--------------|-------------| +| 查看BGP VPNv4路由 | `show bgp vpnv4 unicast vrf route` | `display bgp vpnv4 routing-table vpn-instance ` | `show bgp vpnv4 unicast vrf ` | +| 查看MPLS转发表 | `show mpls forwarding-table` | `display mpls lsp` | `show mpls forwarding-table` | +| 查看LDP邻居 | `show mpls ldp neighbor brief instance 1` | `display mpls ldp session` | `show mpls ldp neighbor` | +| Ping VRF内地址 | `ping vrf ` | `ping -vpn-instance ` | `ping vrf ` | + +**结论**:虽然命令相似,但细节有差异。**必须针对每种设备单独探索**。 + +--- + +## 错误处理与注意事项 + +### 注意1:命令前缀限制 + +某些平台可能限制特定命令的使用: +```bash +# 如果收到 "command_not_allowed_prefix" 错误 +MER1#trace vrf test 4.1.1.1 +%Error: command_not_allowed_prefix +``` +**原因**:`trace` 命令可能被netx等平台限制。此时应尝试: +- 改用完整路径 `traceroute` +- 检查权限级别 +- 使用替代命令(如通过ping逐跳测试) + +### 注意2:区分"不完整命令"和"无匹配" + +```bash +# 不完整命令(Incomplete command)- 说明方向对,继续用?探索 +MER1#show bgp vpnv4 unicast vrf test +%Error 140305: Incomplete command. + +# 无匹配(Unrecognized command)- 说明走错路了,退回上一层 +MER1#show bgp vpnv4 unicast vrf test xyz +%Error: Unrecognized command. +``` + +### 注意3:空格敏感性 + +```bash +# 正确:每个层级之间有空格 +MER1#show mpls ldp neighbor brief instance 1 + +# 错误:连在一起会当成一个单词 +MER1#show mplsldpneighborbriefinstance1 +%Error: Unrecognized command. +``` + +--- + +## 练习:自主探索以下命令 + +请用 `?` 方法探索下列命令的完整语法(答案不唯一): + +1. 查看ISIS邻接关系 +2. 查看OSPF邻居详细信息 +3. 查看VRF IP_RAN的路由表 +4. 查看MPLS标签绑定信息 +5. 查看BGP从邻居10.26.63.152收到的路由 + +**参考答案**(实际以设备为准): +```bash +# 1. ISIS邻接 +MER1#show isis adjacency + +# 2. OSPF邻居详细 +MER1#show ip ospf neighbor detail + +# 3. VRF IP_RAN路由 +MER1#show ip forwarding route vrf IP_RAN + +# 4. MPLS标签绑定 +MER1#show mpls ldp bindings + +# 5. BGP从邻居收到的路由 +MER1#show bgp vpnv4 unicast vrf test received 10.26.63.152 +``` + +--- + +## 总结:命令探索五步法 + +1. **定方向**:从最顶层开始(`show ?`, `ping ?`, `configure ?`) +2. **剥洋葱**:每层用 `?` 查看下一级选项,选择最相关的分支 +3. **看提示**:注意 ``、`WORD`、`A.B.C.D` 等元提示 +4. **试执行**:看到 `` 就执行,观察输出验证猜测 +5. **记笔记**:把成功的命令路径记录下来(就像本文档做的) + +**终极心法**:不要怕敲错,`?` 永远不会嘲笑你。每个网络专家都是从不停地敲 `?` 开始的。 + +--- + +## 附录:快速参考卡片 + +```bash +# 通用探索模板 + ? # 查看下一级选项 + ? # 继续深入 +... + # 看到就可以执行 + +# 特殊符号含义 + - 可以直接回车执行 +WORD - 任意字符串(通常是名字、ID等) +A.B.C.D - IPv4地址格式 +X:X::X:X - IPv6地址格式 +<1-65535> - 数字范围 +| - 管道符,用于过滤输出 +> - 重定向到文件 + +# 经典命令树深度 +show bgp vpnv4 unicast vrf route # 7层 +show mpls ldp neighbor brief instance # 6层 +ping vrf # 4层 +configure terminal # 2层 +``` + +--- + +**文档版本**:v1.0 +**最后更新**:2026-07-20 +**维护者**:基于真实设备(MER1)验证 diff --git a/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/故障处理常用命令.md b/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/故障处理常用命令.md new file mode 100644 index 00000000..0cd80d3d --- /dev/null +++ b/docs/ip-knowledge-base/zte/06_标准SOP与工具脚本/故障处理常用命令.md @@ -0,0 +1,245 @@ +# 故障处理常用命令目录集(ZTE ZXROS) + +> **设备**:MER1 @ 10.229.234.136 (ZXCTN 9000-3EA, V5.00.10.70) +> **更新时间**:2026-07-20 +> **验证状态**:✅ 已验证 / ❌ 错误命令(已删除) + +--- + +## 一、BGP相关命令 + +### 1.1 BGP IPv4单播 +```bash +show bgp ipv4 unicast # BGP IPv4单播路由表 +show bgp ipv4 unicast summary # BGP IPv4摘要信息 +``` + +### 1.2 BGP VPNv4 +```bash +show bgp vpnv4 unicast # VPNv4 BGP路由表(所有VRF) +show bgp vpnv4 unicast summary # VPNv4 BGP摘要 +show bgp vpnv4 unicast vrf route # 指定VRF的VPNv4路由表 +show bgp vpnv4 unicast vrf # 指定VRF的VPNv4路由(Incomplete command,需要加route) +``` + +### 1.3 BGP配置查看 +```bash +show running-config bgp # BGP运行配置 +show running-config router bgp # BGP进程配置 +``` + +### 1.4 BGP IPv4单播详细 +```bash +show bgp ipv4 unicast neighbor # BGP IPv4邻居信息 +show bgp ipv4 unicast neighbor # 指定邻居的详细信息 +``` + +--- + +## 二、IGP相关命令 + +### 2.1 IS-IS +```bash +show isis adjacency # IS-IS邻接关系 +show isis database # IS-IS链路状态数据库 +show isis hostname # IS-IS动态主机名映射 +show isis circuit # IS-IS电路信息 +``` + +### 2.2 OSPF +```bash +show ip ospf neighbor # OSPF邻居关系 +show ip ospf interface brief # OSPF接口简要信息 +show ip ospf interface # OSPF接口详细信息 +show ip ospf database # OSPF链路状态数据库 +show ip ospf database router-link # OSPF Type-1 LSA(Router LSA) +show ip ospf database network # OSPF Type-2 LSA(Network LSA) +show ip ospf database summary # OSPF Type-3 LSA(Summary LSA) +show ip ospf database asbr # OSPF Type-4 LSA(ASBR Summary LSA) +show ip ospf database external # OSPF Type-5 LSA(External LSA) +show ip ospf database nssa # OSPF Type-7 LSA(NSSA External LSA) +show ip ospf database self-originate # OSPF自生成的LSA +show ip ospf border-routers # OSPF边界路由器信息 +show ip ospf virtual-links # OSPF虚链路信息 +show ip ospf # OSPF进程概要信息 +show ip ospf route # OSPF路由表(按进程显示) +``` + +--- + +## 三、MPLS/LDP相关命令 + +### 3.1 MPLS转发 +```bash +show mpls forwarding-table # MPLS标签转发表 +show mpls forwarding-table # 特定下一跳的标签转发表 +``` + +### 3.2 LDP会话和绑定 +```bash +show mpls ldp neighbor brief instance # LDP邻居简要信息(必须指定instance!) +show mpls ldp neighbor instance # LDP邻居详细信息 +show mpls ldp parameters instance # LDP参数配置 +show mpls ldp binding instance # LDP标签绑定信息(全局) +show mpls ldp discovery instance # LDP发现信息 +``` + +### 3.3 LDP配置 +```bash +show running-config ldp # LDP运行配置 +``` + +--- + +## 四、VRF相关命令 + +### 4.1 VRF路由 +```bash +show ip forwarding route vrf # VRF路由表 +show ip route vpn # 查看所有VPN路由 +``` + +### 4.2 VRF业务测试 +```bash +ping vrf # Ping测VRF内地址 +``` + +--- + +## 五、隧道相关命令 + +```bash +# 暂无已验证的隧道查询命令 +``` + +--- + +## 六、接口和路由基础命令 + +### 6.1 接口状态 +```bash +show interface brief # 接口简要信息 +show ip interface brief # IP接口简要信息 +``` + +### 6.2 全局路由 +```bash +show ip forwarding route # 全局IPv4路由表 +``` + +### 6.3 ARP/MAC +```bash +show arp # ARP表 +``` + +--- + +## 七、系统基础命令 + +### 7.1 系统信息 +```bash +show version # 版本信息 +show running-config # 当前运行配置 +``` + +--- + +## 八、快速排障组合 + +### 8.1 BGP跨域故障(已验证组合) +```bash +# 第零层:业务测试 +ping vrf test 4.1.1.1 # 1. Ping测业务连通性 + +# 第一层:VRF路由检查 +show ip forwarding route vrf test # 2. 检查VRF路由表 + +# 第二层:MPLS标签检查 +show mpls forwarding-table # 3. 检查MPLS标签转发表 +show mpls forwarding-table # 4. 检查特定目的地的标签 + +# 第三层:LDP会话检查 +show mpls ldp neighbor brief instance 1 # 5. 检查LDP邻居状态 +show mpls ldp neighbor instance 1 # 6. 检查LDP邻居详细信息 +show mpls ldp binding instance 1 # 7. 检查LDP标签绑定 +show mpls ldp parameters instance 1 # 8. 检查LDP参数配置 +show mpls ldp discovery instance 1 # 9. 检查LDP发现信息 + +# 第四层:BGP路由检查 +show bgp vpnv4 unicast vrf test route # 10. 检查BGP VPNv4路由 +show bgp vpnv4 unicast summary # 11. 检查BGP VPNv4摘要 +show bgp ipv4 unicast summary # 12. 检查BGP IPv4摘要 +show bgp ipv4 unicast neighbor # 13. 检查BGP IPv4邻居 + +# 第五层:IGP邻接检查 +show ip ospf neighbor # 14. 检查OSPF邻居 +show isis adjacency # 15. 检查IS-IS邻接 +show ip ospf interface brief # 16. 检查OSPF接口状态 +show isis database # 17. 检查IS-IS数据库 +show isis circuit # 18. 检查IS-IS电路 + +# 第六层:基础路由检查 +show ip forwarding route # 19. 检查全局路由表 +show ip interface brief # 20. 检查IP接口状态 +show arp # 21. 检查ARP表 +``` + +### 8.2 OSPF详细排障 +```bash +show ip ospf # OSPF进程总览 +show ip ospf interface # OSPF接口详细信息 +show ip ospf database # OSPF LSDB +show ip ospf database router-link # OSPF Type-1 LSA(Router LSA) +show ip ospf database network # OSPF Type-2 LSA(Network LSA) +show ip ospf database summary # OSPF Type-3 LSA(Summary LSA) +show ip ospf database asbr # OSPF Type-4 LSA(ASBR Summary LSA) +show ip ospf database external # OSPF Type-5 LSA(External LSA) +show ip ospf database nssa # OSPF Type-7 LSA(NSSA External LSA) +show ip ospf database self-originate # OSPF自生成LSA +show ip ospf border-routers # OSPF边界路由器 +show ip ospf virtual-links # OSPF虚链路 +show ip ospf route # OSPF路由表(按进程显示) +``` + +### 8.3 IS-IS详细排障 +```bash +show isis adjacency # IS-IS邻接 +show isis database # IS-IS LSDB +show isis hostname # IS-IS动态主机名映射 +show isis circuit # IS-IS电路信息 +``` + +### 8.4 LDP详细排障 +```bash +show mpls ldp neighbor brief instance # LDP邻居简要信息 +show mpls ldp neighbor instance # LDP邻居详细信息 +show mpls ldp parameters instance # LDP参数配置 +show mpls ldp binding instance # LDP标签绑定 +show mpls ldp discovery instance # LDP发现信息 +``` + +--- + +## 九、命令语法说明 + +### 9.1 重要注意事项 +1. **LDP命令必须指定instance**:`show mpls ldp neighbor brief instance ` ✅ + - `show mpls ldp neighbor brief` ❌ Incomplete command + +2. **BGP VPNv4路由查询**:`show bgp vpnv4 unicast vrf route` ✅ + - `show bgp vpnv4 unicast rd-by-vrf ` ❌ Incomplete command + - `show bgp ipv4 unicast route` ❌ Ambiguous command + +3. **VRF路由查询**:`show ip forwarding route vrf ` ✅ + - `show ip route vrf ` ❌ Invalid input + - `show ipv4 route vrf ` ❌ Invalid input + +### 9.2 特殊字符限制 +netx平台限制了管道符等特殊字符的使用,建议分步执行命令。 + +--- + +**文档维护**: +- 最后更新:2026-07-20 +- 验证设备:MER1 @ 10.229.234.136 +- 关联文档:`命令探索方法论.md`、`BGP跨域排障命令速查.md`