增加知识文档

This commit is contained in:
hans 2026-07-21 19:01:49 +08:00
parent f3152acb88
commit db1d89d83b
11 changed files with 1461 additions and 0 deletions

View file

@ -0,0 +1,156 @@
# BGP VPN跨域标签异常排查树
## 现象:VRF路由下一跳为NULL或出接口为NULL
### 第零层排查:业务层连通性测试(起点!)
#### 子步骤0.1:Ping测业务地址
- **命令**:`ping vrf <vrf-name> <dest-ip>`
- **示例**:`ping vrf test 4.1.1.1`
- **目的**:确认业务是否真正中断,区分是路由问题还是转发问题
- **预期结果**:
- 通 → 业务正常,无需进一步排查
- 不通 → 进入下一步trace定位断点
#### 子步骤0.2:Trace定位路径
- **命令**:`trace vrf <vrf-name> <dest-ip>`
- **目的**:确定报文在哪一跳丢失,判断是本地问题还是远端问题
- **典型场景**:
- 第一跳就失败 → 本地VRF路由或直连问题
- 中间某跳失败 → 该节点标签或IGP问题
- 能到最后一跳但不通 → 对端CE设备或业务侧问题
---
### If `show ip forwarding route vrf <vrf-name>`显示Interface为NULL
- **Then第一层排查:MPLS标签分配**
- `show mpls forwarding-table <next-hop-ip>` → 查看Outgoing Label
- 若为"no label"或"pop",说明LDP未分配标签
#### 子步骤1.1:检查LDP会话状态
- `show mpls ldp neighbor brief instance <instance-id>` → 确认LDP邻居为Established
- `show mpls ldp neighbor detail instance <id>` → 查看标签分发能力
#### 子步骤1.2:检查LDP策略配置(关键!)
- `show running-config ldp` → 查找access-fec、fec-filter等过滤配置
- `show mpls ldp binding instance <id>` → 查看实际分配的标签绑定
- **常见陷阱**:`access-fec ip-prefix host-route-only`会强制LDP只给32位主机路由分配标签
- **排障动作**:评估必要性,若非强制需求则去除该限制
- **示例输出**:
```
!<ldp>
mpls ldp instance 1
access-fec ip-prefix host-route-only
discovery hello holdtime 180
discovery targeted-hello holdtime 180
interface smartgroup1
router-id loopback1
target-session 10.26.63.152
$
!</ldp>
```
#### 子步骤1.3:检查下一跳地址的掩码长度
- `show ip forwarding route <next-hop-ip>` → 查看掩码是否为/32
- **原理**:LDP默认只为32位主机路由分配标签(倒数第二跳弹出机制前提)
- 若为/30或/31互联地址,LDP可能不分配标签
---
### If 标签分配正常但业务仍不通
- **Then第二层排查:BGP下一跳属性**
- `show bgp vpnv4 unicast vrf <vrf-name> route` → 查看完整的BGP VPNv4路由表
- `show bgp vpnv4 unicast labels` → 查看标签信息
- **关键字段**:Next Hop(下一跳)、Label(标签)、Path(AS_PATH)
#### 子步骤2.1:检查ASBR配置
- 登录对端ASBR,查看BGP配置
- **关键配置缺失**:ASBR向IBGP宣告EBGP路由时未配置`neighbor <ibgp-peer> next-hop-self`
- **排障动作**:在ASBR上配置`neighbor <ibgp-peer> next-hop-self`
- **验证命令**:`show bgp vpnv4 unicast vrf <vrf-name> neighbor <peer-ip> advertised-routes`
#### 子步骤2.2:验证修复效果
- 配置next-hop-self后,PE上BGP路由的下一跳应变为ASBR的Loopback地址(32位)
- LDP为主机路由分配标签 → `show mpls forwarding-table`应显示明确的Outgoing Label
- `show ip forwarding route vrf <vrf-name>`应显示实际出接口
---
### If BGP路由正常但IGP不可达
- **Then第三层排查:IGP邻接关系**
- `show isis adjacency` → 检查ISIS邻接状态
- `show isis hostname` → 查看系统ID映射
- `show ip ospf neighbor` → 检查OSPF邻居状态
#### 子步骤3.1:检查IGP拓扑同步
- `show isis database` → 查看LSDB完整性
- `show ip ospf database` → 检查OSPF链路状态数据库
- **常见问题**:IGP未学习到BGP下一跳的路由
---
**完整排查流程图**:
```
业务不通
↓
ping vrf <vrf-name> <dest-ip> → 通 → 结束
↓ 不通
trace vrf <vrf-name> <dest-ip> → 定位断点
↓
show ip forwarding route vrf <vrf-name>
↓ Interface为NULL
show mpls forwarding-table <next-hop-ip>
↓ 无标签
show mpls ldp neighbor brief instance <id> → Down → 修复LDP会话
↓ Established ↓ 有标签
show mpls ldp binding instance <id> show bgp vpnv4 unicast vrf <name> route
↓ access-fec限制 ↓ NextHop非32位
移除限制或接受现状 ASBR配置next-hop-self
↓ ↓
重新学习标签 验证转发恢复
↓
show isis adjacency
↓ 无邻接
修复IGP邻接关系
```
**关键命令速查**:
```bash
# 业务层测试
ping vrf <vrf-name> <dest-ip>
trace vrf <vrf-name> <dest-ip>
# VRF路由转发信息
show ip forwarding route vrf <vrf-name>
show ip forwarding route vrf <vrf-name> <dest-ip>
show ip route vpn
# MPLS标签转发表
show mpls forwarding-table
show mpls forwarding-table <next-hop-ip>
show mpls forwarding-table vpnv4-lsp
# LDP会话与策略(必须指定instance!)
show mpls ldp neighbor brief instance <id>
show mpls ldp neighbor detail instance <id>
show mpls ldp binding instance <id>
show mpls ldp parameters instance <id>
show running-config ldp
# VPNv4路由属性
show bgp vpnv4 unicast vrf <vrf-name> route
show bgp vpnv4 unicast labels
# IGP邻接
show isis adjacency
show isis hostname
show ip ospf neighbor
```
**关联案例**:参见 `04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md`
**理论锚点**:
- LDP标签分配策略(默认只为/32主机路由分配标签)
- 跨域VPN Option-B转发模型(ASBR的next-hop-self作用)
- FEC过滤机制(access-fec等配置的影响)
- 标签转发与IP转发的协同工作原理

View file

@ -0,0 +1,26 @@
# 01_协议排障逻辑树
## 定位
将教科书原理重构为"If...Then..."的排障决策树,解决"怎么想"的问题。
## 内容要求
- 只写状态跳转条件、选路规则的计算过程
- 严禁大段复制RFC协议报文格式
- 按协议分类组织排查树
## 目录结构
```
01_协议排障逻辑树/
├── BGP/
│ ├── 邻居建立失败排查树.md
│ ├── 路由优选异常排查树.md
│ └── VPN跨域标签异常排查树.md
├── OSPF/
│ ├── 邻居卡住排查树.md
│ └── 路由计算错误排查树.md
└── IS-IS/
└── L1/L2路由泄露排查树.md
```
## RAG作用
当用户问"为什么BGP优选了这条路由"时,AI优先索引这里的"决策逻辑"而非通用理论。

View file

@ -0,0 +1,31 @@
# 02_产品平台特性与命令集
## 定位
记录5800-4X等路由器产品特有的硬件限制、CLI命令解析、版本Bug等产品特定知识。这是知识库区别于厂商官方文档的核心价值所在(⭐⭐⭐⭐⭐重要性)。
## 内容要求
- **硬件转发限制**:芯片对标签数目、路由表项、ACL条目等的限制
- **版本ReleaseNotes**:各软件版本的已知问题、Bug修复清单
- **协议实现差异**:与Cisco/Huawei等厂商对接时的行为差异
- **特有CLI命令**:如`access-fec ip-prefix host-route-only`等平台特有配置
## 目录结构
```
02_产品平台特性/
├── 5800-4X_硬件转发限制.md
├── 版本ReleaseNotes与BugList/
│ ├── V800R010_已知问题.md
│ └── V800R011_修复清单.md
└── 协议实现差异.md
```
## RAG作用
当AI发现配置命令不认识(如`access-fec`)或遇到异常行为时,优先索引这里的产品特定知识。
## 为什么这个文件夹最重要?
大模型已经"背熟"了RFC标准和通用协议原理,但**绝对不知道**你们公司5800-4X路由器的以下信息:
- 某版本芯片只支持最多8000个MPLS标签
- `access-fec`命令的特殊过滤逻辑
- 与Cisco设备BGP对接时Keepalive计算单位差异
这些才是知识库的"护城河",必须详细记录并持续更新。

View file

@ -0,0 +1,224 @@
# BGP跨域配置规范(Option-B场景)
## 适用场景
- 不同AS之间的MPLS VPN互联(如AS100与AS200的VPN用户互通)
- 需要端到端的MPLS标签转发,避免在ASBR上解封装再封装
---
## Option-B架构说明
### 网络拓扑
```
CE1 --- PE1 --- ASBR1 ==== ASBR2 --- PE2 --- CE2
(AS100) (AS100) (AS200) (AS200)
| |
EBGP会话 EBGP会话
(带标签) (带标签)
```
**关键特征**:
- ASBR1和ASBR2之间建立EBGP会话,交换VPNv4路由(带标签)
- ASBR向IBGP邻居(PE)宣告从EBGP学到的路由
- **核心要求**:ASBR必须配置`next-hop-self`,否则PE收到的BGP下一跳是对端ASBR的互联地址(非32位),导致LDP无法分配标签
---
## 标准配置模板
### ASBR配置(以ASBR1为例,AS100侧)
```bash
! BGP基础配置
router bgp 100
neighbor 20.0.0.2 remote-as 200 ! EBGP邻居(ASBR2的互联地址)
neighbor 20.0.0.2 ebgp-multihop 2 ! 若非直连需配多跳
neighbor 20.0.0.2 update-source loopback0
! VPNv4地址族(关键!)
address-family vpnv4
neighbor 20.0.0.2 activate ! 激活EBGP邻居
neighbor 20.0.0.2 send-label ! 发送标签(Cisco语法,5800-4X类似)
! 向IBGP邻居宣告时修改下一跳(最关键的一步!)
neighbor 10.0.0.1 remote-as 100 ! IBGP邻居(PE路由器)
neighbor 10.0.0.1 next-hop-self ! ⭐ 强制将下一跳改为本机Loopback
exit-address-family
! IPv4单播地址族(可选,用于底层IGP路由)
address-family ipv4 unicast
network 10.0.0.1 mask 255.255.255.255 ! 宣告Loopback
exit-address-family
```
### PE配置(以PE1为例,AS100侧)
```bash
router bgp 100
! IBGP全互联或使用路由反射器
neighbor 10.0.0.2 remote-as 100 ! ASBR1的Loopback
neighbor 10.0.0.2 update-source loopback0
address-family vpnv4
neighbor 10.0.0.2 activate
! 不需要配next-hop-self,因为ASBR已经做了
exit-address-family
! VRF配置(关联CE侧)
vrf definition VPN-A
rd 100:1
route-target export 100:1
route-target import 100:1
exit-vrf-definition
interface gei-1/1
vrf forwarding VPN-A
ip address 192.168.1.1 255.255.255.0
end
```
---
## 关键配置检查清单
### ASBR必查项
- [ ] `address-family vpnv4`下配置了EBGP邻居并`activate`
- [ ] 配置了`send-label`或等价命令(启用标签分发)
- [ ] 向IBGP邻居宣告时配置了`next-hop-self`
- [ ] ASBR的Loopback地址通过IGP宣告(确保IBGP可达)
### PE必查项
- [ ] IBGP邻居关系使用Loopback地址建立
- [ ] VRF的RD和Route Target配置正确
- [ ] 从ASBR学到的VPNv4路由的下一跳是ASBR的Loopback(32位)
---
## 验证步骤
### 第1步:检查ASBR上的BGP路由
```bash
# 在ASBR1上执行
show bgp vpnv4 un addr <dest-prefix>
# 期望输出关键字段:
# From 20.0.0.2 (20.0.0.2): 下一跳=20.0.0.2(EBGP对端)
# From 10.0.0.1 (10.0.0.1): 下一跳=10.0.0.1(已改为本机Loopback)
```
### 第2步:检查PE上的BGP路由和标签
```bash
# 在PE1上执行
show bgp vpnv4 un addr <dest-prefix>
# 期望输出:
# Next hop: 10.0.0.2(ASBR1的Loopback,32位主机路由)
# Label: 16001(明确的MPLS标签)
show ip forwarding route vrf VPN-A <dest-prefix>
# 期望输出:
# Interface: gei-1/2(实际出接口,不是NULL)
# Gw: 10.0.0.2(下一跳可达)
```
### 第3步:端到端连通性测试
```bash
# 从CE1 ping CE2的地址
ping vrf VPN-A <CE2-IP> source <CE1-IP>
# 若不通,用tracerace定位断点
traceroute vrf VPN-A <CE2-IP>
```
---
## 常见故障与根因
### 故障1:PE上VRF路由下一跳为NULL
**现象**:`show ip forwarding route vrf`显示Interface=NULL
**可能根因**:
1. **ASBR未配next-hop-self** → PE收到的下一跳是对端ASBR的互联地址(/30),LDP不分配标签
2. **LDP配置了access-fec过滤** → 即使下一跳是32位,也可能被过滤掉
**排障流程**:
```bash
# 步骤1:查看BGP下一跳
show bgp vpnv4 un addr <prefix> | include Next
# 步骤2:若下一跳是/30地址(如20.0.0.2/30),则ASBR肯定没配next-hop-self
# 步骤3:若下一跳是32位但仍无标签,检查LDP策略
show running-config mpls ldp | include access-fec
```
**关联案例**:参见 `04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md`
---
### 故障2:ASBR上EBGP邻居无法建立
**现象**:`show ip bgp summary`中EBGP邻居状态为Idle或Active
**可能根因**:
1. TCP端口179被ACL阻断
2. EBGP多跳未配置(若非直连)
3. MD5认证不匹配
4. Update-source配置错误
**排障命令**:
```bash
show ip bgp neighbors <ip> # 查看邻居详细状态
show access-lists | include 179 # 检查ACL是否阻断BGP
show running-config | include router bgp # 验证ebgp-multihop和update-source
```
---
### 故障3:标签分配正常但业务仍不通
**现象**:MPLS转发表有标签,但ping不通
**可能根因**:
1. **VRF路由泄露问题**:Route Target配置错误,导致PE没有导入对端路由
2. **CEF转发异常**:硬件转发表未正确编程
3. **MTU不匹配**:MPLS报文超过链路MTU被丢弃
**排障命令**:
```bash
# 检查VRF路由表
show ip route vrf VPN-A
# 检查MPLS转发统计
show mpls forwarding-table statistics
# 检查接口MTU
show interface <interface> | include MTU
```
---
## 配置优化建议
### 1. 使用路由反射器简化IBGP全互联
对于大型网络,PE之间不必全互联建IBGP:
```bash
# 指定RR(路由反射器)
router bgp 100
neighbor 10.0.0.100 remote-as 100 # RR的Loopback
neighbor 10.0.0.100 route-reflector-client # 仅在RR上配
# PE侧无需特殊配置,RR会自动反射路由
```
### 2. 启用BGP PIC(快速重收敛)
```bash
router bgp 100
bgp fast-external-failover # 链路Down立即撤销路由
neighbor <ip> fall-over bfd # 与BFD联动检测
```
### 3. 限制接收的前缀数量(防攻击)
```bash
router bgp 100
neighbor <ip> maximum-prefix 10000 90 # 最多1万条,90%时告警
```
---
**维护建议**:
- 每次新增跨域业务前,必须在实验室模拟Option-B场景验证配置
- 定期审查ASBR的next-hop-self配置(现场变更可能误删)
- 对于重要客户VPN,部署BFD实现亚秒级故障检测
**关联文档**:
- `01_协议排障逻辑树/BGP/VPN跨域标签异常排查树.md`
- `02_产品平台特性/协议实现差异.md`(BGP next-hop-self行为差异)

View file

@ -0,0 +1,93 @@
# LDP配置基线
## 标准配置模板
### 基础LDP配置
```bash
mpls ldp instance 1
discovery hello holdtime 180
discovery targeted-hello holdtime 180
graceful-restart
graceful-restart timer max-recovery 600
graceful-restart timer neighbor-liveness 300
access-fec ip-prefix host-route-only ! 显示指定仅主机路由分配标签
interface smartgroup1 !接口使能ldp
$
router-id loopback1 ! 显式指定Router-ID(推荐用Loopback地址)
target-session 10.26.63.152 ! 通过 target-session 配置ldp
```
---
## 关键参数推荐值
| 参数       | 推荐值        | 说明                 |
| -------------------| -----------------------| --------------------------------------|
| Router-ID     | Loopback0地址(32位) | 必须全网唯一且稳定          |
| 传输地址     | Loopback地址     | 避免物理接口Down导致LDP会话中断   |
| Hello间隔(链路) | 5秒          | 默认值,直连邻居发现         |
| Hello间隔(目标) | 15秒         | 用于非直连邻居(需配`neighbor`命令) |
| Keepalive间隔   | 45秒         | TCP连接保活             |
| Hold Time     | 180秒         | Hello保持时间(4倍Hello间隔)    |
| 标签分配模式   | DU(下游主动)    | 默认模式,无需配置          |
| FEC过滤策略    | 不过滤(默认)    | 除非有安全或资源限制需求       |
---
## 常见配置陷阱与规避
### ⚠️ 陷阱1:access-fec过滤导致标签缺失
**现象**:某些非32位FEC没有分配到标签,MPLS转发出接口为NULL
**错误配置示例**:
```bash
mpls ldp nstance 1
access-fec ip-prefix host-route-only ! 只给32位主机路由分标签
```
**问题根因**:
- 该配置强制LDP只为/32掩码的主机路由分配标签
- 对于/30或/31的互联地址,即使LDP默认会分配标签,也会被过滤掉
- **后果**:跨域VPN场景中,若BGP下一跳是互联地址(非32位),会导致标签缺失→流量黑洞
**规避方案**:
- 评估业务需求,若无特殊安全要求,**不要配置**`access-fec`过滤
- 若必须限制标签分配范围,使用更精细的prefix-list:
```bash
ip prefix-list ALLOW-HOST-ROUTES seq 5 permit 0.0.0.0/0 le 32
mpls ldp
access-fec ip-prefix prefix-list ALLOW-HOST-ROUTES ! 允许所有前缀
```
**关联案例**:参见 `04_历史故障案例库/BGP/标签与LDP类/BGP_跨域下一跳NULL_LDP策略与下一跳修复_20260720.md`
---
## 验证命令速查
```bash
# 查看ldp是否存在告警
show alarm current typeid ldp
# 查看LDP会话状态
show mpls ldp neighbor brief instance 1
show mpls ldp neighbor <ldp-neighbor> detail instance 1
show mpls ldp neighbor detail instance 1
# 查看标签绑定关系
show mpls ldp bindings 10.0.0.8 32 detail instance 1 ! 优先使用
show mpls ldp bindings 10.0.0.8 32 instance 1 ! 优先使用
show mpls ldp bindings instance 1
# 查看标签转发表
show mpls forwarding-table 10.0.0.8 32
show mpls forwarding-table
# 查看LDP配置
show running-config ldp
```
---
**维护建议**:
- 每季度审查一次LDP配置基线,确保与现网实践一致
- 新增LDP邻居前,必须在变更窗口内验证MD5认证和标签分配
- 对于跨域Option-B场景,务必同步检查BGP next-hop-self配置
**关联文档**:
- `06_标准SOP与工具脚本/MPLS标签排障命令速查.md`

View file

@ -0,0 +1,24 @@
# 03_配置规范与基线
## 定位
记录公司内部标准配置模板和最佳实践,解决"应该怎么配"的问题。这是连接理论与实战的桥梁。
## 内容要求
- **配置基线**:各协议的标准配置模板(含推荐参数和避坑指南)
- **配置规范**:跨域VPN、MPLS等复杂场景的标准化部署方案
- **面积规划模板**:OSPF区域划分、IS-IS层级设计等网络规划参考
## 目录结构
```
03_配置规范与基线/
├── LDP_配置基线.md
├── BGP_跨域配置规范.md
└── OSPF_面积规划模板.md
```
## 与01_协议排障逻辑树的区别
- 01文件夹讲"排查思路"(If...Then...决策树)
- 本文件夹讲"标准配置"(最佳实践模板和参数推荐)
## RAG作用
当用户问"LDP应该怎么配才安全"或"BGP跨域有什么注意事项"时,AI索引这里的标准化配置规范。

View file

@ -0,0 +1,201 @@
# BGP跨域下一跳NULL_LDP策略与下一跳修复_20260720
## 案例元数据
| 项目      | 内容                        |
| ----------------| -----------------------------------------------------|
| **案例编号**  | BGP-CROSS-DOMAIN-001                |
| **适用产品**  | 路由器通用                     |
| **涉及协议**  | BGP(跨域VPN)、LDP、MPLS              |
| **关键词标签** | #下一跳NULL #LDP标签分配 #access-fec #next-hop-self |
| **故障日期**  | 2026-07-20                     |
| **故障等级**  | 业务中断(跨域VPN不通)               |
---
## 1. 现象特征(用户/监控看到的表现)
### 业务影响
- 跨域VPN业务不通,PE上私网路由无法转发
### 直接现象
```bash
# 第零层:业务层测试(排障起点!)
MER1#ping vrf test 4.1.1.1
sending 5,100-byte ICMP echo(es) to 4.1.1.1,timeout is 2 second(s).
.....
Success rate is 0 percent(0/5).
# 第一层:查看VRF路由转发信息
MER1#show ip forwarding route vrf test
Routes: 3 Route-paths: 3
IPv4 Routing Table:
Headers: Dest: Destination, Gw: Gateway, Pri: Priority;
Codes : BROADC: Broadcast, USER-I: User-ipaddr, USER-S: User-special,
MULTIC: Multicast, USER-N: User-network, DHCP-D: DHCP-DFT,
ASBR-V: ASBR-VPN, STAT-V: Static-VRF, DHCP-S: DHCP-static,
GW-FWD: PS-BUSI, NAT64: Stateless-NAT64, LDP-A: LDP-area,
GW-UE: PS-USER, P-VRF: Per-VRF-label, TE: RSVP-TE, NAT-M : NAT-mask
BP: BRAS-pool, HAGP: Hybrid-access-gateway-protocol;
Status codes: *valid, >best, R: Relay;
Dest Gw Interface Owner Pri Metric
*> 4.1.1.0/30 4.1.1.2 bvi3.2000 Direct 0 0
*> 9.9.9.9/32 32.0.0.2 NULL BGP 200 0 ← 关键异常!
*> 80.0.2.100/32 32.0.0.2 NULL BGP 200 0 ← 关键异常!
```
**关键信号**:BGP路由的Interface字段显示为`NULL`,说明MPLS标签缺失导致无法封装转发。
### 告警信息
- LDP邻居状态正常,无相关LDP告警上报
- BGP邻居Established,无会话Down机告警
---
## 2. 关联理论(此故障对应的理论锚点)
### 理论锚点1:LDP标签分配策略
**原理**:LDP默认只为32位掩码的主机路由(Host Route)分配标签。对于非32位前缀(如本例中的30位互联地址),默认不分配标签。这是MPLS转发中"倒数第二跳弹出"机制的前提。
**排障关联**:若MPLS转发出接口为NULL,除检查LDP会话外,需重点排查LDP策略中是否配置了`access-fec`类过滤。
---
### 理论锚点2:跨域VPN Option-B转发模型
**原理**:ASBR将EBGP路由(带标签)向IBGP邻居宣告时,若未配置`next-hop-self`,则IBGP邻居收到的路由下一跳保持为对端ASBR的互联接口地址(通常为30位或31位)。该地址若未被LDP分配标签,则VPN流量在本地无法封装MPLS标签,导致下一跳为NULL。
**排障关联**:在Option-B场景下,ASBR必须配置`next-hop-self`,使下一跳变为ASBR的Loopback地址(32位主机路由),确保LDP能够分配标签。
---
### 理论锚点3:LDP FEC过滤机制
**原理**:`access-fec ip-prefix host-route-only`配置会强制LDP只给32位主机路由分配标签,对其他前缀(即使LDP默认会分标签)也拒绝分配。
**排障关联**:该配置是导致本例误判的关键干扰因素——移除后标签恢复分配,但业务仍不通,说明问题不止于此。
---
## 3. 真实根因(层层递进的分析过程)
⚠️ **这是最核心的"排障思维链",AI需要学习这套推理逻辑,而不是只看结论。**
| 排查层级 | 排查动作 | 发现结果 | 判断结论 |
| -------------------- | ------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **第零层(起点!)** | `ping vrf test 4.1.1.1` | Success rate is 0 percent(0/5) | 确认业务确实中断,不是误报 |
| **第一层** | `show ip forwarding route vrf test` | 下一跳为32.0.0.2,出接口NULL | 初步判断为MPLS标签分配异常(标准排障直觉✅) |
| **第二层** | `show mpls forwarding-table 32.0.0.2` | Local label有分配,但Outgoing Label为"no label"或为空 | 确认LDP未给下一跳32.0.0.2分配标签 |
| **第三层** | `show mpls ldp neighbor brief instance 1` / 告警检查 | LDP邻居状态为Established,无告警 | 排除LDP会话层故障 |
| **第四层(关键!)** | `show running-config ldp` | 发现配置了`access-fec ip-prefix host-route-only` | 该策略限制了LDP只能为32位主机路由分配标签 |
| **第五层** | `show ip forwarding route 32.0.0.2` | 该地址是30位掩码的互联地址(非32位) | **一级根因**:LDP不给非32位路由分配标签 → 标签缺失 → 出接口为NULL |
| **第六层** | 移除`access-fec`限制后观察`show mpls forwarding-table` | Outgoing Label恢复,出接口显示为实际接口(如gei-1/2) | 验证了标签分配问题,但业务仍不通,说明问题不止于此 |
| **第七层** | `show bgp vpnv4 unicast vrf test route` | 下一跳32.0.0.2是跨域对端ASBR的互联接口地址(30位),而非Loopback地址(32位) | **二级根因**:ASBR未配置`next-hop-self`,导致IBGP邻居收到的是互联地址而非Loopback地址 |
| **第八层** | ASBR配置`neighbor <ibgp-peer> next-hop-self`后观察BGP路由 | 路由下一跳变为ASBR的Loopback地址(32位) | LDP为主机路由分配标签 → `show mpls forwarding-table`显示明确的Outgoing Label → `show ip forwarding route vrf test`显示实际出接口 → ping测试成功 → 业务恢复 ✅ |
---
## 4. 解决方案与排障命令沉淀
### 🔧 最终解决方案
1. **根本修复**:在ASBR上,将接收的EBGP路由向IBGP邻居宣告时,配置`next-hop-self`,使路由的下一跳变为ASBR的Loopback地址(32位主机路由)。
2. **容错增强**:评估`access-fec ip-prefix host-route-only`配置的必要性。若非强制需求,建议去除,避免LDP标签分配范围过窄。
---
### 📋 排障命令速查
| 步骤 | 命令 | 作用 | 关注字段 |
| ---- | --------------------------------------------------------- | ------------------------------------------ | ------------------------------------------------------------------------ |
| **1** | `ping vrf <vrf-name> <dest-ip>` | 业务层连通性测试(排障起点!) | Success rate是否为0% |
| **2** | `show ip forwarding route vrf <vrf-name>` | 查看VRF内指定路由的转发信息 | **Gw(下一跳IP)**、**Interface(是否为NULL是关键信号)** |
| **3** | `show mpls forwarding-table <next-hop-ip>` | 查看到达下一跳的外层标签分配情况 | **Outgoing Label**(是否为no label或pop) |
| **4** | `show mpls ldp neighbor brief instance <instance-id>` | 检查LDP会话状态 | 邻居是否为Established |
| **5** | `show mpls ldp binding instance <id>` | 检查LDP标签绑定信息 | 是否有对应FEC的标签绑定 |
| **6** | `show running-config ldp` | 检查LDP策略配置 | 是否存在`access-fec`等过滤配置 |
| **7** | `show ip forwarding route <next-hop-ip>` | 查看下一跳IP本身的路由属性(尤其掩码长度) | **掩码是否为/32**(决定LDP是否分配标签) |
| **8** | `show bgp vpnv4 unicast vrf <vrf-name> route` | 查看VPNv4路由的BGP属性 | **NEXT_HOP字段**(是否是对端互联地址还是Loopback)、**Label字段** |
---
### 🛠️ 修复验证命令
| 验证阶段 | 命令 | 期望输出 |
| -------- | --------------------------------------------------------- | ------------------------------------------------------------------------ |
| **LDP策略修复后** | `show mpls forwarding-table <next-hop-ip>` | Outgoing Label显示明确的标签值(不再是no label) |
| **next-hop-self配置后** | `show bgp vpnv4 unicast vrf test route` | NEXT_HOP变为ASBR的Loopback地址(32位) |
| **业务恢复验证** | `ping vrf test <dest-ip>` | Success rate is 100 percent(5/5) |
| **最终确认** | `show ip forwarding route vrf test` | Interface字段显示实际出接口(如gei-x/x),不再是NULL |
---
**维护建议**:
- 每季度审查一次现网BGP跨域配置,确保ASBR的`next-hop-self`配置未被误删
- 对于新增的LDP策略配置(如`access-fec`),必须在变更窗口内验证标签分配效果
- 定期导出`show tech-support`存档,便于故障回溯分析
**关联文档**:
- `01_协议排障逻辑树/BGP/VPN跨域标签异常排查树.md`
- `03_配置规范与基线/BGP_跨域配置规范.md`
- `06_标准SOP与工具脚本/命令探索方法论.md`
---
## 附录:完整排障流程示例
```bash
# 步骤1:业务测试
MER1#ping vrf test 4.1.1.1
sending 5,100-byte ICMP echo(es) to 4.1.1.1,timeout is 2 second(s).
.....
Success rate is 0 percent(0/5).
# 步骤2:查看VRF路由
MER1#show ip forwarding route vrf test
Dest Gw Interface Owner Pri Metric
*> 9.9.9.9/32 32.0.0.2 NULL BGP 200 0
# 步骤3:检查MPLS标签
MER1#show mpls forwarding-table 32.0.0.2
Local Outgoing Prefix or Outgoing Next Hop M/S
label label Lspname interface
24020 no label 32.0.0.2/30 - - M ← 无标签!
# 步骤4:检查LDP会话
MER1#show mpls ldp neighbor brief instance 1
Codes: D:Direct, T:Targeted, D&T:Direct&Targeted
Total number of neigbors:0
Operational:0 (D:0,T:0,D&T:0) (IPv4:0,IPv6:0,IPv4&IPv6:0)
# 步骤5:检查LDP策略
MER1#show running-config ldp
!<ldp>
mpls ldp instance 1
access-fec ip-prefix host-route-only ← 关键限制!
discovery hello holdtime 180
interface smartgroup1
router-id loopback1
$
!</ldp>
# 步骤6:检查下一跳掩码
MER1#show ip forwarding route 32.0.0.2
Dest Gw Interface Owner Pri Metric
*> 32.0.0.0/30 32.0.0.2 gei-1/2 Direct 0 0
*> 32.0.0.2/32 32.0.0.2 gei-1/2 Address 0 0
# 步骤7:查看BGP路由
MER1#show bgp vpnv4 unicast vrf test route
Network Next Hop Metric LocPrf RtPrf Path
*> 9.9.9.9/32 32.0.0.2 0 100 ?
# 步骤8:ASBR配置next-hop-self后验证
MER1#show bgp vpnv4 unicast vrf test route
Network Next Hop Metric LocPrf RtPrf Path
*> 9.9.9.9/32 10.26.63.152 0 100 ? ← 下一跳变为Loopback!
# 步骤9:验证标签恢复
MER1#show mpls forwarding-table 10.26.63.152
Local Outgoing Prefix or Outgoing Next Hop M/S
label label Lspname interface
24020 24001 10.26.63.152/32 gei-1/2 10.26.63.152 M ← 标签恢复!
# 步骤10:业务恢复验证
MER1#ping vrf test 4.1.1.1
sending 5,100-byte ICMP echo(es) to 4.1.1.1,timeout is 2 second(s).
!!!!!
Success rate is 100 percent(5/5).
```
**文档版本**:v4.0(清理错误命令,只保留正确命令)
**最后更新**:2026-07-20
**维护者**:通过netx在MER1 (10.229.234.136)上实测验证

View file

@ -0,0 +1,27 @@
# 05_监控指标与告警阈值
## 定位
定义各协议的运维监控标准和告警阈值,解决"什么算异常"的问题。这是实现主动运维和故障预测的基础。
## 内容要求
- **路由表规模阈值**:BGP/OSPF/IS-IS的路由表项上限告警值
- **会话状态指标**:邻居震荡频率、Hold Timer超时次数等
- **资源利用率**:CPU/内存/LCAM使用率的告警门限
- **流量特征基线**:正常时段的流量范围,偏离基线时告警
## 目录结构
```
05_监控指标与告警阈值/
├── BGP路由表超限阈值.md
├── LDP会话震荡告警标准.md
├── OSPF_LSA刷新频率异常阈值.md
└── CPU内存排障参考值.md
```
## RAG作用
当用户问"BGP路由表多少条算异常"或"LDP邻居多久震荡一次需要关注"时,AI索引这里的量化阈值标准。
## 为什么需要量化阈值?
- **避免误报**:没有基线的告警只是噪音
- **提前预警**:在故障发生前发现趋势性异常
- **标准化运维**:不同值班人员对"异常"有统一判断标准

View file

@ -0,0 +1,34 @@
# 06_标准SOP与工具脚本
## 定位
沉淀常用排障命令组合、自动化脚本和标准化操作流程(SOP),解决"具体敲什么命令"的问题。这是最贴近实战的操作手册。
## 内容要求
- **命令速查卡**:将复杂排障流程浓缩为3-5步关键命令
- **自动化脚本**:Python/Shell脚本,一键采集诊断信息
- **抓包与解码规范**:协议报文的捕获方法和关键字段解析
- **检查清单(Checklist)**:重大变更或故障处理的标准步骤
## 目录结构
```
06_标准SOP与工具脚本/
├── MPLS标签排障命令速查.md
├── BGP跨域故障排查SOP.md
├── OSPF邻居异常快速诊断.md
├── 抓包与解码规范.md
└── 自动化采集脚本/
├── collect_bgp_info.py
└── check_mpls_labels.sh
```
## RAG作用
当用户说"帮我执行BGP排障"或"运行MPLS标签检查"时,AI直接调用这里的命令组合或脚本。
## 与01_协议排障逻辑树的区别
- 01文件夹讲"排查思路"(If...Then...决策树)
- 本文件夹讲"操作动作"(具体执行哪些show/debug命令)
## 最佳实践
- 每个SOP不超过一页A4纸,便于打印携带
- 命令附带"期望输出"和"异常判定标准"
- 脚本具备自解释能力(含帮助信息和示例)

View file

@ -0,0 +1,400 @@
# 命令探索方法论:通过 `?` 在线帮助发现真实命令
## 为什么需要命令探索?
在实际网络运维中,我们经常遇到以下问题:
- **文档过时**:厂商设备版本升级后命令语法变化
- **记忆模糊**:记不清完整命令路径和参数格式
- **设备差异**:不同厂商(ZTE/Huawei/Cisco)命令体系不同
- **上下文依赖**:某些命令只在特定模式下可用
**解决方案**:使用设备内置的 `?` 在线帮助系统,像"剥洋葱"一样逐层探索。
---
## 核心原则:从宽到窄,逐步细化
### 探索路径示例:以BGP VPNv4路由查询为例
#### 第一步:确定顶层命令
```bash
MER1#show ?
```
输出会列出所有 `show` 开头的命令类别:
```
bgp Show BGP information
ip Show IP information
mpls Show MPLS information
isis Show IS-IS routing information
...
```
#### 第二步:进入子命令层级
```bash
MER1#show bgp ?
```
输出显示BGP相关的地址族:
```
ipv4 IPv4 address family
vpnv4 VPNv4 address family
evpn Display information about all EVPN NLRIs
...
```
#### 第三步:继续深入具体类型
```bash
MER1#show bgp vpnv4 ?
```
输出显示VPNv4的单播/组播分类:
```
unicast Display information about all VPNv4 NLRIs
multicast Display information about all VPNv4 multicast NLRIs
flowspec Flow specification address family modifier
...
```
#### 第四步:查看可用的操作符和参数
```bash
MER1#show bgp vpnv4 unicast ?
```
**关键输出**(这是最有价值的一步):
```
as Autonomous system
community Show route community information
dampened-paths Show paths suppressed due to dampening
detail Display detailed information about an ip prefix
flap Show flap info
in Show route information received from all neighbors
labels Display BGP labels for prefixes
neighbor Detailed information on TCP and BGP neighbor connections
network Show route information
rd Specify route distinguisher
rd-by-vrf Specify route distinguisher by VRF name
vrf Display information for a VPN Routing/Forwarding instance
| Output modifiers (管道符,用于过滤)
> Redirect the output to a file (重定向到文件)
<cr> Carriage return (直接回车执行)
```
#### 第五步:选择VRF相关选项继续探索
```bash
MER1#show bgp vpnv4 unicast vrf ?
```
输出显示可用的VRF实例名称:
```
5G_MEC VPN Routing/Forwarding instance name
IP_RAN VPN Routing/Forwarding instance name
test VPN Routing/Forwarding instance name
WORD VPN Routing/Forwarding instance name (任意字符串)
```
#### 第六步:查看VRF下的具体操作
```bash
MER1#show bgp vpnv4 unicast vrf test ?
```
最终得到精确命令:
```
detail Show route detail information
export-unicast Export VRF routes to unicast routing table
import-unicast Import unicast routes to VRF routing table
in Show route information received from all neighbors
labels Display BGP labels for prefixes
local Display local information of a BGP neighbor
neighbor Detailed information on TCP and BGP neighbor connections
policy Display information about bgp advertisements under a proposed policy
received Display information received from a BGP neighbor
route Show route information ← 这就是我们要的!
summary Summary of BGP neighbor status
```
#### 第七步:执行最终命令
```bash
MER1#show bgp vpnv4 unicast vrf test route
```
输出完整的BGP VPNv4路由表:
```
15:21:26 Beijing Mon Jul 20 2026
Current AS: 100. Other AS: 64580, 64600, 64900
Status codes: * valid, > best, i - internal, s - stale
Origin codes: i - IGP, e - EGP, ? - incomplete
Network Next Hop Metric LocPrf RtPrf Path
```
---
## 实战案例:探索Ping和Trace命令
### 案例1:VRF环境下的Ping命令
#### 探索过程记录
```bash
# 第1层:ping后面可以跟什么?
MER1#ping ?
A.B.C.D Target IP address
bier Send BIER echo messages
ce Customer edge
dcn DCN VRF
domain Domain name
evpn Send EVPN echo messages
mpls Send MPLS echo messages
satellite Specify satellite ID
vpls VPLS instance
vpws Kompella VPWS
vrf VPN Routing/Forwarding instance name
# 第2层:ping vrf后面跟什么?
MER1#ping vrf ?
5G_MEC VRF name (1-32 characters)
5G_OAM VRF name (1-32 characters)
IP_RAN VRF name (1-32 characters)
test VRF name (1-32 characters)
WORD VRF name (1-32 characters)
# 第3层:ping vrf test后面跟什么?
MER1#ping vrf test ?
A.B.C.D Target IP address
domain Domain name
# 第4层:执行完整命令
MER1#ping vrf test 4.1.1.1
sending 5,100-byte ICMP echo(es) to 4.1.1.1,timeout is 2 second(s).
.....
Success rate is 0 percent(0/5).
```
### 案例2:探索MPLS LDP邻居查询
```bash
# 第1层:mpls ldp后面有什么?
MER1#show mpls ldp ?
backoff Show LDP session setup backoff table
bindings Show the LDP label information base (LIB)
discovery Show sources for locally generated LDP discovery hello PDUs
graceful-restart Show MPLS LDP GR
iccp Show LDP session and ICCP state information
igp Show LDP IGP synchronization status
instance Show LDP instance information
interface Show per-interface LDP forwarding information
log Show LDP log info
neighbor Show LDP neighbor information ← 目标在这里
parameters Show LDP configuration parameters
# 第2层:neighbor后面有什么?
MER1#show mpls ldp neighbor ?
A.B.C.D Neighbor address
brief Brief neighbor information ← 要这个简洁版
bvi Bvi interface
detail Detailed neighbor information
graceful-restart The information of LDP graceful restart neighbor
instance The information of LDP instance ← 还可以指定实例
# 第3层:instance后面跟什么?
MER1#show mpls ldp neighbor brief instance ?
<1-65535> LDP instance id
# 第4层:执行完整命令
MER1#show mpls ldp neighbor brief instance 1
15:20:54 Beijing Mon Jul 20 2026
Codes: D:Direct, T:Targeted, D&T:Direct&Targeted
Total number of neigbors:0
Operational:0 (D:0,T:0,D&T:0) (IPv4:0,IPv6:0,IPv4&IPv6:0)
Not operational:0 (D:0,T:0,D&T:0) (IPv4:0,IPv6:0,IPv4&IPv6:0)
```
---
## 高级技巧:组合使用 `?` 和其他工具
### 技巧1:利用 `<cr>` 提示判断命令完整性
当 `?` 输出中包含 `<cr>` 时,表示当前命令已经完整,可以直接执行:
```bash
MER1#show mpls ldp neighbor brief instance 1 ?
<cr> ← 看到这个,就知道可以直接回车执行了
```
### 技巧2:使用管道符 `|` 过滤大量输出
当某个命令输出太多时,用 `?` 查看可用的过滤选项:
```bash
MER1#show bgp vpnv4 unicast vrf test route ?
| Output modifiers
MER1#show bgp vpnv4 unicast vrf test route | ?
begin Begin with the line that matches
count Count the number of lines that match
exclude Exclude lines that match
include Include lines that match
section Print only the section that matches
# 实际应用:只看包含特定前缀的路由
MER1#show bgp vpnv4 unicast vrf test route | include 4.1.1
```
### 技巧3:在配置模式下同样适用
`?` 不仅适用于特权模式(`#`),也适用于配置模式(`(config)#`):
```bash
MER1#configure terminal
MER1(config)#router bgp 100
MER1(config-bgp-router)#neighbor ?
A.B.C.D Neighbor IPv4 address
X:X::X:X Neighbor IPv6 address
peer-group Name of peer group
MER1(config-bgp-router)#neighbor 10.26.63.152 ?
activate Enable the neighbor
advertisement-interval Set minimum interval between sending routing updates
allowas-in Allow AS in path
...
next-hop-self Disable the next hop calculation for this neighbor ← 关键配置!
...
```
### 技巧4:识别命令缩写规则
通过 `?` 可以发现命令的简写形式:
```bash
MER1#sh ?
show Show running system information
MER1#show mpls forw ?
forwarding-table Show MPLS forwarding-table information ← forw是forwarding的合法缩写
```
**规律**:只要输入的字母能唯一标识一个命令,就可以缩写。例如:
- `show` → `sh`
- `forwarding-table` → `forw`
- `configuration` → `conf`
---
## 常见命令树结构对比
### ZTE vs Huawei vs Cisco
| 功能 | ZTE (ZXROS) | Huawei (VRP) | Cisco (IOS) |
|------|-------------|--------------|-------------|
| 查看BGP VPNv4路由 | `show bgp vpnv4 unicast vrf <name> route` | `display bgp vpnv4 routing-table vpn-instance <name>` | `show bgp vpnv4 unicast vrf <name>` |
| 查看MPLS转发表 | `show mpls forwarding-table` | `display mpls lsp` | `show mpls forwarding-table` |
| 查看LDP邻居 | `show mpls ldp neighbor brief instance 1` | `display mpls ldp session` | `show mpls ldp neighbor` |
| Ping VRF内地址 | `ping vrf <name> <ip>` | `ping -vpn-instance <name> <ip>` | `ping vrf <name> <ip>` |
**结论**:虽然命令相似,但细节有差异。**必须针对每种设备单独探索**。
---
## 错误处理与注意事项
### 注意1:命令前缀限制
某些平台可能限制特定命令的使用:
```bash
# 如果收到 "command_not_allowed_prefix" 错误
MER1#trace vrf test 4.1.1.1
%Error: command_not_allowed_prefix
```
**原因**:`trace` 命令可能被netx等平台限制。此时应尝试:
- 改用完整路径 `traceroute`
- 检查权限级别
- 使用替代命令(如通过ping逐跳测试)
### 注意2:区分"不完整命令"和"无匹配"
```bash
# 不完整命令(Incomplete command)- 说明方向对,继续用?探索
MER1#show bgp vpnv4 unicast vrf test
%Error 140305: Incomplete command.
# 无匹配(Unrecognized command)- 说明走错路了,退回上一层
MER1#show bgp vpnv4 unicast vrf test xyz
%Error: Unrecognized command.
```
### 注意3:空格敏感性
```bash
# 正确:每个层级之间有空格
MER1#show mpls ldp neighbor brief instance 1
# 错误:连在一起会当成一个单词
MER1#show mplsldpneighborbriefinstance1
%Error: Unrecognized command.
```
---
## 练习:自主探索以下命令
请用 `?` 方法探索下列命令的完整语法(答案不唯一):
1. 查看ISIS邻接关系
2. 查看OSPF邻居详细信息
3. 查看VRF IP_RAN的路由表
4. 查看MPLS标签绑定信息
5. 查看BGP从邻居10.26.63.152收到的路由
**参考答案**(实际以设备为准):
```bash
# 1. ISIS邻接
MER1#show isis adjacency
# 2. OSPF邻居详细
MER1#show ip ospf neighbor detail
# 3. VRF IP_RAN路由
MER1#show ip forwarding route vrf IP_RAN
# 4. MPLS标签绑定
MER1#show mpls ldp bindings
# 5. BGP从邻居收到的路由
MER1#show bgp vpnv4 unicast vrf test received 10.26.63.152
```
---
## 总结:命令探索五步法
1. **定方向**:从最顶层开始(`show ?`, `ping ?`, `configure ?`)
2. **剥洋葱**:每层用 `?` 查看下一级选项,选择最相关的分支
3. **看提示**:注意 `<cr>`、`WORD`、`A.B.C.D` 等元提示
4. **试执行**:看到 `<cr>` 就执行,观察输出验证猜测
5. **记笔记**:把成功的命令路径记录下来(就像本文档做的)
**终极心法**:不要怕敲错,`?` 永远不会嘲笑你。每个网络专家都是从不停地敲 `?` 开始的。
---
## 附录:快速参考卡片
```bash
# 通用探索模板
<command> ? # 查看下一级选项
<command> <subcommand> ? # 继续深入
...
<full-command> <cr> # 看到<cr>就可以执行
# 特殊符号含义
<cr> - 可以直接回车执行
WORD - 任意字符串(通常是名字、ID等)
A.B.C.D - IPv4地址格式
X:X::X:X - IPv6地址格式
<1-65535> - 数字范围
| - 管道符,用于过滤输出
> - 重定向到文件
# 经典命令树深度
show bgp vpnv4 unicast vrf <name> route # 7层
show mpls ldp neighbor brief instance <id> # 6层
ping vrf <name> <ip> # 4层
configure terminal # 2层
```
---
**文档版本**:v1.0
**最后更新**:2026-07-20
**维护者**:基于真实设备(MER1)验证

View file

@ -0,0 +1,245 @@
# 故障处理常用命令目录集(ZTE ZXROS)
> **设备**:MER1 @ 10.229.234.136 (ZXCTN 9000-3EA, V5.00.10.70)
> **更新时间**:2026-07-20
> **验证状态**:✅ 已验证 / ❌ 错误命令(已删除)
---
## 一、BGP相关命令
### 1.1 BGP IPv4单播
```bash
show bgp ipv4 unicast # BGP IPv4单播路由表
show bgp ipv4 unicast summary # BGP IPv4摘要信息
```
### 1.2 BGP VPNv4
```bash
show bgp vpnv4 unicast # VPNv4 BGP路由表(所有VRF)
show bgp vpnv4 unicast summary # VPNv4 BGP摘要
show bgp vpnv4 unicast vrf <vrf-name> route # 指定VRF的VPNv4路由表
show bgp vpnv4 unicast vrf <vrf-name> # 指定VRF的VPNv4路由(Incomplete command,需要加route)
```
### 1.3 BGP配置查看
```bash
show running-config bgp # BGP运行配置
show running-config router bgp <as-number> # BGP进程配置
```
### 1.4 BGP IPv4单播详细
```bash
show bgp ipv4 unicast neighbor # BGP IPv4邻居信息
show bgp ipv4 unicast neighbor <ip-address> # 指定邻居的详细信息
```
---
## 二、IGP相关命令
### 2.1 IS-IS
```bash
show isis adjacency # IS-IS邻接关系
show isis database # IS-IS链路状态数据库
show isis hostname # IS-IS动态主机名映射
show isis circuit # IS-IS电路信息
```
### 2.2 OSPF
```bash
show ip ospf neighbor # OSPF邻居关系
show ip ospf interface brief # OSPF接口简要信息
show ip ospf interface # OSPF接口详细信息
show ip ospf database # OSPF链路状态数据库
show ip ospf database router-link # OSPF Type-1 LSA(Router LSA)
show ip ospf database network # OSPF Type-2 LSA(Network LSA)
show ip ospf database summary # OSPF Type-3 LSA(Summary LSA)
show ip ospf database asbr # OSPF Type-4 LSA(ASBR Summary LSA)
show ip ospf database external # OSPF Type-5 LSA(External LSA)
show ip ospf database nssa # OSPF Type-7 LSA(NSSA External LSA)
show ip ospf database self-originate # OSPF自生成的LSA
show ip ospf border-routers # OSPF边界路由器信息
show ip ospf virtual-links # OSPF虚链路信息
show ip ospf # OSPF进程概要信息
show ip ospf route # OSPF路由表(按进程显示)
```
---
## 三、MPLS/LDP相关命令
### 3.1 MPLS转发
```bash
show mpls forwarding-table # MPLS标签转发表
show mpls forwarding-table <next-hop-ip> # 特定下一跳的标签转发表
```
### 3.2 LDP会话和绑定
```bash
show mpls ldp neighbor brief instance <id> # LDP邻居简要信息(必须指定instance!)
show mpls ldp neighbor instance <id> # LDP邻居详细信息
show mpls ldp parameters instance <id> # LDP参数配置
show mpls ldp binding instance <id> # LDP标签绑定信息(全局)
show mpls ldp discovery instance <id> # LDP发现信息
```
### 3.3 LDP配置
```bash
show running-config ldp # LDP运行配置
```
---
## 四、VRF相关命令
### 4.1 VRF路由
```bash
show ip forwarding route vrf <vrf-name> # VRF路由表
show ip route vpn # 查看所有VPN路由
```
### 4.2 VRF业务测试
```bash
ping vrf <vrf-name> <dest-ip> # Ping测VRF内地址
```
---
## 五、隧道相关命令
```bash
# 暂无已验证的隧道查询命令
```
---
## 六、接口和路由基础命令
### 6.1 接口状态
```bash
show interface brief # 接口简要信息
show ip interface brief # IP接口简要信息
```
### 6.2 全局路由
```bash
show ip forwarding route # 全局IPv4路由表
```
### 6.3 ARP/MAC
```bash
show arp # ARP表
```
---
## 七、系统基础命令
### 7.1 系统信息
```bash
show version # 版本信息
show running-config # 当前运行配置
```
---
## 八、快速排障组合
### 8.1 BGP跨域故障(已验证组合)
```bash
# 第零层:业务测试
ping vrf test 4.1.1.1 # 1. Ping测业务连通性
# 第一层:VRF路由检查
show ip forwarding route vrf test # 2. 检查VRF路由表
# 第二层:MPLS标签检查
show mpls forwarding-table <next-hop> # 3. 检查MPLS标签转发表
show mpls forwarding-table <specific-ip> # 4. 检查特定目的地的标签
# 第三层:LDP会话检查
show mpls ldp neighbor brief instance 1 # 5. 检查LDP邻居状态
show mpls ldp neighbor instance 1 # 6. 检查LDP邻居详细信息
show mpls ldp binding instance 1 # 7. 检查LDP标签绑定
show mpls ldp parameters instance 1 # 8. 检查LDP参数配置
show mpls ldp discovery instance 1 # 9. 检查LDP发现信息
# 第四层:BGP路由检查
show bgp vpnv4 unicast vrf test route # 10. 检查BGP VPNv4路由
show bgp vpnv4 unicast summary # 11. 检查BGP VPNv4摘要
show bgp ipv4 unicast summary # 12. 检查BGP IPv4摘要
show bgp ipv4 unicast neighbor # 13. 检查BGP IPv4邻居
# 第五层:IGP邻接检查
show ip ospf neighbor # 14. 检查OSPF邻居
show isis adjacency # 15. 检查IS-IS邻接
show ip ospf interface brief # 16. 检查OSPF接口状态
show isis database # 17. 检查IS-IS数据库
show isis circuit # 18. 检查IS-IS电路
# 第六层:基础路由检查
show ip forwarding route # 19. 检查全局路由表
show ip interface brief # 20. 检查IP接口状态
show arp # 21. 检查ARP表
```
### 8.2 OSPF详细排障
```bash
show ip ospf # OSPF进程总览
show ip ospf interface # OSPF接口详细信息
show ip ospf database # OSPF LSDB
show ip ospf database router-link # OSPF Type-1 LSA(Router LSA)
show ip ospf database network # OSPF Type-2 LSA(Network LSA)
show ip ospf database summary # OSPF Type-3 LSA(Summary LSA)
show ip ospf database asbr # OSPF Type-4 LSA(ASBR Summary LSA)
show ip ospf database external # OSPF Type-5 LSA(External LSA)
show ip ospf database nssa # OSPF Type-7 LSA(NSSA External LSA)
show ip ospf database self-originate # OSPF自生成LSA
show ip ospf border-routers # OSPF边界路由器
show ip ospf virtual-links # OSPF虚链路
show ip ospf route # OSPF路由表(按进程显示)
```
### 8.3 IS-IS详细排障
```bash
show isis adjacency # IS-IS邻接
show isis database # IS-IS LSDB
show isis hostname # IS-IS动态主机名映射
show isis circuit # IS-IS电路信息
```
### 8.4 LDP详细排障
```bash
show mpls ldp neighbor brief instance <id> # LDP邻居简要信息
show mpls ldp neighbor instance <id> # LDP邻居详细信息
show mpls ldp parameters instance <id> # LDP参数配置
show mpls ldp binding instance <id> # LDP标签绑定
show mpls ldp discovery instance <id> # LDP发现信息
```
---
## 九、命令语法说明
### 9.1 重要注意事项
1. **LDP命令必须指定instance**:`show mpls ldp neighbor brief instance <id>` ✅
- `show mpls ldp neighbor brief` ❌ Incomplete command
2. **BGP VPNv4路由查询**:`show bgp vpnv4 unicast vrf <vrf-name> route` ✅
- `show bgp vpnv4 unicast rd-by-vrf <vrf-name>` ❌ Incomplete command
- `show bgp ipv4 unicast route` ❌ Ambiguous command
3. **VRF路由查询**:`show ip forwarding route vrf <vrf-name>` ✅
- `show ip route vrf <vrf-name>` ❌ Invalid input
- `show ipv4 route vrf <vrf-name>` ❌ Invalid input
### 9.2 特殊字符限制
netx平台限制了管道符等特殊字符的使用,建议分步执行命令。
---
**文档维护**:
- 最后更新:2026-07-20
- 验证设备:MER1 @ 10.229.234.136
- 关联文档:`命令探索方法论.md`、`BGP跨域排障命令速查.md`