此例子是比较典型的内网PC全网中毒,中毒后的现象是一直往外网发包。导致内网口被堵满。
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´故障现象:CPU 90%以上、PING内网网关丢包严重、面板上繁忙饱和正常空闲四个个灯全亮
îT×C%support.ruijie.com.cn¡ÞǰøÀ´通过配置线登录,收集信息。信息收集可以参考以下链接地址:
îT×C%support.ruijie.com.cn¡ÞǰøÀ´http://support.ruijie.com.cn/showtopic-19267.aspxîT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´如何通过收集的信息来查看是哪台PC上行流量过大导致路由器CPU高。一般只需要看三个地方,一个是内网口、一个是外网接口的发送流量,最后一个是每台PC的上行及下行的流量。
îT×C%support.ruijie.com.cn¡ÞǰøÀ´内网口的接收流量,也就是G0/0接口的input流量,是否与G0/1接口的output(发送流量)流量差别很大,如果差了5M以上,那么就需要进一步查看是哪台PC的上行流量偏高导致这两个数值差据了5M以上。
îT×C%support.ruijie.com.cn¡ÞǰøÀ´查看每台PC的上行及下行流量命令:sh ip f o all,总共有五列,
îT×C%support.ruijie.com.cn¡ÞǰøÀ´第一列为IP;
îT×C%support.ruijie.com.cn¡ÞǰøÀ´第二列为通过路由器限速后的上行流量;
îT×C%support.ruijie.com.cn¡ÞǰøÀ´第三列为通过路由器限速后的下行流量;
îT×C%support.ruijie.com.cn¡ÞǰøÀ´第四列为PC真实需要的上行流量;
îT×C%support.ruijie.com.cn¡ÞǰøÀ´第五列为PC真实需要的下行流量。
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´可以看下以下收集的某客户信息,内网口G0/0接口input流量为86M左右,G0/1口的output流量只有17M,这个数据可能得知,咱内网有PC在进行上行流量攻击。
îT×C%support.ruijie.com.cn¡ÞǰøÀ´我们再找出是哪几台PC的上行流量过大导致的,通过sh ip f o all,发现第四列有非常多PC需要高上行带宽的。那么将这几台PC关闭掉后。网络正常。
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´NBR2000#sh int
îT×C%support.ruijie.com.cn¡ÞǰøÀ´========================== FastEthernet 0/2 ========================
îT×C%support.ruijie.com.cn¡ÞǰøÀ´FastEthernet 0/2 is DOWN , line protocol is DOWN
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Hardware is PQ3 FCC FAST ETHERNET CONTROLLER FastEthernet, address is 001a.a941.
îT×C%support.ruijie.com.cn¡ÞǰøÀ´f512 (bia 001a.a941.f512)
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Interface address is: no ip address
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ARP type: ARPA,ARP Timeout: 3600 seconds
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ MTU 1500 bytes, BW 100000 Kbit
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Encapsulation protocol is Ethernet-II, loopback not set
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Keepalive interval is 10 sec , set
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Carrier delay is 2 sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ RXload is 1 ,Txload is 1
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Queueing strategy: FIFO
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Output queue 0/40, 0 drops;
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Input queue 0/75, 0 drops
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 5 seconds input rate 0 bits/sec, 0 packets/sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 5 seconds output rate 0 bits/sec, 0 packets/sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 packets input, 0 bytes, 0 res lack, 0 no buffer,0 dropped
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Received 0 broadcasts, 0 runts, 0 giants
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 abort
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 packets output, 0 bytes, 0 underruns,0 dropped
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 output errors, 0 collisions, 0 interface resets
îT×C%support.ruijie.com.cn¡ÞǰøÀ´========================== Null 0 ========================
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Null 0 is UP , line protocol is UP
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Hardware is Null
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Interface address is: no ip address
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ MTU 1500 bytes, BW 8000000 Kbit
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Encapsulation protocol is NULL, loopback not set
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Keepalive interval is 0 sec , no set
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Carrier delay is 2 sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ RXload is 1 ,Txload is 1
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Queueing strategy: FIFO
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Output queue 0/40, 0 drops;
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Input queue 0/75, 0 drops
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 5 seconds input rate 0 bits/sec, 0 packets/sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 5 seconds output rate 0 bits/sec, 0 packets/sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 packets input, 0 bytes, 0 res lack, 0 no buffer,0 dropped
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Received 0 broadcasts, 0 runts, 0 giants
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 abort
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 packets output, 0 bytes, 0 underruns,0 dropped
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 output errors, 0 collisions, 0 interface resets
îT×C%support.ruijie.com.cn¡ÞǰøÀ´========================== GigabitEthernet 0/0 ========================
îT×C%support.ruijie.com.cn¡ÞǰøÀ´GigabitEthernet 0/0 is UP , line protocol is UP
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Hardware is PQ3 TSEC GIGABIT ETHERNET CONTR GigabitEthernet, address is 001a.a94
îT×C%support.ruijie.com.cn¡ÞǰøÀ´1.f510 (bia 001a.a941.f510)
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Interface address is: 192.168.1.1/24
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ARP type: ARPA,ARP Timeout: 3600 seconds
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ MTU 1500 bytes, BW 50000 Kbit
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Encapsulation protocol is Ethernet-II, loopback not set
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Keepalive interval is 10 sec , set
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Carrier delay is 2 sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ RXload is 261 ,Txload is 1
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Queueing strategy: FIFO
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Output queue 0/40, 0 drops;
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Input queue 0/75, 0 drops
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 5 seconds input rate
864643768 bits/sec, 101582 packets/sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 5 seconds output rate 1455736 bits/sec, 269 packets/sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 128102811 packets input, 3028722988 bytes, 5 res lack, 0 no buffer,0 dropped
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Received 3534 broadcasts, 0 runts, 0 giants
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 5 input errors, 0 CRC, 0 frame, 0 overrun, 0 abort
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 505431 packets output, 375864815 bytes, 0 underruns,0 dropped
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 output errors, 0 collisions, 0 interface resets
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Link Mode: 1000M/Full-Duplex
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Output flowcontrol is off;Input flowcontrol is off.
îT×C%support.ruijie.com.cn¡ÞǰøÀ´========================== GigabitEthernet 0/1 ========================
îT×C%support.ruijie.com.cn¡ÞǰøÀ´GigabitEthernet 0/1 is UP , line protocol is UP
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Hardware is PQ3 TSEC GIGABIT ETHERNET CONTR GigabitEthernet, address is 001a.a94
îT×C%support.ruijie.com.cn¡ÞǰøÀ´1.f511 (bia 001a.a941.f511)
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Interface address is: 222.77.33.2/30
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ARP type: ARPA,ARP Timeout: 3600 seconds
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ MTU 1500 bytes, BW 1000000 Kbit
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Encapsulation protocol is Ethernet-II, loopback not set
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Keepalive interval is 10 sec , set
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Carrier delay is 2 sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ RXload is 1 ,Txload is 1
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Queueing strategy: FIFO
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Output queue 0/40, 0 drops;
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Input queue 0/75, 0 drops
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 5 seconds input rate 1727584 bits/sec, 252 packets/sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 5 seconds output rate
1700152 bits/sec, 362 packets/sec
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 469021 packets input, 425669196 bytes, 0 res lack, 0 no buffer,0 dropped
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Received 0 broadcasts, 0 runts, 0 giants
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 abort
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 603586 packets output, 311332012 bytes, 0 underruns,0 dropped
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ 0 output errors, 0 collisions, 0 interface resets
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Link Mode: 100M/Full-Duplex
îT×C%support.ruijie.com.cn¡ÞǰøÀ´ Output flowcontrol is off;Input flowcontrol is off.
îT×C%support.ruijie.com.cn¡ÞǰøÀ´NBR2000#
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´NBR2000#sh ip f o all
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Inner Network Online User:15
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Total inbound original flowrate:888133 Kbps, Inner Network after rate-limit:1947
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Kbps
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Total outbound original flowrate:1613 Kbps, Inner Network after rate-limit:1403
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Kbps
îT×C%support.ruijie.com.cn¡ÞǰøÀ´IP Inbound(kb/s) Outbound(kb/s) Receive_IN(kb/s) Receive_OUT(kb
îT×C%support.ruijie.com.cn¡ÞǰøÀ´/s)
îT×C%support.ruijie.com.cn¡ÞǰøÀ´Total 1947 1403
888133 1613
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´================================================================================
îT×C%support.ruijie.com.cn¡ÞǰøÀ´===
îT×C%support.ruijie.com.cn¡ÞǰøÀ´To-Router-Local 9 3
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.8 246 999 246 1087
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.4 99 400 109 519
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.123 199 2 59759 2
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.17 200 1 58080 1
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.70 201 1 63442 1
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.10 0 0 0 0
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.6 0 0 0 0
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.88 201 0 66300 0
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.62 201 0 228724 0
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.45 201 0 118725 0
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.5 0 0 0 0
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.21 200 0 223287 0
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.7 0 0 0 0
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.9 0 0 0 0
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´192.168.1.89 199 0 69452 0
îT×C%support.ruijie.com.cn¡ÞǰøÀ´îT×C%support.ruijie.com.cn¡ÞǰøÀ´NBR2000#
îT×C%support.ruijie.com.cn¡ÞǰøÀ´