- 关于本文档
- 安全声明
- 使用eDesk Pro工具进行网络巡检和故障处理
- 使用故障启示录指导故障诊断和排除
例行维护
常用故障诊断功能
故障处理:二层环路
- 二层环路介绍
二层环路故障定位指导
二层环路故障案例
二层环路FAQ
- BPDU报文在设备上能否被透传?
- STP生成树计算的度量依据有哪些,改变端口速率是否会导致STP拓扑变化?
- 交换机是否支持MAC-FLAPPING检测功能
- LDT&LBDT检测到环路后端口被Block是否继续发送协议报文?
- 接口上环回检测功能是否可以和VLAN Mapping配合应用?
- SEP协议报文的目的MAC是多少?
- SEP支持哪几种堵塞点选择方法?
- SEP拓扑变化后支持通知哪几种环网协议刷新转发表?
- RRPP协议报文的目的MAC是什么?
- 配置RRPP时有哪些注意事项?
- RRPP如何做到快速切换的?
- 为什么RRPP传输节点无法看到Health报文统计?
- 部署RRPP时,如何实现负载分担?
- RRPP网络一个环最多可以支持多少台设备?
- S系列交换机的ERPS是否支持子环?
- S系列交换机的ERPS是否支持与其他环网协议混合组网?
- S系列交换机的ERPS是否支持负载分担?
- ERPS功能是否支持Eth-Trunk接口?
- 哪些设备支持环路检测?
- 如何配置单端口环路检测?
- 如何配置多端口环路检测?
- 端口环路检测报文的缺省发送间隔是多少?
- 端口被Block后环回检测协议报文是否可以继续发送?
- 如何区分不同接口发出的环路检测报文?
- 什么是ERPS?
- ERPS协议报文的目的MAC是什么?
- MSTP状态变化时,为什么部分接口需要30秒才变为转发状态?
- 设备部署了环网协议且环网切换时,为什么X1E单板接收IP流量且需要跨板转发时出现丢包?
- 交换机下行口和V100R005C01版本的S5700相连,为什么下行口会被STP阻塞,导致业务不通?
- 为什么机框替换后,网络中出现了MAC地址漂移?
故障处理:以太网接口物理DOWN
故障处理:网络丢包
网络丢包介绍
- 网络丢包故障定位指导
网络丢包故障案例
- 故障案例:测试交换机的组播性能,组播业务启用2分钟后出现少量丢包
- 故障案例:管理用户无法通过Telnet方式登录设备
- 故障案例:监控服务器Ping交换机下接的服务器丢包
- 故障案例:交换机端口入方向存在丢包
- 故障案例:交换机下挂两个终端观看视频时均频繁出现马赛克
- 故障案例:交换机下挂用户上网慢,Ping网关有时延
- 故障案例:交换机与其他厂商设备对接产生丢包
- 故障案例:接入用户Ping堆叠设备有丢包
- 故障案例:下挂用户上线困难
- 故障案例:用户访问服务器有丢包现象
- 故障案例:用户观看视频业务出现花屏
- 故障案例:用户观看视频业务出现马赛克
- 故障案例:用户在业务高峰期观看IPTV出现马赛克
- 故障案例:组播点播时出现节目画面停顿
- 故障案例:交换机下挂其他厂商OLT,用户观看IPTV出现卡顿
网络丢包FAQ
故障处理:用户无法获取IP地址
故障处理:设备重启或单板复位
故障处理:管理员用户AAA认证登录异常
管理员用户AAA认证登录异常介绍
管理员用户AAA认证登录异常故障定位指导
管理员用户AAA认证登录异常故障案例
- 故障案例:管理员登录后无法进入系统视图或者用户级别不正确
- 故障案例:管理员登录成功后立即下线
- 故障案例:修改本地用户失败
- 故障案例:用户密码过期
- 故障案例:快速定位登录失败原因
- 故障案例:本地认证拒绝
- 故障案例:本地用户名或密码错误
- 故障案例:本地用户配置的Service-type不匹配
- 故障案例:AAA本地认证用户类型不匹配
- 故障案例:本地认证账号被锁定
- 故障案例:远端认证账号被锁定
- 故障案例:RADIUS服务器无响应
- 故障案例:HWTACACS服务器无响应
- 故障案例:服务器认证拒绝
- 故障案例:RADIUS服务器下发Login-Service属性值不正确
- 故障案例:FTP用户登录失败
- 故障案例:SSH用户登录失败(V200R011C10之前版本)
- 故障案例:RADIUS认证方式Telnet登录HSB备AC失败
故障处理:有线接入认证异常
- 有线接入认证异常故障定位指导
故障处理:802.1X认证失败
故障处理:802.1X认证用户掉线
故障处理:MAC认证失败
故障处理:MAC认证用户掉线
故障处理:Portal认证页面无法弹出
故障处理:Portal认证失败
故障处理:Portal认证成功一段时间后,访问网络又弹出认证页面(Portal认证用户掉线)
故障处理:静态用户认证失败
故障处理:静态用户掉线
故障处理:用户访问网络权限异常(RADIUS授权属性)
故障处理:云管理场景HACA认证异常定位
故障处理:话机认证类问题定位
- 信息采集
故障处理:RADIUS/Portal逃生类问题
故障处理:对接第三方RADIUS服务器注意事项
有线接入认证异常FAQ
接入认证常见原因参考
- 简介
- AAA cut command (ERRCODE: 87)
- AAA gets service scheme error (ERRCODE: 567)
- AAA get author info error (ERRCODE: 568)
- AAA check author vlan error (ERRCODE: 569)
- AAA authorization dynamic vlan error (ERRCODE: 570)
- Abnormal offline
- Access device authorization fail (ERRCODE: 254)
- Access device authorization timeout (ERRCODE: 374)
- Accounting server no response
- Add FPI item timeout(LPU) (ERRCODE: 372)
- Adding STA entries failed (ERRCODE: 207)
- Add ISP-Vlan resource fail
- Add MAC address error (ERRCODE: 346)
- Add route error (ERRCODE: 352)
- Add Vlan authorization error (ERRCODE: 349)
- Administrator request to offline
- AP delete (ERRCODE: 297)
- AP device authorization fail (ERRCODE: 156)
- AP device authorization timeout (ERRCODE: 373)
- AP fault (ERRCODE: 233)
- AP join slot (ERRCODE: 439)
- AP leave slot (ERRCODE: 440)
- AP restores connection from escape mode
- ARP detect fail (ERRCODE: 29)
- AS configuration changed on interface
- AS detect fail
- AS smooth fail
- A user exception is detected
- Authenticate fail (ERRCODE: 147)
- Authentication during association failed (ERRCODE: 208)
- Authorization data error (ERRCODE: 84)
- Beyond access limit (ERRCODE: 57)
- Black hole mac or static mac
- Block domain force user to offline (ERRCODE: 138)
- CAPWAP down (ERRCODE: 169)
- CM add to FC/TM fail (ERRCODE: 61)
- CM Nas error (ERRCODE: 64)
- CM send table fail (ERRCODE: 428)
- Configuration changed on AP (ERRCODE: 219)
- Configuration changed on interface (ERRCODE: 291)
- Connect check fail (ERRCODE: 20)
- Consistency between AAA and VRP error或者Inconsistency between AAA and VRP (ERRCODE: 400)
- Console reset or disable port (ERRCODE: 145)
- Data flow or online time exceed threshold
- Delete backup user (ERRCODE: 247)
- Delete MAC address error (ERRCODE: 347)
- Delete portal server ip (ERRCODE: 397)
- Delete protect timer create fail (ERRCODE: 426)
- Delete Vlan authorization error (ERRCODE: 350)
- DHCP release (ERRCODE: 69)
- DHCP server no response (ERRCODE: 68)
- Domain or user access limit (ERRCODE: 86)
- Domain policy failed force user to offline (ERRCODE: 371)
- DPSK decryption failed during DPSK authentication (ERRCODE: 550)
- Eapol client restart associate (ERRCODE: 402)
- EAPOL client timeout (ERRCODE: 206)
- EAPOL client user name is different (ERRCODE: 409)
- EAPOL nas error (ERRCODE: 38)
- EAPOL user request (ERRCODE: 34)
- Exceeded the maximum number of PPSK account
- Failed to add FPI item(LPU) (ERRCODE: 170)
- Failed to add ipv4 to hash(LPU) (ERRCODE: 161)
- Failed to add MAC to hash(LPU) (ERRCODE: 163)
- Failed to check the authorization configuration during inter-AC roaming (ERRCODE: 552)
- Failed to modify ipv4 to hash(LPU) (ERRCODE: 460)
- Failed to obtain DPSK data during DPSK authentication (ERRCODE: 548)
- Failed to obtain the port index (ERRCODE: 551)
- Failed to set table to LPU/AP (ERRCODE: 417)
- Failed to set user QoS(LPU) (ERRCODE: 168)
- Failed to synchronize user entries
- Flow limit (ERRCODE: 88)
- Get system time fail (ERRCODE: 418)
- HACA connect check fail (ERRCODE: 432)
- HAP deleted (ERRCODE: 242)
- HAP fault (ERRCODE: 241)
- HSB add sessionID hash fail (ERRCODE: 413)
- HSB connect check fail (ERRCODE: 434)
- HVAP deleted (ERRCODE: 243)
- Idle cut (ERRCODE: 90)
- Inconsistent STA during ACs backup sync (ERRCODE: 213)
- Inconsistent STA on AC and AC during sync (ERRCODE: 234)
- Inconsistent STA on AP and AC during sync (ERRCODE: 235)
- Insufficient key slots or chip self-healing (ERRCODE: 221)
- Interface net down (ERRCODE: 59)
- Interface of MAC table mismatch
- IP address alloc fail (ERRCODE: 60)
- IP address conflict(delay offline) (ERRCODE: 407)
- IP address conflict (ERRCODE: 123)
- Ip-static-user has been configured on interface (ERRCODE: 366)
- Ip-static-user not support pre-authen
- Ipv4 conflict(LPU) (ERRCODE: 158)
- ISP-Vlan resource is full
- LAM Authorization fail (ERRCODE: 152)
- Layer 3 roaming disable (ERRCODE: 292)
- Local authentication reject (ERRCODE: 132)
- Local Authentication user block (ERRCODE: 136)
- Local Authentication user type not match (ERRCODE: 135)
- Local eap authentication reject
- Local user expired. (ERRCODE: 364)
- Local user is not in the time-range. (ERRCODE: 365)
- Local username or password is wrong (ERRCODE: 133)
- Local user reach access limit. (ERRCODE: 316)
- Low rate (ERRCODE: 225)
- Low RSSI (ERRCODE: 224)
- Mac address conflict (ERRCODE: 124)
- MAC conflict(LPU) (ERRCODE: 160)
- MAC limit on interface
- Modify ARP error (ERRCODE: 355)
- Modify MAC address error (ERRCODE: 348)
- Modify Vlan authorization error (ERRCODE: 351)
- Multicast key handshake failure
- ND detect fail (ERRCODE: 153)
- No accounting server configured
- No ack packet from the peer end (ERRCODE: 222)
- No authentication server configured
- No control entry (ERRCODE: 227)
- No cui from radius authorization
- No DHCP request from sta(STA reassociates)
- No radius-server template bound
- Normal user change to ip-static-user (ERRCODE: 363)
- No tacacs-server template bound
- Not support authorization with car
- Not support authorization with user-group
- Not support authorize both vlan and ucl-group
- No wifi entry (ERRCODE: 229)
- Other reasons of roaming check fail (ERRCODE: 296)
- Port security aging
- Port security policy changed on interface
- PPP echo fail (ERRCODE: 22)
- PPP user request (ERRCODE: 21)
- PPP virtual interface has been deleted (ERRCODE: 187)
- PPSK user authenticate fail
- Process slave board error (ERRCODE: 356)
- Query WEB user timer create fail (ERRCODE: 427)
- Quiet table check fail
- Radius authentication reject
- Radius coa down
- Radius server cut command
- reach access limit of global control
- Reach authentication mode limit
- Reached the maximum User Spec (ERRCODE: 144)
- Realtime accounting fail (ERRCODE: 78)
- Remote user is blocked (ERRCODE: 519)
- Remote user sync failed (ERRCODE: 253)
- Reporting the PMK negotiation result times out
- Resources are insufficient
- Restore user authorization information fail
- Restore user domain information fail (ERRCODE: 369)
- Restore user web information fail (ERRCODE: 370)
- Restore user Wlan information fail (ERRCODE: 368)
- Roaming abnormal (ERRCODE: 211)
- Roaming check failed (ERRCODE: 232)
- Roaming is prohibited
- Roaming security check fail (ERRCODE: 294)
- Roaming status check fail (ERRCODE: 295)
- Roam send table fail (ERRCODE: 424)
- Roam timer create fail (ERRCODE: 423)
- SAM add acl-id or decp error (ERRCODE: 444)
- SAM add acl-id or dscp error
- SAM add down car failed (ERRCODE: 182)
- SAM add down car resource full (ERRCODE: 479)
- SAM add down remark dscp error (ERRCODE: 475)
- SAM add down remark dscp error (ERRCODE: 476)
- SAM add down remark dscp resource full (ERRCODE: 477)
- SAM add down remark error (ERRCODE: 472)
- SAM add dynamic acl error (ERRCODE: 196)
- SAM add http remark error
- SAM add http to cpu error (ERRCODE: 450)
- SAM add permit web acl error (ERRCODE: 442)
- SAM add push url error (ERRCODE: 449)
- SAM add redirect acl error (ERRCODE: 456)
- SAM add ucl group failed (ERRCODE: 183)
- SAM add up car failed (ERRCODE: 181)
- SAM add up car resource full (ERRCODE: 478)
- SAM add user deny error (ERRCODE: 452)
- SAM add usergroup acl error (ERRCODE: 443)
- The acl locally delivered by AAA is invalid or does not exist(ERRCODE: 564)
- The description of the acl sent by Radius is incorrect(ERRCODE: 565)
- The Rediect ACL delivered by AAA is incorrectly checked(ERRCODE: 566)
- SAM add usergroup remark dscp error (ERRCODE: 469)
- SAM add usergroup remark error (ERRCODE: 466)
- SAM down remark resource full (ERRCODE: 474)
- SAM failed to deliver authorized VALN (ERRCODE: 571)
- SAM failed to deliver QOS (ERRCODE: 572)
- SAM failed to deliver port mac limit (ERRCODE: 573)
- SAM failed to deliver vm car (ERRCODE: 574)
- SAM modify down car failed (ERRCODE: 465)
- SAM modify down remark error (ERRCODE: 473)
- SAM modify dynamic acl error (ERRCODE: 463)
- SAM modify http remark error
- SAM modify http to cpu error (ERRCODE: 451)
- SAM modify iuib failed (ERRCODE: 459)
- SAM modify permit web acl error (ERRCODE: 445)
- SAM modify push url error (ERRCODE: 448)
- SAM modify redirect acl error (ERRCODE: 457)
- SAM modify ucl group failed (ERRCODE: 462)
- SAM modify up car failed (ERRCODE: 464)
- SAM modify user deny error (ERRCODE: 453)
- SAM modify usergroup acl error (ERRCODE: 446)
- SAM modify usergroup remark dscp error (ERRCODE: 470)
- SAM modify usergroup remark error (ERRCODE: 467)
- SAM restore vlan error (ERRCODE: 180)
- SAM restore vlan resource full (ERRCODE: 480)
- SAM usergroup remark dscp resource full (ERRCODE: 471)
- SAM usergroup remark resource full (ERRCODE: 468)
- Server response times out
- Session time out (ERRCODE: 93)
- Slot down (ERRCODE: 122)
- Smooth start detect timer create fail (ERRCODE: 415)
- Smooth start user online timer fail (ERRCODE: 414)
- SoftGRE tunnel is down
- STA deauthentication (ERRCODE: 217)
- STA disassociation (ERRCODE: 216)
- STA roamed to another AC (ERRCODE: 201)
- Start accounting fail (ERRCODE: 82)
- Start user detect fail (ERRCODE: 421)
- State protect timer create fail
- STA timed out (ERRCODE: 218)
- Success (ERRCODE: 0)
- System error (ERRCODE: 376)
- TAC Authentication fail (ERRCODE: 148)
- TAC Authorication fail (ERRCODE: 150)
- TAC Authorization fail
- The access interface goes Down due to RADIUS CoA authorization
- The authorization VLAN and user UCL cannot be delivered at the same time
- The board does not support user access(LPU) (ERRCODE: 399)
- The device not support authorization (ERRCODE: 378)
- The DPSK length is incorrect during DPSK authentication (ERRCODE: 549)
- The local eap server is up but has no reply
- The Navi-AC STA is kicked off
- The PPSK account expires
- The PPSK configuration is modified
- The radius server is not reachable (ERRCODE: 205)
- The radius server is up but has no reply (ERRCODE: 176)
- The service is released (ERRCODE: 40)
- The shared keys on the device and Portal server are different
- The source interface of the RADIUS server does not exist or has no IP address (ERRCODE: 558)
- The tac authen server is not reachable (ERRCODE: 289)
- The tac author server is not reachable (ERRCODE: 290)
- The to-be-authenticated IPv6 address of the web user is updated
- The user did not specify the FTP path
- The user not support pre-authen (ERRCODE: 385)
- The vlanif interface has been deleted (ERRCODE: 188)
- The vlan is deleted (ERRCODE: 237)
- The vlan on the port has been deleted (ERRCODE: 109)
- TM failed to set fresh timer
- TM fresh table malloc error
- Trunk member change (ERRCODE: 437)
- Tunnel between ACs torn down (ERRCODE: 240)
- Undefined reason (ERRCODE: 231)
- Unsupported access type
- Unsupported terminal type
- Update authen ipv6 for web user
- Update IP for static user (ERRCODE: 392)
- Update IP for web user (ERRCODE: 398)
- Update roam count fail (ERRCODE: 422)
- Update the IP as an IP of a static user (ERRCODE: 393)
- Update user online time fail (ERRCODE: 416)
- User/server timeout (ERRCODE: 58)
- User aging (ERRCODE: 107)
- User device type change
- User entries fail to be synchronized between the local AC and Navi AC
- User flow detect fail (ERRCODE: 386)
- User has mac moved (ERRCODE: 387)
- User information error (ERRCODE: 77)
- User is unassociated by AS或者AS access interface down (ERRCODE: 252)
- User MAC has been deleted
- Username reach access limit
- User not match the allowed MAC address range
- User request to offline (ERRCODE: 19)
- Users with low priorities go offline
- User transfer no available slot (ERRCODE: 167)
- User transfer timeout (ERRCODE: 166)
- VAP configuration is deleted or changed
- Vlanif down (ERRCODE: 438)
- WDS link fault or other unknown reason (ERRCODE: 215)
- WEBS heartbeat fail (ERRCODE: 49)
- Web user request (ERRCODE: 65)
- WEB user synchronize fail (ERRCODE: 203)
- WIDS dynamic blacklist (ERRCODE: 223)
- Wireless access is not supported
- WLAN connect check fail (ERRCODE: 433)
- Work group reject (ERRCODE: 165)
故障处理:无线接入认证异常
故障处理:Ping不通
故障处理:防攻击
故障处理:CPU占用率高
故障处理:PD供电异常
PD供电异常介绍
PD供电异常故障定位指导
PD供电异常故障案例
- 故障案例:S5700EI给下挂AP供电时,接口频繁Up/Down
- 故障案例:交换机连接非标PD,无法上电
- 故障案例:S5720SI、S5720EI设备下挂PD频繁上下电
- 故障案例:S5700LI端口频繁上下电
- 故障案例:非标PD维持电流不足导致PD频繁上下电
- 故障案例:雷击造成S2700EI交换机正常给AP供电一段时间后突然无法供电
- 故障案例:S5700下挂IP话机并进行PD供电,PD频繁上下电
- 故障案例:S5700-52C-PWR-SI给下挂AP供电时电源模块出现红色告警
- 故障案例:S5700 PoE供电时PD设备提示供电不足
- 故障案例:S2700通过PoE给摄像头供电出现摄像头无数据传输
- 故障案例:S5700 PoE交换机拒绝给非标准PD设备供电
- 故障案例:交换机不接地导致PD不上电问题
PD供电异常FAQ
故障处理:其他
TechNotes
TechNotes:S200, S1700, S5700交换机忘记密码怎么办?如何修改或清除密码?
TechNotes:S5700交换机恢复出厂配置
TechNotes:配置系统基本信息
- TechNotes:配置SSH协议
TechNotes:S5700修改堆叠ID操作指导
TechNotes:S7700单框合并为集群系统操作指导
TechNotes:S交换机堆叠最佳实践
TechNotes:从S5700交换机获取日志文件
TechNotes:从S7700集群系统中获取诊断信息和日志文件
TechNotes:获取S系列交换机序列号
TechNotes:什么是镜像
TechNotes:如何捕获报文
TechNotes:如何镜像CPU接收或发出的报文
- TechNotes:IEEE 802.1Q封装的VLAN数据帧格式
TechNotes:LACP模式Eth-Trunk接口不能UP
TechNotes:RSTP的根保护功能
TechNotes:RSTP的环路保护功能
TechNotes:S5700 Eth-Trunk配置和故障处理
TechNotes:S5700生成树协议问题及相关设计注意事项
TechNotes:STP的定时器
TechNotes:STP的拓扑变化机制
TechNotes:S系列交换机Eth-trunk负载分担不均配置调整方法
TechNotes:S系列交换机支持的MAC地址
TechNotes:S系列交换机链路聚合的负载分担方式
- TechNotes:了解VLAN集中管理协议(VCMP)
TechNotes:什么是BPDU保护,如何配置BPDU保护?
TechNotes:使用VBST的端口优先级实现不同VLAN流量的负载分担
- TechNotes:干道链路
TechNotes:手工负载分担模式Eth-Trunk不能UP
TechNotes:通过MIB查询S交换机学习到的动态MAC
TechNotes:OSPF是如何将缺省路由注入Stub区域和Totally Stub区域的
- TechNotes:园区网络如何部署组播特性系列:IGMP Snooping
- TechNotes:组播S系列交换机支持矩阵
TechNotes:DLDP的原理和基本配置
TechNotes:QoS配置——MQC和基于ACL的简化流策略
TechNotes:S5700系列交换机的QoS队列调度和报文丢弃
TechNotes:流量监管、流量整形和接口限速
TechNotes:S系列交换机ACL资源不足怎么办?
TechNotes:S5700的管理接口与管理IP地址
TechNotes:S5700配置自协商与故障排查
TechNotes:802.1X认证失败故障处理
TechNotes:配置RADIUS和HWTACACS
TechNotes:什么是TACACS,如何配置TACACS?
- TechNotes:ERROR DOWN接口状态恢复
TechNotes:交换机常见错误信息处理
TechNotes:S系列交换机接口故障排除
TechNotes:框式交换机单板复位故障
TechNotes:网管收不到S系列交换机的SNMP Trap信息
TechNotes:网管无法纳管S系列交换机的原因排查
TechNotes:S交换机组播二三层混跑配置指导和常见问题
TechNotes:S系列交换机光模块手册
TechNotes:LACP发布
TechNotes:TCP IP协议族概述
TechNotes:VLAN发布
TechNotes:什么是VPN
TechNotes:QoS
- 联系华为技术支持