Chapter6Maintenance
ofserverandswitcharenotsame.Whentheback-endcongurationofaccountingand
authenticationserverischecked,itisfoundthatthesharedkeycongurationofaccess
layerswitchofB1–B3iswrong,theoriginalkey“amtium”isconguredas“antium”now,
whichcausestheunsuccessfulauthenticationnegotiationoftwodevicesandthatuser
authenticationfailure.
Solution
WhentheengineerofcompanyBchangesthepasswordas“amtium”andhavechecked
fortwodays,thefaultsuchas“authenticationtimeout”doesnotappear.Theproblemis
resolvedcompletely.
6.3.9TheSolutiontoARPAttackinCampusNetwork
FaultPhenomenon
The11accesslayerswitchesZXR102900EofthesameVLANinthestudentdormitory
buildingcannotconnectthenetwork.Itcausesthatfortypercentofusersofthebuilding
cannotaccessthenetwork.
FaultAnalysisandLocation
Checkthenetworkmanagementsystem,ndthattheelevenswitchesaredisconnected
andfailtobepingedthrough.Themaintenancepersonnelarrivesattheweakelectricity
well,accessesoneoftheswitchbyHyperT erminal,theIPaddressis172.168.0.123.
TheCPUutilizationreaches93%~100%.Checkthealarminformationandconguration
information,theabnormalityisnotfound.AccesstheconvergencelayerswitchT40G,
ndthealarmthat“port4receivesmoreARPbroadcastpackets”.Checkthetrafc
informationofthisportbycommand,ndthataboutonehundredthousandbroadcast
packetsareaddedeverytenseconds.
AnalyzetheaccessswitchZXR102900Eofthisportandndthefollowingconditions:
1.Thereisloopontheuserside.
2.Userhosthasthevirusandsendsbroadcastpacketcontinuously.
3.UserhostinstallstheARPattacksoftwareandsendsARPattackpacketcontinuously.
CheckthattheIPaddressoftheZXR102900Econnectedwiththisportoftheconvergence
layerswitchis172.168.0.111.Theuserconnectstheswitchbythenetworkcableanddoes
thepacketsnifngandndthatthehostwiththeMACaddress“00:19:e0:a9:5a:fc”sends
theARPbroadcastpacketcontinuously.Accordingtothelabelofthenetworkcable,nd
thatthehostisfrom2606dormitory.Pulloutthenetworkcableofthehost,theeleven
switchesrecovernormalandCPUutilizationisnomorethan5%.
Solution
1.FiltertheMACaddressofthisPCwithfaultontheaccesslayerswitchandprohibitthe
PCfromaccessingtheinternet,whichpreventsitfrominuencingtheotherusers
6-9
SJ-20120409144109-002|2012-07-02(R1.0)ZTEProprietaryandCondential