Доброго дня всем! Прошу помощи у специалистов по оборудованию Cisco, так как сам таковым не являюсь (скорее даже наоборот))), но... Встала задача: предотвратить "падения" интернета. Данную "железку" ставили и настраивали до меня, контакты того человека утеряны.Суть: периодически, нерегулярно (интервал между падениями от 5 мин. до 4-5 часов) пропадает интернет. По внешнему IP в это время Cisco не пингуется, из локальной сети пинг проходит. Через какое-то время все восстанавливается.
Соответственно, вопросы:
1. Как добраться до логов?
2. Может ли помочь в данной ситуации смена IOS (я так понимаю стоит довольно древняя прошивка)?
3. Что еще может помочь?
4. ???
5. По возможности подскажите ссылочку на описание команд Cisco, желательно на русском?
main-offise#sh ver
Cisco IOS Software, 2801 Software (C2801-SPSERVICESK9-M), Version 12.4(4)T8, RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2007 by Cisco Systems, Inc.
Compiled Fri 10-Aug-07 16:37 by khuie
ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)
main-offise uptime is 1 day, 26 minutes
System returned to ROM by reload at 04:55:44 UTC Tue Apr 27 2010
System image file is "flash:c2801-spservicesk9-mz.124-4.T8.bin"
Cisco 2801 (revision 7.0) with 176128K/20480K bytes of memory.
Processor board ID FCZ1141R8C8
2 FastEthernet interfaces
1 ATM interface
DRAM configuration is 64 bits wide with parity disabled.
191K bytes of NVRAM.
62720K bytes of ATA CompactFlash (Read/Write)
main-offise#sh run
Current configuration : 5665 bytes
!
version 12.4
service config
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname main-offise
!
boot-start-marker
boot-end-marker
!
no logging buffered
no logging console
enable secret 5 $1$vmLG$Tbrgg59CCPBCh3IxH61OI/
enable password 7 0023180255551A14
!
aaa new-model
!
aaa authentication login default local
aaa authentication ppp default local
!
aaa session-id common
!
resource policy
!
mmi polling-interval 60
no mmi auto-configure
no mmi pvc
mmi snmp-timeout 180
ip subnet-zero
ip cef
!
ip name-server 10.1.1.2
ip name-server xxx.xxx.xxx.xxx
vpdn enable
!
voice-card 0
!
username XXX privilege 15 password 7 047C00025E2F5D5C
username XXX privilege 15 password 7 000A170C4A1B1D00012C0D
username XXX privilege 15 password 7 03354A5A12086714
!
interface Tunnel0
no ip address
!
interface Tunnel1
description Tunel to lan4
ip address 10.1.104.1 255.255.255.0
ip mtu 1500
tunnel source Dialer1
tunnel destination xxx.xxx.xxx.41
tunnel mode ipip
!
interface Tunnel2
description tunel to lan 3
ip address 10.1.103.1 255.255.255.0
ip mtu 1500
tunnel source Dialer1
tunnel destination xxx.xxx.xxx.42
tunnel mode ipip
!
interface Tunnel3
ip address 10.1.102.1 255.255.255.0
ip mtu 1500
tunnel source Dialer1
tunnel destination xxx.xxx.xxx.88
tunnel mode ipip
!
interface Tunnel4
description tun to lan 6
ip address 10.1.109.1 255.255.255.0
ip mtu 1500
tunnel source Dialer1
tunnel destination xxx.xxx.xxx.52
tunnel mode ipip
!
interface FastEthernet0/0
description Magazin 1 etazh
ip address 10.1.5.1 255.255.255.0
ip nat inside
duplex auto
speed auto
!
interface FastEthernet0/1
description main offise local
ip address 10.1.1.1 255.255.255.0
ip nat inside
ip tcp adjust-mss 1412
duplex auto
speed auto
!
interface ATM0/1/0
no ip address
no atm ilmi-keepalive
dsl operating-mode auto
!
interface ATM0/1/0.2 point-to-point
pvc 0/100
pppoe-client dial-pool-number 1
!
!
interface Virtual-Dot11Radio1
no ip address
!
interface Dialer1
ip address negotiated
ip mtu 1452
ip nat outside
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication chap pap callin
ppp chap hostname xxxxxxxx
ppp chap password 7 03270253535677696A5D3C
ppp pap sent-username xxxxxxxx password 7 03270253535677696A5D3C
!
router rip
network 10.0.0.0
!
ip local pool dialin-vpn 10.1.10.10 10.1.10.50
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer1
!
ip http server
ip http authentication local
no ip http secure-server
ip nat inside source list 100 interface Dialer1 overload
ip nat inside source static tcp 10.1.1.2 3389 xxx.xxx.xxx.40 34389 extendable
!
access-list 100 permit tcp host 10.1.1.2 any eq ftp
access-list 100 deny ip 10.0.0.0 0.255.255.255 host 195.239.51.8
access-list 100 deny ip 10.0.0.0 0.255.255.255 host 81.222.130.3
access-list 100 deny ip 10.0.0.0 0.255.255.255 host 89.108.91.137
access-list 100 deny ip 10.0.0.0 0.255.255.255 host 82.146.40.38
access-list 100 deny ip 10.0.0.0 0.255.255.255 host 78.108.81.30
access-list 100 deny ip 10.0.0.0 0.255.255.255 host 212.113.48.21
access-list 100 deny ip 10.0.0.0 0.255.255.255 host 75.125.134.114
access-list 100 permit tcp host 10.1.5.2 any eq www
access-list 100 permit tcp host 10.1.5.10 any
access-list 100 permit tcp host 10.1.5.11 any
access-list 100 deny tcp host 10.1.1.17 any
access-list 100 deny tcp host 10.1.1.31 any
access-list 100 deny tcp host 10.1.1.33 any
access-list 100 deny tcp host 10.1.1.35 any
access-list 100 permit tcp host 10.1.1.2 any eq 22
access-list 100 permit tcp host 10.1.1.2 any eq www
access-list 100 permit tcp host 10.1.1.2 any eq pop3
access-list 100 permit tcp host 10.1.1.2 any eq 143
access-list 100 permit tcp host 10.1.1.2 any eq 443
access-list 100 permit tcp host 10.1.1.2 any eq 478
access-list 100 permit tcp host 10.1.1.2 any eq 993
access-list 100 permit tcp host 10.1.1.2 any eq 995
access-list 100 permit tcp host 10.1.1.2 any eq 4899
access-list 100 permit tcp 10.0.0.0 0.255.255.255 any eq 1239
access-list 100 permit tcp host 10.1.1.2 any range 49152 65535
access-list 100 permit udp host 10.1.1.2 any eq domain
access-list 100 permit udp host 10.1.1.2 any eq ntp
access-list 100 permit tcp 10.1.5.0 0.0.0.255 any eq www
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq ftp
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq www
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq pop3
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq 8585
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq 143
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq 443
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq 478
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq smtp
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq 993
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq 995
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq 389
access-list 100 permit udp 10.1.1.0 0.0.0.255 any eq domain
access-list 100 permit udp 10.1.1.0 0.0.0.255 any eq ntp
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any range 49152 65535
access-list 100 permit icmp 10.1.1.0 0.0.0.255 any
access-list 100 permit gre 10.1.1.0 0.0.0.255 any
access-list 100 permit icmp 10.1.5.0 0.0.0.255 any
access-list 100 permit gre 10.1.5.0 0.0.0.255 any
access-list 100 deny ip any any
dialer-list 1 protocol ip permit
!
control-plane
!
line con 0
line aux 0
line vty 5 15
!
end
main-offise#sh proc cpu hist (через 1 минуту после восстановления связи)
main-offise 06:44:02 AM Wednesday Apr 28 2010 UTC
1111111111 11111 11111
100
90
80
70
60
50
40
30
20
10
0....5....1....1....2....2....3....3....4....4....5....5....
0 5 0 5 0 5 0 5 0 5
CPU% per second (last 60 seconds)
2212222111111112111211111111121212111111111111111111122222
100
90
80
70
60
50
40
30
20
10
0....5....1....1....2....2....3....3....4....4....5....5....
0 5 0 5 0 5 0 5 0 5
CPU% per minute (last 60 minutes)
* = maximum CPU% # = average CPU%
14 6332
9143454111212231223365002
100
90
80
70 *
60 *
50 *
40 * *
30 * ***
20 ** ****
10 ** * *****
0....5....1....1....2....2....3....3....4....4....5....5....6....6....7.
0 5 0 5 0 5 0 5 0 5 0 5 0
CPU% per hour (last 72 hours)
* = maximum CPU% # = average CPU%
Заранее благодарю за ответы!