VistageraldosmecanismoskeepalivenoCiscoIOSndiceIntroduoInformaesdeApoioMecanismosdokeepalivedeinterfaceInterfacesdeEthernetInterfacesseriaisManutenesdeatividadedeHDLCManutenesdeatividadedePPPInterfacesdotúnelGREKeepalivescriptoKeepalivesdeIKEKeepalivesNATIntroduoEstedocumentodescreveosváriosmecanismoskeepalivenodoCiscoIOS.
InformaesdeApoioOsmensagensdekeepalivesoenviadosporumdispositivoderedeatravésdeumexameoudeunscircuitosvirtuaisafiminformaraindaumoutrodispositivoderedeesseocircuitoentreelesfunes.
ParaqueoKeepalivestrabalhehádoisfatoresessenciais:Ointervalokeepaliveéoperíododetempoentrecadamensagemdekeepalivequeéenviadoporumdispositivoderede.
Istoésempreconfigurável.
qAsnovastentativasdokeepalivesoonúmerodevezesqueodispositivocontinuaaenviarapacoteskeepalivesemrespostaantesqueoestadoestejamudadoa"parabaixo".
ParaalgunstiposdeKeepalivesistoéconfigurável,quandoparaoutrohouverumvalorpadroquenopossasermudado.
qMecanismosdokeepalivedeinterfaceInterfacesdeEthernetEmmeiosdetransmissotaiscomoumEthernet,oKeepalivesélevementeoriginal.
DesdequehámuitospossíveisvizinhosnosEthernet,okeepalivenoestáprojetadodeterminarseotrajetoaqualquerumvizinhoespecíficonofioestádisponível.
Projeta-sesomentecertificar-sedosistemalocaltenhaoacessodeleituraegravaoaofiodosEthernetpróprio.
OroteadorproduzumpacotedeEthernetcomsecomooendereoMACdeorigemededestinoeumcódigotipodeEthernetespecialde0x9000.
OhardwaredeEthernetenviaestepacotenofiodosEtherneteentorecebeimediatamenteestapartetraseiradopacoteoutravez.
IstoverificaohardwaredeemissoedereceponoadaptadordoEtherneteaintegridadebásicadofio.
InterfacesseriaisAsinterfacesserialpodemtertiposdiferentesdeencapsulamentosecadatipodeencapsulamentodeterminaotipodoKeepalivesqueseráusado.
InscrevaocomandokeepalivenomododeconfiguraodainterfaceafimajustarafrequênciaemqueumroteadorenviapacotesECHOREQaseupar:Afimrestaurarosistemaaointervalokeepalivedopadrodossegundos10,inscrevaocomandokeepalivecomnenhumapalavra-chave.
qAfimdesabilitaroKeepalives,inscrevaocomandodisabledokeepalive.
qNota:keepaliveOcomandoaplica-seàsinterfacesserialqueusamolinkdedadosdenívelelevadoContol(HDLC)ouoencapsulamentoPPP.
NoseaplicaàsinterfacesserialqueusamoEncapsulamentoframerelay.
Nota:ParaoPPPeostiposdoencapsulamentodeHDLC,umkeepalivedezerodesabilitaoKeepaliveseérelatadonocomandoshowrunning-configoutputcomoodesabilitaodokeepalive.
ManutenesdeatividadedeHDLCUmoutromecanismokeepaliveconhecidoémanutenesdeatividadeserialparaoHDLC.
AsmanutenesdeatividadeserialsoenviadasparaafrenteeparatrásentredoisRoteadoreseoKeepalivessoreconhecidos.
Comousodosnúmerosdesequênciaseguircadakeepalive,cadadispositivopodeconfirmarseéparHDLCrecebeuokeepalivequeenviou.
ParaoencapsulamentodeHDLC,trêsKeepalivesignoradosfazemcomquearelaosejaderrubada.
PermitaocomandodebugserialinterfaceparaumaconexodeHDLCafimpermitirqueousuárioveroKeepalivesqueégeradoeenviado:SampleOutput:17:21:09.
61f20;BACKGROUND-COLOR:#4ae2f7">85:Serial0/0:HDLCmyseq0,mineseen0*,yourseen1,lineupAsmanutenesdeatividadedeHDLCcontêmtrêspartesafimdeterminá-lotrabalham:O"myseq"queénossopróprionúmerodeincremento.
qO"mineseen"queérealmenteumreconhecimentodooutrolado(incrementado)quedizqueesperaestenúmerodenós.
q"Yourseen"queénossoreconhecimentoaooutrolado.
qNota:Quandoadiferenanosvaloresnoscamposdomyseqedomineseenexcedetrêsnoroteador2,alinhavaiparabaixoearelaoérestaurada.
DesdequeasmanutenesdeatividadedeHDLCsotipoKeepalivesECHOREQ,afrequênciadekeepaliveéimportanteerecomenda-sequecombinamacimaexatamenteemambososlados.
Seostemporizadoressoforadasincronizao,osnúmerosdesequênciacomeamsairdaordem.
Porexemplo,sevocêajustaumladoaossegundos10eooutroa25segundos,aindapermitiráarelaopermaneaacimaenquantoadiferenanafrequêncianoésuficienteparafazercomqueosnúmerosdesequênciaestejamporumadiferenadetrês.
ComoumailustraodecomoasmanutenesdeatividadedeHDLCtrabalham,oroteador1eoroteador2soconectadosdiretamenteatravésdoSerial0/0edoSerial2/0respectivamente.
AfimilustrarcomooKeepalivesfalhadoHDCLéusadoparaseguirosestadosdarelao,oSerial0/0seráfechadonoroteador1.
Roteador1Router1#showinterfacesserial0/0/0Serial0/0/0isup,lineprotocolisup(connected)HardwareisHD64570Internetaddressis10.
0.
0.
1/1f20;BACKGROUND-COLOR:#4ae2f7">8MTU1500bytes,BW64Kbit,DLY20000usec,rely255/255,load1/255EncapsulationHDLC,loopbacknotset,keepaliveset(10sec)[outputisomited]17:21:09.
61f20;BACKGROUND-COLOR:#4ae2f7">85:Serial0/0:HDLCmyseq0,mineseen0*,yourseen1,lineup17:21:19.
725:Serial0/0:HDLCmyseq1,mineseen1*,yourseen2,lineup17:21:29.
753:Serial0/0:HDLCmyseq2,mineseen2*,yourseen3,lineup17:21:39.
773:Serial0/0:HDLCmyseq3,mineseen3*,yourseen4,lineup17:21:49.
1f20;BACKGROUND-COLOR:#4ae2f7">805:Serial0/0:HDLCmyseq4,mineseen4*,yourseen5,lineup17:21:59.
1f20;BACKGROUND-COLOR:#4ae2f7">837:Serial0/0:HDLCmyseq5,mineseen5*,yourseen6,lineup17:22:09.
1f20;BACKGROUND-COLOR:#4ae2f7">865:Serial0/0:HDLCmyseq6,mineseen6*,yourseen7,lineup17:22:19.
905:Serial0/0:HDLCmyseq7,mineseen7*,yourseen1f20;BACKGROUND-COLOR:#4ae2f7">8,lineup17:22:29.
945:Serial0/0:HDLCmyseq1f20;BACKGROUND-COLOR:#4ae2f7">8,mineseen1f20;BACKGROUND-COLOR:#4ae2f7">8*,yourseen9,lineupRouter1(config-if)#shut17:22:39.
965:Serial0/0:HDLCmyseq9,mineseen9*,yourseen10,lineup17:22:42.
225:%LINK-5-CHANGED:InterfaceSerial0/0,changedstatetoadministrativelydown17:22:43.
245:%LINEPROTO-5-UPDOWN:LineprotocolonInterfaceSerial0/0,changedstatetodownRoteador2Router2#showinterfacesserial0/0/0Serial0/0/0isup,lineprotocolisup(connected)HardwareisHD64570Internetaddressis10.
0.
0.
2/1f20;BACKGROUND-COLOR:#4ae2f7">8MTU1500bytes,BW64Kbit,DLY20000usec,rely255/255,load1/255EncapsulationHDLC,loopbacknotset,keepaliveset(10sec)[outputisomited]17:21:04.
929:Serial2/0:HDLCmyseq0,mineseen0,yourseen0,lineup17:21:14.
941:Serial2/0:HDLCmyseq1,mineseen1*,yourseen1,lineup17:21:24.
961:Serial2/0:HDLCmyseq2,mineseen2*,yourseen2,lineup17:21:34.
91f20;BACKGROUND-COLOR:#4ae2f7">81:Serial2/0:HDLCmyseq3,mineseen3*,yourseen3,lineup17:21:45.
001:Serial2/0:HDLCmyseq4,mineseen4*,yourseen4,lineup17:21:55.
021:Serial2/0:HDLCmyseq5,mineseen5*,yourseen5,lineup17:22:05.
041:Serial2/0:HDLCmyseq6,mineseen6*,yourseen6,lineup17:22:15.
061:Serial2/0:HDLCmyseq7,mineseen7*,yourseen7,lineup17:22:25.
01f20;BACKGROUND-COLOR:#4ae2f7">81:Serial2/0:HDLCmyseq1f20;BACKGROUND-COLOR:#4ae2f7">8,mineseen1f20;BACKGROUND-COLOR:#4ae2f7">8*,yourseen1f20;BACKGROUND-COLOR:#4ae2f7">8,lineup17:22:35.
101:Serial2/0:HDLCmyseq9,mineseen9*,yourseen9,lineup17:22:45.
113:Serial2/0:HDLCmyseq10,mineseen10*,yourseen10,lineup17:22:55.
133:Serial2/0:HDLCmyseq11,mineseen10,yourseen10,lineup17:23:05.
153:HD(0):Resetfrom0x203751f20;BACKGROUND-COLOR:#4ae2f7">817:23:05.
153:HD(0):AssertingDTR17:23:05.
153:HD(0):AssertingDTRandRTS17:23:05.
153:Serial2/0:HDLCmyseq12,mineseen10,yourseen10,lineup17:23:15.
173:HD(0):Resetfrom0x203751f20;BACKGROUND-COLOR:#4ae2f7">817:23:15.
173:HD(0):AssertingDTR17:23:15.
173:HD(0):AssertingDTRandRTS17:23:15.
173:Serial2/0:HDLCmyseq13,mineseen10,yourseen10,linedown17:23:16.
201:%LINEPROTO-5-UPDOWN:LineprotocolonInterfaceSerial2/0,changedstatetodownRouter2#17:23:25.
193:Serial2/0:HDLCmyseq14,mineseen10,yourseen10,linedownManutenesdeatividadedePPPAsmanutenesdeatividadedePPPsoumpoucodiferentesdasmanutenesdeatividadedeHDLC.
AocontráriodoHDLC,asmanutenesdeatividadedePPPsomaiscomosibilos.
Osambososladospodemsibilar-seemseulazer.
OmovimentonegociadoapropriadoéresponderSEMPREaeste"sibilo".
AssimparamanutenesdeatividadedePPP,afrequênciaouovalordetemporizadorsosomentelocalmenterelevanteenotêmnenhumimpactonooutrolado.
MesmoseumladodesligaoKeepalives,aindaRESPONDER2aquelasrequisiesdeecodoladoquetemumtemporizadordekeepalive.
Contudo,nuncainiciaráalgumadoseuspróprios.
PermitaocomandodebugppppacketparaumaconexoPPPafimpermitirqueousuárioverasmanutenesdeatividadedePPPquesoenviadas:Router2#showinterfacesserial0/0/0Serial0/0/0isup,lineprotocolisup(connected)HardwareisHD64570Internetaddressis10.
0.
0.
2/1f20;BACKGROUND-COLOR:#4ae2f7">8MTU1500bytes,BW64Kbit,DLY20000usec,rely255/255,load1/255EncapsulationHDLC,loopbacknotset,keepaliveset(10sec)[outputisomited]17:21:04.
929:Serial2/0:HDLCmyseq0,mineseen0,yourseen0,lineup17:21:14.
941:Serial2/0:HDLCmyseq1,mineseen1*,yourseen1,lineup17:21:24.
961:Serial2/0:HDLCmyseq2,mineseen2*,yourseen2,lineup17:21:34.
91f20;BACKGROUND-COLOR:#4ae2f7">81:Serial2/0:HDLCmyseq3,mineseen3*,yourseen3,lineup17:21:45.
001:Serial2/0:HDLCmyseq4,mineseen4*,yourseen4,lineup17:21:55.
021:Serial2/0:HDLCmyseq5,mineseen5*,yourseen5,lineup17:22:05.
041:Serial2/0:HDLCmyseq6,mineseen6*,yourseen6,lineup17:22:15.
061:Serial2/0:HDLCmyseq7,mineseen7*,yourseen7,lineup17:22:25.
01f20;BACKGROUND-COLOR:#4ae2f7">81:Serial2/0:HDLCmyseq1f20;BACKGROUND-COLOR:#4ae2f7">8,mineseen1f20;BACKGROUND-COLOR:#4ae2f7">8*,yourseen1f20;BACKGROUND-COLOR:#4ae2f7">8,lineup17:22:35.
101:Serial2/0:HDLCmyseq9,mineseen9*,yourseen9,lineup17:22:45.
113:Serial2/0:HDLCmyseq10,mineseen10*,yourseen10,lineup17:22:55.
133:Serial2/0:HDLCmyseq11,mineseen10,yourseen10,lineup17:23:05.
153:HD(0):Resetfrom0x203751f20;BACKGROUND-COLOR:#4ae2f7">817:23:05.
153:HD(0):AssertingDTR17:23:05.
153:HD(0):AssertingDTRandRTS17:23:05.
153:Serial2/0:HDLCmyseq12,mineseen10,yourseen10,lineup17:23:15.
173:HD(0):Resetfrom0x203751f20;BACKGROUND-COLOR:#4ae2f7">817:23:15.
173:HD(0):AssertingDTR17:23:15.
173:HD(0):AssertingDTRandRTS17:23:15.
173:Serial2/0:HDLCmyseq13,mineseen10,yourseen10,linedown17:23:16.
201:%LINEPROTO-5-UPDOWN:LineprotocolonInterfaceSerial2/0,changedstatetodownRouter2#17:23:25.
193:Serial2/0:HDLCmyseq14,mineseen10,yourseen10,linedownerespostasquesorecebidas:Router2#showinterfacesserial0/0/0Serial0/0/0isup,lineprotocolisup(connected)HardwareisHD64570Internetaddressis10.
0.
0.
2/1f20;BACKGROUND-COLOR:#4ae2f7">8MTU1500bytes,BW64Kbit,DLY20000usec,rely255/255,load1/255EncapsulationHDLC,loopbacknotset,keepaliveset(10sec)[outputisomited]17:21:04.
929:Serial2/0:HDLCmyseq0,mineseen0,yourseen0,lineup17:21:14.
941:Serial2/0:HDLCmyseq1,mineseen1*,yourseen1,lineup17:21:24.
961:Serial2/0:HDLCmyseq2,mineseen2*,yourseen2,lineup17:21:34.
91f20;BACKGROUND-COLOR:#4ae2f7">81:Serial2/0:HDLCmyseq3,mineseen3*,yourseen3,lineup17:21:45.
001:Serial2/0:HDLCmyseq4,mineseen4*,yourseen4,lineup17:21:55.
021:Serial2/0:HDLCmyseq5,mineseen5*,yourseen5,lineup17:22:05.
041:Serial2/0:HDLCmyseq6,mineseen6*,yourseen6,lineup17:22:15.
061:Serial2/0:HDLCmyseq7,mineseen7*,yourseen7,lineup17:22:25.
01f20;BACKGROUND-COLOR:#4ae2f7">81:Serial2/0:HDLCmyseq1f20;BACKGROUND-COLOR:#4ae2f7">8,mineseen1f20;BACKGROUND-COLOR:#4ae2f7">8*,yourseen1f20;BACKGROUND-COLOR:#4ae2f7">8,lineup17:22:35.
101:Serial2/0:HDLCmyseq9,mineseen9*,yourseen9,lineup17:22:45.
113:Serial2/0:HDLCmyseq10,mineseen10*,yourseen10,lineup17:22:55.
133:Serial2/0:HDLCmyseq11,mineseen10,yourseen10,lineup17:23:05.
153:HD(0):Resetfrom0x203751f20;BACKGROUND-COLOR:#4ae2f7">817:23:05.
153:HD(0):AssertingDTR17:23:05.
153:HD(0):AssertingDTRandRTS17:23:05.
153:Serial2/0:HDLCmyseq12,mineseen10,yourseen10,lineup17:23:15.
173:HD(0):Resetfrom0x203751f20;BACKGROUND-COLOR:#4ae2f7">817:23:15.
173:HD(0):AssertingDTR17:23:15.
173:HD(0):AssertingDTRandRTS17:23:15.
173:Serial2/0:HDLCmyseq13,mineseen10,yourseen10,linedown17:23:16.
201:%LINEPROTO-5-UPDOWN:LineprotocolonInterfaceSerial2/0,changedstatetodownRouter2#17:23:25.
193:Serial2/0:HDLCmyseq14,mineseen10,yourseen10,linedownAsmanutenesdeatividadedePPPcontêmtrêspartes:NúmerodeID-usadoparaidentificaraqueoECHOREQoparresponde.
qTipokeepalive-OECHOREQéKeepalivesenviadopelodispositivodeorigemeoqECHOREPérespostasenviadaspelopar.
Númerosmágicos-asnotificaesincluemosnúmerosmágicosdoserveredoclienteremoto.
OparvalidaonúmeromágiconopacotederequisiodeecoLCP,etransmiteopacotederespostadeecocorrespondenteLCPquecontémonúmeromágiconegociadopeloroteador.
qParaoencapsulamentoPPP,cincoKeepalivesignoradosfazemcomquearelaosejaderrubadaInterfacesdotúnelGREOmecanismokeepalivedotúnelGREélevementediferentedoqueparaEthernetouinterfacesserial.
DáacapacidadeparaqueumladoorigineerecebapacoteskeepaliveaedeumroteadorremotomesmoseoroteadorremotonoapoiamanutenesdeatividadedeGRE.
DesdequeoGREéummecanismodetunelamentodopacoteparaescavarumtúneloIPdentrodoIP,umpacotedotúnelIPGREpodeserconstruídodentrodeumoutropacotedotúnelIPGRE.
ParamanutenesdeatividadedeGRE,asPRE-construesdoremetenteopacotedarespostadekeepalivedentrodopacotederequisiodokeepaliveoriginaldemodoqueasnecessidadesdaextremidaderemotasomentedefazerodesencapsulamentoGREpadrodocabealhoIPexteriorGREeenviamentoopacoteGREinternoIP.
Estemecanismofazcomquearespostadekeepaliveenvieparaforaainterfacefísicaumpoucodoqueainterfacedetúnel.
ParamaisdetalhesaotrabalhardoKeepalivesdotúnelGRE,vejacomoasmanutenesdeatividadedeGREtrabalham.
KeepalivescriptoKeepalivesdeIKEOKeepalivesdoInternetKeyExchange(IKE)éummecanismousadoparadeterminarseumparVPNpodeascendenteereceberotráfegocriptografado.
OKeepalivescriptoseparadoéexigidoalémdoquekeepalivesdeinterfaceporqueosparesVPNgeralmentesoconectadosnuncadevoltaàpartetraseira,assimqueoskeepalivesdeinterfacenofornecembastanteinformaosobreoestadodoparVPN.
EmdispositivosIOSCisco,oskeepalivesdeIKEsopermitidospelousodeummétodoproprietáriochamadooDeadPeerDetection(DPD).
AfimpermitirqueogatewayenvieDPDaopar,incorporeestecomandoaomododeconfiguraoglobal:cryptoisakmpkeepaliveseconds[retry-seconds][periodic|on-demand]AfimdesabilitaroKeepalives,use"no"oformuláriodestecomando.
Paraobtermaisinformaessobredoquecadapalavra-chavenestecomandofaz,vejaokeepalivecriptodoisakmp.
Paramaisgranularidade,oKeepalivespodeigualmenteserconfiguradosoboperfilISAKMP.
Paramaisdetalhes,vejao[CiscoIOSIPsec]davistageraldoperfilISAKMP.
KeepalivesNATEmcasodasencenaesondeumparVPNestáatrásdeumNetworkAddressTranslation(NAT),NAT-Traversaléusadoparaacriptografia.
Contudo,duranteperíodosociososépossívelqueaentradaNATnodispositivoascendentepdecronometrarparafora.
IstopodecausarproblemasquandovocêtrazacimaotúneleoNATnoébidirecional.
OKeepalivesNATépermitidoafimmanterotraodinmicoNATvivoduranteumaconexoentredoispares.
OKeepalivesNATépacotesdeUDPcomumpayloadunencrypteddeumbyte.
EmboraaaplicaoatualDPDsejasimilaraoKeepalivesNAT,háumapequenadiferena-oDPDestáusadoparadetectarostatusdepeerquandooKeepalivesNATforenviadoseaentidadedoIPsecnoenviounemrecebeuopacoteemumperíododetempoespecificado.
Ointervaloválidoestáentre5a3600segundos.
Dica:SeoKeepalivesNATestápermitido(atravésdocomandokeepalivenatdoisamkpcripto),osusuáriosdevemassegurar-sedequeovalorinativosejamaiscurtodoqueotempodeexpiraodomapeamentoNATde20segundos.
Paraobtermaisinformaessobredestacaracterística,vejaatransparênciadeNATdoIPsec.
今天中午的时候看到群里网友在讨论新版本的Apache HTTP Server 2.4.51发布且建议更新升级,如果有服务器在使用较早版本的话可能需要升级安全,这次的版本中涉及到安全漏洞的问题。Apache HTTP 中2.4.50的修复补丁CVE-2021-41773 修复不完整,导致新的漏洞CVE-2021-42013。攻击者可以使用由类似别名的指令配置将URL映射到目录外的文件的遍历攻击。这里...
RAKsmart怎么样?RAKsmart是一家由华人运营的国外主机商,提供的产品包括独立服务器租用和VPS等,可选数据中心包括美国加州圣何塞、洛杉矶、中国香港、韩国、日本、荷兰等国家和地区数据中心(部分自营),支持使用PayPal、支付宝等付款方式,网站可选中文网页,提供中文客服支持。本月商家继续提供每日限量秒杀服务器月付30.62美元起,除了常规服务器外,商家美国/韩国/日本站群服务器、1-10...
今天有看到Raksmart账户中有一台VPS主机即将到期,这台机器之前是用来测试评测使用的。这里有不打算续费,这不面对万一导致被自动续费忘记,所以我还是取消自动续费设置。如果我们也有类似的问题,这里就演示截图设置Raksmart取消自动续费。这里我们可以看到上图,在对应VPS主机的【其余操作】中可以看到默认已经是不自动续费,所以我们也不要担心被自动续费的。当然,如果有被自动续费,我们确实不想续费的...
tcpip上的netbios为你推荐
Thresholdcss思科flash设备ipad奶粉ios8供应商iphonenetbios端口netbios ssn是什么意思?tcpip上的netbios网络连接详细信息上的netbios over tcpip是什么意思?x-routerX-Router这个软件有什么用fusioncharts如何自定义FusionCharts图表上的工具提示?ms17-010win10蒙林北冬虫夏草酒·10年原浆1*6 500ml 176,176是一瓶的价格还是一箱的价格
免备案虚拟主机 快速域名备案 什么是域名解析 淘宝二级域名 老鹰主机 分销主机 秒解服务器 payoneer 42u机柜尺寸 亚洲小于500m 中国电信测速112 百兆独享 网站卫士 什么是服务器托管 免费网页申请 环聊 东莞idc 空间登陆首页 丽萨 linode支付宝 更多