好文档就是一把金锄头!
欢迎来到金锄头文库![会员中心]
电子文档交易市场
安卓APP | ios版本
电子文档交易市场
安卓APP | ios版本

juniper日常维护和故障响应.ppt

40页
  • 卖家[上传人]:枫**
  • 文档编号:606612106
  • 上传时间:2025-05-23
  • 文档格式:PPT
  • 文档大小:287KB
  • / 40 举报 版权申诉 马上下载
  • 文本预览
  • 下载提示
  • 常见问题
    • Click to edit Master title style,Click to edit Master text styles,Second level,Third level,Fourth level,Fifth level,*,防火墙日常维护和故障响应,常规维护,获得基本信息,检查NSRP状态,提高预警水平,策略配置与优化,攻击防御,特殊应用处理,整理业务拓扑和记录,搭建模拟环境,常规维护获得系统基本信息,Get sys-cfg,:了解系统的各种缺省参数设置,Get clock,:确定系统时间,get session info,:,85%,Get session,:查看,session,列表,Get performance session detail,:查看,session,的历史记录,get session id ,:查看,session,细节,get performance cpu,:,50%,get performance cpu detail,:查看,CPU,历史记录,get performance cpu all detail,常规维护获得系统基本信息,Get memory,:采用,“,预分配”机制,,172.27.10.251/512,1(8/0),chose interface trust as incoming nat if.,search route to(trust,192.168.100.205-172.27.10.251)in vr trust-vr for vsd-0/flag-0/ifp-null,Dest 2.route 172.27.10.251-0.0.0.0,to untrust,routed(172.27.10.251,0.0.0.0)from trust(trust in 0)to untrust,policy search from zone 2-zone 1,No SW RPC rule match,search HW rule,Permitted by policy 9,No src xlate choose interface untrust as outgoing phy if,no loop on ifp untrust.,session application type 0,name None,timeout 60sec,service lookup identified service 0.,Session(id:818)created for first pak 1,arp,nsp2 wing prepared,ready,cache mac in the session,flow got session.,flow session id 818,post addr xlation:192.168.100.205-172.27.10.251.,应急处理,Debug,*,997629.0:packet received 60*,ipid=29278(725e),03c391d0,packet passed sanity check.,untrust:172.27.10.251/512-192.168.100.205/4608,1(0/0),existing session found.sess token 3,flow got session.,flow session id 818,post addr xlation:172.27.10.251-192.168.100.205.,IKE Debugger Basics,For simplicity,try to only initiate only 1 IKE tunnel at a time.,To turn the debugger ON/OFF,debug ike basic/debug ike detail,Try to run the debug during a scheduled downtime,IKE Debug Example,P1:Initiate,IKE*Recv kernel msg IDX-0,TYPE-5*,IKE Phase 1:Initiated negotiation in main mode.172.27.10.208,IKE Construct ISAKMP header.,IKE Construct SA for ISAKMP,IKE Construct NetScreen VID,IKE Construct custom VID,IKE Xmit:SA VID VID,IKE*Recv packet if of vsys *,IKE Recv:SA VID VID,IKE Process VID:,IKE Process VID:,IKE Process SA:,IKE Construct ISAKMP header.,IKE Construct KE for ISAKMP,IKE Construct NONCE,IKE Xmit:KE NONCE,IKE*Recv packet if of vsys *,IKE Recv:KE NONCE,IKE Process KE:,IKE Process NONCE:,IKE Construct ISAKMP header.,IKE Construct ID for ISAKMP,IKE Construct HASH,IKE Xmit*:ID HASH,IKE*Recv packet if of vsys *,IKE Recv*:ID HASH,IKE Process ID:,IKE Process HASH:,IKE Phase 1:Completed Main mode negotiation with a-second lifetime.,IKE Debug Example,P2:Initiate,IKE Phase 2:Initiated Quick Mode negotiation.,IKE Construct ISAKMP header.,IKE Construct HASH,IKE Construct SA for IPSEC,IKE Construct NONCE for IPSec,IKE Construct KE for PFS,IKE Construct ID for Phase 2,IKE Construct ID for Phase 2,IKE Xmit*:HASH SA NONCE KE ID ID,IKE*Recv packet if of vsys *,IKE Recv*:HASH SA NONCE KE ID ID,IKE Process SA:,IKE Process KE:,IKE Process NONCE:,IKE Process ID:,IKE Process ID:,IKE Phase 2 msg-id:Completed Quick Mode negotiation with SPI,tunnel ID,and lifetime seconds/KB.,IKE Construct ISAKMP header.,IKE Construct HASH in QM,IKE Xmit*:HASH,IKE Debug Example,P1:Responser,IKE*Recv packet if of vsys *,IKE Recv:SA VID VID,IKE Process VID:,IKE Process VID:,IKE Process SA:,IKE Construct ISAKMP header.,IKE Construct SA for ISAKMP,IKE Construct NetScreen VID,IKE Construct custom VID,IKE Xmit:SA VID VID,IKE*Recv packet if of vsys *,IKE Recv:KE NONCE,IKE Process KE:,IKE Process NONCE:,IKE Construct ISAKMP header.,IKE Construct KE for ISAKMP,IKE Construct NONCE,IKE Xmit:KE NONCE,IKE*Recv packet if of vsys *,IKE Recv*:ID HASH,IKE Process ID:,IKE Process HASH:,IKE Construct ISAKMP header.,IKE Construct ID for ISAKMP,IKE Construct HASH,IKE Xmit*:ID HASH,IKE Phase 1:Completed Main mode negotiation with a-second lifetime.,IKE Debug Example,P2:Responser,IKE*Recv packet if of vsys *,IKE Recv*:HASH SA NONCE KE ID ID,IKE Process SA:,IKE Process KE:,IKE Process NONCE:,IKE Process ID:,IKE Process ID:,IKE Construct ISAKMP header.,IKE Construct HASH,IKE Construct SA for IPSEC,IKE Construct NONCE for IPSec,IKE Construct KE for PFS,IKE Construct ID for Phase 2,IKE Construct ID for Phase 2,IKE Xmit*:HASH SA NONCE KE ID ID,IKE*Recv packet if of vsys *,IKE Recv*:HASH,IKE Phase 2 msg-id:Completed Quick Mode negotiation with SPI,tunnel ID,and lifetime seconds/KB.,Debug?,admin debug admin,arp arp debugging,asp ASP debugging,asset-recovery asset recovery debugging,auth user authentication debugging,autocfg Auto config debugging,av AntiVirus debugging,bgp bgp debugging,cluster command propagated to cluster members,cpapi cpapi debugging,dhcp debug dhcp,dip dip debugging,dlog dlog debugging,dns dns debugging,driver driver debugging,emweb EmWeb debugging,filesys Filesys debugging,flash flash operating debugging,flow Flow level debugging,flow-tunnel Flow Tunnel debugging,fs file system debugging,gc gc receive and transmit debug,gdb GDB debugging,global-pro global-pro debugging,gt generic tunnel debugging,gtmac gtmac debug,h323 h323 debugging,httpfx http-fx debuggi。

      点击阅读更多内容
      关于金锄头网 - 版权申诉 - 免责声明 - 诚邀英才 - 联系我们
      手机版 | 川公网安备 51140202000112号 | 经营许可证(蜀ICP备13022795号)
      ©2008-2016 by Sichuan Goldhoe Inc. All Rights Reserved.