
H3C 的三层作为 DNS 的 proxy ,无法解析一些特定的域名,比如 home.console.aliyun.com
在三层上无法 ping 这个 ip ,但是直接向上查询解析是 ok 的。
PC:
192.168.0.100/24,gatway=192.168.0.50,vlan=20,access
H3C 三层:
dns proxy enable dns server 10.0.0.60 iKuai:
dig baidu.com 正常
dig @192.168.0.50 baidu.com 正常 via 三层
dig @10.0.0.50 baidu.com 正常 via 三层
dig @10.0.0.20 baidu.com 正常 via 爱快
dig @10.0.0.60 baidu.com 正常 via 爱快 VIP
dig home.console.aliyun.com 不正常
dig @192.168.0.50 home.console.aliyun.com 不正常 via 三层
dig @10.0.0.50 home.console.aliyun.com 不正常 via 三层
dig @10.0.0.20 home.console.aliyun.com 正常 via 爱快
dig @10.0.0.60 home.console.aliyun.com 正常 via 爱快 VIP
<H3C>ping baidu.com Ping baidu.com (39.156.66.10): 56 data bytes, press CTRL_C to break 56 bytes from 39.156.66.10: icmp_seq=0 ttl=55 time=7.154 ms 56 bytes from 39.156.66.10: icmp_seq=1 ttl=55 time=6.585 ms 56 bytes from 39.156.66.10: icmp_seq=2 ttl=55 time=6.816 ms 56 bytes from 39.156.66.10: icmp_seq=3 ttl=55 time=6.693 ms 56 bytes from 39.156.66.10: icmp_seq=4 ttl=55 time=6.885 ms --- Ping statistics for baidu.com --- 5 packet(s) transmitted, 5 packet(s) received, 0.0% packet loss round-trip min/avg/max/std-dev = 6.585/6.827/7.154/0.193 ms <H3C>ping home.console.aliyun.com ping: Unknown host. <H3C>ping www.aliyun.com Ping www.aliyun.com (111.62.160.100): 56 data bytes, press CTRL_C to break 56 bytes from 111.62.160.100: icmp_seq=0 ttl=55 time=16.770 ms 56 bytes from 111.62.160.100: icmp_seq=1 ttl=55 time=16.701 ms 56 bytes from 111.62.160.100: icmp_seq=2 ttl=55 time=17.034 ms 56 bytes from 111.62.160.100: icmp_seq=3 ttl=55 time=16.447 ms 56 bytes from 111.62.160.100: icmp_seq=4 ttl=55 time=17.285 ms --- Ping statistics for www.aliyun.com --- 5 packet(s) transmitted, 5 packet(s) received, 0.0% packet loss round-trip min/avg/max/std-dev = 16.447/16.847/17.285/0.288 ms root@port:/etc/nginx/sites-enabled# dig @10.0.0.60 home.console.aliyun.com ;; Warning: Client COOKIE mismatch ; <<>> DiG 9.18.12-0ubuntu0.22.04.3-Ubuntu <<>> @10.0.0.60 home.console.aliyun.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 3431 ;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ; COOKIE: 83b36405866ca8bc (bad) ;; QUESTION SECTION: ;home.console.aliyun.com. IN A ;; ANSWER SECTION: home.console.aliyun.com. 37 IN CNAME one-console-adns.console.aliyun.com. one-console-adns.console.aliyun.com. 37 IN CNAME one-console-adns.console.aliyun.com.gds.alibabadns.com. one-console-adns.console.aliyun.com.gds.alibabadns.com. 37 IN CNAME sh.wagbridge.aliyun.aliyun.com. sh.wagbridge.aliyun.aliyun.com. 37 IN CNAME aliyun-adns.aliyun.com. aliyun-adns.aliyun.com. 37 IN CNAME aliyun-adns.aliyun.com.gds.alibabadns.com. aliyun-adns.aliyun.com.gds.alibabadns.com. 37 IN A 140.205.135.3 ;; Query time: 0 msec ;; SERVER: 10.0.0.60#53(10.0.0.60) (UDP) ;; WHEN: Tue Dec 05 22:20:59 CST 2023 ;; MSG SIZE rcvd: 537 root@port:/etc/nginx/sites-enabled# dig @10.0.0.60 www.aliyun.com ; <<>> DiG 9.18.12-0ubuntu0.22.04.3-Ubuntu <<>> @10.0.0.60 www.aliyun.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50166 ;; flags: qr rd ra; QUERY: 1, ANSWER: 19, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;www.aliyun.com. IN A ;; ANSWER SECTION: www.aliyun.com. 245 IN CNAME www-jp-de-intl-adns.aliyun.com. www-jp-de-intl-adns.aliyun.com. 245 IN CNAME www-jp-de-intl-adns.aliyun.com.gds.alibabadns.com. www-jp-de-intl-adns.aliyun.com.gds.alibabadns.com. 245 IN CNAME www.aliyun.com.w.cdngslb.com. www.aliyun.com.w.cdngslb.com. 245 IN A 111.32.210.193 www.aliyun.com.w.cdngslb.com. 245 IN A 111.32.209.196 www.aliyun.com.w.cdngslb.com. 245 IN A 111.32.209.192 www.aliyun.com.w.cdngslb.com. 245 IN A 111.32.209.194 www.aliyun.com.w.cdngslb.com. 245 IN A 111.32.209.197 www.aliyun.com.w.cdngslb.com. 245 IN A 111.32.210.189 www.aliyun.com.w.cdngslb.com. 245 IN A 111.32.210.188 www.aliyun.com.w.cdngslb.com. 245 IN A 111.32.210.192 www.aliyun.com.w.cdngslb.com. 245 IN A 111.62.160.96 www.aliyun.com.w.cdngslb.com. 245 IN A 111.62.160.94 www.aliyun.com.w.cdngslb.com. 245 IN A 111.62.160.98 www.aliyun.com.w.cdngslb.com. 245 IN A 111.62.160.97 www.aliyun.com.w.cdngslb.com. 245 IN A 111.62.160.95 www.aliyun.com.w.cdngslb.com. 245 IN A 111.62.160.99 www.aliyun.com.w.cdngslb.com. 245 IN A 111.62.160.93 www.aliyun.com.w.cdngslb.com. 245 IN A 111.62.160.100 ;; Query time: 0 msec ;; SERVER: 10.0.0.60#53(10.0.0.60) (UDP) ;; WHEN: Tue Dec 05 22:21:05 CST 2023 ;; MSG SIZE rcvd: 989 这个版本有什么升级建议吗?
<H3C>dis version H3C Comware Software, Version 7.1.070, Release 1312 Copyright (c) 2004-2019 New H3C Technologies Co., Ltd. All rights reserved. H3C S5560-54QS-EI uptime is 14 weeks, 1 day, 13 hours, 10 minutes Last reboot reason : Cold reboot Boot image: flash:/s5560ei-cmw710-boot-r1312.bin Boot image version: 7.1.070, Release 1312 Compiled Nov 19 2019 11:00:00 System image: flash:/s5560ei-cmw710-system-r1312.bin System image version: 7.1.070, Release 1312 Compiled Nov 19 2019 11:00:00 Slot 1: Uptime is 14 weeks,1 day,13 hours,10 minutes S5560-54QS-EI with 2 Processor BOARD TYPE: S5560-54QS-EI DRAM: 1984M bytes FLASH: 512M bytes PCB 1 Version: VER.B Bootrom Version: 128 CPLD 1 Version: 003 Release Version: H3C S5560-54QS-EI-1312 Patch Version : None Reboot Cause : ColdReboot [SubSlot 0] 48GE+4SFP Plus+2QSFP Plus 在官网看了下:
H3C S5560-EI系列以太网交换机 H3C S5560EI-CMW710-R3507P10 版本软件及说明书 40 | 加密软件与手册等级下载 H3C S5560EI-CMW710-R3507P08 版本软件及说明书 40 | 加密软件与手册等级下载 H3C S5560EI-CWM710-R3507P06版本软件及说明书 40 | 加密软件与手册等级下载 H3C S5560EI-CMW710-R3507P02 版本软件及说明书 40 | 加密软件与手册等级下载 H3C S5560EI-CMW710-R3507 版本软件及说明书 40 | 加密软件与手册等级下载 H3C S5560EI-CMW70-R3506P12 版本软件及说明书 40 | 加密软件与手册等级下载 H3C S5560EI-CMW710-R3506P10 版本软件及说明书 40 | 加密软件与手册等级下载 H3C S5560EI-CMW710-R3506P07 版本软件及说明书 40 | 加密软件与手册等级下载 H3C S5560EI-CMW710-R3506P02 版本软件及说明书 40 | 加密软件与手册等级下载 H3C S5560EI-CMW710-R3506 版本软件及说明书 40 | 加密软件与手册等级下载 感觉高我好多
1 mohumohu 2023-12-05 22:33:53 +08:00 1 、直接找 h3c 技术支持 2 、“既然三层负责 dhcp ,理论上下发的 dns 地址也是三层的 vlanip 为好” 似乎也没什么特别的好处 |
2 phpfpm OP |
3 datocp 2023-12-06 03:23:39 +08:00 via Android 用的华为的 s5720s li ,dhcp 是由 openwrt 分配的,那才叫真爽。。。 |
4 a8Fy37XzWf70G0yW 2023-12-06 15:47:48 +08:00 就是 H3C 的老 bug 了,我曾接的一 H3C S10500 系列的交也,所以是升固件吧。 是的如你所是 DNS PACKET 法解析文致的。 |