>>[оверквотинг удален] сделал ночные тесты, результаты ниже
> насчет mtu согласен, это на случай, когда трафик пойдет. Похоже трабл с
> обратным путем. Что показывает ping 192.168.8.1 source 192.168.5.1 и trace
> с машины 192.168.5.2? Можно параллельно debug ip icmp включить, но он
пинг с loc2:
loc2#ping 192.168.8.1 so 192.168.5.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.8.1, timeout is 2 seconds:
Packet sent with a source address of 192.168.5.1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 32/33/36 ms
пинг с dc:
dc#ping 192.168.5.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.5.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 32/32/36 ms
dc#ping 192.168.5.2 so 192.168.3.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.5.2, timeout is 2 seconds:
Packet sent with a source address of 192.168.3.1
.....
Success rate is 0 percent (0/5)
трейс и таблица маршрутизции с 5.2 (loc2-gw):
loc2-gw# traceroute -n 192.168.3.1
traceroute to 192.168.3.1 (192.168.3.1), 64 hops max, 40 byte packets
1 192.168.5.1 (192.168.5.1) 1.691 ms 1.623 ms 1.868 ms
2 * * *
3 * * *
4 *^CDestination Gateway Flags Refs Use Netif Expire
default 192.168.5.1 UGS 16846 230707321 xl0
127.0.0.1 link#4 UH 0 3616796 lo0
192.168.2.0/24 link#2 U 3036 568740143 sk0
192.168.2.237 link#2 UHS 0 312317212 lo0
192.168.5.0/30 link#1 U 586 16392446 xl0
192.168.5.2 link#1 UHS 0 2720661 lo0
> не всегда все пакеты показывает. Есть возможность подключить на loc2 к
> f0/0/0 комп с программой типа Wireshark ? Что показывает sh
> ip rout в loc2?
вполне правильную картину, на мой взгляд (tunnel3 - это tunnel1 из моего изначального конфига, просто сейчас там еще 2 туннеля tun1,tun2 до loc1 в shutdown-е):
Gateway of last resort is zzz.zzz.aaa.agw to network 0.0.0.0D EX 192.168.122.0/24 [170/28160256] via 192.168.3.1, 00:00:50, Tunnel3
D 192.168.8.0/24 [90/27008000] via 192.168.3.1, 00:00:50, Tunnel3
D EX 192.168.10.0/24 [170/27008000] via 192.168.3.1, 00:00:50, Tunnel3
172.16.0.0/29 is subnetted, 1 subnets
D 172.16.250.0 [90/28160256] via 192.168.3.1, 00:00:50, Tunnel3
D 192.168.11.0/24 [90/27008000] via 192.168.3.1, 00:00:50, Tunnel3
192.168.4.0/30 is subnetted, 3 subnets
D 192.168.4.8 [90/29440000] via 192.168.3.1, 00:00:50, Tunnel3
D 192.168.4.4 [90/29440000] via 192.168.3.1, 00:00:50, Tunnel3
D 192.168.4.0 [90/28160000] via 192.168.3.1, 00:00:50, Tunnel3
yyy.yyy.aaa.0/32 is subnetted, 1 subnets
S yyy.yyy.aaa.aaa [1/0] via zzz.zzz.aaa.agw
192.168.5.0/30 is subnetted, 1 subnets
C 192.168.5.0 is directly connected, Vlan4
D EX 10.0.0.0/8 [170/28160256] via 192.168.3.1, 00:00:50, Tunnel3
zzz.zzz.aaa.0/29 is subnetted, 1 subnets
C zzz.zzz.aaa.aaa is directly connected, Vlan2
D 192.168.7.0/24 [90/27008000] via 192.168.3.1, 00:00:50, Tunnel3
zzz.zzz.bbb.0/29 is subnetted, 1 subnets
C zzz.zzz.bbb.bbb is directly connected, Vlan3
yyy.yyy.bbb.0/32 is subnetted, 1 subnets
S yyy.yyy.bbb.bbb [1/0] via zzz.zzz.bbb.bgw
S 192.168.2.0/24 [1/0] via 192.168.5.2
C 192.168.3.0/24 is directly connected, Tunnel3
S* 0.0.0.0/0 [1/0] via zzz.zzz.aaa.agw
[1/0] via zzz.zzz.bbb.bgw
D EX 192.168.160.0/19 [170/27008000] via 192.168.3.1, 00:00:50, Tunnel3
для сравнения картина когда туннели подняты 2 туннеля до loc1 (каждый через своего провайдера):
Gateway of last resort is zzz.zzz.aaa.agw to network 0.0.0.0D EX 192.168.122.0/24 [170/26880256] via 192.168.4.9, 11:51:31, Tunnel1
[170/26880256] via 192.168.4.5, 11:51:31, Tunnel2
D 192.168.8.0/24 [90/28288000] via 192.168.4.9, 11:51:31, Tunnel1
[90/28288000] via 192.168.4.5, 11:51:31, Tunnel2
D EX 192.168.10.0/24 [170/28288000] via 192.168.4.9, 11:51:31, Tunnel1
[170/28288000] via 192.168.4.5, 11:51:31, Tunnel2
172.16.0.0/29 is subnetted, 1 subnets
D 172.16.250.0 [90/26880256] via 192.168.4.9, 11:51:31, Tunnel1
[90/26880256] via 192.168.4.5, 11:51:31, Tunnel2
D 192.168.11.0/24 [90/28288000] via 192.168.4.9, 11:51:31, Tunnel1
[90/28288000] via 192.168.4.5, 11:51:31, Tunnel2
192.168.4.0/30 is subnetted, 3 subnets
C 192.168.4.8 is directly connected, Tunnel1
C 192.168.4.4 is directly connected, Tunnel2
D 192.168.4.0 [90/28160000] via 192.168.4.9, 11:51:32, Tunnel1
[90/28160000] via 192.168.4.5, 11:51:32, Tunnel2
yyy.yyy.aaa.0/32 is subnetted, 1 subnets
S yyy.yyy.aaa.aaa [1/0] via zzz.zzz.aaa.agw
192.168.5.0/30 is subnetted, 1 subnets
C 192.168.5.0 is directly connected, Vlan4
D EX 10.0.0.0/8 [170/26880256] via 192.168.4.9, 11:51:32, Tunnel1
[170/26880256] via 192.168.4.5, 11:51:32, Tunnel2
zzz.zzz.aaa.0/29 is subnetted, 1 subnets
C zzz.zzz.aaa.64 is directly connected, Vlan2
D 192.168.7.0/24 [90/28288000] via 192.168.4.9, 11:51:32, Tunnel1
[90/28288000] via 192.168.4.5, 11:51:32, Tunnel2
zzz.zzz.bbb.0/29 is subnetted, 1 subnets
C zzz.zzz.bbb.bbb is directly connected, Vlan3
yyy.yyy.bbb.0/32 is subnetted, 1 subnets
S yyy.yyy.bbb.bbb [1/0] via zzz.zzz.bbb.bgw
S 192.168.2.0/24 [1/0] via 192.168.5.2
S* 0.0.0.0/0 [1/0] via zzz.zzz.aaa.agw
[1/0] via zzz.zzz.bbb.bgw
D EX 192.168.160.0/19 [170/28288000] via 192.168.4.9, 11:51:32, Tunnel1
[170/28288000] via 192.168.4.5, 11:51:32, Tunnel2