trunk口不通防火墙_交换机S5700与防火墙USG5500无法对接Eth-trunk LACP-static模式

问题:

交换机S5700与防火墙USG5500无法对接Eth-trunk LACP-static模式,两端正常配置后,端口状态显示错误,Eth-trunk端口无法up 。

问题描述:

交换机侧 GE0/0/5和GE 0/0/6 组成Eth-trunk3 通过LACP-static与防火墙对接;防火墙侧采用端口GE0/0/1和GE0/0/2组成Eth-trunk1通过LACP-static与交换机对接。

交换机侧配置:

interface Eth-Trunk3

port link-type trunk

undo port trunk allow-pass vlan 1

port trunk allow-pass vlan 301 321

mode lacp-static

#

interface GigabitEthernet0/0/5

eth-trunk 3

#

interface GigabitEthernet0/0/6

eth-trunk 3

#

防火墙侧的配置:

interface Eth-Trunk1

alias Eth-Trunk1

mode lacp-static

#interface GigabitEthernet0/0/1

undo enable snmp trap updown physic-status

eth-trunk 1

lacp peer-portno 0002

#

interface GigabitEthernet0/0/2

undo enable snmp trap updown physic-status

eth-trunk 1

lacp peer-portno 0003

#

交换机侧端口状态显示:

单独查看物理端口,其物理状态UP;

[Ser-9306-1]disp interface GigabitEthernet 0/0/5

GigabitEthernet0/0/5 current state : UP

Line protocol current state : UP

Description:

Switch Port, TPID : 8100(Hex), The Maximum Frame Length is 9216

IP Sending Frames' Format is PKTFMT_ETHNT_2, Hardware address is 4c1f-cc99-5ec3

Last physical up time   : 2014-02-26 16:29 UTC-08:00

Last physical down time : 2014-02-26 16:29 UTC-08:00

Current system time: 2014-02-26 16:29-08:00

Hardware address is 4c1f-cc99-5ec3

Last 300 seconds input rate 0 bytes/sec, 0 packets/sec

Last 300 seconds output rate

你可能感兴趣的:(trunk口不通防火墙)