
1¡¢control-plane½ûÖ¹µÇ¼ÉèÖã¬ACL¹ýÂËÏÞÖÆ£¬VTYÏß³ÌÕ¼Âú
2¡¢NGINX½ø³Ì¶ªÊ§
1¡¢µÇ¼µØÖ·´íÎó
a. consoleÏߵǼ¿ÉÒԲ鿴½Ó¿ÚµØÖ·£¬¾ßÌåÃüÁîΪshow ip interface brief
ÈçÉÏĿǰ2¿ÚΪÄÚÍø¿Ú£¬7¿ÚΪÍâÍø¿ÚµØÖ·£¬¿ÉÒÔͨ¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼É豸£¬ÍâÍøÓû§Ö»ÄÜͨ¹ýÍâÍø¿ÚµØÖ·µÇ¼É豸
2¡¢µÇ¼¶Ë¿Ú´íÎó
ÃüÁîÐпÉÒÔͨ¹ýshow web-serviceÈ·¶¨µÇ¼¶Ë¿Ú

1¡¢±¾µØ·À¹¥»÷ÉèÖýûÖ¹webµÇ¼µÇ¼µÈ²Ù×÷
¡¾±¸×¢¡¿
¶ÔÓ¦ÃüÁîΪ£º
control-plane
security deny lan-web-----½ûÖ¹ÄÚÍøwebµÇ¼É豸
security deny wan-web-----½ûÖ¹ÍâÍøwebµÇ¼É豸
2¡¢ ÔÚ½Ó¿Úµ÷Óûòip session filterµ÷ÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
a. ½Ó¿Ú·ÃÎÊÁбíϵĵ÷Óã¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP


b. Ip session filter Á÷¹ýÂ˲Ù×÷£¬È«¾Öµ÷Óã¬È«¾ÖÉúЧ£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
c¡¢Line vtyϵ÷ÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î·ÃÎÊÉ豸£¬µ¼ÖÂÎÞ·¨telnet
Ëùµ÷ÓõÄACL161ÐèÒª·ÅͨµÇ¼É豸µÄ¶Ë¿Ú»òIPµØÖ·
¾ßÌå·¾¶£º°²È«—ACL·ÃÎÊÁбí
ÅäÖÃÍ꣬ÃüÁîÐжÔӦϷ¢µÄÃüÁîÈçÏ£º


¾ßÌåÅäÖÃÈçÏ£º
ÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½É豸µÇ¼¶Ë¿Ú±ÈÈç˵80¡¢4430£¬»òÕßÊÇÅäÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬µ¼ÖÂÉ豸µÇ¼¶Ë¿Ú±»Õ¼Ó㬻ᵼÖÂÉ豸ÎÞ·¨µÇ¼£¬
1¡¢¶Ë¿ÚÓ³ÉäÅäÖÃ
¶ÔÓ¦ÃüÁîÈçÏ£ºip nat inside source static tcp 192.168.1.10 80 172.18.161.111 80
2.¡¢Õû»úÓ³ÉäÅäÖÃ

¶ÔÓ¦ÃüÁîÈçÏ£ºip nat inside source static 192.168.1.10 172.18.161.111 permit-inside
¡¾½â¾ö·½·¨¡¿£º½«ÍâÍøÓ³Éä¶Ë¿Ú80»òÕß4430Ó³ÉäΪ1080»òÕß14430µÈ¶Ë¿Ú£¬±ÜÃâ¶Ë¿ÚÕ¼ÓÃÎÊÌâ¡£
¶àÌõÍâÍøÏßµÄÇé¿öÏÂûÓпªÆôÔ´½øÔ´³ö£¬µ¼ÖÂÍâÍø·ÃÎʵ½É豸µÄÊý¾ÝÁ÷³öÏÖ´Ó½Ó¿Ú7½øÀ´µ«ÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£
ËùÒÔÔÚÍâÍø¿ÚÐèÒª¿ªÆôÔ´½øÔ´³ö£¬¾ßÌå·¾¶ÈçÏ£ºÍøÂç—½Ó¿ÚÅäÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö


¶ÔÓ¦µÄÃüÁîÈçÏ£º

1¡¢µÇ¼·þÎñûÓпªÆô£¬¾ßÌåÃüÁîΪ£ºweb·þÎñÊÇ·ñ¿ªÆôshow web-service

2¡¢²é¿´¶Ë¿ÚÊÇ·ñÕý³£¼àÌý
£¨1£©Show tcp connect £¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬

Show cpu | in nginx £¬NGINX½ø³ÌÕ¼ÓýÏС£¬ÊôÓÚÕý³£ÏÖÏó

δ·âshell³¡¾°Ï£º
Run-system-shell
ps aux | grep nginx

·âshell³¡¾°Ï£¬²é¿´½ø³Ì
Debug support
execute diagnose-cmd ps –ef nginx

£¨2£©Èô½ø³Ì²»´æÔÚ£¬ÐèÒªÖØÆô½ø³Ì¿´ÏÂÊÇ·ñÕý³£
Run-system-shell
/etc/rc.d/init.d/nginx start ÖØÆônginx½ø³Ì
/etc/rc.d/init.d/lnsp start ÖØÆôphp½ø³Ì
·âshell³¡¾°ÏÂ
Debug su
execute diagnose-cmd process nginx stop
execute diagnose-cmd process nginx start
£¨3£©ÈônginxµÄ½ø³Ìcpu¸ß
µ¼ÖÂwebµÇ¼²»ÉÏ£¬tcp connectÏÔʾÐÂÁ¬½Ó¶¼syn_rev£¬×¥°üÏÔʾegûÓлذü


½â¾ö·½·¨£º
1. show cpu | in nginx È·¶¨nginx½ø³ÌÐòÁкÅ
2. ɱµô½ø³Ì£¬²»Ó°ÏìÆäËûʹÓã¬Ö»Ó°Ïìweb
debug su
execute diagnose-cmd kill ÐòÁкÅ

3. Kill½ø³Ìºó£¬ÐèÒªÊÖ¶¯ÖØÆô½ø³Ì

½â¾ö¹«º£²Ê´¬¡¤6600¹ÙÍø£º
1. Ôö¼Ó°²ÅÅ·À»¤£¬Ö»ÔÊÐí¹ÜÀíÔ±µÇ¼web

2. µÍ·åÆÚÏÂÔØ×îа汾¡£
sh ver
sh run
sh web-service
sh cpu | in nginx
sh int usage
sh ver all
sh tcp connect
sh memory
sh cpu | ex 0.00
sh log rev
show int usage
sh envir
sh ip fpm sta
debug su
execute diagnose-cmd fdisk
execute diagnose-cmd mount
exit
1¡¢ÐÂÉ豸µÄĬÈϵǼ½Ó¿ÚΪGI0/0½Ó¿Ú£¬¹ÜÀíµØÖ·Îª192.168.1.1£¬µçÄÔÐèÒªÉèÖÃÏàÍ¬Íø¶Î²ÅÄܵǼ¡£
2¡¢É豸ĬÈϽûÖ¹wan¿ÚµÇ¼£¬ÐèҪעÒâ¡£
3¡¢Èç¹û¼ì²éWEB¹¦Äܶ¼Õý³££¬ÈÔÈ»ÎÞ·¨µÇ¼£¬¿ÉÒԲο¼ÉÏÊö²½ÖèÖØÆôweb½ø³Ì²âÊÔÏ¡£
¡¾²¹³ä¡¿Èçδ½â¾ö»òÐèÒªÁ˽â¸ü¶àÏêÇ飬¿Éµã»÷ÊÛºóÉÁµçÍýøÐÐ×Éѯ