C:\>tracert -d www.beihai365.com
Tracing route to web1.beihai365.com [222.216.28.18
over a maximum of 30 hops:
1 * * * Request timed out.
2 3 ms 1 ms 1 ms 218.65.152.49
3 5 ms 6 ms 5 ms 218.65.152.9
4 5 ms 6 ms 5 ms 218.65.136.6
5 16 ms 19 ms 22 ms 218.65.173.54
6 12 ms 10 ms 10 ms 222.217.167.174
7 10 ms 12 ms 10 ms 222.217.167.134
8 * 902 ms 887 ms 222.216.28.3
看最后一条路由。 知道进入机房网关很慢。。
让机房检查了。。机房说 机房木有问题
好的。上服务器。 直接就ping 网关和其他 服务器。 ping 网关的时候很慢。 ping 其他服务器没问题
web1# ping 222.216.28.129
PING 222.216.28.129 (222.216.28.129): 56 data bytes
64 bytes from 222.216.28.129: icmp_seq=0 ttl=255 time=355.228 ms
^C
--- 222.216.28.129 ping statistics ---
2 packets transmitted, 1 packets received, 50.0% packet loss
round-trip min/avg/max/stddev = 355.228/355.228/355.228/0.000 ms
web1# ping 222.216.28.130
PING 222.216.28.130 (222.216.28.130): 56 data bytes
64 bytes from 222.216.28.130: icmp_seq=0 ttl=128 time=0.826 ms
就可以决定是机房问题了。然后再检查下
arp: 222.216.28.134 moved from 00:26:18:d7:de:1c to 00:0f:e2:23:86:31 on em0
arp: 222.216.28.134 moved from 00:0f:e2:23:86:31 to 00:26:18:d7:de:1c on em0
arp: 222.216.28.134 moved from 00:26:18:d7:de:1c to 00:0f:e2:23:86:31 on em0
arp: 222.216.28.134 moved from 00:0f:e2:23:86:31 to 00:26:18:d7:de:1c on em0
arp: 222.216.28.134 moved from 00:26:18:d7:de:1c to 00:0f:e2:23:86:31 on em0
arp: 222.216.28.134 moved from 00:0f:e2:23:86:31 to 00:26:18:d7:de:1c on em0
arp: 222.216.28.134 moved from 00:26:18:d7:de:1c to 00:0f:e2:23:86:31 on em0
arp: 222.216.28.134 moved from 00:0f:e2:23:86:31 to 00:26:18:d7:de:1c on em0
内部网有ARP攻击迹象。
。。证据再次。机房无法抵赖了。。。
最后经过机房处理。。。一切都好了