02-24-2003 02:06 PM - edited 03-02-2019 05:20 AM
--begin ciscomoderator note-- The following post has been edited to remove potentially confidential information. The configuration was removed, edited and posted as a new message by ciscomoderator due to newly implimented posting size restrictions. Please refrain from posting confidential information on the site to reduce security risks to your network. -- end ciscomoderator note --
Im having problem with some of the serial ports of my 3661 router. I got two 4 port serial network modules (NM-4 A/S) slotted into slot 1 and 2 and was working fine. I recently slot in a 16 port analogue modem module and add in the dial up config (aaa) and work fine for 4 days until I face problems with the serial ports. I have check with the telco and they said the line is OK. When I connect the link to another router serial port (cisco 2522) it works fine.
Serial will be up while line protocol would be down. It will happen to one port then gradually moving to the other ports until all ports goes down.
Do I need to upgrade my current IOS ?(refer to show ver below for my current one) And If I need to upgrade it, can someone tell me which version is best to upgrade to.
or
Is there a problem with my dial up configuration. Please help
Here is an e.g of a port affected:
-----------------------------------
Serial1/3 is up, line protocol is down
Hardware is M4T
Description: Trade_Commerce
Internet address is 10.1.254.13/30
MTU 1500 bytes, BW 64 Kbit, DLY 20000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation PPP, crc 16, loopback not set
Keepalive not set
LCP REQsent
Closed: LEXCP, BRIDGECP, IPCP, CCP, CDPCP, LLC2, BACP
Last input 00:00:02, output 00:00:00, output hang never
Last clearing of "show interface" counters 01:39:40
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: weighted fair
Output queue: 0/1000/64/0 (size/max total/threshold/drops)
Conversations 0/17/256 (active/max active/max total)
Reserved Conversations 0/0 (allocated/max allocated)
Available Bandwidth 48 kilobits/sec
5 minute input rate 0 bits/sec, 1 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
7479 packets input, 86760 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
5959 packets output, 74444 bytes, 0 underruns
0 output errors, 0 collisions, 1497 interface resets
0 output buffer failures, 0 output buffers swapped out
1497 carrier transitions DCD=up DSR=up DTR=up RTS=up CTS=up
here is the show diag from my router:
---------------------------------------
--moderator edit-- Router1#sho diag
3660 Chassis type: ENTERPRISE
c3600 Backplane EEPROM:
Hardware Revision : 1.0
Top Assy. Part Number : 800-04740-02
Board Revision : C0
Deviation Number : 0-0
Fab Version : 02
PCB Serial Number : HAD04471SGX
RMA Test History : 00
RMA Number : 0-0-0-0
RMA History : 00
Chassis Serial Number : JAB0549801G
Chassis MAC Address : 0007.85bf.34c0
MAC Address block size : 112
Manufacturing Test Data : 00 00 00 00 00 00 00 00
Fab Part Number : 28-2651-02
Number of Slots : 6
EEPROM format version 4
EEPROM contents (hex):
0x00: 04 FF 40 00 C8 41 01 00 C0 46 03 20 00 12 84 02
0x10: 42 43 30 80 00 00 00 00 02 02 C1 8B 48 41 44 30
0x20: 34 34 37 31 53 47 58 03 00 81 00 00 00 00 04 00
0x30: C2 8B 4A 41 42 30 35 34 39 38 30 31 47 C3 06 00
0x40: 07 85 BF 34 C0 43 00 70 C4 08 00 00 00 00 00 00
0x50: 00 00 85 1C 0A 5B 02 01 06 FF FF FF FF FF FF FF
0x60: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
0x70: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
Slot 0:
C3600 Mother board 1FE(TX) Port adapter, 1 port
Port adapter is analyzed
Port adapter insertion time unknown
EEPROM contents at hardware discovery:
PCB Serial Number : JAB05440FND
Processor type : 34
Top Assy. Part Number : 800-05293-04
Board Revision : C0
Fab Part Number : 28-3234-02
Deviation Number : 65535-65535
Manufacturing Test Data : FF FF FF FF FF FF FF FF
RMA Number : 255-255-255-255
RMA Test History : FF
RMA History : FF
Field Diagnostics Data : FF FF FF FF FF FF FF FF
EEPROM format version 4
EEPROM contents (hex):
0x00: 04 FF C1 8B 4A 41 42 30 35 34 34 30 46 4E 44 09
0x10: 34 40 00 DA C0 46 03 20 00 14 AD 04 42 43 30 85
0x20: 1C 0C A2 02 80 FF FF FF FF C4 08 FF FF FF FF FF
0x30: FF FF FF 81 FF FF FF FF 03 FF 04 FF C5 08 FF FF
0x40: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
0x50: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
0x60: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
0x70: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 00
Slot 1:
Mueslix-4T Port adapter, 4 ports
Port adapter is analyzed
Port adapter insertion time unknown
EEPROM contents at hardware discovery:
Hardware revision 1.1 Board revision J0
Serial number 26536025 Part number 800-02314-02
Test history 0x0 RMA number 00-00-00
EEPROM format version 1
EEPROM contents (hex):
0x20: 01 54 01 01 01 94 E8 59 50 09 0A 02 00 00 00 00
0x30: 98 00 00 00 01 11 29 00 00 05 FF FF FF FF FF FF
Slot 2:
Mueslix-4T Port adapter, 4 ports
Port adapter is analyzed
Port adapter insertion time unknown
EEPROM contents at hardware discovery:
Hardware revision 1.1 Board revision J0
Serial number 26553974 Part number 800-02314-02
Test history 0x0 RMA number 00-00-00
EEPROM format version 1
EEPROM contents (hex):
0x20: 01 54 01 01 01 95 2E 76 50 09 0A 02 00 00 00 00
0x30: 98 00 00 00 01 10 17 00 00 05 FF FF FF FF FF FF
Slot 3:
Analog Modem Port adapter, 16 ports
Port adapter is analyzed
Port adapter insertion time unknown
EEPROM contents at hardware discovery:
Hardware revision 1.0 Board revision F0
Serial number 29089157 Part number 800-02841-02
Test history 0x0 RMA number 00-00-00
EEPROM format version 1
EEPROM contents (hex):
0x20: 01 6F 01 00 01 BB DD 85 50 0B 19 02 00 00 00 00
0x30: 78 00 00 00 02 09 24 17 FF FF FF FF FF FF FF FF
Here is my show version:
---------------------------
--moderator edit-- Router1#sho ver
Cisco Internetwork Operating System Software
IOS (tm) 3600 Software (C3660-I-M), Version 12.2(5a), RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2001 by cisco Systems, Inc.
Compiled Thu 04-Oct-01 22:21 by pwade
Image text-base: 0x600089C0, data-base: 0x60A60000
ROM: System Bootstrap, Version 12.0(6r)T, RELEASE SOFTWARE (fc1)
--moderator edit-- Router1 uptime is 5 days, 20 hours, 43 minutes
System returned to ROM by reload
System image file is "flash:c3660-i-mz.122-5a.bin"
cisco 3660 (R527x) processor (revision 1.0) with 28672K/4096K bytes of memory.
Processor board ID JAB0549801G
R527x CPU at 225Mhz, Implementation 40, Rev 10.0, 2048KB L2 Cache
Bridging software.
X.25 software, Version 3.0.0.
3660 Chassis type: ENTERPRISE
1 FastEthernet/IEEE 802.3 interface(s)
8 Serial network interface(s)
16 terminal line(s)
DRAM configuration is 64 bits wide with parity disabled.
125K bytes of non-volatile configuration memory.
8192K bytes of processor board System flash (Read/Write)
Configuration register is 0x2102
02-24-2003 02:39 PM
Need to know what happens to those serial ports when you reboort the 3600. Are they come back up/up or remain up/down?
If they can't comeback up at all and the serial line works fine in some other routers meams those serail ports may have gone physically bad.
I can also see that some ports are in "shutdown" mode so try to swap serial lines there and see the problem follows with ports or with serial lines.
02-24-2003 08:39 PM
Hi, I have noticed that keepalives have been disabled
on the serial interfaces. AFAIK, keepalives are important
to keep the interface active. There were also quite a number
of interface resets. You might want to try enabling the
keepalives and use the default period value of 10 seconds.
HTH.
02-26-2003 08:53 PM
tepatel,
When I reboot the router(reload) it still stays the same. Serial up/line down
When I swap the connection to a working port on the same module, it shut that port down.
I just remove the dialup config (aaa new-model) out of curiosity and it works fine now. Serial up/line up
Could it be my AAA configuration or could it be my IOS version. If I need to upgrade my IOS version, to what version you will recommend
manasco,
When I turn keepalive the problem still occurs
regards
03-02-2003 03:28 PM
I need help on this as I need to put up our dialup. The thing is whenever I put in the AAA part (refer to my config) it affects the serial ports after say, 2 or 3 days.
Do I need to configure dialer list ?
03-03-2003 07:33 PM
Adding the AAA commands & adding the modem module should not affect the serial interfaces.
show interface s1/3:
Serial1/3 is up, line protocol is down
LCP REQsent <===means that this router is sending LCP req OUT , probably is not getting a response back from the remote router. Ideally LCP should be OPEN.
1497 carrier transitions <===
If we have access to the remote router that's connected to serial1/3 (across the WAN) then will be interesting to see "debug ppp nego" at both end & also output of "sh interface serial x/y" after clearing the counters.
Thanks, Mak.
03-04-2003 05:15 PM
Should I add this command "dialer-list 1 protocol ip permit" and
dialer in-band
dialer idle-timeout 600
dialer-group 1
on interface group-async 1
I saw this in a configuration example on Cisco − Configuring Dialin with the NM−8AM or NM−16AM Analog Modem Module.
Whenever I add AAA commands (refer to my config)for my dial up the serial interface will behave like this after about 2 or 3 days.
Whenever I remove the commands, the lines will come up again with LCP open etc..connectivity established
03-04-2003 06:16 PM
Depends on whether you want idle users to be disconnected or not & after how much time of inactivity.....Only for a dialin we do not need these commands provided we do not need to specify the "dialer idle-timeout xxx"
Without the "dialer in-band" configured first we cannot add "dialer idle-timeout" ....now for the dialer idle timeout to work correctly we need to specify interesting traffic (dialer-list xxxxx & dialer-group x)
Long ago there was a known issue where we would need to config all the above (CSCdi18469)....having them will NOT hurt.
Please capture "deb ppp nego" on both ends when the serial line is UP/DOWN & when you remove the AAA commands.
Thanks, Mak.
03-05-2003 01:23 PM
Here is the result of the "debug ppp nego" I capture yesterday when the same thing happens
ITC_Services#debug ppp negotiation
PPP protocol negotiation debugging is on
ITC_Services#terminal monitor
ITC_Services#
2w0d: Se1/1 IPCP: LCP not open, discarding packet
2w0d: Se1/1 CDPCP: LCP not open, discarding packet
2w0d: Se1/1 LCP: I TERMACK [TERMsent] id 65 len 4
2w0d: Se1/1 LCP: State is Closed
2w0d: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
2w0d: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
2w0d: Se1/1 LCP: State is Listen
2w0d: Se1/1 LCP: TIMEout: State Listen
2w0d: Se1/1 LCP: O CONFREQ [Listen] id 66 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086CA08 (0x05065086CA08)
2w0d: Se1/1 LCP: I CONFREQ [REQsent] id 90 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C0C86 (0x0506025C0C86)
2w0d: Se1/1 LCP: O CONFACK [REQsent] id 90 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C0C86 (0x0506025C0C86)
2w0d: Se1/1 LCP: I CONFACK [ACKsent] id 66 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086CA08 (0x05065086CA08)
2w0d: Se1/1 LCP: State is Open
2w0d: Se1/1 AAA/AUTHOR/LCP: Denied
2w0d: Se1/1 PPP: Phase is TERMINATING [0 sess, 1 load]
2w0d: Se1/1 LCP: O TERMREQ [Open] id 67 len 4
2w0d: Se1/1 IPCP: LCP not open, discarding packet
2w0d: Se1/1 CDPCP: LCP not open, discarding packet
2w0d: Se1/1 LCP: I TERMACK [TERMsent] id 67 len 4
2w0d: Se1/1 LCP: State is Closed
2w0d: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
2w0d: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
2w0d: Se1/1 LCP: State is Listen
2w0d: Se1/1 LCP: TIMEout: State Listen
2w0d: Se1/1 LCP: O CONFREQ [Listen] id 68 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086D1F4 (0x05065086D1F4)
2w0d: Se1/1 LCP: I CONFREQ [REQsent] id 91 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C1470 (0x0506025C1470)
2w0d: Se1/1 LCP: O CONFACK [REQsent] id 91 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C1470 (0x0506025C1470)
2w0d: Se1/1 LCP: I CONFACK [ACKsent] id 68 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086D1F4 (0x05065086D1F4)
2w0d: Se1/1 LCP: State is Open
2w0d: Se1/1 AAA/AUTHOR/LCP: Denied
2w0d: Se1/1 PPP: Phase is TERMINATING [0 sess, 1 load]
2w0d: Se1/1 LCP: O TERMREQ [Open] id 69 len 4
2w0d: Se1/1 IPCP: LCP not open, discarding packet
2w0d: Se1/1 CDPCP: LCP not open, discarding packet
2w0d: Se1/1 LCP: I TERMACK [TERMsent] id 69 len 4
2w0d: Se1/1 LCP: State is Closed
2w0d: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
2w0d: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
2w0d: Se1/1 LCP: State is Listen
2w0d: Se1/1 LCP: TIMEout: State Listen
2w0d: Se1/1 LCP: O CONFREQ [Listen] id 70 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086D9E1 (0x05065086D9E1)
2w0d: Se1/1 LCP: I CONFREQ [REQsent] id 92 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C1C5A (0x0506025C1C5A)
2w0d: Se1/1 LCP: O CONFACK [REQsent] id 92 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C1C5A (0x0506025C1C5A)
2w0d: Se1/1 LCP: I CONFACK [ACKsent] id 70 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086D9E1 (0x05065086D9E1)
2w0d: Se1/1 LCP: State is Open
2w0d: Se1/1 AAA/AUTHOR/LCP: Denied
2w0d: Se1/1 PPP: Phase is TERMINATING [0 sess, 1 load]
2w0d: Se1/1 LCP: O TERMREQ [Open] id 71 len 4
2w0d: Se1/1 IPCP: LCP not open, discarding packet
2w0d: Se1/1 CDPCP: LCP not open, discarding packet
2w0d: Se1/1 LCP: I TERMACK [TERMsent] id 71 len 4
2w0d: Se1/1 LCP: State is Closed
2w0d: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
2w0d: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
2w0d: Se1/1 LCP: State is Listen
2w0d: Se1/1 LCP: TIMEout: State Listen
2w0d: Se1/1 LCP: O CONFREQ [Listen] id 72 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086E1CD (0x05065086E1CD)
2w0d: Se1/1 LCP: I CONFREQ [REQsent] id 93 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C2444 (0x0506025C2444)
2w0d: Se1/1 LCP: O CONFACK [REQsent] id 93 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C2444 (0x0506025C2444)
2w0d: Se1/1 LCP: I CONFACK [ACKsent] id 72 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086E1CD (0x05065086E1CD)
2w0d: Se1/1 LCP: State is Open
2w0d: Se1/1 AAA/AUTHOR/LCP: Denied
2w0d: Se1/1 PPP: Phase is TERMINATING [0 sess, 1 load]
2w0d: Se1/1 LCP: O TERMREQ [Open] id 73 len 4
2w0d: Se1/1 IPCP: LCP not open, discarding packet
2w0d: Se1/1 CDPCP: LCP not open, discarding packet
2w0d: Se1/1 LCP: I TERMACK [TERMsent] id 73 len 4
2w0d: Se1/1 LCP: State is Closed
2w0d: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
2w0d: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
2w0d: Se1/1 LCP: State is Listen
2w0d: Se1/1 LCP: TIMEout: State Listen
2w0d: Se1/1 LCP: O CONFREQ [Listen] id 74 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086E9BA (0x05065086E9BA)
2w0d: Se1/1 LCP: I CONFREQ [REQsent] id 94 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C2C2E (0x0506025C2C2E)
2w0d: Se1/1 LCP: O CONFACK [REQsent] id 94 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C2C2E (0x0506025C2C2E)
2w0d: Se1/1 LCP: I CONFACK [ACKsent] id 74 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086E9BA (0x05065086E9BA)
2w0d: Se1/1 LCP: State is Open
2w0d: Se1/1 AAA/AUTHOR/LCP: Denied
2w0d: Se1/1 PPP: Phase is TERMINATING [0 sess, 1 load]
2w0d: Se1/1 LCP: O TERMREQ [Open] id 75 len 4
2w0d: Se1/1 IPCP: LCP not open, discarding packet
2w0d: Se1/1 CDPCP: LCP not open, discarding packet
2w0d: Se1/1 LCP: I TERMACK [TERMsent] id 75 len 4
2w0d: Se1/1 LCP: State is Closed
2w0d: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
2w0d: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
2w0d: Se1/1 LCP: State is Listen
2w0d: Se1/1 LCP: TIMEout: State Listen
2w0d: Se1/1 LCP: O CONFREQ [Listen] id 76 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086F1A7 (0x05065086F1A7)
2w0d: Se1/1 LCP: I CONFREQ [REQsent] id 95 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C3418 (0x0506025C3418)
2w0d: Se1/1 LCP: O CONFACK [REQsent] id 95 len 10
2w0d: Se1/1 LCP: MagicNumber 0x025C3418 (0x0506025C3418)
2w0d: Se1/1 LCP: I CONFACK [ACKsent] id 76 len 10
2w0d: Se1/1 LCP: MagicNumber 0x5086F1A7 (0x05065086F1A7
03-05-2003 06:06 PM
I just tried this out in my lab...
aaa authorization network default group radius local if-authenticated
we are saying that authorize only if authenticated, under the serial interfaces we do not have any authentication commands, so to make this work:
1)Add the "ppp authentication chap pap" under the serial interfaces & appropriately create accounts on the Radius server. OR
2)Change to "aaa authorization network default group radius local" that is remove the if-authenticated.
I noticed that with the serial links UP & adding this command there are no issues, how ever when we do a shut / no shut it fails on the authorization.....this explains why you had problem after 2-3 days, maybe the serial went down & was trying to come back UP but then failed.
Thanks, Mak.
03-05-2003 09:17 PM
I have done that and will wait and see if there will be any problem again. Here is my dialup config:
aaa new-model
aaa authentication login use-radius group radius local
aaa authentication ppp use-radius group radius local
aaa authorization exec default group radius local if-authenticated
aaa authorization network default group radius local
interface Group-Async1
ip unnumbered FastEthernet0/0
encapsulation ppp
no ip route-cache
no ip mroute-cache
keepalive 10
async dynamic address
async mode dedicated
peer default ip address pool dialin
ppp reliable-link
ppp authentication ms-chap use-radius
group-range 97 112
line 97 112
script dialer cisco-default
login authentication use-radius
modem InOut
transport input all
autoselect during-login
flowcontrol hardware
03-06-2003 08:47 AM
You can test the serial for correct operation by doing a shut/ no shut on the interface...look at "debug ppp nego".
If you want to add authentication under the serial interfaces, will need to add:
"ppp authentication chap use-radius" ...can have chap pap etc.
Thanks, Mak.
03-06-2003 01:28 PM
I did a shu/no shut on serial 1/1and come up with the same problem. debug ppp nego..and here is the result.
If I have to put "ppp authentication chap use-radius on the serial ports, do I need to add it to the serial ports of the remote routers connected to the serial ports and do anything on the Radius server ?
20:48:41: Se1/1 PPP: Treating connection as a dedicated line
20:48:41: Se1/1 PPP: Phase is ESTABLISHING, Active Open [0 sess, 1 load]
20:48:41: Se1/1 LCP: O CONFREQ [Closed] id 3 len 10
20:48:41: Se1/1 LCP: MagicNumber 0x0BFCFCE3 (0x05060BFCFCE3)
ITC_Services#
20:48:42: %SYS-5-CONFIG_I: Configured from console by test on vty0 (10.1.87.80)
20:48:43: Se1/1 LCP: TIMEout: State REQsent
20:48:43: Se1/1 LCP: O CONFREQ [REQsent] id 4 len 10
20:48:43: Se1/1 LCP: MagicNumber 0x0BFCFCE3 (0x05060BFCFCE3)
20:48:43: Se1/1 LCP: I CONFREQ [REQsent] id 25 len 10
20:48:43: Se1/1 LCP: MagicNumber 0x0B09F007 (0x05060B09F007)
20:48:43: Se1/1 LCP: O CONFACK [REQsent] id 25 len 10
20:48:43: Se1/1 LCP: MagicNumber 0x0B09F007 (0x05060B09F007)
20:48:43: Se1/1 LCP: I CONFACK [ACKsent] id 4 len 10
20:48:43: Se1/1 LCP: MagicNumber 0x0BFCFCE3 (0x05060BFCFCE3)
20:48:43: Se1/1 LCP: State is Open
20:48:43: Se1/1 AAA/AUTHOR/LCP: Denied
20:48:43: Se1/1 PPP: Phase is TERMINATING [0 sess, 1 load]
20:48:43: Se1/1 LCP: O TERMREQ [Open] id 5 len 4
20:48:43: Se1/1 IPCP: LCP not open, discarding packet
20:48:43: Se1/1 CDPCP: LCP not open, discarding packet
20:48:43: Se1/1 LCP: I TERMACK [TERMsent] id 5 len 4
20:48:43: Se1/1 LCP: State is Closed
20:48:43: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
20:48:43: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
20:48:43: Se1/1 LCP: State is Listen
20:48:45: Se2/1 LCP: TIMEout: State Listen
20:48:45: Se2/1 LCP: O CONFREQ [Listen] id 133 len 10
20:48:45: Se2/1 LCP: MagicNumber 0x0BFD0935 (0x05060BFD0935)
20:48:45: Se1/1 LCP: TIMEout: State Listen
20:48:45: Se1/1 LCP: O CONFREQ [Listen] id 6 len 10
20:48:45: Se1/1 LCP: MagicNumber 0x0BFD0C9E (0x05060BFD0C9E)
20:48:45: Se1/1 LCP: I CONFREQ [REQsent] id 26 len 10
20:48:45: Se1/1 LCP: MagicNumber 0x0B09F7F1 (0x05060B09F7F1)
20:48:45: Se1/1 LCP: O CONFACK [REQsent] id 26 len 10
20:48:45: Se1/1 LCP: MagicNumber 0x0B09F7F1 (0x05060B09F7F1)
20:48:45: Se1/1 LCP: I CONFACK [ACKsent] id 6 len 10
20:48:45: Se1/1 LCP: MagicNumber 0x0BFD0C9E (0x05060BFD0C9E)
20:48:45: Se1/1 LCP: State is Open
20:48:45: Se1/1 AAA/AUTHOR/LCP: Denied
20:48:45: Se1/1 PPP: Phase is TERMINATING [0 sess, 1 load]
20:48:45: Se1/1 LCP: O TERMREQ [Open] id 7 len 4
20:48:45: Se1/1 IPCP: LCP not open, discarding packet
20:48:45: Se1/1 CDPCP: LCP not open, discarding packet
20:48:45: Se1/1 LCP: I TERMACK [TERMsent] id 7 len 4
20:48:45: Se1/1 LCP: State is Closed
20:48:45: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
20:48:45: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
20:48:45: Se1/1 LCP: State is Listen
20:48:47: Se1/1 LCP: TIMEout: State Listen
20:48:47: Se1/1 LCP: O CONFREQ [Listen] id 8 len 10
20:48:47: Se1/1 LCP: MagicNumber 0x0BFD1488 (0x05060BFD1488)
20:48:47: Se1/1 LCP: I CONFREQ [REQsent] id 27 len 10
20:48:47: Se1/1 LCP: MagicNumber 0x0B09FFDB (0x05060B09FFDB)
20:48:47: Se1/1 LCP: O CONFACK [REQsent] id 27 len 10
20:48:47: Se1/1 LCP: MagicNumber 0x0B09FFDB (0x05060B09FFDB)
20:48:47: Se1/1 LCP: I CONFACK [ACKsent] id 8 len 10
20:48:47: Se1/1 LCP: MagicNumber 0x0BFD1488 (0x05060BFD1488)
20:48:47: Se1/1 LCP: State is Open
20:48:47: Se1/1 AAA/AUTHOR/LCP: Denied
20:48:47: Se1/1 PPP: Phase is TERMINATING [0 sess, 1 load]
20:48:47: Se1/1 LCP: O TERMREQ [Open] id 9 len 4
20:48:47: Se1/1 IPCP: LCP not open, discarding packet
20:48:47: Se1/1 CDPCP: LCP not open, discarding packet
20:48:47: Se1/1 LCP: I TERMACK [TERMsent] id 9 len 4
20:48:47: Se1/1 LCP: State is Closed
20:48:47: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
20:48:47: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
20:48:47: Se1/1 LCP: State is Listen
20:48:49: Se1/1 LCP: TIMEout: State Listen
20:48:49: Se1/1 LCP: O CONFREQ [Listen] id 10 len 10
20:48:49: Se1/1 LCP: MagicNumber 0x0BFD1C73 (0x05060BFD1C73)
20:48:49: Se1/1 LCP: I CONFREQ [REQsent] id 28 len 10
20:48:49: Se1/1 LCP: MagicNumber 0x0B0A07C5 (0x05060B0A07C5)
20:48:49: Se1/1 LCP: O CONFACK [REQsent] id 28 len 10
20:48:49: Se1/1 LCP: MagicNumber 0x0B0A07C5 (0x05060B0A07C5)
20:48:49: Se1/1 LCP: I CONFACK [ACKsent] id 10 len 10
20:48:49: Se1/1 LCP: MagicNumber 0x0BFD1C73 (0x05060BFD1C73)
20:48:49: Se1/1 LCP: State is Open
20:48:49: Se1/1 AAA/AUTHOR/LCP: Denied
20:48:49: Se1/1 PPP: Phase is TERMINATING [0 sess, 1 load]
20:48:49: Se1/1 LCP: O TERMREQ [Open] id 11 len 4
20:48:49: Se1/1 IPCP: LCP not open, discarding packet
20:48:49: Se1/1 CDPCP: LCP not open, discarding packet
20:48:49: Se1/1 LCP: I TERMACK [TERMsent] id 11 len 4
20:48:49: Se1/1 LCP: State is Closed
20:48:49: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
20:48:49: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
20:48:49: Se1/1 LCP: State is Listen
20:48:51: Se1/1 LCP: TIMEout: State Listen
20:48:51: Se1/1 LCP: O CONFREQ [Listen] id 12 len 10
20:48:51: Se1/1 LCP: MagicNumber 0x0BFD245D (0x05060BFD245D)
20:48:51: Se1/1 LCP: I CONFREQ [REQsent] id 29 len 10
20:48:51: Se1/1 LCP: MagicNumber 0x0B0A0FAF (0x05060B0A0FAF)
20:48:51: Se1/1 LCP: O CONFACK [REQsent] id 29 len 10
20:48:51: Se1/1 LCP: MagicNumber 0x0B0A0FAF (0x05060B0A0FAF)
20:48:51: Se1/1 LCP: I CONFACK [ACKsent] id 12 len 10
20:48:51: Se1/1 LCP: MagicNumber 0x0BFD245D (0x05060BFD245D)
20:48:51: Se1/1 LCP: State is Open
20:48:51: Se1/1 AAA/AUTHOR/LCP: Denied
20:48:51: Se1/1 PPP: Phase is TERMINATING [0 sess, 1 load]
20:48:51: Se1/1 LCP: O TERMREQ [Open] id 13 len 4
20:48:52: Se1/1 IPCP: LCP not open, discarding packet
20:48:52: Se1/1 CDPCP: LCP not open, discarding packet
20:48:52: Se1/1 LCP: I TERMACK [TERMsent] id 13 len 4
20:48:52: Se1/1 LCP: State is Closed
20:48:52: Se1/1 PPP: Phase is DOWN [0 sess, 1 load]
20:48:52: Se1/1 PPP: Phase is ESTABLISHING, Passive Open [0 sess, 1 load]
20:48:52: Se1/1 LCP: State is Listen
20:48:53: Se2/1 LCP: TIMEout: State REQsent
20:48:53: Se2/1 LCP: O CONFREQ [REQsent] id 137 len 10
20:48:53: Se2/1 LCP: MagicNumber 0x0BFD0935 (0x05060BFD0935)
03-06-2003 03:30 PM
This looks strange...
Yes, If you add the authentication command on the local end then will also need to enable authentication on the remote router (could be done locally on the remote router or thru AAA).
If using AAA then will need to create appropriate accounts on the Radius server.
Can you please try the following changes:
aaa new-model
aaa authentication login use-radius group radius local
aaa authentication ppp use-radius group radius local
aaa authentication ppp default local <=======add this
aaa authorization exec default group radius local if-authenticated
aaa authorization network default local <====add this
On local router:
conf term
username
int serial x/y
ppp authentication chap
On remote router:
conf term
username
int serial x/y
ppp authentication chap
Thanks, Mak.
03-13-2003 03:26 PM
Mak,
Thank you for all your response. I think I have solve my problem with your ideas. Instead of doing the configuration you suggest (configure PPP authentication on the serial ports and creating accounts on both routers) I change the encapsulation on the serial interface. I change it to HDLC. it works.
So you were right in saying that the serial ports try to use the AAA methods when it trys to go up.
Is there a harm in changing the encapsulation on the serial interface ?
Anyway, thanks for your response. I learn a lot from it
regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide