02-21-2018 12:16 AM - edited 03-01-2019 03:09 PM
Hey guys!
I am currently troubleshooting an issue concerning WCCP on our new BNG (ASR 1001-X).
We migrated from C3900 to ASR1001-X and here we are coming to troubles, because the Cisco AVPair-Attribute for WCCP seems not to work (anymore)
Here is the attribute on Radius-Server:
Cisco-AVpair += "lcp:interface-config=ip wccp 111 redirect in"
There are using a few attributes we are getting from the radius; all of them are working except for the wccp attribute. If we remove wccp attribute, everything else working fine...
When I do debugging on ASR1001-X I get this output:
debug ppp authorization
Feb 21 08:01:36.126: ppp2524 PPP: Using AAA Unique Id = 3CA678
Feb 21 08:01:36.126: ppp2524 PPP: Authorization required
Feb 21 08:01:36.126: ppp2524 PPP LCP: negotiation authorized = 1, tacacs author = 0
Feb 21 08:01:36.131: ppp2524 PPP LCP: neg is authorized, processing incoming CONFREQ
Feb 21 08:01:37.154: ppp2524 PPP: Sent PAP LOGIN Request
Feb 21 08:01:37.155: ppp2524 PPP: Received LOGIN Response PASS
Feb 21 08:01:37.155: ppp2524 PPP AUTHOR: Author Data Available
Feb 21 08:01:37.155: ppp2524 PPP: Receive Attrs from[authen] Keep[LCP] MERGE
Feb 21 08:01:37.155: ppp2524 PPP: Keep Attr: service-type 0 2 [Framed]
Feb 21 08:01:37.155: ppp2524 PPP: Updated the attr service-type in datalist
Feb 21 08:01:37.155: ppp2524 PPP: Skip Attr: interface-config 0 "service-policy input POLICE_10M_IN"
Feb 21 08:01:37.155: ppp2524 PPP: Skip Attr: interface-config 0 "service-policy output SHAPE_20M_OUT"
Feb 21 08:01:37.155: ppp2524 PPP: Skip Attr: interface-config 0 "ip wccp 111 redirect in"
Feb 21 08:01:37.155: ppp2524 PPP: Skip Attr: interface-config 0 "description blablabla"
Feb 21 08:01:37.155: ppp2524 PPP: Receive Attrs from[SSS] Keep[NCPs] MERGE
Feb 21 08:01:37.155: ppp2524 PPP: Skip Attr: service-type 0 2 [Framed]
Feb 21 08:01:37.155: ppp2524 PPP: Skip Attr: interface-config 0 "service-policy input POLICE_10M_IN"
Feb 21 08:01:37.155: ppp2524 PPP: Skip Attr: interface-config 0 "service-policy output SHAPE_20M_OUT"
Feb 21 08:01:37.155: ppp2524 PPP: Skip Attr: interface-config 0 "ip wccp 111 redirect in"
Feb 21 08:01:37.155: ppp2524 PPP: Skip Attr: interface-config 0 "description blablabla"
Feb 21 08:01:37.162: ppp2524 PPP: Sending Acct Event[Down] id[3CA678]
Feb 21 08:01:37.165: ppp2524 PPP: Clearing AAA Unique Id = 3CA678
debug pppoe error
Feb 21 08:04:21.095: [1824]PPPoE 24429: Error adjusting nas port format did
Feb 21 08:04:21.096: [1824]PPPoE 24429 <Te0/0/0.3626:3626/1010>: Unable to add line attributes from ANCP
Feb 21 08:04:21.096: [1824]PPPoE 24429: Unable to Add ANCP Line attributes to the PPPoE Authen attributes
Feb 21 08:04:22.142: PPPoE: Can't retrieve sub-block for VAI
Feb 21 08:04:22.142: PPPoE: Can't retrieve sub-block for VAI
Feb 21 08:04:22.151: PPPoE: Can't retrieve sub-block for VAI
Feb 21 08:04:22.151: PPPoE: Can't retrieve sub-block for VAI
debug ppp negotiation
Feb 21 08:06:05.392: ppp1489 PPP: Phase is ESTABLISHING
Feb 21 08:06:05.393: ppp1489 PPP: Using vpn set call direction
Feb 21 08:06:05.393: ppp1489 PPP: Treating connection as a callin
Feb 21 08:06:05.393: ppp1489 PPP: Session handle[43000131] Session id[1489]
Feb 21 08:06:05.393: ppp1489 LCP: Event[OPEN] State[Initial to Starting]
Feb 21 08:06:05.393: ppp1489 PPP LCP: Enter passive mode, state[Stopped]
Feb 21 08:06:05.398: ppp1489 LCP: I CONFREQ [Stopped] id 1 len 10
Feb 21 08:06:05.398: ppp1489 LCP: MagicNumber 0xD7D37810 (0x0506D7D37810)
Feb 21 08:06:05.398: ppp1489 LCP: O CONFREQ [Stopped] id 1 len 18
Feb 21 08:06:05.398: ppp1489 LCP: MRU 1492 (0x010405D4)
Feb 21 08:06:05.398: ppp1489 LCP: AuthProto PAP (0x0304C023)
Feb 21 08:06:05.398: ppp1489 LCP: MagicNumber 0xEDD7C38F (0x0506EDD7C38F)
Feb 21 08:06:05.398: ppp1489 LCP: O CONFACK [Stopped] id 1 len 10
Feb 21 08:06:05.398: ppp1489 LCP: MagicNumber 0xD7D37810 (0x0506D7D37810)
Feb 21 08:06:05.398: ppp1489 LCP: Event[Receive ConfReq+] State[Stopped to ACKsent]
Feb 21 08:06:05.399: ppp1489 LCP: I CONFNAK [ACKsent] id 1 len 8
Feb 21 08:06:05.399: ppp1489 LCP: MRU 1500 (0x010405DC)
Feb 21 08:06:05.399: ppp1489 LCP: O CONFREQ [ACKsent] id 2 len 18
Feb 21 08:06:05.399: ppp1489 LCP: MRU 1500 (0x010405DC)
Feb 21 08:06:05.399: ppp1489 LCP: AuthProto PAP (0x0304C023)
Feb 21 08:06:05.399: ppp1489 LCP: MagicNumber 0xEDD7C38F (0x0506EDD7C38F)
Feb 21 08:06:05.399: ppp1489 LCP: Event[Receive ConfNak/Rej] State[ACKsent to ACKsent]
Feb 21 08:06:05.400: ppp1489 LCP: I CONFACK [ACKsent] id 2 len 18
Feb 21 08:06:05.400: ppp1489 LCP: MRU 1500 (0x010405DC)
Feb 21 08:06:05.400: ppp1489 LCP: AuthProto PAP (0x0304C023)
Feb 21 08:06:05.400: ppp1489 LCP: MagicNumber 0xEDD7C38F (0x0506EDD7C38F)
Feb 21 08:06:05.400: ppp1489 LCP: Event[Receive ConfAck] State[ACKsent to Open]
Feb 21 08:06:05.401: ppp1489 PPP: Phase is AUTHENTICATING, by this end
Feb 21 08:06:05.401: ppp1489 LCP: State is Open
Feb 21 08:06:05.416: ppp1489 PAP: I AUTH-REQ id 1 len 38 from "TESTTEST@blablabla.at"
Feb 21 08:06:05.416: ppp1489 PAP: Authenticating peer TESTTEST@blablabla.at
Feb 21 08:06:05.416: ppp1489 PPP: Phase is FORWARDING, Attempting Forward
Feb 21 08:06:06.417: ppp1489 PPP: Phase is AUTHENTICATING, Unauthenticated User
Feb 21 08:06:06.418: ppp1489 PPP: Phase is FORWARDING, Attempting Forward
Feb 21 08:06:06.425: ppp1489 PPP DISC: Lower Layer disconnected
Feb 21 08:06:06.425: ppp1489 PPP: Sending Acct Event[Down] id[3CA6D6]
Feb 21 08:06:06.425: ppp1489 PAP: O AUTH-NAK id 1 len 27 msg is "Authentication failure"
Feb 21 08:06:06.425: ppp1489 LCP: O TERMREQ [Open] id 3 len 4
Feb 21 08:06:06.425: ppp1489 LCP: Event[CLOSE] State[Open to Closing]
Feb 21 08:06:06.425: ppp1489 PPP: Phase is TERMINATING
Feb 21 08:06:06.428: ppp1489 LCP: Event[CLOSE] State[Closing to Closing]
Feb 21 08:06:06.428: ppp1489 LCP: Event[DOWN] State[Closing to Initial]
Feb 21 08:06:06.428: ppp1489 PPP: Phase is DOWN
I have also tried to create a new interface Virtual-Template 5, where I copied the original template and added the command "ip wccp 111 redirect in". I got a traceback as output (usually not a good sign):
ROUTER(config-if)#ip wccp 111 redirect in
Feb 21 08:09:52.303: %IOSXE_WCCP-4-NOINTF: No Virtual-Template5 interface info for Service Group (1, 111, 0)
-Traceback= 1#315780af4aa185802629fb38078844ee :7F0D2E8A1000+EB2F077 :7F0D2E8A1000+AE18DF2 :7F0D2E8A1000+AE18B82 :7F0D2E8A1000+7666AE4 :7F0D2E8A1000+7665B82 :7F0D2E8A1000+7663E3A :7F0D2E8A1000+C664C49 :7F0D2E8A1000+76817C5 :7F0D2E8A1000+B3A385D
I have tried a few IOS-Versions but still the same on all of them.
Has anybody an idea? Is this a supported feature on ASR1001-X or is that
Thanks!
Thomas
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide