cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1639
Views
0
Helpful
2
Replies

4G-LTE-ANTM-D AT&T Cell dropping service

Travis-Fleming
Level 1
Level 1

ello,

We have a Cisco 1921 with the below configuration. We are testing our AT&T cell card in the MC7354 modem. It's up and running great at the moment. We are using an ikev2 VPN back to our datacenter. The only service on this router is the AT&T service. We have a Cisco phone on it, and it's currently registered to our CUCM server over the VPN. However after running for a day the cell service was stopped with the below log entries. I understand this can sometimes happen if the cell provider does not see traffic, however with a VoIP phone up and actively registered I don't think that is the case. Plus we have an IP SLA policy going as well. Does anyone have any other ideas what could have caused a flap of service? We had to clear our VPN from the corporate office as when the cell service came back up it had a new DHCP address from AT&T. (I've taken any public IP info and replaced with X.X.X.X).

 

Errors in Log:

Aug 20 18:37:19.819: %CELLWAN-2-BEARER_DELETED: Instance id=0, Default bearer (bearer_id=5) in Cellular0/0/0 is now deleted.
Aug 20 18:37:21.819: %LINK-5-CHANGED: Interface Cellular0/0/0, changed state to reset
Aug 20 18:37:22.819: %LINEPROTO-5-UPDOWN: Line protocol on Interface Cellular0/0/0, changed state to down
Aug 20 18:37:26.819: %LINK-3-UPDOWN: Interface Cellular0/0/0, changed state to down
Aug 20 18:38:30.011: %CELLWAN-4-MODEM_COMM_FAIL: Communication between Modem and IOS failed: link recovery resets modem
Aug 20 18:38:40.011: %CELLWAN-2-MODEM_DOWN: Modem in HWIC slot 0/0 is DOWN
Aug 20 18:39:29.399: %CELLWAN-2-MODEM_UP: Modem in HWIC slot 0/0 is now UP
Aug 20 18:40:26.036: %CELLWAN-2-BEARER_UP: Instance id=0, Default bearer (bearer_id=5) in Cellular0/0/0 is now UP
Aug 20 18:40:28.296: %LINK-3-UPDOWN: Interface Cellular0/0/0, changed state to up
Aug 20 18:40:29.296: %LINEPROTO-5-UPDOWN: Line protocol on Interface Cellular0/0/0, changed state to up
Aug 20 18:40:35.784: %IKEV2-5-OSAL_INITIATE_TUNNEL: Received request to establish an IPsec tunnel; local traffic selector = Address Range: 10.10.33.1-10.10.33.1 Protocol: 1 Port Range: 0-65535; remote traffic selector = Address Range: 172.17.98.78-172.17.98.78 Protocol: 1 Port Range: 0-65535

Aug 20 18:40:36.948: %IKEV2-5-SA_UP: SA UP

Aug 20 18:40:36.948: %CRYPTO-5-IKEV2_SESSION_STATUS: Crypto tunnel v2 is UP. Peer X.X.X.X:4500 Id: 209.188.100.70
Aug 20 18:42:36.592: %IKEV2-5-SA_DOWN: SA DOWN

Aug 20 18:42:36.592: %CRYPTO-5-IKEV2_SESSION_STATUS: Crypto tunnel v2 is DOWN. Peer X.X.X.X:4500 Id: 209.188.100.70

 

Running Config and show cellular 0/0/0 all:

at-lte-agent-33#sh run
Building configuration...

Current configuration : 5998 bytes
!
! Last configuration change at 16:33:02 CDT Tue Aug 20 2019 by travifle
! NVRAM config last updated at 15:36:00 CDT Mon Aug 19 2019 by travifle
!
version 15.5
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
service internal
!
hostname at-lte-agent-33
!
boot-start-marker
boot system usbflash0 c1900-universalk9-mz.SPA.155-3.M9.bin
boot-end-marker
!
!
logging queue-limit 10000
logging buffered informational
logging persistent size 22056960
logging rate-limit 10000
logging monitor informational
enable secret 4 z9YxNLgQytNVcRrjBwjMY.duEEsowT0hvRRpg05O832
!
aaa new-model
!
!
!
aaa session-id common
ethernet lmi ce
clock timezone CST -6 0
clock summer-time CDT recurring
!
!
no ip domain lookup
ip domain name ats-inc.com
ip name-server 172.16.1.161
ip name-server 172.16.1.160
ip inspect WAAS flush-timeout 10
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
!
chat-script lte "" "AT!CALL1" TIMEOUT 20 "OK"
cts logging verbose
!
!
license udi pid CISCO1921/K9 sn XXXX
license boot module c1900 technology-package datak9
!
!
object-group network remote_networks
172.16.0.0 255.240.0.0
10.0.0.0 255.0.0.0
192.168.0.0 255.255.0.0
!
username admin password 7 XXXX
!
redundancy
notification-timer 120000
!
crypto ikev2 proposal AES-256_SHA
encryption aes-cbc-256
integrity sha512
group 21
!
crypto ikev2 policy ikev2_policy
proposal AES-256_SHA
!
!
crypto ikev2 profile ikev2_profile1
match identity remote any
authentication local pre-share key XXXX
authentication remote pre-share key XXXX
!
no crypto ikev2 http-url cert
!
!
controller Cellular 0/0
lte sim data-profile 15 attach-profile 15
lte modem link-recovery rssi onset-threshold -110
lte modem link-recovery monitor-timer 20
lte modem link-recovery wait-timer 10
lte modem link-recovery debounce-count 6
!
!
crypto logging session
crypto logging ikev2
!
crypto isakmp policy 1
encr aes 256
hash sha512
authentication pre-share
group 21
!
!
crypto ipsec transform-set xform1 esp-aes 256 esp-sha-hmac
mode tunnel
!
!
!
crypto map ATS-Tunnel 1 ipsec-isakmp
set peer X.X.X.X
set security-association lifetime seconds 86400
set transform-set xform1
set ikev2-profile ikev2_profile1
match address 101
!
!
!
!
!
interface Embedded-Service-Engine0/0
no ip address
shutdown
!
interface GigabitEthernet0/0
no ip address
duplex auto
speed auto
!
interface GigabitEthernet0/0.1
encapsulation dot1Q 1 native
!
interface GigabitEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface GigabitEthernet0/1/0
no ip address
!
interface GigabitEthernet0/1/1
no ip address
!
interface GigabitEthernet0/1/2
no ip address
!
interface GigabitEthernet0/1/3
no ip address
!
interface Cellular0/0/0
description AT&T DHCP
ip address negotiated
ip nat outside
no ip virtual-reassembly in
encapsulation slip
dialer in-band
dialer idle-timeout 0
dialer string lte
dialer-group 1
crypto map ATS-Tunnel
!
interface Cellular0/0/1
no ip address
encapsulation slip
!
interface Vlan1
ip address 10.10.33.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
ip tftp source-interface Vlan1
ip nat inside source list NAT interface Cellular0/0/0 overload
ip route 0.0.0.0 0.0.0.0 Cellular0/0/0
ip tacacs source-interface Vlan1
ip ssh version 2
!
ip access-list standard Management
permit X.X.X.X 0.0.0.255
permit 172.16.0.0 0.15.255.255
permit 10.10.33.0 0.0.0.255
!
ip access-list extended NAT
deny ip 10.10.33.0 0.0.0.255 172.16.0.0 0.15.255.255
deny ip 10.10.33.0 0.0.0.255 10.0.0.0 0.255.255.255
deny ip 10.10.33.0 0.0.0.255 192.168.0.0 0.0.255.255
permit ip 10.10.33.0 0.0.0.255 any
permit ip 192.168.33.0 0.0.0.255 any
!
ip sla 1
icmp-echo 172.17.98.78 source-ip 10.10.33.1
frequency 10
ip sla schedule 1 life forever start-time now
dialer-list 1 protocol ip list 1
!
!
access-list 1 permit any
access-list 20 permit 172.16.1.166
access-list 101 permit ip 10.10.33.0 0.0.0.255 172.16.0.0 0.15.255.255
access-list 101 permit ip 10.10.33.0 0.0.0.255 10.0.0.0 0.255.255.255
access-list 101 permit ip 10.10.33.0 0.0.0.255 192.168.0.0 0.0.255.255
!
!
!
control-plane
!
!
line con 0
logging synchronous
transport preferred none
line aux 0
line 2
no activation-character
no exec
transport preferred none
transport output pad telnet rlogin lapb-ta mop udptn v120 ssh
stopbits 1
line 0/0/0
script dialer lte
no exec
rxspeed 100000000
txspeed 50000000
line 0/0/1
no exec
rxspeed 100000000
txspeed 50000000
line vty 0 4
access-class Management in
exec-timeout 120 0
privilege level 15
logging synchronous
length 0
transport preferred none
transport input ssh
line vty 5 15
transport preferred none
transport input none
!
scheduler allocate 20000 1000
ntp server 172.16.1.160 source Vlan1
ntp server 172.16.1.161 source Vlan1
!
end


at-lte-agent-33#sh cell 0/0/0 all
Hardware Information
====================
Modem Firmware Version = SWI9X15C_05.05.58.00
Modem Firmware built = 2015/03/04 21:30:23
Hardware Version = 1.0
Device Model ID: MC7354
Package Identifier ID: 1102037_9903214_MC7354_05.05.58.00_00_Cisco_005.013_000
International Mobile Subscriber Identity (IMSI) = 310410209040385
International Mobile Equipment Identity (IMEI) = 356734060504242
Integrated Circuit Card ID (ICCID) = 89014104272090403853
Mobile Subscriber Integrated Services
Digital Network-Number (MSISDN) = 13204066846
Current Modem Temperature = 42 deg C
PRI SKU ID = 1102037, PRI version = 005.026, Carrier = AT&T
OEM PRI version = 05.13

Profile Information
====================

Profile 1 = INACTIVE
--------
PDP Type = IPv4
Access Point Name (APN) = 12281.mcs
Authentication = CHAP
Username: open
Password: open

Profile 15 = ACTIVE* **
--------
PDP Type = IPv4
PDP address = 10.169.63.87
Access Point Name (APN) = broadband
Authentication = None
Primary DNS address = 172.26.38.1
Secondary DNS address = 255.255.255.255
Primary DNS IPV6 address = 0
Secondary DNS IPV6 address = 0

Profile 16 = INACTIVE
--------
PDP Type = IPv4
Access Point Name (APN) = i2gold
Authentication = None

* - Default profile
** - LTE attach profile


Data Connection Information
===========================
Profile 1, Packet Session Status = INACTIVE
Profile 2, Packet Session Status = INACTIVE
Profile 3, Packet Session Status = INACTIVE
Profile 4, Packet Session Status = INACTIVE
Profile 5, Packet Session Status = INACTIVE
Profile 6, Packet Session Status = INACTIVE
Profile 7, Packet Session Status = INACTIVE
Profile 8, Packet Session Status = INACTIVE
Profile 9, Packet Session Status = INACTIVE
Profile 10, Packet Session Status = INACTIVE
Profile 11, Packet Session Status = INACTIVE
Profile 12, Packet Session Status = INACTIVE
Profile 13, Packet Session Status = INACTIVE
Profile 14, Packet Session Status = INACTIVE
Profile 15, Packet Session Status = ACTIVE
Cellular0/0/0:
Data Transmitted = 960151 bytes, Received = 1039456 bytes
IP address = 10.169.63.87
Primary DNS address = 172.26.38.1
Secondary DNS address = 255.255.255.255
Primary DNS IPV6 address = 0
Secondary DNS IPV6 address = 0
Profile 16, Packet Session Status = INACTIVE

Network Information
===================
Current System Time = Tue Aug 20 21:44:37 2019
Current Service Status = Normal
Current Service = Packet switched
Current Roaming Status = Home
Network Selection Mode = Automatic
Network = AT&T
Mobile Country Code (MCC) = 310
Mobile Network Code (MNC) = 410
Packet switch domain(PS) state = Attached
Registration state(EMM) = Registered
EMM Sub State = Normal Service
Tracking Area Code (TAC) = 17956
Cell ID = 82232322

Radio Information
=================
Radio power mode = online
LTE Rx Channel Number = 2475
LTE Tx Channel Number = 20475
LTE Band = 5
LTE Bandwidth = 5 MHz
Current RSSI = -80 dBm
Current RSRP = -114 dBm
Current RSRQ = -20 dB
Current SNR = -3.7 dB
Physical Cell Id = 183
Number of nearby cells = 1
Idx PCI (Physical Cell Id)
--------------------------------
1 183
Radio Access Technology(RAT) Preference = GWL
Radio Access Technology(RAT) Selected = LTE

Modem Security Information
==========================
Card Holder Verification (CHV1) = Disabled
SIM Status = OK
SIM User Operation Required = None
Number of CHV1 Retries remaining = 3

GPS Information
==========================

GPS Info
-------------
GPS Feature: enabled
GPS Port Selected: Dedicated GPS port
GPS State: GPS location error
GPS auto tracking status: unknown
GPS auto tracking config: disabled
GPS Mode Configured: disabled
Last Location Fix Error: Offline [0x0]

SMS Information
===============
Incoming Message Information
----------------------------
SMS stored in modem = 0
SMS archived since booting up = 0
Total SMS deleted since booting up = 0
Storage records allocated = 25
Storage records used = 0
Number of callbacks triggered by SMS = 0
Number of successful archive since booting up = 0
Number of failed archive since booting up = 0

Outgoing Message Information
----------------------------
Total SMS sent successfully = 0
Total SMS send failure = 0
Number of outgoing SMS pending = 0
Number of successful archive since booting up = 0
Number of failed archive since booting up = 0
Last Outgoing SMS Status = SUCCESS
Copy-to-SIM Status = 0x0
Send-to-Network Status = 0x0
Report-Outgoing-Message-Number:
Reference Number = 0
Result Code = 0x0
Diag Code = 0x0 0x0 0x0 0x0 0x0

SMS Archive URL =

Error Information
=================

This command is not supported on this platform.


Modem Crashdump Information
===========================
Modem crashdump logging: off

1 Accepted Solution

Accepted Solutions

Hello,

 

the IP SLA should be sufficient. Either way, try to set the parameters marked in bold in your crypto map and check if that makes a difference:

 

crypto map ATS-Tunnel 1 ipsec-isakmp
set peer X.X.X.X
set security-association lifetime days 30
set security-association lifetime kilobytes disable
set transform-set xform1
set ikev2-profile ikev2_profile1
match address 101

View solution in original post

2 Replies 2

Hello,

 

the IP SLA should be sufficient. Either way, try to set the parameters marked in bold in your crypto map and check if that makes a difference:

 

crypto map ATS-Tunnel 1 ipsec-isakmp
set peer X.X.X.X
set security-association lifetime days 30
set security-association lifetime kilobytes disable
set transform-set xform1
set ikev2-profile ikev2_profile1
match address 101

Thank you. I will run with that today and see if it helps!
Review Cisco Networking products for a $25 gift card