cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
612
Views
0
Helpful
1
Replies

Large Scale Dialout (LSDO) with Freeradius / avpair for Bri

Hi!

We established a test environment for LSDO.

Components:
Cisco 1712 c1700-advsecurityk9-mz.124-3g.bin
FreeRADIUS Version 2.0.4

Question: Is there a (freeradius) "avpair" to assign the physical interface (bri) to the Dialer-Interface?

Everything else looks fine, NAS (Router) receives username/pw/dialoutnumber from Freeradius, but gets no connection to the physical interface...
Additional info: sgbp ist not configured.

Debug-output NAS (router):
Jun 21 14:27:41.084 CEST: RADIUS(0000007C): Send Access-Request to 172.x.x.x:1812 id 1645/62, len 61
Jun 21 14:27:41.084 CEST: RADIUS:  authenticator 8A FD 5A 7C 4A DA 4E C8 - 70 5B FF 68 B6 D9 71 FD
Jun 21 14:27:41.084 CEST: RADIUS:  User-Name           [1]   11  "test-out"
Jun 21 14:27:41.084 CEST: RADIUS:  User-Password       [2]   18  *
Jun 21 14:27:41.084 CEST: RADIUS:  Service-Type        [6]   6   Outbound                  [5]
Jun 21 14:27:41.084 CEST: RADIUS:  NAS-IP-Address      [4]   6   172.x.x.x
Jun 21 14:27:41.088 CEST: RADIUS: Received from id 1645/62 172.x.x.x:1812, Access-Accept, len 148
Jun 21 14:27:41.088 CEST: RADIUS:  authenticator D6 AB CC 2F 8B 3F 02 31 - CC 40 2C 6D BB B2 F2 80
Jun 21 14:27:41.088 CEST: RADIUS:  Service-Type        [6]   6   Outbound                  [5]
Jun 21 14:27:41.092 CEST: RADIUS:  Vendor, Cisco       [26]  34
Jun 21 14:27:41.092 CEST: RADIUS:   Cisco AVpair       [1]   28  "outbound:addr=172.x.x.x"
Jun 21 14:27:41.092 CEST: RADIUS:  Vendor, Cisco       [26]  42
Jun 21 14:27:41.092 CEST: RADIUS:   Cisco AVpair       [1]   36  "lcp:interface-config=dialer pool 1"
Jun 21 14:27:41.092 CEST: RADIUS:  Vendor, Cisco       [26]  46
Jun 21 14:27:41.092 CEST: RADIUS:   Cisco AVpair       [1]   40  "outbound:dial-number=0049xxxxx"
Jun 21 14:27:41.096 CEST: RADIUS(0000007C): Received from id 1645/62
Jun 21 14:27:41.096 CEST: Di15 AAA/AUTHOR/DIALOUT: Authorization success for user test
Jun 21 14:27:41.096 CEST: %LSDialout: debug to verify the data integrity
Jun 21 14:27:41.100 CEST:     dial number = 0049xxxxx
Jun 21 14:27:41.100 CEST:     dialnum_count = 1
Jun 21 14:27:41.100 CEST:     force_56 = 0
Jun 21 14:27:41.100 CEST:     routing = 0
Jun 21 14:27:41.100 CEST:     data_svc = -1
Jun 21 14:27:41.100 CEST:     port_type = -1
Jun 21 14:27:41.100 CEST:     map_class =
Jun 21 14:27:41.100 CEST:     modem_script =
Jun 21 14:27:41.100 CEST:     system_script =
Jun 21 14:27:41.100 CEST:     ip_address = 172.x.x.x
Jun 21 14:27:41.100 CEST:     send_secret =
Jun 21 14:27:41.100 CEST:     send_name =
Jun 21 14:27:41.100 CEST:     send_auth = -1
Jun 21 14:27:41.100 CEST:     trunkgroup =
Jun 21 14:27:41.104 CEST:     auth_required = default, yes
Jun 21 14:27:41.104 CEST:     auth_type =

Thanks a lot!

1 Reply 1

Is there any other possibility/technology instead of LSDO?

.> Using Virtual-Profiles + AAA-Server for dialout?

Review Cisco Networking for a $25 gift card