06-22-2010 04:05 AM - edited 03-04-2019 08:51 AM
Hi!
We established a test environment for LSDO.
Components:
Cisco 1712 c1700-advsecurityk9-mz.124-3g.bin
FreeRADIUS Version 2.0.4
Question: Is there a (freeradius) "avpair" to assign the physical interface (bri) to the Dialer-Interface?
Everything else looks fine, NAS (Router) receives username/pw/dialoutnumber from Freeradius, but gets no connection to the physical interface...
Additional info: sgbp ist not configured.
Debug-output NAS (router):
Jun 21 14:27:41.084 CEST: RADIUS(0000007C): Send Access-Request to 172.x.x.x:1812 id 1645/62, len 61
Jun 21 14:27:41.084 CEST: RADIUS: authenticator 8A FD 5A 7C 4A DA 4E C8 - 70 5B FF 68 B6 D9 71 FD
Jun 21 14:27:41.084 CEST: RADIUS: User-Name [1] 11 "test-out"
Jun 21 14:27:41.084 CEST: RADIUS: User-Password [2] 18 *
Jun 21 14:27:41.084 CEST: RADIUS: Service-Type [6] 6 Outbound [5]
Jun 21 14:27:41.084 CEST: RADIUS: NAS-IP-Address [4] 6 172.x.x.x
Jun 21 14:27:41.088 CEST: RADIUS: Received from id 1645/62 172.x.x.x:1812, Access-Accept, len 148
Jun 21 14:27:41.088 CEST: RADIUS: authenticator D6 AB CC 2F 8B 3F 02 31 - CC 40 2C 6D BB B2 F2 80
Jun 21 14:27:41.088 CEST: RADIUS: Service-Type [6] 6 Outbound [5]
Jun 21 14:27:41.092 CEST: RADIUS: Vendor, Cisco [26] 34
Jun 21 14:27:41.092 CEST: RADIUS: Cisco AVpair [1] 28 "outbound:addr=172.x.x.x"
Jun 21 14:27:41.092 CEST: RADIUS: Vendor, Cisco [26] 42
Jun 21 14:27:41.092 CEST: RADIUS: Cisco AVpair [1] 36 "lcp:interface-config=dialer pool 1"
Jun 21 14:27:41.092 CEST: RADIUS: Vendor, Cisco [26] 46
Jun 21 14:27:41.092 CEST: RADIUS: Cisco AVpair [1] 40 "outbound:dial-number=0049xxxxx"
Jun 21 14:27:41.096 CEST: RADIUS(0000007C): Received from id 1645/62
Jun 21 14:27:41.096 CEST: Di15 AAA/AUTHOR/DIALOUT: Authorization success for user test
Jun 21 14:27:41.096 CEST: %LSDialout: debug to verify the data integrity
Jun 21 14:27:41.100 CEST: dial number = 0049xxxxx
Jun 21 14:27:41.100 CEST: dialnum_count = 1
Jun 21 14:27:41.100 CEST: force_56 = 0
Jun 21 14:27:41.100 CEST: routing = 0
Jun 21 14:27:41.100 CEST: data_svc = -1
Jun 21 14:27:41.100 CEST: port_type = -1
Jun 21 14:27:41.100 CEST: map_class =
Jun 21 14:27:41.100 CEST: modem_script =
Jun 21 14:27:41.100 CEST: system_script =
Jun 21 14:27:41.100 CEST: ip_address = 172.x.x.x
Jun 21 14:27:41.100 CEST: send_secret =
Jun 21 14:27:41.100 CEST: send_name =
Jun 21 14:27:41.100 CEST: send_auth = -1
Jun 21 14:27:41.100 CEST: trunkgroup =
Jun 21 14:27:41.104 CEST: auth_required = default, yes
Jun 21 14:27:41.104 CEST: auth_type =
Thanks a lot!
07-05-2010 07:32 AM
Is there any other possibility/technology instead of LSDO?
.> Using Virtual-Profiles + AAA-Server for dialout?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide