12-12-2010 07:03 AM - edited 03-21-2019 03:24 AM
Hi all,
I have a UC560 box with uc500-advipservicesk9-mz.150-1.XA2 on it and configured for PPTP termination, using windows PPTP client for remote access. Everything works perfectly until I upgrade IOS to uc500-advipservicesk9-mz.150-1.XA3a. Now when the clients try to authenticate I get the following from debugginf ppp:
xxx#
000288: .Dec 12 05:52:56.486: PPP: Alloc Context [86B36B04]
000289: .Dec 12 05:52:56.486: ppp2 PPP: Phase is ESTABLISHING
000290: .Dec 12 05:52:56.486: ppp2 PPP: Using vpn set call direction
000291: .Dec 12 05:52:56.486: ppp2 PPP: Treating connection as a callin
000292: .Dec 12 05:52:56.486: ppp2 PPP: Session handle[BA000002] Session id[2]
000293: .Dec 12 05:52:56.486: ppp2 LCP: Event[OPEN] State[Initial to Starting]
000294: .Dec 12 05:52:56.486: ppp2 PPP LCP: Enter passive mode, state[Stopped]
xxx#
000295: .Dec 12 05:52:58.486: ppp2 PPP LCP: Exit passive mode, state[Starting]
000296: .Dec 12 05:52:58.486: ppp2 LCP: O CONFREQ [Starting] id 1 len 15
000297: .Dec 12 05:52:58.486: ppp2 LCP: AuthProto MS-CHAP (0x0305C22380)
000298: .Dec 12 05:52:58.486: ppp2 LCP: MagicNumber 0xD10211FE (0x0506D10211FE)
000299: .Dec 12 05:52:58.486: ppp2 LCP: Event[UP] State[Starting to REQsent]
xxx#
000300: .Dec 12 05:53:00.502: ppp2 LCP: O CONFREQ [REQsent] id 2 len 15
000301: .Dec 12 05:53:00.502: ppp2 LCP: AuthProto MS-CHAP (0x0305C22380)
000302: .Dec 12 05:53:00.502: ppp2 LCP: MagicNumber 0xD10211FE (0x0506D10211FE)
000303: .Dec 12 05:53:00.502: ppp2 LCP: Event[Timeout+] State[REQsent to REQsent]
xxx#
000304: .Dec 12 05:53:02.518: ppp2 LCP: O CONFREQ [REQsent] id 3 len 15
000305: .Dec 12 05:53:02.518: ppp2 LCP: AuthProto MS-CHAP (0x0305C22380)
000306: .Dec 12 05:53:02.518: ppp2 LCP: MagicNumber 0xD10211FE (0x0506D10211FE)
000307: .Dec 12 05:53:02.518: ppp2 LCP: Event[Timeout+] State[REQsent to REQsent]
xxx#
000308: .Dec 12 05:53:04.534: ppp2 LCP: O CONFREQ [REQsent] id 4 len 15
000309: .Dec 12 05:53:04.534: ppp2 LCP: AuthProto MS-CHAP (0x0305C22380)
000310: .Dec 12 05:53:04.534: ppp2 LCP: MagicNumber 0xD10211FE (0x0506D10211FE)
000311: .Dec 12 05:53:04.534: ppp2 LCP: Event[Timeout+] State[REQsent to REQsent]
xxx#
000312: .Dec 12 05:53:06.550: ppp2 LCP: O CONFREQ [REQsent] id 5 len 15
000313: .Dec 12 05:53:06.550: ppp2 LCP: AuthProto MS-CHAP (0x0305C22380)
000314: .Dec 12 05:53:06.550: ppp2 LCP: MagicNumber 0xD10211FE (0x0506D10211FE)
000315: .Dec 12 05:53:06.550: ppp2 LCP: Event[Timeout+] State[REQsent to REQsent]
xxx#
000316: .Dec 12 05:53:08.567: ppp2 LCP: O CONFREQ [REQsent] id 6 len 15
000317: .Dec 12 05:53:08.567: ppp2 LCP: AuthProto MS-CHAP (0x0305C22380)
000318: .Dec 12 05:53:08.567: ppp2 LCP: MagicNumber 0xD10211FE (0x0506D10211FE)
000319: .Dec 12 05:53:08.567: ppp2 LCP: Event[Timeout+] State[REQsent to REQsent]
xxx#
000320: .Dec 12 05:53:10.583: ppp2 LCP: O CONFREQ [REQsent] id 7 len 15
000321: .Dec 12 05:53:10.583: ppp2 LCP: AuthProto MS-CHAP (0x0305C22380)
000322: .Dec 12 05:53:10.583: ppp2 LCP: MagicNumber 0xD10211FE (0x0506D10211FE)
000323: .Dec 12 05:53:10.583: ppp2 LCP: Event[Timeout+] State[REQsent to REQsent]
xxx#
000324: .Dec 12 05:53:12.599: ppp2 LCP: O CONFREQ [REQsent] id 8 len 15
000325: .Dec 12 05:53:12.599: ppp2 LCP: AuthProto MS-CHAP (0x0305C22380)
000326: .Dec 12 05:53:12.599: ppp2 LCP: MagicNumber 0xD10211FE (0x0506D10211FE)
000327: .Dec 12 05:53:12.599: ppp2 LCP: Event[Timeout+] State[REQsent to REQsent]
000328: .Dec 12 05:53:13.515: ppp2 PPP DISC: Lower Layer disconnected
000329: .Dec 12 05:53:13.515: ppp2 PPP: Sending Acct Event[Down] id[E]
000330: .Dec 12 05:53:13.515: ppp2 LCP: O TERMREQ [REQsent] id 9 len 4
000331: .Dec 12 05:53:13.515: ppp2 LCP: Event[CLOSE] State[REQsent to Closing]
000332: .Dec 12 05:53:13.515: ppp2 PPP: Phase is TERMINATING
xxx#
000333: .Dec 12 05:53:13.519: ppp2 LCP: Event[DOWN] State[Closing to Initial]
000334: .Dec 12 05:53:13.519: ppp2 PPP: Phase is DOWN
xxxx#
The Windows client gets error 619. The funny thing is when I go back to the previous IOS, I still have the same problem so to speak my PPTP termination no longer works with any of the IOS. I tried to reconfigure PPTP and play with the config but with no results. Anyone has any idea how to resolve it? Thanks in advance.
12-12-2010 05:35 PM
There is a bug: CSCtd74135 " ppp encrypt mppe required"
This fix doesn't exist in XA3a but does exist in 15.1(2)T2 images. This image will be released as a part of SWP 8.1.0 at the end of December.
Symptoms: Microsoft Point-to-Point Encryption (MPPE) enforcement may not work
on a Cisco router. The router may allow Point-to-Point Tunneling Protocol
(PPTP) users to connect without negotiating the MPPE.
Conditions: This symptom is observed on a Cisco router that is running Cisco
IOS Release 15.0(1)M even if it is configured with theppp encrypt
mppe 128 requiredcommand.
Workaround:
Using the authentication type of MS-CHAP in place of MS-CHAP-V2 can prevent
this issue. The MPPE works fine with the 'required' option as well, when used
with the authentication type 'MS-CHAP'.
12-12-2010 07:55 PM
Thanks very mach Steve. I will wait for the new SW release for UC560.
Best regards,
12-12-2010 07:56 PM
your welcome.
Sorry about the wait. SHouldnt be much longer at all
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide