cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
716
Views
0
Helpful
5
Replies

Cisco 2600 ISDN to a Netscreen for backup

jfarrer
Level 1
Level 1

We are trying to establish a backup solution using ISDN for an ISP failure at our remote sites. At our remote sites, we currently have several flavors of Netscreen firewalls. According to Juniper, they support failover on the serial interface using ISDN to dial into an ISP. We have set up a Cisco 2600 with a PRI at our main location that will simulate an ISP router. Upon failure of the primary Untrusted connection on the Netscreen, it forces the ISDN TA (MultiTech MTA128NT) to dial the appropriate number and begin PPP negotiations. LCP never completes and the connection gets dropped. I have included the debug ppp negotiations output. Any ideas.

Thanks,

Jack Farrer

5 Replies 5

spremkumar
Level 9
Level 9

HI

hope this helps..

http://cisco.com/en/US/tech/tk713/tk507/technologies_tech_note09186a008019cfa7.shtml

also if possible do post debug outputs of q931 and q921 logs...

regds

I read through this document, but didn't find anything that helps. I have also included the debug isdn q921 and q931 output.

Thanks,

Jack Farrer.

Wilson Samuel
Level 7
Level 7

Dec 1 23:03:02.471 UTC: %LINK-3-UPDOWN: Interface Serial1/0:0, changed state to

down

Dec 1 23:03:02.475 UTC: Se1/0:0 PPP: Authorization NOT required

Dec 1 23:03:02.475 UTC: Se1/0:0 PPP: No remote authentication for call-in

Dec 1 23:03:02.475 UTC: Se1/0:0 PPP: Phase is ESTABLISHING

Dec 1 23:03:02.475 UTC: Se1/0:0 PPP: Authorization NOT required

Dec 1 23:03:02.475 UTC: Se1/0:0 PPP: No remote authentication for call-in

Dec 1 23:03:02.475 UTC: Se1/0:0 PPP: Authorization NOT required

Dec 1 23:03:02.475 UTC: Se1/0:0 PPP: No remote authentication for call-in

Dec 1 23:03:02.475 UTC: Se1/0:0 PPP: Sending Acct Event[Down] id[95]

As per the Debug message, I understand its an Authentication / PPP issue.

Could you please paste the debug ppp authentication as well please along with the debug isdn q931 and sh isdn status

That would certainly help us to resolve the issue.

Regards,

Wilson Samuel

Samuel,

I have attached the requested information. Let me know what you think.

Thanks,

Jack

Hi Jack,

Problem seems with the authentication, you need to chaeck once again username and password on both end router. then give a test call. as per your debug test result every time it is stuck in authentication phase. please remove the earlier username or try to find out the password configured in both side, it should be same on both end.

pls try below one.

for e.g.

On ROUTER A

username ROUTERB password cisco

on ROUTER B

-----------

username ROUTERA password cisco

if it helps, otherwise please paste both end config.

Regards...Mukesh

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: