Помогите разобраться. Ситуация сильно похожа на описанную в цитируемом блоке за тем исключением что как только я вывожу биндинг pppoe сессий в отдельный контекст перестает работать авторизация.
[local]Redback#debug aaa exception
ничего не отображает.
[local]Redback# show subscribers log
4990 IN Thu Feb 1 12:16:01.433122
IPC_ENDPOINT = PPPd, MSG_TYPE = SESSION_DOWN, term_ec = 24
terminate cause = Authentication failure
Username = ,
CCT_HANDLE = Unknown circuit
Internal Circuit = 2/15:511:63:31/1/2/4143
aaa_idx = 10032a7c, extern_handle = 0, pvd_idx = 7fffffff,
Event code = 1
---------------------------------------------------------
4991 OUT Thu Feb 1 12:16:01.433131
IPC_ENDPOINT = ISM-CCT, MSG_TYPE = CCT-SUB-SESS-DOWN-CPLT,
Username = ,
CCT_HANDLE = Unknown circuit
Internal Circuit = 2/15:511:63:31/1/2/4143
aaa_idx = 0, extern_handle = 0, pvd_idx = 7fffffff,
Event code = 0
---------------------------------------------------------
4992 IN Thu Feb 1 12:16:03.754539
IPC_ENDPOINT = PPPd, MSG_TYPE = AUTHEN_REQ_2,
Username = xxx,
CCT_HANDLE = Unknown circuit
Internal Circuit = 2/15:511:63:31/1/2/4143
aaa_idx = 10032a7d, extern_handle = 0, pvd_idx = 7fffffff,
Event code = 0
---------------------------------------------------------
4993 OUT Thu Feb 1 12:16:04.217813
IPC_ENDPOINT = PPPd, MSG_TYPE = DB_RESPONSE, authen response = 2
Username = xxx,
CCT_HANDLE = Unknown circuit
Internal Circuit = 2/15:511:63:31/1/2/4143
aaa_idx = 10032a7d, extern_handle = 0, pvd_idx = 40080085,
Event code = 0
---------------------------------------------------------
4994 IN Thu Feb 1 12:16:04.239593
IPC_ENDPOINT = PPPd, MSG_TYPE = SESSION_DOWN, term_ec = 24
terminate cause = Authentication failure
Username = ,
CCT_HANDLE = Unknown circuit
Internal Circuit = 2/15:511:63:31/1/2/4143
aaa_idx = 10032a7d, extern_handle = 0, pvd_idx = 7fffffff,
Event code = 1
---------------------------------------------------------
4995 OUT Thu Feb 1 12:16:04.239601
IPC_ENDPOINT = ISM-CCT, MSG_TYPE = CCT-SUB-SESS-DOWN-CPLT,
Username = ,
CCT_HANDLE = Unknown circuit
Internal Circuit = 2/15:511:63:31/1/2/4143
aaa_idx = 0, extern_handle = 0, pvd_idx = 7fffffff,
Event code = 0
---------------------------------------------------------
Мой конфиг:
[local]Redback#show configuration
Building configuration...
Current configuration:
!
! Configuration last changed by user '<NO USER>' at Thu Feb 1 15:23:53 2018
!
!
!
aaa global authentication subscriber radius context local
aaa global accounting subscriber radius context local
aaa last-resort context local
!
!
service multiple-contexts
!
service inter-context routing
!
!
!
software license
subscriber active 8000 encrypted 1 $1$HASH
subscriber bandwidth 60 encrypted 1 $1$HASH
!
!context local
domain local.context.ru
!
no ip domain-lookup
!
interface lnk_to_fw
ip address 192.168.10.1/30
!
interface mng
ip address 172.20.255.165/27
!
interface radius loopback
ip address 172.20.254.10/32
ip source-address radius
!
!
enable encrypted 1 $1$........$.nNQmFppgs3ECnFPrOgpx/
!
aaa authentication administrator local
aaa accounting subscriber radius
radius accounting server 10.15.23.21 encrypted-key E3919B89DF3DF70D7E680CB9AD66D872
!
administrator admin encrypted 1 $1$........$.nNQmFppgs3ECnFPrOgpx/
privilege max 15
!
radius server 10.15.23.21 encrypted-key E3919B89DF3DF70D7E680CB9AD66D872
!
subscriber default
ppp mtu 1492
dns primary 8.8.8.8
!
ip route 10.15.23.0/24 172.20.255.161
!
!
!
context bgp
!
no ip domain-lookup
!
interface UPLINK_TMP
ip address WHITE_ADDR/30
!
interface UPLINK_TTK
ip address WHITE_ADDR/30
no logging console
!
router bgp ASNUM
!
neighbor WHITE_ADDR external
remote-as ASNUB
send community
send ext-community
address-family ipv4 unicast
!
ip route 0.0.0.0/0 WHITE_ADDR
!
!!
context pppoe
domain my.domain.ru advertise
!
no ip domain-lookup
!
interface pppoe multibind
ip address WHITE_ADDRESS/28
ip pool WHITE_POOL/28
no logging console
!
aaa authentication administrator local
aaa authentication subscriber global
!
!
subscriber default
ppp mtu 1492
dns primary 8.8.8.8
!
ip route 0.0.0.0/0 context bgp
!
!
!
!
!
! ** End Context **
logging tdm console
logging active
logging standby short
!
!
!
system clock timezone MSK 3 0
!
!
!
port ethernet 1/1
! XCRP management port on slot 1
no shutdown
bind interface mng local
!
card carrier 2
mic 1 ge-2-port
mic 2 ge-2-port
!
port ethernet 2/1
auto-negotiate speed 100
no shutdown
medium-type copper
bind interface UPLINK_TMP bgp
!
port ethernet 2/2
auto-negotiate force enable speed 100
shutdown
medium-type copper
!
port ethernet 2/15
no shutdown
encapsulation dot1q
dot1q pvc 100 encapsulation multi
circuit protocol pppoe
bind authentication pap chap context pppoe maximum 3000
!
port ethernet 2/16
shutdown
!
system hostname Redback
system location ZImbabve
!
!
!
pppoe services marked-domains
pppoe service-name accept-all
pppoe tag ac-name *
pppoe always-send-padt
!
end