arl.termit Posted May 23, 2011 Posted May 23, 2011 Добрый день. Есть доступ к ERX-310, пробуем поднять pppoe с авторизацией через radius. Запросов на стороне radius сервера не наблюдаю. На стороне клиента авторизация не проходит, сразу вылетает 678. Конфиг ERXa - profile PPPoE ip virtual-router INTERNET ip unnumbered loopback 0 ip mtu 1492 ip sa-validate ip filter-options all ip block-multicast-sources ppp authentication pap chap ppp fragmentation ppp reassembly ppp ipcp netmask ppp peer dns pppoe sessions 2000 pppoe duplicate-protection ! profile "Vlan-PPPoE" pppoe sessions 2000 vlan auto-configure pppoe lockout-time 3 5 vlan profile pppoe PPPoE ! virtual-router default aaa authentication atm1483 default radius aaa accounting atm1483 default radius aaa authentication ip default radius aaa accounting ip default radius aaa authentication ipsec default radius aaa accounting ipsec default radius aaa user accounting interval 10 aaa service accounting interval 10 aaa authentication ppp default radius aaa accounting ppp default radius ! interface gigabitEthernet 1/3 mtu 1500 encapsulation vlan ! interface gigabitEthernet 1/3.48 vlan id 48 ip description -= PPPoE =- pppoe pppoe auto-configure pppoe profile any "Vlan-PPPoE" ! radius authentication server 10.10.250.2 retransmit 2 timeout 15 max-sessions 4000 deadtime 10 key passw0rd ! radius accounting server 10.10.250.2 retransmit 2 timeout 15 max-sessions 4000 deadtime 10 key passw0rd ! radius algorithm round-robin radius update-source-addr 10.10.250.1 radius nas-identifier "ERX-NAS" radius acct-session-id-format decimal radius ethernet-port-type virtual radius include profile-service-description access-request enable radius pppoe nas-port-format unique radius vlan nas-port-format stacked radius dynamic-request server 10.10.250.2 key passw0rd ! sh int gigabitEthernet 1/3.48 GigabitEthernet1/3.48 is Up, Administrative status is Up VLAN ID: 48 sh pppoe interface PPPoE interface GigabitEthernet 1/3.48 is operStatusUp 1 PPPoE major interface found sh arp GigabitEthernet 1/3.48 Address Age Hardware Addr Interface Клиент подключен к DGS-3627G, доступа к коммутатору нет. Прошу пнуть в нужную сторону для взлета этого добра. Вставить ник Quote
GFORGX Posted May 25, 2011 Posted May 25, 2011 tcpdump -nne pppoed и pppoe-discovery Вам в руки. Вставить ник Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.