Всем доброго времени суток!
Апну тему - так как проблема топикпастера актуальна и для нас.
Итак Cisco 7206VXR (NPE-G2) странно работает CoA
на исосах типа c7200p-a3jk91s-mz.122-31.SB18.bin и c7200p-js-mz.122-31.SB18.bin фича работает как описано
corban:
attrset.11.title=speed 512 kbit/s in
attrset.11.attributes=Cisco-AVPair=lcp:interface-config=no rate-limit output access-group 2001 256000 48000 96000 conform-action transmit exceed-action drop\nrate-limit output access-group 2001 512000 96000 192000 conform-action transmit exceed-action drop
без сдвоенной команды с no применяются сразу 2 райт лимита
sh int virtual-access 3 rate
Virtual-Access3
Output
matches: access-group 2001
params: 512000 bps, 96000 limit, 192000 extended limit
conformed 8816 packets, 11978578 bytes; action: transmit
exceeded 2690 packets, 3673303 bytes; action: drop
last packet: 0ms ago, current burst: 133168 bytes
last cleared 00:03:20 ago, conformed 478702 bps, exceeded 146797 bps
matches: access-group 2001
params: 256000 bps, 48000 limit, 96000 extended limit
conformed 0 packets, 0 bytes; action: transmit
exceeded 0 packets, 0 bytes; action: drop
last packet: 1184192ms ago, current burst: 0 bytes
last cleared 00:01:24 ago, conformed 0 bps, exceeded 0 bps
с no все нормально, но не работает вариант когда вариантов скорости на тарифе более 2х типа:
Cisco-AVPair=lcp:interface-config=no rate-limit output access-group 2001 512000 96000 192000 conform-action transmit exceed-action drop\nno rate-limit output access-group 2001 64000 12000 24000 conform-action transmit exceed-action drop\nrate-limit output access-group 2001 256000 48000 96000 conform-action transmit exceed-action drop
на исосах типа c7200p-adventerprisek9-mz.122-33.SRE1.bin и c7200p-adventerprisek9-mz.122-33.SRC6.bin не работает совсем
вот дебаг CoA c циски
Код:
Mar 16 15:42:43.031: COA: 212.42.120.242 request queued
*Mar 16 15:42:43.031: RADIUS: authenticator 9A E3 43 27 D1 9B AB 16 - 69 45 C5 F6 67 A4 BF 4D
*Mar 16 15:42:43.031: RADIUS: User-Name [1] 8 "ip0203"
*Mar 16 15:42:43.031: RADIUS: Framed-IP-Address [8] 6 212.42.120.232
*Mar 16 15:42:43.031: RADIUS: Acct-Session-Id [44] 10 "00000002"
*Mar 16 15:42:43.031: RADIUS: Vendor, Unknown [26] 35
*Mar 16 15:42:43.031: RADIUS: Framed-Protocol [7] 29
*Mar 16 15:42:43.031: RADIUS: 6F 75 74 23 33 3D 61 6C 6C 20 73 68 61 70 65 20 [out#3=all shape ]
*Mar 16 15:42:43.031: RADIUS: 32 35 36 30 30 30 20 70 61 73 73 [ 256000 pass]
*Mar 16 15:42:43.031: RADIUS: Vendor, Cisco [26] 229
*Mar 16 15:42:43.031: RADIUS: Cisco AVpair [1] 223 "lcp:interface-config=no rate-limit output access-group 2001 512000 96000 192000 conform-action transmit exceed-action drop\nrate-limit output access-group 2001 256000 48000 96000 conform-action transmit exceed-action drop"
*Mar 16 15:42:43.031: ++++++ CoA Attribute List ++++++
*Mar 16 15:42:43.031: 07271E9C 0 00000009 username(422) 6 ip0203
*Mar 16 15:42:43.031: 07271DC4 0 00000001 addr(8) 4 212.42.120.232
*Mar 16 15:42:43.031: 07271DD4 0 00000001 session-id(385) 4 2(2)
*Mar 16 15:42:43.031: 07271DE4 0 00000009 interface-config(205) 200 no rate-limit output access-group 2001 512000 96000 192000 conform-action transmi
*Mar 16 15:42:43.031:
*Mar 16 15:42:43.031: COA: Unsupported vendor or attribute for LI
*Mar 16 15:42:43.031: COA: Added Reply Message: Unsupported Attribute
*Mar 16 15:42:43.031: COA: Added NACK Error Cause: Unsupported Attribute
*Mar 16 15:42:43.031: COA: Sending NAK from port 1800 to 212.42.120.242/63926
*Mar 16 15:42:43.031: RADIUS: 18 23 556E737570706F7274656420417474726962757465
*Mar 16 15:42:43.031: RADIUS: 101 6 00000191
вот лог радиуса
Код:
01-10/14:39:12 INFO [pool-8-thread-3] connections - [ 73737373; ip0203; 26558 ] Taking zone 512 from response on calculate sid=3
01-10/14:39:12 INFO [pool-8-thread-3] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection set STATUS=1
01-10/14:40:08 INFO [pool-8-thread-4] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection update connection..
01-10/14:40:08 INFO [pool-8-thread-4] connections - [ 73737373; ip0203; 26558 ] Taking zone 256 from response on calculate sid=3
01-10/14:40:08 INFO [pool-8-thread-4] connections - [ 73737373; ip0203; 26558 ] Changed tariff zone from 512 to 256
01-10/14:40:08 INFO [pool-8-thread-4] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection set STATUS=1
01-10/14:40:08 INFO [Thread-39] connections - [ 73737373; ip0203; 26558 ] Change zone do: 10.01.2011 14:40:08
01-10/14:40:08 INFO [Thread-39] connections - [ 73737373; ip0203; 26558 ] Need CoA request
01-10/14:40:08 INFO [Thread-39] connections - [ 73737373; ip0203; 26558 ] Send CoA request with attribute sets: 7
01-10/14:40:08 INFO [pool-3-thread-1] connections - [ 73737373; ip0203; 26558 ] CoA packet tryCount=2 on 212.42.120.246:1800
Type=43
Attributes:
User-Name=ip0203
Framed-IP-Address=212.42.120.232
Acct-Session-Id=00000002
mpd-limit=out#3=all shape 256000 pass
cisco-avpair=lcp:interface-config=no rate-limit output access-group 2001 512000 96000 192000 conform-action transmit exceed-action drop\nrate-limit output access-group 2001 256000 48000 96000 conform-action transmit exceed-action drop
01-10/14:40:08 ERROR [pool-3-thread-1] connections - [ 73737373; ip0203; 26558 ] CoA packet response 45
01-10/14:40:08 INFO [pool-3-thread-1] connections - [ 73737373; ip0203; 26558 ] CoA packet tryCount=1 on 212.42.120.246:1800
Type=43
Attributes:
User-Name=ip0203
Framed-IP-Address=212.42.120.232
Acct-Session-Id=00000002
mpd-limit=out#3=all shape 256000 pass
cisco-avpair=lcp:interface-config=no rate-limit output access-group 2001 512000 96000 192000 conform-action transmit exceed-action drop\nrate-limit output access-group 2001 256000 48000 96000 conform-action transmit exceed-action drop
01-10/14:40:11 INFO [pool-3-thread-1] connections - [ 73737373; ip0203; 26558 ] CoA packet tryCount=0 on 212.42.120.246:1800
Type=43
Attributes:
User-Name=ip0203
Framed-IP-Address=212.42.120.232
Acct-Session-Id=00000002
mpd-limit=out#3=all shape 256000 pass
cisco-avpair=lcp:interface-config=no rate-limit output access-group 2001 512000 96000 192000 conform-action transmit exceed-action drop\nrate-limit output access-group 2001 256000 48000 96000 conform-action transmit exceed-action drop
01-10/14:41:07 INFO [pool-8-thread-5] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection update connection..
01-10/14:41:07 INFO [pool-8-thread-5] connections - [ 73737373; ip0203; 26558 ] Taking zone 256 from response on calculate sid=3
01-10/14:41:07 INFO [pool-8-thread-5] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection set STATUS=1
01-10/14:42:11 INFO [pool-8-thread-6] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection update connection..
01-10/14:42:11 INFO [pool-8-thread-6] connections - [ 73737373; ip0203; 26558 ] Taking zone 256 from response on calculate sid=3
01-10/14:42:11 INFO [pool-8-thread-6] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection set STATUS=1
01-10/14:43:11 INFO [pool-8-thread-7] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection update connection..
01-10/14:43:11 INFO [pool-8-thread-7] connections - [ 73737373; ip0203; 26558 ] Taking zone 256 from response on calculate sid=3
01-10/14:43:11 INFO [pool-8-thread-7] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection set STATUS=1
01-10/14:43:20 INFO [Thread-34] connections - [ 73737373; ip0203; 26558 ] Set connection to KILL
01-10/14:43:20 INFO [Thread-34] connections - [ 73737373; ip0203; 26558 ] Killing connection by user request
01-10/14:43:20 INFO [Thread-14] connections - [ 73737373; ip0203; 26558 ] sendKillRequest
01-10/14:43:20 INFO [Thread-14] connections - [ 73737373; ip0203; 26558 ] PoD reset packet on 212.42.120.246:1800
Type=40
Attributes:
User-Name=ip0203
Framed-IP-Address=212.42.120.232
Acct-Session-Id=00000002
01-10/14:43:25 INFO [pool-4-thread-1] connections - [ 73737373; ip0203; 26558 ] IP address unregistred from collector 212.42.120.232
01-10/14:43:25 INFO [pool-4-thread-1] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection stoppingConnection
01-10/14:43:25 INFO [pool-4-thread-1] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection has stop Packet => true
01-10/14:43:25 INFO [pool-4-thread-1] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection set STATUS=3
01-10/14:43:25 INFO [pool-4-thread-1] connections - [ 73737373; ip0203; 26558 ] DialUpNASConnection sessionTime => 379
optimous уточните пожалуйста вашу версию иос полностью
Кстати в версиях c7200p-a3jk91s-mz.122-31.SB18.bin и c7200p-js-mz.122-31.SB18.bin в фиче навигаторе только
ISG:Policy Control: Policy Server: CoA ASCII Command Code Support
в иосах c7200p-adventerprisek9-mz.122-33.SRE1.bin и c7200p-adventerprisek9-mz.122-33.SRC6.bin 2 фичи
ISG:Policy Control: Policy Server: CoA (QoS, L4 redirect, User ACL, TimeOut)
ISG:Policy Control: Policy Server: CoA ASCII Command Code Support
Код:
version 5.0 build 298 from 09.12.2010 18:59:44
10.01.2011 15:07:50 2 0 2 0
Request accounts per minute start: 0; stop: 0; update: 0
Request auths per minute accept: 0; reject: 0
Netfow packets per minute: 0
Ignore per minute auth: 0; update: 0
Antispam ban count: 0; used per minute: 0
FlowListener: queue_size: 0; threads_active: 0; largest: 6; core: 1000; pool_size: 6; recv_socket_buf_size: 209 712; recv_buf_size: 4 194 304; packets: 6
Started: 10.01.2011 15:07:02 Uptime: 0 d 00:00:47
Memory total: 5 177 344; max: 266 403 840; free: 1 350 600
Trees in cache: 1
Connections pool to Master status Idle: 3; Active: 0; maxActive: 300; maxIdle: 20
Буду рад любым советам по организации связки Cisco+pppoe+coa+rate-limit+больше 2х скоростей на тарифе