No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Integration Problem of new Alcatel MSAN (ISAM Acatel new series) with HUAWEI BRAS

Publication Date:  2012-07-27 Views:  45 Downloads:  0
Issue Description
When Customer did the integration of new Alcatel MSAN product (ISAM serie) with Huawei BRAS MA5200G and ME60, so the ADSL Service is very pertupated and many suscribers complains that are disconnected randomly

the topology is like this:

Suscribers ---> ALCATEL MSAN "ISAM"----> Switches (Metro IP) ---> Huawei BRAS MA5200G/ME60 ---> IP Backbone(toward Internet)

Alarm Information
Null

Handling Process
1) Notice that many users are flopping and are using the same MAC-address (in this log 2 users flopping are showed:

(..)

display access-user mac-address 1880-f534-3f1c

user access index : 82
user name : cyberfiwatonet@menara
user access interface : gigabitethernet3/0/1.1
qinqvlan/uservlan : 0/185
user mac : 1880-f534-3f1c
user ip address : 41.140.190.154
user access type : pppoe
user authentication type : ppp authentication
normal-server-group : menara
two-level-acct-server-group : -
physical-acct-server-group : -
authen method : radius
current authen method : radius
authen result : success
action flag : idle
authen state : authed
author state : idle
accounting method : radius
user access time : 2011/06/24 23:34:48
online time (h:min:sec) : 00:06:00
accounting start time : 2011/06/24 23:34:48
accounting state : accounting
(...)

user access index : 53973
user name : sonacostaz@menara
user access interface : gigabitethernet3/0/1.1
qinqvlan/uservlan : 0/185
user mac : 1880-f534-3f1c
user ip address : 41.140.167.117
user access type : pppoe
user authentication type : ppp authentication
normal-server-group : menara
two-level-acct-server-group : -
physical-acct-server-group : -
authen method : radius
current authen method : radius
authen result : success
action flag : idle
authen state : authed
author state : idle
accounting method : radius
user access time : 2011/06/24 23:34:19
online time (h:min:sec) : 00:06:24
accounting start time : 2011/06/24 23:34:26
(...)


2) Check the Mac-address on internet , find that 18-80-f5 is standard of first 3bytes of ALCATEL Equipement, so think that PPPoA suscribers are used with MSAN ISAM Alcatel.
Then confirm with customer that effectively those suscribers are using PPPoA with the Behavior of Alcatel MSAN that give only just One MAC to many pppoA suscribers.

(Note that this is different from huawei MSAN wich by default give one different mac for each pppoa suscriber, )

3) Configure the optional command on BRAS, and the situation become normal, and all suscribers are connected normaly:
[bas_meknes_cex_01]pppoe-server max-sessions remote-mac 64

So here , we changed the value from 1(default value) to 64.


Root Cause
In fact, by tracing on some Mac-addresses of suscribers who complained that they are disconnected randomly, we can find that lot of suscribers send PPP/PPPoE sessions with the same MAC-Source,

In fact all suscribers that use PPPoA as the the dial-up method on their modems, so the modem just send using ATM and the modem don't have any Mac-address,

For the case of Alcatel MSAN "ISAM" new series, so the behavior of that MSAN is that he give one single MAC-address to each 64 Suscriber, (this MAC is always an ALCATEL Mac-address and begins with 18-80-f5 bytes) and then he transform PPPoA to PPP/PPPoE and try establish PPPoE session for those suscribers using the SAME Mac-address source for PPPoE /PPP session. (Note that this is different from Huawei MSAN wich by default give one different MAC for each pppoA suscriber)

So as result, in HUAWEI BRAS, he receive lot of PPPoE/PPP sessions from different suscribers but with same MAC-Source-address, so the default behavior of HUAWEI BRAS is that he disconnect them and in one time he accept just one.  In fact this behavior of BRAS is good and correct, and also folow the standard.

So this issue is caused by the weird behavior of Alcatel MSAN, and not BRAS, HW BRAS behavior is normal and correct.

In fact, As a solution, we can modify on the BRAS to let accept multi-pppoE/ppp sessions even if the are triggered by the Sam MAC-address
for this we should configure the command:
pppoe-server max-sessions remote-mac  <Number>

In fact, For the Number , the default Value of Huawei BRAS is 1 ,  and this value folow the recommandations of Standards, and also it's a protection against Attacker Flooding.
Suggestions
Null

END