No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

PPPoE Users Under ME60 Failed to Go Online Due to an Incorrect RADIUS Server-Delivered Attribute

Publication Date:  2013-09-30 Views:  17 Downloads:  0
Issue Description

Version: ME60 V600R002C02SPC700

Symptom: After PPPoE services were migrated from an MA5200G to an ME60, the error code 691 was displayed upon user dialing up.
Handling Process

Possible causes include:

1. The NAS-IP after service migration was different from that bound to the RADIUS server.

2. An attribute delivered by the RADIUS server was incorrect.

Huawei performed the following operations to address the problem:

1. Ran debug radius.

The NAS-IP sent from the ME60 was different from that bound to the RADIUS server. After the NAS-IP bound to the RADIUS server was changed to be the same as that sent from the ME60, the problem persisted.

2. Checked the cause of the online failure.

The cause was PPP with authentication fail.

3. Traced the user MAC addresses.

The users received authentication replies indicating that authentication succeeded, but the users were rejected by the AAA module.

[AAA][user info:
  MAC Address    : 782B-CBE7-938C
  IP Address     : 255.255.255.255
  Interface      : Eth-Trunk2.4050
  PE VLAN ID     : 4050
  USERNAME       : 141060871@xq-radius]
[trace info:
 User authen fail, -]

Authentication replies indicating that authentication succeeded:

[trace info:
Radius Received a Packet
Server Template: 2
Server IP : 222.74.59.250
Vpn-Instance: -
Server Port : 1812
NAS Port : 1812
Protocol: Portal
Code : Authentication accept
Len : 203
ID : 84
[Service-Type(6) ] [6 ] [2]
[State(24) ] [10] [544f636d424c4658]
[Termination-Action(29) ] [6 ] [0]
[HW-Input-Committed-Burst-Size(Huawei-1)] [6 ] [10485760]
[HW-Input-Committed-Information-Rate(Huawei-2)] [6 ] [2097152]
[HW-Input-Peak-Information-Rate(Huawei-3)] [6 ] [2097152]
[HW-Output-Committed-Burst-Size(Huawei-4)] [6 ] [11796480]
[HW-Output-Committed-Information-Rate(Huawei-5)] [6 ] [2359296]
[HW-Output-Peak-Information-Rate(Huawei-6)] [6 ] [2359296]
[Session-Timeout(27) ] [6 ] [86401]
[Acct-Interim-Interval(85) ] [6 ] [600]
[HW-Connect-ID(Huawei-26) ] [6 ] [143772]
[HW-Up-Priority(Huawei-61) ] [59] [906362880]]

According to the preceding data, the authentication replies carried HW-Up-Priority(Huawei-61) being [906362880], which was beyond the valid range 1-15 specified in ME60 code. Therefore, the AAA module rejected the users.

4. Masked the HW-Up-Priority(Huawei-61) on the ME60.
The problem was resolved.
Root Cause
The authentication replies from the RADIUS server carried HW-Up-Priority(Huawei-61) being [906362880], which was beyond the valid range 1-15 specified in ME60 code.
Solution
Run radius-attribute disable in the radius-server group view to mask the attribute on the ME60.
Suggestions
None

END