Hi everyone,
First of all, please include my email address when replying, I am not
subscribed to the list.
Secondly, I've failed to configure an Ascend Max 6000 as a dialin
router. The setup is the following:
Client PC -> MAX router -> network
The IPs for the dialin clients are assigned automatically by a
Radiator server from the net 10.0.0.0/24. The radius server has the
IP 192.168.0.2, and Max has the IP 192.168.0.3 and the gateway for
both is 192.168.0.1.
I have configured the Max to be able to 'see' the 192.168.0.0/24 lan,
and to be able to ping any host from internet. So the Lan part is set
up correctly.
As well, the client PCs get the IPs right from the radiator server,
through the Ascend box. Both Auth and Acct work great.
The problem is that even though there is a client with the ip
10.0.0.50 (ip assigned by radius, of course) connected to the max,
from that client no ping works to the max, and the max can't ping
that IP either. So I suspected something was wrong with the internal
routing inside the max. So I've checked it out, and I get the
following:
ascend% sh ip route
Destination Gateway IF Flg Pref Met Use
Age
0.0.0.0/0 192.168.0.1 ie0 SGP 60 1 178
1547
10.0.0.0/25 - rj0 C 0 0 129
1352
127.0.0.0/8 - bh0 CP 0 0 0
3352
127.0.0.1/32 - local CP 0 0 20
3352
127.0.0.2/32 - rj0 CP 0 0 15433
3352
192.168.0.0/24 - ie0 C 0 0 7865
3352
192.168.0.3/32 - local CP 0 0 3368
3352
224.0.0.0/4 - mcast CP 0 0 54
3352
224.0.0.1/32 - local CP 0 0 0
3352
224.0.0.2/32 - local CP 0 0 0
3352
224.0.0.9/32 - local CP 0 0 0
3352
255.255.255.255/32 - ie0 CP 0 0 0
3352
ascend% sh ip address
VRouter:
Interface IP Address Dest IP Address Netmask MTU
Status
ie0 192.168.0.3 N/A 255.255.255.0 1500
Up
wanidle0 192.168.0.3 N/A 255.255.255.0 1500
Up
vr0_main 192.168.0.3 N/A 255.255.255.255 1500
Up
mcast 224.0.0.0 N/A 240.0.0.0 65535
Up
rj0 127.0.0.2 N/A 255.255.255.255 1500
Up
bh0 127.0.0.3 N/A 255.255.255.255 1500
Up
local 127.0.0.1 N/A 255.255.255.255 65535
Up
lo0 127.0.0.1 N/A 255.255.255.255 1500
Up
When somebody logs in, the command outputs are:
ascend% sh ip route
Destination Gateway IF Flg Pref Met Use
Age
0.0.0.0/0 192.168.0.1 ie0 SGP 60 1 178
1710
10.0.0.0/25 - rj0 C 0 0 144
1515
127.0.0.0/8 - bh0 CP 0 0 0
3515
127.0.0.1/32 - local CP 0 0 20
3515
127.0.0.2/32 - rj0 CP 0 0 60101
3515
192.168.0.0/24 - ie0 C 0 0 7949
3515
192.168.0.3/32 - local CP 0 0 3401
3515
224.0.0.0/4 - mcast CP 0 0 54
3515
224.0.0.1/32 - local CP 0 0 0
3515
224.0.0.2/32 - local CP 0 0 0
3515
224.0.0.9/32 - local CP 0 0 0
3515
255.255.255.255/32 - ie0 CP 0 0 15
3515
ascend% sh ip address
VRouter:
Interface IP Address Dest IP Address Netmask MTU
Status
ie0 192.168.0.3 N/A 255.255.255.0 1500
Up
wan25 192.168.0.3 -> 10.0.0.42 255.255.255.255 1500
Up
wanidle0 192.168.0.3 N/A 255.255.255.0 1500
Up
vr0_main 192.168.0.3 N/A 255.255.255.255 1500
Up
mcast 224.0.0.0 N/A 240.0.0.0 65535
Up
rj0 127.0.0.2 N/A 255.255.255.255 1500
Up
bh0 127.0.0.3 N/A 255.255.255.255 1500
Up
local 127.0.0.1 N/A 255.255.255.255 65535
Up
lo0 127.0.0.1 N/A 255.255.255.255 1500
Up
I have also tried to make a pool with the ips in the class
10.0.0.0/24, but that didn't solve anything either. And I've tried a
lot of other things, like proxy = yes, changing the wan ip, the if
addr ips, and so on. No result...
Is there something that I need to add to the radius reply to the
ascend box? Right now the reply looks like:
Code: Access-Accept
Identifier: 9
Authentic:
<16>"<154><214><156><15>b<241>{<224><134><142><154><132><154>2
Attributes:
Service-Type = Framed-User
Framed-Protocol = PPP
Session-Timeout = 3600
Framed-IP-Address = 10.0.0.42
Or what settings do I need to enable/disable on the Ascend? I would
need more-or-less a complete guide, because I'm: 1. new to ascend ;
2. I don't know which switches which I've already set will affect the
new settings that (hopefully) you're gonna guide me to.
Anyways, thanks in advance,
bogdan
_______________________________________________
rte-ascend mailing list
rte-ascend at lists.real-time.com
https://mailman.real-time.com/mailman/listinfo/rte-ascend