Showing posts with label configuration. Show all posts
Showing posts with label configuration. Show all posts

Wednesday, November 26, 2014

Tekradius LT service not starting (initial configuration)

Tekradius service will not start till you configure its parameters.




Initial configuration

You must specify a “Client” for Tekradius as below:
  1. Open Tekradius LT manager console 
  2. Click on “clients” tab
  3. Fill the fields 

  • NAS : ip address of your client
  • Secret : a key which also must be configure at the client side
  •  Interim Update Period : if you use Tekradius for accounting too.
  • Click on “Add/Update”

 You can start Tekradius LT service now
 Right now the client can connect to radius server by using the secret you specified earlier.

You can create user in Tekradius LT as below :
Open Tekradius LT manager console
Click on “Users” tab
Type the username in the box which specified by red line in picture.


Set the attribute to check the password and type the password.
Click on add user profile.

There are lots of other configurations, but for a basic authorization this is enough.
For example if you want Tekradius do your  accounting you can set “time-limit” attribute for the user
and don’t forget to specify the kill command for radius client, so  Tekradius LT send the disconnect
command to the client after the account time limit has been reached.











Tuesday, November 25, 2014

Zyxel IES 6000 DSLAM Series Commands





Zyxel IES 6000 Series Commands:

Set IP Address :
DSLAM> ip set inband 10.32.32.130/25 2 10.32.32.129
usage: set inband <ip>[/<netmask>] [<inband-vid> <gateway-ip>]
  <inband-vid> : inband management vlan id
  <gateway-ip> : default gateway ip

Creating Management Vlan :
DSLAM> vlan set 2 all normal untag
DSLAM> vlan set 2 enet5 fix tag
DSLAM> vlan  name 2 management
usage: set <vid> <giga-port> fix|forbid|normal tag|untag

Creating Access Vlan :
DSLAM> vlan set 11 all normal untag
DSLAM> vlan set 11 enet5 fix tag
DSLAM> vlan  name 11 Access
usage: set <vid> <giga-port> fix|forbid|normal tag|untag

Creating Profiles :
DSLAM> profile adsl set 220 512 2048
usage: set <profile> <us-max-rate> <ds-max-rate>

Removing PVCs:
DSLAM> port pvc delete *-*-0/33
usage: delete <slot-port-vpi/vci>

Creating and assigning new PVC s
DSLAM> port pvc set 1-1-0/35 DEFVAL llc 11 0
usage: set <slot-port-vpi/vci> <profile> <mux> <pvid> <priority>
             <slot-port-vpi/vci>: example: 3-1-0/33, 3-1~10-0/33, 3-*-0/33, *-*-0/33
             <profile>          : atm profile
             <mux>              : encapsulation: llc, vcmux
             <pvid>             : default vlan id, 1~4094
             <priority>         : default priority, 0~7

Assigning Profile to port:
DSLAM> port adsl set 1-1 220 auto
usage: set <slot-port> <profile> <mode>

Activate the first port:
DSLAM> port enable 1-1
usage: enable <slot-port>

Copy first port configuration to others:
DSLAM> port copy 1-1 1-*
DSLAM> port copy 1-1 2-*
DSLAM> port copy 1-1 3-*
DSLAM> port copy 1-1 4-*
.
.
.
usage: copy <source> <destination>
<source>      : source port, example: 3-3, 4-26
<destination> : destination ports, example *-*

Copy first port configuration to a range of ports:
Copy first port (PVC,Profile) to range:
DSLAM> port copy 1-1 1-47~56
usage: copy <source> <destination>
<source>      : source port, example: 3-3, 4-26
  <destination> : destination ports, example 1-1,3~5,10~15

Activating TR101:
DSLAM> acl pppoeagent set 11
usage: set <vid>
DSLAM> acl pppoeagent enable 11
usage: enable <vid>
DSLAM> acl pppoeagent optionmode 11 tr101 vid on
usage: optionmode <vid> private|tr101 [vid on|off]

Activating Antimacspoof  :
DSLAM> acl antimacspoof enable
DSLAM> acl pktfilter set *-* pppoe-only
usage: set <slot-port> <type>
  <type>     : can be accept-all, pppoe-only, or any combination of
               ip, arp, dhcp, eapol, pppoe, netbios, igmp seperate by a space
  pppoe-only : accept pppoe packet only
  accept-all : accept all packets


show commands:
SNR:
DSLAM> show linerate 1-1
payload rate   (kbps)=        509       4095
actual rate    (kbps)=        519       4141
attainable rate(kbps)=       1322      22284
noise margin     (dB)=       31.8       29.3
attenuation      (dB)=       12.4       22.0


Stat:
DSLAM> show linestat 1-1
                    usPayLoadRate dsPayLoadRate
port  link              (kbps)        (kbps)    protocol       up time
----- ------------- ------------- ------------- -------------- --------------
 1- 2 up                      509          4095 adsl2plus         2d 2h53m 6s


Long Test:
DSLAM> diagnostic selt test 1-1
DSLAM> diagnostic selt show 1-1
port     inprogress       cableType loopEstimateLength
----- -------------------- --------- ------------------
 1-1           INPROGRESS     24AWG    1004 m(3.29 kFt)

Profile:
DSLAM> profile adsl show
adsl profile(s):
----------------------
1. 210
2. 220
3. DEFVAL

DSLAM> profile adsl show 220
max rate      (Kbps):      512        2048
  min rate      (Kbps):       64          64
  latency delay   (ms):       20          20
  max margin      (dB):     31.0        31.0
  min margin      (dB):      0.0         0.0
  target margin   (dB):      6.0         6.0
  sra mode            :  startup     startup
  up shift mgn    (dB):      9.0         9.0
  down shift mgn  (dB):      3.0         3.0



PVC:
DSLAM> port pvc show 1-1
pvc               type   mux   pvid  pri  mvlan profile
--------------- ------- ----- ------ ---- ----- ------------------------------
1-1-0/35        bridged  llc     11    0   -   DEFVAL

Vlan:
DSLAM> Vlan show
vid  uplink            12345678901234567 name
----- ----------------- ----------------- -------------------------------
    1 FFFFFFFF/UUUUUUUU XXXXXXX XXXXXXXXX 1
    2 ----F---/UUUUTUUU XXXXXXX XXXXXXXXX Management
  11 ----F---/UUUUTUUU FFFFFFF FFFFFFFFF Access

Line Card:
DSLAM> lcman show
48V power: Input-A up, Input-B up
id state    card type          uptime f/w version         heat vol mon down out
-- -------- ----------- ------------- ------------------- ---------------------
 1 active   ALC1272G-51  146:01:35:18 V3.95(ARV.0)          -   -   -    -   -
 2 active   ALC1272G-51  146:01:35:15 V3.95(ARV.0)          -   -   -    -   -
 3 active   ALC1272G-51  146:01:35:14 V3.95(ARV.0)          -   -   -    -   -       

DSLAM> lcman reset 1
usage: lcman reset <slot>

Tuesday, November 4, 2014

Cisco 2811 as PPTP VPN Server


We can use a cisco 2800 series router as a VPN server in a network, it can be used in a medium business, so there is a sample configuration for cisco 2811 as a PPTP VPN server:


Building configuration...

Current configuration : 1236 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
resource policy
!
ip subnet-zero
!
!
ip cef
!
 --More--         !
vpdn enable
!
vpdn-group vpn
! Default PPTP VPDN group
 accept-dialin
  protocol pptp
  virtual-template 1
!
!
!
voice-card 0
 no dspfarm
!
!
!
!
!
!
!
!
!
!
 --More--         !
!
!
!
!
username test password 0 test
!
!
!
!
!
!
!
interface Loopback0
 ip address 200.200.200.200 255.255.255.255
!
interface FastEthernet0/0
 ip address 210.10.10.1 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 --More--         shutdown
 duplex auto
 speed auto
!
interface Serial0/0/0
 no ip address
 shutdown
 no fair-queue
 clock rate 2000000
!
interface Serial0/0/1
 no ip address
 shutdown
 clock rate 2000000
!
interface Virtual-Template1
 ip unnumbered FastEthernet0/0
 peer default ip address pool vpn
 ppp encrypt mppe auto required
 ppp authentication ms-chap ms-chap-v2
!
ip local pool vpn 100.0.0.1 100.0.0.10
ip classless
 --More--         !
!
ip http server
no ip http secure-server
!
!
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
 --More--         login
!
scheduler allocate 20000 1000
!
end

Router#

LNS LAC sample configuration

unnumbered-ip-dsl-rely





This time we have a sample configuration about LNS - LAC, mostly used for DSL provider to transfer pppoe traffic. We use cisco 2811 for this scenario:

LNS configuration :

Building configuration...

Current configuration : 1309 bytes
!
!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname lns
!
boot-start-marker
boot-end-marker
!
!
aaa new-model
!
!
aaa authentication ppp default local
!
aaa session-id common
!
resource policy
!
!
!
ip cef
!
!
vpdn enable
!
vpdn-group adsl1
! Default L2TP VPDN group
 accept-dialin
  protocol l2tp
  virtual-template 2
 local name vahid
 relay pppoe bba-group test1
!
!
!
!
voice-card 0
 no dspfarm
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
username cisco password 0 cisco
username saeed password 0 saeed
!
!
!
!
!
!
bba-group pppoe test1
 virtual-template 2
!
!
interface Loopback0
 ip address 10.10.10.1 255.255.255.0
!
interface FastEthernet0/0
 ip address 192.168.10.1 255.255.255.0
 duplex auto
 speed auto
 pppoe enable group test
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
interface Virtual-Template2
 ip unnumbered Loopback0
 peer default ip address pool pppoe
 ppp authentication chap pap
!
ip local pool pppoe 100.0.0.1 100.0.0.10
!
!
ip http server
no ip http secure-server
!
!
!
!
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
!
!
gatekeeper
 shutdown
!
!
line con 0
line aux 0
line vty 0 4
!
scheduler allocate 20000 1000
!
end

lns#


here is LAC configuration:

Building configuration...

Current configuration : 1290 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname lac
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
resource policy
!
ip subnet-zero
!
!
ip cef
!
!
!
subscriber profile sam
 service relay pppoe vpdn group adsl
!
vpdn enable
vpdn source-ip 192.168.10.2
!
vpdn-group adsl
 request-dialin
  protocol l2tp
 initiate-to ip 192.168.10.1
 local name vahid
!
!
!
voice-card 0
 no dspfarm
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
username saeed password 0 saeed
!
!
!
!
!
!
bba-group pppoe test
 virtual-template 1
 service profile sam
!
!
interface Loopback0
ip address 10.10.10.2 255.255.255.0
!
interface FastEthernet0/0
 ip address 192.168.10.2 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 duplex auto
 speed auto
 pppoe enable group test
!
interface Serial0/0/0
 no ip address
 shutdown
 no fair-queue
 clock rate 2000000
!
interface Serial0/0/1
 no ip address
 shutdown
 clock rate 2000000
!
interface Virtual-Template1
 ip unnumbered Loopback0
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.10.1
!
!
ip http server
no ip http secure-server
!
!
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
 login
!
scheduler allocate 20000 1000
!
end

lac#



Wednesday, October 29, 2014

Configure Cisco 2811 ATM module



Configure Cisco 2811 ATM module

If you need too configure an ATM module on a cisco router don't hesitate its the simplest task ever:

interface ATM0/0/0
 description Connected to hell :))
 ip address 10.20.152.210 255.255.255.252
 no atm ilmi-keepalive
 pvc 7/92
  cbr 1024
  encapsulation aal5snap

Corecess R1 - AD DSLAM Configuration

Corecess R1 - AD DSLAM Configuration

Corecess R1 - AD DSLAM Configuration
This is a sample configuration for R1-AD Corecess DSLAM that I hope be useful  for you:

Building configuration...

Current configuration:
!
! version  0.78
!
hostname Dslam-Lab
dsl
adsl speed 2/1-48 ds 512 us 512

service tcp syncookies
!
snmp-server contact Unknown
snmp-server location Unknown
snmp-server enable rmon
!
system fan enable 30 20
system temperature enable 90 80
module 2 access-type protected
!
port adsl 2/1-48.1 pvc 0/35
port adsl 2/1-48.1 qos-service unshape
!
vlan id 2 name NMS
vlan id 10 name Accesss
dot1q port gigabitethernet 1/1 tag 2,10
dot1q port adsl 2/1-48.1 pvid 10
!
interface vlan id 2
ip address 10.10.10.2/24
!
ip route default 10.10.10.1
!
line vty 0 10
!
no ntp
!
Dslam# sh dsl vc
2/28.1
VirtualPortIndex: 3/1 IfIndex: 51 BridgeIndex: 129
Name: DEFAULT VLAN: 10
VPI/VCI 0/35
Service Category : unshape
Traffic Parameters : PCR/SCR/MBS/CDV 2320/2320/2320/0

2/31.1
VirtualPortIndex: 3/2 IfIndex: 53 BridgeIndex: 130
Name: DEFAULT VLAN: 10
VPI/VCI 0/35
Service Category : unshape
Traffic Parameters : PCR/SCR/MBS/CDV 2320/2320/2320/0

Dslam-Lab# show vlan
VLAN Name             Status   Slot/Port(s)
---- ---------------- -------- ------------------------------------
1    DEFAULT          active   1/1-2         
                               2/1-48        

2    NMS              active 
10   Accesss          active 
VLAN Interface  IGMPs    STP      Private  Promisc Port(s)
---- ---------- -------- -------- -------- ------------------------
1    disable    disable  enable   Disable  None                   
2    enable     disable  enable   Disable  None                   
10   disable    disable  enable   Disable  None                   
Dslam-Lab# show dot1q port adsl 2/28
Port        PVID  Acceptable frame types  Ingress filter
----------  ----  ----------------------  --------------
2/28         1     all                      off         

Dslam-Lab# show dot1q port adsl 2/28.1
Port        PVID  Acceptable frame types  Ingress filter
----------  ----  ----------------------  --------------
2/28.1       10    all                      off         

Dslam#