<?xml version="1.0" encoding="UTF-8" standalone="no"?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" version="2.0"><channel><title>ccie obsessed</title><description></description><managingEditor>noreply@blogger.com (Ahmad Fadly Abbas)</managingEditor><pubDate>Thu, 24 Oct 2024 18:23:10 +0700</pubDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/">15</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/">25</openSearch:itemsPerPage><link>http://ccieobsessed.blogspot.com/</link><language>en-us</language><item><title>How to install SCABB snmp real time monitoring (SNMP RTM)</title><link>http://ccieobsessed.blogspot.com/2009/08/how-to-install-scabb-snmp-real-time.html</link><category>scabb</category><category>snmp</category><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Mon, 31 Aug 2009 11:14:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-8371284719704982248</guid><description>&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;If you had installed SCABB (Service Control Aplication Broadband) or if you had read scabb end user guide you will be familiar with this topic. This is a tool for network admins to monitor their network using SNMP in real time. Refer to the cisco guide, the snmp tool that we will be used are MRTG (Multi Router Traffic Grapher) and RRD (Round Robin Database) to&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;ol. MRTG will collect snmp data from sce then generate html pages, rrd tool will store data using round robin database and then generate a graph. In my Lab environment &lt;/span&gt;  &lt;span style="font-family:trebuchet ms;"&gt;I'm using my desktop with windowsxp, scabb v3.1.6 , sce 2020.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;How it works :&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWraMFELpWKWxE8SOP4I5FuC27Y41RYoVpGp2_eO9qI8HGrzVWHez94-wX1JG0O25qXCe9rfIXGCmQcP9_WpYypYgNO-wMe0lct8TfmLl0po6f6KBOI1EKO5LukgvFFIjrbYARucro8OM/s1600-h/top.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 251px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWraMFELpWKWxE8SOP4I5FuC27Y41RYoVpGp2_eO9qI8HGrzVWHez94-wX1JG0O25qXCe9rfIXGCmQcP9_WpYypYgNO-wMe0lct8TfmLl0po6f6KBOI1EKO5LukgvFFIjrbYARucro8OM/s400/top.jpg" alt="" id="BLOGGER_PHOTO_ID_5375977881074009106" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;       &lt;span style="font-family:trebuchet ms;"&gt;These are the compone&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;nts that will be used to install SNMP RTM:&lt;/span&gt;  &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;1. MRTG-2.1.5 - download from &lt;a href="http://www.mrtg.org/"&gt;mrtg.org&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;2. rrdtool-1.2.15 - download from &lt;a href="http://www.rrdtool.org/"&gt;rrdtool.org&lt;/a&gt;&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;3. Active Perl 5.8  - search&lt;a href="http://www.google.com/"&gt; google.com&lt;/a&gt; and download&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;4. Apache2 - download from &lt;a href="http://httpd.apache.org/download.cgi"&gt;apache.org&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;5. sca_bb v3.1.6 - download from &lt;a href="http://www.cisco.com/"&gt;cisco.com&lt;/a&gt;&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;6. sca_bb utility - extracted from sca_bb v3.1.6&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;7. scabb_rtm_templates_v3.0.5A_b05 - download&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; from &lt;a href="http://www.cisco.com/"&gt;cisco.com&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;8. firedaemon - search &lt;a href="http://www.cisco.com/"&gt;google.com&lt;/a&gt; and download&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;9. Java (jre) 1.4.2 - download from &lt;a href="http://java.sun.com/"&gt;java.sun.com&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;    &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;- mrtg for collecting snmp&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;- rrd tool to store data&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;- Active perl for running mrtg&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;- Apache for running web server, cgi&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;- scabb v3.1.6 to get scabb utility&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;- scabb utility for generate mrtg cfg files&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;- scabb rtm template for generate&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; cfg file refer to the template and sce configuration&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;- firedaemon for running scheduler&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;- java needs for running scabb utility&lt;/span&gt;   &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;Getting started :&lt;/span&gt;  &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;1. Install mrtg, perl, rrdtool in C:\&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;2. Install apache web-server C:\Program Files&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;3. Install firedaemon&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;4. Install java&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;5. Extract scabb v3.1.6, extract scabb util (bin &amp;amp; lib) to C:\&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;6. Extract scabb rtm template to C:\bin\ &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;7. Create directory rtm-output in C:\bin\&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;8. Edit rtcmd.cfg file&lt;/span&gt;  &lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;#The absolute path to the RRD tool's execution files folder&lt;br /&gt;#Use '\\' or '/' as path separator&lt;br /&gt;rrdtool_bin_dir=C:/rrdtool-1.2.15/rrdtool/Release&lt;br /&gt;&lt;br /&gt;#The absolute path where RTM files will be placed.&lt;br /&gt;#This path will be used by MRTG to create and update the RRD files&lt;br /&gt;#Note: path must not contain white spaces!&lt;br /&gt;rtm_dir=C:/PROGRA~1/APACHE~1/Apache2.2/htdocs&lt;br /&gt;&lt;br /&gt;#The absolute path to the MRTG bin folder.&lt;br /&gt;#This path will be used to create file crontab.txt&lt;br /&gt;mrtg_bin_dir=C:/mrtg-2.14.5/bin&lt;br /&gt;&lt;br /&gt;#The SCE's community string&lt;br /&gt;snmpCommunityString=public&lt;br /&gt;rrdtool_bin_dir=C:/rrdtool-1.2.15/rrdtool/Release&lt;br /&gt;&lt;br /&gt;9. Open command prompt, running this command "rtmcmd -S "ip_sce1;ipsce2" -U xxxxx -P xxxxx --pqb-sce=ip_sce1 --source-dir=/templates --dest-dir=/rtm-output -c ./rtmcmd.cfg&lt;br /&gt;&lt;br /&gt;C:\bin\rtmcmd -S "ip_sce1;ipsce2" -U xxxxx -P xxxxx --pqb-sce=ip_sce1 --source-dir=/templates --dest-dir=/rtm-output -c ./rtmcmd.cfg&lt;br /&gt;connecting to ip_sce1 ... done&lt;br /&gt;retrieving service configuration from SCE ... done&lt;br /&gt;disconnecting from device ... done&lt;br /&gt;loading user configuration from file 'rtmcmd.cfg' ... done&lt;br /&gt;processing templates from '\templates' to '\rtm-output' ... done&lt;br /&gt;C:\bin&gt;&lt;br /&gt;&lt;br /&gt;10. Check rtm-output directory&lt;br /&gt;&lt;br /&gt;C:\bin\rtm-output&gt;dir&lt;br /&gt;Volume in drive C has no label.&lt;br /&gt;Volume Serial Number is C4C2-8BAA&lt;br /&gt;&lt;br /&gt;Directory of C:\bin\rtm-output&lt;br /&gt;&lt;br /&gt;08/31/2009  08:16 AM    dir          .&lt;br /&gt;08/31/2009  08:16 AM    dir         ..&lt;br /&gt;08/31/2009  10:30 AM                43 .htaccess&lt;br /&gt;08/31/2009  10:30 AM               386 crontab-unix.txt&lt;br /&gt;08/31/2009  10:30 AM               310 crontab-windows.txt&lt;br /&gt;08/31/2009  08:16 AM    dir          mrtg-cfg&lt;br /&gt;08/31/2009  08:16 AM    dir          sce_202.155.50.75&lt;br /&gt;08/31/2009  08:16 AM    dir          sce_202.155.50.77&lt;br /&gt;08/31/2009  08:16 AM    dir          static&lt;br /&gt;&lt;br /&gt;11. Copy all file to C:\Program Files\Apache Software Foundation\Apache2.2\htdocs&gt;&lt;br /&gt;12. Edit httpd Apache configuration file and add this text :&lt;br /&gt;&lt;br /&gt;&lt;directory&gt;&lt;br /&gt;Options Indexes FollowSymLinks ExecCGI&lt;br /&gt;AllowOverride Indexes&lt;br /&gt;Order allow,deny&lt;br /&gt;Allow from all&lt;br /&gt;&lt;/directory&gt;&lt;br /&gt;&lt;br /&gt;13. Test mrtg and mrtg cfg file with this command :&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;C:\Perl\bin&gt;perl.exe c:\mrtg-2.14.5\bin\mrtg "c:\Program Files\Apache Software Foundation\Apache2.2\htdocs\mrtg-cfg\ip_sce1_scabb_mrtg.cfg"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;C:\Perl\bin&gt;perl.exe c:\mrtg-2.14.5\bin\mrtg "c:\Program Files\Apache Software Foundation\Apache2.2\htdocs\mrtg-cfg\ip_sce1_scabb_mrtg.cfg"&lt;br /&gt;&lt;br /&gt;If no error appear, you can check working directory a lot of rrd files has been generated.&lt;br /&gt;&lt;br /&gt;14. Open firedaemon, add new service definition :&lt;br /&gt;&lt;br /&gt;Shortname : sce1&lt;br /&gt;Executable : C:\Perl\bin\wperl.exe&lt;br /&gt;Working Dir :C:\Program Files\Apache Software Foundation\Apache2.2\htdocs\sce_ip_sce1&lt;br /&gt;Parameters : C:\mrtg-2.14.5\bin\mrtg "C:\Program Files\Apache Software Foundation\Apache2.2\htdocs\mrtg-cfg\ip_sce1_scabb_mrtg.cfg"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Start Service sce1&lt;br /&gt;&lt;br /&gt;Shortname : sce2&lt;br /&gt;Executable : C:\Perl\bin\wperl.exe&lt;br /&gt;Working Dir :C:\Program Files\Apache Software Foundation\Apache2.2\htdocs\sce_ip_sce2&lt;br /&gt;Parameters : C:\mrtg-2.14.5\bin\mrtg "C:\Program Files\Apache Software Foundation\Apache2.2\htdocs\mrtg-cfg\ip_sce2_scabb_mrtg.cfg"&lt;br /&gt;&lt;br /&gt;Start service sce2&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuLOyWeJhxkFYzuqn_Hf08WaEwGrJRTDYOsLDI-ja61h0sJsuvMxMUY_6DiAMfIHHnSR3XGLoSewAMUNCAxvgFAhkFb2d5qfloako80mVnluPUn5HQd8PPZSLsB8H_5MjDiltcQHqL-2Q/s1600-h/scabb+rtm+fired.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 291px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuLOyWeJhxkFYzuqn_Hf08WaEwGrJRTDYOsLDI-ja61h0sJsuvMxMUY_6DiAMfIHHnSR3XGLoSewAMUNCAxvgFAhkFb2d5qfloako80mVnluPUn5HQd8PPZSLsB8H_5MjDiltcQHqL-2Q/s400/scabb+rtm+fired.JPG" alt="" id="BLOGGER_PHOTO_ID_5375979520222730674" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;15. Open web browser and type :&lt;br /&gt;&lt;br /&gt;http://localhost/sce_ip_sce1/&lt;br /&gt;http://localhost/sce_ip_sce2/&lt;br /&gt;&lt;br /&gt;And finally you will see the following display in your browser :&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvNfgxirCqBXKU8ljdsmInJgFlqjv2mDVUvUr2Dz0Bnx9erXjjmj3IymLxnc8HHzjnMSMu5-Mb43IGJZvRCSl9_6IljYd2JAjhnHdAcjsivdRKqDMkWqvcOvp6ac1TzGuLckC773Jzl6Y/s1600-h/rtm+browser.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 234px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvNfgxirCqBXKU8ljdsmInJgFlqjv2mDVUvUr2Dz0Bnx9erXjjmj3IymLxnc8HHzjnMSMu5-Mb43IGJZvRCSl9_6IljYd2JAjhnHdAcjsivdRKqDMkWqvcOvp6ac1TzGuLckC773Jzl6Y/s400/rtm+browser.JPG" alt="" id="BLOGGER_PHOTO_ID_5375979823806650274" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt;Refference &lt;/span&gt; &lt;a style="font-family: trebuchet ms;" href="http://www.cisco.com/en/US/products/ps613/products_user_guide_book09186a0080843872.html"&gt;http://www.cisco.com/en/US/products/ps61&lt;/a&gt;&lt;a style="font-family: trebuchet ms;" href="http://www.cisco.com/en/US/products/ps613/products_user_guide_book09186a0080843872.html"&gt;/products_user_guide_book09186a0080843872.html&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;dir&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;dir&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;dir&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;dir&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;dir&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;dir&gt; &lt;/dir&gt;&lt;/span&gt;&lt;/dir&gt;&lt;/span&gt;&lt;/dir&gt;&lt;/span&gt;&lt;/dir&gt;&lt;/span&gt;&lt;/dir&gt;&lt;/span&gt;&lt;/dir&gt;&lt;/span&gt;&lt;/span&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWraMFELpWKWxE8SOP4I5FuC27Y41RYoVpGp2_eO9qI8HGrzVWHez94-wX1JG0O25qXCe9rfIXGCmQcP9_WpYypYgNO-wMe0lct8TfmLl0po6f6KBOI1EKO5LukgvFFIjrbYARucro8OM/s72-c/top.jpg" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total></item><item><title>Update protocol pack and signature using SCABB / SCE</title><link>http://ccieobsessed.blogspot.com/2009/08/update-protocol-and-protocol-signature.html</link><category>block flash</category><category>block peer to peer</category><category>block youtube video</category><category>sce protocol pack</category><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Fri, 14 Aug 2009 10:33:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-8661469832566930537</guid><description>&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Using Cisco SCE we can manage traffic per application based on protocol that supported by SCE Software. In my lab I use sce 2020, Software 3.1.6. My goal is I want to control or &lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;even block the subscribers traffic in accessing bandwidth consuming application such as peer to peer, flash youtube, flash yahoo, video google, http download et&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;c.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;First I &lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;applied the streaming service to the package &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;and made some rule t&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;o control it,&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; then I &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;mapped the subscriber using SM to &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;use that package. Somehow the rule was not working,  user could &lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;still have an access to the video google, flash youtube etc. Than I checked the reporting in SCABB the user traffic is classified as a browsing. I was &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;thinking that SCE cannot &lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;detect those protocol as a flash protocol that is define in its service configuration protocol. I checked at the cisco website than I found that I must upgrade the protocol pack of the &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;existing software. This happen because of &lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;there are some of a new update to the &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;protocol in internet, SCE must improve the capabilities in detecting and making classification to the new protocol and signature. The new update of protocol &lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;pack now is SCA BB Protocol Pack #17, it resolved some of caveat in the previous protocol pack, such as miss classifying protocol i.e yahoo login, flash etc.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;  &lt;span style="font-family:trebuchet ms;"&gt;This is the new update protocol :&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;• Flash YouTube HD&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;• Flash YouTube Normal&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;• Yahoo General Login&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;• Sky Player - (Supported by 3.5.0 only)&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;and here is the guide :&lt;br /&gt;&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;1. Download SPQI at cisco.com&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;2. Extract the SPQI file 3.1.6 Protocol Pack #17 ZIP package&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;3. install the ProtocolPack using SCABB, right clik on sce, network navig&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;ator menu&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: right;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIMgyCPU4jRl21uuyl34IMMApy4Fgr83hWSqY3OTIGA_WfbYP2Y1L3cx6QsZ9ghStxlZBB2yVhOfR3RL2pryyMTpeRxYKvEeGX5GbS7j23qt7wTG-N_vG4kocCqv8OJVctvFYzbSdiaUA/s1600-h/sce.bmp"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 182px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIMgyCPU4jRl21uuyl34IMMApy4Fgr83hWSqY3OTIGA_WfbYP2Y1L3cx6QsZ9ghStxlZBB2yVhOfR3RL2pryyMTpeRxYKvEeGX5GbS7j23qt7wTG-N_vG4kocCqv8OJVctvFYzbSdiaUA/s200/sce.bmp" alt="" id="BLOGGER_PHOTO_ID_5369660515099732130" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;4. Extract the script.txt file from the 3.1.6 Protocol Pack #17 ZIP package and upload to the SCE platform using FTP.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;SCE2020#copy-passive ftp://user:pass@ip-address/script.txt script.t&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;xt&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;5. Open a CLI session in the SCE platform and navigate to the director&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;y where the uploaded script.txt. Using admin user run the script run script.txt.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;   &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;SCE2020-2#&gt;script run script.txt&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;configure&lt;br /&gt;interface LineCard 0&lt;br /&gt;&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_UserAgents overwrite-key "Babelgum" value 23&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_UserAgents overwrite-key "babelgum" value 23&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_UserAgents overwrite-key "Deluge*" value 9&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_UserAgents overwrite-key "TVUPlayer*" value 24&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_UserAgents overwrite-key "PIPIPlayer" value 25&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_UserAgents overwrite-key "NateOn*" value 26&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_UserAgents overwrite-key "ed2k" value 6&lt;br /&gt;&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_HOST overwrite-key "*:*.babelgum.com"  value 7&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_HOST overwrite-key "*:*.vuze.com"  value 8&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_HOST overwrite-key "*:channel2.tvunetworks.com"  value 10&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_HOST overwrite-key "co*:*.tvunetworks.com"  value 10&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_HOST overwrite-key "*:mb.tvunetworks.com"  value 10&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_HOST overwrite-key "*:pages.tvunetworks.com"  value 10&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_HOST overwrite-key "*:*mail.google.com"  value 11&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_HOST overwrite-key "*:*skype.com"  value 12&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_HOST overwrite-key "*:*joost.com"  value 13&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_HOST overwrite-key "*:*googlevideo.com"  value 1&lt;br /&gt;&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_URL overwrite-key /videoplayback*:* value 2&lt;br /&gt;lookup GT_LUT_HTTP_BASED_PROTOCOLS_URL overwrite-key *:*.hash value 7&lt;br /&gt;&lt;br /&gt;lookup GT_LUT_DestPortBasedProtocolsPostMultipleSig overwrite-key "0.6.0.22:0xffffffff" value 16777216&lt;br /&gt;&lt;br /&gt;lookup GT_LUT_HTTP_SPLIT_INITIATEE_BASED_PROTOCOLS_Server overwrite-key "AIM*:*"  value 7&lt;br /&gt;&lt;br /&gt;tunable GT_PL_USE_OLD_BEHAVIORAL_DOWNLOAD value false&lt;br /&gt;tunable PL_AGING_RTMP value 3000&lt;br /&gt;tunable GT_PL_SKYPE_TCP_PRECEDE_PKTS_PAT_MAX value 180&lt;br /&gt;&lt;br /&gt;tunable GT_PL_BEHAVIORAL_DOWNLOAD_MIN_AVG_PACKET_SIZE value 700&lt;br /&gt;tunable GT_PL_BEHAVIORAL_DOWNLOAD_MAX_VOLUME_RATIO value 25&lt;br /&gt;tunable GT_PL_BEHAVIORAL_DOWNLOAD_PACKET_DEVIATION_HI_VOL_FACTOR value 50&lt;br /&gt;&lt;br /&gt;tunable GT_PL_WINNYP_NUMBER_OF_CHECKED_PACKETS value 5&lt;br /&gt;tunable GT_PL_WINNYP_MAXIMAL_ALLOWED_DIRECTION_CHANGES value 5&lt;br /&gt;&lt;br /&gt;tunable GT_QQMaxPacketsInSameDir value 7&lt;br /&gt;&lt;br /&gt;exit&lt;br /&gt;exit&lt;br /&gt;&lt;br /&gt;copy running-config-application startup-config-&lt;span style="font-size:100%;"&gt;application&lt;/span&gt;&lt;br /&gt;Writing general configuration file to temporary location...&lt;br /&gt;Removing old application configuration file...&lt;br /&gt;Renaming temporary application configuration file with the final file's name...&lt;br /&gt;&lt;br /&gt;SCE2020-1#&gt;                     &lt;br /&gt;The screenshoot result for successfully blocked youtube and google video.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;youtube :&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgw0VrgfdUXEL3h4Owdwgg0pEjD0q4vP2zud7I74peYGbsuTN2icbjUzIEegPSN81dv_43PTNo7Qb3_K84UaiyhIw0yH2903g3DLM6ILr0A234_56n_y3Xt62Jg6dACrYT8k4yjegDuds/s1600-h/youtube+blok.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 222px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgw0VrgfdUXEL3h4Owdwgg0pEjD0q4vP2zud7I74peYGbsuTN2icbjUzIEegPSN81dv_43PTNo7Qb3_K84UaiyhIw0yH2903g3DLM6ILr0A234_56n_y3Xt62Jg6dACrYT8k4yjegDuds/s320/youtube+blok.JPG" alt="" id="BLOGGER_PHOTO_ID_5369788929548665154" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Google Video :&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimD0D0gBUE8IdSo-1WNczjobIqI0oqh7sImRiNOrqyUk1raCT27zaTs1tpwElRI03x2peVJGFG7uVvNdpzcyk7z7Zy5g-HFT2kPAZ5cXk-tBWOSOaBuDOou88lvBHUG7MYROX07Bnwsfo/s1600-h/video+google.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 246px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimD0D0gBUE8IdSo-1WNczjobIqI0oqh7sImRiNOrqyUk1raCT27zaTs1tpwElRI03x2peVJGFG7uVvNdpzcyk7z7Zy5g-HFT2kPAZ5cXk-tBWOSOaBuDOou88lvBHUG7MYROX07Bnwsfo/s320/video+google.JPG" alt="" id="BLOGGER_PHOTO_ID_5369788439338338418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;This is only the sample if you want to block google video or youtube, you can control any of protocol as long as is supported by protocol pack.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIMgyCPU4jRl21uuyl34IMMApy4Fgr83hWSqY3OTIGA_WfbYP2Y1L3cx6QsZ9ghStxlZBB2yVhOfR3RL2pryyMTpeRxYKvEeGX5GbS7j23qt7wTG-N_vG4kocCqv8OJVctvFYzbSdiaUA/s72-c/sce.bmp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total></item><item><title>ISG - SCE Integration using SCMP</title><link>http://ccieobsessed.blogspot.com/2009/08/isg-sce-integration-using-scmp.html</link><category>integration SCE SCMP</category><category>ISG</category><category>SCE</category><category>SCMP</category><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Tue, 4 Aug 2009 15:29:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-7993612903103175164</guid><description>&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;ISG (Intelligent service Gateway) is a broadband agregation r&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;outer to deliver service from service provider to the broadband subscriber. Using ISG&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; we can control and implement dynamic policy to the subscriber such as turbo button (upgrade or downgrade speed),  Parental control, Subscriber self-control using Captive Portal / Redirect Wallgarden Service and External-policy controll using CoA. For more advanced implementation is to implement ISG &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;colaborative with SCE as a DPI (deep packet inspection) service control. Using SCE we can make some of different s&lt;/span&gt;&lt;/span&gt;ervice levels for subscriber. We can control the subscriber trafic in the aplication  layer (layer7) or we can use taffic shaping capabilites.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;To integrate SCE and ISG we can use  SCMP, it allows that isg and SCE to man&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;age subscriber session and apply subscriber to particular service / profile dynamically intsead of using subscriber manager (SM) using SCABB application. External Portal / Walled garden can send a Coa packet &lt;/span&gt;&lt;/span&gt;&lt;span class="content"&gt;(CoA RFC 3576)&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; to ISG to change the user's service. In the isg policy we can define any package that will be sent using Coa to SCE include the GUID / user identity, next when the SCE accept the CoA, it will assign the package to this GUID.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;I try to make a lab to implement this integration, using isg and sce 2020. Here is the diagram:&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;span style="font-weight: bold;"&gt;DIAGRAM :&lt;/span&gt;&lt;br /&gt;---------------------------------------------&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;---------------------------------------------&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-----------------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOOXCOjedhk8VsmQykFbodora-g1ghmk2beVxos5ramClYxBCzXtW22LQb0PwqjJxSzkT3e-xDdUZZ_ue_L4_En4pS0kOG7Wbxk6DEec_KWWlXmMJao1tp_Hw9PAtilVMXZTpM7Jj1lmA/s1600-h/scmp.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 193px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOOXCOjedhk8VsmQykFbodora-g1ghmk2beVxos5ramClYxBCzXtW22LQb0PwqjJxSzkT3e-xDdUZZ_ue_L4_En4pS0kOG7Wbxk6DEec_KWWlXmMJao1tp_Hw9PAtilVMXZTpM7Jj1lmA/s400/scmp.JPG" alt="" id="BLOGGER_PHOTO_ID_5369791133939205330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-----------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISG configuration :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;ISGD2#&lt;br /&gt;!&lt;br /&gt;aaa attribute list coa&lt;br /&gt;attribute type nas-ip-address 172.16.0.29&lt;br /&gt;!&lt;br /&gt;!&lt;br /&gt;!&lt;br /&gt;aaa server radius policy-device&lt;br /&gt;key peditea&lt;br /&gt;message-authenticator ignore&lt;br /&gt;client 192.168.50.77 vrf vpn_internet key peditea&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Verify the SCMP peer in the ISG:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;ISGD2#sh subscriber policy peer all&lt;br /&gt;EXTERNAL POLICY PEER Details:&lt;br /&gt;=============================&lt;br /&gt;&lt;br /&gt;Peer IP: 192.168.50.77&lt;br /&gt;Conn ID: 11&lt;br /&gt;Mode   : PUSH&lt;br /&gt;State  : ACTIVE&lt;br /&gt;Version: 2.0&lt;br /&gt;Conn up time: 00:08:55&lt;br /&gt;Conf keepalive: 100&lt;br /&gt;Negotiated keepalive: 100&lt;br /&gt;Time since last keepalive: 00:00:34&lt;br /&gt;Inform owner on pull: TRUE&lt;br /&gt;Total number of associated sessions: 1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;CoA from ISG to SCE :&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;*Aug  4 06:16:27.582: RADIUS(00000000): Send CoA Request to 192.168.50.77:3799 id 1645/53, len 211&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:  authenticator C7 E2 B1 A2 F5 7B 13 65 - 98 05 83 9B A5 DF 5E CE&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:  Vendor, Cisco       [26]  37&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:   Cisco AVpair       [1]   31  "session-guid=CA9B591E0000003C"&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:  NAS-Port            [5]   6   60000            &lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:  NAS-Port-Id         [87]  21  "nas-port:0/0/0/86/0"&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:  Vendor, Cisco       [26]  37&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:   Cisco AVpair       [1]   31  "subscriber:command=updateSess"&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:  Vendor, Cisco       [26]  32&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:   Cisco AVpair       [1]   26  "subscriber:policy-name=6"&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:  Vendor, Cisco       [26]  36&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:   Cisco AVpair       [1]   30  "subscriber:service-monitor=1"&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:  NAS-IP-Address      [4]   6   172.16.0.29    &lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:  User-Name           [1]   10  "fadlytea"&lt;br /&gt;*Aug  4 06:16:27.582: RADIUS:  Framed-IP-Address   [8]   6   172.16.94.2      &lt;br /&gt;*Aug  4 06:16:27.586: RADIUS: Received from id 1645/53 192.168.50.77:3799, CoA Ack Response, len 63&lt;br /&gt;*Aug  4 06:16:27.586: RADIUS:  authenticator B8 00 27 53 E2 DF 79 28 - 82 30 38 3F 76 A9 85 06&lt;br /&gt;*Aug  4 06:16:27.586: RADIUS:  NAS-IP-Address      [4]   6   192.168.50.77    &lt;br /&gt;*Aug  4 06:16:27.586: RADIUS:  Vendor, Cisco       [26]  37&lt;br /&gt;*Aug  4 06:16:27.586: RADIUS:   Cisco AVpair       [1]   31  "session-guid=CA9B591E0000003C"&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;span style="font-weight: bold;"&gt;Verify the user session GUID:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;ISGD2#sh subscriber policy peer all  detail&lt;br /&gt;EXTERNAL POLICY PEER Details:&lt;br /&gt;=============================&lt;br /&gt;&lt;br /&gt;Peer IP: 192.168.50.77&lt;br /&gt;Conn ID: 11&lt;br /&gt;Mode   : PUSH&lt;br /&gt;State  : ACTIVE&lt;br /&gt;Version: 2.0&lt;br /&gt;Conn up time: 00:08:57&lt;br /&gt;Conf keepalive: 100&lt;br /&gt;Negotiated keepalive: 100&lt;br /&gt;Time since last keepalive: 00:00:36&lt;br /&gt;Inform owner on pull: TRUE&lt;br /&gt;Total number of associated sessions: 1&lt;br /&gt;Associated session details:&lt;br /&gt;CA9B591E0000003C&lt;br /&gt;&lt;br /&gt;ISGD2#&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Verify SCMP peer in the SCE :&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SCE2020-2#sh scmp all&lt;br /&gt;SCMP Connection 'isg-dev2' status:&lt;br /&gt;172.16.0.29 auth-port 1645 acct-port 1646&lt;br /&gt;Connection state:      Connected&lt;br /&gt;Peer protocol-version: 2.0&lt;br /&gt;Keep-alive interval:   100 seconds&lt;br /&gt;Force single SCE:      Yes&lt;br /&gt;Send session start:    Yes&lt;br /&gt;Time connected:        9 minutes, 18 seconds&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Verify subscriber session GUID mapping package in SCE :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;SCE2020-2#SH interface LineCard 0 subscriber name CA9B591E0000003C&lt;br /&gt;Subscriber 'CA9B591E0000003C' manager: isg-dev2&lt;br /&gt;Subscriber 'CA9B591E0000003C' properties:&lt;br /&gt;downVlinkId=0&lt;br /&gt;monitor=1&lt;br /&gt;new_classification_policy=0&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;packageId=6&lt;/span&gt;&lt;br /&gt;QpLimit[0..17]=0*17,8&lt;br /&gt;QpSet[0..17]=0*17,1&lt;br /&gt;upVlinkId=0&lt;br /&gt;Subscriber 'CA9B591E0000003C' read-only properties:&lt;br /&gt;concurrentAttacksNumber=0&lt;br /&gt;PV_QP_QuotaSetCounter[0..17]=0*18&lt;br /&gt;PV_QP_QuotaUsageCounter[0..17]=0*18&lt;br /&gt;PV_REP_nonReportedSessionsInTUR=0&lt;br /&gt;P_aggPeriodType=5&lt;br /&gt;P_blockReportCounter=0&lt;br /&gt;P_endOfAggPeriodTimestamp=0&lt;br /&gt;P_firstTimeParty=TRUE&lt;br /&gt;P_localEndOfAggPeriodTimestamp=0&lt;br /&gt;P_MibSubCounters16[0..31][0..1]=0*64&lt;br /&gt;P_MibSubCounters32[0..31][0..1]=0*64&lt;br /&gt;P_newParty=TRUE&lt;br /&gt;p_numOfRedirections=0&lt;br /&gt;P_partyCurrentDownVLink=0&lt;br /&gt;P_partyCurrentPackage=6&lt;br /&gt;P_partyCurrentUpVLink=0&lt;br /&gt;P_partyGoOnlineTime=0&lt;br /&gt;P_partyMonth=0&lt;br /&gt;P_serviceReportedBitMap=0&lt;br /&gt;Subscriber 'CA9B591E0000003C' mappings:&lt;br /&gt;IP 172.16.94.2 - Expiration (sec): Unlimited&lt;br /&gt;Subscriber 'CA9B591E0000003C' has 0 active sessions.&lt;br /&gt;Aging disabled&lt;br /&gt;SCE2020-2#                                    &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOOXCOjedhk8VsmQykFbodora-g1ghmk2beVxos5ramClYxBCzXtW22LQb0PwqjJxSzkT3e-xDdUZZ_ue_L4_En4pS0kOG7Wbxk6DEec_KWWlXmMJao1tp_Hw9PAtilVMXZTpM7Jj1lmA/s72-c/scmp.JPG" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>PPPOE and L2TP Multihop VPDN</title><link>http://ccieobsessed.blogspot.com/2009/07/pppoe-and-l2tp-multihop-vpdn.html</link><category>configuration</category><category>l2tp</category><category>multihop vpdn</category><category>pppoe</category><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Thu, 30 Jul 2009 14:35:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-1729165943728134877</guid><description>&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;There are many different technology in broadband access network, include DSL, cable , ethernet, wireless etc. PPPoe is commonly used by ADSL technology in ISP. L2tp is one of the most used protocol in broadband network, it is commonly used by operators or broadband access provider to extend their network to ISP as a wholesale.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I tried to make basic concept and configuration about how to implement them. For PC, i'm using windowsXP as a pppoe client, cisco 2600 as lac (vpn-server), 7200 as lns (isg-dev2), 7200 as lns-2 (isg2-jtpd) for terminating ppp session from pc &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;pc will connect with pppoe using a user with domain @imm.com, vpn-server will accept pppoe request and forward and L2TP based on domain to lns (ISG-DEV2). lns than forward the ppp using l2tp multihop to lns-2 based on multihop lac hostname. lns-2 then will terminate the ppp and give the user ip adress.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;DIAGRAM :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHgFbnS7bKoZ9ZKjyuk51g9n0zbuL-U5dUnqbv7zASrpO2rQkfZnDI-PSWBRqGOhi0xnlC9CQ1ocwUbqy1QRCHn2NhO6sZfSxALyG_XsS7WTnDlkM0GUVb_OlkBlb-zjjyM0EsY8gvs58/s1600-h/vpdn+multihop.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 174px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHgFbnS7bKoZ9ZKjyuk51g9n0zbuL-U5dUnqbv7zASrpO2rQkfZnDI-PSWBRqGOhi0xnlC9CQ1ocwUbqy1QRCHn2NhO6sZfSxALyG_XsS7WTnDlkM0GUVb_OlkBlb-zjjyM0EsY8gvs58/s400/vpdn+multihop.JPG" alt="" id="BLOGGER_PHOTO_ID_5369785373498458754" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;CONFIGURATION :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;1. pppoe :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN-SERVER#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;!         &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;vpdn-group pppoe&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; accept-dialin&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  protocol pppoe&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  virtual-template 15&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; lcp renegotiation always&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;2. VPDN Tunnel Switching :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN-SERVER#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;vpdn search-order domain  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;!         &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;vpdn-group 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; request-dialin&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  protocol l2tp&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  domain imm.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; initiate-to ip 11.0.0.1 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; local name lac&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; no source vpdn-template&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; l2tp tunnel password peditea&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;ISGDEV2#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;vpdn-group multihop-in&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; accept-dialin&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  protocol l2tp&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  virtual-template 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; terminate-from hostname lac&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; local name lns-multi&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; l2tp tunnel password 0 peditea&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;3. VPDN MULTIHOP (L2TP)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;ISGDEV2#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;vpdn multihop&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;vpdn search-order multihop-hostname  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;vpdn-group multihop&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; request-dialin&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  protocol l2tp&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  multihop hostname lac&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; initiate-to ip 192.168.89.6&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; local name lns-multi&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; l2tp tunnel password 0 peditea&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;ISG-JTPD#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;vpdn-group 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; accept-dialin&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  protocol l2tp&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  virtual-template 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; terminate-from hostname lns-multi&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; local name lns-server&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; l2tp tunnel password 0 peditea&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;VERIFYING :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER#sh vpdn &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;L2TP Tunnel and Session Information Total tunnels 1 sessions 1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;LocID RemID Remote Name   State  Remote Address  Port  Sessions VPDN Group&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;3402  65399 lns-multi     est    11.0.0.1        1701  1        1              &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;LocID RemID TunID Intf          Username             State  Last Chg Uniq ID&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;964   33172 3402  SSS Circuit   -imm@imm.com         est    00:00:14 344    &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;ISGDEV2#sh vpdn tunnel &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;L2TP Tunnel Information Total tunnels 2 sessions 2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;LocTunID   RemTunID   Remote Name   State  Remote Address  Sessn L2TP Class/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;                                                           Count VPDN Group &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;30787      61466      lns-server    est    192.168.89.6  1     multihop       &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;65399      3402       lac           est    11.0.0.2        1     multihop-in  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;ISG2-JTPD#sh vpdn &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;L2TP Tunnel and Session Information Total tunnels 1 sessions 1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;LocID RemID Remote Name   State  Remote Address  Port  Sessions L2TP Class/ &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;                                                                VPDN Group &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;61466 30787 lns-multi     est    192.168.89.3   1701  1        1              &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;LocID      RemID      TunID      Username, Intf/      State  Last Chg Uniq ID   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;                                 Vcid, Circuit                                  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;8          10696      61466      -imm@imm.com, Vi3    est    00:01:03 491    &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Reference : http://www.cisco.com/en/US/docs/ios/bbdsl/configuration/guide/bba_understanding_ps6350_TSD_Products_Configuration_Guide_Chapter.html#wp1049344&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHgFbnS7bKoZ9ZKjyuk51g9n0zbuL-U5dUnqbv7zASrpO2rQkfZnDI-PSWBRqGOhi0xnlC9CQ1ocwUbqy1QRCHn2NhO6sZfSxALyG_XsS7WTnDlkM0GUVb_OlkBlb-zjjyM0EsY8gvs58/s72-c/vpdn+multihop.JPG" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Point-to-Point Protocol over Ethernet - using windows &amp; cisco</title><link>http://ccieobsessed.blogspot.com/2009/07/point-to-point-protocol-over-ethernet.html</link><category>pppoe</category><category>pppoe client</category><category>pppoe server</category><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Wed, 29 Jul 2009 14:10:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-113801399783958292</guid><description>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;PPPOE &lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;is a network protocol for encapsulation pp&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;p in ethernet network. It &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;is one of dial technology beside pptp and L2TP. It is usually used in adsl network, subcriber can access &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;internet provider using user's credential (username an&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;d password) .  PPPOE works in layer 2 &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;netw&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;ork meanwhile PPTP work in Layer 3.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;What I want to show you is the &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;basic configuratio&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;n using &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;w&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;i&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;ndows as a pppoe client and cisco 2600 as a pppoe server.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Here is the diagram :&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-----------------------------------------------------------------------------&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;------&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;------------------&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;------------&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgT0aFZFCBTpM-uWQE2wSKwVwcFXvWGF33_Rs7jMaVZrTZUEaY6x63XRfcKKSYlJ88k_ec7ppPWYvihMzfIIZzlG2vfzL9782TAkRZduIkXvt9XHgLEC_-TznO-BnQ7k7HfVYgbOjvQUE4/s1600-h/ppoe+windows+xp+cisco.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 137px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgT0aFZFCBTpM-uWQE2wSKwVwcFXvWGF33_Rs7jMaVZrTZUEaY6x63XRfcKKSYlJ88k_ec7ppPWYvihMzfIIZzlG2vfzL9782TAkRZduIkXvt9XHgLEC_-TznO-BnQ7k7HfVYgbOjvQUE4/s400/ppoe+windows+xp+cisco.JPG" alt="" id="BLOGGER_PHOTO_ID_5369790690290332290" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;------------------------------------------------------&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-----------------------&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;------------------------------------&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;1. Create Virtual-Temp&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;late :&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;config)# interface Virtual-Te&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;mplate1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config-if)#&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; ip unnumbered FastEth&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;ernet0/1.81&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config-if)#&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; ip tcp adjust-mss 1460&lt;br /&gt;&lt;br /&gt;2. Enable vpdn and making vpdn-group :&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(c&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;onfig)# vpdn enable&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config)# &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;vpdn-group pppoe&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config-vpdn)#  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;accept&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-dialin&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-vpdn&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-acc-in)# &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;protocol pppoe&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-vpdn&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-acc-in)# &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;virtual-template 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-vpdn&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;acc-in)# exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;-vpdn&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;)# &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;lcp renegotiatio&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;n always&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;3. Configure authentication &amp;amp; ip address pool :&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Enable AAA and method-list :&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;VPN_SERVER(config&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;)# &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;aaa new-mod&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;e&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;l&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;)# &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;aaa authentication ppp defau&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;lt local&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;)# &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;aaa authorization net&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;work default local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Create Username :&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SE&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;RVER(config&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;)# &lt;/span&gt;&lt;/span&gt;username fadly password 0 cisco&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Create Ip pool :&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;)#&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;  ip local pool vpn_sce 192.168.100.1 192.168.10&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;0.100&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Enable pp&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;p authenti&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;cation and &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;assign &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;pool :&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config)# interface &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Virtual-Template1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config-if)#&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;  &lt;/span&gt;&lt;/span&gt;peer default ip address pool vpn_sce&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config-if)#&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; &lt;/span&gt;&lt;/span&gt; ppp authentication pap chap&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;4. Enable pppoe &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;in interface :&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVE&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;R(config)# &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;interface FastEthernet0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(config-if)#&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; ip &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;address 172.16.0.11 255.255.128.0 &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;secondary&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER(co&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;nfig-if)#&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;pppoe &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;enable&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;5. Create pppoe client and Dial from windows XP :&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi87KKzt-h6jgMMVI8dGFsLfvRMYv63EdV7Zl2jX-vhEvH463dmu1SmYtqW6dfCpZRJI8JOtqg4OdENqqUkzwejX6cHUfIqOQK5DfOvID1QTtsUv-8mLzJ10cDQ90UWSwp2shaByJQhhpg/s1600-h/create+new+conn.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 193px; height: 57px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi87KKzt-h6jgMMVI8dGFsLfvRMYv63EdV7Zl2jX-vhEvH463dmu1SmYtqW6dfCpZRJI8JOtqg4OdENqqUkzwejX6cHUfIqOQK5DfOvID1QTtsUv-8mLzJ10cDQ90UWSwp2shaByJQhhpg/s200/create+new+conn.JPG" alt="" id="BLOGGER_PHOTO_ID_5363796025645305874" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwFda5oKFa77bFAkgI7TWAaHiv_7tA7PBtR66Hakb-GK6HakZso0US2f7XJuND5Cb_XTgwGXv5468obzyIrj2skjn_RW5mvHq7IvPfZDKdfCsAp5p96sY0jG17jKkIUEeecAi5mHgkeX4/s1600-h/pppoe+2.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 158px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwFda5oKFa77bFAkgI7TWAaHiv_7tA7PBtR66Hakb-GK6HakZso0US2f7XJuND5Cb_XTgwGXv5468obzyIrj2skjn_RW5mvHq7IvPfZDKdfCsAp5p96sY0jG17jKkIUEeecAi5mHgkeX4/s200/pppoe+2.JPG" alt="" id="BLOGGER_PHOTO_ID_5363796395766298242" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZaDK0oQ7cLXta0XqRp8ouNokY6jiiMtfXYYdwQoji7wxO-pdjYqoZvsJjIWMeQxDx27s9RQ-s57XVgVjwi1ryn8gdLr9BqJOdQTHl7FtBbJEPzGK2igWisPPHTJWKs3-3l9Cp7lUMIIc/s1600-h/pppoe+3.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 157px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZaDK0oQ7cLXta0XqRp8ouNokY6jiiMtfXYYdwQoji7wxO-pdjYqoZvsJjIWMeQxDx27s9RQ-s57XVgVjwi1ryn8gdLr9BqJOdQTHl7FtBbJEPzGK2igWisPPHTJWKs3-3l9Cp7lUMIIc/s200/pppoe+3.JPG" alt="" id="BLOGGER_PHOTO_ID_5363796491538342786" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjY_mpuwo05-KzGPpvWmhsBg5F0qQNAXuhvdXqsLoobqPPf5XpHCHcjFmUm1TUshRGVD1V4nwsUUG6Xblrau26uvMocSZY4rKsCecnQ74vM3i3hTqgIOsSg3F8lNmmUt4O-glJYXSyE01g/s1600-h/pppoe+4.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 158px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjY_mpuwo05-KzGPpvWmhsBg5F0qQNAXuhvdXqsLoobqPPf5XpHCHcjFmUm1TUshRGVD1V4nwsUUG6Xblrau26uvMocSZY4rKsCecnQ74vM3i3hTqgIOsSg3F8lNmmUt4O-glJYXSyE01g/s200/pppoe+4.JPG" alt="" id="BLOGGER_PHOTO_ID_5363796613669823634" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDyIf-Z-fllAKnNGBkN8raahRSN_CQFZqmttlWgTuzQdfShK2suvIZwm7U2C55npHM1CjeZr-65SgMlG67S7uvUoH2X89HJ9k4BtmWLjL-RXizVKnod2varp7haLA23dwa1XcIvA8A1G0/s1600-h/pppoe+5.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 156px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDyIf-Z-fllAKnNGBkN8raahRSN_CQFZqmttlWgTuzQdfShK2suvIZwm7U2C55npHM1CjeZr-65SgMlG67S7uvUoH2X89HJ9k4BtmWLjL-RXizVKnod2varp7haLA23dwa1XcIvA8A1G0/s200/pppoe+5.JPG" alt="" id="BLOGGER_PHOTO_ID_5363798956608612898" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnWgOwTYB-i8sNgFbI32SKiKbTKpza5rIopVfvOj801nvbL2Jrl76AAz_ddMsYA5RwCDEO3jhT695hUtqAr1atTNj5Ef1vRswh7afaNJnBEmvOgRe2OrzBlIUi40PdFm_OjfoY8BsAYDw/s1600-h/pppoe+6.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 156px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnWgOwTYB-i8sNgFbI32SKiKbTKpza5rIopVfvOj801nvbL2Jrl76AAz_ddMsYA5RwCDEO3jhT695hUtqAr1atTNj5Ef1vRswh7afaNJnBEmvOgRe2OrzBlIUi40PdFm_OjfoY8BsAYDw/s200/pppoe+6.JPG" alt="" id="BLOGGER_PHOTO_ID_5363799097437403922" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjJDBbV393cnx5inyWT1Ek-dTqmTUX-1_bVYpOwTKYWAIlGKebj5At7_myShY2-FbRM0yrdArKKWQ9I0GJfhLQCpQgKO8DvZG30MqVv1LyQNnUe7vY86JColZxrEaM52YyjS4FqNdfXjM/s1600-h/pppoe+7.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 156px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjJDBbV393cnx5inyWT1Ek-dTqmTUX-1_bVYpOwTKYWAIlGKebj5At7_myShY2-FbRM0yrdArKKWQ9I0GJfhLQCpQgKO8DvZG30MqVv1LyQNnUe7vY86JColZxrEaM52YyjS4FqNdfXjM/s200/pppoe+7.JPG" alt="" id="BLOGGER_PHOTO_ID_5363799180433026562" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEih2Fw6hqg7iZxT6FCb-4gWUGUs828y16pyAGWhcBfrl_Qe_RqVlyHVXxqFrzAuirU8kGsoXaQU2m_k2WOkHmz1lZgDzkdVOXz0FPSn49rxeIYBcnQTvzBXXTug_Z6YXf3vCai9zBa_25Y/s1600-h/pppoe+8.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 166px; height: 200px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEih2Fw6hqg7iZxT6FCb-4gWUGUs828y16pyAGWhcBfrl_Qe_RqVlyHVXxqFrzAuirU8kGsoXaQU2m_k2WOkHmz1lZgDzkdVOXz0FPSn49rxeIYBcnQTvzBXXTug_Z6YXf3vCai9zBa_25Y/s200/pppoe+8.JPG" alt="" id="BLOGGER_PHOTO_ID_5363799244702747650" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCpCVc-wIXxLILpsY8vwH1TlxcyqqglSj3U6TMELlYAZUcBvKfxaLyfZ6-RfhYieQaBrNVlzujpeayn6cQGQdEXbc_YP4qmATPFWrNDMUZP5Z2PLJazGb5Hlrewgkno1eOCqKP65XjCPM/s1600-h/pppoe+9.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 169px; height: 200px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCpCVc-wIXxLILpsY8vwH1TlxcyqqglSj3U6TMELlYAZUcBvKfxaLyfZ6-RfhYieQaBrNVlzujpeayn6cQGQdEXbc_YP4qmATPFWrNDMUZP5Z2PLJazGb5Hlrewgkno1eOCqKP65XjCPM/s200/pppoe+9.JPG" alt="" id="BLOGGER_PHOTO_ID_5363799323309643074" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_ZDzqhg_e_ODHPuDMqJsu4UWywAoTEoUYpKOuMy4Jxe5DPWNcrHwmfKVIrnixT2kc6ksTWfcDYlQ3ExNedqQmBcG73OFQPpAAOM5oCmZ0xRiQRSb4dS3Oeol8rmz08StTq1Uq8SqsLeU/s1600-h/pppoe+10.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 188px; height: 200px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_ZDzqhg_e_ODHPuDMqJsu4UWywAoTEoUYpKOuMy4Jxe5DPWNcrHwmfKVIrnixT2kc6ksTWfcDYlQ3ExNedqQmBcG73OFQPpAAOM5oCmZ0xRiQRSb4dS3Oeol8rmz08StTq1Uq8SqsLeU/s200/pppoe+10.JPG" alt="" id="BLOGGER_PHOTO_ID_5363799397532248370" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiq2ZEbr2CoRJ_tKncQF5JmpVQdBT5cidUk-2p7lBduE86USjYOge-IneuwN0pPUIBSCNSBw_Ynhl4OX7J7aTYlCvnUWdtEwha_IINDLwofYlFePNdByu9OTEvEgd35hmOAueL0Ke023oU/s1600-h/pppoe+11.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 164px; height: 200px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiq2ZEbr2CoRJ_tKncQF5JmpVQdBT5cidUk-2p7lBduE86USjYOge-IneuwN0pPUIBSCNSBw_Ynhl4OX7J7aTYlCvnUWdtEwha_IINDLwofYlFePNdByu9OTEvEgd35hmOAueL0Ke023oU/s200/pppoe+11.JPG" alt="" id="BLOGGER_PHOTO_ID_5363799470101659442" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;6. Verif&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;y the pppoe &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;session :&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER#sh user&lt;br /&gt;Line       User       Host(s)              Id&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;le       Location&lt;br /&gt;* 66 vt&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;y 0     fadly      i&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;dle                 0&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;0:00:0&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;0 172.16.0.134&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Interface    User               M&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;ode         Idle     Peer &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Addr&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;ess&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Vi1.1        fadly              PPPoE        00:00:00 192.168.100.5&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER#&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;VPN_SERVER#sh vpdn&lt;br /&gt;&lt;br /&gt;PPPoE Tunnel and Session Information Total tunnels 1 sessions 1&lt;br /&gt;&lt;br /&gt;PPPoE Session Information&lt;br /&gt;UID    SID    RemMAC         OIntf          Intf      Session&lt;br /&gt;LocMAC                        VASt      state&lt;br /&gt;278    841    0090.f55d.6dbc Fa0/0          Vi1.1     CNCT_PTA&lt;br /&gt;000d.bd6c.3fc0               UP&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;VPN_SERVER#&lt;br /&gt;&lt;br /&gt;VPN_SERVER#sh sss session&lt;br /&gt;Current SSS Information: Total sessions 1&lt;br /&gt;&lt;br /&gt;Uniq ID Type       State         Service      Identifier           Last Chg&lt;br /&gt;278     PPPoE/PPP  connected     Local Term   fadly                00:04:18&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;it is very straight forward :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgT0aFZFCBTpM-uWQE2wSKwVwcFXvWGF33_Rs7jMaVZrTZUEaY6x63XRfcKKSYlJ88k_ec7ppPWYvihMzfIIZzlG2vfzL9782TAkRZduIkXvt9XHgLEC_-TznO-BnQ7k7HfVYgbOjvQUE4/s72-c/ppoe+windows+xp+cisco.JPG" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Basic PIX firewall configuration</title><link>http://ccieobsessed.blogspot.com/2009/07/basic-pix-configuration.html</link><category>basic pix</category><category>pix</category><category>pix cli</category><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Tue, 28 Jul 2009 10:02:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-2581933333704255277</guid><description>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;span style="font-weight: bold;"&gt;This is the basic pix firewall configuration and concept&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Firewall is networking device that can protect unauthorized internet &lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;users from accessing private network. it has the concept of inside / private network and outside / internet by assigning security level. The outside has a security level of &lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;0 and inside has a security level of 100. Meaning that traffic from lower security level interface will not pass higher security level interface. We can modifiy the rule to make the traffic flow from outside interface to inside interface.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Diagram :&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihoalQmACg12iGi01IEu2Y7BYlWVVE3lsRxeMoAx-Dtv7IOOEm5Oao-JJFSkF1AZJDzqMgSWYix4sY6rEQPKZj60ldZxjUQdbk5HuTGbjWjdjaVzIb3fAYIX8qAh7g-RbBkjroO_3Q61g/s1600-h/firewall+basic.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 109px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihoalQmACg12iGi01IEu2Y7BYlWVVE3lsRxeMoAx-Dtv7IOOEm5Oao-JJFSkF1AZJDzqMgSWYix4sY6rEQPKZj60ldZxjUQdbk5HuTGbjWjdjaVzIb3fAYIX8qAh7g-RbBkjroO_3Q61g/s400/firewall+basic.JPG" alt="" id="BLOGGER_PHOTO_ID_5369786129700190306" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Basic Configuration&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1. Set the hostname :&lt;br /&gt;&lt;br /&gt;pixfirewall# configure terminal&lt;br /&gt;pixfirewall(config)#hostname pix-jtpd&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2. Set the password :&lt;br /&gt;&lt;br /&gt;Login password :&lt;br /&gt;pix-jtpd(config)# password cisco&lt;br /&gt;&lt;br /&gt;Enable password :&lt;br /&gt;pix-jtpd(config)# enable password cisco&lt;br /&gt;&lt;br /&gt;3. Verifiying security level :&lt;br /&gt;&lt;br /&gt;pix-jtpd# show nameif&lt;br /&gt;Interface                Name                     Security&lt;br /&gt;Ethernet0                outside                    0&lt;br /&gt;Ethernet1                inside                   100&lt;br /&gt;pix-jtpd#&lt;br /&gt;&lt;br /&gt;4. Set ip address :&lt;br /&gt;&lt;br /&gt;interface Ethernet0&lt;br /&gt;nameif outside&lt;br /&gt;security-level 0&lt;br /&gt;ip address 192.168.78.182 255.255.255.252&lt;br /&gt;!&lt;br /&gt;interface Ethernet1&lt;br /&gt;nameif inside&lt;br /&gt;security-level 100&lt;br /&gt;ip address 192.168.78.186 255.255.255.252&lt;br /&gt;&lt;br /&gt;Verify interface ip address :&lt;br /&gt;&lt;br /&gt;pix-jtpd# sh interface ip brief&lt;br /&gt;Interface                  IP-Address      OK? Method Status                Protocol&lt;br /&gt;Ethernet0                  192.168.78.182   YES manual up                    up&lt;br /&gt;Ethernet1                  192.168.78.186   YES manual up                    up&lt;br /&gt;pix-jtpd#&lt;br /&gt;&lt;br /&gt;Ping back to back ip address :&lt;br /&gt;&lt;br /&gt;pix-jtpd# ping 192.168.78.181&lt;br /&gt;Type escape sequence to abort.&lt;br /&gt;Sending 5, 100-byte ICMP Echos to 192.168.78.181, timeout is 2 seconds:&lt;br /&gt;!!!!!&lt;br /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/10 ms&lt;br /&gt;pix-jtpd# ping 192.168.78.185&lt;br /&gt;Type escape sequence to abort.&lt;br /&gt;Sending 5, 100-byte ICMP Echos to 192.168.78.185, timeout is 2 seconds:&lt;br /&gt;!!!!!&lt;br /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;br /&gt;pix-jtpd#&lt;br /&gt;&lt;br /&gt;5. Configure default route&lt;br /&gt;&lt;br /&gt;pix-jtpd(config)# route outside 0.0.0.0 0.0.0.0 192.168.78.181 1&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;pix-jtpd# show ip route&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;C    192.168.78.180 255.255.255.252 is directly connected, outside&lt;br /&gt;C    192.168.78.184 255.255.255.252 is directly connected, inside&lt;br /&gt;S*   0.0.0.0 0.0.0.0 [1/0] via 192.168.78.181, outside&lt;br /&gt;pix-jtpd#&lt;br /&gt;&lt;br /&gt;6. Configuring NAT and define subscriber network :&lt;br /&gt;&lt;br /&gt;a. Set ip address to name :&lt;br /&gt;pix-jtpd(config)# name 192.168.32.0 subscriber&lt;br /&gt;&lt;br /&gt;b. Set subscriber route :&lt;br /&gt;route inside chat-subs 255.255.255.0 192.168.78.185 1&lt;br /&gt;&lt;br /&gt;c. Setting nat :&lt;br /&gt;inside network :&lt;br /&gt;pix-jtpd(config)# nat (inside) 1 chat-subs 255.255.255.0&lt;br /&gt;pix-jtpd(config)# nat (inside) 1 192.168.78.184 255.255.255.252&lt;br /&gt;&lt;br /&gt;global network :&lt;br /&gt;global (outside) 1 192.168.78.188 netmask 255.255.255.255&lt;br /&gt;&lt;br /&gt;NOTE : must configure route from PE to global (outside)&lt;br /&gt;&lt;br /&gt;d. Veryfiy nat is working :&lt;br /&gt;&lt;br /&gt;pix-jtpd# sh xlate&lt;br /&gt;94 in use, 3299 most used&lt;br /&gt;PAT Global 192.168.78.188(1095) Local 192.168.32.30(2182)&lt;br /&gt;PAT Global 192.168.78.188(1053) Local 192.168.32.30(59266)&lt;br /&gt;PAT Global 192.168.78.188(1052) Local 192.168.32.30(65524)&lt;br /&gt;PAT Global 192.168.78.188(1051) Local 192.168.32.30(50954)&lt;br /&gt;&lt;br /&gt;7. Making Rule / Access-list&lt;br /&gt;&lt;br /&gt;Setting ACL :&lt;br /&gt;&lt;br /&gt;pix-jtpd(config)# access-list acl_grp extended permit icmp any any&lt;br /&gt;pix-jtpd(config)# access-list acl_grp extended permit tcp any any&lt;br /&gt;pix-jtpd(config)# access-list acl_grp extended permit ip any any&lt;br /&gt;&lt;br /&gt;Apply to the interface :&lt;br /&gt;&lt;br /&gt;pix-jtpd(config)# access-group acl_grp in interface outside&lt;br /&gt;pix-jtpd(config)# access-group acl_grp in interface inside&lt;br /&gt;&lt;br /&gt;Have a good try :D&lt;br /&gt;&lt;/span&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihoalQmACg12iGi01IEu2Y7BYlWVVE3lsRxeMoAx-Dtv7IOOEm5Oao-JJFSkF1AZJDzqMgSWYix4sY6rEQPKZj60ldZxjUQdbk5HuTGbjWjdjaVzIb3fAYIX8qAh7g-RbBkjroO_3Q61g/s72-c/firewall+basic.JPG" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Dhcp Fixed Address</title><link>http://ccieobsessed.blogspot.com/2009/07/dhcp-fixed-address.html</link><category>dhcp</category><category>fixed address</category><category>ubuntu</category><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Tue, 28 Jul 2009 08:18:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-3481416717167222880</guid><description>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;Some hosts will required fixed ip address, such as : web server, printer etc. Host which require fixed ip address need to be mapped with its mac-address. This is sample configuration of dhcp server :&lt;br /&gt;&lt;br /&gt;root@fadly-desktop:~# vi /etc/dhcp3/dhcpd.conf&lt;br /&gt;&lt;br /&gt;host fadly {&lt;br /&gt;hardware ethernet 00:90:F5:5D:6D:BC;&lt;br /&gt;fixed-address 192.168.78.206;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;subnet 192.168.78.204 netmask 255.255.255.252 {&lt;br /&gt;option broadcast-address 192.168.78.207;&lt;br /&gt;option routers 192.168.78.205;&lt;br /&gt;option subnet-mask 255.255.255.252;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;option domain-name 202.155.0.10;&lt;/span&gt;</description><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Cisco - Linux Dhcp-relay setting</title><link>http://ccieobsessed.blogspot.com/2009/07/cisco-linux-dhcp-relay-setting.html</link><category>dhcp-relay</category><category>linux dhcp</category><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Fri, 17 Jul 2009 11:14:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-1645555744158960272</guid><description>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;This is the configuration of router as dhcp-relay and linux as dhcp server&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:trebuchet ms;font-size:100%;"  &gt;Diagram :&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5Ts2XcpsJ4IiB9MeocpjQmw21wNiKv7kq8hTUqfqJO4ujZQXo5iQEdgmhHeYlQ6B-86IGDDH2NoHY1sYjXb4TzhuJINF5RTflM0z14ZXvwumjuBFl39xqN4v5NAwmWHFCu41Wc1gv5sQ/s1600-h/dchp+relay+ubuntu+server.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 161px;" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5Ts2XcpsJ4IiB9MeocpjQmw21wNiKv7kq8hTUqfqJO4ujZQXo5iQEdgmhHeYlQ6B-86IGDDH2NoHY1sYjXb4TzhuJINF5RTflM0z14ZXvwumjuBFl39xqN4v5NAwmWHFCu41Wc1gv5sQ/s400/dchp+relay+ubuntu+server.JPG" alt="" id="BLOGGER_PHOTO_ID_5369787702630440402" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;1. Interface configuration :&lt;br /&gt;&lt;br /&gt;!&lt;br /&gt;interface GigabitEthernet0/0.11&lt;br /&gt;description ### Test Internet ###&lt;br /&gt;encapsulation dot1Q 11&lt;br /&gt;ip dhcp relay information trusted&lt;br /&gt;ip dhcp relay information option vpn-id none&lt;br /&gt;ip vrf forwarding vpn_internet&lt;br /&gt;ip address 192.168.78.201 255.255.255.252&lt;br /&gt;ip helper-address 192.168.78.198&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Config note :&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:trebuchet ms;font-size:100%;" class="content"  &gt;&lt;span class="cBold"&gt;ip dhcp relay information trusted&lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;" class="content"  &gt; &lt;a name="wp1012807"&gt;&lt;/a&gt;&lt;p class="pB1_Body1"&gt; Usage Guidelines&lt;/p&gt;&lt;p class="pB1_Body1"&gt;By default, if the gateway address is set to all zeros in the DHCP packet and the relay information option is already present in the packet, the Cisco IOS DHCP relay agent will discard the packet. If the &lt;b class="cBold"&gt;ip dhcp relay information trusted &lt;/b&gt;command is configured on an interface, the Cisco IOS DHCP relay agent will not discard the packet even if the gateway address is set to all zeros. Instead, the received DHCPDISCOVER or DHCPREQUEST messages will be forwarded to the addresses configured by the &lt;b class="cCN_CmdName"&gt;ip helper-address&lt;/b&gt; command as in normal DHCP relay operation.  &lt;/p&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;ip dhcp relay information option vpn-id&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="content"&gt;To enable the system to insert VPN suboptions into the DHCP relay agent information option in forwarded BOOTREQUEST messages to a DHCP server and set the gateway address to the outgoing interface toward the DHCP server, use the &lt;b class="cCN_CmdName"&gt;ip dhcp relay information option vpn-id &lt;/b&gt;command in interface configuration mode. To remove the configuration, use the &lt;b class="cBold"&gt;no&lt;/b&gt; form of this command. &lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;&lt;br /&gt;refference : http://www.cisco.com/en/US/docs/ios/ipaddr/command/reference/iad_dhc2.html#wp1012293&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;2. Edit dhcp configuration :&lt;br /&gt;&lt;br /&gt;root@desktop:# vi /etc/dhcp3/dhcpd.conf&lt;br /&gt;&lt;br /&gt;ddns-update-style none;&lt;br /&gt;&lt;br /&gt;default-lease-time 600;&lt;br /&gt;max-lease-time 7200;&lt;br /&gt;&lt;br /&gt;#authoritative;&lt;br /&gt;&lt;br /&gt;log-facility local7;&lt;br /&gt;&lt;br /&gt;option subnet-mask 255.255.255.252;&lt;br /&gt;option broadcast-address 192.168.78.203;&lt;br /&gt;option routers 192.168.78.201;&lt;br /&gt;&lt;br /&gt;subnet 192.168.78.200 netmask 255.255.255.252 {&lt;br /&gt;range 192.168.78.202;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. Checking log :&lt;br /&gt;&lt;br /&gt;Jul 15 18:17:22 -desktop dhcpd: DHCPDISCOVER from 00:0a:e4:36:03:a0 via 192.168.78.201&lt;br /&gt;Jul 15 18:17:23 -desktop dhcpd: DHCPOFFER on 192.168.78.202 to 00:0a:e4:36:03:a0 (LENOVO-2EB43090) via 192.168.78.201&lt;br /&gt;Jul 15 18:17:23 -desktop dhcpd: DHCPREQUEST for 192.168.78.202 (192.168.78.198) from 00:0a:e4:36:03:a0 (LENOVO-2EB43090) via 192.168.78.201&lt;br /&gt;Jul 15 18:17:23 -desktop dhcpd: DHCPACK on 192.168.78.202 to 00:0a:e4:36:03:a0 (LENOVO-2EB43090) via 192.168.78.201&lt;br /&gt;Jul 15 18:17:25 -desktop dhcpd: DHCPREQUEST for 192.168.78.202 from 00:0a:e4:36:03:a0 (LENOVO-2EB43090) via eth1&lt;br /&gt;Jul 15 18:17:25 -desktop dhcpd: DHCPACK on 192.168.78.202 to 00:0a:e4:36:03:a0 (LENOVO-2EB43090) via eth1&lt;br /&gt;&lt;br /&gt;Have a good try.. :)&lt;br /&gt;&lt;/span&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5Ts2XcpsJ4IiB9MeocpjQmw21wNiKv7kq8hTUqfqJO4ujZQXo5iQEdgmhHeYlQ6B-86IGDDH2NoHY1sYjXb4TzhuJINF5RTflM0z14ZXvwumjuBFl39xqN4v5NAwmWHFCu41Wc1gv5sQ/s72-c/dchp+relay+ubuntu+server.JPG" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Dynamips Dynagen Tutorial</title><link>http://ccieobsessed.blogspot.com/2009/07/dynamips-dynagen-tutorial.html</link><category>basic dynamips</category><category>cisco router simulator</category><category>dynagen</category><category>dynamips</category><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Wed, 15 Jul 2009 09:44:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-8595295301550871347</guid><description>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;(First ): Download dynagen at http://dynagen.org&lt;br /&gt;&lt;br /&gt;Go to download menu, you will be redirected to http://sourceforge.net&lt;br /&gt;Go to Dynagen source / Linux : click dynagen-0.11.0.tar.gz&lt;br /&gt;Point your mouse to use direct link, right click then copy link location, http://downloads.sourceforge.net/sourceforge/dyna-gen/dynagen-0.11.0.tar.gz?use_mirror=nchc&lt;br /&gt;&lt;br /&gt;  Download from Linux terminal :&lt;br /&gt;root@desktop:~# wget http://downloads.sourceforge.net/sourceforge/dyna-gen/dynagen-0.11.0.tar.gz?use_mirror=nchc&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;(Second) : Create directory &amp;amp; extract tarball&lt;br /&gt;&lt;br /&gt;Create Directory : root@desktop:~# mkdir /home/dynamips&lt;br /&gt;Move source file to dynamips folder : root@desktop:~# mv dynagen-0.11.0.tar.gz /home/dynamips&lt;br /&gt;Extract tarball : root@desktop:~# tar zxvf dynagen-0.11.0.tar.gz&lt;br /&gt;Go to folder :  root@desktop:~# cd /home/dynamips/dynagen-0.11.0&lt;br /&gt;Check README file :root@desktop:/home/dynamips/dynagen-0.11.0#more README.txt&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;  This version of Dynagen requires at least version 0.2.8-RC1 of Dynamips&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;(Third) : Download dynamips that is match to dynagen requirement&lt;br /&gt;&lt;br /&gt;Go to http://www.ipflow.utc.fr/blog/&lt;br /&gt;point your mouse to this link 0.2.8-RC2 binary for Linux x86 platforms, right click and copy link location&lt;br /&gt;http://www.ipflow.utc.fr/dynamips/dynamips-0.2.8-RC2-x86.bin&lt;br /&gt;&lt;br /&gt;Download from Linux terminal :&lt;br /&gt;root@desktop:/home/dynamips/dynagen-0.11.0# wget http://www.ipflow.utc.fr/dynamips/dynamips-0.2.8-RC2-x86.bin&lt;br /&gt;&lt;br /&gt;Change privilege :&lt;br /&gt;root@desktop:/home/dynamips/dynagen-0.11.0# chmod 777 dynamips-0.2.8-RC2-x86.bin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;(Fourth) : Create Symlink (Symbolic link)&lt;br /&gt;Go to folder : cd /usr/bin&lt;br /&gt;symlink using alias for dynamips program : /usr/bin# ln -s /home/dynamips/dynagen-0.11.0/dynamips-0.2.8-RC2-x86.bin dynamips&lt;br /&gt;  symlink using alias for dynagen program : /usr/bin# ln -s /home/dynamips/dynagen-0.11.0/dynagen dynagen&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;(Fifth) : Download, Extract &amp;amp; Copy IOS image&lt;br /&gt;Download IOS (I will not tell you how to get the IOS)&lt;br /&gt;extract the IOS to make router boot up faster than ziped IOS&lt;br /&gt;Create directory to store IOS :&lt;br /&gt;root@desktop:/home/dynamips/dynagen-0.11.0# mkdir Images&lt;br /&gt;navigate to folder : cd Images&lt;br /&gt;copy IOS file : cp /home/C7200-K9.BIN C7200-K9.BIN&lt;br /&gt;&lt;br /&gt;(Sixth) : Running Sample Lab&lt;br /&gt;Go to sample labs .net file : root@desktop: cd /home/dynamips/dynagen-0.11.0/sample_labs/simple1#&lt;br /&gt;Edit simple1.net : vi sample1.net&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;[localhost]&lt;br /&gt;&lt;br /&gt;  [[7200]]&lt;br /&gt;  # image = \Program Files\Dynamips\images\c7200-jk9o3s-mz.124-7a.image&lt;br /&gt;  # On Linux / Unix use forward slashes:&lt;br /&gt;    image = /home/dynamips/dynagen-0.11.0/Images/C7200-K9.BIN&lt;br /&gt;  npe = npe-400&lt;br /&gt;  ram = 160&lt;br /&gt;&lt;br /&gt;  [[ROUTER R1]]&lt;br /&gt;  s1/0 = R2 s1/0&lt;br /&gt;&lt;br /&gt;  [[router R2]]&lt;br /&gt; # No need to specify an adapter here, it is taken care of&lt;br /&gt; # by the interface specification under Router R1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;# R1 s1/0 -----  R2 s1/0&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;(Seventh) : Run dynamips instance 7200 in background (&amp;amp;)&lt;br /&gt;&lt;br /&gt;root@desktop:/home/dynamips/dynagen-0.11.0/sample_labs/simple1# dynamips -H 7200 &amp;amp;&lt;br /&gt;[1] 7267&lt;br /&gt;root@desktop:/home/dynamips/dynagen-0.11.0/sample_labs/simple1# Cisco Router Simulation Platform (version 0.2.8-RC2-x86)&lt;br /&gt;Copyright (c) 2005-2007 Christophe Fillot.&lt;br /&gt;Build date: Oct  2 2008 01:17:18&lt;br /&gt;&lt;br /&gt;ILT: loaded table "mips64j" from cache.&lt;br /&gt;ILT: loaded table "mips64e" from cache.&lt;br /&gt;ILT: loaded table "ppc32j" from cache.&lt;br /&gt;ILT: loaded table "ppc32e" from cache.&lt;br /&gt;Hypervisor TCP control server started (port 7200).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;(Eighth)    : Run Dynagen simple1.net&lt;br /&gt;root@desktop:/home/dynamips/dynagen-0.11.0/sample_labs/simple1#dynagen simple1.net&lt;br /&gt;&lt;br /&gt;Dynagen management console for Dynamips and Pemuwrapper 0.11.0&lt;br /&gt;Copyright (c) 2005-2007 Greg Anuzelli, contributions Pavel Skovajsa&lt;br /&gt;&lt;br /&gt;=&gt; list&lt;br /&gt;Name       Type       State      Server          Console&lt;br /&gt;R1         7200       running    localhost:7200  2000&lt;br /&gt;R2         7200       running    localhost:7200  2001&lt;br /&gt;=&gt;&lt;br /&gt;&lt;br /&gt;(Ninth)    : Access / Telnet R1 &amp;amp; R2&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;root@desktop:~# telnet localhost 2000&lt;br /&gt;Trying 127.0.0.1...&lt;br /&gt;Connected to localhost.&lt;br /&gt;Escape character is '^]'.&lt;br /&gt;Connected to Dynamips VM "R1" (ID 0, type c7200) - Console port&lt;br /&gt;&lt;br /&gt;Router#conf t&lt;br /&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;br /&gt;Router(config)#hostname R1&lt;br /&gt;R1(config)#int serial 1/0&lt;br /&gt;R1(config-if)#no shutdown&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;root@desktop:~# telnet localhost 2001&lt;br /&gt;Trying 127.0.0.1...&lt;br /&gt;Connected to localhost.&lt;br /&gt;Escape character is '^]'.&lt;br /&gt;Connected to Dynamips VM "R2" (ID 1, type c7200) - Console port&lt;br /&gt;&lt;br /&gt;Router#conf t&lt;br /&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;br /&gt;Router(config)#hostname R2&lt;br /&gt;R2(config)#int serial 1/0&lt;br /&gt;R2(config-if)#no shutdown&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;R1#sh cdp neighbors&lt;br /&gt;Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge&lt;br /&gt;            S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone&lt;br /&gt;&lt;br /&gt;Device ID            Local Intrfce         Holdtme   Capability    Platform    Port ID&lt;br /&gt;R2           Ser 1/0        &lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;15                      R              7206VXR Ser 1/0&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;R2#sh cdp nei&lt;br /&gt;Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge&lt;br /&gt;            S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone&lt;br /&gt;&lt;br /&gt;Device ID            Local Intrfce         Holdtme   Capability    Platform    Port ID&lt;br /&gt;R1                            Ser 1/0                      158         R             7206VXR    Ser 1/0&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;Set ip address :&lt;br /&gt;&lt;br /&gt;R1(config)#int ser 1/0&lt;br /&gt;R1(config-if)#ip add 10.1.0.1 255.255.255.0&lt;br /&gt;&lt;br /&gt;R2(config)#int ser 1/0&lt;br /&gt;R2(config-if)#ip add 10.1.0.2 255.255.255.0&lt;br /&gt;R2(config-if)#&lt;br /&gt;&lt;br /&gt;Ping : R1 to R2&lt;br /&gt;&lt;br /&gt;R1#ping 10.1.0.1&lt;br /&gt;&lt;br /&gt;Type escape sequence to abort.&lt;br /&gt;Sending 5, 100-byte ICMP Echos to 10.1.0.2, timeout is 2 seconds:&lt;br /&gt;!!!!!&lt;br /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 12/15/16 ms&lt;br /&gt;&lt;br /&gt;(Tenth) : Turn off the router, Stop dynagen and dynamips&lt;br /&gt;&lt;br /&gt;Turn off the router :&lt;br /&gt;&lt;br /&gt;=&gt;&lt;br /&gt;=&gt; stop R1&lt;br /&gt;C7200 'R1': stopping simulation.&lt;br /&gt;100-VM 'R1' stopped&lt;br /&gt;=&gt; stop R2&lt;br /&gt;100-VM 'R2' stopped&lt;br /&gt;C7200 'R2': stopping simulation.&lt;br /&gt;=&gt;&lt;br /&gt;&lt;br /&gt;Stop Dynagen simple1.net&lt;br /&gt;&lt;br /&gt;Exit dynagen :&lt;br /&gt;=&gt; exit&lt;br /&gt;Exiting...&lt;br /&gt;Shutdown in progress...&lt;br /&gt;Shutdown completed&lt;br /&gt;&lt;br /&gt;Stop dynamips :&lt;br /&gt;&lt;br /&gt;root@desktop:/home/dynamips/dynagen-0.11.0/sample_labs/simple1# ps -ax |grep dynamips&lt;br /&gt;Warning: bad ps syntax, perhaps a bogus '-'? See http://procps.sf.net/faq.html&lt;br /&gt;7267 pts/0    Sl    39:08 dynamips -H 7200&lt;br /&gt;7699 pts/0    R+     0:00 grep dynamips&lt;br /&gt;&lt;br /&gt;root@desktop:/home/dynamips/dynagen-0.11.0/sample_labs/simple1# kill -9 7267&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To optimize your pc, you have to set the idle-pc. idle-pc depend on IOS, to get the value use this step :&lt;br /&gt;&lt;br /&gt;=&gt; idlepc get R1&lt;br /&gt;Please wait while gathering statistics...&lt;br /&gt;&lt;br /&gt;Please wait while gathering statistics...&lt;br /&gt;Done. Suggested idling PC:&lt;br /&gt;0x608c5bc8 (count=48)&lt;br /&gt; 0x608c5bcc (count=35)&lt;br /&gt; 0x608463cc (count=59)&lt;br /&gt;0x60847050 (count=71)&lt;br /&gt;Restart the emulator with "--idle-pc=0x608c5bc8" (for example)&lt;br /&gt; 1: 0x608c5bc8 [48]&lt;br /&gt; 2: 0x608c5bcc [35]&lt;br /&gt;*  3: 0x608463cc [59]&lt;br /&gt; 4: 0x60847050 [71]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Edit simple1.net : vi sample1.net&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[localhost]&lt;br /&gt;&lt;br /&gt;  [[7200]]&lt;br /&gt;  # image = \Program Files\Dynamips\images\c7200-jk9o3s-mz.124-7a.image&lt;br /&gt;  # On Linux / Unix use forward slashes:&lt;br /&gt;    image = /home/dynamips/dynagen-0.11.0/Images/C7200-K9.BIN&lt;br /&gt;  npe = npe-400&lt;br /&gt;  ram = 160&lt;br /&gt;idlepc = 0x608463cc&lt;br /&gt;&lt;br /&gt;Save file&lt;br /&gt;&lt;br /&gt;simple1#dynagen simple1.net&lt;br /&gt;&lt;br /&gt;=&gt; idlepc show R1&lt;br /&gt;R1 has an idlepc value of: 0x608463cc&lt;br /&gt;=&gt; idlepc show R2&lt;br /&gt;R2 has an idlepc value of: 0x608463cc&lt;br /&gt;=&gt;&lt;br /&gt;&lt;br /&gt;     Have a good try ;)&lt;br /&gt;&lt;br /&gt;here is the usefull link to try dynamips and dynagen from iementor&lt;br /&gt;&lt;a href="http://www.iementor.com/Introduction_to_Dynamips.pdf"&gt;http://www.iementor.com/Introduction_to_Dynamips.pdf&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;</description><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Nas port equal to Zero (Nas-port = 0)</title><link>http://ccieobsessed.blogspot.com/2009/04/nas-port-equal-to-zero-nas-port-0.html</link><category>Nas-Port</category><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Mon, 13 Apr 2009 16:41:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-470230965674456482</guid><description>&lt;span style=";font-family:trebuchet ms;font-size:100%;" class="content"  &gt;&lt;p class="pB1_Body1"&gt;Nas-Port is one of the radius attribute that can be used for identifying user both of in the Router or in the radius server.&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;I'm using IOS SB and 7200 VXR for the router, it can be configured to send Nas-Port attribute or not. If you don't want to send it, you just configure the router like this :&lt;/p&gt;&lt;p class="pB1_Body1"&gt;                                        &lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;Diagram :  PC ----L3 ISG ----- INTERNET&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;                         |---- PORTAL    &lt;/p&gt;&lt;p class="pB1_Body1"&gt;                         |---- RADIUS&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;-----------------------------------------------------------------------------------------------------------------   &lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;Configuration :&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;ISG-L4R(config)#aaa group server radius AAA&lt;br /&gt;ISG-L4R(config-sg-radius)#attribute nas-port ?&lt;br /&gt;format  Set the format of the NAS-Port attribute&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;none    Don't send nas-port attribute&lt;/span&gt;&lt;cr&gt;&lt;br /&gt;ISG-L4R(config-sg-radius)#attribute nas-port none&lt;br /&gt;&lt;/cr&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;The debug result will be like this :&lt;/p&gt;&lt;p class="pB1_Body1"&gt;(1). User login from Website :&lt;br /&gt;&lt;/p&gt;006675: Apr 13 14:52:44 WIB: RADIUS: COA  received from id 105 20.0.92.156:32775, CoA Request, len 93&lt;br /&gt;006676: Apr 13 14:52:44 WIB: RADIUS/DECODE: VSA external len != internal + VSA hdr&lt;br /&gt;&lt;br /&gt;(2). Nas-port is being disable :&lt;br /&gt;&lt;br /&gt;006677: Apr 13 14:52:44 WIB: RADIUS/ENCODE(00000D42):Orig. component type = IEDGE_IP_SIP&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;006678: Apr 13 14:52:44 WIB: RADIUS/ENCODE: &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;NAS PORT sending disabled&lt;/span&gt;&lt;br /&gt;006679: Apr 13 14:52:44 WIB: RADIUS(00000D42): Config NAS IP: 10.0.4.101&lt;br /&gt;006680: Apr 13 14:52:44 WIB: RADIUS/ENCODE(00000D42): acct_session_id: 3447&lt;br /&gt;006681: Apr 13 14:52:44 WIB: RADIUS(00000D42): Config NAS IP: 10.0.4.101&lt;br /&gt;&lt;br /&gt;(3). Login Request to Radius :&lt;br /&gt;&lt;br /&gt;006682: Apr 13 14:52:44 WIB: RADIUS(00000D42): sending&lt;br /&gt;006683: Apr 13 14:52:44 WIB: RADIUS(00000D42): Send Access-Request to 10.0.100.29:1645 id 1645/150, len 109&lt;br /&gt;006684: Apr 13 14:52:44 WIB: RADIUS:  authenticator C0 6E 4D 8F 2E 5B 9B 17 - 89 90 06 DE 9F C4 CB B2&lt;br /&gt;006685: Apr 13 14:52:44 WIB: RADIUS:  Framed-IP-Address   [8]   6   30.0.74.1         &lt;br /&gt;006686: Apr 13 14:52:44 WIB: RADIUS:  User-Name           [1]   11  "pedi128k"&lt;br /&gt;006687: Apr 13 14:52:44 WIB: RADIUS:  User-Password       [2]   18  *&lt;br /&gt;006688: Apr 13 14:52:44 WIB: RADIUS:  NAS-Port-Type       [61]  6   Virtual                   [5]&lt;br /&gt;006689: Apr 13 14:52:44 WIB: RADIUS:  NAS-Port-Id         [87]  11  "0/0/3/806"&lt;br /&gt;006690: Apr 13 14:52:44 WIB: RADIUS:  Service-Type        [6]   6   Login                     [1]&lt;br /&gt;006691: Apr 13 14:52:44 WIB: RADIUS:  NAS-IP-Address      [4]   6   10.0.4.101       &lt;br /&gt;006692: Apr 13 14:52:44 WIB: RADIUS:  Acct-Session-Id     [44]  10  "00000D77"&lt;br /&gt;006693: Apr 13 14:52:44 WIB: RADIUS:  Nas-Identifier      [32]  9   "ISG-L4R"&lt;br /&gt;006694: Apr 13 14:52:44 WIB: RADIUS:  Event-Timestamp     [55]  6   1239609164          &lt;br /&gt;&lt;br /&gt;(4). Received response from Radius :&lt;br /&gt;&lt;br /&gt;006695: Apr 13 14:52:45 WIB: RADIUS: Received from id 1645/150 10.0.100.29:1645, Access-Accept, len 94&lt;br /&gt;006696: Apr 13 14:52:45 WIB: RADIUS:  authenticator 28 0C 18 47 8A E5 4E 9C - 45 7F B6 21 70 E0 A3 F0&lt;br /&gt;006697: Apr 13 14:52:45 WIB: RADIUS:  Class               [25]  50&lt;br /&gt;006698: Apr 13 14:52:45 WIB: RADIUS:   53 42 52 2D 43 4C 20 44 4E 3D 22 63 61 62 6C 65  [SBR-CL DN="pedi]&lt;br /&gt;006699: Apr 13 14:52:45 WIB: RADIUS:   31 32 38 6B 22 20 41 54 3D 22 32 30 30 22 20 55  [128k" AT="200" U]&lt;br /&gt;006700: Apr 13 14:52:45 WIB: RADIUS:   53 3D 22 22 20 53 49 3D 22 32 31 35 32 32 22 00   [ S="" SI="21522"]&lt;br /&gt;006701: Apr 13 14:52:45 WIB: RADIUS:  Vendor, Unknown     [26]  12&lt;br /&gt;006702: Apr 13 14:52:45 WIB: RADIUS:  Unsupported         [2]   6&lt;br /&gt;006703: Apr 13 14:52:45 WIB: RADIUS:   00 00 00 01&lt;br /&gt;006704: Apr 13 14:52:45 WIB: RADIUS:  Session-Timeout     [27]  6   86400               &lt;br /&gt;006705: Apr 13 14:52:45 WIB: RADIUS:  Idle-Timeout        [28]  6   300                 &lt;br /&gt;006706: Apr 13 14:52:45 WIB: RADIUS(00000D42): Received from id 1645/150&lt;br /&gt;006707: Apr 13 14:52:45 WIB: RADIUS/ENCODE(00000D42):Orig. component type = IEDGE_IP_SIP&lt;br /&gt;006708: Apr 13 14:52:45 WIB: RADIUS:  AAA Unsupported Attr: timeout           [371] 4   86400&lt;br /&gt;006709: Apr 13 14:52:45 WIB: RADIUS:  AAA Unsupported Attr: idletime          [123] 4   300&lt;br /&gt;&lt;br /&gt;(6). Ack response to Portal :&lt;br /&gt;&lt;br /&gt;006710: Apr 13 14:52:45 WIB: RADIUS(00000D42): sending&lt;br /&gt;006711: Apr 13 14:52:45 WIB: RADIUS(00000D42): Send CoA Ack Response to 20.0.92.156:32775 id 105, len 70&lt;br /&gt;006712: Apr 13 14:52:45 WIB: RADIUS:  authenticator 55 36 45 5F 9E 23 1E 37 - 0E 07 E7 29 2B FD 0B 16&lt;br /&gt;006713: Apr 13 14:52:45 WIB: RADIUS:  Vendor, Cisco       [26]  18&lt;br /&gt;006714: Apr 13 14:52:45 WIB: RADIUS:   ssg-command-code   [252] 12&lt;br /&gt;006715: Apr 13 14:52:45 WIB: RADIUS:   01 63 61 62 6C 65 31 32 38 6B         [Account-Log-On pedi128k]&lt;br /&gt;006716: Apr 13 14:52:45 WIB: RADIUS:  Vendor, Cisco       [26]  20&lt;br /&gt;006717: Apr 13 14:52:45 WIB: RADIUS:   ssg-account-info   [250] 14  "S30.0.74.1"&lt;br /&gt;006718: Apr 13 14:52:45 WIB: RADIUS:  Session-Timeout     [27]  6   86400               &lt;br /&gt;006719: Apr 13 14:52:45 WIB: RADIUS:  Idle-Timeout        [28]  6   300                 &lt;br /&gt;006720: Apr 13 14:52:45 WIB: RADIUS/ENCODE(00000D42):Orig. component type = IEDGE_IP_SIP&lt;br /&gt;006721: Apr 13 14:52:45 WIB: RADIUS/ENCODE: NAS PORT sending disabled&lt;br /&gt;006722: Apr 13 14:52:45 WIB: RADIUS(00000D42): Config NAS IP: 10.0.4.101&lt;br /&gt;006723: Apr 13 14:52:45 WIB: RADIUS(00000D42): Config NAS IP: 10.0.4.101&lt;br /&gt;&lt;br /&gt;(7). Sending Accounting Request :&lt;br /&gt;&lt;br /&gt;006724: Apr 13 14:52:45 WIB: RADIUS(00000D42): sending&lt;br /&gt;006725: Apr 13 14:52:45 WIB: RADIUS(00000D42): Send Accounting-Request to 10.0.100.29:1646 id 1646/64, len 206&lt;br /&gt;006726: Apr 13 14:52:45 WIB: RADIUS:  authenticator D4 A8 64 DC B7 6B 89 1B - C9 D8 3B AF 45 53 03 0D&lt;br /&gt;006727: Apr 13 14:52:45 WIB: RADIUS:  Acct-Session-Id     [44]  10  "00000D79"&lt;br /&gt;006728: Apr 13 14:52:45 WIB: RADIUS:  Framed-Protocol     [7]   6   PPP                       [1]&lt;br /&gt;006729: Apr 13 14:52:45 WIB: RADIUS:  Vendor, Cisco       [26]  13&lt;br /&gt;006730: Apr 13 14:52:45 WIB: RADIUS:   ssg-service-info   [251] 7   "NINET"&lt;br /&gt;006731: Apr 13 14:52:45 WIB: RADIUS:  Vendor, Cisco       [26]  34&lt;br /&gt;006732: Apr 13 14:52:45 WIB: RADIUS:   Cisco AVpair       [1]   28  "parent-session-id=00000D77"&lt;br /&gt;006733: Apr 13 14:52:45 WIB: RADIUS:  User-Name           [1]   11  "pedi128k"&lt;br /&gt;006734: Apr 13 14:52:45 WIB: RADIUS:  Acct-Status-Type    [40]  6   Start                     [1]&lt;br /&gt;006735: Apr 13 14:52:45 WIB: RADIUS:  Framed-IP-Address   [8]   6   30.0.74.1         &lt;br /&gt;006736: Apr 13 14:52:45 WIB: RADIUS:  NAS-Port-Type       [61]  6   Virtual                   [5]&lt;br /&gt;006737: Apr 13 14:52:45 WIB: RADIUS:  NAS-Port-Id         [87]  11  "0/0/3/806"&lt;br /&gt;006738: Apr 13 14:52:45 WIB: RADIUS:  Class               [25]  50&lt;br /&gt;006739: Apr 13 14:52:45 WIB: RADIUS:   53 42 52 2D 43 4C 20 44 4E 3D 22 63 61 62 6C 65  [SBR-CL DN="pedi]&lt;br /&gt;006740: Apr 13 14:52:45 WIB: RADIUS:   31 32 38 6B 22 20 41 54 3D 22 32 30 30 22 20 55  [128k" AT="200" U]&lt;br /&gt;006741: Apr 13 14:52:45 WIB: RADIUS:   53 3D 22 22 20 53 49 3D 22 32 31 35 32 32 22 00   [ S="" SI="21522"]&lt;br /&gt;006742: Apr 13 14:52:45 WIB: RADIUS:  Service-Type        [6]   6   Framed                    [2]&lt;br /&gt;006743: Apr 13 14:52:45 WIB: RADIUS:  NAS-IP-Address      [4]   6   10.0.4.101       &lt;br /&gt;006744: Apr 13 14:52:45 WIB: RADIUS:  Event-Timestamp     [55]  6   1239609165          &lt;br /&gt;006745: Apr 13 14:52:45 WIB: RADIUS:  Nas-Identifier      [32]  9   "ISG-L4R"&lt;br /&gt;006746: Apr 13 14:52:45 WIB: RADIUS:  Acct-Delay-Time     [41]  6   0                   &lt;br /&gt;&lt;br /&gt;(8). Received accounting response from Radius :&lt;br /&gt;&lt;br /&gt;006747: Apr 13 14:52:45 WIB: RADIUS: Received from id 1646/64 10.0.100.29:1646, Accounting-response, len 20&lt;br /&gt;&lt;br /&gt;In the above debug output you can see that there are no Nas-Port send in the user authentication and accounting. It because Nas-Port sending is being disabled.&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------------------------&lt;br /&gt;In this topology I use ip routed session scenario, in this scenario we can see Router (ISG) is sending the &lt;span style="font-style: italic; font-weight: bold;"&gt;Nas-Port value equal to zero&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Here is the sample debug of nas port equal to zero :&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;" class="content"  &gt;&lt;p class="pB1_Body1"&gt;(1). Sending Authentication request to Radius :&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;001672: Apr 13 12:33:27 WIB: RADIUS(00000A4B): Send Access-Request to 10.0.100.29:1645 id 1645/60, len 116&lt;br /&gt;001673: Apr 13 12:33:27 WIB: RADIUS:  authenticator 0A 4D 6D A0 9A 89 A0 E8 - 2D 70 65 89 25 90 2F 3A&lt;br /&gt;001674: Apr 13 12:33:27 WIB: RADIUS:  Framed-IP-Address   [8]   6   30.0.74.1         &lt;br /&gt;001675: Apr 13 12:33:27 WIB: RADIUS:  User-Name           [1]   12  "pedi1024k"&lt;br /&gt;001676: Apr 13 12:33:27 WIB: RADIUS:  User-Password       [2]   18  *&lt;br /&gt;001677: Apr 13 12:33:27 WIB: RADIUS:  NAS-Port-Type       [61]  6   Virtual                   [5]&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;001678: Apr 13 12:33:27 WIB: RADIUS:  &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;NAS-Port            [5]   6   0       &lt;/span&gt;            &lt;br /&gt;001679: Apr 13 12:33:27 WIB: RADIUS:  NAS-Port-Id         [87]  11  "0/0/3/806"&lt;br /&gt;001680: Apr 13 12:33:27 WIB: RADIUS:  Service-Type        [6]   6   Login                     [1]&lt;br /&gt;001681: Apr 13 12:33:27 WIB: RADIUS:  NAS-IP-Address      [4]   6   10.0.4.101       &lt;br /&gt;001682: Apr 13 12:33:27 WIB: RADIUS:  Acct-Session-Id     [44]  10  "00000A4B"&lt;br /&gt;001683: Apr 13 12:33:27 WIB: RADIUS:  Nas-Identifier      [32]  9   "ISG-L4R"&lt;br /&gt;001684: Apr 13 12:33:27 WIB: RADIUS:  Event-Timestamp     [55]  6   1239600807          &lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;(2). Received Authentication Response from Radius :&lt;/p&gt;&lt;p class="pB1_Body1"&gt;001685: Apr 13 12:33:27 WIB: RADIUS: Received from id 1645/60 10.0.100.29:1645, Access-Accept, len 95&lt;br /&gt;001686: Apr 13 12:33:27 WIB: RADIUS:  authenticator 95 38 A5 67 3E 35 7A B2 - 50 AE 7B F8 2B 0B B3 64&lt;br /&gt;001687: Apr 13 12:33:27 WIB: RADIUS:  Class               [25]  51&lt;br /&gt;001688: Apr 13 12:33:27 WIB: RADIUS:   53 42 52 2D 43 4C 20 44 4E 3D 22 63 61 62 6C 65  [SBR-CL DN="pedi]&lt;br /&gt;001689: Apr 13 12:33:27 WIB: RADIUS:   31 30 32 34 6B 22 20 41 54 3D 22 32 30 30 22 20  [1024k" AT="200" ]&lt;br /&gt;001690: Apr 13 12:33:27 WIB: RADIUS:   55 53 3D 22 22 20 53 49 3D 22 32 31 34 38 32 22  [US="" SI="21482"]&lt;br /&gt;001691: Apr 13 12:33:27 WIB: RADIUS:   00&lt;br /&gt;001692: Apr 13 12:33:27 WIB: RADIUS:  Vendor, Unknown     [26]  12&lt;br /&gt;001693: Apr 13 12:33:27 WIB: RADIUS:  Unsupported         [2]   6&lt;br /&gt;001694: Apr 13 12:33:27 WIB: RADIUS:   00 00 00 01&lt;br /&gt;001695: Apr 13 12:33:27 WIB: RADIUS:  Session-Timeout     [27]  6   86400               &lt;br /&gt;001696: Apr 13 12:33:27 WIB: RADIUS:  Idle-Timeout        [28]  6   300                 &lt;br /&gt;001697: Apr 13 12:33:27 WIB: RADIUS(00000A4B): Received from id 1645/60&lt;br /&gt;001698: Apr 13 12:33:27 WIB: RADIUS/ENCODE(00000A4B):Orig. component type = IEDGE_IP_SIP&lt;br /&gt;001699: Apr 13 12:33:27 WIB: RADIUS:  AAA Unsupported Attr: timeout           [371] 4   86400&lt;br /&gt;001700: Apr 13 12:33:27 WIB: RADIUS:  AAA Unsupported Attr: idletime          [123] 4   300&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;(3) Sending Ack response to portal :&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;001701: Apr 13 12:33:27 WIB: RADIUS(00000A4B): sending&lt;br /&gt;001702: Apr 13 12:33:27 WIB: RADIUS(00000A4B): Send CoA Ack Response to 20.0.92.156:32775 id 44, len 71&lt;br /&gt;001703: Apr 13 12:33:27 WIB: RADIUS:  authenticator 67 B9 4E 33 4C D6 D9 B3 - 7B D4 95 75 6B AF F0 95&lt;br /&gt;001704: Apr 13 12:33:27 WIB: RADIUS:  Vendor, Cisco       [26]  19&lt;br /&gt;001705: Apr 13 12:33:27 WIB: RADIUS:   ssg-command-code   [252] 13&lt;br /&gt;001706: Apr 13 12:33:27 WIB: RADIUS:   01 63 61 62 6C 65 31 30 32 34 6B        [Account-Log-On cable1024k]&lt;br /&gt;001707: Apr 13 12:33:27 WIB: RADIUS:  Vendor, Cisco       [26]  20&lt;br /&gt;001708: Apr 13 12:33:27 WIB: RADIUS:   ssg-account-info   [250] 14  "S30.0.74.1"&lt;br /&gt;001709: Apr 13 12:33:27 WIB: RADIUS:  Session-Timeout     [27]  6   86400               &lt;br /&gt;001710: Apr 13 12:33:27 WIB: RADIUS:  Idle-Timeout        [28]  6   300                 &lt;br /&gt;001711: Apr 13 12:33:27 WIB: RADIUS/ENCODE(00000A4B):Orig. component type = IEDGE_IP_SIP&lt;br /&gt;001712: Apr 13 12:33:27 WIB: RADIUS(00000A4B): Config NAS IP: 10.0.4.101&lt;br /&gt;001713: Apr 13 12:33:27 WIB: RADIUS(00000A4B): Config NAS IP: 10.0.4.101&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;(4). Sending Accounting request to Radius :&lt;/p&gt;&lt;p class="pB1_Body1"&gt;001714: Apr 13 12:33:27 WIB: RADIUS(00000A4B): sending&lt;br /&gt;001715: Apr 13 12:33:27 WIB: RADIUS(00000A4B): Send Accounting-Request to 10.0.100.29:1646 id 1646/11, len 214&lt;br /&gt;001716: Apr 13 12:33:27 WIB: RADIUS:  authenticator 2C 90 A8 7A 46 99 3C 70 - BE 6D F7 25 21 19 4F C9&lt;br /&gt;001717: Apr 13 12:33:27 WIB: RADIUS:  Acct-Session-Id     [44]  10  "00000A4F"&lt;br /&gt;001718: Apr 13 12:33:27 WIB: RADIUS:  Framed-Protocol     [7]   6   PPP                       [1]&lt;br /&gt;001719: Apr 13 12:33:27 WIB: RADIUS:  Vendor, Cisco       [26]  13&lt;br /&gt;001720: Apr 13 12:33:27 WIB: RADIUS:   ssg-service-info   [251] 7   "NINET"&lt;br /&gt;001721: Apr 13 12:33:27 WIB: RADIUS:  Vendor, Cisco       [26]  34&lt;br /&gt;001722: Apr 13 12:33:27 WIB: RADIUS:   Cisco AVpair       [1]   28  "parent-session-id=00000A4B"&lt;br /&gt;001723: Apr 13 12:33:27 WIB: RADIUS:  User-Name           [1]   12  "pedi1024k"&lt;br /&gt;001724: Apr 13 12:33:27 WIB: RADIUS:  Acct-Status-Type    [40]  6   Start                     [1]&lt;br /&gt;001725: Apr 13 12:33:27 WIB: RADIUS:  Framed-IP-Address   [8]   6   30.0.74.1         &lt;br /&gt;001726: Apr 13 12:33:27 WIB: RADIUS:  NAS-Port-Type       [61]  6   Virtual                   [5]&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;001727: Apr 13 12:33:27 WIB: RADIUS:  &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;NAS-Port            [5]   6   0              &lt;/span&gt;     &lt;br /&gt;001728: Apr 13 12:33:27 WIB: RADIUS:  NAS-Port-Id         [87]  11  "0/0/3/806"&lt;br /&gt;001729: Apr 13 12:33:27 WIB: RADIUS:  Class               [25]  51&lt;br /&gt;001730: Apr 13 12:33:27 WIB: RADIUS:   53 42 52 2D 43 4C 20 44 4E 3D 22 63 61 62 6C 65  [SBR-CL DN="pedi]&lt;br /&gt;001731: Apr 13 12:33:27 WIB: RADIUS:   31 30 32 34 6B 22 20 41 54 3D 22 32 30 30 22 20  [1024k" AT="200" ]&lt;br /&gt;001732: Apr 13 12:33:27 WIB: RADIUS:   55 53 3D 22 22 20 53 49 3D 22 32 31 34 38 32 22  [US="" SI="21482"]&lt;br /&gt;001733: Apr 13 12:33:27 WIB: RADIUS:   00&lt;br /&gt;001734: Apr 13 12:33:27 WIB: RADIUS:  Service-Type        [6]   6   Framed                    [2]&lt;br /&gt;001735: Apr 13 12:33:27 WIB: RADIUS:  NAS-IP-Address      [4]   6   10.0.4.101       &lt;br /&gt;001736: Apr 13 12:33:27 WIB: RADIUS:  Event-Timestamp     [55]  6   1239600807          &lt;br /&gt;001737: Apr 13 12:33:27 WIB: RADIUS:  Nas-Identifier      [32]  9   "ISG-L4R"&lt;br /&gt;001738: Apr 13 12:33:27 WIB: RADIUS:  Acct-Delay-Time     [41]  6   0                   &lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;(4). Received Accounting Response from Radius :&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;001739: Apr 13 12:33:28 WIB: RADIUS: Received from id 1646/11 10.0.100.29:1646, Accounting-response, len 20&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;-----------------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;/p&gt;&lt;p class="pB1_Body1"&gt;And if you want to make nas-port not equal to zero, you can use extended Nas-port support.&lt;/p&gt;&lt;p class="pB1_Body1"&gt;Configuration :&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;aaa group server radius AAA&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;server 10.0.100.29 auth-port 1645 acct-port 1646&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;ip radius source-interface GigabitEthernet0/3.806&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;attribute nas-port format e UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;deadtime 10&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;and the result will be like this :&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;(1). User login at portal :&lt;br /&gt;&lt;br /&gt;007259: Apr 13 15:07:39 WIB: RADIUS: COA  received from id 122 20.0.92.156:32775, CoA Request, len 95&lt;br /&gt;007260: Apr 13 15:07:39 WIB: RADIUS/DECODE: VSA external len != internal + VSA hdr&lt;br /&gt;007261: Apr 13 15:07:39 WIB: RADIUS/ENCODE(00000D81):Orig. component type = IEDGE_IP_SIP&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;007262: Apr 13 15:07:39 WIB: RADIUS: Format E value 0xDBD for character U with bitmask 0xFFFFFFFF&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;007263: Apr 13 15:07:39 WIB: RADIUS: Format E port 0xDBD with bit 32 processed&lt;/span&gt;&lt;br /&gt;007264: Apr 13 15:07:39 WIB: RADIUS(00000D81): Config NAS IP: 10.0.4.101&lt;br /&gt;007265: Apr 13 15:07:39 WIB: RADIUS/ENCODE(00000D81): acct_session_id: 3517&lt;br /&gt;007266: Apr 13 15:07:39 WIB: RADIUS(00000D81): Config NAS IP: 10.0.4.101&lt;br /&gt;007267: Apr 13 15:07:39 WIB: RADIUS(00000D81): sending&lt;br /&gt;&lt;br /&gt;(2). Sending Authentication Request to Radius :&lt;br /&gt;&lt;br /&gt;007268: Apr 13 15:07:39 WIB: RADIUS(00000D81): Send Access-Request to 10.0.100.29:1645 id 1645/158, len 116&lt;br /&gt;007269: Apr 13 15:07:39 WIB: RADIUS:  authenticator 89 50 7C 69 43 3C D1 EE - 65 30 C4 22 B1 6A 38 65&lt;br /&gt;007270: Apr 13 15:07:39 WIB: RADIUS:  Framed-IP-Address   [8]   6   30.0.74.3         &lt;br /&gt;007271: Apr 13 15:07:39 WIB: RADIUS:  User-Name           [1]   12  "pedi1024k"&lt;br /&gt;007272: Apr 13 15:07:39 WIB: RADIUS:  User-Password       [2]   18  *&lt;br /&gt;007273: Apr 13 15:07:39 WIB: RADIUS:  NAS-Port-Type       [61]  6   Ethernet                  [15]&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;007274: Apr 13 15:07:39 WIB: RADIUS:  NAS-Port            [5]   6   3517                     &lt;/span&gt;&lt;br /&gt;007275: Apr 13 15:07:39 WIB: RADIUS:  NAS-Port-Id         [87]  11  "0/0/3/806"&lt;br /&gt;007276: Apr 13 15:07:39 WIB: RADIUS:  Service-Type        [6]   6   Login                     [1]&lt;br /&gt;007277: Apr 13 15:07:39 WIB: RADIUS:  NAS-IP-Address      [4]   6   10.0.4.101       &lt;br /&gt;007278: Apr 13 15:07:39 WIB: RADIUS:  Acct-Session-Id     [44]  10  "00000DBD"&lt;br /&gt;007279: Apr 13 15:07:39 WIB: RADIUS:  Nas-Identifier      [32]  9   "ISG-L4R"&lt;br /&gt;007280: Apr 13 15:07:39 WIB: RADIUS:  Event-Timestamp     [55]  6   1239610059          &lt;br /&gt;&lt;br /&gt;(3). Received Response from Radius :&lt;br /&gt;&lt;br /&gt;007281: Apr 13 15:07:39 WIB: RADIUS: Received from id 1645/158 10.0.100.29:1645, Access-Accept, len 95&lt;br /&gt;007282: Apr 13 15:07:39 WIB: RADIUS:  authenticator E3 22 CC 82 6E 49 F3 20 - 9C 20 5E CE 7D B9 EF 45&lt;br /&gt;007283: Apr 13 15:07:39 WIB: RADIUS:  Class               [25]  51&lt;br /&gt;007284: Apr 13 15:07:39 WIB: RADIUS:   53 42 52 2D 43 4C 20 44 4E 3D 22 63 61 62 6C 65  [SBR-CL DN="pedi]&lt;br /&gt;007285: Apr 13 15:07:39 WIB: RADIUS:   31 30 32 34 6B 22 20 41 54 3D 22 32 30 30 22 20  [1024k" AT="200" ]&lt;br /&gt;007286: Apr 13 15:07:39 WIB: RADIUS:   55 53 3D 22 22 20 53 49 3D 22 32 31 35 32 35 22  [US="" SI="21525"]&lt;br /&gt;007287: Apr 13 15:07:39 WIB: RADIUS:   00&lt;br /&gt;007288: Apr 13 15:07:39 WIB: RADIUS:  Vendor, Unknown     [26]  12&lt;br /&gt;007289: Apr 13 15:07:39 WIB: RADIUS:  Unsupported         [2]   6&lt;br /&gt;007290: Apr 13 15:07:39 WIB: RADIUS:   00 00 00 01&lt;br /&gt;007291: Apr 13 15:07:39 WIB: RADIUS:  Session-Timeout     [27]  6   86400               &lt;br /&gt;007292: Apr 13 15:07:39 WIB: RADIUS:  Idle-Timeout        [28]  6   300                 &lt;br /&gt;007293: Apr 13 15:07:39 WIB: RADIUS(00000D81): Received from id 1645/158&lt;br /&gt;007294: Apr 13 15:07:39 WIB: RADIUS/ENCODE(00000D81):Orig. component type = IEDGE_IP_SIP&lt;br /&gt;007295: Apr 13 15:07:39 WIB: RADIUS:  AAA Unsupported Attr: timeout           [371] 4   86400&lt;br /&gt;007296: Apr 13 15:07:39 WIB: RADIUS:  AAA Unsupported Attr: idletime          [123] 4   300&lt;br /&gt;&lt;br /&gt;(4). Sending Ack response to portal :&lt;br /&gt;&lt;br /&gt;007297: Apr 13 15:07:39 WIB: RADIUS(00000D81): sending&lt;br /&gt;007298: Apr 13 15:07:39 WIB: RADIUS(00000D81): Send CoA Ack Response to 20.0.92.156:32775 id 122, len 71&lt;br /&gt;007299: Apr 13 15:07:39 WIB: RADIUS:  authenticator D0 0B D7 83 04 4F 32 6A - 87 17 3C 62 0D 1E 25 64&lt;br /&gt;007300: Apr 13 15:07:39 WIB: RADIUS:  Vendor, Cisco       [26]  19&lt;br /&gt;007301: Apr 13 15:07:39 WIB: RADIUS:   ssg-command-code   [252] 13&lt;br /&gt;007302: Apr 13 15:07:39 WIB: RADIUS:   01 63 61 62 6C 65 31 30 32 34 6B        [Account-Log-On pedi1024k]&lt;br /&gt;007303: Apr 13 15:07:39 WIB: RADIUS:  Vendor, Cisco       [26]  20&lt;br /&gt;007304: Apr 13 15:07:39 WIB: RADIUS:   ssg-account-info   [250] 14  "S30.0.74.3"&lt;br /&gt;007305: Apr 13 15:07:39 WIB: RADIUS:  Session-Timeout     [27]  6   86400               &lt;br /&gt;007306: Apr 13 15:07:39 WIB: RADIUS:  Idle-Timeout        [28]  6   300                 &lt;br /&gt;007307: Apr 13 15:07:39 WIB: RADIUS/ENCODE(00000D81):Orig. component type = IEDGE_IP_SIP&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;007308: Apr 13 15:07:39 WIB: RADIUS: Format E value 0xDBD for character U with bitmask 0xFFFFFFFF&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;007309: Apr 13 15:07:39 WIB: RADIUS: Format E port 0xDBD with bit 32 processed&lt;/span&gt;&lt;br /&gt;007310: Apr 13 15:07:39 WIB: RADIUS(00000D81): Config NAS IP: 10.0.4.101&lt;br /&gt;007311: Apr 13 15:07:39 WIB: RADIUS(00000D81): Config NAS IP: 10.0.4.101&lt;br /&gt;007312: Apr 13 15:07:39 WIB: RADIUS(00000D81): sending&lt;br /&gt;&lt;br /&gt;(5). Sending Accounting Request to Radius :&lt;br /&gt;&lt;br /&gt;007313: Apr 13 15:07:39 WIB: RADIUS(00000D81): Send Accounting-Request to 10.0.100.29:1646 id 1646/72, len 214&lt;br /&gt;007314: Apr 13 15:07:39 WIB: RADIUS:  authenticator 0B 51 C5 1E 61 E2 2F 15 - E2 8A 31 51 10 86 5E 63&lt;br /&gt;007315: Apr 13 15:07:39 WIB: RADIUS:  Acct-Session-Id     [44]  10  "00000DBF"&lt;br /&gt;007316: Apr 13 15:07:39 WIB: RADIUS:  Framed-Protocol     [7]   6   PPP                       [1]&lt;br /&gt;007317: Apr 13 15:07:39 WIB: RADIUS:  Vendor, Cisco       [26]  13&lt;br /&gt;007318: Apr 13 15:07:39 WIB: RADIUS:   ssg-service-info   [251] 7   "NINET"&lt;br /&gt;007319: Apr 13 15:07:39 WIB: RADIUS:  Vendor, Cisco       [26]  34&lt;br /&gt;007320: Apr 13 15:07:39 WIB: RADIUS:   Cisco AVpair       [1]   28  "parent-session-id=00000DBD"&lt;br /&gt;007321: Apr 13 15:07:39 WIB: RADIUS:  User-Name           [1]   12  "pedi1024k"&lt;br /&gt;007322: Apr 13 15:07:39 WIB: RADIUS:  Acct-Status-Type    [40]  6   Start                     [1]&lt;br /&gt;007323: Apr 13 15:07:39 WIB: RADIUS:  Framed-IP-Address   [8]   6   30.0.74.3         &lt;br /&gt;007324: Apr 13 15:07:39 WIB: RADIUS:  NAS-Port-Type       [61]  6   Ethernet                  [15]&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;007325: Apr 13 15:07:39 WIB: RADIUS:  NAS-Port            [5]   6   3517                     &lt;/span&gt;&lt;br /&gt;007326: Apr 13 15:07:39 WIB: RADIUS:  NAS-Port-Id         [87]  11  "0/0/3/806"&lt;br /&gt;007327: Apr 13 15:07:39 WIB: RADIUS:  Class               [25]  51&lt;br /&gt;007328: Apr 13 15:07:39 WIB: RADIUS:   53 42 52 2D 43 4C 20 44 4E 3D 22 63 61 62 6C 65  [SBR-CL DN="pedi]&lt;br /&gt;007329: Apr 13 15:07:39 WIB: RADIUS:   31 30 32 34 6B 22 20 41 54 3D 22 32 30 30 22 20  [1024k" AT="200" ]&lt;br /&gt;007330: Apr 13 15:07:39 WIB: RADIUS:   55 53 3D 22 22 20 53 49 3D 22 32 31 35 32 35 22  [US="" SI="21525"]&lt;br /&gt;007331: Apr 13 15:07:39 WIB: RADIUS:   00&lt;br /&gt;007332: Apr 13 15:07:39 WIB: RADIUS:  Service-Type        [6]   6   Framed                    [2]&lt;br /&gt;007333: Apr 13 15:07:39 WIB: RADIUS:  NAS-IP-Address      [4]   6   10.0.4.101       &lt;br /&gt;007334: Apr 13 15:07:39 WIB: RADIUS:  Event-Timestamp     [55]  6   1239610059          &lt;br /&gt;007335: Apr 13 15:07:39 WIB: RADIUS:  Nas-Identifier      [32]  9   "ISG-L4R"&lt;br /&gt;007336: Apr 13 15:07:39 WIB: RADIUS:  Acct-Delay-Time     [41]  6   0                   &lt;br /&gt;&lt;br /&gt;(6). Received Accounting Response from Radius :&lt;br /&gt;&lt;br /&gt;007337: Apr 13 15:07:39 WIB: RADIUS: Received from id 1646/72 10.0.100.29:1646, Accounting-response, len 20&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;In the above configuration is using format 'e' Nas-Port, format e is customized instead of format a to c, it is developed because not all off format are supported in the new cisco platform.&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;What i'm using  in the configruration for the format nas-port is session id "U"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Radius-server attribute nas-port format&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;table  style="color: rgb(128, 128, 128);font-family:trebuchet ms;" id="wp1096012table1096010" width="80%" border="1" cellpadding="2" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr valign="top" align="left"&gt;&lt;td&gt;&lt;p class="pB1_Body1"&gt;&lt;span style="font-size:100%;"&gt; Session ID &lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td&gt;&lt;span style="font-size:100%;"&gt;&lt;a name="wp1096086"&gt;&lt;/a&gt;&lt;/span&gt;&lt;p class="pB1_Body1"&gt;&lt;span style="font-size:100%;"&gt; U &lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The value of session-id (hexadecimal) is  converted to nas-port value (decimal)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Here is the result :&lt;/span&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;007320: Apr 13 15:07:39 WIB: RADIUS:   Cisco AVpair       [1]   28  "parent-session-id=&lt;span style="font-weight: bold;"&gt;00000DBD&lt;/span&gt;"&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;span style="font-weight: bold;"&gt;Ox 00000DBD&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; = 3517&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;You can find the detail from this cisco site&lt;br /&gt;&lt;br /&gt;http://www.cisco.com/en/US/docs/ios/12_2sb/feature/guide/rd_naspt.html&lt;br /&gt;&lt;/span&gt;</description><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Passed Routing &amp;amp; Swiching CCIE</title><link>http://ccieobsessed.blogspot.com/2009/04/passed-ccie.html</link><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Fri, 3 Apr 2009 14:50:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-6423969691848990716</guid><description>&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Finnaly I passed my CCIE Routing &amp;amp; Switching exam at Sydney 26 November 2008.  Thanks to my wife, friends, My Boss who support me to take this exam. It was very long journey, spent much time to exercise. At the end i'm very happy to be a CCIE. Next I will take another track or another exam. :)&lt;/span&gt;&lt;/span&gt;</description><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Buy another quad ethernet port</title><link>http://ccieobsessed.blogspot.com/2008/07/buy-another-quad-ethernet-port.html</link><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Tue, 15 Jul 2008 19:29:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-8460031342164597835</guid><description>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;Today I bought another Quad ethernet port to complete all what I need for My Lab. Tommorow I will have finished my lab connections. Now I will prepare the .net file for IE scenario. :) , Can't wait to see this lab completely  build.&lt;/span&gt;</description><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Wondering to build advance dynamips lab</title><link>http://ccieobsessed.blogspot.com/2008/07/wondering-to-build-advance-dynamips-lab.html</link><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Mon, 14 Jul 2008 23:17:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-3843067281235383912</guid><description>&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt;Finished with 8 labs scenario from dynamips IE workbooks and wondering how to build a real lab with dynamips and some switches. Can I make a real lab with dynamips and switch?? yes, I found someone in the forum has already tried with this perfect combination (&lt;a class="maintitle" href="http://7200emu.hacki.at/viewtopic.php?t=2754&amp;amp;start=0&amp;amp;postdays=0&amp;amp;postorder=asc&amp;amp;highlight=&amp;amp;sid=6bf8fe3601e9b761bdfedc800838e6ae"&gt;Passed CCIE Lab, thanks to Dynamips).&lt;/a&gt; Using new server from my office, I borrow 4 switches from my friend in my office and try to install them in the rack with the server. After that I buy a quad port ethernet and install to the server.&lt;/span&gt;</description><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Preparing CCIE study material &amp; what's on CCIE</title><link>http://ccieobsessed.blogspot.com/2008/07/preparing-what-to-has-to-prepare.html</link><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Mon, 14 Jul 2008 22:50:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-7052388991688117000</guid><description>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;First, see what's on ccie. A Blue print of ccie lab exam from cisco.com, know what is covered by ccie lab exam. Join groupstudy, to know experiences from people who are working with some preparations and having some difficulties with what they are facing to the problem while they're studying or taking the real lab exam, finding out how to solve the problem.&lt;br /&gt;&lt;br /&gt;Watch CoD from IE and try IEWB scenario step by step, it is very helpful to know and give me very deep understanding about the underlying and the advance technology in ccie lab. There are some good strategy and tips to help in the day of the exam.&lt;/span&gt;</description><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><title>Start to make my own lab</title><link>http://ccieobsessed.blogspot.com/2008/07/starting-to-make-my-own-lab.html</link><author>noreply@blogger.com (Ahmad Fadly Abbas)</author><pubDate>Mon, 14 Jul 2008 22:22:00 +0700</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1547438151139198241.post-2191350184134623470</guid><description>&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Start from making dynamips run in my macbook last year, I could make my 1st dynamips lab in my laptop, it was quite easy to setup good but not powerful enough to build 13 routers with 2GHz processor and 2 G of memory. Tried to do some practice lab refer  to workbook and CoD in my spare time, because i wasn't very serious taking ccie lab in the near time. A year after I though I had to go for pursuing the ccie, why ?? because lots of people and some of my friends pursuing it and study very hard. Now they have got their number (congratulations). My dream is to get ccie in the first attempt, hope so :D&lt;/span&gt;&lt;/span&gt;</description><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item></channel></rss>