Баг MPD 5.6 + vlan + radius

Технические вопросы по UTM 5.0
Ответить
Аватара пользователя
ZeM
Сообщения: 371
Зарегистрирован: Чт фев 17, 2011 08:38

Баг MPD 5.6 + vlan + radius

Сообщение ZeM »

Исходные данные интерфейсы

Код: Выделить всё

igb1&#58; flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
        options=400b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,VLAN_HWTSO>
        ether 00&#58;1b&#58;21&#58;67&#58;81&#58;89
        media&#58; Ethernet autoselect &#40;1000baseT <full-duplex>&#41;
        status&#58; active
pflog0&#58; flags=0<> metric 0 mtu 33152
pfsync0&#58; flags=0<> metric 0 mtu 1500
        syncpeer&#58; 0.0.0.0 maxupd&#58; 128
ipfw0&#58; flags=8801<UP,SIMPLEX,MULTICAST> metric 0 mtu 65536
lo0&#58; flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
        options=3<RXCSUM,TXCSUM>
        inet 127.0.0.1 netmask 0xff000000
vlan200&#58; flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
        ether 00&#58;1b&#58;21&#58;67&#58;81&#58;89
        inet 172.28.200.12 netmask 0xffffff00 broadcast 172.28.200.255
        inet 172.28.200.50 netmask 0xffffff00 broadcast 172.28.200.255
        media&#58; Ethernet autoselect &#40;1000baseT <full-duplex>&#41;
        status&#58; active
        vlan&#58; 200 parent interface&#58; igb1
vlan100&#58; flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
        ether 00&#58;1b&#58;21&#58;67&#58;81&#58;89
        inet 172.28.100.251 netmask 0xffffff00 broadcast 172.28.100.255
        media&#58; Ethernet autoselect &#40;1000baseT <full-duplex>&#41;
        status&#58; active
        vlan&#58; 100 parent interface&#58; igb1
Показания tcpdump

Код: Выделить всё

NAT_new# tcpdump -n -i vlan100 -p -s 1500 udp port 1812
tcpdump&#58; verbose output suppressed, use -v or -vv for full protocol decode
listening on vlan100, link-type EN10MB &#40;Ethernet&#41;, capture size 1500 bytes
^C
0 packets captured
24 packets received by filter
0 packets dropped by kernel
NAT_new# tcpdump -n -i vlan200 -p -s 1500 udp port 1812
tcpdump&#58; verbose output suppressed, use -v or -vv for full protocol decode
listening on vlan200, link-type EN10MB &#40;Ethernet&#41;, capture size 1500 bytes
^C
0 packets captured
221 packets received by filter
0 packets dropped by kernel
NAT_new# tcpdump -n -i vlan100 -p -s 1500 udp port 1813
tcpdump&#58; verbose output suppressed, use -v or -vv for full protocol decode
listening on vlan100, link-type EN10MB &#40;Ethernet&#41;, capture size 1500 bytes
10&#58;31&#58;13.775245 IP 172.28.100.251.55774 > 172.28.100.4.1813&#58; RADIUS, Accounting Request &#40;4&#41;, id&#58; 0xa9 length&#58; 242
10&#58;31&#58;23.775567 IP 172.28.100.251.55774 > 172.28.100.4.1813&#58; RADIUS, Accounting Request &#40;4&#41;, id&#58; 0xa9 length&#58; 242
10&#58;31&#58;33.776707 IP 172.28.100.251.55774 > 172.28.100.4.1813&#58; RADIUS, Accounting Request &#40;4&#41;, id&#58; 0xa9 length&#58; 242
10&#58;31&#58;43.777890 IP 172.28.100.251.13974 > 172.28.100.4.1813&#58; RADIUS, Accounting Request &#40;4&#41;, id&#58; 0xd5 length&#58; 374
10&#58;31&#58;43.778813 IP 172.28.100.4.1813 > 172.28.100.251.13974&#58; RADIUS, Accounting Response &#40;5&#41;, id&#58; 0xd5 length&#58; 20
^C
5 packets captured
74 packets received by filter
0 packets dropped by kernel
Лог mpd5 v5.6

Код: Выделить всё

Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; Incoming L2TP packet from 172.20.254.26 1701
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; L2TP&#58; Control connection 0x802be7610 172.28.200.12 1701 <-> 172.20.254.26 1701 accepted
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; L2TP&#58; Control connection 0x802be7610 172.28.200.12 1701 <-> 172.20.254.26 1701 connected
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; L2TP&#58; Incoming call #0 via connection 0x802be7610 received
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; L2TP&#58; Incoming call #0 via control connection 0x802be7610 accepted
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; Link&#58; OPEN event
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; Open event
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; state change Initial --> Starting
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; LayerStart
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; device&#58; OPEN event
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; L2tpOpen&#40;&#41; on incoming call
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; L2TP&#58; Call #0 connected
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; device&#58; UP event
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; Link&#58; UP event
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; Link&#58; origination is remote
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; Up event
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; state change Starting --> Req-Sent
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; SendConfigReq #1
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   ACFCOMP
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   PROTOCOMP
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MRU 1500
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MAGICNUM a303c198
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MP MRRU 2048
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MP SHORTSEQ
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   ENDPOINTDISC &#91;802.1&#93; 00 1b 21 67 81 88
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; rec'd Configure Request #0 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MRU 1400
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MAGICNUM 47081140
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   PROTOCOMP
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   ACFCOMP
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   CALLBACK 6
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MP MRRU 1614
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   ENDPOINTDISC &#91;LOCAL&#93; 99 09 11 42 43 6a 4f 50 89 9a 22 fe 29 01 62 79 00 00 0
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; SendConfigRej #0
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   CALLBACK 6
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; rec'd Configure Request #1 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MRU 1400
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MAGICNUM 47081140
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   PROTOCOMP
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   ACFCOMP
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MP MRRU 1614
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   ENDPOINTDISC &#91;LOCAL&#93; 99 09 11 42 43 6a 4f 50 89 9a 22 fe 29 01 62 79 00 00 0
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; SendConfigAck #1
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MRU 1400
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MAGICNUM 47081140
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   PROTOCOMP
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   ACFCOMP
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   MP MRRU 1614
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93;   ENDPOINTDISC &#91;LOCAL&#93; 99 09 11 42 43 6a 4f 50 89 9a 22 fe 29 01 62 79 00 00 0
Nov 21 10&#58;34&#58;18 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; state change Req-Sent --> Ack-Sent
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; SendConfigReq #2
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   ACFCOMP
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   PROTOCOMP
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MRU 1500
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MAGICNUM a303c198
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MP MRRU 2048
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MP SHORTSEQ
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   ENDPOINTDISC &#91;802.1&#93; 00 1b 21 67 81 88
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; rec'd Configure Reject #2 &#40;Ack-Sent&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MP SHORTSEQ
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; SendConfigReq #3
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   ACFCOMP
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   PROTOCOMP
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MRU 1500
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MAGICNUM a303c198
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MP MRRU 2048
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   ENDPOINTDISC &#91;802.1&#93; 00 1b 21 67 81 88
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; rec'd Configure Ack #3 &#40;Ack-Sent&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   ACFCOMP
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   PROTOCOMP
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MRU 1500
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MAGICNUM a303c198
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MP MRRU 2048
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   ENDPOINTDISC &#91;802.1&#93; 00 1b 21 67 81 88
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; state change Ack-Sent --> Opened
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; auth&#58; peer wants nothing, I want nothing
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; authorization successful
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; Link&#58; Matched action 'bundle "B" ""'
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; Creating new bundle using template "B".
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; Bundle&#58; Interface ng0 created
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; Link&#58; Join bundle "B-2"
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; Bundle&#58; Status update&#58; up 1 link, total bandwidth 64000 bps
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; Open event
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; state change Initial --> Starting
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; LayerStart
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; Open event
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; state change Initial --> Starting
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; LayerStart
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; Up event
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; Got IP 10.100.1.2 from pool "pool1" for peer
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; state change Starting --> Req-Sent
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; SendConfigReq #1
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   IPADDR 10.100.1.1
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; Up event
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; state change Starting --> Req-Sent
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #1
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; RADIUS&#58; Accounting user '' &#40;Type&#58; 1&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; LayerUp
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; rec'd Ident #2 &#40;Opened&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MESG&#58; MSRASV5.20
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; rec'd Ident #3 &#40;Opened&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MESG&#58; MSRAS-0-ZEM-PC
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; rec'd Ident #4 &#40;Opened&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;L-2&#93;   MESG&#58; M-^HM-^@3Ј^UоM-^ZEM-^WeM-^^^S^FА\з
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Configure Request #5 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   MPPC
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;     0x01000001&#58;MPPC, stateless
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigRej #5
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   MPPC
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;     0x01000001&#58;MPPC, stateless
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; rec'd Configure Request #6 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   IPADDR 0.0.0.0
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;     NAKing with 10.100.1.2
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   PRIDNS 0.0.0.0
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;     NAKing with 109.197.112.254
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   PRINBNS 0.0.0.0
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   SECDNS 0.0.0.0
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;     NAKing with 109.197.113.254
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   SECNBNS 0.0.0.0
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; SendConfigRej #6
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   PRINBNS 0.0.0.0
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   SECNBNS 0.0.0.0
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; rec'd Configure Ack #1 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   IPADDR 10.100.1.1
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; state change Req-Sent --> Ack-Rcvd
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Configure Ack #1 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; state change Req-Sent --> Ack-Rcvd
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Request #7 &#40;Ack-Rcvd&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; state change Ack-Rcvd --> Req-Sent
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendTerminateAck #2
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; rec'd Configure Request #8 &#40;Ack-Rcvd&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   IPADDR 0.0.0.0
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;     NAKing with 10.100.1.2
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   PRIDNS 0.0.0.0
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;     NAKing with 109.197.112.254
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   SECDNS 0.0.0.0
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;     NAKing with 109.197.113.254
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; SendConfigNak #8
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   IPADDR 10.100.1.2
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   PRIDNS 109.197.112.254
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   SECDNS 109.197.113.254
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; rec'd Configure Request #9 &#40;Ack-Rcvd&#41;
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   IPADDR 10.100.1.2
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;     10.100.1.2 is OK
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   PRIDNS 109.197.112.254
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   SECDNS 109.197.113.254
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; SendConfigAck #9
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   IPADDR 10.100.1.2
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   PRIDNS 109.197.112.254
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   SECDNS 109.197.113.254
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; state change Ack-Rcvd --> Opened
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; LayerUp
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93;   10.100.1.1 -> 10.100.1.2
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IFACE&#58; No interface to proxy arp on for 10.100.1.2
Nov 21 10&#58;34&#58;20 NAT_new mpd&#58; &#91;B-2&#93; IFACE&#58; Up event
Nov 21 10&#58;34&#58;22 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Request #10 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;22 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendTerminateAck #3
Nov 21 10&#58;34&#58;22 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #4
Nov 21 10&#58;34&#58;24 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #5
Nov 21 10&#58;34&#58;24 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Ack #5 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;26 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #6
Nov 21 10&#58;34&#58;26 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Ack #6 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;28 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #7
Nov 21 10&#58;34&#58;28 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Ack #7 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;30 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #8
Nov 21 10&#58;34&#58;30 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Ack #8 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;32 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #9
Nov 21 10&#58;34&#58;32 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Ack #9 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;34 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #10
Nov 21 10&#58;34&#58;34 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Ack #10 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;36 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #11
Nov 21 10&#58;34&#58;36 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Ack #11 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;38 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #12
Nov 21 10&#58;34&#58;38 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Ack #12 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;40 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; SendConfigReq #13
Nov 21 10&#58;34&#58;40 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; rec'd Terminate Ack #13 &#40;Req-Sent&#41;
Nov 21 10&#58;34&#58;42 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; parameter negotiation failed
Nov 21 10&#58;34&#58;42 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; state change Req-Sent --> Stopped
Nov 21 10&#58;34&#58;42 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; LayerFinish
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; RADIUS&#58; rad_send_request for user '' failed&#58; No valid RADIUS responses received
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; ACCT&#58; Close link due to accounting start error
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; ACCT&#58; Link close requested by the accounting
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; Link&#58; CLOSE event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; Close event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; state change Opened --> Closing
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; Link&#58; Leave bundle "B-2"
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; RADIUS&#58; Accounting user '' &#40;Type&#58; 2&#41;
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; Bundle&#58; Status update&#58; up 0 links, total bandwidth 9600 bps
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; Close event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; state change Opened --> Closing
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; SendTerminateReq #2
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; LayerDown
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; IFACE&#58; Down event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; Close event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; state change Stopped --> Closed
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; Down event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; LayerFinish
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; Bundle&#58; No NCPs left. Closing links...
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; IPCP&#58; state change Closing --> Initial
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; Down event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; CCP&#58; state change Closed --> Initial
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;B-2&#93; Bundle&#58; Shutdown
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; SendTerminateReq #4
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; LayerDown
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; rec'd Terminate Ack #4 &#40;Closing&#41;
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; state change Closing --> Closed
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; LayerFinish
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; device&#58; CLOSE event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; L2TP&#58; Call #0 terminated locally
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; device&#58; DOWN event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; Link&#58; DOWN event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; Down event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; LCP&#58; state change Closed --> Initial
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; RADIUS&#58; Rec'd RAD_ACCOUNTING_RESPONSE for user ''
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; Link&#58; SHUTDOWN event
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; &#91;L-2&#93; Link&#58; Shutdown
Nov 21 10&#58;34&#58;50 NAT_new mpd&#58; L2TP&#58; Control connection 0x802be7610 terminated&#58; 0 &#40;&#41;
Логи в UTM radius_main.log

Код: Выделить всё

ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find login <>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find login <>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; No data for login&#58; 
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 AcctServer&#58; Error! &#40;2&#41;
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find login <>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find login <>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; No data for login&#58; 
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 AcctServer&#58; Error! &#40;2&#41;
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find login <>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find login <>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; No data for login&#58; 
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 AcctServer&#58; Error! &#40;2&#41;
 Warn  &#58; Nov 21 10&#58;35&#58;55 f71ceb90 RADIUS DBA&#58; Sending bare packet
Файл radius_debug.log

Код: Выделить всё

?Debug &#58; Nov 21 10&#58;35&#58;08 f5bcab90 RADIUS Stream&#91;plugin&#93;&#58; Ping reply received
?Debug &#58; Nov 21 10&#58;35&#58;25 f5ccbb90 RadiusSocket&#58; RADIUS packet successfully received
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RadiusSocket&#58; RADIUS raw data obtained
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS Packet&#58; Size <242>; HDR.Size <242>
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 AcctServer&#58; Recv...
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 AcctServer&#58; Packet from <172.28.100.251> packet dump&#58; RPacket&#58;
Code&#58; 4; ID&#58; 212
<Vendor&#58; 0; Attr&#58; 1>&#91;0&#93;&#58; 
<Vendor&#58; 0; Attr&#58; 5>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 6>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 7>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 8>&#91;4&#93;&#58; 0a640102
<Vendor&#58; 0; Attr&#58; 30>&#91;0&#93;&#58; 
<Vendor&#58; 0; Attr&#58; 31>&#91;13&#93;&#58; 3137322e32302e3235342e3236
<Vendor&#58; 0; Attr&#58; 32>&#91;7&#93;&#58; 4e41545f6e6577
<Vendor&#58; 0; Attr&#58; 40>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 44>&#91;11&#93;&#58; 333439343036302d4c2d32
<Vendor&#58; 0; Attr&#58; 45>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 50>&#91;11&#93;&#58; 333439343036302d422d32
<Vendor&#58; 0; Attr&#58; 51>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 61>&#91;4&#93;&#58; 00000005
<Vendor&#58; 0; Attr&#58; 64>&#91;4&#93;&#58; 00000003
<Vendor&#58; 0; Attr&#58; 65>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 66>&#91;13&#93;&#58; 3137322e32302e3235342e3236
<Vendor&#58; 0; Attr&#58; 67>&#91;13&#93;&#58; 3137322e32382e3230302e3132
<Vendor&#58; 0; Attr&#58; 90>&#91;6&#93;&#58; 5a654d2d5043
<Vendor&#58; 0; Attr&#58; 91>&#91;7&#93;&#58; 4e41545f6e6577
<Vendor&#58; 12341; Attr&#58; 12>&#91;3&#93;&#58; 4c2d32
<Vendor&#58; 12341; Attr&#58; 13>&#91;3&#93;&#58; 422d32
<Vendor&#58; 12341; Attr&#58; 14>&#91;3&#93;&#58; 6e6730
<Vendor&#58; 12341; Attr&#58; 15>&#91;4&#93;&#58; 00000011
<Vendor&#58; 12341; Attr&#58; 19>&#91;0&#93;&#58; 
<Vendor&#58; 12341&#40;0&#41;; Attr&#58; 19>&#91;0&#93;&#58; 
 
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; NAS found. Data size <0>
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 AcctServer&#58; Acct packet with session ID&#58; 3494060-L-2
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; NAS found. Data size <0>
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 AcctServer&#58; Acct-Start packet
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 AcctServer&#58; Acct-Start&#58; User <>
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 AcctServer&#58; Acct-Session-Time &#40;46&#41; not present in accounting packet. 
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 AcctServer&#58; No h323-setup-time &#40;9, 25&#41; attribute in accountig start packet. Setting to NOW <1353479725>!
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find login <>
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Searching card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Calling-Station-ID <172.20.254.26> is used in place of User-Name <>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find login <>
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Searching card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Calling-Station-ID <172.20.254.26> is used in place of User-Name <>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RADIUS DBA&#58; No data for login&#58; 
 ERROR &#58; Nov 21 10&#58;35&#58;25 f71ceb90 AcctServer&#58; Error! &#40;2&#41;
?Debug &#58; Nov 21 10&#58;35&#58;25 f71ceb90 RadiusSocket&#58; Waiting for RADIUS raw data
?Debug &#58; Nov 21 10&#58;35&#58;35 f5ccbb90 RadiusSocket&#58; RADIUS packet successfully received
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RadiusSocket&#58; RADIUS raw data obtained
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS Packet&#58; Size <242>; HDR.Size <242>
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 AcctServer&#58; Recv...
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 AcctServer&#58; Packet from <172.28.100.251> packet dump&#58; RPacket&#58;
Code&#58; 4; ID&#58; 212
<Vendor&#58; 0; Attr&#58; 1>&#91;0&#93;&#58; 
<Vendor&#58; 0; Attr&#58; 5>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 6>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 7>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 8>&#91;4&#93;&#58; 0a640102
<Vendor&#58; 0; Attr&#58; 30>&#91;0&#93;&#58; 
<Vendor&#58; 0; Attr&#58; 31>&#91;13&#93;&#58; 3137322e32302e3235342e3236
<Vendor&#58; 0; Attr&#58; 32>&#91;7&#93;&#58; 4e41545f6e6577
<Vendor&#58; 0; Attr&#58; 40>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 44>&#91;11&#93;&#58; 333439343036302d4c2d32
<Vendor&#58; 0; Attr&#58; 45>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 50>&#91;11&#93;&#58; 333439343036302d422d32
<Vendor&#58; 0; Attr&#58; 51>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 61>&#91;4&#93;&#58; 00000005
<Vendor&#58; 0; Attr&#58; 64>&#91;4&#93;&#58; 00000003
<Vendor&#58; 0; Attr&#58; 65>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 66>&#91;13&#93;&#58; 3137322e32302e3235342e3236
<Vendor&#58; 0; Attr&#58; 67>&#91;13&#93;&#58; 3137322e32382e3230302e3132
<Vendor&#58; 0; Attr&#58; 90>&#91;6&#93;&#58; 5a654d2d5043
<Vendor&#58; 0; Attr&#58; 91>&#91;7&#93;&#58; 4e41545f6e6577
<Vendor&#58; 12341; Attr&#58; 12>&#91;3&#93;&#58; 4c2d32
<Vendor&#58; 12341; Attr&#58; 13>&#91;3&#93;&#58; 422d32
<Vendor&#58; 12341; Attr&#58; 14>&#91;3&#93;&#58; 6e6730
<Vendor&#58; 12341; Attr&#58; 15>&#91;4&#93;&#58; 00000011
<Vendor&#58; 12341; Attr&#58; 19>&#91;0&#93;&#58; 
<Vendor&#58; 12341&#40;0&#41;; Attr&#58; 19>&#91;0&#93;&#58; 
 
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; NAS found. Data size <0>
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 AcctServer&#58; Acct packet with session ID&#58; 3494060-L-2
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; NAS found. Data size <0>
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 AcctServer&#58; Acct-Start packet
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 AcctServer&#58; Acct-Start&#58; User <>
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 AcctServer&#58; Acct-Session-Time &#40;46&#41; not present in accounting packet. 
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 AcctServer&#58; No h323-setup-time &#40;9, 25&#41; attribute in accountig start packet. Setting to NOW <1353479735>!
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find login <>
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Searching card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Calling-Station-ID <172.20.254.26> is used in place of User-Name <>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find login <>
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Searching card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Calling-Station-ID <172.20.254.26> is used in place of User-Name <>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RADIUS DBA&#58; No data for login&#58; 
 ERROR &#58; Nov 21 10&#58;35&#58;35 f71ceb90 AcctServer&#58; Error! &#40;2&#41;
?Debug &#58; Nov 21 10&#58;35&#58;35 f71ceb90 RadiusSocket&#58; Waiting for RADIUS raw data
?Debug &#58; Nov 21 10&#58;35&#58;38 f5bcab90 RADIUS Stream&#91;plugin&#93;&#58; Ping reply received
?Debug &#58; Nov 21 10&#58;35&#58;45 f5ccbb90 RadiusSocket&#58; RADIUS packet successfully received
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RadiusSocket&#58; RADIUS raw data obtained
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS Packet&#58; Size <242>; HDR.Size <242>
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 AcctServer&#58; Recv...
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 AcctServer&#58; Packet from <172.28.100.251> packet dump&#58; RPacket&#58;
Code&#58; 4; ID&#58; 212
<Vendor&#58; 0; Attr&#58; 1>&#91;0&#93;&#58; 
<Vendor&#58; 0; Attr&#58; 5>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 6>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 7>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 8>&#91;4&#93;&#58; 0a640102
<Vendor&#58; 0; Attr&#58; 30>&#91;0&#93;&#58; 
<Vendor&#58; 0; Attr&#58; 31>&#91;13&#93;&#58; 3137322e32302e3235342e3236
<Vendor&#58; 0; Attr&#58; 32>&#91;7&#93;&#58; 4e41545f6e6577
<Vendor&#58; 0; Attr&#58; 40>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 44>&#91;11&#93;&#58; 333439343036302d4c2d32
<Vendor&#58; 0; Attr&#58; 45>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 50>&#91;11&#93;&#58; 333439343036302d422d32
<Vendor&#58; 0; Attr&#58; 51>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 61>&#91;4&#93;&#58; 00000005
<Vendor&#58; 0; Attr&#58; 64>&#91;4&#93;&#58; 00000003
<Vendor&#58; 0; Attr&#58; 65>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 66>&#91;13&#93;&#58; 3137322e32302e3235342e3236
<Vendor&#58; 0; Attr&#58; 67>&#91;13&#93;&#58; 3137322e32382e3230302e3132
<Vendor&#58; 0; Attr&#58; 90>&#91;6&#93;&#58; 5a654d2d5043
<Vendor&#58; 0; Attr&#58; 91>&#91;7&#93;&#58; 4e41545f6e6577
<Vendor&#58; 12341; Attr&#58; 12>&#91;3&#93;&#58; 4c2d32
<Vendor&#58; 12341; Attr&#58; 13>&#91;3&#93;&#58; 422d32
<Vendor&#58; 12341; Attr&#58; 14>&#91;3&#93;&#58; 6e6730
<Vendor&#58; 12341; Attr&#58; 15>&#91;4&#93;&#58; 00000011
<Vendor&#58; 12341; Attr&#58; 19>&#91;0&#93;&#58; 
<Vendor&#58; 12341&#40;0&#41;; Attr&#58; 19>&#91;0&#93;&#58; 
 
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; NAS found. Data size <0>
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 AcctServer&#58; Acct packet with session ID&#58; 3494060-L-2
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; NAS found. Data size <0>
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 AcctServer&#58; Acct-Start packet
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 AcctServer&#58; Acct-Start&#58; User <>
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 AcctServer&#58; Acct-Session-Time &#40;46&#41; not present in accounting packet. 
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 AcctServer&#58; No h323-setup-time &#40;9, 25&#41; attribute in accountig start packet. Setting to NOW <1353479745>!
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find login <>
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Searching card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Calling-Station-ID <172.20.254.26> is used in place of User-Name <>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find login <>
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Searching card login <000000000>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find card login <000000000>
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Calling-Station-ID <172.20.254.26> is used in place of User-Name <>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Can't find login <172.20.254.26>
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; Card login <172.20.254.26> contains not digit symbol with code <46> ! Can't find card login
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RADIUS DBA&#58; No data for login&#58; 
 ERROR &#58; Nov 21 10&#58;35&#58;45 f71ceb90 AcctServer&#58; Error! &#40;2&#41;
?Debug &#58; Nov 21 10&#58;35&#58;45 f71ceb90 RadiusSocket&#58; Waiting for RADIUS raw data
?Debug &#58; Nov 21 10&#58;35&#58;55 f5ccbb90 RadiusSocket&#58; RADIUS packet successfully received
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 RadiusSocket&#58; RADIUS raw data obtained
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 RADIUS Packet&#58; Size <374>; HDR.Size <374>
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 AcctServer&#58; Recv...
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 AcctServer&#58; Packet from <172.28.100.251> packet dump&#58; RPacket&#58;
Code&#58; 4; ID&#58; 24
<Vendor&#58; 0; Attr&#58; 1>&#91;0&#93;&#58; 
<Vendor&#58; 0; Attr&#58; 5>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 6>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 7>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 8>&#91;4&#93;&#58; 0a640102
<Vendor&#58; 0; Attr&#58; 30>&#91;0&#93;&#58; 
<Vendor&#58; 0; Attr&#58; 31>&#91;13&#93;&#58; 3137322e32302e3235342e3236
<Vendor&#58; 0; Attr&#58; 32>&#91;7&#93;&#58; 4e41545f6e6577
<Vendor&#58; 0; Attr&#58; 40>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 42>&#91;4&#93;&#58; 00003dac
<Vendor&#58; 0; Attr&#58; 43>&#91;4&#93;&#58; 0000517f
<Vendor&#58; 0; Attr&#58; 44>&#91;11&#93;&#58; 333439343036302d4c2d32
<Vendor&#58; 0; Attr&#58; 45>&#91;4&#93;&#58; 00000002
<Vendor&#58; 0; Attr&#58; 46>&#91;4&#93;&#58; 00000020
<Vendor&#58; 0; Attr&#58; 47>&#91;4&#93;&#58; 00000083
<Vendor&#58; 0; Attr&#58; 48>&#91;4&#93;&#58; 00000061
<Vendor&#58; 0; Attr&#58; 49>&#91;4&#93;&#58; 00000006
<Vendor&#58; 0; Attr&#58; 50>&#91;11&#93;&#58; 333439343036302d422d32
<Vendor&#58; 0; Attr&#58; 51>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 52>&#91;4&#93;&#58; 00000000
<Vendor&#58; 0; Attr&#58; 53>&#91;4&#93;&#58; 00000000
<Vendor&#58; 0; Attr&#58; 61>&#91;4&#93;&#58; 00000005
<Vendor&#58; 0; Attr&#58; 64>&#91;4&#93;&#58; 00000003
<Vendor&#58; 0; Attr&#58; 65>&#91;4&#93;&#58; 00000001
<Vendor&#58; 0; Attr&#58; 66>&#91;13&#93;&#58; 3137322e32302e3235342e3236
<Vendor&#58; 0; Attr&#58; 67>&#91;13&#93;&#58; 3137322e32382e3230302e3132
<Vendor&#58; 0; Attr&#58; 90>&#91;6&#93;&#58; 5a654d2d5043
<Vendor&#58; 0; Attr&#58; 91>&#91;7&#93;&#58; 4e41545f6e6577
<Vendor&#58; 12341; Attr&#58; 12>&#91;3&#93;&#58; 4c2d32
<Vendor&#58; 12341; Attr&#58; 13>&#91;3&#93;&#58; 422d32
<Vendor&#58; 12341; Attr&#58; 14>&#91;3&#93;&#58; 6e6730
<Vendor&#58; 12341; Attr&#58; 15>&#91;4&#93;&#58; 00000011
<Vendor&#58; 12341; Attr&#58; 19>&#91;42&#93;&#58; 4d5352415356352e3230204d535241532d302d5a454d2d504320888033a315ee9a4597659e1306c05ce7
<Vendor&#58; 12341&#40;0&#41;; Attr&#58; 19>&#91;42&#93;&#58; 4d5352415356352e3230204d535241532d302d5a454d2d504320888033a315ee9a4597659e1306c05ce7
 
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 RADIUS DBA&#58; NAS found. Data size <0>
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 AcctServer&#58; Acct packet with session ID&#58; 3494060-L-2
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 RADIUS DBA&#58; NAS found. Data size <0>
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 AcctServer&#58; Acct-Stop packet
 Warn  &#58; Nov 21 10&#58;35&#58;55 f71ceb90 RADIUS DBA&#58; Sending bare packet
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 RADIUS Stream&#91;plugin&#93;&#58; finish log id <0>
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 AcctServer&#58; Reply packet dump&#58; RPacket&#58;
Code&#58; 5; ID&#58; 24

?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 RadiusSocket&#58; Moving RADIUS packet into send queue
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 RadiusSocket&#58; RADIUS raw data sent
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 AcctServer&#58; Next...
?Debug &#58; Nov 21 10&#58;35&#58;55 f71ceb90 RadiusSocket&#58; Waiting for RADIUS raw data
?Debug &#58; Nov 21 10&#58;36&#58;08 f5bcab90 RADIUS Stream&#91;plugin&#93;&#58; Ping reply received
?Debug &#58; Nov 21 10&#58;36&#58;38 f5bcab90 RADIUS Stream&#91;plugin&#93;&#58; Ping reply received
?Debug &#58; Nov 21 10&#58;37&#58;08 f5bcab90 RADIUS Stream&#91;plugin&#93;&#58; Ping reply received
?Debug &#58; Nov 21 10&#58;37&#58;38 f5bcab90 RADIUS Stream&#91;plugin&#93;&#58; Ping reply received
?Debug &#58; Nov 21 10&#58;38&#58;08 f5bcab90 RADIUS Stream&#91;plugin&#93;&#58; Ping reply received
?Debug &#58; Nov 21 10&#58;38&#58;38 f5bcab90 RADIUS Stream&#91;plugin&#93;&#58; Ping reply received
Очевидно проблема с радиусом
Конфиг MPD стандартный.

Код: Выделить всё

startup&#58;
    set user admin XXXXXX admin
    set console self 127.0.0.1 5005
    set console open
    set web self 172.28.200.12 5006
    set web open
    set netflow peer 172.28.100.4 9996
    set netflow timeouts 120 240
    set iface enable netflow-in
    #set iface enable netflow-in netflow-out
    log +PHYS2

default&#58;
    load l2tp_server
    load pptp_server

l2tp_server&#58;
    set ippool add pool1 10.100.1.2 10.100.1.253
    create bundle template B
    set iface enable proxy-arp
    set iface idle 0
    set iface enable tcpmssfix
    set iface enable netflow-in netflow-out
    set ipcp no vjcomp
    set ipcp ranges 10.100.1.1/24 ippool pool1
    set ipcp dns X.X.112.254 X.X.113.254
    set bundle enable compression
    #set ccp yes mppc
    set mppc yes e40
    set mppc yes e128
    set mppc yes stateless
    create link template L l2tp
    set link action bundle B
    set link max-children 500
    set link enable multilink
    set link yes acfcomp protocomp
    set link no pap chap
    #set link enable chap
    set link enable peer-as-calling
    load radius
    set link keep-alive 10 60
    set link mtu 1450
    set l2tp self 172.28.200.12
    set link enable incoming
    #set bundle disable ipv6cp

pptp_server&#58;
     set ippool add pool2 10.100.172.2 10.100.179.253
    create bundle template C
    set iface enable proxy-arp
    set iface idle 0
    set iface enable tcpmssfix
    set iface enable netflow-in netflow-out
    set ipcp yes vjcomp
     set ipcp ranges 10.100.172.1/21 ippool pool2
     set ipcp dns X.X.112.254 X.X.113.254
    set bundle enable compression
    #set ccp yes mppc
    set mppc yes e40
    set mppc yes e128
    set mppc yes stateless
    create link template M pptp
    set link action bundle C
    set link max-children 500
    set link enable multilink
    set link yes acfcomp protocomp
    set link no pap chap
    set link enable chap
    set link enable peer-as-calling
    load radius
    set link keep-alive 10 60
    set link mtu 1460
    set pptp self 172.28.200.12
    set link enable incoming

radius&#58;
    set radius server 172.28.100.4 XXXXXX 1812 1813
    set radius retries 3
    set radius timeout 10
    set radius me 172.28.100.251
    set auth acct-update 120
    set auth enable radius-auth
    set auth enable radius-acct
    set auth max-logins 0
    set radius enable message-authentic
Изначальный конфиг mpd пришлось поправить так для того чтобы был коннект пришлось #set link enable chap чтобы был коннект.
Сейчас конектится но выкидывает через минуту.
В чем дело mpd и радиус не дружат с vlan?
Не отправляются ауф пакеты - в дебаге только acct.
P.S FreeBSD NAT_new 9.0-RELEASE FreeBSD 9.0-RELEASE #0: Thu Nov 1 10:35:38 UTC 2012 root@NAT_new:/sys/amd64/compile/NAT12 amd64
Вырезана IPV6. Для NAT использую PF вкомпиленый в ядро.

rudf
Сообщения: 150
Зарегистрирован: Чт дек 15, 2011 08:55
Откуда: Москва

Сообщение rudf »

нет ли у вас проблем с маршрутизацией? для аутентификации и авторизации пакеты у вас уходят через разные интерфейсы vlan100 и vlan200?

rudf
Сообщения: 150
Зарегистрирован: Чт дек 15, 2011 08:55
Откуда: Москва

Сообщение rudf »

rudf писал(а):нет ли у вас проблем с маршрутизацией? для аутентификации и авторизации пакеты у вас уходят через разные интерфейсы vlan100 и vlan200?
запутался в ваших интерфейсах :) , но проблема кажется не в них. А в логах
mpd видно:

Nov 21 10:34:20 NAT_new mpd: [L-2] LCP: state change Ack-Sent --> Opened
Nov 21 10:34:20 NAT_new mpd: [L-2] LCP: auth: peer wants nothing, I want nothing
Nov 21 10:34:20 NAT_new mpd: [L-2] LCP: authorization successfull

где-то у вас аутентификация не включена.

rudf
Сообщения: 150
Зарегистрирован: Чт дек 15, 2011 08:55
Откуда: Москва

Сообщение rudf »

если у вас после

set link no pap chap

закомментирована строка

set link enable chap

то вы не задали ни одного метода аутентификации.

Аватара пользователя
ZeM
Сообщения: 371
Зарегистрирован: Чт фев 17, 2011 08:38

Сообщение ZeM »

Вот помогло такое

Код: Выделить всё

    set ipcp no vjcomp #21.11.2012
    set link no pap
    set link enable chap
    set link keep-alive 10 60
    set link mtu 1460
    set l2tp self 172.28.200.12
    set link enable incoming
Что такое set ipcp no vjcomp ? Это вроде сжатие TCP заголовка.

Ответить