Got it

NE8000F1A - Does not respond Disconnect-Messages

Created: Mar 15, 2022 18:14:18Latest reply: Mar 16, 2022 01:19:12 175 4 1 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi,

I'm trying to setup my NE8000F1A to serve as BRAS with Splynx. I can connect CPEs via PPPoE and assign rates without problem, but, when I send a disconnect-request, the router does not answer.


From the splynx server:

# echo "Framed-IP-Address = 170.233.117.254, NAS-IP-Address = 172.16.2.9" | /usr/bin/sudo /usr/bin/radclient 172.16.2.9:3799 disconnect hqk#g6RXondWSL*6
Sent Disconnect-Request Id 45 from 0.0.0.0:44049 to 172.16.2.9:3799 length 32
Sent Disconnect-Request Id 45 from 0.0.0.0:44049 to 172.16.2.9:3799 length 32
Sent Disconnect-Request Id 45 from 0.0.0.0:44049 to 172.16.2.9:3799 length 32
(0) No reply from server for ID 45 socket 3



On the NE8K I see the dyn-auth port open. Both appliances are in the same L2 network ( 172.16.2.0/24 )

[~ne8k.hq.sslocal]display udp status | include 3799
Info: It will take a long time if the content you search is too much or the string you input is too long, you can press CTRL_C to break.
------------------------------------------------------------------------------------
    SockId        Cid LAddr             LPort    FAddr             FPort    FeNode
------------------------------------------------------------------------------------
        13 0x8398042A 172.16.2.9        3799     0.0.0.0           0        0
------------------------------------------------------------------------------------



And here is my radius configuration:

[~ne8k.hq.sslocal]display current-configuration | include radius
Info: It will take a long time if the content you search is too much or the string you input is too long, you can press CTRL_C to break.
info-center source radius channel 2
info-center source radius channel 4 log level informational
radius-server group rd1
 radius-server shared-key-cipher %^%#jy<3>8wM0ZeFsR@x@w<I$^*g$7!j&7!Pu'2ot4+>%^%#
 radius-server authentication 172.16.2.132 vpn-instance __LOCAL_OAM_VPN__ 1812 weight 0
 radius-server accounting 172.16.2.132 vpn-instance __LOCAL_OAM_VPN__ 1813 weight 0
 radius-server retransmit 5 timeout 10
 radius-server accounting-start-packet resend 3
 radius-server accounting-stop-packet resend 3
 radius-server accounting-interim-packet resend 5
 radius-server user-name original
 radius-attribute hw-user-password simple coa-request
radius local-ip 172.16.2.9 __LOCAL_OAM_VPN__
undo radius local-ip all
  authentication-mode local radius
 authentication-scheme radius
 accounting-scheme radius
  authentication-scheme radius
  accounting-scheme radius
  radius-server group rd1


Please tell me if I need to add more info, and thanks in advance!!!


Edit: Added blank lines for ease of read

Featured Answers

Recommended answer

fuzi_yao
Admin Created Mar 16, 2022 01:19:12

Hi, friend!
1. The change key described in your article is a 4-digit number. From my understanding, Huawei's key setting does not support such a short key.
2. Your VRP version is very old. The new VRP version has been updated to V800R21.
3. After you set the 16-bit key, your dm and coa status is abnormal. Is there any more information available to us for analysis.
In your previous article, only the server sends a disconnection request packet but does not receive a response. I need to confirm whether the NE8K has received the request and, if so, whether it can recognize the request.
4. On the NE8K, you only checked the status of the UDP port. Check whether packets can be captured or debugging information can be enabled. Alternatively, view the log information of the device.
View more
  • x
  • convention:

All Answers
Hello User. we are reviewing your question and we will answer you shortly. Thanks.
View more
  • x
  • convention:

good sharing, following solution.

View more
  • x
  • convention:

Well, I changed the shared secret to a 4 digit one and everything works OK now. It may be a bug with radclient or VRP? I'm on V800R012C10SPC300


I double checked the 16 digits Huawei recommended secret and it was OK, and authentication and accounting worked ok. The problem only happened with authorization (dm and coa).

Thanks!

View more
  • x
  • convention:

Hi, friend!
1. The change key described in your article is a 4-digit number. From my understanding, Huawei's key setting does not support such a short key.
2. Your VRP version is very old. The new VRP version has been updated to V800R21.
3. After you set the 16-bit key, your dm and coa status is abnormal. Is there any more information available to us for analysis.
In your previous article, only the server sends a disconnection request packet but does not receive a response. I need to confirm whether the NE8K has received the request and, if so, whether it can recognize the request.
4. On the NE8K, you only checked the status of the UDP port. Check whether packets can be captured or debugging information can be enabled. Alternatively, view the log information of the device.
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.