<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 TRANSITIONAL//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; CHARSET=UTF-8">
<META NAME="GENERATOR" CONTENT="GtkHTML/3.18.3">
</HEAD>
<BODY>
<BR>
Hi<BR>
<BR>
We're having some weird issues with L2TP terminated links.<BR>
L2TP sessions are being terminated and built correctly from Radius sent config but in some cases the router allocates a Virtual-Access interface that is already active.<BR>
<BR>
----------------------------------------------<BR>
L2TP-DSL-PE2#SHOW VPDn SESS<BR>
<BR>
<BR>
L2TP Session Information Total tunnels 9 sessions 9<BR>
<BR>
<BR>
LocID RemID TunID Username, Intf/ State Last Chg Uniq ID <BR>
<BR>
Vcid, Circuit <BR>
<BR>
4012 49 14211 550-nti-mabo-ad, Vi4 est 00:35:44 38 <BR>
<BR>
4009 33 17734 1-mint-rf@bcs-m, Vi3 est 04:24:19 30 <BR>
<BR>
3987 2355 27602 554-nti-pret-no, Vi6 est 16:38:52 6 <BR>
<BR>
1552 11 30424 1-meib-adsl@bcs, Vi6 est 1d17h 576 <BR>
<BR>
3989 894 31125 551-nti-walt-ad, Vi7 est 09:14:24 13 <BR>
<BR>
4008 11193 48740 553-nti-pret-we, Vi2 est 04:58:10 31 <BR>
<BR>
3986 12 58608 552-nti-baba-ad, Vi4 est 18:02:09 9 <BR>
<BR>
3988 936 62131 1-nap-joha-nel-, Vi2 est 12:42:23 11 <BR>
<BR>
1553 11 64953 1-mark-adsl@bcs, Vi8 est 1d17h 577<BR>
<BR>
<BR>
<BR>
L2TP-DSL-PE2#SHOW INT VIRTual-Access 6<BR>
<BR>
Virtual-Access6 is up, line protocol is up <BR>
<BR>
Hardware is Virtual Access interface<BR>
<BR>
Description: 554-nti-pret-nort-adsl<BR>
<BR>
Internet address is 172.16.150.154/30<BR>
<BR>
MTU 1452 bytes, BW 1024 Kbit/sec, RxBW 256 Kbit/sec, DLY 100000 usec, <BR>
<BR>
reliability 255/255, txload 1/255, rxload 1/255<BR>
<BR>
Encapsulation PPP, LCP Open<BR>
<BR>
Open: IPCP<BR>
<BR>
PPPoVPDN vaccess, cloned from AAA, Virtual-Template1<BR>
<BR>
Vaccess status 0x44<BR>
<BR>
Protocol l2tp, tunnel id 27602, session id 3987, loopback not set<BR>
<BR>
Keepalive set (10 sec)<BR>
<BR>
DTR is pulsed for 5 seconds on reset<BR>
<BR>
Last input 00:00:01, output never, output hang never<BR>
<BR>
Last clearing of "show interface" counters 17:49:11<BR>
<BR>
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0<BR>
<BR>
Queueing strategy: fifo<BR>
<BR>
Output queue: 0/40 (size/max)<BR>
<BR>
30 second input rate 0 bits/sec, 0 packets/sec<BR>
<BR>
30 second output rate 0 bits/sec, 0 packets/sec<BR>
<BR>
177636 packets input, 12441878 bytes, 0 no buffer<BR>
<BR>
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles<BR>
<BR>
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort<BR>
<BR>
194012 packets output, 91814604 bytes, 0 underruns<BR>
<BR>
0 output errors, 0 collisions, 0 interface resets<BR>
<BR>
0 unknown protocol drops<BR>
<BR>
0 output buffer failures, 0 output buffers swapped out<BR>
<BR>
0 carrier transitions<BR>
<BR>
<BR>
<BR>
<BR>
<BR>
<BR>
<BR>
L2TP-DSL-PE2#sh l2tun | in Vi6<BR>
<BR>
3987 2355 27602 554-nti-pret-no, Vi6 est 16:45:18 6 <BR>
<BR>
1552 11 30424 1-meib-adsl@bcs, Vi6 est 1d17h 576 <BR>
<BR>
<BR>
<BR>
<BR>
<BR>
<BR>
<BR>
<BR>
<BR>
LocTunID RemTunID Remote Name State Remote Address Sessn L2TP Class/<BR>
<BR>
Count VPDN Group <BR>
<BR>
27602 17646 554-nti-pret- est 10.205.17.62 1 L2TP <BR>
<BR>
<BR>
<BR>
LocID RemID TunID Username, Intf/ State Last Chg Uniq ID <BR>
<BR>
Vcid, Circuit <BR>
<BR>
3987 2355 27602 554-nti-pret-no, Vi6 est 16:46:08 6 <BR>
<BR>
<BR>
<BR>
LocTunID RemTunID Remote Name State Remote Address Sessn L2TP Class/<BR>
<BR>
Count VPDN Group <BR>
<BR>
30424 57600 1-meib est 10.205.20.23 1 L2TP <BR>
-------------------------------------------------------------------------------<BR>
<BR>
The only way to resolve this is to clear the VPDN session ID.<BR>
<BR>
The router is a 7206 VXR NPE-400 running 12.4T(22) IP base.<BR>
<BR>
------------------------<BR>
vpdn enable<BR>
vpdn multihop<BR>
vpdn authen-before-forward<BR>
vpdn search-order domain <BR>
!<BR>
vpdn-group L2TP<BR>
! Default L2TP VPDN group<BR>
accept-dialin<BR>
protocol l2tp<BR>
virtual-template 1<BR>
lcp renegotiation always<BR>
no l2tp tunnel authentication<BR>
l2tp tunnel timeout no-session 1800<BR>
l2tp tunnel retransmit retries 7<BR>
l2tp tunnel retransmit timeout min 2<BR>
l2tp tunnel retransmit timeout max 5<BR>
!<BR>
interface Virtual-Template1<BR>
description L2TP-TEMPLATE<BR>
mtu 1452<BR>
bandwidth 512<BR>
bandwidth receive 256<BR>
no ip address<BR>
ip tcp adjust-mss 1460<BR>
load-interval 30<BR>
no peer default ip address<BR>
keepalive 10 3<BR>
traffic-shape rate 512000 12800 12800 1000<BR>
ppp mtu adaptive<BR>
ppp authentication chap callin<BR>
!<BR>
radius-server host zzz.zzz.zzz.zzz auth-port 1812 acct-port 1813<BR>
radius-server source-ports extended<BR>
!<BR>
----------------------------------<BR>
<BR>
Radius example:<BR>
<BR>
------------------------------------<BR>
test1-l2tp-adsl@test.co.za Auth-Type := Local, Cleartext-Password := "testing123"<BR>
Service-Type = Framed-User,<BR>
Framed-IP-Address = 10.250.0.2,<BR>
Cisco-AVPair += "interface-config#1=ip vrf forwarding CustA ",<BR>
Cisco-AVPair += "lcp:interface-config#2=ip address 10.250.0.1 255.255.255.252",<BR>
Cisco-AVPair += "lcp:interface-config#3=decription TEST1 ADSL Primary",<BR>
Cisco-AVPair += "lcp:interface-config#4=bandwidth 1024",<BR>
Cisco-AVPair += "ip:route=172.16.28.0 255.255.255.0 10.250.0.2"<BR>
--------------------------------------<BR>
<BR>
Has anyone seen similar issues or potential resolutions?<BR>
<BR>
Mauritz Lewies
</BODY>
</HTML>