[j-nsp] Radius Tunnel Switching

Gabriel Blanchard gabe at teksavvy.ca
Tue Nov 2 09:07:55 EDT 2010


Hey,

I'm attempting to dynamically tunnel switch some of our users. 

The requirement is that the tunnel is initiated from a different virtual router and it appears that the radius attribute that I'm using simply doesn't work.

test at teksavvy.com             Cleartext-Password := "test123"
                Tunnel-Medium-Type := IP,
                Tunnel-Type := L2TP,
                ERX-Tunnel-Virtual-Router := "mlppp",
                Tunnel-Password := "<blank>",
                Tunnel-Server-Endpoint := 206.248.155.212,
                Auth-Type := Accept

Everything above works, except for the ERX-Tunnel-Virtual-Router attribute.

Here is what my ERX is seeing

bsr1.tor2:pppoe#test aaa ppp test at teksavvy.com test123
Authentication Grant with Tunnel Attributes
************ user attributes *************
    idle Timeout - 0
    session Timeout - 0
    accounting Timeout - 21600
    Tunnel Set - 1
        Tunnel Tag set - 0
        Tunnel Type set - 3
        Tunnel Medium set - 1
        Tunnel peer set - 206.248.155.212
        Tunnel Password set - <blank>
        Tunnel Router context - pppoe
        Tunnel calling number - atm 2/0.42:100.167#184549476#this is a

What am I doing wrong?

-Gabe





More information about the juniper-nsp mailing list