ISDN user not being validated (fwd)

MegaZone (megazone@livingston.com)
Fri, 8 Aug 1997 04:37:17 -0700 (PDT)

Once upon a time Joe Hartley shaped the electrons to say...
>Received PAP_AUTH_REQ on port S26 of 20 bytes containing:
>01 01 00 14 08 69 73 6c 61 6e 64 73 77 06 46 61
>6b 65 50 57
>Recvd from port S26: 22 bytes PAP Request-1
> <islandsw>
> <FakePW>
>
>Sending PAP_AUTH_NAK to port S26 of 18 bytes containing:
>03 01 00 12 0d 49 6e 76 61 6c 69 64 20 4c 6f 67
>69 6e
>Sent to port S26: 20 bytes PAP Refuse-1
> <Invalid Login>

Can you get the RADIUS debug when this happens. Looks like RADIUS is
telling us NO.

>The login and password above are correct! When I telnet into the PM2, attach
>an open port and call the dialup ISDN number and enter the login and password,
>I see the beginning of the PPP session!

yeah - but that means you are making a V.120 call, his call is NOT - one
difference.

># I don't know how islandsw will come in, so there's the ISDN and ISDN-V120
># Port-Types. Remove the one that's not used later...
>islandsw Auth-Type = System, NAS-Port-Type = ISDN-V120
> Port-Limit = 2,
> Service-Type = Framed-User,
> Framed-Protocol = PPP,
> Framed-IP-Address = 255.255.255.254,
> Framed-IP-Netmask = 255.255.255.0
>islandsw Auth-Type = System, NAS-Port-Type = ISDN
> Port-Limit = 2,
> Service-Type = Framed-User,
> Framed-Protocol = PPP,
> Framed-IP-Address = 255.255.255.254,
> Framed-IP-Netmask = 255.255.255.0
>islandsw Auth-Type = Reject

BTW, bad netmask. If you have VLSM setup you'll route the entire class
C to him. 255.255.255.255 for single IP users.

I'd get the RADIUS debug.

-MZ

--
Livingston Enterprises - Chair, Department of Interstitial Affairs
Phone: 800-458-9966 510-737-2100 FAX: 510-737-2110 megazone@livingston.com
For support requests: support@livingston.com  <http://www.livingston.com/> 
Snail mail: 4464 Willow Road, Pleasanton, CA 94588