Given: PPPoE dialup connections to our Cisco router, which authenticates through FreeRadius 0.93, working fine as such. Default-entry w/fall-through adds some config settings. When I do a "show int viX conf", I get the entries displayed that I configured through the default entry:

interface Virtual-Access6
mtu 1456
ip unnumbered Loopback0
rate-limit input 128000 7500 7500 conform-action continue exceed-action drop
rate-limit output 1048000 7500 7500 conform-action continue exceed-action drop
ip tcp adjust-mss 1416
timeout absolute 1439 43
peer default ip address pool dsl-pool
keepalive 60
ppp authentication pap chap ms-chap
end


(the rate-limit entries come from the default)

Now I'm trying to overwrite the default entry, and having mixed success ... I've tried just about all combinations of "=", ":=" and "+=", but either I get double entries, or the default entry is retained while the dial-in specific one is ignored ...

Default is configured like this ATM:

DEFAULT Suffix == "@dsl"
Session-Timeout := `%{expr:86400 - ((%l - 10800) %% 86400)}`,
Framed-IP-Netmask := "255.255.255.255",
Cisco-Avpair := "lcp:interface-config#1=rate-limit input 131072 7500 7500 conform-action continue exceed-action drop",
Cisco-Avpair += "lcp:interface-config#2=rate-limit output 1048576 7500 7500 conform-action continue exceed-action drop",
Cisco-Avpair += "ip:dns-servers=192.135.7.3 212.218.0.3",
Fall-Through := Yes


Custom entry per dialup looks like this:

[EMAIL PROTECTED] Auth-Type == Local, Password == "secret"
Service-Type := Framed-User,
Framed-IP-Address := 192.168.15.1,
Framed-Protocol := PPP,
Cisco-Avpair := "lcp:interface-config#1=rate-limit input 2304000 7500 7500 conform-action continue exceed-action drop",
Cisco-Avpair += "lcp:interface-config#2=rate-limit output 2308000 7500 7500 conform-action continue exceed-action drop"


With this setup, I get this output from "show int viX conf":

interface Virtual-Access3
mtu 1456
ip unnumbered Loopback0
rate-limit input 2304000 7500 7500 conform-action continue exceed-action drop
rate-limit output 1048000 7500 7500 conform-action continue exceed-action drop
rate-limit output 2304000 7500 7500 conform-action continue exceed-action drop
ip tcp adjust-mss 1416
timeout absolute 50 55
peer default ip address pool dsl-pool
keepalive 60
ppp authentication pap chap ms-chap
end


Any idea?

Tnx, -garry

- List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to