Re: [j-nsp] M-Series DHCP Server

2012-02-03 Thread Joe Shen
hi, don't know too much about M series, in E320 configuration should like: ip dhcp-local unique-client-ids ip dhcp-local pool wlanpool network 10.10.0.0 255.255.128.0 dns-server 10.101.17.6 10.101.17.47 default-router 10.10.0.1 lease 0 0 20 ! ip dhcp-local excluded-address 10.10.0.1 To ou

[j-nsp] poor Performace of C20000 redirect server

2010-09-07 Thread Joe Shen
hi, we use Juniper C2000 to provide captive portal for wlan access. in past months, the service speed of redirect server on C2k degrade a lot. Usually, client pc has to wait one minute or more to see redirect page. On C2k it seems some requests are rejected. ad...@c2k-1> show redirect-server

[j-nsp] Quesion on E320 Radius Accouting packet

2010-03-22 Thread Joe Shen
hi, Could anybody explain Juniper E320 radius accouting packet content? We use Juniper E320 with C2000 to provide portal based wlan access service. subscribers --(WLAN) --- E320 C2000 - Radius server it is notice that there are radius accounting packets has Acct-Output-Packets = 0

[j-nsp] Need help on C2000 license server startup error

2009-11-09 Thread Joe Shen
hi, we have two C2000 used for network access control. The two server form a community in which one act as primary the other act as secondary. Today, we noticed secondary server showed somthing abnormal. there show continous error message in sae_error.log, it looks like: 12:55:34.687

[j-nsp] C2000 and E320 interaction problem

2009-09-29 Thread Joe Shen
hi, we use C2000 with E320 to provide web based authentication service. On a new site we found C2000 could not control E320 even after we tried to configure both sides serval times. If E320 is configured with ' sscc enable' , client could acquire IP address by DHCP (DHCP server runs on E

[j-nsp] Juniper C2K CLI hang up after login

2009-05-08 Thread Joe Shen
hi, we use juniper C2K with E320. Today I found I could not login C2k. After login , the cli hang up without showing out command prompt. it looks like : --- SRC CLI 2.0 build CLI.R.2.0.0.003 (c) 2005-2008 Juniper Networks Inc. ^] I tried with Ctrl+Break but

Re: [j-nsp] Direct any http request to designed web page

2008-08-28 Thread Joe Shen
son managing the list at > [EMAIL PROTECTED] > > When replying, please edit your Subject line so it > is more specific > than "Re: Contents of juniper-nsp digest..." > > > Today's Topics: > >1. Direct any http request to designed web page > for

[j-nsp] Direct any http request to designed web page forcefully

2008-08-28 Thread Joe Shen
hi, is that possible to direct any HTTP request to a designed web page forcefully by BAS? I mean, after people dial in BAS, BAS direct any HTTP request to a designed web page. Or BAS resolve any domain name to the same IP address. when people tried to open web by IP address, it should also be

[j-nsp] Is it possible to upload running-configuration automatically by E1440?

2008-07-02 Thread Joe Shen
there is not TACACS+ server used in our network. So, is it possible to upload running-configurion automatically to backup server by ERX1440 ? Joe > Joe Shen <[EMAIL PROTECTED]> writes: > > > we are trying to set up ERX1440/E320 > configuration > > backup and mon

[j-nsp] ERX1440, how to limit login to be able to "show conf" only

2008-07-01 Thread Joe Shen
hi, we are trying to set up ERX1440/E320 configuration backup and monitoring system. The system is implemented to fetch E320/E1440 configuration file every day. In order to confirm system security, the login account should ONLY be able to fech E1440/E320 configuration file. No privilege on c

[j-nsp] Tool to track special configuration segment

2008-06-13 Thread Joe Shen
Hi, we want to monitor special E320 configuration segment to avoid inconsistence between BRASes. Searching with google, I could only find some tool backing up whold configuration and monitoring changes. It seems they could not focusing on configuration backup and special configuration segme

[j-nsp] Is it possible to include L2TP client ip address in radius accouting packet?

2008-04-15 Thread Joe Shen
hi, Is it possible to include L2Tp client IP address in radius accouting packets? we use Juniper E320 as LAC which authenticate VPDN customer with radius server. we found there is NO L2TP client IP in radius accouting packets. Is is possible to include that information as that of dial-up

[j-nsp] how to send L2TP client IP in radius accouting packets?

2008-04-14 Thread Joe Shen
Hi, Could we configure E320 to include client IP address in radius accouting packets when E320 is used as LAC in L2TP tunnel ? we use Juniper E320 as LNS in VPDN service. the system architecture looks like LNS(E320) -

[j-nsp] Is there any Radius VSA attribute related to igmp fast leave ?

2007-11-20 Thread Joe Shen
hi, There is multicast configuration on our E320. It is planned to control PPPoE subscribers' ability of multicast by radius. Current, IGMP-Enable could be controlled by radius authentication. But, we did not find any VSA attribute on fast leaving. is it possible to control "igmp fast leavi

[j-nsp] Is it possible to include client IP in accounting packet for l2tp session?

2007-11-14 Thread Joe Shen
hi, we use ERX1440/E320 to serve dynamic L2TP dial-up service. When someone dial-up with some dial-up accouting, Radius server will respond with l2tp server ip and tunnel type to BRAS. Then BRAS set up l2tp tunnel to LNS. (BRAS act as LAC) We record these l2tp session in radius servers. But,

[j-nsp] Broadband subscriber got error 718 frequently on E320

2007-10-28 Thread Joe Shen
hi, Our broadband subscribers got error 718 frequently. They are all connected to Juniper E320/E1440. Someone said this may be caused by delayed acknowledge to accounting-start packet from radius server. But, IMHO delayed accouting-start ack packets will not affect E320 service at all.

[j-nsp] why did ERX1400 send radius Acct_ON packet periodically?

2007-08-03 Thread Joe Shen
hi, I noticed one of ERX1400 and one of E320 send radius Acct_ON packet periodically to our radius server. But, the two boxes do not change radius at all. The packet content looks like: Fri Aug 03 22:00:19 EAT 2007 Acct-Status-Type = Accounting-On NAS-IP-Address = 192.168

Re: [j-nsp] How is Accounting-On and Accounting-Off generated inERX1440 or E320?

2007-07-23 Thread Joe Shen
NG-JTAC-1410-3(config-radius)#DEBUG 07/23/2007 > 11:29:28 radiusClient: sendPacket: RADIUS Acct > packet sent (default) > > > > Regards, > > Nitin > > > > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On > B

[j-nsp] How is Accounting-On and Accounting-Off generated in ERX1440 or E320?

2007-07-23 Thread Joe Shen
Hi, I'm trying to understand how BAS send radius packets. In Radius RFCs there states attributes Acct-Status-Type = Accounting-Off Acct-Status-Type = Accounting-On But, it seems rfc does not define how such packets are generated. But, there do exist such packets in our ne

Re: [j-nsp] How to config E320 to round-robinly authenticate user between three radius servers?

2007-07-09 Thread Joe Shen
; of apperance in > configuration. > > 2007/7/8, Joe Shen <[EMAIL PROTECTED]>: > > > > hi, > > > > we set up three radius servers in E320 which is > used > > to authenticate dial-up customers. > > > > how could we make E320 try radius-se

[j-nsp] How to config E320 to round-robinly authenticate user between three radius servers?

2007-07-08 Thread Joe Shen
hi, we set up three radius servers in E320 which is used to authenticate dial-up customers. how could we make E320 try radius-server-1, radius-server-2, radius-server-3 in sequence if there is no response from radius-server-1 and radius-server-2. could we only turn on " radius algorith

[j-nsp] L2TP tunnel authentication with NAS-Port and NAS-Port-Type

2007-04-23 Thread Joe Shen
hi, we use Juniper ERX1440 as L2TP LNS to provide VPDN service to customers. Currently, customer dial into their internal network as follows: 1. client PC init a PPPoE session to LAC, with user name like [EMAIL PROTECTED] 2. According character behind @, a L2TP tnnnel is established fr