The description command associates a text string with a configuration context to help identify the context in the configuration file.
The no form of this command removes any description string from the context.
The shutdown command administratively disables the entity. When disabled, an entity does not change, reset, or remove any configuration settings or statistics. Many entities must be explicitly enabled using the
no shutdown command.
The shutdown command administratively disables an entity. The operational state of the entity is disabled as well as the operational state of any entities contained within. Many objects must be shut down before they can be deleted.
The no form of the command puts an entity into the administratively enabled state.
.The no form of the command removes the profile name from the configuration.
The no form of the command reverts to the default value.
keep-alive [interval
seconds] [retry-count
value] [timeout
retry-seconds]
The no form of the command reverts to the default values.
The no form of the command reverts to the default values.
The no form of the command reverts to the default value.
The no form of the command removes the values from the profile.
The no form of the command removes the string from the configuration.
mgw-map ip-prefix [
/prefix-length] mgw-profile
profile-name
address ip-prefix[/prefix-length] [mgw-profile
profile-name]
The no form of the command removes the parameters form the configuration.
The no form of the command deletes the acct-on-off-group.
The no form of the command removes the policy name from the configuration.
acct-on-off: enables the sending of Accounting-On and Accounting-Off messages for this radius-server-policy. The acct-on-off oper-state is always not blocked.
acct-on-off oper-state-change [group
group-name]: enables the sending of Accounting-On and Accounting-Off messages for this radius-server-policy. The acct-on-off oper-state is function of the Accounting-response received for the Accounting-On and Accounting-Off. Optionally, sets the acct-on-off oper-state of the acct-on-off-group.
acct-on-off monitor-group group-name: no Accounting-On and Accounting-Off messages are sent for this radius-server-policy. The acct-on-off oper-state is inherited from the acct-on-off-group.
The no form of the command disables the sending of Accounting-On and Accounting-Off messages.
-a single radius-server-policy as controller: the
acct-on-off oper-state of the
acct-on-off-group is set to the
acct-on-off oper-state of the
radius-server-policy (acts as master)
-multiple radius-server-policies as monitor: the
acct-on-off oper-state of the
radius-server-policy is inherited from the
acct-on-off oper-state of the
acct-on-off group. (acts as a slave)
The no form of the command deletes the acct-on-off-group.
The no form of the command disables RADIUS message buffering.
The no form of the command disables RADIUS accounting interim update message buffering.
server server-index name
server-name
The no form of the command removes a RADIUS server.
timeout [sec
seconds] [min
minutes]
The no form of the command reverts to the default value.
server server-name [address
ip-address] [secret
key][hash
|hash2
][create
]
The no form of the command removes the parameters from the server configuration.
The no form of the command disables the command.
The no form of the commands resets the UDP port to its default value (1813)
The no form of the commands resets the UDP port to its default value (1812)
The no form of the command removes the policy name from the configuration.
The no form of the command removes the limit value from the configuration.
server server-name [create
] [purpose
{[accounting
| authentication | both
]}]
[no
] interface
ip-int-name
load-balance-key [vendor
vendor-id [vendor-id...(up to 5 max)]] attribute-type
attribute-type [attribute-type...(up to 5 max)]
The no form of the command removes the parameters from the configuration.
The no form of the command removes the parameters from the configuration.
Specifies the key is entered in a more complex encrypted form. If the
hash2 parameter is
not used, the less encrypted hash form is assumed.
The no form of the command removes the policy name from the configuration.
The no form of the command removes the policy name from the configuration.
username [1..32] [prefix-string
prefix-string] [accounting-server-policy
policy-name] [suffix-string
suffix-string]
[no
] send-accounting-response
The no form of the command disables the command.
key packet-type {accept
|request
} attribute-type
attribute-type [vendor
vendor-id]
timeout [hrs
hours] [min
minutes] [sec
seconds]
The no form of the command reverts to the default value.
The no form of the command removes the parameters from the configuration.
The no form of the command reverts to the default.
The no form of the command reverts to the default.
match {circuit-id
|mac
|remote-id
}
The no form of the command reverts to the default.
server [service
service-id] name
server-name
The no form of the command removes the parameters from the configuration.
The no form of the command removes the group
The no form of the command removes the number from the configuration.
The no form of the command removes the number from the configuration.
group-interface ip-int-name [
create]
lns
group-interface ip-int-name [
create]
softgre
no group-interface ip-int-name [
create]
Use the no form of the command to remove the group interface from the subscriber interface.
The no form of the command removes this functionality.
The no form of the command removes the value from the configuration.
The no form of the command removes the policy ID from the configuration.
The no form of the command removes the scheduler policy name from the configuration.
[no
] shape-multi-client-only
The no form of the command disables the egress shaping.
The no form of the command removes the parameter from the configuration.
The no form of the command removes the value from the soft-gre configuration.
The no form of the command removes the IPv6 the gateway IPv6 endpoint address for the soft-GRE tunnel.
Ths no form of the command removes the parameters from the configuration and disables data-plane mobility.
The no form of the command removes the value from the soft-gre configuration.
The no form of the command disables adjusting tcp-mss values.
vlan start [0..4095] end
[0..4095] retail-svc-id
service-id
The no form of the command removes the parameters from the configuration.
The no form of the command removes the value from the soft-gre configuration.
[no] dst-ip ip-address protocol
ip-protocol dst-port
port-number
Values
|
rdr-url-string [255 chars max] macro substitutions: $URL Request-URI in the HTTP GET Request received $MAC string that represents the MAC address of the subscriber host $IP a string that represents the IP address of the subscriber host
|
[no
] range start
[0..4095] end
[0..4095]
hold-time [hrs
hours] [min
minutes] [sec
seconds]
[no
] data-triggered-ue-creation
# show aaa acct-on-off-group "group-1"
===============================================================================
Acct-On-Off-Group Information
===============================================================================
acct on off group name : group-1
- controlling Radius-Server-policy :
aaa-server-policy-3
- monitored by Radius-Serer-policy :
aaa-server-policy-4
-------------------------------------------------------------------------------
Nbr of Acct-on-off-groups displayed : 1
-------------------------------------------------------------------------------
===============================================================================
system# show router 10 radius-proxy-server "myProxyServer1"
===============================================================================
RADIUS Proxy server "myProxyServer1"
===============================================================================
Description : myDesc
Purpose : authentication
Administrative state : in-service
Default acct server policy : myRadiusServerPolicy1
Default auth server policy : myRadiusServerPolicy2
Send accounting response : true
Last management change : 02/17/2012 14:54:28
-------------------------------------------------------------------------------
Cache settings
-------------------------------------------------------------------------------
Administrative state : enabled
Key packet type : access-accept
Key attribute type : 12
Key vendor ID : (Not Specified)
Timeout (s) : 60
Track accounting : stop interim-update accounting-on accounting-off
Load balance key : source-ip-udp
===============================================================================
Interfaces
-------------------------------------------------------------------------------
myInterface1
myInterface2
myInterface3
-------------------------------------------------------------------------------
No. of Interface(s): 3
===============================================================================
Usernames/RADIUS server policies
===============================================================================
Id Username-match RADIUS-server-policy Purpose
------------------------------------------------------------------------------------
1. aaa myRadiusServerPolicy2 auth
==============================================================================
soft-gre-tunnels [local-ip
ip-address] [remote-ip
ip-address][isa-group
wlan-gw-group-id] [member
[1..255]] [summary
] [detail
]
System# show router 50 wlan-gw soft-gre-tunnels
=======================================================================
Soft GRE tunnels
Remote IP address : 20C9::7:1:2
Local IP address : 2032::1:1:7
ISA group ID : 1
ISA group member ID : 3
Time established : 2013/07/02 07:45:31
Number of UE : 1
Tunnel QoS
----------
Operational state : active
Number of UE : 1
Remaining hold time (s) : N/A
----------------------------------------------------------------------
No. of tunnels: 1
=======================================================================
System#
radius-server-policy policy-name msg-buffer-stats
# show aaa radius-server-policy "aaa-server-policy-1"
===============================================================================
RADIUS server policy "aaa-server-policy-1"
===============================================================================
Description : Radius AAA server policy
Acct Request script policy : (Not Specified)
Auth Request script policy : (Not Specified)
Accept script policy : script-policy-1
Acct-On-Off : Enabled (state Not Blocked)
-------------------------------------------------------------------------------
RADIUS server settings
-------------------------------------------------------------------------------
Router : "Base"
Source address : (Not Specified)
Access algorithm : direct
Retry : 3
Timeout (s) : 5
Hold down time (s) : 30
Last management change : 02/20/2013 13:32:05
===============================================================================
===============================================================================
Servers for "aaa-server-policy-1"
===============================================================================
Idx Name Address Port Oper State
Auth/Acct
-------------------------------------------------------------------------------
1 server-1 172.16.1.1 1812/1813 in-service
===============================================================================
# show aaa radius-server-policy acct-on-off
==============================================================================
RADIUS server policies AcctOnOff state
==============================================================================
Name OperState LastStateChange
------------------------------------------------------------------------------
aaa-server-policy-1 on 02/20/2013 21:23:57
aaa-server-policy-2 NotApplicable NotApplicable
aaa-server-policy-3 sendAcctOn NotApplicable
aaa-server-policy-4 off 02/20/2013 21:40:57
------------------------------------------------------------------------------
No. of policies: 4
==============================================================================
# show aaa radius-server-policy "aaa-server-policy-1" acct-on-off
===============================================================================
RADIUS server policy "aaa-server-policy-1" AcctOnOff info
===============================================================================
Oper state : on
Session Id : 242FFF0000000451253EED
Last state change : 02/20/2013 21:23:57
Trigger : startUp
Server : "server-1"
===============================================================================
# show aaa radius-server-policy "aaa-server-policy-3" msg-buffer-stats
===============================================================================
RADIUS server policy "aaa-server-policy-3" message buffering stats
===============================================================================
buffering acct-interim : enabled
min interval (s) : 60
max interval (s) : 3600
lifetime (hrs) : 12
buffering acct-stop : enabled
min interval (s) : 60
max interval (s) : 3600
lifetime (hrs) : 12
Statistics
-------------------------------------------------------------------------------
Total acct-stop messages in buffer : 6
Total acct-interim messages in buffer : 10
Total acct-stop messages dropped (lifetime expired) : 0
Total acct-interim messages dropped (lifetime expired) : 0
Last buffer clear time : N/A
Last buffer statistics clear time : N/A
-------------------------------------------------------------------------------
===============================================================================
# show aaa radius-server-policy "aaa-server-policy-1" statistics
===============================================================================
RADIUS server policy "aaa-server-policy-1" statistics
===============================================================================
Tx transaction requests : 383
Rx transaction responses : 383
Transaction requests timed out : 0
Transaction requests send failed : 0
Packet retries : 0
Transaction requests send rejected : 0
Authentication requests failed : 0
Accounting requests failed : 0
Ratio of access-reject over auth responses : 0%
Transaction success ratio : 100%
Transaction failure ratio : 0%
Statistics last reset at : n/a
Server 1 "server-1" address 172.16.1.1 auth-port 1812 acct-port 1813
-------------------------------------------------------------------------------
Tx request packets : 383
Rx response packets : 383
Request packets timed out : 0
Request packets send failed : 0
Request packets send failed (overload) : 0
Request packets waiting for reply : 0
Response packets with invalid authenticator : 0
Response packets with invalid msg authenticator : 0
Authentication packets failed : 0
Accounting packets failed : 0
Avg auth response delay (10 100 1K 10K) in ms : 27.1 22.8 22.8 22.8
Avg acct response delay (10 100 1K 10K) in ms : 6.24 12.5 11.5 11.5
Statistics last reset at : n/a
===============================================================================
# show aaa radius-server-policy "myRadiusServerPolicy1" associations
===============================================================================
RADIUS Proxy Associations
===============================================================================
Router RADIUS Proxy Server Purpose Username
-------------------------------------------------------------------------------
Base myProxyServerBase acc (default)
vprn10 myProxyServer1 acc (default)
-------------------------------------------------------------------------------
No. of associations: 2
# show aaa radius-server-policy "aaa-server-policy-1" associations
===============================================================================
RADIUS Proxy Associations
===============================================================================
Router RADIUS Proxy Server Purpose Username
-------------------------------------------------------------------------------
Base myProxyServerBase acc (default)
-------------------------------------------------------------------------------
No. of associations: 1
===============================================================================
No route downloader entries found.
===============================================================================
Authentication Policy Associations
===============================================================================
Authentication Policy
-------------------------------------------------------------------------------
auth-policy-1
-------------------------------------------------------------------------------
No. of associations: 1
===============================================================================
===============================================================================
Accounting Policy Associations
===============================================================================
Accounting Policy
-------------------------------------------------------------------------------
acct-policy-1
acct-policy-2
-------------------------------------------------------------------------------
No. of associations: 2
===============================================================================
No dynamic-services policy entries found.
acct-on-off-group
Syntax acct-on-off-group [<group-name>]
Context show>aaa
Description This command displays Acct-On-Off group information and the associated RADIUS server policies
Parameters group-name — Displays information pertaining to the specified acct-on-off group.
Sample Output:
# show aaa acct-on-off-group "group-1"
===============================================================================
Acct-On-Off-Group Information
===============================================================================
acct on off group name : group-1
- controlling Radius-Server-policy :
aaa-server-policy-3
- monitored by Radius-Serer-policy :
aaa-server-policy-4
-------------------------------------------------------------------------------
Nbr of Acct-on-off-groups displayed : 1
-------------------------------------------------------------------------------
===============================================================================
ystem# show isa wlan-gw-group 1
===============================================================================
WLAN Gateway group 1
===============================================================================
test
Administrative state : in-service
Operational state : in-service
Active IOM limit : 2
Port policy : myPortPol
Last Mgmt Change : 02/17/2012 14:54:27
-------------------------------------------------------------------------------
NAT specific information for ISA group 1
-------------------------------------------------------------------------------
Reserved sessions : 10
High Watermark (%) : 20
Low Watermark (%) : 10
Accounting policy : natAccPol
Last Mgmt Change : 02/17/2012 15:01:31
-------------------------------------------------------------------------------
===============================================================================
===============================================================================
ISA Group 1 members
===============================================================================
Group Member State Mda Addresses Blocks Se-% Hi Se-Prio
----------------------------------------------------------------------------------------------------------------------------------
1 1 active 3/1 0 0 < 1 N 10
1 2 active 3/2 0 0 < 1 N 10
1 3 active 4/1 0 0 < 1 N 10
1 4 active 4/2 0 0 < 1 N 10
---------------------------------------------------------------------------------------------------------------------------------
No. of members: 4
===============================================================================
System# show isa wlan-gw-group 1 member 2
===============================================================================
ISA WLAN Gateway Group 1 Member 2
===============================================================================
MDA : 3/2
Number of Soft-GRE tunnels : 0
Number of UE : 0
Number of activated Egress Encapsulation Group members : 0
Number of pending Egress Encapsulation Group members : 0
Number of tunnel QoS problems : 0
===============================================================================
gtp-session imsi imsi apn
apn-string | gtp-session
[mgw-address
ip-address] [mgw-router
router-instance] [remote-control-teid
teid] [local-control-teid
teid] [detail
]
ue [vlan
qtag] [mpls-label
label] [retail-svc-id
service-id] [ssid
service-set-id] [previous-access-point
ip-address]
System# show subscriber-mgmt wlan-gw ue
======================================================================
User Equipments
======================================================================
MAC address : 00:02:00:00:00:39
----------------------------------------------------------------------
VLAN Q-tag : 1
MPLS label : (Not Specified)
Tunnel router : 50
Tunnel remote IP address : 20C9::7:1:2
Tunnel local IP address : 2032::1:1:7
Retail service : N/A
SSID : 1
Previous Access Point IP : (Not Specified)
IMSI : (Not Specified)
Last move time : 2013/07/02 07:45:31
----------------------------------------------------------------------
No. of UE: 1
======================================================================
System#
acct-on [radius-server-policy
policy-name] [force
]
acct-off [radius-server-policy
policy-name] [force
] [acct-terminate-cause
number]
System# tools dump wlan-gw ue
No sessions on Slot #3 MDA #1 match the query
No sessions on Slot #3 MDA #2 match the query
No sessions on Slot #4 MDA #1 match the query
===============================================================================
Matched 1 session on Slot #4 MDA #2
===============================================================================
UE-Mac : 00:02:00:00:00:39 UE-vlan : 1
UE IP Addr : N/A Description : ESM-user
UE timeout : N/A Auth-time : None
Tunnel MDA : 4/1 Tunnel Router : 50
MPLS label : N/A Shaper : 1
GRE Src IP Addr : 20C9::7:1:2
GRE Dst IP Addr : 2032::1:1:7
Anchor SAP : 4/2/nat-out-ip:2049.4
Last-forward : 07/02/2013 07:22:29 Last-move : None
Rx Frames : 2 Rx Octets : 744
Tx Frames : 1 Tx Octets : 352
-------------------------------------------------------------------------------
===============================================================================
No sessions on Slot #5 MDA #1 match the query
No sessions on Slot #5 MDA #2 match the query
server server-index statistics