Monitoring Remote Access
You can use the following commands to monitor remote access on E-series routers.
show aaa accounting
- Accounting duplicationName of the virtual router to which duplicate accounting records are sent to the accounting server
- Broadcast accountingName of the virtual router groups to which broadcast accounting records are sent to the accounting server
- send acct-stop on AAA access denyEnabled, disabled
- send acct-stop on authentication server access denyEnabled, disabled
- acct-interval (for PPP Clients)Number of minutes between accounting update operations
- service-acct-intervalNumber of minutes between interim accounting updates for services created by the Service Manager feature
- send immediate-updateOn receipt of response to Acct-Start message; enabled, disabled
host1:vrXyz7#show aaa accountingAccounting duplication set to router vrXyz25Broadcast accounting uses group groupXyzCompany20send acct-stop on AAA access deny is enabledsend acct-stop on authentication server access deny is disabledacct-interval (for PPP Clients) 0service-acct-interval 0send immediate-update is enabledshow aaa accounting default
- Use to display the AAA accounting default method for a subscriber type. You can view the method used for ATM 1483, IPSec, PPP, RADIUS relay server, and tunnel subscribers, and IP subscriber management interfaces.
- Example
host1#show aaa accounting tunnel defaultradiusshow aaa accounting interval
host1#show aaa accounting intervalacct-interval (for PPP Clients) 10show aaa accounting vr-group
- Use to display the names of a specific virtual router group or of all virtual router groups configured on the router and the virtual routers making up the groups.
- Field descriptions
- vr-groupName of the virtual router group.
- virtual-routerIndex entry and name of virtual routers in the group.
host1#show aaa accounting vr-groupvr-group groupXyzCompany10:virtual-router 1 vrXyzAvirtual-router 2 vrXyzBvirtual-router 3 vrXyzCvirtual-router 4 vrXyzDvr-group groupXyzCompany20:virtual-router 1 vrXyzPvirtual-router 2 vrXyzQvirtual-router 3 vrXyzRvirtual-router 4 vrXyzSshow aaa authentication default
- Use to display the default AAA authentication method list for a subscriber type. You can view the method list used for ATM 1483 subscribers, IPSec subscribers, IP subscriber management interfaces, PPP subscribers, RADIUS relay subscribers, and tunnel subscribers. For example, you can verify that the local authentication method is configured for PPP subscribers.
- Example
host1#show aaa authentication ppp defaultlocal noneshow aaa delimiters
- Use to display the domain and realm name delimiters, parse order, and parse direction configured on the router.
- Example
host1#show aaa delimitersdomain delimiters "@!"realm delimiters "/"parse order is realm-firstdomain parse direction is right-to-leftrealm parse direction is left-to-rightshow aaa domain-map
- Use to display the mapping between user domains and virtual routers.
- The following keywords have significance when used as user domains:
- noneAll client requests with no user domain name are associated with the virtual router mapped to the none entry
- defaultAll client requests with a domain present that have no map are associated with the virtual router mapped to the default entry
- DomainName of the domain
- router-nameVirtual router to which user domain name is mapped
- tunnel-groupName of the tunnel group assigned to the domain map
- ipv6-router-nameIPv6 virtual router to which user domain name is mapped
- local-interfaceInterface information to use on the local (E-series) side of the subscriber's interface
- ipv6-local-interfaceIPv6 interface information to use on the local (E-series) side of the subscriber's interface
- poolnameLocal address pool from which the router allocates addresses for this domain
- IP hintIP hint is enabled
- strip-domainStrip domain is enabled
- override-usernameSingle username used for all users from a domain in place of the values received from the remote client
- override-passwordSingle password used for all users from a domain in place of the values received from the remote client
- Tunnel TagTag that identifies the tunnel
- Tunnel PeerDestination address of the tunnel
- Tunnel SourceSource address of the tunnel
- Tunnel TypeL2TP
- Tunnel MediumType of medium for the tunnel; only IPv4 is supported
- Tunnel PasswordPassword for the tunnel
- Tunnel IdID of the tunnel
- Tunnel Client NameHost name that the LAC sends to the LNS when communicating to the LNS about the tunnel
- Tunnel Server NameHost name expected from the peer (the LNS) when during tunnel startup
- Tunnel PreferencePreference level for the tunnel
- Tunnel Max SessionsMaximum number of sessions allowed on a tunnel
- Tunnel RWSL2TP receive window size (RWS) for a tunnel on the LAC; displays either the configured value or the default behavior, which is indicated by
system chooses- Tunnel Virtual RouterName of the virtual router to map to the user domain name
- Tunnel Failover ResyncL2TP peer resynchronization method
- Tunnel Switch ProfileName of the L2TP tunnel switch profile
- Tunnel Tx Speed MethodMethod that the router uses to calculate the transmit connect speed of the subscriber's access interface: static layer2, dynamic layer2, qos, actual, not set
host1#show aaa domain-mapDomain: lac-tunnel; router-name: lac; ipv6-router-name: defaultTunnel Tunnel Tunnel Tunnel TunnelTag Tunnel Peer Source Type Medium Password Tunnel Id------ ----------- ------ ------ ------ -------- -----------5 192.168.1.1 <null> l2tp ipv4 welcome lac-tunnelTunnel TunnelTunnel Tunnel Server Tunnel MaxTag Client Name Name Preference Sessions Tunnel RWS------ ----------- ------ ---------- -------- --------------5 lac boston 5 0 4TunnelTunnel Tunnel Tunnel TxTunnel Virtual Failover Switch SpeedTag Router Resync Profile Method------ ------- -------- --------- ------5 <null> silent failover denver qosshow aaa duplicate-address-check
- Use to display whether the routing table address lookup or duplicate address check is enabled or disabled.
- Example
host1#show aaa duplicate-address-checkenabledshow aaa model
host1#show aaa modelaaa model: old modelshow aaa name-servers
host1#show aaa name-serversName Server Addresses (for PPP Clients):primary DNS Addr 10.2.3.4secondary DNS Addr 10.6.7.8primary NBNS (WINS) Addr 10.22.33.44secondary NBNS (WINS) Addr 10.66.77.88show aaa profile
- atm nas-port-typeConfiguration of NAS-Port-Type attribute for ATM interfaces
- ethernet nas-port-typeConfiguration of NAS-Port-Type attribute for Ethernet interfaces
- profile-service-descriptionDescription configured in the Service-Description attribute
- pre-authenticateIndicates that subscriber preauthentication is configured for the profile
- allowOne or more domain names that are allowed access to AAA authentication
- denyOne or more domain names that are denied access to AAA authentication
- translateOriginal domain name and the name to which it is mapped for domain map lookup
host1#show aaa profile name PreAuth1preAuth1:atm nas-port-type: ADLSL-CAPethernet nas-port-type: Cableprofile-service-description: xyzServicepre-authenticateallow xyz.comdeny defaulttranslate xyz1.com abc.com
- Use to display statistics about the RADIUS route-download server configuration.
- Use the optional statistics keyword to display information about the RADIUS route download server operation.
- Use the optional delta keyword to show baselined statistics.
- Field descriptions
- AAA Route DownloaderVirtual router where the RADIUS route-download server is configured
- Download IntervalNumber of minutes between route downloads
- Retry IntervalNumber of minutes before retry after a download failure
- Default CostDefault cost of downloaded routes
- Default TagDefault tag for downloaded routes
- Base User NameVirtual router used for route-download requests; either <HOSTNAME> or the configured name
- PasswordPassword for route-download requests or <DEFAULT>
- SynchronizationEither <NOT SET> or the time that the server starts the route download operation each day
- StatusCurrent status of route-download server; waiting for base router, waiting for IP warmstart, idle, downloading, updating ip, downloading and updating ip, or suspended
- Last Download AttemptEither <NEVER> or the day, date, and time of attempt
- Last Download SuccessEither <NEVER> or the day, date, and time of success
- Last Regular DownloadStatus of last regular download; either complete or not complete
- Next Download Scheduled<DOWNLOAD ACTIVE>,<NOT SCHEDULED>, or the day, date, and time of next download
- Next Regular DownloadDay, date, and time
- Total Download AttemptsNumber of downloads attempted
- Successful DownloadsNumber of successful download operations
- Downloaded FragmentsNumber of downloaded fragments
- Downloaded RoutesNumber of downloaded routes
- IP UpdatesNumber of IP updates
- Updated RoutesNumber of updated routes
- Cleared Route IntervalsNumber of cleared route intervals
host1#show aaa route-downloadAAA Route Downloader: configured in virtual router defaultDownload Interval: 720 minutesRetry Interval: 10 minutesDefault Cost: 2Default Tag: 0Base User Name: <HOSTNAME>Password: <DEFAULT>Synchronization: <NOT SET>Status: idleLast Download Attempt: TUE DEC 19 22:46:47 2006Last Download Success: TUE DEC 19 22:46:47 2006Last Regular Download: completeNext Download Scheduled: WED DEC 20 10:46:47 2006Next Regular Download: WED DEC 20 10:46:47 2006Example 2 host1#show aaa route-download statisticsTotal Download Attempts: 2Successful Downloads: 2Downloaded Fragments: 3756Downloaded Routes: 192000IP Updates: 1Updated Routes: 96000Cleared Route Intervals: 0show aaa route-download routes
- Use to display information about the routes that are downloaded by the RADIUS route-download server.
- Use the optional detail keyword to display more detailed information about the downloaded routes.
- Field descriptions
- downloaded routesNumber of current downloaded routes
- Prefix/LengthIP address prefix and mask information for downloaded routes
- TypeType of downloaded routes; Access-P indicates routes downloaded from the RADIUS route-download server
- NextHopIP address of the next hop
- Dst/MetAdministrative distance and number of hops for the route
- TagTag assigned to downloaded routes
- IntfInterface type and specifier
host1#show aaa route-download routes96000 downloaded routesExample 2 host1#show aaa route-download routes detailPrefix/Length Type NextHop Dst/Met Intf Tag--------------- -------- --------------- ------- ----- ---192.168.1.1/32 Access-P 255.255.255.255 254/2 null0 0192.168.1.5/32 Access-P 255.255.255.255 254/2 null0 0192.168.1.9/32 Access-P 255.255.255.255 254/2 null0 0192.168.1.13/32 Access-P 255.255.255.255 254/2 null0 0192.168.1.17/32 Access-P 255.255.255.255 254/2 null0 0192.168.1.21/32 Access-P 255.255.255.255 254/2 null0 0show aaa route-download routes global
- Use to display chassis-wide information about routes that are downloaded by RADIUS route-download servers.
- Use the optional detail keyword to display more detailed information about the downloaded routes.
- Use the optional start keyword to specify the first router context that you want to display in the output. For example, aaa:a2 specifies that the display shows a list of router contexts starting with VRF a2 in virtual router aaa.
- Field descriptions
- Virtual RouterName of the virtual router used to download the routes
- VRFName of the VRF used to download the routes
- PresentRoutes have been downloaded; y (yes) or n (no) indicates if the router context has been created.
- Number of RoutesNumber of current downloaded routes
- Prefix/LengthIP address prefix and mask information for downloaded routes
- TypeType of downloaded routes; Access-P indicates routes downloaded from the RADIUS route-download server
- NextHopIP address of the next hop
- Dst/MetAdministrative distance and number of hops for the route
- TagTag assigned to downloaded routes
- IntfInterface type and specifier
host1#show aaa route-download routes globalNumberofVirtual Router VRF Present Routes--------------- --------------- ------- ------aaa n 4aaa a1 n 4default y 4default d1 n 4Example 2 host1#show aaa route-download routes global detailVirtual Router VRF Present Prefix/Length Type NextHop Dst/Met Intf Tag--------------- --- ------- --------------- -------- --------------- ------- ----- ---aaa n 192.168.1.1/32 Access-P 255.255.255.255 0/2 null0 0aaa n 192.168.1.2/32 Access-P 255.255.255.255 0/2 null0 0aaa n 192.168.3.1/32 Access-P 255.255.255.255 0/2 null0 0aaa n 192.168.4.1/32 Access-P 255.255.255.255 0/2 null0 0aaa a1 n 192.168.5.3/32 Access-P 255.255.255.255 0/2 null0 0aaa a1 n 192.168.7.1/32 Access-P 255.255.255.255 0/2 null0 0aaa a1 n 192.168.7.5/32 Access-P 255.255.255.255 0/2 null0 0aaa a1 n 192.168.9.1/32 Access-P 255.255.255.255 0/2 null0 0default y 192.168.22.1/32 Access-P 255.255.255.255 0/2 null0 0default y 192.168.23.1/32 Access-P 255.255.255.255 0/2 null0 0default y 192.168.24.1/32 Access-P 255.255.255.255 0/2 null0 0default y 192.168.25.1/32 Access-P 255.255.255.255 0/2 null0 0default d1 n 192.168.40.6/32 Access-P 255.255.255.255 0/2 null0 0default d1 n 192.168.40.7/32 Access-P 255.255.255.255 0/2 null0 0default d1 n 192.168.40.8/32 Access-P 255.255.255.255 0/2 null0 0default d1 n 192.168.40.9/32 Access-P 255.255.255.255 0/2 null0 0host1#show aaa route-download routes global start aaa:a2NumberofVirtual Router VRF Present Routes--------------- --------------- ------- ------default y 4default d1 n 4show aaa statistics
- Use to display authentication, authorization, and accounting statistics.
- Use the optional delta keyword to specify that baselined statistics are to be shown.
- Field descriptions
- incoming initiate requestsNumber of incoming AAA requests (from other E-series applications) for user connect services
- incoming disconnect requestsNumber of incoming AAA requests (from other E-series applications) for user disconnect services
- outgoing grant (tunnel) responsesNumber of outgoing tunnel grant responses to AAA requests
- outgoing grant responsesNumber of outgoing grant responses to AAA requests
- outgoing deny responsesNumber of outgoing deny responses to AAA requests
- outgoing error responsesNumber of outgoing error responses to AAA requests
- outgoing Authentication requestsNumber of authentication requests from AAA to the authentication task
- incoming Authentication responsesNumber of authentication responses from the authentication task to AAA
- outgoing Re-Authentication requestsNumber of reauthentication requests from AAA to the authentication task
- incoming Re-Authentication responsesNumber of reauthentication responses from the authentication task to AAA
- outgoing Pre-Authentication requestsNumber of preauthentication requests from AAA to the preauthentication task
- incoming Pre-Authentication responsesNumber of preauthentication responses from the preauthentication task to AAA
- outgoing Accounting requestsNumber of accounting requests (starts, updates, stops) from AAA to the accounting task
- incoming Accounting responsesNumber of accounting responses (starts, updates, stops) from the accounting task to AAA
- outgoing Duplicate Acct requestsNumber of duplicate accounting requests (starts, updates, stops) from AAA to the accounting task
- incoming Duplicate Acct responsesNumber of duplicate accounting responses (starts, updates, stops) from the accounting task to AAA
- outgoing Broadcast Acct requestsNumber of broadcast accounting requests (starts, updates, stops) from AAA to the accounting task
- incoming Broadcast Acct responsesNumber of broadcast accounting responses (starts, updates, stops) from the accounting task to AAA
- outgoing Address requestsNumber of address allocation/release requests from AAA to address allocation task
- incoming Address responsesNumber of address allocation/release responses from the address allocation task to AAA
host1#show aaa statisticsAAA Statistics--------------Statistic Count------------------------------------ -----incoming initiate requests 109incoming disconnect requests 7outgoing grant (tunnel) responses 3outgoing grant responses 6outgoing deny responses 0outgoing error responses 0outgoing Authentication requests 9incoming Authentication responses 9outgoing Re-Authentication requests 0incoming Re-Authentication responses 0outgoing Pre-Authentication requests 1incoming Pre-Authentication responses 1outgoing Accounting requests 120incoming Accounting responses 120outgoing Duplicate Acct requests 18incoming Duplicate Acct responses 18outgoing Broadcast Acct requests 32incoming Broadcast Acct responses 32outgoing Address requests 0incoming Address responses 0show aaa subscriber per-port-limit
host1#show aaa subscriber per-port-limitSubscriber Port Limits----------------------Port Limit--------------- ---------------0/2 50/3 23/2 2show aaa subscriber per-vr-limit
host1#show aaa subscriber per-vr-limitsubscriber limit is 0show aaa timeout
host1#show aaa timeoutidle timeout (for PPP Clients) 0 secondssession timeout (for PPP Clients) 31622400 secondsshow aaa user accounting interval
- Use to display the default interval used for interim accounting for users on the virtual router.
- An entry of 0 indicates that the feature is disabled.
- Example
host1:vrXyz7#show aaa user accounting intervaluser-acct-interval 20show configuration category aaa global-attributes
- Use to display the virtual router groups that are configured for AAA broadcast accounting.
- For additional information about the show configuration command, see Customizing the Configuration Output in JUNOSe System Basics Configuration Guide, Chapter 5, Managing the System.
- Field descriptions
- aaa accounting vr-groupName of virtual router groups
- aaa virtual-routerName and index number of the virtual routers that are members of the virtual router group
host1#show configuration category aaa global-attributes! Configuration script being generated on MON JAN 10 2005 15:19:19 UTC! Juniper Edge Routing Switch ERX-1440! Version: 9.9.9 development-4.0 (January 7, 2005 17:26)! Copyright (c) 1999-2004 Juniper Networks, Inc. All rights reserved.!! Commands displayed are limited to those available at privilege level 15!! NOTE: This script represents only a subset of the full system configuration.! The category displayed is: aaa global-attributes!aaa accounting vr-group groupXyzCompany10aaa virtual-router 1 vrXyzAaaa virtual-router 2 vrXyzBaaa virtual-router 3 vrXyzCaaa virtual-router 4 vrXyzDaaa accounting vr-group groupXyzCompany20aaa virtual-router 1 vrXyzPaaa virtual-router 2 vrXyzQaaa virtual-router 3 vrXyzRaaa virtual-router 4 vrXyzS!hostname "host1"show configuration category aaa local-authentication
- Use to display the configuration information for AAA local authentication. You can display information for the following keywords:
- databasesLocal user databases configured on the router
- usersUsers configured in the local user databases
- virtual-routerLocal user database selected by the specified virtual router for local authentication
- For additional information about the show configuration command, see Customizing the Configuration Output in JUNOSe System Basics Configuration Guide, Chapter 5, Managing the System.
- Field descriptions for all keywords
- aaa local databaseName of the local user database; the name default specifies the default local user database
- aaa local select databaseLocal user database that the virtual router uses for local authentication
- aaa local usernameUnique user entry in the local user database
- databaseName of the local user database for the specified username
- hostnameName of the host router
- ip-addressIP address parameter for the user entry
- ip-address-poolIP address pool parameter for the user entry
- operational virtual-routerVirtual router parameter for the user entry
- passwordPassword used to authenticate the subscriber
- secretSecret used to authenticate the subscriber
- virtual-routerName of virtual router
- Example (see Local Authentication Example in Chapter 1, Configuring Remote Access for additional examples with the users and virtual-router keywords).
host1#show configuration category aaa local-authentication databases! Configuration script being generated on TUE NOV 09 2004 12:50:18 UTC! Juniper Edge Routing Switch ERX-1400! Version: 6.1.0 (November 8, 2004 18:31)! Copyright (c) 1999-2004 Juniper Networks, Inc. All rights reserved.!! Commands displayed are limited to those available at privilege level 15!! NOTE: This script represents only a subset of the full system configuration.! The category displayed is: aaa local-authentication databases!hostname host1aaa new-modelaaa local database defaultaaa local database svaleLdb10show configuration category aaa server-attributes include-defaults
- Use to display status of the attributes on the AAA server, including AAA accounting duplication and broadcast.
- For additional information about the show configuration command, see Customizing the Configuration Output in JUNOSe System Basics Configuration Guide, Chapter 5, Managing the System.
- Field descriptions
- virtual routerName of the virtual router
- aaa accounting duplicationVirtual router used for duplicate accounting
- aaa accounting broadcastVirtual router group used for broadcast accounting
- aaa duplicate-address-checkEnabled, disabled
- aaa accounting acct-stop on-aaa-failureEnabled, disabled
- aaa accounting acct-stop on-access-denyEnabled, disabled
- aaa subscriber limit per-vrEnabled, disabled
- aaa intf-desc-format include sub-intfEnabled, disabled
- aaa intf-desc-format include adapterEnabled, disabled
- aaa accounting immediate-updateEnabled, disabled
host1#show configuration category aaa server-attributes include-defaults! Configuration script being generated on MON JAN 10 2005 15:12:02 UTC! Juniper Edge Routing Switch ERX-1440! Version: 9.9.9 development-4.0 (January 7, 2005 17:26)! Copyright (c) 1999-2004 Juniper Networks, Inc. All rights reserved.!! Commands displayed are limited to those available at privilege level 15!! NOTE: This script represents only a subset of the full system configuration.! The category displayed is: aaa server-attributes!virtual-router defaultaaa accounting duplication lacaaa accounting broadcast group1aaa duplicate-address-check enableaaa accounting acct-stop on-aaa-failure enableaaa accounting acct-stop on-access-deny disableaaa subscriber limit per-vr 0aaa intf-desc-format include sub-intf enableaaa intf-desc-format include adapter enableaaa accounting immediate-update disable!! ==============================================================================!virtual-router lacno aaa accounting duplicationno aaa accounting broadcastaaa duplicate-address-check enableaaa accounting acct-stop on-aaa-failure enableaaa accounting acct-stop on-access-deny disableaaa subscriber limit per-vr 0aaa intf-desc-format include sub-intf enableaaa intf-desc-format include adapter enableaaa accounting immediate-update disable!! ==============================================================================!virtual-router ispno aaa accounting duplicationno aaa accounting broadcastaaa duplicate-address-check enableaaa accounting acct-stop on-aaa-failure enableaaa accounting acct-stop on-access-deny disableaaa subscriber limit per-vr 0aaa intf-desc-format include sub-intf enableaaa intf-desc-format include adapter enableaaa accounting immediate-update disableshow cops info
- Use to display information about the COPS layer over which the SRC connection is made.
- Field descriptions
- Session CreatedNumber of COPS sessions created
- Sessions DeletedNumber of COPS sessions deleted
- Current SessionsNumber of current COPS sessions
- Bytes ReceivedNumber of bytes received on all COPS sessions
- Packets ReceivedNumber of packets received on all COPS sessions
- Bytes SentNumber of bytes transmitted on all COPS sessions
- Packets SentNumber of packets transmitted on all COPS sessions
- Keep Alive ReceivedNumber of COPS keepalive messages received
- Keep Alive SentNumber of COPS keepalive messages sent
- Remote IP AddressIP address of the remote peer
- Remote TCP PortTCP port number of the remote peer
- Client TypeType of client for the session. For this release the client type must be 16640 (SRC client).
- Bytes ReceivedNumber of bytes received for this COPS session
- Packets ReceivedNumber of packets received for this COPS session
- Bytes SentNumber of bytes sent on this COPS session
- Packets SentNumber of packets sent on this COPS session
- REQ SentNumber of Request packets sent on this COPS session
- DEC RcvNumber of Decision packets received on this COPS session
- RPT SentNumber of Report packets sent on this COPS session
- DRQ SentNumber of Delete Requests sent on this COPS session
- SSQ RcvNumber of Synch Requests received on this COPS session
- OPN SentNumber of Open messages sent on this COPS session
- CAT RcvNumber of Client Accepts packets received on this COPS session
- CC SentNumber of Client Closes packets sent on this COPS session
- CC RcvNumber of Client Closes packets received on this COPS session
- SSC SentNumber of Sync Complete packets sent on this COPS session
host1#show cops infoGeneral Cops Information:Sessions Created: 1Sessions Deleted: 0Current Sessions: 1Bytes Received: 680Packets Received: 17Bytes Sent: 692Packets Sent: 21Keep Alive Received: 12Keep Alive Sent: 12Session InformationRemote Ip Address: 10.10.0.223Remote TCP Port: 4001Client Type: 16384Bytes Received: 2224Packets Received: 5Bytes Sent: 596Packets Sent: 9REQ Sent: 4DEC Rcv: 4RPT Sent: 4DRQ Sent: 0SSQ Rcv: 0OPN Sent: 1CAT Rcv: 1CC Sent: 0CC Rcv: 0SSC Sent: 0show cops statistics
- Use to display statistics about the COPS layer over which the SRC connection is made.
- Field descriptions
- Session CreatedNumber of COPS sessions created
- Sessions DeletedNumber of COPS sessions deleted
- Current SessionsNumber of current COPS sessions
- Bytes ReceivedNumber of bytes received on all COPS sessions
- Packets ReceivedNumber of packets received on all COPS sessions
- Bytes SentNumber of bytes transmitted on all COPS sessions
- Packets SentNumber of packets transmitted on all COPS sessions
- Keep Alive ReceivedNumber of COPS keepalive messages received
- Keep Alive SentNumber of COPS keepalive messages sent
- Client TypeType of client for the session.
- Bytes ReceivedNumber of bytes received for this COPS session
- Packets ReceivedNumber of packets received for this COPS session
- Bytes SentNumber of bytes sent on this COPS session
- Packets SentNumber of packets sent on this COPS session
- REQ SentNumber of Request packets sent on this COPS session
- DEC RcvNumber of Decision packets received on this COPS session
- RPT SentNumber of Report packets sent on this COPS session
- DRQ SentNumber of Delete Requests sent on this COPS session
- SSQ RcvNumber of Synch Requests received on this COPS session
- OPN SentNumber of Open messages sent on this COPS session
- CAT RcvNumber of Client Accepts packets received on this COPS session
- CC SentNumber of Client Closes packets sent on this COPS session
- CC RcvNumber of Client Closes packets received on this COPS session
- SSC SentNumber of Sync Complete packets sent on this COPS session
host1#show cops statisticsGeneral Cops Information:Sessions Created: 0Sessions Deleted: 0Current Sessions: 0Bytes Received: 1108Packets Received: 12Bytes Sent: 1572Packets Sent: 18Keep Alive Received: 2Keep Alive Sent: 2Session Information:Client Type: 24754Bytes Received: 2539032Packets Received: 20388Bytes Sent: 4386648Packets Sent: 51337REQ Sent: 21203DEC Rcv: 20388RPT Sent: 20391DRQ Sent: 9743SSQ Rcv: 0OPN Sent: 0CAT Rcv: 0CC Sent: 0CC Rcv: 0SSC Sent: 0show ip local alias
- Use to display information about aliases for the local address pools configured on your router.
- If you do not specify an alias, the router displays all aliases.
- Field descriptions
host1#show ip local aliasAlias Pool------ -----alias1 poolAalias2 poolBalias3 poolCpoolA poolDpoolB poolDpoolC poolDshow ip local pool
- Use to display information about the local address pools configured on your router.
- If you do not specify the name of a local address pool, the router displays all local address pools.
- Field descriptions
- PoolUser-specified name of the address pool
- High ThreshHigh utilization threshold value
- Abated ThreshAbated utilization threshold value
- TrapEnable SNMP pool utilization traps: Y (yes) or N (no)
- AliasesAliases for the local address pool
- BeginStarting IP address
- EndEnding IP address
- FreeNumber of addresses available for use
- In UseNumber of addresses currently in use
host1#show ip local poolHigh AbatedPool Thresh Thresh Trap Group----- ------ ------ ---- -----poolA 85 75 NAliases-------alias1InBegin End Free Use-------- --------- ---- ---10.1.1.1 10.1.1.10 10 010.1.2.1 10.1.2.10 10 010.1.3.1 10.1.3.10 10 0High AbatedPool Thresh Thresh Trap Group----- ------ ------ ---- -----poolB 85 75 NAliases-------alias2InBegin End Free Use-------- --------- ---- ---10.2.1.1 10.2.1.10 10 010.2.2.1 10.2.2.10 10 0High AbatedPool Thresh Thresh Trap Group----- ------ ------ ---- -----poolC 85 75 NAliases-------alias3InBegin End Free Use-------- --------- ---- ---10.3.1.1 10.3.1.10 10 0High AbatedPool Thresh Thresh Trap Group----- ------ ------ ---- -----poolD 85 75 NAliases-------poolApoolBpoolCInBegin End Free Use-------- ---------- ---- ---10.4.1.1 10.4.1.255 255 0show ip local pool statistics
- Use to display local address pool statistics.
- Use the optional delta keyword to specify that baselined statistics are to be shown.
- Example
host1#show ip local pool statisticsLocal Address Pool StatisticsStatistic Values--------------------------------- ------Requests denied (pool exhaustion) 0show ip local shared-pool
- Shared PoolName of the shared local address pool
- In UseNumber of addresses allocated
- Dhcp PoolName of the DHCP address pool
host1#show ip local shared-poolShared Pool In Use Dhcp Pool----------- ------ ---------shared_poolA 253 dhcp_pool_25shared_poolB 83 dhcp_pool_25shared_poolC 99 dhcp_pool_17show ip route
- Use to display the current state of the routing table, including routes not used for forwarding.
- An Access-P entry in the Type column of the output indicates routes that are downloaded by the RADIUS route-download server.
- Refer to the description of the show ip route command in JUNOSe IP, IPv6, and IGP Configuration Guide, Chapter 1, Configuring IP for additional information about the show ip route command.
host1#show ip routeProtocol/Route type codes:I1- ISIS level 1, I2- ISIS level2,I- route type intra, IA- route type inter, E- route type external,i- metric type internal, e- metric type external,P- periodic download, O- OSPF, E1- external type 1, E2- external type2,N1- NSSA external type1, N2- NSSA external type2L- MPLS label, V- VRF, *- via indirect next-hopPrefix/Length Type Next Hop Dst/Met Interface------------------ --------- --------------- ---------- -----------------0.0.0.0/0 Static 10.13.10.1 1/0 FastEthernet6/0/0192.168.10.0/23 Connect 10.13.10.187 0/0 FastEthernet6/0/0192.168.21.21/32 Access-P 255.255.255.255 254/2 null0192.168.22.22/32 Access-P 255.255.255.255 254/2 null0192.168.23.23/32 Access-P 255.255.255.255 254/2 null0192.168.24.24/32 Access-P 255.255.255.255 254/2 null0show license b-ras
host1#show license b-rasK4bZ16Lrshow radius algorithm
host1#show radius algorithmdirectshow radius override
- nas-ip-addrEither the NAS-IP-Address [4] attribute is used, or it is overridden with the Tunnel-Client-Endpoint [66] attribute.
- nas-infoEither the NAS-IP-Address [4] and NAS-Identifier [32] attributes of the virtual router generating the accounting information are used, or they are overridden with the respective attributes of the authentication virtual router.
host1:vrXyz7#show radius overridenas-ip-addr: nas-ip-addrnas-info: from authentication virtual routershow radius rollover-on-reject
host1#show radius rollover-on-rejectrollover-on-reject enabledshow radius servers
- Use to display RADIUS server information.
- Use with the optional accounting, authentication, dynamic-request, route-download, or pre-authentication keywords to limit output to the specific type of server.
- Field descriptions
- IP AddressIP address of RADIUS server
- Udp PortNumber of the UDP port of the RADIUS server
- Retry CountMaximum number of times that the router retransmits a RADIUS packet to the RADIUS server
- TimeoutInterval (in seconds) before the router retransmits a RADIUS packet to the RADIUS server
- Maximum SessionsNumber of outstanding requests to the RADIUS server
- Dead TimeAmount of time to remove the authentication server or accounting server from the available list when a timeout occurs
- SecretConfigured authentication server or accounting server secret
host1#show radius serversRADIUS Authentication Configuration-----------------------------------Udp Retry Maximum DeadIP Address Port Count Timeout Sessions Time Secret------------- ---- ----- ------- -------- ---- ------172.28.30.117 1812 3 3 255 0 radiusRADIUS Accounting Configuration-------------------------------Udp Retry Maximum DeadIP Address Port Count Timeout Sessions Time Secret------------- ---- ----- ------- -------- ---- ------172.28.30.117 1813 3 3 255 0 radiusRADIUS Pre-Authentication Configuration---------------------------------------Udp Retry Maximum DeadIP Address Port Count Timeout Sessions Time Secret------------- ---- ----- ------- -------- ---- ------172.28.30.117 1812 3 3 255 0 radiusRADIUS Route-Download Configuration-----------------------------------Udp Retry Maximum DeadIP Address Port Count Timeout Sessions Time Secret------------- ---- ----- ------- -------- ---- ------192.168.30.16 1812 3 3 255 0 radiusshow radius statistics
- Use to display statistics on RADIUS services.
- Use with the optional accounting, authentication, dynamic-request, route-download, or pre-authentication keywords to limit output to the specific type of statistics.
- Use the optional delta keyword to specify that baselined statistics are to be shown.
- Field descriptions
NOTE: All descriptions apply to the primary, secondary, and tertiary RADIUS authentication and accounting servers.
- UDP PortNumber of the UDP port of a RADIUS server
- Round Trip TimeHundreds of seconds from request to response
- Access RequestsNumber of access requests sent to server
- Rollover RequestsNumber of requests coming into server as a result of the previous server timing out
- RetransmissionsNumber of retransmissions
- Access AcceptsNumber of Access-Accepts received from the server
- Access RejectsNumber of Access-Rejects received from the server
- Access ChallengesNumber of access challenges received from the server
- Malformed ResponsesNumber of responses with attributes having an invalid length or unexpected attributes (such as two attributes when the response is required to have at most one)
- Bad AuthenticatorsNumber of responses in which the authenticator is incorrect for the matching request. This can occur if the RADIUS secret for the client and server does not match.
- Requests PendingNumber of requests waiting for a response
- Request TimeoutsNumber of requests that timed out
- Unknown ResponsesNumber of unknown responses. The RADIUS response type in the header is invalid or unsupported.
- Packets DroppedNumber of packets dropped either because they are too short or the E-series router receives a response for which there is no corresponding request. For example, if the router sends a request and the request times out, the router removes the request from the list and sends a new request. If the server is slow and sends a response to the first request after the router removes the request, the packet is dropped.
- RequestsTotal number of accounting requests sent, which is the combined total of Start Requests, Interim Requests, Stop Requests, and Reject Requests
- Start RequestsNumber of accounting start requests sent; includes Acct-On, Acct-Start, Acct-Link-State, and Acct-Tunnel-Start requests
- Interim RequestsNumber of interim accounting requests
- Stop RequestsNumber of accounting stop requests sent; includes Acct-Off, Acct-Stop, Acct-Link-Stop, and Acct-Tunnel-Stop requests
- Reject RequestsNumber of accounting reject requests sent; includes Acct-Link-Reject and Acct-Tunnel-Reject requests
- ResponsesNumber of accounting responses received from the server
- Start ResponsesNumber of accounting start responses received; includes Acct-On, Acct-Start, Acct-Link-Start, and Acct-Tunnel-Start responses
- Interim ResponsesNumber of interim accounting responses
- Stop ResponsesNumber of accounting stop responses received; includes Acct-Off, Acct-Stop, Acct-Link-Stop, and Acct-Tunnel-Stop responses
- Reject ResponsesNumber of accounting reject responses received; includes Acct-Link-Reject and Acct-Tunnel-Reject responses
host1#show radius statisticsRADIUS Authentication Statistics--------------------------------Statistic 10.10.121.128------------------- -------------UDP Port 1812Round Trip Time 0Access Requests 0Rollover Requests 0Retransmissions 0Access Accepts 0Access Rejects 0Access Challenges 0Malformed Responses 0Bad Authenticators 0Requests Pending 0Request Timeouts 0Unknown Responses 0Packets Dropped 0RADIUS Accounting Statistics----------------------------Statistic 10.10.121.128------------------- -------------UDP Port 1646Round Trip Time 2Requests 1Start Requests 1Interim Requests 0Stop Requests 0Reject Requests 0Rollover Requests 0Retransmissions 3Responses 1Start Responses 1Interim Responses 0Stop Responses 0Reject Responses 0Malformed Responses 0Bad Authenticators 0Requests Pending 0Request Timeouts 3Unknown Responses 0Packets Dropped 0Example 2 host1#show radius pre-authentication statisticsRADIUS Pre-Authentication Statistics------------------------------------Statistic 172.28.30.117------------------- -------------UDP Port 1812Round Trip Time 0Access Requests 2809Rollover Requests 0Retransmissions 56Access Accepts 2809Access Rejects 0Access Challenges 0Malformed Responses 0Bad Authenticators 0Requests Pending 0Request Timeouts 72Unknown Responses 0Packets Dropped 2Example 3 host1#show radius route-download statisticsRADIUS Route-Download Statistics--------------------------------Statistic 192.168.30.16------------------- -------------UDP Port 1812Round Trip Time 0Access Requests 1613Rollover Requests 0Retransmissions 6Access Accepts 1612Access Rejects 1Access Challenges 0Malformed Responses 0Bad Authenticators 0Requests Pending 0Request Timeouts 6Unknown Responses 0Packets Dropped 5show radius trap
host1#show radius traptrap for auth-server-not-responding enabledtrap for no-auth-server-responding disabledtrap for auth-server-responding enabledtrap for acct-server-not-responding enabledtrap for no-acct-server-responding disabledtrap for acct-server-responding disabledshow radius tunnel-accounting
host1#show radius tunnel-accountingdisabledshow radius udp-checksum
host1#show radius udp-checksumenabledshow radius update-source-addr
host1#show radius update-source-address192.168.1.228show sscc info
- Use to display the current status of the SRC client connection to the SAEs. The command output refers to the SRC client by its former name, SSC client.
- Field descriptions
- The SSC client configured serversIP addresses of the primary, secondary, and tertiary SAEs
- Local SourceFixed source interface for the TCP/COPS connection
- Local Source AddressFixed source address for the TCP/COPS connection
- The configured transport router isRouter on which is TCP/COPS connection is established
- The configured retry timer is (seconds)Delay period the client waits for a response from the SAE before submitting request again
- The connection state isCurrent state of the TCP/COPS connection
- SSC Client StatisticsStatistics about the connection between the SRC client and SAE
- Policy Commands receivedNumber of policy commands received on the SRC client connection
- Policy Commands(List)Number of Policy Commands with subtype List
- Policy Commands(Acct)Number of Policy Commands with subtype Accounting
- Bad Policy Cmds receivedNumber of Policy Commands received with bad policies
- Error Policy Cmds receivedNumber of Policy Commands received with errors
- Policy Reports sentNumber of Policy Reports sent
- Connection Open requestsNumber of connections the SRC client has tried to open with a remote SAE
- Connection Open completedNumber of connections successfully open to the SAE
- Connection Closed sentNumber of connections the SRC client has closed
- Connection Closed remotelyNumber of connections that were closed by the remote SAE
- Create Interfaces sentNumber of create interface indications sent to the SAE
- Delete Interfaces sentNumber of delete interface indications sent to the SAE
- Active IP InterfacesCurrent number of active IP interfaces the SRC client is aware of
- IP Interface TransitionsNumber of IP interface transitions logged by the SRC client
- Synchronizes receivedNumber of synchronization requests the SRC client received from the SAE
- Synchronize Complete sentNumber of synchronization complete indications sent
- Internal ErrorsNumber of internal errors
- Communication ErrorsNumber of errors with lower-layer communications (such as socket errors)
host1#show sscc infoThe SSC Client is currently unconnectedThe SSC Client configured servers are:Primary: 10.10.2.2:3Secondary: 0.0.0.0:0Tertiary: 0.0.0.0:0Local Source: FastEthernet 0/0, Local Source Address: 10.13.5.61The configured transport router is: defaultThe configured retry timer is (seconds): 90The connection state is: NoConnectionSSC Client Statistics:Policy Commands received 0Policy Commands(List) 0Policy Commands(Acct) 0Bad Policy Cmds received 0Error Policy Cmds received 0Policy Reports sent 0Connection Open requests 0Connection Open completed 0Connection Closed sent 0Connection Closed remotely 0Create Interfaces sent 0Delete Interfaces sent 0Active IP Interfaces 2IP Interface Transitions 0Synchronizes received 0Synchronize Complete sent 0Internal Errors 0Communication Errors 0Tokens Seen 0Active Tokens 0Token Transitions 0Token Creates Sent 0Token Deletes Sent 0Active Addresses 0Address Transitions 0Create Addresses Sent 0Delete Addresses Sent 0Authentication Successes 0Authentication Failures 0show sscc statistics
- Use to display statistics about connection between the SRC client and SAE. The command output refers to the SRC client by its former name, SSC client.
- Field descriptions
- Policy Commands receivedNumber of policy commands received on the SRC client connection
- Policy Commands(List)Number of Policy Commands with subtype List
- Policy Commands(Acct)Number of Policy Commands with subtype Accounting
- Bad Policy Cmds receivedNumber of Policy Commands received with bad policies
- Error Policy Cmds receivedNumber of Policy Commands received with errors
- Policy Reports sentNumber of Policy Reports sent
- Connection Open requestsNumber of connections the SRC client has tried to open with a remote SAE
- Connection Open completedNumber of connections successfully open to the SAE
- Connection Closed sentNumber of connections the SRC client has closed
- Connection Closed remotelyNumber of connections that were closed by the remote SAE
- Create Interfaces sentNumber of create interface indications sent to the SAE
- Delete Interfaces sentNumber of delete interface indications sent to the SAE
- Active IP InterfacesCurrent number of active IP interfaces the SRC client is aware of
- IP Interface TransitionsNumber of IP interface transitions logged by the SRC client
- Synchronizes receivedNumber of synchronization requests the SRC client received from the SAE
- Synchronize Complete sentNumber of synchronization complete indications sent
- Internal ErrorsNumber of internal errors
- Communication ErrorsNumber of errors with lower-layer communications (such as socket errors)
host1#show sscc statisticsSSC Client Statistics:Policy Commands received 0Policy Commands(List) 0Policy Commands(Acct) 0Bad Policy Cmds received 0Error Policy Cmds received 0Policy Reports sent 3Connection attempts 7Connection Open requests 7Connection Open completed 0Connection Closed sent 0Connection Closed remotely 5Create Interfaces sent 0Delete Interfaces sent 3Active IP Interfaces 3282IP Interface Transitions 3281Synchronizes received 0Synchronizes rcvd & droped 0Synchronize Complete sent 2Internal Errors 0Communication Errors 0Discovers Seen 15263Active Discovers 4911Discover Transitions 20704Discover Creates Sent 15263Discover Deletes Sent 10352Active Addresses 3274Address Transitions 3280Create Addresses Sent 3277Delete Addresses Sent 3show sscc version
host1#show sscc versionThe SSC Client version is: 4.0show subscribers
- Use to display the active subscribers on the router.
- If you specify a username, the router displays only the users that match.
- When you issue the command in the default VR, all users are displayed. When you issue the command in a nondefault VR, only those users attached to that VR are displayed.
- You can use the domain, interface, port, slot, username, or virtual-router keywords on all routers to filter the results. If you do not use a keyword, all active users are displayed.
- When you use the interface keyword to display detailed subscriber information by interface, you must also specify either the atm or ethernet keyword, an interface specifier, and optionally a subinterface specifier.
- The output displayed in the interface field depends on the configuration of two commands at the time the subscriber logs in: aaa intf-desc-format include sub-intf and aaa intf-desc-format include adapter (for the E120 and E320 routers).
When the aaa intf-desc-format include sub-intf disable command has been issued, the subinterface is stripped from the subscriber's interface field at login and is not displayed in the output. In the default state, or when the aaa intf-desc-format include sub-intf enable command has been issued, the subinterface is included in the subscriber's interface field at login, and is displayed in the output.
When the aaa intf-desc-format include adapter disable command has been issued, the adapter is stripped from the subscriber's interface field at login and is not displayed in the output. In the default state, or when the aaa intf-desc-format include adapter enable command has been issued, the adapter is included in the subscriber's interface field at login and is displayed in the output.
Even when the subinterface has been stripped from the subscriber's interface field, you can still include the subinterface specifier in the show subscribers interface command. Even though the subinterface itself is not displayed, only subscribers on the specified subinterface are displayed.
These considerations do not apply when you issue the summary keyword. The output displayed in the Interface field of summary versions is not affected by the state of either the aaa intf-desc-format include sub-intf command or the aaa intf-desc-format include adapter command when the subscriber logs in.
- You can use the ipv6 keyword to display all IPv6 subscribers or include the IPv6 prefix to limit the display to only IPv6 subscribers on a specific network.
- You can use the summary keyword to display only summary information about active subscribers.
- Field descriptions
- User NameName of the subscriber
- TypeType of subscriber: atm, ip, ipsec, ppp, tnl (tunnel), tst (test)
- Addr | EndptIP or IPv6 address and source of the address: l2tp, local, dhcp, radius, user. For local, dhcp, radius, and user endpoints, the address is that of the user. When the endpoint is l2tp, the address is that of the LNS.
- Virtual RouterName of the virtual router context
- InterfaceInterface specifier over which the subscriber is connected
- Login TimeDate, in YY/MM/DD format, and time the subscriber logged in
- Circuit IdUser circuit ID value specified by PPPoE
- Remote IdUser remote ID value specified by PPPoE
- Total SubscribersNumber of active subscribers, chassis-wide
- Peak SubscribersMaximum value of the Total Subscriber field during the time the router has been active, chassis-wide
- SubscribersNumber of subscribers; the sum of the Ppp and Ip fields
- PppNumber of PPPoA and PPPoE users, combined
- IpNumber of DHCP and IP subscriber manager users, combined
- TnlNumber of users tunneled to an LNS
- TotalTotal number of users per virtual router; the sum of the Ppp, Ip, and Tnl fields
- Domain NameDomain name used by the subscriber
- CountNumber of subscribers
- SlotNumber of slot in the chassis
host1#show subscribersSubscriber List----------------VirtualUser Name Type Addr|Endpt Router----------------------- ----- -------------------- ------------fred tst 10.10.65.86/radius defaultbert tst 192.168.10.3/user defaultUser Name Interface----------------------- --------------------------------fred atm 2/1.42:100.104bert FastEthernet 5/2.4User Name Login Time Circuit Id----------------------- ------------------- ----------------fred 06/05/12 10:58:42 atm 5/1.3bert 06/05/12 10:59:08User Name Remote Id----------------------- ----------------fredbert (800) 555-1212host1#show subscribers interface ethernet 5/2Subscriber List---------------VirtualUser Name Type Addr|Endpt Router------------------------ ----- -------------------- ------------bert tst 192.168.10.3/user defaultUser Name Interface------------------------ --------------------------------bert FastEthernet 5/2.4User Name Login Time Circuit Id------------------------ ------------------- ----------------bert 06/05/12 10:59:08User Name Remote Id----------------------- ----------------bert (800) 555-0000host1#show subscribers slot 5Subscriber List---------------VirtualUser Name Type Addr|Endpt Router------------------------ ----- -------------------- ------------fred tst 10.10.65.86/radius defaultUser Name Interface------------------------ --------------------------------fred atm 5/1.42:100.104User Name Login Time Circuit Id------------------------ ------------------- ----------------fred 06/05/12 10:58:42 atm 5/1.3User Name Remote Id----------------------- ----------------fred
- Example 4Shows the number of subscribers on each virtual router, as well as the total and peak subscribers for the chassis
host1#show subscribers summaryVirtualRouter Subscribers Ppp Ip Tnl Total------------ ------------ ------ ------ ------ ------default 1 1 0 0 1Total Subscribers : 10 (chassis-wide total)Peak Subscribers : 15 (chassis-wide total)Example 5Shows the number of subscribers on each port host1#show subscribers summary portInterface Count------------ ------3/1 52/1 5Total Subscribers : 10 (chassis-wide total)Peak Subscribers : 15 (chassis-wide total)Example 6Shows the number of subscribers by domain name host1#show subscribers summary domainDomain Name Count-------------------------------- ------abc.com 5iii.com 5Total Subscribers : 10 (chassis-wide total)Peak Subscribers : 15 (chassis-wide total)Example 7Shows the number of subscribers by interface host1#show subscribers summary interfaceInterface Count-------------------- ------ATM 3/2.1 1ETHERNET 5/2.1 2Total Subscribers : 3 (chassis-wide total)Peak Subscribers : 6 (chassis-wide total)Example 8Shows the number of subscribers by slot host1#show subscribers summary slotSlot Count-------- -----3 15 4Total Subscribers : 5 (chassis-wide total)Peak Subscribers : 8 (chassis-wide total)show terminate-code
- AppsThe application generating the terminate reason; AAA, L2TP, PPP, or RADIUS client
- Terminate ReasonThe application's terminate reason
- DescriptionThe terminate reason
- Radius CodeThe RADIUS Acct-Terminate-Cause code to which the application's terminate reason is mapped
- Example 1Specifies the radius keyword to display all current terminate reasons mapped to RADIUS Acct-Terminate-Cause codes. This command lists all PPP mappings, followed by L2TP mappings, and then AAA mappings.
host1(config)#run show terminate-code radiusRadiusApps Terminate Reason Description Code--------- -------------------------- -------------------------- ------ppp authenticate-authenticator authenticate authenticator 17-timeout timeoutppp authenticate-challenge-tim authenticate challenge tim 10eout eoutppp authenticate-chap-no-resou authenticate chap no resou 10rces rcesppp authenticate-chap-peer-aut authenticate chap peer aut 17henticator-timeout henticator timeoutppp authenticate-deny-by-peer authenticate deny by peer 17ppp authenticate-inactivity-ti authenticate inactivity ti 4meout meoutppp authenticate-max-requests authenticate max requests 10--More--Example 2Specifies the radius keyword and a RADIUS Acct-Terminate-Cause code to display all terminate reasons mapped to the specified terminate code. The following example uses radius 4 as the terminate code. host1(config)#run show terminate-code radius 4RadiusApps Terminate Reason Description Code--------- -------------------------- -------------------------- ------ppp authenticate-inactivity-ti authenticate inactivity ti 4meout meoutl2tp session-timeout-inactivity session timeout inactivity 4Example 3Specifies an application to show all current mappings for the particular application's terminate reasons. This example uses aaa as the application. host1(config)#run show terminate-code aaaRadiusApps Terminate Reason Description Code--------- -------------------------- -------------------------- ------aaa deny-server-not-available deny server not available 17aaa deny-server-request-timeou deny server request timed 17t outaaa deny-authentication-failur deny authentication failur 17e e from serveraaa deny-address-assignment-fa deny address assignment fa 17ilure ilureaaa deny-address-allocation-fa deny address allocation fa 17ilure ilureaaa deny-no-address-allocation deny insufficient resource 17-resources s for address allocationaaa deny-unknown-subscriber deny no such server entry 17aaa deny-no-resources deny no resources availabl 10e--More--Example 4Specifies an application and terminate reason to show the mapping for a specific terminate reason. This example uses l2tp as the application and session-access-interface-down as the terminate reason. host1(config)#run show terminate-code l2tp session-access-interface-downRadiusTerminate Reason Description Code------------------------------------------------------------ ------session access interface down 8