Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

877 LAN issue 7

Not open for further replies.


Aug 30, 2007
Just got a 877 off of eBay (which might be part of the problem).

Most of the items were in sealed bags and looked new. Even the faceplate had the plastic film.

I followed the documentation to the letter, cabled the connections to the correct prots and double checked. Powered up the router. Got an OK light and eventually got a Carrier Detect light. I removed the PC ethernet cable from an operational switch and plugged it into FE0. PC indicated that the cable was unplugged and the ethernet light for LAN 0 did not come on. I tried with the other ports with similar results, the PC continued to indicate the cable was unplugged. I changed cables and tried the procedure again. Nothing, even after power cycle. I powered down the router disconnected all the connections, held in the reset button and powered-up the router. I held in the reset button for about 10 seconds while the router was under power. I waited about two minutes then powered down the router and plugged in the connections. Router came up, got OK and carrier detect, but not did not connect through the LAN.

I don't have a PC with a serial port or I would have connected to the console port to get more information.

Did I miss something? Is there something I can do to get the LAN side working so I can complete the set-up?

Or does this particular unit have a dead switch?
did you try connecting with a cross over cable instead of straight thru? That is most likely the issue.
If I put a port autosensing switch between the two, would that fix the problem?
OK, a little progress....

I got a console working. Noticed that the LAN is working during initial boot. Shortly after boot, the LAN drops and the message displays asking whether I want to enter initial set-up. Any response starts the LAN again, but Carrier Detect drops.

When LAN is restored again, I cannot access via SDM. (PC configured with fixed IP address mask

I think what may be needed is an initial set-up. I'll try a few things tomorrow to see if I can get enough of an initial set-up going so that I can run SDM.

(I'm NOT very technical, but I'm going to at least give it a try....)

router#sh ip int bri

Post that...we can show you how to assign an IP address and bring the interface up with the "no shut" command...

Actually, go ahead and post a sh run. I am not familiar with that router interface names...

Nothing connected except power and console. Boot, then sh run, then sh ip int bri:

System Bootstrap, Version 12.3(8r)YI4, RELEASE SOFTWARE
Technical Support: Copyright (c) 2006 by cisco Systems, Inc.

C870 series (Board ID: 1-148) platform with 131072 Kbytes of main memory

Booting flash:/c870-advipservicesk9-mz.124-6.T6.bin
Self decompressing the image : #################################################
################################################# [OK]

Restricted Rights Legend

Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

cisco Systems, Inc.
170 West Tasman Drive
San Jose, California 95134-1706

Cisco IOS Software, C870 Software (C870-ADVIPSERVICESK9-M), Version 12.4(6)T6, R
Technical Support: Copyright (c) 1986-2006 by Cisco Systems, Inc.
Compiled Fri 08-Dec-06 22:44 by kellythw
Image text-base: 0x8002008C, data-base: 0x81A9383C

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:

If you require further assistance please contact us by sending email to

Installed image archive
Cisco 877 (MPC8272) processor (revision 0x300) with 118784K/12288K bytes of memo
Processor board ID FHK1219298B
MPC8272 CPU Rev: Part Number 0xC, Mask Number 0x10
4 FastEthernet interfaces
1 ATM interface
128K bytes of non-volatile configuration memory.
24576K bytes of processor board System flash (Intel Strataflash)

--- System Configuration Dialog ---

Would you like to enter the initial configuration dialog? [yes/no]: no

Press RETURN to get started!

*Mar 1 00:00:05.303: %VPN_HW-6-INFO_LOC: Crypto engine: onboard 0 State change
d to: Initialized
*Mar 1 00:00:05.363: %VPN_HW-6-INFO_LOC: Crypto engine: onboard 0 State change
d to: Enabled
*Mar 1 00:00:09.479: %LINK-3-UPDOWN: Interface FastEthernet0, changed state to
*Mar 1 00:00:09.887: %PARSER-4-BADCFG: Unexpected end of configuration file.

*Mar 1 00:00:10.479: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthern
et0, changed state to up
*Mar 1 00:01:02.215: %LINK-5-CHANGED: Int
Router>erface ATM0, changed state to administratively down
*Mar 1 00:01:03.215: %LINEPROTO-5-UPDOWN: Line protocol on Interface ATM0, chan
ged state to down
*Mar 5 01:04:42.399: %SYS-5-RESTART: System restarted --
Cisco IOS Software, C870 Software (C870-ADVIPSERVICESK9-M), Version 12.4(6)T6, R
Technical Support: Copyright (c) 1986-2006 by Cisco Systems, Inc.
Compiled Fri 08-Dec-06 22:44 by kellythw
*Mar 5 01:04:42.399: %SNMP-5-COLDSTART: SNMP agent on host Router is undergoing
a cold start
*Mar 5 01:04:42.475: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is OFF
*Mar 5 01:04:43.983: %LINK-3-UPDOWN: Interface FastEthernet3, changed state to
*Mar 5 01:04:43.987: %LINK-3-UPDOWN: Interface FastEthernet2, changed state to
*Mar 5 01:04:43.991: %LINK-3-UPDOWN: Interface FastEthernet1, changed state to
*Mar 5 01:04:43.995: %LINK-3-UPDOWN: Interface FastEthernet0, changed state to
*Mar 5 01:04:44.983: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthern
et3, changed state to down
*Mar 5 01:04:44.987: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthern
et2, changed state to down
*Mar 5 01:04:44.991: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthern
et1, changed state to down
*Mar 5 01:04:44.995: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthern
et0, changed state to down

Router#sh run
Building configuration...

Current configuration : 738 bytes
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname Router
no aaa new-model
resource policy
ip cef
interface ATM0
no ip address
no atm ilmi-keepalive
dsl operating-mode auto
interface FastEthernet0
interface FastEthernet1
interface FastEthernet2
interface FastEthernet3
interface Vlan1
no ip address
no ip http server
no ip http secure-server
line con 0
no modem enable
line aux 0
line vty 0 4
scheduler max-task-time 5000
webvpn context Default_context
ssl authenticate verify all
no inservice


Router#sh ip int bri
Interface IP-Address OK? Method Status Prot
FastEthernet0 unassigned YES unset up down

FastEthernet1 unassigned YES unset up down

FastEthernet2 unassigned YES unset up down

FastEthernet3 unassigned YES unset up down

ATM0 unassigned YES unset administratively down down

Vlan1 unassigned YES unset up down

router#conf t
router(config)#username bla priv 15 secret blabla

Replace "bla" and blabla" with your own, "bla" being the user name and "blabla" being the password---this will be used for SDM...

router(config)#ip http server
router(config)#ip http authen local
router(config)#int vlan1
router(config-if)#ip add
router(config-if)#no shut

This will let you have access to SDM. Just connect a straight-through cable (NOT crossover) cable from one of the fa ports of the router to a computer, and make the computer's IP address in the same subnet ( through, so long as you don't duplicate an IP address, like a printer or something). We can show you how to completely configure this router---it is for ADSL, not cable, by the way...

SDM seems to want to connect to . Will this config work OK or should we use:

router(config-if)#ip add

(Not questioning your code, just questioning my understanding of how this should work.)

I tried a couple of variations of the commands provided and finally got one that let me access the router via SDM. The router assigns addresses to the PC, it seems to get a carrier detect on the DSL/POTS line (light on router face is on), SDM seems to be accessing the router functions.

I think its close. I suspect that the DSL login set-up is not working correctly, it doesn't seem like the router is getting logged on. I'm not getting an IP address on the WAN side.

The router is displaying some messages that might point to part of the problem.

Any ideas?

sensitive information replaced by "[removed]"

sh run and error messages follow:

Building configuration...

Current configuration : 1696 bytes
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname Router
no logging buffered
no aaa new-model
resource policy
ip cef
no ip dhcp use vrf connected
ip dhcp excluded-address
ip dhcp pool client
ip ddns update method sdm_ddns1
DDNS both
username [removed] privilege 15 secret 5 $1$Tpvp$b2qcB4gjR.h4K1RXaAzgj1
interface ATM0
no ip address
no atm ilmi-keepalive
dsl operating-mode auto
interface ATM0.1 point-to-point
no snmp trap link-status
pvc 0/35
pppoe-client dial-pool-number 1
interface FastEthernet0
interface FastEthernet1
interface FastEthernet2
interface FastEthernet3
interface Vlan1
ip address
ip nat inside
ip virtual-reassembly
ip tcp adjust-mss 1412
interface Dialer0
ip address dhcp
ip mtu 1452
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication chap callin
ppp chap hostname [removed]
ppp chap password 0 [removed]
ip http server
ip http authentication local
no ip http secure-server
ip nat inside source list 1 interface Dialer0 overload
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit
dialer-list 1 protocol ip permit
line con 0
no modem enable
line aux 0
line vty 0 4
scheduler max-task-time 5000
webvpn context Default_context
ssl authenticate verify all
no inservice


*Mar 5 01:05:19.591: %DIALER-6-BIND: Interface Vi1 bound to profile Di0
*Mar 5 01:05:19.599: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t
o up
*Mar 5 01:05:21.871: %DIALER-6-UNBIND: Interface Vi1 unbound from profile Di0
*Mar 5 01:05:21.875: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t
o down
*Mar 5 01:05:44.159: %DIALER-6-BIND: Interface Vi1 bound to profile Di0
*Mar 5 01:05:44.163: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t
o up
*Mar 5 01:05:46.423: %DIALER-6-UNBIND: Interface Vi1 unbound from profile Di0
*Mar 5 01:05:46.427: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t
o down
*Mar 5 01:06:08.503: %DIALER-6-BIND: Interface Vi1 bound to profile Di0
*Mar 5 01:06:08.511: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t
o up
*Mar 5 01:06:10.799: %DIALER-6-UNBIND: Interface Vi1 unbound from profile Di0
*Mar 5 01:06:10.803: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t
o down
*Mar 5 01:06:33.075: %DIALER-6-BIND: Interface Vi1 bound to profile Di0
*Mar 5 01:06:33.079: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t
o up
*Mar 5 01:06:35.343: %DIALER-6-UNBIND: Interface Vi1 unbound from profile Di0
*Mar 5 01:06:35.347: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t
o down

First off, new Cisco routers usually come with the interface configured with IP address did not...hmmm...this is why SDM defaults to connect to You have a pull-down arrow for more options, I.E., whatever the IP address is that you set on vlan1.

Second, try

router(config)#int di 0
router(config-if)#ip add neg
router(config-if)#ppp ipcp dns request
router(config-if)#ppp ipcp wins request
router(config-if)#no ip mtu 1452
router(config-if)#ip tcp adjust-mss 1452
router(config)#int vlan1
router(config-if)#no ip tcp adjust-mss 1412

The change that should connect you is the "ip add neg", which in full is "ip address negotiated". This is the standard on DSL. The other thing that would not connect you is a fatfinger on the username and password for ppp, or if the ISP uses PAP. If this does not work, next we will try the PAP config as well. Right now, I am going to hit the hay...

That might have fixed some of the problems, but the router is still not connecting and its displaying the same up/down messages.

I double-checked the DSL ppp logonID and password. Both OK.

Should we try to change to PAP from CHAP?

router(config)#int di0
router(config-if)#no ppp authentication chap callin
router(config-if)#ppp authen pap chap callin
router(config-if)#ppp pap sent-username xxxx pass xxxx
router(config-if)#ppp chap hostname [removed]
router(config-if)#ppp chap password [removed]

If this does not work (shut the router off then back on after the changes), then post a
router#deb ppp authen
router#deb ppp neg

The best thing to do is to go into int atm0 and do a shut/no shut, as well as int di0, shut then no shut, instead of rebooting the router. Do the debug commands first, then shut and no shut on the interfaces.


I hate to post all of this, but follows is a short excerpt of console messages after debug on ppp authen and ppp neg:

*Mar 5 01:17:16.991: Vi1 LCP: AuthProto PAP (0x0304C023)n 8x"15D5752)
*Mar 5 01:07:58.
*Mar 5 0
*Mar 5 01:17:16.991: Vi1 LCP: MagicNumber 0x7031ED8E (0x05067031ED8E)uthentication Fai changed state tface Vi1 u
*Mar 5 01:15:39.535: Vi1 LCP
*Mar 5 01:17:16.991: Vi1 LCP: O CONFNAK [ACKrcvd] id 21 len 8CP: I TERMREQ [Open] id 223 len 4ent
*Mar 5 01:15:39.535: Vi1
*Mar 5 01:17:16.991: Vi1 LCP: MRU 1500 (0x010405DC)1 LCP: O TERMACK [Open] id 22
*Mar 5 01:15:39.535: Vi1
*Mar 5 01:17:17.027: Vi1 LCP: I CONFREQ [ACKrcvd] id 22 len 18Vi1 PPP: Sending Acct Event[Dow
*Mar 5 01:15:39.535: Vi1 LCP:
*Mar 5 01:17:17.027: Vi1 LCP: MRU 1492 (0x010405D4).283: Vi1 PPP: Phase is TERMINATINGer 0x358B7726 (0x050
*Mar 5 01:17:17.027: Vi1 LCP: AuthProto PAP (0x0304C023)9 len 8ut: State TERMsentar 5 01:12:49.067: Vi1 LCP: O CONF
*Mar 5 01:17:17.027: Vi1 LCP: MagicNumber 0x7031ED8E (0x05067031ED8E)CKrcvd] id 109
*Mar 5 01:12:49.067:
*Mar 5

*Mar 5 01:11:1
*Mar 5 01:17:17.091: Vi1 LCP: MRU 1492 (0x010405D4)rom interface PAP
*Mar 5 01:17:17.091: Vi1 LCP: AuthProto PAP (0x0304C023)ng password from interface PAP
*Mar 5 01:09:35.871: V
*Mar 5 01:17:17.091: Vi1 LCP: MagicNumber 0x7031ED8E (0x05067031ED8E)EQ id 1 len 14 from "xxxx" Phase is DOWN
*Mar 5
*Mar 5 01:17:17.091: Vi1 LCP: O CONFNAK [ACKrcvd] id 24 len 8 1 len 27 msg is "Authentication Fai
*Mar 5 01:11
*Mar 5 01:17:17.091: Vi1 LCP: MRU 1500 (0x010405DC)ed."ce Vi
*Mar 5 01:15:39.603: Vi1 LCP: I TERMREQ [Ope
*Mar 5 01:17:17.123: Vi1 LCP: I CONFREQ [ACKrcvd] id 25 len 18
o up3ECB
*Mar 5 01:15:39.603: Vi1 LCP: O TERMACK [Open] id
*Mar 5 01:17:17.127: Vi1 LCP: MRU 1492 (0x010405D4)405D4)646814C
*Mar 5 01:15:39.603: Vi1 PPP: Sending Ac
*Mar 5 01:16:03.695: V
*Mar 5 01:17:17.159: Vi1 LCP: State is Open]rcvd] id 130 len 8P: I TERMREQ [Open] id 11
*Mar 5 01:17:17.159: Vi1 PPP: No authorization without authenticationBLISHING, Active OpenC)LCP: O TERMACK [Open] id 11
*Mar 5 01:12:49.23
*Mar 5 01:17:17.159: Vi1 PPP: Phase is AUTHENTICATING, by the peered 18 PPP: Sending Acct Event[Dow
*Mar 5 01:12:49.231:
*Mar 5 01:
*Mar 5 01:17:17.159: Vi1 PAP: Using hostname from interface PAPPP: Phase is TERMINATINGer 0x71033291 (0x0506710
*Mar 5 01:
*Mar 5 01:17:17.159: Vi1 PAP: Using password from interface PAPtar 5 01:09:58.227: Vi1 LCP: O CONFNAK
*Mar 5 01:14
*Mar 5 0
*Mar 5 01:17:17.159: Vi1 PAP: O AUTH-REQ id 1 len 14 from "xxxx" 5 01:09:58.227:
*Mar 5

*Mar 5 01:16
o down: Vi1
*Mar 5 01:17:42.315: %DIALER-6-BIND: Interface Vi1 bound to profile Di05 01:14:26.503: Vi1 LCP: A
*Mar 5 01:16:03.759: Vi1 LCP: MRU 1492
*Mar 5 01:17:42.315: Vi1 PPP: Phase is DOWN, Setup1:14:26.503: Vi1
*Mar 5 01:16:03.759: Vi1 LCP:
*Mar 5 01:17:42.315: Vi1 PPP: Using dialer call directionpoe-client dial-p
*Mar 5 0
*Mar 5 01:16:03.759: Vi1 LCP:
*Mar 5 01:17:42.315: Vi1 PPP: Treating connection as a calloutaierface FastE
*Mar 5 01:08:20.
*Mar 5 01:14:26.50
*Mar 5 01
*Mar 5 01:17:42.315: Vi1 PPP: Session handle[5400005F] Session id[0]Q [Open] i
*Mar 5 01:14:26.535: Vi1 LCP: I CO
*Mar 5 01:16:03.759:
*Mar 5 01:17:42.315: Vi1 PPP: Phase is ESTABLISHING, Active Open1 le
*Mar 5 01:14:26.
*Mar 5 01:16:03.775: Vi1 LCP: I CONFREQ [
*Mar 5 01:17:42.315: Vi1 PPP: Authorizationt2oti

*Mar 5 01:17:42.351: Vi1 LCP: MagicNumber 0x2161D0FE (0x05062161D0FE)id 109 len 18 LCP: O TERMACK [Open] id 23
*Mar 5 01:09:58.39
*Mar 5 01:
*Mar 5 01:17:42.379: Vi1 LCP: I CONFREQ [ACKrcvd] id 195 len 18: Sending Acct Event[Dow
*Mar 5 01:09:58.395:
*Mar 5 01:16
*Mar 5 01:17:42.379: Vi1 LCP: MRU 1492 (0x010405D4)PAP: Phase is TERMINATING
*Mar 5
*Mar 5 01:17:42.379: Vi1 LCP: AuthProto PAP (0x0304C023)4C3907A1)ace PAP
line vty 0 4
*Mar 5 01:
*Mar 5 01:17:42.379: Vi1 LCP: MagicNumber 0x7699FF7C (0x05067699FF7C)id 109 len 8ault_context
*Mar 5 01

*Mar 5 01:13:13.455: Vi1
*Mar 5 0
*Mar 5 01:17:42.483: Vi1 LCP: O CONFNAK [ACKrcvd] id 198 len 83)P: Phase is DOWNUse, duplication, or disclosu
*Mar 5 0
*Mar 5 01:17:42.483: Vi1 LCP: MRU 1500 (0x010405DC)"Authentication Fai1, changed state trth in subpara
*Mar 5 01:17:42.515: Vi1 LCP: I CONFREQ [ACKrcvd] id 199 len 181:16:03.943: Vi1 LCP: I TERMREQ [Open] id 112 len 4Qsent] id 195
*Mar 5 01:17:42.515: Vi1 LCP: MRU 1492 (0x010405D4)01:16:03.943: Vi1 LCP: O TERMACK [Open] id 112 len 4U 1
*Mar 5 01:17:42.515: Vi1 LCP: AuthProto PAP (0x0304C023)r 5 01:16:03.943: Vi1 PPP: Sending Acct Event[Down] id[1D](
*Mar 5 01:17:42.515: Vi1 LCP: MagicNumber 0x7699FF7C (0x05067699FF7C)6:03.943: Vi1 PPP: Phase is TERMINATcNumb
*Mar 5 01:17:42.547: Vi1 LCP: State is Openection as a calloututhentication Fai
*Mar 5 01:17:42.547: Vi1 PPP: No authorization without authenticationession handle[79000056] Session id[0]1 LCP: I TERMREQ [Open] id 8 len
*Mar 5 01:17:42.547: Vi1 PPP: Phase is AUTHENTICATING, by the peerPhase is ESTABLISHING, Active OpenOpen] id 8 len 40
*Mar 5 01:13:1
*Mar 5 01:17:42.551: Vi1 PAP: Using hostname from interface PAPuthorization requiredEvent[Down] id[12]
*Mar 5
*Mar 5 01:14:5
*Mar 5 01:17:42.551: Vi1 PAP: Using password from interface PAPn for call-outERMINATING83F (0x050639368
*Mar 5 01:14:50.791: V
*Mar 5 01:17:42.551: Vi1 PAP: O AUTH-REQ id 1 len 14 from "xxxx"d] id 1 len 10LCP: O CONFNAK [REQsent] id 31 len 8tel
*Mar 5
*Mar 5 01:17:42.583: Vi1 PAP: I AUTH-NAK id 1 len 27 msg is "Authentication FaiAF)Mar 5 01:11:38
*Mar 5 01:13:13.58
*Mar 5 01:14:50.791: Vi1 LCP: MRU
*Mar 5 01:17:42.583: Vi1 LCP: I TERMREQ [Open] i

*Mar 5 01:16:28.
*Mar 5 01:18:07.423: Vi1 PPP: Phase is DOWN, Setup10*Mar 1 00:00:05.387: %VPN_HW-6-I
*Mar 5 0
*Mar 5 01:18:07.423: Vi1 PPP: Using dialer call directionAK [ACKrcvd] id 199 len 88)
*Mar 5 01:18:07.423: Vi1 PPP: Treating connection as a callout6C1) 1500 (0x010405DC)"Authentication Fai1, changed state t
*Mar 5 01:18:07.423: Vi1 PPP: Session handle[B7000062] Session id[0]6 len 8181:13:13.619: Vi1 LCP: I TERMREQ [Open] id 12 len 4EQsent] id
*Mar 5 01:18:07.423: Vi1 PPP: Phase is ESTABLISHING, Active Open.619: Vi1 LCP: O TERMACK [Open] id 12 len 4 M
*Mar 5 01:16:28.09
*Mar 5 01:18:07.423: Vi1 PPP: Authorization required.623: Vi1 PPP: Sending Acct Event[Down] id[16]PAP (
*Mar 5 01:18:07.423: Vi1 PPP: No remote authentication for call-out79).623: Vi1 PPP: Phase is TERMINATINgicNu

*Mar 5 01:18:07.455: Vi1 LCP: MRU 1500 (0x010405DC)8 len 8tuthentication Fai
*Mar 5 01:14:50.927:
*Mar 5 01:18:07.455: Vi1 LCP: I CONFACK [REQsent] id 1 len 100405DC)1] Session id[0]1 LCP: I TERMREQ [Open] id 171 le
*Mar 5 01:18:07.455: Vi1 LCP: MagicNumber 0x21623313 (0x050621623313)ABLISHING, Active OpenCK [Open] id 171
*Mar 5 01:10
*Mar 5 01:16:28.16
*Mar 5 01:18:07.487: Vi1 LCP: I CONFREQ [ACKrcvd] id 162 len 18redng Acct Event[Down]
*Mar 5 01:16:28.163: Vi1 LCP: Aut
*Mar 5 01:18:07.487: Vi1 LCP: MRU 1492 (0x010405D4)l-oute is TERMINATINGnged s
*Mar 5 01:16:28.163: Vi1 L
*Mar 5 01:18:07.487: Vi1 LCP: AuthProto PAP (0x0304C023)xxxx"d] id 1 len 10.995: %LINK-3-UPDOWN: Interface FastEth
*Mar 5 01:18:07.487: Vi1 LCP: MagicNumber 0x787AD949 (0x0506787AD949)uthentication Fai68)
*Mar 5 01
*Mar 5 01:10
*Mar 5 01:16:28.167: V
*Mar 5 01:18:07.487: Vi1 LCP: O CONFNAK [ACKrcvd] id 162 len 8P: I TERMREQ [Open] irf

*Mar 5 01:15
*Mar 5 01:18:07.555: Vi1 LCP: O CONFNAK [ACKrcvd] id 164 len 8x3B6F56C1 (0x05063B6F56C1)i1, changed state t2.09
*Mar 5 01:15
*Mar 5 01:18:07.555: Vi1 LCP: MRU 1500 (0x010405DC)1: Vi1 LCP: State is Open LCP: I TERMREQ [Open] id 38 l
*Mar 5 01:18:07.587: Vi1 LCP: I CONFREQ [ACKrcvd] id 165 len 18thout authentication Vi1 LCP: O TERMACK [Open] id 38 len 4 MRU 1
*Mar 5 01:18:07.587: Vi1 LCP: MRU 1492 (0x010405D4): Phase is AUTHENTICATING, by the peercct Event[Down] i
*Mar 5 01:18:07.587: Vi1 LCP: AuthProto PAP (0x0304C023):16:28.231: Vi1 PAP: Using hostname from interfacINATINGagic
*Mar 5 01:16:28.
*Mar 5 01:18:07.587: Vi1 LCP: O CONFNAK [ACKrcvd] id 165 len 801:10:24.767: Vi1 PPP: Phas
*Mar 5 01:12:00.603:
*Mar 5 01:16
*Mar 5 01:18:07.587: Vi1 LCP: MRU 1500 (0x010405DC)ication Faied state tnd from profile
*Mar 5 01:12:00.
*Mar 5 01:18:07.619: Vi1 LCP: I CONFREQ [ACKrcvd] id 166 len 18263: Vi1 LCP: I TERMREQ [Open] id 62 len 4id 162 len 18.
*Mar 5
*Mar 5 01:18:07.619: Vi1 LCP: MRU 1492 (0x010405D4)63: Vi1 LCP: O TERMACK [Open] id 62 len 42 (0x010405D4)
*Mar 5 01:18:07.619: Vi1 LCP: AuthProto PAP (0x0304C023)8.267: Vi1 PPP: Sending Acct Event[Down] id[1E]304C023)
*Mar 5 01:18:07.619: Vi1 LCP: MagicNumber 0x787AD949 (0x0506787AD949)1 PPP: Phase is TERMINATING 0x00D7C268 (0x050600D7C268) 01:13:37.827: Vi1
*Mar 5 01:18:07.619: Vi1 LCP: O CONFREJ [ACKrcvd] id 166 len 801:15:15.047: Vi1 LCP: O CONFN

*Mar 5 01:18:07.655: Vi1 PPP: Phase is AUTHENTICATING, by the peertual-Access1, changed state t
*Mar 5 01:15:15.115: Vi1 LCP
*Mar 5 01:18:07.655: Vi1 PAP: Using hostname from interface PAPb ppp au
*Mar 5 01:15:15.115: Vi1
*Mar 5 01:16:52.347: Vi1 P
*Mar 5 01:18:07.655: Vi1 PAP: Using password from interface PAP12
*Mar 5 01:15:15.115: Vi1 LCP: MagicNu
*Mar 5 01:16:52.34
*Mar 5 01:18:07.655: Vi1 PAP: O AUTH-REQ id 1 len 14 from "xxxx"
*Mar 5 0
*Mar 5 01:15:15.
*Mar 5 01:16:52.347: Vi1 L
*Mar 5 01:18:07.687: Vi1 PAP: I AUTH-NAK id 1 len 27 msg is "Authentication Fai
*Mar 5 01:15:15.115: Vi1 LCP: MRU
*Mar 5 01:16:52.351: %LINK-3-UPDOWN: Int
led." Virt
*Mar 5 01:18:07.687: Vi1 LCP: I TERMREQ [Open] id 168 len 4 [ACKrcvd] id 165 len 18P (0x0304C023)D (0x0506
o upA1D
*Mar 5 01:18:07.687: Vi1 LCP: O
*Mar 5 01:18:34.275: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t010405DC)10405D4).959: Vi1 LCP: O TERMACK [Open] id 209 len 40x0
*Mar 5 01:16:5
o downVi1 LC
*Mar 5 01:18:56.331: %DIALER-6-BIND: Interface Vi1 bound to profile Di0Event[Down] id[17]023)
*Mar 5 01:16:52.451: Vi1 LCP: MRU 1492 (
*Mar 5 01:18:56.335: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t52.451: Vi1 LCP: AuthProto PAP (0x0304C023)1 LCP: O CONFREJ [ACKrcvd] id 167
o up01:1
*Mar 5 0
*Mar 5 01:18:58.595: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state tnb
*Mar 5 01:15:15.247: Vi1 LCP:
*Mar 5 01:16:52.455: Vi1 LCP: MRU 1500
o down05DC)e
*Mar 5 01:19:20.671: %DIALER-6-BIND: Interface Vi1 bound to profile Di007: Vi1 LCP: I CONFREQ [ACKrcvd] id 131 len 18d
*Mar 5 01:19:20.675: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t (0x010405D4) 14o profile Di0
*Mar 5 01:10:47.039: V
*Mar 5 01:
o up.507
*Mar 5 01:19:22.943: %DIALER-6-UNBIND: Interface Vi1 unbound from profile Di0
*Mar 5 01:16:52.507: Vi1 LCP: MagicNumber 0x79B5F1D8

Looks like it's only trying PAP...

Post a sh run again, after the changes...


sh run:

Current configuration : 1759 bytes
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname Router
no logging buffered
no aaa new-model
resource policy
ip cef
no ip dhcp use vrf connected
ip dhcp excluded-address
ip dhcp pool client
ip ddns update method sdm_ddns1
DDNS both
username silver privilege 15 secret 5 $1$Tpvp$b2qcB4gjR.h4K1RXaAzgj1
interface ATM0
no ip address
no atm ilmi-keepalive
dsl operating-mode auto
interface ATM0.1 point-to-point
no snmp trap link-status
pvc 0/35
pppoe-client dial-pool-number 1
interface FastEthernet0
interface FastEthernet1
interface FastEtherne
interface FastEthernet3
interface Vlan1
ip address
ip nat inside
ip virtual-reassembly
interface Dialer0
ip address negotiated
ip nat outside
ip virtual-reassembly
encapsulation ppp
ip tcp adjust-mss 1452
dialer pool 1
dialer-group 1
ppp authentication pap chap callin
ppp chap hostname [removed]
ppp chap password 0 [removed]
ppp pap sent-username xxxx password 0 xxxx
ppp ipcp dns request
ip http server
ip http authentication local
no ip http secure-server
ip nat inside source list 1 interface Dialer0 overload
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit
dialer-list 1 protocol ip permit
line con 0
no modem enable
line aux 0
line vty 0 4
scheduler max-task-time 5000
webvpn context Default_context
ssl authenticate verify all
no inservice
Hmmm...I see nothing wrong. Let me stew over this...meanwhile, triple, quadruple check username and password on the account, virtual circuit info (0/35)---didn't you have an 837 or something before this router?

Had (still have) an 831 with a pretty plain vanilla config. I need to do something different with it plus I don't think I'm not getting the throughput with it that I'm paying for.

I got the VC info from the modem we're currently using (831 and modem to be replaced by 877). The logonID and password are the same as my primary email address, also the same in the modem. I keep looking at them in the config and they seem OK.

Could it possibly be that CHAP was not configured correctly in the first place to send ID and pword?

And (separately) the router is still giving the messages:

*Mar 5 01:05:19.591: %DIALER-6-BIND: Interface Vi1 bound to profile Di0
*Mar 5 01:05:19.599: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t
o up
*Mar 5 01:05:21.871: %DIALER-6-UNBIND: Interface Vi1 unbound from profile Di0
*Mar 5 01:05:21.875: %LINK-3-UPDOWN: Interface Virtual-Access1, changed state t
o down
Does this help? Modem configuration information (from the modem):

Connection UP
User ID [removed, but same as in 877 config]
Connected at 6016 Kbps (Downstream)
800 Kbps (Upstream)
IP Address
IP Gateway
DNS Servers dns1.ksc2mo.sbcglobal.net dns1.bcvloh.sbcglobal.net
Mode PPP on the modem (Public IP for LAN device)
Timeout Never

Modem Information

Modem Name Motorola
Model 2210-02

Local Network

Modem IP Address
Ethernet Status Connected

VCI 35
Protocol PPPoE
Maximum allowable MTU 1492
ATM Encapsulation LLC

Connection Type Smart Keep Alive

You are indeed connected and getting an IP address...weird...I would maybe call the ISP at this point. Can you fire up the 831 and post that config? We can compare the two. I mean, you're getting an IP address from the ISP RADIUS server, but L2 is not negotiating. Post a sh int di0

Not open for further replies.

Part and Inventory Search

