Cisco ASR 9006 IOS XR 4.3.0 aaa authorization

Hi,
I've configured two Cisco ASR 9006 with IOS XR 4.3.0 with the aaa. I've a problem with the authorization statement.
I need to distiguish two groups.
Network Administrator (Full access, show, configuration etc etc)
Network Viewer (Users in this group can use only the show command)
I cannot find anything clear on the documentation. Can you help me?
Below the actual configuration (without authorization)
tacacs source-interface Loopback0 vrf default
tacacs-server host 10.10.10.1 port 49
tacacs-server key 7 XXXXXXXXXX
tacacs-server timeout 10
username emergency
group netadmin
password 7 XXXXXXXXXXXXXXX
aaa accounting exec default start-stop group ACS
aaa accounting system default start-stop group ACS
aaa group server tacacs+ ACS
server 10.10.10.1
aaa authentication login default group ACS local
I have configured two Shell Command Authorization Sets in my ACS. One for ReadOnly and one for Full Access.
The ReadOnly Group (called AccessoSolaLettura) is on the attacched png called asr_1.PNG
The Full Access Group (called AccessCompleto) is on the attached png called asr_2.PNG
I associated this Shell Authorization sets to two users group. (Network Administrator and Network Viewer).
The first one with Level 15 and the second one with Level 7. (Attached file ACS_1.png and ACS_2.png)
Can you tell me if the ACS configuration is right and which configuration is needed on the ASR?
The ACS Release is 4.2(0) Build 124.
Tnx
Leonardo

Hi Leonardo,
In XR we have the concept of tasks and taskgroup for determining what a user can do, and we recommend using this. For tasks we have the read/write/execute/debug permissions.
For instance to run 'show bgp summary' we need the read permission on the task BGP. Instead of assigning individual permissions per user we can create a taskgroup and the user can inherit everything from a taskgroup.
So for instance we can add read BGP, read OSPF, and read system to the taskgroup test. We can then have the user inherit the taskgroup test and get all the permissions that taskgroup has. We can inherit multiple tasks and taskgroups.
In addition we have some predefined task groups (for the full access user you will want the cisco-support and root-system taskgroups).
You can find some more information in the following posts
http://www.cisco.com/c/en/us/td/docs/routers/asr9000/software/asr9k_r4-3/security/configuration/guide/b_syssec_cg43xasr9k/b_syssec_cg43asr9k_chapter_010.html
https://supportforums.cisco.com/docs/DOC-15944
HTH,
Sam

Similar Messages

  • CIsco ASR 9006

    Hello All,
    I am configuring Netflow on ASR 9006 IOS-XR. I need to be able to specify specify flow records (basically flexible Netflow) and configure flow aggregation based on destination prefix. This is not possible with the device.
    I will be glad if anyone could help with this challenge.
    Thanks.

    Hi Leonardo,
    In XR we have the concept of tasks and taskgroup for determining what a user can do, and we recommend using this. For tasks we have the read/write/execute/debug permissions.
    For instance to run 'show bgp summary' we need the read permission on the task BGP. Instead of assigning individual permissions per user we can create a taskgroup and the user can inherit everything from a taskgroup.
    So for instance we can add read BGP, read OSPF, and read system to the taskgroup test. We can then have the user inherit the taskgroup test and get all the permissions that taskgroup has. We can inherit multiple tasks and taskgroups.
    In addition we have some predefined task groups (for the full access user you will want the cisco-support and root-system taskgroups).
    You can find some more information in the following posts
    http://www.cisco.com/c/en/us/td/docs/routers/asr9000/software/asr9k_r4-3/security/configuration/guide/b_syssec_cg43xasr9k/b_syssec_cg43asr9k_chapter_010.html
    https://supportforums.cisco.com/docs/DOC-15944
    HTH,
    Sam

  • Ask the Experts: Understanding Cisco ASR 9000 Series Aggregation Services Routers Platform Architecture and Packet Forwarding Troubleshooting

    With Xander Thuijs
    Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to learn how to Cisco ASR 9000 Series Aggregation Services Routers with Cisco expert Xander Thuijs. The Cisco ASR 9000 Series Aggregation Services Routers product family offers a significant added value compared to the prior generations of carrier Ethernet routing offerings. The Cisco ASR 9000 Series is an operationally simple, future-optimized platform using next-generation hardware and software. The ASR 9000 platform family is composed of the Cisco ASR 9010 Router, the Cisco ASR 9006 Router, the Cisco ASR 9922 Router, Cisco ASR 9001 Router and the Cisco ASR 9000v Router.
    This is a continuation of the live Webcast.
    Xander Thuijs is a principal engineer for the Cisco ASR 9000 Series and Cisco IOS-XR product family at Cisco. He is an expert and advisor in many technology areas, including IP routing, WAN, WAN switching, MPLS, multicast, BNG, ISDN, VoIP, Carrier Ethernet, System Architecture, network design and many others. He has more than 20 years of industry experience in carrier Ethernet, carrier routing, and network access technologies. Xander  holds a dual CCIE certification (number 6775) in service provider and voice technologies. He has a master of science degree in electrical engineering from Hogeschool van University in Amsterdam.
    Remember to use the rating system to let Xander know if you have received an adequate response.
    Xander might not be able to answer each question because of the volume expected during this event. Remember that you can continue the conversation on the Service Providers community XR OS And Platforms  shortly after the event. This event lasts through Friday, May 24, 2013. Visit this forum often to view responses to your questions and the questions of other Cisco Support Community members.
    Webcast  related links:
    Slides
    Webcast  Video Recording
    FAQ

    Is there a Cisco lab available for ASR 9000
    we have "XR4U" stations coming available soon when XR 511 comes alive. The plan is for a downloadable play image like that. In the interim we have 2 demo systems available, and they can be booked via your account manager representative.
    How will MOD160 perform with multiple 9000NVS?
    very well. the mod 160 has 4 NPU's, 2 per bay. So if you have a 4x10 MPA to serve a satellite, you effectively have a single NPU per 20 1Gigs from the satellite. The pps performance will be stellar. However it might be price technically more ideal to connect satellite with a 36x10. Since the MOD-x has native MPA's with 1G also.
         2. Is there a shortcut for a Bundle-EthernetX interface, such as port-channel interface (poX), in Cisco IOS® ?.
    usability enhancement is there, we are trying to push this into a new reasonable release. follow CSCuh04526
         3. What  is the revolutions per minute (RPM) on these hard disk drives (HDDs)  compared to the solid state drives (SDDs)? Will the spinning drives be  slow?
    depends on the type we had avaialble at time of production, you will see different sizes and disks on the RSP2. the rpm of the HD is not so much an issue as much as the buffered writing we used to do in XR. This is fixed up with XR43 where the disk writing performance is much better. the HD/SDD is used for logging storage only (and maybe your pictures) but other then that we're not that concerned with write perf of the HD.
    regards
    xander

  • Monitoring Cisco ASR 1002 with IOS-XE in IPM 4.2

    We are running LMS 3.2 with IPM 4.2 installed....and we are looking to do IPSLA monitoring on a couple of our Cisco ASR's with IOS-XE code installed.
    I looked at the IPSLA feature mapping and it only talks about supported IOS code....do we need to upgrade our current IPM module to a current version?

    Hi Konstantin,
    Regarding "It is strange that these commands cleaned from sh run view.": this is normal for many default configuration commands.
    Mine is a lab device so I cannot really comment on stability or provide you a recommendation based on that. However, I see that the download section from Cisco.com mentiones the following release as the recommended based on quality, stability and longevity:
    asr1002x-universal.03.07.04a.S.152-4.S4a.SPA.bin
    The best would be for you to check this with yor cisco Account Team or Advanced Services Team as normally they are the proper point of contacts for SW advisory.
    Regards.

  • ASR 9006 to 6509 1 gig fiber connection

    I have an ASR 9006 with a SFP-GE-L connecting to a Cisco 6500.  The link shows up on the ASR side but not on the 6500 side.  If I move the SFP from the ASR to a
    different 6500 chassis the connection works so I know the SFP is working. 
    Any ideas on making this link work?

    The issue ended up being a negotiation issue.  Apparently IOS-XR is set for nonegotiate disabled by default and IOS is enabled by default. 
    The fix being to put "speed nonegotiate" on the IOS side interfaces and it came up

  • Dual asr 9006 cluster

    Hi expert,
    I have two asr 9006. I'm using dual rsp on router. I'm using Cisco IOS XR Software, Version 4.1.2.
    I want to use two asr 9006 to cluster. But How can do this? I can't find documents on the cisco web site or internet. 

    Hi Umit,
    SW requirement
    •Supported since 4.2.1
    •Requires cluster software license on each chassis
    HW requirement – Chassis
    •Only ASR 9006 and 9010 are supported in 4.2.x
    •ASR 9001 is supported starting in 4.3.0
    •ASR 9001-S and 9922 are supported starting in 4.3.1
    •ASR 9904 and 9912 are supported starting in 5.1.1
    •Only like-like chassis are supported
    HW requirement – Line card and RSP
    •Dual RSP440 for 9006/9010/9904
    •Dual RP for 9912/9922
    •Single RSP 9001/9001-S
    •No RSP-4/8G support
    •Only Typhoon LC and SIP-700 allowed to boot
    •Only Typhoon LC support IRL
    •VSM/ISM not supported
    We have more information on nV Edge posted here
    https://supportforums.cisco.com/docs/DOC-34114
    HTH,
    Sam

  • Can I rate-limit on the sub-interface in cisco asr 1013?

    Hi,
    I am looking for the command of rate-limit on a sub-interface in cisco asr 1013.
    Cisco IOS Software, IOS-XE Software (X86_64_LINUX_IOSD-ADVENTERPRISEK9-M), Version 15.2(2)S, RELEASE SOFTWARE (fc1)
    IOS XE Version: 03.06.00.S
    Please let me know if it is possible in cisco asr 1013. If yes then what are the commands.
    Zobair

    The ASR no longer supports the rate-limit command, but it does support the same functionality in a QoS policy.
    Please find a sample configuration -
    ASR1004(config)#policy-map test
    ASR1004(config-pmap)#class class-default
    ASR1004(config-pmap-c)#shape average 10000
    Applying for both ingress and egress : -
    ASR1004(config)#int gig1/1/0
    ASR1004(config-if)#service-policy output test   
    or
    ASR1004(config-if)#service-policy input test

  • ASR 1001 IOS upgrade issue

    Hi I am changing IOS of Cisco ASR 1001  from asr1001-universalk9.03.07.02.S.152-4.S2.bin
    to asr1000rp1-adventerprisek9.03.04.02.S.151-3.S2.bin but everty time it boot up with old IOS universalk9.
    Is it becaused of Licence issue.
    Router#sh bootvar
    BOOT variable = bootflash:asr1000rp1-adventerprisek9.03.04.02.S.151-3.S2.bin,12;bootflash:asr1001-universalk9.03.07.02.S.152-4.S2.bin,12;
    CONFIG_FILE variable does not exist
    BOOTLDR variable does not exist
    Configuration register is 0x2102
    License Level: advipservices
    License Type: Permanent
    Next reload license Level: advipservices
    cisco ASR1001 (1RU) processor with 1155941K/6147K bytes of memory.
    Processor board ID SSI1607042B
    4 Gigabit Ethernet interfaces
    32768K bytes of non-volatile configuration memory.
    4194304K bytes of physical memory.
    7741439K bytes of eUSB flash at bootflash:.
    Configuration register is 0x2102

    You downloaded the wrong file.  The file you wanted to run has "rp1" but the original file doesn't.  You downloaded a file for a different model.  Your router is an ASR 1001 with fixed RP but you've downloaded a file for a different sub-model of ASR, like the 1002 or 1004.
    Go here instead:  http://software.cisco.com/download/release.html?mdfid=282993672&softwareid=282046477&release=3.10.3S&relind=AVAILABLE&rellifecycle=ED&reltype=latest

  • Anomalies found when downgrade ASR 9K IOS XR 4.3.0 to 4.2.1

    Hai,
    I have problem when downgrade ASR 9K IOS XR version 4.3.0 to version 4.2.1 on RSP 440
    This is the capture :
    RP/0/RSP0/CPU0:PE3-D2-JT2-VPN(admin)#sh instal active summary
    Wed Apr 17 22:42:21.303 UTC
    Default Profile:
      SDRs:
        Owner
      Active Packages:
        disk0:asr9k-mini-px-4.3.0
        disk0:asr9k-k9sec-px-4.3.0
    RP/0/RSP0/CPU0:PE3-D2-JT2-VPN(admin)#
    then this is capture after upgrading proces :
    RP/0/RSP0/CPU0:PE3-D2-JT2-VPN#show install active summary
    Thu Apr 18 02:14:29.457 UTC
      Active Packages:
        disk0:asr9k-services-p-px-4.2.1
        disk0:asr9k-mini-px-4.2.1
        disk0:asr9k-doc-px-4.2.1
        disk0:asr9k-k9sec-px-4.2.1
        disk0:asr9k-mpls-px-4.2.1
        disk0:asr9k-mgbl-px-4.2.1
        disk0:asr9k-mcast-px-4.2.1
        disk0:asr9k-fpd-px-4.2.1
    RP/0/RSP0/CPU0:PE3-D2-JT2-VPN#admin  
    Thu Apr 18 02:14:37.632 UTC
    RP/0/RSP0/CPU0:PE3-D2-JT2-VPN(admin)#show install inactive summary
    Thu Apr 18 02:14:42.139 UTC
    Default Profile:
      SDRs:
        Owner
      Inactive Packages:
        disk0:asr9k-mini-px-4.3.0
        disk0:asr9k-k9sec-px-4.3.0
    RP/0/RSP0/CPU0:PE3-D2-JT2-VPN(admin)#
    when i verify packages, there are anomalies found
    RP/0/RSP0/CPU0:PE3-D2-JT2-VPN(admin)#install verify packages
    Thu Apr 18 02:17:07.973 UTC
    Install operation 29 '(admin) install verify packages' started by user 'cisco'
    via CLI at 02:17:08 UTC Thu Apr 18 2013.
    The install operation will continue asynchronously.
    RP/0/RSP0/CPU0:PE3-D2-JT2-VPN(admin)#Info:     This operation can take up to 2 minutes per package being verified.
    Info:     Please be patient.
    Info:     0/4/CPU0 [LC] [SDR: Owner]
    Info:         meta-data: [SUCCESS] Verification Successful.
    ----output omitted--------
    Info:         /install/asr9k-base-4.2.1: [SUCCESS] Verification Successful.
    Info:     0/RSP1/CPU0 [RP] [SDR: Owner]
    Info:         meta-data: [ERROR] Detected anomalies.
    Info:         /install/iosxr-infra-4.2.1/instdb/component.db: exists with
    Info:     unexpected file size.
    ----output omitted--------
    Info:         0/4/CPU0: SUCCESSFUL. No anomalies found.
    Info:         0/0/CPU0: SUCCESSFUL. No anomalies found.
    Info:         0/7/CPU0: SUCCESSFUL. No anomalies found.
    Info:         0/RSP1/CPU0: Too many anomalies found.
    Info:         0/RSP0/CPU0: Too many anomalies found.
    Info:         Anomalies found on both the RPs.
    Info:         Please contact your technical services representative to repair
    Info:     the system.
    Install operation 29 completed successfully at 02:18:16 UTC Thu Apr 18 2013.
    RP/0/RSP0/CPU0:PE3-D2-JT2-VPN(admin)#RP/0/RSP0/CPU0:Apr 18 02:18:56.272 : canb-server[150]: %PLATFORM-CANB_SERVER-3-MESSAGE_FAILED : Unexpected CBC message received from slot 0/4/CPU0 [ver 20.115] for msg type 3, id 105, len 8 
    RP/0/RSP0/CPU0:Apr 18 02:23:04.937 : ifmgr[245]: %PKT_INFRA-LINK-3-UPDOWN : Interface MgmtEth0/RSP0/CPU0/1, changed state to Down
    RP/0/RSP0/CPU0:PE3-D2-JT2-VPN(admin)#
    I did rollback and reinstall, and issue still same.
    Anyone please help me.
    Thanks

    Hi,
    We can try to fix the anomalies with a package repair operation or by restarting the instdir process. Please try the repair option first.
    ' admin install verify packages repair'
    Or
    'process restart instdir'
    Restarting the above process has no service impact on the router.
    Let me know the result of trying the above steps.
    Thanks,
    Sam Milstead
    CSE - XR TAC

  • PPPoGEC Cisco ASR 1001

    Hi Cisco Professional,
    We want to implementing PPPoE over port-channel (using subinterfaces L2) in Cisco ASR 1001 routers, my question is if this router support this feature?, in the other hand i've see  documents about this theme, pls check these links:
    http://www.cisco.com/en/US/docs/ios/ios_xe/cether/configuration/guide/ce_lnkbndl_xe.html
    http://www.cisco.com/en/US/docs/ios-xml/ios/cether/configuration/xe-3s/ce-ieee-link-bndl-xe.html
    My IOS version Cisco ASR 1001 is:
    System image file is "bootflash:/asr1001-universalk9.03.04.00.S.151-3.S.bin"
    We want this configuration on the router,
    no     interface     GigabitEthernet0/0/0.25
    interface     port-channel     10.25
    description     TURBONETT     PUBLICA     UT
    encapsulation     dot1Q     25
    ip     address     10.17.44.254     255.255.252.0
    no     interface     GigabitEthernet0/0/0.52
    interface     port-channel     10.52
    description     TURBONETT-UT
    encapsulation     dot1Q     52
    pppoe     enable     group     global
    pppoe     max-sessions     4000
    no     interface     GigabitEthernet0/0/0.61
    interface     port-channel     10.61
    description     Turbonett-Sector-A
    encapsulation     dot1Q     61
    pppoe     enable     group     global
    pppoe     max-sessions     4000
    Kind Regards,
    Renzo Tovar

    Hi Renzo,
    PPPoEoVLAN on GEC (LACP mode) is supported as of XE 3.7. I see that you are using XE 3.4 here so I would suggest to move to XE 3.7 and try this feature.
    This is a sample configuration for the feature:
    interface GigabitEthernet2/1/0
    no ip address
    negotiation auto
    channel-group 2 mode active
    interface GigabitEthernet3/1/0
    no ip address
    negotiation auto
    channel-group 2 mode active
    lacp port-priority 65000
    interface Port-channel2
    no ip address
    load-interval 30
    no negotiation auto
    lacp max-bundle 1
    lacp fast-switchover
    interface Port-channel2.200
    encapsulation dot1Q 200
    pppoe enable group global
    interface Port-channel2.500
    encapsulation dot1Q 500 second-dot1q 1500
    pppoe enable group global
    As you can see, both PPPoEoVLAN and  PPPoEoQinQ are supported.
    Hope this helps.
    Best regards.

  • STM1 Back-to-Back Between ASR 9006 and ASR 903

    Dear Gents,
    Seeking your usual support to aid me to connect STM1 Back-to-Back between ASR 9006 and ASR 903.
    I have ASR 9006 comes with SPA-4XOC3-POS-V2 and SFP-OC3-MM using XR-A9K-PXK9-04.03 IOS-XR.
    Also I have ASR 903 comes with A900-IMA4OS interface module with ONS-SI-155-SR-MM SFP using SASR903R1NPEK9-38S IOS-XE.
    I'm using Multi Mode fiber cable between them and the interfaces never came UP UP.
    Below the configuration i did to both sides.
    ASR 903 configuration:
    ASR903#sh run | sec contro
    controller SONET 0/0/0
     framing sdh
     clock source internal
     aug mapping au-4
     au-4 1 pos
    interfaces POS0/0/0.1  
    ip address 10.10.10.2 255.255.255.252
    ASR 9006 configuration
    ASR9006#sh running-config controller soNET 0/1/0/0  
    controller SONET0/1/0/0
     framing sdh
     clock source internal
    interface POS0/1/0/0
     ipv4 address 10.10.10.1 255.255.255.252
    Thanks in advance.

    I think your 900 is running in an oc12/stm4 mode (as you seem to subrate the sonet controller), so they have a speed mismatch already although it looks like you're using the right STM1 optic.
    also one side you will want to have use clock from line while the other internal, otherwise you'll get a lot of clock slips.
    cheers
    xander

  • What are the following:1)Cisco 1600 Series IOS WIRELESS LAN RECOVERY. 2)Service Provider Option 60 for Vendor Class Idenfier

    What are the following:1)Cisco 1600 Series IOS WIRELESS LAN RECOVERY. 2)Service Provider Option 60 for Vendor Class Idenfier
    These items are listed with 1600 series AP but I'm unable to understand what are these things & the use of them

    DHCP Option 60:  Go HERE.

  • Traffic policing question on Cisco ASR 1001

    Hi Experts,
    I have a request to setup aggregated traffic policing on a Cisco ASR 1001 router for multiple networks within a router.
    Lets say I have a router with several subinterfaces:
    interface GigabitEthernet0/2
     description WAN
     ip address x.x.x.x x.x.x.x
    interface GigabitEthernet0/1.70
     description Lan_1
     encapsulation dot1Q 70
     ip address 192.168.55.1 255.255.255.0
    interface GigabitEthernet0/1.80
     description LAN_2
     encapsulation dot1Q 80
     ip address 192.168.56.1 255.255.255.0
    interface GigabitEthernet0/1.90
     description Servers
     encapsulation dot1Q 90
     ip address 172.16.10.1 255.255.255.0
    I have a WAN link 100Mbit/s and I need to police traffic, so that I have 30Mbit/s for servers (GigabitEthernet0/1.90) and the rest 70Mbit I want to share between Interface Lan_1 and LAN_2. The Idea is that I need 70Mbit/s equally shared between two interfaces, so that I have fair policing on both iunterfaces. What is the best way to achieve this?
    Many Thanks

    Hello
    The below configuration is a possible option, Its provides policing inbound from the clients interfaces and LLQ priority queung on the wan interface for the servers and  shaping values from LAN1 & 2 traffic is set to 35MB.each.
    Notice nothing is defined for the default class, however i am on the understanding this is given by default 1% of Hqos implementations.
    Maybe others on here could review to verify any problems with this post and share their thoughts?
    ip access-list extended SRVS_acl
     permit ip 172.16.10.0 0.0.0.255 any
    ip access-list extended LAN1_acl
     permit ip 192.168.55.0 0.0.0.255 any
    ip access-list extended LAN2_acl
     permit ip 192.168.56.0 0.0.0.255 any
    class-map match-all SRVS_CM
     match access-group name SRVS_acl
    class-map match-all LAN_1_CM
     match access-group name  LAN1_acl
    class-map match-all LAN_2_CM
     match access-group name LAN2_acl
    policy-map SRVS_PM
     class SRVS_CM
        police 30720000 conform-action transmit exceed-action drop
    policy-map LAN_2_PM
     class LAN_2_CM
        police 35840000 conform-action transmit 
    policy-map LAN_1_PM
     class LAN_1_CM
        police 35840000 conform-action transmit 
    interface GigabitEthernet0/1.70
    service-policy input LAN_1_PM
    interface GigabitEthernet0/1.90
     service-policy input SRVS_PM
    interface GigabitEthernet0/1.80
     service-policy input LAN_2_PM
    policy-map WAN_CHILD
     class SRVS_CM
      priority 30720
     class LAN_1_CM
      shape average 35840000
     class LAN_2_CM
      shape average 35840000
     class class-default
      fair-queue
    policy-map WAN_PARENT
     class class-default
      shape average 102400000
      service-policy WAN_CHILD
    int  GigabitEthernet0/2
    bandwidth 102400
    service-policy output WAN_PARENT
    res
    Paul

  • CME B-ACD on Cisco 2911 with IOS 15.2(4)M5 not working

    Hi Folks,
    I am currently setting up CME version 9.1 with B-ACD (app-b-acd-aa-3.0.0.2.tcl & app-b-acd-3.0.0.2.tcl), running on
    Cisco 2911 with IOS ver 15.2(4)M5, this is for lab purposes.
    Below is my CME & B-ACD configuration :
    voice service voip
    ip address trusted list
      ipv4 0.0.0.0 0.0.0.0
    allow-connections h323 to h323
    allow-connections h323 to sip
    allow-connections sip to h323
    allow-connections sip to sip
    fax protocol t38 version 0 ls-redundancy 0 hs-redundancy 0 fallback none
    h323
      h225 listen-port 1820
      no call service stop
    sip
      bind control source-interface Vlan400
      bind media source-interface Vlan400
      registrar server expires max 600 min 60
    voice register global
    mode cme
    source-address 172.25.202.1 port 5060
    max-dn 2
    max-pool 2
    load 9971 sip9971.9-2-2SR1-9
    authenticate register
    timezone 28
    time-format 24
    date-format D/M/Y
    tftp-path flash:
    create profile sync 0004714411607756
    voice register dn  1
    number 3005
    name br2phn2
    voice register dn  2
    number 3006
    name br2phn4
    voice register template  1
    dialplan 1
    voice register dialplan 1
    type 7940-7960-others
    pattern 1 3...
    pattern 2 999
    voice register pool  1
    id mac 1C1D.86C4.0D6D
    type 9971
    number 1 dn 1
    template 1
    dtmf-relay rtp-nte
    username 3005 password cisco
    description 3214-3005
    codec g711ulaw
    voice register pool  2
    id mac 1C1D.86C4.A574
    type 9971
    number 1 dn 2
    template 1
    dtmf-relay rtp-nte
    username 3006 password cisco
    description 3214-3006
    codec g711ulaw
    voice hunt-group 1 parallel
    list 3002,3006
    pilot 3210
    application
    service aa flash:/app-b-acd-aa-3.0.0.2.tcl
      paramspace english index 1
      param number-of-hunt-grps 2
      param handoff-string aa
      paramspace english language en
      param max-time-vm-retry 2
      param aa-pilot 3500
      paramspace english location flash://
      param second-greeting-time 60
      param welcome-prompt _bacd_welcome.au
      param call-retry-timer 15
      param voice-mail 3001
      param max-time-call-retry 90
      param service-name queue
    service aa-drop flash:/app-b-acd-aa-3.0.0.2.tcl
      paramspace english index 1
      param service-name queue
      param drop-through-option 2
      param second-greeting-time 60
      paramspace english language en
      param max-time-vm-retry 2
      param max-time-call-retry 90
      param voice-mail 3001
      paramspace english location flash://
      param aa-pilot 3501
      param number-of-hunt-grps 1
      param handoff-string aa-drop
      param call-retry-timer 15
    service queue flash:/app-b-acd-3.0.0.2.tcl
      param queue-len 15
      param aa-hunt10 3006
      param queue-manager-debugs 1
      param number-of-hunt-grps 2
      param aa-hunt2 3210
    interface Loopback0
    ip address 172.25.110.3 255.255.255.255
    ip ospf network point-to-point
    h323-gateway voip interface
    h323-gateway voip id Spain ipaddr 172.25.110.1 1719
    h323-gateway voip h323-id BR2-RTR
    h323-gateway voip tech-prefix 1#
    h323-gateway voip bind srcaddr 172.25.110.3
    interface Vlan400
    ip address 172.25.202.1 255.255.255.0
    ip pim dense-mode
    dial-peer voice 3500 voip
    service aa
    destination-pattern 3500
    session target ipv4:172.25.110.3
    incoming called-number 3500
    dtmf-relay h245-alphanumeric
    codec g711ulaw
    no vad
    dial-peer voice 3501 voip
    service aa-drop
    destination-pattern 3501
    session target ipv4:172.25.110.3
    incoming called-number 3501
    dtmf-relay h245-alphanumeric
    codec g711ulaw
    no vad
    telephony-service
    no auto-reg-ephone
    max-ephones 2
    max-dn 2 no-reg both
    ip source-address 172.25.110.3 port 2000
    cnf-file location flash:
    load 7965 term65.default.loads
    time-zone 28
    time-format 24
    date-format dd-mm-yy
    max-conferences 8 gain -6
    moh "music-on-hold.au"
    web admin system name admin password cisco
    dn-webedit
    transfer-system full-consult
    create cnf-files version-stamp 7960 Feb 14 2014 05:54:44
    ephone-template  1
    softkeys connected  Endcall Hold Park Trnsfer Acct Flash
    ephone-dn  1  octo-line
    number 3001 no-reg both
    description 3214-3001
    name br2phn1
    ephone-dn  2  octo-line
    number 3002 no-reg both
    description 3214-3002
    name br2phn3
    ephone  1
    device-security-mode none
    mac-address 189C.5DB6.D303
    ephone-template 1
    max-calls-per-button 5
    busy-trigger-per-button 3
    type 7965
    button  1:1
    ephone  2
    device-security-mode none
    description 3214-3002
    mac-address 984B.E194.FDDD
    ephone-template 1
    max-calls-per-button 5
    busy-trigger-per-button 3
    type 7960
    button  1:2
    Problem :
    1. When I test call from CME Phone both SIP and SCCP Phone by dial 3500 or 3501, I get the busy tone.
    2. Debug voip dial-peer, match with dial-peer voice 3500 for (aa service) & 3501 for (aa-drop service).
    3. Debug voice application script, show nothing.
    Is there something wrong with my configuration ?
    Rgds
    Novri

    Hi Novriadi,
    In your configuration
    service aa flash:/app-b-acd-aa-3.0.0.2.tcl
    service queue flash:/app-b-acd-3.0.0.2.tcl
    paramspace english location flash://
    Remove "/" and "//" from the configuration
    Then use the call application voice load command in privileged EXEC mode to reload the scripts.
    Router# call application voice load aa
    Router# call application voice load queue
    Router# call application voice load aa-drop
    You can refer to following document as well for more info
    http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucme/bacd/configuration/guide/cme40tcl/40bacd.html#wp1018270
    Please find the sample configuration that is required to configure b-acd in CME for reference.
    telephony-service
    moh music-on-hold.au
    multicast moh 239.1.1.1 port 2000
    application
    service queue flash:app-b-acd-2.1.0.0.tcl
      param number-of-hunt-grps 2
      param aa-hunt2 1111
      param aa-hunt3 1222
      param queue-len 15
      param queue-manager-debugs 1
    service aa flash:app-b-acd-aa-2.1.0.0.tcl
      paramspace english index 1
      paramspace english language en
      paramspace english location flash:
      param service-name queue
      param handoff-string aa
      param aa-pilot 8005550123
      param welcome-prompt _bacd_welcome.au
      param number-of-hunt-grps 2
      param dial-by-extension-option 1
      param second-greeting-time 60
      param call-retry-timer 15
      param max-time-call-retry 700
      param max-time-vm-retry 2
      param voice-mail 5003
    dial-peer voice 222 voip
    service aa
    destination-pattern 8005550123
    session target ipv4:192.168.1.1
    incoming called-number 8005550123
    dtmf-relay h245-alphanumeric
    codec g711ulaw
    no vad
    Thanks & Regards,
    Mudit Mathur

  • Cisco ASR Router Software Version 4.3.1 // PRTG Custom Sensor

    Dears,
    We are encountering problem in doing costume SNMP sensors in PRTG, whenever I create a customized sensor, the sensor goes up and down.  We have faced this problem after updating the software of our Cisco ASR to 4.3.1. In older versions, it was working well.  Is there a problem in Cisco ASR 4.3.1 SNMP with PRTG ? I would appreciate it if you can support in this case as we are in need of these customized sensors. We have gor  all of them down because of the update
    Regards,

    Dear Alexander,
    The standard sensors of PRTG are working well such as traffic sensors, ping etc, but the customized sensors are not working well in version 4.3.1. I always do a customized sensors for QoS, SLAs and others and they are working well in versions below 4.3.1.
    Furthermore, I have tested those OIDs by using Paessler SNMP Tester and I have seen that the reading is not showing properly. For instance, I have a customized OID that shows the reading every 60s (as a minimum) only while in older versions of ASR software I can see the reading every 30s or below of that particular OID using the same version of PRTG!
    Conclusion:
    PRTG latest version + ASR 4.3.1 = Customized sesnors are not working well
    PRTG latest version + ASR Older version = Customized sesnors are working well
    Kind regards,

Maybe you are looking for

  • Foreign curr reval for open items - questions - very urgent

    Hi all, Can anyone explain me the account determination for open item exchange rate difference postings? 1.     What are the accounts meant for under tab Exchange rate difference realized (Loss, Gain) 2.     What are the account meant for under tab v

  • Get the file list of a given directory

    does anyone know how to get the file list of a given directory? I tried "list"/"filelist" but the class not found. THanks!

  • Certificate in HTTP adapter

    Dear Friends, I am working on scenario in which I have to pick file from a folder and send to partner on the link provided by them, and as a security measure i have to use certificate. I am going to use HTTP adapter for sending message. I had done al

  • These two rams are same?

    Hi,i am new hereI am looking for a ram for my desktop , while browsing rams on amazon i found this Crucial CT51264BF160B ram and when i searched for this ram on Crucial's website and then tried to check if its compatible with my PC ,the product page

  • Deleting attachments

    10.6.3 STILL does not fix this problem. I have been posting this problem since i upgraded to snow leopard. i am unable to empty the trash in the finder, if the trash contains a file that i sent as an attachment. i get a message saying "file in use".