CPS vdra Troubleshooting Guide, Release

Similar documents
Software Configuration Guide, Cisco IOS XE Everest 16.6.x (Catalyst 9300 Switches)

Cisco UCS Director API Integration and Customization Guide, Release 5.4

Cisco TEO Adapter Guide for SAP Java

Cisco TEO Adapter Guide for Microsoft System Center Operations Manager 2007

Cisco TEO Adapter Guide for

Cisco TEO Adapter Guide for Microsoft Windows

Cisco Connected Mobile Experiences REST API Getting Started Guide, Release 10.2

Host Upgrade Utility User Guide for Cisco UCS E-Series Servers and the Cisco UCS E-Series Network Compute Engine

Cisco TEO Adapter Guide for SAP ABAP

Videoscape Distribution Suite Software Installation Guide

Cisco Nexus 7000 Series NX-OS Virtual Device Context Command Reference

Cisco Nexus 1000V for KVM REST API Configuration Guide, Release 5.x

Cisco Nexus 1000V for KVM OpenStack REST API Configuration Guide, Release 5.x

Cisco Nexus 9000 Series NX-OS Virtual Machine Tracker Configuration Guide, Release 9.x

Cisco Connected Grid Design Suite (CGDS) - Substation Workbench Designer User Guide

Installation and Configuration Guide for Visual Voic Release 8.5

Cisco UCS Director PowerShell Agent Installation and Configuration Guide, Release 5.4

CPS UDC MoP for Session Migration, Release

Cisco Nexus 7000 Series Switches Configuration Guide: The Catena Solution

Cisco FindIT Plugin for Kaseya Quick Start Guide

Cisco Unified Communications Self Care Portal User Guide, Release

OpenStack Group-Based Policy User Guide

Cisco Terminal Services (TS) Agent Guide, Version 1.1

Cisco UCS Integrated Management Controller Faults Reference Guide

Application Launcher User Guide

SAML SSO Okta Identity Provider 2

Cisco Host Upgrade Utility 1.5(1) User Guide

Cisco Nexus 9000 Series NX-OS IP Fabric for Media Solution Guide, Release 7.0(3)I4(2)

Cisco Terminal Services (TS) Agent Guide, Version 1.1

Cisco Policy Suite Upgrade Guide Release 9.0.0

Cisco Unified Contact Center Express Historical Reporting Guide, Release 10.6(1)

Cisco Unified Contact Center Express Historical Reporting Guide, Release 10.5(1)

Cisco Terminal Services (TS) Agent Guide, Version 1.0

Enterprise Chat and Supervisor s Guide, Release 11.5(1)

Cisco IOS Flexible NetFlow Command Reference

Process Automation Guide for Automation for SAP BOBJ Enterprise

Cisco ASR 9000 Series Aggregation Services Router Netflow Command Reference, Release 4.3.x

Cisco Jabber IM for iphone Frequently Asked Questions

Migration and Upgrade: Frequently Asked Questions

Recovery Guide for Cisco Digital Media Suite 5.4 Appliances

Cisco Unified Communications Manager Device Package 8.6(2)( ) Release Notes

Cisco CIMC Firmware Update Utility User Guide

Cisco UC Integration for Microsoft Lync 9.7(4) User Guide

TechNote on Handling TLS Support with UCCX

IP Routing: ODR Configuration Guide, Cisco IOS Release 15M&T

NetFlow Configuration Guide

Flow Sensor and Load Balancer Integration Guide. (for Stealthwatch System v6.9.2)

Cisco Unified Communications Self Care Portal User Guide, Release 11.5(1)

Method of Procedure for HNB Gateway Configuration on Redundant Serving Nodes

Cisco StadiumVision Management Dashboard Monitored Services Guide

Cisco TelePresence FindMe Cisco TMSPE version 1.2

Cisco UCS Virtual Interface Card Drivers for Windows Installation Guide

Configure WSA to Upload Log Files to CTA System

CPS UDC SNMP and Alarms Guide, Release

AsyncOS 11.0 API - Getting Started Guide for Security Appliances

Cisco IOS XR Carrier Grade NAT Command Reference for the Cisco CRS Router, Release 5.2.x

Release Notes for Cisco Virtualization Experience Client 2111/2211 PCoIP Firmware Release 4.0.2

Configure WSA to Upload Log Files to CTA System

Cisco ACI with OpenStack OpFlex Architectural Overview

Cisco UCS Performance Manager Release Notes

Cisco IOS Shell Command Reference

Cisco Nexus 1000V for KVM Interface Configuration Guide, Release 5.x

Cisco Jabber for Android 10.5 Quick Start Guide

Cisco UCS Director F5 BIG-IP Management Guide, Release 5.0

Media Services Proxy Command Reference

Cisco TelePresence Management Suite Extension for Microsoft Exchange Software version 3.1

Prime Service Catalog: UCS Director Integration Best Practices Importing Advanced Catalogs

Cisco IOS First Hop Redundancy Protocols Command Reference

NNMi Integration User Guide for CiscoWorks Network Compliance Manager 1.6

Cisco Instant Connect MIDlet Reference Guide

Embedded Packet Capture Configuration Guide

Cisco Nexus 7000 Series NX-OS Quality of Service Command Reference

Process Automation Guide for System Copy for SAP

Cisco Proximity Desktop

Cisco IOS HTTP Services Command Reference

Cisco Meeting App. Cisco Meeting App (OS X) Release Notes. July 21, 2017

Cisco TEO Process Automation Guide for System Copy for SAP

Enterprise Chat and Administrator s Guide to System Console, Release 11.6(1)

Flexible Netflow Configuration Guide, Cisco IOS XE Release 3SE (Catalyst 3850 Switches)

Cisco Discovery Protocol Configuration Guide, Cisco IOS XE Release 3S (Cisco ASR 920 Series)

Enterprise Chat and Upgrade Guide, Release 11.6(1)

IP Addressing: Fragmentation and Reassembly Configuration Guide, Cisco IOS XE Release 3S (Cisco ASR 1000)

Cisco Unified Communications Manager Device Package 10.5(1)( ) Release Notes

Cisco TelePresence Management Suite Extension for Microsoft Exchange Software version 5.7. User Guide July 2018

Cisco UCS Performance Manager Release Notes

Cisco Evolved Programmable Network System Test Topology Reference Guide, Release 5.0

Cisco CSPC 2.7x. Configure CSPC Appliance via CLI. Feb 2018

Smart Software Manager satellite Installation Guide

Cisco Meeting App. Cisco Meeting App (Windows) Release Notes. March 08, Cisco Systems, Inc.

Cisco TelePresence Management Suite Extension for Microsoft Exchange 5.5

Cisco Jabber Video for ipad Frequently Asked Questions

Cisco Meeting Management

Cisco TelePresence Management Suite Extension for Microsoft Exchange 5.2

User Guide for Accessing Cisco Unity Connection Voice Messages in an Application

Validating Service Provisioning

Direct Upgrade Procedure for Cisco Unified Communications Manager Releases 6.1(2) 9.0(1) to 9.1(x)

Cisco Terminal Services (TS) Agent Guide, Version 1.2

Backup and Restore Guide for Cisco Unified Communications Domain Manager 8.1.3

IP Addressing: Fragmentation and Reassembly Configuration Guide

Firepower REST API Quick Start Guide, Version 6.1

Transcription:

First Published: 2017-08-18 Last Modified: 2017-08-18 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883

THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS. THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY. The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB's public domain version of the UNIX operating system. All rights reserved. Copyright 1981, Regents of the University of California. NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED AS IS" WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE. IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https:/ /www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R) 2017 Cisco Systems, Inc. All rights reserved.

CONTENTS Preface Preface v About this Guide v Audience v Additional Support v Conventions (all documentation) vi Obtaining Documentation and Submitting a Service Request vii CHAPTER 1 Troubleshooting CPS vdra 1 Overview 1 General Troubleshooting 1 Diameter Troubleshooting and Connections 1 DRA Plug-in Configuration in DRA Policy Builder (PB) 2 Troubleshooting Basics 3 Diameter Error Codes and Scenarios 3 Common Troubleshooting Steps 6 CPS vdra Logs 6 Counters and Statistics 6 Frequently Encountered Troubles in CPS vdra 7 Redis Not Working 7 Gx Bindings not happening on Mongo 8 Rx Call Failing at CPS vdra 9 CPS vdra Forwarding Message to Wrong Peer 9 PCRF Generated Messages not Reaching CPS vdra 10 Issues in Reaching Ports and Setup IPs 10 iii

Contents iv

Preface About this Guide, page v Audience, page v Additional Support, page v Conventions (all documentation), page vi Obtaining Documentation and Submitting a Service Request, page vii About this Guide This document describes common methods and scenarios of correcting processing and production functions for CPS vdra and its various components. Audience This guide is best used by these readers: Network administrators Network engineers Network operators System administrators This document assumes a general understanding of network architecture, configuration, and operations. Additional Support For further documentation and support: Contact your Cisco Systems, Inc. technical representative. Call the Cisco Systems, Inc. technical support number. v

Conventions (all documentation) Preface Write to Cisco Systems, Inc. at support@cisco.com. Refer to support matrix at https://www.cisco.com/c/en/us/support/index.html and to other documents related to Cisco Policy Suite. Conventions (all documentation) This document uses the following conventions. Conventions bold font italic font [ ] {x y z } [ x y z ] string courier font < > [ ]!, # Indication Commands and keywords and user-entered text appear in bold font. Document titles, new or emphasized terms, and arguments for which you supply values are in italic font. Elements in square brackets are optional. Required alternative keywords are grouped in braces and separated by vertical bars. Optional alternative keywords are grouped in brackets and separated by vertical bars. A nonquoted set of characters. Do not use quotation marks around the string or the string will include the quotation marks. Terminal sessions and information the system displays appear in courier font. Nonprinting characters such as passwords are in angle brackets. Default responses to system prompts are in square brackets. An exclamation point (!) or a pound sign (#) at the beginning of a line of code indicates a comment line. Note Means reader take note. Notes contain helpful suggestions or references to material not covered in the manual. vi

Preface Obtaining Documentation and Submitting a Service Request Caution Means reader be careful. In this situation, you might perform an action that could result in equipment damage or loss of data. Warning IMPORTANT SAFETY INSTRUCTIONS. Means danger. You are in a situation that could cause bodily injury. Before you work on any equipment, be aware of the hazards involved with electrical circuitry and be familiar with standard practices for preventing accidents. Use the statement number provided at the end of each warning to locate its translation in the translated safety warnings that accompanied this device. SAVE THESE INSTRUCTIONS Warning Provided for additional information and to comply with regulatory and customer requirements. Obtaining Documentation and Submitting a Service Request For information on obtaining documentation, using the Cisco Bug Search Tool (BST), submitting a service request, and gathering additional information, see What's New in Cisco Product Documentation. To receive new and revised Cisco technical content directly to your desktop, you can subscribe to the What's New in Cisco Product Documentation RSS feed. RSS feeds are a free service. vii

Obtaining Documentation and Submitting a Service Request Preface viii

CHAPTER 1 Troubleshooting CPS vdra Overview, page 1 General Troubleshooting, page 1 Diameter Troubleshooting and Connections, page 1 Troubleshooting Basics, page 3 Common Troubleshooting Steps, page 6 Frequently Encountered Troubles in CPS vdra, page 7 Overview CPS vdra is a functional element that ensures that all Diameter sessions established over Gx, Rx interfaces and for unsolicited application reporting, the Sd interface for a certain IP-CAN session reach the same PCRF or destined PCRF when multiple and separately addressable PCRFs have been deployed in a Diameter realm. General Troubleshooting Run the following command in CLI to view the diagnostics status. Verify that the status of all the nodes is in passing state. admin@orchestrator[master-0]# show system diagnostics status Run the following command in CLI to view the docker engines status. Verify that all docker engines are in CONNECTED state. admin@orchestrator[master-0]# show docker engine Diameter Troubleshooting and Connections For messages belonging to particular interface, CPS vdra should be ready to make diameter connection on the configured application port. As CPS vdra acts as a server, it should be listening on ports for different applications to accept any incoming diameter requests for the application. If you are facing problems making diameter connections, check for the following configuration: 1

DRA Plug-in Configuration in DRA Policy Builder (PB) Troubleshooting CPS vdra DRA Plug-in Configuration in DRA Policy Builder (PB) Figure 1: DRA Endpoints Step 1 Step 2 Check status of application base port on active policy director (lb). It should be listening to diameter connections externally on VIP and internally to Policy Servers (QNS). [root@lb01 ~]# netstat -na grep 3868 tcp 0 0 10.77.207.100:3868 0.0.0.0:* LISTEN tcp 0 0 ::ffff:80.80.80.10:3868 :::* LISTEN Check haproxy-diameter.cfg file for proper entries: For Step 1, on page 2 and Step 2, on page 2 configuration, the entries should be as follows: [root@lb01 ~]# cat /etc/haproxy/haproxy-diameter.cfg global daemon nbproc 1 # number of processing cores stats socket /tmp/haproxy-diameter defaults timeout client 60000ms # maximum inactivity time on the client side timeout server 180000ms # maximum inactivity time on the server side timeout connect 5000ms # maximum time to wait for a connection attempt to a server to succeed log 127.0.0.1 local1 err listen diameter-int1 bind 10.77.207.100:3868 mode tcp option tcpka balance leastconn server lb01-a lb01:3868 check server lb01-b lb01:3869 check server lb01-c lb01:3870 check listen diameter-int2 bind 10.77.207.100:4868 mode tcp option tcpka balance leastconn server lb01-a lb01:4868 check server lb01-b lb01:4869 check server lb01-c lb01:4870 check listen stats_proxy_diameter lbvip01:5540 mode http option httpclose 2

Troubleshooting CPS vdra Troubleshooting Basics Step 3 option abortonclose # enable web-stats stats enable stats uri /haproxy-diam?stats #stats auth haproxy:cisco123 stats refresh 60s stats hide-version Listen for diameter traffic by logging into lb01 and lb02 and execute the following command: tcpdump -i any port 3868 -s 0 -vv Troubleshooting Basics Troubleshooting CPS vdra consists of these types of basic tasks: Gathering Information Collecting Logs Running Traces Diameter Error Codes and Scenarios Table 1: Diameter Error Codes and Scenarios Result-Code Informational DIAMETER_MULTI_ROUND_AUTH Success DIAMETER_SUCCESS DIAMETER_LIMITED_SUCCESS Protocol Errors [E-bit set] DIAMETER_COMMAND _UNSUPPORTED Result-Code Value 1001 2001 2002 3001 Description Subsequent messages triggered by client shall also used in Authentication and to get access of required resources. Generally used in Diameter NAS. Request processed Successfully. Request is processed but some more processing is required by Server to provide access to user. Server returns it if Diameter Command-Code is un-recognized by server. 3

Diameter Error Codes and Scenarios Troubleshooting CPS vdra Result-Code DIAMETER_UNABLE _TO_DELIVER DIAMETER_REALM_NOT _SERVED DIAMETER_TOO_BUSY DIAMETER_LOOP_DETECTED DIAMETER_REDIRECT _INDICATION DIAMETER_APPLICATION _UNSUPPORTED DIAMETER_INVALID_HDR_BITS DIAMETER_INVALID_AVP_BITS DIAMETER_UNKNOWN_PEER Result-Code Value 3002 3003 3004 3005 3006 3007 3008 3009 3010 Description Message cannot be delivered because there is no Host with Diameter URI present in Destination-Host AVP in associated Realm. Intended Realm is not recognized. Shall return by server only when server unable to provide requested service, where all the pre-requisites are also met. Client should also send the request to alternate peer. - In Response from Redirect Agent. - It is sent when a request is received with invalid bits combination for considered command-code in DIAMETER Header structure. For example, Marking Proxy-Bit in CER message. It is sent when a request is received with invalid flag bits in an AVP. A DIAMETER server can be configured whether it shall accept DIAMETER connection from all nodes or only from specific nodes. If it is configured to accept connection from specific nodes and receives CER from message from any node other than specified. Transient Failures [Could not satisfy request at this moment] DIAMETER_AUTHENTICATION _REJECTED DIAMETER_OUT_OF_SPACE 4001 4002 Returned by Server, most likely because of invalid password. Returned by node, when it receives accounting information but unable to store it because of lack of memory. 4

Troubleshooting CPS vdra Diameter Error Codes and Scenarios Result-Code ELECTION_LOST Result-Code Value 4003 Description Peer determines that it has lost election by comparing Origin-Host value received in CER with its own DIAMETER IDENTITY and found that received DIAMETER IDENTITY is higher. Permanent Failures [To inform peer, request is failed, should not be attempted again] DIAMETER_AVP _UNSUPPORTED DIAMETER_UNKNOWN _SESSION_ID DIAMETER_AUTHORIZATION _REJECTED DIAMETER_INVALID_AVP_VALUE DIAMETER_MISSING_AVP DIAMETER_RESOURCES _EXCEEDED DIAMETER_CONTRADICTING _AVPS DIAMETER_AVP_NOT_ALLOWED DIAMETER_AVP_OCCURS _TOO_MANY_TIMES DIAMETER_NO_COMMON _APPLICATION DIAMETER_UNSUPPORTED _VERSION 5001 5002 5003 5004 5005 5006 5007 5008 5009 5010 5011 AVP marked with Mandatory Bit, but peer does not support it. - User can not be authorized. For example, Comes in AIA on s6a interface. - Mandatory AVP in request message is missing. A request was received that cannot be authorized because the user has already expended allowed resources. An example of this error condition is a user that is restricted to one dial-up PPP port, attempts to establish a second PPP connection. Server has identified that AVPs are present that are contradictory to each other. Message is received by node (Server) that contain AVP must not be present. If message contains the a AVP number of times that exceeds permitted occurrence of AVP in message definition. In response of CER if no common application supported between the peers. Self explanatory. 5

Common Troubleshooting Steps Troubleshooting CPS vdra Result-Code DIAMETER_UNABLE _TO_COMPLY DIAMETER_INVALID_BIT _IN_HEADER DIAMETER_INVALID _AVP_LENGTH DIAMETER_INVALID _MESSAGE_LENGTH DIAMETER_INVALID_AVP _BIT_COMBO DIAMETER_NO_COMMON _SECURITY Result-Code Value 5012 5013 5014 5015 5016 5017 Description Message rejected because of unspecified reasons. When an unrecognized bit in the Diameter header is set to one. Self explanatory. Self explanatory. For example, marking AVP to Mandatory while message definition doesn't say so. In response of CER if no common security mechanism supported between the peers. Common Troubleshooting Steps CPS vdra Logs Step 1 Step 2 Use the following command in CLI to view the consolidated application logs. admin@orchestrator[master-0]# show log application Use the following command in CLI to view the consolidated engine logs. admin@orchestrator[master-0]# show log engine Counters and Statistics Check for statistics generated at pcrfclient01/02 in /var/broadhop/stats and counters in beans at jmx terminal. 6

Troubleshooting CPS vdra Frequently Encountered Troubles in CPS vdra Frequently Encountered Troubles in CPS vdra Redis Not Working Step 1 Step 2 Step 3 Step 4 Check redis status by executing the following command: [root@lb01 ~]# service redis status redis-server (pid 22511) is running... Try starting redis process by executing the following command: [root@lb01 ~]# service redis start Check the following entries in /etc/broadhop/dratopology.ini file at policy directors (lb) and Policy Servers (QNS) for redis connecting on ports 6379, 6380, 6381, 6382: [root@lb02 ~]# cat /etc/broadhop/dratopology.ini dra.redis.qserver.1=lb02:6379 dra.redis.qserver.2=lb02:6380 dra.redis.qserver.3=lb02:6381 dra.redis.qserver.4=lb02:6382 dra.redis.qserver.4=lb02:6383 dra.local-control-plane.redis.1=lb02:6379 dra.mongodb.binding.db.ipv6.uri=mongodb://sessionmgr01:27718 dra.mongodb.binding.db.ipv4.uri=mongodb://sessionmgr01:27718 dra.mongodb.binding.db.imsiapn.uri=mongodb://sessionmgr01:27718 dra.mongodb.pcap.uri=mongodb://sessionmgr01:27718 dra.mongodb.binding.db.session.uri=mongodb://sessionmgr01:27718 [root@lb02 ~]# cat /etc/broadhop/redistopology.ini dra.redis.qserver.1=lb02:6379 dra.redis.qserver.2=lb02:6380 dra.redis.qserver.3=lb02:6381 dra.redis.qserver.4=lb02:6382 dra.local-control-plane.redis.1=lb02:6379 Redis process on active policy director (lb) should be established with all Policy Servers (QNS) as shown below: [root@lb01 ~]# netstat -na grep 6379 tcp 0 0 0.0.0.0:6379 0.0.0.0:* LISTEN tcp 0 0 80.80.80.10:6379 80.80.80.10:37400 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:38020 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:38034 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:37390 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38207 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.16:50597 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.14:35703 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.14:35711 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38188 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:37375 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38174 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38229 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38211 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.14:35709 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.16:50590 ESTABLISHED 7

Gx Bindings not happening on Mongo Troubleshooting CPS vdra tcp 0 0 80.80.80.10:6379 80.80.80.10:38032 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38172 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.16:50605 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:38204 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:38213 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:38223 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:38044 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38187 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38205 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:38211 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:37672 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.14:35710 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.17:59833 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:37388 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:37389 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:37662 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.17:59824 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.16:50596 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38210 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.15:49162 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38231 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38230 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.15:49159 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38152 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:37659 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38208 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.17:59832 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.15:49161 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38206 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:38212 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:38033 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:37650 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.15:49160 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38155 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.10:37660 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.17:59831 ESTABLISHED tcp 0 0 80.80.80.10:6379 80.80.80.11:38186 ESTABLISHED tcp 0 0 :::6379 :::* LISTEN tcp 0 0 ::ffff:80.80.80.10:37660 ::ffff:80.80.80.10:6379 ESTABLISHED Gx Bindings not happening on Mongo Step 1 Step 2 Step 3 Check if the binding's exceptions are coming in consolidated-qns.log file. Check for the entry -DdraBindingTier=true in qns.conf file on all Policy Servers (QNS). Check for the entries in /etc/broadhop/dratopology.ini file. dra.redis.qserver.1=lb02:6379 dra.redis.qserver.2=lb02:6380 8

Troubleshooting CPS vdra Rx Call Failing at CPS vdra dra.redis.qserver.3=lb02:6381 dra.redis.qserver.4=lb02:6382 dra.redis.qserver.4=lb02:6383 dra.local-control-plane.redis.1=lb02:6379 dra.mongodb.binding.db.ipv6.uri=mongodb://sessionmgr01:27718 dra.mongodb.binding.db.ipv4.uri=mongodb://sessionmgr01:27718 dra.mongodb.binding.db.imsiapn.uri=mongodb://sessionmgr01:27718 dra.mongodb.pcap.uri=mongodb://sessionmgr01:27718 dra.mongodb.binding.db.session.uri=mongodb://sessionmgr01:27718 For example, make sure if the primary binding server is 27718 only as per above example. Step 4 Check for the Binding Keys entries in binding key type profile and the application attached to the profile. Rx Call Failing at CPS vdra Step 1 Step 2 Step 3 Step 4 Step 5 Step 6 Check for the Binding key Retriever for Rx Profile. Check if the Gx Binding is available for that Binding key. Check the consolidated-qns.log file if CPS vdra is able to retrieve SRK from the bindings. Check for any exception in consolidated-qns.log file during binding retrieval. If Rx peer is available for the same SRK at CPS vdra, CPS vdra should forward the Rx message to that peer. Check the connection for that peer and proper entries in Peer Group, Peer Routing, Peer Group Peer and Rx_Routing for Rx New session rules. CPS vdra Forwarding Message to Wrong Peer Step 1 Step 2 Step 3 Step 4 Check the Control Center configuration in Gx_Routing for new session rules. Gx routing should have the AVP defined on the basis of which, one wants to route the traffic. Check whether the Control Center configuration for the Peer is bonded to correct Peer Group. Check whether the Peer Group is assigned to correct Peer Route and Dynamic AVPs are properly aligned with Peer Route in Gx New Session Rules. Diameter Connection with the desired Destination Peer should be established with CPS vdra. 9

PCRF Generated Messages not Reaching CPS vdra Troubleshooting CPS vdra PCRF Generated Messages not Reaching CPS vdra Step 1 Make sure PCRF has the correct entry of CPS vdra as next hop. Figure 2: Next Hop Routes Next Hop definition is mandatory in PCRF to forward the messages to CPS vdra generated by PCRF itself. For example, Gx-RAR, Sd-TSR Step 2 Wild Card Entry not supported in Next Hop Routing configuration. Issues in Reaching Ports and Setup IPs Step 1 Step 2 Check firewall is running or not. Make sure the firewall configuration is OK. a) To check if this is the problem, then stop the firewall. /etc/init.d/iptables stop 10