trace access-user object online-fail

Function

The trace access-user object online-fail command allows the system to automatically trace the user information corresponding to a specified number of user login failure causes that are listed in descending order within 20 minutes. The system can locate the latest login failure user according to the user login failure records corresponding to each of such failure causes and automatically trace this user by MAC address.

By default, the tracing duration of an object is 15 minutes.

This command is supported only on the NetEngine 8000 F1A.

Format

trace access-user object online-fail top topnum [ -t time-value ]

Parameters

Parameter Description Value
-t time-value

Sets the tracing time.

The value is an integer ranging from 0 to 60, in minutes. If the value is 0, it indicates that the object is being traced all the time.

top topnum

Sets the trace online-fail reason number.

The value is an integer ranging from 1 to 5.

Views

System view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
bras-control execute

Usage Guidelines

Usage Scenario

In case of a user login failure, you can run the trace access-user object online-fail command to rapidly enable the user service tracing function. After this command is run, the causes of user login failures within 20 minutes are listed in descending order by frequency. With the number of user login failure causes that are topped specified, the system locates the latest login failure user according to the user login failure records corresponding to each of such failure causes. The system then automatically traces this user by MAC address and writes the traced service information to a file. A file named user MAC address + time when the tracing object was generated is written for each user. An example of the file name is 00e0-fc12-3456_20201120240605.txt, The output directory of the trace file is "/opt/vrpv8/home/business-trace".

The system can automatically trace the users corresponding to up to five user login failure causes that are topped. That is, the system can automatically trace at most five failure users.

Precautions

  1. This command is used for diagnosis only. In normal cases, this command consumes a large number of resources and may affect services.
  2. The system traces only the users corresponding to the specified number of user login failure causes that are topped. The system traces such users by MAC address. The user types include IPoE, PPPoE, LAC, web, and EAP.
  3. In a scenario of one-to-many mapping between one MAC address and multiple sessions, if multiple users have the same MAC address and the user login failure cause of one of the user having this MAC address is within the scope of automatic tracing, the tracing information about all the users having this MAC address will be displayed and written into the same file. This consumes a large number of resources and may affect services.
  4. In VS mode, this command is applicable only to the admin VS.

Example

# Configure the system to automatically trace the user information corresponding to the top five user login failure causes.
<HUAWEI> system-view
[~HUAWEI] trace access-user object online-fail top 3
# Configure the system to automatically trace the user information corresponding to the top five user login failure causes within five minutes.
<HUAWEI> system-view
[~HUAWEI] trace access-user object online-fail top 3 -t 5
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >