Model: mx80
Junos: 13.3R10.2
set dynamic-profiles CLIENTS-IPoE interfaces "$junos-interface-ifd-name" unit "$junos-underlying-interface-unit" family inet
set dynamic-profiles VLAN-IPoE interfaces demux0 unit "$junos-interface-unit" demux-source inet
set dynamic-profiles VLAN-IPoE interfaces demux0 unit "$junos-interface-unit" no-traps
set dynamic-profiles VLAN-IPoE interfaces demux0 unit "$junos-interface-unit" proxy-arp
set dynamic-profiles VLAN-IPoE interfaces demux0 unit "$junos-interface-unit" vlan-tags outer "$junos-stacked-vlan-id"
set dynamic-profiles VLAN-IPoE interfaces demux0 unit "$junos-interface-unit" vlan-tags inner "$junos-vlan-id"
set dynamic-profiles VLAN-IPoE interfaces demux0 unit "$junos-interface-unit" demux-options underlying-interface "$junos-underlying-interface"
set dynamic-profiles VLAN-IPoE interfaces demux0 unit "$junos-interface-unit" family inet unnumbered-address lo0.0
set dynamic-profiles svc-global-inet variables SPEED_IN default-value 100m
set dynamic-profiles svc-global-inet variables SPEED_OUT default-value 100m
set dynamic-profiles svc-global-inet variables POLICER_IN uid
set dynamic-profiles svc-global-inet variables POLICER_OUT uid
set dynamic-profiles svc-global-inet interfaces "$junos-interface-ifd-name" unit "$junos-interface-unit" family inet filter input "$SPEED_IN"
set dynamic-profiles svc-global-inet interfaces "$junos-interface-ifd-name" unit "$junos-interface-unit" family inet filter input precedence 50
set dynamic-profiles svc-global-inet interfaces "$junos-interface-ifd-name" unit "$junos-interface-unit" family inet filter output "$SPEED_OUT"
set dynamic-profiles svc-global-inet interfaces "$junos-interface-ifd-name" unit "$junos-interface-unit" family inet filter output precedence 50
set dynamic-profiles svc-global-inet firewall family inet filter "$SPEED_IN" interface-specific
set dynamic-profiles svc-global-inet firewall family inet filter "$SPEED_IN" term default then policer "$POLICER_IN"
set dynamic-profiles svc-global-inet firewall family inet filter "$SPEED_IN" term default then service-accounting
set dynamic-profiles svc-global-inet firewall family inet filter "$SPEED_IN" term default then accept
set dynamic-profiles svc-global-inet firewall family inet filter "$SPEED_OUT" interface-specific
set dynamic-profiles svc-global-inet firewall family inet filter "$SPEED_OUT" term default then policer "$POLICER_OUT"
set dynamic-profiles svc-global-inet firewall family inet filter "$SPEED_OUT" term default then service-accounting
set dynamic-profiles svc-global-inet firewall family inet filter "$SPEED_OUT" term default then accept
set dynamic-profiles svc-global-inet firewall policer "$POLICER_IN" filter-specific
set dynamic-profiles svc-global-inet firewall policer "$POLICER_IN" logical-interface-policer
set dynamic-profiles svc-global-inet firewall policer "$POLICER_IN" if-exceeding bandwidth-limit "$SPEED_IN"
set dynamic-profiles svc-global-inet firewall policer "$POLICER_IN" if-exceeding burst-size-limit 512k
set dynamic-profiles svc-global-inet firewall policer "$POLICER_IN" then discard
set dynamic-profiles svc-global-inet firewall policer "$POLICER_OUT" filter-specific
set dynamic-profiles svc-global-inet firewall policer "$POLICER_OUT" logical-interface-policer
set dynamic-profiles svc-global-inet firewall policer "$POLICER_OUT" if-exceeding bandwidth-limit "$SPEED_OUT"
set dynamic-profiles svc-global-inet firewall policer "$POLICER_OUT" if-exceeding burst-size-limit 512k
set dynamic-profiles svc-global-inet firewall policer "$POLICER_OUT" then discard
set system services dhcp-local-server group IPoE authentication password IPoE
set system services dhcp-local-server group IPoE authentication username-include user-prefix OPT82NOIP
set system services dhcp-local-server group IPoE authentication username-include mac-address
set system services dhcp-local-server group IPoE dynamic-profile CLIENTS-IPoE
set system services dhcp-local-server group IPoE interface demux0.0
set access profile BILLING accounting-order radius
set access profile BILLING authentication-order radius
set access profile BILLING radius authentication-server 89.1.1.1
set access profile BILLING radius accounting-server 89.1.1.1
set access profile BILLING radius options accounting-session-id-format decimal
set access profile BILLING radius-server 89.1.1.1 port 1812
set access profile BILLING radius-server 89.1.1.1 accounting-port 1813
set access profile BILLING radius-server 89.1.1.1 secret "$9$cy-rlM7Nb2oGLxb2aZkqTz3/tOrlMXNb"
set access profile BILLING radius-server 89.1.1.1 timeout 30
set access profile BILLING radius-server 89.1.1.1 retry 5
set access profile BILLING radius-server 89.1.1.1 max-outstanding-requests 1000
set access profile BILLING radius-server 89.1.1.1 source-address 89.1.1.2
set access profile BILLING accounting order radius
set access profile BILLING accounting accounting-stop-on-failure
set access profile BILLING accounting accounting-stop-on-access-deny
set access profile BILLING accounting immediate-update
set access profile BILLING accounting coa-immediate-update
set access profile BILLING accounting address-change-immediate-update
set access profile BILLING accounting update-interval 10
set access profile BILLING accounting statistics volume-time
set interfaces xe-0/0/1 flexible-vlan-tagging
set interfaces xe-0/0/1 auto-configure stacked-vlan-ranges dynamic-profile VLAN-IPoE accept dhcp-v4
set interfaces xe-0/0/1 auto-configure stacked-vlan-ranges dynamic-profile VLAN-IPoE ranges 1002-1002,10-15
set interfaces xe-0/0/1 auto-configure stacked-vlan-ranges access-profile BILLING
set interfaces xe-0/0/1 auto-configure remove-when-no-subscribers
set interfaces xe-0/0/1 encapsulation flexible-ethernet-services
When session starts it doents apply svc-global-inet profile. it comes with values svc-global-inet($SPEED_IN,$SPEED_OUT), but it doesn`t aplly, whnat my misstake in the configuration.
Type: VLAN
Logical System: default
Routing Instance: default
Interface: demux0.1073830782
Interface type: Dynamic
Underlying Interface: xe-0/0/1
Dynamic Profile Name: VLAN-IPoE
Dynamic Profile Version: 1
State: Active
Session ID: 183647
Stacked VLAN Id: 0x8100.1002
VLAN Id: 0x8100.11
Login Time: 2020-01-09 14:45:05 UTC
Type: DHCP
User Name: OPT82NOIP.68ff.7b98.0083
IP Address: 89.1.3.12
IP Netmask: 255.255.254.0
Logical System: default
Routing Instance: default
Interface: demux0.1073830780
Interface type: Static
Underlying Interface: demux0.1073830780
Dynamic Profile Name: CLIENTS-IPoE
Dynamic Profile Version: 1
MAC Address: 68:ff:7b:98:00:83
State: Configured
Radius Accounting ID: 183648
Session ID: 183648
Stacked VLAN Id: 1002
VLAN Id: 15
Login Time: 2020-01-09 14:45:05 UTC
DHCP Options: len 40
35 01 01 39 02 02 40 37 08 01 03 06 0c 0f 1c 2a 79 3c 0c 75
64 68 63 70 20 31 2e 33 30 2e 31 0c 07 4f 70 65 6e 57 72 74
IP Address Pool: Dynamic-POOL1
Authentication State: AuthClntRespWait (why?)
dmitry@Mine-Juniper-GW# run show network-access aaa subscribers session-id 183648 detail
Type: dhcp
Stripped username: OPT82NOIP.68ff.7b98.0083
AAA Logical system/Routing instance: default:default
Target Logical system/Routing instance: default:default
Access-profile: BILLING
Session ID: 183648
Accounting Session ID: 183648
Multi Accounting Session ID: 0
IP Address: 89.1.3.12
Authentication State: AuthClntRespWait
Accounting State: Acc-Init
Provisioning Type: None
Maybe my firmware needs to be upgraded?