Cisco Systems OL-4387-02 manual SSG Port-Bundle Host Key, Restrictions for SSG Open Garden

Page 44

Chapter 6 Service Connection

SSG Port-Bundle Host Key

Restrictions for SSG Open Garden

The SSG Open Garden feature has the following restrictions:

RADIUS accounting records are not created for Open Garden services.

The Cisco 10000 router supports the creation of Open Garden services by using local profiles only; you cannot use RADIUS profiles.

The Cisco 10000 router does not support overlapping Open Garden service networks.

Configuration of SSG Open Garden

To designate a service as an Open Garden service, use the ssg open-gardencommand in global configuration mode. For more information on configuring an Open Garden, refer to the

SSG Open Garden, Release 12.2(4)B feature module.

Configuration Example for SSG Open Garden

The following example defines two services named og1 and og2 and adds them to the Open Garden.

!

ssg open-garden og1 ssg open-garden og2

!

local-profile og1

attribute 26 9 251 “Oopengarden1.com” attribute 26 9 251 “D10.13.1.5” attribute 26 9 251 “R10.1.1.0;255.255.255.0 local-profile og2

attribute 26 9 251 “Oopengarden2.com” attribute 26 9 251 “D10.14.1.5”

attribute 26 9 251 “R10.2.1.0;255.255.255.0” attribute 26 9 251 “R10.3.1.0;255.255.255.0”

!

ssg bind service og2 10.5.5.1

SSG Port-Bundle Host Key

The SSG Port-Bundle Host Key feature enhances communication and functionality between SSG and SESM by introducing a mechanism that uses the host source IP address and source port to identify and monitor subscribers.

With the SSG Port-Bundle Host Key feature, SSG performs port-address translation (PAT) and network-address translation (NAT) on the HTTP traffic between the subscriber and the SESM server. When a subscriber sends an HTTP packet to the SESM server, SSG creates a port map that changes the source IP address to a configured SSG source IP address and changes the source TCP port to a port allocated by SSG. SSG assigns a bundle of ports to each subscriber because one subscriber can have several simultaneous TCP sessions when accessing a web page. The assigned host key, or combination of port-bundle and SSG source IP address, uniquely identifies each subscriber. The host key is carried in RADIUS packets sent between the SESM server and SSG in the Subscriber IP vendor-specific attribute (VSA). When the SESM server sends a reply to the subscriber, SSG translates the destination IP address and destination TCP port according to the port map.

Cisco 10000 Series Router Service Selection Gateway Configuration Guide

6-6

OL-4387-02

 

 

Image 44
Contents Corporate Headquarters Copyright 2004, Cisco Systems, Inc All rights reserved N T E N T S IiiConfiguration Example for SSG AutoDomain Configuration Example for SSG Open Garden Configuration of VPI/VCI Static Binding to a Service Profile SSG Unconfig ViiViii Document Organization About This GuideAudience Document Conventions Cisco.com Related DocumentationObtaining Documentation Documentation Feedback Obtaining Technical AssistanceDocumentation CD-ROM Ordering DocumentationCisco TAC Website Opening a TAC CaseTAC Case Priority Definitions XiiiObtaining Additional Publications and Information XivService Selection Gateway Overview Service Selection GatewaySSG Topology Example Default Network Access ProtocolsSupported SSG Features SSG RestrictionsService Selection Gateway Overview SSG Restrictions SSG Prerequisites SSG Architecture ModelService Selection Gateway Overview SSG Architecture Model OL-4387-02 Scalability and Performance Limitations and RestrictionsScalability and Performance Limitations and Restrictions Prerequisites for Single Host Logon SSG Logon and LogoffSingle Host Logon Restrictions for SSG Autologoff Configuration of SSG AutologoffSSG Autologoff SSG Prepaid Idle Timeout Configuration Example for SSG AutologoffExample 3-1 SSG Autologoff Using ARP Ping Example 3-2 SSG Autologoff Using Icmp PingService Authorization Service ReauthorizationRestrictions for SSG Prepaid Idle Timeout Prerequisites for SSG Prepaid Idle TimeoutConfiguration of SSG Prepaid Idle Timeout Configuration Example for SSG Prepaid Idle TimeoutSSG Session and Idle Timeout Example 3-5 SSG Service-Specific TCP RedirectExample 3-7 SSG Threshold Volume Example 3-6 SSG Threshold TimeAuthentication and Accounting SSG Full Username Radius AttributeRestrictions for SSG Full Username Radius Attribute Example 4-1 Radius Freeware Format ExampleAccount Login and Logout Radius Accounting RecordsExample 4-3 Radius Accounting-Start Record Example 4-4 Radius Accounting-Stop RecordService Connection and Termination Authentication and Accounting Radius Accounting Records PTA-Multidomain Service Selection MethodsPPP Terminated Aggregation Web Service Selection Restrictions for PTA-MDSesm and SSG Performance OL-4387-02 Service Connection SSG AutoDomainRestrictions for SSG AutoDomain Configuration of SSG AutoDomainConfiguration Example for SSG AutoDomain Example 6-3 AutoDomain Exclude File Format Example 6-1 SSG AutoDomainExample 6-2 AutoDomain Exclude Profile SSG VSA Format Restrictions for SSG Prepaid Configuration of SSG PrepaidSSG Prepaid Configuration Example for SSG Prepaid SSG Open GardenConfiguration of SSG Open Garden Configuration Example for SSG Open GardenSSG Port-Bundle Host Key Restrictions for SSG Open GardenRestrictions for SSG Port-Bundle Host Key Mutually Exclusive Service Selection Configuration of SSG Port-Bundle Host KeyExclude Networks Prerequisites for SSG Port-Bundle Host KeyConfiguration of Mutually Exclusive Service Selection OL-4387-02 Service Profiles Downstream Access Control ListUpstream Access Control List Service Authentication TypeDomain Name Full UsernameService-Defined Cookie Service DescriptionService Mode Service Next-Hop GatewayCached Service Profiles Type of ServiceService Profile Example Example 7-1 Service ProfileConfiguration of Cached Service Profiles OL-4387-02 SSG Hierarchical Policing Token Bucket Scheme SSG Hierarchical PolicingSSG Hierarchical Policing Overview SSG Hierarchical Policing Configuration Restrictions for SSG Hierarchical PolicingConfiguration Examples for SSG Hierarchical Policing Example 8-2 Enabling Per-Session Policing on a RouterOL-4387-02 Interface Configuration Transparent PassthroughAccess Side Interfaces For exampleConfiguration of Transparent Passthrough Multicast Protocols on SSG InterfacesNetwork Side Interfaces Restrictions of Transparent PassthroughConfiguration of Multicast Protocols on SSG Interfaces 10-1 Redirection for Unauthenticated UsersSSG TCP Redirect Redirection for Unauthorized Services 10-2Initial Captivation 10-3Configuration of SSG TCP Redirect Restrictions for SSG TCP RedirectPrerequisites for SSG TCP Redirect 10-4Example 10-2 Limiting Redirected TCP Sessions 10-5Example 10-1 Binding a Server Group to a Port Configuring SSG TCP Redirect 10-6Configuration Examples for SSG TCP Redirect 10-7Example 10-3 Defining a Captive Portal Server Group Example 10-4 Defining Network Lists10-8 Example 10-5 Defining Port Lists11-1 Miscellaneous SSG FeaturesVPI/VCI Static Binding to a Service Profile AAA Server Group Support for Proxy Services Configuration of Radius Virtual Circuit LoggingRadius Virtual Circuit Logging 11-2Packet Filtering 11-3Downstream Access Control List-outacl Upstream Access Control List-inaclRestrictions for Packet Filtering 11-4SSG Unconfig Configuration of Packet FilteringConfiguration Example for Packet Filtering Restrictions for SSG UnconfigPrerequisites for SSG Unconfig Configuration of SSG UnconfigConfiguration Examples for SSG Unconfig 11-611-7 SSG Enhancements for Overlapping ServicesService Translation 11-8 Restrictions for Service Translation 11-9Configuration of Service Translation 11-10Expansion of Service IDs 11-11Network Sets 11-12Monitoring and Maintaining SSG 12-1Troubleshooting Radius Per-Service StatisticsRestrictions for Per-Service Statistics 12-2Monitoring the Parallel Express Forwarding Engine 12-312-4 SSG Configuration Example Figure A-1 SSG Example TopologyExample A-1 Cisco 10000 Router SSG Configuration Username cisco password 0 cisco clock timezone PSTSsg accounting interval 300 ssg profile-cache Full-duplex Peer default ip address pool SSG-POOL Exec-timeout 0 0 password lab SSG Feature Implementation Notes SSG Implementation NotesMpls Also see the Restrictions for SSG TCP Redirect section on OL-4387-02 O S S a R Y GL-1GL-2 GL-3 GL-4 GL-5 GL-6 D E IN-1DSL G-1 IN-2ISP G-2 L2TP IN-3Radius IN-4Reauthorizing prepaid IN-5TCP IN-6VRF G-5 VSA IN-7IN-8