Cisco Systems OL-4387-02 manual 11-8

Page 78

Chapter 11 Miscellaneous SSG Features

SSG Enhancements for Overlapping Services

Because network sets for services must be unique, the following network sets are defined internally:

Set1

0.0.0.0/0.0.0.0

Set2

10.58.253.0/255.255.255.0

Set3

10.58.254.0/255.255.255.0

Set4

10.58.102.6/255.255.255.255

The service translation mechanism then internally converts the services to the following sets:

Service Default_256

Set1

Service Bronze_256

Set2 and set3

Service Silver_512

Set2, set3, and set4

Service Gold_2048

Set2, set3, and set4

Service Platinum_1024

Set2

Policing of user traffic is based on the service to which the user is assigned. For example, using the services and sets defined above, if user A is subscribed to Default_256 at 256 Kbps, user A traffic is policed at 256 Kbps for all services. If user B is subscribed to Default_256 at 256 Kbps and Platinum_1024 at 1024 Kbps, user B traffic to the service 10.58.253.0/255.255.255.0 is policed at 1024 Kbps, but all other user B traffic is policed at 256 Kbps.

In the previous example, each set contains a single prefix. However, network sets can also contain multiple prefixes. For example, consider the following service definitions:

ssg bind service Bronze_256 <next hop ssg> 10.58.253.0/255.255.255.0 10.58.254.0/255.255.255.0

ssg bind service Default_256 <next hop ssg> 10.58.253.0/255.255.255.0 10.58.254.0/255.255.255.0 10.58.102.6/255.255.255.255 10.58.102.7/255.255.255.255

Based on the service definitions, the service translation mechanism internally defines the following network sets:

Set1

10.58.253.0/255.255.255.0

10.58.254.0/255.255.255.0

Set2

10.58.102.6/255.255.255.255

10.58.102.7/255.255.255.255

Cisco 10000 Series Router Service Selection Gateway Configuration Guide

11-8

OL-4387-02

 

 

Image 78
Contents Corporate Headquarters Copyright 2004, Cisco Systems, Inc All rights reserved N T E N T S IiiConfiguration Example for SSG AutoDomain Configuration Example for SSG Open Garden Configuration of VPI/VCI Static Binding to a Service Profile SSG Unconfig ViiViii About This Guide AudienceDocument Organization Document Conventions Related Documentation Obtaining DocumentationCisco.com Documentation CD-ROM Documentation FeedbackObtaining Technical Assistance Ordering DocumentationTAC Case Priority Definitions Cisco TAC WebsiteOpening a TAC Case XiiiObtaining Additional Publications and Information XivService Selection Gateway Overview Service Selection GatewaySSG Topology Example Default Network Access ProtocolsSupported SSG Features SSG RestrictionsService Selection Gateway Overview SSG Restrictions SSG Prerequisites SSG Architecture ModelService Selection Gateway Overview SSG Architecture Model OL-4387-02 Scalability and Performance Limitations and RestrictionsScalability and Performance Limitations and Restrictions SSG Logon and Logoff Single Host LogonPrerequisites for Single Host Logon Configuration of SSG Autologoff SSG AutologoffRestrictions for SSG Autologoff Example 3-1 SSG Autologoff Using ARP Ping SSG Prepaid Idle TimeoutConfiguration Example for SSG Autologoff Example 3-2 SSG Autologoff Using Icmp PingService Authorization Service ReauthorizationConfiguration of SSG Prepaid Idle Timeout Restrictions for SSG Prepaid Idle TimeoutPrerequisites for SSG Prepaid Idle Timeout Configuration Example for SSG Prepaid Idle TimeoutExample 3-7 SSG Threshold Volume SSG Session and Idle TimeoutExample 3-5 SSG Service-Specific TCP Redirect Example 3-6 SSG Threshold TimeRestrictions for SSG Full Username Radius Attribute Authentication and AccountingSSG Full Username Radius Attribute Example 4-1 Radius Freeware Format ExampleExample 4-3 Radius Accounting-Start Record Account Login and LogoutRadius Accounting Records Example 4-4 Radius Accounting-Stop RecordService Connection and Termination Authentication and Accounting Radius Accounting Records Service Selection Methods PPP Terminated AggregationPTA-Multidomain Web Service Selection Restrictions for PTA-MDSesm and SSG Performance OL-4387-02 Service Connection SSG AutoDomainConfiguration of SSG AutoDomain Configuration Example for SSG AutoDomainRestrictions for SSG AutoDomain Example 6-1 SSG AutoDomain Example 6-2 AutoDomain Exclude Profile SSG VSA FormatExample 6-3 AutoDomain Exclude File Format Configuration of SSG Prepaid SSG PrepaidRestrictions for SSG Prepaid Configuration Example for SSG Prepaid SSG Open GardenSSG Port-Bundle Host Key Configuration of SSG Open GardenConfiguration Example for SSG Open Garden Restrictions for SSG Open GardenRestrictions for SSG Port-Bundle Host Key Exclude Networks Mutually Exclusive Service SelectionConfiguration of SSG Port-Bundle Host Key Prerequisites for SSG Port-Bundle Host KeyConfiguration of Mutually Exclusive Service Selection OL-4387-02 Service Profiles Downstream Access Control ListDomain Name Upstream Access Control ListService Authentication Type Full UsernameService Mode Service-Defined CookieService Description Service Next-Hop GatewayService Profile Example Cached Service ProfilesType of Service Example 7-1 Service ProfileConfiguration of Cached Service Profiles OL-4387-02 SSG Hierarchical Policing SSG Hierarchical Policing OverviewSSG Hierarchical Policing Token Bucket Scheme SSG Hierarchical Policing Configuration Restrictions for SSG Hierarchical PolicingConfiguration Examples for SSG Hierarchical Policing Example 8-2 Enabling Per-Session Policing on a RouterOL-4387-02 Interface Configuration Transparent PassthroughAccess Side Interfaces For exampleNetwork Side Interfaces Configuration of Transparent PassthroughMulticast Protocols on SSG Interfaces Restrictions of Transparent PassthroughConfiguration of Multicast Protocols on SSG Interfaces Redirection for Unauthenticated Users SSG TCP Redirect10-1 Redirection for Unauthorized Services 10-2Initial Captivation 10-3Prerequisites for SSG TCP Redirect Configuration of SSG TCP RedirectRestrictions for SSG TCP Redirect 10-410-5 Example 10-1 Binding a Server Group to a PortExample 10-2 Limiting Redirected TCP Sessions Configuring SSG TCP Redirect 10-6Example 10-3 Defining a Captive Portal Server Group Configuration Examples for SSG TCP Redirect10-7 Example 10-4 Defining Network Lists10-8 Example 10-5 Defining Port ListsMiscellaneous SSG Features VPI/VCI Static Binding to a Service Profile11-1 Radius Virtual Circuit Logging AAA Server Group Support for Proxy ServicesConfiguration of Radius Virtual Circuit Logging 11-2Packet Filtering 11-3Restrictions for Packet Filtering Downstream Access Control List-outaclUpstream Access Control List-inacl 11-4Configuration Example for Packet Filtering SSG UnconfigConfiguration of Packet Filtering Restrictions for SSG UnconfigConfiguration Examples for SSG Unconfig Prerequisites for SSG UnconfigConfiguration of SSG Unconfig 11-6SSG Enhancements for Overlapping Services Service Translation11-7 11-8 Restrictions for Service Translation 11-9Configuration of Service Translation 11-10Expansion of Service IDs 11-11Network Sets 11-12Monitoring and Maintaining SSG 12-1Restrictions for Per-Service Statistics Troubleshooting RadiusPer-Service Statistics 12-2Monitoring the Parallel Express Forwarding Engine 12-312-4 SSG Configuration Example Figure A-1 SSG Example TopologyExample A-1 Cisco 10000 Router SSG Configuration Username cisco password 0 cisco clock timezone PSTSsg accounting interval 300 ssg profile-cache Full-duplex Peer default ip address pool SSG-POOL Exec-timeout 0 0 password lab SSG Feature Implementation Notes SSG Implementation NotesMpls Also see the Restrictions for SSG TCP Redirect section on OL-4387-02 O S S a R Y GL-1GL-2 GL-3 GL-4 GL-5 GL-6 D E IN-1DSL G-1 IN-2ISP G-2 L2TP IN-3Radius IN-4Reauthorizing prepaid IN-5TCP IN-6VRF G-5 VSA IN-7IN-8