Cisco Systems OL-4387-02 manual Service Connection, SSG AutoDomain, C H A P T E R

Models: OL-4387-02

1 110
Download 110 pages 54.42 Kb
Page 39
Image 39
Service Connection

C H A P T E R 6

Service Connection

The Cisco 10000 series router supports the following SSG features for service connection:

SSG AutoDomain, page 6-1

SSG Prepaid, page 6-4

SSG Open Garden, page 6-5

SSG Port-Bundle Host Key, page 6-6

Exclude Networks, page 6-8

Mutually Exclusive Service Selection, page 6-8

This chapter describes the SSG features for service connection.

SSG AutoDomain

The SSG AutoDomain feature allows users to automatically connect to a service based on the domain part of the structured username specified in an Access-Request. When SSG AutoDomain is configured, user authentication is performed at the service (for example, at the AAA server within a corporate network), instead of at the network access server (NAS).

The domain portion of the structured username is the portion after the @ in the username. For example, the domain in the username “abc@cisco.com” is “cisco.com”. Users can bypass the Service Selection Dashboard (SSD) and access a service, such as a corporate intranet. SSG AutoDomain on the

Cisco 10000 router supports login operations from the Subscriber Edge Services Manager (SESM) application.

AutoDomain uses a heuristic to determine the service into which the user is logged. The host object is not activated until successfully authenticated with the service. If the autoservice connection fails for any reason, the user login is rejected.

The AutoDomain service first checks for a structured username. If AutoDomain is enabled and the received Access-Request specifies a structured username, the username is used for AutoDomain selection. If the Access-Request does not specify a username or the specified username is a member of the domain name exclusion list, then no AutoDomain is selected and normal SSG user login proceeds. You can define the domain name exclusion list by using the exclude command in SSG-auto-domain configuration mode.

When you enable AutoDomain, an AutoDomain profile is downloaded from the local AAA server. This profile specifies an outbound service and the password is the globally configured service password.

Cisco 10000 Series Router Service Selection Gateway Configuration Guide

 

OL-4387-02

6-1

 

 

 

Page 39
Image 39
Cisco Systems OL-4387-02 manual Service Connection, SSG AutoDomain, page SSG Prepaid, page SSG Open Garden, page