Cisco Systems OL-4387-02 manual Configuration of Cached Service Profiles

Models: OL-4387-02

1 110
Download 110 pages 54.42 Kb
Page 53
Image 53
Configuration of Cached Service Profiles

Chapter 7 Service Profiles and Cached Service Profiles

Cached Service Profiles

If the service profile exists and it is active, SSG uses the service profile to process the logon request.

If the service profile exists, but it is inactive (for example, SSG is currently downloading the profile), SSG queues the logon request and processes the request after the service profile is downloaded.

If SSG does not find Service-Info attributes in the service profile, SSG creates an inactive service profile and processes any logon requests after downloading the service profile.

After the service profile is downloaded, the inactive service profile is updated with the Service-Info attributes from RADIUS. SSG uses these attributes to process connections for incoming users and any pending connection requests.

The RADIUS packet has an MD5 signature that uniquely identifies the service profile. SSG stores this service profile ID in the service profile.

If the profile changes on the RADIUS server, the SSG timer process periodically updates the cached profile to ensure that the service information is current.

If the service profile fails to update, SSG retains the cached service profile. When a new user connects to the SSG, SSG downloads the service profile again. If SSG cannot download the service profile, the user is not allowed to log on to the service.

Configuration of Cached Service Profiles

To enable cached service profiles, use the ssg service-cache enable command in global configuration mode. Cached service profiles are enabled by default.

To set the refresh-interval time, which sets the length of time after which all the existing service profiles are downloaded, use the ssg service-cacherefresh-intervalcommand in global configuration mode. The refresh time is two hours by default.

To refresh the service profile, even when the timer has not yet expired, use the ssg service-cache refresh command in privileged EXEC mode. You can use this command to refresh a specific service name or to refresh all services. If the service with that service name is not in use when you enter the ssg service-cachecommand, the command does not attempt to download the service profile.

Cisco 10000 Series Router Service Selection Gateway Configuration Guide

 

OL-4387-02

7-5

 

 

 

Page 53
Image 53
Cisco Systems OL-4387-02 manual Configuration of Cached Service Profiles