Chapter 16 Configuring Security for the ML-Series Card

RADIUS Stand Alone Mode

Configuring a nas-ip-address in the RADIUS Packet

The ML-Series card in RADIUS relay mode allows the user to configure a separate nas-ip-address for each ML-Series card. In RADIUS standalone mode, this command is hidden in the Cisco IOS CLI. This allows the RADIUS server to distinguish among individual ML-Series card in the same ONS node.

Identifying the specific ML-Series card that sent the request to the server can be useful in debugging from the server. The nas-ip-address is primarily used for validation of the RADIUS authorization and accounting requests.

If this value is not configured, the nas-ip-address is filled in by the normal Cisco IOS mechanism using the value configured by the ip radius-sourcecommand. If no value is specified then the best IP address routable to the server is used. If no routable address is available, the IP address of the server is used.

Beginning in privileged EXEC mode, follow these steps to configure the nas-ip-address:

 

Command

Purpose

Step 1

 

 

Router# configure terminal

Enter global configuration mode.

Step 2

 

 

Router (config)# [no] ip radius

Specify the IP address or hostname of the attribute 4 (nas-ip-address) in the

 

nas-ip-address {hostname

radius packet.

 

ip-address}

If there is only one ML-Series card in the ONS node, this command does

 

 

 

 

not provide any advantage. The public IP address of the ONS node serves

 

 

as the nas-ip-address in the RADIUS packet sent to the server.

Step 3

 

 

Router (config)# end

Return to privileged EXEC mode.

Step 4

 

 

Router# show running-config

Verify your settings.

Step 5

 

 

Router# copy running-config

(Optional) Save your entries in the configuration file.

 

startup-config

 

 

 

 

Configuring Settings for All RADIUS Servers

Beginning in privileged EXEC mode, follow these steps to configure global communication settings between the ML-Series card and all RADIUS servers:

 

Command

Purpose

Step 1

 

 

Router# configure terminal

Enter global configuration mode.

Step 2

 

 

Router (config)# radius-server key

Specify the shared secret text string used between the ML-Series card and

 

string

all RADIUS servers.

 

 

Note The key is a text string that must match the encryption key used on

 

 

the RADIUS server. Leading spaces are ignored, but spaces within

 

 

and at the end of the key are used. If you use spaces in your key, do

 

 

not enclose the key in quotation marks unless the quotation marks

 

 

are part of the key.

Step 3

 

 

Router (config)# radius-server

Specify the number of times the ML-Series card sends each RADIUS

 

retransmit retries

request to the server before giving up. The default is 3; the range 1 to 1000.

Step 4

 

 

Router (config)# radius-server

Specify the number of seconds a ML-Series card waits for a reply to a

 

timeout seconds

RADIUS request before resending the request. The default is 5 seconds; the

 

 

range is 1 to 1000.

 

 

 

Cisco ONS 15310-CL, ONS 15310-MA, and ONS 15310-MA SDH Ethernet Card Software Feature and Configuration Guide, R9.1 and R9.2

 

78-19415-01

16-17

 

 

 

Page 215
Image 215
Cisco Systems Cisco ONS 15310-MA, ONS 15310-CL manual Configuring a nas-ip-address in the Radius Packet, 16-17

ONS 15310-CL, ONS 15310-MA, Cisco ONS 15310-MA specifications

Cisco Systems has long been a leader in networking and telecommunications technology, and among its impressive lineup of products, the Cisco ONS 15310 series stands out as an essential solution for optical networking. This series includes models such as the ONS 15310-MA, ONS 15310-CL, and ONS 15310-CA, each designed to meet the diverse needs of service providers and enterprises seeking to enhance their optical transport networks.

The Cisco ONS 15310-MA is an advanced multi-service platform designed for metropolitan area networks. It facilitates the seamless transport of data, voice, and video over optical networks. One of its main features is its ability to support a variety of interfaces, including Ethernet, SONET/SDH, and Wavelength Division Multiplexing (WDM), allowing users to integrate multiple services into a single platform. Additionally, the ONS 15310-MA supports advanced traffic management and Quality of Service (QoS) features to prioritize critical applications and ensure consistent performance.

The ONS 15310-CL variant is tailored for more specific applications, providing enhanced capabilities aimed at delivering carrier-grade services. It features a robust architecture that accommodates high-capacity traffic without compromising reliability. This model emphasizes low power consumption and a compact design, making it suitable for deployment in space-constrained environments. The ONS 15310-CL also supports a wide range of optical interfaces, making it highly flexible for various network configurations.

In terms of technologies, the Cisco ONS 15310 series leverages Optical Transport Network (OTN) capabilities, providing high efficiency and greater bandwidth utilization. OTN technology enables efficient error correction and adds resilience to the network through its built-in protection mechanisms. Furthermore, the series supports seamless integration with existing IP/MPLS networks, creating a cohesive infrastructure as organizations evolve their networking requirements.

One of the defining characteristics of the ONS 15310 series is its focus on scalability. Network operators can start with a modest deployment and gradually expand capacity as demand grows. This adaptability is complemented by Cisco's comprehensive management and monitoring tools, providing operators with real-time insights into network performance and facilitating proactive management.

In conclusion, the Cisco ONS 15310-MA and ONS 15310-CL models represent sophisticated solutions for modern optical networks. With their versatile features, advanced technologies, and robust design, they empower service providers and enterprises to build resilient, high-capacity networks that meet the demands of today’s data-driven world.