Bridgewater Service Controller Guide 9.6.1
Bridgewater Service Controller Guide 9.6.1
Bridgewater, Bridgewater Systems, Widespan and the Bridgewater Systems Logo are the trademarks of Bridgewater Systems
Corporation. Other company or product names referenced may be the trademark or registered trademark of their respective
companies. ©1997-2012 Bridgewater Systems Corporation. All rights reserved.
About this guide
This guide contains instructions for the configuration of the Bridgewater Systems
Service Controller, including information about the RADIUS Service Controller, and
the Diameter Service Controller.
Audience
The intended audience for this document is:
• system administrators
• database managers
• network operators
• application developers
Installation
For AAA RPM and package installation procedures, see the Bridgewater
Installation Reference Guide.
For SDB RPM and package installation procedures, see the HSS: Installation and
Configuration Guide.
For Policy Controller RPM and package installation procedures, see the Policy
Controller: Installation and Configuration Guide.
Text conventions
Document history
Related documents
The Release 9.6-AAA documentation consists of the following guides:
• 3G/WLAN Interworking Guide
Describes 3G/WLAN interworking environments. Covers the deployment
options and configuration procedures for 3G/WLAN interworking in a
Bridgewater deployment.
• Accounting Framework Guide
Describes how to configure, operate, and maintain the Accounting Framework,
and how to use the accounting records, and the usage and revenue reports.
• Bridgewater Installation Reference Guide
Describes the deployment options, installation procedures, installation
packages, engineering requirements, and security considerations for
Bridgewater Systems products.
• Bridgewater Master Glossary
Describes the terms and acronyms used in Bridgewater Systems software and
documentation.
• Bridgewater SNMP Guide
Describes how to configure SNMP support for the Bridgewater Systems
software components, and provides reference information about Bridgewater
MIBs. It also describes how to use Key Performance Indicator (KPI) scripts to
obtain SNMP metrics for reporting performance and capacity data. KPI scripts
gather time-based loading level statistics from Bridgewater components.
• CALEA Controller with SS8 Guide
Describes how to install, configure, and operate the CALEA (Communications
Assistance for Law Enforcement Agencies) Controller.
HSS documents
The HSS documentation consists of the following guides:
• HSS: API Guide
Describes the Provisioning Server XML interface, operations, client application
design criteria, and the command line utilities for provisioning operations.
• HSS: Deployment Planning Guide
Describes how to plan an HSS deployment. Provides information about
servers, the software environment, and troubleshooting logs.
• HSS: Getting Started Guide
Describes the 3GPP (3rd Generation Partnership Project) network specification
for Long Term Evolution (LTE). Also describes the HSS and related products
such as the 3GPP-AAA.
• HSS: Installation and Configuration Guide
Describes the deployment options, installation procedures, and installation
packages for the HSS and related products such as the 3GPP-AAA.
• HSS: IPv6 Implementation Guide
Describes the IPv6 protocol. Also describes how to configure IPv6 for Solaris
and the HSS.
• HSS: Operations and Maintenance Guide
Describes procedures for operating and maintaining an HSS deployment, such
as how to configure HSS policy rules or use HSS test tools.
• HSS: Provisioning Guide
Describes how to provision HSS components in the Profile database using the
Service Manager.
To provision subscribers . . . . . . . . . . . . . . . . . . . . . . . . . . . 46
To provision PDSNs/HAs with dynamic HA allocation . . . . 46
To provision PDSN/HA groups . . . . . . . . . . . . . . . . . . . . . . 47
Saving session data to a flat file . . . . . . . . . . . . . . . . . . . . . . . . 47
Prepaid Data SNMP support . . . . . . . . . . . . . . . . . . . . . . . . . . . 49
Configuring Quick-Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49
To create a dictionary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50
To configure Quick-Access . . . . . . . . . . . . . . . . . . . . . . . . . 50
To add PP-Quick-Access to an existing Connection Service 51
Configuring Multiple NAI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52
To configure the RADIUS Server . . . . . . . . . . . . . . . . . . . . 53
To configure the RADIUS Server to enable SNMP . . . . . . . 53
To provision a connection service profile . . . . . . . . . . . . . . 53
To provision User profile sets . . . . . . . . . . . . . . . . . . . . . . . 54
To provision subscribers for multiple NAI services . . . . . . . 54
Multiple NAI SNMP support . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55
Configuring dynamic LNS assignment. . . . . . . . . . . . . . . . . . . . . . . . . . . 55
To enable dynamic LNS assignment . . . . . . . . . . . . . . . . . . 57
To create LNS groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57
Configuring realm routing support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58
Configuring subscriber QoS profiles for EV-DO Rev A service . . . . . . . . 58
To trigger the retrieval of QoS parameters . . . . . . . . . . . . . 59
To create a dictionary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59
To configure the accessReqPolicy file . . . . . . . . . . . . . . . . 59
Access options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60
QoS attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60
Accounting attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62
grantedQoS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62
Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 63
Configuring QoS Profiles using the Service Manager . . . . . . . . . . . . . . . 63
To create a RADIUS QoS Selection Policy Profile . . . . . . . 63
To create a RADIUS QoS Profile . . . . . . . . . . . . . . . . . . . . 63
To create a User Profile Set with QoS Profile . . . . . . . . . . . 64
To define the QoS attributes . . . . . . . . . . . . . . . . . . . . . . . . 65
Configuring user notification messages for internationalization. . . . . . . . 66
Configuring EAP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Configuring SIP Server Interworking . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67
Configuring service selection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67
Configuring GMT offset for proxy. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68
Configuring attribute generation in [Link] . . . . . . . . . . . . . . . . . 69
rejectPolicy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 293
Condition expression . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 293
Action expression . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 295
To enable the rejectPolicy . . . . . . . . . . . . . . . . . . . . . . . . . 295
Supported EAP methods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 296
Configuring PreAuthorize using Access Control Limits (ACL) for proxy 297
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297
acService modifier . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297
service modifier . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 298
RMS sessions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 298
Examples of PreAuthorize and Proxy actions using ACLs . . . 298
rejectPolicy and outageRejectMessage modifiers . . . . . . . . . . 300
Optimizing the policy file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 300
Preventing messages from being discarded . . . . . . . . . . . . . . 300
Testing policy rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 301
Radpet in a proxy deployment . . . . . . . . . . . . . . . . . . . . . . . . . 302
Example policy configurations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 303
Device reboot notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 303
Call check . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 304
Proxy by domain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 304
Proxy by called number . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 305
Service authorization for proxy . . . . . . . . . . . . . . . . . . . . . . . . 305
Default proxy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 306
Compulsory service by called number . . . . . . . . . . . . . . . . . . . 306
Policies based on day and time . . . . . . . . . . . . . . . . . . . . . . . . 306
Group domains for roaming subscribers . . . . . . . . . . . . . . . . . 307
Discarding service requests . . . . . . . . . . . . . . . . . . . . . . . . . . . 307
Default domains . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 307
Using regular expressions . . . . . . . . . . . . . . . . . . . . . . . . . . . . 308
Reference another policy file for roaming subscribers . . . . . . . 308
Policy for replacing loginName with the Calling-Station-Id . . . 309
AssignVar: policy file interaction . . . . . . . . . . . . . . . . . . . . . . . 309
EAP local authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 310
EAP proxy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 312
Microsoft CHAP (MSCHAP) . . . . . . . . . . . . . . . . . . . . . . . . . . . 313
Microsoft Point-To-Point Encryption (MPPE) . . . . . . . . . . . . . . 314
Compare User-Name to Called-Number . . . . . . . . . . . . . . . . . 315
PreAccounting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315
Preauthorization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315
HLR authorization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 316
1
Chapter 1
Chapter
access features
This chapter describes RADIUS Server start-up features an access features and
how to configure them.
The topics are:
• RADIUS Server startup options
• Configuring access features with [Link]
• Preventing network congestion for RADIUS
• RADIUS subscriber data access
For a list of RADIUS Server messages, see “RADIUS Server system logs” in the
Service Controller: Log Messages Guide.
Usage Description
Option Description
-c path The location and filename of the database configuration file. The default is /opt/aaasc/config/[Link].
To startup RADIUS to use an LDAP database, first create and populate an internal memory map file for
RADIUS to access. Next, use the -c option with the location of the memory map file. For example, -c /opt/
aaasc/dal/config/cached_file.mmp.
-d dir The directory in which the RADIUS configuration files are located. The default is <ConfDir>/radius/
[Link].
-F file Enables super administrators to change the limit of file descriptors. If the value of the file descriptor needs
descriptors to be greater than 1024, see the Bridgewater Installation Reference Guide for details about calculating a
value.
-l facility:level Enables logging of RADIUS Server debug messages. Only use this option after consulting Bridgewater
Customer Support. For standard debugging purposes, Bridegwater Systems recommends using the -L
option to log operational messages or use the RADIUS Trace Tool.
The default facility is local6:0.
The options for level are integers between 0 and 15. The default level is 0, which disables logging. 15
records the most detail and 1 records the least detail.
To enable this option, edit [Link] and send a -HUP signal to syslogd for the changes to take effect.
-m opt-value The Mobile IP address where the opt-value is either s or l. Option s is the default ‘S’ key lifetime (in
seconds) for the Home Agent, and option l is the default dynamic ‘S’ key length (in bytes) for the Home
Agent.
Option Description
-P Enables the LDAP attribute that is used to store the password for device authentications by a
WiMAXLocalAA action. An example value for the device password is: abcMobileChapPassword.
This option must be used together with options -f and -n.
-r number The maximum rate of traffic from all clients (in transactions/sec) that the RADIUS Server can support. The
value must be in the range 1–10000. The default is 1500.
• The RADIUS Server’s ingress message queue is initialized to twice the value specified by the -r option.
For more information about RADIUS congestion control, see "Preventing network congestion for
RADIUS" on page 26.
• If the RADIUS log files contain “Failed to allocate RadiusAAAInfo” error messages, consider increasing
the peak transaction rate.
-s port The secondary port for RADIUS communication with NASs for authentication. There is no default value for
the secondary port. The default secondary port for accounting is the next highest port number.
-w num The database alert thread wait-time in seconds. The default is 600 seconds.
[Link] schema
The [Link] schema contains these elements:
RADIUS Configuration: the root element
PrepaidService
UserLockout
RealmMetrics
DefaultRealm
Realm
LocalDomains
BRMPTCPConnectionOptions
RMSClientConfig
Accounting
WLAN
DAE
DuplicateDetection
CongestionControl
StateOrange
StateRed
WiMAXDualSiteRMS
RemoteRMSCluster
DefaultAccessControlService String The default access control service profile assigned to the
Default = “Access subscriber during an Access-Request if there is more than one
Control” access control service profile in the subscriber’s profile set and
no access control service profile is specified on the policy line.
Note This setting is ignored in the case of PreAuthorize where
the access control service must be explicitly configured
in the policy file in order to be evaluated.
Optional.
DNSThreads Integer The number of threads that are created and dedicated to DNS
Default = 0 update handling if the subscriber IP Reachability Service is
used. By default, no threads are created and this feature is
disabled. To enable it, set DNSThreads to a number greater
than 0, and set the “enableIPReach” policy action in access
ReqPolicy.
This parameter is not reloaded on HUP.
For more information about policy actions, see Chapter 7,
"Configuring AAA policies".
Optional.
MaximumLoadedClients Integer (1-32000) The maximum number of RADIUS clients stored in memory.
Default = 5000 The number includes all types of RADIUS clients, such as
PDSN, NAS, GGSN, WiMAX clients and proxies.
Note A typical system initializes approximately 2500 NAS
clients per minute on startup or HUP. If thousands of
clients are configured, the startup or restart time
sequence length is extended proportionally.
ValidateClientIP • Y (default) Checks if the client is a valid RADIUS client. If the client is
• N unknown and the option is disabled, RADIUS will use a
representative client to process the request. The
representative client must be modeled in the system with an IP
of [Link]. For more information about configuring a
representative client, see Service Manager: Getting Started
Guide for AAA.
WiMAXReAuthenticationInterval Integer (300–302400) The time, in seconds, that WiMAX Mobility Keys stay valid
Default = 1800 before reauthentication is required.
Bridgewater Systems recommends setting the value to half or
less of the shortest HA RK Lifetime that is provisioned against
any WiMAX Home Agent Role in the system.
This option returns the Session-Timeout value set to the lower
of:
• this configuration value
• the Session-Timeout attribute provisioned against the
subscriber
Note For information about configuring the reauthentication
interval for Diameter, see "Configuring Diameter
reauthentication" on page 166.
Optional.
WiMAXReAuthenticationInterval Integer (0–302400) The boundaries of a range, from which the RADIUS server
Delta Default = 0 randomly generates a value, in seconds, to add to or subtract
from the Session-Timeout value.
• For example, if
WiMAXReAuthenticationIntervalDelta="100", the range from
which RADIUS randomly generates values is -100 to 100
seconds.
The value of WiMAXReAuthenticationIntervalDelta must be
less than half the WiMAXReAuthenticationInterval value.
• For example, if WiMAXReAuthenticationInterval="900" then
WiMAXReAuthenticationIntervalDelta must be 449 or lower.
Note Bridgewater Systems recommends that
WiMAXReAuthenticationIntervalDelta be significantly
less than half the WiMAXReAuthenticationIntervalDelta.
In the example above, a guideline would be to set
WiMAXReAuthenticationIntervalDelta to 100.
This attribute works with both the CDMA2000LocalAA and
WiMAXLocalAA policy actions.
Optional.
LogNASIP • y|Y When set to y|Y the RADIUS Server adds the NAS-IP-Address
• n|N (Default=n|N) attribute to RADIUS Server operational log messages
(RADOP).
When set to y|Y the RADIUS Server adds the NAS-IP-Address
in the following format:
NAS-IP:x.x.x.x
Note Also use the RADIUS [Link] file to configure
attributes to include in RADOP log messages. For more
information, see the chapter “Configuring the Logging
Framework” in the Service Controller: Monitoring and
Logging Guide.
LengthBasedCSIDDecode • Y|y When set to Y RADIUS assumes the content of the CSID
• N|n (Default=N) attribute is a MAC address.
Also when set to Y RADIUS evaluates the CSID based on the
its length, and uses the CSID length to determine its encoding
type.
Note If LengthBasedCSIDDecode is configured in
[Link] and CSIDDecodeMethod is configured
in [Link] on the same server, the action specified
in [Link] overrides the action specified by
[Link].
EAPSessionCacheEnabled • Y|y When set to Y, RADIUS caches user data required for policy
• N|n (Default=N) actions, such as Pre-Authorize, triggered during an EAP
exchange. This data is saved to the EAP-state cache
and persists for the duration of the EAP exchange.
For more information about enabling and using DAL query
caching, see "Configuring database (DAL query) caching for
multi-leg EAP" on page 74.
Note: This is a custom feature that requires the BWScdal
package. For more information, contact Bridgewater Systems.
PrepaidService Configures prepaid data services parameters. This element is required if Prepaid
service is enabled.
Child element of RADIUS Configuration.
For more information, see "Configuring user and network lockout" on page 38.
For example:
<PrepaidService
PrepaidEnabled="Y"
PrepaidTarget="PrepaidTargetGroup"
ForwardPrepaidAcct="N"
QARejectEnabled=”Y”
QAPoolID=”QuickAccessPool” />
PrepaidTarget • Y The name of the global prepaid target. The target name must exist in
• N (default) [Link].
Required if PrepaidEnabled = Y.
QAPoolID String (1–253 The name of an IP address pool that offers limited network access to
characters) direct subscribers to a replenishment portal to increase their quota.
UserLockout Enables and defines the settings for user and network lockout mechanisms.
Child element of RADIUS Configuration.
For more information, see "Configuring user and network lockout" on page 38.
For example:
<UserLockout
UserLockoutEnabled="Y"
ConsecutiveAuthFailuresAllowed="5"
ConsecutiveAuthFailureMonitorDuration="86400"
ConsecutiveAuthFailureLockoutDuration="1200" />
ConsecutiveAuthFailure Integer (15–86400) The number of seconds to monitor a subscriber account for a
MonitorDuration Default = 86400 particular authentication/authorization event (as defined by the
LockoutConfig settings in [Link]). Monitor duration restarts after
each monitored event. When the time between events exceeds this
value, or the user is locked out, monitoring stops and the event count
resets to zero (for ConsecutiveAuthFailuresAllowed).
Optional.
ConsecutiveAuthFailure Integer (1–31536000) The time, in seconds, that a subscriber account remains locked out.
LockoutDuration Default = 1200 Optional.
RealmMetrics Enables multiple NAI mechanisms. This element is required if RealmMetrics service
is enabled.
Child element of RADIUS Configuration.
For more information, see "Configuring Multiple NAI" on page 52.
The RealmMetrics element encloses:
• an optional DefaultRealm child element
• one or more Realm child element
For example:
<RealmMetrics
RealmMetricsEnabled="Y"
DefaultRealmEnabled="Y">
<DefaultRealm... />
<Realm ... />
</RealmMetrics>
RealmMetricsEnabled • Y Enable realm-based SNMP metrics. MIB tables are generated only for
• N (default) realms provisioned in this file. Optional.
DefaultRealmEnabled • Y Enable default realm metrics. This default realm aggregates metrics for
• N (default) requests that do not match any of the explicitly configured realms.
Optional.
DefaultRealmName String A unique name, containing no spaces, to capture metrics for realms not
Default = specified in this file.
”Unspecified Required if realm-based SNMP metrics are enabled.
Realms”
LocalDomains Local realm information for realm routing syntax conversion. For more information,
see "Configuring realm routing support" on page 58.
Child element of RADIUS Configuration.
The LocalDomains element encloses one or more Domain child element.
For example:
<LocalDomains>
<Domain Name="[Link]"/>
<Domain Name="[Link]"/>
</LocalDomains>
BRMPTCPConnection Minimum, maximum, and threshold values for TCP connections to the RMS. For
Options more information, see the Service Controller: Resource Management Server Guide
Child element of RADIUS Configuration.
For example:
<BRMPTCPConnectionOptions
TCPConnectionsMin="1"
TCPConnectionsMax="100"
TCPConnectionsThreshold="80"
/>
RMSClientConfig The number of threads used to handle the message queue for Asynchronous
requests. This prevents the queue from backing up during connection creation.
These parameters are not huppable.
Child element of RADIUS Configuration.
Note This element is optional. Therefore, upon a fresh installation, this element
must be copied from /opt/aaasc/radius/[Link] to the
[Link] file in /opt/aaasc/config/radius.
<RMSClientConfig
ThreadCount="20"
MaxQueueSize="16000"
/>
ThreadCount Integer (1–300) The number of worker threads in the RMS client.
Default = 20 Optional.
MaxQueueSize Integer (1–128000) The maximum RMS client request queue size.
Default = 16000 Optional.
DistributionAlgorithm String In RoundRobin distribution, RADIUS inserts records into buffers using
Default = round robin.
RoundRobin In LoginName distribution, RADIUS invokes a string hashing function
on the login name which maps the login name to a specific buffer. The
accounting record is written to the assigned buffer. A user’s accounting
records always go to the same buffer.
Name String The names of the buffers. There may be up to four additional buffers.
The names listed here must match the names of buffers configured in
the [Link] file.
CacheClusterId Integer The RMS cluster ID where WLAN sessions are cached.
When not set, the default value is the cluster ID associated with the GSM
node group.
Optional.
ProfileLife Integer (5–43200) The time, in minutes, that the cached subscriber profile remains in the
Default = 1440 RMS before it is purged.
To enforce WLAN session life, you need to configure RMS session audits,
including session life limits. For details, see the “RMS configuration”
chapter the Service Controller: Resource Management Server Guide.
Optional.
DAE Enables and defines the settings for Dynamic Authorization Extensions for CoA
request support.
Child element of RADIUS [Link] example:
<DAE
Port="3799"
DefaultDictionary="RFC2138"
EventTimestampRequired="N"
EventTimestampThreshold="300"/>For more information,see "Configuring
RADIUS mid-session hotlining" in the Service Controller: WiMAX Guide.
Port Integer (1024–65535) The UDP port on which to receive DAE requests.
Default = 3799 Optional.
DefaultDictionary String (1–20) The dictionary RADIUS uses to decode the incoming DAE requests.
Default = RFC2138 The DefaultDictionary value must match an entry in the /opt/aaasc/
config/dictionaries file.
Optional.
EventTimestampThreshold Integer (1–86400) The allowable difference between the system time and the time
Default = 300 reported in the Event-Timestamp attribute in seconds. This value is
only considered if the DAE request/response contains the
Event-Timestamp. If the Event-Timestamp value falls outside the
threshold range, the request is dropped and an error is logged.
Optional.
For example:
<DuplicateDetection
DetectionThreshold="15"
ReplayLastResponseThreshold="1"
AuditInterval="15"/>
DetectionThreshold Integer The time, in seconds, that RADIUS considers a request a duplicate.
Range=value of Note RADIUS generates an ERR log message and fails to start/HUP
(radiusd -T option + 1 if the DetectionThreshold is less than the value of (radiusd -T
second) to option + 1 second).
AuditInterval
Default=value of
(radiusd -T option + 1
second)
ReplayLastResponse Integer The number of times RADIUS can replay the same response
Threshold (0-2) message back to the client.
Default=0 When set to 0, and RADIUS receives a duplicate request, RADIUS
generates a NTCE log message and drops the request.
AuditInterval Integer The time, in seconds, which determines how often the RADIUS
(10-20) Server removes cached response messages from memory.
Default=10
CongestionControl Encloses the child elements StateOrange and StateRed, which specify settings for
how the RADIUS Server applies congestion control processing when in the orange
or red congestion state.
Child element of RADIUS Configuration.
For more information about configuring RADIUS congestion control, see the section
"Preventing network congestion for RADIUS" on page 26.
For example:
<StateOrange
AuthEAPDropProbability="50"
AuthNonEAPDropProbability="60"
AcctStartDropProbability="0"
AcctInterimDropProbability="100"
AcctStopDropProbability="0"
DAERejectProbability="50"/>
AuthEAPDropProbability Integer The probability the RADIUS server drops a new EAP authentication
(0-100) request.
Default=50 The probability is expressed as a percentage between 0 and 100.
AuthNonEAPDrop Integer The probability the RADIUS server drops a non-EAP authentication
Probability (0-100) request.
Default=60 The probability is expressed as a percentage between 0 and 100.
DAERejectProbability Integer The probability the RADIUS server rejects and sends a NAK for a
(0-100) DAE (CoA/DM) request.
Default=50 The probability is expressed as a percentage between 0 and 100.
StateRed attributes specify settings for how the RADIUS Server applies congestion
control processing when RADIUS is in the red congestion state.
Child element of CongestionControl.
For example:
<StateRed
AuthEAPBaseDropProbability="100"
AuthEAPPerLegProbabilityReduction="45"
AuthNonEAPDropProbability="60"
AcctStartDropProbability="0"
AcctInterimDropProbability="100"
AcctStopOldDropProbability="50"
AcctStopYoungDropProbability="60"
DAERejectProbability="60"/>
AuthEAPBaseDrop Integer The probability the RADIUS server drops a new EAP authentication
Probability (0-100) request.
Default=100 The probability is expressed as a percentage between 0 and 100.
AuthEAPPerLegProbability Integer The probability the RADIUS server drops an EAP authentication
Reduction (0-100) request for an in-progress session.
Default=45 The probability of dropping an EAP authentication request for an
in-progress session is determined by the following calculation:
AuthEAPBaseDropProbability - (EAP leg *
AuthEAPPerLegProbabilityReduction)
For example, if AuthEAPBaseDropProbability=100 and
AuthEAPPerLegProbabilityReduction=45:
• for an in-progress session with leg count equal to 1, there is a 55 %
chance the RADIUS Server will drop the message.
• for an in-progress session with leg count equal to 2, there is a 10 %
chance the RADIUS Server will drop the message.
• for an in-progress session with leg count greater than 2, the
RADIUS Server will process the message normally.
The probability is expressed as a percentage between 0 and 100.
AuthNonEAPDrop Integer The probability the RADIUS server drops a non-EAP authentication
Probability (0-100) request.
Default=60 The probability is expressed as a percentage between 0 and 100.
AcctStopOldDrop Integer The probability the RADIUS server drops an Accounting-Stop request
Probability (0-100) for which the Acct-Delay-Time AVP is greater than -T.
Default=50 The probability is expressed as a percentage between 0 and 100.
DAERejectProbability Integer The probability the RADIUS server rejects and sends a NAK for a
(0-100) DAE (CoA/DM) request.
Default=60 The probability is expressed as a percentage between 0 and 100.
WiMAXDualSiteRMS Encloses the attribute LocalSite and the child element RemoteRMSCluster.
Child element of RADIUS Configuration.
WiMAXDualSiteRMS and the child element RemoteRMSCluster can be used in
WiMAX networks with geo-redundant sites to specify a mapping of local RMS
clusters to partner RMS clusters on a remote site. The RADIUS Server uses the
mapping specified in the WiMAXDualSiteRMS and RemoteRMSCluster elements
and configuration in [Link] to determine which site and RMS cluster to
search for subscriber sessions in the event of a WiMAX site failover.
The presence of WiMAXDualSiteRMS in [Link] enables the 4G Service
Controller to support RMS availability during WiMAX site failover:
• If WiMAXDualSiteRMS is not present in [Link], RMS availability
during WiMAX site failover is not supported.
• If WiMAXDualSiteRMS is not present and a local network link between an
ASN-GW and the local Service Controllers goes down after initial
authentication, the local ASN-GW can failover to the remote site but the remote
Service Controller cannot access RMS sessions created on initial
authentication in the local RMS cluster.
For more information about configuring RMS availability during WiMAX site failover,
see the chapter “Configuring WiMAX” in the Service Controller: WiMAX Guide.
# Remote Clusters
100 [Link] 34501 MYSECRET [Link]
34505 SECONDSECR 5 - -
# Remote Clusters
100 [Link] 34501 MYSECRET [Link]
34505 SECONDSECR 5 - -
In this example:
• the LocalSite attribute specifies that the configuration is for the 4G Service
Controller on site A.
• ClusterId specifies the ID of the remote RMS cluster as it appears in site A’s
[Link] file.
• NativeClusterId specifies the ID of the remote RMS cluster as it appears in site
B’s [Link] file.
• LocalMateId specifies the ID of the RMS cluster on site A that is paired with the
remote RMS cluster being defined.
Note RemoteRMSCluster configuration is required on the 4G Service Controllers
on both sites in a WiMAX network with geo-redundant sites.
For more information about configuring RMS availability during WiMAX site failover,
see the chapter “Configuring WiMAX” in the Service Controller: WiMAX Guide.
ClusterId Integer The ID of the remote cluster as it appears in the local site’s
(0-254) [Link] file.
Required.
NativeClusterId Integer The ID of the remote RMS cluster as it appears in the remote site’s
(0-254) [Link] file.
For example if the local site’s [Link] specifies a remote RMS
cluster with an ID of 101, this corresponds to an RMS cluster with ID 2
in the remote site’s [Link] file. In this case, enter 2 for the
NativeClusterId.
Required.
LocalMateId Integer The ID of the RMS cluster on the local site, which is paired with the
(0-254) remote RMS cluster being defined.
Required.
[Link] example
This is an example of the /opt/aaasc/config/radius/[Link] file:
<RADIUSConfiguration>
<PrepaidService
PrepaidEnabled="Y"
PrepaidTarget="PrepaidTargetGroup"
ForwardPrepaidAcct="N" />
<UserLockout
UserLockoutEnabled="Y"
ConsecutiveAuthFailuresAllowed="5"
ConsecutiveAuthFailureMonitorDuration="86400"
ConsecutiveAuthFailureLockoutDuration="1200" />
<RealmMetrics
RealmMetricsEnabled="Y"
DefaultRealmEnabled="Y">
<DefaultRealm
DefaultRealmName="EveryoneElse"
DefaultAcctMetrics="N"/>
<Realm RealmName="xyz" AuthMetrics="N"/>
</RealmMetrics>
<RMSClientConfig
ThreadCount="20"
MaxQueueSize="16000"
/>
<Accounting>
<AccountingBuffers DistributionAlgorithm="RoundRobin">
<AccountingBuffer name="radbuff2"/>
</AccountingBuffers>
</Accounting>
<DAE
Port="3799"
DefaultDictionary="RFC2138">
EventTimestampRequired="N"
EventTimestampThreshold="300"/>
</RADIUSConfiguration>
6XEVFULEHUGHYLFHV
7&3 5$',866HUYLFH
$FFHVV1RGH 0HVVDJH
TXHXH &RQWUROOHU
The RADIUS Server uses a LIFO (last-in-first-out) message queue to receive all
ingress messages. With the congestion control mechanism, the ingress message
queue is initialized to two times the expected peak rate of traffic (-r option in
radiusd). The message queue is divided into three sub-ranges (green, orange, red)
and RADIUS looks at queue size and message age to decide the congestion state.
Based on queue size and message age RADIUS determines one of the following
congestion states:
• Green - Service Controller is in a normal operational state
• Orange - Service Controller is congested
• Red - Service Controller is critically congested
0HVVDJHTXHXH
VL]HLQLWLDOL]HGWRWZRWLPHVWKHH[SHFWHGSHDNUDWHRIWUDIILF
URSWLRQLQUDGLXVG
GLYLGHGLQWRWKUHHVXEUDQJHV
*UHHQFDSDFLW\ KDOIWKHTXHXH
2UDQJHFDSDFLW\ WKHTXDUWHURIWKHTXHXHWKDWLVDERYHWKH
JUHHQWKUHVKROG
5HGFDSDFLW\ WKHTXDUWHURIWKHTXHXHWKDWLVDERYHWKHRUDQJH
WKUHVKROG
Note RADIUS drops any messages where the message age state is older than
the retransmit timeout. If the system state is still in Red or Orange, RADIUS
then applies congestion control using a probability algorithm.
– for non EAP sessions there is a 60% chance that the RADIUS Server will
drop the message.
Configure this probability in [Link] in the StateOrange
“AuthNonEAPDropProbability” attribute
– for an Accounting-Start message the RADIUS Server does not drop the
message.
Configure this probability in [Link] in the StateOrange
“AcctStartDropProbability” attribute
– for an Accounting-Interim message the RADIUS Server drops the
message.
Configure this probability in [Link] in the StateOrange
“AcctInterimDropProbability” attribute
– for an Accounting-Stop message the RADIUS Server does not drop the
message.
Configure this probability in [Link] in the StateOrange
“AcctStopDropProbability” attribute
– for DAE messages (CoA and DM) there is a 50% chance that the RADIUS
Server will send an immediate NAK. The NAK includes Error-Cause 505
“Other Proxy Processing Error”, a fatal error sent when a request cannot be
processed by a proxy for reasons other than routing.
Configure this probability in [Link] in the StateOrange
“DAERejectProbability” attribute.
• Red: the RADIUS Server is critically congested.
For Access-Request messages:
– for a new authentication session, the RADIUS Server drops the message.
Configure this probability in [Link] in the StateRed
“AuthEAPBaseDropProbability” attribute
– by default, for an in-progress session with leg count equal to 1, there is a 55
% chance the RADIUS Server drops the message.
– by default, for an in-progress session with leg count equal to 2, there is a 10
% chance the RADIUS Server drops the message.
– by default, for an in-progress session with leg count greater than 2, the
RADIUS Server processes the message normally.
Configure the probability of dropping in-progress sessions in
[Link] in the StateRed “AuthEAPPerLegDropProbability”
attribute
For non EAP sessions:
– the RADIUS Server drops the message.
Configure this probability in [Link] in the StateRed
“AuthNonEAPDropProbability” attribute
Profile Database
The RADIUS Server connects to the Profile Database using the [Link] file,
located in /opt/aaasc/config/. This file specifies one or more databases, using the
global database name, with which the RADIUS Server connects using a username
and password. The database configuration parameters—username, password,
database—must be at the end of the file. The username and password are set
when the database is installed.
The [Link] file can list multiple databases for backup. If the primary database fails,
the RADIUS Server connects to the next database listed in the file. To configure for
failover, the parameters can be repeated for the failover database. Make sure the
correct order is maintained.
Modify this file only if the location of a database changes, relative to the RADIUS
Server, or the database username or password changes. Do not leave the
database field of the [Link] file blank.
This is an example of the [Link] file:
# Database config
username= r6
password= x123y
database= dbname01
There must be at least one line separating the accounting and database
configuration parameters.
Table 21 describes the configuration parameters.
When the next RADIUS message arrives, the same thread could possibly win the
competition and because it has a good database connection, it processes the
request. Slowly, each of the threads has its statistical chance to process RADIUS
requests. As each thread gets its first request, it also notices its stale primary
database connection is dead and fails over. Each failover shows a log message in /
var/adm/messages.
With a low transaction rate, it could be tens of minutes or a few hours before the last
of the database failover messages is observed. There are two messages per
thread: one as the thread fails over to the remote database, and one as it returns to
the local database after the time period has elapsed.
The syslogd facility can batch duplicate log messages together with a 'Last
message repeated XXX times' that is done to lessen the effect of 'log storming.'
The higher the load on the RADIUS Server, the shorter the average amount of time
it takes for all the RADIUS threads to failover.
The default RADIUS retryinterval is 300 seconds. This is a per thread timer. A
thread that has been failed over to the secondary database for more than 300
seconds tries to go back to the primary database for the next RADIUS request it
handles.
2
Chapter 2
Chapter
Configuring lockout
There are multiple ways of configuring user and network lockouts on a RADIUS
Server, and multiple files to configure. This section provides guidance through the
decision and configuration process.
Table 22 describes the behavior of the lockout feature based on the type and action
of the lockout, assuming UserLockoutEnabled=“Y” in [Link].
Table 23 lists the command line options. Use multiple options, such as
-S (statistics), -F (find), -U (unlock), -C (create), and -h (help), at the same time.
Option Description
-U Find and clear the user lockout status. Clear the lockout applied to a specified loginname to enable the
user to authenticate.
Specify the name and location of the memory mapped file using the -f option.
Unlock (-U) requires both domain (-d) and loginname to be specified.
-f <mmap_file> Location of the memory mapped file. Required for the -S, -F, -U and -C options. For example, the
mmap_file is defined as: /opt/aaasc/config/radius/[Link].
-u <login_name> Login name for a specified user. Use this option in conjunction with the -F and -U options.
-d <domain> Domain name. Use this option in conjunction with the -F and -U options.
-s Set the record count of the memory mapped file. Use this option in conjunction with the -C option. When
the file is created at installation time, a size of 10000 is used.
-l Set the limit for number of records to display. If the -l option is not specified, the ulTool displays 100
records. Increase or decrease this number with the -l option.
Example: ulTool find To find a user in a locked out state for a specific domain:
user ./ulTool -F -f /opt/aaasc/config/radius/[Link] -d
[Link]
The utility returns:
Bridgewater RADIUS UserLockout Database Utility <Version>
=========================
======= FIND USER =======
=========================
Expired user lockout entry for user1@[Link]
Current state [Exp] : failed 2 time(s)
Clear time : 2004-03-10 09:51:13
User lockout entry for user2@[Link]
Current state : locked
Clear time : 2004-03-10 09:51:19
Example: ulTool To display the statistical information for the memory mapped file:
statistics ./ulTool -S -f /opt/aaasc/config/radius/[Link]
The utility returns:
Bridgewater RADIUS UserLockout Database Utility <Version>
=========================
==== DATABASE STATS =====
=========================
Path : /opt/aaasc/config/radius/[Link]
Lock ID : 6
Version : 1
Capacity : 10000
Sequence # : 1
Attached Process : pid (28734)
1HWZRUN$FFHVV
6HUYLFH&RQWUROOHU
$FFHVV5HTXHVW
3'61+$ 5$',86 03,6,3SURFHGXUHV
3UHSDLG&OLHQW 6HUYHU DXWKHQWLFDWLRQDQGDXWKRUL]DWLRQ
)RUZDUG$FFHVV$FFHSW
6XEVFULEHU 6HQG$FFHVV5HTXHVWWR
ZLWK3UHSDLGTXRWD
3UHSDLGWDUJHW
6HQG$FFHVV$FFHSW 3UHSDLGWDUJHWFKHFNVWKH
ZLWK3UHSDLGTXRWD VXEVFULEHU¶VDFFRXQWEDODQFH
3UHSDLGWDUJHW
The Service Controller authenticates the subscriber, applies any applicable policies,
performs DMU and DHA procedures (if configured), and proxies messages to a
third-party billing system (prepaid target).
The prepaid target performs balance checks and quota functions and responds to
the Service Controller. The Service Controller appends required fields from the
subscriber profile and sends the result to the PDSN.
This section describes how to configure the Prepaid Data feature, including:
• To configure the prepaid target
• To configure [Link]
• To configure flat files
• To configure the RADIUS Server
• To set the RADIUS Server to run in SSR mode
• To create a dictionary
• To provision a connection service profile
• To provision a User profile set
• To provision subscribers
• To provision PDSNs/HAs with dynamic HA allocation
• To provision PDSN/HA groups
To configure [Link]
In the [Link] file, located in the /opt/aaasc/config/radius/ directory, configure
the following attributes: This section describes:
1 StripBridgewater VSAs
Configure StripBridgewaterVSAs (default = N) for each vendor to specify
whether RADIUS includes Bridgewater VSAs in Access-Accept messages that
it returns to RADIUS clients.
2 Use ClassAttribute to identify prepaid and postpaid subscribers
To identify a subscriber as prepaid or postpaid in the accounting records,
configure ClassAttribute=Y in the [Link] file and configure
PP-Rating-Type as described in "To create a dictionary" on page 44.
When a PDSN that supports the Class attribute receives an Access-Accept
message, that message contains a value for the Class attribute. The PSDN
then uses this Class attribute value in all accounting requests for this session.
The value used for the Class attribute is inserted by the RADIUS Server based
on the PP-Rating-type that has been configured. For the Class attribute value
to be available in the output accounting flat file, it must be configured as an
accounting record attribute in the [Link] file, using the
<AcctRecordAttribute> element, as defined in Table 70 on page 191.
For more information about these attributes, see Chapter 6, "Managing RADIUS
and Diameter dictionaries".
To create a dictionary
The default dictionaries located in /opt/aaasc/dict are read-only. When an update is
installed, this directory is overwritten. To add dictionaries or overwrite default
dictionaries, create DICT files in another location and reference them in
/opt/aaasc/config/dictionaries.
For the procedure to create a custom dictionary and finalize the changes, see
"Custom RADIUS dictionaries" on page 185.
Add the following attributes or VSAs to the new dictionary file:
VENDOR <vendor name> <vendor ID>
START-VSA 12951
ATTRIBUTE Policy-Type 5 octetstring none both single
ATTRIBUTE Prepaid-Error 6 integer16 none both single
#
#Policy-Type
SUBTYPE Policy-Type Identifier 1 integer16
SUBTYPE Policy-Type Policy-Off 2 flag
SUBTYPE Policy-Type Error 3 integer16
SUBTYPE Policy-Type Qualifier 4 integer16
SUBTYPE_VALUE Policy-Type Identifier PTT 0
SUBTYPE_VALUE Policy-Type Identifier PTT-With-Filtering 1
SUBTYPE_VALUE Policy-Type Error Policy-Cannot-Be-Activated
0
#
#Prepaid-Error
VALUE Prepaid-Error Incorrect-Quota-Type 0
VALUE Prepaid-Error Quota-Not-Received-For-Prepaid 1
7 Select PP-Rating-Type from the list of available attributes and set it to Prepaid.
8 Click Add.
9 Repeat steps 8 to 10 for other PDSN vendors supporting Prepaid Data services
in the network.
10 Click OK.
To provision subscribers
To provision a subscriber for Prepaid Data service:
1 In the Service Manager, select the Subscriber tab.
2 In the left pane, select the organization.
3 Launch the appropriate subscriber edit form.
4 In the left pane, select a connection service that is enabled for Prepaid.
5 Select a PDSN vendor from the drop-down list.
6 Select PP-Rating-Type from the list of available attributes and set it to Prepaid.
7 Click Add.
8 Repeat steps 5 to 7 for other PDSN vendors supporting Prepaid Data services
in the network.
9 Click OK.
6 Repeat steps 3 and 4 for any other PDSNs supporting Prepaid Data services in
the network.
7 Click Apply Changes.
RADIUS re-loads its configuration.
where
x is the time, in seconds, corresponding to the age of sessions in RMS in idle
state
> filename re-directs the data to the specified file, to hold the session data
PPBillingNodeServiceId=AAA_GCAP_TAX
PPBillingSessionId=20070109162122
PPBillingRequestNumber=0
PPBillingReserved=0
2 Display the prepaid sessions on the active RMS:
./prepaidReport
Note: This example shows the command that displays session information to
the screen without deleting sessions.
111111581060761@[Link],20561=[Link],21250=158
1060761,21251=300.00,21252=300.0000,21253=0.0000,21254=0.0
000,21255=0,21256=0,21257=0,21260=chargeable,21262=2,21264
=307200.00,21265=0.00,22529=AAA_GCAP_TAX,22530=20070109162
122,22534=0,22536=0,
Configuring Quick-Access
The Quick-Access feature enables prepaid customers that have used all of their
quota to access the network and replenish their quota. This feature requires that a
PDSN be configured to direct prepaid customers to a replenishment portal.
Note For online (subscriber on the network) requests, an Access-Reject
message is not converted (step 7) because authorization is not performed.
When the billing system determines that customers have used all of their quota, it
responds to the Service Controller with an Access-Reject message. The Service
Controller identifies the customer as a Quick-Access prepaid subscriber, converts
the message to an Access-Accept, authorizes the customer, retrieves the
configured Pool-ID, and sends a response to the PDSN. The PDSN can use this
information to direct customers to a self-administered services portal to replenish
their quota.
To create a dictionary
The default dictionaries located in /opt/aaasc/dict are read-only. When an update is
installed, this directory is overwritten. To add dictionaries or overwrite default
dictionaries, create DICT files in another location and reference them in /opt/aaasc/
config/dictionaries.
For the procedure to create a custom dictionary and finalize the changes, see
"Custom RADIUS dictionaries" on page 185.
Add the following attributes or VSAs to the new dictionary file:
VENDOR <vendor name> <vendor ID>
START-VSA 12951
ATTRIBUTE PP-Quick-Access 8202 integer none out single
## PP-Quick-Access
VALUE PP-Quick-AccessDisabled 0
VALUE PP-Quick-AccessEnabled 1
To configure Quick-Access
To configure RADIUS for the Quick-Access feature:
• Modify the [Link] file
• Modify the [Link] file
• Send a HUP signal to the RADIUS Servers
1 Modify the [Link] file
Update the /opt/aaasc/config/radius/[Link] file with the settings listed
in Table 24 to provide RADIUS Server support for Quick-Access customers.
Attribute Value
QARejectEnabled Y
ForwardPrepaidAcct="N"
QARejectEnabled="Y"
QAPoolID="5648EACD" />
[...]
</RADIUSConfiguration>
2 Modify the [Link] file
Update the [Link] file, located in the /opt/aaasc/config/radius/ directory,
with the elements listed in Table 25.
Element Value/Description
For more information about these parameters, see Table 70 on page 191.
This is an example of the [Link] file:
<VendorConfiguration>
<Vendor VendorName="USR"
[...]
PPQAPoolAttr="TC-Framed-IP-Address-Pool-Name"
PPQAPoolAttrValue="0123456789ABCD"
StripBridgewaterVSAs="Y"
[...]
</Vendor>
</VendorConfiguration>
3 Send a HUP signal to the RADIUS Servers
Send a HUP signal to the RADIUS Servers for changes to the [Link]
and [Link] files to take effect.
3 Launch the ConnectionService Service Profile edit form that you use to enable
Quick-Access for subscribers.
4 Select the “Attribute Information” tab.
5 Verify that the PDSN vendors providing Quick-Access for subscribers are
selected in the “Vendor Availability” tab.
6 Select the “Attribute Availability” tab.
7 Select the Quick-Access for subscribers PDSN vendor from the drop-down list.
8 Add PP-Quick-Access to the list of available attributes. Values are “Disabled”
and “Enabled”.
9 Repeat step 7 and step 8 for any other PDSN vendors supporting
Quick-Access for subscribers in your network.
10 Click OK.
0RELOH
'HYLFH 1HWZRUN$FFHVV
0'1 $FFHVV
8VHU6HUYLFHV
5HTXHVW
1$,
3'61+$ 5$',86 6,3
1$, 6HUYHU 377
3URILOH '81
$FFHVV
1$, 5HVSRQVH 'DWDEDVH
6HUYLFH&RQWUROOHU $FFHVV
&RQWURO
:KHUH 7LPHRI'D\
1$, 0'1#YHQGRUFRP 5RDP
1$, 0'1#SWWYHQGRUFRP $FFHVV3RLQW
1$, 01'#GXQYHQGRUFRP
Depending on the service type that the customer requires, embedded application
versus tethered device services, the Access-Request message contains the
appropriate NAI to access that service.
The Service Controller always initially authenticates the subscriber based on the
vendor realm, [Link]. The Service Controller then authenticates the
subscriber based on the subnet service, if necessary. If the subscriber is
provisioned for the subnet service, the Service Controller returns the authorization
to the PDSN in the Access-Response message.
This section describes how to configure RADIUS for Multiple NAI. The topics are:
• To configure the RADIUS Server
• To configure the RADIUS Server to enable SNMP
• To provision a connection service profile
• To provision User profile sets
• To provision subscribers for multiple NAI services
Note The following procedures assume familiarity with launching entity-specific
edit forms from the Service Manager main window. For more information,
see the Service Manager: Getting Started Guide for AAA.
6HUYLFH&RQWUROOHU
5$',86
6HUYHU
6HUYLFH&RQWUROOHU
5$',86
6HUYHU
The RADIUS Server includes the tunnel authentication attributes for each LNS in
the Access-Accept message.
To create a dictionary
The default dictionaries located in /opt/aaasc/dict are read-only. When an update is
installed, this directory is overwritten. To add dictionaries or overwrite default
dictionaries, create DICT files in another location and reference them in
/opt/aaasc/config/dictionaries.
For the procedure to create a custom dictionary and finalize the changes, see
"Custom RADIUS dictionaries" on page 185.
Add the following attributes or VSAs to the new dictionary file:
VENDOR <vendor name> <vendor ID>
# Bridgewater EVDO
START-VSA 3631
ATTRIBUTE EVDO-Authorization 4 string none out single
# request from FA
# Note that "mobileType=MobileFA" is present so RADIUS will be
# expecting to find the QoS Service policies
- - - CDMA2000LocalAA mobileType=SimpleIP
validateMobileID=Never service=SimpleIP
Access options
Allocate QoS policies for subscribers according to how the subscriber is accessing
the network, as listed in Table 26.
Option Description
Roaming Assign to subscribers that access their home networks via a foreign
network.
IS835-D Subscriber QoS Profiles are configurable using the Service Manager (For
more information, see "Configuring QoS Profiles using the Service Manager" on
page 63) and the Provisioning Server API. For more information, see the Service
Controller: Provisioning API Guide.
QoS attributes
This feature supports the QoS attributes listed in Table 27.
RADIUS supports merging these locally authorized QoS attributes with the QoS
attributes returned by the remote server. The rule for merging attributes from a
remote server applies; the choice of rules are:
• local only
• local first
• remote first
Note The system updates all CDMA2000 RADIUS dictionary files to include the
attributes listed in Table 28 on page 62 during installation of this feature.
The default dictionaries located in /opt/aaasc/dict are read-only. If these
attributes must be modified, create another dictionary. For more
information, see "Custom RADIUS dictionaries" on page 185.
Accounting attributes
This feature supports the accounting attributes listed in Table 28.
The system updates all CDMA2000 RADIUS dictionary files to include the attributes
listed in Table 28 during installation of this feature. The default dictionaries located
in /opt/aaasc/dict are read-only. If these attributes must be modified, create another
dictionary. For more information, see "Custom RADIUS dictionaries" on page 185.
grantedQoS
The IS835-D Subscriber QoS Profile feature supports the “grantedQoS” formatting
function. Multiple grantedQoS attributes can be sent in one RADIUS Accounting
Request message. However, only the first occurrence of a grantedQoS attribute in a
RADIUS Accounting Request message can be formatted.
Example:
$[Link]($[Link](“bin”,$[Link](“v5535:132=([^;]*)
$0”,$[Link])))
Output example with non-verbose option:
1=2|2=5|3=1|4=1
Output example with verbose option:
1=2|2=5|3=2|5=1|6=10|7=2|8=5|9=8|10=10|11=256|12=0
Installation
The BWSwsdbs package creates the “RADIUS QoS Selection Policy” service class
during installation. For information about installing the BWSwsdbs package, see the
Bridgewater Installation Reference Guide.
3 Click OK.
The New Service Profile form displays
4 Type a Service Profile Name in the field provided.
5 Select “Yes” for “Inheritance”.
6 Select the “Attribute Information” tab.
7 Select the “Vendor Availability” tab.
8 Select the vendors that this service profile supports, and then click the >>
button to add them to the list of Profile Supported Vendors.
9 Select the “Vendor Attribute Availability” tab.
10 From the Vendor dropdown list, select the appropriate vendor.
11 Select attributes that this service profile supports in the “Dictionary Supported
Attributes” pane, and click “>” to move them to the “Vendor Supported
Attributes” pane.
12 Select the “Vendor Attributes” tab.
13 Add Dictionary Attributes that this service supports.
14 Click OK to save the profile.
Configuring EAP
Administrators must configure EAP-TLS, EAP-TTLS, LEAP, MD5, MSCHAPv2,
EAP-AKA, and PEAP authentication manually. This information is added to the
[Link] and the accessReqPolicy configuration files for RADIUS, in the /opt/aaasc/
config/radius directory, and for Diameter in /opt/aaasc/config/dia-aaa.
For more information on the [Link] schema, its elements and attributes, and an
example [Link] file, see the Extensible Authentication Protocol Guide.
%s: Loading GMT Offset NTCE The plugin is loading No action required.
values from file the GMT Offset
values from the .csv
file.
No GMT Offset found for NTCE The specified BSID No action required.
BSID %s has no GMT Offset
associated with it.
Valid values for The name of any AVP or VSA in a RADIUS The name of any AVP or VSA in the
acMatchAttribute dictionary that is loaded on the database. [Link] dictionary file.
Must be in the form: Must be in the form: <attribute-name>
[<vendor-name>:]<attribute-name> Note: Do not use the vendor-name parameter in
(vendor-name is optional) Diameter deployments.
Example: User-Name contains @[Link] Example:
LocalAA User-Name contains @[Link] WiMAXLocalAA
acMatchAttribute=Calling-Station-ID acMatchAttribute=Calling-Station-ID
Supported attribute types Supports all RADIUS attribute types except Supports all Diameter attribute types except
for acMatchAttribute “octetstring’ (sub-typed attributes) “grouped”, “float32”, and “float64”.
Note If this modifier is added to a policy line, but the attribute value in the
Access-Request message does not match the attribute value in the
associated Access Control service, the Service Controller returns an
Access-Reject.
– If access attributes are configured at multiple contexts and the Access field
is set to “Unspecified” at the User context, but the Access field is set to
“Allow” or “Deny” at a higher context, the action specified at the higher
context takes precedence
• add this service profile to the User profile sets of all subscribers to whom you
want to apply AVP-based access control
For information about the fields and attributes of the Access Attribute tab on the
Access Control edit form, see the Service Manager: Services Provisioning Guide
for AAA.
6HUYLFH&RQWUROOHU
5$',866HUYHU
&'$/ 3URILOH
5$',86 ($3 FRQWH[W 'DWDEDVH
FOLHQW H[FKDQJH ($3
VHVVLRQGDWD
($3VWDWH
GDWDFRQWDLQHU
($3VWDWH
5$',86 5$',86 3URILOH
GDWD
6HUYHU &OLHQW GDWDEDVH
FRQWDLQHU
15 The RADIUS Server and client continue to exchange EAP messages until the
EAP-TLS process completes.
[Link]
Set the EAPSessionCacheEnabled parameter in the [Link] file to ‘Y’.
The [Link] file is located in the /opt/aaasc/config/radius directory. For
more information about [Link], see "Configuring access features with
[Link]" on page 5.
Example:
<RADIUSConfiguration AcctDBLookup="Y"
DefaultAccessControlService="Access Control" DNSThreads="0"
ValidateClientIP="Y" WiMAXReAuthenticationInterval="1800"
WiMAXReAuthenticationIntervalDelta="0" MaximumLoadedClients="5000"
LogCallingStationIdOnReject="N" LogNASIP="N"
EAPSessionCacheEnabled ="Y" >
HTTP Digest In this call flow, the RADIUS Server receives an authentication request from the
Authentication HTTP proxy that contains Digest attributes.
First Access-Request
Figure 9: First Access-Request
8(
+7733UR[\ $$$6HUYHU +/5
'166HUYHU
86,0 0(
^,06,.` ^,06,.`
^,06,.6415$1'
;5(6&.,.$871`
8QDXWKRUL]HG
:::$XWKHQWLFDWH'LJHVW 0$3
5HDOP ´DEFKRPHQHW´QRQFH EDVH 6HQGB$XWKHQWLFDWLRQB,QIR
5HVSRQVH5$1';5(6&.
5$1'DOJRULWKP $.$Y0' ,.$871
$FFHVV&KDOOHQJH5$1'
TRS ´DXWK´ UHDOPDOJRTRS
$FFHVV&KDOOHQJH
'LJHVW$OJRULWKP ´$.$Y0' $$$VHUYHUILOOV
'LJHVW1RQFH ´5$1'´ VRPHILHOGV
'LJHVW5HDOP ´DEFKRPHQHW´67$7,& UHDOPDOJRDQG
'LJHVW4RS ´DXWK´67$7,& TRS
6WDWH ´;5(6´
0HVVDJH$XWKHQWLFDWRU 0$&!^5)&`
Second Access-Request
Figure 10: Second Access-Request
8(
'166HUYHU +7733UR[\ $$$6HUYHU +/5
86,0 0(
^,06,.`
^,06,.`
$FFHVV&KDOOHQJH
6,0BDXWKHQWLFDWLRQ5$1' 8VHU1DPH ´,06,´
'LJHVW5HDOP ´DEFKRPHQHW´
6,0B*60$XWKHQWLFDWLRQ5(6.& 'LJHVW$OJRULWKP ´$.$Y0'
'LJHVW4RS ´DXWK´
+773UHTXHVW 'LJHVW0HWKRG ´3267´
8VHU$JHQW[[[DXWKHQWLFDWLRQPRGH 'LJHVW85, ´;;;<<<´
$XWKRUL]DWLRQ'LJHVWXVHUQDPH ´,06,´ 'LJHVW&QRQFH ´FQRQFH´
5HODP ´DEFKRPHQHW´QRQFH EDVH 'LJHVW1RQFH ´5$1'´
5$1'DOJRULWKP $.$Y0' 'LJHVW1RQFH&RXQW ´QF´
8UL ´;;;<<<´UHVSRQVH ´[[[[«´ 'LJHVW5HVSRQVH ´UHVSRQVH´5)&
6WDWH ´;5(6´
0HVVDJH$XWKHQWLFDWRU 0$&!^5)&`
0'UHVSRQVHEXLOWXVLQJWKH&KDOOHQJHUHVSRQVHFRPSXWHG $FFHVV5HTXHVW$.$Y0',06,
E\WKH6,0IDOJR,06,UHDOP5(6QRQFHFQRQFHQF DEFKRPHQHWUHVSRQVH3267XUL
PHWKRGXUL
&DOFXODWHI^DOJR,06,UHDOP;5(6
QRQFHFQRQFHQFPHWKRGXUL`
$QGFRPSDUHUHVXOWZLWKUHVSRQVH
0$36(1'5287,1*,1)2)25/&6,06,
0$36(1'5287,1*,1)2)25/&65HVSRQVH06,6'1
$FFHVV$FFHSW06,6'1
$FFHVV$FFHSW
8VHU1DPH ´06,6'1´
0HVVDJH$XWKHQWLFDWRU 0$&!^5)&`
5 Depending on Radius Server s result, the HTTP proxy processes the user
devices request or rejects it with a "(Proxy) Authorization required" response.
AKA synchronization In this call flow, the SQN provided by the RADIUS Server does not match the one
failure maintained by the HTTP Proxy.
Figure 11: AKA synchronization failure
^,06,.`
$XWKUHTXHVW
5$1'$$871
06GHWHUPLQHVWKDWWKH641FRQWDLQHGLQWKH$871GRHV
QRWPDWFKLWVORFDOO\VWRUHG641DQGUHVSRQGVZLWKDQDXWK
DXWKUHV\QFKURQL]H UHV\QFKURQL]HPHVVDJH
)DLOXUHUHSRUWVHQWZLWKDQ$.$537
$.$5(3257$.$537 YDOXHRI³6\QFK)DLOXUH´$876
5$1'$$876 FRQWDLQV&21B06B641 0$&B6
YDOXHVUHFHLYHGIURP06
DNDUHSRUW
$.$9/
+RPHV\VWHPXVHV$876LQIRWR
V\QFKURQL]HZLWK06DQGSURYLGH
DQHZOLVWRI$9V
DXWKUHTXHVW
5$1'$$871 9LVLWHGV\WHPUHDWWHPSWV$.$DXWK
XVLQJ$9IURPQHZOLVW
1 After receiving an AURSYNM response from the HTTP Proxy, the RADIUS
Server sends an AKA status report (AKAREPORT) to the HLR with AKARPT
set to "Synchronization Failure."
Also included in this report are the RANDA used during the AKA attempt and an
AKA authentication token for resynchronization (AUTS) containing the
CON_MS_SQN and MAC_S values received from the HTTP Proxy.
2 The HLR uses the MAC_S to make sure that the resynchronization attempt is
authentic and sets its SQN to the one concealed in the CON_MS_SQN.
3 With the new SQN, the HLR generates a new AV list and provides this new AV
list to the RADIUS Server in the AKAREPORT response message (akareport).
The HLR has resynchronized.
4 The RADIUS Server selects an AV from the new list and reattempts AKA with
the HTTP proxy.
Policies
The HTTPDigest-Policy action modifier enables the RADIUS Server to use AKA
authentication when an Access-Request containing Digest attributes for Digest
Authentication is received from the HTTP proxy.
When not explicitly specified on the policy line, RADIUS automatically looks for a
<http-digest-policy> entry in the [Link] file with the policy name set to
“default”.
[Link]
The [Link] dictionary contains Digest attributes used for HTTP Digest
Authentication.
#RFC 5090 HTTP-Digest Authentication attributes
ATTRIBUTE Digest-Response 103 string none in single
ATTRIBUTE Digest-Realm 104 string none both single
ATTRIBUTE Digest-Nonce 105 string none both single
ATTRIBUTE Digest-Response-Auth 106 string none out single
ATTRIBUTE Digest-Nextnonce 107 string none out single
ATTRIBUTE Digest-Method 108 string none both single
ATTRIBUTE Digest-URI 109 string none in single
ATTRIBUTE Digest-Qop 110 string none both multi
ATTRIBUTE Digest-Algorithm 111 string none both single
ATTRIBUTE Digest-Entity-Body-Hash 112 string none in single
ATTRIBUTE Digest-CNonce 113 string none in single
ATTRIBUTE Digest-Nonce-Count 114 string none in single
ATTRIBUTE Digest-Username 115 string none in single
ATTRIBUTE Digest-Opaque 116 string none both single
ATTRIBUTE Digest-Auth-Param 117 string none both single
ATTRIBUTE Digest-AKA-Auts 118 string none in single
ATTRIBUTE Digest-Domain 119 string none both multi
ATTRIBUTE Digest-Stale 120 string none out single
ATTRIBUTE Digest-HA1 121 string none out single
ATTRIBUTE SIP-AOR 122 string none in single
Configuration
HTTP Digest Authentication requires two configuration files: [Link] and
[Link] file. The [Link] file is configured for a standard WLAN
deployment. For more information about the [Link] file, see the 3G/
WLAN Interworking Guide.
[Link] file The [Link] file, located in /opt/aaasc/config/radius/, defines the specific
HTTP digest configuration. The file is delivered, preconfigured, in the BWSwsrad
package, and is huppable.
vector-setting — Required.
Child element of http-digest-configuration.
vector-setting-name String The name of the vector setting, for example, “HLR”.
Required.
Attribute of vector-setting.
http-digest-policy — Required.
Child element of http-digest-configuration.
[Link] example
<http-digest-configuration>
<vector-setting
vector-setting-name="HLR"
authentication-center="External-No-DB-Lookup"/>
<http-digest-policy
policy-name="default"
realm="[Link]"
quality-of-protection="auth">
<AKAv1-MD5
vector-setting="HLR"
nonce-format="RAND"/>
</http-digest-policy>
</http-digest-configuration>
accessReqPolicy example
---WiFiLocalAA EAP-Policy=default service=DEFAULT
---WiFiLocalAA service=DEFAULT authentication=n
checkSession=y
:LUHOHVV/$1
06 $FFHVV3RLQW 77* 6HUYLFH&RQWUROOHU 506 +/5
&RQWUROOHU
[Link]
The [Link] file is the configuration file for the npcGSM plugin, and it
defines a list of Policy Controller servers. When more than one Policy Controller is
listed, the npcGSM plugin supports failover. If a Policy Controller is unreachable,
the plugin suspends the Policy Controller and fails over to the next Policy Controller
in the list. If all Policy Controllers are suspended, the plugin retries the Policy
Controller with the lowest remaining suspension timeout.
When more than one Policy Controller is defined in the [Link] file, the
list of Policy Controller nodes is also used for load balancing. Requests are
allocated to Policy Controllers in a round robin method.
To make sure the system loads [Link] file changes, send a HUP signal
to the RADIUS server.
The [Link] file is located in the /opt/aaasc/config/radius/ directory.
default-domain String The name of the default domain to add to the request if no domain
is specified.
Attribute of server-config.
port Integer The port on which the plugin contacts the Policy Controller.
Attribute of policy-controller.
timeout Integer The time after which the plugin fails over to the secondary Policy
(100-20000) Controller.
Default =2000 Attribute of policy-controller.
Optional.
max-connection-timeout Integer The timeout for the Policy Controller with the highest number of
(100-20000) queued available connected-connections when the max-connection
Default =2000 is reached.
Attribute of policy-controller.
Optional.
additional-var-list — Encloses the list of RADIUS variable names that the plugin
retrieves from the RADIUS policy.
Child element of server-config.
Create additional Specify additional variables for VBM that can be used to create policies in the RMA.
variables for use in
policies To create additional variables
1 Add a variable, such as “attribute2, to the [Link] file.
The [Link] file is located in the $HOME/is/<instance name>/
provserver/ config/ directory on the Policy Controller server.
Example:
<additional-information entity="Additional Information">
<attribute name="attribute2"/>
</additional-information>
2 Add the entry point for the variable to the [Link] file.
For example, to add a variable to the AAA authorization entry point, add the
variable to the <entry-point name="AAA_Auth"> section:
<entity name="Additional Information">
<attribute name="attribute2" base-type="STRING"/>
</entity>
The [Link] file is located in the $HOME/is/<instance
name>/provserver/config/ruleEngineDescriptors/ directory on the Policy
Controller server.
3 Add the variable to the [Link] file.
The [Link] file is located in the /opt/aaasc/config/radius/ directory
on the Service Controller server.
3
Chapter 3
Chapter
This chapter describes how to configure LDAP as the subscriber data access
method for the Service Controller.
The topics are:
• RADIUS and an LDAP Directory Server
• Configure [Link]
• Managing the memory map file
• Configuring LDAP DAL Query Caching
• Configuring LDAP connection pooling
• Configuring remote LDAP authentication
• Configuring the LDAP secondary shared secret
6HUYLFH&RQWUROOHU
$FFHVV
5$',86
5HTXHVWV
/'$3PHPRU\ /'$3
SDSILOH GLUHFWRU\
Note Configuring the RADIUS Server to use a LDAP Directory Server involves
customizing the [Link] file to interact with the database schema
specific to the LDAP directory. Contact Bridgewater Customer Support for
more information.
Figure 14 illustrates the processes involved in communication between the Service
Controller and the LDAP database.
Figure 14: Service Controller interface with LDAP database
6HUYLFH&RQWUROOHU
UDGLXVG
/'$3
GDWDEDVH
The following steps are required to configure the RADIUS Server to use an LDAP
Directory Server:
• Configure [Link]
• Managing the memory map file
Note Before starting the configuration steps, verify that the LDAP DAL was
selected when installing the BWSdal and BWSwsrad packages.
Configure [Link]
The [Link] file, located in /opt/aaasc/config/, contains the information
required for the RADIUS Server to interact with the LDAP directory database
schema.
After the [Link] file is loaded into the memory map file, the system sends a
HUP signal to the RADIUS Server process to make changes to the XML file take
effect.
For an example [Link] configuration file, see "Example [Link] file"
on page 107.
system-elements The element that encloses the system provisioning elements for RADIUS clients,
PDSN groups, and HA groups:
• one or more pdsn-group child elements (optional)
• one or more client child elements (required)
• one or more client-pool child elements
• one or more ha-group child elements (optional)
• one or more wimax-node-group child elements (optional)
• one or more wimax-ha-group child elements (optional)
The system-elements tag has no attributes.
For example:
<system-elements>
<pdsn-group ... />
<client ... />
<client-pool ... />
<ha-group ... />
<wimax-node-group ... />
<wimax-ha-group ... />
</system-elements>
pdsn-group Defines PDSN groups for client systems. One or more pdsn-group elements may
be defined, up to a maximum of 64.
A pdsn-group element must be defined before it is referenced by a client element.
Child element of system-elements.
Optional
For example:
<pdsn-group id="chicago-pdsn" rms-cluster-id="1"/>
id String The name of the PDSN group. This value must be unique among the
IDs in this file.
Required.
rms-cluster-id Integer (0–254) The RMS cluster number for this group. This value must match a cluster
ID defined in the [Link] file.
Required.
id String The name of the client. This value must be unique among the
IDs in this file.
Required.
secret2 String The secondary shared secret string used by the client.
Optional.
vendor String The vendor name which matches an entry in the [Link]
file.
Required.
model String This value must match the entry in the [Link] file.
Optional.
timezone String The timezone in which the client runs. The typical value is
GMT.
Required.
pdsn-group String This value must match a previously defined pdsn-group ID.
Do not specify the pdsn-group attribute if the
wimax-node-group attribute is specified.
Optional.
skipcount Integer (0–254) A tuning parameter, used for load balancing. For example, if
skipcount=3, the specified client receives every third request.
Optional.
dae-coa-port Integer (1024–65535) The port on which to receive DAE messages. Use for CoA
Default = 3799 messages.
Optional.
dae-dm-port Integer (1024–65535) The port on which to receive DAE messages. Use for DM
Default =value of messages.
dae-coa-port Optional.
dae-retries Integer (0–5) The number of retries the RADIUS client should attempt when
Default = 0 sending a DAE message.
Optional.
dae-timeout Integer (1–15) The time, in seconds, the RADIUS client should wait for the
Default = 2 DAE Ack from the Server.
Optional.
For example:
<system-elements>
<pdsn-group id="chicago-pdsn" rms-cluster-id="1"/>
<wimax-node-group id="dallas-wimax" rms-cluster-id="1"/>
<client id="omaha1" ip-address="[Link]" secret="MYSECRET"
vendor="CISCO" timezone="GMT"/>
<client-pool id="femtos1" ip-address="[Link]"
secret="FEMTOSECRET" vendor="SAMSUNG" timezone="GMT">
<ip-range>[Link]/24</ip-range>
</client-pool>
<client-pool id="femtos2" ip-address="[Link]"
secret="FEMTOSECRET" vendor="CISCO" timezone="GMT">
<ip-range>[Link]-[Link]</ip-range>
</client-pool>
</system-elements>
vendor String The vendor name which matches an entry in the [Link] file.
(1-255 Required.
characters)
id String The name of the HA group. This value must be unique among the IDs in
this file.
Attribute of ha-group.
Required.
skipcount Integer (0–254) Used for load balancing. For example, if skipcount=3, the specified HA
client receives every third request.
Attribute of ha-client.
Optional.
wimax-node-group Defines a WiMAX node group for client systems. One or more wimax-node-group
elements may be defined, up to a maximum of 64.
Child element of system-elements.
Optional.
For example:
<wimax-node-group id="dallas-wimax" rms-cluster-id=”1”/>
The node group may be associated to multiple RMS clusters. If so, use any of the
following formats:
<wimax-node-group id="dallas-wimax" rms-cluster-id=”1, 2, 3, 4” />
<wimax-node-group id="dallas-wimax" rms-cluster-id=”1-4” />
<wimax-node-group id="dallas-wimax" rms-cluster-id=”1-4, 6” />
rms-cluster-id String The RMS cluster number for this group. This value must match a
0 to 254 cluster ID defined in the in [Link] file.
Comma separated list (1,2,3) To define multiple RMS clusters, type a list of comma delimited
cluster IDs, such as 1,2,3 or a range of cluster IDs, such as 0-3.
Range of IDs (1 to 4)
When identifying an RMS cluster range, use the format “0-3”; do
not use the format “3-0”.
Optional.
id String The name of the wimax-ha-group element. This name can be used
to reference the group for purposes of the DHA.
Attribute of wimax-ha-group.
Required.
wimax-ha-client String The name of a client system. One or more distinct wimax-ha-client's
can be listed within one ha-group. One wimax-ha-client can belong
to multiple wimax-ha-groups
Child element of wimax-ha-group.
Optional.
ldap-server Encloses the child element listed in Table 39 on page 100, containing
LDAP-specific connection information for the LDAP server(s). Changes to this
section require a full stop and restart of the RADIUS Server process (radiusd).
ldap-server is a required [Link] to a maximum of 10 instances may be
configured.
Child element of radintdal.
Note At least one instance of <ldap-server> must have the element
<query-name> set to “aaa-auth-query”.
The ldap-server tag has no attributes.
For example:
<ldap-server>
<query-name>aaa-auth-query</query-name>
<dn>cn=Directory Manager</dn>
<password>password</password>
<host host="host1">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<host host="host2">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<connection-pool
max-pool-size="100"
max-wait-time="500"/>
<port>389</port>
<base-dn>ou=domain,dc=mydomain,dc=com</base-dn>
<user-password>userPassword</user-password>
<db-attribute>deviceStatus</db-attribute>
<user-filter>uid=jsmith</user-filter>
<search-scope>0</search-scope>
<retry-interval>20</retry-interval>
<deref-alias>never</deref-alias>
</ldap-server>
host String Encloses the attribute “host”, and the child element <timelimit> and
<retry>, and specifies an LDAP server to query. To specify additional
LDAP servers, add additional <host> elements.
The port can be optionally specified by using the following format:
hostname:port.
There can be a maximum of six host elements. For each failover host,
add a “host” attribute.
Child element of ldap-server.
Required.
retry Integer The number attempts before failing over to the next LDAP server after the
(0-6) “timelimit” for an LDAP server query expires.
Default = 0 Child element of host.
Optional.
idle-timeout Integer The time, in seconds, a connection is allowed to remain idle before it is
(60-32000) closed.
Default=300 Child element of host.
Optional.
connection-pool — Defines settings for the connection pool the LDAP DAL uses to connect
to the LDAP Server. Encloses the attributes initial-pool-size,
max-pool-size, and max-wait-time.
There is a maximum of one connection-pool for each ldap-server section.
For more information about configuring a connection pool, see
"Configuring LDAP connection pooling" on page 116.
Child element of ldap-server.
Required.
max-wait-time Integer The time, in milliseconds, that a request for an LDAP connection can wait
(1-10000) in the connection pool’s request queue.
Note max-wait-time is different from timelimit, which specifies the time,
in milliseconds, for an LDAP server query.
Attribute of connection-pool.
Required.
port Integer The LDAP port for the specified host(s). This value is overridden by any
Default = 389 port(s) specified in the host entry.
Child element of ldap-server.
Optional.
base-dn String The search starting point for the user-filter. For example,
ou={domain},dc=mydomain,dc=com. {domain} is replaced by the
RADIUS domain. This is a simple search and replace algorithm.
Note For subscribers with dual-mode devices, give base-dn a token
value and specify the domains in the accessReqPolicy file using
the authenticateDomain action modifier and in the TLSPolicy file
using the authenticateDomain and authorizeDomain action
modifiers. For example in [Link] or [Link]:
<base-dn>{domain}</base-dn>.
For more information on policy files, see "Configuring AAA policies" on
page 233. For information on [Link], see "Installing and
configuring Diameter" on page 133.
Child element of ldap-server.
Required.
user-password String The name of the password attribute used to authenticate a subscriber.
For example, userPassword searches for a field called userPassword to
find the password to use for authentication.
Child element of ldap-server.
Required.
retry-interval Integer The per thread retry interval, in seconds, to return to the primary LDAP
server.
Child element of ldap-server.
Required.
deref-alias • never (Default) Determines how aliases are handled during a search. Valid values for
• always deref-alias are:
• searching • never—aliases are never de-referenced by the LDAP server
• finding • always—aliases are de-referenced during phase one, when locating
the base object of the search
• searching—aliases are de-referenced during the second phase
• finding—aliases are de-referenced during both phases of the search
Child element of ldap-server.
Optional.
service Defines service parameters and authorization information for a specific network
vendor.
There may be one or more service elements, up to a maximum of 256.
Each service element may enclose one or more optional vendor-attribute child
element.
Child element of radintdal.
For example:
<service id="fa_service">
<vendor-attribute ... />
<vendor-attribute ... />
</service>
id String (1–-255 The name of the service. This must be unique among all IDs in this file.
characters) Required.
vendor-attribute Contains a list of static or ldap attributes to return for the vendor. All attributes are
required unless indicated.
One or more vendor-attribute elements may be defined, up to a maximum of 64.
Child element of service.
For example:
<vendor-attribute vendor="SHASTA">
<ldap-attribute name="3GPP2-HA-IP-Addr" ldapvalue="DHAIP"
defaultvalue=”#GmipHAIPAddr,dynamicHAPolicy”>
<exception-value>[Link]</exception-value>
<exception-value>[Link]</exception-value>
</ldap-attribute>
</vendor-attribute>
Attribute or
Value Description
element
vendor • COMMON The vendor name. This value must match an entry in the [Link] (case-sensitive)
• String or the string 'COMMON'.
One or more services can be listed, each with zero or more static and/or LDAP
attributes. Attributes listed under the COMMON vendor are applied to any subscriber
whose specific vendor is not explicitly listed under the service or whose vendor does
not also contain that particular RADIUS attribute.
Attribute of vendor-attribute.
Required.
name String The RADIUS attribute name, found in the vendor dictionary.
name String The RADIUS attribute containing the value retrieved. Define sub AVPs in the
ldap-value attribute.
Note For Sip Server Interworking, this parameter must be configured as “Class”. This
maps to the AcctRecordAttribute in the [Link] file.
Attribute of ldap-attribute.
Attribute or
Value Description
element
ldapvalue String The name of the LDAP attributes to retrieve. Define sub AVPs in this field. The sub
AVPs correspond to the AVP name specified in the “name” attribute.
The ldapvalue attribute can have the following syntax:
• no sub AVPs: <ldap-attribute name="attributeX” ldapvalue="getvalue"/>
• one sub AVP: <ldap-attribute name="attributeY” ldapvalue="1022={getvalue}"/>
• multiple sub AVP: <ldap-attribute name="attributeZ” ldapvalue="1023={getZ} |
1026=stated"/>
Separate multiple sub AVPs by a “|” character and at least one value enclosed with
curly braces {}.
Note For Sip Server Interworking, this parameter must be configured as: mdn.
Attribute of ldap-attribute.
defaultvalue String A default attribute value that is returned if an ldap-attribute is not found in an LDAP
search or if the ldap-attribute matches a configured exception-value. The defaultvalue
must be defined if exception values are specified for an ldap-attribute. The
defaultvalue string is limited to 253 characters.
Attribute of ldap-attribute.
Optional.
exception-value String When an exception-value matches the stored ldap-value, the configured default value
is returned as the RADIUS attribute. If exception values are specified, then a
defaultvalue must be defined.
The exception-value string is limited to 253 characters. A maximum of 5 exception
values (no duplicates) can be configured for each ldap-attribute. A maximum of 640
exception values can be configured in a [Link] file.
Make sure that attribute names are mapped statically or dynamically, not both.
Configuring an attribute name in static-attribute and ldap-attribute within the same
service results in two values being returned for a single attribute and can cause
inconsistent behavior.
Child element of ldap-attribute.
Optional.
dal-cache Encloses attributes to enable or disable LDAP DAL query caching, and establish
settings for the cache. If dal-cache and is missing from [Link], LDAP DAL
query caching is disabled. For information about configuring LDAP DAL query
caching, see "Configuring LDAP DAL Query Caching" on page 112.
Note After installing the LDAP DAL cache, check the attribute values to make
sure they are optimal for your deployment.
Restart RADIUS for changes to dal-cache to take effect.
Note dal-cache is only available for RADIUS.
dal-cache encloses the following attributes:
• enabled
• max-entries
• max-memory
• time-to-live
Child element of radintdal.
Optional.
For example:
<dal-cache enabled="y" max-entries="10" max-memory="1000000"
time-to-live="30"/>
max-entries Integer The maximum number of entries stored in the cache. This should be
Default =4096 calculated as the average number of authentication requests expected
during the time-to-live plus one or two standard deviations.
Range= 0-1000000 (1
million entries. The If max-entries is reached and a new LDAP query needs to be cached,
cache entry overhead the LDAP DAL purges the oldest entry out of the cache and stores the
consumes around 200 new query and its results in the cache.
MB) Optional.
max-memory Integer The upper bound for the total memory consumption of the cache,
Default =10000000 represented as the number of bytes. The max-memory does not include
the overhead for each cache entry
Range= 0-1000000000
(1 GB) If a max-memory value is reached and a new LDAP query needs to be
cached, the LDAP DAL removes the oldest cache entries until there is
enough space to add the new query and its results in the cache.
Optional.
time-to-live Integer The time, in seconds, an entry remains before it is aged out. This should
Default= 30 be calculated as the time for a standard EAP authentication plus one or
two standard deviations to account for outliers.
Range= 0-100000000 (3
years) If the RADIUS server makes a DAL query and the LDAP DAL finds the
query is cached but has reached the time-to-live:
• the LDAP DAL passes the LDAP query to the LDAP database
• the LDAP database returns the query results back to the LDAP DAL
• the LDAP DAL replaces the old query with the new one if the LDAP
query was successful
Note Any update to the LDAP database is not reflected in the cache
until the time-to-live expires for an entry.
Optional.
Example <radintdal>
[Link] file <system-elements>
<pdsn-group id="chicago-pdsn" rms-cluster-id="1"/>
<wimax-node-group id="dallas-wimax" rms-cluster-id="1" />
<client id="omaha1"
ip-address="[Link]"
secret="MYSECRET"
vendor="CISCO"
timezone="GMT"/>
<client id="omaha2"
ip-address="[Link]"
secret="MYSECRET"
vendor="STARENT"
timezone="GMT"/>
<clientid="chicago1"
ip-address="[Link]"
secret="MYSECRET"
vendor="NORTEL"
timezone="GMT"
pdsn-group="chicago-pdsn"/>
<client id="chicago2"
ip-address="[Link]"
secret="MYSECRET"
vendor="NORTEL"
timezone="GMT"
pdsn-group="chicago-pdsn"/>
<client id="dallas1"
ip-address="[Link]"
secret="MYSECRET"
vendor="NORTEL"
timezone="GMT"
wimax-node-group="dallas-wimax"
ha-root-key-lifetime="86400" />
<client id="dallas2"
ip-address="[Link]"
secret="MYSECRET"
vendor="CISCO"
timezone="GMT"
wimax-node-group="dallas-wimax"
ha-root-key-lifetime="86400" />
<client id="dallas3"
ip-address="[Link]"
secret="MYSECRET" vendor="STARENT"
timezone="GMT"
wimax-node-group="dallas-wimax"
dae-enabled="true"
dae-coa-ip-address="[Link]"
dae-coa-port="2000"
dae-coa-shared-secret="DAESECRET"
dae-dm-ip-address="[Link]"
dae-dm-port="2000"
dae-dm-shared-secret="DAESECRET"
dae-timeout="5"
dae-retries="0"/>
<ha-group id="omahaG1">
<ha-client>omaha1</ha-client>
<ha-client skipcount="10">omaha2</ha-client>
</ha-group>
<ha-group id="omahaG2">
<ha-client skipcount="1">omaha1</ha-client>
<ha-client skipcount="2">omaha2</ha-client>
</ha-group>
<wimax-ha-group id="betaH1">
<wimax-ha-client>dallas1</wimax-ha-client>
<wimax-ha-client>dallas2</wimax-ha-client>
</wimax-ha-group>
</system-elements>
<ldap-server>
<dn>cn=Directory Manager</dn>
<password>password</password>
<host host="host1">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<host host="host2">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<connection-pool
max-pool-size="100"
max-wait-time="500"/>
<port>389</port>
<base-dn>ou=domain,dc=mydomain,dc=com</base-dn>
<user-password>userPassword</user-password>
<user-filter>uid=jsmith</user-filter>
<search-scope>2</search-scope>
<retry-interval>20</retry-interval>
<deref-alias>never</deref-alias>
</ldap-server>
<service id="fa_service">
<vendor-attribute vendor="STARENT">
<static-attribute name="Idle-Timeout" value="60"/>
</vendor-attribute>
<vendor-attribute vendor="NORTEL"/>
</service>
<service id="ha_service">
<vendor-attribute vendor="COMMON">
<static-attribute name="idle-timeout" value="hard-coded-value"/>
<ldap-attribute name="serviceprofile" ldapvalue="HotLineURL"/>
</vendor-attribute>
<vendor-attribute vendor="STARENT">
<static-attribute name="idle-timeout" value="12"/>
</vendor-attribute>
</service>
<service id="defaultDHA">
<vendor-attribute vendor="SHASTA">
<ldap-attribute name="3GPP2-HA-IP-Addr" ldapvalue="DHAIP"
defaultvalue=”#GmipHAIPAddr,dynamicHAPolicy”>
<exception-value>[Link]</exception-value>
<exception-value>[Link]</exception-value>
</ldap-attribute>
</vendor-attribute>
</service>
<dal-cache enabled="y" max-entries="4096" max-memory="1000000"
time-to-live="30"/>
</radintdal>
Option Description
Option Description
-f MMAP_filename The name and location of the memory map file created with the
ldapdalinit utility.
-x XML_filename The name and location of the [Link] file. By default, this
file is located in the /opt/aaasc/config directory.
6HUYLFH&RQWUROOHU
/'$3'$/
Usage Description
Statistic Description
Statistic Description
Not Cached Number of instances where the cache entry's memory size
is larger than the configured max-memory, and thus is not
cached.
2403 DAL statistics is not ERR If a DAL library that does not support
supported by the loaded DAL statistics is loaded by the
DAL library. RADIUS server and an attempt is
made to execute the dalstats utility to
signal the RADIUS server to log
statistics, this log appears.
6HUYLFH&RQWUROOHU
UDGLXVG UDGOGDSGDO[PO
GLDDDDG GLDOGDSGDO[PO
UDGLXVGGLDDDDG
/'$3'$/ &RQQHFWLRQ3RRO
LQWHUIDFH
/'$3
GDWDEDVH
For example:
--- ProxyAA target=LDAPServer1 dnSearchBaseRegExp=”s/
user@(.*)/cn=submanagers,cn=managers,ou=people,o=$
{1}”
where
the leading “s” means “substitute” and is a required parameter.
“/” is a delimiter for separating fields. The first occurring “/” indicates the
start of the first field (the search field) and the second “/” indicates the start
of the second field which is the replacement string used to build the DN.
() indicates a value to save to the first regular expression variable defined
by “${1}”.
“.*” within the parentheses indicates 0 or more of any character; where “.” is
any character and “*” is 0 or more.
An optional target action-modifier called dnPrefix is configurable in the
accessReqPolicy file for the ProxyAA action. RADIUS uses the dnPrefix to
construct the DN string. As an example:
--- ProxyAA target=LDAPServer1
dnSearchBase=”cn=submanagers,cn=managers,ou=people,o=abc.c
om”
dnPrefix=cn
The dnPrefix target action-modifier overrides the DNPrefix XML parameter
specified in the [Link] file for the referenced LDAP target.
An organization may deploy an LDAP server so that one organizational hierarchy
may use a dnPrefix value that differs from the dnPrefix value used in another
organizational branch. In such cases, it is desirable to set up policy rules to reflect
this situation.
This enables the administrator to determine which dnPrefix to use based on the
location of its subscribers on the LDAP server. For example, subscribers under the
[Link] organization may be modeled on the LDAP server to use a
dnPrefix of value “uid”.
Subscribers under the [Link] organization may be modeled to
use the dnPrefix value of “cn”. An administrator can setup policy rules to handle
these types of situations. As an example:
User-Name EndsWithCI [Link] ProxyAA
target=LDAPServer1
dnSearchBase=”g=sales,ou=canada,o=[Link]” dnPrefix=uid
User-Name EndsWithCI [Link] ProxyAA
target=LDAPServer1
dnSearchBase=”g=support,ou=canada,o=[Link]” dnPrefix=cn
If, however, all subscribers in all branches of the LDAP server use the same
dnPrefix value, it is sufficient to exclude the dnPrefix action-modifier in any policy
rule that references this LDAP target. The value specified in the DNPrefix for the
LDAP entry in the [Link] file is used to construct the start of the DN string.
Access-Request handling
Upon receiving an Access-Request, the Service Controller uses the primary shared
secret to validate the Message-Authenticator attribute. If the Service Controller
cannot validate the attribute with the primary shared secret, it generates a notice
message and uses the secondary shared secret.
If the Service Controller can validate the attribute, it uses the valid shared secret to
compute the Message-Authenticator attribute, and returns the attribute with the
Access-Challenge/Accept/Reject message to the client.
If the Service Controller cannot validate the attribute with the primary or secondary
shared secret, the Service Controller drops the request.
Note RADIUS does not validate the Authenticator field in Access-Request
messages.
If the Message-Authenticator attribute is not present in the Access-Request
message, the Service Controller processes the request and returns a response to
the client without a Message-Authenticator attribute.
Accounting-Request handling
Upon receiving an Accounting-Request, the Service Controller uses the primary
shared secret to validate the Authenticator field. If the Service Controller cannot
validate the field, it uses the secondary shared secret. If the Service Controller can
validate the field, and (optionally) the Message-Authenticator attribute, it uses the
valid shared secret to compute the Authenticator field in the Account-Ack message
that it returns to the client.
If the Service Controller cannot validate the Authenticator field, with the primary or
secondary shared secret, the Service Controller drops the request.
Error handling
If the Message-Authenticator attribute validation fails or If the Authenticator field
validation fails, the Service Controller generates a NTCE level syslog message
indicating the secondary shared secret is being used. This message is throttled
over a 60-second period.
4
Chapter 4
Chapter
About Diameter
Diameter is an extensible protocol derived from the RADIUS protocol and defined
by RFC 3588. It provides AAA functionality for network access and IP mobility
applications.
The Diameter protocol uses standard attributes and message sequences that
enable a single server to handle policies for many services. It is used, for example,
by the IP Multi-media subsystem (IMS) and by prepaid billing for the Multi-media
Messaging Service (MMS).
Transport protocol • Connection-oriented protocols (TCP and SCTP) • Connectionless protocol (UDP)
Server initiated • Peer to peer—re-authentication message and • Supported only if the RADIUS client
message session termination. and server support dynamic
• A server can send unsolicited messages to a authorization extensions.
client. • RADIUS is a client/server protocol that
requires the client to initiate a request.
Agent support • Relay, proxy, redirect, and translate • Implicit: the agent behaviors might be
implemented on a RADIUS Server
Error notification • Fast recovery and response when a message • Not supported
goes missing
D
E
F
G
D
E
F
Command
Command Name Description Abbreviation
Code
Accounting-Request Transmits the accounting information to the home Diameter ACR 271
Server.
Device-Watchdog- Tests the status of the transport layer during periods when DWR 280
Request no other traffic is exchanged between two peers.
Device-Watchdog- Answer Confirms reception of a DWA, to verify the transport layer DWA
connection.
Disconnect-Peer -Request Sent by a Diameter node to inform a peer that it intends to DPR 282
disconnect the transport layer.
Command
Command Name Description Abbreviation
Code
Abort-Session- Request Sent by any server to the access device that is providing ASR 274
session service, to request that the session identified by the
Session-Id be stopped.
Abort-Session- Answer Sent in response to the ASR. The Result-Code AVP must ASA
be present, and indicates the disposition of the request.
Diameter operation
This section describes the operation of the Diameter AAA application. The topics
are:
• Startup, peer discovery, and connection confirmation
• Subscriber authentication
• Accounting collection
• Peer connection termination
Subscriber authentication
Figure 18 summarizes the authentication process that is applied to a subscriber
who connects to the Diameter network.
Figure 18: subscriber authentication in a Diameter network
($37/6ZLWK;FHUWIRUGHYLFHDXWKHQWLFDWLRQ
($377/6ZLWK06&+$3YIRUVXEVFULEHUDXWKHQWLFDWLRQ
1 The Diameter AAA application authenticates the mobile device using EAP-TLS
with a X.509 certificate.
2 The Diameter AAA application authenticates the subscriber using EAP-TTLS
with MSCHAPv2. Figure 19 on page 128 shows the details of the authentication
process.
Figure 19: Details of EAP-TLS and EAP-TTLS (shaded) authentication
D
E
F
G
3 The Diameter AAA application responds with a DEA containing an EAP ‘Start’
packet.
4 The ASN gateway sends the EAP ‘Start’ packet to the mobile device.
5 The mobile device responds with an EAP Client Hello packet.
6 The ASN gateway sends a DER with the EAP Client Hello packet to the
Diameter AAA application. The Diameter AAA application validates the
message.
7 The Diameter AAA application responds with a DEA. The message includes an
EAP Server Hello packet which contains the server certificate.
8 The ASN gateway sends the EAP Server Hello packet to the mobile device.
The mobile device validates the server certificate.
9 The mobile device sends an EAP ‘Finished’ packet containing the client
certificate to the ASN gateway.
10 The ASN gateway sends a DER containing the EAP ‘Finished’ packet to the
Diameter AAA application. The Diameter AAA application validates the
message format and makes sure that the certificate is not on the CRL.
11 The Diameter AAA application responds with a DEA containing the EAP
‘Finished’ packet to the ASN gateway.
12 The ASN gateway sends the EAP ‘Finished’ packet to the mobile device. The
mobile device validates the message.
13 The mobile device sends an EAP-Response to the ASN gateway.
Note: For the EAP-TTLS Phase II only, the EAP-Response contains the
authentication information: MSCHAPv2.
14 The ASN gateway sends a DER containing the EAP-Response to the Diameter
AAA application. The Diameter AAA application:
– validates the message
– retrieves the service and QoS attributes
– allocates the HA IP address
Note: For the EAP-TTLS Phase II only, the Diameter AAA application: obtains
the user credentials from the mobile device and validates them against
the user credentials in the database.
15 The Diameter AAA application:
a retrieves the HA-RK and SPIs
b derives the MIP-RK, MN-HA-CMIP4, MN-HA-PMIP4, and FA-RK using the
derived EMSK from the EAP-TTLS CMIPv4 authentication
c creates a WiMAX session with State = Reserved
d sends a DEA to the ASN gateway with EAP-Success, MIP-RK,
MN-HA-CMIP4, MN-HA-PMIP4, FA-RK, HA-IP-Address, AAA-Session-ID,
and Session-Lifetime
16 The ASN gateway sends an EAP-Success message to the mobile device,
signalling that the session is established.
At this point the Service Controller is ready for an Accounting-Request Start from
the ASN gateway. For information about the creation and termination of accounting
session records, see "Accounting collection".
Accounting collection
Figure 20 shows the exchange of messages required to collect accounting
information after the authentication process described in "Subscriber
authentication" on page 128 and illustrated in Figure 19 on page 128.
Figure 20: AAA SC with RMS for WiMAX
$61 'LDPHWHU$$$
506
*DWHZD\ $SSOLFDWLRQ
1 The ASN gateway sends an ACR with the AVP Beginning-Session=1 that
signals the initial Acct-Start message. The Diameter AAA application validates
the message.
The AVP Acct-Multi-Session-ID contains the AAA-Session-ID that identifies the
WiMAX sessions to update in RMS. The AVP Acct-Multi-Session-ID maps the
pseudo identity to the real identity for use in the accounting records.
Start messages are sent at the beginning of a session, when a device exits idle
mode, or when a QOS parameter changes.
2 The Diameter AAA application responds with an ACA.
3 The Diameter AAA application updates the WiMAX RMS session to
State=InUse.
Note No RMS interaction occurs when the AVP Beginning-Session=0 is
present in the Acct-Start message.
4 The ASN gateway and Diameter AAA application may exchange interim
messages throughout the session.
5 The ASN gateway sends the AVP Session-Continue=0 to signal the final stop.
The AVP Acct-Multi-Session-ID contains the AAA-Session-ID that identifies the
WiMAX sessions to remove in RMS. The Diameter AAA application validates
the message format.
6 The Diameter AAA application responds with an ACA to the ASN gateway.
7 The ASN gateway sends an STR (Session-Termination-Request) message to
the Diameter AAA application.
8 The Diameter AAA application responds to the ASN gateway with an STA
(Session-Termination-Answer) message.
9 The Diameter AAA application removes the WiMAX session and releases the
resources associated with the session.
Note The Accounting Framework sends accounting information to a flat file
throughout the session.
For more information about RMS WiMAX HA sessions or RMS WiMAX subscriber
sessions, see the “Overview” chapter of the Service Controller: WiMAX Guide.
$61 6HUYLFH&RQWUROOHU
*DWHZD\ 'LDPHWHU$$$DSSOLFDWLRQ
'LVFRQQHFW3HHU5HTXHVW'35
9DOLGDWLRQ
'LVFRQQHFW3HHU$QVZHU'3$
7HUPLQDWHWKH7&3VHVVLRQ
1 The ASN gateway sends a DPR to the Diameter AAA application. The
message includes a Disconnect-Cause. The Diameter AAA application
validates the message format.
2 The Diameter AAA application responds with a DPA that includes a
Result-code. The TCP session is terminated and the associated resources are
made available.
5
Chapter 5
Chapter
Prerequisites
The Diameter AAA application requires:
• A Profile Database or LDAP database
• Solaris 10
To display the release information for the Solaris operating system that is installed
on your server:
cat /etc/release
bge0: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4>
mtu 1500 index 2 inet [Link] netmask ffffff00
broadcast [Link]
In this example, the IP address of the local Diameter Server is [Link].
To configure [Link]
The Diameter and RADIUS memory map files, [Link] and [Link],
contain the same elements and attributes, with the following exceptions:
• For Diameter environments, configure the service element using the “id” and
“type” attributes. The “type” attribute must always contain the value
“DIAMETER”, which tells the system to use a Diameter ConnectionService. For
example:
<service id=”DEFAULT” type=”DIAMETER”>
• The dal-cache element is only available for RADIUS
For more information about the elements and attributes of the [Link] file,
see the section "Configure [Link]" on page 89.
<host host="host1">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<host host="host2">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<connection-pool
max-pool-size="100"
max-wait-time="500"/>
<base-dn>ou=People,o=ptt,o=customerpcs,
dc=bridgewatersys,dc=com</base-dn>
<user-password>radiusChapPassword</user-password>
<user-filter>(&(uid={loginname})
(objectClass=spcs3guser))</user-filter>
<search-scope>2</search-scope>
<retry-interval>30</retry-interval>
<deref-alias>never</deref-alias>
</ldap-server>
<service id="DEFAULT" type=”DIAMETER”>
<vendor-attribute vendor="VendorS">
<static-attribute name="Reply-Message" value="Service
profile works with LDAP"/>
</vendor-attribute>
</service>
</radintdal>
[Link]
The [Link] file provides configuration for the Bridgewater Diameter
stack and its peers. During the installation process, the BWSwsdia package
prompts for values to all required parameters in the [Link] file.
Therefore, manual configuration is not necessary.
The [Link] file is located in the /opt/aaasc/config/dia directory.
Note This section refers to the following acronyms:
– DFN: Diameter Front Node (Bridgewater Diameter Stack), which sends and
receives messages to other Diameter peers.
– APN: Application Process Node, which processes Diameter messages.
The Diameter AAA process is an example of an APN.
– DSM: Diameter Stack Manager, which can be used to modify the
configuration of the Bridgewater Diameter stack.
This section describes each of the primary configuration parameters of the
[Link] file:
• DEBUG
• LOCAL_INFO
• DIAMETER_ TRANSPORT_INFO
• SUPPORTED_ APPLICATIONS
• SYSTEM_INFO
• REALM_INFO
• REALM_ROUTING_ TABLE
• APN_INFO
DEBUG Use the DEBUG parameter to set logging and tracing parameters.
For example:
DEBUG
{
LOG_TYPE=syslog
STATISTICS=off
TRACE=off
BUFFER=off
INFO_LEVEL1=on
INFO_LEVEL2=off
INFO_LEVEL3=off
}
LOCAL_INFO Use the LOCAL_INFO parameter to configure information about the local node,
such as its realm.
For example:
LOCAL_INFO
{
DICTIONARY_FILE=/opt/aaasc/config/dia/[Link]
NODE_ID=1
ORIG_HOST=[Link]
LOCAL_REALM=[Link]
PRODUCT_NAME=Bridgewater Systems Diameter Stack
LOCAL_APN_PORT=7888
LOCAL_APN_IP=[Link]
APN_TRANSPORT=TCP
VENDOR_ID=0
FIRMWARE_REVISION=1
}
ALLOW_UNSUPPORTED_AVPS 1=enables AVPs that are not defined in the dictionary to • 0 (default)
be sent to the peer node. • 1
Optional.
APN_TRANSPORT Transport type used between the local Bridgewater • TCP (default)
Diameter Stack and the APN (Diameter AAA application). • UDP
Optional.
LOCAL_APN_PORT Port that the Bridgewater Diameter Stack listens on for • Integer
communications with applications, such as the Diameter (0 - 65535)
AAA application.
Example: 7888
Required.
Note Enter this information during the BWSwsdia
package installation.
LOCAL_DSM_PORT Bridgewater Diameter Stack listens on this port for • Integer (0–65535)
communication with the Diameter stack management Default = 32111
module (DSM).
Optional
Note Do not modify this parameter unless the default
setting conflicts with other elements in the system.
NODE_ID A number that identifies the local Bridgewater Diameter • Integer (0–65535)
Stack.
Required.
Note Enter this information during the BWSwsdia
package installation.
}
Table 52 describes the elements of the DIAMETER_TRANSPORT_INFO
parameter.
LOCAL_TCP_PORT The Bridgewater Diameter Stack listens on this port for • Integer (0–65535)
incoming Diameter messages. Default = 3868
Required.
Note Enter this information during the BWSwsdia
package installation.
TCP_NO_OF_CONNECTION The maximum number of pending incoming requests that • Integer (0–65535)
the Bridgewater Diameter Stack can queue. Default = 10
This does not limit the number of peers that can be
configured.
Optional.
GDAM Specifies whether the application is supported over the • true (default)
Generic Diameter Application Module (GDAM). • false
Optional.
PEER_NODE
{
IP_ADDRESS=[Link]
PORT=3868
HOST_ID=[Link]
PEER_APPS=4,CreditControl
}
}
}
Table 55 describes the elements of the REALM_INFO parameter.
IP_ADDRESS • IP address of the Diameter peer, such as a network access server. • IP dot notation format
• This can contain multiple entries. Example: [Link]
• Required.
Note Enter this information during the BWSwsdia package installation.
REALM_ROUTING_ Use the REALM_ROUTING_TABLE section to specify routing information about the
TABLE destination for incoming requests.
Example:
REALM_ROUTING_TABLE
{
ENTRY
{
REALM_NAME=[Link]
ACTION=LOCAL
DESTINATION_HOST
{
APPLICATION_ID=5
DESTINATION_ID=[Link]
}
DESTINATION_HOST
{
APPLICATION_ID=3
DESTINATION_ID=[Link]
}
}
ENTRY
{
REALM_NAME=DEFAULT
ACTION=LOCAL
DESTINATION_HOST
{
APPLICATION_ID=5
DESTINATION_ID=[Link]
}
DESTINATION_HOST
{
APPLICATION_ID=3
DESTINATION_ID=[Link]
}
}
}
Table 56 describes the elements of the REALM_ROUTING_TABLE parameter.
APN_INFO Use the APN_INFO parameter to identify the Application Process Nodes on the
Diameter stack. This parameter can have multiple instances.
For example:
APN_INFO
{
APN
{
APN_ID=1
APPLICATION=5
}
APN
{
APN_ID=1
APPLICATION=3
}
}
Table 57 describes the elements of the APN_INFO parameter.
Example [Link]
DIAMETER_CONFIG_DATA
{
DEBUG
{
LOG_TYPE=syslog
STATISTICS=off
TRACE=off
BUFFER=off
INFO_LEVEL1=on
INFO_LEVEL2=off
INFO_LEVEL3=off
}
LOCAL_INFO
{
DICTIONARY_FILE=/opt/aaasc/config/dia/[Link]
NODE_ID=1
ORIG_HOST=[Link]
LOCAL_REALM=[Link]
PRODUCT_NAME=Bridgewater Systems Diameter Stack
LOCAL_APN_PORT=7888
LOCAL_APN_IP=[Link]
APN_TRANSPORT=TCP
VENDOR_ID=0
FIRMWARE_REVISION=1
}
DIAMETER_TRANSPORT_INFO
{
LOCAL_IP=[Link]
LOCAL_TCP_PORT=3868
TCP_NO_OF_CONNECTION=10
}
SUPPORTED_APPLICATIONS
{
APPLICATION_INFO
{
APP_ID=5
APP_NAME=EAP
APP_VENDOR_ID=0
APP_TYPE=AUTH
}
APPLICATION_INFO
{
APP_ID=3
APP_NAME=BASE Accounting
APP_VENDOR_ID=0
APP_TYPE=ACCT
}
}
SYSTEM_INFO
{
THREAD_COUNT=10
WATCH_DOG_TIMER=30000
}
REALM_INFO
{
REALM
{
NAME=[Link]
PEER_NODE
{
IP_ADDRESS=[Link]
PORT=3868
HOST_ID=[Link]
}
}
}
REALM_ROUTING_TABLE
{
ENTRY
{
REALM_NAME=[Link]
ACTION=LOCAL
DESTINATION_HOST
{
APPLICATION_ID=5
DESTINATION_ID=[Link]
}
DESTINATION_HOST
{
APPLICATION_ID=3
DESTINATION_ID=[Link]
}
}
ENTRY
{
REALM_NAME=DEFAULT
ACTION=LOCAL
DESTINATION_HOST
{
APPLICATION_ID=5
DESTINATION_ID=[Link]
}
DESTINATION_HOST
{
APPLICATION_ID=3
DESTINATION_ID=[Link]
}
}
}
APN_INFO
{
APN
{
APN_ID=1
APPLICATION=5
}
APN
{
APN_ID=1
APPLICATION=3
}
}
}
[Link]
[Link], located in the /opt/aaasc/config/dia-aaa directory, is the primary
configuration file for the Diameter AAA process. The system automatically
populates this file using information supplied during installation of the Diameter
AAA software package (BWSwsaaa). This file does not require configuration, but
the default settings can be modified.
For more information about [Link] parameters, see the
[Link] schema file, located in the /opt/aaasc/dia-aaa directory.
For more information about the BWSwsaaa package prompts, see the Bridgewater
Installation Reference Guide.
APNNodeID Integer (0–65535) A unique identifier for the Diameter AAA Server.
ThreadCount Integer (0–2147483647) Number of worker threads in the Diameter AAA Server.
Default = 20
SessionCount Integer (0–2147483647) The number of concurrent sessions before the Diameter AAA
Default = 2000 Server returns a failure.
Diameter AAA supports twice the value of this parameter.
SessionTimeoutInterval Integer (0–2147483647) The time, in milliseconds, that a session can be inactive before
Default = 30000 timing out.
HealthCheckTimer Integer (0–2147483647) How often, in milliseconds, the Diameter AAA Server exchanges
Default = 30000 health check messages with the Diameter Stack to detect
connection errors.
ConnectionTimer Integer (0– 2147483647) How often, in milliseconds, the Diameter AAA Server checks the
Default = 10000 connection to the Diameter Stack when the connection is lost.
MaxBuffersInPool Integer (0–2147483647) The maximum number of buffers in the memory pool.
Default = 50000
EnableStatistics • true True: enable counters for all incoming and outgoing messages.
• false
ID Integer (0 to 65535) A unique identifier for the Diameter Stack (Diameter Front Node).
Example [Link]
<DiameterAAA xmlns:xsi="[Link]
xsi:noNamespaceSchemaLocation="/opt/aaasc/dia-aaa/[Link]">
<Debug>
<EnableTrace>false</EnableTrace>
<LogLevel>1</LogLevel>
</Debug>
<LocalInfo>
<OriginHost>[Link]</OriginHost>
<OriginRealm>[Link]</OriginRealm>
<LocalIP>[Link]</LocalIP>
<APNNodeID>2</APNNodeID>
</LocalInfo>
<SystemInfo>
<ThreadCount>20</ThreadCount>
<SessionCount>2000</SessionCount>
<SessionTimeoutInterval>30000</SessionTimeoutInterval>
<HealthCheckTimer>30000</HealthCheckTimer>
<ConnectionTimer>10000</ConnectionTimer>
<MaxRetry>2147483647</MaxRetry>
<RetransmitTimer>5000</RetransmitTimer>
<MaxBuffersInPool>50000</MaxBuffersInPool>
<EnableStatistics>false</EnableStatistics>
</SystemInfo>
<DFNConfig>
<DFN>
<IPAddress>[Link]</IPAddress>
<Port>7888</Port>
</DFN>
</DFNConfig>
</DiameterAAA>
TLSPolicy
The TLSPolicy file is used by EAP-TTLS phase 2 authentication to evaluate the
inner subscriber identity. Configure policy rules for Diameter using the TLSPolicy
file located in the /opt/aaasc/config/dia-aaa directory.
For more information about configuring TLSPolicy and about supported actions and
modifiers, see "TLS request actions" on page 254, and see the chapter “EAP in
AAA policies”, in the Extensible Authentication Protocol Guide.
Note For information about configuring EAP-TTLS phase 2 proxy to a RADIUS
server, see "Configuring Diameter EAP-TTLS phase 2 proxy to RADIUS
AAA" on page 158.
accessReqPolicy
The accessReqPolicy for Diameter is located in /opt/aaasc/config/dia-aaa/
accessReqPolicy.
For example:
User-Name ContainsCI AM_1 WiMAXLocalAA EAP-Policy=TTLS-AM_1
User-Name ContainsCI eapuser_1 WiMAXLocalAA service=EAPUSER_1
- - - WiMAXLocalAA
For more information about configuring acctReqPolicy and about supported actions
and modifiers, see "Access request actions" on page 240.
acctReqPolicy
The acctReqPolicy for Diameter is located in /opt/aaasc/config/dia-aaa/
acctReqPolicy.
For example:
- - - WiMAXLocalAcct
For more information about configuring acctReqPolicy and about supported actions
and modifiers, see "Accounting request actions" on page 246.
[Link]
The [Link] file located in the /opt/aaasc/config directory contains the RMS
connection information. Insert this line at the end of the [Link] file:
0 <rms_server_ip> 34501 MYSECRET - - - 5 - -
[Link]
Configure the [Link] file located in the /opt/aaasc/config/dia-aaa directory for
EAP-TLS, EAP-AKA, or EAP-TTLS authentication.
Provision the client (application or mobile device) with the CA certificate file that
signed the server (Service Controller) certificate. The CA certificate file is used by
the client to validate the server certificate during EAP-TLS/EAP-TTLS
authentication.
For more information about the elements and attributes used in the examples
shown in this section, see the chapter “EAP configuration” in the Extensible
Authentication Protocol Guide.
This section provides the following examples and configuration information:
• Settings shared by EAP-TLS and EAP-TTLS
• Settings specific to EAP-TLS
• Settings specific to EAP-TTLS authmode 1
• Settings specific to EAP-TTLS authmode 4
• Settings for EAP-AKA
• Configuring Diameter EAP-TTLS phase 2 proxy to RADIUS AAA
Settings shared by This example shows an [Link] file that is configured for either EAP-TLS or
EAP-TLS and EAP-TTLS authentication. These settings are common to both types of
EAP-TTLS authentication.
<eap-configuration
timeout="10"
certificate-directory="/opt/aaasc/config/dia-aaa"
dh-file="[Link]">
<cache-setting/>
<certificate
certificate-name="serverCert"
verification-depth="2"
certificate-file="[Link]"
private-key-file="[Link]"
private-key-password="serverkey"
ca-list-file="calistfile"
Settings specific to This example shows an [Link] file that is configured to use EAP-TLS to test
EAP-TLS WiMAX authmode 2 "Device authentication". This example builds on the settings
displayed in "Settings shared by EAP-TLS and EAP-TTLS" on page 155.
<tls-setting
setting-name="mytls"
certificate="serverCert"
fragment-size="2048"
require-client-certificate="Always"/>
<type-selection-policy
policy-name="default"
tls-setting="mytls">
<eap-tls/>
</type-selection-policy>
In particular, for EAP-TLS functionality:
• set require-client-certificate=”Always” so that the server and the client
exchange certificates
• set policy-name="default" so that the EAP policy is applied to the DER
message
• list eap-tls within the type-selection-policy element so that this policy performs
EAP-TLS authentication
Settings specific to This example shows an [Link] file that is configured to use EAP-T’TLS to test
EAP-TTLS WiMAX authmode 1 "User authentication". With authmode 1 the subscriber is
authmode 1 authenticated during EAP-TTLS/MSCHAPv2 phase 2. This example builds on the
settings displayed in "Settings shared by EAP-TLS and EAP-TTLS" on page 155.
With EAP-TTLS, the server must send a certificate to the client and the client may
optionally respond with a certificate. If the client does not provide a certificate,
EAP-TTLS phase 2 is implemented and the subscriber is authenticated using
MSCHAPv2.
<tls-setting
setting-name="myttls"
certificate="serverCert"
fragment-size="2048"
require-client-certificate="Never"/>
<type-selection-policy
policy-name="default"
tls-setting="myttls">
<eap-ttls/>
</type-selection-policy>
Settings specific to This example shows an [Link] file that is configured to use EAP-TTLS to test
EAP-TTLS WiMAX authmode 4 "Single EAP device and subscriber authentication". This
authmode 4 example builds on the settings displayed in "Settings shared by EAP-TLS and
EAP-TTLS" on page 155.
The server and client exchange certificates to authenticate a device during
EAP-TTLS phase 1.
A subscriber is authenticated during EAP-TTLS/MSCHAPv2 phase 2 using TLS
tunneled subscriber name and password attributes. The TLS tunnel is established
during EAP-TTLS phase 1.
<tls-setting
setting-name="myttls"
certificate="serverCert"
fragment-size="2048"
require-client-certificate="Always"/>
<type-selection-policy
policy-name="default"
tls-setting="myttls">
<eap-ttls
force-phase-2="Y"/>
</type-selection-policy>
In particular, for EAP-TTLS authmode 4 functionality:
• set require-client-certificate=”Always” so that the RADIUS Server requests a
client certificate from the client.
• set policy-name="default" so that the EAP policy is applied to the DER
message
• list eap-ttls within the type-selection-policy element so that this policy performs
EAP-TTLS authentication
• set force-phase-2=”Y” so that EAP-TTLS phase 2 authenticates the subscriber
using MSCHAPv2 subscriber name and password credentials. If this is not
specified or is set to "N" and a client certificate is presented during phase 1,
phase 2 is skipped.
Settings for EAP-AKA This example shows a section of the [Link] file specific to EAP-AKA:
<eap-configuration>
<type-selection-policy policy-name="AKA">
<eap-aka identity-exchange-supported=”Y”/>
</type-selection-policy>
</eap-configuration>
Note For more information about the elements and attributes used in the
examples shown in this section, see the chapter “EAP configuration” in the
Extensible Authentication Protocol Guide
Configuring Diameter The Diameter AAA application can provide EAP-TTLS phase 2 client authentication
EAP-TTLS phase 2 (using MSCHAPv2) proxy to a remote RADIUS AAA.
proxy to RADIUS AAA This section provides the following overview information and configuration
procedures:
• Diameter/RADIUS Translation Agent
• Diameter proxy to RADIUS AAA message flow
• To enable Diameter EAP-TTLS phase 2 proxy to RADIUS AAA
• To configure accessReqPolicy
• To configure [Link]
• To configure TLSPolicy
• To configure [Link]
Note Diameter EAP-TTLS only supports MSCHAPv2 as a phase 2 client
authentication method. If the Diameter AAA application detects a method
other than MSCHAPv2, it returns a DEA with
Result-Code=DIAMETER_AUTHENTICATION_REJECTED.
Note The Diameter AAA application only supports one RADIUS AAA target.
Translation Description
DER to Access-Request • The Diameter AAA application translates MSCHAPv2 Diameter AVPs
• EAP-TTLS Phase 2 Client Authentication (embedded in the EAP-Payload AVP) to MSCHAPv2 RADIUS
(using MSCHAPv2) DER to Access-Request attributes.
Access-Reject to DEA • If the RADIUS AAA returns an Access-Reject, the Diameter AAA
• RADIUS MSCHAPv2 Access-Reject application sends the client a DEA with
Response to DEA Result-Code=AUTHENTICATION_REJECTED.
'LDPHWHU 5HPRWH
&OLHQW
6HUYLFH&RQWUROOHU 5$',86$$$
'(5
($377/63KDVH
'($
'(5
$FFHVV5HTXHVW
($377/63KDVH
5$',86UHVSRQVH
'($
For a complete message flow, see the chapter “EAP-TTLS” in the Extensible
Authentication Protocol Guide.
To configure accessReqPolicy
Add the WiMAXLocalAA action with the EAP-Policy modifier.
Make sure EAP-Policy is the same value as the policy-name in [Link].
For example:
- - - WiMAXLocalAA EAP-Policy="ttlspolicy"
To configure [Link]
1 Configure [Link], located in /opt/aaasc/config/dia-aaa. In the
type-selection-policy section, specify a value for policy-name to match the
value of the EAP-Policy modifier used in the accessReqPolicy.
For example:
<type-selection-policy policy-name="ttlspolicy">
2 In the eap-ttls section, specify a value for authentication-policy such as
TLSPolicy.
For example:
<eap-ttls
tls-setting="mytls"
session-resumption-timeout="600"
authentication-policy="TLSPolicy"
force-phase-2="Y"/>
Note If no value for authentication-policy is specified, the Diameter AAA
application performs phase 2 client authentication locally.
For more information about [Link], see the chapter “EAP configuration” in the
Extensible Authentication Protocol Guide.
To configure TLSPolicy
In the TLSPolicy file, located at /opt/aaasc/config/dia-aaa add the TLSProxyAA
action.
TLSProxyAA specifies that the Diameter AAA application proxies phase 2 client
authentication (using MSCHAPv2) to a RADIUS AAA. For example:
- - - TLSProxyAA
Note Use the -p option in the Diameter startup script when using TLSProxyAA. -p
configures the number of proxy threads. For more information, see "To
enable Diameter EAP-TTLS phase 2 proxy to RADIUS AAA".
The following example shows policies configured for Diameter EAP-TTLS phase 2
proxy to a RADIUS server. This example includes local authorization modifiers in
TLSPolicy that override instances of these same modifiers in the accessReqPolicy:
accessReqPolicy:
- - - WiMAXLocalAA EAP-Policy=ttlspolicy
authorizeLoginName=rep authorizeDomain=[Link]
TLSPolicy:
- - - Inner-User-ID EndsWith [Link] TLSProxyAA
authorizeLoginName=innerRep authorizeDomain=[Link]
outageRejectMessage="Remote RADIUS server is unresponsive"
In this example, in phase 2 of EAP-TTLS:
• if the Diameter AAA application receives an Access-Accept, it uses
innerRep@[Link] to perform the authorization.
• if the RADIUS AAA does not respond, the Diameter AAA application rejects the
subscriber with a DEA including Reply-Message="Remote RADIUS server is
unresponsive" and
Result-Code=DIAMETER_AUTHENTICATION_REJECTED.
To configure [Link]
1 Configure the RADIUS proxy target using [Link], located in /opt/aaasc/
config/dia-aaa.
For example:
<APIConfiguration>
<STSServers>
<Server Address="[Link]" Port="1234"
Secret="secret1" MaxRetries="1" RequestTimeout="2"/>
</STSServers>
</APIConfiguration>
2 Send the Diameter AAA application a HUP signal for the changes to
[Link] to take effect:
pkill -HUP diaaaad
Note The Diameter AAA application only supports one RADIUS proxy target.
Table 60 describes the [Link] elements and attributes.
Secret String The secret shared between the Diameter AAA application and the RADIUS
proxy target.
Attribute of Server.
Required.
MaxRetries Integer The maximum number of attempts to retransmit proxy messages to the
(0–65535) RADIUS AAA target.
Default = 1 Attribute of Server.
Optional.
RequestTimeout Integer The time, in seconds, to wait for a response from the RADIUS AAA target.
(1–65535) Attribute of Server.
Default = 2 Optional.
To configure reauthentication
Provision a value for a subscriber’s session timeout in one of the following ways:
• Use the diaaaad command line option to provision a value for
WiMAXReAuthenticationInterval. The Service Controller returns this
provisioned value to the ASN in the attribute Session-Timeout.
– Navigate to /opt/aaasc/config/dia-aaa
– Open the file diaaaa and in the “start-line” add the argument -q 1800
– Restart Diameter:
/etc/init.d/diaaaa stop
/etc/init.d/diaaaa start
• For LDAP database deployments, modify the file [Link] as follows:
– Within the element <static-attribute> add a “name” attribute and specify a
value of “Session-Timeout”. Add a “value” attribute and provision a value in
seconds (valid range 300-302400 seconds, default=1800). For example:
<static-attribute name="Session-Timeout" value="1800"/>
For more information about configuring “[Link]”, see "Example
[Link] file" on page 136.
Note If a value for “Session-Timeout” is not provisioned in the file [Link]
or specified as a diaaaad command line option, the Service Controller uses
a default value of 1800 seconds.
6XEVFULEHU
GHYLFHV 'LDPHWHU6HUYLFH&RQWUROOHU
The Diameter AAA application (APN) uses a LIFO (last-in-first-out) message queue
to receive all ingress messages. With the congestion control mechanism, the
ingress message queue is initialized to two times the expected peak rate of traffic
and the message queue is divided into three sub-ranges: green, orange, and red.
Figure 24: Message queue size and system congestion state sub-ranges
0HVVDJHTXHXH
VL]HLQLWLDOL]HGWRWZRWLPHVWKHH[SHFWHGSHDNUDWHRIWUDIILF
SHDNUDWHFRQILJXUHGLQGLDDDDGFRPPDQGOLQH
GLYLGHGLQWRWKUHHVXEUDQJHV
*UHHQVL]H RQHVHFRQGRIWKHSHDNUDWHRIWUDIILF
2UDQJHVL]H KDOIDVHFRQGRIWKHSHDNUDWHRIWUDIILF
5HGVL]H KDOIDVHFRQGRIWKHSHDNUDWHRIWUDIILF
6\VWHPFRQJHVWLRQVWDWH
*UHHQ±6HUYLFH&RQWUROOHULQQRUPDORSHUDWLRQDOVWDWH
2UDQJH±6HUYLFH&RQWUROOHULVFRQJHVWHG
5HG±6HUYLFH&RQWUROOHULVFULWLFDOO\FRQJHVWHG
Accounting records
The Diameter AAA application injects the Accounting-Realtime-Required AVP with
the value set to GRANT_AND_LOSE in all ACA Start messages returned to the
client to indicate to the client to grant service to the subscriber even if the client
cannot deliver accounting records or store accounting records locally.
Note Bridgewater Systems recommends that the Access Node (NAS, ASN-GW)
support the Accounting-Realtime-Required AVP, but support for the
Accounting-Realtime-Required is not required.
Option Description
-i HA IP address.
Option Description
-p The number of proxy response threads and indicates to the diaaaad process to load
[Link].
Add the -p option to the diaaaad process to enable Diameter EAP-TTLS phase 2 proxy
to RADIUS AAA.
If -p is not present, Diameter EAP-TTLS phase 2 proxy to RADIUS AAA is disabled.
-P Enables the LDAP attribute that is used, to store the password for device authentications
by a WiMAXLocalAA action. An example value for the device password is:
abcMobileChapPassword.
Note This option must be used together with options -f and -n.
-q The Session-Time-Out value, in seconds. This value determines the time after which a
subscriber’s session expires and Diameter performs reauthentication.
Default=1800
-r The client request retransmit timeout, in seconds, which the Diameter AAA application
uses to determine the age of a message, relative to the retransmit timeout configured on
the Diameter client.
-r must be the same as the retransmit timeout configured on the Diameter client.
The timeout on the client indicates the time after which the client retransmits a request to
the Service Controller.
Range=1-30
Default=5 seconds.
-t N The number of worker threads to run. For information about calculating the required
number of threads, see the Bridgewater Installation Reference Guide.
Default = 10
Option Description
-Z The expected peak rate of messages per second on the Diameter AAA application.
When the congestion control mechanism is enabled the Diameter AAA application’s
ingress message queue is initialized to twice the value specified by the -Z option.
Range=1-10000
Default=1500.
Example:
diaaaad -C /opt/aaasc/config -s [Link] -o [Link]
-r 5 -i [Link]
Diameter logging
This section describes:
• Log messages
• Debug messages
Log messages
By default, operational and system log messages for the Diameter AAA application
are written to /var/adm/messages using the Logging Framework with the family
names AAAOP and AAASYS. The system reports Bridgewater Diameter Stack
syslog messages using the DIA log family.
To view a specific log message:
/opt/aaasc/logf/bwslogd -f family -n number
To view all Diameter AAA operational log messages:
/opt/aaasc/logf/bwslogd -f AAAOP
For details, see the Service Controller: Monitoring and Logging Guide.
Debug messages
Configure debug messages for the Diameter AAA application using the
[Link] file, and for the Bridgewater Diameter Stack using the
[Link] file.
Debug messages for Configure debug messages for the Diameter AAA application using the
the Diameter AAA [Link] file, located in /opt/aaasc/config/dia-aaa/.
application The following example shows how to enable debug logs, display all debug
messages, and send the debug messages to syslog. For more information about
debug parameters for the Diameter AAA application, see the [Link]
schema file, located in /opt/aaasc/dia-aaa.
Example [Link]
<Debug>
<EnableDebugging>true</EnableDebugging>
<LogLevel>3</LogLevel>
<EnableConsoleLog>false</EnableConsoleLog>
</Debug>
Debug messages for Configure Debug messages for the Bridgewater Diameter Stack using the
the Bridgewater [Link] file, located in /opt/aaasc/config/dia.
Diameter stack The following example shows how to enable debug logs, provide only high priority
logs, and send log messages to syslog.
For more information about configuring debug messages for the Bridgewater
Diameter Stack, see "DEBUG parameters" on page 139.
Example [Link]
DEBUG
{
LOG_TYPE=syslog
STATISTICS=off
TRACE=on
BUFFER=off
INFO_LEVEL1=on
INFO_LEVEL2=off
INFO_LEVEL3=off
}
Diameter troubleshooting
Protocol errors refer to problems with the underlying protocol that carries Diameter
messages, for example, incorrect routing information or temporary network failure.
Application errors result from the failure of the Diameter protocol.
Error codes
The Diameter protocol shares the same semantics of error code definition as the
HTTP protocol. The return status of a message is identified by the first digit of the
return code:
1xxx—the request cannot be satisfied and additional information is required for the
service to be granted.
2xxx—the request was processed successfully.
3xxx—there was a protocol error when transmitting a Diameter message.
Generally, a Diameter proxy should try to fix this problem by either routing the
message to another Diameter server, or by keeping the message in a local cache
and sending it again later.
4xxx—the requested message cannot be satisfied at the moment, but it might work
in the future. An example is a server that temporarily lacks physical storage space
to handle any incoming requests.
5xxx—there was an application error when the server was processing the request
message. The sender should not try to send the same message again. Instead, the
sender will have to determine the cause of the application error by checking the
error code, and then fix the problem.
Syntax errors
Use the following utility to determine the cause of a problem with the syntax of an
XML configuration file:
/bin/xmllint <xml_config_file>
where:
<xml_config_file> is the name of the file with the problem
6
Chapter 6
Chapter
dictionaries
This chapter describes how to manage RADIUS and Diameter dictionary files, and
how to configure the files that support the RADIUS and Diameter dictionary
processes.
The topics are:
• Managing RADIUS dictionaries (.DICT)
• Configuring vendor-specific data ([Link])
• Managing Diameter dictionaries
.DICT files
The RADIUS dictionary consists of a set of vendor dictionary files stored as .DICT
files. There is a .DICT file for each NAS vendor. The .DICT file for a vendor lists the
attributes supported for that NAS vendor, including RFC 2865, and vendor-specific
attributes, including TS29.061 GSM attributes.
Table 63 shows the .DICT file parameters.
<code>
<code>
<type>
<encryptionType>
<direction>
<value-name>
<value-code>
<sub-type-name>
<sub-type-code>
<type>
SUBTYPE_VALUE <name>
<sub-type-name>
<sub-type-code>
<type>
BITSET <attribute-name>
<sub-type-name>
<bitset-code>
<value>
STARENT and CISCO There are two versions of the STARENT and CISCO dictionaries. [Link]
dictionaries and [Link] use VSAs with the prefix SN1 and use a standard decoder.
[Link] and [Link] use a custom Starent decoder.
These two dictionaries store the vendor-type field in 2 bytes instead of the standard
1 byte. This allows more than 255 VSAs to be defined for a specific vendor.
During installation of the Service Controller and SDB, the installer must determine
which version of the dictionay to use.
When the BWSaaaco or BWSwsco RPMs or packages are upgraded, be sure to
update the dictionaries in both locations, /opt/aaasc/config/dictionaries and /
WideSpan/config/dictionaries. If the VSAs are not present in both of the
dictionaries, requests are ignored.
Tunnel attributes in Tunnel attributes, such as Tunnel-Type, only display in the Service Manager GUI if
RADIUS dictionaries they are active in the appropriate vendor dictionary. As Figure 25 shows, you
activate a tunnel attribute by adding the modifier “=#T” to a specific attribute’s
value-name.
Typically, these attributes are active upon installation. If they are not, modify the
appropriate tunnel attributes in the vendor dictionary using the format:
Tunnelattribute RADIUSattributenumber Value-name=#T
where
Tunnelattribute is the attribute being activated, such as Tunnel-Type
RADIUSattributenumber is the RFC 2865 number associated with the attribute
Value-name is the type of value required, such as integer
=#T is the modifier that activates the attribute
Figure 25: Active Tunnel attributes in a RADIUS vendor dictionary
Field Description
Field Description
type The type of data subscribers input for the attribute. The format is
specified in the brackets:
• string (1–255 alphanumeric characters)
• integer (1– 2,147,483,647)
• integer8 (1–255)
• integer16 (1– 65,535)
• integer64 (0–18,446,744,073,709,551,615)
• ipaddr (an IP address in standard notation, with maximum values of
[Link])
• ipv6addr (an IP address in IPv6 notation)
• octetstring
Note An octetstring is composed of one or more sub-types, also known
as sub-attributes. Sub-types are defined in the dictionary using
SUBTYPE entries. Enumerated values for sub-types can be
defined using the SUBTYPE_VALUE entries.
encryption The type of encryption used to encrypt and decrypt the attribute.
Type There are three encryption types:
• rfcmd5
• saltmd5
• none
By default, rfcmd5 encryption is used for the User-Password,
Acc-MN-HA-Secret and CDMA2000-Pre-Shared-Secret attributes.
Saltmd5 encryption is used for the Tunnel-Password attribute.
multiplexity Specifies if the attribute can be defined once or multiple times for the
NAS vendor.
The options are:
• single
• multi
The .DICT file also includes lists of enumerated values for the RFC 2865 and
vendor-specific attributes. Enumerated values set options for the attributes that
display in the Service Manager interface when creating a connection service profile.
Only the values specified in the dictionary file are available as options for the
attribute. The enumerated values for the RFC 2865 attributes follow the list of RFC
2865 attributes and the enumerated values for vendor-specific attributes for the list
of attributes for each vendor.
Table 65 lists the enumerated value fields.
Field Description
value-name Possible value for the attribute. This value displays as an option on the
connection service form in the Service Manager when creating a
connection service profile.
A list of the possible values for an attribute is supplied by the NAS
vendor.
Field Description
Field Description
Field Description
# IPv6 attributes
ATTRIBUTE NAS-IPv6-Address95ipv6addrnoneinsingle
ATTRIBUTEFramed-Interface-Id96ipv6addrnonebothsingle
ATTRIBUTEFramed-IPv6-Prefix97ipv6addrnonebothmulti
# ==================
# Enum Value Section
# ==================
# VALUE <attribute-name> <value-name>
<value-code>
# =================================
# Vendor Specific Attribute Section
# =================================
# START-VSA [<vendor-code>] [<VSA-coder>]
# ATTRIBUTE ...
# Aptis VSAs
START-VSA 2637 APTIS
# =================================
# Octetstring Sub-Type Section
# =================================
# SUBTYPE <attribute-name> <sub-type-name> <sub-type-code>
<type>
#3GPP2-Service-Option-Profile
SUBTYPE 3GPP2-Service-Option-Profile Max-Svc-Connections
1000 integer
SUBTYPE 3GPP2-Service-Option-Profile Svc-Option-Prf-Code
1001 integer8
SUBTYPE 3GPP2-Service-Option-Profile
Max-Svc-Option-Instances 1002 integer8
BITSET3GPP2-Remote-Addr-Table-IndexQualifier0
Exempt-from-PrePaid-accounting
BITSET3GPP2-Remote-Addr-Table-IndexQualifier1
Summarize-Remote-Addr-Octet-Count
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
...
/opt/aaasc/custom_dict/VENDOR_NEW.DICT
Note: If an attribute is listed in multiple DICT files, the attribute definition in
the last file referenced in /opt/aaasc/config/dictionaries takes
precedence.
8 After adding a new vendor to a RADIUS dictionary, add the new vendor to the
RADIUS ConnectionService of the root Service Classes:
Note The following procedures assume familiarity with launching
entity-specific edit forms from the Service Manager main window. For
more information, see Service Manager: Getting Started Guide for
AAA.
a Open the Service Manager and select the Service tab.
b In the left pane of the Service tab, select the Root Organization.
c Launch the RADIUS ConnectionService Service Class edit form.
d On the Service Profile tab, add the new vendor name to the end of Data
field, separated from the previous dictionary by a semi-colon.
e Click Update.
9 To finalize the dictionary changes, stop and restart the Provisioning server:
/etc/init.d/wsprovs stop
/etc/init.d/wsprovs start
Check the log files to see changes to each attribute that is being merged. For
example:
Jul 31 11:14:36 ewn-anaaa radiusd[486]: [ID 819157
[Link]] NTCE RADSYS(15) HUP signal detected:
reloading configuration data...
properly with the modified “inbound” or “both” attributes. Note that radpet does
not test “inbound” attributes.
a Log in as the aaasc user.
b Run the RADIUS Policy Engine Test utility:
/opt/aaasc/radius/radpet -i client-IP -t packet-type -c
dal_conf -d RADIUS_conf attr=val
where
client-IP is the IP address of the NAS or RADIUS Server
packet-type is either auth (access-request) or acct (accounting-request)
dal_conf is database configuration file (default /opt/aaasc/config/[Link])
RADIUS_conf is RADIUS configuration directory (default /opt/aaasc/radius/
config)
attr=val is one or more attribute-value pairs
For example, send the message:
/opt/aaasc/radius/radpet -i [Link] -t auth -c /
opt/aaasc/conf/[Link] -d /opt/aaasc/config/radius
User-Name=Jean
c Verify that the modified dictionary attributes are handled without error.
The new vendor attributes are available for use. Use the Service Manager to add
the attribute(s) to any applicable RADIUS connection service profiles. For
information about editing service profiles, see the Service Manager: Subscriber
Provisioning Guide.
[Link] overview
Use the [Link] file to define:
• the RADIUS or Diameter attributes, received in a RADIUS Access-Request
message from a NAS, or a Diameter DER message from an ASN, that
comprise a unique port ID
• the RADIUS or Diameter attributes to write to accounting records when a
RADIUS accounting-stop or interim-accounting message, or Diameter ACR is
received, to store service usage data, and to generate correlated accounting
records
The [Link] file is created at installation and includes vendor entries for major
NAS and ASN vendors for the RADIUS and Diameter Server. Every NAS and ASN
vendor must have an entry in the [Link] file. A default vendor and model can
be specified in the [Link] file.
To store the MDN in the Class Attribute, the [Link] file must be configured to
support the Class Attribute, and the Class Attribute must be specified in the
AcctRecord Attributes field. For more information, see "Configuring SIP Server
Interworking" on page 67.
Attribute
Attribute
SupportedEAPTypes
EAPType
LockoutConfig
StoredSession Attributes
Attribute
ValidateEquipID
WLAN
APN2WAPN
VendorConfiguration The root element that encloses optional Vendor entries. If no Vendor elements are
defined, the DefaultVendor attribute must be specified.
For example:
<VendorConfiguration DefaultVendor=”RFC2138”>
<Vendor ... />
</VendorConfiguration>
DefaultVendor String The active Vendor entry to use for unidentified NASs or ASNs. Optional.
Default (RADIUS) =
RFC2138
Default (Diameter) =
SAMSUNG
DefaultModel String The active Vendor entry to use, in conjunct with the DefaultVendor, for
unidentified NASs.
Optional.
Vendor A NAS vendor, based on a vendor name and model name. The VendorName and
ModelName combination must be unique. If no Vendor elements are defined, the
DefaultVendor attribute must be specified in the VendorConfiguration root element.
This element may enclose these optional child element:
• PortIDAttributes
• SessionIDAttributes
• SessionRecoveryAttributes
• AcctRecordAttributes
• AcctStartAttributes
• AcctStopAttributes
• Attribute
• SupportedEAPTypes
• EAPType
• LockoutConfig
• StoredSessionAttributes
• ValidateEquipID
All attributes are optional except VendorName.
Child element of the VendorConfiguration.
For example:
<Vendor VendorName=”USR” DuplicateDetection=”N”>
<PortIDAttributes ... />
<SessionRecovery Attributes ... />
<AcctRecordAttributes ... />
<AcctStartAttributes ... />
<AcctStopAttributes ... />
<SupportedEAPTypes ... />
</Vendor>
VendorName String (1 to 20 Name of the NAS vendor. Must match the vendor name selected for NASs in the
characters) Service Manager.
Required.
ModelName String (1 to 20 Defines a NASmodel for each vendor. Must match the vendor model selected for
characters) NASs in the Service Manager.
If this attribute is not set, the entry applies to all models for the specified NAS
vendor.
Optional.
ClassAttribute • Y (default) The NAS supports the use of the RADIUS Class attribute.
• N Set to Y for:
• SIP Server Interworking. For more information, see "Configuring SIP Server
Interworking" on page 67.
• Prepaid data support. For more information, see "Configuring user and network
lockout" on page 38.
• CDMA2000 max sessions access control support
• Generating Correlation ID. For more information, see "Configuring
vendor-specific data ([Link])" on page 189.
• IS835-C prepaid support
If the NAS does not support the Class attribute, it uses a RADIUS Session ID. The
Resource Management Server deletes idle sessions.
Set to Y if devices (NAS/PDSN) that support the Class attribute are in use.
Set to N if devices that do not support the Class attribute are in use.
MultipleClass • Y Set to “Y” to support multiple instances of the class (25) attribute.
Attributes • N (default) This attribute only accepts a value of “Y” when the attribute
UseBWSClassEncoding is set to “Y”.
MaxAttribute If The maximum segment size for segmented class (25) attributes before applying
SegmentSize Base64ClassAttrib additional encoding.
ute is enabled:
• 126 (default)
• 64–126
Otherwise:
• 253 (default)
• 64–253
UseBWSClass • Y (default) Enables RADIUS to send a NAS device a non-encoded value for the Class
Encoding • N attribute. The non-encoded value can only be configured in the Service Manager
GUI or in the [Link] file.
For information about using the Service Manager GUI, see the section “RADIUS
Connection Services” in the Service Manager: Services Provisioning Guide for AAA
For information about configuring the [Link] file, see "Configure
[Link]" on page 89.
Set to “N” if the NAS device needs to receive and interpret a non-encoded value for
the Class attribute.
Note Only set to “N” for authorization-only devices. Setting
UseBWSClassEncoding to “N” for a device that sends authorization and
accounting requests prevent accounting features that rely on encoded Class
data from working.
These accounting features are disabled if set to “N”:
• IS-835C prepaid support (not available)
• DNS updates via RADIUS (not available)
• CDMA based SSR sessions (won’t include PP-Rating-Type)
• CDMA based subscriber session limits using RMS (not available)
• Class data returned from a remote’s Access-Accept (are not forwarded to the
client)
• proxy accounting (accounting requests are not forwarded to proxy targets)
These accounting features work differently or need modification if set to “N”:
• subscriber entity ID (not stored in the Class attribute). The Service Controller
performs database lookups for Acct-Interim and Stop requests to complete the
accounting record.
• Pending correlation (include SessionIDAttributes in [Link])
• Dial-up based subscriber session limits (configure SessionIDAttributes in
[Link] so RADIUS can create a session in the Resource Management
Server)
Duplicate • Y The RADIUS Server uses the Request-Identifier attribute, in addition to IP Address
Detection • N (default) and port, to detect duplicate requests, as described in the RADIUS-v2 RFC.
• Set to Y for most NAS vendors.
• Set to N for Redback NASs.
Note Also configure the DuplicateDetection element in [Link] to enable
the RADIUS Server to process duplicate request messages. For more
information, see "DuplicateDetection" on page 17.
PortID • Y (default) The PortID is required by the RADIUS Server for the NAS.
Mandatory • N
ServiceClass String (1–80 The service class name to be used for connection services.
Selection characters)
AccessControl • Y (default) An access control service class is used for this NAS vendor and model.
Enabled • N Set to Y for most NAS vendors.
AccessControl String (1–80 The service class name to use for access controls.
ServiceClass characters) This parameter is used only if AccessControlEnabled is set to Y.
Default =
AccessControl
WriteAcct • Y Specifies whether or not the RADIUS Server writes an accounting-pending record
PendingRecord • N when it authenticates a session.
Set this attribute to Y.
By default, no accounting record is written.
WriteAcctStart • Y The RADIUS Server writes an accounting-start record when a session starts. If this
Record • N attribute is not specified, the accounting record is written only if its backup method
is ‘C’ (collate). Otherwise, an accounting record is not written. If writing a record of
type ACCT-START is enabled, a valid value must be specified.
Optional.
WriteAcctStop • Y Specifies whether or not the RADIUS Server writes an accounting-stop record
Record • N when a session ends.
WriteAcct • Y (default) The RADIUS Server writes interim accounting records when it receives interim
InterimRecord • N accounting messages from the NAS.
AcctTunnelStart Integer (0– A positive integer value to be written for a record of type ACCT-TUNNEL-START.
RecordType 2147483647) This value is written only if WriteAcctTunnelStartRecord is enabled.
Default = 9
AcctTunnelStop Integer (0– A positive integer value to be written for a record of type ACCT-TUNNEL-STOP.
RecordType 2147483647) This value is only written if WriteAcctTunnelStopRecord is enabled.
Default = 10
AcctTunnel Integer (0– A positive integer value to be written for a record of type ACCT-TUNNEL-REJECT.
Reject 2147483647) This value is only written if WriteAcctTunnelRejectRecord is enabled.
RecordType Default = 11
AcctTunnel Integer (0– A positive integer value to be written for a record of type
LinkStart 2147483647) ACCT-TUNNEL-LINK-START. This value is only written if
RecordType Default = 12 WriteAcctTunnelLinkStartRecord is enabled.
AcctTunnel Integer (0– A positive integer value to be written for a record of type
LinkStop 2147483647) ACCT-TUNNEL-LINK-STOP. This value is only written if
RecordType Default = 13 WriteAcctTunnelLinkStopRecord is enabled.
AcctTunnelLink Integer (0– A positive integer value to be written for a record of type
RejectRecord 2147483647) ACCT-TUNNEL-LINK-REJECT. This value is only written if
Type Default = 14 WriteAcctTunnelLinkRejectRecord is enabled.
AcceptBadAcct • Y Specifies whether or not the RADIUS Server accepts accounting-request messages
Authenticator • N (default) with bad Authenticator values.
For most NAS vendors, set this value to N. In this case, the RADIUS Server silently
discards the accounting-request.
Set this parameter to Y only if a specific NAS vendor is known to calculate the
authenticator field incorrectly. In this case, the RADIUS Server treats an
accounting-request like a valid accounting-request. This poses a security risk. This
also causes a discrepancy in SNMP accounting metrics: Response and
BadAuthenticator metrics are both incremented.
If the RADIUS Server receives an Accounting-Request message with a bad
authenticator value, it generates a warning syslog message and increments the
radiusAccServTotalBadAuthenticators and radiusAccServBadAuthenticators
metrics for the client. This error can be caused by misconfigured shared secrets or
by a problem with the NAS firmware.
CallCheck • Y RADIUS should reserve a session within Resource Management Server during
Session • N (default) Call-Check (Pre-Auth) request. If the value is set to Y, RADIUS creates a generic
Reservation session in RMS during Call-Check (Pre-Auth).
All session limits, except session limit per user, are checked. RADIUS updates the
generic session with the subscriber session data during authentication.
CallingStationID String A regular expression used to extract the real Calling-Station-Id value from the
RegExp pseudo value found in the Radius Calling-Station-Id attribute. The vendor may pad
this attribute's value with extra characters, or remove extra padding.
TaggedTunnel • Supported Specifies whether or not RADIUS sends the tunnel attribute with the tag value
Attribute (default) provisioned in the Service Manager.
• Never • "Supported"—the tunnel attribute index is based on the setting of the
• Always useTagIndex action in accessReqPolicy.
• "Never"—the tunnel attribute index is always 0.
• "Always"—the tunnel attribute index is based on the value provisioned in the
Service Manager.
EAPFragment Integer (128– The fragment size of the EAP-Message supported per RADIUS packet.
Size 2147483647) Do not exceed half the RADIUS packet size (1/2 x 4096 = 2048) so as to
Default = 1500. accommodate other attributes.
Write • Y Specifies whether or not the Service Controller generates the Correlation ID.
CorrelationID • N (default) WriteCorrelationID can be configured for each vendor in the vendors file.
To generate the Correlation ID, this element must be set to “Y”.
WritePolicy • Y (default) • Y—RADIUS writes the policy action type into the RADIUSATTR field of the
ActionType • N accounting record. This field is used by downstream accounting to route
accounting records based on the access technology (for example, GSM or
CDMA).
• N—RADIUS does not write the policy action type into the accounting record.
PPQAPoolAttr String The Prepaid Quick-Access Pool Attribute defines the name of a RADIUS attribute
Default = that is included in all Access-Accept messages from a rejecting SurePay prepaid
”Framed-Pool” server when the Quick-Access feature is enabled.
PPQAPoolAttr String (1–253 The Prepaid Quick-Access Pool Attribute Value may be provisioned to override the
Value characters) value of QAPoolID in [Link] (if provisioned). This value is assigned to the
RADIUS attribute defined by PPQAPoolAttr when the Quick-Access feature is
enabled.
Strip • Y • Y—RADIUS strips all Bridgewater VSA attributes from outgoing Access-Accept
Bridgewater • N (default) messages.
VSAs • N—RADIUS does not strip Bridgewater VSA attributes from outgoing
Access-Accept messages.
CSIDDecode • ASCII Instructs RADIUS to assume the contents of the CSID attribute are encoded in
Method • HEX either ASCII or HEX for the specified vendor.
• Undefined Options are:
(Default)
• ASCII: RADIUS assumes the contents of the CSID are encodes in ASCII
• HEX: RADIUS assumes the contents of the CSID are encoded in HEX
• Undefined: (default) RADIUS does not make any assumption about the CSID
encoding and processes the CSID normally
Note If LengthBasedCSIDDecode is configured in [Link] and
CSIDDecodeMethod is configured in [Link] on the same server, the
action specified in [Link] overrides the action specified by
[Link].
PortIDAttributes The RADIUS attributes that the RADIUS Server writes to the Port field in
accounting records to uniquely identify the NAS port.
This element encloses one or more Attribute child element.
Child element of a Vendor element.
Optional.
For example:
<PortIDAttributes>
<Attribute>NAS-Port</Attribute>
<Attribute>Chassis-Call-Channel</Attribute>
<Attribute>Chassis-Call-Span</Attribute>
</PortIDAttributes>
Class attribute
Type of ID Description
setting
RMS session ID for enabled The SessionIDAttributes element is ignored as RMS provides RADIUS with a
dial-up session Session ID.
RMS session ID for enabled The SessionIDAttributes must be available in both Accounting-Start and
CDMA session Accounting-Stop. If they are not specified, then the ClientID and
Acct-Session-ID are used by default.
IncludeClientIP • Y Specifies whether or not the client IP address is included in the Session ID.
• N (Default) RADIUS searches for attributes in the following order:
• Framed-IP-Address
• IPv6-Prefix
• IPv6 Interface ID
IncludeUserIP • Y Specifies whether or not the subscriber IP address is included in the Session
• N (Default) ID.
RADIUS searches for attributes in the following order:
• NAS-IPv6-Address
• NAS-IP-Address
• UDP Source IP Address of the request
Normalize • Y When set to Y, specifies to normalize all strings used to build the session ID.
• N (Default) When set to Y, all alphabetic characters are transformed to uppercase, and
the punctuation characters '.', ':', and '-' are removed.
Note If there are existing sessions with a state of InUse and you set
Normalize to Y, new session IDs might have a different value from
existing session IDs. This issue is resolved by the RMS audit, which
removes existing sessions (configured in the /opt/aaasc/config/rms/
[Link] file).
Optional.
Normalize • Y When set to Y, normalize all strings used to build the session recovery ID.
• N When set to Y, all alphabetic characters are transformed to uppercase, and
Default=N the punctuation characters '.', ':', and '-' are removed.
Note If there are existing sessions with a state of InUse and you set
Normalize to Y, new session IDs might have a different value from
existing session IDs. This issue is resolved by the RMS audit, which
removes existing sessions (configured in the /opt/aaasc/config/rms/
[Link] file).
Optional.
AcctRecordAttributes The attributes that the RADIUS Server writes to accounting records. The RADIUS
Server writes to the RADIUSATTR field.
To store the MDN in each accounting record, the Class attribute must be configured
as “Class”.
The Class attribute ID is 25. The MDN value is stored against Attribute ID 25 in the
RADIUSATTR field of the accounting record. For example, 25=1234567890.
This element encloses one or more Attribute child element
Child element of a Vendor element.
Optional.
For example:
<AcctRecordAttributes>
<Attribute>User-Name</Attribute>
</AcctRecordAttributes>
AcctStartAttributes The attributes that the RADIUS Server write to an accounting start record. The
RADIUS Server writes to the STARTATTR field.
Attribute elements are used to define attributes in the list.
This element encloses one or more Attribute child element.
Child element of a Vendor element.
Optional.
<AcctStartAttributes>
<Attribute>User-Name</Attribute>
</AcctStartAttributes>
AcctStopAttributes The attributes that the RADIUS Server write to an accounting stop/interim record.
The RADIUS Server writes to the RADIUSATTR field.
Attribute elements are used to define attributes in the list.
This element encloses one or more Attribute child element.
SupportedEAPTypes A list of EAP types that are supported by the vendor. EAPType elements are used
to define EAP types in the list.
The list of EAPTypes specifies the order in which RADIUS/Diameter tries to
negotiate an EAP type with the client to authenticate the subscriber.
By default, all EAP types are supported.
This element encloses one or more EAPType child element.
Child element of a Vendor element.
Optional.
For example:
<SupportedEAPTypes>
<EAPType>MD5</EAPType>
</SupportedEAPTypes>
EAPType The name of an EAP type to include in the list of supported EAP types. The type is
used for the first or second phase of PEAP. Valid EAP types are:
• MD5
• LEAP
• PEAP
• TLS
• TTLS
• MSCHAPv2 (along with PEAP)
• EAP-AKA
LockoutConfig The representative user and connection service to be used after an account is
locked out, and the type and action of the lockout. For more information about the
subscriber lockout feature and how to configure it, see "Configuring Prepaid Data"
on page 42. For a description of lockout parameters in [Link], see
"UserLockout" on page 10.
Child element of a Vendor element.
Optional.
For example:
<LockoutConfig
AcceptLoginName=”Admin”
AcceptDomain=”[Link]”
LockoutOnUserAccept=”Y”
LockoutOnAuthorizeOnly=”Y”/>
AcceptLoginName String The login name of the representative user that is used to authorize
locked-out users.
Required.
AcceptDomain String The domain name of the representative user that is used to authorize
locked-out users.
Required.
AcceptConnectionService String The RADIUS Connection Service that is applied to locked-out users.
Profile Default = Required if LockoutOnUserAccept is set to “Y”.
DEFAULT
StoredSession The base set and optional attributes that the RADIUS Server stores, for each
Attributes session, in the Session Database in SSR mode. These attributes (shown in
Table 75 and Table 76 on page 204) are ignored for all other sessions. You can
reduce session storage requirements by configuring only those attributes that are
required for each vendor in your network.
Child element of a Vendor element.
Optional.
Billing ID Yes
Correlation ID Yes
SessionRecoveryId Yes
Protocol Yes
Pseudo ID Yes
UserIpAddr Yes
1 These base attributes are included in the RADIUS message. If these base attributes are spec-
ified as (optional) stored session attributes, the RADIUS Server does not start and the system
generates an error message.
AAAServerIpAddr Yes
Calling-Station-Id Yes
When RADIUS creates an SSR session, it stores the base attributes and all other
attributes that are present in the accounting start message. If an attribute is
configured, but is not present in the accounting start message, it is not stored. If a
configured attribute is repeated in an accounting start message, the first instance is
stored in the SSR session.
The list of stored session attributes must obey the following rules:
• Attributes must not be specified more than once. Duplicate attributes cause an
error to be logged, and the RADIUS Server fails to load.
• Base attributes (shown in Table 75 on page 203) are always present and
cannot be configured separately as stored session attributes. An error is logged
and the RADIUS Server fails to load if the base attributes are specified as
stored session attributes.
• Stored session attributes must be either:
– valid RADIUS dictionary attributes, defined in the vendor dictionary
– one of the RMS attributes RadiusIpAddress or SourceIpAddress
Unidentified attributes cause an error to be logged, and the RADIUS Server
fails to load. For more information about vendor dictionary files, see ".DICT
files" on page 178.
• Attribute and vendor identifiers longer than 2 bytes are not supported for SSR
sessions. If these are specified, an error is logged, and the RADIUS Server fails
to load.
If the StoredSessionAttribute element is not defined, the following default attributes
are configured:
• Calling-Station-Id
• SourceIpAddress
• 3GPP2-PCF-IP-Addr
• RadiusIpAddress
• 3GPP2-Correlation-Id
• 3GPPS-HA-IP-Address
• 3GPP2-BSID
• 3GPP2-IP-Tech
• 3GPP2-Always-ON
The StoredSessionAttribute element encloses one or more Attribute child element.
For example:
<StoredSessionAttributes>
<Attribute>3GPP2-BSID</Attribute>
<Attribute>3GPP2-IP-Tech</Attribute>
<Attribute>3GPP2-PCF-IP-Addr</Attribute>
</StoredSessionAttributes>
MSISDNAttr="Vendor-MSISDN"
APNNIAttr="Vendor-APN"
APNOIAttr="Vendor-APN-OI"/>/>
APNAttr String The RADIUS attribute name that the RADIUS client uses to transmit the APN
1-255 characters address.
The attribute must be in the vendor dictionary.
The attribute must be a string.
Optional.
QoSAttr String The RADIUS attribute used to send back a GPRS QoS profile associated with the
1-255 characters requested APN.
The attribute must be in the vendor dictionary.
The attribute must be a string.
Optional.
ChargingCharacteri String The RADIUS attribute used to send back the Charging Characteristic values
sticAttr 1-255 characters associated with the requested APN.
The attribute must be in the vendor dictionary.
The attribute must be a string.
Optional.
IMSIAttr String The RADIUS attribute the RADIUS server uses to return the IMSI.
1-255 characters The attribute must be in the vendor dictionary.
The attribute must be a string.
Only use IMSIAttr if the client does not support CUI.
Optional.
MSISDNAttr String The RADIUS attribute the RADIUS server uses to return the MSISDN.
1-255 characters The attribute must be in the vendor dictionary.
The attribute must be a string.
Only use MSISDNAttr if the client does not support CUI
Optional.
APNNIAttr String The RADIUS attribute the RADIUS server uses to return the APN Network
1-255 characters Identifier.
The attribute must be in the vendor dictionary.
The attribute must be a string.
Optional.
APNOIAttr String The RADIUS attribute the RADIUS server uses to return the APN Operator
1-255 characters Identifier.
The attribute must be in the vendor dictionary.
The attribute must be a string.
Optional.
APN2WAPN The function to be used for mapping APNs (retrieved from an HLR) to a standard
WAPN format.
The APN2WAPN element encloses one or more of the following attributes:
• APNRegEx
• WAPNFormat
Child element of a WLAN element.
Optional.
For example:
<APN2WAPN
APNRegEx="(.*)\.(mnc[0-9]+)\.(mcc[0-9]+).*"
WAPNFormat="${1}.w-apn.${2}.${3}.[Link]"/>
[Link] examples
This section provides example for:
• RADIUS [Link]
• Diameter [Link]
<AcctRecordAttributes>
<Attribute>User-Name</Attribute>
</AcctRecordAttributes>
<AcctStartAttributes>
<Attribute>User-Name</Attribute>
</AcctStartAttributes>
<AcctStopAttributes>
<Attribute>User-Name</Attribute>
</AcctStopAttributes>
<SupportedEAPTypes>
<EAPType>LEAP</EAPType>
<EAPType>MD5</EAPType>
<EAPType>MSCHAPv2</EAPType>
<EAPType>PEAP</EAPType>
<EAPType>TLS</EAPType>
<EAPType>TTLS</EAPType>
</SupportedEAPTypes>
</Vendor>
</VendorConfiguration>
GLFWLRQDU\YHQGRUGHILQLWLRQV[PO
DDDSURYVHUYLFH[PO FRPELQHYHQGRU$93VVXFKDV
6$0681* 6$0681*%$6(
GHILQHWKHGLFWLRQDU\XWLOLW\DQGSRLQWWRWKH
GLFWLRQDU\YHQGRUGHILQLWLRQV[POILOH
GLD'LFWLRQDU\[PO
DOOYHQGRUVDQG$93V
%$6(5)&
:L0$;
0,&5262)7
'LFWLRQDU\XWLOLW\ 6$0681*
1257(/
3URYLVLRQLQJ 'LDPHWHU
'LDPHWHU
6HUYHU 6WDFN
$$$
DSSOLFDWLRQ
YHQGRUV[PO
[Link]
The unified Diameter dictionary, [Link], defines all Diameter vendors
and the attribute-value pairs that they support. The Diameter AAA application and
the Bridgewater Diameter Stack use the [Link] file to source all Diameter
AVPs and Diameter commands.
Note After modifying the [Link] file, send a HUP signal to the
Provisioning Server (wsprovs) and the Diameter AAA application (diaaaa).
Restart the Bridgewater Diameter Stack (BWSwsdia).
The [Link] file is located in the /opt/aaasc/config/dia directory, and its
schema file, [Link], is located in the /opt/aaasc/dict/dia directory.
This section describes the elements, child elements, and attributes of the
[Link] file.
The Diameter dictionary schema contains these elements:
dictionary: the root element
avp-group
vendor-group
avp
default-flag
type
enumerated
enum
grouped
fixed
avp-rule
flag
required
avp-rule
flag
optional
avp-rule
flag
avp-extension
enumerated
enum
application
import-avp-group
import-command
command
request-rule
required
avp-rule
optional
response-rule
required
avp-rule
optional
avp-rule
dictionary The root element that encloses the <avp-group> and <application> elements. At
least one <avp-group> element must be defined.
Example:
<dictionary>
<avp-group... />
<application ... />
</dictionary>
avp-group A collection of AVPs. The avp-group element contains the avp-extension, and
vendor-group child elements.
Child element of dictionary.
Example:
<avp-group>
<vendor-group .../>
<avp-extension .../>
</avp-group>
avp A specific attribute-value pair, such as User-Name. The avp element contains zero
or more default-flag child elements and one of the following child elements: type,
enumerated, or grouped.
Child element of vendor-group.
Example:
<avp code=”1” name=”User-Name”>
<default-flag .../>
<type .../>
</avp>
default-flag Enables the use of the flags that are defined in section 4.1 of RFC 3588. To
override the value of the flag, specify the Diameter command.
Child element of avp.
Optional.
Example:
<default-flag mandatory=”may”/>
name • OctetString • The name of the specified AVP type, such as Integer32.
• UTF8String
• DiameterIdentity
• DiameterURI
• Integer32
• Integer64
• Unsigned32
• Unsigned64
• Float32
• Float64
• Address
• Time
• IPFilterRule
• QosFilterRule
enumerated Defines the specific values for enumerated AVPs. The enumerated element
contains one or more enum child elements.
Child element of avp and avp-extension.
Example:
<enumerated>
<enum .../>
<enum .../>
</enumerated>
allow-any-avp • true • true = permit any AVP to be present in the grouped attribute.
• false (default)
fixed Requires all enclosed AVPs to be present and in a fixed position in relation to the
start of a Diameter message.
The fixe> element must contain one or more avp-rule elements.
Child element of grouped.
Example:
<fixed>
<avp-rule name=”SessionId” group-name=”BASE” min-occur=”1”
max-occur=”1”>
<flag mandatory=”may”/>
</avp-rule>
</fixed>
required Requires all enclosed AVPs to be present. These AVPs can appear anywhere in a
Diameter message.
The required element must contain one or more avp-rule elements.
Child element of grouped.
Example:
<required>
<avp-rule name=”Auth-Application-Id” min-occur=”1” max-occur=”1”>
<flag mandatory=”may”>
</avp-rule>
</required>
avp-rule Encloses AVPs required for the grouped attribute, and it encloses the optional flag
child element.
Child element of fixed, required, or optional.
Example:
<required>
<avp-rule name=”Auth-Application-Id” min-occur=”1” max-occur=”1”>
</required>
group-name • String (1–255 • The name of the avp group that defines the attribute.
characters) • If the group-name is not specified, the system searches for the AVP
definition in all AVP groups defined in the file.
• Optional.
min-occur Default = 0 • The minimum number of times that this attribute can occur.
• Optional.
max-occur Default = no limit • The maximum number of times that this attribute can occur.
• Optional.
flag Enables the use of the flags that are defined in section 4.1 of RFC 3588. If the fla>
element is not present, the system uses the value defined in the default-flag
element.
Child element of avp-rule.
Example:
<avp-rule name=”Auth-Application-Id” min-occur=”1” max-occur=”1”>
<flag mandatory=”may”>
</avp-rule>
mandatory • must-not (default) • Use flags to define how AVPs are managed.
• must
• may
avp-extension Defines extensions to AVPs that add new enumerated values to AVPs.
The avp-extension element contains the enumerated child element.
Child element of vendor-group.
Example:
<avp-group ...>
<avp-extension name=”Auth-Request-Type group=”BASE”>
<enumerated .../>
</avp-extension>
</avp-group>
import-avp-group Creates a master list of all the AVPs that the application supports. The value of
import-avp-group must be an avp-group that is defined in the Diameter dictionary.
Child element of application.
Example:
<application id=”5” name=”EAP”>
<import-avp-group>SAMSUNG</import-avp-group>
<import-avp-group>MICROSOFT</import-avp-group>
application • String • The name of the application from which to import the command.
• 1 to 255 • The application name must be present in the Diameter dictionary.
• Required.
abbr-name • 2 letter string • Two letter abbreviation for the command name.
• User capital letters only.
• Example=DE (Diameter-EAP).
• Required.
allow-proxy • true • —
• false
allow-any-avp • true • true = permit any AVP to be present in the grouped attribute.
• false (default)
[Link] The following [Link] example uses all the elements described in
example "[Link]" on page 210.
<?xml version="1.0" encoding="UTF-8"?>
<dictionary xmlns="[Link] xmlns:xsi="http://
[Link]/2001/XMLSchema-instance" xsi:schemaLocation="/opt/aaasc/dict/dia/
[Link]">
<type name="OctetString"/>
</avp>
<avp code="5" name="NAS-Port">
<type name="Unsigned32"/>
</avp>
<avp code="6" name="Service-Type">
<type name="Unsigned32"/>
</avp>
<avp code="8" name="Framed-IP-Address">
<type name="Unsigned32"/>
</avp>
<avp code="12" name="Framed-MTU">
<type name="Unsigned32"/>
</avp>
<avp code="25" name="Class">
<type name="OctetString"/>
</avp>
<avp code="27" name="Session-Timeout">
<type name="Unsigned32"/>
</avp>
<avp code="31" name="Calling-Station-Id">
<type name="UTF8String"/>
</avp>
<avp code="32" name="NAS-Identifier">
<type name="OctetString"/>
</avp>
<avp code="46" name="Acct-Session-Time">
<type name="Unsigned32"/>
</avp>
<avp code="50" name="Acct-Multi-Session-Id">
<type name="Unsigned32"/>
</avp>
<avp code="55" name="Event-Timestamp">
<type name="Unsigned32"/>
</avp>
<avp code="60" name="WIMAX-DM-Action-Code">
<type name="Unsigned32"/>
</avp>
<avp code="61" name="NAS-Port-Type">
<type name="Unsigned32"/>
</avp>
<avp code="85" name="Acct-Interim-Interval">
<type name="Unsigned32"/>
</avp>
<avp code="89" name="CUI">
<type name="OctetString"/>
</avp>
<avp code="258" name="Auth-Application-Id">
<type name="Unsigned32"/>
</avp>
<avp code="259" name="Acct-Application-Id">
<type name="Integer32"/>
</avp>
<avp code="263" name="Session-Id">
<type name="OctetString"/>
</avp>
<avp code="264" name="Origin-Host">
<type name="OctetString"/>
</avp>
<avp code="268" name="Result-Code">
<type name="Unsigned32"/>
</avp>
<avp code="272" name="Multi-Round-Timeout">
<type name="Unsigned32"/>
</avp>
<avp code="274" name="Auth-Request-Type">
<enumerated>
<enum name="AUTHENTICATE_ONLY" code="1"/>
<enum name="AUTHORIZE_ONLY" code="2"/>
<enum name="AUTHORIZE_AUTHENTICATE" code="3"/>
</enumerated>
</avp>
</vendor-group>
</avp-group>
<!-- WiMAX avp group definition -->
<avp-group name="WIMAX">
<!-- WiMAX Vendor AVPs -->
<vendor-group vendor-id="24757">
<avp code="1025" name="Accounting-Capabilities">
<enumerated>
<enum name="No-Accounting" code="0"/>
<enum name="IP-Session-Based" code="1"/>
<enum name="Flow-Based" code="2"/>
</enumerated>
</avp>
<avp code="1026" name="Hotlining-Capabilities">
<enumerated>
<enum name="No-Hotlining" code="0"/>
<enum name="IP-Redirection" code="1"/>
<enum name="HTTP-Redirection" code="2"/>
</enumerated>
</avp>
<avp code="1027" name="Idle-Mode-Notification-Capabilities">
<enumerated>
<enum name="Idle-Mode-Not-Supported" code="0"/>
<enum name="Idle-Mode-Supported" code="1"/>
</enumerated>
</avp>
<avp code="1" name="WiMAX-Capability">
<default-flag mandatory="may"/>
<grouped allow-any-avp="true">
<fixed/>
<required>
<avp-rule name="Accounting-Capabilities" min-occur="1"
max-occur="1">
<flag mandatory="may"/>
</avp-rule>
</required>
<optional>
<avp-rule name="Hotlining-Capabilities" min-occur="0"
max-occur="1">
</avp-rule>
<avp-rule name="Idle-Mode-Notification-Capabilities"
min-occur="0" max-occur="1">
</avp-rule>
</optional>
</grouped>
</avp>
</vendor-group>
</avp-group>
<!-- SAMSUNG avp group definition -->
<avp-group name="SAMSUNG">
<!-- Samsung Vendor AVPs -->
<vendor-group vendor-id="236">
<avp code="11000" name="DIR">
<default-flag mandatory="must-not"/>
<type name="UTF8String"/>
</avp>
</vendor-group>
</avp-group>
<!-- Microsoft avp group definition -->
<avp-group name="MICROSOFT">
<!-- Microsoft Vendor AVPs -->
<vendor-group vendor-id="311">
<avp code="11" name="MS-CHAP-Challenge">
<default-flag mandatory="must-not"/>
<type name="OctetString"/>
</avp>
<avp code="25" name="MS-CHAP2-Response">
<default-flag mandatory="must-not"/>
<type name="OctetString"/>
</avp>
<avp code="26" name="MS-CHAP2-Success">
<default-flag mandatory="must-not"/>
<type name="OctetString"/>
</avp>
</vendor-group>
</avp-group>
<!--
Example to show what avp extension looks like. The following avp-group extends
the BASE avp Auth-Request-Type by adding new enumeration values.
-->
<avp-group name="BASE_EXT">
<avp-extension name="Auth-Request-Type" group="BASE">
<enumerated>
<enum name="myExtraEnum1" code="4"/>
<enum name="myExtraEnum2" code="5"/>
</enumerated>
</avp-extension>
<vendor-group vendor-id="0">
</vendor-group>
</avp-group>
max-occur="1"/>
<avp-rule name="Origin-Host" min-occur="1" max-occur="1"/>
<avp-rule name="Origin-Realm" min-occur="1" max-occur="1"/>
<avp-rule name="Result-Code" min-occur="1" max-occur="1"/>
</required>
<optional>
<avp-rule name="User-Name" max-occur="1"/>
</optional>
</response-rule>
</command>
</application>
</dictionary>
[Link]
The Diameter AAA application queries the [Link] file for definitions of the
vendor-specific Diameter attributes to write to accounting records when a Diameter
ACR is received. It also uses [Link] to store service usage data, and to
generate correlated accounting records.
Note Vendors defined in the [Link] file must match the vendors defined in
the [Link] file used by the Diameter Server.
For more information about [Link], see "Configuring vendor-specific data
([Link])" on page 189.
[Link]
The [Link] file, located in the /opt/aaasc/config/dia
directory, enables you combining the AVPs from different vendors into avp-groups,
such as combining SAMSUNG VSAs with RFC 3588 AVPs. The system makes
these groups of AVPs available to the specified vendor by reading the appropriate
sections of the [Link] Diameter dictionary file.
For example, assign all the BASE and SAMSUNG AVPs to the SAMSUNG vendor
by adding the following entry in the [Link] file:
<vendor name="SAMSUNG">
<import-avp-group name="BASE" />
<import-avp-group name="SAMSUNG" />
</vendor>
The [Link] file is .
Note After modifying [Link] file, send a HUP signal to
the Provisioning Server (wsprovs) for the changes to take effect.
changes are not accepted. The system reverts to the original dictionary
parameters. Fix the problem and send another HUP signal.
[Link]
In a Diameter environment, the [Link] file, located in the /opt/aaasc/
config/provserver directory, defines the utility that loads the Diameter dictionary into
the Provisioning Server, and it points to the directory that contains the
[Link] file. The [Link] file also configures
the Diameter dictionary API.
Note For a new installation, there is no need to manually configure Diameter
information in the [Link] file. For upgrades, see the README
file in the BWSaaapr package for information about configuring the
[Link] file.
7
Chapter 7
Chapter
This chapter provides information about configuring RADIUS and Diameter Server
policy rules to handle preauthentication, authentication, and accounting requests.
The topics are:
• Rules files
• Conditions
• Actions
• Action modifiers
• rejectPolicy
• Configuring PreAuthorize using Access Control Limits (ACL) for proxy
• Testing policy rules
• Example policy configurations
Rules files
The policy rules are listed in the following policy files:
Mandatory
• accessReqPolicy defines rules for handling Access-Request messages
• acctReqPolicy defines rules for handling Accounting-Request messages
Note The accessReqPolicy and the acctReqPolicy files must be present for the
RADIUS Server to start.
Optional
• TLSPolicy defines rules for handling Access-Request messages to evaluate the
Inner-User-ID found in TLS-based EAP mechanisms such as EAP-TTLS
• dynamicHAPolicy defines rules for handling dynamic home agent allocation
requests, which are used in Mobile IP scenarios
• daeReqPolicy defines rules for handling Dynamic Authorization Extensions
requests
• ejectPolicy defines rules for adding service AVPs to Access-Reject messages
delivered to the gateway
Other
• additional policy files, invoked using the policyRun action, contain policy rules in
the same format.
For policy actions, such as Pre-Authorize, that are triggered during a multi-leg EAP
exchange, enable DAL query caching, which stores user attributes to the EAP-state
cache. RADIUS retrieves these attributes from the cache, which minimizes the load
on the Profile database. For more information, see "Configuring database (DAL
query) caching for multi-leg EAP" on page 74.
Policy files are located in the /opt/aaasc/config/radius and /opt/aaasc/config/dia-aaa
directories.
Each policy file contains an ordered list of rules. Each rule consists of two
expressions:
• a condition – which must be met by the incoming message
• an action – which occurs when the condition is met
Conditions
The condition in each policy rule has the following syntax:
<attribute> <operator> <value>
The condition “- - -” can be used as a “catch-all” rule for any requests that do not
match other rule conditions.
Table 93 lists the possible entries for attribute fields in a condition.
Options Notes
Any attribute from any vendor If no vendor is specified, the RFC dictionary is assumed.
dictionary, in the format For the PreAuthorize action, use the optional PreAuth: tag to specify that the
<vendor-name>:<attribute-name>. attribute should be retrieved from the specified RADIUS connection service profile.
Subtype attributes are also Without the PreAuth: tag, the attribute defaults to the value in the
supported, including subtype [Link] example: PreAuth:<vendor-name>:<attribute-name>.
attributes in octet string format. For For HLR authorization with the authorizationPolicy action modifier, use the optional
subtype attributes you must use the HLRAuth: tag to specify that the comparision should occur against an attribute
format injected with data retrieved from an HLR. If the HLRAuth: tag is not specified, the
<vendor-name>:<attribute-name>. attribute comparison occurs against the attribute received from the Access-Request.
To specify one of a subtype
This tag should only be used in conjunction with a policy that uses the
attribute’s nested subtypes for
hlrAuthoriztion and authorizationPolicy action modifiers together.
comparison, use an extractReg
modifier in the policy line. Supported condition attributes are Equals, NotEquals, EqualsCI, NotEqualsCl,
RegExp, and NotRegExp.
For more information about using
subtype attributes, see "Using
subtype attributes in
Access-Requests to control network
access" on page 317.
Client-IP-Address The source IP address of the incoming request. The value is the IP address in
standard dot notation. Supported condition attributes are Equals, NotEquals,
Between, Matches, and BelongsToClientGroup.
Time-Of-Day The local time of the RADIUS client (NAS or Proxy Server) based on the time zone
defined for it in the Service Manager. Equals and NotEquals are the only valid
operator for the Time-Of-Day condition. The Time-Of-Day condition requires a value
in the form: DayofWeek:TimeRange, where DayofWeek is either a range (Mon-Fri)
or a list (Fri,Sat,Sun) and TimeRange is a range in the form hhmmss-hhmmss.
myVar:<user-defined-variable> An attribute name of myVar refers to an AssignVar action where the myVar variable
was defined. For more information, see "myVar" on page 281.
Supported condition attributes are NotEquals and NotEqualsCl.
Options Notes
Pre-Acct-Service A pre-authorization service is in the Profile Database. “Appears” is the only valid
operator. “Once”, and “Never” are the only valid condition values.
• “Once” — the pre-authorization service must be in the Profile Database for the
condition to evaluate successfully.
• “Never” — the pre-authorization service is not in the Profile Database.
Pre-Auth-User A pre-authorization user is in the Profile Database. “Appears” is the only valid
operator. “Once”, and “Never” are the only valid condition values.
• “Once” — the pre-authorization user must be in the Profile Database for the
condition to evaluate successfully.
• “Never” — the pre-authorization user is not in the Profile Database.
Pre-Auth-Service A pre-authorization service is in the Profile Database. “Appears” is the only valid
operator. “Once”, and “Never” are the only valid condition values.
• “Once” — the pre-authorization service must be in the Profile Database for the
condition to evaluate successfully.
• “Never” — the pre-authorization service is not in the Profile Database.
Options Notes
Reject-Reason The Access-Request has been rejected. “Equals” is the only valid operator. The
valid condtion values are:
• subscriber not found in the database
• Password is incorrect
• Invalid Auth Request
• Invalid Key Index
• Locked User
• MIP Attributes Not Available
• Password Missing
• Service Unavailable
• IP Address Allocation Failure
• NAS Client ID Failure
• Time Access Denial
• Location Access Denial
• Access Type Denial
• RMS Session Limit
• Ambiguous User
• HA Unavailable
• No Auth Mechanism Supported
• Invalid Mobile ID
• Server Error
• No Prepaid Support
• No Remote Prepaid Response
• MIP Not Available
• Invalid Equipment ID
• No Remote EAP Response
• Missing WiMAX Session
Options Notes
NotEquals [NotEqualsCI]
StartsWith [StartsWithCI]
EndsWith [EndsWithCI]
Contains [ContainsCI]
NotRegExp If the attribute does not match the value of the regular expression, the associated
policy action is executed.
Options Notes
GreaterThan Only valid with type string and type integer attributes in call check policy rules.
LessThan
Appears Only one of these values is allowed with the Appears operator: Never (n=0), Once
(n=1), AtLeastOnce (n>=1), or Multiple (n>1).
MatchesAny [MatchesAnyCI] Compares an attribute to incoming or retrieved attributes. Supports wildcard (*).
Use the wildcard in front of a value, or to represent a complete value.
The PreAuth: tag can be used in front of a value to specify that the value should
come from the PreAuthorize action.
The HLRAuth: tag can be used in front of a value to specify that the value comes
from data retrieved from an HLR.
MatchesAnyCI is a case-insensitive version of the MatchesAny condition operator.
Matches Matches only supports CIDR notation. For example, [Link]/24. Only
Client-IP-Address and NAS-IP-Address support this option.
Option Notes
Appears qualifier Never (n=0), Once (n=1), AtLeastOnce (n>=1), or Multiple (n>1)
Actions
The action expression in each policy rule has the following syntax:
<action-name> <action-modifiers>
The action modifiers that can be applied to the action depend on the type of action
and the context in which it is used:
• Access request actions
• Accounting request actions
• Dynamic HA request actions
• TLS request actions
• DAE request actions
The RADIUS and Diameter Servers evaluate incoming messages against each
condition in the policy file, from top to bottom. If a condition is met, the action
specified in the rule is performed and no further evaluations are performed on the
message. If none of the conditions are met, the message is discarded.
By default, if the policy file is empty the RADIUS and Diameter servers perform
local authentication and accounting on incoming messages.
Action-name Action
PreAuthorize Preauthorizes the subscriber against the local Profile Database. Values are retrieved from the
specified RADIUS connection service profile. The default user is configurable. Policy evaluation
continues after the PreAuthorize action.
Note: To authorize against the ‘service’ action modifier, you must specify a value. This modifier does
not use a default setting.
If no subscriber identifiers are specified, the User-Name attribute is used for preauthorization. For a
policy configuration example, see ”Preauthorization” on page 315.
Attributes retrieved by a PreAuthorize action are referenced with the string “PreAuth”.
Example:
- - - ProxyAA target=PreAuth:$BRIDGEWATER:Proxy-Target \
authorizeProxyLevel=PreAuth:$BRIDGEWATER:Authorize-Proxy-Level
For deployments that require port quota checks, configure a policy to perform Access Control Limit
checks prior to sending a proxy request. For more information, see "Configuring PreAuthorize using
Access Control Limits (ACL) for proxy" on page 297.
LogMessage Enables an administrator to generate a custom log message to the RADSYS log family. Must be
configured with the “message” action modifier and can be optionally configured with the “priority”
and “attrs” action modifiers. For more information, see "CSID/MSID mismatch detection for LDAP
deployments" on page 320.
After LogMessage is executed, policy evaluation continues to the next specified policy line.
CDMA2000LocalAA Authenticates CDMA2000 wireless subscribers against the local Profile Database.
Action-name Action
DMUProxyAA Forwards Dynamic Mobile IP Key Update authentication requests to an external RADIUS Server
WiFiLocalAA Authenticates requests from subscribers for initial attachment to, or transition from, a Wi-Fi access
point using the device MAC address and session information stored in RMS.
WiMAXLocalAA Authenticates requests from an ASN gateway or WiMAX home agent node against the local Profile
Database.
WiMAXProxyAA Forwards requests from an ASN gateway or WiMAX home agent node to an external RADIUS
Server.
AssignVar Enables an administrator to define variables for the assignment of values to be used as conditions
in other policies and/or values for other action modifiers.
$FFHVV 3DFNHW
1RGH 7\SH
1H[W
3ROLF\ 5XOH
5XOHV
&RQGLWLRQ
12 6SHFLILHG
<(6
&RQGLWLRQ
6DWLVILHG 12
<(6 $VVLJQ9DU
$FWLRQ
/RFDO$$$FWLRQVLQFOXGH
&DOO&KHFN$$ /RFDO$$
/RFDO$$
7\SH
&'0$/RFDO$$
'08/RFDO$$
*60/RFDO$$
:L)L/RFDO$$
6HQG5HMHFW 3UR[\$$
:L0D[/RFDO$$
3ROLF\5XQ
3UR[\$$$FWLRQVLQFOXGH
3UR[\$$
&'0$3UR[\$$
'083UR[\$$
3ROLF\ *603UR[\$$
:L0D[3UR[\$$
5XOHV
Table 97 on page 243 lists action-modifiers for Access-Requests and the policy
actions for which they are valid.
Some modifiers only support RADIUS, some only support Diameter, and some
support both RADIUS and Diameter. For syntax and descriptions of each modifier,
see "Action modifiers" on page 262.
Policy action
CallCheckAA
PreAuthorize
LocalAA
ProxyAA
CDMA2000LocalAA
CDMA2000ProxyAA
DMULocalAA
DMUProxyAA
GSMLocalAA
GSMProxyAA
WiMAXLocalAA
WiMAXProxyAA
WiFiLocalAA
SendReject
PolicyRun
AssignVar
Action-modifier
ACCT-Mode
acMatchAttribute
acService
allowLockedoutUsers
appendDomain
appendService
assignVisitedFramedIP
assignVisitedHome Agent
attrs
authenticate
authenticateDomain
authorizationPolicy
authorize
authorizeDefault Domain
authorizeDefault LoginName
authorizeDomain
authorizeLoginName
authorizeProxyLevel
BTSCheck
BTSService
cacheCertFields
checkNasGroupLimit
checkSession
continue PreProcessing
continueNotFound
defaultProxy
disableDMU
discardDomain
discardService
dnPrefix
dnSearchBase
dnSearchBaseReq Exp
Policy action
CallCheckAA
PreAuthorize
LocalAA
ProxyAA
CDMA2000LocalAA
CDMA2000ProxyAA
DMULocalAA
DMUProxyAA
GSMLocalAA
GSMProxyAA
WiMAXLocalAA
WiMAXProxyAA
WiFiLocalAA
SendReject
PolicyRun
AssignVar
Action-modifier
domain
domainRegexFormat
EAP-OTA-Policy
EAP-Policy
enableIPReach
evaluatePolicy
extractAttr
extractReg
Force-WiMAX- Session
getMobileID
getProxyService
hlrAuthorization
hotlineSet
HTTPDigest-Policy
ignorePreProcessingFailure
ipAllocPoolName Override
LDAPPassword Attribute
LDAPUserFilter
loginName
loginNameRegex Format
message
mobileType
mppeEncryptionType
multimode
myVar
optionalService
outageAction
outageDomain
outageLoginName
outageReject Message
outageService
PANIEnabled
Policy action
CallCheckAA
PreAuthorize
LocalAA
ProxyAA
CDMA2000LocalAA
CDMA2000ProxyAA
DMULocalAA
DMUProxyAA
GSMLocalAA
GSMProxyAA
WiMAXLocalAA
WiMAXProxyAA
WiFiLocalAA
SendReject
PolicyRun
AssignVar
Action-modifier
PPHotlineSet
priority
proxyAVPs
reason
rejectPolicy
replaceDomain
replyMessage
returnAVPs
runPlugIn
service
serviceAVP
serviceRegexFormat
suppress-MS-MPPE
switchLocalAuthorizeUser
target
trunkGroupAVP
useAuthorize BillingId
useMobileKey
useTagIndex
validateEquipID
validateMobileID
writeAccounting
Action-name Action
LocalAcct The RADIUS Server sends an accounting record to the Accounting Framework.
ProxyAcct The RADIUS Server forwards the accounting message to a remote RADIUS server, as well
as sending an accounting record to the Accounting Framework.
DeviceReboot The RADIUS Server interprets the accounting-request as an indication of a device reboot. It
sends an update to the Resource Management Suite Products to close any sessions that
were active on the NAS before the reboot. The RADIUS Server still sends the accounting
record to the Accounting Framework. This policy action is only required if one of the
Resource Management Suite Products is deployed.
CDMA2000LocalAcct The RADIUS Server forwards a CDMA accounting record to the Accounting Framework.
Required for SSR mode.
CDMA2000ProxyAcct The RADIUS Server forwards the CDMA accounting message to a remote RADIUS Server,
as well as sending an accounting record to the Accounting Framework.
GSMLocalAcct The RADIUS Server sends a GSM accounting record to the Accounting Framework.
GSMProxyAcct The RADIUS Server forwards the GSM accounting message to a remote RADIUS Server, as
well as sending an accounting record to the Accounting Framework. This only supports RMS
interactions in SSR mode.
WiFiLocalAcct Sends accounting records from a Wi-Fi access point to the Accounting Framework.
WiMAXLocalAcct Sends accounting records from an ASN gateway or WiMAX home agent node to the
Accounting Framework.
WiMAXProxyAcct Forwards accounting messages from an ASN gateway or WiMAX home agent node to a
remote RADIUS server, as well as sending the accounting records to the Accounting
Framework.
Action-name Action
AssignVar Enables an administrator to define variables for the assignment of values to be used as
conditions in other policies and/or values for other action modifiers.
LogMessage Enables an administrator to generate a custom log message to the RADSYS log family. Must
be configured with the “message” action modifier and can be optionally configured with the
“priority” and “attrs” action modifiers. For more information, see "CSID/MSID mismatch
detection for LDAP deployments" on page 320.
After LogMessage is executed, policy evaluation continues to the next specified policy line.
Figure 28 on page 248 shows how accounting requests are processed. The actions
specified in the diagram are specific to RADIUS, but the process flow is the same
for RADIUS and Diameter.
$FFHVV
3DFNHW
1RGH
7\SH
1H[W
3ROLF\ 5XOH
5XOHV
&RQGLWLRQ
12 6SHFLILHG
<(6
&RQGLWLRQ
6DWLVILHG 12
<(6 $VVLJQ9DU
$FWLRQ
/RFDO$FFW$FWLRQVLQFOXGH
/RFDO$FFW
/RFDO$FFW
7\SH
&'0$/RFDO$FFW
'08/RFDO$FFW
*60/RFDO$FFW
:L)L/RFDO$FFW
'HYLFH5HERRW 3UR[\$FFW
:L0D[/RFDO$FFW
3ROLF\5XQ
3UR[\$FFW$FWLRQVLQFOXGH
3UR[\$FFW
&'0$3UR[\$FFW
'083UR[\$FFW
3ROLF\ *603UR[\$FFW
5XOHV :L0D[3UR[\$FFW
Table 99 lists action-modifiers for Accounting-Requests and the policy actions for
which they are valid.
Some modifiers only support RADIUS, some only support Diameter, and some
support both RADIUS and Diameter. For syntax and descriptions of each modifier,
see "Action modifiers" on page 262.
Policy action
PreAccounting
LocalAcct
ProxyAcct
DeviceReboot
CDMA2000LocalAcct
CDMA2000ProxyAcct
GSMLocalAcct
GSMProxyAcct
WiMAXLocalAcct
WiMAXProxyAcct
WiFiLocalAcct
PolicyRun
AssignVar
Action-modifier
acctDBLookup
appendDomain
attrs
continueNotFound
continue PreProcessing
defaultProxy
disableAcctAckOn ProxyTimeout
discardClassAttr
discardDomain
domain
domainRegexFormat
evaluatePolicy
extractAttr
extractReg
getMobileID
getProxyService
hotlineSet
idleSessionRestore
ignorePreProcessingFailure
loginName
message
multimode
myVar
priority
replaceDomain
replaceMIN
Policy action
PreAccounting
LocalAcct
ProxyAcct
DeviceReboot
CDMA2000LocalAcct
CDMA2000ProxyAcct
GSMLocalAcct
GSMProxyAcct
WiMAXLocalAcct
WiMAXProxyAcct
WiFiLocalAcct
PolicyRun
AssignVar
Action-modifier
rmsLocationUpdate
runPlugIn
service
target
useMobileKey
writeAccounting
writeCertFields
Action-name Action
DHARoundRobin Assigns HAs evenly across all HAs defined in the named HA
group.
Action-name Action
$FFHVV 3DFNHW
1RGH 7\SH
1H[W
3ROLF\ 5XOH
5XOHV
&RQGLWLRQ
12 6SHFLILHG
<(6
&RQGLWLRQ
6DWLVILHG 12
<(6 $VVLJQ9DU
'+$5RXQG5RELQ
$FWLRQ
:LWK3ULPDU\+$ '+$5RXQG5RELQ
DQG3'61)DLOXUH 7\SH
'+$5RXQG5RELQ '+$9DOLGDWH
:LWK3ULPDU\+$ 2QO\
3ROLF\5XQ
3ROLF\
5XOHV
Table 101 lists action-modifiers for Dynamic HA-Requests and the policy actions for
which they are valid. For syntax and descriptions of each modifier, see "Action
modifiers" on page 262.
Policy action
DHARoundRobin
PolicyRun
DHAValidateOnly
withPrimaryHA
DHARoundRobin
andPDSNFailure
withPrimaryHA
DHARoundRobin
AssignVar
Action-modifier
allowHA
continue PreProcessing
evaluatePolicy
extractAttr
extractReg
haAlternateList
haGroup
ignorePreProcessingFailure
myVar
pdsnList
policyFailover Enabled
primaryHA
Action-name Action
$FFHVV 3DFNHW
1RGH 7\SH
1H[W
3ROLF\ 5XOH
5XOHV
&RQGLWLRQ
12 6SHFLILHG
<(6
&RQGLWLRQ
6DWLVILHG 12
<(6
$FWLRQ
7\SH
7/63UR[\$$ 7/6/RFDO$$
RADIUS TLSPolicy Table 103 lists the RADIUS action-modifiers for TLS-Requests and the policy
action modifiers actions for which they are valid. For syntax and descriptions of each modifier, see
"Action modifiers" on page 262.
Policy action
TLSLocalAA
TLSProxyAA
Action-modifier
allowLockedoutUsers
appendDomain
authenticate
authorize
authorizeDomain
authorizeLoginName
authorizeProxyLevel
discardDomain
domain
domainRegexFormat
EAP-Policy
LDAPPassword Attribute
LDAPUserFilter
loginName
loginNameRegex Format
outageAction
outageDomain
outageLoginName
outageReject Message
outageService
rejectPolicy
replaceDomain
target
One or more action-modifiers can be used in each rule, unless otherwise noted.
If RADIUS is configured to write account pending records:
• the authentication modifiers specified for TLSLocalAA or TLSProxyAA are used
in the pending record
• the login and domain fields of the inner user ID are used in the pending record if
authentication modifiers are not specified for TLSLocalAA or TLSProxyAA
When a representative user is specified in the outer policy, that is, LocalAA, the
representative user is used for authorization. Otherwise the inner TLS user is used
for authorization. For example:
accessReqPolicy:
- - - LocalAA EAP-Policy=ttlspolicy authorizeLoginName=rep
authorizeDomain=[Link]
TLSPolicy:
- - - TLSLocalAA authorizeLoginName=innerRep
authorizeDomain=[Link]
TLSProxyAA can be used with the [Link] RADIUSServerGroup element. For
information, see "RADIUSServer Group" on page 358.
Diameter TLSPolicy Table 104 lists the Diameter action-modifiers for TLS-Requests and the policy
action modifiers actions for which they are valid. For syntax and descriptions of each modifier, see
"Action modifiers" on page 262.
Policy action
TLSLocalAA
TLSProxyAA
Action-modifier
authenticateDomain
authorizeDomain
authorizeLoginName
EAP-Policy
outageReject Message
unknownUserSecret
Rules Each rule consists of a condition expression and an action expression. The
condition expression is as follows:
<attribute> <operator> <value>
where
<attribute> is:
'Client-IP-Address'
'-’
<operator> is:
Equals
'-'
<value> is a range
For more information about conditions, see "Conditions" on page 235.
Examples This section provides examples of how to use the daeReqPolicy file.
Local network
If a Hotlining Device is on a local network, use the following:
- - - ProxyDAE
In this case the Service Controller retrieves the information about the Hotlining
Device from the Profile Database.
Proxy
If a Hotlining Device is remote, use the following:
WLAN deployments
To support unsolicited requests from an HLR in WLAN deployments, use the
following:
- - - HLRProxyDAE
Action-name Action
Action-name Action
$FFHVV 3DFNHW
1RGH 7\SH
1H[W
3ROLF\ 5XOH
5XOHV
&RQGLWLRQ
12 6SHFLILHG
<(6
&RQGLWLRQ
6DWLVILHG 12
<(6
$FWLRQ
7\SH
GDH5HT3ROLF\
The only action modifier for DAE Requests is target for ProxyDAE. For syntax and
descriptions of each modifier, see "Action modifiers" on page 262.
Action modifiers
This section provides descriptions for all supported action modifiers.
– HA: the Service Controller responds and specifies no accounting for the
subscriber.
Note For RADIUS, when the ASN or HA does not send Accounting-Capabilities
in the Access-Request, RADIUS does not send any
Accounting-Capabilities in the Access-Accept message.
For Diameter when the ASN does not send Accounting-Capabilities in the
DER, Diameter sends "session based" as the accounting capability in the
DEA.
• If the BSID check is done using the incoming WiMAX-BS-ID, the case of the
provisioned BSID does not matter because the incoming WiMAX-BS-ID is in
hex format.
If the BSID check is done on the incoming 3GPP-BSID or BSID in the Called
Station-Id, the Service Controller does a case-sensitive match with the
provisioned BSID.
If the WiMAX-BS-ID is not present in the Access-Request, the Service Controller
also looks for the BSID in the Called-Station-Id attribute.
When BTSCheck=”Y”:
• if the BSID from the Access-Request matches a BSID provisioned against the
subscriber, the Service Controller returns an Access-Accept
• if the BSID in the Access-Request doesn’t match any BSIDs provisioned
against the subscriber, the Service Controller sends a reject or retrieves the
service specified by BTSService and returns this service for the subscriber
– if the BTSService modifier is present in the accessReqPolicy, and
cacheMode is set to “L”, when the BSID check doesn’t find a match, the
Service Controller retrieves and caches service specified by BTSService
and returns the cached service to the Ericsson BRAS during the second
phase authentication.
– If cacheService is present in the same policy line, the service specified by
BTSService is cached and used instead of a service specified by
cacheService.
– if BTSService is set to “reject” the Service Controller returns an
Access-Reject
The actions WiMAXLocalAA, CDMA2000LocalAA, LocalAA, GSMLocalAA,
WiFiLocalAA, and DMULocalAA support the BTSCheck modifier.
Default=N
For more information about provisioning BSIDs against subscribers, see the
Service Manager: Services Provisioning Guide for AAA.
Example: s/([^@]+)(@(.*)){0,1}/${3}-{1}
This expression extracts everything before ‘@’ into pattern 1, extracts the first
string after the ‘@’ into pattern 3 and swaps them, putting them together with ‘-’.
Input: user; Result: -user
Input: user@[Link];Result: [Link]-user
Input: user@[Link]@[Link]; Result: [Link]-user
idleSessionRestore Syntax:idleSessionRestore=<y|n>
When a session is missing, this modifier enables RMS to recreate the session upon
receiving an Accounting-Start or Accounting-Interim message. RMS recreates the
session by restoring the session pool reservation IDs that it writes to the class
attribute.
This modifier provides flexibility to deal with the fact that the User-Name in the 3G/
4G HA Access-Request may contain either the pseudo-identity or PANI depending
on operator deployment and subscriber provisioning.
Values:
• false: the RADIUS Server uses the subscriber’s pseudo identity
• true: the RADIUS Server uses the subscriber’s PANI instead of their
pseudo-identity
When set to “true” the User-Name in the Access-Request must contain the
subscriber’s PANI instead of their pseudo-identity.
• PANIPreferred: the RADIUS Server looks for the PANI first, and if it doesn’t find
it, looks for the subscriber’s pseudo-identity.
• PseudoPreferred: the RADIUS Server looks for the pseudo-identity first, and if it
doesn’t find it, looks for the subscriber’s PANI.
Default=false
Applies to the WiMAXLocalAA action.
• ALERT
• EMERGENCY
Example:
# log failed validation and reject
- - - LogMessage message="CSID length is not 10 or 15 digits long." priority=error
attrs=ID|555,CSID|$Calling-Station-Id,ESN|$STARENT:3GPP2-ESN,
UID|myVar:uid,SERVICE|PreAuth:$Configuration-Token
This action modifier generates an Access-Request that comprises two call events:
one database access for authentication and one for authorization. For the
PreAuthorize action, this action-modifier does not generate an Access-Request, but
is used to specify the RADIUS connection service profile from which to retrieve
preauthorization values.
Note For PreAuthorize actions, when a service modifier is not specified, no
service profile retrieval is performed.
- - - PreAuthorize getProxyService=y
- - - ProxyAA target=PreAuth:$BRIDGEWATER:Proxy-Target \
authorizeProxyLevel=PreAuth:$BRIDGEWATER:Authorize-Proxy-
Level
• attributes received from a PreAccounting action, and referenced using the
string ‘PreAcct’
Example:
- - - ProxyAcct target=PreAcct:$BRIDGEWATER:Proxy-Target
Required.
• creates the subscriber RMS SSR (RADIUS) session in the RMS cluster
associated with the NAS-IP-Address in the request or with the source IP
Address if the NAS-IP-Address is absent
When useMobileKey=n for WiMAXLocalAcct and the ACR message does not
contain the Acct-Multi-Session-ID attribute, the Service Controller:
• does not drop the ACR
• uses the pseudo-id from the User-Name attribute in the ACR to lookup RMS
sessions
rejectPolicy
The rejectPolicy modifies Access-Reject messages by inserting multiple service
AVPs into the Access-Reject message.
The PreAuthorize and Proxy policy actions support the rejectPolicy modifier to
specify reply message values when an Access-Reject is returned. For more
information, see "rejectPolicy and outageRejectMessage modifiers" on page 300.
The rejectPolicy file contains an ordered list of rules that are applied to
Access-Reject messages. Each rule consists of the following:
• Condition expression
• Action expression
Condition expression
The condition expression format for the rejectPolicy is:
<attribute> <operator> <value>
where
<attribute> is one of the following:
'Reject-Reason'
'-’
<operator> is one of the following:
Equals
'-'
<value> is one of the reasons specified in Table 106.
LockedUser The user has been locked by the user lockout feature.
NoRemoteEAPResponse Remote server did not respond in time for EAP phase
2 authentication.
Use the condition expression '- - -' to specify that there is no condition for the action
that follows. Use the condition expression '-' to specify that the condition always
evaluates to true.
Action expression
The action expression format for the rejectPolicy is:
<action-name> <action-modifiers...>
where
<action-name> is: SendReject
The SendReject action rejects the authentication request with a subscriber
message. Modify the SendReject action using the following optional action
modifiers:
• replyMessage=<Reject Message>
• serviceAVP=[vendorName:]<AVPname>=<AVPvalue>
replyMessage
The replyMessage modifier specifies that a text message, which can be one line of
ASCII text, is sent in the Access-Reject. If the line contains white space, the
message must be enclosed by single or double quotes.
Example:
Reject-Reason Equals InvalidUser SendReject replyMessage=16380
serviceAVP
Use the serviceAVP modifier to specify multiple RFC AVPs or vendor VSAs to
return in the Access-Reject message. When returning a non-RFC VSA, specify the
name of the equipment vendor, such as STARENT.
Optional.
Example:
Reject-Reason Equals InvalidPassword SendReject replyMessage=16381
serviceAVP=STARENT:Password-Retry=5
4 In the same directory, open the rejectPolicy file and configure the policy
according to the appropriate access reject reasons.
Optionally, return one or more service AVPs with the Access-Reject message
by using the serviceAVP modifier.
Example:
Reject-Reason Equals InvalidUser SendReject replyMessage=16380
Reject-Reason Equals InvalidPassword SendReject replyMessage=16381
serviceAVP=STARENT:Password-Retry=5
5 Save the file and exit.
6 Send a HUP signal to the radiusd process for the changes to take effect.
Example:
pkill -HUP radiusd
Overview
PreAuthorize policy actions enable operators to perform Access Control Limit
checks, such as Port Quota Control checks, prior to performing a proxy action. If the
ACL check passes, the Service Controller (SC) can proxy the request to a customer
AA server. If the ACL check fails, the Service Controller returns an Access-Reject
with an optional, and configurable Reply-Message.
To enable the ACL evaluations, configure an Access Control service (see the
chapter “Managing Access Controls” in the Service Manager: Services Provisioning
Guide for AAA) and specify it in the PreAuthorize policy action using the “acService”
modifier. Optionally, use the “service” modifier to authorize the subscriber against a
specified service.
Note The RADIUS Server issues an error log at startup or HUP if the service
specified by either the “acService” or the “service” modifier is not
configured in the database.
Note Only Access Control Limits (ACLs) assigned to the PreAuthorize action are
performed. ACLs specified in subsequent policy lines are ignored.
acService modifier
When using the PreAuthorize policy action to perform ACL checks, the acService
modifier specifies the name of the Access Control service profile that is assigned to
the subscriber by the PreAuthorize policy. If the acService is not configured for the
PreAuthorize policy action, the system does not perform PQC validation. If the
acService modifier is configured but the PQC check fails, the Service Controller
returns an Access-Reject.
service modifier
Authorizes a RADIUS Connection Service against the PreAuthorize action. In the
following example, the PreAuthorize action triggers the Port Quota Control check. If
it passes, the Service Controller attempts to authorize based on the User-Name
and the S2 RADIUS Connection Service.
Optional.
Example:
Service-Type Equals 10 PreAuthorize acService=PortQuotaCheck service=S2
For more information and examples, see the section "Examples of PreAuthorize
and Proxy actions using ACLs" on page 298.
RMS sessions
When a ACL check passes during a PreAuthorize policy action, RMS creates a
session. If the final policy action returns an Access-Reject, RMS deletes this
session.
PreAuth using ACL This policy example incorporates the PortQuotaControl check, ProxyAA,
and proxy rejectPolicy, and SendReject with a reply message.
Example:
Service-Type Equals 10 PreAuthorize acService=PortQuotaCheck
loginName=$Called-Station-Id rejectPolicy=y
- - - ProxyAA outageAction=SendReject rejectPolicy=y =T1
- - - SendReject Reject-Reason Equals ProxyTimeout replyMessage="Remote
target is unavailable."
In this example, the “acService” action modifier requests a Port Quota Check to see
if the customer ISP’s port quota has been exhausted. If the PQC check passes, the
Service Controller proxies the request to the specified target. If the T1 target is
unavailable, the Service Controller is configured to send an Access-Reject with the
reply message: “Remote target is unavailable”.
Evaluating the ACL The PreAuthorization policy can be configured in several ways depending on the
and proxying the subscriber’s need. Consider the following examples:
request • Specifying a backup service
• PreAuthorization service unspecified
• ACL not configured
Example 1 If the RADIUS Server primarily handles proxy requests, but also handles local
authentication requests, list all the proxy rules first and place a “catch-all” local
authentication rule at the end of the accessReqPolicy file. For example:
User-Name EndsWithCI @[Link] ProxyAA
target=proxytargetgroup
User-Name EndsWithCI @[Link] ProxyAA target=proxy2
...
- - - LocalAA
Example 2 If the RADIUS Server primarily handles local authentication requests, but also
handles proxy requests, list all the local authentication rules first and place a
“catch-all” proxy rule at the end of the accessReqPolicy file. For example:
User-Name EndsWithCI @[Link] LocalAA
User-Name EndsWithCI @[Link] LocalAA
...
- - - ProxyAA target=proxy-target
The RADIUS Packet Attribute Modifier Plugin feature provides a framework for
supporting VoIP and Prepaid applications. This feature enables RADIUS Server
policies to arbitrarily change the content of attributes under specified conditions. For
more details, contact Bridgewater Customer Support.
For example:
/opt/aaasc/radius/radpet -i [Link] -t auth -c
/opt/aaasc/conf/[Link] -d /opt/aaasc/config/radius
User-Name=username@[Link]
Note The radpet utility cannot decode the PreAuth: tag references extracted from
the PreAuthorize action and always evaluates to FALSE.
The radpet utility cannot decode HLRAuth: tag references and always
evaluates to FALSE.
Call check
A call check policy rule is used to check access controls to preauthenticate a
subscriber before the call is actually answered. For more details about call
checking, see "Preauthentication call checking" on page 7.
Define this policy rule:
User-Name Equals $Called-Station-Id CallCheckAA
authorizeDomain=[Link] authorizeLoginName=usera
authenticate=N
This policy rule preauthenticates subscribers within the [Link] domain,
checking access controls to verify that the session is allowed before the subscriber
is authenticated.
Define the access controls for each limit at the following levels:
• DefaultMaxSession—defined in the default Access Control level
• MaxSessionsPerDomainGroup—defined in the default Access Control or
Domain Group levels
• MaxSessionsPerDomain—defined in the default Access Control, Domain
Group or Domain levels
• MaxSessionsPerOrgGroup—defined in the default Access Control or the
Organization Group levels
• MaxSessionsPerOrg—defined in the default Access Control, Organization
Group or Organization levels
• MaxSessionsPerUser—defined in the default Access Control, Domain Group,
Domain, Organization Group, Organization, User Group or User levels.
Note To use the call check functionality, create a preauthentication connection
profile set. This profile set must be added to the User profile set of the
representative user.
Proxy by domain
Proxy access and accounting requests based on the subscriber’s domain. Define
this policy rule:
User-Name EndsWithCI @[Link] ProxyAA
target=proxytargetgroupA outageAction=SendReject
outageRejectMessage=”Please try dialing 800-675-8875”
In this example, the request is proxied to one of the RADIUS Servers listed in the
[Link] file for proxytargetgroupA. If none of the target servers in this group are
available, the Access-Request is rejected and the specified message is returned.
Default proxy
Define a default proxy so that when subscribers cannot be authenticated locally, the
Access-Request is proxied to a default remote server.
Include the defaultProxy=<target> action modifier in the policy rule. Then define
one or more RADIUS Servers for the target in the proxies file.
When the subscriber is authenticated by default proxy, perform local authorization
with a proxy subscriber account, as explained in "Service authorization for proxy"
on page 305. By default, the billing ID of this proxy subscriber account is used;
however, specify that this billing ID should be ignored with the
useAuthorizeBillingId=n parameter.
User-Name EndsWithCI @[Link] LocalAA
defaultProxy=ispconnect authorizeDomain=[Link]
authorizeLoginName=proxyuser useAuthorizeBillingId=n
Default domains
A default domain can be used when a service provider must transfer subscribers
from one system to another system. Create the subscriber accounts for these
subscribers under a single domain in system B. Then define a policy rule to assign
this domain to all subscribers who dial in to the NASs for system A.
Define the following rule in the accessReqPolicy file:
Client-IP-Address Equals [Link] LocalAA
appendDomain=[Link]
This rule appends the [Link] domain for any subscriber that dials in to this
NAS without providing a domain. The subscriber can then be authenticated based
on login name and this domain.
Basic communication 1 The authenticating peer and the authenticating server exchange identification
steps information during the link control phase.
2 The authenticating server and authenticating peer negotiate EAP and
exchange authentication information requests for authentication and responses
depending on the EAP type selected. The length and detail of the exchange
depends on the EAP type selected.
3 The authentication phase ends when the authenticating server sends a
success or failure packet to the authenticating peer.
The Service Controller RADIUS Server supports local EAP authentication for the
following EAP types:
• EAP-MD5-Challenge—duplicates Challenge Handshake Authentication
Protocol (CHAP) password protection on a Wireless Local Area Network
(WLAN)
• LEAP—Lightweight Extensible Authentication Protocol (LEAP) is Cisco’s
protocol for PPP authentication that supports mutual authentication between
the Cisco Access Point (AP) and RADIUS. In addition, a dynamic WEP session
key is generated.
• PEAP—Protected EAP. A secured TLS tunnel is established using a
server-side certificate. Client authentication occurs over this tunnel. PEAP
supports EAP methods through this tunnel including MSCHAP-v2.
• EAP-TLS—Extensible Authentication Protocol Transport Level Security. Client
and server authenticate each other using certificates.
• EAP-TTLS—Tunneled Transport Layer Security. A secured TLS tunnel is
established using a server-side certificate.
– The server may authenticate the client using a certificate or, if there is no
certificate, for RADIUS, using PAP/CHAP/MSCHAPv1 or v2, or EAP.
EAP proxy
This section provides information about RADIUS and Diameter EAP proxy.
RADIUS proxy mode In addition to supporting EAP-MD5, PEAP, EAP-TLS, EAP-TTLS, MSCHAP, and
LEAP local authentication, the Service Controller RADIUS Server supports all EAP
types in proxy mode.
Note In a WiMAX environment RADIUS only supports CHAP and MSCHAPv2 for
phase 2 of EAP-TTLS.
The Service Controller sends the RADIUS-encapsulated EAP packets between the
Access Point (AP) and an EAP-supported RADIUS Server. Two attributes are sent
during proxy from RADIUS to the authentication RADIUS Server if they are
received from the AP: EAP-Message and Message-Authenticator. The remote
EAP-supported RADIUS Server selects which EAP type to apply for the user.
Depending on the type of EAP authentication, the actual authentication may be
done on an EAP-supported RADIUS Server or on a backend server.
The following example policy configures local authentication on an EAP-supported
RADIUS Server:
EAP-Message Appears Once LocalAA EAP-Policy=LEAP
where
LEAP is a type-selection-policy name entry in the [Link] configuration file
The following example policy configures proxying to a remote third-party EAP-
supported RADIUS Server:
EAP-Message Appears - ProxyAA target=EAPRadius
authorizeLoginName=repuser AuthorizeDomain=[Link]
In the [Link] file, define EAPRadius as the TargetName, for example:
<ProxyTargetConfiguration ProxyTimeoutFactor=”100”>
<RADIUSServer
TargetName="EAPRadius"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="5"
AccountingPort="1813"
AuthenticationPort="1812"
MaxRetries="1"
OverwriteIP="Y"
StripDomain="N"
DigitizeAcctSessionID="Y"
/>
</ProxyTargetConfiguration>
Diameter proxy For information about Diameter proxy mode, see "Configuring Diameter EAP-TTLS
mode phase 2 proxy to RADIUS AAA" on page 158, and see the chapter “EAP-TTLS” in
the Extensible Authentication Protocol Guide.
PreAccounting
PreAccounting performs subscriber pre-authorization prior to completing an
accounting action. The usage and behaviour of PreAccounting are identical to
Preauthorization but apply to accounting-request messages. For more information,
see "Preauthorization" on page 315.
- - - PreAccounting service=ServiceA
Preauthorization
Preauthorize a subscriber by retrieving information from the Profile Database and
by comparing this information to a value from a specified connection service profile.
In ACL deployments, use PreAuthorize to check Access Control Limits as well as to
authorize against a specified RADIUS Connection Service prior to proxying a
request to a customer AA server.
In either case, policy evaluation may continue after executing a PreAuthorize policy
action. The PreAuthorize action is described in Table 96 on page 240 and in
"Configuring PreAuthorize using Access Control Limits (ACL) for proxy" on page
297.
Note The Service Controller only stores the attributes retrieved by the most
recently executed PreAuthorize policy rule.
A PreAuthorize action must include one of the following action modifiers, otherwise
the RADIUS Server fails to start:
• service
• acService
• getProxyService
PreAuth: tag Use the PreAuth: tag to indicate that the attribute comparison should occur against
the attribute retrieved from the RADIUS connection service profile specified by the
preceding PreAuthorize policy rule. If the PreAuth: tag is not specified, the attribute
comparison occurs against the attribute received from the Access-Request.
In this annotated example, ServiceA is provisioned with a Callback-Id of 123, and
ServiceB is provisioned with a Callback-Id of 456:
--- PreAuthorize service=ServiceA
Retrieves attribute value pairs from a service profile called ServiceA.
PreAuth:STARENT:Callback-Id Equals 123 PreAuthorize
service=ServiceB
Attempts to match the retrieved ServiceA Callback-Id against a given value, “123”.
The ServiceA Callback-Id does equal 123, so the Service Controller returns the
ServiceB attributes.
PreAuth:STARENT:Callback-Id Equals 123 PreAuthorize
service=ServiceC
Attempts to match the retrieved ServiceB Callback-Id against a given value, “123”.
The ServiceB Callback-Id does not match the given value, so the policy line is not
executed.
--- LocalAA
Catch-all rule to perform local authentication.
Using myVar and In this example, this policy compares the Calling-Station-Id to the preauthorization
rejection messages Callback-Number, and returns an error if the values don’t match:
- - - AssignVar myVar=myCallingID:$Calling-Station-Id
- - - PreAuthorize service=HRPD
myVar:myCallingID Equals PreAuth:$Callback-Number LocalAA
- - - SendReject replyMessage="AVP verification failed"
HLR authorization
The GSMLocalAA action supports the retrieval of subscriber profile information
from an HLR using the hlrAuthorization action modifier. If the hlrAuthorization action
modifier is set to Generic, the Service Controller stores the following values
retrieved from the HLR in Bridgewater VSAs:
• Bearer Services (WLAN-HLR-BS)
• Tele Services (WLAN-HLR-TS)
• Operator Determined Barring (WLAN-HLR-ODB)
If the GSMLocalAA action is configured with the authorizationPolicy action modifier,
the corresponding Bridgewater VSAs can be referenced in the authorization policy
to perform additional decisions. For specific examples, see "authorizationPolicy" on
page 267.
HLRAuth: tag Use the HLRAuth: tag to indicate that the attribute comparison should occur against
an attribute injected with data retrieved from an HLR. If the HLRAuth: tag is not
specified, the attribute comparison occurs against the attribute received from the
Access-Request.
3 Assign the RADIUS Connection Service Profile from step 2 to a user profile set.
For more information about configuring a RADIUS Connection Service Profile
and a user profile set, see:
– the chapter “Managing service profiles” in the Service Manager: Subscriber
Provisioning Guide for AAA
– the chapter “RADIUS connection service” in the Service Manager: Services
Provisioning Guide for AAA.
Overview
Use policy configuration to detect a mismatch between the value of the
Calling-Station ID supplied in a subscriber’s Access-Request message and the
Mobile-Station ID provisioned in a subscriber’s profile. The subscriber’s profile is
stored in the LDAP database.
CSID/MSID mismatches can be caused by:
• copying one subscriber’s credentials {network access identifier (NAI) and
password} to another subscriber’s device
• activating a subscriber device that was previously provisioned with another
subscriber’s credentials
• IT systems improperly re-setting subscriber/device credentials
Note To use this feature, the [Link] file must be configured with an IMSI
service profile that contains attributes that match to those contained in the
subscriber profile, which is stored in the LDAP database. Typically these
attributes are the MSID and either the MEID or the ESN.
Validation process
When you configure CSID/MSID mismatch detection, the Service Controller
evaluates subscriber requests based on the options specified in the Mismatch
Detection policy files you create.
$FFHVV5HT3ROLF\
3UH$XWKSROLF\
IRU0(,'(61
9DOLGDWLRQ 'RHVWKH
RSWLRQV 1R /RJ 5HMHFW
&6,'
PDWFKWKH06,'"
&RQILJXUDEOH
&RQWLQXH
<HV
'RWKHODVW
GLJLWVLQWKH&6,' 1R /RJ 5HMHFW
VWDUWZLWKWR"
&RQILJXUDEOH
&RQWLQXH
<HV
,IWKHUHTXHVW
FRQWDLQVDQ0(,'RU
(61GRHVLWPDWFKWRWKH 1R /RJ 5HMHFW
VWRUHGSURILOH"
&RQILJXUDEOH
&RQWLQXH
<HV
&RQILJXUDEOH
&RPSOHWHVWDQGDUG &RQILJXUHWKHSROLF\WRFUHDWHDORJDQGHLWKHU
SROLF\H[HFXWLRQ UHMHFWWKHXVHURUFRQWLQXHWKHSROLF\HYDOXDWLRQ
Configuration options
Configure any or all of the validation options described in the section “"CSID
validation options" on page 320”.
For each option, you can configure CSID/MSID mismatch detection to:
• log an error and continue validating
or
• log an error and reject the request
For example, you can configure policy to log an error and reject a request as soon
as the feature detects a mismatch.
Configuring the Configure the primary policy file, such as accessReqPolicy, to evaluate specified
primary policy file subscribers using the Mismatch Detection policy file.
Make sure to specify the:
• PreAuthorize policy action, which enables the Service Controller to retrieve the
appropriate attributes from the LDAP database
• policy file in which CSID/MSID mismatch detection is evaluated
In the following example, the Service Controller evaluates policy using the
Mismatch Detection policy file for all subscribers that belong to the realm
“@[Link]”:
- - - PreAuthorize service=IMSI returnAVPs=n continueNotFound=y
loginName=$User-Name
User-Name EndsWithCI @[Link] PolicyRun
evaluatePolicy=MismatchDetection
- - - PolicyRun evaluatePolicy=ExistingPolicies
Creating the CSID Create a CSID Mismatch Detection policy file that is used to compare the CSID
Mismatch Detection received in a subscriber’s Access Request message to the MSID attribute in the
policy file subscriber’s profile stored in the LDAP database.
Note Make sure to save the CSID Mismatch Detection policy file to your policy
file directory, such as /opt/aaasc/config/radius.
In this policy file:
• specify each validation option and provide the associated actions and action
modifiers as specified in the example file below
• for mismatches, configure each validation option to do one of the following:
– generate a custom log and continue validating
– continue validating without generating a log
– generate a custom log and reject the request
– reject the request without generating a custom log
• for each validation option configured to “log and continue validating”, create a
custom log message
• for each validation option configured to “log and reject” a request, point to the
associated “log and reject” policy file
• [optional] for MEID/ESN validation, point to the MEID and ESN Mismatch
Detection files
• point to standard policy file(s) that must be executed after CSID/MSIDmismatch
detection completes
In the following example, all “CSID/MSID mismatch detection” validation options are
evaluated. All validation options are configured to “log and reject” the request when
a mismatch is detected.
Each validation option is introduced by a comment, such as:
# validate mismatch_detection_option
where:
mismatch_detection_option defines the validation option
For more information about the conditions, actions, and action modifiers used in the
following example, see:
• "Conditions" on page 235
• "Actions" on page 239
• "Action modifiers" on page 262
CSID Mismatch Detection policy file example
# validate that the CSID exists
Calling-Station-Id Appears Never PolicyRun evaluatePolicy=CSIDMissing
# validate that the last 10 digits of the received CSID is equal to last 10 digits of the
MSID (provisioned)
- - - AssignVar extractAttr=Calling-Station-Id extractReg=([0-9]{10})$
myVar=LastTenCSID:${1} continuePreProcessing=y ignorePreProcessingFailure=y
- - - AssignVar extractAttr=PreAuth:$STARENT:Prov-IMSI extractReg=([0-9]{10})$
myVar=LastTenMSID:${1} continuePreProcessing=y
ignorePreProcessingFailure=y
myVar:LastTenCSID NotEquals myVar:LastTenMSID PolicyRun
evaluatePolicy=CSIDMSIDMatchFail
# validate the first 3 digits of the last 10 digits of the received CSID is in the range of
201-989 inclusive
Calling-Station-Id RegExp [01][0-9][0-9][0-9]{7}$|200[0-9]{7}$|99[0-9][0-9]{7}$
PolicyRun evaluatePolicy=CSIDRangeFail
- - - PolicyRun evaluatePolicy=ExistingPolicies
where:
ExistingPolicies describe any standard policies that need to be executed
Creating MEID and For Access-Request messages that contain an MEID or an ESN, create separate
ESN mismatch mismatch detection policy files to validate the MEID and ESN attributes.
detection files Note Make sure to save the MEID and ESN Mismatch Detection policy files to
your policy file directory, such as /opt/aaasc/config/radius.
For more information about the conditions, actions, and action modifiers used in the
following examples, see:
• "Conditions" on page 235
• "Actions" on page 239
• "Action modifiers" on page 262
Creating “log and For each validation option configured to “log and reject” a request when a
reject” policy files mismatched attribute value is detected, create an associated “log and reject” policy
file that specifies the:
• LogMessage policy action, which generates a custom log message
• “message” action modifier whose value is the custom message describing the
error
• [optional] “priority” action modifier set to the log level, such as INFO
• [optional] “attrs” action modifier that specifies the attributes and values you
want to expose in the log
• replyMessage to be included in the Access-Reject message
Note Make sure to save “log and reject” policy files to your policy file directory,
such as /opt/aaasc/config/radius.
The following examples show how to create a “log and reject” policy file for each
validation option described in "CSID validation options" on page 320.
Creating custom log Use the LogMessage action and appropriate action modifiers, such as “message”,
messages to generate a custom log message when a mismatch is detected.
For validation options that are configured to “log and continue validating”:
• add the LogMessage action and appropriate action modifiers to each section of
the CSID Mismatch Detection policy file that defines a specific validation option
For validation options that are configured to “log and reject” the request:
• add the LogMessage action and appropriate action modifiers to each “log and
reject” policy file associated with mismatched validation options
When a custom log is configured for a validation option and the system detects a
mismatch, the system writes the associated custom log message to the RADSYS
log family.
- - - AssignVar extractAttr=Calling-Station-Id
extractReg=([0-9]{10})$ myVar=LastTenCSID:${1}
continuePreProcessing=y ignorePreProcessingFailure=y
- - - AssignVar
extractAttr=PreAuth:$STARENT:Calling-Station-Id
extractReg=([0-9]{10})$ myVar=LastTenMSID:${1}
continuePreProcessing=y ignorePreProcessingFailure=y
— if the values do not match, the subscriber is not in their home zone, and
RADIUS sends an Access-Reject
- - - AssignVar extractAttr=STARENT:3GPP2-Subnet
extractReg="(([0-9a-zA-Z]{49})([0-9a-zA-Z]{9}))"
myVar=mySubnetId:${3}
- - - PreAuthorize service=Subnetvalidation returnAVPs=n
continueNotFound=y myVar:mySubnetId Equals
PreAuth:$STARENT:3GPP2-Subnet CDMA2000LocalAA
service=PFD-V2-ST-SP
- - - SendReject replyMessage="Not in Zone1"
2 Provision the 3GPP2-Subnet Sector ID in a RADIUS Connection Service
Profile.
When provisioning the 3GPP2-Subnet Sector ID in Service Manager the format
must be the same as that expected in the Access-Request.
— For example if the 3GPP2-Subnet string in the Access-Request message is
011368008E7E039FA1F501AC1D8D3E520000000212008E7E039FA1F50
1, the RADIUS Server extracts the Sector ID value 39FA1F501, and
matches the extracted value with the value provisioned in Service Manager.
— In this case, provision the 3GPP2-Subnet Sector ID in Service Manager as
39FA1F501.
3 Assign the RADIUS Connection Service Profile from step 2 to a user profile set.
For more information about configuring a RADIUS Connection Service Profile
and a user profile set, see:
– the chapter “Managing service profiles” in the Service Manager: Subscriber
Provisioning Guide for AAA
– the chapter “RADIUS connection service” in the Service Manager: Services
Provisioning Guide for AAA.
8
Chapter 8
Chapter
target groups
This chapter describes proxy targets, proxy target groups, and how to configure
them.
The topics are:
• Proxy overview
• Attribute filters
• Proxy configuration file
• Proxy target configuration considerations
• Filter examples
• Proxy target server and group examples
• Manually locking and unlocking a proxy target
• Configuring attribute manipulation
Proxy overview
Proxy targets and proxy target groups are defined within RADIUS [Link] or by
provisioning RADIUS Servers and RADIUS Server groups using the Service
Manager. For proxy targets or groups that are RADIUS servers, you can configure
attribute filters to control which attributes of an outgoing request are proxied to a
remote server and which attributes of the incoming response are returned to the
client.
Note Configure RADIUS Servers, RADIUS Server Groups, proxy filters, proxy
override attribute groups, and proxy required attribute groups using either
the [Link] file or the Service Manager. Both methods cannot be used.
After purchasing the BWSoaaapdb Proxy Database Configuration optionality
package, see the section “Managing proxy targets and filters” in the chapter
“Managing Systems” in the Service Manager: Network Access Guide for AAA to
find more information about provisioning proxy targets and proxy filters using the
Service Manager.
Note Before configuring proxy deployments using the Service Manager, set the
ReadProxyConfigFromDB attribute in the [Link] file to ‘Y’.
Proxy targets
Valid proxy targets are RADIUS servers, LDAP servers, and SecurID servers. For
each proxy target, you define connectivity parameters and the conditions under
which the server is marked as inactive or unreachable based on the number of
consecutive failed retries or the number of failed retries in a configurable time
period. For more information, see "Manually locking and unlocking a proxy target"
on page 379.
When a proxy target is locked out due to intermittent failure, it is only reflected in the
MIB variables when the next Access-Request is received after the lockout state
change occurs.
For manual proxy target lockouts, the RadiusClientGroupUnlockedTargets metric is
not updated until the Access-Request is received. This same behavior occurs when
a proxy target is manually unlocked.
Both situations are only noticeable under very light or sporadic load.
Note If RADIUS receives a HUP signal, it resets all knowledge of the consecutive
or intermittent failure events that determine whether a proxy target should
be locked.
The proxy target element and attributes are described in "RADIUSServer" on page
352. For example proxy target element definitions, see "Proxy target server and
group examples" on page 376.
For information about provisioning proxy targets and groups using the Service
Manager, see the chapter “Managing proxy targets and filters” in the Service
Manager: Network Access Guide for AAA.
Attribute filters
On RADIUS targets and target groups, define filters in [Link] to modify
attributes in the outgoing and incoming proxy messages, for example, to remove
unwanted or unsupported attributes.
As shown in Figure 33, the attribute filters can be applied to proxy requests or proxy
responses or both, and can be defined on the proxy targets or proxy target groups.
Figure 33: Attribute filtering flow
2XW$FWLRQ
&OLHQW )LOWHUDWWULEXWHVLQ 3UR[\
UHTXHVW DXWKHQWLFDWLRQDQG UHTXHVW
DFFRXQWLQJPHVVDJHV
5$',86 3UR[\
&OLHQW
6HUYHU 7DUJHW
,Q$FWLRQ
&OLHQW )LOWHUDWWULEXWHVLQ 3UR[\
UHVSRQVH DXWKHQWLFDWLRQ UHVSRQVH
PHVVDJHV
The core element of a filter is one or more attribute value pairs that are allowed,
denied, or modified in the message. When specifying an attribute value pair, the
name of the attribute must match the name in the vendor dictionary. A filter cannot
contain multiple entries for the same attribute.
An attribute value pair can include subtypes but only if the filter is configured using
[Link]. Filtering based on AVP subtypes is not supported in Service Manager.
In many scenarios, multiple filters on different attributes are required to accomplish
a goal. For example, to properly deny login services, a network administrator would
define a filter to prevent the remote server setting the Service-Type attribute to
“Login”, as well as filters to deny the Login-IP-Host, Login-TCP-Port, and
Login-Service attributes.
Note If a filter is defined on both a proxy server and a proxy group containing the
same server and messages are directed to the proxy group, the filter
provisioned on the group overrides the filter provisioned on the individual
target. This precedence applies to the entire filter, not to the individual
attributes.
[Link] schema
The [Link] schema contains these elements:
ProxyTarget Configuration: The root element
Filter
AVP
ExceptionVal
ExceptionRange
ExceptionRegExp
OverrideAttribute
Override
DataValue
AttributeValue
RegExValue
Condition
Matches
AttributeValue
DataValue
RegExValue
Required Attributes
Reqd
RADIUSServer
InAction
OutAction
RADIUSServer Group
SecurIDServer
SecurIDServer Group
LDAPServer
ServiceAVP
LDAPServerGroup
ServiceAVP
ProxyTimeout Integer The time RADIUS waits for a proxy response is:
Factor (1–100) RequestTimeout / ProxyTimeoutFactor.
Default=1 Used only by the RADIUSServer element to provide finer grain
timeout values for both authentication and accounting requests.
Optional.
Filter Defines which attribute values are sent or returned in a proxied message. A Filter
may be applied to an InAction or OutAction proxy attribute filter child element within
a RADIUSServer or RADIUSServerGroup element.
• The Filter element may enclose one or more AVP child element.
• The filter cannot contain multiple entries of the same AVP.
Child element of ProxyTarget Configuration.
For example:
<Filter FilterName="AuthFilter" Action="Deny">
<AVP AttrName="Framed-Pool" Action="Deny"/>
<AVP AttrName="Framed-IP-Address" Action="Allow">
<ExceptionRegExp Pattern="255\.255\.255\.(.*)"/>
</AVP>
<AVP Attrname=”WiMAX-QoS-Descriptor:Schedule-Type” Action=”Allow”>
<ExceptionVal Value=”4”/>
</AVP>
</Filter>
AVP Defines Attribute Value Pair (AVP) and subtype values to include in the
RADIUSServer or RADIUSServerGroup filter.
Considerations:
• in each filter, there cannot be multiple entries of the same AVP.
• AVPs with cannot have separate entries for the AVP and for its subtypes. There
must be either one entry for the AVP, or entries for the AVP subtypes.
• the AVP element can enclose zero or more ExceptionVal, ExceptionRange,
and/or ExceptionRegExp child elements.
• AVPs with subtypes cannot specify ExceptionVal, ExceptionRange, and
ExceptionRegExp against the AVP. AVPs with subtypes can only specify the
exceptions against the subtypes.
• Actions specified for a subtype of an AVP apply against the AVP itself
Child element of Filter.
Example filter
The following example includes:
• an AVP (AttrName1)
• an AVP with two subtypes (AttrName2)
<Filter FilterName="Filter1" Action="Deny">
<AVP AttrName="AttrName1" Action="Deny"/>
<AVP AttrName="AttrName2:Subtype1" Action="Allow">
<ExceptionRegExp Value="255\.255\.255\.(.*)"/>
</AVP>
<AVP AttrName="AttrName2:Subtype2" Action="Allow">
<ExceptionRange Start="1" End="4"/>
</AVP>
</Filter>
For more examples of filter configurations, see "Filter examples" on page 372.
Action • Allow Action at the AVP attribute or subtype level, which takes
• Deny precedence over the action at the filter level.
The AVP action is taken when no exception criteria are explicitly
met for the value of the attribute or subtype.
Required.
AttrName • String The name of the attribute to be added to the proxy request.
(1–256 characters) For AVPs with subtypes you can also specify the subtype as part
Format: String[:String …] of the AttrName and can filter AVPs based on their subtypes.
• attributes are delimited from subtypes by a colon
• you can apply exceptions to AVP subtypes
• you can specify a sub-subtype
Example formats:
<AVP AttrName="AttrName1 Action="Allow/>
<AVP AttrName="AttrName1:Subtype" Action="Allow/>
Required.
VendorName • String The *.DICT file that contains the attribute’s definition.
(1–256 characters) Only used if the attribute is vendor-specific.
Default=RFC2138 Not required for RFC attributes or for subtypes.
Optional.
ExceptionVal A value that is an exception to the action specified in the AVP element. Exceptions
are supported for attributes and subtypes.
AVPs with subtypes cannot specify ExceptionVal against the AVP. AVPs with
subtypes can only specify the ExceptionVal against the subtypes.
Child element of AVP.
Example:
<AVP AttrName="Service-Type" Action="Allow">
<ExceptionVal Value="1" />
</AVP>
<AVP AttrName="Callback-Id" Action="Allow">
<ExceptionVal Value="123456789" />
</AVP>
<AVP Attrname=”WiMAX-QoS-Descriptor:Schedule-Type” Action=”Deny”>
<ExceptionVal Value=”4”/>
</AVP>
ExceptionRange A value range that is an exception to the action specified in the AVP element.
AVPs with subtypes cannot specify ExceptionRange against the AVP. AVPs with
subtypes can only specify the ExceptionRange against the subtypes.
Child element of AVP.
Example:
<AVP AttrName="Service-Type" Action="Deny">
<ExceptionRange Start="1" End="4"/>
<ExceptionVal Value="6" />
</AVP>
<AVP Attrname=”WiMAX-QoS-Descriptor:Schedule-Type” Action=”Deny”>
<ExceptionRange Start="1" End="4"/>
</AVP>
ExceptionRegExp A regular expression that is an exception to the action specified in the AVP element.
AVPs with subtypes cannot specify ExceptionRegExp against the AVP. AVPs with
subtypes can only specify the ExceptionRegExp against the subtypes.
Child element of AVP.
Example:
<AVP AttrName="SSG-Service-Info" VendorName="CISCO" Action="Deny">
<ExceptionVal Value="Prepaid" />
<ExceptionRegExp Value="DATA|MMS|WAP"/>
</AVP>
<AVP Attrname=”WiMAX-QoS-Descriptor:Schedule-Type” Action=”Deny”>
<ExceptionRegExp Value="DATA|MMS|WAP"/>
</AVP>
• If the RADIUS Server injects the Class or Proxy-State attributes in the reply
packet, the RADIUS Server marks these attributes as local data so that they
are not proxied to remote servers in subsequent messages.
• If the State attribute is specified as an OverrideAttribute in a proxy filter, the
RADIUS Server only adds its value to the reply packet if there is no State
attribute already present.
Example:
<OverrideAttributes Name="Assign">
<Override
AttrName="Ascend-Primary-Dns"
VendorName="Ascend"
Precedence="Filter"
Mandatory="Y">
<AttributeValue
AttrName="Unisphere-Primary-Dns"
VendorName="Juniper"/>
</Override>
</OverrideAttributes>
Element or
Value Description
Attribute
Mandatory="Y">
<Condition>
<Matches.../>
</Condition>
Complex example:
• A proxy request contains a NAS-IP-Address attribute with the value
[Link] and an Acct-Session-Id attribute with the value of
abcdef01234567890.
• When the request is proxied through a target assigned with the overrides
shown in the following example, the value of the outgoing Acct-Session-Id is:
3232274276[]abcdef01234567890.
<OverrideAttributes Name="Acct_Session_Id">
<Override
AttrName="Acct-Session-Id"
Precedence="Filter"
Mandatory="Y">
<AttributeValue
AttrName="NAS-IP-Address"
From="ProxyRequest"
Type="String"/>
<DataValue Type="String">[]</DataValue>
<AttributeValue
AttrName="Acct-Session-Id"
From="ProxyRequest"/>
</Override>
</OverrideAttributes>
Note The final value of an Override XML element cannot exceed the following
maximum lengths:
string — 253 bytes
integer — 4 bytes
ipv4addr — 4 bytes
ipv6addr — 16 bytes
AttrName • String The name of the attribute value pair (AVP) to be added/modified
(1–256 characters) to the proxy message.
Required.
Precedence • Filter Determines whether or not to replace the original attribute value.
• Packet Only applies to override attributes that exist in the client request.
Default=Filter Values:
• Filter: the override value replaces the attribute value in the
request and is sent to the proxy target
• Packet: the original attribute in the client request is unchanged
and is sent to the proxy target
Precedence does not apply if the attribute is not in the original
message.
Optional.
Mandatory • Y (Default) Determines the behavior of the override if the attribute does not
• N exist in the original packet or has been filtered out by the Proxy
Filter:
• Y: insert the attribute AttrName into the request to the proxy
target (use the DataValue, AttributeValue, RegExValue, or
Condition child elements to provide a value)
• N: do not insert the attribute into the request
Optional.
<DataValue Type="Binary">0123456789ABCDEF</DataValue>
Note The characters “&”, “<“, and “>” are illegal in XML syntax. To define a string
override with any of these values, use “&”, “<“, and “>” without
quotes.
Type • Integer (4 byte integer) Interpret this attribute as the specified type, such as String.
• String (ASCII) Allows the flexibility to convert integer attributes to strings and
• IPv4 (4 byte integer) string attributes to integer.
• IPv6 (16 byte integer)
Required.
• Binary (ASCII-Hex)
No default value
AttrName • String The name of the AVP (as it appears in the dictionary for the
(1–256 characters) specified vendor) whose value is used as an override.
Required.
VendorName • String The *.DICT file that contains the attribute’s definition.
(1–256 characters) Only used if the attribute is vendor-specific.
Default=RFC2138 Not required for RFC attributes.
Optional.
Type • Integer (4 byte integer value) Interpret this attribute as the specified type, such as String.
• String (ACSCII) Allows the flexibility to convert integer attributes to strings and
• IPv4 in dot notation format string attributes to integer.
• IPv6 in dot notation format If a type is not specified, the default type is taken from the
• Binary (ASCII-Hex) RADIUS dictionary.
Optional.
From • ProxyRequest Identifies which RADIUS packet contains the attribute whose
• ProxyResponse (default) value must be replaced.
ProxyRequest — the packet received from the RADIUS client.
ProxyResponse — the packet received from the proxy server.
Optional.
RegExValue examples
Treat the value of the Framed-IP-Address attribute as an IPv4 string and re-arrange
the octets ([Link] ' [Link]):
<RegExValue
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="(\d{1,3})\.(\d{1,3})\.(\d{1,3})\.(\d{1,3})">
${4}\.${3}\.${2}\.${1}
</RegExValue>
Extract the login-name portion of the User-Name attribute:
<RegExValue
AttrName="User-Name "
StringFormat="String"
Pattern="(([^\\]*)\\){0,1}([^@]*)(@(.*)){0,1}">
${3}
</RegExValue>
Change the case of the Calling-Station-Id to lower case, insert colons between
octets, and override the value of the User-Name attribute with the re-formatted
value of Calling-Station-Id:
<OverrideAttributes Name="Renaming">
<Override AttrName="User-Name">
<RegExValue AttrName="Calling-Station-Id" StringFormat="String"
Pattern="(.{2})(.{2})(.{2})(.{2})(.{2})(.{2})">
{strtolower}${1}:${2}:${3}:${4}:${5}:${6}
</RegExValue>
</Override>
</OverrideAttributes>
AttrName • String The name of the AVP (as it appears in the dictionary for the
(1–256 characters) specified vendor) whose value is applied to the regular
expression’s Pattern modifier.
Required.
VendorName • String The *.DICT file that contains the attribute’s definition.
(1–256 characters) Only used if the attribute is vendor-specific.
Default=RFC2138 Not required for RFC attributes.
Optional.
StringFormat • Integer (treated as a 4 byte The format that is used to interpret the Pattern modifier.
integer, then converted to an Integer — treat the value of the attribute identified by the
ASCII string) AttrName XML attribute as a string of ASCII numbers.
• String (ASCII)
String — treat the value of the attribute identified by the AttrName
• IPv4 (treated as a 4 byte
XML attribute as ASCII.
integer, then converted to an
IP address in dot notation) IPv4 — treat the value of the attribute identified by the AttrName
• IPv6 (treated as a 16 byte XML attribute as a string in IPv4 dot notation
binary string, then converted IPv6 — treat the value of the attribute identified by the AttrName
to an IP address in dot XML attribute as a string in IPv6 dot notation.
notation) BinaryHex — treat the value of the attribute identified by the
• BinaryHex (treated as a binary AttrName XML attribute as ASCII-hex encoded.
string, then converted to
ASCII-Hex) Required.
From • ProxyRequest Which RADIUS packet contains the attribute identified by the
• ProxyResponse (Default) AttrName XML attribute.
Optional.
Pattern • A regular expression APOSIX regular expression (man -s5 regex) that is applied to the
value of the AVP (identified by the AttrName modifier).
Required.
Condition Assigns override values. Similar to an if/else construct, each child element defines
a logical expression that, if satisfied, provides a value to override the original value.
If the logical expression is not satisfied, the next logical expression is evaluated. If
no logical expression can be satisfied, the condition has no value. Logical
expressions are defined using the Matches element.
The Condition element encloses one or more Matches elements.
Child element of Override.
Example:
<Override
AttrName="Framed-Pool"
Precedence="Filter"
Mandatory="Y">
<Condition>
<Matches.../>
</Condition>
</Override>
The <Condition> element has no modifying attributes.
Matches A condition which requires a RADIUS attribute value to match a specified pattern. If
the condition is satisfied, the value of the Matches element overrides the RADIUS
attribute value defined by the parent Override element.
The Matches element encloses one or more of the following child elements:
AttributeValue, DataValue, and/or RegExValue. For more information about these
child elements, see "AttributeValue" on page 346, "DataValue" on page 345, and
"RegExValue" on page 347.
Child element of Condition.
Simple match condition example:
If the value of the Framed-IP-Address (interpreted as IPv4 dot notation string
format) equals [Link], then the value of the condition is "pool_254":
<Condition>
<Matches
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="[Link]">
<DataValue Type="String">pool_254</DataValue>
</Matches>
</Condition>
AttrName • String The name of the AVP (as it appears in the dictionary for the
(1–256 characters) specified vendor) whose value is applied to the regular
expression’s Pattern modifier.
Required.
VendorName • String The *.DICT file that contains the attribute’s definition.
(1–256 characters) Only used if the attribute is vendor-specific.
Default=RFC2138 Not required for RFC attributes.
Optional.
StringFormat • Integer The format that is used to interpret the Pattern modifier.
• String Values:
• IPv4
• Integer: treat the value of the attribute identified by the
• IPv6
AttrName XML attribute as a string of ASCII numbers.
• BinaryHex
• String: treat the value of the attribute identified by the
AttrName XML attribute as ASCII.
• IPv4: treat the value of the attribute identified by the AttrName
XML attribute as a string in IPv4 dot notation
• IPv6: treat the value of the attribute identified by the AttrName
XML attribute as a string in IPv6 dot notation.
• BinaryHex: treat the value of the attribute identified by the
AttrName XML attribute as ASCII-hex encoded.
Required.
From • ProxyRequest Which RADIUS packet contains the attribute identified by the
• ProxyResponse (Default) AttrName XML attribute.
Optional.
Pattern • A regular expression A POSIX regular expression (man -s5 regex) that is applied to the
value of the AVP (identified by the AttrName modifier).
Required.
Required Attributes A list of AVPs that must exist in a RADIUS message. If one or more attributes do
not exist, the message is rejected (for an Access-Request message) or discarded
(for Accounting and DAE messages).
The RequiredAttributes element encloses one or more Reqd child elements.
Child element of ProxyTarget Configuration.
Example:
<RequiredAttributes Name="Acct_Session_Id">
<Reqd AttrName="Acct-Session-Id"/>
<Reqd AttrName="NAS-IP-Address"/>
</RequiredAttributes>
Name • String (1–256 characters) The list name for the AVPs that are required in the RADIUS message.
• The name must start with a Required.
letter (a-z, A-Z)
• Periods are permitted after the
first character
• Special characters and spaces
are not permitted
<RequiredAttributes Name="Required2">
<Reqd AttrName="Acct-Status-Type"/>
</RequiredAttributes>
VendorName • String The *.DICT file that contains the attribute’s definition.
(1–256 characters) Only used if the attribute is vendor-specific.
Default=RFC2138 Not required for RFC attributes.
Optional.
RADIUSServer A RADIUS proxy server and optional incoming or outgoing actions that it takes on
RADIUS messages. Each ProxyTargetConfiguration root element must enclose at
least one proxy target server (RADIUSServer, SecurIDServer, or LDAPServer) or
proxy target group (RADIUSServer Group, SecurIDServer Group, or
LDAPServerGroup) element.
Note Behaviour defined at the RADIUSServerGroup level takes precedence over
behaviour defined at the RADIUSServer level.
The RADIUSServer element encloses an optional InAction and an optional
OutAction child element.
Child element of ProxyTarget Configuration.
Example:
<RADIUSServer
TargetName="FilteredRadiusServer"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="2"
AccountingPort="1813"
AuthenticationPort="1812"
BindLocalIP=”[Link]”>
<InAction Filter="InFilter" />
<OutAction
Type="Auth"
Filter="GenericFilter"
OverrideAttributes="Override1"
RequiredAttributes="Required1"/>
<OutAction
Type="Acct"
Filter="AcctFilter"
RequiredAttributes="Required2">
</OutAction>
</RADIUSServer>
TargetName • String (1–256 characters) A unique identifier for the proxy target.
• Spaces are not supported Required.
DAEPort • Integer The port of the server to which CoA or DM messages are
Default = 3799 proxied.
Optional.
Secret • String (1–256 characters) Shared secret used when communicating with the target server.
Not used for LDAPServer elements.
Required for RADIUSServer and SecurIDServer elements.
RequestTimeout • Integer (1–65535) The maximum time, in seconds, that the RADIUS Server waits
for a response from the proxy target before it sends the request
to an alternate proxy server in the group or deals with the request
as defined in the policy rules.
WARNING: Failure to coordinate these parameters may result in
severe degradation of RADIUS performance.
For more information, see "RequestTimeout" on page 370.
Required.
AccountingPort • N (not set; default) UDP Port of the proxy target for accounting. The RFC standard
• Integer (1–65535) port for accounting is 1813.
Define either AccountingPort or AuthenticationPort.
Optional.
AuthenticationPort • N (not set; default) UDP port of the proxy target for authentication. The RFC
• Integer (1–65535) standard port for authentication is 1812.
Define either AccountingPort or AuthenticationPort.
Optional.
AttributeEncryption • none (Default) Specifies whether all RADIUS attributes in the messages sent to
• RFCMD5 the proxy target are encrypted. Both authentication and
accounting message attributes are encrypted.
Both the proxy and the target servers must be Bridgewater
RADIUS Servers installed with a release that supports the
attribute encryption feature. Otherwise, the originating proxy
server may not get a response or may get an Access-Reject
message.
Performance degradation with the attribute encryption feature
enabled is expected. For details, see the engineering
requirements in the Bridgewater Installation Reference Guide.
Optional.
BindLocalIP • IP address (dot notation The local IP address to bind when sending proxy requests. Use
format) this parameter for systems with multiple network interfaces.
Default=local host IP address If this parameter is not configured, only one proxy thread is
created and listens on the primary IP address. A separate proxy
thread is created for each IP address specified.
For multi-homed boxes, the primary IP address is the default.
Only one IP address can be specified and this parameter can
only be used once per RADIUSServer entry. However, each
RADIUSServer entry can specify a different BindLocalIP in the
case of a multi-homed system.
For each different specified bind IP address, a separate
dedicated proxy receiver thread is created by RADIUS to handle
responses and timeouts for the IP address.
Optional.
Consecutive Failure Lockout attributes (For examples, see "Consecutive failure lockout" on page 371.
ConsecutiveFailure • Integer (1–65535) The time, in seconds, that a proxy target is locked out due to
LockoutDuration • Indefinite consecutive retry cycle failures.
Default=900 If this parameter is set to “Indefinite”, the proxy target is not
considered for service until it is manually unlocked by an
operator.
Optional.
ConsecutiveRetry • N (not set) The maximum number of consecutive retry failures before
Cycles • Integer (1–65535) lockout of the proxy target occurs.
Required for RADIUSServer elements only if
ConsecutiveLockoutEnabled is configured.
Intermittent Failure Lockout attributes (For examples, see "Intermittent failure lockout" on page 371.
IntermittentFailure • Integer (1–65535) The time, in seconds, over which request failure and success are
Interval Default=900 tracked.
Length Optional.
IntermittentFailure • N (not set) The time, in seconds, during which the proxy is not available due
Lockout • Integer (1–65535) to consecutive retry failures.
Duration Default=900 Setting this parameter to ‘Indefinite’ prevents the proxy target
from being considered for service until it is manually unlocked by
an operator.
The only exception is if all proxy targets are locked and Dynamic
Unlock is enabled for the proxy target group.
Optional.
IntermittentFailure • Integer The number of successive failed intervals before a proxy target
SuccessiveFailed (1–65535) lockout occurs.
Intervals Optional.
Default=1
Additional attributes
MaxRetries • Integer The number of retry attempts per request before failing over or
(1–65535) rejecting the request.
Default=0 If this parameter is not set, there are no retries for that proxy
target.
Optional.
StripDomain • Y Set to Y for the RADIUS Server to remove the domain from the
• N (Default) login name when forwarding an Access-Request.
This removes any domain, including a domain appended or
replaced by a RADIUS policy rule.
The domain is still used for local authorization and is stored in
local accounting records.
Optional.
InAction A set of actions to apply to attributes returned from the proxy target. Proxy filters are
used to modify or remove attributes in RADIUS messages received from proxy
targets.
The RADIUS Server applies filters in the order in which they appear in the
[Link] file.
The InAction element encloses no child elements.
Child element of RADIUSServer or RADIUSServer Group.
Example:
<InAction Filter="InFilter"/>
Filter • String (1–256 characters) The name of the filter to apply to the RADIUS packet that is
received from the proxy target. The filter must be defined in the
[Link] file, as described in "Filter" on page 339.
If OverwriteIP is enabled for the RADIUS Server, the IP address
replacement is performed after any incoming proxy filters are
applied. The use of OverwriteIP interferes with the Framed-IP
exception values set in the InAction filters.
Optional.
RequiredAttributes • String (1–256 characters) The name of the RequiredAttributes filter to apply to the RADIUS
packet that is received from the proxy target.
Optional.
OverrideAttributes • String (1–256 characters) The name of the OverrideAttributes filter to apply to the RADIUS
packet that is received from the proxy target.
Optional.
OutAction The actions to apply to attributes in RADIUS messages going from the RADIUS
client to the proxy target. Filters can be used to modify or remove attributes in the
authentication or accounting messages sent to proxy targets.
The RADIUS Server applies filters in the order in which they appear in the
[Link] file.
The OutAction element encloses no child elements.
Child element of RADIUSServer or RADIUSServer Group.
Example:
<OutAction
Type="Auth"
Filter="GenericFilter"
OverrideAttributes="Override1"
RequiredAttributes="Required1"/>
Filter • String (1–256 characters) The name of the filter to apply. The filter must be defined in the
[Link] file, as described in "Filter" on page 339.
Required when no RequiredAttributes or OverrideAttributes are
defined.
OverrideAttributes • String (1–256 characters) The name of the OverrideAttributes filter to apply to the RADIUS
packet that is sent to the proxy target.
Optional.
RequiredAttributes • String (1–256 characters) The name of the RequiredAttributes filter to apply to the RADIUS
packet that is sent to the proxy target.
Optional.
RADIUSServer Group A group of RADIUS proxy servers and the actions the group takes on RADIUS
messages. Each ProxyTargetConfiguration root element must enclose at least one
proxy target server (RADIUSServer, SecurIDServer, or LDAPServer) or proxy
target group (RADIUSServerGroup, SecurIDServer Group, or LDAPServerGroup)
element.
The RADIUSServerGroup element encloses an optional InAction and an optional
OutAction child element. For more information, see "InAction" on page 356 or
"OutAction" on page 357.
Child element of ProxyTarget Configuration.
Example:
<RADIUSServerGroup
GroupName="RadiusGroup1"
Failover="n"
LoadSharing="y"
MaxConcurrentLockouts="1"
DynamicUnlock="y"
RADIUSServer="RadiusServer1">
<InAction
Filter="InFilter"/>
<OutAction
Filter="GenericFilter"
Type="Auth"/>
</RADIUSServerGroup>
GroupName • String (1–256 characters) A unique name to identify the RADIUS server group.
• Spaces are not supported Required.
MaxConcurrent • Integer The number of proxy targets that can be locked out per proxy
Lockouts Default=all targets in the group group.
When the maximum number of lockouts has been reached, the
proxy target that is a candidate for lockout remains unlocked.
If this is less than the total number of proxy targets in the group,
when that number of targets is locked out, no further targets can
be locked out.
Optional.
MaxFailoverLimit • Integer When Failover is enabled, define the maximum number of targets
Default=number of servers in the to attempt in the group.
group This parameter is ignored when Failover=N.
A value of '0' is invalid.
Optional.
RADIUSServer • String (1–256 characters) A unique name to identify the RADIUS proxy server.
Identify a minimum of one Radius proxy server.
Required.
SecurIDServer A SecurID server proxy target. Each ProxyTargetConfiguration root element must
enclose at least one proxy target server (RADIUSServer, SecurIDServer, or
LDAPServer) or proxy target group (RADIUSServer Group, SecurIDServer Group,
or LDAPServerGroup) element.
Child element of ProxyTarget Configuration.
[Link]:
<SecurIDServer
TargetName="SecurIDServer1"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="3"
AuthenticationPort="1812"
ConsecutiveLockoutEnabled="n"
IntermittentFailureLockoutEnabled="n"
MaxRetries="1" >
</SecurIDServer>
TargetName • String (1–256 characters) A unique identifier for the proxy target.
• Spaces are not supported Required.
Secret • String (1–256 characters) Shared secret used when communicating with the target server.
Required.
RequestTimeout • Integer (1–65535) The maximum time, in seconds, that the RADIUS Server waits for
Default=5 a response from the proxy target before it sends the request to an
alternate proxy server in the group, or deals with the request as
defined in the policy rules.
WARNING: Failure to coordinate these parameters may result in
severe degradation of RADIUS performance.
For more information, see "RequestTimeout" on page 370.
Required.
AuthenticationPort • N (not set; default) UDP port of the proxy target for authentication. The RFC
• Integer (1–65535) standard port for authentication is 1812.
Define either AccountingPort or AuthenticationPort.
Required.
BindLocalIP • IP address (standard dot The local IP address to bind to when sending proxy requests.
notation) Use this parameter for systems with multiple network interfaces.
Default=local host IP address If this is not configured, only one proxy thread is created, which
listens on the primary IP address. A separate proxy thread is
created for each IP address specified.
For multi-homed boxes, the primary IP address is the default.
Only one IP address can be specified and this parameter can
only be used once per RADIUSServer entry. However, each
RADIUSServer entry can specify a different BindLocalIP in the
case of a multi-homed system.
For each different specified bind IP address, a separate
dedicated proxy receiver thread is created by RADIUS to handle
responses and timeouts for the IP address.
Optional.
ConsecutiveFailure • Integer (1–65535) The time, in seconds, that a proxy target is locked out due to
LockoutDuration • Indefinite consecutive retry cycle failures.
Default=900 If this parameter is set to “Indefinite”, the proxy target is not
considered for service until it is manually unlocked by an
operator.
Optional.
ConsecutiveRetry • N (not set) The maximum number of consecutive retry failures before
Cycles • Integer (1–65535) lockout of the proxy target occurs.
Optional.
IntermittentFailure • Integer (1–65535) The time, in seconds, that request failure and success are
Interval Default=900 tracked.
Length Optional.
IntermittentFailure • N (not set) The time, in seconds, during which the proxy is not available due
Lockout • Integer (1–65535) to consecutive retry failures.
Duration Default=900 Setting this parameter to ‘Indefinite’ prevents the proxy target
from being considered for service until it is manually unlocked by
an operator.
The only exception is if all proxy targets are locked and Dynamic
Unlock is enabled for the proxy target group.
Optional.
IntermittentFailure • Integer (1–65535) The minimum number of requests within an interval for it to be
MinimumRequests Default=1 considered valid.
Optional.
IntermittentFailure • Integer (1–65535) The number of successive failed intervals before a proxy target
SuccessiveFailed Default=1 lockout occurs.
Intervals Optional.
Additional attributes
MaxRetries • Integer (1–65535) The number of retry attempts per request before failing over or
Default=0 rejecting the request.
If this parameter is not set, there are no retries for that proxy
target.
Optional.
SecurIDServer Group A proxy target group of SecurID servers. Each ProxyTargetConfiguration root
element must enclose at least one proxy target server (RADIUSServer,
SecurIDServer, or LDAPServer) or proxy target group (RADIUSServer Group,
SecurIDServerGroup, or LDAPServerGroup) element.
Child element of ProxyTarget Configuration.
Optional.
Example:
<SecurIDServerGroup
GroupName="SecurIDGroup1"
Failover="y"
LoadSharing="n"
MaxConcurrentLockouts="2"
DynamicUnlock="N"
SecurIDServer="SecurIDServer1 SecurIDServer2">
</SecurIDServerGroup>
GroupName • String (1–256 characters) A unique name to identify the RADIUS server group.
• Spaces are not supported Required.
MaxFailoverLimit • Integer (> 0) When Failover is enabled, define the maximum number of targets
Default=number of servers in the to attempt in the group.
group This parameter is ignored when Failover=N.
A value of '0' is invalid.
Optional.
MaxConcurrent • Integer (1–65535) The number of proxy targets that can be locked out per proxy
Lockouts Default=number of proxy targets group.
in the group When the maximum number of lockouts has been reached, the
proxy target that is a candidate for lockout remains unlocked.
If this is less than the total number of proxy targets in the group,
when that number of targets is locked out, no further targets can
be locked out.
Optional.
SecurIDServer • String (1–256 characters) List of the names of all proxy targets in the proxy target group,
separated by spaces. There must be at least one entry in the
proxy target group.
Required.
LDAPServer An LDAP server proxy target. Each ProxyTargetConfiguration root element must
enclose at least one proxy target server (RADIUSServer, SecurIDServer, or
LDAPServer) or proxy target group (RADIUSServer Group, SecurIDServer Group,
or LDAPServerGroup) element.
Child element of ProxyTarget Configuration.
Optional.
Example:
<LDAPServer
TargetName="LDAPServer1"
TargetHost="[Link]"
AuthenticationPort="389"
RequestTimeout="5"
MaxRetries="2"
DNPrefix="uid">
</LDAPServer>
Description
Attribute Value
Optional/Required
TargetName • String (1–256 characters) A unique identifier for the proxy target.
• Spaces are not supported Required.
Description
Attribute Value
Optional/Required
RequestTimeout • Integer (1–65535) The maximum time, in seconds, that the RADIUS Server waits for
Default=5 a response from the proxy target before it sends the request to an
alternate proxy server in the group, or deals with the request as
defined in the policy rules.
WARNING: Failure to coordinate these parameters may result in
severe degradation of RADIUS performance.
For more information, see "RequestTimeout" on page 370.
Required.
AuthenticationPort • N (not set; default) UDP port of the proxy target for authentication. The RFC
• Integer (1–65535) standard port for authentication is 1812.
Define either AccountingPort or AuthenticationPort.
Required.
Additional attributes
MaxRetries • Integer (1–65535) The number of retry attempts per request before failing over or
Default=0 rejecting the request. If this parameter is not set, there are no
retries for that proxy target.
Optional.
DNPrefix • String (1–256 characters) The distinguished name prefix used to create a DN login string to
authenticate a subscriber against an LDAP target. Examples are
“uid” or “cn”.
Required.
<ServiceAVP
LDAPAttrName=”userData”
RADIUSAttrName=”Cisco-AVPair”
VendorName=”CISCO”/>
In the example above the LDAP attribute named “userMessage” is mapped to the
RADIUS attribute “Reply-Message” and the LDAP attribute “userData” is mapped to
the RADIUS VSA “Cisco-AVPair” in the Cisco dictionary.
If multiple instances of an attribute exist in the LDAP database, all instances are
returned to the RADIUS server.
Also define attributes for an LDAPServerGroup. Attributes defined for a group apply
to all LDAP servers in that group. If both the LDAPServer and LDAPServerGroup
have attributes defined, then the LDAPServerGroup attributes override the
LDAPServer attributes. If an LDAP server with defined attributes belongs to a group
with no defined attributes, the attributes defined for each LDAPServer are used.
LDAPServerGroup A proxy target group of LDAP servers. Each ProxyTargetConfiguration root element
must enclose at least one proxy target server (RADIUSServer, SecurIDServer, or
LDAPServer) or proxy target group (RADIUSServer Group, SecurIDServer Group,
or LDAPServerGroup) element.
Child element of ProxyTarget Configuration.
Optional.
Example:
<LDAPServerGroup
GroupName="LDAPGroup1"
Failover="Y"
LoadSharing="y"
LDAPServer="LDAPServer1 LDAPServer2">
</LDAPServerGroup>
GroupName • String (1–256 characters) A unique name to identify the RADIUS server group.
• Spaces are not supported Required.
MaxFailoverLimit • Integer (> 0) When Failover is enabled, define the maximum number of targets
Default=number of servers in the to attempt in the group.
group This parameter is ignored when Failover=N.
A value of '0' is invalid.
Optional.
LDAPServer • String (1–256 characters) List of the names of all proxy targets in the proxy target group,
separated by spaces. There must be at least one entry in the
proxy target group.
Required
RequestTimeout
The RADIUS Server must respond to requests before the NAS times out. This
makes sure that the NAS does not mark the RADIUS as “dead” and that the NAS
does not send redundant messages to its failover target. This avoids the cascade
effect of overloading multiple RADIUS Servers.
To do this, make sure that an outage policy is defined for all policy rules for auth and
accounting-accept, reject, and acknowledge messages. Also, the NAS timeout
must be greater than the time it takes the system to respond. For example: NAS
timeout > RMS delays + proxy delays + internal processing. The absolute value for
the NAS timeout must be greater than the system response time.
For example: if the auth timeout is 3 seconds per target and there are 2 targets in
the group, there is a worst-case delay of 6 seconds to get a response from the
target. If the RADIUS RMS RequestTimeout is set to 5, there is a worst-case delay
of 5 seconds to get a response from the RMS. Assume 0.5 seconds for internal
RADIUS processing. Therefore, the NAS timeout must be greater than 11.5
seconds (6 + 5 + 0.5).
For more information about RMSP timeouts, see “Client to Server Communication”
in the Service Controller: Resource Management Server Guide.
Base the RequestTimeout values on observed RTT (round trip times) for the proxy
targets. Set RequestTimeout to between 5 and 10 times the RTT to make sure that,
under normal operating conditions (no network congestion, no proxy target delays),
virtually all requests are processed.
RequestTimeout can be set lower for accounting proxy targets than for
authentication proxy targets. It is more important to receive the proxy response from
an authentication target since it may contain RADIUS attributes that define the
service to be delivered.
Filter examples
The following examples show the use of attribute filters for a proxy authentication
message response, a proxy accounting request, filters against AVP subtypes, and a
proxy authentication response generic filter in a RADIUS proxy target definition.
This section provides the following examples:
• Disallow attributes with a specific value
• Allow explicit set of attributes
• Allow only supported attributes
• Filters based on AVP subtypes
• RADIUS proxy target with filtered attributes
Allow all attributes This filter proxies all attributes and excludes WiMAX-QoS-Descriptor when
except WiMAX-QoS- Traffic-Priority=3 or Schedule-type=4.
Descriptor <Filter FilterName="QoS" Action="Allow">
<AVP Attrname="WiMAX-QoS-Descriptor:Traffic-Priority" Action="Allow">
<ExceptionVal Value="3"/>
</AVP>
<AVP Attrname="WiMAX-QoS-Descriptor:Schedule-Type" Action="Allow"
<ExceptionVal Value="4"/>
</AVP>
</Filter>
Remove all attributes This filter removes all attributes and includes WiMAX-QoS-Descriptor when
except WiMAX-QoS- Traffic-Priority is between 2 and 3 and Schedule-type=4.
Descriptor <Filter FilterName="QoS" Action="Deny">
<AVP Attrname="WiMAX-QoS-Descriptor:Traffic-Priority" Action="Deny">
<ExceptionRange Start="2" End="3"/>
</AVP>
<AVP Attrname="WiMAX-QoS-Descriptor:Schedule-Type" Action="Deny"
<ExceptionVal Value="4"/>
</AVP>
</Filter>
Include all This filter includes all attributes. WiMAX-QoS-Descriptor is included if and only if
attributes, restrict Traffic-Priority is between 2 and 3 and Schedule-type=4.
WiMAX-QoS- <Filter FilterName="QoS" Action="Allow">
Descriptor <AVP Attrname="WiMAX-QoS-Descriptor:Traffic-Priority" Action="Deny">
<ExceptionRange Start="2" End="3"/>
</AVP>
<AVP Attrname="WiMAX-QoS-Descriptor:Schedule-Type" Action="Deny"
<ExceptionVal Value="4"/>
</AVP>
</Filter>
Remove all This filter removes all attributes. WiMAX-QoS-Descriptor is included if and only if
attributes, restrict Traffic-Priority is not between 2 and 3 and Schedule-type is not 4.
WiMAX-QoS- <Filter FilterName="QoS" Action="Deny">
Descriptor <AVP Attrname="WiMAX-QoS-Descriptor:Traffic-Priority" Action="Allow">
<ExceptionRange Start="2" End="3"/>
</AVP>
<AVP Attrname="WiMAX-QoS-Descriptor:Schedule-Type" Action="Allow"
<ExceptionVal Value="4"/>
</AVP>
</Filter>
<Override
AttrName="Callback-Id"
Precedence="Packet">
<DataValue Type=”Integer”>5551212</DataValue>
</Override>
</OverrideAttributes>
<RequiredAttributes Name=”UserInfo”>
<Reqd AttrName="User-Name"/>
<Reqd AttrName="User-Password"/>
</RequiredAttributes>
<RequiredAttributes Name=”Acct”>
<Reqd AttrName="Acct-Status-Type"/>
</RequiredAttributes>
<RADIUSServer
TargetName="FilteredRadiusServer"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="2"
AccountingPort="1813"
AuthenticationPort="1812">
<InAction Filter="InFilter" />
<OutAction Filter="GenericFilter" Type="Auth"
OverrideAttributes=”Assign”/>
RequiredAttributes=”UserInfo”/>
<OutAction Filter="AcctFilter" Type="Acct">
RequiredAttributes=”Acct”/>
</RADIUSServer>
AccountingPort="1813"
AuthenticationPort="1812"
ConsecutiveLockoutEnabled="N"
ConsecutiveFailureLockoutDuration="3600"
ConsecutiveRetryCycles="200"
IntermittentFailureLockoutEnabled="N"
IntermittentFailureIntervalLength="60"
IntermittentFailureLockoutDuration="Indefinite"
IntermittentFailureMinimumRequests="40"
IntermittentFailurePercentageFailureThreshold="25"
IntermittentFailureSuccessiveFailedIntervals="2"
MaxRetries="1"
OverwriteIP="N"
StripDomain="N"
DigitizeAcctSessionID="Y">
</RADIUSServer>
<SecurIDServer
TargetName="SecurIDServer1"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="3"
AuthenticationPort="1812"
ConsecutiveLockoutEnabled="n"
IntermittentFailureLockoutEnabled="n"
MaxRetries="1" >
</SecurIDServer>
<SecurIDServer
TargetName="SecurIDServer2"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="5"
AuthenticationPort="1812"
ConsecutiveLockoutEnabled="y"
ConsecutiveFailureLockoutDuration="3600"
ConsecutiveRetryCycles="1"
IntermittentFailureLockoutEnabled="n"
IntermittentFailureIntervalLength="60"
IntermittentFailureLockoutDuration="1800"
IntermittentFailureMinimumRequests="10"
IntermittentFailurePercentageFailureThreshold="10"
IntermittentFailureSuccessiveFailedIntervals="1"
MaxRetries="0">
</SecurIDServer>
<LDAPServer
TargetName="LDAPServer1"
TargetHost="[Link]"
AuthenticationPort="389"
RequestTimeout="5"
MaxRetries="2"
DNPrefix="uid">
</LDAPServer>
<LDAPServer
TargetName="LDAPServer2"
TargetHost="[Link]"
AuthenticationPort="389"
RequestTimeout="4"
MaxRetries="1"
DNPrefix="cn">
</LDAPServer>
<RADIUSServerGroup
GroupName="RadiusGroup1"
Failover="n"
LoadSharing="y"
MaxConcurrentLockouts="1"
DynamicUnlock="y"
RADIUSServer="RadiusServer1">
<InAction Filter="InFilter"/>
<OutAction Filter="GenericFilter" Type="Auth"/>
</RADIUSServerGroup>
<SecurIDServerGroup
GroupName="SecurIDGroup1"
Failover="y"
LoadSharing="n"
MaxConcurrentLockouts="2"
DynamicUnlock="N"
SecurIDServer="SecurIDServer1 SecurIDServer2">
</SecurIDServerGroup>
<LDAPServerGroup
GroupName="LDAPGroup1"
Failover="Y"
LoadSharing="y"
LDAPServer="LDAPServer1 LDAPServer2">
</LDAPServerGroup>
For more information about the [Link] file, see "Proxy configuration file" on
page 337.
This section describes the following examples of attribute manipulation for a proxy
environment:
• Configuring P/FIP attribute manipulation
• Configuring Accounting Session ID attribute manipulation
• Configuring Calling Station ID (CSID) masking
• Configuring Proxy attribute translation
• Manipulating the case of attributes in the [Link] file
• Attribute conversion plugin overview
Note These examples are not usable for LDAP or SecurID deployments.
1HWZRUN$FFHVV6HUYHU
6HQG)UDPHG3RRODWWULEXWH 6HQG)UDPHG3RRODWWULEXWH
6HQG)UDPHG,3$GGUHVV
SRROB>WR@ SRROB
([DPSOH
5HPRYH)UDPHG,3$GGUHVV 5HPRYH)UDPHG,3$GGUHVV
%ULGJHZDWHU5$',866HUYHU
$FFHVV$FFHSW
$FFHVV$FFHSW
$FFHVV$FFHSW
)UDPHG,3$GGUHVVLVQRW
)UDPHG,3$GGUHVV )UDPHG,3$GGUHVV
>WR@
>WR@
([DPSOH
$$$SUR[\VHUYHU
The value of the Framed-IP-Address attribute that the AAA proxy server sends to
the Service Controller determines how it is manipulated. This attribute manipulation
is described in Table 130.
Configuring P/FIP Configure P/FIP attribute manipulation by creating the following system elements:
attribute • one Proxy Filter with a Framed-Pool AVP and a Framed-IP-Pool AVP
manipulation in
• one Proxy Override Attribute Group with a Framed-Pool override attribute
Service Manager
• one Proxy Required Attribute Group with a Framed-Pool AVP and a
Framed-IP-Pool AVP
• one Radius Server with an InAction
Note To provision P/FIP attribute manipulation using the Service Manager, set
the ReadProxyConfigFromDB XML attribute in the [Link] file to ‘Y’.
For more information, see "Proxy configuration file" on page 337.
Note These procedures assume familiarity with the Service Manager
provisioning process. For more information, see the Service Manager:
Getting Started Guide for AAA.
Perform the following procedures:
• To create a Proxy Filter
• To create a Proxy Override Attribute Group
• To create a new Proxy Required Attribute Group
• To create a RADIUS Server
Configuring P/FIP This section provides a procedure for configuring P/FIP attribute manipulation using
attribute [Link].
manipulation in Configure P/FIP attribute manipulation by creating the following system elements:
[Link]
• one Proxy Filter with a Framed-Pool AVP and a Framed-IP-Pool AVP
• one Proxy Override Attribute Group with a Framed-Pool override attribute
• one Proxy Required Attribute Group with a Framed-Pool AVP and a
Framed-IP-Pool AVP
• one Radius Server with an InAction
<OverrideAttributes Name="Pools">
<Override
AttrName="Framed-Pool"
Precedence="Filter"
Mandatory="Y">
<Condition>
<Matches
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="[Link]">
<DataValue Type="String">pool_254</Data>
</Matches>
<Matches
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.[1-9]">
<DataValue Type="String">pool_00</Data>
<RegExValue
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.([1-9])">
${1}
</RegExValue>
</Matches>
<Matches
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.[1-9][1-9]">
<DataValue Type="String">pool_0</Data>
<RegExValue
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.([1-9][1-9])">
${1}
</RegExValue>
</Matches>
<Matches
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.[1-9][1-9][1-9]">
<DataValue Type="String">pool_</Data>
<RegExValue
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.([1-9][1-9][1-9])">
${1}
</RegExValue>
</Matches>
</Condition>
</Override>
</OverrideAttributes>
<RequiredAttributes Name="Pools">
<Reqd AttrName="Framed-IP-Address"/>
<Reqd AttrName="Framed-Pool"/>
</RequiredAttributes>
<RADIUSServer
TargetName="Target1"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="2"
AccountingPort="1813"
AuthenticationPort="1812">
<InAction
Filter="AuthFilter"
OverrideAttributes="Pools"
RequiredAttributes="Pools"/>
</RADIUSServer>
ASID overview
With Accounting Session ID (ASID) attribute manipulation, when the Service
Controller needs to proxy a request that contains the Accounting-Session-ID, the
Service Controller modifies the Accounting-Session-Id as follows:
Accounting-Session-Id=<NAS ID><delimiter><session-id-from-NAS>
where
NAS ID = the NAS IP Address
delimiter=[]
session-id-from-NAS = Accounting-Session-ID received from the NAS
For example, if the:
NAS IP Address = [Link]
Accounting-Session-ID = 12345
then, the modified Accounting-Session-ID = 1921681551[]12345
Note If the NAS sends the Session Director a Session Disconnect message, the
Session Director strips the NAS Identifier and delimiter from the
Accounting-Session-ID before forwarding it in the Session Disconnect
message to the NAS.
– Value = ${1}XXX.\
4 Saves CallingStationIdOverrideGroup.
5 Create a RADIUS Server with the following parameters:
– Name = Target3
– Host = [Link]
– Secret = TESTSECRET
– Request timeout = 2
– Accounting port = 1813
– Authentication port = 1812
6 On the RADIUS Server edit form, click the Actions tab.
7 Assign the following information:
– InAction
– Override Group = CallingStationIdOverrideGroup
8 Save Target3.
<RADIUSServer
TargetName="Target3"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="2"
AccountingPort="1813"
AuthenticationPort="1812">
<InAction
OverrideAttributes="Mask"/>
</RADIUSServer>
– Mandatory = Yes
5 To the second attribute to replace, such as Ascend-Secibdart-Dns, add an
AttributeValue (the replacement attribute) using the following parameters:
– Attribute = (the replacement attribute, such as Lucent-Secondary-Dns)
– Vendor = (the attribute’s vendor, such as Lucent)
6 Save DnsOverrideGroup into database.
7 Repeat steps 2 to 6 to add the override attribute groups, override attributes, and
attribute values that you need.
8 Create a RADIUS Server using the following parameters:
– Name = Target4
– Host = [Link]
– Secret = TESTSECRET
– Request timeout = 2
– Accounting port = 1813
– Authentication port = 1812
9 Assign the following information for Target4:
– In Action
– Override Group = DnsOverrideGroup
10 Save Target4 and exit.
AttrName="Ascend-Secondary-Dns"
VendorName="Ascend"
Precedence="Filter"
Mandatory="Y">
<AttributeValue
AttrName="Lucent-Secondary-Dns"
VendorName="Lucent"/>
</Override>
</OverrideAttributes>
<RADIUSServer
TargetName="Target4"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="2"
AccountingPort="1813"
AuthenticationPort="1812">
<InAction
OverrideAttributes="Assign"/>
</RADIUSServer>
{strtolower}${1}:${2}:${3}:${4}:${5}:${6}
For example, in [Link] configure the following sections:
<OverrideAttributes Name="Renaming">
<Override AttrName="User-Name">
<RegExValue AttrName="Calling-Station-Id" StringFormat="String"
Pattern="(.{2})(.{2})(.{2})(.{2})(.{2})(.{2})">
{strtolower}${1}:${2}:${3}:${4}:${5}:${6}
</RegExValue>
</Override>
</OverrideAttributes>
...
<RADIUSServer
TargetName="target1"
TargetHost="[Link]"
Secret="MYSECRET"
RequestTimeout="2"
DAEPort="3599">
<OutAction OverrideAttributes="Renaming" Type="DAE"/>
</RADIUSServer>
In the example above, when the Service Controller sends messages to the target
named “target1”, the Service Controller applies the override specified in the
OverrideAttributes section of [Link] (the Service Controller matches the
override specified in the OutAction element to the name of the OverrideAttributes
section in [Link]).
In this example the Service Controller adds colons between octets and changes the
alpha characters to lower case for the Calling-Station-Id (the MAC address) and
includes the Calling-Station-Id value (the MAC address) in the colon-delimited lower
case format in the User-Name attribute when sending messages to the proxy
target.
For more information about configuring overrides, see "OverrideAttribute" on page
342.
Example conversion This example shows how the RADIUS plugin converts the Extended-Data-Filter in
an Access-Accept returned from a proxy target.
Note This example only shows instances of Ascend-Data-Filter and
Extended-Data-Filter and does not include other attributes that may be in
the Access-Accept from the proxy target.
-------------------------------------------------------------
[242]
<Extended-Data-Filter>=([Link].[Link].[Link].0
[Link].[Link].[Link].[Link].[Link])32
Byte
Installing and This section provides information about installing and configuring the RADIUS
configuring the attribute conversion plugin.
attribute conversion • To install the attribute conversion plugin
plugin
• To configure the attribute conversion plugin in the accessReqPolicy file
• To configure the dictionary
- - - AssignVar myVar=CALLEDID:$Called-Station-Id
- - - PreAuthorize loginName=$Called-Station-Id
domain=null getProxyService=y continueNotFound=y
PreAuth:BRIDGEWATER:Proxy-Target Appears Once ProxyAA
target=PreAuth:$BRIDGEWATER:Proxy-Target
service=BPNAttrReturn-Auth
authorizeLoginName=myVar:CALLEDID authorizeDomain=null
authorizeProxyLevel=l outageAction=SendReject
outageRejectMessage="Could not connect to end AAA"
runPlugIn=TelstraPlugin
- - - SendReject replyMessage="BigPond service
mis-configured"
3 Save the file and exit.
4 Send the RADIUS Server a HUP signal for the changes to take effect.
pkill -HUP radiusd
For more information about RADIUS access request policies, see the chapter
“Configuring AAA Policies” in the Service Controller: Network Access Guide.
9
Chapter 9
Chapter
This chapter describes tools used to test and monitor the RADIUS Server
configuration.
The topics are:
• Validating configuration files
• Testing RADIUS Server configuration
• Monitoring RADIUS communications
Option Function
Option Function
-U Run the test in user interactive mode with prompts as the test is
executed.
-t <sec> The time, in seconds, after which radtest stops attempting to run the
test.
Default = 120
-R <num> The number of times radtest retries the test before it fails.
Default = 1
-p <Port> The RADIUS Server UDP port If the RADIUS Server is configured to
listen on alternate ports.
The default port for authentication is 1812 and the default port for
accounting is 1813.
-l A looped test.
n or N=<loop A looped test executes tests continuously until a specified value, either
count> a number of executions (n=<loop>) or a length of time (t=<time>), is
t or T=<time> reached.
-r <num> The maximum number of cycles per second for a looped test.
Option Function
-D <domain> When radtest generates login names for looped tests, specify a domain
for these login names using the -D option.
-T <msec> The time, in milliseconds, for interim accounting messages. This value
overrides the Acct-Interval attribute in the Access-Accept message from
RADIUS.
In addition to the attribute value pairs specified, the following attributes are added or
replaced in a looped test with the user generator module:
• User-Name="user<uid>[@domain]"
• User-Password="user<uid>p"
• NAS-IP-Address="NAS Network.[1-255]"
• NAS-Port="[0-255]"
where
uid is an integer in the range of [1-max uid] inclusive
NAS Network is the network address of the NAS, which is by default the
network address of RADIUS
NAS-IP-Address is replaced only if NAS netaddr is specified on the command
line
It is not necessary to specify options for the radtest request. If no options are
specified, default options and values are used. For example, send this message:
radtest -v [Link] DEMOSECRET User-Name=user@[Link]
User-Password=test NAS-Port=1 NAS-IP-Address=[Link]
radtest output
RADIUS
IP address : [Link]
Auth UDP Port: 1812
Acct UDP Port: 1813
User Interact: disabled
Timeout Intvl: 120
Retry Count : 1
Acct Wait Int: 0
User-Name = “auth_stats@[Link]”
User-Password = “auth_stats”
NAS-Port = 555
=====================Final Result===========================
cd /opt/aaasc/testtools/radtest
2 Run the prvsa tool:
./prvsa options
where options are any of the choices in Table 132.
Options Description
-c Attribute code
-v vendor ID
-s string
-i 32-bit integer
-l 64-bit integer
-l IPv4 address
-P IPv6 address
-u Create VSAs with a continuation byte. This option sets the continuation
byte to zero and disables attribute continuation.
For example: prvsa –c 26 –v 24757 –u 0 –w 12321
Example 1 To display values in the octal and hex formats required by the VSA for
non-octet-string attribute 73:
./prvsa -c 73 -v 5 -s TestSecret
In Octal: 16
:\000\000\000\005\111\014\164\145\163\164\123\145\143\162\
145\164
In Hex: 16 :0:0:0:5:49:c:74:65:73:74:53:65:63:72:65:74
Example 2 To display values in the octal and hex formats required by the VSA for octet-string
attribute 71 (3GPP2-Remote-Addr-Table-Index):
./prvsa -c 71 -v 5535 -o -t 1 -w 6792 -t 2 -w 1
In Octal: 14
:\000\000\025\237\107\012\001\004\032\210\002\004\000\001
In Hex: 14 :0:0:15:9f:47:a:1:4:1a:88:2:4:0:1
Example 3 To apply radtest using the "Vendor-Specific" values obtained from the prvsa tool in
"Example 1" and "Example 2":
radtest -vbp 1645 n.n.n.n 'abc$123' User-Name=”123@[Link]”
CHAP-Password="123abctest" NAS-Port="77453"
NAS-IP-Address="n.n.n.n" NAS-Identifier=PDSN125
Calling-Station-Id="1234567899" NAS-Port-Type=18
Service-Type=2 Framed-Protocol=1
Vendor-Specific="\000\000\000\005\111\014\124\145\163\164\123
\145\143\162\145\164"
Vendor-Specific="\000\000\025\237\107\012\001\004\032\210\002
\004\000\001"
Note Substitute an IP address for n.n.n.n, in these examples.
Use the Trace Tool output to decrypt the values of the attributes that are provided.
For information about the Trace Tool, see "To start the Trace Tool" on page 413.
Authenticator Tracking ID
[Link].c2.86.9c.3b.94 390518
[ 1] <User-Name>=(123@[Link])25Byte
[ 3] <CHAP-Password>=([Link].8c.c7.d6.e9.1f.a6) 17Byte
[ 5] <NAS-Port>=(77453) 4Byte
[ 4] <NAS-IP-Address>=(n.n.n.n) 4Byte
[ 6] <Service-Type>=(Framed) 4Byte
[ 7] <Framed-Protocol>=(PPP) 4Byte
In this example, the information that is returned, “{VSA} [0,0]”, is not what is
expected for VSA 5 (from "Example 1"). Therefore, check the dictionaries to verify
that START-VSA = 5 is specified.
For the purposes of this example, START-VSA = 5 is not specified. However,
START-VSA = 5535 is specified as:
ATTRIBUTE 3GPP2-MN-HA-Shared-Key 58 string saltmd5 out single
Therefore, use a prvsa command that includes this information:
./prvsa -c 58 -v 5535 -s TestSecret
In Octal: 16
:\000\000\025\237\072\014\124\145\163\164\123\145\143\162\145
\164
Run the radtest with the values obtained from the prvsa tool:
radtest -vbp 1645 n.n.n.n 'abc$123' User-Name=”123@[Link]”
CHAP-Password="123abctest" NAS-Port="77453" NAS-IP-Ad
dress="n.n.n.n" NAS-Identifier=PDSN125
Calling-Station-Id="1234567899" NAS-Port-Type=18
Service-Type=2 Framed-Protocol=1 Vendor-
Specific="\000\000\025\237\072\014\124\145\163\164\123\145\14
3\162\145\164"
Vendor-Specific="\000\000\025\237\107\012\001\004\032\21
0\002\004\000\001"
PORT Integer (greater The port on which the RADIUS Server accepts connections from Trace Tool
than 1023) clients.
Default = 30000 After changing this field, restart the RADIUS Server.
TRACEBIND IP address A single interface for connections with Trace Tool clients, when the machine
Default = any has more than one IP address or more than one virtual address.
After changing this field, restart the RADIUS Server.
CONNECTIONS Integer (1–8) The maximum number of simultaneous connections with Trace Tool clients.
Default = 4
TRACECLIENT String (hostname or A server that can connect to the RADIUS Server. More than one trace client
IPv4 address) can be specified.
Field Description
RequestInitiator=IP_address IP address of the NAS or RADIUS server that is the source of the access-request.
For more information, see "RequestInitiator, RequestHandler, and Direction
fields" on page 414.
Note This field does not support the * wildcard.
RequestInitiatorPort=port_number Port used by the Request Initiator to communicate with the RADIUS Server.
RequestHandler= IP address of the RADIUS server that is the target of the access-request. For more
IP_address information, see "RequestInitiator, RequestHandler, and Direction fields" on page
414.
Note This field does not support the * wildcard.
RequestHandlerPort=port_number Port used by the Request Handler to communicate with NASs or remote RADIUS
servers.
Field Description
Direction= [1 | 2] Specifies whether the packet was incoming or outgoing from the request handler.
Either:
1 = incoming
2 = outgoing
Incoming packets go from the request initiator to the request handler; outgoing
packets go from the request handler back to the request initiator.
For more information, see "RequestInitiator, RequestHandler, and Direction fields"
on page 414.
[M:]Attribute=[* | value] Attribute-value pair in the packet. You can type a specific value or an asterisk (*) to
allow any value.
Precede the attribute-value string with M: if the presence of this string is mandatory.
If M: is not added then the packet is logged if the attribute is missing or when the
attribute and value match the specified pair.
1$6 6HUYLFH&RQWUROOHU
,3 5$',866HUYHU
,3
7UDFH7RRORXWSXWIRU$FFHVV5HTXHVW
5HTXHVW,QLWLDWRU
5HTXHVW+DQGOHU
'LUHFWLRQ ,1
1$6 6HUYLFH&RQWUROOHU
,3 5$',866HUYHU
,3
7UDFH7RRORXWSXWIRU$FFHVV$FFHSW
5HTXHVW,QLWLDWRU
5HTXHVW+DQGOHU
'LUHFWLRQ 287
1$6 6HUYLFH&RQWUROOHU
,3 $FFHVV5HTXHVW 5$',866HUYHU
,3
7UDFH7RRORXWSXWIRU$FFHVV5HTXHVW
5HTXHVW,QLWLDWRU
5HTXHVW+DQGOHU
'LUHFWLRQ ,1
7UDFH7RRORXWSXWIRU3UR[\$FFHVV5HTXHVW
5HTXHVW,QLWLDWRU
5HTXHVW+DQGOHU
'LUHFWLRQ 287
5$',866HUYHU
,3
1$6 6HUYLFH&RQWUROOHU
,3 $FFHVV5HMHFW 5$',866HUYHU
,3
7UDFH7RRORXWSXWIRU$FFHVV5HMHFW
5HTXHVW,QLWLDWRU
5HTXHVW+DQGOHU
'LUHFWLRQ ,1
7UDFH7RRORXWSXWIRU3UR[\$FFHVV5HMHFW
5HTXHVW,QLWLDWRU
5HTXHVW+DQGOHU
'LUHFWLRQ 287
5$',866HUYHU
,3
10
Chapter 10
Chapter
Translation (NAT)
Overview
IPv4 NAT provides the ability to allocate private IP addresses to devices and
perform IP address translation at the PDSN/HA. This conserves utilization of IP
address resources and avoids exhaustion of globally unique public IP addresses.
Multiple HAs use a single private IP pool. Different regions use the same private IP
pool but each HA in the region has unique private IPs within its own pool. The public
IP address space remains the same.
The Service Controller accepts NAT binding request messages from PDSN/HAs
and stores NAT information in the RMS. The RMS stores one or more NAT bindings
for each session.
When NAT support is enabled, the RMS supports the creation, deletion, and
querying of NAT binding records.
When queried for NAT sessions, the RMS queries the TimesTen database to
retrieve the latest NAT session that matches the search criteria. It uses the
User-Name, Domain, and User-Ip-Address found in the NAT session to find the
latest matching RADIUS session in the same TimesTen database. The RMS returns
a single compound session, made up of the NAT and RADIUS sessions, to the
RMS client. If there are no matching RADIUS sessions, only the NAT session is
returned.
If an exhaustive search is enabled, RMS queries for IP addresses that are not
found in the [Link] file searches for
• NAT sessions first if [Link] includes any NATed ranges.
• RADIUS sessions if [Link] does not include any NATed ranges.
• RADIUS sessions if the initial search for NAT sessions does not yield any
results.
The RMS supports NAT session queries by NATed IP and NAT port number.
Message flows
This section provides message flows for NAT binding.
NAT binding creation In Simple IP, the PDSN provides the NAT binding for a session. In Mobile IP, the HA
or update provides the NAT binding.
1 The Service Controller receives an accounting interim request from the PDSN/
HA.
2 Based on the accounting type Interim and the presence of the
SN1-NAT-Bind-Record AVP, the Service Controller determines the request is a
NAT binding request.
3 The Service Controller extracts AVPs/Sub-types from the NAT binding request
message including NAT-Loading-Factor, NAT-IP-Address,
NAT-Port-Block-Start, NAT-Port-Block-End, User-Name, Framed-IP-Address,
Event-Timestamp, and Port-Chunk-Alloc (set to alloc indicating it is a binding
creation).
4 The Service Controller increments the SNMP metrics tracking the total number
of NAT binding alloc requests and the total number of NAT binding requests
(allocs + de-allocs).
5 The Service Controller validates that the extracted Loading-Factor is supported.
6 The Service Controller validates the extracted NAT port range.
7 The Service Controller adds a NAT binding to RMS.
8 The Service Controller replies with an Accounting-Response to the PDSN/HA.
The RMS has a new NAT binding stored against the session.
Note The NAT-IPAddress, NAT-Loading-Factor, NAT-Port-Block-Start, and
NAT-Port-Block-End form a unique combination. If a new binding creation
request is received, if any of those four attributes are changed, a new
binding record is created. If any other attributes but those four are changed,
the existing binding record is updated.
Table 136: VSA sub-types and AVPs required for alloc requests
User-Name RADIUS
Framed-IP-Address RADIUS
Event-Timestamp RADIUS
NAT binding removal NAT bindings expire at the PDSN/HA that are managing them.
1 The Service Controller receives an accounting interim request from the PDSN/
HA
2 Based on the accounting type Interim and the presence of the
SN1-NAT-Bind-Record AVP, the Service Controller determines the request is a
NAT binding request.
3 The Service Controller extracts AVPs from the NAT binding request message
including NAT-Loading-Factor, NAT-IP-Address, NAT-Port-Block-Start,
NAT-Port-Block-End, User-Name, and Port-Chunk-Alloc (set to dealloc
indicating it is a binding removal).
4 The Service Controller increments the SNMP metrics tracking the total number
of NAT binding de-alloc requests and the total number of NAT binding requests
(allocs + de-allocs).
Table 137: VSA subtypes and AVPs required for de-alloc requests
User-Name RADIUS
Session stop The PDSN/HA stops the session by providing the Service Controller with an
accounting stop message.
1 The Service Controller receives an accounting stop request from the PDSN.
2 The Service Controller sends a message to RMS to remove the session.
3 RMS removes the session and all stored NAT bindings for that user.
4 The Service Controller responds with an Accounting-Response to the PDSN.
The RMS no longer contains the session or its associated NAT bindings.
Tethered device Tethered devices, for example, a Blackberry connected as a dongle to a laptop,
support despite being provisioned against a NATed IP Pool, should not be subject to NAT.
To solve this problem, when a request from a tethered device is processed, a
provisioned Framed-Pool AVP is removed from an Access-Accept message if its
value matches one of the configured NAT pools in the [Link] file.
A policy line for Access-Requests is configured with a condition to match the DUN
NAI (tethered devices). The policy line must define a myVar variable that has the
same name as the one defined in the [Link] file. For example:
User-Name Contains @[Link] AssignVar
myVar=NATTethered:
When an access request comes from a tethered device, the provisioned instance of
the Framed-Pool AVP that represents NATed IP pools is removed from the
Access-Accept message.
This is supported in DMULocalAA and CDMA2000LocalAA policy actions.
Configuration files
The following files are required for NAT:
• [Link]
• [Link]
[Link]
The [Link] file, located in /opt/aaasc/config/radius, stores NAT
configurations and is used to enable or disable the processing of NATed requests.
For an example of the file, see the [Link] located in /opt/aaasc/radius.
Send the file a HUP signal after making any changes.
Table 138 describes the [Link] attributes.
NATConfiguration
LoadingFactor Each loading factor must have a unique value. A child element
of LoadingFactors.
Note For the collection of SNMP statistics, if a loading factor is
removed from [Link] and the RADIUS Server is
HUPed, the SNMP metric for the loading factor remains
and is not removed until the RADIUS Server is restarted.
If the loading factor is added back in to [Link],
the total number of NAT binding requests continues to be
incremented.
value Integer (0-65535) The unique value of the loading factor. An attribute of
LoadingFactor.
Required.
NATPool Each NAT Pool must have a unique value. A child element of
NATPools.
At least one NAT Pool must be configured if TetheredMode is
provisioned and NAT is enabled.
value String (1-253) The unique name of the supported NAT pool. An attribute of
NATPool.
Required.
[Link]
The RMS stores one or more NAT bindings per session. At a minimum, each
binding contains a login name, domain, loading factor, user IP address, NAT IP
address, port chunk start, port chunk end, and event timestamp.
To support the creation, deletion, and querying of NAT binding records, NAT binding
must be enabled in the [Link] file. NAT audit must also be enabled if the NAT
feature is enabled in RMS.
For more information, see “RMS Configuration” in the Service Controller: Resource
Management Server Guide.
Loading factor The loading factor should not be changed against previously established and
populated IP range. If the loading factor is increased, the port range decreases; if
the loading factor is decreased, the port range increases. An IP range with a new
loading factor should point to a different RMS.
The following examples describe what may occur if the loading factor is changed
and a second session is created:
• When there are two sessions with different port ranges, then both are logged
within the RMS.
– Session 1: NATPortStart=1, NATPortEnd=100, and NATIpAddr=[Link]
– Session 2: NATPortStart=200, NATPortEnd=300, and
NATIpaddr=[Link]
• When there are two sessions where the new session has a port range that is
within the older session, then the older session is overwritten with latest
session details.
– Session 1: NATportStart=1, NATPortEnd=100, and NATIpAddr=[Link]
– Session 2: NATPortStart=40, NATPortEnd=100, and NATIpAddr=[Link]
with different user and same domain
• When there are two sessions where the new session has a port range that
encloses the port range of the older session, the RMS creates a second
session and does not overwrite the first. The APC rejects the request as
ambiguous.
– Session 1: NATportStart=40 and NATportEnd=100
– Session 2: NATportStart=1 and NATportEnd=100
[Link] file
Table 139 lists the NAT VSA and sub-types in the [Link] file:
Note There are two STARENT dictionaries. Make sure the correct one is used.
For more information, see "STARENT and CISCO dictionaries" on page
180.
Sub-types
addSession
addSession requires -sessiontype NAT and supports the following options: -i, -d,
-ip, -natip, -natportstart, -natportend, and -natloadingfactor.
For example:
addSession -rms 0 -sessiontype NAT -l bshah4 -d [Link]
-ip [Link] -natip [Link] -natportstart 1 -natportend 50
-natloadingfactor 1
addSession -rms 0 -sessiontype NAT -l bshah4 -d [Link]
-ip [Link] -natip [Link] -natportstart 51 -natportend 100
-natloadingfactor 1
delSessions
delSessions requires -sessiontype NAT and supports the following options: -i, -d,
-ip, -natip, -natportstart, -natportend, and -natloadingfactor.
delSessions supports the AVP combinations listed in Table 140.
For example:
delSessions -rms 0 -sessiontype NAT -ip [Link]
delSessions -rms 0 -sessiontype NAT -natip [Link]
-natloadingfactor 1
delSessions -rms 0 -sessiontype NAT -l bshah4 -d [Link]
Note All NAT bindings that match the login name and domain are deleted.
listSessions
listSessions requires -sessiontype NAT and supports the following options: -i, -d,
-ip, -natip, -natport, and -natloadingfactor.
listSessions supports the AVP combinations listed in Table 140.
For example:
listSessions -rms 0 -sessiontype NAT -natip [Link] -natport
51
listSessions -rms 0 -sessiontype NAT -l bshah4 -d [Link]
login_name, domain
login_name
user_ip_addr
nat_ip_addr, nat_port
nat_ip_addr, nat_loading_factor
nat_ip_addr
SNMP
The NAT feature supports SNMP additions for radius accounting clients. The MIB
variables for NAT bindings are:
• radiusAcctServerNATBindingAllocs ([Link].4.1.3631.[Link].5.1.6)
• radiusAcctServerNATBindingDeallocs ([Link].4.1.3631.[Link].5.1.7)
• radiusAcctServerNATBindingRequests ([Link].4.1.3631.[Link].5.1.8)
The radiusAuthenticationServer branch has an OID of [Link].4.1.3631.[Link].
• radiusAuthenticationServerNATTetheredRequests ([Link].4.1.3631.[Link].1)
For more information about these variables, see “BW-RADIUS MIB” in the
Bridgewater SNMP Guide.
Log messages
System logs are logged using the RADSYS family.
Operational logs are logged using the RADOP family.
11
Chapter 11
Chapter
This chapter provides an overview of DAL Query Caching and how to configure the
[Link] file.
The topics are:
• DAL Query Caching overview
• [Link] file
• Enabling and disabling DAL Query Caching
• Configuration guidelines
• DAL cache metrics
Table 141: Additional memory requirements for DEF, DOM, and USR contexts
The amount of memory used is cumulative through the contexts. For example, if
caching at three contexts, include the attributes for the three contexts.
In this example, there is one context with 100 attributes and ten entries, and five
contexts with ten or fewer attributes with ten or fewer entries. Finally, account for
the additional service profiles and domains.
cachmaxmemory for each context cached must be greater than or equal to the
number of frequently used entities * number of attributes * 400 bytes
cachemaxmemory
= 1 context * (10 service profiles * 100 DEF attributes * 400 bytes) +
5 contexts (DOM, DOM_GROUP, ORG, ORG_GROUP, USR_GROUP)
* (10 entities * 10 attributes * 400 bytes) +
10 (DEF: service profile) contexts * 200 bytes +
10 (DOM) contexts * 200 bytes +
= 400000 + 200000 + 2000 + 2000
= 604,000 bytes
In this example, the constants are the size of the structures rounded to the nearest
100.
[Link] file
The [Link] file specifies a single database, using the global database name, with
which the RADIUS Server connects using a username and password. The
username and password are set when the database is installed.
Note The [Link] file is read at startup only.
The [Link] file can list multiple databases for backup. If the primary database
fails, the RADIUS Server connects to the next database listed in the file.
Modify this file only if the location of a database changes, relative to the RADIUS
Server, or the database username or password changes. Do not leave the
database field of the [Link] file blank.
Table 142 describes the [Link] parameters. Bridgewater Systems recommends
using the default values shown.
# Database config
username=r6
password=r6
database=wsp
Configuration guidelines
This section describes the design considerations for optimizing the DAL Query
Caching feature. The topics are:
• General
• cachemaxentries
• cachemaxmemory
• cachecontextbitmap
• cachetimetolive
General
Only cache entities if their highly-used attributes reasonably fit into a cache. For
example, in a network with millions of users, each with many attributes at the user
level, it is not reasonable to cache the USER context. The overhead of moving
results in and out of the cache for a low cache hit-rate decreases performance. On
the other hand, in a network with fewer than ten organizations, each with fewer than
ten attributes at the ORG context, it is reasonable to cache the ORG context. In this
case, if cachemaxentries is greater than ten, all of the organization level attributes
can be cached.
cachemaxentries
The cachemaxentries parameter is a single value shared with the queries. If
cachemaxentries is exceeded, the next incoming cache entry replaces the oldest
cache entry.
The cache results are shared among the RADIUS threads. Set cachemaxentries to
greater than or equal to the number of threads, if the data set is larger than the
number of threads.
In general, keep enough entries for each query in the cache to optimize
performance:
1 Calculate cachemaxentries to fit the contents, based on an understanding of
the data.
2 Set cachemaxmemory to fit the context and data.
For example, if caching at the domain context, set cachemaxentries to a value
greater than or equal to the number of domains. Even if the number of domains is
high, but only a few are used, then caching this query is beneficial, since the
commonly used domains remain in the cache.
cachemaxmemory
The value of cachemaxmemory is the upper boundary for memory usage. Each
query maintains an upper limit for its memory usage in the cache.
cachecontextbitmap
Whether the query is cached depends on the context set in cachecontextbitmap.
Table 143 describes the cachecontextbitmap settings.
DB_CONTEXT_NONE 0 If the context is set to zero, the cache is initialized but not used. In this case,
consider using the non-cached DAL.
DB_CONTEXT_USER 1 In general, do not set this context. If set , users are cached for authentication
and all the user level attributes are cached. With more than a few thousand
users, caching at this level reduces performance.
DB_CONTEXT_DOM 64 Set to cache the domain alias information with the domain level attributes.
This is recommended if the number of customer domains is low (in the
hundreds), even if the alias table is empty.
DB_CONTEXT_DEF 256 Set to cache the service profiles and the default level attributes for a user’s
profile set.
Consider this option if a small number of service profiles are defined for each
user and the total number of profiles is relatively small for many users.
cachetimetolive
Each entry is tagged with a cachetimetolive. This value sets the maximum time that
the cached results are valid. When this value is reached, the cached results are no
longer used, the query goes to the database instead, and the cache is updated with
the result.
When the system uses the cache, provisioning changes to the database are not
noticed by RADIUS as long as the entry remains in the cache. When an entry in the
cache reaches cachetimetolive, the entry is discarded. This forces RADIUS to
query the database the next time it needs this data.
For example, if cachetimetolive is set to 300 seconds, then RADIUS queries the
database at least every 300 seconds. However, RADIUS may need to query the
database more often if the entry is removed from the cache before it times out. This
can happen if the cachemaxmemory is exceeded or if cachemaxentries is
exceeded and the oldest entry in the cache is removed to make room for another
entry.
Set cachetimetolive greater than the time it takes to replicate the Profile database.
Usage
./bsig -h | -a <action> <PID>
where
-h prints the message and exits
-a specifies the action to execute
<action> is the action to execute. The only action available is dalstats
<PID> is the process ID of the application to be signaled
A
Appendix A
generation logic
Term Definition
BM The backup method type. RADIUS can set to the following types:
C - generated when an RMS product is not deployed.
L - incomplete records requiring a lookup in the provision data using the entity ID and
context.
F - the record contains complete accounting data.
I - Ignore. This is an indication to RADIUS Correlation to ignore this record.
Write Acct The policy writeAccounting action modifier is set to yes or no.
Class? The class attribute is available from the RADIUS client (configured in the [Link] file).
AcctStartAttrib configured? The AcctStartAttribute is configured in the [Link] to populate the RADIUSATTR field.
6WDUW
%0 &
506/RJLF/D\HU
&ODVV" <(6 %0 /
12
$FFWXVLQJ
506 9HQGRU
$&" <(6 5HDFKDEOH"
<(6 6XSSRUW"
12 506LQIR
<"
<(6
12 <(6
%0QRW
12 12 %0 ,
HTXDOWR&"
<(6
%0 )
12 9HQGRU
:ULWH$FFRXQWLQJ/RJLF/D\HU :ULWH
12 ZULWH <(6
EHKDYLRU UHFRUG
'RQRW
ZULWH 8
:ULWH$FFW
UHFRUG <HV $FFW6WDUW$WWULE
<(6 %0 &
SROLF\" RU8 FRQILJXUHG"
'RQH
12
6WDUW
%0 &
506/RJLF/D\HU
9HQGRU
<(6 %0 /
VXSSRUW
12
$FFWXVLQJ
506 9HQGRU
12 5HDFKDEOH"
<(6 12 506LQIR
6XSSRUW"
<"
<(6
<(6 12
%0 ,
:ULWH$FFRXQWLQJ/RJLF/D\HU
12
9HQGRU
:ULWH
12 ZULWH <(6
EHKDYLRU UHFRUG
12
8
<(6
:ULWH$FFW
SROLF\"
12
'RQRW
ZULWH
UHFRUG
12RU8
%0QRW
<(6 HTXDOWR
&"
'RQH
6WDUW
%0 &
506/RJLF/D\HU
9HQGRU
<(6 %0 /
VXSSRUW
12
%0 /DQG
12 506
5HDFKDEOH"
<(6 %0 )
:ULWH$FFRXQWLQJ/RJLF/D\HU
12
9HQGRU
12 12 ZULWH 8
EHKDYLRU
'RQRW
ZULWH <(6
UHFRUG
:ULWH
UHFRUG
'RQH
6WDUW
%0 &
506/RJLF/D\HU
9HQGRU
<(6 %0 /
VXSSRUW
12
%0 &
506 &ODVV 1DQG
12 5HDFKDEOH"
<(6 $FFRXQWLQJ <(6 %0 ,
XVLQJ506
LQIR <"
12
%0QRW
%0 ) <(6 HTXDOWR&"
12
:ULWH$FFRXQWLQJ/RJLF/D\HU
12
9HQGRU
12 12 ZULWH 8
EHKDYLRU
'RQRW
ZULWH <(6
UHFRUG
:ULWH
UHFRUG
'RQH