0% found this document useful (0 votes)
16 views462 pages

Bridgewater Service Controller Guide 9.6.1

The document provides an overview and instructions for configuring the Bridgewater Systems Service Controller, including information about the RADIUS Service Controller and Diameter Service Controller. It describes the intended audience, installation instructions, text conventions, document history, and related Bridgewater documentation.

Uploaded by

Vivek Kumar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views462 pages

Bridgewater Service Controller Guide 9.6.1

The document provides an overview and instructions for configuring the Bridgewater Systems Service Controller, including information about the RADIUS Service Controller and Diameter Service Controller. It describes the intended audience, installation instructions, text conventions, document history, and related Bridgewater documentation.

Uploaded by

Vivek Kumar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Service Controller

Network Access Guide


Release 9.6.1-AAA

Document version 1.1 October 12, 2012


The manufacturer (MFR) reserves the right to make changes to this document and the products which it describes without notice.
The MFR shall not be liable for technical or editorial errors or omissions made herein; nor for incidental or consequential damages
resulting from the furnishing, performance, or use of this material or of the accompanying Software or any files derived from the
Software.

Bridgewater Systems Corporation


303 Terry Fox Dr.
Suite 500
Ottawa, Ontario
Canada K2K 3J1
Phone: +1 613 591-6655
Fax: +1 613 591-6656
[Link]

Bridgewater Customer Support


North America and Puerto Rico: 1-877 943-3772
Mexico (Avantel, Telmex): 00-1-800-514-3772
International: 1-800 943-37726
support@[Link]

Bridgewater, Bridgewater Systems, Widespan and the Bridgewater Systems Logo are the trademarks of Bridgewater Systems
Corporation. Other company or product names referenced may be the trademark or registered trademark of their respective
companies. ©1997-2012 Bridgewater Systems Corporation. All rights reserved.
About this guide
This guide contains instructions for the configuration of the Bridgewater Systems
Service Controller, including information about the RADIUS Service Controller, and
the Diameter Service Controller.

Audience
The intended audience for this document is:
• system administrators
• database managers
• network operators
• application developers

Installation
For AAA RPM and package installation procedures, see the Bridgewater
Installation Reference Guide.
For SDB RPM and package installation procedures, see the HSS: Installation and
Configuration Guide.
For Policy Controller RPM and package installation procedures, see the Policy
Controller: Installation and Configuration Guide.

Text conventions

Font or convention Used for Example

Courier System responses and The buffer


messages, sample text files, configuration
and other screen text file:
/opt/aaasc/
config/
buffer_config.xml
is valid

Courier bold Commands entered by the user cd /opt/aaasc/


buffer

Courier bold A variable name that should be .bcvalid -c


italics replaced with an appropriate configfile
value.

Arial Italics Book or document title. Bridgewater Installation


Reference Guide

Service Controller 9.6.1-AAA October 12, 2012 Page iii


About this guide Network Access Guide

Font or convention Used for Example

[...] Sections of an example that <ARTLSndr ID="Send1">


have been omitted for clarity. [...]
</ARTLSndr>

Document history

Date Release Version Comments

July 2012 9.6-AAA 1.0 New for Release 9.6-AAA.

October 2012 9.6.1-AAA 1.1 Added WiMAX NWG prepaid. Updated


CISCO and STARENT dictionaries.

Related documents
The Release 9.6-AAA documentation consists of the following guides:
• 3G/WLAN Interworking Guide
Describes 3G/WLAN interworking environments. Covers the deployment
options and configuration procedures for 3G/WLAN interworking in a
Bridgewater deployment.
• Accounting Framework Guide
Describes how to configure, operate, and maintain the Accounting Framework,
and how to use the accounting records, and the usage and revenue reports.
• Bridgewater Installation Reference Guide
Describes the deployment options, installation procedures, installation
packages, engineering requirements, and security considerations for
Bridgewater Systems products.
• Bridgewater Master Glossary
Describes the terms and acronyms used in Bridgewater Systems software and
documentation.
• Bridgewater SNMP Guide
Describes how to configure SNMP support for the Bridgewater Systems
software components, and provides reference information about Bridgewater
MIBs. It also describes how to use Key Performance Indicator (KPI) scripts to
obtain SNMP metrics for reporting performance and capacity data. KPI scripts
gather time-based loading level statistics from Bridgewater components.
• CALEA Controller with SS8 Guide
Describes how to install, configure, and operate the CALEA (Communications
Assistance for Law Enforcement Agencies) Controller.

Page iv October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide About this guide

• CALEA Controller with Verint Guide


Describes how to install, configure, and operate the CALEA (Communications
Assistance for Law Enforcement Agencies) Controller.
• Data Streaming Server Guide
Describes how to configure, operate, and troubleshoot the Data Streaming
Server, and lists the DSS log messages.
• Extensible Authentication Protocol Guide
Describes the Extensible Authentication Protocol (EAP) supported by
Bridgewater Systems, including configuration examples and message flows for
the supported EAP methods.
• Prepaid Integrator Guide
Describes how to use the Prepaid Integrator to support customers with prepaid
or volume accounts. Covers CDMA, ECS, DCCA, and WiMAX deployments, as
well as logging, XML file parameters, plugin parameters, and command line
utilities.
• Provisioning Gateway Guide
Describes the Provisioning Gateway, which maps a single provisioning request
from a client to multiple outgoing requests for different target applications. The
guide describes how to use Provisioning Gateway to send provisioning
requests.
• Service Controller: Getting Started Guide
Describes the components of the Bridgewater Service Controller, including the
Resource Management Server. Also describes how to operate and maintain the
deployment.
• Service Controller: Log Messages Guide
Describes the log messages for the RADIUS Server, Diameter Server, the
Provisioning Server, the Accounting Framework, the Prepaid server, the DSS
server, the Provisioning Gateway, and the MAP Gateway.
• Service Controller: Mobile Services Guide
Describes how to configure mobile services such as Simple IP, Mobile IP, A12
Authentication, or WiFi Roaming for the Bridgewater Service Controller.
• Service Controller: Monitoring and Logging Guide
Describes how to operate the monitoring utility, and how to configure, operate,
and maintain the Logging Framework. Also provides an overview of the test
tools.
• Service Controller: Network Access Guide
Describes how to configure the RADIUS Server and the Diameter Server.
• Service Controller: Provisioning API Guide
Describes the Provisioning Server XML interface, operations, client application
design criteria, and the command line utilities for provisioning operations.

Service Controller 9.6.1-AAA October 12, 2012 Page v


About this guide Network Access Guide

• Service Controller: Resource Management Server Guide


Describes how to configure and operate the RMS and its product logs, as well
as the modules dependent on the RMS: the IP Address Manager, User Session
Controller, and Port Quota Controller.
• Service Controller: Subscriber and Database Management Guide
Describes how to configure the Provisioning Server and the Profile Database.
• Service Controller: WiMAX Guide
Describes WiMAX networks and how to configure the Service Controller for
WiMAX.

Service Manager documents


The Service Manager documentation consists of the following guides:
• Service Manager: Getting Started Guide for AAA
Describes how to configure, log in, navigate, and use the Service Manager
graphical interface to your Bridgewater deployment. Also describes how to
create and provision the administrators who manage your deployment.
• Service Manager: Network Access Guide for AAA
Describes how to model, and manage network entities, such as PDSNs, and
GGSNs, in a Bridgewater deployment using the Bridgewater Service Manager.
• Service Manager: Services Provisioning Guide for AAA
Describes how to create and provision services, such as a RADIUS connection
service, that are part of a complete service offering to subscribers.
• Service Manager: Subscriber Provisioning Guide for AAA
Describes how to provision subscribers, organizations, profile sets, and service
profiles.

Policy Controller documents


The Policy Controller documentation consists of the following guides:
• Policy Controller: Getting Started Guide
Describes the Bridgewater Policy Controller and PCRF solutions.
• Policy Controller: Installation and Configuration Guide
Describes how to install and configure the Bridgewater Policy Controller and
PCRF products. Also describes the packages and package prompts used to
install the Bridgewater Policy Controller and PCRF.
• Policy Controller: Provisioning Guide
Describes how to create and provision services, subscribers, and network
entities in a Bridgewater Policy Controller or PCRF deployment.

Page vi October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide About this guide

• Policy Controller: API Guide


Describes the APIs and WSDLs supported by the Bridgewater Policy Controller
and PCRF. Also describes how to use APIs and WSDLs to provision the Policy
Controller and PCRF, and to integrate with third party applications.

HSS documents
The HSS documentation consists of the following guides:
• HSS: API Guide
Describes the Provisioning Server XML interface, operations, client application
design criteria, and the command line utilities for provisioning operations.
• HSS: Deployment Planning Guide
Describes how to plan an HSS deployment. Provides information about
servers, the software environment, and troubleshooting logs.
• HSS: Getting Started Guide
Describes the 3GPP (3rd Generation Partnership Project) network specification
for Long Term Evolution (LTE). Also describes the HSS and related products
such as the 3GPP-AAA.
• HSS: Installation and Configuration Guide
Describes the deployment options, installation procedures, and installation
packages for the HSS and related products such as the 3GPP-AAA.
• HSS: IPv6 Implementation Guide
Describes the IPv6 protocol. Also describes how to configure IPv6 for Solaris
and the HSS.
• HSS: Operations and Maintenance Guide
Describes procedures for operating and maintaining an HSS deployment, such
as how to configure HSS policy rules or use HSS test tools.
• HSS: Provisioning Guide
Describes how to provision HSS components in the Profile database using the
Service Manager.

Service Controller 9.6.1-AAA October 12, 2012 Page vii


About this guide Network Access Guide

Page viii October 12, 2012 Service Controller 9.6.1-AAA


Contents
About this guide . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . iii
Audience . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . iii
Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . iii
Text conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . iii
Document history . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . iv
Related documents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . iv
Service Manager documents . . . . . . . . . . . . . . . . . . . . . . . . . . . . vi
Policy Controller documents . . . . . . . . . . . . . . . . . . . . . . . . . . . . vi
HSS documents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . vii

Chapter 1 RADIUS Server start-up options and access features . . 1


RADIUS Server startup options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2
Configuring access features with [Link] . . . . . . . . . . . . . . . . . . 5
[Link] schema . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
[Link] example . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
Applying [Link] changes . . . . . . . . . . . . . . . . . . . . . . 25
Preventing network congestion for RADIUS . . . . . . . . . . . . . . . . . . . . . . 26
To configure settings for the congestion control mechanism 31
To configure message drop probabilities . . . . . . . . . . . . . . 31
RADIUS subscriber data access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Profile Database . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Profile Database connection failover . . . . . . . . . . . . . . . . . . . . . 34

Chapter 2 RADIUS Server special features . . . . . . . . . . . . . . . . . . . 37


Configuring user and network lockout . . . . . . . . . . . . . . . . . . . . . . . . . . . 38
To configure user or network lockout . . . . . . . . . . . . . . . . . 39
Managing lockouts with ulTool . . . . . . . . . . . . . . . . . . . . . . 39
Configuring Prepaid Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42
To configure the prepaid target . . . . . . . . . . . . . . . . . . . . . . 43
To configure [Link] . . . . . . . . . . . . . . . . . . . . . . . . . . 43
To configure flat files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43
To configure the RADIUS Server . . . . . . . . . . . . . . . . . . . . 44
To set the RADIUS Server to run in SSR mode . . . . . . . . . 44
To create a dictionary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44
To provision a connection service profile . . . . . . . . . . . . . . 45
To provision a User profile set . . . . . . . . . . . . . . . . . . . . . . . 45

Service Controller 9.6.1-AAA October 12, 2012 Page ix


Contents Network Access Guide

To provision subscribers . . . . . . . . . . . . . . . . . . . . . . . . . . . 46
To provision PDSNs/HAs with dynamic HA allocation . . . . 46
To provision PDSN/HA groups . . . . . . . . . . . . . . . . . . . . . . 47
Saving session data to a flat file . . . . . . . . . . . . . . . . . . . . . . . . 47
Prepaid Data SNMP support . . . . . . . . . . . . . . . . . . . . . . . . . . . 49
Configuring Quick-Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49
To create a dictionary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50
To configure Quick-Access . . . . . . . . . . . . . . . . . . . . . . . . . 50
To add PP-Quick-Access to an existing Connection Service 51
Configuring Multiple NAI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52
To configure the RADIUS Server . . . . . . . . . . . . . . . . . . . . 53
To configure the RADIUS Server to enable SNMP . . . . . . . 53
To provision a connection service profile . . . . . . . . . . . . . . 53
To provision User profile sets . . . . . . . . . . . . . . . . . . . . . . . 54
To provision subscribers for multiple NAI services . . . . . . . 54
Multiple NAI SNMP support . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55
Configuring dynamic LNS assignment. . . . . . . . . . . . . . . . . . . . . . . . . . . 55
To enable dynamic LNS assignment . . . . . . . . . . . . . . . . . . 57
To create LNS groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57
Configuring realm routing support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58
Configuring subscriber QoS profiles for EV-DO Rev A service . . . . . . . . 58
To trigger the retrieval of QoS parameters . . . . . . . . . . . . . 59
To create a dictionary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59
To configure the accessReqPolicy file . . . . . . . . . . . . . . . . 59
Access options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60
QoS attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60
Accounting attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62
grantedQoS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62
Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 63
Configuring QoS Profiles using the Service Manager . . . . . . . . . . . . . . . 63
To create a RADIUS QoS Selection Policy Profile . . . . . . . 63
To create a RADIUS QoS Profile . . . . . . . . . . . . . . . . . . . . 63
To create a User Profile Set with QoS Profile . . . . . . . . . . . 64
To define the QoS attributes . . . . . . . . . . . . . . . . . . . . . . . . 65
Configuring user notification messages for internationalization. . . . . . . . 66
Configuring EAP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Configuring SIP Server Interworking . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67
Configuring service selection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67
Configuring GMT offset for proxy. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68
Configuring attribute generation in [Link] . . . . . . . . . . . . . . . . . 69

Page x October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Contents

Configuring attributes to include in RADOP log messages . . . . . . . . . . . 70


Configuring AVP-based access control . . . . . . . . . . . . . . . . . . . . . . . . . . 70
To configure the acMatchAttribute policy modifier . . . . . . . 71
To use acService with acMatchAttribute . . . . . . . . . . . . . . . 72
To provision the Access Attribute tab . . . . . . . . . . . . . . . . . 72
Configuring duplicate detection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
To configure duplicate detection . . . . . . . . . . . . . . . . . . . . . 73
Configuring database (DAL query) caching for multi-leg EAP . . . . . . . . . 74
To enable DAL query caching . . . . . . . . . . . . . . . . . . . . . . . 74
DAL query caching call flow . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76
Configuring HTTP Digest Authentication . . . . . . . . . . . . . . . . . . . . . . . . . 76
HTTP Digest Authentication call flows . . . . . . . . . . . . . . . . . . . . 77
Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80
Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80
Configuring MAC caching using Calling-Station-Id . . . . . . . . . . . . . . . . . 82
MAC caching message flow . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82
Configuring RADIUS-based metering . . . . . . . . . . . . . . . . . . . . . . . . . . . 83
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83
To create additional variables . . . . . . . . . . . . . . . . . . . . . . . 86

Chapter 3 Configuring LDAP for RADIUS access . . . . . . . . . . . . . 87


RADIUS and an LDAP Directory Server . . . . . . . . . . . . . . . . . . . . . . . . . 88
Configure [Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 89
Managing the memory map file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 110
To initialize the memory map file . . . . . . . . . . . . . . . . . . . . 110
To load the memory map file . . . . . . . . . . . . . . . . . . . . . . . 111
To configure the RADIUS startup script . . . . . . . . . . . . . . 111
Configuring LDAP DAL Query Caching . . . . . . . . . . . . . . . . . . . . . . . . . 112
To install LDAP DAL Query Caching . . . . . . . . . . . . . . . . . 113
To enable the LDAP DAL query cache . . . . . . . . . . . . . . . 113
To collect statistics about LDAP DAL Query Caching . . . . 114
Configuring LDAP connection pooling . . . . . . . . . . . . . . . . . . . . . . . . . . 116
Configuring remote LDAP authentication . . . . . . . . . . . . . . . . . . . . . . . 117
To define subscriber policies for remote LDAP subscribers 117
Configuring the LDAP secondary shared secret . . . . . . . . . . . . . . . . . . 119
To provision a RADIUS client with two shared secrets . . . 120

Service Controller 9.6.1-AAA October 12, 2012 Page xi


Contents Network Access Guide

Chapter 4 Diameter overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121


About Diameter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 122
Diameter interface components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 122
Bridgewater Diameter Stack . . . . . . . . . . . . . . . . . . . . . . . . . . 122
Diameter AAA application . . . . . . . . . . . . . . . . . . . . . . . . . . . . 122
Comparison of Diameter and RADIUS capabilities . . . . . . . . . . . . . . . . 123
Combined Diameter and RADIUS interfaces. . . . . . . . . . . . . . . . . . . . . 124
Diameter message format . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126
Diameter operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 127
Startup, peer discovery, and connection confirmation . . . . . . . 127
Subscriber authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . 128
Accounting collection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 130
Peer connection termination . . . . . . . . . . . . . . . . . . . . . . . . . . 131

Chapter 5 Installing and configuring Diameter. . . . . . . . . . . . . . . 133


Diameter Service Controller overview . . . . . . . . . . . . . . . . . . . . . . . . . . 134
Installing the Diameter software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 134
To determine the local IP address . . . . . . . . . . . . . . . . . . . 134
To install the Diameter packages . . . . . . . . . . . . . . . . . . . 135
Configuring LDAP access for Diameter . . . . . . . . . . . . . . . . . . . . . . . . . 135
To configure [Link] . . . . . . . . . . . . . . . . . . . . . . . 135
To create the memory map file . . . . . . . . . . . . . . . . . . . . . 135
To load the memory map file . . . . . . . . . . . . . . . . . . . . . . . 136
To modify Diameter startup (diaaaa) . . . . . . . . . . . . . . . . . 136
Configuring the Bridgewater Diameter Stack. . . . . . . . . . . . . . . . . . . . . 137
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 138
Configuring the Diameter AAA application . . . . . . . . . . . . . . . . . . . . . . 151
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 151
TLSPolicy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 154
accessReqPolicy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 154
acctReqPolicy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 154
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155
Configuring a Diameter AAA application buffer . . . . . . . . . . . . . . . . . . . 164
Configuring Diameter dictionary support . . . . . . . . . . . . . . . . . . . . . . . . 165
To install and configure Diameter dictionary files . . . . . . . 165
Configuring Diameter reauthentication . . . . . . . . . . . . . . . . . . . . . . . . . 166
To configure reauthentication . . . . . . . . . . . . . . . . . . . . . . 166
To set a local RMS cluster . . . . . . . . . . . . . . . . . . . . . . . . 166

Page xii October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Contents

Preventing network congestion for Diameter . . . . . . . . . . . . . . . . . . . . . 167


To configure settings for the congestion control
mechanism . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 169
diaaaad command line options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 170
Configuring the RMS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172
Starting and stopping the Diameter processes . . . . . . . . . . . . . . . . . . . 172
Diameter logging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
Log messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
Debug messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
Diameter troubleshooting. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 174
Error codes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 174
Syntax errors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 175

Chapter 6 Managing RADIUS and Diameter dictionaries . . . . . . 177


Managing RADIUS dictionaries (.DICT). . . . . . . . . . . . . . . . . . . . . . . . . 178
.DICT files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
Custom RADIUS dictionaries . . . . . . . . . . . . . . . . . . . . . . . . . . 185
To modify or create a RADIUS dictionary . . . . . . . . . . . . . 185
Configuring vendor-specific data ([Link]). . . . . . . . . . . . . . . . . . . 189
[Link] overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 189
[Link] elements and attributes . . . . . . . . . . . . . . . . . . . . 190
[Link] examples . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207
Managing Diameter dictionaries . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 209
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 210
To add custom Diameter vendor attributes . . . . . . . . . . . . 219
To add enumerated values to the Diameter dictionary . . . 221
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 229
[Link] . . . . . . . . . . . . . . . . . . . . . . . 229
To modify dictionary-vendor- [Link] . . . . . . . . . . . 230
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 231

Chapter 7 Configuring AAA policies . . . . . . . . . . . . . . . . . . . . . . . 233


Rules files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 234
Conditions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235
Actions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 239
Access request actions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 240
Accounting request actions . . . . . . . . . . . . . . . . . . . . . . . . . . . 246
Dynamic HA request actions . . . . . . . . . . . . . . . . . . . . . . . . . . 250
TLS request actions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 254
DAE request actions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 258
Action modifiers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 262

Service Controller 9.6.1-AAA October 12, 2012 Page xiii


Contents Network Access Guide

rejectPolicy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 293
Condition expression . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 293
Action expression . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 295
To enable the rejectPolicy . . . . . . . . . . . . . . . . . . . . . . . . . 295
Supported EAP methods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 296
Configuring PreAuthorize using Access Control Limits (ACL) for proxy 297
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297
acService modifier . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297
service modifier . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 298
RMS sessions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 298
Examples of PreAuthorize and Proxy actions using ACLs . . . 298
rejectPolicy and outageRejectMessage modifiers . . . . . . . . . . 300
Optimizing the policy file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 300
Preventing messages from being discarded . . . . . . . . . . . . . . 300
Testing policy rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 301
Radpet in a proxy deployment . . . . . . . . . . . . . . . . . . . . . . . . . 302
Example policy configurations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 303
Device reboot notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 303
Call check . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 304
Proxy by domain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 304
Proxy by called number . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 305
Service authorization for proxy . . . . . . . . . . . . . . . . . . . . . . . . 305
Default proxy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 306
Compulsory service by called number . . . . . . . . . . . . . . . . . . . 306
Policies based on day and time . . . . . . . . . . . . . . . . . . . . . . . . 306
Group domains for roaming subscribers . . . . . . . . . . . . . . . . . 307
Discarding service requests . . . . . . . . . . . . . . . . . . . . . . . . . . . 307
Default domains . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 307
Using regular expressions . . . . . . . . . . . . . . . . . . . . . . . . . . . . 308
Reference another policy file for roaming subscribers . . . . . . . 308
Policy for replacing loginName with the Calling-Station-Id . . . 309
AssignVar: policy file interaction . . . . . . . . . . . . . . . . . . . . . . . 309
EAP local authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 310
EAP proxy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 312
Microsoft CHAP (MSCHAP) . . . . . . . . . . . . . . . . . . . . . . . . . . . 313
Microsoft Point-To-Point Encryption (MPPE) . . . . . . . . . . . . . . 314
Compare User-Name to Called-Number . . . . . . . . . . . . . . . . . 315
PreAccounting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315
Preauthorization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315
HLR authorization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 316

Page xiv October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Contents

Conditional dynamic proxy target assignment . . . . . . . . . . . . . 317


Using subtype attributes in Access-Requests to control network
access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 317
To configure zone-based authorization using the
3GPP2-Subnet VSA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 318
CSID/MSID mismatch detection for LDAP deployments . . . . . . . . . . . . 320
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 320
CSID validation options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 320
Validation process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 320
Configuration options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 322
Configuring CSID/MSID mismatch detection . . . . . . . . . . . . . . 322
To create a custom log message . . . . . . . . . . . . . . . . . . . 327
Using subtype attributes in Access-Requests to control network
access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 329
To configure zone-based authorization using the
3GPP2-Subnet VSA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 329

Chapter 8 Configuring proxy targets and proxy target groups. . 331


Proxy overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 332
Proxy targets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 332
Proxy target groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 333
Attribute filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 334
Filtering using [Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . 335
Filtering using Service Manager . . . . . . . . . . . . . . . . . . . . . . . 335
Proxy request filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 335
Proxy response filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 336
Proxy configuration file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 337
[Link] schema . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 337
Proxy target configuration considerations . . . . . . . . . . . . . . . . . . . . . . . 370
RequestTimeout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 370
Consecutive failure lockout . . . . . . . . . . . . . . . . . . . . . . . . . . . 371
Intermittent failure lockout . . . . . . . . . . . . . . . . . . . . . . . . . . . . 371
Filter examples . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 372
Disallow attributes with a specific value . . . . . . . . . . . . . . . . . . 372
Allow explicit set of attributes . . . . . . . . . . . . . . . . . . . . . . . . . . 372
Allow only supported attributes . . . . . . . . . . . . . . . . . . . . . . . . 373
Filters based on AVP subtypes . . . . . . . . . . . . . . . . . . . . . . . . 374
RADIUS proxy target with filtered attributes . . . . . . . . . . . . . . 375
Proxy target server and group examples . . . . . . . . . . . . . . . . . . . . . . . . 376
Manually locking and unlocking a proxy target . . . . . . . . . . . . . . . . . . . 379
To lock or unlock a proxy target . . . . . . . . . . . . . . . . . . . . 379

Service Controller 9.6.1-AAA October 12, 2012 Page xv


Contents Network Access Guide

Configuring attribute manipulation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 379


Configuring P/FIP attribute manipulation . . . . . . . . . . . . . . . . . 380
To create a Proxy Filter . . . . . . . . . . . . . . . . . . . . . . . . . . . 382
To create a Proxy Override Attribute Group . . . . . . . . . . . 382
To create a new Proxy Required Attribute Group . . . . . . . 383
To create a RADIUS Server . . . . . . . . . . . . . . . . . . . . . . . 384
To configure P/FIP attribute manipulation in [Link] . 384
Configuring Accounting Session ID attribute manipulation . . . 386
To provision Service Manager for attribute manipulation . 387
To configure [Link] for attribute manipulation . . . . . . 389
Configuring Calling Station ID (CSID) masking . . . . . . . . . . . . 390
To provision Service Manager to enable CSID masking . . 390
To configure [Link] to enable CSID masking . . . . . . 391
Configuring Proxy attribute translation . . . . . . . . . . . . . . . . . . . 392
To provision Service Manager to enable proxy attribute
translation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 392
To modify [Link] to enable proxy attribute translation 393
Manipulating the case of attributes in the [Link] file . . . . 394
To manipulate the case of the MAC address . . . . . . . . . . 394
Attribute conversion plugin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 395
Attribute conversion plugin overview . . . . . . . . . . . . . . . . . . . . 396
To install the attribute conversion plugin . . . . . . . . . . . . . . 397
To configure the attribute conversion plugin in the
accessReqPolicy file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 397
To configure the dictionary . . . . . . . . . . . . . . . . . . . . . . . . 398

Chapter 9 Testing RADIUS Server configuration . . . . . . . . . . . . . 399


Validating configuration files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 400
Testing RADIUS Server configuration . . . . . . . . . . . . . . . . . . . . . . . . . . 401
To execute radtest requests . . . . . . . . . . . . . . . . . . . . . . . 401
To use the decryptor tool . . . . . . . . . . . . . . . . . . . . . . . . . . 405
To use the prvsa tool . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 405
Monitoring RADIUS communications. . . . . . . . . . . . . . . . . . . . . . . . . . . 409
To define valid Trace Tool clients . . . . . . . . . . . . . . . . . . . 410
To configure trace filters . . . . . . . . . . . . . . . . . . . . . . . . . . 410
To start the Trace Tool . . . . . . . . . . . . . . . . . . . . . . . . . . . 413
RADIUS dictionary files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 413
RequestInitiator, RequestHandler, and Direction fields . . . . . . 414

Page xvi October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Contents

Chapter 10 Configuring Network Address Translation (NAT) . . . . 417


Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 418
Message flows . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 418
Configuration files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 421
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 421
[Link] . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 423
Provisioning for NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 423
[Link] file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 424
Command line utilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 425
addSession . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 425
delSessions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 425
listSessions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 425
SNMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 426
Log messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 426

Chapter 11 DAL Query Caching . . . . . . . . . . . . . . . . . . . . . . . . . . . . 427


DAL Query Caching overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 428
When to use DAL Query Caching . . . . . . . . . . . . . . . . . . . . . . 428
Guidelines for DAL Query Caching . . . . . . . . . . . . . . . . . . . . . 429
[Link] file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 430
Example [Link] file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 431
Enabling and disabling DAL Query Caching . . . . . . . . . . . . . . . . . . . . . 432
To enable DAL Query Caching . . . . . . . . . . . . . . . . . . . . . 432
To disable DAL Query Caching . . . . . . . . . . . . . . . . . . . . . 433
Configuration guidelines . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 433
General . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 433
cachemaxentries . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 433
cachemaxmemory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 434
cachecontextbitmap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 434
cachetimetolive . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 435
DAL cache metrics. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 435
Usage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 435

Appendix A RADIUS accounting record generation logic . . . . . . . 437


Accounting record generation logic overview . . . . . . . . . . . . . . . . . . . . 438
Terms used in the flow charts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 438
RADIUS accounting pending record . . . . . . . . . . . . . . . . . . . . . . . . . . . 439
RADIUS accounting start record . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 440
RADIUS accounting interim record . . . . . . . . . . . . . . . . . . . . . . . . . . . . 441
RADIUS accounting stop record . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 442

Service Controller 9.6.1-AAA October 12, 2012 Page xvii


Contents Network Access Guide

Page xviii October 12, 2012 Service Controller 9.6.1-AAA


RADIUS Server start-up options and

1
Chapter 1
Chapter

access features

This chapter describes RADIUS Server start-up features an access features and
how to configure them.
The topics are:
• RADIUS Server startup options
• Configuring access features with [Link]
• Preventing network congestion for RADIUS
• RADIUS subscriber data access
For a list of RADIUS Server messages, see “RADIUS Server system logs” in the
Service Controller: Log Messages Guide.

Service Controller 9.6.1-AAA October 12, 2012 Page 1


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

RADIUS Server startup options


Control RADIUS Server operations by changing the parameters in the RADIUS
Server startup file /opt/aaasc/config/radius/wsradius.
As the root user, in the /opt/aaasc/config/radius directory, edit the ‘start’ line in the
wsradius file to change the command line parameters:
$PRODUCT_DIR/radius/radiusd -C $PRODUCT_DIR/config
$WSRADIUS_CLI -p 1812 -t 50 -F 1500
Restart the RADIUS Server for the changes to take effect.
Table 1 lists the parameters for the radiusd command.

Table 1: radiusd command parameters

Usage Description

radiusd -C <ConfigDir>options Run in daemon mode.


For a list of options, see Table 2.

radiusd -x -C <ConfigDir>options Run in debug mode.


For a list of options, see Table 2.

radiusd -V -C <ConfigDir>options Verify configuration files.


For a list of options, see Table 2.

radiusd -T timeout Timeout value for RADIUS request.


• the default is 5 seconds.
• the range is 1 to 30 seconds.
Use this parameter to deal with congestion on the RADIUS Server. For example, if this
is set to 5 seconds, RADIUS discards packets from the queue if the packet is older
than 5 seconds.
Under normal circumstances a packet remains in the queue for only a few
milliseconds, but as the number of threads is exhausted, the queue may grow and
eventually the timeout parameter kicks in.
For more information about RADIUS congestion control, see "Preventing network
congestion for RADIUS" on page 26.
For information about the relation between this timeout value and the duplicate
detection feature configured in [Link], see "DuplicateDetection" on page 17.

Table 2 on page 3 lists the options for the radiusd command.


Note If the -n, -f, and -P command line options are not specified, the base DN,
user filter, and password configuration fields in the [Link] file are
used for device authentications.

Page 2 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

Table 2: radiusd command options

Option Description

-a type=opt Accounting type and directory that holds accounting files.


Valid accounting types are:
• liv (Livingston accounting), for example,
-a liv =<base_directory>
• buf (local buffer accounting). The default <config_file_name> is buffer_config.xml. The default
<BufferName> is radbuff. For example:
-a buf =<config_file_name>:<BufferName>

-b ip address The bind IP address.

-c path The location and filename of the database configuration file. The default is /opt/aaasc/config/[Link].
To startup RADIUS to use an LDAP database, first create and populate an internal memory map file for
RADIUS to access. Next, use the -c option with the location of the memory map file. For example, -c /opt/
aaasc/dal/config/cached_file.mmp.

-d dir The directory in which the RADIUS configuration files are located. The default is <ConfDir>/radius/
[Link].

-E|D features Enable/Disable one or more of the following features:


• trace—trace client support (default is enabled)
• snmp—SNMP agent (default is enabled)
• dbalert—DB Alert (default is enabled)
• accounting—Global accounting (default is enabled)
• wsacct—Bridgewater accounting (default is enabled)
• lvacct—Livingston accounting (default is disabled)
• ssr—Session State Register (default is disabled)
• hotline—Hotline (default is disabled)

-F file Enables super administrators to change the limit of file descriptors. If the value of the file descriptor needs
descriptors to be greater than 1024, see the Bridgewater Installation Reference Guide for details about calculating a
value.

-f Enables an LDAP filter to be configured for device authentications by a WiMAXLocalAA action. An


example filter is: (&amp;(uid={loginname})(objectClass=wimaxHandsetId)).
This option must be used together with options -n and -P.

-h Displays online help pages.

-l facility:level Enables logging of RADIUS Server debug messages. Only use this option after consulting Bridgewater
Customer Support. For standard debugging purposes, Bridegwater Systems recommends using the -L
option to log operational messages or use the RADIUS Trace Tool.
The default facility is local6:0.
The options for level are integers between 0 and 15. The default level is 0, which disables logging. 15
records the most detail and 1 records the least detail.
To enable this option, edit [Link] and send a -HUP signal to syslogd for the changes to take effect.

-m opt-value The Mobile IP address where the opt-value is either s or l. Option s is the default ‘S’ key lifetime (in
seconds) for the Home Agent, and option l is the default dynamic ‘S’ key length (in bytes) for the Home
Agent.

Service Controller 9.6.1-AAA October 12, 2012 Page 3


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

Table 2: radiusd command options (continued)

Option Description

-n Enables an LDAP base DN to be configured for device authentications by a WiMAXLocalAA action. An


example base DN for devices is: o=handsets,o=wimaxusers,dc=bridgewatersys,dc=com.
This option must be used together with options -f and -P.

-P Enables the LDAP attribute that is used to store the password for device authentications by a
WiMAXLocalAA action. An example value for the device password is: abcMobileChapPassword.
This option must be used together with options -f and -n.

-p portnum A port for RADIUS communication with NASs for authentication.


The default port for authentication is 1812. The default port for accounting is the next highest port number.
RADIUS selects which authentication ports to listen on based on the following algorithm:
• If the port is specified on the command line, RADIUS uses it as the authentication port.
• Else if a "radius" entry exists in the /etc/services file, RADIUS uses the port in the entry as the
authentication port.
• If 1 and 2 are not met, use the default port 1812.
For the accounting port:
• If the port is specified on the command line, the accounting port is +1 the port that was specified.
• If there is a "radacct" entry in the /etc/services file, RADIUS uses the port in the entry
• If 1 and 2 are not met, use the default port 1813.
If a facility other than local1 is specified, there may be a need to add an entry to the [Link] file.

-r number The maximum rate of traffic from all clients (in transactions/sec) that the RADIUS Server can support. The
value must be in the range 1–10000. The default is 1500.
• The RADIUS Server’s ingress message queue is initialized to twice the value specified by the -r option.
For more information about RADIUS congestion control, see "Preventing network congestion for
RADIUS" on page 26.
• If the RADIUS log files contain “Failed to allocate RadiusAAAInfo” error messages, consider increasing
the peak transaction rate.

-s port The secondary port for RADIUS communication with NASs for authentication. There is no default value for
the secondary port. The default secondary port for accounting is the next highest port number.

-t N Specifies N number of threads to run. The default is 50.


For information about calculating the required number of threads, contact Bridgewater Customer Support.

-u Enable processing of unknown attributes.

-V Validates RADIUS Server configuration files.

-v Displays the RADIUS Server version.

-w num The database alert thread wait-time in seconds. The default is 600 seconds.

Page 4 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

Configuring access features with [Link]


Use the [Link] file, located in the /opt/aaasc/config/radius directory, to
configure the RADIUS Server access features described in this chapter.
For an example, see "[Link] example" on page 24.

[Link] schema
The [Link] schema contains these elements:
RADIUS Configuration: the root element
PrepaidService
UserLockout
RealmMetrics
DefaultRealm
Realm
LocalDomains
BRMPTCPConnectionOptions
RMSClientConfig
Accounting
WLAN
DAE
DuplicateDetection
CongestionControl
StateOrange
StateRed
WiMAXDualSiteRMS
RemoteRMSCluster

Service Controller 9.6.1-AAA October 12, 2012 Page 5


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

RADIUS The root element that encloses the optional elements:


Configuration • PrepaidService
• UserLockout
• RealmMetrics
• LocalDomains
• BRMPTCPConnectionOptions
• RMSClientConfig
• Accounting
• WLAN
• DAE
• DuplicateDetection
• CongestionControl
• WiMAXDualSiteRMS

Table 3: RADIUSConfiguration attributes

Attribute Value Description

AcctDBLookup • Y (default) Perform database information retrieval for accounting requests.


• N Disabling this increases performance; however, it does prevent
retrieval of database information, such as, "account name",
“Billing ID", and, "Domain".
Optional.

DefaultAccessControlService String The default access control service profile assigned to the
Default = “Access subscriber during an Access-Request if there is more than one
Control” access control service profile in the subscriber’s profile set and
no access control service profile is specified on the policy line.
Note This setting is ignored in the case of PreAuthorize where
the access control service must be explicitly configured
in the policy file in order to be evaluated.
Optional.

DNSThreads Integer The number of threads that are created and dedicated to DNS
Default = 0 update handling if the subscriber IP Reachability Service is
used. By default, no threads are created and this feature is
disabled. To enable it, set DNSThreads to a number greater
than 0, and set the “enableIPReach” policy action in access
ReqPolicy.
This parameter is not reloaded on HUP.
For more information about policy actions, see Chapter 7,
"Configuring AAA policies".
Optional.

Page 6 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

Table 3: RADIUSConfiguration attributes (continued)

Attribute Value Description

MaximumLoadedClients Integer (1-32000) The maximum number of RADIUS clients stored in memory.
Default = 5000 The number includes all types of RADIUS clients, such as
PDSN, NAS, GGSN, WiMAX clients and proxies.
Note A typical system initializes approximately 2500 NAS
clients per minute on startup or HUP. If thousands of
clients are configured, the startup or restart time
sequence length is extended proportionally.

ValidateClientIP • Y (default) Checks if the client is a valid RADIUS client. If the client is
• N unknown and the option is disabled, RADIUS will use a
representative client to process the request. The
representative client must be modeled in the system with an IP
of [Link]. For more information about configuring a
representative client, see Service Manager: Getting Started
Guide for AAA.

WiMAXReAuthenticationInterval Integer (300–302400) The time, in seconds, that WiMAX Mobility Keys stay valid
Default = 1800 before reauthentication is required.
Bridgewater Systems recommends setting the value to half or
less of the shortest HA RK Lifetime that is provisioned against
any WiMAX Home Agent Role in the system.
This option returns the Session-Timeout value set to the lower
of:
• this configuration value
• the Session-Timeout attribute provisioned against the
subscriber
Note For information about configuring the reauthentication
interval for Diameter, see "Configuring Diameter
reauthentication" on page 166.
Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 7


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

Table 3: RADIUSConfiguration attributes (continued)

Attribute Value Description

WiMAXReAuthenticationInterval Integer (0–302400) The boundaries of a range, from which the RADIUS server
Delta Default = 0 randomly generates a value, in seconds, to add to or subtract
from the Session-Timeout value.
• For example, if
WiMAXReAuthenticationIntervalDelta="100", the range from
which RADIUS randomly generates values is -100 to 100
seconds.
The value of WiMAXReAuthenticationIntervalDelta must be
less than half the WiMAXReAuthenticationInterval value.
• For example, if WiMAXReAuthenticationInterval="900" then
WiMAXReAuthenticationIntervalDelta must be 449 or lower.
Note Bridgewater Systems recommends that
WiMAXReAuthenticationIntervalDelta be significantly
less than half the WiMAXReAuthenticationIntervalDelta.
In the example above, a guideline would be to set
WiMAXReAuthenticationIntervalDelta to 100.
This attribute works with both the CDMA2000LocalAA and
WiMAXLocalAA policy actions.
Optional.

LogCallingStationIdOnReject • Y When set to Y, specifies to include the Calling-Station-Id in the


• N (default) log message when a subscriber is rejected for any of the
following reasons:
• SendReject Policy specified in policy file
• subscriber cannot be found
• invalid password
When enabled, the Calling-Station-Id in the affected logs is
displayed as the concatenation of the User-Name and
Calling-Station-Id attributes, separated by a "|" character. For
example:
"MDN@realm|111112123141241"
If the Calling-Station-Id is unavailable in the Access Request,
the Calling-Station-Id is shown in the log message as
"MDN@realm|null".

LogNASIP • y|Y When set to y|Y the RADIUS Server adds the NAS-IP-Address
• n|N (Default=n|N) attribute to RADIUS Server operational log messages
(RADOP).
When set to y|Y the RADIUS Server adds the NAS-IP-Address
in the following format:
NAS-IP:x.x.x.x
Note Also use the RADIUS [Link] file to configure
attributes to include in RADOP log messages. For more
information, see the chapter “Configuring the Logging
Framework” in the Service Controller: Monitoring and
Logging Guide.

Page 8 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

Table 3: RADIUSConfiguration attributes (continued)

Attribute Value Description

LengthBasedCSIDDecode • Y|y When set to Y RADIUS assumes the content of the CSID
• N|n (Default=N) attribute is a MAC address.
Also when set to Y RADIUS evaluates the CSID based on the
its length, and uses the CSID length to determine its encoding
type.
Note If LengthBasedCSIDDecode is configured in
[Link] and CSIDDecodeMethod is configured
in [Link] on the same server, the action specified
in [Link] overrides the action specified by
[Link].

TGPP2ChargingCharsUTF8 • Y|y When set to Y RADIUS converts the contents of the


Encode • N|n (Default=N) 3GPP2-Charging-Characteristics attribute to UTF-8 format
before returning it in an Access-Accept message.

EAPSessionCacheEnabled • Y|y When set to Y, RADIUS caches user data required for policy
• N|n (Default=N) actions, such as Pre-Authorize, triggered during an EAP
exchange. This data is saved to the EAP-state cache
and persists for the duration of the EAP exchange.
For more information about enabling and using DAL query
caching, see "Configuring database (DAL query) caching for
multi-leg EAP" on page 74.
Note: This is a custom feature that requires the BWScdal
package. For more information, contact Bridgewater Systems.

PrepaidService Configures prepaid data services parameters. This element is required if Prepaid
service is enabled.
Child element of RADIUS Configuration.
For more information, see "Configuring user and network lockout" on page 38.
For example:
<PrepaidService
PrepaidEnabled="Y"
PrepaidTarget="PrepaidTargetGroup"
ForwardPrepaidAcct="N"
QARejectEnabled=”Y”
QAPoolID=”QuickAccessPool” />

Service Controller 9.6.1-AAA October 12, 2012 Page 9


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

Table 4: PrepaidService attributes

Attribute Value Description

PrepaidEnabled • Y Enable prepaid services for CDMA2000 prepaid subscribers.


• N (default) Optional

PrepaidTarget • Y The name of the global prepaid target. The target name must exist in
• N (default) [Link].
Required if PrepaidEnabled = Y.

ForwardPrepaidAcct • Y Forward prepaid accounting records to the 'PrepaidTarget'.


• N (default) Optional.

QARejectEnabled • Y Enable Quick-Access for prepaid subscribers.


• N (default)

QAPoolID String (1–253 The name of an IP address pool that offers limited network access to
characters) direct subscribers to a replenishment portal to increase their quota.

UserLockout Enables and defines the settings for user and network lockout mechanisms.
Child element of RADIUS Configuration.
For more information, see "Configuring user and network lockout" on page 38.
For example:
<UserLockout
UserLockoutEnabled="Y"
ConsecutiveAuthFailuresAllowed="5"
ConsecutiveAuthFailureMonitorDuration="86400"
ConsecutiveAuthFailureLockoutDuration="1200" />

Table 5: UserLockout attributes

Attribute Value Description

UserLockoutEnabled • Y Y—Enable lockout. Also requires configuration of


• N (default) LockoutOnUserAccept and LockoutOnAuthorizeOnly in [Link]
to define the type of lockout.
N—The lockout feature is disabled.
Optional.

ConsecutiveAuthFailures Integer (1–50) The number of consecutive authentication/authorization events


Allowed Default = 5 allowed before a lockout occurs.
Optional.

Page 10 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

Table 5: UserLockout attributes (continued)

Attribute Value Description

ConsecutiveAuthFailure Integer (15–86400) The number of seconds to monitor a subscriber account for a
MonitorDuration Default = 86400 particular authentication/authorization event (as defined by the
LockoutConfig settings in [Link]). Monitor duration restarts after
each monitored event. When the time between events exceeds this
value, or the user is locked out, monitoring stops and the event count
resets to zero (for ConsecutiveAuthFailuresAllowed).
Optional.

ConsecutiveAuthFailure Integer (1–31536000) The time, in seconds, that a subscriber account remains locked out.
LockoutDuration Default = 1200 Optional.

RealmMetrics Enables multiple NAI mechanisms. This element is required if RealmMetrics service
is enabled.
Child element of RADIUS Configuration.
For more information, see "Configuring Multiple NAI" on page 52.
The RealmMetrics element encloses:
• an optional DefaultRealm child element
• one or more Realm child element
For example:
<RealmMetrics
RealmMetricsEnabled="Y"
DefaultRealmEnabled="Y">
<DefaultRealm... />
<Realm ... />
</RealmMetrics>

Table 6: RealmMetrics attributes

Attribute Value Description

RealmMetricsEnabled • Y Enable realm-based SNMP metrics. MIB tables are generated only for
• N (default) realms provisioned in this file. Optional.

DefaultRealmEnabled • Y Enable default realm metrics. This default realm aggregates metrics for
• N (default) requests that do not match any of the explicitly configured realms.
Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 11


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

DefaultRealm Default realm information.


Child element of RealmMetrics.
For example:
<DefaultRealm
DefaultRealmName="EveryoneElse"
DefaultAcctMetrics="N"/>

Table 7: DefaultRealm attributes

Attribute Value Description

DefaultRealmName String A unique name, containing no spaces, to capture metrics for realms not
Default = specified in this file.
”Unspecified Required if realm-based SNMP metrics are enabled.
Realms”

DefaultAuthMetrics • Y (default) Enable tracking of authorization metrics.


• N One or both of DefaultAuthMetrics and DefaultAcctMetrics is required.

DefaultAcctMetrics • Y (default) Enable tracking of accounting metrics.


• N One or both of DefaultAuthMetrics and DefaultAcctMetrics is required

Realm Realm information.


Child element of RealmMetrics.
For example:
<Realm RealmName="xyz" AuthMetrics="N"/>

Table 8: Realm attributes

Attribute Value Description

RealmName String A unique name, containing no spaces, identifying the realm.

AuthMetrics • Y (default) Enable tracking of authorization metrics.


• N

AcctMetrics • Y (default) Enable tracking of accounting metrics.


• N

Page 12 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

LocalDomains Local realm information for realm routing syntax conversion. For more information,
see "Configuring realm routing support" on page 58.
Child element of RADIUS Configuration.
The LocalDomains element encloses one or more Domain child element.
For example:
<LocalDomains>
<Domain Name="[Link]"/>
<Domain Name="[Link]"/>
</LocalDomains>

BRMPTCPConnection Minimum, maximum, and threshold values for TCP connections to the RMS. For
Options more information, see the Service Controller: Resource Management Server Guide
Child element of RADIUS Configuration.
For example:
<BRMPTCPConnectionOptions
TCPConnectionsMin="1"
TCPConnectionsMax="100"
TCPConnectionsThreshold="80"
/>

Table 9: BRMPTCPConnectionOptions attributes

Attribute Value Description

TCPConnectionsMin Integer The minimum number of TCP connections to an RMS server.


Default = 1

TCPConnectionsMax Integer The maximum number of open TCP connections to an RMS


Default = 100 server.

TCPConnectionsThreshold Integer The usage threshold value.


Default = 80

RMSClientConfig The number of threads used to handle the message queue for Asynchronous
requests. This prevents the queue from backing up during connection creation.
These parameters are not huppable.
Child element of RADIUS Configuration.
Note This element is optional. Therefore, upon a fresh installation, this element
must be copied from /opt/aaasc/radius/[Link] to the
[Link] file in /opt/aaasc/config/radius.

Service Controller 9.6.1-AAA October 12, 2012 Page 13


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

<RMSClientConfig
ThreadCount="20"
MaxQueueSize="16000"
/>

Table 10: RMSClientConfig attributes

Attribute Value Description

ThreadCount Integer (1–300) The number of worker threads in the RMS client.
Default = 20 Optional.

MaxQueueSize Integer (1–128000) The maximum RMS client request queue size.
Default = 16000 Optional.

Accounting Enables configuration of multiple buffers.


Child element of RADIUS Configuration.
Optional.
The Accounting element encloses an optional AccountingBuffers element.
<Accounting>
<AccountingBuffers DistributionAlgorithm="RoundRobin">
<AccountingBuffer name="radbuff2"/>
</AccountingBuffers>
</Accounting>

AccountingBuffers Sets up the record distribution method.


Child element of Accounting.
Optional.
Accounting Buffers encloses the AccountingBuffer child element.

Table 11: AccountingBuffers attributes

Attribute Value Description

DistributionAlgorithm String In RoundRobin distribution, RADIUS inserts records into buffers using
Default = round robin.
RoundRobin In LoginName distribution, RADIUS invokes a string hashing function
on the login name which maps the login name to a specific buffer. The
accounting record is written to the assigned buffer. A user’s accounting
records always go to the same buffer.

Page 14 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

AccountingBuffer Lists buffers in addition to the default radbuff.


Child element of AccountingBuffers.
Optional.

Table 12: AccountingBuffer attributes

Attribute Value Description

Name String The names of the buffers. There may be up to four additional buffers.
The names listed here must match the names of buffers configured in
the [Link] file.

WLAN Global WLAN configuration for the RADIUS Server.


Child element of RADIUS Configuration.
The WLAN element encloses one or more of the following attributes:
• CacheClusterId
• ProfileLife
For example:
<WLAN
CacheClusterId="1"
ProfileLife="1440"/>

Table 13: WLAN attributes

Attribute Value Description

CacheClusterId Integer The RMS cluster ID where WLAN sessions are cached.
When not set, the default value is the cluster ID associated with the GSM
node group.
Optional.

ProfileLife Integer (5–43200) The time, in minutes, that the cached subscriber profile remains in the
Default = 1440 RMS before it is purged.
To enforce WLAN session life, you need to configure RMS session audits,
including session life limits. For details, see the “RMS configuration”
chapter the Service Controller: Resource Management Server Guide.
Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 15


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

DAE Enables and defines the settings for Dynamic Authorization Extensions for CoA
request support.
Child element of RADIUS [Link] example:
<DAE
Port="3799"
DefaultDictionary="RFC2138"
EventTimestampRequired="N"
EventTimestampThreshold="300"/>For more information,see "Configuring
RADIUS mid-session hotlining" in the Service Controller: WiMAX Guide.

Table 14: DAE attributes

Attribute Value Description

Port Integer (1024–65535) The UDP port on which to receive DAE requests.
Default = 3799 Optional.

DefaultDictionary String (1–20) The dictionary RADIUS uses to decode the incoming DAE requests.
Default = RFC2138 The DefaultDictionary value must match an entry in the /opt/aaasc/
config/dictionaries file.
Optional.

EventTimestampRequired • Y, y N, n—The Event-Timestamp attribute is not required in DAE


• N, n (default) requests. If the Event-Timestamp attribute is in the request, RADIUS
validates it according to the EventTimestampThreshold value. If the
Event-Timestamp attribute is not in the request, RADIUS processes
the request as usual.
Y, y—The Event-Timestamp attribute is required in DAE requests. If
the Event-Timestamp attribute is not present, RADIUS generates an
ERR log and discards the request.
Optional.

EventTimestampThreshold Integer (1–86400) The allowable difference between the system time and the time
Default = 300 reported in the Event-Timestamp attribute in seconds. This value is
only considered if the DAE request/response contains the
Event-Timestamp. If the Event-Timestamp value falls outside the
threshold range, the request is dropped and an error is logged.
Optional.

Page 16 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

DuplicateDetection Encloses the attributes DetectionThreshold, ReplayLastResponseThreshold, and


AuditInterval, which specify settings for how the RADIUS Server processes
duplicate request messages.
Child element of RADIUS Configuration.
Considerations:
• To configure RADIUS to process duplicate request messages, you must also
set the DuplicateDetection attribute in [Link] to “Y” for each required
vendor. For more information, see "Configuring vendor-specific data
([Link])" on page 189.
• RADIUS generates an ERR log message and fails to HUP if the configuration
for the DuplicateDetection element has changed since the RADIUS Server was
first started.
• the cache that RADIUS uses to detect duplicate requests is in memory only and
does not persist across multiple RADIUS instances or RADIUS Server restarts.
• RADIUS generates a NTCE level log message and retransmits the same
response for a received request message when:
– the time when the first response was sent is less than or equal to the
DetectionThreshold
– RADIUS has re-transmitted the response message less than or equal to
the value specified by ReplayLastResponseThreshold,.
• When ReplayLastResponseThreshold is set to 0, and RADIUS receives a
duplicate request, RADIUS generates a NTCE log message and drops the
request.
• RADIUS generates a WARN log message and drops a request if RADIUS has
returned the same response message (ReplayLastResponseThreshold+1)
times in the time specified by the DetectionThreshold.
• if the ReplayLastResponseThreshold is exceeded within an AuditInterval period
and RADIUS receives a duplicate request, RADIUS processes the duplicate
request as follows:
– sends an Access-Reject for Access-Request messages
– drops the message if the request is an Accounting-Request
– NAKs the message if the request is a CoA or DM
• when the AuditInterval expires, RADIUS has to process the duplicate message
again and considers the duplicate message as a new message.
• when the RADIUS server receives a duplicate request, but has not yet sent a
response for the first request, the RADIUS Server generates an NTCE log
message and drops the duplicate request.
• RADIUS increments SNMP duplicate metrics when it detects a duplicate
request.
• RADIUS increments SNMP response metrics when it replays a duplicate
response message.

Service Controller 9.6.1-AAA October 12, 2012 Page 17


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

For example:
<DuplicateDetection
DetectionThreshold="15"
ReplayLastResponseThreshold="1"
AuditInterval="15"/>

Table 15: DuplicateDetection attributes

Attribute Value Description

DetectionThreshold Integer The time, in seconds, that RADIUS considers a request a duplicate.
Range=value of Note RADIUS generates an ERR log message and fails to start/HUP
(radiusd -T option + 1 if the DetectionThreshold is less than the value of (radiusd -T
second) to option + 1 second).
AuditInterval
Default=value of
(radiusd -T option + 1
second)

ReplayLastResponse Integer The number of times RADIUS can replay the same response
Threshold (0-2) message back to the client.
Default=0 When set to 0, and RADIUS receives a duplicate request, RADIUS
generates a NTCE log message and drops the request.

AuditInterval Integer The time, in seconds, which determines how often the RADIUS
(10-20) Server removes cached response messages from memory.
Default=10

CongestionControl Encloses the child elements StateOrange and StateRed, which specify settings for
how the RADIUS Server applies congestion control processing when in the orange
or red congestion state.
Child element of RADIUS Configuration.
For more information about configuring RADIUS congestion control, see the section
"Preventing network congestion for RADIUS" on page 26.

StateOrange Encloses the following attributes:


• AuthEAPDropProbability
• AuthNonEAPDropProbability
• AcctStartDropProbability
• AcctInterimDropProbability
• AcctStopDropProbability
• DAERejectProbability
StateOrange attributes specify settings for how the RADIUS Server applies
congestion control processing when RADIUS is in the orange congestion state.
Child element of CongestionControl.

Page 18 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

For example:
<StateOrange
AuthEAPDropProbability="50"
AuthNonEAPDropProbability="60"
AcctStartDropProbability="0"
AcctInterimDropProbability="100"
AcctStopDropProbability="0"
DAERejectProbability="50"/>

Table 16: StateOrange attributes

Attribute Value Description

AuthEAPDropProbability Integer The probability the RADIUS server drops a new EAP authentication
(0-100) request.
Default=50 The probability is expressed as a percentage between 0 and 100.

AuthNonEAPDrop Integer The probability the RADIUS server drops a non-EAP authentication
Probability (0-100) request.
Default=60 The probability is expressed as a percentage between 0 and 100.

AcctStartDropProbability Integer The probability the RADIUS server drops an Accounting-Start


(0-100) request.
Default=0 The probability is expressed as a percentage between 0 and 100.

AcctInterimDropProbability Integer The probability the RADIUS server drops an Accounting-Interim


(0-100) request.
Default=100 The probability is expressed as a percentage between 0 and 100.

AcctStopDropProbability Integer The probability the RADIUS server drops an Accounting-Stop


(0-100) request.
Default=0 The probability is expressed as a percentage between 0 and 100.

DAERejectProbability Integer The probability the RADIUS server rejects and sends a NAK for a
(0-100) DAE (CoA/DM) request.
Default=50 The probability is expressed as a percentage between 0 and 100.

StateRed Encloses the following attributes:


• AuthEAPBaseDropProbability
• AuthEAPPerLegProbabilityReduction
• AuthNonEAPDropProbability
• AcctStartDropProbability
• AcctInterimDropProbability
• AcctStopOldDropProbability
• AcctStopYoungDropProbability
• DAERejectProbability

Service Controller 9.6.1-AAA October 12, 2012 Page 19


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

StateRed attributes specify settings for how the RADIUS Server applies congestion
control processing when RADIUS is in the red congestion state.
Child element of CongestionControl.
For example:
<StateRed
AuthEAPBaseDropProbability="100"
AuthEAPPerLegProbabilityReduction="45"
AuthNonEAPDropProbability="60"
AcctStartDropProbability="0"
AcctInterimDropProbability="100"
AcctStopOldDropProbability="50"
AcctStopYoungDropProbability="60"
DAERejectProbability="60"/>

Table 17: StateRed attributes

Attribute Value Description

AuthEAPBaseDrop Integer The probability the RADIUS server drops a new EAP authentication
Probability (0-100) request.
Default=100 The probability is expressed as a percentage between 0 and 100.

AuthEAPPerLegProbability Integer The probability the RADIUS server drops an EAP authentication
Reduction (0-100) request for an in-progress session.
Default=45 The probability of dropping an EAP authentication request for an
in-progress session is determined by the following calculation:
AuthEAPBaseDropProbability - (EAP leg *
AuthEAPPerLegProbabilityReduction)
For example, if AuthEAPBaseDropProbability=100 and
AuthEAPPerLegProbabilityReduction=45:
• for an in-progress session with leg count equal to 1, there is a 55 %
chance the RADIUS Server will drop the message.
• for an in-progress session with leg count equal to 2, there is a 10 %
chance the RADIUS Server will drop the message.
• for an in-progress session with leg count greater than 2, the
RADIUS Server will process the message normally.
The probability is expressed as a percentage between 0 and 100.

AuthNonEAPDrop Integer The probability the RADIUS server drops a non-EAP authentication
Probability (0-100) request.
Default=60 The probability is expressed as a percentage between 0 and 100.

AcctStartDropProbability Integer The probability the RADIUS server drops an Accounting-Start


(0-100) request.
Default=0 The probability is expressed as a percentage between 0 and 100.

Page 20 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

Table 17: StateRed attributes (continued)

Attribute Value Description

AcctInterimDropProbability Integer The probability the RADIUS server drops an Accounting-Interim


(0-100) request.
Default=100 The probability is expressed as a percentage between 0 and 100.

AcctStopOldDrop Integer The probability the RADIUS server drops an Accounting-Stop request
Probability (0-100) for which the Acct-Delay-Time AVP is greater than -T.
Default=50 The probability is expressed as a percentage between 0 and 100.

AcctStopYoungDrop Integer The probability the RADIUS server drops an Accounting-Stop


Probability (0-100) request, for which the Acct-Delay-Time AVP is less than -T.
Default=60 The probability is expressed as a percentage between 0 and 100.

DAERejectProbability Integer The probability the RADIUS server rejects and sends a NAK for a
(0-100) DAE (CoA/DM) request.
Default=60 The probability is expressed as a percentage between 0 and 100.

WiMAXDualSiteRMS Encloses the attribute LocalSite and the child element RemoteRMSCluster.
Child element of RADIUS Configuration.
WiMAXDualSiteRMS and the child element RemoteRMSCluster can be used in
WiMAX networks with geo-redundant sites to specify a mapping of local RMS
clusters to partner RMS clusters on a remote site. The RADIUS Server uses the
mapping specified in the WiMAXDualSiteRMS and RemoteRMSCluster elements
and configuration in [Link] to determine which site and RMS cluster to
search for subscriber sessions in the event of a WiMAX site failover.
The presence of WiMAXDualSiteRMS in [Link] enables the 4G Service
Controller to support RMS availability during WiMAX site failover:
• If WiMAXDualSiteRMS is not present in [Link], RMS availability
during WiMAX site failover is not supported.
• If WiMAXDualSiteRMS is not present and a local network link between an
ASN-GW and the local Service Controllers goes down after initial
authentication, the local ASN-GW can failover to the remote site but the remote
Service Controller cannot access RMS sessions created on initial
authentication in the local RMS cluster.
For more information about configuring RMS availability during WiMAX site failover,
see the chapter “Configuring WiMAX” in the Service Controller: WiMAX Guide.

Service Controller 9.6.1-AAA October 12, 2012 Page 21


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

Example configuration for site A


Example [Link] configuration on the 4G Service Controller on site A:
<WiMAXDualSiteRMS LocalSite="A">
<RemoteRMSCluster ClusterId="100" LocalMateId="0" NativeClusterId="0"/>
<RemoteRMSCluster ClusterId="101" LocalMateId="1" NativeClusterId="2"/>
</WiMAXDualSiteRMS>
• LocalSite specifies configuration is for the 4G Service Controller on site A.
• ClusterId specifies the ID of the remote RMS cluster as it appears in site A’s
[Link] file.
• NativeClusterId specifies the ID of the remote RMS cluster as it appears in site
B’s [Link] file.
• LocalMateId specifies the ID of the RMS cluster on site A that is paired with the
remote RMS cluster being defined.
The [Link] configuration above corresponds to the following in
[Link] for the 4G Service Controller on site A:
# Local Clusters
0 [Link] 34501 MYSECRET [Link]
34505 SECONDSECR 5 - -

1 [Link] 34501 MYSECRET [Link]


34505 SECONDSECR 5 - -

# Remote Clusters
100 [Link] 34501 MYSECRET [Link]
34505 SECONDSECR 5 - -

101 [Link] 34501 MYSECRET [Link]


34505 SECONDSECR 5 - -
For failover, the 4G Service Controller on site A compares the RMS cluster and site
hint specified in incoming Access and Accounting messages against the site A
configuration for [Link] and [Link] to determine which site and
RMS cluster to search for subscriber sessions.

Example configuration for site B


The following configuration is also required on site B:
<WiMAXDualSiteRMS LocalSite="B">
<RemoteRMSCluster ClusterId="100" LocalMateId="0" NativeClusterId="0"
/>
<RemoteRMSCluster ClusterId="102" LocalMateId="2" NativeClusterId="1"
/>
</WiMAXDualSiteRMS>

Page 22 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

The [Link] configuration above corresponds to the following in


[Link] for the 4G Service Controller on site B:
# Local Clusters
0 [Link] 34501 MYSECRET [Link]
34505 SECONDSECR 5 - -

2 [Link] 34501 MYSECRET [Link]


34505 SECONDSECR 5 - -

# Remote Clusters
100 [Link] 34501 MYSECRET [Link]
34505 SECONDSECR 5 - -

102 [Link] 34501 MYSECRET [Link]


34505 SECONDSECR 5 - -
For failover, the 4G Service Controller on site B compares the RMS cluster and site
hint specified in incoming Access and Accounting messages against the site B
configuration for [Link] and [Link] to determine which site and
RMS cluster to search for subscriber sessions.

Table 18: WiMAXDualSiteRMS attributes

Attribute Value Description

LocalSite • A Specifies whether the configuration is for site A or B.


• B Required.

RemoteRMSCluster Encloses the attributes ClusterId, NativeClusterId, and LocalMateId. These


attributes provide a mapping of local RMS clusters to partner RMS clusters on a
remote site. The RADIUS Server uses the mapping specified in the
WiMAXDualSiteRMS and RemoteRMSCluster elements and configuration in
[Link] to determine which site and RMS cluster to search for subscriber
sessions in the event of a WiMAX site failover.
Child element of WiMAXDualSiteRMS.
Example of RemoteRMSCluster configuration on the 4G Service Controller on site
A:
<WiMAXDualSiteRMS LocalSite="A">
<RemoteRMSCluster ClusterId="101" LocalMateId="1" NativeClusterId="2"/>
</WiMAXDualSiteRMS>

Service Controller 9.6.1-AAA October 12, 2012 Page 23


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

In this example:
• the LocalSite attribute specifies that the configuration is for the 4G Service
Controller on site A.
• ClusterId specifies the ID of the remote RMS cluster as it appears in site A’s
[Link] file.
• NativeClusterId specifies the ID of the remote RMS cluster as it appears in site
B’s [Link] file.
• LocalMateId specifies the ID of the RMS cluster on site A that is paired with the
remote RMS cluster being defined.
Note RemoteRMSCluster configuration is required on the 4G Service Controllers
on both sites in a WiMAX network with geo-redundant sites.
For more information about configuring RMS availability during WiMAX site failover,
see the chapter “Configuring WiMAX” in the Service Controller: WiMAX Guide.

Table 19: RemoteRMSCluster attributes

Attribute Value Description

ClusterId Integer The ID of the remote cluster as it appears in the local site’s
(0-254) [Link] file.
Required.

NativeClusterId Integer The ID of the remote RMS cluster as it appears in the remote site’s
(0-254) [Link] file.
For example if the local site’s [Link] specifies a remote RMS
cluster with an ID of 101, this corresponds to an RMS cluster with ID 2
in the remote site’s [Link] file. In this case, enter 2 for the
NativeClusterId.
Required.

LocalMateId Integer The ID of the RMS cluster on the local site, which is paired with the
(0-254) remote RMS cluster being defined.
Required.

[Link] example
This is an example of the /opt/aaasc/config/radius/[Link] file:
<RADIUSConfiguration>
<PrepaidService
PrepaidEnabled="Y"
PrepaidTarget="PrepaidTargetGroup"
ForwardPrepaidAcct="N" />
<UserLockout
UserLockoutEnabled="Y"
ConsecutiveAuthFailuresAllowed="5"
ConsecutiveAuthFailureMonitorDuration="86400"

Page 24 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

ConsecutiveAuthFailureLockoutDuration="1200" />
<RealmMetrics
RealmMetricsEnabled="Y"
DefaultRealmEnabled="Y">
<DefaultRealm
DefaultRealmName="EveryoneElse"
DefaultAcctMetrics="N"/>
<Realm RealmName="xyz" AuthMetrics="N"/>
</RealmMetrics>
<RMSClientConfig
ThreadCount="20"
MaxQueueSize="16000"
/>
<Accounting>
<AccountingBuffers DistributionAlgorithm="RoundRobin">
<AccountingBuffer name="radbuff2"/>
</AccountingBuffers>
</Accounting>
<DAE
Port="3799"
DefaultDictionary="RFC2138">
EventTimestampRequired="N"
EventTimestampThreshold="300"/>
</RADIUSConfiguration>

Applying [Link] changes


Apply configuration changes without restarting the RADIUS Server process. As
root, send a HUP signal to the RADIUS Server:
pkill -HUP radiusd
On receiving a HUP signal, if the [Link] file contains a parameter with an
invalid value, the RADIUS Server continues to run with the previous configuration
and generates an error message. For details about error messages, see the
Service Controller: Log Messages Guide.

Service Controller 9.6.1-AAA October 12, 2012 Page 25


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

Preventing network congestion for RADIUS


To prevent network congestion in the event of a power failure or any other network
disruption, the RADIUS Server provides a congestion control mechanism.
This section provides an overview of the congestion control mechanism and
information about configuring settings for the congestion control mechanism:
• Congestion control overview
• Ingress message queue monitoring and packet coloring
• Packet coloring and congestion control
• Differentiating new from in-progress requests
• To configure settings for the congestion control mechanism
• To configure message drop probabilities
• Congestion control log messages

Congestion control overview


Figure 1 shows the RADIUS Service Controller and its message queue.
Figure 1: RADIUS Service Controller and access network

6XEVFULEHUGHYLFHV

7&3 5$',866HUYLFH
$FFHVV1RGH 0HVVDJH
TXHXH &RQWUROOHU

The RADIUS Server uses a LIFO (last-in-first-out) message queue to receive all
ingress messages. With the congestion control mechanism, the ingress message
queue is initialized to two times the expected peak rate of traffic (-r option in
radiusd). The message queue is divided into three sub-ranges (green, orange, red)
and RADIUS looks at queue size and message age to decide the congestion state.
Based on queue size and message age RADIUS determines one of the following
congestion states:
• Green - Service Controller is in a normal operational state
• Orange - Service Controller is congested
• Red - Service Controller is critically congested

Page 26 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

Ingress message queue monitoring and packet coloring


1 The RADIUS Server tags messages with two colors based on:
a the size of the message queue when the RADIUS Server de-queues a
message from the ingress message queue for processing. For details, see
Figure 2.
Figure 2: Message queue size and system congestion state sub-ranges

0HVVDJHTXHXH
VL]HLQLWLDOL]HGWRWZRWLPHVWKHH[SHFWHGSHDNUDWHRIWUDIILF
URSWLRQLQUDGLXVG
GLYLGHGLQWRWKUHHVXEUDQJHV
*UHHQ FDSDFLW\ KDOIWKHTXHXH
2UDQJH FDSDFLW\ WKHTXDUWHURIWKHTXHXHWKDWLVDERYHWKH
JUHHQWKUHVKROG
5HG FDSDFLW\ WKHTXDUWHURIWKHTXHXHWKDWLVDERYHWKHRUDQJH
WKUHVKROG

b the age of the message, determined by comparing the message age


against the retransmit timeout set in the radiusd -T option.
Message age relative to retransmit timeout yields the following colors:
- Green: the message age is less than or equal to 3/5 of the retransmit
timeout
- Orange: the message age is greater than 3/5 of the retransmit timeout
and less than or equal to 4/5 of the retransmit timeout.
- Red: the message age is greater than 4/5 of the retransmit timeout
2 Whichever of the message queue size and message age state yields the more
critical color is the color given to the message.
Table 20 on page 28 describes how the RADIUS Server tags messages.

Service Controller 9.6.1-AAA October 12, 2012 Page 27


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

Table 20: Packet coloring

Message queue size Message age state System congestion state

Green Green Green

Green Orange Orange

Green Red Red

Orange Green Orange

Orange Orange Orange

Orange Red Red

Red Any state Red

Note RADIUS drops any messages where the message age state is older than
the retransmit timeout. If the system state is still in Red or Orange, RADIUS
then applies congestion control using a probability algorithm.

Packet coloring and congestion control


Note The probabilities listed below are defaults. Also modify [Link] to
specify the probability that RADIUS drops certain message types in the
event of an orange or red congestion state. For information, see the
procedure "To configure message drop probabilities" on page 31. See also
"CongestionControl" on page 18.
The RADIUS Server applies congestion control processing to PAP/CHAP, EAP
requests, Accounting-Interim and Stop messages, and DAE messages.
The color of each message is a key input for the RADIUS Server’s congestion
control processing. A message can be tagged with a color that reflects one of the
following systems states:
• Green: no congestion control action needed, the RADIUS Server processes the
message normally
• Orange: the RADIUS Server is in a congested state.
– for a new authentication request there is a 50% chance the RADIUS Server
will drop the message. The RADIUS Server includes the Session-Timeout
attribute (randomly generated value between -T and (4 times -T)) in the
Access-Challenge response message
Configure this probability in [Link] in the StateOrange
“AuthEAPDropProbability” attribute
– for an in-progress EAP session RADIUS does not drop the message but
the RADIUS Server includes the Session-Timeout attribute (randomly
generated value between -T and (4 times -T)) in the Access-Challenge
response message
This is the default behaviour and is not configurable in [Link].

Page 28 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

– for non EAP sessions there is a 60% chance that the RADIUS Server will
drop the message.
Configure this probability in [Link] in the StateOrange
“AuthNonEAPDropProbability” attribute
– for an Accounting-Start message the RADIUS Server does not drop the
message.
Configure this probability in [Link] in the StateOrange
“AcctStartDropProbability” attribute
– for an Accounting-Interim message the RADIUS Server drops the
message.
Configure this probability in [Link] in the StateOrange
“AcctInterimDropProbability” attribute
– for an Accounting-Stop message the RADIUS Server does not drop the
message.
Configure this probability in [Link] in the StateOrange
“AcctStopDropProbability” attribute
– for DAE messages (CoA and DM) there is a 50% chance that the RADIUS
Server will send an immediate NAK. The NAK includes Error-Cause 505
“Other Proxy Processing Error”, a fatal error sent when a request cannot be
processed by a proxy for reasons other than routing.
Configure this probability in [Link] in the StateOrange
“DAERejectProbability” attribute.
• Red: the RADIUS Server is critically congested.
For Access-Request messages:
– for a new authentication session, the RADIUS Server drops the message.
Configure this probability in [Link] in the StateRed
“AuthEAPBaseDropProbability” attribute
– by default, for an in-progress session with leg count equal to 1, there is a 55
% chance the RADIUS Server drops the message.
– by default, for an in-progress session with leg count equal to 2, there is a 10
% chance the RADIUS Server drops the message.
– by default, for an in-progress session with leg count greater than 2, the
RADIUS Server processes the message normally.
Configure the probability of dropping in-progress sessions in
[Link] in the StateRed “AuthEAPPerLegDropProbability”
attribute
For non EAP sessions:
– the RADIUS Server drops the message.
Configure this probability in [Link] in the StateRed
“AuthNonEAPDropProbability” attribute

Service Controller 9.6.1-AAA October 12, 2012 Page 29


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

For Accounting-Start, Accounting-Interim, and Accounting-Stop messages:


– by default, for an Accounting-Start message the RADIUS Server does not
drop the message.
Configure this probability in [Link] in the StateRed
“AcctStartDropProbability” attribute.
– for an Accounting-Interim message the RADIUS Server drops the
message.
Configure this probability in [Link] in the StateRed
“AcctInterimDropProbability” attribute.
– by default, for an Accounting-Stop message where the Acct-Delay-Time
AVP is great than -T, there is a 50% chance that the RADIUS Server drops
the message.
Configure this probability in [Link] in the StateRed
“AcctStopOldDropProbability” attribute.
– by default, for an Accounting-Stop message where the Acct-Delay-Time
AVP is less than -T, there is a 60% chance that the RADIUS Server drops
the message.
Configure this probability in [Link] in the StateRed
“AcctStopYoungDropProbability” attribute.
For DAE messages (CoA and DM):
– there is a 60% chance that the RADIUS Server will send an immediate
NAK. The NAK includes Error-Cause 505 “Other Proxy Processing Error”, a
fatal error sent when a request cannot be processed by a proxy for reasons
other than routing.
Configure this probability in [Link] in the StateRed
“DAERejectProbability” attribute.
Note If the Service Controller’s pre-allocated memory pool is exhausted, it drops
the newest message and continue until it reaches a stable state.

Differentiating new from in-progress requests


In addition, the congestion control mechanism enables the RADIUS Server to
differentiate new authentication sessions from in-progress, multi-round
authentication sessions (such as for EAP). When the RADIUS Server is overloaded
it can drop the newer sessions in favor of in-progress sessions. The RADIUS
Server uses the State attribute to track multi-round EAP sessions.
To use the congestion control mechanism the Access Node (NAS, ASN-GW) must
support the State AVP.
RADIUS generates an ERR log message and returns an Access-Reject if the state
data it receives in the State attribute is stale.

Page 30 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

To configure settings for the congestion control mechanism


Configure congestion control using the command line by adding the -r and -T
options to the radiusd process.
• -r configures the expected peak rate of messages per second on the RADIUS
Server.
– the RADIUS Server’s ingress message queue is initialized to twice the
value specified by the -r option.
– Default=1500.
• -T configures the client request retransmit timeout in seconds. The RADIUS
Server compares the message age against the retransmit timeout to determine
the latency of the message.
– The timeout on the client indicates the time after which the client
retransmits a request to the RADIUS Server.
– Default=5 seconds.
For example:
radiusd -r 1500 -T 5

To configure message drop probabilities


Also modify [Link] to specify the probability that RADIUS drops certain
message types in the event of an orange or red congestion state.
1 Open the [Link] file, located in /opt/aaasc/config/radius.
2 In [Link], configure the CongestionControl section to specify the
probability that RADIUS drops certain message types in the event of an orange
or red congestion state. For example:
<CongestionControl>
<StateOrange
AuthEAPDropProbability="50"
AuthNonEAPDropProbability="60"
AcctStartDropProbability="0"
AcctInterimDropProbability="100"
AcctStopDropProbability="0">
DAERejectProbability="50"/>
<StateRed
AuthEAPBaseDropProbability="100"
AuthEAPPerLegProbabilityReduction="45"
AuthNonEAPDropProbability="60"
AcctStartDropProbability="0"
AcctInterimDropProbability="100"
AcctStopOldDropProbability="50"
AcctStopYoungDropProbability="60"
DAERejectProbability="60"/>
</CongestionControl>

Service Controller 9.6.1-AAA October 12, 2012 Page 31


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

3 To apply configuration changes, send a HUP signal to the RADIUS Server:


pkill -HUP radiusd
For more information about configuring the CongestionControl section in
[Link], see "CongestionControl" on page 18.

Congestion control log messages


The RADIUS congestion control mechanism provides the following log messages:
• RADIUS generates a NTCE log message when transitioning from congestion
state GREEN to ORANGE.
• RADIUS generates a WARN log message when transitioning from congestion
state GREEN to RED.
• RADIUS generates a WARN log message when transitioning from congestion
state ORANGE to RED.
• RADIUS generates an INFO log message when transitioning from congestion
state ORANGE to GREEN.
• RADIUS generates an INFO log message when transitioning from congestion
state RED to GREEN.
• RADIUS generates a NTCE log message when transitioning from congestion
state RED to ORANGE.
Note Logs indicating a transition to RED or ORANGE include the state of the
ingress message queue and the age of the most recently processed
message in the queue.
• When in congestion state ORANGE, RADIUS generates a NTCE log message,
throttled every 30 seconds.
• When in congestion state RED, RADIUS generates a WARN log message,
throttled every 30 seconds.
The RADIUS congestion control mechanism provides the following SNMP metrics:
• RADIUS increments the SNMP drop metrics when a message is dropped due
to congestion control processing.
• RADIUS sends an SNMP trap that indicates the congestion state, when a
congestion state transition occurs.
For more information about RADIUS Server log message, see the Service
Controller: Log Messages Guide. For more information about SNMP metrics, see
the Bridgewater SNMP Guide.

Page 32 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

RADIUS subscriber data access


RADIUS has two options for accessing subscriber data:
• Profile Database—supports the full set of provisioning tools available from the
Service Manager GUI, as well as the provisioning APIs and command line
utilities.
• LDAP Directory Server—supports a limited set of provisioning tools. All
provisioning is done through the [Link] file. The Service Manager,
User Self Administration, User Self Registration, and provisioning APIs are not
supported by this option. For more information, see the chapter "Configuring
LDAP for RADIUS access" on page 87.

Profile Database
The RADIUS Server connects to the Profile Database using the [Link] file,
located in /opt/aaasc/config/. This file specifies one or more databases, using the
global database name, with which the RADIUS Server connects using a username
and password. The database configuration parameters—username, password,
database—must be at the end of the file. The username and password are set
when the database is installed.
The [Link] file can list multiple databases for backup. If the primary database fails,
the RADIUS Server connects to the next database listed in the file. To configure for
failover, the parameters can be repeated for the failover database. Make sure the
correct order is maintained.
Modify this file only if the location of a database changes, relative to the RADIUS
Server, or the database username or password changes. Do not leave the
database field of the [Link] file blank.
This is an example of the [Link] file:
# Database config
username= r6
password= x123y
database= dbname01
There must be at least one line separating the accounting and database
configuration parameters.
Table 21 describes the configuration parameters.

Table 21: [Link] parameters

Parameter Value Description

username Must be r6 Database schema owner.


Required.

password String Password of the r6 user.


Required.

Service Controller 9.6.1-AAA October 12, 2012 Page 33


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

Table 21: [Link] parameters (continued)

Parameter Value Description

database String Global database name (dbname) of the Profile


Database.
Required.

retryinterval Integer The time, in seconds, allotted to using the secondary


Default = 300 database before attempting to reconnect to the
primary.
If a secondary database is not specified, set this
value to an acceptable amount of time for RADIUS to
retry its database connection so the RADIUS outage
is less than 300 seconds (5 minutes).
Optional.

Profile Database connection failover


The behavior with respect to RADIUS and the database is difficult to observe
because RADIUS is a multi-threaded application, and each thread behaves
independently.
• RADIUS runs with 100 threads, with each thread having a dedicated
connection to the database. RADIUS messages are handled competitively
rather than using a round-robin approach. When a RADIUS message arrives,
every available thread competes to process it. Therefore, some threads may
not get used for long periods of time.
• Each thread acts independently of the others. The first thread to failover may be
failing back to the local database before the last thread realizes that its
database connection is stale.
• RADIUS does not fail all threads immediately when the first thread detects a
database problem because it is less efficient. Connecting 100 threads to a
database instantly is harder on the database than connecting them slowly over
time.
Database issues can be of different types. If there is a network blip talking to the
database, then that single thread fails over. The network blip, if it is temporary, may
be gone when the next threads do work. Since the database never went down, the
threads do not realize there was a problem, and they keep working with the same
database.
When the local database instance stops, the local RADIUS process is not
immediately aware of the stoppage. When the next RADIUS message arrives, the
thread that wins tries to talk to the database. The thread sees that its database
connection has gone stale and connects to the remote database. This triggers the
first message in /var/adm/messages.

Page 34 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 1 RADIUS Server start-up options and access features

When the next RADIUS message arrives, the same thread could possibly win the
competition and because it has a good database connection, it processes the
request. Slowly, each of the threads has its statistical chance to process RADIUS
requests. As each thread gets its first request, it also notices its stale primary
database connection is dead and fails over. Each failover shows a log message in /
var/adm/messages.
With a low transaction rate, it could be tens of minutes or a few hours before the last
of the database failover messages is observed. There are two messages per
thread: one as the thread fails over to the remote database, and one as it returns to
the local database after the time period has elapsed.
The syslogd facility can batch duplicate log messages together with a 'Last
message repeated XXX times' that is done to lessen the effect of 'log storming.'
The higher the load on the RADIUS Server, the shorter the average amount of time
it takes for all the RADIUS threads to failover.
The default RADIUS retryinterval is 300 seconds. This is a per thread timer. A
thread that has been failed over to the secondary database for more than 300
seconds tries to go back to the primary database for the next RADIUS request it
handles.

Service Controller 9.6.1-AAA October 12, 2012 Page 35


Chapter 1 RADIUS Server start-up options and access features Network Access Guide

Page 36 October 12, 2012 Service Controller 9.6.1-AAA


RADIUS Server special features

2
Chapter 2
Chapter

This chapter explains how to configure RADIUS Server features.


The topics are:
• Configuring user and network lockout
• Configuring Prepaid Data
• Configuring Quick-Access
• Configuring Multiple NAI
• Configuring dynamic LNS assignment
• Configuring realm routing support
• Configuring subscriber QoS profiles for EV-DO Rev A service
• Configuring QoS Profiles using the Service Manager
• Configuring user notification messages for internationalization
• Configuring EAP
• Configuring SIP Server Interworking
• Configuring service selection
• Configuring GMT offset for proxy
• Configuring attribute generation in [Link]
• Configuring attributes to include in RADOP log messages
• Configuring AVP-based access control
• Configuring duplicate detection
• Configuring database (DAL query) caching for multi-leg EAP
• Configuring HTTP Digest Authentication
• Configuring MAC caching using Calling-Station-Id
• Configuring RADIUS-based metering

Service Controller 9.6.1-AAA October 12, 2012 Page 37


Chapter 2 RADIUS Server special features Network Access Guide

Configuring user and network lockout


The lockout feature locks out a subscriber or network device in one of two
scenarios:
• user lockout, to prevent, for example, hacking of a subscriber’s account by
locking the account after a number of failed authentication or authorization
attempts in a specified period
• network lockout, to prevent a misconfigured or faulty device from flooding the
network with messages by locking the account after a number of successful
authentication or authorization attempts in a specified period
There are two options for locking an account:
• RADIUS sends an Access-Accept to authorize the user as a representative
user and locks the account for a specified duration
• RADIUS sends an Access-Reject and locks the account for a specified duration
Note Only one lockout scenario and one account lockout option can be used in
combination on a single RADIUS Server.
The lockout feature is fully implemented for LocalAA and ProxyAA policy actions
configured in the accessReqPolicy file.

Configuring lockout
There are multiple ways of configuring user and network lockouts on a RADIUS
Server, and multiple files to configure. This section provides guidance through the
decision and configuration process.
Table 22 describes the behavior of the lockout feature based on the type and action
of the lockout, assuming UserLockoutEnabled=“Y” in [Link].

Table 22: Lockout options ([Link]) and behavior

Attribute value LockoutOnUserAccept=N LockoutOnUserAccept=Y

Monitor users for consecutive Monitor users for consecutive


LockoutOnAuthorizeOnly=N authentication failures (user lockout). authentication successes (network
lockout).

Monitor users for consecutive Monitor users for consecutive


LockoutOnAuthorizeOnly=Y authorization failures (user lockout). authorization successes (network
lockout).

For more information about:


• the allowLockedoutUsers modifier, see "allowLockedoutUsers" on page 261.
• the UserLockout attributes in [Link], see "UserLockout" on page 10.
• the LockoutConfig attributes in [Link], see "LockoutConfig" on page 198.

Page 38 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

To configure user or network lockout


1 During installation of the RADIUS Server package BWSwsrad, answer yes
when prompted to configure RADIUS user lockout functionality.
2 In the accessReqPolicy file:
– If authorizing locked out users with a representative user, make sure
allowLockedoutUsers=Y.
3 In the [Link] file:
a Define the representative user (if required) by configuring LockoutConfig
with an AcceptLoginName, AcceptDomain, and optionally, an
AcceptConnectionServiceProfile (RADIUS connection service profile).
b To lock accounts based on failed connection attempts, make sure
LockoutOnUserAccept=“N” (default); to lockout accounts based on
successful connection attempts, set LockoutOnUserAccept=“Y”.
c To monitor users during the authentication process, make sure
LockoutOnAuthorizeOnly=“N”; to monitor users during the authorization
process, set LockoutOnAuthorizeOnly=“Y”;.
4 In the [Link] file, set these values:
a UserLockoutEnabled=“Y”.
b ConsecutiveAuthFailuresAllowed with the number of consecutive failed or
successful authentication/authorization attempts before an account is
locked.
c ConsecutiveAuthFailureMonitorDuration with the amount of time to monitor
the account for consecutive failed or successful authentication/
authorization attempts.
d ConsecutiveAuthFailureLockoutDuration with the amount of time to lock out
the user before the account is dynamically unlocked.
A RADIUS operational log message, useful for fraud investigation, is generated
when the user’s account is locked.

Managing lockouts with ulTool


Lockouts are recorded by the RADIUS Server in a local memory mapped file. Use
the ulTool to access the memory mapped file to find and clear locked out users,
create a memory mapped file, or increase the capacity of the memory mapped file.
By default, the ulTool utility is located in the /opt/aaasc/radius directory. Run the
utility as the root user.

Service Controller 9.6.1-AAA October 12, 2012 Page 39


Chapter 2 RADIUS Server special features Network Access Guide

Table 23 lists the command line options. Use multiple options, such as
-S (statistics), -F (find), -U (unlock), -C (create), and -h (help), at the same time.

Table 23: ulTool utility options

Option Description

-S Show statistics on the memory mapped file. Such as:


• Path to the memory mapped file. For example: /opt/aaasc/config/radius/[Link]
• Lock ID for the memory mapped file. This is used for debugging a dead lock on a memory mapped
file. For example: 6.
• Version for the memory mapped format. For example: 1 for the release.
• Capacity of the memory mapped file. For example: 10000 records.
• Sequence number for the memory mapped file. Each time capacity of the memory mapped file is
increased, using the -C option, the sequence number is increased. For example: 1.
• Attached Processes—lists the process ID, for a process, such as RADIUS, that is bound to the
memory mapped file. Only one process can be bound to the memory mapped file. For example: pid
(28734).
Specify the name and location of the memory mapped file using the -f option.

-F Find and display the user locking status.


Specify the location of the memory mapped file using the -f option.
Specify one, or both, domain (-d) or loginname (-u) options. By default, -F only displays up to 100
records; use the -l option to change this limit.

-U Find and clear the user lockout status. Clear the lockout applied to a specified loginname to enable the
user to authenticate.
Specify the name and location of the memory mapped file using the -f option.
Unlock (-U) requires both domain (-d) and loginname to be specified.

-C Create or increase the size of the memory mapped file.


A log is generated to syslog, by the RADIUS Server, if the memory mapped is full and needs to be
increased. Increase the size of the memory mapped file to store more failed authentications.
Create the memory mapped file if it was not created it when the BWSwsrad package was installed.
The database name is the name and location of the memory mapped file. This is the path and filename
required by RADIUS when user lockout is enabled. For example: /opt/aaasc/config/radius/[Link].
When doing Create or Grow (-C), memory mapped record size (-s) is required.

-f <mmap_file> Location of the memory mapped file. Required for the -S, -F, -U and -C options. For example, the
mmap_file is defined as: /opt/aaasc/config/radius/[Link].

-u <login_name> Login name for a specified user. Use this option in conjunction with the -F and -U options.

-d <domain> Domain name. Use this option in conjunction with the -F and -U options.

-s Set the record count of the memory mapped file. Use this option in conjunction with the -C option. When
the file is created at installation time, a size of 10000 is used.

-l Set the limit for number of records to display. If the -l option is not specified, the ulTool displays 100
records. Increase or decrease this number with the -l option.

-h Displays the usage for this utility.

Page 40 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

Example: ulTool find To find a user in a locked out state for a specific domain:
user ./ulTool -F -f /opt/aaasc/config/radius/[Link] -d
[Link]
The utility returns:
Bridgewater RADIUS UserLockout Database Utility <Version>
=========================
======= FIND USER =======
=========================
Expired user lockout entry for user1@[Link]
Current state [Exp] : failed 2 time(s)
Clear time : 2004-03-10 09:51:13
User lockout entry for user2@[Link]
Current state : locked
Clear time : 2004-03-10 09:51:19

Example: ulTool To display the statistical information for the memory mapped file:
statistics ./ulTool -S -f /opt/aaasc/config/radius/[Link]
The utility returns:
Bridgewater RADIUS UserLockout Database Utility <Version>
=========================
==== DATABASE STATS =====
=========================
Path : /opt/aaasc/config/radius/[Link]
Lock ID : 6
Version : 1
Capacity : 10000
Sequence # : 1
Attached Process : pid (28734)

Service Controller 9.6.1-AAA October 12, 2012 Page 41


Chapter 2 RADIUS Server special features Network Access Guide

Configuring Prepaid Data


The Prepaid Data feature provides wireless customers with access to services for
which they have prepaid. Figure 3 shows a typical Prepaid Data Access-Request /
Access-Accept sequence.
Figure 3: Typical Prepaid Data Access-Request / Access-Accept sequence

1HWZRUN$FFHVV
6HUYLFH&RQWUROOHU

$FFHVV5HTXHVW
3'61+$ 5$',86 03,6,3SURFHGXUHV
3UHSDLG&OLHQW 6HUYHU DXWKHQWLFDWLRQDQGDXWKRUL]DWLRQ
)RUZDUG$FFHVV$FFHSW
6XEVFULEHU 6HQG$FFHVV5HTXHVWWR
ZLWK3UHSDLGTXRWD
3UHSDLGWDUJHW

6HQG$FFHVV$FFHSW 3UHSDLGWDUJHWFKHFNVWKH
ZLWK3UHSDLGTXRWD VXEVFULEHU¶VDFFRXQWEDODQFH

3UHSDLGWDUJHW

The Service Controller authenticates the subscriber, applies any applicable policies,
performs DMU and DHA procedures (if configured), and proxies messages to a
third-party billing system (prepaid target).
The prepaid target performs balance checks and quota functions and responds to
the Service Controller. The Service Controller appends required fields from the
subscriber profile and sends the result to the PDSN.
This section describes how to configure the Prepaid Data feature, including:
• To configure the prepaid target
• To configure [Link]
• To configure flat files
• To configure the RADIUS Server
• To set the RADIUS Server to run in SSR mode
• To create a dictionary
• To provision a connection service profile
• To provision a User profile set
• To provision subscribers
• To provision PDSNs/HAs with dynamic HA allocation
• To provision PDSN/HA groups

Page 42 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

To configure the prepaid target


Configure each prepaid target in the network to support Prepaid Data service using
the /opt/aaasc/config/radius/[Link] file:
1 Add a RADIUS Server TargetName.
2 Set the appropriate parameters for the target.
Group any number of prepaid targets by adding a GroupName and assigning the
TargetName of each prepaid target to the GroupName:
1 Add a GroupName.
2 Set the appropriate parameters for the GroupName.
3 Assign the prepaid target names to the group.

To configure [Link]
In the [Link] file, located in the /opt/aaasc/config/radius/ directory, configure
the following attributes: This section describes:
1 StripBridgewater VSAs
Configure StripBridgewaterVSAs (default = N) for each vendor to specify
whether RADIUS includes Bridgewater VSAs in Access-Accept messages that
it returns to RADIUS clients.
2 Use ClassAttribute to identify prepaid and postpaid subscribers
To identify a subscriber as prepaid or postpaid in the accounting records,
configure ClassAttribute=Y in the [Link] file and configure
PP-Rating-Type as described in "To create a dictionary" on page 44.
When a PDSN that supports the Class attribute receives an Access-Accept
message, that message contains a value for the Class attribute. The PSDN
then uses this Class attribute value in all accounting requests for this session.
The value used for the Class attribute is inserted by the RADIUS Server based
on the PP-Rating-type that has been configured. For the Class attribute value
to be available in the output accounting flat file, it must be configured as an
accounting record attribute in the [Link] file, using the
<AcctRecordAttribute> element, as defined in Table 70 on page 191.
For more information about these attributes, see Chapter 6, "Managing RADIUS
and Diameter dictionaries".

To configure flat files


To write an accounting flat file that identifies the subscriber as prepaid or postpaid,
configure the Service Controller to do one of the following:
a include the entire radiusattr field in the accounting flat file
b use regexp to extract the ClassAttribute and place it in the format section in
the accounting flat file
Note The <AcctRecordAttribute> element in the [Link] file must include
the ClassAttribute.

Service Controller 9.6.1-AAA October 12, 2012 Page 43


Chapter 2 RADIUS Server special features Network Access Guide

To configure the RADIUS Server


Configure the RADIUS Server to support Prepaid Data service using the /opt/aaasc/
config/radius/[Link] file:
1 Set PrepaidEnabled to Y.
2 Set PrepaidTarget to a TargetName or GroupName that defines the prepaid
target, from the [Link] file.
3 Set ForwardPrepaidAcct to Y or N.

To set the RADIUS Server to run in SSR mode


When using the Session State Register:
1 Set the RADIUS Server to run in SSR mode by adding “-E ssr” to the startup
script in /opt/aaasc/config/radius/wsradius.
For more information about the RADIUS Server startup script, see "RADIUS
Server startup options" on page 2.
2 Stop and start the RADIUS process for the changes to take effect.
The RADIUS policy type for SSR must be CDMA2000LocalAcct,
CDMA2000LocalAA, or CDMA2000ProxyAcct.

To create a dictionary
The default dictionaries located in /opt/aaasc/dict are read-only. When an update is
installed, this directory is overwritten. To add dictionaries or overwrite default
dictionaries, create DICT files in another location and reference them in
/opt/aaasc/config/dictionaries.
For the procedure to create a custom dictionary and finalize the changes, see
"Custom RADIUS dictionaries" on page 185.
Add the following attributes or VSAs to the new dictionary file:
VENDOR <vendor name> <vendor ID>
START-VSA 12951
ATTRIBUTE Policy-Type 5 octetstring none both single
ATTRIBUTE Prepaid-Error 6 integer16 none both single
#
#Policy-Type
SUBTYPE Policy-Type Identifier 1 integer16
SUBTYPE Policy-Type Policy-Off 2 flag
SUBTYPE Policy-Type Error 3 integer16
SUBTYPE Policy-Type Qualifier 4 integer16
SUBTYPE_VALUE Policy-Type Identifier PTT 0
SUBTYPE_VALUE Policy-Type Identifier PTT-With-Filtering 1
SUBTYPE_VALUE Policy-Type Error Policy-Cannot-Be-Activated
0
#
#Prepaid-Error
VALUE Prepaid-Error Incorrect-Quota-Type 0
VALUE Prepaid-Error Quota-Not-Received-For-Prepaid 1

Page 44 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

VALUE Prepaid-Error Quota-Received-For-Non-Prepaid 2


VALUE Prepaid-Error PPP-Establish-Failed-With-MS 3
#
# Bridgewater VSA Section
START-VSA 3631 UInt16TypeCoder
#
# Bridgewater Prepaid
## Product ID = 2, Feature ID = 0
#
ATTRIBUTE PP-Rating-Type 8201 integer none out single
## PP-Rating-Type
VALUE PP-Rating-Type Prepaid 1
VALUE PP-Rating-Type Postpaid 2

To provision a connection service profile


Note The following procedures assume familiarity with launching entity-specific
edit forms from the Service Manager main window. For more information,
see the Service Manager: Getting Started Guide for AAA.
To provision connections using a given profile:
1 In the Service Manager, select the Subscriber tab.
2 In the left pane, select the organization.
3 Launch the ConnectionService Service Profile edit form used to enable prepaid
subscribers.
4 Select the Attribute Information tab.
5 Verify that the PDSN vendors providing Prepaid Data services are selected in
the Vendor Availability tab.
6 Select the “Vendor Attribute Availability” tab.
7 Select the prepaid PDSN vendor from the drop-down list.
8 Add PP-Rating-Type to the list of available attributes.
9 Repeat steps 9 and 10 for any other PDSN vendors supporting Prepaid Data
services in the network.
10 Click OK.

To provision a User profile set


To provision subscribers using a given profile:
1 In the Service Manager, select the Subscriber tab.
2 In the left pane, select the organization.
3 Launch the User Profile Set edit form used to enable prepaid data services.
4 In the right pane, select a connection service that is enabled for Prepaid.
5 Select the Service Profile tab.
6 Select a PDSN vendor from the drop-down list.

Service Controller 9.6.1-AAA October 12, 2012 Page 45


Chapter 2 RADIUS Server special features Network Access Guide

7 Select PP-Rating-Type from the list of available attributes and set it to Prepaid.
8 Click Add.
9 Repeat steps 8 to 10 for other PDSN vendors supporting Prepaid Data services
in the network.
10 Click OK.

To provision subscribers
To provision a subscriber for Prepaid Data service:
1 In the Service Manager, select the Subscriber tab.
2 In the left pane, select the organization.
3 Launch the appropriate subscriber edit form.
4 In the left pane, select a connection service that is enabled for Prepaid.
5 Select a PDSN vendor from the drop-down list.
6 Select PP-Rating-Type from the list of available attributes and set it to Prepaid.
7 Click Add.
8 Repeat steps 5 to 7 for other PDSN vendors supporting Prepaid Data services
in the network.
9 Click OK.

To provision PDSNs/HAs with dynamic HA allocation


This procedure is only required for enabling Prepaid for PDSNs/HAs with dynamic
HA allocation configurations.
To provision a PDSN/HA:
1 In the Service Manager, select the System tab.
1 Launch the Access Node edit form.
2 Configure the common access node properties:
a From the Access Node pane, select Properties.
b Type the information in the required fields.
Note Make sure to select a vendor that supports the protocols, for example,.
RADIUS, Diameter, or both, to use for the access node.
3 Select an access node role:
a From the Access Node pane, select Roles.
b From the Available Roles field, select a role for the access node.
You can select more than one role for an access node.
4 Check Prepaid Capable.
5 Click OK to save the change.

Page 46 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

6 Repeat steps 3 and 4 for any other PDSNs supporting Prepaid Data services in
the network.
7 Click Apply Changes.
RADIUS re-loads its configuration.

To provision PDSN/HA groups


This procedure is required only when using RADIUS in SSR mode. For more
information about SSR, see the Service Controller: Resource Management Server
Guide.
To provision PDSN/HA groups:
1 Configure the RMS cluster in the /opt/aaasc/config/[Link] file.
2 Create the PDSN/HA groups required for each set of access controls supported
by the network.
3 In the Service Manager, select the System tab and add PDSNs, as appropriate,
to match the access controls provided by each PDSN/HA group.
4 Add the RMS cluster ID, from the [Link] file.

Saving session data to a flat file


In rare cases, the Session Database may have to be re-initialized. In such cases, it
is possible that prepaid session data may be lost. therefore, save the prepaid
session data to a flat file for accounting purposes (for example, to determine
subscriber account credits), before re-initializing the Session Database.
The topics are:
• Displaying help information
• Recording session data
• Recording session data and deleting sessions
• prepaid sessions example
Note The commands described in this section can only be run on an active RMS.

Displaying help information


To display the help menu on an active RMS:
./prepaidReport -h

Recording session data


To create a report of the sessions older than time x on an active RMS:
./prepaidReport x > filename

Service Controller 9.6.1-AAA October 12, 2012 Page 47


Chapter 2 RADIUS Server special features Network Access Guide

where
x is the time, in seconds, corresponding to the age of sessions in RMS in idle
state
> filename re-directs the data to the specified file, to hold the session data

Recording session data and deleting sessions


Use the following command on an active RMS to save some of the session data to
a file and delete the sessions.
CAUTION: The command described in this section irretrievably deletes session
data from the database. There is no undo. Use this command only under the
direction of Bridgewater Customer Support.
./prepaidReport -d x > filename
where
x is the time, in seconds, corresponding to the age of sessions in RMS in idle
state and > filename re-directs the data to the specified file, to hold the session
data

prepaid sessions example


1 List the prepaid sessions on the active RMS:
/opt/aaasc/utilities/RMSCmd/listSessions -rms 0 -state
InUse -sessiontype Prepaid
Note: This step is shown only to compare the information displayed by the
listSessions command to the information displayed by the
prepaidReport command (shown in Step 2).
SessionParcel
SessionId=0000000000acc60e981038aa7718a6f35b4d4401b6
SessionType=Pre-Paid
Timestamp=Jan 09 16:21:22
CurrentSessionState=InUse
StateChangeTime=1168359682
UserName=111111581060761@[Link]
NASIpAddr=[Link]
RadiusIpAddress=[Link]
PPSUserName=1581060761
PPSIncrementalCharge=300.00
PPSBalance=300.0000
PPSChargePerKb=0.0000
PPSChargePerSec=0.0000
PPSSecondsUsed=0
PPSVolumeUsed=0
PPSAuthStatus=0
PPSSubscriptionStatus=chargeable
PPSBillingType=2
PPSVolumeQuotaInBytes=307200.00
PPSDurationQuota=0.00

Page 48 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

PPBillingNodeServiceId=AAA_GCAP_TAX
PPBillingSessionId=20070109162122
PPBillingRequestNumber=0
PPBillingReserved=0
2 Display the prepaid sessions on the active RMS:
./prepaidReport
Note: This example shows the command that displays session information to
the screen without deleting sessions.
111111581060761@[Link],20561=[Link],21250=158
1060761,21251=300.00,21252=300.0000,21253=0.0000,21254=0.0
000,21255=0,21256=0,21257=0,21260=chargeable,21262=2,21264
=307200.00,21265=0.00,22529=AAA_GCAP_TAX,22530=20070109162
122,22534=0,22536=0,

The command was processed successfully and returned 1


entries
Note For information about the session data that is displayed, contact
Bridgewater Customer Support.

Prepaid Data SNMP support


The Prepaid Data feature supports SNMP additions for online Access-Requests
(containing Service-Type = 17). The MIB variables for online Access-Requests are:
• radiusOnlineAuthTargetStatistics ([Link].4.1.3631.[Link].3)
• radiusOnlineAuthTargetTable ([Link].4.1.3631.[Link].4)
• radiusServerOnlineStatistics ([Link].4.1.3631.[Link].1)
• radiusOnlineClientTable ([Link].4.1.3631.[Link].2)
For more information about these variables, see the appendix “BW-RADIUS MIB” in
the Bridgewater SNMP Guide.

Configuring Quick-Access
The Quick-Access feature enables prepaid customers that have used all of their
quota to access the network and replenish their quota. This feature requires that a
PDSN be configured to direct prepaid customers to a replenishment portal.
Note For online (subscriber on the network) requests, an Access-Reject
message is not converted (step 7) because authorization is not performed.
When the billing system determines that customers have used all of their quota, it
responds to the Service Controller with an Access-Reject message. The Service
Controller identifies the customer as a Quick-Access prepaid subscriber, converts
the message to an Access-Accept, authorizes the customer, retrieves the
configured Pool-ID, and sends a response to the PDSN. The PDSN can use this
information to direct customers to a self-administered services portal to replenish
their quota.

Service Controller 9.6.1-AAA October 12, 2012 Page 49


Chapter 2 RADIUS Server special features Network Access Guide

Configuring the Quick-Access feature consists of the following tasks:


• To create a dictionary
• To configure Quick-Access
• To add PP-Quick-Access to an existing Connection Service

To create a dictionary
The default dictionaries located in /opt/aaasc/dict are read-only. When an update is
installed, this directory is overwritten. To add dictionaries or overwrite default
dictionaries, create DICT files in another location and reference them in /opt/aaasc/
config/dictionaries.
For the procedure to create a custom dictionary and finalize the changes, see
"Custom RADIUS dictionaries" on page 185.
Add the following attributes or VSAs to the new dictionary file:
VENDOR <vendor name> <vendor ID>
START-VSA 12951
ATTRIBUTE PP-Quick-Access 8202 integer none out single
## PP-Quick-Access
VALUE PP-Quick-AccessDisabled 0
VALUE PP-Quick-AccessEnabled 1

To configure Quick-Access
To configure RADIUS for the Quick-Access feature:
• Modify the [Link] file
• Modify the [Link] file
• Send a HUP signal to the RADIUS Servers
1 Modify the [Link] file
Update the /opt/aaasc/config/radius/[Link] file with the settings listed
in Table 24 to provide RADIUS Server support for Quick-Access customers.

Table 24: [Link] settings

Attribute Value

QARejectEnabled Y

QAPoolID The identifier of the IP pool provisioned on the PDSN/HA.

For more information about these parameters, see "PrepaidService" on page 9.


This is an example of the PrePaidService section of the [Link] file:
<RADIUSConfiguration>
[...]
<PrepaidService PrepaidEnabled="Y"
PrepaidTarget="IS835C"

Page 50 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

ForwardPrepaidAcct="N"
QARejectEnabled="Y"
QAPoolID="5648EACD" />
[...]
</RADIUSConfiguration>
2 Modify the [Link] file
Update the [Link] file, located in the /opt/aaasc/config/radius/ directory,
with the elements listed in Table 25.

Table 25: [Link] settings

Element Value/Description

PPQAPoolAttr Any RADIUS string attribute, including:


• Framed-Pool (default)
• TC-Framed-IP-Address-Pool-Name (used by USR vendor)

PPQAPoolAttrValue The identifier of the IP pool provisioned on the PDSN/HA. The


value set here overrides the value of QAPoolID in
[Link] on a per-vendor basis.

For more information about these parameters, see Table 70 on page 191.
This is an example of the [Link] file:
<VendorConfiguration>
<Vendor VendorName="USR"
[...]
PPQAPoolAttr="TC-Framed-IP-Address-Pool-Name"
PPQAPoolAttrValue="0123456789ABCD"
StripBridgewaterVSAs="Y"
[...]
</Vendor>
</VendorConfiguration>
3 Send a HUP signal to the RADIUS Servers
Send a HUP signal to the RADIUS Servers for changes to the [Link]
and [Link] files to take effect.

To add PP-Quick-Access to an existing Connection Service


Note The following procedures assume familiarity with launching entity-specific
edit forms from the Service Manager main window. For more information,
see the Service Manager: Getting Started Guide for AAA.
To provision connections using a profile:
1 In the Service Manager, select the Subscriber tab.
2 In the left pane, select the organization.

Service Controller 9.6.1-AAA October 12, 2012 Page 51


Chapter 2 RADIUS Server special features Network Access Guide

3 Launch the ConnectionService Service Profile edit form that you use to enable
Quick-Access for subscribers.
4 Select the “Attribute Information” tab.
5 Verify that the PDSN vendors providing Quick-Access for subscribers are
selected in the “Vendor Availability” tab.
6 Select the “Attribute Availability” tab.
7 Select the Quick-Access for subscribers PDSN vendor from the drop-down list.
8 Add PP-Quick-Access to the list of available attributes. Values are “Disabled”
and “Enabled”.
9 Repeat step 7 and step 8 for any other PDSN vendors supporting
Quick-Access for subscribers in your network.
10 Click OK.

Configuring Multiple NAI


The Service Controller supports multiple Access Control service profiles to enable
different billing plans for different services used by a single customer.
This feature requires that a mobile device be configured with a distinct NAI for each
service type, embedded application, or tethered device. The type of data service a
customer is using can be tracked, depending on the NAI used to connect to the
service.
Figure 4 shows a typical Multiple NAI Access-Request/Access-Accept sequence.
Figure 4: Typical Multiple NAI Access-Request/Access-Accept sequence

0RELOH
'HYLFH 1HWZRUN$FFHVV

0'1 $FFHVV
8VHU6HUYLFHV
5HTXHVW
1$,
3'61+$ 5$',86 6,3
1$, 6HUYHU 377
3URILOH '81
$FFHVV
1$, 5HVSRQVH 'DWDEDVH
6HUYLFH&RQWUROOHU $FFHVV
&RQWURO
:KHUH 7LPHRI'D\
1$, 0'1#YHQGRUFRP 5RDP
1$, 0'1#SWWYHQGRUFRP $FFHVV3RLQW
1$, 01'#GXQYHQGRUFRP
Depending on the service type that the customer requires, embedded application
versus tethered device services, the Access-Request message contains the
appropriate NAI to access that service.

Page 52 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

The Service Controller always initially authenticates the subscriber based on the
vendor realm, [Link]. The Service Controller then authenticates the
subscriber based on the subnet service, if necessary. If the subscriber is
provisioned for the subnet service, the Service Controller returns the authorization
to the PDSN in the Access-Response message.
This section describes how to configure RADIUS for Multiple NAI. The topics are:
• To configure the RADIUS Server
• To configure the RADIUS Server to enable SNMP
• To provision a connection service profile
• To provision User profile sets
• To provision subscribers for multiple NAI services
Note The following procedures assume familiarity with launching entity-specific
edit forms from the Service Manager main window. For more information,
see the Service Manager: Getting Started Guide for AAA.

To configure the RADIUS Server


Configure the [Link] file, located in /opt/aaasc/config/radius/, for the
RADIUS Server to support Multiple NAI.
1 Assign the default access control service profile to the subscriber.
2 Configure the realm metrics.
3 Configure the default realm metrics.
For more information about these parameters, see "RealmMetrics" on page 11.

To configure the RADIUS Server to enable SNMP


Configure the RADIUS Server to enable SNMP:
$PRODUCT_DIR/radius/radiusd -C $PRODUCT_DIR/config -p 1812
-t 50 -F 1024 -E snmp
For more information about these parameters, see Table 1 on page 2 and Table 2
on page 3.

To provision a connection service profile


1 In the Service Manager, select the Subscriber tab.
2 In the left pane, select the organization.
3 Launch the ConnectionService Service Profile edit form that you use enable
Multiple NAI services.
4 Select the Attribute Information tab.
5 Verify that the PDSN vendors providing Multiple NAI services are selected in
the Vendor Availability tab.
6 Select the Attribute Availability tab.
7 Select the prepaid PDSN vendor from the drop-down list.

Service Controller 9.6.1-AAA October 12, 2012 Page 53


Chapter 2 RADIUS Server special features Network Access Guide

8 Add PP-Rating-Type to the list of available attributes.


9 Repeat steps 9 and 10 for any other PDSN vendors supporting Multiple NAI
services in the network.
10 Click OK.

To provision User profile sets


1 In the Service Manager, select the Subscriber tab.
2 In the left pane, select the organization.
3 Launch the User Profile Set edit form that you for Multiple NAI services.
4 In the right pane, select a connection service that is enabled for Multiple NAI.
5 Select the Service Profile tab.
6 Select a PDSN vendor from the drop-down list.
7 Select PP-Rating-Type from the list of available attributes and set it to Multiple
NAI.
8 Click Add.
9 Repeat steps 8 to 10 for other PDSN vendors supporting Multiple NAI services
in the network.
10 Click OK.

To provision subscribers for multiple NAI services


1 In the Service Manager, select the Subscriber tab.
2 In the left pane, select the organization.
3 Launch the appropriate User edit form.
4 In the left pane, select a connection service that is enabled for Multiple NAI
services.
5 Select a PDSN vendor from the drop-down list.
6 Select PP-Rating-Type from the list of available attributes and set it to Multiple
NAI.
7 Click Add.
8 Repeat steps 5 to 7 for other PDSN vendors supporting Multiple NAI services in
the network.
9 Click OK.

Page 54 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

Multiple NAI SNMP support


The Multiple NAI feature supports SNMP additions for online Access-Requests
(containing Service-Type = 17). The MIB variables for online Access-Requests are:
• radiusAuthRealmTable ([Link].4.1.3631.[Link].1)
• radiusAuthRealmProxyTable ([Link].4.1.3631.[Link].1)
• radiusAccRealmTable ([Link].4.1.3631.[Link].1)
• radiusAccRealmProxyTable ([Link].4.1.3631.[Link].1)
For more information about these variables, see the appendix “BW-RADIUS MIB” in
the Bridgewater SNMP Guide.

Configuring dynamic LNS assignment


To provide load balancing of LNS (L2TP Network Server) assignment, define LNSs
and create LNS groups with Service Manager, and RADIUS assigns LNSs from the
group to Access-Accept messages using a sliding window model.

How dynamic LNS assignment works


In some DSL deployments, the Service Controller provides secure tunnel
information to permit a LAC (L2TP Access Concentrator) to create a tunnel to an
LNS for subscriber authentication. Dynamic LNS assignment balances the traffic
loads between servers by assigning a configurable number of LNSs to
Access-Accept messages using a sliding window model. LNSs are identified by an
automatically generated tunnel tag ID used to differentiate between LNSs in
messages.
Figure 5 on page 56 illustrates the simplified assignment of LNSs to Access-Accept
messages when an LNS group is configured in Service Manager with:
• Maximum Number of LNSs to Return set to 3
• 4 LNSs in the group (3 primary, 1 backup)
• the 4th LNS in the list designated as the backup LNS

Service Controller 9.6.1-AAA October 12, 2012 Page 55


Chapter 2 RADIUS Server special features Network Access Guide

Figure 5: Example LNS assignment with backup configured

6HUYLFH&RQWUROOHU

5$',86
6HUYHU

/16 /16 /16 /16


   
   
   
$FFHVV$FFHSW $FFHVV$FFHSW $FFHVV$FFHSW $FFHVV$FFHSW

Figure 6 on page 56 illustrates LNS assignment when an LNS group is configured


in Service Manager with:
• Maximum Number of LNSs to Return set to 3
• 4 LNSs in the group
• no designated backup LNS
Figure 6: Example LNS assignment without backup configured

6HUYLFH&RQWUROOHU

5$',86
6HUYHU

/16 /16 /16 /16


   
   
   
$FFHVV$FFHSW $FFHVV$FFHSW $FFHVV$FFHSW $FFHVV$FFHSW

The RADIUS Server includes the tunnel authentication attributes for each LNS in
the Access-Accept message.

Page 56 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

RADIUS tunnel authentication attributes


L2TP tunnels are defined by a set of RADIUS tunnel authentication attributes, such
as Tunnel-Type, Tunnel-Medium, and Tunnel-Preference.
• Tunnel attributes for LNS groups or particular LNSs are added and defined
using Service Manager, and LNS in the group inherit the group attributes.
Attributes defined at the LNS level override the group attributes.
• Tunnel-Preference values can be set dynamically to match the tunnel-tag IDs.
• Tunnel attributes are inserted into Access-Accept messages and the attribute
values are flagged with the tunnel tag ID number.
• See RFC 2868 RADIUS Attributes for Tunnel Protocol Support for information
on tunnel attributes.

To enable dynamic LNS assignment


The following steps are required to provision and enable dynamic LNS assignment:
1 Uncomment the LNS-Group VSA in the [Link] file (and add it
to any required vendor dictionary files), then send RADIUS a HUP signal and
restart the Provisioning Server (provserver) to load the updated dictionary files.
2 Use the system side of Service Manager to define LNSs, create an LNS group,
determine the tunnel attributes to use, and assign LNSs to the group.
3 Use the service side of Service Manager to add one LNS group per vendor to a
specific RADIUS connection service profile.

To create LNS groups


This section presents guidelines for configuring weighting and preference within
groups. For procedures to create, edit, and delete LNS groups, see the Service
Manager: Network Access Guide for AAA.
• Setting preference levels
The Tunnel-Preference attribute is used by the LAC to determine which LNS to
use. All other attributes being equal, the LNS with the lowest Tunnel-Preference
value is given the highest preference. Tunnel-Preference values can be
dynamically set to match the automatically generated tunnel tag ID. If dynamic
Tunnel-Preference values are not used, RADIUS automatically gives the
backup server the highest Tunnel-Preference value (lowest preference) among
the LNS returned in an Access-Accept. For more information, see the Service
Manager: Network Access Guide for AAA or online help.
• Configuring weighted server assignment
To give more weight to a particular LNS, add the same LNS more than once to
a single LNS group. This makes sure that the LNS is returned more frequently
in Access-Accept messages. Arrange the order of the LNSs in Service
Manager to increase the chance of returning the particular [Link] assign an
LNS to multiple LNS groups.

Service Controller 9.6.1-AAA October 12, 2012 Page 57


Chapter 2 RADIUS Server special features Network Access Guide

Configuring realm routing support


All local and proxy policy actions support the realm routing syntax for NAIs, as
defined in RFC4282.
For example, the NAI user@[Link] may be represented in the RADIUS
User-Name attribute as [Link]!user@[Link], to enable routing to the
subscriber’s home realm ([Link]) through an intermediary realm ([Link]).
When the Service Controller in domain [Link] receives this NAI, it converts it to
user@[Link] and passes it forward.
Multiple intermediary realms are supported, by recursively applying the realm
routing syntax conversion.
For example, the NAI [Link]![Link]!user@[Link] would be:
• received in [Link], converted to [Link]!user@[Link], and passed
forward
• received in [Link], converted to user@[Link], and routed accordingly
To configure realm routing support, local realms must be configured in the
[Link] file. For more information, see "LocalDomains" on page 13.
When the RADIUS Server proxies a request that contains one or more routing
realms, it rewrites the User-Name attribute if the domain resolved by the policy is in
the list of configured local realms. If there are no local realms configured, RADIUS
User-Name attributes are not rewritten.
Some policy action modifiers affect the resolution of domain names. The effective
domain after any applicable modifiers have been executed is the name that is
compared against the list of configured local realms. These modifiers affect domain
name resolution: domain, appendDomain, replaceDomain, discardDomain, and
domainRegexFormat.
Note If an override value for the User-Name attribute has been specified in the
filter for the target in [Link], this takes precedence. For more
information, see "OverrideAttribute" on page 342.
For information about NAI decorations, see the Service Controller: WiMAX Guide.

Configuring subscriber QoS profiles for EV-DO Rev A service


The IS835-D Subscriber QoS Profile feature enables a RADIUS Server to allocate
per subscriber QoS Profiles to a PDSN when acting as the home Service Controller
in a CDMA2000 network. This feature supports EV-DO Rev A: a wireless
technology that delivers high data rates and improved QoS for low-latency packet
[Link] feature is compliant with CDMA2000 standard TIA-835.1-D v1.0
draft version PN-3-4732-RV4.

Page 58 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

To trigger the retrieval of QoS parameters


The Service Controller detects that an Access-Request requires a Rev A QoS
profile whenever one of the following conditions is met:
• a carrier ID is present in the Access-Request
• the selected RADIUS policy file contains "mobileType=MobileFA" or
"mobileType=SimpleIP"
The Service Controller delivers "local" or "roaming" QoS policies after comparing
the NAS-IP-Address RADIUS attribute in the packet with the IP address of the
PDSN. If the NAS-IP-Address matches the IP address of the PDSN, the local QoS
policy is used. Otherwise the roaming QoS policy is used.

To create a dictionary
The default dictionaries located in /opt/aaasc/dict are read-only. When an update is
installed, this directory is overwritten. To add dictionaries or overwrite default
dictionaries, create DICT files in another location and reference them in
/opt/aaasc/config/dictionaries.
For the procedure to create a custom dictionary and finalize the changes, see
"Custom RADIUS dictionaries" on page 185.
Add the following attributes or VSAs to the new dictionary file:
VENDOR <vendor name> <vendor ID>
# Bridgewater EVDO
START-VSA 3631
ATTRIBUTE EVDO-Authorization 4 string none out single

To configure the accessReqPolicy file


Configure the accessReqPolicy file to support home agent (HA) and foreign agent
(FA) Mobile IP and simple IP calls. For example:
# request from HA

STARENT:3GPP2-MN-HA-SPI Appears Once CDMA2000LocalAA


mobileType=MobileHA validateMobileID=Never service=MIPHA

# request from FA
# Note that "mobileType=MobileFA" is present so RADIUS will be
# expecting to find the QoS Service policies

STARENT:3GPP2-HA-IP-Addr Appears Once CDMA2000LocalAA


mobileType=MobileFA validateMobileID=Never service=MIPFA

# request from PDSN for Simple IP


# Note that "mobileType=SimpleIP" is present so RADIUS will be
# expecting to find the QoS Service policies

- - - CDMA2000LocalAA mobileType=SimpleIP
validateMobileID=Never service=SimpleIP

Service Controller 9.6.1-AAA October 12, 2012 Page 59


Chapter 2 RADIUS Server special features Network Access Guide

Access options
Allocate QoS policies for subscribers according to how the subscriber is accessing
the network, as listed in Table 26.

Table 26: Access options

Option Description

Local Assign to subscribers that access their home networks directly.

Roaming Assign to subscribers that access their home networks via a foreign
network.

Static Assign to subscribers regardless of how they access the network.

IS835-D Subscriber QoS Profiles are configurable using the Service Manager (For
more information, see "Configuring QoS Profiles using the Service Manager" on
page 63) and the Provisioning Server API. For more information, see the Service
Controller: Provisioning API Guide.

QoS attributes
This feature supports the QoS attributes listed in Table 27.

Table 27: QoS attributes

Parameter Value Description

3GPP2-Allowed-Diff-Services- Octetstring 1={A,E,O}|2=<Value>|3=<Value>


Marking where
<Value> = {SC0, AF11,AF12, AF13, AF21, AF22, AF23, AF31,
AF32, AF33, AF41, AF42, AF43, EF, SC1, SC2, SC3, SC4, SC5,
SC6, SC7}

Page 60 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

Table 27: QoS attributes (continued)

Parameter Value Description

3GPP2-Service-Option-Profile Octetstring 1000=<Int32>|1001=<Int8>


|1002=<Int8>|1001=<Int8>
|1002=<Int8>| … |1001=<Int8>
|1002=<Int8>
where
• 1000 is the maximum service connections/Link Flows total
• 1001 is Service Option n
• 1002 is the maximum number of service instances of Service
Option n
• <Int32> is an integer. Range: 0 - 232
• <Int8> is an integer. Range: 0 - 28
For example, to provision service option 59 and 64:
1000=<max_svc_conn>|1001=59|
1002=<max_#_of_svc_instances>|1001=64|
1002=<max_#_svc_instances>

3GPP2-Allowed-Persistent-TFTs Integer (0–232) <Int32>


32)
3GPP2-Max-Authorized- Integer (0–2 <Int32>
Aggregate-Bandwidth

3GPP2-Authorized-Flow-Profile-IDs Octetstring 1=<Int32>|…|1=<Int32>


|2=<Int32>|…|2=<Int32>
|3=<Int32>|…|3=<Int32>
where
<Int16> is an integer. Range: 0–216
<Int32> is an integer. Range: 0–232

3GPP2-Max-Per-Flow-Priority Integer (0–232) <Int32>

3GPP2-Inter-User-Priority Integer (0–232) <Int32>

RADIUS supports merging these locally authorized QoS attributes with the QoS
attributes returned by the remote server. The rule for merging attributes from a
remote server applies; the choice of rules are:
• local only
• local first
• remote first
Note The system updates all CDMA2000 RADIUS dictionary files to include the
attributes listed in Table 28 on page 62 during installation of this feature.
The default dictionaries located in /opt/aaasc/dict are read-only. If these
attributes must be modified, create another dictionary. For more
information, see "Custom RADIUS dictionaries" on page 185.

Service Controller 9.6.1-AAA October 12, 2012 Page 61


Chapter 2 RADIUS Server special features Network Access Guide

Accounting attributes
This feature supports the accounting attributes listed in Table 28.

Table 28: QoS attributes

Parameter Value Description

3GPP2-Granted-QoS- Text (for IOT) v5535:132=<hex>


Parameters Default is unspecified. Verbose version:
v5535:132=1=<Int16>
|2=<Int16>
|3=<Int16>
|5=<Int16>
|6=<Int16>
|7=<Int16>
|8=<Int16>
|9=<Int16>
|10=<Int16>
|11=<Int16>
|12=<Int16>
where
<Int16> is an integer. Range: 0–216
<hex> is a string of hexadecimal characters

3GPP2-Flow-ID-Parameter Octetstring v5535:144=1=<Int8>|2=<Int8>


where
<Int8> is an integer. Range: 0–28
<Int16>is an integer. Range: 0–216

3GPP2-Flow-Status Integer (0–232) v5535:145=<Int32>

The system updates all CDMA2000 RADIUS dictionary files to include the attributes
listed in Table 28 during installation of this feature. The default dictionaries located
in /opt/aaasc/dict are read-only. If these attributes must be modified, create another
dictionary. For more information, see "Custom RADIUS dictionaries" on page 185.

grantedQoS
The IS835-D Subscriber QoS Profile feature supports the “grantedQoS” formatting
function. Multiple grantedQoS attributes can be sent in one RADIUS Accounting
Request message. However, only the first occurrence of a grantedQoS attribute in a
RADIUS Accounting Request message can be formatted.
Example:
$[Link]($[Link](“bin”,$[Link](“v5535:132=([^;]*)
$0”,$[Link])))
Output example with non-verbose option:
1=2|2=5|3=1|4=1
Output example with verbose option:

Page 62 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

1=2|2=5|3=2|5=1|6=10|7=2|8=5|9=8|10=10|11=256|12=0

Installation
The BWSwsdbs package creates the “RADIUS QoS Selection Policy” service class
during installation. For information about installing the BWSwsdbs package, see the
Bridgewater Installation Reference Guide.

Configuring QoS Profiles using the Service Manager


This section describes how to configure the IS835-D Subscriber QoS Profile
feature. The topics are:
• To create a RADIUS QoS Selection Policy Profile
• To create a RADIUS QoS Profile
• To create a User Profile Set with QoS Profile
• To define the QoS attributes
Note The following procedures assume familiarity with launching entity-specific
edit forms from the Service Manager main window. For more information,
see the Service Manager: Getting Started Guide for AAA.

To create a RADIUS QoS Selection Policy Profile


1 Launch the Create Service Profile edit form.
2 From the Service Class Name dropdown list, select “RADIUS QoS Selection
Policy” from the “Service Class Name” dropdown menu.
3 Click OK.
The New Service Profile form displays.
4 Type a Service Profile Name in the field provided.
5 Select “Yes” for “Inheritance”.
6 Click the “Attribute Information” tab.
7 Specify how the RADIUS QoS Policies are allocated to subscribers. Select
either of the following options:
a Allocate statically.
b Allocate based on system access type.
8 Click OK to save the profile.

To create a RADIUS QoS Profile


To create a RADIUS QoS Profile:
1 Launch the Create Service Profile edit form.
2 Select “RADIUS ConnectionService” from the pull-down menu for “Service
Class Name”.

Service Controller 9.6.1-AAA October 12, 2012 Page 63


Chapter 2 RADIUS Server special features Network Access Guide

3 Click OK.
The New Service Profile form displays
4 Type a Service Profile Name in the field provided.
5 Select “Yes” for “Inheritance”.
6 Select the “Attribute Information” tab.
7 Select the “Vendor Availability” tab.
8 Select the vendors that this service profile supports, and then click the >>
button to add them to the list of Profile Supported Vendors.
9 Select the “Vendor Attribute Availability” tab.
10 From the Vendor dropdown list, select the appropriate vendor.
11 Select attributes that this service profile supports in the “Dictionary Supported
Attributes” pane, and click “>” to move them to the “Vendor Supported
Attributes” pane.
12 Select the “Vendor Attributes” tab.
13 Add Dictionary Attributes that this service supports.
14 Click OK to save the profile.

To create a User Profile Set with QoS Profile


To create a User Profile Set with QoS Profile:
1 Launch the New User Profile Set edit form.
2 Type the name of the User Profile Set in the field provided.
3 Select “Yes” for “Inheritance”.
4 In the list of Available Profiles, select the RADIUS QoS Selection Policy profile
created in "To create a RADIUS QoS Selection Policy Profile" on page 63.
5 Click “Add>>” to assign it to the list of Assigned Profiles.
6 In the list of Available Profiles, select the RADIUS QoS Profile (RADIUS
Connection Service) created in "To create a RADIUS QoS Profile" on page 63.
7 Click “Add” to assign it to the list of Assigned Profiles.
8 In the list of Assigned Profiles, select the RADIUS QoS Selection Policy profile.
9 Click Edit.
The RADIUS QoS Selection Policy edit form displays.
10 Select the RADIUS QoS policy to assign to subscribers. Choose from the
pull-down menu for the following fields:
a Local Access QoS Policy

Page 64 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

b Roaming Access QoS Policy


Note "System Access-based QoS Policies" or "Static QoS Policy" display
depending on which radio button is selected when the profile is
created.
Note When editing a User Profile Set, the system prevents de-assigning a
RADIUS ConnectionService profile if it is selected in an assigned
RADIUS QoS Selection Policy profile.
11 Click OK to save the profile.

To define the QoS attributes


1 Search for and launch the User Profile Set edit form associated to the Root
Organization.
2 In the Assigned Profiles pane, select the RADIUS QoS Profile (RADIUS
Connection Service) created in "To create a RADIUS QoS Profile" on page 63.
3 Click Edit.
4 The RADIUS QoS Profile (RADIUS Connection Service) edit form displays.
5 From the Vendor dropdown list, select the appropriate vendor.
6 In the list of Dictionary Attributes, select QoS attributes (from Table 27 on
page 60) to add or modify, as required.
7 Repeat Step 6 until the appropriate QoS attributes are defined.
8 Click Update.

Service Controller 9.6.1-AAA October 12, 2012 Page 65


Chapter 2 RADIUS Server special features Network Access Guide

Configuring user notification messages for internationalization


For internationalization or foreign language purposes, configure the messages
displayed when users try to log in but their accounts are not available.
These messages are Access-Reject responses, and they are stored in the /opt/
aaasc/radius/[Link] file. To edit this file:
1 Edit /opt/aaasc/radius/[Link] to edit user notification messages.
2 Compile /opt/aaasc/radius/[Link]:
msgfmt [Link]
This generates a [Link] file for the messages.
3 Create a directory for the [Link] file:
mkdir -p /opt/aaasc/config/radius/locale/LC_MESSAGES
where locale is the name of the directory for the message language. For
example, en_CA is the directory name for Canadian English.
4 Copy the [Link] file to /opt/aaasc/config/radius/locale/LC_MESSAGES:
# cp [Link] /opt/aaasc/config/radius/locale/
LC_MESSAGES
5 Add the following line to /etc/init.d/wsradius to update environment variables:
LC_MESSAGES=locale; export LC_MESSAGES
where locale is the name of the directory for the message language.
6 Restart the RADIUS Server.

Configuring EAP
Administrators must configure EAP-TLS, EAP-TTLS, LEAP, MD5, MSCHAPv2,
EAP-AKA, and PEAP authentication manually. This information is added to the
[Link] and the accessReqPolicy configuration files for RADIUS, in the /opt/aaasc/
config/radius directory, and for Diameter in /opt/aaasc/config/dia-aaa.
For more information on the [Link] schema, its elements and attributes, and an
example [Link] file, see the Extensible Authentication Protocol Guide.

Page 66 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

Configuring SIP Server Interworking


With SIP Server Interworking, a SIP Notify message is sent to the SIP Server for
each accounting message received. This SIP Notify message is configured based
on parameters set in the Accounting Framework.
Additionally, the Service Controller can be configured to retrieve the subscriber’s
mobile directory number (MDN) from the LDAP database and place it in the
RADIUSATTR field of an Accounting Start, Stop, and Interim Record.
To configure the MDN to be sent in the SIP Notify message, the Accounting
Framework must be configured, the [Link] file must be updated, and the
[Link] file must include an entry for the Class Attribute.
To have the MDN sent in the SIP Notify message:
1 Edit the [Link] file to configure the ldap-attribute name and ldapvalue
parameters.
2 Edit the [Link] file to enable the ClassAttribute and to configure the
AcctRecordAttribute parameter.
3 Make sure that the BWSacctf package is installed on the Revenue Collector
and Formatter server.
4 For more information, see the Bridgewater Installation Reference Guide.
5 Configure the buffer_config.xml file to include the input buffer for the SIPClient
plugin.
6 Configure the [Link] file to include the SIPClient plugin.
7 Configure [Link]. This is the configuration file for SIPClients.
For more information, see ““Configuring SIP Server Interworking” in the
Accounting Framework Guide.

Configuring service selection


The /opt/aaasc/radius/[Link] file defines how the RADIUS Server chooses a
connection service profile during service authorization.
Note Under normal circumstances, only edit this file only with the assistance of
Bridgewater Customer Support. Making a mistake in the [Link] file
can result in incorrect service authorization or a service outage.
Each ServiceSelection entry in this file tells the RADIUS Server how to choose the
service class and service profile for authorizing connection services.
The entry for each NAS vendor in the [Link] file can specify a
ServiceSelection entry to use. For more information, see Chapter 6, "Managing
RADIUS and Diameter dictionaries".
The RADIUS Server searches for a ServiceSelection entry in the following order:
1 It looks for the SelectionName specified for the vendor in the [Link] file.
2 It looks for a SelectionName “Default<VENDOR>”.

Service Controller 9.6.1-AAA October 12, 2012 Page 67


Chapter 2 RADIUS Server special features Network Access Guide

3 It uses the SelectionName “Default”.


This is an example of a service selection element:
<ServiceSelection SelectionName="Default" DefaultProfileName="DEFAULT">
<CoalescedSVC UseDeviceVendor="y"/>
<CoalescedSVC UseDeviceVendor="n" MatchVendorName="RFC2865"/>
</ServiceSelection>

Configuring GMT offset for proxy


The BWSgmtpi package installs the [Link] RADIUS plugin to enable
the RADIUS server to retrieve a correct GMT offset, based on the BSID and write
the GMT offset to an accounting record.
The [Link] plugin activates during post authorization. If an
Access-Request contains a 3GPP2-BSID attribute, the plugin looks up the GMT
offset associated with the BSID, and returns the GMT offset in the
3GPP2-GMT-Offset attribute in the Access-Response.
The [Link] plugin reads the [Link] file to retrieve the cellID,
SID, NID, and GMTOffset. The SID, NID, and cellID are concatenated in that order
to create a BSID which is associated with the GMTOffset. The plugin saves the
BSID to GMTOffset mappings for future lookups.
The [Link] file is generated by the [Link] script,
which is installed to /opt/aaasc/gmtOffset.
For information about installing BWSgmtpi and running the
[Link] script, see the Bridgewater Installation Reference
Guide.
Note The [Link] plugin writes BSIDs which are not in the
[Link] file to the [Link] log family. Table 29 lists the
GMTOffsetPlugin log messages.

Table 29: GMTOffsetPlugin log messages

Message Priority Description Action

%s: Loading GMT Offset NTCE The plugin is loading No action required.
values from file the GMT Offset
values from the .csv
file.

No GMT Offset found for NTCE The specified BSID No action required.
BSID %s has no GMT Offset
associated with it.

Page 68 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

Configuring attribute generation in [Link]


To configure the Service Controller to generate string-type attribute values for an
LDAP deployment, update [Link] to specify a string type of static-attribute:
<service id="service2">
<vendor-attribute vendor="COMMON">
<static-attribute name="Reply-Message" value="Test"/>
</vendor-attribute>
<vendor-attribute vendor="SHASTA">
<ldap-attribute name="Service-Profile"
ldapvalue="HotLineURL"/>
<ldap-attribute name="Framed-Route" ldapvalue="uid"/>
<static-attribute name="Callback-Id"
value="###########"/>
</vendor-attribute>
</service>
The value field is a combination of the following in order:
• #A or #a to indicate generated value parameters. #A indicates that there is a
pre or post fixed value. #a indicates that there is no pre or post fixed value.
• #i and #I to indicate an incremented numeric value. #I indicates that there is a
pre or post fixed value. #i indicates that there is no pre or post fixed value. You
must also specify a numerical range up to 20 digits. All generated incremented
numeric values are the same length. If the high end of a range has fewer digits
the generated value is padded with leading zeroes. After the high end value is
generated, the generation restarts with the low end value.
• a or b to indicate Ascii Hex or Binary (used only with #a or #A)
• pr or po to indicate Pre, or Post fixed value (used only with #A or #I)
• a comma to separate the fixed value (used only with #A)
• <value> to indicate the fixed value (used only with #A)
When generating a value with a pre or post fixed value, all the parameters are
required. For example:
• #Abpo,0101 generates a binary value with 0101 appended to the end of the
generated value
• #Aapr,123 generates an ASCII Hex value with 123 appended to the beginning
of the generated value
• #i012345,234567 generates a 6 digit incremented value between 12345 and
234567
• #IprABCXYZ,001122334455,009988776655 generates a 12 digit incremented
value, between 1122334455 and 9988776655, prefixed with ABCXYZ.
• #ab generates a binary value (the minimum binary value is 16 bytes)
• #aa generates an ASCII Hex value (the minimum binary value is 32 bytes)
Note For more information about configuring [Link], see "Configuring
LDAP for RADIUS access" on page 87.

Service Controller 9.6.1-AAA October 12, 2012 Page 69


Chapter 2 RADIUS Server special features Network Access Guide

Configuring attributes to include in RADOP log messages


In addition to the default attributes included in RADIUS Server operational log
messages (RADOP) use the RADIUS [Link] file to configure attributes to
include in RADOP log messages. Specify which VSAs or non-VSAs to include in
one or all of the RADOP sub-groups [Link], [Link], and
[Link] log messages.
• Attributes for RADOP log messages 83, 211, 212, 248, 249, and 279. cannot be
configured
• For RADOP log messages, after configuring an attribute in OctetString format in
[Link], RADIUS prints the attribute in hex format.
For more information about configuring [Link], see the chapter “Configuring
the Logging Framework” in the Service Controller: Monitoring and Logging Guide.

Configuring AVP-based access control


Manage a subscriber’s access to the network based on the value of a specified
AVP or VSA contained in the subscriber’s Access-Request message.
AVP-based access control uses a policy line to trigger the Service Controller (when
conditions are met) to retrieve the Access Control service profile associated to a
subscriber. The Service Controller compares the value of a specific AVP or VSA
sent in the subscriber’s Access-Request message to a list of values provisioned
against the Access Control service profile. If the values match, the subscriber is
allowed or denied access to the network.
For example, in a WiMAX network, to deny access to all subscribers connected to a
specific base station, configure the following:
• In the Access Control service that is associated to User profile sets of all
applicable subscribers, the service provider:
– provisions the ID associated to a specific base station
– selects the Deny option
• In the Service Controller accessReqPolicy file, the service provider defines a
policy line that directs the Service Controller to match the base station ID in the
Access-Request to the ID provisioned in the Access Control service.
When a subscriber requests network access, and the base station ID contained in
the Access-Request message matches the ID provisioned in the associated Access
Control service, the Service Controller sends an Access-Reject message to the
ASN Gateway and the subscriber is rejected.
Configure AVP-based access control using the following procedures:
• To configure the acMatchAttribute policy modifier
• To use acService with acMatchAttribute
• To provision the Access Attribute tab

Page 70 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

To configure the acMatchAttribute policy modifier


Add the acMatchAttribute policy modifier to a policy line in the accessReqPolicy file
to enable the AVP-based access control feature. This triggers the Service
Controller (during the authorization phase) to look for a specific attribute value in
the subscriber’s Access-Request message. The Service Controller compares this
value to the list of values provisioned in the subscriber’s Access Control service. If
the values match, the Service Controller executes the specified action, such as
allowing or denying access to the network.
Policy line example:
- - - LocalAA acMatchAttribute=Calling-Station-ID
Use acMatchAttribute in RADIUS and/or Diameter but the behavior and
configuration is different for each protocol. For details about configuring
acMatchAttribute for RADIUS and Diameter, see Table 30.

Table 30: Parameters for the acMatchAttribute modifier

Parameter RADIUS Diameter

Supported actions for • LocalAA, ProxyAA • WiMAXLocalAA


acMatchAttribute • PreAuthorize
• CallCheckAA
• CDMA2000LocalAA
• CDMA2000ProxyAA
• SSCLocalAA
• DMULocalAA
• DMUProxyAA
• GSMLocalAA\
• GSMProxyAA
• WiFiLocalAA
• WiMAXLocalAA
• WiMAXProxyAA

Valid values for The name of any AVP or VSA in a RADIUS The name of any AVP or VSA in the
acMatchAttribute dictionary that is loaded on the database. [Link] dictionary file.
Must be in the form: Must be in the form: <attribute-name>
[<vendor-name>:]<attribute-name> Note: Do not use the vendor-name parameter in
(vendor-name is optional) Diameter deployments.
Example: User-Name contains @[Link] Example:
LocalAA User-Name contains @[Link] WiMAXLocalAA
acMatchAttribute=Calling-Station-ID acMatchAttribute=Calling-Station-ID

Supported attribute types Supports all RADIUS attribute types except Supports all Diameter attribute types except
for acMatchAttribute “octetstring’ (sub-typed attributes) “grouped”, “float32”, and “float64”.

Policy line restrictions Cannot use the action modifier/value —


when using “authorize=n” on the same line as
acMatchAttribute acMatchAttribute

Service Controller 9.6.1-AAA October 12, 2012 Page 71


Chapter 2 RADIUS Server special features Network Access Guide

Table 30: Parameters for the acMatchAttribute modifier (continued)

Parameter RADIUS Diameter

IP version support — acMatchAttribute only supports address-type


AVPs if the AVP contains an IPv4 address.
IPv6 is not supported.

Note If this modifier is added to a policy line, but the attribute value in the
Access-Request message does not match the attribute value in the
associated Access Control service, the Service Controller returns an
Access-Reject.

To use acService with acMatchAttribute


Using only the default Access Control service profile does not require the acService
modifier because the Service Controller automatically retrieves the default service
(Access Control).
However, after provisioning multiple Access Control service profiles, add the
acService action modifier to define the name of the service to be used.
For example, after provisioning multiple Access Control service profiles, such as
AccessControl1, AccessControl2, and AccessControl3, add the acService modifier
using the following syntax:
- - - WiMAXLocalAA acMatchAttribute=Calling-Station-ID
acService=AccessControl3

To provision the Access Attribute tab


The Access Attribute tab on the Access Control edit form enables provisioning of
the attribute value that the system uses to compare to the attribute value contained
in the subscriber’s Access-Request message or Diameter DER message.
The Access Attribute tab displays at all contexts, such as the Organization, User
Profile Set, and User contexts. The fields and attributes are identical at all contexts.
Make sure that you add the appropriate Access Control service profile to the User
profile set for all users to whom you want to apply AVP-based access control. If a
user is not provisioned with the Access Control service containing the attribute
value required for AVP-based Access Control, the user’s request is rejected.
To provision AVP-based access control:
• create or edit an Access Control service
• provision the Access Attribute tab on the Access Control edit form:
– provision the AVP value(s)
– choose the action to apply to applicable subscribers.
– Service Manager displays a pop-up message when trying to save an
attribute list where the Access field is set to “Unspecified”.
– If access attributes are configured at multiple contexts and the Access field
is set to “Unspecified” for each context, the subscriber is denied access to
the network.

Page 72 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

– If access attributes are configured at multiple contexts and the Access field
is set to “Unspecified” at the User context, but the Access field is set to
“Allow” or “Deny” at a higher context, the action specified at the higher
context takes precedence
• add this service profile to the User profile sets of all subscribers to whom you
want to apply AVP-based access control
For information about the fields and attributes of the Access Attribute tab on the
Access Control edit form, see the Service Manager: Services Provisioning Guide
for AAA.

Configuring duplicate detection


Configure the RADIUS Server to identify and process duplicate request messages,
including Access-Requests, Accounting messages, and DAE messages. When
configuring the RADIUS Server for duplicate detection, specify to enable this
feature for specific vendors and specify how long RADIUS processes a duplicate
request before dropping the request, and how many times RADIUS returns the
same response for a duplicate request.
Configure duplicate detection settings in the [Link] file and enable
duplicate detection for specific vendors in the [Link] file.

To configure duplicate detection


1 Navigate to [Link], located in /opt/aaasc/config/radius.
2 Go to the DuplicateDetection element and provide values for the following
attributes:
– DetectionThreshold
– ReplayLastResponseThreshold
– AuditInterval attributes
For example:
<DuplicateDetection
DetectionThreshold="15"
ReplayLastResponseThreshold="1"
AuditInterval="15"/>
3 Navigate to [Link], located in the /opt/aaasc/config/radius.
4 Go to the Vendor element and set the DuplicateDetection attribute to “Y”.
For example:
<Vendor
VendorName=”VendorName”
DuplicateDetection=”Y”>
5 Restart the RADIUS Server for the changes to take effect:
For more information about configuring duplicate detection, see
"DuplicateDetection" on page 17 and see "Configuring vendor-specific data
([Link])" on page 189.

Service Controller 9.6.1-AAA October 12, 2012 Page 73


Chapter 2 RADIUS Server special features Network Access Guide

Configuring database (DAL query) caching for multi-leg EAP


Note This feature installs with the BWScdal package, which requires a special
licence. For more information, contact Bridgewater Customer Support.
During subscriber authorization, some deployments require multiple database
queries to support policy actions, such as PreAuthorize, during a multi-leg EAP
exchange. Multiple database queries per subscriber can significantly diminish the
performance of your network.
To reduce the number of queries to the Profile database and improve performance,
configure the DAL Query Caching feature. This feature enables RADIUS to store
data for a DAL query context, such as User, in the existing EAP-state cache for the
duration of the EAP exchange. Once RADIUS saves the DAL query context data to
the cache, subsequent queries (during the EAP exchange) retrieve this data from
the cache and not from the Profile database.
Figure 7: Caching CDAL context data in the EAP-state cache

6HUYLFH&RQWUROOHU
5$',866HUYHU

&'$/ 3URILOH
5$',86 ($3 FRQWH[W 'DWDEDVH
FOLHQW H[FKDQJH ($3
VHVVLRQGDWD
($3VWDWH
GDWDFRQWDLQHU

To enable DAL query caching


1 Install and configure the BWScdal package under the guidance of Bridgewater
Customer Support.
2 Modify the [Link] file.

Page 74 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

DAL query caching call flow


Figure 8 and the associated description provide information about the process of
caching and retrieving data during a multi-leg EAP exchange.
Figure 8: Call flow for DAL query caching

($3VWDWH
5$',86 5$',86 3URILOH
GDWD
6HUYHU &OLHQW GDWDEDVH
FRQWDLQHU


















1 The RADIUS Server receives the first Access-Request message of a multi-leg


EAP exchange.
2 The RADIUS Server discovers and processes a Pre-Authorize policy action,
which results in a database query to retrieve the required attributes.
3 RADIUS creates and stores the EAP-state data container in RADIUS memory.
4 The RADIUS Server sends the client an Access-Challenge message.
5 As part of the EAP-TLS exchange, the RADIUS client sends the RADIUS
Server an Access-Request.
6 The RADIUS Server processes the Pre-Authorize policy action.
7 The RADIUS Server looks for the EAP-state data container, but does not find
the cached DAL query context, which has not been created.
8 RADIUS uses DAL to retrieve the required attributes from the Profile database.
9 RADIUS stores the DAL query context to the EAP-state data container.
10 The RADIUS Server sends the client another Access-Challenge message.
11 As part of the EAP-TLS exchange, the RADIUS client sends the RADIUS
Server another Access-Request.
12 The RADIUS Server processes the Pre-Authorize policy action.
13 The RADIUS Server looks for the EAP-state data container and finds the
cached DAL query context.
14 The RADIUS Server uses the DAL query context to retrieve the cached
attributes.

Service Controller 9.6.1-AAA October 12, 2012 Page 75


Chapter 2 RADIUS Server special features Network Access Guide

15 The RADIUS Server and client continue to exchange EAP messages until the
EAP-TLS process completes.

[Link]
Set the EAPSessionCacheEnabled parameter in the [Link] file to ‘Y’.
The [Link] file is located in the /opt/aaasc/config/radius directory. For
more information about [Link], see "Configuring access features with
[Link]" on page 5.
Example:
<RADIUSConfiguration AcctDBLookup="Y"
DefaultAccessControlService="Access Control" DNSThreads="0"
ValidateClientIP="Y" WiMAXReAuthenticationInterval="1800"
WiMAXReAuthenticationIntervalDelta="0" MaximumLoadedClients="5000"
LogCallingStationIdOnReject="N" LogNASIP="N"
EAPSessionCacheEnabled ="Y" >

Configuring HTTP Digest Authentication


When the HTTP proxy receives a client HTTP access request without an
authorization header, HTTP Digest Authentication is used to obtain EAP-AKA
parameters that are used as a one-time password generation mechanism for Digest
authentication. When the RADIUS Server receives the access request, it retrieves
an AKA vector from the HLR using the MAP protocol.
HTTP Digest Authentication requires the following packages:
• BWSoras1—Database Server
• BWSoras2—Database Server
• BVWSorap—Database patch
• BWSwsco—SDB common utilities, test tools, and libraries
• BWSwsdbs—Database scripts
• BWSorac—Database Client
• BWSaaaco—Service Controller common utilities, test tools, libraries
• BWSdal—Bridgewater data access layer
• BWSprovs—Service Controller Provisioning Server
• BWSaaapr—Provisioning Server API
• BWSwssc—Service Controller client utilities
• BWSwsmw—Middleware Service
• BWSwsrad—RADIUS Server
• BWSgsmgw—GSM MAP Authentication Gateway
For installation prompts and instructions, see the Bridgewater Installation
Reference Guide.

Page 76 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

HTTP Digest Authentication call flows


This section describes the following call flows:
• HTTP Digest Authentication
• AKA synchronization failure

HTTP Digest In this call flow, the RADIUS Server receives an authentication request from the
Authentication HTTP proxy that contains Digest attributes.

First Access-Request
Figure 9: First Access-Request

8(
+7733UR[\ $$$6HUYHU +/5
'166HUYHU
86,0 0(

^,06,.` ^,06,.`

6,0B5HDG +773UHTXHVW $FFHVV5HTXHVW


8VHU$JHQW[[[DXWKHQWLFDWLRQPRGH 8VHU1DPH ´,06,´
,06, $XWKRUL]DWLRQ'LJHVWXVHUQDPH ´,06,´ 'LJHVW$OJRULWKP ´$.$Y0'
8UL ´;;;<<<´ 'LJHVW0HWKRG ´JHW´ ^,06,.`
$OJRULWKP$.$Y0' 'LJHVW85, ´;;;<<<´
0HVVDJH$XWKHQWLFDWRU 0$&!^5)&`
$FFHVV5HTXHVW ,06, 0$3
6HQGB$XWKHQWLFDWLRQB,QIR
5HTXHVW ,06,

^,06,.6415$1'
;5(6&.,.$871`
8QDXWKRUL]HG
:::$XWKHQWLFDWH'LJHVW 0$3
5HDOP ´DEFKRPHQHW´QRQFH EDVH 6HQGB$XWKHQWLFDWLRQB,QIR
5HVSRQVH 5$1';5(6&.
5$1' DOJRULWKP $.$Y0' ,.$871
$FFHVV&KDOOHQJH 5$1'
TRS ´DXWK´ UHDOPDOJRTRS

$FFHVV&KDOOHQJH
'LJHVW$OJRULWKP ´$.$Y0' $$$VHUYHUILOOV
'LJHVW1RQFH ´5$1'´ VRPHILHOGV
'LJHVW5HDOP ´DEFKRPHQHW´ 67$7,& UHDOPDOJRDQG
'LJHVW4RS ´DXWK´ 67$7,& TRS
6WDWH ´;5(6´
0HVVDJH$XWKHQWLFDWRU 0$&!^5)&`

1 A user device sends an HTTP request without an Authorization header to the


HTTP proxy.
2 The HTTP proxy sends an Access-Request packet with the newly defined
Digest-Method and Digest-URI attributes but without a Digest-Nonce Attribute
to the RADIUS server.

Service Controller 9.6.1-AAA October 12, 2012 Page 77


Chapter 2 RADIUS Server special features Network Access Guide

3 The RADIUS Server retrieves an AKA vector from an HLR by using


sendAuthenticationInfo MAP messages.
The RADIUS server chooses a nonce and responds with an Access-Challenge.
This Access-Challenge contains Digest attributes from which HTTP proxy takes
values to construct an HTTP "(Proxy) Authorization required" response.
4 The HTTP proxy sends this response to the user device.

Second Access-Request
Figure 10: Second Access-Request

8(
'166HUYHU +7733UR[\ $$$6HUYHU +/5
86,0 0(

^,06,.`
^,06,.`
$FFHVV&KDOOHQJH
6,0BDXWKHQWLFDWLRQ 5$1' 8VHU1DPH ´,06,´
'LJHVW5HDOP ´DEFKRPHQHW´
6,0B*60$XWKHQWLFDWLRQ 5(6.& 'LJHVW$OJRULWKP ´$.$Y0'
'LJHVW4RS ´DXWK´
+773UHTXHVW 'LJHVW0HWKRG ´3267´
8VHU$JHQW[[[DXWKHQWLFDWLRQPRGH 'LJHVW85, ´;;;<<<´
$XWKRUL]DWLRQ'LJHVWXVHUQDPH ´,06,´ 'LJHVW&QRQFH ´FQRQFH´
5HODP ´DEFKRPHQHW´QRQFH EDVH 'LJHVW1RQFH ´5$1'´
5$1' DOJRULWKP $.$Y0' 'LJHVW1RQFH&RXQW ´QF´
8UL ´;;;<<<´UHVSRQVH ´[[[[«´ 'LJHVW5HVSRQVH ´UHVSRQVH´ 5)&
6WDWH ´;5(6´
0HVVDJH$XWKHQWLFDWRU 0$&!^5)&`
0'UHVSRQVHEXLOWXVLQJWKH&KDOOHQJHUHVSRQVHFRPSXWHG $FFHVV5HTXHVW $.$Y0',06,
E\WKH6,0I DOJR,06,UHDOP5(6QRQFHFQRQFHQF DEFKRPHQHWUHVSRQVH3267XUL
PHWKRGXUL

&DOFXODWHI^DOJR,06,UHDOP;5(6
QRQFHFQRQFHQFPHWKRGXUL`
$QGFRPSDUHUHVXOWZLWKUHVSRQVH

0$36(1'5287,1*,1)2)25/&6 ,06,

0$36(1'5287,1*,1)2)25/&65HVSRQVH 06,6'1
$FFHVV$FFHSW 06,6'1

$FFHVV$FFHSW
8VHU1DPH ´06,6'1´
0HVVDJH$XWKHQWLFDWRU 0$&!^5)&`

1 The user device resends its request with its credentials.


2 The HTTP proxy sends an Access-Request to Radius Server.
3 The Radius Server retrieves the MSISDN from the HLR using the message
MAP-SEND-ROUTING-INFO-FOR-LCS.
Note The MSIDSNs retrieved are cached through the RMS interface.
4 The Radius Server checks the credentials and replies with Access-Accept or
Access-Reject message.

Page 78 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

5 Depending on Radius Server s result, the HTTP proxy processes the user
devices request or rejects it with a "(Proxy) Authorization required" response.

AKA synchronization In this call flow, the SQN provided by the RADIUS Server does not match the one
failure maintained by the HTTP Proxy.
Figure 11: AKA synchronization failure

+7733UR[\ 5$',86 +20(+/5$&

^,06,.`
$XWKUHTXHVW
5$1'$$871
06GHWHUPLQHVWKDWWKH641FRQWDLQHGLQWKH$871GRHV
QRWPDWFKLWVORFDOO\VWRUHG641DQGUHVSRQGVZLWKDQDXWK
DXWKUHV\QFKURQL]H UHV\QFKURQL]HPHVVDJH

)DLOXUHUHSRUWVHQWZLWKDQ$.$537
$.$5(3257$.$537 YDOXHRI³6\QFK)DLOXUH´$876
5$1'$$876 FRQWDLQV&21B06B641 0$&B6
YDOXHVUHFHLYHGIURP06

DNDUHSRUW
$.$9/
+RPHV\VWHPXVHV$876LQIRWR
V\QFKURQL]HZLWK06DQGSURYLGH
DQHZOLVWRI$9V

DXWKUHTXHVW
5$1'$$871 9LVLWHGV\WHPUHDWWHPSWV$.$DXWK
XVLQJ$9IURPQHZOLVW

1 After receiving an AURSYNM response from the HTTP Proxy, the RADIUS
Server sends an AKA status report (AKAREPORT) to the HLR with AKARPT
set to "Synchronization Failure."
Also included in this report are the RANDA used during the AKA attempt and an
AKA authentication token for resynchronization (AUTS) containing the
CON_MS_SQN and MAC_S values received from the HTTP Proxy.
2 The HLR uses the MAC_S to make sure that the resynchronization attempt is
authentic and sets its SQN to the one concealed in the CON_MS_SQN.
3 With the new SQN, the HLR generates a new AV list and provides this new AV
list to the RADIUS Server in the AKAREPORT response message (akareport).
The HLR has resynchronized.
4 The RADIUS Server selects an AV from the new list and reattempts AKA with
the HTTP proxy.

Service Controller 9.6.1-AAA October 12, 2012 Page 79


Chapter 2 RADIUS Server special features Network Access Guide

Policies
The HTTPDigest-Policy action modifier enables the RADIUS Server to use AKA
authentication when an Access-Request containing Digest attributes for Digest
Authentication is received from the HTTP proxy.
When not explicitly specified on the policy line, RADIUS automatically looks for a
<http-digest-policy> entry in the [Link] file with the policy name set to
“default”.

[Link]
The [Link] dictionary contains Digest attributes used for HTTP Digest
Authentication.
#RFC 5090 HTTP-Digest Authentication attributes
ATTRIBUTE Digest-Response 103 string none in single
ATTRIBUTE Digest-Realm 104 string none both single
ATTRIBUTE Digest-Nonce 105 string none both single
ATTRIBUTE Digest-Response-Auth 106 string none out single
ATTRIBUTE Digest-Nextnonce 107 string none out single
ATTRIBUTE Digest-Method 108 string none both single
ATTRIBUTE Digest-URI 109 string none in single
ATTRIBUTE Digest-Qop 110 string none both multi
ATTRIBUTE Digest-Algorithm 111 string none both single
ATTRIBUTE Digest-Entity-Body-Hash 112 string none in single
ATTRIBUTE Digest-CNonce 113 string none in single
ATTRIBUTE Digest-Nonce-Count 114 string none in single
ATTRIBUTE Digest-Username 115 string none in single
ATTRIBUTE Digest-Opaque 116 string none both single
ATTRIBUTE Digest-Auth-Param 117 string none both single
ATTRIBUTE Digest-AKA-Auts 118 string none in single
ATTRIBUTE Digest-Domain 119 string none both multi
ATTRIBUTE Digest-Stale 120 string none out single
ATTRIBUTE Digest-HA1 121 string none out single
ATTRIBUTE SIP-AOR 122 string none in single

Configuration
HTTP Digest Authentication requires two configuration files: [Link] and
[Link] file. The [Link] file is configured for a standard WLAN
deployment. For more information about the [Link] file, see the 3G/
WLAN Interworking Guide.

Page 80 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

[Link] file The [Link] file, located in /opt/aaasc/config/radius/, defines the specific
HTTP digest configuration. The file is delivered, preconfigured, in the BWSwsrad
package, and is huppable.

Table 31: [Link] attributes

Element Value Description

http-digest-configuration — The parent element.

vector-setting — Required.
Child element of http-digest-configuration.

vector-setting-name String The name of the vector setting, for example, “HLR”.
Required.
Attribute of vector-setting.

http-digest-policy — Required.
Child element of http-digest-configuration.

AKAv1-MD5 or — The configuration for the AKAv1-MD5 or AKAv1-MD5-sess


AKAv1-MD5-sess HTTP digest algorithms.
Child element of http-digest-policy.

[Link] example
<http-digest-configuration>
<vector-setting
vector-setting-name="HLR"
authentication-center="External-No-DB-Lookup"/>
<http-digest-policy
policy-name="default"
realm="[Link]"
quality-of-protection="auth">
<AKAv1-MD5
vector-setting="HLR"
nonce-format="RAND"/>
</http-digest-policy>
</http-digest-configuration>

Service Controller 9.6.1-AAA October 12, 2012 Page 81


Chapter 2 RADIUS Server special features Network Access Guide

Configuring MAC caching using Calling-Station-Id


In a two-stage authentication, the first stage is a standard EAP-SIM/AKA
authentication. the second stage is a standard authentication from a Tunnel
Terminating Gateway (TTG). The user identity in the second stage must be related
back to the user identity in the first stage. To achieve this, the Service Controller
caches the subscriber’s MAC address from the Calling-Station-Id attribute received
during the EAP-SIM/AKA authentication in the RMS.
When the access request modifier checkSession is set to ‘y’, the cached MAC
address is compared to the MAC address returned in the second access request
packet.

accessReqPolicy example
---WiFiLocalAA EAP-Policy=default service=DEFAULT
---WiFiLocalAA service=DEFAULT authentication=n
checkSession=y

MAC caching message flow


In this call flow, the Service Controller caches the subscriber’s MAC address in the
RMS and verifies the MAC address received from the HLR.
Figure 12: MAC caching message flow

:LUHOHVV/$1
06 $FFHVV3RLQW 77* 6HUYLFH&RQWUROOHU 506 +/5
&RQWUROOHU














Page 82 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

1 A subscriber sends an Access-Request message through the Access point and


Wireless LAN Controller (WLC) to the Service Controller.
2 The Service Controller queries the HLR for the subscriber profile.
3 The HLR returns the subscriber profile to the Service Controller which then
sends an Access-Accept message to the WLC.
4 The WLC sends an Acct-Start message to the Service Controller.
5 The Service Controller creates a WiFi offload session in the RMS and stores
the subscriber’s Calling-Station-Id received in the Acct-Start message as the
MAC address.
6 The Service Controller sends an accounting response message to the WLC.
7 The TTG sends an Access-Request message to the Service Controller.
8 The Service Controller compares the Calling-Station-Id in the Access-Request
message with the cached MAC address in the RMS.
9 If the MAC addresses are the same, the Service Controller sends an
Access-Accept message to the TTG.

Configuring RADIUS-based metering


Use volume-based metering to track a subscriber’s usage and to apply the
configured policy when a subscriber:
• comes online
• passes a configured threshold or usage cap
• changes account
• goes offline
After exceeding a configured threshold, the Policy Controller re-evaluates the
subscriber’s policy and sends a new threshold or vendor QoS.
For information about provisioning VBM, see the Policy Controller documentation.

[Link]
The [Link] file is the configuration file for the npcGSM plugin, and it
defines a list of Policy Controller servers. When more than one Policy Controller is
listed, the npcGSM plugin supports failover. If a Policy Controller is unreachable,
the plugin suspends the Policy Controller and fails over to the next Policy Controller
in the list. If all Policy Controllers are suspended, the plugin retries the Policy
Controller with the lowest remaining suspension timeout.
When more than one Policy Controller is defined in the [Link] file, the
list of Policy Controller nodes is also used for load balancing. Requests are
allocated to Policy Controllers in a round robin method.
To make sure the system loads [Link] file changes, send a HUP signal
to the RADIUS server.
The [Link] file is located in the /opt/aaasc/config/radius/ directory.

Service Controller 9.6.1-AAA October 12, 2012 Page 83


Chapter 2 RADIUS Server special features Network Access Guide

For installation information, see Bridgewater Installation Reference Guide.

Table 32: [Link] elements and attributes

Elements/Attribute Value Description

server-config — Encloses elements that define Policy Controllers.

max-connection Integer The maximum number of connections to the Policy Controller.


Attribute of server-config.

default-domain String The name of the default domain to add to the request if no domain
is specified.
Attribute of server-config.

primary-policy-controller — Parent element for the list of Policy Controller nodes.


Child element of server-config.

policy-controller — Encloses element that define a Policy Controller.


Child element of primary-policy-controller.

address String The IP address of the Policy Controller.


Attribute of policy-controller.

port Integer The port on which the plugin contacts the Policy Controller.
Attribute of policy-controller.

timeout Integer The time after which the plugin fails over to the secondary Policy
(100-20000) Controller.
Default =2000 Attribute of policy-controller.
Optional.

suspension-timeout Integer The Policy Controller suspension length.


(100-20000) Attribute of policy-controller.
Default =2000 Optional.

max-connection-timeout Integer The timeout for the Policy Controller with the highest number of
(100-20000) queued available connected-connections when the max-connection
Default =2000 is reached.
Attribute of policy-controller.
Optional.

remote • true For geo-redundant Policy Controller deployments, set to true to


• false indicate that the associated server is a back-up server for a Policy
Controller cluster in a different geographic area.
Attribute of policy-controller.

additional-var-list — Encloses the list of RADIUS variable names that the plugin
retrieves from the RADIUS policy.
Child element of server-config.

Page 84 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 2 RADIUS Server special features

Table 32: [Link] elements and attributes (continued)

Elements/Attribute Value Description

additional-var-name String Child element of additional-var-list.


For more information about configuring additional variables, see
"Create additional variables for use in policies" on page 86.

radius-attribute-list — Encloses the list of RADIUS attributes.


Child element of policy-plugin-config.

default-stop-indicator • false (Default) The value for the 3GPP-Session-Stop-Indicator attribute.


• true Optional.
Attribute of radius-attribute-list.

radius-attribute — Defines the radius attribute.

name String The RADIUS attribute name.


Attribute of radius-attribute.

optional • false Define whether the RADIUS attribute is optional or mandatory.


• true (Default) Attribute of radius-attribute.

Example [Link] file


<policy-plugin-config xmlns:xsi="[Link]
xsi:noNamespaceSchemaLocation="[Link]">
<server-config max-connection="20" default-domain="[Link]">
<primary-policy-controller>
<policy-controller address="[Link] port="32010"
timeout="2000" max-connection-timeout="2000"
suspension-timeout="20000" />
<policy-controller address="[Link] port="32010"
timeout="2000" max-connection-timeout="2000"
suspension-timeout="20000" />
<policy-controller address="[Link] port="32010"
timeout="2000" max-connection-timeout="2000"
suspension-timeout="6000" remote="true"/>
<policy-controller address="[Link] port="32010"
timeout="2000" max-connection-timeout="2000"
suspension-timeout="6000" remote="true"/>
</primary-policy-controller>
<additional-var-list>
<additional-var-name>attribute2<additional-var-name>/>
</additional-var-list>
</server-config>
<radius-attribute-list default-stop-indicator="true">
<radius-attribute name="3GPP-IMSI" optional="true" />

Service Controller 9.6.1-AAA October 12, 2012 Page 85


Chapter 2 RADIUS Server special features Network Access Guide

<radius-attribute name="3GPP-SGSN-MCC-MNC" optional="true" />


<radius-attribute name="3GPP-MS-Timezone" optional="true" />
<radius-attribute name="3GPP-SGSN-Address" optional="true" />
<radius-attribute name="3GPP-Session-Stop-Indicator" optional="false" />
</radius-attribute-list>
</policy-plugin-config>

Create additional Specify additional variables for VBM that can be used to create policies in the RMA.
variables for use in
policies To create additional variables
1 Add a variable, such as “attribute2, to the [Link] file.
The [Link] file is located in the $HOME/is/<instance name>/
provserver/ config/ directory on the Policy Controller server.
Example:
<additional-information entity="Additional Information">
<attribute name="attribute2"/>
</additional-information>
2 Add the entry point for the variable to the [Link] file.
For example, to add a variable to the AAA authorization entry point, add the
variable to the <entry-point name="AAA_Auth"> section:
<entity name="Additional Information">
<attribute name="attribute2" base-type="STRING"/>
</entity>
The [Link] file is located in the $HOME/is/<instance
name>/provserver/config/ruleEngineDescriptors/ directory on the Policy
Controller server.
3 Add the variable to the [Link] file.
The [Link] file is located in the /opt/aaasc/config/radius/ directory
on the Service Controller server.

Page 86 October 12, 2012 Service Controller 9.6.1-AAA


Configuring LDAP for RADIUS access

3
Chapter 3
Chapter

This chapter describes how to configure LDAP as the subscriber data access
method for the Service Controller.
The topics are:
• RADIUS and an LDAP Directory Server
• Configure [Link]
• Managing the memory map file
• Configuring LDAP DAL Query Caching
• Configuring LDAP connection pooling
• Configuring remote LDAP authentication
• Configuring the LDAP secondary shared secret

Service Controller 9.6.1-AAA October 12, 2012 Page 87


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

RADIUS and an LDAP Directory Server


Figure 13 shows how the RADIUS Server and the LDAP Directory Server
communicate using an LDAP memory map file. The memory map file contains a
cached copy of the [Link] file.
Figure 13: Service Controller with LDAP

6HUYLFH&RQWUROOHU

$FFHVV
5$',86
5HTXHVWV

/'$3PHPRU\ /'$3
SDSILOH GLUHFWRU\

Note Configuring the RADIUS Server to use a LDAP Directory Server involves
customizing the [Link] file to interact with the database schema
specific to the LDAP directory. Contact Bridgewater Customer Support for
more information.
Figure 14 illustrates the processes involved in communication between the Service
Controller and the LDAP database.
Figure 14: Service Controller interface with LDAP database

6HUYLFH&RQWUROOHU

UDGLXVG

/'$3'$/ UDGLXVGLQWHUIDFH /'$3'$/VKDUHGOLEUDU\ OLEZVBGDOBOGDSVR

/'$3
GDWDEDVH

Page 88 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

The following steps are required to configure the RADIUS Server to use an LDAP
Directory Server:
• Configure [Link]
• Managing the memory map file
Note Before starting the configuration steps, verify that the LDAP DAL was
selected when installing the BWSdal and BWSwsrad packages.

Configure [Link]
The [Link] file, located in /opt/aaasc/config/, contains the information
required for the RADIUS Server to interact with the LDAP directory database
schema.
After the [Link] file is loaded into the memory map file, the system sends a
HUP signal to the RADIUS Server process to make changes to the XML file take
effect.
For an example [Link] configuration file, see "Example [Link] file"
on page 107.

[Link] The [Link] schema contains these elements:


schema radintdal: the root element
system-elements
pdsn-group
client
client-pool
ip-range
ha-group
wimax-node-group
wimax-ha-group
ldap-server
service
vendor-attribute
dal-cache

Service Controller 9.6.1-AAA October 12, 2012 Page 89


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

radintdal The ldapload utility root element. It encloses these elements:


• system-elements (required)
• ldap-server (required)
• one or more service elements (required)
• dal-cache (optional)
For example:
<radintdal>
<system-elements ... />
<ldap-server ... />
<service ... />
<service ... />
<dal-cache .../>
</radintdal>

system-elements The element that encloses the system provisioning elements for RADIUS clients,
PDSN groups, and HA groups:
• one or more pdsn-group child elements (optional)
• one or more client child elements (required)
• one or more client-pool child elements
• one or more ha-group child elements (optional)
• one or more wimax-node-group child elements (optional)
• one or more wimax-ha-group child elements (optional)
The system-elements tag has no attributes.
For example:
<system-elements>
<pdsn-group ... />
<client ... />
<client-pool ... />
<ha-group ... />
<wimax-node-group ... />
<wimax-ha-group ... />
</system-elements>

pdsn-group Defines PDSN groups for client systems. One or more pdsn-group elements may
be defined, up to a maximum of 64.
A pdsn-group element must be defined before it is referenced by a client element.
Child element of system-elements.
Optional

Page 90 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

For example:
<pdsn-group id="chicago-pdsn" rms-cluster-id="1"/>

Table 33: pdsn-group attributes

Attribute Value Description

id String The name of the PDSN group. This value must be unique among the
IDs in this file.
Required.

rms-cluster-id Integer (0–254) The RMS cluster number for this group. This value must match a cluster
ID defined in the [Link] file.
Required.

client Defines a client system.


When adding clients:
• One or more client elements may be defined, up to a maximum of 4602.
• Up to 512 of the total clients may be WiMAX clients. This means that up to 512
client elements can contain the optional wimax-node-group attribute.
• Up to 512 of the total number of clients can be client-pools.
• All attributes are required unless indicated.
Child element of system-elements.
Required.
For example:
<client
id="chicago1"
ip-address="[Link]"
secret="MYSECRET"
vendor="NORTEL"
timezone="GMT"
pdsn-group="chicago-pdsn"/>

Table 34: client attributes

Attribute Value Description

id String The name of the client. This value must be unique among the
IDs in this file.
Required.

ip-address IPv4 address A valid IPv4 address in decimal-dot notation.


Required.

Service Controller 9.6.1-AAA October 12, 2012 Page 91


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

Table 34: client attributes (continued)

Attribute Value Description

ipv6-address IPv6 address A valid IPv6 address in hexadecimal-colon notation.


Optional.

hl-prefix IPv6 prefix A valid IPv6 network prefix.


Optional.
Required if an IPv6 address is specified.

mip6-ha-protocol-capability • Y, y When enabled, indicates that the HA supports the


• N, n (default) authentication protocol specified by RFC 4285 for MIP6
signalling security.

secret String The shared secret string used by the client.


Required.

secret2 String The secondary shared secret string used by the client.
Optional.

vendor String The vendor name which matches an entry in the [Link]
file.
Required.

model String This value must match the entry in the [Link] file.
Optional.

timezone String The timezone in which the client runs. The typical value is
GMT.
Required.

pdsn-group String This value must match a previously defined pdsn-group ID.
Do not specify the pdsn-group attribute if the
wimax-node-group attribute is specified.
Optional.

skipcount Integer (0–254) A tuning parameter, used for load balancing. For example, if
skipcount=3, the specified client receives every third request.
Optional.

ha-root-key-lifetime Integer The lifetime, in seconds, of the WiMAX HA root key


associated with the client. Setting this attribute with a value
greater than zero defines the client as an HA and roots keys
are generated. The recommended value is 86400 (24 hours).
If this attribute is not set or not set to a value greater than
zero, the client does not have an HA role and will not have
root keys generated.
This attribute is only valid if wimax-node-group is present.
Optional.

Page 92 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

Table 34: client attributes (continued)

Attribute Value Description

ha-root-key-rms-cluster-id Integer When the HA belongs to a WiMAX node group that is


0 to 254 associated to multiple RMS clusters, use the
ha-root-key-rms-cluster-id to identify the cluster in which HA
keys are stored.
An ha-root-key-lifetime attribute value must be present;
otherwise, the system generates an error.
Note If the client is an HA, and it belongs to a WiMAX node
group configured with multiple RMS clusters, an
ha-root-key-rms-cluster-id attribute value is required.
Note Bridgewater does not recommend changing the value
of the Root Key RMS Cluster Id. However, after
modifying this value, restart the RADIUS Server, which
enables the RADIUS Server to re-create HA keys in the
new RMS cluster.
Bridgewater Systems recommends restarting the RADIUS
Server when network traffic is minimal and when the HA key
nears its expiration date.

wimax-node-group String The name of the wimax-node-group element that matches a


previously defined wimax-node-group-id.
Do not specify the wimax-node-group attribute if the
pdsn-group attribute is specified.
Optional.

dae-enabled • false (default) Enables Dynamic Authorization Extensions support for


• true WiMAX hotlining.
Optional.

dae-coa-ip-address IP address The IP address, in dot notation, to receive DAE messages.


Default = ip address Automatically set to the ip-address configured for the WiMAX
configured for the WiMAX node. Use for CoA messages.
node Optional.

dae-coa-port Integer (1024–65535) The port on which to receive DAE messages. Use for CoA
Default = 3799 messages.
Optional.

dae-dm-ip-address IP address The IP address, in dot notation, to receive DAE messages.


Default = value of Automatically set to the ip-address configured for the WiMAX
dae-coa-ip- node. Use for DM messages.
address Optional.

dae-dm-port Integer (1024–65535) The port on which to receive DAE messages. Use for DM
Default =value of messages.
dae-coa-port Optional.

dae-coa-shared-secret String (1–255) The shared secret for CoA messages.


Default = value of secret Optional.
element

Service Controller 9.6.1-AAA October 12, 2012 Page 93


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

Table 34: client attributes (continued)

Attribute Value Description

dae-dm-shared-secret String (1–255) The shared secret for DM messages.


Default = value of Optional.
dae-coa-shared-secret

dae-retries Integer (0–5) The number of retries the RADIUS client should attempt when
Default = 0 sending a DAE message.
Optional.

dae-timeout Integer (1–15) The time, in seconds, the RADIUS client should wait for the
Default = 2 DAE Ack from the Server.
Optional.

ha-mode • dual-mode When set to dual-mode, indicates that the client is a


dual-mode HA. All other cases indicate that the client is not a
dual-mode HA.
Only applies if the client is a Home Agent (HA).

client-pool Defines a RADIUS client pool.


A RADIUS client pool defines a set of RADIUS clients that share the same shared
secret, vendor, model, and time zone. A RADIUS client pool enables quick
configuration of multiple RADIUS clients for a specified range of IP addresses.
When adding RADIUS client pools:
• One or more client-pool elements may be defined, up to a maximum of 512.
• The total number of client and client-pool elements combined can only be 4602.
• Each client-pool can only have one ip-range
• A RADIUS client's IP address can overlap with an IP range defined in a
RADIUS client pool.
• The RADIUS client's IP address must not overlap the RADIUS client pool's
primary IP address (the IP address specified in the ip-address element).
• The RADIUS client's IP address and associated configuration take precedence
in the case of an overlap with a RADIUS client pool.
• A RADIUS client pool’s primary IP address can overlap the IP range defined for
the pool.
• A RADIUS client pool’s primary IP address cannot be [Link]
• A RADIUS client pool’s ip-range cannot contain [Link]
• When clients are part of a RADIUS client pool, SNMP metrics are generated for
the pool, but not for individual RADIUS clients.
Note RADIUS client pools cannot be added to a group such as HA, PDSN, or
WiMAX.
Child element of system-elements.

Page 94 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

For example:
<system-elements>
<pdsn-group id="chicago-pdsn" rms-cluster-id="1"/>
<wimax-node-group id="dallas-wimax" rms-cluster-id="1"/>
<client id="omaha1" ip-address="[Link]" secret="MYSECRET"
vendor="CISCO" timezone="GMT"/>
<client-pool id="femtos1" ip-address="[Link]"
secret="FEMTOSECRET" vendor="SAMSUNG" timezone="GMT">
<ip-range>[Link]/24</ip-range>
</client-pool>
<client-pool id="femtos2" ip-address="[Link]"
secret="FEMTOSECRET" vendor="CISCO" timezone="GMT">
<ip-range>[Link]-[Link]</ip-range>
</client-pool>
</system-elements>

Table 35: client-pool attributes

Attribute Value Description

id String The name of the client-pool.


(1-255 This value must be unique among the IDs in [Link].
characters) Required.

ip-address IPv4 address A valid IPv4 address in dot notation.


This is the primary IP for the client pool.
Required.

secret String The shared secret string used by the client.


(1-255 Required.
characters)

vendor String The vendor name which matches an entry in the [Link] file.
(1-255 Required.
characters)

model String The model name.


(1-255 When present, it is paired with the vendor name and must match an entry
characters) in the [Link] file.
Optional.

timezone String The timezone in which the client runs.


(1-255 The typical value is GMT.
characters) Required.

Service Controller 9.6.1-AAA October 12, 2012 Page 95


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

ip-range Defines a range of IPv4 addresses for a RADIUS client pool.


Considerations:
• Each client-pool can only have one ip-range.
• A client-pool’s ip-range cannot overlap an ip-range from another client-pool.
• An ip-range cannot contain the IP address [Link]
The ip-range can have one of the following formats:
• CIDR notation
• Range with two dot notation values <ip-address>-<ip-address>
where
<ip-address> can be one of the following:
– [Link]
– 1.1.1
– 1.1
– 1
Child element of client-pool.
Examples:
<! - - CIDR notation>
<client-pool id="femtos1" ip-address="[Link]"
secret="FEMTOSECRET" vendor="SAMSUNG" timezone="GMT">
<ip-range>[Link]/24</ip-range>
</client-pool>
<! - - Range with two dot notation values>
<client-pool id="femtos2" ip-address="[Link]"
secret="FEMTOSECRET" vendor="CISCO" timezone="GMT">
<ip-range>[Link]-[Link]</ip-range>
</client-pool>

ha-group Defines an HA group for client systems.


One or more ha-group elements may be defined, up to a maximum of 256.
Child element of system-elements.
Optional.
For example:
<ha-group id="omahaG1">
<ha-client>omaha1</ha-client>
<ha-client skipcount="10">omaha2</ha-client>
</ha-group>

Page 96 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

Table 36: ha-group attribute and elements

Attributes/elements Value Description

id String The name of the HA group. This value must be unique among the IDs in
this file.
Attribute of ha-group.
Required.

ha-client String The name of a client system.


The name must match a previously defined client ID. One or more ha-client
tags may be listed. An ha-client may belong to multiple HA groups.
Child element of ha-group.
Optional.

skipcount Integer (0–254) Used for load balancing. For example, if skipcount=3, the specified HA
client receives every third request.
Attribute of ha-client.
Optional.

wimax-node-group Defines a WiMAX node group for client systems. One or more wimax-node-group
elements may be defined, up to a maximum of 64.
Child element of system-elements.
Optional.
For example:
<wimax-node-group id="dallas-wimax" rms-cluster-id=”1”/>
The node group may be associated to multiple RMS clusters. If so, use any of the
following formats:
<wimax-node-group id="dallas-wimax" rms-cluster-id=”1, 2, 3, 4” />
<wimax-node-group id="dallas-wimax" rms-cluster-id=”1-4” />
<wimax-node-group id="dallas-wimax" rms-cluster-id=”1-4, 6” />

Service Controller 9.6.1-AAA October 12, 2012 Page 97


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

Table 37: wimax-node-group attributes

Attribute Value Description

id String The name of the wimax-node-group element. This value must be


unique among the IDs in this file.
Required.

rms-cluster-id String The RMS cluster number for this group. This value must match a
0 to 254 cluster ID defined in the in [Link] file.
Comma separated list (1,2,3) To define multiple RMS clusters, type a list of comma delimited
cluster IDs, such as 1,2,3 or a range of cluster IDs, such as 0-3.
Range of IDs (1 to 4)
When identifying an RMS cluster range, use the format “0-3”; do
not use the format “3-0”.
Optional.

wimax-ha-group Defines a WiMAX HA group for client systems.


One or more wimax-ha-group elements may be defined, up to a maximum of 64.
Child element of system-elements.
Optional.
For example:
<wimax-ha-group id="betaH1">
<wimax-ha-client>dallas1</wimax-ha-client>
<wimax-ha-client>dallas2</wimax-ha-client>
</wimax-ha-group>

Table 38: wimax-ha-group attributes and elements

Attribute/element Value Description

id String The name of the wimax-ha-group element. This name can be used
to reference the group for purposes of the DHA.
Attribute of wimax-ha-group.
Required.

wimax-ha-client String The name of a client system. One or more distinct wimax-ha-client's
can be listed within one ha-group. One wimax-ha-client can belong
to multiple wimax-ha-groups
Child element of wimax-ha-group.
Optional.

Page 98 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

ldap-server Encloses the child element listed in Table 39 on page 100, containing
LDAP-specific connection information for the LDAP server(s). Changes to this
section require a full stop and restart of the RADIUS Server process (radiusd).
ldap-server is a required [Link] to a maximum of 10 instances may be
configured.
Child element of radintdal.
Note At least one instance of <ldap-server> must have the element
<query-name> set to “aaa-auth-query”.
The ldap-server tag has no attributes.
For example:
<ldap-server>
<query-name>aaa-auth-query</query-name>
<dn>cn=Directory Manager</dn>
<password>password</password>
<host host="host1">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<host host="host2">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<connection-pool
max-pool-size="100"
max-wait-time="500"/>
<port>389</port>
<base-dn>ou=domain,dc=mydomain,dc=com</base-dn>
<user-password>userPassword</user-password>
<db-attribute>deviceStatus</db-attribute>
<user-filter>uid=jsmith</user-filter>
<search-scope>0</search-scope>
<retry-interval>20</retry-interval>
<deref-alias>never</deref-alias>
</ldap-server>

Service Controller 9.6.1-AAA October 12, 2012 Page 99


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

Table 39: ldap-server child element

Element Value Description

query-name String Specifies whether <ldap-server> is configured for authentication ldap


queries or for retrieving ldap attributes.
• “aaa-auth-query”—set for authentication ldap query
• “mac-id-query”—set for retrieving ldap attributes
Required.

dn String The LDAP privileged user distinguished name.


Required.

password String The password for the LDAP distinguished name.


Required.

host String Encloses the attribute “host”, and the child element <timelimit> and
<retry>, and specifies an LDAP server to query. To specify additional
LDAP servers, add additional <host> elements.
The port can be optionally specified by using the following format:
hostname:port.
There can be a maximum of six host elements. For each failover host,
add a “host” attribute.
Child element of ldap-server.
Required.

host String The host name for the LDAP server.


Attribute of host.

timelimit Integer The timelimit, in milliseconds, for an LDAP server query.


Default = 3000 Child element of host.
Optional.

retry Integer The number attempts before failing over to the next LDAP server after the
(0-6) “timelimit” for an LDAP server query expires.
Default = 0 Child element of host.
Optional.

idle-timeout Integer The time, in seconds, a connection is allowed to remain idle before it is
(60-32000) closed.
Default=300 Child element of host.
Optional.

connection-pool — Defines settings for the connection pool the LDAP DAL uses to connect
to the LDAP Server. Encloses the attributes initial-pool-size,
max-pool-size, and max-wait-time.
There is a maximum of one connection-pool for each ldap-server section.
For more information about configuring a connection pool, see
"Configuring LDAP connection pooling" on page 116.
Child element of ldap-server.
Required.

Page 100 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

Table 39: ldap-server child element (continued)

Element Value Description

max-pool-size Integer The maximum size of the connection pool.


(value of Note Bridgewater Systems recommends against setting the
initial-pool-size-2048) max-pool-size to a value greater than the application’s number of
worker threads (such as radiusd or diaaaad).
Attribute of connection.
Required.

max-wait-time Integer The time, in milliseconds, that a request for an LDAP connection can wait
(1-10000) in the connection pool’s request queue.
Note max-wait-time is different from timelimit, which specifies the time,
in milliseconds, for an LDAP server query.
Attribute of connection-pool.
Required.

port Integer The LDAP port for the specified host(s). This value is overridden by any
Default = 389 port(s) specified in the host entry.
Child element of ldap-server.
Optional.

base-dn String The search starting point for the user-filter. For example,
ou={domain},dc=mydomain,dc=com. {domain} is replaced by the
RADIUS domain. This is a simple search and replace algorithm.
Note For subscribers with dual-mode devices, give base-dn a token
value and specify the domains in the accessReqPolicy file using
the authenticateDomain action modifier and in the TLSPolicy file
using the authenticateDomain and authorizeDomain action
modifiers. For example in [Link] or [Link]:
<base-dn>{domain}</base-dn>.
For more information on policy files, see "Configuring AAA policies" on
page 233. For information on [Link], see "Installing and
configuring Diameter" on page 133.
Child element of ldap-server.
Required.

user-password String The name of the password attribute used to authenticate a subscriber.
For example, userPassword searches for a field called userPassword to
find the password to use for authentication.
Child element of ldap-server.
Required.

db-attribute String The attribute to be retrieved from the LDAP server.


For each ldap-server element, add a maximum of five db-attribute child
element.
Child element of ldap-server.
Required when the element query-name is set to “mac-id-query”.

Service Controller 9.6.1-AAA October 12, 2012 Page 101


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

Table 39: ldap-server child element (continued)

Element Value Description

user-filter String The search query to authenticate a subscriber. For example,


(&(uid={loginname})(ntlRadiusStatus=Active)). {loginname} is replaced
by the RADIUS loginname. This is a simple search and replace
algorithm.
Child element of ldap-server.
Required.

search-scope • 0 The LDAP search scope:


• 1 • 0—search base-dn only
• 2 (Default) • 1—search one level below base-dn
• 2—search entire subtree starting at base-dn
Child element of ldap-server.
Optional.

retry-interval Integer The per thread retry interval, in seconds, to return to the primary LDAP
server.
Child element of ldap-server.
Required.

deref-alias • never (Default) Determines how aliases are handled during a search. Valid values for
• always deref-alias are:
• searching • never—aliases are never de-referenced by the LDAP server
• finding • always—aliases are de-referenced during phase one, when locating
the base object of the search
• searching—aliases are de-referenced during the second phase
• finding—aliases are de-referenced during both phases of the search
Child element of ldap-server.
Optional.

Page 102 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

service Defines service parameters and authorization information for a specific network
vendor.
There may be one or more service elements, up to a maximum of 256.
Each service element may enclose one or more optional vendor-attribute child
element.
Child element of radintdal.
For example:
<service id="fa_service">
<vendor-attribute ... />
<vendor-attribute ... />
</service>

Table 40: service attributes

Attribute Value Description

id String (1–-255 The name of the service. This must be unique among all IDs in this file.
characters) Required.

vendor-attribute Contains a list of static or ldap attributes to return for the vendor. All attributes are
required unless indicated.
One or more vendor-attribute elements may be defined, up to a maximum of 64.
Child element of service.
For example:
<vendor-attribute vendor="SHASTA">
<ldap-attribute name="3GPP2-HA-IP-Addr" ldapvalue="DHAIP"
defaultvalue=”#GmipHAIPAddr,dynamicHAPolicy”>
<exception-value>[Link]</exception-value>
<exception-value>[Link]</exception-value>
</ldap-attribute>
</vendor-attribute>

Service Controller 9.6.1-AAA October 12, 2012 Page 103


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

Table 41: vendor-attribute and ldap-attribute elements and attributes

Attribute or
Value Description
element

vendor • COMMON The vendor name. This value must match an entry in the [Link] (case-sensitive)
• String or the string 'COMMON'.
One or more services can be listed, each with zero or more static and/or LDAP
attributes. Attributes listed under the COMMON vendor are applied to any subscriber
whose specific vendor is not explicitly listed under the service or whose vendor does
not also contain that particular RADIUS attribute.
Attribute of vendor-attribute.
Required.

static-attribute String A hard-coded RADIUS attribute to return for a specific vendor.


You can also configure the Service Controller to generate a random value for string
type attributes. For more information, see "Configuring attribute generation in
[Link]" on page 69.
One or more static-attribute elements may be defined, up to a maximum of 128.
Child element of vendor-attribute.
Optional.

name String The RADIUS attribute name, found in the vendor dictionary.

value String The RADIUS attribute value.


Define sub AVPs in this field. The sub AVPs correspond to the AVP name specified in
the “name” attribute.
The “value” attribute can have the following syntax:
• no sub AVPs: <static-attribute name="attributeX” value="getvalue"/>
• one sub AVP: <static-attribute name="attributeY” value="1030=20"/>
• multiple sub AVPs: <static-attribute name="attributeZ” value="1028=30 |
1029=string"/>
Child element of static-attribute.
Note Multiple sub AVPs need to be separated by a “|” character.

ldap-attribute — Supports nested attribute-value pairs. <ldap-attribute> specifies an attribute stored in


LDAP whose value is returned as a vendor's RADIUS or Diameter attribute.
To send the MDN in the SIP Notify message, this parameter must be configured to
retrieve the MDN and place it in the Class Attribute.
Note Changes to attributes in this section require a full stop and start of RADIUS or
Diameter.
One or more ldap-attribute elements may be defined, up to a maximum of 128.
Child element of vendor-attribute.
Optional.

name String The RADIUS attribute containing the value retrieved. Define sub AVPs in the
ldap-value attribute.
Note For Sip Server Interworking, this parameter must be configured as “Class”. This
maps to the AcctRecordAttribute in the [Link] file.
Attribute of ldap-attribute.

Page 104 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

Table 41: vendor-attribute and ldap-attribute elements and attributes (continued)

Attribute or
Value Description
element

ldapvalue String The name of the LDAP attributes to retrieve. Define sub AVPs in this field. The sub
AVPs correspond to the AVP name specified in the “name” attribute.
The ldapvalue attribute can have the following syntax:
• no sub AVPs: <ldap-attribute name="attributeX” ldapvalue="getvalue"/>
• one sub AVP: <ldap-attribute name="attributeY” ldapvalue="1022={getvalue}"/>
• multiple sub AVP: <ldap-attribute name="attributeZ” ldapvalue="1023={getZ} |
1026=stated"/>
Separate multiple sub AVPs by a “|” character and at least one value enclosed with
curly braces {}.
Note For Sip Server Interworking, this parameter must be configured as: mdn.
Attribute of ldap-attribute.

defaultvalue String A default attribute value that is returned if an ldap-attribute is not found in an LDAP
search or if the ldap-attribute matches a configured exception-value. The defaultvalue
must be defined if exception values are specified for an ldap-attribute. The
defaultvalue string is limited to 253 characters.
Attribute of ldap-attribute.
Optional.

exception-value String When an exception-value matches the stored ldap-value, the configured default value
is returned as the RADIUS attribute. If exception values are specified, then a
defaultvalue must be defined.
The exception-value string is limited to 253 characters. A maximum of 5 exception
values (no duplicates) can be configured for each ldap-attribute. A maximum of 640
exception values can be configured in a [Link] file.
Make sure that attribute names are mapped statically or dynamically, not both.
Configuring an attribute name in static-attribute and ldap-attribute within the same
service results in two values being returned for a single attribute and can cause
inconsistent behavior.
Child element of ldap-attribute.
Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 105


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

dal-cache Encloses attributes to enable or disable LDAP DAL query caching, and establish
settings for the cache. If dal-cache and is missing from [Link], LDAP DAL
query caching is disabled. For information about configuring LDAP DAL query
caching, see "Configuring LDAP DAL Query Caching" on page 112.
Note After installing the LDAP DAL cache, check the attribute values to make
sure they are optimal for your deployment.
Restart RADIUS for changes to dal-cache to take effect.
Note dal-cache is only available for RADIUS.
dal-cache encloses the following attributes:
• enabled
• max-entries
• max-memory
• time-to-live
Child element of radintdal.
Optional.
For example:
<dal-cache enabled="y" max-entries="10" max-memory="1000000"
time-to-live="30"/>

Table 42: dal-cache attributes

Attribute Value Description

enabled • y Enables or disables LDAP DAL query caching.


• n (Default) Values:
• y: enables LDAP DAL query caching
• n: disables LDAP DAL query caching
Required if dal-cache is added to [Link].

max-entries Integer The maximum number of entries stored in the cache. This should be
Default =4096 calculated as the average number of authentication requests expected
during the time-to-live plus one or two standard deviations.
Range= 0-1000000 (1
million entries. The If max-entries is reached and a new LDAP query needs to be cached,
cache entry overhead the LDAP DAL purges the oldest entry out of the cache and stores the
consumes around 200 new query and its results in the cache.
MB) Optional.

max-memory Integer The upper bound for the total memory consumption of the cache,
Default =10000000 represented as the number of bytes. The max-memory does not include
the overhead for each cache entry
Range= 0-1000000000
(1 GB) If a max-memory value is reached and a new LDAP query needs to be
cached, the LDAP DAL removes the oldest cache entries until there is
enough space to add the new query and its results in the cache.
Optional.

Page 106 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

Table 42: dal-cache attributes (continued)

Attribute Value Description

time-to-live Integer The time, in seconds, an entry remains before it is aged out. This should
Default= 30 be calculated as the time for a standard EAP authentication plus one or
two standard deviations to account for outliers.
Range= 0-100000000 (3
years) If the RADIUS server makes a DAL query and the LDAP DAL finds the
query is cached but has reached the time-to-live:
• the LDAP DAL passes the LDAP query to the LDAP database
• the LDAP database returns the query results back to the LDAP DAL
• the LDAP DAL replaces the old query with the new one if the LDAP
query was successful
Note Any update to the LDAP database is not reflected in the cache
until the time-to-live expires for an entry.
Optional.

Example <radintdal>
[Link] file <system-elements>
<pdsn-group id="chicago-pdsn" rms-cluster-id="1"/>
<wimax-node-group id="dallas-wimax" rms-cluster-id="1" />
<client id="omaha1"
ip-address="[Link]"
secret="MYSECRET"
vendor="CISCO"
timezone="GMT"/>
<client id="omaha2"
ip-address="[Link]"
secret="MYSECRET"
vendor="STARENT"
timezone="GMT"/>
<clientid="chicago1"
ip-address="[Link]"
secret="MYSECRET"
vendor="NORTEL"
timezone="GMT"
pdsn-group="chicago-pdsn"/>
<client id="chicago2"
ip-address="[Link]"
secret="MYSECRET"
vendor="NORTEL"
timezone="GMT"
pdsn-group="chicago-pdsn"/>
<client id="dallas1"
ip-address="[Link]"

Service Controller 9.6.1-AAA October 12, 2012 Page 107


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

secret="MYSECRET"
vendor="NORTEL"
timezone="GMT"
wimax-node-group="dallas-wimax"
ha-root-key-lifetime="86400" />
<client id="dallas2"
ip-address="[Link]"
secret="MYSECRET"
vendor="CISCO"
timezone="GMT"
wimax-node-group="dallas-wimax"
ha-root-key-lifetime="86400" />
<client id="dallas3"
ip-address="[Link]"
secret="MYSECRET" vendor="STARENT"
timezone="GMT"
wimax-node-group="dallas-wimax"
dae-enabled="true"
dae-coa-ip-address="[Link]"
dae-coa-port="2000"
dae-coa-shared-secret="DAESECRET"
dae-dm-ip-address="[Link]"
dae-dm-port="2000"
dae-dm-shared-secret="DAESECRET"
dae-timeout="5"
dae-retries="0"/>
<ha-group id="omahaG1">
<ha-client>omaha1</ha-client>
<ha-client skipcount="10">omaha2</ha-client>
</ha-group>
<ha-group id="omahaG2">
<ha-client skipcount="1">omaha1</ha-client>
<ha-client skipcount="2">omaha2</ha-client>
</ha-group>
<wimax-ha-group id="betaH1">
<wimax-ha-client>dallas1</wimax-ha-client>
<wimax-ha-client>dallas2</wimax-ha-client>
</wimax-ha-group>
</system-elements>
<ldap-server>
<dn>cn=Directory Manager</dn>
<password>password</password>
<host host="host1">

Page 108 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<host host="host2">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<connection-pool
max-pool-size="100"
max-wait-time="500"/>
<port>389</port>
<base-dn>ou=domain,dc=mydomain,dc=com</base-dn>
<user-password>userPassword</user-password>
<user-filter>uid=jsmith</user-filter>
<search-scope>2</search-scope>
<retry-interval>20</retry-interval>
<deref-alias>never</deref-alias>
</ldap-server>
<service id="fa_service">
<vendor-attribute vendor="STARENT">
<static-attribute name="Idle-Timeout" value="60"/>
</vendor-attribute>
<vendor-attribute vendor="NORTEL"/>
</service>
<service id="ha_service">
<vendor-attribute vendor="COMMON">
<static-attribute name="idle-timeout" value="hard-coded-value"/>
<ldap-attribute name="serviceprofile" ldapvalue="HotLineURL"/>
</vendor-attribute>
<vendor-attribute vendor="STARENT">
<static-attribute name="idle-timeout" value="12"/>
</vendor-attribute>
</service>
<service id="defaultDHA">
<vendor-attribute vendor="SHASTA">
<ldap-attribute name="3GPP2-HA-IP-Addr" ldapvalue="DHAIP"
defaultvalue=”#GmipHAIPAddr,dynamicHAPolicy”>
<exception-value>[Link]</exception-value>
<exception-value>[Link]</exception-value>
</ldap-attribute>
</vendor-attribute>
</service>
<dal-cache enabled="y" max-entries="4096" max-memory="1000000"

Service Controller 9.6.1-AAA October 12, 2012 Page 109


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

time-to-live="30"/>
</radintdal>

Managing the memory map file


This section provides procedures for managing the memory map file, including:
• To initialize the memory map file
• To load the memory map file
• To configure the RADIUS startup script

To initialize the memory map file


The ldapdalinit utility, located in the /opt/aaasc/dal directory, initializes the LDAP
DAL memory map file.
To run the utility from the command line:
1 Log in as root:
su - root
2 Run a Unix C shell and source the startup file:
csh
source /opt/aaasc/.cshrc
3 Run the utility:
/opt/aaasc/dal/ldapdalinit -f MMAP_filename
where
MMAP_filename is the name and location of the shared memory map file
Table 43 lists the command line options.

Table 43: ldapdalinit utility options

Option Description

-f MMAP_filename The name and location of the memory map file to


create.

-h Displays the usage for this utility.

-v Displays the version of the utility.

For example, to create a memory map file, type:


/opt/aaasc/dal/ldapdalinit -f /opt/aaasc/config/[Link]
If the memory map file was created successfully the utility returns:
FileDal cache successfully initialized.

Page 110 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

To load the memory map file


The ldapdalload utility, located in the /opt/aaasc/dal directory, loads the contents of
the [Link] file into the LDAP DAL memory map file created with the
ldapdalinit utility.
To run the utility from the command line, as the aaasc user:
/opt/aaasc/dal/ldapdalload -f MMAP_filename -x
XML_filename
where
MMAP_filename is the full file name and location of the memory map file
created with the ldapdalinit utility
XML_filename is the name and location of the [Link] configuration
file
Table 44 lists the command line options.

Table 44: ldapdalload utility options

Option Description

-V XML_filename Validates the format of the [Link] file.

-f MMAP_filename The name and location of the memory map file created with the
ldapdalinit utility.

-x XML_filename The name and location of the [Link] file. By default, this
file is located in the /opt/aaasc/config directory.

-h Displays the usage for this utility.

-v Displays the version of this utility.

-d Displays debugging information for this utility.

For example, to create a memory cache file, type:


/opt/aaasc/dal/ldapdalload -f /opt/aaasc/config/radius/
[Link] -x /opt/aaasc/config/[Link]
If the memory map file was created successfully, no error messages are returned.
Note The ldapdalload utility does not update the memory map file and displays
an error if a client’s IPv6 address or HL prefix is not unique in the
[Link] file, or if a client’s mip6-ha-protocol-capability contains an
invalid value.

To configure the RADIUS startup script


Configure the /opt/aaasc/config/radius/wsradius startup script to point to the
memory map file (.mmap). For more information, see "RADIUS Server startup
options" on page 2.

Service Controller 9.6.1-AAA October 12, 2012 Page 111


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

Configuring LDAP DAL Query Caching


This section provides an overview and configuration information for LDAP DAL
Query Caching, including:
• LDAP DAL Query Caching overview
• To install LDAP DAL Query Caching
• To enable the LDAP DAL query cache
• To collect statistics about LDAP DAL Query Caching
• LDAP DAL query caching log messages
Note LDAP Query Caching is only available for RADIUS.

LDAP DAL Query Caching overview


The LDAP DAL shared library provides data caching to reduce the number of
search queries from the RADIUS server to the LDAP database.
Query caching is useful when using the PreAuthorize policy action and a multi-leg
authentication method such as EAP-TLS to authenticate a subscriber. When the
LDAP DAL shared library is enabled and an LDAP search query occurs, the query
and its results are cached for later use. Similar LDAP search queries can use the
cached data (if the data is not expired).
Note The higher the number of entries and the longer the time to live for each
entry, the less efficient the search becomes when the cache is full.
Configure this in the [Link] file. For more information, see
"dal-cache" on page 106.
For more information about the interface between the Service Controller and the
LDAP database, see Figure 14 on page 88.
Figure 15 on page 113 illustrates the basic message flow for an Access-Request
with LDAP DAL query caching enabled.

Page 112 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

Figure 15: LDAP DAL query caching message flow

6HUYLFH&RQWUROOHU
/'$3'$/

$FFHVV1RGH 5$',86 /'$3'$/ /'$3


8VHU FDFKH
$61+$ 6HUYHU OLEUDU\ 'DWDEDVH







1 A subscriber logs on to the network.


2 The Access Node sends an Access-Request to the RADIUS Server.
3 The RADIUS Server makes a DAL query.
4 The LDAP DAL looks in the cache to see if there is any data cached for the
LDAP query.
5 If the LDAP DAL does not find a cache entry for the LDAP query, or the cached
entry has exceeded the configured time to live, the LDAP DAL queries the
LDAP database and stores the query data in the cache.

To install LDAP DAL Query Caching


Install BWSdal and specify an LDAP database.
For more information about installing BWSdal, see the Bridgewater Installation
Reference Guide.

To enable the LDAP DAL query cache


1 Navigate to /opt/aaasc/config and open [Link].
2 In [Link], add the dal-cache element as a child element of radintdal.
Configure the dal-cache attributes, to enable the LDAP DAL query cache and
establish cache settings.
For example:
<dal-cache enabled="y" max-entries="10" max-memory="1000000"
time-to-live="30"/>
For more information about dal-cache, see "dal-cache" on page 106.
Note Restart RADIUS for changes to dal-cache to take effect.

Service Controller 9.6.1-AAA October 12, 2012 Page 113


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

To collect statistics about LDAP DAL Query Caching


1 Use the dalstats tool, located in /opt/aaasc/dal to confirm cache operation and
for cache tuning. Table 45 lists the dalstats options.

Table 45: dalstats Tool options

Usage Description

dalstats -p <PID> Process ID of the application, such as RADIUS, that is


using the DAL.
RADIUS uses syslog to display the cache statistics.

dalstats -h Print this usage screen

Provide the RADIUS server’s PID as a command line argument to signal


RADIUS to log cache statistics. For example:
/opt/aaasc/dal/dalstats -p `pgrep radiusd`
2 Check RADSYS log 2406 for the following cache statistics:
Oct 5 15:17:53 kansparc5126 radiusd[6709]: [ID 549945
[Link]] INFO RADSYS(2406) LDAPSearch Size: 10000000,
Used: 2948, Requests: 42, Fetch: 4, Found: 38, Busy: 0,
Error: 0, Replace: 0, Remove: 0, Not Cached: 0
Table 46 lists and describes the cache statistics.

Table 46: cache statistics

Statistic Description

LDAPSearch Size Size of the cache, in bytes.

Used Amount of bytes used by the cache.

Requests Number of searches the DAL has made in the cache.

Fetch Number of times the cache indicated to the DAL to query


the LDAP database.

Found Number of times the DAL found an entry in the cache.

Busy Number of times the cache was in a busy state.


If the cache is in a busy state the DAL queries the LDAP
database.

Error Number of errors reported by the cache.


The DAL queries the LDAP database and even if the
cache reports an error, the DAL returns the query result to
RADIUS.

Replace Number of instances when the number of cache entries


reaches max-entries and the cache replaces an already
existing entry with a new one.

Page 114 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

Table 46: cache statistics (continued)

Statistic Description

Remove Number of instances when there is not enough memory in


the cache (reached max-memory) and an old cache entry
is removed to make space for a new entry.
This occurs when max-memory has been reached for an
entry and a new entry needs to be added.

Not Cached Number of instances where the cache entry's memory size
is larger than the configured max-memory, and thus is not
cached.

LDAP DAL query caching log messages


LDAP DAL query caching logs the following messages:

Table 47: LDAP DAL query caching log messages

ID Message Priority Description

— LDAP DAL query caching is — Indicates LDAP DAL query caching is


enabled. enabled.
This messages is logged during
RADIUS startup.

2403 DAL statistics is not ERR If a DAL library that does not support
supported by the loaded DAL statistics is loaded by the
DAL library. RADIUS server and an attempt is
made to execute the dalstats utility to
signal the RADIUS server to log
statistics, this log appears.

2403 DAL statistics is not ERR If LDAP DAL query caching is


supported if LDAP DAL disabled and an attempt is made to
caching is disabled. execute the dalstats utility to signal
the RADIUS server to log statistics,
this log appears.

Service Controller 9.6.1-AAA October 12, 2012 Page 115


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

Configuring LDAP connection pooling


A connection pool enables different application threads to share connections to the
LDAP database, which results in fewer open connections to the LDAP database.
Connection pooling is helpful for device and subscriber authentication that use
EAP-TLS and EAP-TTLS, which require multiple exchanges between the Service
Controller and the LDAP database.
For details about configuring LDAP connection pooling, see "ldap-server" on page
99.
Figure 16 illustrates the initialization of a connection pool.
Figure 16: Connection pool initialization

6HUYLFH&RQWUROOHU

UDGLXVG UDGOGDSGDO[PO

GLDDDDG GLDOGDSGDO[PO

UDGLXVGGLDDDDG
/'$3'$/  &RQQHFWLRQ3RRO
LQWHUIDFH

/'$3
GDWDEDVH

1 The application (radiusd/diaaaad) reads the [Link] or [Link]


file to find the settings for the connection pool.
2 The application passes the connection pool settings to the LDAP DAL.
3 The LDAP DAL requests to create a connection pool.
4 The LDAP DAL opens connections to the LDAP Database.
The LDAP DAL returns connections to the connection pool when it is done with
its search operation.

Page 116 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

Configuring remote LDAP authentication


Configure remote LDAP subscriber authentication by defining the LDAP target in
the [Link] file and defining policies in the accessReqPolicy file.
For information, see "Proxy target configuration considerations" on page 370.
Configure these attributes for an LDAPServer element:
• TargetName
• TargetHost
• AuthenticationPort
• RequestTimeout
• MaxRetries (optional, default is 0)
• DNPrefix
Configure these attributes for an LDAPServerGroup element:
• GroupName
• Failover (default is "Y")
• LoadSharing (default is "Y")
• LDAPServer
Note An LDAP server does not require a shared secret, nor does it define an
accounting port.
An LDAP group does not define the MaxConcurrentLockouts and
DynamicUnlock parameters.
For example, if LDAPServer1 in the [Link] file has its DNPrefix parameter
defined as “uid”. johndoe@[Link] requests to be authenticated
using LDAP. The start of the DN string is in the form: “uid=johndoe, … “

To define subscriber policies for remote LDAP subscribers


The dnSearchBase action modifier enables an administrator to map a subscriber’s
loginname to an LDAP directory structure. It defines how the DN string is
constructed by RADIUS and sent to the LDAP target.
An example of a policy configured in the accessRequestPolicy file is:
User-Name StartsWithCI joe ProxyAA target=LDAPServer1
dnSearchBase=”cn=managers,ou=canada,o=[Link]”
---ProxyAA target=LDAPServer1
dnSearchBase=”g=sales,ou=canada,o=[Link]
An alternative to using the dnSearchBase action-modifier is the
dnSearchBaseRegExp action-modifier. This action-modifier enables an
administrator to define a regular expression to build the DN string.

Service Controller 9.6.1-AAA October 12, 2012 Page 117


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

For example:
--- ProxyAA target=LDAPServer1 dnSearchBaseRegExp=”s/
user@(.*)/cn=submanagers,cn=managers,ou=people,o=$
{1}”
where
the leading “s” means “substitute” and is a required parameter.
“/” is a delimiter for separating fields. The first occurring “/” indicates the
start of the first field (the search field) and the second “/” indicates the start
of the second field which is the replacement string used to build the DN.
() indicates a value to save to the first regular expression variable defined
by “${1}”.
“.*” within the parentheses indicates 0 or more of any character; where “.” is
any character and “*” is 0 or more.
An optional target action-modifier called dnPrefix is configurable in the
accessReqPolicy file for the ProxyAA action. RADIUS uses the dnPrefix to
construct the DN string. As an example:
--- ProxyAA target=LDAPServer1
dnSearchBase=”cn=submanagers,cn=managers,ou=people,o=abc.c
om”
dnPrefix=cn
The dnPrefix target action-modifier overrides the DNPrefix XML parameter
specified in the [Link] file for the referenced LDAP target.
An organization may deploy an LDAP server so that one organizational hierarchy
may use a dnPrefix value that differs from the dnPrefix value used in another
organizational branch. In such cases, it is desirable to set up policy rules to reflect
this situation.
This enables the administrator to determine which dnPrefix to use based on the
location of its subscribers on the LDAP server. For example, subscribers under the
[Link] organization may be modeled on the LDAP server to use a
dnPrefix of value “uid”.
Subscribers under the [Link] organization may be modeled to
use the dnPrefix value of “cn”. An administrator can setup policy rules to handle
these types of situations. As an example:
User-Name EndsWithCI [Link] ProxyAA
target=LDAPServer1
dnSearchBase=”g=sales,ou=canada,o=[Link]” dnPrefix=uid
User-Name EndsWithCI [Link] ProxyAA
target=LDAPServer1
dnSearchBase=”g=support,ou=canada,o=[Link]” dnPrefix=cn
If, however, all subscribers in all branches of the LDAP server use the same
dnPrefix value, it is sufficient to exclude the dnPrefix action-modifier in any policy
rule that references this LDAP target. The value specified in the DNPrefix for the
LDAP entry in the [Link] file is used to construct the start of the DN string.

Page 118 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 3 Configuring LDAP for RADIUS access

For authorization purposes, the subscriber or a representative user must be


modeled in the Profile Database to deliver authorization information for the
subscriber authenticated by the remote LDAP directory server. For a representative
user, the BillingIDLookup parameter in [Link] must be set to ‘N’.
For example, johndoe modeled in the Profile Database:
User-Name EndsWithCI [Link] ProxyAA
target=LDAPServer1
authorizeDomain=[Link]
If the ‘authorizeLoginName’ action-modifier is not specified, the subscriber's login
name is used for authorization, johndoe in this example.
A representative user may be used for a group of subscribers that are not modeled
in the Profile Database. For example:
User-Name EndsWithCI [Link] ProxyAA
target=LDAPServer1
authorizeLoginName=repuser authorizeDomain=[Link]

Configuring the LDAP secondary shared secret


The Service Controller can process RADIUS messages from a client using a
secondary shared secret if the primary shared secret fails. Each client, including the
Representative RADIUS client, must support two shared secrets to establish a
security association with the Service Controller.
This functionality is only available for LDAP deployments of the Service Controller.
The Service Controller compares authentication requests from clients with the
values stored in the associated LDAP database.
This feature supports 802.1X RADIUS authentication using PEAP v0 with
MSCHAPv2.

Access-Request handling
Upon receiving an Access-Request, the Service Controller uses the primary shared
secret to validate the Message-Authenticator attribute. If the Service Controller
cannot validate the attribute with the primary shared secret, it generates a notice
message and uses the secondary shared secret.
If the Service Controller can validate the attribute, it uses the valid shared secret to
compute the Message-Authenticator attribute, and returns the attribute with the
Access-Challenge/Accept/Reject message to the client.
If the Service Controller cannot validate the attribute with the primary or secondary
shared secret, the Service Controller drops the request.
Note RADIUS does not validate the Authenticator field in Access-Request
messages.
If the Message-Authenticator attribute is not present in the Access-Request
message, the Service Controller processes the request and returns a response to
the client without a Message-Authenticator attribute.

Service Controller 9.6.1-AAA October 12, 2012 Page 119


Chapter 3 Configuring LDAP for RADIUS access Network Access Guide

Accounting-Request handling
Upon receiving an Accounting-Request, the Service Controller uses the primary
shared secret to validate the Authenticator field. If the Service Controller cannot
validate the field, it uses the secondary shared secret. If the Service Controller can
validate the field, and (optionally) the Message-Authenticator attribute, it uses the
valid shared secret to compute the Authenticator field in the Account-Ack message
that it returns to the client.
If the Service Controller cannot validate the Authenticator field, with the primary or
secondary shared secret, the Service Controller drops the request.

Error handling
If the Message-Authenticator attribute validation fails or If the Authenticator field
validation fails, the Service Controller generates a NTCE level syslog message
indicating the secondary shared secret is being used. This message is throttled
over a 60-second period.

To provision a RADIUS client with two shared secrets


RADIUS Clients can be configured with an optional secondary shared secret with
XML attribute name, secret2.
For example, client1 can be provisioned as:
<client id="client1" ip-address="[Link]"
secret="TESTSECRET" vendor="STARENT" timezone="GMT"
pdsn-group="pdsngroup0"/>
or
<client id="client1" ip-address="[Link]"
secret="TESTSECRET" secret2=”SECONDSECRET”
vendor="STARENT" timezone="GMT" pdsn-group="pdsngroup0"/>
1 Add a RADIUS client, with a primary and secondary shared secret, to the
[Link] file.
Note Installations that use [Link] require an entry for the
representative client (IP=[Link]) that includes two shared
secrets.
2 Save the changes.
3 Load the XML file into the configured memory map file, as described in "To load
the memory map file" on page 111.
4 Restart or send a HUP signal to the radiusd process.
The Service Controller loads the RADIUS client with the primary and secondary
shared secrets.

Page 120 October 12, 2012 Service Controller 9.6.1-AAA


Diameter overview

4
Chapter 4
Chapter

This chapter provides an overview of Diameter.


This topics are:
• About Diameter
• Diameter interface components
• Comparison of Diameter and RADIUS capabilities
• Combined Diameter and RADIUS interfaces
• Diameter message format
• Diameter operation

Service Controller 9.6.1-AAA October 12, 2012 Page 121


Chapter 4 Diameter overview Network Access Guide

About Diameter
Diameter is an extensible protocol derived from the RADIUS protocol and defined
by RFC 3588. It provides AAA functionality for network access and IP mobility
applications.
The Diameter protocol uses standard attributes and message sequences that
enable a single server to handle policies for many services. It is used, for example,
by the IP Multi-media subsystem (IMS) and by prepaid billing for the Multi-media
Messaging Service (MMS).

Diameter interface components


The Diameter interface consists of:
• Bridgewater Diameter Stack
• Diameter AAA application

Bridgewater Diameter Stack


The Bridgewater Diameter Stack defines the minimum requirements for the AAA
protocol—including header, connections, security extensions, routing, mandatory
commands, and Attribute Value Pairs (AVPs).

Diameter AAA application


The Diameter AAA application provides:
• additional AAA commands and AVPs
• subscriber authentication using EAP-TLS or EAP-TTLS with an inner identity
using MSCHAPv2
• reauthentication
• mobile IP keys, subscriber profiles, QoS, and HA IP addresses to ASN
gateways
• connection to Profile Database or LDAP repository
• accounting support
With the Diameter AAA application:
• a subscriber can use the same subscriber name and password across all
access networks
• subscriber data can be managed in a single profile repository
• system-wide attributes can be applied for session timeout and idle timeouts

Page 122 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 4 Diameter overview

Comparison of Diameter and RADIUS capabilities


Table 48 lists the differences between Diameter and RADIUS protocols.

Table 48: Comparison of the Diameter and RADIUS protocols

Item Diameter RADIUS

Transport protocol • Connection-oriented protocols (TCP and SCTP) • Connectionless protocol (UDP)

Peer discovery • Static configuration • Static configuration

Capabilities negotiation • Negotiate supported applications, capabilities, • Not supported


and security preferences

Server initiated • Peer to peer—re-authentication message and • Supported only if the RADIUS client
message session termination. and server support dynamic
• A server can send unsolicited messages to a authorization extensions.
client. • RADIUS is a client/server protocol that
requires the client to initiate a request.

Agent support • Relay, proxy, redirect, and translate • Implicit: the agent behaviors might be
implemented on a RADIUS Server

Security • Hop-to-hop • Hop-to-hop


• End-to-end: information is in the clear only at
trusted end points.
Unprotected AVPs may be modified in transit by
intermediate proxy servers. Therefore, the
initiator must sign messages using public key
cryptography so that the end server can verify
that a proxy has not modified any protected
AVPs in the message.
• Uses EAP-TLS to authenticate devices
• Uses EAP-TTLS with an inner-identity of
MSCHAPv2 to authenticate subscribers
• supports CRL for EAP-TLS and EAP-TTLS

Stateful and Stateless • Stateful • Stateless


support Resource allocation decisions are based on the Each request is handled as if it is
context of earlier packets, as well as unrelated to any previous request.
administrator-defined rules. Decisions are not based on network
• Stateless behavior patterns.

Error notification • Fast recovery and response when a message • Not supported
goes missing

Vendor-specific support • Vendor-specific attributes • Vendor-specific attributes


• Vendor-specific messages

Address space for AVPs • 32-bit • 8-bit


and identifiers This reduces the likelihood that information is
fragmented across many AVPs.

Maximum attribute data • 16,777,215 octets • 255 octets


size

Service Controller 9.6.1-AAA October 12, 2012 Page 123


Chapter 4 Diameter overview Network Access Guide

Table 48: Comparison of the Diameter and RADIUS protocols (continued)

Item Diameter RADIUS

Maximum packet size • Greater than 4 KB • Less than 4 KB

Combined Diameter and RADIUS interfaces


The Diameter AAA application and RADIUS interface, shown in Figure 17, can
either coexist on a single Service Controller, or reside on separate Service
Controllers.
Figure 17 illustrates the flow of messages in a Diameter configuration:
Figure 17: Service Controller with both Diameter and RADIUS interfaces

0RELOH $61 'LDPHWHU$$$ 5$',86 506


'DWDEDVH +$
GHYLFH *DWHZD\ $SSOLFDWLRQ 6HUYHU FOXVWHU



D

E
F
G


D
E
F









1 The mobile device sends an EAP message to the ASN gateway.


2 The ASN gateway and Diameter AAA application exchange messages to
authenticate the device and subscriber.
Up to eight Diameter-EAP-Request (DER) and Diameter-EAP-Answer (DEA)
messages are exchanged for EAP Phase I device authentication.
In addition, multiple DER and DEA messages are exchanged for EAP Phase II
subscriber authentication on the inner-identity.

Page 124 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 4 Diameter overview

3 The Diameter AAA application:


a retrieves the service and QoS attributes and allocates an HA IP address for
the session
b retrieves the HA-RK and the SPIs associated with the HA IP address
c creates a subscriber session in the RMS
d sends a DEA to the ASN gateway with the service and QoS attributes,
HA-RK, and SPIs
4 The ASN gateway sends a MIP Registration Request (RRQ) to the HA.
5 The HA sends a MIP authentication request, with the WiMAX-HA-IP-Address
and SPI, to the RADIUS Server.
6 The RADIUS Server:
a looks up the subscriber in the database
b looks up the HA session in the RMS
c sends a MIP authentication accept, with the HA-RK, MIP key, and
associated data, to the HA
7 The HA sends a MIP Registration Reply (RRP) to the ASN gateway.
8 The ASN gateway sends an EAP-Success message to the mobile device,
signalling that the session is established.
9 The subscriber accesses the features configured for the account.
10 The ASN gateway and Diameter AAA application exchange
Accounting-Request (ACR) and Accounting-Answer (ACA) messages
throughout the session.
11 The mobile device terminates the call.
12 The ASN gateway sends a Session-Termination-Request (STR) to the
Diameter AAA application.
13 The Diameter AAA application responds with a Session-Termination-Answer
(STA) to the ASN gateway.
14 The Diameter AAA application releases the resources for the session.
Note The Accounting Framework sends accounting information to a flat file
throughout the session.
For more information about the flow of messages in a Diameter configuration, see
"Diameter operation" on page 127.

Service Controller 9.6.1-AAA October 12, 2012 Page 125


Chapter 4 Diameter overview Network Access Guide

Diameter message format


A Diameter message consists of:
• a header—with a command code that identifies the intent of the message. The
values 0–255 are used for RADIUS backward compatibility, and are defined as
"RADIUS Packet Type Codes".
• one or more AVPs—with routing, security, capability, and AAA information
Table 49 lists the Diameter message types (commands) that are supported.

Table 49: Diameter message types (commands)

Command
Command Name Description Abbreviation
Code

Accounting-Request Transmits the accounting information to the home Diameter ACR 271
Server.

Accounting-Answer Confirms reception of an ACR. An ACA includes the ACA


Result-Code AVP.

Capabilities-Exchange- Exchanges information about local capabilities. CER 257


Request

Capabilities-Exchange- Confirms reception of a CER. CEA


Answer

Device-Watchdog- Tests the status of the transport layer during periods when DWR 280
Request no other traffic is exchanged between two peers.

Device-Watchdog- Answer Confirms reception of a DWA, to verify the transport layer DWA
connection.

Diameter-EAP- Request Sent by a Diameter node to initiate EAP. DER 268

Diameter-EAP- Answer Confirms reception of a DER. DEA

Disconnect-Peer -Request Sent by a Diameter node to inform a peer that it intends to DPR 282
disconnect the transport layer.

Disconnect-Peer- Answer Confirms reception of a DPR. This command contains an DPA


error if recently forwarded messages are likely to be in
transit.
The Diameter node which receives the DPA disconnects
the transport layer.

Session-Termination- Sent by an access device to terminate a session. STR 275


Request For information about using the
DIAMETER_USER_MOVED termination cause in a WiMAX
deployment, see the chapter “Configuring WiMAX” in the
Service Controller: WiMAX Guide

Session-Termination- Sent by the Diameter Server to confirm reception of a STR. STA


Answer After sending or receiving a STA, the Diameter Server
releases the resources for the session.

Page 126 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 4 Diameter overview

Table 49: Diameter message types (commands) (continued)

Command
Command Name Description Abbreviation
Code

Abort-Session- Request Sent by any server to the access device that is providing ASR 274
session service, to request that the session identified by the
Session-Id be stopped.

Abort-Session- Answer Sent in response to the ASR. The Result-Code AVP must ASA
be present, and indicates the disposition of the request.

Diameter operation
This section describes the operation of the Diameter AAA application. The topics
are:
• Startup, peer discovery, and connection confirmation
• Subscriber authentication
• Accounting collection
• Peer connection termination

Startup, peer discovery, and connection confirmation


At startup, the Diameter AAA application:
• connects with each Diameter node listed in its configuration file
• determines which applications each node supports by using a Capabilities
Exchange procedure
• loads the WiMAX Node Group network elements to retrieve the RMS cluster ID
assigned to the group
The initial exchange of CER and CEA messages establishes a connection between
an ASN Gateway and a Service Controller. The subsequent exchange of DWR and
DWA messages confirms the connection is intact.
The TCP connection between the client (ASN gateway) and Diameter AAA can be
initiated by either host. When the Service Controller initiates or verifies the
connection, the message flow, as shown below, is reversed.
1 The ASN gateway sends a CER to the Diameter AAA application. The
message includes the ASN gateway’s identity, capabilities, and security
preferences. The Diameter AAA application validates the message format and
the Host-IP-Address.
2 The Diameter AAA application responds with a CEA. The message includes the
Result-Code and the Diameter AAA application’s capability information.
3 Periodically, the ASN gateway sends a DWR to the Diameter AAA application
to verify that the connection is intact. The Diameter AAA application validates
the message.
4 The Diameter AAA application responds with a DWA to indicate that it is active.

Service Controller 9.6.1-AAA October 12, 2012 Page 127


Chapter 4 Diameter overview Network Access Guide

Subscriber authentication
Figure 18 summarizes the authentication process that is applied to a subscriber
who connects to the Diameter network.
Figure 18: subscriber authentication in a Diameter network

0RELOH $61 6HUYLFH&RQWUROOHU


'HYLFH *DWHZD\ 'LDPHWHU$$$DSSOLFDWLRQ

($37/6ZLWK;FHUWIRUGHYLFHDXWKHQWLFDWLRQ
($377/6ZLWK06&+$3YIRUVXEVFULEHUDXWKHQWLFDWLRQ

1 The Diameter AAA application authenticates the mobile device using EAP-TLS
with a X.509 certificate.
2 The Diameter AAA application authenticates the subscriber using EAP-TTLS
with MSCHAPv2. Figure 19 on page 128 shows the details of the authentication
process.
Figure 19: Details of EAP-TLS and EAP-TTLS (shaded) authentication

0RELOH $61 'LDPHWHU$$$


506
GHYLFH *DWHZD\ $SSOLFDWLRQ















D
E
F
G


1 The mobile device sends an EAP message to the ASN gateway.


2 The ASN gateway sends a DER to the Diameter AAA application. The
Diameter AAA application validates the message.
Note For the EAP-TTLS phase I, the DER indicates an anonymous identity.

Page 128 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 4 Diameter overview

3 The Diameter AAA application responds with a DEA containing an EAP ‘Start’
packet.
4 The ASN gateway sends the EAP ‘Start’ packet to the mobile device.
5 The mobile device responds with an EAP Client Hello packet.
6 The ASN gateway sends a DER with the EAP Client Hello packet to the
Diameter AAA application. The Diameter AAA application validates the
message.
7 The Diameter AAA application responds with a DEA. The message includes an
EAP Server Hello packet which contains the server certificate.
8 The ASN gateway sends the EAP Server Hello packet to the mobile device.
The mobile device validates the server certificate.
9 The mobile device sends an EAP ‘Finished’ packet containing the client
certificate to the ASN gateway.
10 The ASN gateway sends a DER containing the EAP ‘Finished’ packet to the
Diameter AAA application. The Diameter AAA application validates the
message format and makes sure that the certificate is not on the CRL.
11 The Diameter AAA application responds with a DEA containing the EAP
‘Finished’ packet to the ASN gateway.
12 The ASN gateway sends the EAP ‘Finished’ packet to the mobile device. The
mobile device validates the message.
13 The mobile device sends an EAP-Response to the ASN gateway.
Note: For the EAP-TTLS Phase II only, the EAP-Response contains the
authentication information: MSCHAPv2.
14 The ASN gateway sends a DER containing the EAP-Response to the Diameter
AAA application. The Diameter AAA application:
– validates the message
– retrieves the service and QoS attributes
– allocates the HA IP address
Note: For the EAP-TTLS Phase II only, the Diameter AAA application: obtains
the user credentials from the mobile device and validates them against
the user credentials in the database.
15 The Diameter AAA application:
a retrieves the HA-RK and SPIs
b derives the MIP-RK, MN-HA-CMIP4, MN-HA-PMIP4, and FA-RK using the
derived EMSK from the EAP-TTLS CMIPv4 authentication
c creates a WiMAX session with State = Reserved
d sends a DEA to the ASN gateway with EAP-Success, MIP-RK,
MN-HA-CMIP4, MN-HA-PMIP4, FA-RK, HA-IP-Address, AAA-Session-ID,
and Session-Lifetime
16 The ASN gateway sends an EAP-Success message to the mobile device,
signalling that the session is established.

Service Controller 9.6.1-AAA October 12, 2012 Page 129


Chapter 4 Diameter overview Network Access Guide

At this point the Service Controller is ready for an Accounting-Request Start from
the ASN gateway. For information about the creation and termination of accounting
session records, see "Accounting collection".

Accounting collection
Figure 20 shows the exchange of messages required to collect accounting
information after the authentication process described in "Subscriber
authentication" on page 128 and illustrated in Figure 19 on page 128.
Figure 20: AAA SC with RMS for WiMAX

$61 'LDPHWHU$$$
506
*DWHZD\ $SSOLFDWLRQ











1 The ASN gateway sends an ACR with the AVP Beginning-Session=1 that
signals the initial Acct-Start message. The Diameter AAA application validates
the message.
The AVP Acct-Multi-Session-ID contains the AAA-Session-ID that identifies the
WiMAX sessions to update in RMS. The AVP Acct-Multi-Session-ID maps the
pseudo identity to the real identity for use in the accounting records.
Start messages are sent at the beginning of a session, when a device exits idle
mode, or when a QOS parameter changes.
2 The Diameter AAA application responds with an ACA.
3 The Diameter AAA application updates the WiMAX RMS session to
State=InUse.
Note No RMS interaction occurs when the AVP Beginning-Session=0 is
present in the Acct-Start message.
4 The ASN gateway and Diameter AAA application may exchange interim
messages throughout the session.
5 The ASN gateway sends the AVP Session-Continue=0 to signal the final stop.
The AVP Acct-Multi-Session-ID contains the AAA-Session-ID that identifies the
WiMAX sessions to remove in RMS. The Diameter AAA application validates
the message format.

Page 130 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 4 Diameter overview

6 The Diameter AAA application responds with an ACA to the ASN gateway.
7 The ASN gateway sends an STR (Session-Termination-Request) message to
the Diameter AAA application.
8 The Diameter AAA application responds to the ASN gateway with an STA
(Session-Termination-Answer) message.
9 The Diameter AAA application removes the WiMAX session and releases the
resources associated with the session.
Note The Accounting Framework sends accounting information to a flat file
throughout the session.
For more information about RMS WiMAX HA sessions or RMS WiMAX subscriber
sessions, see the “Overview” chapter of the Service Controller: WiMAX Guide.

Peer connection termination


Figure 21 shows the exchange of messages when an ASN Gateway disconnects
from the Service Controller. The flow is reversed in cases where the Service
Controller terminates the connection.
Figure 21: Exchange of messages during peer disconnection

$61 6HUYLFH&RQWUROOHU
*DWHZD\ 'LDPHWHU$$$DSSOLFDWLRQ

'LVFRQQHFW3HHU5HTXHVW '35

9DOLGDWLRQ
'LVFRQQHFW3HHU$QVZHU '3$

7HUPLQDWHWKH7&3VHVVLRQ

1 The ASN gateway sends a DPR to the Diameter AAA application. The
message includes a Disconnect-Cause. The Diameter AAA application
validates the message format.
2 The Diameter AAA application responds with a DPA that includes a
Result-code. The TCP session is terminated and the associated resources are
made available.

Service Controller 9.6.1-AAA October 12, 2012 Page 131


Chapter 4 Diameter overview Network Access Guide

Page 132 October 12, 2012 Service Controller 9.6.1-AAA


Installing and configuring Diameter

5
Chapter 5
Chapter

This chapter provides information about configuring Diameter services on the


Service Controller.
The topics are:
• Diameter Service Controller overview
• Installing the Diameter software
• Configuring LDAP access for Diameter
• Configuring the Bridgewater Diameter Stack
• Configuring the Diameter AAA application
• Configuring a Diameter AAA application buffer
• Configuring Diameter dictionary support
• Configuring Diameter reauthentication
• Preventing network congestion for Diameter
• diaaaad command line options
• Configuring the RMS
• Starting and stopping the Diameter processes
• Diameter logging
• Diameter troubleshooting

Service Controller 9.6.1-AAA October 12, 2012 Page 133


Chapter 5 Installing and configuring Diameter Network Access Guide

Diameter Service Controller overview


The Diameter Service Controller provides two options for subscriber data access:
• Profile Database—supporting the full set of provisioning tools available from the
Service Manager GUI. For more information, see the Service Manager: Getting
Started Guide for AAA.
The Diameter Server connects to the Profile Database using the /opt/aaasc/
config/[Link] file. The same [Link] file is used by both Diameter and
RADIUS. For more information about [Link], see the description in the
section “"RADIUS subscriber data access" on page 33.
• LDAP Directory Server—supporting a limited set of provisioning tools. All
provisioning is done through the [Link] file. The Service Manager, User
Self Administration, User Self Registration, and provisioning APIs are not
supported by this option.
Installing and configuring the Diameter application involves:
• Installing the Diameter software
• Configuring LDAP access for Diameter
• Configuring the Bridgewater Diameter Stack
• Configuring the Diameter AAA application
• Configuring a Diameter AAA application buffer
• Configuring Diameter dictionary support
• Configuring Diameter reauthentication
• Configuring the RMS

Installing the Diameter software


This section describes how to install the Bridgewater Diameter Stack software and
the Diameter AAA application.

Prerequisites
The Diameter AAA application requires:
• A Profile Database or LDAP database
• Solaris 10
To display the release information for the Solaris operating system that is installed
on your server:
cat /etc/release

To determine the local IP address


If the IP address of the local Bridgewater Diameter Stack is not known:
ifconfig -a
Information similar to the following displays:

Page 134 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

bge0: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4>
mtu 1500 index 2 inet [Link] netmask ffffff00
broadcast [Link]
In this example, the IP address of the local Diameter Server is [Link].

To install the Diameter packages


Install the Diameter software as the root administrator. The Diameter-specific
packages are BWSwsdia and BWSwsaaa. The BWSwsdia package installs the
Bridgewater Diameter Stack software; the BWSwsaaa package installs the
Diameter AAA application.
For installation instructions, see the Bridgewater Installation Reference Guide.

Configuring LDAP access for Diameter


To configure LDAP access for Diameter, perform the following procedures:
• To configure [Link]
• To create the memory map file
• To load the memory map file
• To modify Diameter startup (diaaaa)

To configure [Link]
The Diameter and RADIUS memory map files, [Link] and [Link],
contain the same elements and attributes, with the following exceptions:
• For Diameter environments, configure the service element using the “id” and
“type” attributes. The “type” attribute must always contain the value
“DIAMETER”, which tells the system to use a Diameter ConnectionService. For
example:
<service id=”DEFAULT” type=”DIAMETER”>
• The dal-cache element is only available for RADIUS
For more information about the elements and attributes of the [Link] file,
see the section "Configure [Link]" on page 89.

To create the memory map file


Create the LDAP memory map file that is used only by the Diameter Server. Do the
following as root:
ldapdalinit -f /opt/aaasc/config/dia-aaa/[Link]
For more information, see "To initialize the memory map file" on page 110.

Service Controller 9.6.1-AAA October 12, 2012 Page 135


Chapter 5 Installing and configuring Diameter Network Access Guide

To load the memory map file


Load the memory map using the [Link] file:
ldapdalload -f /opt/aaasc/config/dia-aaa/[Link]
/opt/aaasc/config/dia-aaa/[Link]
For more information, see "To load the memory map file" on page 111.

To modify Diameter startup (diaaaa)


Edit the start-up line in /opt/aaasc/config/dia-aaa/diaaaa so that the system loads
the Diameter memory map file:
$PRODUCT_DIR/dia-aaa/diaaaad -t 10 -i <HA IP Address> -C
$PRODUCT_DIR/config -l 15 -c /opt/aaasc/config/dia-aaa/
[Link] >> $PRODUCT_DIR/logs/[Link]
The -i argument is optional. This argument specifies a Global HA IP address
that is statically allocated. The value of the HA IP address provided by the -i
command is always assigned to the HA-IP-MIP4 attribute in the Access-Accept
message.
The Diameter AAA application’s origin host and origin realm, and the Diameter
Server’s application port and IP address are set during the installation process. For
more information, see the Bridgewater Installation Reference Guide.
Changes made to /opt/aaasc/config/dia-aaa/diaaaa must also be made to /opt/
aaasc/vr/BWSwsaaa_<build date>/dia-aaa/start up/diaaaa. When "aaapkg add" is
used, the system copies the configuration from this location, making any changes to
/opt/aaasc/config/dia-aaa/diaaaa obsolete.

Example [Link] file


<radintdal mip-enabled="y">
<system-elements>
<wimax-node-group id="wimax-node-group1"
rms-cluster-id="0"/>
<client id="client.01"
ip-address="n.n.n.n" secret="TESTSECRET"
vendor="vendorA" timezone="GMT"
wimax-node-group="wimax-node-group1" skip-count="1"/>
<client id="client.02" ip-address="n.n.n.n"
secret="TESTSECRET" vendor="vendorB" timezone="GMT"
wimax-node-group="wimax-node-group1"
ha-root-key-lifetime="86400"/>
<wimax-ha-group id="wimax-ha-group1">
<wimax-ha-client>client.02</wimax-ha-client>
</wimax-ha-group>
</system-elements>
<ldap-server>
<dn>cn=Directory Manager</dn>
<password>mypassword</password>

Page 136 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

<host host="host1">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<host host="host2">
<timelimit>3000</timelimit>
<retry>1</retry>
</host>
<connection-pool
max-pool-size="100"
max-wait-time="500"/>
<base-dn>ou=People,o=ptt,o=customerpcs,
dc=bridgewatersys,dc=com</base-dn>
<user-password>radiusChapPassword</user-password>
<user-filter>(&amp;(uid={loginname})
(objectClass=spcs3guser))</user-filter>
<search-scope>2</search-scope>
<retry-interval>30</retry-interval>
<deref-alias>never</deref-alias>
</ldap-server>
<service id="DEFAULT" type=”DIAMETER”>
<vendor-attribute vendor="VendorS">
<static-attribute name="Reply-Message" value="Service
profile works with LDAP"/>
</vendor-attribute>
</service>
</radintdal>

Configuring the Bridgewater Diameter Stack


The primary configuration file for the Bridgewater Diameter Stack is the
[Link] file, which is located in the /opt/aaasc/config/dia directory. This
file defines:
• AAA and WiMAX application identities
• server ports
• ASNs
• realm routing
Note After modifying the [Link] file, stop and restart the Bridgewater
Diameter Stack and the Diameter AAA application, otherwise errors occur.
For information, see "Starting and stopping the Diameter processes" on
page 172.

Service Controller 9.6.1-AAA October 12, 2012 Page 137


Chapter 5 Installing and configuring Diameter Network Access Guide

[Link]
The [Link] file provides configuration for the Bridgewater Diameter
stack and its peers. During the installation process, the BWSwsdia package
prompts for values to all required parameters in the [Link] file.
Therefore, manual configuration is not necessary.
The [Link] file is located in the /opt/aaasc/config/dia directory.
Note This section refers to the following acronyms:
– DFN: Diameter Front Node (Bridgewater Diameter Stack), which sends and
receives messages to other Diameter peers.
– APN: Application Process Node, which processes Diameter messages.
The Diameter AAA process is an example of an APN.
– DSM: Diameter Stack Manager, which can be used to modify the
configuration of the Bridgewater Diameter stack.
This section describes each of the primary configuration parameters of the
[Link] file:
• DEBUG
• LOCAL_INFO
• DIAMETER_ TRANSPORT_INFO
• SUPPORTED_ APPLICATIONS
• SYSTEM_INFO
• REALM_INFO
• REALM_ROUTING_ TABLE
• APN_INFO

DEBUG Use the DEBUG parameter to set logging and tracing parameters.
For example:
DEBUG
{
LOG_TYPE=syslog
STATISTICS=off
TRACE=off
BUFFER=off
INFO_LEVEL1=on
INFO_LEVEL2=off
INFO_LEVEL3=off
}

Page 138 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Table 50 describes the elements of the DEBUG. parameter.

Table 50: DEBUG parameters

Parameter Description Values

BUFFER ON=all Diameter messages print in hex format. • on


Optional. • off (default)

INFO_LEVEL_1 ON=provides priority 1 (high priority) log messages. • on (default)


Optional. • off

INFO_LEVEL_2 ON=provides priority 2 log messages. • on


Optional. • off (default)

INFO_LEVEL_3 ON=provides priority 3 log messages. • on


Optional. • off (default)

LOG TYPE Describes the type of log. • console


Optional. • syslog (default)

STATISTICS Prints statistics related to the Bridgewater Diameter Stack, • on


including count of incoming/outgoing request and response • off (default)
messages
Optional.

TRACE Enables debug trace logs. • on


When disabled, all info log levels and HEX DUMP printing • off (default)
are disabled
Optional.

LOCAL_INFO Use the LOCAL_INFO parameter to configure information about the local node,
such as its realm.
For example:
LOCAL_INFO
{
DICTIONARY_FILE=/opt/aaasc/config/dia/[Link]
NODE_ID=1
ORIG_HOST=[Link]
LOCAL_REALM=[Link]
PRODUCT_NAME=Bridgewater Systems Diameter Stack
LOCAL_APN_PORT=7888
LOCAL_APN_IP=[Link]
APN_TRANSPORT=TCP
VENDOR_ID=0
FIRMWARE_REVISION=1
}

Service Controller 9.6.1-AAA October 12, 2012 Page 139


Chapter 5 Installing and configuring Diameter Network Access Guide

Table 51 describes the elements of the LOCAL_INFO parameter.

Table 51: LOCAL_INFO parameters

Parameter Description Values

ALLOW_UNSUPPORTED_AVPS 1=enables AVPs that are not defined in the dictionary to • 0 (default)
be sent to the peer node. • 1
Optional.

APN_TRANSPORT Transport type used between the local Bridgewater • TCP (default)
Diameter Stack and the APN (Diameter AAA application). • UDP
Optional.

DICTIONARY_FILE Path to the dictionary XML file. • String


Required. • Valid directory path
• Example: /opt/aaasc/
config/dia/
[Link]

FIRMWARE_REVISION Used to inform a Diameter peer of the firmware revision of • String


the issuing device.
Required.

LOCAL_APN_IP IP address that the Bridgewater Diameter Stack uses to • String


communicate with applications, such as the Diameter • Standard dot notation
AAA application. format
Required. • Example: [Link]
Note Enter this information during the BWSwsdia
package installation.

LOCAL_APN_PORT Port that the Bridgewater Diameter Stack listens on for • Integer
communications with applications, such as the Diameter (0 - 65535)
AAA application.
Example: 7888
Required.
Note Enter this information during the BWSwsdia
package installation.

LOCAL_DSM_PORT Bridgewater Diameter Stack listens on this port for • Integer (0–65535)
communication with the Diameter stack management Default = 32111
module (DSM).
Optional
Note Do not modify this parameter unless the default
setting conflicts with other elements in the system.

NODE_ID A number that identifies the local Bridgewater Diameter • Integer (0–65535)
Stack.
Required.
Note Enter this information during the BWSwsdia
package installation.

Page 140 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Table 51: LOCAL_INFO parameters (continued)

Parameter Description Values

ORIG_HOST Origin host (Diameter ID) of the Bridgewater Diameter • String


Stack. Example: [Link]
Required
Note Enter this information during the BWSwsdia
package installation.

ORIGIN_REALM Realm of the Bridgewater Diameter Stack. • String


Required. Example: [Link]
Note Enter this information during the BWSwsdia
package installation.

PRODUCT_NAME Name of the Diameter vendor’s software. • String


Required. Example: Bridgewater
Diameter Stack

SESSION_BASED 1=enables subsequent messages to be sent to the APN • 0 (default)


that originated the session. • 1
Optional.

SUPPORTED_VENDOR_ID Used in the CER and CEA messages. • String


Informs the peer that the sender supports a subset of the
vendor-specific AVPs.
Optional.

USE_STANDARD_AVP_FLAGS Optional. • 0 (default)


• 1

VALIDATE_MESSAGE 1=Bridgewater Diameter Stack validates AVP flags in all • 0


messages received from the APN against all flags defined • 1 (default)
in the dictionary.
Optional.

VENDOR_ID In combination with the Supported-Vendor-Id AVP, this • String


may be used to determine which vendor specific attributes Example: 0
can be sent to the peer.
Shared with the peer in the CER message.
Required.

DIAMETER_ Use the DIAMETER_TRANSPORT_INFO to configure connection information for


TRANSPORT_INFO the Bridgewater Diameter Stack.
For example:
DIAMETER_TRANSPORT_INFO
{
LOCAL_IP=[Link]
LOCAL_TCP_PORT=3868
TCP_NO_OF_CONNECTION=10

Service Controller 9.6.1-AAA October 12, 2012 Page 141


Chapter 5 Installing and configuring Diameter Network Access Guide

}
Table 52 describes the elements of the DIAMETER_TRANSPORT_INFO
parameter.

Table 52: The DIAMETER_TRANSPORT_INFO child element parameters

Parameter Description Value

LOCAL_IP IP address for the Bridgewater Diameter Stack. • String


This information is added to the CER message to be • Standard dot notation
shared with the peer. format
This parameter can have multiple entries. Example: [Link]
Required.
Note Enter this information during the BWSwsdia
package installation.

LOCAL_TCP_PORT The Bridgewater Diameter Stack listens on this port for • Integer (0–65535)
incoming Diameter messages. Default = 3868
Required.
Note Enter this information during the BWSwsdia
package installation.

TCP_NO_OF_CONNECTION The maximum number of pending incoming requests that • Integer (0–65535)
the Bridgewater Diameter Stack can queue. Default = 10
This does not limit the number of peers that can be
configured.
Optional.

SUPPORTED_ Use the SUPPORTED_APPLICATIONS parameter to identify locally or externally


APPLICATIONS supported applications.
For example:
SUPPORTED_APPLICATIONS
{
APPLICATION_INFO
{
APP_ID=5
APP_NAME=EAP
APP_VENDOR_ID=0
APP_TYPE=AUTH
}
}

Page 142 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Table 53 describes the elements of the SUPPORTED_APPLICATIONS parameter.

Table 53: The SUPPORTED_APPLICATIONS child element parameters

Parameter Description Value

APP_ID ID of the supported application. • String


Required. • For DCCA deployments, set
the value to “4”
Example: 5

APP_NAME The name of the application. • String


• For DCCA deployments, set
the value to “CC”

APP_TYPE The application type. • AUTH


• ACCT

APP_VENDOR_ID The vendor ID of the application. Default = 0


For DCCA deployments, set the
value to “0”

GDAM Specifies whether the application is supported over the • true (default)
Generic Diameter Application Module (GDAM). • false
Optional.

SYSTEM_INFO Use the SYSTEM_INFO parameter to configure system parameters, such as a


watchdog timer.
For example:
SYSTEM_INFO
{
THREAD_COUNT=10
WATCH_DOG_TIMER=30000
}
Table 54 describes the elements of the SYSTEM_INFO parameter.

Table 54: The SYSTEM_INFO child element parameters

Parameter Description Value

AGENT_TRANSACTION_POOL The size of the transaction pool. • Integer


Optional. (0–2147483647)
Default = 10000

MAX_BUFFERS_IN_POOL The number of buffers in the memory pool. • Integer


Optional. (0–200000)
Default = 3000

Service Controller 9.6.1-AAA October 12, 2012 Page 143


Chapter 5 Installing and configuring Diameter Network Access Guide

Table 54: The SYSTEM_INFO child element parameters (continued)

Parameter Description Value

PEER_CER_TIME _OUT The CER ‘time-out’ timer. • Integer


After sending a CER message to a peer node, the (1–2147483647)
Bridgewater Diameter Stack starts a ‘time-out’ timer In Default = 40000
milliseconds.
If the stack does not receive a CEA message during this
time, it re-sends the CER message.
Optional.

PEER_CONNECTION_ATTEMPT_TIMER The time to wait, in milliseconds, between connection • Integer


attempts to a peer node. (1–2147483647)
Optional. Default = 3000

PEER_CONNECTION_ATTEMPTS Number of times the Bridgewater Diameter Stack • Integer


attempts to connect to a peer node. (1–65535)
Optional. Default = 20

THREAD_COUNT Number of worker threads assigned to the Bridgewater • Integer (0–100)


Diameter Stack. Default = 6
Optional.

WATCH_DOG_TIMER Diameter Watchdog timer in milliseconds (heartbeat). • Integer


Optional. (1–2147483647)
Default = 30000

REALM_INFO Use the REALM_INFO parameter to configure peer nodes.


Note Only configure one PEER_NODE for each REALM.
Example:
REALM_INFO
{
REALM
{
NAME=[Link]
PEER_NODE
{
IP_ADDRESS=[Link]
PORT=3868
HOST_ID=[Link]
PEER_APPS=4,CreditControl
}
}
REALM
{
NAME=[Link]

Page 144 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

PEER_NODE
{
IP_ADDRESS=[Link]
PORT=3868
HOST_ID=[Link]
PEER_APPS=4,CreditControl
}
}
}
Table 55 describes the elements of the REALM_INFO parameter.

Table 55: The REALM_INFO child element parameters

Parameter Description Value

REALM • Encloses the child element parameter PEER_NODE. —


• Only configure one PEER_NODE for each REALM

PEER_NODE • Encloses child element parameters that define the PEER_NODE —

HOST_ID • Diameter URI of the Diameter peer. • A valid URI


• Required. Example: [Link]
Note Enter this information during the BWSwsdia package installation.

IP_ADDRESS • IP address of the Diameter peer, such as a network access server. • IP dot notation format
• This can contain multiple entries. Example: [Link]
• Required.
Note Enter this information during the BWSwsdia package installation.

NAME • Name of the peer realm. • String


• Required. Example: [Link]
Note Enter this information during the BWSwsdia package installation.

PORT • Port number of the Diameter peer. • Integer


• Required. Default = 3868
Note Enter this information during the BWSwsdia package installation.

PEER_APPS • The name of the peer application. • Integer


• Required. Example: PEER_APPS=4
Note Enter this information during the BWSwsdia package installation.

REALM_ROUTING_ Use the REALM_ROUTING_TABLE section to specify routing information about the
TABLE destination for incoming requests.
Example:
REALM_ROUTING_TABLE
{
ENTRY
{

Service Controller 9.6.1-AAA October 12, 2012 Page 145


Chapter 5 Installing and configuring Diameter Network Access Guide

REALM_NAME=[Link]
ACTION=LOCAL
DESTINATION_HOST
{
APPLICATION_ID=5
DESTINATION_ID=[Link]
}
DESTINATION_HOST
{
APPLICATION_ID=3
DESTINATION_ID=[Link]
}
}
ENTRY
{
REALM_NAME=DEFAULT
ACTION=LOCAL
DESTINATION_HOST
{
APPLICATION_ID=5
DESTINATION_ID=[Link]
}
DESTINATION_HOST
{
APPLICATION_ID=3
DESTINATION_ID=[Link]
}
}
}
Table 56 describes the elements of the REALM_ROUTING_TABLE parameter.

Table 56: The REALM_ROUITING_TABLE child element parameters

Parameter Description Value

ENTRY • Encloses routing information —

REALM_NAME • Name of the peer realm. • String


Note A value of “DEFAULT” defines a default realm to use Example: [Link]
for messages received that are not otherwise defined
in the realm routing table.

ACTION • The action to take on the incoming request. • Local

DESTINATION_ • Encloses APPLICATION_ID and DESTINATION_ID. —


HOST

Page 146 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Table 56: The REALM_ROUITING_TABLE child element parameters (continued)

Parameter Description Value

APPLICATION_ID • ID of the Diameter application to be used. • String


Example: 5

DESTINATION_ID • Diameter Identity to which the request is forwarded. • String


Note The DESTINATION_ID must be the same as Example: [Link]
ORIG_HOST in the LOCAL_INFO section.

APN_INFO Use the APN_INFO parameter to identify the Application Process Nodes on the
Diameter stack. This parameter can have multiple instances.
For example:
APN_INFO
{
APN
{
APN_ID=1
APPLICATION=5
}
APN
{
APN_ID=1
APPLICATION=3
}
}
Table 57 describes the elements of the APN_INFO parameter.

Table 57: The APN_INFO child element parameters

Parameter Description Value

APN_ID • ID of the Application Process Node on the Bridgewater • Integer (0 - 65535)


Diameter Stack (can have multiple instances) • For DCCA deployments, set the
• Required. value to “1”
Note Enter this information during the BWSwsdia package
installation.

APPLICATION • The application ID that the APN supports. • String


• This parameter can have multiple instances. • For DCCA deployments, set the
• Required. value to “4”
Note Enter this information during the BWSwsdia package
installation.

Service Controller 9.6.1-AAA October 12, 2012 Page 147


Chapter 5 Installing and configuring Diameter Network Access Guide

Example [Link]
DIAMETER_CONFIG_DATA
{
DEBUG
{
LOG_TYPE=syslog
STATISTICS=off
TRACE=off
BUFFER=off
INFO_LEVEL1=on
INFO_LEVEL2=off
INFO_LEVEL3=off
}
LOCAL_INFO
{
DICTIONARY_FILE=/opt/aaasc/config/dia/[Link]
NODE_ID=1
ORIG_HOST=[Link]
LOCAL_REALM=[Link]
PRODUCT_NAME=Bridgewater Systems Diameter Stack
LOCAL_APN_PORT=7888
LOCAL_APN_IP=[Link]
APN_TRANSPORT=TCP
VENDOR_ID=0
FIRMWARE_REVISION=1
}
DIAMETER_TRANSPORT_INFO
{
LOCAL_IP=[Link]
LOCAL_TCP_PORT=3868
TCP_NO_OF_CONNECTION=10
}
SUPPORTED_APPLICATIONS
{
APPLICATION_INFO
{
APP_ID=5
APP_NAME=EAP
APP_VENDOR_ID=0
APP_TYPE=AUTH
}
APPLICATION_INFO
{

Page 148 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

APP_ID=3
APP_NAME=BASE Accounting
APP_VENDOR_ID=0
APP_TYPE=ACCT
}
}
SYSTEM_INFO
{
THREAD_COUNT=10
WATCH_DOG_TIMER=30000
}
REALM_INFO
{
REALM
{
NAME=[Link]
PEER_NODE
{
IP_ADDRESS=[Link]
PORT=3868
HOST_ID=[Link]
}
}
}
REALM_ROUTING_TABLE
{
ENTRY
{
REALM_NAME=[Link]
ACTION=LOCAL
DESTINATION_HOST
{
APPLICATION_ID=5
DESTINATION_ID=[Link]
}
DESTINATION_HOST
{
APPLICATION_ID=3
DESTINATION_ID=[Link]
}
}
ENTRY
{

Service Controller 9.6.1-AAA October 12, 2012 Page 149


Chapter 5 Installing and configuring Diameter Network Access Guide

REALM_NAME=DEFAULT
ACTION=LOCAL
DESTINATION_HOST
{
APPLICATION_ID=5
DESTINATION_ID=[Link]
}
DESTINATION_HOST
{
APPLICATION_ID=3
DESTINATION_ID=[Link]
}
}
}
APN_INFO
{
APN
{
APN_ID=1
APPLICATION=5
}
APN
{
APN_ID=1
APPLICATION=3
}
}
}

Page 150 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Configuring the Diameter AAA application


This section describes the primary configuration file for the Diameter AAA
application:
• [Link]
This section also describes the following configuration files that are used to
configure the Diameter AAA application:
• TLSPolicy
• accessReqPolicy
• acctReqPolicy
• [Link]
• [Link]

[Link]
[Link], located in the /opt/aaasc/config/dia-aaa directory, is the primary
configuration file for the Diameter AAA process. The system automatically
populates this file using information supplied during installation of the Diameter
AAA software package (BWSwsaaa). This file does not require configuration, but
the default settings can be modified.
For more information about [Link] parameters, see the
[Link] schema file, located in the /opt/aaasc/dia-aaa directory.
For more information about the BWSwsaaa package prompts, see the Bridgewater
Installation Reference Guide.

Table 58: [Link] elements

Elements Value Description

Debug — Encloses EnableTrace, and LogLevel

EnableTrace • true Enable trace debug messaging.


• false

LogLevel • 0 Define the log level.


• 1 (Default) • 0: off
• 2 • 1: standard logs (no debug messages)
• 3 • 2: enhanced logging
• 3: all debug messages

EnableConsoleLog • true Log messages to the console instead of syslog.


• false

LocalInfo — Encloses OriginHost, OriginRealm, LocalIP, and APNNodeID.

OriginHost String The application origin host.

OriginRealm String The application origin realm.

Service Controller 9.6.1-AAA October 12, 2012 Page 151


Chapter 5 Installing and configuring Diameter Network Access Guide

Table 58: [Link] elements (continued)

Elements Value Description

LocalIP String The IP address of the Diameter AAA application.

APNNodeID Integer (0–65535) A unique identifier for the Diameter AAA Server.

SystemInfo — Encloses ThreadCount, SessionCount, SessionTimeoutInterval,


HealthCheckTimer, ConnectionTimer, MaxRetry,
ReTransmitTimer, MaxBuffersInPool, and EnableStatistics.

ThreadCount Integer (0–2147483647) Number of worker threads in the Diameter AAA Server.
Default = 20

SessionCount Integer (0–2147483647) The number of concurrent sessions before the Diameter AAA
Default = 2000 Server returns a failure.
Diameter AAA supports twice the value of this parameter.

SessionTimeoutInterval Integer (0–2147483647) The time, in milliseconds, that a session can be inactive before
Default = 30000 timing out.

HealthCheckTimer Integer (0–2147483647) How often, in milliseconds, the Diameter AAA Server exchanges
Default = 30000 health check messages with the Diameter Stack to detect
connection errors.

ConnectionTimer Integer (0– 2147483647) How often, in milliseconds, the Diameter AAA Server checks the
Default = 10000 connection to the Diameter Stack when the connection is lost.

MaxRetry Integer (0–2147483647) The number of attempts to retransmit a Diameter message


Default = 0 during the session.

ReTransmitTimer Integer (0–2147483647) The time, in milliseconds, between retransmission attempts


Default = 5000 when the Diameter AAA Server does not receive a response to a
request.

MaxBuffersInPool Integer (0–2147483647) The maximum number of buffers in the memory pool.
Default = 50000

EnableStatistics • true True: enable counters for all incoming and outgoing messages.
• false

DFNConfig — Encloses DFN.

DFN — Encloses ID, IPAddress, and Port.

ID Integer (0 to 65535) A unique identifier for the Diameter Stack (Diameter Front Node).

IPAddress String The IP address of the Diameter Stack.

Port Integer (0 to 65535) The application port of the Diameter Stack.

Page 152 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Example [Link]
<DiameterAAA xmlns:xsi="[Link]
xsi:noNamespaceSchemaLocation="/opt/aaasc/dia-aaa/[Link]">
<Debug>
<EnableTrace>false</EnableTrace>
<LogLevel>1</LogLevel>
</Debug>
<LocalInfo>
<OriginHost>[Link]</OriginHost>
<OriginRealm>[Link]</OriginRealm>
<LocalIP>[Link]</LocalIP>
<APNNodeID>2</APNNodeID>
</LocalInfo>
<SystemInfo>
<ThreadCount>20</ThreadCount>
<SessionCount>2000</SessionCount>
<SessionTimeoutInterval>30000</SessionTimeoutInterval>
<HealthCheckTimer>30000</HealthCheckTimer>
<ConnectionTimer>10000</ConnectionTimer>
<MaxRetry>2147483647</MaxRetry>
<RetransmitTimer>5000</RetransmitTimer>
<MaxBuffersInPool>50000</MaxBuffersInPool>
<EnableStatistics>false</EnableStatistics>
</SystemInfo>
<DFNConfig>
<DFN>
<IPAddress>[Link]</IPAddress>
<Port>7888</Port>
</DFN>
</DFNConfig>
</DiameterAAA>

Service Controller 9.6.1-AAA October 12, 2012 Page 153


Chapter 5 Installing and configuring Diameter Network Access Guide

TLSPolicy
The TLSPolicy file is used by EAP-TTLS phase 2 authentication to evaluate the
inner subscriber identity. Configure policy rules for Diameter using the TLSPolicy
file located in the /opt/aaasc/config/dia-aaa directory.
For more information about configuring TLSPolicy and about supported actions and
modifiers, see "TLS request actions" on page 254, and see the chapter “EAP in
AAA policies”, in the Extensible Authentication Protocol Guide.
Note For information about configuring EAP-TTLS phase 2 proxy to a RADIUS
server, see "Configuring Diameter EAP-TTLS phase 2 proxy to RADIUS
AAA" on page 158.

To configure dual-mode devices in LDAP deployments


For subscribers with dual-mode devices:
• modify the [Link] file to set <base-dn> to a token value
• specify the domains in the accessReqPolicy using the authenticateDomain
action modifier
• specify the domains in the TLSPolicy file using the authenticateDomain and
authorizeDomain action modifiers
For information about configuring [Link], see "Configuring LDAP access for
Diameter" on page 135.
For information about configuring policy files, see "Configuring AAA policies" on
page 233.

accessReqPolicy
The accessReqPolicy for Diameter is located in /opt/aaasc/config/dia-aaa/
accessReqPolicy.
For example:
User-Name ContainsCI AM_1 WiMAXLocalAA EAP-Policy=TTLS-AM_1
User-Name ContainsCI eapuser_1 WiMAXLocalAA service=EAPUSER_1
- - - WiMAXLocalAA
For more information about configuring acctReqPolicy and about supported actions
and modifiers, see "Access request actions" on page 240.

acctReqPolicy
The acctReqPolicy for Diameter is located in /opt/aaasc/config/dia-aaa/
acctReqPolicy.
For example:
- - - WiMAXLocalAcct
For more information about configuring acctReqPolicy and about supported actions
and modifiers, see "Accounting request actions" on page 246.

Page 154 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

[Link]
The [Link] file located in the /opt/aaasc/config directory contains the RMS
connection information. Insert this line at the end of the [Link] file:
0 <rms_server_ip> 34501 MYSECRET - - - 5 - -

[Link]
Configure the [Link] file located in the /opt/aaasc/config/dia-aaa directory for
EAP-TLS, EAP-AKA, or EAP-TTLS authentication.
Provision the client (application or mobile device) with the CA certificate file that
signed the server (Service Controller) certificate. The CA certificate file is used by
the client to validate the server certificate during EAP-TLS/EAP-TTLS
authentication.
For more information about the elements and attributes used in the examples
shown in this section, see the chapter “EAP configuration” in the Extensible
Authentication Protocol Guide.
This section provides the following examples and configuration information:
• Settings shared by EAP-TLS and EAP-TTLS
• Settings specific to EAP-TLS
• Settings specific to EAP-TTLS authmode 1
• Settings specific to EAP-TTLS authmode 4
• Settings for EAP-AKA
• Configuring Diameter EAP-TTLS phase 2 proxy to RADIUS AAA

Settings shared by This example shows an [Link] file that is configured for either EAP-TLS or
EAP-TLS and EAP-TTLS authentication. These settings are common to both types of
EAP-TTLS authentication.
<eap-configuration
timeout="10"
certificate-directory="/opt/aaasc/config/dia-aaa"
dh-file="[Link]">
<cache-setting/>
<certificate
certificate-name="serverCert"
verification-depth="2"
certificate-file="[Link]"
private-key-file="[Link]"
private-key-password="serverkey"
ca-list-file="calistfile"

Service Controller 9.6.1-AAA October 12, 2012 Page 155


Chapter 5 Installing and configuring Diameter Network Access Guide

Settings specific to This example shows an [Link] file that is configured to use EAP-TLS to test
EAP-TLS WiMAX authmode 2 "Device authentication". This example builds on the settings
displayed in "Settings shared by EAP-TLS and EAP-TTLS" on page 155.
<tls-setting
setting-name="mytls"
certificate="serverCert"
fragment-size="2048"
require-client-certificate="Always"/>
<type-selection-policy
policy-name="default"
tls-setting="mytls">
<eap-tls/>
</type-selection-policy>
In particular, for EAP-TLS functionality:
• set require-client-certificate=”Always” so that the server and the client
exchange certificates
• set policy-name="default" so that the EAP policy is applied to the DER
message
• list eap-tls within the type-selection-policy element so that this policy performs
EAP-TLS authentication

Settings specific to This example shows an [Link] file that is configured to use EAP-T’TLS to test
EAP-TTLS WiMAX authmode 1 "User authentication". With authmode 1 the subscriber is
authmode 1 authenticated during EAP-TTLS/MSCHAPv2 phase 2. This example builds on the
settings displayed in "Settings shared by EAP-TLS and EAP-TTLS" on page 155.
With EAP-TTLS, the server must send a certificate to the client and the client may
optionally respond with a certificate. If the client does not provide a certificate,
EAP-TTLS phase 2 is implemented and the subscriber is authenticated using
MSCHAPv2.
<tls-setting
setting-name="myttls"
certificate="serverCert"
fragment-size="2048"
require-client-certificate="Never"/>
<type-selection-policy
policy-name="default"
tls-setting="myttls">
<eap-ttls/>
</type-selection-policy>

Page 156 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

In particular, for EAP-TTLS authmode 1 functionality:


• set require-client-certificate=”Never” so that the RADIUS Server does not
request a client certificate from the client. This causes the RADIUS Server to
enter phase 2 of EAP-TTLS (that is, MSCHAPv2) authentication using the
subscriber name and password provided by the client through the TLS tunnel
that was established during EAP-TTLS phase 1.
• set policy-name="default" so that the EAP policy is applied to the DER
message
• list eap-ttls within the type-selection-policy element so that this policy performs
EAP-TTLS authentication

Settings specific to This example shows an [Link] file that is configured to use EAP-TTLS to test
EAP-TTLS WiMAX authmode 4 "Single EAP device and subscriber authentication". This
authmode 4 example builds on the settings displayed in "Settings shared by EAP-TLS and
EAP-TTLS" on page 155.
The server and client exchange certificates to authenticate a device during
EAP-TTLS phase 1.
A subscriber is authenticated during EAP-TTLS/MSCHAPv2 phase 2 using TLS
tunneled subscriber name and password attributes. The TLS tunnel is established
during EAP-TTLS phase 1.
<tls-setting
setting-name="myttls"
certificate="serverCert"
fragment-size="2048"
require-client-certificate="Always"/>
<type-selection-policy
policy-name="default"
tls-setting="myttls">
<eap-ttls
force-phase-2="Y"/>
</type-selection-policy>
In particular, for EAP-TTLS authmode 4 functionality:
• set require-client-certificate=”Always” so that the RADIUS Server requests a
client certificate from the client.
• set policy-name="default" so that the EAP policy is applied to the DER
message
• list eap-ttls within the type-selection-policy element so that this policy performs
EAP-TTLS authentication
• set force-phase-2=”Y” so that EAP-TTLS phase 2 authenticates the subscriber
using MSCHAPv2 subscriber name and password credentials. If this is not
specified or is set to "N" and a client certificate is presented during phase 1,
phase 2 is skipped.

Service Controller 9.6.1-AAA October 12, 2012 Page 157


Chapter 5 Installing and configuring Diameter Network Access Guide

Settings for EAP-AKA This example shows a section of the [Link] file specific to EAP-AKA:
<eap-configuration>
<type-selection-policy policy-name="AKA">
<eap-aka identity-exchange-supported=”Y”/>
</type-selection-policy>
</eap-configuration>
Note For more information about the elements and attributes used in the
examples shown in this section, see the chapter “EAP configuration” in the
Extensible Authentication Protocol Guide

Configuring Diameter The Diameter AAA application can provide EAP-TTLS phase 2 client authentication
EAP-TTLS phase 2 (using MSCHAPv2) proxy to a remote RADIUS AAA.
proxy to RADIUS AAA This section provides the following overview information and configuration
procedures:
• Diameter/RADIUS Translation Agent
• Diameter proxy to RADIUS AAA message flow
• To enable Diameter EAP-TTLS phase 2 proxy to RADIUS AAA
• To configure accessReqPolicy
• To configure [Link]
• To configure TLSPolicy
• To configure [Link]
Note Diameter EAP-TTLS only supports MSCHAPv2 as a phase 2 client
authentication method. If the Diameter AAA application detects a method
other than MSCHAPv2, it returns a DEA with
Result-Code=DIAMETER_AUTHENTICATION_REJECTED.
Note The Diameter AAA application only supports one RADIUS AAA target.

Diameter/RADIUS Translation Agent


The communications between the Diameter AAA application and the RADIUS AAA
are provided by a Diameter/RADIUS Translation Agent, which includes the
following:
• translate MSCHAPv2 Diameter AVPs to MSCHAPv2 RADIUS attributes
• translate MSCHAPv2 RADIUS attributes to MSCHAPv2 Diameter AVPs.
• process the following RADIUS message types:
– Access-Challenge
– Access-Reject
– Access-Accept
Note If the RADIUS AAA returns attributes that are not found in the RFC 2138
dictionary on the Diameter server, the Diameter AAA application fails to
decode the RADIUS message. The solution is to add any missing attributes
to the RFC 2138 dictionary on the Diameter server. For information, see "To
modify or create a RADIUS dictionary" on page 185.

Page 158 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Table 59 describes the translations the Diameter/RADIUS Translation Agent


supports.

Table 59: Diameter/RADIUS Translation Agent

Translation Description

DER to Access-Request • The Diameter AAA application translates MSCHAPv2 Diameter AVPs
• EAP-TTLS Phase 2 Client Authentication (embedded in the EAP-Payload AVP) to MSCHAPv2 RADIUS
(using MSCHAPv2) DER to Access-Request attributes.

Access-Challenge to DEA • The Diameter AAA application translates an RADIUS MSCHAPv2


• RADIUS MSCHAPv2 Access-Challenge Access-Challenge to a DEA message
Response to DEA • The DEA message has Result-Code=DIAMETER_MULTI_ROUND_
AUTH
• The Diameter AAA application embeds the EAP information from the
translated RADIUS Access-Challenge in the EAP-Payload AVP
returned to the client in the DEA message
Note The RADIUS AAA returns an Access-Challenge if it cannot
validate the MSCHAPv2 response attribute. If the RADIUS AAA
returns an Access-Challenge, the Diameter AAA application
performs phase 2 client authentication again.

Access-Accept to DEA • The Diameter AAA application translates a RADIUS MSCHAPv2


• RADIUS MSCHAPv2 Access-Accept Access-Accept to a DEA message
Response to DEA • The DEA message has Result-Code=DIAMETER_SUCCESS
• The Diameter AAA application embeds the EAP information from the
translated RADIUS Access-Accept in the EAP-Payload AVP returned
to the client in the DEA message
Note If the RADIUS Access-Accept contains authorization attributes, the
Diameter AAA application does not include them in the DEA sent
to the client.

Access-Reject to DEA • If the RADIUS AAA returns an Access-Reject, the Diameter AAA
• RADIUS MSCHAPv2 Access-Reject application sends the client a DEA with
Response to DEA Result-Code=AUTHENTICATION_REJECTED.

Service Controller 9.6.1-AAA October 12, 2012 Page 159


Chapter 5 Installing and configuring Diameter Network Access Guide

Diameter proxy to RADIUS AAA message flow


Figure 22 illustrates Diameter EAP-TTLS phases 1 and 2, with phase 2 proxy to a
remote RADIUS AAA.
Figure 22: Diameter EAP-TTLS phase 2 proxy to RADIUS AAA

'LDPHWHU 5HPRWH
&OLHQW
6HUYLFH&RQWUROOHU 5$',86$$$

'(5
($377/63KDVH
'($

'(5

$FFHVV5HTXHVW
($377/63KDVH
5$',86UHVSRQVH

'($

For a complete message flow, see the chapter “EAP-TTLS” in the Extensible
Authentication Protocol Guide.

To enable Diameter EAP-TTLS phase 2 proxy to RADIUS AAA


Add the -p option to the diaaaad process to enable Diameter EAP-TTLS phase 2
proxy to RADIUS AAA.
The -p option configures the number of proxy response threads and indicates to the
diaaaad process to load [Link].
For example:
diaaaad -p 5
Note If -p is not present, Diameter EAP-TTLS phase 2 proxy to RADIUS AAA is
disabled and TLSProxyAA cannot be used.
For more information about Diameter command line arguments, see "diaaaad
command line options" on page 170.

To configure accessReqPolicy
Add the WiMAXLocalAA action with the EAP-Policy modifier.
Make sure EAP-Policy is the same value as the policy-name in [Link].
For example:
- - - WiMAXLocalAA EAP-Policy="ttlspolicy"

Page 160 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

To configure [Link]
1 Configure [Link], located in /opt/aaasc/config/dia-aaa. In the
type-selection-policy section, specify a value for policy-name to match the
value of the EAP-Policy modifier used in the accessReqPolicy.
For example:
<type-selection-policy policy-name="ttlspolicy">
2 In the eap-ttls section, specify a value for authentication-policy such as
TLSPolicy.
For example:
<eap-ttls
tls-setting="mytls"
session-resumption-timeout="600"
authentication-policy="TLSPolicy"
force-phase-2="Y"/>
Note If no value for authentication-policy is specified, the Diameter AAA
application performs phase 2 client authentication locally.
For more information about [Link], see the chapter “EAP configuration” in the
Extensible Authentication Protocol Guide.

To configure TLSPolicy
In the TLSPolicy file, located at /opt/aaasc/config/dia-aaa add the TLSProxyAA
action.
TLSProxyAA specifies that the Diameter AAA application proxies phase 2 client
authentication (using MSCHAPv2) to a RADIUS AAA. For example:
- - - TLSProxyAA
Note Use the -p option in the Diameter startup script when using TLSProxyAA. -p
configures the number of proxy threads. For more information, see "To
enable Diameter EAP-TTLS phase 2 proxy to RADIUS AAA".

Example with local authorization modifiers


If a representative subscriber is not configured on the policy line, the Diameter AAA
application performs local authorization using the credentials in the Inner-User-ID
from the client.
If a representative subscriber is configured on the policy line, the Diameter AAA
application performs local authorization using the following optional local
authorization action modifiers:
• authorizeLoginName
• authorizeDomain
Aso use the outageRejectMessage action modifier to specify a message sent in the
DEA.
For information about using these action modifiers, see "Diameter TLSPolicy action
modifiers" on page 257.

Service Controller 9.6.1-AAA October 12, 2012 Page 161


Chapter 5 Installing and configuring Diameter Network Access Guide

The following example shows policies configured for Diameter EAP-TTLS phase 2
proxy to a RADIUS server. This example includes local authorization modifiers in
TLSPolicy that override instances of these same modifiers in the accessReqPolicy:
accessReqPolicy:
- - - WiMAXLocalAA EAP-Policy=ttlspolicy
authorizeLoginName=rep authorizeDomain=[Link]
TLSPolicy:
- - - Inner-User-ID EndsWith [Link] TLSProxyAA
authorizeLoginName=innerRep authorizeDomain=[Link]
outageRejectMessage="Remote RADIUS server is unresponsive"
In this example, in phase 2 of EAP-TTLS:
• if the Diameter AAA application receives an Access-Accept, it uses
innerRep@[Link] to perform the authorization.
• if the RADIUS AAA does not respond, the Diameter AAA application rejects the
subscriber with a DEA including Reply-Message="Remote RADIUS server is
unresponsive" and
Result-Code=DIAMETER_AUTHENTICATION_REJECTED.

To configure [Link]
1 Configure the RADIUS proxy target using [Link], located in /opt/aaasc/
config/dia-aaa.
For example:
<APIConfiguration>
<STSServers>
<Server Address="[Link]" Port="1234"
Secret="secret1" MaxRetries="1" RequestTimeout="2"/>
</STSServers>
</APIConfiguration>
2 Send the Diameter AAA application a HUP signal for the changes to
[Link] to take effect:
pkill -HUP diaaaad
Note The Diameter AAA application only supports one RADIUS proxy target.
Table 60 describes the [Link] elements and attributes.

Page 162 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Table 60: [Link] elements and attributes

Element/Attribute Value Description

APIConfiguration — Root element that encloses STSServers.


Required.

STSServers — Encloses the child element Server.


This section is used to configure the RADIUS proxy target.
Note Only configure one STSServer element. The Diameter AAA application
only supports one RADIUS AAA target.
Child element of APIConfiguration.
Required.

Server — Encloses the attributes Address, Port, Secret, MaxRetries, and


RequestTimeout.
This element is used to configure the RADIUS proxy target.
Note Only configure one Server element. The Diameter AAA application only
supports one RADIUS AAA target.
Child element of STSServers
Required.

Address IP address Identifies the IP address of the RADIUS server.


Attribute of Server.
Required.

Port Integer The port where the RADIUS server is listening.


(0–65535) Bridgewater Systems recommends port 1812.
No default Attribute of Server.
Required.

Secret String The secret shared between the Diameter AAA application and the RADIUS
proxy target.
Attribute of Server.
Required.

MaxRetries Integer The maximum number of attempts to retransmit proxy messages to the
(0–65535) RADIUS AAA target.
Default = 1 Attribute of Server.
Optional.

RequestTimeout Integer The time, in seconds, to wait for a response from the RADIUS AAA target.
(1–65535) Attribute of Server.
Default = 2 Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 163


Chapter 5 Installing and configuring Diameter Network Access Guide

Configuring a Diameter AAA application buffer


The Diameter server requires an Accounting Framework buffer, named aaabuff,
and does not start unless one is present.
To create a buffer add the following lines to the buffer_config.xml file located in the /
opt/aaasc/config directory:
<Buffer BufferName="aaabuff">
<InitSize>10485760</InitSize>
<AuditInterval>900</AuditInterval>
<HWM>90</HWM>
<RecFlush>0</RecFlush>
<BaseLoc>/opt/aaasc/config/acctbuffer/aaa</BaseLoc>
<GrpOwner>ws</GrpOwner>
<Extension>
<ExtSize>5242880</ExtSize>
<UnusedAge/>
<ExtLocation>
<Directory>/opt/aaasc/config/acctbuffer/aaa
</Directory>
<Amount/>
</ExtLocation>
</Extension>
</Buffer>
Note The values shown in bold are for illustrative purposes only; replace them
with values appropriate for the network configuration. For more information,
see the chapter “Configuring buffers” in the Accounting Framework Guide.

Page 164 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Configuring Diameter dictionary support


The Bridgewater Diameter Stack and the Diameter AAA application use the
[Link] dictionary file to source Diameter AVPs for all vendors. Do not
configure this dictionary unless vendor VSAs or enumerated values are added.
For more information about Diameter dictionaries, see "Managing Diameter
dictionaries" on page 209.

To install and configure Diameter dictionary files


To install and configure all Diameter dictionary files, do the following:
• Install all Diameter packages including the BWSaaaco and BWSwsaaa
packages. These files contain:
– [Link] Diameter AAA dictionary, which installs to /opt/aaasc/
config/dia/[Link]
– Diameter dictionary library, libbws_dia_dict.so, copied to /opt/aaasc/lib
– [Link], which installs to /opt/aaasc/config/dia/
[Link]
For information see the chapter “Package Installation” in the Bridgewater
Installation Reference Guide.
• When using Diameter with an LDAP database:
– configure the [Link] file. The attributes supported in Diameter
dictionary must be added to the [Link] file in the element
<ldap-attribute>. For information about configuring [Link], see
"Configure [Link]" on page 89. The elements and attributes are
the same for [Link] and [Link].
– configure the memory map files. For information about configuring the
memory map files, see "Configuring LDAP access for Diameter" on page
135.
• Configure Diameter accessReqPolicy. For information see "accessReqPolicy"
on page 154.
• Configure [Link]
In a Diameter environment, the [Link] file defines the utility that
loads the Diameter dictionary into the Provisioning Server, and it points to the
directory that contains the [Link] file. The
[Link] file also configures the Diameter dictionary API. The
[Link] file is located in the /opt/aaasc/config/provserver directory.
Note For a new installation, manual configuration of the Diameter information in
the [Link] file is not required. For upgrades, see the
README file in the BWSaaapr package for information about configuring
the [Link] file.

Service Controller 9.6.1-AAA October 12, 2012 Page 165


Chapter 5 Installing and configuring Diameter Network Access Guide

Configuring Diameter reauthentication


Diameter provides reauthentication when a subscriber’s session expires or when
the subscriber roams to another ASN. Configure the session timeout for
reauthentication using the file [Link], or the diaaaad command line option.
For an example Diameter reauthentication message flow, see "Reauthentication" in
the “Configuring WiMAX” chapter of the Service Controller: WiMAX Guide.
For more information on diaaaad command line options, see "diaaaad command
line options" on page 170.

To configure reauthentication
Provision a value for a subscriber’s session timeout in one of the following ways:
• Use the diaaaad command line option to provision a value for
WiMAXReAuthenticationInterval. The Service Controller returns this
provisioned value to the ASN in the attribute Session-Timeout.
– Navigate to /opt/aaasc/config/dia-aaa
– Open the file diaaaa and in the “start-line” add the argument -q 1800
– Restart Diameter:
/etc/init.d/diaaaa stop
/etc/init.d/diaaaa start
• For LDAP database deployments, modify the file [Link] as follows:
– Within the element <static-attribute> add a “name” attribute and specify a
value of “Session-Timeout”. Add a “value” attribute and provision a value in
seconds (valid range 300-302400 seconds, default=1800). For example:
<static-attribute name="Session-Timeout" value="1800"/>
For more information about configuring “[Link]”, see "Example
[Link] file" on page 136.
Note If a value for “Session-Timeout” is not provisioned in the file [Link]
or specified as a diaaaad command line option, the Service Controller uses
a default value of 1800 seconds.

To set a local RMS cluster


Use the -R diaaaad command line option to specify a local RMS cluster ID on the
Service Controller.
The RMS cluster ID specified by -R should match the RMS cluster ID for the HAs
assigned to most subscribers authenticated on a Service Controller.
Not setting a local RMS cluster ID using -R does not disable any functionality, but it
can have a serious impact on performance during subscriber re-authentications.
If no AAA-Session-ID is present and no value is specified for -R, during
re-authentications the queries all configured RMS clusters in numeric order until it
finds the session.

Page 166 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Preventing network congestion for Diameter


To prevent network congestion in the event of a power failure or any other network
disruption between the access network and the Diameter Service Controller, the
Service Controller provides a congestion control mechanism.
This section provides an overview of the congestion control mechanism and
information about configuring settings for the congestion control mechanism:
• Congestion control overview
• To configure settings for the congestion control mechanism

Congestion control overview


Figure 23 shows the Diameter Service Controller and its message queue.
Figure 23: Diameter Service Controller and access network

6XEVFULEHU
GHYLFHV 'LDPHWHU6HUYLFH&RQWUROOHU

$61 7&3 7&3 'LDPHWHU$$$


')1 0HVVDJH DSSOLFDWLRQ
*DWHZD\
TXHXH $31

The Diameter AAA application (APN) uses a LIFO (last-in-first-out) message queue
to receive all ingress messages. With the congestion control mechanism, the
ingress message queue is initialized to two times the expected peak rate of traffic
and the message queue is divided into three sub-ranges: green, orange, and red.
Figure 24: Message queue size and system congestion state sub-ranges

0HVVDJHTXHXH
VL]HLQLWLDOL]HGWRWZRWLPHVWKHH[SHFWHGSHDNUDWHRIWUDIILF
SHDNUDWHFRQILJXUHGLQGLDDDDGFRPPDQGOLQH
GLYLGHGLQWRWKUHHVXEUDQJHV
*UHHQ VL]H RQHVHFRQGRIWKHSHDNUDWHRIWUDIILF
2UDQJH VL]H KDOIDVHFRQGRIWKHSHDNUDWHRIWUDIILF
5HG VL]H KDOIDVHFRQGRIWKHSHDNUDWHRIWUDIILF

6\VWHPFRQJHVWLRQVWDWH
*UHHQ±6HUYLFH&RQWUROOHULQQRUPDORSHUDWLRQDOVWDWH
2UDQJH±6HUYLFH&RQWUROOHULVFRQJHVWHG
5HG±6HUYLFH&RQWUROOHULVFULWLFDOO\FRQJHVWHG

Service Controller 9.6.1-AAA October 12, 2012 Page 167


Chapter 5 Installing and configuring Diameter Network Access Guide

Ingress message queue monitoring and packet coloring


1 The Diameter AAA application tags messages with two colors based on:
a the size of the message queue when the Diameter AAA application
de-queues a message from the ingress message queue for processing. For
details, see Figure 24 on page 167.
b the age of the message, determined by comparing the message age
against the retransmit timeout set in the diaaaad -r option (the -r value is
the same as the retransmit timeout configured on the Diameter client).
Message age relative to retransmit timeout yields the following colors:
- Green: the message age is less than or equal to 3/5 of the retransmit
timeout
- Orange: the message age greater than 3/5 of the retransmit timeout and
less than or equal to 4/5 of the retransmit timeout.
- Red: the message age is greater than 4/5 of the retransmit timeout
2 Whichever of the message queue size and message age state yields the more
critical color is the color given to the message.
Table 61 describes how the Diameter AAA application tags messages.

Table 61: Packet coloring

Message queue size Message age state System congestion state

Green Green Green

Green Orange Orange

Green Red Red

Orange Green Orange

Orange Orange Orange

Orange Red Red

Red Any state Red

Packet coloring and congestion control


Note The Diameter AAA application only applies congestion control processing
to Diameter EAP requests and Accounting-Interim and Stop messages.
The color of each message is a key input for the Diameter AAA application’s
congestion control processing. A message can be tagged with a color that reflects
one of the following systems states:
• Green: no congestion control action needed, the Diameter AAA application
processes the message normally
• Orange: Diameter AAA application is in a congested state, for a new
authentication request or Accounting-Interim message there is a 50% chance
the Diameter AAA application will drop the message

Page 168 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

• Red: the Diameter AAA application is critically congested.


For DER messages:
– for a new authentication session, the Diameter AAA application drops the
message.
– for an in-progress session with leg count equal to 1, there is a 55% chance
the Diameter AAA application drops the message.
– for an in-progress session with leg count equal to 2, there is a 10% chance
the Diameter AAA application drops the message.
– for an in-progress session with leg count greater than 2, the Diameter AAA
application processes the message normally.
For Accounting-Interim and Accounting-Stop messages:
– there is a 60% chance the Diameter AAA application drops the message.
Note If the Service Controller’s pre-allocated memory pool is exhausted, it drops
the newest message and continue until it reaches a stable state.

Accounting records
The Diameter AAA application injects the Accounting-Realtime-Required AVP with
the value set to GRANT_AND_LOSE in all ACA Start messages returned to the
client to indicate to the client to grant service to the subscriber even if the client
cannot deliver accounting records or store accounting records locally.
Note Bridgewater Systems recommends that the Access Node (NAS, ASN-GW)
support the Accounting-Realtime-Required AVP, but support for the
Accounting-Realtime-Required is not required.

Differentiating new from in-progress requests


The congestion control mechanism enables the Diameter AAA application to
differentiate new authentication sessions from in-progress, multi-round
authentication sessions (such as for EAP). When the Diameter AAA application is
overloaded, it can drop the newer sessions in favor of in-progress sessions. The
State AVP is used to tag sessions.
Note To use the congestion control mechanism the Access Node (NAS,
ASN-GW) must support the State AVP.

To configure settings for the congestion control mechanism


Configure congestion control using BWSwsaaa package prompts or by using the
diaaaad command line. To configure congestion control using the command line,
add the -Z and -r options to the diaaaad process.
• -Z configures the expected peak rate of messages per second on the Diameter
AAA application.
– the Diameter AAA application’s ingress message queue is initialized to
twice the value specified by the -Z option.
– Default=1500.

Service Controller 9.6.1-AAA October 12, 2012 Page 169


Chapter 5 Installing and configuring Diameter Network Access Guide

• -r configures the client request retransmit timeout in seconds. The Diameter


AAA application compares the message age against the retransmit timeout to
determine the latency of the message.
– -r must be the same as the retransmit timeout configured on the Diameter
client.
– The timeout on the client indicates the time after which the client
retransmits a request to the Service Controller.
– Default=5 seconds.
For example:
diaaaad -Z 1500 -r 5

diaaaad command line options


Table 62 describes the diaaaad command line options used in /opt/aaasc/config/
dia-aaa/diaaaa.

Table 62: diaaaad command line options

Option Description

-a The Acct-Interim-Interval for DER messages.

-b The Acct-Interim-Interval for ACA messages.

-C The base configuration directory.

-c path The location and filename of the database configuration file.


Default=[Link]

-d dir The application directory [/opt/aaasc/aaa]

-E|D features Enable/Disable one or more of the following features:


(Default = disabled) • ssr—Session State Register
• soap—soap messages between diaaaad and a network node such as an ASN or HA.
This allows diaaaad to send ASR messages to a network node
• multimode—enables 3G/4G interworking

-f Enables an LDAP filter to be configured for device authentications by a WiMAXLocalAA


action. An example filter is: (&amp;(uid={loginname})(objectClass=wimaxHandsetId)).
Note This option must be used together with options -n and -P.

-h The help menu.

-i HA IP address.

-l facility:level Enables debug logging.


Default=LOCAL6

-m The maximum RMS Client Queue size. The range is 1 to 128000.


Default=16000

Page 170 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Table 62: diaaaad command line options (continued)

Option Description

-n Enables an LDAP base DN to be configured for device authentications by a


WiMAXLocalAA action. An example base DN for devices is:
o=handsets,o=wimaxusers,dc=bridgewatersys,dc=com.
Note The -n <dn> -f <f> -P <p> LDAP options must either all be specified or none
specified.

-p The number of proxy response threads and indicates to the diaaaad process to load
[Link].
Add the -p option to the diaaaad process to enable Diameter EAP-TTLS phase 2 proxy
to RADIUS AAA.
If -p is not present, Diameter EAP-TTLS phase 2 proxy to RADIUS AAA is disabled.

-P Enables the LDAP attribute that is used, to store the password for device authentications
by a WiMAXLocalAA action. An example value for the device password is:
abcMobileChapPassword.
Note This option must be used together with options -f and -n.

-q The Session-Time-Out value, in seconds. This value determines the time after which a
subscriber’s session expires and Diameter performs reauthentication.
Default=1800

-r The client request retransmit timeout, in seconds, which the Diameter AAA application
uses to determine the age of a message, relative to the retransmit timeout configured on
the Diameter client.
-r must be the same as the retransmit timeout configured on the Diameter client.
The timeout on the client indicates the time after which the client retransmits a request to
the Service Controller.
Range=1-30
Default=5 seconds.

-R A local RMS cluster ID on the.


The RMS cluster ID specified by -R should match the RMS cluster ID for the HAs
assigned to most subscribers authenticated on a Service Controller.
Not setting a local RMS cluster ID using -R does not disable any functionality, but it can
have a serious impact on performance during subscriber re-authentications.
If no AAA-Session-ID is present and no value is specified for -R, during
re-authentications the queries all configured RMS clusters in numeric order until it finds
the session.

-t N The number of worker threads to run. For information about calculating the required
number of threads, see the Bridgewater Installation Reference Guide.
Default = 10

-T The number of SOAP processing threads.


Default=100

-v Displays the Diameter version

Service Controller 9.6.1-AAA October 12, 2012 Page 171


Chapter 5 Installing and configuring Diameter Network Access Guide

Table 62: diaaaad command line options (continued)

Option Description

-w The number of RMS Client worker threads. The range is 1 to 300.


Default=20

-Z The expected peak rate of messages per second on the Diameter AAA application.
When the congestion control mechanism is enabled the Diameter AAA application’s
ingress message queue is initialized to twice the value specified by the -Z option.
Range=1-10000
Default=1500.

--foreground Do not fork to background (must be the last argument)

Example:
diaaaad -C /opt/aaasc/config -s [Link] -o [Link]
-r 5 -i [Link]

Configuring the RMS


The [Link] file, located in the /opt/aaasc/config/rms directory, defines the local
host name as a client. For information about the [Link] file, see the chapter “RMS
configuration” in the Service Controller: Resource Management Server Guide.
To configure RMS for Diameter do one of the following:
– disable RMS accounting:
ENABLE_ACCNT = FALSE
– create a client record:
$CLIENT_START
CLIENT_HOST <host_name_or_ip_address_of_the_RMS_server>
CLIENT_SECRET MYSECRET
CLIENT_ALLOW_UPDATE true
$CLIENT_END

Starting and stopping the Diameter processes


For changes to the [Link] file to take effect, stop and start the
Bridgewater Diameter Stack and the Diameter AAA application:
/etc/init.d/wsdia stop
/etc/init.d/wsdia start
/etc/init.d/diaaaa stop
/etc/init.d/diaaaa start

Page 172 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

Diameter logging
This section describes:
• Log messages
• Debug messages

Log messages
By default, operational and system log messages for the Diameter AAA application
are written to /var/adm/messages using the Logging Framework with the family
names AAAOP and AAASYS. The system reports Bridgewater Diameter Stack
syslog messages using the DIA log family.
To view a specific log message:
/opt/aaasc/logf/bwslogd -f family -n number
To view all Diameter AAA operational log messages:
/opt/aaasc/logf/bwslogd -f AAAOP
For details, see the Service Controller: Monitoring and Logging Guide.

Debug messages
Configure debug messages for the Diameter AAA application using the
[Link] file, and for the Bridgewater Diameter Stack using the
[Link] file.

Debug messages for Configure debug messages for the Diameter AAA application using the
the Diameter AAA [Link] file, located in /opt/aaasc/config/dia-aaa/.
application The following example shows how to enable debug logs, display all debug
messages, and send the debug messages to syslog. For more information about
debug parameters for the Diameter AAA application, see the [Link]
schema file, located in /opt/aaasc/dia-aaa.

Example [Link]
<Debug>
<EnableDebugging>true</EnableDebugging>
<LogLevel>3</LogLevel>
<EnableConsoleLog>false</EnableConsoleLog>
</Debug>

Service Controller 9.6.1-AAA October 12, 2012 Page 173


Chapter 5 Installing and configuring Diameter Network Access Guide

Debug messages for Configure Debug messages for the Bridgewater Diameter Stack using the
the Bridgewater [Link] file, located in /opt/aaasc/config/dia.
Diameter stack The following example shows how to enable debug logs, provide only high priority
logs, and send log messages to syslog.
For more information about configuring debug messages for the Bridgewater
Diameter Stack, see "DEBUG parameters" on page 139.

Example [Link]
DEBUG
{
LOG_TYPE=syslog
STATISTICS=off
TRACE=on
BUFFER=off
INFO_LEVEL1=on
INFO_LEVEL2=off
INFO_LEVEL3=off
}

Diameter troubleshooting
Protocol errors refer to problems with the underlying protocol that carries Diameter
messages, for example, incorrect routing information or temporary network failure.
Application errors result from the failure of the Diameter protocol.

Error codes
The Diameter protocol shares the same semantics of error code definition as the
HTTP protocol. The return status of a message is identified by the first digit of the
return code:
1xxx—the request cannot be satisfied and additional information is required for the
service to be granted.
2xxx—the request was processed successfully.
3xxx—there was a protocol error when transmitting a Diameter message.
Generally, a Diameter proxy should try to fix this problem by either routing the
message to another Diameter server, or by keeping the message in a local cache
and sending it again later.
4xxx—the requested message cannot be satisfied at the moment, but it might work
in the future. An example is a server that temporarily lacks physical storage space
to handle any incoming requests.

Page 174 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 5 Installing and configuring Diameter

5xxx—there was an application error when the server was processing the request
message. The sender should not try to send the same message again. Instead, the
sender will have to determine the cause of the application error by checking the
error code, and then fix the problem.

Syntax errors
Use the following utility to determine the cause of a problem with the syntax of an
XML configuration file:
/bin/xmllint <xml_config_file>
where:
<xml_config_file> is the name of the file with the problem

Service Controller 9.6.1-AAA October 12, 2012 Page 175


Chapter 5 Installing and configuring Diameter Network Access Guide

Page 176 October 12, 2012 Service Controller 9.6.1-AAA


Managing RADIUS and Diameter

6
Chapter 6
Chapter

dictionaries

This chapter describes how to manage RADIUS and Diameter dictionary files, and
how to configure the files that support the RADIUS and Diameter dictionary
processes.
The topics are:
• Managing RADIUS dictionaries (.DICT)
• Configuring vendor-specific data ([Link])
• Managing Diameter dictionaries

Service Controller 9.6.1-AAA October 12, 2012 Page 177


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Managing RADIUS dictionaries (.DICT)


A common RADIUS dictionary is used by the RADIUS Server for communication
with the NASs, and by the Provisioning Server for defining connection services.
The RADIUS dictionary defines the attribute value pairs that can be contained in a
RADIUS message. The attribute value pairs comprise the majority of the packet
and contain the information that the service provider needs to identify the
subscriber and define the service request.
Common attributes are username and subscriber password, but equipment
vendors extend RADIUS beyond the basic attributes by using vendor-specific
attributes (VSA). The RADIUS server supports multiple dictionaries—one for each
NAS/PDSN vendor.
RADIUS messages identify attributes by numbers. The RADIUS Server uses the
RADIUS dictionary to match the attribute numbers in RADIUS messages with a
data type and a printable name. The attributes must match those in the vendor
dictionary; if they do not, RADIUS rejects the request.
A dictionary loader stored in the middleware service of the Provisioning Server
loads dictionary attributes from the dictionary files. There is a client-side dictionary
cache on the Service Manager client to store dictionaries loaded from the dictionary
loader. The dictionary stored in the cache is referenced when a connection service
profile is created.
The topics in this section are:
• .DICT files
• Custom RADIUS dictionaries

.DICT files
The RADIUS dictionary consists of a set of vendor dictionary files stored as .DICT
files. There is a .DICT file for each NAS vendor. The .DICT file for a vendor lists the
attributes supported for that NAS vendor, including RFC 2865, and vendor-specific
attributes, including TS29.061 GSM attributes.
Table 63 shows the .DICT file parameters.

Table 63: .DICT file parameters

Section Field Value

Header VENDOR <name>

<code>

Page 178 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Table 63: .DICT file parameters (continued)

Normal/Extended Attribute ATTRIBUTE <name>

<code>

<type>

<encryptionType>

<direction>

Enumerated Value VALUE <attribute-name>

<value-name>

<value-code>

Octetstring Sub-Type SUBTYPE <attribute-name>

<sub-type-name>

<sub-type-code>

<type>

SUBTYPE_VALUE <name>

<sub-type-name>

<sub-type-code>

<type>

BITSET <attribute-name>

<sub-type-name>

<bitset-code>

<value>

Table 64 to Table 67 describe the fields in the .DICT file.


The RFC 2865 attributes are listed first, with the header VENDOR [vendor-name]
[vendor-code]. The vendor-code is the SMI Network Management Private
Enterprise Code for the vendor.
The vendor-specific attributes follow the RFC attributes. There is a separate section
for each vendor, with the header START-VSA. This header has the optional
modifiers [vendor-code] [VSA-coder]. The vendor-code is the SMI Network
Management Private Enterprise Code for the vendor and the VSA-coder is the
software module used to encode and decode the vendor-specific attributes. The
supported VSA coders are RFC Coder, USR, and APTIS. If a VSA coder is not
specified, RFC 2865 is used.

Service Controller 9.6.1-AAA October 12, 2012 Page 179


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

STARENT and CISCO There are two versions of the STARENT and CISCO dictionaries. [Link]
dictionaries and [Link] use VSAs with the prefix SN1 and use a standard decoder.
[Link] and [Link] use a custom Starent decoder.
These two dictionaries store the vendor-type field in 2 bytes instead of the standard
1 byte. This allows more than 255 VSAs to be defined for a specific vendor.
During installation of the Service Controller and SDB, the installer must determine
which version of the dictionay to use.
When the BWSaaaco or BWSwsco RPMs or packages are upgraded, be sure to
update the dictionaries in both locations, /opt/aaasc/config/dictionaries and /
WideSpan/config/dictionaries. If the VSAs are not present in both of the
dictionaries, requests are ignored.

Tunnel attributes in Tunnel attributes, such as Tunnel-Type, only display in the Service Manager GUI if
RADIUS dictionaries they are active in the appropriate vendor dictionary. As Figure 25 shows, you
activate a tunnel attribute by adding the modifier “=#T” to a specific attribute’s
value-name.
Typically, these attributes are active upon installation. If they are not, modify the
appropriate tunnel attributes in the vendor dictionary using the format:
Tunnelattribute RADIUSattributenumber Value-name=#T
where
Tunnelattribute is the attribute being activated, such as Tunnel-Type
RADIUSattributenumber is the RFC 2865 number associated with the attribute
Value-name is the type of value required, such as integer
=#T is the modifier that activates the attribute
Figure 25: Active Tunnel attributes in a RADIUS vendor dictionary

Table 64: Normal/extended attribute fields

Field Description

ATTRIBUTE Mandatory field required for each attribute line.


The entry for this field is always ATTRIBUTE.

name Name of the attribute.


For example, User-Name.

Page 180 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Table 64: Normal/extended attribute fields (continued)

Field Description

code Integer assigned to the attribute by the NAS vendor.


The code for an attribute is available from the vendor web site or the
document that shows how attributes for that NAS are encoded.

type The type of data subscribers input for the attribute. The format is
specified in the brackets:
• string (1–255 alphanumeric characters)
• integer (1– 2,147,483,647)
• integer8 (1–255)
• integer16 (1– 65,535)
• integer64 (0–18,446,744,073,709,551,615)
• ipaddr (an IP address in standard notation, with maximum values of
[Link])
• ipv6addr (an IP address in IPv6 notation)
• octetstring
Note An octetstring is composed of one or more sub-types, also known
as sub-attributes. Sub-types are defined in the dictionary using
SUBTYPE entries. Enumerated values for sub-types can be
defined using the SUBTYPE_VALUE entries.

encryption The type of encryption used to encrypt and decrypt the attribute.
Type There are three encryption types:
• rfcmd5
• saltmd5
• none
By default, rfcmd5 encryption is used for the User-Password,
Acc-MN-HA-Secret and CDMA2000-Pre-Shared-Secret attributes.
Saltmd5 encryption is used for the Tunnel-Password attribute.

direction The origin of NAS attributes and their values.


The options are:
• in - attribute is incoming from the NAS
• out - attribute is outgoing from RADIUS; the value of the attribute is
subscriber defined
• both - attribute can come from either the NAS or RADIUS

multiplexity Specifies if the attribute can be defined once or multiple times for the
NAS vendor.
The options are:
• single
• multi

1 An octetstring is composed of one or more sub-types, also known as sub-attributes. Sub-types


are defined in the dictionary using SUBTYPE entries. Enumerated values for sub-types can be
defined using the SUBTYPE_VALUE entries.

Service Controller 9.6.1-AAA October 12, 2012 Page 181


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

The .DICT file also includes lists of enumerated values for the RFC 2865 and
vendor-specific attributes. Enumerated values set options for the attributes that
display in the Service Manager interface when creating a connection service profile.
Only the values specified in the dictionary file are available as options for the
attribute. The enumerated values for the RFC 2865 attributes follow the list of RFC
2865 attributes and the enumerated values for vendor-specific attributes for the list
of attributes for each vendor.
Table 65 lists the enumerated value fields.

Table 65: Enumerated value fields

Field Description

VALUE Mandatory field required for each attribute value line.


The entry for this field is always VALUE.

attribute-name Name of the attribute.


For example, User-Name.

value-name Possible value for the attribute. This value displays as an option on the
connection service form in the Service Manager when creating a
connection service profile.
A list of the possible values for an attribute is supplied by the NAS
vendor.

value-code Integer assigned to the attribute value by the NAS vendor.

Table 66 lists the SUBTYPE fields.

Table 66: SUBTYPE fields

Field Description

VALUE Mandatory field required for each attribute value line.


The entry for this field is always SUBTYPE.

Name Name of the attribute.


For example, 3GPP2-Service-Option-Profile.

sub-type-name For example, Max-Svc-Connections.

sub-type-code For example, 1000.

type For example, integer.

Page 182 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Table 67 lists the SUBTYPE_VALUE fields.

Table 67: SUBTYPE_VALUE fields

Field Description

VALUE Mandatory field required for each attribute value line.


The entry for this field is always SUBTYPE_VALUE.

name For example, 3GPP2-Allowed-Diff-Services-Marking.

sub-type-name For example, Packet-Marking-Flags.

sub-type-code For example, None.

type For example, 0.

Table 68 lists the BITSET fields.

Table 68: BITSET fields

Field Description

VALUE Mandatory field required for each attribute value line.


The entry for this field is always BITSET.

name For example, 3GPP2-Remote-Addr-Table-Index.

sub-type-name For example, Qualifier.

bitset-code For example, 0.

value For example, Exempt-from-PrePaid-accounting.

An excerpt from a sample .DICT file is:


VENDOR NORTEL 562
# ===================================
# Normal / Extended Attribute Section
# ===================================
# ATTRIBUTE <name> <code> <type> <encryptionType>
# <direction> <multiplexity>
# ...

ATTRIBUTE User-Name 1 string none in


single
ATTRIBUTE User-Password 2 string rfcmd5 in
single
ATTRIBUTE CHAP-Password 3 string none in
single
ATTRIBUTE NAS-IP-Address 4 ipaddr none in
single

Service Controller 9.6.1-AAA October 12, 2012 Page 183


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

# IPv6 attributes
ATTRIBUTE NAS-IPv6-Address95ipv6addrnoneinsingle
ATTRIBUTEFramed-Interface-Id96ipv6addrnonebothsingle
ATTRIBUTEFramed-IPv6-Prefix97ipv6addrnonebothmulti

# ==================
# Enum Value Section
# ==================
# VALUE <attribute-name> <value-name>
<value-code>

VALUE Service-Type Login 1


VALUE Service-Type Framed 2
VALUE Service-Type Callback-Login 3
VALUE Service-Type Callback-Framed 4
VALUE Service-Type Outbound 5
VALUE Service-Type Administrative 6
VALUE Service-Type NAS-Prompt 7
VALUE Service-Type Authenticate-Only 8
VALUE Service-Type Callback-NAS-Prompt 9

# =================================
# Vendor Specific Attribute Section
# =================================
# START-VSA [<vendor-code>] [<VSA-coder>]
# ATTRIBUTE ...
# Aptis VSAs
START-VSA 2637 APTIS

ATTRIBUTE CVX-Identification 1 integer none both


multi
ATTRIBUTE CVX-VPOP-Id 2 integer none both
multi
ATTRIBUTE CVX-SS7-Session-Id-Type 3 integer none both
multi
ATTRIBUTE CVX-Radius-Redirect 4 integer none both
multi

#Attributes added in support of the IS-835-B standard.


ATTRIBUTE3GPP2-Remote-Addr-Table-Index71octetstringnoneout
multi
ATTRIBUTE3GPP2-Remote-IPv4-Addr-Octet-Count72octetstringnone
inmulti

# =================================
# Octetstring Sub-Type Section
# =================================
# SUBTYPE <attribute-name> <sub-type-name> <sub-type-code>
<type>

Page 184 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

# BITSET<attribute-name> <sub-type-name> <bitset-code>


<value>

#3GPP2-Service-Option-Profile
SUBTYPE 3GPP2-Service-Option-Profile Max-Svc-Connections
1000 integer
SUBTYPE 3GPP2-Service-Option-Profile Svc-Option-Prf-Code
1001 integer8
SUBTYPE 3GPP2-Service-Option-Profile
Max-Svc-Option-Instances 1002 integer8

BITSET3GPP2-Remote-Addr-Table-IndexQualifier0
Exempt-from-PrePaid-accounting
BITSET3GPP2-Remote-Addr-Table-IndexQualifier1
Summarize-Remote-Addr-Octet-Count

Custom RADIUS dictionaries


The default RADIUS dictionaries, located in /opt/aaasc/dict, are read-only. To add
or modify attributes, create a custom dictionary and add or modify attributes in the
custom dictionary.
Note In a distributed deployment, the RADIUS dictionaries must be modified on
both the Provisioning servers and the RADIUS servers.
To add dictionaries or overwrite default dictionaries, create .DICT files in another
location and reference them in /opt/aaasc/config/dictionaries. During startup, the
new or modified attributes added in the custom dictionary are merged with the
default dictionary.
Note The use of custom dictionaries makes sure that patching does not affect
RADIUS behavior. If the default dictionaries are modified directly, RADIUS
may start, but the modified dictionaries may be overwritten when patches
are applied.

To modify or create a RADIUS dictionary


1 Log on to the server as root.
2 Create (if necessary) and navigate to a location, other than /opt/aaasc/dict, to
store custom dictionary files. For example:
mkdir /opt/aaasc/custom_dict
cd /opt/aaasc/custom_dict
3 Create a new dictionary file.
To modify a default dictionary:
a Copy the default dictionary for that vendor to a new file and open the new
file or editing. For example:
cp /opt/aaasc/dict/[Link] VENDOR_MOD.DICT
vi VENDOR_MOD.DICT

Service Controller 9.6.1-AAA October 12, 2012 Page 185


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

b Make sure the VENDOR <name> <vendor_id> or START-VSA <vsa_id>


fields match those in the default dictionary you want to override.
Note Having the same VENDOR <name> <vendor_id> or START-VSA
<vsa_id> in the custom and default dictionaries allows the new or
modified attributes in the custom dictionary to override the attributes in
the default dictionary.
To create a custom dictionary:
a Create a new vendor dictionary to contain the vendor attributes. For
example:
vi VENDOR_NEW.DICT
b Add the VENDOR <name> <vendor_id> fields for your specific vendor. For
example:
VENDOR NEW_VENDOR_NAME 123
4 Add or modify the applicable attributes.
Note The Attribute field must contain the value ATTRIBUTE.
For a description of the fields, see Table 64 on page 180.
Before deleting an attribute from a .DICT file, use the Service Manager to
remove the attribute from all connection service profiles that include the
attribute. For more information about editing service profiles, see the Service
Manager: Subscriber Provisioning Guide.
Note If an attribute is deleted from a .DICT file but is still in a connection
service profile, the RADIUS Server is not able to authorize access
requests that use that connection service, which can result in a service
outage.
5 If required, modify the enumerated values for any of the attributes. The values
are listed by attribute at the end of the .DICT file.
For a description of enumerated values, see Table 65 on page 182.
6 Save the dictionary and change the ownership to aaasc. For example:
chown aaasc:ws VENDOR_NEW.DICT
Note Bridgewater Systems recommends placing any dictionaries to be
modified in a configuration management system to make sure of proper
version tracking.
7 Edit /opt/aaasc/config/dictionaries and add the path for the custom dictionary:
a Make a backup of the file:
cp -p /opt/aaasc/config/dictionaries /opt/aaasc/config/
dictionaries.<date>
b Open the file for editing:
vi /opt/aaasc/config/dictionaries
c Go to the bottom of the file and add the custom dictionary’s full path:
opt/aaasc/dict/[Link]

Page 186 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
/opt/aaasc/dict/[Link]
...
/opt/aaasc/custom_dict/VENDOR_NEW.DICT
Note: If an attribute is listed in multiple DICT files, the attribute definition in
the last file referenced in /opt/aaasc/config/dictionaries takes
precedence.
8 After adding a new vendor to a RADIUS dictionary, add the new vendor to the
RADIUS ConnectionService of the root Service Classes:
Note The following procedures assume familiarity with launching
entity-specific edit forms from the Service Manager main window. For
more information, see Service Manager: Getting Started Guide for
AAA.
a Open the Service Manager and select the Service tab.
b In the left pane of the Service tab, select the Root Organization.
c Launch the RADIUS ConnectionService Service Class edit form.
d On the Service Profile tab, add the new vendor name to the end of Data
field, separated from the previous dictionary by a semi-colon.
e Click Update.
9 To finalize the dictionary changes, stop and restart the Provisioning server:
/etc/init.d/wsprovs stop
/etc/init.d/wsprovs start
Check the log files to see changes to each attribute that is being merged. For
example:
Jul 31 11:14:36 ewn-anaaa radiusd[486]: [ID 819157
[Link]] NTCE RADSYS(15) HUP signal detected:
reloading configuration data...

Jul 31 11:14:37 ewn-anaaa radiusd[486]: [ID 459686


[Link]] INFO BWDICT(69) /opt/opt/aaasc/custom_dict/
CUSTOM_STARENT.DICT:Vendor STARENT is replacing the
attribute Error-Cause(0:101) and its associated entries
with entry Error-Cause(0:101
10 Restart the trace tool, if being used, to recognize the modified RADIUS vendor
dictionaries.
11 [Optional] Use the RADIUS policy engine test utility (radpet) to specify a test
packet for the appropriate policy engine to verify that RADIUS functions

Service Controller 9.6.1-AAA October 12, 2012 Page 187


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

properly with the modified “inbound” or “both” attributes. Note that radpet does
not test “inbound” attributes.
a Log in as the aaasc user.
b Run the RADIUS Policy Engine Test utility:
/opt/aaasc/radius/radpet -i client-IP -t packet-type -c
dal_conf -d RADIUS_conf attr=val
where
client-IP is the IP address of the NAS or RADIUS Server
packet-type is either auth (access-request) or acct (accounting-request)
dal_conf is database configuration file (default /opt/aaasc/config/[Link])
RADIUS_conf is RADIUS configuration directory (default /opt/aaasc/radius/
config)
attr=val is one or more attribute-value pairs
For example, send the message:
/opt/aaasc/radius/radpet -i [Link] -t auth -c /
opt/aaasc/conf/[Link] -d /opt/aaasc/config/radius
User-Name=Jean
c Verify that the modified dictionary attributes are handled without error.
The new vendor attributes are available for use. Use the Service Manager to add
the attribute(s) to any applicable RADIUS connection service profiles. For
information about editing service profiles, see the Service Manager: Subscriber
Provisioning Guide.

Page 188 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Configuring vendor-specific data ([Link])


The RADIUS and Diameter [Link] file, located in the /opt/aaasc/config/radius
directory, is a mandatory file that defines how RADIUS and Diameter process
vendor attributes into accounting and usage records. It enables different settings
based on the client vendor.
This section describes:
• [Link] overview
• [Link] elements and attributes
• [Link] examples

[Link] overview
Use the [Link] file to define:
• the RADIUS or Diameter attributes, received in a RADIUS Access-Request
message from a NAS, or a Diameter DER message from an ASN, that
comprise a unique port ID
• the RADIUS or Diameter attributes to write to accounting records when a
RADIUS accounting-stop or interim-accounting message, or Diameter ACR is
received, to store service usage data, and to generate correlated accounting
records
The [Link] file is created at installation and includes vendor entries for major
NAS and ASN vendors for the RADIUS and Diameter Server. Every NAS and ASN
vendor must have an entry in the [Link] file. A default vendor and model can
be specified in the [Link] file.
To store the MDN in the Class Attribute, the [Link] file must be configured to
support the Class Attribute, and the Class Attribute must be specified in the
AcctRecord Attributes field. For more information, see "Configuring SIP Server
Interworking" on page 67.

RADIUS [Link] The RADIUS [Link] schema contains these elements:


schema VendorConfiguration: the root element
Vendor
PortIDAttributes
Attribute
SessionIDAttributes
Attribute
SessionRecovery Attributes
Attribute
AcctRecordAttributes
Attribute
AcctStartAttributes
Attribute
AcctStopAttributes

Service Controller 9.6.1-AAA October 12, 2012 Page 189


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Attribute
Attribute
SupportedEAPTypes
EAPType
LockoutConfig
StoredSession Attributes
Attribute
ValidateEquipID
WLAN
APN2WAPN

Diameter The Diameter [Link] schema contains these elements:


[Link] schema VendorConfiguration: the root element
Vendor
AcctRecordAttributes
Attribute
AcctStartAttributes
Attribute
AcctStopAttributes
Attribute
Attribute
SupportedEAPTypes
EAPType

[Link] elements and attributes


This section describes the elements and attributes of the [Link] file.

VendorConfiguration The root element that encloses optional Vendor entries. If no Vendor elements are
defined, the DefaultVendor attribute must be specified.
For example:
<VendorConfiguration DefaultVendor=”RFC2138”>
<Vendor ... />
</VendorConfiguration>

Table 69: VendorConfiguration attributes

Attribute Value Description

DefaultVendor String The active Vendor entry to use for unidentified NASs or ASNs. Optional.
Default (RADIUS) =
RFC2138
Default (Diameter) =
SAMSUNG

Page 190 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Table 69: VendorConfiguration attributes (continued)

Attribute Value Description

DefaultModel String The active Vendor entry to use, in conjunct with the DefaultVendor, for
unidentified NASs.
Optional.

Vendor A NAS vendor, based on a vendor name and model name. The VendorName and
ModelName combination must be unique. If no Vendor elements are defined, the
DefaultVendor attribute must be specified in the VendorConfiguration root element.
This element may enclose these optional child element:
• PortIDAttributes
• SessionIDAttributes
• SessionRecoveryAttributes
• AcctRecordAttributes
• AcctStartAttributes
• AcctStopAttributes
• Attribute
• SupportedEAPTypes
• EAPType
• LockoutConfig
• StoredSessionAttributes
• ValidateEquipID
All attributes are optional except VendorName.
Child element of the VendorConfiguration.
For example:
<Vendor VendorName=”USR” DuplicateDetection=”N”>
<PortIDAttributes ... />
<SessionRecovery Attributes ... />
<AcctRecordAttributes ... />
<AcctStartAttributes ... />
<AcctStopAttributes ... />
<SupportedEAPTypes ... />
</Vendor>

Table 70: Vendor attributes

Attribute Value Description

VendorName String (1 to 20 Name of the NAS vendor. Must match the vendor name selected for NASs in the
characters) Service Manager.
Required.

Service Controller 9.6.1-AAA October 12, 2012 Page 191


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Table 70: Vendor attributes (continued)

Attribute Value Description

ModelName String (1 to 20 Defines a NASmodel for each vendor. Must match the vendor model selected for
characters) NASs in the Service Manager.
If this attribute is not set, the entry applies to all models for the specified NAS
vendor.
Optional.

ClassAttribute • Y (default) The NAS supports the use of the RADIUS Class attribute.
• N Set to Y for:
• SIP Server Interworking. For more information, see "Configuring SIP Server
Interworking" on page 67.
• Prepaid data support. For more information, see "Configuring user and network
lockout" on page 38.
• CDMA2000 max sessions access control support
• Generating Correlation ID. For more information, see "Configuring
vendor-specific data ([Link])" on page 189.
• IS835-C prepaid support
If the NAS does not support the Class attribute, it uses a RADIUS Session ID. The
Resource Management Server deletes idle sessions.
Set to Y if devices (NAS/PDSN) that support the Class attribute are in use.
Set to N if devices that do not support the Class attribute are in use.

MultipleClass • Y Set to “Y” to support multiple instances of the class (25) attribute.
Attributes • N (default) This attribute only accepts a value of “Y” when the attribute
UseBWSClassEncoding is set to “Y”.

MaxAttribute If The maximum segment size for segmented class (25) attributes before applying
SegmentSize Base64ClassAttrib additional encoding.
ute is enabled:
• 126 (default)
• 64–126
Otherwise:
• 253 (default)
• 64–253

Base64Class • Y This must be "N" if ClassAttribute is "N".


Attribute • N (default) Set to “Y” if the device does not support the binary class attribute as per the
RADIUS RFC.
Note This may not work for all deployments.

Page 192 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Table 70: Vendor attributes (continued)

Attribute Value Description

UseBWSClass • Y (default) Enables RADIUS to send a NAS device a non-encoded value for the Class
Encoding • N attribute. The non-encoded value can only be configured in the Service Manager
GUI or in the [Link] file.
For information about using the Service Manager GUI, see the section “RADIUS
Connection Services” in the Service Manager: Services Provisioning Guide for AAA
For information about configuring the [Link] file, see "Configure
[Link]" on page 89.
Set to “N” if the NAS device needs to receive and interpret a non-encoded value for
the Class attribute.
Note Only set to “N” for authorization-only devices. Setting
UseBWSClassEncoding to “N” for a device that sends authorization and
accounting requests prevent accounting features that rely on encoded Class
data from working.
These accounting features are disabled if set to “N”:
• IS-835C prepaid support (not available)
• DNS updates via RADIUS (not available)
• CDMA based SSR sessions (won’t include PP-Rating-Type)
• CDMA based subscriber session limits using RMS (not available)
• Class data returned from a remote’s Access-Accept (are not forwarded to the
client)
• proxy accounting (accounting requests are not forwarded to proxy targets)
These accounting features work differently or need modification if set to “N”:
• subscriber entity ID (not stored in the Class attribute). The Service Controller
performs database lookups for Acct-Interim and Stop requests to complete the
accounting record.
• Pending correlation (include SessionIDAttributes in [Link])
• Dial-up based subscriber session limits (configure SessionIDAttributes in
[Link] so RADIUS can create a session in the Resource Management
Server)

AcctUsingRMS • Y Enables the accounting record population to be modified by RMS-based product


Info • N (default) behavior when the Class attribute is not supported.

Duplicate • Y The RADIUS Server uses the Request-Identifier attribute, in addition to IP Address
Detection • N (default) and port, to detect duplicate requests, as described in the RADIUS-v2 RFC.
• Set to Y for most NAS vendors.
• Set to N for Redback NASs.
Note Also configure the DuplicateDetection element in [Link] to enable
the RADIUS Server to process duplicate request messages. For more
information, see "DuplicateDetection" on page 17.

PortID • Y (default) The PortID is required by the RADIUS Server for the NAS.
Mandatory • N

ServiceClass String (1–80 The service class name to be used for connection services.
Selection characters)

Service Controller 9.6.1-AAA October 12, 2012 Page 193


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Table 70: Vendor attributes (continued)

Attribute Value Description

AccessControl • Y (default) An access control service class is used for this NAS vendor and model.
Enabled • N Set to Y for most NAS vendors.

AccessControl String (1–80 The service class name to use for access controls.
ServiceClass characters) This parameter is used only if AccessControlEnabled is set to Y.
Default =
AccessControl

WriteAcct • Y Specifies whether or not the RADIUS Server writes an accounting-pending record
PendingRecord • N when it authenticates a session.
Set this attribute to Y.
By default, no accounting record is written.

AcctPending Integer (0– A type value for accounting pending records.


RecordType 2147483647) Do not change the default.
Default = 0

WriteAcctStart • Y The RADIUS Server writes an accounting-start record when a session starts. If this
Record • N attribute is not specified, the accounting record is written only if its backup method
is ‘C’ (collate). Otherwise, an accounting record is not written. If writing a record of
type ACCT-START is enabled, a valid value must be specified.
Optional.

AcctStart Integer (0– A type value for accounting-start records.


RecordType 2147483647) Do not change the default for NAS vendors.
Default = 1

WriteAcctStop • Y Specifies whether or not the RADIUS Server writes an accounting-stop record
Record • N when a session ends.

AcctStop Integer (0– A type value for accounting-stop records.


RecordType 2147483647) Do not change the default for NAS vendors.
Default = 2

WriteAcct • Y (default) The RADIUS Server writes interim accounting records when it receives interim
InterimRecord • N accounting messages from the NAS.

AcctInterim Integer (0– A value to use for interim accounting records.


RecordType 2147483647)
Default = 3

WriteAcct • Y Specifies whether or not a record of type ACCT-TUNNEL-START is written. If


TunnelStart • N (default) enabled, a valid value must be specified for AcctTunnelStartRecordType.
Record

AcctTunnelStart Integer (0– A positive integer value to be written for a record of type ACCT-TUNNEL-START.
RecordType 2147483647) This value is written only if WriteAcctTunnelStartRecord is enabled.
Default = 9

Page 194 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Table 70: Vendor attributes (continued)

Attribute Value Description

WriteAcct • Y Specifies whether or not a record of type ACCT-TUNNEL-STOP is written. If


TunnelStop • N (default) enabled, a valid value must be specified for AcctTunnelStopRecordType.
Record

AcctTunnelStop Integer (0– A positive integer value to be written for a record of type ACCT-TUNNEL-STOP.
RecordType 2147483647) This value is only written if WriteAcctTunnelStopRecord is enabled.
Default = 10

WriteAcct • Y Specifies whether or not a record of type ACCT-TUNNEL-REJECT is written. If


TunnelReject • N (default) enabled, a valid value must be specified for AcctTunnelRejectRecordType.
Record

AcctTunnel Integer (0– A positive integer value to be written for a record of type ACCT-TUNNEL-REJECT.
Reject 2147483647) This value is only written if WriteAcctTunnelRejectRecord is enabled.
RecordType Default = 11

WriteAcct • Y Specifies whether or not a record of type ACCT-TUNNEL-LINK-START is written. If


TunnelLink • N (default) enabled, a valid value must be specified for AcctTunnelLinkStartRecordType.
StartRecord

AcctTunnel Integer (0– A positive integer value to be written for a record of type
LinkStart 2147483647) ACCT-TUNNEL-LINK-START. This value is only written if
RecordType Default = 12 WriteAcctTunnelLinkStartRecord is enabled.

WriteAcct • Y Specifies whether or not a record of type ACCT-TUNNEL-LINK-STOP is written. If


TunnelLink • N (default) enabled, a valid value must be specified for AcctTunnelLinkStopRecordType.
StopRecord

AcctTunnel Integer (0– A positive integer value to be written for a record of type
LinkStop 2147483647) ACCT-TUNNEL-LINK-STOP. This value is only written if
RecordType Default = 13 WriteAcctTunnelLinkStopRecord is enabled.

WriteAcct • Y Specifies whether or not a record of type ACCT-TUNNEL-LINK-REJECT is written.


TunnelLink • N (default) If enabled, a valid value must be specified for AcctTunnelLinkRejectRecordType.
RejectRecord

AcctTunnelLink Integer (0– A positive integer value to be written for a record of type
RejectRecord 2147483647) ACCT-TUNNEL-LINK-REJECT. This value is only written if
Type Default = 14 WriteAcctTunnelLinkRejectRecord is enabled.

Service Controller 9.6.1-AAA October 12, 2012 Page 195


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Table 70: Vendor attributes (continued)

Attribute Value Description

AcceptBadAcct • Y Specifies whether or not the RADIUS Server accepts accounting-request messages
Authenticator • N (default) with bad Authenticator values.
For most NAS vendors, set this value to N. In this case, the RADIUS Server silently
discards the accounting-request.
Set this parameter to Y only if a specific NAS vendor is known to calculate the
authenticator field incorrectly. In this case, the RADIUS Server treats an
accounting-request like a valid accounting-request. This poses a security risk. This
also causes a discrepancy in SNMP accounting metrics: Response and
BadAuthenticator metrics are both incremented.
If the RADIUS Server receives an Accounting-Request message with a bad
authenticator value, it generates a warning syslog message and increments the
radiusAccServTotalBadAuthenticators and radiusAccServBadAuthenticators
metrics for the client. This error can be caused by misconfigured shared secrets or
by a problem with the NAS firmware.

CallCheck • Y RADIUS should reserve a session within Resource Management Server during
Session • N (default) Call-Check (Pre-Auth) request. If the value is set to Y, RADIUS creates a generic
Reservation session in RMS during Call-Check (Pre-Auth).
All session limits, except session limit per user, are checked. RADIUS updates the
generic session with the subscriber session data during authentication.

CallingStationID String A regular expression used to extract the real Calling-Station-Id value from the
RegExp pseudo value found in the Radius Calling-Station-Id attribute. The vendor may pad
this attribute's value with extra characters, or remove extra padding.

TaggedTunnel • Supported Specifies whether or not RADIUS sends the tunnel attribute with the tag value
Attribute (default) provisioned in the Service Manager.
• Never • "Supported"—the tunnel attribute index is based on the setting of the
• Always useTagIndex action in accessReqPolicy.
• "Never"—the tunnel attribute index is always 0.
• "Always"—the tunnel attribute index is based on the value provisioned in the
Service Manager.

EAPFragment Integer (128– The fragment size of the EAP-Message supported per RADIUS packet.
Size 2147483647) Do not exceed half the RADIUS packet size (1/2 x 4096 = 2048) so as to
Default = 1500. accommodate other attributes.

Write • Y Specifies whether or not the Service Controller generates the Correlation ID.
CorrelationID • N (default) WriteCorrelationID can be configured for each vendor in the vendors file.
To generate the Correlation ID, this element must be set to “Y”.

WritePolicy • Y (default) • Y—RADIUS writes the policy action type into the RADIUSATTR field of the
ActionType • N accounting record. This field is used by downstream accounting to route
accounting records based on the access technology (for example, GSM or
CDMA).
• N—RADIUS does not write the policy action type into the accounting record.

PPQAPoolAttr String The Prepaid Quick-Access Pool Attribute defines the name of a RADIUS attribute
Default = that is included in all Access-Accept messages from a rejecting SurePay prepaid
”Framed-Pool” server when the Quick-Access feature is enabled.

Page 196 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Table 70: Vendor attributes (continued)

Attribute Value Description

PPQAPoolAttr String (1–253 The Prepaid Quick-Access Pool Attribute Value may be provisioned to override the
Value characters) value of QAPoolID in [Link] (if provisioned). This value is assigned to the
RADIUS attribute defined by PPQAPoolAttr when the Quick-Access feature is
enabled.

Strip • Y • Y—RADIUS strips all Bridgewater VSA attributes from outgoing Access-Accept
Bridgewater • N (default) messages.
VSAs • N—RADIUS does not strip Bridgewater VSA attributes from outgoing
Access-Accept messages.

CSIDDecode • ASCII Instructs RADIUS to assume the contents of the CSID attribute are encoded in
Method • HEX either ASCII or HEX for the specified vendor.
• Undefined Options are:
(Default)
• ASCII: RADIUS assumes the contents of the CSID are encodes in ASCII
• HEX: RADIUS assumes the contents of the CSID are encoded in HEX
• Undefined: (default) RADIUS does not make any assumption about the CSID
encoding and processes the CSID normally
Note If LengthBasedCSIDDecode is configured in [Link] and
CSIDDecodeMethod is configured in [Link] on the same server, the
action specified in [Link] overrides the action specified by
[Link].

PortIDAttributes The RADIUS attributes that the RADIUS Server writes to the Port field in
accounting records to uniquely identify the NAS port.
This element encloses one or more Attribute child element.
Child element of a Vendor element.
Optional.
For example:
<PortIDAttributes>
<Attribute>NAS-Port</Attribute>
<Attribute>Chassis-Call-Channel</Attribute>
<Attribute>Chassis-Call-Span</Attribute>
</PortIDAttributes>

SessionIDAttributes The attributes which can be used to generate IDs for:


• an RMS session ID used to communicate with RMS
• a Correlation ID used to correlate accounting records
This element is interpreted in different ways depending on: the type of ID, and the
Class attribute setting.
Child element of a Vendor element.
Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 197


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Table 71 describes the dependencies.

Table 71: Session ID dependencies

Class attribute
Type of ID Description
setting

RMS session ID for enabled The SessionIDAttributes element is ignored as RMS provides RADIUS with a
dial-up session Session ID.

disabled SessionIDAttributes must be specified to communicate with RMS. These


attributes must be available in the Authentication-Request, Accounting-Start,
Accounting-Interim, and Accounting-Stop.

RMS session ID for enabled The SessionIDAttributes must be available in both Accounting-Start and
CDMA session Accounting-Stop. If they are not specified, then the ClientID and
Acct-Session-ID are used by default.

disabled RADIUS does not communicate with RMS.

Correlation ID used to enabled The SessionIDAttributes element is optional. If it is configured, RADIUS


correlate accounting generates the Correlation ID using the listed attributes. If it is not configured,
records RADIUS generates the Correlation ID based on the RADIUS IP address, the
process ID, the start time of the RADIUS thread handling the request, the
thread ID, and a thread counter.
Bridgewater Systems recommends that this element not be configured.
Configuring this element for this feature may result in duplicate Correlation IDs
generated for accounting records among multiple sessions if the wrong
attributes are chosen.

disabled The SessionIDAttributes element is required. RADIUS generates the


Correlation ID using the listed attributes.

The SessionIDAttributes element encloses one or more Attribute child element.


For example:
<SessionIDAttributes IncludeClientIP=”Y”>
<Attribute>User-Name</Attribute>
</SessionIDAttributes>

Table 72: SessionIDAttributes attributes

Attribute Value Description

IncludeClientIP • Y Specifies whether or not the client IP address is included in the Session ID.
• N (Default) RADIUS searches for attributes in the following order:
• Framed-IP-Address
• IPv6-Prefix
• IPv6 Interface ID

Page 198 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Table 72: SessionIDAttributes attributes (continued)

Attribute Value Description

IncludeUserIP • Y Specifies whether or not the subscriber IP address is included in the Session
• N (Default) ID.
RADIUS searches for attributes in the following order:
• NAS-IPv6-Address
• NAS-IP-Address
• UDP Source IP Address of the request

Normalize • Y When set to Y, specifies to normalize all strings used to build the session ID.
• N (Default) When set to Y, all alphabetic characters are transformed to uppercase, and
the punctuation characters '.', ':', and '-' are removed.
Note If there are existing sessions with a state of InUse and you set
Normalize to Y, new session IDs might have a different value from
existing session IDs. This issue is resolved by the RMS audit, which
removes existing sessions (configured in the /opt/aaasc/config/rms/
[Link] file).
Optional.

SessionRecovery A list of attributes used to enable session collision recovery.


Attributes For CDMA2000, the session recovery attributes must be in both the
Accounting-Start and Accounting-Stop.
For non-CDMA2000, the session recovery attributes must be available in the
Authentication-Request, Accounting-Start, and Accounting-Stop.
Child element of a Vendor element.
Optional.
For example:
<SessionRecoveryAttributes>
<Attribute>NAS-IP-Address</Attribute>
<Attribute>Nas-Port</Attribute>
</SessionRecoveryAttributes>

Table 73: SessionRecoveryAttributes attributes

Attribute Value Description

IncludeClientIP • Y Specifies whether or not the client IP address is included.


• N (Default)

IncludeUserIP • Y Specifies whether or not the subscriber IP address is included.


• N (Default)

Service Controller 9.6.1-AAA October 12, 2012 Page 199


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Table 73: SessionRecoveryAttributes attributes (continued)

Attribute Value Description

Normalize • Y When set to Y, normalize all strings used to build the session recovery ID.
• N When set to Y, all alphabetic characters are transformed to uppercase, and
Default=N the punctuation characters '.', ':', and '-' are removed.
Note If there are existing sessions with a state of InUse and you set
Normalize to Y, new session IDs might have a different value from
existing session IDs. This issue is resolved by the RMS audit, which
removes existing sessions (configured in the /opt/aaasc/config/rms/
[Link] file).
Optional.

AcctRecordAttributes The attributes that the RADIUS Server writes to accounting records. The RADIUS
Server writes to the RADIUSATTR field.
To store the MDN in each accounting record, the Class attribute must be configured
as “Class”.
The Class attribute ID is 25. The MDN value is stored against Attribute ID 25 in the
RADIUSATTR field of the accounting record. For example, 25=1234567890.
This element encloses one or more Attribute child element
Child element of a Vendor element.
Optional.
For example:
<AcctRecordAttributes>
<Attribute>User-Name</Attribute>
</AcctRecordAttributes>

AcctStartAttributes The attributes that the RADIUS Server write to an accounting start record. The
RADIUS Server writes to the STARTATTR field.
Attribute elements are used to define attributes in the list.
This element encloses one or more Attribute child element.
Child element of a Vendor element.
Optional.
<AcctStartAttributes>
<Attribute>User-Name</Attribute>
</AcctStartAttributes>

AcctStopAttributes The attributes that the RADIUS Server write to an accounting stop/interim record.
The RADIUS Server writes to the RADIUSATTR field.
Attribute elements are used to define attributes in the list.
This element encloses one or more Attribute child element.

Page 200 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Child element of a Vendor element.


Optional.
For example:
<AcctStopAttributes>
<Attribute>User-Name</Attribute>
</AcctStopAttributes>

Attribute One or more Attribute elements may be specified.


Child element of a Vendor element, as well as the child element of PortIDAttributes,
SessionIDAttributes, SessionRecovery Attributes, AcctRecordAttributes,
AcctStartAttributes, AcctStopAttributes, or StoredSession Attributes elements.
Optional.
For example:
<SessionRecoveryAttributes>
<Attribute>NAS-Port</Attribute>
</SessionRecoveryAttributes>

SupportedEAPTypes A list of EAP types that are supported by the vendor. EAPType elements are used
to define EAP types in the list.
The list of EAPTypes specifies the order in which RADIUS/Diameter tries to
negotiate an EAP type with the client to authenticate the subscriber.
By default, all EAP types are supported.
This element encloses one or more EAPType child element.
Child element of a Vendor element.
Optional.
For example:
<SupportedEAPTypes>
<EAPType>MD5</EAPType>
</SupportedEAPTypes>

EAPType The name of an EAP type to include in the list of supported EAP types. The type is
used for the first or second phase of PEAP. Valid EAP types are:
• MD5
• LEAP
• PEAP
• TLS
• TTLS
• MSCHAPv2 (along with PEAP)
• EAP-AKA

Service Controller 9.6.1-AAA October 12, 2012 Page 201


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

One or more EAPType elements may be specified.


Child element of SupportedEAPTypes.
For example:
<EAPType>MD5</EAPType>

LockoutConfig The representative user and connection service to be used after an account is
locked out, and the type and action of the lockout. For more information about the
subscriber lockout feature and how to configure it, see "Configuring Prepaid Data"
on page 42. For a description of lockout parameters in [Link], see
"UserLockout" on page 10.
Child element of a Vendor element.
Optional.
For example:
<LockoutConfig
AcceptLoginName=”Admin”
AcceptDomain=”[Link]”
LockoutOnUserAccept=”Y”
LockoutOnAuthorizeOnly=”Y”/>

Table 74: LockoutConfig attributes

Attribute Value Description

AcceptLoginName String The login name of the representative user that is used to authorize
locked-out users.
Required.

AcceptDomain String The domain name of the representative user that is used to authorize
locked-out users.
Required.

AcceptConnectionService String The RADIUS Connection Service that is applied to locked-out users.
Profile Default = Required if LockoutOnUserAccept is set to “Y”.
DEFAULT

LockoutOnUserAccept • Y, y • N (n)— Lockout is based on authentication or authorization failures


• N, n (default) (user lockout).
• Y (y)—Lockout is based on authentication or authorization successes
(network lockout). RADIUS will ignore the allowLockedoutUsers
action modifier in the accessReqPolicy file.

LockoutOnAuthorizeOnly • Y, y • N (n)—Lockout monitoring is done during the authentication process.


• N, n (default) • Y (y)—Lockout monitoring is done during the authorization process.

Page 202 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

StoredSession The base set and optional attributes that the RADIUS Server stores, for each
Attributes session, in the Session Database in SSR mode. These attributes (shown in
Table 75 and Table 76 on page 204) are ignored for all other sessions. You can
reduce session storage requirements by configuring only those attributes that are
required for each vendor in your network.
Child element of a Vendor element.
Optional.

Table 75: Base set of StoredSessionAttribute parameters in SSR sessions

Attribute CDMA WiMAX

CurrentSessionState Yes Yes

Domain Yes Yes

SessionId Yes Yes

SessionType Yes Yes

StateChangeTime Yes Yes

Timestamp Yes Yes

User-Name (1) Yes Yes

Acct-Session-Id (1) Yes (Optional attribute only)

Billing ID Yes

Called-Station-Id (1) Yes

Correlation ID Yes

Framed-IP-Address (1) Yes

Login Name Yes

NAS IP Address (1) Yes

NAS Port (1) Yes

SessionRecoveryId Yes

Protocol Yes

Pseudo ID Yes

UserIpAddr Yes

1 These base attributes are included in the RADIUS message. If these base attributes are spec-
ified as (optional) stored session attributes, the RADIUS Server does not start and the system
generates an error message.

Service Controller 9.6.1-AAA October 12, 2012 Page 203


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Table 76: Optional StoredSessionAttribute parameters in SSR sessions

Attribute CDMA WiMAX

Acct-Session-Id (Included in base set) Yes

AAAServerIpAddr Yes

Calling-Station-Id Yes

When RADIUS creates an SSR session, it stores the base attributes and all other
attributes that are present in the accounting start message. If an attribute is
configured, but is not present in the accounting start message, it is not stored. If a
configured attribute is repeated in an accounting start message, the first instance is
stored in the SSR session.
The list of stored session attributes must obey the following rules:
• Attributes must not be specified more than once. Duplicate attributes cause an
error to be logged, and the RADIUS Server fails to load.
• Base attributes (shown in Table 75 on page 203) are always present and
cannot be configured separately as stored session attributes. An error is logged
and the RADIUS Server fails to load if the base attributes are specified as
stored session attributes.
• Stored session attributes must be either:
– valid RADIUS dictionary attributes, defined in the vendor dictionary
– one of the RMS attributes RadiusIpAddress or SourceIpAddress
Unidentified attributes cause an error to be logged, and the RADIUS Server
fails to load. For more information about vendor dictionary files, see ".DICT
files" on page 178.
• Attribute and vendor identifiers longer than 2 bytes are not supported for SSR
sessions. If these are specified, an error is logged, and the RADIUS Server fails
to load.
If the StoredSessionAttribute element is not defined, the following default attributes
are configured:
• Calling-Station-Id
• SourceIpAddress
• 3GPP2-PCF-IP-Addr
• RadiusIpAddress
• 3GPP2-Correlation-Id
• 3GPPS-HA-IP-Address
• 3GPP2-BSID
• 3GPP2-IP-Tech
• 3GPP2-Always-ON
The StoredSessionAttribute element encloses one or more Attribute child element.

Page 204 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

For example:
<StoredSessionAttributes>
<Attribute>3GPP2-BSID</Attribute>
<Attribute>3GPP2-IP-Tech</Attribute>
<Attribute>3GPP2-PCF-IP-Addr</Attribute>
</StoredSessionAttributes>

ValidateEquipID The attributes of hardware IDs to be validated.


The ValidateEquipID element takes one or more of the following attributes:
• ProvisionedESN
• ProvisionedMEID
• HRPDEquipIDService
Child element of a Vendor element.
Optional.
For example:
<ValidateEquipID
ProvisionedESN="Calling-Station-Id"
ProvisionedMEID="Calling-Station-Id"
HRPDEquipIDService="HRPDServiceProfile"/>

WLAN The WLAN configuration items for a vendor.


The WLAN element encloses one or more of the following attributes:
• APNAttr
• QoSAttr
• ChargingCharacteristicAttr
• ChargingCharacteristicAttr
• IMSIAttr
• MSISDNAttr
• APNNIAttr
• APNOIAttr
This WLAN element encloses one (and only one) APN2WAPN child element.
Child element of a Vendor element.
Optional.
For example:
<WLAN
APNAttr="Calling-Station-Id"
QoSAttr="HLR-QoS-Profile"
ChargingCharacteristicAttr="3GPP-Charging-Characteristics"
IMSIAttr="Vendor-IMSI"

Service Controller 9.6.1-AAA October 12, 2012 Page 205


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

MSISDNAttr="Vendor-MSISDN"
APNNIAttr="Vendor-APN"
APNOIAttr="Vendor-APN-OI"/>/>

Table 77: WLAN attributes

Attribute Value Description

APNAttr String The RADIUS attribute name that the RADIUS client uses to transmit the APN
1-255 characters address.
The attribute must be in the vendor dictionary.
The attribute must be a string.
Optional.

QoSAttr String The RADIUS attribute used to send back a GPRS QoS profile associated with the
1-255 characters requested APN.
The attribute must be in the vendor dictionary.
The attribute must be a string.
Optional.

ChargingCharacteri String The RADIUS attribute used to send back the Charging Characteristic values
sticAttr 1-255 characters associated with the requested APN.
The attribute must be in the vendor dictionary.
The attribute must be a string.
Optional.

IMSIAttr String The RADIUS attribute the RADIUS server uses to return the IMSI.
1-255 characters The attribute must be in the vendor dictionary.
The attribute must be a string.
Only use IMSIAttr if the client does not support CUI.
Optional.

MSISDNAttr String The RADIUS attribute the RADIUS server uses to return the MSISDN.
1-255 characters The attribute must be in the vendor dictionary.
The attribute must be a string.
Only use MSISDNAttr if the client does not support CUI
Optional.

APNNIAttr String The RADIUS attribute the RADIUS server uses to return the APN Network
1-255 characters Identifier.
The attribute must be in the vendor dictionary.
The attribute must be a string.
Optional.

APNOIAttr String The RADIUS attribute the RADIUS server uses to return the APN Operator
1-255 characters Identifier.
The attribute must be in the vendor dictionary.
The attribute must be a string.
Optional.

Page 206 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

APN2WAPN The function to be used for mapping APNs (retrieved from an HLR) to a standard
WAPN format.
The APN2WAPN element encloses one or more of the following attributes:
• APNRegEx
• WAPNFormat
Child element of a WLAN element.
Optional.
For example:
<APN2WAPN
APNRegEx="(.*)\.(mnc[0-9]+)\.(mcc[0-9]+).*"
WAPNFormat="${1}.w-apn.${2}.${3}.[Link]"/>

Table 78: APN2WAPN attributes

Attribute Value Description

APNRegEx String A POSIX regular expression. Used to characterize a GPRS APN.


Required.

WAPNFormat String The WAPN format applied to the APN.


Required.

[Link] examples
This section provides example for:
• RADIUS [Link]
• Diameter [Link]

RADIUS [Link] This is an example configuration for a USR NAS.


The RADIUS [Link] file is located in the /opt/aaasc/config/radius directory.
<VendorConfiguration>
<Vendor
VendorName=”USR”
DuplicateDetection=”N”>
<PortIDAttributes>
<Attribute>NAS-Port</Attribute>
<Attribute>Chassis-Call-Channel</Attribute>
<Attribute>Chassis-Call-Span</Attribute>
</PortIDAttributes>
<SessionRecoveryAttributes>
<Attribute>NAS-IP-Address</Attribute>
<Attribute>Nas-Port</Attribute>
</SessionRecoveryAttributes>

Service Controller 9.6.1-AAA October 12, 2012 Page 207


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

<AcctRecordAttributes>
<Attribute>User-Name</Attribute>
</AcctRecordAttributes>
<AcctStartAttributes>
<Attribute>User-Name</Attribute>
</AcctStartAttributes>
<AcctStopAttributes>
<Attribute>User-Name</Attribute>
</AcctStopAttributes>
<SupportedEAPTypes>
<EAPType>LEAP</EAPType>
<EAPType>MD5</EAPType>
<EAPType>MSCHAPv2</EAPType>
<EAPType>PEAP</EAPType>
<EAPType>TLS</EAPType>
<EAPType>TTLS</EAPType>
</SupportedEAPTypes>
</Vendor>
</VendorConfiguration>

Diameter This is an example configuration for a Samsung ASN.


[Link] <VendorConfiguration DefaultVendor="SAMSUNG">
<Vendor VendorName="SAMSUNG" EAPFragmentSize="1500">
<AcctRecordAttributes>
<Attribute>Calling-Station-Id</Attribute>
</AcctRecordAttributes>
</Vendor>
</VendorConfiguration>

Page 208 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Managing Diameter dictionaries


The Diameter dictionary defines the attribute value pairs that can be contained in a
Diameter message. The attribute value pairs comprise the majority of the packet
and contain the information that the service provider needs to identify the
subscriber and define the service request.
Common attributes are subscribername and subscriber password, but equipment
vendors extend Diameter beyond the basic attributes by using vendor-specific
attributes (VSA). The Bridgewater Diameter Stack and the Diameter AAA
application support a unified dictionary, [Link], that comprises all
Diameter vendors and VSAs.
Diameter messages identify attributes by numbers. The Diameter AAA application
and the Bridgewater Diameter Stack match the attribute numbers in Diameter
messages with a data type and a printable name. The attributes must match those
in the dictionary. If the incoming attributes don’t match those in the dictionary,
Diameter ignores the request. If the outgoing attributes don’t match those in the
dictionary, Diameter rejects the request.
Make disparate groups of AVPs available to specific vendors by combining various
vendors’ AVPs in the [Link] file. For example, combine
SAMSUNG AVPs and MICROSOFT AVPs and make them available to the
Samsung vendor.
The Diameter dictionary process relies on the following files:
• [Link]
• [Link]
• [Link]
• [Link]

Service Controller 9.6.1-AAA October 12, 2012 Page 209


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Figure 26: The files used in the Diameter dictionary process

GLFWLRQDU\YHQGRUGHILQLWLRQV[PO
DDDSURYVHUYLFH[PO FRPELQHYHQGRU$93VVXFKDV
6$0681* 6$0681*%$6(
GHILQHWKHGLFWLRQDU\XWLOLW\DQGSRLQWWRWKH
GLFWLRQDU\YHQGRUGHILQLWLRQV[POILOH

GLD'LFWLRQDU\[PO
DOOYHQGRUVDQG$93V
%$6( 5)&
:L0$;
0,&5262)7
'LFWLRQDU\XWLOLW\ 6$0681*
1257(/

3URYLVLRQLQJ 'LDPHWHU
'LDPHWHU
6HUYHU 6WDFN
$$$
DSSOLFDWLRQ

YHQGRUV[PO

[Link]
The unified Diameter dictionary, [Link], defines all Diameter vendors
and the attribute-value pairs that they support. The Diameter AAA application and
the Bridgewater Diameter Stack use the [Link] file to source all Diameter
AVPs and Diameter commands.
Note After modifying the [Link] file, send a HUP signal to the
Provisioning Server (wsprovs) and the Diameter AAA application (diaaaa).
Restart the Bridgewater Diameter Stack (BWSwsdia).
The [Link] file is located in the /opt/aaasc/config/dia directory, and its
schema file, [Link], is located in the /opt/aaasc/dict/dia directory.
This section describes the elements, child elements, and attributes of the
[Link] file.
The Diameter dictionary schema contains these elements:
dictionary: the root element
avp-group
vendor-group
avp
default-flag
type
enumerated
enum
grouped
fixed

Page 210 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

avp-rule
flag
required
avp-rule
flag
optional
avp-rule
flag
avp-extension
enumerated
enum
application
import-avp-group
import-command
command
request-rule
required
avp-rule
optional
response-rule
required
avp-rule
optional
avp-rule

dictionary The root element that encloses the <avp-group> and <application> elements. At
least one <avp-group> element must be defined.
Example:
<dictionary>
<avp-group... />
<application ... />
</dictionary>

avp-group A collection of AVPs. The avp-group element contains the avp-extension, and
vendor-group child elements.
Child element of dictionary.
Example:
<avp-group>
<vendor-group .../>
<avp-extension .../>

Service Controller 9.6.1-AAA October 12, 2012 Page 211


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

</avp-group>

Table 79: avp-group attributes

Attribute Value Description

name • String • Name of the ASN vendor, such as SAMSUNG


• 1 to 255 characters • Must be unique.
• Required.

vendor-group Defines a specific vendor, such as RFC3588 or SAMSUNG. It contains zero or


more avp> child elements.
Child element of avp-group.
Example:
<vendor-group>
<avp .../>
<avp .../>
</vendor-group>

Table 80: vendor-group attributes

Attribute Value Description

vendor-id • Integer • Unique ID for the vendor.


• 0 to 4294967295 • Required.

avp A specific attribute-value pair, such as User-Name. The avp element contains zero
or more default-flag child elements and one of the following child elements: type,
enumerated, or grouped.
Child element of vendor-group.
Example:
<avp code=”1” name=”User-Name”>
<default-flag .../>
<type .../>
</avp>

Table 81: avp attributes

Attribute Value Description

name • String (1–60 • Unique name for the attribute-value pair.


characters) • Required.

code • Integer • The unique code assigned to the AVP.


(0–4294967295

Page 212 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

default-flag Enables the use of the flags that are defined in section 4.1 of RFC 3588. To
override the value of the flag, specify the Diameter command.
Child element of avp.
Optional.
Example:
<default-flag mandatory=”may”/>

Table 82: default-flag attributes

Attribute Value Description

mandatory • must • Use flags to define how AVPs are managed.


• may
• must-not (default)

type The datatype of the attribute.


Child element of avp.
Example:
<type name=”Unsigned32”/>

Table 83: type attributes

Attribute Value Description

name • OctetString • The name of the specified AVP type, such as Integer32.
• UTF8String
• DiameterIdentity
• DiameterURI
• Integer32
• Integer64
• Unsigned32
• Unsigned64
• Float32
• Float64
• Address
• Time
• IPFilterRule
• QosFilterRule

enumerated Defines the specific values for enumerated AVPs. The enumerated element
contains one or more enum child elements.
Child element of avp and avp-extension.
Example:
<enumerated>
<enum .../>
<enum .../>

Service Controller 9.6.1-AAA October 12, 2012 Page 213


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

</enumerated>

enum Defines specific enumerated values.


Child element of enumerated.
Example:
<enumerated>
<enum name=””AUTHENTICATE_ONLY” code=”1”/>
<enum name=””AUTHORIZE_ONLY” code=”2”/>
<enum name=””AUTHENTICATE_AUTHORIZE” code=”3”/>
</enumerated>

Table 84: enum attributes

Attribute Value Description

name • String (1–255 • A unique name for the enumerated attribute.


characters)

code • -2147483648 to • A unique code to define the attribute.


2147483648

grouped A series of AVPs that are grouped as a single attribute.


The grouped element contains the fixed, required, and optional child elements.
Child element of avp.
Example:
<grouped allow-any-avp=”true”>
<fixed/>
<required .../>
<optional .../>
</grouped>

Table 85: grouped attributes

Attribute Value Description

allow-any-avp • true • true = permit any AVP to be present in the grouped attribute.
• false (default)

fixed Requires all enclosed AVPs to be present and in a fixed position in relation to the
start of a Diameter message.
The fixe> element must contain one or more avp-rule elements.
Child element of grouped.
Example:

Page 214 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

<fixed>
<avp-rule name=”SessionId” group-name=”BASE” min-occur=”1”
max-occur=”1”>
<flag mandatory=”may”/>
</avp-rule>
</fixed>

required Requires all enclosed AVPs to be present. These AVPs can appear anywhere in a
Diameter message.
The required element must contain one or more avp-rule elements.
Child element of grouped.
Example:
<required>
<avp-rule name=”Auth-Application-Id” min-occur=”1” max-occur=”1”>
<flag mandatory=”may”>
</avp-rule>
</required>

optional Permits all enclosed AVPs to display anywhere in a Diameter message.


The optional element must contain one or more avp-rule elements.
Child element of grouped.
Example:
<optional>
<avp-rule name=”Destination-Host” min-occur=”0” max-occur=”1”/>
</optional>

avp-rule Encloses AVPs required for the grouped attribute, and it encloses the optional flag
child element.
Child element of fixed, required, or optional.
Example:
<required>
<avp-rule name=”Auth-Application-Id” min-occur=”1” max-occur=”1”>
</required>

Table 86: avp-rule attributes

Attribute Value Description

name • String (1– 60 • Required.


characters)

Service Controller 9.6.1-AAA October 12, 2012 Page 215


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Table 86: avp-rule attributes (continued)

Attribute Value Description

group-name • String (1–255 • The name of the avp group that defines the attribute.
characters) • If the group-name is not specified, the system searches for the AVP
definition in all AVP groups defined in the file.
• Optional.

min-occur Default = 0 • The minimum number of times that this attribute can occur.
• Optional.

max-occur Default = no limit • The maximum number of times that this attribute can occur.
• Optional.

flag Enables the use of the flags that are defined in section 4.1 of RFC 3588. If the fla>
element is not present, the system uses the value defined in the default-flag
element.
Child element of avp-rule.
Example:
<avp-rule name=”Auth-Application-Id” min-occur=”1” max-occur=”1”>
<flag mandatory=”may”>
</avp-rule>

Table 87: flag attributes

Attribute Value Description

mandatory • must-not (default) • Use flags to define how AVPs are managed.
• must
• may

avp-extension Defines extensions to AVPs that add new enumerated values to AVPs.
The avp-extension element contains the enumerated child element.
Child element of vendor-group.
Example:
<avp-group ...>
<avp-extension name=”Auth-Request-Type group=”BASE”>
<enumerated .../>
</avp-extension>
</avp-group>

Page 216 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

Table 88: avp-extension attributes

Attribute Value Description

name • String (1–60 • The name of the attribute being extended.


characters) • The name must match the name of the AVP.
• Required.

group • String (1–255 • The avp-group to which the attribute belongs.


characters) • If the group is not specified, the system searches all AVP groups for
the AVP.
• Optional

enumerated For more information, see"enumerated" on page 213.

application The Diameter application, such as Diameter Common Messages or Mobile-IP.


The application element contains zero or more import-avp-group and
import-command child elements, and one or more command child elements.
Child element of dictionary.
Example:
<application id=”0” name=”5”>
<import-avp-group .../>
<import-command.../>
<command .../>
</application>

Table 89: application attributes

Attribute Value Description

name • String • The name of an application that is defined in the dictionary.


• 1 to 255 • Example: EAP

id • Integer • The ID number of the application.


• 0 to 4294967295

import-avp-group Creates a master list of all the AVPs that the application supports. The value of
import-avp-group must be an avp-group that is defined in the Diameter dictionary.
Child element of application.
Example:
<application id=”5” name=”EAP”>
<import-avp-group>SAMSUNG</import-avp-group>
<import-avp-group>MICROSOFT</import-avp-group>

import-command Enables importing of commands from a different application.

Service Controller 9.6.1-AAA October 12, 2012 Page 217


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Child element of application.


Example:
<application .../>
<import-command application=”BASE” command=”Capablities-Exchange”/>

Table 90: import-command attributes

Attribute Value Description

application • String • The name of the application from which to import the command.
• 1 to 255 • The application name must be present in the Diameter dictionary.
• Required.

command • String • The name of the command to import.


• 1 to 255 • Required.

command Enables definition of commands for an application.


The command element contains the request-rule and response-rule child elements.
Child element of application.
Example:
<command code=”268” name=’”Diameter-EAP” abbr-name=’DE”
allow-proxy=”yes”>
<request-rule .../>
<response-rule .../>
</command>

Table 91: command attributes

Attribute Value Description

code • Integer • The code number that identifies the command.


• 0 to 16777215 • Required.

name • String • The name of the command.


• 1 to 255 • Example: Diameter-EAP
• Required.

abbr-name • 2 letter string • Two letter abbreviation for the command name.
• User capital letters only.
• Example=DE (Diameter-EAP).
• Required.

allow-proxy • true • —
• false

Page 218 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

request-rule Defines the AVPs that are permitted on the request.


The request-rule element contains the fixed, required, and optional child elements.
Child element of command.
Example:
<request-rule allow-any-avp=”true”>
<fixed/>
<required .../>
<optional .../>
</request-rule>

Table 92: request-rule and response-rule attribute

Attribute Value Description

allow-any-avp • true • true = permit any AVP to be present in the grouped attribute.
• false (default)

response-rule Defines the AVPs that are permitted on the response.


The response-rule element contains the fixed, required, and optional child
elements.
Child element of command.

To add custom Diameter vendor attributes


To add custom Diameter vendor attributes:
• create a custom avp-group in the Diameter dictionary, [Link]
• if applicable, modify the Application responses section of [Link]
• modify the [Link] file
• send a HUP signal or restart the Diameter AAA application, the Bridgewater
Diameter Stack, and the Provisioning Server
1 Using a text editor, open the Diameter dictionary, [Link], located in
the /opt/aaasc/config/dia directory.
2 Create an avp-group and if required, add sub AVPs.
Example:
<avp-group name=”CUSTOM”>
<!---Custom Vendor AVPs-->
<vendor-group vendorId=”0”>
<avp code=”1101” name=”MyNew-OctetString”>
<type name=”OctetString”/>
</avp>
<avp name="QoS-Descriptor" code="29">
<grouped>
<required>

Service Controller 9.6.1-AAA October 12, 2012 Page 219


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

<avp-rule name="QoS-ID" min-occur="1" max-occur="1"/>


<avp-rule name="Service-Class-Name" min-occur="1"
max-occur="1"/>
</required>
</grouped>
</avp>
</vendor-group>
</avp-group>
3 If required, add the CUSTOM avp-group into the definitions section of each
appropriate application, such as the EAP Application section, using the
<import-avp-group> parameter.
Example:
<application id=”5” name=”EAP”>
<import-avp-group>BASE</import-avp-group>
<import-avp-group>EAP</import-avp-group>
<import-avp-group>CUSTOM</import-avp-group>
4 In the command response section for each appropriate application, add an
<avp-rule> parameter for each new AVP.
Example:
<command code=”268” name=”Diameter-EAP abbr-name=”DE”
allow-proxy=”true”>
<request-rule allow-any-avp=”true”>
<fixed.../>
<required.../>
<optional.../>
</request-rule>
<response-rule allow-any-avp=”true”>
<fixed.../>
<required.../>
<optional>
<avp-rule.../>
<avp-rule.../>
<!--MY CUSTOM AVPs-->
<avp-rule name=”MyNew-OctetString” max-occur=”1”>
<avp-rule name="MyNew-OctetString" max-occur="1">
<avp name="QoS-Descriptor" max-occur="1">
</optional>
</response-rule>
</command>
Note The Service Manager only displays attributes provisioned within the
application <response-rule> parameters. Provisioned attributes that are

Page 220 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

only within the <request-rule> parameters, do not display in the Service


Manager.
Note The DiameterIdentity and DiameterURI type attributes do not display in
the Service Manager.
5 Save the [Link] file.
6 Using a text editor, open the [Link] file, located in the
/opt/aaasc/config/dia directory.
7 Add the CUSTOM avp-group to the appropriate vendor section, such as
SAMSUNG.
Example:
<vendor name="SAMSUNG">
<import-avp-group name="BASE" />
<import-avp-group name="SAMSUNG" />
<import-avp-group name=”CUSTOM”/>
</vendor>
8 Save the file and exit.
9 Stop the Diameter AAA application (diaaaa), then stop the Diameter Stack
(wsdia); restart the Bridgewater Diameter Stack, then restart the Diameter AAA
process. Send the Provisioning Server (wsprovs) a HUP signal.
Example:
/etc/init.d/diaaaa stop
/etc/init.d/wsdia stop
/etc/init.d/wsdia start
/etc/init.d/diaaaa start
/etc/init.d/wsprovs hup

To add enumerated values to the Diameter dictionary


To add enumerated values to AVPs, use the <avp-extension> element, and the
<enumerated> and <enum> child elements.
For example, consider the Auth-Request-Type attribute, which is defined under the
BASE avp-group (for the complete example, see the "[Link] example"
on page 222:
<avp code="274" name="Auth-Request-Type">
<enumerated>
<enum name="AUTHENTICATE_ONLY" code="1"/>
<enum name="AUTHORIZE_ONLY" code="2"/>
<enum name="AUTHORIZE_AUTHENTICATE" code="3"/>
</enumerated>
</avp>

Service Controller 9.6.1-AAA October 12, 2012 Page 221


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

To add the enumerated values ”MyExtraEnum1” and ”MyExtraEnum2” to the


Auth-Request-Type AVP of the BASE avp-group:
• Add the following elements and values before the <application> tag:
<avp-group name=”BASE_EXT”>
<avp-extension name=”Auth-Request-Type” group=”BASE”>
<enumerated>
<enum name=”MyExtraEnum1” code=”4”/>
<enum name=”MyExtraEnum2” code=”5”/>
</enumerated>
</avp-extension>
</avp-group>
where
<avp-group> provides a unique name for this group
<avp-extension> describes the name of the AVP to extend, and the avp-group
to which the attribute belongs
<enumerated> defines this attribute type as enumerated
<enum> defines each of the new values
Note After modifying the [Link] file, stop the Diameter AAA
application (diaaaa), then stop the Diameter Stack (wsdia). Restart the
Diameter Stack (wsdia), then restart the Diameter AAA application
(diaaaa). Send the Provisioning Server (wsprovs) a HUP signal.

[Link] The following [Link] example uses all the elements described in
example "[Link]" on page 210.
<?xml version="1.0" encoding="UTF-8"?>
<dictionary xmlns="[Link] xmlns:xsi="http://
[Link]/2001/XMLSchema-instance" xsi:schemaLocation="/opt/aaasc/dict/dia/
[Link]">

<!-- DIAMETER Base Protocol AVPs -->


<avp-group name="BASE">
<vendor-group vendor-id="0">
<avp code="0" name="AVP">
<default-flag mandatory="may"/>
<type name="Unsigned32"/>
</avp>
<avp code="1" name="User-Name">
<default-flag mandatory="may"/>
<type name="OctetString"/>
</avp>
<avp code="4" name="NAS-IP-Address-Name">
<default-flag mandatory="may"/>

Page 222 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

<type name="OctetString"/>
</avp>
<avp code="5" name="NAS-Port">
<type name="Unsigned32"/>
</avp>
<avp code="6" name="Service-Type">
<type name="Unsigned32"/>
</avp>
<avp code="8" name="Framed-IP-Address">
<type name="Unsigned32"/>
</avp>
<avp code="12" name="Framed-MTU">
<type name="Unsigned32"/>
</avp>
<avp code="25" name="Class">
<type name="OctetString"/>
</avp>
<avp code="27" name="Session-Timeout">
<type name="Unsigned32"/>
</avp>
<avp code="31" name="Calling-Station-Id">
<type name="UTF8String"/>
</avp>
<avp code="32" name="NAS-Identifier">
<type name="OctetString"/>
</avp>
<avp code="46" name="Acct-Session-Time">
<type name="Unsigned32"/>
</avp>
<avp code="50" name="Acct-Multi-Session-Id">
<type name="Unsigned32"/>
</avp>
<avp code="55" name="Event-Timestamp">
<type name="Unsigned32"/>
</avp>
<avp code="60" name="WIMAX-DM-Action-Code">
<type name="Unsigned32"/>
</avp>
<avp code="61" name="NAS-Port-Type">
<type name="Unsigned32"/>
</avp>
<avp code="85" name="Acct-Interim-Interval">
<type name="Unsigned32"/>

Service Controller 9.6.1-AAA October 12, 2012 Page 223


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

</avp>
<avp code="89" name="CUI">
<type name="OctetString"/>
</avp>
<avp code="258" name="Auth-Application-Id">
<type name="Unsigned32"/>
</avp>
<avp code="259" name="Acct-Application-Id">
<type name="Integer32"/>
</avp>
<avp code="263" name="Session-Id">
<type name="OctetString"/>
</avp>
<avp code="264" name="Origin-Host">
<type name="OctetString"/>
</avp>
<avp code="268" name="Result-Code">
<type name="Unsigned32"/>
</avp>
<avp code="272" name="Multi-Round-Timeout">
<type name="Unsigned32"/>
</avp>
<avp code="274" name="Auth-Request-Type">
<enumerated>
<enum name="AUTHENTICATE_ONLY" code="1"/>
<enum name="AUTHORIZE_ONLY" code="2"/>
<enum name="AUTHORIZE_AUTHENTICATE" code="3"/>
</enumerated>
</avp>
</vendor-group>
</avp-group>
<!-- WiMAX avp group definition -->
<avp-group name="WIMAX">
<!-- WiMAX Vendor AVPs -->
<vendor-group vendor-id="24757">
<avp code="1025" name="Accounting-Capabilities">
<enumerated>
<enum name="No-Accounting" code="0"/>
<enum name="IP-Session-Based" code="1"/>
<enum name="Flow-Based" code="2"/>
</enumerated>
</avp>
<avp code="1026" name="Hotlining-Capabilities">

Page 224 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

<enumerated>
<enum name="No-Hotlining" code="0"/>
<enum name="IP-Redirection" code="1"/>
<enum name="HTTP-Redirection" code="2"/>
</enumerated>
</avp>
<avp code="1027" name="Idle-Mode-Notification-Capabilities">
<enumerated>
<enum name="Idle-Mode-Not-Supported" code="0"/>
<enum name="Idle-Mode-Supported" code="1"/>
</enumerated>
</avp>
<avp code="1" name="WiMAX-Capability">
<default-flag mandatory="may"/>
<grouped allow-any-avp="true">
<fixed/>
<required>
<avp-rule name="Accounting-Capabilities" min-occur="1"
max-occur="1">
<flag mandatory="may"/>
</avp-rule>
</required>
<optional>
<avp-rule name="Hotlining-Capabilities" min-occur="0"
max-occur="1">
</avp-rule>
<avp-rule name="Idle-Mode-Notification-Capabilities"
min-occur="0" max-occur="1">
</avp-rule>
</optional>
</grouped>
</avp>
</vendor-group>
</avp-group>
<!-- SAMSUNG avp group definition -->
<avp-group name="SAMSUNG">
<!-- Samsung Vendor AVPs -->
<vendor-group vendor-id="236">
<avp code="11000" name="DIR">
<default-flag mandatory="must-not"/>
<type name="UTF8String"/>
</avp>
</vendor-group>

Service Controller 9.6.1-AAA October 12, 2012 Page 225


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

</avp-group>
<!-- Microsoft avp group definition -->
<avp-group name="MICROSOFT">
<!-- Microsoft Vendor AVPs -->
<vendor-group vendor-id="311">
<avp code="11" name="MS-CHAP-Challenge">
<default-flag mandatory="must-not"/>
<type name="OctetString"/>
</avp>
<avp code="25" name="MS-CHAP2-Response">
<default-flag mandatory="must-not"/>
<type name="OctetString"/>
</avp>
<avp code="26" name="MS-CHAP2-Success">
<default-flag mandatory="must-not"/>
<type name="OctetString"/>
</avp>
</vendor-group>
</avp-group>
<!--
Example to show what avp extension looks like. The following avp-group extends
the BASE avp Auth-Request-Type by adding new enumeration values.
-->
<avp-group name="BASE_EXT">
<avp-extension name="Auth-Request-Type" group="BASE">
<enumerated>
<enum name="myExtraEnum1" code="4"/>
<enum name="myExtraEnum2" code="5"/>
</enumerated>
</avp-extension>
<vendor-group vendor-id="0">
</vendor-group>
</avp-group>

<application id="0" name="BASE">


<!-- import AVP definitions -->
<import-avp-group >BASE</import-avp-group>
<command code="257" name="Capabilities-Exchange" abbr-name="CE"
allow-proxy="no">
<request-rule allow-any-avp="1">
<required>
<avp-rule name="Origin-Host" min-occur="1" max-occur="1"/>
<avp-rule name="Origin-Realm" min-occur="1" max-occur="1"/>

Page 226 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

<avp-rule name="Host-Ip-Address" min-occur="1"


max-occur="5"/>
<avp-rule name="Vendor-Id" min-occur="1" max-occur="1"/>
<avp-rule name="Product-Name" min-occur="1" max-occur="1"/>
</required>
<optional>
<avp-rule name="Origin-State-Id" max-occur="1"/>
<avp-rule name="Auth-Application-Id" max-occur="5"/>
<avp-rule name="Acct-Application-Id" max-occur="5"/>
<avp-rule name="Inband-Security-Id" max-occur="5"/>
<avp-rule name="Vendor-Specific-Application-Id"
max-occur="5"/>
<avp-rule name="Firmware-Revision" max-occur="1"/>
<avp-rule name="Supported-Vendor-Id" max-occur="5"/>
</optional>
</request-rule>
<response-rule allow-any-avp="1">
<required>
<avp-rule name="Result-Code" min-occur="1" max-occur="1"/>
<avp-rule name="Origin-Host" min-occur="1" max-occur="1"/>
<avp-rule name="Origin-Realm" min-occur="1" max-occur="1"/>
<avp-rule name="Host-Ip-Address" min-occur="1"
max-occur="5"/>
<avp-rule name="Vendor-Id" min-occur="1" max-occur="1"/>
<avp-rule name="Product-Name" min-occur="1" max-occur="1"/>
</required>
<optional>
<avp-rule name="Origin-State-Id" max-occur="1"/>
<avp-rule name="Error-Message" max-occur="1"/>
<avp-rule name="Failed-AVP" max-occur="5"/>
<avp-rule name="Auth-Application-Id" max-occur="5"/>
<avp-rule name="Auth-Request-Type" max-occur="5"/>
<avp-rule name="Inband-Security-Id" max-occur="5"/>
<avp-rule name="Vendor-Specific-Application-Id"
max-occur="5"/>
<avp-rule name="Firmware-Revision" max-occur="1"/>
<avp-rule name="Supported-Vendor-Id" max-occur="5"/>
</optional>
</response-rule>
</command>
</application>
<!-- EAP Application -->
<application id="5" name="EAP">

Service Controller 9.6.1-AAA October 12, 2012 Page 227


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

<!-- import AVP definitions -->


<import-avp-group>BASE</import-avp-group>
<import-avp-group>BASE_EXT</import-avp-group>
<import-avp-group>WIMAX</import-avp-group>
<import-avp-group>MICROSOFT</import-avp-group>
<import-avp-group>SAMSUNG</import-avp-group>
<!-- import commands -->
<import-command application="BASE"
command="Capabilities-Exchange"/>
<!-- define EAP commands -->
<command code="268" name="Diameter-EAP" abbr-name="DE"
allow-proxy="yes">
<request-rule allow-any-avp="1">
<fixed>
<avp-rule name="Session-Id"
group=name="BASE" min-occur="1"
max-occur="1">
<flag mandatory="may"/>
</avp-rule>
</fixed>
<required>
<avp-rule name="Auth-Application-Id" min-occur="1" max-occur="1">
<flag mandatory="may"/>
</avp-rule>
<avp-rule name="Origin-Host" min-occur="1" max-occur="1"/>
<avp-rule name="Origin-Realm" min-occur="1" max-occur="1"/>
<avp-rule name="Destination-Realm" min-occur="1" max-occur="1"/>
<avp-rule name="Auth-Request-Type" min-occur="1"
max-occur="1"/>
</required>
<optional>
<avp-rule name="Destination-Host" min-occur="0" max-occur="1"/>
<avp-rule name="NAS-Identifier" min-occur="0" max-occur="1"/>
</optional>
</request-rule>
<response-rule allow-any-avp="1">
<fixed>
<avp-rule name="Session-Id" min-occur="1" max-occur="1"/>
</fixed>
<required>
<avp-rule name="Auth-Application-Id" min-occur="1"
max-occur="1"/>
<avp-rule name="Auth-Request-Type" min-occur="1"

Page 228 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

max-occur="1"/>
<avp-rule name="Origin-Host" min-occur="1" max-occur="1"/>
<avp-rule name="Origin-Realm" min-occur="1" max-occur="1"/>
<avp-rule name="Result-Code" min-occur="1" max-occur="1"/>
</required>
<optional>
<avp-rule name="User-Name" max-occur="1"/>
</optional>
</response-rule>
</command>
</application>
</dictionary>

[Link]
The Diameter AAA application queries the [Link] file for definitions of the
vendor-specific Diameter attributes to write to accounting records when a Diameter
ACR is received. It also uses [Link] to store service usage data, and to
generate correlated accounting records.
Note Vendors defined in the [Link] file must match the vendors defined in
the [Link] file used by the Diameter Server.
For more information about [Link], see "Configuring vendor-specific data
([Link])" on page 189.

[Link]
The [Link] file, located in the /opt/aaasc/config/dia
directory, enables you combining the AVPs from different vendors into avp-groups,
such as combining SAMSUNG VSAs with RFC 3588 AVPs. The system makes
these groups of AVPs available to the specified vendor by reading the appropriate
sections of the [Link] Diameter dictionary file.
For example, assign all the BASE and SAMSUNG AVPs to the SAMSUNG vendor
by adding the following entry in the [Link] file:
<vendor name="SAMSUNG">
<import-avp-group name="BASE" />
<import-avp-group name="SAMSUNG" />
</vendor>
The [Link] file is .
Note After modifying [Link] file, send a HUP signal to
the Provisioning Server (wsprovs) for the changes to take effect.

Service Controller 9.6.1-AAA October 12, 2012 Page 229


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

dictionary-vendor- The following is an example of the [Link] file.


[Link] <?xml version="1.0" encoding="UTF-8"?>
example
<dictionaries xmlns:xsi='[Link]
xmlns='[Link]
xsi:schemaLocation='/opt/aaasc/dict/dia/[Link]'>
<dictionary type="diameter">
<file>/opt/aaasc/config/dia/[Link]</file>
<vendor name="RFC3588">
<import-avp-group name="BASE" />
</vendor>
<vendor name="SAMSUNG">
<import-avp-group name="BASE" />
<import-avp-group name="SAMSUNG" />
</vendor>
<vendor name="NORTEL">
<import-avp-group name="BASE" />
<import-avp-group name="NORTEL"/>
</vendor>
</dictionary>
</dictionaries>

To modify dictionary-vendor- [Link]


To modify the [Link] file:
1 Go to the /opt/aaasc/config/dia directory.
2 Using a text editor, open [Link].
3 Modify the file as required.
Note AVP group names must match to avp-groups listed in the
[Link] file.
4 Save the file and exit.
5 For the changes to take effect, restart the Provisioning Server. Optionally, send
the Provisioning Server a HUP signal. For example:
/etc/init.d/wsprovs stop
/etc/init.d/wsprovs start
or
/etc/init.d/wsprovs hup
Note After modifying the dictionary, if the system encounters a dictionary error
when restarting the Provisioning Server, the Provisioning Server does not
restart. Check the logs, fix the error, and restart the Provisioning Server.
Note After modifying the dictionary, if the system encounters a dictionary error
when sending the Provisioning Server a HUP signal, the dictionary

Page 230 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 6 Managing RADIUS and Diameter dictionaries

changes are not accepted. The system reverts to the original dictionary
parameters. Fix the problem and send another HUP signal.

[Link]
In a Diameter environment, the [Link] file, located in the /opt/aaasc/
config/provserver directory, defines the utility that loads the Diameter dictionary into
the Provisioning Server, and it points to the directory that contains the
[Link] file. The [Link] file also configures
the Diameter dictionary API.
Note For a new installation, there is no need to manually configure Diameter
information in the [Link] file. For upgrades, see the README
file in the BWSaaapr package for information about configuring the
[Link] file.

Diameter sections of <!-- configure The XML Dictionary Utility -->


[Link] <component
class="[Link]
VendorUtility">
<configuration>
<file>/opt/aaasc/dia/[Link]</file>
</configuration>
</component>
<!-- Configure the Diameter Dictionary API -->
<component
class="[Link]"
>
<remote
interface="[Link]">
<name>DiameterDictionaryAPI</name>
</remote>
</component>

Service Controller 9.6.1-AAA October 12, 2012 Page 231


Chapter 6 Managing RADIUS and Diameter dictionaries Network Access Guide

Page 232 October 12, 2012 Service Controller 9.6.1-AAA


Configuring AAA policies

7
Chapter 7
Chapter

This chapter provides information about configuring RADIUS and Diameter Server
policy rules to handle preauthentication, authentication, and accounting requests.
The topics are:
• Rules files
• Conditions
• Actions
• Action modifiers
• rejectPolicy
• Configuring PreAuthorize using Access Control Limits (ACL) for proxy
• Testing policy rules
• Example policy configurations

Service Controller 9.6.1-AAA October 12, 2012 Page 233


Chapter 7 Configuring AAA policies Network Access Guide

Rules files
The policy rules are listed in the following policy files:

Mandatory
• accessReqPolicy defines rules for handling Access-Request messages
• acctReqPolicy defines rules for handling Accounting-Request messages
Note The accessReqPolicy and the acctReqPolicy files must be present for the
RADIUS Server to start.

Optional
• TLSPolicy defines rules for handling Access-Request messages to evaluate the
Inner-User-ID found in TLS-based EAP mechanisms such as EAP-TTLS
• dynamicHAPolicy defines rules for handling dynamic home agent allocation
requests, which are used in Mobile IP scenarios
• daeReqPolicy defines rules for handling Dynamic Authorization Extensions
requests
• ejectPolicy defines rules for adding service AVPs to Access-Reject messages
delivered to the gateway

Other
• additional policy files, invoked using the policyRun action, contain policy rules in
the same format.
For policy actions, such as Pre-Authorize, that are triggered during a multi-leg EAP
exchange, enable DAL query caching, which stores user attributes to the EAP-state
cache. RADIUS retrieves these attributes from the cache, which minimizes the load
on the Profile database. For more information, see "Configuring database (DAL
query) caching for multi-leg EAP" on page 74.
Policy files are located in the /opt/aaasc/config/radius and /opt/aaasc/config/dia-aaa
directories.
Each policy file contains an ordered list of rules. Each rule consists of two
expressions:
• a condition – which must be met by the incoming message
• an action – which occurs when the condition is met

Page 234 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Conditions
The condition in each policy rule has the following syntax:
<attribute> <operator> <value>
The condition “- - -” can be used as a “catch-all” rule for any requests that do not
match other rule conditions.
Table 93 lists the possible entries for attribute fields in a condition.

Table 93: Attribute field entries

Options Notes

Any attribute from any vendor If no vendor is specified, the RFC dictionary is assumed.
dictionary, in the format For the PreAuthorize action, use the optional PreAuth: tag to specify that the
<vendor-name>:<attribute-name>. attribute should be retrieved from the specified RADIUS connection service profile.
Subtype attributes are also Without the PreAuth: tag, the attribute defaults to the value in the
supported, including subtype [Link] example: PreAuth:<vendor-name>:<attribute-name>.
attributes in octet string format. For For HLR authorization with the authorizationPolicy action modifier, use the optional
subtype attributes you must use the HLRAuth: tag to specify that the comparision should occur against an attribute
format injected with data retrieved from an HLR. If the HLRAuth: tag is not specified, the
<vendor-name>:<attribute-name>. attribute comparison occurs against the attribute received from the Access-Request.
To specify one of a subtype
This tag should only be used in conjunction with a policy that uses the
attribute’s nested subtypes for
hlrAuthoriztion and authorizationPolicy action modifiers together.
comparison, use an extractReg
modifier in the policy line. Supported condition attributes are Equals, NotEquals, EqualsCI, NotEqualsCl,
RegExp, and NotRegExp.
For more information about using
subtype attributes, see "Using
subtype attributes in
Access-Requests to control network
access" on page 317.

Client-IP-Address The source IP address of the incoming request. The value is the IP address in
standard dot notation. Supported condition attributes are Equals, NotEquals,
Between, Matches, and BelongsToClientGroup.

Time-Of-Day The local time of the RADIUS client (NAS or Proxy Server) based on the time zone
defined for it in the Service Manager. Equals and NotEquals are the only valid
operator for the Time-Of-Day condition. The Time-Of-Day condition requires a value
in the form: DayofWeek:TimeRange, where DayofWeek is either a range (Mon-Fri)
or a list (Fri,Sat,Sun) and TimeRange is a range in the form hhmmss-hhmmss.

myVar:<user-defined-variable> An attribute name of myVar refers to an AssignVar action where the myVar variable
was defined. For more information, see "myVar" on page 281.
Supported condition attributes are NotEquals and NotEqualsCl.

Service Controller 9.6.1-AAA October 12, 2012 Page 235


Chapter 7 Configuring AAA policies Network Access Guide

Table 93: Attribute field entries (continued)

Options Notes

Inner-User-ID This option is available only in the TLSPolicy file.


Inner-User-ID is a hidden value encrypted in the TLS portion of an EAP-Message. It
identifies the subscriber during phase 2 authentication.
Inner-User-ID can be used to determine if authentication occurs locally or remotely.
For local authentication, an EAP selection policy can be applied if Inner-User-ID was
received as part of EAP information. Otherwise, PAP/CHAP/MSCHAPv1/2 are used
based on the received inner attributes.
Supported condition attributes are Equals, NotEquals, EqualsCI, NotEqualsCl,
Contains, ContainsCI, StartsWith, StartsWithCI, EndsWith, EndsWithCI,
GreaterThan, and LessThan.
Works with RADIUS and Diameter.

Pre-Acct-User A pre-authorization user is in the Profile Database.


“Appears” is the only valid operator. “Once”, and “Never” are the only valid condition
values.
• Once” — the pre-authorization user must be in the Profile Database for the
condition to evaluate successfully.
• “Never” — the pre-authorization user is not in the Profile Database.

Pre-Acct-Service A pre-authorization service is in the Profile Database. “Appears” is the only valid
operator. “Once”, and “Never” are the only valid condition values.
• “Once” — the pre-authorization service must be in the Profile Database for the
condition to evaluate successfully.
• “Never” — the pre-authorization service is not in the Profile Database.

Pre-Auth-User A pre-authorization user is in the Profile Database. “Appears” is the only valid
operator. “Once”, and “Never” are the only valid condition values.
• “Once” — the pre-authorization user must be in the Profile Database for the
condition to evaluate successfully.
• “Never” — the pre-authorization user is not in the Profile Database.

Pre-Auth-Service A pre-authorization service is in the Profile Database. “Appears” is the only valid
operator. “Once”, and “Never” are the only valid condition values.
• “Once” — the pre-authorization service must be in the Profile Database for the
condition to evaluate successfully.
• “Never” — the pre-authorization service is not in the Profile Database.

Page 236 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Table 93: Attribute field entries (continued)

Options Notes

Reject-Reason The Access-Request has been rejected. “Equals” is the only valid operator. The
valid condtion values are:
• subscriber not found in the database
• Password is incorrect
• Invalid Auth Request
• Invalid Key Index
• Locked User
• MIP Attributes Not Available
• Password Missing
• Service Unavailable
• IP Address Allocation Failure
• NAS Client ID Failure
• Time Access Denial
• Location Access Denial
• Access Type Denial
• RMS Session Limit
• Ambiguous User
• HA Unavailable
• No Auth Mechanism Supported
• Invalid Mobile ID
• Server Error
• No Prepaid Support
• No Remote Prepaid Response
• MIP Not Available
• Invalid Equipment ID
• No Remote EAP Response
• Missing WiMAX Session

Table 94 lists the possible entries for operator fields in a condition.

Table 94: Operator field entries

Options Notes

Equals [Equals CI] CI denotes case-insensitive.

NotEquals [NotEqualsCI]

StartsWith [StartsWithCI]

EndsWith [EndsWithCI]

Contains [ContainsCI]

RegExp The RegExp operator requires a regular expression as its value.

NotRegExp If the attribute does not match the value of the regular expression, the associated
policy action is executed.

Service Controller 9.6.1-AAA October 12, 2012 Page 237


Chapter 7 Configuring AAA policies Network Access Guide

Table 94: Operator field entries (continued)

Options Notes

GreaterThan Only valid with type string and type integer attributes in call check policy rules.

LessThan

Between [BetweenCI] CI denotes case-insensitive.

Appears Only one of these values is allowed with the Appears operator: Never (n=0), Once
(n=1), AtLeastOnce (n>=1), or Multiple (n>1).

MatchesAny [MatchesAnyCI] Compares an attribute to incoming or retrieved attributes. Supports wildcard (*).
Use the wildcard in front of a value, or to represent a complete value.
The PreAuth: tag can be used in front of a value to specify that the value should
come from the PreAuthorize action.
The HLRAuth: tag can be used in front of a value to specify that the value comes
from data retrieved from an HLR.
MatchesAnyCI is a case-insensitive version of the MatchesAny condition operator.

Matches Matches only supports CIDR notation. For example, [Link]/24. Only
Client-IP-Address and NAS-IP-Address support this option.

BelongsToClientGroup Determines whether a Client-IP-Address attribute belongs to a specified NAS,


PDSN, or WiMAX node group.
Requires that the Client-IP-Address and the name of a NAS, PDSN, or WiMAX
node group be defined in the Service Manager.

BelongsToClientGroupRegExp Determines whether a Client-IP-Address attribute belongs to a specified NAS,


PDSN, or WiMAX node group.
Requires a regular expression as its value. Evaluates to true when:
• the Client-IP-Address attribute, if present in a RADIUS request, matches a NAS,
PDSN, or WiMAX client
• the NAS, PDSN, or WiMAX node group to which the NAS, PDSN, or WiMAX
client belongs matches the configured regular expression
Requires that the NAS, PDSN, or WiMAX client and the name of a NAS, PDSN, or
WiMAX group be defined in the Service Manager.

BelongsToTrunkGroup Determines whether a string attribute belongs to a specified Trunk group.


Requires a Trunk group name as its value. Evaluates to true when the attribute, if
present in a RADIUS request, matches a Directory Number (DN) or DN range
configured for the specified Trunk group.
Requires that the name of the Trunk group be defined in the Service Manager, and
that DNs are configured for the Trunk group.
Supported for any string attribute.

Page 238 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Table 95 lists the possible entries for value fields in a condition.

Table 95: Value field entries

Option Notes

<attribute value> The <attribute value> can be:


• a literal value, such as a string or integer
• a referenced attribute, such as a defined myVar or other variable
• an attribute value retrieved from a RADIUS connection service profile
(PreAuthorize action), indicated by the PreAuth: tag before the attribute
name. Without the PreAuth: tag, the attribute defaults to the value in the
Access-Request.
• an attribute value injected with data retrieved from an HLR (HLR
authorization), indicated by the HLRAuth: tag before the attribute name.
Without the HLRAuth: tag, the attribute defaults to the value in the
Access-Request.

Appears qualifier Never (n=0), Once (n=1), AtLeastOnce (n>=1), or Multiple (n>1)

<range> An inclusive domain of string, ipaddr, ipv6addr, integer8, integer16, integer,


or integer64 values defined with the following syntax (a range is only
applicable to the 'Between' operators):
<lowerbound_value>&<upperbound_value>
For example: 100&64938

Actions
The action expression in each policy rule has the following syntax:
<action-name> <action-modifiers>
The action modifiers that can be applied to the action depend on the type of action
and the context in which it is used:
• Access request actions
• Accounting request actions
• Dynamic HA request actions
• TLS request actions
• DAE request actions
The RADIUS and Diameter Servers evaluate incoming messages against each
condition in the policy file, from top to bottom. If a condition is met, the action
specified in the rule is performed and no further evaluations are performed on the
message. If none of the conditions are met, the message is discarded.
By default, if the policy file is empty the RADIUS and Diameter servers perform
local authentication and accounting on incoming messages.

Service Controller 9.6.1-AAA October 12, 2012 Page 239


Chapter 7 Configuring AAA policies Network Access Guide

Access request actions


The actions for Access-Requests are handled according to policies defined in the
accessReqPolicy file.
The accessReqPolicy file contains an ordered list of rules that are applied to
Access-Request messages. Each rule consists of a condition expression and an
action expression.
Table 96 lists the action names that can be specified in the policy rules of the
accessReqPolicy file.
One or more action modifiers can be used in each rule.

Table 96: Access-Request actions

Action-name Action

CallCheckAA Checks access controls to preauthenticate subscribers.

PreAuthorize Preauthorizes the subscriber against the local Profile Database. Values are retrieved from the
specified RADIUS connection service profile. The default user is configurable. Policy evaluation
continues after the PreAuthorize action.
Note: To authorize against the ‘service’ action modifier, you must specify a value. This modifier does
not use a default setting.
If no subscriber identifiers are specified, the User-Name attribute is used for preauthorization. For a
policy configuration example, see ”Preauthorization” on page 315.
Attributes retrieved by a PreAuthorize action are referenced with the string “PreAuth”.
Example:
- - - ProxyAA target=PreAuth:$BRIDGEWATER:Proxy-Target \
authorizeProxyLevel=PreAuth:$BRIDGEWATER:Authorize-Proxy-Level
For deployments that require port quota checks, configure a policy to perform Access Control Limit
checks prior to sending a proxy request. For more information, see "Configuring PreAuthorize using
Access Control Limits (ACL) for proxy" on page 297.

LocalAA Authenticates subscribers against the local Profile Database.

LogMessage Enables an administrator to generate a custom log message to the RADSYS log family. Must be
configured with the “message” action modifier and can be optionally configured with the “priority”
and “attrs” action modifiers. For more information, see "CSID/MSID mismatch detection for LDAP
deployments" on page 320.
After LogMessage is executed, policy evaluation continues to the next specified policy line.

ProxyAA Forwards the message to an external RADIUS Server.

PolicyRun Evaluates another policy file.


Works with RADIUS and Diameter.

SendReject Rejects the Access-Request.

CDMA2000LocalAA Authenticates CDMA2000 wireless subscribers against the local Profile Database.

CDMA2000ProxyAA Forwards CDMA2000 wireless authentication requests to an external RADIUS Server.

Page 240 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Table 96: Access-Request actions (continued)

Action-name Action

DMULocalAA Local authentication of Dynamic Mobile IP Key Update subscribers

DMUProxyAA Forwards Dynamic Mobile IP Key Update authentication requests to an external RADIUS Server

GSMLocalAA Authenticates GSM subscribers against the local Profile Database.


For interaction between the Service Controller and the HLR, the Service Controller supports Layer 2
user lockout with the GSMLocalAA policy action.
With the GSMLocalAA policy action, the Service Controller can limit a subscriber’s network access
if there is a device that repeatedly tries to reconnect to a network.

GSMProxyAA Forwards the GSM message to an external RADIUS Server.

WiFiLocalAA Authenticates requests from subscribers for initial attachment to, or transition from, a Wi-Fi access
point using the device MAC address and session information stored in RMS.

WiMAXLocalAA Authenticates requests from an ASN gateway or WiMAX home agent node against the local Profile
Database.

WiMAXProxyAA Forwards requests from an ASN gateway or WiMAX home agent node to an external RADIUS
Server.

AssignVar Enables an administrator to define variables for the assignment of values to be used as conditions
in other policies and/or values for other action modifiers.

Figure 27 on page 242 shows how access requests are processed.


The actions specified in the diagram are specific to RADIUS, but the process flow is
the same for RADIUS and Diameter.

Service Controller 9.6.1-AAA October 12, 2012 Page 241


Chapter 7 Configuring AAA policies Network Access Guide

Figure 27: Access Request process flow

$FFHVV 3DFNHW
1RGH 7\SH

DFFHVV5HT DFFW5HT G\QDPLF+$ 7/6 '$(

1H[W
3ROLF\ 5XOH
5XOHV

&RQGLWLRQ
12 6SHFLILHG

<(6

&RQGLWLRQ
6DWLVILHG 12

<(6 $VVLJQ9DU

$FWLRQ /RFDO$$$FWLRQVLQFOXGH
&DOO&KHFN$$ /RFDO$$ /RFDO$$
7\SH
&'0$/RFDO$$
'08/RFDO$$
*60/RFDO$$
:L)L/RFDO$$
6HQG5HMHFW 3UR[\$$ :L0D[/RFDO$$
3ROLF\5XQ

3UR[\$$$FWLRQVLQFOXGH
3UR[\$$
&'0$3UR[\$$
'083UR[\$$
3ROLF\ *603UR[\$$
:L0D[3UR[\$$
5XOHV

Table 97 on page 243 lists action-modifiers for Access-Requests and the policy
actions for which they are valid.
Some modifiers only support RADIUS, some only support Diameter, and some
support both RADIUS and Diameter. For syntax and descriptions of each modifier,
see "Action modifiers" on page 262.

Page 242 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Table 97: Action-modifiers for Access-Requests

Policy action

CallCheckAA

PreAuthorize

LocalAA

ProxyAA

CDMA2000LocalAA

CDMA2000ProxyAA

DMULocalAA

DMUProxyAA

GSMLocalAA

GSMProxyAA

WiMAXLocalAA

WiMAXProxyAA

WiFiLocalAA

SendReject

PolicyRun

AssignVar
Action-modifier

ACCT-Mode 
acMatchAttribute             
acService             
allowLockedoutUsers           
appendDomain             
appendService 
assignVisitedFramedIP 
assignVisitedHome Agent 
attrs 
authenticate       
authenticateDomain       
authorizationPolicy               
authorize             
authorizeDefault Domain     
authorizeDefault LoginName     
authorizeDomain            
authorizeLoginName            
authorizeProxyLevel           
BTSCheck      
BTSService      
cacheCertFields 
checkNasGroupLimit 
checkSession 
continue PreProcessing 
continueNotFound 
defaultProxy      
disableDMU 
discardDomain             
discardService            
dnPrefix    
dnSearchBase    
dnSearchBaseReq Exp    

Service Controller 9.6.1-AAA October 12, 2012 Page 243


Chapter 7 Configuring AAA policies Network Access Guide

Table 97: Action-modifiers for Access-Requests (continued)

Policy action

CallCheckAA

PreAuthorize

LocalAA

ProxyAA

CDMA2000LocalAA

CDMA2000ProxyAA

DMULocalAA

DMUProxyAA

GSMLocalAA

GSMProxyAA

WiMAXLocalAA

WiMAXProxyAA

WiFiLocalAA

SendReject

PolicyRun

AssignVar
Action-modifier

domain             
domainRegexFormat             
EAP-OTA-Policy  
EAP-Policy      
enableIPReach           
evaluatePolicy 
extractAttr 
extractReg 
Force-WiMAX- Session  
getMobileID  
getProxyService 
hlrAuthorization 
hotlineSet  
HTTPDigest-Policy 
ignorePreProcessingFailure 
ipAllocPoolName Override        
LDAPPassword Attribute       
LDAPUserFilter       
loginName             
loginNameRegex Format             
message 
mobileType     
mppeEncryptionType      
multimode  
myVar 
optionalService            
outageAction           
outageDomain           
outageLoginName           
outageReject Message           
outageService           
PANIEnabled 

Page 244 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Table 97: Action-modifiers for Access-Requests (continued)

Policy action

CallCheckAA

PreAuthorize

LocalAA

ProxyAA

CDMA2000LocalAA

CDMA2000ProxyAA

DMULocalAA

DMUProxyAA

GSMLocalAA

GSMProxyAA

WiMAXLocalAA

WiMAXProxyAA

WiFiLocalAA

SendReject

PolicyRun

AssignVar
Action-modifier

PPHotlineSet 
priority 
proxyAVPs 
reason 
rejectPolicy             
replaceDomain             
replyMessage 
returnAVPs 
runPlugIn           
service             
serviceAVP            
serviceRegexFormat            
suppress-MS-MPPE 
switchLocalAuthorizeUser      
target     
trunkGroupAVP             
useAuthorize BillingId            
useMobileKey 
useTagIndex            
validateEquipID  
validateMobileID  
writeAccounting            

Service Controller 9.6.1-AAA October 12, 2012 Page 245


Chapter 7 Configuring AAA policies Network Access Guide

Accounting request actions


The actions for Accounting-Requests are handled according to policies defined in
the acctReqPolicy file.
The acctReqPolicy file contains an ordered list of rules that are applied to
Accounting-Request messages. Each rule consists of a condition expression and
an action expression.
Table 98 lists the action names that can be specified in the policy rules of the
acctReqPolicy file. One or more action modifiers can be used in each rule.

Table 98: Accounting-Request actions

Action-name Action

LocalAcct The RADIUS Server sends an accounting record to the Accounting Framework.

ProxyAcct The RADIUS Server forwards the accounting message to a remote RADIUS server, as well
as sending an accounting record to the Accounting Framework.

DeviceReboot The RADIUS Server interprets the accounting-request as an indication of a device reboot. It
sends an update to the Resource Management Suite Products to close any sessions that
were active on the NAS before the reboot. The RADIUS Server still sends the accounting
record to the Accounting Framework. This policy action is only required if one of the
Resource Management Suite Products is deployed.

CDMA2000LocalAcct The RADIUS Server forwards a CDMA accounting record to the Accounting Framework.
Required for SSR mode.

CDMA2000ProxyAcct The RADIUS Server forwards the CDMA accounting message to a remote RADIUS Server,
as well as sending an accounting record to the Accounting Framework.

GSMLocalAcct The RADIUS Server sends a GSM accounting record to the Accounting Framework.

GSMProxyAcct The RADIUS Server forwards the GSM accounting message to a remote RADIUS Server, as
well as sending an accounting record to the Accounting Framework. This only supports RMS
interactions in SSR mode.

WiFiLocalAcct Sends accounting records from a Wi-Fi access point to the Accounting Framework.

WiMAXLocalAcct Sends accounting records from an ASN gateway or WiMAX home agent node to the
Accounting Framework.

WiMAXProxyAcct Forwards accounting messages from an ASN gateway or WiMAX home agent node to a
remote RADIUS server, as well as sending the accounting records to the Accounting
Framework.

PolicyRun Evaluates another policy file.


Works with RADIUS and Diameter.

Page 246 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Table 98: Accounting-Request actions (continued)

Action-name Action

PreAccounting Performs user pre-authorization prior to completing an accounting action.


In the acctReqPolicy file, PreAccounting must precede existing policy actions, such as
LocalAcct or ProxyAcct.
PreAccounting enables the RADIUS Server to retrieve AVPs from a RADIUS
ConnectionService service profile (accounting requests do not support the returnAVP action
modifier). These AVPs are available for further policy evaluation.
Examples:
- - - PreAccounting
The RADIUS Server looks up a pre-auth user based on User-Name, and retrieves AVPs
found in the Default RADIUS ConnectionService service profile.
- - - PreAccounting loginName=joe domain=[Link] service=myService
The RADIUS Server looks up the pre-auth user joe@[Link], and uses the service,
myService.
If there are no action modifiers with PreAccounting, the RADIUS Server pre-authorizes using
User-Name, and retrieves AVPs from the Default RADIUS ConnectionService.

AssignVar Enables an administrator to define variables for the assignment of values to be used as
conditions in other policies and/or values for other action modifiers.

LogMessage Enables an administrator to generate a custom log message to the RADSYS log family. Must
be configured with the “message” action modifier and can be optionally configured with the
“priority” and “attrs” action modifiers. For more information, see "CSID/MSID mismatch
detection for LDAP deployments" on page 320.
After LogMessage is executed, policy evaluation continues to the next specified policy line.

Figure 28 on page 248 shows how accounting requests are processed. The actions
specified in the diagram are specific to RADIUS, but the process flow is the same
for RADIUS and Diameter.

Service Controller 9.6.1-AAA October 12, 2012 Page 247


Chapter 7 Configuring AAA policies Network Access Guide

Figure 28: Accounting request process flow

$FFHVV
3DFNHW
1RGH
7\SH

DFFHVV5HT DFFW5HT G\QDPLF+$ 7/6 '$(

1H[W
3ROLF\ 5XOH
5XOHV

&RQGLWLRQ
12 6SHFLILHG

<(6

&RQGLWLRQ
6DWLVILHG 12

<(6 $VVLJQ9DU

$FWLRQ /RFDO$FFW$FWLRQVLQFOXGH
/RFDO$FFW /RFDO$FFW
7\SH
&'0$/RFDO$FFW
'08/RFDO$FFW
*60/RFDO$FFW
:L)L/RFDO$FFW
'HYLFH5HERRW 3UR[\$FFW :L0D[/RFDO$FFW
3ROLF\5XQ

3UR[\$FFW$FWLRQVLQFOXGH
3UR[\$FFW
&'0$3UR[\$FFW
'083UR[\$FFW
3ROLF\ *603UR[\$FFW
5XOHV :L0D[3UR[\$FFW

Page 248 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Table 99 lists action-modifiers for Accounting-Requests and the policy actions for
which they are valid.
Some modifiers only support RADIUS, some only support Diameter, and some
support both RADIUS and Diameter. For syntax and descriptions of each modifier,
see "Action modifiers" on page 262.

Table 99: Action-modifiers for Accounting-Requests

Policy action

PreAccounting
LocalAcct

ProxyAcct

DeviceReboot

CDMA2000LocalAcct

CDMA2000ProxyAcct

GSMLocalAcct

GSMProxyAcct

WiMAXLocalAcct

WiMAXProxyAcct

WiFiLocalAcct

PolicyRun

AssignVar
Action-modifier

acctDBLookup          
appendDomain           
attrs 
continueNotFound 
continue PreProcessing 
defaultProxy     
disableAcctAckOn ProxyTimeout    
discardClassAttr  
discardDomain           
domain           
domainRegexFormat           
evaluatePolicy 
extractAttr 
extractReg 
getMobileID 
getProxyService 
hotlineSet  
idleSessionRestore   
ignorePreProcessingFailure 
loginName           
message 
multimode  
myVar 
priority 
replaceDomain           
replaceMIN  

Service Controller 9.6.1-AAA October 12, 2012 Page 249


Chapter 7 Configuring AAA policies Network Access Guide

Table 99: Action-modifiers for Accounting-Requests (continued)

Policy action

PreAccounting
LocalAcct

ProxyAcct

DeviceReboot

CDMA2000LocalAcct

CDMA2000ProxyAcct

GSMLocalAcct

GSMProxyAcct

WiMAXLocalAcct

WiMAXProxyAcct

WiFiLocalAcct

PolicyRun

AssignVar
Action-modifier

rmsLocationUpdate 
runPlugIn          
service           
target    
useMobileKey 
writeAccounting          
writeCertFields 

Dynamic HA request actions


The actions for Dynamic HA Requests are handled according to:
• the mobileType action modifier defined in the accessReqPolicy file
• policies defined in the dynamicHAPolicy file
For an example configuration, see "Configuring Mobile IP using Dynamic HA
Assignment" in the “Configuring mobile services” chapter of the Service Controller:
Mobile Services Guide.
The dynamicHAPolicy file contains an ordered list of rules that are applied to
Dynamic HA-Request messages. Each rule consists of a condition expression and
an action expression.
Table 100 lists the action names that can be specified in the policy rules of the
dynamicHAPolicy file.
One or more action modifiers can be used in each rule, unless otherwise noted.

Table 100: DHA-Request actions

Action-name Action

DHAValidateOnly Performs validation of the PDSN-requested Home Agent.


This action does not support any modifiers.

DHARoundRobin Assigns HAs evenly across all HAs defined in the named HA
group.

Page 250 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Table 100: DHA-Request actions (continued)

Action-name Action

DHARoundRobinWith Assigns a specific, primary HA for a subscriber to access. If the


PrimaryHA primary HA becomes overloaded or unreachable, the
assignment of HAs is load balanced evenly across the remaining
HAs in the named HA group.

DHARoundRobinWith When a PDSN from a specified list fails, round-robin behavior


PrimaryHAandPDSN occurs. HAs are assigned from the HA group or Alternate list
Failure specified rather than assigning a primary HA to PDSNs. When
the failed PDSN is back in service, primary HAs are assigned as
in the DHARoundRobinWithPrimaryHA action.

PolicyRun Evaluates another policy file.

AssignVar Defines variables for the assignment of values to be used as


conditions in other policies and/or values for other action
modifiers.

Figure 29 on page 252 shows how dynamic HA requests are processed.


The actions specified in the diagram are specific to RADIUS, but the process flow is
the same for RADIUS and Diameter.

Service Controller 9.6.1-AAA October 12, 2012 Page 251


Chapter 7 Configuring AAA policies Network Access Guide

Figure 29: Dynamic HA process flow

$FFHVV 3DFNHW
1RGH 7\SH

DFFHVV5HT DFFW5HT G\QDPLF+$ 7/6 '$(

1H[W
3ROLF\ 5XOH
5XOHV

&RQGLWLRQ
12 6SHFLILHG

<(6

&RQGLWLRQ
6DWLVILHG 12

<(6 $VVLJQ9DU

'+$5RXQG5RELQ
$FWLRQ
:LWK3ULPDU\+$ '+$5RXQG5RELQ
DQG3'61)DLOXUH 7\SH

'+$5RXQG5RELQ '+$9DOLGDWH
:LWK3ULPDU\+$ 2QO\
3ROLF\5XQ

3ROLF\
5XOHV

Page 252 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Table 101 lists action-modifiers for Dynamic HA-Requests and the policy actions for
which they are valid. For syntax and descriptions of each modifier, see "Action
modifiers" on page 262.

Table 101: Action-modifiers for Dynamic HA-Requests

Policy action

DHARoundRobin

PolicyRun
DHAValidateOnly

withPrimaryHA
DHARoundRobin

andPDSNFailure
withPrimaryHA
DHARoundRobin

AssignVar
Action-modifier

allowHA   
continue PreProcessing 
evaluatePolicy 
extractAttr 
extractReg 
haAlternateList 
haGroup   
ignorePreProcessingFailure 
myVar 
pdsnList 
policyFailover Enabled   
primaryHA  

Service Controller 9.6.1-AAA October 12, 2012 Page 253


Chapter 7 Configuring AAA policies Network Access Guide

TLS request actions


The actions for TLS Requests are handled according to:
• the EAP-Policy action modifier defined in the accessReqPolicy file and
authenticate-policy="TLSPolicy" in [Link]
• policies defined in the TLSPolicy file
The TLSPolicy file contains an ordered list of rules that are applied to TLS Request
messages. Table 102 lists the action names that can be specified in the policy rules
of the TLSPolicy file. Each rule consists of a condition expression and an action
expression.
For more information about EAP, see the Extensible Authentication Protocol Guide.
This section describes TLSPolicy action modifiers for RADIUS and Diameter:
• RADIUS TLSPolicy action modifiers
• Diameter TLSPolicy action modifiers

Table 102: TLS-Request actions for RADIUS and Diameter

Action-name Action

TLSLocalAA Performs phase 2 local authentication.


Performs local authorization.
The authorizeLoginName and authorizeDomain action-modifiers
override those used in the outer policy action such as LocalAA
and CDMA2000LocalAA.
RADIUS notes:
• For RADIUS, authorize="n" cannot be used if WiMAXLocalAA
is used.

TLSProxyAA Performs phase 2 remote authentication.


For RADIUS and Diameter, authorizeLoginName and
authorizeDomain override those in the outer policy actions, such
as RADIUS ProxyAA and CDMA2000ProxyAA, and Diameter
WiMAXLocalAA.
RADIUS notes:
• For RADIUS WiMAX environments the authorizeProxyLevel
modifier is required.
• In WiMAX environments RADIUS only supports CHAP and
MSCHAPv2 for phase 2 of EAP-TTLS.
• For RADIUS, authorize="n" cannot be used if WiMAXLocalAA
is used.
Diameter notes:
• In all environments Diameter only supports MSCHAPv2 for
phase 2 of EAP-TTLS.

Figure 30 on page 255 shows how TLS requests are processed.

Page 254 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Figure 30: TLS process flow

$FFHVV 3DFNHW
1RGH 7\SH

DFFHVV5HT DFFW5HT G\QDPLF+$ 7/6 '$(

1H[W
3ROLF\ 5XOH
5XOHV

&RQGLWLRQ
12 6SHFLILHG

<(6

&RQGLWLRQ
6DWLVILHG 12

<(6

$FWLRQ
7\SH

7/63UR[\$$ 7/6/RFDO$$

Service Controller 9.6.1-AAA October 12, 2012 Page 255


Chapter 7 Configuring AAA policies Network Access Guide

RADIUS TLSPolicy Table 103 lists the RADIUS action-modifiers for TLS-Requests and the policy
action modifiers actions for which they are valid. For syntax and descriptions of each modifier, see
"Action modifiers" on page 262.

Table 103: RADIUS action-modifiers for TLS-Requests

Policy action

TLSLocalAA

TLSProxyAA
Action-modifier

allowLockedoutUsers  
appendDomain  
authenticate 
authorize  
authorizeDomain  
authorizeLoginName  
authorizeProxyLevel 
discardDomain  
domain  
domainRegexFormat  
EAP-Policy 
LDAPPassword Attribute  
LDAPUserFilter  
loginName  
loginNameRegex Format  
outageAction 
outageDomain 
outageLoginName 
outageReject Message 
outageService 
rejectPolicy 
replaceDomain  
target 
One or more action-modifiers can be used in each rule, unless otherwise noted.
If RADIUS is configured to write account pending records:
• the authentication modifiers specified for TLSLocalAA or TLSProxyAA are used
in the pending record

Page 256 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

• the login and domain fields of the inner user ID are used in the pending record if
authentication modifiers are not specified for TLSLocalAA or TLSProxyAA
When a representative user is specified in the outer policy, that is, LocalAA, the
representative user is used for authorization. Otherwise the inner TLS user is used
for authorization. For example:
accessReqPolicy:
- - - LocalAA EAP-Policy=ttlspolicy authorizeLoginName=rep
authorizeDomain=[Link]
TLSPolicy:
- - - TLSLocalAA authorizeLoginName=innerRep
authorizeDomain=[Link]
TLSProxyAA can be used with the [Link] RADIUSServerGroup element. For
information, see "RADIUSServer Group" on page 358.

Diameter TLSPolicy Table 104 lists the Diameter action-modifiers for TLS-Requests and the policy
action modifiers actions for which they are valid. For syntax and descriptions of each modifier, see
"Action modifiers" on page 262.

Table 104: Diameter action-modifiers for TLS-Requests

Policy action

TLSLocalAA

TLSProxyAA
Action-modifier

authenticateDomain 
authorizeDomain  
authorizeLoginName  
EAP-Policy 
outageReject Message 
unknownUserSecret 

Service Controller 9.6.1-AAA October 12, 2012 Page 257


Chapter 7 Configuring AAA policies Network Access Guide

DAE request actions


The actions for Dynamic Authorization Extensions requests are handled according
to policies defined in the daeReqPolicy file.
The daeReqPolicy file contains catch-all rules to apply to incoming DAE requests
for the ProxyDAE and HLRProxyDAE actions. ProxyDAE enables CoA and DM
messages on a local network and HLRProxyDAE enables support for unsolicited
requests from an HLR in WLAN deployments. For information about WLAN
deployments, see the 3GPP AAA Wm Interface specification.
Administrators can also specify the target action modifier to send CoA and DM
messages to a device on a visited network, for roaming scenarios. For more
information about configuring DAE, see the chapter “Configuring RADIUS
mid-session hotlining” in the Service Controller: WiMAX Guide.
Note If CoA/DM cloning is configured, a remote target cannot be configured in
daeReqPolicy. For more information about CoA/DM cloning, see the
chapter “Configuring RADIUS mid-session hotlining” in the Service
Controller: WiMAX Guide.

Rules Each rule consists of a condition expression and an action expression. The
condition expression is as follows:
<attribute> <operator> <value>
where
<attribute> is:
'Client-IP-Address'
'-’
<operator> is:
Equals
'-'
<value> is a range
For more information about conditions, see "Conditions" on page 235.

Examples This section provides examples of how to use the daeReqPolicy file.

Local network
If a Hotlining Device is on a local network, use the following:
- - - ProxyDAE
In this case the Service Controller retrieves the information about the Hotlining
Device from the Profile Database.

Proxy
If a Hotlining Device is remote, use the following:

Page 258 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Client-IP-Address Equals [Link] ProxyDAE


target="AAAproxy"
- - - ProxyDAE
In this case, the Service Controller uses the value of the target action modifier to
retrieve the target defined in [Link].
The example above specifies the target “AAAproxy”, which triggers the Service
Controller to retrieve target information from the RADIUSServer section in
[Link] that has the target name “AAAproxy”:
<RADIUSServer
TargetName="AAAproxy"
TargetHost="[Link]"
DAE-Port=3799
Secret=SECRET
RequestTimeout=1
MaxRetries=0/>
Note The target in [Link] must be defined in a RADIUSServer element and
not in a RADIUSServerGroup element.

WLAN deployments
To support unsolicited requests from an HLR in WLAN deployments, use the
following:
- - - HLRProxyDAE

Table 105: DAE-Request actions

Action-name Action

ProxyDAE • ProxyDAE with no action modifier determines the intended


target from the NAS-IP-Address provided in the DAE request
(for non-roaming)
• ProxyDAE with target action modifier determines the target
from the IP address extracted from the lookup of the specified
target in [Link] (for roaming)
• looks up and validates the DAE shared secret
• ensures the NAS’ response to the CoA or DM message is
properly returned to the sender
• checks that the Event-Timestamp attribute (if present) is
current within a specified time window (configured in
[Link])

Service Controller 9.6.1-AAA October 12, 2012 Page 259


Chapter 7 Configuring AAA policies Network Access Guide

Table 105: DAE-Request actions (continued)

Action-name Action

HLRProxyDAE In WLAN deployments, enables support of unsolicited requests


from an HLR to remove or update subscriber sessions. Enables
support for the following HLR requests:
• MAP_CANCEL_ LOCATION
• MAP_DELETE_ SUBSCRIBER_DATA
• MAP_INSERT_ SUBSCRIBER_DATA
The request from the HLR must contain the following AVPs:
• User-Name
• NAS-IP-Address
• WLAN-HLR-Request-Type
The WLAN-HLR-Request-Type AVP can specify the following
requests:
• Delete-Subscriber-Data: removes all WLAN RMS sessions
(EAP, profile). If a subscriber is online (SSR session is
present), the Service Controller sends a DM to a proxy target
with a name matching the value of the NAS-IP-Addr, prefixed
with a colon (from the SSR session) found in [Link]. If
NAS-IP-Addr is not present in SSR, the Service Controller
uses the NAS-Identifier, prefixed with a colon.
• Disconnect-Subscriber, Replace-Subscriber-Data: removes
WLAN RMS sessions and sends ACK to HLR. For these
requests the Service Controller does not send a DM/CoA to
the TTG/PDG.

Figure 31 on page 261 shows how DAE messages are processed.

Page 260 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Figure 31: RADIUS Server DAE process flow

$FFHVV 3DFNHW
1RGH 7\SH

DFFHVV5HT DFFW5HT G\QDPLF+$ 7/6 '$(

1H[W
3ROLF\ 5XOH
5XOHV

&RQGLWLRQ
12 6SHFLILHG

<(6

&RQGLWLRQ
6DWLVILHG 12

<(6

$FWLRQ
7\SH

GDH5HT3ROLF\

The only action modifier for DAE Requests is target for ProxyDAE. For syntax and
descriptions of each modifier, see "Action modifiers" on page 262.

Service Controller 9.6.1-AAA October 12, 2012 Page 261


Chapter 7 Configuring AAA policies Network Access Guide

Action modifiers
This section provides descriptions for all supported action modifiers.

ACCT-Mode Syntax: ACCT-Mode=<flow | session | none>


The ASN or HA sends an Access-Request including the Accounting-Capabilities
AVP and the Service Controller responds with suggested Accounting -Capabilities
based on the value of ACCT-Mode. ACCT-Mode can be added for RADIUS and/or
Diameter.
Optional.
The Accounting-Capabilities AVP can have the following values:
• missing
• 0- no accounting
• 1 - IP session based
• 2 - flow based
• 3 - both (session based and flow based
The following list describes ACCT-Mode values and how the Service Controller
interprets these values to respond to an ASN or HA.
• session: (IP-Session-Based) (Default)
– ASN: If ASN supports both session flow based accounting the Service
Controller chooses session based. If the ASN supports session or
flow-based the Service Controller responds with the same. Otherwise the
Service Controller chooses session based.
– HA: If the HA supports both session flow based accounting the Service
Controller chooses session based. If the HA supports session or flow
based the Service Controller responds with the same. If the HA supports
no-accounting the Service Controller chooses no-accounting.
• flow: (flow-based)
– ASN: If ASN supports both session and flow based accounting the Service
Controller chooses flow based. If the ASN supports session or flow based
the Service Controller responds with the same. Otherwise the Service
Controller chooses session based.
– HA: If the HA supports both session flow based accounting the Service
Controller chooses flow based. If the HA supports session or flow based
the Service Controller responds with the same. If the HA supports
no-accounting the Service Controller chooses no-accounting.
• none: (equivalent to no accounting)
– ASN: the Service Controller responds to the ASN to use session based
accounting.

Page 262 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

– HA: the Service Controller responds and specifies no accounting for the
subscriber.
Note For RADIUS, when the ASN or HA does not send Accounting-Capabilities
in the Access-Request, RADIUS does not send any
Accounting-Capabilities in the Access-Accept message.
For Diameter when the ASN does not send Accounting-Capabilities in the
DER, Diameter sends "session based" as the accounting capability in the
DEA.

acMatchAttribute Syntax: acMatchAttribute=[<Vendor Name>:]<AVP or VSA>


The vendor name is optional and can only be used for RADIUS deployments. Do
not use the vendor name for Diameter deployments.
Example: acMatchAttribute=Calling-Station-ID
Use this modifier to enable AVP-based Access Control.
During authorization, find this AVP or VSA in a RADIUS Access-Request or
Diameter DER. Use any AVP or VSA found in a RADIUS or Diameter dictionary that
is loaded to the Profile Database.
Use this modifier with the acService modifier, which specifies the Access Control
service in which to provision the AVP value to match. The Service Controller
attempts to match the AVP value in the request to the AVP value provisioned in the
specified Access Control.
If there is no acService modifier, the Service Controller uses the AVP value
specified in the default Access Control service “Access Control”.
Note The acMatchAttribute modifier does not support RADIUS octetstring
(subtype) attributes or Diameter grouped attributes.
In RADIUS deployments, the acMatchAttribute modifier may not be used on the
same policy line as “authorize=n”.
The value of the AVP or VSA is provisioned on the Access Attribute tab of the
Access Control service applied to a subscriber’s profile set. For more information,
see "Configuring AVP-based access control" on page 70.

acService Syntax: acService=<accessControlService>|<myVar:variableName>


An access control service profile name assigned to a subscriber during an
Access-Request. This value overrides the default name defined in the
[Link] file. Names can be hard coded or a reference to a myVar variable.
To perform ACL checks using the PreAuthorize action, the acService modifier must
be configured. For more information, see Configuring PreAuthorize using Access
Control Limits (ACL) for proxy.

Service Controller 9.6.1-AAA October 12, 2012 Page 263


Chapter 7 Configuring AAA policies Network Access Guide

acctDBLookup Syntax: acctDBLookup=<y|n>


Perform database information retrieval for accounting requests. Disabling this
increases performance; however, it does prevent retrieval of database information,
such as "account name", "Billing ID", and "Domain". Setting this action modifier
overrides the value set in [Link].
This action modifier generates an Access-Request that comprises two call events:
one database access for authentication and one for authorization.
Default is the value set in [Link] (Default: y).

allowHA Syntax: allowHA=<All | InGroup | None>


Performs an optional validation of the PDSN-requested Home Agent. Additionally, it
can perform allocation of a Home Agent from a group of Home Agents in a
round-robin fashion.
• All: Validate that the Home Agent is modeled in the system. If not found, assign
one from the HA group.
• InGroup: Validate that the Home Agent is modeled in the HA Group. If not
found, assign one from the HA group.
• None: Ignore the requested Home Agent and assign one from the HA group.

allowLockedoutUsers Syntax: allowLockedoutUsers=<y/n>


If allowLockedoutUsers=y, RADIUS authorizes locked out users as per the
LockoutConfig settings for the NAS/PDSN vendor found in [Link] and returns
an Access-Accept. Setting this value to "y" has no effect if there is no
LockoutConfig specified in [Link].
If allowLockedOutUsers=n, RADIUS returns an Access-Reject for locked out users.
For more information, see "Configuring user and network lockout" on page 38.
Default: y

appendDomain Syntax: appendDomain=<domain>


A domain assigned to the subscriber if no domain is found in the User-Name
attribute. This action-modifier has no effect if a domain is found in the User-Name
attribute.

appendService Syntax: appendService=<service-profile-name>


The name of the service profile to be delivered as part of the subscriber service. For
example, attributes in the service profile are delivered along with the attributes from
other service profiles authorized for the request.
This action modifier generates an Access-Request that comprises two call events:
one database access for authentication and one for authorization.

Page 264 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

assignVisitedFramed Syntax: assignVisitedFramedIP=<never | ifAvailable | ifExclusive>


IP Indicates to RADIUS whether to assign a Framed-IP-Address in a visited network.
Possible values:
• never: (Default)
– If neither Visited-Framed-IP-Address and Framed-IP-Address are present,
RADIUS does not return a Framed IP.
– if Visited-Framed-IP-Address is in the Access-Request and
Framed-IP-Address is not in the Service profile, RADIUS does not return a
Framed IP.
– If Visited-Framed-IP-Address is not in the Access-Request and
Framed-IP-Address is in the Service profile, RADIUS returns
Framed-IP-Address.
– If both Visited-Framed-IP-Address and Framed-IP-Address are present,
RADIUS returns Framed-IP-Address.
• ifAvailable:
– If neither Visited-Framed-IP-Address and Framed-IP-Address are present,
RADIUS does not return a Framed IP.
– if Visited-Framed-IP-Address is in the Access-Request and
Framed-IP-Address is not in the Service profile, RADIUS returns
Visited-Framed-IP-Address in the Access-Accept.
– If Visited-Framed-IP-Address is not in the Access-Request and
Framed-IP-Address is in the Service profile, RADIUS returns
Framed-IP-Address.
– If both Visited-Framed-IP-Address and Framed-IP-Address are present,
RADIUS returns both.
• ifExclusive:
– If neither Visited-Framed-IP-Address and Framed-IP-Address are present,
RADIUS does not return a Framed IP.
– if Visited-Framed-IP-Address is in the Access-Request and
Framed-IP-Address is not in the Service profile, RADIUS returns
Visited-Framed-IP-Address in the Access-Accept.
– If Visited-Framed-IP-Address is not in the Access-Request and
Framed-IP-Address is in the Service profile, RADIUS returns
Framed-IP-Address.
– If both Visited-Framed-IP-Address and Framed-IP-Address are present,
RADIUS returns Framed-IP-Address.

Service Controller 9.6.1-AAA October 12, 2012 Page 265


Chapter 7 Configuring AAA policies Network Access Guide

assignVisitedHome Syntax: assignVisitedHomeAgent=<never | ifAvailable | ifExclusive>


Agent Indicates to RADIUS to process the vHA-IP-MIP4 attribute and decide whether to
assign an HA in a visited network. Possible values:
• never: (Default)
– If neither vHA-IP-MIP4 and hHA-IP-MIP4 are present, RADIUS rejects the
subscriber.
– if vHA-IP-MIP4 is in the Access-Request and hHA-IP-MIP4 is not in the
Service profile, RADIUS rejects the subscriber.
– If vHA-IP-MIP4 is not in the Access-Request and hHA-IP-MIP4 is in the
Service profile, RADIUS returns hHA-IP-MIP4.
– If both vHA-IP-MIP4 and hHA-IP-MIP4 are present, RADIUS returns
hHA-IP-MIP4.
• ifAvailable:
– If neither vHA-IP-MIP4 and hHA-IP-MIP4 are present, RADIUS rejects the
subscriber.
– if vHA-IP-MIP4 is in the Access-Request and hHA-IP-MIP4 is not in the
Service profile, RADIUS returns vHA-IP-MIP4.
– If vHA-IP-MIP4 is not in the Access-Request and hHA-IP-MIP4 is in the
Service profile, RADIUS returns hHA-IP-MIP4.
– If both vHA-IP-MIP4 and hHA-IP-MIP4 are present, RADIUS returns both.
• ifExclusive:
– If neither vHA-IP-MIP4 and hHA-IP-MIP4 are present, RADIUS rejects the
subscriber.
– if vHA-IP-MIP4 is in the Access-Request and hHA-IP-MIP4 is not in the
Service profile, RADIUS returns vHA-IP-MIP4.
– If vHA-IP-MIP4 is not in the Access-Request and hHA-IP-MIP4 is in the
Service profile, RADIUS returns hHA-IP-MIP4.
– If both vHA-IP-MIP4 and hHA-IP-MIP4 are present, RADIUS returns
hHA-IP-MIP4.

attrs Syntax: attrs=<attribute name>|<attribute value>


[,<attribute name>|<attribute value>]
where:
<attribute name> is a string (with no white space) representing the name of the
attribute value that is logged.
<attribute value> is of the form:
<static string>|<myVar variable
name>|[PreAuth:]$[<vendor-name>:]<attribute-name>
[,<attribute name>|<attribute value>] specifies a comma-delimited list of
attribute name and value pairs to log along with the user-defined message.
Every related attribute name and attribute value is separated by the pipe
character '|'.

Page 266 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Used with the LogMessage action.


Supported attribute values:
• static string (with no white space).
• myVar variable.
• RADIUS attribute of type string:
• Non-RFC attribute of type string.
• PreAuth attribute
Note A PreAuth attribute is supported in access-request policy files; a PreAcct
attribute is supported in acct-request policy files.
Example:
attrs=ID|555,CSID|$Calling-Station-Id,ESN|$STARENT:3GPP2-ESN,
UID|myVar:uid,SERVICE|PreAuth:$Configuration-Token
This example is logged as:
ID=555, CSID=5551234567, ESN=AABBCCDD, UID=1234567890, SERVICE=test

authenticate Syntax: authenticate=<y|n>


Authenticate the subscriber.
Regardless of the setting, the subscriber must be in the database for the request to
be accepted.
Default: y

authenticateDomain Syntax: authenticateDomain=<domain>


A replacement domain used for authentication of the subscriber. This value is not
used for accounting or session tracking.

authorizationPolicy Syntax: authorizationPolicy=<path>


Specifies the absolute path to the authorization policy file.
RADIUS fails to HUP/start if this action modifier is used in conjunction with any of
the following action modifiers:
• authorize=n
• authorizeLoginName
• authorizeDomain
• useAuthorizeBillingId
• authorizeDefaultLoginName
• authorizeDefaultDomain

Service Controller 9.6.1-AAA October 12, 2012 Page 267


Chapter 7 Configuring AAA policies Network Access Guide

authorize Syntax: authorize=<y|n>


Perform local authorization for a subscriber. Authorization includes retrieval of
service attributes and access control.
Default: y

authorizeDefault Syntax: authorizeDefaultDomain=<domain>


Domain A default domain for authorizing the subscriber when the subscriber is not defined
in the local database.
Requires the authorizeDefaultLoginName option.

authorizeDefault Syntax: authorizeDefaultLoginName=<loginName>


LoginName A default login name for authorizing the subscriber when the subscriber is not
defined in the local database.
This action modifier generates an Access-Request that comprises two call events:
one database access for authentication and one for authorization.

authorizeDomain Syntax: authorizeDomain=<domain>|<myVar:variableName>


A replacement domain to use for service authorization, specified explicitly or by a
reference to a myVar variable.

authorizeLoginName Syntax: authorizeLoginName=<loginName>|<myVar:variableName>


A replacement login name to use for service authorization, specified explicitly or by
a reference to a myVar variable. The authorizeDomain action-modifier must be
used as well.
Is authorizeLoginName is used with both accessReqPolicy and TLSPolicy the
instance of authorizeLoginName in TLSPolicy takes priority over the instance in
accessReqPolicy.

authorizeProxyLevel Syntax: authorizeProxyLevel=<l|r|L>


Options are:
• l—merge with local precedence (merge attributes from local and remote
servers, but, in the case of identical attributes, give precedence to local
attributes)
• L—complete local authorization (service attributes returned from the proxy
target are ignored; the RADIUS Server uses the attributes defined locally)
• r—merge with remote precedence (merge attributes from local and remote
servers, but, in the case of identical attributes, give precedence to remote
attributes)
This modifier specifies the authorization level for proxy authorization. The level can
be hardcoded or a RADIUS attribute of type string. Non-RFC attributes require the
equipment vendor name to be specified.
Merge does not apply to RADIUS Class (25) attributes.

Page 268 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

If authorizeDomain is not specified, the subscriber's domain name is re-used.


If authorizeLoginName is not specified, the subscriber's login name is re-used.
If defined with a RADIUS attribute, the value of the attribute must be an exact match
of one of the possible values.
If defined with a RADIUS attribute and the value of the attribute cannot be resolved,
complete remote authorization is used.
Default:
• If neither authorizeLoginName nor authorizeDomain is specified, level R is
used internally by RADIUS for complete remote authorization (R is NOT a valid
entry here).
• If authorizeLoginName or authorizeDomain are specified, level L is used for
complete local authorization.
The ‘authorize-proxy-level’ modifier supports:
• string RADIUS attribute values
Example:
- - - ProxyAA target=$Called-Station-Id
authorizeProxyLevel=$Filter-Id
• string RADIUS VSA values
Example:
- - - ProxyAA target=$STARENT:3GPP2-ESN \
authorizeProxyLevel=$STARENT:3GPP2-Container
• attributes received from a PreAuthorize action

BTSCheck Syntax: BTSCheck=<Y|N>


Set the accessReqPolicy modifier BTSCheck to “Y” to enable the WiMAX restricted
mobility feature. When the WiMAX restricted mobility feature is enabled, the
Service Controller checks the BSID in an Access-Request against BSIDs
provisioned against a subscriber in Service Manager to decide if a subscriber is
granted access to the network.
Considerations:
• The Service Controller checks the incoming BSID against BSIDs provisioned at
the user, domain, and organization contexts, and if a BSID at any of these
contexts matches the incoming BSID, the check passes.
• The Service Controller checks the incoming BSID against all vendors for which
BSIDs are provisioned.
• BTSCheck can be specified for a policy line that contains a “backup” service. In
this case, BSIDs must also be provisioned against the “backup” service in
Service Manager.
• If the WiMAX-BS-ID is not present in the Access-Request, the Service
Controller also looks for the BSID in the Called-Station-Id attribute.

Service Controller 9.6.1-AAA October 12, 2012 Page 269


Chapter 7 Configuring AAA policies Network Access Guide

• If the BSID check is done using the incoming WiMAX-BS-ID, the case of the
provisioned BSID does not matter because the incoming WiMAX-BS-ID is in
hex format.
If the BSID check is done on the incoming 3GPP-BSID or BSID in the Called
Station-Id, the Service Controller does a case-sensitive match with the
provisioned BSID.
If the WiMAX-BS-ID is not present in the Access-Request, the Service Controller
also looks for the BSID in the Called-Station-Id attribute.
When BTSCheck=”Y”:
• if the BSID from the Access-Request matches a BSID provisioned against the
subscriber, the Service Controller returns an Access-Accept
• if the BSID in the Access-Request doesn’t match any BSIDs provisioned
against the subscriber, the Service Controller sends a reject or retrieves the
service specified by BTSService and returns this service for the subscriber
– if the BTSService modifier is present in the accessReqPolicy, and
cacheMode is set to “L”, when the BSID check doesn’t find a match, the
Service Controller retrieves and caches service specified by BTSService
and returns the cached service to the Ericsson BRAS during the second
phase authentication.
– If cacheService is present in the same policy line, the service specified by
BTSService is cached and used instead of a service specified by
cacheService.
– if BTSService is set to “reject” the Service Controller returns an
Access-Reject
The actions WiMAXLocalAA, CDMA2000LocalAA, LocalAA, GSMLocalAA,
WiFiLocalAA, and DMULocalAA support the BTSCheck modifier.
Default=N
For more information about provisioning BSIDs against subscribers, see the
Service Manager: Services Provisioning Guide for AAA.

BTSService Syntax: BTSService=<Reject|<service>>


A service the Service Controller returns for a subscriber when the result of the BSID
check (triggered by BTSCheck) is to reject the subscriber.
Only specify one instance of BTSService in a policy line.
myVars are supported for BTSService.
If the result of the BSID check is to reject the subscriber, BTSService provides the
following options:
• Reject: when BTSService is set to “Reject” the Service Controller returns an
Access-Reject for the subscriber.
• <service>: when BTSService specifies a Connection Service profile, the
Service Controller returns the Connection Service profile in an Access-Accept
for the subscriber.

Page 270 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

• In the case where the accessReqPolicy includes the modifier cacheMode=”L”, if


the BSID check doesn’t find a match and BTSService specifies a Connection
Service profile, the Service Controller retrieves and caches the profile specified
by BTSService. The cached profile is returned for second phase authentication
with an Ericsson BRAS.
– If cacheService is present in the same policy line, the service specified by
BTSService is cached and used instead of the service specified by
cacheService.
The actions WiMAXLocalAA, CDMA2000LocalAA, LocalAA, GSMLocalAA,
WiFiLocalAA, and DMULocalAA support the BTSService modifier.

cacheCertFields Syntax: cacheCertFields=<y | n>


When set to y the Service Controller examines the device’s client certificate and
extracts and stores the CN and O portions of the certificate’s subject field in an
RMS WiMAX session. The Service Controller stores the value of CN and O in the
X509_CN and X509_O attributes in RMS.
Default: n

checkNasGroupLimit Syntax: checkNasGroupLimit=<y|n>


The NasGroup limit should be checked.
Applies only to the CallCheckAA action.
Default: y

checkSession Syntax: checkSession=<y|n>


Used with Wi-Fi roaming optimization feature. If set to ‘y’, RMS checks for an
existing session prior to processing other actions. In this case, the authenticate
action modifier must be set to ‘n’ to prevent valid Access-Requests from failing
authentication because of missing login credentials.
When used with two-stage authentication, set to ‘y’, a cached MAC address is
compared to the MAC address returned in the second access request packet.
Set to ‘n’ to perform full user authentication.
Applies only to the WiFiLocalAA policy action.
Default: n

continueNotFound Syntax: continueNotFound=<y|n>


Determines the action to take if the subscriber or service specified by the
PreAuthorize or PreAccounting action is not in the database. If ‘y’, policy evaluation
continues. If ‘n’, the request is rejected with the appropriate RADIUS operations log
message.
Valid only for the PreAuthorize and PreAccounting actions.
Default: n

Service Controller 9.6.1-AAA October 12, 2012 Page 271


Chapter 7 Configuring AAA policies Network Access Guide

continue Syntax: continuePreProcessing=<y|n>


PreProcessing Enables the evaluation of subsequent AssignVar policies. If set to 'n', evaluation of
subsequent AssignVar policies is skipped. If 'y', subsequent AssignVar policies are
evaluated if their condition is satisfied.
Default: n

defaultProxy Syntax: defaultProxy=<target>


The name of a proxy target, defined in the proxies file, to which to forward an
Access-Request or Accounting-Request message if local authentication fails
because the subscriber account does not exist.

disableDMU Syntax: disableDMU = <y|n>


Specifies whether authentication is performed using DMU key exchange. When set
to 'y', no DMU key exchange is performed. Instead, the CHAP-Password is
authenticated against an attribute determined by the mobileType setting:
• If mobileType is SimpleIP, the CHAP-Password is authenticated against the
CHAP-Key attribute set in the subscriber's Mobile Extension table.
• If mobileType is either MobileHA or MobileFA, the CHAP-Password is
authenticated against the MN-AAA key attribute set in the subscriber's Mobile
Extension table.
Default: n

disableAcctAckOn Syntax: disableAcctAckOnProxyTimeout=<true|false>


ProxyTimeout Used when a RADIUS client (Service Controller, NAS) sends an Accounting
request to a RADIUS Service Controller that is configured to proxy the request to a
proxy target (such as a partner Service Controller).
When disableAcctAckOnProxyTimeout=true, if the proxy target times-out in
processing an Accounting request and does not return an Acknowledge message
to the RADIUS Service Controller that proxied the request, the RADIUS Service
Controller does not return an Acknowledge message to the RADIUS client.
This modifier is configured on the RADIUS Service Controller that proxies the
Accounting messages.
Note Setting this modifier to “true” could cause the RADIUS client to retry the
Accounting request if the proxy target or the RADIUS Service Controller are
not available. The number of retries depends on configuration settings for
the RADIUS client.
Default: false

discardClassAttr Syntax: discardClassAttr=<y|n>


Specifies whether the RADIUS Class attribute should be discarded from the
Access-Accept being returned to the RADIUS client.
Default: n

Page 272 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

discardDomain Syntax: discardDomain=<y|n>


Discard any domain in the User-Name attribute.
Default: n

discardService Syntax: discardService=<y|n>


Discard a requested service if one is found in the User-Name attribute.
Default: n

dnPrefix Syntax: dnPrefix=<LDAP-dnPrefix>


A prefix for the dnSearchBase.
For LDAP targets only.
Default: dnPrefix value provisioned for the LDAP target

dnSearchBase Syntax: dnSearchBase=<dnSearchBase>


The dnSearchBase required for LDAP authentication.
For LDAP targets only.

dnSearchBaseReq Syntax: dnSearchBaseReqExp=<dnSearchBaseReqExp>


Exp The regular expression format of the dnSearchBase required for LDAP
authentication.
For LDAP targets only.

domain Syntax: domain=<domain>


A domain to assign to the subscriber. This replaces the domain in the User-Name
attribute or appends a domain if one is not found.

domainRegexFormat Syntax: domainRegexFormat=s<c><reg_expression><c><format expression>


where
• <c> is a separator character
• <regular expression> is a POSIX regular expression (see the Unix man page
regex)
• <format expression> is <[<prefix string>]${<pattern index>}[<suffix string>]>...
• <pattern index> specifies the sub-pattern in the regular expression by (), 0 is
the index of the whole match. If any pattern does not have a match, the
${<pattern index>} is replaced by an empty string. Prefix string and suffix string
may contain any ASCII character to appear as output.
This is a regular expression to find the domain in the User-Name attribute. If not
specified, the default behavior is loginname@domain or domain\loginname.

Service Controller 9.6.1-AAA October 12, 2012 Page 273


Chapter 7 Configuring AAA policies Network Access Guide

Example: s/([^@]+)(@(.*)){0,1}/${3}-{1}
This expression extracts everything before ‘@’ into pattern 1, extracts the first
string after the ‘@’ into pattern 3 and swaps them, putting them together with ‘-’.
Input: user; Result: -user
Input: user@[Link];Result: [Link]-user
Input: user@[Link]@[Link]; Result: [Link]-user

EAP-Policy Syntax: EAP-Policy=<EAP policy name>


An EAP policy to be used for authentication. The policies must be defined in the
[Link] configuration file.
Default: “default”

EAP-OTA-Policy Syntax: EAP-OTA-Policy=<EAP method specified in [Link]>


An EAP method to be used for OTA provisioning. The EAP method must be
specified in the [Link] configuration file.
If the “EAP-OTA-Policy” action modifier is not present, the EAP method specified by
the “EAP-Policy” action modifier is used.
Applies to the actions CDMALocalAA, and WiMAXLocalAA.

enableIPReach Syntax: enableIPReach=<Never/Always/Override>


Specifies whether or not to apply the IPReachability service profile. For example,
apply the IPReachability service profile, if assigned in the subscriber’s profile set:
• only when the subscriber accesses the network using CDMA
• not when the subscriber accesses the network using dial-up
RADIUS looks for the IPReachability service profile only if enableIPReach =
‘Always’ or ‘Override’.
• Never (default). RADIUS:
– ignores the 3GPP2-DNS-Update-Capability VSA
– does not perform DNS updates
– does not return the DNS-Update-Required VSA in the Access-Accept
message if the 3GPP2-DNS-Update-Capability VSA was included by a
remote HA, thus preventing the remote HA from performing DNS updates
• Override. RADIUS performs DNS updates and explicitly forbids the remote HA
PDSN from performing the update.
• Always. RADIUS returns DNS-Update-Required = 1 (but does not insert the IP
Reach class attribute) in the Access-Accept message to signal to the remote
HA PDSN that it may proceed with a DNS update, if the Access-Request
message contains 3GPP2-DNS-Update-Capability = 1

Page 274 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

evaluatePolicy Syntax: evaluatePolicy=<policy-file>


The file name of a policy file to evaluate.
Only valid for the policyRun action.
Cyclic execution (for example, <Policy1> Run <Policy2>, <Policy2> Run <Policy1>)
is not supported.

extractAttr Syntax: extractAttr=[<vendor-name>:]<attribute-name>


The RADIUS attribute against which to apply a regular expression. The attribute
must be of type string. The attribute can be of type string or octet string (binary).
When used in conjunction with the AssignVar policy action, the extractAttr modifier
also supports attributes retrieved using the PreAuth tag for access-request policy
files or the PreAcct tag for act-request policy files.
Examples:
For access-req: [PreAuth:][<vendor-name>:]<attribute-name>
For acct-req: [PreAcct:][<vendor-name>:]<attribute-name>
For non-RFC attributes, the optional vendor part specifies the equipment vendor
name, for example, CISCO.
Required if extractReg is configured.

extractReg Syntax: extractReg=<regFormatExp>


The regular expression to be applied against the value of the attribute identified in
extractAttr.
The regular expression can be applied against string or octet string (binary)
attributes.
Required if extractAttr is specified.

Force-WiMAX- Syntax: Force-WiMAX-Session=<y|Y|n|N|ifMACMatches>


Session Settings:
• y - the RADIUS and/or Diameter creates a WiMAX session, or replaces a
WiMAX session that has a pseudo id that matches the pseudo id in the
Access-Request.
This setting prevents RADIUS and/or Diameter from rejecting Access-Requests
when the pseudo id check fails.
• n - RADIUS and/or Diameter rejects the Access-Request if the pseudo id check
fails.
• ifMACMatches (only for RADIUS) - the RADIUS server compares the MAC
address found in the Calling-Station-ID of the Access-Request, and the pseudo
id from the Access-Request with the MAC address and pseudo id in the
subscriber’s WiMAX session in RMS:
– if the MAC address and pseudo id from the Access-Request match the
MAC address and pseudo id in the subscriber’s WiMAX session in RMS,

Service Controller 9.6.1-AAA October 12, 2012 Page 275


Chapter 7 Configuring AAA policies Network Access Guide

RADIUS replaces the WiMAX session (the same behaviour as when


Force-WiMAX-Session is set to “y”)
– if the MAC address from the Access-Request does not match the MAC
address in the subscriber’s WiMAX session, and the pseudo id from the
Access-Request matches the pseudo id in the subscriber’s WiMAX
session, RADIUS preserves the subscriber’s WiMAX session, logs a
RADSYS WARN log message indicating a possible fraudulent attempt was
stopped, and returns an Access-Reject.
The actions CDMA2000LocalAA and WiMAXLocalAA support the
Force-WiMAX-Session modifier.
Note When using Force-WiMAX-Session with CDMA2000LocalAA, also set a
value for hotlineSet.
Note Force-WiMAX-Session only works for the initial Access-Request/DER.
Default: n

getMobileID Syntax: getMobileID=<y|n>


Replace the value of the Calling-Station-Id attribute in the client request with the
MIN value provisioned in the subscriber's Mobile Extension table. If the
Calling-Station-Id attribute is not present in the request, a Calling-Station-Id attribute
is added with the MIN value from the subscriber's Mobile Extension table.
In an Accounting-Request action, this applies to Acct-Start, Interim, and Stop
requests.
This action modifier generates an Access-Request that comprises two call events:
one database access for authentication and one for authorization.
For getMobileID, if authenticate=n, authorizeLoginName and authorizeDomain are
not supported. The following combinations are not supported:
• authenticate=n validateMobileID=Always/IfAvailable/Never getMobileID=n/y
authorizeLoginName=value authorizeDomain=value
Default: n

getProxyService Syntax: getProxyService=<y|n>


Directs the RADIUS Server to look for an instance of the RADIUS Proxy Service
service profile in the subscriber’s profile set. If it finds the service profile, the
information is used for further policy evaluation.
When the RADIUS Server finds a proxy target or proxy target group in the RADIUS
Proxy Service service profile, it caches the target or target group in the Bridgewater
Proxy-Target attribute, and makes it available to the accessReqPolicy and
acctReqPolicy using the PreAuth and PreAcct tags.
This action modifier can only be used with the PreAuthorize or PreAccounting
actions.
Default: n

Page 276 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

haAlternateList Syntax: haAlternateList=<HA_IPADDRESS_1,HA_IPADDRESS_2,...> or


haAlternateList=<HA_group_name>
The list of HAs or the HA group name to use for round-robin allocation if a PDSN
failure occurred. The DHARoundRobinWithPrimaryHAandPDSNFailure DHA policy
action verifies that the IP addresses in the list are valid addresses of configured
HAs. If this modifier is not specified in the policy, the HA group defined by the
haGroup modifier is used. Optional.

haGroup Syntax: haGroup=<group name>


The name of the HA group from which the Home Agent is allocated in a dynamic
HA configuration.

hlrAuthorization Syntax: hlrAuthorization=<off|Generic|GPRS>


Configures how to retrieve subscriber profile data from an HLR.
• off: Disables GSM based authorization.
This is the default value for this action modifier when not specified on a
GSMLocalAA policy.
• Generic: Configures GA service authorization.
• GPRS: Configures GPRS service authorization.
– For GPRS authorization, add attributes to the WLAN element in
[Link] to specify which RADIUS attributes the RADIUS server uses
to return the IMSI, MSISDN, APN Network Identifier, and APN Operator
Identifier. For information about configuring [Link], see "Configuring
vendor-specific data ([Link])" on page 189.
Default: off

hotlineSet Syntax: hotlineSet=<string>


A name that matches the value of the hotlineSet element in [Link]. The
presence of hotlineSet allows network entry and mid-session hotlining.
The value of hotlineSet must also be set for the hotlineSet element in
[Link]. If the values do not match hotlining fails.
Applies to the actions CDMA2000LocalAA, CDMA2000LocalAcct, WiMAXLocalAA,
and WiMAXLocalAcct.

HTTPDigest-Policy Syntax: HTTPDigest-Policy=<attribute>


Enables the RADIUS Server to use AKA authentication when an Access-Request
containing Digest attributes for Digest Authentication is received from the HTTP
proxy.
When not explicitly specified on the policy line, RADIUS automatically looks for a
<http-digest-policy> entry in the [Link] file with the policy name set to
“default”.
Applies to LocalAA only.

Service Controller 9.6.1-AAA October 12, 2012 Page 277


Chapter 7 Configuring AAA policies Network Access Guide

idleSessionRestore Syntax:idleSessionRestore=<y|n>
When a session is missing, this modifier enables RMS to recreate the session upon
receiving an Accounting-Start or Accounting-Interim message. RMS recreates the
session by restoring the session pool reservation IDs that it writes to the class
attribute.

ignorePreProcessing Syntax: ignorePreProcessingFailure=<y|n>


Failure Enables the evaluation of other policies when an AssignVar action fails to execute.
If no error occurs, the value of this flag (y|n) is ignored. If an error occurs and
ignorePreProcessingFailure=n, then the request is rejected. If an error occurs and
ignorePreProcessingFailure=y, then if continuePreProcessing=n, evaluate
subsequent non-AssignVar policies, otherwise evaluate subsequent AssignVar
policies.
Default: n

ipAllocPoolName Syntax: ipAllocPoolNameOverride=<IP pool


Override name>|<myVar:variableName>|[PreAuth:]$[<vendor-name>:]<attribute-name>
The name can be: hardcoded, a reference to a myVar variable, or a RADIUS
attribute of type string. Non-RFC attributes require the equipment vendor name to
be specified. Hardcoded names must exist in the proxy configuration at start/HUP
time for RADIUS to load. myVar and RADIUS attribute values are cross-referenced
at runtime. When using a RADIUS attribute, the attribute value must also be
specified in the subscriber’s RADIUS Connection Service.
Only for IPAM deployments with multiple IP address pools assigned to an access
node group.

LDAPPassword Syntax: LDAPPasswordAttribute=<passwordAttribute>


Attribute Replaces the value of the ldap-server user-password in the RADIUS LDAP
configuration file [Link].
The LDAPPasswordAttribute field can have a maximum of 255 characters. If the
LDAPPasswordAttribute is not configured in the policy, the server uses the
user-password value from [Link] by default.

LDAPUserFilter Syntax: LDAPUserFilter=<user filter query>


Replaces the ldap-server user-filter query in the RADIUS LDAP configuration file:
[Link]. For example:
LDAPUserFilter=(&(uid={loginname})(ntlRadiusStatus=Active)
(inetUserStatus=Active))
The LDAPUserFilter field can have a maximum of 255 characters. If the
LDAPUserFilter is not configured in the policy, the server uses the user-filter value
from [Link] by default.

Page 278 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

loginName Syntax: loginName=<loginName>|<myVar:variableName>|$[<vendor-name>:]


<attribute-name>
A value to be used as the login name. The value can be: hard coded, a reference to
a myVar variable, or a RADIUS attribute of type string. Non-RFC attributes require
the equipment vendor name to be specified; for example: CISCO.

loginNameRegex Syntax: loginNameRegexFormat=s<c><reg_expression><c><format expression>


Format where
• <c> is a separator character
• <regular expression> is a POSIX regular expression (see the Unix man page
regex)
• <format expression> is <[<prefix string>]${<pattern index>}[<suffix string>]>...
• <pattern index> specifies the sub-pattern in the regular expression by (), 0 is
the index of the whole match. If any pattern does not have a match, the
${<pattern index>} is replaced by an empty string. Prefix string and suffix string
may contain any ASCII character to appear as output.
This is a regular expression to find the login name in the User-Name attribute. If not
specified, the default behavior is loginname@domain or domain\loginname.
Example: s/([^@]+)(@(.*)){0,1}/${3}-{1}
This expression extracts everything before ‘@’ into pattern 1, extracts the first
string after the ‘@’ into pattern 3 and swaps them, putting them together with ‘-’.
Input: user; Result: -user
Input: user@[Link]; Result: [Link]-user
Input: user@[Link]@[Link]; Result: [Link]-user

message Syntax: message=”<message-text>”


Valid only with the LogMessage policy action.
Required.
A short custom RADSYS log message that is generated when the CSID Mismatch
feature detects an attribute mismatch and is configured to log the error.
Example:
# log failed validation and reject
- - - LogMessage message="CSID length is not 10 or 15 digits long."
priority=error
attrs=ID|555,CSID|$Calling-Station-Id,ESN|$STARENT:3GPP2-ESN,
UID|myVar:uid,SERVICE|PreAuth:$Configuration-Token

Service Controller 9.6.1-AAA October 12, 2012 Page 279


Chapter 7 Configuring AAA policies Network Access Guide

mobileType Syntax: mobileType=SimpleIP | MobileHA | MobileFA | A12


The type of client originating the request. Supported for RADIUS only.
Optional.
The value “A12” is not supported for WiMAX.
Values for CDMA2000LocalAA, CDMA2000ProxyAA, DMULocalAA, and
DMUProxyAA:
• SimpleIP—validate CHAP-Password against the Simple IP CHAP Key. The
DMU procedure is not executed.
• MobileHA—validate the Home Agent. Action supports ‘S’ key download.
• MobileFA—validate the Foreign Agent. Action supports Pre-Shared-Secret
download. When used with the DMULocalAA action, executes the DMU
procedure to distribute MIP Keys and verifies the password against the
MN_AAA Key.
• A12—used with Dynamic Mobile IP Key Update (DMU):
– UPDATE KEYS (1) or KEYS UPDATED (2): accept the A12
Access-Request without password verification.
– KEYS VALID (0): perform a simple CHAP authentication Access-Request.
The DMU procedure is not executed.
By default, no value is specified, in which case two scenarios are possible:
• If the 3GPP1-IP-Tech attribute is present, MN-AAA Extension validation occurs.
• If the 3GPP2-IP-Tech attribute is not present, CHAP key validation occurs.
Values for WiMAXLocalAA:
• SimpleIP—the Service Controller treats a request as an authentication request
for Simple IP service from an ASN Gateway. The Service Controller:
– skips all Home Agent assignment processing and does not return a
WiMAX-HA-IP-MIPv4 address if one is provisioned against a subscriber
– creates a subscriber’s RMS WiMAX session in the RMS cluster associated
to the NAS-IP-Address in the Access Request. If the NAS-IP-Address is
missing, the Service Controller uses the subscriber’s Source IP Address to
determine which RMS cluster to write to.
– does not compute the following keys and does not store the following
values in RMS: MIP-RK, PMIP4-MN-HA, CMIP4-MN-HA, FA-RK,
PMIP4-SPI, CMIP4-SPI, CMIP6-SPI
– does not store an HA-IP-Address in the subscribers’s RMS WiMAX
session.
Note The Service Controller does not startup or HUP if a policy line has
mobileType=SimpleIP and assignVisitedHomeAgent is set to
“ifAvailable” or “ifExclusive”.
• MobileHA—the Service Controller treats a request as an authentication request
for Mobile IP service from a WiMAX Home Agent.

Page 280 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

– The Service Controller processes the request as a request from a WiMAX


Home Agent regardless of whether NAS-Port-Type is present and
regardless of the value of NAS-Port-Type.
– If any attributes that are required for processing Access Requests from a
WiMAX Home Agent are missing, the Service Controller returns an
Access-Reject
• MobileFA—the Service Controller treats a request as an authentication request
for Mobile IP service from an ASN Gateway.
– The Service Controller processes the request as a request from an ASN
Gateway regardless of whether NAS-Port-Type is present and regardless
of the value of NAS-Port-Type.
– If any attributes that are required for processing Access Requests from an
ASN Gateway are missing, the Service Controller returns an
Access-Reject.
If no value is specified for mobileType, the Service Controller uses the following
logic to evaluate requests:
• If NAS-Port-Type is present and set to 27, this indicates a request for Mobile IP
service from an ASN Gateway.
• If NAS-Port-Type is absent, this indicates a request for Mobile IP service from a
WiMAX Home Agent.

mppeEncryptionType Syntax: mppeEncryptionType=<None|40|56|128>


The type of encryption allowed for use with MPPE:
• None—no encryption available
• 40—RC4 encryption using a 40-bit key is allowed
• 56—RC4 encryption using a 56-bit key is allowed
• 128—RC4 encryption using a 128-bit key is allowed

multimode Syntax: multimode=true | false


A multimode subscriber who can access both:
• 3G networks, including CDMA2000-based networks
• 4G networks, including WiMAX-based networks
Default: false

myVar Syntax: myVar=<user-defined-variable-name>:[l|U]<reg exp


result>|$[<vendor-name>:]<attribute-name>|<literal>
Stores the results of the regular expression; the value of a RADIUS attribute; or the
concatenation (denoted by the '||' operator) of regular expressions, RADIUS
attribute values (of type string or integer), and string literals. Vendor refers to the
equipment vendor name (for example CISCO) for non-RFC attributes. At least one
must be defined.
Optionally use case conversion to convert the value to lowercase or uppercase by
inserting “l” (lowercase L) or “U” (uppercase U) after the colon.

Service Controller 9.6.1-AAA October 12, 2012 Page 281


Chapter 7 Configuring AAA policies Network Access Guide

These guidelines apply when defining and using myVar variables:


• The same variable name cannot be used for the same AssignVar action.
• A variable name can be reused in subsequent AssignVar actions.
• myVar variables can be referenced as attributes in other policy conditions.
• myVar variables can be referenced by the authorizeDomain,
authorizeLoginName, and loginName action modifiers.
• Use case conversion (“l” or “U”) with a regular expression result or a RADIUS
string attribute value. If “l” or “U” is used with a string literal it is interpreted as
part of the value and no conversion occurs.
• Use case conversion (”l” or “U”) with concatenation to covert the entire value to
the specified case (as long as the concatenation does not begin with a string
literal).
• When the AssignVar action is used to extract values and store them in myVar
variables, policy conditions support the comparison of one myVar variable to
the value of another myVar variable.
Examples:
myVar=Realm:${1} => assign result of regular expression string 1 to Realm variable
myVar=NAI:$User-Name => assign value of User-Name attribute to NAI variable
myVar=NAI:U$User-Name => assign value of User-Name attribute to NAI variable
and convert it to uppercase
myVar=NAI:$User-Name||@||${1} => assign value of User-Name attribute
concatenated with the string literal '@' and the result of regular expression string 1
myVar:LastTenCSID NotEquals myVar:LastTenMSID=>compare the value of two
myVar variables

optionalService Syntax: optionalService=<service>|<myVar:variableName>


An optional service name; if the service is present and is available, then it is
appended to the list of profiles to be applied. If the service does not exist, then it is
ignored. This modifier may be specified multiple times on a policy line to indicate a
series of optional services to be assigned to a subscriber.
A myVar variable can be referenced as a value.
This action modifier generates an Access-Request that comprises two call events:
one database access for authentication and one for authorization.

PANIEnabled Syntax: PANIEnabled=<false|true|PANIPreferred|PseudoPreferred>


Indicates whether the RADIUS Server uses the subscriber’s pseudo-identity or
PANI (PMIP-Authenticated-Network-Identity) for 3G/4G session continuity.
This modifier is used when the 3G/4G HA sends an Access-Request to RADIUS as
part of the WiMAX MIP procedures.
For an Access-Request from an ASN-GW the PANIEnabled modifier is not used by
the RADIUS Server.

Page 282 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

This modifier provides flexibility to deal with the fact that the User-Name in the 3G/
4G HA Access-Request may contain either the pseudo-identity or PANI depending
on operator deployment and subscriber provisioning.
Values:
• false: the RADIUS Server uses the subscriber’s pseudo identity
• true: the RADIUS Server uses the subscriber’s PANI instead of their
pseudo-identity
When set to “true” the User-Name in the Access-Request must contain the
subscriber’s PANI instead of their pseudo-identity.
• PANIPreferred: the RADIUS Server looks for the PANI first, and if it doesn’t find
it, looks for the subscriber’s pseudo-identity.
• PseudoPreferred: the RADIUS Server looks for the pseudo-identity first, and if it
doesn’t find it, looks for the subscriber’s PANI.
Default=false
Applies to the WiMAXLocalAA action.

PPHotlineSet Syntax: PPHotlineSet=<string>


Used for WiMAX NWG Prepaid deployments.
A name that matches the value of the hotlineSet element in [Link]. The
presence of PPHotlineSet triggers the RADIUS server to match a hotlineReason
(part of the CCA sent by a Billing Server) with a bitpos in [Link] to
retrieve a potential list of attributes to return to the Access Node to redirect the
subscriber.
In [Link] bitpos 16 is reserved for Prepaid.
If the value of PPHotlineSet does not match a hotlineSet in [Link], the
RADIUS server doesn’t not look up subscriber redirect attributes in
[Link].
Supported for RADIUS.
Applies to the action WiMAXLocalAA.

priority Syntax: priority=<log-level>


The log level to set for custom RADSYS logs generated using the LogMessage
policy action.
Optional.
Supports the following priority levels:
• DEBUG
• INFO (default)
• NOTICE
• WARNING
• ERROR
• CRITICAL

Service Controller 9.6.1-AAA October 12, 2012 Page 283


Chapter 7 Configuring AAA policies Network Access Guide

• ALERT
• EMERGENCY
Example:
# log failed validation and reject
- - - LogMessage message="CSID length is not 10 or 15 digits long." priority=error
attrs=ID|555,CSID|$Calling-Station-Id,ESN|$STARENT:3GPP2-ESN,
UID|myVar:uid,SERVICE|PreAuth:$Configuration-Token

proxyAVPs Syntax: proxyAVPs=<y|n>


The action to take with the attributes retrieved by the PreAuthorize action. If
proxyAVPs=y, the attributes retrieved from the service identified in the PreAuthorize
action are inserted into the proxy Access-Request message. If proxyAVPs=n, the
retrieved attributes are only used for policy evaluation and are not inserted in the
proxy Access-Request message.
Valid only for the PreAuthorize action.
Default: n

outageAction Syntax: outageAction=<SendReject/SendAccept>


Accept or reject the request if no proxy targets within the group can be reached.
The valid values for outageAction are SendReject or SendAccept.
SendAccept requires a representative user created in the Service Manager for the
specified domain. For more information about subscribers, see the Service
Provisioning module.
Applies to the CDMA2000LocalAA action and the LocalAA action in a proxy
scenario.

outageDomain Syntax: outageDomain=<domain>


The replacement domain to authorize the subscriber if no proxy target can be
reached.
Required if outageAction=SendAccept.

outageLoginName Syntax: outageLoginName=<login-name>


Used when outageAction=SendAccept. It specifies the replacement login name
used to authorize the subscriber if no proxy target can be reached. Optional.

outageReject Syntax: outageRejectMessage=<message-text>


Message A configurable message sent in an Access-Reject/DEA. The outageRejectMessage
is included in the Access-Reject/DEA when a remote server does not respond.
Optional.

Page 284 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

outageService Syntax: outageService=<service-profile>


Used when outageAction=SendAccept. It specifies the service profile returned if no
proxy target can be reached. Optional.

pdsnList Syntax: pdsnList=<PDSN_IPADDRESS_1,PDSN_IPADDRESS_2,...>


The list of PDSNs that cause round-robin behavior if detected by the HA Monitor as
being down. A PDSN has failed if its status in the pdsnList is either “down” or
“manualDown”. The DHARoundRobinWithPrimaryHAandPDSNFailure DHA policy
action verifies that the IP addresses in the list are valid addresses of configured
PDSNs. Required.

policyFailover Syntax: policyFailoverEnabled=<y|n>


Enabled Try the next matching policy if the policy fails to allocate a Home Agent.
Default: n

primaryHA Syntax: primaryHA=<IP address>


The primary HA can be assigned using the service profile or policy. If the primary
HA is specified in both locations, the policy value overrides the service profile. If the
primary Home Agent is available, the primary Home Agent is allocated; otherwise, it
performs allocation of a Home Agent from the specified group of Home Agents in a
round-robin fashion.

reason Syntax: reason=<reason>


The reason for the SendReject. If a reason is specified, corresponding metrics are
increased. Reasons are: InvalidRequest, BadAuthenticator,
MalformedAccessRequest, UnknownType.

replaceDomain Syntax: replaceDomain=<domain>


A domain to replace the domain in the User-Name attribute. This modifier does not
apply if a domain is not found in the User-Name attribute.

replaceMIN Syntax: replaceMIN=<y|n>


The incoming MIN should be replaced with the MIN provisioned for the subscriber.
MIN is only replaced on accounting start requests when RADIUS is running in SSR
mode. Optional.
This action modifier generates an Access-Request that comprises two call events:
one database access for authentication and one for authorization.
Default: n

replyMessage Syntax: replyMessage=<message-text>


If message text is specified, this text is displayed when an Access-Request is
rejected.
Valid only for the SendReject action.

Service Controller 9.6.1-AAA October 12, 2012 Page 285


Chapter 7 Configuring AAA policies Network Access Guide

returnAVPs Syntax: returnAVPs=<y/n>


The action to take with the attributes retrieved by the PreAuthorize action. If
returnAVPs=y, the attributes retrieved from the service identified in the PreAuthorize
action are inserted into the Access-Accept message. If returnAVPs=n, the retrieved
attributes are only used for policy evaluation and are not inserted in the
Access-Accept message.
Valid only for the PreAuthorize action.
Default: y

rmsLocationUpdate Syntax: rmsLocationUpdate=<y/n>


The value of the incoming WiMAX-BS-ID, which specifies the subscriber’s location,
replaces the WiMAX-BS-ID value if it is different. This session-related information is
stored in RMS.
Example:
- - WiMAXLocalAcct rmsLocationUpdate=Y
Supported in RADIUS and Diameter AAA deployments.
Note RADIUS/Diameter must be set to run in SSR mode.
Valid for the WiMAXLocalAcct action only.
Default: n

runPlugIn Syntax: runPlugIn=<PlugInName>


A Plugin module used for inspecting and/or modifying packet attributes during:
• Pre-authorization, post-authorization, pre-authentication, and
post-authentication for an access-request action
• Pre-accounting and post-accounting for an accounting-request action
This feature requires an authentication signature. Contact Bridgewater Customer
Support to activate this feature.

service Syntax: service=<service>|<myVar:variableName>


Replaces the connection service for the subscriber. The service name must match
the service profile name in the Service Manager. If an LDAP database is used, the
RADIUS Server retrieves service profiles from the memory map file that was
specified on installation.
If the service profile is in the subscriber’s profile set, the RADIUS Server adds the
attributes from the service profile to the outgoing Access-Accept. This modifier may
be specified multiple times on a policy line to indicate a series of backup services to
be assigned to a subscriber.
A myVar variable can be referenced as a value.

Page 286 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

This action modifier generates an Access-Request that comprises two call events:
one database access for authentication and one for authorization. For the
PreAuthorize action, this action-modifier does not generate an Access-Request, but
is used to specify the RADIUS connection service profile from which to retrieve
preauthorization values.
Note For PreAuthorize actions, when a service modifier is not specified, no
service profile retrieval is performed.

serviceAVP Syntax: serviceAVP=[<vendor-name>:]<attribute-name>=<attribute-value>


An attribute name and value returned to the client in an Access-Accept. Multiple
serviceAVPs can be specified per policy. The equipment vendor name (for example,
CISCO) must be specified for non-RFC attributes.
When specified with authorizeProxyLevel action modifier, the same precedence
rules apply as with attributes contained in a subscriber's local Connection Service
Profile.

serviceRegexFormat Syntax: serviceRegexFormat=s<c><regular expression><c><format expression>


where
• <c> is a separator character
• <regular expression> is a POSIX regular expression (see the Unix man page
regex)
• <format expression> is <[<prefix string>]${<pattern index>}[<suffix string>]>...
• <pattern index> specifies the sub-pattern in the regular expression by (), 0 is
the index of the whole match. If any pattern does not have a match, the
${<pattern index>} is replaced by an empty string. Prefix string and suffix string
may contain any ASCII character to appear as output.
This is a regular expression to find a requested service name in the User-Name
attribute. The default behavior is a %service suffix: joe@[Link]%L2TP.
Example: s/([^@]+)(@(.*)){0,1}/${3}-{1}
This expression extracts everything before ‘@’ into pattern 1, extracts the first
string after the ‘@’ into pattern 3 and swaps them, putting them together with ‘-’.
Input: user; Result: -user
Input: user@[Link];Result: [Link]-user
Input: user@[Link]@[Link]; Result: [Link]-user

suppress-MS-MPPE Syntax: suppress-MS-MPPE=<y|n>


When set to y, the RADIUS Server does not include MS-MPPE attributes in
responses to Access-Request messages.
This modifier is only supported for RADIUS.
This modifier is only supported for the WiMAXLocalAA action.
Default: n

Service Controller 9.6.1-AAA October 12, 2012 Page 287


Chapter 7 Configuring AAA policies Network Access Guide

switchLocalAuthorize Syntax: switchLocalAuthorizeUser=<y|n>


User If no value is specified for the defaultProxy attribute, the switchLocalAuthorizeUser
value defaults to y.
This switches to the subscriber specified by the authorizeDomain and
authorizeLoginName attributes for local subscriber authorization.

target Syntax: target=<proxy-target>|<myVar:variableName>|


[PreAuth:]$[<vendor-name>:]<attribute-name>
With accessReqPolicy and acctReqPolicy, this modifier specifies the name of a
single proxy target server or a proxy target server group to which the
Access-Request or Accounting-Request message is forwarded.
The name can be: hardcoded, a reference to a myVar variable, or a RADIUS
attribute of type string. Non-RFC attributes require the equipment vendor name to
be specified. Hardcoded names must exist in the proxy configuration at start/HUP
time for RADIUS to load. myVar and RADIUS attribute values are cross-referenced
at runtime.
If the target is not defined in the proxy configuration, the request is rejected.
With daeReqPolicy this modifier specifies the name of the proxy target to send CoA
and DM messages to.
The proxy target or proxy target group can be defined in the [Link] file or in the
Service Manager (with the ProxyDatabase Configuration optionality package).
The ‘target’ action modifier supports the following for all associated access and
accounting actions:
• myVar values
accessReqPolicy example:
- - - AssignVar myVar=Target:Server||$Called-Station-Id
- - - ProxyAA target=myVar:Target
acctReqPolicy example:
- - - AssignVar myVar=Target:Server||$Called-Station-Id
- - - ProxyAcct target=myVar:Target
• string RADIUS attribute values
accessReqPolicy example:
- - - ProxyAA target=$Called-Station-Id
authorizeProxyLevel=$Filter-Id
• string RADIUS VSA values
acctReqPolicy example:
- - - ProxyAcct target=$STARENT:3GPP2-ESN
• attributes received from a PreAuthorize action, and referenced using the string
‘PreAuth’
Example:

Page 288 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

- - - PreAuthorize getProxyService=y
- - - ProxyAA target=PreAuth:$BRIDGEWATER:Proxy-Target \
authorizeProxyLevel=PreAuth:$BRIDGEWATER:Authorize-Proxy-
Level
• attributes received from a PreAccounting action, and referenced using the
string ‘PreAcct’
Example:
- - - ProxyAcct target=PreAcct:$BRIDGEWATER:Proxy-Target
Required.

trunkGroupAVP Syntax: trunkGroupAVP=[<vendor-name>:]<attribute-name>


An RFC attribute or vendor-specific attribute that the RADIUS Server uses to
resolve the Trunk group for access control. The RADIUS Server identifies the
correct Trunk group by matching the value of the AVP defined in the
trunkGroupAVP to a Directory Number (DN) for a Trunk group or to a DN in the
range of DNs defined for the Trunk group. Any AVP, including vendor-specific AVPs,
can be used to resolve the Trunk group provided that the payload of the AVP is a
string that contains an integer.
If the AVP defined in the trunkGroupAVP modifier is not present in an
Access-Request or if the AVP is not a string that contains an integer, the RADIUS
Server does not perform Trunk group access control.
The equipment vendor name (e.g CISCO) must be specified for Non-RFC
attributes.
Default: Called-Station-Id

unknownUserSecret Syntax: unknownUserSecret=<shared secret>


Used for the second phase of EAP-TTLS.
A shared secret to use as the password for MSCHAPv2 authentication. The
specified secret is used for the mutual authentication for subscribers who are not
provisioned in the Profile Database.
Note The specified secret is associated with a username provisioned for
unknown users. The username for unknown users is specified in the
authorize-user-name attribute in [Link].
The specified secret must match the password provisioned in Service
Manager for an unknown subscriber.
This modifier must be used with hotlineSet. If unknownUserSecret is used without
hotlineSet, no hotlining occurs and the subscriber gains unauthorized access to the
network.
For use with Diameter EAP-TTLS only. Use with TLSLocalAA action.

Service Controller 9.6.1-AAA October 12, 2012 Page 289


Chapter 7 Configuring AAA policies Network Access Guide

useAuthorize Syntax: useAuthorizeBillingId=<y|n>


BillingId Use the billing ID of the local subscriber account used for authorization. Used only
when the authorizeLoginName and authorizeDomain modifiers are set.
Default: n (local authentication), y (proxy authentication)

useMobileKey Syntax: useMobileKey=<Y|y|N|n>


Enables or disables WiMAX key management.
This modifier is for Diameter only.
useMobileKey must be provisioned in both accessReqPolicy and acctReqPolicy
files.
When using useMobileKey in the accessReqPolicy and acctReqPolicy files, also
set Force-WiMAX-Session to “y” in the accessReqPolicy file.
Default: y
When useMobileKey=y or is not included in the policy, the Service Controller uses
default logic to process the DER or ACR coming from the ASN-GW
When useMobileKey=n for WiMAXLocalAA, the Service Controller:
• does not assign a Home Agent.
• HA-IP-Address is in the WiMAX session, but has an empty value of [Link]
• does not perform computations for the MIP-RK, PMIP4-MN-HA,
CMIP4-MN-HA, BEK, FA-RK, PMIP4-SPI, CMIP4-SPI, CMIP6-SPI
• these attributes are in the WiMAX session, but have an empty value: MIP-RK,
PMIP4-MN-HA, CMIP4-MN-HA, BEK, FA-RK, PMIP4-SPI, CMIP4-SPI,
CMIP6-SPI
• deletes these AVPs from the DEA message: WiMAX-Capability,
WiMAX-HA-IP-MIPv4, WiMAX-MN-hHA-MIP4-Key,
WiMAX-MN-hHA-MIP4-SPI, WiMAX-FA-RK, WiMAX-hHA-RK-Key,
WiMAX-hHA-RK-SPI
• uses the Session-ID AVP instead of the State AVP, as the key to cache the EAP
state
Note When the Service Controller uses Session-ID as the key to cache the EAP
state, the log message for an expired EAP session is one of the following:
– AAASYS 3053: Unexpected EAP type encountered: internal error.
– AAAOP 106: DER for %s from %s[%s] dropped: An EAP error has
occurred.
– AAASYS 3019: Failed to process EAP request for subscriber %s from %s:
unexpected EAP type.
When useMobileKey=n for WiMAXLocalAcct, and the ACR message does not
contain the WiMAX-HA-IP-MIPv4 attribute, the Service Controller:
• does not drop the ACR

Page 290 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

• creates the subscriber RMS SSR (RADIUS) session in the RMS cluster
associated with the NAS-IP-Address in the request or with the source IP
Address if the NAS-IP-Address is absent
When useMobileKey=n for WiMAXLocalAcct and the ACR message does not
contain the Acct-Multi-Session-ID attribute, the Service Controller:
• does not drop the ACR
• uses the pseudo-id from the User-Name attribute in the ACR to lookup RMS
sessions

useTagIndex Syntax: useTagIndex=<y|n>


Specifies the tunnel ID.
If useTagIndex is set to "n" the tunnel ID is 0. If useTagIndex is set to 'y" the tunnel
ID is based on the value provisioned in the Service Manager.
This action modifier does not apply if the dynamic LNS assignment feature is used.

validateEquipID Syntax: validateEquipID= Always | IfAvailable | Never


Enables RADIUS to verify the 3GPP2-AT-Hardware-Identifier, 3GPP2-MEID, or
3GPP2-ESN Equipment Identifier attributes using one of the following options:
• Always - RADIUS performs hardware ID verification for every Access-Request.
If the Equipment Identifier is missing from either the Access-Request or the
user’s service profile(s) (Equipment service profile and/or RADIUS connection
service profile), RADIUS returns an Access-Reject and logs an error.
If an Equipment Identifier is present in the Access-Request and the user’s
service profile, the values must match, otherwise RADIUS returns an
Access-Reject.
• IfAvailable - RADIUS performs hardware ID verification only if an Equipment
Identifier is present in the Access-Request and provisioned in the user's service
profile(s) (Equipment service profile and/or RADIUS connection service profile).
If no Equipment Identifiers are found in the Access-Request message or the
user’s service profile(s), RADIUS proceeds with authentication.
If an Equipment Identifier is present in the Access-Request and the user’s
service profile, the values must match, otherwise RADIUS returns an
Access-Reject.
• Never - RADIUS always skips hardware ID verification.
Note A user can have multiple connection service profiles with an Equipment
Identifier provisioned. The Equipment Identifier provisioned in a user’s
Equipment service profile takes precedence over any Equipment Identifiers
provisioned in a user’s RADIUS connection service profile.
Optional.
Default: Never

Service Controller 9.6.1-AAA October 12, 2012 Page 291


Chapter 7 Configuring AAA policies Network Access Guide

validateMobileID Syntax: validateMobileID= Always | IfAvailable | Never


Validate the MSID (for example MIN, IMSI, ESN or MEID) against the known MSID
of the subscriber, provisioned in the GUI User Profile Set.
Set to Always if the MSID is to always be validated.
Set to IfAvailable if the MSID is only to be checked if the subscriber has been
provisioned as a mobile subscriber and the Calling-Station-Id attribute is available.
Set to Never if the MSID is not validated in any case.
Optional.
This action modifier generates an Access-Request that comprises two call events:
one database access for authentication and one for authorization.
Default: IfAvailable

writeAccounting Syntax: writeAccounting=<y|n>


The RADIUS Server writes the accounting record to the database. This has no
effect on Livingston accounting.
This modifier can be used for all actions.
If writeAccounting=n, the radiusAccServTotalNoRecords and the
radiusAccServNoRecords SNMP metrics are incremented.
Default: y

writeCertFields Syntax: writeCertFields=<y | n>


When set to y, the Service Controller writes the value of the WiMAX session
attributes X509_CN and X509_O in accounting records. The Service Controller
writes the X509_CN and X509_O values as the X509-Common-Name and
X509-Organization VSAs in the radiusAttr field for RADIUS and in the aaaAttr field
for Diameter.
cacheCertFields must be set to y for writeCertFields to work.
Default: n

Page 292 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

rejectPolicy
The rejectPolicy modifies Access-Reject messages by inserting multiple service
AVPs into the Access-Reject message.
The PreAuthorize and Proxy policy actions support the rejectPolicy modifier to
specify reply message values when an Access-Reject is returned. For more
information, see "rejectPolicy and outageRejectMessage modifiers" on page 300.
The rejectPolicy file contains an ordered list of rules that are applied to
Access-Reject messages. Each rule consists of the following:
• Condition expression
• Action expression

Condition expression
The condition expression format for the rejectPolicy is:
<attribute> <operator> <value>
where
<attribute> is one of the following:
'Reject-Reason'
'-’
<operator> is one of the following:
Equals
'-'
<value> is one of the reasons specified in Table 106.

Table 106: Valid condition expression values for rejectPolicy

Condition value Description

InvalidUser An invalid subscriber was specified in the request.

Suspended The account status is ‘suspended’ or ‘pending’.

MissingPassword The request does not contain a password attribute.

NoService The account is not provisioned for the requested


service

IPAddrAllocFailure Unable to allocate an IP address.

NASClientIDFailure Unable to identify the NAS client.

TimeAccessDenial Access denied at the current time.

LocationAccessDenial Access denied from current location.

AccessTypeDenial Access denied, access method is not allowed.

Service Controller 9.6.1-AAA October 12, 2012 Page 293


Chapter 7 Configuring AAA policies Network Access Guide

Table 106: Valid condition expression values for rejectPolicy (continued)

Condition value Description

RMSSessionLimit Session limit in RMS has been reached.

AmbiguousUser Ambiguous user. A domain or password is required.

InvalidKeyIndex Invalid DMU key index.

InvalidAuthReq Invalid authentication request.

HAUnavailable No home agent is available.

NoAuthMechSupported An authentication mechanism could not be


determined.

InvalidMobileID Invalid MSID.

UnavailableResources Unable to complete the request due to a lack of


resources.

LockedUser The user has been locked by the user lockout feature.

NoPrepaidSupport The HA is not prepaid capable.

NoRemotePrepaidResponse The remote prepaid server did not respond in time.

MIPNotAvail MIP functionality is not available.

InvalidEquipmentID Invalid equipment identifier.

NoRemoteEAPResponse Remote server did not respond in time for EAP phase
2 authentication.

InvalidDMUState The current EAP method is provisioned to use the


DMU key as the password and the key is not in a valid
state.

MissingWiMAXSession WiMAX session not found.

InvalidAPN Unauthorized APN access attempt.

InvalidPassword Invalid password.

Proxy Timeout Proxy target is unreachable.

Use the condition expression '- - -' to specify that there is no condition for the action
that follows. Use the condition expression '-' to specify that the condition always
evaluates to true.

Page 294 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Action expression
The action expression format for the rejectPolicy is:
<action-name> <action-modifiers...>
where
<action-name> is: SendReject
The SendReject action rejects the authentication request with a subscriber
message. Modify the SendReject action using the following optional action
modifiers:
• replyMessage=<Reject Message>
• serviceAVP=[vendorName:]<AVPname>=<AVPvalue>

replyMessage
The replyMessage modifier specifies that a text message, which can be one line of
ASCII text, is sent in the Access-Reject. If the line contains white space, the
message must be enclosed by single or double quotes.
Example:
Reject-Reason Equals InvalidUser SendReject replyMessage=16380

serviceAVP
Use the serviceAVP modifier to specify multiple RFC AVPs or vendor VSAs to
return in the Access-Reject message. When returning a non-RFC VSA, specify the
name of the equipment vendor, such as STARENT.
Optional.
Example:
Reject-Reason Equals InvalidPassword SendReject replyMessage=16381
serviceAVP=STARENT:Password-Retry=5

To enable the rejectPolicy


Note Make a backup of the rejectPolicy file before modifying it.
1 Change to the /opt/aaasc/config/radius directory.
2 Open the accessReqPolicy file and specify the use of the rejectPolicy.
Example:
- - - LocalAA rejectPolicy=Y
3 Save the accessReqPolicy file.

Service Controller 9.6.1-AAA October 12, 2012 Page 295


Chapter 7 Configuring AAA policies Network Access Guide

4 In the same directory, open the rejectPolicy file and configure the policy
according to the appropriate access reject reasons.
Optionally, return one or more service AVPs with the Access-Reject message
by using the serviceAVP modifier.
Example:
Reject-Reason Equals InvalidUser SendReject replyMessage=16380
Reject-Reason Equals InvalidPassword SendReject replyMessage=16381
serviceAVP=STARENT:Password-Retry=5
5 Save the file and exit.
6 Send a HUP signal to the radiusd process for the changes to take effect.
Example:
pkill -HUP radiusd

Supported EAP methods


The following EAP methods support the rejectPolicy:
• EAP-AKA
• PEAP/MSCHAPv2
• EAP-SIM
• EAP-TLS
• EAP-TTLS
• EAP-MD5

Page 296 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Configuring PreAuthorize using Access Control Limits (ACL) for


proxy
This topics in this section are:
• Overview
• acService modifier
• service modifier
• RMS sessions
• Examples of PreAuthorize and Proxy actions using ACLs
• rejectPolicy and outageRejectMessage modifiers

Overview
PreAuthorize policy actions enable operators to perform Access Control Limit
checks, such as Port Quota Control checks, prior to performing a proxy action. If the
ACL check passes, the Service Controller (SC) can proxy the request to a customer
AA server. If the ACL check fails, the Service Controller returns an Access-Reject
with an optional, and configurable Reply-Message.
To enable the ACL evaluations, configure an Access Control service (see the
chapter “Managing Access Controls” in the Service Manager: Services Provisioning
Guide for AAA) and specify it in the PreAuthorize policy action using the “acService”
modifier. Optionally, use the “service” modifier to authorize the subscriber against a
specified service.
Note The RADIUS Server issues an error log at startup or HUP if the service
specified by either the “acService” or the “service” modifier is not
configured in the database.
Note Only Access Control Limits (ACLs) assigned to the PreAuthorize action are
performed. ACLs specified in subsequent policy lines are ignored.

acService modifier
When using the PreAuthorize policy action to perform ACL checks, the acService
modifier specifies the name of the Access Control service profile that is assigned to
the subscriber by the PreAuthorize policy. If the acService is not configured for the
PreAuthorize policy action, the system does not perform PQC validation. If the
acService modifier is configured but the PQC check fails, the Service Controller
returns an Access-Reject.

Service Controller 9.6.1-AAA October 12, 2012 Page 297


Chapter 7 Configuring AAA policies Network Access Guide

continueNotFound Determines whether or not policy evaluation should continue.


Regardless of the value of the continueNotFound modifier, if the acService modifier
is configured:
• but it is not found
• but ACL fails
then, the Service Controller ends policy file evaluation, writes an appropriate
RADOP log, and sends an Access-Reject message.

service modifier
Authorizes a RADIUS Connection Service against the PreAuthorize action. In the
following example, the PreAuthorize action triggers the Port Quota Control check. If
it passes, the Service Controller attempts to authorize based on the User-Name
and the S2 RADIUS Connection Service.
Optional.
Example:
Service-Type Equals 10 PreAuthorize acService=PortQuotaCheck service=S2
For more information and examples, see the section "Examples of PreAuthorize
and Proxy actions using ACLs" on page 298.

RMS sessions
When a ACL check passes during a PreAuthorize policy action, RMS creates a
session. If the final policy action returns an Access-Reject, RMS deletes this
session.

Examples of PreAuthorize and Proxy actions using ACLs


The following PreAuthorize policy examples show how to incorporate ACL checks
with other actions in a proxy environment.

PreAuth using ACL This policy example incorporates the PortQuotaControl check, ProxyAA,
and proxy rejectPolicy, and SendReject with a reply message.
Example:
Service-Type Equals 10 PreAuthorize acService=PortQuotaCheck
loginName=$Called-Station-Id rejectPolicy=y
- - - ProxyAA outageAction=SendReject rejectPolicy=y =T1
- - - SendReject Reject-Reason Equals ProxyTimeout replyMessage="Remote
target is unavailable."

Page 298 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

In this example, the “acService” action modifier requests a Port Quota Check to see
if the customer ISP’s port quota has been exhausted. If the PQC check passes, the
Service Controller proxies the request to the specified target. If the T1 target is
unavailable, the Service Controller is configured to send an Access-Reject with the
reply message: “Remote target is unavailable”.

Evaluating the ACL The PreAuthorization policy can be configured in several ways depending on the
and proxying the subscriber’s need. Consider the following examples:
request • Specifying a backup service
• PreAuthorization service unspecified
• ACL not configured

Specifying a backup service


In this example, two service modifiers are configured against the Preauthorize
action.
Example:
Service-Type Equals 10 PreAuthorize acService=PortQuotaCheck service=S2
service=S1
- - - ProxyAA target=T1
If the S2 service profile is not found, the Service Controller searches for the S1
service. Since continueNotFound defaults to “n”, if the S1 service is not found, the
Service Controller returns an Access-Reject.

PreAuthorization service unspecified


In this example, Preauthorize does not specify a service. Since the PreAuthorize
action is forbidden to default to the DEFAULT RADIUS Connection Service,
PreAuthorize does not perform service authorization. The final policy action
performs authorization.
Example:
Service-Type Equals 10 PreAuthorize acService=PortQuotaCheck
loginName=$Called-Station-Id rejectPolicy=y
PreAuth:$BRIDGEWATER:Proxy-Target Appears Once ProxyAA
loginName=$Called-Station-Id target=T1

Service Controller 9.6.1-AAA October 12, 2012 Page 299


Chapter 7 Configuring AAA policies Network Access Guide

ACL not configured


In this example, an acService modifier is not configured against a PreAuthorize
action, which means that ACL validation is not performed. Though the PreAuthorize
policy does not perform ACL validation, the LocalAA policy does perform ACL
validation as part of the authorization.
Example:
Service-Type Equals 10 PreAuthorize loginName=$Called-Station-Id
rejectPolicy=y service=R1
- - - LocalAA

rejectPolicy and outageRejectMessage modifiers


The PreAuthorize and Proxy policy actions support the rejectPolicy modifier and
enable administrators to specify reply message values when the Service Controller
returns an Access-Reject message.
Example:
Reject-Reason Equals InvalidUser SendReject replyMessage="Representative
User not found in the database"
Reject-Reason Equals RMSSessionLimit SendReject replyMessage="Session
Limits have been reached, sorry!"
- - - SendReject replyMessage="Generic reject reply message"
If ProxyAA is configured to send a reject message when a proxy target cannot be
reached, and ProxyAA carries a value for the outageRejectMessage, the value of
outageRejectMessage is returned. Even if the rejectPolicy modifier is set to ‘Y’, the
value of outageRejectMessage still overrides any value of Reply-Message set in
the Reject Policy file.

Optimizing the policy file


For optimum performance, apply the following guidelines when configuring policy
files:
• list rules in order of frequency with the most frequently requested conditions are
listed first
• place a “catch-all” rule at the end of the list so that no request is discarded

Preventing messages from being discarded


To make sure that no messages are discarded, add a “catch-all” rule to the end of a
policy file. For example, add:
• “---LocalAA“ to the accessReqPolicy file to perform local authentication
• “---SendReject“ to the accessReqPolicy file to reject requests
• “---LocalAcct” to the acctReqPolicy file to perform local accounting.

Page 300 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

• “---DHAValidateOnly“ to the dynamicHAPolicy file to perform local


authentication
• “---TLSLocalAA“ to the TLSPolicy file to perform local authentication
Note Specify the text of the message that is sent when a request is rejected.

Example 1 If the RADIUS Server primarily handles proxy requests, but also handles local
authentication requests, list all the proxy rules first and place a “catch-all” local
authentication rule at the end of the accessReqPolicy file. For example:
User-Name EndsWithCI @[Link] ProxyAA
target=proxytargetgroup
User-Name EndsWithCI @[Link] ProxyAA target=proxy2
...
- - - LocalAA

Example 2 If the RADIUS Server primarily handles local authentication requests, but also
handles proxy requests, list all the local authentication rules first and place a
“catch-all” proxy rule at the end of the accessReqPolicy file. For example:
User-Name EndsWithCI @[Link] LocalAA
User-Name EndsWithCI @[Link] LocalAA
...
- - - ProxyAA target=proxy-target
The RADIUS Packet Attribute Modifier Plugin feature provides a framework for
supporting VoIP and Prepaid applications. This feature enables RADIUS Server
policies to arbitrarily change the content of attributes under specified conditions. For
more details, contact Bridgewater Customer Support.

Testing policy rules


To verify which rule is triggered, use the RADIUS Policy Engine Test utility (radpet)
to specify a test packet to be run through the appropriate policy engine.
1 Login as the aaasc user.
2 Run radpet:
/opt/aaasc/radius/radpet -i client-IP -t packet-type -C
[config_dir] -c dal_conf -d RADIUS_dir attr=val
where
client-IP is the IP address of the NAS or RADIUS Server
packet-type is either auth (Access-Request) or acct (Accounting-Request)
config_dir is the base configuration directory (default is /opt/aaasc/config)
dal_conf is the database configuration file (default /opt/aaasc/config/
[Link])
RADIUS_dir is the RADIUS configuration directory (default /opt/aaasc/
config/radius)
attr=val is one or more attribute-value pairs

Service Controller 9.6.1-AAA October 12, 2012 Page 301


Chapter 7 Configuring AAA policies Network Access Guide

For example:
/opt/aaasc/radius/radpet -i [Link] -t auth -c
/opt/aaasc/conf/[Link] -d /opt/aaasc/config/radius
User-Name=username@[Link]
Note The radpet utility cannot decode the PreAuth: tag references extracted from
the PreAuthorize action and always evaluates to FALSE.
The radpet utility cannot decode HLRAuth: tag references and always
evaluates to FALSE.

Radpet in a proxy deployment


Customers who deploy the Proxy Database Configuration optionality package can
use radpet to test policy rules in a proxy environment. Use the following information
to determine how radpet reports specific elements in a proxy environment.
When processing a proxy authentication, authorization, or accounting policy with:
• a target action modifier with the value of a RADIUS attribute, radpet reports the
value of the target action modifier as the value of the RADIUS attribute
• a target action modifier with the value of a RADIUS VSA, radpet reports the
value of the target action modifier as the value of the RADIUS VSA
• an authorizeProxyLevel action modifier with the value of a RADIUS attribute,
radpet reports the value of the authorizeProxyLevel action modifier as the value
of the RADIUS attribute
• an authorizeProxyLevel action modifier with the value of a RADIUS VSA,
radpet reports the value of the authorizeProxyLevel action modifier as the value
of the RADIUS VSA
• an authorizeProxyLevel action modifier assigned with the value of a myVar
variable, radpet reports the value of the authorizeProxyLevel action modifier as
the resolved value of the myVar variable.
Radpet supports the following:
• PreAccounting policy action as part of its output, and radpet indicates whether
the policy action criteria matches (based on the command line options)
• Pre-Acct-User condition as part of its output, and radpet indicates whether the
condition has been satisfied (based on evaluation of a PreAccounting action)
• Pre-Acct-Service condition as part of its output, and radpet indicates whether
the condition has been satisfied (based on evaluation of a PreAccounting
action)

Page 302 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Example policy configurations


This section provides examples for the following common policy rules:
• Device reboot notification
• Call check
• Proxy by domain
• Proxy by called number
• Service authorization for proxy
• Default proxy
• Compulsory service by called number
• Policies based on day and time
• Group domains for roaming subscribers
• Discarding service requests
• Default domains
• Using regular expressions
• Reference another policy file for roaming subscribers
• Policy for replacing loginName with the Calling-Station-Id
• AssignVar: policy file interaction
• EAP local authentication
• Microsoft CHAP (MSCHAP)
• Microsoft Point-To-Point Encryption (MPPE)
• Compare User-Name to Called-Number
• Preauthorization
• HLR authorization
• Conditional dynamic proxy target assignment
• Using subtype attributes in Access-Requests to control network access

Device reboot notification


In the AcctReqPolicy file, define policy rules to tell the RADIUS Server when to
interpret Accounting-Request messages as indicating a device reboot. In the case
where more than one attribute is required to indicate a reboot event, use embedded
policy files. For example, if Acct-Status-Type must have a value of Acctg-Off and
Acct-Terminate-Cause must have a value of NAS-Reboot, define this rule:
Acct-Status-Type Equals Acctg-Off PolicyRun
evaluatePolicy=rebootPolicy
Then define another policy file, rebootPolicy, to specify what action the RADIUS
Server takes when it receives these Accounting-Off messages:
Acct-Terminate-Cause Equals NAS-Reboot DeviceReboot

Service Controller 9.6.1-AAA October 12, 2012 Page 303


Chapter 7 Configuring AAA policies Network Access Guide

Also add an action-modifier to proxy the Accounting-Request message to a remote


server, for example, if the NAS is owned by a retail ISP or corporate customer:
Acct-Terminate-Cause Equals NAS-Reboot DeviceReboot
target=Acct1

Call check
A call check policy rule is used to check access controls to preauthenticate a
subscriber before the call is actually answered. For more details about call
checking, see "Preauthentication call checking" on page 7.
Define this policy rule:
User-Name Equals $Called-Station-Id CallCheckAA
authorizeDomain=[Link] authorizeLoginName=usera
authenticate=N
This policy rule preauthenticates subscribers within the [Link] domain,
checking access controls to verify that the session is allowed before the subscriber
is authenticated.
Define the access controls for each limit at the following levels:
• DefaultMaxSession—defined in the default Access Control level
• MaxSessionsPerDomainGroup—defined in the default Access Control or
Domain Group levels
• MaxSessionsPerDomain—defined in the default Access Control, Domain
Group or Domain levels
• MaxSessionsPerOrgGroup—defined in the default Access Control or the
Organization Group levels
• MaxSessionsPerOrg—defined in the default Access Control, Organization
Group or Organization levels
• MaxSessionsPerUser—defined in the default Access Control, Domain Group,
Domain, Organization Group, Organization, User Group or User levels.
Note To use the call check functionality, create a preauthentication connection
profile set. This profile set must be added to the User profile set of the
representative user.

Proxy by domain
Proxy access and accounting requests based on the subscriber’s domain. Define
this policy rule:
User-Name EndsWithCI @[Link] ProxyAA
target=proxytargetgroupA outageAction=SendReject
outageRejectMessage=”Please try dialing 800-675-8875”
In this example, the request is proxied to one of the RADIUS Servers listed in the
[Link] file for proxytargetgroupA. If none of the target servers in this group are
available, the Access-Request is rejected and the specified message is returned.

Page 304 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Proxy by called number


Proxy access and accounting requests based on the number the subscriber dials to
access the ISP. Define this policy rule:
Called-Station-Id Equals 8006463456 ProxyAA
target=proxytargetgroupB outageAction=SendAccept
outageDomain=[Link] outageLoginName=proxyUser
outageService=outageServiceProfile
In this example, the request is proxied to one of the RADIUS Servers listed in the
[Link] file for proxytargetgroupB, based on the called number. If none of the
target servers in this group are available, the subscriber is authorized locally using
the domain, login name and service profile specified in the policy rule.

Service authorization for proxy


When Access-Requests are proxied to a remote RADIUS Server for authentication,
define to what extent service authorization is performed locally by the RADIUS
Server.
Service authorization includes:
• checking access controls
• returning connection service attributes to the NAS
For proxying, control how the RADIUS Server handles the reply messages from the
remote RADIUS Servers.
By default, the RADIUS Server forwards all attributes returned from the remote
RADIUS Server to the NAS without change. This implies trust in the remote
RADIUS Server to configure the NAS correctly.
Create a subscriber account in the Service Manager to represent the proxy. Use the
authorizeDomain and authorizeLoginName action-modifiers in the policy rule to
identify this subscriber account regardless if the subscriber is defined locally. Use
authorizeDefaultDomain and authorizeLoginName to identify the subscriber when
the subscriber is not defined locally.
Use the authorizeProxyLevel to determine how much service authorization is done
locally. Provide complete local authorization, which means that any service
attributes returned from the remote RADIUS Server are ignored, and the attributes
defined locally for the proxy subscriber account are sent instead. Also merge
attributes from the remote and local services.
Define an access control service profile for the proxy account; for example, to
restrict the number of simultaneous sessions allowed for an ISP or to restrict
access based on day and time. The following is an example policy rule to provide
complete local service authorization for a proxied Access-Request:
User-Name EndsWithCI @[Link] ProxyAA
target=ispconnect authorizeDomain=[Link]
authorizeLoginName=proxyuser authorizeProxyLevel=L

Service Controller 9.6.1-AAA October 12, 2012 Page 305


Chapter 7 Configuring AAA policies Network Access Guide

Default proxy
Define a default proxy so that when subscribers cannot be authenticated locally, the
Access-Request is proxied to a default remote server.
Include the defaultProxy=<target> action modifier in the policy rule. Then define
one or more RADIUS Servers for the target in the proxies file.
When the subscriber is authenticated by default proxy, perform local authorization
with a proxy subscriber account, as explained in "Service authorization for proxy"
on page 305. By default, the billing ID of this proxy subscriber account is used;
however, specify that this billing ID should be ignored with the
useAuthorizeBillingId=n parameter.
User-Name EndsWithCI @[Link] LocalAA
defaultProxy=ispconnect authorizeDomain=[Link]
authorizeLoginName=proxyuser useAuthorizeBillingId=n

Compulsory service by called number


Deliver a tunnel service automatically based on the number the subscriber dials to
access the ISP.
Define the following policy rule:
Called-Station-Id Equals 6045554341 LocalAA authenticate=n
authorizeDomain=[Link] authorizeLoginName=creativeuser
service=L2TP
In this case, the subscriber is not authenticated. A subscriber account
“creativeuser” is in the “[Link]” domain in the Service Manager. The L2TP
service profile is retrieved from this subscriber account and returned to the NAS.
The NAS and the tunnel endpoint are responsible for setting up the tunnel and
authenticating the subscriber.

Policies based on day and time


Define policies to control RADIUS Server behavior depending on day and time.
For example, define policy rules to deliver a different connection service for
corporate subscribers depending on the day and time:
Time-Of-Day Equals Mon-Fri:0900-1700 LocalAA service=L2TP
Time-Of-Day Equals Sat,Sun LocalAA service=PPP
During business hours, deliver a secure L2TP tunnel connection to the corporate
intranet. On weekends, provide a standard PPP dial-up connection to the Internet.
Note 1 Do not use time-of-day policy rules to change a representative user with
simultaneous session limits. Session tracking is tied to the representative
user, so enforcement of limits would not take into account sessions active
for the original subscriber.

Page 306 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Note 2 Do not define time-of-day policy rules to control subscribers’ network


access based on day and time. Define the appropriate access controls for
the subscriber. For more information, see the Service Manager: Services
Provisioning Guide for AAA or Online Help.

Group domains for roaming subscribers


Define dummy domains for subscribers to use when roaming. When roaming
subscribers log in to a remote network, they use this group domain, regardless of
their actual domain name.
This simplifies provisioning for the remote ISPs, who define one proxy entry for this
group domain.
For example, define a domain, such as “[Link]”. The remote ISP proxies
all requests for this domain to the RADIUS Server.
Define this policy rule:
User-Name EndsWithCI @[Link] LocalAA discardDomain=y
The [Link] domain is removed from the User-Name attribute. The
RADIUS Server authenticates subscribers against the Profile Database based on
login name and password only. The group domain is ignored.

Discarding service requests


Use the discardService parameter to ignore subscriber-requested services.
The DEFAULT service profile in the subscriber’s profile set is always be used. This
is useful, for example, to deliver a particular type of service to subscribers, and
never check NAS hints.
To discard this service request, specify discardService=y. For example:
User-Name EndsWithCI @[Link] LocalAA
discardService=y
In this case, the DEFAULT service profile in the subscriber’s profile set is always
used.

Default domains
A default domain can be used when a service provider must transfer subscribers
from one system to another system. Create the subscriber accounts for these
subscribers under a single domain in system B. Then define a policy rule to assign
this domain to all subscribers who dial in to the NASs for system A.
Define the following rule in the accessReqPolicy file:
Client-IP-Address Equals [Link] LocalAA
appendDomain=[Link]
This rule appends the [Link] domain for any subscriber that dials in to this
NAS without providing a domain. The subscriber can then be authenticated based
on login name and this domain.

Service Controller 9.6.1-AAA October 12, 2012 Page 307


Chapter 7 Configuring AAA policies Network Access Guide

Alternatively, define this rule:


Client-IP-Address Equals [Link] LocalAA
domain=[Link]
This rule appends the [Link] domain to all subscribers, and replaces any
domain name in the User-Name attribute. This effectively disables any roaming
subscribers in other domains from dialing in to this NAS.

Using regular expressions


There are three action-modifiers that enable the use of regular expressions to
extract information out of the User-Name attribute:
• domainRegexFormat—extracts a domain name
• loginNameRegexFormat—extracts a login name
• serviceRegexFormat—extracts a service
These action-modifiers are required only if the defaults are not sufficient. For login
names and domains, the strings loginname@domain or domain\login_name are
both identified by default. For services, the string %service at the end of the
User-Name attribute is identified by default.
The use of these action-modifiers requires familiarity with regular expressions
(RegExp). For information about how regular expressions are used in policy rules,
see ”Attribute field entries” on page 235.

Reference another policy file for roaming subscribers


Define the following rule in the accessReqPolicy file:
User-Name StartsWith BWS/ PolicyRun
evaluatePolicy=RoamingPolicy
In a RoamingPolicy file, define the following rules:
NAS-IP-Address Equals [Link] LocalAA domain=[Link]
NAS-IP-Address Equals [Link] LocalAA domain=[Link]
- - - LocalAA
In this example, Access-Requests from subscribers with BWS as part of their
subscriber name evaluate the policy rules in the RoamingPolicy file. Based on the
RoamingPolicy file, subscribers with the IP addresses are authenticated locally
using the respective domains, otherwise local authentication is performed.
The PolicyRun policy action enables the RADIUS and/or Diameter Server to branch
policy evaluation into another policy file.

Page 308 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Policy for replacing loginName with the Calling-Station-Id


A myVar variable defined in the accessReqPolicy file can also be referenced as a
condition in the acctReqPolicy file (and vice-versa). However, the referenced myVar
condition never evaluates to “true” in the file that does not have a definition because
the myVar variable is not assigned a value. The AssignVar action that defines the
myVar variable is not executed because it resides in a different policy file.
A myVar variable defined in an accessReqPolicy, acctReqPolicy, dynamicHAPolicy,
or TLSPolicy file can be referenced as a condition in a PolicyRun file. In this case,
the value assigned to myVar is extended to the PolicyRun file.
A myVar variable defined in accessReqPolicy can be referenced as a condition in a
dynamicHAPolicy file, without needing to redefine the myVar variable in
dynamicHAPolicy file). The assigned value carries over to the dynamicHAPolicy
file. The dynamicHAPolicy files can extend only from the accessReqPolicy file, not
the acctReqPolicy file.
Replace the loginName with the Calling-Station-Id for incoming requests. To do this,
define the following rule in the accessReqPolicy file:
User-Name Contains / AssignVar extractAttr=User-Name
extractReg=(([^/]*)/){0,1}([^@]*)(@(.*) ){0,1}
myVar=RealmPrefix:${2} myVar=NAI:${3} myVar=RealmSuffix:${5}
myVar=LoginName:$Calling-Station-Id
myVar:NAI Equals [Link] CDMA2000LocalAA
loginName=myVar:LoginName ...
Use the radpet utility to show those policies that evaluate to true including the
AssignVar policies. Bridgewater Systems recommends using the radpet utility
before deploying any policy files into production and running test cases against it.
For more details, see "Testing policy rules" on page 301.

AssignVar: policy file interaction


This section describes how the AssignVar works with policy files.
A myVar variable defined in an accessReqPolicy file can also be referenced as a
condition in the acctReqPolicy file (and vice-versa), except that the referenced
myVar condition never evaluates to true in the file that does not have a definition
because the myVar variable is not assigned a value. A value is not assigned
because the AssignVar action that defines the myVar variable is not be executed
because it is in a different policy file.
A myVar variable defined in accessReqPolicy or acctReqPolicy or
dynamicHAPolicy file can be referenced as a condition in a PolicyRun file (without
needing to redefine the myVar variable in PolicyRun file). The assigned value
carries on to the PolicyRun file.
A myVar variable defined in accessReqPolicy can be referenced as a condition in a
dynamicHAPolicy file (without needing to redefine the myVar variable in
dynamicHAPolicy file). The assigned value carries on to the dynamicHAPolicy file.
Note DynamicHAPolicy files can only extend from the accessReqPolicy file, not
the acctReqPolicy file.

Service Controller 9.6.1-AAA October 12, 2012 Page 309


Chapter 7 Configuring AAA policies Network Access Guide

EAP local authentication


EAP is a PPP extension that supports additional authentication mechanisms within
PPP.
An advantage of EAP is that it can support multiple authentication mechanisms
without having to negotiate a specific mechanism during the link control phase.
Instead, the authentication mechanism is selected during the authentication phase.
With this protocol, the authenticator can request more information about the
authenticating peer.
An additional advantage of EAP is that NASs do not necessarily have to understand
each request type. A NAS may act as a pass through device between an
authenticating peer and a back-end authentication server. EAP messages from the
peer are encapsulated in the EAP-Message attribute of Access-Request
messages.
EAP is supported in IEEE 802.1X. EAP is described in RFC 2284.
Note For information about Diameter EAP support, see "Installing and
configuring Diameter" on page 133 and see the Extensible Authentication
Protocol Guide.

Basic communication 1 The authenticating peer and the authenticating server exchange identification
steps information during the link control phase.
2 The authenticating server and authenticating peer negotiate EAP and
exchange authentication information requests for authentication and responses
depending on the EAP type selected. The length and detail of the exchange
depends on the EAP type selected.
3 The authentication phase ends when the authenticating server sends a
success or failure packet to the authenticating peer.
The Service Controller RADIUS Server supports local EAP authentication for the
following EAP types:
• EAP-MD5-Challenge—duplicates Challenge Handshake Authentication
Protocol (CHAP) password protection on a Wireless Local Area Network
(WLAN)
• LEAP—Lightweight Extensible Authentication Protocol (LEAP) is Cisco’s
protocol for PPP authentication that supports mutual authentication between
the Cisco Access Point (AP) and RADIUS. In addition, a dynamic WEP session
key is generated.
• PEAP—Protected EAP. A secured TLS tunnel is established using a
server-side certificate. Client authentication occurs over this tunnel. PEAP
supports EAP methods through this tunnel including MSCHAP-v2.
• EAP-TLS—Extensible Authentication Protocol Transport Level Security. Client
and server authenticate each other using certificates.
• EAP-TTLS—Tunneled Transport Layer Security. A secured TLS tunnel is
established using a server-side certificate.
– The server may authenticate the client using a certificate or, if there is no
certificate, for RADIUS, using PAP/CHAP/MSCHAPv1 or v2, or EAP.

Page 310 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

– Policy decisions can be based on the Inner-User-ID to direct phase 2


authentication to the appropriate remote RADIUS server or to handle
authentications locally.
– An example RADIUS TLSPolicy is located in /opt/aaasc/radius/
[Link] or /opt/aaasc/config/radius, and a Diameter example is
installed in /opt/aaasc/dia-aaa/[Link].
Note In a WiMAX environment RADIUS only supports CHAP and
MSCHAPv2 for phase 2 of EAP-TTLS.
Note In all environments Diameter only supports MSCHAPv2 for phase 2 of
EAP-TTLS.
• EAP-SIM—Extensible Authentication Protocol Method for Global System for
Mobile Communications (GSM) Subscriber Identity Modules. SIM is based on
challenge-response mechanisms and symmetric cryptography.
• EAP-AKA—Extensible Authentication Protocol Authentication Key Agreement.
AKA is based on challenge-response mechanisms and symmetric
cryptography.
Note For configuration information, see the chapter “EAP configuration” in the
Extensible Authentication Protocol Guide.
EAP is encapsulated within three different protocols:
• 802.11 WLAN
• RADIUS AAA
• PPP client
LEAP is a proprietary Cisco EAP [Link] use LEAP authentication, install the Cisco
Aironet Wireless 350 series LAN adapter. This adapter is designed to communicate
with a Wireless-to-Wireline network access device such as the Cisco Aironet 350
series Access Point (AP). It encrypts data transmission using dynamically
generated WEP keys.
The Cisco Aironet LAN adapter must be installed on the user end and the Service
Controller configured for LEAP authentication. The AP must be a Cisco device,
such as the Aironet 350 AP, as a Cisco vendor attribute (VSA) is returned from the
Service Controller to the device in an access-accept message.
This VSA contains the dynamic WEP session key. In addition to having the Cisco
Aironet LAN adapter installed on the client machine, the Cisco Aironet Client Utility
application must also be installed on the client machine and configured for LEAP.
When using LEAP, in addition to defining the policy, use the Cisco/Aironet entry in
the RADIUS [Link] file.
EAP-TLS is used in environments that use certificate-based security. EAP-TLS
enables mutual authentication, integrity-protected ciphersuite negotiation, and key
exchange between two end points in a communication link. EAP-TLS is described
in RFC 2716.
This authentication method has the following advantages:
• data encryption keys are determined at both ends of the communication link

Service Controller 9.6.1-AAA October 12, 2012 Page 311


Chapter 7 Configuring AAA policies Network Access Guide

• data exchange is protected by public key encryption


• certificates are used to provide greater security
• automatic authentication
• no dependency on a user’s account password
For information about PEAP, see the chapter “EAP configuration” in the Extensible
Authentication Protocol Guide.
EAP-TTLS supports dual-mode authentication where the AAA server and the TTLS
AAA server are on the same process (Mode 1) or on different processes (Mode 2).

EAP proxy
This section provides information about RADIUS and Diameter EAP proxy.

RADIUS proxy mode In addition to supporting EAP-MD5, PEAP, EAP-TLS, EAP-TTLS, MSCHAP, and
LEAP local authentication, the Service Controller RADIUS Server supports all EAP
types in proxy mode.
Note In a WiMAX environment RADIUS only supports CHAP and MSCHAPv2 for
phase 2 of EAP-TTLS.
The Service Controller sends the RADIUS-encapsulated EAP packets between the
Access Point (AP) and an EAP-supported RADIUS Server. Two attributes are sent
during proxy from RADIUS to the authentication RADIUS Server if they are
received from the AP: EAP-Message and Message-Authenticator. The remote
EAP-supported RADIUS Server selects which EAP type to apply for the user.
Depending on the type of EAP authentication, the actual authentication may be
done on an EAP-supported RADIUS Server or on a backend server.
The following example policy configures local authentication on an EAP-supported
RADIUS Server:
EAP-Message Appears Once LocalAA EAP-Policy=LEAP
where
LEAP is a type-selection-policy name entry in the [Link] configuration file
The following example policy configures proxying to a remote third-party EAP-
supported RADIUS Server:
EAP-Message Appears - ProxyAA target=EAPRadius
authorizeLoginName=repuser AuthorizeDomain=[Link]
In the [Link] file, define EAPRadius as the TargetName, for example:
<ProxyTargetConfiguration ProxyTimeoutFactor=”100”>
<RADIUSServer
TargetName="EAPRadius"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="5"
AccountingPort="1813"

Page 312 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

AuthenticationPort="1812"
MaxRetries="1"
OverwriteIP="Y"
StripDomain="N"
DigitizeAcctSessionID="Y"
/>
</ProxyTargetConfiguration>

Diameter proxy For information about Diameter proxy mode, see "Configuring Diameter EAP-TTLS
mode phase 2 proxy to RADIUS AAA" on page 158, and see the chapter “EAP-TTLS” in
the Extensible Authentication Protocol Guide.

Microsoft CHAP (MSCHAP)


The Service Controller supports two versions of MSCHAP: MSCHAPv1 (RFC 2433)
and MSCHAPv2 (RFC 2759). This support enables the Service Controller to
provide additional dial-up authentication mechanisms above the standard PAP and
CHAP mechanisms. The target platform for MSCHAP is Microsoft Windows.
No configuration is required on the Service Controller to enable MSCHAPv1
support. To enable subscribers to be authenticated with MSCHAPv1 the NAS and
the client’s dial-up software must be configured. The Service Controller
authenticates using MSCHAPv1 when it receives two MS VSAs in an
Access-Request: MS-CHAP-Challenge and MS-CHAP-Response.
There are two versions of MSCHAPv1: LM-version (LAN Manager) and NT-version
(WinNT). For local authentications the Service Controller only supports the
NT-version of MSCHAPv1. In proxy mode, both versions of MSCHAPv1 are
supported.
The Service Controller does not support the MSCHAPv1 and MSCHAPv2
subscriber password changing mechanism.
Bridgewater Systems recommends that MSCHAPv1 not be used to authenticate
subscribers as there are known security issues. MSCHAPv2 was created to
address these security issues.
MSCHAPv2 provides mutual authentication between the Service Controller and the
NAS. PAP, CHAP and MSCHAPv1 do not provide mutual authentication.
No configuration is required on the Service Controller to enable MSCHAPv2. The
Service Controller authenticates using MSCHAPv2 when it receives two MS VSAs
in an Access-Request: MS-CHAP-Challenge and MS-CHAP2-Response.
Configuration is required on the NAS and the client’s dial-up software to
authenticate a subscriber with MSCHAPv2.

Service Controller 9.6.1-AAA October 12, 2012 Page 313


Chapter 7 Configuring AAA policies Network Access Guide

The Service Controller returns the MS-CHAP2-Success VSA in an Access-Accept


message. The NAS then verifies the value of this VSA. If it successfully validates
the value, mutual authentication is successful and the connections is permitted. If
the value of the VSA is not valid the connection is dropped. MSCHAPv2 is also
supported for proxy authentication.
Note In a WiMAX environment RADIUS only supports CHAP and MSCHAPv2 for
phase 2 of EAP-TTLS. Diameter only supports MSCHAPv2 for phase 2 of
EAP-TTLS.

Microsoft Point-To-Point Encryption (MPPE)


MPPE (RFCs 3078 and 3079) cryptographically secures the PPP communication
link between the remote client’s computer and the NAS. MPPE forces the Service
Controller to return two session keys to the NAS via MS VSAs in the Access-Accept
message: MS-MPPE-Send-Key and MS-MPPE-Recv-Key. These session keys are
used by the NAS and the client’s computer to encrypt and decrypt PPP packets.
To provide MPPE support, an action modifier (mppeEncryptionTypes) must be
added to a LocalAA policy in the accessReqPolicy file. There are three key
strengths: 40, 56, and 128 bit.
The following shows the MPPE usage:
mppeEncryptionTypes=keystrength
where
keystrength specifies the type of encryption allowed for MPPE
The options are:
• None (default): no encryption available
• 40: RC4 encryption using a 40-bit key is allowed
• 56: RC4 encryption using a 56-bit key is allowed
• 128: RC4 encryption using a 128-bit key is allowed
For example, add the following line to the accessReqPolicy file:
User-Name EndsWithCI @[Link] LocalAA mppeEncryptionTypes=128
As well as specifying the mppeEncryptionTypes action modifier, a subscriber must
also be authenticated via MSCHAPv2 because the generation of MPPE keys is
based on contents in the MS-CHAP2-Response VSA in an Access-Request
message.
When the mppeEncryptionTypes action modifier is not configured or set to “None”,
a subscriber can be authenticated with MSCHAPv2 but MPPE VSAs are not
returned in the Access-Accept message. In this scenario the PPP connection is not
encrypted.
MPPE is not supported for MSCHAPv1 for local authentications. MPPE for
MCHAPv1 and MSCHAPv2 is supported for proxy authentications.

Page 314 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Compare User-Name to Called-Number


Define the following rule in the accessReqPolicy file:
User-Name Equals $Called-Station-Id LocalAA

PreAccounting
PreAccounting performs subscriber pre-authorization prior to completing an
accounting action. The usage and behaviour of PreAccounting are identical to
Preauthorization but apply to accounting-request messages. For more information,
see "Preauthorization" on page 315.
- - - PreAccounting service=ServiceA

Preauthorization
Preauthorize a subscriber by retrieving information from the Profile Database and
by comparing this information to a value from a specified connection service profile.
In ACL deployments, use PreAuthorize to check Access Control Limits as well as to
authorize against a specified RADIUS Connection Service prior to proxying a
request to a customer AA server.
In either case, policy evaluation may continue after executing a PreAuthorize policy
action. The PreAuthorize action is described in Table 96 on page 240 and in
"Configuring PreAuthorize using Access Control Limits (ACL) for proxy" on page
297.
Note The Service Controller only stores the attributes retrieved by the most
recently executed PreAuthorize policy rule.
A PreAuthorize action must include one of the following action modifiers, otherwise
the RADIUS Server fails to start:
• service
• acService
• getProxyService

PreAuth: tag Use the PreAuth: tag to indicate that the attribute comparison should occur against
the attribute retrieved from the RADIUS connection service profile specified by the
preceding PreAuthorize policy rule. If the PreAuth: tag is not specified, the attribute
comparison occurs against the attribute received from the Access-Request.
In this annotated example, ServiceA is provisioned with a Callback-Id of 123, and
ServiceB is provisioned with a Callback-Id of 456:
--- PreAuthorize service=ServiceA
Retrieves attribute value pairs from a service profile called ServiceA.
PreAuth:STARENT:Callback-Id Equals 123 PreAuthorize
service=ServiceB

Service Controller 9.6.1-AAA October 12, 2012 Page 315


Chapter 7 Configuring AAA policies Network Access Guide

Attempts to match the retrieved ServiceA Callback-Id against a given value, “123”.
The ServiceA Callback-Id does equal 123, so the Service Controller returns the
ServiceB attributes.
PreAuth:STARENT:Callback-Id Equals 123 PreAuthorize
service=ServiceC
Attempts to match the retrieved ServiceB Callback-Id against a given value, “123”.
The ServiceB Callback-Id does not match the given value, so the policy line is not
executed.
--- LocalAA
Catch-all rule to perform local authentication.

Using myVar and In this example, this policy compares the Calling-Station-Id to the preauthorization
rejection messages Callback-Number, and returns an error if the values don’t match:
- - - AssignVar myVar=myCallingID:$Calling-Station-Id
- - - PreAuthorize service=HRPD
myVar:myCallingID Equals PreAuth:$Callback-Number LocalAA
- - - SendReject replyMessage="AVP verification failed"

HLR authorization
The GSMLocalAA action supports the retrieval of subscriber profile information
from an HLR using the hlrAuthorization action modifier. If the hlrAuthorization action
modifier is set to Generic, the Service Controller stores the following values
retrieved from the HLR in Bridgewater VSAs:
• Bearer Services (WLAN-HLR-BS)
• Tele Services (WLAN-HLR-TS)
• Operator Determined Barring (WLAN-HLR-ODB)
If the GSMLocalAA action is configured with the authorizationPolicy action modifier,
the corresponding Bridgewater VSAs can be referenced in the authorization policy
to perform additional decisions. For specific examples, see "authorizationPolicy" on
page 267.

HLRAuth: tag Use the HLRAuth: tag to indicate that the attribute comparison should occur against
an attribute injected with data retrieved from an HLR. If the HLRAuth: tag is not
specified, the attribute comparison occurs against the attribute received from the
Access-Request.

Page 316 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Conditional dynamic proxy target assignment


Assign proxy targets and proxy target groups to subscribers using the
accessReqPolicy and acctReqPolicy policy files.

accessReqPolicy This accessReqPolicy configuration enables administrators to assign proxy targets


and proxy target groups by retrieving and assigning to the subscriber a RADIUS
Proxy Service service profile.
Note This is available only to customers using the Proxy Database Configuration
optionality package.
- - - AssignVar myVar=repUser:prefix||$Calling-Station-Id
- - - PreAuthorize loginName=myVar:repUser getProxyService=Y
PreAuth:BRIDGEWATER:Proxy-Target Appears Once ProxyAA
target=PreAuth:$BRIDGEWATER:Proxy-Target
- - - LocalAA

acctReqPolicy This acctReqPolicy configuration enables administrators to assign proxy targets


and proxy target groups by retrieving and assigning to the subscriber a RADIUS
Proxy Service service profile.
Note This is available only to customers using the Proxy Database Configuration
optionality package.
- - - AssignVar myVar=repUser:prefix||$Calling-Station-Id
- - - PreAccounting loginName=myVar:repUser getProxyService=Y
PreAcct:BRIDGEWATER:Proxy-Target Appears Once ProxyAcct
target=PreAcct:$BRIDGEWATER:Proxy-Target
- - - LocalAcct

Using subtype attributes in Access-Requests to control network access


Manage a subscriber’s access to the network based on the value of a specified
subtype attribute in an Access-Request message.
RADIUS supports subtype attributes, including subtype attributes in octet string
(binary) format, in Access-Request messages.
Configure the RADIUS accessReqPolicy to trigger the RADIUS Server to retrieve
the RADIUS Connection Service profile associated to a subscriber. The RADIUS
Server compares the value of a specific subtype attribute or the value of a nested
subtype sent in the Access-Request to a list of values provisioned against the
RADIUS Connection Service Profile. If the values match, the subscriber is allowed
access to the network.

Zone-based authorization using the 3GPP2-Subnet VSA


This section and the following procedure provide information about configuring
RADIUS to authorize or reject subscribers based on their geographic zone.
The 3GPP2-Subnet is a subtype attribute that contains 2 nested subtypes. Nested
subtype 2 contains the Sector ID, which determines the subscriber’s location.

Service Controller 9.6.1-AAA October 12, 2012 Page 317


Chapter 7 Configuring AAA policies Network Access Guide

Provision a subscriber’s home zone in Service Manager using the 3GPP2-Subnet


Sector ID, and configure the RADIUS Server to compare the 3GPP2-Subnet Sector
ID in Access-Request messages against the provisioned value, to allow or deny
access to the network.
• If RADIUS compares the incoming 3GGP2-Subnet Sector ID with the
provisioned 3GPP2-Subnet Sector ID and finds the subscriber is in the home
zone, RADIUS sends an Access-Accept.
• If RADIUS compares the incoming 3GGP2-Subnet Sector ID with the
provisioned 3GPP2-Subnet Sector ID and finds the subscriber is not in the
home zone, RADIUS sends an Access-Reject.

To configure zone-based authorization using the 3GPP2-Subnet VSA


1 Configure the RADIUS accessReqPolicy file to extract the Sector ID from the
3GPP2-Subnet in the Access-Request and compare it against the
3GPP2-Subnet Sector ID provisioned in the RADIUS Connection Service
Profile associated to a subscriber.
The 3GPP2-Subnet contains 2 nested subtypes. Subtype 2 contains the Sector
ID, which determines the subscriber’s location.
The following policy example configures RADIUS to:
— extract the Sector ID from the 3GPP2-Subnet in the Access-Request and
compare it against the 3GPP2-Subnet Sector ID provisioned against the
subscriber
— if the values match, the subscriber is in the home zone, and RADIUS sends
an Access-Accept
— if the values do not match, the subscriber is not in the home zone, and
RADIUS sends an Access-Reject
- - - AssignVar extractAttr=STARENT:3GPP2-Subnet
extractReg="(([0-9a-zA-Z]{49})([0-9a-zA-Z]{9}))"
myVar=mySubnetId:${3}
- - - PreAuthorize service=Subnetvalidation returnAVPs=n
continueNotFound=y myVar:mySubnetId Equals
PreAuth:$STARENT:3GPP2-Subnet CDMA2000LocalAA
service=PFD-V2-ST-SP
- - - SendReject replyMessage="Not in Zone1"
2 Provision the 3GPP2-Subnet Sector ID in a RADIUS Connection Service
Profile.
When provisioning the 3GPP2-Subnet Sector ID in Service Manager the format
must be the same as that expected in the Access-Request.
— For example if the 3GPP2-Subnet string in the Access-Request message is
011368008E7E039FA1F501AC1D8D3E520000000212008E7E039FA1F50
1, the RADIUS Server extracts the Sector ID value 39FA1F501, and
matches the extracted value with the value provisioned in Service Manager.
— In this case, provision the 3GPP2-Subnet Sector ID in Service Manager as
39FA1F501.

Page 318 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

3 Assign the RADIUS Connection Service Profile from step 2 to a user profile set.
For more information about configuring a RADIUS Connection Service Profile
and a user profile set, see:
– the chapter “Managing service profiles” in the Service Manager: Subscriber
Provisioning Guide for AAA
– the chapter “RADIUS connection service” in the Service Manager: Services
Provisioning Guide for AAA.

Service Controller 9.6.1-AAA October 12, 2012 Page 319


Chapter 7 Configuring AAA policies Network Access Guide

CSID/MSID mismatch detection for LDAP deployments


The topics in this section are:
• Overview
• CSID validation options
• Validation process
• Configuration options
• Configuring CSID/MSID mismatch detection

Overview
Use policy configuration to detect a mismatch between the value of the
Calling-Station ID supplied in a subscriber’s Access-Request message and the
Mobile-Station ID provisioned in a subscriber’s profile. The subscriber’s profile is
stored in the LDAP database.
CSID/MSID mismatches can be caused by:
• copying one subscriber’s credentials {network access identifier (NAI) and
password} to another subscriber’s device
• activating a subscriber device that was previously provisioned with another
subscriber’s credentials
• IT systems improperly re-setting subscriber/device credentials
Note To use this feature, the [Link] file must be configured with an IMSI
service profile that contains attributes that match to those contained in the
subscriber profile, which is stored in the LDAP database. Typically these
attributes are the MSID and either the MEID or the ESN.

CSID validation options


CSID/MSID mismatch detection enables you to create a policy file that validates
any or all of the following options (for LDAP deployments only):
• CSID is either 10 or 15 digits
• last 10 digits of the CSID (received in the Access-Request message) matches
the last 10 digits of the MSID retrieved from the LDAP database
• the first 3 of the last 10 digits in the CSID map to a number in the following
range: 201 to 989 inclusive
• if the Access-Request message contains an MEID or ESN, use the associated
MEID or ESN Mismatch Detection policy file to validate the attribute

Validation process
When you configure CSID/MSID mismatch detection, the Service Controller
evaluates subscriber requests based on the options specified in the Mismatch
Detection policy files you create.

Page 320 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

As Figure 32 shows, during the CSID/MSID “mismatch detection” process, if a


specific attribute in a request passes one validation option, the “mismatch
detection” process continues to the next validation option. If the request fails a
validation option (a mismatch is detected), the policy can be configured to log an
error and continue the validation process or to log an error and reject the request.
If the detection process completes without detecting mismatches (or it is configured
to continue validating regardless of the outcome), the Service Controller evaluates
existing policies and applies the appropriate actions.
Figure 32: Policy call flow for CSID/MSID mismatch detection

$FFHVV5HT3ROLF\

3UH$XWKSROLF\
IRU0(,'(61

,V&6,' 1R /RJ 5HMHFW


RUGLJLWV"
&RQILJXUDEOH
&RQWLQXH
<HV

9DOLGDWLRQ 'RHVWKH
RSWLRQV 1R /RJ 5HMHFW
&6,'
PDWFKWKH06,'" &RQILJXUDEOH
&RQWLQXH
<HV

'RWKHODVW
GLJLWVLQWKH&6,' 1R /RJ 5HMHFW
VWDUWZLWKWR"
&RQILJXUDEOH
&RQWLQXH
<HV

,IWKHUHTXHVW
FRQWDLQVDQ0(,'RU
(61GRHVLWPDWFKWRWKH 1R /RJ 5HMHFW
VWRUHGSURILOH"
&RQILJXUDEOH
&RQWLQXH
<HV

&RQILJXUDEOH

&RPSOHWHVWDQGDUG &RQILJXUHWKHSROLF\WRFUHDWHDORJDQGHLWKHU
SROLF\H[HFXWLRQ UHMHFWWKHXVHURUFRQWLQXHWKHSROLF\HYDOXDWLRQ

Service Controller 9.6.1-AAA October 12, 2012 Page 321


Chapter 7 Configuring AAA policies Network Access Guide

Configuration options
Configure any or all of the validation options described in the section “"CSID
validation options" on page 320”.
For each option, you can configure CSID/MSID mismatch detection to:
• log an error and continue validating
or
• log an error and reject the request
For example, you can configure policy to log an error and reject a request as soon
as the feature detects a mismatch.

Configuring CSID/MSID mismatch detection


To configure CSID/MSID mismatch detection, you need to:
• configure the primary policy file, such as accessReqPolicy, to point to the
Mismatch Detection policy file, which defines the validation options
• create the CSID Mismatch Detection policy file to define the validation options
• [optional] create a custom log message for validation options configured to “log
and continue validating”
• create the MEID and ESN Mismatch Detection policy files to validate MEIDs or
ESNs contained subscriber requests
• [optional] create one “log and reject” policy file for each validation option that is
configured to reject a subscriber when a mismatch is detected
• confirm which existing policy files you want to execute after the CSID/MSID
validation process completes

Configuring the Configure the primary policy file, such as accessReqPolicy, to evaluate specified
primary policy file subscribers using the Mismatch Detection policy file.
Make sure to specify the:
• PreAuthorize policy action, which enables the Service Controller to retrieve the
appropriate attributes from the LDAP database
• policy file in which CSID/MSID mismatch detection is evaluated
In the following example, the Service Controller evaluates policy using the
Mismatch Detection policy file for all subscribers that belong to the realm
“@[Link]”:
- - - PreAuthorize service=IMSI returnAVPs=n continueNotFound=y
loginName=$User-Name
User-Name EndsWithCI @[Link] PolicyRun
evaluatePolicy=MismatchDetection
- - - PolicyRun evaluatePolicy=ExistingPolicies

Page 322 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Creating the CSID Create a CSID Mismatch Detection policy file that is used to compare the CSID
Mismatch Detection received in a subscriber’s Access Request message to the MSID attribute in the
policy file subscriber’s profile stored in the LDAP database.
Note Make sure to save the CSID Mismatch Detection policy file to your policy
file directory, such as /opt/aaasc/config/radius.
In this policy file:
• specify each validation option and provide the associated actions and action
modifiers as specified in the example file below
• for mismatches, configure each validation option to do one of the following:
– generate a custom log and continue validating
– continue validating without generating a log
– generate a custom log and reject the request
– reject the request without generating a custom log
• for each validation option configured to “log and continue validating”, create a
custom log message
• for each validation option configured to “log and reject” a request, point to the
associated “log and reject” policy file
• [optional] for MEID/ESN validation, point to the MEID and ESN Mismatch
Detection files
• point to standard policy file(s) that must be executed after CSID/MSIDmismatch
detection completes
In the following example, all “CSID/MSID mismatch detection” validation options are
evaluated. All validation options are configured to “log and reject” the request when
a mismatch is detected.
Each validation option is introduced by a comment, such as:
# validate mismatch_detection_option
where:
mismatch_detection_option defines the validation option
For more information about the conditions, actions, and action modifiers used in the
following example, see:
• "Conditions" on page 235
• "Actions" on page 239
• "Action modifiers" on page 262
CSID Mismatch Detection policy file example
# validate that the CSID exists
Calling-Station-Id Appears Never PolicyRun evaluatePolicy=CSIDMissing

# validate that the received CSID's length is 10 or 15 digits long

Service Controller 9.6.1-AAA October 12, 2012 Page 323


Chapter 7 Configuring AAA policies Network Access Guide

Calling-Station-Id NotRegExp ^[0-9]{10}$|^[0-9]{15}$ PolicyRun


evaluatePolicy=CSIDLengthFail

# validate that the last 10 digits of the received CSID is equal to last 10 digits of the
MSID (provisioned)
- - - AssignVar extractAttr=Calling-Station-Id extractReg=([0-9]{10})$
myVar=LastTenCSID:${1} continuePreProcessing=y ignorePreProcessingFailure=y
- - - AssignVar extractAttr=PreAuth:$STARENT:Prov-IMSI extractReg=([0-9]{10})$
myVar=LastTenMSID:${1} continuePreProcessing=y
ignorePreProcessingFailure=y
myVar:LastTenCSID NotEquals myVar:LastTenMSID PolicyRun
evaluatePolicy=CSIDMSIDMatchFail

# validate the first 3 digits of the last 10 digits of the received CSID is in the range of
201-989 inclusive
Calling-Station-Id RegExp [01][0-9][0-9][0-9]{7}$|200[0-9]{7}$|99[0-9][0-9]{7}$
PolicyRun evaluatePolicy=CSIDRangeFail

#does the request contain an MEID?


STARENT:3GPP2-MEID Appears Once PolicyRun evaluatePolicy=ValidateMEID

#does the request contain an ESN?


STARENT:3GPP2-ESN Appears Once PolicyRun evaluatePolicy=ValidateESN

- - - PolicyRun evaluatePolicy=ExistingPolicies
where:
ExistingPolicies describe any standard policies that need to be executed

Creating MEID and For Access-Request messages that contain an MEID or an ESN, create separate
ESN mismatch mismatch detection policy files to validate the MEID and ESN attributes.
detection files Note Make sure to save the MEID and ESN Mismatch Detection policy files to
your policy file directory, such as /opt/aaasc/config/radius.
For more information about the conditions, actions, and action modifiers used in the
following examples, see:
• "Conditions" on page 235
• "Actions" on page 239
• "Action modifiers" on page 262

Page 324 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

MEID Mismatch Detection policy file example


The following policy example is configured to validate the MEID received in the
Access-Request message against the MEID stored in the subscriber’s profile.
If the MEIDs do not match, the file is configured to evaluate the MEIDMatchFail
policy file, which generates a custom log and rejects the subscriber’s request.
The MEIDMatchFail policy file is described in the section "Creating “log and reject”
policy files" on page 326.
If the MEIDs match, policy evaluation continues to any standard policies.
Example:
# validate that the MEID received in request matches the provisioned MEID
STARENT:3GPP2-MEID NotEqualsCI PreAuth:MEID PolicyRun
evaluatePolicy=MEIDMatchFail
- - - PolicyRun evaluatePolicy=ExistingPolicies
where:
ExistingPolicies describe any standard policies that need to be executed

ESN Mismatch Detection policy file example


The following policy example is configured to validate the ESN received in the
Access-Request message against the ESN stored in the subscriber’s profile.
If the ESNs do not match, the following example is configured to “log and continue
validating”. The system generate a custom log message that is populated with the
log level, specified attributes, and attribute values (if available).
The policy evaluation continues to any standard policies whether or not the ESNs
match.
Example:
# validate that the ESN received in request matches the provisioned ESN
STARENT:3GPP2-ESN NotEqualsCI PreAuth:ESN LogMessage message="ESN
received in request does not match provisioned ESN." priority=error
attrs=ReqCSID|$Calling-Station-Id,ReqMEID|$STARENT:3GPP2-MEID,ReqESN|$
STARENT:3GPP2-ESN,ProvMSID|PreAuth:$Calling-Station-Id,ProvMEID|PreAuth:
$STARENT:3GPP2-MEID,ProvESN|PreAuth:$STARENT:3GPP2-ESN

# continue running existing policies


- - - PolicyRun evaluatePolicy=ExistingPolicies
where:
ExistingPolicies describe any standard policies that need to be executed

Service Controller 9.6.1-AAA October 12, 2012 Page 325


Chapter 7 Configuring AAA policies Network Access Guide

Creating “log and For each validation option configured to “log and reject” a request when a
reject” policy files mismatched attribute value is detected, create an associated “log and reject” policy
file that specifies the:
• LogMessage policy action, which generates a custom log message
• “message” action modifier whose value is the custom message describing the
error
• [optional] “priority” action modifier set to the log level, such as INFO
• [optional] “attrs” action modifier that specifies the attributes and values you
want to expose in the log
• replyMessage to be included in the Access-Reject message
Note Make sure to save “log and reject” policy files to your policy file directory,
such as /opt/aaasc/config/radius.
The following examples show how to create a “log and reject” policy file for each
validation option described in "CSID validation options" on page 320.

CSIDMissing policy file


# log failed validation and reject
- - - LogMessage message="CSID is missing from request." priority=error
- - - SendReject replyMessage=“Missing CSID"

CSIDLengthFail policy file


Use this example to create a “log and reject” policy file associated with the
validation option: “CSID length is not 10 or 15 digits long”
# log failed validation and reject
- - - LogMessage message="CSID length is not 10 or 15 digits long." priority=error
attrs=ReqCSID:Calling-Station-Id,ReqMEID:STARENT:3GPP2-MEID,ReqESN:STA
RENT:3GPP2-ESN,ProvMSID:PreAuth:,ProvMEID:PreAuth:MEID,ProvESN:PreAut
h:ESN
- - - SendReject replyMessage="Invalid CSID"

CSIDMSIDMatchFail policy file


Use this example to create a “log and reject” policy file associated with the
validation option: “CSID received in the request does not match provisioned MSID”
# log failed validation and reject
- - - LogMessage message="CSID received in the request does not match
provisioned MSID." priority=error
attrs=ReqCSID:Calling-Station-Id,ReqMEID:STARENT:3GPP2-MEID,ReqESN:STA
RENT:3GPP2-ESN,ProvMSID:PreAuth:,ProvMEID:PreAuth:MEID,ProvESN:PreAut
h:ESN
- - - SendReject replyMessage="Invalid CSID"

Page 326 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

CSIDRangeFail policy file


Use this example to create a “log and reject” policy file associated with the
validation option: “CSID received in the request does not match the range
provisioned MSID”
# log failed validation and reject
- - - LogMessage message="First three digits of the last ten digits of CSID not in the
valid range of 201-989." priority=error
attrs=ReqCSID:Calling-Station-Id,ReqMEID:STARENT:3GPP2-MEID,ReqESN:STA
RENT:3GPP2-ESN,ProvMSID:PreAuth:,ProvMEID:PreAuth:MEID,ProvESN:PreAut
h:ESN
- - - SendReject replyMessage="Invalid CSID"

MEID_ESNMatchFail policy file


Use this example to create a “log and reject” policy file associated with the
validation option: “MEID received in the request does not match provisioned MEID."
# log failed validation and reject
- - - LogMessage message="MEID or ESN received in the request does not match
provisioned MEID." priority=error
attrs=ReqCSID:Calling-Station-Id,ReqMEID:STARENT:3GPP2-MEID,ReqESN:STA
RENT:3GPP2-ESN,ProvMSID:PreAuth:,ProvMEID:PreAuth:MEID,ProvESN:PreAut
h:ESN
- - - SendReject replyMessage="Invalid MEID or ESN"

Creating custom log Use the LogMessage action and appropriate action modifiers, such as “message”,
messages to generate a custom log message when a mismatch is detected.
For validation options that are configured to “log and continue validating”:
• add the LogMessage action and appropriate action modifiers to each section of
the CSID Mismatch Detection policy file that defines a specific validation option
For validation options that are configured to “log and reject” the request:
• add the LogMessage action and appropriate action modifiers to each “log and
reject” policy file associated with mismatched validation options
When a custom log is configured for a validation option and the system detects a
mismatch, the system writes the associated custom log message to the RADSYS
log family.

To create a custom log message


1 In the appropriate section of the Mismatch Detection policy file or in the
associated “reject” policy file, add the LogMessage policy action.
2 On the same line, add the “message” action modifier and provide a short
custom message as the value.
3 [Optional] On the same line, add one or both of the following action modifiers:
– “priority” set to the preferred log level (default=INFO).

Service Controller 9.6.1-AAA October 12, 2012 Page 327


Chapter 7 Configuring AAA policies Network Access Guide

– “attrs” set to a comma-delimited list of attributes and values.


4 Save the file and exit.
For more information about the actions and action modifiers used in the following
examples, see:
• "Actions" on page 239
• "Action modifiers" on page 262

Example of a custom log configured in the CSID Mismatch Detection


policy file
# validate that the last 10 digits of the CSID (in request) is
equal to last 10 digits of the MSID (provisioned)

- - - AssignVar extractAttr=Calling-Station-Id
extractReg=([0-9]{10})$ myVar=LastTenCSID:${1}
continuePreProcessing=y ignorePreProcessingFailure=y

- - - AssignVar
extractAttr=PreAuth:$STARENT:Calling-Station-Id
extractReg=([0-9]{10})$ myVar=LastTenMSID:${1}
continuePreProcessing=y ignorePreProcessingFailure=y

myVar:LastTenCSID NotEqualsCI myVar:LastTenMSID LogMessage


message="CSID received in the request does not match
provisioned MSID." priority=error
attrs=ReqCSID|$Calling-Station-Id,ReqMEID|$STARENT:3GPP2-MEID
,ReqESN|$STARENT:3GPP2-ESN,ProvMSID|PreAuth:$Calling-Station-
Id,ProvMEID|PreAuth:$STARENT:3GPP2-MEID,ProvESN|PreAuth:$STAR
ENT:3GPP2-ESN

Example a custom log configured in the CSIDLengthFail “log and reject”


policy file
# log failed validation and reject
- - - LogMessage message="CSID length is not 10 or 15 digits
long."
priority=error
attrs=ReqCSID:Calling-Station-Id,ReqMEID:STARENT:
3GPP2-MEID,ReqESN:STARENT:3GPP2-ESN,ProvMSID:PreAuth:,ProvMEI
D:PreAuth:MEID,ProvESN:PreAuth:ESN
- - - SendReject replyMessage="Invalid CSID"

Example of custom log output


Dec 12 13:02:41 kansparc99 radiusd[8591]: [ID 309018
[Link]] ERR RADSYS(6085) CSID length is not 10 or 15
digits long. ReqCSID=1234555512345678,
ReqMEID=XXYYZZIIJJKKAA, ReqESN=AABBCCDD,
ProvMSID=0123455551234567, ProvMEID=XXyyZZiiJJkkaa,
ProvESN=AaBbCcDd

Page 328 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 7 Configuring AAA policies

Using subtype attributes in Access-Requests to control network access


You can manage a subscriber’s access to the network based on the value of a
specified subtype attribute in an Access-Request message.
RADIUS supports subtype attributes, including subtype attributes in octet string
(binary) format, in Access-Request messages.
Configure the RADIUS accessReqPolicy to trigger the RADIUS Server to retrieve
the RADIUS Connection Service profile associated to a subscriber. The RADIUS
Server compares the value of a specific subtype attribute or the value of a nested
subtype sent in the Access-Request to a list of values provisioned against the
RADIUS Connection Service Profile. If the values match, the subscriber is allowed
access to the network.

Zone-based authorization using the 3GPP2-Subnet VSA


This section and the following procedure provide information about configuring
RADIUS to authorize or reject subscribers based on their geographic zone.
The 3GPP2-Subnet is a subtype attribute that contains 2 nested subtypes. Nested
subtype 2 contains the Sector ID, which determines the subscriber’s location.
Provision a subscriber’s home zone in Service Manager using the 3GPP2-Subnet
Sector ID, and configure the RADIUS Server to compare the 3GPP2-Subnet Sector
ID in Access-Request messages against the provisioned value, to allow or deny
access to the network.
• If RADIUS compares the incoming 3GGP2-Subnet Sector ID with the
provisioned 3GPP2-Subnet Sector ID and finds the subscriber is in their home
zone, RADIUS sends an Access-Accept.
• If RADIUS compares the incoming 3GGP2-Subnet Sector ID with the
provisioned 3GPP2-Subnet Sector ID and finds the subscriber is not in their
home zone, RADIUS sends an Access-Reject.

To configure zone-based authorization using the 3GPP2-Subnet VSA


1 Configure the RADIUS accessReqPolicy file to extract the Sector ID from the
3GPP2-Subnet in the Access-Request and compare it against the
3GPP2-Subnet Sector ID provisioned in the RADIUS Connection Service
Profile associated to a subscriber.
The 3GPP2-Subnet contains 2 nested subtypes. Subtype 2 contains the Sector
ID, which determines the subscriber’s location.
The following policy example configures RADIUS to:
— extract the Sector ID from the 3GPP2-Subnet in the Access-Request and
compare it against the 3GPP2-Subnet Sector ID provisioned against the
subscriber
— if the values match, the subscriber is in their home zone, and RADIUS
sends an Access-Accept

Service Controller 9.6.1-AAA October 12, 2012 Page 329


Chapter 7 Configuring AAA policies Network Access Guide

— if the values do not match, the subscriber is not in their home zone, and
RADIUS sends an Access-Reject
- - - AssignVar extractAttr=STARENT:3GPP2-Subnet
extractReg="(([0-9a-zA-Z]{49})([0-9a-zA-Z]{9}))"
myVar=mySubnetId:${3}
- - - PreAuthorize service=Subnetvalidation returnAVPs=n
continueNotFound=y myVar:mySubnetId Equals
PreAuth:$STARENT:3GPP2-Subnet CDMA2000LocalAA
service=PFD-V2-ST-SP
- - - SendReject replyMessage="Not in Zone1"
2 Provision the 3GPP2-Subnet Sector ID in a RADIUS Connection Service
Profile.
When provisioning the 3GPP2-Subnet Sector ID in Service Manager the format
must be the same as that expected in the Access-Request.
— For example if the 3GPP2-Subnet string in the Access-Request message is
011368008E7E039FA1F501AC1D8D3E520000000212008E7E039FA1F50
1, the RADIUS Server extracts the Sector ID value 39FA1F501, and
matches the extracted value with the value provisioned in Service Manager.
— In this case, provision the 3GPP2-Subnet Sector ID in Service Manager as
39FA1F501.
3 Assign the RADIUS Connection Service Profile from step 2 to a user profile set.
For more information about configuring a RADIUS Connection Service Profile
and a user profile set, see:
– the chapter “Managing service profiles” in the Service Manager: Subscriber
Provisioning Guide for AAA
– the chapter “RADIUS connection service” in the Service Manager: Services
Provisioning Guide for AAA.

Page 330 October 12, 2012 Service Controller 9.6.1-AAA


Configuring proxy targets and proxy

8
Chapter 8
Chapter

target groups

This chapter describes proxy targets, proxy target groups, and how to configure
them.
The topics are:
• Proxy overview
• Attribute filters
• Proxy configuration file
• Proxy target configuration considerations
• Filter examples
• Proxy target server and group examples
• Manually locking and unlocking a proxy target
• Configuring attribute manipulation

Service Controller 9.6.1-AAA October 12, 2012 Page 331


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Proxy overview
Proxy targets and proxy target groups are defined within RADIUS [Link] or by
provisioning RADIUS Servers and RADIUS Server groups using the Service
Manager. For proxy targets or groups that are RADIUS servers, you can configure
attribute filters to control which attributes of an outgoing request are proxied to a
remote server and which attributes of the incoming response are returned to the
client.
Note Configure RADIUS Servers, RADIUS Server Groups, proxy filters, proxy
override attribute groups, and proxy required attribute groups using either
the [Link] file or the Service Manager. Both methods cannot be used.
After purchasing the BWSoaaapdb Proxy Database Configuration optionality
package, see the section “Managing proxy targets and filters” in the chapter
“Managing Systems” in the Service Manager: Network Access Guide for AAA to
find more information about provisioning proxy targets and proxy filters using the
Service Manager.
Note Before configuring proxy deployments using the Service Manager, set the
ReadProxyConfigFromDB attribute in the [Link] file to ‘Y’.

Proxy targets
Valid proxy targets are RADIUS servers, LDAP servers, and SecurID servers. For
each proxy target, you define connectivity parameters and the conditions under
which the server is marked as inactive or unreachable based on the number of
consecutive failed retries or the number of failed retries in a configurable time
period. For more information, see "Manually locking and unlocking a proxy target"
on page 379.
When a proxy target is locked out due to intermittent failure, it is only reflected in the
MIB variables when the next Access-Request is received after the lockout state
change occurs.
For manual proxy target lockouts, the RadiusClientGroupUnlockedTargets metric is
not updated until the Access-Request is received. This same behavior occurs when
a proxy target is manually unlocked.
Both situations are only noticeable under very light or sporadic load.
Note If RADIUS receives a HUP signal, it resets all knowledge of the consecutive
or intermittent failure events that determine whether a proxy target should
be locked.
The proxy target element and attributes are described in "RADIUSServer" on page
352. For example proxy target element definitions, see "Proxy target server and
group examples" on page 376.
For information about provisioning proxy targets and groups using the Service
Manager, see the chapter “Managing proxy targets and filters” in the Service
Manager: Network Access Guide for AAA.

Page 332 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Proxy target groups


For each proxy target group entry, list the proxy targets in the group. Valid proxy
target groups are RADIUS server groups, LDAP server groups, and SecurID server
groups.
Make sure to define the parameters for each proxy target before defining the proxy
target groups in [Link] file. Otherwise, [Link] fails to load.
By enabling failover for a proxy target group, if the connection to one server times
out before a response is received, the RADIUS Server sends the request to another
server. Apply round-robin load-sharing to distribute authentication and accounting
requests evenly across the proxy targets in the proxy target group.
When load-sharing is enabled, each of the Access-Request, the Accounting-Start,
and the Accounting-Stop messages are distributed to the next available proxy
target in the group. The target to which the message is sent depends on which
target is available next in the load-sharing cycle.
Enable dynamic unlocking for the proxy target group so that if all proxy targets
within the group are locked, the target with which the RADIUS Server can
successfully communicate is automatically unlocked. Alternatively, set the
maximum number of concurrent lockouts for the group to a number less than the
total number of targets in the proxy target group.
The proxy target group elements and attributes are described in:
• "RADIUSServer Group" on page 358
• "SecurIDServer Group" on page 364
• "LDAPServerGroup" on page 368
For example proxy target element definitions, see "Proxy target server and group
examples" on page 376.
For information about provisioning proxy target groups using the Service Manager,
see the chapter “Managing proxy targets and filters” in the Service Manager:
Network Access Guide for AAA.

Service Controller 9.6.1-AAA October 12, 2012 Page 333


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Attribute filters
On RADIUS targets and target groups, define filters in [Link] to modify
attributes in the outgoing and incoming proxy messages, for example, to remove
unwanted or unsupported attributes.
As shown in Figure 33, the attribute filters can be applied to proxy requests or proxy
responses or both, and can be defined on the proxy targets or proxy target groups.
Figure 33: Attribute filtering flow

2XW$FWLRQ
&OLHQW )LOWHUDWWULEXWHVLQ 3UR[\
UHTXHVW DXWKHQWLFDWLRQDQG UHTXHVW
DFFRXQWLQJPHVVDJHV

5$',86 3UR[\
&OLHQW
6HUYHU 7DUJHW

,Q$FWLRQ
&OLHQW )LOWHUDWWULEXWHVLQ 3UR[\
UHVSRQVH DXWKHQWLFDWLRQ UHVSRQVH
PHVVDJHV

The core element of a filter is one or more attribute value pairs that are allowed,
denied, or modified in the message. When specifying an attribute value pair, the
name of the attribute must match the name in the vendor dictionary. A filter cannot
contain multiple entries for the same attribute.
An attribute value pair can include subtypes but only if the filter is configured using
[Link]. Filtering based on AVP subtypes is not supported in Service Manager.
In many scenarios, multiple filters on different attributes are required to accomplish
a goal. For example, to properly deny login services, a network administrator would
define a filter to prevent the remote server setting the Service-Type attribute to
“Login”, as well as filters to deny the Login-IP-Host, Login-TCP-Port, and
Login-Service attributes.
Note If a filter is defined on both a proxy server and a proxy group containing the
same server and messages are directed to the proxy group, the filter
provisioned on the group overrides the filter provisioned on the individual
target. This precedence applies to the entire filter, not to the individual
attributes.

Page 334 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Filtering using [Link]


Use the Filter element in [Link] to filter attributes. For information, see "Filter"
on page 339.
For examples of filter definitions, see "Filter examples" on page 372.
Note Filtering based on AVP subtypes is only supported in [Link], not in
Service Manager.

Filtering using Service Manager


After an attribute is added at a higher context in the service profile in the Service
Manager and then deleted (which marks the attribute with REMOVED status),
RADIUS does not add the attribute to response messages.
For information about provisioning filter attributes using the Service Manager, see
the section “Managing proxy targets and filters” Service Manager: Network Access
Guide for AAA.
Note Filtering attributes based on AVP subtypes is only supported in [Link]
not in the Service Manager.

Proxy request filters


Proxy request filters define which attributes must be present, be replaced, or be
removed in outgoing messages sent to a proxy target server or group. The filtering
is performed against an Access-Request or Accounting-Request from the client.
Proxy request filters
• are defined using the OutAction element with a filter
• apply to all requests sent to the remote proxy server or group on which they are
defined
• can apply to authentication and accounting messages
• are applied in the following order:
– list of required attributes
– outgoing filter(s)
– list of override attributes
• only one proxy request filter of each type (acct or auth) can be specified per
RADIUS server or RADIUS server group

Service Controller 9.6.1-AAA October 12, 2012 Page 335


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Proxy response filters


Proxy response filters define which attributes must be passed along or removed in
incoming messages received from a proxy target server or group.
Proxy response filters
• are defined using the InAction element with a filter
• apply to all responses received from the remote proxy server or group on which
they are defined
• apply only to authentication messages
• only one proxy response filter can be specified per RADIUS server or RADIUS
server group
The filter element and attributes are described in "Filter" on page 339.
For examples of filter definitions, see "Filter examples" on page 372.
For information about provisioning proxy filters using the Service Manager, see the
section “Managing proxy targets and filters” in the Service Manager: Network
Access Guide for AAA.

Page 336 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Proxy configuration file


The proxies file, located in /opt/aaasc/config/radius/[Link], contains an entry
for each proxy target, proxy target group, and attribute filter configured on the local
RADIUS Server. The DTD is embedded in the [Link] file.
Note Use the [Link] file to manage proxy targets, groups, and filters in the
network, or the Service Manager, not both. For information about
provisioning proxy targets, groups, and filters using the Service Manager,
see the Service Manager: Network Access Guide for AAA.

[Link] schema
The [Link] schema contains these elements:
ProxyTarget Configuration: The root element
Filter
AVP
ExceptionVal
ExceptionRange
ExceptionRegExp
OverrideAttribute
Override
DataValue
AttributeValue
RegExValue
Condition
Matches
AttributeValue
DataValue
RegExValue
Required Attributes
Reqd
RADIUSServer
InAction
OutAction
RADIUSServer Group
SecurIDServer
SecurIDServer Group
LDAPServer
ServiceAVP
LDAPServerGroup
ServiceAVP

Service Controller 9.6.1-AAA October 12, 2012 Page 337


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

ProxyTarget The root element that encloses:


Configuration • optional Filter elements
• one or more OverrideAttribute and/or Required Attributes elements
• one or more proxy target (RADIUSServer, SecurIDServer, or LDAPServer) or
proxy target group (RADIUSServer Group, SecurIDServer Group, or
LDAPServerGroup) elements

Table 107: ProxyTargetConfiguration attributes

Attribute Value Description

ProxyTimeout Integer The time RADIUS waits for a proxy response is:
Factor (1–100) RequestTimeout / ProxyTimeoutFactor.
Default=1 Used only by the RADIUSServer element to provide finer grain
timeout values for both authentication and accounting requests.
Optional.

ReadProxyTarget • Y Determines whether the RADIUS Server reads proxy


ConfigFromDB • N (Default) configuration from the database or the [Link] file.
• N: configure proxy deployments using the [Link] file only.
• Y: configure proxy deployments using the Service Manager.
Note Provision proxy entities with the Service Manager, or using
the [Link] file.
Note Proxy deployments with Service Manager are only
available to customers who have purchased the Proxy
Database Configuration package.
Only for RADIUS Servers in a non-LDAP environment.
For more information, see "Configuring attribute manipulation" on
page 379.
Optional.

Page 338 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Filter Defines which attribute values are sent or returned in a proxied message. A Filter
may be applied to an InAction or OutAction proxy attribute filter child element within
a RADIUSServer or RADIUSServerGroup element.
• The Filter element may enclose one or more AVP child element.
• The filter cannot contain multiple entries of the same AVP.
Child element of ProxyTarget Configuration.
For example:
<Filter FilterName="AuthFilter" Action="Deny">
<AVP AttrName="Framed-Pool" Action="Deny"/>
<AVP AttrName="Framed-IP-Address" Action="Allow">
<ExceptionRegExp Pattern="255\.255\.255\.(.*)"/>
</AVP>
<AVP Attrname=”WiMAX-QoS-Descriptor:Schedule-Type” Action=”Allow”>
<ExceptionVal Value=”4”/>
</AVP>
</Filter>

Table 108: Filter attributes

Attribute Value Description

FilterName • String Unique name of the filter.


(1–256 characters)

Action • Allow Default action of the proxy filter.


• Deny • Deny: silently discard all attribute whose filter action is not
explicitly defined in an AVP element.
• Allow: pass all attributes whose filter action is not explicitly
defined in an AVP element.
Required.

AVP Defines Attribute Value Pair (AVP) and subtype values to include in the
RADIUSServer or RADIUSServerGroup filter.
Considerations:
• in each filter, there cannot be multiple entries of the same AVP.
• AVPs with cannot have separate entries for the AVP and for its subtypes. There
must be either one entry for the AVP, or entries for the AVP subtypes.
• the AVP element can enclose zero or more ExceptionVal, ExceptionRange,
and/or ExceptionRegExp child elements.
• AVPs with subtypes cannot specify ExceptionVal, ExceptionRange, and
ExceptionRegExp against the AVP. AVPs with subtypes can only specify the
exceptions against the subtypes.
• Actions specified for a subtype of an AVP apply against the AVP itself
Child element of Filter.

Service Controller 9.6.1-AAA October 12, 2012 Page 339


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Example filter
The following example includes:
• an AVP (AttrName1)
• an AVP with two subtypes (AttrName2)
<Filter FilterName="Filter1" Action="Deny">
<AVP AttrName="AttrName1" Action="Deny"/>
<AVP AttrName="AttrName2:Subtype1" Action="Allow">
<ExceptionRegExp Value="255\.255\.255\.(.*)"/>
</AVP>
<AVP AttrName="AttrName2:Subtype2" Action="Allow">
<ExceptionRange Start="1" End="4"/>
</AVP>
</Filter>
For more examples of filter configurations, see "Filter examples" on page 372.

Table 109: AVP attributes

Attribute Value Description

Action • Allow Action at the AVP attribute or subtype level, which takes
• Deny precedence over the action at the filter level.
The AVP action is taken when no exception criteria are explicitly
met for the value of the attribute or subtype.
Required.

AttrName • String The name of the attribute to be added to the proxy request.
(1–256 characters) For AVPs with subtypes you can also specify the subtype as part
Format: String[:String …] of the AttrName and can filter AVPs based on their subtypes.
• attributes are delimited from subtypes by a colon
• you can apply exceptions to AVP subtypes
• you can specify a sub-subtype
Example formats:
<AVP AttrName="AttrName1 Action="Allow/>
<AVP AttrName="AttrName1:Subtype" Action="Allow/>
Required.

VendorName • String The *.DICT file that contains the attribute’s definition.
(1–256 characters) Only used if the attribute is vendor-specific.
Default=RFC2138 Not required for RFC attributes or for subtypes.
Optional.

Page 340 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

ExceptionVal A value that is an exception to the action specified in the AVP element. Exceptions
are supported for attributes and subtypes.
AVPs with subtypes cannot specify ExceptionVal against the AVP. AVPs with
subtypes can only specify the ExceptionVal against the subtypes.
Child element of AVP.
Example:
<AVP AttrName="Service-Type" Action="Allow">
<ExceptionVal Value="1" />
</AVP>
<AVP AttrName="Callback-Id" Action="Allow">
<ExceptionVal Value="123456789" />
</AVP>
<AVP Attrname=”WiMAX-QoS-Descriptor:Schedule-Type” Action=”Deny”>
<ExceptionVal Value=”4”/>
</AVP>

Table 110: ExceptionVal attributes

Attribute Value Description

Value • Integer (1–65535) A discrete value for the attribute or subtype.


• String (1–256 characters) The attribute or subtype must have this value to be exempt from
• IPv4 address (dot notation the action specified in the AVP element.
format)
Required.
• IPv6 address (dot notation
format)

ExceptionRange A value range that is an exception to the action specified in the AVP element.
AVPs with subtypes cannot specify ExceptionRange against the AVP. AVPs with
subtypes can only specify the ExceptionRange against the subtypes.
Child element of AVP.
Example:
<AVP AttrName="Service-Type" Action="Deny">
<ExceptionRange Start="1" End="4"/>
<ExceptionVal Value="6" />
</AVP>
<AVP Attrname=”WiMAX-QoS-Descriptor:Schedule-Type” Action=”Deny”>
<ExceptionRange Start="1" End="4"/>

Service Controller 9.6.1-AAA October 12, 2012 Page 341


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

</AVP>

Table 111: ExceptionRange attributes

Attribute Value Description

Start • Integer (1–65535) A starting value for a range (inclusive).


• IPv4 address Required.

End • Integer (1–65535) An ending value for a range (inclusive).


• IPv4 address Required.

ExceptionRegExp A regular expression that is an exception to the action specified in the AVP element.
AVPs with subtypes cannot specify ExceptionRegExp against the AVP. AVPs with
subtypes can only specify the ExceptionRegExp against the subtypes.
Child element of AVP.
Example:
<AVP AttrName="SSG-Service-Info" VendorName="CISCO" Action="Deny">
<ExceptionVal Value="Prepaid" />
<ExceptionRegExp Value="DATA|MMS|WAP"/>
</AVP>
<AVP Attrname=”WiMAX-QoS-Descriptor:Schedule-Type” Action=”Deny”>
<ExceptionRegExp Value="DATA|MMS|WAP"/>
</AVP>

Table 112: ExceptionRegExp attributes

Attribute Value Description

Value • String A regular expression. Used to evaluate against an attribute or


(1–256 characters) subtype value to determine whether it is exempt from the action
specified in the AVP element.
Required.

OverrideAttribute A list of attributes that are overwritten/added to a RADIUS message.


OverrideAttributes encloses one or more Override child elements.
Child element of ProxyTarget Configuration.
Considerations:
• If the Class or Proxy-State attributes are specified as OverrideAttribute entries
in a proxy filter, the RADIUS Server adds their values to the reply packet even if
the attributes are already present with different values.
This allows the RADIUS Server to inject a new value but maintain the values
sent by the proxy target in accordance with RFC 2865.

Page 342 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

• If the RADIUS Server injects the Class or Proxy-State attributes in the reply
packet, the RADIUS Server marks these attributes as local data so that they
are not proxied to remote servers in subsequent messages.
• If the State attribute is specified as an OverrideAttribute in a proxy filter, the
RADIUS Server only adds its value to the reply packet if there is no State
attribute already present.
Example:
<OverrideAttributes Name="Assign">
<Override
AttrName="Ascend-Primary-Dns"
VendorName="Ascend"
Precedence="Filter"
Mandatory="Y">
<AttributeValue
AttrName="Unisphere-Primary-Dns"
VendorName="Juniper"/>
</Override>
</OverrideAttributes>

Table 113: OverrideAttributes attributes

Element or
Value Description
Attribute

Name • String (1–256 characters) The name of the element.


• The name must start with a Required.
letter (a-z, A-Z)
• Periods are permitted after the
first character
• Special characters and spaces
are not permitted

Override An attribute to add or to replace. The Override element can be a combination of


static values or the value of other RADIUS attributes. The Override element
encloses one or more of the following child elements:
• DataValue
• AttributeValue
• RegExValue
• Condition
Child element of OverrideAttribute.
Basic example:
<Override
AttrName="Framed-Pool"
Precedence="Filter"

Service Controller 9.6.1-AAA October 12, 2012 Page 343


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Mandatory="Y">
<Condition>
<Matches.../>
</Condition>
Complex example:
• A proxy request contains a NAS-IP-Address attribute with the value
[Link] and an Acct-Session-Id attribute with the value of
abcdef01234567890.
• When the request is proxied through a target assigned with the overrides
shown in the following example, the value of the outgoing Acct-Session-Id is:
3232274276[]abcdef01234567890.
<OverrideAttributes Name="Acct_Session_Id">
<Override
AttrName="Acct-Session-Id"
Precedence="Filter"
Mandatory="Y">
<AttributeValue
AttrName="NAS-IP-Address"
From="ProxyRequest"
Type="String"/>
<DataValue Type="String">[]</DataValue>
<AttributeValue
AttrName="Acct-Session-Id"
From="ProxyRequest"/>
</Override>
</OverrideAttributes>
Note The final value of an Override XML element cannot exceed the following
maximum lengths:
string — 253 bytes
integer — 4 bytes
ipv4addr — 4 bytes
ipv6addr — 16 bytes

Table 114: Override attributes

Attribute Value Description

AttrName • String The name of the attribute value pair (AVP) to be added/modified
(1–256 characters) to the proxy message.
Required.

Page 344 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Table 114: Override attributes (continued)

Attribute Value Description

VendorName • String The vendor name associated with the AVP.


(1–256 characters) Identifies the *.DICT file that contains the attribute’s definition.
Default=RFC2138 Only used if the attribute is vendor-specific.
Not required for RFC attributes.
Optional.

Precedence • Filter Determines whether or not to replace the original attribute value.
• Packet Only applies to override attributes that exist in the client request.
Default=Filter Values:
• Filter: the override value replaces the attribute value in the
request and is sent to the proxy target
• Packet: the original attribute in the client request is unchanged
and is sent to the proxy target
Precedence does not apply if the attribute is not in the original
message.
Optional.

Mandatory • Y (Default) Determines the behavior of the override if the attribute does not
• N exist in the original packet or has been filtered out by the Proxy
Filter:
• Y: insert the attribute AttrName into the request to the proxy
target (use the DataValue, AttributeValue, RegExValue, or
Condition child elements to provide a value)
• N: do not insert the attribute into the request
Optional.

DataValue Assigns a static value.


Child element of Override.
Examples
Define an IPv4 address:
<Override
AttrName="Framed-IP-Address">
<DataValue Type="IPv4">[Link]</DataValue>
</Override>
Define a string:
<DataValue Type="string">[Link]</DataValue>
Define a binary value:

Service Controller 9.6.1-AAA October 12, 2012 Page 345


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

<DataValue Type="Binary">0123456789ABCDEF</DataValue>
Note The characters “&”, “<“, and “>” are illegal in XML syntax. To define a string
override with any of these values, use “&#38;”, “&#60;“, and “&#62;” without
quotes.

Table 115: DataValue attributes

Attribute Value Description

Type • Integer (4 byte integer) Interpret this attribute as the specified type, such as String.
• String (ASCII) Allows the flexibility to convert integer attributes to strings and
• IPv4 (4 byte integer) string attributes to integer.
• IPv6 (16 byte integer)
Required.
• Binary (ASCII-Hex)
No default value

AttributeValue Assigns the value of another RADIUS attribute.


Child element Override.
Example:
<AttributeValue
AttrName="NAS-IP-Address"
From="ProxyRequest"
Type="IPv4"/>

Table 116: AttributeValue attributes

Attribute Value Description

AttrName • String The name of the AVP (as it appears in the dictionary for the
(1–256 characters) specified vendor) whose value is used as an override.
Required.

VendorName • String The *.DICT file that contains the attribute’s definition.
(1–256 characters) Only used if the attribute is vendor-specific.
Default=RFC2138 Not required for RFC attributes.
Optional.

Type • Integer (4 byte integer value) Interpret this attribute as the specified type, such as String.
• String (ACSCII) Allows the flexibility to convert integer attributes to strings and
• IPv4 in dot notation format string attributes to integer.
• IPv6 in dot notation format If a type is not specified, the default type is taken from the
• Binary (ASCII-Hex) RADIUS dictionary.
Optional.

Page 346 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Table 116: AttributeValue attributes (continued)

Attribute Value Description

From • ProxyRequest Identifies which RADIUS packet contains the attribute whose
• ProxyResponse (default) value must be replaced.
ProxyRequest — the packet received from the RADIUS client.
ProxyResponse — the packet received from the proxy server.
Optional.

RegExValue A pattern and a corresponding replacement string that is applied to a RADIUS


attribute. The replacement string is used to override the value of the RADIUS
attribute defined in the parent Override element.
Child element of Override and Matches.
For changing the case of attributes to lower or upper case, RegExValue supports
the {strtolower} and {strtoupper} functions.
• Only one of {strtolower} or {strtoupper} can be present and must be placed at
the beginning of the replacement string.
– {strtolower} - the replacement string is generated in lower case
– {strtoupper} - the replacement string is generated in upper case
• The RegExValue element in the Matches section of [Link] does not
support the {strtolower} and {strtoupper} functions.
For more information about manipulating the case of attributes, see
"Manipulating the case of attributes in the [Link] file" on page 394.

RegExValue examples
Treat the value of the Framed-IP-Address attribute as an IPv4 string and re-arrange
the octets ([Link] ' [Link]):
<RegExValue
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="(\d{1,3})\.(\d{1,3})\.(\d{1,3})\.(\d{1,3})">
${4}\.${3}\.${2}\.${1}
</RegExValue>
Extract the login-name portion of the User-Name attribute:
<RegExValue
AttrName="User-Name "
StringFormat="String"
Pattern="(([^\\]*)\\){0,1}([^@]*)(@(.*)){0,1}">
${3}
</RegExValue>

Service Controller 9.6.1-AAA October 12, 2012 Page 347


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Change the case of the Calling-Station-Id to lower case, insert colons between
octets, and override the value of the User-Name attribute with the re-formatted
value of Calling-Station-Id:
<OverrideAttributes Name="Renaming">
<Override AttrName="User-Name">
<RegExValue AttrName="Calling-Station-Id" StringFormat="String"
Pattern="(.{2})(.{2})(.{2})(.{2})(.{2})(.{2})">
{strtolower}${1}:${2}:${3}:${4}:${5}:${6}
</RegExValue>
</Override>
</OverrideAttributes>

Table 117: RegExValue attributes

Attribute Value Description

AttrName • String The name of the AVP (as it appears in the dictionary for the
(1–256 characters) specified vendor) whose value is applied to the regular
expression’s Pattern modifier.
Required.

VendorName • String The *.DICT file that contains the attribute’s definition.
(1–256 characters) Only used if the attribute is vendor-specific.
Default=RFC2138 Not required for RFC attributes.
Optional.

StringFormat • Integer (treated as a 4 byte The format that is used to interpret the Pattern modifier.
integer, then converted to an Integer — treat the value of the attribute identified by the
ASCII string) AttrName XML attribute as a string of ASCII numbers.
• String (ASCII)
String — treat the value of the attribute identified by the AttrName
• IPv4 (treated as a 4 byte
XML attribute as ASCII.
integer, then converted to an
IP address in dot notation) IPv4 — treat the value of the attribute identified by the AttrName
• IPv6 (treated as a 16 byte XML attribute as a string in IPv4 dot notation
binary string, then converted IPv6 — treat the value of the attribute identified by the AttrName
to an IP address in dot XML attribute as a string in IPv6 dot notation.
notation) BinaryHex — treat the value of the attribute identified by the
• BinaryHex (treated as a binary AttrName XML attribute as ASCII-hex encoded.
string, then converted to
ASCII-Hex) Required.

From • ProxyRequest Which RADIUS packet contains the attribute identified by the
• ProxyResponse (Default) AttrName XML attribute.
Optional.

Pattern • A regular expression APOSIX regular expression (man -s5 regex) that is applied to the
value of the AVP (identified by the AttrName modifier).
Required.

Page 348 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Condition Assigns override values. Similar to an if/else construct, each child element defines
a logical expression that, if satisfied, provides a value to override the original value.
If the logical expression is not satisfied, the next logical expression is evaluated. If
no logical expression can be satisfied, the condition has no value. Logical
expressions are defined using the Matches element.
The Condition element encloses one or more Matches elements.
Child element of Override.
Example:
<Override
AttrName="Framed-Pool"
Precedence="Filter"
Mandatory="Y">
<Condition>
<Matches.../>
</Condition>
</Override>
The <Condition> element has no modifying attributes.

Matches A condition which requires a RADIUS attribute value to match a specified pattern. If
the condition is satisfied, the value of the Matches element overrides the RADIUS
attribute value defined by the parent Override element.
The Matches element encloses one or more of the following child elements:
AttributeValue, DataValue, and/or RegExValue. For more information about these
child elements, see "AttributeValue" on page 346, "DataValue" on page 345, and
"RegExValue" on page 347.
Child element of Condition.
Simple match condition example:
If the value of the Framed-IP-Address (interpreted as IPv4 dot notation string
format) equals [Link], then the value of the condition is "pool_254":
<Condition>
<Matches
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="[Link]">
<DataValue Type="String">pool_254</DataValue>
</Matches>
</Condition>

Service Controller 9.6.1-AAA October 12, 2012 Page 349


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Concatenating values of the child elements


If the value of the RADIUS attribute defined by the AttrName attribute matches the
pattern defined by the Pattern attribute, and the value of the Matches element
contains one or more instances of an AttributeValue, DataValue, and/or
RegExValue XML child element, the RADIUS Server resolves the values of each
child element, then concatenates them (in the order they are defined) to form the
override value of the RADIUS attribute defined by the parent Override element.
For example, if a proxy request contains a NAS-IP-Address attribute with the value
[Link] and an Acct-Session-Id attribute with the value
abcdef01234567890, when the request is proxied through a target assigned with
the overrides shown in the following example, the value of the outgoing
Acct-Session-Id is: 3232274276[]abcdef01234567890.
Note If the concatenated value exceeds the maximum length of the override
attribute, the RADIUS Server writes a notice level log and issues a 60
second throttle.
Concatenation example:
<OverrideAttributes Name="Acct_Session_Id">
<Override
AttrName="Acct-Session-Id"
Precedence="Filter"
Mandatory="Y">
<AttributeValue
AttrName="NAS-IP-Address"
From="ProxyRequest"
Type="String"/>
<DataValue Type="String">[]</DataValue>
<AttributeValue
AttrName="Acct-Session-Id"
From="ProxyRequest"/>
</Override>
</OverrideAttributes>

Table 118: Matches attributes

Attribute Value Description

AttrName • String The name of the AVP (as it appears in the dictionary for the
(1–256 characters) specified vendor) whose value is applied to the regular
expression’s Pattern modifier.
Required.

VendorName • String The *.DICT file that contains the attribute’s definition.
(1–256 characters) Only used if the attribute is vendor-specific.
Default=RFC2138 Not required for RFC attributes.
Optional.

Page 350 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Table 118: Matches attributes (continued)

Attribute Value Description

StringFormat • Integer The format that is used to interpret the Pattern modifier.
• String Values:
• IPv4
• Integer: treat the value of the attribute identified by the
• IPv6
AttrName XML attribute as a string of ASCII numbers.
• BinaryHex
• String: treat the value of the attribute identified by the
AttrName XML attribute as ASCII.
• IPv4: treat the value of the attribute identified by the AttrName
XML attribute as a string in IPv4 dot notation
• IPv6: treat the value of the attribute identified by the AttrName
XML attribute as a string in IPv6 dot notation.
• BinaryHex: treat the value of the attribute identified by the
AttrName XML attribute as ASCII-hex encoded.
Required.

From • ProxyRequest Which RADIUS packet contains the attribute identified by the
• ProxyResponse (Default) AttrName XML attribute.
Optional.

Pattern • A regular expression A POSIX regular expression (man -s5 regex) that is applied to the
value of the AVP (identified by the AttrName modifier).
Required.

Required Attributes A list of AVPs that must exist in a RADIUS message. If one or more attributes do
not exist, the message is rejected (for an Access-Request message) or discarded
(for Accounting and DAE messages).
The RequiredAttributes element encloses one or more Reqd child elements.
Child element of ProxyTarget Configuration.
Example:
<RequiredAttributes Name="Acct_Session_Id">
<Reqd AttrName="Acct-Session-Id"/>
<Reqd AttrName="NAS-IP-Address"/>
</RequiredAttributes>

Table 119: RequiredAttributes attributes

Attribute Value Description

Name • String (1–256 characters) The list name for the AVPs that are required in the RADIUS message.
• The name must start with a Required.
letter (a-z, A-Z)
• Periods are permitted after the
first character
• Special characters and spaces
are not permitted

Service Controller 9.6.1-AAA October 12, 2012 Page 351


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Reqd An RFC or vendor-specific attribute that must exist in a RADIUS message.


Reqd has no child elements.
Child element of Required Attributes.
Example:
<RequiredAttributes Name="Required1">
<Reqd AttrName="User-Name"/>
<Reqd AttrName="User-Password"/>
</RequiredAttributes>

<RequiredAttributes Name="Required2">
<Reqd AttrName="Acct-Status-Type"/>
</RequiredAttributes>

Table 120: Reqd attributes

Attribute Value Description

AttrName • String The AVP that is required in the RADIUS message.


(1–256 characters) Required.

VendorName • String The *.DICT file that contains the attribute’s definition.
(1–256 characters) Only used if the attribute is vendor-specific.
Default=RFC2138 Not required for RFC attributes.
Optional.

RADIUSServer A RADIUS proxy server and optional incoming or outgoing actions that it takes on
RADIUS messages. Each ProxyTargetConfiguration root element must enclose at
least one proxy target server (RADIUSServer, SecurIDServer, or LDAPServer) or
proxy target group (RADIUSServer Group, SecurIDServer Group, or
LDAPServerGroup) element.
Note Behaviour defined at the RADIUSServerGroup level takes precedence over
behaviour defined at the RADIUSServer level.
The RADIUSServer element encloses an optional InAction and an optional
OutAction child element.
Child element of ProxyTarget Configuration.
Example:
<RADIUSServer
TargetName="FilteredRadiusServer"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="2"
AccountingPort="1813"
AuthenticationPort="1812"

Page 352 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

BindLocalIP=”[Link]”>
<InAction Filter="InFilter" />
<OutAction
Type="Auth"
Filter="GenericFilter"
OverrideAttributes="Override1"
RequiredAttributes="Required1"/>
<OutAction
Type="Acct"
Filter="AcctFilter"
RequiredAttributes="Required2">
</OutAction>
</RADIUSServer>

Table 121: RADIUSServer attributes

Attribute Value Description

Proxy target attributes

TargetName • String (1–256 characters) A unique identifier for the proxy target.
• Spaces are not supported Required.

TargetHost • DNS hostname IP address or DNS hostname of the proxy target.


• IP address (dot notation Required.
format)

DAEPort • Integer The port of the server to which CoA or DM messages are
Default = 3799 proxied.
Optional.

Secret • String (1–256 characters) Shared secret used when communicating with the target server.
Not used for LDAPServer elements.
Required for RADIUSServer and SecurIDServer elements.

RequestTimeout • Integer (1–65535) The maximum time, in seconds, that the RADIUS Server waits
for a response from the proxy target before it sends the request
to an alternate proxy server in the group or deals with the request
as defined in the policy rules.
WARNING: Failure to coordinate these parameters may result in
severe degradation of RADIUS performance.
For more information, see "RequestTimeout" on page 370.
Required.

AccountingPort • N (not set; default) UDP Port of the proxy target for accounting. The RFC standard
• Integer (1–65535) port for accounting is 1813.
Define either AccountingPort or AuthenticationPort.
Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 353


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Table 121: RADIUSServer attributes (continued)

Attribute Value Description

AuthenticationPort • N (not set; default) UDP port of the proxy target for authentication. The RFC
• Integer (1–65535) standard port for authentication is 1812.
Define either AccountingPort or AuthenticationPort.
Optional.

AttributeEncryption • none (Default) Specifies whether all RADIUS attributes in the messages sent to
• RFCMD5 the proxy target are encrypted. Both authentication and
accounting message attributes are encrypted.
Both the proxy and the target servers must be Bridgewater
RADIUS Servers installed with a release that supports the
attribute encryption feature. Otherwise, the originating proxy
server may not get a response or may get an Access-Reject
message.
Performance degradation with the attribute encryption feature
enabled is expected. For details, see the engineering
requirements in the Bridgewater Installation Reference Guide.
Optional.

BindLocalIP • IP address (dot notation The local IP address to bind when sending proxy requests. Use
format) this parameter for systems with multiple network interfaces.
Default=local host IP address If this parameter is not configured, only one proxy thread is
created and listens on the primary IP address. A separate proxy
thread is created for each IP address specified.
For multi-homed boxes, the primary IP address is the default.
Only one IP address can be specified and this parameter can
only be used once per RADIUSServer entry. However, each
RADIUSServer entry can specify a different BindLocalIP in the
case of a multi-homed system.
For each different specified bind IP address, a separate
dedicated proxy receiver thread is created by RADIUS to handle
responses and timeouts for the IP address.
Optional.

Consecutive Failure Lockout attributes (For examples, see "Consecutive failure lockout" on page 371.

Consecutive • Y Enables or disables consecutive lockout. Set to Y to enable


LockoutEnabled • N (default) consecutive lockout.
Optional.

ConsecutiveFailure • Integer (1–65535) The time, in seconds, that a proxy target is locked out due to
LockoutDuration • Indefinite consecutive retry cycle failures.
Default=900 If this parameter is set to “Indefinite”, the proxy target is not
considered for service until it is manually unlocked by an
operator.
Optional.

Page 354 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Table 121: RADIUSServer attributes (continued)

Attribute Value Description

ConsecutiveRetry • N (not set) The maximum number of consecutive retry failures before
Cycles • Integer (1–65535) lockout of the proxy target occurs.
Required for RADIUSServer elements only if
ConsecutiveLockoutEnabled is configured.

Intermittent Failure Lockout attributes (For examples, see "Intermittent failure lockout" on page 371.

IntermittentFailure • Y Enables or disables intermittent lockout for the proxy target.


Lockout • N (Default) Intermittent lockout covers the situation where a server is partially
Enabled failing, possibly due to an unreliable network or a failure in a
proxy chaining scenario.
Optional.

IntermittentFailure • Integer (1–65535) The time, in seconds, over which request failure and success are
Interval Default=900 tracked.
Length Optional.

IntermittentFailure • N (not set) The time, in seconds, during which the proxy is not available due
Lockout • Integer (1–65535) to consecutive retry failures.
Duration Default=900 Setting this parameter to ‘Indefinite’ prevents the proxy target
from being considered for service until it is manually unlocked by
an operator.
The only exception is if all proxy targets are locked and Dynamic
Unlock is enabled for the proxy target group.
Optional.

IntermittentFailure • Integer The minimum number of requests within an interval for it to be


MinimumRequests (1–65535) considered valid.
Default=1 Optional.

IntermittentFailure • Integer The number of failed requests, specified as a percentage,


PercentageFailure (1–65535) required for the interval to be considered ‘failed’.
Threshold Optional.
Default=100

IntermittentFailure • Integer The number of successive failed intervals before a proxy target
SuccessiveFailed (1–65535) lockout occurs.
Intervals Optional.
Default=1

Additional attributes

MaxRetries • Integer The number of retry attempts per request before failing over or
(1–65535) rejecting the request.
Default=0 If this parameter is not set, there are no retries for that proxy
target.
Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 355


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Table 121: RADIUSServer attributes (continued)

Attribute Value Description

OverwriteIP • Y (Default) A static IP address in a proxy authentication reply is replaced by


• N an IP address assigned by the RADIUS Server or left as is.
Set to Y to overwrite the IP address. Set to N to accept the IP
address in the proxy reply.
Note IP address replacement is performed after any incoming
proxy filters are applied. The use of the OverwriteIP
interferes with the Framed-IP exception values set in the
InAction filters.
Optional.

StripDomain • Y Set to Y for the RADIUS Server to remove the domain from the
• N (Default) login name when forwarding an Access-Request.
This removes any domain, including a domain appended or
replaced by a RADIUS policy rule.
The domain is still used for local authorization and is stored in
local accounting records.
Optional.

DigitizeAcct • Y Convert characters to digits in the Accounting Session ID


SessionId • N (Default) attribute when forwarding to the proxy target.
Optional.

AddMessage • Y Insert the RADIUS Message-Authenticator attribute into requests


Authenticator • N (Default) sent to this target.
If the attribute is already present in the client request, then this
flag has no effect as it is automatically inserted into the proxy
request.
Adding this attribute provides anti-spoofing protection to requests
as some remote servers may require protection.
Note This parameter is configurable at both the TargetName and
GroupName levels. Specifying this at the GroupName level
overrides the values specified on each TargetName.
Optional.

InAction A set of actions to apply to attributes returned from the proxy target. Proxy filters are
used to modify or remove attributes in RADIUS messages received from proxy
targets.
The RADIUS Server applies filters in the order in which they appear in the
[Link] file.
The InAction element encloses no child elements.
Child element of RADIUSServer or RADIUSServer Group.
Example:

Page 356 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

<InAction Filter="InFilter"/>

Table 122: InAction attributes

Attribute Value Description

Filter • String (1–256 characters) The name of the filter to apply to the RADIUS packet that is
received from the proxy target. The filter must be defined in the
[Link] file, as described in "Filter" on page 339.
If OverwriteIP is enabled for the RADIUS Server, the IP address
replacement is performed after any incoming proxy filters are
applied. The use of OverwriteIP interferes with the Framed-IP
exception values set in the InAction filters.
Optional.

RequiredAttributes • String (1–256 characters) The name of the RequiredAttributes filter to apply to the RADIUS
packet that is received from the proxy target.
Optional.

OverrideAttributes • String (1–256 characters) The name of the OverrideAttributes filter to apply to the RADIUS
packet that is received from the proxy target.
Optional.

OutAction The actions to apply to attributes in RADIUS messages going from the RADIUS
client to the proxy target. Filters can be used to modify or remove attributes in the
authentication or accounting messages sent to proxy targets.
The RADIUS Server applies filters in the order in which they appear in the
[Link] file.
The OutAction element encloses no child elements.
Child element of RADIUSServer or RADIUSServer Group.
Example:
<OutAction
Type="Auth"
Filter="GenericFilter"
OverrideAttributes="Override1"

Service Controller 9.6.1-AAA October 12, 2012 Page 357


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

RequiredAttributes="Required1"/>

Table 123: OutAction attributes

Attribute Value Description

Type • Auth The type of message to be filtered:


• Acct • Auth: filter applied to the proxied Access-Request messages.
• DAE • Acct: filter applied to the proxied Accounting-Request
• All messages.
• DAE: filter applied to the proxied CoA and Disconnect
messages.
• All: filter applied to all proxied messages.
Required.

Filter • String (1–256 characters) The name of the filter to apply. The filter must be defined in the
[Link] file, as described in "Filter" on page 339.
Required when no RequiredAttributes or OverrideAttributes are
defined.

OverrideAttributes • String (1–256 characters) The name of the OverrideAttributes filter to apply to the RADIUS
packet that is sent to the proxy target.
Optional.

RequiredAttributes • String (1–256 characters) The name of the RequiredAttributes filter to apply to the RADIUS
packet that is sent to the proxy target.
Optional.

RADIUSServer Group A group of RADIUS proxy servers and the actions the group takes on RADIUS
messages. Each ProxyTargetConfiguration root element must enclose at least one
proxy target server (RADIUSServer, SecurIDServer, or LDAPServer) or proxy
target group (RADIUSServerGroup, SecurIDServer Group, or LDAPServerGroup)
element.
The RADIUSServerGroup element encloses an optional InAction and an optional
OutAction child element. For more information, see "InAction" on page 356 or
"OutAction" on page 357.
Child element of ProxyTarget Configuration.
Example:
<RADIUSServerGroup
GroupName="RadiusGroup1"
Failover="n"
LoadSharing="y"
MaxConcurrentLockouts="1"
DynamicUnlock="y"
RADIUSServer="RadiusServer1">
<InAction
Filter="InFilter"/>
<OutAction

Page 358 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Filter="GenericFilter"
Type="Auth"/>
</RADIUSServerGroup>

Table 124: RADIUSServerGroup attributes

Attribute Value Description

GroupName • String (1–256 characters) A unique name to identify the RADIUS server group.
• Spaces are not supported Required.

Failover • Y, y • Y: enable the RADIUS Server to failover to an ordered list of


• N, n proxy targets, as defined in the ordered list for that group.
Example: if no response is received from the first target within
the "RequestTimeout" duration then the message is sent to the
second target.
• N: the RADIUS Server only directs requests to the first
candidate proxy target.
If load sharing is disabled, the proxy target is the first proxy target
in the ordered list of targets; otherwise, it is the current proxy
target in the round-robin cycle.
Optional.

Loadsharing • Y. y • Y: the RADIUS Server distributes requests to an ordered list of


• N, n proxy targets as defined in the proxy target group.
Example: a request is sent to the first proxy target and the next
request is sent to the next listed proxy target etc.
• N: the RADIUS Server only directs requests to the first proxy
target in the group.
If failover is enabled, requests are forwarded to the next available
proxy target in the ordered list when the first proxy target is down
or unreachable.
Optional.

MaxConcurrent • Integer The number of proxy targets that can be locked out per proxy
Lockouts Default=all targets in the group group.
When the maximum number of lockouts has been reached, the
proxy target that is a candidate for lockout remains unlocked.
If this is less than the total number of proxy targets in the group,
when that number of targets is locked out, no further targets can
be locked out.
Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 359


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Table 124: RADIUSServerGroup attributes (continued)

Attribute Value Description

DynamicUnlock • Y, y Y — enable the RADIUS Server to dynamically unlock a proxy


• N, n target if all proxy targets within a proxy target group are locked.
When all targets are locked, a single thread sends a message to
the next RADIUS target following the standard loadshare and
failover rules for the group.
When a target is found to be responsive, it is unlocked and used
by all threads.
N — the proxy target is unlocked when the
ConsecutiveFailureLockoutDuration and/or
IntermitentFailureLockoutDuration interval expires.
Optional.

MaxFailoverLimit • Integer When Failover is enabled, define the maximum number of targets
Default=number of servers in the to attempt in the group.
group This parameter is ignored when Failover=N.
A value of '0' is invalid.
Optional.

AddMessage • Y, y Y — insert the RADIUS Message-Authenticator attribute into all


Authenticator • N, n requests sent to this target.
If the attribute is already present in the client request, then this
flag has no effect as it is automatically inserted into the proxy
request.
Adding this attribute provides anti-spoofing protection to requests
as some remote servers may require protection.
Note This parameter is configurable at both the TargetName and
GroupName levels. Specifying this at the GroupName level
overrides the flag values specified on each TargetName.
Optional.

RADIUSServer • String (1–256 characters) A unique name to identify the RADIUS proxy server.
Identify a minimum of one Radius proxy server.
Required.

Page 360 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

SecurIDServer A SecurID server proxy target. Each ProxyTargetConfiguration root element must
enclose at least one proxy target server (RADIUSServer, SecurIDServer, or
LDAPServer) or proxy target group (RADIUSServer Group, SecurIDServer Group,
or LDAPServerGroup) element.
Child element of ProxyTarget Configuration.
[Link]:
<SecurIDServer
TargetName="SecurIDServer1"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="3"
AuthenticationPort="1812"
ConsecutiveLockoutEnabled="n"
IntermittentFailureLockoutEnabled="n"
MaxRetries="1" >
</SecurIDServer>

Table 125: SecurIDServer attributes

Attribute Value Description

Proxy target attributes

TargetName • String (1–256 characters) A unique identifier for the proxy target.
• Spaces are not supported Required.

TargetHost • DNS hostname IP address or DNS hostname of the proxy target.


• IP address (dot notation Required.
format)

Secret • String (1–256 characters) Shared secret used when communicating with the target server.
Required.

RequestTimeout • Integer (1–65535) The maximum time, in seconds, that the RADIUS Server waits for
Default=5 a response from the proxy target before it sends the request to an
alternate proxy server in the group, or deals with the request as
defined in the policy rules.
WARNING: Failure to coordinate these parameters may result in
severe degradation of RADIUS performance.
For more information, see "RequestTimeout" on page 370.
Required.

AuthenticationPort • N (not set; default) UDP port of the proxy target for authentication. The RFC
• Integer (1–65535) standard port for authentication is 1812.
Define either AccountingPort or AuthenticationPort.
Required.

Service Controller 9.6.1-AAA October 12, 2012 Page 361


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Table 125: SecurIDServer attributes (continued)

Attribute Value Description

BindLocalIP • IP address (standard dot The local IP address to bind to when sending proxy requests.
notation) Use this parameter for systems with multiple network interfaces.
Default=local host IP address If this is not configured, only one proxy thread is created, which
listens on the primary IP address. A separate proxy thread is
created for each IP address specified.
For multi-homed boxes, the primary IP address is the default.
Only one IP address can be specified and this parameter can
only be used once per RADIUSServer entry. However, each
RADIUSServer entry can specify a different BindLocalIP in the
case of a multi-homed system.
For each different specified bind IP address, a separate
dedicated proxy receiver thread is created by RADIUS to handle
responses and timeouts for the IP address.
Optional.

Consecutive failure lockout attributes

Consecutive • Y Y — enable consecutive lockout.


LockoutEnabled • N (Default) Optional.

ConsecutiveFailure • Integer (1–65535) The time, in seconds, that a proxy target is locked out due to
LockoutDuration • Indefinite consecutive retry cycle failures.
Default=900 If this parameter is set to “Indefinite”, the proxy target is not
considered for service until it is manually unlocked by an
operator.
Optional.

ConsecutiveRetry • N (not set) The maximum number of consecutive retry failures before
Cycles • Integer (1–65535) lockout of the proxy target occurs.
Optional.

Intermittent failure lockout attributes

IntermittentFailure • Y Y — enable intermittent lockout for the proxy target when a


Lockout • N (Default) server is partially failing due to an unreliable network or a failure
Enabled in a proxy chaining scenario.
Optional.

IntermittentFailure • Integer (1–65535) The time, in seconds, that request failure and success are
Interval Default=900 tracked.
Length Optional.

Page 362 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Table 125: SecurIDServer attributes (continued)

Attribute Value Description

IntermittentFailure • N (not set) The time, in seconds, during which the proxy is not available due
Lockout • Integer (1–65535) to consecutive retry failures.
Duration Default=900 Setting this parameter to ‘Indefinite’ prevents the proxy target
from being considered for service until it is manually unlocked by
an operator.
The only exception is if all proxy targets are locked and Dynamic
Unlock is enabled for the proxy target group.
Optional.

IntermittentFailure • Integer (1–65535) The minimum number of requests within an interval for it to be
MinimumRequests Default=1 considered valid.
Optional.

IntermittentFailure • Integer (1–65535) The number of failed requests, specified as a percentage,


PercentageFailure Default=100 required for the interval to be considered ‘failed’.
Threshold Optional.

IntermittentFailure • Integer (1–65535) The number of successive failed intervals before a proxy target
SuccessiveFailed Default=1 lockout occurs.
Intervals Optional.

Additional attributes

MaxRetries • Integer (1–65535) The number of retry attempts per request before failing over or
Default=0 rejecting the request.
If this parameter is not set, there are no retries for that proxy
target.
Optional.

AddMessage • Y Insert the RADIUS Message-Authenticator attribute into requests


Authenticator • N (Default) sent to this target.
If the attribute is already present in the client request, then this
flag has no effect as it is automatically inserted into the proxy
request.
Adding this attribute provides anti-spoofing protection to requests
as some remote servers may require protection.
Note This parameter is configurable at both the TargetName and
GroupName levels. Specifying this at the GroupName level
overrides the values specified on each TargetName.
Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 363


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

SecurIDServer Group A proxy target group of SecurID servers. Each ProxyTargetConfiguration root
element must enclose at least one proxy target server (RADIUSServer,
SecurIDServer, or LDAPServer) or proxy target group (RADIUSServer Group,
SecurIDServerGroup, or LDAPServerGroup) element.
Child element of ProxyTarget Configuration.
Optional.
Example:
<SecurIDServerGroup
GroupName="SecurIDGroup1"
Failover="y"
LoadSharing="n"
MaxConcurrentLockouts="2"
DynamicUnlock="N"
SecurIDServer="SecurIDServer1 SecurIDServer2">
</SecurIDServerGroup>

Table 126: SecurIDServerGroup attributes

Attribute Value Description

GroupName • String (1–256 characters) A unique name to identify the RADIUS server group.
• Spaces are not supported Required.

Failover • Y (default) Y — enable the RADIUS Server to failover to an ordered list of


• N proxy targets, as defined in the ordered list for that group.
Example: if no response is received from the first target within the
"RequestTimeout" duration then the message is sent to the
second target.
N — the RADIUS Server only directs requests to the first
candidate proxy target.
If load sharing is disabled, the proxy target is the first proxy target
in the ordered list of targets; otherwise, it is the current proxy
target in the round-robin cycle.
Optional.

MaxFailoverLimit • Integer (> 0) When Failover is enabled, define the maximum number of targets
Default=number of servers in the to attempt in the group.
group This parameter is ignored when Failover=N.
A value of '0' is invalid.
Optional.

Page 364 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Table 126: SecurIDServerGroup attributes (continued)

Attribute Value Description

LoadSharing • Y (Default) Y — the RADIUS Server distributes requests to an ordered list of


• N proxy targets as defined in the proxy target group.
Example: a request is sent to the first proxy target and the next
request is sent to the next listed proxy target etc.
N — the RADIUS Server only directs requests to the first proxy
target in the group.
If failover is enabled, requests are forwarded to the next available
proxy target in the ordered list when the first proxy target is down
or unreachable.
Optional.

MaxConcurrent • Integer (1–65535) The number of proxy targets that can be locked out per proxy
Lockouts Default=number of proxy targets group.
in the group When the maximum number of lockouts has been reached, the
proxy target that is a candidate for lockout remains unlocked.
If this is less than the total number of proxy targets in the group,
when that number of targets is locked out, no further targets can
be locked out.
Optional.

DynamicUnlock • Y (Default) Y — enable the RADIUS Server to dynamically unlock a proxy


• N target if all proxy targets within a proxy target group are locked.
When all targets are locked, a single thread sends a message to
the next RADIUS target following the standard loadshare and
failover rules for the group.
When a target is found to be responsive, it is unlocked and used
by all threads.
N — the proxy target is unlocked when the
ConsecutiveFailureLockoutDuration and/or
IntermitentFailureLockoutDuration interval expires.
Optional.

Service Controller 9.6.1-AAA October 12, 2012 Page 365


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Table 126: SecurIDServerGroup attributes (continued)

Attribute Value Description

AddMessage • Y Y — insert the RADIUS Message-Authenticator attribute into all


Authenticator • N (Default) requests sent to this target.
If the attribute is already present in the client request, then this
flag has no effect as it is automatically inserted into the proxy
request.
Adding this attribute provides anti-spoofing protection to requests
as some remote servers may require protection.
Note This parameter is configurable at both the TargetName and
GroupName levels. Specifying this at the GroupName level
overrides the flag values specified on each TargetName.
Optional.

SecurIDServer • String (1–256 characters) List of the names of all proxy targets in the proxy target group,
separated by spaces. There must be at least one entry in the
proxy target group.
Required.

LDAPServer An LDAP server proxy target. Each ProxyTargetConfiguration root element must
enclose at least one proxy target server (RADIUSServer, SecurIDServer, or
LDAPServer) or proxy target group (RADIUSServer Group, SecurIDServer Group,
or LDAPServerGroup) element.
Child element of ProxyTarget Configuration.
Optional.
Example:
<LDAPServer
TargetName="LDAPServer1"
TargetHost="[Link]"
AuthenticationPort="389"
RequestTimeout="5"
MaxRetries="2"
DNPrefix="uid">
</LDAPServer>

Table 127: LDAPServer attributes

Description
Attribute Value
Optional/Required

Proxy target attributes

TargetName • String (1–256 characters) A unique identifier for the proxy target.
• Spaces are not supported Required.

Page 366 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Table 127: LDAPServer attributes (continued)

Description
Attribute Value
Optional/Required

TargetHost • DNS hostname IP address or DNS hostname of the proxy target.


• IP address (dot notation Required.
format)

RequestTimeout • Integer (1–65535) The maximum time, in seconds, that the RADIUS Server waits for
Default=5 a response from the proxy target before it sends the request to an
alternate proxy server in the group, or deals with the request as
defined in the policy rules.
WARNING: Failure to coordinate these parameters may result in
severe degradation of RADIUS performance.
For more information, see "RequestTimeout" on page 370.
Required.

AuthenticationPort • N (not set; default) UDP port of the proxy target for authentication. The RFC
• Integer (1–65535) standard port for authentication is 1812.
Define either AccountingPort or AuthenticationPort.
Required.

Additional attributes

MaxRetries • Integer (1–65535) The number of retry attempts per request before failing over or
Default=0 rejecting the request. If this parameter is not set, there are no
retries for that proxy target.
Optional.

DNPrefix • String (1–256 characters) The distinguished name prefix used to create a DN login string to
authenticate a subscriber against an LDAP target. Examples are
“uid” or “cn”.
Required.

ServiceAVP An attribute to be returned in an Access-Accept message by the LDAP Server to


the RADIUS database. The attribute is retrieved from the LDAP database, mapped
to the equivalent RADIUS attribute name, and inserted in the RADIUS request.
Note The LDAP attribute must be the same type as defined in the RADIUS
dictionary, for example a string or integer. If the attribute is not the same
type, RADIUS ignores it. See "Managing RADIUS and Diameter
dictionaries" on page 177 for more information about RADIUS dictionaries
and attribute types.
Child element of the LDAPServer and LDAPServerGroup.
Optional.
Example:
<ServiceAVP
LDAPAttrName=”userMessage”
RADIUSAttrName=”Reply-Message”/>

Service Controller 9.6.1-AAA October 12, 2012 Page 367


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

<ServiceAVP
LDAPAttrName=”userData”
RADIUSAttrName=”Cisco-AVPair”
VendorName=”CISCO”/>
In the example above the LDAP attribute named “userMessage” is mapped to the
RADIUS attribute “Reply-Message” and the LDAP attribute “userData” is mapped to
the RADIUS VSA “Cisco-AVPair” in the Cisco dictionary.
If multiple instances of an attribute exist in the LDAP database, all instances are
returned to the RADIUS server.
Also define attributes for an LDAPServerGroup. Attributes defined for a group apply
to all LDAP servers in that group. If both the LDAPServer and LDAPServerGroup
have attributes defined, then the LDAPServerGroup attributes override the
LDAPServer attributes. If an LDAP server with defined attributes belongs to a group
with no defined attributes, the attributes defined for each LDAPServer are used.

Table 128: ServiceAVP attributes

Attribute Value Description

LDAPAttrName • String (1–256 characters) The LDAP attribute name.


Required.

RADIUSAttrName • String (1–256 characters) The RADIUS attribute name.


Required.

VendorName • String (1–256 characters) The RADIUS vendor dictionary name.


Default=RFC2138 Optional.

LDAPServerGroup A proxy target group of LDAP servers. Each ProxyTargetConfiguration root element
must enclose at least one proxy target server (RADIUSServer, SecurIDServer, or
LDAPServer) or proxy target group (RADIUSServer Group, SecurIDServer Group,
or LDAPServerGroup) element.
Child element of ProxyTarget Configuration.
Optional.
Example:
<LDAPServerGroup
GroupName="LDAPGroup1"
Failover="Y"
LoadSharing="y"
LDAPServer="LDAPServer1 LDAPServer2">
</LDAPServerGroup>

Page 368 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Table 129: LDAPServerGroup attributes

Attribute Value Description

GroupName • String (1–256 characters) A unique name to identify the RADIUS server group.
• Spaces are not supported Required.

Failover • Y (Default) Y — enable the RADIUS Server to failover to an ordered list of


• N proxy targets, as defined in the ordered list for that group.
Example: if no response is received from the first target within the
"RequestTimeout" duration then the message is sent to the
second target.
N — the RADIUS Server only directs requests to the first
candidate proxy target.
If load sharing is disabled, the proxy target is the first proxy target
in the ordered list of targets; otherwise, it is the current proxy
target in the round-robin cycle.
Optional.

MaxFailoverLimit • Integer (> 0) When Failover is enabled, define the maximum number of targets
Default=number of servers in the to attempt in the group.
group This parameter is ignored when Failover=N.
A value of '0' is invalid.
Optional.

LoadSharing • Y (Default) Y — the RADIUS Server distributes requests to an ordered list of


• N proxy targets as defined in the proxy target group.
Example: a request is sent to the first proxy target and the next
request is sent to the next listed proxy target etc.
N — the RADIUS Server only directs requests to the first proxy
target in the group.
If failover is enabled, requests are forwarded to the next available
proxy target in the ordered list when the first proxy target is down
or unreachable.
Optional.

LDAPServer • String (1–256 characters) List of the names of all proxy targets in the proxy target group,
separated by spaces. There must be at least one entry in the
proxy target group.
Required

Service Controller 9.6.1-AAA October 12, 2012 Page 369


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Proxy target configuration considerations


• When configuring proxy targets, it is important to balance the need to protect
RADIUS from tying up resources waiting for slow or dead proxy targets versus
always trying to get a response from the proxy target, which is the correct and
normal behavior.
• For accounting messages, it is less important to wait for a response. There is
no downside to not getting a response, as RADIUS still writes the accounting
message locally and acknowledges the NAS.
• For authentication messages, it is more important to wait for a response, as the
response may include RADIUS attributes that define the service for that
subscriber.
• Decide if the preferred outage policy when there is no response from a proxy
group for an authentication message is a reject, for example, no service, or
accept with a potentially incorrect service.
• It is important to make sure that the RADIUS Server responds to the NAS
before the NAS times out. After the NAS times out, it resends its request to an
alternative RADIUS Server, which in all cases except when the RADIUS Server
is down, means processing redundant messages.
• Configure the NAS timeout to be greater than, or equal to, the worst case delay
in responding. For example, NAS timeout = RMS timeouts + proxy timeouts per
proxy target + RADIUS processing time.
• To make sure RADIUS responds to the NAS before it fails over, set an
appropriate outage policy in the RADIUS policy rules: either accept or reject for
authentication messages and acknowledgements for accounting messages.
• For example, the NAS timeout is 5 seconds, RMSP timeout is 2 seconds,
RequestTimeout is 2 seconds, and there are two proxy targets. In a worst case
scenario, a response is received within 6 + (RADIUS processing delay)
seconds. Since this exceeds the NAS timeout, this would imply the need to
reduce some, or all, of the timeouts or increase the NAS timeout.
• With dynamic unlock = n for the authentication servers, this means all proxy
targets can be locked out. If this is combined with an outage policy of “accept”,
the service impact is reduced. If this is combined with an outage policy of reject,
extra sessions may be rejected because there has been no attempt to unlock
any previously locked out targets.

RequestTimeout
The RADIUS Server must respond to requests before the NAS times out. This
makes sure that the NAS does not mark the RADIUS as “dead” and that the NAS
does not send redundant messages to its failover target. This avoids the cascade
effect of overloading multiple RADIUS Servers.
To do this, make sure that an outage policy is defined for all policy rules for auth and
accounting-accept, reject, and acknowledge messages. Also, the NAS timeout
must be greater than the time it takes the system to respond. For example: NAS
timeout > RMS delays + proxy delays + internal processing. The absolute value for
the NAS timeout must be greater than the system response time.

Page 370 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

For example: if the auth timeout is 3 seconds per target and there are 2 targets in
the group, there is a worst-case delay of 6 seconds to get a response from the
target. If the RADIUS RMS RequestTimeout is set to 5, there is a worst-case delay
of 5 seconds to get a response from the RMS. Assume 0.5 seconds for internal
RADIUS processing. Therefore, the NAS timeout must be greater than 11.5
seconds (6 + 5 + 0.5).
For more information about RMSP timeouts, see “Client to Server Communication”
in the Service Controller: Resource Management Server Guide.
Base the RequestTimeout values on observed RTT (round trip times) for the proxy
targets. Set RequestTimeout to between 5 and 10 times the RTT to make sure that,
under normal operating conditions (no network congestion, no proxy target delays),
virtually all requests are processed.
RequestTimeout can be set lower for accounting proxy targets than for
authentication proxy targets. It is more important to receive the proxy response from
an authentication target since it may contain RADIUS attributes that define the
service to be delivered.

Consecutive failure lockout


The following example shows the consecutive failure lockout parameters in
[Link]:
ConsecutiveLockoutEnabled="y"
ConsecutiveFailureLockoutDuration="60"
ConsecutiveRetryCycles="6"
In this example, RADIUS locks out the proxy target for 60 seconds whenever 6
consecutive messages do not get a response. This removes the target from the
loadshare group for the lockout duration.

Intermittent failure lockout


This example shows how the intermittent failure lockout parameters display in
[Link]:
IntermittentFailureLockoutEnabled="y"
IntermittentFailurePercentageFailureThreshold="80"
IntermittentFailureLockoutDuration="60"
IntermittentFailureIntervalLength="30"
IntermittentFailureMinimumRequests="10"
IntermittentFailureSuccessiveFailedIntervals="3"
Using this example: if 80% of the requests to this proxy target fail during the
30-second interval, three intervals in a row, then lock out this target for 60 seconds.
In this example, there must be at least 10 requests in the interval for the lockout to
take effect. Otherwise, the results for the interval are ignored.

Service Controller 9.6.1-AAA October 12, 2012 Page 371


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Filter examples
The following examples show the use of attribute filters for a proxy authentication
message response, a proxy accounting request, filters against AVP subtypes, and a
proxy authentication response generic filter in a RADIUS proxy target definition.
This section provides the following examples:
• Disallow attributes with a specific value
• Allow explicit set of attributes
• Allow only supported attributes
• Filters based on AVP subtypes
• RADIUS proxy target with filtered attributes

Disallow attributes with a specific value


This example defines a filter that can remove attributes in an authentication
message returned from a target proxy. This filter returns all attributes to the client
except:
• the Service-Type attribute if the value equals 1
• the Callback-Id attribute if the value equals 123456789
For example:
<Filter FilterName="InFilter" Action="Allow">
<AVP AttrName="Service-Type" Action="Allow">
<ExceptionVal Value="1" />
</AVP>
<AVP AttrName="Callback-Id" Action="Allow">
<ExceptionVal Value="123456789" />
</AVP>
</Filter>

Allow explicit set of attributes


This example defines a filter than can limit the attributes in an accounting message
forwarded to a proxy target. This filter only proxies:
• the Acct-Status-Type attribute
• the Acct-Session-Id attribute
• the Acct-Session-Time attribute if its value is between 300 and 500 inclusive.
• the Acct-Input-Octets attribute
• the Class attribute
All other attributes are removed from the message before it is forwarded to the
proxy target.
<Filter FilterName="AcctFilter" Action="Deny">
<AVP AttrName="Acct-Status-Type" Action="Allow"/>

Page 372 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

<AVP AttrName="Acct-Session-Id" Action="Allow"/>


<AVP AttrName="Acct-Session-Time" Action="Deny">
<ExceptionRange Start="300" End="500" />
</AVP>
<AVP AttrName="Acct-Input-Octets" Action="Allow"/>
<AVP AttrName="Class" Action="Allow"/>
</Filter>

Allow only supported attributes


This example defines a filter than can be used on incoming or outgoing proxy
messages to include only supported attributes. This filter proxies attributes with the
following restrictions:
• include the Service-Type attribute if the value is between 1 and 4 or equal to 6
• include the NAS-IP-Address attribute if the values are not equal or do not fall
within the values specified.
• include the SSG-Service-Info attribute if it is equal to Prepaid or DATA or MMS
or WAP
• include the NAS-IPv6-Address if it is equal to the values specified.
<Filter FilterName="GenericFilter" Action="Allow">
<AVP AttrName="Service-Type" Action="Deny">
<ExceptionRange Start="1" End="4"/>
<ExceptionVal Value="6" />
</AVP>
<AVP AttrName="NAS-IP-Address" Action="Allow">
<ExceptionVal Value="[Link]" />
<ExceptionRange Start="[Link]" End="[Link]"/>
<ExceptionRange Start="[Link]" End="[Link]"/>
<ExceptionVal Value="[Link]" />
</AVP>
<AVP AttrName="SSG-Service-Info" VendorName="CISCO" Action="Deny">
<ExceptionVal Value="Prepaid" />
<ExceptionRegExp Value="DATA|MMS|WAP" />
</AVP>
<AVP AttrName="NAS-IPv6-Address" Action="Deny">
<ExceptionVal Value="5F05:2000:80AD:5800:0058:0800:2023:2F8E"/>
<ExceptionVal Value="6F05:2000:80AD:5800:0058:0800:2023:2F8E"/>
</AVP>
</Filter>

Service Controller 9.6.1-AAA October 12, 2012 Page 373


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Filters based on AVP subtypes


This section provides examples of attribute filters based on AVP subtypes,
including:
• Allow all attributes except WiMAX-QoS- Descriptor
• Remove all attributes except WiMAX-QoS- Descriptor
• Include all attributes, restrict WiMAX-QoS- Descriptor
• Remove all attributes, restrict WiMAX-QoS- Descriptor
Note The examples in this section use WiMAX-QoS-Descriptor as the specified
AVP.
Note Configuring a filter against an AVP subtype is only supported in
[Link]. This cannot be configured in Service Manager.

Allow all attributes This filter proxies all attributes and excludes WiMAX-QoS-Descriptor when
except WiMAX-QoS- Traffic-Priority=3 or Schedule-type=4.
Descriptor <Filter FilterName="QoS" Action="Allow">
<AVP Attrname="WiMAX-QoS-Descriptor:Traffic-Priority" Action="Allow">
<ExceptionVal Value="3"/>
</AVP>
<AVP Attrname="WiMAX-QoS-Descriptor:Schedule-Type" Action="Allow"
<ExceptionVal Value="4"/>
</AVP>
</Filter>

Remove all attributes This filter removes all attributes and includes WiMAX-QoS-Descriptor when
except WiMAX-QoS- Traffic-Priority is between 2 and 3 and Schedule-type=4.
Descriptor <Filter FilterName="QoS" Action="Deny">
<AVP Attrname="WiMAX-QoS-Descriptor:Traffic-Priority" Action="Deny">
<ExceptionRange Start="2" End="3"/>
</AVP>
<AVP Attrname="WiMAX-QoS-Descriptor:Schedule-Type" Action="Deny"
<ExceptionVal Value="4"/>
</AVP>
</Filter>

Include all This filter includes all attributes. WiMAX-QoS-Descriptor is included if and only if
attributes, restrict Traffic-Priority is between 2 and 3 and Schedule-type=4.
WiMAX-QoS- <Filter FilterName="QoS" Action="Allow">
Descriptor <AVP Attrname="WiMAX-QoS-Descriptor:Traffic-Priority" Action="Deny">
<ExceptionRange Start="2" End="3"/>
</AVP>
<AVP Attrname="WiMAX-QoS-Descriptor:Schedule-Type" Action="Deny"
<ExceptionVal Value="4"/>

Page 374 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

</AVP>
</Filter>

Remove all This filter removes all attributes. WiMAX-QoS-Descriptor is included if and only if
attributes, restrict Traffic-Priority is not between 2 and 3 and Schedule-type is not 4.
WiMAX-QoS- <Filter FilterName="QoS" Action="Deny">
Descriptor <AVP Attrname="WiMAX-QoS-Descriptor:Traffic-Priority" Action="Allow">
<ExceptionRange Start="2" End="3"/>
</AVP>
<AVP Attrname="WiMAX-QoS-Descriptor:Schedule-Type" Action="Allow"
<ExceptionVal Value="4"/>
</AVP>
</Filter>

RADIUS proxy target with filtered attributes


This example proxy target definition applies the filters from "Filter examples" on
page 372 to the incoming and outgoing proxy messages. The example shows the
use of filters with override and required attributes in the outgoing proxy messages.
<OverrideAttributes Name=”Assign”>
<Override
AttrName="Framed-IP-Address">
<DataValue Type="IPv4">[Link]</DataValue>
</Override>

<Override
AttrName="Callback-Id"
Precedence="Packet">
<DataValue Type=”Integer”>5551212</DataValue>
</Override>
</OverrideAttributes>
<RequiredAttributes Name=”UserInfo”>
<Reqd AttrName="User-Name"/>
<Reqd AttrName="User-Password"/>
</RequiredAttributes>
<RequiredAttributes Name=”Acct”>
<Reqd AttrName="Acct-Status-Type"/>
</RequiredAttributes>
<RADIUSServer
TargetName="FilteredRadiusServer"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="2"

Service Controller 9.6.1-AAA October 12, 2012 Page 375


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

AccountingPort="1813"
AuthenticationPort="1812">
<InAction Filter="InFilter" />
<OutAction Filter="GenericFilter" Type="Auth"
OverrideAttributes=”Assign”/>
RequiredAttributes=”UserInfo”/>
<OutAction Filter="AcctFilter" Type="Acct">
RequiredAttributes=”Acct”/>
</RADIUSServer>

Proxy target server and group examples


The following examples are sample proxy target server and proxy target group
entries in the [Link] file. The “RadiusGroup1” RADIUSServerGroup
references the attribute filters in "Filter examples" on page 372.
Note These are sample entries and not a complete [Link] file. All entries
need to be enclosed by the ProxyTargetConfiguration root element.
<RADIUSServer
TargetName="RadiusServer1"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="5"
AccountingPort="1813"
AuthenticationPort="1812"
ConsecutiveLockoutEnabled="N"
ConsecutiveFailureLockoutDuration="3600"
ConsecutiveRetryCycles="200"
IntermittentFailureLockoutEnabled="N"
IntermittentFailureIntervalLength="60"
IntermittentFailureLockoutDuration="Indefinite"
IntermittentFailureMinimumRequests="40"
IntermittentFailurePercentageFailureThreshold="25"
IntermittentFailureSuccessiveFailedIntervals="2"
MaxRetries="1"
OverwriteIP="N"
StripDomain="N"
DigitizeAcctSessionID="Y">
</RADIUSServer>
<RADIUSServer
TargetName="RadiusServer2"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="5"

Page 376 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

AccountingPort="1813"
AuthenticationPort="1812"
ConsecutiveLockoutEnabled="N"
ConsecutiveFailureLockoutDuration="3600"
ConsecutiveRetryCycles="200"
IntermittentFailureLockoutEnabled="N"
IntermittentFailureIntervalLength="60"
IntermittentFailureLockoutDuration="Indefinite"
IntermittentFailureMinimumRequests="40"
IntermittentFailurePercentageFailureThreshold="25"
IntermittentFailureSuccessiveFailedIntervals="2"
MaxRetries="1"
OverwriteIP="N"
StripDomain="N"
DigitizeAcctSessionID="Y">
</RADIUSServer>
<SecurIDServer
TargetName="SecurIDServer1"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="3"
AuthenticationPort="1812"
ConsecutiveLockoutEnabled="n"
IntermittentFailureLockoutEnabled="n"
MaxRetries="1" >
</SecurIDServer>
<SecurIDServer
TargetName="SecurIDServer2"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="5"
AuthenticationPort="1812"
ConsecutiveLockoutEnabled="y"
ConsecutiveFailureLockoutDuration="3600"
ConsecutiveRetryCycles="1"
IntermittentFailureLockoutEnabled="n"
IntermittentFailureIntervalLength="60"
IntermittentFailureLockoutDuration="1800"
IntermittentFailureMinimumRequests="10"
IntermittentFailurePercentageFailureThreshold="10"
IntermittentFailureSuccessiveFailedIntervals="1"
MaxRetries="0">
</SecurIDServer>

Service Controller 9.6.1-AAA October 12, 2012 Page 377


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

<LDAPServer
TargetName="LDAPServer1"
TargetHost="[Link]"
AuthenticationPort="389"
RequestTimeout="5"
MaxRetries="2"
DNPrefix="uid">
</LDAPServer>
<LDAPServer
TargetName="LDAPServer2"
TargetHost="[Link]"
AuthenticationPort="389"
RequestTimeout="4"
MaxRetries="1"
DNPrefix="cn">
</LDAPServer>
<RADIUSServerGroup
GroupName="RadiusGroup1"
Failover="n"
LoadSharing="y"
MaxConcurrentLockouts="1"
DynamicUnlock="y"
RADIUSServer="RadiusServer1">
<InAction Filter="InFilter"/>
<OutAction Filter="GenericFilter" Type="Auth"/>
</RADIUSServerGroup>
<SecurIDServerGroup
GroupName="SecurIDGroup1"
Failover="y"
LoadSharing="n"
MaxConcurrentLockouts="2"
DynamicUnlock="N"
SecurIDServer="SecurIDServer1 SecurIDServer2">
</SecurIDServerGroup>
<LDAPServerGroup
GroupName="LDAPGroup1"
Failover="Y"
LoadSharing="y"
LDAPServer="LDAPServer1 LDAPServer2">
</LDAPServerGroup>

Page 378 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Manually locking and unlocking a proxy target


Manually lock or unlock a proxy target using a proxy target-specific MIB variable
called radiusClientLockState. Set this variable using a MIB browser or from the
command line using the setany utility provided with the SNMP master agent. For
more information about the SNMP master agent, see the Bridgewater SNMP
Guide.

To lock or unlock a proxy target


1 Log in as the aaasc user:
su - aaasc
2 To lock or unlock a proxy target:
setany -v2c MasterAgentIPAddress setcommunitystring
[Link] -i LockState
where
MasterAgentIPAddress is the IP address of the SNMP master
[Link] is the snmpCommunitySecurityName of the
community string with set privileges. The default is sysadmin.
index is the index of the proxy target. Use the walkrad utility to determine
this value.
LockState is the lock state of the proxy target. The values for LockState are
1 (locked) or 2 (unlocked).
3 To verify that the LockState variable for the proxy target has been set:
walkrad -e
For more information about using the walkrad utility to view MIB variables, see
the Bridgewater SNMP Guide.

Configuring attribute manipulation


Network operators who deploy proxy targets and proxy target groups can
manipulate RADIUS attributes in a variety of ways. This section provides several
examples of RFC and vendor-specific attribute manipulation.
Manipulate RADIUS attributes in a proxy environment using one of the following:
• the Service Manager
• the [Link] file
Note Before manipulating attributes in a proxy environment, set the
ReadProxyConfigFromDB attribute in the [Link] file according to the
method of provisioning:
– Service Manager, set the ReadProxyConfigFromDB attribute to Y
– [Link], set the ReadProxyConfigFromDB attribute to N (default)
Example: ReadProxyConfigFromDB (Y | y | N | n) "Y"

Service Controller 9.6.1-AAA October 12, 2012 Page 379


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

For more information about the [Link] file, see "Proxy configuration file" on
page 337.
This section describes the following examples of attribute manipulation for a proxy
environment:
• Configuring P/FIP attribute manipulation
• Configuring Accounting Session ID attribute manipulation
• Configuring Calling Station ID (CSID) masking
• Configuring Proxy attribute translation
• Manipulating the case of attributes in the [Link] file
• Attribute conversion plugin overview
Note These examples are not usable for LDAP or SecurID deployments.

Configuring P/FIP attribute manipulation


This section provides information about configuring P/FIP attribute manipulation,
including:
• P/FIP attribute manipulation overview
• Configuring P/FIP attribute manipulation in Service Manager
• Configuring P/FIP attribute manipulation in [Link]
Note Configure P/FIP attribute manipulation in either Service Manager or
[Link]. It cannot be configured in both places.

P/FIP attribute manipulation overview


In a proxy environment, the authenticating AAA proxy server may return a
Framed-IP-Address and a Framed-Pool attribute to the Service Controller (SC).
Network operators may want to modify the value of one of these attributes using the
value of the other during the message handling process.
Proxy/Framed IP (P/FIP) attribute manipulation feature provides a mechanism to
manipulate the Framed-Pool attribute that a AAA proxy server returns to the
Service Controller in an Access-Accept message. The Service Controller
determines how to manipulate the Framed-Pool attribute based on the
Framed-IP-Address attribute that the AAA proxy server sends.
When configured, P/FIP attribute manipulation creates a Framed-Pool attribute by
appending the last octet of the Framed-IP-Address attribute that the AAA proxy
server sends. For example, when a AAA proxy server returns the
Framed-IP-Address value [Link], the Service Controller creates the
Framed-Pool attribute value pool_234. The Framed-Pool attribute value takes the
form ‘pool_x’, where x is the last octet of the inbound Framed-IP-Address. The
Service Controller amends or adds the Framed-Pool attribute value in the
Access-Accept message and removes the Framed-IP-Address.

Page 380 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

Figure 34: How Proxy/Framed IP attribute manipulation works

1HWZRUN$FFHVV6HUYHU

6HQG)UDPHG3RRODWWULEXWH  6HQG)UDPHG3RRODWWULEXWH 
6HQG)UDPHG,3$GGUHVV
SRROB>WR@ SRROB
([DPSOH
5HPRYH)UDPHG,3$GGUHVV 5HPRYH)UDPHG,3$GGUHVV

%ULGJHZDWHU5$',866HUYHU
$FFHVV$FFHSW

$FFHVV$FFHSW

$FFHVV$FFHSW
)UDPHG,3$GGUHVVLVQRW
)UDPHG,3$GGUHVV  )UDPHG,3$GGUHVV 
>WR@
>WR@ 
([DPSOH

$$$SUR[\VHUYHU

The value of the Framed-IP-Address attribute that the AAA proxy server sends to
the Service Controller determines how it is manipulated. This attribute manipulation
is described in Table 130.

Table 130: Proxy/Framed IP attribute manipulation

Framed-IP-Address sent to the Service Controller sends this


Other
Service Controller to the Network Access Server

255.255.255.X (X = 1 -254) pool_X (X = 1 -254) Framed-IP-Address is removed


(Framed-Pool attribute)

[Link] pool_254 Framed-IP-Address is removed


(Framed-Pool attribute)

Not in the form 255.255.255.[0 - 255] Framed-IP-Address (unchanged) None

Service Controller 9.6.1-AAA October 12, 2012 Page 381


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Configuring P/FIP Configure P/FIP attribute manipulation by creating the following system elements:
attribute • one Proxy Filter with a Framed-Pool AVP and a Framed-IP-Pool AVP
manipulation in
• one Proxy Override Attribute Group with a Framed-Pool override attribute
Service Manager
• one Proxy Required Attribute Group with a Framed-Pool AVP and a
Framed-IP-Pool AVP
• one Radius Server with an InAction
Note To provision P/FIP attribute manipulation using the Service Manager, set
the ReadProxyConfigFromDB XML attribute in the [Link] file to ‘Y’.
For more information, see "Proxy configuration file" on page 337.
Note These procedures assume familiarity with the Service Manager
provisioning process. For more information, see the Service Manager:
Getting Started Guide for AAA.
Perform the following procedures:
• To create a Proxy Filter
• To create a Proxy Override Attribute Group
• To create a new Proxy Required Attribute Group
• To create a RADIUS Server

To create a Proxy Filter


1 Create a Proxy Filter called AuthFilter using the parameter:
– Action = Deny
2 To AuthFilter, add a Framed-Pool AVP using the parameter:
– Action = Deny

3 To AuthFilter, add a Framed-IP-Address AVP using the following parameters:


– Action = Allow
– ExceptionRegExp = 255\.255\.255\.(.*)
4 Save AuthFilter.

To create a Proxy Override Attribute Group


1 Create a Proxy Override Attribute Group called FramedIPOverrideGroup.
2 Add an Override Attribute using the following parameters:
– Attribute = Framed-Pool
– Precedence = Filter
– Mandatory = Yes
3 To the Framed-Pool override attribute, add a Condition Group.
4 To the Condition Group, add a Match Condition using the following parameters:
– Attribute = Framed-IP-Address
– Type = IPv4
– Pattern = [Link]

Page 382 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

5 To the Match Condition, add a DataValue using the following parameters:


– Type = String
– Value = pool_254
6 To the Condition Group created in Step 3, add another Match Condition using
the following parameters:
– Attribute = Framed-IP-Address
– Type = IPv4
– Pattern = 255.255.255.[1-9]
7 To the Match Condition, add the following:
– DataValue with the parameters: Type = String, Value = pool_00
– RegExValue with the parameters: Attribute = Framed-IP-Address, Type =
IPv4, Pattern = 255.255.255.([1-9]), and Value = ${1}
8 To the Condition Group created in Step 3, add another Match Condition using
the following parameters:
– Attribute = Framed-IP-Address
– Type = IPv4
– Pattern = 255.255.255.[1-9][1-9]
9 To the Match Condition, add the following:
– DataValue with the parameters: Type = String, and Value = pool_0
– RegExValue with the parameters: Attribute = Framed-IP-Address, Type =
IPv4, Pattern = 255.255.255.([1-9][1-9]), and Value = ${1}
10 To the Condition Group created in Step 3, add another Match Condition using
the following parameters:
– Attribute = Framed-IP-Address
– Type = IPv4
– Pattern = 255.255.255.[1-9][1-9][1-9]
– The Match Condition contains a complex value of:
11 To the Match Condition, add the following:
– DataValue with the parameters: Type = String and Value = pool_
– RegExValue with the parameters: Attribute = Framed-IP-Address, Type =
IPv4, Pattern = 255.255.255.([1-9][1-9][1-9]), and Value = ${1}
12 Save FramedIPOverrideGroup.

To create a new Proxy Required Attribute Group


1 Create a new Proxy Required Attribute Group called FramedIPRequiredGroup.
2 To FramedIPRequiredGroup, add the required attribute Framed-IP-Address.
3 To FramedIPRequiredGroup, add the required attribute Framed-Pool.
4 Save FramedIPRequiredGroup.

Service Controller 9.6.1-AAA October 12, 2012 Page 383


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

To create a RADIUS Server


1 Create a RADIUS Server using the following parameters:
– Name = Target1
– Host = [Link]
– Secret = TESTSECRET
– Request timeout = 2
– Accounting port = 1813
– Authentication port = 1812
2 On the RADIUSServer edit form, click the Actions tab.
3 On the Actions tab, choose the InAction parameters for Target1:
– Proxy Filter = AuthFilter
– Override Attribute Group = FramedIPOverrideGroup
– Required Attribute Group = FramedIPRequiredGroup
4 Save Target1.

Configuring P/FIP This section provides a procedure for configuring P/FIP attribute manipulation using
attribute [Link].
manipulation in Configure P/FIP attribute manipulation by creating the following system elements:
[Link]
• one Proxy Filter with a Framed-Pool AVP and a Framed-IP-Pool AVP
• one Proxy Override Attribute Group with a Framed-Pool override attribute
• one Proxy Required Attribute Group with a Framed-Pool AVP and a
Framed-IP-Pool AVP
• one Radius Server with an InAction

To configure P/FIP attribute manipulation in [Link]


To provision P/FIP attribute manipulation using the [Link] file, set the
ReadProxyConfigFromDB XML attribute in the [Link] file to ‘N’. For more
information, see "Proxy configuration file" on page 337.
Using an XML or text editor, open the [Link] file, located in the /opt/aaasc/
config/radius directory, and add the elements provided in the following example.
Note For the changes to take effect, send the RADIUS Server a HUP signal.
Example:
<Filter FilterName="AuthFilter" Action="Deny">
<AVP AttrName="Framed-Pool" Action="Deny"/>
<AVP AttrName="Framed-IP-Address" Action="Allow">
<ExceptionRegExp Pattern="255\.255\.255\.(.*)"/>
</AVP>
</Filter>

<OverrideAttributes Name="Pools">

Page 384 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

<Override
AttrName="Framed-Pool"
Precedence="Filter"
Mandatory="Y">
<Condition>
<Matches
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="[Link]">
<DataValue Type="String">pool_254</Data>
</Matches>
<Matches
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.[1-9]">
<DataValue Type="String">pool_00</Data>
<RegExValue
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.([1-9])">
${1}
</RegExValue>
</Matches>
<Matches
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.[1-9][1-9]">
<DataValue Type="String">pool_0</Data>
<RegExValue
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.([1-9][1-9])">
${1}
</RegExValue>
</Matches>
<Matches
AttrName="Framed-IP-Address"
StringFormat="IPv4"
Pattern="255.255.255.[1-9][1-9][1-9]">
<DataValue Type="String">pool_</Data>
<RegExValue
AttrName="Framed-IP-Address"
StringFormat="IPv4"

Service Controller 9.6.1-AAA October 12, 2012 Page 385


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Pattern="255.255.255.([1-9][1-9][1-9])">
${1}
</RegExValue>
</Matches>
</Condition>
</Override>
</OverrideAttributes>

<RequiredAttributes Name="Pools">
<Reqd AttrName="Framed-IP-Address"/>
<Reqd AttrName="Framed-Pool"/>
</RequiredAttributes>

<RADIUSServer
TargetName="Target1"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="2"
AccountingPort="1813"
AuthenticationPort="1812">
<InAction
Filter="AuthFilter"
OverrideAttributes="Pools"
RequiredAttributes="Pools"/>
</RADIUSServer>

Configuring Accounting Session ID attribute manipulation


Some network operators use the Accounting Session ID (ASID) to pass the value of
other attributes, such as the NAS-IP-Address, during RADIUS authentication or
accounting requests. Accounting-Session-Id attribute manipulation enables
modification of the Accounting-Session-Id attribute that the NAS sends to the AAA
proxy server. The Service Controller can manipulate the Accounting-Session-Id
attribute for pre-authentication, authentication, and accounting requests.

Page 386 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

ASID overview
With Accounting Session ID (ASID) attribute manipulation, when the Service
Controller needs to proxy a request that contains the Accounting-Session-ID, the
Service Controller modifies the Accounting-Session-Id as follows:
Accounting-Session-Id=<NAS ID><delimiter><session-id-from-NAS>
where
NAS ID = the NAS IP Address
delimiter=[]
session-id-from-NAS = Accounting-Session-ID received from the NAS
For example, if the:
NAS IP Address = [Link]
Accounting-Session-ID = 12345
then, the modified Accounting-Session-ID = 1921681551[]12345
Note If the NAS sends the Session Director a Session Disconnect message, the
Session Director strips the NAS Identifier and delimiter from the
Accounting-Session-ID before forwarding it in the Session Disconnect
message to the NAS.

Configuring ASID Configure Accounting Session ID attribute manipulation by creating:


attribute – one Proxy Override Attribute Group with one override attribute
manipulation
– one Proxy Required Attribute Group with two required attributes
– one Radius Server with Acct OutAction
Create these system elements using the following methods:
• To provision Service Manager for attribute manipulation
• To configure [Link] for attribute manipulation

To provision Service Manager for attribute manipulation


To provision ASID attribute manipulation using the Service Manager, set the
ReadProxyConfigFromDB XML attribute in the [Link] file to ‘Y’. For more
information, see "Proxy configuration file" on page 337.
Note This procedure assumes familiarity with the Service Manager provisioning
process. For more information, see the Service Manager: Getting Started
Guide for AAA.
1 Create a Proxy Override Attribute Group called AcctSessionIdOverrideGroup
using the following parameters:
– Attribute = Acct-Session-Id
– Precedence = Filter
– Mandatory = Yes

Service Controller 9.6.1-AAA October 12, 2012 Page 387


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

2 To AcctSessionIdOverrideGroup, add an Override Attribute using the following


parameters:
– Attribute = Acct-Session-Id
– Precedence = Filter
– Mandatory = Yes
3 To the Acct-Session-Id override attribute, add an AttributeValue using the
following parameters:
– Attribute = NAS-IP-Address
– Precedence = Request
– Type = String
4 To the Acct-Session-Id override attribute, add a DataValue using the following
parameters:
– Type = String
– Value = []
5 To the Acct-Session-Id override attribute, add an AttributeValue using the
following parameters:
– attribute Acct-Session-Id and precedence Request to Acct-Session-Id
override attribute.
6 Saves AcctSessionIdOverrideGroup.
7 Create a Proxy Required Attribute Group called AcctSessionRequiredGroup.
8 To AcctSessionRequiredGroup, add a Required Attribute using the following
parameters:
– Attribute = Acct-Session-Id
9 To AcctSessionRequiredGroup, add a Required Attribute using the following
parameters:
– Attribute = NAS-IP-Address
10 Save AcctSessionRequiredGroup.
11 Create a RADIUS Server using the following parameters:
– Name = Target2
– Host = [Link]
– Secret = TESTSECRET
– Request timeout = 2
– Accounting port = 1813
– Authentication port = 1812
12 On the RADIUSServer edit form, click the Actions tab.
13 On the Actions tab, provision the following parameters:
– OutAction = Acct
– AcctSessionIdOverrideGroup
– AcctSessionRequiredGroup

Page 388 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

14 Save Target2 and exit.

To configure [Link] for attribute manipulation


To provision ASID attribute manipulation using the [Link] file, set the
ReadProxyConfigFromDB XML attribute in the [Link] file to ‘N’. For more
information, see "Proxy configuration file" on page 337.
Using an XML or text editor, open the [Link] file, located in the /opt/aaasc/
config/radius directory, and add the elements provided in the example.
For the changes to take effect, send the RADIUS Server a HUP signal.
Example:
<OverrideAttributes Name="Acct_Session_Id">
<Override
AttrName="Acct-Session-Id"
Precedence="Filter"
Mandatory="Y">
<AttributeValue
AttrName="NAS-IP-Address"
Precedence="Request"
Type="IPv4"/>
<DataValue Type="String">[]</Data>
<AttributeValue
AttrName="Acct-Session-Id"
Precedence="Request"/>
</Override>
</OverrideAttributes>
<RequiredAttributes Name="Acct_Session_Id">
<Reqd AttrName="Acct-Session-Id"/>
<Reqd AttrName="NAS-IP-Address"/>
</RequiredAttributes>
<RADIUSServer
TargetName="Target2"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="2"
AccountingPort="1813"
AuthenticationPort="1812">
<OutAction
Type="Acct"
OverrideAttributes="Acct_Session_Id"
RequiredAttributes="Acct_Session_Id"/>
</RADIUSServer>

Service Controller 9.6.1-AAA October 12, 2012 Page 389


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Configuring Calling Station ID (CSID) masking


Some network operators mask a portion of the Calling-Station-ID for privacy
reasons. Calling-Station-ID (CSID) masking masks a configurable number of digits
of a Calling-Station-ID attribute value for all RADIUS messages that are processed
by a Proxy Target Group.

CSID masking overview


If CSID masking is enabled, when the Service Controller receives an
Access-Request or Accounting-Request message that is to be forwarded to a Proxy
Target Group, it masks a configured number of digits in the Calling-Station-ID, then
sends the message to the proxy target.
For example, if the feature is configured to mask the final three digits using the
letter X, the Calling-Station-ID 023456789 becomes 023456XXX.
The CSID Masking feature enables you to configure the following parameters:
• the number of characters to mask
• the character used to mask (alphanumeric only)
Note If an inbound RADIUS request does not contain a Calling-Station-ID
attribute, the call is processed normally.

Configuring CSID Configure CSID masking using the following methods:


masking • To provision Service Manager to enable CSID masking
• To configure [Link] to enable CSID masking

To provision Service Manager to enable CSID masking


To provision CSID masking using the Service Manager, set the
ReadProxyConfigFromDB XML attribute in the [Link] file to ‘Y’. For more
information, see "Proxy configuration file" on page 337.
Note This procedure assumes familiarity with the Service Manager provisioning
process. For more information, see the Service Manager: Getting Started
Guide for AAA.
1 Create a Proxy Override Attribute Group called CallingStationIdOverrideGroup.
2 To CallingStationIdOverrideGroup2, add an Override Attribute using the
following parameters:
– Attribute = Calling-Station-Id
– Precedence = Filter
– Mandatory = Yes
3 To the Calling-Station-Id override attribute, add a RegExValue with the following
parameters:
– Attribute = Calling-Station-Id
– Type = IPv4
– Pattern = ([0-9]{6}).*

Page 390 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

– Value = ${1}XXX.\
4 Saves CallingStationIdOverrideGroup.
5 Create a RADIUS Server with the following parameters:
– Name = Target3
– Host = [Link]
– Secret = TESTSECRET
– Request timeout = 2
– Accounting port = 1813
– Authentication port = 1812
6 On the RADIUS Server edit form, click the Actions tab.
7 Assign the following information:
– InAction
– Override Group = CallingStationIdOverrideGroup
8 Save Target3.

To configure [Link] to enable CSID masking


To provision CSID masking using the [Link] file, set the
ReadProxyConfigFromDB XML attribute in the [Link] file to ‘N’. For more
information, see "Proxy configuration file" on page 337.
Using an XML or text editor, open the [Link] file, located in the /opt/aaasc/
config/radius directory, and add the elements provided in the example.
For the changes to take effect, send the RADIUS Server a HUP signal.
Example:
<OverrideAttributes Name="Mask">
<Override
AttrName="Calling-Station-Id"
Precedence="Filter"
Mandatory="Y">
<RegExValue
AttrName="Calling-Station-Id"
StringFormat="IPv4"
Pattern="([0-9]{6}).*">
${1}XXX
</RegExValue>
</Override>
</OverrideAttributes>

<RADIUSServer
TargetName="Target3"
TargetHost="[Link]"

Service Controller 9.6.1-AAA October 12, 2012 Page 391


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Secret="TESTSECRET"
RequestTimeout="2"
AccountingPort="1813"
AuthenticationPort="1812">
<InAction
OverrideAttributes="Mask"/>
</RADIUSServer>

Configuring Proxy attribute translation


When RADIUS messages are sent in a proxy deployment, some network operators
want the ability to remove a specific VSA or AVP and replace it with a different VSA
or AVP without changing the original attribute’s value. Proxy attribute translation
‘translates’ the VSAs and AVPs that reside in an Access-Accept message, which
has been sent by a downstream proxy target.
Configure proxy attribute translation by creating:
• one Proxy Override Attribute Group with one override attribute
• one Radius Server with InAction populated
Configure this feature using one of the following methods:
• To provision Service Manager to enable proxy attribute translation
• To modify [Link] to enable proxy attribute translation

To provision Service Manager to enable proxy attribute translation


Note This procedure assumes familiarity with the Service Manager provisioning
process. For more information, see the Service Manager: Getting Started
Guide for AAA.
1 Create a Proxy Override Attribute Group called DnsOverrideGroup.
2 To DnsOverrideGroup, add an Override Attribute (an attribute to replace) using
the following parameters:
– Attribute = (an attribute to replace, such as Ascend-Primary-Dns)
– Vendor = (the attribute’s vendor, such as Ascend)
– Precedence = Filter
– Mandatory = Yes
3 To the override attribute, such as Ascend-Primary-Dns, add an Attribute Value
(the replacement attribute) using the following parameters:
– Attribute = (the replacement attribute, such as Unisphere-Primary-Dns)
– Vendor = (the replacement vendor, such as Juniper)
4 To the override group, such as DnsOverrideGroup, add a second override
attribute (an attribute to replace) using the following parameters:
– Attribute = (another attribute to replace, such as Ascend-Secibdart-Dns)
– Vendor = (the attribute’s vendor, such as Ascend)
– Precedence = Filter

Page 392 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

– Mandatory = Yes
5 To the second attribute to replace, such as Ascend-Secibdart-Dns, add an
AttributeValue (the replacement attribute) using the following parameters:
– Attribute = (the replacement attribute, such as Lucent-Secondary-Dns)
– Vendor = (the attribute’s vendor, such as Lucent)
6 Save DnsOverrideGroup into database.
7 Repeat steps 2 to 6 to add the override attribute groups, override attributes, and
attribute values that you need.
8 Create a RADIUS Server using the following parameters:
– Name = Target4
– Host = [Link]
– Secret = TESTSECRET
– Request timeout = 2
– Accounting port = 1813
– Authentication port = 1812
9 Assign the following information for Target4:
– In Action
– Override Group = DnsOverrideGroup
10 Save Target4 and exit.

To modify [Link] to enable proxy attribute translation


To provision proxy attribute translation using the [Link] file, set the
ReadProxyConfigFromDB XML attribute in the [Link] file to ‘N’. For more
information, see "Proxy configuration file" on page 337.
Using an XML or text editor, open the [Link] file, which is located in the /opt/
aaasc/config/radius directory. Using the following example, add the parameters to
[Link], and replace the italicized values with the appropriate information.
For the changes to take effect, send the RADIUS Server a HUP signal.
Example:
<OverrideAttributes Name="Assign">
<Override
AttrName="Ascend-Primary-Dns"
VendorName="Ascend"
Precedence="Filter"
Mandatory="Y">
<AttributeValue
AttrName="Unisphere-Primary-Dns"
VendorName="Juniper"/>
</Override>
<Override

Service Controller 9.6.1-AAA October 12, 2012 Page 393


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

AttrName="Ascend-Secondary-Dns"
VendorName="Ascend"
Precedence="Filter"
Mandatory="Y">
<AttributeValue
AttrName="Lucent-Secondary-Dns"
VendorName="Lucent"/>
</Override>
</OverrideAttributes>

<RADIUSServer
TargetName="Target4"
TargetHost="[Link]"
Secret="TESTSECRET"
RequestTimeout="2"
AccountingPort="1813"
AuthenticationPort="1812">
<InAction
OverrideAttributes="Assign"/>
</RADIUSServer>

Manipulating the case of attributes in the [Link] file


Use the RegExValue element in the Override section of [Link] to manipulate
the case of attributes in [Link]. Within the RegExValue in the Override section,
use the {strtoupper} and {strtolower} functions to change the case of attribute.
For example, in some networks an Access Node may identify subscribers using a
MAC address in colon-delimited lower case format(ab:cd:11:22:df:33) but when the
Service Controller sends a message to the Access Node, such as a CoA or DM
message, it sends the MAC address in upper case without delimiters
(ABCD1122DF33). Since the Access Node expects the MAC address in lower case
with colons you need to configure the Service Controller to change the
Calling-Station-Id (MAC address) to lower case and insert colons.

To manipulate the case of the MAC address


To use [Link], set the ReadProxyConfigFromDB attribute in the [Link]
file to ‘N’. For more information, see "Proxy configuration file" on page 337.
Note The value of the Calling-Station-Id is actually the subscriber’s MAC
address. This example talks about manipulating the case of the MAC
address, but the MAC address is stored in the Calling-Station-Id, so in
[Link], specify to manipulate the Calling-Station-Id.
Use the following pattern and function to have the Service Controller insert colons
between octets in the MAC address and to switch the MAC address from upper
case to lower case:

Page 394 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

{strtolower}${1}:${2}:${3}:${4}:${5}:${6}
For example, in [Link] configure the following sections:
<OverrideAttributes Name="Renaming">
<Override AttrName="User-Name">
<RegExValue AttrName="Calling-Station-Id" StringFormat="String"
Pattern="(.{2})(.{2})(.{2})(.{2})(.{2})(.{2})">
{strtolower}${1}:${2}:${3}:${4}:${5}:${6}
</RegExValue>
</Override>
</OverrideAttributes>
...
<RADIUSServer
TargetName="target1"
TargetHost="[Link]"
Secret="MYSECRET"
RequestTimeout="2"
DAEPort="3599">
<OutAction OverrideAttributes="Renaming" Type="DAE"/>
</RADIUSServer>
In the example above, when the Service Controller sends messages to the target
named “target1”, the Service Controller applies the override specified in the
OverrideAttributes section of [Link] (the Service Controller matches the
override specified in the OutAction element to the name of the OverrideAttributes
section in [Link]).
In this example the Service Controller adds colons between octets and changes the
alpha characters to lower case for the Calling-Station-Id (the MAC address) and
includes the Calling-Station-Id value (the MAC address) in the colon-delimited lower
case format in the User-Name attribute when sending messages to the proxy
target.
For more information about configuring overrides, see "OverrideAttribute" on page
342.

Attribute conversion plugin


This document provides information about installing and configuring a RADIUS
plugin that converts RADIUS attributes in Access-Accept messages from a proxy
target.
The topics include:
• Attribute conversion plugin overview
• Installing and configuring the attribute conversion plugin

Service Controller 9.6.1-AAA October 12, 2012 Page 395


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

Attribute conversion plugin overview


In a network, a proxy target can return a value for the Ascend-Data-Filter attribute in
either the Ascend-Data-Filter or Extended-Data-Filter attributes. Because the NAS
only accepts the Ascend-Data-Filter attribute, any instances of the
Extended-Data-Filter attribute in the Access-Accept from the proxy target need to
be converted to Ascend-Data-Filter.
Attribute conversion is enabled by a RADIUS attribute conversion plugin
([Link]), configured in the accessReqPolicy file, with the ProxyAA action.
When installed and configured on the policy line, the RADIUS attribute conversion
plugin performs the following:
• allows instances of the Ascend-Data-Filter attribute in Access-Accept
messages from the proxy target
• converts instances of the Extended-Data-Filter to Ascend-Data-Filter.
– the plugin changes the attribute type, but keeps the value of the attribute
the same.
• when converting the Extended-Data-Filter to Ascend-Data-Filter the plugin
creates a new instance of Ascend-Data-Filter.
– the plugin does not overwrite any instances of Ascend-Data-Filter, and
removes any instances of Extended-Data-Filter from the Access-Accept.
• the plugin can handle multiple instances of the Extended-Data-Filter attribute in
the Access-Accept from the proxy target.
• the plugin is triggered for Access-Accept messages from a proxy target.
• for an Access-Reject the plugin is not triggered.

Example conversion This example shows how the RADIUS plugin converts the Extended-Data-Filter in
an Access-Accept returned from a proxy target.
Note This example only shows instances of Ascend-Data-Filter and
Extended-Data-Filter and does not include other attributes that may be in
the Access-Accept from the proxy target.

Access-Accept from proxy target


{VSA} [ 4846,242]
<Ascend-Data-Filter>=([Link].[Link].[Link].00.
[Link].[Link].[Link].[Link].00.00.00)
{VSA Length: 35Bytes} {Attribute Length: 39Bytes}
-------------------------------------------------------------
{VSA} [ 4846,242]
<Ascend-Data-Filter>=([Link].[Link].[Link].00.
[Link].[Link].[Link].[Link].00.00.00)
{VSA Length: 35Bytes} {Attribute Length: 39Bytes}
-------------------------------------------------------------
[242]
<Extended-Data-Filter>=([Link].[Link].[Link].0
[Link].[Link].[Link].[Link].[Link])32
Byte

Page 396 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 8 Configuring proxy targets and proxy target groups

-------------------------------------------------------------
[242]
<Extended-Data-Filter>=([Link].[Link].[Link].0
[Link].[Link].[Link].[Link].[Link])32
Byte

Access-Accept returned to the NAS


{VSA} [ 4846,242]
<Ascend-Data-Filter>=([Link].[Link].[Link].00.
[Link].[Link].[Link].[Link].00.00.00)
{VSA Length: 35Bytes} {Attribute Length: 39Bytes}
-------------------------------------------------------------
{VSA} [ 4846,242]
<Ascend-Data-Filter>=([Link].[Link].[Link].00.
[Link].[Link].[Link].[Link].00.00.00)
{VSA Length: 35Bytes} {Attribute Length: 39Bytes}
-------------------------------------------------------------
{VSA} [ 4846,242]
<Ascend-Data-Filter>=([Link].[Link].[Link].00.
[Link].[Link].[Link].[Link].00.00.00)
{VSA Length: 35Bytes} {Attribute Length: 39Bytes}
-------------------------------------------------------------
{VSA} [ 4846,242]
<Ascend-Data-Filter>=([Link].[Link].[Link].00.
[Link].[Link].[Link].[Link].00.00.00)
{VSA Length: 35Bytes} {Attribute Length: 39Bytes}

Installing and This section provides information about installing and configuring the RADIUS
configuring the attribute conversion plugin.
attribute conversion • To install the attribute conversion plugin
plugin
• To configure the attribute conversion plugin in the accessReqPolicy file
• To configure the dictionary

To install the attribute conversion plugin


Install the BWStelspi package.
This package installs the RADIUS attribute conversion plugin [Link] to
/opt/aaasc/plugins/radius.
Package dependencies: BWSaaaco

To configure the attribute conversion plugin in the accessReqPolicy file


1 As the root user, change to the RADIUS configuration directory and open the
accessReqPolicy file for editing.
cd /opt/aaasc/config/radius
vi accessReqPolicy
2 Add the TelstraPlugin to the policy file. For example:

Service Controller 9.6.1-AAA October 12, 2012 Page 397


Chapter 8 Configuring proxy targets and proxy target groups Network Access Guide

- - - AssignVar myVar=CALLEDID:$Called-Station-Id
- - - PreAuthorize loginName=$Called-Station-Id
domain=null getProxyService=y continueNotFound=y
PreAuth:BRIDGEWATER:Proxy-Target Appears Once ProxyAA
target=PreAuth:$BRIDGEWATER:Proxy-Target
service=BPNAttrReturn-Auth
authorizeLoginName=myVar:CALLEDID authorizeDomain=null
authorizeProxyLevel=l outageAction=SendReject
outageRejectMessage="Could not connect to end AAA"
runPlugIn=TelstraPlugin
- - - SendReject replyMessage="BigPond service
mis-configured"
3 Save the file and exit.
4 Send the RADIUS Server a HUP signal for the changes to take effect.
pkill -HUP radiusd
For more information about RADIUS access request policies, see the chapter
“Configuring AAA Policies” in the Service Controller: Network Access Guide.

To configure the dictionary


Make sure that the following attributes are defined in the LUCENT dictionary:

VENDOR LUCENT 1751


...
...
ATTRIBUTE Extended-Data-Filter 242 string none both multi

START-VSA 4846 UInt16TypeCoder


ATTRIBUTE Ascend-Data-Filter 242 string none both multi

Note Extended-Data-Filter must be defined near the beginning of the dictionary


in the VENDOR LUCENT 1751 section.

Page 398 October 12, 2012 Service Controller 9.6.1-AAA


Testing RADIUS Server configuration

9
Chapter 9
Chapter

This chapter describes tools used to test and monitor the RADIUS Server
configuration.
The topics are:
• Validating configuration files
• Testing RADIUS Server configuration
• Monitoring RADIUS communications

Service Controller 9.6.1-AAA October 12, 2012 Page 399


Chapter 9 Testing RADIUS Server configuration Network Access Guide

Validating configuration files


Validate changes to RADIUS configuration files before applying the changes.
The validation script checks the following files:
• [Link]
• traceclients
• [Link]
• accessReqPolicy
• acctReqPolicy
• dynamicHAPolicy
• TLSPolicy
• [Link]
• [Link]
• any policy files created for the PolicyRun action
1 Log in as the aaasc user:
su - aaasc
2 Navigate to the RADIUS directory and run radiusd:
cd /opt/aaasc/radius
./radiusd -V -C /opt/aaasc/config -d /opt/aaasc/config/
radius
If a configuration error is found, an error message displays on the console. For
example:
ERROR: Failed to read radius configuration file(s)
3 Correct the error and then run the validation again.
When all files are valid, the following message displays:
INFORMATION: Configuration file data verified
The RADIUS log file (/var/adm/messages) also includes file verification details,
such as:

Mar 27 04:42:45 [19762]: NTCE RADSYS(26) Bridgewater


MT-RADIUS Version [81GA_12060130]
Mar 27 04:42:45 [19762]: INFO RADSYS(2406) WS_ConnectToDB
-- Successful Database Connection to db_host
Mar 27 04:42:46 [19762]: INFO RADSYS(10) Configuration
file data verified

Page 400 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 9 Testing RADIUS Server configuration

Testing RADIUS Server configuration


Test the RADIUS Server configuration using radtest. Radtest simulates a NAS
requesting authentication from the RADIUS Server. Using the specified test data,
radtest tests how the RADIUS Server processes Service Controller requests.
Use radtest to test different aspects of the RADIUS Server configuration, such as to
verify that a service connection is working properly.
When executing a radtest request, attributes encrypted with rfcmd5 and saltmd5
encryption are returned encrypted. To decrypt these attributes, use the decryptor
tool, as described in "To use the decryptor tool" on page 405.
To convert values such as vendor identification and strings, and display the
equivalent octal and hex values that are required by the VSAs, use the prvsa tool,
as described in "To use the prvsa tool" on page 405.
Radtest accepts zero-length packets.

To execute radtest requests


1 Log in as the aaasc user:
su - aaasc
2 Navigate to the radtest directory and run radtest:
cd /opt/aaasc/testtools/radtest
./radtest option radiusIP sharedsecret request:attr=val
where
option is zero or more options from Table 131
radiusIP is the IP address, in dot notation, of the target RADIUS Server for
the test
sharedsecret is the shared secret that the RADIUS server uses to
communicate with the RADIUS client. This must be the same shared secret
as the one for the RADIUS client.
request:attr=val specifies one or more RADIUS attribute-value pairs from
the vendor dictionaries
Table 131 lists radtest request options.

Table 131: radtest request options

Option Function

-V Displays the radtest software version.

-h Displays this list of options and other information about radtest.

-A <type> Specifies the accounting status type name.

-a Sends accounting requests only (no authentication).

Service Controller 9.6.1-AAA October 12, 2012 Page 401


Chapter 9 Testing RADIUS Server configuration Network Access Guide

Table 131: radtest request options (continued)

Option Function

-b Sends authentication requests only (no accounting).

-v Verbose mode explains what is occurring at each step of the test as it is


executed.

-E Encrypts all attributes in the accounting and authentication messages.

-U Run the test in user interactive mode with prompts as the test is
executed.

-i Prompts when an access-challenge occurs.

-t <sec> The time, in seconds, after which radtest stops attempting to run the
test.
Default = 120

-R <num> The number of times radtest retries the test before it fails.
Default = 1

-d <ID> An identifier that matches authentication and accounting requests to


their replies, detecting and discarding duplicate requests.

-p <Port> The RADIUS Server UDP port If the RADIUS Server is configured to
listen on alternate ports.
The default port for authentication is 1812 and the default port for
accounting is 1813.

-s <msec> The time, in milliseconds, between Accounting-Start and


Accounting-Stop messages.
Default = 0

-l A looped test.
n or N=<loop A looped test executes tests continuously until a specified value, either
count> a number of executions (n=<loop>) or a length of time (t=<time>), is
t or T=<time> reached.

-P <sec> The output interval, in seconds, for a looped test.

-r <num> The maximum number of cycles per second for a looped test.

-u <uid> The maximum userid for a looped test.


This is a default option for a looped test. The default value is 25 000.

-n <net> The NAS network address for a looped test.

-c Ignores the timeout value when performing a looped test.

Page 402 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 9 Testing RADIUS Server configuration

Table 131: radtest request options (continued)

Option Function

-L <mod> A login name generator is provided to automatically generate login


names and passwords for looped tests. If a different login name
generator is used, use the -L option to specify the generator module
name.
The default login name generator creates login names in the format
user999 and passwords in the format user999p, where 999 is a random
number between 1 and the number specified by the -u option.

-D <domain> When radtest generates login names for looped tests, specify a domain
for these login names using the -D option.

-I <count> The number of Acct-Interim-Updates radtest must send when executing


a test.

-T <msec> The time, in milliseconds, for interim accounting messages. This value
overrides the Acct-Interval attribute in the Access-Accept message from
RADIUS.

-w <lockfile> Wait for a shared (read) lock before start.

-W<msec> The time, in milliseconds, to wait before starting.

-N Non-RFC compliant mode. In this mode, the length of the


User-Password attribute-value pair is the same as the password.
Without the -N switch, radtest handles the User-Password as specified
in RFC 2865 by padding the end of the password to a multiple of 16
octets, up to a maximum of 16 characters.

-g Enables the automatic generation of one Message-Authenticator


attribute and its value. This attribute and its value are added to the
Access-Request message.

-C Add call-check request.

-e <IP> An IP address to bind to this network interface.

In addition to the attribute value pairs specified, the following attributes are added or
replaced in a looped test with the user generator module:
• User-Name="user<uid>[@domain]"
• User-Password="user<uid>p"
• NAS-IP-Address="NAS Network.[1-255]"
• NAS-Port="[0-255]"
where
uid is an integer in the range of [1-max uid] inclusive
NAS Network is the network address of the NAS, which is by default the
network address of RADIUS
NAS-IP-Address is replaced only if NAS netaddr is specified on the command
line

Service Controller 9.6.1-AAA October 12, 2012 Page 403


Chapter 9 Testing RADIUS Server configuration Network Access Guide

It is not necessary to specify options for the radtest request. If no options are
specified, default options and values are used. For example, send this message:
radtest -v [Link] DEMOSECRET User-Name=user@[Link]
User-Password=test NAS-Port=1 NAS-IP-Address=[Link]

radtest output
RADIUS
IP address : [Link]
Auth UDP Port: 1812
Acct UDP Port: 1813
User Interact: disabled
Timeout Intvl: 120
Retry Count : 1
Acct Wait Int: 0

Sending Authentication Request (1:1) Sent


Using Request Authenticator: [Link].[Link].[Link].[Link]

User-Name = “auth_stats@[Link]”
User-Password = “auth_stats”
NAS-Port = 555

ready to receive RADIUS auth response (1:1)


Access Accepted - time = 0 seconds
total time is >64< ms
Service-Type = Framed
Framed-Protocol = PPP
Framed-IP-Address = [Link]
Framed-IP-Netmask = [Link]
Reply-Message = “ACC PPP Service”
Session-Timeout = 300

Sending Accounting start Request (2:1)... Sent


ready to receive RADIUS acct start response (2:1)
Received Accounting Response - time = 0 seconds
START REQ: total time is >32< ms

Sending Accounting stop Request (3:1)... Sent


ready to receive RADIUS acct stop response (3:1)
Received Accounting Response - time = 0 seconds
STOP REQ: total time is >24< ms

=====================Final Result===========================

Authentication : Success = 1, Failures = 0, Min = 64, Max =


64, Avg = 64
Accounting Start: Success = 1, Min = 32, Max = 32, Avg = 32
Accounting Stop : Success = 1, Min = 24, Max = 24, Avg = 24

Page 404 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 9 Testing RADIUS Server configuration

Overall Cycle : Success = 1/1, Min = 120, Max = 120, Avg =


120
Cycles per Sec. : 8.3333333
If the test is not successful, radtest displays the text it receives inside the
Reply-Message attribute from the RADIUS Server. RADIUS also writes error
messages to syslog on the RADIUS Server.

To use the decryptor tool


Use the decryptor tool to decrypt rfcmd5 and saltmd5 encrypted attributes returned
from a NAS when a radtest request is executed. The decryptor tool is stored in
/opt/aaasc/testtools/radtest.
1 Log in as the aaasc user and navigate to the radtest directory:
su - aaasc
cd /opt/aaasc/testtools/radtest
2 Run the decryptor tool:
./decryptor -s sharedsecret -a request-authenticator -v
value-to-be-decrypted -S
where
sharedsecret is the shared secret between the RADIUS Server and the
NAS
request-authenticator is a 16-bit randomly generated number used with the
shared secret to encrypt and decrypt attribute values
value-to-be-decrypted is the encrypted value to be decrypted. When
attempting to decrypt a Tunnel-Password, do not add the 00 tag into the
value-to-be-decrypted. For example, if
Tunnel-Password=[Link].e4.21.97.
4a was received, skip the 00 tag and use -v
[Link].e4.21.97.4a.
-S is used to decrypt saltmd5 encrypted attribute values. This option is not
necessary to decrypt rfcmd5 attribute values.
For example:
decryptor -s SECRET -a [Link].[Link].[Link].[Link] -v
[Link].42.16.34.6c.e7.48.e9
The decrypted value is returned in hexidecimal or octal format.

To use the prvsa tool


The prvsa (Prepare VSA) tool converts values, such as vendor identification and
strings, and displays the equivalent octal and hex values that are required by the
VSA. The prvsa tool also supports the encoding of octet-string VSAs.
1 Log in as the aaasc user and navigate to the radtest directory:
su - aaasc

Service Controller 9.6.1-AAA October 12, 2012 Page 405


Chapter 9 Testing RADIUS Server configuration Network Access Guide

cd /opt/aaasc/testtools/radtest
2 Run the prvsa tool:
./prvsa options
where options are any of the choices in Table 132.

Table 132: prvsa tool options

Options Description

-h Displays this list of options and other information about prvsa.

-e Encoding type: 1,2, or 4 bytes

-d Encoding length: 1 or 2 bytes

-c Attribute code

-v vendor ID

-s string

-b (1 octet) 8-bit integer

-w (2 octets) 16-bit integer

-i 32-bit integer

-l 64-bit integer

-l IPv4 address

-P IPv6 address

-o An indication that the VSA contains octet-string sub-types

-t code value VSA subtype code

-f Sub-type flag. Allows a sub-type without a specified value.

-u Create VSAs with a continuation byte. This option sets the continuation
byte to zero and disables attribute continuation.
For example: prvsa –c 26 –v 24757 –u 0 –w 12321

Example 1 To display values in the octal and hex formats required by the VSA for
non-octet-string attribute 73:
./prvsa -c 73 -v 5 -s TestSecret
In Octal: 16
:\000\000\000\005\111\014\164\145\163\164\123\145\143\162\
145\164
In Hex: 16 :0:0:0:5:49:c:74:65:73:74:53:65:63:72:65:74

Page 406 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 9 Testing RADIUS Server configuration

Example 2 To display values in the octal and hex formats required by the VSA for octet-string
attribute 71 (3GPP2-Remote-Addr-Table-Index):
./prvsa -c 71 -v 5535 -o -t 1 -w 6792 -t 2 -w 1
In Octal: 14
:\000\000\025\237\107\012\001\004\032\210\002\004\000\001
In Hex: 14 :0:0:15:9f:47:a:1:4:1a:88:2:4:0:1

Example 3 To apply radtest using the "Vendor-Specific" values obtained from the prvsa tool in
"Example 1" and "Example 2":
radtest -vbp 1645 n.n.n.n 'abc$123' User-Name=”123@[Link]”
CHAP-Password="123abctest" NAS-Port="77453"
NAS-IP-Address="n.n.n.n" NAS-Identifier=PDSN125
Calling-Station-Id="1234567899" NAS-Port-Type=18
Service-Type=2 Framed-Protocol=1
Vendor-Specific="\000\000\000\005\111\014\124\145\163\164\123
\145\143\162\145\164"
Vendor-Specific="\000\000\025\237\107\012\001\004\032\210\002
\004\000\001"
Note Substitute an IP address for n.n.n.n, in these examples.
Use the Trace Tool output to decrypt the values of the attributes that are provided.
For information about the Trace Tool, see "To start the Trace Tool" on page 413.

Service Controller 9.6.1-AAA October 12, 2012 Page 407


Chapter 9 Testing RADIUS Server configuration Network Access Guide

Table 133: Trace tool output

Request Type Req Initiator IP [Link] Req Handler IP R.H. Port


Access Request n.n.n.n 61555 n.n.n.n 1645

Timestamp Direction Thread ID Req ID Vendor ID # of Attr


20:59:00 16-Apr-2007 IN 51 1 8164 11

Authenticator Tracking ID

[Link].c2.86.9c.3b.94 390518

[ 1] <User-Name>=(123@[Link])25Byte

[ 3] <CHAP-Password>=([Link].8c.c7.d6.e9.1f.a6) 17Byte

[ 5] <NAS-Port>=(77453) 4Byte

[ 4] <NAS-IP-Address>=(n.n.n.n) 4Byte

[ 32] <NAS-Identifier>=(PDSN125) 7Byte

[ 31] <Calling-Station-Id>=(1234567899) 10Byte

[ 61] <NAS-Port-Type>=(Wireless-Other) 4Byte

[ 6] <Service-Type>=(Framed) 4Byte

[ 7] <Framed-Protocol>=(PPP) 4Byte

{VSA} [ 0,0] <Vendor-Specific>=([Link].49.0c.[Link].[Link].65.74)


{VSA Length: 0Bytes} {Attribute Length: 16Bytes}

{VSA} [ 5535,71] <3GPP2-Remote-Addr-Table-Index>=(<Table-Index>=6792 2Bytes


<Qualifier>=1 2Bytes) {VSA Length: 10Bytes} {Attribute Length: 14Bytes}

In this example, the information that is returned, “{VSA} [0,0]”, is not what is
expected for VSA 5 (from "Example 1"). Therefore, check the dictionaries to verify
that START-VSA = 5 is specified.
For the purposes of this example, START-VSA = 5 is not specified. However,
START-VSA = 5535 is specified as:
ATTRIBUTE 3GPP2-MN-HA-Shared-Key 58 string saltmd5 out single
Therefore, use a prvsa command that includes this information:
./prvsa -c 58 -v 5535 -s TestSecret
In Octal: 16
:\000\000\025\237\072\014\124\145\163\164\123\145\143\162\145
\164

Page 408 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 9 Testing RADIUS Server configuration

Run the radtest with the values obtained from the prvsa tool:
radtest -vbp 1645 n.n.n.n 'abc$123' User-Name=”123@[Link]”
CHAP-Password="123abctest" NAS-Port="77453" NAS-IP-Ad
dress="n.n.n.n" NAS-Identifier=PDSN125
Calling-Station-Id="1234567899" NAS-Port-Type=18
Service-Type=2 Framed-Protocol=1 Vendor-
Specific="\000\000\025\237\072\014\124\145\163\164\123\145\14
3\162\145\164"
Vendor-Specific="\000\000\025\237\107\012\001\004\032\21
0\002\004\000\001"

Monitoring RADIUS communications


Use the RADIUS Trace Tool to monitor RADIUS communication with NASs and
other RADIUS Servers, and to test and correct problems with the RADIUS Server.
The Trace Tool connects to the RADIUS Server as a client. The Trace Tool can run
on the same host machine as the RADIUS Server, or on a remote machine
connected through TCP/IP.
On the RADIUS Server, in the traceclients file, define the valid Trace Tool clients
that can connect to it.
In the [Link] file, define filters to control which RADIUS messages are logged and
where the messages are logged, such as to the console or to a file.
The Trace Tool workflow is:
1 To define valid Trace Tool clients (/opt/aaasc/config/radius/traceclients)
– Defines which clients can connect to the RADIUS server
– Any changes to the traceclients file require a RADIUS HUP
2 To configure trace filters
– Defines which messages is recorded
– Defines where the messages are logged
Note Trace Tool operates at a low level and has a performance impact on the
system while the tracing is running. Bridgewater Systems recommends that
Trace Tool be used only to see the specific RADIUS attributes for an
individual request. An alternative is to monitor the operational logs (oplogs).

Service Controller 9.6.1-AAA October 12, 2012 Page 409


Chapter 9 Testing RADIUS Server configuration Network Access Guide

To define valid Trace Tool clients


On the RADIUS Server, edit the /opt/aaasc/config/radius/traceclients file to define a
list of valid Trace Tool clients that can connect to the RADIUS Server.
The RADIUS Server only accepts connections from the clients listed in this file.
Note The RADIUS Server reads the traceclients file at startup. After changing the
traceclients file, send the RADIUS Server a HUP signal, using the
command pkill -HUP radiusd.
When the RADIUS Server receives a HUP signal, it rereads the
CONNECTIONS and TRACECLIENT fields only. After changing the PORT
or TRACEBIND fields, restart the RADIUS Server.
Table 134 describes the fields in the traceclients file. All fields are optional.

Table 134: traceclients fields

Field Value Description

PORT Integer (greater The port on which the RADIUS Server accepts connections from Trace Tool
than 1023) clients.
Default = 30000 After changing this field, restart the RADIUS Server.

TRACEBIND IP address A single interface for connections with Trace Tool clients, when the machine
Default = any has more than one IP address or more than one virtual address.
After changing this field, restart the RADIUS Server.

CONNECTIONS Integer (1–8) The maximum number of simultaneous connections with Trace Tool clients.
Default = 4

TRACECLIENT String (hostname or A server that can connect to the RADIUS Server. More than one trace client
IPv4 address) can be specified.

This is an example of a traceclients file:


PORT 30000
TRACEBIND [Link]
CONNECTIONS 4
TRACECLIENT [Link]
TRACECLIENT [Link]
TRACECLIENT [Link]

To configure trace filters


Define several sets of filters using one or more TARGET sections in the filters
[Link] TARGET section has its own filters and has one or more LOG
destinations, such as the screen or log file. For example:
– Log access requests for user1234 to a [Link] file and to the console
– Log access reject messages from [Link] to a [Link] file
– Log messages with a vendor ID of 9 to vendor_packets.log

Page 410 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 9 Testing RADIUS Server configuration

On the Trace Tool host machine, edit the /opt/aaasc/testtools/tracetool/[Link] file


to configure how the Trace Tool records RADIUS messages. Filters specify the
header information and attribute-value pairs that must be contained in the message.
This is an example of the filter configuration file.
TARGET
LOG=SCREEN
LOG=[Link]
M:User-Name=user1234
M:User-Password=*
TARGET
LOG=[Link]
RequestType=3
RequestHandler=[Link]
TARGET
LOG=vendor_packets.log
VendorId=9
This example writes access requests for user1234 to a [Link] file and to the
console, writes access reject messages from [Link] to a [Link] file and
writes packets with a vendor ID of 9 to vendor_packets.log.
Table 135 lists the fields in the trace filter file.

Table 135: Filter configuration file format

Field Description

TARGET Indicates start of one set of filters.


Define several sets of filters, each preceded by TARGET. Each TARGET section
has its own filters and has one or more LOG destinations, such as the console or a
file.

LOG=SCREEN Indicates the destination for messages:


LOG=filename • SCREEN—writes to the console
• filename—writes to a file in the directory
There can b multiple destinations for each TARGET.

RequestInitiator=IP_address IP address of the NAS or RADIUS server that is the source of the access-request.
For more information, see "RequestInitiator, RequestHandler, and Direction
fields" on page 414.
Note This field does not support the * wildcard.

RequestInitiatorPort=port_number Port used by the Request Initiator to communicate with the RADIUS Server.

RequestHandler= IP address of the RADIUS server that is the target of the access-request. For more
IP_address information, see "RequestInitiator, RequestHandler, and Direction fields" on page
414.
Note This field does not support the * wildcard.

RequestHandlerPort=port_number Port used by the Request Handler to communicate with NASs or remote RADIUS
servers.

Service Controller 9.6.1-AAA October 12, 2012 Page 411


Chapter 9 Testing RADIUS Server configuration Network Access Guide

Table 135: Filter configuration file format (continued)

Field Description

ThreadId=thread_number RADIUS thread that forwarded the packet.

Direction= [1 | 2] Specifies whether the packet was incoming or outgoing from the request handler.
Either:
1 = incoming
2 = outgoing
Incoming packets go from the request initiator to the request handler; outgoing
packets go from the request handler back to the request initiator.
For more information, see "RequestInitiator, RequestHandler, and Direction fields"
on page 414.

VendorId=vendor_number Vendor of the NAS, as provisioned in the Profile Database.

RequestType=type_number Type of request, as defined in RFC 2865.


For example, RequestType=1 for Access-Request.

RequestId=request_identifier Packet’s unique request identifier, as defined in RFC 2865.

[M:]Attribute=[* | value] Attribute-value pair in the packet. You can type a specific value or an asterisk (*) to
allow any value.
Precede the attribute-value string with M: if the presence of this string is mandatory.
If M: is not added then the packet is logged if the attribute is missing or when the
attribute and value match the specified pair.

Page 412 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 9 Testing RADIUS Server configuration

To start the Trace Tool


The Trace Tool connects to the RADIUS Server as a client. Run the Trace Tool on
the same host machine as the RADIUS Server or on a remote machine connected
with TCP/IP.
1 Log in as the aaasc user and navigate to the tracetool directory:
su - aaasc
cd /opt/aaasc/testtools/tracetool
2 Run the Trace Tool:
./tracetool -f file -p port -h host -d -s -e -v
where
-f specifies the location and name of the trace filter configuration file. For
more information, see "To configure trace filters" on page 410.
-p specifies the port on the RADIUS Server to which to connect (default is
30000)
-h specifies the hostname to which to connect. The default is the local host,
which is resolved to the loopback address [Link].
-d displays the filter rules in the output
-s runs the Trace Tool client as a single thread (do not use the -s option on
a single CPU machine)
-e initiates end to end tracing
-v identifies the software version
-H displays help and closes the Trace Tool
The traceclients configuration file must contain a TRACECLIENT entry for this IP
address for the RADIUS Server to accept the Trace Tool connection.
When the RADIUS Server is shut down, it terminates any Trace Tool connections.
After restarting the RADIUS Server, restart the Trace Tool.

RADIUS dictionary files


The /opt/aaasc/dict directory contains a .DICT file for each vendor and a
dictionaries file that lists all vendor dictionaries used in the system. If custom vendor
dictionaries are created, these are located in a different directory.
Stop and start tracetool whenever a change is made to the dictionary files. For more
information, see "Managing RADIUS and Diameter dictionaries" on page 177.

Service Controller 9.6.1-AAA October 12, 2012 Page 413


Chapter 9 Testing RADIUS Server configuration Network Access Guide

RequestInitiator, RequestHandler, and Direction fields


Figure 35 and Figure 36 on page 415 show how the RequestInitiator,
RequestHandler, and Direction fields indicate where the packet is coming from and
going to, relative to the RADIUS Server.
The Request Initiator field identifies the source of the access request. The Request
Handler field identifies the target of the access request.
The Direction field identifies whether the packet was incoming (sent from the
request initiator to the request handler) or outgoing (sent from the request handler
to the request initiator).
Figure 35: RADIUS as target of access-request

1$6 6HUYLFH&RQWUROOHU
,3 5$',866HUYHU
,3

7UDFH7RRORXWSXWIRU$FFHVV5HTXHVW
5HTXHVW,QLWLDWRU 
5HTXHVW+DQGOHU 
'LUHFWLRQ ,1

1$6 6HUYLFH&RQWUROOHU
,3 5$',866HUYHU
,3

7UDFH7RRORXWSXWIRU$FFHVV$FFHSW
5HTXHVW,QLWLDWRU 
5HTXHVW+DQGOHU 
'LUHFWLRQ 287

Page 414 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 9 Testing RADIUS Server configuration

Figure 36: RADIUS Server as proxy server

1$6 6HUYLFH&RQWUROOHU
,3 $FFHVV5HTXHVW 5$',866HUYHU
,3

7UDFH7RRORXWSXWIRU$FFHVV5HTXHVW
5HTXHVW,QLWLDWRU 
5HTXHVW+DQGOHU 
'LUHFWLRQ ,1
7UDFH7RRORXWSXWIRU3UR[\$FFHVV5HTXHVW
5HTXHVW,QLWLDWRU 
5HTXHVW+DQGOHU 
'LUHFWLRQ 287

5$',866HUYHU
,3

1$6 6HUYLFH&RQWUROOHU
,3 $FFHVV5HMHFW 5$',866HUYHU
,3

7UDFH7RRORXWSXWIRU$FFHVV5HMHFW
5HTXHVW,QLWLDWRU 
5HTXHVW+DQGOHU 
'LUHFWLRQ ,1
7UDFH7RRORXWSXWIRU3UR[\$FFHVV5HMHFW
5HTXHVW,QLWLDWRU 
5HTXHVW+DQGOHU 
'LUHFWLRQ 287

5$',866HUYHU
,3

Service Controller 9.6.1-AAA October 12, 2012 Page 415


Chapter 9 Testing RADIUS Server configuration Network Access Guide

Page 416 October 12, 2012 Service Controller 9.6.1-AAA


Configuring Network Address

10
Chapter 10
Chapter

Translation (NAT)

This chapter describes how to configure NAT on the Service Controller.


The topics are:
• Overview
• Configuration files
• Provisioning for NAT
• [Link] file
• Command line utilities
• SNMP
• Log messages

Service Controller 9.6.1-AAA October 12, 2012 Page 417


Chapter 10 Configuring Network Address Translation (NAT) Network Access Guide

Overview
IPv4 NAT provides the ability to allocate private IP addresses to devices and
perform IP address translation at the PDSN/HA. This conserves utilization of IP
address resources and avoids exhaustion of globally unique public IP addresses.
Multiple HAs use a single private IP pool. Different regions use the same private IP
pool but each HA in the region has unique private IPs within its own pool. The public
IP address space remains the same.
The Service Controller accepts NAT binding request messages from PDSN/HAs
and stores NAT information in the RMS. The RMS stores one or more NAT bindings
for each session.
When NAT support is enabled, the RMS supports the creation, deletion, and
querying of NAT binding records.
When queried for NAT sessions, the RMS queries the TimesTen database to
retrieve the latest NAT session that matches the search criteria. It uses the
User-Name, Domain, and User-Ip-Address found in the NAT session to find the
latest matching RADIUS session in the same TimesTen database. The RMS returns
a single compound session, made up of the NAT and RADIUS sessions, to the
RMS client. If there are no matching RADIUS sessions, only the NAT session is
returned.
If an exhaustive search is enabled, RMS queries for IP addresses that are not
found in the [Link] file searches for
• NAT sessions first if [Link] includes any NATed ranges.
• RADIUS sessions if [Link] does not include any NATed ranges.
• RADIUS sessions if the initial search for NAT sessions does not yield any
results.
The RMS supports NAT session queries by NATed IP and NAT port number.

Message flows
This section provides message flows for NAT binding.

NAT binding creation In Simple IP, the PDSN provides the NAT binding for a session. In Mobile IP, the HA
or update provides the NAT binding.
1 The Service Controller receives an accounting interim request from the PDSN/
HA.
2 Based on the accounting type Interim and the presence of the
SN1-NAT-Bind-Record AVP, the Service Controller determines the request is a
NAT binding request.
3 The Service Controller extracts AVPs/Sub-types from the NAT binding request
message including NAT-Loading-Factor, NAT-IP-Address,
NAT-Port-Block-Start, NAT-Port-Block-End, User-Name, Framed-IP-Address,
Event-Timestamp, and Port-Chunk-Alloc (set to alloc indicating it is a binding
creation).

Page 418 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 10 Configuring Network Address Translation (NAT)

4 The Service Controller increments the SNMP metrics tracking the total number
of NAT binding alloc requests and the total number of NAT binding requests
(allocs + de-allocs).
5 The Service Controller validates that the extracted Loading-Factor is supported.
6 The Service Controller validates the extracted NAT port range.
7 The Service Controller adds a NAT binding to RMS.
8 The Service Controller replies with an Accounting-Response to the PDSN/HA.
The RMS has a new NAT binding stored against the session.
Note The NAT-IPAddress, NAT-Loading-Factor, NAT-Port-Block-Start, and
NAT-Port-Block-End form a unique combination. If a new binding creation
request is received, if any of those four attributes are changed, a new
binding record is created. If any other attributes but those four are changed,
the existing binding record is updated.

Table 136: VSA sub-types and AVPs required for alloc requests

AVP/Sub-type Names Vendor

SN1-NAT-Bind-Record (NAT-IP-Address sub-type) STARENT

SN1-NAT-Bind-Record (NAT-Port-Block-Start sub-type) STARENT

SN1-NAT-Bind-Record (NAT-Port-Block-End sub-type) STARENT

SN1-NAT-Bind-Record (NAT-Port-Chunk-Alloc sub-type) STARENT

SN1-NAT-Bind-Record (NAT-Loading-Factor sub-type) STARENT

User-Name RADIUS

Framed-IP-Address RADIUS

Event-Timestamp RADIUS

NAT binding removal NAT bindings expire at the PDSN/HA that are managing them.
1 The Service Controller receives an accounting interim request from the PDSN/
HA
2 Based on the accounting type Interim and the presence of the
SN1-NAT-Bind-Record AVP, the Service Controller determines the request is a
NAT binding request.
3 The Service Controller extracts AVPs from the NAT binding request message
including NAT-Loading-Factor, NAT-IP-Address, NAT-Port-Block-Start,
NAT-Port-Block-End, User-Name, and Port-Chunk-Alloc (set to dealloc
indicating it is a binding removal).
4 The Service Controller increments the SNMP metrics tracking the total number
of NAT binding de-alloc requests and the total number of NAT binding requests
(allocs + de-allocs).

Service Controller 9.6.1-AAA October 12, 2012 Page 419


Chapter 10 Configuring Network Address Translation (NAT) Network Access Guide

5 The Service Controller validates that the extracted Loading-Factor is supported


by the AAASC.
6 The Service Controller validates the extracted NAT port range.
7 The Service Controller removes the specified NAT binding from the RMS.
8 The Service Controller replies with an Accounting-Response to the PDSN/HA.
The NAT binding session is removed from the RMS.

Table 137: VSA subtypes and AVPs required for de-alloc requests

AVP/Sub-type Names Vendor

SN1-NAT-Bind-Record (NAT-IP-Address subtype) STARENT

SN1-NAT-Bind-Record (NAT-Port-Block-Start subtype) STARENT

SN1-NAT-Bind-Record (NAT-Port-Block-End subtype) STARENT

SN1-NAT-Bind-Record (NAT-Port-Chunk-Alloc subtype) STARENT

SN1-NAT-Bind-Record (NAT-Loading-Factor subtype) STARENT

User-Name RADIUS

Session stop The PDSN/HA stops the session by providing the Service Controller with an
accounting stop message.
1 The Service Controller receives an accounting stop request from the PDSN.
2 The Service Controller sends a message to RMS to remove the session.
3 RMS removes the session and all stored NAT bindings for that user.
4 The Service Controller responds with an Accounting-Response to the PDSN.
The RMS no longer contains the session or its associated NAT bindings.

Tethered device Tethered devices, for example, a Blackberry connected as a dongle to a laptop,
support despite being provisioned against a NATed IP Pool, should not be subject to NAT.
To solve this problem, when a request from a tethered device is processed, a
provisioned Framed-Pool AVP is removed from an Access-Accept message if its
value matches one of the configured NAT pools in the [Link] file.
A policy line for Access-Requests is configured with a condition to match the DUN
NAI (tethered devices). The policy line must define a myVar variable that has the
same name as the one defined in the [Link] file. For example:
User-Name Contains @[Link] AssignVar
myVar=NATTethered:
When an access request comes from a tethered device, the provisioned instance of
the Framed-Pool AVP that represents NATed IP pools is removed from the
Access-Accept message.
This is supported in DMULocalAA and CDMA2000LocalAA policy actions.

Page 420 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 10 Configuring Network Address Translation (NAT)

For configuration information, see "[Link]" on page 421.


1 PDSN/HA sends a RADIUS Access-Request message to the Service Controller
for the tethered device using a DUN NAI.
2 Based on the NAI, the Service Controller enters a specific AssignVar policy
action that defines a myVar variable with a name that is configured in the
[Link] file.
3 Either a DMULocalAA or CDMA2000LocalAA policy action is executed.
4 The Service Controller finds that the defined myVar name in [Link] has
been initialized in the policy line.
5 The Service Controller removes the provisioned Framed-Pool AVP if it contains
a string that matches one of the configured NAT pools in the [Link] file
from the Access-Accept message.

Configuration files
The following files are required for NAT:
• [Link]
• [Link]

[Link]
The [Link] file, located in /opt/aaasc/config/radius, stores NAT
configurations and is used to enable or disable the processing of NATed requests.
For an example of the file, see the [Link] located in /opt/aaasc/radius.
Send the file a HUP signal after making any changes.
Table 138 describes the [Link] attributes.

Table 138: [Link] attributes

Element Value Description

NATConfiguration

enabled String Set to ‘yes’ enable or ‘no’ to disable NAT processing


Default = no functionality. An attribute of NATConfiguration.

LoadingFactors The list of supported loading factors. A child element of


NATConfiguration.

Service Controller 9.6.1-AAA October 12, 2012 Page 421


Chapter 10 Configuring Network Address Translation (NAT) Network Access Guide

Table 138: [Link] attributes (continued)

Element Value Description

LoadingFactor Each loading factor must have a unique value. A child element
of LoadingFactors.
Note For the collection of SNMP statistics, if a loading factor is
removed from [Link] and the RADIUS Server is
HUPed, the SNMP metric for the loading factor remains
and is not removed until the RADIUS Server is restarted.
If the loading factor is added back in to [Link],
the total number of NAT binding requests continues to be
incremented.

value Integer (0-65535) The unique value of the loading factor. An attribute of
LoadingFactor.
Required.

NATPools The list of supported NAT pools. A child element of


NATConfiguration.
This must be provisioned when TetheredMode is provisioned
and NAT is enabled.
Optional.

NATPool Each NAT Pool must have a unique value. A child element of
NATPools.
At least one NAT Pool must be configured if TetheredMode is
provisioned and NAT is enabled.

value String (1-253) The unique name of the supported NAT pool. An attribute of
NATPool.
Required.

TetheredMode Configure to process requests from tethered devices. A child


element of NATConfiguration.

myVarName String Required to execute on requests from tethered devices. An


Default = attribute of TetheredMode.
NATTethered

[Link] <NATConfiguration enabled=”yes”>


example <LoadingFactors>
<LoadingFactor value=”1”>
<LoadingFactor value=”50”>
</LoadingFactors>
<NATPools>
<NATPool value=”MIP_Private”/>
</NATPools>
<TetheredMode myVarName=”NATTethered”/>
</NATConfiguration>

Page 422 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 10 Configuring Network Address Translation (NAT)

[Link]
The RMS stores one or more NAT bindings per session. At a minimum, each
binding contains a login name, domain, loading factor, user IP address, NAT IP
address, port chunk start, port chunk end, and event timestamp.
To support the creation, deletion, and querying of NAT binding records, NAT binding
must be enabled in the [Link] file. NAT audit must also be enabled if the NAT
feature is enabled in RMS.
For more information, see “RMS Configuration” in the Service Controller: Resource
Management Server Guide.

Loading factor The loading factor should not be changed against previously established and
populated IP range. If the loading factor is increased, the port range decreases; if
the loading factor is decreased, the port range increases. An IP range with a new
loading factor should point to a different RMS.
The following examples describe what may occur if the loading factor is changed
and a second session is created:
• When there are two sessions with different port ranges, then both are logged
within the RMS.
– Session 1: NATPortStart=1, NATPortEnd=100, and NATIpAddr=[Link]
– Session 2: NATPortStart=200, NATPortEnd=300, and
NATIpaddr=[Link]
• When there are two sessions where the new session has a port range that is
within the older session, then the older session is overwritten with latest
session details.
– Session 1: NATportStart=1, NATPortEnd=100, and NATIpAddr=[Link]
– Session 2: NATPortStart=40, NATPortEnd=100, and NATIpAddr=[Link]
with different user and same domain
• When there are two sessions where the new session has a port range that
encloses the port range of the older session, the RMS creates a second
session and does not overwrite the first. The APC rejects the request as
ambiguous.
– Session 1: NATportStart=40 and NATportEnd=100
– Session 2: NATportStart=1 and NATportEnd=100

Provisioning for NAT


To enable NAT functionality, provision PDSN/HAs as STARENT clients. The value
of the Framed-Pool AVP in the RADIUS ConnectionService service profile must
contain the string “NAT”. This is returned to the PDSN/HA upon successful
authentication by the Service Controller and triggers the PDSN/HA to send a NAT
binding request.
For more information, see “Managing service profiles” in the Service Manager:
Subscriber Provisioning Guide for AAA.

Service Controller 9.6.1-AAA October 12, 2012 Page 423


Chapter 10 Configuring Network Address Translation (NAT) Network Access Guide

[Link] file
Table 139 lists the NAT VSA and sub-types in the [Link] file:
Note There are two STARENT dictionaries. Make sure the correct one is used.
For more information, see "STARENT and CISCO dictionaries" on page
180.

Table 139: NAT VSA and sub-types in the [Link] file

AVP/Sub-type Names Vendor ID Type Sub-type Datatype

SN1-NAT-Bind-Record 8164 216

Sub-types

NAT-IP-Address 8164 216 1 ipaddr

NAT-Port-Block-Start 8164 216 2 integer16

NAT-Port-Block-End 8164 216 3 integer16

NAT-Port-Chunk-Alloc 8164 216 4 integer8

NAT-Correlation-Id 8164 216 5 string

NAT-Loading-Factor 8164 216 6 integer16

NAT-Binding-Timer-Value 8164 216 7 integer

SN1-NAT-IP-Address 8164 217

SN1-NAT-Port 8164 218

SN1-NAT-CoA-ACK 8164 246

Framed-IP-Address 8164 246 1 ipaddr

NAT-IP-Address 8164 246 2 ipaddr

NAT-Port-Block-Start 8164 246 3 integer16

NAT-Port-Block-End 8164 246 4 integer16

Acct-Session-Id 8164 246 5 string

User-Name 8164 246 6 string

NAT-Correlation-Id 8164 246 7 string

Page 424 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 10 Configuring Network Address Translation (NAT)

Command line utilities


The addSession, delSessions, and listSessions command line utilities support NAT.
For more information about the command line utilities, see “RMS operation” in the
Service Controller: Resource Management Server Guide.

addSession
addSession requires -sessiontype NAT and supports the following options: -i, -d,
-ip, -natip, -natportstart, -natportend, and -natloadingfactor.
For example:
addSession -rms 0 -sessiontype NAT -l bshah4 -d [Link]
-ip [Link] -natip [Link] -natportstart 1 -natportend 50
-natloadingfactor 1
addSession -rms 0 -sessiontype NAT -l bshah4 -d [Link]
-ip [Link] -natip [Link] -natportstart 51 -natportend 100
-natloadingfactor 1

delSessions
delSessions requires -sessiontype NAT and supports the following options: -i, -d,
-ip, -natip, -natportstart, -natportend, and -natloadingfactor.
delSessions supports the AVP combinations listed in Table 140.
For example:
delSessions -rms 0 -sessiontype NAT -ip [Link]
delSessions -rms 0 -sessiontype NAT -natip [Link]
-natloadingfactor 1
delSessions -rms 0 -sessiontype NAT -l bshah4 -d [Link]
Note All NAT bindings that match the login name and domain are deleted.

listSessions
listSessions requires -sessiontype NAT and supports the following options: -i, -d,
-ip, -natip, -natport, and -natloadingfactor.
listSessions supports the AVP combinations listed in Table 140.
For example:
listSessions -rms 0 -sessiontype NAT -natip [Link] -natport
51
listSessions -rms 0 -sessiontype NAT -l bshah4 -d [Link]

Service Controller 9.6.1-AAA October 12, 2012 Page 425


Chapter 10 Configuring Network Address Translation (NAT) Network Access Guide

listSessions -rms 0 -sessiontype NAT -l \*

Table 140: AVP combinations for queries

AVP combinations for queries

login_name, domain

login_name

user_ip_addr

nat_ip_addr, nat_port, nat_loading_factor

nat_ip_addr, nat_port

nat_ip_addr, nat_loading_factor

nat_ip_addr

SNMP
The NAT feature supports SNMP additions for radius accounting clients. The MIB
variables for NAT bindings are:
• radiusAcctServerNATBindingAllocs ([Link].4.1.3631.[Link].5.1.6)
• radiusAcctServerNATBindingDeallocs ([Link].4.1.3631.[Link].5.1.7)
• radiusAcctServerNATBindingRequests ([Link].4.1.3631.[Link].5.1.8)
The radiusAuthenticationServer branch has an OID of [Link].4.1.3631.[Link].
• radiusAuthenticationServerNATTetheredRequests ([Link].4.1.3631.[Link].1)
For more information about these variables, see “BW-RADIUS MIB” in the
Bridgewater SNMP Guide.

Log messages
System logs are logged using the RADSYS family.
Operational logs are logged using the RADOP family.

Page 426 October 12, 2012 Service Controller 9.6.1-AAA


DAL Query Caching

11
Chapter 11
Chapter

This chapter provides an overview of DAL Query Caching and how to configure the
[Link] file.
The topics are:
• DAL Query Caching overview
• [Link] file
• Enabling and disabling DAL Query Caching
• Configuration guidelines
• DAL cache metrics

Service Controller 9.6.1-AAA October 12, 2012 Page 427


Chapter 11 DAL Query Caching Network Access Guide

DAL Query Caching overview


The DAL Query Caching feature supports large networks with high demands on the
database by providing:
• increased RADIUS authentication throughput
• reduced RADIUS demand on the database server
• reduced CPU consumption on the database server
This feature provides a shared library, in the Cached Oracle (CORA) DAL, that
supports the query caching functions required by the radiusd process.
Note The query cache is not a copy of the database and has no refresh or clear
functionality. The cache exists only as long as RADIUS is operating.
The CORA DAL library connects to a single version of the database schema only
and caches Oracle database queries by thread.

When to use DAL Query Caching


The DAL Query Caching feature is for RADIUS applications only.
Performance gains may be obtained by using DAL Query Caching, if:
• the database has over a million rows in any table
• there are fewer than 1000 frequently used service profiles. In this case, caching
may provide a performance gain at the DEF context.
• there are fewer than 1000 frequently used domains, domain aliases, and
domain groups combined. In this case, caching may provide a performance
gain at the DOM and DOM_GROUP contexts.
• there are fewer than 1000 frequently used organizations and organization
groups combined. In this case, caching may provide a performance gain at the
ORG and ORG_GROUP contexts.
• there are fewer than 1000 frequently used accounts and account groups, and
you use accounts. In this case, caching may provide a performance gain at the
ACCOUNT and ACCOUNT_GROUP contexts.
• there are fewer than 1000 frequently used user groups. In this case, caching
may provide a performance gain at the USR_GROUP context.
• there are fewer than 1000 frequently used users. In this case, caching may
provide a performance gain at the USR context.
These values are representative only. For example, cache data at the ORG level if
there are a million organizations but typically only ten are used. Each case is
dependant on the type of traffic in the network.

Page 428 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 11 DAL Query Caching

Guidelines for DAL Query Caching


In cases where the entity value is less than or equal to 1000, the maximum value for
cachemaxentries, apply the following guideline:
cachmaxmemory for each context cached must be greater than or equal to the
number of frequently used entities * number of attributes * 400 bytes
In the case of the DEF, DOM, and USR contexts, additional memory is required, as
listed in Table 141.

Table 141: Additional memory requirements for DEF, DOM, and USR contexts

Context Additional memory required

DEF Number of frequently used service profiles * 200 bytes

DOM Number of frequently used domains * 200 bytes

USR Number of frequently used users * 600 bytes

The amount of memory used is cumulative through the contexts. For example, if
caching at three contexts, include the attributes for the three contexts.

Example For a configuration with:


• 10 service profiles, each with 100 DEF attributes
• 10 domains with no attributes
• 1 domain group with no attributes
• 0 accounts
• 0 account groups
• 10 organizations with 10 attributes
• 1 organization group with no attributes
• 10 user groups with 10 attributes
• 100,000,000 users with 1 attribute
The candidates to cache, those with 1000 entities or fewer, are: DEF, DOM,
DOM_GROUP, ORG, ORG_GROUP, and USR_GROUP.
The entities that are not candidates to cache are: ACCT (none), ACCT_GROUP
(none), and USER (greater than 1000).
From the context bitmap shown in Table 142 on page 430, cachecontextbitmap
= DEF + DOM + DOM_GROUP + ORG + ORG_GROUP + USR_GROUP
= 256 + 64 + 128 + 16 + 32 + 2
= 498
= 111110010 (binary)
In this example, the cached entries are each approximately ten. Using the number
of entries for the largest frequently used entry, set cachemaxentries = 10.

Service Controller 9.6.1-AAA October 12, 2012 Page 429


Chapter 11 DAL Query Caching Network Access Guide

In this example, there is one context with 100 attributes and ten entries, and five
contexts with ten or fewer attributes with ten or fewer entries. Finally, account for
the additional service profiles and domains.
cachmaxmemory for each context cached must be greater than or equal to the
number of frequently used entities * number of attributes * 400 bytes
cachemaxmemory
= 1 context * (10 service profiles * 100 DEF attributes * 400 bytes) +
5 contexts (DOM, DOM_GROUP, ORG, ORG_GROUP, USR_GROUP)
* (10 entities * 10 attributes * 400 bytes) +
10 (DEF: service profile) contexts * 200 bytes +
10 (DOM) contexts * 200 bytes +
= 400000 + 200000 + 2000 + 2000
= 604,000 bytes
In this example, the constants are the size of the structures rounded to the nearest
100.

[Link] file
The [Link] file specifies a single database, using the global database name, with
which the RADIUS Server connects using a username and password. The
username and password are set when the database is installed.
Note The [Link] file is read at startup only.
The [Link] file can list multiple databases for backup. If the primary database
fails, the RADIUS Server connects to the next database listed in the file.
Modify this file only if the location of a database changes, relative to the RADIUS
Server, or the database username or password changes. Do not leave the
database field of the [Link] file blank.
Table 142 describes the [Link] parameters. Bridgewater Systems recommends
using the default values shown.

Table 142: [Link] parameters

Parameter Value Description

cachemaxentries Integer Maximum number of entries, for each


Default = 10 cached query, that are stored in the cache.
After this number is reached, the cache
Maximum = 1000
removes aged cache entries. Optional.

cachemaxmemory Integer Maximum memory consumption, in bytes,


Default = 1000000 of the cache. If cachemaxmemory is
reached before cachemaxentries is
reached, then fewer than
cachemaxentries are used. Optional.

Page 430 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 11 DAL Query Caching

Table 142: [Link] parameters (continued)

Parameter Value Description

cachecontextbitmap Integer 9-bit bitmap that sets the context to cache


Default = 506 attributes, services, and entities. Optional.
The values are:
• DB_CONTEXT_NONE0
• DB_CONTEXT_USER1
• DB_CONTEXT_USER_GROUP2
• DB_CONTEXT_ACCT4
• DB_CONTEXT_ACCT_GROUP8
• DB_CONTEXT_ORG16
• DB_CONTEXT_ORG_GROUP32
• DB_CONTEXT_DOM64
• DB_CONTEXT_DOM_GROUP128
• DB_CONTEXT_DEF256

cachetimetolive Integer Time, in seconds, an entry remains in the


Default = 500 cache before a forced refresh is
performed. Optional.

retryinterval Integer Time, in seconds, allotted to using the


Default = 300 secondary database before attempting to
reconnect to the primary. If a secondary
database is not specified, set this value to
an acceptable amount of time for RADIUS
to retry its database connection so the
RADIUS outage is less than 5 minutes.
Optional.

username Must be r6 Database schema owner. Required.

password Text Password of the r6 user. Required.

database Text (dbname) Global database name of the Service


Controller database. Required.

Example [Link] file


There must be at least one line separating the accounting and database
configuration parameters. The database configuration parameters—username,
password, database—must be at the end of the file. To configure for failover, the
parameters can be repeated for the failover database. Make sure the correct order
is maintained.
# This file contains Bridgewater database config info.
#
# Number of seconds before retrying the primary connection
# Default value is 300
# retryinterval=300
#
# Cache Tuning:
# cachemaxentries defines the number of entries for each

Service Controller 9.6.1-AAA October 12, 2012 Page 431


Chapter 11 DAL Query Caching Network Access Guide

# cached query that will be stored in the cache.


cachemaxentries=10
# cachemaxmemory defines the upper bound for the total
# memory consumption of the cache
cachemaxmemory=1000000
# cachecontextbitmap defines a 9-bit context bitmap for the
# context at which to cache attributes, services, and
# entities.
cachecontextbitmap=506
# cachetimetolive is a decimal number for the amount of
# time in seconds an entry will remain before it will be
# aged out
cachetimetolive=500

# Database config
username=r6
password=r6
database=wsp

Enabling and disabling DAL Query Caching


For package requirements and installation procedures, see the Bridgewater
Installation Reference Guide.

To enable DAL Query Caching


Edit wsradius and load the CORA library.
Note This procedure is only required for updating a system. If this is an initial
installation, continue with the procedures described in the Bridgewater
Installation Reference Guide to install any additional required packages.
1 In wsradius, add the CORA library by changing libws_dal_ora.so.3 to
libws_dal_cora.so.3.
2 Add the cdal database configuration file path to the end of the radiusd startup
command:
-c $PRODUCT_DIR/config/[Link]
3 Add $PRODUCT_DIR/cdal to the LD_LIBRARY_PATH definition.
4 Stop RADIUS:
/etc/init.d/wsradius stop
5 Start RADIUS:
/etc/init.d/wsradius start

Page 432 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 11 DAL Query Caching

To disable DAL Query Caching


1 Remove [Link] from the startup file so RADIUS can pick up [Link]:
- remove -c $PRODUCT_DIR/config/[Link]
2 Remove [Link] from /opt/aaasc/config/env/.
3 Stop RADIUS:
/etc/init.d/wsradius stop
4 Start RADIUS:
/etc/init.d/wsradius start

Configuration guidelines
This section describes the design considerations for optimizing the DAL Query
Caching feature. The topics are:
• General
• cachemaxentries
• cachemaxmemory
• cachecontextbitmap
• cachetimetolive

General
Only cache entities if their highly-used attributes reasonably fit into a cache. For
example, in a network with millions of users, each with many attributes at the user
level, it is not reasonable to cache the USER context. The overhead of moving
results in and out of the cache for a low cache hit-rate decreases performance. On
the other hand, in a network with fewer than ten organizations, each with fewer than
ten attributes at the ORG context, it is reasonable to cache the ORG context. In this
case, if cachemaxentries is greater than ten, all of the organization level attributes
can be cached.

cachemaxentries
The cachemaxentries parameter is a single value shared with the queries. If
cachemaxentries is exceeded, the next incoming cache entry replaces the oldest
cache entry.
The cache results are shared among the RADIUS threads. Set cachemaxentries to
greater than or equal to the number of threads, if the data set is larger than the
number of threads.

Service Controller 9.6.1-AAA October 12, 2012 Page 433


Chapter 11 DAL Query Caching Network Access Guide

In general, keep enough entries for each query in the cache to optimize
performance:
1 Calculate cachemaxentries to fit the contents, based on an understanding of
the data.
2 Set cachemaxmemory to fit the context and data.
For example, if caching at the domain context, set cachemaxentries to a value
greater than or equal to the number of domains. Even if the number of domains is
high, but only a few are used, then caching this query is beneficial, since the
commonly used domains remain in the cache.

cachemaxmemory
The value of cachemaxmemory is the upper boundary for memory usage. Each
query maintains an upper limit for its memory usage in the cache.

cachecontextbitmap
Whether the query is cached depends on the context set in cachecontextbitmap.
Table 143 describes the cachecontextbitmap settings.

Table 143: cachecontextbitmap values

Name Value Description

DB_CONTEXT_NONE 0 If the context is set to zero, the cache is initialized but not used. In this case,
consider using the non-cached DAL.

DB_CONTEXT_USER 1 In general, do not set this context. If set , users are cached for authentication
and all the user level attributes are cached. With more than a few thousand
users, caching at this level reduces performance.

DB_CONTEXT_USER_GROUP 2 Set to cache user group attributes.

DB_CONTEXT_ACCT 4 Set to cache account attributes.

DB_CONTEXT_ACCT_GROUP 8 Set to cache account group attributes.

DB_CONTEXT_ORG 16 Set to cache organization attributes.

DB_CONTEXT_ORG_GROUP 32 Set to cache organization group attributes.

DB_CONTEXT_DOM 64 Set to cache the domain alias information with the domain level attributes.
This is recommended if the number of customer domains is low (in the
hundreds), even if the alias table is empty.

DB_CONTEXT_DOM_GROUP 128 Set to cache domain group attributes.

DB_CONTEXT_DEF 256 Set to cache the service profiles and the default level attributes for a user’s
profile set.
Consider this option if a small number of service profiles are defined for each
user and the total number of profiles is relatively small for many users.

Page 434 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Chapter 11 DAL Query Caching

When a query is set to be cached by cachecontextbitmap, the memory is created


for the cache. The amount of memory needed to cache the query is dependant on
cachemaxentries and cachemaxmemory. In general, cachemaxmemory is divided
among the queries to be cached, and up to cachemaxentries can be cached for that
query.

cachetimetolive
Each entry is tagged with a cachetimetolive. This value sets the maximum time that
the cached results are valid. When this value is reached, the cached results are no
longer used, the query goes to the database instead, and the cache is updated with
the result.
When the system uses the cache, provisioning changes to the database are not
noticed by RADIUS as long as the entry remains in the cache. When an entry in the
cache reaches cachetimetolive, the entry is discarded. This forces RADIUS to
query the database the next time it needs this data.
For example, if cachetimetolive is set to 300 seconds, then RADIUS queries the
database at least every 300 seconds. However, RADIUS may need to query the
database more often if the entry is removed from the cache before it times out. This
can happen if the cachemaxmemory is exceeded or if cachemaxentries is
exceeded and the oldest entry in the cache is removed to make room for another
entry.
Set cachetimetolive greater than the time it takes to replicate the Profile database.

DAL cache metrics


Use the bsig tool to signal the RADIUS Server to log DAL cache statistics. The
RADIUS Server is the only application that handles signals sent by the bsig tool.
The tool is installed to the /opt/aaasc/utilities/bsig directory by the BWSaaaco
package.
The BWScdal package must be installed because only the CDAL library is capable
of logging cache statistics.
Note If a signal is sent to an application that does not support bsig signals, the
application may terminate.

Usage
./bsig -h | -a <action> <PID>
where
-h prints the message and exits
-a specifies the action to execute
<action> is the action to execute. The only action available is dalstats
<PID> is the process ID of the application to be signaled

Service Controller 9.6.1-AAA October 12, 2012 Page 435


Chapter 11 DAL Query Caching Network Access Guide

For example, as root


/opt/aaasc/.cshrc
./bsig -a dalstats ‘pgrep radiusd’
When the RADIUS server receives a signal to log DAL statistics, the following is
logged in syslog (notice the NTCE log from RADIUS: the DAL statistics action is
indicated by integer value 100):
Jun 22 14:21:04 kansparc5125 radiusd[19342]: [ID 896497 [Link]] NTCE
RADSYS(671) SIGRTMAX signal detected: Integer with value (100) was passed
along with the signal.
Jun 22 14:21:04 kansparc5125 radiusd[19342]: [ID 549945 [Link]] INFO
RADSYS(2406) GetUserProfileAttrStatement4_e Size: 498995, Used: 0, Requests:
0, Fetch: 0, Found: 0, Busy: 0, Error: 0, Replace: 0, Remove: 0, Not Cached: 0
Jun 22 14:21:04 kansparc5125 radiusd[19342]: [ID 549945 [Link]] INFO
RADSYS(2406) WS_GetUserProfiles1_e Size: 498995, Used: 0, Requests: 0,
Fetch: 0, Found: 0, Busy: 0, Error: 0, Replace: 0, Remove: 0, Not Cached: 0
Jun 22 14:21:04 kansparc5125 radiusd[19342]: [ID 549945 [Link]] INFO
RADSYS(2406) getCanonicalDomain_v1_e Size: 810, Used: 0, Requests: 0, Fetch:
0, Found: 0, Busy: 0, Error: 0, Replace: 0, Remove: 0, Not Cached: 0
Jun 22 14:21:04 kansparc5125 radiusd[19342]: [ID 549945 [Link]] INFO
RADSYS(2406) GetDom_e Size: 200, Used: 0, Requests: 0, Fetch: 0, Found: 0,
Busy: 0, Error: 0, Replace: 0, Remove: 0, Not Cached: 0
Jun 22 14:21:04 kansparc5125 radiusd[19342]: [ID 549945 [Link]] INFO
RADSYS(2406) GetOrg_e Size: 1000, Used: 0, Requests: 0, Fetch: 0, Found: 0,
Busy: 0, Error: 0, Replace: 0, Remove: 0, Not Cached: 0

Page 436 October 12, 2012 Service Controller 9.6.1-AAA


RADIUS accounting record
Appendix

A
Appendix A

generation logic

This appendix provides an overview and examples of RADIUS accounting record


generation logic.
The topics are:
• Accounting record generation logic overview
• Terms used in the flow charts
• RADIUS accounting pending record
• RADIUS accounting start record
• RADIUS accounting interim record
• RADIUS accounting stop record

Service Controller 9.6.1-AAA October 12, 2012 Page 437


Appendix A RADIUS accounting record generation logic Network Access Guide

Accounting record generation logic overview


This appendix provides flow charts to illustrate when RADIUS generates accounting
records based on the RADIUS message types: start, pending, interim, and stop.
These flow charts also illustrate how the backup method field is populated in these
records.
Note These flow charts illustrate the RADIUS logic only. If the Revenue Collector
and Formatter is installed and the RADIUS Correlation functionality
enabled, the records and backup types are further manipulated by the
Revenue Collector and Formatter. For more information about the RADIUS
Correlation process, see the Accounting Framework Guide.

Terms used in the flow charts


Table 144 defines the terms used in the flow charts.

Table 144: Flow chart legend

Term Definition

BM The backup method type. RADIUS can set to the following types:
C - generated when an RMS product is not deployed.
L - incomplete records requiring a lookup in the provision data using the entity ID and
context.
F - the record contains complete accounting data.
I - Ignore. This is an indication to RADIUS Correlation to ignore this record.

U A RADIUS configuration parameter is not specified.

Write Acct The policy writeAccounting action modifier is set to yes or no.

AC? An Access control is specified for the subscriber.

RMS Reachable? The RMS is deployed and is tracking session information.


Accounting using RMS info?

Class? The class attribute is available from the RADIUS client (configured in the [Link] file).

AcctStartAttrib configured? The AcctStartAttribute is configured in the [Link] to populate the RADIUSATTR field.

vendor write behavior The WriteAcctPendingRecord, WriteAcctStartRecord, WriteAcctInterimRecord, or


WriteAcctStopRecord parameter is set in the [Link].

Page 438 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Appendix A RADIUS accounting record generation logic

RADIUS accounting pending record


Figure 37 shows the RADIUS logic for generating an accounting pending record
and how the backup method is populated.
Figure 37: RADIUS accounting pending record generation

6WDUW

%0 &

506/RJLF/D\HU

&ODVV" <(6 %0 /

12

$FFWXVLQJ
506 9HQGRU
$&" <(6 5HDFKDEOH"
<(6 6XSSRUW"
12 506LQIR 
<"

<(6
12 <(6

%0QRW
12 12 %0 ,
HTXDOWR&"

<(6

%0 )
12 9HQGRU
:ULWH$FFRXQWLQJ/RJLF/D\HU :ULWH
12 ZULWH <(6
EHKDYLRU UHFRUG

'RQRW
ZULWH 8
:ULWH$FFW
UHFRUG <HV $FFW6WDUW$WWULE
<(6 %0 &
SROLF\" RU8 FRQILJXUHG"

'RQH
12

Service Controller 9.6.1-AAA October 12, 2012 Page 439


Appendix A RADIUS accounting record generation logic Network Access Guide

RADIUS accounting start record


Figure 38 shows the RADIUS logic for generating an accounting start record and
how the backup method is populated. RADIUS accounting start record generation
Figure 38: RADIUS logic for generating an accounting start record

6WDUW

%0 &

506/RJLF/D\HU

9HQGRU
<(6 %0 /
VXSSRUW

12

$FFWXVLQJ
506 9HQGRU
12 5HDFKDEOH"
<(6 12 506LQIR 
6XSSRUW"
<"

<(6

<(6 12

%0 ,

:ULWH$FFRXQWLQJ/RJLF/D\HU

:ULWH$FFW <(6 $FFW6WDUW$WWULE


<(6 %0 &
SROLF\" RU8 FRQILJXUHG"

12

9HQGRU
:ULWH
12 ZULWH <(6
EHKDYLRU UHFRUG

12
8
<(6

:ULWH$FFW
SROLF\"
12
'RQRW
ZULWH
UHFRUG
12RU8

%0QRW
<(6 HTXDOWR
&"

'RQH

Page 440 October 12, 2012 Service Controller 9.6.1-AAA


Network Access Guide Appendix A RADIUS accounting record generation logic

RADIUS accounting interim record


Figure 39 shows the RADIUS logic for generating an accounting interim record and
how the backup method is populated.
Figure 39: RADIUS accounting interim record generation

6WDUW

%0 &

506/RJLF/D\HU

9HQGRU
<(6 %0 /
VXSSRUW

12

%0 /DQG
12 506
5HDFKDEOH"

<(6 %0 )

:ULWH$FFRXQWLQJ/RJLF/D\HU

:ULWH$FFW <(6 $FFW6WDUW$WWULE


<(6 %0 &
SROLF\" RU8 FRQILJXUHG"

12

9HQGRU
12 12 ZULWH 8
EHKDYLRU

'RQRW
ZULWH <(6
UHFRUG
:ULWH
UHFRUG

'RQH

Service Controller 9.6.1-AAA October 12, 2012 Page 441


Appendix A RADIUS accounting record generation logic Network Access Guide

RADIUS accounting stop record


Figure 40 shows the RADIUS logic for generating an accounting stop record and
how the backup method is populated.
Figure 40: RADIUS accounting stop record generation

6WDUW

%0 &

506/RJLF/D\HU

9HQGRU
<(6 %0 /
VXSSRUW

12

%0 &
506 &ODVV 1DQG
12 5HDFKDEOH"
<(6 $FFRXQWLQJ <(6 %0 ,
XVLQJ506
LQIR <"

12
%0QRW
%0 ) <(6 HTXDOWR&"

12

:ULWH$FFRXQWLQJ/RJLF/D\HU

:ULWH$FFW <(6 $FFW6WDUW$WWULE


<(6 %0 &
SROLF\" RU8 FRQILJXUHG"

12

9HQGRU
12 12 ZULWH 8
EHKDYLRU

'RQRW
ZULWH <(6
UHFRUG
:ULWH
UHFRUG

'RQH

Page 442 October 12, 2012 Service Controller 9.6.1-AAA


©1997-2012
Bridgewater Systems Corporation
All rights reserved.

You might also like