Cisco ASR1002-5G-SHA/K9 Software Guide - Page 215

Enhancing the Scalability of Per-User Configurations

Page 215 highlights

Chapter 6 Broadband Scalability and Performance Using the cisco-avpair="lcp:interface-config" RADIUS Attribute Before configuring the virtual access subscriber interface using the lcp:interface-config command, configure the aaa policy interface-config allow-subinterface command. If the subinterface is not configured, the following error message is displayed when creating a session with one of the RADIUS attributes: *Mar 13 22:04:03.358: %FMANRP_ESS-4-FULLVAI: Session creation failed due to Full Virtual-Access Interfaces not being supported. Check that all applied Virtual-Template and RADIUS features support Virtual-Access sub-interfaces. swidb= 0x7FA35A42F218, ifnum= 30 To enhance the scalability of per-user configurations, in many cases, different Cisco AV-pairs are available to place the subscriber interface in a Virtual Routing and Forwarding (VRF) instance or to apply a policy map to the session. For example, use the ip:vrf-id and ip:ip-unnumbered VSAs to reconfigure a user's VRF. For information about enhancing scalability see, "Enhancing the Scalability of Per-User Configurations" section on page 6-7. Enhancing the Scalability of Per-User Configurations To enhance scalability of per-user configurations without changing the router configuration, use the ip:vrf-id and ip:ip-unnumbered RADIUS attributes. These per-user vendor-specific attributes (VSAs) are used to map sessions to VRFs and IP unnumbered interfaces. The VSAs are applied to virtual access subinterfaces and are processed during PPP authorization. The ip:vrf-id attribute is used to map sessions to VRFs. Any profile that uses the ip:vrf-id VSA must also use the ip:ip-unnumbered VSA to install IP configurations on the VAI that is to be created. The PPP that is used on a VAI to be created requires the ip:ip-unnumbered VSA. An Internet Protocol Control Protocol (IPCP) session is not established if IP is not configured on the interface. You must configure either the ip address command or the ip unnumbered command on the interface so that these configurations are present on the VAI that is to be created. However, specifying the ip address and ip unnumbered commands on a virtual template interface is not required because pre-existing IP configurations, if any, are removed when the ip:ip-vrf VSA is installed on the VAI. Therefore, any profile that uses the ip:vrf-id VSA must also use the ip:ip-unnumbered VSA to install IP configurations on the VAI that is to be created. These per-user VSAs can be applied to VAIs. Therefore, the per-user authorization process does not require the creation of full VAIs, which improves scalability. Setting the VRF and IP Unnumbered Interface Configurations in User Profiles Although the Cisco ASR 1000 Series Router continues to support the lcp:interface-config VSA, the ip:vrf-id and ip:ip-unnumbered VSAs provide another way to set the VRF and IP unnumbered interface configurations in user profiles. The ip:vrf-id and ip:ip-unnumbered VSAs have the following syntax: Cisco:Cisco-AVpair = "ip:vrf-id=vrf-name" Cisco:Cisco-AVpair = "ip:ip-unnumbered=interface-name" You should specify only one ip:vrf-id and one ip:ip-unnumbered value in a user profile. However, if the profile configuration includes multiple values, the Cisco ASR 1000 Series Router applies the value of the last VSA received, and creates a virtual access subinterface. If the profile includes the lcp:interface-config VSA, the router always applies the value of the lcp:interface-config VSA. OL-16506-10 Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide 6-7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378

6-7
Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide
OL-16506-10
Chapter 6
Broadband Scalability and Performance
Using the cisco-avpair="lcp:interface-config" RADIUS Attribute
Before configuring the virtual access subscriber interface using the
lcp:interface-config
command,
configure the
aaa policy interface-config allow-subinterface
command.
If the subinterface is not configured, the following error message is displayed when creating a session
with one of the RADIUS attributes:
*Mar 13 22:04:03.358: %FMANRP_ESS-4-FULLVAI: Session creation failed due to Full
Virtual-Access Interfaces not being supported. Check that all applied Virtual-Template and
RADIUS features support Virtual-Access sub-interfaces. swidb= 0x7FA35A42F218, ifnum= 30
To enhance the scalability of per-user configurations, in many cases, different Cisco AV-pairs are
available to place the subscriber interface in a Virtual Routing and Forwarding (VRF) instance or to
apply a policy map to the session. For example, use the ip:vrf-id and ip:ip-unnumbered VSAs to
reconfigure a user’s VRF. For information about enhancing scalability see,
“Enhancing the Scalability
of Per-User Configurations” section on page 6-7
.
Enhancing the Scalability of Per-User Configurations
To enhance scalability of per-user configurations without changing the router configuration, use the
ip:vrf-id and ip:ip-unnumbered RADIUS attributes. These per-user vendor-specific attributes (VSAs)
are used to map sessions to VRFs and IP unnumbered interfaces. The VSAs are applied to virtual access
subinterfaces and are processed during PPP authorization.
The ip:vrf-id attribute is used to map sessions to VRFs. Any profile that uses the ip:vrf-id VSA must also
use the ip:ip-unnumbered VSA to install IP configurations on the VAI that is to be created. The PPP that
is used on a VAI to be created requires the ip:ip-unnumbered VSA. An Internet Protocol Control Protocol
(IPCP) session is not established if IP is not configured on the interface. You must configure either the
ip address command or the ip unnumbered command on the interface so that these configurations are
present on the VAI that is to be created. However, specifying the ip address and ip unnumbered
commands on a virtual template interface is not required because pre-existing IP configurations, if any,
are removed when the ip:ip-vrf VSA is installed on the VAI. Therefore, any profile that uses the ip:vrf-id
VSA must also use the ip:ip-unnumbered VSA to install IP configurations on the VAI that is to be
created.
These per-user VSAs can be applied to VAIs. Therefore, the per-user authorization process does not
require the creation of full VAIs, which improves scalability.
Setting the VRF and IP Unnumbered Interface Configurations in User Profiles
Although the Cisco ASR 1000 Series Router continues to support the lcp:interface-config VSA, the
ip:vrf-id and ip:ip-unnumbered VSAs provide another way to set the VRF and IP unnumbered interface
configurations in user profiles. The ip:vrf-id and ip:ip-unnumbered VSAs have the following syntax:
Cisco:Cisco-AVpair = “ip:vrf-id=vrf-name”
Cisco:Cisco-AVpair = “ip:ip-unnumbered=interface-name”
You should specify only one ip:vrf-id and one ip:ip-unnumbered value in a user profile. However, if the
profile configuration includes multiple values, the Cisco ASR 1000 Series Router applies the value of
the last VSA received, and creates a virtual access subinterface. If the profile includes the
lcp:interface-config VSA, the router always applies the value of the lcp:interface-config VSA.