Cisco ASR1002 Configuration Guide - Page 241

Scaling the L2TP Tunnel Configurations, Using the cisco-avpair=\

Page 241 highlights

Broadband Scalability and Performance Using the cisco-avpair="lcp:interface-config" RADIUS Attribute Note For IP sessions, the keepalives are not enabled by default. Enabling keepalives for IP sessions provides the same capability as PPP keepalives except that ICMP or ARP is used to test the presence of subscribers. For more information about Using ARP for Keepalive Messages and Using ICMP for Keepalive Messages, see the feature documentation at: http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/xe-3s/Configuring_ISG_Policies_for_ Session_Maintenance.html Scaling the L2TP Tunnel Configurations To prevent head-of-the-line blocking of the IP input process and save system resources, configure the vpdn ip udp ignore checksum command: Router(config)# vpdn ip udp ignore checksum When you configure this command, the router directly queues the L2TP Hello packets and Hello acknowledgements to the L2TP control process. We recommend that you configure this command in all the scaled LAC and LNS L2TP tunnel configurations. If you do not configure the vpdn ip udp ignore checksum command, the L2TP software sends the packets to UDP to validate the checksum. When too many packets are queued to the IP input process, the router starts Selective Packet Discard (SPD) mechanism that causes IP packets to be dropped. Note Head-of-the-line blocking of the IP input process might occur in other nonL2TP configurations. A flush occurring on an input interface indicates that the SPD mechanism is discarding packets. Using the cisco-avpair="lcp:interface-config" RADIUS Attribute When you use the lcp:interface-config RADIUS attribute to reconfigure the virtual access subscriber interface, scaling decreases on the Cisco ASR 1000 Series Router for the following reasons: • The lcp:interface-config command syntax includes an IOS interface configuration command. This command is any valid IOS command that can be applied to an interface. When the lcp:interface-config attribute is downloaded from the RADIUS server to the Cisco ASR 1000 Series Router, the command parser is activated to configure the interface according to AV-pair, determining if the option is valid and then applying the configuration to the virtual access interface (VAI). • The lcp:interface-config command degrades the call rate. Before configuring the virtual access subscriber interface using the lcp:interface-config command, configure the aaa policy interface-config allow-subinterface command. If the subinterface is not configured, the following error message is displayed when creating a session with one of the RADIUS attributes: *Mar 13 22:04:03.358: %FMANRP_ESS-4-FULLVAI: Session creation failed due to Full Virtual-Access Interfaces not being supported. Check that all applied Virtual-Template and RADIUS features support Virtual-Access sub-interfaces. swidb= 0x7FA35A42F218, ifnum= 30 Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide 7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462

Broadband Scalability and Performance
Using the cisco-avpair="lcp:interface-config" RADIUS Attribute
7
Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide
Note
For IP sessions, the keepalives are not enabled by default. Enabling keepalives for IP sessions provides
the same capability as PPP keepalives except that ICMP or ARP is used to test the presence of
subscribers. For more information about Using ARP for Keepalive Messages and Using ICMP for
Keepalive Messages, see the feature documentation at:
Session_Maintenance.html
Scaling the L2TP Tunnel Configurations
To prevent head-of-the-line blocking of the IP input process and save system resources, configure the
vpdn ip udp ignore checksum
command:
Router(config)#
vpdn ip udp ignore checksum
When you configure this command, the router directly queues the L2TP Hello packets and Hello
acknowledgements to the L2TP control process. We recommend that you configure this command in all
the scaled LAC and LNS L2TP tunnel configurations.
If you do not configure the
vpdn ip udp ignore checksum
command, the L2TP software sends the
packets to UDP to validate the checksum. When too many packets are queued to the IP input process,
the router starts Selective Packet Discard (SPD) mechanism that causes IP packets to be dropped.
Note
Head-of-the-line blocking of the IP input process might occur in other nonL2TP configurations. A flush
occurring on an input interface indicates that the SPD mechanism is discarding packets.
Using the cisco-avpair="lcp:interface-config" RADIUS Attribute
When you use the
lcp:interface-config
RADIUS attribute to reconfigure the virtual access subscriber
interface, scaling decreases on the Cisco ASR 1000 Series Router for the following reasons:
The
lcp:interface-config
command syntax includes an IOS interface configuration command. This
command is any valid IOS command that can be applied to an interface. When the
lcp:interface-config
attribute is downloaded from the RADIUS server to the Cisco ASR 1000
Series Router, the command parser is activated to configure the interface according to AV-pair,
determining if the option is valid and then applying the configuration to the virtual access interface
(VAI).
The
lcp:interface-config
command degrades the call rate.
Before configuring the virtual access subscriber interface using the
lcp:interface-config
command,
configure the
aaa policy interface-config allow-subinterface
command.
If the subinterface is not configured, the following error message is displayed when creating a session
with one of the RADIUS attributes:
*Mar 13 22:04:03.358: %FMANRP_ESS-4-FULLVAI: Session creation failed due to Full
Virtual-Access Interfaces not being supported. Check that all applied Virtual-Template and
RADIUS features support Virtual-Access sub-interfaces. swidb= 0x7FA35A42F218, ifnum= 30