NOTE:
There are two domain names with special meaning. The domain name
none
indicates that there is no domain name present in the subscriber’s name. For more
information about
none
, see the section “Mapping User Requests Without a Valid
Domain Name” on page 8. The domain name
default
indicates that no other match
occurs. For more information about
default
, see the section “Mapping User Requests
Without a Configured Domain Name” on page 9.
Allowing or Denying Domain Names
You can control a PPP subscriber’s access to certain domains on given interfaces.
As the administrator, you can use the
deny
command to prevent PPP subscribers
from using unauthorized domain names. Using the
allow
command, you can allow
PPP subscribers to use authorized domain names.
Configuration Example
In this example, the administrator wants to restrict access of a PPP interface to the
specific domain
abc.com
.
1.
Create an AAA profile.
host1(config)#
aaa profile restrictToABC
2.
Specify the domain name you want to allow.
host1(config-aaa-profile)#
allow abc.com
3.
Specify the domain name you want to restrict.
host1(config-aaa-profile)#
deny default
4.
Associate the AAA profile to the designated PPP interface.
host1(config-if)#
ppp aaa-profile restrictToABC
When configured as such, the following is a likely scenario:
■
PPP passes the AAA profile
restrictToABC
to AAA in the authentication request.
■
AAA performs the following:
■
Receives the authentication request from PPP with the subscriber’s name
.
■
Parses the domain name
xyz.com
and examines the specified AAA profile
restrictToABC
.
■
Determines that the AAA profile
restrictToABC
is valid.
■
Searches
restrictToABC
for a match on the PPP subscriber’s domain name
and finds no match.
64
■
Configuring AAA Profiles
JUNOSe 11.0.x Broadband Access Configuration Guide
Summary of Contents for JUNOSE 11.0.X MULTICAST ROUTING
Page 6: ...vi...
Page 28: ...xxviii Table of Contents JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 36: ...xxxvi List of Tables JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 42: ...2 Managing Remote Access JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 204: ...164 Managing RADIUS and TACACS JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 292: ...252 Monitoring RADIUS Relay Server JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 336: ...296 RADIUS Client Terminate Reasons JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 368: ...328 Managing L2TP JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 444: ...404 PPP Accounting Statistics JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 494: ...454 Managing DHCP JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 510: ...470 DHCP Local Server Configuration Tasks JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 556: ...516 Configuring DHCP Relay Proxy JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 616: ...576 Managing the Subscriber Environment JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 674: ...634 Managing Subscriber Services JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 767: ...Part 7 Index Index on page 729 Index 727...
Page 768: ...728 Index JUNOSe 11 0 x Broadband Access Configuration Guide...