2-21
Cisco 10000 Series Router Software Configuration Guide
OL-2226-23
Chapter 2 Scalability and Performance
Preventing Full Virtual Access Interfaces
Preventing Full Virtual Access Interfaces
The
lcp:interface-config
RADIUS attribute is used to reconfigure the subscriber interface. To
accommodate the requirements of this attribute, the per-user authorization process forces the router to
create full VAIs.
Cisco IOS Release 12.2(31)SB2, Release 12.2(28)SB6, and later releases include an enhancement that
allows you to use the
lcp:interface-config
attribute while preserving subvirtual access subinterfaces.
You can achieve this behaviour in the following ways:
•
Entering the following command in global configuration mode to preserve virtual access
subinterfaces:
Router(config)#
aaa policy interface-config allow-subinterface
•
Sending a Cisco attribute-value pair (AV-pair) in the user’s profile on the RADIUS server:
cisco-avpair="lcp:interface-config allow-subinterface=yes"
When you use the
aaa policy interface-config allow-subinterface
command, the router does not allow
you to reconfigure the router using any commands that interact with the interface’s hardware interface
descriptor block (HWIDB), for example, the
compression
command.
When you use the
lcp:interface-config
attribute, sessions are not established if the sessions receive the
attribute and the attribute reconfigures the HWIDB for the virtual access interface (VAI).
When the
allow-subinterface=yes
option is used in the Cisco AV-pair or the
aaa policy interface-config
allow-subinterface
command is set, enter the following command to verify the condition for which a
full VAI reconfiguration is required:
Router#
debug sss
feature-name
interface-config
{
error
|
event
}
In general, for interface reconfiguration, use the dedicated Cisco vendor specific attributes (VSAs). For
example, use
Cisco-Policy-Up
or
Cisco-Policy-Down,
or
ip:vrf-id
instead of
lcp:interface-config
.
Alternatively, when no dedicated Cisco AV-pair is present, use
lcp:interface-config
with the
allow-subinterface=yes
option, or the
aaa policy interface-config allow-subinterface
command to
preserve VAI subinterfaces (for example, to enable multicast on the subscriber interface).