ASN Gateway Overview
ASN Mobility Management ▀
Cisco ASR 5000 Series Product Overview ▄
OL-22938-02
Figure 36.
Basic ASN Gateway Mobile IP Network
Internet
Enterprise
ASN Gateway / FA
Acess Service Network (ASN)
Home Agent
(HA)
Connectivity Service Network (CSN)
WiMAX SS/MS
WiMAX Base
Station
EAP User Authentication
The ASN Gateway serves as the Extensible Authentication Protocol (EAP) authenticator and mobility key holder for
subscriber connections and RADIUS clients to attached Authorization, Authentication, and Accounting (AAA) servers.
ASN Gateway and AAA
ASN control is handled by the ASN Gateway and the base station. The ASN Gateway control plane handles the feature
set, including AAA functions, context management, profile management, service flow authorization, paging, radio
resource management, and handover. The data plane feature set includes mapping radio bearer to the IP network, packet
inspection, tunneling, admission control, policing, QoS, and data forwarding.
The ASN Gateway acts as an authenticator. It operates in pass-through mode for EAP authentication between the EAP
client (the mobile station) and the EAP (AAA) server. After successful EAP authentication, the AAA server sends the
master session key (MSK) to the ASN Gateway. The ASN Gateway, as authenticator, performs authorization key (AK)
context management. It derives the AK from the MSK and sends it to the base station. As part of the AK context, other
information, such as the AkID and CMAC are sent to the base station to secure the R1 interface.
An AAA module in the ASN Gateway provides flow information for accounting. Every detail about a flow, such as the
transferred or received number of bits, the duration of the connection, and the applied policy, is retrievable from the data
plane.
Profile Management
The ASN Gateway provides profile management and a policy function that resides in the connectivity network. Profile
management identifies a subscriber‘s feature set, such as the allowed QoS rate, number of flows, and type of flows.
In addition, the ASN Gateway maintains a context for the mobile subscriber and the base station. Each subscriber‘s
context contains the subscriber‘s profile and security context, and the characteristics of the subscriber‘s mobile device.
Содержание ASR 5000 Series
Страница 1: ......
Страница 26: ......
Страница 48: ...New In Release 10 0 SCM Features Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 50: ......
Страница 58: ......
Страница 67: ...Product Service and Feature Licenses Default Licenses Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 68: ......
Страница 126: ......
Страница 138: ......
Страница 146: ......
Страница 218: ......
Страница 236: ......
Страница 356: ......
Страница 374: ......
Страница 422: ......
Страница 496: ......
Страница 572: ......
Страница 654: ......
Страница 700: ......
Страница 726: ......
Страница 784: ......
Страница 816: ......
Страница 839: ...Network Address Translation Overview How NAT Works Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 841: ...Network Address Translation Overview How NAT Works Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 844: ......
Страница 906: ......
Страница 926: ......
Страница 942: ......
Страница 943: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 30 Technical Specifications ...
Страница 966: ......
Страница 967: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 31 Safety Electrical and Environmental Certifications ...
Страница 972: ......