Configuring ISG Policies for Session Maintenance
How to Configure Policies for Session Maintenance Timers
4
For IP subnet sessions, the peer (destination) IP address to be used for ICMP “hello” requests will be all
the IP addresses within the subnet. This means “hello” requests will be sent sequentially (not
simultaneously) to all the possible hosts within that subnet. If there is no response from any host in that
subnet, the session will be disconnected.
Another option is to configure ICMP directed broadcast for keepalive requests. If the subscriber hosts
recognize the IP subnet broadcast address, the ISG can send the ICMP “hello” request to the subnet
broadcast address. The subscribers need not be on the same subnet as the ISG for this configuration to
work. A directed broadcast keepalive request can work multiple hops away as long as these conditions
are satisfied:
•
The group of subscribers identified by the subnet must have the same subnet mask provisioned
locally as the subnet provisioned on the subnet subscriber session on the ISG. Otherwise, the
subscriber hosts will not recognize the subnet broadcast address.
•
The router directly connected to the hosts must enable directed-broadcast forwarding, so that the IP
subnet broadcast gets translated into a Layer 2 broadcast.
When these two conditions are satisfied, you can optimize the ICMP keepalive configuration to
minimize the number of ICMP packets.
Note
Because enabling directed broadcasts increases the risk of denial of service attacks, the use of subnet
directed broadcasts is not turned on by default.
How to Configure Policies for Session Maintenance Timers
Configuring the session maintenance timers requires two separate tasks, one to set the idle timer and one
to set the session timer. Either one or both of these tasks can be performed in order to set session
maintenance control. The following tasks show how to set these timers in a service policy map and in a
RADIUS AAA server profile:
•
Configuring the Session Timer in a Service Policy Map, page 5
•
Configuring the Session Timer on a AAA Server, page 6
•
Configuring the Connection Timer in a Service Policy Map, page 6
•
Configuring the Connection Timer on a AAA Server, page 7
•
Verifying the Session and Connection Timer Settings, page 8
•
Troubleshooting the Session and Connection Timer Settings, page 8
•
Configuring a Session Keepalive on the Router, page 10
•
Configuring a Session Keepalive on a RADIUS Server, page 12
•
Configuring the ISG to Interact with the RADIUS Server, page 12
Содержание IOS XE
Страница 14: ...About Cisco IOS XE Software Documentation Additional Resources and Documentation Feedback xii ...
Страница 28: ...Using the Command Line Interface in Cisco IOS XE Software Additional Information xiv ...
Страница 36: ...Intelligent Services Gateway Features Roadmap 8 ...
Страница 46: ...Overview of ISG Feature Information for the Overview of ISG 10 ...
Страница 70: ...Configuring ISG Control Policies Feature Information for ISG Control Policies 24 ...
Страница 128: ...Configuring ISG Access for IP Subscriber Sessions Feature Information for ISG Access for IP Subscriber Sessions 44 ...
Страница 136: ...Configuring MQC Support for IP Sessions Feature Information for MQC Support for IP Sessions 8 ...
Страница 194: ...Configuring ISG Policies for Automatic Subscriber Logon Feature Information for ISG Automatic Subscriber Logon 12 ...
Страница 224: ...Configuring ISG Subscriber Services Feature Information for ISG Subscriber Services 20 ...
Страница 336: ...Configuring ISG Integration with SCE Feature Information for Configuring ISG Integration with SCE 16 ...
Страница 344: ...Service Gateway Interface Feature Information for Service Gateway Interface 8 ...