10-6
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Chapter 10 Managing Subscribers
Information About Subscribers
VPN-Based Subscribers
A VPN-based subscriber contains a set of mappings of the form: IP@VpnName, where IP can be either
a single IP address or a range of addresses. A VPN-based subscriber is VLAN-based.
Most VPN-based subscriber functionality is managed via the SM, with the role of the Cisco SCE
platform CLI being more limited.
The Cisco SCE platform CLI can be used to do the following:
•
Display VPN-related mappings
•
View all automatic VLAN VPNs
•
Clear all automatic VLAN VPNs (only VPNs that have no active subscriber mappings).
Automatic VLAN VPNs
The Cisco SCE platform will automatically create a new VPN under the following conditions
•
The VPN name does not currently exist
and
•
The VPN name is a number in the range [0 to 4095]
The number is used as the VLAN mapping of the newly created VPN. VLAN mappings cannot be added
to automatic VPNs.
Synchronizing Subscriber Information in a Cascade System
In a hot standby, cascade setup with full redundancy, the external provisioning server updates only the
active Cisco SCE platform. However, the standby Cisco SCE platform must always be updated with the
latest subscriber-related information (login, logout). This is required to minimize information loss in
case of failover. In general, the only entity that is allowed to change subscriber information in the
standby Cisco SCE platform is the active Cisco SCE platform. The standby Cisco SCE platform does
not accept any subscriber operations (it returns a STANDBY_VIOLATION error instead), and it also
does not generate any asynchronous subscriber notifications (such as pull-response or
logout-notification).
There are only two exceptions to this rule:
•
Standby Cisco SCE platform can change subscriber information of the default subscriber.
•
Standby Cisco SCE platform can perform subscriber aging
Therefore, when working as a pair, the active Cisco SCE platform constantly updates the standby Cisco
SCE platform with external data information. In addition, the standby Cisco SCE platform constantly
requests external data information from the active Cisco SCE platform. The synchronization is
bi-directional to ensure that the subscriber databases in both Cisco SCE platforms are identical.
Note that external data is only relevant for introduced subscribers (both static and dynamic). It has no
meaning for anonymous subscribers or the default subscriber. No more than two minutes of external data
information will be lost by the standby Cisco SCE platform if a failover occurs.
The following subscriber information is considered as external data:
•
subscriber name
•
IP mappings