not in the demultiplexer table. In this case, the primary IP interface must be in
autoconfiguration mode.
Packet detection is the only method of dynamically creating subscriber interfaces
on GRE tunnel interfaces; you cannot use DHCP local server or DHCP external server.
Issuing the
ip auto-configure ip-subscriber
command configures the primary IP
address to enable dynamic configuration of subscriber interfaces. Unlike DHCP
configurations, the router creates the dynamic subscriber interface when it receives
the first packet that contains the subscriber’s IP address as the source address.
In addition, a dynamic subscriber interface becomes inactive after a period of time
in which the router receives no packets that contain the subscriber’s IP address as
the source address. You can configure the period of time by issuing the
ip
inactivity-timer
command.
To configure dynamic creation of subscriber interfaces on GRE tunnel interfaces, see
“Configuring Dynamic Subscriber Interfaces” on page 616.
Designating Traffic for the Primary IP Interface
When dynamic creation of subscriber interfaces is enabled on the primary IP interface
(by means of the
ip auto-configure ip-subscriber
command), you can use the
ip
source-prefix
command to specify the source address of traffic that is destined for
the primary IP interface instead of the subscriber interface. If the DHCP server (for
DHCP server configurations) or the router (for packet detection configurations) then
assigns a subscriber an IP address matching this source prefix, the router does not
create a dynamic subscriber interface for that address.
Using Framed Routes
You can use the
ip use-framed-routes ip-subscriber
command to enable a primary
IP interface to use framed routes as source IP addresses when creating dynamic
subscriber interfaces. The framed routes are applied to the dynamic subscriber
interface during configuration so traffic from the subsets can traverse the interface.
By applying framed routes in this fashion, you can extend the per-subscriber interface
management to any subnetworks behind the dynamic subscriber interface. RADIUS
includes the Framed-Route attribute [22] in Access-Accept messages to specify the
route in the following format:
Framed-Route =
ipAddress/mask nextHop
Inheritance of MAC Address Validation State for Dynamic Subscriber Interfaces
A dynamic IP subscriber interface inherits the MAC address validation state (enabled
or disabled) configured for its parent static primary IP interface.
MAC address validation binds a MAC source address for an interface to a given IP
source address. When the IP-MAC binding is established, the router forwards ingress
packets on the interface when the packet’s MAC source address and IP source address
match, and drops ingress packets when the packet’s MAC source address and IP
source address do not match. MAC address validation thereby prevents spoofing on
Dynamic Creation of Subscriber Interfaces
■
607
Chapter 25: Configuring Subscriber Interfaces
Содержание JUNOSE 11.0.X MULTICAST ROUTING
Страница 6: ...vi...
Страница 28: ...xxviii Table of Contents JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 36: ...xxxvi List of Tables JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 42: ...2 Managing Remote Access JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 204: ...164 Managing RADIUS and TACACS JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 274: ...234 CLI Commands Used to Modify RADIUS Attributes JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 292: ...252 Monitoring RADIUS Relay Server JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 336: ...296 RADIUS Client Terminate Reasons JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 368: ...328 Managing L2TP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 408: ...368 Configuring the Weighted Load Balancing Method JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 444: ...404 PPP Accounting Statistics JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 492: ...452 Monitoring Operational Status within the Current VR Context JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 494: ...454 Managing DHCP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 510: ...470 DHCP Local Server Configuration Tasks JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 528: ...488 Configuring the Router to Work with the SRC Software JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 556: ...516 Configuring DHCP Relay Proxy JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 616: ...576 Managing the Subscriber Environment JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 632: ...592 Subscriber Management Configuration Examples JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 636: ...596 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 672: ...632 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 674: ...634 Managing Subscriber Services JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 767: ...Part 7 Index Index on page 729 Index 727...
Страница 768: ...728 Index JUNOSe 11 0 x Broadband Access Configuration Guide...