Summary of Contents for Cisco Intelligent Wireless Access Gateway
Page 1
Intelligent Wireless Access Gateway Configuration Guide First Published: July 26, 2013 Last Modified: March 28, 2014 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 Text Part Number: OL-30226-03...
Page 2
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks . Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.
Configuring Authentication, Authorization, and Accounting for the iWAG Configuring DHCP when the iWAG Acts as a DHCP Proxy Configuring the Cisco ISG Class Map and Policy Map for the iWAG Configuring a Session Initiator for the iWAG Configuring a Tunnel Interface for the iWAG...
Page 4
Feature Information for Configuring Ethernet Over GRE GTPv2 Support in the iWAG C H A P T E R 5 Finding Feature Information Restrictions for GTPv2 of the iWAG Information About GTPv2 in the iWAG Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 5
Finding Feature Information Information About Cisco ISG Accounting Accuracy for LNS Sessions Additional References Feature Information for Cisco ISG Accounting Accuracy for LNS Sessions Dual Stack Support for PMIPv6 and GTP C H A P T E R 9 Finding Feature Information...
Page 6
Activating and Deactivating the Flow-Based Redirect Feature Through Vendor-Specific Attributes Configuring Flow-Based Redirect for a Traffic Class Service Examples Best Practices for Configuring the NAT on the Cisco ASR 1000 Series Routers NAT Overloading and Port Parity NAT Interface Overloading with VRF Additional References...
Page 7
Dual-Stack Mobile IPoE Session with IPv6 ND as FSOL for GTP Call Flow Additional References Feature Information for Call Flows for Dual-Stack PMIPv6 and GTP iWAG Scalability and Performance C H A P T E R 1 4 Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 8
Contents iWAG Scaling Restrictions for iWAG Scalability Layer 4 Redirect Scaling Configuring Call Admission Control Walk-by User Support for PWLAN in iWAG Additional References Feature Information for iWAG Scalability and Performance Intelligent Wireless Access Gateway Configuration Guide viii OL-30226-03...
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
• Enable the ipv6 unicast-routing command. Restrictions for the iWAG • Roaming from a 3G mobility network to a WLAN is not supported for the GTP and Cisco ISG sessions. • IP subscriber-routed (L3) sessions are not supported. • IPv6 and quality of service (QoS) are not supported in a 3G mobility network.
Overview of the Intelligent Wireless Access Gateway Benefits of the iWAG The following figure shows a deployment model of the iWAG on a Cisco ASR 1000 Series Aggregation Services Router. Figure 1: iWAG Deployment on a Cisco ASR 1000 Series Aggregation Services Router...
Page 12
Overview of the Intelligent Wireless Access Gateway AAA Attributes The following indicate the availability of the attributes: Note C: Conditional M: Mandatory O: Optional N: Not present Table 1: iWAG AAA Attributes Attrib Attri Value Description bute /Subattri Name bute...
Page 13
Overview of the Intelligent Wireless Access Gateway AAA Attributes Attrib Attri Value Description bute /Subattri Name bute 26/9/1 Cisco String Mobile Subscriber ISDN number -MSISDN 26/9/1 Cisco-MN ENUM Mobile Node Service type -Service • none • ipv4 • ipv6 • dual...
Page 14
Overview of the Intelligent Wireless Access Gateway AAA Attributes Attrib Attri Value Description bute /Subattri Name bute 26/9/1 Cisco String Mobile node's Visited LMA IPv6 address -Visited -LMA -IPv6 -Address 26/9/1 Cisco IPv4 Address Mobile node's Home LMA IPv4 address...
Overview of the Intelligent Wireless Access Gateway Supported Hardware and Software Compatibility Matrix for the iWAG Attrib Attri Value Description bute /Subattri Name bute THREEGENPP IPv4 Address GGSN's Address /10415 _GGSN _ADDRESS 26/9/1 Cisco String Access-side VRF ID -Access -Vrf...
How to Configure the iWAG Configuring the iWAG for Simple IP Users You must configure the Cisco Intelligent Services Gateway (ISG) for the iWAG to enable simple IP users to access Internet services. The tasks listed below enable IP sessions and indicate how these sessions are identified. For detailed steps, see the "Creating ISG Sessions for IP Subscribers"...
Page 17
Overview of the Intelligent Wireless Access Gateway Configuring the iWAG for 3G Mobile IP Users SUMMARY STEPS 1. enable 2. configure terminal 3. aaa new-model 4. aaa group server radius group-name 5. server-private ip-address [auth-port port-number | acct-port port-number ] [non-standard] [timeout seconds ] [retransmit retries ] [ key string] 6.
GGSN or PGW. Configuring the Cisco ISG Class Map and Policy Map for the iWAG This section describes how to configure the Cisco ISG class map and policy map for the iWAG. SUMMARY STEPS 1. enable 2.
Page 21
Overview of the Intelligent Wireless Access Gateway Configuring the iWAG for 3G Mobile IP Users DETAILED STEPS Command or Action Purpose Step 1 enable Enables the privileged EXEC mode. Enter your password, if prompted. Example: Router> enable Step 2 Enters the global configuration mode.
Page 22
Overview of the Intelligent Wireless Access Gateway Configuring the iWAG for 3G Mobile IP Users Command or Action Purpose Step 9 [ priority ] class type traffic { class-map-name | default {in-out | Creates or modifies a traffic class map that is used...
MAC address, an unclassified MAC address, a RADIUS message with the Cisco ASR 1000 Series Aggregation Services Router acting as RADIUS proxy or a DHCP DISCOVER message with the Cisco ASR 1000 Series Aggregation Services Router acting as DHCP proxy.
Router(config-if)# ip subscriber l2-connected method. Step 9 initiator {dhcp | radius-proxy | static ip subscriber list Enables the Cisco ISG to create an IP subscriber session listname | unclassified ip | unclassified mac-address} upon receipt of a specified type of packet. Example:...
Overview of the Intelligent Wireless Access Gateway Configuring the iWAG for 3G Mobile IP Users Enabling MCSA is mandatory before you enable the Mobility feature in the Cisco ASR 1000 Series Note Aggregation Services Routers. SUMMARY STEPS 1. enable 2. configure terminal 3.
Page 27
Step 2 configure terminal Enters the global configuration mode. Example: Router# configure terminal Step 3 Configures the GTP for the iWAG solution on the Cisco ASR 1000 Series Aggregation Services Router. Example: Router(config)# gtp Step 4 n3-request number of requests Specifies the number of times a control message must be retried before a failure message is sent.
Page 28
192.168.10.1 Step 13 dhcp-lease seconds Configures the duration (in seconds) of the lease for an IP address that is assigned from a Cisco IOS DHCP Server to a DHCP client. Example: Router(config-gtp-apn)# dhcp-lease 3000 Intelligent Wireless Access Gateway Configuration Guide...
• Configuring a Detailed Configuration for an LMA Enabling Mobile Client Service Abstraction This section describes how to enable Mobile Client Service Abstraction (MCSA) for PMIPv6. Enabling MCSA is mandatory before you enable the Mobility feature in the Cisco ASR 1000 Series Note Aggregation Services Routers.
Enters the global configuration mode. configure terminal Example: Router# configure terminal Step 3 mcsa Enables MCSA on the Cisco ASR 1000 Series Aggregation Services Router. Example: Router(config)# mcsa Step 4 Enables MCSA to receive notifications from the Cisco ISG. enable sessionmgr...
Overview of the Intelligent Wireless Access Gateway Feature Information for the Intelligent Wireless Access Gateway Standards and RFCs Standard/RFC Title RFC 3775 Mobility Support in IPv6 RFC 5213 Proxy Mobile IPv6 RFC 5844 IPv4 Support for Proxy Mobile IPv6 RFC 5845...
Page 32
ASR 1000 Series Aggregation Services Routers. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
11. initiator {dhcp | radius-proxy | static ip subscriber list listname | unclassified ip | unclassified mac-address} DETAILED STEPS Command or Action Purpose Step 1 Enters the global configuration mode. configure terminal Example: Router# configure terminal Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 35
The iWAG does not support the routed access method. Step 10 initiator {dhcp | radius-proxy | static ip subscriber list Enables the Cisco ISG to create an IP subscriber session listname | unclassified ip | unclassified mac-address} upon receipt of a specified type of packet. Example:...
Command or Action Purpose Step 11 initiator {dhcp | radius-proxy | static ip subscriber list Enables the Cisco ISG to create an IP subscriber session listname | unclassified ip | unclassified mac-address} upon receipt of a specified type of packet. Example:...
Unless noted otherwise, subsequent releases of that software release train also support that feature. Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Page 39
Cisco ASR 1000 Series Aggregation Services Routers. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
Page 40
IP Sessions Over Gigabit EtherChannel Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
PMIPv6 subscribers can be attached. Cisco high-end routing platforms, such as the Cisco ASR 1000 Series Route Processor 2, the Cisco ASR 1000 Series 40-Gbps ESP, and the Cisco ASR 1000 Series 100-Gbps ESP support 128,000 scaling for the LMA.
Cisco ASR 1000 Series Aggregation Services Routers. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Restrictions for Configuring Ethernet Over GRE The following features are not supported on the Cisco ASR 1000 Series Aggregation Services Routers: • IPsec tunnel between the Cisco ASR 1000 Series Aggregation Services Routers and the CPE devices • Native multicast coexistence for subscribers •...
Prerequisites for Configuring Ethernet Over GRE Prerequisites for Configuring Ethernet Over GRE Before you configure the Ethernet over GRE feature on the Cisco ASR 1000 Series Aggregation Services Routers, ensure that the following prerequisites are met: • A physical interface or dot1Q interface should be configured.
Page 48
Information About Configuring Ethernet Over GRE The following figure shows the structure of the EoGRE feature with PMIP/GTP integrated for mobility service. Figure 3: Structure of the EoGRE Feature with PMIP/GTP Integrated for Mobility Service Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 49
The EoGRE feature supports the following deployments: • EoGRE Deployment with PMIPv6 Integrated for Mobility Service • EoGRE Deployment with GTP Integrated for Mobility Service • EoGRE Deployment with ISG Integrated for Simple IP Service Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
WLCs are used as residential gateways or CPE devices. CPEs are preconfigured with a point-to-multipoint GRE IP tunnel to the Cisco ASR 1000 Series Aggregation Services Routers as the MAG. The tunnel from the CPE device can be configured with a static GRE key. The CPEs are provisioned to forward the Ethernet traffic from both public and private customers to the GRE tunnel, and to add a VLAN tag on the Ethernet frame before forwarding the traffic.
The ISG provides simple IP service to mobile nodes that are connected to ISG via the EoGRE tunnel, as shown in the following figure. The Cisco ASR 1000 Series Aggregation Services Routers use the ISG Intelligent Wireless Access Gateway Configuration Guide...
Figure 7: Structure of the EoGRE Deployment with ISG Integrated for Simple IP Service Supported Features The following features are supported as part of the EoGRE feature on the Cisco ASR 1000 Series Aggregation Services Routers: • Ethernet over GRE traffic termination on the routers •...
For a simple IP scenario, only a specified IP address can be configured on the tunnel interface. This IP address can be used Router(config-if)# ip unnumbered loopback 0 as a default gateway IP address. Router(config-if)# ip address 20.1.1.2 255.255.255.0 Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Router(config-if)# end Example: Configuring the EoGRE Feature aaa new-model aaa group server radius AAA_SERVER_CAR server-private 5.3.1.76 auth-port 2145 acct-port 2146 key cisco aaa authentication login default none aaa authentication login ISG_PROXY_LIST group AAA_SERVER_CAR aaa authorization network ISG_PROXY_LIST group AAA_SERVER_CAR aaa authorization subscriber-service default local group AAA_SERVER_CAR...
Page 55
172.16.254.254 domain-name cisco.com policy-map type control EOGRE_L2_ISG class type control always event session-start 2 authorize aaa list ISG_PROXY_LIST password cisco identifier mac-address 4 set-timer IP_UNAUTH_TIMER 5 class type control always event service-start 1 service-policy type service identifier service-name 2 collect identifier nas-port interface Loopback0 ip address 9.9.9.9 255.255.255.255...
No new or modified MIBs are supported by this To locate and download MIBs for selected platforms, feature. Cisco software releases, and feature sets, use Cisco MIB Locator found at the following URL: http://www.cisco.com/go/mibs Intelligent Wireless Access Gateway Configuration Guide...
Unless noted otherwise, subsequent releases of that software release train also support that feature. Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Page 58
ASR 1000 Series Aggregation Services Routers. The following sections provide information about this feature: • Information About Configuring Ethernet Over GRE, on page 39 • How to Configure the EoGRE Feature, on page Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Effective from Cisco IOS XE Release 3.10S, the support for GPRS Tunneling Protocol Version 2 (GTPv2) is offered on the Cisco ASR 1000 Series Aggregation Services Routers as an enhancement to the GTPv1 offering in the iWAG solution that was introduced in Cisco IOS XE Release 3.8S. GTPv2 provides support for both the 4G and 3G mobile users, whereas GTPv1 provides support only for 3G mobile users.
AAA attributes. However, the new gtpv2 enum value for the Cisco-MPC-Protocol-Interface attribute is necessary to specify the use of GTPv2. The AAA server identifies a subscriber depending upon whether the subscriber profile is sent over GTPv1 tunnel or GTPv2 tunnel from the iWAG back to the Evolved Packet Core (EPC).
98 Intra-iWAG Roaming Effective from Cisco IOS XE Release 3.10S, both GTPv1 and GTPv2 support connected subscriber roaming across different access interfaces of the iWAG. GTPv1 and GTPv2 preserve and update their existing sessions to allow their data traffic to flow through the new ingress interfaces from the access network.
No new or modified MIBs are supported by this To locate and download MIBs for selected platforms, feature. Cisco software releases, and feature sets, use Cisco MIB Locator found at the following URL: http://www.cisco.com/go/mibs Intelligent Wireless Access Gateway Configuration Guide...
Cisco ASR 1000 Series Aggregation Services Routers. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
Page 64
GTPv2 Support in the iWAG Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
(FSOL) triggers that are supported on SSO include DHCP proxy (where the iWAG acts as the DHCP proxy server) and DHCP proxy plus unclassified MAC. For more information about ISSU, see the “Overview of ISSU on the Cisco ASR 1000 Series Routers” section of the Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide.
If traffic interruption exceeds the configured t3 and n3 limits, the session is disconnected. Enabling SSO Support for the GTP This section describes how to enable SSO support for the GTP on the Cisco ASR 1000 Series Aggregation Services Routers. SUMMARY STEPS 1.
No new or modified MIBs are supported by this To locate and download MIBs for selected platforms, feature. Cisco software releases, and feature sets, use Cisco MIB Locator found at the following URL: http://www.cisco.com/go/mibs Intelligent Wireless Access Gateway Configuration Guide...
Cisco ASR 1000 Series Aggregation Services Routers. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
ISG policies on IPv4 and IPv6 subscriber sessions. It enables support of up to 128,000 IP subscriber sessions with more complex ISG policies at a higher churn rate on the Cisco ASR 1000 Series Aggregation Services Routers.
No new or modified MIBs are supported by this To locate and download MIBs for selected platforms, feature. Cisco software releases, and feature sets, use Cisco MIB Locator found at the following URL: http://www.cisco.com/go/mibs Intelligent Wireless Access Gateway Configuration Guide...
Cisco ASR 1000 Series Aggregation Services Routers. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Product Alert Tool (accessed from Field Notices), the Cisco Technical Services Newsletter, and Really Simple Syndication (RSS) Feeds. Access to most tools on the Cisco Support website requires a Cisco.com user ID and password. Intelligent Wireless Access Gateway Configuration Guide...
Cisco ASR 1000 Series Aggregation Services Routers. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
C H A P T E R Dual Stack Support for PMIPv6 and GTP Effective from Cisco IOS XE Release 3.11S, the Intelligent Wireless Access Gateway (iWAG) supports dual-stack session for Proxy Mobile IPv6 (PMIPv6) and GPRS Tunneling Protocol (GTP) sessions.
This feature enables the assignment of both an IPv4 address and an IPv6 address to a client. Therefore, the overall number of supported subscribers on the Cisco ASR 1000 Series Aggregation Services Routers are not affected by a mix of IPv4 and IPv6 traffic.
ACL_OUT_INTERNET match access-group input name ACL_IN_INTERNET class-map type traffic match-any TC_INTERNET_IPV6 match access-group output name IPV6_ACL_INTERNET match access-group input name IPV6_ACL_INTERNET class-map type traffic match-any TC_INTERNET_IPV6_2 match access-group output name IPV6_ACL_INTERNET2 Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
30 authorize aaa list default identifier mac-address #performs MAC TAL authorization class type control always event session-restart 10 service-policy type service name DRL_V4 #applying services during dual stack 11 service-policy type service name DRL_V6 #applying services during dual Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
#DHCP control packets are used as FSOL to create DHCPv4 only session Example: Configuring the Local Mobility Anchor for Cisco ASR 5000 Routers context pgw ip pool PMIP_POOL 70.70.0.1 255.255.0.0 public 0 subscriber-gw-address 70.70.70.1 ip pool v4_staticpool 9.9.9.1 255.255.0.0 static...
Example: Configuring a Control Policy for Dual-Stack GTP policy-map type control BB_PMAP class type control always event session-start 10 authorize aaa list BB_1 password cisco identifier mac-address Example: Configuring an Access Interface for Dual-Stack GTP interface GigabitEthernet0/0/3 ip address 21.0.0.1 255.255.0.0...
Product Alert Tool (accessed from Field Notices), the Cisco Technical Services Newsletter, and Really Simple Syndication (RSS) Feeds. Access to most tools on the Cisco Support website requires a Cisco.com user ID and password. Intelligent Wireless Access Gateway Configuration Guide...
Cisco ASR 1000 Series Aggregation Services Routers. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
Page 86
Dual Stack Support for PMIPv6 and GTP Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Configuring Flow-Based Redirect for a Traffic Class Service, page 82 • Examples, page 85 • Best Practices for Configuring the NAT on the Cisco ASR 1000 Series Routers, page 87 • NAT Overloading and Port Parity, page 88 • NAT Interface Overloading with VRF, page 88 •...
Flow-Based Redirect Flow-Based Redirect for Adult Content Filtering Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required. Flow-Based Redirect for Adult Content Filtering In a typical WiFi hotspot deployment, all subscriber traffic goes through Cisco ISG (Intelligent Service Gateway) after successful authentication.
Flow-Based Redirect for Selective IP Traffic Offload Mobile IP sessions are provisioned with a traffic class service in the Cisco Intelligent Wireless Access Gateway (iWAG) for routing web traffic to a next hop device, depending on the local policies or the policies that are downloaded from the Cisco IOS authentication, authorization, and accounting (AAA) network security services.
14. 1 service-policy type service unapply identifier service-name 15. class type control always event service-start 16. 10 service-policy type service identifier service-name 17. class type control always event account-logoff 18. 10 service disconnect delay 5 Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 91
Example: Router (config-service-policymap)# class type traffic ACF_ACL Step 9 reroute to next-hop ip IP address Redirects traffic to the specified IP address. Example: Router (config-service-policymap-class-traffic)# reroute to next-hop ip 44.0.0.22 Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 92
Router (config-control-policymap)# class type control always event account-logoff Step 18 10 service disconnect delay 5 Disconnects upon an account-logoff event, after a 5 second delay. Example: Router (config-control-policymap-class-control)# 10 service disconnect delay 5 Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Class-id Packets Bytes Pri. Definition 31936 Match Any Match Any 31936 Match ACL WEB_ACL_IN Match ACL WEB_ACL_OUT Template Id : 1 Features: Absolute Timeout: Class-id Timeout Value Time Remaining Source 3000 00:48:16 Peruser Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 94
Router# Show platform hardware qfp active statistics drop ------------------------------------------------------------------------- Global Drop Stats Packets Octets ------------------------------------------------------------------------- Disabled 1166 essipsubfsoldrop 2327 216495 UnconfiguredIpv6Fia 9492 Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Best Practices for Configuring the NAT on the Cisco ASR 1000 Series Routers The following are the recommended best practices to configure the NAT on the Cisco ASR 1000 Series Aggregation Services Routers: • Restriction on the total QFP DRAM usage At 97 percent DRAM utilization, depletion messages are displayed in the syslog as a warning message to make the operator aware of low QFP DRAM availability.
NAT Overloading and Port Parity • The ip nat translation max-entries all-host command can be used in scenarios where the Cisco ASR 1000 Series Router acting as ISG, performs NAT on all or most of the subscriber traffic. This helps the operator to prevent a single host from occupying the entire translation table, while allowing a reasonable upper limit to each host.
Product Alert Tool (accessed from Field Notices), the Cisco Technical Services Newsletter, and Really Simple Syndication (RSS) Feeds. Access to most tools on the Cisco Support website requires a Cisco.com user ID and password. Feature Information for Flow-Based Redirect The following table provides release information about the feature or features described in this module.
Page 98
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Page 100
• User redirection to the portal (on user authorization failure only) • User authentication at the RADIUS server • Profile download and auto-login service activation • Access to features such as change of authorization (CoA), account logout, account stop, account ping Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
IP user. Figure 10: Simple IP Unclassified MAC with MAC TAL Authentication Call Flow The following steps describe the call flow for a successful MAC TAL Web authorization for a simple IP subscriber: Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 102
6 An Accounting Start message is sent to the application provider to indicate the start of the subscriber’s service. The subscriber can now access the Internet services applicable as part of the subscription. Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
1 The subscriber initiates IP traffic to get connected to the Internet service. ISG notices a new subscriber address and creates an unauthenticated subscriber session. 2 ISG then sends an authorization request to the RADIUS server with the subscriber’s MAC address as the username. Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
#---------------------------------------------- interface GigabitEthernet0/0/2.10 #Connected to the client, access interface. encapsulation dot1Q 10 ip address 11.11.11.1 255.255.255.0 service-policy type control TAL ip subscriber l2-connected initiator unclassified mac-address interface GigabitEthernet0/0/3 #Connected to the RADIUS server Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 105
10 authenticate aaa list IP_AUTHEN_LIST 20 service-policy type service unapply name OPENGARDEN_SERVICE 30 service-policy type service unapply name L4REDIRECT_SERVICE class type control UNAUTHEN_COND event timed-policy-expiry 10 service disconnect #---------------------------------------------- # ACL Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
No new or modified MIBs are supported by this To locate and download MIBs for selected platforms, feature. Cisco software releases, and feature sets, use Cisco MIB Locator found at the following URL: http://www.cisco.com/go/mibs Intelligent Wireless Access Gateway Configuration Guide...
Cisco ASR 1000 Series Aggregation Services Routers. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
Page 108
Call Flows for Simple IP Users Feature Information for Call Flows for Simple IP Users Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Page 110
The following figures and steps describe the call flow pertaining to DHCP Discover authentication for a 3G user: Figure 12: 3G DHCP Discover Call Flow (Part 1) Figure 13: 3G DHCP Discover Call Flow (Part 2) Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 111
5 After the subscriber is authenticated, the AAA server caches its entire user profile that includes the information about IMSI, MSISDN, APN, and the Cisco AV pair having ssg-service-info set to GTP-service. The cached data also includes the client's MAC address, which is set as the calling-station-ID in the incoming EAP messages.
The following example shows a 3G DHCP Discover call flow configuration: aaa new-model //authentication, authorization, and accounting configurations aaa group server radius AAA_SERVER1 server-private 99.0.7.10 auth-port 1812 acct-port 1813 key cisco aaa authentication login default none aaa authentication login WEB_LOGON group AAA_SERVER1...
Page 113
10 service-policy type service name OPENGARDEN_SERVICE 20 service-policy type service name SERVICE_POSTPAID 25 service-policy type service name SERVICE_TIMEOUT 30 authorize aaa list ISG_PROXY_LIST password lab1 identifier mac-address Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 114
5.28.0.1 ip forward-protocol nd no ip http server no ip http secure-server ip route 5.28.0.0 255.255.0.0 5.28.0.1 ip route vrf Mgmt-intf 5.28.0.0 255.255.0.0 5.28.0.1 ip route vrf Mgmt-intf 223.0.0.0 255.0.0.0 5.28.0.1 Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 115
98.0.7.13 # details for the iWAG to reach the GGSN default-gw 192.168.0.1 prefix-len 16 dns-server 192.168.255.253 dhcp-lease 3000 apn 2356 apn-name cisco1.com # you can have multiple APNs ip address ggsn 98.0.7.14 default-gw 10.254.0.1 prefix-len 16 dns-server 10.254.255.253 dhcp-lease 3000 Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
5 The LMA responds with a PBA message that includes IP address, gateway, and mask. 6 Now the PMIP tunnel is established between the iWAG and the LMA. 7 The iWAG offers an IP address to the client and creates a binding. Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 117
1 The client sends an EAP authentication request to the AP or WLC. 2 The WLC sends an Access Request message to AAA server. 3 On receiving Access Accept message from the AAA server, the WLC authenticates the client or mobile node. Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
MAC address, the iWAG creates a session and sends an Access Request message to the AAA server. The iWAG downloads mobility parameters from the AAA server through an Access Accept message. The iWAG initiates PMIP signaling by sending a PBU message. The LMA responds with a PBA message. Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 120
This call flow covers the following: • Session roaming from iWAG 1 to another iWAG 2 • PMIP tunnel creation between LMA and iWAG 2 • Assigning same IP address to the MN after roaming • Session termination Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 121
1 A mobile node roams from iWAG 1 to iWAG 2. The mobile node directly sends the IP packet to iWAG 2. The iWAG 2 creates sessions and send access request to the AAA server. Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
#---------------------------------------------- IWAG2 (ASR 1000) Local Profile without AAA (Simple Configuration using the MN’s MAC) #---------------------------------------------- ipv6 unicast-routing policy-map type control PROXYRULE class type control always event session-start 10 proxy aaa list RP Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
No new or modified MIBs are supported by this To locate and download MIBs for selected platforms, feature. Cisco software releases, and feature sets, use Cisco MIB Locator found at the following URL: http://www.cisco.com/go/mibs Intelligent Wireless Access Gateway Configuration Guide...
Cisco ASR 1000 Series Aggregation Services Routers. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
The following figure and steps describe the call flow pertaining to a Dual-Stack Mobile IP over Ethernet (IPoE) session with Dynamic Host Configuration Protocol version 4 (DHCPv4) as first sign of life (FSOL) for PMIPv6. Figure 16: Dual-Stack Mobile IPoE Session with DHCPv4 as FSOL for PMIPv6 Call Flow Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 127
Dual-Stack Mobile IPoE Session with DHCPv4 as FSOL for PMIPv6 Call Flow 1 A mobile device is automatically associated to the service set identifier (SSID) broadcast by the access points to establish and maintain wireless connectivity. Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 128
8 The AAA server sends the RADIUS Access Accept message to the iWAG. 9 If the received profile has "cisco-mpc-protocol-interface" attribute with value as pmipv6, then iWAG initiates PMIPv6 tunneling by sending a Proxy Binding Update (PBU) message to the local mobility anchor (LMA).
The following figure and steps describe the call flow pertaining to a Dual-Stack Mobile IP over Ethernet (IPoE) session with IPv6 Neighbor Discovery (ND) as first sign of life (FSOL) for PMIPv6 Call Flow. Figure 17: Dual-Stack Mobile IPoE Session with IPv6 ND as FSOL for PMIPv6 Call Flow Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 130
Dual-Stack Mobile IPoE Session with IPv6 ND as FSOL for PMIPv6 Call Flow 1 A mobile device is automatically associated to the service set identifier (SSID) broadcast by the access points to establish and maintain wireless connectivity. Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 131
8 The AAA server sends the RADIUS Access Accept message to the iWAG. 9 If the received profile has "cisco-mpc-protocol-interface" attribute with value as pmipv6, then iWAG initiates PMIPv6 tunneling by sending a Proxy Binding Update (PBU) message to the local mobility anchor (LMA).
The following figure and steps describe the call flow pertaining to a Dual-Stack Mobile IP over Ethernet (IPoE) session with Dynamic Host Configuration Protocol version 4 (DHCPv4) as first sign of life (FSOL) for GTP. Figure 18: Dual-Stack Mobile IPoE Session with DHCPv4 as FSOL for GTP Call Flow Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 133
8 The AAA server sends the RADIUS Access Accept message to the iWAG. 9 If the received profile has "cisco-mpc-protocol-interface" attribute with value as GTP, then iWAG initiates GTP tunneling by sending a Create PDP Context Request to the GGSN.
The following figure and steps describe the call flow pertaining to a Dual-Stack Mobile IP over Ethernet (IPoE) session with IPv6 Neighbor Discovery (ND) as first sign of life (FSOL) for GTP. Figure 19: Dual-Stack Mobile IPoE Session with IPv6 ND as FSOL for GTP Call Flow Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Page 135
Dual-Stack Mobile IPoE Session with IPv6 ND as FSOL for GTP Call Flow 1 A mobile device is automatically associated to the service set identifier (SSID) broadcast by the access points to establish and maintain wireless connectivity. Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
8 The AAA server sends the RADIUS Access Accept message to the iWAG. 9 If the received profile has "cisco-mpc-protocol-interface" attribute with value as GTP, then iWAG initiates GTP tunneling by sending a Create PDP Context Request to the GGSN.
Unless noted otherwise, subsequent releases of that software release train also support that feature. Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Page 138
Call Flows for Dual-Stack PMIPv6 and GTP Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: http://www.cisco.com/go/trademarks.
Internet service provider (ISP) wants to offer its subscribers. The service provider must also be able to scale up to an expanding subscriber base. You can configure IWAG on the Cisco ASR1000 Series Routers for high scalability and performance.
128000 384000 Restrictions for iWAG Scalability The following are the restrictions pertaining to iWAG scalability: The Intelligent Wireless Access Gateway (iWAG) feature is not supported on the following hardware. • RP1 with ESP10 or ESP20 • ASR1002 • ASR1002F Intelligent Wireless Access Gateway Configuration Guide...
CAC can restrict creation of new sessions when system resources exceed configured thresholds. For examples about configuring the CAC for IPoE feature, see the “Call Admission Control” section in the Intelligent Wireless Access Gateway Configuration Guide located at: http://www.cisco.com/en/US/docs/routers/asr1000/configuration/guide/chassis/IWAG_Config_Guide_ BookMap_chapter_01001.html...
Title None — MIBs MIBs Link None To locate and download MIBs for selected platforms, Cisco IOS releases, and feature sets, use Cisco MIB Locator found at this URL: http://www.cisco.com/go/mibs RFCs Title None — Intelligent Wireless Access Gateway Configuration Guide...
Feature Information for IWAG Scalability and Performance table lists the features in this module and provides links to specific configuration information. Use Cisco Feature Navigator to find information about platform support and software image support. Cisco Feature Navigator enables you to determine which software images support a specific software release, feature set, or platform.
Page 144
Scalability and Performance Feature Information for iWAG Scalability and Performance Intelligent Wireless Access Gateway Configuration Guide OL-30226-03...
Need help?
Do you have a question about the Intelligent Wireless Access Gateway and is the answer not in the manual?
Questions and answers