Using Radius To Create And Apply Policies Overview - Juniper POLICY MANAGEMENT - CONFIGURATION GUIDE V11.1.X Configuration Manual

Junose software for broadband services routers policy management configuration guide
Table of Contents

Advertisement

JUNOSe 11.1.x Policy Management Configuration Guide

Using RADIUS to Create and Apply Policies Overview

E Series routers enable you to use RADIUS to create and apply policies on IPv4 and
IPv6 interfaces. This feature supports the Ascend-Data-Filter attribute [242] through
a RADIUS vendor-specific attribute (VSA) that specifies a hexadecimal field. The
hexadecimal field is encoded with policy attachment, classification, and policy action
information
The policy defined in the Ascend-Data-Filter attribute is applied when RADIUS receives
a client authorization request and replies with an Access-Accept message.
When you use RADIUS to apply policies, a subset of the router's classification fields
and actions is supported. The supported actions and classification fields are:
NOTE: An E Series router dynamically assigns names to the new classifier list and
policy list as described in "Ascend-Data-Filter Attribute for IPv4/IPv6 Subscribers in
a Dual Stack" on page 49.
To create a policy, you use hexadecimal format to configure the Ascend-Data-Filter
attribute on the RADIUS server. For example:
46
Using RADIUS to Create and Apply Policies Overview
mpls policy
vlan policy
Actions
Filter
Forward
Packet marking
Rate limit
Traffic class
Classifiers
Destination address
Destination port
Protocol
Source address
Source port
Ascend-Data-Filter="01000100 0A020100 00000000 18000000 00000000
00000000"

Advertisement

Table of Contents
loading

This manual is also suitable for:

E series

Table of Contents