Applying An Acl To Multiple Subscriber Via Apns - Cisco ASR 5500 Administration Manual

Asr 5500 system administration guide, staros release 19
Table of Contents

Advertisement

Access Control Lists
Function
default subscriber
When configured properly, the functions described in the table above could be used to apply an ACL to:
• All subscribers facilitated within a specific context by applying the ACL to the profile of the subscriber
named default.
• All subscribers facilitated by specific services by applying the ACL to a subscriber profile and then
using the default subscriber command to configure the service to use that subscriber as the "default"
profile.

Applying an ACL to Multiple Subscriber via APNs

To apply the ACL to multiple subscribers via APN, use the following configuration:
configure
context dest_context_name [-noconfirm]
apn apn_name
Notes:
• The ACL to be applied must be in the destination context of the APN (which can be different from the
context where the APN is configured).
• If neither the in nor the out keyword is specified, the ACL will be applied to all inbound and outbound
packets.
• Up to eight ACLs can be applied to a group provided that the number of rules configured within the
ACL(s) does not exceed the 128-rule limit for the interface.
Applying an ACL to Multiple Subscriber via APNs
If IP ACLs are applied to subscribers via attributes in their profile, the subscriber profile could be configured
locally on the system or remotely on a RADIUS server.
To reduce configuration time, ACLs can alternatively be applied to APN templates for GGSN subscribers.
When configured, any subscriber packets facilitated by the APN template would then have the associated
ACL applied.
This section provides information and instructions for applying an ACL to an APN template.
Description
This command in the PDSN, FA, and HA service Configuration modes
specifies a profile from a subscriber named something other than default
to use a configuration template of attribute values for subscribers
authenticated in that context.
This command allows multiple services to draw "default" subscriber
information from multiple profiles.
{ ip | ipv6 } access-group acl_list_name [ in | out ]
end
Applying a Single ACL to Multiple Subscribers
ASR 5500 System Administration Guide, StarOS Release 19
199

Advertisement

Table of Contents
loading

Table of Contents