Cisco ASR 5000 Series Administration Manual page 155

Gprs support node
Hide thumbs Also See for ASR 5000 Series:
Table of Contents

Advertisement

GGSN and Mobile IP Service in a Single System Configuration Example
Required Information
Mobile node re-registration
requirements
HA service Configuration
HA service name
UDP port number for
Mobile IP traffic
Mobile node re-registration
requirements
FA-to-HA Security
Parameter Index
Information
Mobile Node Security
Parameter Index
Information
OL-22944-02
Description
Specifies how the system should handle authentication for mobile node re-registrations.
The FA service can be configured to always require authentication or not. If not, the initial
registration and de-registration will still be handled normally.
This is an identification string between 1 and 63 characters (alpha and/or numeric) by which the HA
service will be recognized by the system.
Multiple names are needed if multiple HA services will be used.
HA services are configured in the destination context.
Specifies the port used by the HA service and the FA for communications. The UDP port number
can be any integer value between 1 and 65535. The default value is 434.
Specifies how the system should handle authentication for mobile node re-registrations.The HA
service can be configured as follows:
Always require authentication
Never require authentication
NOTE: The initial registration and de-registration will still be handled normally)
Never look for mn-aaa extension
Not require authentication but will authenticate if mn-aaa extension present.
FA IP address: The HA service allows the creation of a security profile that can be associated with
a particular FA.
This specifies the IP address of the FA that the HA service will be communicating with.
Multiple FA addresses are needed if the HA will be communicating with multiple FAs.
Index: Specifies the shared SPI between the HA service and a particular FA. The SPI can be
configured to any integer value between 256 and 4294967295.
Multiple SPIs can be configured if the HA service is to communicate with multiple FAs.
Secret: Specifies the shared SPI secret between the HA service and the FA. The secret can be
between 1 and 127 characters (alpha and/or numeric).
An SPI secret is required for each SPI configured.
Hash-algorithm: Specifies the algorithm used to hash the SPI and SPI secret. The possible
algorithms that can be configured are MD5 per RFC 1321 and keyed-MD5 per RFC 2002. The
default algorithm is hmac-md5.
A hash-algorithm is required for each SPI configured.
Index: Specifies the shared SPI between the HA service and a particular FA. The SPI can be
configured to any integer value between 256 and 4294967295.
Multiple SPIs can be configured if the HA service is to communicate with multiple FAs.
Secret: Specifies the shared SPI secret between the HA service and the FA. The secret can be
between 1 and 127 characters (alpha and/or numeric).
An SPI secret is required for each SPI configured.
Hash-algorithm: Specifies the algorithm used to hash the SPI and SPI secret. The possible
algorithms that can be configured are MD5 per RFC 1321 and keyed-MD5 per RFC 2002. The
default algorithm is hmac-md5.
A hash-algorithm is required for each SPI configured.
Cisco ASR 5000 Series Gateway GPRS Support Node Administration Guide ▄
Using the System as Both a GGSN/FA and an HA ▀

Advertisement

Table of Contents
loading

Table of Contents