


 



<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://docwiki.cisco.com/w/skins/common/feed.css?270"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;feed=atom&amp;action=history</id>
		<title>Intelligent Services Gateway (ISG) -- Residential Access Using DHCP Sessions Configuration Example - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;action=history"/>
		<updated>2013-05-19T14:29:12Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.16.0</generator>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;diff=42262&amp;oldid=prev</id>
		<title>Lmendiol: /* Related Information */</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;diff=42262&amp;oldid=prev"/>
				<updated>2011-08-24T20:23:31Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Related Information&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 20:23, 24 August 2011&lt;/td&gt;
		&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 254:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 254:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[http://www.cisco.com/web/psa/products/index.html Technical Support &amp;amp;amp; Documentation - Cisco Systems] &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[http://www.cisco.com/web/psa/products/index.html Technical Support &amp;amp;amp; Documentation - Cisco Systems] &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [[Intelligent Services Gateway (ISG) -- WiMAX Service Provider Network Configuration Example&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [[Intelligent Services Gateway (ISG) -- WiMAX Service Provider Network Configuration Example]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/15-1s/isg-15-1s-book.html Intelligent Services Gateway Configuration Guide, Cisco IOS Release 15.1S]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/15-1s/isg-15-1s-book.html Intelligent Services Gateway Configuration Guide, Cisco IOS Release 15.1S]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/xe-3s/isg-xe-3s-book.html Intelligent Services Gateway Configuration Guide, Cisco IOS XE Release 3S]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/xe-3s/isg-xe-3s-book.html Intelligent Services Gateway Configuration Guide, Cisco IOS XE Release 3S]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[Category:Intelligent Services Gateway (ISG) Configuration Examples]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[Category:Intelligent Services Gateway (ISG) Configuration Examples]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Lmendiol</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;diff=42261&amp;oldid=prev</id>
		<title>Lmendiol: /* Related Information */</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;diff=42261&amp;oldid=prev"/>
				<updated>2011-08-24T20:22:44Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Related Information&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 20:22, 24 August 2011&lt;/td&gt;
		&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 254:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 254:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[http://www.cisco.com/web/psa/products/index.html Technical Support &amp;amp;amp; Documentation - Cisco Systems] &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[http://www.cisco.com/web/psa/products/index.html Technical Support &amp;amp;amp; Documentation - Cisco Systems] &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [[WiMAX Service Provider Network Configuration Example]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Intelligent Services Gateway (ISG) -- &lt;/ins&gt;WiMAX Service Provider Network Configuration Example&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/15-1s/isg-15-1s-book.html Intelligent Services Gateway Configuration Guide, Cisco IOS Release 15.1S]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/15-1s/isg-15-1s-book.html Intelligent Services Gateway Configuration Guide, Cisco IOS Release 15.1S]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/xe-3s/isg-xe-3s-book.html Intelligent Services Gateway Configuration Guide, Cisco IOS XE Release 3S]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/xe-3s/isg-xe-3s-book.html Intelligent Services Gateway Configuration Guide, Cisco IOS XE Release 3S]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[Category:Intelligent Services Gateway (ISG) Configuration Examples]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[Category:Intelligent Services Gateway (ISG) Configuration Examples]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Lmendiol</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;diff=42253&amp;oldid=prev</id>
		<title>Lmendiol: 1 revision</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;diff=42253&amp;oldid=prev"/>
				<updated>2011-08-24T19:20:11Z</updated>
		
		<summary type="html">&lt;p&gt;1 revision&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 19:20, 24 August 2011&lt;/td&gt;
		&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Lmendiol</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;diff=42252&amp;oldid=prev</id>
		<title>Lmendiol: /* Design */</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Intelligent_Services_Gateway_(ISG)_--_Residential_Access_Using_DHCP_Sessions_Configuration_Example&amp;diff=42252&amp;oldid=prev"/>
				<updated>2011-07-29T21:26:56Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Design&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
This example provides a sample configuration of Cisco Intelligent Services Gateway (ISG) deployed in a service provider's broadband network with residential subscriber access through DHCP-initiated sessions. &lt;br /&gt;
&lt;br /&gt;
== Design ==&lt;br /&gt;
&lt;br /&gt;
Service delivery model includes: &lt;br /&gt;
&lt;br /&gt;
*DHCP-initiated sessions with no features &lt;br /&gt;
*Transaparent auto-logon (TAL) based on DHCP option 82 &lt;br /&gt;
*Remote ID and web logon fallback through L4 redirect and change of authorization (CoA) &lt;br /&gt;
*Downloading of QoS profile from RADIUS server for authenticated users&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:209509.jpg]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
The following example shows the configuration of a Layer 2 subscriber network using the Port-Bundle Host Key (PBHK) and Layer 4 Redirect features. The basic behavior of the ISG is summarized in the control policy that is used when a First Sign of Life (FSOL) is detected. In this example, the FSOL is an unclassified source IP address.&lt;br /&gt;
&lt;br /&gt;
=== Control Policy ===&lt;br /&gt;
&lt;br /&gt;
The key to understanding an individual ISG configuration is generally the control policy, which maps out the actions taken by the ISG when different ISG events occur. The following example shows a control policy that allows some source IP address traffic to pass through the ISG without authentication, performing Transparent Auto Logon (TAL) for a set of predefined IP addresses, and performing web (portal) authentication for all other subscribers.&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;policy-map type control DHCP                                             &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|Control policy definition&lt;br /&gt;
|}&lt;br /&gt;
'''Session Start Events'''&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;class type control always event session-start&lt;br /&gt;
  5 authorize aaa list AUTHOR_LIST password EXAMP identifier remote-id    &lt;br /&gt;
  26 service-policy type service name L4REDIRECT_SERVICE&lt;br /&gt;
  27 service-policy type service name OPENGARDEN_SERVICE&lt;br /&gt;
  50 set-timer IP_UNAUTH_TIMER 10&lt;br /&gt;
! &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|Any FSOL traffic that does not match previous class maps is handled here.&lt;br /&gt;
*Authorize&lt;br /&gt;
*Apply L4 Redirection service&lt;br /&gt;
*Apply Open Garden service&lt;br /&gt;
*Set unauthenticated timer&lt;br /&gt;
|}&lt;br /&gt;
'''Account Logon Events'''&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;class type control always event account-logon                             &lt;br /&gt;
  10 authenticate aaa list default &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|On an account-logon event, authenticate the subscriber.&lt;br /&gt;
|}&lt;br /&gt;
'''Account Logoff Events'''&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;class type control always event account-logoff                            &lt;br /&gt;
  10 service disconnect delay 5 &lt;br /&gt;
! &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|Upon a account-logoff event, disconnect after a 5 second delay. This should ensure that the client TCP sessions close before disconnection.&lt;br /&gt;
|}&lt;br /&gt;
'''Session Restart Event'''&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;class type control always event session-restart&lt;br /&gt;
  5 authorize aaa list AUTHOR_LIST password 7300test identifier remote-id &lt;br /&gt;
  20 service-policy type service name OPENGARDEN_SERVICE&lt;br /&gt;
  30 service-policy type service name L4REDIRECT_SERVICE&lt;br /&gt;
  50 set-timer IP_UNAUTH_TIMER 10 &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|Upon a service-restart event, apply the service defined in the message.&lt;br /&gt;
|}&lt;br /&gt;
'''Timed Policy Expiry Event'''&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;class type control UNAUTHEN_COND event timed-policy-expiry                &lt;br /&gt;
  10 service disconnect &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|Upon a timed-policy-expiry event, if the class-map UNAUTHEN_COND is true, disconnect the session.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Class Maps ===&lt;br /&gt;
In the previous section class maps were used to select which actions would occur for certain events. The following examples show these class maps.&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;class-map type traffic match-any ISG_OPENGARDEN                      &lt;br /&gt;
 match access-group output name ACL_OUT_OPENGARDEN&lt;br /&gt;
 match access-group input name ACL_IN_OPENGARDEN &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|Class-map for the Open Garden Access Control List (ACL)&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;pre&amp;gt;class-map type control match-all IP_UNAUTH_COND                           &lt;br /&gt;
 match timer IP_UNAUTH_TIMER &lt;br /&gt;
 match authen-status unauthenticated &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|Class-map for unauthenticated user timeout&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AAA ===&lt;br /&gt;
AAA is a key part of ISG and ISG cannot operate without a minimum AAA configuration.&lt;br /&gt;
 &lt;br /&gt;
{|&lt;br /&gt;
'''AAA Server'''&lt;br /&gt;
|&amp;lt;pre&amp;gt;aaa new-model&lt;br /&gt;
!&lt;br /&gt;
aaa group server radius ISG_TEST&lt;br /&gt;
 server 10.10.96.34 auth-port 1812 acct-port 1813&lt;br /&gt;
 server 10.10.96.35 auth-port 1812 acct-port 1813&lt;br /&gt;
 ip radius source-interface GigabitEthernet1/0/4.1020                       &lt;br /&gt;
 attribute nas-port format d &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|This command is required.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Typical server group definition&lt;br /&gt;
|}&lt;br /&gt;
'''ISG Authentication and Accounting'''&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;aaa authentication login AUTHEN_LIST group AAA_GROUP&lt;br /&gt;
aaa authorization network AUTHOR_LIST group AAA_GROUP &lt;br /&gt;
aaa authorization subscriber-service default local group AAA_GROUP&lt;br /&gt;
aaa accounting update periodic 30&lt;br /&gt;
aaa accounting network ACCNT_LIST start-stop group AAA_GROUP &lt;br /&gt;
&lt;br /&gt;
aaa authorization network AUTHOR_LIST group ISG_TEST&lt;br /&gt;
aaa authorization subscriber-service default local group ISG_TEST &lt;br /&gt;
aaa accounting network default start-stop group ISG_TEST&lt;br /&gt;
aaa accounting network IP_SESSION start-stop group ISG_TEST group ISG_TEST1&amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|&lt;br /&gt;
*ISG authentication configuration&lt;br /&gt;
*ISG authorization configuration&lt;br /&gt;
*ISG subscriber services configuration&lt;br /&gt;
&lt;br /&gt;
*Periodic accounting updates&lt;br /&gt;
*ISG accounting configuration&lt;br /&gt;
|}&lt;br /&gt;
'''ISG RADIUS Server'''&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;radius-server attribute 44 include-in-access-req                          &lt;br /&gt;
radius-server attribute 6 on-for-login-auth&lt;br /&gt;
radius-server attribute 8 include-in-access-req&lt;br /&gt;
radius-server attribute 32 include-in-access-req &lt;br /&gt;
radius-server attribute 32 include-in-accounting-req &lt;br /&gt;
radius-server attribute 55 include-in-acct-req&lt;br /&gt;
radius-server attribute 55 access-request include&lt;br /&gt;
radius-server attribute 25 access-request include &lt;br /&gt;
radius-server attribute nas-port format d&lt;br /&gt;
radius-server attribute 31 send nas-port-detail mac-only                   &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|RADIUS extensions&lt;br /&gt;
|}&lt;br /&gt;
'''RADIUS Server'''&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;radius-server host 10.10.96.34 auth-port 1812 acct-port 1813 key 7 &amp;lt;Removed&amp;gt;&lt;br /&gt;
radius-server host 10.10.96.35 auth-port 1812 acct-port 1813 key 7 &amp;lt;Removed&amp;gt;&lt;br /&gt;
radius-server dead-criteria tries 3&lt;br /&gt;
radius-server retransmit 5&lt;br /&gt;
radius-server timeout 10&lt;br /&gt;
radius-server deadtime 15&lt;br /&gt;
radius-server directed-request&lt;br /&gt;
radius-server domain-stripping&lt;br /&gt;
radius-server key 7 &amp;lt;Removed&amp;gt;&lt;br /&gt;
radius-server vsa send accounting&lt;br /&gt;
radius-server vsa send authentication &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|RADIUS server&lt;br /&gt;
|}&lt;br /&gt;
'''CoA Portal'''&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;aaa server radius dynamic-author                                            &lt;br /&gt;
client 10.10.33.166&lt;br /&gt;
server-key 7 &amp;lt;Removed&amp;gt;&lt;br /&gt;
 auth-type any&lt;br /&gt;
 ignore session-key&lt;br /&gt;
 ignore server-key &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|Class of service (CoS) server &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Services ===&lt;br /&gt;
'''Open Garden Service''' &lt;br /&gt;
&lt;br /&gt;
The Open Garden service is a traffic class that is defined to only allow limited services prior to authentication. These services are typically Domain Name System (DNS), web portal, and any other services that are necessary to get the subscriber to a level where they can authenticate themselves. Examples of the service configuration are shown below.&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;ip access-list extended ACL_IN_OPENGARDEN&lt;br /&gt;
 …&lt;br /&gt;
 permit ip any host 10.10.33.166&lt;br /&gt;
 …&lt;br /&gt;
ip access-list extended ACL_OUT_OPENGARDEN&lt;br /&gt;
 …&lt;br /&gt;
 permit ip host 10.10.33.166 any&lt;br /&gt;
 …&lt;br /&gt;
&lt;br /&gt;
class-map type traffic match-any ISG_OPENGARDEN&lt;br /&gt;
 match access-group output name ACL_OUT_OPENGARDEN   &lt;br /&gt;
 match access-group input name ACL_IN_OPENGARDEN &lt;br /&gt;
&lt;br /&gt;
policy-map type service OPENGARDEN_SERVICE&lt;br /&gt;
 20 class type traffic ISG_OPENGARDEN &lt;br /&gt;
! &amp;lt;/pre&amp;gt;&lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|Define hosts reachable by subscribers.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Define return path for client traffic.&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Create class map based on the host ACLs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Define the Open Garden service&lt;br /&gt;
*Match the traffic class &lt;br /&gt;
*Action upon matching the class  &lt;br /&gt;
|}&lt;br /&gt;
'''Layer 4 Redirect Service'''&lt;br /&gt;
&lt;br /&gt;
The L4 Redirect service is typically used to force subscribers to a web portal for authentication purposes.&lt;br /&gt;
{|&lt;br /&gt;
|&amp;lt;pre&amp;gt;ip access-list extended ACL_IN_L4REDIRECT&lt;br /&gt;
 …&lt;br /&gt;
 deny   tcp any host 10.10.33.166&lt;br /&gt;
 permit tcp any any eq www&lt;br /&gt;
 permit tcp any any eq 443&lt;br /&gt;
 &lt;br /&gt;
class-map type traffic match-any L4REDIRECT&lt;br /&gt;
 match access-group input name ACL_IN_L4REDIRECT     &lt;br /&gt;
!&lt;br /&gt;
&lt;br /&gt;
policy-map type service L4REDIRECT_SERVICE&lt;br /&gt;
 10 class type traffic L4REDIRECT&lt;br /&gt;
  redirect to group ISG_GROUP&lt;br /&gt;
  accounting aaa list IP_SESSION&lt;br /&gt;
 !&lt;br /&gt;
 class type traffic default input&lt;br /&gt;
  drop&lt;br /&gt;
&lt;br /&gt;
redirect server-group ISG_GROUP&lt;br /&gt;
 server ip 10.10.33.166 port 80 &amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
|valign=&amp;quot;top&amp;quot;|Define traffic to be diverted&lt;br /&gt;
*Do not divert traffic going to the portal&lt;br /&gt;
*Divert all other web traffic&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Create a class map for the diverted traffic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Create L4 Redirect service&lt;br /&gt;
*Traffic that matches the class-map is sent to the redirect group&lt;br /&gt;
&lt;br /&gt;
Default action upon traffic not matching&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Define the redirect group&lt;br /&gt;
*Define the destination address and port&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Related Information ==&lt;br /&gt;
&lt;br /&gt;
[http://www.cisco.com/web/psa/products/index.html Technical Support &amp;amp;amp; Documentation - Cisco Systems] &lt;br /&gt;
&lt;br /&gt;
* [[WiMAX Service Provider Network Configuration Example]]&lt;br /&gt;
* [http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/15-1s/isg-15-1s-book.html Intelligent Services Gateway Configuration Guide, Cisco IOS Release 15.1S]&lt;br /&gt;
* [http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/xe-3s/isg-xe-3s-book.html Intelligent Services Gateway Configuration Guide, Cisco IOS XE Release 3S]&lt;br /&gt;
&lt;br /&gt;
[[Category:Intelligent Services Gateway (ISG) Configuration Examples]]&lt;/div&gt;</summary>
		<author><name>Lmendiol</name></author>	</entry>

	</feed>