Cisco 10000 Series Internet Router Service Selection Gateway Configuration Guide
Index

Table Of Contents

A - B - C - D - E - F - H - I - L - M - N - O - P - Q - R - S - T - V - W - X -

Index

A

aaa group server radius command 6-4

AAA servers, proxy services 11-2, 11-3

access-side interfaces 9-2

accounting for SSG4-1to 4-4

accounting records (RADIUS) 4-2, 4-3

Account Session Time (Attribute 46) 3-4

Acct-Info attribute 6-9

Acct-Status-Type attribute 4-2, 6-4, 6-6

ACLs

downstream traffic attribute (outacl) 7-1, 11-4

implementation notes B-1

transparent passthrough 9-3

upstream traffic attribute (inacl) 7-2, 11-4

attributes

Account Session Time (Attribute 46) 3-4

Acct-Info 6-9

Acct-Status-Type 4-2, 6-4, 6-6

ACL (inacl and outacl) 7-1, 9-3, 11-4

Domain Name 7-2

Full Username RADIUS 4-1, 7-2

Idle Timeout (Attribute 28) 3-4, 3-6

MTU Size 7-2

Quota (Attribute 26) 3-4, 3-6

RADIUS Server 7-2, 11-2, 11-3

Service Authentication 7-2

Service-Defined Cookie 7-3

Service Description 7-3

Service Mode 7-3

Service Next-Hop Gateway 7-3

service profile7-1to 7-4

Service Route 7-3

Service URL 7-3, 7-4

Type of Service (TOS) 7-4

VSAs 3-4, 3-6

authentication G-1

authentication for SSG4-1to 4-4

AutoDomain services 6-1, 6-2

implementation notes B-1

autologoff 3-2

B

bandwidth G-1

broadcast G-1

C

cached service profiles 7-1, 7-4, 7-5

captive portal G-1

CEF

definition G-1

Cisco Express Forwarding

See CEF

Cisco Subscriber Edge Services Manager (SESM)

See SESM

clear pxf

interface command 12-3

statistics command 12-3

commands

aaa group server radius 6-4

clear pxf

interface 12-3

statistics 12-3

debug radius 12-2

download exclude-profile 6-8

no ssg enable force-cleanup 11-5

PXF 12-3

show

pxf cpu access-lists 12-3

pxf cpu buffers 12-3

pxf cpu cef 12-3

pxf cpu cef memory 12-3

pxf cpu context 12-3

pxf cpu mroute 12-3

pxf cpu queue 12-3

pxf cpu schedule 12-3

pxf cpu statistics 12-3

pxf cpu subblocks 12-3

pxf interface 12-3

pxf microcode 12-3

pxf statistics 12-3

ssg connection 12-2

version 1-6

ssg

aaa group prepaid 6-4

auto-domain 6-2

bind direction downlink 9-1

bind direction uplink 9-1

direction 9-2

open-garden 6-6

port-map enable 6-8

port-map source ip 6-7

service-cache enable 7-5

service-cache refresh 7-5

service-cache refresh-interval 7-5

SSG (list of) 12-1, 12-2

ssg service-overlap 11-10

TCP Redirect 10-6

configuring

AAA servers 11-2, 11-3

SSG interfaces 9-1

TCP Redirect 10-4, 10-5

transparent passthrough interfaces 9-1

connecting to SSG services4-3, 6-1to 6-9

D

debug radius command 12-2

default network 1-3

Digital Subscriber Line G-1

Directory Enabled Service Selection/Subscription (DESS) mode 5-2

disabling SSG 11-5, 11-6

Domain Name attribute 7-2

download exclude-profile command 6-8

download exclusion lists 6-8

DSL G-1

E

encapsulation

definition G-2

Ethernet G-2

exclusion lists

AutoDomain download 6-8

F

Full Username RADIUS attribute 4-1, 7-2

H

host key G-2

I

idle timeout 3-6

Idle Timeout (Attribute 28) 3-4, 3-6

inacl attribute 7-2, 9-3, 11-4

initial captivation for TCP Redirect 10-3, 10-4

interfaces

access-side 9-2

network-side 9-3

transparent passthrough 9-1

Internet Protocol G-2

ISP G-2

L

L2TP

implementation notes B-1

local forwarding, implementation notes B-2

logging in to SSG 3-1

logging on to SSG services 7-4, 7-5

login

RADIUS 4-2

logon

implementation notes B-1

M

mini-ACL G-2

Modular QoS Command-line interface

See MQC.

MPLS

implementation notes B-2

MQC, definition G-2

MTU Size attribute 7-2

multicast G-2

multicast protocols on SSG interfaces 9-3, 9-4

N

NAT, enabling 6-6

networks

accessing Open Garden 6-5, 6-6

default 1-3

excluding access to 6-8

network-side interfaces 9-3

no ssg enable force-cleanup command 11-5

O

OAP G-2

definition G-2

Open Garden 6-5, 6-6

implementation notes B-2

open garden G-2

outacl attribute 7-1, 9-3, 11-4

overlapping services

providing for 11-7

service translation 11-7, 11-8, 11-9, 11-10

P

packet filtering 11-3, 11-4, 11-5

parallel express forwarding

See PXF

passthrough

implementation notes B-3

PAT, enabling 6-6

performance

routing engine 1-6

permanent

virtual circuit G-3

virtual circuit or connection G-3

virtual path G-4

per service statistics

implementation notes B-2

ping, autologoff 3-2

Point-to-Point Protocol

See PPP

point-to-point subinterface G-3

policing, SSG hierarchical 8-1, 8-2

port G-3

Port-Bundle Host Key 6-6, 6-8

implementation notes B-2

PPP

definition G-3

PPPoA G-3

PPPoE

definition G-3

PPPoEoA, definition G-3

PPPoE over Ethernet G-3

PPPoE over IEEE 802.1Q VLAN

definition G-3

PPPoX G-3

PPP terminated aggregation

definition G-3

PPP terminated aggregation. See PTA

PPP terminated aggregation multidomain. See PTA-MD

PRE, part number ESR-PRE2 1-6

prepaid services

authorizing access 3-4

enabling 6-4, 6-5

idle timeout 3-3, 3-5, 3-6

implementation notes B-2

reauthorizing 3-3, 3-4

profiles

service group 6-8

PTA

definition G-3

PTA-MD G-3

PTA-MD service selection 5-1

PTA multi-domain

See PTA-MD

PTA service selection 5-1

PVC G-3

PVP G-4

PXF G-4

PXF, monitoring 12-3

Q

QoS

implementation notes B-1

Quota (Attribute 26) 3-4, 3-6

R

RADIUS

accounting records 4-2, 4-3

definition G-4

Idle Timeout attribute 3-4, 3-6

login 4-2

RADIUS Server attribute 7-2, 11-2, 11-3

Session-Timeout attribute 3-6

troubleshooting SSG problems with 12-2

virtual circuit logging 11-2

RBE

definition G-4

restrictions

AAA proxy services 11-2

AutoDomain 6-2

autologoff 3-2

Full Username RADIUS attribute 4-1

Open Garden 6-6

packet filtering 11-4

per-service statistics 12-2

policing 8-2

Port-Bundle Host Key 6-7

prepaid idle timeout 3-5

prepaid services 6-4

PTA-MD 5-2

SSG 1-4, 1-5, 2-1, 2-2

VPI/VCI service profiles 11-1

routed bridge encapsulation G-4

See RBE

S

selecting services 5-1, 5-2

Service Authentication attribute 7-2

service connection methods

AutoDomain 6-1, 6-2

Exclude Networks 6-8, 6-9

Open Garden 6-5, 6-6

Port-Bundle Host Key 6-6, 6-8

Prepaid 6-4

Service-Defined Cookie attribute 7-3

Service Description attribute 7-3

service groups 6-8

service IDs, network sets 11-11, 11-12

Service Mode attribute 7-3

Service Next-Hop Gateway attribute 7-3

service profiles

attributes7-1to 7-4

automatic download 7-5

cache feature 7-1, 7-4, 7-5

description 7-1

example 7-4

for VPI/VCI 11-1

implementation notes B-3

Service Route attribute 7-3

services

accessing multiple 5-1

AutoDomain 6-1, 6-2

connecting to6-1to 6-9

defining user 7-1

enabling prepaid 6-4, 6-5

logging on to 7-4, 7-5

per-service statistics 12-2

reauthorizing prepaid 3-3, 3-4

restricting access through mutually exclusive selection 6-8, 6-9

selecting 5-2

service selection dashboard, definition G-4

Service Selection Gateway, See SSG.

service selection methods

PPP terminated aggregation (PTA) 5-1

PTA multidomain (PTA-MD) 5-1

SESM 5-2

web 5-2

service translation, for overlapping services 11-7, 11-8, 11-9, 11-10

Service URL attribute 7-3, 7-4

SESM 1-2

definition G-4

session timeout 3-6

Session-Timeout RADIUS attribute 3-6

sets, for overlapping services 11-7

show

pxf

interface command 12-3

microcode command 12-3

statistics command 12-3

pxf cpu

access-lists command 12-3

buffers command 12-3

cef command 12-3

cef memory command 12-3

context command 12-3

mroute command 12-3

queue command 12-3

schedule command 12-3

statistics command 12-3

subblocks command 12-3

ssg connection command 12-2

version command 1-6

SMTP redirect

implementation notes B-3

SSD, definition G-4

SSG

attributes 3-4, 3-6, 4-2, 6-4, 6-6, 6-9

authentication and accouting4-1to 4-4

AutoDomain 6-1, 6-2

autologoff 3-2

captive portal G-1

commands 12-1, 12-2

defining user services 7-1

definition G-4

description 1-1, 1-2, 1-6, 1-7

enabling NAT and PAT 6-6

encapsulations supported 1-3

implementation notes B-1

interfaces 1-3, 9-1, 9-3, 9-4

logon and logoff 3-1

network access 6-8

Open Garden 6-5, 6-6

open garden G-2

packet filtering 11-3, 11-4, 11-5

Port-Bundle Host Key 6-6, 6-8

prepaid idle timeout 3-3, 3-5, 3-6

prepaid services 6-4, 6-5

protocols 1-3

restricting access to services 6-8, 6-9

restrictions 1-4, 1-5, 2-1, 2-2

service connection methods6-1to 6-9

service reauthorization 3-4

service selection 5-1, 5-2

SESM 1-2

session and idle timeout 3-6

Subscriber Edge Services Manager (SESM) 5-2

TCP Redirect10-1to 10-8

terminating services 4-3

traffic policing 8-1, 8-2

troubleshooting RADIUS problems 12-2

unconfig 11-5, 11-6

ssg

aaa group prepaid command 6-4

auto-domain command 6-2

bind direction downlink command 9-1

bind direction uplink command 9-1

direction command 9-2

open-garden command 6-6

port-map enable command 6-8

port-map source ip command 6-7

service-cache enable command 7-5

service-cache refresh command 7-5

service-cache refresh-interval command 7-5

ssg service-overlap command 11-10

Subscriber Edge Services Manager (SESM) 5-2

SVC G-4

switched virtual circuit G-4

T

TCP G-5

TCP Redirect

commands 10-6

configuring 10-4, 10-5

initial captivation 10-3, 10-4

unauthenticated users 10-1, 10-2

unauthorized services 10-2, 10-3

TCP redirect

implementation notes B-3

overview 10-1

terminating

SSG 11-5, 11-6

SSG services 4-3

token bucket policing algorithm 8-1

traffic policing 8-1, 8-2

Transmission Control Protocol G-5

transparent passthrough 9-1, 9-3

implementation notes B-3

turbo access control lists G-5

Type of Service (TOS) attribute 7-4

V

VC G-5

VCI G-5

vendor-specific attributes

definition G-5

virtual channel identifier

See VCI

virtual circuit

See VC

virtual circuit logging (RADIUS) 11-2

virtual path identifier

See VPI

virtual routing and forwarding

See VRF

VLAN G-5

VPI G-5

VPI/VCI

implementation notes B-3

service profiles 11-1

subscriber 11-2

VRF G-5

VSA

definition G-5

W

web service selection 5-2

web sites

accessing through Open Garden 6-5, 6-6

X

xDSL G-6