IMPORTANT:
Creating and Configuring an HA Service
configure
context <ha_context_name>
ha-service <ha_service_name>
ip local-port <port_number>
authentication mn-aaa { allow-noauth | always | dereg-noauth | noauth | renew-and-dereg-noauth | renew-reg-noauth }
fa-ha-spi remote-address <fa_ip_address> spi-number <number> { encrypted secret <enc_secret> | secret <secret> } [ description <string> ] [ hash-algorithm { hmac-md5 | md5 | rfc2002-md5 } ]
mn-ha-spi
spi-number <number> [ description <string> ] { encrypted
secret <enc_secret> | secret <secret> } [ hash-algorithm { hmac-md5 | md5 | rfc2002-md5 } ] [ permit-any-hash-algorithm ] [ replay-protection { nonce | timestamp } [ timestamp-tolerance <tolerance> ]
reg-lifetime <lifetime>
simul-bindings <simul_bindings>
bind address <address> max-subscribers <max_subs>
end
Verifying HA Service Configuration
show ha-service { name service_name | all }
Service name: ha1
Context: ha
Bind:
Done Max Subscribers: 500000
Local IP Address:
192.168.4.10 Local IP Port: 434
Lifetime:
00h01m40s Simul Bindings: 3
Reverse Tunnel:
Enabled
GRE Encapsulation
with-key: Enabled Keyless GRE Encapsulation: Disabled
Optimize Tunnel Reassembly:
Enabled Setup Timeout: 60 sec
Allow Priv Addr w/o
Rev Tunnel: Disabled
WIMAX-3GPP2 Interworking: DisabledSPI(s):MNHA: Remote Addr: 0.0.0.0 Description:Hash Algorithm: HMAC_MD5 SPI Num: 258Replay Protection: Nonce Timestamp Tolerance: 100
Permit Any Hash
Algorithm: Enabled
FAHA: Remote Addr: 195.20.20.6/32 Description:Hash Algorithm: HMAC_MD5 SPI Num: 258Replay Protection: Timestamp Timestamp Tolerance: 60
'S' Lifetime Skew:
00h00m10s
IPSEC AAA Context:
aaa_context
GRE Sequence Numbers:
Disabled GRE Sequence Mode: None
GRE Reorder Timeout:
100 msec
GRE Checksum:
Disabled GRE Checksum Verification: Disabled
Registration Revocation:
Disabled Reg-Revocation I Bit: Enabled
Reg-Revocation Max
Retries: 3 Reg-Revocation Timeout: 3 (secs)
Reg-Rev Handoff old-FA:
Enabled Reg-Rev Idle-Timeout: Enabled
Send NAI Extension
in Reg-Revocation: Disabled
MIP NAT Traversal:
Disabled Force UDP Tunnel: Enabled
Default Subscriber:
None
Max Sessions: 500000
Service Status: Started
MN-AAA Auth Policy:
Always
MN-HA Auth Policy:
Always
IMSI Auth:
Disabled
DMU Refresh Key:
Disabled
AAA Distributed MIP
Keys:Disabled
AAA accounting:
Enabled
Idle Timeout Mode:
Aggressive
Newcall Policy:
None
Overload Policy:
Reject (Reject code: Admin Prohibited)
NW-Reachability Policy:
Reject (Reject code: Admin Prohibited)
Null-username Policy:
Reject
BC Rsp Code for Nw
Fail: 0xffff
IP Pool/Group:
Name: n/a
Destination Context:
n/a
Session Continuity Support
Hybrid HA Service Configuration
IMPORTANT:
configure
context <ha_context_name>
ha-service <ha_service_name>
authentication aaa-distributed-mip-keys
required
end
configure
context <ha_context_name>
ha-service <ha_service_name>
authentication aaa-distributed-mip-keys
disabled
end
configure
context <ha_context_name>
ha-service <ha_service_name>
authentication aaa-distributed-mip-keys
optional
wimax-3gpp2 interworking
end
WiMAX-3GPP2 Interworking at HA
Mobile Node Requirement
H-AAA Requirements
FA and HA Function for 3GPP-WiMAX Interworking at HA
configure
context <context_name>
fa-service <fa_service_name>
authentication aaa-distributed-mip-keys
override
revocation negotiate-i-bit
end
configure
context <context_name>
fa-service <fa_service_name>
default mn-aaa-removal-indication
revocation negotiate-i-bit
end
Note:
configure
context <ha_context_name>
ha-service <ha_service_name>
authentication aaa-distributed-mip-keys
required
wimax-3gpp2 interworking
authentication mn-aaa
allow-noauth
revocation negotiate-i-bit
end