Important: The commands or keywords/variables that are available are dependent on platform type, product version, and installed license(s).
aaa attribute { 3gpp2-bsid string | 3gpp2-service-option integer | calling-station-id integer | 3gpp2-serving-pcf ip-address }3gpp2-bsid stringstring must contain 12 hexadecimal upper-case ASCII characters.3gpp2-service-option integerinteger can be configured to any value in the range 0 - 32767calling-station-id integerinteger can be configured to any value from 1 - 15 numbers.3gpp2-serving-pcf ip-addressaaa attribute 3gpp2-bsid 0ab23289acb3Important: First phase authentication is mandatory when multiple authentication is configured on the system.
•
• aaa-group name: Name of the aaa-group to be used for authentication. name must be a string of size 1-63.
•
• aaa-group name: Name of the aaa-group to be used for authentication. name must be a string of size 1-63.Use the following to configure first-phase authentication for an aaa group named aaa-10 in the pdif context:crypto-template stringstring is any value from 0 - 127 alpha and/or numeric characters.max-sessions numbernumber can be any integer value from 0 to 3000000.The following command binds a service with the ip address 13.1.1.1 to the crypto template T1 and sets the maximum number of sessions to 2000000:default { { aaa attribute 3gpp2-service-option } | duplicate-session-detection | hss { failure-handling mac-address-validation-failure | mac-address-validation | update-profile } | ip source-violation { drop-limit | period } | setup-timeout | subscriber name | username mac-address-stripping } }
• mac-address-validation: By default, validating the MAC address is disabled.
• update-profile: By default, updating the PDIF profile is disabled.
• drop-limit: Default number of ip source violations permitted in detection period before the call is dropped is 10.
• period: Default detection period is 120 seconds.subscriber nameConfigures the default subscriber name. name is a string of 1-127 characters.
• continue: Ignore a mac-address-validation-failure and continue the session.
• terminate: Terminate the session on a mac-address-validation-failure.ims-sh-service name nameims-sh-service name ims1drop-limit numSets the number of allowed source violations within a detection period before forcing a call disconnect. If num is not specified, the value is set to the default.num can be any integer value from 1 to 1000000.period secsIf secs is not specified, the value is set to the default.secs can be any integer value from 1 to1000000.The following command sets the drop limit to 15 and leaves the other values at their defaults:foreign-agent context stringProvides the context name in which the FA is configured. string is any value in the range 1 - 79 alpha and/or numeric characters.fa-service stringDesignates the name of the FA service in the FA context. string is any value in the range 1 - 79 alpha and/or numeric characters.setup-timeout integersetup-timeout integerThis command manually sets the session setup timer. integer is a value in the range 2 - 300 seconds.
|
| Cisco Systems Inc. |
| Tel: 408-526-4000 |
| Fax: 408-527-0883 |