05-06-2013 02:16 AM - edited 03-04-2019 07:49 PM
Hello everyone! We use ISG on asr1000 (l3 routed subscriber). Now we are trying to implement ipv6 isg sessions. so.. for ipv4 sessions we have
radius-server attribute 8 include-in-access-req radius-server attribute 32 include-in-access-req
but for ipv6 there is no such attribute#radius-server attribute ?
11 Filter-Id attribute configuration
188 Num-In-Multilink attribute configuration218 Address-Pool attribute
25 Class attribute30 DNIS attribute
31 Calling Station ID32 NAS-Identifier attribute
4 NAS IP address attribute44 Acct-Session-Id attribute
55 Event-Timestamp attribute6 Service-Type attribute
60 CHAP-Challenge attribute61 NAS-Port-Type attribute configuration
66 Tunnel-Client-Endpoint attribute67 Tunnel-Server-Endpoint attribute
69 Tunnel-Password attribute77 Connect-Info attribute
8 Framed IP address attribute95 NAS IPv6 address attribute
list List of Attribute Typesnas-port NAS-Port attribute configuration
nas-port-id Nas-Port-Id attribute configuration
what is best practice for authorize ipv6 l3 subscribers ?
05-06-2013 06:59 AM
Hi Evgeniy,
ISG IPv6 support will be supported in 3.10S, which should be released on CCO this summer.
Regards
05-06-2013 07:10 AM
what do you mean under "support"? We have got it working in 3.6. :-)
11149 IP authen Lterm 00:13:49 2 2A03:C700:0:2:6EF0:49FF:FE79:3870
RDR l4 working.. services with policing will be a bit later..
05-06-2013 07:45 AM
Hi Evgeniy,
Basic support has been there for a while as you mentionned. Full support for subscriber sessions will be in 3.10S. I presume the things you are looking for might not be supported yet.
Here's a list of what is currently supported:
http://www.cisco.com/en/US/docs/ios-xml/ios/isg/configuration/xe-3s/isg-ipv6.html
I will look to see if what you are looking for will be part of 3.10S.
Regards
09-21-2013 09:50 PM
nothing changed in 3.10 for ipv6 isg..
tac said that it will be in 3.11.. waiting..
12-20-2013 12:22 AM
3.11 still nothing about prefix authorization..
btw
i found "These sessions are identified by their unique IPv6 IP address or an IPv6 subnet session (IPv6 address and prefix)." in docs, where i can found mode info about ipv6 subnet session ? i mean radius attributes and etc..
problem:
some customers have a CPE device (PD), but other didn't have a CPE (so just /128 address). is it possible to auth this two types on single interface (under single policy) ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide