Telco subscriber management
-
Subscriber policy enforcement and management.
-
Configure the appliance to uniquely identify a subscriber by using only the IPv6 prefix instead of the complete IPv6 address.
-
Use policies to optimize TCP traffic for both dynamic and static subscribers. These policies associate different TCP profiles with different types of users.
-
Manage idle sessions on a NetScaler appliance.
-
Enable logging to a log server.
-
Remove LSN sessions for deleted subscriber sessions.
Allocating memory for the subscriber session store module
Example
show extendedmemoryparam
Extended Memory Global Configuration. This memory is utilized by LSN and Subscriber Session Store Modules:
Active Memory Usage: 0 MBytes
Configured Memory Limit: 0 MBytes
Minimum Memory Required: 2058 MBytes
Maximum Memory Usage Limit: 2606 MBytes
Done
set extendedmemoryparam -memLimit 2558
Done
show extendedmemoryparam
Extended Memory Global Configuration. This memory is utilized by LSN and Subscriber Session Store Modules:
Active Memory Usage: 2558 MBytes
Configured Memory Limit: 2558 MBytes
Minimum Memory Required: 2058 MBytes
Maximum Memory Usage Limit: 2606 MBytes
Done
Configure an interface for dynamic subscribers
-
Starting with NetScaler release 12.0 build 57.19, Gx interface is supported for a cluster deployment. For more information see Gx interface in a cluster topology.
-
In an HA setup, the subscriber sessions are continually synchronized on the secondary node. In the event of a failover, the subscriber information is still available on the secondary node.
Gx interface
To set up a Gx interface, perform the following tasks
add service pcrf-svc1 203.0.113.1 DIAMETER 3868
add service pcrf-svc2 203.0.113.2 DIAMETER 3868
add lb vserver vdiam DIAMETER 0.0.0.0 0 -persistenceType DIAMETER -persistAVPno 263
bind lb vserver vdiam pcrf-svc1
bind lb vserver vdiam pcrf-svc2
set ns diameter –identity netscaler.com –realm com
set subscriber gxInterface -vServer vdiam -pcrfRealm pcrf.com
set subscriber param -interfaceType GxOnly
show subscriber gxinterface
Example
show subscriber gxinterface
Gx Interface parameters:
PCRF Vserver: vdiam (DOWN)
Gx Client Identity...: netscaler1.com
Gx Client Realm ..........: com
PCRF Realm: epc.mnc030.mcc234.3gppnetwork.org
Hold Packets On Subscriber Absence: YES
CCR Request Timeout: 4 Seconds
CCR Request Retry Attempts: 1
Gx HealthCheck enabled: NO
Gx HealthCheck TTL : 30 Seconds
CER Request Timeout: 10 Seconds
RevalidationTimeout: 30 Seconds
NegativeTTL: 60 Seconds
NegativeTTL Limited Success: NO
Purge SDB on Gx Failure: YES
ServicePath AVP code: 262099 ServicePath AVP VendorID: 3845
PCRF Connection State: PCRF is not ready
Done
ARGUMENTS
vServer
Service
pcrfRealm
holdOnSubscriberAbsence
requestTimeout
requestRetryAttempts
healthCheck
healthCheckTTL
cerRequestTimeout
revalidationTimeout
negativeTTL
negativeTTLLimitedSuccess
purgeSDBonGxFailure
servicePathAVP
servicePathVendorid
To configure Gx interface by using the GUI
-
Navigate to Traffic Management > Subscriber > Parameters.
-
Click Configure Subscriber Parameters.
-
In Interface Type, select GxOnly.
-
Specify the values for the all required parameters.
-
Click OK.
Detect transport failures over established Gx connections
-
If the DWA is received, a peer’s availability is confirmed and the watchdog timer is reset.
-
If the DWA is not received and the watchdog timer expires twice consecutively, the session is considered as down and peer unavailable. The appliance closes the session and tries to establish a new session with the Gx peer.
To detect transport failures over established Gx connections by using the CLI
set subscriber gxInterface [-vServer <string>] [-service <string>] [-healthCheck ( YES | NO )] [-healthCheckTTL<positive_integer>][-cerRequestTimeout <positive_integer>] [-purgeSDBonGxFailure ( YES | NO )]
set subscriber gxInterface set subscriber gxInterface -vServer vdiam -healthCheck YES -healthCheckTTL 31 -cerRequestTimeout 15 purgeSDBonGxFailure YES
To detect transport failures over established Gx connections by using the GUI
-
Navigate to Traffic Management > Subscriber > Parameters.
-
Click Configure Subscriber Parameters.
-
In Interface Type, select GxOnly.
-
Specify the values for all required parameters.
-
Select Health Check and specify values for Health Check TTL and CER Request Timeout.
-
Click OK.
Gx interface in a cluster topology
-
Sends a CCR-I request to the PCRF server to fetch subscriber information.
-
The PCRF server responds with a CCR-A.
-
The NetScaler node then stores the received subscriber information in its subscriber store and applies the rules to the client traffic.
To configure the diameter parameters by using the GUI
-
Navigate to System > Settings.
-
In the details pane, click Change Diameter Parameters.
-
In the Diameter Parameters page, select the NetScaler node for which you want to configure the diameter parameters and then click Configure.
-
In the Configure Diameter Parameters page, configure the diameter Identity, diameter Realm, and server Close Propagation for the selected node.
-
Click OK.
To configure the diameter parameters by using the CLI
set ns diameter [-identity <string>] [-ownerNode <positive_integer>]
ARGUMENTS
Identity
OwnerNode
show diameter -ownerNode <0-31>
To configure a Gx interface for cluster deployment
add service pcrf-svc1 203.0.113.1 DIAMETER 3868
add service pcrf-svc2 203.0.113.2 DIAMETER 3868
add lb vserver vdiam DIAMETER 0.0.0.0 0 -persistenceType DIAMETER -persistAVPno 263
bind lb vserver vdiam pcrf-svc1
bind lb vserver vdiam pcrf-svc2
set ns diameter -identity node0.netscaler.com -realm netscaler.com -ownerNode 0
set ns diameter -identity node1.netscaler.com -realm netscaler.com -ownerNode 1
set subscriber gxInterface -vServer vdiam -pcrfRealm pcrf.com
Set the subscriber interface type to GxOnly.
set subscriber param -interfaceType GxOnly
show subscriber gxinterface
RADIUS interface
add service srad1 192.0.0.206 RADIUSLISTENER 1813
set subscriber radiusInterface -listeningService srad1
set subscriber param -interfaceType RadiusOnly
add radius client 192.0.2.0/24 -radkey client123
show subscriber radiusInterface
add service pcrf-svc1 203.0.113.1 DIAMETER 3868
add service pcrf-svc2 203.0.113.2 DIAMETER 3868
ARGUMENTS
ListeningService
svrState
To configure RadiusOnly interface by using the GUI
-
Navigate to Traffic Management > Subscriber > Parameters.
-
Click Configure Subscriber Parameters.
-
In Interface Type, select RadiusOnly.
-
Specify the values for the all required parameters.
-
Click OK.
RADIUS and Gx interface
set subscriber param -interfaceType RadiusandGx
add service pcrf-svc 203.0.113.1 DIAMETER 3868
add lb vserver vdiam DIAMETER 0.0.0.0 0 -persistenceType DIAMETER -persistAVPno 263
bind lb vserver vdiam pcrf-svc
set subscriber gxInterface -vServer vdiam -pcrfRealm testrealm1.net -holdOnSubscriberAbsence YES -revalidationTimeout 60 -negativeTTL 120
add service srad1 192.0.0.206 RADIUSLISTENER 1813 set subscriber radiusInterface -listeningService srad1
To configure RadiusAndGx interface by using the GUI
-
Navigate to Traffic Management > Subscriber > Parameters.
-
Click Configure Subscriber Parameters.
-
In Interface Type, select RadiusAndGx.
-
Specify the values for the all required parameters.
-
Click OK.
Configure static subscribers
add subscriber profile 203.0.113.6 -subscriberRules policy1 policy2 -subscriptionIdType E164 -subscriptionIdvalue 98767543211
add subscriber profile 2002::a66:e8d3/64 -subscriberRules policy1 policy3 -subscriptionIdtype E164 -subscriptionIdvalue 98767543212
add subscriber profile 203.0.24.2 10 -subscriberRules policy2 policy3 -subscriptionIdtype E164 -subscriptionIdvalue 98767543213
> show subscriber profile
1) Subscriber IP: 203.0.24.2 VLAN:10
Profile Attributes:
Active Rules: policy2, policy3
Subscriber Id Type: E164
Subscriber Id Value: 98767543213
2) Subscriber IP: 2002::/64
Profile Attributes:
Active Rules: policy1, policy3
Subscriber Id Type: E164
Subscriber Id Value: 98767543212
3) Subscriber IP: 203.0.113.6
Profile Attributes:
Active Rules: policy1, policy2
Subscriber Id Type: E164
Subscriber Id Value: 98767543211
Done
Default subscriber profile
> add subscriber profile * -subscriberRules policy1
View and clear subscriber sessions
> show subscriber sessions
1) Subscriber IP: 2002::/64
Session Attributes:
Active Rules: policy1, policy3
Subscriber Id Type: E164
Subscriber Id Value: 98767543212
2) Subscriber IP: *
Session Attributes:
Active Rules: policy1
3) Subscriber IP: 203.0.24.2 VLAN:10
Session Attributes:
Active Rules: policy2, policy3
Subscriber Id Type: E164
Subscriber Id Value: 98767543213
4) Subscriber IP: 203.0.113.6
Session Attributes:
Active Rules: policy1, policy2
Subscriber Id Type: E164
Subscriber Id Value: 98767543211
5) Subscriber IP: 192.168.0.11
Session Attributes:
Idle TTL remaining: 361 Seconds
Active Rules: policy1
Subscriber Id Type: E164
Subscriber Id Value: 1234567811
Service Path: policy1
AVP(44): 34 44 32 42 42 38 41 43 2D 30 30 30 30 30 30 31 31
AVP(257): 00 01 C0 A8 0A 02
PCRF-Host: host.pcrf.com
AVP(280): 74 65 73 74 2E 63 6F 6D
Done
clear subscriber sessions <ip>
Subscriber policy enforcement & management system
add responder action error_msg respondwith '"HTTP/1.1 403 OKrnrn" + " You are not authorized to access Internet"'
add responder policy no_internet_access "SUBSCRIBER.RULE_ACTIVE("pol1")" error_msg
> add rewrite action AddHDR-act insert_http_header X-Nokia-MSISDN "SUBSCRIBER.AVP(45).VALUE"
> add rewrite policy AddHDR-pol "HTTP.REQ.HOSTNAME.APPEND(HTTP.REQ.URL).EQUALS_ANY("patset-test")" AddHDR-act
> add cache policy nocachepol -rule "SUBSCRIBER.RULE_ACTIVE("cache_disable")" - action NOCACHE
> add cache policy cachepol -rule "SUBSCRIBER.RULE_ACTIVE("cache_enable")" - action CACHE -storeInGroup cg1
IPv6 prefix based subscriber sessions
To configure the IPv6 prefix by using the command line
set subscriber param [-ipv6PrefixLookupList <positive_integer> ...]
set subscriber param -ipv6PrefixLookupList 64
set subscriber param -ipv6PrefixLookupList 64 72 96
To configure the IPv6 prefix by using the configuration utility
-
Navigate to Traffic Management > Subscriber > Parameters.
-
In the details pane, under Settings, click Configure Subscriber Parameters and in IPv6 Prefix Lookup List, specify one or more prefixes.
IP address and VLAN ID key lookup method
-
Includes the originating VLAN ID in the Gx query for IPv4 subscribers.
-
Includes the Gx VLAN AVP in all Gx responses. However, if there is a VLAN ID mismatch, the appliance ignores the responses.
-
Interface type RadiusAndGx and RadiusOnly cannot be configured together with key type IPANDVLAN.
-
If the traffic is from an IPv6 address, the NetScaler appliance uses the IP lookup method.
To configure IP or IPANDVLAN as the key lookup method by using the CLI
set subscriber param [-keytype ( IP | IPANDVLAN )] [-interfaceType <interfaceType>]
set subscriber param -keytype IPANDVLAN -interfaceType GxOnly
set subscriber param -keytype IP -interfaceType GxOnly
VLAN parameter
add subscriber profile <ip>@ [-vlan]
set subscriber profile <ip>@ [-vlan] [-subscriptionIdType <subscriptionIdType>]
show subscriber profile [<ip>@] [-vlan]
rm subscriber profile <ip>@ [-vlan <positive_integer>]
Arguments
ip
vlan
add subscriber profile 192.0.2.23 10
set subscriber profile 192.0.2.23 10 -subscriptionIdtype E164
show subscriber profile 192.0.2.23 10
rm subscriber profile 192.0.2.23 10
To configure IP or IPANDVLAN as the key lookup method by using the GUI
-
Navigate to Traffic Management > Subscriber > Parameters.
-
Click Configure Subscriber Parameters.
-
In Key Type, select IP or IPANDVLAN as per your requirement.
-
Complete the configuration and click OK.
Idle session management of subscriber sessions in a Telco network
To configure the idle session timeout and the associated action by using the command line
set subscriber param [-idleTTL <positive_integer>] [-idleAction <idleAction>]
set subscriber param -idleTTL 3600 -idleAction ccrTerminate
set subscriber param -idleTTL 3600 -idleAction ccrUpdate
set subscriber param -idleTTL 3600 -idleAction delete
To configure the idle session timeout and the associated action by using the configuration utility
-
Navigate to Traffic Management > Subscriber > Parameters.
-
In the details pane, under Settings, click Configure Subscriber Parameters and specify an Idle Time and Idle Action.
Subscriber session event logging
-
Session Event (Install, Update, Delete, Error)
-
Gx Message Type (CCR-I, CCR-U, CCR-T, RAR)
-
Radius Message Type (Start, Stop)
-
Subscriber IP
-
SubscriberID Type (MSISDN(E164), IMSI)
-
SubscriberID value
> add syslogAction sysact1 192.0.2.0 -loglevel EMERGENCY ALERT CRITICAL ERROR WARNING NOTICE INFORMATIONAL -subscriberlog enabled
-
The following log entries are examples of RADIUSandGx session creation, session update, and session deletion.09/30/2015:16:29:18 GMT Informational 0-PPE-0 : default SUBSCRIBER SESSION_EVENT 147 0 : Session Install, GX MsgType: CCR-I, RADIUS MsgType: Start, IP: 100.10.1.1, ID: E164 - 3000000000109/30/2015:16:30:18 GMT Informational 0-PPE-0 : default SUBSCRIBER SESSION_EVENT 148 0 : Session Update, GX MsgType: CCR-U, IP: 100.10.1.1, ID: E164 - 3000000000109/30/2015:17:27:56 GMT Informational 0-PPE-0 : default SUBSCRIBER SESSION_EVENT 185 0 : Session Delete, GX MsgType: CCR-T, RADIUS MsgType: Stop, IP: 100.10.1.1, ID: E164 - 30000000001
-
The following log entries are examples of failure messages, such as when a subscriber is not found on the PCRF server and when the appliance cannot connect to the PCRF server.09/30/2015:16:44:15 GMT Error 0-PPE-0 : default SUBSCRIBER SESSION_FAILURE 169 0 : Failure Reason: PCRF failure response, GX MsgType: CCR-I, IP: 100.10.1.1Sep 30 13:03:01 09/30/2015:16:49:08 GMT 0-PPE-0 : default SUBSCRIBER SESSION_FAILURE 176 0 : Failure Reason: Unable to connect to PCRF, GX MsgType: CCR-I, RADIUS MsgType: Start, IP: 100.10.1.1, ID: E164 - 30000000001#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000#000
Subscriber aware LSN session termination
To configure subscriber aware LSN session termination by using the CLI
> set lsn parameter -subscrSessionRemoval ENABLED
Done
> sh lsn parameter
LSN Global Configuration:
Active Memory Usage: 0 MBytes
Configured Memory Limit: 0 MBytes
Maximum Memory Usage Limit: 912 MBytes
Session synchronization: ENABLED
Subscriber aware session removal: ENABLED
To configure subscriber aware LSN session termination by using the GUI
-
Navigate to System > Large Scale NAT.
-
In Getting started, click Set LSN Parameter.
-
Set the Subscriber Aware Session Removal parameter.
Troubleshooting
-
show subscriber gxinterface This command's output can include the following error messages (shown here with suggested responses):
-
Gx Interface Not Configured-Use set subscriber param command to configure the correct interface type.
-
PCRF not configured-Configure a Diameter vServer or Service on GxInterface-Use the set subscriber gx interface command to assign a Diameter virtual server or service to this interface.
-
PCRF is not ready-Check corresponding vserver/service for more details-Use the show LB vserver or show service command to check the state of the service.
-
NetScaler is waiting for CEA from PCRF-Capability negotiation between the PCRF and NetScaler might be failing. This could be an intermittent state. If it persists, check the DIAMETER settings on your PCRF server.
-
Memory is not configured to store subscriber sessions. Please use 'set extendedmemoryparam -memlimit <>'-Use the set extendedmemoryparam command to configure extended memory.
-
-
show subscriber radiusinterface If "Not Configured" is the output of this command, use the set subscriber radiusinterface command to specify a RADIUSListener service.