思科移动交换CMX课件.ppt
- 【下载声明】
1. 本站全部试题类文档,若标题没写含答案,则无答案;标题注明含答案的文档,主观题也可能无答案。请谨慎下单,一旦售出,不予退换。
2. 本站全部PPT文档均不含视频和音频,PPT中出现的音频或视频标识(或文字)仅表示流程,实际无音频或视频文件。请谨慎下单,一旦售出,不予退换。
3. 本页资料《思科移动交换CMX课件.ppt》由用户(三亚风情)主动上传,其收益全归该用户。163文库仅提供信息存储空间,仅对该用户上传内容的表现方式做保护处理,对上传内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知163文库(点击联系客服),我们立即给予删除!
4. 请根据预览情况,自愿下载本文。本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
5. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007及以上版本和PDF阅读器,压缩文件请下载最新的WinRAR软件解压。
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 思科 移动 交换 CMX 课件
- 资源描述:
-
1、1 2004 Cisco Systems,Inc.All rights reserved.Cisco Mobile Exchange2 2 2 2004 Cisco Systems,Inc.All rights reserved.SLAmonitoringSLAmonitoringSLAmonitoringAccessYours,anyonesCoreYours,anyonesServicesYours,anyonesOperatorControl point1OperatorControl point2Cisco Mobile Exchange Solution Set:Giving con
2、trol back to the operatorMS:Mobile StationSGSN:Servicing GPRS Support NodeGGSN:Gateway GPRS Support NodePDSN:Packet Data Serving NodeCMX:Cisco Mobile ExchangeMSFC:Multilayer Switch Feature CardRLB:Radius Load-balancerFWLB:Firewall Load-balancer SSG:Service Selection Gateway POP:Point of Presence CSG
3、:Content Services Gateway BMA:Billing Mediation AgentSESM:Subscriber Edge Service Manager3 3 3 2004 Cisco Systems,Inc.All rights reserved.The Cisco Mobile Exchange Scope Radio EdgeMobile Internet EdgeAggregationMSCRadius Web PortalServices SelectionMIPL2TPGREIPSecMPLSIPV4IPV6CMXSession establishment
4、IP routing&forwardingAddress allocationUser authenticationAccess selectionAccountingVPN edge functionService profileContent billing/accounting Charging gatewayLoad balancingNetwork managementVPNIntranetInternetInternetISP/ASPMVNOOpen GardenVPNWalledGardenWLAN2.5/3 GBSC/PCFCDMA 1X/DO/DVSGSNGGSNPDSNHA
5、Packet GWGGSN HA PDSN 802.11 VPN SGSNService Proxy Passthrough TunnelSSGs4 4 4 2004 Cisco Systems,Inc.All rights reserved.Framework of solutions targeted at the Subscriber Internet EdgeA collection of Cisco devices that provide consistent mobile and IP servicesDelivers cost effective and scalable so
6、lutions to meet the needs of Mobile OperatorsDemonstrates Cisco IOS/IP value add servicesLeverage Catalyst 7600 family with IP,mobile&content functionalityWhat is CMX?Cisco Mobile ExchangeNetwork Managementand OperationsPlatforms forPerformance and ReliabilityLoad Balancing and continuous availabili
7、ty.Mobile ServicesService SelectionContent MonitoringAdvanced BillingPacket Gateways(GPRS/UMTS,PDSN,HA,)5 5 5 2004 Cisco Systems,Inc.All rights reserved.Agenda SSG CSG Billing Hardware6 6 6 2004 Cisco Systems,Inc.All rights reserved.Service SelectionEnable Service SelectionSSG Service TypesService A
8、ccessSSGProxyPassthruUsernamePasswordInternet accessTunnelAccessing content partner networksCorporate accessAuto services logon(based on user configured settings)7 7 7 2004 Cisco Systems,Inc.All rights reserved.Typical Service Selection Call FlowRouterSESMAAA ServerPPPWeb RequestRedirectionUnAuth Us
9、er PageLogin ResponseLogin InfoAuthentication Get ProfileAccess control and service selectionService access based on user profileSSGClientAccess ControlPDSNAccounting-StartAccounting-Start8 8 8 2004 Cisco Systems,Inc.All rights reserved.Service Selection(SSG,SESM,AAA.)Features Include:Captive Portal
10、Open Garden(Free services)Walled Garden(Premium services)Prepaid ServicesHierarchical Policing Subscriber Self-CareAdvertisingRADIUS/Directory AuthenticationLocation brandingAuto loginWeb Services Gateway9 9 9 2004 Cisco Systems,Inc.All rights reserved.SSG Services SSG provides a way to give differe
11、nt types of subscriber access to particular IP domains.The IP Domains can be a single host,a subnetwork or multiple networks.Depending on the configuration the services can be authenticated or free access.101010 2004 Cisco Systems,Inc.All rights reserved.OPEN-GARDENOPEN-GARDEN(Free Services)(Free Se
12、rvices)Walled-GARDENWalled-GARDEN(Authenticated(Authenticated Services)Services)Services Network or Application AccessServices Network or Application AccessSubscriber ServicesSSGSSGBackboneBackboneSESM111111 2004 Cisco Systems,Inc.All rights reserved.Service Control User ExperienceTime/VolumePrepaid
13、/PostpaidAllowed&ChargedNot Allowed121212 2004 Cisco Systems,Inc.All rights reserved.SSG Service Summary Host Objects Connection Objects SubscriberINTERNETVODQUAKEHost-ObjService ObjectsNATNATL2TPPROXYRouted131313 2004 Cisco Systems,Inc.All rights reserved.SSG Service Access Types141414 2004 Cisco S
14、ystems,Inc.All rights reserved.SSG Service Access:Passthru Radius AAA is done by SSG Providers local AAA server Traffic is sent out“bound”interface based on service route definition Use next-hop table or explicit bindingsPassthrough Service TypeIntranetInternetSSGR192.168.1.0,255.255.255.0RADIUSR0.0
15、.0.0;SSG151515 2004 Cisco Systems,Inc.All rights reserved.SSG Service Definition:PassthruPassthrough Service TypeSample Passthrough Service Profilezap-com Password=“servicecisco”,Service-Type=OutboundService-Info=“I”,Service-Info=“R192.168.1.100;255.255.255.255”,Service-Info=“TP”service destination
16、route definitionService Type-passthroughRADIUS161616 2004 Cisco Systems,Inc.All rights reserved.SSG Service Definition:Passthru Passthrough Service Type(Internet)Sample Passthrough Service Profileintranet Password=“servicecisco”,Service-Type=OutboundService-Info=“IInternet”,Service-Info=“R0.0.0.0;0.
17、0.0.0”,Service-Info=R192.168.6.0;255.255.255.0;E,Service-Info=“TP”service destination route definition(special case for Internet)service type-passthroughRADIUS171717 2004 Cisco Systems,Inc.All rights reserved.SSG Service Access:Proxy-RADIUSThe SSG terminates user sessions from hosts to the SSG and m
18、akes a virtual Connection from the SSG to the service destinationThe SSG will Authenticate and Authorize the service via the remote Radius Server.The SSG does NAT if the remote RADIUS user authorization includes IP addressProxy-Radius Service TypeWeb PortalApplicationIntranetInternetExtranetRADIUSHT
19、TP TRAFFICRadius Request10.0.0.112.17.1.10Radius Reply(accept/IP)10.0.0.1192.168.1.10NATRADIUSSSG181818 2004 Cisco Systems,Inc.All rights reserved.SSG Service Definition:Proxy-RADIUSProxy-Radius Service TypeIP Address,Ports and shared-secret of Remote AAASample Proxy Service Profileproxy-service Pas
20、sword=“servicecisco”,Service-Type=OutboundService-Info=“IProxy-service”,Service-Info=“R12.17.1.10;255.255.255.255”,Service-Info=“S192.168.1.1;1812;1813;cisco”,Service-Info=“TX”service route definitionservice type-proxyRADIUS191919 2004 Cisco Systems,Inc.All rights reserved.SSG Service Access:L2TPLAC
21、 initiates L2TP tunnel to destination LNS,SSG-PPP session is establishedSSG-NAT is performed between subscribers IP address and LNS assigned IP addressTraffic is sent out the tunnel virtual-access interface based on service route definitionRadius AAA is done by SSG Providers local AAA server(RADIUS-
22、B)Tunnel(L2TP)Service TypeSSG-PPPVPDNR192.168.7.0,255.255.255.0RADIUS-ASubscriber ConnectionLACLNSRADIUS-BPool:192.168.1.xPPP SessionIOS-NAT10.0.0.1192.168.1.10SSG202020 2004 Cisco Systems,Inc.All rights reserved.SSG Service Definition:L2TPTunnel(L2TP)Service TypeSample Tunnel Service Profiletunnel1
23、 Password=“servicecisco”,Service-Type=OutboundService-Info=“IVPDN Tunnel Service”,Service-Info=“R192.168.1.0;255.255.255.0”,Service-Info=“vpdn:l2tp-tunnel-password=cisco”,Service-Info=“vpdn:ip-addresses=192.168.1.1”,Service-Info=“vpdn:tunnel-id=tunnelxyx”,Service-Info=“TT”Tunnel informationservice t
24、ype-TunnelRADIUS212121 2004 Cisco Systems,Inc.All rights reserved.SSG Host Object Building BlocksHost Object Maintains user information User IP address Created at time of user Account logon List of Services user can access222222 2004 Cisco Systems,Inc.All rights reserved.SSG-Service Object Building
25、BlocksService Object Maintains Info about SSG service Service Name Service IP Domain(s)Other Service Attributes232323 2004 Cisco Systems,Inc.All rights reserved.SSG-Connection Object Building BlocksConnection Object Accounting information Service QoS Created at time of Service logon242424 2004 Cisco
展开阅读全文