EPON System RADIUS Authorization User Manual.doc

15
EPON System RADIU Authorization 1. Connection Diagram 192.168.120.100 192.168.120.70 OLT RADIUS SERVER ONU 00:a1:02:01: af:c0 ONU 2. Log in EPON’s command line interface User name: admin Password: admin; Enable password: blank ( no password) Enter system’s sub‐interface: 3. Change EPON’s Radius parameters 1RADIUS authorization server’s IP address, port number,KEY Command epon(sys)# radius auth [ipaddr <ip_address>] [port <unsigned_short>] [priority <unsigned_short>] [key <string>]

Transcript of EPON System RADIUS Authorization User Manual.doc

Microsoft Word - EPON System RADIUS Authorization User Manual.doc

EPON System RADIU Authorization

1. Connection Diagram

192.168.120.100192.168.120.70

OLTRADIUS SERVER

ONU

00:a1:02:01:af:c0

ONU

2. Log in EPONs command line interface

User name: admin

Password: admin;

Enable password: blank ( no password) Enter systems subinterface:

3. Change EPONs Radius parameters

1RADIUS authorization servers IP address, port number,KEY

Command epon(sys)# radius auth [ipaddr ] [port ] [priority ] [key ]

1

radius auth commad include 4 optional index :

ipaddrRADIUS is authorization servers IP address

portRADIUS is the port number which the authorization server uses

priority RADIUS is the priority of the authorization server

key: the key to communicate with Raidus

When the command didnt have any indes , it would show as follows:

Change Radius authorization server IP address to : 192.168.120.70

2RADIUS AUTH Time Interval

Commandepon(sys)# radiusinterval[]

An optional index seconds is the radius AUTHs time interval .the budget range is 10 to

31536000 seconds. The default budget is 60 second. User could configure this index according to the real filed application.

Display current Radius AUTH time interval :

Change Radius Auth time interval is 10 seconds :

4. Change ONU Authorization mode to Radius Auth.

Enter onuauth interface and display current authorization mode:

The current ONU authorization mode is noe ,meaning non authorization. Commandepon(sysonuauth)#type[]

Index :

Blacklist

2

Whitelist

Noneno authorization

RadiusRADIUS Authorization

Change ONU authorization mode to Radius authorization :

5. Configure Radius authorization server index

Set up cdatas attributes :

Configure ONU(00A10201AFC0) authorization is enabled and configure following configuration

CDT_ONU_LLID1_UPCIRLLID1s uplink guaranteed bandwidth is 1024kbps CDT_ONU_LLID1_DOWNCIRLLID1s downlink guaranteed bandwidth is 2048kbps CDT_ONU_LLID1_UPMIRLLID1s uplink permitted bandwidth is 1024kbps CDT_ONU_LLID1_DOWNMIRLLID1s downlink permitted bandwidth is 1024kbps CDT_ONU_UNI1_ENABLEEnable ONU UNIT port 1

CDT_ONU_UNI1_UPSPEEDONU UNIT port1s uplink maximum bandwidth is 512kbps

CDT_ONU_UNI1_DOWNSPEEDONU UNIT PORT1s downlink maximum bandwidth is

4094kbps

CDT_ONU_UNI1_VLANONU Unit Port1s Vlan is 100

CDT_ONU_UNI2_VLANONU Unit Port 2s Vlan is 200

CDT_ONU_UNI3_VLANONU Unit Port 3s Vlan is 300

3

6. RADIUS Packets Exchange

RADIUS AccessRequest:

RADIUS AccessAccept:

4

7. Check out ONUs current configuration information via EMS software.(No need configuration on EMS ,just checkout).Pls find out the interface from the English version as follows :

ONU LINK SLA Configuration:

5

ONU Unit Port1 s Vlan configuration:

6

ONU UNIT port 2s Vlan configuration:

ONU Unit port 3s vlan configuration:

7

ONUPON Ports Vlan configuration (PON ports Vlan configuration is made automatically.)

8

ONU Unit ports speed limitation configuration

9

8. Radius Attribute that EPON supports

VENDOR ID18819VENDOR NAMECDATA

ATTRIBUTES:

ID

NAME

TYPE

RANGE

100

CDT_ONU_LLID1_UPCIR

integer

0~1000000 kbps

101

CDT_ONU_LLID1_DOWNCIR

integer

0~1000000 kbps

102

CDT_ONU_LLID1_UPMIR

integer

0~1000000 kbps

103

CDT_ONU_LLID1_DOWNMIR

integer

0~1000000 kbps

104

CDT_ONU_UNI1_ENABLE

integer

0:disable1:enable

105

CDT _ONU_UNI1_UPSPEED

integer

0~100000 kbps

106

CDT _ONU_UNI1_DOWNSPEED

integer

0~100000 kbps

107

CDT _ONU_UNI1_VLAN

integer

1~4094

108

CDT _ONU_UNI2_ENABLE

integer

0:disable1:enable

109

CDT _ONU_UNI2_UPSPEED

integer

0~100000 kbps

110

CDT _ONU_UNI2_DOWNSPEED

integer

0~100000 kbps

111

CDT _ONU_UNI2_VLAN

integer

1~4094

112

CDT _ONU _UNI3_ENABLE

integer

0:disable1:enable

113

CDT _ONU _UNI3_UPSPEED

integer

0~100000 kbps

114

CDT _ONU _UNI3_DOWNSPEED

integer

0~100000 kbps

115

CDT _ONU _UNI3_VLAN

integer

1~4094

116

CDT _ONU _UNI4_ENABLE

integer

0:disable1:enable

117

CDT _ONU _UNI4_UPSPEED

integer

0~100000 kbps

10

118

CDT _ONU _UNI4_DOWNSPEED

integer

0~100000 kbps

119

CDT _ONU _UNI4_VLAN

integer

1~4094

120

CDT _ONU _UNI5_ENABLE

integer

0:disable1:enable

121

CDT _ONU _UNI5_UPSPEED

integer

0~100000 kbps

122

CDT _ONU _UNI5_DOWNSPEED

integer

0~100000 kbps

123

CDT _ONU _UNI5_VLAN

integer

1~4094

124

CDT _ONU _UNI6_ENABLE

integer

0:disable1:enable

125

CDT _ONU _UNI6_UPSPEED

integer

0~100000 kbps

126

CDT _ONU _UNI6_DOWNSPEED

integer

0~100000 kbps

127

CDT _ONU _UNI6_VLAN

integer

1~4094

128

CDT _ONU _UNI7_ENABLE

integer

0:disable1:enable

129

CDT _ONU _UNI7_UPSPEED

integer

0~100000 kbps

130

CDT _ONU _UNI7_DOWNSPEED

integer

0~100000 kbps

131

CDT _ONU _UNI7_VLAN

integer

1~4094

132

CDT _ONU _UNI8_ENABLE

integer

0:disable1:enable

133

CDT _ONU _UNI8_UPSPEED

integer

0~100000 kbps

134

CDT _ONU _UNI8_DOWNSPEED

integer

0~100000 kbps

135

CDT _ONU _UNI8_VLAN

integer

1~4094

11