Documente Academic
Documente Profesional
Documente Cultură
Alcatel-Lucent
8950 Authentication, Authorization, and Accounting (AAA) | Release 8.1
QuickStart guide
365-360-007
Issue 2 | September 2013
Legal notice
Legal notice
Alcatel, Lucent, Alcatel-Lucent and the Alcatel-Lucent logo are trademarks of Alcatel-Lucent. All other trademarks are the property of their respective
owners.
The information presented is subject to change without notice. Alcatel-Lucent assumes no responsibility for inaccuracies contained herein.
Copyright 2013 Alcatel-Lucent. All rights reserved.
Contents
About this document
Purpose
............................................................................................................................................................................................. xi
xi
Intended audience
......................................................................................................................................................................... xi
xi
......................................................................................................................................................... xi
xi
........................................................................................................................................................................ xii
xii
Technical support
....................................................................................................................................................................... xiii
xiii
How to comment
........................................................................................................................................................................ xiii
xiii
................................................................................................................................................................ 1-1
1-1
...................................................................................................................................................................... 1-4
1-4
.................................................................................................................................. 2-2
2-2
Contents
....................................................................................................................................................................................................................................
........................................................................................................................................................... 2-4
2-4
................................................................................................................... 3-2
3-2
.................................................................................................................................. 3-13
3-13
................................................................................................................... 3-20
3-20
............................................................................................................................................................. 3-35
3-35
.................................................................................................................................................................... 3-36
3-36
Technical support
................................................................................................................................................................... 3-37
3-37
............................................................................................................................................ 4-2
4-2
....................................................................................................................................................................................................................................
8950 AAA
iv
365-360-007 Release 8.1
Issue 2 September 2013
Contents
....................................................................................................................................................................................................................................
Hardware needs
......................................................................................................................................................................... 5-1
5-1
............................................................................................................................................................................... 5-4
5-4
....................................................................................................................................................................................................................................
8950 AAA
v
365-360-007 Release 8.1
Issue 2 September 2013
Contents
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
vi
365-360-007 Release 8.1
Issue 2 September 2013
List of tables
1
........................................................................................................................... xii
....................................................................................................................................................................................................................................
8950 AAA
vii
365-360-007 Release 8.1
Issue 2 September 2013
List of tables
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
viii
365-360-007 Release 8.1
Issue 2 September 2013
List of figures
3-1
3-2
3-3
............................................................................................................................ 3-33
3-4
............................................................................................................................. 3-34
....................................................................................................................................................................................................................................
8950 AAA
ix
365-360-007 Release 8.1
Issue 2 September 2013
List of figures
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
x
365-360-007 Release 8.1
Issue 2 September 2013
Purpose
This guide helps you understand the system and platform requirements for the installation
of 8950 AAA, know how to install it, and estimate the hardware needs.
Intended audience
Installation
Operation
Engineering
Validation
This guide is also useful to any other user who wants to know more about 8950 AAA
installation and configuration procedures.
Supported systems
This publication applies to the 8950 AAA System Release 8.1 and 8.1.x.
How to use this document
The recommended approach for using this guide is to read the entire guide and refer to it,
as needed, for specific configuration details of the 8950 AAA.
The chapters that provide information on installation, pre requirements, system and
platform requirements, and so on of the 8950 AAA application are listed in the table as
follows:
Table 1
Document usage
Document organization
When to use
...................................................................................................................................................................................................................................
8950 AAA
xi
365-360-007 Release 8.1
Issue 2 September 2013
Table 1
Document usage
(continued)
Document organization
When to use
Chapter 5, Determine
hardware needs
Conventions used
The terms AAA and 8950 AAA describe the Alcatel-Lucent 8950 AAA server.
The terms USS and USSv1 describe the Universal State Server version 1.
The term USSv2 describes the Universal State Server version 2.
This guide uses the following typographical conventions as shown in the table.
Table 2
Appearance
Description
Emphasis
Document titles
Keyboard keys
System input
System output
variable
[]
{value1 | value2}
{variable1 | variable2}
....................................................................................................................................................................................................................................
8950 AAA
xii
365-360-007 Release 8.1
Issue 2 September 2013
Related information
The following documents are referenced in this document and include additional
information relevant to this document.
Alcatel-Lucent 8950 AAA Quick Start Guide; this guide provides information as to
how to install the 8950 AAA, where to obtain licenses, and about system
requirements.
Alcatel-Lucent 8950 AAA System Administration Guide, 365-360-009; this guide
provides a general information and features of the 8950 AAA, how to configure the
8950 AAA, and how to perform monitoring and administrative tasks.
Alcatel-Lucent User Provisioning System User Guide; this guide provides information
on the User Provisioning System (UPS) included in the 8950 AAA that allows you to
manage (create/search/modify/delete) users in a predefined DB schema.
All 8950 AAA documents are available at Alcatel-Lucent OnLine Customer Support Site
(http://support.alcatel-lucent.com/). Download the zipped files from the Downloads and
Registration section.
Document support
To order Alcatel-Lucent documents, contact your local sales representative or use Online
Customer Support (OLCS) (http://support.alcatel-lucent.com).
Technical support
For technical support, contact your local Alcatel-Lucent customer support team. See the
Alcatel-Lucent Support web site (http://www.alcatel-lucent.com/support/) for contact
information.
For Alcatel-Lucent remote technical support and warranty claims, send an e-mail to
(mailto:support@alcatel-lucent.com).
How to comment
To comment on this document, go to the Online Comment Form (http://infodoc.alcatellucent.com/comments/) or e-mail your comments to the Comments Hotline
(comments@alcatel-lucent.com).
....................................................................................................................................................................................................................................
8950 AAA
xiii
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
8950 AAA
xiv
365-360-007 Release 8.1
Issue 2 September 2013
Overview
Purpose
This chapter provides a brief overview of the 8950 AAA server and lists the main product
features. The chapter also provides information about the platforms supported by the
8950 AAA and the hardware and memory requirements to install and run the 8950 AAA.
Contents
8950 AAA overview
1-1
Platform support
1-3
Java environment
1-4
Server memory
1-5
Server storage
1-5
Hardware requirements
1-6
The 8950 AAA server is a highly flexible AAA server available today for remote access
services. The 8950 AAA handles user requests for access to network resources and
provides authentication, authorization, and accounting (AAA) services. This guide
provides information to help you understand system and platform requirements, install
8950 AAA, and estimate hardware needs.
...................................................................................................................................................................................................................................
8950 AAA
1-1
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
The main product features of the 8950 AAA server are as follows:
Radius
Diameter
TACACS+
EAP-GTC
EAP-SIM
EAP-AKA
EAP-FAST
Implements XML-based dictionary, which is a superset of RFC standard and Vendor
Specific Attributes (VSA).
This design provides the 8950 AAA, the ability to adapt to various vendors in any
network.
Offers a built-in programming language for writing custom 8950 AAA policy
applications. The PolicyFlow language allows configuration of the 8950 AAA
according to any complex policy rules of a network. The proprietary PolicyFlow
architecture built on Java programming language is flexible and extensible.
Provides a Command Line Interface (CLI) in addition to the SMT.
The CLI allows you to access and operate the 8950 AAA in any network environment.
It supports Telnet and SSH-based CLI through the admin console. An administrator
can use this CLI for executing commands for administrative purposes.
Supports the Server Management Tool (SMT) that provides a graphical remote
configuration and management interface to all features of the 8950 AAA.
Interfaces with the following back-end systems:
SQL database (JDBC complaint)
LDAP server
....................................................................................................................................................................................................................................
8950 AAA
1-2
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
Platform support
Hardware and platform support
Solaris: Solaris 10
Linux: Red Hat 5.x and 6.x
Windows: Server 2003, XP, Server 2008, Vista, and Windows7
Oracle: Oracle T1000/T2000 and X86 hardware. Install the hardware with Solaris 10
OS version and Oracle JRE1.7
Ulticom D7G product: HP x86 machines with Red Hat Linux 6.3 or above
Note: For more information on the latest versions of the operating systems and
hardware supported by the 8950 AAA, refer ReleaseNotes.html included in your
software package. When installed, you can find the release notes in the
<AAA_Install>\doc folder.
....................................................................................................................................................................................................................................
8950 AAA
1-3
365-360-007 Release 8.1
Issue 2 September 2013
Java environment
....................................................................................................................................................................................................................................
Java environment
Using Java
Before you install the 8950 AAA, check that you have the appropriate version of Java,
that is, the Java 2 Standard Edition (J2SE) for the 8950 AAA and install Java on your
system.
The 8950 AAA requires Java 2 Standard Edition (J2SE) version 7.0 (also known as
version 1.7.0) or later to run on all platforms. Both J2SE JDK and JRE are supported.
However, JDK is recommended as it provides additional tools for supporting Java
applications.
Contact the operating system vendor or for information on Java support for your
computer. It is important that the operating system and Java environment are kept at
current patch levels.
Download latest Java version
The 8950 AAA does not run with the MS-Java release included in many Windows
releases.
If your server does not have the correct Java version installed, get the current Java version
as per the operating systems. For Windows, Solaris, and Linux platform, visit the Oracle
web site: (http://www.oracle.com/technetwork/java/index.html)
Check current Java version
Note: The Java version displayed is the version available on your system.
....................................................................................................................................................................................................................................
8950 AAA
1-4
365-360-007 Release 8.1
Issue 2 September 2013
Server memory
....................................................................................................................................................................................................................................
Server memory
Memory allocation
By default, memory allocated for 8950 AAA process is 1 GB for a 32 bit JVM.
Memory use is affected by the following factors:
Server configuration.
User file size (when used).
Total number of active subscribers (during peak hour).
Whether the Universal State Server (USS) or the Server Management Tool (SMT)
runs on the same platform as that of the 8950 AAA server.
Note: For the memory configuration, contact 8950 AAA product support team to get a
confirmation on the following:
Server storage
Storage requirements
The server must have at least 150 MB of free disk space for installation.
Note: The storage requirement of 150 MB is for installation. For daily operations,
allow storage space for accounting data and log files. The actual amount of disk space
needed for logs and accounting records depends on many factors such as logging
level, accounting detail, and the length of time for which the data is retained.
Additional storage is also required for USS/USSv2 persistence files, IPAMv2, and
Statistics Collector, if configured.
....................................................................................................................................................................................................................................
8950 AAA
1-5
365-360-007 Release 8.1
Issue 2 September 2013
Hardware requirements
....................................................................................................................................................................................................................................
Hardware requirements
For more details on estimating system hardware requirements, see Chapter 5, Determine
hardware needs.
....................................................................................................................................................................................................................................
8950 AAA
1-6
365-360-007 Release 8.1
Issue 2 September 2013
Overview
Purpose
This chapter describes the several system and server requirements that must be met to
ensure a complete installation.
Contents
Download latest 8950 AAA version
2-2
2-3
2-3
2-3
2-4
...................................................................................................................................................................................................................................
8950 AAA
2-1
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
This procedure provides instructions to download the latest 8950 AAA installation
package from the Alcatel-Lucent OnLine Customer Support Site.
Before you begin
To download the software, you need to be a registered user with login credentials.
To get the latest version
...................................................................................................................................................................................................
From the drop-down list box in the Technical Content For section, select 8950 AAA
(Authentication, Authorization, and Accounting).
...................................................................................................................................................................................................
Follow the instructions and download the zipped folder for the latest version of 8950
AAA software. The zipped folder contains the installation files of both Windows and
UNIX operating systems.
Note: If required, download the zipped folder of documents from the same location.
...................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
2-2
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
The 8950 AAA requires a valid license for installation. If you are using a demonstration
copy, you require an evaluation license that is valid for six months. Permanent licenses
are specific to a single major version such as 7.x.x or 8.x.x. Upgrading 8950 AAA point
releases for example, version 7.0.x to 7.2.x or version 7.2.1 to 7.2.2, does not require a
different license. If you are performing a major version upgrade for example, 7.x. to 8.x, a
new license is required.
For more information on version upgrades and to obtain licenses, contact your local
Alcatel-Lucent sales representative.
You need to have a file extraction utility for the 8950 AAA archive type. Use the file
extraction utilities to extract files from the aaa-8.x.x.zip file you download from the 8950
AAA website.
Note: Some unzip programs truncate file names longer than 8 characters. This
prevents the 8950 AAA installer to run. Ensure that your unzip program does not
truncate or alter file names.
It is important that operating systems are at their current patch level. Failure to install
required patches can significantly impact the operation of 8950 AAA. For information on
the patches available for your server, contact the operating system vendor or
representative or visit their support website. Verify that all applicable patches are applied
to your Java environment.
....................................................................................................................................................................................................................................
8950 AAA
2-3
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
In either case, the original software is replaced with the new version of 8950 AAA
software.
....................................................................................................................................................................................................................................
8950 AAA
2-4
365-360-007 Release 8.1
Issue 2 September 2013
Overview
Purpose
This section provides the steps required to install the 8950 AAA server on a
UNIX/LINUX or Windows platform. It addresses the requirements and procedures
necessary for new installations only. When upgrading the 8950 AAA server, ensure not to
overwrite existing configuration files.
Contents
Install 8950 AAA server on UNIX/LINUX
3-2
3-8
3-13
3-13
3-14
3-16
3-18
3-20
3-23
3-27
3-29
Connect local SMT or MT to remote AAA server using RMI over SSH or NAT
3-31
3-34
3-35
3-36
Technical support
3-37
...................................................................................................................................................................................................................................
8950 AAA
3-1
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
Before you begin, ensure that you have a valid license file for the 8950 AAA software
version you are installing.
Procedure
...................................................................................................................................................................................................
Open the terminal window and extract the aaa-8.x.x.zip to a temporary directory.
...................................................................................................................................................................................................
Note: The Java version displayed is the version available on your system.
...................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
3-2
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
Press Enter key to accept the default directory or enter the desired location.
Result: The following prompt appears if the directory does not exist:
The directory does not exist. Do you want to create it? [Y /
N (Default)]
...................................................................................................................................................................................................
To install the 8950 AAA server, type 1 and press the Enter key.
Result: The following prompt appears if the license file is not in the installation
directory:
Enter path that contains the license file:
...................................................................................................................................................................................................
Enter the path to reflect the location of your license file. Press Enter key.
Result: The following prompt appears:
Enter the administrator's user credentials for the Servers:
Administrator User [admin]:
....................................................................................................................................................................................................................................
8950 AAA
3-3
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
...................................................................................................................................................................................................
10
11
Press Enter key to accept the default company name, or change the name if required.
Enter the other details as follows:
Enter the Website:
Enter the City:
Enter the State:
Enter the Country:
Result: The following prompt appears:
Enter the Root Password (required):
...................................................................................................................................................................................................
12
Enter the password for root certificate and press Enter key.
Note: 8950 AAA allows secure communication from the remote client-SMTs to the
8950 AAA servers, when connecting to the built-in web service, and for
communication between Diameter peers. The 8950 AAA can act as a CA (Certificate
Authority) to issue server or client certificates. Root password entered here is the
password for the Root-CA Certificate. Server password entered in the next step is the
password for the Server certificate for 8950 AAA server process.
Result: The following prompt appears:
Enter the Server Password (required):
...................................................................................................................................................................................................
13
Enter the password for server certificate and press the Enter key.
....................................................................................................................................................................................................................................
8950 AAA
3-4
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
14
Enter the file name of the root certificate and press the Enter key.
Result: The following prompt appears:
Enter the Trusted Certificate File Name [trusted.pem]:
...................................................................................................................................................................................................
15
Enter the file name of the trusted certificate and press the Enter key.
Result: The following prompt appears:
Enter the Server Certificate File Name [server.pem]:
...................................................................................................................................................................................................
16
Enter the file name of the server certificate and press the Enter key.
Result: You are prompted to change or accept the default company name, website,
17
....................................................................................................................................................................................................................................
8950 AAA
3-5
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
LTE Configuration
The Alcatel-Lucent LTE configuration is a predefined PolicyFlow
that works specifically with LTE eHRPD installations.
Sample Set
Installs a predefined PolicyFlow configuration. Select a set
from the list to install it.
Build Your Own
Installs an empty PolicyFlow. Use this option if you want to
configure your own PolicyFlow.
Install: PolicyAssistant [P], Wimax [W], Femto [F], LTE eHRPD
[L], Sample from List [S], or Build Your Own [B]:
...................................................................................................................................................................................................
18
Enter the appropriate letter to install the required Policy Set. Press Enter key to complete
the installation process.
Result: When the installation is complete, the following output is displayed and you
Note: For prompt less installation use the command line options. To know about the
command line options, use the following command:
./setup.sh -usage
....................................................................................................................................................................................................................................
8950 AAA
3-6
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
8950 AAA can also be installed using a GUI form of installer. Follow the steps to install
the 8950 AAA:
1. Open the terminal window and extract the aaa-8.x.x.zip to a temporary directory.
2. Type the following at the command prompt:
./setup.sh -gui
....................................................................................................................................................................................................................................
8950 AAA
3-7
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
This procedure provides instructions to install the 8950 AAA server on Microsoft
Windows platform.
Before you begin
The Microsoft Windows 8950 AAA Setup program assists you through a series of
interactive panels that contain information about configuring the 8950 AAA installation.
As you progress through the panels you are asked to make several decisions. Read each
panel and carefully follow the instructions.
Ensure that you have a valid license file for the 8950 AAA software version you are
installing.
Procedure
...................................................................................................................................................................................................
Navigate to the location of the unzipped 8950 AAA files and double-click setup.exe. The
8950 AAA Setup program is displayed. Click Next twice.
Result: The Software License Agreement window appears.
...................................................................................................................................................................................................
If you agree to the licensing terms, select Accept License Agreement Terms and click
Next.
....................................................................................................................................................................................................................................
8950 AAA
3-8
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
...................................................................................................................................................................................................
Then...
Click Next.
Click Next.
Enter the full path and the name of the folder.
Click Next.
Note: You are prompted to allow the folder to be created.
Click Yes.
....................................................................................................................................................................................................................................
8950 AAA
3-9
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
...................................................................................................................................................................................................
...................................................................................................................................................................................................
Follow the instructions listed on the dialog to specify the location of the license file and
click Next.
....................................................................................................................................................................................................................................
8950 AAA
3-10
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
...................................................................................................................................................................................................
Enter the administrator information (username and password) and click Next.
Result: The 8950 AAA Policy Set Installation window is displayed.
...................................................................................................................................................................................................
Follow the instructions on the dialog to select the desired Configuration Set.
Note: If you select the Install WiMAX Configuration set, WiMAX Configuration
window appears. Follow the instructions on the dialog and select the required
WiMAX set.
....................................................................................................................................................................................................................................
8950 AAA
3-11
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
Click Next.
Result: The Certificate Configuration window is displayed.
...................................................................................................................................................................................................
Enter the Root Password and the Server Password (this allows secure connection from
SMT to the Servers). The default file names and location information are displayed. Edit
the information if required.
Result: The 8950 AAA is installed on the selected location.
10
Click Finish to close the installation program, or click Run Server Management Tool to
start the SMT to configure and manage your servers.
Note: You can also view the Release Notes from the Setup Complete dialog box.
E...................................................................................................................................................................................................
N D O F S T E P S
....................................................................................................................................................................................................................................
8950 AAA
3-12
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
If you want to configure or monitor the 8950 AAA Servers from a remote machine, you
can install only the Server Management Tool (SMT) GUI on the remote machine. The
configuration server must be running on the 8950 AAA server before launching the
remote SMT GUI client to connect to the 8950 AAA server.
To install the Server Management Tool follow the instructions to install 8950 AAA on
UNIX or on Windows, however, when you are prompted to install either the 8950 AAA
Server or Server Management Tool, select Install Server Management Tool check box.
Note: If you do not have access to the SMT because of firewall restrictions or other
environment limitations, you can still access the sample Policy Sets shipped with the
8950 AAA, with the exception of the PolicyAssistant. The PolicyAssistant is a
UI-based interactive tool used to help create and manage policies.
The 8950 AAA software package includes certain third-party software bundled along with
it. By installing the 8950 AAA software package, you implicitly agree to these third-party
software licenses also.
More information about the third-party software licenses is found at the
<AAA-Install>\doc\legalfolder. All terms and conditions listed, disclaimers, and
copyright notices provided are based on information made available to the 8950 AAA by
the third-party licensors.
....................................................................................................................................................................................................................................
8950 AAA
3-13
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
Windows
UNIX or Linux
Related information
The 8950 AAA Server Management Tool (SMT) is an application that is used to
configure and manage 8950 AAA servers. SMT is a graphical user interface that
interfaces with the 8950 AAA server and can be used to manage all aspects of server
operation. The SMT is a standalone application that is started and run independently of
the 8950 AAA server.
You can also install the 8950 AAA on a UNIX server and the SMT GUI on your PC.
Before you connect to the 8950 AAA server from remote SMT GUI, ensure to start the
configuration server on the UNIX server. For information on how to start the
configuration server, see Start 8950 AAA configuration server (p. 3-16).
Before you begin
On Windows platform
Choose one of the following methods to start the SMT:
....................................................................................................................................................................................................................................
8950 AAA
3-14
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
In the Server Management Tool Login screen, enter the user name and password.
...................................................................................................................................................................................................
Click Connect.
Result: The 8950 AAA Server Management Tool launches.
E...................................................................................................................................................................................................
N D O F S T E P S
....................................................................................................................................................................................................................................
8950 AAA
3-15
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
This topic provides various methods that you can use to start the configuration server.
Related information
The configuration server runs on the 8950 AAA server machine. Configuration server is
used by the remote SMT GUI to configure or monitor the 8950 AAA server from a
remote machine.
Before you begin
None
Steps
...................................................................................................................................................................................................
Perform one of the following tasks where the 8950 AAA server is installed to start the
configuration server:
From the SMT application - in the SMT navigation pane, click the Configuration
Server tool icon, .
Select Start Server in the drop-down list.
Result: The configuration server starts and the status changes to green in SMT.
As a Windows service - navigate to Start Menu -> Control Panel -> Administrative
Tools -> Services.
Select 8950 AAA Configuration Service from the list of applications.
In the left-hand panel, click Start the service, or right-click and select Start.
Result: The server starts as a Windows service. The status changes to Started.
E...................................................................................................................................................................................................
N D O F S T E P S
....................................................................................................................................................................................................................................
8950 AAA
3-16
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
You can check the status of the configuration server in one of the following ways:
....................................................................................................................................................................................................................................
8950 AAA
3-17
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
This topic provides various methods that you can use to start the policy server.
Related information
The 8950 AAA policy server handles the authentication, authorization, and accounting
requests. The policy server process runs on the 8950 AAA server. It is a multi-threaded
system designed to handle multiple tasks concurrently.
Before you begin
None
Steps
...................................................................................................................................................................................................
Perform one of the following tasks where the 8950 AAA server is installed to start the
policy server:
From the SMT application - in the SMT tool bar, click the Policy Server tool icon
.
Select Start Server in the drop-down list.
Result: The policy server starts and the status changes to green in SMT.
As a Windows service - navigate to Start Menu -> Control Panel -> Administrative
Tools -> Services.
Select 8950 AAA Policy Service from the list of applications.
In the left-hand panel, click Start the service, or right-click and select Start.
Result: The server starts as a Windows service. The status changes to Started.
E...................................................................................................................................................................................................
N D O F S T E P S
....................................................................................................................................................................................................................................
8950 AAA
3-18
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
You can check the status of the policy server in one of the following ways:
....................................................................................................................................................................................................................................
8950 AAA
3-19
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
In the event of a sudden machine outage and when the machine reboots, you can set the
8950 AAA processes to start automatically whenever the operating system reloads. These
two procedures provide instructions to automatically start the 8950 AAA servers. The
procedures can be performed on Windows platform or on UNIX as required.
Related information
None
Before you begin
Ensure that you have the right privileges as a Windows user to operate on Windows
service.
Steps
Click Start Menu -> Control Panel -> Administrative Tools -> Services.
Result: The Services window opens.
...................................................................................................................................................................................................
Select 8950 AAA Policy Service or 8950 AAA Configuration Service from the list of
applications.
...................................................................................................................................................................................................
To automatically start the servers when the 8950 AAA is started, from the drop-down list
in the Startup type field, select Automatic and click OK.
E...................................................................................................................................................................................................
N D O F S T E P S
Steps
Perform the following configuration on the 8950 AAA server installed on a Solaris
machine:
...................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
3-20
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
Note: Based on the flavour of the UNIX , the script may change. Refer your UNIX
documentation for the same.
#!/sbin/sh
#
AAA_HOME=/opt/AAA
[ ! -f $AAA_HOME/bin/aaa ] && exit
# Start/stop processes required for 8950 AAA
case "$1" in
'start')
$AAA_HOME/bin/aaa start
;;
'stop')
$AAA_HOME/bin/aaa stop
;;
'restart')
$AAA_HOME/bin/aaa restart
;;
*)
echo "Usage: $0 { start | stop | restart }"
exit 1
;;
esac
Note:
1. Change the line AAA_HOME=/opt/AAA with the correct path where you have
installed the 8950 AAA.
2. If the AAA processes are not owned by the root, but by another OS user, then
change the lines that begin after start, restart, or stop the processes to:
su - aaa -c "$AAA_HOME/bin/aaa xxx"
...................................................................................................................................................................................................
Create some symbolic links, so that this file is executed when starting up or shutting
down Solaris:
# chmod a+x /etc/init.d/aaa
....................................................................................................................................................................................................................................
8950 AAA
3-21
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
# ln -s /etc/init.d/aaa /etc/rc3.d/S99aaa
# ln -s /etc/init.d/aaa /etc/rc0.d/K01aaa
# ln -s /etc/init.d/aaa /etc/rc1.d/K01aaa
# ln -s /etc/init.d/aaa /etc/rcS.d/K01aaa
...................................................................................................................................................................................................
To ensure that this script and the links works, you can optionally execute the following
commands:
# /etc/rc3.d/S99aaa start
# /etc/rc0.d/K01aaa stop
....................................................................................................................................................................................................................................
8950 AAA
3-22
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
This topic provides procedures to install configuration sets from the SMT after installing
8950 AAA:
Use From the SMT (p. 3-23) to install the configuration sets from the SMT.
Use From installation directory (p. 3-26) to install the configuration sets from the
<AAA_Install>/run/samples folder.
Related information
A configuration is a collection of policy and data files, which the 8950 AAA server uses
to determine the following:
User authentication
Authorized access and configuration
A configuration set includes all the files necessary to support a particular AAA
configuration.
Before you begin
Refer to the list of configuration set options at Step 7 in the Install 8950 AAA server on
Windows (p. 3-8) procedure.
From the SMT
...................................................................................................................................................................................................
To start the 8950 AAA SMT, perform one of the following tasks:
On a CLI:
Change to the <AAA_Install>/bin folder in the 8950 AAA install directory.
Enter aaa-smt at the command prompt and press Enter.
....................................................................................................................................................................................................................................
8950 AAA
3-23
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
...................................................................................................................................................................................................
From the SMT, select Server Configuration tab. In the left navigation pane, select Policy
Server > Policies > PolicyFlow Editor.
Note: If the PolicyAssistant configuration set is selected during installation, click
PolicyAssistant on the navigation pane and click Install New PolicyFlow.
Figure 3-1 Install new PolicyFlow
...................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
3-24
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
...................................................................................................................................................................................................
...................................................................................................................................................................................................
...................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
3-25
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
You can find the sample configuration sets in the <AAA_Install>/run/samples folder.
...................................................................................................................................................................................................
Review the readme.txt files in run/samples/ directory to determine the policy set that best
matches your business needs.
...................................................................................................................................................................................................
Copy all the files from the correct folder under the <AAA_Install>/run/samples/ directory
to the <AAA_Install>/run folder.
Note: Do not perform this step if this is an upgrade and you are unsure of what
configuration files are stored in the <AAA_Install>/run folder.
...................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
3-26
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
None
Before you begin
Ensure that the configuration server is running. Always start and stop the configuration
server from where the 8950 AAA server is installed. Do not start or stop the configuration
server from a remote SMT GUI.
Steps
...................................................................................................................................................................................................
Perform one of the following tasks where the 8950 AAA server is installed to stop the
configuration server:
From the SMT application - in the SMT navigation pane, click the Configuration
Server tool icon, .
Select Shutdown Server in the drop-down list.
Result: The configuration server stops and the status changes to red in SMT.
As a Windows service - navigate to Start Menu -> Control Panel -> Administrative
Tools -> Services.
Select 8950 AAA Configuration Service from the list of applications.
In the left-hand panel, click Stop the service, or right-click and select Stop.
Result: The configuration server stops and no status is displayed in the window.
....................................................................................................................................................................................................................................
8950 AAA
3-27
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
Note: To restart the configuration server, perform any of the tasks as follows:
From the SMT application, select Restart Server from the drop-down list to
restart the configuration server.
From the command-line window, execute the command
./aaa restart config
....................................................................................................................................................................................................................................
8950 AAA
3-28
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
None
Before you begin
Perform one of the following tasks where the 8950 AAA server is installed to stop the
policy server:
From the SMT application - in the SMT tool bar, click the Policy Server tool icon,
.
Select Shutdown Server in the drop-down list.
Result: The policy server stops and the status changes to red in SMT.
As a Windows service - navigate to Start Menu -> Control Panel -> Administrative
Tools -> Services.
Select 8950 AAA Policy Service from the list of applications.
In the left-hand panel, click Stop the service, or right-click and select Stop.
Result: The policy server stops and no status is displayed in the window.
Note: To restart the policy server, perform any of the tasks as follows:
From the SMT application, select Restart Server from the drop-down list to
restart the policy server.
From the command-line window, execute the command
./aaa restart policy
....................................................................................................................................................................................................................................
8950 AAA
3-29
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
3-30
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
This topic provides port details with an example to connect the local SMT or MT to
remote 8950 AAA server using Remote Method Invocation (RMI) over Secure Shell
(SSH) or Network Address Translation (NAT) tunnel.
Related information
The following ports are used to connect SMT or MT using RMI over SSH or NAT:
Log in to the local 8950 AAA server as root. In the command prompt, enter the following:
# ssh -L <local free port>:<destination>:<port> <osuser>@<remotehost>
Where grape is the local 8950 AAA machine, aaa is the user to log into the OS on the
remote server at 135.254.229.51 hosting the 8950 AAA server.
....................................................................................................................................................................................................................................
8950 AAA
3-31
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
...................................................................................................................................................................................................
Log in to the SMT on local host with the port forwarded to remote host as shown in the
Figure 3-2, Login screen (p. 3-32).
Figure 3-2 Login screen
....................................................................................................................................................................................................................................
8950 AAA
3-32
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
3-33
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
E...................................................................................................................................................................................................
N D O F S T E P S
This topic provides procedures to disconnect and close the SMT application on both
Windows and UNIX platforms.
Steps
....................................................................................................................................................................................................................................
8950 AAA
3-34
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
The 8950 AAA can run within a virtual machine without conflict and has been used
successfully with various VMware products and also with Solaris Zones. However, there
are specific known issues that can arise out of an inadequate VM environment.
The 8950 AAA provides real-time network service for requests using protocols such as
Diameter and Radius. In order to provide real-time service, the 8950 AAA server needs to
have guaranteed access to machine resources such as CPU, memory and disk. Any time
that the AAA application shares hardware with other independent applications in a
production mode, there must be some infrastructure in place to guarantee AAA an
appropriate share of resources. This is true whether AAA runs in a VM, or simply resides
on the same host with another application.
This is particularly noticeable when using the Radius protocol. Radius runs on top of the
UDP network layer and as such does not possess the packet-delivery guarantees that
services using TCP do. In cases where the Radius receiver is starved of resources, it is
very likely that Radius packets are lost.
Radius is designed to deal with packet loss, and in non-production modes this may be
acceptable, since lost packets are simply retried. But in cases where performance is
critical and network behaviors including packet loss are monitored, excessive packet loss
is unacceptable.
So, any use of VMs in production cases needs to take care to use only VM products that
are capable of providing resource quotas to a VM. Oracle/Solaris containers and VMware
ExSI do provide this when installed on the bare hardware. Any time a VM server is
installed on top of another OS, that OS must of course provide resource quota
management to the VM host; the VM host can only allocate those resources it itself is
guaranteed access to.
....................................................................................................................................................................................................................................
8950 AAA
3-35
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
Alcatel-Lucent provides a variety of options for you to learn 8950 AAA, including
context help, tool tips for the graphical interface, and reference manuals.
Context help in SMT
The SMT tool tips display the name of tools, buttons, or controls and provide helpful
information when entering data in fields.
Position the pointer over a tool, button, or control, and pause. A tool tip appears showing
the name or a descriptive note for the item.
View reference manuals
To download the latest version of Adobe Reader to view pdf based manuals, visit the 8950
AAA web site or (http://www.adobe.com).
....................................................................................................................................................................................................................................
8950 AAA
3-36
365-360-007 Release 8.1
Issue 2 September 2013
Technical support
....................................................................................................................................................................................................................................
Technical support
Remote technical support and pre-sales support
For Alcatel-Lucent remote technical support and warranty claims, send an e-mail to
(mailto:support@alcatel-lucent.com).
To find hotline contact information for your country, refer the website
(http://www.alcatel-lucent.com/wps/portal/support).
For pre-sales and sales information, contact your local Alcatel-Lucent sales
representative.
....................................................................................................................................................................................................................................
8950 AAA
3-37
365-360-007 Release 8.1
Issue 2 September 2013
Technical support
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
3-38
365-360-007 Release 8.1
Issue 2 September 2013
Overview
Purpose
This chapter provides procedures to remove the 8950 AAA from your UNIX or Microsoft
Windows systems.
The uninstall process does not remove the 8950 AAA configuration files from the
<AAA_Install>/run directory or any files you put in the 8950 AAA directories. To
uninstall the 8950 AAA completely, remove the installation directory after completing the
uninstall procedures.
Contents
Uninstall from UNIX platform
4-2
4-4
...................................................................................................................................................................................................................................
8950 AAA
4-1
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
This procedure provides instructions to uninstall 8950 AAA from UNIX platform.
Procedure
...................................................................................................................................................................................................
Using the command prompt, navigate to the temporary directory that contains the
aaa-8.x.x.zip file.
Note: If you have deleted the unzipped version, unzip again before you proceed with
the next step.
...................................................................................................................................................................................................
Type Y to confirm the uninstallation and press Enter key. The following output is
displayed:
Enter the directory for AAA: [/opt/AAA]:
...................................................................................................................................................................................................
Press Enter key to accept the default or change the location to the 8950 AAA installed
directory. Press Enter key. The Setup program removes the 8950 AAA from your system
and the following output is displayed:
Removing from: /opt/AAA
Setting up for reading entries
Removing installation files...DONE
Uninstall of 8950AAA complete.
....................................................................................................................................................................................................................................
8950 AAA
4-2
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
4-3
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
This procedure provides instructions to uninstall 8950 AAA using the Control Panel on
Windows platform.
To uninstall from Control Panel:
...................................................................................................................................................................................................
Click Start > Settings > Control Panel > Add or Remove Programs.
...................................................................................................................................................................................................
Using the command prompt navigate to the temporary directory that contains the
extracted aaa-8.x.x.zip file.
Ensure that the setup.exefile is present in this directory
Note: If you have deleted the unzipped version, unzip again to proceed with the next
step.
...................................................................................................................................................................................................
In the Choose 8950 AAA Location window, enter or browse to the installed directory, and
click Next.
Result: The 8950 AAA is removed from the system.
E...................................................................................................................................................................................................
N D O F S T E P S
....................................................................................................................................................................................................................................
8950 AAA
4-4
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
4-5
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
4-6
365-360-007 Release 8.1
Issue 2 September 2013
5 etermine hardware
D
needs
Overview
Purpose
This chapter deals with the major issues involved in planning an 8950 AAA server
implementation
Contents
Hardware needs
5-1
5-2
Server sizing
5-4
5-5
Load distribution
5-6
Hardware needs
Analyzing requirements
This section covers the basic sizing calculations, two sample scenarios, implementation
considerations and additional recommendations to help you estimate your system needs.
The performance of the 8950 AAA software depends on a variety of factors. Consult your
Alcatel-Lucent sales representative to determine the hardware necessary to run the 8950
AAA server in your production environment.
Consider the following factors that determines the hardware requirement:
...................................................................................................................................................................................................................................
8950 AAA
5-1
365-360-007 Release 8.1
Issue 2 September 2013
Hardware needs
....................................................................................................................................................................................................................................
Hardware currently in use, such as Oracle servers or Intel Based server (number of
CPUs, Memory).
Volume of subscribers or ports that the system handles.
Type of connection services that are available, such as dial-in, DSL, VPN, 802.11
Wireless LAN (802.1x), or 3G-1X Data.
Operating system that the customer prefers, such as Oracle Solaris, Windows/Intel,
and Linux.
Layout of the physical network, such as the location of Radius clients.
The standard measurement of a load created by a single user session that generates one
Access Request and two accounting records namely START record and STOP record.
AAA load
It is the hour of the day when the greatest number of users access the network and is also
called The Peak Hour.
Maximum Simultaneous Sessions (MSS)
MSS is the total number of concurrent sessions during the Peak Hour. This is equal to the
total number of occupied ports.
Peak Hour Load
The 8950 AAA implementation must be designed to handle the load during the Peak
Hour.
To estimate the Peak Hour Load, it is necessary to know the following:
....................................................................................................................................................................................................................................
8950 AAA
5-2
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
The number or percentage of ports not used is subtracted from the total ports on the
network during the Peak Hour (MSS = total number of ports percentage of ports not
used ). For example, in a network with 100,000 ports and an expected Peak Hour vacancy
factor of 5 percent, the estimated MSS total at Peak would be 100,000 - 5,000 = 95,000
(or 95 percent of 100,000).
In many cases, it is sufficient to use the maximum number of sessions as the MSS.
Port Use Factor
The number of times a port is used during the Peak Hour. For example, in a network
where an average Peak Hour user session lasts 30 min, each port could be used twice
during the hour
Port Use Factor = {60/average call length in minutes}. . If the total number of ports in use
is 60 and the average call length in minutes is 30, the Port Use Factor is 2 (60/30 = 2). For
an average session length of 20 min, the Port Use factor is 3 (60/20 = 3).
Peak Hour User Sessions
....................................................................................................................................................................................................................................
8950 AAA
5-3
365-360-007 Release 8.1
Issue 2 September 2013
Server sizing
....................................................................................................................................................................................................................................
Server sizing
Maximum AAA capacity
Estimating server size requires learning how the access servers select and balance the
load between AAA servers. Some access servers can switch between a maximum of three
AAA servers while others can only switch between two.
For this example, assuming the following factors:
The two AAA servers use the IP Addresses 10.0.1.11 and 10.0.1.12
Configure the access servers such that the first choice server, RADIUS #1, is equally
divided between the access servers
Half of the access servers list the RADIUS servers in the following order:
RADIUS #1 = 10.0.1.11
RADIUS #2 = 10.0.1.12
The next half reverses the preference and lists the RADIUS servers in the following
order:
RADIUS #1 = 10.0.1.12
RADIUS #2 = 10.0.1.11
With this configuration, you can expect the Peak Load 25AAA/sec total load to be
equally divided between the two RADIUS servers - each server processes 12.5 AAA/sec
in the Peak Busy Hour.
....................................................................................................................................................................................................................................
8950 AAA
5-4
365-360-007 Release 8.1
Issue 2 September 2013
Server sizing
....................................................................................................................................................................................................................................
If one of the two RADIUS servers becomes unavailable (for example, the network
experiences an outage or power failure) the entire load of 25 AAA/sec falls on the
remaining RADIUS server which is safely under its maximum rating of 30 AAA/sec.
As this example demonstrates, in cases where access servers can select between two
RADIUS servers, it is important to distribute the load so that in normal operation no
RADIUS server handles more than 50% of its rated capacity. This ensures a reserve
capacity in the event of server failure.
The second example of Server Sizing assumes that the network has grown from a Peak
Hour load of 25 AAA/sec to a load of 36 AAA/sec.
In normal operation, one 8950 AAA server can handle 18 AAAs/second (1/2 the load). If
one server fails, the remaining server has to handle all 36 AAA/sec, which is not possible.
In such cases, a failure requires a third 8950 AAA server to handle the load.
If there are three 8950 AAA servers each with 30 AAA/second capacities and with the
following IP addresses 10.0.1.11, 10.0.1.12, and 10.0.1.13 assigned to the servers.
Configure the servers so that the RADIUS #1 is equally divided between the three
servers.
The first three of the access servers list the RADIUS servers in the following order:
RADIUS #1 = 10.0.1.11
RADIUS #2 = 10.0.1.12
RADIUS #3 = 10.0.1.13
The second three stagger the preference and list the RADIUS servers in the following
order:
RADIUS #1 = 10.0.1.12
RADIUS #2 = 10.0.1.13
RADIUS #3 = 10.0.1.11
The last three stagger the preference and list the RADIUS servers in the following order:
RADIUS #1 = 10.0.1.13
RADIUS #2 = 10.0.1.11
RADIUS #3 = 10.0.1.12
....................................................................................................................................................................................................................................
8950 AAA
5-5
365-360-007 Release 8.1
Issue 2 September 2013
....................................................................................................................................................................................................................................
As in the previous example with two 8950 AAA servers, the normal load is evenly
distributed across the three 8950 AAA servers. With a Peak Hour AAAs/sec rate of 36,
each of the 8950 AAA servers can handle 12 AAA/sec during the peak hour.
If one of the 8950 AAA servers fails or otherwise becomes unavailable, the load is evenly
distributed across the other two servers. This leaves each with an 18 AAA/sec load, which
is safely within its load capacity.
This example shows that when the access server can list three AAA servers, each server
can handle up to two- thirds of its maximum (30 AAA/sec in this example) capacity.
However, a more conservative load factor of 50% should be used and an allowance must
be made for simultaneous failure of two systems in situations where:
Load distribution
Load distribution
In cases where the total Peak Hour AAA load exceeds the rated capacity of a RADIUS
server, develop a means to ensure that the load is evenly distributed.
For example, in the case of the three 8950 AAA servers and the three access servers that
can only list two 8950 AAA servers, a scheme using three 8950 AAA servers similar to
the following could be used. One bank of the access servers would list the 8950 AAA
servers in this order:
The first group lists the RADIUS servers in this order:
RADIUS #1 = 10.0.1.11
RADIUS #2 = 10.0.1.12
The next group lists the RADIUS servers in this order:
RADIUS #1 = 10.0.1.12
RADIUS #2 = 10.0.1.13
The last group lists the RADIUS servers in this order:
RADIUS #1 = 10.0.1.13
RADIUS #2 = 10.0.1.11
....................................................................................................................................................................................................................................
8950 AAA
5-6
365-360-007 Release 8.1
Issue 2 September 2013
Load distribution
....................................................................................................................................................................................................................................
The access servers are configured so that first and second 8950 AAA server choices are
equally divided between the three server banks.
....................................................................................................................................................................................................................................
8950 AAA
5-7
365-360-007 Release 8.1
Issue 2 September 2013
Load distribution
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
5-8
365-360-007 Release 8.1
Issue 2 September 2013
Index
version, 2-2
.............................................................
H hardware needs, 5-1
Ports, 3-31
connect SMT or MT using
RMI over SSH or NAT, 3-31
product overview, 1-1
.............................................................
V valid license, 2-3
R RIM, 3-31
.............................................................
S scaling network, 5-5
.............................................................
on UNIX, 3-14
J java environments, 1-4
.............................................................
L latest java version, 1-4
on Windows, 3-14
remotely, 3-14
stop configuration server, 3-27
2-3
.............................................................
T technical support, 3-37
Index
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
8950 AAA
IN-2
365-360-007 Release 8.1
Issue 2 September 2013