Cisco Cisco Packet Data Gateway (PDG)
dmu-refresh-key
Typically, when a Dynamic Mobile IP Update (DMU) resets, the next MIP re-registration causes MN-HA
authorization failure and the HA rejects the MIP RRQ. This parameter enables the HA to retrieve the MN-HA
key again from the AAA during the call and to use the freshly retrieved key value to recheck authentication.
authorization failure and the HA rejects the MIP RRQ. This parameter enables the HA to retrieve the MN-HA
key again from the AAA during the call and to use the freshly retrieved key value to recheck authentication.
Default is disabled.
imsi-auth
Enable uses the International Subscriber Mobile identity (IMSI) to determine if MN-AAA or MN-FAC
extensions are not present in the RRQ.
extensions are not present in the RRQ.
Default is disabled.
mn-aaa
{ allow-noauth | always | dereg-noauth | noauth | renew-reg-noauth | renew-and-dereg-noauth }
Specifies how mobile node-to-AAA authentication extension in registration requests from the mobile node
should be handled by the HA service.
should be handled by the HA service.
Default is always.
allow-noauth: Specifies that the HA service does not require authentication for every mobile node registration
request. However, if the mn-aaa extension is received, the HA service will authenticate it.
request. However, if the mn-aaa extension is received, the HA service will authenticate it.
always: Specifies that the HA service will perform authentication each time a mobile node registers.
dereg-noauth: Disables authentication request upon de-registration.
noauth: Specifies that the HA service will not look for mn-aaa extension and will not authenticate it.
renew-reg-noauth: Specifies that the HA service will not perform authentication for mobile node
re-registrations. Initial registration and de-registration will be handled normally.
re-registrations. Initial registration and de-registration will be handled normally.
renew-and-dereg-noauth: Disables authentication request upon re-registration and de-registration.
mn-ha
{ allow-noauth | always }
Specifies whether the HA service looks for an MN-HA authentication extension in the RRQ.
Default is always.
allow-noauth: Allows a request that does not contain the auth extension.
always: A request should always contain the auth extension to be accepted.
pmip-auth
Specifies whether the HA service looks for an MN-HA authentication extension in the RRQ.
Default is always.
allow-noauth: Allows a request that does not contain the auth extension.
always: A request should always contain the auth extension to be accepted.
stale-key-disconnect
If MN-HA auth fails for MIP renew and dereg, disconnects the call immediately.
Disabled by default.
Command Line Interface Reference, Modes G - H, StarOS Release 19
1240
HA Service Configuration Mode Commands
authentication