Wifi - Mobile BNG Offload Deployments SP-T07-I
Total Page:16
File Type:pdf, Size:1020Kb
Toronto, Canada May 30th, 2013 WiFi - Mobile BNG Offload Deployments SP-T07-I Derick Linegar, [email protected] © 20112012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 1 Agenda vSP Wi-Fi - Key drivers vIntelligent Broadband vSP Wi-Fi Deployments vSP WiFi Evolution with MPC Integration vCall Flow vReferences © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 2 SP-WiFi Key Drivers © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 3 SP-WiFi Solutions © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 4 Why Should I Care About WiFi? The “New Normal” © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 5 Wi-Fi Subscribers, Wireline/Wi-Fi & Mobile Different Motivations Internet Mobile Operator Motivations • Data traffic growing exponentially Mobile Operators • Licensed spectrum limitations Mobile Mobile Operator1 Operator2 • Access – Trusted/Untrusted 3G/4G delivered Wireline / Wi-Fi Operator Gateway Peering via Mobile Motivation Backhaul Wireline Operator with • Increase Service Revenues Wi-Fi Access • Cater to multiple Mobile Operators • Provide a scalable peering model Wireline Wireline Operator 1 Operator 2 • Leverage existing infrastructure Subscriber Motivation • Always connected experience Wi-Fi Access • Seamless Authentication • Mobility/Roaming without Mobile Users disrupting apps © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 6 Terminology Primer Service Provider Wi-Fi Wireline Broadband Session Type IP Based Sessions PPP Based Sessions User type Mobile Users Fixed Residential Session Control Intelligent Services Gateway (ISG) – software component Place in Network Wireless Access Gateway Broadband Network Gateway (PIN) Designation (WAG) (BNG) © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 7 SP Wi-Fi Solutions – At a Glance Availability Deployment Type Software Components ASR1000 ASR9000 Traditional Public Open SSID with ISG Redirect for Wireless LAN Available Now Available Now Web based Authentication (PWLAN) Seamless EAP based secure authentication Now – relies on Cisco Available Now Authentication using ISG Access Registrar (CAR) Mobile Network ISG and Proxy Mobile (PMIP) iWAG - Available now Now – ASR5K based Integration configured on a single box © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 8 Intelligent Broadband © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 9 Evolution in Service Provider Architectures Diverged Reduced Operational Expenses: “Per Service” Networks ü Consolidation of multiple networks Converged “All in One” Increased Service Revenues: Networks ü Customized services ü Rapid deployment of new Converged services “User Centric” ü Subscriber Self Subscription Networks and Self Care © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 10 The New User Experience Enabling the Next Wave of Broadband © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 11 Subscriber Awareness - Elements of Customization Session Multi-Dimensional Identifier for Subscribers over initiation L2/L3 access networks Initiators & Identity From multiple sources and events Over session lifecycle L2 – Pt-to-Pt vis-à-vis L3 – Pt-to-Cloud Session authentication Different Services and Rules applied based on Intelligent Session Who the subscriber is Service Services Location of the subscriber Requirement of the subscriber Gateway Dynamic Policy Push and Pull Dynamic Services and Rules updated based on Service How subscriber behaves Management What the subscriber requires NOW © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 12 Building the Identity and Assigning Services Example Subscriber Subscriber Subscriber Subscriber DHCP Exchange Starts DHCP Exchange Completes(*) Subscriber Authentication(*) Dynamic Service Update T0 T1 T2 TN ISG Akshay Akshay Subscriber Session Subscriber Session Subscriber Session Subscriber Session Identities MAC Addr: 00:DE:34:F1:C0:28 MAC Addr: 00:DE:34:F1:C0:28 MAC Addr: 00:DE:34:F1:C0:28 MAC Addr: 00:DE:34:F1:C0:28 IP Addr: ? IP Addr: 10.1.2.211 IP Addr: 10.1.2.211 IP Addr: 10.1.2.211 Username: ? Username: ? Username: dlinegar Username: dlinegar Service: DEFAULT_SRV Service: DEFAULT_SRV Service: PPU_SRV Service: PREMIUM_SRV Services PREMIUM_SRV DEFAULT_SRV PPU_SRV Service: Only permits management Pay Per Use Service: - Permits all traffic traffic through the session - Permits all traffic - 512K/1Mbps US./DS - 1M/8Mbps US/DS - Accounting enabled on session (*) Order of operations not representative of a real call flow © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 13 What Is ISG? Subscriber Policy Layer Policy Web DHCP AAA … Server Server Portal Server Open Cisco Intelligent Services Gateway Northbound (ISG) is a licensed feature set on Interfaces Cisco IOS that provides Session Policy Management and Policy Subscriber Identity Management and Management Management services to a variety of ISG Enforcement access networks So focal, that the entire device is often referred as an: Intelligent Services Gateway router or simply “The ISG ISG” © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 14 Access Technology Abstraction DSL DSLAM ATM/Ethernet Switch CMTS Cable Walled Garden Open Garden BRAS/BNG Access Ethernet Distribution Subscriber-centric services regardless of Access Technology, Access Protocol 802.11 or Access Technology Access Protocol 802.16 Legacy DSL/ATM IP Metro Ethernet, PPP Wireless LAN, Cable © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 15 SP-WiFi Deployments © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 16 SP Wi-Fi Deployment Models At a glance Access Type Session Initiator Authentication Type MPC Integration 1 Layer 2 Unclassified MAC MAC Address None 2 Layer 2 DHCP MAC Address None 3 Layer 2 Unclassified MAC/ Radius MAC Address / EAP HLR based Proxy 4 Layer 3 Unclassified IP / Radius IP Address / EAP HLR based Proxy 5 Layer 2 DHCP / Unclassified MAC / MAC Address / EAP PMIPv6 / GTPv1 based and HLR based Radius Proxy 6 Layer 2 DHCP / Unclassified / Radius MAC Address / EAP PMIPv6 based, Wholesale services and HLR based © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 17 SP Wi-Fi Access + Aggregation + Core Network MNO Home Network Policy HLR OCS PCRF CGF AP Portal DHCP AAA WLC WLC AP Roaming Internet Services Partner Core Access Network Policy PMIP Hotspot PGW/LMA S2a AP GTP Aggregation Roaming Internet Services Switch Gn’ Partner VLAN Core AP WAG Optional GGSN Public/Large NAT Mobile Network Venue Operators AP/CPE Home Internet Services Network Core Access & Wholesale Provider Community WiFi Unified Architecture © 2012 Cisco and/or its affiliates. All rights reserved.Radio Intelligence Cisco Connect 18 SP WiFi Deployment #1 Connectivity • L2 connected network • FSOL: Unclassified MAC address in data packet IP Addressing • IPv4 Clients • External DHCP Authorization • Transparent Auto Logon • Web Based Logon Services • Wi-Fi Services for Residential, Enterprise users. ( per device Billing) • For users behind CPE (billing per CPE) • Pre-paid service • Dynamic Service Selection © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 19 Architecture Overview AAA/ Portal HLR OCS PCRF DHCP Server MPLS /IP Internet Core ISG Int or Sub-int GE (.1Q) Client Services Smartphone Layer 2 network user Web Authentication GE (dot1Q) Open Access users PC/Laptop EAP users user VPLS/EoIP Traffic flow AAA interactions © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 20 SP WiFi Deployment #2 Connectivity • L2 connected network • FSOL: DHCP Initiator IP Addressing • IPv4 Clients • Internal DHCP ( DHCP Server or Relay) Authorization • Transparent Auto Logon • Web Based Logon Services • Wi-Fi Services for Residential, Enterprise users. ( per device Billing) • For users behind CPE (billing per CPE) • Pre-paid service • Dynamic Service Selection © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 21 Architecture Overview AAA/ Portal HLR OCS PCRF Access Network SSID BLUE :: VLAN 2 SSID RED :: VLAN 3 DHCP Server SSID BLUE L2 L3 EoIP Tunnel Encap L2 Vlan#2 L2 L3 EoIP Tunnel Encap L2 Vlan#3 VLAN# 2 Internet SSID RED EoIP VLAN# 3 EoIP Tunnel Transport NW Tunnel Server Layer 2 network GE (dot1Q) VPLS/EoIP Client Smartphone user VLAN #2 Traffic flow VLAN #3 AAA interactions © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 22 SP WiFi Deployment #3 Connectivity • L2 connected network • FSOL: [BLUE] DHCP Initiator or [RED] Unclassified MAC IP Addressing • [BLUE] Dynamic(VRF) domain customer - Internal DHCP • [RED] Mobile Data Offload - External DHCP Authorization • SSID [BLUE] Transparent Auto Logon (EAP Auth) • SSID [RED] Web Based Logon (Open Auth) Services • SSID [BLUE] Mobile Packet Core Integration for Billing • [BLUE] Dynamic VPN services for L3VPN clients • SSID [RED] Mobile Offload Wi-Fi Services -Web Authentication © 2012 Cisco and/or its affiliates. All rights reserved. Cisco Connect 23 Architecture Overview AAA/ Portal HLR OCS PCRF Packet core integration SSID BLUE DHCP Server ISG Accounting packet also Mobile trigger session in ASR 5000 Core Trusted IPSG Internet Wi-Fi SSID RED ISG Client VLAN #2 Smartfone user NAT-FW VLAN #3 Access Network SSID RED :: Simple IP Users Traffic flow SSID BLUE :: Mobile Offload AAA interactions Accounting Trigger © 2012 Cisco and/or its affiliates.