Routing Services and Enhanced Subscriber Management
This topic describes routing services for enhanced subscriber management, including routing service requirements, pseudo logical interface creation, RADIUS-based service control, and deployment options for dynamic subscribers.
When client connections require additional routing protocols on dynamic interfaces, with the exception of IGMP and MLD, you must include routing services in the dynamic profile interface configuration. If you do not do so, then the pseudo logical interface is not created and routing services cannot be associated with the dynamic interface. The additional routing protocols cannot run on the dynamic subscriber interface.
You do not have to include routing services in the dynamic profile interface configuration when clients use only the standard access-internal routes, access routes, and framed routes. In other words, the routing service configuration is not required for simple client reachability purposes.
Routing service configuration is not required for IGMP or MLD, because these protocols are natively supported on enhanced subscriber management interfaces.
Distributed IGMP is not supported on subscriber management interfaces where routing-services are enabled.
When a dynamic profile containing the routing-services statement is instantiated, the router creates an
enhanced subscriber management logical interface, also referred to as a pseudo logical
interface, in the form demux0.nnnnnnnnnn (for example,
demux0.3221225472). Any associated subscriber routes or routes learned from a routing
protocol running on the enhanced subscriber management interface use this pseudo interface
as the next-hop interface.
Besides enabling or disabling routing services for all subscribers on the dynamic
interface, the routing-service statement enables you to use RADIUS to selectively
enable or disable routing services for a specific subscriber during authentication if
RADIUS returns the Routing-Services VSA (26-212) in the Access-Accept message.
This RADIUS capability requires you to specify the $junos-routing-services predefined variable in the dynamic profile. A VSA value of one enables routing services for the subscriber; a value of zero disables routing services for the subscriber. Any value other than zero or one is rejected. If you configure the variable and RADIUS does not return the VSA, then routing services are disabled for the subscriber.
You can specify the variable in the dynamic profiles for PPPoE subscribers, the underlying VLAN, or both. When you include the variable in the VLAN dynamic profile, then you must also configure the VLAN to be authenticated; otherwise, routing services remain disabled for the underlying interface and therefore also disabled for the PPPoE subscriber.
You can optionally create dedicated dynamic VLAN profiles to enable routing services for
subscribers that require them. The following code sample shows two VLAN profiles.
vlan-profile1 enables routing services, whereas
vlan-profile2 does not.
dynamic-profiles vlan-profile1 {
interfaces $junos-interface-ifd-name {
unit $junos-interface-unit {
routing-service {
enable;
}
}
}
}
dynamic-profiles vlan-profile2 {
interfaces $junos-interface-ifd-name {
unit $junos-interface-unit {
}
}
}The VLAN profile is chosen based on the VLAN range associated with the profile by the
ranges statement at the [edit interfaces] hierarchy
level. In the following code sample, vlan-profile1 uses VLAN IDs in the range 100 through
500; vlan-profile2 uses IDs in the range from 501 through 1000:
interfaces ge-0/0/1 {
auto-configure;
vlan-ranges {
dynamic-profile vlan-profile1 {
ranges 100-500;
}
dynamic-profile vlan-profile2 {
ranges 501-1000;
}
}
}
}When you need to enable routing services for PPPoE subscribers, do not configure
family inet or family inet6 configuration in the
underlying dynamic VLAN profile. To support both IPoE and PPPoE subscribers on the same
access interface, use separate dynamic VLAN profiles. Configure a PPPoE VLAN profile
with routing services enabled and a separate IPoE VLAN profile without routing services
enabled. For an example, see Example: Configuring IPoE and PPPoE Subscribers on the Same Access Interface with Routing Services Support.