Redirecting Subscriber Traffic Using ISG Layer 4 Redirect
Configuration Examples for ISG Layer 4 Redirect
9
subscriber rule-map blind-rdt
condition always event session-start
action 1 service-policy type service name blind-rdt
Session inbound features:
Feature: Layer 4 Redirect
Rule Cfg Definition
#1 SVC Redirect to group sesm-grp !! applied redirect
Configuration sources associated with this session:
Service: blind-rdt, Active Time = 40 minutes, 32 seconds
Interface: ATM2/0.53, Active Time = 40 minutes, 32 seconds
The following is sample output for the show subscriber session command for a session in which the
Layer 4 redirection is applied on the interface:
Router# show subscriber session uid 133
Subscriber session handle: D7000110, state: connected, service: Local Term
Unique Session ID: 133
Identifier:
SIP subscriber access type(s): IP-Interface
Root SIP Handle: 1E, PID: 73
Current SIP options: Req Fwding/Req Fwded
Session Up-time: 42 minutes, 54 seconds, Last Changed: 42 minutes, 54 seconds
AAA unique ID: 133
Switch handle: 17000084
Interface: FastEthernet0/0.505
Policy information:
Authentication status: unauthen
Session inbound features:
Feature: Layer 4 Redirect
Rule Cfg Definition
#1 INT Redirect to group sesm-grp
Configuration sources associated with this session:
Interface: FastEthernet0/0.505, Active Time = 42 minutes, 54 seconds
Configuration Examples for ISG Layer 4 Redirect
This section contains the following examples:
• Redirecting Unauthenticated Subscriber Traffic: Example, page 9
• Redirecting Unauthorized Subscriber Traffic: Example, page 10
• Initial Redirection: Example, page 11
• Periodic Redirection: Examples, page 11
• Redirecting DNS Traffic: Example, page 12
Redirecting Unauthenticated Subscriber Traffic: Example
In the following example, Layer 4 redirection is configured in the service policy map “BLIND-RDT”.
This policy is applied to all sessions at session start and redirects subscriber TCP traffic to the server
group called “PORTAL”. At account logon the subscriber is authenticated and the redirection is not
applied.