HOTSPOT GATEWAY
Appendix B: Addendum 321
See next figure for a realm routing policy that handles suffix-based usernames using a
tunnel profile. The differences in this example are the realm name is “tcisp.com”,
“Suffix match only” is enabled (the delimiter in this case is “@”), and a tunnel
profile, “LNS-One”, is selected instead of a RADIUS service profile.
This means that this realm routing policy will match usernames that are of the format
“username@tcisp.com”. Since this policy references a tunnel profile, no RADIUS
access requests will be sent to any RADIUS server. In this case, the HSG will use the
L2TP tunnel parameters specified in the tunnel profile to establish a tunnel and pass
the username/password input to the tunnel server.