SRC-PE 2.0.x Integration Guide

About This Guide
Objectives
Audience
Documentation Conventions
Related Juniper Networks Documentation
Obtaining Documentation
Documentation Feedback
Requesting Support
Integrating Third-Party Network Devices into the SRC Network with the SRC CLI
Overview of Integrating Network Devices into the SRC Network
SAE Communities
Storing Session Data
Using Script Services to Provision Third-Party Devices
Logging In Subscribers and Creating Sessions
Assigned IP Subscribers
Login Interactions with Assigned IP Subscribers
Event Notification from an IP Address Manager
Login with Event Notification
Configuration Tasks for Integrating Third-Party Network Devices
Setting Up Script Services
Adding Objects for Network Devices
Adding Virtual Router Objects
Setting Up SAE Communities
Configuring the SAE Community Manager
Specifying the Community Manager in the SAE Device Driver
Configuring SAE Properties for the Event Notification API
Developing Initialization Scripts for Network Devices
Interface Object Fields
Required Methods
Example: Initialization Script
Copying Initialization Scripts to the C-series Controller
Specifying Initialization Scripts on the SAE
Using SNMP to Retrieve Information from Network Devices
Configuring Global SNMP Communities in the SRC Software
Using the NIC Resolver
Overview of LDAP Integration
LDAP Overview
Directory Availability
Directory Updates
Supported Directories
Directory Security
Directory Access
LDAPS Directory Connections
Provisioning the Directory
Naming Directory Entries
SDX Directory Schema and Object Model
Naming Convention for Entries
Directory Schema for SRC Software
Object Classes
Objects Representing Folders
Subscriber Objects
Service Objects
Subscription Profile Objects
Policy Objects
Network Device Objects
Configuration and System Management
Attributes
Structure Rules
Content Rules
Where to Find More Information About the Object Model and Directory Schema
Integrating eTrust Directory
Overview of Integration with eTrust Directory
About the eTrust Directory Add-On Package
Integrating the eTrust Directory with the SRC Software
Installing eTrust Directory to Integrate with the SRC Software
Configuring the SDX eTrust Directory Server Agent with the SRC Software
Starting SDX eTrust Directory
Stopping SDX eTrust Directory
Displaying the Status of SDX eTrust Directory
Backing Up and Restoring eTrust Directory
Integrating Oracle Internet Directory
Overview of Oracle Internet Directory Integration
About the Oracle Internet Directory Add-On Package
Integrating the Oracle Internet Directory with the SRC Software
Installing Oracle Internet Directory to Integrate with the SRC Software
Before You Install Oracle Internet Directory
Specifying Configuration Values During Installation
Verifying Directory Settings
Running the Load Script for the Oracle Internet Directory Integration
Starting and Stopping Oracle Internet Directory
Setting Up Local Configuration for SRC Components
Backing Up and Restoring the Oracle Internet Directory
Integrating Sun ONE Directory Server
Overview of Sun ONE Directory Server Integration
About the Sun ONE Add-On Package
Silent Installation for Sun ONE Directory Server
Load Script to Integrate Sun ONE Directory Server
Integrating the Sun ONE Directory with the SRC Software
Installing the Sun ONE Directory Add-On Package
Configuring an Instance of Sun ONE Directory Server
Starting Sun ONE Directory Server
Stopping Sun ONE Directory Server
Restarting Sun ONE Directory Server
Backing Up the Sun ONE Database
Restoring the Sun ONE Database
Integrating the DirX Directory Server
Overview of DirX Directory Server Integration
About the DirX Add-On Package
Integrating the DirX Directory with the SRC Software
Preparing to Install the DirX Directory Server
Installing the DirX Directory Server
Installing the UMCdirxa Add-On Package
Configuring the DirX Directory Server
Provisioning the Directory by Using DirXmetahub
Uninstalling the DirX Directory Server
Starting the DirX Directory Server
Starting the DirX Directory Server in a dirx user Environment
Starting the DirX Directory Server in a Superuser Environment
Stopping the DirX Directory Server
Stopping the DirX Directory Server in a dirx user Environment
Stopping the DirX Directory Server in a Superuser Environment
Backing Up the DirX Database
Restoring the DirX Directory Database
Configuring LDAPS for SRC Components
Overview of LDAPS Support
LDAPS Authentication and Connection
Configuring LDAPS Connections
Configuring the Directory Server to Support LDAPS Connections
Establishing Trust for Directory Clients
Configuring the SAE to Find the Certificate Store
Enabling LDAPS Communication for SAE Components
Disabling LDAPS Communication for SAE Components
Access Control Scheme
Directory Configuration
Directories
User Class
Permissions
Access Controls
Access Controls for the Entire Tree
Access Controls Against Objects from Type cachedAuthentication Profile and UmcConfiguration
Access Controls Against sspServiceProfile
Access Controls Against umcRadius Person and umcUser
Access Controls Against RADIUS Profiles
Access Controls Against the Policy Subtree
Access Controls Against the Parameter Subtree
Access Controls for System Management
Access Controls Against the Lock Subtree
Access Controls Against the Network Subtree
Access Controls Against Services and Mutex Group Objects
Access Controls Against the User Subtree
Access Controls Against Service, Policy, and Global Parameter Objects
Activation Access Rights
Subscription Access Rights
Substitution Access Rights
Common Access Rights for All Managers
Directory-Specific Access Control Implementation
DirX Directory Server
Sun ONE Directory Server
Integrating Steel-Belted Radius/SPE Server
System Requirements for the Steel-Belted Radius Server
Installing the Steel-Belted Radius/SPE Software
Integrating RAD-Series RADIUS Server
System Requirements for the RAD-Series RADIUS Server
Installing the RAD-Series RADIUS Server
LDAP Features for the RAD-Series RADIUS Server
Configuring UDP Ports for the RAD-Series RADIUS Server
Starting and Stopping RAD-Series Server Manager
Changing the UDP Ports
Extending Dictionary Files with JUNOSe Parameters for the RAD-Series RADIUS Server
Configuring LDAP Authentication for the RAD-Series RADIUS Server
Configuring the RAD-Series Server Manager
Configuring Realm Administration
Configuring LDAP Settings
Configuring RADIUS Profiles with the LDAP Directory
Example: RAD-Series RADIUS Server Accounting Log File Format
Configuring the RAD-Series RADIUS Server and RADIUS Clients
Configuring the RAD-Series RADIUS Server
Configuring RADIUS Clients
Testing the RAD-Series RADIUS Server
Index