Both MPC10E line card versions support subscriber management. MPC10E-10C has 2 Trio-5 PFEs, supporting 32K Dual Stack subscribers per PFE, for a total of 64K Dual Stack subscribers. MPC10E-15C has 3 Trio-5 PFEs supporting 32K Dual Stack subscribers per PFE, for a total of 96K subscribers.
MPC10E supports both PPPoE and IPoE access methods along PWHT for PPPoE or IPoE, scalability is the same for any of these access methods.
Enabling HQoS, ingress/egress FW Filtering, or ingress/egress policing for subscriber access connections in any of the MPC10E line cards, doesn't impact subscriber scalability.
This tech post will explore the following BNG capabilities on MPC10E:
Test Topology
Hardware Used
RADIUS Subscribers' Profiles
Configuration
DS Subscribers
DS CGNAT Subscribers
Verification
DS Subscribers
DS CGNAT Subscribers
We will show both DS subscribers and DS CGNAT subscribers in the same BNG, in other words, for CGNAT subscribers, BNG will perform DS subscriber termination plus CGNAT functionalities.
PPPoE is the broadband access method used in this tech post, NDRA for IPv6 WAN addressing, and DHCPv6 Prefix Delegation for IPv6 LAN addressing. IPoE could be used as an alternative access method and DHCPv6 IA_NA also as an alternative for WAN Addressing.
BNG+CGNAT with MPC10+SPC3 is supported starting in 23.1R1 release.
The test is based on MPC10E-10C using JUNOS 23.2R1 release and having 10GigE access connections, although we connect 16K DS subscribers in a single PFE, this is not a scalability report, it's target to demonstrate typical Dual Stack BNG functionalities on MPC10E.
Our test topology consists of a Tester (Spirent Test Center) to emulate PPPoE Dual Stack subscribers, connected to xe-9/0/3:0 port on MPC10E, uplink interfaces, and RADIUS to provide AAA service for subscribers. The below figures show both a public IPv4 DS subscriber and DS CGNAT subscriber.
MX960 is acting as BNG, it includes 1 x MPC10E-10C for access and uplink connections, it also includes an SPC3 to perform CGNAT functions for BNG subscribers.
The Inte-Subsc is the username used for DS subscribers, RADIUS returns this profile to subscribers with the following RADIUS attributes:
An IPv4 Pool configured on MX, this pool emulates public IPv4 addressing.
The dynamic profile "GIGE_DS_POFILE" has parameters and variables for IPv4, IPv6, NDRA, and HQoS to be applied to the subscriber.
A service activate "SERVICE_ACTIVATE_DS" dynamic profile to be applied to subscribers returns two values that correspond to two variables configured in this dynamic profile. In this way, the MX configuration is reduced, and the values are handled via AAA, which reduces time to market and human errors. This dynamic profile contains IPv4 and IPv6 ingress FWF with MF classifiers and policers.
CoS parameter for egress shaping is applied to subscribers, same here, this reduces MX configuration, and downstream bandwidth per subscriber is handled from AAA reducing time to market and human errors.
A scheduler transmit-rate value, reducing MX configuration, time to market, and human errors. This value is handled by AAA.
IPv6 NDRA Pool configured on MX, this one is used for IPv6 WAN addressing.
IPv6 PD Pool configured on MX and used for IPV6 LAN addressing.
The MX configuration for the above parameters is shown in the configuration section.
Below is displayed the RADIUS Profile for DS CGNAT subscribers.
The CGNAT-Subsc is the username used for DS CGNAT subscribers, RADIUS returns this profile to subscribers with the following RADIUS attributes:
An IPv4 Pool configured on MX, this pool emulates private IPv4 addressing.
The dynamic profile "GGNAT_DS_POFILE" that has parameters and variables for IPv4, IPV6, NDRA, HQoS, and a Routing-Instance to be applied to the subscriber.
A service activate "SERVICE_ACTIVATE_DS" dynamic profile to be applied to subscribers returns two values that correspond to two variables configured in this dynamic profile. In this way, the MX configuration is reduced, and the values are handled via AAA, which reduces time to market and human errors. This dynamic profile contains IPv4 and IPV6 ingress FWF with MF classifiers and policers.
CoS parameter for egress shaping is applied to subscribers, same here, this reduces MX configuration and downstream bandwidth per subscriber is handled from AAA reducing time to market and human errors.
A scheduler transmit-rate value, reducing MX configuration, time to market, and human errors. This value is handled by AAA.
The Routing-Instance name which the subscriber interface will be assigned.
IPv6 NDRA Pool configured on MX, this one is used for IPv6 WAN addressing.
IPv6 PD Pool configured on MX and used for IPV6 LAN addressing.
Again, MX configuration for the above parameters is shown in the configuration section.
In the following sections are shown the most relevant BNG configuration such as an access interface, IPv4 and IPv6 pools, and dynamics profiles. The DS CGNAT specific configuration is displayed in the DS CGNAT subscribers configuration.
Routing, MPLS, RADIUS, uplink interfaces, ALG, QoS along more generic configurations are omitted for brevity.
MPC10E access interfaces xe-9/0/3:0 for PPPoE subscribers in displayed below, it will negotiate PPPoE parameters received over VLAN 1585 statically configured (N:1 access) based on "GIGE_DS_PROFILE" and RADIUS returned attributes.
For IPv6 LAN addressing, we use local DHCPv6 server in our testing scenario, the configuration is shown below, this includes de IPv6 PD pool along with accepting DHCPv6 over PPP interfaces. DHCPv6 Relay configuration is also supported.
IPv6 LAN addressing is negotiated via DHCPv6 PD. IPv6 WAN addressing is negotiated either via NDRA or DHCPv6 IA_NA.
PPPoE "GIGE_DS_PROFILE" configuration is displayed below, this profile allows PPP parameters, IPv4, IPv6 NDRA, and IPv6 LAN negotiation. It also includes egress HQoS parameters assignment to a subscriber such as a shaping rate (subscriber downstream bandwidth) and schedulers for a different kinds of traffic treatment as shown in this dynamic profile configuration.
Subscriber downstream bandwidth is returned by RADIUS in the Access-Accept message according to the subscriber bandwidth profile acquired. The transmit rate value for the "DOWNSTREAM_VoIP" scheduler is also returned by RADIUS, based on the subscriber profile acquired.
Using JUNOS variables in dynamic profiles allows:
Reduce MX configuration.
A central place to modify values.
Expedite go to market for any downstream or upstream bandwidth profile modification.
Reduce human errors.
It also allows to assign a default value to a variable If RADIUS is not configured correctly.
Service Activate "SERVICE_ACTIVATE_DS_IN" dynamic profile is used to assign upstream parameters to a subscriber such as upstream policer for upstream subscriber bandwidth, and MF classifier to assign a specific forwarding-class for traffic treatment accordingly.
Subscriber upstream bandwidth is returned by RADIUS in the Access-Accept message according to the subscriber bandwidth profile acquired. RADIUS service activate VSA allows a dynamic profile to be assigned to a subscriber for different use cases, in our example RADIUS instructs MX to activate the "SERVICE_ACTIVATE_DS_IN" dynamic profile, this one is used for upstream purposes.
Service Activate Profiles can be attached during session setup via a service activation in the access-accept and it can be attached via CoA. It is possible to dynamically add/remove one or more service profiles via CoA.
The variable used in this dynamic profile allows:
Upstream subscriber bandwidth.
VoIP upstream bandwidth.
Upstream Policer Burst is calculated dynamically based on upstream subscriber bandwidth, reducing MX configuration and human errors.
A logical interface hierarchical policer to limit Premium (VoIP) traffic and aggregate traffic.
dynamic-profiles {
SERVICE_ACTIVATE_DS_IN {
variables {
inBW;
voiceBW;
burstPolicer equals "$inBW * 0.125";
policer uid;
UPSTREAM_IN uid;
UPSTREAM_IN_v6 uid;
}
interfaces {
pp0 {
unit "$junos-interface-unit" {
family inet {
filter {
input "$UPSTREAM_IN";
}
}
family inet6 {
filter {
input "$UPSTREAM_IN_v6";
}
}
}
}
}
firewall {
family inet {
filter "$UPSTREAM_IN" {
interface-specific;
term 1 {
from {
dscp ef;
}
then {
hierarchical-policer "$policer";
count VoIP_ACCEPT;
forwarding-class VoIP;
accept;
}
}
term 2 {
from {
dscp [ af33 af32 af31 ];
}
then {
hierarchical-policer "$policer";
forwarding-class AF3X;
accept;
}
}
term 3 {
from {
dscp [ af23 af22 af21 ];
}
then {
hierarchical-policer "$policer";
forwarding-class AF2X;
accept;
}
}
term 4 {
then {
hierarchical-policer "$policer";
forwarding-class best-effort;
accept;
}
}
}
}
family inet6 {
filter "$UPSTREAM_IN_v6" {
interface-specific;
term 1 {
from {
traffic-class ef;
}
then {
hierarchical-policer "$policer";
count VoIP_IPV6_ACCEPT;
forwarding-class VoIP;
accept;
}
}
term 2 {
from {
traffic-class [ af33 af32 af31 ];
}
then {
hierarchical-policer "$policer";
forwarding-class AF3X;
accept;
}
}
term 3 {
from {
traffic-class [ af23 af22 af21 ];
}
then {
hierarchical-policer "$policer";
forwarding-class AF2X;
accept;
}
}
term 4 {
then {
hierarchical-policer "$policer";
forwarding-class best-effort;
accept;
}
}
}
}
hierarchical-policer "$policer" {
logical-interface-policer;
aggregate {
if-exceeding {
bandwidth-limit "$inBW";
burst-size-limit "$burstPolicer";
}
then {
discard;
}
}
premium {
if-exceeding {
bandwidth-limit "$voiceBW";
burst-size-limit 9216;
}
then {
discard;
}
}
}
}
}
}
Having both "GIGE_DS_PROFILE" and "SERVICE_ACTIVATE_DS_IN" dynamic profiles allows MX to limit subscriber downstream and upstream traffic based on downstream and upstream values returned by RADIUS according to the subscriber profile acquired.
IPv4, IPv6 PD (LAN addressing), and IPv6 NDRA (WAN addressing) pools for a DS subscriber are displayed below. These pools allow IPv4 addresses and IPv6 prefixes assignment to a subscriber. It also assigns IPv4 and IPv6 DNS to a subscriber.
The multiservice interface allows traffic to be NATed in ingress and egress traffic direction. This interface has 2 legs, one to the private network (inside) and one to the public network (outside), the inside multiservice interface is in charge of sending traffic to the Juniper MX SPC3 service card, so traffic can be translated, this interface is assigned to a routing-instance. These interfaces are numbered according to the slot in which SPC3 is inserted, PIC0 represents SPC3 NPU0 and PIC1 represents SPC3 NPU1, the port number is always 0.
PPPoE "GGNAT_DS_PROFILE" is assigned to the subscriber by RADIUS during the subscriber's authentication. If the subscriber is a CGNAT subscriber, RADIUS will return another dynamic profile than the one assigned to the MPC10E access interface, because to CGNAT dynamic profile needs to assign the subscriber to a routing-instance which in our example is specified by RADIUS in the access-accept attributes returned to subscriber.
Routing redirect can be achieved in three ways: RADIUS returned Unisphere-Virtual-Router VSA, predefined-variable in the dynamic-profile and access domain-map target-routing-instance.
"CGNAT_DS_PROFILE" dynamic profile configuration is almost identical to the one described in the dynamic profile configuration section. The difference is that the "CGNAT_DS_PROFILE" dynamic profile includes a routing-instance to which the subscriber will be assigned.
DS CGNAT subscriber is assigned to a CGNAT routing instance, we're using a VRF routing-instance in our example, a virtual-router routing-instance can also be used
The CGNAT routing-instance name is specified by RADIUS in the access-accept attributes returned to the subscriber.
This CGNAT routing-instance includes the DHCPv6 server configuration used for IPv6 PD assignment (LAN addressing) as described in the DHCPv6 Local Server configuration section. It also includes IPv4 private, IPv6 PD (LAN addressing), and IPv6 NDRA (WAN addressing) pools for a DS CGNAT subscriber. These pools allow IPv4 private address and IPv6 prefix assignment to a DS CGNAT subscriber. It also assigns IPv4 and IPv6 DNS to a DS CGNAT subscriber.
In our example, DS CGNAT subscriber's traffic is sent to virtual-router (PIC0) via a forwarding-options input filter. The inside multiservice interface is assigned to a virtual-router, this is used to send traffic to the corresponding multiservice interface in the next-hop CGNAT solution.
Default route redirects traffic to inside multiservice interface, so traffic can be NATed. Static route 172.29/16 sends traffic to NAT-44 routing-instance which subscriber resides.
CGNAT specific configuration includes a service-set which is the main CGNAT building block, it groups the inside and outside multiservice interfaces along the NAT rule, this is where the translation takes place. The packets toward the inside multiservice interface are translated based on the NAT rule defined under this service-set.
Having a next-hop style service represents an inside multiservice interface (private network addressing) and an outside multiservice interface (public network addressing).
A firewall rule is needed for the service-set, this firewall rule can accept everything as displayed below or can do firewalling based on specific requirements.
The NAT rule identifies the source private addressing and based on the source addressing along the ALGs does the source NAT, it calls a pool in the source NAT action. A NAT rule is defined under a NAT rule-set, the NAT rule-set can have multiple NAT rules.
An address-book contains address ranges, and private source addressing is defined under these ranges.
Application Layer Gateways allows applications to work within NAT, Junos includes rich ALGs for NAT such as FTP, DNS, H323, ICMP, SIP, PPTP, SNMP, TFTP, etc. Most applications have evolved to function in an IPv4 NAT, working in the application layer.
The NAT pool contains the public IPv4 address to which private addressing will be translated, and the ports range available per public IPv4 address, if PBA or Deterministic NAT is used, it then also includes the port block-size and the IPv4 private addressing.
jnpr@MX960> show subscribers summary port
Interface Count
xe-9/0/3:0 16000
Total Subscribers: 16000
jnpr@MX960> show subscribers summary
Subscribers by State
Active: 32000
Total: 32000
Subscribers by Client Type
DHCP: 16000
PPPoE: 16000
Total: 32000
DS and DS CGNAT subscribers are shown below. DS subscribers are assigned to the default routing-instance, and DS CGNAT subscribers are assigned to the NAT-44 routing-instance.
Each subscriber has a unique dynamic PPPoE interface, an IPv4 address representing either a Public or Private IPv4, an Internet IPv6 PD (LAN addressing) pefix, and a private IPv6 prefix for WAN addressing.
The IPv4 172.20/16 prefix represents public addressing, while the IPv4 172.29/16 prefix represents private addressing.
IPv6 prefixes 2222::/64 and 2223::/64 represent Internet IPv6 prefixes.
IPv6 prefixes fdff:fffe::/64 and fdff:ffff::/64 represent private IPv6 prefixes.
Inte-Subsc username is used for 8K DS subscribers, and the CGNAT-Subsc username is used for 8K DS CGNAT subscribers.
jnpr@MX960> show pppoe statistics
Active PPPoE sessions: 16000
PacketType Sent Received
PADI 0 16000
PADO 16000 0
PADR 0 16000
PADS 16000 0
PADT 0 0
Service name error 0 0
AC system error 0 0
Generic error 0 0
Malformed packets 0 0
Unknown packets 0 0
jnpr@MX960> show pppoe sessions
Interface Underlying State Session Remote
interface ID MAC
pp0.3221225483 xe-9/0/3:0.1585 Session Up 1 DC:8D:B7:00:00:00
pp0.3221225485 xe-9/0/3:0.1585 Session Up 2 DC:8D:B7:00:00:01
pp0.3221225489 xe-9/0/3:0.1585 Session Up 3 DC:8D:B7:00:00:02
pp0.3221225493 xe-9/0/3:0.1585 Session Up 4 DC:8D:B7:00:00:03
pp0.3221225497 xe-9/0/3:0.1585 Session Up 5 DC:8D:B7:00:00:04
jnpr@MX960> show pppoe underlying-interfaces xe-9/0/3:0.1585 extensive
xe-9/0/3:0.1585 Index 539
State: Static, Dynamic Profile: GIGE_DS_PROFILE,
Max Sessions: 16000, Max Sessions VSA Ignore: Off,
Active Sessions: 16000,
Service Name Table: None,
Duplicate Protection: On, Short Cycle Protection: mac-address,
Direct Connect: Off,
AC Name: MX960,
PacketType Sent Received
PADI 0 16000
PADO 16000 0
PADR 0 16000
PADS 16000 0
PADT 0 0
Service name error 0 0
AC system error 0 0
Generic error 0 0
Malformed packets 0 0
Unknown packets 0 0
Lockout Time (sec): Min: 60, Max: 240
Total clients in lockout: 0
Total clients in lockout grace period: 0
NDRA packets per PPPoE interface are exchanged for both DS and DS GNAT subscribers, and NDRA is used for IPv6 WAN Addressing.
jnpr@MX960> show ipv6 router-advertisement
Interface: pp0.3221225483
Advertisements sent: 9, last sent 0:08:22 ago
Solicits received: 1, last received 1:02:28 ago
Advertisements received: 0
Interface: pp0.3221225484
Advertisements sent: 9, last sent 0:08:22 ago
Solicits received: 1, last received 1:02:28 ago
Advertisements received: 0
Interface: pp0.3221225485
Advertisements sent: 9, last sent 0:08:22 ago
Solicits received: 1, last received 1:02:28 ago
Advertisements received: 0
Interface: pp0.3221225486
Advertisements sent: 9, last sent 0:08:22 ago
Solicits received: 1, last received 1:02:28 ago
Advertisements received: 0
All subscribers have a shaping rate and a service activate assigned via RADIUS. Each subscriber also has an IPv4 and IPv6 input FWF.
jnpr@MX960> show subscribers summary routing-instance default
Subscribers by State
Active: 16000
Total: 16000
Subscribers by Client Type
DHCP: 8000
PPPoE: 8000
Total: 16000
Subscribers by LS:RI
default:default: 16000
Total: 16000
DHCPv6 PD (IPv6 LAN addressing) sessions are bound for each PPPoE subscriber.
jnpr@MX960> show network-access aaa statistics address-assignment pool POOL_IPv4_PUBLIC
Address assignment statistics
Pool Name: POOL_IPv4_PUBLIC
Out of Memory: 0
Out of Addresses: 0
Address total: 65536
Addresses in use: 8000
Address Usage (percent): 13
Pool drain configured: no
jnpr@MX960> show network-access aaa statistics address-assignment pool POOL_IPV6_PD
Address assignment statistics
Pool Name: POOL_IPV6_PD
Out of Memory: 0
Out of Addresses: 0
Address total: 65536
Addresses in use: 8000
Address Usage (percent): 13
Pool drain configured: no
Each subscriber has been assigned an IPv4 address, DNS, an IPv6 PD prefix, and an IPv6 prefix for WAN addressing. IPv4 addresses and IPv6 prefixes are taken from the corresponding pools indicated by RADIUS.
A shaping rate to limit downstream subscriber bandwidth and a transmit rate for a scheduler are assigned to each subscriber via RADIUS. A service activate is also assigned to each subscriber by RADIUS with the corresponding IPv4 and IPv6 input FWF. The variables defined for such service-activate receive a value from RADIUS to limit upstream bandwidth for each subscriber.
In DS, a DHCP logical interface is tied to a PPPoE interface. The DHCP logical interface specifies the DHCPv6 pool used for DHCPv6 PD.
A 2,048 port block size from a public IPv4 address is assigned to each of the 8K private IPv4 addresses, in other words, 2,048 Deterministic NAT sessions are allowed per private IPv4 address.
Each of the subscribers has been assigned an IPv4 address, DNS, an IPv6 PD prefix, and an IPv6 prefix for WAN addressing. IPv4 addresses and IPv6 prefixes are taken from the corresponding NAT-44 routing-instance pools indicated by RADIUS.
For DS CGNAT subscribers, the client profile name is changed by RADIUS in order to assign subscriber to corresponding NAT-44 routing-instance.
A shaping rate to limit downstream subscriber bandwidth and a transmit rate for a scheduler are assigned to each subscriber via RADIUS. A service activate is also assigned to each subscriber by RADIUS with corresponding IPv4 and IPv6 input FWF. The variables defined for such service-activate receive a value from RADIUS to limit upstream bandwidth to each subscriber.
In DS, a DHCP logical interface is tied to a PPPoE interface, DHCP logical interface specifies the DHCPv6 pool used for DHCPv6 PD.
Juniper MX MPC10E-10C and MPC10E-15C line cards have subscriber management capabilities starting in the 22.4R1 release. These line cards support DS subscriber sessions, either IPoE or PPPoE access methods, NDRA or DHCP6 IA_NA for WAN addressing, and DHCPv6 PD for LAN addressing. MX Trio-5 supports subscriber management as in previous MX Trio generations.
MPC10E-10C supports 32K Dual Stack subscribers per PFE, for a total of 64K Dual Stack subscribers. MPC10E-15C supports 32K Dual Stack subscribers per PFE, for a total of 96K subscribers.
MPC10E line cards subscriber scalability is not impacted when enabling HQoS, ingress/egress FW Filtering, or ingress/egress policing per subscriber access connection.
Thanks to Nicolas Fevrier for the opportunity and guidance to write this tech post. Thanks to Dirk van den Borne for encouraging me to create a tech post and also thanks to Aris Georgakas for the review and comments.