Index


A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

GS: Getting Started Guide; IG: Integration Guide; MT: Monitoring and Troubleshooting Guide;
NG: Network Guide; SG: Solutions Guide; SP: Services and Policies Guide; SS: Subscribers and Subscriptions Guide


Index Key

A

aaaCheck
Merit    IG-137, IG-145
RAD    IG-161
aaaDeny
Merit    IG-137, IG-145
RAD    IG-152, IG-161
aaaReply
Merit    IG-137, IG-145
RAD    IG-152, IG-161
access control information
DirX directory server    IG-64
eTrust Directory    IG-44
Oracle Internet Directory    IG-50, IG-52
Sun ONE Directory Server    IG-57
access control scheme
activating access
operator    IG-105
subscription operator    IG-105
binding    IG-97
cachedAuthentication profile    IG-98
common access rights    IG-106
directories    IG-96
directory entries    IG-95
directory-specific    IG-107
DirX directory server    IG-107
LDAP    IG-108
lock subtree    IG-101
mutex group objects    IG-103
network subtree    IG-102
parameter subtree    IG-100
permissions    IG-96
policy subtree    IG-100
RADIUS profile    IG-99
service, policy, and global parameter objects    IG-104
sspServiceProfile    IG-98
subscriber, retailer, and service profiles    IG-102
substitution access    IG-106
Sun ONE Directory Server    IG-109
system management    IG-101
UmcConfiguration    IG-98
umcRadius Person    IG-99
umcUser    IG-99
user class    IG-96
user subtree    IG-104
workflow subtree    IG-103
access DNs    NG-181
access lines    SS-6
description    SS-5
access policy, examples    SP-243
DHCP    SP-244
PPP    SP-246
access services    SP-4
adding    SP-5
configuring subscriptions    SS-171
access subscribers    SS-4
configuring    SS-146
accessing
Prepaid Account Administration application    SG-151
account server, prepaid services demo    SG-146
manual configuration    SG-149
publishing object references    SG-148
script configuration    SG-147
starting    SG-149
stopping    SG-150
accounting
applications    GS-4
basic RADIUS accounting plug-in    SS-102
custom RADIUS accounting plug-ins    SS-102
description    GS-7
flat file accounting plug-ins    SS-102
flexible RADIUS accounting plug-ins    SS-102
SAE, description    NG-10
accounting log file
Merit    IG-145
RAD    IG-162
SPE    IG-129
accounts
administering with Prepaid Account Administration application    SG-152
aci attribute (Sun)    IG-57
ACP (Admission Control Plug-In)
event publishers, configuring    SG-123
overview    GS-34
SAE, configuring for    SG-121
Web administration application    GS-20
action classes in the sample residential portal    SS-188
action threshold, service schedules    SP-59, SP-65
actions. See policy actions
Adaptive Services PIC    SP-93
See also JUNOS ASP policy rules
add-on packages
description    GS-65
directory types    GS-15
DirX directory server    IG-64
eTrust Directory    IG-43
migration    GS-151
OpenLDAP    GS-80, IG-72
Oracle Internet Directory    IG-50
Sun ONE Directory Server    IG-56-IG-57
address pools
assigned IP subscribers
configuring    SG-107
See also IP address pools    NG-42
admin command    GS-73
administration user interface (SPE)    IG-130
administrative users    GS-52
admintool command    GS-71, GS-75
agents. See NIC
aggregate services    SP-17, SP-28-SP-37
adding    SP-31
before you configure    SP-30
fragment services    SP-28
infrastructure services    SP-37
mandatory services    SP-28
Python expressions    SP-33
redundancy    SP-28
sessions    SP-29
activation    SP-29
deactivation    SP-30
monitoring    SP-30
subscriber reference expressions, configuring    SP-32
timers, configuring    SP-36
alarms, license server    GS-116
APIs (application programming interfaces)
CORBA plug-in SPI    GS-32
CORBA remote API    GS-32, NG-9
description    GS-8
documentation    GS-161, SP-60, SS-224
NIC    NG-165
provided with SAE    NG-8
SAE core API    GS-32, NG-8
application manager
role, in PCMM environment    SG-34
application programming interfaces. See APIs
application protocols, managing    SS-351-SS-356
apply-groups statement, JUNOS routing platforms    SP-158
architecture
enterprise service portal    SS-289
SDX software    GS-3-GS-6
ASG (Advanced Services Gateway)
description    GS-24
Subscriber Manager    GS-24
assigned IP subscribers
PCMM network    SG-45
address pools    SG-107
IP address pools    SG-45, SG-64
setting timeouts    SG-31
third-party devices    IG-6
IP address pools    IG-6
voice over IP    SG-31
attribute value pairs
Merit    IG-137, IG-145
RAD    IG-152
Attribute/name section, LDAP authentication (SPE)    IG-124
attributes
AAA
Merit    IG-145
RAD    IG-161
JUNOSe-specific
integration    IG-121, IG-142
Merit    IG-136, IG-140, IG-145
RAD    IG-154, IG-161, IG-162
LDAP    IG-39
Attributes section, customizing authentication
file (SPE)    IG-129
authentication
credentials (SPE)    IG-130
log file, customizing (SPE)    IG-129
authentication plug-ins
configuring    SS-111
types    SS-84
authentication/authorization transfer vectors (AATVs)
Merit    IG-136
RAD    IG-151
authfile file
Merit    IG-142
RAD    IG-157
authorization plug-ins
configuring    SS-111
types    SS-84

B

backing up
DirX directory    IG-70
OpenLDAP directory    IG-72
Sun ONE directory    IG-60
backup directory    GS-163
bandwidth on demand. See BoD
Base variable (SPE)    IG-124
basic RADIUS accounting plug-in    SS-102
configuring    SS-107
basic RADIUS authentication plug-in    SS-111
configuring    SS-112
BEEP, JUNOS routing platforms    NG-4
configuring port    NG-76
connecting    NG-66
binary directory (RAD)    IG-150
Bind
LDAP authentication (SPE)    IG-121
request (SPE)    IG-121, IG-126
binding
access control    IG-97
BindName
LDAP authentication (SPE)    IG-122
LDAP server (SPE)    IG-123
SDX application (SPE)    IG-124
user password attribute (SPE)    IG-124
BindPassword
LDAP authentication (SPE)    IG-122
LDAP server (SPE)    IG-123
Blocks Extensible Exchange Protocol. See BEEP
BoD (bandwidth on demand)
services    SS-246, SS-258-SS-265
subscriptions    SS-334-SS-381
Bootstrap section, LDAP authentication (SPE)    IG-121
browser requirements (SPE)    IG-114

C

cable modem termination system. See CMTS devices
cacerts files, LDAPS    IG-77
cachedAuthentication and access controls    IG-98
callback interface    SS-283
captive portal
implementing    SS-226
preventing access to resources    SS-225
using with next-hop action    SP-212
CDs for SDX software distribution    GS-52
certificate authority (CA)    MT-52, NG-78
certificate files, LDAPS    IG-77
certificate signing request (CSR), SAE Web Admin    MT-52, NG-80
certificates, securing SAE Web Admin    MT-51
Class
Merit    IG-145
RAD    IG-162
SPE    IG-129
class of service. See CoS
classification scripts
configuring    SS-52
criteria
definition    SS-50
glob matching    SS-53
joining    SS-53
regular expression matching    SS-54
descriptions    SS-49
DHCP classification
configuring    SS-71
criteria    SS-72
description    SS-49
targets    SS-73
interface classification
configuring    SS-58
criteria    SS-58
description    SS-49
examples    SS-60
how it works    SS-50
targets    SS-60
testing    MT-74
structure    SS-52
subscriber classification
configuring    SS-62
criteria    SS-63
description    SS-49
DHCP options    SS-66
enterprise subscriber example    SS-69
how it works    SS-51
static IP subscriber example    SS-68
subscriber group example    SS-69
targets    SS-68
testing    MT-73
wholesaler/retailer example    SS-70
target
definition    SS-50
expressions    SS-52
types    SS-52
classify-traffic condition    SP-104
application protocol
defining    SP-186
map expressions    SP-187
configuring    SP-171-SP-193
destination network, setting    SP-176
expanded classifiers    SP-105
configuring    SP-172, SG-144
extended classifiers    SP-111
configuring    SP-173
ICMP type and code, setting    SP-182
IGMP type, setting    SP-182
IP protocol, setting    SP-179
JUNOS filter conditions, setting    SP-184
match direction, setting    SP-174
multiple classifiers    SP-104
network protocol, setting    SP-175
packet length, setting    SP-179
PCMM I02 and I03    SP-111
configuring    SP-173
source network, setting    SP-176
SPI (security parameter index), setting    SP-182
TCP flags, setting    SP-182
ToS byte, setting    SP-181
client type 1, PCMM    SG-36
client type 2, PCMM    SG-37
CMTS devices
adding objects to directory    SG-60
adding virtual router objects to directory    SG-62
role    SG-34
commands
keytool    IG-77
Common Information Model (CIM)    IG-33
component distribution scenarios
consolidated installation    GS-46-GS-48
distributed installation    GS-41-GS-43
regionalized installation    GS-44-GS-45
single host installation    GS-40
component installation    GS-72
component interactions
DHCP
initial login    SS-17
persistent login    SS-20
subscriber account login    SS-19
subscriber logout    SS-22
enterprise subscribers
login    SS-26
remote session activation    SS-32
JUNOS routing platforms and SAE    NG-4
PPP
login    SS-13
logout    SS-15
static IP subscribers    SS-23
subscription activation    SS-28
subscription deactivation    SS-30
compress command    GS-75
config command    GS-175
configuration
enable LDAP host (SPE)    IG-116
files (SPE)    IG-115, IG-116
procedure (SPE)    IG-116, IG-117
configuration directory
Merit    IG-140, IG-142
RAD    IG-150
configuration group, JUNOS routing
platforms    NG-66, NG-95
configuration level in Enterprise Manager Portal    SS-327
configuration manager, instantiating for NIC    NG-166
configuration tool. See local configuration tool
configuring
SAE for ACP    SG-121
consolidated installation
component distribution scenario    GS-46-GS-48
redundancy schemes    GS-47
content rules    IG-40
controlled load service, FlowSpec    SP-113
COPS (Common Open Policy Service)
connection with JUNOSe routers    NG-38
COPS-PR versus COPS XDR    NG-4
DHCP interactions
initial login    SS-18
logout    SS-22
persistent login    SS-21
subscriber account login    SS-19
interface startup interactions    SS-16
JUNOSe router connection    NG-4, NG-38
configuring router    NG-61, NG-62
configuring SAE    NG-46
PPP interactions
login    SS-14
logout    SS-15
static IP subscriber interactions    SS-23
subscription activation interactions    SS-30
subscription deactivation interactions    SS-31
CORBA (Common Object Request Broker Architecture)
object reference in external plug-ins    SS-95
plug-in interface
enterprise service portal    SS-290-SS-291
remote API    NG-9, SS-224
CORBA-based plug-in SPI. See plug-ins, external
CoS (class of service)    SP-92
ToS byte, setting    SP-181
credentials
authentication (SPE)    IG-130
bind to LDAP server (SPE)    IG-123
LDAP authentication (SPE)    IG-122
crontab file    IG-85, IG-90, SS-276
custom RADIUS accounting plug-ins    SS-102
configuring    SS-109
custom RADIUS authentication plug-ins    SG-23, SS-111
configuring    SS-114
customized interface modules    NG-9

D

data directory (RAD)    IG-150
data integrators
adding VPNs    IG-90, SS-270
configuring    IG-85
deactivating invalid subscriptions
to VPNs    IG-92, SS-275
description    IG-81
developing    IG-84
executing    IG-90
getting help    IG-83
logging properties    IG-85
order of processors    IG-86
planning    IG-84
processors
Database Reader    IG-86
description    IG-82
Enterprise Audit File Reader    IG-88
LDAP Reader    IG-87
LDAP Writer    IG-89
suite, installing    IG-84
XML File Reader    IG-88
XML File Writer    IG-89
Data over Cable Service Interface Specifications.
See DOCSIS protocol
data security, Policy Editor    SP-135
database
files
installation (SPE)    IG-115
previous installations (SPE)    IG-116
integrating data into directory    IG-82
JDBC drivers    IG-84
Database Reader    IG-86
Data-over-Cable Service Interface Specifications. See DOCSIS
datastream format    GS-75
DCU (destination class usage)    SS-268
default policies    SP-94
example    SP-243
installing on router    SP-95
reloading on router    SP-95
default retailer authentication plug-ins    SS-135, SS-136
default SDX installation directory    GS-71
default.properties file    GS-93
demonstration application, prepaid services    SG-145
denial-of-service attacks    SS-238
deploying
Prepaid Account Administration application    SG-151
deployment scenarios
enterprise service portal    SS-291
SDX software    GS-40
DES (directory eventing system)    GS-163
sample configuration    GS-168
SDX properties    GS-165
standard properties    GS-164
using
large directories    GS-171
OpenLDAP    GS-171
destination class usage    SS-268
DHCP (Dynamic Host Configuration Protocol)
access policy example    SP-244
address assignment    SS-86
classification scripts. See classification scripts
options    SS-74
profiles    SS-77
subscribers
login process    SS-16-SS-21
logout process    SS-22
dictionary files with JUNOSe parameters
Merit    IG-139
RAD    IG-154
SPE    IG-119
differentiated QoS    GS-8
Differentiated Services code point, ToS byte    SP-181
directed accounting (SPE)    IG-128
directed authentication (SPE)    IG-127, IG-128
directory
access control scheme    IG-95-IG-110
access rights    IG-31
client    GS-15
configuring
redundancy    GS-163
type    GS-169
default SDX installation    GS-71
deleting entries    GS-169
description    GS-10
enterprise service portal    SS-290
eventing and failover, description    GS-15
exception handling, Policy Editor    SP-135
failover    GS-163
finding new entries    GS-169
LDAP version 3 compatibility    GS-14
managing problems    GS-170
multimaster replication    NG-172
prepackaged integration    GS-15
primary    GS-163
provisioning    IG-67
RADIUS    GS-33
reading data    IG-82
redundancy    IG-30
retrieving changed data    GS-163
schema    IG-33-IG-40
secondary (backup)    GS-163
supported directory servers    IG-31
synchronizing    SP-135
transferring data    IG-81
updates to    IG-30
Workflow application    GS-30
See also LDAP
directory eventing system. See DES
Directory Information Shadowing Protocol    GS-42
directory migration
cloning the directory server    GS-152
DirX    GS-153
OpenLDAP    GS-152
Sun ONE    GS-153
completion
DirX    GS-156
OpenLDAP    GS-156
Sun ONE    GS-156
configuration file    GS-154
DirX slave directories    GS-149
host preparation    GS-151
installing directory packages    GS-151, GS-154
OpenLDAP slave directories    GS-148
script    GS-146, GS-155
shadowed environment    GS-148
DirX    GS-149
OpenLDAP    GS-148
Sun ONE    GS-150
updating the host    GS-157
directory server
cloning    GS-152
deployment with remote SAE    SS-291
supported    GS-57
third-party    GS-15
See DirX directory server; eTrust Directory; OpenLDAP directory server; Oracle Internet Directory; Sun ONE Directory Server
Directory Service Protocol    GS-42
directory shadows    GS-42
DirX directory server
access control scheme    IG-107
add-on package    GS-15, IG-64
backing up directory    IG-70
cloning the directory server    GS-153
deployment with remote SAE    SS-291
directory user    IG-65
dirx user environment    IG-68, IG-69
installing    IG-66
integrating with SDX software    IG-64-IG-67
integration    GS-14, GS-15
loading sample data    IG-67
obtaining    IG-65
restoring directory database    IG-70
slave directories, migrating    GS-149
standards    IG-64
starting    IG-68, IG-69
stopping    IG-69
superuser environment    IG-69
uninstalling    IG-68
dirxadm (DirX)    GS-149
DirXmetahub    IG-64, IG-67
DISP (Directory Information Shadowing Protocol)    GS-42
distinguished name. See DN
distributed installation
reliability    GS-43
scalability    GS-43
simplified management and security    GS-43
DIT (Directory Information Tree)
content rules    IG-40
structure rules    IG-40
dlm1Chassis object class    IG-38
DN (distinguished name)
NIC resolution    NG-181
subscriber data    NG-15
DOCSIS policy actions    SP-105
configuring    SP-195
DOCSIS protocol    SG-35
Document Object Model. See DOM
document type definitions. See DTDs
DOM (Document Object Model)    IG-86
domain name parsing
configuring    SS-45
testing    MT-75
domains
IP service edge    SG-40
IP subscriber edge    SG-40
radio frequency    SG-40
draft RFCs    GS-210
drop profile maps
configuring    SP-230
drop probability, setting    SP-232
fill level, setting    SP-232
DSCP (Differentiated Services code point), ToS byte    SP-181
DSP (Directory Service Protocol)    GS-42
DTDs (document type definitions), data integrators    IG-82
dtterm command    GS-63
duplicate entries    GS-190
duplicate entries in SDX Admin    GS-190
dynamic Web pages    GS-7

E

editing level, SDX Configuration Editor    GS-194
effective period, service schedules    SP-61
embedded AdminServer authorization plug-in    SS-137
end-to-end services    SG-40
enterprise
description    SS-5
hierarchy    SS-6
service parameters    SS-284
subscriptions    SS-6
Enterprise Audit File Reader    IG-88
Enterprise Manager Portal
application protocols, managing    SS-352-SS-356
BoD subscriptions    SS-334-SS-381
configuration level    SS-327
deployment settings    SS-299
directory eventing    SS-315
firewall exception rules
stateful firewalls    SS-368
stateless firewalls    SS-359
firewall subscriptions    SS-356-SS-373
fixed addresses for outgoing traffic    SS-381
help    SS-325
NAT
IP address    SS-374, SS-376
rules for traffic    SS-378
NAT Address Management Portal    SS-305
NAT rules    SS-377, SS-381
overview    SS-282, SS-326
policies    SS-245-SS-268
public IP addresses, configuring
incoming traffic    SS-379
outgoing traffic    SS-378
schedules    SS-327-SS-334
services    SS-245-SS-268
Enterprise Service Portal audit plug-in    SS-316-SS-320
logs    IG-82
using with VPN Subscription Deactivator    SS-275
enterprise service portals
accessing    SS-287
architecture    SS-289
communication protocols    SS-290
configuring directory connections    SS-297
data, displaying    SS-321
deploying    SS-305
description    GS-27
improving performance    SS-283
installing    SS-296-SS-305
IT Manager audit plug-in sample    SS-318-SS-320
locating in SDX software distribution    SS-281
logging properties    SS-314
NIC proxy    SS-314
operators, managing    SS-322, SS-324
overview    SS-279
performance    SS-283
planning    SS-292
prerequisites    SS-287, SS-295, SS-321, SS-385, SS-399
properties    SS-306
remote SAE properties    SS-315
search bases    SS-312
server description    SS-290
service directory connection    SS-310
subscriber directory connection    SS-307
value substitution    SS-286
value substitution for policy parameters    SS-286
See also Enterprise Manager Portal
enterprise subscribers    SS-3
adding to directory    SS-156
enterprise subscribers, login process    SS-26
enterprise tag library    SS-280, SS-281
equipment registration
deleting    MT-67
description    SS-187
viewing on SAE    MT-67
See also sample residential portal
ERX VSA    SP-11, SP-15
/etc/services file (Merit)    IG-137
eTrust Directory
add-on package    GS-15, IG-43
installing    IG-45
integrating with SDX software    IG-45
integration    GS-14
Juniper SDX eTrust Directory
displaying status    IG-47
starting    IG-46
stopping    IG-47
load script    IG-43, IG-46
loading sample data    IG-46
setup.sh script    IG-44, IG-46
event messages    MT-3
categories    MT-10
severity levels    MT-10
system logging    MT-7
writing to text file    MT-5
event notification
DHCP server    SG-117
IP address manager    SG-117
PCMM network    SG-117
RADIUS server    SG-117
event notification, PCMM network
configuring properties    SG-54
description    SG-47
event notification, third-party devices
configuring properties    IG-20
description    IG-7
event publishers
accessing    SS-91
configuring in property file    SS-99
configuring with SDX Configuration Editor    SS-134
default retailer authentication, configuring    SS-135
default retailer DHCP authentication,
configuring    SS-136
description    SS-84
global, configuring    SS-135-SS-137
retailer-specific    SS-138
service-specific    SS-137
virtual router-specific    SS-138
events
IT manager audit    SS-316
publishing    SG-123
examples
access policy
PPP    SP-246
exclusions to service schedule    SP-63, SP-71, SP-73
expanded classifiers    SP-105
configuring    SP-172, SG-144
expressions
map, application protocol conditions    SP-187
parameter definitions    SP-267-SP-273
policy fields    SP-158
extended classifiers, PCMM    SP-111
configuring    SP-173
external applications, interaction with NIC    NG-165
external database (SPE)    IG-121
external plug-ins. See plug-ins
extranet clients
adding to VPNs
Enterprise Manager portal    SS-273
LDAP clients    SS-273
SDX Admin    SS-273
removing from VPNs    SS-275

F

failover directories    GS-163
feature sets for installation    GS-72
file format translation    GS-75
file system format    GS-75
file transfer, verifying    GS-75
files
ipnat.conf    SS-228
WEB-INF/jboss-web.xml    SS-192
WEB-INF/portalBehavior.properties    SS-192
WEB-INF/struts-config.xml    SS-192, SS-195
WEB-INF/tiles-defs.xml    SS-192, SS-197
WEB-INF/web.xml    SS-192
filter actions    SP-105
configuring    SP-200
finding new directory entries    GS-169
firewall filter    SP-92
matching destination class    SP-185
matching source class    SP-185
firewall ports for SDX-related components    GS-83
firewall services
configuring    SS-247, SS-250
description    SS-356
managing in Enterprise
Manager Portal    SS-356-SS-373
policies for    SS-249
router support    SS-246
flat file accounting plug-ins    SS-102
configuring    SS-102
headers    SS-106
flexible RADIUS accounting plug-ins    SS-102
attributes, defining    SS-127
examples    SS-132
configuring    SS-108
RADIUS packets, defining    SS-99, SS-126
flexible RADIUS authentication plug-ins    SS-111
attributes, defining    SS-127
examples    SS-132
configuring    SG-23, SS-113
RADIUS packets, defining    SS-99, SS-126
setting responses    SS-133
FlowSpec actions    SP-105
configuring    SP-201
folders
default SDX installation    GS-71
SDX Admin    GS-183
format translation, file    GS-75
forward actions    SP-106
configuring    SP-204
forwarding class actions    SP-106
configuring    SP-205
forwarding preferences    SS-263, SS-265
fragment services    SP-28
configuring    SP-32

G

gates, PCMM    SP-110
gateSpec actions    SP-106
configuring    SP-206
generate.sh script (DirX)    IG-67
getting help, data integration    IG-83
global parameter objects and access
control scheme    IG-104
global parameters    SP-114
configuring    SP-126-SP-129
predefined, list    SP-123
runtime    SP-123
summary table    SP-115
types    SP-117
viewing in Policy Editor    SP-115
global plug-ins, configuring    SS-135-SS-137
graphical installation mode    GS-65
groups, NIC hosts    NG-109, NG-134
guaranteed service, FlowSpec    SP-113
gzip command    GS-75

H

hard-disk space requirements
Merit    IG-136
RAD    IG-150
SPE    IG-114
hardware
consolidated installation    GS-48
requirements    GS-54
Host values (SPE)    IG-123
hosted plug-ins. See plug-ins
hostid command    GS-96
hosts
transferring software packages    GS-75
See also NIC hosts
HTTP proxy    SS-227, SS-228
HTTP with Workflow application    GS-31

I

Idle-Timeout    IG-145, IG-162
IDP (Intrusion Detection and Protection) integration applications    GS-26
ifconfig command    SS-229
infrastructure services    SP-17, SP-37-SP-38
initialize.cp flat file (DirX)    IG-64
install.sh script (SPE)    IG-114, IG-117
installation
components    GS-72
designating nonroot users    GS-73
feature sets    GS-72
graphical mode    GS-65
installation folders    GS-71, GS-72
installation sets    GS-67
IP Filter    GS-74
logging the session    GS-63
modes    GS-65
package names for features    GS-72
packages    GS-73
patches    GS-57
procedure    GS-63
procedure (Merit)    IG-136
scripts (SPE)    IG-115, IG-116
silent mode    GS-65
software CD (SPE)    IG-114
starting the installation program    GS-70
system resource limits    GS-73
uninstallation    GS-76
Web applications    GS-137
installing software
enterprise service portals    SS-296-SS-305
Merit    IG-136
RAD    IG-150
SPE    IG-114
instlic command    GS-101, GS-103, GS-104
integrating data into directory    IG-32, IG-82
interface classification scripts. See classification scripts
interface modules, SAE    NG-9
interfaces
callback    SS-283
viewing on SAE    MT-65
interim accounting, configuring on SAE    SS-38
interim update interval    SG-146
Interlink RAD-Series RADIUS Server    GS-33
internal plug-ins. See plug-ins
internationalization of SDX Admin    GS-191
interoperable object reference. See IOR
invalid subscriptions to VPNs    IG-92
IOR (interoperable object reference)
external plug-ins    SS-95, SS-98
router initialization scripts    NG-51, NG-89
SNMP file locations    MT-23
IP address managers
logging in subscribers
event notification method    SG-117
IP address pools    NG-55-NG-58
assigned IP subscribers    SG-45
configuring    SG-64
example, ranges    NG-42
local address pools, configuring    NG-42
static pools, configuring    NG-43
syntax    NG-42, SG-64, SG-107
updating for JUNOSe VRs    NG-55-NG-58
poolRepublish    NG-56
SDX Admin    NG-56
IP addresses
acknowledging release    SS-387
assigning in NAT Address Management
Portal    SS-385, SS-386
NAT services    SS-374, SS-376
IP Filter    SS-226, SS-228
installation order    GS-74
installation prerequisite    GS-62
IP Security. See IPSec
IP service, life-cycle process    GS-4
IP-in-IP tunneling    SS-238
ipnat.conf file    SS-228
IPSec
between SAE and other applications    SG-69-SG-80
configuring for SAE    SG-71
keys, supported    SG-70
IPTV application    GS-27
configuring    SG-119
installing    SG-118
ISP service in sample residential portal    SS-188, SS-190
IT manager
audit plug-in
configuring    SS-318
events    SS-316
operators, managing    SS-322, SS-324
IVE (Instant Virtual Extranet) Host Checker integration application    GS-27

J

J2EE application server    GS-36
J2SE patches    GS-57
JacORB, for NIC
configuring
default ORB for JRE    NG-154
properties on redundant NIC hosts    NG-177
Web application    NG-155
Web application server    NG-156
JRE package    NG-154
Jakarta Struts Web application framework    SS-187
Java Database Connectivity. See JDBC
Java development environment, Tomcat    SS-239, SS-399
Java Management Extension    MT-91
Java Naming and Directory Interface. See JNDI
Java Runtime Environment, NIC proxy    NG-154
Java Virtual Machine, for NIC proxy    NG-154
Javadoc documentation for sample
residential portal    SS-224
JBoss
installing Web applications    SS-198, SS-295
installing Web applications inside    GS-138
removing Web applications    GS-139
JDBC (Java Database Connectivity) drivers    IG-84
JMX (Java Management Extension) software    MT-91
JNDI (Java Naming and Directory Interface)    GS-164
JPS (Juniper Policy Server)
advanced properties, configuring    SG-99
architecture    SG-82
installing    SG-83
local configuration, applying    SG-83
monitoring    SG-86, SG-114
NTP configuration
applying    SG-84
modifying local time    SG-84
operational status    SG-86
overview    SG-81
stopping    SG-86
subscriber address mappings, configuring    SG-100
subscriber configuration, modifying    SG-100
JPS Administration
CMTS locator, configuring    SG-100
description    GS-20
JPS configuration, monitoring    SG-115
JPS state, monitoring    SG-114
monitoring    SG-114
server process, monitoring    SG-114
starting    SG-87
subscriber configuration
configuring    SG-100
monitoring    SG-116
JSP (Java Server Pages) technology
Web application server    GS-36
JSP tag library. See enterprise tag library
Juniper Networks dictionary files
Merit    IG-139
RAD    IG-155
SPE    IG-119
Juniper Networks Professional Services    IG-83
Juniper Policy Server. See JPS; JPS Administration
Juniper SDX eTrust Directory. See eTrust Directory
JUNOS ASP policy rules    SP-101
NAT actions    SP-106
configuring    SP-210
network, specifying    SP-177
stateful firewall actions, configuring    SP-235
JUNOS filter policy rules    SP-101
conditions, setting    SP-184
JUNOS policer policy rules    SP-101
policer actions    SP-106
configuring    SP-217
JUNOS port mirror policy rules
traffic mirror actions    SP-107
JUNOS routing platforms
accessing CLI    NG-92
BEEP connection    NG-4
configuring port    NG-76
configuration groups    NG-66, NG-95
configuring to interact with SAE    NG-94
CoS (Class of Service)    SS-258
default virtual router    NG-66
disabling interactions with SAE    NG-95
enabling interactions with SAE    NG-95
forwarding preferences    SS-265
logging    NG-96
managing traffic    SS-246
monitoring interactions with SAE    NG-95
policies
basic BoD    SS-260
BOD    SS-261
BoD and VPNs    SS-267
firewall    SS-247-SS-256
NAT    SS-256
policy features
Adaptive Services PIC    SP-93
CoS    SP-92
firewall filter    SP-92
NAT, description    SP-93
policing, description    SP-92
policy sharing    SP-96
rate-shaping    SP-101
stateful firewall, description    SP-93
provisioning services
prerequisites    SS-247
router objects, adding    NG-68-NG-69
routing preferences    SS-263
SAE interactions    NG-4
scalability    GS-6
SDX software process    NG-66
services
basic BoD    SS-260
BoD    SS-262
BoD and VPNs    SS-267
firewall    SS-247-SS-256
NAT    SS-256
value-added services    SS-268
simulated router driver, configuring    MT-15
statements for integration
port-number    NG-94
server-address    NG-94
source-address    NG-94
troubleshooting    NG-96
VR objects, adding individually    NG-70-NG-75
JUNOS scheduler policy rules    SP-101
actions    SP-106
configuring    SP-227
drop profile maps
configuring    SP-230
drop probability, setting    SP-232
fill level, setting    SP-232
QoS conditions, configuring    SP-191
JUNOS shaping policy rules    SP-101
JUNOSe RADIUS client
Merit    IG-145
RAD    IG-162
JUNOSe routers
(QoS) quality of service    SS-258
accessing CLI    NG-59
COPS connection    NG-4
configuring    NG-46
integration overview    NG-38
logging    NG-63
monitoring interactions with SAE    NG-62
policies
basic BoD    SS-260
BOD    SS-261
policy features
packet filtering    SP-93
packet forwarding    SP-93
policy routing    SP-93
policy sharing    SP-96
QoS classification and marking    SP-93
rate limiting    SP-93
router objects, adding    NG-38-NG-40
scalability with SDX software    GS-6
SDX client    NG-38
starting    NG-61
stopping    NG-62
services
basic BoD    SS-260
BoD    SS-262
SNMP communities, configuring    NG-50
SNMP server, configuring    NG-49
troubleshooting    NG-63
VR objects
adding individually    NG-41-NG-46
adding operative VRs    NG-38
JVM (Java virtual machine), for NIC proxy    NG-154

K

keytool command    IG-77

L

language, setting with SDX Admin    GS-191
LDAP
attributes    IG-39
integration overview    IG-29-IG-31
models
operators    SS-144
policy    SP-107
services    SP-4
subscribers    SS-139
subscriptions    SS-141
overview    IG-29
See also directory; LDAPS
LDAP (Lightweight Directory Access Protocol ). See directory; directory server
LDAP access. See SAE (service activation engine), configuring
LDAP authentication
AATV
Merit    IG-136
RAD    IG-151
Attribute/name section (SPE)    IG-124
Bind (SPE)    IG-121
bind credentials (SPE)    IG-122
BindName (SPE)    IG-122
Bootstrap section (SPE)    IG-121
configuring
Merit    IG-142
SPE    IG-121
enabling
SPE    IG-116
file, sections (SPE)    IG-121
Request section (SPE)    IG-126
Response section (SPE)    IG-126
Search/name section (SPE)    IG-123
Server section (SPE)    IG-122
server/serverName section (SPE)    IG-123
Settings section (SPE)    IG-121
LDAP authentication plug-in    SS-111, SS-116
LDAP configuration
interface (SPE)    IG-128
RAD    IG-161
LDAP database (SPE)    IG-126
LDAP directory
Merit    IG-136, IG-142
SPE    IG-127
See also directory
LDAP features
Merit    IG-136
RAD    IG-151
LDAP host (SPE)    IG-116
LDAP libraries (SPE)    IG-117
LDAP Reader    IG-87
LDAP server
Merit    IG-138
SPE    IG-118, IG-121
LDAP Writer    IG-89
ldapauth.aut file (SPE)    IG-121
LDAPS
authentication and connection sequence    IG-75
cacerts files    IG-77
certificate files    IG-77
configuring
directory server    IG-76
overview    IG-76
SAE components    IG-78, IG-79
directory connections    IG-32
disabling connection for SAE components    IG-79
enabling connection for SAE components    IG-78
overview    IG-75
LDIF (LDAP Data Interchange Format) files    GS-15, IG-32, IG-41
leases for licenses. See license server
licchk command    GS-104
license
installing    GS-102
master    GS-103
obtaining    GS-96
pilot license
description    GS-96
installing    GS-97, GS-101-GS-103
server license    GS-111
configuration properties    GS-98
description    GS-96
installing    GS-97, GS-103
location    GS-113
types    GS-96
upgrading software    GS-103
verifying    GS-104
license manager, configuring SAE properties    GS-106
client properties    GS-109
directory access    GS-106
license server
accessing directory data    GS-118
alarms    GS-116
cleaning log files    GS-114
customizing    GS-106, GS-115-GS-121
errors    GS-112
general properties    GS-119
lease renewal    GS-113
license allocation    GS-113
license release    GS-113
license requests    GS-112
license switching    GS-114
location, configuring    GS-120
management commands    GS-105
SAE failover    GS-114
SNMP traps    GS-116
troubleshooting    GS-121
license string
SPE    IG-114, IG-116
Lightweight Data Interchange Format (LDIF) (Merit)    IG-145
Lightweight Directory Access Protocol. See LDAP
limit command    GS-73
limiting subscribers plug-in    SS-111, SS-112
listeners, defining    SS-283
load balancing (SPE)    IG-122
local configuration tool
description    GS-175
GUI elements    GS-176
local parameters    SP-114
configuring    SP-129-SP-131
parameter folder    SP-116
summary table    SP-130
types    SP-117
viewing in Policy Editor    SP-116
lock subtree and access control scheme    IG-101
log files
license server    GS-114
log filters, syntax    MT-11
log.txt log file (DirX)    IG-67
logging
accessing configuration    MT-4
cleaning log files    MT-12
filters, configuring    MT-10
installation session    GS-63, GS-64
JUNOS routing platforms    NG-96
JUNOSe routers    NG-63
properties
data integrators    IG-85
enterprise service portal    SS-314
redirect server    SS-231
solpkg.log    GS-64
solpkg_Uninstall.log    GS-76
system logging, configuring    MT-7
text files, configuring    MT-5
write access    MT-7
uninstallation session    GS-76
See also event messages
logging out
simulated subscriber sessions    MT-72
subscriber sessions    MT-64
login events, description    SS-10
login names    NG-181
login process
assigned IP subscribers, PCMM    SG-45
assigned IP subscribers, third-party devices    IG-6
enterprise    SS-26
event notification method, PCMM    SG-47
event notification method, third-party devices    IG-7
residential    SS-11
DHCP    SS-16-SS-21
PPP    SS-12-SS-14
See also logout process, residential
summary    SS-10
login registration
configuring    SS-41
deleting    MT-67
viewing on SAE    MT-67
LogLevel (SPE)    IG-122
logout process, residential
DHCP    SS-22
PPP    SS-15
See also login process
logs, Enterprise Service Portal audit plug-in    IG-82
loss priority actions    SP-106
configuring    SP-208

M

managing
unresponsive directories    GS-170
map expressions
application protocol conditions    SP-187
substitutions    SP-269
mark actions    SP-106
configuring    SP-209
master directory    GS-42
master license    GS-103
md5sum command    GS-75
menu bar, SDX Admin    GS-180-GS-182
Merit AAA server
Oracle Internet Directory integration, with    IG-49
Merit RADIUS    GS-33
Merit server
command syntax    IG-138, IG-148
testing    IG-148
meta agent    IG-67
Meta Data tab in SDX Admin    GS-186
metacontroller    IG-67
metadirectory store    IG-67
MIBs
Juniper Networks, list    MT-22
location    MT-23
monitoring with SNMP agent    MT-22
migration. See directory migration
modes, installation    GS-65
monitoring agent application    GS-35
monitors
configuring NIC    NG-177
multihop environment    SS-238
multimaster directory replication    NG-172
multiple classifiers, policies    SP-104
mutex group    SP-45
access control scheme    IG-103
adding    SP-45
adding to service scopes    SP-51

N

naming syntax    IG-33
NAT (Network Address Translation)
rules    SS-381
services for Enterprise Manager Portal    SS-256
services, IP address    SS-374, SS-376, SS-386
types    SS-377
VPNs    SS-270
See also NAT Address Management Portal
NAT (Network Address Translation) policies    SP-93
actions    SP-106
configuring    SP-210
application protocol condition
defining    SP-186
map expressions    SP-187
NAT Address Management Portal
acknowledging IP address release    SS-387
assigning IP addresses    SS-386
deployment settings    SS-299
Enterprise Manager Portal    SS-305
overview    SS-385
navigation pane, SDX Admin    GS-183
Net-SNMP master agent    GS-62, GS-123, MT-20
installing    GS-135
monitoring    GS-136
starting    GS-136
stopping    GS-136
supported    GS-62
using    GS-135
network address translation. See NAT
network and access control scheme    IG-102
network information collector. See NIC
network publisher. See NIC    NG-136
next-hop actions    SP-106
captive portal feature    SP-212
configuring    SP-212
next-interface actions    SP-106
configuring    SP-214
next-rule actions    SP-106
configuring    SP-216
NIC (network information collector)
API    NG-165
communities    NG-171, NG-174
data mapping    MT-84, NG-107
description    GS-13
enterprise service portals. with    SS-283
factory interface    NG-165, NG-166
IP address pool    SG-64, SG-107
IP address pools, syntax    NG-42
log files    MT-90, MT-91
logging configuration, accessing    MT-5
monitors    NG-171
configuring    NG-177
example    NG-257
starting    MT-88, NG-178
stopping    MT-88
network publisher
configuration file    NG-136
input directory    NG-142
output file    NG-142
overview    NG-136
prerequisites    NG-136
running    NG-141
troubleshooting    NG-141
overview    GS-13, NG-106
planning implementation    NG-111
realms
configuring    NG-196
overview    NG-182
viewing    MT-88
replication
configuring    NG-134
groups    NG-109, NG-120, NG-134
overview    NG-109
SAE plug-in agents    NG-131
resolution performance    NG-150
resolution processes    GS-13, NG-181, NG-182
resolvers
constraints    NG-185
managing    MT-83
overview    NG-109
viewing data mappings    MT-84
roles    NG-182
simulating resolutions    MT-89
starting    NG-178
testing    NG-156
troubleshooting resolution processes    MT-84
viewing
configuration    NG-228
host log    MT-90
host status    MT-82
monitor log    MT-90
monitor status    MT-88
See also other NIC entries
NIC agents
configuration overview    NG-123
configuring    NG-199
consolidator    NG-198, NG-199
directory    NG-194, NG-201
managing    MT-86
overview    NG-108
properties    NG-215, NG-216
router access    NG-205
SAE plug-in    NG-209, NG-211
XML    NG-218, NG-219, NG-225
See also other NIC entries
NIC configuration scenarios
changing    NG-134
Multipop    NG-259
OnePop    NG-228
OnePopAcctId    NG-243
OnePopAllRealms    NG-255
OnePopAssignedIp    NG-238
OnePopDnSharedIp    NG-251
OnePopDynamicIp    NG-234
OnePopLogin    NG-245
OnePopPcmm    NG-232
OnePopPrimaryUser    NG-249
OnePopSharedIp    NG-236
OnePopStaticRouteIp    NG-135, NG-241
overview    NG-112, NG-228
See also other NIC entries
NIC hosts
configuration prerequisites    NG-115
configuring    NG-117-NG-134, NG-223, NG-224
groups    NG-109, NG-120, NG-134
logging    NG-224
managing    MT-81
overview    NG-108
redundancy
configuring    NG-171-NG-179
configuring JacORB properties    NG-177
example    NG-255-NG-258
overview    NG-171
viewing configuration    MT-87
starting    NG-133
stopping    NG-133
See also other NIC entries
NIC locators
configuration    NG-225
external applications    NG-163, NG-164
overview    NG-106, NG-108
NIC proxies
cache    NG-150
configuration overview    NG-148
configuring    NG-148-NG-153
enterprise service portals    SS-314
instantiating    NG-168
JacORB    NG-154
logging    NG-167
monitoring    MT-91
optimizing performance    NG-179
ORB version    NG-154
overview    NG-107
prerequisites    NG-147
proxy stub    NG-159
removing instances    NG-170
replication    NG-146, NG-152, NG-158
requirements    NG-165
resetting MBeans    MT-91
resolution requests    NG-168
See also other NIC entries
NIC Web Admin
connecting to the directory    MT-79
deploying WAR file    MT-78
description    GS-20
managing hosts    MT-81
overview    MT-78
selecting NIC configuration scenario    MT-81
starting    MT-79
viewing NIC configuration    MT-81
See also other NIC entries
nicDump program    MT-84
non-real-time polling service.    SP-108
nonroot user vs. root user    GS-52
normal services. See value-added services
NRTPS (non-real-time polling service)    SP-108

O

object classes    IG-35-IG-39
object interdependence, SDX Admin    GS-190
object references, publishing    SG-148
objects
creating with SDX Configuration Editor    GS-199
exporting to directory    GS-199
importing into SDX Configuration Editor    GS-197
on-demand services    GS-4, GS-7
open interfaces    GS-8
OpenLDAP directory server
add-on package    GS-15
backing up directory    IG-72
cloning the directory server    GS-152
integration    GS-14
loading sample data    GS-81
monitoring    GS-80, GS-81, IG-72
restoring directory    IG-73
slave directories, migrating    GS-148
starting    GS-80, GS-81, IG-72
stopping    GS-80, GS-81, IG-72
using DES    GS-171
operating system requirements
Merit    IG-136
RAD    IG-150
SPE    IG-114
operators
activating access    IG-105
adding to directory    SS-163
control over all retailers    SS-144
LDAP model    SS-144
management privileges    SS-7, SS-143
subscribers and subscriptions    SS-6, SS-142
operators in substitution expressions    SP-270-SP-273
Oracle Internet Directory
add-on package    GS-15, IG-50
directory settings    IG-52
installing    IG-51
integrating with SDX software    IG-50-IG-52
integration    GS-14, GS-15
load script    IG-50, IG-52
loading sample data    IG-52
Merit AAA server, and    IG-49
password configuration    IG-50
ORB (object request broker), NIC proxy    NG-179
order, processes in data integrators    IG-86
OSM (object state manager)
extensible markup language (XML)    GS-31
OSS integration    GS-6
outsourced services    SP-4
adding    SP-6
configuring subscriptions    SS-168
retailer ISP, strategy (SPE)    IG-124

P

packet filtering, JUNOSe routers    SP-93
packet forwarding, JUNOSe routers    SP-93
packet loss priority. See loss priority actions
PacketCable Multimedia Specifications. See PCMM
PacketCable Multimedia. See PCMM
parameter value acquisition    SP-261-SP-274
example    SP-275
multiple subscriptions    SP-264
single subscriptions    SP-262
See also substitutions
parameters    SP-114
acquisition path and substitutions    SS-284
defining    SP-265
definition    SP-261
fixing    SP-262
global. See global parameters
local. See local parameters
ranking sources    SP-262
sample enterprise service portal    SS-397
subtree and access control scheme    IG-100
types    SP-117
See also substitutions
password, authentication credentials (SPE)    IG-130
PasswordCase (SPE)    IG-122
PasswordFormat (SPE)    IG-122
patches
installation    GS-57
J2SE    GS-57
Solaris    GS-57
PCIM (Policy Core Information Model)    IG-38
PCMM (PacketCable Multimedia)
application manager, role    SG-34
client type 1    SG-36
client type 2    SG-37
CMTS device, role    SG-34
configuring SAE    SG-49
creating sessions    SG-45
description    SG-34-SG-38
DOCSIS protocol    SG-35
end-to-end QoS architecture    SG-40
end-to-end services    SG-40
integrating SDX software    SG-33
IP service edge domain    SG-40
IP subscriber edge domain    SG-40
logging in subscribers
assigned IP method    SG-45
event notification method    SG-47
overview    SG-45
overview    SG-33
policy server, role    SG-34
provisioning end-to-end services    SG-41
record-keeping server    SG-34
RF domain    SG-33
SAE    SG-44
SAE communities    SG-48
SAE connection    NG-5
SDX software in
description    SG-39
traffic profiles    SG-39
service flows    SG-35
session store    SG-49
single-phase resource reservation model    SG-36, SG-37
videoconferencing example    SG-42
video-on-demand example    SG-43
PCMM device driver, configuring    SG-50
PCMM policies
classifiers    SP-111
client type 1 support    SP-109
conditions and actions supported    SP-103
DOCSIS parameters    SP-112
configuring    SP-195
extended classifiers    SP-111
configuring    SP-173
FlowSpec parameters    SP-112
configuring    SP-201
controlled load service    SP-113
guaranteed service    SP-113
request specification (RSpec)    SP-112
traffic specification (TSpec)    SP-112
gate    SP-110
gateSpec parameters, configuring    SP-206
I02 and I03 classifiers    SP-111
configuring    SP-173
marking packets    SP-114
proxied QoS with policy push    SP-110
service class name    SP-112
configuring    SP-234
service flow scheduling types    SP-108
SessionClassId    SP-110
traffic profiles    SP-112
PCMM record-keeping server plug-in
configuring    SG-55
description    SG-49
PDA (personal digital assistant) to display portal    GS-28
performance
enterprise service portals    SS-283
NIC proxy    NG-179
permanent service    SP-54
configuring    SP-54
permissions in access control lists    IG-96
pilot license. See license
pkgadd command    GS-75
pkgrm command    GS-76
pkgtrans command    GS-75
planning
data integration    IG-84
plug-ins
activating service sessions    SS-89
architecture    NG-6
audit plug-in, configuring    SS-318
authentication    SS-111
authorization    SP-66, SS-111
basic RADIUS accounting    SS-102
configuring    SS-107
basic RADIUS authentication    SS-111
configuring    SS-112
configuring with SDX Configuration Editor    SS-91
creating subscriber sessions    SS-88
custom RADIUS accounting    SS-102
configuring    SS-109
custom RADIUS authentication    SS-111
configuring    SS-114
defining RADIUS packets    SS-99, SS-126
DHCP address assignment    SS-86
embedded AdminServer authorization    SS-137
event publishers. See event publishers
external    NG-7
configuring in SAE property file    SS-98
configuring with SDX Configuration Editor    SS-94
CORBA object reference    SS-95
flat file accounting    SS-102
flexible RADIUS accounting    SS-102
configuring    SS-108
flexible RADIUS authentication    SS-111
configuring    SS-113
hosted    NG-7
how SAE uses    SS-86
instances, creating    SS-93
internal    NG-6, SS-84
authorization    SS-84
configuring in SAE property file    SS-98
configuring RADIUS peers    SS-125
configuring with SDX Configuration Editor    SS-93
customizing RADIUS packets    SS-86
how they work    SS-83
pool    SS-83
RADIUS attributes    SS-127
tracking    SS-85
LDAP authentication    SS-111, SS-116
limiting subscribers    SS-111, SS-112
listeners    SS-283
PCMM record-keeping server plug-in    SG-49
pool, accessing    SS-91
prepaid plug-in    SG-150
tracking
configuring    SS-101
configuring for virtual routers    NG-44, NG-73
list    SS-102
service sessions    SS-89
subscriber sessions    SS-88
types    NG-6
See also Enterprise Service Portal audit plug-in
point of presence. See POP
policer actions    SP-106
configuring    SP-217
policies
basic BoD    SS-260
BoD    SS-261
BoD and VPNs    SS-267
defining parameters in repository    SP-261
management    GS-7
NAT    SS-256
parameters    SS-286
storing and retrieving    SP-155
viewing on SAE    MT-58
policing policies
described    SP-92
example    SP-250
policy actions    SP-99
combining    SP-107
configuring    SP-193
DOCSIS    SP-105
configuring    SP-195
filter    SP-105
configuring    SP-200
FlowSpec    SP-105
configuring    SP-201
forward    SP-106
configuring    SP-204
forwarding class    SP-106
configuring    SP-205
gateSpec    SP-106
configuring    SP-206
loss priority    SP-106
configuring    SP-208
mark    SP-106
configuring    SP-209
NAT    SP-106
configuring    SP-210
next hop    SP-106
configuring    SP-212
next interface    SP-106
configuring    SP-214
next rule    SP-106
configuring    SP-216
policer    SP-106
configuring    SP-217
policy rules supported    SP-101
QoS profile attachment    SP-106
configuring    SP-219
rate limit    SP-106
configuring    SP-220
reject    SP-106
configuring    SP-225
routing instance    SP-106
configuring    SP-226
scheduler    SP-106
configuring    SP-227
service class name    SP-106
configuring    SP-234
stateful firewall    SP-106
configuring    SP-235
traffic class    SP-106
configuring    SP-236
traffic mirror    SP-107
configuring    SP-237
traffic-shape    SP-107
configuring    SP-239
types    SP-105
policy components    SP-97
policy decision point, description    SP-98
Policy Editor    SP-98
policy enforcement point, description    SP-99
policy engine    SP-98
policy repository    SP-98
policy conditions    SP-99
policy rules supported    SP-101
types    SP-104
See also classify-traffic condition; QoS condition
Policy Editor
accessing routers    NG-59, NG-92
concurrence control    SP-135
content pane    SP-152
copying objects    SP-148
customizing properties    SP-143
cutting objects    SP-147
data security    SP-135
deleting objects    SP-148
description    GS-17, SP-98
directory connection fields    SP-137
drag and drop    SP-147
exception handling in directory    SP-135
filtering searches    SP-145
finding objects    SP-146
icons, navigation pane    SP-142
internationalizing    SP-154
keys, customizing    SP-134
layout    SP-138
menu bar    SP-139
modifying policies    SP-147
multiple operators    SP-135
navigation pane    SP-141
nonroot users    SP-134
pasting objects    SP-148
pop-up menus    SP-149
printing policy objects    SP-144
redoing operations    SP-144
reloading objects    SP-149
sample window    GS-17
selecting multiple objects    SP-147
sorting policy objects    SP-155
starting    SP-137
storing and retrieving policies    SP-155
summary tables    SP-152
tool tips    SP-153
toolbar    SP-140
undoing operations    SP-144
policy engine    SP-98
policy examples
access policy    SP-243
premium service    SP-253
tiered Internet service    SP-247
policy folders
configuring    SP-160
described    SP-100
policy groups
configuring    SP-161
deleting from directory    SP-240
described    SP-100
purging from directory    SP-240
summary table    SP-163
policy list sharing    SP-96
policy lists
configuring    SP-164
described    SP-100
sharing    SP-96
summary table    SP-166
policy management    GS-16
policy objects
access control    IG-104
adding policy groups in directory    SP-240
modifying in directory    SP-240
organization    SP-100
policy overview
actions. See policy actions
collecting accounting statistics    SP-97
conditions. See classify-traffic condition; QoS condition
default policies. See default policies
installing policies on router    SP-94
network perspective diagram    SP-96
parameters. See parameters
policy object organization    SP-100
router features supported    SP-92
service policies. See service policies
sharing policies    SP-96
policy repository, description    SP-98
policy rules
actions supported    SP-101
conditions supported    SP-101
configuring    SP-167
described    SP-100
JUNOS Adaptive Services PIC (ASP). See JUNOS ASP policy rules
JUNOS filter. See JUNOS filter policy rules
JUNOS policer. See JUNOS policer policy rules
JUNOS scheduler. See JUNOS scheduler policy rules
JUNOS shaping. See JUNOS shaping policy rules
precedence, setting    SP-168
summary table    SP-170
types    SP-101
policy servers
adding application manager groups    SG-105
adding objects to directory    SG-109
role, in PCMM architecture    SG-34
specifying application managers    SG-105
specifying SAE communities    SG-105
policy subtree and access control scheme    IG-100
Policy Web Admin
connecting to directory    SG-19
description    GS-21
launching    SG-18
querying directory    SG-20
searching for QoS Policy data    SG-17
poolRepublish command
executing    NG-56
prerequisites    NG-55
troubleshooting    NG-58
variables    NG-57
POP (point of presence)
master directory and directory shadows    GS-42
port-number statement    NG-94
ports
SDX-related components    GS-83
UDP
Merit    IG-137
RAD    IG-152
SPE    IG-118
PPP
access policy example    SP-246
PPP subscribers
login process    SS-12-SS-14
logout process    SS-15
Web login    SS-12
precedence
policy rules    SP-168
subscriptions    SS-246
premium service, example    SP-253
Prepaid Account Administration application    GS-22, GS-27, SG-145, SG-151
accessing    SG-151
administering accounts    SG-152
configuring    SG-151
deploying WAR file    SG-151
prepaid plug-in configuration    SG-150
prepaid services demonstration application    GS-27, SG-145
account server    SG-146
components    SG-145
configuring    SG-147
configuring prepaid services    SG-150
installing    SG-147
interim update interval    SG-146
SAE configuration    SG-150
time-based prepaid services    SG-146
volume-based prepaid services    SG-146
preparation time, service schedules    SP-59, SP-65
prevention, use of unauthorized resources    SS-225
primary directory    GS-163
privileges
IT managers    SS-280
processors for data integration    IG-82
product features    GS-6-GS-8
project, creating in SDX Configuration Editor    GS-196
ProLDAP AATV
LDAP directory (Merit)    IG-137
Merit    IG-137
RAD    IG-152, IG-157, IG-158
server configuration (Merit)    IG-142
ProLDAP process (Merit)    IG-137
properties
processors in data integrators    IG-85
remote SAE properties    SS-315
subscriber information    SS-307, SS-312
WEB-INF/portalBehavior.properties    SS-193
property files
configuring SAE and directory attributes    GS-93
data integrators    IG-85
default.properties    GS-93
protocols
communication    SS-290
routing    SS-270
proxied QoS with policy push    SP-110
proxy HTTP    SS-227, SS-228
proxy request management    SS-227
public addresses, VPNs    SS-270
public wireless LAN applications    SS-238
publishing events    SG-123
Python installation prerequisite    GS-62

Q

QoS (quality of service)
classification and marking    SP-93
condition
configuring    SP-191
described    SP-104
PCMM cable networks. See PCMM policies
PCMM environments
description    SG-33
end-to-end QoS architecture    SG-40
extending to service edge domain    SG-41
extending to subscriber edge domain    SG-41
QoS profile attachment actions    SP-106
configuring    SP-219
QoS profile, configuring    SP-220
searching for policies in directory    SG-14, SG-17
QoS profiles, JUNOSe routers
how tracking works    SG-2
managing dynamically    SG-1-SG-7
updating directory, using
qosProfilePublish    SG-12
SDX Admin    SG-11
QoS profile-tracking plug-in
configuring    SG-7
description    SG-1
QoS tracking plug-in    SS-102
quality of service. See QoS

R

RADIUS
description    GS-33
first-time installations (SPE)    IG-114
master directory and directory shadows    GS-43
OSS integration    GS-6
previous installations (SPE)    IG-115
profiles and access control scheme    IG-99
server and equipment registration    SS-190
server compliant RFCs    GS-33
server with ISP service    SS-190
subscriber management    GS-7
vendor-specific attributes for wireless ISP
roaming    SG-23
versions supported    GS-57
See also Merit RADIUS; RAD-Series RADIUS Server; Steel-Belted Radius/SPE server
RADIUS accounting
Merit    IG-137
RADIUS attributes
defining in RADIUS plug-ins    SS-127
dictionary files
Merit    IG-139
RAD    IG-154
SPE    IG-119
examples, defining in RADIUS plug-ins    SS-132
incoming from Access-Request (SPE)    IG-126
values, Merit    IG-145
RADIUS authentication
Merit    IG-137
RAD    IG-157
SPE    IG-121
RADIUS client
configuration
Merit    IG-147
RAD    IG-164
SPE    IG-129
UDP ports
Merit    IG-137
RAD    IG-152
SPE    IG-117
vendor
Merit    IG-147
RAD    IG-163
RADIUS client library, custom RADIUS plug-ins    SS-86
RADIUS packets, customizing in plug-ins    SS-86
RADIUS peers, configuring in plug-ins    SS-125
RADIUS plug-ins
authentication    SS-111
UDP port    SS-124
See also plug-ins
RADIUS process    IG-114
Merit    IG-138
SPE    IG-115, IG-118
RADIUS profiles
configuring (Merit)    IG-145
Merit    IG-145
RAD    IG-161
RADIUS protocol, transaction-based (SPE)    IG-117
RADIUS server
configuring
Merit    IG-147
RAD    IG-163
SPE    IG-129
displaying status
Merit    IG-139
starting
Merit    IG-138
RAD    IG-153
SPE    IG-118
stopping
Merit    IG-139
RAD    IG-153
SPE    IG-118
testing installation (RAD)    IG-164
RADIUS services    SP-4
adding    SP-8-SP-17
and ERX VSA    SP-11, SP-15
configuring subscriptions    SS-174
VSAs (vendor-specific attributes),
configuring    SP-11-SP-17
RADIUS shared secret
Merit    IG-147
RAD    IG-163, IG-164
radius.ini file (SPE)    IG-118
RAD-Series RADIUS Server    GS-33
installation    IG-150
syntax description    IG-164
testing    IG-164
RAD-Series Server Manager    IG-153
RAM requirements
Merit    IG-136
RAD    IG-150
SPE    IG-114
RAS client, configuring (SPE)    IG-132
rate-limit actions    SP-106
configuring    SP-220
example    SP-248
rate-limiting, with multiple classifiers    SP-104
realm
administration (RAD)    IG-160
configuration file (SPE)    IG-128
syntax (Merit)    IG-143
See also NIC realms
realm name
authentication (RAD)    IG-157
description (RAD)    IG-158
directed authentication (SPE)    IG-127
real-time polling service. See RTPS
record-keeping server. See RKS
redirect server
configuring    SS-231
failover    SS-231
logging    SS-231
protection against denial-of-service attacks    SS-238
redundancy    SS-230, SS-231
redundancy
consolidated configuration, for    GS-47
directory    GS-163
redirect server    SS-230
references
draft RFCs    GS-210
non-RFC software standards    GS-210
RFCs    GS-209
URLs, third-party    GS-210
regional data centers, consolidated installation    GS-46
regionalized installation, SDX components    GS-44-GS-45
reject actions    SP-106
configuring    SP-225
reliability, distributed installation    GS-43
Request section, LDAP authentication (SPE)    IG-126
requirements, system    GS-54
residential portal
description    GS-28
developing    SS-186
directory eventing and failover    GS-15
overview    SS-185, SS-223
PDAs    GS-28
prerequisites for development    SS-223
RADIUS authentication for login    SS-191
security    SS-238
See also sample residential portal
residential subscribers    SS-3
adding to directory    SS-152
login process. See login process
resolution processes
DN to SAE reference    NG-251, NG-255, NG-263
IP address to login name    NG-245
IP address to SAE reference    NG-228, NG-236,
NG-238, NG-251, NG-255, NG-260
login name to SAE reference    NG-245
resource checking, after installation    GS-55
Response section, LDAP authentication (SPE)    IG-126
restoring
DirX directory database    IG-70
OpenLDAP directory database    IG-73
Sun ONE directory database    IG-60
retailer ISP
directed authentication    IG-127
realm name (SPE)    IG-127
retailers
access control    IG-102
subscribers    SS-3
adding to directory    SS-146
retrieving directory changes    GS-163
RFCs    GS-209, GS-210
RKS (record-keeping server)
peers, configuring in plug-ins    SG-59
plug-in    SG-49
configuring    SG-55
role in PCMM environment    SG-34
roaming wireless environment    SG-21-SG-28
roles
substitutions    SP-267
NIC    NG-182
root user vs. nonroot user    GS-52
round-robin method
Merit    IG-143
SPE    IG-122
router drivers
configuring
JUNOS router drivers    NG-75
JUNOSe router drivers    NG-46
viewing on SAE    MT-60
router initialization scripts
for third-party devices    IG-23
IorPublisher    NG-51
JUNOS    NG-89
configuring location for SAE    NG-91
example    NG-90
JUNOSe    NG-51
configuring location for SAE    NG-54
example    NG-53
poolPublisher    NG-51
specifying for NIC    NG-116
router subscribers    SS-4
adding to directory    SS-161
routers
accessing CLI    NG-59
adding JUNOS routing platforms    NG-66-NG-75
adding JUNOSe routers    NG-38-NG-46
integrating JUNOS routing platform    NG-66
integrating JUNOSe routers    NG-38
routing instance actions
configuring    SP-226
described    SP-106
routing instances    SS-266
routing instances, VPNs    SS-271
routing scheme    SS-270
RTPS (real-time polling service)    SP-109
configuring    SP-195
rules, NAT    SS-381

S

SAE (service activation engine)
accounting    NG-10
APIs. See APIs
BEEP connection, JUNOS routing platforms    NG-4
classification scripts. See classification scripts
configuring
NIC replication    NG-131
configuring as an application manager    SG-105
configuring for ACP    SG-121
COPS
JUNOSe router connection    NG-4
description    GS-8, GS-12
disabling interactions with JUNOS routing
platform    NG-95
enabling interactions with JUNOS routing
platform    NG-95
identifying    SS-281
idle timeout    SG-28
JUNOS routing platform client    NG-94
login events    SS-9
login process. See login process
logout process. See logout process
monitoring    GS-83
monitoring in cable network    SG-68
monitoring interactions
JUNOS routing platform    NG-95
JUNOSe routers    NG-62
overview    NG-3-NG-12
PCMM environment    NG-5, SG-44
plug-ins. See plug-ins
property file
configuring external plug-ins    SS-98
configuring internal and hosted plug-ins    SS-98
redundancy. See SAE communities
reloading configuration    MT-70
role    NG-3
router initialization scripts. See router initialization scripts
security properties    IG-78
session store    NG-25
starting    GS-82, GS-83
SDX client on JUNOSe router    NG-61
stopping    GS-83
SDX client on JUNOSe router    NG-62
viewing
configuration    MT-70
data    MT-54
SAE (service activation engine), configuring
accepting login names with different formats    SS-45
BEEP connection    NG-76
community manager    SG-53
COPS connection    NG-46
directory eventing, SAE configuration data    NG-24
event notification API properties    SG-54
interim accounting    SS-38
IPSec    SG-71
JUNOS routing platforms
simulated router driver    MT-15
LDAP access
directory data    NG-13
persistent login cache data    NG-21
persistent session cache repository    NG-24
policy data    NG-19
router data    NG-24
SAE cache repository    NG-24
service data    NG-17
subscriber data    NG-14
license manager    GS-106
client properties    GS-109
directory access    GS-106
loading subscriptions, RADIUS authorization    SS-44
login registration    SS-41
multiple logins from same IP address    SS-40
PCMM device driver    SG-50
property file
modifying with SDX Admin    SS-43
modifying with text editor    SS-44
router initialization script location    NG-54, NG-91
serialized data compression    NG-32
session job manager    NG-34
session reactivation timers    SS-42
session store    NG-27
SNMP communities    NG-49
unauthenticated user DN    SS-37
virtual portal address    SS-225
See also SAE (service activation engine)
SAE communities
configuring manager    SG-53
configuring manager, third-party devices    IG-18
defining members    SG-63
description    SG-48
description, third-party devices    IG-4
SAE remote interface
customized interface modules    NG-9
SAE Web Admin    MT-51
description    GS-22
logging out subscriber sessions    MT-64
reloading SAE configuration    MT-70
securing connections    MT-51
starting    MT-53
testing
classification scripts    MT-72
domain name parser scripts    MT-75
portals    MT-71
viewing
interfaces    MT-65
policies    MT-58
router drivers    MT-60
SAE configuration    MT-70
SAE data    MT-54
services    MT-56
SNMP information    MT-69
subscriber sessions    MT-62
threads    MT-68
sample data    IG-41
description    GS-15
loading    GS-81
DirX directory server    IG-67
eTrust Directory    IG-46
Oracle Internet Directory    IG-52
Sun ONE Directory Server    IG-59
sample data integrators    IG-90
sample enterprise service portal
configuring    SS-306-SS-316
configuring connection to directory    SS-297
customizing    SS-297
privileges    SS-280
data, displaying    SS-322
managing services    SS-391-SS-393
monitoring
service sessions    SS-395
subscriptions    SS-393
networks for departments    SS-396, SS-397
overview    SS-281
parameters    SS-397
service parameters    SS-394
sample residential portal
action classes    SS-188
behaviors    SS-188
customizing    SS-199
developing portal based on the sample    SS-239, SS-399
development tools    SS-224
equipment registration    SS-188, SS-190, SS-216
installing    SS-198
login    SS-202
model components    SS-188
overview    SS-201, SS-224
personal digital assistant (PDA)    SS-221
prerequisites    SS-198
schedules    SS-211
service activation    SS-210
services
management    SS-206
schedules    SS-211
subscriptions    SS-215
usage
information    SS-208
view components    SS-188
Web application framework    SS-187
scalability, distributed installation    GS-43
scheduleAuth plug-in    SP-66
scheduler actions    SP-106
configuring    SP-227
drop profile maps
configuring    SP-230
drop probability, setting    SP-232
fill level, setting    SP-232
schema, loading
DirX directory server    IG-64
OpenLDAP    GS-81
Oracle Internet Directory    IG-50
Sun ONE Directory Server    IG-57
scopes. See service scopes
script command    GS-64
script services    SP-38-SP-44
adding    SP-42-SP-44
example
ScriptService SPI in Java    SP-41
ScriptService SPI in Jython    SP-40
for third-party devices    IG-5
ScriptService interface    SP-39
scripts
generate (DirX)    IG-64
install.sh (SPE)    IG-115
load (eTrust Directory)    IG-43
load (OID)    IG-50, IG-52
load (Sun)    IG-58
setup.sh (eTrust Directory)    IG-44
vpndatamgt    IG-85
Workflow application    GS-30
SDX Admin
content pane    GS-186
data conversion to Unicode Transformation
Format-8    GS-191
deleting an entry    GS-189
description    GS-17
directory eventing and failure    GS-15
general operating procedures    GS-187
GUI panes example    GS-18
icons
navigation pane    GS-184
toolbar    GS-182
layout    GS-179
limitations    GS-190
menu bar    GS-180-GS-182
Meta Data tab    GS-186
modifying an entry    GS-188
navigation pane    GS-183
Options menu, configuration parameters    GS-181
pop-up menus    GS-187
redo    GS-188
save and revert command    GS-189
setting language    GS-191
starting    GS-178
text search    GS-190
toolbar    GS-182
undo    GS-188
virtual deletion of object    GS-189
SDX client, JUNOSe routers
configuring    NG-38
starting    NG-61
stopping    NG-62
SDX components
config command    GS-175
description    GS-9
diagram    GS-4
installation    GS-72
SDX Configuration Editor
configuration items
creating    GS-200
deleting    GS-200
description    GS-18, GS-193
directory connection    GS-195
editing level    GS-194
exporting objects to directory    GS-199
GUI elements    GS-200
importing objects from directory    GS-197
objects, creating    GS-199
project, creating    GS-196
starting    GS-194
using    GS-197-GS-200
SDX RADIUS client (Merit)    IG-145
SDX single-hop requirement    SS-238
SDX software
consolidated installation    GS-46
deployment scenarios    GS-39-GS-49
description    GS-3-GS-4
distributed installation    GS-41
documentation, locating    GS-161
features and benefits    GS-6-GS-8
financial advantages    GS-6
limits for system resources    GS-73
OSS integration    GS-6
regionalized installation    GS-44
removing    GS-76
services
description    GS-3
single-host installation    GS-48
SDX software process, JUNOS routing platforms    NG-66
disabling    NG-95
reenabling    NG-95
SDX Web Admin. See SAE Web Admin
Search requests (SPE)    IG-121, IG-126
Search/name section, LDAP authentication (SPE)    IG-123
secondary directory    GS-163
secure Web server certificates, SAE Web Admin    MT-51
security, residential portal    SS-238
sending traffic to VPNs    SS-350
serialized data compression, configuring    NG-32
server license. See license
Server Manager
password (RAD)    IG-151
user (RAD)    IG-151
Server section, LDAP authentication (SPE)    IG-122
server.csr file    MT-52, NG-80
Server/name, LDAP authentication (SPE)    IG-122
server/serverName section, LDAP authentication
(SPE)    IG-123
server-address statement    NG-94
service activation    SS-283
service activation engine. See SAE
service class name actions    SP-106
configuring    SP-234
Service Deployment System. See SDX software
service flow scheduling types    SP-108
service flows    SG-35
service objects, access control    IG-104
service parameters, enterprise    SS-284
service policies    SP-94
installing on router    SP-95
removing from router    SP-95
service providers
access control    IG-102
service schedules
action threshold    SP-59, SP-65
authorization schedules    SP-59, SP-66
changing    SP-76
configuring    SP-62, SP-67-SP-76
effective period    SP-61
Enterprise Manager Portal, in    SS-327-SS-334
event-based schedules    SP-58
examples    SP-77, SP-82, SP-88
exclusions    SP-63, SP-71, SP-73
guidelines    SP-63
one-time events    SP-62
overview    SP-57
planning    SP-64
preparation time    SP-59, SP-65
recurring events    SP-62
sample residential portal, in    SS-212
state-based schedules    SP-60
service scopes    SP-48
adding    SP-50
adding to mutex groups    SP-51
assigning
services    SP-51
subscribers    SP-48, SS-150
VRs    SP-48
configuring    SP-49
deleting    SP-56
example    SP-53
multiple scopes, defining    SP-49
service sessions
activate-on-login    SS-32, SS-89
activating and tracking    SS-89
activating with Web application    SS-27
enterprise, remote activation    SS-32
services    SP-4-SP-56
access. See access services
activate-only    SP-55
adding    SP-4
access    SP-5
aggregate    SP-31
infrastructure    SP-37
outsourced    SP-6
RADIUS    SP-8
script services    SP-42
value-added    SP-17, SP-18
aggregate. See aggregate services
assigning to service scopes    SP-51
automatic activation    SP-54
basic BoD    SS-258, SS-261
BoD    SS-262, SS-263, SS-334
configuring prepaid    SG-150
deleting    SP-55
scopes    SP-56
using SDX Admin    SP-56
using tools other than SDX Admin    SP-56
firewall. See firewall services
infrastructure. See infrastructure services
JUNOS routing platforms
BoD and VPNs    SS-267
NAT    SS-256
value-added services    SS-268
modifying    SP-55
mutually exclusive    SP-45
on demand    GS-7
outsourced. See outsourced services
premium service example    SP-253
RADIUS. See RADIUS services
restricting availability    SP-48
restricting simultaneous activation    SP-45
sample enterprise service portal, managing    SS-391
script. See script services
tiered Internet example    SP-247
time-based    SG-146
value-added. See value-added services
viewing on SAE    MT-56
voice over IP (VoIP)    SG-29
volume-based    SG-146
session job manager, configuring    NG-34
session store    NG-25
configuring
compressing session objects    NG-32
device driver    NG-27
global parameters    NG-31
in PCMM environment    SG-49
in third-party networks    IG-4
SessionClassId, PCMM policies    SP-110
Session-Timeout
Merit    IG-145
RAD    IG-162
Settings section, LDAP authentication (SPE)    IG-121
shaping rate. See traffic shaping
shared secret (RAD)    IG-151
silent installation file (Sun)    IG-56
silent installation mode    GS-65
simulated user profile    SS-202
single phase resource reservation model, PCMM    SG-36, SG-37
single-hop environment    SS-238
single-host installation    GS-48
sites    SS-5, SS-6
subscriber    SS-3
adding to directory    SS-159
SNMP
configuring
community for JUNOSe routers    NG-50
server on JUNOSe router    NG-49
SNMP agent
components    MT-27
adding    MT-29
deleting    MT-33
fields    MT-31
description    GS-23, GS-123
directory connection parameters, configuring    GS-124
hierarchy and objects    MT-25
how it works    MT-20
IOR file locations    MT-23
Java Runtime Environment, configuring    GS-132
logging
configuring    GS-126
severity levels    GS-126
master agent
commands    GS-135
SNMP versions    GS-135
master agent communication, configuring    GS-131
MIBs    MT-22
monitoring    GS-134
Net-SNMP master agent    GS-62, GS-123, MT-20
overview    MT-20-MT-25
starting    GS-134
stopping    GS-134
subagent to master agent    GS-123, MT-20
subfolders    MT-27
adding    MT-28
deleting    MT-28
system management configurations    MT-26
adding    MT-28
deleting    MT-29
trap history, configuring    GS-132
viewing data on SAE    MT-69
watchdog program, configuring    GS-132
See also SNMP traps
SNMP communities
configuring on SAE    NG-49
SNMP traps    MT-27
adding    MT-34
alarm state transitions    MT-49
deleting    MT-37
event traps
defined    MT-28
list and description    MT-48
pane in SDX Admin    MT-36
license server    GS-116
performance traps
accounting    MT-42
authentication    MT-43
defined    MT-27
NIC    MT-44
pane in SDX Admin    MT-35
policy engine    MT-47
router driver    MT-45
SAE    MT-41
SDX redirector    MT-47
system management    MT-47
workflow    MT-46
software
CD installation (SPE)    IG-114
software standards
draft RFCs    GS-210
non-RFC standards    GS-210
RFCs    GS-209
Solaris
packages    GS-72
transferring to other hosts    GS-75
patches    GS-57
Solaris packages
UMCppdemo    SG-145
source class usage (SCU)    SS-268
source-address statement    NG-94
SQL queries    IG-84
SSL (secure sockets layer)
secure SAE Web Admin connections    MT-51
See LDAPS
SSP services. See value-added services
sspServiceProfile and access control scheme    IG-98
standards
draft RFCs    GS-210
non-RFC software standards    GS-210
RFCs    GS-209
state synchronization plug-in interface
configuring with SDX Configuration Editor    SS-96
stateful firewall policies    SP-93
actions    SP-106
configuring    SP-235
application protocol conditions
defining    SP-186
map expressions    SP-187
static IP subscribers, login process    SS-23-SS-25
static routing    SS-270
Steel-Belted Radius/SPE server    GS-33
software requirements    IG-114
structure rules    IG-40
subfolders, managing in SDX Admin    GS-183
subscriber
management, description    GS-7
wireless environment    SG-22
subscriber classification scripts. See classification scripts
subscriber folders    SS-4
adding to directory    SS-150
subscriber sessions
activating with Web application    SS-28
creating and tracking    SS-88
deactivating with Web application    SS-30
enterprise, creating and activating    SS-26
logging out with SAE Web Admin    MT-64
viewing on SAE    MT-62
subscribers
access    SS-4
access control scheme    IG-102
adding to directory    SS-146-SS-162
billing    SS-268
directory connection properties    SS-307, SS-312
enterprise    SS-3
adding to directory    SS-156
inheriting properties    SS-145
inheriting subscriptions    SS-145
IP addresses    NG-181
LDAP model    SS-139
login names    NG-181
password encryption    SS-145
residential    SS-3
adding to directory    SS-152
retailer    SS-3
adding to directory    SS-146
router    SS-4
adding to directory    SS-161
service scopes, assigning    SS-150
sites    SS-3
adding to directory    SS-159
types    SS-3
subscriptions    SS-4, SS-140
access, configuring    SS-171
activating access for operators    IG-105
activation order, specifying    SS-141
hierarchy    SS-6
LDAP model    SS-141
multiple per subscriber    SS-168
outsourced services, configuring    SS-168
password encryption    SS-145
priority    SS-246
RADIUS, configuring    SS-174
sample enterprise service portal, creating    SS-391
value-added services, configuring    SS-165
substitutions
access    IG-106
aggregate services, configuring    SP-33
comments    SP-267
adding    SP-273
configuring    SP-25, SS-179
definition    SP-262
exceptions, raising    SP-268
expressions    SP-267-SP-273
IPv4 addresses    SP-269
keywords    SP-270
lists, formatting    SP-269
maps, formatting    SP-269
numbers, formatting    SP-268
operators    SP-270-SP-273
ranges    SP-269
separators    SP-270
strings, formatting    SP-269
subordinate expressions    SP-268
syntax    SP-268
formatting    SP-266-SP-273
map expressions    SP-269
mathematical expressions    SP-267-SP-273
parameter acquisition path    SS-284
roles    SP-267
sample enterprise portal    SS-397
types    SP-267
use    SS-285
validation    SP-274
See also parameters
sudo command    GS-52
Sun ONE Directory Server
access control    IG-109
add-on package    IG-56-IG-57
backing up directory    IG-60
cloning the directory server    GS-153
enterprise service portal    SS-291
installing    IG-58
integrating with SDX software    IG-57-IG-59
integration    GS-14, GS-15
load script    IG-58
loading sample data    IG-59
obtaining    IG-57
product description    IG-55
restarting    IG-60
restoring directory    IG-60
silent installation feature    IG-56
starting    IG-59
stopping    IG-59
superuser environment (DirX)    IG-69
syntax for directory entries    IG-33
sysconf command    GS-194
sysdef command    GS-73
syslog. See system logging
system logging    MT-3, MT-7
See also logging; event messages
system management    MT-20
access control scheme    IG-101
See also SNMP agent
system requirements    GS-54
Merit    IG-136
RAD    IG-150
SPE    IG-114
system resources, SDX processes    GS-73

T

TargetNumber (SPE)    IG-123
targets. See classification scripts
tariff models    GS-7
tee command    GS-64
test script (Merit)    IG-148
test user password (RAD)    IG-151
testing
components that use NIC    NG-156
domain name parser scripts    MT-75
interface classification scripts    MT-74
portals    MT-71
subscriber classification scripts    MT-73
third-party devices
creating sessions    IG-5
integrating into SDX network    IG-3-IG-26
logging in subscribers
assigned IP method    IG-6
event notification method    IG-7
overview    IG-5
provisioning with script services    IG-5
SAE communities    IG-4
VR objects, adding    IG-12
third-party URLs    GS-210
threads
configuring for COPS    NG-49
configuring for sessions    NG-34
tiered Internet service, example    SP-247
Tomcat installation (RAD)    IG-150
Tomcat, as Java development environment    SS-239, SS-399
toolbar, SDX Admin    GS-182
tracking plug-ins    SS-85
configuring    SS-101
configuring for virtual routers    NG-44, NG-73
traffic mirror actions    SP-107
configuring    SP-237
traffic mirroring
administration    GS-23
application    GS-29
policies, configuring    SP-237
traffic profiles
PCMM    SG-39
PCMM policies    SP-112
traffic shaping
actions    SP-107
configuring    SP-239
policy rules    SP-101
traffic-class actions    SP-106
configuring    SP-236
traffic-class profile, setting    SP-237
transaction-based RADIUS protocol
Merit    IG-137
RAD    IG-152
SPE    IG-117
transferring
data to directory    IG-81
translation, file format    GS-75
traps. See SNMP traps
troubleshooting
JUNOS routing platforms    NG-96
JUNOSe routers    NG-63
poolRepublish command    NG-58
with log files    MT-3

U

UDP ports
changing default
Merit    IG-137
RAD    IG-152, IG-154
Merit    IG-137
RAD    IG-152, IG-164
RADIUS client
Merit    IG-147
SPE    IG-129
RADIUS plug-ins    SS-124
SPE    IG-117, IG-118
UGS (unsolicited grant service)    SP-109
configuring    SP-195
UGS-AD (unsolicited grant service with activity
detection)    SP-109
configuring    SP-195
uid-uniqueness plug-in (Sun)    IG-56
ulimit command    GS-73
UmcConfiguration and access controls    IG-98
UMCppdemo Solaris package    SG-145
umcRadius Person and access control scheme    IG-99
umcUser and access control scheme    IG-99
Unicode Transformation Format-8
localization in SDX Admin    GS-191
uninstall command    GS-76
uninstallation
description    GS-76
logging session    GS-76
unique user IDs, SDX Admin    GS-190
Unisphere VSA, updating (RAD)    IG-155
UNIX password checking (Merit)    IG-136
unsolicited grant service. See UGS
unsolicited grant with activity detection. See UGS-AD
upgrade license requirements    GS-103
UpperCaseName (SPE)    IG-122
usage
data    GS-8
user class in access control lists    IG-96
User Datagram Protocol. See UDP
user password, specifying (Merit)    IG-148
user subtree and access control scheme    IG-104
username, authentication credentials (SPE)    IG-130
users, authorized    GS-52

V

validating
substitutions    SP-274
VPNs    SS-275
value acquisition for parameters
multiple subscriptions    SP-264
single subscriptions    SP-262
value consistency, SDX Admin    GS-190
value substitution    SS-286
value-added services    SP-4
adding    SP-17
aggregate services    SP-28-SP-37
fragment services    SP-28
prerequisites    SP-28
session    SP-29
infrastructure services    SP-37-SP-38
normal services    SP-17-SP-23
script services    SP-42-SP-44
subscriptions
configuring    SS-165
types    SP-17
variables.tcl file (DirX)    IG-64
vendor files
Merit    IG-142
RAD    IG-157
SPE    IG-117
vendor-specific attributes
Merit    IG-142
RAD    IG-157
vendor-specific attributes. See VSAs
verifyInst command    GS-55
virtual deletion, SDX Admin    GS-189
virtual portal address    SS-225
configuring    SS-225
virtual private networks. See VPNs
virtual routers
adding for third-party devices    IG-12
adding individually for JUNOS routing
platforms    NG-70-NG-75
adding individually for JUNOSe routers    NG-41-NG-46
adding operative VRs    NG-38
updating IP address pools. See IP address pools    NG-55
VPN Subscription Deactivator    IG-92, SS-275
vpndatamgt script    IG-85
VPNs (virtual private networks)    SS-270
adding
data integrator    IG-90, SS-270
SDX Admin    SS-271
definition    SS-269
deleting    SS-276
directory    SS-347
exporting    SS-273
extranet clients
adding    SS-273
removing    SS-275
identifiers    SS-266
invalid subscriptions    SS-275
modifying    SS-272, SS-347
VPN to which router sends traffic    SS-350
routing schemes    SS-270
sending traffic    SS-350
stopping router from sending traffic    SS-351
using NAT    SS-270
validating    SS-275
VSAs (vendor-specific attributes)
configuring for services    SP-11-SP-17

W

WAR files    GS-137
Web Admin applications    SG-145, SG-151
Web applications
installing    GS-137
removing    GS-139
Web-based interfaces
SAE Web Admin    MT-51
WEB-INF/jboss-web.xml    SS-192
WEB-INF/portalBehavior.properties    SS-192
WEB-INF/struts-config.xml    SS-192, SS-195
WEB-INF/tiles-defs.xml    SS-192, SS-197
WEB-INF/web.xml    SS-192
wholesale-retail model
description    GS-6
SDX system architecture    GS-6
wireless environment    SG-21-SG-28
Workflow application
description    GS-6, GS-30
elements in directory    IG-39
e-mail send/receive protocols    GS-31
HTTP    GS-31
Java API    GS-30
scripts and external programs    GS-30
workflow subtree and access control scheme    IG-103

X

XML documents    IG-82
XML File Reader    IG-88
XML File Writer    IG-89
XSLT files    IG-84
XSLT transformers    IG-82
X-Windows access    GS-57

GS: Getting Started Guide; IG: Integration Guide; MT: Monitoring and Troubleshooting Guide;
NG: Network Guide; SG: Solutions Guide; SP: Services and Policies Guide; SS: Subscribers and Subscriptions Guide