Guidelines for Configuring Subscriber Secure Policy Mirroring on the RADIUS-Flow-Tap Service
The subscriber secure policy service runs on the radius-flow-tap service infrastructure. When configuring subscriber secure policy mirroring, consider the following guidelines regarding the relationship between subscriber secure policy service and the radius-flow-tap service:
- Subscriber secure policy inherits the limitations of the flow-tap service. For example, the radius-flow-tap service and the flow-tap service cannot run simultaneously on the router. Therefore, port mirroring and subscriber secure policy mirroring cannot run simultaneously on the same router.
- You can configure one instance of the radius-flow-tap service on the router. Both subscriber secure policy RADIUS-initiated mirroring and DTCP-initiated mirroring use the radius-flow-tap service.
- If you configure both RADIUS-initiated mirroring and DTCP-initiated mirroring, and the two mirroring requests are the same, duplicate mirrored traffic is sent to the mediation device.
- You cannot delete the radius-flow-tap service configuration while a subscriber secure policy mirroring session is active on the service.
Hide Navigation Pane
Show Navigation Pane
Download
SHA1