Manual Chapter : Configuring Policy and RADIUS Updates

Applies To:

Show Versions Show Versions


  • 11.5.10, 11.5.9, 11.5.8, 11.5.7, 11.5.6, 11.5.5, 11.5.4, 11.5.3, 11.5.2, 11.5.1
Manual Chapter

Overview: Configuring policy and RADIUS updates

Policy Enforcement Manager (PEM) enables you to schedule policy reevaluations and radius updates on the BIG-IP system in the following two ways:

  • You can change policies for a subscriber session over a period of time. You can also configure the interval for reevaluation of policies, for a subscriber session, by configuring the re-evaluation interval. The BIG-IP system evaluates changes in the policy for traffic, once the re-evaluation interval is configured.
  • The RADIUS traffic contains the subscriber and IP address information that is monitored by the BIG-IP system. If you enable the timeout interval, the BIG-IP system avoids repeated deletion and creation of the subscriber during the configured interval rate.

Configuring PEM options

You can set up the BIG-IP system to schedule an interval that sets policy reevaluation and RADIUS re-transmission updates periodically.
  1. On the Main tab, click Policy Enforcement > Options. The Options screen opens.
  2. In the Policy Options area, specify (in seconds) the Policy Re-evaluation Interval at which the policy re-evaluation is triggered, to evaluate the flow policy again. The re-valuation interval is only for active flows. For example, a subscriber is provisioned over GX which has a policy to allow Netflix with some bandwidth. The subscriber is able to watch a movie using the Netflix service. However, consider that the PCRF installs a policy for this subscriber to block Netflix over the Gx interface. Then, while the subscriber is viewing the content, the Netflix content is blocked for the subscriber after the configured re-evaluation interval.
  3. In the RADIUS Options area, for the Re-Transmit Timeout setting, select Enabled and specify the time in seconds. If you select Disabled, each RADIUS message is handled as a new message and this might lead to deletion and creation of sessions even though the radius massage is a duplicate. This is the timeout after which the RADIUS message is considered as a new message, by the BIG-IP system.
The policy and RADIUS updates take effect immediately.