Case Study

CSP D – TIER 1 EUROPEAN MOBILE OPERATOR

RADIUS-as-a-Service for Mobile IP Enterprise VPN

CSP D, a leading Tier 1 European mobile operator, deployed the Enea AAA Server as a dedicated 3GPP AAA to support its Enterprise IP VPN RADIUS service. This solution—branded internally as RADIUS-as-a-Service (RaaS)—is embedded within their Mobile IP Enterprise VPN offering, allowing enterprise customers to securely access their private corporate networks directly from the CSP D mobile network.

Explore seven additional case studies by downloading the full Why Intellegent AAA is the Swiss Army Knife of Telecom paper below. You can also go here to learn more about the Enea AAA Server.

RADIUS as a Service for Mobile IP Enterprise VPN

The Challenge OL
Specialized High-End Enterprise Requirements

While CSP D’s existing Enea AAA infrastructure was optimized for consumer and mass-market enterprise services, the high-end enterprise segment required more granular control. Key requirements included:

  • Secure, direct access to private customer networks.
  • Self-management capabilities for both static and dynamic IP address assignment.
  • Specialized accounting handling to support VPN RADIUS session keepalives.

The Solution OL
Dedicated AAA Instance for Mobile IP Enterprise VPN

To meet these demands, CSP D implemented a dedicated Enea AAA Server instance tailored for RaaS. This instance provides robust access control, advanced IP Address Management (IPAM), and specialized accounting, ensuring enterprise subscribers maintain secure and persistent connections to their private networks.

CSP D Mobile IP VPN Architecture OL

The architecture comprises three core elements:

  • Business Service Portal (BSP): Provides the user interface for managing access control policies and IP configuration data.
  • Common Nokia NT Subscriber Database (cNTDB): Serves as the persistent repository for all subscriber-related data.
  • Enea AAA Server: Functions as the 3GPP AAA, executing the access control and IP configuration logic.

The solution integrates with the mobile packet core via the RADIUS protocol and leverages Private APNs to facilitate secure enterprise network access.

RADIUS Service Separation

CSP D Separation RADIUS Traffic

To ensure isolation and performance, a separate RADIUS service instance was introduced within the Enea AAA Server framework. This architectural separation allows the Mobile IP VPN traffic to be managed independently from mass-market traffic, ensuring excellent user experience for mission-critical enterprise sessions.

Service Capabilities

The Enea AAA Server Mobile IP VPN instance supports the following technical requirements:

1 – Access Control
  • Support for both PAP and CHAP authentication protocols.
2 – IP Address Management (IPAM)
  • Dynamic IP Assignment: IP pool selection is determined by a combination of the (alias) APN, Realm, and the (alias) PGW IP address. The system supports IPv4, IPv6, and dual-stack IPv4v6 pools.
  • Static IP Assignment: Supports IPv4, IPv6, and IPv4v6 addresses provisioned directly within the cNTDB.
  • DNS Management: Automated assignment of DNS server addresses.
3 – Accounting
  • Processing of RADIUS Start, Interim, and Stop messages to support VPN session keepalives and auditing.

High-Level Call Flow

CSP D Call Flow

The Enea AAA Server processes Mobile IP Enterprise VPN access requests through a two-step logic engine:

  • Access Control: The system first validates the subscriber’s credentials to grant or deny access to the private customer network.
  • IP Address Allocation: Once access is granted, the Enea AAA evaluates the incoming RADIUS Access-Request attributes, PDP context, and cNTDB data to apply the appropriate static or dynamic IP assignment logic.

Additionally, the Enea AAA manages RADIUS Accounting messages throughout the session to maintain keepalive status, ensuring the VPN tunnel remains active and monitored.