The ingress and egress IP and IPv6 filter policies can be overridden per subscriber host or session at creation time or mid-session:
from RADIUS by including the [26.6527.134] Alc-Subscriber-Filter attribute in an Access-Accept or CoA message.
from Diameter Gx by including the Charging-Rule-Name AVP with corresponding predefined name in a CCA or RAR message.
Notes:
Irrelevant fields (for example, IPv4 filters for an IPv6 host) are ignored.
RADIUS CoA message: if the ingress or egress field is missing in the VSA, there is no change for that direction.
RADIUS Access-Accept message: if the ingress or egress field is missing in the VSA, then the IP filters as specified in the SLA profile are active for that direction.
An SLA profile IP filter override is applicable to all dynamic host types, including L2TP LNS but excluding L2TP LAC.