![]() |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
RADIUS Vendor-Specific Attributes and RADIUS Disconnect-Cause Attribute Values
![]() |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Contents
RADIUS Vendor-Specific Attributes and RADIUS Disconnect-Cause Attribute ValuesLast Updated: July 01, 2011
The Internet Engineering Task Force (IETF) draft standard specifies a method for communicating vendor-specific information between the network access server and the RADIUS server by using the vendor-specific attribute (attribute 26). Attribute 26 encapsulates vendor specific attributes (VSA), thereby, allowing vendors to support their own extended attributes otherwise not suitable for general use. Finding Feature InformationYour software release may not support all the features documented in this module. For the latest feature information and caveats, see the release notes for your platform and software release. To find information about the features documented in this module, and to see a list of the releases in which each feature is supported, see the Feature Information Table at the end of this document. Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required. Information About RADIUS Vendor-Specific Attributes and RADIUS Disconnect-Cause Attribute ValuesThe Cisco RADIUS implementation supports one vendor-specific option using the format recommended in the specification. Ciscoâs vendor-ID is 9, and the supported option has vendor-type 1, which is named âcisco-avpair.â The value is a string of the following format: protocol : attribute sep value * âProtocolâ is a value of the Cisco âprotocolâ attribute for a particular type of authorization; protocols that can be used include IP, IPX, VPDN, VOIP, SHELL, RSVP, SIP, AIRNET, OUTBOUND. âAttributeâ and âvalueâ are an appropriate attribute-value (AV) pair defined in the Cisco TACACS+ specification, and âsepâ is â=â for mandatory attributes and â*â for optional attributes. This allows the full set of features available for TACACS+ authorization to also be used for RADIUS. For example, the following AV pair causes Ciscoâs âmultiple named ip address poolsâ feature to be activated during IP authorization (during PPPâs IPCP address assignment): cisco-avpair= âip:addr-pool=firstâ If you insert an â*â, the AV pair âip:addr-pool=firstâ becomes optional. Note that any AV pair can be made optional. cisco-avpair= âip:addr-pool*firstâ The following example shows how to cause a user logging in from a network access server to have immediate access to EXEC commands: cisco-avpair= âshell:priv-lvl=15â Attribute 26 contains the following three elements: The figure below shows the packet format for a VSA encapsulated âbehindâ attribute 26.
The table below describes significant fields listed in the Vendor-Specific RADIUS IETF Attributes table (second table below), which lists supported vendor-specific RADIUS attributes (IETF attribute 26).
For more information on configuring your NAS to recognize and use VSAs, refer to the âConfiguring Router to Use Vendor-Specific RADIUS Attributesâ section of th e â Configuring RADIUS â module. RADIUS Disconnect-Cause Attribute ValuesDisconnect-cause attribute values specify the reason a connection was taken offline. The attribute values are sent in Accounting request packets. These values are sent at the end of a session, even if the session fails to be authenticated. If the session is not authenticated, the attribute can cause stop records to be generated without first generating start records. The table below lists the cause codes, values, and descriptions for the Disconnect-Cause (195) attribute.
For Q.850 cause codes and descriptions, see the Cisco IOS Voice Troubleshooting and Monitoring Guide , Release 12.4T. Additional ReferencesThe following sections provide references related to RADIUS Vendor-Specific Attributes (VSA) and RADIUS Disconnect-Cause Attribute Values. Standards
MIBsTechnical Assistance
Feature Information for RADIUS Vendor-Specific Attributes and RADIUS Disconnect-Cause Attribute ValuesThe following table provides release information about the feature or features described in this module. This table lists only the software release that introduced support for a given feature in a given software release train. Unless noted otherwise, subsequent releases of that software release train also support that feature. Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Cisco and the Cisco Logo are trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and other countries. A listing of Cisco's trademarks can be found at www.cisco.com/go/trademarks. Third party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1005R) Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||