Qualifications For Change Of Authorization; Security/Authentication; Configuring Radius-Initiated Change Of Authorization - Juniper JUNOSE 11.1.X - BROADBAND ACCESS CONFIGURATION GUIDE 6-4-2010 Configuration Manual

For e series broadband services routers - broadband access
Table of Contents

Advertisement

Qualifications for Change of Authorization

To complete the change of authorization for a user, the CoA-Request must contain
one of the following RADIUS attributes or pairs of attributes. AAA services handle
the actual request.
NOTE: The Calling-Station-ID attribute is valid only for the tunneled subscribers and
on the LNS. Additionally, the Calling-Station-ID and Nas-Port-ID attributes are valid
only if there is no RADIUS override setting.

Security/Authentication

For change-of-authorization operations, the RADIUS server calculates the authenticator
as specified for an Accounting-Request message in RFC 2866. The RADIUS
dynamic-request server verifies the request using authenticator calculation as specified
for an Accounting-Request in RFC 2866. A key (secret), as specified in RFC 2865,
must be configured and used in the calculation of the authenticator. The response
authenticator is calculated as specified for an Accounting-Response message in RFC
2866.

Configuring RADIUS-Initiated Change of Authorization

To configure the RADIUS dynamic-request change of authorization feature, perform
the following steps to set up the RADIUS dynamic-request server that will perform
the CoA operation:
1.
2.
User-Name [attribute 1] with Virtual-Router [attribute 26–1] to identify the user
per virtual router context
Framed-IP-Address [attribute 8] with Virtual-Router [attribute 26–1] to identify
the address per virtual router context
Calling-Station-ID [attribute 31]
Acct-Session-ID [attribute 44] (mandatory for all CoA requests, except when the
request is for packet mirroring)
Nas-Port-ID [attribute 5]
DHCP-Option-82 [attribute 26–159], Vendor ID 4874
Agent-Circuit-ID [attribute 26–1], Vendor ID 3561
Agent-Remote-ID [attribute 26–2], Vendor ID 3561
Configure the RADIUS dynamic-request server, and enter RADIUS Configuration
mode.
host1(config)#radius dynamic-request server 10.10.5.10
Enable the CoA capability on the RADIUS dynamic-request server.
host1(config-radius)#authorization change
Chapter 4: Configuring RADIUS Dynamic-Request Server
Configuring RADIUS-Initiated Change of Authorization
247

Advertisement

Table of Contents
loading

Table of Contents