Qualifications For Change Of Authorization; Security/Authentication - Juniper JUNOSE SOFTWARE 11.2.X - BROADBAND ACCESS CONFIGURATION GUIDE 7-20-2010 Configuration Manual

Software for e series broadband services routers broadband access configuration guide
Table of Contents

Advertisement

Qualifications for Change of Authorization

Security/Authentication

Copyright © 2010, Juniper Networks, Inc.
Table 46: Error-Cause Codes (RADIUS Attribute 101) (continued)
Code
Value
504
Session context not
removable
506
Resources
unavailable
To complete the change of authorization for a user, the CoA-Request must contain one
of the following RADIUS attributes or pairs of attributes. AAA services handle the actual
request.
User-Name [attribute 1] with Virtual-Router [attribute 26–1] to identify the user per
virtual router context
Framed-IP-Address [attribute 8] with Virtual-Router [attribute 26–1] to identify the
address per virtual router context
Calling-Station-ID [attribute 31]
Acct-Session-ID [attribute 44] (mandatory for all CoA requests, except when the
request is for packet mirroring)
Nas-Port-ID [attribute 5]
DHCP-Option-82 [attribute 26–159], Vendor ID 4874
Agent-Circuit-ID [attribute 26–1], Vendor ID 3561
Agent-Remote-ID [attribute 26–2], Vendor ID 3561
NOTE: The Calling-Station-ID attribute is valid only for the tunneled subscribers and
on the LNS. Additionally, the Calling-Station-ID and Nas-Port-ID attributes are valid
only if there is no RADIUS override setting.
For change-of-authorization operations, the RADIUS server calculates the authenticator
as specified for an Accounting-Request message in RFC 2866. The RADIUS
dynamic-request server verifies the request using authenticator calculation as specified
for an Accounting-Request in RFC 2866. A key (secret), as specified in RFC 2865, must
be configured and used in the calculation of the authenticator. The response authenticator
is calculated as specified for an Accounting-Response message in RFC 2866.
Chapter 4: Configuring RADIUS Dynamic-Request Server
Description
The subscriber identified by attributes in the disconnect request
is owned by a component that does not support RADIUS-initiated
disconnect (for example, IP LAC subscribers cannot be
disconnected).
A request could not be honored due to lack of available NAS
resources (such as memory).
237

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.2

Table of Contents