|
|
|
|
|
- Name of user to be authenticated
- Configurable username override
|
|
|
- Password of user to be authenticated
- Configurable password override
- PAP (Password Authentication Protocol)
|
|
|
Response value provided by a PPP Challenge Handshake Authorization Protocol (CHAP) user in the response to an access challenge |
|
|
|
|
|
|
|
|
- Type of service the user has requested or the type of service to be provided
- Admin, Login, NAS Prompt, or Framed only
|
|
|
- Framing protocol used for framed access
- Standard value of 1 set for PPP
|
|
|
|
|
|
- IP network to be configured for the user when the user is a router to a network
- Absence implies 255.255.255.255
|
|
|
- Name of the filter list for the user
- Interpreted as input policy name
|
|
|
|
|
|
- Text that may be displayed to the user
- Only the first instance of this attribute is used
|
|
|
Provides routing information to be configured for the user on the NAS |
|
|
- An arbitrary value that the ERX includes in new Access-Request packets from the previous Accept-Challenge
- Applicable for CLI/telnet only
|
|
|
An arbitrary value that the NAS includes in all accounting packets for the user if supplied by the RADIUS server |
|
|
Juniper Networks Enterprise number 0x0000130A |
|
|
- Virtual router name for the B-RAS user's IP interface
- Allowed only from RADIUS server in default virtual router context
- For restricted users, specifies the only VR that the user may access.
- For nonrestricted users, specifies the initial VR that the user accesses.
- See the enable command in ERX System Basics Configuration Guide, Chapter 6, Passwords and Security.
|
|
|
- Name of an assigned address pool that should be used to assign an address for the user
- Same as RADIUS attribute 88, Framed-Pool
|
|
|
Interface to apply to the ERX side of the connection |
|
|
- B-RAS user's DNS address negotiated during IPCP
- 4-octet IP address
|
|
|
- B-RAS user's DNS address negotiated during IPCP
- 4-octet IP address
|
|
|
- B-RAS user's WINS (NBNS) address negotiated during IPCP
- 4-octet IP address
|
|
|
- B-RAS user's WINS (NBNS) address negotiated during IPCP
- 4-octet IP address
|
|
|
Virtual router name for tunnel connection |
|
|
Tunnel password in cleartext |
|
|
Input policy name to apply to B-RAS user's interface |
|
|
Output policy name to apply to B-RAS user's interface |
|
|
Enable or disable input statistics on B-RAS user's interface |
|
|
Enable or disable output statistics on B-RAS user's interface |
|
|
ATM service category to apply to B-RAS user's interface |
|
|
- Peak cell rate
- 4-octet integer
|
|
|
- Sustained cell rate or CBR, depending on the Atm-Service-Category RADIUS attribute [26-14]
- 4-octet integer
|
|
|
- Maximum burst rate
- 4-octet integer
|
|
Juniper-Initial-CLI-Access-Level |
- Specifies the initial level of access to CLI commands
- See the enable command in ERX System Basics Configuration Guide, Chapter 6, Passwords and Security.
|
|
Juniper-Allow-All-VR-Access |
- Specifies user access to all virtual routers
- See the enable command in ERX System Basics Configuration Guide, Chapter 6, Passwords and Security.
|
|
Juniper-Alt-CLI-Access-Level |
- Specifies other levels of access to CLI commands
- See the enable command in ERX System Basics Configuration Guide, Chapter 6, Passwords and Security.
|
|
Juniper-Alt-CLI-Virtual-Router- Name |
- For restricted users, specifies other VRs that the user may access.
- See the enable command in ERX System Basics Configuration Guide, Chapter 6, Passwords and Security.
|
|
|
- Enable or disable source address validation on a user's interface
- 4-octet integer
|
|
|
- Enable or disable IGMP on a user's interface
- Allows the end user to register for the reception of multicast services
- 4-octet integer
|
|
|
The string pppoe <mac addr> sent to the RADIUS server supplied by PPPoE |
|
|
- Virtual router name indicating the VR context in which to authenticate the user
- Behavior is similar to that of a remote domain-map lookup.
|
|
|
Name of the QoS profile to attach to the user's interface |
|
|
Specifies the SSC service bundle |
|
|
Route tag to apply to returned framed-ip-address |
|
|
Number of times input-packets attribute rolls over its 4-octet field |
|
|
Number of times output-packets attribute rolls over its 4-octet field |
|
|
Maximum number of seconds of service to be provided to the user before termination of the session |
|
|
Maximum number of consecutive seconds of idle connection allowed to the user before termination of the session |
|
|
- Allows the NAS to send the phone number that the user called
- Not supported for non tunneled or LAC session side.
- For the LNS (L2TP), the format is the string passed in the Called Number AVP.
|
|
|
- Allows the NAS to send the phone number from which the call originated
- See the radius calling-station-format and the radius calling-station-delimiter commands in Chapter 2, Configuring RADIUS Attributes.
|
|
|
- Identifies the NAS originating the request
- System-wide configurable hostname or VR-sensitive configurable NAS-identifier name
|
|
|
Indicates whether this Accounting-Request marks the beginning of the user service (Start), the end (Stop), or the interim (Interim-Update) |
|
|
Indicates how many seconds the client has been trying to send a particular record |
|
|
- Indicates how many octets have been received from the port during the time this service has been provided
- PPP payload only
|
|
|
- Indicates how many octets have been sent to the port during the time this service has been provided
- PPP payload only
|
|
|
- Unique accounting identifier that makes it easy to match start and stop records in a log file
- See the radius acct-session-id-format and the radius include acct-session-id access-request commands in Chapter 2, Configuring RADIUS Attributes.
|
|
|
- Indicates how the user was authenticated, whether by RADIUS, the NAS itself, or another remote authentication protocol
- Always 1
|
|
|
Indicates how long in seconds that the user has received service |
|
|
- Indicates how many packets have been received from the port during the time this service has been provided to a framed user
- PPP payload only
|
|
|
- Indicates how many packets have been sent to the port in the course of delivering this service to a framed user
- PPP payload only
|
|
|
Contains the reason the service (a PPP session) was terminated. The service can be terminated for the following reasons:
- User Request (1) - user initiated the disconnect (log out)
- Idle Timeout (4) - idle timer has expired
- Session Timeout (5) - client reached the maximum continuous time allowed on the service or session
- Admin Reset (6) - system administrator terminated the session
- Port Error (8) - PVC failed; no hardware or no interface
- NAS Error (9) - negotiation failures, connection failures, or address lease expiration
- NAS Request (10) - PPP challenge timeout, PPP request timeout, tunnel establishment failure, PPP bundle failure, IP address lease expiration, PPP keep-alive failure, Tunnel disconnect, or an unaccounted-for error
|
|
|
- Indicates how many times the Acct-Input-Octets counter has wrapped around 2^32 during the time this service has been provided, and can be present in Accounting-Request records only where the Acct-Status-Type is set to Stop or Interim-Update
- PPP payload only
|
|
|
- Indicates how many times the Acct-Output-Octets counter has wrapped around 2^32 in the course of delivering this service, and can be present in Accounting-Request records only where the Acct-Status-Type is set to Stop or Interim-Update
- PPP payload only
|
|
|
Records the time that this event occurred on the NAS, in seconds, since January 1, 1970 00:00 UTC |
|
|
Contains the CHAP challenge sent by the NAS to a PPP CHAP user |
|
|
|
|
|
Specifies the maximum number of Multilink Point-to-Point protocol (MP) member links allowed for the subscriber |
|
|
- Tunneling protocol(s) to be used (in the case of a tunnel initiator) or the tunneling protocol in use (in the case of a tunnel terminator)
- Only L2TP and L2F supported at this time
|
|
|
- Transport medium to use when creating a tunnel for those protocols (such as L2TP) that can operate over multiple transports
- Only Ipv4 supported at this time
|
|
|
Address of the initiator end of the tunnel |
|
|
Address of the server end of the tunnel |
|
|
- Indicates the identifier assigned to the tunnel session
- Value is L2TP call-serial number
|
|
|
Password to be used to authenticate to a remote server |
|
|
Sent from the NAS to indicate the nature of the user's connection |
|
|
Indicate to the tunnel initiator the particular tunnel to which a session is to be assigned |
|
|
- If more than one set of tunneling attributes is returned by the RADIUS server to the tunnel initiator, this attribute is included in each set to indicate the relative preference assigned to each tunnel.
- Included in the Tunnel-Link-Start, the Tunnel-Link-Reject, and the Tunnel-Link-Stop packets (LAC only)
|
|
|
Number of seconds between each interim accounting update in seconds for this specific session |
|
|
Number of packets lost on a given link |
|
|
- Text string that identifies the physical interface of the NAS that is authenticating the user
- If the PPP user connects via ATM slot 12, port 2, vpi 100, vci 101, then the NAS-Port-Id value in the RADIUS packets will be atm 12/2:100.101
- If the user is a PPP user that started as a result of the ERX LNS feature (that is, no physical port), then the NAS-Port-Id value is as follows: media:local address:peer address:local tunnel id:peer tunnel id:local session id:peer session id:call serial number
> For example: ip:172.81.1.98:172.81.1.99:18d:cb8:ce6:9f4:6
> In this case, the local information refers to the LNS, and the peer information refers to the LAC
- NAS-Port-Id usually contains one of the following:
> atm <slot> / <port>:<vpi>.<vci>
> fastEthernet <slot> / <port> [:<vlan>]
> gigabitEthernet <slot> / <port> [<vlan>
> serial <slot>/<port> [:<sonetPath> [/<sonetTributary (x/x/x)> [/<fractionalInterface>] ] ]
> from LNS - ip:local ip:peer ip:local tid:peer tid:local sid:peer sid:call serial number
· tid - tunnel id
· sid - session id
|
|
|
Name of an assigned address pool that should be used to assign an address for the user |
|
|
Name used by the tunnel initiator during the authentication phase of tunnel establishment |
|
|
Name used by the tunnel terminator during the authentication phase of tunnel establishment |
|
|
- RADIUS policy definitions allow you to configure a policy that consists of Filter/Forward rules based on classified packet flows.
- The RADIUS policy definitions use the Ascend-Data-Filter format or Filter-Id, Ingress-Policy-Name, and Egress-Policy-Name.
|
|
|
|
|
|
|
|
|
|
string: virtual-router-name |
|
|
|
|
string: address-pool-name |
|
|
|
|
|
|
|
|
|
string: primary-dns-address |
|
|
|
|
string: secondary-dns-address |
|
|
|
|
string: primary-wins-address |
|
|
|
|
string: secondary-wins-address |
|
|
|
|
string: tunnel-virtual-router |
|
|
|
|
|
|
|
|
|
string: input-policy-name |
|
|
|
|
string: output-policy-name |
|
|
|
|
integer: 0 = disable, 1 = enable |
|
|
|
|
integer: 0 = disable, 1 = enable |
|
|
|
|
integer: 1= UBR, 2= UBR PCR, 3=NRT VBR, 4=CBR |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Juniper-Initial-CLI-Access-Level |
|
|
single attribute: enter 0, 1, 5, 10, or 15 |
|
Juniper-Allow-All-VR-Access |
|
|
integer: 0 = disable, 1 = enable |
|
Juniper-Alt-CLI-Access-Level |
|
|
single attribute; enter 0, 1, 5, 10, or 15 |
|
Juniper-Alt-CLI-Virtual-Router-Name |
|
|
string: virtual-router-name |
|
|
|
|
integer: 0 = disable, 1 = enable |
|
|
|
|
integer: 0 = disable, 1 = enable |
|
|
|
|
|
|
|
|
|
authentication-redirection |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|