![Alcatel-Lucent 7950 SR System Management Manual Download Page 45](http://html1.mh-extra.com/html/alcatel-lucent/7950-sr/7950-sr_system-management-manual_2892148045.webp)
Security
7950 SR OS System Management Guide
Page 45
Vendor-Specific Attributes (VSAs)
The software supports the configuration of Alcatel-Lucent-specific RADIUS attributes. These
attributes are known as vendor-specific attributes (VSAs) and are discussed in RFC 2138.
VSAs must be configured when RADIUS authorization is enabled. It is up to the vendor to
specify the format of their VSA. The attribute-specific field is dependent on the vendor's
definition of that attribute. The Alcatel-Lucent-defined attributes are encapsulated in a
RADIUS vendor-specific attribute with the vendor ID field set to 6527, the vendor ID number.
Note that the PE-record entry is required in order to support the RADIUS Discovery for Layer
2 VPN feature. Note that a PE-record is only relevant if the RADIUS Discovery feature is
used, not for the standard RADIUS setup.
The following RADIUS vendor-specific attributes (VSAs) are supported by Alcatel-Lucent.
•
timetra-access <ftp> <console>
<both>
— This is a mandatory command
that must be configured. This command specifies if the user has FTP and /or console
(serial port, Telnet, and SSH) access.
•
timetra-profile <profile-name>
— When configuring this VSA for a user, it
is assumed that the user profiles are configured on the local router and the following
applies for local and remote authentication:
1. The
authentication-order
parameters configured on the router must include
the
local
keyword.
2. The user name may or may not be configured on the router.
3. The user must be authenticated by the RADIUS server
4. Up to 8 valid profiles can exist on the router for a user. The sequence in which the
profiles are specified is relevant. The most explicit matching criteria must be or-
dered first. The process stops when the first complete match is found.
If all the above mentioned conditions are not met, then access to the router is denied
and a failed login event/trap is written to the security log.
•
timetra-default-action <permit-all|deny-all|none>
— This is a
mandatory command that must be configured even if the
timetra-cmd
VSA is not
used. This command specifies the default action when the user has entered a
command and no entry configured in the
timetra-cmd
VSA for the user resulted in
a match condition.
•
timetra-cmd <match-string>
— Configures a command or command subtree as
the scope for the match condition.
The command and all subordinate commands in subordinate command levels are
specified.
Summary of Contents for 7950 SR
Page 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Page 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Page 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Page 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Page 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Page 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Page 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Page 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Page 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Page 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Page 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Page 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Page 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Page 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Page 460: ...Standards and Protocols Page 460 Standards and Protocols...