Authentication, Authorization and Accounting (AAA) for ERS and ES
Technical Configuration Guide
13
November 2010
avaya.com
#CLI profile
ATTRIBUTE Command-Access 194 integer
VALUE Command-Access False 0
VALUE Command-Access True 1
#CLI Commands
ATTRIBUTE Commands 195 string
#802 priority (value: 0-7)
ATTRIBUTE EAP-Port-Priority 1 integer
END-VENDOR Nortel
2.3.4 /etc/raddb/users
This file contains the users list with user rights and specific parameters. It can also contain the VLAN ID
and port priority for 802.1x (EAP) clients
– please see ―eap‖ user shown below as an example which
defines VLAN ID 51 and port priority 3.
bsro Auth-Type == Local,User-Password == "bsro"
Service-Type = NAS-Prompt-User
bsrw Auth-Type == Local,User-Password == "bsrw"
Service-Type = Administrative-User
ro Auth-Type == Local,User-Password == "ro"
Access-Priority = ro
rwa Auth-Type == Local,User-Password == "rwa"
Access-Priority = rwa
eap Auth-Type == EAP,User-Password == "eap"
Tunnel-Type = 13,
Tunnel-Medium-Type = 6,
Tunnel-private-Group-Id = 51,
EAP-port-Priority = 3
The ES 460/470 and ERS 2500, 4500, 5500 switches each has two user access levels:
read-only or read-write
The ERS 1600, 8300 and 8600 switches each has six different user access levels: ro,
l1, l2, l3, rw and rwa