Explanation
Value
Session Context Not Removable
504
Other Proxy Processing Error
505
Resources Unavailable
506
Request Initiated
507
Multiple Session Selection Unsupported
508
Preconditions
To use the CoA interface, a session must already exist on the switch. CoA can be used to identify a session
and enforce a disconnect request. The update affects only the specified session.
CoA Request Response Code
The CoA Request response code can be used to convey a command to the switch.
The packet format for a CoA Request Response code as defined in RFC 5176 consists of the following fields:
Code, Identifier, Length, Authenticator, and Attributes in the Type:Length:Value (TLV) format. The Attributes
field is used to carry Cisco vendor-specific attributes (VSAs).
Related Topics
CoA Request Commands, on page 65
Session Identification
For disconnect and CoA requests targeted at a particular session, the switch locates the session based on one
or more of the following attributes:
•
Acct-Session-Id (IETF attribute #44)
•
Audit-Session-Id (Cisco VSA)
•
Calling-Station-Id (IETF attribute #31 which contains the host MAC address)
•
IPv6 Attributes, which can be one of the following:
•
Framed-IPv6-Prefix (IETF attribute #97) and Framed-Interface-Id (IETF attribute #96), which
together create a full IPv6 address per RFC 3162
•
Framed-IPv6-Address
•
Plain IP Address (IETF attribute #8)
Unless all session identification attributes included in the CoA message match the session, the switch returns
a Disconnect-NAK or CoA-NAK with the
“
Invalid Attribute Value
”
error-code attribute.
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
64
OL-29048-01
Configuring RADIUS
RADIUS Change of Authorization