![HP HP ProCurve Series 6600 Access Security Manual Download Page 283](http://html.mh-extra.com/html/hp/hp-procurve-series-6600/hp-procurve-series-6600_access-security-manual_163101283.webp)
6-49
RADIUS Authentication, Authorization, and Accounting
VLAN Assignment in an Authentication Session
reports on terminated sessions. This attribute provides extended
information on the statistics provided by the acct-terminate-cause
attribute.
■
Change-of-Authorization (CoA) (RFC 3576: Dynamic Authorization
Extensions to RADIUS): A mechanism that allows a RADIUS server
to dynamically disconnect messages (DM) or change the authoriza-
tion parameters (such as VLAN assignment) used in an active client
session on the switch. The switch (NAS) does not have to initiate the
exchange.
For example, for security reasons you may want to limit the network
services granted to an authenticated user. In this case, you can change the
user profile on the RADIUS server and have the new authorization settings
take effect immediately in the active client session. The Change-of-Autho-
rization attribute provides the mechanism to dynamically update an active
client session with a new user policy that is sent in RADIUS packets. See
figures 6-16 and 6-17. See “3. Configure the Switch To Access a RADIUS
Server” on page 6-15 for configuration commands for dynamic authoriza-
tion.
Figure 6-16. Example of Output for Dynamic Authorization Configuration
HP Switch
(config)# show radius dyn-authorization
Status and Counters - RADIUS Dynamic Authorization Information
NAS Identifier : LAB-8212
Invalid Client Addresses (CoA-Reqs) : 0
Invalid Client Addresses (Disc-Reqs) : 0
Disc Disc Disc CoA CoA CoA
Client IP Addr Reqs ACKs NAKs Reqs ACKs NAKs
--------------- -------- -------- -------- -------- -------- --------
154.34.23.106 1 1 0 2 2 0
154.45.234.12 2 1 1 3 3 0
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......