|
Authenticator
|
|
|
|
|
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|
Attributes ...
+-+-+-+-+-+-+-+-+-+-+-+-+-
The attributes field is used to carry Cisco vendor-specific attributes (VSAs).
Related Topics
CoA Disconnect-Request, on page 60
CoA Request: Disable Host Port, on page 60
CoA Request: Bounce-Port, on page 60
CoA ACK Response Code
If the authorization state is changed successfully, a positive acknowledgment (ACK) is sent. The attributes
returned within CoA ACK will vary based on the CoA Request and are discussed in individual CoA Commands.
CoA NAK Response Code
A negative acknowledgment (NAK) indicates a failure to change the authorization state and can include
attributes that indicate the reason for the failure. Use
show
commands to verify a successful CoA.
CoA Request Commands
Table 9: CoA Commands Supported on the Switch
Cisco VSA
Command
Cisco:Avpair=
“
subscriber:command=reauthenticate
”
Reauthenticate host
This is a standard disconnect request that does not
require a VSA.
Terminate session
Cisco:Avpair=
“
subscriber:command=bounce-host-port
”
Bounce host port
Cisco:Avpair=
“
subscriber:command=disable-host-port
”
Disable host port
1 All CoA commands must include the session identifier between the switch and the CoA client.
Related Topics
CoA Request Response Code, on page 57
Session Reauthentication
The AAA server typically generates a session reauthentication request when a host with an unknown identity
or posture joins the network and is associated with a restricted access authorization profile (such as a guest
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
58
OL-29434-01
Configuring RADIUS
RADIUS Change of Authorization