6
No. Attribute
No. Attribute
35 Login-LAT-Node
82 Tunnel-Assignment-id
36 Login-LAT-Group
83 Tunnel-Preference
37 Framed-AppleTalk-Link
84 ARAP-Challenge-Response
38 Framed-AppleTalk-Network
85 Acct-Interim-Interval
39 Framed-AppleTalk-Zone
86 Acct-Tunnel-Packets-Lost
40 Acct-Status-Type
87 NAS-Port-Id
41 Acct-Delay-Time
88 Framed-Pool
42 Acct-Input-Octets 89
(unassigned)
43 Acct-Output-Octets
90 Tunnel-Client-Auth-id
44 Acct-Session-Id
91 Tunnel-Server-Auth-id
Extended RADIUS attributes
The RADIUS protocol features excellent extensibility. The Vendor-Specific attribute (attribute 26)
allows a vendor to define extended attributes. The extended attributes can implement functions that
the standard RADIUS protocol does not provide.
A vendor can encapsulate multiple subattributes in the TLV format in attribute 26 to provide extended
functions. As shown in
, a subattribute encapsulated in attribute 26 consists of the following
parts:
•
Vendor-ID
—ID of the vendor. The most significant byte is 0. The other three bytes contains a
code compliant to RFC 1700.
•
Vendor-Type
—Type of the subattribute.
•
Vendor-Length
—Length of the subattribute.
•
Vendor-Data
—Contents of the subattribute.
The device supports RADIUS subattributes with a vendor ID of 25506. For more information, see
"
Proprietary RADIUS subattributes (vendor ID 25506)
Figure 5 Format of attribute 26
HWTACACS
HW Terminal Access Controller Access Control System (HWTACACS) is an enhanced security
protocol based on TACACS (RFC 1492). HWTACACS is similar to RADIUS, and uses a client/server
model for information exchange between the NAS and the HWTACACS server.
HWTACACS typically provides AAA services for PPP, VPDN, and terminal users. In a typical
HWTACACS scenario, terminal users need to log in to the NAS. Working as the HWTACACS client,
the NAS sends users' usernames and passwords to the HWTACACS server for authentication. After
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...