Security/Authentication
The RADIUS server (the disconnect client) must calculate the authenticator as specified
for an Accounting-Request message in RFC 2866. The router’s RADIUS
dynamic-request server verifies the request using authenticator calculation as specified
for an Accounting-Request message in RFC 2866. A key (secret), as specified in RFC
2865, must be configured and used in the calculation of the authenticator. The
response authenticator is calculated as specified for an Accounting-Response message
in RFC 2866.
Configuring RADIUS-Initiated Disconnect
To configure RADIUS-initiated disconnect feature, perform the following steps to set
up the RADIUS dynamic-request server that will perform the disconnect operation:
1.
Configure the RADIUS dynamic-request server, and enter RADIUS Configuration
mode.
host1(config)#
radius dynamic-request server 10.10.5.10
host1(config-radius)#
2.
Enable the RADIUS-initiated disconnect capability on the RADIUS dynamic-request
server.
host1(config-radius)#
subscriber disconnect
3.
Define the secret used in the RADIUS Authenticator field during exchanges
between the RADIUS dynamic-request server and the RADIUS server.
host1(config-radius)#
key Secret3Clientkey
4.
(Optional) Specify the UDP port on which the RADIUS dynamic-request server
listens for messages from the RADIUS server. The default is 1700.
host1(config-radius)#
udp-port 1770
RADIUS-Initiated Change of Authorization
This section describes the RADIUS dynamic-request server’s support for CoA
messages. CoA messages are used by the E Series router’s RADIUS-initiated packet
mirroring feature, which is described in the
Configuring RADIUS-Based Mirroring
chapter in
JUNOSe Policy Management Configuration Guide
, and by Service Manager,
which is described in “Configuring Service Manager” on page 635 of this guide.
Change-of-Authorization Messages
The RADIUS dynamic-request server receives and processes the unsolicited CoA
messages from RADIUS servers. The RADIUS-initiated CoA feature uses the following
codes in its RADIUS request and response messages:
■
CoA-Request (43)
Configuring RADIUS-Initiated Disconnect
■
239
Chapter 4: Configuring RADIUS Dynamic-Request Server
Содержание JUNOSE 11.0.X MULTICAST ROUTING
Страница 6: ...vi...
Страница 28: ...xxviii Table of Contents JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 36: ...xxxvi List of Tables JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 42: ...2 Managing Remote Access JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 204: ...164 Managing RADIUS and TACACS JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 274: ...234 CLI Commands Used to Modify RADIUS Attributes JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 292: ...252 Monitoring RADIUS Relay Server JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 336: ...296 RADIUS Client Terminate Reasons JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 368: ...328 Managing L2TP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 408: ...368 Configuring the Weighted Load Balancing Method JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 444: ...404 PPP Accounting Statistics JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 492: ...452 Monitoring Operational Status within the Current VR Context JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 494: ...454 Managing DHCP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 510: ...470 DHCP Local Server Configuration Tasks JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 528: ...488 Configuring the Router to Work with the SRC Software JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 556: ...516 Configuring DHCP Relay Proxy JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 616: ...576 Managing the Subscriber Environment JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 632: ...592 Subscriber Management Configuration Examples JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 636: ...596 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 672: ...632 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 674: ...634 Managing Subscriber Services JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 767: ...Part 7 Index Index on page 729 Index 727...
Страница 768: ...728 Index JUNOSe 11 0 x Broadband Access Configuration Guide...