Cisco Catalyst 2975 Software Configuration Manual page 219

Ios release 12.2(55)se
Hide thumbs Also See for Catalyst 2975:
Table of Contents

Advertisement

Chapter 9
Configuring Switch-Based Authentication
For disconnect and CoA requests targeted to a particular session, any one of these session identifiers can
be used:
If more than one session identification attribute is included in the message, all the attributes must match
the session or the switch returns a Disconnect- negative acknowledgement (NAK) or CoA-NAK with the
error code Invalid Attribute Value.
The packet format for a CoA Request code as defined in RFC 5176 consists of the fields: Code,
Identifier, Length, Authenticator, and Attributes in Type:Length:Value (TLV) format.
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|
|
|
|
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|
+-+-+-+-+-+-+-+-+-+-+-+-+-
The attributes field is used to carry Cisco VSAs.
CoA ACK Response Code
If the authorization state is changed successfully, a positive acknowledgement (ACK) is sent. The
attributes returned within CoA ACK will vary based on the CoA Request and are discussed in individual
CoA Commands.
CoA NAK Response Code
A negative acknowledgement (NAK) indicates a failure to change the authorization state and can include
attributes that indicate the reason for the failure. Use show commands to verify a successful CoA.
CoA Request Commands
This section includes:
Beginning with Cisco IOS Release 12.2(52)SE, the switch supports the commands shown in
OL-19720-02
Calling-Station-ID (IETF attribute 31, which should contain the MAC address)
Audit-Session-ID (Cisco vendor-specific attribute)
Accounting-Session-ID (IETF attribute 44).
0
1
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
Code
|
Identifier
Attributes ...
Session Reauthentication
Session Reauthentication in a Switch Stack
Session Termination
CoA Disconnect-Request
CoA Request: Disable Host Port
CoA Request: Bounce-Port
2
|
Length
Authenticator
Catalyst 2975 Switch Software Configuration Guide
Controlling Switch Access with RADIUS
3
|
|
|
|
|
Table
9-4.
9-23

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents