Cisco AS5800 Specifications Page 157

  • Download
  • Add to my manuals
  • Print
  • Page
    / 334
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 156
4-19
Cisco AS5800 Operations, Administration, Maintenance, and Provisioning Guide
DOC-7810814=
Chapter 4 Administration
Access Service Security
Configure Router to Query RADIUS Server for Static Routes and IP Addresses
Some vendor-proprietary implementations of RADIUS let the user define static routes and IP pool
definitions on the RADIUS server, instead of on each individual Cisco AS5800 in the network. Each
network Cisco AS5800 then queries the RADIUS server for static route and IP pool information.
To have the Cisco AS5800 query the RADIUS server for static routes and IP pool definitions when the
device first starts up, use the following commands in global configuration mode:
radius-server configure-nas
Note Because the radius-server configure-nas command is performed when the Cisco router
starts up, it will not take effect until you enter a copy running-config startup-config
command.
Configure Router to Expand Network Cisco AS5800 Port Information
In some situations, PPP or login authentication occurs on an interface different from the interface on
which the call itself comes in. For example, in a V.120 ISDN call, login or PPP authentication occurs on
a virtual asynchronous interface ttt but the call itself occurs on one of the channels of the ISDN
interface.
The radius-server attribute nas-port extended command configures RADIUS to expand the size of
the NAS-Port attribute (RADIUS IETF Attribute 5) field to 32 bits. The upper 16 bits of the NAS-Port
attribute display the type and number of the controlling interface; the lower 16 bits indicate the interface
undergoing authentication.
To display expanded interface information in the NAS-Port attribute field, perform the following task
in global configuration mode.
Expand the NAS-Port attribute size from 16 to 32 bits to display extended interface information.
radius-server attribute nas-port extended
Note This command replaces the deprecated radius-server extended-portnames command.
On platforms with multiple interfaces (ports) per slot, the Cisco RADIUS implementation will not
provide a unique NAS-Port attribute that permits distinguishing between the interfaces. For example, if
a dual PRI interface is in slot 1, calls on both Serial1/0:1 and Serial1/1:1 will appear as
NAS-Port = 20101. This is due to the 16-bit field size limitation associated with RADIUS IETF
NAS-port attribute. In this case, replace the NAS-port attribute with a vendor-specific attribute
(RADIUS IETF Attribute 26). The Cisco vendor-ID is 9, and the Cisco-NAS-Port attribute is subtype 2.
Vendor-specific attributes (VSAs) can be turned on by entering the radius-server vsa send command.
The port information in this attribute is provided and configured using the aaa nas port extended
command.
To replace the NAS-Port attribute with RADIUS IETF Attribute 26 and to display extended field
information, use the following commands in global configuration mode.
Enable the network Cisco AS5800 to recognize and use vendor-specific attributes as defined by
RADIUS IETF Attribute 26.
radius-server vsa send [accounting | authentication]
Expand the size of the VSA NAS-Port field from 16 to 32 bits to display extended interface information.
aaa nas-port extended
Page view 156
1 2 ... 152 153 154 155 156 157 158 159 160 161 162 ... 333 334

Comments to this Manuals

No comments