13-18
User Guide for Cisco Secure Access Control System 5.4
OL-26225-01
Chapter13 M anaging Reports
Working with Catalog Reports
Changing Authorization and Disconnecting Active RADIUS Sessions
Note Some of the NADs in your deployment do not send an Accounting Stop or Accounting Off packet after
a reload. As a result of this, you might find two sessions in the Session Directory reports, one of which
has expired. Hence, when you want to dynamically change the authorization of an active RADIUS
session or disconnect an active RADIUS session, ensure that you always choose the most recent session.
To change authorization or disconnect an active RADIUS session:
Step1 Run the RADIUS Active Sessions report under Session Directory.
See Running Catalog Reports, page 13-11 for information on how to run a RADIUS Act ive Sessions
report.
A report similar to the one shown in Figure 13-2 appears.
Figure13-2 RADIUS Active Session Report
Step2 Click the CoA link from the RADIUS session that you want to reauthenticate or terminate.
The Change of Authorization Request page appears.
Step3 Select a CoA option from the CoA option drop-down list box shown in Figure 13-3.
Valid options are:
Disconnect:None—Do not terminate the session.
Disconnect:Port Bounce—Terminate the session and restart the port.
Disconnect:Port Disable—Terminate the session and shut down the port.
Re-Auth—Reauthenticate the user.