Chapter 7 Configuring RADIUS Servers

Configuring and Enabling RADIUS

RADIUS Attributes Sent by the Access Point

Table 7-2through Table 7-6identify the attributes sent by an access point to a client in access-request, access-accept, and accounting-request packets.

Note You can configure the access point to include in its RADIUS accounting and authentication requests attributes recommended by the Wi-Fi Alliance’s WISPr Best Current Practices for Wireless Internet Service Provider (WISP) Roaming document. Refer to the “Configuring WISPr RADIUS Attributes” section on page 7-16for instructions.

Table 7-2

Attributes Sent in Access-Request Packets

 

 

 

Attribute ID

 

Description

 

 

 

1

 

User-Name

 

 

 

4

 

NAS-IP-Address

 

 

 

5

 

NAS-Port

 

 

 

12

 

Framed-MTU

 

 

 

30

 

Called-Station-ID (MAC address)

 

 

 

31

 

Calling-Station-ID (MAC address)

 

 

 

32

 

NAS-Identifier1

61

 

NAS-Port-Type

 

 

 

79

 

EAP-Message

 

 

 

80

 

Message-Authenticator

 

 

 

1. The access point sends the NAS-Identifier if attribute 32 (include-in-access-req) is configured.

Table 7-3 Attributes Honored in Access-Accept Packets

Attribute ID

Description

 

 

25

Class

 

 

27

Session-Timeout

 

 

64

Tunnel-Type1

65

Tunnel-Medium-Type1

79

EAP-Message

 

 

80

Message-Authenticator

 

 

81

Tunnel-Private-Group-ID1

VSA (attribute 26)

LEAP session-key

 

 

VSA (attribute 26)

Auth-Algo-Type

 

 

VSA (attribute 26)

SSID

 

 

1. RFC2868; defines a VLAN override number.

Cisco Wireless ISR and HWIC Access Point Configuration Guide

7-18

OL-6415-04

 

 

Page 124
Image 124
Cisco Systems OL-6415-04 manual Radius Attributes Sent by the Access Point, Attribute ID Description