Nortel Networks 2300 Series manual Service-type, Session-timeout, Ssid, Start-date

Models: 2300 Series

1 622
Download 622 pages 48.74 Kb
Page 210
Image 210

210AAA Commands

Table 1: Authentication Attributes for Local Users (continued)

Attribute

Description

Valid Value(s)

service-type

Type of access the user is

 

requesting.

One of the following numbers:

2—Framed; for network user access

6—Administrative; for administrative access to the WSS, with authorization to access the enabled (configuration) mode. The user must enter the enable command and the correct enable password to access the enabled mode.

7—NAS-Prompt; for administrative access to the nonenabled mode only. In this mode, the user can still enter the enable command and the correct enable password to access the enabled mode.

 

 

For administrative sessions, the WSS always

 

 

sends 6 (Administrative).

 

 

The RADIUS server can reply with one of the

 

 

values listed above.

 

 

If the service-type is not set on the RADIUS

 

 

server, administrative users receive NAS-Prompt

 

 

access, and network users receive Framed access.

 

 

 

session-timeout

Maximum number of

Number between 0 and 4,294,967,296 seconds

(network access mode

seconds for the user’s

(approximately 136.2 years).

only)

session.

Note. If the global reauthentication timeout (set

 

 

 

 

by the set dot1x reauth-period command) is

 

 

shorter than the session-timeout, WSS Software

 

 

uses the global timeout instead.

 

 

 

ssid

SSID the user is allowed to

Name of the SSID you want the user to use. The

(network access mode

access after authentication.

SSID must be configured in a service profile, and

only)

 

the service profile must be used by a radio profile

 

 

assigned to Nortel radios in the Mobility Domain.

 

 

 

start-date

Date and time at which the

Date and time, in the following format:

 

user becomes eligible to

YY/MM/DD-HH:MM

 

access the network.

You can use start-datealone or with end-date.

 

WSS Software does not

 

You also can use start-date, end-date, or both in

 

authenticate the user unless

conjunction with time-of-day.

 

the attempt to access the

 

 

network occurs at or after

 

 

the specified date and time,

 

 

but before the end-date (if

 

 

specified).

 

 

 

 

NN47250-100 (Version 02.51)

Page 210
Image 210
Nortel Networks 2300 Series Service-type, Session-timeout, By the set dot1x reauth-period command is, Ssid, Start-date