Chapter 10 Configuring system settings 555

When you add an external RADIUS audit server to the configuration, the server is automatically assigned an index number. You can add several RADIUS audit servers, for backup purposes. Nortel SNAS 4050 auditing will be performed by an available server with the lowest index number. You can control audit server usage by reassigning index numbers (see “Managing RADIUS audit servers using the SREM” on page 559).

For information about configuring a RADIUS accounting server to log portal user sessions, see “Configuring RADIUS accounting using the SREM” on page 183.

About the vendor-specific attributes

The RADIUS audit server uses Vendor-Id and Vendor-Type attributes in combination to identify the source of the audit information. The attributes are sent to the RADIUS audit server together with the event log information.

Each vendor has a specific dictionary. The Vendor-Id specified for an attribute identifies the dictionary the RADIUS server will use to retrieve the attribute value. The Vendor-Type indicates the index number of the required entry in the dictionary file.

The Internet Assigned Numbers Authority (IANA) has designated SMI Network Management Private Enterprise Codes that can be assigned to the Vendor-Id attribute (see http://www.iana.org/assignments/enterprise-numbers).

RFC 2866 describes usage of the Vendor-Type attribute.

Contact your RADIUS system administrator for information about the vendor-specific attributes used by the external RADIUS audit server.

To simplify the task of finding audit entries in the RADIUS server log, do the following:

1In the RADIUS server dictionary, define a descriptive string (for example,

NSNAS-SSL-Audit-Trail).

2Map this string to the Vendor-Type value.

Nortel Secure Network Access Switch 4050 User Guide

Page 555
Image 555
Nortel Networks 4050 manual About the vendor-specific attributes