Include the attributes statement at the [edit access
profile profile-name radius] hierarchy level
to specify attributes that are ignored in RADIUS Access-Accept messages,
or that are excluded from particular RADIUS message types.
The following list describes the ignore and exclude statements:
Use the ignore statement to configure the router
to ignore a particular attribute in RADIUS Access-Accept messages.
By default, the router processes the attributes received from the
external AAA server. You can specify that the following attributes
be ignored:
logical-system-routing-instance—Virtual-Router,
VSA 26-1
output-filter—Egress-Policy-Name, VSA 26-11
Use the exclude statement to configure the router
to exclude the specified attributes from the specified type of RADIUS
message. Not all attributes appear in all types of RADIUS messages—the
CLI indicates the RADIUS message type. By default, the router includes
the specified attributes in RADIUS Access-Request, Acct-On, Acct-Off,
Acct-Start, and Acct-Stop messages. You can configure the router to
exclude the following attributes: