Table 48 describes the RADIUS IETF attributes supported by JUNOSe software. The attributes are sorted by standard number.
Table 48: RADIUS IETF Attributes Supported by JUNOSe Software
Attribute Number |
Attribute Name |
Description |
|---|---|---|
[1] |
User-Name |
|
[2] |
User-Password |
|
[3] |
CHAP-Password |
Response value provided by a Point-to-Point Protocol (PPP) Challenge Handshake Authorization Protocol (CHAP) user in the response to an access challenge |
[4] |
NAS-IP-Address |
|
[5] |
NAS-Port |
|
[6] |
Service-Type |
|
[7] |
Framed-Protocol |
|
[8] |
Framed-IP-Address |
|
[9] |
Framed-IP-Netmask |
|
[11] |
Filter-Id |
|
[12] |
Framed-MTU |
|
[13] |
Framed-Compression |
Always set to none. |
[18] |
Reply-Message |
|
[22] |
Framed-Route |
String that provides routing information to be configured for the user on the NAS; in the format: <addr>[/<maskLen>] [<nexthop> [<cost>]] [tag <tagValue>] [distance <distValue>] |
[24] |
State |
|
[25] |
Class |
An arbitrary value that the NAS includes in all accounting packets for the user if supplied by the RADIUS server |
[26] |
Vendor-Specific |
Juniper Networks Enterprise number 0x0000130A |
[27] |
Session-Timeout |
Maximum number of consecutive seconds of service to be provided to the user before termination of the session |
[28] |
Idle-Timeout |
Maximum number of consecutive seconds of idle connection provided to the user before termination of the session |
[30] |
Called-Station-Id |
|
[31] |
Calling-Station-Id |
|
[32] |
NAS-Identifier |
|
[33] |
Proxy-State |
E Series router’s port ID and IP address |
[40] |
Acct-Status-Type |
Indicates whether this Accounting-Request marks the beginning of the user service (Start), the end (Stop), or the interim (Interim-Update) |
[41] |
Acct-Delay-Time |
Indicates how many seconds the client has been trying to send a particular record |
[42] |
Acct-Input-Octets |
|
[43] |
Acct-Output-Octets |
|
[44] |
Acct-Session-Id |
|
[45] |
Acct-Authentic |
|
[46] |
Acct-Session-Time |
Indicates how long in seconds that the user has received service |
[47] |
Acct-Input-Packets |
|
[48] |
Acct-Output-Packets |
|
[49] |
Acct-Terminate-Cause |
Contains the reason the service (a PPP session) was terminated. The service can be terminated for the following reasons:
|
[50] |
Acct-Multi-Session-Id |
|
[51] |
Acct-Link-Count |
A value that increments with each link that joins the MLPPP bundle. This attribute does not indicate the number of active links. For more details, see RFC 2866—RADIUS Accounting (June 2000). |
[52] |
Acct-Input-Gigawords |
|
[53] |
Acct-Output-Gigawords |
|
[55] |
Event-Timestamp |
Records the time that this event occurred on the NAS, in seconds, since January 1, 1970 00:00 UTC |
[60] |
CHAP-Challenge |
Contains the CHAP challenge sent by the NAS to a PPP CHAP user |
[61] |
NAS-Port-Type |
|
[62] |
Port-Limit |
Specifies the maximum number of MLPPP member links allowed for the subscriber |
[64] |
Tunnel-Type |
|
[65] |
Tunnel-Medium-Type |
|
[66] |
Tunnel-Client-Endpoint |
Address of the initiator end of the tunnel |
[67] |
Tunnel-Server-Endpoint |
Address of the server end of the tunnel |
[68] |
Acct-Tunnel-Connection |
|
[69] |
Tunnel-Password |
Password to be used to authenticate to a remote server |
[77] |
Connect-Info |
Sent from the NAS to indicate the nature of the user’s connection |
[79] |
EAP-Message |
Encapsulates EAP packets, which allows the NAS to authenticate users through EAP without having to understand the EAP protocol |
[80] |
Message-Authenticator |
Must be used in any Access-Request, Access-Accept, Access-Reject or Access- Challenge messages that include EAP-Message attributes |
[82] |
Tunnel-Assignment-Id |
Indicates to the tunnel initiator the particular tunnel to which a session is to be assigned |
[83] |
Tunnel-Preference |
|
[85] |
Acct-Interim-Interval |
Number of seconds between each interim accounting update for this session |
[86] |
Acct-Tunnel-Packets-Lost |
Number of packets lost on a given link |
[87] |
NAS-Port-Id |
NOTE: Releases before 4.0.0 did not pass the subinterface number to RADIUS for inclusion in the NAS-Port-Id. If you do not want the subinterface number to be included, you must enter the aaa intf-desc-format include sub-intf disable command to omit the subinterface. |
[88] |
Framed-Pool |
Name of an assigned address pool that should be used to assign an address for the user |
[90] |
Tunnel-Client-Auth-Id |
Name used by the tunnel initiator during the authentication phase of tunnel establishment |
[91] |
Tunnel-Server-Auth-Id |
Name used by the tunnel terminator during the authentication phase of tunnel establishment |
[96] |
Framed-Interface-Id |
IPv6 interface identifier configured by the user |
[97] |
Framed-Ipv6-Prefix |
Provides the IPv6 prefix that is delegated to a downstream CPE |
[99] |
Framed-Ipv6-Route |
Provides routing information to be configured for the user on the NAS |
[100] |
Framed-Ipv6-Pool |
Name of the local address pool from which an IPv6 prefix is assigned to the requesting router |
[101] |
Error-Cause |
4-octet field that contains an integer that specifies the cause of the error |
[123] |
Delegated-Ipv6-Prefix |
IPv6 prefix to be delegated to clients using the DHCPv6 Prefix Delegation mechanism |
[135] |
Ascend-Primary-DNS |
|
[136] |
Ascend-Secondary-DNS |
|
[188] |
Ascend-Num-In-Multilink |
Current number of links in a multilink bundle |
[242] |
Ascend-Data-Filter |
RADIUS policy definitions used to configure a policy to classify packet flows and perform filter, forward, packet marking, rate-limit profile, and traffic class actions |