Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asean Region (Vietnam, Indonesia, Singapore, Malaysia)
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center

Technical Documentation

Support
Technical Documentation
Content Explorer New
 
Enterprise MIBs
 
EOL Documentation
 
Feature Explorer Login required New
 
File Format Help
 
Glossary
 
Portable Libraries
 
 
Home > Support > Technical Documentation > JunosE Software > RADIUS Server and Attributes on E Series Broadband Services Routers, Release 13.2
Print
Rate and give feedback:  Feedback Received. Thank You!
Rate and give feedback: 
Close
This document helped resolve my issue.  Yes No

Additional Comments

800 characters remaining

May we contact you if necessary?

Name:  
E-mail: 
Submitting...

RADIUS Server and Attributes on E Series Broadband Services Routers, Release 13.2

Remote Authentication Dial-In User Service (RADIUS) is a distributed client/server that protects networks against unauthorized access. RADIUS clients running on E Series routers send authentication requests to a central RADIUS server. This page provides information regarding the RADIUS attributes that JunosE Software supports and the RADIUS attributes you can configure with the CLI.


JunosE Software Documentation for E Series Broadband Services Routers, Release 13.2

  • Overview
  • Configuration
  • Administration
  • Troubleshooting
Understanding the RADIUS Features

RADIUS Overview

RADIUS Platform Considerations

RADIUS References

RADIUS Authentication and Accounting Servers Configuration Overview

RADIUS IETF Attributes and VSAs in Access Messages

Subscriber AAA Access Messages Overview

RADIUS IETF Attributes Supported for Subscriber AAA Access Messages

Juniper Networks VSAs Supported for Subscriber AAA Access Messages

RADIUS IETF Attributes and VSAs in Accounting Messages

Subscriber AAA Accounting Messages Overview

RADIUS IETF Attributes Supported for Subscriber AAA Accounting Messages

Juniper Networks VSAs Supported for Subscriber AAA Accounting Messages

RADIUS IETF Attributes Supported for AAA Tunnel Accounting Messages

DSL Forum VSAs in RADIUS Access and Accounting Messages

DSL Forum VSAs in AAA Access and Accounting Messages Overview

DSL Forum VSAs Supported for AAA Access and Accounting Messages

RADIUS IETF Attributes and VSAs in Access Messages

RADIUS Attributes Supported for CLI AAA Messages

RADIUS Attribute Definitions

RADIUS IETF Attributes

Juniper Networks VSAs

DSL Forum VSAs

Pass Through RADIUS Attributes

RADIUS Attributes References

RADIUS Attributes for Dynamic and LAG Interfaces

VSAs for Dynamic IP Interfaces Overview

Propagation of LAG Subscriber Information to AAA and RADIUS

Application Terminate Reasons

AAA Terminate Reasons

RADIUS Client Terminate Reasons

Configuration Tasks for RADIUS Servers

Configuring RADIUS AAA Servers

Configuring RADIUS Attributes in Access and Accounting Messages

CLI Commands Used to Modify RADIUS Attributes

CLI Commands Used to Include or Exclude Attributes in RADIUS Messages

CLI Commands Used to Include DSL Forum VSAs in Access and Accounting Messages

CLI Commands Used to Include ANCP-Related Juniper Networks VSAs in Access and Accounting Messages

CLI Commands Used to Ignore Attributes when Receiving Access-Accept Messages

CLI Commands Used to Configure RADIUS IETF Attributes

CLI Commands Used to Configure Juniper Networks VSAs

Configuration Commands for RADIUS Servers

aaa accounting broadcast

aaa accounting duplication

aaa accounting immediate-update

aaa authentication default

aaa duplicate-address-check

key

max-sessions

radius accounting server

radius authentication server

radius rollover-on-reject

radius tunnel-accounting

radius udp-checksum

retransmit

timeout

udp-port

virtual-router

Configuration Commands for RADIUS Attributes

radius override nas-info

radius accounting server

radius authentication server

radius connect-info-format

radius ignore

radius include

radius nas-port-format

radius nas-port-format extended

radius pppoe nas-port-format unique

radius calling-station-delimiter

radius calling-station-format

radius include dsl-forum-attributes

radius override calling-station-id remote-circuit-id

radius override nas-info

radius override nas-ip-addr tunnel-client-endpoint

radius override nas-port-id remote-circuit-id

radius remote-circuit-id-format

radius remote-circuit-id-delimiter

radius rollover-on-reject

radius tunnel-accounting

radius udp-checksum

Examples

Example: Configuring RADIUS-Specific Attributes

Monitoring the RADIUS Attribute Settings

Monitoring Override Settings of RADIUS IETF Attributes

Monitoring the NAS-Port-Format RADIUS Attribute

Monitoring the Calling-Station-Id RADIUS Attribute

Monitoring the NAS-Identifier RADIUS Attribute

Monitoring the Format of the Remote-Circuit-ID for RADIUS

Monitoring the Delimiter Character in the Remote-Circuit-ID for RADIUS

Monitoring the Acct-Session-Id RADIUS Attribute

Monitoring the DSL-Port-Type RADIUS Attribute

Monitoring the Connect-Info RADIUS Attribute

Monitoring the NAS-Port-ID RADIUS Attribute

Verifying RADIUS Attributes Used in Access and Accounting Messages

Monitoring Included RADIUS Attributes

Monitoring Ignored RADIUS Attributes

Monitoring the Status of ICR Partition Accounting

Monitoring RADIUS Servers and Services for AAA Features

Monitoring the RADIUS Server Algorithm

Monitoring the RADIUS Attribute Used for DHCPv6 Prefix Delegation

Monitoring the RADIUS Attribute Used for IPv6 Neighbor Discovery Router Advertisements

Monitoring the RADIUS Rollover Configuration

Monitoring RADIUS Override Settings

Monitoring RADIUS Server Information

Monitoring RADIUS Accounting for L2TP Tunnels

Monitoring RADIUS Services Statistics

Monitoring RADIUS SNMP Traps

Monitoring RADIUS UDP Checksums

Monitoring RADIUS Server IP Addresses

Monitoring Commands

show radius algorithm

show radius override

show radius rollover-on-reject

show radius servers

show radius statistics

show radius tunnel-accounting

Knowledge Base

A way to add local RADIUS Attributes to the SRC

The ERX can't interpret some Radius attributes for more than one tunnel

Framed-route RADIUS attributes don't get installed for IPSEC dynamic interface columns

Policies created using Ascend Data-Filter Radius Attributes are limited to 12. When attempting to apply more then 12, only the first 12 policies are defined on the interface.

Metric value in the RADIUS framed route attribute is ignored by the ERX

The limit for the value of the Tunnel-Assignment-Id RADIUS attribute can be too short depending on the configuration used

ERX doesn't send multiple instances of RADIUS Class attribute to Accounting Server.

Radius does not record the correct value for the radius vsa attribute, "service-bundle"

ERX will ignore the RADIUS attribute Unisphere-PppoE-Url when "ip local pool" is used

The 'test aaa' command does not decode radius attribute tunnel-calling-number

Attributes excluded from RADIUS Interim-Accounting/Accounting-Stop messages for non-established PPP sessions.

Understanding RADIUS Accounting Statistics

RADIUS Accounting Stop does not include IPCP packets.

Policy name in radius accounting not changed

L2TP/PPP RADIUS Accounting byte/packet values

RADIUS Accounting statistics are not reported for Service Manager subscriber sessions

Missing interim radius accounting records for a service activated by CoA

Wrong shaping values reported for connect-info in Radius accounting records

SSC's RADIUS accounting messages are missing timestamp and IP address of the user

RADIUS Accounting records for DHCP local subscribers contain incorrect packet and byte counts

Radius Accounting Stop Generated with Incorrect Terminate-Cause and Zero Session Throughput

ERX implementaton of RADIUS Accounting Attribute 49 - Acct-Terminate-Cause

Client "Framed-Ip-Address" not being provided via a Radius Access Request Message

The ERX does not send the NAS-Port attribute in the RADIUS Access-Request message for DHCP authentication.

Radius VR access not working right

Dynamic Subscriber Interface (DSI) gets created in the ERX despite of an Access-Reject from the RADIUS

RADIUS Accounting-Start messages aren't being sent when using a non-PPP equal access

E-series router incorrectly sends a RADIUS Accounting-Stop after an Access-Reject. The CLI command 'aaa accounting acct-stop on-access-deny' has no effect.

ERX is not processing RADIUS packets and loosing ANCP sessions under heavy load

GE VLAN IDs missing from RADIUS accounting records for DHCP subscribers

 

Downloads

  • Broadband Access Configuration Guide, Release 13.2.0 PDF Document
  • RADIUS Server and Attributes on E Series Broadband Services Routers PDF Document
 
 
  • About Juniper
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Green Networking
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Developers
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out