Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asean Region (Vietnam, Indonesia, Singapore, Malaysia)
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center

Technical Documentation

Support
Technical Documentation
Content Explorer New
 
Enterprise MIBs
 
EOL Documentation
 
Feature Explorer Login required New
 
File Format Help
 
Glossary
 
Portable Libraries
 
 
Home > Support > Technical Documentation > JunosE Software > RADIUS Attributes Used for Packet Mirroring
Print
Rate and give feedback:  Feedback Received. Thank You!
Rate and give feedback: 
Close
This document helped resolve my issue.  Yes No

Additional Comments

800 characters remaining

May we contact you if necessary?

Name:  
E-mail: 
Submitting...
 

Related Documentation

  • RADIUS-Based Mirroring Overview
  • RADIUS-Based Mirroring Sequence of Events
 

RADIUS Attributes Used for Packet Mirroring

Table 1 and Table 2 list the packet mirroring triggers. The triggers are RADIUS attributes that identify a user whose traffic is to be mirrored. A packet mirroring session starts when the router receives a RADIUS packet that contains mirroring attributes and then applies the mirroring configuration to the appropriate interface. For example, packet mirroring starts when a logon request occurs that contains a specified User-Name attribute.

The triggers also enable RADIUS-initiated mirroring to start when the user is already logged in.

Table 1: RADIUS Attributes Used as Packet Mirroring Triggers (Vendor ID 4874)

Standard Number

Attribute Name

Order of Preference

[1]

User-Name

4

[8]

Framed-IP-Address

3

[26-1]

Virtual-Router

Used with Framed-IP-Address and User-Name

[31]

Calling-Station-ID

2

[44]

Acct-Session-ID

1

[87]

Nas-Port-ID

5

[26–159]

DHCP- Option-82

6

Table 2: RADIUS Attributes Used as Packet Mirroring Triggers (Vendor ID 3561)

Standard Number

Attribute Name

Order of Preference

[26-1]

Agent-Circuit-ID

7

[26-2]

Agent-Remote-ID

8

You add the trigger to the RADIUS record of the user whose traffic will be mirrored. In addition, you must include the RADIUS VSAs listed in Table 3 in the mirrored user’s RADIUS record.

Note: For IP mirroring, you must include both VSA 26-59 and VSA 26-61, or you must omit both of these VSAs. If you use only one of these VSAs, the configuration fails.

Table 3: RADIUS-Based Mirroring Attributes

Standard Number

Attribute Name

Setting

[26-58]

LI-Action

0 = disable mirroring
1 = enable mirroring
2 = no action

[26-59]

Med-Dev-Handle

String (not null-terminated)

[26-60]

Med-IP-Address

IP address of analyzer device

[26-61]

Med-Port-Number

UDP port number of monitoring application in analyzer device

An LI-Action setting of 2 specifies that the router does not perform any packet mirroring–related configuration. This setting can provide additional security by confusing unauthorized users who attempt to access packet mirroring communication between the router and the RADIUS server.

 

Related Documentation

  • RADIUS-Based Mirroring Overview
  • RADIUS-Based Mirroring Sequence of Events
 

Published: 2012-06-21

 
  • About Juniper
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Green Networking
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Developers
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out