Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asean Region (Vietnam, Indonesia, Singapore, Malaysia)
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center

Technical Documentation

Support
Technical Documentation
Content Explorer New
 
Enterprise MIBs
 
EOL Documentation
 
Feature Explorer Login required New
 
File Format Help
 
Glossary
 
Portable Libraries
 
 
Home > Support > Technical Documentation > JunosE Software > Understanding Service Manager RADIUS Attributes
Print
Rate and give feedback:  Feedback Received. Thank You!
Rate and give feedback: 
Close
This document helped resolve my issue.  Yes No

Additional Comments

800 characters remaining

May we contact you if necessary?

Name:  
E-mail: 
Submitting...
 

Related Documentation

  • Service Session Profiles Overview
  • Working with Service Session Profiles
  • Overview of Managing and Activating Service Sessions
  • Overview of Managing Subscriber Service Sessions Using RADIUS
  • Understanding RADIUS Accounting for Service Manager
  • Activating Subscriber Service Sessions Using RADIUS
  • Deactivating Service Sessions Using RADIUS
 

Understanding Service Manager RADIUS Attributes

For the RADIUS login method, the RADIUS VSAs for service activation, threshold configuration, statistics configuration, and interim accounting in Access-Accept messages at subscriber login are used by Service Manager to activate the appropriate service session. For the RADIUS CoA method, Service Manager uses the VSAs for service activation and deactivation, threshold configuration, statistics configuration, and interim accounting in CoA-Request messages to activate the service session. The accounting-related VSAs are included in RADIUS accounting messages.

Table 1 lists the Service Manager-related attributes and indicates which are tagged VSAs. See Using Tags with RADIUS Attributes for a discussion about using tagged VSAs to group attributes for a service.

Table 1: Service Manager RADIUS Attributes

Attribute Number

Attribute Name

RADIUS Message Type

VSA Description

[1]

User-Name (used with Virtual-Router, Juniper Networks VSA 26-1)

Access-Accept

Uniquely identifies the subscriber session

[8]

Framed-IP-Address (used with Virtual-Router, Juniper Networks VSA 26-1)

Access-Accept

Uniquely identifies the subscriber session

[26-65]

Activate-Service

Access-Accept and CoA-Request

Name of the service to be activated; includes parameter values; a tagged VSA

[26-66]

Deactivate-Service

Access-Accept and CoA-Request

Name of the service to be deactivated

Note: This VSA is only used by CoA.

[26-67]

Service-Volume

Access-Accept and CoA-Request

Number of MB of traffic that the service can consume; the service is terminated when output byte count exceeds this value; a tagged VSA

[26-68]

Service-Timeout

Access-Accept and CoA-Request

Number of seconds that the service is to remain active; the service is terminated when the time expires; a tagged VSA

[26-69]

Service-Statistics

Access-Accept and CoA-Request

Statistics configuration; a tagged VSA:
0 = disable
1 = timestamp only
2 = timestamp and volume

[26-83]

Service-Session

For service sessions only:
Acct-Start
Acct-Stop
Interim-Acct

Name of the service (including parameter values) with which the statistics are associated

[26-140]

Service-Interim-Acct-
Interval

Access-Accept and
CoA-Request

Number of seconds between accounting updates for a service; a tagged VSA

[31]

Calling-Station-ID

Access-Accept

Uniquely identifies the subscriber session

[44]

Acct-Session-ID

Acct-Start
Acct-Stop
Interim-Acct

Accounting identifier that makes it easy to match start and stop records in a log file; the format is extended to include a colon-separated value that uniquely identifies the subscriber session

Note: Service Manager statistics collection is a three-part procedure. You must configure statistics information in the service definition macro file, enable statistics collection in the RADIUS record, and also enable statistics collection for the policy referenced in the service macro using the statistics enabled keyword in the command used for policy attachment in the profile.

The Service-Volume and Service-Timeout VSAs rely on the values captured by the Service Manager statistics feature to determine when a threshold is exceeded. Therefore, you must configure and enable statistics collection to use these attributes. Service-Volume For detailed information about Service Manager statistics see Configuring Service Manager Statistics.

Table 2 describes a partial RADIUS Access-Accept packet that activates a service session for subscriber client1@isp1.com. (The figure in Creating Service Definitions shows the service definition macro file that creates the tiered service.) The session enables the subscriber to use the tiered service with an input bandwidth of 1280000 and output bandwidth of 5120000. The subscriber can use the service for 5 hours (18000 seconds), and Service Manager captures both timestamp and volume statistics during the session (service-statistics value of 2). Also, accounting for the service is updated every 600 seconds (10 minutes).

Table 2: Sample RADIUS Access-Accept Packet

RADIUS Attribute

Tag

Value

username

none

client1@isp1.com

class

none

(binary data)

service-activation

6

tiered(1280000, 5120000)

service-timeout

6

18000

service-statistics

6

2

service-interim-acct-interval

6

600

Using Tags with RADIUS Attributes

Service Manager uses tagged RADIUS VSAs to enable a single RADIUS record to activate multiple service sessions for a subscriber, with each session having unique attributes. A particular tag identifies a specific Activate-Service attribute and all other RADIUS attributes that are associated with that Activate-Service attribute.

You can specify a maximum of 8 tags (1–8), which enables you to activate up to eight unique service sessions for a subscriber in a single RADIUS record. The following are tagged VSAs—they must always have a tag in their RADIUS entry:

  • Activate-Service
  • Service-Statistics
  • Service-Timeout
  • Service-Volume
  • Service-Interim-Acct-Interval

Table 3 describes an Access-Accept packet that activates the two services, tiered and voice, for subscriber client1@isp1.com. Each service has its own unique tag, enabling you to assign attributes for one service, but not the other. For example, the two services have different timeout settings and different interim accounting intervals, and statistics are enabled only for the tiered service.

Table 3: Using Tags

RADIUS Attribute

Tag

Value

username

none

client1@isp1.com

class

none

(binary data)

service-activation

2

tiered(1280000, 5120000)

service-timeout

2

18000

service-statistics

2

1

service-interim-acct-interval

2

600

service-activation

6

voice(100000)

service-timeout

6

1440

service-interim-acct-interval

6

1200

 

Related Documentation

  • Service Session Profiles Overview
  • Working with Service Session Profiles
  • Overview of Managing and Activating Service Sessions
  • Overview of Managing Subscriber Service Sessions Using RADIUS
  • Understanding RADIUS Accounting for Service Manager
  • Activating Subscriber Service Sessions Using RADIUS
  • Deactivating Service Sessions Using RADIUS
 

Published: 2012-06-27

 
  • About Juniper
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Green Networking
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Developers
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out