The RADIUS CoA feature supports five IETF attributes as defined in RFC 5176. These are:
Event-Timestamp: This attribute indicates the time when the CoA request was generated by the server.
State: This attribute contains a value that is copied from the Access-Accept message that authorized the session.
Session-Timeout: This attribute specifies the maximum number of seconds of service provided to the user before termination of the session or prompt.
Idle-Timeout: This attribute specifies the maximum number of consecutive seconds of idle connection allowed to the user before termination of the session or prompt.
Filter-Id: This attribute identifies the filter list to be applied to the user session.
The RADIUS CoA feature also supports vendor-specific attributes (VSAs) that are defined by Cisco or other vendors. These VSAs can be used to perform additional actions such as port shutdown, port bounce, or security and password accounting. References :=
Some possible references are:
RFC 5176: This document describes the dynamic authorization extensions to RADIUS, including the CoA request and response codes, and the supported IETF attributes.
RADIUS Change of Authorization - Cisco: This document provides the configuration guide for the RADIUS CoA feature on Cisco IOS devices, including the supported IETF and Cisco VSAs.
Supported IETF attributes in RFC 5176 - Ruckus Networks: This document lists the supported IETF attributes and error clause values for the RADIUS CoA feature on Ruckus devices.
V
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit