Cisco 10000-2P2-2DC Software Guide - Page 349

Feature History for Extended NAS-Port-Type and NAS-Port Support, NAS-Port-Type (RADIUS Attribute 61

Page 349 highlights

Chapter 16 Configuring RADIUS Features Extended NAS-Port-Type and NAS-Port Support Feature History for Extended NAS-Port-Type and NAS-Port Support Cisco IOS Release 12.3(7)XI1 12.2(28)SB Description This feature was introduced on the Cisco 10000 series router. This feature was integrated into Cisco IOS Release 12.2(28)SB. Required PRE PRE2 PRE2 NAS-Port-Type (RADIUS Attribute 61) Remote Authentication Dial-In User Service (RADIUS) attributes are used to define specific Authentication, Authorization, and Accounting (AAA) elements in a user profile, which is stored on the RADIUS daemon. Currently the Internet Engineering Task Force (IETF) RADIUS attributes that are supported include an attribute 61, NAS-Port-Type. NAS-Port-Type indicates the type of physical port the network access server (NAS) is using to authenticate the user. However there was no method to identify NAS-Port-Type based on a specific broadband service type because the RADIUS RFC does not support extended types that defines these types of ports. Basically all PPPoA, PPPoEoE, and PPPoEoA sessions were identified as being VIRTUAL and all PPPoEoVLAN and PPPoEoQinQ as ETHERNET. The Extended NAS-Port-Type Attribute Support feature expands NAS-Port-Type, attribute 61, in order that the client can better identify what type of service is taking place on the different types of ports. One advantage of this feature is that service providers can have their own coding mechanism to track users on given ports differently. Service providers may especially want to track customers using shared resources such as Ethernet or ATM interfaces that have VLANs (or Q-in-Q) and VCs connected to certain customers. The configuration command radius-server attribute 61 extended enables identifying the following new non-RFC compliant, broadband service port types that are indicated by the following numeric values: • Value 30: PPPoA • Value 31: PPPoEoA • Value 32: PPPoEoE • Value 33: PPPoEoVLAN • Value 34: PPPoEoQinQ An additional capability is that subinterfaces such as VLAN, Q-in-Q, VC, or VC ranges are allowed to override the NAS-Port-Type attribute value to be sent on any session that resides on it. This capability provides an extra level of granularity for service providers in managing their end users and allows for further differentiation of different customer usage. This capability is provided with the radius attribute nas-port-type [value] command. The value for NAS-Port-Type can be any number chosen by the customer. In particular, customizing your own value is useful when you need to differentiate the NAS-Port-Type based on which type of end client is actually using the port. For example if you want to track mobile clients behind a specific PVC, you can define your own NAS-Port-Type for mobile clients. OL-2226-23 Cisco 10000 Series Router Software Configuration Guide 16-45

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576
  • 577
  • 578
  • 579
  • 580
  • 581
  • 582
  • 583
  • 584
  • 585
  • 586
  • 587
  • 588
  • 589
  • 590
  • 591
  • 592
  • 593
  • 594
  • 595
  • 596
  • 597
  • 598
  • 599
  • 600
  • 601
  • 602
  • 603
  • 604
  • 605
  • 606
  • 607
  • 608
  • 609
  • 610
  • 611
  • 612
  • 613
  • 614
  • 615
  • 616
  • 617
  • 618
  • 619
  • 620
  • 621
  • 622
  • 623
  • 624

16-45
Cisco 10000 Series Router Software Configuration Guide
OL-2226-23
Chapter 16
Configuring RADIUS Features
Extended NAS-Port-Type and NAS-Port Support
Feature History for Extended NAS-Port-Type and NAS-Port Support
NAS-Port-Type (RADIUS Attribute 61)
Remote Authentication Dial-In User Service (RADIUS) attributes are used to define specific Authentication,
Authorization, and Accounting (AAA) elements in a user profile, which is stored on the RADIUS daemon.
Currently the Internet Engineering Task Force (IETF) RADIUS attributes that are supported include an
attribute 61, NAS-Port-Type. NAS-Port-Type indicates the type of physical port the network access
server (NAS) is using to authenticate the user.
However there was no method to identify NAS-Port-Type based on a specific broadband service type
because the RADIUS RFC does not support extended types that defines these types of ports. Basically
all PPPoA, PPPoEoE, and PPPoEoA sessions were identified as being VIRTUAL and all PPPoEoVLAN
and PPPoEoQinQ as ETHERNET.
The Extended NAS-Port-Type Attribute Support feature expands NAS-Port-Type, attribute 61, in order
that the client can better identify what type of service is taking place on the different types of ports.
One advantage of this feature is that service providers can have their own coding mechanism to track
users on given ports differently. Service providers may especially want to track customers using shared
resources such as Ethernet or ATM interfaces that have VLANs (or Q-in-Q) and VCs connected to
certain customers.
The configuration command
radius-server attribute 61 extended
enables identifying the following
new non-RFC compliant, broadband service port types that are indicated by the following numeric
values:
Value 30: PPPoA
Value 31: PPPoEoA
Value 32: PPPoEoE
Value 33: PPPoEoVLAN
Value 34: PPPoEoQinQ
An additional capability is that subinterfaces such as VLAN, Q-in-Q, VC, or VC ranges are allowed to
override the NAS-Port-Type attribute value to be sent on any session that resides on it. This capability
provides an extra level of granularity for service providers in managing their end users and allows for
further differentiation of different customer usage. This capability is provided with the
radius attribute
nas-port-type
[
value
] command.
The value for NAS-Port-Type can be any number chosen by the customer. In particular, customizing your
own value is useful when you need to differentiate the NAS-Port-Type based on which type of end client
is actually using the port. For example if you want to track mobile clients behind a specific PVC, you
can define your own NAS-Port-Type for mobile clients.
Cisco IOS Release
Description
Required PRE
12.3(7)XI1
This feature was introduced on the Cisco 10000 series
router.
PRE2
12.2(28)SB
This feature was integrated into Cisco IOS Release
12.2(28)SB.
PRE2