Chapter 25 AAA
GS2210 Series User’s Guide
219
25.6 Technical Reference
This sect ion pr ovides t echnical backgr ound infor m at ion on t he t opics discussed in t his chapt er.
25.6.1 Vendor Specific Attribute
RFC 2865 st andar d specifies a m et hod for sending vendor- specific infor m at ion bet w een a RADI US
ser ver and a net w or k access device ( for exam ple, t he Sw it ch) . A com pany can cr eat e Vendor
Specific At t r ibut es ( VSAs) t o expand t he funct ionalit y of a RADI US ser ver.
The Swit ch support s VSAs t hat allow you t o per for m t he follow ing act ions based on user
aut hent icat ion:
•
Lim it bandw idt h on incom ing or out going t raffic for t he por t t he user connect s t o.
•
Assign account pr ivilege levels ( See t he CLI Refer ence Guide for m or e infor m at ion on account
pr ivilege levels) for t he aut hent icat ed user.
The VSAs ar e com posed of t he follow ing:
• V e n dor - I D : An ident ificat ion num ber assigned t o t he com pany by t he I ANA ( I nt er net Assigned
Num bers Aut horit y) . Zy XEL’s vendor I D is 890.
• V e n dor - Ty pe : A vendor specified at t r ibut e, ident ifying t he set t ing you want t o m odify.
• V e n dor - da t a : A value you want t o assign t o t he set t ing.
Not e: Refer t o t he docum ent at ion t hat com es w it h your RADI US ser ver on how t o
configur e VSAs for user s aut hent icat ing via t he RADI US ser ver.
Mode
The Sw it ch suppor t s t w o m odes of r ecor ding login event s. Select :
• st a r t - st op - t o have t he Sw it ch send infor m at ion t o t he account ing ser ver w hen a user
begins a session, dur ing a user ’s session ( if it last s past t he Upda t e Pe r iod ) , and w hen a
user ends a session.
• st op- on ly - t o have t he Sw it ch send infor m at ion t o t he account ing ser ver only w hen a
user ends a session.
Met hod
Select w het her you want t o use RADI US or for account ing of specific t y pes of
event s.
is t he only m et hod for r ecor ding Com m a n ds t ype of event .
Pr iv ilege
This field is only configurable for Com m a n d s t y pe of event . Select t he t hr eshold com m and
pr iv ilege level for w hich t he Sw it ch should send account ing infor m at ion. The Sw it ch w ill
send account ing infor m at ion w hen com m ands at t he level you specify and higher ar e
execut ed on t he Sw it ch.
Apply
Click App ly t o save your changes t o t he Sw it ch’s r un- t im e m em or y. The Sw it ch loses t hese
changes if it is t ur ned off or loses pow er, so use t he Sa v e link on t he t op nav igat ion panel
t o save your changes t o t he non- volat ile m em ory w hen you ar e done configuring.
Cancel
Click Ca n ce l t o begin configur ing t his scr een afr esh.
Table 94
Advanced Applicat ion > AAA > AAA Set up ( cont inued)
LABEL
DESCRIPTION