Users Guide

Authentication, Authorization, and Accounting 267
SERVICE-TYPE
The Service-Type attribute may be validated in the Access-Accept packet
received from the RADIUS server. Only the Login-User(1),
Administrative-User(6), and Call-Check(10) values are considered valid
for Service-Type in the Access-Accept message returned from the RADIUS
server.
SESSION-TIMEOUT
Session time-out value for the session (in seconds). Used by both 802.1x
and Captive Portal.
TERMINATION-ACTION
Indication as to the action taken when the service is completed.
EAP-MESSAGE
Contains an EAP message to be sent to the user. This is typically used for
MAB clients.
VENDOR-SPECIFIC
The following vendor proprietary (vendor ID 9, sub-type 1) AV Pairs are
supported:
shell:priv-lvl
shell:roles
ip:inacl={standard-access-control-list-name | extended-access-
control-list-name}
ipv6:inacl={standard-access-control-list-name | extended-access-
control-list-name}
ip:inacl[#number]={extended-access-control-list}
ip:outacl[#number]={extended-access-control-list}
ipv6:inacl[#number]={extended-access-control-list}
ipv6:outacl[#number]={extended-access-control-list}
ip:traffic-class={existing ACL name}
device-traffic-class=switch
subscriber:command=reauthenticate (COA only)
subscriber:command=bounce-host-port (COA only)