Users Guide

Security Commands 956
radius server attribute 168
Use the radius server attribute 168 include-in-access-req command to enable
the switch to send the RADIUS Framed-IPv6-Address attribute in Access-
Request messages sent to the RADIUS authentication server.
Syntax
radius server attribute 168 include-in-access-req
no radius server attribute 168 include-in-access-req
Default Configuration
By default, RADIUS attribute 168 is not sent.
Command Mode
Global Configuration mode.
User Guidelines
The switch sends the IPv6 address of the host attempting to access the
network in the Framed-IPv6-Address attribute if it is available to the switch.
If accounting is enabled and the address is available to the switch, the switch
will send the IPv6 address in the Access-Request, Acct-Start/Acct-
Interim/Acct-Stop messages sent to the accounting server.
The switch discovers the client IPv6 address via its inclusion in the RADIUS
Access-Accept, or via DHCPv6 snooping. DHCPv6 snooping must be enabled
for the switch to discover a host IPv6 address.
After an Access-Accept has been received by the switch and the switch grants
the host access to the network, it may take a few seconds before the DHCPv6
transaction completes. Use the aaa accounting delay-start command to delay
the sending of the Acct-Start packet to the accounting server. Accounting
messages are not sent for hosts placed in the Guest VLAN.
Use the show dot1x clients command to display the RADIUS Server supplied
IPv6 address, if any.
RADIUS attribute 168 Framed-IPv6-Address is defined in RFC 6911.