Administrator Guide
286 Authentication, Authorization, and Accounting
RADIUS server state. Transmitted in Access-Request and Accounting-
Request messages.
• SERVICE-TYPE
The Service-Type attribute may be validated in the Access-Accept packet
received from the RADIUS server. Only the Login-User(1) and
Administrative-User(6) values are considered valid for Service-Type in the
Access-Accept message returned from the RADIUS server.
• SESSION-TIMEOUT
Session time-out value for the session (in seconds). Used by both 802.1x
and Captive Portal.
• TERMINATION-ACTION
Indication as to the action taken when the service is completed.
• EAP-MESSAGE
Contains an EAP message to be sent to the user. This is typically used for
MAB clients.
• VENDOR-SPECIFIC
The following Cisco AV Pairs are supported:
– shell:priv-lvl
– shell:roles
• FILTER-ID
Name of an existing DiffServ policy for this user.
• TUNNEL-TYPE
Used to indicate that a VLAN is to be assigned to the user when set to
tunnel type VLAN (13).
• TUNNEL-MEDIUM-TYPE
Used to indicate the tunnel medium type. Must be set to medium type
802 (6) to enable VLAN assignment.
• TUNNEL-PRIVATE-GROUP-ID