Operation Manual
Session Management Commands
Session Management Commands
19 – 459
Vlan-Name
(and other
attributes if
set)
Authorization attributes for the user and how they were assigned (the sources of the attribute
values).
For Vlan-Name, the source of the attribute value can be one of the following:
❑ AAA—VLAN is from RADIUS or the local database.
❑ initial-assignment—For a client that has roamed from one MX to another, VLAN is the one
assigned to the user on the MX where the user first accessed the network. (This is the MX
where the client’s global session in the Mobility Domain started.)
This authorization source (initial-assignment) is displayed only if the following conditions are
true:
• The client roamed from another MX.
• The service profile for the SSID the user is on is configured to keep the client’s initial VLAN
assignment. (This means the keep-initial-vlan option is enabled on the service profile.)
• The VLAN is not configured for the user on the roamed-to switch by the local database.
• A Location Policy on the roamed-to MX does not set the VLAN.
❑ location policy—Attribute value was assigned by a Location Policy.
❑ service-profile—Attribute value is configured on the SSID, and was not overridden by other
attribute sources (such as AAA or location policy).
❑ Web Portal—Session is for a Web Portal client.
Table 19– 6. show sessions network session-id Output
Field Description
Local Id Identifier for the session on this particular MX. (This is the session ID you specify when
entering the show sessions network session-id command.)
Global Id Unique session identifier within the Mobility Domain.
State Status of the session:
❑ AUTH, ASSOC REQ—Client is associating by the 802.1X protocol.
❑ AUTH AND ASSOC—Client is associating by the 802.1X protocol, and the user is
authenticating.
❑ AUTHORIZING—User is authenticated (for example, by the 802.1X protocol and an
AAA method), and is entering AAA authorization.
❑ AUTHORIZED—User is authorized by an AAA method.
❑ ACTIVE—User’s AAA attributes are applied, and the user is active on the network.
State,
cont.
❑ DEASSOCIATED—One of the following:
• Wireless client has sent the MX a disassociate message.
• User associated with one of the MPs of the current MX has appeared at another MX
in the Mobility Domain.
❑ ROAMING AWAY—The MX was sent a request to transfer the user, who is roaming, to
another MX.
❑ STATUS UPDATED—MX is receiving a final update from an MP about the user, who
has roamed away.
❑ WEB_AUTHING—User is authenticating by WebAAA.
❑ WIRED AUTH’ING—User is authenticating by the 802.1X protocol on a wired
authentication port.
❑ KILLING—User’s session is cleared, because of 802.1X authentication failure, entry of
a clear command, or some other event.
SSID Name of the SSID of the user.
AP/Radio Number of the port and radio that the user is accessing for this session.
MAC address MAC address of the session user.
User Name Name of the authenticated user of this session
IP Address IP address of the session user.
Vlan Name Name of the VLAN associated with the session.
Table 19– 5. Additional show sessions network verbose
Output (continued)
Field Description