User's Manual

Table Of Contents
PMP 450 Operations Guide
Configuring a RADIUS server
pmp-0049 (September 2012)
2-33
If an operator clears the VC statistics on the device through the management GUI, a RADIUS stop
message and data start message will be issued for each device affected. The start and stop messages
will only be sent once every 5 minutes, so if an operator clears these statistics multiple times within 5
minutes, only one set of data stop/start messages will be sent. This may result in inaccurate data
accumulation results.
RADIUS Device Re-Authentication
PMP 450 systems include support for periodic SM re-authentication in a network without requiring the
SM to re-register (and drop the session). The re-authentication may be configured to occur in the range
of every 30 minutes to weekly.
Table 15 Device re-authentication configuration
The re-authentication interval is only configurable on the AP. When this feature is enabled, each SM
that enters the network will re-authenticate each the interval time has expired without dropping the
session. The response that the SM receives from the AAA server upon re-authentication is one of the
following:
Success: The SM will continue normal operation
Reject: The SM will de-register and will attempt network entry again after 1 minute and then if
rejected will attempt re-entry every 15 minutes
Timeout or other error: The SM will remain in session and attempt 5 times to re-authenticate with
the RADIUS-REQUEST message. If these attempts fail, then the SM will go out of session and
proceed to re-authenticate after 5 minutes, then every 15 minutes.
Although re-authentication is an independent feature, it was designed to work alongside with the
RADIUS data usage accounting messages. If a user is over their data usage limit the network operator
can reject the user from staying in the network. Operators may configure the RADIUS ‗Reply-
Message‘ attribute with an applicable message (i.e. ―Data Usage Limit Reached‖) that will be sent to
the subscriber module and displayed on the general page.
RADIUS Attribute Framed-IP-Address
Operators may now use a RADIUS AAA server to assign management IP addressing to SM modules
(framed IP address). SMs now interpret attributes Framed-IP-Address, Framed-IP-Netmask, and
Cambium-Gateway from RADIUS. The RADIUS dictionary file has been updated to include the
Cambium-Gateway attribute and is available on the Cambium Software Support website.
In order for these attributes to be assigned and used by the SM, the following must be true: