RADIUS Attributes Reference
7750 SR RADIUS Attributes Reference Guide Page 121
46 Acct-Session-Time This attribute represents the tunnel’s lifetime in seconds. It is included in an
Accounting-Stop packet.
79 EAP-Message This attribute encapsulates the received IKEv2 EAP payload in access-
request. A RADIUS server can include this attribute in an access-challenge or
access-accept.
80 Message-Authenticator This attribute is used in EAP authentication and provides message integrity
verification.
87 Nas-Port-Id The public SAP ID of IKEv2 remote-access tunnel. The attribute can be
included/excluded with configure ipsec radius-authentication-policy
<policy-name> include-radius-attribute nas-port-id or configure ipsec
radius-accounting-policy <policy-name> include-radius-attribute nas-
port-id.
97 Framed-IPv6-Prefix The IPv6 address to be assigned to IKEv2 remote-access tunnel client via
IKEv2 configuration payload: INTERNAL_IP6_ADDRESS. The prefix and
prefix-length of Framed-IPv6-Prefix are conveyed in the corresponding part
of INTERNAL_IP6_ADDRESS. The attribute is included in RADIUS
accounting request packet.
26-311-16 MS-MPPE-Send-Key This attribute along with [26-311-17] MS-MPPE-Recv-Key hold the Master
Session Key (MSK) of the EAP authentication. It is expected in access-accept
when EAP authentication succeed with certain EAP methods.
26-311-17 MS-MPPE-Recv-Key This attribute along with [26-311-16] MS-MPPE-Send-Key hold the Master
Session Key (MSK) of the EAP authentication. It is expected in access-accept
when EAP authentication succeed with certain EAP methods.
26-6527-9 Alc-Primary-Dns The IPv4 DNS server address to be assigned to an IKEv1/v2 remote-access
tunnel client via configuration payload: INTERNAL_IP4_DNS. In case of
IKEv2, up to four DNS server addresses can be returned to a client, including
Alc-Primary-Dns, Alc-Secondary-Dns, Alc-Ipv6-Primary-Dns and Alc-Ipv6-
Secondary-Dns.
26-6527-10 Alc-Secondary-Dns The IPv4 DNS server address to be assigned to an IKEv2 remote-access
tunnel client via IKEv2 configuration payload: INTERNAL_IP4_DNS. Up to
four DNS server addresses can be returned to a client, including Alc-Primary-
Dns, Alc-Secondary-Dns, Alc-Ipv6-Primary-Dns and Alc-Ipv6-Secondary-
Dns.
26-6527-61 Alc-IPsec-Serv-Id IPSec private service id, used by IKEv1/v2 remote-access tunnel, referring to
the preconfigured VPRN where the IPSec tunnel terminates (configure
service vprn <service-id>). A default private service is used when this
attribute is omitted (configure service vprn interface sap ipsec-gw default-
secure-service). If the returned service id doesn't exist/out-of limits or exists
but not a VPRN service, the tunnel setup will fail.
Table 38: IPSEC (description) (Continued)
Attribute ID Attribute Name Description