Configuring Access Guardian Bring Your Own Devices (BYOD) Overview
OmniSwitch AOS Release 8 Network Configuration Guide December 2017 page 28-119
41 DM-ACK On reception of Disconnect request message (DM), all device
authentication is removed from the switch.
Disconnect request message (DM) Acknowledgment for
RADIUS/UPAM or ClearPass authentication
42 DM-NACK Disconnect request message (DM) Not Acknowledged
43 CoA-Request CoA message is sent from UPAM or ClearPass Server. CoA-
Request packets contain information for dynamically changing
session authorizations.The following attributes are used:
• The User-Name: AOS retrieves the MAC address associated
to this user
• The Calling-Station-ID: This explicitly specify the user
MAC address
When the message contains both the User-Name and Calling-
Station-ID, the MAC address is identified based on the Calling-
Station-ID only.
44 CoA-ACK Supports a Change of Authorization-Request (CoA) message for
RADIUS authentication.COA-ACK is sent by OmniSwitch to
UPAM or ClearPass that has attributes MD5 hash value and
Identifier.
45 CoA-NACK COA-NACK message is sent from OmniSwitch. For NAK
message, the Error-Cause attribute must be supported and filled
accordingly.
Error-Cause Supported as part of CoA-NAK and DM-NAK message. Error-
Cause Scenarios:
Missing Attribute - If User name and Calling station ID Filter
ID not present
Invalid Request - If Client context does not exist
Unsupported Attribute - Request contains an unsupported
Vendor-Specific attribute
Unsupported Service - Request contains an unsupported or
invalid service in Service-Type attribute
Nas Identification Mismatch - Request contains one or more
NAS identification attributes that does not match the identity of
the NAS receiving the request
Administratively Prohibited - NAS prohibiting the Request
messages for the specified session
Session Context Not Found - Session context identified in the
request does not exist on the NAS
Resources Unavailable - Request could not be honored due to
lack of available NAS resources