CoA NAK Response Code 65
CoA Request Commands 65
Session Reauthentication 66
Session Reauthentication in a Switch Stack 66
Session Termination 67
CoA Disconnect-Request 67
CoA Request: Disable Host Port 67
CoA Request: Bounce-Port 68
Stacking Guidelines for Session Termination 68
Stacking Guidelines for CoA-Request Bounce-Port 68
Stacking Guidelines for CoA-Request Disable-Port 69
Default RADIUS Configuration 69
RADIUS Server Host 69
RADIUS Login Authentication 70
AAA Server Groups 70
AAA Authorization 71
RADIUS Accounting 71
Vendor-Specific RADIUS Attributes 71
Vendor-Proprietary RADIUS Server Communication 83
How to Configure RADIUS 83
Identifying the RADIUS Server Host 83
Configuring RADIUS Login Authentication 86
Defining AAA Server Groups 88
Configuring RADIUS Authorization for User Privileged Access and Network Services 90
Starting RADIUS Accounting 92
Establishing a Session with a Router if the AAA Server is Unreachable 93
Configuring Settings for All RADIUS Servers 93
Configuring the Switch to Use Vendor-Specific RADIUS Attributes 95
Configuring the Switch for Vendor-Proprietary RADIUS Server Communication 97
Configuring CoA on the Switch 98
Configuring RADIUS Server Load Balancing 101
Monitoring CoA Functionality 101
Configuration Examples for Controlling Switch Access with RADIUS 102
Examples: Identifying the RADIUS Server Host 102
Example: Using Two Different RADIUS Group Servers 102
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
vi OL-29048-01
Contents