Security
Using an external RADIUS server
6-7
Vendor-specific attribute type number = 0
Attribute type: A string in the following format <keyword>=<value>
Access Accept attributes
This table lists all attributes supported in Access Accept packets for each authentication
type.
Descriptions
Acct-Interim-Interval (32-bit unsigned integer): When present, enables the
transmission of RADIUS accounting requests of the Interim Update type. Specify the
number of seconds between each transmission.
Class (string): As defined in RFC 2865.
EAP-Message (string): Note that the content will not be read as the RADIUS Access
Accept overrides whatever indication is contained inside this packet.
Idle-Timeout (32-bit unsigned integer): Maximum idle time in seconds allowed for the
user. Once reached, the user session is terminated with termination-cause IDLE-
TIMEOUT. Omitting the attribute or specifying 0 disables the feature.
Session-Timeout (32-bit unsigned integer): Maximum time a session can be active. After
this interval:
802.1X clients are automatically re-authenticated.
Attribute Admin login 802.1X MAC
Acct-Interim-Interval ✕✔✔
Class ✕✔✔
EAP-Message ✔✔✕
Idle-Timeout ✕✔✕
MS-MPPE-Recv-Key ✕✔✕
MS-MPPE-Send-Key ✕✔✕
Session-TImeout ✕✔✔
Termination-Action ✕✔✔
Tunnel-Medium-Type ✕✔✕
Tunnel-Private-Group-ID ✕✔✕
Tunnel-Type ✕✔✕
Vendor-specific (Microsoft)
MS-MPPE-Recv-Key
MS-MPPE-Send-Key
✕
✕
✔
✔
✕
✕