11
No. Attribute No. Attribute
32 NAS-Identifier 79 EAP-Message
33 Proxy-State 80 Message-Authenticator
34 Login-LAT-Service 81 Tunnel-Private-Group-id
35 Login-LAT-Node 82 Tunnel-Assignment-id
36 Login-LAT-Group 83 Tunnel-Preference
37 Framed-AppleTalk-Link 84 ARAP-Challenge-Response
38 Framed-AppleTalk-Network 85 Acct-Interim-Interval
39 Framed-AppleTalk-Zone 86 Acct-Tunnel-Packets-Lost
40 Acct-Status-Type 87 NAS-Port-Id
41 Acct-Delay-Time 88 Framed-Pool
42 Acct-Input-Octets 89 (unassigned)
43 Acct-Output-Octets 90 Tunnel-Client-Auth-id
44 Acct-Session-Id 91 Tunnel-Server-Auth-id
Extended RADIUS attributes
Attribute 26 (Vendor-Specific), an attribute defined in RFC 2865, allows a vendor to define extended
attributes to implement functions that the standard RADIUS protocol does not provide.
A vendor can encapsulate multiple sub-attributes as TLVs in attribute 26 to provide extended
functions. As shown in Figure 5, a sub-attribute en
capsulated in attribute 26 consists of the following
parts:
• Vendor-ID—ID of the vendor. Its most significant byte is 0. The other 3 bytes contains a code
that is compliant to RFC 1700. The vendor ID is 25506. For more information about the
proprietary RADIUS sub-attributes (vendor ID 25506), see "Proprietary RADIUS sub-attributes
(v
endor ID 25506)."
• Vendor-Type—Type of the sub-attribute.
• Vendor-Length—Length of the sub-attribute.
• Vendor-Data—Contents of the sub-attribute.
Figure 5 Format of attribute 26
HWTACACS
HW Terminal Access Controller Access Control System (HWTACACS) is an enhanced security
protocol based on TACACS (RFC 1492). Similar to RADIUS, it uses a client/server model for
information exchange between the NAS and the HWTACACS server.