RADIUS ATTRIBUTES REFERENCE GUIDE 
RELEASE 14.0.R4
RADIUS Attributes Reference
Issue: 01 3HE 10793 AAAB TQZZA 01 143
 
80 Message-
Authenticator
This attribute is used in EAP authentication and provides message 
integrity verification.
87 Nas-Port-Id The public SAP ID of IKEv2 remote-access tunnel. The attribute can be 
included/excluded with configure ipsec radius-authentication-policy 
policy-name include-radius-attribute nas-port-id or configure ipsec 
radius-accounting-policy policy-name include-radius-attribute nas-
port-id.
88 Framed-Pool The name of one IPv4 address pool or the name of a primary and 
secondary IPv4 address pool separated with a one character 
configurable delimiter (configure router | service vprn service-id dhcp 
local-dhcp-server server-name use-pool-from-client delimiter 
delimiter) that should be used for local address assignment during 
IKEv2 remote-access tunnel setup. A RADIUS server can include the 
attribute in an Access-Accept. The value of this attribute overrides the 
local configured value in the …>ipec-gw>local-address-
assignment>ipv4 CLI context.
97 Framed-IPv6-Prefix The IPv6 address to be assigned to IKEv2 remote-access tunnel client 
via IKEv2 configuration payload: INTERNAL_IP6_ADDRESS. The 
prefix and prefix-length of Framed-IPv6-Prefix are conveyed in the 
corresponding part of INTERNAL_IP6_ADDRESS. The attribute is 
included in RADIUS accounting request packet.
100 Framed-IPv6-Pool The name of the IPv6 address pool used for local address assignment 
during IKEv2 remote-access tunnel setup. A RADIUS server can 
include the attribute in an Access-Accept. The value of this attribute 
overrides the local configured value in the …>ipec-gw>local-address-
assignment>ipv6 CLI context.
26-311-16 MS-MPPE-Send-Key This attribute along with [26-311-17] MS-MPPE-Recv-Key hold the 
Master Session Key (MSK) of the EAP authentication. It is expected in 
access-accept when EAP authentication succeed with certain EAP 
methods.
26-311-17 MS-MPPE-Recv-Key This attribute along with [26-311-16] MS-MPPE-Send-Key hold the 
Master Session Key (MSK) of the EAP authentication. It is expected in 
access-accept when EAP authentication succeed with certain EAP 
methods.
26-6527-9 Alc-Primary-Dns The IPv4 DNS server address to be assigned to an IKEv1/v2 remote-
access tunnel client via configuration payload: INTERNAL_IP4_DNS. In 
case of IKEv2, up to four DNS server addresses can be returned to a 
client, including Alc-Primary-Dns, Alc-Secondary-Dns, Alc-Ipv6-
Primary-Dns and Alc-Ipv6-Secondary-Dns.
Table 48 IPSec (Description) (Continued)
Attribute ID Attribute Name Description