RADIUS ATTRIBUTES REFERENCE GUIDE
RELEASE 14.0.R4
RADIUS Attributes Reference
Issue: 01 3HE 10793 AAAB TQZZA 01 143
80 Message-
Authenticator
This attribute is used in EAP authentication and provides message
integrity verification.
87 Nas-Port-Id The public SAP ID of IKEv2 remote-access tunnel. The attribute can be
included/excluded with configure ipsec radius-authentication-policy
policy-name include-radius-attribute nas-port-id or configure ipsec
radius-accounting-policy policy-name include-radius-attribute nas-
port-id.
88 Framed-Pool The name of one IPv4 address pool or the name of a primary and
secondary IPv4 address pool separated with a one character
configurable delimiter (configure router | service vprn service-id dhcp
local-dhcp-server server-name use-pool-from-client delimiter
delimiter) that should be used for local address assignment during
IKEv2 remote-access tunnel setup. A RADIUS server can include the
attribute in an Access-Accept. The value of this attribute overrides the
local configured value in the …>ipec-gw>local-address-
assignment>ipv4 CLI context.
97 Framed-IPv6-Prefix The IPv6 address to be assigned to IKEv2 remote-access tunnel client
via IKEv2 configuration payload: INTERNAL_IP6_ADDRESS. The
prefix and prefix-length of Framed-IPv6-Prefix are conveyed in the
corresponding part of INTERNAL_IP6_ADDRESS. The attribute is
included in RADIUS accounting request packet.
100 Framed-IPv6-Pool The name of the IPv6 address pool used for local address assignment
during IKEv2 remote-access tunnel setup. A RADIUS server can
include the attribute in an Access-Accept. The value of this attribute
overrides the local configured value in the …>ipec-gw>local-address-
assignment>ipv6 CLI context.
26-311-16 MS-MPPE-Send-Key This attribute along with [26-311-17] MS-MPPE-Recv-Key hold the
Master Session Key (MSK) of the EAP authentication. It is expected in
access-accept when EAP authentication succeed with certain EAP
methods.
26-311-17 MS-MPPE-Recv-Key This attribute along with [26-311-16] MS-MPPE-Send-Key hold the
Master Session Key (MSK) of the EAP authentication. It is expected in
access-accept when EAP authentication succeed with certain EAP
methods.
26-6527-9 Alc-Primary-Dns The IPv4 DNS server address to be assigned to an IKEv1/v2 remote-
access tunnel client via configuration payload: INTERNAL_IP4_DNS. In
case of IKEv2, up to four DNS server addresses can be returned to a
client, including Alc-Primary-Dns, Alc-Secondary-Dns, Alc-Ipv6-
Primary-Dns and Alc-Ipv6-Secondary-Dns.
Table 48 IPSec (Description) (Continued)
Attribute ID Attribute Name Description