<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC WLAN Authentication from External RADIUS Server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357288#M89258</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for reply but i mean which message External Radius Server can sent to Wireless Lan Controller to disconnect Client Session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Dec 2013 13:35:26 GMT</pubDate>
    <dc:creator>Ahmed Ayaad</dc:creator>
    <dc:date>2013-12-16T13:35:26Z</dc:date>
    <item>
      <title>WLC WLAN Authentication from External RADIUS Server</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357286#M89249</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to make WLC Receive PoD (Packet of Disconnect) from the RADIUS server to terminate the session and disconnect authenticating clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357286#M89249</guid>
      <dc:creator>Ahmed Ayaad</dc:creator>
      <dc:date>2019-03-11T04:11:29Z</dc:date>
    </item>
    <item>
      <title>WLC WLAN Authentication from External RADIUS Server</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357287#M89254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahmed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the wireless controller side of it if this is a Cisco one:&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-weight: bold;"&gt;config radius auth rfc3576 {enable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; | &lt;/P&gt;&lt;P&gt; &lt;STRONG style="font-weight: bold;"&gt;disable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;} &lt;/P&gt;&lt;P&gt; &lt;EM style="font-weight: bold;"&gt;index&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;—Enables&amp;nbsp; or disables RFC 3576, which is an extension to the RADIUS protocol that&amp;nbsp; allows dynamic changes to a user session. RFC 3576 includes support for&amp;nbsp; disconnecting users and changing authorizations applicable to a user&amp;nbsp; session and supports disconnect and change-of-authorization (CoA)&amp;nbsp; messages. Disconnect messages cause a user session to be terminated&amp;nbsp; immediately where CoA messages modify session authorization attributes&amp;nbsp; such as data filters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/xe-3se/5700/sec-usr-aaa-xe-3se-5700-book/sec-rad-coa.html"&gt;http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/xe-3se/5700/sec-usr-aaa-xe-3se-5700-book/sec-rad-coa.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-0/configuration/guide/c70/c70sol.html"&gt;http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-0/configuration/guide/c70/c70sol.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Dec 2013 11:51:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357287#M89254</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2013-12-16T11:51:00Z</dc:date>
    </item>
    <item>
      <title>WLC WLAN Authentication from External RADIUS Server</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357288#M89258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for reply but i mean which message External Radius Server can sent to Wireless Lan Controller to disconnect Client Session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Dec 2013 13:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357288#M89258</guid>
      <dc:creator>Ahmed Ayaad</dc:creator>
      <dc:date>2013-12-16T13:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: WLC WLAN Authentication from External RADIUS Server</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357289#M89263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ahmed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its not documented well, but here is it:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;A href="https://cdetsng.cisco.com/webui/#view=CSCso52532" rel="nofollow"&gt;CSCso52532&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;A href="http://wwwin.cisco.com/ops/infra/pds/cbms/cdets/legend.shtml" rel="nofollow" target="_blank" title="Help"&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;No Documentation for sending RADIUS Disconnect-Request (RFC 3576)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="font-family: monospace; font-size: 12px; white-space: -o-pre-wrap; word-wrap: break-word;"&gt;. If a user has to be logged out then, following attributes are expected
&amp;nbsp; - SSH_RADIUS_AVP_SERVICE_TYPE(6) attribte with following value.
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSH_RADIUS_SERVICE_TYPE_LOGIN(1)
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - SSH_RADIUS_AVP_CALLING_STATION_ID(31) - this is needed, if 
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; we want to delete&amp;nbsp; particular user&amp;nbsp; session via particular device 
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (like PDA, Phone or PC)

&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - SSH_RADIUS_AVP_USER_NAME(1)

. If a management user has to be logged out then, following attributes
are expected
&amp;nbsp; - SSH_RADIUS_AVP_SERVICE_TYPE(6) attribte with following value
&amp;nbsp; - SSH_RADIUS_SERVICE_TYPE_ADMINISTRATIVE 
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OR
&amp;nbsp;&amp;nbsp; - SSH_RADIUS_SERVICE_TYPE_NAS_PROMPT
&amp;nbsp;&amp;nbsp; - SSH_RADIUS_AVP_USER_NAME(1)
&amp;nbsp;&amp;nbsp; - SSH_RADIUS_AVP_FRAMED_IP_ADDRESS(8)
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eg:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp; Packet contains 14 AVPs:

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[01] User-Name................................user@domain (17 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[02] Nas-Port.................................0x0000000d (13) (4 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[03] Nas-Ip-Address...........................0x0a0047fb (167790587) (4 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[04] Framed-IP-Address........................0x0a003f1b (167788315) (4 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[05] NAS-Identifier...........................wlcRM_1 (7 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[06] Airespace / WLAN-Identifier..............0x00000004 (4) (4 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[07] Acct-Session-Id..........................4b2a1d0c/00:1c:26:cb:27:71/4 (28 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[08] Acct-Authentic...........................0x00000001 (1) (4 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[09] Tunnel-Type..............................0x0000000d (13) (4 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[10] Tunnel-Medium-Type.......................0x00000006 (6) (4 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[11] Tunnel-Group-Id..........................0x3633 (13875) (2 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[12] Acct-Status-Type.........................0x00000001 (1) (4 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[13] Calling-Station-Id.......................10.0.63.27 (10 bytes)

*Dec 17 12:59:08.926:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[14] Called-Station-Id........................10.0.71.251 (11 bytes)

 

*Dec 17 12:59:10.943: 00:1c:26:cb:27:71 Accounting-Response received from RADIUS server 10.0.71.249 for mobile 00:1c:26:cb:27:71 receiveId = 0

*Dec 17 12:59:34.044: Received a 'RFC-3576 Disconnect-Request' from 10.0.71.249

*Dec 17 12:59:34.044:&amp;nbsp;&amp;nbsp; Packet contains 6 AVPs:

*Dec 17 12:59:34.044:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[01] Nas-Ip-Address...........................0x0a0047fb (167790587) (4 bytes)

*Dec 17 12:59:34.044:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[02] User-Name................................user@domain (17 bytes)

*Dec 17 12:59:34.044:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[03] Acct-Session-Id..........................4b2a1d0c/00:1c:26:cb:27:71/4 (28 bytes)

*Dec 17 12:59:34.044:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[04] Calling-Station-Id.......................10.0.63.27 (10 bytes)

*Dec 17 12:59:34.044:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[05] Called-Station-Id........................10.0.71.251 (11 bytes)

*Dec 17 12:59:34.044:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AVP[06] Service-Type.............................0x00000001 (1) (4 bytes)

*Dec 17 12:59:34.044: Error cause 503 generated for 'RFC-3576 Disconnect-Request' from 10.0.71.249 (Session Identification attributes not valid)

*Dec 17 12:59:34.045: Sent a 'RFC-3576 Disconnect-Nak' to 10.0.71.249:3799

*Dec 17 12:59:36.561: ****Enter processIncomingMessages: response code=5
&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Dec 2013 00:12:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357289#M89263</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2013-12-17T00:12:07Z</dc:date>
    </item>
    <item>
      <title>Hello, Ed!What is the format</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357290#M89266</link>
      <description>&lt;P&gt;Hello, Ed!&lt;/P&gt;&lt;P&gt;What is the format of messages for CoA? I've added User-Name and Service-Type, but WLC wants somewhat other:&lt;/P&gt;&lt;P&gt;&lt;SAMP&gt;*radiusRFC3576TransportThread: Sep 09 18:48:18.990: Invalid attributes received in 'RFC-3576 CoA-Request' from 11.1.7.240&lt;/SAMP&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2014 14:58:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-wlan-authentication-from-external-radius-server/m-p/2357290#M89266</guid>
      <dc:creator>ivan.yarygin</dc:creator>
      <dc:date>2014-09-09T14:58:12Z</dc:date>
    </item>
  </channel>
</rss>

