05-20-2021 02:54 AM - edited 07-05-2021 01:19 PM
Does anyone know if it's possible to set a device rate limit (downstream/upstream) via the RADIUS Access-Accept response like we can in AireOS using similar to the below attributes:
We can't seem to find equivalent radius attributes or av-pair values to make this work on IOS-XE devices...
Thanks
James
05-20-2021 04:45 AM
i know we can do old controllers , i am also part of journey with Cat 9800
its possible as per the document - yet to be tested :
05-20-2021 04:54 AM
Thanks. I did see this document, but it's not really showing if it can be done via the RADIUS reply. And it seems to support defined policies on the WLC, rather than dynamic values set via the RADIUS reply. i.e. some clients get 1Mb, some 2Mb, some 10, some 20 etc. depending on their package.
05-20-2021 05:43 AM - edited 05-20-2021 05:47 AM
Got you, so you looking based on the user, not all clients, not that i am aware this was tested my self. but good option, if you looking to offer services to clients.
what kind of Radius you using ISE ?
check below thread may help you :
05-20-2021 06:05 AM
We already do this (have for years ) on the AireOS WLCs (as per the link you posted) but with Catalyst IOS-XE we can't find the equivalent RADIUS attribute to use
05-20-2021 08:01 AM
what radius you using - looking at document there command syntax bit changed : (still required for me to test) - will test later with ISE
05-20-2021 08:33 AM
Freeradius, though it shouldn't matter as the attribute name should work with any RADIUS, once we know what it is!
The guide you linked to is for the Cisco Cloud Services Router 1000 Voice Series, not wireless?
Thanks
James
05-21-2021 07:43 AM - edited 05-21-2021 08:47 AM
This should do what you need but the WLC must be running IOS XE 17.5 or later:
Check out the attached screenshot from the doc for the required A/V pairs. Just substitute "BWLimitAAAClients" for the name of your preconfigured QoS policy in your authz profile.
I've not tested it myself but I too need the functionality for a customer project!
(Credit to @vibobrov for identifying the solution)
05-21-2021 10:37 AM - edited 05-21-2021 10:37 AM
Thanks - but this still relies on multiple profiles/policies being added manually on the controller first. We're looking to dynamically pass a figure in bits/kbits like you can on the AOS WLC, i.e. we can just limit the speed for a particular user by setting the attribute value to 2000k.
Thanks
James
05-21-2021 11:10 AM
Oh I see, sorry James I misunderstood your requirement. I'm not sure that's possible but I'm sure somebody else here will pipe up if it is. Either way, please bear in mind that you will need IOS XE 17.5 for AAA override.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide