Description

This article provides the 802.1x (DOT1X) attributes for the EX-series switch and SRX branch devices.  Please refer to Juniper Technical Assistance Center for further information concerning 802.1x and current supported options.

Symptoms


Solution


<style type="text/css"> /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin:0in; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; mso-ansi-language:#0400; mso-fareast-language:#0400; mso-bidi-language:#0400;} table.MsoTableGrid {mso-style-name:"Table Grid"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; border:solid windowtext 1.0pt; mso-border-alt:solid windowtext .5pt; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-border-insideh:.5pt solid windowtext; mso-border-insidev:.5pt solid windowtext; mso-para-margin:0in; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:10.0pt; font-family:Times; mso-bidi-font-family:"Times New Roman"; mso-ansi-language:#0400; mso-fareast-language:#0400; mso-bidi-language:#0400;}


<o:p>   RADIUS attributes used for Authentication on EX switches and SRX branch devices

Attribute number as defined by RADIUS RFCs <o:p>

Attribute-Value (AV) pair name <o:p>

Messages used in <o:p>

1 <o:p>

User-Name <o:p>

Access-Request <o:p>

2 <o:p>

User-Password <o:p>

Access-Request <o:p>

4 <o:p>

NAS-IP-Address <o:p>

Access-Request <o:p>

5 <o:p>

NAS-Port <o:p>

Access-Request <o:p>

11 <o:p>

Filter-Id <o:p>

Access-Accept. The value(s) refer to already existing ACL(s) defined on the switch. <o:p>

12 <o:p>

Framed-MTU <o:p>

Access-Request. The value is set to 1500 for Ethernet. <o:p>

25 <o:p>

Class <o:p>

Access-Accept <o:p>

26 <o:p>

Vendor-specific <o:p>

Access-Accept. This will be a series of ASCII characters defining an ACL to be applied on the port. Vendor-Id used will be 2636. <o:p>

27 <o:p>

Session-Timeout <o:p>

Access-Accept. This can be used to override the re-authentication timeout value configured on the switch. <o:p>

Access-Challenge. This can be used to override the Supplicant timeout value configured on the switch. <o:p>

29 <o:p>

Termination-Action <o:p>

Access-Accept. The only valid value is RADIUS-Accept (This parameter is made mandatory by IEEE if Session-Timeout is used, even though it can have only one value) <o:p>

30 <o:p>

Called-Station-Id (MAC address of switch) <o:p>

Access-Request <o:p>

31 <o:p>

Calling-Station-Id (MAC address of supplicant) <o:p>

Access-Request <o:p>

61 <o:p>

NAS-Port-Type <o:p>

Access-Request <o:p>

64 <o:p>

Tunnel-Type <o:p>

Access-Accept. Used for Dynamic VLAN assignment. Should have value VLAN (type 13). <o:p>

65 <o:p>

Tunnel-Medium-Type <o:p>

Access-Accept. Used for Dynamic VLAN assignment. Should have value 802 (type 6). <o:p>

79 <o:p>

EAP-Message <o:p>

Access-Request <o:p>

Access-Challenge <o:p>

Access-Accept <o:p>

Access-Reject <o:p>

80 <o:p>

Message Authenticator <o:p>

Access-Request <o:p>

Access-Challenge <o:p>

Access-Accept <o:p>

Access-Reject <o:p>

81 <o:p>

Tunnel-Private-Group-ID <o:p>

Access-Accept. Used for Dynamic VLAN assignment. Has either the VLAN ID or the VLAN name to which the port has to be moved to. <o:p>

Not yet defined <o:p>

NAS-Traffic-Rule <o:p>

Access-Accept <o:p>

Change-of-Authorization ( CoA ) <o:p>

<o:p>  

Related Information