< Home

radius-server authorization hw-ext-specific command bounce-port disable

Function

The radius-server authorization hw-ext-specific command bounce-port disable command configures the function of ignoring the authorization attribute indicating that the port goes Down intermittently in a CoA packet.

The undo radius-server authorization hw-ext-specific command bounce-port disable command restores the default setting.

By default, the device supports the authorization attribute indicating that the port goes Down intermittently in a CoA packet.

Format

radius-server authorization hw-ext-specific command bounce-port disable

undo radius-server authorization hw-ext-specific command bounce-port disable

Parameters

None

Views

System view

Default Level

3: Management level

Usage Guidelines

Usage Scenario

The value of the user-command field in the RADIUS attribute HW-Ext-Specific(26-238) carried in a CoA packet can be:
  • 1: Indicates that user reauthentication will be performed.
  • 2: Indicates that the port where the authorized user resides goes Down intermittently.
  • 3: Indicates that the port where the authorized user resides is disabled.

After the server authorizes a VLAN, the VLAN to which the terminal belongs will be changed. However, the terminal does not proactively trigger an IP address reapplication event using DHCP and you must manually trigger such an event on the terminal. Such operations cannot be directly performed on dumb terminals such as printers. You can disconnect the authentication port intermittently to trigger terminals connected to the authentication port to re-apply for an IP address. To configure the function of intermittently disconnecting the authentication port, you need to run the undo radius-server authorization hw-ext-specific command bounce-port disable command on the device, and set the value of the RADIUS attribute HW-Ext-Specific (26-238) on the server to user-command=2.

After this attribute is delivered, the authentication port goes Down and then goes Up after 12 seconds. Because the device supports the anti-intermittent disconnection function that can be configured using the link-down offline delay command, users go offline 10 seconds after the port goes Down by default. To ensure that users can go offline, the anti-intermittent disconnection time cannot be greater than 12 seconds and you cannot configure users not to go offline after the port goes Down.

Precautions

Pay attention to the following points if the value of the user-command field in the RADIUS attribute HW-Ext-Specific(26-238) carried in a CoA packet sent by the RADIUS server is 2 or 3:
  • Ensure that only one user resides on the authentication port or the user to be authenticated is directly connected to the authentication port; otherwise, other users on the authentication port will be affected if the port goes Down intermittently or disabled.
  • Only a physical port, as opposed to an Eth-Trunk, can function as the authentication port.
  • The policy association scenario is not supported.

Example

# Configure the function of ignoring the authorization attribute indicating that the port goes Down intermittently in a CoA packet.

<HUAWEI> system-view
[HUAWEI] radius-server authorization hw-ext-specific command bounce-port disable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >