radius-server coa update username

Function

The radius-server coa update username command enables a BRAS to update user names based on those delivered in CoA messages and switch users to the domains carried in the RADIUS-delivered user names.

The undo radius-server coa update username command disables a BRAS from updating user names based on those delivered in CoA messages and switching users to the domains carried in the RADIUS-delivered user names.

By default, a BRAS discards CoA messages if user names carried in the CoA messages differ from those saved on the BRAS.

This command is supported only on the NetEngine 8000 F1A.

Format

radius-server coa update username

undo radius-server coa update username

Parameters

None

Views

System view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
bras-radius write

Usage Guidelines

Usage Scenario

In the web authentication scenario where a portal server cannot exchange authentication messages with a BRAS, you can configure the portal server to exchange authentication messages with a RADIUS server. To enable a BRAS to update user names based on those delivered in CoA messages and switch users to the domains carried in the RADIUS-delivered user names, run the radius-server coa update username command.

  • After this command is run, if the user names carried in CoA messages differ from the existing ones, the BRAS adopts the RADIUS-delivered user names and switches the users to the domains carried in the user names (The user names must be in the format of username <domain>).
  • After the radius-server coa update username command is run, the RADIUS server stops accounting in the pre-authentication domain, but starts accounting for the users with RADIUS-delivered user names in the post-authentication domain.

Follow-up Procedure

After a user is switched to the post-authentication domain, only the user name, domain name, and accounting scheme are updated by default. You can run the redirect-domain effect-attribute command to enable specified attributes to take effect in the post-authentication domain. Currently, only qos-profile, user-group, web-url, and ip-unr-tag attributes are supported.

Precautions

In VS mode, this command is supported only by the admin VS.

Example

# Enable a BRAS to update user names based on those delivered in CoA messages from the RADIUS server and switch users to a new domain.
<HUAWEI> system-view
[~HUAWEI] radius-server coa update username
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >