Radius Access-Accept
Access-Accept user authorization is treated as a comprehensive and proper set of the user settings: the fastDPI modifies its inner database in full compliance with the Access-Accept attributes.
Access-Accept have to contain the following attributes, along with previously described VasExperts-*:
Framed-IP-Address– is the user IP address (the same as in the request). This is a mandatory attribute.- The username (login) – corresponds to one of the following attributes:
VasExperts-UserName,Chargeable-User-Identity(CUI),User-Name. Note that theUser-Nameattribute within the Access-Request request typically contains the user IP address. Access-Accept response should contain one of the attributes specifying the user login. Session-Timeout– is the optional attribute, it specifies the authorization timeout in seconds. Upon the expiry of this timeout the user authorization status is set to "unknown" value resulting in sending the Access-Request authoriztion request.
[SSG 9.2] In the Access-Accept response, you can indicate that this subscriber is an L2 subscriber and L2 BRAS is applicable to it. This is achieved by the VSA attribute
ATTRIBUTE VasExperts-L2-User 12 integer
If VasExperts-L2-User=1 is indicated in the response, then SSG will remember the L2-properties of the subscriber from the packet - MAC, VLANs - and will apply L2-termination to such a subscriber.
Was this information helpful?