aaa authorization coa ignore
aaa authorization coa ignore
{
disable-port
|
dm-request
|
flip-port
|
modify-acl
|
reauth-host
}
no aaa authorization coa ignore
{
disable-port
|
dm-request
|
flip-port
|
modify-acl
|
reauth-host
}
The default state is maintained, and the packets are not discarded. All options are enabled for CoA processing.
Global configuration mode
Use this command to discard the specified RADIUS messages. A CoA request packet can be sent by the Dynamic Authorization Client (DAC) to change the session authorizations on the Network Access Server (NAS). This is used to change the filters, such as Layer 3 ACLs.
Before RFC 5176, when a user or device was authenticated on the RADIUS server, the session could be ended only if the user or device logs out. RFC 5176 addresses this issue by adding two more packet types to the current RADIUS standard: Disconnect Message and Change of Authorization. The Dynamic Authorization Client (DAC) server makes the requests to either delete the previously established sessions or replace the previous configuration or policies. Currently, these new extensions can be used to dynamically terminate or authorize sessions that are authenticated through MAC authentication or 802.1X authentication.
The following example ignores the disconnect message request.
device(config)# aaa authorization coa ignore dm-request
| Release version | Command history |
|---|---|
| 08.0.20 | This command was introduced. |
| 08.0.50 | This command was updated with disable-port, flip-port, and reauth-host options. |