RADIUS attribute for change of authorization

Change of authorization (CoA) allows you to change authorization dynamically after the device or user is authenticated. As part of authorization, the user or device is given access to specific resources on the network based on the policies or commands downloaded from the RADIUS server. The CoA allows you to change these policies without terminating the sessions. A CoA request packet can be sent by the CoA client (typically a RADIUS or policy server) to change the session authorizations on the FastIron device. The request identifies the device and the sessions to be authorized. To modify a Layer 3 ACL, filter ID attribute (type 11) can be used.

A CoA request can also initiate changes on the host or port using the foundry-coa command. Possible values for the command are disconnect, disable-port, reauth-host, flip-port, and modify-acl. The options can be sent individually. For more information on attributes for RADIUS to support CoA, refer to Company-specific attributes on the RADIUS server.