Enabling RADIUS CoA and Disconnect Message Handling for Dynamic Authorization

Per RFC 5176, a Dynamic Authorization Client (DAC) can dynamically terminate or authorize RADIUS sessions authenticated through MAC, 802.1x, or Web authentication. The ability to manage sessions also allows previous policies or configurations to be replaced. When no DAC is configured, established RADIUS sessions end only if the user or device logs out.

You must enable Disconnect Messages (DMs) and Change of Authorization (CoA) message handling on the ICX device for use with a DAC. To enable RADIUS Disconnect Message and CoA handling, complete the following steps:

  1. Enter global configuration mode.
    device# configure terminal
  2. Enter the aaa authorization coa enable command.
    device(config)# aaa authorization coa enable
  3. Configure the shared secret key required between the CoA client and the device as shown in the following example. Enter the radius-client coa host command followed by the CoA host address, the word key, and the string that is required between the CoA client and the ICX device.
    device(config)# radius-client coa host 10.24.65.6 key fastiron123
    The example configures the shared secret key fastiron123 to be used between the ICX device and the CoA host with the IP address 10.24.65.6.
    Note: An IPv6 address can be used when preceded by the keyword ipv6.