Enabling RADIUS CoA and Disconnect Message Handling for Dynamic Authorization
Per RFC 5176, a Dynamic Authorization Client (DAC) can dynamically terminate or authorize RADIUS sessions authenticated through MAC, 802.1x, or Web authentication. The ability to manage sessions also allows previous policies or configurations to be replaced. When no DAC is configured, established RADIUS sessions end only if the user or device logs out.
You must enable Disconnect Messages (DMs) and Change of Authorization (CoA) message handling on the ICX device for use with a DAC. To enable RADIUS Disconnect Message and CoA handling, complete the following steps:
- Enter global configuration mode.
- Enter the
aaa authorization coa enablecommand. - Configure the shared secret key required between the CoA client and the device as
shown in the following example. Enter the
radius-client coa hostcommand followed by the CoA host address, the word key, and the string that is required between the CoA client and the ICX device.The example configures the shared secret key fastiron123 to be used between the ICX device and the CoA host with the IP address 10.24.65.6.Note: An IPv6 address can be used when preceded by the keyword ipv6.