aaa authorization coa enable

Enables RADIUS Change of Authorization (CoA).
Syntax
aaa authorization coa enable
no aaa authorization coa enable
Command Default

RADIUS CoA is not enabled.

Modes

Global configuration mode

Usage Guidelines

Use this command to enable RADIUS CoA authorization. The no form of the command disables the CoA functionality. A change of authorization request packet can be sent by the Dynamic Authorization Client (DAC) to change the session authorizations on the Network Access Server (NAS). This is used to change the filters, such as Layer 3 ACLs.

Before RFC 5176 when a user or device was authenticated on the RADIUS server, the session could only be ended if the user or device logs out. RFC 5176 addresses this issue by adding two more packet types to the current RADIUS standard: Disconnect Message and Change of Authorization. The Dynamic Authorization Client (DAC) server makes the requests to either delete the previously established sessions or replace the previous configuration or policies. Currently, these new extensions can be used to dynamically terminate or authorize sessions that are authenticated through multi-device-port-authentication or dot1x authentication.

Examples

The following example enables RADIUS CoA.

device# configure terminal
device(config)# aaa authorization coa enable
History
Release version Command history
08.0.20 This command was introduced.