The first Layer 3 packet (other than DHCP) will trigger RADIUS authentication from the ISA based on configured isa-radius-policy in the
configure>aaa context. The user-name in the access-request is as per the user-name-format configured in the isa-radius-policy. By default it is the MAC address of the UE. The isa-radius-policy can be configured as the authentication policy under the soft-gre group-interface, or under specific VLAN tag ranges on the soft-gre group-interface. The latter allows for the use of a different authentication policy per SSID.
debug router "management" radius packet-type authentication | accounting | coa
253 2013/08/07 20:58:35.53 UTC MINOR: DEBUG #2001 Base WLAN-GW
"WLAN-GW: MDA 2/1, SeqNo 11830
Info: anchor egressing frame
radius-auth-req
IP/UDP: from 192.168.0.2:1142 to 192.0.2.3:1812
RADIUS: Access-Request (continued)
"
254 2013/08/07 20:58:35.53 UTC MINOR: DEBUG #2001 Base RADIUS
"RADIUS: Transmit
Access-Request(1) 192.168.0.2:1142 id 40 len 158 vrid 1
NAS IP ADDRESS [4] 4 192.0.2.3
NAS PORT TYPE [61] 4 Virtual(5)
NAS PORT ID [87] 43 GRE rtr-3#lip-192.168.0.1#rip-192.0.2.1
USER NAME [1] 17 00:0a:0a:00:01:00
PASSWORD [2] 16 rCmhFboYeM2M8hOuBYJXJk
CALLING STATION ID [31] 17 00:0a:0a:00:01:00
VSA [26] 19 Alcatel(6527)
CHADDR [27] 17 00:0a:0a:00:01:00
"
255 2013/08/07 20:58:35.61 UTC MINOR: DEBUG #2001 Base WLAN-GW
"WLAN-GW: MDA 2/1, SeqNo 11831
Info: anchor ingressing frame
portal auth-accept
IP/UDP: from 192.0.2.3:1812 to 192.168.0.2:1142
RADIUS: Access-Accept (continued)
"
256 2013/08/07 20:58:35.62 UTC MINOR: DEBUG #2001 Base RADIUS
"RADIUS: Receive
Access-Accept(2) id 40 len 64 from 192.0.2.3:1812 vrid 1
VSA [26] 14 Alcatel(6527)
SUBSC ID STR [11] 12 migrant_user
VSA [26] 18 Alcatel(6527)
WLAN PORTAL REDIRECT [172] 16 redirect-policy-1
"
*A:PE-1# tools dump wlan-gw ue
===============================================================================
Matched 1 session on Slot #2 MDA #1
===============================================================================
UE-Mac : 00:0a:0a:00:01:00 UE-vlan : N/A
UE IP Addr : 10.0.0.10 Description : Portal
UE timeout : 288 sec Auth-time : 08/07/13 20:58:35
Tunnel MDA : 2/2 Tunnel Router : 10
MPLS label : 3000 Shaper : Default
GRE Src IP Addr : 192.0.2.2 GRE Dst IP Addr : 192.168.0.1
Anchor SAP : 2/1/nat-out-ip:2049.1
Last-forward : None Last-move : None
Rx Frames : 0 Rx Octets : 0
Tx Frames : 0 Tx Octets : 0
-------------------------------------------------------------------------------
===============================================================================
No sessions on Slot #2 MDA #2 match the query
248 2013/08/07 19:12:38.29 UTC MINOR: DEBUG #2001 Base RADIUS
"RADIUS: Transmit
Change of Authorization(43) 192.0.2.3:36776 id 124 len 96 vrid 1
VSA [26] 19 Alcatel(6527)
SUBSC ID STR [11] 17 00:0a:0a:00:01:00
USER NAME [1] 17 00:0a:0a:00:01:00
VSA [26] 10 Alcatel(6527)
SLA PROF STR [13] 8 sla-profile-1
VSA [26] 10 Alcatel(6527)
SUBSC PROF STR [12] 8 sub-profile-1
"
A:PE-1# tools dump wlan-gw ue
===============================================================================
Matched 1 session on Slot #2 MDA #1
===============================================================================
UE-Mac : 00:0a:0a:00:01:00 UE-vlan : N/A
UE IP Addr : N/A Description : ESM-user
UE timeout : N/A Auth-time : 08/07/13 19:12:38
Tunnel MDA : 2/2 Tunnel Router : 10
MPLS label : 3000 Shaper : 1
GRE Src IP Addr : 192.0.2.2 GRE Dst IP Addr : 192.168.0.1
Anchor SAP : 2/1/nat-out-ip:2049.1
Last-forward : 08/07/13 19:12:25 Last-move : None
Rx Frames : 1 Rx Octets : 88
Tx Frames : 1 Tx Octets : 222
-------------------------------------------------------------------------------
===============================================================================
No sessions on Slot #2 MDA #2 match the query
subscriber-mgmt
authentication-policy "authentication-1" create
password "E40PedK6aqrEIpr2DEoJyVR8PQ3XkFF7" hash2
radius-authentication-server
source-address 192.0.2.1
router "management"
server 1 address 192.0.2.3 secret "6uuGli25Vtl49q0." hash2
exit
accept-authorization-change
include-radius-attribute
acct-session-id
circuit-id
remote-id
nas-port-id
nas-identifier
nas-port-type
pppoe-service-name
dhcp-options
dhcp-vendor-class-id
access-loop-options
mac-address
called-station-id
calling-station-id sap-string
tunnel-server-attrs
aaa
isa-radius-policy "isa-policy-1" create
nas-ip-address-origin isa-ip
password "CAO6ALDnhyBJERE4xnXoW15MQ/hu74x5nDE7F.OJxHM" hash2
auth-include-attributes
called-station-id
calling-station-id
circuit-id
dhcp-options
dhcp-vendor-class-id
mac-address
nas-identifier
nas-port-id
nas-port-type
remote-id
exit
servers
router 1
source-address-range 192.168.0.2
server 1 create
authentication
coa
ip-address 192.0.2.3
secret "CAO6ALDnhyBJERE4xnXoW15MQ/hu74x5nDE7F.OJxHM" hash2
no shutdown
exit
exit
exit
exit
subscriber-mgmt
http-redirect-policy "redirect-policy-1" create
url "http://66.185.84.163"
forward-entries
dst-ip 192.168.1.1 protocol udp dst-port 53
dst-ip 192.168.1.2 protocol udp dst-port 53
dst-ip 66.185.84.163 protocol tcp dst-port 80
dst-ip 10.0.0.1 protocol udp dst-port 67
dst-ip 10.0.0.1 protocol udp dst-port 68
exit
exit
exit
vprn 10 customer 1 create
nat
inside
l2-aware
address 10.0.0.1/24
exit
exit
outside
pool "migrant-pool-1" nat-group 1 type wlan-gw-anchor create
address-range 192.168.2.0 192.168.2.255 create
exit
no shutdown
exit
pool "auth-pool-1" nat-group 1 type l2-aware create
address-range 192.168.3.0 192.168.3.255 create
exit
no shutdown
exit
exit
exit
exit
service
nat
nat-policy "migrant-policy" create
pool "migrant-pool-1" router 1
timeouts
tcp-established min 1
exit
exit
exit
exit
service
nat
nat-policy "nat-auth-policy-1" create
pool "auth-pool-1" router 10
exit
exit
exit
vprn 1 customer 1 create
subscriber-interface "sub-int-1" create
address 10.0.0.1/24
group-interface "soft-gre-1" softgre create
sap-parameters
sub-sla-mgmt
def-sla-profile "sla-profile-1"
def-sub-id use-auto-id
def-sub-profile "sub-profile-1"
sub-ident-policy "sub_ident"
exit
exit
dhcp
proxy-server
emulated-server 10.0.0.1
lease-time hrs 1
no shutdown
exit
trusted
lease-populate 32767
gi-address 10.0.0.1
no shutdown
exit
authentication-policy "authentication-1"
host-connectivity-verify
soft-gre
authentication
authentication-policy "isa-policy-1"
exit
gw-address 192.168.0.1
mobility
hold-time 0
trigger data iapp
exit
router 1
wlan-gw-group 1
vlan-tag-ranges
range start 100 end 100
authentication
authentication-policy "isa-policy-1"
exit
data-triggered-ue-creation
dhcp
active-lease-time min 12
initial-lease-time min 5
l2-aware-ip-address 10.0.0.10
primary-dns 192.168.1.1
secondary-dns 192.168.1.2
no shutdown
exit
http-redirect-policy "redirect-policy-1"
nat-policy "migrant-policy"
exit
exit
no shutdown
exit
exit
exit
exit