aaa commands

configure 
aaa 
apply-groups reference
apply-groups-exclude reference
diameter 
node string 
apply-groups reference
apply-groups-exclude reference
connection 
ipv4 
allow-connections boolean
local-address string
ipv6 
allow-connections boolean
local-address string
timer number
description string
origin-realm string
peer index number 
address (ipv4-address-no-zone | ipv6-address-no-zone)
admin-state keyword
apply-groups reference
apply-groups-exclude reference
connection-timer number
default-peer boolean
destination-host string
preference number
route index number 
application keyword
apply-groups reference
apply-groups-exclude reference
preference number
realm string
watchdog-timer number
python-policy reference
router-instance string
radius 
acct-on-off-group string 
apply-groups reference
apply-groups-exclude reference
description string
coa-port number
isa-policy string 
accounting 
include-attributes 
acct-delay-time boolean
acct-triggered-reason boolean
called-station-id boolean
calling-station-id boolean
circuit-id boolean
class boolean
credit-control-quota boolean
dhcp-options boolean
dhcp-vendor-class-id boolean
frame-counters boolean
framed-ip-address boolean
framed-ip-netmask boolean
framed-ipv6-prefix boolean
hardware-timestamp boolean
ipv6-address boolean
mac-address boolean
millisecond-event-timestamp boolean
multi-session-id boolean
nas-identifier boolean
nas-ip-address boolean
nas-ipv6-address boolean
nas-port boolean
nas-port-id boolean
nas-port-type boolean
nat-inside-service-id boolean
nat-outside-ip-address boolean
nat-outside-service-id boolean
nat-port-forward-logging boolean
nat-port-range-block boolean
nat-subscriber-string boolean
octet-counters boolean
proxied-subscriber-data boolean
release-reason boolean
remote-id boolean
rssi boolean
session-time boolean
subscriber-id boolean
toserver-dhcp6-options boolean
ue-creation-type boolean
user-name boolean
wlan-custom-user-group boolean
wlan-ssid-vlan boolean
xconnect-tunnel-home-address boolean
xconnect-tunnel-local-ipv6-address boolean
xconnect-tunnel-remote-ipv6-address boolean
xconnect-tunnel-service boolean
xconnect-tunnel-type boolean
nat-periodic-update 
interval number
rate-limit (number | keyword)
update-triggers 
address-state boolean
soft-quota-exhausted boolean
apply-groups reference
apply-groups-exclude reference
authentication 
include-attributes 
called-station-id boolean
calling-station-id boolean
circuit-id boolean
dhcp-vendor-class-id boolean
framed-ip-address boolean
ipv6-address boolean
mac-address boolean
nas-identifier boolean
nas-ip-address boolean
nas-ipv6-address boolean
nas-port boolean
nas-port-id boolean
nas-port-type boolean
remote-id boolean
toserver-dhcp-options boolean
toserver-dhcp6-options boolean
wlan-ssid-vlan boolean
xconnect-tunnel-home-address boolean
description string
nas-ip-address-origin keyword
password string
python-policy reference
servers 
access-algorithm keyword
ipv6 
mtu number
source-prefix string
router-instance string
server number 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
purpose 
accounting 
udp-port number
authentication 
udp-port number
coa 
udp-port number
secret string
source-address-range string
timeout number
total-tries number
user-name 
format keyword
mac-format keyword
l2tp-accounting-policy string 
accounting-type 
session boolean
tunnel boolean
acct-tunnel-connection-fmt string
apply-groups reference
apply-groups-exclude reference
description string
include-radius-attribute 
calling-station-id boolean
nas-identifier boolean
nas-port 
bit-spec string
nas-port-id 
prefix-string string
suffix keyword
nas-port-type 
type (keyword | number)
radius-server-policy reference
route-downloader string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
base-user-name string
default-metric number
default-tag number
description string
download-interval number
max-routes number
password string
radius-server-policy reference
retry-interval 
max number
min number
server-policy string 
acct-on-off 
apply-groups reference
apply-groups-exclude reference
monitor reference
oper-state-change 
group reference
apply-groups reference
apply-groups-exclude reference
description string
python-policy reference
servers 
access-algorithm keyword
buffering 
acct-interim 
lifetime number
max number
min number
acct-start 
lifetime number
max number
min number
acct-stop 
lifetime number
max number
min number
health-check 
down-timeout number
test-account 
admin-state keyword
interval number
password string
user-name string
hold-down-time number
ipv6-source-address string
retry-count number
router-instance string
server number 
apply-groups reference
apply-groups-exclude reference
server-name string
source-address string
stickiness boolean
timeout number
wpp 
apply-groups reference
apply-groups-exclude reference
portal-group string 
admin-state keyword
apply-groups reference
apply-groups-exclude reference
description string
portal string name string 
system-name string

aaa command descriptions

aaa

Synopsis Enter the aaa context
Context configure aaa
Treeaaa
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

diameter

Synopsis Enter the diameter context
Context configure aaa diameter
Treediameter

Description

Commands in this context configure Diameter Base parameters.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

node [origin-host] string
Synopsis Enter the node list instance
Context configure aaa diameter node string
Treenode
Max. Instances32
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[origin-host] string
Synopsis Origin-Host AVP
Context configure aaa diameter node string
Treenode
String Length1 to 80

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

connection
Synopsis Enter the connection context
Context configure aaa diameter node string connection
Treeconnection
Introduced16.0.R6

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv4
Synopsis Enter the ipv4 context
Context configure aaa diameter node string connection ipv4
Treeipv4
Introduced16.0.R6

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

allow-connections boolean
Synopsis Listen on local address for incoming peer connections
Contextconfigure aaa diameter node string connection ipv4 allow-connections boolean
Treeallow-connections

Description

When configured to true, this command is used in multi-chassis redundancy where the local Diameter node accepts connection from the inter-chassis peer. The peer requesting the connection must have the same Diameter name as the local peer and its source address must match the IP address of the locally configured destination peer.

The IPv4 address on which the node listens for incoming connection is the configured source address of the local peer. This source IPv4 address can reference any local interface, including loopbacks.

When configured to false, incoming requests for connections are refused.

Defaultfalse
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enter the ipv6 context
Context configure aaa diameter node string connection ipv6
Treeipv6
Introduced16.0.R6

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

timer number
Synopsis Wait time before attempting reconnection to peer
Contextconfigure aaa diameter node string connection timer number
Treetimer

Description

This command configures the time the system waits before attempting to reconnect to a peer after the connection is lost.

Range1 to 1000
Unitsseconds
Default 30
Introduced16.0.R6

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure aaa diameter node string description string
Treedescription
String Length1 to 80
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

origin-realm string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisOrigin-realm name
Contextconfigure aaa diameter node string origin-realm string
Treeorigin-realm
String Length1 to 80
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

peer index number
Synopsis Enter the peer list instance
Context configure aaa diameter node string peer index number
Treepeer
Max. Instances5
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

index number
Synopsis Index of a peer within the node
Context configure aaa diameter node string peer index number
Treepeer
Range1 to 5

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Diameter peer address
Context configure aaa diameter node string peer index number address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the Diameter peer
Contextconfigure aaa diameter node string peer index number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

connection-timer number
Synopsis Wait time before attempting reconnection to peer
Contextconfigure aaa diameter node string peer index number connection-timer number
Treeconnection-timer
Range1 to 1000
Unitsseconds
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

default-peer boolean
Synopsis Use the peer as default route for realm-based routing
Contextconfigure aaa diameter node string peer index number default-peer boolean
Treedefault-peer
Defaultfalse
Introduced19.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

destination-host string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination-Host AVP string for Diameter messages
Contextconfigure aaa diameter node string peer index number destination-host string
Treedestination-host
String Length1 to 80

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference number
Synopsis Diameter routing preference for a peer
Contextconfigure aaa diameter node string peer index number preference number
Treepreference
Range1 to 100
Default50
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

route index number
Synopsis Enter the route list instance
Context configure aaa diameter node string peer index number route index number
Treeroute
Max. Instances15
Introduced20.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

index number
Synopsis Static Diameter route ID
Context configure aaa diameter node string peer index number route index number
Treeroute

Description

This command configures the ID of the static route used to reach remote realms that are not directly connected to the origin realm. The route can also be used to override the route preference (peer preference) of the directly-connected realms.

Range1 to 15

Notes

This element is part of a list key.

Introduced20.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

application keyword
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDiameter application to which the route applies
Contextconfigure aaa diameter node string peer index number route index number application keyword
Treeapplication

Description

This command specifies the Diameter application in the destination realm reachable via the static route. 

Optionsnasreq, gy, gx

Notes

This element is mandatory.

Introduced20.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

preference number
Synopsis Static route preference; lower value is preferred
Contextconfigure aaa diameter node string peer index number route index number preference number
Treepreference

Description

This command configures the preference of the static route. The preference is compared with the preference values of all other static and dynamic routes. The dynamic route is a realm route learned directly from the peer via the Capabilities Exchange process during the peer negotiation phase. The preference value of the dynamic route is configured directly under the peer configuration. A lower preference value is preferred for route selection.

Range1 to 100
Default50
Introduced 20.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

realm string
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisDestination realm reachable via the static route
Contextconfigure aaa diameter node string peer index number route index number realm string
Treerealm
String Length1 to 80

Notes

This element is mandatory.

Introduced20.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

watchdog-timer number
Synopsis Time between consecutive watchdog messages
Contextconfigure aaa diameter node string peer index number watchdog-timer number
Treewatchdog-timer
Range1 to 1000
Unitsseconds
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

python-policy reference
Synopsis Python policy for received or sent Diameter messages
Contextconfigure aaa diameter node string python-policy reference
Treepython-policy

Reference

configure python python-policy string

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

router-instance string
Synopsis Router in which this node connects to its peers
Contextconfigure aaa diameter node string router-instance string
Treerouter-instance
DefaultBase
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

radius

Synopsis Enter the radius context
Context configure aaa radius
Treeradius
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

acct-on-off-group [name] string
Synopsis Enter the acct-on-off-group list instance
Contextconfigure aaa radius acct-on-off-group string
Treeacct-on-off-group
Max. Instances32
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis Group name for accounting on/off
Context configure aaa radius acct-on-off-group string
Treeacct-on-off-group
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

coa-port number
Synopsis RADIUS listening port for CoA and Disconnect messages
Contextconfigure aaa radius coa-port number
Treecoa-port
Range1647 | 1700 | 1812 | 3799
Default3799
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

isa-policy [name] string
Synopsis Enter the isa-policy list instance
Contextconfigure aaa radius isa-policy string
Treeisa-policy
Max. Instances8
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis ISA RADIUS policy name referenced by a NAT application
Contextconfigure aaa radius isa-policy string
Treeisa-policy
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

accounting
Synopsis Enter the accounting context
Context configure aaa radius isa-policy string accounting
Treeaccounting
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

include-attributes
Synopsis Enter the include-attributes context
Contextconfigure aaa radius isa-policy string accounting include-attributes
Treeinclude-attributes

Description

Commands in this context specify the attributes to include in the RADIUS accounting messages.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv6-address boolean
Synopsis Include the Alc-Ipv6-Address attribute
Contextconfigure aaa radius isa-policy string accounting include-attributes ipv6-address boolean
Treeipv6-address

Description

When configured to true, the IA_NA address of the UE is included in the accounting message if an active IA_NA lease exists.

When configured to false, the address is not included.

Defaultfalse
Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

millisecond-event-timestamp boolean
Synopsis Include the Alc-Millisecond-Event-Timestamp attribute
Contextconfigure aaa radius isa-policy string accounting include-attributes millisecond-event-timestamp boolean
Treemillisecond-event-timestamp

Description

When configured to true, the router includes the Alc-Millisecond-Event-Timestamp attribute in the accounting message. This attribute includes the time the accounting event was logged in milliseconds since Jan 1, 1970 00:00:00 UTC.

When configured to false, the router does not include this attribute.

Defaultfalse
Introduced20.10.R1

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

nas-ipv6-address boolean
Synopsis Include the NAS-IPv6-Address attribute
Contextconfigure aaa radius isa-policy string accounting include-attributes nas-ipv6-address boolean
Treenas-ipv6-address

Description

When configured to true, the router includes the NAS-IPv6-Address attribute in RADIUS accounting messages using the address specified in the configure aaa radius isa-policy nas-ip-address-origin command. The NAS-IPv6-Address attribute is included in both IPv4 and IPv6 RADIUS connections.

When configured to false, the router does not include the NAS-IPv6-Address attribute in RADIUS accounting messages.

Defaultfalse
Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-port-forward-logging boolean
Synopsis Enable logging of port forwards via RADIUS
Contextconfigure aaa radius isa-policy string accounting include-attributes nat-port-forward-logging boolean
Treenat-port-forward-logging

Description

When configured to true, the router enables static or PCP port-forward logging via RADIUS. Port-forward logging is supported only in conjunction with the logging of port blocks.

When configured to false, the router disables static or PCP port-forward logging.

Defaultfalse
Introduced24.3.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nat-periodic-update
Synopsis Enter the nat-periodic-update context
Contextconfigure aaa radius isa-policy string accounting nat-periodic-update
Treenat-periodic-update
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

rate-limit (number | keyword)
Synopsis Rate limit for periodic RADIUS Interim-Update messages
Contextconfigure aaa radius isa-policy string accounting nat-periodic-update rate-limit (number | keyword)
Treerate-limit
Range1 to 100000
Unitspackets per second
Optionsunlimited
Defaultunlimited
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

update-triggers
Synopsis Enter the update-triggers context
Contextconfigure aaa radius isa-policy string accounting update-triggers
Treeupdate-triggers
Introduced16.0.R4

Platforms

7750 SR, 7750 SR-e, 7750 SR-s, VSR

authentication
Synopsis Enter the authentication context
Contextconfigure aaa radius isa-policy string authentication
Treeauthentication
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

include-attributes
Synopsis Enter the include-attributes context
Contextconfigure aaa radius isa-policy string authentication include-attributes
Treeinclude-attributes

Description

Commands in this context specify the attributes to include in the RADIUS authentication messages.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

nas-ipv6-address boolean
Synopsis Include the NAS-IPv6-Address attribute
Contextconfigure aaa radius isa-policy string authentication include-attributes nas-ipv6-address boolean
Treenas-ipv6-address

Description

When configured to true, the router includes the NAS-IPv6-Address attribute in RADIUS authentication messages using the address specified in the configure aaa radius isa-policy nas-ip-address-origin command. The NAS-IPv6-Address attribute is included in both IPv4 and IPv6 RADIUS connections.

When configured to false, the router does not include the NAS-IPv6-Address attribute in RADIUS authentication messages.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure aaa radius isa-policy string description string
Treedescription
String Length1 to 80
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

password string
Synopsis Password used in the RADIUS access requests
Contextconfigure aaa radius isa-policy string password string
Treepassword
String Length1 to 42
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

servers
Synopsis Enter the servers context
Context configure aaa radius isa-policy string servers
Treeservers
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

access-algorithm keyword
Synopsis Algorithm that accesses the RADIUS servers
Contextconfigure aaa radius isa-policy string servers access-algorithm keyword
Treeaccess-algorithm
Optionsdirect, round-robin, hash-based, direct-priority
Defaultdirect
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ipv6
Synopsis Enter the ipv6 context
Context configure aaa radius isa-policy string servers ipv6
Treeipv6

Description

Commands in this context configure how to communicate with IPv6 RADIUS servers.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mtu number
Synopsis MTU used to fragment outgoing IPv6 RADIUS packets
Contextconfigure aaa radius isa-policy string servers ipv6 mtu number
Treemtu
Range1280 to 9000
Default9000
Introduced 22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

source-prefix string
Synopsis Prefix containing individual source addresses per ISA
Contextconfigure aaa radius isa-policy string servers ipv6 source-prefix string
Treesource-prefix

Description

This command configures an IPv6 prefix containing individual /128 addresses. These addresses are used as the source address for connections to IPv6 RADIUS servers.

The prefix must be large enough to accommodate all BB-ISAs or ESA VMs in the system.

Introduced22.10.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

server [index] number
Synopsis Enter the server list instance
Contextconfigure aaa radius isa-policy string servers server number
Treeserver
Max. Instances10
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

[index] number
Synopsis RADIUS server ID
Context configure aaa radius isa-policy string servers server number
Treeserver
Range1 to 10

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the ISA RADIUS server
Contextconfigure aaa radius isa-policy string servers server number admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisIP address of the RADIUS server
Contextconfigure aaa radius isa-policy string servers server number ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

purpose
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnter the purpose context
Contextconfigure aaa radius isa-policy string servers server number purpose
Treepurpose
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

accounting
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the accounting context
Contextconfigure aaa radius isa-policy string servers server number purpose accounting
Treeaccounting
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp-port number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisISA RADIUS server accounting UDP port
Contextconfigure aaa radius isa-policy string servers server number purpose accounting udp-port number
Treeudp-port
Range1 to 65535
Default1813
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

authentication
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the authentication context
Contextconfigure aaa radius isa-policy string servers server number purpose authentication
Treeauthentication
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp-port number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisISA RADIUS server authentication UDP port
Contextconfigure aaa radius isa-policy string servers server number purpose authentication udp-port number
Treeudp-port
Range1 to 65535
Default1812
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

coa
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisEnable the coa context
Contextconfigure aaa radius isa-policy string servers server number purpose coa
Treecoa
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

udp-port number
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisISA RADIUS server change of authorization UDP port
Contextconfigure aaa radius isa-policy string servers server number purpose coa udp-port number
Treeudp-port
Range1 to 65535
Default3799
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

secret string
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisSecret key to access the RADIUS server
Contextconfigure aaa radius isa-policy string servers server number secret string
Treesecret
String Length1 to 115
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

timeout number
Synopsis Timeout for a response from the RADIUS server
Contextconfigure aaa radius isa-policy string servers timeout number
Treetimeout
Range1 to 90
Unitsseconds
Default 5
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

total-tries number
Synopsis Maximum number of tries toward the same RADIUS server
Contextconfigure aaa radius isa-policy string servers total-tries number
Treetotal-tries
Range1 to 10
Default3
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

user-name
Synopsis Enter the user-name context
Context configure aaa radius isa-policy string user-name
Treeuser-name

Description

Commands in this context define the format of the username field in the UE authentication request sent to the RADIUS server. For authentication of IPv6 triggers (ICMPv6, DHCPv6, IPv6 data-trigger) the username format will always fall back to MAC only.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

format keyword
Synopsis Username format in RADIUS message
Context configure aaa radius isa-policy string user-name format keyword
Treeformat
Optionsmac, mac-ip, dhcp-vendor, circuit-id
Default mac
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

mac-format keyword
Synopsis MAC address format when contacting RADIUS server
Contextconfigure aaa radius isa-policy string user-name mac-format keyword
Treemac-format
Optionsalu, ieee
Default alu
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-e, 7750 SR-s, VSR

l2tp-accounting-policy [name] string
Synopsis Enter the l2tp-accounting-policy list instance
Contextconfigure aaa radius l2tp-accounting-policy string
Treel2tp-accounting-policy
Max. Instances32
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis L2TP RADIUS accounting policy name
Context configure aaa radius l2tp-accounting-policy string
Treel2tp-accounting-policy
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

accounting-type
Synopsis Enter the accounting-type context
Contextconfigure aaa radius l2tp-accounting-policy string accounting-type
Treeaccounting-type
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

include-radius-attribute
Synopsis Enter the include-radius-attribute context
Contextconfigure aaa radius l2tp-accounting-policy string include-radius-attribute
Treeinclude-radius-attribute
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

nas-port
Synopsis Enable the nas-port context
Context configure aaa radius l2tp-accounting-policy string include-radius-attribute nas-port
Treenas-port
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

nas-port-id
Synopsis Enable the nas-port-id context
Contextconfigure aaa radius l2tp-accounting-policy string include-radius-attribute nas-port-id
Treenas-port-id
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

nas-port-type
Synopsis Enable the nas-port-type context
Contextconfigure aaa radius l2tp-accounting-policy string include-radius-attribute nas-port-type
Treenas-port-type
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

route-downloader [name] string
Synopsis Enter the route-downloader list instance
Contextconfigure aaa radius route-downloader string
Treeroute-downloader
Max. Instances1
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis RADIUS route downloader name
Context configure aaa radius route-downloader string
Treeroute-downloader
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of this route downloader
Contextconfigure aaa radius route-downloader string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

base-user-name string
Synopsis Prefix of the username used as access requests
Contextconfigure aaa radius route-downloader string base-user-name string
Treebase-user-name

Description

This command sets the prefix for the username that is used for access requests. The actual name used is a concatenation of this string, the “-” (dash) character and a monotonically increasing integer.

String Length1 to 32
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

default-metric number
Synopsis Default metric that RTM imported routes acquire
Contextconfigure aaa radius route-downloader string default-metric number
Treedefault-metric
Range0 to 254
Default2
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

default-tag number
Synopsis Default tag of this route downloader
Context configure aaa radius route-downloader string default-tag number
Treedefault-tag
Range0 to 4294967295
Default0
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure aaa radius route-downloader string description string
Treedescription
String Length1 to 80
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

download-interval number
Synopsis Wait time between consecutive runs of the process
Contextconfigure aaa radius route-downloader string download-interval number
Treedownload-interval
Range1 to 1440
Unitsminutes
Default 720
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

max-routes number
Synopsis Maximum routes imported by this route downloader
Contextconfigure aaa radius route-downloader string max-routes number
Treemax-routes
Range1 to 200000
Default200000
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

password string
Synopsis Route downloader password for RADIUS access requests
Contextconfigure aaa radius route-downloader string password string
Treepassword
String Length1 to 71
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

radius-server-policy reference
WARNING:

Modifying this element toggles the admin-state of the parent element automatically for the new value to take effect.

SynopsisRADIUS server policy referenced
Contextconfigure aaa radius route-downloader string radius-server-policy reference
Treeradius-server-policy

Reference

configure aaa radius server-policy string

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

retry-interval
Synopsis Enter the retry-interval context
Contextconfigure aaa radius route-downloader string retry-interval
Treeretry-interval

Description

Commands in this context configure parameters of the retry interval timer, which is an exponential backoff timer. The system retries sending an Access Request message after the previous message was unanswered (for example, a RADIUS failure or ICMP port unreachable error).

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

max number
Synopsis Maximum duration of the retry interval
Contextconfigure aaa radius route-downloader string retry-interval max number
Treemax
Range1 to 1440
Unitsminutes
Default 20
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

min number
Synopsis Minimum duration of the retry interval
Contextconfigure aaa radius route-downloader string retry-interval min number
Treemin

Description

This command specifies the minimum duration of the retry interval. This duration grows exponentially after each sequential failure.

Range1 to 1440
Unitsminutes
Default 10
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server-policy [name] string
Synopsis Enter the server-policy list instance
Contextconfigure aaa radius server-policy string
Treeserver-policy
Max. Instances32
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[name] string
Synopsis RADIUS server policy name
Context configure aaa radius server-policy string
Treeserver-policy
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

acct-on-off
Synopsis Enable the acct-on-off context
Contextconfigure aaa radius server-policy string acct-on-off
Treeacct-on-off
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

monitor reference
WARNING:

Modifying this element recreates the parent element automatically for the new value to take effect.

SynopsisAccounting on/off group name
Contextconfigure aaa radius server-policy string acct-on-off monitor reference
Treemonitor

Reference

configure aaa radius acct-on-off-group string

Notes

The following elements are part of a choice: monitor or oper-state-change.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

oper-state-change
Synopsis Enable the oper-state-change context
Contextconfigure aaa radius server-policy string acct-on-off oper-state-change
Treeoper-state-change

Notes

The following elements are part of a choice: monitor or oper-state-change.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure aaa radius server-policy string description string
Treedescription
String Length1 to 80
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

servers
Synopsis Enter the servers context
Context configure aaa radius server-policy string servers
Treeservers
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

access-algorithm keyword
Synopsis Algorithm to select a RADIUS server from the pool
Contextconfigure aaa radius server-policy string servers access-algorithm keyword
Treeaccess-algorithm
Optionsdirect, round-robin, hash-based
Defaultdirect
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

buffering
Synopsis Enter the buffering context
Context configure aaa radius server-policy string servers buffering
Treebuffering
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

acct-interim
Synopsis Enable the acct-interim context
Contextconfigure aaa radius server-policy string servers buffering acct-interim
Treeacct-interim
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

max number
Synopsis Maximum time between accounting message resend attempts
Contextconfigure aaa radius server-policy string servers buffering acct-interim max number
Treemax
Range1 to 3600
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

min number
Synopsis Minimum time between accounting message resend attempts
Contextconfigure aaa radius server-policy string servers buffering acct-interim min number
Treemin
Range1 to 3600
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

acct-start
Synopsis Enable the acct-start context
Context configure aaa radius server-policy string servers buffering acct-start
Treeacct-start
Introduced20.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lifetime number
Synopsis Time accounting message can be in retransmission buffer
Contextconfigure aaa radius server-policy string servers buffering acct-start lifetime number
Treelifetime
Range1 to 25
Unitshours

Notes

This element is mandatory.

Introduced 20.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

max number
Synopsis Maximum time between accounting message resend attempts
Contextconfigure aaa radius server-policy string servers buffering acct-start max number
Treemax
Range1 to 3600
Unitsseconds

Notes

This element is mandatory.

Introduced 20.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

min number
Synopsis Minimum time between accounting message resend attempts
Contextconfigure aaa radius server-policy string servers buffering acct-start min number
Treemin
Range1 to 3600
Unitsseconds

Notes

This element is mandatory.

Introduced 20.7.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

acct-stop
Synopsis Enable the acct-stop context
Context configure aaa radius server-policy string servers buffering acct-stop
Treeacct-stop
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

lifetime number
Synopsis Time accounting message can be in retransmission buffer
Contextconfigure aaa radius server-policy string servers buffering acct-stop lifetime number
Treelifetime
Range1 to 25
Unitshours

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

max number
Synopsis Maximum time between accounting message resend attempts
Contextconfigure aaa radius server-policy string servers buffering acct-stop max number
Treemax
Range1 to 3600
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

min number
Synopsis Minimum time between accounting message resend attempts
Contextconfigure aaa radius server-policy string servers buffering acct-stop min number
Treemin
Range1 to 3600
Unitsseconds

Notes

This element is mandatory.

Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

health-check
Synopsis Enter the health-check context
Contextconfigure aaa radius server-policy string servers health-check
Treehealth-check
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

test-account
Synopsis Enter the test-account context
Contextconfigure aaa radius server-policy string servers health-check test-account
Treetest-account
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

hold-down-time number
Synopsis Hold time before reusing a RADIUS server that was down
Contextconfigure aaa radius server-policy string servers hold-down-time number
Treehold-down-time
Range30 to 86400
Unitsseconds
Default 30
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

retry-count number
Synopsis Number of retries for contacting the RADIUS server
Contextconfigure aaa radius server-policy string servers retry-count number
Treeretry-count
Range1 to 256
Default3
Introduced 16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server [server-index] number
Synopsis Enter the server list instance
Contextconfigure aaa radius server-policy string servers server number
Treeserver
Max. Instances32
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[server-index] number
Synopsis RADIUS server index
Context configure aaa radius server-policy string servers server number
Treeserver
Range1 to 16

Notes

This element is part of a list key.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

server-name string
Synopsis RADIUS server name
Context configure aaa radius server-policy string servers server number server-name string
Treeserver-name
String Length1 to 32

Notes

This element is mandatory.

Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

stickiness boolean
Synopsis Allow stickiness in a multi-server application
Contextconfigure aaa radius server-policy string servers stickiness boolean
Treestickiness
Defaulttrue
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

timeout number
Synopsis Time until the next retry to the RADIUS server
Contextconfigure aaa radius server-policy string servers timeout number
Treetimeout
Range1 to 340
Unitsseconds
Default 5
Introduced16.0.R4

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

wpp

Synopsis Enter the wpp context
Context configure aaa wpp
Treewpp
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

portal-group [group-name] string
Synopsis Enter the portal-group list instance
Contextconfigure aaa wpp portal-group string
Treeportal-group
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[group-name] string
Synopsis Portal group name
Context configure aaa wpp portal-group string
Treeportal-group
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

admin-state keyword
Synopsis Administrative state of the portal group
Contextconfigure aaa wpp portal-group string admin-state keyword
Treeadmin-state
Optionsenable, disable
Default disable
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

description string
Synopsis Text description
Context configure aaa wpp portal-group string description string
Treedescription
String Length1 to 80
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

portal [router-instance] string name string
Synopsis Add a list entry for portal
Context configure aaa wpp portal-group string portal string name string
Treeportal
Max. Instances8
Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

[router-instance] string
Synopsis Router on which the portal is configured
Contextconfigure aaa wpp portal-group string portal string name string
Treeportal

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

name string
Synopsis Web portal server name
Context configure aaa wpp portal-group string portal string name string
Treeportal
String Length1 to 32

Notes

This element is part of a list key.

Introduced16.0.R1

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR

system-name string
Synopsis System name used in WPP protocol messages
Contextconfigure aaa wpp system-name string
Treesystem-name
String Length1 to 16
Introduced16.0.R6

Platforms

7450 ESS, 7750 SR, 7750 SR-a, 7750 SR-e, 7750 SR-s, VSR