Adding RADIUS Services
JUNOSe routers support the use of RADIUS services; JUNOS routing platforms, however, do not. To add a new RADIUS service:
- In the SDX Admin navigation pane, highlight the Services folder, and right-click.
- Select New > RADIUS Service.
The New RADIUS Service dialog box appears.
An object for the new service appears in the navigation pane, and basic details for the new service appear in the Main tab of the RADIUS Service pane.
![]()
- Use the field descriptions in RADIUS Service Fields to configure the service, and then click Save.
- Define how the RADIUS service interacts with the JUNOSe router by filling in the fields in the ERX VSA tabs. See:
- Defining Vendor-Specific Attributes in the ERX VSA (I) Tab.
- Defining Vendor-Specific Attributes in the ERX VSA (II) Tab.
RADIUS Service Fields
Use the fields in this section to configure RADIUS services.
Description
Acct. Attribute Key
Acct. Interim Interval (sec)
- Interval between interim accounting messages for this service.
- Value—Number of seconds in the range 0-2147483647
- No value—The globally configured accounting interim value is used.
- 0—Interim accounting is disabled for this service.
Radius Class
- Arbitrary value. If the RADIUS server supplies this value, the network access server (NAS) includes it in all accounting packets for the subscriber.
- Value—Text
- Default—No value
Idle Timeout (sec)
- Time at which the RADIUS session ends if there is no activity between the subscriber and the RADIUS server.
- Value—Number of seconds in the range 0-2147483647
- Default—No value
Session Timeout (sec)
- Time at which the RADIUS session ends.
- Value—Number of seconds in the range 0-2147483647
- Default—No value
Reply
- Text to be displayed to the subscriber. This is the RADIUS ReplyMessage attribute.
- Value-Text string
- Default-No value
Status
State Machine
- DN of a state machine that identifies a set of transitions associated with a workflow for this service. If you specify a DN, all subscriptions to this service should be governed by this state machine.
- Value—Text
- Default—No value
Defining Vendor-Specific Attributes in the ERX VSA (I) Tab
There are two tabs in the RADIUS service that you can use to enter information about how the RADIUS service interacts: ERX VSA (I) and ERX VSA (II).
You can set the following values in the ERX VSA (I) tab.
![]()
Primary DNS
- Subscriber's DNS address negotiated during Internet Protocol Control Protocol (IPCP).
- Value—4-octet IP address
- Default—No value
Secondary DNS
- Subscriber's secondary DNS address negotiated during IPCP.
- Value—4-octet IP address
- Default—No value
Primary WINS
- Subscriber's Windows Internet Naming Service (WINS), also referred to as a NetBIOS Name Server (NBNS), address negotiated during IPCP.
- Value—4-octet IP address
- Default—No value
Secondary WINS
- Subscriber's secondary WINS address negotiated during IPCP.
- Value—4-octet IP address
- Default—No value
Virtual Router Name
Local Address Pool
Local Interface
Ingress Policy Name
Egress Policy Name
Ingress Statistics
- blank—Router uses default setting
- disable—Disables generation of statistics
- enable—Enables generation of statistics
Egress Statistics
- blank—Router uses default setting
- disable—Disables generation of statistics
- enable—Enables generation of statistics
Sa Validate
IGMP Enable
- Specifies whether the subscriber can register to receive multicast services through Internet Group Management Protocol (IGMP).
- Value
Redirect VR Name
- VR name that identifies the VR context in which to authenticate the subscriber.
- Value—Text
- Default—No value
QoS Profile Name
- Name of the quality of service (QoS) profile to attach to the subscriber's interface.
- Value—Text
- Default—No value
PPPoE Description
- String pppoe<mac addr> that the router obtains from Point-to-Point Protocol over Ethernet (PPPoE) operations and sends to the RADIUS server.
- Value—Text
- Default—No value
Service Bundle
Defining Vendor-Specific Attributes in the ERX VSA (II) Tab
There are two tabs in the RADIUS service that you can use to enter information about how the RADIUS service interacts: ERX VSA (I) and ERX VSA (II).
You can set the following values in the ERX VSA (II) tab.
![]()
CLI Initial Access Level
- Privilege level for the JUNOSe command-line interface (CLI) that determines the command to which subscribers of this RADIUS service have access.
See the JUNOSe System Basics Configuration Guide for information about security and the JUNOSe CLI.
CLI Allow All VR Access
- blank—Router uses default setting.
- disable—Subscribers can access only the specified VRs.
- enable—Subscribers can access all VRs.
Alternate CLI Access Level
Alternate CLI Virtual Router
Atm Service Category
- blank—Router uses default setting
- UBR—Unspecified bit rate (UBR)
- UBRPCR—UBR with a peak cell rate (PCR)
- nrtVBR—Variable bit rate, non-real time (VBR-NRT)
- CBR—Constant bit rate (CBR)
Atm PCR
Atm SCR
ATM MBS