RADIUS support for responder
Configuring Responder Policies for RADIUS
-
add responder action <actName> <actType> -
add responder policy <polName> <rule> <actName> -
bind responder policy <polName> <priority> <nextExpr> -type <bindPoint>where<bindPoint>represents one of the RADIUS-specific global bind points.
RADIUS Expressions for Responder
-
RADIUS.IS_CLIENT. Returns TRUE if the connection is a RADIUS client (request) message.
-
RADIUS.IS_SERVER. Returns TRUE if the connection is a RADIUS server (response) message.
-
RADIUS.REQ.CODE. Returns the number that corresponds to the RADIUS request type. A derivative of the num_at class. For example, a RADIUS access request would return 1 (one). A RADIUS accounting request would return 4. -
RADIUS.REQ.LENGTH. Returns the length of the RADIUS request, including the header. A derivative of the num_at class. -
RADIUS.REQ.IDENTIFIER. Returns the RADIUS request identifier, a number assigned to each request that allows the request to be matched to the corresponding response. A derivative of the num_at class. -
RADIUS.REQ.AVP(<AVP Code No>).VALUE. Returns the value of first occurrence of this AVP as a string of type text_t. -
RADIUS.REQ.AVP(<AVP code no>).INSTANCE(instance number). Returns the specified instance of the AVP as a string of type RAVP_t. A specific RADIUS AVP can occur multiple times in a RADIUS message. INSTANCE (0) returns the first instance, INSTANCE (1) returns second instance, and so on, up to sixteen instances. -
RADIUS.REQ.AVP(<AVP code no>).VALUE(instance number). Returns the value of specified instance of the AVP as a string of type text_t. -
RADIUS.REQ.AVP(<AVP code no>).COUNT. Returns the number of instances of a specific AVP in a RADIUS connection, as an integer. -
RADIUS.REQ.AVP(<AVP code no>).EXISTS. Returns TRUE if the specified type of AVP exists in the message, or FALSE if it does not.
RADIUS.REQ.AVP(8).VALUE(0).typecast_ip_address_at
-
RADIUS.REQ.AVP (1).VALUE or RADIUS.REQ.USERNAME.value. Extracts the RADIUS user-name value.
-
RADIUS.REQ.AVP (4). VALUE or RADIUS.REQ. ACCT_SESSION_ID.value. Extracts the Acct-Session-ID AVP (code 44) from the message.
-
RADIUS.REQ.AVP (26). VALUE or RADIUS.REQ.VENDOR_SPECIFIC.VALUE. Extracts the vendor-specific value.
-
RADIUS_REQ_OVERRIDE. Priority/override request policy queue.
-
RADIUS_REQ_DEFAULT. Standard request policy queue.
-
RADIUS_RES_OVERRIDE. Priority/override response policy queue.
-
RADIUS_RES_DEFAULT. Standard response policy queue.
-
RADIUS_RESPONDWITH. Respond with the specified RADIUS response. The response is created with NetScaler expressions, both RADIUS expressions and any others that are applicable.
-
RADIUS.NEW_ANSWER. Sends a new RADIUS answer to the user.
-
RADIUS.NEW_ACCESSREJECT. Rejects the RADIUS request.
-
RADIUS.NEW_AVP. Adds the specified new AVP to the response.
Use Cases
Blocking RADIUS Requests from a Specific Network
-
The priority
-
END as the nextExpr value, to ensure that policy evaluation stops when this policy is matched
-
RADIUS_REQ_OVERRIDE as the queue to which you assign the policy, so that it is evaluated before policies assigned to the default queue
-
add responder action <actName> <actType> -
add responder policy <polName> <rule> <actName> -
bind responder global <polName> <priority> <nextExpr> -type <bindPoint>
> add responder action rspActRadiusReject respondwith radius.new_accessreject
Done
> add responder policy rspPolRadiusReject client.ip.src.in_subnet(10.224.85.0/24) rspActRadiusReject
Done
> bind responder global rspPolRadiusReject 1 END -type RADIUS_REQ_OVERRIDE