RADIUS support for the rewrite feature
-
Remove the domain\\ portion of the RADIUS user-name AVP to simplify single sign-on (SSO).
-
Insert a vendor-specific AVP, such as the MSISDN field used in telephone company operations to contain subscriber information.
-
The NetScaler does not re-sign rewritten RADIUS requests or responses. If the RADIUS authentication server requires signed RADIUS messages, authentication will fail.
-
The currently available RADIUS expressions do not work with RADIUS IPv6 attributes.
Configuring Rewrite Policies for RADIUS
-
add rewrite action <actName> <actType> -
add rewrite policy <polName> <rule> <actName> -
bind rewrite policy <polName> <priority> <nextExpr> -type <bindPoint>where<bindPoint>represents one of the rewrite-specific global bind points.
RADIUS Expressions for Rewrite
-
RADIUS.IS_CLIENTReturns TRUE if the connection is a RADIUS client (request) message. -
RADIUS.IS_SERVERReturns TRUE if the connection is a RADIUS server (response) message.
-
RADIUS.REQ.CODEReturns the number that corresponds to the RADIUS request type. A derivative of the num_at class. For example, a RADIUS access request would return 1 (one). A RADIUS accounting request would return 4. -
RADIUS.REQ.LENGTHReturns the length of the RADIUS request, including the header. A derivative of the num_at class. -
RADIUS.REQ.IDENTIFIERReturns the RADIUS request identifier, a number assigned to each request that allows the request to be matched to the corresponding response. A derivative of the num_at class. -
RADIUS.REQ.AVP(<AVP Code No>).VALUEReturns the value of first occurrence of this AVP as a string of type text_t. -
RADIUS.REQ.AVP(<AVP code no>).INSTANCE(instance number)Returns the specified instance of the AVP as a string of type RAVP\_t. A specific RADIUS AVP can occur multiple times in a RADIUS message. INSTANCE (0) returns the first instance, INSTANCE (1) returns second instance, and so on, up to sixteen instances. -
RADIUS.REQ.AVP(<AVP code no>).VALUE(instance number)Returns the value of specified instance of the AVP as a string of type text_t. -
RADIUS.REQ.AVP(<AVP code no>).COUNTReturns the number of instances of a specific AVP in a RADIUS connection, as an integer. -
RADIUS.REQ.AVP(<AVP code no>).EXISTSReturns TRUE if the specified type of AVP exists in the message, or FALSE if it does not.
RADIUS.REQ.AVP(8).VALUE(0).typecast_ip_address_at
-
RADIUS.REQ.AVP (1).VALUE or RADIUS.REQ.USERNAME.valueExtracts the RADIUS user-name value. -
RADIUS.REQ.AVP (4). VALUE or RADIUS.REQ. ACCT\_SESSION\_ID.valueExtracts the Acct-Session-ID AVP (code 44) from the message. -
RADIUS.REQ.AVP (26). VALUE or RADIUS.REQ.VENDOR\_SPECIFIC.VALUEExtracts the vendor-specific value.
-
RADIUS_REQ_OVERRIDEPriority/override request policy queue. -
RADIUS_REQ_DEFAULTStandard request policy queue. -
RADIUS_RES_OVERRIDEPriority/override response policy queue. -
RADIUS_RES_DEFAULTStandard response policy queue.
-
RADIUS.NEW_AVPReturns the specified RADIUS AVP as a string. -
RADIUS.NEW_AVP_INTEGER32Returns the specified RADIUS AVP as an integer. -
RADIUS.NEW_AVP_UNSIGNED32Returns the specified RADIUS AVP as an unsigned integer. -
RADIUS.NEW_VENDOR_SPEC_AVP(<ID>, <definition>)Adds the specified extended vendor specific AVPs to the connection. For<ID>, substitute a long number. For<definition>, substitute a string that contains the data for the AVP. -
RADIUS.REQ.AVP_STARTReturns the location between the end of the RADIUS header and the start of the AVPs. Used in rewrite actions.Example:
add rewrite action insert1 insert_after radius.req.avp_start radius.new_avp(33, "NEW AVP")
-
RADIUS.REQ.AVP_ENDReturns the location at the end of radius message (or in other words end of all AVPs) in radius message. Used when performing rewrite actions.Example:
add rewrite action insert2 insert_before radius.req.avp_end "radius.new_avp(33, \"NEW AVP\")"
-
RADIUS.REQ.AVP_LISTReturns the location at the start of the AVPs in a RADIUS message, and the length of the RADIUS message, excluding the header. In other words, returns all AVPs in a RADIUS message. Used to perform Rewrite actions.Example:
add rewrite action insert3 insert_before_all radius.req.avp_list "radius.new_avp(33, \"NEW AVP\")" -search "avp(33)"
-
INSERT_AFTER
-
INSERT_BEFORE
-
INSERT_AFTER_ALL
-
INSERT_BEFORE_ALL
-
DELETE
-
DELETE_ALL
-
REPLACE
-
REPLACE_ALL
INSERT_ actions can be used to insert a RADIUS AVP into a RADIUS connection.
Use Cases
Rewriting the User-Name AVP
add rewrite action rwActRadiusDomainDel replace radius.req.user_name q/RADIUS.NEW_AVP(1,RADIUS.REQ.USER_NAME.VALUE.AFTER_STR(" "))/
add rewrite policy RadiusRemoveDomainPol true rwActRadiusDomainDel
Inserting a Vendor-Specific AVP
add rewrite action rwActRadiusInsMSISDN insert_after radius.req.avp_start RADIUS.NEW_VENDOR_SPEC_AVP(<VENDOR ID>, "RADIUS.NEW_AVP(<Attribute Code>, <MSISDN>)")
add rewrite policy rwPolRadiusInsMSISDN true rwActRadiusInsMSISDN
bind rewrite global rwPolRadiusInsMSISDN 100 NEXT -type RADIUS_REQ_DEFAULT