Note
NAI Routing cannot be enabled for a Local Onboarding AAA Policy. RADSEC and UDP enabled servers can be associated with realms. Dynamic Peer Discovery (RFC 7585) for the specific UDP Server within the realm entry must be Disabled.Identifies a group of access points. The Call Station ID is often configured in a large network using an external NAC or RADIUS server. Possible values are:
Note
Call Station ID allows for Zone authentication with a Centralized site.The appliance sends the accounting requests to a remote RADIUS server.
Note
Realm entries are available when NAI Routing is selected. Up to four realm entries are supported per AAA policy and each realm supports four Authentication servers and four Accounting servers.To add a new realm entry:
Configure the Realm Name in accordance with the user domain name.
Allow a realm entry to reference a UDP server. Note that for this configuration, NAI Realm Routing in AAA Policy needs to be Enabledand Dynamic Peer Discovery (RFC 7585)for the specific UDP Server within the realm entry needs to be Disabled.
Use the NAI Routing in the RADIUS packet to dynamically discover the RADIUS server for the realm. Enter an asterisk (*) as the realm name and enable Peer Discovery in the RADIUS Settings. Dynamic Discovery eliminates the need for static configuration of the server IP address.
When the realm name specifies an asterisk, it matches any realm specified in the
Username attribute. If the realm specifies a string, matching looks for an @ in the
Username RADIUS attribute and performs an exact, case insensitive match between what
comes after the @ and the name of the realm. For example, if the received Username
RADIUS attribute is anonymous@example.com
, then the lookup is for
example.com
. If the realm name starts with a /, the name is treated
as a regular expression. A case insensitive regular expression match is performed
using the regular expression on the value of the entire Username attribute. A trailing
/ indicates the end of the regular expression. A trailing / is optional.