Support for the RADIUS user-name attribute in Access-Accept messages

Authentication-enabled ports support the RADIUS user-name (type 1) attribute in the Access-Accept message returned during authentication.

When sFlow is enabled on the port, sFlow samples taken from the interface include the username of 802.1X client based on the source MAC address of the sFlow sample. For example, when the user-name attribute is sent in the Access-Accept message, it is then available for display in sFlow sample messages sent to a collector, and in the output of some show dot1x commands, such as show dot1x session-info.

To enable the user-name attribute, add the following attribute on the RADIUS server.

Table 1. RADIUS user-name attribute details

Attribute name

Type

Value

user-name

1

name (string)