Support Support Downloads Knowledge Base Juniper Support Portal Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

[SBR] Processing (COA/DM) Messages from Proxy Target



Article ID: KB36359 KB Last Updated: 22 Dec 2020Version: 1.0

This article talks about proxy target configuration and also explains the workflow when a (CoA/DM) disconnect is issued from the proxy target.



Consider a proxy setup as below:

NAS(> Proxy Server ([standalone]-> Proxy Target([Standalone]

Proxy Server Configuration

# more proxy.ini
;RealmPrefix = /
RealmSuffix = @


# more
Enable = 1

IncludeDeviceModel = 1

# radius.ini
Enable = 1
CheckReversePath = yes
ForwardMethod = session-table

# dbclusterlocal.gen
; enable IncludeDynAuth if dynamic authorization proxy is enabled
IncludeDynAuth = 1
# Dbc_mapping.xml
(changes to get the session details for these below attributes in SessionControlScript)
At the end of xml:
    <attributeMapping field="Sbr_NasClientName"     attribute="Funk-NAS-Identifier">
    <attributeMapping field="Sbr_NasDeviceModel"    attribute="Funk-Device-Model">
    <attributeMapping field="Sbr_ProxyState"        attribute="Funk-Proxy-State">
    <attributeMapping field="Sbr_ProxyRealm"        attribute="Funk-Realm-Name">

Now let us see the SBR UI configuration that is needed:

  1. Create a RADIUS client with a valid name (name should be NAS name) and Description. Give the IP address as NASIPAddress.

  1. In RADIUS Client > Advanced Configuration, set the COA/DM port as 3799. Provide the COA shared secret and POD shared secret.

  1. Also, create the target proxy and give its IP address.

Proxy Target Configuration

Add “NAS-IP-Address” and “NAS-Identifier” as the required attributes for the "- Standard Radius -” device model as shown below:

    <controlledDeviceModel id="- Standard Radius -" vendor="juniper" model="Standard RADIUS DM Support" dictionary="radius">
            <!--specifies default port, can be changed per device -->
            <radiusPort name="RFC3576" description="Dynamic Authorization via RADIUS" port="3799"/>
            <action name="query">
                <localSessionQuery description="return local session data"/>
            <action name="disconnect">
                <radiusRequest description="RFC 3576 Disconnect Message" code="DM" portName="RFC3576" dictionary="radius">
                        <requiredAttribute name="Acct-Session-Id"/>
                        <requiredAttribute name="NAS-IP-Address"/>
                        <requiredAttribute name="NAS-Identifier"/>
                        <!--this device does not send Stop when we knock someone off -->
                        <sessionStop description="Simulated Session Stop"/>
                        <!--assume bad session record -->
                        <sessionStop description="Cleaning Session Database"/>
  1. Create a RADIUS client that is the same as that configured in the Proxy Server, except the IP Address, which should be the Proxy Server IP Address.

  1. In RADIUS Client > Advanced Configuration, set the COA/DM port as 3799. Provide the COA shared secret and POD shared secret as that given for the Proxy Server.

  1. Execute a Proxy Disconnect from target:

After the proxy disconnect from target, observe that the session gets deleted both in the Proxy Target and Proxy Server machine.

Find the packet flow as below:

Packet flow

     NAS                                               Proxy                                   Proxy target

     |     Accounting request                            |           Proxy request                     |
     |    ----------------------------->                 |  ---------------------------------->        |
     |     Accounting response                           |           Proxy response                    |
     |    <-------------------------------               |  <----------------------------------        |
     |                                                   |                                             |
     |                                                   |           Proxy Disconnect request          |
     |                                                   |     < -------------------------------       |
     |              UDP Dyn Auth request                 |                                             |                             
     |      <--------------------------------            |                                             |
     |              UDP Dyn Auth response                |                                             |                             
     |     -------------------------------->             |                                             |
     |                                                   |           Proxy Disconnect ACK              |
     |                                                   |     --------------------------------->      |


Note that SBR does not support a disconnect from more than one NAS in a proxy scenario.


Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search