698 Appendix A:Supported RADIUS attributesNN47250-500 (320657-F Version 02.01)Table 1: 802.1X attributesAttribute TypeRcv inAccessResp?Sent inAccessReqst?Sent inAcctReqst?Description and ValuesUser-Name 1 No Yes Yes String. Name of the user to beauthenticated. Used only in Requestpackets.User-Password 2 No Yes No Password of the user to be authenticated,unless a CHAP-Password is used.CHAP-Password 3 No Yes No Password of the user to be authenticated,unless a User-Password is used.NAS-IP-Address 4 No Yes Yes IP address sent by the WSS.Service-Type 5 No Yes Yes Access type, which can be one of thefollowing:• 2—Framed; for network user access• 6—Administrative; foradministrative access to the WSS,with authorization to access theenabled (configuration) mode. Theuser must enter the enable commandand the correct enable password toaccess the enabled mode.• 7—NAS-Prompt; for administrativeaccess to the nonenabled mode only.In this mode, the user can still enterthe enable command and the correctenable password to access theenabled mode.For administrative sessions, the WSSalways sends 6 (Administrative).The RADIUS server can reply with oneof the values listed above.If the service-type is not set on theRADIUS server, administrative usersreceive NAS-Prompt access, and networkusers receive Framed access.Note: WSS Software will quietly acceptCallback Framed but you cannot selectthis access type in WSS Software.Filter-Id 11 Yes No Optional Name of an access control list (ACL) tofilter outbound or inbound traffic. Use theform ACL name.in and ACL name.out.(For details, see “Configuring andmanaging security ACLs” (page 407).)