radattr Plugin
Purpose
The radattr
plugin for libcharon
provides and prints RADIUS attributes
forwarded via strongSwan specific, private IKEv2 notify payloads (40969
).
The plugin is disabled by default and can be enabled with the
./configure
option
--enable-radattr
Behavior
RADIUS attributes to be forwarded to a peer are defined in files named after the local EAP-Identity (or IKE-Identity) used during authentication. Received attributes are written to the log.
Configuration
The radattr
plugin is configured using the following options in the
charon.plugins.radattr
section of strongswan.conf
:
Key | Default | Description |
---|---|---|
dir |
Directory where RADIUS attributes are stored in client-ID specific files |
|
message_id |
|
RADIUS attributes are added to all IKE_AUTH messages by default [ |