What Is RADIUS Dynamic Authorization (CoA)?
RADIUS Dynamic Authorization, commonly known as CoA (Change of Authorization), is a powerful extension to the standard RADIUS protocol defined in RFC 5176. It allows a RADIUS server to dynamically modify the attributes of an already-authenticated and active user session — without requiring the user to log out and reconnect.
For ISPs in India managing thousands of broadband subscribers, CoA is not just a convenience — it is a critical operational tool. Whether you need to upgrade a customer's speed mid-session, enforce a Fair Usage Policy (FUP), or disconnect a non-paying subscriber instantly, CoA makes all of this possible in real time.
---
The Problem CoA Solves
In traditional RADIUS authentication flows, once a user is authenticated and a session begins, the parameters of that session — such as bandwidth limits, IP address, and session timeout — are fixed until the session ends.
But real ISP operations are not static. Consider these everyday scenarios:
- A subscriber upgrades their plan mid-month
- A subscriber exhausts their FUP data limit and must be speed-throttled
- An account gets suspended due to non-payment
- A subscriber's session needs to be refreshed after a policy change
Without CoA, the only way to apply new policies would be to wait for the session to expire or manually disconnect the user. CoA eliminates this limitation entirely.
---
How RADIUS CoA Works — Step by Step
Step 1: The Active Session
A subscriber connects to the network. The NAS (Network Access Server) — typically a BRAS, router, or OLT — sends an Access-Request to the RADIUS server. The RADIUS server authenticates the user and sends back an Access-Accept with session attributes like bandwidth profile, session timeout, and IP address. The session is now live.
Step 2: A Policy Change Is Triggered
Something changes on the ISP's side. For example:
- The billing system marks the subscriber as FUP-exceeded
- The subscriber calls support and upgrades their plan
- The network management system detects abuse
This trigger reaches the RADIUS server or a connected system (like OneRADIUS) that needs to act on the live session.
Step 3: The CoA-Request Is Sent
The RADIUS server (acting as the Dynamic Authorization Client or DAC) sends a CoA-Request packet to the NAS. This is the reverse of the usual flow — the server initiates communication to the NAS instead of the other way around.
The CoA-Request packet contains:
- **Session identification attributes** — such as Acct-Session-Id, Framed-IP-Address, or NAS-IP-Address to identify which session to target
- **New policy attributes** — such as updated bandwidth limits using vendor-specific attributes (VSAs)
The CoA-Request is sent to the NAS on UDP port 3799 (the standard Dynamic Authorization port).
Step 4: The NAS Processes the Request
The NAS receives the CoA-Request, verifies the shared secret, identifies the matching active session, and applies the new attributes. The subscriber's session continues uninterrupted — only the policy parameters change.
Step 5: CoA-ACK or CoA-NAK Response
The NAS sends back either:
- **CoA-ACK** — The change was successfully applied
- **CoA-NAK** — The request failed, with an Error-Cause attribute explaining why
---
Disconnect Message (DM) — CoA's Close Cousin
RFC 5176 also defines the Disconnect Message (DM), which works similarly to CoA but instead of modifying a session, it terminates it entirely.
- The RADIUS server sends a **DM-Request** to the NAS
- The NAS terminates the session and sends a **DM-ACK** or **DM-NAK** in response
Disconnect Messages are commonly used when:
- A subscriber's account is suspended for non-payment
- A fraudulent or duplicate session is detected
- Manual session clearing is needed during troubleshooting
---
RADIUS CoA Packet Structure
Understanding the packet structure helps in troubleshooting and configuration.
CoA-Request Packet
- **Code:** 43
- **Identifier:** 1-byte unique ID
- **Length:** Total packet length
- **Authenticator:** 16-byte MD5 hash for security
- **Attributes:** Session ID + new policy attributes (VSAs for bandwidth, etc.)
CoA-ACK Packet
- **Code:** 44
- **Identifier:** Matches the CoA-Request
- **Authenticator:** Response authenticator
CoA-NAK Packet
- **Code:** 45
- **Includes:** Error-Cause attribute (e.g., 503 = Session Not Found)
Disconnect Message Codes
- DM-Request: **Code 40**
- DM-ACK: **Code 41**
- DM-NAK: **Code 42**
---
Key RADIUS Attributes Used in CoA
These are the most commonly used attributes in CoA transactions:
- **Acct-Session-Id** — Unique session identifier from the NAS
- **Framed-IP-Address** — The IP assigned to the subscriber
- **NAS-IP-Address** — The IP of the NAS device
- **NAS-Port-Id** — The port identifier on the NAS
- **User-Name** — The subscriber's username
- **Filter-Id** — Policy or profile name to apply
- **Session-Timeout** — Maximum session duration
- **Idle-Timeout** — Idle time before session termination
- **Vendor-Specific Attributes (VSAs)** — Used for bandwidth control, e.g., Mikrotik-Rate-Limit, Cisco-AVPair for rate-limiting
---
Real-World CoA Use Cases for ISPs
1. FUP (Fair Usage Policy) Enforcement
When a subscriber crosses their monthly data threshold, the billing system triggers a CoA to reduce their speed from, say, 50 Mbps to 2 Mbps — automatically and instantly without disconnecting them.
2. Plan Upgrade Mid-Session
A subscriber calls and upgrades from a 30 Mbps plan to 100 Mbps. The support team triggers a CoA from OneRADIUS and the subscriber immediately gets the higher speed without reconnecting.
3. Account Suspension
When an invoice goes unpaid past the due date, the billing system triggers a Disconnect Message (DM) to kick the subscriber off. Once payment is made, a normal re-authentication restores access.
4. Temporary Speed Boost (Turbo Boost Feature)
Some ISPs offer 'turbo boost' features where a subscriber can temporarily increase their speed for a few hours. CoA makes this possible without any session interruption.
5. Network Abuse Control
If a subscriber is consuming abnormal bandwidth or engaging in abuse, the NOC team can instantly apply a restrictive policy via CoA or disconnect the session via DM.
---
NAS Device Configuration for CoA
For CoA to work, your NAS device must be configured to accept CoA packets from the RADIUS server.
Mikrotik Configuration
On Mikrotik RouterOS, ensure the RADIUS client entry includes the CoA port:
- Go to **RADIUS > Client** and enable **CoA** checkbox
- Set the RADIUS server IP and shared secret
- Ensure port 3799 is open from the RADIUS server to the Mikrotik router
Cisco IOS Configuration
Use the following in your Cisco router config:
- `aaa server radius dynamic-author`
- `client <RADIUS_SERVER_IP> server-key <shared_secret>`
- `port 3799`
- `auth-type any`
Huawei / ZTE / BDCOM
Consult your vendor documentation for enabling RFC 5176 CoA support. Most modern OLTs and BRASes support this natively.
---
How OneRADIUS Implements CoA
OneRADIUS by ARCR Technologies provides a robust and ISP-ready implementation of RADIUS Dynamic Authorization. Here is what makes it stand out for Indian ISPs:
- **Automated CoA triggering** based on FUP thresholds integrated with billing systems
- **Manual CoA/DM dispatch** from the admin dashboard for on-demand session control
- **API-based CoA** — trigger dynamic authorization changes via REST API from any billing or NMS platform
- **Multi-NAS support** — send CoA to multiple NAS devices simultaneously across distributed networks
- **Detailed CoA logs** — every CoA transaction is logged with timestamp, result, and error cause for full auditability
- **VSA library** — pre-configured vendor-specific attributes for all major NAS devices used by Indian ISPs
With OneRADIUS, ISPs can automate their entire subscriber lifecycle management — from authentication to real-time policy enforcement — from a single unified platform.
---
Common CoA Troubleshooting Issues
CoA-NAK with Error-Cause 503 (Session Not Found)
This means the NAS cannot find an active session matching the attributes you sent. Fix: Ensure you are using the correct Acct-Session-Id or Framed-IP-Address that the NAS originally reported in its Accounting-Start packet.
CoA Packets Not Reaching the NAS
Check firewall rules. UDP port 3799 must be open between the RADIUS server and NAS. Also verify the NAS IP is correctly configured in your CoA client settings.
CoA-NAK with Error-Cause 401 (Unsupported Attribute)
The NAS does not support one or more attributes in your CoA-Request. Fix: Remove unsupported attributes or use VSAs supported by that specific NAS vendor.
Shared Secret Mismatch
All CoA packets are silently dropped if the shared secret does not match. Fix: Double-check the shared secret in both OneRADIUS and the NAS RADIUS client configuration.
---
Security Considerations for CoA
- **Always use a strong shared secret** between your RADIUS server and NAS for CoA transactions
- **Restrict CoA source IPs** — configure your NAS to only accept CoA packets from trusted RADIUS server IPs
- **Monitor CoA logs** regularly for unexpected or unauthorized CoA attempts
- **Use RADIUS over IPSec or VPN tunnels** for CoA traffic traversing untrusted networks
---
Conclusion
RADIUS Dynamic Authorization (CoA) is an essential feature for any modern ISP that wants to manage subscriber sessions intelligently and in real time. From FUP enforcement to plan upgrades and account suspensions, CoA gives ISPs the power to control their network without disrupting the subscriber experience.
OneRADIUS makes CoA implementation simple, reliable, and scalable — designed specifically for the needs of ISPs operating in India. Whether you are running a small city-level ISP or a large multi-city broadband network, OneRADIUS gives you full control over every subscriber session on your network.
Ready to implement CoA on your network? [Visit oneradius.com](https://oneradius.com) to learn more or request a free demo today.