cancel
Showing results for 
Search instead for 
Did you mean: 

Send radius accounting interim-updates when User-Name Changes

lyubomir_trayko
New Contributor II

Hello, I am trying to configure ICX7450 with FortiGate Firewall Radius SSO. It is working ok for most of the cases. The only problem I have is on Windows 10 domain computer using User or computer authentication dot1x. The behaviour is as fallows:

1. The computer authenticates with the Computer Domain account. The switch sends radius accounting START packet and INTERIM packet with the computer User-Name and IP. Till this point everything is working as expected.

2. The User logs in and performs Authentication Request. The switch is not sending Accounting START, STOP or INTERIM packet to the firewall and the accounting session continues. Because of this the User-Name in the firewall is not updated.

3. When some time passes INTERIM Update is sent with the new User-Name by the switch to the firewall and the firewall updates the User-Name.

Question: How to configure the switch to send INTERIM Update immediately after the User logs in. 

5 REPLIES 5

Orlando_Elias
RUCKUS Team Member

Hello lyubomir_traykov

I understand your point.
I haven't tested such a scenario in my lab, so I am not able to tell whether the behavior observed is expected, but it's something that definitely worths the try.
For a better approach, the best action is opening a support case, that way we can replicate in our lab and even request for the fix/enhancement in case we found it's applicable.
As a workaround, I can think of enabling COA to see if that will force the interim update to be immediately sent when the new user logs in:
device(config)# aaa authorization coa enable
With regards,
--
Orlando Elias
Technical Support