Hello, I am trying to configure ICX7450 with FortiGate Firewall Radius SSO. It is working ok for most of the cases. The only problem I have is on Windows 10 domain computer using User or computer authentication dot1x. The behaviour is as fallows:
1. The computer authenticates with the Computer Domain account. The switch sends radius accounting START packet and INTERIM packet with the computer User-Name and IP. Till this point everything is working as expected.
2. The User logs in and performs Authentication Request. The switch is not sending Accounting START, STOP or INTERIM packet to the firewall and the accounting session continues. Because of this the User-Name in the firewall is not updated.
3. When some time passes INTERIM Update is sent with the new User-Name by the switch to the firewall and the firewall updates the User-Name.
Question: How to configure the switch to send INTERIM Update immediately after the User logs in.
The interval in which interim updates for RADIUS accounting are sent can be configured and modified using these commands,
device(config)# radius-server accounting interim-updates
device(config)# radius-server accounting interim-interval 1
Please refer to the below guide for further details,
Please let me know if you had any comments or concerns.
I am concerned that you mention the ICX switch is not sending any START/STOP messages.
That is something we should definitely double-check.
An Accounting Start packet is sent to the RADIUS server when a user is successfully authenticated.
To enable start/stop packets for accounting, we should run this command:
device(config)# aaa accounting dot1x default start-stop radius
device(config)# aaa accounting mac-auth default start-stop radius