ipsec accounting on 1841

May 18, 2006 0 Replies
ipsec accounting on 1841 open original image

Hi all,



i'm using a 1841 to terminate cisco vpn clients. The radius authentication works fine, but the accounting does not. Tcpdumping the radius server i see that several attributes are included in the stop access-request (acct-session time and stuff) but the two most important: acct-input-octets and acct-output-octets (attribute 42 and 43) are missing. I've followed

formatting link
configure the accounting, therefore i have these in the config (besides the normal ipsec config):



aaa accounting network default start-stop group radius aaa accounting connection default start-stop group radius aaa accounting system default start-stop group radius aaa session-id unique



radius-server attribute list vpnaccounting attribute 42-43,46-48,52



radius-server vsa send accounting radius-server vsa send authentication



crypto map vpn-cmap client accounting list default



as i mentioned authentication works from radius, so as accouting, but some attributes are missing from the accounting-request packet and i don't know how to put them there.



Thanks for any help!



regards Adam


Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required