[prev in list] [next in list] [prev in thread] [next in thread] 

List:       freeradius-users
Subject:    Re: Freeradius accounting of inner identity when using PEAP
From:       Alan DeKok <aland () deployingradius ! com>
Date:       2011-12-27 15:20:45
Message-ID: 4EF9E24D.20105 () deployingradius ! com
[Download RAW message or body]

Pietro Accerboni wrote:
> The problem arises from the tunneled nature of PEAP. Accounting works, i
> guess, only on the esternal attribute User-Name, so all users that
> (correctly) configure outer identity with a generic 'anonymous' is
> logged in the accounting session with the same, useless, username:

  You can send a User-Name back in the Access-Accept.  The NAS will use
it for accounting.

> Is there some practical way to get this information from freeradius or,
> better, 'link' this information with the Accounting-Request packets i
> get from the nas after the authentication phase?

  See eap.conf.  Set "use_tunneled_reply"

  Alan DeKok.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic