RADIUS报文如下:
(598) User-Name = "test@sslvpn"
(598) NAS-Identifier = "firewall"
(598) NAS-IP-Address = 172.16.1.1
(598) Calling-Station-Id = "0c-11-11-36-12-11"
(598) Framed-IP-Address = 10.0.161.2
(598) Acct-Session-Id = "0000001120240515175336000001de08100385"
(598) Acct-Session-Time = 1704
(598) H3C-Ip-Host-Addr = "10.0.161.2 0c:11:11:36:12:11"
(598) Attr-26.25506.17 = 0x73736c76706e
(598) Acct-Authentic = RADIUS
(598) Acct-Status-Type = Interim-Update
(598) Acct-Delay-Time = 0
(598) Event-Timestamp = "May 16 2024 02:22:00 CST"
(598) H3C-Product-ID = "H3C SecPath F1080"
(598) H3C-NAS-Startup-Timestamp = 1714264252
没有Acct-Input-Octets 和 Acct-Input-Packets 报文, 导致用户超过闲置时间没有流量radiusserver就把用户踢下线了~~~
NAS配置如下:
sslvpn ip address-pool sslvpnpool 10.0.161.2 10.0.161.254
#
sslvpn gateway gw
ip address 172.16.1.1 port 443
service enable
radius scheme radius1
primary authentication 10.0.126.232 key cipher XXXXX
primary accounting 10.0.126.232 key cipher XXXX
accounting-on enable
key authentication cipher XXXX
key accounting cipher XXXX
timer response-timeout 5
timer realtime-accounting 12 second
nas-ip 172.16.1.1
domain sslvpn
authentication sslvpn radius-scheme radius1 local
authorization sslvpn radius-scheme radius1 local
accounting sslvpn radius-scheme radius1 local
sslvpn context sslvpn111
gateway gw domain sslvpn
ip-tunnel interface SSLVPN-AC1
ip-tunnel address-pool sslvpnpool mask 255.255.252.0
ip-tunnel dns-server primary 10.0.0.1
ip-tunnel dns-server secondary 10.0.0.2
login-message english Welcome to XXX
ip-route-list route-list1
include 0.0.0.0 0.0.0.0
ip-route-list route-list2
include 10.0.0.0 255.0.0.0
default-policy-group route-list2
aaa domain sslvpn
idle-cut traffic-threshold 1024
log user-login enable
session-connections 1000
service enable
(1)
是sslvpn结合radius服务器做认证吗?认证完成之后防火墙不会主动下线sslvpn用户
(0)
是radius server踢用户下线了,因为配置的有闲置无流量下线。而防火墙发给radius服务器的报文中没有带用户的流量信息
我现在不清楚为什么记账报文内没有Acct-Input-Octets Acct-Out-Octets 这两个字段....
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
我现在不清楚为什么记账报文内没有Acct-Input-Octets Acct-Out-Octets 这两个字段....