Got it

[NE Router-Troubleshooting] The Telnet User Is Logged Out Because the Accounting Function Is Not Enabled on the RADIUS Server

Latest reply: Jun 25, 2021 17:44:48 165 1 1 0 0

Fault Symptom

The RADIUS server authenticates the Telnet user. However, the Telnet user is forced to log out about 1 minute after logging in to the device. The fault persists after the user re-logs in to the device.

Fault Analysis

1.     Delete the authentication-mode aaa command configured on the user-interface vty 0 4 command and use local authentication. No fault occurs.

2.     Configure the authentication-mode aaa command again and find that the user still goes offline.

3.     Enable the debugging of the RADIUS, the following information is displayed.

[Acct-Status-Type(40) ]      [6 ] [2]

Acct-Status-Type(40) indicates the type of accounting request packets; 2 indicates that the accounting is stopped. The accounting function is disabled by the RADIUS server.

4.     Check AAA configurations:

domain default
  authentication-scheme  admin
  accounting-scheme admin    //Accounting scheme
  radius-server admin
accounting-scheme admin
  accounting-mode radius      //The accounting mode is the RADIUS accounting.

The accounting function is not enabled on the RADIUS server. As a result, the RADIUS server fails to charge the Telnet user and sends the offline packet to the device. The user is logged out.

Procedure

1.     Delete the accounting mode of the device, or run the accounting-mode none command in the accounting scheme view to set the accounting mode to none.

After the preceding operation, the Telnet user logs in to the device and keeps online. The fault is rectified.

Summary

AAA needs to be correctly configured based on the actual situation. The user may fail to go online if irrelevant functions are configured.


andersoncf1
MVE Author Created Jun 25, 2021 17:44:48

Thanks for sharing knowledge. Very useful
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.