RADIUS Accounting for 802.1X Authentication and MAC Authentication

802.1X accounting and MAC authentication accounting record information about the clients that were successfully authenticated and allowed access to the network. When 802.1X or MAC authentication accounting is enabled, the device sends accounting information to the RADIUS server when a session begins and a message when the session ends.

An Accounting Start packet is sent to the RADIUS server when a user is successfully authenticated. The Start packet indicates the start of a new session and contains the user's MAC address and physical port number. The 802.1X or MAC session state changes to Authenticated and Permit after a response to the accounting Start packet is received from the accounting server. If the Accounting service is not available, the session status changes to Authenticated and Permit after a RADIUS timeout. The device retries authentication requests three times by default or the number of times configured on the device.

When 802.1X or MAC authentication accounting is enabled on the RUCKUS device, it sends the following information to a RADIUS server whenever an authenticated client (user) logs into or out of the RUCKUS device:

  • The user name
  • The session ID
  • The user MAC address
  • The authenticating physical port number
  • Input bytes/octets
  • Input packets
  • Output octets/bytes
  • Output packets
  • VLAN-ID
  • Elapsed Session-time
  • Framed IP Address (client IP address)
    Note: The IP address is set in the RADIUS accounting message only when the ICX device is running a router image.

An Accounting Stop packet is sent to the RADIUS server when one of the following events occurs:

  • The user logs off
  • The port goes down
  • The port is disabled
  • The user fails to re-authenticate after a RADIUS timeout
  • The 802.1X port control-auto configuration changes
  • The MAC session clears (through use of the clear dot1x mac-session or clear mac-auth sessions commands)

The Accounting Stop packet indicates the end of the session and the time the user logged out.

Interim RADIUS Accounting Update for 802.1X Authentication and MAC Authentication

Apart from setting the device to send the Accounting Start and Accounting Stop messages, you can configure the device to send interim accounting update messages to the RADIUS server at regular intervals. At regular intervals, the interim update message sends the status of an active session and current user statistics, including the duration of the current session and information on current data usage.

The interim update message is useful for billing longer sessions. Normally, a RADIUS server uses the information from Accounting Start and Accounting Stop packets to generate accounting information for billing or other purposes. Information such as session time and number of bytes transferred that are critical for billing are available only in the Accounting Stop packets. If the device becomes unavailable unexpectedly, the data required for billing the sessions initiated on the device is not recorded. In such scenarios, interim updates send useful information regarding a specific session to the RADIUS server at regular intervals. For more information about the RADIUS attributes that support interim updates, refer to the list of supported RADIUS attributes in Flexible Authentication.

The interim update and the interval between each interim update can also be configured on the device using the radius-server accounting interim-updates and radius-server accounting interim-interval commands. The RADIUS accounting for 802.1X authentication and MAC authentication accepts either the interim update interval value configured using the RADIUS attribute or the interval time value set on the device, whichever is higher.