Acct-Authentic & changing usernames

Phil Mayers p.mayers at imperial.ac.uk
Fri Feb 15 19:02:21 CET 2008


Phil Mayers wrote:
> We're bringing a Cisco (formerly Airespace) lightweight wireless system 
> online, and I'm seeing some odd things in the accounting.
> 
> Specifically, the usernames can change in the accounting packets. This 
> causes the default SQL queries (at least, the ones for Postgres under 
> 1.1.7) to generate duplicate entries for the session, because the 
> "where" clause includes the username.
> 
...
> However it seems to consistently set Acct-Authentic to RADIUS for "real" 
> usernames, and "Remote" for unknown or non-authenticated usernames, so 
> it sort of "knows" this is happening.

All,

For the record, this is not in fact the case. I've used some SQL-fu to 
"fix" the problem but I'm still seeing a (very) few changing records 
where the WLC reports "Acct-Authentic = RADIUS" for a username which 
most definitely is *not* valid.

Sigh; anyway, I'll be opening a bug with Cisco about this.



More information about the Freeradius-Users mailing list