accounting to local and remote server

d tbsky tbskyd at gmail.com
Thu May 28 06:23:58 CEST 2015


2015-05-27 1:35 GMT+08:00 Alan DeKok <aland at deployingradius.com>:
> On May 26, 2015, at 12:49 PM, d tbsky <tbskyd at gmail.com> wrote:
>>    I need to setup proxy for a realm, and sent accounting to remote
>> radius server.
>> but I want to keep a copy of accounting data at local radius server too.
>
>   That's easy.  Configure local accounting.  Configure proxying.  Done.

yes you are right. I have misunderstanding that if I configure proxy,
local will not get accounting.

now I have setup testing  proxy with the upstream. I am a little
confused about the attribute which upstream sent back.

for example, If I use "test at upsteam" to authenticate, upstream will
sent back "User-Name = test" alone with "Access-Accept".
then the NAS will use username "test" to do accounting, not
"test at upstream". but in my local accounting, I want to keep the
nostrip name.
I know I can filter out the reply attribute, but should I do that? or
there are better ways to do with this kind of situation.
eg: upstream get the strip accounting name he wants, and I get the
nostrip accounting name I want?

and should I enable "attr_filter.post-proxy" to further protecting our site?


More information about the Freeradius-Users mailing list