Technical Tip: No RADIUS Accounting packets for 'Remote RADIUS Users' when using IKEv2
| Description | This article describes an issue with RADIUS Accounting when using IKEv2 with a remote RADIUS User. When using IKEv2 with RADIUS authentication, RADIUS Accounting packets can be seen on the RADIUS Server for users on the RADIUS Server, however, when a 'Remote RADIUS User' config is used (in order to use FortiToken), there are no RADIUS Accounting packets. |
| Scope | FortiOS. |
| Solution |
FortiGate configuration.
RADIUS configuration:
Remote RADIUS User:
RADIUS User.
Group for testing with RADIUS User:
A capture on both scenarios shows that RADIUS Accounting packets are not being sent for the case when a Remote RADIUS user is being used.
RADIUS User: normal.user.
Remote RADIUS User: tobias.ahlfors.
Note: This is currently under investigation, and there is no fix available yet. This only affects IKEv2 with Remote RADIUS User, on IKEv1, there is no issue, so a possible workaround is to use IKEv1 if FortiToken is mandatory.
Related article: Technical Tip: Configure Fortinet Single Sign On (FSSO) for Dialup IPsec VPN users via Radius-Accounting |


