Skip to main content
Akmostafa
Explorer
August 18, 2022
Solved

Accounting to FortiAuthenticator and user usage profiles

  • August 18, 2022
  • 12 replies
  • 5383 views

Hello Friends.

I have followed the exact steps described in the below KB.

The user is successfully authenticated to the SSID and is viewed on the Fortigate as a firewall user (#dia firewall auth list)

I can see from packet capture that FG is sending the interm accounting messages to FAC on the specified period  and I see the ACC response packets from fAC in the sniffer.

 

However, on FAC -- monitor --- radius sessions I see 0 accounting sessions.

When I view user usage details : it is not counting anything and the user is not disconnected when reaching the max kilobytes specified in the suer profile.

 

I am not sure what I am missing here.

 

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Usage-Profiles-not-enforced-for-RADIUS/ta-p/198682

 

 

Best answer by Markus_M

Hello,

 

please also check this one (that should match the ports you are using):

2022-08-24_18-05-51.png

Best regards,

 

Markus

12 replies

Markus_M
Staff & Editor
Staff & Editor
August 20, 2022

Hello Akmostafa,

 

there must be an "Accounting Start" packet as well, prior to the interim updates, which should contain only the updates to the session.

Under your FortiAuthenticator debug, you should see (https://fac-ip/debug) a section for RADIUS accounting. Check this one to see what is done with the respective sessions.

 

Best regards,

 

Markus

Akmostafa
AkmostafaAuthor
Explorer
August 21, 2022

I verified RADIUS accounting start is sent. (See snapshot , note the duplicate packets are due to that I am capturing from Fortigate and the packets are being caputured many times due to packet seeing on input and output interfaces)

On the debugs I can only see the below lines:

 

08/21/2022 14:23:25 [588305792] FortiAuthenticator rad_accounting [1260] [DEBUG]: [Maintenance] Publish accounting state to file
08/21/2022 14:23:25 [588305792] FortiAuthenticator rad_accounting [1260] [INFO]: Updated accounting sessions file. Status = 0
08/21/2022 14:23:55 [588305792] FortiAuthenticator rad_accounting [1260] [DEBUG]: [Maintenance] Save expired accounting sessions to DB
08/21/2022 14:24:22 [588305792] FortiAuthenticator rad_accounting [1260] [DEBUG]: [Maintenance] Publish accounting state to file
08/21/2022 14:24:22 [588305792] FortiAuthenticator rad_accounting [1260] [INFO]: Updated accounting sessions file. Status = 0
08/21/2022 14:24:22 [588305792] FortiAuthenticator rad_accounting [1260] [DEBUG]: [Maintenance] Publish accounting state to file
08/21/2022 14:24:22 [588305792] FortiAuthenticator rad_accounting [1260] [INFO]: Updated accounting sessions file. Status = 0
08/21/2022 14:25:36 [588305792] FortiAuthenticator rad_accounting [1260] [INFO]: Updated accounting sessions file. Status = 0
08/21/2022 14:28:36 [588305792] FortiAuthenticator rad_accounting [1260] [DEBUG]: [Maintenance] Publish accounting state to file
08/21/2022 14:28:36 [588305792] FortiAuthenticator rad_accounting [1260] [INFO]: Updated accounting sessions file. Status = 0
08/21/2022 14:28:36 [588305792] FortiAuthenticator rad_accounting [1260] [DEBUG]: [Maintenance] Publish accounting state to file

 

accnt.PNG

Markus_M
Staff & Editor
Staff & Editor
August 21, 2022

Hi,

 

do you have accounting enabled on the interface?

Accounting MonitorAccounting Monitor

Best regards,

 

Markus

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!