
RADIUS Accounting
One of the most useful outputs provided
by
RADIUS server software is a real-time
list of active
RADIUS users.The snapshot of
user activity in Figure 3 displays the follow-
ing fields:
• Distinguished Name shows the full user
name which was used for the authen-
tication.If the user name is part of
NT
Domain directory services or NetWare
Directory Services
(NDS),or part of UNIX
Network Information Services (NIS),the
distinguished name is the
NT/NDS/NIS
common name or container object
name prepended with the user name.
• The
RADIUS server displays RADIUS
clients,either the RAS’s name or IP
address.
•
RAS Port shows the Remote Access
Server port number,which represents a
unique port number on the
RAS.
• Time contains the date and time at
which the connection was started,
according to the accounting transactions.
• Session
ID contains the unique session
key generated by the
RADIUS server.
RADIUS Accounting tracks the Authentication
and Authorization transactions from begin-
ning to end.
RADIUS Accounting captures
statistics about each session. For instance,
the accounting process allows a
RADIUS
server to track when users start and stop
their dial-in connections.
Using
RADIUS Accounting,the RADIUS server
can maintain:
• A history of all user dial-in sessions,
indicating start time,stop time,and
various statistics for the session
• A current User list indicating which
users are currently connected to which
Remote Access Servers
All Accounting transactions are logged to a
comma-delimited file that can be imported
into standard word processors,spread-
sheets,and database programs and can be
used to generate reports,and for billing.
Figure 3: RADIUS technology provides a
snapshot showing each current connection
made through all RAS devices.
Figure 3 Snapshot of Current User Connections
White Paper RADIUS Security Technology 7
Comentarios a estos manuales