Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Junos CLI Reference
Table of Contents Expand all
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

radius-accounting

date_range 24-Jun-24

Syntax

content_copy zoom_out_map
   radius-accounting {   
      session-drop;
   }

Hierarchy Level

content_copy zoom_out_map
[edit security nat source]

Description

Configure RADIUS accounting options for NAT.

Note:

If you have configured both syslog and RADIUS server for the same stream, NAT PBA logs are sent to the RADIUS server and other logs are sent to the syslog server.

If you want to receive all logs (including NAT PBA and flow logs), you must use different streams for the RADIUS server and syslog server.

Options

session-drop

Drop Source NAT sessions until RADIUS accounting succeeds.

When you enable the session-drop statement at the [edit security nat source radius-accounting] hierarchy, subscribers cannot use a port block until RADIUS logging succeeds for the port block. The device drops the subscriber's NAT PBA sessions until it receives a positive acknowledgement for the RADIUS log sent. The port block is released when the RADIUS logging timeout or a negative acknowledgement is received from the RADIUS accounting server.

When you disable this command, subscribers can continue using the allocated port block even if RADIUS logging fails for the port block.

Required Privilege Level

security—To view this statement in the configuration.

security-control—To add this statement to the configuration.

Release Information

Statement introduced in Junos OS Release 24.2R1.

footer-navigation