Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

radius-accounting

Syntax

Hierarchy Level

Description

Configure RADIUS accounting options for NAT.

Note:

If you have configured both syslog and RADIUS server for the same stream, NAT PBA logs are sent to the RADIUS server and other logs are sent to the syslog server.

If you want to receive all logs (including NAT PBA and flow logs), you must use different streams for the RADIUS server and syslog server.

Options

session-drop

Drop Source NAT sessions until RADIUS accounting succeeds.

When you enable the session-drop statement at the [edit security nat source radius-accounting] hierarchy, subscribers cannot use a port block until RADIUS logging succeeds for the port block. The device drops the subscriber's NAT PBA sessions until it receives a positive acknowledgement for the RADIUS log sent. The port block is released when the RADIUS logging timeout or a negative acknowledgement is received from the RADIUS accounting server.

When you disable this command, subscribers can continue using the allocated port block even if RADIUS logging fails for the port block.

Required Privilege Level

security—To view this statement in the configuration.

security-control—To add this statement to the configuration.

Release Information

Statement introduced in Junos OS Release 24.2R1.