We've setup the VPDN (using L2TP) using RADIUS as AAA server. The authentication part has no problem for both LAC and LNS using two RADIUS servers.
For example when the user login using firstname.lastname@example.org, the LAC will authenticate to LAC radius server using cisco.com and then the LNS will authenticate to the LNS radius server using the full name email@example.com.
But for AAA accounting, both the LAC and LNS will use firstname.lastname@example.org as the user ID to send the RADIUS accounting. In the LAC RADIUS server, only user ID cisco.com exists. My RADIUS servr will drop this accounting packet. Is it possible to configure the LAC router to use cisco.com as the user ID to send the RADIUS accounting?
Since there has been no response to your post, it appears to be either too complex or too rare an issue for other forum members to assist you. If you don't get a suitable response to your post, you may wish to review our resources at the online Technical Assistance Center (http://www.cisco.com/tac) or speak with a TAC engineer. You can open a TAC case online at http://www.cisco.com/tac/caseopen
If anyone else in the forum has some advice, please reply to this thread.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...