cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
542
Views
4
Helpful
5
Replies

Send radius accounting to a server that isn't ISE

ryan14
Level 1
Level 1

What is the drawback or what will break if I authenticate my machines to ISE via radius, but send the accounting information to another server that isn't an ISE node? A server of ours requires raw accounting data to function, and ISE can only send the data in syslog format. The NAD can only send to one radius acct server at a time (not multiple).

5 Replies 5

I think you can assign specific server and send all accounts to it.

Yes the NAD can support multi AAA server' servers for authc/authz and server for accout.

MHM

@MHM Cisco World - are you sure that IOS supports sending RADIUS Accounting to more than one RADIUS server?  When I look at the command on the IOS device, e.g.

aaa accounting identity default start-stop group danc-client-radius-group

it specifies the AAA group (which can contain one or more servers)- but in the traffic flow, I only see the IOS sending RADIUS Accounting to ONE of the servers. It's always the current server that is Alive/Active according to the SMD.

Is there an IOS command to tell the device to send to multiple servers?   I know that with IBNS 2.0 you can split the Authentication traffic to use one Group of servers, and the accounting to use another Group of servers.

I recall this question from my service provider days (Cisco Prime Access Registrar) and it support it either (back in the day). The solution was to send accounting traffic to an app that would duplicate the UDP traffic to various destinations.  A load balancer can do that. Even nginx could do this (as an open source suggestion). 

 

Interesting' I will check and update you.

MHM

andrewswanson
Level 7
Level 7

Does your NAD support AAA Broadcast Accounting? According to Cisco documentation:

AAA broadcast accounting allows accounting information to be sent to multiple AAA servers at the same time; that is, accounting information can be broadcast to one or more AAA servers simultaneously

I've not tried this myself, but maybe something like this would work (with ISE defined in one group and the other server in the second group)

aaa accounting identity default start-stop broadcast group grp1 group grp2

hth
Andy

Arne Bier
VIP
VIP

Excellent - that looks like it would do the trick. Thanks for sharing that.