Do you support RADIUS accounting?
Yes, on 1813. Point your equipment's accounting server at the same addresses you already use for authentication, with the same shared secret. It is worth turning on.
It gives you the Sessions page. The authentication log tells you who was let on; accounting tells you who is still there — the device, the address it is holding, the switch port it is plugged into, how long it has been on and how much it has moved. That is what answers "which device had 10.6.101.42 at three o'clock", which nothing else in the product can.
And it is what makes disconnecting possible. The Disconnect button hangs off a live session, so with no accounting there is nothing to press — see "How do I disconnect a device that is already connected?".
RADSec accounting goes to 1813 as well, not 2083: that is where UniFi sends it, so that is where we listen. Accounting arriving on 2083 is accepted too, for equipment that follows the RFC.
Related questions
- RADIUS or RADSec — which should I use?
- Is standard RADIUS safe enough to use?
- What address and port do I point my equipment at?
- A printer keeps failing with a TLS error. Why would I let a site accept older TLS?
- A camera or printer is still refused after I allowed older TLS. What now?
- Can Passbeam authenticate our VPN as well as the network?
- Our VPN concentrator serves several clients from one address. Will Passbeam tell them apart?
- Can I let only some people use the VPN, but everyone use the office network?
- Can I require a second factor on the VPN?
- Do you support PEAP, MSCHAPv2 or EAP-TTLS?
- How do I disconnect a device that is already connected?
- What firewall rules does the connector need?
Still stuck? Ask us, or read the rest of the knowledge base.