Specifications
7-41
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 7 User Management: Configuring Authentication Servers
RADIUS Accounting
Note The Auth Test feature does not apply to S/Ident, Windows NetBIOS SSO, and Cisco VPN SSO
authentication provider types.
RADIUS Accounting
The Clean Access Manager can be configured to send accounting messages to a RADIUS accounting
server. The CAM sends a Start accounting message when a user logs into the network and sends a Stop
accounting message when the user logs out of the system (or is logged out or timed out). This allows for
the accounting of user time and other attributes on the network.
You can also customize the data to be sent in accounting packets for login events, logout events, or shared
events (login and logout events).
Enable RADIUS Accounting
Step 1 Go to User Management > Auth Servers > Accounting > Server Config.
Table 7-1 Example “Authentication Failed” Results
Message Description
Message: Invalid User Credential
Correct user name, incorrect password
Message: Unable to find the full DN
for user <User Name>
Correct password, incorrect user name (LDAP provider)
Message: Client Receive Exception:
Packet Receive Failed (Receive timed
out)
Correct password, incorrect user name (RADIUS
provider)
Message: Invalid Admin(Search)
Credential
Correct user name, correct password, incorrect value
configured in the Search(Admin) Full DN field of the
Auth provider (e.g. incorrect CN configured for LDAP
Server)
Message: Naming Error (x.x.x.x: x)
Correct user name, correct password, incorrect value
configured in the Server URL field of the Auth provider
(e.g. incorrect port or URL configured for LDAP)