Copying User-Name from inner tunnel to outer for accounting

Dominik George via Freeradius-Users <[email protected]> Mon, 20 Jul 2026 17:27:03 +0200
Newsgroups gmane.comp.freeradius.user
Message-ID <[email protected]>
Hi,

I am trying to do accounting for a user that previously authenticated 
through RADIUS. I know that the best way would be to use cui and have 
the NAS send a properly hashed identifier in its Accounting-Request, but 
unfortunately, my NAS does not support re-using the User-Name from the 
Access-Response for accounting. It always sends the anomymous identity 
from EAP instead.

My idea was to save the authenticated user in the auth phase in inner 
tunnel, then extract this again when the accounting request comes in. 
However, I can't get this to work.

What I tried is to set

   post-auth {
     update outer.session-state {
       User-Name := "%{User-Name}"
     }
   }

in inner tunnel, then

   accounting {
     update request {
       User-Name := "%{session-state:User-Name}"
     }
   }

in the outer config. HOwever, it always is empty that way.

I verified that the NAS does correctly send the same Acct-Session-Id for 
both the auth ant the accounting requests, so FreeRADIUS should be able 
to correlate the state.

The accounting request will ultimately be forwarded using the REST module.

Can anyone explain how I could get this to work?

Kind regards,
Nik
- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html