Bug ID 920541: Incorrect values in 'Class Attribute' in Radius-Acct STOP request

Last Modified: Jan 22, 2021

Bug Tracker

Affected Product:  See more info
BIG-IP APM(all modules)

Known Affected Versions:
13.1.0,,,,,,,,, 13.1.1,,,,, 13.1.3,,,,,, 14.0.0,,,,,, 14.0.1,, 14.1.0,,,,,, 14.1.2,,,,,,,,, 14.1.3,, 15.0.0, 15.0.1,,,,, 15.1.0,,,,,, 15.1.1, 15.1.2,, 16.0.0,, 16.0.1

Opened: Jun 24, 2020
Severity: 3-Major


'Class Attribute' value in the Radius-Acct STOP request from the BIG-IP APM system does not match the 'Class Attribute' value in the Radius-Acct START request from the RADIUS server.


RADIUS server does not log accounting information properly.


-- Access policy is configured with RADIUS Acct VPE item to send accounting messages to RADIUS server when users log on and off.


This workaround textually describes reconfiguring an access policy in the Visual Policy Editor (VPE). Descriptions may not be as straightforward as in regular GUI workarounds. This is a description of the visual layout of the policy: Start --+-- Logon Page --+-- RADIUS Auth --+-- RADIUS Acct --+-- Variable Assign (1) --+-- Advanced Resource Assign --+-- Variable Assign --+-- Allow 1. Decode the class attribute and save it in a temporary variable: -- Click Variable Assign (1); in the two sub-areas, enter the following: temp.radius.last.attr.class.decoded expr { [mcget -decode {session.radius.last.attr.class}] } 2. Copy the temporary variable into the class session var: -- Click Variable Assign; in the two sub-areas, enter the following: session.radius.last.attr.class, expr { [mcget {temp.radius.last.attr.class.decoded}] } In this way, when you log out, and APM sends the RADIUS Stop accounting message, it uses the decoded value that is saved in the session.radius.last.attr.class variable.

Fix Information


Behavior Change