Additional RADIUS Attributes
Depending on the message, the following additional RADIUS attributes may be present:
- Acct-Terminate-Cause—Indicates whether the session ended because of a deliberate logout or a session timeout.
- Juniper-Junos Scope-Privileged-Operation—The symbolic name for the operation that was performed.
- Juniper-Junos Scope-Target—The name of the object affected by the privileged operation.
- Juniper-Junos Scope-Login-Failure-Reason—The reason for login failure: 'user locked' or 'login failure'.
The RADIUS accounting server expects all accounting records to occur in the context of a session. Since Junos Scope operations can be performed on a schedule after a user's session is no longer valid, a new session is created for each scheduled task. A session start message is sent before the scheduled task executes; a session end message is sent after the task completes.