<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA Reports in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453714#M377655</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ganesh, thanks for reply.&lt;/P&gt;&lt;P&gt;Unfortunately i am still unable to see executed commands in tacacs+ accounting report. I have all report fields enabled, configuration is the same as you suggested but still no luck.&amp;nbsp; I setup shell command authorization set and can see if readonly users (which has rights to run only commands in readonly authorization set) trying to execute commands they are not authorize to run but cannot see all commands executed on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is really important to have a record who and when initiated what commands on network devices.&lt;/P&gt;&lt;PRE&gt;07/16/2010,09:18:30,AAAServer,GRoup,SWITCHES,CAT3560-T,UserName,192.168.182.1,start,15,,,,,,2,(Default),,,shell,,,,,,,,,,,,,,UTC,,,,,,,,,,,,,,,,,,,,,,,,No,Login,1,6,192.168.182.20,tty1&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Jul 2010 17:31:54 GMT</pubDate>
    <dc:creator>endpoint</dc:creator>
    <dc:date>2010-07-16T17:31:54Z</dc:date>
    <item>
      <title>AAA Reports</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453712#M377648</link>
      <description>&lt;P&gt;Hi, need to provide a ACS reports that will include all commands entered on firewalls/switches/routers. &lt;/P&gt;&lt;P&gt;Successfully setup acs for these network devices, basic AAA is working, can login failed/passed authentications, different level of authentication was correctly configured, but in reports i can see only commands that have been denied (have tested different user levels). How can i setup AAA to log all&amp;nbsp; commands&amp;nbsp; enterend by eg network device admins? &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453712#M377648</guid>
      <dc:creator>endpoint</dc:creator>
      <dc:date>2019-03-11T00:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Reports</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453713#M377651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;Hi, need to provide a ACS reports 
that will include all commands entered on firewalls/switches/routers. &lt;/P&gt;&lt;P&gt;Successfully
 setup acs for these network devices, basic AAA is working, can login 
failed/passed authentications, different level of authentication was 
correctly configured, but in reports i can see only commands that have 
been denied (have tested different user levels). How can i setup AAA to 
log all&amp;nbsp; commands&amp;nbsp; enterend by eg network device admins? &lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to get the executed commands in router or switch you need to configure aaa accounting command in router and switch like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;BR /&gt;aaa accounting network default start-stop group tacacs+&lt;BR /&gt;aaa accounting connection default start-stop group tacacs+&lt;BR /&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you can see in command logs TACAS adminstration tab in ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope to Help !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ganesh.H&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate the helpful post&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jul 2010 09:50:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453713#M377651</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2010-07-16T09:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Reports</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453714#M377655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ganesh, thanks for reply.&lt;/P&gt;&lt;P&gt;Unfortunately i am still unable to see executed commands in tacacs+ accounting report. I have all report fields enabled, configuration is the same as you suggested but still no luck.&amp;nbsp; I setup shell command authorization set and can see if readonly users (which has rights to run only commands in readonly authorization set) trying to execute commands they are not authorize to run but cannot see all commands executed on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is really important to have a record who and when initiated what commands on network devices.&lt;/P&gt;&lt;PRE&gt;07/16/2010,09:18:30,AAAServer,GRoup,SWITCHES,CAT3560-T,UserName,192.168.182.1,start,15,,,,,,2,(Default),,,shell,,,,,,,,,,,,,,UTC,,,,,,,,,,,,,,,,,,,,,,,,No,Login,1,6,192.168.182.20,tty1&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jul 2010 17:31:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453714#M377655</guid>
      <dc:creator>endpoint</dc:creator>
      <dc:date>2010-07-16T17:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Reports</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453715#M377666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Hi Ganesh, thanks for reply.&lt;/P&gt;&lt;P&gt;Unfortunately
i am still unable to see executed commands in tacacs+ accounting
report. I have all report fields enabled, configuration is the same as
you suggested but still no luck.&amp;nbsp; I setup shell command authorization
set and can see if readonly users (which has rights to run only
commands in readonly authorization set) trying to execute commands they
are not authorize to run but cannot see all commands executed on the
switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is really important to have a record who and when initiated what commands on network devices.&lt;/P&gt;&lt;PRE&gt;07/16/2010,09:18:30,AAAServer,GRoup,SWITCHES,CAT3560-T,UserName,192.168.182.1,start,15,,,,,,2,(Default),,,shell,,,,,,,,,,,,,,UTC,,,,,,,,,,,,,,,,,,,,,,,,No,Login,1,6,192.168.182.20,tty1&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any other suggestions?&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your ACS version is 4.1 &lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;TACACS+ Command Accounting no longer works. No accounting records are visible in the TACACS+ Administration log (bug CSCsg97429). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;SPAN style="font-family: Arial;"&gt;Click this link if you are using ACS Solution Engine: &lt;/SPAN&gt;&lt;A href="http://www.cisco.com/pcgi-bin/tablebuild.pl/acs-win-3des" rel="nofollow" target="_blank"&gt;&lt;SPAN style="font-family: Arial;"&gt;http://www.cisco.com/pcgi-bin/tablebuild.pl/acs-soleng-3des?psrtdcat20e2 &lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-family: Arial;"&gt;and download: &lt;/SPAN&gt;&lt;/P&gt;&lt;A name="wp165060" rel="nofollow"&gt;&lt;/A&gt;&lt;P class="pB2_Body2"&gt;&lt;SPAN style="font-family: Arial;"&gt;applAcs_4.1.1.23_ACS-4.1-CSTacacs-CSCsg97429.zip &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pB2_Body2"&gt;&lt;/P&gt;&lt;P class="pB2_Body2"&gt;Hope to Help !!&lt;/P&gt;&lt;P class="pB2_Body2"&gt;&lt;/P&gt;&lt;P class="pB2_Body2"&gt;Ganesh.H&lt;/P&gt;&lt;P class="pB2_Body2"&gt;&lt;/P&gt;&lt;P class="pB2_Body2"&gt;Remember to rate the helpful post&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jul 2010 18:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453715#M377666</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2010-07-16T18:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Reports</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453716#M377670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Ganesh&lt;/P&gt;&lt;P&gt;I am updating to v4.2 and will check out reports. Will keep this group posted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jul 2010 19:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453716#M377670</guid>
      <dc:creator>endpoint</dc:creator>
      <dc:date>2010-07-16T19:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Reports</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453717#M377680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Works like a charm:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;16/07/2010,13:19:41,UserName,Group,hostname NewSwitchName &lt;CR&gt;,15,shell,tty1,258,192.168.182.1,&lt;BR /&gt;16/07/2010,13:19:44,UserName,Group,write &lt;CR&gt;,15,shell,tty1,259,192.168.182.1,'&lt;/CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jul 2010 20:29:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-reports/m-p/1453717#M377680</guid>
      <dc:creator>endpoint</dc:creator>
      <dc:date>2010-07-16T20:29:28Z</dc:date>
    </item>
  </channel>
</rss>

