<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sending AAA accouting log records to multiple AAA servers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sending-aaa-accouting-log-records-to-multiple-aaa-servers/m-p/1180193#M389162</link>
    <description>&lt;P&gt;IOS version c3640-a3jk9s-mz.123-18.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ cciesec&lt;/P&gt;&lt;P&gt; server 192.168.3.10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ ccievoice&lt;/P&gt;&lt;P&gt; server 192.168.3.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login VTY group cciesec local&lt;/P&gt;&lt;P&gt;aaa accounting exec cciesec start-stop broadcast group cciesec group ccievoice&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 cciesec start-stop broadcast group cciesec group ccievoice&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 cciesec start-stop broadcast group cciesec group ccievoice&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 cciesec start-stop broadcast group cciesec group ccievoice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.3.10 key 123456&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.3.11 key 123456&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C3640#sh tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tacacs+ Server            : 192.168.3.10/49&lt;/P&gt;&lt;P&gt;              Socket opens:          8&lt;/P&gt;&lt;P&gt;             Socket closes:          8&lt;/P&gt;&lt;P&gt;             Socket aborts:          0&lt;/P&gt;&lt;P&gt;             Socket errors:          0&lt;/P&gt;&lt;P&gt;           Socket Timeouts:          0&lt;/P&gt;&lt;P&gt;   Failed Connect Attempts:          0&lt;/P&gt;&lt;P&gt;        Total Packets Sent:         21&lt;/P&gt;&lt;P&gt;        Total Packets Recv:         21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tacacs+ Server            : 192.168.3.11/49&lt;/P&gt;&lt;P&gt;              Socket opens:          0&lt;/P&gt;&lt;P&gt;             Socket closes:          0&lt;/P&gt;&lt;P&gt;             Socket aborts:          0&lt;/P&gt;&lt;P&gt;             Socket errors:          0&lt;/P&gt;&lt;P&gt;           Socket Timeouts:          0&lt;/P&gt;&lt;P&gt;   Failed Connect Attempts:          0&lt;/P&gt;&lt;P&gt;        Total Packets Sent:          0&lt;/P&gt;&lt;P&gt;        Total Packets Recv:          0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C3640#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see, I can receive AAA accounting logs on server 192.168.3.10 but I am not getting logs on 192.168.3.11.  I can confirm this with&lt;/P&gt;&lt;P&gt;tcpdump on host 192.168.3.11 and that I am not seeing any sent AAA to host 192.168.3.11.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know why?  &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 23:16:30 GMT</pubDate>
    <dc:creator>cisco24x7</dc:creator>
    <dc:date>2019-03-10T23:16:30Z</dc:date>
    <item>
      <title>Sending AAA accouting log records to multiple AAA servers</title>
      <link>https://community.cisco.com/t5/network-access-control/sending-aaa-accouting-log-records-to-multiple-aaa-servers/m-p/1180193#M389162</link>
      <description>&lt;P&gt;IOS version c3640-a3jk9s-mz.123-18.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ cciesec&lt;/P&gt;&lt;P&gt; server 192.168.3.10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ ccievoice&lt;/P&gt;&lt;P&gt; server 192.168.3.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login VTY group cciesec local&lt;/P&gt;&lt;P&gt;aaa accounting exec cciesec start-stop broadcast group cciesec group ccievoice&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 cciesec start-stop broadcast group cciesec group ccievoice&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 cciesec start-stop broadcast group cciesec group ccievoice&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 cciesec start-stop broadcast group cciesec group ccievoice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.3.10 key 123456&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.3.11 key 123456&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C3640#sh tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tacacs+ Server            : 192.168.3.10/49&lt;/P&gt;&lt;P&gt;              Socket opens:          8&lt;/P&gt;&lt;P&gt;             Socket closes:          8&lt;/P&gt;&lt;P&gt;             Socket aborts:          0&lt;/P&gt;&lt;P&gt;             Socket errors:          0&lt;/P&gt;&lt;P&gt;           Socket Timeouts:          0&lt;/P&gt;&lt;P&gt;   Failed Connect Attempts:          0&lt;/P&gt;&lt;P&gt;        Total Packets Sent:         21&lt;/P&gt;&lt;P&gt;        Total Packets Recv:         21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tacacs+ Server            : 192.168.3.11/49&lt;/P&gt;&lt;P&gt;              Socket opens:          0&lt;/P&gt;&lt;P&gt;             Socket closes:          0&lt;/P&gt;&lt;P&gt;             Socket aborts:          0&lt;/P&gt;&lt;P&gt;             Socket errors:          0&lt;/P&gt;&lt;P&gt;           Socket Timeouts:          0&lt;/P&gt;&lt;P&gt;   Failed Connect Attempts:          0&lt;/P&gt;&lt;P&gt;        Total Packets Sent:          0&lt;/P&gt;&lt;P&gt;        Total Packets Recv:          0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C3640#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see, I can receive AAA accounting logs on server 192.168.3.10 but I am not getting logs on 192.168.3.11.  I can confirm this with&lt;/P&gt;&lt;P&gt;tcpdump on host 192.168.3.11 and that I am not seeing any sent AAA to host 192.168.3.11.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know why?  &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sending-aaa-accouting-log-records-to-multiple-aaa-servers/m-p/1180193#M389162</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2019-03-10T23:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Sending AAA accouting log records to multiple AAA servers</title>
      <link>https://community.cisco.com/t5/network-access-control/sending-aaa-accouting-log-records-to-multiple-aaa-servers/m-p/1180194#M389179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not tested this and do not have authoritative knowledge of it. But usually when you configure multiple parameters in a method list they are used as backups for each other. So the second group would typically be used only if attempts to use the first group failed. The behavior that you describe is consistent with this, so I assume that this may be the explanation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 19:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sending-aaa-accouting-log-records-to-multiple-aaa-servers/m-p/1180194#M389179</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-01-12T19:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Sending AAA accouting log records to multiple AAA servers</title>
      <link>https://community.cisco.com/t5/network-access-control/sending-aaa-accouting-log-records-to-multiple-aaa-servers/m-p/1180195#M389266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/12_1t/12_1t1/feature/guide/dt_aaaba.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_1t/12_1t1/feature/guide/dt_aaaba.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It stated the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Before the introduction of the AAA Broadcast Accounting feature, Cisco IOS AAA could send accounting information to only one server at a time. This feature allows accounting information to be sent to one or more AAA servers at the same time. Service providers are thus able to simultaneously send accounting information to their own private AAA servers and to the AAA servers of their end customers. This feature also provides redundant billing information for voice applications."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 19:41:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sending-aaa-accouting-log-records-to-multiple-aaa-servers/m-p/1180195#M389266</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2009-01-12T19:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: Sending AAA accouting log records to multiple AAA servers</title>
      <link>https://community.cisco.com/t5/network-access-control/sending-aaa-accouting-log-records-to-multiple-aaa-servers/m-p/1180196#M389326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This appears to be an interesting feature and one I was not familiar with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you change the order of groups in the accounting command and put ccievoice before cciesec do the accounting records start going to the .11 server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 20:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sending-aaa-accouting-log-records-to-multiple-aaa-servers/m-p/1180196#M389326</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-01-12T20:15:32Z</dc:date>
    </item>
  </channel>
</rss>

