<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic configure aaa accounting in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/configure-aaa-accounting/m-p/2877444#M40306</link>
    <description>&lt;P&gt;Hello guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;could someone please kindly explain aaa accounting configuration to me?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have 2 configuration lines for accounting:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;aaa accounting exec default start-stop group SERVER1&lt;BR /&gt;aaa accounting commands 15 default start-stop group SERVER1&lt;/PRE&gt;
&lt;P&gt;first of all, I don't understand the difference between "exec" and "command", because cisco documentation for exec is near the same, as for command:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;STRONG&gt;EXEC&lt;/STRONG&gt;--Provides information about user EXEC terminal sessions of the network access Server.&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;&lt;STRONG&gt;Command&lt;/STRONG&gt;--Provides information about the EXEC mode commands that a user issues. Command accounting generates accounting records for all EXEC mode commands, including global configuration commands, associated with a specific privilege Level.&lt;/PRE&gt;
&lt;P&gt;"&lt;EM&gt;user EXEC terminal sessions&lt;/EM&gt;" is my console in exec mode, isn't it?&amp;nbsp;But what does the second sentence part&amp;nbsp;"&lt;EM&gt;of the network access Server&lt;/EM&gt;" means?&amp;nbsp;about what&amp;nbsp;"Network Access Server" do cisco talk? Does't "command" logs the same? -What is the difference?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I also don't understand what "start-stop" does. I found some description, but i still don't got it:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif; font-size: 10pt;"&gt;AAA resource accounting for start-stop records supports the ability to send a “start” record at each call setup, followed by a corresponding “stop” record at the call disconnect. This functionality can be used to manage and monitor wholesale customers from one source of data reporting, such as accounting records.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;So I&amp;nbsp;logged in to my accounting Server and got this picture:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/accounting_0.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;I can see, that i logged in to 172.17.68.4 from my admin host (public IP is black) and a new "start-stop" record was created (start).&amp;nbsp;After that i executed some commands and after each command record received "stop". But what is the usage of this "start-stop" record?&lt;/P&gt;
&lt;P&gt;btw. what does the Zero stands for between destination and source&amp;nbsp;IP in "Audit Session Key"? And does somebody know something about the "Task ID" field?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My next question is about&amp;nbsp;the privilege Level in "aaa accounting commands 15" - do i understend it right, that only privilege Level 15 commands will be logged and all other won't?&lt;/P&gt;
&lt;P&gt;Because i did a comparation&amp;nbsp;between my&amp;nbsp;authorized commands and accounting, so there are some differences. I marked them red.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/missed.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN style="text-decoration: underline;"&gt;I will summarize my Qustions:&lt;/SPAN&gt;&lt;/H3&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN style="color: #339966;"&gt;What is the difference between "aaa accounting exec" and "aaa accounting commands"&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;OL style="list-style-type: lower-roman;"&gt;
&lt;LI&gt;&lt;SPAN style="color: #000000;"&gt;What does the command "aaa accounting exec default start-stop group SERVER1" do?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL style="list-style-type: lower-alpha;"&gt;
&lt;LI&gt;&lt;SPAN style="color: #000000;"&gt;What is the meaning of "user EXEC terminal sessions" in the description of "EXEC" scope&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="color: #000000;"&gt;Which "network access Server" is mentioned in the description of "EXEC" scope?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/OL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN style="color: #339966;"&gt;What&amp;nbsp;does the "start-stop" record do?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;OL style="list-style-type: lower-roman;"&gt;
&lt;LI&gt;&lt;SPAN style="color: #000000;"&gt;Which Advantages can I get by implementing&amp;nbsp;this record?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN style="color: #339966;"&gt;Is this Statement true or false: command "aaa accounting commands 15 default start-stop group SERVER1" does accounting only for privilege Level 15 commands&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN style="color: #339966;"&gt;What should i change in my accounting configuration, to be able to see all issued commands?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thank you very much in advance. If you have any question, please do not&amp;nbsp;hesit to contact me&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:30:33 GMT</pubDate>
    <dc:creator>Thomas Schmitt</dc:creator>
    <dc:date>2019-03-11T06:30:33Z</dc:date>
    <item>
      <title>configure aaa accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-aaa-accounting/m-p/2877444#M40306</link>
      <description>Please explain these two commands
aaa accounting exec default start-stop group SERVER1
aaa accounting commands 15 default start-stop group SERVER1</description>
      <pubDate>Mon, 11 Mar 2019 06:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-aaa-accounting/m-p/2877444#M40306</guid>
      <dc:creator>Thomas Schmitt</dc:creator>
      <dc:date>2019-03-11T06:30:33Z</dc:date>
    </item>
    <item>
      <title>"Exec accounting” will</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-aaa-accounting/m-p/2877445#M40307</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt; color: #000000; font-family: helvetica,arial,sans-serif;"&gt;"Exec accounting” will capture details about user accessing the shell prompt where you run all the commands &amp;amp; “command accounting” keep track of what commands users execute on a Cisco device. Exec terminal session where you have priv 15. The network server mentioned in EXEC scope when user login and logoff.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt; color: #000000; font-family: helvetica,arial,sans-serif;"&gt;AAA resource accounting for start-stop records supports the ability to send a “start” record at each connection setup, followed by a corresponding “stop” record at the connection disconnect. This functionality can be used to manage and monitor wholesale customers from one source of data reporting, such as accounting records&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt; color: #000000; font-family: helvetica,arial,sans-serif;"&gt;yes that's true aaa accounting commands 15 default start-stop group SERVER1" does accounting only for privilege Level 15 commands. Basically we use 3 commands 0,1 &amp;amp; 15 that covers most of the command accounting. However sometimes if we use custom command accounting then you need to have that level of accounting command configured.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt; color: #000000; font-family: helvetica,arial,sans-serif;"&gt;In order to cover all the commands please make sure you have all 3 commands:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt; color: #000000; font-family: helvetica,arial,sans-serif;"&gt;aaa accounting commands 0 default start-stop group SERVER1" &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000; font-family: helvetica,arial,sans-serif; font-size: 10pt;"&gt;aaa accounting commands 1 default start-stop group SERVER1" &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #339966; font-family: helvetica,arial,sans-serif; font-size: 10pt;"&gt;&lt;SPAN style="color: #000000;"&gt;aaa accounting commands 15 default start-stop group SERVER1"&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #339966; font-family: helvetica,arial,sans-serif; font-size: 10pt;"&gt;&lt;SPAN style="color: #000000;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #339966; font-family: helvetica,arial,sans-serif; font-size: 10pt;"&gt;&lt;SPAN style="color: #000000;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #339966; font-family: helvetica,arial,sans-serif; font-size: 10pt;"&gt;&lt;SPAN style="color: #000000;"&gt;Jatin&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 07:18:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-aaa-accounting/m-p/2877445#M40307</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-02-20T07:18:13Z</dc:date>
    </item>
    <item>
      <title>Hello ans thank you very much</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-aaa-accounting/m-p/2877446#M40308</link>
      <description>&lt;P&gt;Hello ans thank you very much for exploration&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm still not sure&amp;nbsp;about&amp;nbsp;EXEC in accounting. -is it just a message, that user XYZ started started/closed exec console?&lt;/P&gt;
&lt;P&gt;I have configured "aaa accounting exec", so the entries in "audit s session key" ware created by EXEC accounting?&lt;/P&gt;
&lt;P&gt;you can see in first post a screenshot from AAA accounting report on my ACS. -which entries I wouldn't be able to see, if I say "no aaa accounting exec" in order?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 18:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-aaa-accounting/m-p/2877446#M40308</guid>
      <dc:creator>Thomas Schmitt</dc:creator>
      <dc:date>2016-02-20T18:22:10Z</dc:date>
    </item>
    <item>
      <title>Thomas,</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-aaa-accounting/m-p/2877447#M40309</link>
      <description>&lt;P&gt;Thomas,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;"exec accounting" indicates when an exec session starts and stops. If you eliminate exec accounting then ACS won't show the related start and stop events.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Javier Henderson&lt;/P&gt;
&lt;P&gt;Cisco Systems&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 15:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-aaa-accounting/m-p/2877447#M40309</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2016-02-26T15:05:22Z</dc:date>
    </item>
  </channel>
</rss>

