<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem for see accounting in ACS 4.1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-for-see-accounting-in-acs-4-1/m-p/1150673#M405549</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info. Their is a know bug for command accounting in ACS v4.1 and it is fixed in cumulative patch 5. The patch is available at cisco.com. make sure you take the backup before applying the patch. CSCsg97429    TACACS+ Command Accounting does not work in ACS 4.1(1) Build 23. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Apr 2009 17:25:00 GMT</pubDate>
    <dc:creator>Vinay Sharma</dc:creator>
    <dc:date>2009-04-13T17:25:00Z</dc:date>
    <item>
      <title>Problem for see accounting in ACS 4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-for-see-accounting-in-acs-4-1/m-p/1150671#M405547</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ACS 4.1 and i've configured aaa in a Router, my problem is that I can't see the accounting in ACS for example i want to know that has done the users for example if an user type show runn, conf ter, shutdown in the interface. actually my aaa configuration is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How i can see the accounting?? in the acs?? in acs 3.3.3 I can see the accounting, but in this version nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 12.4&lt;/P&gt;&lt;P&gt;hostname Router_Lab&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;enable secret 5 $1$051s$Few6cFXNT6T0TdAZqHkNu.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default enable&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting connection default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;!         &lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;!         &lt;/P&gt;&lt;P&gt;resource policy&lt;/P&gt;&lt;P&gt;!         &lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username admin password 0 cisco123&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 172.20.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;snmp-server community adexus123 RW&lt;/P&gt;&lt;P&gt;snmp-server host 172.20.0.100 adexus123 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host 172.20.0.11 key cisco123&lt;/P&gt;&lt;P&gt;tacacs-server timeout 3&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my logs when I put show running-config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router_Lab#&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.599: AAA: parse name=tty2 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.599: AAA: name=tty2 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=2 channel=0&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.603: AAA/MEMORY: create_user (0x654D1F28) user='adexus' ruser='Router_Lab' ds0=0 port='tty2' rem_addr='172.20.0.100' authen_type=ASCII service=NONE priv=15 initial_task_id='0', vrf= (id=0)&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.607: tty2 AAA/AUTHOR/CMD(3705108292): Port='tty2' list='' service=CMD&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.611: AAA/AUTHOR/CMD: tty2(3705108292) user='adexus'&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.611: tty2 AAA/AUTHOR/CMD(3705108292): send AV service=shell&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.615: tty2 AAA/AUTHOR/CMD(3705108292): send AV cmd=show&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.615: tty2 AAA/AUTHOR/CMD(3705108292): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.619: tty2 AAA/AUTHOR/CMD(3705108292): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.619: tty2 AAA/AUTHOR/CMD(3705108292): found list "default"&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.623: tty2 AAA/AUTHOR/CMD(3705108292): Method=tacacs+ (tacacs+)&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.627: AAA/AUTHOR/TAC+: (3705108292): user=adexus&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.627: AAA/AUTHOR/TAC+: (3705108292): send AV service=shell&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.627: AAA/AUTHOR/TAC+: (3705108292): send AV cmd=show&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.631: AAA/AUTHOR/TAC+: (3705108292): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.631: AAA/AUTHOR/TAC+: (3705108292): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.875: AAA/AUTHOR (3705108292): Post authorization status = PASS_ADD&lt;/P&gt;&lt;P&gt;*Mar 19 18:42:59.875: AAA/MEMORY: free_user (0x654D1F28) user='adexus' ruser='Router_Lab' port='tty2' rem_addr='172.20.0.100' authen_type=ASCII service=NONE priv=15 vrf= (id=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:25:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-for-see-accounting-in-acs-4-1/m-p/1150671#M405547</guid>
      <dc:creator>Alvaro Perez Unzueta</dc:creator>
      <dc:date>2019-03-26T00:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Problem for see accounting in ACS 4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-for-see-accounting-in-acs-4-1/m-p/1150672#M405548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check this link, there is a bug in 4.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://supportwiki.cisco.com/ViewWiki/index.php/Cisco_Secure_ACS_server_is_unable_to_register_TACACS%2B_admin_logs" target="_blank"&gt;http://supportwiki.cisco.com/ViewWiki/index.php/Cisco_Secure_ACS_server_is_unable_to_register_TACACS%2B_admin_logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but you should atleast see the accounting records being sent on the router, I wonder why you don't see those in your debugs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Mar 2009 12:23:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-for-see-accounting-in-acs-4-1/m-p/1150672#M405548</guid>
      <dc:creator>vikram_anumukonda</dc:creator>
      <dc:date>2009-03-20T12:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Problem for see accounting in ACS 4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-for-see-accounting-in-acs-4-1/m-p/1150673#M405549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info. Their is a know bug for command accounting in ACS v4.1 and it is fixed in cumulative patch 5. The patch is available at cisco.com. make sure you take the backup before applying the patch. CSCsg97429    TACACS+ Command Accounting does not work in ACS 4.1(1) Build 23. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Apr 2009 17:25:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-for-see-accounting-in-acs-4-1/m-p/1150673#M405549</guid>
      <dc:creator>Vinay Sharma</dc:creator>
      <dc:date>2009-04-13T17:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Problem for see accounting in ACS 4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-for-see-accounting-in-acs-4-1/m-p/1150674#M405550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vinashar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This issue occurs due to the presence of Cisco bug ID CSCsg97429. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No accounting records appear in the Terminal Access Controller Access Control System (TACACS+) Administration log file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem starts when command Accounting is configured on the Network Attached Storage (NAS). After commands are entered on the NAS, no records appear in the TACACS+ Administration log file. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debugs on the NAS show the records are sent, and they do arrive at the ACS, but the appropriate log file fails to update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With ACS logging set to Full in System Configuration &amp;gt; Service Control, the log file of the CSLog service shows these entries each time a command is entered on the NAS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;12/06/2006 14:22:52 U 5111 2608 Handling message at 0x010A7FF8 (339 bytes)&lt;/P&gt;&lt;P&gt;12/06/2006 14:22:52 A 0000 0960 Logger CSV TACACS+ Accounting: filter denies logging &lt;/P&gt;&lt;P&gt;Resolution  For a workaround: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Download and install these patches from Cisco Downloads: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CiscoSecure ACS for Microsoft Windows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Acs_4.1.1.23.5-SW.zip?ACS 4.1.1.23.1 accumulative patch&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Apr 2009 17:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-for-see-accounting-in-acs-4-1/m-p/1150674#M405550</guid>
      <dc:creator>sachinga.hcl</dc:creator>
      <dc:date>2009-04-14T17:55:56Z</dc:date>
    </item>
  </channel>
</rss>

