<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052255#M406251</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS is a Radius and Tacacs server. So the question would be, Can/does your web server support Radius/tacacs protocol ? If yes, then you can add the web server as a client on the ACS server, and configure your web server for Radius/tacacs accounting and send the accounting logs to ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I doubt this to be the case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AFAIK, the web servers also have some logging feature/functionality. Check with the web server documentation, there must be some option to log the user logins/activity on the web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if it helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Aug 2008 13:49:28 GMT</pubDate>
    <dc:creator>Premdeep Banga</dc:creator>
    <dc:date>2008-08-26T13:49:28Z</dc:date>
    <item>
      <title>ACS question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052254#M406249</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;our customer has a vpn tunnel site-to-site with another company . The vpn is established between two routers and its working fine . The users in the customer site can login to a web server in the remote peer site using username &amp;amp; password  through this tunnel . Our customer need to log the time that the users login to this web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the ACS do that or not ??  and how ??&lt;/P&gt;&lt;P&gt;if the ACS cannot do that , is there any other method can be used to log the users login??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;waiting your replies.&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:03:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052254#M406249</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2019-03-10T23:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: ACS question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052255#M406251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS is a Radius and Tacacs server. So the question would be, Can/does your web server support Radius/tacacs protocol ? If yes, then you can add the web server as a client on the ACS server, and configure your web server for Radius/tacacs accounting and send the accounting logs to ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I doubt this to be the case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AFAIK, the web servers also have some logging feature/functionality. Check with the web server documentation, there must be some option to log the user logins/activity on the web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if it helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2008 13:49:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052255#M406251</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2008-08-26T13:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052256#M406253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;i want to tell you something that the web server isnot under our control .it is controlled by the peer company.So we need to log the users login to this server (using any method) without changing anything in the web server settings.&lt;/P&gt;&lt;P&gt;i mean we need to do that from our side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if the ACS cannot do that , is there any other S/W do that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2008 14:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052256#M406253</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2008-08-26T14:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: ACS question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052257#M406255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have not tried this, but just an idea, you can try this out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create an acl, something like,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list auth permit &lt;NETWORK&gt; host &lt;WEB-SERVER&gt;.....&lt;/WEB-SERVER&gt;&lt;/NETWORK&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication match auth &lt;SERVER-TAG&gt;&lt;/SERVER-TAG&gt;&lt;/P&gt;&lt;P&gt;aaa accounting match auth &lt;SERVER-TAG&gt;&lt;/SERVER-TAG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this will add an Added authentication, before users go to destination web server,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please test this before applying it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also have,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list auth permit &lt;NETWORK&gt; host &lt;WEB-SERVER&gt;.....&lt;/WEB-SERVER&gt;&lt;/NETWORK&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting match auth &lt;SERVER-TAG&gt;&lt;/SERVER-TAG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is accounting alone, but not sure what information you may get in this. But you can give this a try and see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if it helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2008 14:54:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052257#M406255</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2008-08-26T14:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACS question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052258#M406257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found this, might be helpful,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/fwaaa.html#wp1043741" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/fwaaa.html#wp1043741&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The security appliance can send accounting information to a RADIUS or TACACS+ server about any TCP or UDP traffic that passes through the security appliance. If that traffic is also authenticated, then the AAA server can maintain accounting information by username. If the traffic is not authenticated, the AAA server can maintain accounting information by IP address. Accounting information includes when sessions start and stop, username, the number of bytes that pass through the security appliance for the session, the service used, and the duration of each session. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2008 15:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-question/m-p/1052258#M406257</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2008-08-26T15:08:23Z</dc:date>
    </item>
  </channel>
</rss>

