<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius/m-p/785630#M420662</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure, are you talking on the "Remote Acces Logging"? If so, i used the default Local file logs from the IAS server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are my commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius line&lt;/P&gt;&lt;P&gt;aaa authentication login radius_localcon local-case&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group radius&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host xx.xx.xx.xx auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;radius-server key 7 xxxxxxxxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please feel free to suggest on how i could implement accounting with repsect to the commands that has been entered by the admin users logged-in from my routers/switches using the IAS.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 09 Jun 2007 09:28:57 GMT</pubDate>
    <dc:creator>jigz.bagsicjr</dc:creator>
    <dc:date>2007-06-09T09:28:57Z</dc:date>
    <item>
      <title>Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/radius/m-p/785625#M420654</link>
      <description>&lt;P&gt;Hi, i would like to know if there is a way to account the commands entered by certain profile log-in to the router/switch using MS IAS method? Currently i'm using IAS radius server from my switches and routers. And i'm having problem in doing an accounting of commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius/m-p/785625#M420654</guid>
      <dc:creator>jigz.bagsicjr</dc:creator>
      <dc:date>2019-03-10T22:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/radius/m-p/785626#M420655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually, I just reviewed the IAS capabilities and you should be able to do accounting. Do you have accounting logging enabled on the IAS server? Do you also have the appropriate AAA accounting commands implemented. Please post your AAA accounting related commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2007 16:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius/m-p/785626#M420655</guid>
      <dc:creator>palomoj</dc:creator>
      <dc:date>2007-05-24T16:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/radius/m-p/785627#M420656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i see, just last question. Is there any unix/linux based application that can support this accounting of commands aside from Cisco ACS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2007 16:27:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius/m-p/785627#M420656</guid>
      <dc:creator>jigz.bagsicjr</dc:creator>
      <dc:date>2007-05-24T16:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/radius/m-p/785628#M420658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Cisco Systems implementation of RADIUS does not support command accounting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124cg/hsec_c/part05/schacct.htm#wp1001268" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124cg/hsec_c/part05/schacct.htm#wp1001268&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 May 2007 22:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius/m-p/785628#M420658</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-05-26T22:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/radius/m-p/785629#M420660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Prem is correct. All radius  can do in Cisco is send the start and stop bits...no command accounting anyway.  try tacacs+. (of course IAS doesn't support this).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2007 13:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius/m-p/785629#M420660</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-05-30T13:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/radius/m-p/785630#M420662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure, are you talking on the "Remote Acces Logging"? If so, i used the default Local file logs from the IAS server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are my commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius line&lt;/P&gt;&lt;P&gt;aaa authentication login radius_localcon local-case&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group radius&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host xx.xx.xx.xx auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;radius-server key 7 xxxxxxxxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please feel free to suggest on how i could implement accounting with repsect to the commands that has been entered by the admin users logged-in from my routers/switches using the IAS.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Jun 2007 09:28:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius/m-p/785630#M420662</guid>
      <dc:creator>jigz.bagsicjr</dc:creator>
      <dc:date>2007-06-09T09:28:57Z</dc:date>
    </item>
  </channel>
</rss>

