<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Keystroke logging in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/keystroke-logging/m-p/625727#M422802</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes , you can record whatever commands a user has run on the Cisco IOS box . For this you need to firstly configure command authorization on the IOS device along with the accounting. Below are the commands that you need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs if-autheticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group tacacs if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs if-authenticated&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default group tacacs&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default group tacacs&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default group tacacs&lt;/P&gt;&lt;P&gt;tacacs-server host x.x.x.x ket &lt;SECRETKEY&gt;&lt;/SECRETKEY&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also need to configure command authorization in ACS server using the below link ( Note : this link show the sample configuration of ACS using PIX but you can configure the IOS devices similarly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/sw/secursw/ps2086/products_configuration_guide_chapter09186a00801fd7cb.html" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/sw/secursw/ps2086/products_configuration_guide_chapter09186a00801fd7cb.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once we have configured the ACS and the IOS devices you can check the commands run by users in ACS by going to Reports &amp;amp; Activities &amp;gt; Tacacs admin logs .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Sep 2006 07:56:18 GMT</pubDate>
    <dc:creator>pbunet</dc:creator>
    <dc:date>2006-09-29T07:56:18Z</dc:date>
    <item>
      <title>Keystroke logging</title>
      <link>https://community.cisco.com/t5/network-access-control/keystroke-logging/m-p/625726#M422801</link>
      <description>&lt;P&gt;Using ACS and tacacs+ can I record the keystrokes users type when they enter commands on a device such as a router or switch?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/keystroke-logging/m-p/625726#M422801</guid>
      <dc:creator>MITCH JOHNSON</dc:creator>
      <dc:date>2019-03-10T21:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Keystroke logging</title>
      <link>https://community.cisco.com/t5/network-access-control/keystroke-logging/m-p/625727#M422802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes , you can record whatever commands a user has run on the Cisco IOS box . For this you need to firstly configure command authorization on the IOS device along with the accounting. Below are the commands that you need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs if-autheticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group tacacs if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs if-authenticated&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default group tacacs&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default group tacacs&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default group tacacs&lt;/P&gt;&lt;P&gt;tacacs-server host x.x.x.x ket &lt;SECRETKEY&gt;&lt;/SECRETKEY&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also need to configure command authorization in ACS server using the below link ( Note : this link show the sample configuration of ACS using PIX but you can configure the IOS devices similarly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/sw/secursw/ps2086/products_configuration_guide_chapter09186a00801fd7cb.html" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/sw/secursw/ps2086/products_configuration_guide_chapter09186a00801fd7cb.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once we have configured the ACS and the IOS devices you can check the commands run by users in ACS by going to Reports &amp;amp; Activities &amp;gt; Tacacs admin logs .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Sep 2006 07:56:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/keystroke-logging/m-p/625727#M422802</guid>
      <dc:creator>pbunet</dc:creator>
      <dc:date>2006-09-29T07:56:18Z</dc:date>
    </item>
  </channel>
</rss>

