<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS and AAA Help in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-and-aaa-help/m-p/528683#M426773</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Refers to the previous post at:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40.1ddb89cb/0#selected_message" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40.1ddb89cb/0#selected_message&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.The audit feature that you're looking at is available for valid command once the user/admin entered 'conf t' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following command can be used to monitor what commands are being entered by the user/admin:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting network SAMPLE start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can see the report under ACS's "Logs and Reports" section - look for tacacs+. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7aa.html#wp1005522" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7aa.html#wp1005522&lt;/A&gt;&lt;/P&gt;&lt;P&gt;*can also look under sample config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Jul 2006 13:20:39 GMT</pubDate>
    <dc:creator>a.kiprawih</dc:creator>
    <dc:date>2006-07-31T13:20:39Z</dc:date>
    <item>
      <title>ACS and AAA Help</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-aaa-help/m-p/528682#M426770</link>
      <description>&lt;P&gt;I've just configured ACS and TACACS+ for access to our switches using our AD for authentication. It works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would like to know is firstly how can I configure ACS to only allow access to our switches if you belong in a particular AD group or ACS group as at the moment anyone can login to our switches if they are a user on the domain?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly is there a way within TACACS+ to audit every single command that is entered while someone is loggin into a switch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:41:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-aaa-help/m-p/528682#M426770</guid>
      <dc:creator>jonchill</dc:creator>
      <dc:date>2019-03-10T21:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and AAA Help</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-aaa-help/m-p/528683#M426773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Refers to the previous post at:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40.1ddb89cb/0#selected_message" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40.1ddb89cb/0#selected_message&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.The audit feature that you're looking at is available for valid command once the user/admin entered 'conf t' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following command can be used to monitor what commands are being entered by the user/admin:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting network SAMPLE start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can see the report under ACS's "Logs and Reports" section - look for tacacs+. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7aa.html#wp1005522" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7aa.html#wp1005522&lt;/A&gt;&lt;/P&gt;&lt;P&gt;*can also look under sample config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2006 13:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-aaa-help/m-p/528683#M426773</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-07-31T13:20:39Z</dc:date>
    </item>
  </channel>
</rss>

