<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS+ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tacacs/m-p/3937437#M132441</link>
    <description>&lt;P&gt;aaa authorization command *********&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;aaa accounting ssh console *********&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;these commands enable command and user accounting.&amp;nbsp; Though I might suggest adding &lt;STRONG&gt;aaa accounting serial ********&lt;/STRONG&gt; incase anyone connects to the console port and makes changes.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Oct 2019 20:56:39 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2019-10-08T20:56:39Z</dc:date>
    <item>
      <title>TACACS+</title>
      <link>https://community.cisco.com/t5/network-security/tacacs/m-p/3937283#M132440</link>
      <description>&lt;P&gt;I want to keep track of the change in ACL in ASA by using TACACS+ accounting, by determining the user, command, time,...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the following command in ASA:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa-server ********* protocol tacacs+&lt;/P&gt;
&lt;P&gt;aaa-server ********* (inside) host x.x.x.x&lt;/P&gt;
&lt;P&gt;aaa-server ********* (inside) host y.y.y.y&lt;/P&gt;
&lt;P&gt;aaa-server ********* (inside) host z.z.z.z&lt;/P&gt;
&lt;P&gt;aaa-server ********* (inside) host f.f.f.f&lt;/P&gt;
&lt;P&gt;aaa authentication enable console ********* LOCAL&lt;/P&gt;
&lt;P&gt;aaa authentication ssh console ********* LOCAL&lt;/P&gt;
&lt;P&gt;aaa authentication http console ********* LOCAL&lt;/P&gt;
&lt;P&gt;aaa authorization command *********&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;aaa accounting ssh console *********&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;what configuration should I add in ASA and ACS to enable this feature?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 18:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tacacs/m-p/3937283#M132440</guid>
      <dc:creator>Tuba</dc:creator>
      <dc:date>2019-10-08T18:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+</title>
      <link>https://community.cisco.com/t5/network-security/tacacs/m-p/3937437#M132441</link>
      <description>&lt;P&gt;aaa authorization command *********&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;aaa accounting ssh console *********&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;these commands enable command and user accounting.&amp;nbsp; Though I might suggest adding &lt;STRONG&gt;aaa accounting serial ********&lt;/STRONG&gt; incase anyone connects to the console port and makes changes.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 20:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tacacs/m-p/3937437#M132441</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2019-10-08T20:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+</title>
      <link>https://community.cisco.com/t5/network-security/tacacs/m-p/3941412#M132442</link>
      <description>&lt;P&gt;Can you tell me which is better to use ACL log or TACACS accounting to keep track of changes?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 06:47:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tacacs/m-p/3941412#M132442</guid>
      <dc:creator>Tuba</dc:creator>
      <dc:date>2019-10-16T06:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+</title>
      <link>https://community.cisco.com/t5/network-security/tacacs/m-p/3941422#M132443</link>
      <description>&lt;P&gt;For changes I would suggest TACACS accounting&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 06:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tacacs/m-p/3941422#M132443</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2019-10-16T06:51:34Z</dc:date>
    </item>
  </channel>
</rss>

