07-17-2013 07:53 AM - edited 03-10-2019 08:39 PM
Hi everyone,
We have configured our Cisco devices to use Windows 2008 NPS for radius. However, we are unable to configure aaa accounting for priv 15 commands to use the same radius servers for logging privileged mode commands. During configuration using the following command:
aaa accounting commands 15 default start-stop group RADIUS_SERVERS
I noticed that there are only TACACS+ servers and 'group' categories as options. After entering the radius servers group, I realized that the command is not saved and when inspecting the logs I saw the following:
The server-group "MF_RAD" is not a tacacs+ server group. Please define "RADIUS_SERVERS" as a tacacs+ server group.
Does this mean that the 'commands' accounting feature ( and probably most others ) can only be enabled when using a TACACS+ server?
Thanks in advance
Solved! Go to Solution.
07-17-2013 08:49 AM
You got it absolutely right. Command accounting only works with tacacs+. We cannot have command accounting for radius protocol. Radius accounting only gives you start and stop packet of the sessions.
~BR
Jatin Katyal
**Do rate helpful posts**
07-17-2013 08:49 AM
You got it absolutely right. Command accounting only works with tacacs+. We cannot have command accounting for radius protocol. Radius accounting only gives you start and stop packet of the sessions.
~BR
Jatin Katyal
**Do rate helpful posts**
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide