cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1534
Views
0
Helpful
2
Replies

Logging all IOS commands to AAA

adancso
Level 1
Level 1

Hi everyone,

Is it possible to log every command issued on routers/switches to an AAA server such as CiscoSecure ACS?

If yes, how?

Cheers,

Attila

2 Replies 2

jeff_caprock
Level 1
Level 1

Sure, just use the "tacacs administration" command along with the apporpriate accounting commands.

-Jeff

4brown
Level 1
Level 1

There is an excellent example of using IOS command authorization and accounting with CiscoSecure ACS for Unix here:

http://www.cisco.com/univercd/cc/td/doc/cisintwk/intsolns/secsols/aaasols/c262c4.htm#xtocid6

and

http://www.cisco.com/univercd/cc/td/doc/cisintwk/intsolns/secsols/aaasols/c262c5.htm#86578

Note this is command accounting for privilege level 15 commands. If you want to account for others, just specify the privilege level.

Hope this helps....