07-13-2007 09:26 AM - edited 03-10-2019 03:16 PM
We are using Microsoft IAS Radius server for authentication to a large number of Cisco routers in our organization. Is it possible to log the commands that are entered on routers (Whether console or telnet session) for audit purposes? If so, is there a document on how to do implement it?
07-13-2007 09:28 AM
Hi,
That is very much possible but I am not sure if IAS logging supports it. Here are the commands we need to configure on IOS devcie.
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 0 default start-stop group tacacs+/Radius
aaa accounting commands 1 default start-stop group tacacs+/Radius
aaa accounting commands 15 default start-stop group tacacs+/Radius
HTH
Parminder
07-13-2007 09:31 AM
Unfortunately its not possible using IAS, as it only supports Radius protocol.
And you are looking for is covered under TACACS+ protocol (Cisco ACS)
Regards,
Prem
07-13-2007 11:28 AM
Hi,
My apologies for the incorrect information, I recreated this issue and Prem is correct, we cannot configure radius accounting for the commands. Tacacs is the only option available for the command accounting.
Thanks
Parminder
07-13-2007 02:48 PM
Check this out.
http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a0080454f73.html
HTH and please rate.
07-14-2007 09:31 AM
Collin
This is a very neat feature that I was not aware of. I believe it deserves the 5 rating that I gave it.
HTH
Rick
07-14-2007 11:10 AM
Indeed a very good feature.
rated :-)
Narayan
07-10-2013 04:13 PM
The link no longer seems to be valid. What is the neat/good feature that you guys are talking about ??
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide