05-11-2011 06:46 AM
Hello, my friends. We're using cisco routers and switches. I'm concerned about the following things:
who (the ip address) loged into the device, what commands did he/she wrote, when did he/she exit,
who tried to log but failed.
how can I configure the router and switch to let them log the informations to a server?
this has nothing with configure the server-end, but only foucus on configuring the cisco router and switch.
I've tried the " logging enable", "logging server xxx", "logging trap", "terminal monitor" commands, but they
don't work.
Any one can help me? Thanks in advance!
05-11-2011 01:49 PM
To meet *all* of your requirements, I think your best bet would be to install a TACACS+ server (or more, for redundancy) and configure your Cisco devices to authenticate/authorize/account (AAA) through that. There're both commercial and freeware implementations of TACACS+, including Cisco's own Cisco Secure ACS. On the router/switch config side, you can simply search for "aaa new-model" on the cisco sites.
05-12-2011 02:54 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide