03-17-2011 03:44 AM - edited 03-11-2019 01:08 PM
hi,
can we do accounting for normal any connect users? i.e. accouting for anyone who is logged on to the network using anyconnect?
03-28-2011 02:56 AM
Hello Gavin,
You posted your question in the Firewalling section instead of the VPN section. That's probably why you haven't received any replies yet.
Regarding your question: Yes, accounting for AnyConnect users is possible.
If you only need to know when each AnyConnect user logs on and off, you only need to configure an accounting server group in the Connection Profile ("Tunnel Group" in the CLI) as explained here:
http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/vpngrp.html#wp1062323
Further information on the "accounting-server-group" CLI command can be found here:
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a1.html#wp1560638
If you also need to know which TCP and UDP traffic each AnyConnect user passes through the tunnel, this can be done as well. Please find a configuration example here:
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080b04552.shtml
Cheers,
Michael
03-30-2011 06:14 AM
Thanks machael. so I will also be able to know which user did what?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide