cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
449
Views
0
Helpful
2
Replies

accounting for anyconnect users

gavin han
Level 1
Level 1

hi,

can we do accounting for normal any connect users? i.e. accouting for anyone who is logged on to the network using anyconnect?

2 Replies 2

Michael Schueler
Cisco Employee
Cisco Employee

Hello Gavin,

You posted your question in the Firewalling section instead of the VPN section. That's probably why you haven't received any replies yet.

Regarding your question: Yes, accounting for AnyConnect users is possible.

If you only need to know when each AnyConnect user logs on and off, you only need to configure an accounting server group in the Connection Profile ("Tunnel Group" in the CLI) as explained here:

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/vpngrp.html#wp1062323

Further information on the "accounting-server-group" CLI command can be found here:

http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a1.html#wp1560638

If you also need to know which TCP and UDP traffic each AnyConnect user passes through the tunnel, this can be done as well. Please find a configuration example here:

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080b04552.shtml

Cheers,

Michael

Thanks machael. so I will also be able to know which user did what?

Review Cisco Networking for a $25 gift card