06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

About ACS Logs and Reports<br />

Table 10-1 AAA-Related Log Descriptions<br />

10-2<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Chapter 10 Logs and Reports<br />

Log Description<br />

TACACS+ Accounting Contains:<br />

<strong>User</strong> sessions stop and start times<br />

AAA client messages with username<br />

Caller line identification (CLID)<br />

Session duration<br />

TACACS+ Administration Lists configuration commands entered on a AAA client by using TACACS+ (<strong>Cisco</strong> IOS).<br />

Particularly if you use ACS to per<strong>for</strong>m command authorization, we recommend that you use this<br />

log.<br />

RADIUS Accounting Contains:<br />

Note To use the TACACS+ Administration log, you must configure TACACS+ AAA clients to<br />

per<strong>for</strong>m command accounting with ACS. The following line must appear in the access<br />

server or router configuration file:<br />

aaa accounting commands start-stop tacacs+<br />

<strong>User</strong> sessions stop and start times<br />

AAA client messages with username<br />

Caller line identification in<strong>for</strong>mation<br />

Session duration<br />

You can configure ACS to include accounting <strong>for</strong> Voice-over-IP (VoIP) in the RADIUS<br />

Accounting log, in a separate VoIP accounting log, or in both places.<br />

VoIP Accounting Contains:<br />

VoIP session stop and start times<br />

AAA client messages with username<br />

CLID in<strong>for</strong>mation<br />

VoIP session duration<br />

cisco-av-pair attribute in<strong>for</strong>mation<br />

You can configure ACS to include accounting <strong>for</strong> VoIP in this separate VoIP accounting log, in<br />

the RADIUS Accounting log, or in both places.<br />

Failed Attempts Lists authentication and authorization failures with an indication of the cause. For<br />

posture-validation requests, this log records the results of any posture validation that returns a<br />

posture token other than Healthy.<br />

You can use these reports to find out who disabled the account if a given number of failed<br />

attempts has been enabled under the expiration in<strong>for</strong>mation. This can also provide some insight<br />

into intrusion attempts and is a valuable tool <strong>for</strong> troubleshooting.<br />

Passed Authentications Lists successful authentication requests. This log does not depend on accounting packets from<br />

your AAA clients, so it is available; even if your AAA clients do not support RADIUS<br />

accounting or if you have disabled accounting on your AAA clients. For posture-validation<br />

requests, this log records the results of all posture-validation requests resulting in an SPT.<br />

OL-14386-02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!