02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

• Suppressing AAA Accounting <strong>for</strong> null username sessions on page 134 (optional)<br />

• Configuring Accounting of EXEC and privilege-level command usage on page 135 (optional)<br />

• Configuring AAA Accounting <strong>for</strong> terminal lines on page 135 (optional)<br />

• Monitoring AAA Accounting on page 135 (optional)<br />

Enabling AAA Accounting<br />

The aaa accounting command enables you to create a record <strong>for</strong> any or all of <strong>the</strong> accounting functions<br />

monitored. To enable AAA accounting, per<strong>for</strong>m <strong>the</strong> following task in CONFIGURATION mode:<br />

Command Syntax Command Mode Purpose<br />

aaa accounting {system | exec |<br />

command level} {default | name}<br />

{start-stop | wait-start | stop-only}<br />

{tacacs+}<br />

Suppressing AAA Accounting <strong>for</strong> null username sessions<br />

When AAA Accounting is activated, <strong>the</strong> <strong>FTOS</strong> software issues accounting records <strong>for</strong> all users on <strong>the</strong><br />

system, including users whose username string, because of protocol translation, is NULL. An example of<br />

this is a user who comes in on a line where <strong>the</strong> AAA Au<strong>the</strong>ntication login method-list none command is<br />

applied. To prevent accounting records from being generated <strong>for</strong> sessions that do not have usernames<br />

associated with <strong>the</strong>m, per<strong>for</strong>m <strong>the</strong> following task in CONFIGURATION mode:<br />

Command Syntax Command Mode Purpose<br />

aaa accounting suppress<br />

null-username<br />

CONFIGURATION Enable AAA Accounting and create a record <strong>for</strong><br />

monitoring <strong>the</strong> accounting function.<br />

The variables are:<br />

• system—sends accounting in<strong>for</strong>mation of<br />

any o<strong>the</strong>r AAA configuration<br />

• exec—sends accounting in<strong>for</strong>mation when a<br />

user has logged in to <strong>the</strong> EXEC mode<br />

• command level—sends accounting of<br />

commands executed at <strong>the</strong> specified<br />

privilege level<br />

• default | name—Enter <strong>the</strong> name of a list of<br />

accounting methods.<br />

• start-stop—Use <strong>for</strong> more accounting<br />

in<strong>for</strong>mation, to send a start-accounting notice<br />

at <strong>the</strong> beginning of <strong>the</strong> requested event and a<br />

stop-accounting notice at <strong>the</strong> end.<br />

• wait-start—ensures that <strong>the</strong> TACACS+<br />

security server acknowledges <strong>the</strong> start notice<br />

be<strong>for</strong>e granting <strong>the</strong> user's process request<br />

• stop-only—Use <strong>for</strong> minimal accounting;<br />

instructs <strong>the</strong> TACACS+ server to send a stop<br />

record accounting notice at <strong>the</strong> end of <strong>the</strong><br />

requested user process.<br />

• tacacs+ —Designate <strong>the</strong> security service.<br />

Currently, <strong>FTOS</strong> supports only TACACS+<br />

CONFIGURATION Prevent accounting records from being<br />

generated <strong>for</strong> users whose username string is<br />

NULL<br />

134 Security

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!