02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring Accounting of EXEC and privilege-level command usage<br />

The network access server monitors <strong>the</strong> accounting functions defined in <strong>the</strong> TACACS+ attribute/value<br />

(AV) pairs.<br />

In <strong>the</strong> following sample configuration, AAA accounting is set to track all usage of EXEC commands and<br />

commands on privilege level 15.<br />

<strong>Force10</strong>(conf)#aaa accounting exec default start-stop tacacs+<br />

<strong>Force10</strong>(conf)#aaa accounting command 15 default start-stop tacacs+<br />

System accounting can use only <strong>the</strong> default method list:<br />

aaa accounting system default start-stop tacacs+<br />

Configuring AAA Accounting <strong>for</strong> terminal lines<br />

Use <strong>the</strong> following commands to enable accounting with a named method list <strong>for</strong> a specific terminal line<br />

(where com15 and execAcct are <strong>the</strong> method list names):<br />

<strong>Force10</strong>(config-line-vty)# accounting commands 15 com15<br />

<strong>Force10</strong>(config-line-vty)# accounting exec execAcct<br />

Monitoring AAA Accounting<br />

<strong>FTOS</strong> does not support periodic interim accounting, because <strong>the</strong> periodic command can cause heavy<br />

congestion when many users are logged in to <strong>the</strong> network.<br />

No specific show command exists <strong>for</strong> TACACS+ accounting. To obtain accounting records displaying<br />

in<strong>for</strong>mation about users currently logged in, per<strong>for</strong>m <strong>the</strong> following task in Privileged EXEC mode:<br />

Command Syntax Command Mode Purpose<br />

show accounting CONFIGURATION Step through all active sessions and print all <strong>the</strong> accounting<br />

records <strong>for</strong> <strong>the</strong> actively accounted functions.<br />

Figure 65 show accounting Command Example <strong>for</strong> AAA Accounting<br />

<strong>Force10</strong>#show accounting<br />

Active accounted actions on tty2, User admin Priv 1<br />

Task ID 1, EXEC Accounting record, 00:00:39 Elapsed, service=shell<br />

Active accounted actions on tty3, User admin Priv 1<br />

Task ID 2, EXEC Accounting record, 00:00:26 Elapsed, service=shell<br />

<strong>Force10</strong>#<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 135

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!