09.12.2012 Views

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

and<br />

<br />

The authorization process works by having <strong>the</strong> router check <strong>the</strong> user's<br />

au<strong>the</strong>ntication method and access privileges. If <strong>the</strong>y meet <strong>the</strong><br />

configured authorization requirements, access <strong>to</strong> <strong>the</strong> command is<br />

permitted. This means you have <strong>to</strong> configure <strong>the</strong><br />

users'RADIUS/TACACS user profiles <strong>to</strong> reflect <strong>the</strong> specific types of<br />

services <strong>the</strong>y need. This can be quite a task, so you must decide if <strong>the</strong><br />

work is worth <strong>the</strong> return.<br />

Configuring Accounting<br />

Accounting is one of those things you just need <strong>to</strong> do, especially with<br />

services like dial-in, where security risks are high. Accounting gives<br />

you <strong>the</strong> ability <strong>to</strong> track service abuse and login failures, generate<br />

usage statistics, and so on. If you are not using some kind of system<br />

accounting on at least your high-risk system, you really should do so.<br />

There are two types of IOS accounting: user and operations. IOS<br />

provides access information on <strong>network</strong> sessions (PPP, SLIP, ARA)<br />

and outbound connections (such as Telnet, rlogin). Operational<br />

accounting, on <strong>the</strong> o<strong>the</strong>r hand, tracks <strong>the</strong> information pertaining <strong>to</strong><br />

router-centric activities. The IOS splits operational accounting<br />

between two accounting systems:<br />

• accounting—Provides system event information<br />

(similar <strong>to</strong> logging information)<br />

• accounting—Keeps track of EXEC shell commands<br />

usage<br />

IOS accounting requires a TACACS+ or RADIUS server <strong>to</strong> process <strong>the</strong><br />

accounting records. The records are collections of attribute-value

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!