29.04.2019 Views

OS6860(E)_AOS_8.1.1.R01_Switch_Management_Guide

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing <strong>Switch</strong> Security<br />

Configuring Accounting for ASA<br />

Configuring Accounting for ASA<br />

Accounting servers track network resources such as time, packets, bytes, etc., and user activity (when a<br />

user logs in and out, how many login attempts were made, session length, etc.). The accounting servers<br />

may be located anywhere in the network.<br />

Note the following:<br />

• The servers may be different types.<br />

• The keyword local must be specified if you want accounting to be performed via the <strong>Switch</strong> Logging<br />

feature in the switch. If local is specified, it must be the last server in the list.<br />

Note that external accounting servers are configured through the aaa radius-server and<br />

aaa tacacs+-server commands. These commands are described in “Managing Authentication Servers” in<br />

the Omni<strong>Switch</strong> <strong>AOS</strong> Release 8 Network Configuration <strong>Guide</strong>.<br />

To enable accounting (logging a user session) for Authenticated <strong>Switch</strong> Access, use the<br />

aaa accounting session command with the relevant server name(s). In this example, the RADIUS and<br />

LDAP servers have already been configured through the aaa radius-server and aaa ldap-server<br />

commands.<br />

-> aaa accounting session rad1 ldap2 local<br />

After this command is entered, accounting will be performed through the rad1 RADIUS server. If that<br />

server is unavailable, the LDAP server, ldap2, will be used for accounting. If that server is unavailable,<br />

logging will be done locally on the switch through the <strong>Switch</strong> Logging feature. (For more information<br />

about <strong>Switch</strong> Logging, see the Omni<strong>Switch</strong> <strong>AOS</strong> Release 8 Network Configuration <strong>Guide</strong>.)<br />

To remove an individual server from the list of servers, enter the aaa accounting session command with<br />

the relevant server name(s), removing the desired server from the list. For example:<br />

-> aaa accounting session rad1 local<br />

The server ldap2 is removed as an accounting server.<br />

To disable accounting for Authenticated <strong>Switch</strong> Access, use the no form of the aaa accounting session<br />

command:<br />

-> no aaa accounting session<br />

Accounting will not be performed for Authenticated <strong>Switch</strong> Access sessions.<br />

Omni<strong>Switch</strong> <strong>AOS</strong> Release 8 <strong>Switch</strong> <strong>Management</strong> <strong>Guide</strong> May 2014 page 7-11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!