AAA accounting Config help

I have Cisco ACS 3.2 on widnows with cisco (IOS 12.3) devices configured with authentication. I need enable accounting. I just need the list of commands (changes) on the cisco device. What is the command to correct authentication? This is the current configuration.

AAA server Ganymede group + tacgrp

Server X.X.X.X

Server Y.Y.Y.Y

!

AAA authentication login default group Ganymede + local

AAA authentication login relief group Ganymede + activate

AAA - the id of the joint session

GANYMEDE-server host X.X.X.X

GANYMEDE-server host Y.Y.Y.Y

RADIUS-server application made

RADIUS-server key 7 XXXXXXXXXXXXXXXXXXX

Line con 0

line vty 0 4

There is no accounting for SNMP.

The snmp on the router show command can tell you how many polls where done.

Example to see the output of snmp:

RAME: SCA043004DW

Contact: smotwani

Location: noida

SNMP 56224160 to input packets

0 bad SNMP version error

38 unknown community name

Illegal operation in name of the provided community 0

Coding errors 0

Number of requested variables 268814216

Number 112 of the variables changed

35437579 get PDUs request

20781918 get-next PDUs

24 set-request PDUs

0 input queue DROPS number package (Maximum 1000 queue size)

56224122 release of SNMP packets

0 too big mistakes (maximum 1500 packet size)

15 no such errors of name

Bad values 0 errors

0 General errors

56219928 response PDUs

0 trap PDUs

You can also define a list of access allowing for any snmp and connect the access list which will have a counter that increments.

There is no such thing as research in the papers of the ACS to know how often snmp has been consulted and what ip address for the simple reason that the authorization does not apply to the snmp.

Tags: Cisco Security

Similar Questions

  • AAA accounting report is not with issued orders.

    Hello everyone, I have a problem with the AAA accounting on my ACS 4.0 device. When I view the posting journal lists the connections, protocols and addresses IP but not the commands executed on the specific switch. When I debug AAA accounting I see ouput but when I debug Ganymede accounting I see nothing. An exammple of my config is:

    AAA new-model

    AAA group Ganymede Server + ACS

    Server [ip address here]

    Server [ip address here]

    AAA accounting exec by default start-stop group ACS

    AAA accounting command 0 arrhythmic group ACS

    orders accounting AAA 15 start-stop ACS group

    RADIUS-server key [here].

    I left on the framework for the authentication of the configuration (in the example above) that it works very well.

    Someone at - it ideas why the actual orders are not be captured on GBA?

    Thanks in advance.

    GBA, accounting of the order must be recorded in the Administration of GANYMEDE + do not connect not the journal GANYMEDE + accounting! Don't ask me why, what just. At least it is on my own and took me a while to discover as well.

    Hope this helps

    Concerning

    Mike

  • GANYMEDE + config help

    Having trouble with a Ganymede config...

    I can't SSH into my switch 3560 with a configured RADIUS username / password but orders as write mem or dir display an error message.

    The command ' write' is not allowed for the user [user_name] and customer [ip address]

    AAA new-model
    AAA authentication login default group Ganymede + local
    the AAA authentication enable default group Ganymede + activate
    AAA authorization config-commands
    AAA authorization exec default group Ganymede + authenticated if
    AAA authorization commands 1 default group Ganymede + authenticated if
    AAA authorization commands 15 default group Ganymede + authenticated if
    AAA accounting exec default start-stop Ganymede group.
    orders accounting AAA 1 by default start-stop Ganymede group.
    orders accounting AAA 15 by default start-stop Ganymede group.
    AAA - the id of the joint session

    Hi Rob,

    As everything is Ganymede + specific.

    If the command is without authority, this has be checked on the Ganymede server +.

    What is a Ganymede server + you use?

    Concerning

    Ed

  • AAA accounting on routers

    Hey guys,.

    I'm looking for help to set up my router to where it makes account of my CSACS all commands run by users. For example, I login as the user bbaggins and I change a configuration of ACL, is there a way for the orders that I typed in being connected by the ACS?

    Thanks for your help.

    You must configure this Ganymede. Here are the commands.

    AAA accounting exec default start-stop Ganymede group.

    orders accounting AAA 1 by default start-stop Ganymede group.

    orders accounting AAA 15 by default start-stop Ganymede group.

    Command accounting logs are stored in the newspapers of the administration of Ganymede. There is also a known issue on ver 4.1.1 and we must apply the ACS 4.1.1.23.5 patch to fix the problem.

    Patch for the unit is available on

    http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-Soleng-3DES

    The patch name: ACS SE 4.1.1.23.5 rollup

    Acs hotfix for windows is available on

    http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-win-3DES

    The patch name: ACS 4.1.1.23.5 rollup

    Kind regards

    ~ JG

    Note the useful messages

  • AAA router Config

    I found the following config on one of the routers. Are RADIUS server defined two groups as well as individually. That we can remove?

    AAA server Ganymede group + mytacgrp
    Server X.X.80.55
    Server Y.Y.126.50

    AAA authentication login default group Ganymede + local
    AAA authentication login relief group Ganymede + activate
    AAA accounting exec default start-stop Ganymede group.
    orders accounting AAA 0 arrhythmic default group Ganymede +.
    orders accounting AAA 1 by default start-stop Ganymede group.
    orders accounting AAA 15 by default start-stop Ganymede group.
    AAA accounting system default start-stop Ganymede group.
    AAA - the id of the joint session

    radius-server X.X.80.55 host
    radius-server Y.Y.126.50 host
    RADIUS-server application made
    RADIUS-server key 7 XXXXXXXXXXXX

    The AAA server-group feature introduces a way to group existing server hosts. The feature enables you to select a subset of the configured server hosts and use them for a particular service

    you use global "Ganymede +" group of servers so

    AAA server Ganymede group + mytacgrp can be deleted (its unused)

    If you for example 'aaa authentication login default group local mytacgrp', you would use it. What more this group has exactly the same servers that global is not necessary

    concerning

    Przemek

  • When I try to buy a book, it seems it download but does not work. If I am able to get a sample and try to buy the sample goes far & no new book. There are funds in my account iTunes Help!

    When I try to buy a book, it seems it download but does not work. If I am able to get a sample & try to buy the sample goes far & no new book. There are funds in my account iTunes Help!

    Mine just did the same thing. I've even went and was sold again in case I did something wrong the first time. Still no book! I had to happen a few weeks ago, but when I closed iBooks and reopened, the book was there. This time that didn't happen.  I prefer to read on the iBook, but I'm not if my books download

  • I can't open my email account please help me my email id is * address email is removed from the privacy * and my cell number is 09820010620

    I can't open my email account please help me my email id is * address email is removed from the privacy * and my cell number is * deleted phone number *.

    View all Windows Live and Hotmail questions in the appropriate forum found here:
    http://windowslivehelp.com/

    Stupid idea posting your cell phone number.

  • The system, I cannot delete permission in the help section. I need to authorize another account. Help, please!

    The system, I cannot delete permission in the help section. I need to authorize another account. Help, please!

    The account I want to delete the authorization already has the limit of the installed PC. I want to authorize another account.

    If for some reason you cannot withdraw the authorization of ADE, follow the steps below:

    Mac:

    1. go-> go to folder.

    Go to the folder dialog box will appear.

    2. Enter ~/Library/Application Support/Adobe/Digital Editions

    Drag the activation.dat file to the trash.

    ADE will be cancelled now.

    Now allow ADE new [help-> allow the computer].

    Windows:

    Click Start > run.

    Open, type regedit in the text box and press ENTER. The Registry Editor opens.

    In the left pane of the registry editor, find the following registry key:

    HKEY_CURRENT_USER\Software\Adobe\Adept

    Right click on the key to the follower, and then choose Remove.

    In the dialog box confirm the key deletion, click OK.

    Your permission is removed.

    ADE will be cancelled now.

    Now allow ADE new. [Help-> allows computer].

  • I want to delete my account, please help me!

    I want to delete my account, please help me!

    Hi celiine,

    Looks like you're all set! Your account has been cancelled.

    If this is not the case, let me know.

    Best regards, Stacy

  • He can't change the region of my account! Help, please! Thank you ~ ~ ~

    Hello

    I want to change my account area. But I still balance ($0.02) so I couldn't change. Please delete my balance.

    Thank you!

    and now I can not contact the Apple Support it's always show

    We're sorry.

    We are unable to respond to your request at this time. Please try again or come back later.

    1c14bb55-ED82-4B43-9c22-fc79914a022c

    is could someone please help me contact the apple support to clear my balance or help me another way to change the region on my account please!

    Thank you!!

  • Online store account login help

    I forgot to e-mail and password to connect account toshiba virtual store
    Can you help me to access my account?

    Thank you for the request.

    Please see this FAQ:
    http://www.toshibatouch.EU/journe_touch_wince/FAQs.php

    In your request, you must provide your user account identifier.
    You can find it in the virtual store Toshiba connection dialog box

  • suspended account need help.

    my account has been used by my brother, I give him promise need help get back help please!

    Hello

    Answers has no influence on the XBox or XBox Live must
    contact with them.

    XBox - Support
    http://support.Xbox.com/en-us/pages/default.aspx

    XBox - Contact us (support)
    http://support.Xbox.com/en-us/contact-us

    XBox - Support Forums - and my XBox (top-right)
    http://forums.Xbox.com/

    Xbox technical support phone number

    • Toll-free: (800) 4MY-XBOX or (800) 469-9269

    XBox LIVE - Service status
    http://support.Xbox.com/en-us/Xbox-Live-status

    Manage the XBox Live account
    http://support.Xbox.com/en-us/billing-and-subscriptions/account-management/Xbox-Live-account-management

    XBox Live Sign-in problems
    http://support.Xbox.com/en-us/billing-and-subscriptions/Windows-Live-ID/Xbox-Live-sign-in

    I hope this helps.

    Rob Brown - Microsoft MVP<- profile="" -="" windows="" expert="" -="" consumer="" :="" bicycle=""><- mark="" twain="" said="" it="">

  • Blocked account please help

    Hi How are you please help me that my account has been banned in your email, nor I see the Inbox

    {Removed by moderator}

    {Removed by moderator}
    {Removed by moderator}

    Hi wa8,.

    Please check if the problem persists.

    Thank you!

  • Icannot access my hotmail again in2 Wks account! Help, please...

    I TRIED TO ACCESS MY ACCOUNT HOTMAIL FOR FOUR DAYS AND HAVE VALUABLE CONTAACTS AND I MUST HAVE ACCESS TO EMAILS... THIS IS THE 2ND TIME THIS HAS HAPPENED WITH A PERIOD OF 2 WEEKS! PLEASE ADVISE... I TRIED ALL OF THEIR SITES AND SUGGESTIONS AND WILL CLOSE THIS ACCOUNT ONCE FOR ALL, BUT AFTER I GET MY MATERIALS NECESSARY

    THANK YOU, ELLEN

    Hello

    Answers is supported through peer review and has no real influence on Hotmail or
    other sites.

    ---------------------------------------------------------------------------------------------

    HotMail has its own Forums, so you can ask your questions there.

    Windows Live Solution Center - HotMail - HotMail Forums Solutions
    http://windowslivehelp.com/

    Hotmail - Forums
    http://windowslivehelp.com/forums.aspx?ProductID=1

    Hotmail - Solutions
    http://windowslivehelp.com/solutions.aspx?ProductID=1

    How to contact Windows Live Hotmail Support
    http://email.about.com/od/hotmailtips/Qt/et_hotmail_supp.htm

    Windows Live Hotmail Top issues and Support information
    http://support.Microsoft.com/kb/316659/en-us

    Compromised account - access unauthorized account - how to recover your account
    http://windowslivehelp.com/solution.aspx?SolutionID=6ea0c7b3-1473-4176-b03f-145b951dcb41

    Hotmail hacked? Take these steps
    http://blogs.msdn.com/b/securitytipstalk/archive/2010/07/07/Hotmail-hacked-take-these-steps.aspx

    I hope this helps.

  • Pirated Windows live account. Help :(

    My Windows Live hotmail account was closed because apparently being hacked. I made this account about 12 years ago, the e-mail address attached to it I have not used since I have about seven years, so I can't do it to retrieve the code that I need to free my account. Also same problem when I tried to correct the password that they need an answer to my secret question, without the slightest trace. I made this account once again at any age 9 so same problem. Any help?

    https://windowslivehelp.com/PasswordReset.aspx

Maybe you are looking for

  • HP 240 g3: you can upgrade the graphics card on hp 240g 3

    I have the 240 with celeron n2840 g3 and intel hd 2 GB ram is it possible to upgrade ram and a dedicated video memory?

  • Aspire v5 471g computer laptop problems

    When I start the pc and try to go to the bios by pressing f2 at the time... After a month, when I press f2, it just beeps (like before), clears the screen and proceed to load the operating system... 2nd thing, hyper v is not in the bios, I can't even

  • SW trigger send 33120 IVI - C step fails

    I use the driver FOR the HP33120 in send step TS 4.0 IVI - C SW trigger. I set up the device without problem for burst trigger 2 software leaders and validate it. When I try to use the SW trigger send IVI - V step I get the error Component works IVI

  • BlackBerry smartphones, does that mean symbol?

    I have a black circle with a white arrow pointing downwards through the Center. Anyone know what this indicates?

  • 6500 e 709n

    I get a msg err {0 x 61011 bed}, I can't find my manual Can someone give me help to find a solution to this error msg. The printer does not print