accounting of the ASA

Hello guys,.

I would like to kindly ask if someone can give me some advice on the following situation:

I play with Asa 8.2 version device (5). I have installed it with freeradius and mysql. I try to do the accounting with ASA:

My configuration:

Configuration of the SAA for accounting:

accounting AAA match ACCOUNTANTS inside radius

accounting AAA match ACCOUNTING outside RADIUS

ASA ACL:

Show running-config-list of access ACCOUNTING

ACCOUNTING allowed ip extended access list a whole

ACCOUNTING list extended access permitted tcp a whole

ACCOUNTING list extended access udp allowed a whole

ACCOUNTING list extended access permit icmp any one

I obtaion in mysql accounting journal of the asa. But my problem is that: I get data just with session start and end which correspond to the ACL. I find no better way on how to do it. I want to record all the user session to vpn-> session start and end when the user connect by vpn. Not just at the moment where the user meets my ACL interesting traffic.

Thanks for the tips!

Hi Veronika,

Try this:

global-tunnel-group attributes

Group accountant-Server Radius

To be honest I don't know off the top of my head if it will work without also the radius authentication - so if you do not have authentication radius and of the above does not work, try adding, i.e.:

global-tunnel-group attributes

Group-Radius Authentication Server

HTH

Herbert

Tags: Cisco Security

Similar Questions

  • What is the current status of the feature of Kerberos delegation constrained on the platform of the ASA?

    What is the current status of the feature of Kerberos delegation constrained on the platform of the ASA?

    Hi Oscar,.

    It is not yet available in the current software. Now, we can give no official information on this forum about software that has not yet been published, but if you really want to know, I suggest that you contact your local sales office Cisco to confirm with your account team that news will be in the next version of Software ASA 8.4.

    HTH

    Herbert

  • Activate the ASA system context AAA authentication

    Hello!

    We have ASA configured in multiplayer in context with 8.4 (2) software configured for AAA

    Configuration is admin context as follows:

    AAA-server TAC Protocol Ganymede +.

    host of the TAC AAA-server 10.162.2.201 (management)

    key *.

    Console to enable AAA authentication LOCAL TAC

    TAC LOCAL console for AAA of http authentication

    AAA authentication serial console LOCAL TAC

    authentication AAA ssh console LOCAL TAC

    Because of the multiple context, after the connection we enter in the system context. Console port authentication works very well except access to the privileged mode when you connect through the console port.

    After the show 'enable' command ASA accepts only configured activate secret in context and change ID of user system for enable_15, so we are unable to do accounting and authorization of user level control.

    It seems that the ASA in the context of the system is not aware of all the configurations of AAA, and it is not a command to configure AAA in the context of the system.

    Is there a way to configure enable AAA authentication in the context of the system?

    Thanks in advance!

    Hello

    It looks like you hit this known issue that follows:

    http://Tools.Cisco.com/support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsw18455

    Admin context allow mode compared to the context system DB credentials

    Symptom:

    In multi-mode configuration, the user to enter privileged mode credentials
    (enable mode) via the serial console is not sent to an external server
    role of authentication.

    Conditions:

    ASA/PIX is in multi mode. serial console and activate the console authentication
    are configured to use external aaa server in the context of the admin.

    Workaround solution:

    Option 1: Configure enable password in the system context. Option 2: Avoid the use of the interface of the console series and rely on telnet
    or ssh console access.  SSH or telnet consoles, tries to enter
    active mode is authenticated as specified by the configuration of aaa in
    the context of "admin".
    Other Description of the problem:

    When authentication is enabled for the serial console and activate console in
    Executive admin via an external aaa Server (for example: radius or Ganymede +), series
    Console OmniPass is against the external aaa server, but the mode
    credentials are compared with enable db in the context of the system.

    Hope that clarifies it. Unfortunately there is no solution for this problem.

    Kind regards.

  • Can I keep my itunes account in the United Kingdom and add applications to the United States on my account so that the United States pls.?

    Can I keep my itunes account in the United Kingdom and add applications to the United States on my account so that the United States pls.?

    How long you will be in the United States? To use the US store, you must be physically located in the United States, have issued US credit card and billing address in the United States on this credit card. Without it, you won't be able to change for the US store. And, you can only change stores every 90 days.

  • Cannot configure the Exchange account on the iPhone 6

    I have an iPhone installed 6 9.3.2. I tried to add my work Exchange account to the native application and the Outlook application and will not work. He says no more it cannot check account details or it asks me to check the user name and password. My exchange account will not also add to my old iPhone 4S or iPad 3.

    Other users of the iPhone to work added to their Exchange accounts without problem. Mine is the only one Exchange is aware of this does not work. They were not able to help. There is no IMAP settings, so I can only add an Exchange account.

    I tried to reset the network settings, but that didn't help. I even tried the soft CloudMail and does not work either.

    Any ideas?

    I saw a few times at my work. Cause is more than likely the local rather than on iPhone, mail server because it does not work in the Mail as Outlook App application.

    It could be that the settings on the e-mail server does not have Activesync devices – might be useful to check with HER to see if they enabled that.

  • I have two main e-mail accounts and mail is "forwarding" emails sent to one account to the other older account, they arrive a few hours later. Not sure why it's duplicate my emails at all. How can I stop this?

    Kind of hard to explain in the title... who probably is meaningless.

    Basically, I used to use a BTinternet email for any account. But over the years, I went to my iCloud email account. I have both implemented in mail because I still have the BTinternet account that is linked to many things, despite always use iCloud for the new things now.

    However, when I get a message that was sent to my new iCloud account originally, it appear a new message in my BTinternet a few hours later. And it's quite annoying! Makes me think I have a new email, but this is the one I read Twitter.com.

    It's as if there's some rule set up causing Mail to transmit all messages sent to my email from iCloud, to my BTinternet email. I have no idea why this is happening. There is no actual 'rules' put in place for this in my Mail preferences. Don't know what it could be.

    Any ideas?

    Check iCloud.com/Mail, click on the gear at the bottom left, select Preferences, then accounts. The iCloud account is set up to transfer emails?

  • How can I send pictures to my e-mail account to the cell phone of others?

    I have a request to send photos to someone who uses their smart phone and I do not have pictures in a phone; only on my PC. Can I send pictures of this person's mobile phone? They gave me their number. Thank you

    It is possible to send a text message (SMS) to a phone by email (look for "sms e-mail gateway"), but I don't know if you can join this way, i.e. MMS pictures. The simplest method would be for the recipient create an e-mail account on the phone. If they can't or won't, but they can access the web via a browser, I guess you could upload photos on one of the free file hosting services photo and send them links using the email-to-text method mentioned above.

  • How to remove an e-mail account on the iphone?

    How to remove an e-mail account on the iphone?

    davidfromgambrills wrote:

    How to remove an e-mail account on the iphone?

    mail/contacts/calendar settings - E-mail account - select - scroll down to delete.

  • Some accounts have the Recycle Bin instead of the trash icon. Cannot run 'Empty trash' on the record, only on an icon to the trash.

    I have four accounts open TB: mine, woman, club and spam. Only mine and spam account display the Recycle Bin icon. The other two accounts have a folder named "Trash". Deleted files go in the Trash files, is similarly in the trash icon files. However, there is a single action, I can perform on files from the Recycle Bin. When right clicking on folders, "empty trash" is not available as an option. The function is available only on folders with the Recycle Bin icon.
    Is there a way to get the appropriate folder to the trash with function 'empty trash' in all accounts?

    OK - I messed around with the settings more and came across a solution.
    1 right-click on the account name in the left pane, and then select settings.
    2. Select Server settings
    3. in the central block under deletion actions, select Advanced
    4. uncheck the "show only subscribed folders", and then click OK
    5. click OK in the parameters, and then collapse the account name in the left pane so not subfolders appear.
    6 expand the name of the account. This is - the trash is now a garbage can with the function of "empty trash".
    7. If desired, return to the advanced settings and re - select "show only subscribed folders" and click OK

    Don't ask me why this works. It's a total coincidence that I even found it.

  • account on the left side of the screen endangered

    I had 3 e-mail accounts defined. They came with folders over there on the left side of the screen. I then tried to add a fourth account that the missing 3rd account is if it was withdrawn and the fourth new account shows nothing on the left side. All the most as it does not exist. But when I use the menu option [file - get new messages for] the window pop up shows that the 4th account is there.
    Or I can click on one of the names of account on the side left then [display for this account setting] and in the left window, I see the 4th account. I have the screen shot speaks on behalf of bob.

    How can I get the main screen to display the accounts of al in the left window?

    I have xp configured to display system files and folders. My xp is not Thunderbird [help > troubleshooting] option. Each account that local directory has been replaced by C:\Documents and Settings\King\My Documents\Thunderbird_Mail\jail1 - 119.web - hosting.com
    This way I can back up the directories of mail for each account. Also for backup purposes, I also copied directory C:\Documents and Settings\King\Application Data\Thunderbird\Profiles\e5hjmse7.default tree in My Documents. To fix the problem I just copied the supported by directory 5hjmse7.default tree which he original path and everything was back to normal. Thunderbird has need bkup option that records these hidden config and directories of email in my documents.

  • In what one account all read emails disappear when I go on a different account than the back. Read all emails will appear is no longer in the Inbox or the trash.

    In what one account all read emails disappear when I go on a different account than the back. Read all emails will appear is no longer in the Inbox or the trash. Is there a setting that I don't see. Thanks Johnny1

    Try view (Alt - V) - son - everything.

  • Hide the list of accounts in the left in unified folders view window

    I am from Eudora and trying to put things up in a similar way on Thunderbird. To the extent where everything has been working PERFECTLY and I really didn't miss Eudora that much more.

    However, since I have several e-mail accounts (I participate in several companies and projects including requieres all me to use different accounts) and I'm trying to keep it as simple as possible in Thunderbird.

    I am currently in folders 'Uni' mode, which helps me get rid of a large number of files that I would never use. Now I want to get rid of the list of accounts in the left window while I have that Inbox, Sent, Trash, Outbox, drafts and then my custom folders. Is it possible to do this in Thunderbird (I hope that without the help of an add-on)?

    The "Unified" view breaks records in particular is very useful especially for the IMAP folders that cannot use a global Inbox. But it may not be the best for your application.

    I use a useful feature in thunderbird called "Favorite" folders, which may be of interest to you.

    If you have a few folders that you use most of the time and I would like to see them, but not the other so that the view is less crowded, then right-click on a folder of choice and select 'Favorites '. You can select several folders.

    Then view > folders > Favorites
    Then displays only selected favorite records.

  • I can arrange the order of my accounts in the order of my use of priority

    I have several e-mail accounts, they are in the order I added the.
    is it possible that I can move the account to the top or to the bottom of the order

    Go to the add ons page and search the files of manual sorting. This add on will do what you want.

  • My local folders appear above my accounts in the LH pane; they used to be under the accounts?

    When I first installed TB a few days ago, the LH receives the order from top to bottom as 1 account, account 2, local folders. Now, it's local folders at the top. I used the add-on "Manual sorting files" to sort IN the accounts and local folders, but as far as I see it, there is no way that local folders should appear first? Any suggestions, as I don't want my accounts at the top.

    Allan

    The one above is the default.

    Maybe the local folders is currently set as a default value.

    • Tools > accounts settings
    • Select / Select the account you want as default
    • Click on "Actions account."
    • Select "Set as default"
    • Click OK
  • At the end of the creation of an e-mail account, that the program will ask a software password security device, I don't know what it is or where to find it.

    At the end of the creation of an e-mail account, that the program will ask a software password security device, I don't know what it is or where to find it. To my knowledge I don't have a 'software security device. I use Windows 7 on an IMac.

    Apparently, you have defined a master password at one point. The password protects passwords that Thunderbird remembered.
    You can reset the password. More information in this article.

    http://KB.mozillazine.org/Master_password

Maybe you are looking for