Accounting Using A Tacacs+ Server - Cisco SF500-24 Administration Manual

Esw2 series advanced switches
Hide thumbs Also See for SF500-24:
Table of Contents

Advertisement

20
369
Accounting—Enable accounting of login sessions using the TACACS+
server. This enables a system administrator to generate accounting reports
from the TACACS+ server.
In addition to providing authentication and authorization services, the TACACS+
protocol helps to ensure TACACS message protection through encrypted
TACACS body messages.
TACACS+ is supported only with IPv4.
Some TACACS+ servers support a single connection that enables the device to
receive all information in a single connection. If the TACACS+ server does not
support this, the device reverts to multiple connections.

Accounting Using a TACACS+ Server

The user can enable accounting of login sessions using either a RADIUS or
TACACS+ server.
The user-configurable, TCP port used for TACACS+ server accounting is the same
TCP port that is used for TACACS+ server authentication and authorization.
The following information is sent to the TACACS+ server by the device when a
user logs in or out:
Argument
Description
task_id
A unique accounting session
identifier.
user
Username that is entered for
login authentication.
rem-addr
P address of the user.
elapsed-time
Indicates how long the user was
logged in.
reason
Reports why the session was
terminated.
Cisco 500 Series Stackable Managed Switch Administration Guide Release 1.3
Security
Configuring TACACS+
In Start
In Stop
Message
Message
Yes
Yes
Yes
Yes
Yes
Yes
No
Yes
No
Yes

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents