Starting Tacacs+ Accounting - Cisco C3201FESMIC-TP= - 3201 Fast EN Switch Mobile Interface Card Expansion Module Software Configuration Manual

Wireless mic
Table of Contents

Advertisement

Administering the WMIC
The aaa authorization exec tacacs+ local command sets these authorization parameters:
Note
Authorization is bypassed for authenticated users who log in through the CLI even if authorization has
been configured.
To specify TACACS+ authorization for privileged EXEC access and network services, follow these steps,
beginning in privileged EXEC mode:
Command
Step 1
configure terminal
Step 2
aaa authorization network tacacs+
Step 3
aaa authorization exec tacacs+
Step 4
end
Step 5
show running-config
Step 6
copy running-config startup-config
To disable authorization, use the no aaa authorization {network | exec} method1 command in global
configuration mode.

Starting TACACS+ Accounting

The AAA accounting feature tracks the services that administrators are accessing and the amount of
network resources that they are consuming. When AAA accounting is enabled, the WMIC reports
administrator activity to the TACACS+ security server in the form of accounting records. Each
accounting record contains accounting attribute-value (AV) pairs, and is stored on the security server.
This data can then be analyzed for network management, client billing, or auditing.
To enable TACACS+ accounting for each Cisco IOS privilege level and for network services, follow
these steps, beginning in privileged EXEC mode:
Command
Step 1
configure terminal
Step 2
aaa accounting network start-stop
tacacs+
Step 3
aaa accounting exec start-stop tacacs+
Step 4
end
Use TACACS+ for privileged EXEC access authorization if authentication was performed by using
TACACS+.
Use the local database if authentication was not performed by using TACACS+.
Purpose
Enters global configuration mode.
Configures the WMIC for user TACACS+ authorization for all
network-related service requests.
Configures the WMIC for user TACACS+ authorization to determine
whether the user has privileged EXEC access.
The exec keyword might return user profile information (such as
autocommand information).
Returns to privileged EXEC mode.
Verifies your entries.
(Optional) Saves your entries in the configuration file.
Purpose
Enters global configuration mode.
Enables TACACS+ accounting for all network-related service requests.
Enables TACACS+ accounting to send a start-record accounting notice
at the beginning of a privileged EXEC process and a stop-record at the
end.
Returns to privileged EXEC mode.
Cisco 3200 Series Wireless MIC Software Configuration Guide
Controlling WMIC Access with TACACS+
37

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents