Dell PowerEdge FX2 Dell PowerEdge FN I/O Aggregator Configuration Guide 9.6(0 - Page 158

AAA Accounting, Configuration Task List for AAA Accounting

Page 158 highlights

AAA Accounting Accounting, authentication, and authorization (AAA) accounting is part of the AAA security model. For details about commands related to AAA security, refer to the Security chapter in the Dell Networking OS Command Reference Guide. AAA accounting enables tracking of services that users are accessing and the amount of network resources being consumed by those services. When you enable AAA accounting, the network server reports user activity to the security server in the form of accounting records. Each accounting record comprises accounting attribute/value (AV) pairs and is stored on the access control server. As with authentication and authorization, you must configure AAA accounting by defining a named list of accounting methods and then applying that list to various virtual terminal line (VTY) lines. Configuration Task List for AAA Accounting The following sections present the AAA accounting configuration tasks. • Enabling AAA Accounting (mandatory) • Suppressing AAA Accounting for Null Username Sessions (optional) • Configuring Accounting of EXEC and Privilege-Level Command Usage (optional) • Configuring AAA Accounting for Terminal Lines (optional) • Monitoring AAA Accounting (optional) Enabling AAA Accounting The aaa accounting command allows you to create a record for any or all of the accounting functions monitored. To enable AAA accounting, use the following command. • Enable AAA accounting and create a record for monitoring the accounting function. CONFIGURATION mode aaa accounting {commands | exec | suppress | system level} {default | name} {start-stop | wait-start | stop-only} {tacacs+} The variables are: - system: sends accounting information of any other AAA configuration. - exec: sends accounting information when a user has logged in to EXEC mode. - command level: sends accounting of commands executed at the specified privilege level. - suppress: Do not generate accounting records for a specific type of user. - default | name: enter the name of a list of accounting methods. - start-stop: use for more accounting information, to send a start-accounting notice at the beginning of the requested event and a stop-accounting notice at the end. - wait-start: ensures that the TACACS+ security server acknowledges the start notice before granting the user's process request. - stop-only: use for minimal accounting; instructs the TACACS+ server to send a stop record accounting notice at the end of the requested user process. - tacacs+: designate the security service. Currently, Dell Networking OS supports only TACACS+. 158 Security

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292

AAA Accounting
Accounting, authentication, and authorization (AAA) accounting is part of the AAA security model.
For details about commands related to AAA security, refer to the
Security
chapter in the
Dell Networking
OS Command Reference Guide
.
AAA accounting enables tracking of services that users are accessing and the amount of network
resources being consumed by those services. When you enable AAA accounting, the network server
reports user activity to the security server in the form of accounting records. Each accounting record
comprises accounting attribute/value (AV) pairs and is stored on the access control server.
As with authentication and authorization, you must configure AAA accounting by defining a named list of
accounting methods and then applying that list to various virtual terminal line (VTY) lines.
Configuration Task List for AAA Accounting
The following sections present the AAA accounting configuration tasks.
Enabling AAA Accounting
(mandatory)
Suppressing AAA Accounting for Null Username Sessions
(optional)
Configuring Accounting of EXEC and Privilege-Level Command Usage
(optional)
Configuring AAA Accounting for Terminal Lines
(optional)
Monitoring AAA Accounting
(optional)
Enabling AAA Accounting
The
aaa accounting
command allows you to create a record for any or all of the accounting functions
monitored.
To enable AAA accounting, use the following command.
Enable AAA accounting and create a record for monitoring the accounting function.
CONFIGURATION mode
aaa accounting {commands | exec | suppress | system
level
} {
default
|
name
}
{start-stop | wait-start | stop-only} {tacacs+}
The variables are:
system
: sends accounting information of any other AAA configuration.
exec
: sends accounting information when a user has logged in to EXEC mode.
command
level
: sends accounting of commands executed at the specified privilege level.
suppress
: Do not generate accounting records for a specific type of user.
default
|
name
: enter the name of a list of accounting methods.
start-stop
: use for more accounting information, to send a start-accounting notice at the
beginning of the requested event and a stop-accounting notice at the end.
wait-start
: ensures that the TACACS+ security server acknowledges the start notice before
granting the user's process request.
stop-only
: use for minimal accounting; instructs the TACACS+ server to send a stop record
accounting notice at the end of the requested user process.
tacacs+
: designate the security service. Currently, Dell Networking OS supports only TACACS+.
158
Security