HP 6120G/XG HP ProCurve Series 6120 Blade Switches Access Security Guide - Page 224
Exec accounting, Commands accounting, RADIUS accounting with IP attribute
View all HP 6120G/XG manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 224 highlights
RADIUS Authentication, Authorization, and Accounting Configuring RADIUS Accounting ■ Exec accounting: Provides records holding the information listed below about login sessions (console, Telnet, and SSH) on the switch: • Acct-Authentic • Acct-Delay-Time • Acct-Session-Id • Acct-Session-Time • Acct-Status-Type • Acct-Terminate-Cause • Calling-Station-Id • MS-RAS-Vendor • NAS-Identifier • NAS-IP-Address • Service-Type • Username ■ System accounting: Provides records containing the information listed below when system events occur on the switch, including system reset, system boot, and enabling or disabling of system accounting. • Acct-Authentic • Acct-Delay-Time • Acct-Session-Id • Acct-Session-Time • Acct-Terminate-Cause • Calling-Station-Id • MS-RAS-Vendor • NAS-Identifier • NAS-IP-Address • Service-Type • Username ■ Commands accounting: Provides records containing information after the execution of a command. • Acct-Session-Id • Acct-Status-Type • Service-Type • Acct-Authentic • User-Name • NAS-IP-Address • NAS-Identifier • NAS-Port-Type • Calling-Station-Id • HP-Command-String • Acct-Delay-Time ■ RADIUS accounting with IP attribute: The RADIUS Attribute 8 (Framed-IP-Address) feature provides the RADIUS server with infor mation about the client's IP address after the client is authenticated. DHCP snooping is queried for the IP address of the client, so DHCP snooping must be enabled for the VLAN of which the client is a member. When the switch begins communications with the RADIUS server it sends the IP address of the client requesting access to the RADIUS server as RADIUS Attribute 8 (Framed-IP-Address) in the RADIUS accounting request. The RADIUS server can use this information to build a map of usernames and addresses. It may take a minute or longer for the switch to learn the IP address and then send the accounting packet with the Framed-IP-Address attribute to the RADIUS server. If the switch does not learn the IP address after a 5-48