![Alcatel OmniSwitch 6624 Network Configuration Manual Download Page 326](http://html1.mh-extra.com/html/alcatel/omniswitch-6624/omniswitch-6624_network-configuration-manual_2891390326.webp)
LDAP Servers
Managing Authentication Servers
page 17-24
OmniSwitch 6624/6648 Network Configuration Guide
April 2004
Dynamic Logging
Dynamic logging may be performed by an LDAP-enabled directory server if an LDAP server is config-
ured
first
in the list of authentication servers configured through the the
aaa accounting vlan
or
aaa
accounting session
command. Any other servers configured are used for accounting (storing history
records) only. For example:
-> aaa accounting session ldap2 rad1 rad2
In this example, server
ldap2
will be used for dynamic logging, and servers
rad1
and
rad2
will be used
for accounting.
If you specify a RADIUS server first, all of the servers specified will be used for recording history records
(not logging). For example:
-> aaa accounting session rad1 ldap2
In this example, both the
rad1
and
ldap2
servers will be used for history only. Dynamic logging will not
take place on the LDAP server.
Dynamic entries are stored in the LDAP-enabled directory server database from the time the user success-
fully logs in until the user logs out. The entries are removed when the user logs out.
•
Entries are associated with the switch the user is logged into.
•
Each dynamic entry contains information about the user’s connection. The related attribute in the
server is bop-loggedusers.
A specific object class called
alcatelBopSwitchLogging
contains three attributes as follows:
Each switch that is connected to the LDAP-enabled directory server will have a DN starting with bop-
basemac-
xxxxx
, ou=bop-logging. If the organizational unit ou=bop.logging exists somewhere in the tree
under searchbase, logging records are written on the server. See the server manufacturer’s documentation
for more information about setting up the server.
The bop-loggedusers attribute is a formatted string with the following syntax:
loggingMode : accessType ipAddress port macAddress vlanList userName
The fields are defined here:
Attribute
Description
bop-basemac
MAC range, which uniquely identifies the switch
bop-switchname
Host name of the switch.
bop-loggedusers
Current activity records for every user logged
onto the switch identified by bop-basemac.
Field
Possible Values
loggingMode
ASA
x
—for an authenticated user session, where
x
is the num-
ber of the session
AVLAN
—for Authenticated VLAN session in single authority
mode
AVLAN
y
—for Authenticated VLAN session in multiple
authority mode, where
y
is relevant VLAN