802.1x Accounting
The 802.1x standard defines how users are authorized and authenticated for network access but does not keep
track of network usage. 802.1x accounting is disabled by default. You can enable 802.1x accounting to monitor
this activity on 802.1x-enabled ports:
•
User successfully authenticates.
•
User logs off.
•
Link-down occurs.
•
Re-authentication successfully occurs.
•
Re-authentication fails.
The switch does not log 802.1x accounting information. Instead, it sends this information to the RADIUS
server, which must be configured to log accounting messages.
802.1x Accounting Attribute-Value Pairs
The information sent to the RADIUS server is represented in the form of Attribute-Value (AV) pairs. These
AV pairs provide data for different applications. (For example, a billing application might require information
that is in the Acct-Input-Octets or the Acct-Output-Octets attributes of a RADIUS packet.)
AV pairs are automatically sent by a switch that is configured for 802.1x accounting. Three types of RADIUS
accounting packets are sent by a switch:
•
START
–
sent when a new user session starts
•
INTERIM
–
sent during an existing session for updates
•
STOP
–
sent when a session terminates
You can view the AV pairs that are being sent by the switch by entering the
debug radius accounting
privileged EXEC command. For more information about this command, see the
Cisco IOS Debug Command
Reference, Release 12.4.
This table lists the AV pairs and when they are sent are sent by the switch.
Table 125: Accounting AV Pairs
STOP
INTERIM
START
AV Pair Name
Attribute Number
Always
Always
Always
User-Name
Attribute[1]
Always
Always
Always
NAS-IP-Address
Attribute[4]
Always
Always
Always
NAS-Port
Attribute[5]
Sometimes
Sometimes
Never
Framed-IP-Address
Attribute[8]
Always
Always
Always
Class
Attribute[25]
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
1332
Information About 802.1x Port-Based Authentication
Summary of Contents for Catalyst 2960 Series
Page 96: ......
Page 196: ......
Page 250: ......
Page 292: ......
Page 488: ......
Page 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Page 590: ......
Page 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Page 620: ......
Page 750: ......
Page 1604: ......
Page 1740: ......
Page 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Page 2106: ......
Page 2118: ......
Page 2164: ......