9-3
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 9 Working with Logging and Reports
Special Logging Attributes
•
Network Device Group—The network device group to which the access
device (AAA client) belongs.
•
Filter Information—The result of network access restrictions (NARs)
applied to the user, if any. The message in this field indicates whether all
applicable NARs permitted the user access, all applicable NARs denied the
user access, or more specific information about which NAR denied the user
access. If no NARs apply to the user, this logging attribute notes that no
NARs were applied.
The Filter Information attribute is available for Passed Authentication and
Failed Attempts logs.
•
Device Command Set—The name of the device command set, if any, that
was used to satisfy a command authorization request.
The Device Command Set attribute is available for Failed Attempts logs.
•
Remote Logging Result—Whether a forwarded accounting packet is
successfully processed by a remote logging service. This attribute is useful
for determining which accounting packets, if any, may not have been logged
by a central logging service. It is dependent upon the receipt of an
acknowledgment message from the remote logging service. The
acknowledgment message indicates that the remote logging service properly
processed the accounting packet in the manner that the remote logging
service is configured to do. A value of
Remote-logging-successful
indicates that the remote logging service successfully processed the
accounting packet. A value of
Remote-logging-failed
indicates that the
remote logging service did not process the accounting packet successfully.
Note
Cisco Secure ACS cannot determine how a remote logging service is
configured to process accounting packets that it is forwarded. For
example, if a remote logging service is configured to discard
accounting packets, it discards a forwarded accounting packet and
responds to Cisco Secure ACS with an acknowledgment message,
causing Cisco Secure ACS to write a value of
Remote-logging-successful
in the Remote Logging Result attribute
in the local log that records the account packet.