39-53
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 39 Configuring the Switch Access Using AAA
Understanding How Accounting Works
•
System accounting—Provides information on the system events that are not related to users
(includes system reset, system boot, and user configuration of accounting).
•
Command accounting—Sends a record for each command that is issued by the user. This feature
permits the audit trail information to be gathered.
Specifying When to Create Accounting Records
You configure the switch to gather accounting information to create records. When you configure
accounting (using the
set accounting commands
), the switch can generate two types of records:
•
Start records—Include partial information of the event (when the event started, type of service, and
traffic statistics).
•
Stop records—Include complete information of the event (when the event started, its duration, type
of service, and traffic statistics).
The accounting records are created and sent to the server at two events:
•
Start-stop—Records are sent at both the start and stop of an action if the action has duration. If the
NAS fails to send the accounting record at the start of the action, it still allows you to proceed with
the action.
•
Stop-only—Records are sent only at the termination of the event. Commands are assumed to have
zero duration, so only stop records are generated for command accounting. No users are associated
with system events; therefore, the
start-stop
option in the
set accounting system
command is
ignored for system events.
Note
The stop records include complete information of the event (when the event started, its
duration, and traffic statistics). However, you might want redundancy and may monitor both
the start and stop records of the events occurring on the NAS.
Specifying RADIUS Servers
To specify one or more RADIUS servers, perform this task in privileged mode:
Task
Command
Step 1
Specify the IP address of up to three RADIUS
servers. Specify the primary server using the
primary
keyword. Optionally, specify the
destination UDP port to use on the server.
set radius server
ip_addr
[
acct-port
port
]
[
primary
]
Step 2
Verify the RADIUS server configuration.
show radius