81
[Device-luser-manage-monitor] authorization-attribute user-role level-1
Configuring command accounting
Command accounting uses the HWTACACS server to record all executed commands to monitor
user behavior on the device.
If command accounting is enabled but command authorization is not, every executed command is
recorded. If both command accounting and command authorization are enabled, only authorized
commands that are executed are recorded.
The command accounting method can be the same as or different from the command authorization
method and user login authorization method.
This section provides only the procedure for configuring command accounting. To make the
command accounting feature take effect, you must configure a command accounting method in ISP
domain view. For more information, see
Security Configuration Guide
.
Configuration procedure
To configure command accounting:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter user line view or
user line class view.
•
Enter user line view:
line
{
first-number1
[
last-number1
] | {
aux
|
console
|
vty
}
first-number2
[
last-number2
] }
•
Enter user line class view:
line class
{
aux
|
console
|
vty
}
A setting in user line view applies only to
the user line. A setting in user line class
view applies to all user lines of the class.
A non-default setting in either view takes
precedence over a default setting in the
other view. A non-default setting in user
line view takes precedence over a
non-default setting in user line class view.
A setting in user line class view does not
take effect for current online users. It
takes effect only for new login users.
3.
Enable scheme
authentication.
authentication-mode
scheme
In non-FIPS mode, authentication is
disabled for console lines and password
authentication is enabled for AUX and
VTY lines by default.
In FIPS mode, scheme authentication is
enabled by default.
In VTY line view, this command is
associated with the
protocol inbound
command. If you specify a non-default
value for one of the two commands, the
other command uses the default setting,
regardless of the setting in VTY line class
view.
Содержание FlexNetwork 10500 Series
Страница 139: ...130 Sysname display version ...