If someone logs in to a router and issue a command, this is recorded in a
file. I currently use IOS 12.2 The following commands are configured on the
Cisco router.
<aaa accounting commands 15 acc1 start-stop radius>
<radius-server host x.x.x.x auth-port 1812 acct-port 1813> this
<radius-server key xxxxxxxxx
Foundry has the same config and is working as it should. Below is a snapshot
of the file freeradius has generated for a Foundry.
Mon Sep 16 22:07:56 2002
User-Name = "mathias"
NAS-IP-Address = x.x.x.x
NAS-Port = 1
NAS-Port-Type = Virtual
Calling-Station-Id = "x.x.x.x"
Acct-Status-Type = Alive
Acct-Authentic = RADIUS
Service-Type = NAS-Prompt-User
Acct-Session-Id = "0"
Attr-130482178 = "copy running-config tftp x.x.x.x lon50big.conf"
Acct-Delay-Time = 0
Client-IP-Address = x.x.x.x
Timestamp = 1032210476
Mon Sep 16 22:08:38 2002
User-Name = "mathias"
NAS-IP-Address = x.x.x.x.x
NAS-Port = 1
NAS-Port-Type = Virtual
Calling-Station-Id = "x.x.x.x"
Acct-Status-Type = Alive
Acct-Authentic = RADIUS
Service-Type = NAS-Prompt-User
Acct-Session-Id = "0"
Attr-130482178 = "exit"
Acct-Delay-Time = 0
Client-IP-Address = x.x.x.x
Timestamp = 1032210518
Mathias,
-----Original Message-----
From: Frank Cusack [mailto:[EMAIL PROTECTED]]
Sent: 18 September 2002 05:09
To: [EMAIL PROTECTED]
Subject: Re: Cisco accounting
On Wed, Sep 18, 2002 at 04:05:58AM +0100,
[EMAIL PROTECTED] wrote:
> I recently installed freeradius 0.7.1 on freebsd4.6 and authentication is
> working just fine. But accounting only works on Foundry and not Cisco. I'm
> not sure if anyone has experienced this in the pass. Any help is
> appreciated.
Exactly what kind of accounting are you talking about here? Cisco IOS
(up to 12.1 at least) does not support command accounting via RADIUS.
Other accounting should be supported but I have no further info on it.
/fc
-
List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html
DISCLAIMER
This e-mail is intended only for the use of the addressees named above and
may be confidential. If you are not an addressee you must not read it and
must not use any information contained in nor copy it nor inform any person
other than TeleCity Limited or the addressees of its existence or contents.
If you have received this email and are not a named addressee, please delete
it and notify the TeleCity IT department on 0161 226 7643 or by email at
[EMAIL PROTECTED]
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html