Lab 12.2.4: AAA Accounting

Objectives:

  • Add AAA local Accounting to a NAS device.

Scenario:

The Denver office needs a record of what commands are being issued on the router and what users are using the PPP modem dial-in. You will setup AAA Accounting on this router and test each user account.

Notes: 

Lab Tasks:

  1. Log into the Denver office router and enter global configuration mode.
  2. On the router, start configuring AAA Accounting. The commands to configure AAA Accounting are:

AAA_Router(config)# aaa accounting exec default start-stop group tacacs+
AAA_Router(config)# aaa accounting commands 15 default start-stop group tacacs+
AAA_Router(config)# aaa accounting network default start-stop group tacacs+
AAA_Router(config)# aaa accounting connection default start-stop group tacacs+
AAA_Router(config)# aaa accounting system default start-stop group tacacs+


Below is a brief description of each of the above commands. 

AAA This a AAA command
Accounting  This only applies to accounting
Exec  This only applies to exec commands on the Router
Commands 15 This only applies to privilege level 15
Network  This lists network services like PPP
Connection  This only applies to outbound telnet sessions
System  This lists system events
Start-Stop List both Start and Stop records
Default  This is the default method
Group  Prepare to use a group of “Servers”
TACACS+ This is the type of servers, not RADIUS
  1. The next step is to test the accounting of commands. On the AAA_Router issue the following commands from the console:

AAA_Router# debug aaa accounting

  1. From a remote workstation telnet to the AAA_Router. You should see a prompt like the one below:

User Access Verification

Username:

Login with the Username of superstar and the Password of ciscorocks. Issue a few commands and record the debugging output below: