Chapter 27
Configuring Switch Access Using AAA
Table 27-5 Accounting Default Configuration
Feature
Accounting
Accounting events (exec, system, commands, and connect)
Accounting records
Accounting Configuration Guidelines
These guidelines apply when configuring accounting on the switch:
•
•
The amount of DRAM allocated for one accounting event is approximately 500 bytes. The total amount
Note
of DRAM used by accounting will depend on the number of concurrent accountable events occurring in
the system.
Configuring Accounting
These sections describe how to configure RADIUS and TACACS+ accounting on the switch:
•
•
Enabling Accounting
To enable accounting on the switch, perform this task in privileged mode:
Task
Step 1
Enable accounting for connection events.
Step 2
Enable accounting for EXEC mode.
Step 3
Enable accounting for system events.
Step 4
Enable accounting of configuration commands.
Step 5
Enable suppression of information for unknown
users.
78-12647-02
Configure RADIUS and TACACS+ servers before enabling accounting. See the
TACACS+ Servers" section on page 27-17
page
27-23, for more information on server setup.
Configure RADIUS and TACACS+ keys to encrypt protocol packets before enabling accounting.
See the
"Specifying the TACACS+ Key" section on page 27-19
Key" section on page
27-25, for more information on the key setup.
Enabling Accounting, page 27-59
Disabling Accounting, page 27-61
Software Configuration Guide—Catalyst 4000 Family, Catalyst 2948G, Catalyst 2980G, Releases 6.3 and 6.4
Default Value
Disabled
Disabled
Stop-only
or the
"Specifying RADIUS Servers" section on
or the
Command
set accounting connect enable {start-stop |
stop-only} {tacacs+ | radius}
set accounting exec enable {start-stop |
stop-only} {tacacs+ | radius}
set accounting system enable {start-stop |
stop-only} {tacacs+ | radius}
set accounting commands enable {config | all}
{stop-only} tacacs+
set accounting suppress null-username enable
Configuring Accounting
"Specifying
"Specifying the RADIUS
27-59