Configuring Accounting
Updating the Server
You can configure the switch to send accounting information to the TACACS+ server. There are two
options:
•
•
Suppressing Accounting
You can configure the system to suppress accounting when an unknown user with no username accesses
the switch by using the set accounting suppress null-username enable command.
RADIUS and TACACS+ accounting are the same, except that RADIUS does not do command
Note
accounting, periodic updates, or allow null-username suppression.
Configuring Accounting
The following sections describe how to configure accounting for both TACACS+ and RADIUS.
Accounting Default Configuration
Table 30-4
Table 30-4 Accounting Default Configuration
Feature
Accounting
Accounting events (EXEC, system, commands, and connect) Disabled
Accounting records
Accounting Configuration Guidelines
This section lists the guidelines for configuring accounting on the switch:
•
•
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2980G Switches Software Configuration Guide
30-50
Newinfo—Sends accounting information to the server only when new accounting information
becomes available.
Periodic—Sends accounting update records at regular intervals. This option can be used to keep
up-to-date connection and session information even if the NAS restarts and loses the initial start
time. You must set a time lapse between periodic updates. Valid intervals are from 1 to
71582 minutes.
shows the default accounting configuration.
Configure RADIUS and TACACS+ servers before enabling accounting. See the
TACACS+ Servers" section on page 30-17
page
30-23, for more information on server setup.
Configure RADIUS and TACACS+ keys to encrypt protocol packets before enabling accounting.
See the
"Specifying the TACACS+ Key" section on page 30-19
Key" section on page
30-25, for more information on the key setup.
Chapter 30
Configuring Switch Access Using AAA
Default
Disabled
Stop-only
or the
"Specifying RADIUS Servers" section on
or the
—
Release 8.1
"Specifying
"Specifying the RADIUS
78-15486-01