cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
621
Views
0
Helpful
5
Replies

aaa accounting commands levels

akota
Level 1
Level 1

Hello,

I am confused on aaa accounting. If I wish to account all commands and the levels I have configured are say 5 and 15, do I need to include level 0 in my aaa accounting commands?

5 Replies 5

premdeep.banga
Level 1
Level 1

Hello,

By default on IOS devices we have three commands distributed over three privilege levels i.e.,

Level 0

Level 1, and

Level 15.

If you explicitly donot change the privilege level of command(s), then only commands that you require to enter in an IOS device to monitor all commands executed over device is:

aaa accounting commands 0 default start-stop group tacacs+

aaa accounting commands 1 default start-stop group tacacs+

aaa accounting commands 15 default start-stop group tacacs+

I have defined TACACS+ as the as the accounting server, as it jells best for adminstrative purposes i.e. Shell Command authorization

Let me know if this clarifies your doubt :)

Ok, I think I understand. So even though I have created a privilege level 5, if I want to make sure ALL commands are accounted for then I still need to include levels 0 and 1, since accounting for level 5 will only catcht the commands explicitly configured for that level. Is this correct?

You got that right. Bulls eye :)

Great, you solved my problem, thanks!

Please rate it that helped, it encourages me :)

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: