cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
427
Views
0
Helpful
1
Replies

AAA Accounting Report

brijeshpatel
Level 1
Level 1

Hi,

I am using Tacacs for AAA accounting.I have customer network NAT behind a single IP address and hence I am getting report from all customer device showing single IP.Based on the logs I cannot identify on which device the command was executed.I cannot use static NAT that is one to one mapping.I want Accouting report to reflect if not the right IP atleast the correct hostname.Now the AAA is showing the hostname of the NAT router and not the actual device.Any help will be appreciated

1 Reply 1

rochopra
Cisco Employee
Cisco Employee

ACS will always pick global address in case of PAT and there will be no workaround if ACS server is on outside.

Consider another instance of ACS in the customers network

Or

consider sending authentication traffic through Ipsec tunnel to ACS, if security is a concern to the client.

: Rohit

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: