01-02-2012 02:05 PM
Hello guys,
I would like to kindly ask if somebody can give me a advice on following situation:
I'm playing with Asa device in version 8.2(5). I setup it with freeradius and mysql. I try do accounting with asa:
My setup:
ASA configuration for accounting:
aaa accounting match ACCOUNTING inside Radius
aaa accounting match ACCOUNTING outside Radius
ASA ACL:
show running-config access-list ACCOUNTING
access-list ACCOUNTING extended permit ip any any
access-list ACCOUNTING extended permit tcp any any
access-list ACCOUNTING extended permit udp any any
access-list ACCOUNTING extended permit icmp any any
I obtaion to mysql log from asa accounting. But my problem is that: I receive data just with start and end session that match the ACL. I don't find better way on how to do it. I want record all vpn user session -> start and end session when user log into vpn. Not just when the user match my interesting traffic ACL.
Thanks for any advice!
Solved! Go to Solution.
01-10-2012 01:27 AM
Hi Veronika,
try this:
tunnel-group
accounting-server-group Radius
To be honest I don't know off the top of my head if this will work without also doing radius authentication - so if you're not doing radius authentication and the above doesn't work, try adding it, i.e.:
tunnel-group
authentication-server-group Radius
hth
Herbert
01-10-2012 01:27 AM
Hi Veronika,
try this:
tunnel-group
accounting-server-group Radius
To be honest I don't know off the top of my head if this will work without also doing radius authentication - so if you're not doing radius authentication and the above doesn't work, try adding it, i.e.:
tunnel-group
authentication-server-group Radius
hth
Herbert
01-18-2012 06:51 AM
Yeah, that's true and thanks for your reply. I found it here: http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a1.html#wp1560638
I am just posting the link if somebody will be interested in same topic. Your answer is correct, first time I was doing some other type of accounting - it was cut-through acct.
Best regards,
Veronika
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: