Users Guide

Table Of Contents
Enable AAA accounting in CONFIGURATION mode.
aaa accounting commands all {console | default} {start-stop | stop-only | none}
[logging] [group tacacs+]
The no version of this command disables AAA accounting.
AAA commands
aaa accounting
Enables AAA accounting.
Syntax
aaa accounting exec commands all {console | default} {start-stop | stop-
only | none} [logging] [group tacacs+]
Parameters
exec Record user authentication events.
commands all Record all user-entered commands. RADIUS accounting does not support this
option.
console Record all user authentication and logins or all user-entered commands in OS10 sessions
on console connections.
default Record all user authentication and logins or all user-entered commands in OS10 sessions
on remote connections; for example, Telnet and SSH.
start-stop Send a start notice when a process begins, and a stop notice when the process
ends.
stop-only Send only a stop notice when a process ends.
none No accounting notices are sent.
logging Logs all accounting notices in syslog.
group tacacs+ Logs all accounting notices on the first reachable TACACS+ server.
Default AAA accounting is disabled.
Command Mode CONFIGURATION
Usage
Information
You can enable the recording of accounting events in both the syslog and on TACACS+ servers.
Supported on the MX9116n and MX5108n switches in Full Switch mode starting in release 10.4.1.0. Also
supported in SmartFabric mode starting in release 10.5.0.1.
The no version of the command disables AAA accounting.
Example
OS10(config)# aaa accounting commands all console start-stop logging
group tacacs+
Supported
Releases
10.4.1.0 or later
aaa authentication login
Configures the AAA authentication method for console, SSH, and Telnet logins.
Syntax
aaa authentication login {console | default} {local | group radius | group
tacacs+}
Parameters
console Configure authentication methods for console logins.
default Configure authentication methods for SSH and Telnet logins.
local Use the local username, password, and role entries configured with the username
password role command.
group radius Use the RADIUS servers configured with the radius-server host command.
group tacacs+ Use the TACACS+ servers configured with the tacacs-server host
command.
Security 1025