Configuring Accounting Settings On The Tacacs+ Server - Cisco GSS-4492R-K9 Administration Manual

Administration guide
Table of Contents

Advertisement

Chapter 4
Managing GSS User Accounts Through a TACACS+ Server
Note

Configuring Accounting Settings on the TACACS+ Server

OL-10410-01
If you want to assign a view to an authenticated user, configure a custom GUI
view for the user on the primary GSSM GUI. Be sure to use the exact login name
when creating the primary GSSM GUI user account. During the user
authentication process, the GSS makes a correlation with the user name to
determine if there is an associated user view configured on the primary GSSM
GUI for that user. The custom user view is activated when the user accesses the
primary GSSM GUI.
A password will also be required when creating a user account on the primary
GSSM GUI. However, the GUI-specific password is not used during user
authentication from a TACACS+ server. When you configure TACACS+
authentication on the GSS from the CLI, if you choose not to select the local
fallback option for the aaa authentication gui CLI command (see the
"Configuring Authentication Settings on the TACACS+ Server"
that you set the user account GUI-specific password to a random setting. Setting
the password to a random setting helps to maintain the security of the primary
GSSM GUI in the event that TACACS+ authentication fails for a GUI connection.
To configure the accounting service for the Cisco Secure ACS, perform the
following steps:
1.
In the System Configuration section of the Cisco Secure ACS interface, the
Logging Configuration page, click CSV TACACS+ Accounting. The Edit
page appears (see
Configuring a TACACS+ Server for Use with the GSS
Figure
4-9).
Cisco Global Site Selector Administration Guide
section), ensure
4-17

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents