Cisco ASA 5505 Configuration Manual page 695

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Chapter 32
Configuring Management Access
To enable accounting of users when they enter the enable command:
Step 1
a.
b.
To enable accounting of users when they access the adaptive security appliance using Telnet, SSH, or
Step 2
the serial console:
a.
b.
Step 3
To configure command accounting:
a.
b.
c.
Click Apply.
Step 4
Viewing the Current Logged-In User
To view the current logged-in user, enter the following command in Tools > Command Line Interface:
show curpriv
See the following sample show curpriv command output. A description of each field follows.
show curpriv
Username : admin
Current privilege level : 15
Current Mode/s : P_PRIV
Table 32-1
Table 32-1
Field
Username
OL-20339-01
Go to Configuration > Device Management > Users/AAA > AAA Access > Accounting, and check
the Require accounting to allow accounting of user activity > Enable check box.
From the Server Group drop-down list, choose a RADIUS or TACACS+ server group name.
Under the Require accounting for the following types of connections area, check the check boxes
for Serial, SSH, and/or Telnet.
For each connection type, from the Server Group drop-down list, choose a RADIUS or TACACS+
server group name.
Under the Require command accounting area, check Enable.
From the Server Group drop-down list, choose a TACACS+ server group name. RADIUS is not
supported.
You can send accounting messages to the TACACS+ accounting server when you enter any
command other than show commands at the CLI.
If you customize the command privilege level using the Command Privilege Setup dialog box (see
the
"Assigning Privilege Levels to Commands and Enabling Authorization" section on page
you can limit which commands the adaptive security appliance accounts for by specifying a
minimum privilege level in the Privilege level drop-down list. The adaptive security appliance does
not account for commands that are below the minimum privilege level.
describes the show curpriv command output.
show curpriv Command Output Description
Description
Username. If you are logged in as the default user, the name is enable_1 (user
EXEC) or enable_15 (privileged EXEC).
Configuring AAA for System Administrators
Cisco ASA 5500 Series Configuration Guide using ASDM
32-17),
32-23

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents