Configuring Command Accounting; Configuration Procedure - HPE FlexFabric 5940 Series Configuration Manual

Fundamentals configuration guide
Hide thumbs Also See for FlexFabric 5940 Series:
Table of Contents

Advertisement

[Device-luser-manage-monitor] authorization-attribute user-role level-1

Configuring command accounting

Command accounting uses the HWTACACS server to record all executed commands to monitor
user behavior on the device.
If command accounting is enabled but command authorization is not, every executed command is
recorded. If both command accounting and command authorization are enabled, only authorized
commands that are executed are recorded.
The command accounting method can be the same as or different from the command authorization
method and user login authorization method.
This section provides only the procedure for configuring command accounting. To make the
command accounting feature take effect, you must configure a command accounting method in ISP
domain view. For more information, see Security Configuration Guide.

Configuration procedure

To configure command accounting:
Step
Enter system view.
1.
Enter user line view or
2.
user line class view.
Enable scheme
3.
authentication.
Command
system-view
Enter user line view:
line { first-number1
[ last-number1 ] | { aux |
vty } first-number2
[ last-number2 ] }
Enter user line class view:
line class { aux | vty }
authentication-mode scheme
74
Remarks
N/A
A setting in user line view applies only to
the user line. A setting in user line class
view applies to all user lines of the class.
A non-default setting in either view takes
precedence over a default setting in the
other view. A non-default setting in user
line view takes precedence over a
non-default setting in user line class view.
A setting in user line class view does not
take effect for current online users. It
takes effect only for new login users.
In non-FIPS mode, authentication is
disabled for AUX lines, and password
authentication is enabled for VTY lines by
default.
In FIPS mode, scheme authentication is
enabled by default.
In VTY line view, this command is
associated with the protocol inbound
command. If you specify a non-default
value for one of the two commands, the
other command uses the default setting,
regardless of the setting in VTY line class
view.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Flexfabric 5950 series

Table of Contents