Avaya ERS 1600 Technical Configuration Manual page 42

Authentication, authorization and accounting (aaa) for ers and es
Hide thumbs Also See for ERS 1600:
Table of Contents

Advertisement

3.2.3 TACACS+ Accounting
TACACS+ accounting enables you to track:
the services accessed by users
the amount of network resources consumed by users
When accounting is enabled, the NAS reports user activity to the TACACS+ server in the form of
accounting records. Each accounting record contains accounting AV pairs. The accounting records are
stored on the security server. The accounting data can then be analyzed for network management and
auditing.
USER login
(Console/Telnet/SSH
)
USER logout
(Console/Telnet/SSH
)
TACACS+ accounting provides information about user CLI terminal sessions within serial, Telnet, or SSH
shells (in other words, from the CLI management interface).
3.2.4 TACACS+ Session
A TACACS+ session is a single authentication sequence, a single authorization exchange, or a single
accounting exchange.
The session concept is important because a session identifier is used as a part of the encryption, and it is
used by both ends to distinguish between packets belonging to multiple sessions.
Multiple sessions may be supported simultaneously and/or consecutively on a single TCP connection if
both the daemon and client support this.
If multiple sessions are not being multiplexed over a single tcp connection, a new connection should be
opened for each TACACS+ session and closed at the end of that session. For accounting and
authorization, this implies just a single pair of packets exchanged over the connection (the request and its
reply). For authentication, a single session may involve an arbitrary number of packets being exchanged.
The session is an operational concept that is maintained between the TACACS+ client and daemon. It
does not necessarily correspond to a given user or user action.
Authentication, Authorization and Accounting (AAA) for ERS and ES
November 2010
Accounting Request
Start
Accounting Reply
Success, error, follow
Accounting Request
more, watchdog
Accounting Reply
TACACS+
Success, error, follow
CLIENT
ACCOUNTING
Accounting Request
Stop
Accounting Reply
Success, error, follow
Technical Configuration Guide
avaya.com
TACACS+
SERVER
Accounting
Service
42

Advertisement

Table of Contents
loading

Table of Contents