RADIUS Authentication, Authorization, and Accounting

Configuring RADIUS Accounting

Note that there is no time span associated with using the system option. It simply causes the switch to transmit whatever accounting data it currently has when one of the above events occurs.

Network: Use Network if you want to collect accounting information on 802.1X port-based-access users connected to the physical ports on the switch to access the network. (See also “Accounting Services” on page 4.)

Commands: When commands authorization is enabled, a record accounting notice is sent after the execution of a command.

Web or MAC: You can also use Web or MAC to collect accounting information.

Determine how you want the switch to send accounting data to a RADIUS server:

Start-Stop:

Send a start record accounting notice at the beginning of the account- ing session and a stop record notice at the end of the session. Both notices include the latest data the switch has collected for the requested accounting type (Network, Exec, Commands, or System).

Do not wait for an acknowledgement.

The system option (page 5-42) ignores start-stopbecause the switch sends the accumulated data only when there is a reboot, reload, or accounting on/off event.

Stop-Only:

Send a stop record accounting notice at the end of the accounting session. The notice includes the latest data the switch has collected for the requested accounting type (Network, Exec, Commands, or System).

Do not wait for an acknowledgment.

The system option (page 5-42) always delivers stop-onlyoperation because the switch sends the accumulated data only when there is a reboot, reload, or accounting on/off event.

Syntax: [no] aaa accounting < exec network system commands > < start-stop stop-only > radius

Configures RADIUS accounting type and how data will be sent to the RADIUS server.

5-43