Determining Security Configuration

Showing the Authentication Counters

This access server can display the counters for all realms (local, RADIUS, KERBEROS). Any session authenticated by RADIUS attempts to send accounting data to the RADIUS Server. Sessions authenticated by other methods may be configured to send accounting packets to a RADIUS accounting server as well (if one exists).

Reference

See SHOW AUTHENTICATION COUNTERS in the Network Access Server Command Reference for a sample of this display.

Showing the User Port Authorization Profile

The SHOW AUTHORIZATION command shows the user profile being used for the specified port(s).

Example: Showing the User Port Authorization Profile

The following example shows the resulting display for this command for a port that was authenticated:

LOCAL> SHOW PORT 7 AUTHORIZATION

Port 7: user1

Server: DECSERVER1

 

Username: user1@finance_realm

 

 

Access:

LOCAL

Forced CallBack:

DISABLED

Max Connect:

00 08:00:00

DialOut Service:

DIAL14400

Remaining Time:

00 00:33:24

Framed IP Address: 16.22.33.44

Login IP Host:

16.20.22.33

Login LAT Service:

LATSERVICE

Login Service Type:

LAT

Login Port:

15

Authenticated By: 16.129.42.15

Authentication Type:

RADIUS

Login LAT Node:

MONEY

 

 

DialOut Number:

(Any)

 

 

DialBack Number:

1-802-767-8345

 

 

Login LAT Groups:

1,2,5,66-68,133,135,139,172,206,230-250

Permissions:

LAT, TELNET, SLIP, PPP, DIALACK,

 

 

DIALOUT,NONPRIVILEGED

 

Showing Security Counters

The SHOW/LIST/MONITOR SECURITY COUNTERS command displays all port- related security counters. This display is very similar to results from the SHOW PORT AUTHENTICATION COUNT command shown in the previous example.

Example: Showing Security Counters

Local> SHOW PORT 8 SECURITY COUNTERS

Managing Access Server Security 22-31