Configuring TACACS+ Accounting for CLI Commands

You can configure TACACS+ accounting for CLI commands by specifying a privilege level for which commands require accounting. For example, to configure the RUCKUS device to perform TACACS+ accounting for the commands available at the Super User privilege level (that is, all commands on the device), enter the following command.

device(config)# aaa accounting commands 0 default start-stop tacacs+

An Accounting Start packet is sent to the TACACS+ accounting server when a user enters a command, and an Accounting Stop packet is sent when the service provided by the command is completed.

Note: If authorization is enabled and the command requires authorization, authorization is performed before accounting takes place. If authorization fails for the command, no accounting takes place.

The privilege-level parameter can be one of the following:

  • 0: Records commands available at the Super User level (all commands)
  • 4: Records commands available at the Port Configuration level (port-config and read-only commands)
  • 5: Records commands available at the Read Only level (read-only commands)