1.1.8 Set 'aaa accounting connection'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Provides information about all outbound connections made from the network access server.

Rationale:

Authentication, authorization and accounting (AAA) systems provide an authoritative source for managing and monitoring access for devices. Centralizing control improves consistency of access control, the services that may be accessed once authenticated and accountability by tracking services accessed. Additionally, centralizing access control simplifies and reduces administrative costs of account provisioning and de-provisioning, especially when managing a large number of devices. AAA Accounting provides a management and audit trail for user and administrative sessions through RADIUS and TACACS+.

Solution

Configure AAA accounting for connections.

hostname(config)#aaa accounting connection {default | list-name | guarantee-first}
{start-stop | stop-only | none} {radius | group group-name}

Impact:

Implementing aaa accounting connection creates accounting records about connections from the network access server. Organizations should regular monitor these connection records for exceptions, remediate issues, and report findings regularly.

Default Value:

AAA accounting is not enabled.

References:

http://www.cisco.com/en/US/docs/ios-xml/ios/security/a1/sec-cr-a1.html#GUID-0520BCEF-89FB-4505-A5DF-D7F1389F1BBA

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12(1), CSCv6|16.9

Plugin: Cisco

Control ID: 70464abea65b64c60ab38ef1c3165b787320159df6e14d42e2401896c3c90062