Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

User log/accounting

This thread has been viewed 7 times
  • 1.  User log/accounting

    Posted Mar 26, 2014 04:19 PM

    Hi,

     

    We want to keep track of users login times, user IDs and the device they login from (may be mac address). We are using dot1x auth on SSID. Dot1x authenticate against our nps server. 

     

    Any ideas to achieve this? Can I get the details from controller and logs it somewhere?



  • 2.  RE: User log/accounting
    Best Answer

    EMPLOYEE
    Posted Mar 26, 2014 04:22 PM

    You would want to turn up RADIUS accounting. You will need some type of SQL server for NPS to store the data.

     

    On the controller side, you would simply enable a RADIUS accounting server group.

     

    Here's a doc from Microsoft on setting it up with NPS:

     

    http://technet.microsoft.com/en-us/library/cc754123.aspx



  • 3.  RE: User log/accounting

    Posted Mar 26, 2014 04:24 PM

    Thanks for your prompt response. I will try that and will get back to you.



  • 4.  RE: User log/accounting

    Posted Mar 26, 2014 04:32 PM

    Where i can define accounting server on controller?



  • 5.  RE: User log/accounting
    Best Answer

    EMPLOYEE
    Posted Mar 26, 2014 04:34 PM

    Inside your AAA profile. You'll probably use the same server group as 802.1X.

     

    radius-accounting-sg.png



  • 6.  RE: User log/accounting

    Posted Mar 26, 2014 04:44 PM

    Completely forgot, sorry. 

    Working on it at the moment.

     

    Thanks



  • 7.  RE: User log/accounting

    Posted Mar 26, 2014 05:22 PM

    Thanks for helping me with this. I have configured it. I am getting user name and time stamp but what I also need is user IP address which I am not getting. We want to log what IP user has at the time of login to track the details. Is it possible?

     

    I only get the IP address of our controller as client.



  • 8.  RE: User log/accounting

    Posted Mar 26, 2014 05:24 PM

    I am sorry spoken too soon. Yes I am getting everything what I need.

    Thanks a bunch