Q14Network Access Device Administration
A user reports that RADIUS accounting packets are not arriving at the Cisco ISE server. Which command is missing from the switch configuration?
← → navigate · a answer
Community votes
Discussion · 21
C 5
Selected Answer: C
The right answer is aaa accounting network default start-stop group radius.
The command aaa accounting network default start-stop group radius turns on RADIUS accounting for all network activity on the switch. That covers both inbound and outbound traffic. The start-stop keyword tells the switch to send a RADIUS accounting packet at the start and at the end of each network activity. The group radius keyword tells the switch to send the RADIUS accounting packets to the RADIUS server configured in the radius-server command.
4
CORRECT IS C
Cause Beginning from Cisco IOS version 15.2(1)E / XE 3.5.0E , the VSA commands are enabled by default. To disbale VSA, the “no” option must be used.
Correct answer is the command in answer C
3
Sorry changing answer to C. A google search of the other command showed that it does exist:
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9200/software/release/16-10/configuration_guide/sec/b_1610_sec_9200_cg/configuring_accounting.html
aaa accounting network default start-stop group loginrad (where loginrad is the name of group of radius servers). Correct answer is C
C 3
Selected Answer: C
radius-server vsa send accounting - > Lets the gateway recognize and use accounting VSAs as defined by RADIUS attribute 26.
aaa accounting network default start-stop group radius - > Enables accounting for all network-related service requests and sets the default method to use for all start-stop accounting services.
3
guys! Watch out! The commands related to the network function are needed for this purpose only:
Accounting method lists are specific to the type of accounting being requested. AAA supports six different types of accounting:
Network--Provides information for all PPP, SLIP, or ARAP sessions, including packet and byte counts.
2
Correct answer is C.
B 2
Selected Answer: B
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_troubleshooting.html#wp1050265
RADIUS Accounting Packets (Attributes) Not Coming from Switch
Possible Causes
The Cisco ISE network enforcement device (switch) is missing the radius-server vsa send accounting command.
2
C. aaa accounting network default start-stop group radius
2
For me in this case is B:
You can set the device to send Cisco vendor-specific attributes (VSAs) to the RADIUS server.
Before VSAs can be sent in the accounting records you must configure this command:
radius-server vsa send accounting
Here they are asking about the switch that has to send these packets.
BTW in every reference guide the configuration provided by Cisco is this:
You must configure the RADIUS server to perform accounting tasks.
Router# configure terminal
Router(config)# aaa new-model
Router(config)# radius-server host 172.20.39.46 auth-port 1812 acct-port 1813 key rad123
Router(config)# aaa accounting dot1x default start-stop group radius
Router(config)# aaa accounting system default start-stop group radius
Router(config)# end
Router#
2
Correct is B - "aaa accounting dot1x...", not "accounting network"
802.1X accounting config:
Switch(config)# aaa new-model
Switch(config)# aaa accounting dot1x default start-stop group radius
Switch(config)# radius-server vsa send accounting
B 1
Selected Answer: B
Picking B because the proper command for enabling accounting on switch is as below:
aaa accounting system default start-stop group radius
aaa accounting dot1x default start-stop group radius
The answers dont show any such command. While the VSA attributes are sent by default in newer OS versions, B still seems like a more valid answer than the others
1
so if i have a switch OS does not sent VSA attributes by default which i have to enable it should the answer be B?
C 1
Selected Answer: C
I would choose C too, refer to the link below explaining that B is not serving exactly the purpose mentioned here.
https://www.cisco.com/c/en/us/td/docs/ios/voice/cdr/developer/manual/cdrdev/cdradius.html
C 1
Selected Answer: C
aaa accounting network default start-stop group radius
1
I go with B to iceise provided a very useful link:
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_troubleshooting.html#wp1050265
he Cisco ISE network enforcement device (switch) is missing the radius-server vsa send accounting command.
1
BTW THE COMMAND aaa accounting network deafult start-stop group radius EXISTS TRY IT!
Link for answer:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/15-sy/sec-usr-8021x-15-sy-book/sec-ieee-802x-rad-account.pdf
Link for provided accounting configuration cisco:
https://www.cisco.com/en/US/docs/ios-xml/ios/sec_usr_8021x/configuration/15-2mt/sec-ieee-802x-rad-account.html
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3850/sec-user-8021x-xe-3se-3850-book/sec-ieee-802x-rad-account.pdf
1
The AAA server verifies whether a PPP session by the client is allowed. In addition, PPP options can be requested by the client: callback, compression, IP address, and so on. These options have to be configured on the user profile on the AAA server. In addition, for a specific client, the AAA profile can include idle-timeout, access-list and other per-user attributes which will be downloaded by the Cisco IOS software and applied for this client.
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/xe-3s/sec-usr-aaa-xe-3s-book/sec-cfg-accountg.html
https://www.certificationkits.com/cisco-certification/ccna-security-certification-topics/ccna-security-aaa-on-cisco-routers/ccna-security-configuring-aaa/
For me the valid option is still B if the documentation provided by Cisco is right the aaa accounting network provide only informations related to PPP, SLIP, or ARAP sessions.
1
Should be "aaa accounting dot1x...", not "accounting network".
Correct is C - "radius-server vsa send accounting"
1
Sorry, I meant B - "radius-server vsa send accounting"
1
Correct Answer is C. Don't listen to anyone who starts with "I think I will go with,..." that means they are guessing. Just a tip ;)
C 1
Selected Answer: C
Correct answer is C
Not sure why some of you picked B ( it's a default command and won't work if aaa accounting is not even activated ).
aaa accounting network will activate accounting
Config guide for 9300 17.6 ( fairly new IOS XE ) go to step 3
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-6/configuration_guide/sec/b_176_sec_9300_cg/configuring_radius.html