6.1.1 Ensure Accounting Destination is configured

Information

Where external Authentication, Authorization and Accounting services using either RADIUS or TACACS+ are used, accounting data should be sent to at least one AAA server destination.

Rationale:

RADIUS and TACACS+ are centralized Authentication, Authorization and Accounting (AAA) services.

Both protocols provide services to receive and record information about what users and processes on a router are doing.

Where RADIUS or TACACS+ are configured for AAA, at least one accounting RADIUS or TACACS+ server should be configured to record accounting data for the JUNOS device. Generally, it is recommended that more than one server is used to ensure resilience of this vital service.

Solution

Configure one or more RADIUS or TACACS+ servers as Accounting Destinations use the following commands under the [edit system accounting destination] hierarchy; For RADIUS

[edit system accounting destination]
user@host#set radius server <server ip> secret <shared secret>

For TACACS+

[edit system accounting destination]
user@host#set tacplus server <server ip> secret <shared secret>

Default Value:

Accounting is not configured by default.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, 800-53|AU-9(2), 800-53|AU-12, CSCv7|6.2, CSCv7|6.5

Plugin: Juniper

Control ID: a2f12b37b674e7653ba6b3f51de744a72f3cb62db598330ec27b8db2b98ae6f1