Welcome to the extraxi blog...
The servers are predominantly used to secure network services such as dial, wireless lan, vpn, firewall and network device management.
Typically these servers just chuck out MBs of raw CSV log data about network activity. What we do is to help collect this data then import and turn it into useable information.
Thursday, 29 November 2007
Negative values in canned reports
After some delving it turned out to be the customers PIX sending garbage values in the TACACS+ "elapsed time" attribute.
The customer is now following this up with Cisco.
Saturday, 24 November 2007
aaa-reports! "Software as a service"
Monday, 5 November 2007
Extraxi Licensing FAQ
- Number of AAA servers you wish to report against
- Number of installed copies you wish to purchase
- Maintenance & support requirements
Its a common mistake to assume if you have 2 AAA servers you need 2 copies of say aaa-reports! as well - you don't. A single copy of aaa-reports! can import logs from 10's of servers.
You only need multiple copies if you want to install on multiple PCs - for example if you wanted a copy in two locations.
Saturday, 3 November 2007
aaa-reports! v2.2.1 released
Thursday, 18 October 2007
Scripting Automation and MS Office
If you create a specific Windows user account for running aaa-reports! automation (most people do) and you have retail MS Office installed on the same PC.... you'll need to login as this user and start an Office app (eg Word) at least ONCE. When you do this Office will spot its a new user and prompt you to confirm your name an initials.
Now, when aaa-reports! automation kicks in Office will not throw a spanner in the works by asking for user details.
Otherwise an unattended session is left waiting for user input and you'll think aaa-reports! is broken. Thank you Microsoft!
Wednesday, 17 October 2007
aaa-reports! v2.2.1
Enhancements include
- Multi-Database feature enhanced to allow database “cloning”. Cloning allows the creation of a new database by copying any existing database and provides a simple mechanism to quickly create pre-configured blank databases or copy existing populated databases for diagnostic work or as point-in-time snapshots.
- User List import (for inactive user reports). It is now possible to populate the User List from an ACS Dump/CAB File. Where users have access to the Dump/CAB file this can be imported instead of creating and importing a separate CSV file with User List data.
- New Data Purge facility with much improved filtering and selection options to make it easier to identify and purge specific log data.
- Improved processing of ACS logs to find and handle known problematic issues with log content.
- Support for very long filenames (previously 64 characters) to offer more flexibility when processing logs with CSVsync and/or CSVsplit and adding descriptive suffixes and AAA Server names to create meaningful filenames.
- Recognition of logs with underscores in place of spaces in their filenames. Some systems appear to automatically insert underscores into filenames when downloading logs from ACS, e.g. “Administration Audit 2007-10-10.csv” becomes “Administration_Audit_2007-10-10.csv”. Previously filenames with underscores were not recognised as valid log files.
- Improved detection and warning when importing logs that have a different date format to the MDY or DMY setting in Options. Specifying the wrong date format will result in log dates being misinterpreted and have adverse affects on the integrity of reports.
Extended handling of common issues with log content that can otherwise prevent logs being parsed correctly. - Improved regional support for the Log Import process running in Locales where the comma character “ , ‘” is not used as the Field Separator character. Users in most affected regions no longer have to change to a compatible locale prior to importing log files.
Tuesday, 16 October 2007
Support for ACS Express v5
A version of aaa-reports! with ACS v5.0 support is planned to coincide with the full feature version of ACS shipping in late 2008.
Friday, 12 October 2007
What Can Extraxi Get From The ACS Database?
In v2.0 we added the csutil "dump.txt" and also included account expiry, password aging, user defined fields (eg Real Name, Description etc) and a whole lot more.
In v2.1 we started to look at TACACS+ Device Admin (TDA) policy to pull in Shared Device Command Sets (DCS) for Shell and PIX, IP based Network Access Restrictions (Group & Shared), Network Device Group (NDG) memberships. Finally aaa-reports! is able to look into each ACS group to pull in the Shell & PIX service authorizations:
- Service enabled (y/n)
- Service attributes (returned after authentication)
- Group level access restrictions
- Shared access restrictions
- Group level shell/pix command authorisations
- Shared shell/pix command authorisations (via NDG->DCS mappings)
With all this data imported we can offer reports to both document the config (eg our group/user detail report that has layout similar to the ACS UI) and explore the config (eg who has access to what devices AND what commands can they execute. Also, the Query Builder can see the same data too - so you can create custom reports about the users in the ACS db too!
Cool huh?
Of course, the next question is how to get the data OUT of ACS and then IN to aaa-reports!
If you have ACS v4.x on either software or appliances its easy. You just create a support "package.cab" using either the command line cssupport.exe (s/w version) or the Support admin page (appliance version). Make sure you tick the check boxes to include the user & group db + config.
If you have ACS v3.x then unfortunately the appliance is not supported. On the s/w version we have a script you can download to suck the data out - available on our download page.
Once you have a .cab file (from either of the methods above) you just click on Import ACS Database on the aaa-reports Import page.
Thursday, 11 October 2007
Minimum Server Spec for aaa-reports!
Here is Microsoft's guide to the hardware requirements for Server 2003. The R2 datacenter reqs probably make the most sense.
BTW the same goes for csvsync and csvsplit too.