Cisco Cisco ASA 5580 Adaptive Security Appliance Leaflet
14-27
思科 ASA 系列命令参考,S 命令
第 14 章 show uauth 至 show xlate 命令
show user-identity user active
指定了用户组关键字时,只显示激活的用户组。当组属于访问组、导入用户组或服务策略组配置
的一部分时,组已激活。
的一部分时,组已激活。
未指定
user-group 关键字和
domain_nickname 时,ASA 显示默认域中具有 user_group_name 的组
的信息。
注
用
disable-user-identity-rule 关键字配置了 user-identity action domain-controller-down 且指定的
域关闭时,或者以
disable-user-identity-rule 关键字配置了 user-identity action ad-agent-down 命
令且
AD 代理已关闭时,所有已登录用户都在用户统计信息中显示为禁用。
注
只有当您为身份防火墙启用用户统计信息扫描或记账时,
ASA 才显示详细的用户统计信息,例
如,指定时间段内接收的数据包数、发送数据包数和丢弃数。请参阅
CLI 配置指南以了解关于配
置身份防火墙的信息。
示例
以下示例展示如何显示身份防火墙的活动用户的相关信息:
ciscoasa# show user-identity user active
Total active users: 30 Total IP addresses: 35
LOCAL: 0 users, 0 IP addresses
cisco.com: 0 users, 0 IP addresses
d1: 0 users, 0 IP addresses
IDFW: 0 users, 0 IP addresses
idfw.com: 0 users, 0 IP addresses
IDFWTEST: 30 users, 35 IP addresses
ciscoasa# show user-identity user active domain CSCO
Total active users: 48020 Total IP addresses:10000
CSCO: 48020 users, 10000 IP addresses
ciscoasa# show user-identity user active domain CSCO list
Total active users: 48020 Total IP addresses: 10000
CSCO: 48020 users, 10000 IP addresses
CSCO\sampleuser1: 20 active conns; idle 0 mins
CSCO\member-1: 20 active conns; idle 5 mins
CSCO\member-2: 20 active conns; idle 20 mins
CSCO\member-3: 3 active conns; idle 101 mins
…
ciscoasa# show user-identity user active list
Total active users: 48032 Total IP addresses: 10000
CSCO\sampleuser1: 20 active conns; idle 0 mins
CSCO\member-1: 20 active conns; idle 6 mins
APAC\sampleuser2: 20 active conns; idle 0 mins
CSCO\member-2: 20 active conns; idle 1 mins
CSCO\member-3: 20 active conns; idle 0 mins
APAC\member-2: 20 active conns; idle 22 mins
CSCO\member-4: 3 active conns; idle 101 mins
…
ciscoasa# show user-identity user active list detail
Total active users: 48032 Total IP addresses: 10010
CSCO: 48020 users, 10000 IP addresses
APAC: 12 users, 10 IP addresses
CSCO\sampleuser1: 20 active conns; idle 0 mins
172.1.1.1: login 360 mins, idle 0 mins, 15 active conns