It all started with a request from one of our application administrators that seemed pretty straightforward. They wanted detailed insights for one SSID they planned to possibly rollout on our ships specifically; they needed to track when users connected or disconnected and identify which Access Points (APs) and SSIDs were in use. My initial thought was to direct them toward Syslog. However, Syslog’s verbosity quickly became apparent; it would inundate their logs with data, turning their simple request into a daunting task of parsing and analysis. Clearly, it was far from ideal.
The conversation took an unexpected turn when the application administrator suggested an alternative I hadn’t considered for this context: AAA Accounting. My experience with AAA (Authentication, Authorization, and Accounting) had always been in tandem with Tacacs or Radius—never had I seen AAA Accounting used in isolation, especially not on a WLAN configured with Pre-shared Key (PSK) authentication. Skeptical, I assumed this approach wouldn’t work.
Driven by a blend of skepticism and intrigue, I tweaked some configurations on our Cisco Wireless LAN Controller (WLC) settings to accommodate this unconventional use case. The result? A revelation. Contrary to my initial doubts, the adjustments provided the application administrator with the information they sought. This was not just about solving a technical problem; it was a learning curve that shattered my preconceptions about the capabilities and flexibility of AAA Accounting.