AAA Accounting with WLSM

I have a customer with Cat6500 and WLSM running WDS. The APs and dot1x clients can authenticate with the ACS server. However, we cannot get any accounting information. We have tried configuring the WLSM with the following commands:
aaa accounting network default start-stop group ClientDevices
aaa accounting resource default start-stop group ClientDevices
aaa accounting auth-proxy default start-stop group ClientDevices
but none of these work. Devices are running the following code:
Cat6500/Sup720 - 12.2(18)SXD5
WLSM - 12.3(4)JA
1200APs - 12.3(7)JA2
Any assistance would be greatly appreciated.
Tracey

I set this up in the lab using an AP as the WDS and got the same problem; authentication logs but no accounting logs. Here are excerpts from the configs:
AP:
no aaa new-model
dot11 ssid eduroam
vlan 1800
authentication open eap eap_methods
authentication network-eap eap_methods
authentication key-management wpa
mobility network-id 180
wlccp ap username xxxx password xxxx
wlccp ap wds ip address 172.30.2.174
WLSM:
aaa new-model
aaa group server radius AccessPoints
server 130.x.x.139 auth-port 1645 acct-port 1646
aaa group server radius ClientDevices
server 130.x.x.32 auth-port 1812 acct-port 1813
aaa authentication login Leap-devices group AccessPoints
aaa authentication login client-authentication group ClientDevices
aaa session-id common
radius-server host 130.x.x.32 auth-port 1812 acct-port 1813 key 7
radius-server host 130.209.13.139 auth-port 1645 acct-port 1646 key 7
wlccp authentication-server infrastructure Leap-devices
wlccp authentication-server client any client-authentication
wlccp wds interface Ethernet0/0.2
wlccp wnm ip address 172.20.18.58
The WLSM currently does not have any aaa accounting config. The following commands have been tried with no success:
aaa accounting network default start-stop group ClientDevices
aaa accounting resource default start-stop group ClientDevices
aaa accounting auth-proxy default start-stop group ClientDevices
Thanks for your help.
Tracey

Similar Messages

  • FWSM 2.3(4) with AAA accounting

    i have FWSM version 2.3(4) , but i can't find a command to enable AAA accounting to
    remote TACACS server , does 2.3(4) support AAA accounting or not , and what is the minimum version that support AAA accounting

    FWSM 2.3(4) does support aaa accounting.  To define a TACACS server, you can use the 'aaa-server' command.  Please see the command reference below for more details:
    aaa accounting:
    http://www.cisco.com/en/US/docs/security/fwsm/fwsm23/command/reference/ab.html#wp1073208
    aaa-server:
    http://www.cisco.com/en/US/docs/security/fwsm/fwsm23/command/reference/ab.html#wp1070086

  • Missing Tunnel-Client-Endpoint attribute in AAA accounting from 2821

    I am trying to optimise the detailed accounting records for VPN client connections on our system
    but have noticed I am not receiving Tunnel-Client-Endpoint (attribute 66) in tunnel start accounting records from the router.
    The VPN functionality works fine, this is just an accounting issue.
    All other accouting attributes I need are received fine (times, username, VPN Framed IP, NAS identifier).
    The system details are:
    VPN server : Cisco 2821 with IOS 12.4(11)XW3
    Tunnel type: VPDN, PPTP, MPPE 128bit, MS-CHAPv2
    Accouting RADIUS: Microsoft Windows Server 2008 R2 NPS
    I have used the same setup many times previously on various 2801, 2811, and 2911 platfroms with no issue (across v12 and v15 IOS).
    Sending attribute 66 "Tunnel-Client-Endpoint" appeared to be standard for any tunnel setup, no config was require to send it.
    Does anyone know a reason why this fairly standard tunnel RADIUS attribute is not being sent to us from the router in this case?
    Example debug of tunnel start accounting message, showing that attribute 66 is not included in info sent to accouting server:
    Jun 25 2013 14:55:13.591 AEST: RADIUS/ENCODE(0000061A):Orig. component type = VPDN
    Jun 25 2013 14:55:13.595 AEST: RADIUS(0000061A): Config NAS IP: 0.0.0.0
    Jun 25 2013 14:55:13.595 AEST: RADIUS(0000061A): sending
    Jun 25 2013 14:55:13.595 AEST: RADIUS/ENCODE: Best Local IP-Address 192.168.xxx.xxx for Radius-Server 192.168.xxx.xxx
    Jun 25 2013 14:55:13.595 AEST: RADIUS(0000061A): Send Accounting-Request to 192.168.xxx.xxx:1646 id 1646/220, len 184
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  authenticator D7 DD 05 D9 72 FC 72 9C - 02 E0 6A FD D1 AC DB 06
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Acct-Session-Id     [44]  10  "00000642"
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Tunnel-Medium-Type  [65]  6   00:IPv4                   [1]
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Tunnel-Assignment-Id[82]  3   "1"
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Tunnel-Server-Auth-I[91]  14  "********"
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Acct-Tunnel-Connecti[68]  4   "44"
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Framed-Protocol     [7]   6   PPP                       [1]
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Framed-IP-Address   [8]   6   192.168.xxx.xxx          
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  User-Name           [1]   10  "*********"
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Acct-Authentic      [45]  6  
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Acct-Status-Type    [40]  6   Start                     [1]
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  NAS-Port-Type       [61]  6   Virtual                   [5]
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  NAS-Port            [5]   6   426                      
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  NAS-Port-Id         [87]  17  "Uniq-Sess-ID426"
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Class               [25]  46 
    Jun 25 2013 14:55:13.595 AEST: RADIUS:   69 89 04 FA 00 00 01 37 00 01 02 00 C0 A8 AC 01  [i??????7????????]
    Jun 25 2013 14:55:13.595 AEST: RADIUS:   00 00 00 00 00 00 00 00 00 00 00 00 01 CE 6E 22  [??????????????n"]
    Jun 25 2013 14:55:13.595 AEST: RADIUS:   2F A7 37 14 00 00 00 00 00 00 00 29              [/?7????????)]
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Service-Type        [6]   6   Framed                    [2]
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  NAS-IP-Address      [4]   6   192.168.xxx.xxx          
    Jun 25 2013 14:55:13.595 AEST: RADIUS:  Acct-Delay-Time     [41]  6   0                        
    Jun 25 2013 14:55:13.691 AEST: RADIUS: Received from id 1646/220 192.168.xxx.xxx:1646, Accounting-response, len 20
    Jun 25 2013 14:55:13.691 AEST: RADIUS:  authenticator E8 EC 1C 30 D2 01 8E D8 - 15 10 09 5F 37 95 D4 25
    Important config
    aaa new-model
    aaa authentication login default local group radius
    aaa authentication ppp default local group radius
    aaa authorization exec default local group radius
    aaa authorization network default local group radius
    aaa accounting delay-start
    aaa accounting session-duration ntp-adjusted
    aaa accounting exec default start-stop group radius
    aaa accounting network default start-stop group radius
    aaa session-id common
    vpdn enable
    vpdn-group 1
    ! Default PPTP VPDN group
    accept-dialin
      protocol pptp
      virtual-template 1
    interface Virtual-Template1
    ip unnumbered Dialer1
    ip nat inside
    ip virtual-reassembly
    peer default ip address pool VPN
    no keepalive
    ppp encrypt mppe 128
    ppp authentication ms-chap-v2
    ip local pool VPN 192.168.xxx.xxx 192.168.xxx.xxx
    radius-server host 192.168.xxx.xxx auth-port 1645 acct-port 1646 key 7 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

    Larry,
    1) Please set up enable authentication to get the actual user name,
    aaa authentication enable console tacacs-auth LOCAL
    On ACS user setup you need to set up tacacs+ enable password.
    3) Since you have defined both server for authentication and accounting ie 219 and 218 it is sending accounting to 218, as it is also defined as accounting server and firewall it active.
    Use only
    aaa-server tacacs-auth (dept-outside) host 10.1.26.218 key tacacs-secret
    aaa-server tacacs-acct (dept-outside) host 10.1.26.219 key tacacs-secret
    Now auth should go to 218 and acc to 219.
    Regards,
    ~JG
    Do rate helpful posts

  • Missing aaa accounting commands

    Hi,
    I might be being REALLY STUPID, but I am trying to config a 12.3 IOS router to send command accounting records to an ACS 3.3 server via RADIUS.
    When a input the 'aaa accounting commands 15 default group radius' command, it is accepted by the router, but show the config, and its not there. This is the same for all command levels. This router is logging VoIP accounting records too, to the same RADIUS box, without problems.
    Have I missed somthing about setting up AAA ?
    Grateful for any help!
    Thanks
    Pete Moore

    Even if IOS did support it, the format of any RADIUS cmd accounting will be inferior for a couple of reasons
    1) The ACS TACACS+ reports are totally geared up for this with pre-defined columns for each T+ attrbute.
    2) ACS has a dedicated cmd accounting report which splits out cmds from sessions
    3) To package in RADIUS, IOS would have to create many cisco-av-pair VSA instances. In the RADIUS accounting logs these will all be compressed into a single column of the format
    "attr1=value1;attr2=value2;..."
    Depending on what you want to do with the data this format is quite restrictive.
    My advice is to enable TACACS+
    Darran

  • AAA Accounting Commands

    I have just started logging AAA accounting commands on my ACS. I am able to view all commands entered without any trouble. I would like to NOT see commands entered from one particular source. I have an IDS device that shuns to a router. The shunning frequency causes the ACS TACACS+ admin report to become full and unusable. Any ideas on how to exempt commands issued by the IDS?
    I have considered setting up multiple vty line configurations. Set up a vty 0 0 and vty 1 4. Configure the vty 0 0 to use something other than the 'default' AAA group. This, of course, assumes that the IDS will always use vty 0 and everyone else will use vty 1 - 4.
    Thanks, Rick

    Give extraxi aaa-reports! a try (free trial version available)
    We offer loads of great canned reports for device admin.. and more importantly you can filter out stuff you dont want during import.
    Once the CSVs are imported we also have a visual query builder for drilling down into your data - with the results exportable to word/excel/html etc.
    Our csvsync utility can also harvest CSV logs from any number of ACS servers of any version and type (sw & appliance)
    We are a Cisco Technology Partner and aaa-reports! is tested "Cisco Compatible"
    Darran

  • AAA Accounting 'wait-start' option

    I am configuring aaa accounting on a Catalyst 3750 running 12.2(25)SEE, but not have the wait-start option; I only have start-stop and stop-only. So I go to univercd and the wait-start option is in the IOS documentation for 12.0 and prior, but does not show up in documentation for 12.1 and beyond. I cannot find any evidence, however, that the option was removed in any documentation that I have found. So I use start-stop and continue configuring on other devices. Then, I get to a Cisco 2621 router running 12.2(5d), and it does have the wait-start option. Any ideas why it would be available on one and not the other? Is it a router/switch thing? Also, any idea why it disappears from the IOS documentation at version 12.1 and up, even though it shows as an option on a router with 12.2? Thanks.

    As I understood it, each device group runs their own source train of IOS and it can all get a bit messy.
    for example multiple implementations of 802.1x across the various device types.
    A difference between routers and switches is not suprising to an old ex-cisco hack.

  • WLC8510 AAA Accounting Record

    Dear All,      
    I listed an AAA accounting record from my radius server with WLC8510 after I finished a session with downloaded a 100MB file.
    1.) The Acct-Output-Octets > Input-Octets mean the Octets direction is from Controller to Client because I download a 100mb file, in general should be input > outpu, but in cisco WLC, it is inverted, is it correct?
    2) The packet number of input and output is similar, that is different with other brands when I perform the same testing.
    NAS-Identifier = "WLC8510"
            Airespace-WLAN-Id = 124
            Acct-Session-Id = "52a91c23/00:1c:bf:78:2b:21/1575117"
            NAS-Port-Type = Wireless-IEEE-802-11
            Acct-Authentic = Remote
            Tunnel-Type = 0:VLAN
            Tunnel-Medium-Type = 0:802
            Tunnel-Private-Group-ID = 30
            Event-Timestamp = 1386814675
            Acct-Status-Type = Stop
            Acct-Input-Octets = 3773718
            Acct-Input-Gigawords = 0
            Acct-Output-Octets = 98257335
            Acct-Output-Gigawords = 0
            Acct-Input-Packets = 64838
            Acct-Output-Packets = 64886
    <omitted>
    Thanks.
    Mic

    Check the following services are working:
    CSAdmin
    CSauth
    CSDBsync
    CSlog
    CSmon
    cSradius
    CSTacacs

  • 3640 RAS aaa accounting on IAS Server

    Hi gentlemen,
    I have configured aaa accounting on Cisco 3640 RAS and I need collect the aaa remote user time connections (start and end time connections) for time management cost.
    Accounting information received on IAS seems to be only from start remote connection and never to stop connection.
    I don't know if the problem is on 3640 configuration or on IAS configuration, but I would undertood if my configuration is correct.
    I send RAS config file to you.
    Many Thank in advance,
    Luca

    Luca
    I have looked at the config that you posted and I believe that I see an issue. You have configured accounting for DIALER with this method list:
    aaa accounting network DIALER start-stop group radius
    I would expect to see the method list DIALER accounting referenced under interfaces Serial1/0:15, interface Virtual-Template1, and interface Group-Async10. I suggest that you add:
    ppp accounting DIALER
    under these interfaces and let us know if it helps.
    HTH
    Rick

  • Aaa accounting records

    I have asa5510 with aaa accounting configured to microsoft IAS radius without authentication, the output is so confusing more that 40 columns
    is there a way to know the records, at least the essential ones; session-time, bytes-in, bytes-out
    thanks
    Elie

    thanks JG
    there are 2 output options in IAS, DB format and IAS; the DB format does not show the IP addresses.
    the IAS is like below
    192.168.200.1,unknown,01/13/2008,00:00:06,IAS,ISA,5,0,14,193.227.177.130,16,53,40,1,44,10337B5E,4,192.168.200.1,4108,192.168.200.1,4116,9,4128,ASA5510,4154,ASA,5000,ip:source-port=1034,5000,ip:destination-port=53,5000,ip:source-ip=192.168.200.254,5000,ip:destination-ip=193.227.177.130,4136,4,4142,0
    192.168.200.1,unknown,01/13/2008,00:00:06,IAS,ISA,5,0,14,193.227.177.130,16,53,40,2,42,270,43,35,44,10337B5E,46,0,49,0,4,192.168.200.1,4108,192.168.200.1,4116,9,4128,ASA5510,4154,ASA,5000,ip:source-port=1034,5000,ip:destination-port=53,5000,ip:source-ip=192.168.200.254,5000,ip:destination-ip=193.227.177.130,4136,4,4142,0
    192.168.200.1,unknown,01/13/2008,00:00:26,IAS,ISA,5,0,14,192.168.1.252,16,1745,40,1,44,1A38FC26,4,192.168.200.1,4108,192.168.200.1,4116,9,4128,ASA5510,4154,ASA,5000,ip:source-port=4880,5000,ip:destination-port=1745,5000,ip:source-ip=192.168.200.53,5000,ip:destination-ip=192.168.1.252,4136,4,4142,0
    192.168.200.1,unknown,01/13/2008,00:00:56,IAS,ISA,5,0,14,192.168.1.252,16,1745,40,2,42,0,43,0,44,1A38FC26,46,31,49,0,4,192.168.200.1,4108,192.168.200.1,4116,9,4128,ASA5510,4154,ASA,5000,ip:source-port=4880,5000,ip:destination-port=1745,5000,ip:source-ip=192.168.200.53,5000,ip:destination-ip=192.168.1.252,4136,4,4142,0

  • AAA accounting of Lan-to-Lan VPN connections on a 3005 Concentrator

    Hello all,
    I am trying to do AAA accounting for the Lan-to-Lan connections on a 3005 VPN concentrator. It does not seem to work. For incoming VPN client connections, it's working ok, I see the 3005 sending accounting data to our radius server. But nothig is sent for Lan-to-Lan connections.
    Any ideas ? Is this not supported on the 3005 ?
    Thanks,
    Stefan

    Ok, I have updated the image and now I can access all the SNMP info that was not there before. As before, no AAA data is sent for Lan-to-Lan connections and you only have access to current connection info via SNMP. So no historical data. But still, I can make a script that posts on a webpage the current connections, so people with no access to the concentrator can see it.
    I see something weird tho, the snmpwalk is very slow. If I try to walk the interfaces.ifTable for example, it's very slow, one line every second. Must be something from the concentrator because the same snmpwalk on another router is very fast. Walking through the active vpn list takes longer than walking through the whole snmp tree on another router.
    I only found something about SNMP reuqests queued ... but that didn't help. Any idea how I can speed up the snmp replies ?
    Thanks,
    Stefan

  • AAA authorization with ACS 3.2

    I'm trying to configure my devices to use shell command authorization sets located on my ACS box. I want users that are members of a specific group to only be allowed to certain commands (ex. show). I'm pretty sure my ACS box is setup correctly, but my devices aren't. Here is the current config:
    aaa new-model
    aaa authentication login default group tacacs+ local
    aaa authentication enable default group tacacs+ enable
    aaa authorization exec default group tacacs+ local
    aaa accounting exec default start-stop group tacacs+
    I want the aaa authorization to use tacacs on my ACS box and whatever shell commands sets that are group specific when a user that is a member of that group logs in.

    Marek
    1) it is good to know that authentication is working and does fail over to the enable password. This helps assure that the problem that we are dealing with is not an issue of failure to communicate.
    2) it is not necessary that the router mirror the groups that are configured on the server. So unless you want to specify authentication or authorization processing different from default then you do not need level1 to be mentioned on the router.
    I agree that there is not a lot of clear documentation about authorization. One of the purposes of this forum is to allow people to ask questions about things that they do not yet understand and hopefully to get some helpful answers. As you get more experience and understand more then you may be able to participate in the forum and providing answers in addition to asking questions.
    3) As I read your config authentication does have a backup method and authorization does not. I am a proponent of having backup methods configured. As long as the server is available you do not need them. But if they are not configured and the server is not available you can manage to lock yourself out of the router.
    I can understand removing them while you concentrate on why the authorization is not working (though I would not do it that way) but I strongly suggest that you plan to put the backups in before you put anything like this into production.
    4) the fact that both users log in and are already at privilege level 15 may be a clue. Look in the config under the console and under the vty ports. Look for this configuration command privilege level 15. If it is there remove it and test over again.
    HTH
    Rick

  • AAA Authorization with ACS Shell-Sets

    Hi all,
    I am using a cisco 871 router running Version 12.4(11)T advanced IP Services.
    I am having trouble getting AAA Authorization to work correctly with ACS.
    I am able to set the users up on ACS fine and assign them shell and priv level 7.
    I then setup a Shell Auth Set, and enter in the commands show and configure.
    When I log in as a user, I get an exec with a priv level of 7 no problems, but I never seem to be able
    to access global config mode by typing in conf (or configure) terminal or t.
    If I type con? the only command there is connect, configure is never an option...
    The only way I can get this to work is by entering the command:
    privilege exec level 7 configure terminal
    I thought the whole purpose of the ACS Shell Set was to provide this information to the Router?
    This is most frustrating
    The ACS Server is set up with a Shell Command Authorization Set named Level_7
    It is assigned to the relevant groups and I even have the "Unmatched Commands" option selected to "Permit"
    The "Permit Unmatched Args" is also selected.
    See an excerpt of my IOS config below:
    aaa new-model
    aaa group server tacacs+ ACS
    server 10.90.0.11
    aaa authentication login default group ACS local
    aaa authorization exec default group ACS
    aaa authorization commands 7 default group ACS local
    tacacs-server host 10.90.0.11 key cisco
    privilege exec level 7 configure terminal
    privilege exec level 7 configure
    privilege exec level 7 show running-config
    privilege exec level 7 show
    Hope you can help me with this one..
    P.s I have tried it with the privilege commands on the router and removed from the router and just keep getting the same results!?

    Hi,
    So here it is,
    You are actually using two different options and trying to couple then together. What I would suggest you is either use Shell command authorization set feature or play with privilege level. Not both mixed together.
    Above scenario might work, if you move commands to privilege level 6 and give user privilege level 7. It might not sure. Give it a try and share the result.
    This is what I suggest the commands back to normal level.
    Below provided are steps to configure shell command authorization:
    Follow the following steps over the router:
    !--- is the desired username
    !--- is the desired password
    !--- we create a local username and password
    !--- in case we are not able to get authenticated via
    !--- our tacacs+ server. To provide a back door.
    username password privilege 15
    !--- To apply aaa model over the router
    aaa new-model
    !--- Following command is to specify our ACS
    !--- server location, where is the
    !--- ip-address of the ACS server. And
    !--- is the key that should be same over the ACS and the router.
    tacacs-server host key
    !--- To get users authentication via ACS, when they try to log-in
    !--- If our router is unable to contact to ACS, then we will use
    !--- our local username & password that we created above. This
    !--- prevents us from locking out.
    aaa authentication login default group tacacs+ local
    aaa authorization exec default group tacacs+ local
    aaa authorization config-commands
    aaa authorization commands 0 default group tacacs+ local
    aaa authorization commands 1 default group tacacs+ local
    aaa authorization commands 15 default group tacacs+ local
    !--- Following commands are for accounting the user's activity,
    !--- when user is logged into the device.
    aaa accounting exec default start-stop group tacacs+
    aaa accounting system default start-stop group tacacs+
    aaa accounting commands 0 default start-stop group tacacs+
    aaa accounting commands 1 default start-stop group tacacs+
    aaa accounting commands 15 default start-stop group tacacs+
    Configuration on ACS
    [1] Goto 'Shared Profile Components' -> 'Shell Command Authorization Sets' -> 'Add'
    Provide any name to the set.
    provide the sufficent description (if required)
    (a) For Full Access administrative set.
    In Unmatched Commands, select 'Permit'
    (b) For Limited Access set.
    In Unmatched commands, select 'Deny'.
    And in the box above 'Add Command' box type in the main command, and in box below 'Permit unmatched Args'. Provide with the sub command allow.
    For example: If we want user to be only able to access the following commads:
    login
    logout
    exit
    enable
    disable
    show
    Then the configuration should be:
    ------------------------Permit unmatched Args--
    login permit
    logout permit
    exit permit
    enable permit
    disable permit
    configure permit terminal
    interface permit ethernet
    permit 0
    show permit running-config
    in above example, user will be allowed to run only above commands. If user tries to execute 'interface ethernet 1', user will get 'Command authorization failed'.
    [2] Press 'Submit'.
    [3] Goto the group on which we want to apply these command authorization set. Select 'Edit Settings'.
    (cont...)

  • How do I change my Ipad to access Itunes store in a different country than the one I usually use and have my account with?

    I usually use the Itunes application on my Ipad in FRence and use the French Itunes store. I am now in Cyprus and after synchronising my Ipad there I now can access the US Itunes Store but my purchases are refused as my account is with the French Itunes store.  How do I either open an account with the US Itunes store or revert to the French Itunes store on my Ipad?

    synchronising is not the problem i think, you need a new US apple id. i only have a malaysian credit card but i have separate ids for US UK and Malaysia. i have travelled to these 3 countries and have home adresses in each country but for buying stuff, I use an iTunes store card instead of a credit card cos its easier. you do not need a credit card that must have billing address from the same country as the iTunes store. So I would suggest if you are currently based in the US go the nearest apple store buy an iTunes store card (i buy in multiples of US$100 with a credit card) and use your current US home address as the US iTunes address.
    so log off your french iTunes store account, create new US apple id for your iTunes store account using your current US address and then redeem your itunes store card and voila you are set to go. (did i mention you will also need a new separate email address for the new apple id) i have one each from gmail, yahoo and hotmail for each separate id.
    the only drawback is that when you want to do an update for the apps that you buy from the different iTunes store, you must log in to that iTunes store account ie if you buy an app from the US store you must log in and update with the US store id and to update the apps from the French store you must log off from the US store and log in again with the french store id.
    hope this makes sense to you.

  • Sharing one itunes account with two computers

    I used to share my itunes account with my sister and our ipods were synched to one computer. We now have two new computers and would still like to continue to share that account. Is it possible to open the same account on two separate computers?

    Explain how you transfer content manually.
    Control-click or right-click it in iTunes, choose Get Info, locate the music files, move them to the other computer's hard disk as you would any other type of file, and then drag them into the open iTunes window. By default on a Mac, dragging them to the open iTunes window also copies them to the hard disk.
    (40011)

  • How Can I Use a Gmail Account with Multiple Email Addresses in iPhone Mail?

    So I have a Gmail account with 4 POP accounts that it checks...  Is there a way to get "Reply From" from multiple addresses?
    I've tried the following sites...  No luck with iOS 5...
    http://email.about.com/od/iphonemailtips/qt/gmail_multiaddr.htm
    http://modernerd.com/post/535350679/solved-gmail-ipad-iphone-and-multiple-from

    By setting up your GMail account to forward emails to your iCloud email account address.
    You won't be able to reply from your Gmail address from within iCloud though.

Maybe you are looking for

  • Custom images all jumbled in Address book

    I have about 4000 contacts in my address book. Some of them had custom images (photo) attached. I sync my Mac, .Mac, and iPhone routinely. One day, my Address Book decided to jumble up all the photos. Not nice. Is there a way to delete all my custom

  • IDVD exporting low resolution

    I made 5 slideshows on iMovie and exported them HD quality, and they look great on my iMac. I put them on a basic iDVD menu and burnt them onto a DVD (burnt 3 seperate disks as best performance, high quality AND professional quality) and the entire t

  • Help opening Flash Presentaion with .exe extension

    I need help opening a flash presentation that was created for my business. I has a .exe extension. It was created as an cd business card. I want to host this presentation on my website, but my site does not allow me to upload .exe files. How do I cha

  • My new photoshop Elements 11 opens off centered and won't move with my cursor (on a MacBook )why?

    My new photoshop Elements 11 opens off centered and won't move with my cursor (on a MacBook )why?

  • DB Links and APEX

    Has anyone got Data Base Links to work when used through XE's APEX. Via sql*plus, I can create a DB link from my XE database to a 9.2.0.x database I can then successfully use this via sql*plus and a packaged procedure called from sql*plus, so I know