Cisco PIX 500 Series Configuration Manual page 1090

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Configuring an External RADIUS Server
Table E-6
Security Appliance Supported RADIUS Attributes and Values (continued)
Attribute Name
WebVPN-File-Server-Browsing-Enable
WebVPN-Port-Forwarding-Enable
WebVPN-Outlook-Exchange-Proxy-Enable
WebVPN-Port-Forwarding-HTTP-Proxy
WebVPN-Auto-Applet-Download-Enable
WebVPN-Citrix-Metaframe-Enable
WebVPN-Apply-ACL
WebVPN-SSL-VPN-Client-Enable
WebVPN-SSL-VPN-Client-Required
WebVPN-SSL-VPN-Client-Keep-
Installation
Strip-Realm
RADIUS attribute names do not contain the cVPN3000 prefix to better reflect support for all three
Note
security appliances (VPN 3000, PIX, and the ASA). Cisco Secure ACS 4.x supports this new
nomenclature, but attribute names in pre-4.0 ACS releases still include the cVPN3000 prefix. The
appliances enforce the RADIUS attributes based on attribute numeric ID, not attribute name. LDAP
attributes are enforced by their name, not by the ID.
Security Appliance TACACS+ Attributes
The security appliance provides support for TACACS+ attributes. TACACS+ separates the functions of
authentication, authorization, and accounting. The protocol supports two types of attributes: mandatory
and optional. Both the server and client must understand a mandatory attribute, and the mandatory
attribute must be applied to the user. An optional attribute may or may not be understood or used.
Cisco Security Appliance Command Line Configuration Guide
E-40
Appendix E
Configuring an External Server for Authorization and Authentication
VPN
Attr.
3000 ASA PIX
#
Y
Y
96
Y
Y
97
Y
Y
98
Y
Y
99
Y
Y
100 Integer
Y
Y
101 Integer
Y
Y
102 Integer
Y
Y
103 Integer
Y
Y
104 Integer
Y
Y
105 Integer
Y
Y
Y
135 Boolean
Single
or
Syntax/
Multi-
Type
Valued
Description or Value
Single
Integer
0 = Disabled
1 = Enabled
Single
Integer
0 = Disabled
1 = Enabled
Single
Integer
0 = Disabled
1 = Enabled
Single
Integer
0 = Disabled
1 = Enabled
Single
0 = Disabled
1 = Enabled
Single
0 = Disabled
1 = Enabled
Single
0 = Disabled
1 = Enabled
Single
0 = Disabled
1 = Enabled
Single
0 = Disabled
1 = Enabled
Single
0 = Disabled
1 = Enabled
Single
0 = Disabled
1 = Enabled
OL-12172-03

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents