Cisco ASA 5505 Configuration Manual page 1368

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Configuring SSL VPN Connections
Table 64-2
Starting Index
1
6
6
Using a negative index, as in the third row of this table, specifies to count from the end of the string
backwards to the end of the substring, in this case, the "r" of "user".
When using filtering by substrings, you should know the length of the substring that you are seeking.
From the following examples, use either the regular expression matching or the custom script in Lua
format:
Example 1: Regular Expression Matching—Enter a regular expression to apply to the search in the
Regular Expression field. Standard regular expression operators apply. For example, suppose you
want to use a regular expression to filter everything up to the @ symbol of the "Email Address (EA)"
DN value. The regular expression ^[^@]* would be one way to do this. In this example, if the DN
value contained a value of user1234@company.com, the return value after the regular expression
would be user1234.
Example 2: Use custom script in Lua format—Specify a custom script written in the Lua
programming language to parse the search fields. Selecting this option makes available a field in
which you can enter your custom Lua script; for example, the script:
return cert.subject.cn..'/'..cert.subject.l
combines two DN fields, username (cn) and locality (l), to use as a single username and inserts the
slash (/) character between the two fields.
Table 64-3
Note
Table 64-3
Attribute Name
cert.subject.c
cert.subject.cn
cert.subject.dnq
cert.subject.ea
cert.subject.genq
cert.subject.gn
cert.subject.i
cert.subject.l
cert.subject.n
cert.subject.o
cert.subject.ou
Cisco ASA 5500 Series Configuration Guide using ASDM
64-58
Filtering by Substring
Ending Index
5
10
-1
lists the attribute names and descriptions that you can use in a Lua script.
Lua is case-sensitive.
Attribute Names and Descriptions
Return Value
host/
user
user
Description
Country
Common Name
DN qualifier
Email Address
Generational qualified
Given Name
Initials
Locality
Name
Organization
Organization Unit
Chapter 64
General VPN Setup
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents