Cisco ASA 5505 Configuration Manual page 1738

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Configuring an External LDAP Server
Defining the Security Appliance LDAP Configuration
This section describes how to define the LDAP AV-pair attribute syntax. It includes the following topics:
The adaptive security appliance enforces the LDAP attributes based on attribute name, not numeric ID.
Note
RADIUS attributes, on the other hand, are enforced by numeric ID, not by name.
Authorization refers to the process of enforcing permissions or attributes. An LDAP server defined as
an authentication or authorization server will enforce permissions or attributes if they are configured.
For software Version 7.0, LDAP attributes include the cVPN3000 prefix. For Version 7.1 and later, this
prefix was removed.
Supported Cisco Attributes for LDAP Authorization
This section provides a complete list of attributes
500 series adaptive security appliances. The table includes attribute support information for the VPN
3000 and PIX 500 series to assist you configure networks with a mixture of these adaptive security
appliances.
Table B-2
Security Appliance Supported Cisco Attributes for LDAP Authorization
Attribute Name/
Access-Hours
Allow-Network-Extension- Mode
Authenticated-User-Idle- Timeout
Authorization-Required
Authorization-Type
Banner1
Banner2
Cisco ASA 5500 Series Configuration Guide using ASDM
B-6
Supported Cisco Attributes for LDAP Authorization, page B-6
Cisco AV Pair Attribute Syntax, page B-13
Cisco AV Pairs ACL Examples, page B-15
VPN 3000 ASA PIX
Y
Y
Y
Y
Y
Y
Y
Y
Y
Y
Y
Y
Appendix B
Configuring an External Server for Authorization and Authentication
(Table
B-2) for the ASA 5500, VPN 3000, and PIX
Syntax/
Single or
Type
Multi-Valued Possible Values
Y
String
Single
Y
Boolean Single
Y
Integer
Single
Integer
Single
Integer
Single
Y
String
Single
Y
String
Single
Name of the time-range
(for example, Business-Hours)
0 = Disabled
1 = Enabled
1 - 35791394 minutes
0 = No
1 = Yes
0 = None
1 = RADIUS
2 = LDAP
Banner string for clientless and
client SSL VPN, and IPSec clients.
Banner string for clientless and
client SSL VPN, and IPSec clients.
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents