Cisco ASA 5505 Configuration Manual page 1741

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Appendix B
Configuring an External Server for Authorization and Authentication
Table B-2
Security Appliance Supported Cisco Attributes for LDAP Authorization (continued)
Attribute Name/
IPSec-Backup-Servers
IPSec-Client-Firewall-Filter- Name Y
IPSec-Client-Firewall-Filter-
Optional
IPSec-Default-Domain
IPSec-Extended-Auth-On-Rekey
IPSec-IKE-Peer-ID-Check
IPSec-IP-Compression
IPSec-Mode-Config
IPSec-Over-UDP
IPSec-Over-UDP-Port
IPSec-Required-Client-Firewall-
Capability
IPSec-Sec-Association
IPSec-Split-DNS-Names
IPSec-Split-Tunneling-Policy
IPSec-Split-Tunnel-List
IPSec-Tunnel-Type
IPSec-User-Group-Lock
OL-20339-01
Syntax/
VPN 3000 ASA PIX
Type
Y
Y
Y
String
String
Y
Y
Y
Integer
Y
Y
Y
String
Y
Y
String
Y
Y
Y
Integer
Y
Y
Y
Integer
Y
Y
Y
Boolean Single
Y
Y
Y
Boolean Single
Y
Y
Y
Integer
Y
Y
Y
Integer
Y
String
Y
Y
Y
String
Y
Y
Y
Integer
Y
Y
Y
String
Y
Y
Y
Integer
Y
Boolean Single
Configuring an External LDAP Server
Single or
Multi-Valued Possible Values
Single
1 = Use Client-Configured list
2 = Disabled and clear client list
3 = Use Backup Server list
Single
Specifies the name of the filter to be
pushed to the client as firewall
policy.
Single
0 = Required
1 = Optional
Single
Specifies the single default domain
name to send to the client (1 - 255
characters).
Single
Single
1 = Required
2 = If supported by peer certificate
3 = Do not check
Single
0 = Disabled
1 = Enabled
0 = Disabled
1 = Enabled
0 = Disabled
1 = Enabled
Single
4001 - 49151; default = 10000
Single
0 = None
1 = Policy defined by remote FW
Are-You-There (AYT)
2 = Policy pushed CPP
4 = Policy from server
Single
Name of the security association
Single
Specifies the list of secondary
domain names to send to the client
(1 - 255 characters).
Single
0 = Tunnel everything
1 = Split tunneling
2 = Local LAN permitted
Single
Specifies the name of the network or
access list that describes the split
tunnel inclusion list.
Single
1 = LAN-to-LAN
2 = Remote access
0 = Disabled
1 = Enabled
Cisco ASA 5500 Series Configuration Guide using ASDM
B-9

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents