Cisco ASA 5505 Configuration Manual page 1771

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Appendix B
Configuring an External Server for Authorization and Authentication
Table B-8
Security Appliance Supported IETF RADIUS Attributes and Values
IETF-Radius-Idle-Timeout
IETF-Radius-Service-Type
IETF-Radius-Session-Timeout
Configuring an External TACACS+ Server
The adaptive security appliance provides support for TACACS+ attributes. TACACS+ separates the
functions of authentication, authorization, and accounting. The protocol supports two types of attributes:
mandatory and optional. Both the server and client must understand a mandatory attribute, and the
mandatory attribute must be applied to the user. An optional attribute may or may not be understood or
used.
To use TACACS+ attributes, make sure you have enabled AAA services on the NAS.
Note
Table B-9
connections.
Table B-9
Attribute
acl
idletime
timeout
.
Table B-10
Attribute
bytes_in
bytes_out
cmd
disc-cause
OL-20339-01
Y
Y
Y
Y
Y
Y
Y
Y
Y
lists supported TACACS+ authorization response attributes for cut-through-proxy
Table B-10
lists supported TACACS+ accounting attributes.
Supported TACACS+ Authorization Response Attributes
Description
Identifies a locally configured access list to be applied to the connection.
Indicates the amount of inactivity in minutes that is allowed before the
authenticated user session is terminated.
Specifies the absolute amount of time in minutes that authentication credentials
remain active before the authenticated user session is terminated.
Supported TACACS+ Accounting Attributes
Description
Specifies the number of input bytes transferred during this connection (stop
records only).
Specifies the number of output bytes transferred during this connection (stop
records only).
Defines the command executed (command accounting only).
Indicates the numeric code that identifies the reason for disconnecting (stop
records only).
28
Integer
Single
6
Integer
Single
27
Integer
Single
Cisco ASA 5500 Series Configuration Guide using ASDM
Configuring an External TACACS+ Server
seconds
seconds. Possible Service Type
values:
.Administrative—user is allowed
access to configure prompt.
.NAS-Prompt—user is allowed
access to exec prompt.
.remote-access—user is allowed
network access
seconds
B-39

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents