Appendix; Configuring An External Server For Authorization And Authentication; Selecting Ldap, Radius, Or Local Authentication And Authorization - Cisco PIX 500 Series Configuration Manual

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Configuring an External Server for Authorization
and Authentication
This appendix describes how to configure an external LDAP or RADIUS server to support the
authentication and authorization of security appliance, VPN 3000, and PIX users. Authentication
determines who the user is and authorization determines what the user can do. Before you configure the
security appliance to use an external server, you must configure the server with the correct security
appliance authorization attributes and, from a subset of these attributes, assign specific permissions to
individual users.
This appendix includes the following sections:
Selecting LDAP, RADIUS, or Local Authentication and
Authorization
To help you decide which authentication or authorization method is right for your platform, this section
describes the LDAP and RADIUS support provided with the security appliance (ASA), PIX, and the
VPN 3000 platforms.
OL-12172-03

Selecting LDAP, RADIUS, or Local Authentication and Authorization

Understanding Policy Enforcement of Permissions and Attributes
Configuring an External LDAP Server
Configuring an External RADIUS Server
LDAP Authentication
Supported on PIX 7.1.x and the security appliance only. VPN 3000 does not support native LDAP
authentication. The LDAP server retrieves and searches for the username and enforces any defined
attributes as part of the authorization function.
LDAP Authorization
Supported on PIX, VPN 3000, and the security appliance. The LDAP server retrieves and searches
for the username and enforces any defined attributes.
RADIUS Authentication
Supported on PIX, VPN 3000, and the security appliance. The RADIUS server retrieves and
searches for the username and enforces any defined attributes as it performs the authorization
function.
RADIUS Authorization
A P P E N D I X
Cisco Security Appliance Command Line Configuration Guide
E
E-1

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents