Cisco PIX 500 Series Configuration Manual page 1075

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Appendix E
Configuring an External Server for Authorization and Authentication
Set up the users or groups with the permissions and attributes to send during IPSec/WebVPN tunnel
Step 2
establishment. The permissions or attributes might include access hours, primary DNS, banner, and so
forth.
Security Appliance RADIUS Authorization Attributes
Note
Authorization refers to the process of enforcing permissions or attributes. A RADIUS server defined as
an authentication server enforces permissions or attributes if they are configured.
Table E-5
authorization.
Table E-5
Security Appliance Supported RADIUS Attributes and Values
Attribute Name
Access-Hours
Simultaneous-Logins
Primary-DNS
Secondary-DNS
Primary-WINS
Secondary-WINS
SEP-Card-Assignment
Tunneling-Protocols
IPSec-Sec-Association
OL-12172-03
If you are using a FUNK RADIUS server: Cisco supplies a dictionary file that contains all the
security appliance attributes. Obtain this dictionary file,
CCO or from the security appliance CD-ROM. Load the dictionary file on your server.
For other vendors' RADIUS servers (for example, Microsoft Internet Authentication Service): you
must manually define each security appliance attribute. To define an attribute, use the attribute name
or number, type, value, and vendor code (3076). For a list of security appliance RADIUS
authorization attributes and values, see
lists all the possible security appliance supported attributes that can be used for user
VPN
3000 ASA PIX
Y
Y
Y
Y
Y
Y
Y
Y
Table
E-5.
Attr.
Syntax/
#
Type
Y
Y
1
String
Y
Y
2
Integer
Y
Y
5
String
Y
Y
6
String
Y
Y
7
String
Y
Y
8
String
9
Integer
Y
Y
11
Integer
12
String
Cisco Security Appliance Command Line Configuration Guide
Configuring an External RADIUS Server
, from Software Center on
cisco3k.dct
Single
or
Multi-
Valued
Description or Value
Single
Name of the time range, for
example, Business-hours
Single
An integer 0 to 2147483647
Single
An IP address
Single
An IP address
Single
An IP address
Single
An IP address
Single
Not used
Single
1 = PPTP
2 = L2TP
4 = IPSec
8 = L2TP/IPSec
16 = WebVPN
4 and 8 are mutually exclusive;
0-11 and 16-27 are legal
values.
Single
Name of the security
association
E-25

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents