Cisco PIX 500 Series Configuration Manual page 1091

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Appendix E
Configuring an External Server for Authorization and Authentication
To use TACACS+ attributes, make sure you have enabled AAA services on the NAS.
Note
Table E-7
connections.
Table E-7
Attribute
acl
idletime
timeout
.
Table E-8
Attribute
bytes_in
bytes_out
cmd
disc-cause
elapsed_time
foreign_ip
local_ip
NAS port
packs_in
packs_out
priv-level
rem_iddr
service
task_id
username
OL-12172-03
lists supported TACACS+ authorization response attributes for cut-through-proxy
Table E-8
lists supported TACACS+ accounting attributes.
Supported TACACS+ Authorization Response Attributes
Description
Identifies a locally configured access list to be applied to the connection.
Indicates the amount of inactivity in minutes that is allowed before the
authenticated user session is terminated.
Specifies the absolute amount of time in minutes that authentication credentials
remain active before the authenticated user session is terminated.
Supported TACACS+ Accounting Attributes
Description
Specifies the number of input bytes transferred during this connection (stop
records only).
Specifies the number of output bytes transferred during this connection (stop
records only).
Defines the command executed (command accounting only).
Indicates the numeric code that identifies the reason for disconnecting (stop
records only).
Defines the elapsed time in seconds for the connection (stop records only).
Specifies the IP address of the client for tunnel connections. Defines the address
on the lowest security interface for cut-through-proxy connections.
Specifies the IP address that the client connected to for tunnel connections. Defines
the address on the highest security interface for cut-through-proxy connections.
Contains a session ID for the connection.
Specifies the number of input packets transferred during this connection.
Specifies the number of output packets transferred during this connection.
Set to the user's privilege level for command accounting requests or to 1 otherwise.
Indicates the IP address of the client.
Specifies the service used. Always set to "shell" for command accounting only.
Specifies a unique task ID for the accounting transaction.
Indicates the name of the user.
Cisco Security Appliance Command Line Configuration Guide
Configuring an External RADIUS Server
E-41

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents