Radius Server Support; Authentication Methods; Attribute Support; Radius Authorization Functions - Cisco PIX 500 Series Configuration Manual

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

AAA Server and Local Database Support
4. Local command authorization is supported by privilege level only.
5. Command accounting is available for TACACS+ only.

RADIUS Server Support

The security appliance supports RADIUS servers.
This section contains the following topics:

Authentication Methods

The security appliance supports the following authentication methods with RADIUS:

Attribute Support

The security appliance supports the following sets of RADIUS attributes:

RADIUS Authorization Functions

The security appliance can use RADIUS servers for user authorization for network access using dynamic
access lists or access list names per user. To implement dynamic access lists, you must configure the
RADIUS server to support it. When the user authenticates, the RADIUS server sends a downloadable
access list or access list name to the security appliance. Access to a given service is either permitted or
denied by the access list. The security appliance deletes the access list when the authentication session
expires.

TACACS+ Server Support

The security appliance supports TACACS+ authentication with ASCII, PAP, CHAP, and MS-CHAPv1.
Cisco Security Appliance Command Line Configuration Guide
13-4
Authentication Methods, page 13-4
Attribute Support, page 13-4
RADIUS Authorization Functions, page 13-4
PAP—For all connection types.
CHAP—For L2TP-over-IPSec.
MS-CHAPv1—For L2TP-over-IPSec.
MS-CHAPv2—For L2TP-over-IPSec, and for regular IPSec remote access connections when the
password management feature is enabled.
Authentication attributes defined in RFC 2138.
Accounting attributes defined in RFC 2139.
RADIUS attributes for tunneled protocol support, defined in RFC 2868.
Cisco IOS VSAs, identified by RADIUS vendor ID 9.
Cisco VPN-related VSAs, identified by RADIUS vendor ID 3076.
Microsoft VSAs, defined in RFC 2548.
Chapter 13
Configuring AAA Servers and the Local Database
OL-12172-03

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents