Cisco PIX 500 Series Configuration Manual page 213

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Chapter 13
Configuring AAA Servers and the Local Database
Table 13-2
Command
accounting-port
acl-netmask-convert
authentication-port
kerberos-realm
key
ldap-attribute-map
ldap-base-dn
ldap-login-dn
ldap-login-password
ldap-naming-attribute
ldap-over-ssl
ldap-scope
nt-auth-domain-controller NT
radius-common-pw
retry-interval
sasl-mechanism
server-port
server-type
timeout
Example 13-1
one RADIUS group with a single server, and an NT domain server.
Example 13-1 Multiple AAA Server Groups and Servers
hostname(config)# aaa-server AuthInbound protocol tacacs+
hostname(config-aaa-server-group)# max-failed-attempts 2
hostname(config-aaa-server-group)# reactivation-mode depletion deadtime 20
hostname(config-aaa-server-group)# exit
hostname(config)# aaa-server AuthInbound (inside) host 10.1.1.1
hostname(config-aaa-server-host)# key TACPlusUauthKey
OL-12172-03
Host Mode Commands, Server Types, and Defaults
Applicable AAA Server Types Default Value
RADIUS
RADIUS
RADIUS
Kerberos
RADIUS
TACACS+
LDAP
LDAP
LDAP
LDAP
LDAP
LDAP
LDAP
RADIUS
Kerberos
RADIUS
SDI
LDAP
Kerberos
LDAP
NT
SDI
TACACS+
LDAP
All
shows commands that add one TACACS+ group with one primary and one backup server,
Identifying AAA Server Groups and Servers
1646
standard
1645
10 seconds
10 seconds
10 seconds
88
389
139
5500
49
auto-discovery
10 seconds
Cisco Security Appliance Command Line Configuration Guide
13-11

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents