Using Active Directory To Override An Account Disabled Aaa Indicator - Cisco PIX 500 Series Configuration Manual

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Configuring Connection Profiles
Figure 30-3
Note

Using Active Directory to Override an Account Disabled AAA Indicator

To override an account-disabled indication from a AAA server, specify the override-account-disable
command in tunnel-group general-attributes configuration mode on thesecurity appliance and do the
following steps under Active Directory:
Allowing override account-disabled is a potential security risk.
Note
Step 1
Select Start > Programs > Administrative Tools > Active Directory Users and Computers.
Right-click Username > Properties > Account and select Disable Account from the menu.
Step 2
Cisco Security Appliance Command Line Configuration Guide
30-30
Active Directory—Maximum Password Age
The radius-with-expiry command, formerly configured as part of tunnel-group remote-access
configuration to perform the password age function, is deprecated. The password-management
command, entered in tunnel-group general-attributes mode, replaces it.
Chapter 30
Configuring Connection Profiles, Group Policies, and Users
OL-12172-03

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents