Configuring Group Policies; Configuring An External Group Policy - Cisco PIX 500 Series Configuration Manual

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Group Policies

Configuring Group Policies

A group policy can apply to any kind of tunnel. In each case, if you do not explicitly define a parameter,
the group takes the value from the default group policy. To configure a group policy, follow the steps in
the subsequent sections.

Configuring an External Group Policy

External group policies take their attribute values from the external server that you specify. For an
external group policy, you must identify the AAA server group that the security appliance can query for
attributes and specify the password to use when retrieving attributes from the external AAA server
group. If you are using an external authentication server, and if your external group-policy attributes
exist in the same RADIUS server as the users that you plan to authenticate, you have to make sure that
there is no name duplication between them.
External group names on the security appliance refer to user names on the RADIUS server. In other
Note
words, if you configure external group X on the security appliance, the RADIUS server sees the query
as an authentication request for user X. So external groups are really just user accounts on the RADIUS
server that have special meaning to the security appliance. If your external group attributes exist in the
same RADIUS server as the users that you plan to authenticate, there must be no name duplication
between them.
The security appliance supports user authorization on an external LDAP or RADIUS server. Before you
configure the security appliance to use an external server, you must configure the server with the correct
security appliance authorization attributes and, from a subset of these attributes, assign specific
permissions to individual users. Follow the instructions in
for Authorization and Authentication"
To configure an external group policy, do the following steps specify a name and type for the group
policy, along with the server-group name and a password:
hostname(config)# group-policy group_policy_name type server-group server_group_name
password server_ password
hostname(config)#
For an external group policy, RADIUS is the only supported AAA server type.
Note
For example, the following command creates an external group policy named ExtGroup that gets its
attributes from an external RADIUS server named ExtRAD and specifies that the password to use when
retrieving the attributes is newpassword:
hostname(config)# group-policy ExtGroup external server-group ExtRAD password newpassword
hostname(config)#
You can configure several vendor-specific attributes (VSAs), as described in
Note
an External Server for Authorization and
the Class attribute (#25), the security appliance uses that attribute to authenticate the Group Name. On
the RADIUS server, the attribute must be formatted as: OU=groupname; where groupname is identical
to the Group Name configured on the security appliance—for example, OU=Finance.
Cisco Security Appliance Command Line Configuration Guide
30-36
Chapter 30
Configuring Connection Profiles, Group Policies, and Users
Appendix E, "Configuring an External Server
to configure your external server.
Authentication". If a RADIUS server is configured to return
Appendix E, "Configuring
OL-12172-03

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents