Cisco ASA 5505 Configuration Manual page 707

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Chapter 33
Configuring AAA Rules for Network Access
Configuring the Authentication Proxy Limit
You can manually configure the uauth session limit by setting the maximum number of concurrent proxy
connections allowed per user.
To set the proxy limit, perform the following steps:
From the Configuration > Firewall > AAA Rules pane, click Advanced.
Step 1
The AAA Rules Advanced Options dialog box appears.
In the Proxy Limit area, check Enable Proxy Limit.
Step 2
In the Proxy Limit field, enter the number of concurrent proxy connections allowed per user, from 1 to
Step 3
128.
Click OK, and then click Apply.
Step 4
Configuring Authorization for Network Access
After a user authenticates for a given connection, the adaptive security appliance can use authorization
to further control traffic from the user.
This section includes the following topics:
Configuring TACACS+ Authorization
You can configure the adaptive security appliance to perform network access authorization with
TACACS+.
Authentication and authorization rules are independent; however, any unauthenticated traffic matched
by an authorization rule will be denied. For authorization to succeed:
1.
2.
3.
4.
5.
See the documentation for your TACACS+ server for information about configuring network access
authorizations for a user.
OL-20339-01
Configuring TACACS+ Authorization, page 33-9
Configuring RADIUS Authorization, page 33-10
A user must first authenticate with the adaptive security appliance.
Because a user at a given IP address only needs to authenticate one time for all rules and types, if
the authentication session hasn't expired, authorization can occur even if the traffic is not matched
by an authentication rule.
After a user authenticates, the adaptive security appliance checks the authorization rules for
matching traffic.
If the traffic matches the authorization rule, the adaptive security appliance sends the username to
the TACACS+ server.
The TACACS+ server responds to the adaptive security appliance with a permit or a deny for that
traffic, based on the user profile.
The adaptive security appliance enforces the authorization rule in the response.
Configuring Authorization for Network Access
Cisco ASA 5500 Series Configuration Guide using ASDM
33-9

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents