Cisco FirePOWER ASA 5500 series Configuration Manual page 917

Security appliance command line
Hide thumbs Also See for FirePOWER ASA 5500 series:
Table of Contents

Advertisement

Appendix E
Configuring an External Server for Authorization and Authentication
Table E-2
Security Appliance Supported LDAP Cisco Schema Attributes (continued)
Attribute Name/
OID (Object Identifier)
cVPN3000-PPTP-Encryption
cVPN3000-L2TP-Encryption
cVPN3000-IPSec-Split-Tunnel-List
cVPN3000-IPSec-Default-Domain
cVPN3000-IPSec-Split-DNS-Name
cVPN3000-IPSec-Tunnel-Type
cVPN3000-IPSec-Mode-Config
cVPN3000-IPSec-User-Group-Lock
cVPN3000-IPSec-Over-UDP
cVPN3000-IPSec-Over-UDP-Port
cVPN3000-IPSec-Banner2
cVPN3000-PPTP-MPPC-Compression
OL-10088-01
VPN
Attr.
1
3000 ASA PIX
OID
Y
14
Y
15
Y
Y
Y
16
Y
Y
Y
17
Y
Y
Y
18
Y
Y
Y
19
Y
Y
Y
20
Y
21
Y
Y
Y
22
Y
Y
Y
23
Y
Y
Y
24
Y
25
Cisco Security Appliance Command Line Configuration Guide
Configuring an External LDAP Server
Single
or
Syntax/
Multi-
Type
Valued
Possible Values
Integer
Single
Bitmap:
1 = Encryption required
2 = 40 bits
4 = 128 bits
8 = Stateless-Required
Example: 15 =
40/128-Encr/Stateless-Req
Integer
Single
Bitmap:
1 = Encryption required
2 = 40 bit
4 = 128 bits
8 = Stateless-Req
15 =
40/128-Encr/Stateless-Req
String
Single
Specifies the name of the
network or access list that
describes the split tunnel
inclusion list.
String
Single
Specifies the single default
domain name to send to the
client (1-255 characters).
String
Single
Specifies the list of secondary
domain names to send to the
client (1-255 characters).
Integer
Single
1 = LAN-to-LAN
2 = Remote access
Boolean Single
0 = Disabled
1 = Enabled
Boolean Single
0 = Disabled
1 = Enabled
Boolean Single
0 = Disabled
1 = Enabled
Integer
Single
4001 - 49151, default = 10000
String
Single
Banner string
Integer
Single
0 = Disabled
1 = Enabled
E-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Pix 500 seriesCisco asa 5500 series

Table of Contents