Cisco -Av-Pair Attribute Syntax - Cisco FirePOWER ASA 5500 series Configuration Manual

Security appliance command line
Hide thumbs Also See for FirePOWER ASA 5500 series:
Table of Contents

Advertisement

Configuring an External LDAP Server
1. To get the complete Object Identifier of each attribute, append the number in the column to the end of 1.2.840.113556.8000.795.2. Thus, the OID of the
first attribute in the table, cVPN3000-Access-Hours, is 1.2.840.113556.8000.795.2.1. Likewise, the OID of the last attribute in the table,
cVPN3000-WebVPN-SVC-Compression, is 1.2.840.113556.8000.795.2.115.

Cisco -AV-Pair Attribute Syntax

The syntax of each Cisco-AV-Pair rule is as follows:
[Prefix] [Action] [Protocol] [Source] [Source Wildcard Mask] [Destination] [Destination Wildcard
Mask] [Established] [Log] [Operator] [Port]:
Field
Prefix
Action
Protocol
Source
Source Wildcard Mask
Destination
Destination Wildcard
Mask
Log
Operator
Port
For example:
ip:inacl#1=deny ip 10.155.10.0 0.0.0.255 10.159.2.0 0.0.0.255 log
ip:inacl#2=permit TCP any host 10.160.0.1 eq 80 log
webvpn:inacl#1=permit url http://www.cnn.com
webvpn:inacl#2=deny smtp any host 10.1.3.5
webvpn:inacl#3=permit url cifs://mar_server/peopleshare1
Cisco Security Appliance Command Line Configuration Guide
E-14
Appendix E
Configuring an External Server for Authorization and Authentication
Description
A unique identifier for the AV pair. For example:
standard ACLs) or
webvpn:inacl#
only appears when the filter has been sent as an AV pair.
Action to perform if rule matches: deny, permit.
Number or name of an IP protocol. Either an integer in the range 0-255 or
one of the following keywords: icmp, igmp, ip, tcp, udp.
Network or host that sends the packet. It is specified as an IP address, a
hostname, or the keyword "any". If specified as an IP address, the source
wildcard mask must follow.
The wildcard mask applied to the source address.
Network or host that receives the packet. It is specified as an IP address, a
hostname, or the keyword "any". If specified as an IP address, the source
wildcard mask must follow.
The wildcard mask applied to the destination address.
Generates a FILTER log message. You must use this keyword to generate
events of severity level 9.
Logic operators: greater than, less than, equal to, not equal to.
The number of a TCP or UDP port in the range 0-65535.
ip:inacl#1=
(used for WebVPN ACLs). This field
(used for
OL-10088-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Pix 500 seriesCisco asa 5500 series

Table of Contents