Cisco ASA Series Cli Configuration Manual page 880

Software version 9.0 for the services module
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Feature History for AAA Servers
Table 1-3
Feature History for AAA Servers
Feature Name
AAA Servers
Key vendor-specific attributes (VSAs) sent in
RADIUS access request and accounting request
packets from the ASA
Cisco ASA Series CLI Configuration Guide
1-34
Chapter 1
Platform
Releases
Feature Information
7.0(1)
AAA Servers describe support for AAA and how to
configure AAA servers and the local database.
We introduced the following commands:
username, aaa authorization exec authentication-server,
aaa authentication console LOCAL, aaa authorization
exec LOCAL, service-type, ldap attribute-map,
aaa-server protocol, aaa authentication {telnet | ssh |
serial} console LOCAL, aaa authentication http console
LOCAL, aaa authentication enable console LOCAL,
max-failed-attempts, reactivation-mode,
accounting-mode simultaneous, aaa-server host,
authorization-server-group, tunnel-group, tunnel-group
general-attributes, map-name, map-value,
ldap-attribute-map, zonelabs-Integrity server-address,
zonelabs-integrity port, zonelabs-integrity interface,
zonelabs-integrity fail-timeout, zonelabs-integrity
fail-close, zonelabs-integrity fail-open,
zonelabs-integrity ssl-certificate-port,
zonelabs-integrity ssl-client-authentication {enable |
disable}, client-firewall {opt | req} zonelabs-integrity
8.4(3)
Four New VSAs—Tunnel Group Name (146) and Client
Type (150) are sent in RADIUS access request packets from
the ASA. Session Type (151) and Session Subtype (152) are
sent in RADIUS accounting request packets from the ASA.
All four attributes are sent for all accounting request packet
types: Start, Interim-Update, and Stop. The RADIUS server
(for example, ACS and ISE) can then enforce authorization
and policy attributes or use them for accounting and billing
purposes.
Configuring AAA Servers and the Local Database

Advertisement

Table of Contents
loading

Table of Contents