Kerberos Server Support; Ldap Server Support; Local Database Support; User Profiles - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

AAA Server and Local Database Support
NT servers have a maximum length of 14 characters for user passwords. Longer passwords are truncated.
Note
This is a limitation of NTLM Version 1.

Kerberos Server Support

The FWSM can use Kerberos servers for VPN-based management connections. When a user attempts to
establish VPN access, and the traffic matches an authentication statement, the FWSM consults the
Kerberos server for user authentication and grants or denies user access based on the response from the
server.
The FWSM supports 3DES, DES, and RC4 encryption types.
The FWSM does not support changing user passwords during tunnel negotiation. To avoid this situation
Note
happening inadvertently, disable password expiration on the Kerberos/Active Directory server for users
connecting to the FWSM.

LDAP Server Support

The FWSM can use LDAP servers for authorization of VPN-based management connections. When user
authentication for VPN access has succeeded and the applicable tunnel-group record specifies an LDAP
authorization server group, the FWSM queries the LDAP server and applies to the VPN session the
authorizations it receives.

Local Database Support

The FWSM maintains a local database that you can populate with user profiles.
This section contains the following topics:

User Profiles

User profiles contain, at a minimum, a username. Typically, a password is assigned to each username,
although passwords are optional.
The username attributes command enables you to enter the username mode. In this mode, you can add
other information to a specific user profile. The information you can add includes VPN-related
attributes, such as a VPN session timeout value.

Fallback Support

With the exception of fallback for network access authentication, the local database can act as a fallback
method for the functions in
from the FWSM.
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
11-6
User Profiles, page 11-6
Fallback Support, page 11-6
Table
Chapter 11
11-1. This behavior is designed to help you prevent accidental lockout
Configuring AAA Servers and the Local Database
OL-20748-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents