E-14
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Appendix E Configuring an External Server for Authorization and Authentication
Configuring an External LDAP Server
For example:
ip:inacl#1=deny ip 10.155.10.0 0.0.0.255 10.159.2.0 0.0.0.255 log
ip:inacl#2=permit TCP any host 10.160.0.1 eq 80 log
webvpn:inacl#1=permit url http://www.website.com
webvpn:inacl#2=deny smtp any host 10.1.3.5
webvpn:inacl#3=permit url cifs://mar_server/peopleshare1
Note
Use Cisco-AV pair entries with the ip:inacl# prefix to enforce ACLs for remote IPSec and SSL VPN
Client (SVC) tunnels.
Use Cisco-AV pair entries with the webvpn:inacl# prefix to enforce ACLs for WebVPN clientless
(browser-mode) tunnels.
Table E-4
lists the tokens for the Cisco-AV-pair attribute:
Table E-3
AV-Pair Attribute Syntax Rules
Field
Description
Prefix
A unique identifier for the AV pair. For example:
ip:inacl#1=
(used for
standard ACLs) or
webvpn:inacl#
(used for WebVPN ACLs). This field
only appears when the filter has been sent as an AV pair.
Action
Action to perform if rule matches: deny, permit.
Protocol
Number or name of an IP protocol. Either an integer in the range 0 - 255 or
one of the following keywords: icmp, igmp, ip, tcp, udp.
Source
Network or host that sends the packet. It is specified as an IP address, a
hostname, or the keyword “any”. If specified as an IP address, the source
wildcard mask must follow.
Source Wildcard Mask
The wildcard mask applied to the source address.
Destination
Network or host that receives the packet. It is specified as an IP address, a
hostname, or the keyword “any.” If specified as an IP address, the source
wildcard mask must follow.
Destination Wildcard
Mask
The wildcard mask applied to the destination address.
Log
Generates a FILTER log message. You must use this keyword to generate
events of severity level 9.
Operator
Logic operators: greater than, less than, equal to, not equal to.
Port
The number of a TCP or UDP port in the range 0 - 65535.
Table E-4
Security Appliance-Supported Tokens
Token
Syntax Field
Description
ip:inacl#
Num
=
N/A (Identifier)
(Where
Num
is a unique integer.) Starts all AV pair access control lists. Enforces
ACLs for remote IPSec and SSL VPN (SVC) tunnels.
webvpn:inacl#
Num
=
N/A (Identifier)
(Where
Num
is a unique integer.) Starts all WebVPN AV pair access control lists.
Enforces ACLs for WebVPN clientless (browser-mode) tunnels.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......