E-40
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Appendix E Configuring an External Server for Authorization and Authentication
Configuring an External RADIUS Server
Note
RADIUS attribute names do not contain the cVPN3000 prefix to better reflect support for all three
security appliances (VPN 3000, PIX, and the ASA). Cisco Secure ACS 4.x supports this new
nomenclature, but attribute names in pre-4.0 ACS releases still include the cVPN3000 prefix. The
appliances enforce the RADIUS attributes based on attribute numeric ID, not attribute name. LDAP
attributes are enforced by their name, not by the ID.
Security Appliance Attributes
The security appliance provides support for attributes. separates the functions of
authentication, authorization, and accounting. The protocol supports two types of attributes: mandatory
and optional. Both the server and client must understand a mandatory attribute, and the mandatory
attribute must be applied to the user. An optional attribute may or may not be understood or used.
WebVPN-File-Server-Browsing-Enable
Y
Y
96
Integer
Single
0 = Disabled
1 = Enabled
WebVPN-Port-Forwarding-Enable
Y
Y
97
Integer
Single
0 = Disabled
1 = Enabled
WebVPN-Outlook-Exchange-Proxy-Enable
Y
Y
98
Integer
Single
0 = Disabled
1 = Enabled
WebVPN-Port-Forwarding-HTTP-Proxy
Y
Y
99
Integer
Single
0 = Disabled
1 = Enabled
WebVPN-Auto-Applet-Download-Enable
Y
Y
100
Integer
Single
0 = Disabled
1 = Enabled
WebVPN-Citrix-Metaframe-Enable
Y
Y
101
Integer
Single
0 = Disabled
1 = Enabled
WebVPN-Apply-ACL
Y
Y
102
Integer
Single
0 = Disabled
1 = Enabled
WebVPN-SSL-VPN-Client-Enable
Y
Y
103
Integer
Single
0 = Disabled
1 = Enabled
WebVPN-SSL-VPN-Client-Required
Y
Y
104
Integer
Single
0 = Disabled
1 = Enabled
WebVPN-SSL-VPN-Client-Keep-
Installation
Y
Y
105
Integer
Single
0 = Disabled
1 = Enabled
Strip-Realm
Y
Y
Y
135
Boolean
Single
0 = Disabled
1 = Enabled
Table E-6
Security Appliance Supported RADIUS Attributes and Values (continued)
Attribute Name
VPN
3000
ASA
PIX
Attr.
#
Syntax/
Type
Single
or
Multi-
Valued
Description or Value
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......