E-41
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Appendix E Configuring an External Server for Authorization and Authentication
Configuring an External RADIUS Server
Note
To use attributes, make sure you have enabled AAA services on the NAS.
Table E-7
lists supported authorization response attributes for cut-through-proxy
connections.
Table E-8
lists supported accounting attributes.
.
Table E-7
Supported Authorization Response Attributes
Attribute
Description
acl
Identifies a locally configured access list to be applied to the connection.
idletime
Indicates the amount of inactivity in minutes that is allowed before the
authenticated user session is terminated.
timeout
Specifies the absolute amount of time in minutes that authentication credentials
remain active before the authenticated user session is terminated.
Table E-8
Supported Accounting Attributes
Attribute
Description
bytes_in
Specifies the number of input bytes transferred during this connection (stop
records only).
bytes_out
Specifies the number of output bytes transferred during this connection (stop
records only).
cmd
Defines the command executed (command accounting only).
disc-cause
Indicates the numeric code that identifies the reason for disconnecting (stop
records only).
elapsed_time
Defines the elapsed time in seconds for the connection (stop records only).
foreign_ip
Specifies the IP address of the client for tunnel connections. Defines the address
on the lowest security interface for cut-through-proxy connections.
local_ip
Specifies the IP address that the client connected to for tunnel connections. Defines
the address on the highest security interface for cut-through-proxy connections.
NAS port
Contains a session ID for the connection.
packs_in
Specifies the number of input packets transferred during this connection.
packs_out
Specifies the number of output packets transferred during this connection.
priv-level
Set to the user’s privilege level for command accounting requests or to 1 otherwise.
rem_iddr
Indicates the IP address of the client.
service
Specifies the service used. Always set to “shell” for command accounting only.
task_id
Specifies a unique task ID for the accounting transaction.
username
Indicates the name of the user.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......