30-27
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 30 Configuring Connection Profiles, Group Policies, and Users
Configuring Connection Profiles
hostname#
tunnel-group sales webvpn-attributes
hostname(config-tunnel-webvpn)#
customization salesgui
Step 5
Set the group URL to the address that the user enters into the browser to log in to the security appliance;
for example, if the security appliance has the IP address 192.168.3.3, set the group URL to
https://192.168.3.3:
hostname(config-tunnel-webvpn)#
group-url https://192.168.3.3.
hostname(config-tunnel-webvpn)#
If a port number is required for a successful login, include the port number, preceded by a colon. The
security appliance maps this URL to the sales connection profile and applies the salesgui customization
profile to the login screen that the user sees upon logging in to https://192.168.3.3.
Configuring Microsoft Active Directory Settings for Password Management
Note
If you are using an LDAP directory server for authentication, password management is supported with
the Sun Microsystems JAVA System Directory Server (formerly named the Sun ONE Directory Server)
and the Microsoft Active Directory.
•
Sun—The DN configured on the security appliance to access a Sun directory server must be able to
access the default password policy on that server. We recommend using the directory administrator,
or a user with directory administrator privileges, as the DN. Alternatively, you can place an ACI on
the default password policy.
•
Microsoft—You must configure LDAP over SSL to enable password management with Microsoft
Active Directory.
See the
“Setting the LDAP Server Type” section on page 13-13
for more information.
To use password management with Microsoft Active Directory, you must set certain Active Directory
parameters as well as configuring password management on the security appliance. This section
describes the Active Directory settings associated with various password management actions. These
descriptions assume that you have also enabled password management on the security appliance and
configured the corresponding password management attributes. The specific steps in the following
sections refer to Active Directory terminology under Windows 2000.
•
Using Active Directory to Force the User to Change Password at Next Logon, page 30-28
.
•
Using Active Directory to Specify Maximum Password Age, page 30-29
.
•
Using Active Directory to Override an Account Disabled AAA Indicator, page 30-30
•
Using Active Directory to Enforce Password Complexity, page 30-32
.
The following sections assume that you are using an LDAP directory server for authentication.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......