1-21
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Connection Profiles, Group Policies, and Users
Configuring Connection Profiles
The authentication-server-group name identifies a previously configured authentication server or group
of servers. Use the
aaa-server
command to configure authentication servers. The maximum length of
the group tag is 16 characters.
You can also configure interface-specific authentication by including the name of an interface in
parentheses before the group name. The following interfaces are available by default:
•
inside—Name of interface GigabitEthernet0/1
•
outside— Name of interface GigabitEthernet0/0
Note
The ASA’s outside interface address (for both IPv4/IPv6) cannot overlap with the private side
address space.
Other interfaces you have configured (using the
interface
command) are also available. The following
command configures interface-specific authentication for the interface named outside using the server
servergroup1 for authentication:
hostname(config-tunnel-general)#
authentication-server-group (outside) servergroup1
hostname(config-tunnel-general)#
Step 3
Optionally, specify the name of the authorization-server group, if any, to use. If you are not using
authorization, go to Step 6. When you configure this value, users must exist in the authorization database
to connect:
hostname(config-tunnel-general)#
authorization-server-group
groupname
hostname(config-tunnel-general)#
Use the
aaa-server
command to configure authorization servers. The maximum length of the group tag
is 16 characters.
For example, the following command specifies the use of the authorization-server group FinGroup:
hostname(config-tunnel-general)#
authorization-server-group
FinGroup
hostname(config-tunnel-general)#
Step 4
Specify whether to require a successful authorization before allowing a user to connect. The default is
not to require authorization.
hostname(config-tunnel-general)#
authorization-required
hostname(config-tunnel-general)#
Step 5
Specify the attribute or attributes to use in deriving a name for an authorization query from a certificate.
This attribute specifies what part of the subject DN field to use as the username for authorization:
hostname(config-tunnel-general)#
authorization-dn-attributes
{
primary-attribute
[
secondary-attribute
] |
use-entire-name
}
For example, the following command specifies the use of the CN attribute as the username for
authorization:
hostname(config-tunnel-general)#
authorization-dn-attributes CN
hostname(config-tunnel-general)#
The authorization-dn-attributes are
C
(Country),
CN
(Common Name),
DNQ
(DN qualifier),
EA
(E-mail Address),
GENQ
(Generational qualifier),
GN
(Given Name),
I
(Initials),
L
(Locality),
N
(Name),
O
(Organization),
OU
(Organizational Unit),
SER
(Serial Number),
SN
(Surname),
SP
(State/Province),
T
(Title),
UID
(User ID), and
UPN
(User Principal Name).
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......