Chapter 5 Setting Up and Managing Shared Profile Components
Downloadable PIX ACLs
5-2
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
command on each possible device. Creating and applying these named shared
profile components (access restrictions, command sets, and ACLs) makes it
unnecessary to repeatedly enter long lists of devices or commands when defining
network access parameters.
Shared profile components also enable Cisco Secure ACS to authorize a
command on behalf of another device or devices. Their scalability extends to the
following capabilities:
•
A way to determine the list of commands a user could issue against one or
more devices in the network.
•
A way to determine the list of devices on which a particular user may execute
a particular command.
Downloadable PIX ACLs
This section describes downloadable PIX ACLs followed by detailed instructions
for configuring and managing them.
About Downloadable PIX ACLs
Downloadable PIX ACLs enable you to enter an ACL once, in Cisco Secure ACS,
and then load that ACL to any number of PIX Firewalls that authenticate using the
Cisco IOS/PIX protocol. This is far more efficient than directly entering the ACL
into each PIX Firewall via its CLI. No additional configuration of the
PIX Firewall is necessary after it has been configured to undertake authorization
using RADIUS.