C H A P T E R
13-1
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
13
Configuring AAA Servers and the Local Database
This chapter describes support for AAA
(
pronounced “triple A”) and how to configure AAA servers and
the local database.
This chapter contains the following sections:
•
AAA Overview, page 13-1
•
AAA Server and Local Database Support, page 13-3
•
Configuring the Local Database, page 13-7
•
Identifying AAA Server Groups and Servers, page 13-9
•
Configuring an LDAP Server, page 13-12
•
Using Certificates and User Login Credentials, page 13-16
•
Supporting a Zone Labs Integrity Server, page 13-17
AAA Overview
AAA enables the security appliance to determine who the user is (authentication), what the user can do
(authorization), and what the user did (accounting).
AAA provides an extra level of protection and control for user access than using access lists alone. For
example, you can create an access list allowing all outside users to access Telnet on a server on the DMZ
network. If you want only some users to access the server and you might not always know IP addresses
of these users, you can enable AAA to allow only authenticated and/or authorized users to make it
through the security appliance. (The Telnet server enforces authentication, too; the security appliance
prevents unauthorized users from attempting to access the server.)
You can use authentication alone or with authorization and accounting. Authorization always requires a
user to be authenticated first. You can use accounting alone, or with authentication and authorization.
This section includes the following topics:
•
About Authentication, page 13-2
•
About Authorization, page 13-2
•
About Accounting, page 13-2
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......