13-4
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 13 Configuring AAA Servers and the Local Database
AAA Server and Local Database Support
RADIUS Server Support
The security appliance supports RADIUS servers.
This section contains the following topics:
•
Authentication Methods, page 13-4
•
Attribute Support, page 13-4
•
RADIUS Authorization Functions, page 13-4
Authentication Methods
The security appliance supports the following authentication methods with RADIUS:
•
PAP—For all connection types.
•
CHAP—For L2TP-over-IPSec.
•
MS-CHAPv1—For L2TP-over-IPSec.
•
MS-CHAPv2—For L2TP-over-IPSec, and for regular IPSec remote access connections when the
password management feature is enabled.
Attribute Support
The security appliance supports the following sets of RADIUS attributes:
•
Authentication attributes defined in RFC 2138.
•
Accounting attributes defined in RFC 2139.
•
RADIUS attributes for tunneled protocol support, defined in RFC 2868.
•
Cisco IOS VSAs, identified by RADIUS vendor ID 9.
•
Cisco VPN-related VSAs, identified by RADIUS vendor ID 3076.
•
Microsoft VSAs, defined in RFC 2548.
RADIUS Authorization Functions
The security appliance can use RADIUS servers for user authorization for network access using dynamic
access lists or access list names per user. To implement dynamic access lists, you must configure the
RADIUS server to support it. When the user authenticates, the RADIUS server sends a downloadable
access list or access list name to the security appliance. Access to a given service is either permitted or
denied by the access list. The security appliance deletes the access list when the authentication session
expires.
Server Support
The security appliance supports authentication with ASCII, PAP, CHAP, and MS-CHAPv1.
4.
Local command authorization is supported by privilege level only.
5.
Command accounting is available for only.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......