30-36
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 30 Configuring Connection Profiles, Group Policies, and Users
Group Policies
Configuring Group Policies
A group policy can apply to any kind of tunnel. In each case, if you do not explicitly define a parameter,
the group takes the value from the default group policy. To configure a group policy, follow the steps in
the subsequent sections.
Configuring an External Group Policy
External group policies take their attribute values from the external server that you specify. For an
external group policy, you must identify the AAA server group that the security appliance can query for
attributes and specify the password to use when retrieving attributes from the external AAA server
group. If you are using an external authentication server, and if your external group-policy attributes
exist in the same RADIUS server as the users that you plan to authenticate, you have to make sure that
there is no name duplication between them.
Note
External group names on the security appliance refer to user names on the RADIUS server. In other
words, if you configure external group X on the security appliance, the RADIUS server sees the query
as an authentication request for user X. So external groups are really just user accounts on the RADIUS
server that have special meaning to the security appliance. If your external group attributes exist in the
same RADIUS server as the users that you plan to authenticate, there must be no name duplication
between them.
The security appliance supports user authorization on an external LDAP or RADIUS server. Before you
configure the security appliance to use an external server, you must configure the server with the correct
security appliance authorization attributes and, from a subset of these attributes, assign specific
permissions to individual users. Follow the instructions in
Appendix E, “Configuring an External Server
for Authorization and Authentication”
to configure your external server.
To configure an external group policy, do the following steps specify a name and type for the group
policy, along with the server-group name and a password:
hostname(config)#
group-policy
group_policy_name
type
server-group
server_group_name
password
server_
password
hostname(config)#
Note
For an external group policy, RADIUS is the only supported AAA server type.
For example, the following command creates an external group policy named ExtGroup that gets its
attributes from an external RADIUS server named ExtRAD and specifies that the password to use when
retrieving the attributes is newpassword:
hostname(config)#
group-policy ExtGroup external server-group ExtRAD password newpassword
hostname(config)#
Note
You can configure several vendor-specific attributes (VSAs), as described in
Appendix E, “Configuring
an External Server for Authorization and Authentication”
. If a RADIUS server is configured to return
the Class attribute (#25), the security appliance uses that attribute to authenticate the Group Name. On
the RADIUS server, the attribute must be formatted as: OU=
groupname
; where
groupname
is identical
to the Group Name configured on the security appliance—for example, OU=Finance.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......