User Management
Configuring the User Authentication Settings
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
279
9
Using Local Database for Authentication
Use the local database to authenticate the users when the number of users
accessing the network is less than 100 users. When you use the local database for
authentication, the local database verifies the user name and password
information of the users who try to access the network. Only the valid local users
are allowed to access the network.
STEP 1
Click
Users -> Settings
.
The User Settings window opens.
STEP 2
In the
User Login Settings
area, choose
Local Database
as the authentication
method from the
Authentication Method
drop-down list.
STEP 3
Click
Save
to apply your settings.
Using RADIUS Server for Authentication
Use the RADIUS server to authenticate the users when more than 100 users need
to access the network. The security appliance uses the Framed-Filter-ID attribute
to store the user and group information in the RADIUS server, and checks a user’s
credentials by using the Password Authentication Protocol (PAP) authentication
scheme.
If you use RADIUS for user authentication, users must log into the security
appliance using HTTPS in order to encrypt the password. The security appliance
verifies the user name and password information of the users through the RADIUS
server. The RADIUS server returns the authentication result to the security
appliance. For a valid RADIUS user, the security appliance checks its user group
service policy from the local database and permits the access. For a invalid
RADIUS user, the security appliance denies the access.
NOTE
The user group service policies can only be configured locally. All user groups on
an AAA server need to be duplicated locally.
STEP 1
Click
Users -> Settings
.
The User Settings window opens.