Cisco Systems OL-16647-01 Network Router User Manual


  Open as PDF
of 1230
 
C-7
Cisco ASDM User Guide
OL-16647-01
Appendix C Configuring an External Server for Authorization and Authentication
Configuring an External LDAP Server
DHCP-Network-Scope Y Y Y String Single IP address
DN-Field Y Y Y String Single Possible values: UID, OU, O, CN,
L, SP, C, EA, T, N, GN, SN, I,
GENQ, DNQ, SER,
use-entire-name.
Firewall-ACL-In Y Y String Single Access list ID
Firewall-ACL-Out Y Y String Single Access list ID
IE-Proxy-Bypass-Local Boolean Single 0=Disabled
1=Enabled
IE-Proxy-Exception-List String Single A list of DNS domains. Entries must
be separated by the new line
character sequence (\n).
IE-Proxy-Method Y Y Y Integer Single 1 = Do not modify proxy settings
2 = Do not use proxy
3 = Auto detect
4 = Use security appliance setting
IE-Proxy-Server Y Y Y Integer Single IP Address
IETF-Radius-Class Y Y Y Single Sets the group policy for the remote
access VPN session
IETF-Radius-Filter-Id Y Y Y String Single access list name that is defined on
the security appliance
IETF-Radius-Framed-IP-Address Y Y Y String Single An IP address
IETF-Radius-Framed-IP-Netmask Y Y Y String Single An IP address mask
IETF-Radius-Idle-Timeout Y Y Y Integer Single minutes
IETF-Radius-Service-Type Y Y Y Integer Single
IETF-Radius-Session-Timeout Y Y Y Integer Single
IKE-Keep-Alives Y Y Y Boolean Single 0 = Disabled
1 = Enabled
IPSec-Allow-Passwd-Store Y Y Y Boolean Single 0 = Disabled
1 = Enabled
IPSec-Authentication Y Y Y Integer Single 0 = None
1 = RADIUS
2 = LDAP (authorization only)
3 = NT Domain
4 = SDI (RSA)
5 = Internal
6 = RADIUS with Expiry
7 = Kerberos/Active Directory
IPSec-Auth-On-Rekey Y Y Y Boolean Single 0 = Disabled
1 = Enabled
IPSec-Backup-Server-List Y Y Y String Single Server Addresses (space delimited)
Table C-2 Security Appliance Supported Cisco Attributes for LDAP Authorization (continued)
Attribute Name/ VPN 3000 ASA PIX
Syntax/
Type
Single or
Multi-Valued Possible Values