Cisco Systems OL-16647-01 Network Router User Manual


  Open as PDF
of 1230
 
23-4
Cisco ASDM User Guide
OL-16647-01
Chapter 23 Applying AAA for Network Access
Configuring Authentication for Network Access
Configuring Network Access Authentication
To enable network access authentication, perform the following steps. For more information about
authentication, see the “Information About Authentication” section on page 23-2.
Step 1 From the Configuration > Firewall > AAA Rules pane, choose Add > Add Authentication Rule.
The Add Authentication Rule dialog box appears.
Step 2 From the Interface drop-down list, choose the interface for applying the rule.
Step 3 In the Action field, click one of the following, depending on the implementation:
Authenticate
Do not Authenticate.
Step 4 From the AAA Server Group drop-down list, choose a server group. To add a AAA server to the server
group, click Add Server. See the “Configuring AAA Server Groups” section on page 14-9 for more
information.
If you chose LOCAL for the AAA server group, you can optionally add a new user by clicking Add User.
See the “Adding a User Account” section on page 14-18 for more information.
Step 5 In the Source field, add the source IP address, or click the ellipsis (...) to choose an IP address already
defined in ASDM.
Step 6 In the Destination field, enter the destination IP address, or click the ellipsis (...) to choose an IP address
already defined in ASDM.
Step 7 In the Service field, enter an IP service name or number for the destination service, or click ellipsis (...)
button to choose a service.
Step 8 (Optional) In the Description field, add a description.
Step 9 (Optional) Click More Options to do any of the following:
To specify a source service for TCP or UDP, enter a TCP or UDP service in the Source Service field.
The destination service and source service must be the same. Copy and paste the destination Service
field to the Source Service field.
To make the rule inactive, uncheck Enable Rule.
You may not want to remove a rule, but instead turn it off.
To set a time range for the rule, from the Time Range drop-down list, choose an existing time range.
To add a new time range, click the ellipsis (...). For more information, see Configuring Time Ranges,
page 19-15.
Step 10 Click OK.
The dialog box closes and the rule appears in the AAA Rules table.
Step 11 Click Apply.
The changes are saved to the running configuration.