Cisco Systems Servers Server User Manual


 
5-3
Cisco Secure ACS 3.0 for Windows 2000/NT Servers User Guide
78-13751-01, Version 3.0
Chapter 5 Setting Up and Managing Shared Profile Components
Downloadable PIX ACLs
ACLs entered into the Cisco Secure ACS are protected by whatever backup or
replication regime you have established for the Cisco Secure ACS. After you
configure an ACL as a named shared profile component, you can include that
ACL in any Cisco Secure ACS user, or user group, profile. When
Cisco Secure ACS returns an attribute with a named ACL as part of a users
session RADIUS access accept packet, the PIX Firewall applies that ACL to that
users session. Cisco Secure ACS employs a versioning stamp for ensuring that
the PIX Firewall has cached the latest ACL version. If a PIX Firewall responds
that it does not have the current version of the named ACL in its cache (that is,
the ACL is new or has changed), Cisco Secure ACS automatically uploads the
ACL update to the PIX Firewall cache.
After you configure a downloadable PIX ACL, it can be applied against any
number of single users or user groups.
Downloadable PIX ACL Configuration
This section contains the following procedures:
Adding a Downloadable PIX ACL, page 5-3
Editing a Downloadable PIX ACL, page 5-4
Deleting a Downloadable PIX ACL, page 5-5
Adding a Downloadable PIX ACL
To add a downloadable PIX ACL, follow these steps:
Step 1 In the navigation bar, click Shared Profile Components.
Result: The Shared Profile Components page appears.
Step 2 Click Downloadable PIX ACLs.
Step 3 Click Add.
Result: The Downloadable PIX ACLs page appears.
Step 4 In the Name: box, type the name of the new PIX ACL.