Cisco Systems OL-12180-01 manual AAA Overview, About Authentication, 12-1

Page 1

C H A P T E R 12

Configuring AAA Servers and User Accounts

This chapter describes support for AAA (pronounced “triple A”) and how to configure AAA servers and the local database.

This chapter contains the following sections:

AAA Overview, page 12-1

AAA Server and Local Database Support, page 12-2

Configuring the Local Database, page 12-7

Identifying AAA Server Groups and Servers, page 12-12

Configuring an Authentication Prompt, page 12-20

Configuring an LDAP Attribute Map, page 12-21

AAAOverview

AAAenables the security appliance to determine who the user is (authentication), what the user can do (authorization), and what the user did (accounting).

AAAprovides an extra level of protection and control for user access than using access lists alone. For example, you can create an access list allowing all outside users to access Telnet on a server on the DMZ network. If you want only some users to access the server and you might not always know IP addresses of these users, you can enable AAA to allow only authenticated and/or authorized users to make it through the security appliance. (The Telnet server enforces authentication, too; the security appliance prevents unauthorized users from attempting to access the server.)

You can use authentication alone or with authorization and accounting. Authorization always requires a user to be authenticated first. You can use accounting alone, or with authentication and authorization.

This section includes the following topics:

About Authentication, page 12-1

About Authorization, page 12-2

About Accounting, page 12-2

About Authentication

Authentication controls access by requiring valid user credentials, which are typically a username and password. You can configure the security appliance to authenticate the following items:

 

 

ASDM User Guide

 

 

 

 

 

 

 

OL-12180-01

 

 

12-1

 

 

 

 

 

Image 1
Contents AAA Overview About Authentication12-1 AAA Server and Local Database Support About AuthorizationAbout Accounting 12-2Radius Server Support Summary of Support12-3 Radius Authorization Functions Authentication MethodsTACACS+ Server Support SDI Server SupportNT Server Support Two-step Authentication ProcessKerberos Server Support SDI Version SupportSSO Support for Clientless SSL VPN with Http Forms Ldap Server SupportLocal Database Support 12-6User Profiles Configuring the Local DatabaseFallback Support 12-712-8 User Accounts12-9 Add/Edit User Account Identity12-10 Add/Edit User Account VPN Policy12-11 AAA Server Groups Identifying AAA Server Groups and Servers12-12 12-13 12-14 Add/Edit AAA Server GroupAdd/Edit AAA Server Edit AAA Local Server Group12-15 12-16 12-17 12-18 12-19 Test AAA Server12-20 Configuring an Authentication Prompt12-21 Configuring an Ldap Attribute MapAdd/Edit Ldap Attribute Map Map Name Tab Add/Edit Ldap Attribute Map12-22 Add/Edit Ldap Attributes Value Map Add/Edit Ldap Attribute Map Map Value Tab12-23 12-24