Cisco Systems OL-12180-01 TACACS+ Server Support, SDI Server Support, Authentication Methods

Page 4

Chapter 12 Configuring AAA Servers and User Accounts

AAA Server and Local Database Support

This section contains the following topics:

Authentication Methods, page 12-4

Attribute Support, page 12-4

RADIUS Authorization Functions, page 12-4

Authentication Methods

The security appliance supports the following authentication methods with RADIUS:

PAP—For all connection types.

CHAP—For L2TP-over-IPSec.

MS-CHAPv1—For L2TP-over-IPSec.

MS-CHAPv2—For L2TP-over-IPSec, and for regular IPSec remote access connections when the password management feature is enabled.

Attribute Support

The security appliance supports the following sets of RADIUS attributes:

Authentication attributes defined in RFC 2138.

Accounting attributes defined in RFC 2139.

RADIUS attributes for tunneled protocol support, defined in RFC 2868.

Cisco IOS VSAs, identified by RADIUS vendor ID 9.

Cisco VPN-related VSAs, identified by RADIUS vendor ID 3076.

Microsoft VSAs, defined in RFC 2548.

RADIUS Authorization Functions

The security appliance can use RADIUS servers for user authorization for network access using dynamic access lists or access list names per user. To implement dynamic access lists, you must configure the RADIUS server to support it. When the user authenticates, the RADIUS server sends a downloadable access list or access list name to the security appliance. Access to a given service is either permitted or denied by the access list. The security appliance deletes the access list when the authentication session expires.

TACACS+ Server Support

The security appliance supports TACACS+ authentication with ASCII, PAP, CHAP, and MS-CHAPv1.

SDI Server Support

The RSA SecureID servers are also known as SDI servers.

This section contains the following topics:

SDI Version Support, page 12-5

 

ASDM User Guide

12-4

OL-12180-01

Image 4
Contents AAA Overview About Authentication12-1 About Authorization AAA Server and Local Database SupportAbout Accounting 12-2Radius Server Support Summary of Support12-3 Authentication Methods Radius Authorization FunctionsTACACS+ Server Support SDI Server SupportTwo-step Authentication Process NT Server SupportKerberos Server Support SDI Version SupportLdap Server Support SSO Support for Clientless SSL VPN with Http FormsLocal Database Support 12-6Configuring the Local Database User ProfilesFallback Support 12-7User Accounts 12-8Add/Edit User Account Identity 12-9Add/Edit User Account VPN Policy 12-1012-11 AAA Server Groups Identifying AAA Server Groups and Servers12-12 12-13 Add/Edit AAA Server Group 12-14Add/Edit AAA Server Edit AAA Local Server Group12-15 12-16 12-17 12-18 Test AAA Server 12-19Configuring an Authentication Prompt 12-20Configuring an Ldap Attribute Map 12-21Add/Edit Ldap Attribute Map Map Name Tab Add/Edit Ldap Attribute Map12-22 Add/Edit Ldap Attributes Value Map Add/Edit Ldap Attribute Map Map Value Tab12-23 12-24