70-13
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter70 Configuring Dynamic Access Policies
Testing Dynamic Access Policies
Testing Dynamic Access Policies
Figure70-3 Test Dynamic Access Policies Pane
This pane lets you test the retrieval of the set of DAP records configured on the device by specifying
authorization attribute value pairs. To specify these pairs, use the Add/Edit buttons associated with the
AAA Attribute and Endpoint Attribute tables. The dialogs that display when you click these Add/Edit
buttons are similar to those in the Add/Edit AAA Attributes and Add/Edit Endpoint Attributes dialog
boxes.
When you enter attribute value pairs and click the “Test” button, the DAP subsystem on the device
references these values when evaluating the AAA and endpoint selection attributes for each record. The
results display in the “Test Results” text area.
Fields
Selection Criteria—Determine the AAA and endpoint attributes to test for dynamic access policy
retrieval.
AAA Attributes
AAA Attribute—Identifies the AAA attribute.
Operation Value—Identifies the attribute as =/!= to the given value.
Add/Edit—Click to add or edit a AAA attribute.
Endpoint Attributes—Identifies the endpoint attribute.
Endpoint ID—Provides the endpoint attribute ID.
Name/Operation/Value—
Add/Edit/Delete—Click to add, edit or delete and endpoint attribute.