Contents
xxxiii
Cisco ASA 5500 Series Configuration Guide using ASDM
Configuring AAA for System Administrators 40-15
Information About AAA for System Administrators 40-15
Information About Management Authentication 40-15
Information About Command Authorization 40-16
Licensing Requirements for AAA for System Administrators 40-18
Prerequisites 40-18
Guidelines and Limitations 40-19
Default Settings 40-19
Configuring Authentication for CLI, ASDM, and enable command Access 40-20
Limiting User CLI and ASDM Access with Management Authorization 40-21
Configuring Command Authorization 40-22
Configuring Local Command Authorization 40-22
Viewing Local Command Privilege Levels 40-23
Configuring Commands on the TACACS+ Server 40-24
Configuring TACACS+ Command Authorization 40-27
Configuring Management Access Accounting 40-28
Viewing the Currently Logged-In User 40-28
Recovering from a Lockout 40-29
Setting a Management Session Quota 40-30
Monitoring Device Access 40-30
Feature History for Management Access 40-32
CHAPTER
41 Configuring AAA Rules for Network Access 41-1
AAA Performance 41-1
Licensing Requirements for AAA Rules 41-1
Guidelines and Limitations 41-2
Configuring Authentication for Network Access 41-2
Information About Authentication 41-2
One-Time Authentication 41-3
Applications Required to Receive an Authentication Challenge 41-3
ASA Authentication Prompts 41-3
Static PAT and HTTP 41-4
Configuring Network Access Authentication 41-4
Enabling the Redirection Method of Authentication for HTTP and HTTPS 41-5
Enabling Secure Authentication of Web Clients 41-6
Authenticating Directly with the ASA 41-7
Authenticating HTTP(S) Connections with a Virtual Server 41-7
Authenticating Telnet Connections with a Virtual Server 41-8
Configuring the Authentication Proxy Limit 41-9