38-11
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter38 Configuring AAA Servers and the Local Database
Configuring AAA
Step2 For a server group, add a server to the group. See the “Adding a Server to a Group” section on
page 38-13.
Step3 For a server group, configure server parameters. See the “Configuring AAA Server Parameters” section
on page 38-13.
Step4 For an LDAP server, configure LDAP attribute maps. See the “Configuring LDAP Attribute Maps”
section on page 38-20.
Step5 (Optional) Specify text to display to the user during the AAA authentication challenge process. See the
“Adding an Authentication Prompt” section on page38-26.
Step6 For an administrator, specify the password policy attributes for users. See the “Managing User
Passwords” section on page 38-27.
Step7 (Optional) Users can change their own passwords. See the “Changing User Passwords” section on
page 38-28.
Step8 (Optional) Users can authenticate with a public key. See the “Authenticating Users with a Public Key for
SSH” section on page 38-28.
Configuring AAA Server Groups
If you want to use an external AAA server for authentication, authorization, or accounting, you must first
create at least one AAA server group per AAA protocol and add one or more servers to each group. You
identify AAA server groups by name. Each server group is specific to one type of server: Kerberos,
LDAP, NT, RADIUS, SDI, or TACACS+.
Guidelines
You can have up to 100 server groups in single mode or 4 server groups per context in multiple mode.
Each group can have up to 16 servers in single mode or 4 servers in multiple mode.
When a user logs in, the servers are accessed one at a time, starting with the first server you specify
in the configuration, until a server responds. If all servers in the group are unavailable, the ASA tries
the local database if you configured it as a fallback method (management authentication and
authorization only). If you do not have a fallback method, the ASA continues to try the AAA servers.
Detailed Steps
To add a server group, perform the following steps:
Step1 Choose Configuration > Device Management > Users/AAA > AAA Server Groups.
Step2 In the AAA Server Groups area, click Add.
The Add AAA Server Group dialog box appears.
Step3 In the Server Group field, enter a name for the group.
Step4 From the Protocol drop-down list, choose the server type:
RADIUS
TACAC S+
SDI