38-14
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter38 Configuring AAA Servers and the Local Database
Configuring AAA
Kerberos Server Fields, page38-16
LDAP Server Fields, page38-17
HTTP Form Server Fields, page 38-19
For more information, see the “Adding a Server to a Group” section on page38-13.
RADIUS Server Fields
The following table describes the unique fields for configuring RADIUS servers, for use with the
“Adding a Server to a Group” section on page38-13.
Field Description
ACL Netmask Convert How you want the ASA to handle netmasks received in downloadable
access lists.
Detect automatically: The ASA attempts to determine the type of
netmask expression used. If the ASA detects a wildcard netmask
expression, the ASA converts it to a standard netmask expression.
Note Because some wildcard expressions are difficult to detect
clearly, this setting may misinterpret a wildcard netmask
expression as a standard netmask expression.
Standard: The ASA assumes downloadable access lists received
from the RADIUS server contain only standard netmask
expressions. No translation from wildcard netmask expressions is
performed.
Wildcard: The ASA assumes downloadable access lists received
from the RADIUS server contain only wildcard netmask
expressions, and it converts them all to standard netmask
expressions when the access lists are downloaded.
Common Password A case-sensitive password that is common among users who access this
RADIUS authorization server through this ASA. Be sure to provide this
information to your RADIUS server administrator.
Note For an authentication RADIUS server (rather than
authorization), do not configure a common password.
If you leave this field blank, the user username is the password for
accessing this RADIUS authorization server.
Never use a RADIUS authorization server for authentication. Common
passwords or usernames as passwords are less secure than assigning
unique user passwords.
Note Although the password is required by the RADIUS protocol and
the RADIUS server, users do not need to know it.