38-26
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter38 Configuring AAA Servers and the Local Database
Configuring AAA
d. If the Inherit check box is not checked, the Maximum Connect Time parameter specifies the
maximum user connection time in minutes. At the end of this time, the system terminates the
connection. The minimum is 1 minute, and the maximum is 2147483647 minutes (over 4000 years).
To allow unlimited connection time, check the Unlimited check box (the default).
e. If the Inherit check box is not checked, the Idle Timeout parameter specifies the idle timeout period
in minutes of this user. If there is no communication activity on the connection of this user in this
period, the system terminates the connection. The minimum time is 1 minute, and the maximum time
is 10080 minutes. This value does not apply to users of clientless SSL VPN connections.
Step4 To set a dedicated IP address for this user, enter an IP address and subnet mask in the Dedicated IP
Address (Optional) area.
Step5 To configure clientless SSL settings, in the left-hand pane, click Clientless SSL VPN. To override each
setting, uncheck the Inherit check box, and enter a new value.
Step6 Click Apply.
The changes are saved to the running configuration.
Adding an Authentication Prompt
You can specify text to display to the user during the AAA authentication challenge process. You can
specify the AAA challenge text for HTTP, FTP, and Telnet access through the ASA when requiring user
authentication from TACACS+ or RADIUS servers. This text is primarily for cosmetic purposes and
appears above the username and password prompts that users see when they log in.
If you do not specify an authentication prompt, users see the following when authenticating with a
RADIUS or TACACS+ server:
To add an authentication prompt, perform the following steps:
Step1 From the Configuration > Device Management > Users/AAA > Authentication Prompt pane, enter text
in the Prompt field to add as a message to appear above the username and password prompts that users
see when they log in.
The following table shows the allowed character limits for authentication prompts:
Connection Type Default Prompt
FTP FTP authentication
HTTP HTTPAuthentication
Telne t None
Application
Character Limit for
Authentication Prompt
Microsoft Internet Explorer 37
Telnet 235
FTP 235