15-22
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 15 Managing Firewall AAA Rules
AAA Firewall Settings Policies
Field Reference
Clear Connection Configuration Dialog Box
Use the Clear Connection Configuration dialog box to identify the source addresses whose active
connections to close immediately after the user authentication times out or when you clear the
authentication session with the clear uauth command. You must specify the interfaces on which those
sessions should be cleared. These settings are used only for FWSM 3.2+ devices.
User authentication timeouts are defined in the Platform > Security > Timeouts policy.
Navigation Path
Go to the AAA Firewall Settings Page, Advanced Setting Tab, page 15-19 and click the Add Row button
beneath the Clear Connections When Uauth Timer Expires table, or select an item in the table and click
the Edit Row button.
Field Reference
Table15-4 Interactive Authentication Configuration Dialog Box
Element Description
Protocol The protocol that you want to listen for, either HTTP or HTTPS. If you
want to listen for both protocols on an interface, add the interface to the
table twice.
Interface The interface or interface role on which to enable listeners. Enter the
name of the interface or interface role, or click Select to select it from
a list or to create a new interface role.
Port The port number that the security appliance listens on for this protocol
if other than the default, which is 80 (HTTP) and 443 (HTTPS).
Redirect network users for
authentication request
Whether to redirect users who are making requests through the device
to the authentication web page served by the security appliance. If you
do not select this option, only traffic directed to the interface is
prompted with the improved authentication web page.
Table15-5 Clear Connection Configuration Dialog Box
Element Description
Interface The interfaces or interface roles for which you are configuring settings.
Enter the name or click Select to select the interface or interface role or
to create a new role. Separate multiple entries with commas.
Source IP Address/Netmask The host or network addresses for which you want to clear connections
immediately when the user authentication timer expires. The list can
include host IP addresses, network addresses, address ranges, or
network/host objects Separate multiple addresses with commas. For
more information on entering addresses, see Specifying IP Addresses
During Policy Definition, page 6-81.