Cisco PIX 525 Specifikace Strana 122

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 604
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 121
10-4
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 10 Configuring AAA Servers and the Local Database
AAA Server and Local Database Support
RADIUS Server Support
The security appliance supports RADIUS servers.
This section contains the following topics:
Authentication Methods, page 10-4
Attribute Support, page 10-4
RADIUS Functions, page 10-4
Authentication Methods
The security appliance supports the following authentication methods with RADIUS:
PAP
CHAP
MS-CHAPv1
MS-CHAPv2 (including password aging), for IPSec users only
Attribute Support
The security appliance supports the following sets of RADIUS attributes:
Authentication attributes defined in RFC 2138.
Accounting attributes defined in RFC 2139.
RADIUS attributes for tunneled protocol support, defined in RFC 2868.
Cisco IOS VSAs, identified by RADIUS vendor ID 9.
Cisco VPN-related VSAs, identified by RADIUS vendor ID 3076.
Microsoft VSAs, defined in RFC 2548.
RADIUS Functions
The security appliance can use RADIUS servers for the functionality described in Table 10-2.
Table 10-2 RADIUS Functions
Functions Description
User authentication for CLI access When a user attempts to access the security appliance with Telnet, SSH, HTTP, or a
serial console connection and the traffic matches an authentication statement, the
security appliance challenges the user for a username and password, sends these
credentials to the RADIUS server, and grants or denies user CLI access based on the
response from the server.
User authentication for the enable
command
When a user attempts to access the enable command, the security appliance
challenges the user for a password, sends to the RADIUS server the username and
enable password, and grants or denies user access to enable mode based on the
response from the server.
Accounting for CLI access You can configure the security appliance to send accounting information to a
RADIUS server about administrative sessions.
Zobrazit stránku 121
1 2 ... 117 118 119 120 121 122 123 124 125 126 127 ... 603 604

Komentáře k této Příručce

Žádné komentáře