B-38
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Appendix B Configuring an External Server for Authorization and Authentication
Configuring an External RADIUS Server
Security Appliance IETF RADIUS Authorization Attributes
Table B-8 list all the possible IETF Radius attributes.
WebVPN-Macro-Value1 Y 223 String Single Unbounded. See the
SSL VPN Deployment Guide for
examples and use cases at this
URL:
http://supportwiki.cisco.com/Vi
ewWiki/index.php/Cisco_ASA
_5500_SSL_VPN_Deployment
_Guide%2C_Version_8.x
WebVPN-Macro-Value2 Y 224 String Single Unbounded. See the
SSL VPN Deployment Guide for
examples and use cases at this
URL:
http://supportwiki.cisco.com/Vi
ewWiki/index.php/Cisco_ASA
_5500_SSL_VPN_Deployment
_Guide%2C_Version_8.x
Table B-7 Security Appliance Supported RADIUS Attributes and Values (continued)
Attribute Name
VPN
3000 ASA PIX
Attr.
#
Syntax/
Type
Single
or
Multi-
Valued Description or Value
Table B-8 Security Appliance Supported IETF RADIUS Attributes and Values
Attribute Name
VPN
3000 ASA PIX
Attr.
#
Syntax/
Type
Single or
Multi-
Valued Description or Value
IETF-Radius-Class Y Y Y 25 Single Sets the group policy for the remote
access VPN session. For 8.2 and
later, we recommend that you use
the Group-Policy attribute. You can
use one of the three following
formats:
• <group policy name>
• OU=<group policy name>
• OU=<group policy name>;
IETF-Radius-Filter-Id Y Y Y 11 String Single Access list name that is defined on
the adaptive security appliance. This
applies only to full tunnel IPsec and
SSL VPN clients
IETF-Radius-Framed-IP-Address Y Y Y n/a String Single An IP address
IETF-Radius-Framed-IP-Netmask Y Y Y n/a String Single An IP address mask