1-29
Cisco ASA Series CLI Configuration Guide
Appendix 1 Configuring an External Server for Authorization and Authentication
Configuring an External RADIUS Server
Group-Policy Y 25 String Single Sets the group policy for the remote access
VPN session. For Versions 8.2 and later, use
this attribute instead of IETF-Radius-Class.
You can use one of the three following
formats:
• group policy name
• OU=group policy name
• OU=group policy name;
IE-Proxy-Bypass-Local 83 Integer Single 0 = None
1 = Local
IE-Proxy-Exception-List 82 String Single New line (\n) separated list of DNS domains
IE-Proxy-PAC-URL Y 133 String Single PAC Address String
IE-Proxy-Server 80 String Single IP address
IE-Proxy-Server-Policy 81 Integer Single 1 = No Modify
2 = No Proxy
3 = Auto detect
4 = Use Concentrator Setting
IKE-KeepAlive-Confidence-Interval Y 68 Integer Single 10 - 300 seconds
IKE-Keepalive-Retry-Interval Y 84 Integer Single 2 - 10 seconds
IKE-Keep-Alives Y 41 Boolean Single 0 = Disabled
1 = Enabled
Intercept-DHCP-Configure-Msg Y 62 Boolean Single 0 = Disabled
1 = Enabled
IPsec-Allow-Passwd-Store Y 16 Boolean Single 0 = Disabled
1 = Enabled
IPsec-Authentication 13 Integer Single 0 = None
1 = RADIUS
2 = LDAP (authorization only)
3 = NT Domain
4 = SDI
5 = Internal
6 = RADIUS with Expiry
7 = Kerberos/Active Directory
IPsec-Auth-On-Rekey Y 42 Boolean Single 0 = Disabled
1 = Enabled
IPsec-Backup-Server-List Y 60 String Single Server Addresses (space delimited)
IPsec-Backup-Servers Y 59 String Single 1 = Use Client-Configured list
2 = Disable and clear client list
3 = Use Backup Server list
Table 1-7 ASA Supported RADIUS Attributes and Values (continued)
Attribute Name ASA
Attr.
No.
Syntax/
Type
Single
or
Multi-
Valued Description or Value