EasyManuals Logo

Cisco ASA 5506-X Configuration Guide

Cisco ASA 5506-X
428 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #75 background imageLoading...
Page #75 background image
5-15
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 Identity Firewall
Configure the Identity Firewall
Step 3 Associate the LDAP parameters defined for the AAA server for importing user group queries with the
domain name.
user-identity domain domain_nickname aaa-server aaa_server_group_tag
Example:
hostname(config)# user-identity domain SAMPLE aaa-server ds
For the domain_nickname argument, enter a name of up to 32 characters consisting of [a-z], [A-Z],
[0-9], [!@#$%^&()-_=+[]{};,. ] except '.' and ' ' at the first character. If the domain name includes a
space, you must enclose that space character in quotation marks. The domain name is not case sensitive.
Step 4 Enable NetBIOS probing.
user-identity logout-probe netbios local-system probe-time minutes minutes retry-interval
seconds seconds retry-count times [user-not-needed | match-any | exact-match]
Example:
hostname(config)# user-identity logout-probe netbios local-system probe-time minutes 10
retry-interval seconds 10 retry-count 2 user-not-needed
Enabling this option configures how often the ASA probes the user client IP address to determine
whether the client is still active. By default, NetBIOS probing is disabled. To minimize the NetBIOS
packets, the ASA only sends a NetBIOS probe to a client when the user has been idle for more than the
specified number of minutes.
Exact-match—The username of the user assigned to the IP address must be the only one in the
NetBIOS response. Otherwise, the user identity of that IP address is considered invalid.
User-not-needed—As long as the ASA received a NetBIOS response from the client, the user
identity is considered valid.
The Identity Firewall only performs NetBIOS probing for those users identities that are in the active state
and exist in at least one security policy. The ASA does not perform NetBIOS probing for clients where
the users logged in through cut-through proxy or by using a VPN.
Step 5 Specify the amount of time before a user is considered idle, meaning the ASA has not received traffic
from the user's IP address for the specified amount of time.
user-identity inactive-user-timer minutes minutes
Example:
hostname(config)# user-identity inactive-user-timer minutes 120
When the timer expires, the user's IP address is marked as inactive and removed from the local cached
user identity-IP address mapping database, and the ASA no longer notifies the AD Agent about that IP
address. Existing traffic is still allowed to pass. When this command is specified, the ASA runs an
inactive timer even when the NetBIOS Logout Probe is configured.
By default, the idle timeout is set to 60 minutes. This option does not apply to VPN or cut-through proxy
users.
Step 6 Specify the amount of time before the ASA queries the Active Directory server for user group
information.
user-identity poll-import-user-group-timer hours hours
Example:
hostname(config)# user-identity poll-import-user-group-timer hours 1

Table of Contents

Other manuals for Cisco ASA 5506-X

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASA 5506-X and is the answer not in the manual?

Cisco ASA 5506-X Specifications

General IconGeneral
ModelASA 5506-X
Firewall Throughput750 Mbps
Maximum Firewall Connections50, 000
Maximum VPN Peers50
Integrated Ports8 x 1 GE
Stateful Inspection Throughput750 Mbps
Weight4.4 lb (2 kg)
Firewall Throughput (Multiprotocol)750 Mbps
Firewall Throughput (Application Visibility and Control AVC)250 Mbps
Concurrent Sessions50, 000
New Connections per Second10, 000
IPsec VPN Throughput100 Mbps
Interfaces8 x 1 GE
Memory4 GB
Flash Memory8 GB
Form FactorDesktop
VPN Throughput100 Mbps
Maximum Concurrent Sessions50, 000
New Sessions per Second10, 000
Operating Temperature32 to 104°F (0 to 40°C)
Storage Temperature-13 to 158°F (-25 to 70°C)
Power SupplyExternal
Humidity10% to 90% non-condensing

Related product manuals