1-31
Cisco ASA Series CLI Configuration Guide
Appendix 1 Configuring an External Server for Authorization and Authentication
Configuring an External RADIUS Server
L2TP-MPPC-Compression 38 Integer Single 0 = Disabled
1 = Enabled
Member-Of Y 145 String Single Comma-delimited string, for example:
Engineering, Sales
An administrative attribute that can be used
in dynamic access policies. It does not set a
group policy.
MS-Client-Subnet-Mask Y 63 Boolean Single An IP address
NAC-Default-ACL 92 String ACL
NAC-Enable 89 Integer Single 0 = No
1 = Yes
NAC-Revalidation-Timer 91 Integer Single 300 - 86400 seconds
NAC-Settings Y 141 String Single Name of the NAC policy
NAC-Status-Query-Timer 90 Integer Single 30 - 1800 seconds
Perfect-Forward-Secrecy-Enable Y 88 Boolean Single 0 = No
1 = Yes
PPTP-Encryption 20 Integer Single Bitmap:
1 = Encryption required
2 = 40 bits
4 = 128 bits
8 = Stateless-Required
15= 40/128-Encr/Stateless-Req
PPTP-MPPC-Compression 37 Integer Single 0 = Disabled
1 = Enabled
Primary-DNS Y 5 String Single An IP address
Primary-WINS Y 7 String Single An IP address
Privilege-Level Y 220 Integer Single An integer between 0 and 15.
Required-Client- Firewall-Vendor-Code Y 45 Integer Single 1 = Cisco Systems (with Cisco Integrated
Client)
2 = Zone Labs
3 = NetworkICE
4 = Sygate
5 = Cisco Systems (with Cisco Intrusion
Prevention Security Agent)
Required-Client-Firewall-Description Y 47 String Single String
Table 1-7 ASA Supported RADIUS Attributes and Values (continued)
Attribute Name ASA
Attr.
No.
Syntax/
Type
Single
or
Multi-
Valued Description or Value