Contents
ix
Cisco Security Appliance Command Line Configuration Guide
OL-10088-01
Verifying the IPv6 Configuration 12-11
The show ipv6 interface Command 12-11
The show ipv6 route Command 12-12
CHAPTER
13 Configuring AAA Servers and the Local Database 13-1
AAA Overview 13-1
About Authentication 13-1
About Authorization 13-2
About Accounting 13-2
AAA Server and Local Database Support 13-2
Summary of Support 13-3
RADIUS Server Support 13-3
Authentication Methods 13-4
Attribute Support 13-4
RADIUS Authorization Functions 13-4
TACACS+ Server Support 13-4
SDI Server Support 13-4
SDI Version Support 13-5
Two-step Authentication Process 13-5
SDI Primary and Replica Servers 13-5
NT Server Support 13-5
Kerberos Server Support 13-5
LDAP Server Support 13-6
Authentication with LDAP 13-6
Authorization with LDAP for VPN 13-7
LDAP Attribute Mapping 13-8
SSO Support for WebVPN with HTTP Forms 13-9
Local Database Support 13-9
User Profiles 13-10
Fallback Support 13-10
Configuring the Local Database 13-10
Identifying AAA Server Groups and Servers 13-12
Using Certificates and User Login Credentials 13-15
Using User Login Credentials 13-15
Using certificates 13-16
Supporting a Zone Labs Integrity Server 13-16
Overview of Integrity Server and Security Appliance Interaction 13-17
Configuring Integrity Server Support 13-17