
10-3
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 10 Configuring AAA Servers and the Local Database
AAA Server and Local Database Support
AAA Server and Local Database Support
The security appliance supports a variety of AAA server types and a local database that is stored on the
security appliance. This section describes support for each AAA server type and the local database.
This section contains the following topics:
• Summary of Support, page 10-3
• RADIUS Server Support, page 10-4
• TACACS+ Server Support, page 10-5
• SDI Server Support, page 10-6
• NT Server Support, page 10-7
• Kerberos Server Support, page 10-7
• LDAP Server Support, page 10-8
• Local Database Support, page 10-8
Summary of Support
Table 10-1 summarizes the support for each AAA service by each AAA server type, including the local
database. For more information about support for a specific AAA server type, refer to the topics
following the table.
Table 10-1 Summary of AAA Support
AAA Service
Database Type
Local RADIUS TACACS+ SDI NT Kerberos LDAP
Authentication of. . .
VPN users Yes Yes Yes Yes Yes Yes No
Firewall sessions Yes Yes Yes No No No No
Administrators Yes Yes Yes No No No No
Authorization of. . .
VPN users Yes Yes No No No No Yes
Firewall sessions No Yes
1
1. For firewall sessions, RADIUS authorization is supported with user-specific ACLs only, which are received
or specified in a RADIUS authentication response.
Yes NoNoNo No
Administrators Yes
2
2. Local command authorization is supported by privilege level only.
No Yes NoNoNo No
Accounting of. . .
VPN connections No Yes Yes No No No No
Firewall sessions No Yes Yes No No No No
Administrators No Yes Yes No No No No
Comentarios a estos manuales