Cisco PIX 525 Especificaciones Pagina 130

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 604
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 129
10-12
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 10 Configuring AAA Servers and the Local Database
Identifying AAA Server Groups and Servers
unresponsive, and the fallback method is tried. The server group remains marked as unresponsive
for a period of 10 minutes (by default) so that additional AAA requests within that period do not
attempt to contact the server group, and the fallback method is used immediately. To change the
unresponsive period from the default, see the reactivation-mode command in the following step.
If you do not have a fallback method, the security appliance continues to retry the servers in the
group.
c. If you want to specify the method (reactivation policy) by which failed servers in a group are
reactivated, use the reactivation-mode command. For more information about this command, see
the Cisco Security Appliance Command Reference.
d. If you want to indicate whether accounting messages are sent to a single server (single mode) or sent
to all servers in the group (simultaneous mode), use the accounting-mode command. For more
information about this command, see the Cisco Security Appliance Command Reference.
e. When you have finished configuring the AAA server group, enter exit.
Step 2 For each AAA server on your network, follow these steps:
a. Identify the server, including the AAA server group it belongs to. To do so, enter the following
command:
hostname/contexta(config)# aaa-server
server_group
(
interface_name
) host
server_ip
When you enter a aaa-server host command, you enter host mode.
b. As needed, use host mode commands to further configure the AAA server.
The commands in host mode do not apply to all AAA server types. Table 10-5 lists the available
commands, the server types they apply to, and whether a new AAA server definition has a default
value for that command. Where a command is applicable to the server type you specified and no
default value is provided (indicated by “—”), use the command to specify the value. For more
information about these commands, see the Cisco Security Appliance Command Reference.
Table 10-5 Host Mode Commands, Server Types, and Defaults
Command Applicable AAA Server Types Default Value
accounting-port RADIUS 1646
authentication-port RADIUS 1645
kerberos-realm Kerberos
key RADIUS
TAC ACS+
ldap-base-dn LDAP
ldap-login-dn LDAP
ldap-login-password LDAP
ldap-naming-attribute LDAP
ldap-scope LDAP
nt-auth-domain-controller NT
radius-common-pw RADIUS
retry-interval Kerberos 10 seconds
RADIUS 10 seconds
sdi-pre-5-slave SDI
Vista de pagina 129
1 2 ... 125 126 127 128 129 130 131 132 133 134 135 ... 603 604

Comentarios a estos manuales

Sin comentarios