1-3
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring AAA Servers and the Local Database
Information About AAA
Information About Accounting
Accounting tracks traffic that passes through the ASA, enabling you to have a record of user activity. If
you enable authentication for that traffic, you can account for traffic per user. If you do not authenticate
the traffic, you can account for traffic per IP address. Accounting information includes session start and
stop times, username, the number of bytes that pass through the ASA for the session, the service used,
and the duration of each session.
Summary of Server Support
summarizes the support for each AAA service by each AAA server type, including the local
database. For more information about support for a specific AAA server type, see the topics following
the table.
Note
In addition to the native protocol authentication listed in
, the ASA supports proxying
authentication. For example, the ASA can proxy to an RSA/SDI and/or LDAP server via a RADIUS
server. Authentication via digital certificates and/or digital certificates with the AAA combinations
listed in the table are also supported.
Table 1-1
Summary of AAA Support
AAA Service
Database Type
Local
RADIU
S
TACACS
+
SDI
(RSA)
NT
Kerberos
LDA
P
HTTP
Form
Authentication of...
VPN users
1
1.
For SSL VPN connections, either PAP or MS-CHAPv2 can be used.
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
2
2.
HTTP Form protocol supports both authentication and SSO operations for clientless SSL VPN users sessions only.
Firewall sessions
Yes
Yes
Yes
Yes
Yes
Yes
Yes
No
Administrators
Yes
Yes
Yes
Yes
3
3.
RSA/SDI is supported for ASDM HTTP administrative access with ASA 5500 software version 8.2(1) or later.
Yes
Yes
Yes
No
Authorization of...
VPN users
Yes
Yes
No
No
No
No
Yes
No
Firewall sessions
No
Yes
4
4.
For firewall sessions, RADIUS authorization is supported with user-specific access lists only, which are received or specified
in a RADIUS authentication response.
Yes
No
No
No
No
No
Administrators
Yes
5
5.
Local command authorization is supported by privilege level only.
No
Yes
No
No
No
No
No
Accounting of...
VPN connections
No
Yes
Yes
No
No
No
No
No
Firewall sessions
No
Yes
Yes
No
No
No
No
No
Administrators
No
Yes
6
6.
Command accounting is available for only.
Yes
No
No
No
No
No
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......