Chapter 11
Configuring AAA Servers and the Local Database
AAA Server and Local Database Support
The FWSM supports a variety of AAA server types and a local database that is stored on the FWSM.
This section describes support for each AAA server type and the local database.
This section includes the following topics:
•
•
•
•
•
•
•
•
Summary of Support
Table 11-1
database. For more information about support for a specific AAA server type, see the topics following
the table.
Table 11-1
AAA Service
Authentication of. . .
VPN users
Firewall sessions
Administrators
Authorization of. . .
VPN users
Firewall sessions
Administrators
Accounting of. . .
VPN connections
Firewall sessions
Administrators
1. VPN is available for management connections only.
2. For firewall sessions, RADIUS authorization is supported with user-specific access lists only, which are
3. Local command authorization is supported by privilege level only.
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Summary of Support, page 11-3
RADIUS Server Support, page 11-4
TACACS+ Server Support, page 11-4
SDI Server Support, page 11-5
NT Server Support, page 11-5
Kerberos Server Support, page 11-6
LDAP Server Support, page 11-6
Local Database Support, page 11-6
summarizes the support for each AAA service by each AAA server type, including the local
Summary of AAA Support
Database Type
Local
1
Yes
Yes
Yes
1
Yes
No
3
Yes
1
No
No
No
received or specified in a RADIUS authentication response.
RADIUS
TACACS+
SDI
Yes
Yes
Yes
Yes
Yes
No
Yes
Yes
No
Yes
No
No
2
Yes
Yes
No
No
Yes
No
Yes
Yes
No
Yes
Yes
No
No
Yes
No
AAA Server and Local Database Support
NT
Kerberos
LDAP
Yes
Yes
No
No
No
No
No
No
No
No
No
Yes
No
No
No
No
No
No
No
No
No
No
No
No
No
No
No
11-3