Cisco ASA 5505 Configuration Manual page 694

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Configuring AAA for System Administrators
Enabling TACACS+ Command Authorization
Before you enable TACACS+ command authorization, be sure that you are logged into the adaptive
security appliance as a user that is defined on the TACACS+ server, and that you have the necessary
command authorization to continue configuring the adaptive security appliance. For example, you
should log in as an admin user with all commands authorized. Otherwise, you could become
unintentionally locked out.
Detailed Steps
To perform command authorization using a TACACS+ server, go to Configuration > Device
Step 1
Management > Users/AAA > AAA Access > Authorization, and check the Enable authorization for
command access > Enable check box.
Step 2
From the Server Group drop-down list, choose a AAA server group name.
(Optional) you can configure the adaptive security appliance to use the local database as a fallback
Step 3
method if the AAA server is unavailable. Click the Use LOCAL when server group fails check box.
We recommend that you use the same username and password in the local database as the AAA server
because the adaptive security appliance prompt does not give any indication which method is being used.
Be sure to configure users in the local database (see the
and command privilege levels (see the
page
Step 4
Click Apply.
Configuring Management Access Accounting
You can configure accounting when users log in, when they enter the enable command, or when they
issue commands.
Prerequisites
You can only account for users that first authenticate with the adaptive security appliance, so configure
authentication using the
section on page
For information about configuring a AAA server group, see the
section on page
accounting, you can only use TACACS+ servers.
Detailed Steps
Cisco ASA 5500 Series Configuration Guide using ASDM
32-22
show pager
clear pager
quit
show version
32-15).
"Configuring Authentication for CLI, ASDM, and enable command Access"
32-11.
31-8. For CLI access, you can use TACACS+ or RADIUS servers. For command
Chapter 32
"Adding a User Account" section on page
"Configuring Local Command Authorization" section on
"Configuring AAA Server Groups"
Configuring Management Access
31-18)
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents