About The Cisco-Av-Pair Raduis Attribute - Cisco 3.3 User Manual

For windows server version 3.3
Table of Contents

Advertisement

Appendix C
RADIUS Attributes
Table C-2
Cisco IOS/PIX RADIUS VSAs (continued)
Number
Attribute
250
cisco-ssg-account-info
251
cisco-ssg-service-info
253
cisco-ssg-control-info

About the cisco-av-pair RADUIS Attribute

Note
78-16592-01
Type of Value
String (maximum length
247 characters)
String (maximum length
247 characters)
String (maximum length
247 characters)
The first attribute in the Cisco IOS/PIX RADIUS implementation, cisco-av-pair,
supports the inclusion of many AV pairs, using the following format:
attribute sep value
where attribute and value are an AV pair supported by the releases of IOS
implemented on your AAA clients, and sep is "=" for mandatory attributes and
"*" for optional attributes. This allows the full set of TACACS+ authorization
features to be used for RADIUS.
The attribute name in an AV pair is case sensitive. Typically, attribute names are
all in lowercase letters.
The following is an example of two AV pairs included in a single Cisco IOS/PIX
RADIUS cisco-av-pair attribute:
ip:addr-pool=first
shell:priv-lvl=15
The first example causes the Cisco multiple named IP address pools feature to be
activated during IP authorization (during PPP IPCP address assignment). The
second example causes a user of a device-hosted administrative session to have
immediate access to EXEC commands.
About the cisco-av-pair RADUIS Attribute
User Guide for Cisco Secure ACS for Windows Server
Inbound/Outbound
Multiple
Outbound
No
Both
No
Both
No
C-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Secure access control serverSecure acs

Table of Contents