Configuring per-User Configuration
How to Configure a AAA Server for Per-User Configuration
DC-685
Cisco IOS Dial Technologies Configuration Guide
How to Configure a AAA Server for Per-User Configuration
The configuration requirements and the structure of per-user configuration information is set by the
specifications of each type of AAA server. Refer to your server documentation for more detailed
information. The following sections about TACACS and RADIUS servers are specific to per-user
configuration:
• Configuring a Freeware TACACS Server for Per-User Configuration (As required)
• Configuring a CiscoSecure TACACS Server for Per-User Configuration (As required)
• Configuring a RADIUS Server for Per-User Configuration (As required)
See the section “Monitoring and Debugging Per-User Configuration Settings” later in this chapter for
tips on troubleshooting per-user configuration settings. See the section “Configuration Examples for
Per-User Configuration” at the end of this chapter for examples of configuring RADIUS and TACACS
servers.
outacl#
cisco-avpair = "ip:outacl#2=permit ip any any precedence
immediate",
cisco-avpair = "ip:outacl#3=deny igrp 10.0.9.10 255.255.0.0 any",
rte-fltr-in#
IP:
cisco-avpair = "ip:rte-fltr-in#1=router igrp 60",
cisco-avpair = "ip:rte-fltr-in#3=permit 10.0.3.4 255.255.0.0",
cisco-avpair = "ip:rte-fltr-in#4=deny any",
IPX:
cisco-avpair = "ipx:rte-fltr-in=deny 3C01.0000.0000.0001",
rte-fltr-out#
cisco-avpair = "ip:rte-fltr-out#1=router igrp 60",
cisco-avpair = "ip:rte-fltr-out#3=permit 10.0.5.6 255.255.0.0",
cisco-avpair = "ip:rte-fltr-out#4=permit any",
route#
IP:
cisco-avpair = "ip:route=3.10.0.0 255.0.0.0 1.2.3.4",
cisco-avpair = "ip:route=4.10.0.0 255.0.0.0",
IPX:
cisco-avpair = "ipx:route=4C000000 ff000000 10.12.3.4",
cisco-avpair = "ipx:route=5C000000 ff000000 10.12.3.5"
sap#
cisco-avpair = "ipx:sap=4 CE1-LAB 1234.0000.0000.0001 451 4",
cisco-avpair = "ipx:sap=5 CE3-LAB 2345.0000.0000.0001 452 5",
sap-fltr-in#
cisco-avpair = "ipx:sap-fltr-in=deny 6C01.0000.0000.0001",
cisco-avpair = "ipx:sap-fltr-in=permit -1"
sap-fltr-out#
cisco-avpair = "ipx:sap-fltr-out=deny 6C01.0000.0000.0001",
cisco-avpair = "ipx:sap-fltr-out=permit -1"
pool-def#
cisco-avpair = "ip:pool-def#1=aaa 10.0.0.1 1.0.0.3",
cisco-avpair = "ip:pool-def#2=bbb 10.1.0.1 2.0.0.10",
cisco-avpair = "ip:pool-def#3=ccc 10.2.0.1 3.0.0.20",
pool-timeout
cisco-avpair = "ip:pool-timeout=60"
1. This attribute is specific to RADIUS servers. It can be used to add Cisco IOS interface configuration commands to specific
user configuration information.
Table 39 RADIUS Server AV Pair Examples for Each Attribute (continued)
Attribute RADIUS Server Examples
Comments to this Manuals